AI agents create a different security problem when they gain permission to change business systems. Reading email or querying a database exposes information. Calling APIs or initiating operations can change another system immediately.
Google Cloud reports that 35% of senior IT decision-makers cite inadequate security for access across multiple systems as a primary issue holding back agentic deployment. Google Cloud sells AI and cloud infrastructure, so it benefits commercially when companies invest in infrastructure and security for these deployments. The finding points to a concrete concern for executives: an agent that acts across systems needs tightly defined identity, permissions and oversight.
AI agent security changes when agents can act
An agent with operational authority needs safeguards around the actions it can take. An incorrect response may mislead a user. An incorrect action can immediately affect another system.
Security therefore becomes part of workflow design. Businesses have to decide which systems an agent can reach, which actions it can initiate and when a person must intervene.
Google Cloud describes agents with this level of access as “ultimate insiders.” That is Google Cloud’s characterization of software trusted to operate across sensitive systems.
Useful agents need carefully bounded permissions
An enterprise agent may need to read email, query databases and invoke APIs to complete a task across applications. Multi-system access creates a deployment challenge because the permissions that make an agent useful also determine the scope of its authority.
Executives need to define that authority at the task level: which resources the agent can access, which operations it can perform and which actions require approval. Google Cloud identifies human review for critical actions as one control, allowing a high-impact step to require approval before execution.
A project in mind?
Schedule a 30-minute meeting with us.
Senior experts helping you move faster across product, engineering, cloud & AI.
Authorized agents can also be manipulated
Access credentials are one part of the threat model. Google Cloud also identifies tool poisoning and indirect prompt injection as risks. Tool poisoning means compromising or manipulating a tool or its description to steer an agent toward harmful behavior. Indirect prompt injection occurs when malicious instructions are embedded in content that an agent processes.
These attacks can influence software that already has permission to act. Security design therefore has to address the information and tools that shape an agent’s behavior.
Google Cloud argues for secure-by-default design, meaning security measures are built into AI systems from the start. Its recommendations include measures intended to reduce exposure to prompt injection, along with agent-specific identity controls, permission structures and visibility into what an agent can access and do. These recommendations align with Google Cloud’s commercial interest in selling infrastructure and security services for AI deployments and should be evaluated in that context.
Google Cloud also argues that organizations deploying agents into sensitive workloads may need to rebuild parts of their technology stacks around security and governance. That is a vendor recommendation rather than a universal requirement. The survey finding establishes concern about multi-system access security. It does not establish rebuilding the stack as the required response.
Infrastructure challenges extend beyond agent permissions
Google Cloud reports that 79% of technology leaders identify security, governance or operations as their biggest challenge in expanding inference workloads. Inference is the process of running a trained AI model to produce an output.
That figure combines three categories, so it cannot establish identity or agent permissions as the leading infrastructure problem. It also measures a broader issue than the finding on multi-system access security for agentic deployment.
The two findings answer different questions. One concerns expansion of inference workloads across security, governance or operations. The other focuses on access across multiple systems when agents can act.
Integrated platforms are one vendor response
Google Cloud says 69% of surveyed executives consider a full-stack platform a critical requirement, while 80% say data compliance is the main factor shaping that choice. A full-stack platform provides multiple layers of infrastructure and management within one technology environment.
Google Cloud has a direct commercial stake in this framing because it sells cloud and AI infrastructure. Its survey findings are vendor-produced evidence of customer priorities. They do not independently establish that companies should consolidate onto one platform.
Google Cloud connects its approach to a central control plane for agent activity and its Secure AI Framework, or SAIF. A control plane is a management layer for applying policy and oversight across systems. Under Google Cloud’s framing, identities, data, models, APIs, policies and monitoring can be governed through coordinated infrastructure.
For executives, the platform decision comes down to a concrete test: whether the architecture can give an agent a defined identity, limit what that identity can do, observe its behavior and route consequential operations to human approval. Each enterprise still has to determine which architecture can enforce those boundaries in its own sensitive workflows.
Key executive takeaways
- Control agents that can act: AI agents with authority to change business systems require stronger safeguards than tools that only retrieve information. Define which systems and actions each agent can access and where human approval is required.
- Bound permissions at the task level: Give agents only the access needed for specific workflows. Agent identities, resource permissions and approval requirements should limit the scope of consequential actions.
- Protect authorized agents from manipulation: Credentials alone do not address tool poisoning or indirect prompt injection. Leaders should assess the tools and information that can influence an agent after access has been granted.
- Separate agent security from broader infrastructure concerns: Google Cloud reports challenges spanning security, governance and operations for inference workloads, but these findings do not establish agent permissions as the leading infrastructure problem. Evaluate each risk against the specific workload.
- Test platforms against concrete controls: Integrated platforms may simplify governance, but vendor survey data does not establish consolidation as the required approach. Assess whether the architecture can enforce agent identity, permissions, monitoring and human approval across sensitive workflows.
A project in mind?
Schedule a 30-minute meeting with us.
Senior experts helping you move faster across product, engineering, cloud & AI.


