Google Cloud Blog Note

Google Cloud Blog

cloud.google.com/blog is the official blog of Google Cloud. It provides news, updates, and insights on Google Cloud's products and services, as well as trends and innovations in the cloud computing industry. The blog features articles written by Google Cloud experts, engineers, and thought leaders, covering a wide range of topics such as artificial intelligence, machine learning, data analytics, security, and more. The articles often include technical tutorials, case studies, and best practices, making the blog a valuable resource for developers, IT professionals, and business leaders who use or are interested in Google Cloud. The blog is well-organized, with articles categorized by topic, product, and industry. Visitors can browse the latest articles, search for specific topics, or subscribe to the blog's RSS feed to stay up-to-date with the latest news and updates. Some of the key features of the blog include: - In-depth articles on Google Cloud products and services, such as Google Cloud Platform, Google Cloud Storage, and Google Cloud AI Platform - Technical tutorials and guides on how to use Google Cloud services - Case studies and success stories from Google Cloud customers - Insights and analysis on industry trends and innovations - News and updates on Google Cloud's partnerships and collaborations - Interviews with Google Cloud experts and thought leaders Overall, the Google Cloud blog is a valuable resource for anyone interested in cloud computing, artificial intelligence, and related technologies.

Thread Of Notes

Effective delegation is a crucial leadership skill, now being applied to AI agents in enterprise workflows. Multi-agent systems are ideal for complex tasks, requiring AI agents to become intelligent delegators. Research from Google DeepMind highlights delegation as an intelligent process involving negotiation, contracts, and security. Four principles emerge for building AI agents that can effectively delegate tasks.The first principle is to verify delegated work through "contract-first decomposition," breaking tasks into manageable, verifiable chunks. Ideally, work can be reliably graded, but subjective assessment may necessitate human expert judgment. The second principle emphasizes being smart about cost by matching task complexity to appropriate AI models. Simple tasks should not burden expensive, powerful models, while complex ones require greater capability.The third principle, respecting sensitive data, means AI agents must adhere to boundaries and permissions, granting only the minimum necessary access for a task. Advanced cryptography, like zero-knowledge proofs, can verify work without revealing private data. The fourth principle, beware the zone of indifference, cautions against AI agents blindly complying with requests. Intelligent delegation requires "dynamic cognitive friction" to validate information and challenge ambiguous requests. This prevents subtle errors or harms from propagating through delegation chains. Ultimately, the goal is to integrate AI agents seamlessly into organizations, working alongside human experts.
Google Antigravity is now integrated into eligible Gemini Enterprise app subscriptions, addressing customer feedback for enhanced developer access and enterprise controls. Developers can now utilize Antigravity across various surfaces, including IDE extensions for VS Code, Visual Studio, Jetbrains, and Zed, as well as a desktop app and CLI. Enterprise governance teams benefit from built-in administrative features, security controls, and license management, all consolidated within the Gemini Enterprise admin console. Finance teams gain flexibility with pooled usage quotas, preventing prepaid tokens from remaining idle.Granular spend thresholds and overage enablement options allow administrators to set project-level budget caps and maintain continuous developer workflows. Comprehensive usage metrics provide visibility into token consumption and developer activity for optimization. The integration ensures Antigravity operates under Google Cloud's standard security and compliance protections, including configurable security policies, central audit logging, and data privacy adherence. Identity federation and application default credentials simplify setup for technical teams.Customers like Accenture, AirAsia, CGI, and Cognizant are already leveraging Antigravity in Gemini Enterprise to accelerate development, automate tasks, and deliver transformative value. The platform empowers teams to move beyond simple code generation towards orchestrating complex outcomes securely and responsibly. Antigravity in Gemini Enterprise is available today for eligible Gemini Enterprise Standard, Plus, and Standard Emerging Market licenses. Administrators can enable AI developer tools via the enterprise setup guide, while developers can begin building with Antigravity 2.0, the CLI, or IDE extensions.
CdXz5zHNQW_mRaZZsqdoS.gif
Google Cloud has been recognized as a Leader in the Gartner Magic Quadrant for Cloud-Native Application Platforms for the third consecutive year. This recognition highlights Google's commitment to a developer-centric platform that simplifies infrastructure complexity for modern workloads. The platform supports serverless, containerized, and agentic deployment options, catering to both traditional microservices and advanced AI applications. Generative AI is integrated, enabling rapid prototyping through tools like Google AI Studio and managed MCP servers for AI agent interaction. Google's official Skills Repository provides pre-built expertise for agents, further accelerating development.Transitioning from prototypes to production, Google Cloud offers tools for architects and platform engineers throughout the application lifecycle. The Antigravity harness unifies development, while Application Design Center automates configuration and design for standardized deployments. For operations, Gemini Cloud Assist provides AI-driven incident investigations and cost analysis, leveraging machine learning for efficiency. High availability and reliability are ensured through features like Cloud Run's automated cross-region failover.Google Cloud champions an open-source strategy, contributing to the Cloud Native Computing Foundation for enhanced application portability. Looking ahead, the platform is building the future of cloud-native applications with a focus on autonomous AI agents. A dedicated infrastructure stack supports hosting, governing, and securing agent fleets, integrating with Agent Development Kit and other frameworks. The Gemini Enterprise Agent Platform offers native personalization, observability, and simulation tools for scalable agent development. Cloud Run also provides a flexible alternative for hosting agents with upcoming features like persistent instances and secure sandboxes. Robust security and governance are provided through Agent Identity, Registry, and Gateway to manage and secure AI agents effectively.
