Welcome to issue #512 July 20th, 2026
News
AI Google Kubernetes EngineSecuring the AI supply chain on GKE: Introducing k8s-aibom for automated AI BOMs - We’re open-sourcing k8s-aibom, a Kubernetes controller that continuously monitors environments to detect AI runtimes and generate standard ML-BOMs.
Public SectorKey findings from the 2026 Public Sector M-Trends report and beyond - Explore the 2026 Public Sector M-Trends and beyond report. Learn how agencies are shifting to continuous verification and agentic defense to stop machine-speed attacks.
LLM QuadrantGoogle named a Leader in the 2026 IDC MarketScape for Worldwide Foundation Model Software - Google has been named a Leader in the IDC MarketScape: Worldwide Foundation Model Software 2026 Vendor Assessment.
AI QuadrantGoogle is a Leader and positioned furthest in Vision and highest in Execution in the 2026 Gartner® Magic Quadrant™ for Conversational AI Platforms - For the second consecutive year, Google has been named a Leader in the Gartner® Magic Quadrant™ for Conversational AI Platforms.
Articles, Tutorials
Infrastructure, Networking, Security, Kubernetes
AI NetworkingIDC: Why the right networking approach is foundational to agentic AI - According to IDC research, many of the delays in moving AI projects from pilot to production are related to concerns about networking.
AI CI LLM Threat IntelligenceDemystifying AI Exploits: A Blueprint for AI-Assisted Vulnerability Management - Details the architectural risks of integrating LLM agents into CI/CD pipelines for automated vulnerability discovery.
CISOCloud CISO Perspectives: How AI leverages deep context as the defender’s advantage - Francis deSouza explains the crucial role that deep context plays in creating an AI advantage for defenders.
AI Google Kubernetes EngineSecuring AI at Enterprise Scale: The Google Kubernetes Engine Blueprint - Learn how to secure AI workloads at enterprise scale with the Google Kubernetes Engine (GKE) security blueprint. Discover best practices for protecting infrastructure, model integrity, and inference paths to build secure AI applications.
App Development, Serverless, Databases, DevOps
FinOps GCP Experience Gemini SecurityThe 31-Minute Gap — Cloud Billing, Abuse, and Consumer Protection - This article exposes how cloud customers can incur massive, unexpected charges from abused API keys due to significant delays in billing and spend-alerting systems.
AlloyDB Cloud SQL DatabasesHow to solve PostgreSQL multilingual full-text search limitations with AlloyDB AI - Learn how AlloyDB integrates multilingual world knowledge of Gemini models natively in your database tier with AlloyDB AI Functions.
AlloyDBHow your sample data impact vector tests in PostgreSQL and AlloyDB. - This article demonstrates how the choice of sample data critically impacts vector tests in PostgreSQL and AlloyDB, particularly for Approximate Nearest Neighbor (ANN) indexes.
OracleUsing Your Own DNS Names with Oracle Database@Google Cloud - This article outlines how to configure custom DNS names for Oracle Database@Google Cloud, enabling organizations to use their established naming conventions instead of default Oracle-managed FQDNs.
Cloud Functions Threat IntelligenceThe Risk of Exposed Cloud Functions and How to Harden - Vibe coding has made it easier and faster to deploy code, but this breakneck speed demands that teams integrate security.
Cloud Run FinOps InfrastructureCloud Run Pricing - This article addresses the common challenge of estimating Google Cloud Run pricing and introduces a custom Terminal User Interface (TUI) tool developed to simplify this process. The tool provides a conservative cost estimate by assuming worst-case scenarios and omitting the free tier, with its code and pre-built containers openly available for users.
BigQuery Databases GCP ExperienceBuilding the AI-defined vehicle with Android, Google Cloud, and Nexus SDV - With its Valtech’s Nexus-SDV, Google’s Android and Google Cloud are helping the automotive industry go from the software- to AI-defined vehicle.
Antigravity Machine LearningWhere does Antigravity look for Hooks? - This article explores "Hooks" within the Antigravity framework, detailing how they allow custom scripts to extend agent functionality by running at specific points in its lifecycle. It explains the configuration process, including where these hooks are stored for global or workspace-specific settings, and demonstrates the types of events they can capture.
