On October 8, Google Cloud CEO Thomas Kurian used the Gemini at Work 2026 keynote to call Gemini "your new single, universal agent for work." The interesting part isn't a smarter chatbot. It's agents that get their own email address, their own storage and their own name in your document history.
That shift matters for anyone building or buying enterprise AI agents. Once an agent is a named coworker instead of a feature inside an app, the hard questions stop being about prompts. They become questions about identity, permissions, audit trails and spend. Here's what Google announced, what it leaves open, and what a scaling business should do about it this quarter.
TL;DR#
- Google's Gemini agent takes objectives, runs for hours in the cloud and can create "coworker agents" with their own identity and Workspace account.
- The real news is governance: a separate identity per agent, admin-approved permissions, an audit trail, a policy gateway and spend caps.
- You can copy that pattern today on your own stack, starting with one workflow.
What Google announced on October 8#
According to Google's announcement, Gemini now handles chat, autonomous tasks and code from one prompt box and one API. Work can be assigned, scheduled or triggered by events, and long jobs keep running after you close your laptop.
Coworker agents#
The headline feature is the coworker agent. You describe a role and Gemini creates an agent with a persistent job, its own @agents.company.com email, its own storage, calendar and directory entry. Your team can @mention it in Chat or tag it in a document comment. Its edits appear under its own name, and it only sees what people share with it.
Tools, skills and models#
It connects to Jira, Salesforce, Slack, Microsoft 365, Snowflake, Postgres and more, and works with any Model Context Protocol (MCP) server inside or outside your network. Teams can publish shared tools and reusable "skills" to company-wide registries. Each job is routed to a model, with Gemini and Anthropic's Claude models supported today, as Quartz and The Register also reported.
Why an AI coworker with its own identity matters#
Most AI assistants so far have acted as you. They borrow your login, so if your account can see payroll, so can the assistant. When something goes wrong, the logs say you did it.
Google is going the other way. As Google put it, "Every Gemini agent has an identity of its own, separate from your identity." That sounds like a small detail. It changes a lot:
- Least privilege becomes possible. The agent gets the folders and systems it needs, not everything you can reach.
- Accountability gets clearer. The audit trail separates what the agent did from what people did.
- Offboarding works. If an agent misbehaves, you revoke one identity.
Engineers have run automation this way for years with service accounts. What's new is a major vendor packaging that discipline for everyday knowledge work. We'd expect it to become the default way to run an AI coworker on any platform.
How enterprise AI agents are governed: the four questions#
Google frames governance around four questions. They're a good AI agent governance framework even if you never touch Gemini, so here's how Google answers them and what the equivalent looks like when you build your own.
| Question | Google's answer | If you build your own |
|---|---|---|
| Who is the agent? | Cryptographically attested identity, stamped into every log | One service account or OAuth client per agent, never a shared admin key |
| What can it do? | Role-based permissions approved by security admins, OAuth to outside systems | Scoped tools: read-only by default, writes behind human approval |
| What did it do? | Every action written to an audit trail in the agent's name | A decision log with input, tool call, result and approver |
| What should it never touch? | Agent Sandbox plus Agent Gateway, which checks all traffic against policy | Deny rules enforced in the tool layer, not in the prompt |
A fifth control is worth copying too: money. Google lets you set a hard spend cap per project, and the agent pauses when it's hit.
In practice, the request path for a well-governed agent looks like this:
Teammate request
|
v
Agent (own identity) -> Policy gateway -> Scoped tool (MCP) -> System of record
| |
blocked + logged approval gate on writes
The key design choice: the rules live outside the model. A prompt that says "never open HR files" is a suggestion. A gateway that refuses the request is a control.
Trade-offs and what's still missing#
No price tag or launch date yet. Google's post gives no per-seat pricing and no general availability date for the agent or Agent Gateway. Only the financial services and legal editions are labeled as preview.
