This page documents production updates to Vertex AI. You can periodically check this page for announcements about new or updated features, bug fixes, known issues, and deprecated functionality.
See also:
You can see the latest product updates for all of Google Cloud on the Google Cloud page, browse and filter all release notes in the Google Cloud console, or programmatically access release notes in BigQuery.
To get the latest product updates delivered to you, add the URL of this page to your feed reader, or add the feed URL directly.
September 08, 2026
Agent Platform WorkbenchScheduled upgrade metadata is validated
The value of the notebook-upgrade-schedule metadata key is now validated when
you create or update an Agent Platform Workbench instance. The value must be a
single-line unix-cron
format schedule. For more
information, see Manage features through
metadata.
August 30, 2026
Agent Platform Workbench20260830-2330-rc0 Release
20260831.01_p0 Release
Installed latest packages from upstream dependencies.
Installed latest packages from upstream dependencies.
The terminal and file browser are now more responsive when working in a Cloud Storage bucket that is mounted through the file browser. Frequent background checks for non-existent files are now cached instead of repeatedly querying Cloud Storage, which previously could make actions such as listing files or running terminal commands take several seconds.
Cloud Storage buckets that you mount through the file browser are now automatically re-mounted after the instance is restarted or is stopped and started. Previously the mounted folder could be left behind as an empty, unusable directory that had to be manually removed and re-mounted.
The obsolete google-cloud-sdk transitional package is no longer installed. The Google Cloud CLI itself is unchanged; it was already provided by the google-cloud-cli package.
20260830-2230-rc0 Release
20260830-2230-rc0 Release
Installed latest packages from upstream dependencies.
Installed latest packages from upstream dependencies.
Cloud Storage buckets that you mount through the file browser are now automatically re-mounted after the instance is restarted or is stopped and started. Previously the mounted folder could be left behind as an empty, unusable directory that had to be manually removed and re-mounted.
The terminal and file browser are now more responsive when working in a Cloud Storage bucket that is mounted through the file browser. Frequent background checks for non-existent files are now cached instead of repeatedly querying Cloud Storage, which previously could make actions such as listing files or running terminal commands take several seconds.
20260830-2154-rc1 Release
Installed latest packages from upstream dependencies.
Fixed an issue where a notebook's cells and their outputs could be unexpectedly erased. The automatic reload of an open notebook (which keeps it in sync with changes made to its file on disk) is now restricted to run only while the Gemini CLI is in use, so notebooks are no longer overwritten at other times.
Cloud Storage buckets that you mount through the file browser are now automatically re-mounted after the instance is restarted or is stopped and started. Previously the mounted folder could be left behind as an empty, unusable directory that had to be manually removed and re-mounted.
The terminal and file browser are now more responsive when working in a Cloud Storage bucket that is mounted through the file browser. Frequent background checks for non-existent files are now cached instead of repeatedly querying Cloud Storage, which previously could make actions such as listing files or running terminal commands take several seconds.
Agent Platform Workbench instances internal agents now honor custom CA certificates installed on the host OS (e.g. via a custom VM image), fixing TLS certificate verification failures when Google API traffic is routed through a customer-managed proxy.
M148 Release
Installed latest packages from upstream dependencies.
Fixed an issue where a notebook's cells and their outputs could be unexpectedly erased. The automatic reload of an open notebook (which keeps it in sync with changes made to its file on disk) is now restricted to run only while the Gemini CLI is in use, so notebooks are no longer overwritten at other times.
The terminal and file browser are now more responsive when working in a Cloud Storage bucket that is mounted through the file browser. Frequent background checks for non-existent files are now cached instead of repeatedly querying Cloud Storage, which previously could make actions such as listing files or running terminal commands take several seconds.
Cloud Storage buckets that you mount through the file browser are now automatically re-mounted after the instance is restarted or is stopped and started. Previously the mounted folder could be left behind as an empty, unusable directory that had to be manually removed and re-mounted.