AI AntigravityEvolving Spec-Driven Development: Conductor Now Supports Antigravity - Conductor has evolved from a Gemini CLI extension into a portable plugin, bringing conversational Spec-Driven Development (SDD) to ecosystems like Antigravity CLI and Claude. Rather than relying on strict command sequences, developers can now chat naturally with their AI assistant while it dynamically manages persistent markdown artifacts (like spec.md and plan.md) in the background.
Big Data, Analytics, ML&AI
AgentsWhat 10 autonomous film crews taught us about agent teamwork - As part of an internal Google generative media hackathon (for humans), we put this question to the test – specifically, to uncover whether AI agents could work collaboratively in a domain less innately familiar than software development.
BigQuery Data Analytics IAMLevel Up Your Column-level Security: Using IAM Data Governance Tags in BigQuery - Learn how to manage column-level access controls in BigQuery using IAM data governance tags, ensuring secure, scalable data classification and protection.
BigQuery Data Analytics PythonBridging the gap between SQL and Python with BigQuery and the %%bqsql magic - Seamlessly chain Python and SQL in Jupyter notebooks using BigQuery DataFrames and the %%bqsql cell magic. Learn how in this step-by-step guide.
BigQuery Data Analytics VisualizationHow to Analyze and Govern Gemini Enterprise App Usage at Scale with BigQuery - Learn how to use BigQuery to analyze Gemini Enterprise usage logs, audit compliance, and build Looker dashboards at scale for your organization.
Agents AIGive Your AI Agent a Security Policy in Plain English with Semantic Governance - How to govern an ADK agent’s tool calls with a single sentence on Google’s Gemini Enterprise Agent Platform.
ADK InfrastructureADK Agent Identity on Google Cloud: Separate Identities, Separate Blast Radius - This article emphasizes the importance of establishing separate identities for agents in multi-agent systems on Google Cloud to create clear security boundaries and limit the "blast radius." It demonstrates how the default deployment can inadvertently assign overly broad permissions, necessitating the explicit configuration of dedicated service accounts with least-privilege IAM roles for each agent.
Colab GPU PaywallDon't Give Up Learning Just Because You Don't Have a Graphics Card – Google Gives You a Cloud Computer with a Built-In GPU - This article introduces Google Colab as a free, browser-based cloud environment equipped with a built-in GPU, enabling users to learn and practice deep learning without needing expensive hardware. It provides clear steps on how to get started, enable GPU runtime, integrate with Google Drive for data persistence, and run basic deep learning models like PyTorch. The guide also addresses common pitfalls and solutions, ensuring a smooth learning experience for students and developers.
AI LLM PartnersClaude at scale on Google Cloud: Frontier AI, built for enterprise production - To achieve frontier AI at scale, Claude brings the reasoning and Google Cloud brings the managed infrastructure, global reach, and compliance posture that enterprises already run on.
Antigravity Gemini Enterprise Agent PlatformThree lessons in accelerating foundation model upgrades - In this blog, we’ll show you our approach and three lessons you can apply to accelerate your own foundation model upgrades using Gemini Enterprise Agent Platform and Google Antigravity,.
AI Generative AI LLMGuide to AI Tokenomics: Eleven Principles for Token Efficient Software Engineering - Optimize your software engineering with our Guide to AI Tokenomics. Explore 11 actionable principles to improve coding assistant performance, reduce latency, and control costs effectively.
Gemini Enterprise Agent Platform Tutorial13 hands-on demos to build on Gemini Enterprise Agent Platform - Here are 13 demos that walk you through what Gemini Enterprise Agent Platform can do. Each one teaches a concept, a pattern, or an architecture you can put to work immediately.
AI GeminiExpanding Choice in Gemini Enterprise Agent Platform: Introducing Grounding with Parallel Web Search - Google Cloud has partnered with Parallel Web Systems to natively integrate Parallel search infrastructure as a web grounding provider on the Gemini Enterprise Agent Platform. This integration enables developers to anchor their AI agents in verifiable, real-time web results, significantly improving factual accuracy for complex enterprise workflows. Additionally, the partnership offers expanded architectural flexibility, allowing users to programmatically extract, permanently cache, and process web data alongside other large language models.
