Google Just Turned Every Workspace User Into an AI Agent Operator. Who's Governing This?

Google just gave 3B+ Workspace users an AI agent that can reach into third-party apps from Search — with zero organisational governance. Here's the gap, the counter-architecture, and three things ops teams must do now.

Google Just Turned Every Workspace User Into an AI Agent Operator. Who's Governing This?

On the same day last week, Google shipped two things that look separate but aren't. AI Mode now lets users link third-party apps (Instacart, Canva, YouTube Music to start) and have the Gemini agent act inside them without leaving Search. You can ask it to order groceries, generate a design asset, queue up a playlist, and it reaches into those services on your behalf. Meanwhile, NotebookLM got rebranded to Gemini Notebook, gaining a per-notebook "secure cloud computer" that writes and executes code against your sources, with deeper hooks into the Gemini app and AI Mode itself.

Read separately, they're product updates. Read together, they're a strategy: Google is turning its consumer AI into an ambient agent layer that sits between every user and every app they touch. The agent lives in Search. It lives in Workspace. It lives in your notebook. And starting this month, it reaches out into third-party services.

I think this is a governance crisis waiting to happen. The technology works. It's impressive. But Google just handed every one of its 3 billion-plus Workspace users a universal AI agent keychain, and asked precisely zero organisational questions about who should have those keys.

What actually shipped

Let me be precise about what changed, because the details matter.

AI Mode Connected Apps (launched July 16) lets users link third-party services to their Google account. Once linked, you can issue natural-language instructions from AI Mode that execute actions within those apps. Order from Instacart. Generate in Canva. Control YouTube Music. Google frames it as convenience: "complete tasks across the apps you use regularly." The linked apps are treated as tools the agent can call, with structured actions behind the scenes. User control is the stated safety boundary: you choose whether to link an app, and you can unlink it.

Gemini Notebook (same day) is the NotebookLM rebrand, but the product change under the hood is the "secure cloud computer" attached to each notebook. This lets Gemini Notebook write and run code natively, doing complex analysis grounded in your uploaded sources. It's available now for Google AI Ultra and Workspace subscribers, rolling out to all Pro users in the coming weeks. Notebooks also become accessible from AI Mode in Search soon. A user researching supplier contracts in a notebook could, in the same session, ask AI Mode to order supplies from an Instacart-linked account, and the agent would move seamlessly between analysis and action.

The integration surface is expanding in real time. Google says it's working with more app partners. The architecture is built to scale.

The governance gap nobody's naming

Here's the problem: if every one of your employees who uses Google Workspace can link their personal or corporate apps to AI Mode, who's tracking what those agents are doing?

The answer right now is: nobody.

AI Mode's Connected Apps are linked at the individual Google account level. There's no Workspace admin console for managing which apps employees have connected to their AI agents. No audit log of agent actions across third-party services. No policy engine that says "Sarah in procurement can use Canva via AI Mode but can't use Instacart on the corporate account." The permission model is: you linked it, you can use it. That's a consumer permission model attached to a tool that's now deployed inside organisations with SOC 2 obligations.

We've covered the agent identity governance problem before, when NewCore raised $66M to give AI agents employee IDs. That was the enterprise waking up to the fact that agents need credentials, audit trails, and revocation paths just like humans do. Google's Connected Apps launch makes that problem worse, because it decentralises agent creation to the individual user level while keeping the governance model at the consumer level.

Think about what happens when procurement runs on AI Mode. Someone in finance asks the agent to "find the best supplier pricing for office furniture and order samples." The agent searches, compares, and places orders through linked services. Did it choose the supplier with the best terms, or the one whose product data was most readable to a language model? Did it check your organisation's approved vendor list? Did it log the decision anywhere that would survive an audit?

Nobody knows. Because nobody built that layer.

The counter-architecture

There are two ways to handle this. One is to wait for Google to ship a Workspace admin governance layer for AI Mode. The company's enterprise admin tooling for AI features has consistently lagged consumer launches, so I wouldn't hold my breath. The other is to accept that distributed agents will happen (you cannot stop employees from using AI Mode) and build a governance layer that sits above them.

That second approach is where standalone governed platforms get interesting. Platforms like Stacker, Bubble Enterprise, and Retool centralise how agents interact with business data. They give you:

  • Role-based permissions that scope what any agent (or user) can read and modify
  • Audit trails that show who did what, when, and under what policy
  • Approval workflows that require human sign-off before agents act on sensitive records
  • A single pane of glass for seeing every agent connected to your systems

The architectural bet is that centralised agent orchestration beats distributed agent chaos. Not "don't use Google's agents" (that ship sailed). But "connect Google's agents to a governed platform that logs, scopes, and audits their actions."

A mid-size company with 200 Workspace users cannot manually audit 200 individual Connected App setups. It can, however, route those agents through a platform that enforces the same governance rules it applies to human users. The agent becomes just another identity with a role, a scope, and a log.

What ops teams should do now

If you run operations, IT, or compliance for a company that uses Google Workspace, three things matter right now.

First, find out whether your employees are already using AI Mode. It's the default Search experience globally. The odds that nobody in your organisation has investigated the Connected Apps feature are close to zero. Don't wait for a breach notification to discover this.

Second, add AI agent actions to your acceptable use policy. Most corporate policies still treat AI tools as information retrieval systems. They're now action-taking systems. The gap between "an employee read something with AI" and "an employee ordered something with AI" is the gap your policy probably doesn't cover yet.

Third, evaluate whether your internal tools and customer-facing platforms can expose an agent governance layer. If you're already on a governed platform, use its permission model for agents the same way you use it for humans. If you're building on something that doesn't have one, start asking when it will. Google just made the governance question urgent. It won't be the last to do so.

The infrastructure is already forming. NewCore's $66M round treating agents as employees with corporate identities. AWS's agent operating system. The standalone governance platforms. The pieces exist. The question is whether ops teams connect them before an agent causes real damage.

The takeaway

Google's July 16 launches are impressive technology solving a real consumer need. But Google is also the default productivity layer for millions of businesses, and those businesses now have employees who can spawn AI agents that reach into third-party services from a search box. The governance layer for that capability does not exist yet.

There are two paths from here. Either every SaaS platform builds its own agent governance, fragmenting control across a dozen admin consoles, or organisations adopt a centralised governance platform that treats agents as just another identity to manage. The first path is what's happening now. The second is what ops teams should be building toward.

Don't wait for Google to write your agent governance policy. It's not their job. It's yours.

Want to read
more articles
like these?

Become a NoCode Member and get access to our community, discounts and - of course - our latest articles delivered straight to your inbox twice a month!

Join 10,000+ NoCoders already reading!

Similar STORIES