On October 8, Google Cloud changed its sentence at Gemini at Work 2026. CEO Thomas Kurian put it in one line:
"Today, Gemini became an agent. You give it objectives, not just instructions."
This was not one more model. It was a declaration that scattered assistants and specialist tools would merge into a single work agent. From AI that answers questions to AI that returns finished work.
This post cross-checks the announcement against independent reporting. One caution first: this is an enterprise story. Read it separately from what everyday users can switch on today.
What was announced: give an objective, get finished work back
The official structure is simple.
Before: question → answer (ends in the chat box)
Now: objective + attachments (files, folders, projects)
→ plan → execute → finished artifact
(inside documents, the inbox, and dev environments)
The Gemini agent starts from a single prompt box. Knowledge work, Q&A, content creation, and coding all run through it. Three promises come attached.
- It plans the work, uses skills and tools, connects to company systems, and brings back something finished
- It picks the right model per job with built-in cost controls
- It ships the security, administration, and governance enterprises require
The connection list is wide: Google Workspace plus Microsoft 365, Slack, Jira, Confluence, Git, BigQuery, Databricks, Postgres, Snowflake, Salesforce, and ServiceNow. MCP servers and a shared company skill registry are supported. Grounding answers in company data is the premise.
It works long: it keeps going after the laptop closes
The most practical change is run duration.
Short jobs: handled inside the chat session
Long jobs: run in the cloud for hours or days
→ survive the laptop closing
→ react to scheduled tasks and events
Picture researching a market, building a financial model on company data, and producing the deck. The old way meant directing every step. The new shape is delegating the objective once and coming back for finished work. Progress shows in a tasks inbox: the agent's thinking, subagent delegation, skill loading, code, and progress.
One nuance matters. The announcement promises long runs but does not pin down exactly how customers activate the universal agent or when every capability lands. It runs through Gemini Enterprise across web, mobile, CLI, Workspace, M365, and Slack, but the rollout schedule needs its own confirmation. Separate the glossy wording from what you can actually provision.
It splits work: a temporary roster of subagents
One agent does not do complex work alone. Gemini spins up temporary subagents.
1 objective
├─ research subagent (parallel)
├─ financial-model subagent (parallel)
└─ deck subagent (sequential, uses prior output)
Each subagent carries a temporary identity
→ the lead agent coordinates
→ the roster disbands when done
Each subagent having its own identity is the point. It means every contribution is traceable. Read this alongside the three-layer memory post: reporting describes Gemini memory in four strands, session, semantic, procedural, and episodic. For agents that run long, memory is an execution requirement, not decoration.
Coworker agents: colleagues with email addresses
This was the headline. Beyond personal assistants, persistent digital coworkers shared across a team appear.
The example is concrete. A manager creates an Event Planner Agent that gets its own Workspace account, email address, calendar, Drive storage, and directory presence. Employees assign work the way they would to a colleague: mention it in Google Chat, email it, share a doc, add it to a group chat.
Assigning to a human colleague:
mention → email → share doc → invite to group chat
Assigning to a coworker agent:
identical. mention → email → share doc → invite to group chat
The difference is where authority comes from. The agent acts under its own identity, not a borrowed employee identity. A cryptographically attested identity stamps its logs and any VM it starts, administrators approve role-based permissions, and every action lands in an audit trail under the agent's name, not a person's. That is exactly the point regulators have been asking about all year.
Scope is bounded too. The official line is access only to information shared with it. Calendar access does not mean the whole company's schedule; it means working context inside the approved boundary, who is on which team, time zones, approvers, within limits.
It picks models: routing across Gemini and Claude
One more line deserves attention. The Gemini agent routes each job to the model that fits best, across the Gemini family and Anthropic's Claude today, with private and open models planned later.
Job arrives → judge difficulty, cost, quality → pick model
├─ light cleanup and summaries → cheap model
└─ hard analysis and coding → top model
Set the budget before it starts
→ one budget covers the whole cost of the work
That matches the model routing implementation exactly. Classify, attempt, escalate, record, now inside the product. Built-in cost controls and an upfront budget are named features. Routers save money through verification, caps, and logs, not clever classification.
Applying it to your portfolio: a five-step design
The briefing's action item, expanded into practice.
1. Agent Identity: name, role, and identity per agent
2. Tools: an explicit tool list (including MCP)
3. Permissions: split read, write, and danger with approval paths
4. Execution: checkpoints and resume for long jobs
5. Audit: agent-attributed records of who did what
It connects directly to layer-2 approvals in the four-layer security post and checkpoints in the durable execution post. Start small. Give one project agent a one-page doc covering the five items. That doc later becomes the sandbox policy and the audit-log schema.
CodeBridge Mini Lab: give your agent an identity
1. Pick 1 agent (e.g. weekly-report organizer)
2. Write its identity card:
[ ] name, role, team (whose work it does)
[ ] read scope (folders, docs, calendars)
[ ] write scope (what it may edit or send)
[ ] forbidden zones (credentials, personal docs, payments)
3. Run 1 delegation test:
- hand over 1 objective, receive only the finished artifact
- log the process like a tasks inbox (which tools ran)
4. Leave 1 audit line:
- which agent, what, when, under which permission
Conclusion: identity, permission, and audit are the product
One line to close.
The model race ended and the identity race began. For agents that work long, the audit trail comes before the email address.
The real message of the Gemini agent launch is not a score. AI competition has moved past model benchmarks into identity, permissions, memory, long runs, and cost control. And the stage is enterprise first. Read consumer rollout as a separate story.
Today's job is small. Give every agent you run a one-page identity card. Split read, write, and forbidden. Record actions under the agent's name. That is the difference the next year of portfolios will show.
Further reading
- Model routing in code: cheap models first, escalate when stuck
- Why you must not run agents without permissions in the computer-use era
- Runtimes, not models, save long jobs
References
- Google Cloud Blog: introducing the Gemini agent at Gemini at Work 2026
- Google Cloud Blog: Gemini at Work 2026 details
- TechCrunch: Google brings agentic AI to Gemini, starting with businesses (Oct 8, 2026)
- VentureBeat: persistent Gemini Agents with own Gmail, Calendar, Drive (Oct 8, 2026)
Go deeper with a course
To practice designing identity, tools, permissions, execution, and audit as structure, this course stacks harness, loop, and graph in order, exactly like the five-step design here.