AI Generative AI LLMBuilding scalable AI agents with modular prompt transpilation - To resolve the scaling bottlenecks and runtime errors caused by monolithic system prompts, engineering teams should treat prompts as build artifacts by modularizing instructions into reusable templates. By running these modular "skill files" through a transpiler, developers can enforce static validation, catch missing dependencies at build time, and integrate prompt generation directly into their CI/CD pipelines. This deterministic approach prevents code drift and ultimately establishes a safe framework where agents can propose updates to their own logic via standard pull requests.
LLM Machine Learning Vertex AITuning enterprise embeddings in Google Vertex AI: The mathematics of LoRA, Weighted Contrastive Loss, and GCP Pipelines - This deep-dive explores the engineering and mathematics behind fine-tuning embeddings on Google Cloud's Vertex AI to overcome the limitations of general pre-trained models for enterprise data. It details how proprietary jargon is handled by mathematically warping the embedding space using advanced techniques like Weighted Multiple Negatives Ranking Loss (wMNRL) and Parameter-Efficient Fine-Tuning (LoRA). This process, managed through Vertex AI Pipelines, significantly improves retrieval accuracy for specialized corporate use cases.
BigQueryHow to Evaluate BigQuery Text-to-SQL Models Using Standard Benchmarks - This article introduces EvalBench's Hybrid Execution Accuracy evaluation mode, designed to solve the challenge of assessing BigQuery Text-to-SQL models using SQLite-based standard benchmarks. It overcomes dialect mismatch by executing generated BigQuery queries on BigQuery and original SQLite reference queries on a local fallback, then comparing normalized results.
Slides, Videos, Audio
GCP Bytes Podcast - #45 In this episode we discuss; GCVE Outage, OCR Token Reduction, Amazon Leo, Claud Team, China Rocket, MS July Patch, Community News, Phillip Larson, GCVE using CMEK, Google Fine, UNSW MS Storage Cuts, MS Xbox Cuts, Bendigo Bank AI Use Cases, Telstra Outage, Garter Magic Quadrant, New Google Models, Anthropic Google $200 Billion Deal, MCP For Gemini Enterprise, 9router, gpt5.6.
Releases
Apigee Hybrid - Various security and CVE fixes are included in this release. v1.15.6 On July 15, 2026 we released an updated version of the Apigee hybrid software, v1.15.6. For information on upgrading, see Upgrading Apigee hybrid to version v1.15.6. For information on new installations, see The big picture. Note: This is a patch release: The container images used in patch releases are integrated with the Apigee hybrid Helm charts. Upgrading to a patch via the Helm chart automatically updates the images. No manual image changes are typically needed. For information on container image support in Apigee hybrid releases, see Apigee release process.
Apigee UI - Apigee UI Fixed an issue where editing a legacy API Product with a selected API Proxy could cause the Apigee UI to become unresponsive.
Batch - Instance flexibility is available in Preview. Instance flexibility lets you allow a job to run on multiple machine types that you specify and can optionally rank. Use instance flexibility to improve obtainability —the probability that resources are available to run your job. For example, by allowing multiple machine types, you can reduce the probability of resource availability errors and try to obtain Spot VMs that are less likely to be preempted. To get started, see Improve resource obtainability for jobs.
BigQuery - You can now use the ALTER SEARCH INDEX DDL statement to update the configuration of a search index. This feature is in Preview. Incremental data transfers for the BigQuery Data Transfer Service for Salesforce are now generally available (GA). The BigQuery Overview page is a hub for discovering tutorials, features, and resources to help you get the most out of BigQuery. It provides guided paths for users of all skill levels. This feature is now generally available (GA). Project caps (also known as scheduling policies) let you limit maximum slots and concurrency per project within a BigQuery reservation. This feature is in Preview. You can use the BigQuery Migration Service MCP server to perform SQL translation tasks, including translating SQL queries into GoogleSQL syntax, generating DDL statements from SQL input queries, and getting explanations of SQL translations. This feature is Generally Available. A Missing Authorization vulnerability was discovered in repositories in BigQuery, Dataform, and Colab Enterprise. An authenticated attacker could potentially escalate permissions and perform cross-tenant repository takeover. For more information, see the GCP-2026-047 security bulletin. Table partitioning, multi-statement transactions, and advanced runtime are now generally available (GA) for Apache Iceberg managed tables. Conversational analytics now supports the AI.AGG function. This function is in Preview. As part of Gemini in BigQuery, conversational analytics now supports HIPAA compliance. BigQuery supports data governance tags, which let you enforce column-level security and data masking. Data governance tags are a type of Resource Manager tag that you can attach to sensitive columns and use in BigQuery data policies to grant conditional access to your users. This feature is in Preview.
