Industry story
Google launches unified agentic Gemini for enterprise, with Anthropic Claude integration
agents model-pricing orchestration security tool-use
At a Google Cloud event, Google announced a new unified AI agent built on Gemini that goes beyond question-answering to autonomously complete multi-step tasks — such as scheduling, coding, and navigating internal business systems — on behalf of users. The agent accepts high-level objectives (not just commands), plans its own workflow, delegates to subagents, and connects to enterprise tools including Google Workspace, Microsoft 365, Slack, Jira, Databricks, Snowflake, and any Model Context Protocol (MCP) server. Notably, the agent gets its own Workspace account with its own email address, acting as a virtual co-worker with awareness of org structure, calendars, and approval chains.
Google is prioritizing enterprise rollout before consumers, citing the need to solve harder problems around security, scale, and performance at scale. Users can override the default model selection and choose third-party models, starting with Anthropic's Claude — with open-source and other private models to follow. Sundar Pichai noted Gemini has over 1 billion monthly active users and is used by nearly 90% of Fortune 100 companies via Gemini Enterprise. Early testers included Shopify and PayPal.
Analysis
Showing the shorter version.
Google launched a unified Gemini agent for enterprise. It takes a goal, plans the steps, splits work among sub-agents, and connects to Workspace, Microsoft 365, Slack, Jira, Databricks, Snowflake, and any MCP server (the open standard for letting AI call outside tools). The agent gets its own Workspace account and email address, sitting inside your org chart like a coworker. You can also swap Google's Gemini for Anthropic's Claude mid-task.
The Claude integration reveals where Gemini actually stands. If Gemini were winning on coding and long-context work, Google would not route to a direct competitor inside its own product. The multi-model router is sound engineering and an admission of weakness at the same time. Both are true.
The account is the real issue. Giving the agent a Workspace identity creates a legitimate audit trail, which is genuinely useful. It also adds a brand-new actor to your trust graph that prompt injection can hijack. A poisoned calendar invite or a planted Slack message can instruct the agent to move data, approve a purchase, or edit a ticket, and every action logs as legitimate because the agent is a legitimate principal. Google already blinked by holding consumer back, citing security. That means the consumer version was worse.
The announcement says nothing about sandboxed execution, action rate limits, or mandatory human sign-off before irreversible actions. Those omissions matter more than anything in the demo.
Cost math. One five-step task spawning three sub-agents, each making two tool calls, can burn ten times the tokens of a single answer. Add cross-provider latency from routing to Claude, plus Snowflake and Databricks query costs, and the all-in price per completed task will surprise anyone whose mental model is "a few cents a prompt."
The enterprise buyer's actual checklist. Who is liable when the agent approves the wrong invoice? Where does the data sit when it queries Snowflake? Can I revoke access across all five systems in one click? Which data-processing agreement covers the Anthropic calls? None of that is in the announcement. Buyers who already pay for Workspace will pilot this because it is already there. They will not wire it to anything that touches money until the controls are written down.
Before connecting this to any billing or procurement workflow, test it on your own messy data and ask in writing for the revocation, rate-limit, and human-approval controls. If they are not contractually available, this is a smart assistant, not a coworker.
Prediction: At Google Cloud Next in April 2027, the Gemini enterprise agent will still require human approval before any irreversible action, payments, external email, production changes, with no default fully-autonomous mode for money-touching workflows. The liability and injection exposure forces a human checkpoint. No vendor absorbs the risk of a fully autonomous agent approving a wrong payment at Fortune 100 scale, and no enterprise buyer signs for it without a human gate.
Google put out a new Gemini agent for businesses. It does not just answer questions. It takes a goal, plans the steps, splits the work among smaller helper agents, and plugs into Workspace, Microsoft 365, Slack, Jira, Databricks, Snowflake, and any MCP server (the open standard for letting an AI call outside tools). The part everyone will fixate on: the agent gets its own Workspace account and its own email address, so it sits inside your org chart like a coworker. And you can swap Google's own Gemini out for Anthropic's Claude mid-task.
The decision this forces on a business reader is not "do I switch to Gemini." It is "do I let a non-human employee hold credentials across my entire stack." That is hard to undo once it is wired in. No deadline is set; this ships to enterprise first, consumer later, and nobody has to move this quarter.
The Skeptic. Google has done this show before. Duet AI, Workspace AI, Bard Enterprise. Strong demo, slow uptake, every time. The "nearly 90% of the Fortune 100" line counts seat licenses, not people actually letting an agent approve purchases. Giving the thing an email address is a UX trick, not proof it works. And the Claude option tells you something: if Gemini were winning on coding and long-context work, Google would not be routing to a direct competitor inside its own product. Real agentic work needs tool calls that succeed better than 99 times in 100 across many steps. No public test shows Gemini or Claude there yet on messy enterprise tasks. Shopify and PayPal piloted the easy workloads.
