Skip to content
redactsure
Book a demo

Explore.

Comparison · By Chris Sowa · Published
Last updated

Does Gemini Enterprise's Model Armor Control What an Agent Sees?

Model Armor can inspect supported inputs routed through it, including images through its direct API. Coverage depends on the integration and enforcement settings; task-specific tokenization is a separate control to verify.

A routed data stream passes an inspection gate while a separate stream reaches a browser, illustrating coverage by input path.

Model Armor can inspect supported inputs routed through it, including images through its direct API. Coverage depends on the integration and enforcement settings; task-specific tokenization is a separate control to verify. Google documents several Model Armor integrations with different supported content types. A screenshot is not inherently outside inspection: a developer can route supported image input through the API. The practical review is to trace each input path and establish which values are blocked, retained or transformed before the model receives them. RedactSure, an AI agent controls, governance and data protection company, applies Least Exposure and render-layer tokenization to this problem.

Key findings

What does the Gemini Enterprise Agent Platform include?

Google's announcement lists the parts. An enhanced Agent Development Kit brings "a graph-based framework" and MCP support. Agent Studio is the low-code path. Agent Designer lets "anyone create agents to automate complex, multi-system processes with simple, natural language," including agents that run on a schedule or a trigger. Connectors "integrate with your enterprise data, including data in third-party systems."

Around those build tools sit the controls. Agent Identity "assigns every agent a unique cryptographic ID for complete traceability and auditing." Agent Gateway is described as "air traffic control to ensure interactions between agents and data is secure." Model Armor "protects against activities like prompt injection, tool poisoning, and sensitive data leakage." Agent Observability gives "a real-time view into safety and performance."

The security write-up adds sandboxed agent workspaces and an agent registry so that "all autonomous actions are authenticated, observable, and mapped to a specific lifecycle owner." It also lists Google Cloud IAM for least-privilege access, Sensitive Data Protection on model inputs and outputs, and audit and lineage. The list is a platform for building agents. Nothing in either document describes an agent that operates a screen.

What does Model Armor protect, and where does it sit?

Model Armor inspects supported content sent through its API or integrations. Google's integration documentation distinguishes the paths: the direct REST API supports text, documents and images, while integrated services have narrower modality support. The API returns findings for the application to enforce; supported integrations can block configured violations.

That is more than a network-only control. It can inspect content before a model receives it, provided the input is routed through a supported path. The Gemini Enterprise integration blocks sensitive content rather than de-identifying it. A task-specific tokenization policy remains a separate implementation question.

Why is a gateway not the screen?

A screenshot can be routed through an inspection service; coming from a screen does not make it inherently invisible to a gateway. The coverage question is whether the application routes that input through a supported inspection path before the model call.

For a workflow crossing an EHR and payer portal, trace screenshots, extracted text and tool responses independently. A control on one path may leave another uninspected. A render-layer policy can replace selected values before those observations are formed, while a gateway can inspect supported content on its configured route. The two controls can be combined.

Who decides what the agent sees?

In the Gemini Enterprise documentation, three things decide. IAM decides what data an agent may query or manipulate. Agent Identity and Agent Gateway decide which agent may reach which data, authenticated and mapped to a lifecycle owner. Model Armor and Sensitive Data Protection inspect content on their configured paths.

Access and inspection controls need to be configured for the workflow; their presence alone does not establish its field-level input policy. IAM says the agent may read the claims system. It does not say that for this claim the model should receive the loss date, the reserve and the coverage code, with the claimant's name as CLAIMANT_001 and the SSN as SSN_001. That decision is specific to a piece of work. It is confirmed by a named workflow owner and enforced at the render (render-layer tokenization). Access permissions alone do not specify every field to forward after access is granted (Does Least Privilege Cover What the AI Sees?).

Accountability follows the same split. Agent Identity makes an agent traceable, which matters. It does not put a named person's approval in front of each payment, submission or record change. That is Supervised Delegation, and it is a workflow control, not an identity control.

Where does the bought application's screen sit in a regulated estate?

In healthcare, the EHR is the bought estate. An agent working a prior authorization or a claim appeal reads the chart in Epic and the payer's portal, whose observations must be explicitly routed through an inspection path to be covered. HIPAA's minimum necessary standard at 45 CFR 164.502(b) asks what the use requires. The chart is more than the task requires. The render is where that standard can be met for a screen-based task (Can an AI Agent Work in Epic Without Holding PHI?).

In insurance, the claims platform is the bought estate. An injury claim moves across ClaimCenter, ISO ClaimSearch and a payment portal, each a rendered screen. The NAIC Model Bulletin, adopted by 24 states as of March 2025 per Quarles & Brady, asks insurers to govern the data their AI systems use. The examiner's question is what the model received for one claim (Can an AI Agent Work Guidewire Claims Without PII?).

