đ Zero-Trust Security, Identity & Threat Defence
Security architectures are actively evolving to combat automated threats, introducing advanced data protection for AI models, secure runtimes, and quantum-resistant cryptography.
- Model Armor Doesnât Redact PII. Sensitive Data Protection Does: An explanation of how to properly configure Google Cloud Model Armor and Sensitive Data Protection (SDP) to redact personally identifiable information (PII) from AI model responses instead of simply blocking them.
- Eval Is Evil: How to Safely Execute Untrusted AI Code with Cloud Run sandboxes and ADK: Exploring how Google Cloud Run sandboxes provide a secure isolation boundary for safely executing untrusted user input and AI-generated code.
- Future-proofing data integrity: Quantum-safe digital signatures in Cloud KMS: Extending the PQC digital signature algorithms suite available in Google Cloud Key Management System to include ML-DSA and SLH-DSA.
- Mastering Agent Runtime Security Controls on Google Cloud Platform: A comprehensive architectural guide for securing enterprise AI Agent Runtimes on GCP, focusing on preventing unauthorised data exfiltration and shadow tool integrations.
- Cloud CISO Perspectives: Why AI Threat Defense is the new boardroom baseline: Why boards and CISOs must focus on AI-era security governance and threat defence as a standard business baseline.
- Best Buy scales AI workloads and secures access with Workforce Identity Federation: To support tens of thousands of users, Best Buy modernised its identity architecture using Workforce Identity Federation.
- Advancing brain tumor research with privacy-first AI: Discover how Google Cloud and MedPerf use Confidential Computing to enable secure, privacy-first collaborative medical AI evaluation.
- Batten Down Your Packages: Mitigation Guidance for Supply Chain Compromise: Trends observed in threat actor use of software supply chain compromise, complete with mitigation and hardening recommendations.
- UNC6671 Rebrands: Multi-Brand Vishing Extortion Targets Cloud Environments: Tracking UNC6671's rebranding from BlackFile to REDACT as they diversify extortion operations targeting financial and cloud services.
đ High-Performance Databases, Analytics & Open Knowledge
Data platforms are focusing heavily on performance optimisation, cross-cloud querying, and deploying autonomous agents for database operations.
- Unifying public and private data: Scale knowledge graphs with Data Commons on Spanner: Create a knowledge graph combining public Data Commons data as well as your private data with the new Spanner Graph-native platform.
- Introducing Database Operations Agents: The future of autonomous database management: A closer look at AI-powered database operations agents for setting up, onboarding, and managing AlloyDB, Bigtable, Cloud SQL, and Spanner.
- The borderless Lakehouse: Bring AWS, Databricks and Snowflake data to your AI agents: The borderless Lakehouse provides secure, bi-directional access via BigQuery and Managed Service for Apache Spark to any Iceberg-compatible engine.
- Databricks Iceberg â BigQuery query: A comprehensive technical guide on how to configure and query Apache Iceberg tables created in Databricks using BigQuery.
- Zero-code, low-cost data ingestion: New BigQuery DTS capabilities: Automate low-cost data ingestion from diverse sources directly into your data warehouse with new BigQuery Data Transfer Service capabilities.
- Building an Agentic DB Analyst: pgvector, Google Cloud Storage (GCS), and Deterministic SQL: Bridging relational databases and Cloud Storage without sacrificing mathematical accuracy using deterministic SQL and pgvector.
- How Target is enhancing retail discovery with Spanner Graph: Target transitioned to Spanner Graph to overcome siloed data and build a generative AI-powered Shopping Graph.
- Agentic Future Ready With BigQuery: Continually improving price-performance through autonomous query processing with zero effort required.
- How Database Migration Service automates SQL server to PostgreSQL translation: Automating the translation of SQL Server Stored Procedures into PostgreSQL using Google DMS.
- How to Build a Serverless Agent Observability Pipeline in BigQuery: Building a real-time observability pipeline for multi-agent systems using the ADK, Continuous Queries, and BigQuery ML.
⥠High-Efficiency Compute, Networking & GKE Workloads
Cloud infrastructure engineering continues to maximise accelerator density, introducing new failover mechanisms and smarter workload scheduling.
- GCP Cloud Runâs New Automated Failover Is a Direct Answer to a Real Outage: Exploring Google Cloudâs rapid launch of automated cross-region failover for Cloud Run, utilising standard readiness probes and application load balancers.
- Stop Over-Provisioning for Startup: GKEâs New CPU Startup Boost: GKE's new CPU startup boost feature allows developers to temporarily increase CPU requests during heavy application initialisation phases.
- How to build an elastic, scalable LLM Inference Platform on GKE using Fluid Compute: Architecting a fault-tolerant, cost-optimised LLM serving platform on Google Cloud using diverse GPU consumption types and multi-region GCS buckets.
- Scaling real-time AI agents with session-aware load balancing: Implementing application-level session tracking directly within the runtime to accurately measure the committed concurrent workload of active conversations.
