Gemini Enterprise: industry agents require business governance
On 25 August, Google Cloud introduced Gemini Enterprise for Legal and Gemini Enterprise for Financial Services. Beyond the product launch, the useful signal for companies is clear: industry AI agents become production-ready only when sources, permissions, citations, actions, and production controls are designed as a complete business architecture.
1. What Google Cloud announced
For legal work, Google describes a governed environment with specialized skills, connections to document management systems, agents able to act within matters, and a control dashboard for IT, risk, and compliance teams. Examples include contract review, regulatory horizon scanning, DSAR responses, contracting playbooks, legal research, and document drafting.
For financial services, Google applies the same logic to capital markets and corporate banking: financial skills, MCP connectors to licensed data and internal systems, and a Financial Research agent with citations, confidence scores, explicit methodologies, and data snapshots for audit. The announced integrations also touch Workspace, Microsoft 365, market data, regulatory sources, and specialist partners.
2. What changes for a Belgian or French company
For an SME or mid-market company, the change is not to buy a general agent and open every document to it. Teams should first select a precise process, such as supplier contract review, commercial dossier preparation, compliance checks, or customer request handling, then verify which sources are authorized, which actions may be suggested, and which actions must remain under human approval.
For a large enterprise, bank, insurer, law firm, or public administration, the challenge is more structural. Agents must respect existing permissions, ethical walls, data licenses, GDPR, the AI Act, evidence retention, and the separation between recommendation and decision. IT and business leaders therefore need an operating model: who owns the agent, who approves its skills, who controls connectors, who handles errors, and which audit trails are available.
3. Underside analysis: the industry agent is an integration, not just a model
Underside's analysis is that these announcements confirm a shift: enterprise AI value is moving from the model alone to governed integration. MCP connectors, RAG indexes, citations, inherited permissions, logs, and human control become as important as LLM performance. An agent that drafts a memo, extracts clauses, or analyzes a portfolio must be able to explain which sources were used and why an action was proposed.
The same logic applies to Odoo, Apple Enterprise, CRM, document management, and back-office environments. An Odoo invoicing, purchasing, inventory, or support workflow may benefit from an agent, but only if consulted fields, allowed writes, approvals, and evidence are framed. Sovereignty is not guaranteed by the platform name: it depends on processing location, permissions, data sent, reversibility, and the ability to operate or isolate the system.
4. Practical architecture for agents, RAG, and regulated work
A robust project separates four layers. The data layer qualifies sources, licenses, confidentiality, and residency. The RAG or retrieval layer measures result quality and preserves references. The agent layer limits tools, service identities, timeouts, and actions. The governance layer defines human approval, logging, cyber supervision, budget, and degraded mode.
For Belgian and French teams, this approach avoids two common mistakes: letting a general agent cross complex permission boundaries, or freezing a local architecture too early without covering business integration needs. The right arbitration may be hybrid: sensitive data and indexes under stronger control, a remote model for some use cases, a local model for others, and connectors restricted to necessary actions.
5. Operational priority
Before industrialization, each agent should have an operating sheet: purpose, user populations, authorized sources, inherited permissions, MCP tools, forbidden actions, citation requirements, approval thresholds, retention policy, forecast cost, business owner, IT owner, and stop procedure.
Recommendation: select one regulated process and build a complete architecture proof before scaling: permissions, RAG, connectors, logs, human approval, cybersecurity, budget, and local, cloud, or hybrid deployment choice.
Frame a business agent