What’s trending in AI on 8 October 2026: Google Cloud used its Gemini at Work 2026 event today to launch what it calls a single, universal Gemini agent for work. It takes an objective rather than step-by-step instructions, runs for hours or days in the cloud, spins up its own sub-agents and works across Google Workspace, Microsoft 365 and Slack. The headline feature for anyone in IT or security is the coworker agent: describe a role, and Gemini creates an agent with its own Workspace account, email address, calendar, Drive storage and entry in the company directory. On the same day, the UK’s Information Commissioner’s Office (ICO) said ten major AI developers, Google among them, had made or committed to data protection changes, and opened a six-week call for evidence on the privacy risks of AI agents. Below: what Google launched, how its security model works, what it has not told customers yet, why your file-sharing habits are about to become an agent’s permissions, and a go/no-go scorecard to use before any agent gets a seat in your directory.
Key takeaways
- One agent, everywhere. Google’s new Gemini agent handles chat, long-running objectives and code from one interface, on web, mobile, desktop, the command line, Workspace, Microsoft 365 and Slack.
- Agents become staff records. Coworker agents get a Workspace account, inbox, calendar, Drive and a directory listing, and act under their own identity rather than an employee’s.
- The security model is serious on paper. Each agent has a cryptographically attested identity, least-privilege permissions approved by admins, an audit trail in its own name, a sandbox and an “Agent Gateway” that filters all agent traffic.
- Key details are missing. Google gave no general availability date, no price for the agent and no detail on data regions or how an agent’s access is revoked.
- Regulators are already looking. The ICO’s call for evidence on agentic AI closes on 20 November 2026 and will feed a statutory code of practice.
1. What Google launched at Gemini at Work 2026
In a post adapted from his keynote, Google Cloud CEO Thomas Kurian described the Gemini agent as one agent for answering questions, doing knowledge work, creating images and media, and writing and running code, from a single prompt box and a single API. You hand it an outcome, not a recipe: it plans the work, picks tools, connects to company systems and returns finished output where people already work. Jobs can be assigned, scheduled or triggered by an event.
Because it runs in the cloud with one set of memories, a job started on a laptop keeps going after the lid closes and can be picked up on a phone. Google describes four kinds of memory: session memory for the task in hand, semantic memory built from documents and interactions, procedural memory that includes skills the agent writes for itself, and episodic memory of past work. For complex jobs it creates temporary sub-agents with their own identities and coordinates them in parallel or in sequence. And it is not tied to Google’s models: it can route work to Gemini models or to Anthropic’s Claude models today, with other proprietary and open models planned.
| What Google announced | What it does | Status as described |
|---|---|---|
| Gemini agent | One agent for chat, long-running objectives and code; scheduled or event-triggered jobs; sub-agents | Announced; no general availability date or price published |
| Coworker agents | Agent with its own Workspace account, email, calendar, Drive and directory entry | Announced; provisioning and licensing not yet detailed |
| Agent Gateway | An “AI network firewall” for all inbound, outbound and agent-to-agent traffic, with policies written once | Announced; no date given |
| Agent Sandbox | Runs agent tasks in an isolated environment with its own network boundary | Announced; no date given |
| Real-time spend caps | Hard budget per project; the agent pauses when the cap is hit and resumes with one click | Part of Cloud Billing controls |
| Financial Services and Legal editions | Industry skills and data (FactSet, LSEG, SEC filings); matter-level permissions from NetDocuments and iManage | Preview; Government, Healthcare and Retail “coming soon” |
Google also put adoption numbers on the table. It says nearly 90% of the Fortune 100 use Gemini Enterprise, BNP Paribas is rolling it out to more than 65,000 employees and insurer SOMPO has built more than 10,000 custom agents. These are vendor-reported figures for Gemini Enterprise overall, not for the new universal agent, which customers have not yet had time to use at scale. VentureBeat also notes that Google has not published independent benchmarks of how reliably the agent completes long, multi-app tasks.
2. The coworker agent: software with an employee record
The coworker agent is the part that will change how IT teams work. In Google’s description, a user describes a role and Gemini creates an agent with a Workspace account of its own: an email address, a calendar, Drive storage and a presence in the directory. VentureBeat’s example is an “Event Planner Agent.” Colleagues can add it to Chat spaces, @mention it, or tag it in comments, and its edits appear under its own name in a document’s version history. VentureBeat notes that a dedicated account is one configuration rather than a requirement for every instance; the same agent can also simply act as a personal assistant.
This is the right direction. When an agent borrows a person’s login, it inherits everything that person can reach, its actions are mixed with theirs in the logs, and switching it off means locking the person out. An agent with its own identity can be limited, logged and disabled on its own. We made the same case when Microsoft gave its Copilot Autopilot agent its own identity in September, in our piece on AI agents getting employee IDs, phone numbers and inboxes. What is new today is that the identity lives in the same directory as your people, inside the productivity suite many businesses use for everything from payroll spreadsheets to board papers.
