Google's universal Gemini agent arrives in private preview

The enterprise agent race found its biggest entrant today, while a security research team showed just how badly shared cloud agent infrastructure can fail.
Google Cloud announced a universal Gemini agent that works across your apps, devices, and even other companies' tools. Unveiled at the Gemini at Work 2026 event on Thursday, the agent lives inside the Gemini Enterprise app and runs in the cloud, so it keeps the same context whether you talk to it from your phone, desktop, the web, or a third-party app like Slack or Microsoft 365. It works directly inside Workspace — Gmail, Drive, Docs, Sheets, Calendar — and it can spin up job-specific sub-agents or act as a "coworker agent" with its own identity and an @agents.company.com email address, picking whatever model best fits each task (VentureBeat reports Anthropic's Claude models are already supported, with more proprietary and open-weight models planned). The pitch is a single persistent assistant for workflows that last hours or days, not a chat box per app. It lands in a crowded field — Microsoft's Copilot agent platform, OpenAI's Dots, and Anthropic's Claude inside Workspace all shipped in the last two weeks — and Google's differentiator is the breadth of the surface it controls: the biggest email and calendar install base on earth plus the cloud to run the agent in. The catch is availability: it is enterprise-only, private preview, with no general-availability date, so today's announcement is a statement of direction rather than a product most readers can touch.
A single prompt to one public agent was enough to take over every AI agent in an AWS account, Zenity researchers found. The security firm's "AgentCorruption" chain exploited missing sandbox isolation in Amazon's Bedrock AgentCore platform: a plain-language request made a test agent query AWS's internal metadata service and hand over its own temporary credentials, which worked outside the platform entirely. Because AgentCore's default execution role applied region-wide rather than per-agent, those credentials let the researchers list every agent, pull all their container images and source code in seconds, read private user conversations, poison long-term memory for persistent hijacking, and pull secrets — including keys stored for services outside AWS. Zenity reported the findings on December 25, 2025; AWS since made the hardened metadata service the default for new deployments and tightened the default role, with the role changes first observed on September 29, 2026 — a gap of roughly nine months during which broad default permissions persisted. One caveat worth stating: Zenity sells an agent-security platform, so it has a business interest in this research; AWS's own remediation actions corroborate the underlying findings. Zenity CTO Michael Bargury frames the underlying tension plainly: "Cloud security is about segmentation and least-privilege access. But AI agents need creative freedom to be useful."
Harness acquired Augment Code's assets, folding its AI coding platform into the delivery pipeline. The deal — terms not disclosed, and it covers "select assets" rather than the whole company — brings over Cosmos, Augment's multi-agent code development platform, plus the Auggie command-line tool and the Code Context Engine, along with the team. Cosmos will be renamed Harness Cosmos Software Factory and handle the idea-to-code half, while Harness's existing agents take code through testing, security, and deployment to production. Augment had raised $227 million and Harness is valued at $5.5 billion, so this is a well-funded coding startup landing inside a delivery platform rather than burning through another round. The logic is that code generation and code delivery have been sold as separate products; customers who buy the story get one agent chain from prompt to production, and everyone else keeps using their existing tools.
What to watch: whether Google sets a general-availability date for the Gemini agent, and how many enterprises actually move to custom agent roles on AWS instead of relying on the tightened defaults.
Is a shared default role across every agent in a region an acceptable trade for making agents useful — or should cloud providers segment per agent by default? Tell us in the comments.




