Kategorie
Google wants to be the gatekeeper for enterprise AI agents
Google seems to be making a strategic play to control the AI infrastructure layer, not just roll out another shiny new agent.
At its Gemini at Work 2026 event this week, the tech giant unveiled what it calls a “single, universal agent” and API in Gemini that can be kicked off from a simple prompt box. Like other available agents, it is plugged into skills, tools, and enterprise systems, can answer questions, create media, and write and run code, return finished work via of documents, inboxes, and developer environments, and spin up sub-agents to help it do its job.
But Google isn’t just looking to go toe-to-toe with existing offerings, or trying to convince enterprises its models are qualitatively and quantitatively superior, said independent tech analyst Carmi Levy.
“Instead, it’s trying to establish itself as the gatekeeper of the new enterprise operating system, powered by whatever underlying model makes the most sense,” he said.
‘Omnipresent access,’ orchestration capabilitiesGoogle says its Gemini agent works autonomously from a single interface, and can function as a personal assistant or team member, akin to a project manager or analyst. Coworker agents can perform tasks across days, sessions, and shifting responsibilities; they have dedicated identities, and are given their own @agents.company.com emails and persistent storage.
However, Google says, they only have access to specifically-defined data and channels. Enterprise-dictated security, governance, and cost controls are built-in.
“You give it objectives, not instructions,” Google Cloud CEO Thomas Kurian said in his keynote. “Work now starts in the prompt window.”
The agent runs in the cloud and has “omnipresent access,” meaning it can work on nearly any device, including iOS and Android phones or Windows and Mac desktops, he said. It can also be accessed through any channel, including command line interfaces (CLIs), Google Workspace, Microsoft 365, or Slack channels, and when integrated into third-party apps. When needed, it also works as a headless agent, or even without a dedicated user interface.
Working autonomously, the Gemini agent can spin up temporary or job-specific underlying agents and communicate and coordinate workflows with them to orchestrate multi-step tasks. These include parallel and sequential steps that might run for hours or days, Google said.
Notably, the agent is given the flexibility to choose which model should drive different workflows, to improve quality and reduce cost; right now, those models include the Gemini family and Claude, but Google says it will soon expand capabilities to other leading private and open models.
This is important because the leading model changes every few months, Kurian noted, and “the best model for the task is not always the largest one.”
Choice a ‘unique value proposition’Mahmoud Ramin, a research director at Info-Tech Research Group, noted that Google’s announcement does not create a whole new category, since OpenAI, Anthropic, Microsoft, and Meta have already positioned multiagent capabilities in their platforms.
What is interesting with Gemini, though, is that not only can it operate directly in multiple Google products like Gmail, Drive, Sheets, and Slides, it also connects to external systems. It is, of course, a good fit for those already using the Google environment, he noted, and the strongest use cases are around repetitive tasks and information synthesis, such as that described in the research performed by project managers, analysts, and marketing specialists.
Levy agreed that Google’s unique value proposition revolves around choice. “It separates the agent from the underlying model, and allows enterprises to use whatever model makes sense for a given workload,” he said.
Its role-based agents are also “compellingly unique,” because they allow enterprises to create agents optimized for specific roles; meanwhile, more granular permission-setting addresses growing concerns about automated bots going off the rails.
While OpenAI and Microsoft have made similar claims, Google is “arguably leading the conversation around identity, audit trails, and who, or what, is ultimately responsible for workflows,” Levy said.
Google and others looking to be ‘gatekeepers’As the AI industry pivots beyond mere chatbots toward its “inevitably agentic future,” the role of companies like Google, OpenAI, Anthropic, Microsoft, and others in the role of gatekeepers comes into sharper focus, Levy noted. The defining layer has shifted from operating systems to browsers, apps, cloud platforms, and now large language models (LLMs).
In the agentic rush, key players are racing to establish their role in enterprise workflow infrastructure. “The agent layer could be the ultimate prize of the AI era, and it largely explains why every vendor announcement seems to essentially claim the same thing,” Levy said.
But Google has to convince IT decision makers that its agentic roadmap is better than the competition’s; this means shifting the AI conversation to autonomy, rather than just basic tasks.
Like virtually every other vendor’s agent, Google’s Gemini agent can write an email, tweak a spreadsheet, and build a presentation. “However,” Levy said, “whether CIOs and CISOs can trust it to run mission critical business processes indefinitely without doing something stupid enough to generate damaging headlines is another story altogether.”
“Will enterprises care? If they’re already heavily invested in Google’s workplace stack, this could be an easier sell in the C-suite,” he noted.
Raising important governance questionsInfo-Tech’s Ramin noted that whatever platform enterprises choose, the front-and-center focus going forward should be who controls AI agents.
