I/O 2026 was the second half of a sentence Google began at Cloud Next — and the real news sat in two quiet decisions: where the agent runs, and who pays for it.

Google held I/O 2026 on May 19–20 at the Shoreline Amphitheater. The keynote was, once again, almost entirely about AI. The big releases will fill every recap: Gemini 3.5 Flash, the Gemini Omni model family and its first model, Omni Flash, and an upgraded Antigravity platform. But a list of releases is not the story. It is structural, and it only comes into focus when you read I/O against something that happened six weeks earlier.
At Google Cloud Next in April, Thomas Kurian emphasized “The Agentic Cloud” in his keynote. The substance was infrastructure: the Agent2Agent protocol for cross-platform agent communication, managed MCP servers wired into Google Cloud services, and a no-code agent builder for Workspace. Google had also renamed Vertex AI to the Gemini Enterprise Agent Platform at that event. That was not cosmetic. Model training, the registry, and endpoints were demoted to sub-features beneath an agent-first hierarchy. The platform’s organizing unit had been inverted publicly six weeks before I/O. That was the enterprise half of the argument, which we covered here. It is the baseline against which I/O 2026 should be read.
I/O 2026 delivered the consumer half. And the most revealing news was not a model or a benchmark. It was two quieter decisions — one about where the agent runs, one about what it costs.
The Tell — The agent left your device
Gemini Spark is Google’s new personal AI agent, the headliner of the entire event. What matters about Spark is not what it does. Navigating your digital life, taking actions on your behalf — that part is expected. The notable thing is a sentence Google buried in the specification: Spark runs on dedicated virtual machines in Google Cloud, not on your phone or laptop. It operates around the clock. You can close every screen you own, and the work continues.
This pattern repeats across every agentic announcement at I/O. Daily Brief assembles your morning — urgent mail, the next meeting, the follow-up you forgot — from Gmail, Calendar, and Tasks before you open the app. Information Agents sit inside Search and keep working on a question after you have asked it, scanning the web and returning a synthesized update while you are asleep. Universal Cart keeps a single shopping session alive as you move between Search, Gemini, YouTube, and Gmail, tracking price drops and restocks in the background.
For roughly three years, the agent was something a person invoked. You opened a window, typed a prompt, read the answer, and closed the window. The interaction had a beginning and an end, and you were present for both. That is over. What Google shipped at I/O 2026 is an agent that is not invoked at all — a process that runs whether or not you are watching.
The unit of AI is shifting from the prompt to the standing task. That is the entire story of I/O 2026.
This is why the “everything Google announced” lists undersell the event. A list treats Spark, Daily Brief, Information Agents, and Universal Cart as four features. They are not four features. They are four expressions of one architectural commitment — the agent is now a resident process in Google’s cloud, attached to your accounts, working on a schedule rather than on a request.
The Unpriced Unit — A bill CloudDon already flagged
A standing process is not only an architectural choice. It is a cost structure — and this is where I/O 2026 connects directly to the ground CloudDon has already covered.
Six weeks before I/O, we graded Google Cloud’s developments since 2025. While most verdicts were favorable, one was not. On pricing transparency, the finding was blunt — not delivered. Google had priced every component: Agent Runtime per vCPU-hour, Memory Bank per thousand memories, model tokens per unit. What it had not shipped was a composite unit. You could price every brick and still not price the building. Nobody could say cleanly what a single autonomous agent costs to run for three days. Spend Caps shipped as a workaround — and a workaround is a tell.
I/O 2026 did not just answer that question. It scaled it.
Gemini Spark is a standing process on dedicated cloud machines, running around the clock. The enterprise buyer at Cloud Next could not price a three-day agent run. The consumer cannot either — and Google is about to manufacture a great many more consumers of exactly that uncertainty. The unpriced unit did not stay an enterprise procurement headache. It became a mass-market product.
And the tell migrated with it. Buried in the I/O app announcements, beneath the redesign and the new models, sat a single line: the Gemini app is moving from daily prompt limits to a “compute-used” model. Usage now factors in prompt complexity, the features invoked, and the session length. That is not a feature. It is the consumer-facing translation of Spend Caps. Google is conceding, in pricing-page language, that a standing agent has no predictable cost — so the meter moves to the user. Subscribers caught it immediately: the change drew criticism across Reddit and social media as less transparent and harder to predict than the model it replaced, sharpened by Google's quiet drop of the monthly AI credits the old plans had included.
A summoned tool has a bounded cost. A standing task has an open-ended one — it runs while you sleep, and the bill accrues with it.
This is the real weight of the shift from the prompt to the standing task. Every pricing model the industry built for a request economy assumes a unit with edges — one request, one response, one charge you can see coming. The standing task removes the edges. CloudDon flagged the missing composite unit as a Google gap. I/O reframes it as an industry one. Neither Google, OpenAI, nor Anthropic can yet quote a clean “agent-day” price. Whoever solves that first — whoever can tell a buyer what one agent costs to run for one day before they turn it loose — will hold an advantage as durable as any benchmark. Pricing legibility is about to become a competitive surface.
