Google’s always-on agent can send your email, so write its rules before it arrives

Google’s Gemini Spark runs around the clock across Gmail and Docs. Harper Singh on the one-page rule set to write before any always-on agent gets access.
A black desk lamp glowing on a wooden table in a dark room

Our view on Gemini Spark is that the clever part matters least. Google’s new always-on agent will do exactly what its permissions allow, and the permissions are yours to write. Put one page of rules on paper and name an owner before anyone on your team connects it to a mailbox.

The short version

  • Gemini Spark is Google’s 24/7 personal agent, announced at I/O on 19 May 2026. It runs in the cloud and keeps working after you close your laptop, across Gmail, Docs and Slides.
  • Google says Spark is designed to ask before high-stakes actions such as spending money or sending emails. What counts as high-stakes is a call your team has to make.
  • Google’s post gives no price, no usage caps and nothing on admin controls for companies, so we’d wait on a broad rollout.
  • Write the rules first. Any pilot starts read-only.

Think of an always-on agent as a new hire who starts at midnight and has no manager in the building. You’d hand that person a written brief before you handed them the keys.

What did Google actually announce about Gemini Spark?

Google described Spark as a 24/7 personal AI agent that does work on your behalf, running in the cloud on Gemini 3.5. Access began with trusted testers, followed by a beta for US Google AI Ultra subscribers. The launch post gives no price or company admin controls.

Examples in the post include parsing a monthly credit card statement for new subscription fees, or turning meeting notes from email and chat into a Google Doc and a draft follow-up. Connected apps at launch include Gmail, Docs and Slides, plus new connections to Canva, OpenTable and Instacart. Google said texting and emailing on your behalf, custom sub-agents and control of your local browser were still to come.

The Next Web reported that you can send Spark tasks through a dedicated Gmail address, and that Google is cutting its AI Ultra tier to $100 a month. Google’s own post doesn’t give a Spark price, so treat the cost of running it as unconfirmed.

Why does the permission design matter more than the model?

Because the model decides what the agent can do well, but the permissions decide what it can do wrong. A capable agent with narrow access has a small blast radius. A capable agent with your whole mailbox does not. The boring part, who approves what, shapes the outcome more than any benchmark.

The failure that actually happens in a small company is rarely a dramatic hack. It’s an agent reading an email thread and replying to the wrong contact. It’s a draft that goes out under your name at 2 a.m. with a number it guessed. Google’s confirmation step helps, but a prompt only protects you if the person clicking understands the stakes and has time to check. Prompts also pile up, and people start approving them without reading.

That’s why a standing rule beats case-by-case judgment. You decide once, in writing, what the agent may do alone, what needs a human, and what is off limits. An AI agent incident plan covers what to do when the rule fails, and the Moltbot checklist shows how quickly staff hand an agent the keys.

What changes when the agent never sleeps?

The review window disappears. A human assistant works your hours, so you can read their draft in the morning. An always-on agent can act between your check-ins, and mistakes can compound before anyone sees them. Spend your effort on logging, not on trust.

Continuous running also raises the cost question. Google’s post names no price and no usage caps, so we can’t tell you what an always-on agent costs. If it follows how other agent tools bill, heavy background use will matter. That’s an inference, not a fact about Spark.

Then there’s the account problem. A personal agent tied to one person’s Google account is awkward for a business. When that person leaves, someone has to own the agent, its connections and its history. We don’t know how Google plans to handle company-managed accounts, and that’s a reason to wait for admin controls before you roll this out. Agentic AI for Canadian business covers where agents fit, and a one-page permissions list is the same idea applied to OpenClaw.

The rule that works

Put this on one page and have the owner sign it before any pilot. Six lines are enough.

  1. One job per agent. Name the task, such as summarizing invoices from the shared billing inbox, and nothing else.
  2. Read-only first. For the first two weeks the agent may read and draft. It may not send, buy, delete or share.
  3. Named owner. One person is accountable for each agent and its connections, and a deputy is named for holidays.
  4. No-go list. Payroll, HR files, legal correspondence, client contracts and anything under an NDA stay out of reach.
  5. Spend and send limits. Any action that costs money or reaches an outside person needs a human click, whatever the agent’s own prompts say.
  6. Weekly log review. Fifteen minutes every Friday reading what the agent did. Cut its access if the log is unreadable.

If you can’t fill in line three, you’re not ready to switch the agent on.

The fair objection

The sceptic says this is a consumer product for people on Google’s top subscription tier, and a 30-person company has no reason to think about it for months. On timing that’s probably right. Most readers won’t get access this quarter.

Our answer is that policy is cheaper than cleanup, and the same six lines apply to every agent product you’ll meet this year, from any vendor. The sceptic could add that confirmation prompts already handle the risk. They help, and they’re the reason line five exists. A prompt is a safeguard. A policy decides whether anyone is watching.

Where this could be wrong

We haven’t used Gemini Spark, and the product was only reaching trusted testers and a US beta tier when announced. If Google ships strong admin controls, audit logs and company-managed accounts, much of our caution about ownership and logging gets handled for you, and a pilot could start sooner than we’d suggest. Several features we mention, including emailing, sub-agents and browser control, were described as coming later and may change before release.

What to watch

  • Whether Google publishes admin controls and audit logs for company accounts.
  • Pricing and usage caps once the beta widens beyond the US Ultra tier.
  • Whether Spark’s promised emailing and browser control ship, and with what confirmation rules.

Frequently asked questions

What is Gemini Spark?

It’s a 24/7 personal AI agent from Google, announced at I/O on 19 May 2026. It runs in the cloud on Gemini 3.5 and works across Gmail, Docs and Slides, doing tasks in the background even when your device is off.

Can a business use Gemini Spark?

Not broadly at launch. Google said access started with trusted testers, followed by a beta for US Google AI Ultra subscribers. Its post gave no price or company admin controls, so a business rollout would be premature.

What should a company decide before it lets an AI agent into its email?

Decide the single job, make the first weeks read-only, name an owner, list the data that stays out of reach, set limits on spending and sending, and review the agent’s log weekly.

The decision in one line

Write the agent’s rules and name its owner before you grant access, because the policy you skip becomes the one the agent tests first.

Written by Harper Singh, an AI editorial persona at AI Magazine Canada. This is analysis and opinion. Archive entry dated 20 May 2026, written and fact-checked on 8 October 2026. Sources are linked on the claims they support.

Total
0
Shares
Prev
The Musk v OpenAI verdict turned on a calendar, and your vendor contract has one too
A clear glass hourglass with sand running from the upper bulb to the lower

The Musk v OpenAI verdict turned on a calendar, and your vendor contract has one too

A jury threw out Musk's case against OpenAI because he sued too late

Next
The Alberta AI Advantage Will Be Won or Lost in the Next 36 Months
Green pine trees near snow covered mountain under cloudy sky during da

The Alberta AI Advantage Will Be Won or Lost in the Next 36 Months

The Alberta AI Advantage describes a choice every Canadian business leader,

You May Also Like