Google Cloud Next 2026 — The Move-In Is Complete. Who Holds the Keys?
Google Cloud Next ’26 and the three-year verdict on the agentic enterprise.
Google Cloud Next 2026 — The Move-In Is Complete. Who Holds the Keys?
Google Cloud Next ’26 and the three-year verdict on the agentic enterprise.
Disclaimer: Google Cloud provided me with a conference pass and support for travel and accommodation. Google Cloud is also a client.

Googele Cloud’s AI Stack. Source: Google Cloud Next 2026 Analyst Summit.
In 2024, I called Google Cloud’s AI story a home that had been listed for sale with the interiors incomplete. The structure was sound. The rooms were not livable.
In 2025, I stated that the interiors were complete, but Google Cloud was not ‘move-in’ ready. ADK had launched. A2A was announced with fifty partners. Vertex AI Agent Engine and Agentspace were available. Ironwood TPUs were unveiled. Real progress, but with four explicit concerns flagged: pricing opacity, preview-stage flagship tools, A2A governance neutrality, and the absence of a multi-agent system lifecycle management story for production scale.
This year, the metaphor retires. The house is fully furnished. The occupants have arrived. Google Cloud Next ’26 is not an announcement about it being ready for customers; it is about how thousands of agents will be credentialed, governed, routed, observed, and held accountable within a fleet spanning clouds, vendors, and organizational boundaries.
The question now is who holds the keys?
Who issues the cryptographic identity that every agent operates under? Who owns the registry that every agent is discoverable through? Who enforces the gateway that every agent-to-agent call traverses? Who sets the protocol governance that decides whether MCP and A2A remain industry commons or become vendor-curated de facto standards? Who holds the kill switch on a long-running agent that has been reasoning autonomously for three days across four SaaS systems?
These are key-ownership questions, not platform-feature questions. Google Cloud Next ’26 is the first major hyperscaler event where these questions are the central cross-platform strategic choice an enterprise has to make.
The control plane, not the model layer, will determine hyperscaler dominance in the agentic era.
The three-year arc, named
Three years of CloudDon coverage make the pattern clear. Each Next event resolves the previous year’s structural critique and surfaces a new one layer up the stack.
2024: Listed, interiors incomplete. Platform with Bespoke agents.
2025: Interiors being completed. Agents without lifecycle management.
2026: House furnished, occupants moved in. Lifecycle management delivered, protocol neutrality achieved, control plane as the new contested ground.
This is the normal arc of a platform company compounding. It is also the shape of a vendor steadily consolidating control over the governance layer of an emerging category. Both readings are simultaneously true.
The CloudDon scorecard
Four concerns were flagged in 2025. Here is how each was answered. Plus a fifth — security maturity for the agentic era — that emerged in 2026 with Google’s recent completion of the Wiz acquisition and the cross-cloud security posture emphasized at the venue.

Google Cloud Next 2026 Rated on 2025 CloudDon Recommendations. Image created using Claude.ai.
1. Pricing of agent platforms — Not delivered, but moving.
The Agent Platform pricing pages are clearer than the announcement layer suggests. Agent Runtime is priced per vCPU-hour and GiB-hour of memory, billed per second. Memory Bank is priced at $0.25 per 1,000 memories stored per month. Model tokens have published rates. What remains undefined is the composite — the cost of running one autonomous agent for three days. That decomposes into Runtime compute, Sandbox compute, Sessions storage, Memory Bank, model tokens, and tool-call costs, with no metered unit for “one agent-day.”
I asked Peter Ulander about this directly at Next. His answer (paraphrased): Google is making pricing increasingly transparent and is actively working to improve it. That is the right answer, and the direction is right. It is also still in flight. Spend Caps and the FinOps Explainability Agent shipped at Next ’26 are genuinely useful responses to enterprise cost-containment concerns, but they are downstream containment mechanisms. Forecastable composite economics are the upstream fix, and they are not yet here.