Bigtable - AI agents can use the list_hot_tablets Model Context Protocol (MCP) tool to programmatically query Bigtable cluster health to isolate resource-intensive tablets (hot tablets) and detect overutilized node CPUs. This feature is generally available (GA).
Chronicle - Advanced Filtering in Dashboards This feature is in Public Preview. Advanced Filtering in dashboards is now available in Google SecOps. This feature enhances dashboard capabilities by enabling security analysts to use query variables, also known as tokens, to inject dynamic values, complex regular expressions, or boolean logic directly into YARA-L queries at runtime. Key aspects of Advanced Filtering include: Token Variable Definition: When creating an advanced filter, you can define a Token Variable. Token variable names must consist only of alphanumeric characters and underscores ( ^[a-zA-Z0-9_]+$ ) and must be unique within the dashboard. Filter Value Generation: Token values can be generated dynamically from YARA-L query results or entered manually as a static list. Customizable Wrappers: You can specify prefixes and suffixes to wrap token values, enabling specific logic such as regular expressions. Multi-Select Support: The ability to select multiple options for a token can be enabled, with a configurable delimiter (for example, | ) for combining values in queries. For more information, see Dashboard filters.
Chronicle SOAR - Release 6.3.93 is now available for all regions. Release 6.3.94 is being rolled out to the first phase of regions as listed here. This release contains internal and customer bug fixes.
Chronicle Security Operations - SOAR migration to Google Cloud validation status You can now check if the SOAR migration was successful by going to the SOAR Settings > License Management page. After successful completion of Stage 1, it will say Google.com after the system version number. After successful completion of Stage 2 of SOAR permissions to IAM roles, it will say both Google.com and CloudIAM Enabled after the system version number. For more information on the migration, see the SOAR migration guide [Spotlight Feature] Advanced Filtering in Dashboards Advanced Filtering in dashboards is now available in Preview. This feature enhances dashboard capabilities by enabling security analysts to use query variables, also known as tokens, to inject dynamic values, complex regular expressions, or boolean logic directly into YARA-L queries at runtime. Key aspects of Advanced Filtering include: Token Variable Definition: When creating an advanced filter, you can define a Token Variable. Token variable names must consist only of alphanumeric characters and underscores ( ^[a-zA-Z0-9_]+$ ) and must be unique within the dashboard. Filter Value Generation: Token values can be generated dynamically from YARA-L query results or entered manually as a static list. Customizable Wrappers: You can specify prefixes and suffixes to wrap token values, enabling specific logic such as regular expressions. Multi-Select Support: The ability to select multiple options for a token can be enabled, with a configurable delimiter (for example, | ) for combining values in queries. For more information, see Dashboard filters.
Cloud Composer - In Managed Airflow (Gen 3) builds with Airflow 2.11.1 starting from composer-3-airflow-2.11.1-build.7, the Airflow web server requires at least 3 GB of memory (the default amount of memory for a Small environment preset is 4 GB). If the Airflow web server has less than 3 GB of memory, it might experience intermittent out-of-memory (OOM) issues. To resolve these issues, increase the web server memory to at least 3 GB.
Cloud Run - Cloud Run support for importing public container images from GitHub Container Registry is in General Availability.
Cloud SQL MySQL - You can now create and query parameterized secure views in Cloud SQL for MySQL. Parameterized secure views let you create MySQL views in your MySQL database that reference session variables for managing data access. By using a parameterized secure view, you can create a single view that is flexible enough to accommodate multiple queries across a predefined range of data without being required to create multiple static view definitions for different users. To use parameterized secure views, you're required to have Cloud SQL for MySQL 8.0.43 or later and maintenance version R20260320.00_20 or later installed on your instance. For more information, see Parameterized secure views in Cloud SQL. This feature is in Preview.
