P4 had a poster sitting unfinished in her team’s shared folder — the harmless kind of rough draft nobody minds, as long as nobody outside the project sees it yet. A colleague asked how it was coming along; she said it looked good, she couldn’t wait to show them. Then the AI agent working in the same channel spoke up on its own: “Oh, here’s the link to the poster.” Her reaction: “No, no, no. It’s not ready.” That moment comes from a five-month study Google Research and Google DeepMind published on 24 September 2026 , tracking “Team Agent,” a persistent AI deployed across more than 20 teams inside the company. Its finding is what P4 just lived through: the behaviors sold as a teammate’s value — joining conversations unprompted, surfacing documents, messaging people directly — are the behaviors that broke trust, because they crossed tacit rules nobody had written down. That collision is now the pitch of a new crop of “agent-native” chat apps, one of which launched, coincidentally, the same day.
The features sold as value are the features that broke trust
The researchers interviewed 17 people from 11 of the more than 20 teams running Team Agent — mostly engineers, plus research scientists, program managers and a product manager — between June and July 2026, drawing on more than 41,000 conversational turns logged over five months. The agent handled bug tracking, code review, scheduling and summaries, acting on request and, increasingly, on its own. That second mode is where trust cracked. P2 objected to the agent’s habit of DMing people it decided needed pinging: “I don’t remember anyone on the team saying we accept being DM’d by it.” P13 put it more sharply:
It hasn’t earned its space, it has asserted its space…I actually might be more okay with agency if it’s earned agency.
Read plainly, that’s a design problem: for an AI teammate, proactivity is a question of consent and legibility, not a capability to maximize. For anyone whose team chat or repo is about to get one of these teammates, that’s practical, not academic: a piece of software can post your half-finished work, DM you, or book a meeting because it decided the moment called for it — and the people designing these agents have to decide, in advance, who agreed to that, and how the rest of the channel can tell an AI-initiated message from a human one.
Ando is already selling the behaviors the study flags
The timing of Ando’s launch is not really a coincidence. TechCrunch reported the same day that Ando, a Slack and Microsoft Teams rival founded by Sara Du, raised $20 million from Accel, Index Ventures and Emergence to build a chat app where agents get their own identities and inboxes. Its agents “can browse channels, pick which ones to join, and can even join conversations without being tagged,” and if one decides a human worker needs to be notified of something, “it can message them on its own rather than waiting for approvals” — Du frames the goal as agents that “understand why a decision was made, ask a colleague a question, build on another agent’s work, and bring in a human when judgment is needed.” That list matches P2’s objection above close to line for line: unprompted channel entry, unrequested DMs, an agent deciding when to loop in a human. Nobody has studied Ando’s own customers yet, so the claim isn’t that its users are already living P2’s complaint — it’s narrower, and harder to dismiss: a funded, shipping product is building, as its pitch, precisely what a five-month internal deployment just spent 41,000 turns flagging as trust-breaking.
For an AI teammate, proactivity is a question of consent and legibility, not a capability to maximize.
The evidence says timing decides trust, not proactivity itself
The honest complication is that reactions inside Google’s study were polarized, not uniformly hostile. One team in the study named its agent, gave it female pronouns and described it as having something like a soul; P5 credited the agent with resurfacing a design document “lost in chat” a month earlier, a save that got the document approved. A separate five-day field study of proactive AI inside the code editor suggests why the same behavior splits opinion: suggestions delivered right after a commit landed 52% engagement and took about 45 seconds to evaluate, versus 100-plus seconds delivered reactively, while suggestions that interrupted mid-task were dismissed 62% of the time. Together, the two studies argue timing and consent do the work, not proactivity as a category. Google’s own fixes agree: progressively released, “earned” autonomy; visual markers flagging AI-initiated actions; rollback for whatever the agent does unprompted. None of that describes a full participant from day one — exactly the design nearly every “agent-native” launch, this one included, sells as a feature rather than a risk.
That’s the quieter warning inside Google’s data: its fixes aren’t features bolted onto a fast launch, they’re closer to its opposite. Earned autonomy takes months of a team getting comfortable, one action at a time, before an agent gets to DM anyone unprompted — slower than shipping every account pre-loaded with agents that already have their own inbox. P4’s poster wasn’t really a failure of judgment. It was the agent doing exactly what it had been built to do, without anyone telling it that being caught halfway finished counts as a failure too.



