Welcome, welcome, welcome to Google IO 2026. This is the dialogue stage. My name is Matt Berman. I'm the CEO of Ford Future. And today I am super excited to share a conversation with the man who has been leading Google for the last 10 years. Please help me welcome Sundar Pichai.
Well, thanks for joining me. A real pleasure to be here. Congratulations on all the announcements, of course. I kind of want to dive right into it. I actually recently found out that you're the first PM of Google Chrome.
Oh. Uh, yes. Yeah. You have a unique insight and probably very strong opinions about the future of the internet. And so that's where I want to start. It seems like the internet is being transformed right before our eyes. Agents are being built. They're infiltrating the internet. And I'm wondering, do you see the future as agents being the entry point to the internet for most people?
First of all, great to be here. Thanks for doing it Matt and love your show. I love your content and I appreciate all of you joining as well. Look, I do think agents are going to be a fundamental part of how we work because having used them, if you're living, maybe today the people who are on the frontier of how agents work are developers, right? And particularly with coding, two years ago most developers started using these tools. They started giving them more and more autocompletions and you were accepting them, etc. But over the last few months, developers are actually doing agentic workflows, right? The developers on the frontier and they are actually deploying agents, orchestrating agents. You saw the demo in anti-gravity for building an OS, you are effectively in an agentic workflow. So I think once you get the taste of using something like that and the superpower that comes with it, I think they're genuinely adding value in a way I think people will use them. I think it's important we build it in a way that users feel a sense of control and agency and transparency when they use agents. I think that's an important foundation. But I think yes, I do expect agents to be a core part of how we use the web, but that doesn't mean it'll take away from people use the web for a lot of reasons, right? You're entertaining yourself, you're trying to do something meaningful at times and it depends on if you're shopping what you're shopping for, if it's your weekly groceries versus you're trying to buy your loved one a gift, right? And so I think it'll allow humans to use the internet in ways that gives them joy and purpose and not always be forced to deal with I have to fill these 18 form fields to renew a DMV license, right? So that's how agents will separate it out, I think.
Yeah. I mean, I'm particularly excited to have agents actually do real world tasks. You mentioned the DMV, that use case is incredible. But I also think about putting so much trust into agents to really be the arbiter of our information diet and I'm wondering how do we make sure that we are putting the trust in the right agents and the agents are deciding correctly what information that we should have.
We are already doing a version of that. I don't know, like if you use Gmail and there's a spam filter working on your behalf filtering spam, like in some ways you're trusting an agent. It is an agent, right? Not the way we think of agents today. So I think we've always, I look at it as working on Waymo. You have to make people trust sitting on the backseat of a Waymo and let the car go. That is an agent in some ways. But people are willing to trust. But that's because we've done the work over time to demonstrate to people both with data with how we have operated it that it's fundamentally safe and it's freeing you up to enjoy the ride. And so I think it all depends on the value you deliver, right? And I think that's why building the agency and trust with users is a shared journey and we have to get that part right. Part of the reason in Gemini Spark, Gemini Spark is actually very powerful under the hood but we are taking the deliberate careful step of making it work with your first party services like Gmail, calendar etc. before we expose third party with MCP and full computer use and browser use. It can do all that but we want to make sure users are in control and they feel comfortable, we're getting their feedback improving the product as we give those capabilities.
You know Sundar, if I'm crossing the street you mentioned Waymo, I actually trust walking in front of a Waymo more so than I trust walking in front of a human driver. I don't know if other people agree with that, but there was almost an immediate trust that I had for Waymo, so I'm hoping agents are the same way. I'm old enough to remember the early days of the internet, which was an absolute wild west, but you got to raw information very quickly. And I think, part of something I'm concerned about is that we're increasing the buffer between us and the raw internet. We saw it, a little bit with the browser, a little bit with apps, and now more so with agents. How do we account for that?
I think, look, people in our experience with search and YouTube, YouTube is a great example, right? People have this sense of connection with the creators they like and follow, right? And so that's a big part of what they're looking for. So I think people are in different mindsets. I mean there are times they want to discover content on the web like shopping is delightful for a lot of people in a lot of moments, right? And so they're not trying to fully outsource that, right? That's why I try to distinguish between what feels like something which may be a chore at times and what feels like something which is delightful. Similarly, it could be in news, it could be people have their trusted sources at least at Google through search and YouTube and through agents. We think there will always be an incredible value from the ecosystem which users want to connect to and the agents should be in the job of doing that. Yeah. But you are right. There are times the agents are playing a role in the middle. Sometimes it's very good because it helps improve user satisfaction because users are getting to what they want in a better way, but there's a layer of abstraction too and that's what you're talking about. But I think it's always been true with technology a bit. But I don't think ultimately, it's also at the same time the tools with which you can create content are also exploding. So people will also be creating more content. So I think there'll be a new balance which we will find. But yeah, it is an interesting moment of evolution.
Yeah, I like that. But I think you're saying there's definitely going to be a strong place for agents to do that curation on our behalf, especially in the era of complete slop domination.
But also, that feeling of exploration can still be there.
