Secure Your AI ๐Ÿ”’ AI Governance with Apigee & Vertex AI | October 2025

Thanks to everyone who joined our latest Community Tech Talk on AI Governance! We had a fantastic session demonstrating how to manage security and policy enforcement for modern GenAI applications.

For those who missed it, or if you want to revisit the technical deep dive, the full recording is now available.

What You Will Learn

Scaling AI agents requires robust governance. We covered the essential architecture to shift from fragmented controls to a unified control plane.

  • Centralized Security: Use Apigee as the critical governance layer for all Vertex AI and GenAI applications.

  • Compliance Made Easy: Learn the blueprint for achieving end-to-end auditing and observability of AI-driven API calls.

  • Mission-Critical Safety: Discover key principles for protecting sensitive data and ensuring high availability.

:movie_camera: Watch the Full Recording

:movie_camera: Q&A Recap

Donโ€™t miss the detailed Q&A starting at minute 30 in the recording.

Q: Is the model armor more part of Apigee policies and not a separate application?
A: SanitizeUserPrompt policy  |  Apigee  |  Google Cloud Documentation

Q: So usually the enterprise right in enterprise we have all the APIs right now on the APIGEE. Okay. โ†’ And the way I understood your session is we are going to have GenAI as model as one of the proxy on the APIGEE and that will be used by agent space or any chat bots. Is that accurate?
A: If we think an AGENt is API and LLM is an API you will be able to proxy them through APIGEE.

Q: Can Vertex and APIGEE work with agent force?
A: Iโ€™m not an Agent Force expert but for Apigee if SFDC exposes its agents via standard protocols and hasnโ€™t added any special restrictions.

Q: One question. Every prompt from the user will be considered one call to APIGEE. If so, can this consume the entitlements in number of calls of APIGEE contract?
A: Overall, all prompts sent from an agent or model and secured by Apigee are counted as entitlement calls.

Q: My question is more about converting APIs into MCPs to expose them as MCP servers to other clients. Right now in our org we have hundreds of proxies deployed for different teams. So is there any way that we can turn on these proxies into MCPS because each and every team is protecting their proxies using arbback using policies for authentication and authorization using W2 and other policies so securely. So is there any way that we can turn on these proxies into MCPS? Do we have any native capabilities in APIGEE uh to directly uh convert the proxies into MCPS and to deploy them as MCPS so that uh the clients can directly MCP clients can directly uh convert talk to these MCP servers uh from their MCP tool set.
A: Mathilde suggested two ways, mentioned existing APIGEE samples or go-gen.

Next Up in the Tech Talk Series!

If you found this session valuable, donโ€™t miss our next talks. We meet every Thursday to dive into the latest on Apigee, Application Integration, and Google Cloud.

:test_tube: AI-Powered Testing (API Test Automation with API Hub & Gemini)

:cloud: Cloud Native Services & APIs (Cloud Run & Apigee)

What was your biggest takeaway from the governance session?

:loudspeaker: Contact our sales team today to explore further โ†’ https://goo.gle/43i4Rmv