Google Cloud Adds Agent Sandbox and Skills Registry to Gemini Enterprise
The Brazil Summit update introduces governed agent execution and reusable skills alongside persistent project workspaces, but rollout scope and independent security evidence remain unclear.
Edited by Tyronne Panaino
Google Cloud announced new Gemini Enterprise controls on September 24 at its Brazil Summit, adding persistent Projects, a Skills Registry and an Agent Sandbox. The changes matter to organizations moving from chat-style assistance toward agents that retain working context, reuse specialized capabilities and execute actions inside managed environments.
For administrators, developers and security teams, the important change is not a new model. It is a set of control surfaces around how enterprise agents remember work, obtain reusable skills and run tools. Google describes the features on one official announcement page, so the confirmed scope is limited to what that page establishes.
Persistent projects create a governed work boundary
Projects give an employee or team a dedicated space tied to a chosen set of files or documents. Google says those spaces persist, keeping shared organizational memory, context and operational state over time. That creates a more durable workspace than a single isolated prompt session.
Persistence also raises practical governance questions. Organizations will need to decide who may add material, how access changes are reflected, when retained context should expire and how a project's state is reviewed. Google's announcement does not specify retention controls, audit exports or plan eligibility for Projects, so buyers should treat those details as unresolved rather than implied.
The Skills Registry separates capability from permission
The Skills Registry is presented as a central place to govern reusable instructions, scripts and resources. Policy can determine which skill is available to a particular agent, person or team. That separation is useful because an agent's ability to discover a capability should not automatically mean every user or workflow may invoke it.
A registry can make ownership and reuse easier to inspect, but the announcement does not describe approval workflows, version history, dependency checks or how a compromised skill would be contained. Teams evaluating the feature should ask for those operational details and test whether policy decisions remain understandable as the number of agents and skills grows.
Agent Sandbox moves execution into a managed environment
Google describes Agent Sandbox as a secure, isolated and managed environment where agents can compile and execute code, use a command-line interface and operate a browser. This is the most consequential part of the update because it brings execution, network activity and tool use closer to the agent platform itself.
The word sandbox does not by itself establish resistance to escape, data leakage or malicious dependencies. The fetched announcement provides no independent security assessment, isolation design, default network policy or measured abuse testing for the feature. Security teams should therefore evaluate the actual permission model and logging before treating the product label as a complete control.
Availability remains the main missing detail
The source clearly announces the three capabilities, but it does not attach a general-availability or preview label, a rollout date, a plan requirement or a geographic boundary to Projects, Skills Registry or Agent Sandbox. That leaves a gap between the product direction and what every Gemini Enterprise customer can use today.
The announcement was made in Brazil alongside regional infrastructure and data-residency news, yet it does not say that these three controls are Brazil-only. The safest reading is that Google introduced the capabilities in a regional launch package while leaving their exact entitlement and rollout scope unspecified.
Status
Confirmed. Google Cloud's official announcement establishes the new Gemini Enterprise capabilities. Internal confidence is medium because one vendor source supports the story and no independent deployment, security or adoption evidence was fetched.
Sources
Update note: Last reviewed 2026-09-24. We will revise this post if Google publishes availability, entitlement, governance or independent security details for these controls.
Sources
Drafted with AI assistance from source briefs; reviewed for citation completeness and label accuracy.