Google I/O 2026

The Connector List Is the Product and the Risk Surface

原演讲者: Google Workspace developer team, Google · Google

来源已核验演讲日期待核实presentation12:31EN2 分钟阅读

An agent over a productivity suite has the most valuable context available for workplace tasks and the most sensitive corpus an organisation owns — and the permission model that governs a person reading their own mail was not designed for a process reading it under instructions that may have come from a document.

The claim in this session that generalises past the products is about where agents get their reach: connectors for mail, chat, drive, calendar and contacts, letting agent developers search across them (8:09).

That list is the actual substance. An agent with access to a person's calendar, correspondence and documents can do work that an agent with a language model and a web search cannot — not because it reasons better, but because it knows things.

The capability nobody quite states

The example offered is ordinary: focus entirely on a discussion and catch up later when a meeting conflicts (3:24).

Underneath it is a shift worth naming. The value of a meeting summary is not the summary. It is that attending stops being the only way to know what happened, which changes the calculus of every scheduling conflict a person has. That is a small change repeated many times a week, which is usually where compounding value comes from.

Why this is the strongest position and the most uncomfortable one

An agent operating over a productivity suite has something no model provider can supply: the accumulated record of how an organisation actually works. Who talks to whom, what was decided, which document is current, what happened last time this came up.

That is the most valuable context available for any workplace task, and it is also the most sensitive corpus most organisations own. Every capability described here is a capability to read across it.

The connector list is therefore both the product and the risk surface, and the two cannot be separated. An agent that can search mail to answer a question can search mail to answer a question it was manipulated into asking. The permission model that governs a person reading their own mail was not designed for a process reading it on their behalf under instructions that may have come from a document.

What a twelve-minute session cannot cover

None of the above is a criticism of the direction, which is correct — the productivity suite is where the useful context lives, and putting agents there is obviously right.

It is an observation about sequence. The connectors arrived first because they are the capability. The governance question they create is real, unanswered here, and will be answered by whoever ships an incident first.

演讲章节

关键要点

  1. 01

    Reach comes from connectors across mail, chat, drive, calendar and contacts, with agent developers able to search over them. 8:09

  2. 02

    The framing example is a scheduling conflict: attending stops being the only way to know what happened, which is a small change repeated weekly. 3:24

  3. 03

    The same connector surface that gives an agent useful context is the organisation's most sensitive corpus, and the two cannot be separated. 8:09

提及的实体

相关演讲

Jeff Dean on Why Tools, Not Models, Are the Next Bottleneck (Google I/O 2026)
Jeff Dean on Why Tools, Not Models, Are the Next Bottleneck (Google I/O 2026)

Four of Google's model, product and search leads on what changes once agents run for hours rather than seconds, and the most quotable argument comes from Dean: the constraint is moving out of the model and into the tools around it. By Amdahl's law, an agent spending half its time in tools built for human-speed interaction cannot gain more than a doubling however fast the model becomes — which reframes a great deal of current infrastructure work as latency debt. Their internal response is concrete: rewriting Python tooling into Go, framed as a fully specified translation task rather than an open prompt, produced order-of-magnitude speedups overnight. Reid supplies the counterweight from Search, where acceptable latency turns out to scale with how much work is being taken off the user rather than being a fixed budget. Woodward's detail is the quietest and perhaps the most telling: teams that have stopped writing product documents for humans and now write context files for models to act on directly.

panel

"Pick Up the Extinct Animal": Where Robotics Actually Stands
"Pick Up the Extinct Animal": Where Robotics Actually Stands

The anecdote that opens the panel does the work: a robot asked to pick up the extinct animal selected a dinosaur toy, with nothing in its training data connecting the phrase to the object. That transfer from language models into machines with hands is the premise of the current wave. What the practitioners then describe is where it stops. Physical intelligence is about exerting force and using a body to do it, which is knowledge about consequences — the one thing a corpus of internet images contains almost nothing about. The humanoid question gets an honest treatment: not that human shape is optimal, but that the world is already built for it, plus a development-loop argument about collecting data and deploying on the same hardware. The most useful passage is scepticism about the field's favourite shortcut: generated video looks realistic and does not hold up for dexterous manipulation, because looking right and being physically consistent are different properties.

panel

When Developers Stop Opening the Editor, Chat Becomes an Interrupt Handler
When Developers Stop Opening the Editor, Chat Becomes an Interrupt Handler

The observation that organises this session is not about capability but about attention. Engineers increasingly file a ticket rather than opening an editor, and the code comes back — which changes what the surrounding tools are for. If the agent works while you do something else, the conversation between you is no longer a workspace; it is the mechanism by which the agent surfaces a question it cannot resolve alone. Interfaces built for continuous conversation optimise for flow, and interfaces built for interruption should optimise for the opposite. A runtime constraint follows immediately: an agent that starts a long-running job cannot block until it finishes, which turns out to be a workflow-engine problem rather than a model one. The panel's closing formulation — that deciding what to build is the hard skill and always was — reads as reassurance and functions as a warning, since that judgement is downstream of exactly the work now being delegated.

panel

The Moment It Stops Being Single Player
The Moment It Stops Being Single Player

The most honest moment here is an aside about how the presenters have tracked their own projects: plans in documents, plans in spreadsheets, plans in bug comments, and once a plan written on a receipt. That describes the actual category being addressed — not software nobody has built, but the small internal tool every team improvises badly because building it properly was never worth the effort. The demo turns on a single question: the generated app is strictly single player, so what happens when you want to share it with the team? That boundary is where improvised tools historically died, because it is where accounts, shared storage and access rules begin. Here it is crossed in one step, with the access rules generated and deployed automatically — which is convenient, and is also the moment the application acquires obligations nobody reviewed.

session

Why Google Dropped Chat Turns for Steps: The Interactions API at I/O 2026
Why Google Dropped Chat Turns for Steps: The Interactions API at I/O 2026

The clearest statement at I/O of how an agent API differs from a chat API, and the reasoning behind each departure is stated rather than assumed. Three changes matter. Conversation state moves to the server: a call returns an identifier, and passing it back continues the thread, retiring the client-side history array. The data model abandons alternating user and model turns for discrete steps, on the argument that a trace containing reasoning, tool calls, environment responses and compaction was never really a conversation and modelling it as one distorted it. And agents receive their own persistent remote environment rather than acting on the caller's machine — addressable by identifier, and shareable, so a research agent's output files become an application builder's input without passing through the context window. Schmid is explicit that scaffolded environment files are deliberately not model input, which is what keeps large artefacts out of the context budget. Schaeff's first half covers the real-time voice path, where the notable property is speech-to-speech across ninety languages with transcription of both directions.

presentation

Pichai Calls Google a Buffer Between People and the Raw Internet
Pichai Calls Google a Buffer Between People and the Raw Internet

Pichai's framing of Google as the buffer between people and the raw internet is offered as continuity — search did it, browsers did it, agents do it more — and it is also the most contested claim in the industry, because a buffer decides what passes through. He reaches immediately for the counterweight, the connection people feel to creators they follow, which is precisely the tension the company is currently managing without resolving. Two answers are sharper than the format usually produces. On competition he describes participants running on different pre-training and release cadences rather than at different speeds in one race, which is a more honest account than the leaderboard framing and comes from someone with an interest in leaderboards. On security he acknowledges models improving at cyber work, which is the one domain where better capability does not obviously net out positive, since an attacker needs one vulnerability and a defender needs all of them.

fireside