CdXz5zHNQW_IhsB4Fbu06.png
Starting an AI-powered startup on Google Cloud is streamlined through tools like Google AI Studio and Gemini Enterprise Agent Platform. However, challenges can arise, such as leaked API keys leading to unexpected bills, IAM complexities hindering migration, and quota limits causing request errors. To mitigate these, startups need a strategic plan.The first phase, Onboard, focuses on establishing a solid foundation. It's crucial to decide between Google AI Studio for rapid prototyping and Gemini Enterprise Agent Platform for enterprise-grade controls, with a planned migration strategy. Setting up Google Cloud projects efficiently involves using templates, enabling necessary APIs upfront, and leveraging AI assistance for granting narrow IAM roles. For authentication, raw API keys are only suitable for local development; service accounts with least-privilege roles are best for production workloads. The migration from AI Studio's API key to Agent Platform's IAM model should occur when multiple users need API access, significant costs are incurred, or paying customers are onboarded.The Scale phase addresses increasing throughput without excessive costs. HTTP 429 errors often stem from hitting shared quota limits or global demand spikes; solutions include pinning to regional endpoints and implementing proper retry mechanisms with exponential backoff. Understanding consumption modes is vital: Standard PayGo is cost-effective but without guarantees, Priority PayGo offers faster access at a premium, and Provisioned Throughput guarantees capacity but requires prepayment.
CdXz5zHNQW_JPYYRiseWZ.png
For over a decade, Apache Hive Metastore (HMS) has been the central authority for big data analytics, managing schemas for query engines like Spark and Presto. However, as data architectures scale and span multiple query engines, legacy HMS deployments become significant operational bottlenecks. These legacy systems struggle with architectural scaling issues, as their reliance on relational databases creates performance issues. They also create siloed identity and security governance, requiring fragmented policies across different control planes. Furthermore, managing and tuning standalone HMS instances leads to considerable operational overhead and increased total cost of ownership.Google Cloud's serverless Lakehouse runtime catalog offers a solution, built on the open Apache Iceberg REST Catalog specification. This catalog is a unified, highly available metadata registry supporting both legacy Hive/Parquet and modern formats like Iceberg. It decouples metadata discovery from compute engines, allowing multiple engines to access data without copying. This enables multi-engine interoperability, open APIs, and zero-data-copy migrations by directly referencing existing data in cloud storage. AI-powered governance integrates with Cloud IAM for consistent security and trusted context, and credential vending further enhances security.The Lakehouse runtime catalog is enterprise-ready, scaling on Google's infrastructure and offering high availability for failover. Its serverless nature reduces operational toil and total cost of ownership. A zero-copy migration capability allows direct transition from legacy Hive Metastores to the Lakehouse catalog. Modernizing to the Lakehouse unifies governance, provides trusted context for agents, and slashes operational costs, preparing cloud environments for agent-scale operations.
CdXz5zHNQW_H3FQKMqnb7.png
Enterprise content management is undergoing a significant architectural transformation, moving beyond traditional text-based AI. Businesses store vast amounts of critical data in Box, including financial models and legal documents. While text-based search and RAG have been effective, the new agentic era requires multimodal capabilities. This evolution allows systems to process and understand not only text but also spatial and structural data. Google Cloud and Box are integrating advanced multimodal capabilities into Box’s Agentic Platform, powered by Gemini Multimodal Embeddings 2. This merge enhances Box’s platform with Google Cloud’s AI embeddings.Improved embeddings preserve visual and spatial geometry crucial for understanding complex documents like financial tables. They illuminate visual elements such as charts and flowcharts, making them searchable alongside text. This technology also connects hybrid file formats, unifying understanding across PDFs, spreadsheets, and presentations. Gemini Multimodal Embeddings 2 creates a unified vector space for text, images, and document pages. It enables crossmodal retrieval (text-to-visual and visual-to-text) without manual tagging. The system also supports layout-aware document embedding, preserving visual hierarchies, and bridges heterogeneous formats seamlessly.Three core patterns for multimodal enterprise agents emerge from this integration within Box. The first pattern addresses complex financial and analytical reporting by capturing the structural alignment of tables and charts. This allows agents to perform visual trend analysis and contextual sourcing. The second pattern focuses on multimodal clinical decision support, synthesizing various data formats like physical photos and pathology slides. It enables cross-modal clinical synthesis, granular anomaly identification, and risk-aware decision support. The third pattern tackles cross-document multimodal synthesis and data reconciliation for fragmented enterprise information. This leads to cross-file synthesis, conflict resolution, and visual-to-text auditing across disparate documents.The future of agentic enterprise content management relies on this integration to move beyond basic search to intelligent collaboration. Box's platform provides a governed, semantically indexed reasoning layer for AI agents, ensuring compliance and security. By proactively surfacing insights and flagging discrepancies, Box helps mitigate business risks. This multimodal understanding is critical for industries like financial services and life sciences. Box serves as a governed content foundation, ensuring AI-driven workflows use authorized and auditable data. The ability to make sense of the inherently multimodal enterprise data landscape marks a new era of productivity and innovation.
CdXz5zHNQW_Uu4pQ4xq4a.gif
CdXz5zHNQW_5vcpows2Qd.jpeg
The increasing risk of data theft and extortion due to AI-driven code analysis necessitates a structured approach to defense. The Agentic Vulnerability Discovery Harness (AVDH) enhances vulnerability discovery by combining AI models with human expertise in an orchestrated pipeline. This framework accelerates the identification and validation of vulnerabilities during proactive reviews, penetration tests, and incident response. AVDH has demonstrated real-world success, discovering over 100 critical vulnerabilities in two days during a recent incident response. It has analyzed millions of lines of code, generating tens of thousands of findings and leading to numerous CVE disclosures. The AVDH architecture utilizes harnesses, which mitigate AI unpredictability and improve code analysis effectiveness. It is built using Google's Agent Development Kit (ADK) and integrates with Google Antigravity for managing agentic workflows. The pipeline follows a structured, sequential approach, similar to waterfall development, beginning with threat modeling. An Explorer agent identifies the codebase's purpose, followed by Specialist Explorers delving into specific areas. A Threat Model Synthesis agent aggregates findings, which are then presented to a human consultant for verification. Entry point discovery agents, using Gemini Flash Lite, identify application entry points and associated user input sources. Enrichment agents aggregate relevant code for isolated entry points to enable deeper analysis. Hypothesis generation agents focus on control and data flow, with a confidence filter managing the volume of hypotheses. Validation agents, configured with high temperature settings, assess these hypotheses, and a Synthesis agent makes a final determination. Confirmed findings are then subjected to rigorous human expert review, including dynamic exploitation and proof-of-concept execution. Any findings not passing human validation are discarded.