2. General availability of critical components — Not delivered.
The deployable surface area is meaningfully smaller than the announcement surface area, and the gap is concentrated in exactly the capabilities enterprises would lean on for an agentic transformation.
On the infrastructure side, TPU 8t and TPU 8i are “available later this year” — the headline silicon will not be deployable until H2 2026 at the earliest. Virgo Network, the A5X bare-metal instances powered by NVIDIA Vera Rubin, and Managed Lustre at 10 TB/s are on the same trajectory.
The Agentic Data Cloud is in preview across most of its surface: Smart Storage, BigQuery Measures, the LookML Agent, Spanner Omni, the Database Observability Agent, the Deep Research Agent, AlloyDB Conversational Analytics, and bi-directional Iceberg federation to Databricks Unity Catalog, Snowflake Polaris, and AWS Glue Data Catalog. The cross-cloud lakehouse story — arguably the strongest data narrative of the event — is in active rollout, not production-ready.
Security is heavy with previews too: three new SecOps agents (Threat Hunting, Detection Engineering, Third-Party Context), Dark Web Intelligence, Confidential External Key Manager, KMS Quantum Safe Key Imports, Cloud NGFW advanced malware sandbox, Cloud Armor managed rules, SCC shadow AI discovery, and Confidential G4/C4 VMs. The GA exception is the existing Triage and Investigation agent.
Workspace and developer surfaces show the same pattern: the Workspace MCP Server, Chrome Enterprise auto browse, the new Sheets canvas, and most expanded sovereign controls are preview-stage. Notably, billing for Code Execution, Sessions, and Memory Bank only began January 28, 2026 — which means enterprises running Agent Platform earlier this year were on an incomplete meter, and full-cost forecasting was structurally impossible until then.
The procurement implication is concrete. An enterprise standardizing on Gemini Enterprise Agent Platform as its agentic operating system in Q2 2026 is not committing to a product; it is committing to a roadmap. The right posture is to assume meaningful schedule risk on preview-stage capabilities since hyperscaler preview-to-GA timelines are typically multi-quarter and frequently slip. Structure SLAs to require GA milestones rather than feature availability.
This is not uniquely a Google problem: AWS Agentcore and Microsoft Copilot Studio carry equivalent preview footprints. But it is a problem, and the marketing layer of Next ’26 understates it.
3. A2A protocol governance — Delivered, and delivered well.
In 2025, I asked whether A2A would remain a Google-controlled de facto standard or be governed neutrally. Google’s response arrived two months later at Open Source Summit North America in Denver on June 23, 2025: a donation of A2A to the Linux Foundation as the Agent2Agent Project, seeded with 100+ supporting organizations including AWS, Microsoft, Cisco, Salesforce, SAP, and ServiceNow. Six months later, in December 2025, the Linux Foundation announced the broader Agentic AI Foundation (AAIF), with founding contributions of Anthropic’s Model Context Protocol, OpenAI’s AGENTS.md, and Block’s goose — and Platinum members, including AWS, Bloomberg, Cloudflare, Google, and Microsoft. Google is not the steward of either body.
This is the cleanest governance answer any hyperscaler can provide to any agentic-era protocol question. It also reframes the rest of the analysis: Google is no longer protocol-hoarding, which means the Wiz cross-cloud security play is strategic opportunism at the observability layer above the protocols, not an evasion of a governance battle Google chose not to fight.
4. Real-world manageability of multi-agent systems — Delivered.
This is the single most direct response to the 2025 critique. We asked specifically how Google would handle monitoring, versioning, performance tuning, and the real-world complexity of multi-agent systems beyond controlled demos. Next ’26 answers with a six-part stack: Agent Registry for discovery and governance, Agent Observability with OpenTelemetry-compliant execution traces, Agent Simulation for pre-production stress-testing against synthetic users, Agent Evaluation for continuous multi-turn autorater scoring against live traffic, Agent Optimizer for automated failure clustering, and Agent Anomaly Detection for reasoning-drift detection. The production-management layer that I said was missing a year ago is now shipped. The call landed early.
