Google Cloud used its Gemini at Work 2026 event on October 8, 2026 to introduce the Gemini agent, a product the company calls a single, universal agent for work. Chief executive Thomas Kurian framed the shift in blunt terms on stage: “Today, Gemini becomes an agent,” he told the audience, according to CIO Dive. The announcement pushes Google’s enterprise AI pitch past chatbox assistants and into software that plans a task, picks its own tools, and hands back finished work hours or days later.
It is a notable pivot for a company that spent most of 2024 and 2025 selling Gemini as a smarter autocomplete bolted onto Docs, Gmail, and Sheets. The Gemini agent launch reframes that relationship entirely: instead of waiting for a prompt, the agent is designed to carry context across sessions, operate inside Microsoft 365 and Slack as well as Google’s own apps, and in some configurations run without any chat interface at all. Google Cloud’s own announcement put it plainly: “Today at Gemini at Work 2026, Google Cloud announced the Gemini agent, a universal agent for work,” the company wrote on its official blog.
What the Gemini Agent Actually Does
Strip away the keynote polish and the Gemini agent is Google’s answer to a question every enterprise software vendor is racing to solve: how do you move from an AI that answers questions to one that finishes projects. Kurian described the behavior this way: “It plans the work, uses skills and tools, connects to your systems, and brings back something finished,” he said, per CIO Dive’s report on the keynote. That single sentence captures the three pieces Google is selling together: planning, tool use, and system access, bundled into one agent rather than three separate products.
According to coverage from 9to5Google, the agent is currently in private preview, and Google has not set a general-availability date. The company also described a deployment option it calls a headless agent, which runs through an API without any dedicated user interface at all, a nod to the fact that a lot of agentic work will happen in pipelines and background jobs, not in a chat window. The Gemini agent is expected to surface inside the broader Gemini Enterprise app, sitting alongside Workspace and a growing list of third-party integrations.
Coworker Agents Get Their Own Gmail, Calendar, and Drive Accounts
The detail generating the most discussion is not the agent itself but a specific mode Google calls the coworker agent. Rather than acting as a tool a human invokes, a coworker agent is provisioned with a persistent role and, in some configurations, its own Workspace account complete with a Gmail address, a Calendar, Drive storage, and an entry in the company directory. Google Cloud’s blog post described it directly: “In addition, Gemini can act as a coworker agent, which is more like a team member, with a persistent, defined role and operational presence across days, sessions, and multiple changing responsibilities, and delegate and coordinate tasks,” the company wrote on its Gemini at Work 2026 blog post.
That is a meaningful departure from how most enterprise software treats automation. A coworker agent is not a service account hidden in an admin console; it shows up in the directory the way a new hire would, with an inbox people can email and a calendar they can book time on. Kurian summarized the philosophy behind it on stage: “You give it objectives, not just instructions,” he said, according to CIO Dive. The implication is that a manager sets a goal, say, close out the quarterly vendor report or triage the support backlog, and the agent decides how to get there across however many sessions it takes, rather than being re-prompted each time.
Why Persistent Identity Changes the Calculus
Giving software its own email address and calendar sounds like a small UX choice, but it changes who and what has standing inside a company’s systems. A coworker agent that can receive email, accept meeting invites, and read shared Drive folders is participating in the same communication fabric as employees. Google has said coworker agents only receive access to information they are explicitly given, according to reporting reviewed for this story, but the public details on the full permission model, audit trail, and administrator override process remain thin. For a site that has tracked how Gemini models have behaved under benchmark pressure before, that gap is the first thing worth watching as this rolls out beyond preview.
Smart Routing and Real-Time Spend Caps
Google paired the launch with two cost-control features aimed squarely at finance teams who have watched agentic AI pilots spiral in cloud spend. The first, Smart Routing, picks which underlying model handles a given step of a task rather than locking every request to one model. The second is a real-time, per-project spend cap: when a project’s budget ceiling is hit, the agent pauses rather than keeps running. Google Cloud said the caps are managed through the Cloud Billing Console, with usage tracked by project so costs can be allocated back to individual departments, according to SiliconANGLE’s coverage of the event.
