Skip to content

Blocks.ai publishes this comparison and sells in this market. Every claim about another product links to a public source.

Gemini Enterprise Agent Platform vs Zenity

Gemini Enterprise Agent Platform

Google Cloud platform to build, deploy, govern, and optimize AI agents

Zenity AI Agent Security & Governance Platform

Security and governance platform for AI agents, aimed at security teams

Short answer

Gemini Enterprise Agent Platform is Google Cloud’s platform to build, deploy, and govern agents; Zenity is a security and governance platform for AI agents.⁠Source 1, Source 2 Agent Platform’s gateway can govern Agent Runtime and Gemini Enterprise app traffic, while Zenity says it catalogs agents widely and blocks inline on Copilot Studio, Microsoft Foundry, and coding agents.⁠Source 3, Source 4, Source 5, Source 6

Where each one sits

Six layers of running AI agents at a company, and what each product’s own public sources say it covers.

These aren’t the same kind of product

Where they overlap
Agent Platform catalogs agents, applies rules to what agents can reach or do, and logs agent activity; Zenity says it does too.⁠Source 3, Source 4, Source 5, Source 7, Source 8
Where they differ
Teams can also build and run agents on Agent Platform.⁠Source 1, Source 3 Zenity says it scans for agents, including in Copilot Studio and Agentforce.⁠Source 4 Building agents isn’t in Zenity’s public docs.
Running both
Zenity says it tracks homegrown agents built on Google Vertex AI, which Agent Platform evolved from, with detection and posture only.⁠Source 1, Source 4, Source 6 Zenity’s page names Vertex AI, not Agent Platform.⁠Source 4
Public sources · checked 2 October 2026
  • Offered
  • Not publicly documented

Gemini Enterprise Agent Platform

  • Build agents: OfferedAgent Studio low-code canvas⁠Source 1
  • Host and run agents: OfferedAgent Runtime⁠Source 3
  • Identity and access: OfferedSPIFFE-based Agent Identity⁠Source 8
  • Registry and governance: OfferedAgent Registry⁠Source 7
  • Traffic between agents, tools, and models: OfferedAgent Gateway⁠Source 3
  • Agents across organizations: OfferedGateway calls to outside agents⁠Source 3

Zenity

  • Build agents: Not publicly documented
  • Host and run agents: Not publicly documented
  • Identity and access: Not publicly documented
  • Registry and governance: OfferedAI Observability agent inventory⁠Source 4
  • Traffic between agents, tools, and models: OfferedTool-call blocking for coding agents⁠Source 9
  • Agents across organizations: Not publicly documented

At a glance

TopicGemini Enterprise Agent PlatformZenity
What it doesA platform to build, deploy, and govern agents: teams can build with Agent Studio or the open-source Agent Development Kit and run agents on Agent Runtime.⁠Source 1, Source 3, Source 10A security and governance platform for agents built elsewhere: Zenity says AI Observability scans for agents in SaaS platforms, custom builds, and on laptops.⁠Source 2, Source 4
Who it’s forDevelopers and technical teams building agents.⁠Source 11Security teams that discover and inventory agents and enforce policies, per Zenity.⁠Source 12
DeploymentGoogle Cloud services, enabled per project.⁠Source 13 Agent Gateway is managed and regional; Agent Runtime and the gateway keep data at rest in a supported location you select.⁠Source 14, Source 15Software as a service; Zenity’s AWS Marketplace listing shows it deployed on AWS.⁠Source 2
Pricing modelBy use: Agent Runtime compute is $0.085 per vCPU-hour, and Agent Gateway egress $0.085 per 15,000 requests.⁠Source 16 Agent Registry is free; skill scanning is billed from January 2027.⁠Source 17Custom pricing on its main AWS Marketplace listing.⁠Source 2 A separate Security Hub Extended listing shows usage prices per resource and per million tokens.⁠Source 18
AvailabilityGoogle announced it on 22 April 2026.⁠Source 19 Agent Registry and Agent Gateway have been generally available since 18 June 2026.⁠Source 20Zenity announced Azure Marketplace availability in March 2025 and AWS in January 2026.⁠Source 21, Source 22 Microsoft says Azure Marketplace is now part of Microsoft Marketplace.⁠Source 23

