# Gemini agent vs Agent 365: the agent identity decision

Google introduced the Gemini agent on 8 October 2026: a universal work agent whose coworker agents get their own @agents.company.com mailbox, calendar and Drive, in private preview with no price. We set it against Microsoft Entra Agent ID and Agent 365, both GA since spring at $15 per user per month, compare the two identity models, run the cost math for a 1,000-user Swedish M365 shop, and list the EU residency and offboarding questions to ask before a pilot.

- Published: 2026-10-11 · Category: AI & Cloud Infrastructure · Tags: Gemini agent, Google Cloud, Agent 365, Entra Agent ID, Agent Identity, AI Agents, Microsoft 365, Google Workspace, Data Residency, EU AI Act, Governance
- Author: Technspire AB, Stockholm (https://technspire.com)
- Canonical: https://technspire.com/en/blog/gemini-agent-vs-agent-365-the-agent-identity-decision

On 8 October 2026 Google Cloud introduced the Gemini agent at its Gemini at Work event, and the detail that will reach your identity team first is the mailbox. A "coworker agent" gets its own Workspace account: an address under @agents.company.com, a calendar, Drive storage and an entry in the company directory. It acts under that identity rather than yours, and every action it takes is logged against the agent. The whole thing is in private preview with no price and no date. Microsoft reached the same design question earlier and answered it differently: Entra Agent ID went generally available in April 2026 and Agent 365, the control plane on top of it, followed on 1 May at $15 per user per month. For a Swedish organisation running Microsoft 365, the Gemini agent is less a question of which assistant writes better slides and more a question of which agent identity model your IAM team can actually govern.

## What Google announced on 8 October

- **One agent, one API.** Google's own description: it "answers your questions, handles your knowledge work, creates your images and media, and writes and runs code — all in a single agent and a single API." You "give it objectives, not instructions."
- **It runs where you already work.** Web, iOS, Android, Windows and Mac clients, plus the command line, Google Workspace, Microsoft 365 and Slack. It can also run headless inside third-party applications.
- **It keeps running when you close the laptop.** The agent executes in Google's cloud with one set of memories and one personalisation graph across devices. Google lists four memory types: session, semantic, procedural and episodic.
- **It spawns sub-agents with their own identities.** Temporary, job-specific agents coordinate parallel and sequential steps "that can run for hours or days."
- **Coworker agents are persistent team members.** Describe a role and Gemini creates the agent, complete with its own Workspace account. Access "follows the sharing and membership your team already uses."
- **Models.** Each job runs on "the model that fits best," across Gemini models and Anthropic's Claude models today, with other private and open models promised. The 8 October Gemini Enterprise release notes separately enabled Claude Opus 5.5 and Sonnet 5.5 for the AI developer tools on consumption billing.
- **Connectors.** Named systems include Microsoft Office and Teams, Confluence, Jira, Git, Salesforce, ServiceNow, BigQuery, Databricks, Snowflake, Postgres, SAP, Workday, Amazon S3 and Azure Data Lake, plus "any Model Context Protocol (MCP) server inside or outside your company network."
- **Governance.** Every agent identity is "cryptographically attested and governed like an employee, with least-privilege permissions." Permissions are approved by security administrators and propagated to external systems over OAuth. Every action goes to an audit trail attributed to the agent. Code runs inside an Agent Sandbox with its own network boundary, and all traffic passes through Agent Gateway, which Google calls "an AI network firewall enforcing your organization's policies in real time."
- **Spend caps.** A hard per-project limit on AI spend set in the Cloud Billing console, covering token usage and sandbox cost.
- **Availability.** Private preview. Industry specialisations for Financial Services and Legal are in preview; Government, Healthcare and Retail are "coming soon." No pricing was published. VentureBeat reports the agent is included in Gemini Enterprise subscriptions where available, and Futurum reports a Google representative saying the company does not intend to charge per seat for coworker agents in Workspace. How agent activity will be metered instead is not public.

