Google put a leash on Antigravity, and that’s the whole story

Google spent the better part of a year telling everyone that Antigravity, its agentic coding environment, was the future of software work. Agents that plan, write, test, and ship with a human somewhere in the loop, loosely defined. Last week The Register reported that Google is now tethering Antigravity to its enterprise admin controls. Policy enforcement, permission scoping, audit visibility, the works.

Read that again. The company with more AI research muscle than almost anyone on the planet looked at its own autonomous agents running inside customer environments and decided they needed a leash.

That’s not a product announcement. That’s an admission.

What the tether actually tells you

For roughly two years the agentic AI pitch has been velocity. Let the agent touch the repo, the ticket queue, the database, the deployment pipeline. Trust the model. Move fast.

Enterprises, it turns out, were not buying it at scale. Security teams kept asking the same unglamorous questions. What can this agent read? What can it write? Who approved that? Where’s the log? And the honest answer, for most agentic tools shipped since 2024, was some version of “we’re working on it.”

So Google did what a vendor under pressure does: it built the controls its buyers were demanding and wired them into the Google admin plane. Good for Google. Genuinely good for Antigravity customers, too, in the narrow sense. An agent with scoped permissions and an audit trail beats an agent without them every single day.

But notice where those controls live. Inside Google’s console, expressed in Google’s policy language, enforced by Google’s infrastructure, covering Google’s agents. If you run Antigravity plus a Copilot deployment plus a homegrown agent on an open-weights model, and most mid-size shops we talk to are already in exactly that mixed state, you now have one well-governed island and a lot of open water.

Governance rented from a vendor is still lock-in

Here’s the part that should bother you more than the ungoverned agents did.

When your AI governance is a feature of one vendor’s platform, your policy layer becomes a switching cost. Every rule you write in their console, every approval workflow you build around their audit log, every compliance attestation that cites their controls, all of it deepens the moat around that one product. Leave the product and you leave your governance behind. You’d have to rebuild it from scratch inside the next vendor’s console, in their language, with their gaps.

That’s a strange place to park something as load-bearing as “who is allowed to let software act on our behalf, and under what conditions.”

Governance isn’t a feature. It’s a function. It belongs to the organization, above the tools, the way your security policy isn’t a setting inside your firewall vendor’s dashboard. The firewall enforces the policy. It doesn’t own it.

What owning it looks like

This is exactly the problem a fractional Chief AI Officer, or a small AI Program Office if you want the standing version, exists to solve. Not a committee that meets quarterly and produces a PDF. A working function that does specific things:

  • Keeps an inventory of every agent and model in use, sanctioned or not. Most orgs that build this list for the first time find two or three tools nobody in leadership knew about.
  • Writes permission and data-access policy once, in plain language the business owns, then maps it onto each platform’s controls. Google’s tether becomes one enforcement point among several, instead of the whole strategy.
  • Defines what gets logged, reviewed, and escalated when an agent acts, regardless of whose agent it is.
  • Maintains an exit plan per vendor. If the policy layer is yours, swapping the tool underneath is an engineering project, not an identity crisis.

None of this requires a full-time executive salary, and at most firms it shouldn’t get one. It requires a few disciplined days a month from someone who has done it before and answers to you, not to a platform’s roadmap.

The alternative is what we’re watching play out now: each hyperscaler ships its own governance surface, each one slightly different, and enterprises stitch together a compliance story out of four vendors’ screenshots and hope the auditor doesn’t ask how the pieces relate.

The principle underneath

Modular’s position on data has been the same since day one. Your data, your rules. And that includes the AI working on it. Your AI, your rules. An agent that can read your files, write your code, and act in your name is not a productivity toy. It’s an actor inside your business, and the rules governing an actor inside your business should be written by you, enforceable everywhere, and portable to whatever stack you run next year.

Google tethering Antigravity is a milestone worth marking, because it settles the argument. Ungoverned agentic AI is untenable, and now even the people selling the agents say so out loud. The open question is only who holds the tether. The vendor, or you.

We think the answer is obvious, and we think it’s a solvable, medium-sized project rather than a moonshot. Most of the firms we work with get a real inventory, a written policy, and enforcement mapping in place within a quarter.

So here’s what I’m curious about. If an auditor walked in tomorrow and asked you to list every AI agent with write access to something that matters in your business, how long would that list take to produce, and who in your org would have to produce it? Tell me honestly. The answers I’ve heard so far range from “ten minutes” to “we’d have to send an all-staff email,” and the gap between those two companies is the entire story.