Google began rolling out Gemini Spark this week as a beta to subscribers of its AI Ultra plan, which starts at $100 a month. Spark is an always-on agent that connects to a user's Gmail, Google Docs, and Google Calendar, executes online tasks, and can operate a remote browser on the user's behalf. It lives inside the Gemini chatbot as a new tab and runs on both Android and iPhone.
The product is Google's answer to OpenClaw, the agent that drew Silicon Valley attention at the start of 2026 after early adopters wired it into their messaging and scheduling. Spark reframes the interaction model: instead of "prompts," users send "tasks," which the agent can fulfill by drafting emails, creating calendar events (with approval), or driving a browser session. The first wave of access is gated behind the $100/month tier — a deliberately narrow rollout that keeps the blast radius small while Google tests behavior on real inboxes.
In a hands-on writeup, Wired's Reece Rogers granted Spark full access to his personal Gmail, Docs, and Calendar, then issued a one-sentence request to help plan his 32nd birthday party. Spark returned a 5-page itinerary in a couple of minutes that included the real karaoke-bar reservation already in his email, the last four digits of the credit card used for the $50 deposit, nearby restaurants with phone numbers, after-party bars, draft email invites, and venue rules.
Key facts
- 01Google began rolling out Gemini Spark this week as a beta to AI Ultra subscribers, a plan that starts at $100 a month.
- 02Spark connects to Gmail, Google Docs, and Google Calendar, and runs on both Android and iPhone inside the Gemini chatbot as a new tab.
- 03The agent generated a 5-page birthday itinerary with a 15-person guest list pulled from the user's Workspace history in a couple of minutes.
- 04Google's own help page warns Spark is exposed to prompt injection attacks that could exfiltrate Gmail data to external services.
- 05Spark is Google's answer to OpenClaw, the agent that drew Silicon Valley attention at the start of 2026.
The agent also produced a 15-person guest list — the karaoke room's exact capacity — scraped from contacts and travel history across the connected apps. Spark surfaced specific source material for each suggestion, including emails the user no longer remembered, and named venues such as Toad Hall and OASIS and groups including Stonewall Sports and the Sons of Pitches as inputs. When asked why those venues were chosen, Spark insisted it was matching keywords, not inferring identity.
Spark's reasoning, in its own words, was that it was reading the file system, not reading the person. That distinction matters for how Google is positioning the product legally and editorially: Spark presents itself as a retrieval-and-execution layer over personal data, not a profiler.
“The system does not make inferences about your personal identity. Instead, it scans your files and emails for exact keywords, past itineraries, and transactions”— Gemini Spark, Google AI agent (in-product response)
Execution was uneven. Spark attempted to book dinner reservations through a remote browser session, triggered a 6-digit verification code to be texted to the user's phone, and still failed to complete the task across multiple retries. It also misjudged tone on the draft invite — scolding guests about minimum age requirements for a party where everyone was over 21 — until prompted to rewrite. After approval, it sent the test email automatically to the user's boyfriend, whom Spark had separately classified as a "close friend and frequent companion" rather than a partner, despite shared housing and account recovery records.
Google is shipping Spark with an unusually direct security disclaimer. The product's help page explicitly flags prompt injection risk, describing scenarios where a hostile instruction embedded in incoming content could redirect the agent against the user.
“A malicious instruction could tell the agent to take your private info from your emails or documents and post it on a public website, send your emails in Gmail to an external service without you knowing, expose insights about you based on your data in connected apps”— Google, Gemini Spark help page
That warning is load-bearing. Spark's value proposition — deep context from Gmail, Docs, and Calendar — is the same surface that prompt injection attacks exploit. A poisoned email, a malicious Google Doc shared into an inbox, or a compromised webpage opened in Spark's remote browser could all become attack vectors against the most sensitive data the agent can reach. Google is asking $100-a-month customers to weigh that trade-off themselves.
Spark's capability ceiling extends beyond one-shot tasks. Users can schedule recurring tasks and upload custom skills, including a tone-mimicking skill that lets Spark compose email in the user's voice. Those features point toward a more ambient assistant model, where Spark handles routine workflow without per-task supervision — closer to what OpenClaw users adopted earlier this year, with the same accompanying mishap risk.
Spark's launch is the clearest signal yet that Google intends to compete in the consumer-agent category on the same terms as OpenClaw rather than ceding it. The $100 price point and Workspace-deep integration suggest Google is targeting power users who already live inside Gmail and Calendar, where the data-access moat is structural. The open question is whether early adopters tolerate the prompt-injection exposure long enough for Google to harden the agent — and whether "friend-zoned my boyfriend" stays a punchline or becomes the kind of repeated common-sense failure that erodes trust before the security model is ever stress-tested.
Working on something we should cover, or seeing a story we missed? Send leads, documents, or feedback to hello@aichatdaily.com. For sensitive tips, see our secure tips page for Signal and PGP options.
Spotted an error? Email hello@aichatdaily.com with the URL and the issue, or read our full corrections policy.




