Agentic AI  ·  BraivIQ AI Blog

Agentic AI Gets Its Own Login: What Google's Gemini Agent Means For UK Financial Firms

On 8 October 2026 Google Cloud introduced the Gemini agent, along with coworker agents that get their own email address, Workspace account, storage and place in the company directory. Agentic AI is moving from a tool people use to a colleague with its own identity. For UK financial firms that makes two questions urgent: who approves what an agent can access, and who signs off what it does.

Published  ·  Updated  ·  7 min read  ·  By BraivIQ Editorial

Person wearing an identity badge on a lanyard, illustrating agentic AI agents that now get their own workplace identity and login

Key takeaways

  • Google says the Gemini agent takes objectives rather than instructions: “You delegate an outcome and come back to finished work” (Google Cloud, 8 October 2026).
  • Coworker agents get their own @agents.company.com email, storage, Workspace account, calendar and company directory listing, and see only what people share with them.
  • Every agent action “is written to an audit trail and attributed to the agent rather than to a person”, according to Google.
  • Gemini for Financial Services is in preview and, Google says, already used by CME Group and Deutsche Bank.
  • Before any agent gets a login, a UK firm should decide who approves its permissions, who reviews its audit trail and which actions always need a person's sign-off.

What did Google announce on 8 October 2026?

At its Gemini at Work event on 8 October 2026, Google Cloud chief executive Thomas Kurian introduced the Gemini agent, which he described as a single agent for work. “You give it objectives, not instructions,” his post says. “You delegate an outcome and come back to finished work.”

The bigger change for regulated firms is identity. Google says: “Coworker agents have dedicated identities including their own @agents.company.com emails, their own persistent storage, and only have access to the context that you or your team members provide.” Each one “receives its own Workspace account, including an email address, calendar, Drive, and presence in your company directory.”

The agent can also split a job into parts. Google says it “can dynamically create a roster of sub-agents — temporary, job-specific agents, each with their own identity — to tackle multi-step tasks.” It runs each job on the model that fits, using Google's Gemini models and Anthropic's Claude models today.

It can be reached from the web, mobile and desktop apps, the command line, Google Workspace, Microsoft 365 and Slack. TechCrunch, reporting the launch on 8 October 2026, described an agent that can plan, carry out tasks and work across business apps and systems.

What is agentic AI, in simple terms?

An AI agent is software that takes a goal, works out the steps, uses tools such as email, files or other systems to carry them out, and checks its own progress. A chatbot answers a question. An agent does a piece of work.

Agentic AI is the wider shift towards systems built this way. The practical difference for a firm is that an agent acts on systems, so the questions move from “is the answer right?” to “what is it allowed to touch, and who checks what it did?”

Why does an AI agent need its own identity?

Until now, many agents have worked under the login of the person who set them up. That makes it hard to tell later whether a person or an agent took an action, and it usually gives the agent far more access than the task needs.

Google's design addresses both points. “Every agent gets its own identity, cryptographically attested and governed like an employee, with least-privilege permissions,” the post says. Permissions are role-based and “approved by your organization's security administrators”, and “every action Gemini takes is written to an audit trail and attributed to the agent rather than to a person.”

UK policy is heading the same way. HM Treasury's Financial Services AI Adoption Plan, published on 14 July 2026, proposes “Know Your Agent” protocols, which it describes as “standardised identity and verification frameworks specifically designed for AI and autonomous software agents.”

How should a UK financial firm manage AI agent identity and access?

An agent with its own email address is, in practice, a new member of staff who never sleeps. Treat it with the same care as a new joiner, and decide these points before it is switched on:

  1. A named owner. One person is accountable for what the agent is for, what it can reach and when it is reviewed.
  2. Least access to start. Begin read-only on the data the task needs, and add rights only with a recorded approval.
  3. Approval points that cannot be skipped. Anything that changes a client record, sends a message outside the firm or touches money needs a person's sign-off.
  4. A regular look at the audit trail. A log is only useful if someone reads it, so review a sample of agent actions every week at first.
  5. Joiners, movers and leavers for agents. When a task changes or ends, change or remove the agent's access, as you would for a person.
  6. Sub-agents counted. If an agent can create temporary helpers, make sure their identities and actions appear in the same logs.

