How is 'an agent with its own Workspace account' different from agents borrowing an employee's account?
The common past approach was an agent acting through some employee's OAuth grant, so audit logs read as "that employee did it," making it hard to tell human from agent when something went wrong. The Gemini agent's coworker mode uses a separate account: it appears under its own identity in version history and audit logs, and its permissions come only from what others have shared with it.
This clarifies accountability, but it also shifts the agent's boundary from "the employee's full permissions" to "whatever was shared," making sharing-settings hygiene the new control point.
Why would Google build a hard spending cap into the agent platform?
A long-running agent nobody is watching accrues cost in the background. An interactive agent's spend is bounded by how many instructions a person is willing to send; a persistent one has no such natural brake. Google's answer is a hard AI spending cap per project in the Cloud Billing Console — when it triggers, that project's agents pause and can be resumed with one click.
It amounts to acknowledging that an agent running for days needs a financial Circuit Breaker, not just a permissions one.
What does the Agent Gateway, as an 'AI network firewall,' actually Block?
Per the official description, all traffic in and out of agents passes through the Agent Gateway, which enforces policy in real time, and a policy written once applies across every agent in the company. The key idea is moving the control point out of each agent's own code and into a centralized traffic layer.
Which attack types it can detect and intercept (Prompt Injection, for example) isn't detailed in the announcement, so that needs actual documentation or third-party testing.
My company doesn't use Google Workspace — is this still relevant?
Yes, as a design reference. Google says the Gemini agent can also be used from inside Microsoft 365 and Slack and can orchestrate other models such as Claude, so it isn't fully tied to Google's ecosystem. The three designs worth borrowing: agents get a separate identity, permissions are bounded by what's shared, and cost has a hard cap.
When evaluating any comparable product, ask the vendor how far each of those three goes.
On October 8, 2026, Google Cloud launched the "Gemini agent" at Gemini at Work 2026, positioned as a single, universal work agent that handles knowledge work, Q&A, media creation, and coding from one prompt box. Google Cloud CEO Thomas Kurian put it as "You give it objectives, not instructions." What deserves attention from developers and enterprise IT isn't that there's another agent that can chat — it's that Google turned an agent's identity into a formal enterprise account.
According to Google's official blog, the Gemini agent runs in the cloud, so work continues after you close your laptop. It can handle tasks lasting hours to days and keeps task context across days through session memory. It dynamically spins up temporary, task-specific sub-agents, each with its own identity, to coordinate parallel and sequential steps. There are also "coworker agents" — persistent-role agents that operate across multiple days and sessions.
The most concrete design choice: a coworker agent gets its own Workspace account, including an @agents.company.com mailbox, calendar, and Drive, and appears in the company directory. Colleagues can add it to a Chat space, @-mention it, or assign it edits via document comments. It acts under its own identity, shows up in version history, and can only access what you or your team have shared with it.
Google's published controls include: each agent has a cryptographically attested identity under least privilege; fine-grained role permissions must be approved by the organization's security administrator; all actions are written to audit logs attributed to the agent rather than a person; all agents run inside an Agent Sandbox with a separate network boundary; and traffic in and out of agents passes through an Agent Gateway that enforces policy in real time as an "AI network firewall," with policies written once and applied across every agent in the company. On cost, a hard AI spending cap can be set per project in the Cloud Billing Console — when it triggers, that project's agents pause and can be resumed with one click.
Tool integrations span Microsoft Office and Teams, Slack, Jira, Salesforce, ServiceNow, BigQuery, Snowflake, Databricks, Postgres, and any MCP Server; access channels include web and mobile as well as inside Microsoft 365 and Slack. Google also says the agent and the underlying model are separate choices: it can currently orchestrate Gemini and Anthropic's Claude, with Smart Routing assigning models by workload.
Caveats: the official materials publish no pricing or general availability date; industry-specific versions for financial services and legal are in preview, with government, healthcare, and retail "coming soon." Customer outcome figures in the post (for example, Bradesco cutting document review from one hour to five minutes) are customer-reported and not independently verified.
If your company runs Google Workspace or plans to adopt this kind of agent, the most practical impact is on permissions and cost structure. An agent becoming an account in the directory means its reach is defined by who shared what with it, so sharing hygiene directly determines how much data it can touch. Settle two things before rollout: which shared drives or mailboxes are never shared with agent accounts, and what the project-level AI spending cap should be. Whether it's worth adopting is a calculation for after pricing is published — until then, don't treat customer-reported gains as your own expected value.