Google's Gemini Agent Gets Its Own Email, Memory, and Drive: What Can It Access?

October 11, 2026

Google's new Gemini coworker can get its own email, memory, calendar, and Drive. Here is what it can access, what controls exist, and what remains unclear.

Google's Gemini Agent Gets Its Own Email, Memory, and Drive: What Can It Access?

Short answer: Google says its new Gemini agent can become a persistent digital coworker with its own Workspace account, email address, calendar, Drive storage, and company-directory identity. It can work for hours or days, remember context across sessions, create temporary sub-agents, and act inside Workspace under permissions set by an organization. Google also says a coworker agent sees only the context people share with it and that every action is attributed to the agent in an audit trail.

That does not mean Gemini can automatically read every email or file in a company. It does mean that deploying one is closer to provisioning a new service account or employee than opening an ordinary chatbot. The important questions are therefore about identity, access, memory, sharing, model routing, audit logs, deletion, and who owns the agent after the person who created it changes roles.

The new universal Gemini agent was announced on October 8, 2026, and is initially available to selected customers in private preview. Several implementation details—including broad-release timing, coworker-account licensing, service-by-service controls, and the full data path when a task is routed to a third-party model—remain unclear.

Research cutoff: October 11, 2026.

The Answer in One Minute

Google's Gemini at Work 2026 announcement describes one cloud agent that can answer questions, create content, write and run code, schedule or respond to events, and continue working after a user closes a laptop. The same agent can appear in Google Workspace, Microsoft 365, Slack, desktop and mobile apps, the command line, or other applications.

There are two relevant forms:

The coworker version can receive its own Workspace account, email address, calendar, Drive, and directory presence. Google says it acts under its own identity, not the identity of the employee who assigned the job. Access follows the organization's existing sharing and membership rules, and the agent should see only what people share with it.

Google is also making persistence a core feature. The agent runs in the cloud, retains context across devices, and uses session, semantic, procedural, and episodic memory. Current Gemini Enterprise memory documentation says the product can learn from connected apps, recent conversations, email, calendar, documents, work patterns, and saved memories. Administrators can disable memory and personalization for an organization, while individual users can disconnect sources, turn off learning from conversation history, and remove saved memories. Some changes can take up to 24 hours, and deleting a saved memory may not remove the same information from the original conversation.

The privacy question is therefore not simply “Does Gemini read Gmail?” It is:

Which identity is acting, what was shared with that identity, what context and memory did it retain, which model handled the task, what external system did it reach, and can an administrator reconstruct and revoke the whole path?

What Is Confirmed

A coworker agent can have its own Workspace identity

Google says a manager can describe a needed role and create a coworker agent that receives:

Employees can add the agent to a Chat space, mention it, send it work, or tag it in a document comment. Google says edits and replies appear under the agent's own name, rather than impersonating the human who created it.

That separation is useful. A named agent can be given narrower permissions, disabled independently, and investigated through its own logs. It also creates a new identity-lifecycle problem. The account needs an owner, a business purpose, an access review, an offboarding rule, and a way to stop work immediately if something goes wrong.

Google says the agent sees only what is shared with it

The launch post says a coworker agent “sees only what you share with it.” It also says access follows the sharing and membership mechanisms a team already uses.

That is an important boundary, but “shared” can grow quickly in a real organization. Adding an agent to a broad Chat space, shared drive, mailing list, project group, or inherited folder can expose far more context than attaching one document. A permission that is technically valid can still be too broad for the task.

The right test is not whether the agent has administrator access. It is whether the complete effective access graph—direct shares, group memberships, inherited folders, connected apps, delegated calendars, and external systems—is no broader than the agent's current job.

Gemini can run after the user closes a device

Google says the agent runs in the cloud and can keep working on jobs that take hours or days. It can respond to schedules and events, coordinate parallel and sequential steps, and create temporary job-specific sub-agents.

This is materially different from a chat tab that stops when the conversation ends. A persistent worker can act while nobody is watching the screen. That makes pause, cancel, spend-limit, network, and approval controls part of the privacy design—not merely operational conveniences.