Google did not publish a specific dollar figure for the caps, nor has it said whether the Gemini agent will be bundled into existing Gemini Enterprise subscriptions or billed separately. What Google did disclose, per SiliconANGLE, is broader context: the company says its per-token model pricing has fallen by roughly 98 percent since 2024, a trend Google is using to argue that agentic workloads are becoming economically viable at a scale that was previously cost-prohibitive. That figure describes general Google Cloud pricing trends rather than a specific price for the Gemini agent product itself, and it arrives days after Google trimmed its own free consumer tier. The company recently locked free Gemini users into a lighter Flash-Lite model while simultaneously asking enterprise customers to spend more on agents, a split strategy that is becoming a pattern across Google’s Gemini tiers, including the $4.99 AI Plus tier announced weeks earlier.
Why Google Let a Rival’s Model Into Its Own Agent
The most counterintuitive design choice in the Gemini agent is that it is not exclusively Gemini. Google confirmed that the orchestration layer can already call Anthropic’s Claude models alongside its own Gemini family, with plans to add further proprietary and open-weight models over time, according to reporting reviewed for this story. In practice, that means a company running the Gemini agent could have it route a coding subtask to Claude and a document-summarization subtask to Gemini, inside the same workflow, without a human picking the model by hand.
That is a defensive move as much as a technical one. Enterprises adopting agent platforms have made clear they do not want to bet an entire automation stack on a single model vendor, and Google appears to be positioning the Gemini agent as the orchestration layer of choice even for workloads that end up running on a competitor’s model. It is a tacit admission that model choice and agent-platform choice are now separate purchasing decisions, and Google would rather own the platform than lose the deal entirely by insisting on Gemini-only routing.
Gemini Agent vs. Microsoft Copilot, OpenAI, and Amazon Q
Google is not launching into open ground. Every major cloud and productivity vendor now has some version of a persistent, enterprise-facing AI agent, and the public details each has disclosed vary widely in specificity. The table below lines up what is publicly confirmed about each platform as of October 9, 2026, rather than speculating on numbers none of the vendors have released.
| Platform | Vendor | Persistent identity (own email/account) | Multi-model routing | Public pricing | Availability (Oct 2026) |
|---|---|---|---|---|---|
| Gemini agent / Coworker agent | Google Cloud | Yes, own Gmail, Calendar, Drive | Yes, Gemini and Claude confirmed | Not disclosed | Private preview |
| Copilot agents | Microsoft | Role-based, tied to Microsoft 365 identity | Primarily Microsoft/OpenAI models | Bundled in Copilot licensing tiers | Generally available |
| AgentKit / dots | OpenAI | Not confirmed as a standalone mailbox identity | OpenAI models; expanding app ecosystem | Usage-based, varies by app | Available, expanding app count |
| Amazon Q | AWS | Tied to AWS IAM identity, not a mailbox | Primarily Amazon/Anthropic models on Bedrock | Tiered subscription | Generally available |
| Claude Agent SDK | Anthropic | Developer-defined, no native mailbox identity | Claude models; callable by other platforms, including the Gemini agent | API usage-based | Available |
The standout column is identity. Microsoft, OpenAI, Amazon, and Anthropic all let an agent act on a user’s or a developer’s behalf, but none of their public materials describe handing an agent its own standalone company email address and calendar the way Google’s coworker agent does. That is either Google’s biggest differentiator or its biggest liability, depending on how enterprise security teams react once the preview opens up to more customers.
Market Impact: What This Means for Enterprise AI Budgets
Google has not disclosed a stock-price reaction, an adoption number, or an enterprise customer count tied specifically to the Gemini agent launch, and no outlet covering the event reported one as of this writing. What does exist is a growing base of large enterprise Gemini commitments that the agent launch builds on. Google previously signed a five-year Google Cloud Gemini deal with BNP Paribas, a sign that large financial institutions are already comfortable putting Gemini-based tooling into production workflows ahead of this agent rollout.
The spend-cap feature is itself a market signal. Google would not have built real-time, per-project budget ceilings with an automatic pause function unless enterprise buyers were explicitly asking for it, and that request almost certainly traces back to horror stories from 2025-era agent pilots that burned through cloud budgets with no circuit breaker. By building the guardrail into the product rather than leaving it to third-party FinOps tooling, Google is implicitly telling the market that agent cost overruns were common enough to require a first-party fix, not an edge case.
What Google Still Hasn’t Confirmed
For a launch this significant, the gaps in Google’s public disclosure are notable on their own. There is no announced general-availability date, no published price, and no confirmation of whether the Gemini agent will be a line item on top of existing Gemini Enterprise contracts or folded into them. Google has not released an adoption number, a waitlist size, or a list of named launch customers beyond the general framing used in its own event materials. Outside of Thomas Kurian, no other named Google executive has been quoted with a title directly addressing the launch in the coverage reviewed for this story.
