Gemini Spark
Google · gemini.google/overview/agent/spark
Gemini Spark is a 24/7 background agent that runs tasks, reusable skills and schedules on Google-hosted remote browsers and computers, with an optional local Chrome mode. Skills are markdown (SKILL.md) plus scripts that owners can edit, download and upload, sensitive actions require confirmation, and custom MCP servers can be added in the US. The runtime, harness and model are proprietary Google services; Spark requires a paid plan and Keep Activity on, which enables training on activity, and there is no complete agent export or tamper-evident audit trail.
- Skills stored as editable SKILL.md markdown with scripts, downloadable as .zip
- Confirmation before sending, modifying data, purchases and form submission
- Stop button, and deleting a task removes its schedules and activity
- Custom MCP servers can be connected (US)
- Remote browser and computer data can be deleted from Spark settings
- Runs only on Google VMs with Gemini models and a closed harness
- No complete export of tasks, schedules, remote computer state or credentials
- Requires Keep Activity on, which enables training and human review
- Paid Pro/Ultra plan required for all use
- System instructions not published
- No tamper-evident audit trail
All 34 findings
Gemini Spark beta inside the consumer Gemini app (web, mobile, Mac) for personal Google Accounts on Google AI Pro/Ultra, launched May 2026 on Gemini 3.5 with the Antigravity harness, per public documentation as of 2026-09-27. Business/Workspace availability not assessed; the general Gemini app is covered separately.
Portable · Can you leave, and take the whole agent with you?
8%- P1Round-trip portability
Incomplete and not restorable in one action: skills download and re-upload as .zip files, but tasks, schedules, remote computer state and credentials have no export or import, so the Spark agent itself cannot be restored.
Fail - P2Complete export
Skill downloads include instructions and files, and Takeout covers chats, media and uploads, but tasks, schedules, remote computer files, remote browser cookies, Connected App credentials and personal context are not documented as exportable.
Partial - P3Independent execution
Spark runs on Gemini 3.5 with Google's Antigravity harness on Google-hosted remote browsers and computers; no open-source runtime can run it without Google servers.
Fail - P4Identity continuity
Spark is bound to the owner's personal Google Account, and nothing lets peers verify its continuity outside Google.
Fail - P5No kill switch
The functioning agent exists only on Google infrastructure and depends on an active Pro/Ultra subscription and Keep Activity; exported skills are files, not an executable agent.
Fail - P6Capability independence
Schedules, triggers, remote browsing, code execution and Connected Apps are delivered by Google's platform on Gemini models, with no documented way to keep them on another model. Skills use the portable SKILL.md format but rely on Spark to execute.
Fail
Transparent · Can you see everything the agent is, with ordinary tools?
33%- T1Open storage format
Skills are markdown and ordinary code/config files, and Takeout exports activity in a .zip/.tgz archive. Storage of tasks, schedules and remote computer state is undocumented and reachable only through Google's software.
Partial - T2No hidden instructions
Skill instructions are visible, but Google does not publish Spark's system instructions or the context it injects from Personal Intelligence and Connected Apps.
Fail - T3No shadow memory
Spark data follows Gemini retention rules: chats selected for human review are kept up to three years, disconnected from the account, beyond the owner's deletion.
Fail - T4Complete action history
Task threads show planned, current and completed steps, and task activity is stored in Gemini Apps Activity, but no complete record of tool calls is documented, and Spark task steps are not documented as part of the Takeout export.
Partial - T5Readable logic
Skills are human-readable markdown and can include .py and .sh scripts, but the Antigravity harness and task orchestration are closed source.
Partial - T6No third-party influence channel
Google states Gemini Apps chats are not used to show ads and the app shows none. There is no binding commitment to keep Spark ad-free.
Partial
Auditable · Can you reconstruct exactly what the agent did?
10%- A1No unrecorded actions
Google does not document whether every consequential Spark action is durably recorded, or whether an action is blocked when it cannot be recorded.
Unverified - A2Tamper evidence
Task threads and their activity can be deleted without a detectable trace, and no tamper-evident record is documented.
Fail - A3Separation from the audited
Google does not document whether the agent, which can save files and run code on its remote computer, can alter or delete records of its own actions.
Unverified - A4Readable with ordinary tools
Takeout exports Gemini Apps activity in readable archives, but it is an activity export, and Spark task steps are not documented as included.
Partial - A5Corroborated interactions
No exchanges with other agents whose records each side could match against the other's are documented for Spark.
Unverified
Verifiable · Can you prove the agent runs what it claims?
0%- V1Open, reproducible runtime
The Spark runtime and Antigravity harness as hosted by Google are proprietary; no OSI-licensed, reproducible runtime is published.
Fail - V2Active config is inspectable config
System instructions and injected personal context are not published, so the active configuration cannot be compared with what the owner can inspect.
Fail - V3Attributable messages
Spark sends through the owner's Google and connected accounts, so recipients cannot verify that messages came from this agent under the owner's authority.
Fail - V4Independently checkable record
No action record is offered whose integrity can be checked with open tools that do not depend on Google.
Fail - V5Comparable state
Remote computer, task and server-side state are not fully exposed, so the owner cannot verify whether the agent's state changed between two points in time.
Fail
Modifiable · Can you change anything, without asking?
33%- M1Instructions
Owners can edit skill descriptions and instructions directly or conversationally, but cannot read or rewrite Spark's system instructions.
Partial - M2Memory
Owners can delete tasks with their activity and bulk-delete remote computer and browser data, but no item-level viewer or editor for derived memory or saved remote state is documented.
Partial - M3Logic
Owners can create, edit, upload and delete skills including .py and .sh scripts (without internet access), and set schedules. The harness and orchestration logic cannot be changed.
Partial - M4Tools and permissions
Owners can enable, disable and remove Connected Apps and add custom MCP servers. Custom apps are limited to US adults with personal accounts, English and Keep Activity on, and write actions require confirmation.
Partial - M5Model choice
Spark runs on Google's Gemini 3.5; third-party or local open-weight models cannot be selected.
Fail - M6No gatekeeping
Spark and skills require a paid Google AI Pro or Ultra subscription, an eligible region and Keep Activity on; custom apps are further limited to the US.
Fail
Controllable · Is your word final?
42%- C1Communication boundaries
Owners choose which apps to connect, and Spark asks before sending communications, but owners cannot set which recipients or channels it may contact, no enforcement below the model is documented, and Google notes Spark may share chat information with websites and custom apps.
Partial - C2Approval gates
Spark prompts for confirmation before sending communications, modifying data, purchases and submitting web forms. The gated categories are set by Google rather than selected by the owner, and enforcement cannot be independently verified.
Partial - C3Immediate halt
Owners can stop a running task at any time with the Stop button, and deleting a task also removes its schedules.
Pass - C4Data sovereignty
Spark runs entirely on Google servers and requires Keep Activity on, under which chats are used to improve Google models and a subset is human-reviewed; there is no opt-in for training.
Fail - C5Credential custody
Remote browser authentication cookies and Connected App and MCP credentials are held in Google's service; owners can delete or disconnect them, but they are not inspectable and do not travel with an export.
Fail - C6Full deletion
Owners can delete tasks, skills, remote computer and browser data, Gemini Apps activity or the Google Account, but chats reviewed by humans are retained up to three years.
Partial
Vendors and the public can dispute any finding with evidence. Disputes and their resolutions are published.