Gemini Agent for Work: Should Sydney Businesses Use It?

Should Sydney businesses let Google's Gemini Agent run tasks for days? Review privacy, access controls, cost and oversight before automating critical workflows.

By ELYMENT Insights
Gemini Agent for Work: Should Sydney Businesses Use It?

Google's new Gemini agent for work is designed to execute tasks over hours or days, coordinate specialist agents and operate across connected workplace applications. For Sydney businesses, the opportunity is faster administration and project coordination. The risk is allowing autonomous work to continue after instructions, permissions or commercial circumstances change. Businesses should establish accountable owners, time-limited authority and human approval before agents make consequential operational decisions.

The AI Coworker Could Still Be Working When Everyone Else Has Gone Home

On Friday afternoon, a Sydney operations manager asks an AI agent to prepare the following week's project schedule, reconcile outstanding supplier confirmations and assemble an updated management report.

The manager closes their laptop. The agent continues.

By Monday morning, a contractor has changed an installation date, a building manager has withdrawn an access window and a client has requested a variation. The agent may have completed much of its assignment, but parts of the original instructions no longer reflect the project.

That scenario illustrates the central operational challenge raised by Google's latest workplace AI announcement. Persistence is valuable only when the system can distinguish instructions that remain valid from decisions that require fresh authority.

At its Gemini at Work event on 8 October 2026, Google Cloud introduced a universal Gemini agent intended to handle knowledge work, create content, generate and run code, and coordinate activities across business applications.

According to Google's official Gemini at Work announcement, tasks can continue in the cloud for hours or days, even after the user disconnects. The system is also designed to coordinate specialist sub-agents and preserve context across different devices and working sessions.

The new universal agent was reported to be in private enterprise preview at launch. Its announced capabilities should therefore not be confused with independently demonstrated reliability across every business process or general availability to all Google Workspace customers.

Elyment has previously examined how Google's managed AI agents can execute background business tasks. The October announcement introduces a different organisational question: what changes when the technology is presented not merely as a background service, but as a continuing member of a team?

Google Is Giving the Agent a Workplace Identity. That Changes the Accountability Question.

One of the more consequential details in Google's announcement is its proposed coworker identity.

A Gemini coworker agent can have its own email address, calendar, persistent storage and presence in the organisation's directory. Colleagues can involve it in shared conversations, mention it in documents and assign it responsibilities.

This is a significant departure from an employee privately using an AI assistant to draft an email.

An agent operating under a distinct identity can become part of the organisation's visible record of work. It may prepare reports, participate in discussions, produce document revisions and coordinate multiple contributors.

However, a separate account does not create independent commercial, professional or legal authority.

Consider a Sydney property services business. An AI coworker could collect contractor updates, identify missing documents and compile a schedule for review. But the existence of an agent email address does not mean it should be authorised to confirm building access, accept a contract variation or promise a revised completion date.

Every persistent agent therefore needs an accountable human owner, a defined operational role and a clear distinction between preparing work and authorising outcomes.

The Four Clocks That Can Make a Multi-Day Agent's Work Outdated

Most enterprise automation discussions concentrate on speed, task completion and access permissions. Long-running agents introduce a further variable: time.

A multi-day assignment can cross four different operational clocks.

1. The project clock

Site conditions, work sequences, supplier availability and delivery dependencies can change while the agent is processing an earlier instruction. A valid Friday programme may be commercially useless on Monday.

2. The authority clock

Approval may be valid only for a particular transaction, amount, customer request or stage of work. Permission to draft an initial programme should not automatically extend to approving a changed programme after new information arrives.

3. The information clock

The agent may retrieve a document before its revision, rely on an outdated price or miss information held outside connected systems. Persistent memory does not establish that the information remains current.

4. The human clock

Employees finish shifts, take leave, hand projects to colleagues or become unavailable. An agent can keep working when the person who initiated the assignment is no longer responsible for the next decision.

For Sydney businesses with contractors, building managers, owners and professional advisers operating on different schedules, these clocks rarely align perfectly.

The practical response is to treat a long-running assignment as a sequence of authorised stages, rather than one instruction that remains valid indefinitely.

Where an AI Coworker Could Help Sydney Property Operations

Google's architecture is relevant to businesses whose information is distributed across email, document repositories, calendars, project systems and external suppliers.

In renovation and property delivery, the administrative burden can involve dozens of small dependencies surrounding a relatively straightforward physical job.

