Skip to content

Google Gemini Agent: Enterprise AI That Can Run Claude Too

Google's Gemini agent runs objectives, not just prompts, with persistent memory and sub-agents that can use Claude. It's in private preview with no confirmed…

7 min read How we work

The Gemini agent is Google Cloud's new enterprise AI agent, unveiled on October 8 at Gemini at Work 2026. It combines persistent memory, business tools, and the ability to delegate tasks to sub-agents into a single system. The architectural breakthrough is that the underlying model is a separate choice from the agent itself: today it can run Gemini or Anthropic's Claude. This isn't an open product. It's in private preview for selected customers, and Google has not specified supported regions or a general availability date.

The real story here goes beyond a product launch. Competition among enterprise AI platforms is shifting away from model quality toward the systems that manage work, data, and permissions. That shift reframes the question worth asking: not which model gives the best answer, but who controls an agent when it runs for hours on behalf of a person, inside systems holding confidential documents.

Gemini at Work 2026: Introducing Gemini agent | Google Cloud Blog
This article is adapted from Thomas Kurian's keynote address at Gemini at Work 2026. Read on to learn more.

What Is the Gemini Agent and How Does It Differ from a Chatbot

A chatbot responds to a message. The Gemini agent, according to Google, receives objectives rather than instructions and returns a finished result. It runs in the cloud, meaning a task can start on one device and continue after the laptop is closed, as VentureBeat reports, and it can run for hours or days. For multi-step work it creates temporary sub-agents, each with its own identity, operating in parallel or in sequence. Memory is split into four types: session, semantic, procedural, and episodic, covering the active task, the knowledge base, the method for completing a job, and what the agent has already done.

It's accessible from web, mobile, desktop, and command-line interfaces, inside Google Workspace, Microsoft 365, and Slack, as well as via API for headless deployments. In Gmail, Docs, Sheets, Slides, and Chat it's invoked with @Gemini, as reported by 9to5Google. Supported tools include Salesforce, ServiceNow, Jira, Git, BigQuery, Snowflake, Databricks, Microsoft Teams, and any server using the Model Context Protocol, the open standard for connecting agents to external systems. There's also a “coworker agent”: a persistent agent with a defined role that, in Google's description, receives a Workspace account with email, calendar, and Drive, and signs edits under its own name in document history. VentureBeat notes, though, that Google has not clarified whether each agent receives an account or only persistent coworker agents do.

The Model Is a Separate Choice: Gemini or Claude

Google frames it this way: Gemini is the agent and the underlying model is a separate choice. Today orchestration runs across the Gemini family and Claude models, with additional proprietary and open-source models planned later. Administrators decide which models are available, and a Smart Routing layer selects among permitted models based on task requirements and cost. According to Futurum, users can choose the model per task or use an automatic mode that starts with a fast model and escalates to a more powerful one when needed. Google claims that only 10 to 15 percent of a typical workflow requires a high-tier model, with an estimated cost saving of around one third. That figure comes from Google and has not been independently verified; Futurum's analyst describes it as technically credible but also a significant commercial concession.

On Claude specifically, sources say little. None identifies the version in use, none quantifies how much work runs on that model, and VentureBeat notes that Google has not clarified whether data is sent to external providers such as Anthropic, nor under what retention or residency terms. Futurum adds a market-level observation: Claude gains distribution and consumption revenue, but customers adopting Google's agent may use Anthropic's own interface less as a result.

Who Controls an Agent Running for Hours

Google's blog post frames security around four questions: who is the agent, what can it do, what has it done. What must it never touch. The stated answers are as follows. Every agent has its own identity, cryptographically attested and operating under least-privilege permissions. That identity appears in the logs. Permissions are role-based and approved by security administrators; for external systems, identity travels via standards such as OAuth. According to VentureBeat the agent accesses only files explicitly shared under Workspace permissions. Every action lands in a log attributed to the agent rather than to a human, monitorable in real time.

On containment, the agent runs inside an isolated environment called the Agent Sandbox, with its own network boundary. All inbound, outbound, and inter-agent traffic passes through the Agent Gateway, an AI-specific firewall that enforces policies in real time. Google gives the example of a rule preventing agents from opening documents classified as “need to know,” and VentureBeat adds that controls block workflows attempting to send sensitive data to unauthorized models. On costs, a hard spending cap is enforced per project: when it's hit, the project's agent pauses and can be resumed with a single click.

Four security questions for an AI agent and Google stated answers
Four security questions for an AI agent, with Google's stated answers

The overall design is that of a governed non-human identity, which Futurum analyst Nick Patience describes as “the right design” in his published analysis. Open questions remain. Google has not released independent benchmarks on agent reliability for long-running tasks that span multiple applications, and Patience notes that the breadth of a connector list says little about how much an agent can genuinely accomplish with each one. Accountability is already embedded in Claude's usage rules, which from November 12 onward establish that whoever builds or deploys an agent is also responsible for actions taken through connected tools, browsers, or systems.

