{"type":"post","slug":"build-zero-trust-ai-agents-with-google-s-adk","title":"Build zero-trust AI agents with Google's ADK","description":"Google's ADK team open-sourced a deliberately exploitable refund agent to argue that perimeter security is blind once an LLM chooses its own execution path through production systems.","retrieval_nugget":"Google's ADK team open-sourced a deliberately exploitable refund agent to argue that perimeter security is blind once an LLM chooses its own execution path through production systems.","published_at":"2026-08-31","updated_at":"2026-09-12","record_date":"2026-08-25","date_kind":"discovered_at","topics":["agent-security","agents","ai"],"entities":["Google"],"source_url":"https://developers.googleblog.com/build-zero-trust-ai-agents-with-googles-agent-development-kit","source_title":"Build zero-trust AI agents with Google's Agent Development Kit- Google Developers Blog","source_domain":"developers.googleblog.com","source_terms":["zero-trust","Google's","refund","prompt","autonomous"],"summary_word_count":198,"schema_version":"newruntime-agent-readable-v0.2","stable_id":"post:build-zero-trust-ai-agents-with-google-s-adk","status":"published","source_urls":["https://developers.googleblog.com/build-zero-trust-ai-agents-with-googles-agent-development-kit"],"visuals":[],"editorial_provenance":{"schema_version":"newruntime-editorial-copy-v1","content_status":"source_grounded_final","final_copy_sha256":"sha256:001259e77ee82f5e18746324337f982b0c03d1171288fe72704d9dcd09ba191c","reviewed_at":"2026-09-12T10:00:00Z","source_evidence_count":1,"verified_claim_count":2,"site_analysis_schema_version":"newruntime-site-analysis-v1","site_object_kind":"field_note","observed_fact_count":2,"implication_count":1,"watch_condition_count":1,"related_record_count":3},"analysis":{"schema_version":"newruntime-site-analysis-v1","object_kind":"field_note","thesis":"Google's Agent Development Kit team published a zero-trust guide on 17 August built around a deliberately realistic target: an autonomous customer support and returns agent, written with ADK and Gemini, open-sourced with a runnable demo in a zero-trust-agents repository.","observed_facts":[{"text":"The team built and open-sourced an autonomous customer support and returns agent using ADK and Gemini with a runnable demo.","source_urls":["https://developers.googleblog.com/build-zero-trust-ai-agents-with-googles-agent-development-kit"]},{"text":"The post states that an agent connected to live databases and internal APIs mutates production state rather than generating text.","source_urls":["https://developers.googleblog.com/build-zero-trust-ai-agents-with-googles-agent-development-kit"]}],"mechanism":"Because the model determines its own execution path in unstructured natural language, traditional perimeter security is blind to how the agent behaves internally, so the controls have to sit on each action rather than at the edge.","why_now":"A framework makes multi-tool autonomous workflows trivial to assemble, but the moment those sessions reach live databases, internal APIs and dynamic runtimes, the agent stops generating text and starts mutating production state: issuing refunds, modifying records, executing code.","implications":["The point of shipping the vulnerable thing is that defence patterns are only checkable against real exploits."],"evidence_boundary":"This is a vendor engineering post with an open repository, not an audited threat model or a measured comparison of defence patterns.","watch_conditions":["The condition to watch is whether the repository accumulates reproduced exploits and their mitigations over time, because a zero-trust demo that stays at one scenario teaches a pattern rather than a boundary."],"related_records":[{"url":"https://newruntime.com/posts/agent-security-moves-outside-the-model","relation":"Prior coverage of security controls moving outside the model."},{"url":"https://newruntime.com/posts/aisi-unsanctioned-agent-actions","relation":"Prior coverage of an authorization failure misread as a sandbox failure."},{"url":"https://newruntime.com/topics/agent-security","relation":"Topic hub for agent action-level controls."}]},"routes":{"html":"https://newruntime.com/posts/build-zero-trust-ai-agents-with-google-s-adk/","markdown":"https://newruntime.com/posts/build-zero-trust-ai-agents-with-google-s-adk.md","json":"https://newruntime.com/posts/build-zero-trust-ai-agents-with-google-s-adk.json"}}
