Field Notes
Agents in Production Was the Only Conversation at Google Cloud Next '26
Field notes from Las Vegas. Nobody asked whether an agent could do the job. They asked how to secure it, monitor it and govern it once it does. And on the bubble question: the constraint is hardware supply, not demand.
The word everyone kept saying was production
I have just come back from a week in Las Vegas for Google Cloud Next, and the thing I keep turning over is not a product announcement. It is how completely the conversation has moved.
Two years ago the questions were about capability. Can it summarise this. Can it draft that. Can it read our documents. This year almost nobody asked me whether an agent could do something. They asked how to run one properly once it does.
The theme was clear. AI agents in production. Not experiments. Production. How do you secure them, how do you make them compliant, how do you monitor them, how do you govern them at enterprise scale. Every conversation circled back to this.
The gap that has replaced the capability gap
That shift matters more than it sounds, because it moves the hard problem somewhere most organisations are not set up to solve it.
A capability gap is a vendor problem. You wait, the models improve, the gap closes without you doing anything. A production gap is your problem. It is answered in your identity system, your data classification, your change process and your audit requirements. No model release closes it for you.
This is why so many pilots stall at exactly the same point. The demo works. Then somebody in security asks what the agent can reach, somebody in legal asks what happens when it is wrong, and nobody has an answer that survives the meeting.
The hard part is no longer whether the model can. It is whether you can run it.
Four questions, over and over
If I compress every serious conversation I had that week, it comes down to four questions, and they were always asked in this order.
What can it see. Not what is it allowed to say, but what is inside its reach in the first place. The answer has to be the same as what the person asking could already open themselves, and being able to demonstrate that is a different thing from asserting it.
What happens when it is wrong. Everyone has accepted that models are wrong sometimes. What they want to know is whether being wrong is recoverable. An agent that drafts something a human sends is a very different risk profile from an agent that sends it.
Who watches it. A pilot has an owner watching it every day. A production system has fifty of them and no one watching. That gap is where most of the risk lives.
Can we prove any of this later. Not a dashboard. A record that reconstructs what happened, who asked, what was retrieved and what was returned, months after the fact.
On the bubble question
It also made me think about the whole "AI bubble is about to burst" narrative, which I got asked about more than once over dinner.
I have been working in this space for over a decade, with enterprise customers every day, and the untapped potential I see is enormous. We are genuinely just getting started. As agents get smarter their applications will only grow: systems that can reason, decide and act on their own, inside the systems a business already runs.
The demand is not the fragile part. In every conversation that week the constraint was never "we cannot find a use case". It was "we cannot get this past our own controls fast enough".
The constraint is supply, not enthusiasm
If anything slows this down it will not be demand. It will be hardware.
If we cannot build enough infrastructure to handle the compute these models need, AI will not burst. It will just get more expensive and harder to access. The organisations that got their governance and their data foundations right early will absorb that. The ones still running twelve disconnected pilots will find that the price of catching up went up while they were deciding.
That is a supply problem, not a hype problem. It is also, for anyone building right now, a fairly strong argument for doing the unglamorous work first.
The interesting question coming out of Next is no longer which model to use. It is whether your organisation can put any of them into production without a six month argument with its own security team. That is a solvable problem, and it is mostly not a technical one.
Related Articles
Working on something like this?
No pitch, just a practical conversation with the team that builds and operates these systems in production.
Start a conversation