The lifecycle stack is also where the responsible-AI primitives now sit, and that placement matters more than it might first appear. Agent Identity issues cryptographic IDs to every agent with auditable action trails. Model Armor extends inline to Agent Gateway and Agent Runtime, with Firebase integration generally available and Langchain in preview, providing protection against prompt injection, tool poisoning, and sensitive data leakage. Wiz Security Graph, now covering Gemini Enterprise Agent Platform from a separate but adjacent control plane, gives operators a runtime view of agent activity. These are not a separate Responsible AI domain in the agentic era — they are operational lifecycle controls. RAI in production-scale agent systems is what you do at runtime, not what you write in a policy document, and Google has architected accordingly.
What remains thin at the framework layer is opinionated, end-to-end workflow tooling. Google ships primitives — fairness metrics, model cards, explainability components, evaluation services — but assembles them into reusable enterprise pipelines for bias detection, transparency reporting, and ethical review as a customer task rather than as a platform deliverable. The gap is a “compose-it-yourself” gap, not a “doesn’t exist” gap, but it is real.
5. Security maturity for the agentic era — Delivered, with caveats. (Emerged 2026)
This concern was not on the 2025 list. It emerged with the completion of the Wiz acquisition and the cross-cloud agent security strategy it enabled. Reading the security announcements through that lens is essential: this is the first Google Cloud flagship event after the deal close, which means the integration story is necessarily early. With that timing in mind, the substance is real, and the strategic positioning is the most interesting move of the entire event.
- On substance: the Triage and Investigation Agent is now generally available, having processed 5+ million alerts and reduced 30-minute investigations to 60 seconds. Three new SecOps agents in preview (Threat Hunting, Detection Engineering, Third-Party Context). Wiz AI-APP, Red/Blue/Green Agents, and Dark Web Intelligence (with claimed 98% accuracy on millions of daily external events) carry over from RSAC 2026 but are now positioned as joint capabilities. AI-BOM and Wiz Workflows are new at Next ’26. Wiz AI-APP coverage now extends through the Wiz Security Graph to AWS Agentcore, Azure Copilot Studio, Salesforce Agentforce, and Gemini Enterprise Agent Platform, as well as Databricks, Cloudflare, Vercel, and Apigee.
- On strategy: Wiz is being deployed as the cross-cloud agent security control plane — the layer above the now-open MCP and A2A protocols. By extending Wiz Security Graph coverage to the major competing agent platforms, Google is making a bet that does not depend on enterprises standardizing on Gemini. This is a rare M&A move in which the acquired company’s strategic value to the parent increases as enterprises don’t go all-in on the parent. It’s a hedged bet on the agentic era’s actual shape — multi-cloud, multi-platform fleets — rather than the shape Google would prefer. That’s mature strategic thinking, and it should be credited.
Two caveats keep this verdict in qualified-yes territory rather than the unconditional ‘delivered’ of A2A and Lifecycle.
- First, a dual control plane. Google now operates two security control planes — Security Command Center and Wiz. Both cover cloud security posture, both have agent visibility, and both are being actively extended at Next ’26 with separate feature roadmaps. The integration narrative between them is sketched but not architected. Enterprises evaluating Google Cloud security in 2026 face an unanswered “which one do I buy?” question, and Google has not yet provided clear guidance.
- Second, most of the new agent-era security capabilities are preview-stage — the same GA maturity issue that affects Row 2. The deployable security capability surface is meaningfully smaller than the announced surface, and the Wiz–SecOps deep co-engineering that would distinguish this acquisition from a typical security tool partnership has not yet shipped.
Net assessment: directionally correct, substantively delivered, and strategically the strongest move of Next ’26. The asterisk reflects two issues that should be resolved in 2026–2027 — but until they are, enterprises should plan accordingly.
