
Key takeaways
- Google Cloud announced the Gemini agent on Thursday at Gemini at Work 2026, and it is in private preview for enterprise customers now.
- According to The Verge, it can run as a 'coworker agent' with a dedicated identity and its own email address, which makes it something IT has to manage like an account.
- Google has not reported pricing, a general availability date, or how agent identities are secured and audited.
- Nearly every capability claim comes from Google's own announcement, so treat the preview as a pilot, not a rollout.
Google Cloud announced the Gemini agent on Thursday at its Gemini at Work 2026 event, pitching it as a single, universal agent for work. It’s in private preview for enterprise customers. For IT and security teams, the detail that matters is not the chat window. According to The Verge, the agent can run as a ‘coworker agent’ with a dedicated identity and its own email address.
What Google announced
Google describes one agent that users chat with and hand tasks to from a single interface. It lives in the Gemini Enterprise app, in Workspace, and in third-party services. It’s in private preview, and Google says it will be widely available soon to Workspace customers on select Business and Enterprise plans. No date or price has been given.
Per 9to5Google, people can call it by mentioning @Gemini in Gmail, Docs, Sheets, Slides and Chat. It can also work inside Drive and Calendar. Outside Google’s apps, users can reach it from Slack and Microsoft 365. An API lets other apps embed it as a ‘headless agent’ with no interface of its own.
Under the hood, Google says the agent splits multi-step jobs across job-specific sub-agents, run in parallel and in sequence, sometimes for hours or days. Each job goes to whichever model fits best. Today that means the Gemini and Claude families, with private and open models promised later.
What is a coworker agent, and why does the email address matter?
A coworker agent, as The Verge describes it, is an agent with its own dedicated identity and its own email address, not one borrowing a person’s. The reported format is @agents.company.com. That appears in only one source and is probably a placeholder domain, so don’t plan around the exact string.
Google also says the agent can act as a team member for a group, such as a project manager, or for a role, such as a finance analyst. A mailbox changes how the thing behaves in your environment. People can write to it, forward it documents and add it to threads. I’d treat it as an account from day one, not as a feature toggle.
Two other claims are thinner. A VentureBeat headline says the agents persist through long-running tasks and come with a mailbox, calendar and Drive space of their own. Neowin’s teaser mentions ‘cryptographically attested identities’ that act like employees. Neither piece gives detail, and only the headline and teaser are available, so take both as Google-adjacent claims, not documented controls.
Identity questions to ask before a pilot
Start with who the agent is in your directory and who can stop it. Google hasn’t published how these identities are secured or audited, so the burden falls on the buyer to ask. These are the questions I’d put to a Google rep, in writing:
- Is the agent a separate identity in our directory, or does it act under a human user’s credentials?
- What does ‘cryptographically attested’ mean in practice, and who vouches for the identity?
- Can an admin suspend the agent instantly, and what happens to tasks already running?
- Do logs separate what the agent did from what the person who assigned the task did?
- Who owns an agent when the employee who set it up leaves or changes roles?
- Who can read its mailbox, its Drive storage and its stored memory?
The offboarding question is the one most teams will miss. A human account gets disabled when someone leaves. An agent persistent enough to work for days could quietly outlive its sponsor.

An agent that emails outsiders and writes its own skills
Google’s own examples show the agent making judgment calls about who to contact. In one, a user asks for a meeting with the regional event leads they normally work with. The agent infers that group from chat-space membership and the previous event’s thread, looks at availability, then opens an email conversation to find a time. External participants are included.
That’s useful, and it’s also an agent deciding on recipients and sending mail outside your company. Admins should ask whether external email can be restricted, logged or held for approval, and whether the policy can differ by role.
Memory raises a second set of questions. Google says the agent has four memory types: session, semantic, procedural and episodic. Procedural memory covers how jobs get done, including skills the agent writes itself. Episodic memory holds everything it has done before. Can you review and delete those skills? Can you wipe the history? Where is it stored, and for how long? Google hasn’t said.
Then there’s the model mix. Google says routing each job to the best-fit model delivers optimal quality and lower costs, and Claude models are in the lineup today. Which Claude models, and whether a second model family changes data-handling terms, hasn’t been reported. For a framework on how agents get manipulated by what they read, our piece on a threat model for agents is a useful starting point.
What this changes for IT and security teams
Short term, nothing is forced on you. It’s a private preview, and Workspace availability is ‘soon’ on select Business and Enterprise plans. But once it’s generally available, it will sit inside Gmail, Docs and Chat, where employees already work, and they can invoke it with a mention. Shadow adoption could get ahead of policy.
If you’re an enterprise buyer, get the preview terms and controls documentation before you get a quote. Pricing hasn’t been reported, and it’s unclear whether the agent will be an add-on or bundled into existing plans.
If you’re a security lead, write the agent policy now: what an agent identity may access, what it may send externally, who sponsors it, and when it expires. Tasks defined as objectives instead of step-by-step instructions are also harder to audit after the fact. Google says users can give the agent objectives, not instructions, so scoping matters. Our guide to writing better AI prompts covers the basics of making a request specific.
And keep expectations modest. Almost everything we know about what the agent can do comes from Google’s announcement. Nobody outside the company has published tests.
Gaps Google hasn’t filled
The list of unknowns is long, and most of it is governance. Google hasn’t reported pricing or an exact availability date. It hasn’t explained how agent identities are secured and audited. It hasn’t said what guardrails govern an agent that can email external people and write its own skills.
The relationship to the consumer side is also unclear. The Verge reports Google launched a consumer agent, Gemini Spark, in May, which subscribers use across Workspace and the web through a separate interface in the Gemini app. That detail comes from The Verge alone. Whether the two agents will merge isn’t known.
Also missing: which Claude models are used and how Google decides which model takes a job, independent reliability tests on tasks that run for days, and how the agent compares with enterprise agents from Microsoft, OpenAI and Anthropic. Until those answers exist, a small, tightly scoped pilot is the sensible way to start.
Frequently asked questions
What is the Google Gemini agent?
It's a single, universal agent for work that Google Cloud announced at Gemini at Work 2026. Users chat with it and assign tasks from one interface, and it works across Workspace apps and third-party services.
Can the Gemini agent have its own email address?
According to The Verge, it can act as a 'coworker agent' with a dedicated identity and its own email address in the form @agents.company.com. That address appears in only one source and is probably a placeholder domain.
When will the Gemini agent be available?
It's in private preview for enterprise customers now. Google says it will be widely available soon to Workspace customers on select Business and Enterprise plans, with no date given.
How much does the Gemini agent cost?
Pricing hasn't been reported. It's also unclear whether it will be a separate add-on or bundled into existing plans.
Get the next one in your inbox. One email a day with the tech stories that matter, explained in plain English. Subscribe free.
Sources
This article was compiled from reporting by the following outlets. Links go to the original reports.
- The Verge: Google is launching a one-stop Gemini agent for your work tasks
- Neowin: Google Cloud unveils universal Gemini agent at Gemini at Work 2026
- 9to5Google: Google Cloud announces ‘Gemini agent’ as ‘universal agent for work’
- VentureBeat: Google Cloud unveils persistent Gemini Agents for long-running tasks, and they get their own Gmail, Calendar, and Drive storage
