News · curated 5 Jul 2026
Securing agentic AI: What's new in VPC Service Controls | Google Cloud Blog
First reported google.com
Coverage timeline
Why it matters
VPC Service Controls' new MCP- and agent-identity-aware perimeter rules give defenders a network-level mechanism to contain compromised or misbehaving AI agents and constrain tool-calling abuse in production deployments.
Google Cloud announced new VPC Service Controls capabilities for securing agentic AI workloads, including treating AI agents as first-class IAM identities in perimeter ingress/egress rules, conditional access based on Model Context Protocol (MCP) attributes such as mcp.toolName and mcp.tool.isReadOnly, and native integration with the Gemini Enterprise Agent Platform that blocks public internet access. The features let administrators enforce least-privilege boundaries and revoke a compromised agent's access at the network perimeter.