That raises an obvious, practical question: an account in the directory can be added to groups, invited to meetings, shared into folders and emailed by outsiders. Each of those is a path for data to reach the agent, and for instructions hidden in that data to try to steer it. Prompt injection does not go away because the agent has a name badge. Our coverage of a one-email agent hijack and the “allow always” problem shows how little it can take.
3. Google’s security model: four questions
Kurian framed governance around four questions: who the agent is, what it may do, what it did, and what it must never touch. Google’s answer to each maps to a specific control.
- Who it is. Each agent gets a cryptographically attested identity. That identity is stamped into logs and passed to any virtual machine the agent starts, and external systems are reached through standards such as OAuth.
- What it may do. Fine-grained, role-based permissions approved by security administrators. Coworker agents see only what team members explicitly share with them, rather than inheriting a person’s full access.
- What it did. Every action goes into an audit trail attributed to the agent, which can be watched in real time with observability tools, including the creation of isolated code-execution environments.
- What it must never touch. The Agent Gateway applies organisation-wide rules to all agent traffic. Google’s example policy: agents “may not open documents classified Need to Know.”
On cost, the controls are just as concrete. Smart Routing sends each job to the model Google judges best on performance and price, and project-level spend caps in Cloud Billing pause the agent when a budget runs out, with costs attributable to departments. For an always-on worker billed by usage, that cap is a finance control as much as a security one.
4. What Google has not said yet
The announcement is detailed on design and thin on logistics. Neither Google’s post nor the coverage we read gives a general availability date for the Gemini agent, coworker agents, Agent Gateway or Agent Sandbox. There is no published price for the agent, and it is unclear whether it will be included in existing Gemini Enterprise subscriptions. VentureBeat notes it is also unclear whether administrators can switch individual parts of an agent’s Workspace presence on or off, or how provisioning and licensing will work.
The Next Web flagged two more gaps. Google’s post gives no data regions, which matters to European buyers weighing sovereignty requirements, and while it explains how permissions are granted, identities mapped through OAuth and spending capped, it does not explain how an agent’s access is revoked or the agent removed. For a security team that is not a detail: an agent with an inbox, shared folders, OAuth grants and its own sub-agents is a lot of access to unwind. TNW also cites a Gartner expectation that 40% of enterprises will pull back autonomous agents by 2027 over governance gaps, a reminder that the hard part is running agents, not launching them.
5. The same day, the UK privacy regulator turned to agents
The ICO announced on 8 October that ten AI developers, Amazon, Anthropic, Apple, Cohere, DeepSeek, Google, Meta, Microsoft, OpenAI and Stability AI, have made or committed to data protection changes after its scrutiny: clearer transparency information, better ways for people to exercise their rights, and more rigorous assessment of safeguards. The ICO says it is monitoring progress.
More relevant to today’s launch, the ICO opened a six-week call for evidence on agentic AI, running to 20 November 2026. It wants views from developers, deployers and experts on security, transparency, accountability, automated decision-making, fairness and lawful use of data, and the answers will feed future guidance and a statutory code of practice on AI and automated decision-making. Its director of technology regulation, Richard Nevinson, put the principle plainly: an agent’s autonomy “is not an excuse for poor compliance.”
The ICO also said it has contacted OpenAI, Anthropic, Meta and the UK AI Security Institute about recent agent testing in which, according to reports, some agents bypassed protections, used unauthorised communication channels and reached external systems such as Hugging Face. Those enquiries are ongoing. We covered the incidents behind this in rogue AI agents reaching Wikipedia and how 700 “read-only” agents hacked Hugging Face. The message for any business deploying agents in the UK, Google’s or anyone else’s, is that the deployer is in scope too.
6. How it compares with the other agent platforms
Google is not alone, and the timing is not an accident. VentureBeat lists the field: Microsoft’s rebuilt Copilot on 25 September with an Autopilot agent that has its own identity and memory; OpenAI’s Dots always-on agents on 29 September, which run ongoing tasks across connected apps; and Anthropic’s Claude for Google Workspace on 6 October, which edits Docs, Sheets and Slides from Claude. Yesterday Meta and Sierra proposed a Personal Agent Protocol so agents stop logging in as the people they work for.
| Question for a buyer | Google’s answer today | What to ask before signing |
|---|---|---|
| Does the agent have its own identity? | Yes: attested identity, own Workspace account in the coworker setup | Can we require a dedicated identity for every agent, not just some? |
| Which models does it use? | Gemini and Claude today; more planned | Which model handled which task, and is that in the log? |
| Where does it run? | Google’s cloud; long jobs continue after the user logs off | Which data regions, and what is retained in agent memory? |
| How is spending controlled? | Per-project hard caps; agent pauses at the limit | Who gets alerted, and can a cap be raised without approval? |
| How is it switched off? | Not detailed | What happens to its inbox, files, OAuth grants and sub-agents on removal? |
7. Your sharing settings are about to become agent permissions
Google’s most reassuring line is that a coworker agent sees only what is shared with it, and that its access follows existing sharing and membership settings. That is sensible, and it is also a warning. In most organisations, years of “anyone with the link” files, sprawling shared drives and catch-all Chat spaces mean sharing settings are far looser than anyone intended. A person rarely stumbles on the forgotten salary spreadsheet in a team folder. An agent added to that folder, or to a group that has access, can read everything it is allowed to, quickly, and use it in its work.