“As organizations unleash the power of agent autonomy, it raises the pivotal and non-negotiable requirement of enforcing governance,” he said, noting that with basic AI systems, risk is “much more contained” compared to that of an autonomous agent that has access to multiple business systems and can communicate with other agents.
In the latter case, enterprises should significantly enforce guardrails, including permissions, identity, human oversight, and system audits, he said. They should “clearly outline which decisions the agent is allowed to make, what data should be accessed, and how performance will be monitored.”
FBI disrupts Chinese hacking tools used to breach critical infrastructure
ICANN’s new TLD land rush draws 13 applicants for dot-agent alone, with AI a focus for new names
When ICANN revealed the 1,615 applications for new top-level domains (TLDs) on Wednesday, it provided a peek into efforts to control mindshare and organization perceptions via URL naming.
Existing TLDs include .com, .org, .net, .edu and .gov, as well as country-specific TLDs such as .uk and .ca, and an already long list of generic ones, but ICANN envisions even further expanding the number globally, potentially also expanding the headaches for IT teams who must manage routing, allowlists, and blocklists.
Judging from the number of applicants, there’s considerable enthusiasm for ICANN’s notion.
Although it will be months before ICANN officials can whittle down the list of applications, sort out multiple requests for some TLDs, and ultimately decide who gets which one, Meta seems to be in the tech lead for attempts, with 21 requests, including .aiglasses, .facebook, .instagram, .llama, .messenger, .meta, .metaai, .metaglasses, .metaverse, .muse, .superintelligence, .threads, .vrs, .wearables and .whatsapp. It is also one of 13 organizations seeking to grab .agent.
OpenAI made 15 requests, for everything from the obvious, such as .chatgpt and .openai, to .asi, .codex, .deploy, .evals, .gpt, .mcp, .model, .oai and even .skill and .voice. It, too, is after .agent, and is one of seven trying to register .agi (signifying artificial general intelligence, AI’s Holy Grail).
Amazon submitted applications for eight TLDs, including .alexa, .echo, .eero, .kgs, .kuiper, .leo, .ring and .twitch. Despite its plethora of products, Microsoft only sought two: .msft and .copilot. OpenClaw also asked for two, specifically .claw and .oss, as did Anthropic, which only requested .anthropic and .claude.
Although it’s unclear who, if anyone, will ultimately get either .superintelligence or .si, the battle for those domains is already being fought. And to counter the AI focus, six organizations are looking to acquire the .human TLD.
“Reveal Day marks an important milestone for the next expansion of the Domain Name System,” said Kurtis Lindqvist, president and chief executive officer of ICANN, in its announcement. “These applications demonstrate how organizations around the world are innovating new ways to build trusted online identities, serve their communities, and connect with internet users. ICANN remains focused on administering a fair, transparent, and predictable evaluation process grounded in the policies developed by our global multistakeholder community.”
Now that the initial list has been published, ICANN’s process gives applicants who also applied for a second choice two weeks to potentially switch. “Applicants may switch to the replacement string only during this period, and only if their replacement string is eligible. If the replacement string is identical to another applied-for primary string, or another replacement string, it cannot be used,” the site said. “Applicants should be aware that replacement strings could end up in contention in the later stages of the program.”
Once that period, known as the string replacement period, has wrapped, a final list will be published, marking the start of the 104 day Community Input and Objections Period during which members of the general public, the ICANN community, governments, and other parties can provide input, raise concerns, or formally object to new generic top-level domain (gTLD) applications before final decisions are made.
Ransomware attack disrupts Japan's IDCF Cloud used by govt clients
Low-cost Android phones ship with residential proxy malware
FBI Says China-Linked Hackers Ran Portal Giving Third Parties Access to Stolen Emails
ThreatsDay: Ransomware Affiliate Betrayal, WhatsApp RAT, Exposed Hacker Tools and 12 More Stories
FakeGit malware campaign returns with 17,610 malicious GitHub repos
Microsoft will let Copilot act on local files on Windows PCs
Microsoft is giving Copilot greater control over Windows PCs, allowing the AI assistant to organize and make changes to local files, and run certain tasks using on-device AI models.
The changes were announced at Microsoft’s Hybrid Intelligence event, where it outlined plans to combine local and cloud AI processing to help customers reduce AI costs and retain more control over data.
Three new Copilot capabilities will be available to Copilot+ PC users “in the coming months,” Microsoft said.
One is the ability for Copilot to access local files and recent user activity, providing additional context for the AI assistant’s outputs.
Copilot will also be able to perform actions on a device, such as moving files and changing settings.
“It has the same level of the ability to control and change things that I do as a user, but always with permission,” said Jacob Andreou, Microsoft EVP, Copilot, during the event.
The capability sounds similar to Copilot Actions, an “experimental” feature that Microsoft announced last year in preview for Windows Insiders at the time.