Agent Platform Workbench instances internal agents now honor custom CA certificates installed on the host OS (e.g. via a custom VM image), fixing TLS certificate verification failures when Google API traffic is routed through a customer-managed proxy.
August 23, 2026
Agent Platform Workbench20260823-2330-rc0 Release
20260823-2330-rc0 Release
Installed latest packages from upstream dependencies.
Installed latest packages from upstream dependencies.
20260823-2230-rc0 Release
20260823-2230-rc0 Release
Installed latest packages from upstream dependencies.
Installed latest packages from upstream dependencies.
20260823-2130-rc0 Release
Scheduled notebook executions now report their final status when the execution user's credentials stop working part way through a run, instead of continuing until the execution timeout.
Installed latest packages from upstream dependencies.
M147 Release
Scheduled notebook executions now report their final status when the execution user's credentials stop working part way through a run, instead of continuing until the execution timeout.
Installed latest packages from upstream dependencies.
August 16, 2026
Agent Platform Workbench20260816-2330-rc0 Release
20260816-2330-rc0 Release
Updated the bundled Ruby gems rexml and net-imap to patched versions, addressing known vulnerabilities.
Updated aiohttp, joblib and cryptography to patched versions, addressing known vulnerabilities including CVE-2022-21797 and CVE-2025-69223.
Installed latest packages from upstream dependencies.
Updated the CUDA base image from 12.8.1 to 12.9.2 (CUDA 12.9, cuDNN 9.10). This is a minor CUDA 12 update, binary compatible with the previous image, and also addresses known vulnerabilities in a bundled NVIDIA profiler component.
Updated the bundled Ruby gems rexml and net-imap to patched versions, addressing known vulnerabilities.
Removed the JupyterLab 3 environment from the Python 3.12 custom container; JupyterLab 4 is now the only JupyterLab environment and is always used. The Python 3.10 images are unaffected.
Updated aiohttp, joblib and cryptography to patched versions, addressing known vulnerabilities including CVE-2022-21797 and CVE-2025-69223.
Installed latest packages from upstream dependencies.
20260816-2230-rc0 Release
20260816-2230-rc0 Release
Installed latest packages from upstream dependencies.
Installed latest packages from upstream dependencies.
20260816-2130-rc0 Release
Installed latest packages from upstream dependencies.
M146 Release
Installed latest packages from upstream dependencies.
Fixed the Git panel's grayed out buttons, which were disabled due to an issue with the Jupyter Lab's Git plugin introduced in version 0.54.0.
August 09, 2026
Agent Platform WorkbenchInstalled latest packages from upstream dependencies.
20260809-2330-rc0 Release
Installed latest packages from upstream dependencies.
20260809-2330-rc0 Release
Fixed the Git panel's grayed out buttons which were disabled due to an issue with the Jupyter Lab's Git plugin introduced in version 0.54.0.
20260809-2230-rc0 Release
Installed latest packages from upstream dependencies.
Fixed the Git panel's grayed out buttons which were disabled due to an issue with the Jupyter Lab's Git plugin introduced in version 0.54.0.
20260809-2230-rc0 Release
Installed latest packages from upstream dependencies.
20260809-2130-rc0 Release
Updated the NVIDIA GPU driver on Workbench Debian 12 images from 580.65.06 to 580.126.20 for compatibility with the Debian 12 6.1.0-52 kernel.
Installed latest packages from upstream dependencies.
Fixed the Git panel's grayed out buttons which were disabled due to an issue with the Jupyter Lab's Git plugin introduced in version 0.54.0.
August 02, 2026
Agent Platform Workbench20260802-2330-rc0 Release
20260802-2330-rc0 Release
Fixed issue with JupyterLab UI silently reverting file changes and interrupting kernels due to Gemini CLI's auto reload extension.
The JupyterLab last-active and auto-reload extensions are now enabled only when Gemini CLI is configured, preventing them from affecting the native JupyterLab UI otherwise.
Installed latest packages from upstream dependencies.