## Two identity models, side by side

Both vendors have now said the same sentence: an agent needs its own identity, least privilege, and an audit trail in its own name. They built it on different primitives. Google's agent is a directory account that looks like a person. Microsoft's is a distinct identity type with its own blueprint, owner, sponsor and policy set, which can optionally be given a user account when it needs to appear inside Microsoft 365 apps. That difference drives everything in the table.

| Dimension | Google Gemini agent | Microsoft Entra Agent ID + Agent 365 |
| --- | --- | --- |
| Identity object | Workspace account with email, calendar, Drive and directory entry; cryptographically attested | Agent identity created from an agent identity blueprint; optional agent user account for M365 presence |
| Human accountability | Permissions approved by security administrators; team sharing governs data access | Named owners, sponsors and managers; lifecycle workflows reassign sponsorship when a sponsor leaves |
| Acting for a user vs alone | Personal assistant mode and coworker mode; the coworker "sees only what you share with it" | Explicit on-behalf-of and autonomous modes, each with its own Conditional Access template |
| Access policy | Agent Gateway enforces written policy on all traffic, including between agents | Conditional Access for agents, ID Protection risk signals, access packages, block-high-risk template |
| Third-party reach | OAuth propagation to connectors, including Microsoft 365 and any MCP server | Native for Copilot Studio and Foundry; sidecar or federation for AWS Bedrock, GCP and n8n |
| Code execution | Agent Sandbox with its own network boundary; identity stamped into the VM | Per platform: Foundry Agent Service, Copilot Studio, and Windows Execution Containers on the client |
| Audit | Every action attributed to the agent; real-time observability | Entra sign-in and audit logs per agent identity; Agent 365 inventory for registered agents |
| Spend control | Hard per-project cap in Cloud Billing | Copilot Credits and Azure budgets, no single agent-level cap |
| Price | Not published; included in Gemini Enterprise per press reports | Agent 365 at $15 per user per month; Agent ID itself in Entra |
| Status, 11 October 2026 | Private preview, no date | Both GA since spring 2026 |

Three things in that table decide the pilot. First, Microsoft separates the "who answers for this agent" question from the agent itself: an agent identity has owners and sponsors, and Entra ID Governance ships two lifecycle templates specifically to prevent orphaned agents when a sponsor changes role or leaves. Google's model leans on existing team membership and administrator approval, and the keynote says nothing about what happens to a coworker agent's account, memory and mailbox when its creator leaves. Ask. Second, Microsoft's Conditional Access templates distinguish an agent acting on behalf of a signed-in user from an autonomous one with no user context. Google's coworker agent is autonomous by design, and its policy layer is Agent Gateway rather than the sign-in. Only one of them plugs into the Conditional Access policies your security team already maintains. Third, Google's agent reaches into Microsoft 365 through a connector. For an M365 shop that means a second processor holding Graph-scoped OAuth grants to mail, files and Teams, which is a DPIA, not a toggle.

### The mailbox is a feature and a liability

Giving an agent a real address solves a real problem: humans can @-mention it, invite it to a meeting and forward it a thread, with no connector in the way. It also means the agent's mailbox and Drive accumulate personal data about customers and colleagues under an account nobody logs into. Retention schedules, legal hold, eDiscovery, subject access requests and offboarding all have to cover @agents.company.com accounts from day one. Microsoft's optional agent user account raises the same questions, but the default agent identity in Entra has no mailbox, which keeps a forgotten agent's blast radius smaller. Put Gemini coworker agents in their own organisational unit with their own retention and sharing rules before the first one is created.

## What Microsoft has that Google is still previewing

Microsoft's advantage in October 2026 is not architecture. It is that the pieces shipped. The Entra Agent ID "what's new" page, last updated 13 August, lists GA features we described at preview in [Azure Entra Agent ID: identity and permissions for agentic AI](/en/blog/azure-entra-agent-id-identity-permissions-agentic-ai): blueprints, a creation wizard, AI-guided setup, cascade deletion, a sidecar Auth SDK, token validation guidance for downstream APIs, migration guides for custom app registrations and Copilot Studio agents, and integration guides for Amazon Bedrock and n8n. Conditional Access for agents and ID Protection for agents began rolling out in July. Agent registry experiences are converging under Agent 365, which we covered when it was announced at Ignite in [Agent 365: unified control plane for AI agent management](/en/blog/ignite-2025-brk305-agent-365-unified-control-plane-ai-agent-management).

Google's side is not empty. The Gemini Enterprise Agent Platform has had GA pieces since Next in April, and the September release notes show the governance layer filling in: resource-level IAM permissions on 28 September, admin transfer of shared agent ownership on 21 September, latency and error-rate views for agents on 4 September, Workflow Builder GA the same day. We compared that platform with Foundry in [Gemini Enterprise Agent Platform vs Azure AI Foundry](/en/blog/managed-agent-platforms-compared-google-s-gemini-enterprise-agent). What is new on 8 October is the end-user product on top: the single agent, the coworker accounts, the Gateway and the Sandbox as a bundle. That bundle is the part in private preview.

