Google Cloud introduces Gemini agent with agent identities and spend caps
Image: Google CloudGoogle Cloud chief executive Thomas Kurian announced the Gemini agent on 8 October, with per-agent identities, a traffic gateway and project spend limits.
- Google says the Gemini agent runs in the cloud and keeps one set of memories across web, mobile, desktop, command line, Workspace, Microsoft 365 and Slack.
- Google says every agent gets its own cryptographically attested identity with least-privilege permissions, and all agent traffic passes through Agent Gateway, which it calls an AI network firewall.
- Google says a project's AI spend can have a hard limit, and the project's agent pauses when the cap is triggered; Financial Services and Legal versions are in preview.
Thomas Kurian, chief executive of Google Cloud, introduced the Gemini agent in a post dated 8 October 2026. Google describes it as a single agent that runs in the cloud and keeps one set of memory and context across web, mobile, desktop, command line, Google Workspace, Microsoft 365 and Slack. It can create temporary sub-agents for a job, and persistent coworker agents that get their own Workspace account with an email address. Google says it runs each job on the model that fits best, across its Gemini family and Anthropic's Claude models. Every agent gets its own cryptographically attested identity with least-privilege permissions, and all agent traffic passes through Agent Gateway, which Google calls an AI network firewall that enforces an organisation's policies. A project owner can set a hard limit on a project's AI spend in the Cloud Billing Console, and the project's agent pauses when the cap is triggered. Gemini for Financial Services and Legal is in preview; Government, Healthcare and Retail are listed as coming soon.
What it means for you Our view
The post announces the Gemini agent and its controls, and it gives no date or price for the agent itself; only the Financial Services and Legal versions are in preview, so there is nothing to buy from this announcement alone. The design is still worth reading for its controls: Google says each agent has its own attested identity, all agent traffic passes through Agent Gateway, and a project's agent pauses when a spend cap is triggered. These are Google's descriptions, not results from a test. If you plan to let agents act across Workspace, Microsoft 365 or Slack, ask Google which of these controls are generally available, what the spend cap covers, and how agent identities appear in your audit logs.