Because it's a fundamental human need that doesn't go away.
Yeah. Exactly. Okay. So speaking of the wild west and I know you're probably feeling this pretty strongly at Google, there have been increasing cyber security cyber attacks, the models are getting better at cyber. Obviously Google has been thinking about cyber security for decades. Are you seeing cyber attacks especially AI enhanced cyber attacks ramp up at Google?
Look, we've been seeing, to be very clear, we've deeply cared about cyber because we've been working on frontier technologies for a while. Google pioneered many important security frontiers like zero trust and so on. We have worked hard to keep the company at the frontier and also we operate many products and platforms around the world that touch billions of people. We've been pretty aggressive in deploying agentic workflows. Our internal security teams use agentic workflows to help detect vulnerabilities and then how do you work to patch them? And we have steadily seen over the last two years as the model capabilities have progressed, we are able to detect more vulnerabilities and we've been working very hard to patch them. I think Mythos was a point of inflection of capturing that moment in time. They put out a model which was really well built for that particular task and it was frontier there, right? But what we are excited about it is part of the reason we are sharing maybe one of the undermentioned announcements today at IO is Code Mender. So, Code Mender is a product which we use internally and which you're building to share externally. It not only helps you identify the vulnerabilities, generate patches, test and verify that they work and deploy them and it's running 24/7. That's right. And real time we completed our recent acquisition of Wiz, so Wiz is state-of-the-art in being able to do this realtime monitoring of vulnerabilities etc. So I think combination of what we have with Wiz and Code Mender, I think we are using it internally to stay at the frontier and I think it's an important moment for the industry. I have to say I'm heartened by the cross industry collaboration going on in this moment. I think one of the examples I would call out today be it SynthID or watermarking companies coming together, companies coming together around cyber that is so important for this industry with this technology, right? So I'm encouraged by those trends as well.
So you mentioned Mythos so I want to talk about that for a moment. Obviously Anthropic decided not to release Mythos publicly. Just a handful of companies, we have OpenAI releasing GPT 5.5 Cyber. Which approach do you think is more appropriate? Which is right for Google? Is there some model that is just too good and you're going to hold it back or is the more iterative deployment strategy that OpenAI takes more aligned with what Google believes?
Look, I think it depends on where you feel it depends on the model capability. If it is not fundamentally changing what's out there already in terms of the state-of-the-art, I think it's definitely okay to put it out. But in the security world, there's a well-established practice. Google has done Project Zero for a long time, right? And we have teams of people who find vulnerabilities, then we notify the vendor give them 90 days to patch it before we acknowledge the vulnerability in the wild. And so there are well-established practices in the security industry around how to do it. So I think it makes sense to me if you suddenly have something which dramatically changes the frontier. First of all, I think it's important to work closely with the government on that and you approach it in a responsible way. So I think that is consistent with how the security industry works and but I do think it's important to also make sure enough people get access to it so they can patch their systems and so on and they go hand in hand. So I think there's validity to that approach.
So is there some threshold by which you would say past that point we can't release it or is it more let's look at what the landscape of model capabilities are, let's look at how cyber is right now and let's make the determination on a model per model basis.
Yeah that's what I would say like is the next one you're introducing does it dramatically change the frontier? Is it a 1 to 2% improvement over the current state-of-the-art or are you taking these 20% jumps? That's where the judgment comes in and I think that's how I would change my approach.
So on the topic of model strategy, something near and dear to my heart is open source. Basically Google and Nvidia are the only companies with a real open source model strategy nowadays. Google's model is smaller, meant to run on edge devices. Why not release a large open-source frontier model?
Look, first of all, Google, we've been big fans of open source. Google was built on a lot of open source systems. We have worked on many big things which are open source. I mean I personally worked on Chromium and Android and so on, Kubernetes and I can name many projects which Google has contributed pretty strongly to the world in open source. In AI, we've been building Gemma models and we've been updating them year after year, right? And they're awesome and I think the recent release of Gemma 4 was a great release and so we are pushing it. I think all of us are trying to make sure the frontier takes a lot of investment to get the frontier done right, you've seen our capex dollars right? And so you're putting a lot of R&D dollars to generate those incremental frontier models. So I think and you're discovering new techniques as part of doing those models so we all have to be mindful of that but I think we are also committed to making sure there's an open source ecosystem which is able to develop and so we take a balanced approach there and I think we'll continue to take that balanced approach, that's how I see it.
Yeah and by the way I do love the Gemma models I run them locally at home they are fantastic so definitely thank you. Obviously a company of the size and the resources of Google if you're making that decision of okay large closed source large open source we can't do both, probably most startups in the US also will struggle with that decision. Like what is your sense of the business model for open-source in America? Is it viable right now?
Look, first of all, we not only do open source, part of the reason we invest so much in Flash Lite and Flash models is so that we are giving a range of options, right? And those models are workhorses too to support. But to your question on open source, it's not that we don't, we've been moving the open source frontier too. There's a lot of very good open source models like particularly from China which startups are adopting too.
Yeah, we're going to talk about that.