Google judges an agent's intent at runtime, and the catalog cannot see the gateway

Google judges an agent's intent at runtime, and the catalog cannot see the gateway

Google has published the clearest worked example of runtime governance for agents I have read. In Build zero-trust AI agents that judge intent, not just syntax, Eric Dong and Shubham Saboo start from the limit of build-time controls: “they only catch cases that you can explicitly specify ahead of time.” The line that carries the piece: “A SQL parser cannot tell a socially engineered refund from a legitimate one if the syntax is valid.” The architecture is three layers behind an Agent Gateway on the Gemini Enterprise Agent Platform. Model Armor screens prompts at the edge, so a jailbreak is dropped with a 403 and “the agent’s model is never invoked, so no tokens are consumed.” Semantic Governance Policies judge each proposed tool call against a natural-language rule before it runs. Agent Anomaly Detection watches session telemetry across the fleet for what no single turn reveals.

There are no adoption numbers, only the scenario, and the scenario is what makes it teachable. A support agent handles order 99281, a $149 total made of a $29 docking station and a $120 software license. A polite request to refund the license is denied by a rule written in English, that refunds for opened digital goods over 30 dollars must be denied, which catches a “Google Workplace user license” that keyword matching would miss. Then the attacker splits the same refund into eight $20 turns, each one passing the policy on its own, and the anomaly detector flags the cumulative total against the order’s $149 baseline. The fix is the part worth copying: “you can close the loop without modifying or redeploying agent code,” because an administrator authors a new constraint that takes effect at runtime. Every write is still signed with a Cloud KMS key, and the reference implementation ships as open source with local stand-ins for the cloud services.

The catalog cannot see any of it. The Google Vertex AI provider page lists 5 API pages, and they are the classic machine learning platform: the Google Vertex AI Models API, the Google Vertex AI Endpoints API, and the Google Vertex AI Predictions API are where the agent’s model calls land, alongside datasets and training pipelines. Agent Gateway, Model Armor, Semantic Governance Policies, and the agent engine underneath them have no page, on this record or any other. That is our gap, and it is filed, the mirror of the AgentCore gap on the Bedrock record. The agentic access profile maps 8 operations, 3 of them acting.

The Kin Score is 42.6, developing band. Discoverability carries it at 66.1 and contract quality at 52.7, with access clarity at 47.4, developer ergonomics at 34.5, operational transparency at 26.3, and contract governance at 9.8. The Agent Readiness score is 24.8, agent-aware. Delegated identity is lit, which is the one dimension this story’s KMS-signed, user-attributed writes would exercise. Consent identity, dry-run mode, error semantics, and the MCP server are unlit. Google’s post is about a gateway that decides what an agent may do before it does it. The catalog’s record of Google’s platform describes a model endpoint and stops there. Until the gateway is on the record, the best runtime governance design in the market scores as if it did not exist.

← Dynatrace scores 85.7 and ships its own MCP server, but 14 of the 23 contracts we hold never say where to call
Hygraph's agent door scores twice its developer door →