On October 9, 2026, Google Cloud launched the Coworker Agent for Gemini Enterprise. Each agent gets its own Workspace account, email, calendar, Drive storage, and an entry in the company directory. They run inside an Agent Sandbox, with all traffic passing through an Agent Gateway.
The most counterintuitive design decision is not any of that. It is that the agent can call Claude.
Google Put Claude Inside Its Own Agent
Coworker Agent selects models automatically by default. Users can also choose manually — including Anthropic's Claude. Google says it plans to add open-source and other private models in the future.
The decision follows a specific data point. A Futurum survey found that 69% of enterprise developers already use Claude and plan to continue, compared with 39% for Gemini. If Google insisted on Gemini-only, it would be asking enterprises to abandon the model family they already prefer.
By including Claude, Google effectively conceded the model layer — at least in enterprise developer preference. What it is betting on instead is that once the model becomes a swappable component chosen by the agent, the durable assets become memory, skills, tool connections, identity, and policy.
Google's own framing: “Leading models change every few months. Keeping choice open means context, skills, and data stay in place.”
The risk in that bet is structural. Google is telling customers the model is interchangeable while still needing them to pay for Gemini models and TPU capacity.

The Agent Has an Email. Your SaaS Vendor Charges Per Seat.
Each agent has an @agents.company.com email address, a calendar, Drive access, and a directory entry. It looks like an employee.
Each agent also has a cryptographically attested identity, least-privilege permissions, and an audit log where every action is attributed to the agent rather than the user.
But enterprise software is priced per seat. Futurum notes that Google says it will not charge an additional seat fee for Gemini Agent, though advanced, long-running work will be billed through pooled quotas or consumption pricing.
Futurum‘s assessment: “Agents are absorbing work that used to justify additional licenses.” It expects “licensing for agent identities” to become a real negotiation point in 2027 enterprise software renewals.
Sandboxes and Gateways Are Runtime Controls. The Wall Already Cracked Once.
Google built an Agent Sandbox for isolated execution and an Agent Gateway described as an “AI network firewall.” All agent traffic passes through the gateway. Code runs in the sandbox.
That is the right engineering instinct. It also has a precedent. In July 2026, researchers at Accomplish AI found that Claude Cowork’s local mode could escape a Linux virtual machine on a Mac and reach host files.
Futurum also notes that Google‘s “universal” claim depends partly on running inside Microsoft 365 and Slack — where Microsoft has every incentive to make Copilot the default agent and to control how third-party agents read and act on data in Outlook, Teams, and SharePoint.
An Agent Gateway can control traffic inside Google’s own boundary. It cannot control how Microsoft or Salesforce treats an agent that enters their platforms.
P.S. Google has not published details on how Agent Gateway manages third-party traffic, or whether agent identity licensing will be introduced in a future version. Futurum‘s 2027 expectation is analysis, not an official roadmap.
Frequently Asked Questions
Q: What is the Coworker Agent?
A: A Gemini Enterprise feature launched on October 9, 2026. Each agent has its own Workspace account, email, calendar, Drive, and directory entry, and runs inside an Agent Sandbox with traffic routed through an Agent Gateway.
Q: Why does it matter that the agent can call Claude?
A: A Futurum survey found 69% of enterprise developers use Claude versus 39% for Gemini. By including Claude, Google conceded the model layer and is betting that memory, skills, and identity are more durable than model choice.
Q: What is the seat-licensing issue?
A: Agents absorb work that previously justified additional licenses. Google says it will not charge extra seat fees but will bill long-running work via consumption. Futurum expects agent identity licensing to become a negotiation point in 2027 renewals.
Q: What was the sandbox escape precedent?
A: In July 2026, Accomplish AI researchers found Claude Cowork‘s local mode could escape a Linux VM on a Mac and reach host files, illustrating that runtime controls have limits.
Q: What does Google not control?
A: The Agent Gateway governs traffic inside Google’s boundary. It cannot control how Microsoft or Salesforce treats an agent entering their platforms, where Copilot has default status.