Fixed issue with JupyterLab UI silently reverting file changes and interrupting kernels due to Gemini CLI's auto reload extension.
The JupyterLab last-active and auto-reload extensions are now enabled only when Gemini CLI is configured, preventing them from affecting the native JupyterLab UI otherwise.
Installed latest packages from upstream dependencies.
Fixed an error that could prevent creating new micromamba environments at runtime due to package cache permissions.
Fixed an error that could prevent creating new micromamba environments at runtime due to package cache permissions.
20260802-2230-rc0 Release
20260802-2230-rc0 Release
Fixed issue with JupyterLab UI silently reverting file changes and interrupting kernels due to Gemini CLI's auto reload extension.
The JupyterLab last-active and auto-reload extensions are now enabled only when Gemini CLI is configured, preventing them from affecting the native JupyterLab UI otherwise.
Installed latest packages from upstream dependencies.
Fixed issue with JupyterLab UI silently reverting file changes and interrupting kernels due to Gemini CLI's auto reload extension.
The JupyterLab last-active and auto-reload extensions are now enabled only when Gemini CLI is configured, preventing them from affecting the native JupyterLab UI otherwise.
Installed latest packages from upstream dependencies.
July 30, 2026
Agent Platform WorkbenchM145 Release
20260730-2130-rc0 Release
Installed latest packages from upstream dependencies.
Installed latest packages from upstream dependencies.
Fixed issue with JupyterLab UI silently reverting file changes and interrupting kernels due to Gemini CLI's auto reload extension.
The JupyterLab last-active and auto-reload extensions are now enabled only when Gemini CLI is configured, preventing them from affecting the native JupyterLab UI otherwise.
Fixed the JupyterLab Git extension's Pull and Push buttons being disabled by pinning jupyterlab-git to 0.53.0.
Fixed the JupyterLab Git extension's Pull and Push buttons being disabled by pinning jupyterlab-git to 0.53.0.
Fixed an error that could prevent creating new micromamba environments at runtime due to package cache permissions.
Fixed an error that could prevent creating new micromamba environments at runtime due to package cache permissions.
Workbench internal agents now trust custom and enterprise CA certificates installed on the host operating system, fixing TLS certificate verification failures for connections routed through the instance proxy.
Workbench internal agents now trust custom and enterprise CA certificates installed on the host operating system, fixing TLS certificate verification failures for connections routed through the instance proxy.
Files created by the post-startup script are now owned by the jupyter user, and git safe.directory is configured so that root-owned repositories continue to work.
Files created by the post-startup script are now owned by the jupyter user, and git safe.directory is configured so that root-owned repositories continue to work.
Fixed issue with JupyterLab UI silently reverting file changes and interrupting kernels due to Gemini CLI's auto reload extension.
The JupyterLab last-active and auto-reload extensions are now enabled only when Gemini CLI is configured, preventing them from affecting the native JupyterLab UI otherwise.
The JupyterLab last-active and auto-reload extensions are now enabled only when Gemini CLI is configured, preventing them from affecting the native JupyterLab UI otherwise.
July 13, 2026
Agent Platform WorkbenchAgent Platform Workbench image release
The following Agent Platform Workbench instances image releases are available:
- 20260712-2130-rc0 (
workbench-instances-2603- Debian 12)- Installed latest packages from upstream dependencies.
- Fixed broken cupy installation.
- M144 (
workbench-instances- Debian 11)- Installed latest packages from upstream dependencies.
- Fixed a race condition that could cause JupyterLab to be unreachable (HTTP 524) on GPU instances.
M144 Release
20260712-2130-rc0 Release
Installed latest packages from upstream dependencies.
Installed latest packages from upstream dependencies.
Fixed a race condition that could cause JupyterLab to be unreachable (HTTP 524) on GPU instances.
Fixed broken cupy installation.
