Your Staff Now Have AI Agents Running in Their Google Accounts Around the Clock – Here’s What Your IT Policy Needs to Say

A friendly robot with blue eyes sits at a desk using a silver laptop, with two speech bubbles above it, suggesting it's chatting about IT policy and Google accounts. The background is a solid blue colour.

Gemini Spark, announced at Google I/O on 19 May 2026, is not a chatbot. It is a persistent, cloud-based AI agent that runs continuously on dedicated Google virtual machines, 24 hours a day, even when every device in your office is switched off. Out of the box, it has access to Gmail, Google Docs, Sheets, Slides, and Calendar. It can draft and send emails on your staff’s behalf. It connects to third-party tools via MCP integrations that are expanding throughout 2026.

For businesses using Google Workspace, this is already a live consideration. Most IT policies cover what employees can do on their devices. Almost none cover what an AI agent can do on their behalf.

That gap needs closing now.

What Gemini Spark Actually Is – and Why It Is Different From a Chatbot

Most AI tools operate on a prompt-and-response basis. You ask a question; the AI answers. You close the tab; it stops.

Spark works differently. It runs persistently in Google Cloud, on dedicated virtual machines that are separate from your device. You do not need to have a laptop open, a browser running, or a phone unlocked for Spark to continue working. It monitors, drafts, and acts independently until you tell it to stop.

At launch, Spark can:

  • Monitor your Gmail inbox and surface urgent messages
  • Draft documents by pulling information from across Gmail, Docs, Sheets, and Slides
  • Manage calendar scheduling and preparation
  • Connect to Canva, OpenTable, and Instacart via live MCP integrations, with broader third-party connections expanding across summer 2026
  • Operate Chrome as an agentic browser — arriving later this summer

Google has described Spark as “designed to ask before performing high-stakes actions.” The definition of what counts as high-stakes is Google’s, not yours. For most businesses, that distinction matters.

Spark is currently available to Google AI Ultra subscribers in the US, with broader rollout following. If any of your staff hold personal Google AI Ultra subscriptions, they may already have access. If your business has Google Workspace accounts on higher-tier plans, access timelines will vary.

Why This Is an IT and Security Question, Not Just a Productivity One

The questions most businesses have not yet asked:

Who has access? Conduct an audit of which staff hold Google AI Pro or Ultra subscriptions, whether personal or through a business account. Spark access follows subscription tier, not company policy. A staff member with a personal Google AI Ultra account has Spark available regardless of what your IT policy says.

What data can Spark reach? If an employee enables Spark on their work Gmail account, it has read access to their full inbox. If that inbox contains client communications, financial information, HR correspondence, or confidential project data, Spark can synthesise and act on all of it.

What happens when MCP connections are added? MCP is an open protocol, and Google has confirmed that Spark’s third-party connections will expand significantly in 2026. An employee connecting Spark to a project management tool, a CRM, or a file-sharing platform creates a data pathway that your MDM setup will not see.

Who owns communications sent by Spark? If Spark drafts and sends an email on behalf of a staff member, which it is capable of doing, the business is responsible for that communication. The employee may not have reviewed it. Your acceptable use policy almost certainly does not address this scenario.

How does this interact with your DSAR obligations? Under UK GDPR, a Subject Access Request requires you to produce all personal data held about an individual. Spark reading and synthesising email content across an account complicates what “data held” means in practice. If Spark has summarised or categorised communications involving a data subject, the status of that synthesised output is not yet clearly defined.

What Your IT Policy Should Address

The businesses that navigate this well will be those that act now, before an incident forces a reactive response. Dr Logic recommends the following as a starting framework.

Audit access first. Before writing policy, know the current state. Which staff have Google AI Ultra personally? Which Workspace accounts include Gemini AI features? This audit is the foundation for everything else.

Extend your acceptable use policy to AI agents. Your AUP almost certainly covers device use, cloud storage, and BYOD. Add a section that covers AI agents explicitly: what data sources they may connect to, what actions they are permitted to take autonomously, and what requires human review before execution.

