Live
Enforcing US Data Residency with Cloudflare D1AI agents CI: why repository‑centric pipelines are breakingAI Agent Inbox: Deploy Pizza Bot for Background Task ExecutionOpenAPPA delivers zero‑success prompt‑injection protection in benchmark tests – what AI engineers need to knowEU Cyber Resilience Act expands software supply‑chain responsibilities for digital product manufacturersTyped Probability Model Jev Shifts AI Output from Text to Structured DecisionsBasin Pipelines per‑stream ingest capacity jumps to 1 GB/s – what engineers need to knowAI‑driven vulnerability management: moving from CVE counts to contextual riskEnforcing US Data Residency with Cloudflare D1AI agents CI: why repository‑centric pipelines are breakingAI Agent Inbox: Deploy Pizza Bot for Background Task ExecutionOpenAPPA delivers zero‑success prompt‑injection protection in benchmark tests – what AI engineers need to knowEU Cyber Resilience Act expands software supply‑chain responsibilities for digital product manufacturersTyped Probability Model Jev Shifts AI Output from Text to Structured DecisionsBasin Pipelines per‑stream ingest capacity jumps to 1 GB/s – what engineers need to knowAI‑driven vulnerability management: moving from CVE counts to contextual risk

Google Expands Antigravity Agents to Native IDEs with Enterprise Guardrails

AI SummaryPowered by AI

Google has integrated its Antigravity AI coding agents directly into Visual Studio Code, JetBrains suites, and Zed via new extensions for Gemini Enterprise subscribers. This shift allows engineering teams to delegate multi-step tasks within their existing workflows while maintaining strict administrative controls over token budgets and data boundaries.

When Google launched the Antigravity AI coding agent in November 2025, it operated on a premise that required developers to hand off entire engineering tasks to an external application. That model has changed as of Thursday with the release of new extensions for Visual Studio Code (macOS, Linux, Windows), Visual Studio 2026 and .NET solutions, JetBrains IDEs including IntelliJ IDEA and PyCharm, and Zed.

This architectural shift moves agent execution from a standalone desktop application into developers' existing environments. For platform teams managing tooling sprawl or security engineers concerned with data exfiltration risks, this integration represents a significant change in how AI agents access local resources without requiring company-wide infrastructure changes to adopt the technology.

Architecture and Operational Implications

The primary operational impact is that agent sessions now inherit organization-level policies directly within the editor. When an enterprise developer signs in using Workforce Identity Federation or Application Default Credentials, their session automatically connects to a specific Google Cloud project and region.

This design ensures that regardless of whether a user switches between VS Code on Linux or JetBrains Rider on Windows, they draw from a single pool of credits defined by the organization's edition (Standard, Plus, Standard Emerging Market). The system meters usage via a rolling seven-day token allowance rather than strict monthly buckets. A nontrivial engineering task can consume 150,000 to 200,000 tokens; multi-agent handoffs add further input costs as work passes between agents.

Without these controls in place, an agent-heavy workflow could exhaust a team's entire credit pool within hours. This mirrors recent budgetary issues faced by other vendors where engineers spent hundreds or thousands of dollars per month on token consumption alone. Administrators can now cap monthly spending for each project; once the quota is exhausted, Antigravity either shuts off operations or switches to pay-as-you-go pricing.

Security and Access Controls

The integration introduces a critical distinction between authentication (signing in) and authorization. Once authenticated via company credentials, agent sessions inherit IAM policies, VPC Service Controls, and regional data boundaries defined by the organization's security posture.

This architecture treats MCP servers—such as ElevenLabs' server used for voice agents—as privileged access points that require strict governance. Administrators can limit an agent's workspace scope or block browser access to prevent lateral movement within a production system. Google explicitly states that data from these enterprise sessions is not used to train foundation models, addressing concerns about intellectual property leakage.

However, practitioners must recognize that application-layer filtering and prompt rules complement authorization but do not replace IAM/RBAC controls. A bad setting in one of those connections reaching a production system can have serious consequences if the agent possesses permissions it should not hold.

What This Means For Practitioners

The expansion into native IDEs allows Google to land inside enterprise engineering teams without forcing users to adopt new desktop applications. However, this convenience introduces a dependency on specific extensions for Visual Studio 2026 and JetBrains suite version 2026.2.1.

For security engineers, the immediate task is evaluating whether existing IAM policies sufficiently restrict agent capabilities within these trusted environments. Platform teams should monitor token consumption rates closely to avoid hitting rolling seven-day limits that could disrupt workflows unexpectedly. As controls for individual users and teams arrive later this year, organizations must prepare their governance frameworks now.

Ultimately, the ability to delegate multi-step engineering tasks without moving projects into a separate application stream is valuable, but it requires rigorous oversight of token budgets and access scopes before deployment at scale.

Originally published atThe New Stack