Securing autonomous agents requires a layered defense that combines IAM identities, resource policies, and network perimeters. New updates introduce agent-specific identity rules, conditional access based on Model Context Protocol attributes, and native integration with the Gemini Enterprise Agent Platform to enforce destination-based boundaries.