Finally, there will be an option to run Copilot on local AI models for certain tasks, only accessing cloud servers “when needed,” Microsoft said.
“Copilot will still use the cloud for the hardest tasks,” said Andreou, “but for times when cost or privacy matter more, it can delegate down to local models that run directly on your computer.”
Microsoft’s hybrid model reflects market demand, noted Biswajeet Mahapatra, principal analyst at Forrester. “The demand we see is not for AI that runs exclusively on-device, but for AI that can intelligently decide which workloads should run locally and which belong in the cloud,” Mahapatra said. “Enterprises increasingly want both options available.”
In a demo, Andreou also showed how the ability to access and interact with local files will increase the usefulness of Autopilot (formerly called Scout), the long-running Copilot agent that can be set to work continuously in the background. (Autopilot is currently in private preview.) Autopilot can also run on locally hosted models, he added, helping reduce costs and avoid sending private data to the cloud.
Microsoft also announced more powerful hardware — including the Surface Laptop Ultra and Surface RTX Spark Dev Box — and more efficient AI models designed to run on devices.
“Most companies are still getting their heads around AI, token usage, which models to use, and where to run them,” said Tom Mainelli, group vice president, Device & Consumer Research, at IDC. “As these companies get more savvy and look to scale AI to more employees, the need to run AI locally — including Microsoft Copilot — will increase.”
Current business laptops have some local AI capabilities and features, said Mainelli, but still largely rely on Copilot running in the cloud. This could change once more advanced hardware is broadly available, he said.
“As more systems ship with the right combination of CPU, GPU, NPU, and memory, and as local models continue to improve, I expect more AI jobs to run on the device,” said Mainelli.
For now, the installed base of enterprise PCs “remains highly mixed,” said Mahapatra.
“While Microsoft highlighted new AI-capable hardware, and noted that a growing share of business laptops are Copilot+ PCs, most enterprise fleets will take several years to refresh,” he said.
“The immediate opportunity is therefore concentrated among organizations already investing in AI PCs and high-performance devices. Many enterprises will continue to rely primarily on cloud-hosted AI while selectively adopting local AI capabilities as refresh cycles progress.”
Microsoft is also attempting to address security when running agents on-device. This includes the general availability launch of Microsoft Execution Containers (MXC) on Windows 11, which allows organizations to set up policies that define which files and networks agents can access. MXC is supported by a range of agent tools, including OpenAI’s Codex and OpenClaw, with Anthropic Claude Code, Box, Manus, and others to follow.
Added security measures should give business customers more confidence when enabling Copilot to access local files, said Mainelli. “That’s what Microsoft is bringing to the table: a level of security and traceability in these processes that should give companies confidence in using them,” he said. “Microsoft took major steps in telling that story today, and we’ll see how companies respond.”
Enterprises should manage agents on Windows devices “in the same way they approach any automation platform: trust should be based on controls, not on the AI itself,” said Mahapatra.
“Microsoft’s announcement is significant because it acknowledges that agents require a different security model than traditional applications,” he said. “Technologies such as Microsoft Execution Containers are designed to limit what agents can access, identify which agent took an action, and enforce policy-based controls.”
At the same, he warned against granting broad autonomous access to local files without appropriate governance. “Role-based access, read-only assistance, document summarization, search, and workflow support are likely to be adopted more quickly than autonomous file modification or business process execution,” Mahapatra said.
“As agents move from providing recommendations to taking actions, organizations will need stronger approval controls, monitoring, auditing, and human oversight. This is especially important for agents interacting with sensitive data, regulated processes, or systems of record.”
Japan Sees Sharp Rise in Web Data Leaks Amid Mobile API Abuse and Metabase Attacks
UAC-0099 Targets Ukrainian Government Personnel With ASHVEIN RAT Hiding Commands in HTML
Cisco warns of critical flaws allowing Nexus switch takeover
Fast AI, slow rollback: the risk facing Apple IT teams
There’s a big disconnect between the rate at which IT is deploying various kinds of AI-generated output and the speed with which it can roll those changes back when things go wrong, warns a new report from Fleet Device Management. It’s almost as if the rush to embrace AI has eclipsed the need to manage its deployment effectively.
The research, based on a survey of more than 250 enterprise IT practitioners managing Apple devices, is available in full via the company’s website and echoes similar concerns I’ve heard from others in the space. I spoke with Fleet founder and CEO Mike McNeil to get his take on the disconnect.
What’s happening in the enterpriseFirst, some of the stats gathered in the survey:
- 86% of respondents allow AI-written output to reach production devices following some review.
- 61% used AI to author an MDM profile/configuration in the past month.
- 62% used it to write scripts/code.
- 69% can’t roll back a bad configuration within an hour; 43% need more than a day.
- About a quarter (26%) can recover the same day but only with manual intervention.