In education, the student information system is the bought estate. FERPA's school official exception at 34 CFR 99.31(a)(1)(i)(B) requires the district to have direct control over the use of education records. A district needs to establish direct control through its agreement and configured service, and inspect the data the model actually receives (Can an AI Agent Use PowerSchool Without Student PII?).

What does a regulated buyer do with both?

Two lines in the budget. The first is a gateway for the built estate: the agents the organization's developers write, the connectors it wires, the tool calls it routes. Model Armor and Sensitive Data Protection belong there, and a Google shop should use them. The second is a render layer for the bought estate: the applications the organization runs but did not build, worked through the screen under the permissions the user already holds. What the model receives is decided per task before it reads anything. The AWS pattern leaves the same second line for the customer to build. The screen versus API question decides which line a given workflow falls under.

How does the Gemini Enterprise Agent Platform compare with a governed environment?

Control Gemini Enterprise Agent Platform (from documentation) RedactSure governed environment
Where the control sits The gateway between built agents and the model The render layer, before any model reads the screen
What it inspects Model inputs and outputs routed through the gateway Every screen of every application the agent works
Coverage of built flows Yes: ADK, Agent Studio, Agent Designer, connectors Yes, when the flow renders inside the environment
Coverage of bought applications' screens Not described Yes: no per-application integration
Who decides what the agent sees IAM (access), the application (content) The Planner, per task; a named person confirms
Action gate Agent Gateway policies and IAM A named person approves every consequential action
Record Agent Observability, audit and lineage Every action logged, human and computer; all PII as tokens
Model choice Not described in the cited material Claude, GPT, Gemini, open-weights, swappable without moving the controls
Keys Not described in the cited material Customer-held; RedactSure holds ciphertext it cannot decrypt
Injection collects What the gateway lets through Tokens and remaining task context; consequential actions require approval

Where does RedactSure sit?

RedactSure supplies the second line. AI co-workers do real work on the claims platform, the EHR, the student information system, the ERP and the portals around them, inside a governed environment. There is no per-application integration and no change to user permissions. The environment is a secure virtual machine deployed into the cloud the customer's posture requires, on hardware-encrypted enclaves, with keys the customer holds. Every sensitive value chosen by policy is replaced by a consistent token at the render layer before any model reads the screen. The model is handed the task's fields rather than a picture of the page. The Planner sets which values are tokenized and what the agent may do on each screen. A named person confirms that policy and approves every payment, submission and record change. Deployments are in pilot.

This adds a field-level policy to the screen observations in the selected workflow. It can be combined with supported gateway inspection and application controls. Every screen as tokens, every action and every approval lands in the AI Control Record and exports to the customer's SIEM. The model is swappable, so a Gemini model can do the work under the same controls, with Model Armor still on the built estate.

Methodology and limitations

The HIPAA minimum necessary standard has exceptions, including certain treatment disclosures. Its application depends on the purpose and parties. Replacing direct identifiers does not by itself establish HIPAA de-identification or remove all PHI from the remaining context.

The page rests on two Google documents read as of September 30, 2026. They are the Google Cloud Blog post of April 22, 2026, and the Google Cloud Security Community post "Securing the Agentic Era" (2026). Google's wording is cited with their dates; where it is silent the page says so. Quarles & Brady's March 2025 adoption count is cited as that firm's view. Regulation is read from its text: 45 CFR 164.502(b), 34 CFR 99.31, the NAIC bulletin adoption map and OWASP's LLM01:2025 entry. Case law and enforcement actions were not surveyed.

No hands-on testing of the Gemini Enterprise Agent Platform was performed; what Model Armor, Sensitive Data Protection and Agent Identity do is Google's own description. The Security Community post is read as Google's account of the controls, not as reference documentation. The editorial pass checked Model Armor's integration documentation. Google's service-specific terms, BAA coverage and the platform's FedRAMP status were not reviewed. Those could disclose inspection scope, key management or certifications the launch material does not. Vendor features change; the page carries its date and is revised when documentation changes. Statements about claims platforms, EHRs and student portals describe the record type, not any organization; no customer or prospect is described.

Whether a deployment meets the minimum necessary standard, FERPA's school official exception or the NAIC bulletin is for the organization's counsel, assessor or compliance officer, not this page.

We did not run the vendor products or capture their model requests. Workflow examples are analysis, and RedactSure behavior is described from its current design.

What the record shows

Model Armor can inspect supported inputs routed through it, including images through its direct API. Coverage depends on the integration and enforcement settings; task-specific tokenization is a separate control to verify. Trace screenshots, tool responses and prompts separately. Confirm the supported modality and enforcement mode on every path before relying on the control.

Frequently asked questions

Does Model Armor inspect what a connector returns?

It can inspect supported tool or connector content routed through an enabled integration. Trace the actual response and verify the integration's modality and enforcement settings. Inspection or blocking is not the same as a stable, task-scoped replacement token.

