Google Cloud Introduces Remote MCP Server, Enabling AI Agents to Manage Cloud Infrastructure Through Natural Language

Facebook
X
WhatsApp
In brief
Key points
Table of Contents

Google Cloud’s new CLI remote Model Context Protocol (MCP) server, now in public preview, allows AI agents to execute cloud administration commands through a managed environment. The development signals a shift towards agent-operated cloud infrastructure, where autonomous systems can monitor services, manage resources, and support operational workflows while remaining subject to enterprise identity, security, and governance controls.

Google Cloud Introduces Remote MCP Server, Enabling AI Agents to Manage Cloud Infrastructure Through Natural Language

Google Cloud has introduced its Google Cloud CLI remote Model Context Protocol (MCP) server in public preview, extending the ability of artificial intelligence agents to interact with cloud infrastructure through natural-language instructions.

The new service enables MCP-compatible AI assistants and autonomous agents to execute Google Cloud CLI commands remotely, without requiring developers to install and maintain command-line tools within their own agent environments.

By providing access to established gcloud and bq command-line capabilities through a managed MCP interface, Google Cloud is introducing a broader operational framework for AI-powered infrastructure management.

The development reflects an emerging direction in enterprise technology: moving AI systems beyond information retrieval and content generation towards controlled interaction with the underlying infrastructure that supports modern digital businesses.

How Google’s Remote MCP Server Works

The Model Context Protocol is an open standard designed to connect AI applications with external tools, services, and data sources.

Google Cloud’s new implementation introduces a different approach to connecting AI agents with enterprise infrastructure.

Traditionally, developers building AI-powered cloud management systems have needed to integrate individual APIs for specific operations, such as creating virtual machines, configuring networks, retrieving logs, or managing databases.

Google’s remote MCP server instead exposes two primary tools:

  • run_gcloud_command: Enables agents to execute supported Google Cloud CLI commands for infrastructure and service management.
  • run_bq_command: Enables agents to execute supported BigQuery CLI commands for data platform administration and operational workflows.

These tools provide access to a broad range of existing command-line capabilities, subject to the service’s restrictions and the permissions assigned to the requesting identity.

For example, an authorised AI agent could receive a natural-language instruction to identify recent errors affecting a production virtual machine.

The agent could translate that instruction into an appropriate Google Cloud logging command, retrieve the relevant information, and present its findings to an engineer.

Similarly, agents could assist with BigQuery administration by inspecting jobs, managing reservations, scheduling queries, or cancelling long-running operations where appropriate permissions are available.

The underlying architecture follows a relatively straightforward sequence:

Natural-language instruction → AI agent → MCP server → Google Cloud CLI → Google Cloud APIs

This approach allows AI systems to interact with established operational interfaces rather than requiring every cloud function to be redesigned as a separate AI-specific tool.

Moving Cloud Operations Beyond Traditional AI Assistants

The introduction of the remote MCP server represents a potential development in how organisations manage increasingly complex cloud environments.

Most enterprise AI assistants have traditionally focused on answering questions, generating code, analysing information, or recommending operational actions.

Connecting AI agents to cloud management interfaces creates opportunities for more extensive operational workflows.

For example, an AI-powered site reliability engineering system could potentially identify a service disruption, retrieve logs, inspect recent deployments, examine configurations, recommend corrective action, and execute an approved remediation.

This process could reduce the manual coordination required across monitoring systems, administrative interfaces, and command-line environments.

However, the ability to perform such operations does not automatically make an AI system reliable or fully autonomous.

Organisations would still need to establish appropriate controls around decision-making, operational permissions, testing, and human approval, particularly for actions capable of affecting production infrastructure.

The broader significance is that AI agents could increasingly participate in the operational lifecycle of cloud systems rather than functioning exclusively as advisory interfaces.

Why Google Is Using Existing Cloud CLI Tools

One of the notable aspects of Google’s approach is its reliance on command-line interfaces already familiar to cloud engineers.

Google Cloud’s gcloud and bq tools have been developed to support established administrative workflows across infrastructure, networking, logging, resource management, and analytics.

By exposing supported commands through MCP, Google can make existing capabilities available to compatible AI systems without constructing a separate tool definition for every administrative function.

Command-line interfaces also provide an established layer of operational logic, including argument handling and command validation.

For AI developers, this approach could simplify integration with cloud services and reduce the need to maintain extensive collections of specialised tools.

Google’s managed execution environment also addresses practical deployment challenges.

Previously, an agent requiring CLI access would typically need the relevant software development kits, dependencies, and authentication configuration installed within its execution environment.

With the remote MCP service, commands run in a Google-managed, network-isolated environment.

This reduces the need for locally installed CLI software and may make cloud administration capabilities more accessible to hosted AI applications.