The Board — Three companies, three different bets
If the agent is becoming a standing process rather than a summoned tool, the competitive question changes shape. It is no longer “whose model scores highest.” It is “whose agent can be trusted to run unattended, on surfaces people already use, at a cost a buyer can see coming.” Three companies answer that question in directly comparable terms — Google, the subject here, and OpenAI and Anthropic, the rivals I/O most squarely reframes. Each is betting its core position on the model-and-agent itself, and each has bet differently. Microsoft and Amazon are also building frontier models and agent platforms, but on a more enterprise-infrastructure footing; the fuller five-way comparison belongs in the forthcoming report available behind paywall.
- Google is betting on distribution. Its agents do not need to be discovered, downloaded, or adopted. They arrive inside Search, Gmail, YouTube, and Android — surfaces a billion-plus people already open every day — through an update to an app the user already has. No competitor can match that. The bet is fed from underneath: proprietary TPU capacity and a model stack Google owns end to end, the same vertically integrated system it displayed at Cloud Next. Kurian framed rivals as “handing you the pieces, not the platform.” At I/O, that stopped being a slogan and became a demonstration. The wager, stated plainly: ubiquity beats benchmarks. You do not have to build the best agent if yours is the one already running on everyone’s phone.
- OpenAI is betting on the workflow. Its route runs through Codex, which began as a coding agent and is now, deliberately, becoming something larger. More than four million developers use it weekly; Gartner named it a Leader in enterprise coding agents; and OpenAI has been expanding it beyond code to general business work, connecting Slack, Drive, calendar, and email so the agent coordinates tasks rather than just commits. The recent Dell partnership pushes Codex into on-premises environments, next to the corporate data that never leaves the building. The logic is a land grab from the inside: win the developer, then the developer’s team, then the workflows around them, and the enterprise contract follows the tool already embedded. The wager: own the agent that does the work, and distribution compounds from there.
- Anthropic is betting on trust. Its position is the most enterprise-weighted of the three, and it is built on a single proposition: an agent is only worth deploying if it can be left alone with real consequences. Safety, predictability, the discipline of failing gracefully — Anthropic treats these not as compliance overhead but as the product itself, the reason a regulated enterprise signs. The wager is that trust is the moat: capability is being commoditized across all three labs, but the right to run unattended is not. There is a tension worth naming. Anthropic has itself conceded that demand has strained its infrastructure, denting reliability at peak hours. The company selling reliability as the moat has not fully secured it.
Among the three bets — distribution, workflow, and trust, Google holds the strongest hand, and it is not close: nobody else can deploy to a billion users overnight. But a hand is not a win. Each bet still has to clear the same two bars — an agent a buyer can trust unattended, at a cost they can see coming. On neither bar has any of the three closed the question.
The Exposure — The risk is the same as the advantage
Here is the problem the reliability bet is built on: trust is asymmetric. An agent that runs continuously, with standing access to your inbox, your calendar, and your payment methods, is only ever as valuable as it is trusted. A summoned tool that fails is an annoyance — you witnessed it, you can correct it. A standing agent fails differently. It fails while you are not looking, on accounts that matter, and you find out after the fact.
Google has comprehensively won the distribution question. It has not yet answered the reliability question, and a standing-task architecture makes that question load-bearing rather than academic. The contest of late 2026 will not be decided on multimodal benchmarks. It will be decided by whose autonomous agent earns the right to be left alone.
Google appears to understand this. It called Spark “very early in its product journey,” prioritized safety in the first release, held the rollout for trusted testers, and built in a confirmation step before consequential actions — sending mail or completing a purchase. That is a company hedging against its own ambition. The hedge is warranted. The anxiety is not hypothetical: before the keynote, a leaked Spark onboarding screen — Google’s own warning that the agent “may do things like share your info or make purchases without asking” — spread widely enough that Google visibly softened the language for the stage. This skepticism is not new, either. In late 2025, Google faced public backlash when a buried Gmail setting enabled Gemini to read inboxes and calendars by default. A standing agent with inbox access walks straight into that unhealed wound.
It is also Google’s sharpest structural advantage, stated plainly: in the race to build a personal agent, the company that already holds all your email starts several laps ahead. Distribution and exposure are the same asset viewed from two angles.
Gemini Spark’s beta opens to U.S. AI Ultra subscribers within the week. That is the first real-world test — not of whether the agent is capable, but of whether a person who has watched it work for a month stops feeling the need to check.
The agentic era truly begins only when one of these systems runs unattended, and the user does not think twice. I/O 2026 was Google making that the explicit goal. Whether the trust follows the capability and whether the cost ever becomes legible are the questions worth tracking from here.