Google Cloud Rolls Out Extensive Updates to AI, Networking, and Security Infrastructure

src-b36332b9

Google Cloud has announced a broad series of updates spanning its AI, data analytics, and infrastructure portfolios, marking a significant push toward enhanced streaming capabilities and security hardening. The updates, detailed in the September 2026 release notes, emphasize improved support for large language models (LLMs) and expanded cross-cloud connectivity options.

### Advancements in LLM and AI Infrastructure
A primary focus of this release is the optimization of LLM workflows. Google’s API Gateway now supports streaming requests and responses, allowing developers to move away from traditional buffering. By enabling the `–enable-streaming` flag, users can deliver incremental responses via HTTP/2, Server-Sent Events (SSE), WebSockets, or gRPC bidirectional streaming, which is specifically designed to facilitate token-by-token generation from LLMs.

In the realm of model evolution, Gemini 3.8 Flash has become the default model for AlphaEvolve experiments, replacing the 3.5 version. Furthermore, the Agent Platform has introduced granular access controls, allowing administrators to assign resource-level IAM permissions for Gemini Enterprise apps and data stores. This decoupling of permissions ensures that principals can interact only with authorized assets, rather than requiring access to an entire Google Cloud project.

### Security and Governance Hardening
Security continues to be a central pillar of Google’s platform strategy. New features in the Agent Platform include custom denial messages for semantic governance policies. When a request is blocked, users can now receive a fixed explanation—up to 1,000 characters—rather than a generic error. Additionally, semantic governance policies now support VPC Service Controls in Preview, providing a stronger perimeter against potential data exfiltration during agent tool execution.

Google has also addressed critical vulnerabilities across various services. Patches were released for the Workbench custom container images to remediate high-severity CVEs, and several legacy vulnerabilities in Application Integration, such as those related to “Confused Deputy” and deserialization of untrusted data, have been resolved. In a move to improve database security, Google Cloud modified the `Cloud SQL Viewer` and basic reader roles to remove the `cloudsql.instances.export` permission, requiring users to migrate to the `Cloud SQL Editor` role to retain export functionality.

### Networking and Infrastructure Scalability
Networking updates include the General Availability (GA) of Network Connectivity Center (NCC) support for Partner Cross-Cloud Interconnect for Amazon Web Services (AWS). This provides a more robust path for hybrid and multi-cloud architectures. On the compute side, Google has increased memory capacity for its memory-optimized instances. The new X5 series introduces massive 48TB configurations, exceeding the previous 32TB limit of the X4 series, which is a major boon for large-scale SAP HANA deployments.

For containerized environments, GKE is seeing a significant boost in pod density. Standard clusters now support up to 512 maximum pods per node, doubling the previous 256-pod capacity. Additionally, Google has introduced GKE ambient networking in Preview, which offers a sidecarless deployment model for service meshes. By offloading proxy functionality to node-level components in GKE Dataplane V2, Google aims to reduce resource overhead and simplify mesh lifecycle management.

### Operational Changes and Deprecations
As the ecosystem evolves, Google is phasing out older tools. Notably, the legacy Monitoring and Logging agents have officially reached their end of support, with the company strongly advising customers to transition to modern, supported alternatives. Similarly, the company has set a firm deadline of March 1, 2028, for migrating away from the in-cluster Istiod control plane in favor of managed Cloud Service Mesh deployments. These moves reflect Google’s broader strategy of centralizing control and streamlining maintenance for enterprise users.

Source: Microsoft Azure Updates