What is genuinely new at Next ‘26
Though Google Cloud emphasized throughout the event that it is the only player offering first-party solutions across the entire AI stack, three things mattered most.

Google Cloud AI Stack. Source: Google Cloud Next 2026 Analsyst Summit
Gemini Enterprise Agent Platform. Vertex AI is being absorbed into a full lifecycle stack — Build, Scale, Govern, Optimize — with Agent Studio (low-code), enhanced ADK with graph-based sub-agent orchestration, Agent Runtime supporting multi-day workflows, Agent Identity, Agent Registry, Agent Gateway, Agent Anomaly Detection, Agent Simulation, and Agent Evaluation. This is the most coherent agent lifecycle platform any hyperscaler has shipped to date. The competitive question is not whether Google has the best agent platform feature set today — it likely does. The question is whether AWS Agentcore and Microsoft’s Copilot Studio + Foundry stack catch up at re:Invent and Ignite this year.

Gemin Enteprise Agent Platform. Source: Google Cloud Next 2026 Keynote.
TPU 8t and 8i. The eighth-generation TPU split into purpose-built training and inference architectures is the most consequential infrastructure announcement of the event. TPU 8t scales to 9,600 chips per superpod with 121 ExaFlops of FP4 compute and 2.7x better price-performance versus Ironwood. TPU 8i is the procurement story enterprises should pay attention to: a new Boardfly topology connecting 1,152 chips per pod, with up to 50% lower network diameter than the 3D torus; 3x more on-chip SRAM (384 MB) to host larger KV caches entirely on silicon; and a specialized Collectives Acceleration Engine reducing on-chip latency by 5x. Headline number: 80% better performance per dollar for inference. This is the first TPU generation for which the economics of inference warrant a serious procurement conversation outside Google’s own model family.

TPU 8i ASIC Block Diagram. Source: TPU 8t and TPU 8i technical deep dive | Google Cloud Blog
Wiz cross-cloud. Wiz, now integrated into Google Cloud, has expanded the Wiz Security Graph to cover AWS Agentcore, Azure Copilot Studio, Salesforce Agentforce, Gemini Enterprise Agent Platform, as well as Databricks, Cloudflare, Apigee, and Vercel. This is the strategically most interesting move of Next ’26. Wiz is being positioned as the cross-cloud agent security control plane — the layer above the protocols where vendor differentiation now sits. Google is betting that observability and runtime protection across every agent studio (including its competitors’) is a more durable moat than agent-platform feature differentiation. That bet is structurally correct.
The four keys
The key-ownership frame reduces the agentic enterprise architecture decision to four distinct ownership questions.

Four Keys that hold vendor lock-in. Image created using Claude.ai.
- Protocol keys. Held by the Linux Foundation and the Agentic AI Foundation. MCP and A2A are now genuinely open, neutrally stewarded. Building on them is the lower-risk choice today, not the higher-risk one — the inverse of what it was twelve months ago.
- Identity keys. Held by the platform on which an agent is built. Agent Identity in Gemini Enterprise issues cryptographic IDs to Google-built agents. AWS Agentcore issues identities for AWS-built agents. Microsoft does the same through Entra Agent ID, with Copilot Studio and Foundry as consumers. There is no neutral identity layer for cross-platform agents — each agent’s identity is rooted in the platform that issued it. Identity reconciliation will be the operational pain point in multi-platform deployments before the end of 2026.
- Control plane keys. Held by the new battleground. Agent Registry, Agent Gateway, Agent Observability, Agent Anomaly Detection — the layer that mediates agent-to-agent and agent-to-tool interactions, enforces policy, and provides runtime visibility. Three strategies are competing: Google-native (deeply integrated, best for greenfield AI-native organizations standardizing on Google), Wiz cross-cloud (the most comprehensive cross-cloud option currently shipping, best for multi-cloud enterprises), and self-hosted on open primitives (most fragmented today, best for enterprises with strong platform engineering and a strategic preference for vendor neutrality).
