2026-06-24 · Google

Introducing computer use in Gemini 3.5 Flash

securityagentsmodelsenterpriseresearch

read at source ↗ deepmind.google

Introducing computer use in Gemini 3.5 Flash

Source: DeepMind Date: 2026-06-24 URL: https://deepmind.google/blog/introducing-computer-use-in-gemini-3-5-flash/

Summary

Google introduced computer use as a native tool in Gemini 3.5 Flash, enabling AI agents to perceive and act across browser, mobile, and desktop environments. The capability is accessible via the Gemini API with a reference implementation on GitHub, and through the Gemini Enterprise Agent Platform for production deployments. The announcement emphasizes adversarial training to reduce prompt injection risk, plus enterprise safeguards including explicit user confirmation gates for sensitive actions and automatic task stoppage when indirect prompt injection is detected. Benchmark results on OSWorld show substantial improvement over previous computer-use models.

Implications

  • Computer-use/agentic capability. Gemini 3.5 Flash entering the computer-use space matters because it’s a cost-tier model — Flash pricing sits well below Opus or Claude 3.7 Sonnet. Accessible computer-use at lower cost per token lowers the threshold for building agentic products that interact with arbitrary UIs, which is a different market than frontier-model deployments.
  • Security and trust surface. The explicit call-out of prompt injection defenses — adversarial training plus in-flight detection and task stoppage — signals that Google is treating this as a known failure mode requiring layered mitigations rather than hoping models generalize to safe behavior. That framing should set expectations for the rest of the field.
  • Enterprise targeting. The Enterprise Agent Platform pathway, combined with the OSWorld benchmark framing (software testing, knowledge work across professional apps), signals this is positioned for IT automation and business-process use cases rather than personal assistant scenarios. Watch how this interacts with Microsoft’s Copilot computer-use work and Anthropic’s computer-use in Claude — the enterprise automation market has room for multiple providers, but convergence on shared evaluation benchmarks (OSWorld, WindowsAgentArena) will start producing clearer head-to-head comparisons.

← all signals