Google says a hard project spend cap can pause an agent. The company also describes an Agent Sandbox with a network boundary and an Agent Gateway that applies organization policies to traffic entering, leaving, or moving between agents.

The agent carries persistent memory and context

Google's announcement describes four kinds of memory:

  1. Session memory for the current task, including jobs that run for days.
  2. Semantic memory for structured knowledge accumulated from documents, people, and other agents.
  3. Procedural memory for how work gets done, including skills the agent creates.
  4. Episodic memory covering prior work.

The company says this context follows the agent across devices and channels. Gemini Enterprise's current configuration guide adds more concrete controls: it can learn from conversation history, connected Outlook or OneDrive data, email, calendars, documents, saved facts, and inferred preferences.

Memory is on by default in the documented enterprise configuration, although an administrator can disable memory and personalization for all users. Users can turn off learning from conversation history, disconnect connected sources, and delete saved memories. Google cautions that source changes can take up to 24 hours to take effect.

The deletion boundary matters. Google's documentation says deleting a saved memory does not necessarily remove the same information if it remains in a saved original conversation. Complete removal may require deleting both the memory and the conversation.

The agent can choose between Google and third-party models

Google says Gemini is the agent layer while the underlying model is a separate choice. At launch, tasks can be routed across Google's Gemini family and Anthropic's Claude models, with additional private and open models planned.

Google says context, skills, and data remain in the Gemini environment as models change. That is a product architecture claim, not a complete public description of every processing path. VentureBeat's launch report says Google told it prompts, documents, and chat histories remain inside Gemini Enterprise when third-party models are used, but did not publicly specify whether task data is transmitted to outside model providers for processing or detail every applicable retention and residency arrangement.

For a sensitive deployment, “supported model” is not enough information. Administrators need to know the processor, region, retention setting, contract, telemetry path, and whether a policy can force particular work to stay on an approved model.

Google describes identity, permission, audit, sandbox, and gateway controls

Google says each agent receives a cryptographically attested identity with least-privilege permissions. An administrator grants role-based access, and the identity can propagate to external systems through standards such as OAuth.

The company also says:

Google's Gemini Enterprise Business security guide separately describes automated prompt-injection screening, input and response sanitization, and data-leakage filters. It also says Business-edition prompts, uploads, responses, and chat history are not used to train Google AI models without permission. The same guide warns that the Business edition uses global infrastructure and does not provide controls to restrict storage and processing to a particular region; Google points customers needing regional controls toward other Enterprise options.

These are meaningful safeguards. They are not proof that every configuration prevents every mistaken action, indirect prompt injection, oversharing event, or account-lifecycle failure.

The new universal agent is not broadly available yet

Google's launch article announces the product but does not provide a universal availability date. VentureBeat reports that a Google Cloud spokesperson described the new agent as a private preview for selected customers, with wider availability planned but no specific date.

That means current press coverage describes a launch direction and early product, not a feature already active in every Workspace account. Ordinary Gmail users should not assume that an autonomous coworker with its own account has appeared in their personal inbox.

What The Announcement Does—and Does Not—Mean

It means AI identity is becoming a real administrative object

Giving an agent its own account is more than branding. It creates an object that can receive messages, own files, join groups, appear in a directory, create artifacts, and leave an audit record.

Organizations already know how to manage human and service identities, but an agent combines both. It may need a human sponsor like an employee, narrow credentials like a service account, and ongoing behavioral review like an automated application. Reusing only one of those governance models is likely to leave gaps.

It does not mean the agent can read every employee's inbox

Google's stated model is permission-based. A coworker agent sees content shared with it. The launch materials do not say that creating one grants organization-wide Gmail or Drive access by default.

However, “not every inbox” is not the same as “low risk.” One shared project drive may contain contracts, customer exports, credentials in old documents, meeting recordings, or personnel files. Permissions need to be evaluated by data sensitivity and purpose, not only by folder name.

It means memory can outlive a single task

Persistent context is a main selling point. Google wants employees to avoid re-explaining a project on every device or in every app. That convenience depends on remembering work history, relationships, preferences, and prior activity.

The privacy tradeoff is straightforward: the more an agent remembers, the more useful—and more consequential—its identity becomes. Deleting one memory, disconnecting one source, or removing one folder may not erase every related fact from conversations, summaries, artifacts, logs, or documents the agent created.