Is Sensitive Data Protection the same as render-layer tokenization?

No. Google's data protection services can detect and transform data in supported integrations. The relevant question is which feature the application actually uses before the model call. RedactSure applies consistent replacement tokens at the render layer; assess that behavior separately from gateway inspection or blocking.

Does Gemini Enterprise have a computer-use agent?

Not in the cited material. The announcement describes build tools, connectors and controls for agents that call tools and data through the platform. No agent that operates a screen, takes screenshots or works a web or desktop application through its user interface is described. An organization that needs an agent on a bought application's screen should ask Google directly and record the answer.

Can RedactSure run on Google Cloud?

Yes. The governed environment is a secure virtual machine deployed into the cloud the customer's posture requires, on hardware-encrypted enclaves, with keys the customer holds. A Google shop can run the environment in its own Google Cloud project and keep Model Armor on its built agents. A Gemini model can do the screen-based work inside the environment under the same controls.

Does Agent Identity make an agent accountable?

Traceable, yes. Agent Identity gives each agent a cryptographic ID and maps its actions to a lifecycle owner, which an auditor can follow. Accountability for a consequential action is a named person answering for it before it happens: the payment, the submission, the record change. That is Supervised Delegation, and it is a workflow control the identity layer does not supply on its own.

Which should a Google shop buy first?

Start with the workflow and trace its input and action paths. Use supported gateway inspection where data is routed through it, and evaluate render-layer tokenization where screen observations need consistent stand-ins. The needed controls depend on the implementation, not simply on whether the application was bought or built.

Sources

Vendor documentation

  1. Google Cloud Blog, "The new Gemini Enterprise: one platform for agent development" (April 22, 2026). https://cloud.google.com/blog/products/ai-machine-learning/the-new-gemini-enterprise-one-platform-for-agent-development
  2. Google Cloud Security Community, "Securing the Agentic Era: New Gemini Enterprise Agent Platform" (2026). https://security.googlecloudcommunity.com/security-command-center-4/securing-the-agentic-era-new-gemini-enterprise-agent-platform-7376

Regulation and standards

  1. 45 CFR 164.502(b), HIPAA minimum necessary standard. https://www.ecfr.gov/current/title-45/subtitle-A/subchapter-C/part-164/subpart-E/section-164.502
  2. 34 CFR 99.31, FERPA school official exception. https://www.ecfr.gov/current/title-34/subtitle-A/part-99/subpart-D/section-99.31
  3. NAIC, Model Bulletin on the Use of AI Systems by Insurers, adoption map. https://content.naic.org/sites/default/files/legal-adoption-map-ai-model-bulletin.pdf
  4. OWASP, LLM01:2025 Prompt Injection. https://genai.owasp.org/llmrisk/llm01-prompt-injection/

Independent analysis and press

  1. Quarles & Brady, "Nearly Half of States Have Now Adopted NAIC Model Bulletin" (March 2025). https://www.quarles.com/newsroom/publications/nearly-half-of-states-have-now-adopted-naic-model-bulletin-on-insurers-use-of-ai

RedactSure documents

  1. RedactSure, "The Two Gaps AI Agents Opened in Your Security Stack" (2026). https://redactsure.com/blog/two-gaps-ai-agents-opened-in-your-security-stack/
  2. RedactSure, "Accountable AI and Workflow Governance" (2026). https://redactsure.com/blog/accountable-ai-and-workflow-governance/
  3. RedactSure, "Secure AI That Crosses Every Silo" (2026). https://redactsure.com/blog/secure-ai-that-crosses-every-silo/
  4. RedactSure Research, "AI Gateway, DLP, or Tokenization: Which Layer Decides What the AI Sees?" (2026). https://redactsure.com/research/ai-gateway-dlp-or-tokenization
  5. RedactSure Research, "What Is Least Exposure?" (2026). https://redactsure.com/research/what-is-least-exposure
  6. RedactSure Research, "What Is Render-Layer Tokenization?" (2026). https://redactsure.com/research/what-is-render-layer-tokenization
  7. RedactSure Research, "What Is Supervised Delegation?" (2026). https://redactsure.com/research/what-is-supervised-delegation
  8. RedactSure Research, "What Is an AI Control Record?" (2026). https://redactsure.com/research/what-is-an-ai-control-record
  9. Product behavior described on this page reflects RedactSure's current design. Google, Google Cloud, Gemini and Model Armor are trademarks of Google LLC; named to identify the products. Compliance determinations belong to the organization's counsel.

Editorial verification

  1. Google Cloud, Model Armor integration overview, supported modalities and enforcement. https://docs.cloud.google.com/model-armor/integrations

See it on your workflow.

Bring one billing, collections, claims or patient-account workflow and your questions.

Book a demo

Book a demo

Having trouble? Open the booking page or email us.