Secure Boot is compatible with GPUs
You can now enable Secure Boot on Agent Platform Workbench instances that have a
GPU attached. Secure Boot with GPUs is supported on the workbench-instances-2603
VM image and the workbench-container-2606 custom container, which include a
Secure Boot-signed NVIDIA GPU driver so the driver loads under Secure Boot. For
more information, see Create an
instance.
Secure Boot is compatible with GPUs
You can now enable Secure Boot on Agent Platform Workbench instances that have a
GPU attached. Secure Boot with GPUs is supported on the workbench-instances-2603
VM image and the workbench-container-2606 custom container, which include a
Secure Boot-signed NVIDIA GPU driver so the driver loads under Secure Boot. For
more information, see Create an
instance.
Secure Boot is compatible with GPUs
You can now enable Secure Boot on Agent Platform Workbench instances that have a
GPU attached. Secure Boot with GPUs is supported on the workbench-instances-2603
VM image and the workbench-container-2606 custom container, which include a
Secure Boot-signed NVIDIA GPU driver so the driver loads under Secure Boot. For
more information, see Create an
instance.
A Missing Authorization vulnerability was discovered in repositories in BigQuery, Dataform, and Colab Enterprise. An authenticated attacker could potentially escalate permissions and perform cross-tenant repository takeover. For more information, see the GCP-2026-047 security bulletin.
July 06, 2026
Agent Platform WorkbenchAgent Platform Workbench image release
The following Agent Platform Workbench instances image release is available:
- 20260701-2130-rc0 (
workbench-instances-2603- Debian 12)- Installed latest packages from upstream dependencies.
- Fixed a race condition that could cause JupyterLab to be unreachable (HTTP 524) on GPU instances.
- Fixed an issue where long-running requests (for example, streaming or long-poll connections) could be terminated after about 60 seconds.
20260701-2130-rc0 Release
Installed latest packages from upstream dependencies.
Fixed a race condition that could cause JupyterLab to be unreachable (HTTP 524) on GPU instances.
Fixed an issue where long-running requests (for example, streaming or long-poll connections) could be terminated after about 60 seconds.
June 30, 2026
Agent Platform WorkbenchPython 3.12 base containers for Agent Platform Workbench custom containers
You can build custom containers for Agent Platform Workbench instances using Python 3.12 base containers, in addition to the default Python 3.10 base containers. The Python 3.12 standard and slim base containers are available at the following URIs:
us-docker.pkg.dev/workbench-images/gcr.io/workbench-container-2606:latestus-docker.pkg.dev/workbench-images/gcr.io/workbench-container-slim-2606:latest
Python 3.12 base containers for Agent Platform Workbench custom containers
You can build custom containers for Agent Platform Workbench instances using Python 3.12 base containers, in addition to the default Python 3.10 base containers. The Python 3.12 standard and slim base containers are available at the following URIs:
us-docker.pkg.dev/workbench-images/gcr.io/workbench-container-2606:latestus-docker.pkg.dev/workbench-images/gcr.io/workbench-container-slim-2606:latest
Python 3.12 base containers for Agent Platform Workbench custom containers
You can build custom containers for Agent Platform Workbench instances using Python 3.12 base containers, in addition to the default Python 3.10 base containers. The Python 3.12 standard and slim base containers are available at the following URIs:
us-docker.pkg.dev/workbench-images/gcr.io/workbench-container-2606:latestus-docker.pkg.dev/workbench-images/gcr.io/workbench-container-slim-2606:latest
June 29, 2026
Agent Platform WorkbenchAgent Platform Workbench image release
The following Agent Platform Workbench instances image release is available:
- 20260628-2130-rc0 (
workbench-instances-2603- Debian 12)- Installed latest packages from upstream dependencies.
- Installed TensorFlow and PyTorch packages to the default kernel.
20260628-2130-rc0 Release
Installed latest packages from upstream dependencies.
Installed TensorFlow and PyTorch packages to the default kernel.
June 24, 2026
Agent Platform WorkbenchAgent Platform Workbench image release
The following Agent Platform Workbench instances image release is available:
- 20260624-1604-rc0 (
workbench-instances-2603- Debian 12)- Installed latest packages from upstream dependencies.