## Cost math: what you can and cannot price today

Take a 1,000-user Swedish organisation on Microsoft 365 E5 that wants governed agents by Q1 2027.

- **Microsoft route.** Agent 365 at $15 per user per month is $180,000 a year for the full user base, on top of the E5 that is its prerequisite. Microsoft 365 E7 at $99 per user per month bundles it, which matters only if you were going to E7 anyway. Agent runtime cost sits in Copilot Credits and Azure consumption; we did that arithmetic in [Copilot Credits go default-on: your 2 November checklist](/en/blog/copilot-credits-go-default-on-your-2-november-checklist). The number is knowable this week.
- **Google route.** The Gemini agent is reported as included in Gemini Enterprise seats, and a Google representative has said coworker agents will not be charged per seat. That leaves agent compute, sandbox time, memory, storage and model tokens on consumption billing with a published per-project cap and no published rate card for the agent itself. You can set the cap. You cannot forecast what it buys.
- **Hybrid route.** The one most Swedish M365 shops will actually consider: keep Microsoft 365 and Entra as the identity and data plane, and pilot Gemini agents against BigQuery or Workspace data where those already live. That doubles the governance surface. Entra Agent ID supports federation for GCP-hosted agents, so a Gemini agent could in principle be registered in your Agent 365 inventory, but that is an integration project with no vendor reference architecture yet.

A platform without a rate card cannot pass a Swedish public-sector procurement, and most private-sector CFOs will treat an unpriced consumption line the same way. Until Google publishes metering, the Gemini agent is a pilot budget item, not a platform decision.

## The Swedish and EU angle

**Neither vendor's EU story is the default.** Google's data residency page for Gemini Enterprise supports an `eu` multi-region for both data at rest and ML processing on base functionality, but lists gaps: Agent Code Execution has no at-rest residency commitment in the EU, Web Grounding for Enterprise has none at all, and Gemini 3.1 Pro is not served from the EU location. Agent Code Execution is precisely what the Gemini agent does all day. For Workspace, the Gemini app has honoured organisational data regions for storage and processing since 29 June 2026, but only on Enterprise Plus and Frontline Plus, and the EU data region in Workspace is an explicit admin configuration, not a default. On the Microsoft side, Microsoft 365 Copilot's Flex Routing has been on by default for EU and EFTA tenants since 17 April 2026 under MC1269223, which permits LLM inference outside the EU Data Boundary at peak demand until an admin turns it off under Copilot settings. Whichever platform you pilot, the residency posture is an action item, not an inherited property.

**Where does the memory live?** The Gemini agent's semantic, procedural and episodic memory is a persistent, growing store of what the agent has read, learned and done, including about named people. Google's announcement says the agent runs in the cloud with a single memory set across devices; it does not say in which region that memory is stored or processed, or whether the `eu` location commitment covers it. That is the first question for a Swedish DPO, ahead of model choice, because it determines whether Article 28 processor terms and the residency commitment actually reach the data the agent accumulates.

**An agent that emails people must say it is an agent.** The AI Act's Article 50 transparency obligations have applied since 2 August 2026. The @agents.company.com pattern makes disclosure easy to implement, but it has to be enforced for every surface the agent writes to, including Teams messages via the Microsoft 365 connector and Slack. Add a standing instruction and a Gateway policy, and test both.

**Swedish identity governance already has the vocabulary.** Most Swedish enterprises run access reviews, sponsor models for external accounts and leaver workflows in Entra today. Microsoft's agent model slots into that vocabulary: an agent has a sponsor the way a consultant has a sponsor, and the same lifecycle workflow catches both. Google's model asks you to extend Workspace group membership and sharing rules to cover a new class of principal. Both are doable. The Microsoft version is less new work for a team that already lives in Entra, which is why most Swedish M365 shops will pilot Agent 365 first and evaluate Gemini agents second.