CdXz5zHNQW_PijpR50ObO.png
CdXz5zHNQW_7jZ2QqAh3O.png
Enterprises face challenges when autonomous AI agents work with raw data tables, leading to inaccurate insights. Traditional data structures fail to capture real-world dependencies, hindering agents' ability to understand complex relationships. BigQuery Graph addresses this by enabling organizations to represent data as interconnected business entities. This new approach allows agents to reason across these relationships with greater precision.Relationships are crucial because blind reliance on flat tables prevents AI agents from understanding multi-hop business context. For example, an agent might report a sales drop but fail to identify the cause due to an inability to trace relational paths. This can lead to costly, irrelevant marketing campaigns and operational inefficiencies. Maintaining separate systems for relationships and metrics further exacerbates these issues, making runtime stitching slow and inconsistent.Measures in BigQuery Graph unify metrics with relationship mapping by allowing existing tables to be mapped to a property graph in-place, eliminating the need for ETL. This setup grounds metadata, calculates business performance, and uncovers the reasons behind performance changes. BigQuery Graph natively solves historical issues with SQL joins in graph traversals that caused incorrect aggregations. Data modelers now define measures within the Property Graph DDL.The engine resolves graph paths before evaluating metrics using standard SQL and the AGG aggregator, ensuring agents intelligently combine analytical tools. Tools like a visual graph modeler and conversational analytics integration within BigQuery Studio democratize graph intelligence. Conversational analytics enables natural language interaction, translating queries into precise graph-aware SQL. Native Looker integration ensures business metrics reside at the data layer, providing unified semantics and avoiding fragmented logic. This integration allows for database-managed or Looker-managed models, ensuring consistent KPIs through Git-based version control and CI/CD workflows.
CdXz5zHNQW_SFOIk3WOJP.gif
Organizations struggle with AI agents processing both structured and unstructured data, as LLMs handle text well but falter with databases, while NL2SQL models can generate inaccurate queries. Gemini Enterprise offers a unified AI interface, now enhanced by Looker's governed semantic layer for trusted structured data. This integration allows Looker analysts to publish conversational agents directly into Gemini Enterprise via a secure A2A protocol. This empowers employees with real-time, natural language access to governed business intelligence, reducing friction and fostering a data-driven culture.Looker's semantic layer eliminates guesswork in data queries, preventing inconsistent metrics and AI hallucinations by providing codified context. When a Gemini Enterprise user requests a business KPI, a Looker agent generates precise SQL based on version-controlled business logic, ensuring deterministic and predictable results. This integration prioritizes robust governance and secure access, employing a zero-risk pass-through architecture that doesn't ingest or store user data. Data access is controlled through OAuth authorization and Looker's existing row- and column-level access policies, maintaining strict security isolation. Technical capabilities include rich visual interactivity with native charts and interoperability with other agents, enabling complex multi-agent workflows. A robust, identity-centric authentication model ensures every query is authenticated at the user level, enforcing existing permission structures. This integration brings trusted data analytics, visualizations, and data storytelling directly into users' daily workspaces, bringing operational metrics to life.
CdXz5zHNQW_1fzLLwEtAe.gif
Migrating complex applications from commercial databases to PostgreSQL or managed services like AlloyDB often hits a bottleneck with proprietary stored procedures and functions. This manual translation process, typically involving PL/SQL or T-SQL, can be time-consuming and error-prone, delaying modernization projects. Recent advancements in AI, specifically Gemini integrated into Database Migration Service (DMS), offer a solution to this "last mile" challenge. DMS uses generative AI to automate the conversion of these legacy routines into PostgreSQL PL/pgSQL code, significantly speeding up the process and improving accuracy. Unlike generic AI tools, Gemini in DMS analyzes the entire database context for more reliable conversions. It operates within Google Cloud's secure environment, preserving proprietary business logic. The service provides an integrated workspace for reviewing, editing, and validating converted code side-by-side with explanations. This AI-assisted approach streamlines the migration by converting complex logic in days instead of months, allowing teams to focus on application development and performance. By pulling schema context automatically and validating syntax, DMS ensures a structured workflow for reliable code conversion. This enables database teams to maintain full control and validate changes before deploying to staging or production environments. Database Migration Service with Gemini empowers faster, more accurate, and secure database modernization.
CdXz5zHNQW_8iQntpUtu1.jpeg
Google is updating its Google Cloud roadmap to fully migrate to post-quantum cryptography by 2029. Their strategy focuses on three key areas: mitigating store now, decrypt later risks, ensuring integrity against forgery, and enhancing cryptographic agility. Google is already transitioning internal and customer-facing services to PQC algorithms. They are also deploying PQC solutions across their Sovereign Cloud initiatives and integrating them into AI services.The company aims for full PQC readiness by 2029, with efforts extending into the 2030s to align with evolving global standards. Key milestones for 2026 include quantum-safe API endpoints and load balancers, along with experimentation in quantum-safe certificates. Cloud Key Management Service (KMS) now supports NIST-standardized PQC algorithms for encryption and signing keys.The roadmap to 2029 is structured around customer-centered journeys, prioritizing areas most vulnerable to quantum computing impacts. Domain 1 targets store now, decrypt later mitigation by 2027, securing customer workloads, administrator flows, and data pipelines. Domain 2 focuses on integrity and non-repudiation, aiming for completion by 2028 by securing the software supply chain, issuing quantum-safe certificates, and protecting identity and access. Domain 3 addresses foundations and key management, targeting completion also by 2028 with standardized quantum-safe keys, hardware-backed services, and partner solutions. Google emphasizes a shared responsibility for quantum safety, managing the transition of cloud infrastructure while customers manage their own applications and data.
