Back to blog

Google Beyond Zero: AI-agent security moves to action-level control

Article created on 29 July 2026 · Publication analyzed: 27 July 2026 · Source: Google Security Blog

Google's official 27 July 2026 post presents Beyond Zero as an evolution of zero trust for the age of AI agents. The important point for enterprises is not only adding AI to cybersecurity. It is the move toward contextual, resource-level, and action-level authorization across interfaces, APIs, and the Model Context Protocol.

1. What Google actually announced

Google describes Beyond Zero as a security paradigm designed to secure humans and agents at machine speed. The model is built on five principles: resource and action-based security, a blend of static policies and dynamic controls, automatically enriched context, automated in-depth investigation, then verification challenges and containment measures.

The announcement is intentionally methodological: Google says early internal prototypes and deployments improve access-abuse detection and intellectual-property protection, while announcing a series of technical publications to follow. This is not a single product announcement; it is an access-control architecture model.

2. What this changes for Belgian or French companies

For SMEs, the immediate impact is to treat AI agents as constrained operational identities: read-only access when enough, separated write permissions, and explicit approval for risky actions. For mid-market companies and large enterprises, Beyond Zero pushes authorization down to the business action, not only the application.

For public administrations and regulated organizations, the signal is sharper: agents that consult sensitive data, launch workflows, modify records, or call APIs must produce evidence. CIOs therefore need to define permissions, logs, risk thresholds, and suspension mechanisms before scaling agents in production.

3. Underside reading: AI agents, RAG, Odoo, and sovereignty

In a sovereign AI architecture, Beyond Zero is a reminder that an agent is not only a model. It is a full chain: identity, connectors, RAG, access rights, tools, APIs, supervision, and evidence. The issue becomes critical as soon as an agent can read internal documents, write into Odoo, trigger automation, or move from a local environment to a cloud service.

For Odoo Belgium, Odoo France, and Odoo Enterprise, the right control level is action-specific: reading an invoice, creating a draft, changing an order, sending a customer message, or executing an accounting action should not share the same trust regime. The same applies to Apple Enterprise and local workstations: local execution protects some data, but it does not replace permission and audit governance.

4. Operational recommendation

IT, cybersecurity, data, and business teams should map existing or planned agents by authorized action: data accessed, tools called, autonomy level, logging, human approval, and blocking mechanism. This mapping should happen before wide integration of MCP connectors, ERP automations, or RAG over sensitive documents.

Concrete priority: run an "AI agents + action-level authorization" scoping exercise on one critical business workflow, then define read, write, approval, and suspension controls before production deployment.

Scope agent controls

Read official source