The Safety Lens. This is the first time a non-human account sits inside the approval chain at this scale, and the attack math is ugly. A poisoned calendar invite or a planted Slack message can now tell the agent to move data, green-light a purchase, or edit a Jira ticket, and every action logs as legitimate because the agent is a legitimate principal. That is prompt injection with a badge. Google naming "security" as the reason to delay consumer is comforting as a sentence and worrying as a signal: it means the consumer version was worse. The announcement says nothing about sandboxed execution, action rate limits, or a mandatory human sign-off before anything irreversible. MCP's open-server model widens the door further.
The Researcher. The real concession here is the Claude integration. Google is admitting out loud that no single model wins every subtask, so they built a router that sends work to the best model for the job. That is an architecture decision, not a courtesy to Anthropic. The agent's own Workspace identity is the more interesting idea: tie every action to a named account and you get an audit trail, which is genuinely useful for provenance. But you have also added a brand-new actor to every org's trust graph, and nobody has stress-tested what that does when thousands of them run at once.
The Enterprise Buyer. A CTO does not sign for "objectives, not just instructions." A CTO signs for: who is liable when the agent approves the wrong invoice, where does the data sit when it queries Snowflake, and can I revoke this account's access across all five systems in one click. None of that is in the announcement. The model-swap feature is a procurement headache, not a feature: if the agent used Claude on Tuesday and Gemini on Thursday, whose indemnification covers the output, and which data-processing agreement governs the Anthropic calls. Buyers who already pay for Workspace will pilot this because it is sitting right there. They will not wire it to anything that touches money until the controls are written down.
The Compute Pragmatist. Helper agents multiply the bill in a way per-query pricing hides. One five-step task that spawns three subagents, each making two tool calls, can burn ten times the tokens of a single answer. Routing to Claude means Google eats cross-provider latency and token cost at orchestration time, which only makes sense if Gemini cannot close the quality gap on its own. Add Snowflake and Databricks query costs on top of inference, and the all-in cost per completed task will shock people whose mental model is "a few cents a prompt." The first month's bill is the reality check.
Where they split. The Researcher sees the multi-model router as the honest, grown-up design. The Skeptic and the Compute Pragmatist see the same feature as evidence Gemini is behind and as a cost bomb. Both can be right: best-of-breed routing is smart engineering and an admission of weakness. The other split is more consequential. The Safety Lens and the Enterprise Buyer are looking at the identical feature, the agent's own account, and reaching opposite conclusions. The Researcher calls it auditable provenance. The Safety Lens calls it a legitimate principal that prompt injection can hijack. The deciding question is whether Google ships hard controls, scoped and revocable access, rate limits, mandatory human sign-off on irreversible actions, before anyone trusts it with money or data.
What it hinges on. Not whether the demo is impressive. It is. It hinges on two things a buyer can actually check: does the agent complete multi-step tasks reliably enough to trust unattended, and are there real guardrails on what a hijacked agent can do. Before anyone wires this into a billing or procurement workflow, run your own test on your own messy data, not Google's pilot set, and ask in writing for the revocation, rate-limit, and human-approval controls. If they are not contractually available, this is a smart assistant, not a coworker.
Prediction: At Google Cloud Next in April 2027, the Gemini enterprise agent will still require human approval before any irreversible action (payments, external email, production changes), with no default fully-autonomous mode for money-touching workflows.
Confidence: Medium. The liability and injection exposure forces a human checkpoint; Google cannot eat that risk.
Why: The agent holds a real account inside the approval chain, which means a poisoned Slack message or calendar invite can instruct it to move money or data, and every action logs as legitimate. Google already blinked once by holding consumer back and citing security, so they know the exposure. No vendor absorbs the liability of a fully autonomous agent approving a wrong payment at Fortune 100 scale, and no enterprise buyer signs for it without a human gate. The opposite outcome, a shipped default autonomous mode for irreversible actions within a year, would require Google to accept open-ended indemnification risk that no DPA or insurer prices yet. That is the less likely path.
Revisit by 2027-04-30: We're right if, at or after Google Cloud Next 2027, the agent still gates payments, external email, and production changes behind human approval by default. We're wrong if Google ships a default mode that lets the agent complete money-touching or irreversible workflows end-to-end with no human sign-off.
Also covered this issue
-
Dario Amodei Calls for AI Capability Slowdown; Altman and Musk Agree
semianalysis
Three AI CEOs announced a voluntary slowdown with no enforcement mechanism, but your API costs and model capabilities won't actually change.
-
AI Leaderboard Arena Raises $200M at $3.1B Valuation
techcrunch-ai
A startup's $3.1 billion valuation now hinges on whether its crowd-voted rankings become the standard your company uses to pick which AI model to deploy and trust.
-
Fired OpenAI safety researchers deny misconduct, warn of chilling effect
techcrunch-ai
Fired safety researchers warn that OpenAI now punishes external safety review, quietly weakening the oversight you rely on without knowing it.
Comments