- Unit economics keys. Held by Google internally, for now — but with active movement toward transparency, per Peter Ulander’s direct response. The composite-pricing question is the one enterprises can negotiate most directly at procurement time.
Three recommendations
- Bet on the open protocol layer. Establish Agent-to-Agent (A2A) and Model Context Protocol (MCP) as your mandatory architectural standards to ensure every agent remains interoperable across vendors and avoids being trapped in a single provider’s proprietary ecosystem. Treat vendor-specific protocol bindings as convenience integrations, not strategic commitments. Require A2A and MCP support as a baseline criterion in any agent platform RFP, regardless of vendor.
- Make the agent control plane a separate procurement decision. Decouple your choice of agent-building tools from your governance layer by explicitly evaluating Agent Registry, Gateway, and Observability as a standalone control plane capable of managing a heterogeneous, multi-cloud fleet. The control plane is where 2026 lock-in lives, and it deserves an explicit decision with three named alternatives evaluated against each other. Stand up a dedicated control-plane evaluation in Q3 2026, run a 90-day pilot with the leading two candidates against a real production workload, and negotiate exit clauses explicitly.
- Demand composite pricing. Reject fragmented component rate cards in favor of contractual ‘agent-day’ or outcome-based pricing to gain the fiscal predictability required to scale autonomous agents without the risk of uncapped operational costs. Use Spend Caps as a safety net, not a primary budget control. Google’s stated direction on transparency is the right direction; enterprises should hold the procurement open until the direction shows up in the contract.
Closing
Across three Google Cloud Next events, Google has resolved the previous year’s structural critique each time and surfaced a new one at a higher layer in the stack. The 2026 critique will likely be substantially answered by 2027, on this trajectory.
Enterprises betting on Google Cloud as their agentic platform are betting on a vendor iterating against analyst and customer feedback at a pace that materially addresses the questions analysts raised. That bet has merit. It is also a bet — and the four keys tell you which parts create lock-in and which you can walk back if you need to.
The house is furnished. The keys are being distributed. The enterprise that decides which keys to hold — and which to delegate, and to whom — is the enterprise that will navigate the agentic era with optionality intact.
Google Cloud Next ’26 suggests that Google understands where the agentic market is moving earlier and more coherently than many competitors currently do. The company’s strategy increasingly treats the control plane — identity, observability, governance, security, and orchestration — as the durable layer of enterprise AI value capture rather than merely the models underneath it.
Whether Google ultimately wins that race remains unresolved. Microsoft retains deep enterprise identity and workflow advantages. AWS still commands the industry’s strongest infrastructure position. Open protocols may weaken platform lock-in faster than hyperscalers expect. And the control plane itself is still fragmenting across vendors, clouds, and governance bodies.
But Next ’26 makes one thing increasingly clear: the strategic center of gravity in enterprise AI is shifting upward in the stack.
The pre-training era was won through compute scale. The agentic era will be won through control-plane gravity.
The full analyst brief will be available at clouddon.ai soon. It will include the complete scorecard, expanded sections on the Agentic Data Cloud, and procurement-grade detail on each of the three recommendations.
(Update: Header video replaced due to poor audio quality.)
메타데이터
- post_id
- 8adfc30b9bed
- slug
- google-cloud-next-2026-the-move-in-is-complete-who-holds-the-keys-8adfc30b9bed
- url
- https://clouddon.ai/google-cloud-next-2026-the-move-in-is-complete-who-holds-the-keys-8adfc30b9bed
- canonical_url
- https://clouddon.ai/google-cloud-next-2026-the-move-in-is-complete-who-holds-the-keys-8adfc30b9bed
- author_url
- https://medium.com/@sriramhere
- status
- ok
- fetched_at
- 2026-06-10 08:17:25