## Decision guide

- **Pilot the Gemini agent now** if you are a Workspace organisation, or a mixed estate whose data gravity is in BigQuery and Google Cloud, and you can get into the private preview. The coworker model is the most complete product expression of "agent as team member" any vendor has shipped, and you want to learn its failure modes before it goes GA.
- **Stay on Agent 365 and Entra Agent ID** if you are Microsoft 365 first, your Conditional Access estate is mature, and you need a priced, GA control plane this budget year. Use Copilot Studio or Foundry for the agents themselves and register everything with an Agent ID so it shows up in the inventory.
- **Do not connect the Gemini agent to Microsoft 365** until you have run a DPIA on the connector's Graph scopes, confirmed where agent memory is stored, and decided how a Gemini coworker account will appear in your Entra inventory. The connector is the easiest click in the product and the hardest one to explain to IMY.
- **Treat agent-to-agent traffic as the new perimeter** on either platform. Google's Agent Gateway and Microsoft's Conditional Access both claim to police it; neither has a public policy language you can review yet. Ask for the policy schema in writing before you rely on it. The trust-model questions we worked through in [OpenAI Dots vs Meta Muse: two agent trust models compared](/en/blog/openai-dots-vs-meta-muse-two-agent-trust-models-compared) apply unchanged.

## Five questions to put to Google before a pilot

- **1. Metering.** What exactly is billed for a coworker agent that runs for a week: compute hours, sandbox time, memory, tokens by model? Which SKUs, and which of them are covered by the per-project spend cap?
- **2. Memory residency.** In which region are session, semantic, procedural and episodic memory stored and processed for a tenant pinned to the `eu` location, and is that covered by the Data Processing Amendment?
- **3. Offboarding.** When the human who created a coworker agent leaves, what happens to the agent's account, mailbox, Drive and memory, and who is notified?
- **4. Log export.** Can the agent-attributed audit trail be streamed to Microsoft Sentinel or another SIEM outside Google Cloud, with the agent identity preserved as the actor?
- **5. Gateway policy.** What is the policy language of Agent Gateway, can it be version-controlled, and does it apply to MCP servers the agent calls outside your network?

## Conclusion

Google has shipped the clearest picture yet of what a governed enterprise agent should look like: its own identity, its own mailbox, a sandbox, a gateway and a spend cap. It has not shipped a price, a date or an EU answer for the memory that makes the agent useful. Microsoft shipped a less vivid product and a complete control plane, priced per user, that fits the Entra processes a Swedish organisation already runs. Pilot the Gemini agent to learn, buy Agent 365 to govern what you run this year, and do not let a connector decide your architecture for you.

## Sources

- [Google Cloud: Gemini at Work 2026: Introducing Gemini agent](https://cloud.google.com/blog/products/ai-machine-learning/welcome-to-gemini-at-work-2026)
- [Google: Google Cloud introduces the Gemini agent (8 October 2026)](https://blog.google/innovation-and-ai/infrastructure-and-cloud/google-cloud/gemini-at-work/)
- [VentureBeat: Google Cloud unveils persistent Gemini agents for long-running tasks](https://venturebeat.com/orchestration/google-cloud-unveils-persistent-gemini-agents-for-long-running-tasks-and-they-get-their-own-gmail-calendar-and-drive-storage)
- [Futurum: Google collapses enterprise AI into a single Gemini agent](https://futurumgroup.com/insights/google-collapses-enterprise-ai-into-a-single-gemini-agent-at-gemini-at-work-2026/)
- [9to5Google: Google Cloud announces Gemini agent as universal agent for work](https://9to5google.com/2026/10/08/gemini-agent-google-cloud/)
- [Google Cloud docs: Data residency for Gemini Enterprise](https://docs.cloud.google.com/gemini/enterprise/docs/locations)
- [Google Cloud docs: Gemini Enterprise release notes](https://docs.cloud.google.com/gemini/enterprise/docs/release-notes)
- [Google Workspace Updates: Gemini app data regions support (29 June 2026)](https://workspaceupdates.googleblog.com/2026/06/gemini-app-data-regions-support.html)
- [Microsoft Learn: What's new in Microsoft Entra Agent ID](https://learn.microsoft.com/en-us/entra/agent-id/whats-new-agent-id)
- [Microsoft Learn: Conditional Access for agents](https://learn.microsoft.com/en-us/entra/identity/conditional-access/agent-id)
- [Microsoft Tech Community: Agent 365 will be generally available on May 1, 2026](https://techcommunity.microsoft.com/discussions/agent-365-discussions/agent-365-will-be-generally-available-on-may-1-2026/4500380)
- [Message Center MC1269223: Microsoft 365 Copilot Flex Routing in the EU Data Boundary](https://changepilot.cloud/blog/microsoft-365-copilot-flex-routing-eu-data-boundary-mc1269223)

---

Technspire AB builds AI agents, Azure OpenAI solutions, and production web platforms for Swedish and EU enterprises. Book a call: https://calendly.com/technspire · hello@technspire.com · More articles: https://technspire.com/en/blog · Site overview for agents: https://technspire.com/llms.txt