CdXz5zHNQW_9qzhoiPOVY.png
CdXz5zHNQW_EzDUKh4eBP.jpeg
Managing multi-tenant Kubernetes network security requires balancing developer needs for communication with security team demands for compliance. Standard Kubernetes NetworkPolicy, while useful for single namespaces, struggles with cluster-wide enforcement due to its namespace scope and developer-centric design. ClusterNetworkPolicy (CNP) was introduced as an open-source standard to address these limitations. CNP is a cluster-wide resource enabling centralized network security management for administrators. It features a hierarchical tier system: the admin tier for highest precedence global rules, the network policy tier for namespace-specific developer policies, and the baseline tier for default cluster behavior. This tiered structure aligns security with organizational roles, allowing for compliance mandates by security teams and default deny-all postures by platform teams. Developers can then manage their application-specific policies without overriding core security mandates. The deterministic evaluation resolves policy conflicts, with the admin tier capable of an explicit Pass action to delegate final decisions to namespace policies. Common use cases include isolating sensitive workloads, protecting core services, and managing external egress traffic. CNP simplifies complex security requirements into centralized rules, such as denying access to sensitive namespaces while permitting essential services. The ClusterNetworkPolicy API is an open-source standard, ensuring portability across environments. GKE's implementation of CNP provides native tier selection for clear and deterministic policy evaluation. This elevates workload network security to unified, cluster-wide governance.
CdXz5zHNQW_bAPXfDa5Dc.jpeg
Google Cloud empowers organizations to build and deploy agentic workflows with confidence. Their integrated AI platform combines research with flexibility to deliver business value. Gemini Enterprise is central to this, unifying tools for the agentic enterprise and offering built-in enterprise trust. This approach led to Google being named a Leader in The Forrester Wave AI Platforms report, with the highest score in Strategy. Gemini Enterprise acts as a unified entry point to AI, breaking down silos and connecting business users, developers, and IT leaders with shared context. The Gemini Enterprise Agent Platform enables safe, secure, and cost-effective agent development and deployment across the workforce via the Gemini Enterprise app. By integrating data, models, developer tools, and IT operations, Gemini Enterprise empowers transformation while maintaining control. The platform caters to diverse builder needs, supporting high-code, low-code, and no-code environments with access to numerous models and templates. Gemini Enterprise is inherently multi-modal, processing and generating various data types to create contextual business experiences. Trust is paramount, so the Agent Platform includes default enterprise-grade governance, security, and observability. Built-in guardrails, continuous evaluation, and real-time tracking ensure safe scaling of agentic workflows. Features like Knowledge Catalog improve agent accuracy by establishing a universal context engine. Google believes Gemini Enterprise provides the necessary foundation for developers to build agentic systems with confidence.
CdXz5zHNQW_iqAMPwLR9H.png
WPP is transforming its marketing and communications services by leveraging AI to provide predictive certainty for clients in a volatile market. Traditionally, agencies relied on intuition, but WPP is now using an AI-powered system called WPP Open to analyze market dynamics. A significant engineering challenge arose from WPP's fragmented global marketing data, making AI deployment difficult and insecure. To address this, WPP partnered with Google Cloud to create a unified data backbone and a custom platform engineering path. This collaboration standardized serverless compute patterns and data processing, enabling faster, more secure marketing campaigns.The project involved architecting a centralized, service-based data foundation, consolidating data into secure, shared Google Cloud Storage and BigQuery projects. Granular identity and access management controls ensure data security, while Managed Service for Apache Spark cleans and normalizes raw data. This serverless architecture, combined with Kubeflow, allowed WPP to focus on data transformation logic without managing infrastructure overhead. The platform then converts raw data into standardized cohort definitions (SCDs) based on key metrics like age, gender, geo, product, and interest.These SCDs enable global data aggregation without exposing sensitive information, with a type-safe Scala framework ensuring data traceability and compliance for AI applications. WPP also standardized its enterprise software lifecycle using reusable GitLab CI/CD templates for secure and efficient deployments. They adopted a "build once, deploy many" methodology, promoting exact, validated container images directly to production for consistency. Integrated security scanning and intelligent networking tools automate vulnerability detection and resolve network conflicts, further accelerating releases.Monitoring operational health through granular metrics like latency and error rates ensures platform resilience and high availability. This comprehensive approach has enabled WPP to significantly reduce creative and strategy time, boost production efficiency, increase content volume, and improve campaign return on investment. By building a robust data and AI foundation with Google Cloud, WPP has achieved substantial business impact and accelerated its transition to an AI-driven future.
