GCP

Google Cloud Next ‘26: AI agents, Wiz integration, and new security controls

Google Cloud unveiled AI-powered security agents, Wiz’s expanded AI protection, and new Trusted Cloud capabilities at Next ‘26.

E

Everything Cloud

Everything Cloud

Google Cloud Next ‘26: AI agents, Wiz integration, and new security controls

At Google Cloud Next ‘26, the company introduced three new AI agents in Security Operations for threat hunting, detection engineering, and third-party context, while Wiz announced AI-native development lifecycle protections and integrations with Databricks and agent studios. Trusted Cloud received updates to IAM, data security, network controls, and Security Command Center to secure AI workloads across clouds.

https://storage.googleapis.com/gweb-cloudblog-publish/images/GCN26_102_BlogHeader_2436x1200_Opt_3_Dark.max-2500x2500.jpg

AI agents accelerate defense in Security Operations

Google Security Operations now includes three new AI agents: the Threat Hunting agent in preview helps teams proactively identify novel attack patterns and stealthy adversary behaviors that bypass traditional defenses; the Detection Engineering agent in preview automates detection creation by identifying coverage gaps and generating new detections for threat scenarios, reducing manual toil; and the Third-Party Context agent, coming soon to preview, will enrich workflows with contextual data from external sources. These agents enable defense at machine speed by augmenting analyst workflows with AI-driven insights.

The existing Triage and Investigation agent processed over 5 million alerts in the past year, cutting average manual analysis time from 30 minutes to 60 seconds using Gemini. BBVA’s head of Security Technology noted the agent filters false positives and provides transparent explanations, allowing teams to focus on complex investigations. Organizations can now build custom security agents using remote Google Cloud Model Context Protocol (MCP) server support, which is generally available, with a preview MCP client accessible directly from the Security Operations chat interface.

Agentic automation in Security Operations enables automated response actions, while dark web intelligence in Google Threat Intelligence—now in preview—analyzes millions of daily external events with 98% accuracy to surface high-fidelity threats. IDC research cited in the announcement found that AI-augmented security operations reduce mean time to detect and respond, lower false positives, and boost analyst productivity, translating into shorter disruption periods and lower incident-related costs.

Wiz expands AI application and workload protection

Wiz, now part of Google Cloud, announced its AI-Application Protection Platform (AI-APP) at RSA Conference, offering deep visibility, risk posture, and runtime analysis for AI applications. Wiz also introduced Security Agents and Workflows to identify and respond to risks at machine speed. The platform now supports Databricks and agent studios including AWS Agentcore, Gemini Enterprise Agent Platform, Microsoft Azure Copilot Studio, and Salesforce Agentforce, ensuring visibility regardless of how teams build AI workloads.

Wiz continues to extend its security graph with integrations to Google Cloud Apigee for API discovery, Cloudflare AI Security for Apps, and the Vercel platform. Detection forwarding from Wiz Defend to Google Security Operations and Mandiant Threat Defense has been updated to help analysts configure automatic threat information flow more easily. These integrations strengthen end-to-end protection across the outer layer of cloud environments.

To secure the AI-native development lifecycle, Wiz announced four new capabilities: a generally available integration (May) that runs security scans inside the Lovable platform to surface vulnerabilities in built-in security views; inline AI security hooks that scan AI-generated code in IDEs and agent workflows before commitment; Wiz Skills that equip coding agents with full code-to-cloud context for automated agent-driven remediation locally or at the repository level; and an AI-Bill of Materials (AI-BOM) that automatically inventories AI frameworks, models, and IDE extensions to uncover shadow AI and track sanctioned tools like Gemini Code Assist and GitHub Copilot.

Trusted Cloud updates strengthen AI workload security

Trusted Cloud received updates across identity, data, and network security. IAM improvements include a streamlined predefined roles catalog with easy-to-use administrator, editor, and viewer roles, plus an IAM role picker and the ability to re-authenticate sensitive actions. Data security gains include Confidential Computing support for G4 VMs with NVIDIA RTX PRO 6000 Blackwell GPUs (preview), preview of C4 Confidential VMs with Intel TDX, Confidential External Key Manager (cEKM) in preview, KMS Quantum Safe Key Imports in preview, and general availability of Secret Manager integration with the Agent Development Kit to prevent password leaks and prompt injection risks.

Network security enhancements feature Cloud NGFW with an advanced malware sandbox (preview later this year) powered by Palo Alto Networks Advanced Wildfire, trained on data from over 70,000 customers to stop 99% of known and unknown malware. Cloud Armor now offers managed rules in preview, powered by Thales Imperva, to detect Layer 7 application attacks and zero-day CVEs like React2Shell. These controls help defend against evasive threats at the network layer.

Security Command Center (SCC) now provides continuous discovery and risk analysis for AI agents, models, and MCP servers. An upcoming preview feature will automatically discover unmanaged agentic workloads on Cloud Run, GKE, and inference endpoints, surfacing them as posture findings. The enhanced SCC Standard tier offers data security posture management, compliance, vulnerability management, and risk analysis at no extra cost, helping customers establish a strong security baseline from the start.

What to do next

Security teams should explore the preview AI agents in Security Operations, evaluate Wiz’s AI-BOM and IDE integrations for developer workflows, and review the updated Trusted Cloud controls—especially Confidential Computing and SCC Standard tier—to align AI adoption with automated, intelligence-driven defense.

Source: Next ‘26: Redefining security for the AI era with Google Cloud and Wiz (GCP).

Share:TwitterLinkedIn

Related Articles