Google seems to be making a strategic play to control the AI infrastructure layer, not just roll out another shiny new agent.
At its Gemini at Work 2026 event this week, the tech giant unveiled what it calls a “single, universal agent” and API in Gemini that can be kicked off from a simple prompt box. Like other available agents, it is plugged into skills, tools, and enterprise systems, can answer questions, create media, and write and run code, return finished work via of documents, inboxes, and developer environments, and spin up sub-agents to help it do its job.
But Google isn’t just looking to go toe-to-toe with existing offerings, or trying to convince enterprises its models are qualitatively and quantitatively superior, said independent tech analyst Carmi Levy.
“Instead, it’s trying to establish itself as the gatekeeper of the new enterprise operating system, powered by whatever underlying model makes the most sense,” he said.
Google says its Gemini agent works autonomously from a single interface, and can function as a personal assistant or team member, akin to a project manager or analyst. Coworker agents can perform tasks across days, sessions, and shifting responsibilities; they have dedicated identities, and are given their own @agents.company.com emails and persistent storage.
However, Google says, they only have access to specifically-defined data and channels. Enterprise-dictated security, governance, and cost controls are built-in.
“You give it objectives, not instructions,” Google Cloud CEO Thomas Kurian said in his keynote. “Work now starts in the prompt window.”
The agent runs in the cloud and has “omnipresent access,” meaning it can work on nearly any device, including iOS and Android phones or Windows and Mac desktops, he said. It can also be accessed through any channel, including command line interfaces (CLIs), Google Workspace, Microsoft 365, or Slack channels, and when integrated into third-party apps. When needed, it also works as a headless agent, or even without a dedicated user interface.
Working autonomously, the Gemini agent can spin up temporary or job-specific underlying agents and communicate and coordinate workflows with them to orchestrate multi-step tasks. These include parallel and sequential steps that might run for hours or days, Google said.
Notably, the agent is given the flexibility to choose which model should drive different workflows, to improve quality and reduce cost; right now, those models include the Gemini family and Claude, but Google says it will soon expand capabilities to other leading private and open models.
This is important because the leading model changes every few months, Kurian noted, and “the best model for the task is not always the largest one.”
Mahmoud Ramin, a research director at Info-Tech Research Group, noted that Google’s announcement does not create a whole new category, since OpenAI, Anthropic, Microsoft, and Meta have already positioned multiagent capabilities in their platforms.
What is interesting with Gemini, though, is that not only can it operate directly in multiple Google products like Gmail, Drive, Sheets, and Slides, it also connects to external systems. It is, of course, a good fit for those already using the Google environment, he noted, and the strongest use cases are around repetitive tasks and information synthesis, such as that described in the research performed by project managers, analysts, and marketing specialists.
Levy agreed that Google’s unique value proposition revolves around choice. “It separates the agent from the underlying model, and allows enterprises to use whatever model makes sense for a given workload,” he said.
Its role-based agents are also “compellingly unique,” because they allow enterprises to create agents optimized for specific roles; meanwhile, more granular permission-setting addresses growing concerns about automated bots going off the rails.
While OpenAI and Microsoft have made similar claims, Google is “arguably leading the conversation around identity, audit trails, and who, or what, is ultimately responsible for workflows,” Levy said. As the AI industry pivots beyond mere chatbots toward its “inevitably agentic future,” the role of companies like Google, OpenAI, Anthropic, Microsoft, and others in the role of gatekeepers comes into sharper focus, Levy noted. The defining layer has shifted from operating systems to browsers, apps, cloud platforms, and now large language models (LLMs).
In the agentic rush, key players are racing to establish their role in enterprise workflow infrastructure. “The agent layer could be the ultimate prize of the AI era, and it largely explains why every vendor announcement seems to essentially claim the same thing,” Levy said.
But Google has to convince IT decision makers that its agentic roadmap is better than the competition’s; this means shifting the AI conversation to autonomy, rather than just basic tasks.
Like virtually every other vendor’s agent, Google’s Gemini agent can write an email, tweak a spreadsheet, and build a presentation. “However,” Levy said, “whether CIOs and CISOs can trust it to run mission critical business processes indefinitely without doing something stupid enough to generate damaging headlines is another story altogether.”
“Will enterprises care? If they’re already heavily invested in Google’s workplace stack, this could be an easier sell in the C-suite,” he noted.
Info-Tech’s Ramin noted that whatever platform enterprises choose, the front-and-center focus going forward should be who controls AI agents.
“As organizations unleash the power of agent autonomy, it raises the pivotal and non-negotiable requirement of enforcing governance,” he said, noting that with basic AI systems, risk is “much more contained” compared to that of an autonomous agent that has access to multiple business systems and can communicate with other agents.
In the latter case, enterprises should significantly enforce guardrails, including permissions, identity, human oversight, and system audits, he said. They should “clearly outline which decisions the agent is allowed to make, what data should be accessed, and how performance will be monitored.”