Details
- Google for Developers used Google I/O Connect to unveil new tools and open standards aimed at safer agentic AI development.
- The company highlighted Sec-Gemini v3, a specialized cybersecurity agent designed to reason over complex security data and help teams investigate incidents at machine speed.
- Google introduced CodeMender, a developer-focused tool intended to help diagnose, fix, and secure code generated or orchestrated by AI agents in real-world workflows.
- CAPSEM, a secure runtime environment for AI agents that isolates and protects the broader system even if an agent is compromised or hit by a malicious prompt, is being open-sourced for developers.
- Google is promoting open industry standards including Device Bound Session Credentials (DBSC), which invalidate stolen session cookies, and the Agents-to-Payments protocol (AP2/A2A) to make low-value, agent-led financial transactions more secure and accountable.
- These tools and standards are framed as foundational safeguards for the emerging "agentic era," where AI systems act as autonomous agents across apps, infrastructure, and financial operations.
- The announcement is positioned within the broader Build With Gemini initiative, signaling that Gemini-based agents will have built-in support for stronger security, compliance, and runtime isolation.
- Google indicated that early access for some of these capabilities, such as Sec-Gemini v3 and CAPSEM, will focus on trusted government, enterprise, and regulated industry partners before broader developer rollout.
- By combining security-focused agents, safe runtimes, and open protocols, Google aims to create a more interoperable and defensible ecosystem for agent-based applications across cloud, on-prem, and distributed environments.
- Community responses in the thread suggest enthusiasm for the goal of making agentic development safer and more reliable for mainstream use cases.
Impact
This announcement signals Google’s push to make security and governance a first-class feature of agentic AI, not an afterthought. By open-sourcing CAPSEM and backing standards like DBSC and AP2, Google strengthens its position against rivals that focus more on model capabilities than agent safety. The move could accelerate enterprise adoption of AI agents, particularly in regulated and financial contexts, while nudging the broader ecosystem toward interoperable, standards-based defenses against session hijacking and unsafe autonomous transactions.