IA al Día
Back to archive
Tools news Sep 16, 2026 3 min read

Google Lets Outside AI Agents Control Google Home Devices for the First Time

Google opened early access to a Home MCP server so agents like Claude and Antigravity can control devices and read home history, not just its own Gemini assistant.

primary source · support.google.com — Introducing Home MCP: enabling your agent to interact with your home

Google is letting outside AI agents, alongside its own Gemini for Home, reach into a user’s smart home. On September 16 the company opened early access to Home MCP, a server built on the Model Context Protocol that lets any MCP-capable agent — Google names Google Antigravity, Claude, Hermes and OpenClaw as examples — discover, monitor and control the devices in a Google Home account, and query their event history in natural language.

The server exposes 5 tools: listing a user’s homes, their connected resources, current device states, event history, and running actions on them. Setup requires a Google Home Premium Advanced subscription in the US, a Google Cloud project, and an OAuth consent flow through which the user grants the agent permission; a separate consent step gates access to “familiar faces” camera recognition. Google says the server enforces rate limits and blocks sensitive actions such as unlocking doors, and it does not yet support creating or managing automations. It also warns, without elaborating, that connecting an agent “can result in unexpected or even undesired behavior.”

That warning leaves open the question that matters most for physical-safety framing: whether every action an agent takes on a device requires a fresh human confirmation, or whether that is left to each AI client’s own design once the initial OAuth grant is in place. Google’s documentation describes granting tool-execution permission “when prompted by your client” during setup but does not say whether a lock, thermostat or blind command gets checked with the user each time it runs. The company also has not said whether Home MCP will expand beyond Premium Advanced subscribers in the US, or whether device access is granted all at once for a home or can be scoped to individual devices.

Home MCP follows a pattern of Google exposing MCP servers across its stack, and it puts Google Home in the same position as Home Assistant, the open-source platform that already offers its own free MCP integration. It also arrives about a year after researchers from Tel Aviv University, Technion and SafeBreach showed that an indirect prompt-injection attack delivered through a poisoned Google Calendar invite could hijack Gemini for Home into operating lights, blinds and a boiler without authorization — a finding aimed at a different product surface, before Home MCP existed, that Google answered with stronger prompt-injection filters and mandatory confirmation before sensitive actions.