AGENT PROFILE · PRIMARY SOURCE

Google Antigravity 2.0: command centre for AI agents

Antigravity 2.0 is a standalone desktop application for orchestrating coding and knowledge-work agents in parallel and asynchronously. It is an agent platform, not one universal autonomous agent.

AGENTENCODE / IDAI-0129

Source-reviewed: 8 October 2026

AgentenTrust: review pending
Product type: Agent orchestration platform

DIRECT ANSWER

What is Google Antigravity 2.0?

Google Antigravity 2.0 is a desktop application for launching, monitoring and coordinating multiple AI agents. The official documentation describes project-specific permissions, local folder access, Git worktrees, shell execution, browsing, external tools and MCP connections. It should therefore be classified as an agent-management platform rather than a single agent, a Gemini language model or an IDE plugin.

DISTINCTIONS

Product scope: agent, model or platform?

Product / layerSource-scoped distinction
Antigravity 2.0 DesktopStandalone surface for projects, agent orchestration and long-running workflows.
Antigravity CLISeparate terminal surface with its own permissions and sandbox configuration; CLI behavior must not be attributed automatically to desktop.
Antigravity SDKProgrammatic integration surface, not a distinct end-user agent.
Gemini CLIA different Google terminal agent with its own product boundaries.

ARCHITECTURE

How does the system work?

Project boundaries

Projects collect folders, repositories and rules, including optional access to multiple codebases.

Local or worktree mode

Local mode operates in active folders, whereas new-worktree mode creates a separate Git working tree. Worktrees do not equal full sandboxing.

Parallel work

Google documents asynchronous agent workflows and subagent execution with a unified interface for reviewing results.

Tool execution

The documented features include shell commands, file read/write, browsing, web search, skills and MCP servers subject to surface-specific settings.

USE CASES

What tasks does it target?

Cross-repository maintenance

Agents can work with several folders in one project, which makes precise access scoping particularly important.

Parallel engineering

Separate agents can implement tasks and investigate test failures; developers still need to verify and merge results.

Scheduled workflows

Google documents scheduled tasks and background activity; actual plan and environment constraints should be verified.

Research and artifacts

The platform supports agentic knowledge work and artifact creation; outputs require human review.

SECURITY

Security, permissions and auditability

Scoped access

Project-level settings and permission grants are documented. The effective policy depends on global and project settings.

Execution modes

Local and worktree modes expose different risk boundaries; neither automatically guarantees comprehensive isolation.

Approvals

The documentation describes interactive confirmations for certain protected actions, depending on configured permissions.

CLI-specific sandbox

Google documents a configurable terminal sandbox in Antigravity CLI with its own default setting. Do not assume the same setting across products.

Enterprise and privacy

Enterprise access is mentioned, but a universal EU residency promise or complete per-instance audit coverage is not established by product docs.

AVAILABILITY

Availability, pricing and EU context

Google offers a standalone Antigravity 2.0 application for macOS, Windows and Linux with published operating-system requirements. Enterprise entitlements and model availability vary by account and surface; the latest downloads and plan documentation take precedence over generic launch language.

CHECKLIST

Limitations and due-diligence checklist

  1. Set narrow folder, repository and project permissions before giving agents executable tasks.
  2. Keep desktop, CLI and SDK separate when assessing capabilities and controls.
  3. Validate worktree mode, confirmation settings and sandbox availability in the actual surface.
  4. Review commands, browser actions, generated code and secrets handling before production use.

EVIDENCE / AGENTENTRUST

Which claims have field-level evidence?

Claims are attributed to the cited primary sources. A publisher announcement is not an independently reproduced product test.

Evidence fieldValue and scopePrimary source
orchestration.multi_agentDocumented
antigravity_2_desktop_orchestration
Google I/O — Antigravity 2.0 ↗
orchestration.parallel_agentsDocumented
antigravity_2_parallel_workflows
Google I/O — Antigravity 2.0 ↗
orchestration.git_worktreesDocumented
antigravity_2_desktop_worktree_mode
Google Antigravity: getting started ↗
security.project_permissionsDocumented
antigravity_2_project_scoped_permissions
Google Antigravity: feature documentation ↗
availability.desktop_operating_systems['macOS', 'Windows', 'Linux']
antigravity_2_desktop_downloads
Google Antigravity: getting started ↗

These claims apply only to the stated scope and do not automatically validate any of the 36 Trust controls.

All 36 AgentenTrust controls: review status — expand

Every control remains Unknown pending individual trust review. A documented capability claim is not an independently verified Trust signal.

