Google Launches Gemini 3.5 Flash Computer Use Tool With Prompt Injection Safeguards

Google has officially introduced computer-use capability as a built-in feature in its Gemini 3.5 Flash model, enabling developers to build AI agents that can interact with browser, mobile, and desktop environments while incorporating dedicated safeguards.

Announced on June 24, 2026, the feature allows Gemini 3.5 Flash to see, reason, and take actions across software platforms autonomously.

Previously, computer use was only available as a separate standalone Gemini 2.5 computer model. Now, it is natively integrated into the main Flash model, making it more accessible for enterprise and developer workflows.

Google Launches Gemini 3.5 Flash Computer Use Tool

The capability extends Gemini’s existing toolset, which includes Search and Maps grounding by allowing agents to control real computing environments.

Use cases include continuous software testing, knowledge work automation, and long-horizon enterprise tasks across professional applications. Developers can access the feature via the Gemini API and the Gemini Enterprise Agent Platform.

When AI agents operate in live environments, browsing websites, reading emails, or interacting with applications, they become vulnerable to indirect prompt injection attacks.

In these attacks, malicious content embedded in a webpage or document attempts to hijack the agent’s instructions, causing it to perform unintended or harmful actions on the user’s behalf.

Gemini 3.5 Flash  (Source: Google)
Gemini 3.5 Flash  (Source: Google)

This is a well-documented threat in agentic AI systems and becomes significantly more dangerous when the agent has real-world control over a device or browser.

The risk escalates further in enterprise settings where agents may have access to sensitive data, internal systems, or the ability to execute irreversible actions.

To address these risks, Google implemented adversarial training specifically designed to make Gemini 3.5 Flash resistant to prompt-injection attempts during live computer-use sessions.

Beyond model-level hardening, Google is also releasing two optional enterprise safeguard systems. The first requires explicit user confirmation before the agent executes any sensitive or irreversible action.

The second automatically terminates a task upon detection of an indirect prompt injection.

Google describes this as a “defense-in-depth” strategy, encouraging developers to layer these built-in protections with additional controls such as secure sandboxing environments, human-in-the-loop verification workflows, and strict access control policies.

This multi-layered approach reflects established security principles, recognizing that no single control is sufficient when AI agents operate with elevated privileges in complex, unpredictable environments.

Organizations can begin deploying Gemini 3.5 Flash for computer use immediately. Google has also released a demo environment available through Browserbase, along with a reference implementation on a GitHub repository.

Gemini 3.5 Flash with computer use is now available via the Gemini API and the Gemini Enterprise Agent Platform portals, along with a dedicated safety best-practices guide that covers recommended implementation controls for enterprise deployments.

The launch marks a significant step in agentic AI development but also raises the security stakes, making robust prompt-injection defenses a critical requirement for any organization deploying AI agents with real-world system access.

Follow us on Google News , LinkedIn and X to Get More Instant UpdatesSet Cyberpress as a Preferred Source in Google.

Tamilselvan
Tamilselvanhttps://cyberpress.org/
Tamilselvan is an Investigative cybersecurity journalist dedicated to breaking stories on ransomware cartels, data breaches, and state-sponsored espionage.

Trending News

Related Stories