McNeil stressed the challenge exposed by this data. “When one of those changes is wrong, 69% can’t undo it within an hour, and 43% need more than 24 hours,” he said. “So the exposure is real even without a count of incidents. The AI tool isn’t what gets pulled back. The configuration it produced is, and most teams do that by hand.”
The risk of moving too fastHe told me that just 7.6% of Fleet’s customers are exclusively Mac shops, confirming that most Fleet clients manage multiple platforms. It’s not a platform-specific challenge; McNeil sees this as a problem for all of them.
“I’d frame risk by two things: how much privilege the code runs with and how hard recovery is,” he explained, noting the risk of scripts running at root, which can take full control of the machine to the extent that reversion can’t undo what’s done.
“Windows and Linux have the most scripting-heavy management, so they have the most room for script-level mistakes,” he said — but even iOS is at risk from a bad restriction or network profile, particularly when attempting to recover remotely.
He pointed out: “36% of respondents manage Apple devices through Intune, a Windows-first platform. Tooling built around one platform’s assumptions tends to be weakest at the edges of another’s.”
Why MDM is a high-risk toolFor Apple in the enterprise, the risk is inherent to device management and IT’s power to use MDM to deploy a potentially poorly crafted AI tool at scale.
“MDM is one of the few trusted paths that can bypass the [macOS platform security] prompts, which is exactly why a bad or malicious MDM-delivered change is so consequential,” he warned.
He continued: “Windows has a larger and older attack ecosystem, with more legacy surface area. Linux gives administrators the most freedom and the fewest guardrails. On every platform, the management channel is the high-value target, so the same controls apply — review, least privilege, a change record, and a fast revert.”
The risk is that poorly crafted AI-generated MDM profiles can set off a chain of problems that can take days to resolve, particularly in large-scale device deployments. The problem is that unless there’s a clear audit record, it’s harder to remediate errors.
“AI speeds up authoring, but review capacity stays the same,” McNeil said. “Without a gate, errors and anything malicious in a script reach production faster.”
Speed needs to be managedUltimately, while AI can accelerate a multitude of IT tasks, the speed of deployment must also be matched by robust review and strong rollback tools. “Speed is only an advantage if recovery keeps pace,” he said.
Fleet’s core argument is that IT needs to change how it approaches what it does. “Mac administration is an engineering discipline now, and these admins are further along than the industry thinks,” he said. “The infrastructure around them hasn’t caught up.”
How should IT approach this? McNeil suggests a succession of protections his own MDM system already supports through GitOps with YAML files, adding, “the pattern works with any tool that has an API.”
- Treat device configuration like application code.
- Profiles, scripts, and policies should live as files in a Git repository.
- A change arrives as a pull request, a second person reviews it, and automation applies it to devices.
- To undo it, you revert the commit.
“One caveat: a revert fixes what the configuration says. It doesn’t undo a script that has already run. That’s an argument for preferring declarative configuration over imperative scripts where you can,” he advised.
Less clicking, more engineeringNone of these cautions are arguments against use of AI in enterprise IT, of course. They are arguments to promote a more conscious management system around the use of it. All the same, as AI proliferates, the Fleet CEO does think IT pros must anticipate a change in their roles. “Less clicking, more engineering,” he said.
“As AI takes on more of the mechanics like creating configuration profiles, drafting scripts, and troubleshooting routine issues, admins can spend less time figuring out how to make a change and more time deciding what should change, how it affects the business and where human judgment is required,” he said.
Finally, I pointed to the ongoing dilemma between Apple and IT. Some people complain Apple doesn’t innovate in the enterprise fast enough, others say it innovates too fast. What does Fleet think?
“Keeping up with Apple’s release pace was the single most cited hardest part of the job, at 31%,” he told me. “Budget and headcount came last, at 5%. Admins aren’t complaining that Apple ships too little. They’re stretched by the yearly OS cycle, new frameworks, and deprecations.”
“My own view is that the direction is right,” he said. “Declarative Device Management and tighter platform security are good for enterprises. The pace is the issue, and it’s the main reason admins need automation and a safety net.”
Now please subscribe to my daily, human-curated Apple-related news headline feed at The Core, or follow me on BlueSky, LinkedIn, or Mastodon.
ARTEX AI Pentesting Tool Used in Data Theft Attacks on South Korean Financial Firms
OAuth grants pile up faster than you can review them. Here's how to keep up.
Uranium crypto exchange hacker convicted for stealing $53 million
Microsoft Teams to get support for third-party deepfake detection tools
ASOS links data breach to social engineering attack, credential theft
Wazza Phishkit Targets Banking, Government, and Manufacturing Across the US, EU, and Australia
Owner of Empire cybercrime market gets 40 years in prison
- 1
- 2
- 3
- 4
- 5
- 6
- 7
- 8
- 9
- …
- následující ›
- poslední »