- Inside the optimization of Mistral 3 large inference on Ironwood: Detailed strategies like hybrid sharding and SparseCore tree reductions that boosted Mistral 3 inference throughput by 48% on Ironwood TPUs.
- How We Reduced GKE Costs by 33% Through Smarter Scheduling and Resource Governance: A DevOps case study demonstrating how migrating to Spot nodes and right-sizing resource requests transformed cluster efficiency.
- Cloud Run vs. GKE Autopilot: A Comparison for ADK Agents: A practical evaluation highlighting differences in identity configuration, cold-start behaviour, and infrastructure complexity when hosting ADK workloads.
- Do more with less: How GKE can reduce your cost per agent by 75%: GKE Agent Sandbox increases agent density up to 3.5x and cuts compute costs without sacrificing performance.
- Bootstrapping OSS Kubernetes on GCE with TPU6 and Open-Source DRANET: Exploring how to deploy an open-source Kubernetes cluster directly on Google Compute Engine while integrating Cloud TPU v6e accelerators.
đ ď¸ Ecosystem, Agents & Platform Modernisation
The ecosystem is rapidly standardising agentic workflows, focusing on stateless protocols and unified model routing gateways.
- Scaling AI Agent Infrastructure with the MCP Stateless updates: The 2026-07-28 Model Context Protocol (MCP) specification introduces a fully stateless core, enabling cloud-native horizontal scaling and serverless deployments.
- Agent Plugins package your skills, tools, and more: Agent Plugins 1.0.0 provides a vendor-neutral directory specification for packaging Agent Skills and MCP servers into a single portable unit.
- Model routing with Google Cloud API Gateway: API Gateway now allows developers to dynamically route traffic to models like Gemini, Claude, or OpenAI OSS-GPT directly within their OpenAPI 3.x specifications.
- From repetitive queries to instant SQL: Building Carrefourâs internal data assistant: How retail giant Carrefour leveraged Google Cloud ADK, Gemini, and Cloud Run to build a scale-to-zero RAG assistant integrated directly into Google Chat.
- Enable on-demand expertise with Agent Skills in Genkit Go: To prevent context window bloat, Genkit Go introduces Agent Skills based on a progressive disclosure architecture.
- Finally â Hard Caps to Limit Your Google Cloud Spend: Google Cloud introduces native Cloud Spend Caps to hard-stop spend before your budget target amount is exceeded.
- The anatomy of an AI agent on Google Cloud: a complete guide: A comprehensive guide breaking down agent architecturesâcovering models, frameworks, runtimes, and memoryâonto Google Cloud products.
- Behind the scenes: How we build, test, and scale Google Agent Skills: Discover how Google maintains quality for Agent Skills with standard layouts, automated CI/CD checks, and continuous evaluations.
- Scaling agentic AI: How UiPath built its high-performance GPU platform on AI Hypercomputer: UiPath successfully transitioned toward agentic AI using a high-performance GPU platform powered by Google Cloud.
- Automate data monitoring and root-cause analysis with Looker Agentic Workflows: Extending one-time questions to ongoing inquiries utilising background agents that surface results directly in chat.
đ Essential Release Notes
A summary of critical platform updates, feature deprecations, and runtime enhancements rolling out across Google Cloud.
- Cloud Run: Support for sandboxes is now available in Preview for all resources, including jobs and worker pools.
- GKE: TPU Subslicing (Dynamic Subslicing) is now Generally Available for Ironwood (TPU7x), enabling incremental provisioning of node pools.
- Cloud SQL: DNS automation and global write endpoint DNS are Generally Available on instances with Private Service Connect. Performance capture is also GA.
- Cloud KMS: Cloud KMS now supports quantum-safe key import in Preview, including
HPKE_KEM_ML_KEM_768and1024methods. - Secret Manager: Automatic rotation of regional Cloud SQL database credentials is now available in Preview.
- Load Balancing: Regular expression URL rewrites (
regexRewrite) for route rules in URL maps are now available in Preview for Application Load Balancers. - Compute Engine: The maximum IOPS per GiB for Hyperdisk Balanced Storage Pools have increased to 30 IOPS/GiB for Standard performance and 6 IOPS/GiB for Advanced.
- AlloyDB: BigQuery integration enables real-time access (lakehouse federation) and periodic data synchronisation (Preview). Best Matching 25 (BM25) indexes are also supported.
- Bigtable: The Bigtable remote MCP server and
execute_sqltool are now Generally Available. You can also utilise Bigtable as a remote storage backend for LMCache (Preview). - Confidential VM: The accelerator-optimised
g4-standard-48machine type (Turin, AMD SEV, NVIDIA RTX PRO 6000) is now GA. - Policy Intelligence: The Policy Troubleshooter MCP server is generally available to let agents and AI applications troubleshoot IAM issues.
- Billing: Spend cap budgets are available in Preview, alongside the new Originating products filter in Cloud Billing Reports.