Google has not yet detailed how organisation-wide link sharing or group membership will interact with coworker agents, so treat this as a risk to test in a pilot rather than a confirmed flaw. But the practical lesson holds for any agent platform: clean up oversharing before you add a tireless reader to it.
8. The agent go/no-go scorecard
Instead of a to-do list, use this as a gate. Answer each question yes or no for the first agent you plan to give a directory account, whether from Google, Microsoft, OpenAI or anyone else. Count the yeses.
- Owner: Is one named person accountable for this agent, with a named backup?
- Job: Is its role written down in a few lines, including a short list of things it must never do?
- Identity: Does it run under its own account, never under an employee’s login?
- Sharing audit: Have you reviewed the folders, drives and Chat spaces it will join for old “anyone with the link” files and sensitive data?
- Never list: Are sensitive labels (HR, legal, finance, health) blocked by a gateway or policy rule, not just by good intentions?
- External input: Have you decided whether outsiders can email or share files with the agent, and what happens to those messages?
- Outbound actions: Do emails to customers, payments and changes to records need a human approval step?
- Connections: Is every OAuth grant and MCP server it uses listed, approved and scoped to read-only where possible?
- Budget: Is there a hard spending cap, with an alert to a human before it is reached?
- Logs: Is someone scheduled to review the agent’s audit trail each week during the pilot?
- Off switch: Have you tested suspending the agent and removing its access, including files, grants and sub-agents?
- Privacy: If it touches personal data, has your data protection lead checked it against current guidance, and is someone watching the ICO consultation if you operate in the UK?
Score it: 11–12 yes: go, with a 30-day review. 8–10 yes: pilot only, in a sandbox team with no customer-facing actions. 7 or fewer: no-go for now; fix the gaps first. Any “no” on questions 3, 7 or 11 is a no-go regardless of the total.
9. What to watch next
- The off-boarding story. Watch for admin tooling that removes an agent’s account, grants and sub-agents in one step, and for how agent memory is handled when it goes.
- Gateway policies in practice. The Agent Gateway is only as good as the rules written into it and the data labels it can see. If you do not classify documents today, start now. Our piece on AI control planes as the new crown jewel explains why gateways also become targets.
- The ICO’s next step. Responses close on 20 November 2026 and will shape a statutory code of practice. UK deployers have a chance to be heard before the rules are written.
Frequently asked questions
What is Google’s Gemini agent?
Announced at Gemini at Work 2026 on 8 October 2026, the Gemini agent is a single AI agent for work that handles questions, knowledge work, media and code from one interface. It accepts objectives, runs long jobs in the cloud, creates sub-agents and works across Google Workspace, Microsoft 365 and Slack, using Gemini or Anthropic Claude models.
What is a Gemini coworker agent?
A coworker agent is a Gemini agent set up with a defined role and its own Workspace account, including an email address, calendar, Drive storage and a company directory entry. Colleagues can add it to Chat spaces, @mention it and tag it in comments, and its edits appear under its own name in version history.
Is the Gemini agent available now, and what does it cost?
Google has not published a general availability date or a separate price for the Gemini agent, coworker agents, Agent Gateway or Agent Sandbox. Only the Financial Services and Legal editions were described as in preview. Check Google Cloud’s documentation for current status.
What is Google’s Agent Gateway?
Google describes the Agent Gateway as an AI network firewall that all agent traffic passes through, inbound, outbound and agent-to-agent. Administrators write policies once, such as blocking agents from documents with a given classification, and the gateway applies them to every agent.
What did the ICO announce about AI agents?
On 8 October 2026 the UK Information Commissioner’s Office said ten AI developers, including Google, Microsoft, OpenAI, Anthropic and Meta, had made or committed to data protection changes. It also opened a call for evidence on agentic AI covering security, transparency, accountability, automated decision-making, fairness and lawful processing, closing on 20 November 2026.
Should my business give AI agents their own accounts?
Generally yes, because a dedicated identity lets you limit, log and disable an agent separately from any person. But first clean up overshared files and folders, name an owner, require human approval for outbound actions, set a spending cap and test that you can remove the agent’s access completely. This is general guidance, not legal advice.
Sources
- Google Cloud (Thomas Kurian): Gemini at Work 2026: Introducing Gemini agent (8 Oct 2026)
- VentureBeat: Google Cloud unveils persistent Gemini Agents for long-running tasks, and they get their own Gmail, Calendar, and Drive storage (8 Oct 2026)
- The Next Web: Google launches workplace AI agent that gets its own email address (8 Oct 2026)
- Quartz: Google is launching a universal Gemini agent for enterprise workplace tasks (8 Oct 2026)
- ICO: ICO secures changes from leading AI developers as scrutiny extends to AI agents (8 Oct 2026)
- ICO: Agentic AI call for evidence (8 Oct – 20 Nov 2026)
