Google Cloud on Thursday introduced Gemini Agent, a workplace AI system it says can take a goal, carry out the work on its own, and return with a finished result. Google Cloud CEO Thomas Kurian presented the product at the company’s Gemini at Work event, saying that “work now starts in the prompt window.”

According to Google, Gemini Agent works across Gmail, Docs, Sheets, Slides, Drive, Chat, and Calendar. It also connects with Microsoft 365 and Slack. The company said the agent keeps running in the cloud after a user closes a laptop, which allows a single task to continue for hours or even days.
Google’s “coworker agents” get their own Workspace accounts
The most notable feature in the launch is what Google calls coworker agents. A manager can describe a role, such as an events coordinator, and Gemini will create an agent for that role with its own Workspace account. That includes an email address, a calendar, Drive storage, and a listing in the company directory.
Decrypt noted that the setup resembles ideas explored in other agent frameworks. Grok pushed a similar concept with Grok Bot, OpenAI did the same with GPT dots, and Hermes introduced a bots feature with comparable functionality.
It connects to enterprise software and can route work across multiple models
The new agent connects with Salesforce, ServiceNow, Jira, Snowflake, and BigQuery. It can also work with any server that supports Model Context Protocol, an open standard Google described as a universal plug between AI and software.
Google said the system is not limited to its own models. Gemini currently orchestrates work across both Gemini models and Anthropic’s Claude models, routing each job to the model Google considers the best fit for quality and cost.
Google frames agent security around identity, isolation, and audit logs
Letting software act independently brings clear security questions. Google’s answer is to treat each agent like an employee. Every agent receives a cryptographically attested identity, meaning a digital identity verified through cryptography, and every action is recorded in an audit trail attributed to the agent rather than to a person.
All agents run inside what Google calls an Agent Sandbox, an isolated environment intended to keep the software separated from the rest of a system. Their traffic also passes through Agent Gateway, which Google described as an “AI network firewall.”
The report also pointed to a prior containment failure. In July, researchers at Accomplish AI said the local mode of Claude Cowork could escape its Linux virtual machine on Macs and reach files on the host computer.
Google added spending caps but has not disclosed pricing
Cost is another issue for agent products because they consume tokens, the units of text AI models read and write and the basis on which customers are billed.
Google said nearly 500 of its customers each processed more than 1 trillion tokens over the past year. To manage spending, the company added real-time spend caps. When a project reaches its limit, the agent pauses until someone clicks to resume it.
Google did not publish pricing for Gemini Agent and did not give a general availability date. Versions for financial services and legal are in preview, while government, healthcare, and retail are listed as coming soon.

