Advent of Agents Season 3
Building an AI agent is the easy part now. Trusting it with your company’s data, credentials, and credit card? That’s where things get interesting.
That’s exactly the problem Google Cloud is tackling this month with Advent of Agents Season 3, a free, 31-day tutorial series running through October 2026. Here’s what it is, why it matters, and how to get the most out of it.
Table of contents
- First, a 30-second primer: what’s an AI agent?
- What is Advent of Agents?
- Why governance? Why now?
- How it works
- Who should follow along?
- The bottom line
First, a 30-second primer: what’s an AI agent?
A regular chatbot answers questions. An AI agent goes further: it does things. It can search the web, query a database, call an API, write and run code, or send an email, all on its own, in pursuit of a goal you gave it.
Think of the difference between asking a friend for directions and handing them your car keys. The agent is the friend with the keys.
What is Advent of Agents?
The name borrows from Advent of Code, the much-loved December puzzle tradition where programmers solve one challenge a day. Google Cloud applied the same “one bite a day” format to AI agents.
- Season 1 (December 2025) ran for 25 days and took developers from zero to a production-ready agent. Each lesson was designed to be tried in under five minutes, using tools like Gemini, the Agent Development Kit (ADK), and Agent Engine. One early lesson even had people building an agent with no code at all, just a config file.
- Season 2 continued the building-focused track.
- Season 3 (October 2026) changes the subject entirely.
The first two seasons were about building agents. Season 3 is about governing them.
Why governance? Why now?
Because once an agent can take actions, a whole new category of things can go wrong:
- It can be tricked. A malicious instruction hidden in a web page or document (known as prompt injection) can hijack what the agent does next.
- It can leak data. An agent with access to customer records might happily paste them somewhere they shouldn’t go.
- It can overreach. If it has admin-level permissions “just to make things easier,” a single mistake can have a huge blast radius.
- It can quietly burn money. An agent stuck in a retry loop at 3 a.m. doesn’t send you a warning. It sends you a bill.
- Nobody knows who did what. When ten agents are running across a company, tracing a bad action back to its source gets hard fast.
None of these are hypothetical. They’re the questions security teams ask before they’ll let an agent anywhere near production. Season 3 is built around answering them.
How it works
Every day in October, a new tutorial drops at adventofagents.com. Each one follows a simple pattern:
- Start with a real question. Something an actual customer, developer, or security reviewer has asked.
- Answer it with a working demo. Not slides. Runnable code you can reproduce yourself.
The 31 days are grouped into four themes:
| Theme | What it covers, in plain English |
|---|---|
| Foundations | The lifecycle every agent goes through, the ways it can be attacked, and a blueprint for deploying agents in a large organization. |
| Identity & access | Giving each agent its own verifiable identity, letting it act on behalf of a logged-in user, and granting it only the permissions it truly needs. |
| Runtime guardrails | Blocking prompt injection, stopping data leaks, running agent-generated code in a locked-down sandbox, and keeping agents’ memories separate. |
| Fleet & operations | Managing many agents at once: a central registry, rules for which tools they can use, spotting weird behavior, emergency “kill switches,” and cost limits. |
A taste of the first few days
- Day 1 maps out the five stages an agent moves through, from defining its scope to optimizing it, and walks one agent through the whole loop in about five minutes.
- Day 2 uses Google’s Secure AI Framework (SAIF) to model threats like rogue actions and accidental data disclosure.
- Day 3 shows how to move from a single-agent prototype to a hardened, multi-agent setup on Google Cloud.
- Day 4 gives you a 15-question Python self-assessment that scores your organization across five governance layers and turns the result into a 90-day roadmap.
Who should follow along?
- Developers who’ve built an agent demo and are now being asked, “Is this safe to ship?”
- Security and platform teams who need concrete patterns, not vague principles, for approving agent deployments.
- Tech leads and architects planning how dozens of agents will coexist without chaos.
- Curious newcomers. If you’re brand new, start with the Season 1 and Season 2 archives on the same site to learn the basics, then come back for the governance layer.
The bottom line
The AI conversation has shifted from “Can we build an agent?” to “Can we trust one?” Advent of Agents Season 3 is a practical, bite-sized way to learn the answer, one question and one working demo at a time.
It’s free, it’s hands-on, and it’s already underway. Bookmark adventofagents.com and catch up on the days you’ve missed.