Potential AI Agent Applications and Required Human Decisions

Contractor coordination

  • Potential agent contribution: Collate updates and identify conflicting proposed dates.
  • Required human decision: Confirm changes with responsible contractors and project managers.

Renovation scheduling

  • Potential agent contribution: Prepare programme options using recorded task dependencies.
  • Required human decision: Approve sequence, site access and resource commitments.

Quotation administration

  • Potential agent contribution: Compare scope versions and identify missing pricing details.
  • Required human decision: Approve final prices, exclusions and contractual communications.

Strata project preparation

  • Potential agent contribution: Assemble approval correspondence and identify missing documents.
  • Required human decision: Verify actual strata approvals, permitted work and access conditions.

Property transaction support

  • Potential agent contribution: Organise correspondence and flag outstanding information.
  • Required human decision: Qualified practitioners verify legal requirements and advise clients.

Management reporting

  • Potential agent contribution: Consolidate project status, costs and unresolved actions.
  • Required human decision: Validate source records before issuing consequential reports.

These are potential workflow applications, not claims that Google's newly announced agent has been independently tested on Sydney property projects.

The distinction matters. A system capable of drafting an installation schedule is not necessarily capable of recognising that an apartment's goods lift has become unavailable, that noisy works require additional coordination or that a substrate inspection has identified an unexpected issue.

Physical works still depend on verified conditions, competent site assessments, appropriate permissions and accountable project personnel.

An Approval Given on Friday Should Not Automatically Apply on Monday

Google says its new agent architecture includes distinct agent identities, permission controls, audit trails, sandboxing and policy enforcement. These are important enterprise design features.

The harder business question is what happens when an agent remains technically authorised but the circumstances supporting the original decision have changed.

Consider an agent instructed to coordinate supplier availability for a commercial fit-out. During the assignment, the preferred supplier changes its delivery date and offers a different product.

If the agent merely identifies the change and requests a decision, it is supporting coordination.

If it automatically accepts the substitution, alters the installation sequence and confirms the new arrangement to the client, it has crossed into commercial decision-making.

A safer delegation policy would distinguish between:

  • Read authority: Retrieve information from approved systems.
  • Preparation authority: Create drafts, comparisons and recommendations.
  • Internal update authority: Modify narrowly defined records with appropriate validation.
  • External action authority: Send commitments or change shared arrangements only after required approvals.
  • Expiry conditions: Pause or seek renewed approval after material changes or a defined time period.

The expiry condition is particularly relevant to persistent agents. A task lasting three days should not automatically carry three days of unrestricted decision-making authority.

Elyment's earlier examination of Google's Beyond Zero approach to AI agent permissions explains why access needs to be assessed at the level of individual actions. Multi-day operations add another requirement: revalidate the circumstances before consequential actions proceed.

The Agent's Own Email Account Creates a New Records Problem

Giving an agent a recognisable workplace identity may make collaboration easier. It also creates questions about document authorship, communication history and responsibility.

If an AI coworker posts a project status update, staff should be able to determine whether the information was independently verified or generated from earlier records.

If the agent drafts a response to a customer, the business should know whether that response was actually sent, who authorised it and which information supported its contents.

An agent's name appearing in a document's version history is useful for traceability. It does not replace the need to determine who is accountable for the resulting decision.

This is also a privacy question.

The Office of the Australian Information Commissioner's guidance on commercially available AI recommends due diligence, appropriate human oversight, information accuracy, data minimisation and ongoing monitoring.

Australian Privacy Principles obligations apply to covered entities and relevant handling of personal information. The precise obligations depend on the organisation and circumstances, so businesses should not assume every deployment has identical statutory requirements.

A Sydney business using an AI coworker should examine whether connected folders, email threads and shared workspaces contain customer addresses, employee information, property documents, quotations or confidential professional correspondence.

For example, permission to read a shared project programme does not necessarily justify access to an entire customer's property transaction file.

NSW Is Moving Towards Formal AI Assurance, but the Rules Are Not Identical for Every Business

NSW's approach to public-sector artificial intelligence provides a useful governance comparison for commercial operators.

Under the NSW AI Assessment Framework, government agencies must register AI use cases and undertake assessments when required. The framework addresses governance, transparency, privacy, security and lifecycle monitoring.

Its centralised registration platform became mandatory for NSW Government agencies from 30 September 2026.

This is not a blanket legal requirement imposed on every private Sydney company. Nevertheless, the underlying governance questions are commercially relevant.