Cloud Tasks - Cloud Tasks is available in the following locations: me-central1 (Doha, Qatar) me-central2 (Dammam, Saudi Arabia)
Colab - A Missing Authorization vulnerability was discovered in repositories in BigQuery, Dataform, and Colab Enterprise. An authenticated attacker could potentially escalate permissions and perform cross-tenant repository takeover. For more information, see the GCP-2026-047 security bulletin.
Compute Engine - Preview: The network-optimized C4N machine series offers machine types with 375 GiB to 12,000 GiB of attached Titanium SSD. To use C4N machine types with attached Local SSD disks, you can Request preview access. For more information, see C4N machine series. Changed: The following operations on the boot disk of a Compute Engine instance that has a service account attached no longer require the iam.serviceAccounts.actAs permission. In the following list, the boot disk of such an instance is referred to as the source disk. Creating a standard or archive snapshot of the source disk. Cloning the source disk. Creating a machine image of the instance. Creating a custom image of the source disk. Starting asynchronous replication of the source disk to another region. Creating a new disk when you create an instance, if the new disk is created from an instant snapshot of the source disk.
Data Fusion - Cloud Data Fusion version 6.11.1.4 is generally available ( GA ). Fixed in Cloud Data Fusion 6.11.1.4: Fixed a race condition where successfully completed Dataproc jobs were incorrectly marked as failed on the Dataproc console due to premature program cancellation ( CDAP-21219 ). Fixed an issue where the Pipeline list page would hang due to a race condition in an internal service ( CDAP-21241 ). Fixed a security vulnerability in log downloads by enforcing strict validation on requested log paths and query parameters to prevent unauthorized access ( CDAP-21260 ). Changes in Cloud Data Fusion 6.11.1.4: Increased the default Wrangler browsing limit to 2,000 items ( CDAP-21259 ).
Dataform - A Missing Authorization vulnerability was discovered in repositories in BigQuery, Dataform, and Colab Enterprise. An authenticated attacker could potentially escalate permissions and perform cross-tenant repository takeover. For more information, see the GCP-2026-047 Dataform security bulletin.
Dataplex - Data lineage control at the organization, folder, or project level is generally available for BigQuery, Managed Service for Apache Spark, and Managed Service for Apache Airflow. For more information, see About data lineage ingestion control and Configure data lineage ingestion for a service.
Dataproc - Managed Service for Apache Spark (formerly Dataproc on Compute Engine): The 2.1, 2.2 and 2.3 cluster image versions now support Confidential Compute for the g4-standard-48 GPU machine type.
Dataproc Serverless - Managed Service for Apache Spark (formerly Google Cloud Serverless for Apache Spark): The 3.0 runtime now uses fewer executors, as follows: 0 min executors for spark.dynamicAllocation.minExecutors property 1 min executor for spark.executor.instances and spark.dynamicAllocation.initialExecutors properties All runtimes now configure spark.scheduler.listenerbus.exitTimeout to 30 seconds.
Datastream - You can now replicate change data from the following application sources with Datastream: ServiceNow Salesforce Marketing Cloud Microsoft Dataverse. This feature is in Preview.
Document AI - Custom extractor model pretrained-foundation-model-v3.5-2026-05-26 powered by Gemini 3.5 Flash LLM is available in Preview. This processor version has ML processing capabilities in the US and EU. For more information about available models, see the custom extractor page.