CdXz5zHNQW_bQfJCUmGLT.jpeg
CdXz5zHNQW_zzLyeeAAsM.png
In the digital economy, efficient data management is crucial, but many companies struggle with complex, in-house ETL pipelines or unreliable third-party tools. BigQuery Data Transfer Service (DTS) offers a fully managed, zero-code solution that automates data ingestion into BigQuery, freeing teams from pipeline maintenance. The service is expanding its integrations to address data silos across various platforms. New capabilities include direct ingestion into Apache Iceberg tables from cloud storage, enabling multi-cloud compatibility with BigQuery's performance.A next-generation agentic architecture allows AI applications to programmatically discover and manage data transfers. DTS now supports enterprise databases like Microsoft SQL Server, PostgreSQL, and MySQL for both full and incremental transfers, consolidating data into BigQuery. E-commerce and marketing platforms such as Shopify, Klaviyo, HubSpot, and Mailchimp are also integrated to automate the extraction of granular data.Migration connectors, including Snowflake, offer features for seamless data movement. Major connectors like ServiceNow, Salesforce, and Oracle have been enhanced with native incremental updates. BigQuery DTS provides cost efficiency with free ingestion for many Google and other major sources, and low consumption-based rates for third-party SaaS.Security is frictionless, with automatic inheritance of BigQuery's security features like Column-Level Security and Customer-Managed Encryption Keys without extra configuration. The service boasts industry-leading performance and resilience with a >=99.99% monthly uptime SLA, ensuring reliable data updates. Companies can transform their data operations by using BigQuery DTS to build a scalable data stack, with new connectors continuously being developed based on user needs.
CdXz5zHNQW_EirBGeM6Z0.png
Google Cloud is committed to data and business system security through its infrastructure, tools, and governance. They employ a shared fate model, proactively identifying and mitigating threats before they impact customers. Hyperscale cloud platforms are attractive targets for malicious actors seeking disruption or financial gain. Google Cloud security teams actively monitor for AI workload exploitation, cryptocurrency mining, and credential exfiltration. They also defend against account takeovers using techniques like phishing and session cookie theft.To mitigate these risks, Google Cloud implements granular containment and throttling measures for anomalous traffic. They use collaborative triage for complex AI workloads and localized identity isolation to prevent lateral movement. As a last resort, targeted project suspensions are enacted if platform integrity is severely threatened. Google also partners with repository hosts to catch exposed credentials early.Transparency is crucial, with Cloud Abuse Event Logging providing visibility into security notifications. Proactive support cases and abuse notifications are generated upon detection of critical abuse. Cloud Audit Logging and anomaly spending alerts help identify unauthorized activity, while essential contacts ensure timely communication. Customers are responsible for hardening their environments through actions like enforcing multi-factor authentication and securing service accounts.Implementing least privilege, perimeter defense, and regular resource hygiene are also recommended. Google continuously monitors platform health to detect anomalous usage patterns. Maintaining a secure environment is a partnership requiring dedication from both Google Cloud and its customers. By adopting robust access controls and security best practices, together they can ensure workload security and resilience.
Enterprises face challenges managing unstructured data like PDFs, audio, and images. BigQuery now offers a simplified five-step framework to unlock insights from this data: Access, Process, Ground, Relate, and Activate. This post focuses on three key milestones that enhance the "Ground" phase. Autonomous Embedding Generation is now Generally Available, automatically creating data embeddings as new information is ingested without complex pipelines. This feature supports both external and native Gemma embedding models and now includes multimodal image embedding capabilities. BigQuery eliminates the need for separate vector databases by managing enterprise-scale processing and keeping data synchronized automatically. General Availability of AI.SEARCH improves natural language search performance with significant single-query gains. This function allows users to easily find semantically related records without needing embeddings in their search path. Performance optimizations have led to substantial speed improvements, enabling faster and more cost-effective user-facing searches. Public Preview of Hybrid Search unifies keyword and vector search capabilities. This approach combines the conceptual understanding of semantic search with the pinpoint accuracy of lexical matching. Hybrid search improves precision and reduces LLM hallucinations by reranking results based on both semantic relevance and keyword frequency. These advancements are part of BigQuery's broader vision to create an end-to-end unstructured data analytics platform.
CdXz5zHNQW_jYrUlOLOjk.gif
Modern data platforms face challenges with query performance tuning and system price-performance, especially with increasing agentic workloads. Manual query optimization is becoming impractical as data volume, variety, and velocity grow, and queries are generated automatically by agents. BigQuery has evolved into a primary engine for the Agentic AI era, focusing on autonomous query processing. Its disaggregated storage and compute architecture, serverless processing, and fine-grained compute management contribute to optimal price-performance. Key innovations include a Self-Learning Engine with History-Based Optimizations (HBO) that learns from past query executions to apply beneficial optimizations automatically without user intervention. This system includes safety guardrails to prevent regressions, rejecting optimizations that don't improve performance. The advanced runtime enhances vectorization and implements short query optimizations, accelerating eligible queries and reducing slot usage. These improvements apply consistently across different data formats, including open lakehouse architectures. Fluid scaling enhances autoscaling, enabling per-second billing for compute resources and reducing costs. These autonomous capabilities are crucial for the future of data platforms as AI agents require significantly higher query latency and concurrency than human users. BigQuery's goal is to automatically and safely optimize queries, allowing users to focus on delivering better experiences rather than manual infrastructure management and query optimization.
CdXz5zHNQW_RZymwO4c5H.png
The intersection of medicine and artificial intelligence has led to numerous innovations, but developers are now facing the challenge of building robust medical AI tools that have been tested and evaluated on diverse, real-world patient data while protecting patient privacy. To address this issue, Google Cloud is collaborating with MLCommons through the MedPerf initiative, which uses Confidential Computing to establish a secure environment for benchmarking AI models. The MedPerf initiative, launched by MLCommons in 2023, aims to standardize the evaluation of medical AI by using federated evaluation to test models. By utilizing Google Cloud Confidential Space, proprietary AI models can be evaluated inside hardware-isolated Trusted Execution Environments, ensuring that none of the parties involved can see model code or patient data. The Confidential VM extends beyond the CPU to the GPU, protecting model weights and patient data during GPU-accelerated inference. The MedPerf platform is already driving critical research, such as the Federated Tumor Segmentation initiative, which is working to improve brain tumor research by validating AI models on private brain MRI data from around the world. This collaborative approach demonstrates that AI tools can be proven to work across a truly representative patient population, achieving clinical trust and validation. The impact of this collaboration is significant, with researchers and clinicians praising the secure, scalable, and collaborative cloud environment provided by Google Cloud. The future of medical AI holds enormous promise, but it can only be realized if clinicians, researchers, and regulators can trust the benchmarks used to evaluate it. By making it easier to securely share and evaluate data and models, the collaboration between MLCommons and Google Cloud is clearing the path for faster, safer, and more equitable medical breakthroughs.
