Refacto AI

Industry story

Google launches unified agentic Gemini for enterprise, with Anthropic Claude integration

agents model-pricing orchestration security tool-use

At a Google Cloud event, Google announced a new unified AI agent built on Gemini that goes beyond question-answering to autonomously complete multi-step tasks — such as scheduling, coding, and navigating internal business systems — on behalf of users. The agent accepts high-level objectives (not just commands), plans its own workflow, delegates to subagents, and connects to enterprise tools including Google Workspace, Microsoft 365, Slack, Jira, Databricks, Snowflake, and any Model Context Protocol (MCP) server. Notably, the agent gets its own Workspace account with its own email address, acting as a virtual co-worker with awareness of org structure, calendars, and approval chains.

Google is prioritizing enterprise rollout before consumers, citing the need to solve harder problems around security, scale, and performance at scale. Users can override the default model selection and choose third-party models, starting with Anthropic's Claude — with open-source and other private models to follow. Sundar Pichai noted Gemini has over 1 billion monthly active users and is used by nearly 90% of Fortune 100 companies via Gemini Enterprise. Early testers included Shopify and PayPal.

Analysis

Showing the shorter version.

Google launched a unified Gemini agent for enterprise. It takes a goal, plans the steps, splits work among sub-agents, and connects to Workspace, Microsoft 365, Slack, Jira, Databricks, Snowflake, and any MCP server (the open standard for letting AI call outside tools). The agent gets its own Workspace account and email address, sitting inside your org chart like a coworker. You can also swap Google's Gemini for Anthropic's Claude mid-task.

The Claude integration reveals where Gemini actually stands. If Gemini were winning on coding and long-context work, Google would not route to a direct competitor inside its own product. The multi-model router is sound engineering and an admission of weakness at the same time. Both are true.

The account is the real issue. Giving the agent a Workspace identity creates a legitimate audit trail, which is genuinely useful. It also adds a brand-new actor to your trust graph that prompt injection can hijack. A poisoned calendar invite or a planted Slack message can instruct the agent to move data, approve a purchase, or edit a ticket, and every action logs as legitimate because the agent is a legitimate principal. Google already blinked by holding consumer back, citing security. That means the consumer version was worse.

The announcement says nothing about sandboxed execution, action rate limits, or mandatory human sign-off before irreversible actions. Those omissions matter more than anything in the demo.

Cost math. One five-step task spawning three sub-agents, each making two tool calls, can burn ten times the tokens of a single answer. Add cross-provider latency from routing to Claude, plus Snowflake and Databricks query costs, and the all-in price per completed task will surprise anyone whose mental model is "a few cents a prompt."

The enterprise buyer's actual checklist. Who is liable when the agent approves the wrong invoice? Where does the data sit when it queries Snowflake? Can I revoke access across all five systems in one click? Which data-processing agreement covers the Anthropic calls? None of that is in the announcement. Buyers who already pay for Workspace will pilot this because it is already there. They will not wire it to anything that touches money until the controls are written down.

Before connecting this to any billing or procurement workflow, test it on your own messy data and ask in writing for the revocation, rate-limit, and human-approval controls. If they are not contractually available, this is a smart assistant, not a coworker.

Prediction: At Google Cloud Next in April 2027, the Gemini enterprise agent will still require human approval before any irreversible action, payments, external email, production changes, with no default fully-autonomous mode for money-touching workflows. The liability and injection exposure forces a human checkpoint. No vendor absorbs the risk of a fully autonomous agent approving a wrong payment at Fortune 100 scale, and no enterprise buyer signs for it without a human gate.

Also covered this issue

Comments