What each one is

Gemini Enterprise Agent Platform

Gemini Enterprise Agent Platform, an evolution of Vertex AI, is Google Cloud’s platform to build, deploy, govern, and optimize agents.⁠Source 1 Agent Registry catalogs agents and MCP servers, Agent Identity can give agents on supported runtimes an identity, and Agent Gateway checks agent traffic against policy.⁠Source 3, Source 7, Source 8

Zenity AI Agent Security & Governance Platform

Zenity is a SaaS security and governance platform for AI agents, which it aims at security teams.⁠Source 2, Source 12 Zenity describes three layers: Surface finds agents and their exposure, Enforce governs their actions in real time, and Protect detects and responds to runtime threats.⁠Source 12

The differences that matter

  1. How agents get into the inventory

    Gemini Enterprise Agent Platform

    Agents on supported Google Cloud runtimes can be registered automatically within one project; others can be registered manually with the API, CLI, or Terraform.⁠Source 24, Source 25

    Zenity

    Zenity says AI Observability scans the environment and catalogs agents with their configuration, permissions, and tool access, flagging ones outside sanctioned deployment channels.⁠Source 4

    Agent Registry can also be searched, by keyword or semantically, for agents, their skills, and MCP servers.⁠Source 26 Whether employees or agents can search Zenity’s inventory isn’t in Zenity’s public docs.

  2. Where rules are enforced

    Gemini Enterprise Agent Platform

    At Agent Gateway: outbound calls are blocked by default unless an IAM policy grants them, and attached Model Armor filters scan prompts and tool responses.⁠Source 3

    Zenity

    Runtime Boundaries can check agent actions in real time; Zenity says it can block them on Copilot Studio, Microsoft Foundry, and coding agents.⁠Source 5, Source 6

    Inbound, Agent Gateway can control which clients reach Agent Runtime agents.⁠Source 3 Zenity says its Custom Agents integration supports inline enforcement through an Evaluate API.⁠Source 27

  3. Which agents each one covers

    Gemini Enterprise Agent Platform

    Agent Gateway can govern traffic for agents on Agent Runtime and in the Gemini Enterprise app; agents hosted elsewhere can be registered manually.⁠Source 3, Source 28

    Zenity

    Zenity says it tracks agents in Copilot Studio, Agentforce, and homegrown cloud builds, and blocks inline on Copilot Studio, Microsoft Foundry, and coding agents.⁠Source 4, Source 6

For security teams

What a security review asks, answered from each vendor’s public documentation.

TopicGemini Enterprise Agent PlatformZenity
Network exposureAgent Gateway manages mTLS; its ingress mode supports only Agent Runtime agents, and egress needs an IAM access policy.⁠Source 3Not in Zenity’s public docs; its product docs require a login (checked 2 October 2026)⁠Source 29
IdentityAgents on supported runtimes can have a SPIFFE-based identity, generally available; the Agent Identity API is in preview.⁠Source 8, Source 20Zenity says Boundaries rules can use Okta attributes like role and status.⁠Source 5 Issuing agent identities isn’t in Zenity’s public docs.
Access changes and revocationDeny rules override allow rules.⁠Source 30 Deleting an agent leaves its IAM bindings as inactive grants, to be removed by hand.⁠Source 8Zenity says its kill switch immediately disables an agent’s tool and data access.⁠Source 5
Audit trailRegistry admin changes are audit-logged; other calls only if Data Access logs are on.⁠Source 31, Source 32 Gateway logs record access requests.⁠Source 33Zenity says it logs agent messages and tool calls, and can stream audit log events to Splunk or Microsoft Sentinel.⁠Source 4, Source 27
ComplianceIn scope for ISO 27001, SOC 1, 2, and 3, and PCI DSS.⁠Source 34 Listed in Google Cloud’s HIPAA BAA.⁠Source 35Zenity says the company holds SOC 2 Type II and is ISO 27001 compliant; FedRAMP “In Process” announced March 2026.⁠Source 36, Source 37

Full comparison

18 criteria in five groups. Every cell links to its source, or says no public source answers it.