CdXz5zHNQW_XwzheZFbR2.png
CdXz5zHNQW_oek9BOyxep.png
UiPath is transitioning to agentic AI, deploying autonomous agents that reason and make decisions to orchestrate complex business processes. This shift requires significant computational power and reliable infrastructure, especially for large enterprises. Orchestrating hundreds of GPUs efficiently is crucial for global AI platforms, balancing training and inference without increasing costs or latency. UiPath re-architected its infrastructure on Google Cloud, moving to a shared GPU fleet for intelligent document processing. They now use A3 VM instances for training and G4 VM instances for inference, addressing spiky workloads and ensuring predictable costs. This partnership with Google Cloud provides the necessary scale, flexibility, and specialized AI capabilities for UiPath's ambitious agentic AI initiatives. The company's previous approach of provisioning GPUs on demand became unmanageable due to spiky workloads, supply bottlenecks for high-end chips, and operational overhead. By treating GPUs as a shared strategic resource, UiPath's ML Services platform prioritizes work and balances demand across workflows, optimizing utilization. Google Cloud's AI Hypercomputer architecture, integrating hardware, software, and flexible consumption models, further supports UiPath's growing scale. UiPath leveraged Google Kubernetes Engine and Google Cloud's Dynamic Workload Scheduler (DWS) to secure GPU capacity in advance, enabling proactive planning. They now use A3 VM instances for training and cost-effective G4 VM instances for inference, optimizing performance and price. This new infrastructure allows UiPath to bring advanced models into production, such as those used by Omega Healthcare and Thermo Fisher Scientific, achieving remarkable accuracy and processing efficiencies. Key lessons learned include decoupling capacity, scheduling compute in advance, and right-sizing silicon for different workloads.
CdXz5zHNQW_xB4j7Tpaox.jpeg
Shared infrastructure environments, like those used by SaaS providers and enterprises, are vulnerable to the "noisy neighbor" problem. A single tenant's intense data activity or a failing database can degrade performance for all users, leading to backlogs and SLA violations. Legacy monolithic architectures, where all data flows through a single stream, exacerbate this issue. This means one database failure can halt all processing, requiring inefficient scaling for worst-case scenarios. Maintaining stable SLAs becomes nearly impossible when one tenant's high volume impacts the entire system.The solution is a sharded hub-and-spoke architecture, which decouples processing into a central hub for routing and isolated spokes for execution. The hub, a lightweight Dataflow job, acts as a traffic controller, parsing tenant IDs and fanning data into isolated buffers. These buffers, implemented as durable Pub/Sub topics, prevent slow downstream sinks from impacting the original source. The spokes consist of multiple smaller Dataflow instances, categorized by workload like high-priority, shared tiers, or domain-specific pipelines. This isolation significantly reduces the blast radius of failures from 100% to under 5%. It also allows for independent scaling based on tenant load, unlike the inefficient worst-case scaling of monolithic systems. Maintenance becomes safer, as updates to one domain do not necessarily affect others. Additional optimizations like Dead Letter Queues, strict connection pooling, and asynchronous I/O further enhance stability and prevent pipeline stalls. By adopting this sharded approach, platforms can eliminate the noisy neighbor threat, ensuring strict SLAs and enabling safer deployments.
CdXz5zHNQW_wDjs5eoArR.png
Google Cloud's Filestore, a scalable NFS file service, has received a significant enhancement by integrating a cloud-native backend storage layer built on Colossus. This upgrade allows Filestore to leverage the same foundational distributed storage system that powers Google's largest global services. The integration enables greater flexibility and scalability for demanding modern workloads, including AI and agentic workflows. A key benefit is the decoupling of storage capacity and performance, allowing independent provisioning of IOPS to match workload demands precisely. This decoupled scaling is particularly advantageous for containerized environments, providing persistent, high-performance storage for GKE workloads via the Filestore CSI driver. Filestore multishares for GKE further optimize resource utilization by segmenting instances into smaller shares for project-specific needs. This new architecture unlocks critical use cases like high-concurrency workspaces for AI agent swarms, where shared data access is essential. Filestore's NFS protocol, backed by Colossus, supports millions of agents with consistent file system access and strict data consistency through NFS file locking. Operationally, the enhancement offers improved agility with real-time IOPS scaling and faster failure recovery. Security is also bolstered through deep integration with Google Cloud IAM and IP Access Control Lists. This update positions Filestore to meet the evolving needs of AI-era data workflows, offering flexibility and cost-efficiency.
CdXz5zHNQW_dhhtMvrokU.jpeg
Google Cloud has launched two AI-powered database agents to simplify database management. The Database Onboarding Agent assists with initial setup, configuration, and deployment by recommending suitable database services based on user requirements, described in natural language. For ongoing operations, the Database Observability Agent monitors, troubleshoots, and maintains databases. These agents are integrated across various Google Cloud surfaces and third-party tools like IDEs, providing assistance where and when needed. Traditionally, database management has been a complex, manual, and skill-intensive process involving significant troubleshooting time. The new agents automate tasks like query optimization and anomaly detection, reducing operational overhead and improving efficiency. The Observability Agent helps resolve complex issues by analyzing data from multiple sources, providing root cause analysis, and suggesting or executing validated remediations. It offers fleet-level troubleshooting and in-product investigations, correlating telemetry from services like Cloud Monitoring and Cloud Logging. Integration within existing workflows is seamless, with capabilities accessible via Cloud Assist chat, in-console investigations, and developer tools. The agents support a broad range of Google Cloud databases, including Cloud SQL, Spanner, AlloyDB, and Bigtable, addressing various performance and operational challenges. The Onboarding Agent analyzes workload needs to recommend specific managed database services, streamlining the selection and provisioning process.