GKE new features - Rollout sequencing with custom stages is now generally available. This version of rollout sequencing, which is recommended if you're configuring an environment for the first time, offers a robust set of features including the following: Define custom stages: Sequence the rollout of a new GKE version across environments. With custom stages, you can, for example, deploy a new version on a small subset of production clusters before a wider rollout. Choose the scope of rollouts: Decide what types of versions that GKE rolls out in the sequence. For example, you can have GKE roll out patch versions, but not minor versions, across a sequence. Initiate a rollout: Create a rollout of a specific version, if you want GKE to roll out that version across your sequence. Manage a rollout: Pause, resume, cancel rollouts, or complete rollout stages as needed. For more information, see About rollout sequencing with custom stages. In GKE version 1.36.0-gke.3204000 and later, when you manually or automatically create a GKE node pool that consumes capacity reservations, you can stop GKE from falling back to on-demand capacity if reserved capacity isn't available. To consume any matching reservation without fallback, specify the any-reservation-then-fail reservation affinity in your node pool creation request, Pod specification, or ComputeClass specification. In ComputeClasses, this reservation affinity lets GKE move on to the next priority rule instead of creating on-demand compute resources. For more information, see Consuming reserved zonal resources. GKE version 1.33 now supports the N4D machine series for node pool auto-creation and Autopilot clusters in the following patch versions and later: Node pool auto-creation: 1.33.12-gke.1208000 and later Autopilot: 1.33.13-gke.1079000 and later In GKE version 1.36.0-gke.4447000 and later, the VerticalPodAutoscaler supports CPU startup boost, which temporarily increases CPU requests during application startup to improve startup latency and cost efficiency. This feature is available in Preview.
KMS - Cloud KMS supports the following post-quantum computing (PQC) signing algorithms in General Availability: PQ_SIGN_HASH_SLH_DSA_SHA2_128S_SHA256 PQ_SIGN_ML_DSA_44 PQ_SIGN_ML_DSA_44_EXTERNAL_MU PQ_SIGN_ML_DSA_65 PQ_SIGN_ML_DSA_65_EXTERNAL_MU PQ_SIGN_ML_DSA_87 PQ_SIGN_ML_DSA_87_EXTERNAL_MU PQ_SIGN_SLH_DSA_SHA2_128S For more information about supported algorithms, see PQC signing algorithms. For more information about PQC signing, see Post-quantum cryptography (PQC) digital signature.
Looker - The latest versions in the Looker (Google Cloud core) release channels are beginning deployment as follows: Latest version in the Rapid channel: Looker 26.12 Latest version in the Regular channel: Looker 26.10 Latest version in the No Channel channel: Looker 26.12 Starting in Looker 26.8, Looker supports Java OpenJDK version 21. Looker-hosted instances have been upgraded to OpenJDK 21. Customer-hosted instances should upgrade to OpenJDK 21. If you run Looker directly using the java -jar command (instead of using the startup script), you must include these three specific settings: --add-opens=java.base/sun.nio.ch=ALL-UNNAMED --add-opens=java.base/java.io=ALL-UNNAMED --add-opens=java.base/java.nio=ALL-UNNAMED Looker recommends that you transition to new Java updates as they are released. Other versions of Java, Oracle JDK, and OpenJDK are not supported at this time.
Security Command Center - You can integrate Security Command Center with Jira to review findings in your Jira project. For more information, see Integrate Jira with Security Command Center.
Sensitive Data Protection - If you leave InfoType.version unset or set it to stable when setting the MEDICAL_ID infoType in your InspectConfig, Sensitive Data Protection includes MEDICAL_RECORD_NUMBER findings as type MEDICAL_ID in the scan results. You can still use the old functionality by setting InfoType.version to legacy for the next 90 days. The CRIME_STATUS infoType detector is available in all regions. For more information about all built-in infoTypes, see the InfoType detector reference.
Vertex AI Workbench - Agent Platform Workbench image release The following Agent Platform Workbench instances image releases are available: 20260712-2130-rc0 ( workbench-instances-2603 - Debian 12) Installed latest packages from upstream dependencies. Fixed broken cupy installation. M144 ( workbench-instances - Debian 11) Installed latest packages from upstream dependencies. Fixed a race condition that could cause JupyterLab to be unreachable (HTTP 524) on GPU instances. Secure Boot is compatible with GPUs You can now enable Secure Boot on Agent Platform Workbench instances that have a GPU attached. Secure Boot with GPUs is supported on the workbench-instances-2603 VM image and the workbench-container-2606 custom container, which include a Secure Boot-signed NVIDIA GPU driver so the driver loads under Secure Boot. For more information, see Create an instance.