Google’s New AI Coworker Promises Autonomy—and Raises the Stakes for Security
Google’s New AI Coworker Promises Autonomy—and Raises the Stakes for Security
Google unveiled its new Gemini Agent at its Gemini at Work event, presenting it as a single enterprise AI that carries a company’s business context and can handle knowledge work from one prompt. Sundar Pichai described the launch to more than 700 Google Cloud customers as the arrival of a “single, universal agent for work.”
The shift is central to Google’s pitch: instead of merely answering questions, the agent is meant to take on objectives. Thomas Kurian, the Google Cloud chief executive, said it can receive “objectives, not just instructions,” then plan work, use tools and connect to internal business systems to complete it. Google is initially keeping the product in private preview for enterprise customers, rather than broadly releasing it to consumers.
That agent can operate through Workspace and reach services including Microsoft 365, Slack, Jira, Confluence, Git and major databases. It has its own Workspace account, email address and audit trail, positioning it less like a chatbot and more like a colleague that can be tagged, emailed or added to a group chat. Google says cloud-based operation will preserve context across devices, while job-specific sub-agents can take on pieces of larger assignments.
The same design that makes Gemini useful also sharpens the risk. Andrea Sivieri, chief product and technology officer at CoreView, welcomed the concept of a distinct agent identity and limited sharing permissions—but warned those protections alone are inadequate. “An agent with administrative access could change permissions, weaken security controls or even expose sensitive information across an entire Microsoft 365 environment before anyone notices,” he said.
Google’s bet is that enterprise deployment offers time to solve the hard problems of security, scale and performance. The counterargument is more immediate: if agents are becoming workforce members, companies need explicit access boundaries, continuous visibility and a record of every action before handing them the keys.
Write a comment