CdXz5zHNQW_EaJdqPA9kl.gif
Google's Chrome Enterprise is evolving its security features to support the rise of autonomous AI agents. These agents are increasingly performing complex tasks within the browser, necessitating robust data protection for both users and the AI itself. The browser offers a unique advantage by holding user context, existing access policies, and awareness of active applications. This allows agents to operate securely while leveraging existing enterprise permissions.Chrome Enterprise Premium introduces advanced Data Loss Prevention (DLP) to inspect agentic data flows in real-time. This prevents sensitive information from being leaked to public large language models and allows for management of extension permissions. Access controls are extended from users to their AI agents, so if a user cannot access certain data, their agents cannot either.To ensure secure agentic collaboration, Chrome is implementing several safeguards. A User Alignment Critic acts as a gatekeeper, analyzing metadata to prevent prompt injection attacks. Site Isolation is enhanced to limit agent activity to relevant task origins, preventing unauthorized actions on unrelated sites. Agents log their actions, and Chrome automatically pauses at critical junctures for human approval, maintaining the employee in the loop. For example, major financial transactions or mass emails require explicit human consent. Agent actions are clearly tagged in Chrome History for transparency.Google is actively testing these defenses through automated red-teaming and has expanded its Vulnerability Rewards Program. By extending browser isolation principles and providing visibility controls, Chrome Enterprise aims to enable businesses to adopt AI productivity tools without compromising security. This approach ensures enterprises can innovate safely in the evolving landscape of AI-assisted work.
Enterprises face a difficult choice between maintaining legacy mainframes or undertaking risky big-bang migrations. Google Cloud offers an alternative iterative modernization strategy powered by AI and the cloud. This approach acknowledges that mainframe modernization involves more than just code conversion, encompassing complex dependencies, data formats, transaction monitors, workflows, and proprietary interfaces. Google Cloud's solution combines its Gemini models with specialized mainframe modernization products across four pillars: assessment, modernization, de-risking, and data migration.The Mainframe Assessment Tool (MAT) uses AI for reverse-engineering legacy applications, providing insights into dependencies, business rules, documentation, and domain discovery. Modernization offers flexible paths, including rewriting applications for innovation or performing deterministic, like-to-like modernization to preserve behavior. Google Cloud's Dual Run process ensures safety by running workloads simultaneously on both mainframe and cloud environments, comparing outputs to validate equivalence. The Mainframe Connector facilitates data migration to various Google Cloud services, enabling offloading of processing and unlocking siloed data. This comprehensive approach addresses real-world mainframe modernization challenges by understanding existing processes, modernizing applications, de-risking before go-live, and modernizing data. Google Cloud invites enterprises to test this AI-accelerated approach through pilot programs starting with automated codebase assessment.
CdXz5zHNQW_Bxqmdjy8fD.png
Businesses need to deploy AI agents quickly and safely to boost revenue and reduce risk, all while protecting core ERP systems. This requires more than raw data; it demands interoperable data products that serve as a single source of truth, translating complex records into understandable business terms. Google Cloud's Cortex Framework version 7 addresses this by modernizing data architecture for AI agent readiness. This release simplifies deploying, customizing, and extending data products, reducing infrastructure overhead.Cortex Framework v7 includes purpose-built data product accelerators for SAP, deploying directly in BigQuery and Knowledge Catalog. These feed the Gemini Enterprise Agent Platform with accurate business context, enabling AI agents to execute with high fidelity. Dataform powers the framework's modular and scalable deployment architecture, simplifying orchestration and enabling data teams to build and version control workflows.The new release delivers agent-ready data products that contain AI-friendly metadata, allowing agents to reason and execute workflows. It translates raw SAP data into clear business terms and handles complex logic like currency decimal shifts, ensuring high data fidelity for AI. Accelerating custom AI projects, v7 includes agent skills for an AI-driven data product builder that uses natural language. The framework can also be extended to maintain separation between framework content and custom models, allowing for clean updates.Modular deployments, powered by Dataform, ensure version-controlled SQL and native dependency management, processing only required tables. This modular approach handles complex SAP environments, deploying products for various SAP systems in parallel and ingesting custom fields automatically. Cost-effective scaling is achieved through BigQuery incremental loading and non-destructive schema updates, minimizing compute time and operational expenses. Orchestration relies on Dataform's serverless execution for scalable data processing without additional infrastructure.Cortex Framework v7 now natively supports SAP’s Business Data Cloud, combining its data products with SAP BDC data products to uncover new business opportunities. Solution samples are included for both SAP BDC and SAP ERP data to address critical business questions. Co-innovation with industry leaders has shaped v7, prioritizing enterprise agility and AI readiness. This release transforms complex enterprise data into a strategic asset through serverless execution, AI-ready semantics, and native SAP integration.
