---
格式版本: 2
标题: "State of AI infrastructure report agent governance and security"
原文链接: "https://cloud.google.com/blog/topics/ai-infrastructure/state-of-ai-infrastructure-report-agent-governance-and-security"
发布日期: "2026-08-25"
发布时间校准状态: "found"
发布时间需复核: "否"
发布时间来源: "rule:configured_publication_date_rule"
发布时间证据: "google-cloud-blog-date-div html:original: August 25, 2026"
发布时间校准原因: "信源发布日期识别规则直接确认发布时间"
发布时间校准置信度: "high"
发布时间候选数量: 1
发布时间严格候选数量: 1
发布时间原页读取状态: "source template page reused from URL open"
发布时间未找到原因: ""
发布时间校准时间: "2026-08-25T01:57:12+08:00"
发布时间仲裁状态: "skipped"
发布时间仲裁尝试次数: 0
发布时间仲裁耗时毫秒: 0
发现时间: "2026-08-25T01:56:20+08:00"
入库时间: "2026-08-24T17:57:12.542Z"
来源平台: "固定入口"
搜索渠道: "fixed_url"
搜索词: "https://cloud.google.com/blog/"
匹配关键词:
  - "AI"
  - "deployment"
相关厂家:
  - "Google"
相关专家:
  []
内容类型: "网页"
抓取工具: "Free Fetch + Defuddle"
清洗工具: "Defuddle Markdown + Defuddle/Readability 正文提取"
原始附件:
  []
AI优质: "否"
AI打分: 14
AI分档: "非优质"
AI质检状态: "不通过"
AI打分理由: "文章主题为AI代理安全治理，讨论权限管理、提示注入等，未涉及超节点、AI Rack、机柜级硬件、供电散热互连或相关部署，与项目关注范围无关。"
AI质检模型: "ali-deepseek-v4-flash"
AI质检时间: "2026-08-25T01:57:57+08:00"
AI主题相关性: 1
AI来源权威性: 8
AI新颖性: 3
AI技术细节: 0
AI商业部署信号: 0
AI完整性: 2
图片摘要:
  - "✓ ./assets/img-a8213f84.png | other | https://storage.googleapis.com/gweb-cloudblog-publish/images/Blog_4_Infographic_1.max-1100x1100.png"
  - "✓ ./assets/img-0572c04b.png | other | https://storage.googleapis.com/gweb-cloudblog-publish/images/Blog_4_Infographic_2.max-600x600.png"
  - "✓ ./assets/img-c9752340.png | other | https://storage.googleapis.com/gweb-cloudblog-publish/images/Blog_4_Infographic_3.max-600x600.png"
AI摘要: "Google Cloud《AI基础设施现状》报告显示，79%的科技领导者将安全、治理或运营视为扩展推理的最大挑战，35%的IT决策者认为多系统访问安全性不足阻碍了AI代理部署。"
AI摘要模型: "ali-deepseek-v4-flash"
AI摘要时间: "2026-09-07T02:11:09.881Z"
采集批次: "2026年8月25日1点56分17秒"
采集批次ID: "20260825-015617-463"
去重键: "https://cloud.google.com/blog/topics/ai-infrastructure/state-of-ai-infrastructure-report-agent-governance-and-security"
---

##### Doug Ko

Senior Product Marketing Manager, Security

##### Try Gemini Enterprise Business Edition today

The front door to AI in the workplace

[Try now](https://business.gemini.google/?utm_source=cloud.google.com/blog&utm_medium=et&utm_campaign=FY26-Q2-GLOBAL-GLO27877-physicalevent-er-next26-mc-105752)

AI agents are the ultimate insiders. We grant them permission to read emails, query databases, and trigger API calls. They don’t just retrieve information, they take action.

Agents offer incredible potential for increased productivity and better customer experiences, but they also come with new security concerns. In our new [State of AI infrastructure report](https://cloud.google.com/resources/content/state-of-infrastructure-in-the-agentic-ai-era), 79% of tech leaders cite security, governance, or operations as their most significant challenge to scaling inference.

While there’s still a crucial role for traditional security tools, the threat model has fundamentally changed. Autonomous workflows have redefined enterprise risk, so it's crucial that we give agents the access they need without compromising security.

![https://storage.googleapis.com/gweb-cloudblog-publish/images/Blog_4_Infographic_1.max-1100x1100.png](./assets/img-a8213f84.png)

![https://storage.googleapis.com/gweb-cloudblog-publish/images/Blog_4_Infographic_2.max-600x600.png](./assets/img-0572c04b.png)

### The agentic paradox

The path to success starts with viewing governance as a driver for innovation. To be useful and secure, an agent needs access — and also guardrails. Yet 35% of senior IT decision makers cite insufficient security for multi-system access as a primary issue preventing agentic deployment.

Agents expand the surface area that defenders need to protect, and can introduce new threats, including tool poisoning and indirect prompt injection, where an attacker can hijack an agent’s logic through the data it processes. Managing the dynamic permissions that agents need to succeed at their tasks can also be a significant challenge, particularly as legacy security wasn’t designed for today’s automated threats.

![https://storage.googleapis.com/gweb-cloudblog-publish/images/Blog_4_Infographic_3.max-600x600.png](./assets/img-c9752340.png)

### Securing the chain of thought

Along with securing more identity and access issues, it’s important for defenders to secure both the network layer and the model.

Security leaders are increasingly shifting their focus from preventing breaches to verifying provenance to guard against misuse, including indirect [prompt injection](https://cloud.google.com/transform/5-gen-ai-security-terms-busy-business-leaders-should-know).

**From an infrastructure perspective, what are your top security concerns related to AI?**

### From blocking to managing

We’ve looked at the new security challenges posed by agentic AI. You can’t solve them by simply locking down the system, as that defeats the purpose of autonomous agents.

Many organizations are turning to integrated, full-stack cloud platforms to give them greater oversight. 69% of surveyed executives now rate a full-stack platform as a critical requirement, and 80% say data compliance is the primary factor dictating that choice.

By adopting frameworks like the [Secure AI Framework](https://cloud.google.com/blog/products/identity-security/cloud-ciso-perspectives-practical-guidance-building-with-SAIF/) (SAIF) and moving to a central control plane, purpose-built platforms such as [Gemini Enterprise Agent Platform](https://cloud.google.com/blog/products/ai-machine-learning/introducing-gemini-enterprise-agent-platform), organizations can manage risk in three main areas:

- **Secure-by-default design:** Embedding security directly into the AI development process to proactively guard against threats including prompt injection.
- **Agent governance and oversight:** Adopting purpose-built permission and identity management for agents — giving greater control over agent interactions, exposing blind spots and limiting risks tools.
- **Human-in-the-loop control:** Enforcing clear rules that automatically flag when an agent requires human approval before moving forward with a critical action.

### Governance will guide you to success

The true value of a modern security foundation is its ability to encourage innovation. By embedding robust governance directly into a unified foundation, organizations can deploy agents with confidence across their most sensitive, business-critical workloads.

The leaders of the agentic era are re-architecting their stack to use security as a launchpad — empowering them to innovate securely and scale faster than their competition.

Find out more about how enterprise leaders are rethinking security for the agentic era in the [State of AI infrastructure](https://cloud.google.com/resources/content/state-of-infrastructure-in-the-agentic-ai-era) report.
