Gemini Spark, announced at Google I/O on 19 May 2026, is not a chatbot. It is a persistent, cloud-based AI agent that runs continuously on dedicated Google virtual machines, 24 hours a day, even when every device in your office is switched off. Out of the box, it has access to Gmail, Google Docs, Sheets, Slides, and Calendar. It can draft and send emails on your staff’s behalf. It connects to third-party tools via MCP integrations that are expanding throughout 2026.
For businesses using Google Workspace, this is already a live consideration. Most IT policies cover what employees can do on their devices. Almost none cover what an AI agent can do on their behalf.
That gap needs closing now.
What Gemini Spark Actually Is – and Why It Is Different From a Chatbot
Most AI tools operate on a prompt-and-response basis. You ask a question; the AI answers. You close the tab; it stops.
Spark works differently. It runs persistently in Google Cloud, on dedicated virtual machines that are separate from your device. You do not need to have a laptop open, a browser running, or a phone unlocked for Spark to continue working. It monitors, drafts, and acts independently until you tell it to stop.
At launch, Spark can:
- Monitor your Gmail inbox and surface urgent messages
- Draft documents by pulling information from across Gmail, Docs, Sheets, and Slides
- Manage calendar scheduling and preparation
- Connect to Canva, OpenTable, and Instacart via live MCP integrations, with broader third-party connections expanding across summer 2026
- Operate Chrome as an agentic browser — arriving later this summer
Google has described Spark as “designed to ask before performing high-stakes actions.” The definition of what counts as high-stakes is Google’s, not yours. For most businesses, that distinction matters.
Spark is currently available to Google AI Ultra subscribers in the US, with broader rollout following. If any of your staff hold personal Google AI Ultra subscriptions, they may already have access. If your business has Google Workspace accounts on higher-tier plans, access timelines will vary.
Why This Is an IT and Security Question, Not Just a Productivity One
The questions most businesses have not yet asked:
Who has access? Conduct an audit of which staff hold Google AI Pro or Ultra subscriptions, whether personal or through a business account. Spark access follows subscription tier, not company policy. A staff member with a personal Google AI Ultra account has Spark available regardless of what your IT policy says.
What data can Spark reach? If an employee enables Spark on their work Gmail account, it has read access to their full inbox. If that inbox contains client communications, financial information, HR correspondence, or confidential project data, Spark can synthesise and act on all of it.
What happens when MCP connections are added? MCP is an open protocol, and Google has confirmed that Spark’s third-party connections will expand significantly in 2026. An employee connecting Spark to a project management tool, a CRM, or a file-sharing platform creates a data pathway that your MDM setup will not see.
Who owns communications sent by Spark? If Spark drafts and sends an email on behalf of a staff member, which it is capable of doing, the business is responsible for that communication. The employee may not have reviewed it. Your acceptable use policy almost certainly does not address this scenario.
How does this interact with your DSAR obligations? Under UK GDPR, a Subject Access Request requires you to produce all personal data held about an individual. Spark reading and synthesising email content across an account complicates what “data held” means in practice. If Spark has summarised or categorised communications involving a data subject, the status of that synthesised output is not yet clearly defined.
What Your IT Policy Should Address
The businesses that navigate this well will be those that act now, before an incident forces a reactive response. Dr Logic recommends the following as a starting framework.
Audit access first. Before writing policy, know the current state. Which staff have Google AI Ultra personally? Which Workspace accounts include Gemini AI features? This audit is the foundation for everything else.
Extend your acceptable use policy to AI agents. Your AUP almost certainly covers device use, cloud storage, and BYOD. Add a section that covers AI agents explicitly: what data sources they may connect to, what actions they are permitted to take autonomously, and what requires human review before execution.
| Data Category | Permitted AI Agent Access | Notes |
|---|---|---|
| Personal inbox and calendar | Yes, with employee consent | Default at individual level |
| Shared team drives | Defined by role and sensitivity | Requires policy decision |
| Client project files | Restricted | Review required before connection |
| Financial records | Restricted | Restrict by default |
| HR and personnel data | Prohibited | No AI agent connection |
Define which data sources are off-limits. Not every connection Spark could make should be permitted in a business context. Client data repositories, financial systems, and HR records should be explicitly excluded from AI agent access until your business has reviewed the implications.
Consider disclosure for AI-generated communications. If Spark is drafting emails on behalf of staff, your business needs a position on whether those communications require review before sending, and whether clients or counterparties have a reasonable expectation of knowing the content was AI-generated.
Recognise that device-level controls do not cover this. MDM manages devices. Spark runs in the cloud. Your Jamf or MDM configuration, however well set up, has no visibility over what Spark is doing in an employee’s Google account. This requires policy, not software.
The Opportunity, Not Just the Risk
Spark and tools like it represent genuine productivity gains that small and lean teams will find meaningful. A founder who cannot monitor every incoming customer enquiry now has an agent that can. A two-person operations team that spends hours preparing status documents now has a tool that drafts them automatically. These are real capabilities, not theoretical ones.
The goal is not to block agentic AI. It is to adopt it with appropriate guardrails in place. Businesses that do this now, that audit access, define boundaries, and update their policies before an incident, will be able to use these tools confidently and move faster as they mature.
Businesses that do not will find themselves managing reactive compliance problems against a background of tools that were already running.
Dr Logic helps businesses build IT governance frameworks that keep pace with the rate of change. If your team is already using Gemini tools or you want to understand what the right guardrails look like for your setup, an IT assessment is the right starting point.
Related Articles
- Apple Business Manager: The Foundation of Scalable Apple Deployment
- Apple for Regulated Industries: What Compliance Looks Like on macOS
- What Cyber Essentials Certification Actually Looks Like for an All-Mac Office
FAQs
Does Gemini Spark have access to my staff's email without permission?
Spark requires the individual user to enable it and grant access. However, once enabled on a personal or work Google account, it can access the full Gmail inbox by default. Businesses should audit which staff have Google AI Ultra subscriptions and confirm whether Spark has been enabled on any work accounts, this is not something MDM or device management will surface automatically.
Does my existing IT policy cover AI agents acting on behalf of employees?
Almost certainly not. Most IT acceptable use policies address device use, cloud storage, and BYOD, not AI agents that can autonomously draft emails, connect to third-party tools, and act on behalf of staff in the background. Extending your AUP to cover AI agent access and permitted actions is now a practical necessity, not a future consideration.
How does Gemini Spark interact with UK GDPR and Subject Access Requests?
This is an evolving area. Spark reading and synthesising personal data held in an employee’s Gmail account raises questions about what constitutes “data held” under UK GDPR and how synthesised AI outputs should be treated in response to a Subject Access Request. Businesses that handle significant volumes of personal data in Gmail should take legal advice on their specific position and review their DSAR procedures accordingly.



















































