Microsoft and Google add enterprise controls for AI agents

Microsoft and Google have introduced new governance controls for AI agents as enterprises move beyond chatbot pilots and into systems that can act across business applications. Analysts say the tools improve visibility, but they do not solve risks from shadow AI, third-party integrations, and autonomous actions outside vendor platforms.

Microsoft and Google add enterprise controls for AI agents

Microsoft and Google are adding new controls for AI agents as enterprise IT teams try to manage software that can access corporate data and act across business applications.

Microsoft’s Agent 365 became generally available for commercial customers on May 1. The product is designed to help organizations discover, govern, and secure AI agents, including agents operating across Microsoft, third-party software as a service (SaaS), cloud, and local environments.

⚡ New to this?

This news is about how big tech vendors are building controls for AI agents, which are programs that can do tasks for users instead of just answering questions. The important part for non-experts is that these agents can touch company data and business systems, so they create security and management issues that are closer to normal IT operations than to simple chatbot use.

🦞 OpenClaw angle

If you run self-hosted agents, do not assume platform-native controls will cover you. Keep a central inventory of every agent, tool connection, and API permission, and separate what is approved from what is experimental or user-created.

Add audit logging that records not just actions, but the prompt, tool call, and policy decision behind each action. Also define an explicit owner for each agent so security issues do not get lost between developers, operators, and platform teams.

Google announced a new AI control center for Workspace this week. Google said the tool gives administrators a centralized view of AI usage, security settings, data protection controls, and privacy safeguards within Workspace.

The timing reflects a shift in how companies are using AI. Many enterprises are moving past chatbot trials and starting to deploy agents that can reach corporate systems and carry out tasks on behalf of users.

Analysts said that change affects how CIOs and CISOs think about AI inside the enterprise. A CIO, or chief information officer, runs technology strategy, while a CISO, or chief information security officer, oversees security.

“By placing agent controls alongside identity, access, data, and workload management, vendors are positioning AI governance as an operational discipline owned jointly by IT and security,” said Biswajeet Mahapatra, principal analyst at Forrester. He said CIOs should treat AI agents like other digital workers, with lifecycle oversight, cost visibility, and service management integration.

For CISOs, Mahapatra said the issue goes beyond model risk and data leakage. As agents get more autonomy, security teams need a more continuous way to control what they can do and reduce the impact when their actions create risk.

Lian Jye Su, chief analyst at Omdia, said the announcements make AI governance a “core component of all AI-assisted enterprise applications.” He said that signals to CIOs and CISOs that governance has to be built into AI deployments as adoption moves from pilots to enterprise-wide use.

The two vendors are taking different approaches. Su said the tools are complementary for enterprises running multicloud and hybrid IT environments, and that companies heavily invested in one vendor will probably have a smoother experience using that vendor’s native controls.

Mahapatra said the distinction is more about platform scope than governance maturity. Microsoft’s approach treats AI agents as enterprise actors that need broad oversight across the organization, while Google’s controls focus more narrowly on how AI interacts with collaboration data and user content.

“These are not fully competing approaches because they govern different control planes,” Mahapatra said. He added that they are not fully complementary either unless an enterprise standardizes on both ecosystems.

Pareekh Jain, CEO of Pareekh Consulting, described the relationship as both complementary and competitive. He said enterprises that use both Microsoft and Google may find AI governance becoming more closely tied to each vendor’s underlying platform.

The new controls still leave important risks unresolved. Jain said shadow AI agents can appear through developer tools, browser extensions, local assistants, SaaS copilots, and unsanctioned tool connections. He also said third-party integrations may grow faster than security teams can validate them.

“Audit logs may show what happened, but not always why an autonomous agent chose an action,” Jain said. That creates problems when an agent takes actions that cause business or security impact, because logs alone do not answer questions of control or responsibility.

Mahapatra said the biggest gaps are likely to remain outside native platforms. Shadow agents built through low-code tools, external APIs, or embedded SaaS applications can bypass central controls and operate with excessive or inherited permissions.

“Third-party integrations often expand agent reach without equivalent visibility into downstream actions or data propagation,” Mahapatra said. He said auditability is still uneven when agents chain actions across systems, and accountability remains unresolved when autonomous agents cause material business or security impacts.

The broader message is that Microsoft and Google may improve visibility and control inside their own platforms, but they do not cover the full agent field. Enterprises using multiple clouds, SaaS tools, developer platforms, and browser-based AI assistants will still need governance that extends beyond any one vendor’s console.

Source: CIO AI ↗

More from Security News