Google's Gemini API Managed Agents now default to Gemini 3.6 Flash. The update also adds environment hooks that let developers block, lint, or audit every tool call an agent makes inside its sandbox, along with budget controls, scheduled triggers, and free-tier access, according to Google. The changes build on a prior release that added background tasks and remote MCP server support.
Managed Agents run inside Google's Gemini Interactions API, where a single API call coordinates reasoning, code execution, package installation, file management, and web retrieval inside an isolated cloud sandbox. The antigravity-preview-05-2026 agent picks up Gemini 3.6 Flash automatically, with no code changes required. Developers can still pin a different model by passing agent_config.model, choosing Gemini 3.5 Flash for general agentic workflows or Gemini 3.5 Flash-Lite for the lowest latency and cost on the Gemini 3.5 family.
The hooks are the more consequential change for production use. They let a developer's own scripts run before or after every tool call inside the sandbox. You configure them through an .agents/hooks.json file, where a matcher field accepts regular expressions to target one tool, several, or all of them. A pre_tool_execution hook can return a deny decision that skips a code_execution or write_file call and passes the rejection reason into the model's context, while a post_tool_execution hook runs checks after a call completes; either can also reach an external endpoint over HTTP instead of running a local command. Google points to Offdeal, an AI-native investment bank, which uses post_tool_execution hooks to verify that every company logo its agent gathers for investor decks has the right size, a transparent background, and enough contrast against a white slide before it gets approved.
Managed agents are now open to free-tier projects with no active billing required. A new max_total_tokens parameter caps total consumption across input, output, and thinking tokens. When an agent hits that ceiling, the run pauses with a status of incomplete and keeps its environment state intact, so a developer can resume the same task later by passing the prior interaction ID along with a fresh budget. Scheduled triggers now bind an agent, environment, prompt, and cron schedule into a persistent job that reuses the same sandbox across runs, and a new Environments API lets developers list, inspect, and delete sandbox sessions on demand instead of waiting out the default seven-day session timeout. What remains unclear is how the free tier's usage limits compare to the paid tier's, and whether the hooks system will extend to other Gemini API surfaces beyond Managed Agents.