Who approved the use case? What records can the agent access? How will its decisions be reviewed? What happens when the system changes, the task is reassigned or the original business need no longer exists?

An organisation responsible for renovation, infrastructure, property management or sensitive client information should answer those questions before granting an agent broader operational responsibilities.

The Commercial Test Is Accepted Work, Not How Long the Agent Remains Active

Google's announcement includes model selection, workload routing and spending controls intended to make autonomous operation more economical.

However, a task continuing for 48 hours does not necessarily represent 48 hours of productive work.

A business evaluating multi-day automation should measure the complete cost of obtaining an accepted result.

This includes compute and model costs, tool usage, integration work, human review, correction of errors and any operational delay created by incorrect recommendations.

Suppose an agent produces a comprehensive project report without staff intervention. If a coordinator then spends substantial time correcting outdated information, checking unsupported conclusions and rebuilding the recommended schedule, the apparent automation saving may be substantially reduced.

Conversely, a more restricted agent that produces a concise, source-linked exception report might create greater business value, even if its output appears less sophisticated.

Elyment previously analysed Gemini coding agents and the economics of long-running technical work. For a workplace coworker, the comparable measure is how much verified operational work reaches the correct person without creating additional coordination burden.

What a Sydney Business Should Require From a Multi-Day Pilot

The most defensible first application is a defined workflow in which the agent can provide measurable assistance without independently binding the organisation to new commitments.

A suitable example would be a project coordination assistant preparing handover reports for a small portfolio of renovation jobs.

Before starting, the business should define the following operating conditions.

  1. Establish one accountable owner. Nominate a staff member responsible for the agent's objectives and exceptions.
  2. Restrict its source material. Provide only the project records necessary for the approved task.
  3. Set freshness requirements. Require renewed checks before relying on dates, pricing, access arrangements or changing project status.
  4. Create explicit handover points. Record what the agent completed, what remains uncertain and what needs a human decision.
  5. Keep external commitments locked. Draft customer messages and supplier instructions for approval rather than allowing unrestricted dispatch.
  6. Measure verified outcomes. Compare review time, errors, accepted outputs and costs against the existing manual process.

The assessment should include a controlled scenario in which the agent's original information becomes outdated while the assignment remains active.

Can the system identify the change, stop the affected action and notify the correct person? Or does it continue towards an obsolete objective?

That result may reveal more about operational readiness than a polished demonstration.

The Next Workplace Test Is Whether an AI Agent Knows When to Stop

Google is moving workplace AI towards continuing assignments, persistent identity and coordination between specialised agents. The ambition is significant, particularly for businesses where administrative work spans multiple employees, applications and working days.

Yet autonomy introduces a management problem that faster models alone cannot solve. The organisation must determine when an instruction expires, when circumstances require renewed approval and who accepts responsibility for the outcome.

Sydney businesses do not need an AI coworker that simply continues working for days. They need one that can continue useful work while recognising the boundary between administrative progress and a decision that belongs to a person.

The defining capability may ultimately be less about how long the agent can run and more about whether it knows when it must stop.

Before You Delegate the Work, Define the Decision.

OPERATIONAL WORKFLOW & PROJECT REVIEW

Review project dependencies, workflow responsibilities, information access and approval requirements before introducing autonomous agents into everyday operations.

Discuss an Operational Workflow Review →

PROJECT COORDINATION • WORKFLOW ASSURANCE • CONTROLLED DELIVERY

Sources and References

  1. Google Cloud: Welcome to Gemini at Work 2026
  2. Office of the Australian Information Commissioner: Guidance on Privacy and the Use of Commercially Available AI Products
  3. NSW Government: NSW AI Assessment Framework
  4. Elyment: AI Services Can Now Run as Background Workers — What Google's Managed Agents Change for Business Automation
  5. Elyment: Google Says Zero Trust Is Not Enough for AI Agents — What Beyond Zero Changes for Business Automation
  6. Elyment: Google Gemini 4 Argon, Coding Agents and 1M-Token Output


OPERATIONAL WORKFLOW & PROJECT REVIEW

Before You Delegate the Work, Define the Decision.

Review project dependencies, workflow responsibilities, information access and approval requirements before introducing autonomous agents into everyday operations.

Request a Workflow Review PROJECT COORDINATION • WORKFLOW ASSURANCE • CONTROLLED DELIVERY

Relevant next actions

Explore the ELYMENT service most closely connected to this article.

Explore more ELYMENT articles