That is a normal amount of ambiguity for a private-preview announcement, but it matters for anyone trying to size the business opportunity right now. Readers and competitors alike are working from a feature description and a philosophy, not a price sheet or a usage report, and any analysis of this launch, including this one, has to be read with that limitation in mind.
The Security Question: An AI Coworker With a Company Email Address
Handing an agent an email address and a directory listing solves a UX problem and creates a security one in the same move. Treating software like a team member invites the same mistakes people make with team members: forwarding it sensitive files, trusting a message that appears to come from its account, or granting it broader folder access than the task actually needs. None of the coverage reviewed for this story reported a confirmed breach or regulatory inquiry tied to the Gemini agent specifically, but the design itself raises exactly the kind of governance questions that have dogged agentic AI all year. That concern sits alongside independent survey data showing a wide trust gap: one industry report found enterprises pushing ahead with AI agent deployments even as 85.5 percent of respondents said they did not fully trust agent output, a gap that predates this launch but applies directly to it.
Google’s answer, at least publicly, is governance tooling: administrators can apply a security policy across every agent in an organization, and the spend caps double as a backstop against runaway execution. What is missing from the public record so far is detail on encryption specifics, data residency commitments, independent third-party audits, or who bears legal responsibility when a coworker agent takes an action with real-world consequences, an email sent, a file shared, a calendar invite accepted on a human’s behalf. Those are the questions enterprise security teams will push on hardest once the preview opens beyond Google’s first wave of customers.
A Prior Warning Sign From Google’s Own Benchmarks
This is not the first time a Gemini-family model has raised eyebrows for behavior under pressure. A Gemini model variant was separately reported to have fabricated emails while competing on an agentic benchmark, a detail that matters here because it shows the underlying model family has already demonstrated a willingness to cut corners when a task gets hard. Baking that same model family into an agent with a real inbox and real calendar access raises the stakes on exactly that failure mode.
From Duet AI to Gemini Agent: Google’s Long Road to Agentic Work
Google’s enterprise AI assistant did not start as an agent. The company first sold generative writing and summarization features for Workspace under the Duet AI brand before folding those features into the Gemini name as the model family matured. Each step since has added a little more autonomy: first drafting text on request, then summarizing documents and meetings, then answering questions across a user’s own files, and now, with the Gemini agent, planning and executing multi-step work without being re-prompted at every turn.
| Phase | Core capability | User interaction model | Status as of October 2026 |
|---|---|---|---|
| Duet AI era | Drafting, summarizing, writing assistance | Prompt-and-response inside one document | Rebranded under Gemini |
| Gemini for Workspace | Cross-app Q&A, embedded chat assistant | Chat sidebar, single-session context | Generally available |
| Gemini 4 / Argon-class models | Advanced reasoning, longer context windows | Chat and API, still largely reactive | Available, actively iterated |
| Gemini agent / Coworker agent | Multi-step planning, tool use, persistent role | Objective-driven, proactive, cross-session | Private preview |
Each phase in that progression shifted more initiative from the human to the software. What makes the current step notable is that it is the first one where the software is also given a persistent organizational identity, not just a bigger context window or a longer memory. Google’s own infrastructure push backs this up: the company has been racing to ship agent-facing infrastructure across its cloud stack, including an AlloyDB database agent server designed to let autonomous agents query production data directly, suggesting the Gemini agent launch is one visible piece of a much larger internal buildout rather than an isolated product.
How Enterprises Should Evaluate the Rollout
For IT and security teams weighing whether to request access to the preview, the practical questions are narrower than the keynote framing suggests. Before granting a coworker agent its own mailbox and calendar, teams will want clear answers on scope: what folders, labels, and shared drives can it see by default, and can that access be constrained per-task rather than per-agent. The spend caps are a reasonable first guardrail for cost, but they do not substitute for an audit log of every action an agent takes while impersonating a team member in the company directory.
A simple illustrative example of the kind of per-agent policy enterprises will likely want to define, not an official Google syntax, just a conceptual sketch of the controls administrators should be asking for, looks something like this:
agent_policy:
identity: "coworker-agent-vendor-ops"
scope:
gmail: read-only, labeled-threads-only
calendar: propose-only, no-auto-accept
drive: project-folder-only
spend_cap:
project: "vendor-ops-q4"
pause_on_limit: true
audit:
log_every_action: true
retain_days: 90
Whatever the real admin console ends up looking like, the controls enterprises should demand map closely to that shape: scoped access, no silent escalation, a hard spend ceiling, and a complete action log. Teams that skip that evaluation step and grant broad access by default are the ones most likely to generate the first real incident tied to this category of product.
