Login / Register ID | EN
This page has no official English version. It was translated automatically and may contain errors. Read the original in Indonesian →
Agen yang Bekerja 24 Jam: Yang Menentukan Bukan Kecanggihan, tapi Izin yang Diberikan
Foto: Pexels
Cyber Security AI

Agents Working 24 Hours: What Matters Is Not Sophistication, but the License Granted

Google introduced Gemini Spark at the I/O 2026 event as a personal agent that operates continuously. Unlike assistants that only respond when opened, Spark works in the cloud and continues to perform tasks after the laptop is closed or the phone is locked, with connections to Gmail, Drive, Documents, and Calendar.

The shift is subtle but significant. Tools that are called upon only see what we paste into the conversation. An agent that is active all day needs persistent access, as it must be able to read something when no one is asking it questions.

Permissions That Don't Expire

When a task is completed, the results stop. Its permissions do not. Access granted for one purpose remains until revoked, and this is the part that is most often overlooked when people assess an agent solely based on its sophistication.

Google has placed safeguards on the action side. According to circulating reports, Spark is designed to request explicit confirmation before taking actions that have external impacts, such as sending documents to others or actions that incur costs. Such safeguards are useful, but they address a different question. Confirmation regulates what the agent is allowed to do. It does not regulate what the agent is allowed to read when it is idle.

These two aspects need to be treated separately. Most privacy concerns raised in Indonesian technology media regarding AI integration in email services actually center on reading scope, not on actions.

A Boundary Easily Overlooked: Personal Accounts and Office Data

The next issue is rarely felt until it's too late. Personal agents are set up with personal accounts, but the tasks requested are usually office work. Once directed to organize attachments from clients or summarize internal documents, company data moves to services that have never been reviewed by anyone in the office.

Hukumonline discusses this practice with the term shadow AI, which refers to the use of artificial intelligence tools without organizational consent and governance. The legal consequences do not stop at the individual level. Referring to the principle of employer liability in Article 1367 of the Civil Code, losses arising from employee negligence in using AI systems can become the company's burden.

Law Number 27 of 2022 concerning Personal Data Protection, which will be fully effective from October 2024, places several obligations on personal data controllers, including those related to the basis for processing and its security. Customer data that passes through a staff member's personal agent remains customer data, with obligations that do not transfer.

Four Things to Consider Before Activating It

What makes an agent safe to use is not secret settings, but rather boring habits.

Separate accounts. Agents that touch work should operate on a recorded work account, not a personal account.

Narrow the scope. If the service allows, grant access to specific labels or folders, not the entire inbox and all storage.

Review permissions regularly. The list of applications connected to the account tends to only grow. Setting aside time every few months to revoke those that are no longer used is more effective than guessing.

Agree on a list of prohibitions. Determine from the outset what types of data should not enter any agent, such as customer identity data, employment documents, and system credentials.

The Minister of Communication and Information Circular Number 9 of 2023 on Artificial Intelligence Ethics mentions oversight as a shared responsibility of providers and users. For agents that work without waiting, that oversight begins long before the first task is assigned, namely at the moment of deciding what they are allowed to see.

Sources