Lock-in is real. The Register pointed to a GitHub dataset of 308 discontinued Google products with a median lifespan of about 4.1 years. Whatever platform you pick, keep your prompts, skills and tool definitions somewhere you control.
Connectors stop at the big names. Salesforce is covered. Your Shopify store talking to Zoho and a custom billing script probably aren't. MCP is the way in, but someone has to build and secure that server.
Learning cuts both ways. Gemini keeps several kinds of memory, including skills it writes for itself. That helps consistency, but behavior can drift, so test it against known-good examples.
What it means for a scaling business#
Most of the businesses we work with look nothing like the keynote customers. They run on Google Workspace or Microsoft 365, with Shopify, Stripe or Zoho doing the heavy lifting, and often nobody in-house whose job is AI.
Four points stand out:
- The governance pattern is the valuable part. You can apply identity, scoped tools, logging and spend caps to agents built on any platform.
- Your data definitions decide the results. If your team hasn't agreed what "net margin" means, an agent will guess.
- Agents need a narrow interface to your systems. A small set of well-named tools is safer and easier to test than database credentials.
- Long-running agents need budgets. Google says per-token prices have dropped 98% since 2024, but an agent stuck in a loop for hours still costs real money.
A checklist before you hire an AI coworker#
Treat it like hiring a person for a narrow role:
- Pick one workflow with clear volume, such as refund requests or invoice matching.
- Write the job description: inputs, outputs, systems involved and what it must never do.
- Create a dedicated identity for the agent. No shared logins, no borrowed admin keys.
- Expose tools, not databases. Start with read-only tools and put every write behind a human approval step.
- Log every decision with the agent's name and who approved it.
- Set a hard monthly spend cap with an alert well before you reach it.
- Run it in shadow mode for two weeks and compare its output with what your team actually did.
- Plan your exit. Keep prompts, skills and tool definitions in your own repository so you can switch platforms later.
How MagicMakers Lab approaches this#
This is how we already build agents: scoped tools, human approval gates on anything that writes or spends, and a decision log you can read. When your systems aren't in a vendor's connector list, we build MCP servers that give agents safe, narrow access. See Framico, where 200+ orders a day ship with zero manual steps, or Business Hub, where three disconnected systems became one platform.
Key takeaways#
- Google's Gemini agent treats AI as a named coworker with its own identity, email and audit trail.
- The four governance questions (who, what it can do, what it did, what it must never touch) apply to any agent you deploy.
- Put the rules in tools and gateways, not in prompts.
- Pricing and launch dates are still open, so keep your agent logic portable.
- Start small: one workflow, one identity, scoped tools, a decision log and a spend cap.
FAQ#
What are enterprise AI agents?#
They're AI systems that complete multi-step business tasks, such as reconciling invoices or triaging support tickets, by calling tools in your existing software. Unlike a chatbot, they take actions, so they need their own identity, limited permissions, a log of what they did and human approval for risky steps.
What is a Gemini coworker agent?#
It's an agent Google's Gemini creates from a role you describe. It gets its own Google Workspace account, including an email address, calendar and storage. Teammates can mention it in Chat or tag it in document comments, its edits appear under its own name, and it can only see what people share with it.
How do you govern AI agents in a business?#
Answer four questions for every agent: who it is, what it can do, what it did and what it must never touch. That means a dedicated identity, read-only tools by default, approval gates on writes, a decision log and a spending limit, all enforced in code rather than in the prompt.
Can AI agents connect to tools like Shopify, Stripe or Zoho?#
Yes, through APIs or an MCP server that exposes a few safe actions, like looking up an order or drafting a refund. Big platforms ship connectors for popular enterprise apps, but smaller or custom systems usually need a server built for them. Keep writes behind human approval until the agent earns trust.
Ready to give an AI coworker its first job without handing it the keys to everything? We'll map one workflow, the tools it needs and the guardrails around it. Book a free audit.