Agentic AI

Gemini Agent: Google gives its agents an email address, their own permissions and a spending cap

At Gemini at Work 2026 (October 8), Google folded its enterprise AI offerings into a single Gemini agent: chat, task management and code generation in one interface.

The "coworker" agent

The standout feature: an agent can be deployed as a coworker with its own Workspace identity: email address, calendar, Drive and storage. It acts under its own name, not the user's, and shows up as such in a document's edit history.

Governance and costs

Google highlights:

  • a per-agent identity and permissions propagated through OAuth;
  • a per-agent audit trail (every action is attributed to the agent);
  • a sandbox (Agent Sandbox) and a gateway (Agent Gateway);
  • smart routing across models and real-time spend caps, per project or per agent.

On the model side, Gemini 3.8 Flash (same speed and cost as 3.7 Flash, better at reasoning and coding) replaces 3.7 Flash, with requests routed automatically.

Why it's instructive beyond Google

These are exactly the building blocks of a serious self-hosted agent stack:

  1. One identity per agent, never a human's account: you know who did what, and you can revoke one agent without touching the rest.
  2. Least privilege: rights scoped to the role.
  3. Spend cap: a looping agent shouldn't drain the budget. A gateway like LiteLLM supports per-key budgets.
  4. An audit log you can actually use afterward.

Caution

These are vendor announcements: real-world effectiveness (and availability in Europe, which the press is starting to examine) remains to be seen. An agent with its own mailbox is also a new attack surface, notably prompt injection through incoming email.

Sources: The Neuron, Futurum, The Next Web, The AI Insider, Google AI changelog.