Gemini Enterprise Agent Platform and Zenity compared on 18 criteria
Gemini Enterprise Agent PlatformZenity
What it is
What it is and who it’s forGoogle Cloud platform to build, deploy, govern, and optimize AI agents, described as an evolution of Vertex AI, for developers and technical teams.⁠Source 1, Source 11Security and governance platform for AI agents across SaaS, homegrown cloud platforms, and end-user devices, which Zenity aims at security teams.⁠Source 2, Source 12
MaturityGoogle announced it on 22 April 2026.⁠Source 19 Registry and Gateway GA 18 June 2026; access policies GA 31 August 2026.⁠Source 20 Agent Identity is GA; its API is in preview.⁠Source 20Zenity announced AWS Marketplace availability in January 2026, Foundry runtime GA in March 2026, and GitHub Copilot and Codex coverage GA in August 2026.⁠Source 22, Source 27, Source 38
Control
Agent registry and discoveryAgent Registry: a per-project catalog of agents, MCP servers, and tools.⁠Source 7, Source 13 Agents on supported runtimes can be registered automatically, others manually.⁠Source 24, Source 25Zenity says AI Observability scans for agents in SaaS platforms, custom builds, and on laptops, listing each with its permissions and tool access.⁠Source 4
Identity and access controlAgents on supported runtimes can get a SPIFFE-based identity.⁠Source 8 Access policies link it to approved tools; other outbound gateway calls are blocked by default.⁠Source 3Zenity says Boundaries rules can reference Okta attributes such as active status, role, and department.⁠Source 5 Issuing agent identities isn’t in Zenity’s public docs.
Ownership, policy, and revocationAllow and deny access policies (deny overrides allow), in enforce or dry-run mode, plus Model Armor filters.⁠Source 3, Source 30 An agent owner field: not publicly documented.Zenity says it blocks actions inline on Copilot Studio, Microsoft Foundry, and coding agents.⁠Source 6 It says ownership is surfaced per discovered agent.⁠Source 39
Audit log and observabilityRegistry admin changes are audit-logged; reads only if Data Access logs are on.⁠Source 31, Source 32 Gateway traffic shows in Cloud Logging.⁠Source 3 Traces need agents’ OpenTelemetry data.⁠Source 40Zenity says it logs messages, tool calls, and handoffs, and can send audit log events to Splunk or Sentinel and findings to AWS Security Hub.⁠Source 4, Source 27, Source 41
Connection
How agents connectAgent Gateway can govern traffic in and out of Runtime agents and out of the Gemini Enterprise app.⁠Source 3 Outside agents can be registered by endpoint or agent card.⁠Source 28Zenity says OpenTelemetry-emitting agents can connect, with an Evaluate API for inline enforcement.⁠Source 27 Network requirements aren’t in Zenity’s public docs.
Agents across organizationsAgent Runtime agents can call outside agents and MCP servers.⁠Source 3 Partners sharing agents under access they control: not publicly documented.Not in Zenity’s public docs; its product docs require a login (checked 2 October 2026)⁠Source 29
Protocol supportAgent Registry catalogs MCP servers and A2A agents; Agent Gateway carries MCP and A2A traffic.⁠Source 3, Source 25, Source 42 A2A agents on Agent Runtime are in preview.⁠Source 43Zenity says custom agents use OpenTelemetry and agent hooks can block risky coding-agent tool calls.⁠Source 9, Source 27 Whether Zenity supports A2A isn’t publicly documented.
