As an analyst working in the AI space, I’ve been closely following the debate around governance: where it comes from, who leads it, and how to get it right. That’s why I want to explore every angle of this integral piece of the AI puzzle, including the smaller breakthroughs that often ripple across the industry.
We recently saw the tech bosses from the largest AI firms meet at the White House to discuss how they would collectively follow self-imposed standards. Now, that’s noteworthy, but it’s not the full picture. Other alliances and collaborations are also helping to secure the AI ecosystem.
They are more nuanced and specific, but collectively, they are contributing to a safer operating landscape. I want to look at two of them today, both focused on one of the most pressing challenges facing the industry: securing agentic AI workflows.
Google Cloud + Thales
French technology company Thales and Google Cloud have expanded their existing collaboration, with a focus on the security and governance challenges associated with agentic AI technologies.
“By expanding our collaboration with Google Cloud, we are helping organizations build the necessary trust with security and governance as the foundation required for the next generation of enterprise AI,” said Eva Rudin, Senior Vice President, Thales.
So, what does that mean in practice?
Thales AI Security Fabric will be integrated with Google Cloud’s Gemini Enterprise, providing security, governance and visibility across interactions between users, agents, models, and tools in real time.
The aim is to give companies greater control over how AI agents access data, interact with other agents and systems, and take action.
The security layer is designed to help detect AI-specific threats, enforce policies, and prevent unacceptable or unauthorized actions while at the same time, giving teams an overview of agent behavior. These controls manage some of the emerging risks associated with agentic AI, including prompt injection, sensitive data leakage, unsafe or unauthorized actions, and interactions between agents.
This expanded collaboration comes at a point when AI is becoming increasingly autonomous, meaning security has to happen in real time. Google Cloud has found a strong partner in Thales to help enable this shift in governance — from standard-setting to embedded technical controls that define how this infrastructure actually operates.
SAP + NVIDIA
In another significant announcement, SAP has revealed that it’s working with NVIDIA to support safer agentic AI, with a focus on making enterprise agents more governable, secure, and auditable by design. The announcement came alongside NVIDIA’s launch of its Open Agent Safety Platform, an open software platform designed to strengthen AI security from testing through to deployment
SAP says its engineers are contributing directly to the OpenShell codebase and that it’s embedding OpenShell within the SAP Business AI Platform. OpenShell is NVIDIA’s open-source secure runtime for autonomous AI agents, creating a secure layer that controls what agents can do and access.
Beyond OpenShell itself, the runtime will be paired with SAP’s Joule Studio runtime, which delivers the business governance layer. Joule Studio can determine whether an action should be executed in the first place before a request is authorized. OpenShell then provides the technical runtime boundary that governs how the agent carries out its task, what it can access, and what it can do.
Final Thought
I’ll reiterate my opening point here. Understanding how AI will be governed in a way that ensures it is not only safe, but also operates in ways that support human endeavors and achievements, is about more than high-level agreements, whether at the governmental or corporate level.
As with many technologies throughout history, small successes, alliances, and collaborations focused on specific areas — not just blanket promises — can eventually converge to help ensure that an industry as a whole works for the better.
For an example from history, look no further than commercial aviation, something we all rely on and trust. Aviation didn’t become safe through regulation alone.
It started as a fragmented collection of airlines, aircraft manufacturers, airports, and regulators, each with different standards and, indeed, different goals. Turning commercial aviation into something we can rely on and trust required an entire ecosystem of standards, engineering, audits, industry cooperation, and technical safeguards.
This might be a bit of a wild guess, but agentic AI, at least, could well be heading down the same path.