Security, Agent Identity, and Governance Remain Central

Giving AI agents the ability to execute cloud infrastructure commands introduces significant security and governance considerations.

An incorrectly generated command, excessive permissions, or a successful prompt-injection attack could potentially lead to unintended infrastructure changes or exposure of sensitive information.

Google Cloud’s implementation therefore relies on multiple layers of security.

Requests to the remote MCP server are authenticated, and downstream operations remain subject to Google Cloud Identity and Access Management (IAM) permissions and applicable organisation policies.

Importantly, permission to invoke the MCP tool does not automatically grant an agent unrestricted access to cloud resources.

An agent must also possess the underlying permissions required for the operation it attempts.

Google’s Agent Identity capabilities provide another potential security mechanism by allowing organisations to assign distinguishable identities and permissions to individual AI agents.

This can support more granular access management, helping organisations limit each agent to the resources and operations necessary for its assigned responsibilities.

Google also supports integration with Model Armor, an AI security capability designed to inspect interactions for risks including prompt injection, malicious content, and sensitive-information disclosure.

Additional audit logging can provide visibility into MCP interactions and authorisation events.

These mechanisms are important, although they do not eliminate operational risk. Organisations must still configure permissions, logging, security policies, and approval processes appropriately.

BigQuery Administration and the Evolution of Enterprise Data Operations

The remote MCP server also extends AI agent capabilities into BigQuery administration.

Google Cloud already provides a dedicated BigQuery MCP integration for data-related tasks, including SQL queries and metadata exploration.

The new CLI-based interface supports a different category of operational activity.

Through supported bq commands, appropriately authorised agents can assist with administrative workflows such as managing jobs, scheduling queries, administering reservations, modifying access controls, and creating table snapshots.

This distinction illustrates how specialised AI tools and broader command-line interfaces could coexist within enterprise systems.

Specialised MCP integrations can provide narrowly defined capabilities for particular tasks, while CLI-backed interfaces can support a wider range of operational requirements.

For enterprises managing large-scale analytics environments, this combination could support more integrated workflows across data analysis, administration, and infrastructure operations.

What This Means for Enterprise AI and Cloud Infrastructure

Google Cloud’s announcement is part of a wider technological transition towards agentic AI: systems capable of planning and executing multistep tasks through external tools.

The implications extend beyond cloud administration.

Enterprise technology has historically been organised around different interfaces for different users.

Graphical interfaces made computing systems accessible to human users. APIs enabled software applications to communicate with one another. Command-line interfaces provided engineers with efficient ways to manage infrastructure.

MCP-based integrations introduce another layer, allowing AI agents to interact with these existing systems through standardised tool interfaces.

This development could influence how enterprises design future automation strategies.

Rather than building separate AI integrations for every operational task, organisations may increasingly consider how existing enterprise tools can be made accessible to authorised AI agents.

Potential applications include infrastructure monitoring, incident response, analytics administration, resource provisioning, and routine operational maintenance.

At the same time, the expansion of agent capabilities will require corresponding advances in governance.

Enterprises must determine which operations AI agents can perform independently, which require human authorisation, and how accountability should be maintained when automated systems make consequential decisions.

Public Preview and Future Outlook

Google Cloud’s CLI remote MCP server is currently available in public preview.

According to the announcement, the MCP service itself carries no additional charge during the preview, although standard Google Cloud resource usage and data-transfer charges continue to apply.

The service supports MCP-compatible applications, allowing organisations to explore integrations with different AI assistants and custom agent systems rather than relying exclusively on Google’s own AI models.

The public preview also comes with limitations, including restrictions on certain CLI commands and administrative functions.

As the technology develops, several areas are likely to determine its enterprise adoption: stronger command-level security controls, more granular agent permissions, standardised human approval mechanisms, operational reliability, and integration with existing cloud governance systems.

The introduction of remote CLI execution through MCP suggests that cloud platforms are evolving from infrastructure environments operated primarily by humans and conventional software towards systems that can also be operated by authorised AI agents.

For enterprises, the central challenge will be balancing this increased automation capability with security, transparency, and human accountability.

  • Pallavi Singal is the Vice President of Content at ztudium, where she leads innovative content strategies and oversees the development of high-impact editorial initiatives. With a strong background in digital media and a passion for storytelling, Pallavi plays a pivotal role in scaling the content operations for ztudium's platforms, including Businessabc, Citiesabc, and IntelligentHQ, Wisdomia.ai, MStores, and many others. Her expertise spans content creation, SEO, and digital marketing, driving engagement and growth across multiple channels. Pallavi's work is characterised by a keen insight into emerging trends in business, technologies like AI, blockchain, metaverse and others, and society, making her a trusted voice in the industry.

Follow us on Google

Choose IntelligentHQ as one of your Preferred Sources to see more of our latest stories in Google.

Fill out the form below to request your copy.

Name(Required)