Frameworks, models, and clouds supportedAgent Development Kit or any open-source framework, with Gemini or other Model Garden models.⁠Source 10 Google calls Agent Gateway framework agnostic.⁠Source 3Zenity says it covers agents in Copilot Studio, ChatGPT Enterprise, and Agentforce, homegrown agents on Bedrock or Vertex AI, and coding agents.⁠Source 4, Source 9
Operations
Deployment options and data residencyAgent Gateway is managed and regional; Runtime and gateway data at rest stays in the selected location.⁠Source 14, Source 15 Gateway self-hosting: not publicly documented.Software as a service, deployed on AWS per its AWS Marketplace listing.⁠Source 2 Regions, data residency, and self-hosting aren’t in Zenity’s public docs.
Compliance attestationsGoogle lists Agent Platform in scope for ISO 27001, 27017, and 27018, SOC 1, 2, and 3, and PCI DSS.⁠Source 34 It is in Google Cloud’s HIPAA BAA.⁠Source 35Zenity says the company holds SOC 2 Type II and is ISO 27001 compliant.⁠Source 36 It announced FedRAMP “In Process” status in March 2026, with authorization pending.⁠Source 37
Support and SLAGoogle Cloud support packages, with options such as 24/7 coverage.⁠Source 44 An uptime SLA naming Agent Registry, Gateway, Identity, or Runtime: not publicly documented.Zenity’s subscription terms commit to commercially reasonable efforts toward 99.9% monthly uptime.⁠Source 45 Support requests go through Zendesk during business hours.⁠Source 45
Time and effort to get runningA Google Cloud project with the Agent Registry API enabled, plus the Identity-Aware Proxy API for gateway policy.⁠Source 13 Google recommends dry-run mode in staging.⁠Source 30Zenity says its Cursor plugin installs in Cursor desktop, and Security Hub activates from its console.⁠Source 41, Source 46 Prerequisites aren’t in Zenity’s public docs.
Pricing model and public pricesAgent Registry is free; skill scanning is billed from January 2027.⁠Source 17 Gateway egress: $0.085 per 15,000 requests; runtime: $0.085 a vCPU-hour.⁠Source 16 Monthly free tier.⁠Source 16Main AWS listing: custom pricing.⁠Source 2 Security Hub Extended listing: $130 per resource a month (Observability), $16 per million tokens a month (Runtime Protection).⁠Source 18
Building
Agent building toolsAgent Studio (low-code canvas), the open-source Agent Development Kit, and Agent Garden prebuilt agents and templates.⁠Source 1, Source 10 A Managed Agents API is in preview.⁠Source 1Not in Zenity’s public docs; its product docs require a login (checked 2 October 2026)⁠Source 29
Model accessGoogle says Model Garden offers more than 200 models, including Gemini, third-party models such as Anthropic’s Claude, and open-source models.⁠Source 1, Source 19Zenity says AIDR combines deterministic rules with LLM-based detections.⁠Source 47 Its models aren’t in Zenity’s public docs.
Integrations and ecosystemAgents in Agent Registry can be made available to users of the Gemini Enterprise app.⁠Source 14 Google’s own remote MCP servers are registered automatically.⁠Source 42Zenity says it integrates with Microsoft Agent 365 and AWS Security Hub and is on the Cursor Marketplace.⁠Source 41, Source 46, Source 48 It announced a ServiceNow SecOps partnership.⁠Source 49

