The sequel to Prompt Injection to Playbook is here, and this time, we’re going up a level! While everyone is being urged to "adopt AI agents," almost nobody has been handed a blueprint for doing so without exposing a massive new attack surface. To address this, I built an entire Security Operations Center staffed by five autonomous AI agents running live on Google's Agent Platform to answer the ultimate question: At 2:00 AM, would you trust an unattended fleet of AI agents running without a leash? Join me as we break down the five native Google Cloud control planes—Identity, Mediation, Observability, Detection, and Response—and lay out the exact end-to-end architecture you need to secure, monitor, and safely govern your autonomous agent fleets on Google Cloud.
What You Can Expect
In this webinar, you can expect to learn how to:
- Orchestrate a multi-agent fleet by understanding how a master orchestrator coordinates specialized threat hunters, detection engineers, and remediation agents safely.
- Minimize the blast radius of compromised AI agents by implementing keyless Workload Identity (SPIFFE) as a modern alternative to insecure service account JSON keys.
- Deploy Inline Model Armor to establish real-time screening filters that catch prompt injections, jailbreaks, and sensitive data leaks.
- Avoid the "silent failure" in logging by properly configuring GCP Data Access audit logs to ensure malicious credential exfiltration doesn't remain invisible to your security tools.
- Build behavioral meta-detections by writing YARA-L rules in Google SecOps that monitor the agents themselves for abnormal API volumes or secret access.
- Design human-in-the-loop SOAR playbooks that require manual human approval gates before executing high-impact actions like revoking certificates.
- Unify cost and security governance by translating token consumption metrics into BigQuery dashboards that spot budget overruns and potential compromise signals.
Key Discussion Points & Timestamps
-
07:54 - Why Securing AI Agents Matters: The reality of the autonomous SOC and the challenge of "governing the governor."
-
10:04 - Governing the Autonomous SOC: Overview of the 5-agent live fleet on Google's Agent Platform.
-
12:14 - The Trust Question: Would you run five AI agents unattended at 2:00 AM? Defining the needed leash.
-
13:03 - The 5-Part Control Plane Blueprint: High-level look at Identity, Mediation, Observability, Detection, and Response.
-
14:53 - Control Plane 1 - Workload Identity: Why keyless, short-lived SPIFFE certificates eliminate service account risks and limit blast radius.
-
17:24 - Control Plane 2 - Inline Mediation: Leveraging Model Armor and IAM scopes to block prompt injections and data leaks.
-
19:15 - Control Plane 3 - Forensic Observability: Activating Data Access audit logs to feed telemetry to SecOps and BigQuery.
-
20:41 - Control Plane 4 - Behavioral Detection: Running YARA-L rules and meta-detections to watch the SOC itself for misbehavior.
-
22:08 - Control Plane 5 - Human-in-the-Loop Response: SOAR playbooks and manual approval gates for certificate revocation.
-
24:22 - Defense in Depth: Evaluating the four layers of protection against direct prompt injections and RAG poisoning.
-
26:18 - Cost Governance as Security Governance: Tracking token consumption to spot cost anomalies and runaway loops.
-
28:17 - Trace Walkthrough & Tool Delegation: Analyzing how the orchestrator processes requests and coordinates the fleet.
-
29:19 - Live Demo - CLI & Claude Code Setup: Generating automated threat hunting reports and IOC analysis.
-
35:20 - Live Demo - GCP Console & Agent Platform: Navigating the agent registry and workload certificates.
-
36:50 - Live Demo - Model Armor in Action: How prompt sanitization and jailbreak filters flag interactions in real-time.
-
43:22 - Live Demo - SecOps Rules & Meta-Detections: Utilizing data tables and YARA-L to trigger alerts on out-of-scope actions.
-
46:49 - Live Demo - Case Containment Playbooks: Watching a simulated SOAR playbook halt execution at a manual approval gate.
-
48:09 - Live Demo - ROI & Token Cost Dashboard: Analyzing token Z-scores, model calls, and cost metrics in BigQuery.
-
52:43 - Recap - Governing the Governors: Key takeaways on securing next-generation AI pipelines.