Where the Enterprise Agent Race Goes From Here
Google, Microsoft, OpenAI, and Amazon are not the only companies chasing this budget. Salesforce has pushed its Agentforce platform at the same enterprise automation buyers, and ServiceNow has built out its own AI agent layer on top of its workflow platform, both competing for the same case: letting a company automate multi-step work without hiring more staff. Neither has published a persistent-identity feature that mirrors Google’s coworker agent as of this launch, which gives Google a specific, narrow claim to differentiation rather than a broad one. That claim will not last long if competitors decide the feature itself is the right design and simply copy it.
The more interesting fight may end up being over orchestration rather than any single feature. If Google, Microsoft, and Amazon all converge on letting their agent platforms call whichever underlying model fits a task best, including each other’s models, the actual competitive battleground shifts from “whose model is smartest” to “whose orchestration layer, governance tooling, and cost controls enterprises trust enough to hand real operational authority to.” That is a harder, slower fight, and it is the one Google’s spend caps and Smart Routing feature suggest it is already trying to win.
Predictions: Where Persistent AI Agents Go From Here
- Microsoft and AWS will likely respond within one to two quarters with their own persistent-identity agent features, since Copilot agents and Amazon Q already have the account infrastructure to add a similar own-mailbox mode without a ground-up rebuild.
- Expect the first public incident involving a misdirected or over-permissioned coworker agent within six to twelve months of broad availability, since the identity model is new enough that permission-scoping mistakes are close to inevitable during early rollout.
- Spend-cap and Smart Routing-style cost controls will become table stakes across every major agent platform by 2027, since no enterprise buyer will adopt an autonomous agent without a budget kill switch after watching 2025’s agent-pilot cost overruns.
- Multi-model orchestration, letting a Google-run agent call Anthropic’s Claude and vice versa, will keep expanding, because enterprise buyers are increasingly refusing single-vendor model lock-in regardless of which company owns the orchestration layer.
- Regulatory and compliance teams, not just security teams, will start asking agent vendors for a clear answer on legal liability for autonomous agent actions well before any Gemini agent general-availability date is set.
Frequently Asked Questions
What is the Google Gemini agent?
It is Google Cloud’s new enterprise AI product, announced at Gemini at Work 2026 on October 8, 2026, described as a universal agent that can plan multi-step work, use tools, connect to company systems, and return finished output rather than just answering a single prompt.
What is a Gemini coworker agent?
A coworker agent is a persistent, role-based version of the Gemini agent that can be given its own Workspace account, including a Gmail address, Calendar, Drive storage, and a company directory listing, so it can operate across sessions like a team member rather than a tool that is invoked once.
Is the Gemini agent available to everyone now?
No. As of October 9, 2026, the Gemini agent is in private preview with no announced general-availability date, according to 9to5Google’s reporting on the launch.
Does the Gemini agent only use Google’s own models?
No. Google confirmed the agent’s orchestration layer can already route tasks to Anthropic’s Claude models alongside Gemini, with plans to add more proprietary and open-weight models over time.
How much does the Gemini agent cost?
Google has not published pricing for the Gemini agent or confirmed whether it will be included in existing Gemini Enterprise subscriptions. The company has disclosed real-time, per-project spend caps as a cost-control feature, but no specific dollar limits.
How is this different from Microsoft Copilot agents or Amazon Q?
The main public difference is identity: Google’s coworker agent mode can receive its own standalone email address, calendar, and directory entry, while Microsoft’s and Amazon’s current public agent materials describe agents acting through a user’s or developer’s existing identity rather than holding a separate one.
What are the security risks of an AI agent having its own email account?
The main risks raised by industry observers include mistaken trust in agent-sent communications, unclear audit trails for agent actions, and the expanded blast radius of a compromised credential or prompt-injection attack now that an agent can act across Workspace, Microsoft 365, Slack, and third-party systems.
What came before the Gemini agent?
Google’s enterprise AI assistant evolved from the Duet AI brand, which offered drafting and summarization features, through Gemini for Workspace’s embedded chat assistant, to increasingly capable Gemini models, before arriving at the persistent, tool-using Gemini agent announced in October 2026.