CdXz5zHNQW_2lk7aE3kwy.png
The Data Commons project aims to organize the world's information and make it universally accessible and useful by unifying fragmented public datasets from over 100 authoritative providers. Data Commons provides a knowledge graph that connects real-world things and their relationships, with over 400 billion data points structured using standardized Schema.org definitions. The platform offers data exploration tools, MCP tools, and cloud-based APIs to access and integrate the clean datasets, making it easier for businesses to connect their internal data with public reference data. Data Commons integrates public information across multiple domains, including agriculture, demographics, economy, environment, and health, unlocking powerful use cases such as analyzing national GDP trends and tracking local health equity. The platform has transitioned to a native graph model with Spanner Graph, which brings the convenience of a SQL-like interface and graph expressiveness to Spanner, with its high availability, horizontal scale-out, and native ISO/IEC 39075 Graph Query Language support. By adopting a multi-entity Spanner Graph schema, Data Commons represents entities as nodes and their domain links as dynamic graph edges, allowing for complex relationship queries directly within the database using GQL. The new architecture simplifies pipelines by removing the need for complex, pre-computed indices and enables incremental updates to specific datasets without refreshing the entire database. Data Commons also adopts a lean implementation of the Statistical Data and Metadata eXchange technical standard, providing a consistent approach for describing and exchanging statistical data along with descriptive statistical meta-information. The Data Commons Platform update adds support for the SDMX technical standard version 3.0, providing out-of-the-box integration with third-party tools for multi-dimensional datasets. By federating across the public knowledge graph and a private knowledge graph containing their own data, users can light up exciting new use cases while maintaining data isolation and ensuring no data duplication.
CdXz5zHNQW_8FZTNms1zk.png
AI agents' effectiveness depends heavily on the quality of instructions and context provided. Google Agent Skills aims to enhance AI coding agent capabilities by encoding Google Cloud domain knowledge into structured, open-source instructions. This initiative, launched as a rapid "swarm" effort for Google Cloud Next 2026, aims to make AI agents smarter, safer, and more accurate. A cross-functional team developed standardized, agent-readable instructions for Google Cloud knowledge. The project quickly gained traction, with over 15,000 GitHub stars indicating strong community interest.The growing popularity presented a significant challenge in maintaining quality control across diverse team contributions. To address this, strict standards and automated governance were established to prevent a chaotic repository. Each skill adheres to a standardized layout, prioritizing remote MCP tools for better architecture. Skills are rigorously built and evaluated internally before being publicly exported, stripping sensitive internal data and ensuring cleanliness.Automated checks, including linters, link checkers, and AI-assisted validations, are performed before any skill is merged into the repository. Continuous evaluations, both on-submit and weekly, are crucial to catch regressions caused by evolving documentation, APIs, or LLM models. These evaluations measure accuracy and efficiency, ensuring skills provide a measurable uplift. The project emphasizes that skills are treated as living products requiring ongoing maintenance, with defined ownership for repository health and individual skill upkeep.To support authors, tools and agentic workflows have been developed to assist in creating effective instructions and evaluation suites. A parallel internal initiative, DevRel Skills, focuses on building agent skills for internal team workflows to improve efficiency and consistency. Google Agent Skills offers public skills on GitHub and related introductory materials for developers.
CdXz5zHNQW_snlohUPtMF.png
Google is making comprehensive advancements in AI infrastructure to support the agentic era. They develop leading AI models like Gemini and design software frameworks and hardware. Google also integrates AI into everyday tools and builds the underlying infrastructure, including compute, accelerators, and orchestration software. This robust infrastructure is crucial for companies aiming to innovate faster and deliver better user experiences. Google provides monthly updates on its AI infrastructure news, including product, technology, and tool updates. Recent updates highlight Google Cloud Managed Lustre, C4N network-optimized VMs, and GKE Dataplane V2 scaling. New features include co-operative time-slicing for RL workloads and the open-sourced k8s-aibom security tool. Practitioner guides offer detailed instructions on deploying models like Kimi K3 and running various AI workloads on TPUs. Technical blueprints showcase performance optimizations for large models on Google's TPUs. Google has been recognized as a leader in AI infrastructure by Gartner. Reports indicate a widening gap between AI ambitions and infrastructure reality, with most organizations needing upgrades. Confidential Computing is now available on accelerator-optimized G4 machine series for secure AI data handling. The TPU Developer Hub and TPU AI Telemetry Collector Agent offer new resources for developers. Building high availability into AI inference workloads on GKE and connecting AI agents to data in Cloud Storage are detailed in new guides. Independent benchmarks show GKE Inference Gateway outperforming leading managed Kubernetes services. Customer wins demonstrate the successful application of Google's AI infrastructure in healthcare and customer review platforms.
Modern cloud applications are becoming autonomous digital workers capable of reasoning and taking action. Initially, deploying agents on virtual machines with frameworks like OpenClaw is a simple approach. However, as these workloads scale, the bursty nature of AI agents leads to inefficient resource consumption with idle agents still using CPU and memory. The challenge is to pack more agents onto fixed compute without sacrificing reliability or efficiency. Orchestration, when incorporated into the architecture, significantly improves economics, scalability, and reliability. Google Kubernetes Engine (GKE) offers sophisticated orchestration capabilities to maximize compute capacity. A baseline test running OpenClaw agents on microVMs hit a scaling limit of 61 agents due to the overhead of guest operating systems. Migrating to GKE Agent Sandbox, which uses the lightweight gVisor for isolation, increased agent density by 44% to 88 agents on the same node. This optimization also reduced the cost per agent by over 30%. Further enhancing density involves using GKE Pod snapshots with suspend and resume features to checkpoint idle agents, freeing up resources. This allows for oversubscription of compute capacity, but requires tailoring strategies for different agent latency requirements. GKE enables simultaneous support for latency-sensitive, balanced, and latency-tolerant agent workloads. By combining GKE Agent Sandbox with suspend and resume, agent density can be increased up to 3.5 times and costs reduced by up to 75% for intermittently active agents. Ultimately, scaling agents efficiently in the agentic era is achievable by leveraging platform features and integrating orchestration from the outset.
CdXz5zHNQW_BPn0h5T532.png