It does not prove that Google trains a foundation model on company data

Google's Business-edition documentation says business prompts, uploaded content, generated responses, and chat history are not used to train Google AI models without permission. That is different from saying no processing occurs, no logs exist, no memory is stored, or no administrator can access organizational records.

Training, active request processing, personalization, security monitoring, audit logging, and saved conversation history are different data uses. A useful privacy review separates them instead of collapsing them into one “Does Google use my data?” question.

It does not prove that the agent is immune to prompt injection

Google documents prompt-injection screening and network controls, but no public control is perfect. Email, shared documents, web pages, connected tools, and comments can contain instructions an agent was not meant to follow.

Prior research on promptware attacks against production AI assistants demonstrated why messages, calendar invitations, and shared documents can become indirect instruction channels. That research predates this launch and does not establish a successful attack on the new Gemini agent. It does show why inbox and Drive access expand the material an agent must treat as untrusted.

The Permission Questions To Ask Before Creating A Gemini Coworker

1. Who owns the agent?

Assign a named human sponsor and a team responsible for access reviews. Decide what happens when the sponsor leaves, changes departments, or loses authority over the underlying business process.

2. What is the smallest useful role?

Avoid a generic “assistant” identity with permanent access to everything. Define one job, one set of data sources, one output destination, and one review owner. Create another agent when the role materially changes.

3. Which groups and shared drives does it inherit?

Inspect effective permissions, not the direct-sharing screen alone. Group membership, nested groups, link sharing, shared drives, calendar delegation, and chat-space membership can silently widen reach.

4. Can it send, publish, edit, or execute without approval?

Reading and acting are different risk levels. An agent that drafts an email is not equivalent to one that sends it. A tool that proposes code is not equivalent to one that runs it. Require confirmation for external messages, public publishing, payments, destructive edits, credential changes, and high-impact commands.

5. Which model and region process each task?

Document allowed models, residency requirements, retention terms, and third-party processors. If the agent can route dynamically, confirm whether policies can stop sensitive work from reaching a disallowed model or region.

6. What does it remember, and how is that memory removed?

Test memory deletion before production use. Remove a saved fact, delete the related conversation, disconnect a source, wait through the documented propagation window, and verify that the information no longer appears where it should not.

7. Are the logs usable during an incident?

An audit trail is useful only if it records enough context to answer who assigned the task, which identity acted, what resource was accessed, which model was used, what tool executed, what data left the boundary, and who approved the final action.

8. How quickly can the agent be stopped?

Practice revoking tokens, removing group memberships, pausing work, disabling the account, blocking network egress, and preserving logs. Do not make the first offboarding test during a live incident.

Where OpenVeil Fits—and Where It Does Not

OpenVeil is a hosted, privacy-focused AI workspace for adults who want a narrower place to ask questions, draft, analyze, or brainstorm without creating an autonomous digital employee.

OpenVeil's documented product design keeps normal chat history in the user's browser and does not create a normal server-side chat-history account record. Documented product content is not used for foundation-model training. Active requests still have to be processed by OpenVeil and its model providers, so OpenVeil is not fully offline, anonymous, zero-log, or free of provider processing.

The relevant distinction is authority. OpenVeil is not designed to receive its own company email, join your Workspace directory, keep working for days, operate a Drive account, send messages as a coworker, create sub-agents, run enterprise code, or inherit broad organizational permissions.

That narrower surface can be a better fit when the job is simply:

OpenVeil is not a substitute for Gemini Enterprise governance. It is not an identity-management system, enterprise data-loss-prevention tool, agent sandbox, prompt-injection filter, audit platform, regional-residency control, approval engine, incident-response product, or compliance certification. It also does not protect data already placed in Gmail, Drive, Gemini, or another connected service.

The practical choice is not “Google bad, private chatbot good.” It is to use the least authority required for the task. If you need a persistent coworker that acts across systems, govern it like a privileged identity. If you only need a focused conversation, do not connect an inbox and Drive merely because the option exists.

What Is Still Unclear

Which deployments receive full coworker accounts?