Data CategoryPermitted AI Agent AccessNotes
Personal inbox and calendarYes, with employee consentDefault at individual level
Shared team drivesDefined by role and sensitivityRequires policy decision
Client project filesRestrictedReview required before connection
Financial recordsRestrictedRestrict by default
HR and personnel data Prohibited No AI agent connection

Define which data sources are off-limits. Not every connection Spark could make should be permitted in a business context. Client data repositories, financial systems, and HR records should be explicitly excluded from AI agent access until your business has reviewed the implications.

Consider disclosure for AI-generated communications. If Spark is drafting emails on behalf of staff, your business needs a position on whether those communications require review before sending, and whether clients or counterparties have a reasonable expectation of knowing the content was AI-generated.

Recognise that device-level controls do not cover this. MDM manages devices. Spark runs in the cloud. Your Jamf or MDM configuration, however well set up, has no visibility over what Spark is doing in an employee’s Google account. This requires policy, not software.

The Opportunity, Not Just the Risk

Spark and tools like it represent genuine productivity gains that small and lean teams will find meaningful. A founder who cannot monitor every incoming customer enquiry now has an agent that can. A two-person operations team that spends hours preparing status documents now has a tool that drafts them automatically. These are real capabilities, not theoretical ones.

The goal is not to block agentic AI. It is to adopt it with appropriate guardrails in place. Businesses that do this now, that audit access, define boundaries, and update their policies before an incident, will be able to use these tools confidently and move faster as they mature.

Businesses that do not will find themselves managing reactive compliance problems against a background of tools that were already running.

Dr Logic helps businesses build IT governance frameworks that keep pace with the rate of change. If your team is already using Gemini tools or you want to understand what the right guardrails look like for your setup, an IT assessment is the right starting point.

Related Articles

FAQs

Does Gemini Spark have access to my staff's email without permission?

Spark requires the individual user to enable it and grant access. However, once enabled on a personal or work Google account, it can access the full Gmail inbox by default. Businesses should audit which staff have Google AI Ultra subscriptions and confirm whether Spark has been enabled on any work accounts, this is not something MDM or device management will surface automatically.

Does my existing IT policy cover AI agents acting on behalf of employees?

Almost certainly not. Most IT acceptable use policies address device use, cloud storage, and BYOD, not AI agents that can autonomously draft emails, connect to third-party tools, and act on behalf of staff in the background. Extending your AUP to cover AI agent access and permitted actions is now a practical necessity, not a future consideration.

How does Gemini Spark interact with UK GDPR and Subject Access Requests?

This is an evolving area. Spark reading and synthesising personal data held in an employee’s Gmail account raises questions about what constitutes “data held” under UK GDPR and how synthesised AI outputs should be treated in response to a Subject Access Request. Businesses that handle significant volumes of personal data in Gmail should take legal advice on their specific position and review their DSAR procedures accordingly.

Woman with long dark hair and layered necklaces sits at an outdoor cafe table, with buildings visible in the background.
Paige

Marketing Executive

Paige leads content and marketing at Dr Logic, translating the team's deep technical expertise into practical, straight-talking advice for businesses running on Apple. She covers everything from IT strategy and cyber security to the trends shaping how modern teams work - always with a focus on what actually matters to the people making the decisions.

Explore More Articles

Clear, Actionable Advice – No Jargon, No Pressure.

Get In Touch With an IT Expert

Scaling up, tackling downtime, or reviewing your setup? Contact us or book a quick call for expert advice on running your IT smarter and more securely.

Rather speak to us right now? Our phone number is: 020 3642 6540


Contact Form

You can unsubscribe from these communications at any time. To learn more about how to unsubscribe and how we protect your personal data, please see our Privacy Policy.

Book a Consultation Form

You can unsubscribe from these communications at any time. To learn more about how to unsubscribe and how we protect your personal data, please see our Privacy Policy.

Want IT to Work Smarter for You?

Get expert tips, security advice, and practical insights for Apple and hybrid teams – straight to your inbox.


Subscription Form

You can unsubscribe from these communications at any time. To learn more about how to unsubscribe and how we protect your personal data, please see our Privacy Policy.