- Fixed an issue where notebook kernels could become unavailable if the Dataproc plugin failed to load.
20260624-1604-rc0 Release
Installed latest packages from upstream dependencies.
Fixed an issue where notebook kernels could become unavailable if the Dataproc plugin failed to load.
June 23, 2026
Agent Platform WorkbenchAgent Platform Workbench image release
The following Agent Platform Workbench instances image releases are available:
- 20260622-2130-rc0 (
workbench-instances-2603- Debian 12)- Installed latest packages from upstream dependencies.
- Fixed a duplicate "Python 3 (ipykernel)" kernel appearing in the launcher.
- M143 (
workbench-instances- Debian 11)- Installed latest packages from upstream dependencies.
M143 Release
20260622-2130-rc0 Release
Installed latest packages from upstream dependencies.
Installed latest packages from upstream dependencies.
Fixed a duplicate "Python 3 (ipykernel)" kernel appearing in the launcher.
June 01, 2026
Agent Platform WorkbenchAgent Platform Workbench image release
The following Agent Platform Workbench instances image release is available:
- 20260531-2130-rc0 (
workbench-instances-2603- Debian 12)- Installed latest packages from upstream dependencies.
20260531-2130-rc0 Release
Installed latest packages from upstream dependencies.
May 28, 2026
Agent Platform WorkbenchAgent Platform Workbench image release
The following Agent Platform Workbench instances image release is available:
- M142 (
workbench-instances- Debian 11)- Installed latest packages from upstream dependencies.
- Fixed pip availability in the base environment.
- Hardened JupyterLab authentication configuration.
M142 Release
Installed latest packages from upstream dependencies.
Fixed pip availability in the base environment.
Hardened JupyterLab authentication configuration.
May 26, 2026
Colab EnterpriseData Science Agent
Generally available: Use the Data Science Agent to automate exploratory data analysis, perform machine learning tasks, and deliver insights from within a Colab Enterprise notebook. To get started, see Use the Data Science Agent.
Vertex AI Extensions deprecation
Vertex AI Extensions is deprecated and will be shut down after November 26, 2026. We recommend migrating to Agent Platform to avoid service disruption.
May 25, 2026
Agent Platform WorkbenchAgent Platform Workbench image release
The following Agent Platform Workbench instances image release is available:
- 20260524-2130-rc0 (
workbench-instances-2603- Debian 12)- Installed latest packages from upstream dependencies.
- Fixed a Python 3.12 compatibility issue in the JupyterLab server configuration.
- Hardened JupyterLab authentication configuration.
20260524-2130-rc0 Release
Installed latest packages from upstream dependencies.
Fixed a Python 3.12 compatibility issue in the JupyterLab server configuration.
Hardened JupyterLab authentication configuration.
May 11, 2026
Agent Platform WorkbenchAgent Platform Workbench image release
The following Agent Platform Workbench instances image release is available:
- 20260510-2130-rc0 (
workbench-instances-2603- Debian 12)- Installed latest packages from upstream dependencies.
20260510-2130-rc0 Release
Installed latest packages from upstream dependencies.
May 04, 2026
Agent Platform WorkbenchAgent Platform Workbench image release
The following Agent Platform Workbench instances image release is available:
- 20260503-2130-rc0 (
workbench-instances-2603- Debian 12)- Installed latest packages from upstream dependencies.
- Improved metadata server resolution reliability on Debian 12 by using the recommended metadata.google.internal name.
20260503-2130-rc0 Release
Installed latest packages from upstream dependencies.
Improved metadata server resolution reliability on Debian 12 by using the recommended metadata.google.internal name.
April 27, 2026
Agent Platform WorkbenchAgent Platform Workbench image release
The following Agent Platform Workbench instances image release is available:
- 20260426-2130-rc0 (
workbench-instances-2603- Debian 12)- Installed latest packages from upstream dependencies.