Google has not publicly established whether every configuration of the new universal agent can receive a complete Workspace account, or whether email, calendar, Drive, and directory identities are limited to persistent coworker roles.

How granular are the service controls?

The launch materials do not fully explain whether administrators can independently enable or disable email, calendar, Drive, Chat, code execution, sub-agents, or particular outbound actions for each coworker.

What are the complete retention and deletion timelines?

Current memory documentation explains controls and warns that some changes can take 24 hours. It does not provide a complete public matrix covering every kind of universal-agent memory, generated artifact, audit event, temporary sub-agent, sandbox file, backup, or third-party-model path.

What exactly happens when Claude or another model handles a task?

Google says data remains within Gemini Enterprise and that policy controls can govern model use. Public launch materials do not fully describe every transmission, processing, logging, residency, and retention step for third-party models.

How well do the safeguards work in production?

Google describes identity, least privilege, sandboxing, gateways, audit trails, prompt-injection screening, and data-leakage filters. The reviewed sources do not provide independent, real-world failure rates for the new universal agent or prove that every long-running cross-app workflow stays within intended scope.

When will ordinary customers receive it, and what will it cost?

The product is in private preview for selected customers. Google has not published a firm general-availability date, complete licensing rules for dedicated coworker accounts, usage limits, or the number of coworker identities each organization can create.

Frequently Asked Questions

Can Google's Gemini agent read all my email?

Not according to the announced coworker model. Google says the agent sees only context shared with it and follows existing Workspace sharing and membership rules. Its effective access can still become broad through groups, shared spaces, connected apps, or delegated permissions, so administrators should inspect the full access graph.

Does every Gemini agent get its own Gmail account?

Google confirms that a coworker agent can receive its own Workspace account and email address. It has not publicly said that every personal or temporary Gemini agent receives one.

Does the new agent keep memory?

Yes. Persistent memory is central to the announcement. Google describes session, semantic, procedural, and episodic memory, while current Gemini Enterprise documentation describes conversation-history learning, connected data sources, saved memories, and administrator controls.

Can I delete Gemini Enterprise memories?

Users can remove saved memories, turn off referencing saved memories, disable learning from conversation history, and disconnect sources. Administrators can turn off memory and personalization for the organization. Google says a deleted saved memory may still be present in its original saved conversation, which must also be deleted for fuller removal.

Is Workspace data used to train Gemini?

Google's Gemini Enterprise Business documentation says prompts, uploaded content, generated responses, and chat history are not used to train Google AI models without permission. That statement does not mean requests are processed locally or that there is no memory, logging, security screening, or retention.

Can the agent use Anthropic's Claude?

Google says the agent can route work to Gemini models and Anthropic's Claude models, with more options planned. Organizations handling sensitive data should verify the precise processor, region, retention terms, and policy controls for each model path.

Is the universal Gemini agent available to everyone?

No. As of the research cutoff, it is in private preview for selected customers. Google says wider availability is planned but has not supplied a firm date.

Is OpenVeil an alternative to an enterprise agent?

Only when the task does not require autonomous action or connected enterprise systems. OpenVeil provides a narrower hosted conversation workspace; it does not replace Workspace identity, email, Drive, audit, sandbox, permission, or compliance controls.

Bottom Line

Google's new Gemini agent is not merely a chatbot with a longer prompt. A persistent coworker can have an identity, inbox, calendar, storage, memory, tools, and permissioned access to business systems. Google has announced serious controls around least privilege, auditability, sandboxing, network policy, and memory management. It has also left important deployment details unanswered while the product remains in private preview.

The useful privacy posture is neither panic nor blind trust. Treat every coworker agent as a privileged non-human identity. Give it one owner, one purpose, the smallest possible access, explicit approval gates, testable deletion, and a practiced shutdown path. For work that needs conversation rather than autonomous authority, choose a narrower tool and avoid connecting systems the task does not require.

Sources

This article reports product documentation and public coverage available through October 11, 2026. Features, availability, and policies can change; confirm current controls and contracts before deploying an agent with sensitive access.

When privacy, account control, uploads, and search matter, OpenVeil gives you a private AI workspace designed for that job.