Course Overview
This course identifies different attack vectors where malicious actors could abuse AI agents and proposes a defense-in-depth strategy, using a multi-layered approach to guard against attacks. These include guardrails on content, identity and access management of users and agents, network security, discoverability and observability.
Who should attend
Architects, Cloud Developers, AI Engineers, Security Experts.
Prerequisites
Working knowledge of building ADK agents and deploying them to Agent Runtime.
Course Objectives
- Deploy Agent Gateway as the centralized solution for managing network and content security.
- Implement content security guardrails using Model Armor and Cloud DLP to mitigate semantic threats like prompt injection and data leakage.
- Establish a zero-trust security perimeter using unique Agent Identity with mTLS, per-tool authorization with REQUEST_AUTHZ, and granular CEL policies.
- Discover agent tools through the Agent Registry and ensure end-to-end observability and threat detection using Cloud Trace and Security Command Center.
Outline: Govern agents on Gemini Enterprise Agent Platform (GAGEAP)
Module 1 - The new agent paradigm and threat landscape
Topics:
- Chatbots vs. actionable autonomous agents
- The reach of gaining access to your AI agents
- Google’s defensive strategy
Objectives:
- Understand the danger of deploying AI agents.
- Identify attack vectors for your agents.
- Discover Google’s defensive strategy with the Project PISA and SAIF
Module 2 - Content security guardrails
Topics:
- ADK native content defense mechanisms.
- Agent Gateway as an external enforcement tool.
- Model Armor detects and blocks prompt injection and jailbreak attacks.
- Cloud DLP to analyse data sensitive information.
Objectives:
- Implement callbacks to inspect the messages before and after they enter tools and agents to identify and prevent attacks in messages.
- Deploy Agent Gateway as a centralized policy enforcement point.
- Configure Model Armor templates to detect and mitigate prompt injection and jailbreak attacks.
- Integrate Cloud DLP de-identification templates with Model Armor to mask sensitive information like SSNs in model responses.
Module 3 - Identity and access control (IAM and IAP)
Topics:
- Agent Registry and IAM policies for workloads and agents
- Agent Identity to identify agents
- Common Expression Language (CEL) to enforce access boundaries.
Objectives:
- Integrate Agent Gateway with the Agent Registry and IAM policies to govern agent workloads.
- Configure and deploy unique Agent Identities using mTLS.
- Implement per-tool authorization policies using the REQUEST_AUTHZ extension.
- Author Common Expression Language (CEL) policies to enforce granular, condition-based access boundaries.
Activities:
- Secure Agent Tools with Google Cloud Agent Identity and Auth Manager lab
Module 4 - Network Security
Topics:
- Network segmentation and micro-segmentation strategies for agent communication.
- Securing transit using mTLS and private endpoints.
- Configuring firewall rules and VPC Service Controls for agents
Objectives:
- Implement network segmentation and micro-segmentation strategies for agent communication.
- Secure transit between agents and external services using mTLS and private endpoints.
- Configure firewall rules and VPC service controls to restrict agent access.
Module 5 - Discoverability and observability
Topics:
- Tool and agent discovery.
- Observability across your agent ecosystem.
- End-to-end time spans for agent interactions.
Objectives:
- Register and manage Google APIs and third-party MCP servers in the Agent Registry.
- Configure an Agent Development Kit agent to dynamically discover and bind tools at runtime.
- Analyze distributed traces in Cloud Trace to audit security policies and tool execution paths.
Module 6 - Monitor and governance
Topics:
- Observe deployed agents.
- Protect against semantic attack detection, egress violations and credential misuse.
Objectives:
- Identifies sustained prompt injection attempts, jailbreak payloads, or jailbreak-style probing patterns across agent runtimes.
- Triggers critical alerts if an agent runtime attempts to bypass the Agent Gateway or connect to unapproved IP addresses.
- Flags anomalous usage of auto-provisioned Agent Identity tokens (e.g., an agent identity token being used from a workstation IP outside the designated Google Cloud VPC).