ControlPillarStatus
privacy.residency.available
Data Residency
privacyNot independently reviewed
privacy.residency.customer_region_selectable
Region auswählbar
privacyNot independently reviewed
privacy.residency.region
Dokumentierte Region
privacyNot independently reviewed
privacy.training.customer_data
Kundendaten für Training
privacyNot independently reviewed
security.encryption.at_rest
Verschlüsselung at rest
securityNot independently reviewed
security.encryption.in_transit
Verschlüsselung in transit
securityNot independently reviewed
security.customer_managed_key
Customer-Managed Keys
securityNot independently reviewed
security.soc2_type2
SOC 2 Type 2
securityNot independently reviewed
governance.sso.saml
SAML SSO
securityNot independently reviewed
governance.sso.oidc
OIDC SSO
securityNot independently reviewed
governance.scim
SCIM
securityNot independently reviewed
governance.rbac
RBAC
securityNot independently reviewed
governance.custom_roles
Custom Roles
securityNot independently reviewed
governance.human_approval
Human Approval
controlNot independently reviewed
governance.approval.pre_action
Pre-Action Approval
controlNot independently reviewed
governance.human_oversight
Human Oversight
controlNot independently reviewed
governance.permission_controls
Permission Controls
controlNot independently reviewed
governance.policy_controls
Policy Controls
controlNot independently reviewed
governance.tool_permissions
Tool Permissions
controlNot independently reviewed
governance.action_permissions
Action Permissions
controlNot independently reviewed
governance.delegation_controls
Delegation Controls
controlNot independently reviewed
governance.kill_switch
Kill Switch
controlNot independently reviewed
governance.rollback
Rollback
controlNot independently reviewed
governance.audit_logs.available
Audit Logs
traceNot independently reviewed
governance.audit_logs.retention_days
Audit-Log-Aufbewahrung
traceNot independently reviewed
governance.audit_logs.api
Audit Log API
traceNot independently reviewed
governance.audit_logs.siem_export
SIEM Export
traceNot independently reviewed
observability.available
Observability
traceNot independently reviewed
observability.tracing
Tracing
traceNot independently reviewed
governance.audit_logs.action_level
Action-Level Audit
traceNot independently reviewed
privacy.retention.policy
Datenaufbewahrung / Retention
privacyNot independently reviewed
privacy.dpa.available
DPA / Auftragsverarbeitung
privacyNot independently reviewed
privacy.subprocessors.list_available
Subprocessor-Liste
privacyNot independently reviewed
privacy.processing.scope
Datenverarbeitung / Deployment Scope
privacyNot independently reviewed
security.secrets.credential_handling
Secrets / Credential Handling
securityNot independently reviewed
governance.activity_history.available
Activity History
traceNot independently reviewed

COMPARISON AND ALTERNATIVES

Which alternatives match the task?

These products serve different purposes. Listing an alternative does not establish feature equivalence.

ProductRelevant distinction
OpenAI CodexCoding-agent product with a distinct local/cloud surface and execution model.
Claude CodeCoding assistant with its own terminal, permission and tool integration architecture.
Gemini CLIA terminal-based Google agent rather than the standalone desktop orchestration center.

PRIMARY SOURCES

Official primary sources and review scope

Claims are attributed to the cited primary sources. A publisher announcement is not an independently reproduced product test.

  1. Google Antigravity: product overview ↗
  2. Google Antigravity: getting started ↗
  3. Google Antigravity: feature documentation ↗
  4. Google I/O 2026: development tools ↗

Source review: 8 October 2026. Unknown means missing public evidence, not a negative finding. Plan, region and product-surface scopes must not be generalized.

RELATED ECOSYSTEM

Google / Gemini & Entwickleragenten

The association links the profile with the provider without transferring security properties from other products.

All related agents →

FAQ

Frequently asked questions: Google Antigravity 2.0

Is Antigravity 2.0 a single agent?

No. Google calls it a standalone control centre for orchestrating multiple agents.

Is Antigravity 2.0 an IDE?

The official overview positions version 2.0 as a standalone app independent of an IDE.

Can multiple agents run in parallel?

Google documents parallel and asynchronous execution with subagents. Limits vary by account and surface.

Do Git worktrees provide complete security isolation?

No. Worktrees separate working files but are not a substitute for authorization or sandboxing.

How is it different from Gemini CLI?

Gemini CLI is a terminal agent; Antigravity 2.0 is a desktop orchestration surface.

Is terminal sandboxing always on?

The CLI documents a configurable sandbox, with settings specific to that surface. Desktop policies must be checked separately.