As threat actors increasingly use AI to accelerate and develop cyberattacks, enterprise defenders need to rely on both AI and a critical defender’s advantage: Business context that only you possess. Enterprise cyber defense spans identity, network, endpoint, data, cloud, and application layers, often split across a dozen or more products, each with its own context. At Google Cloud Next, we brought partner-built agents into Gemini Enterprise to give you one place to discover and deploy specialized agents across functions including sales, content and creative workflows, HR, and security.

Today, we're expanding our catalog of partner-built security offerings in the Gemini Enterprise ecosystem to help you leverage your full security context from one unified interface. These new security agents and integrations from leading cybersecurity vendors span two areas: partner security agents that your teams invoke directly in Gemini Enterprise, and protections for AI and agentic workloads. By bringing them into Gemini Enterprise, you can now orchestrate multi-step security workflows directly in your Gemini Enterprise environment, bringing AI-powered capabilities to your defenses.

Acalvio : The Acalvio ShadowPlex deception agent, accessible through Gemini Enterprise, automates the deployment of decoys and honeytokens across enterprise networks and embeds deception guardrails directly into customer’s operating environment, with no manual configuration required. ShadowPlex deploys network decoys, identity honey accounts, retrieval-augmented generation (RAG) decoys, honey skills, and honeytokens at scale, trapping unauthorized interactions quickly.

Britive : The Britive Emergency Termination Agent, built on Gemini Enterprise, lets security teams contain a compromised human or non-human identity from a single natural-language request instead of working across multiple consoles. The agent confirms the identity, lists all active privileged sessions, revokes all sessions with human approval, disables the identity, and gathers audit context for the incident ticket. The result is significantly lower mean time to containment (MTTC) while maintaining strict governance and least-privilege access for agents.