Google has opened early access to the Google Home MCP server — a connection that lets an outside AI agent talk directly to your smart home. Not Google's assistant. Someone else's agent: Claude, Google's own Antigravity tool, OpenClaw, or any other MCP-compatible client.

Here's what makes it worth reading carefully. The strongest warnings about this are not from a privacy group or a journalist. They're on Google's own developer page, in a box at the top.

What the Agent Can Actually Do

From the documentation:

"By exposing standard MCP tools and RPC interfaces, the server enables Large Language Models (LLMs) to inspect home structures, monitor device states, execute control actions, and analyze historical events."

Four capabilities, and they escalate.

Inspect home structures — the layout. Which rooms exist, what's in them, what each device can do.

Monitor device states — what's happening right now. Which lights are on, whether a camera is connected, whether a door sensor reads open.

Execute control actions — do things. Turn devices on and off, run commands.

Analyze historical events — and this is the one that deserves a second read. The documented tool queries "past state changes and event logs over specific time ranges." That is the record of a household over time: when the house was empty, when someone came to the door, when the upstairs went quiet.

The first three are about a moment. The fourth is about a pattern — and patterns are what tell you about people.

Google's Warning, In Full

The page opens with this:

"Connecting a real-life home to an AI agent allows that agent to control devices on your behalf."

Then the guardrail, which is specific and real:

"Home MCP enforces rate limits and safety protections, such as prohibiting sensitive actions like unlocking doors."

Good. That is exactly the failure everyone imagines first, and Google closed it explicitly.

Then the sentence the whole story hangs on:

"However, depending on your agent, connecting it to Home MCP can result in unexpected or even undesired behavior."

Depending on your agent. That is Google acknowledging, on its own page, that the safety of this arrangement isn't entirely Google's to guarantee.

It's a reasonable thing to say, and it's the structural feature worth understanding. Google controls what the API will execute. It does not control what an arbitrary AI agent will decide to request, or how that agent will interpret a loosely worded instruction. The boundary is drawn at the API. The judgment lives on the other side of it.

The Friction Is the Feature

It would be easy to write this as "Google just opened your house to AI." That would be wrong, and the accurate version is more interesting anyway.

Getting this running requires, per the docs:

  • An active Google Home setup with connected devices

  • An active Google Home Premium Advanced subscription (paid)

  • Access to a Google Cloud project

  • Enabling the Home API in that project

  • Configuring an OAuth consent screen and generating a client ID and secret

  • Publishing the app and pasting credentials into your AI client

That is a developer workflow, not a toggle. Nobody's home gets connected by accident, and no ordinary Google Home user is suddenly exposed by this announcement.

Two more guardrails worth knowing:

Camera face data is separately gated. To let the agent access familiar-faces data, a user has to "explicitly consent to this feature separately" — and the person granting it must be a manager of the home structure, with a compatible Nest camera or doorbell and familiar face detection already enabled.

It's revocable. "Your agent's access to Home MCP can be revoked at any time from the Google Home app (GHA) or your My Accounts page."

These are not afterthoughts. They're the design of someone who thought about what could go wrong.

The Line for Families

And then there's this instruction, which is the one I'd put in front of any parent:

"If you choose to connect a Google Home used by other household members with Home MCP, you should inform them that your agent can control devices and access home data."

Google's alternative suggestion is telling: "you can create an additional home and set up devices for development and testing."

Translation — if you're experimenting, don't experiment on the house your family lives in.

Sit with the shape of that for a second. One person in the household sets this up. That person consented, read the docs, understood the tradeoff. Everyone else in the home did not. They are simply inside the environment the agent can now see and act on.

In most homes that includes children, who are:

  • On the cameras

  • In the historical event logs — when they got home, which rooms they were in, what time the lights went off

  • Unable to meaningfully consent to any of it

This isn't unique to Home MCP. It's true of every smart home camera ever installed. What changes is who's looking. Until now the history sat in a Google account that a person had to deliberately go and review. Now a language model can query it, summarize it, and act on what it finds — continuously, and in response to whatever it was asked.

"Did anything unusual happen at the house this week?" is a reasonable question to ask an assistant. It's also a request to profile everyone who lives there.

What This Isn't

(This section is context, not the documentation.)

A few things this story is not, because they'll get blurred in the retelling.

It's not Gemini being replaced. Google's own assistant still runs the speakers and displays. This is a separate, developer-facing door for external agents.

It's not door-unlocking. Google prohibits that explicitly. The real surface is cameras, sensors, history, and everything that isn't on the prohibited list.

It's not settled. "Early Access" is stamped at the top of the page. Behavior, guardrails, and the prohibited-actions list can all change — and the only accounts of how this behaves in a real home so far are Google's.

And it's not evidence of harm. Nothing here reports an incident. This is a design and its documented warnings, published before the thing is widespread. That's the good version of how this is supposed to go.

For Parents, Practically

If someone in your household is a developer, this is the kind of thing they might set up on a weekend without mentioning it. Three questions worth asking, none of them accusatory:

1. Which home is it connected to? Google itself suggests using a separate test home. That suggestion exists for a reason.

2. Does it have camera access — and familiar faces? Faces require a separate, explicit consent step. Knowing whether that step was taken tells you a lot.

3. Who else knows? Google's instruction is to inform the household. That's a floor, not a ceiling — and "the household" includes kids old enough to understand that the cameras now answer questions about them.

None of that requires treating the technology as dangerous. It requires treating a house as a shared space, which it is.

Disclosure: Claude is one of the AI clients Google names as compatible with Home MCP. Claude is made by Anthropic.

Source: "Google Home MCP Server," Google Home Developers documentation: https://developers.home.google.com/mcp/home

All quotes above are from that page. Press coverage of the announcement reports a monthly price for the required Premium Advanced subscription; that figure is not in the documentation and is not stated here as Google's.

The sections marked as context — the comparison to Gemini, and the practical questions for parents — are ours, not Google's claims.

Want practical AI guidance for parents and educators every week? Subscribe: https://www.aibyage.com/?modal=signup&utm_source=beehiiv&utm_medium=newsletter