Two Use Cases: Financial Research and Document Analysis

The examples closest to a real hours-long workload come from the financial sector, currently in preview. Google describes more than 50 core capabilities covering investment research, credit analysis, and risk modeling, drawing on sources including FactSet, LSEG, S&P Global, SEC filings, and proprietary archives, with confidence scores, documented methodologies, data traceability, and source citations. Named customers include CME Group and Deutsche Bank. DBS Bank, according to Google, uses chains of 70 to 80 agents for credit memos. This is precisely the kind of work European banks are already preparing to fund: Generali has allocated 325 million euros for AI, data, and automation in its 2027 plan, and Banca Popolare dell'Emilia Romagna sees AI as support for advisers on documentation and research, keeping client relationship responsibility with human staff.

On document analysis, Google cites Bradesco, which reports cutting document review time from one hour to five minutes with 60 percent fewer risk inconsistencies, Commerzbank, with documentary checks reduced from 20 hours to one, and Grupo Bafar, with contract preparation per branch cut from 140 minutes to 17. For the legal sector, also in preview, the agent inherits practice-level permissions and ethical walls between teams from NetDocuments and iManage. These are results declared by Google or its customers without independent validation, and Futurum observes that examples like Bradesco and DBS are scoped implementations with humans in the loop, not agents running unsupervised for multiple days.

Access, Availability, and Pricing

According to a Google Cloud spokesperson quoted by VentureBeat, the Gemini agent has been in private preview since today for a select group of customers, with broader availability promised “soon” but without a specific date. 9to5Google clarifies that the rollout will cover Workspace customers on certain Business and Enterprise plans, and that the product targets organizations rather than individual consumers. The only concrete timeline comes from Futurum, which reports that Google expects general availability by the end of October 2026, starting in North America; the firm flags European expansion as a key variable to watch, given data residency requirements. No indication has been found for availability in the UK or other specific markets outside North America.

On pricing, VentureBeat reports no additional cost for customers where Gemini Enterprise is already included, covering Workspace Business and Enterprise licenses, with detailed pricing promised closer to the general release. Futurum cites Gemini Enterprise at $30 per seat per month and notes that Google does not charge for extra seats but shifts costs onto tokens, compute, and spending caps. Pricing for persistent coworkers, long-horizon autonomous tasks, and sub-agents remains unspecified.

Source table on Gemini agent availability, with date and region indicated only by Futurum
Source table on Gemini agent availability, with date and region indicated only by Futurum

Gemini Agent at a Glance

What is confirmed, what is not. Sources: Google Cloud, VentureBeat, 9to5Google, Futurum

  • Confirmed: single agent with persistent memory, sub-agents and coworkers, separate model layer (Gemini or Claude), declared identity, permissions and action log, private preview for selected customers.
  • Not specified: regional availability outside North America, general availability date (only Futurum cites end of October, North America), coworker pricing, Claude version, data routing to model providers, independent benchmarks.
  • To watch: general availability date and regions, European data residency compliance, full pricing structure, connector documentation, and reliability limits for long autonomous tasks.

The Bigger Picture

By decoupling the agent from the model, Google turns the model itself into a replaceable component and shifts the actual lock-in elsewhere: memory, skills, connectors, identity, and audit logs. That reading aligns with Futurum's analysis, which treats this architectural choice as more consequential than any individual feature. For the financial sector, the implication is direct: an agent that routes work across multiple model providers expands the number of parties that can access data, unless administrators restrict which models are permitted. European supervisory authorities have already warned that EU finance depends on non-European AI providers, and Christine Lagarde has cautioned against systemic risks enabled by AI already embedded in banking and payments infrastructure. The question of who controls an agent is, at its core, also a question about concentration.

The next phase, when agents begin making payments autonomously, will make identity and spending limits even more critical. Google's spending cap applies to compute costs, not to financial transactions. Stripe and OpenAI have already published a protocol for AI agent commerce, where an agent completes a transaction without user approval at each step. None of the sources reviewed here mention crypto or blockchain directly; the connection to this sector lies in the convergence of agents, identity, and payments infrastructure. The race to build that infrastructure is itself a factor, illustrated by Google's €13 billion commitment in Finland.

The signals worth tracking are concrete: the general availability date and covered regions, European data residency terms, coworker pricing, Google's clarification on what reaches model providers, and the first independent reliability tests on long-horizon tasks. Until those answers arrive, the Gemini agent remains an announcement with a genuinely interesting governance design, not a verifiable tool for organizations operating under European regulatory frameworks.

Promotional content