Story
October 9, 2026
Google’s Gemini Agent Wants to Be Your Coworker—Security Experts See a Bigger Risk
Google casts Gemini Agent as a universal coworker that can take high-level objectives and execute work across an organisation’s tools. Security specialists agree that a dedicated identity and audit trails are useful, but argue that autonomy at this scale demands strict, continuously monitored limits.
At Google Cloud’s Gemini at Work event on Thursday, the company introduced Gemini Agent, pushing its AI beyond answering prompts and toward completing assigned work across corporate systems. CEO Sundar Pichai described it as a “single, universal agent for work” with a company’s business context, capable of handling knowledge work, creating content and coding.
1
Google’s initial bet is enterprise deployment, not a broad consumer launch. The agent is in private preview for business customers and can work across Workspace, Microsoft 365, Slack and other connected applications, while retaining context in the cloud across devices.2 Pichai has said the business-first rollout gives Google room to address the harder questions of “security, scale, and performance” that accompany more powerful agents.3
The shift is significant because Gemini is being positioned less as a chatbot than as an employee-like participant. Google Cloud CEO Thomas Kurian said users give it “objectives, not just instructions”: the system can plan work, use tools and skills, and connect to internal business systems.3 It has its own Workspace account, can be brought into chats or email threads, and records an audit trail under the agent’s identity rather than a human user’s.3
That design is precisely where the security argument sharpens. Andrea Sivieri, chief product and technology officer at CoreView, called an agent identity and access limited to what colleagues share “a prudent step,” but said those controls are insufficient by themselves.4
His warning is blunt: an agent with administrative privileges could alter permissions, weaken controls or expose sensitive data across a Microsoft 365 environment before anyone notices. “A single mistake could rapidly become a business-wide security incident,” Sivieri said, urging clear access boundaries, constant visibility and a record of every action.4
Google’s proposition is therefore simple but high-stakes: make AI useful enough to act like a coworker, while proving it can be governed more tightly than one.