Our engineering team explains the technical side, from delegated authorisation to token exchange, in our Playbook guide to agent identity. For why controls must sit outside the agent itself, see our analysis of Nvidia's agent safety platform.

Where does Gemini for Financial Services fit?

Google also announced industry versions, and financial services is one of the first. According to the post, “Gemini for Financial Services automates what is usually pieced together across many workstreams: investment research, credit analysis, and risk modeling.” It draws on data from FactSet, LSEG and S&P Global, SEC filings and a firm's own repositories.

Google says it shows its reasoning through confidence scores, explicit methodologies, full data lineage and source citations, and that it is already used by CME Group and Deutsche Bank. The industry versions are “now in preview for Financial Services and Legal”. The post does not set out availability for UK firms.

For a wealth manager, broker or payments firm with 10 to 250 staff, the first gains are more likely to come from operations than research. Reconciliations, onboarding files and report checks are repetitive, rule-heavy and easy to measure, which makes them good first jobs for an agent with a tightly limited identity.

What should an AI agent never be allowed to do in a financial firm?

Identity tells you who acted. It does not decide what the agent should be allowed to do. In our view, AI agents for financial firms should prepare work and leave decisions to people. Our own agents work within five limits:

  • They never give financial advice.
  • They never make investment or client decisions.
  • They never move money.
  • They never change a client system without a person approving it.
  • They never train on client data.

How do you put an agent into production with a person signing off?

Start small and measure. BraivIQ, an AI agency in London that works with UK financial firms, begins with a 14-day Proof Run on the firm's own exports, read-only. One workflow then goes live in 60 days through four gates: a signed baseline, a controlled build, a parallel run on live cases and an evidenced go-live with a named owner.

Each agent has its own limited access, a full activity log and an approval point on every decision that matters. See what our agents prepare and how our senior team built exception queues a compliance team could trust. For firms exploring agentic AI in London and across the UK, that is the pattern we recommend.

Frequently asked questions

What is agentic AI?

Agentic AI describes systems that take a goal, plan the steps, use tools and systems to carry them out, and check their own progress. Unlike a chatbot, an agent acts, which is why access controls, audit trails and human approval matter so much.

Can an AI agent have its own email address?

Yes. Google said on 8 October 2026 that its coworker agents get their own @agents.company.com email address, persistent storage, Workspace account, calendar and directory listing, and act under their own identity rather than the user's.

Who is accountable for what an AI agent does?

The firm remains accountable for the work. HM Treasury's Financial Services AI Adoption Plan of 14 July 2026 keeps AI within the existing regulatory framework, and its assurance proposal leaves each firm responsible for managing the risk of any model it uses. In practice, that means a named owner and a person approving every decision that matters.

Is the Gemini agent available to UK firms?

Google's 8 October 2026 post does not set out UK availability. It says the financial services and legal versions are in preview, with government, healthcare and retail coming soon.

References

  1. Google Cloud, "Gemini at Work 2026: Introducing Gemini agent", 8 October 2026. https://cloud.google.com/blog/products/ai-machine-learning/welcome-to-gemini-at-work-2026
  2. TechCrunch, "Google brings agentic AI to Gemini, starting with businesses", 8 October 2026. https://techcrunch.com/2026/10/08/google-brings-agentic-ai-to-gemini-starting-with-businesses/
  3. HM Treasury, "Financial Services AI Adoption Plan", 14 July 2026. https://www.gov.uk/government/publications/ai-adoption-plan-financial-services/financial-services-ai-adoption-plan