Which to choose

Choose Gemini Enterprise Agent Platform if

  • You want to build, deploy, and govern agents on one platform, with Agent Studio and the open-source Agent Development Kit.⁠Source 1, Source 10
  • Your agents run on Google Cloud, where agents on supported runtimes, such as Google Kubernetes Engine, can be registered automatically.⁠Source 24, Source 25
  • You want outbound gateway calls blocked unless an IAM policy grants them, with Model Armor filters scanning prompts and tool responses.⁠Source 3
  • You want agents on Agent Runtime, the Gemini Enterprise app, or Cloud Run to be able to get their own SPIFFE-based identity.⁠Source 8

Choose Zenity if

  • You want what Zenity says it offers: one inventory and activity record for agents in Copilot Studio, ChatGPT Enterprise, and Agentforce.⁠Source 4
  • Your security team wants what Zenity says it offers: agents found by scanning, including on laptops or outside sanctioned channels.⁠Source 4
  • You want what Zenity says it offers: real-time checks on agent actions, and a kill switch for tool and data access.⁠Source 5
  • You need the coverage Zenity says it gives coding agents such as Claude Code, Cursor, GitHub Copilot, and ChatGPT Codex.⁠Source 9, Source 27

Questions buyers ask

Is Gemini Enterprise Agent Platform the same as the Gemini Enterprise app?

Agent Platform is Google Cloud’s platform to build, deploy, govern, and optimize agents.⁠Source 1 The Gemini Enterprise app is a separate product: agents in Agent Registry can be associated with it to make them available to its end users.⁠Source 14

How is each one priced?

Agent Registry is free; skill scanning is billed from January 2027.⁠Source 17 Agent Runtime is $0.085 per vCPU-hour; Agent Gateway egress, $0.085 per 15,000 requests.⁠Source 16 Zenity’s AWS Marketplace listing has custom pricing; its Security Hub Extended listing shows usage prices, such as $130 per resource monthly.⁠Source 2, Source 18

Do they support MCP and A2A?

Agent Registry catalogs MCP servers and A2A agents, and Agent Gateway carries MCP and A2A traffic.⁠Source 3, Source 25, Source 42 For coding agents, Zenity says its agent hooks can block or modify a dangerous tool call before it executes.⁠Source 9 Whether Zenity supports A2A isn’t publicly documented.

Can either one find agents running in other vendors’ platforms?

Agent Registry lists agents hosted on external platforms, on premises, or in other Google Cloud projects only through manual registration.⁠Source 25 Zenity says its AI Observability inventories agents inside platforms such as Copilot Studio, ChatGPT Enterprise, and Agentforce, and homegrown agents on Bedrock or Vertex AI.⁠Source 4

How we compare

Read the full method

Every claim on this page links to a public source. Where none answers a question, the page says so.

We re-check every fact at least every 90 days. This page was last checked .

Something wrong or out of date? Tell us and we’ll correct it.

Sources

56 public sources, each with the date we checked it. Every one opens in a new tab.

  1. Source 1: Agent Platform overview Google · checked Back:abcdefghijkl

  2. Source 2: AWS Marketplace: Zenity Zenity · checked Back:abcdefghi

  3. Source 3: Agent Gateway overview Google · checked Back:abcdefghijklmnopqrstu

  4. Source 4: AI Observability | See Every Agent, Know What it Touches | Zenity Zenity · checked Back:abcdefghijklmnop

  5. Source 5: Runtime Boundaries | The Runtime Boundary for Autonomous AI | Zenity Zenity · checked Back:abcdefg

  6. Source 6: Zenity's Coverage of the 2026 OWASP Top 10 for LLM Apps Zenity · checked Back:abcde

  7. Source 7: Agent Registry overview Google · checked Back:abcd

  8. Source 8: Agent Identity overview Google · checked Back:abcdefg

  9. Source 9: Coding and Personal Agents | Zenity Zenity · checked Back:abcde

  10. Source 10: Build with Gemini Enterprise Agent Platform Google · checked Back:abcd

  11. Source 11: Gemini Enterprise Agent Platform (formerly Vertex AI) Google · checked Back:ab

  12. Source 12: Platform | AI Agent Security & Governance Platform | Zenity Zenity · checked Back:abcd

  13. Source 13: Set up Agent Registry Google · checked Back:abc

  14. Source 14: Import A2A agents from Agent Registry Google · checked Back:abcd

  15. Source 15: Supported locations for agents in Agent Platform Google · checked Back:ab

  16. Source 16: Gemini Enterprise Agent Platform pricing Google · checked Back:abcd

  17. Source 17: Agent Registry pricing Google · checked Back:abc

  18. Source 18: AWS Marketplace: Zenity AI Security & Governance Platform for Security Hub Extended Zenity · checked Back:abc

  19. Source 19: Introducing Gemini Enterprise Agent Platform, powering the next wave of agents Google · checked Back:abc

  20. Source 20: Gemini Enterprise Agent Platform release notes Google · checked Back:abcd

  21. Source 21: Zenity Now Available in the Microsoft Azure Marketplace Zenity · checked Back to text

  22. Source 22: Zenity Now Available on AWS Marketplace, Bringing End-to-End Security to Amazon Bedrock AgentCore and Enterprise AI Agents Everywhere Zenity · checked Back:ab

  23. Source 23: Introducing Microsoft Marketplace - Thousands of solutions. Millions of customers. One Marketplace. - The Official Microsoft Blog Zenity · checked Back to text

  24. Source 24: Use automatic registration Google · checked Back:abc

  25. Source 25: Register agents Google · checked Back:abcdef

  26. Source 26: Search for agents, tools, and skills Google · checked Back to text

  27. Source 27: From Triage to Full Coverage: The Shift AI Agent Security Took in August Zenity · checked Back:abcdefg

  28. Source 28: Use manual registration Google · checked Back:ab

  29. Source 29: Zenity Documentation (login) Zenity · checked Back:abc

  30. Source 30: IAM Access policies overview Google · checked Back:abc

  31. Source 31: Agent Registry audit logging Google · checked Back:ab

  32. Source 32: Cloud Audit Logs overview Google · checked Back:ab

  33. Source 33: Monitor traffic through Agent Gateway Google · checked Back to text

  34. Source 34: Google Cloud Platform Services in Scope by Compliance Program Google · checked Back:ab

  35. Source 35: HIPAA compliance on Google Cloud Google · checked Back:ab

  36. Source 36: Zenity Trust Center Zenity · checked Back:ab

  37. Source 37: Zenity Achieves FedRAMP “In Process” Status for AI Agent Security Zenity · checked Back:ab

  38. Source 38: Zenity Announces Availability of Inline Agent Runtime Security for Agents Built on Microsoft Foundry Zenity · checked Back to text

  39. Source 39: AI Security Posture Management (AISPM) | Stop Agent Risk Before Deployment | Zenity Zenity · checked Back to text

  40. Source 40: Observability overview Google · checked Back to text

  41. Source 41: Zenity Selected for AWS Security Hub Extended to Secure Enterprise AI Agents Zenity · checked Back:abc

  42. Source 42: Register MCP servers Google · checked Back:abc

  43. Source 43: Create an Agent2Agent agent Google · checked Back to text

  44. Source 44: Getting help for agents Google · checked Back to text

  45. Source 45: Zenity Subscription Terms and Conditions (EULA linked from Zenity's AWS Marketplace listings) Zenity · checked Back:ab

  46. Source 46: Seeing Every MCP Connection: Zenity Joins the Cursor Marketplace Zenity · checked Back:ab

  47. Source 47: AI Detection and Response (AIDR) | See the Threat, Stop the Action | Zenity Zenity · checked Back to text

  48. Source 48: Zenity Now Integrates with Microsoft Agent 365 Zenity · checked Back to text

  49. Source 49: Zenity Announces Partnership with ServiceNow to Operationalize AI Agent Risk Reduction in SecOps Zenity · checked Back to text

  50. Source 50: Why Blocks? Blocks.ai · checked Back to text

  51. Source 51: What is Blocks? Blocks.ai · checked Back to text

  52. Source 52: Your company's private network Blocks.ai · checked Back to text

  53. Source 53: Network requirements Blocks.ai · checked Back to text

  54. Source 54: Solutions: Agent sprawl Blocks.ai · checked Back to text

  55. Source 55: Solutions: Partner networks Blocks.ai · checked Back to text

  56. Source 56: Pricing Blocks.ai · checked Back to text