On October 2, Google moved Gemini Enterprise's Data Cloud connectors into Preview with a second operating mode, and it inverts the standard retrieval architecture. Federated query mode — now available for BigQuery, Spanner, Cloud SQL, and AlloyDB for PostgreSQL — queries operational and analytical data in place over the Model Context Protocol, using each user's own credentials, without copying or indexing anything into a Gemini Enterprise data store.
If you've built enterprise RAG, you know the pipeline it replaces: crawl the source, chunk, embed, write to a vector store, replicate ACLs, schedule incremental syncs, and spend the next year explaining to users why the policy doc published ten minutes ago isn't searchable yet. Google's own admin guidance is blunt about this failure mode — ingestion connectors run on scheduled cycles measured in hours, and data stores are not real-time mirrors.
What actually runs at query time
Each Data Cloud connector is backed by a first-party MCP server. A request authenticates through the user's IAM permissions or OAuth 2.1 and executes directly against the source. The retrieval step is no longer embedding similarity — it's Knowledge Catalog, also in Preview, which auto-enables on the app's Assistant tab when you attach a federated connector. The agent uses read-only Catalog tools to find tables the user can access and pull context: schemas, business glossary terms, and enriched metadata derived from technical metadata, historical query patterns, and LLM inference. It then formulates SQL from that context and invokes the connector's MCP tools.
So the retrieval index becomes a *metadata* index over schemas and semantics, and the actual fetch is a governed query. Freshness and authorization stop being pipeline problems and become properties of the source system.
The tradeoffs are real and mostly about cost and shape
Ingestion mode still wins where it always did: large document corpora needing high concurrency, fast responses, and deep semantic matching. Federated mode moves cost to query time — Google's BigQuery connector docs note federated queries incur BigQuery compute when users run them, while ingestion incurs BigQuery plus Gemini Enterprise indexing cost, along with egress for moving the data. The governance argument is sharper than the cost one: in ingestion mode, existing IAM permissions aren't replicated into the data store. For regulated deployments, Google's Gemini for Government guidance makes the distinction explicit — federated connector data is not persisted in the Gemini Enterprise index at all.
Who should care: anyone currently maintaining a permission-mirroring layer between a source system and a vector DB. That layer is the most expensive and most security-sensitive part of most internal knowledge stacks, and this is a credible argument for deleting it on structured data.
The caveats: Preview, Google-Cloud-native sources only for this release, and text-to-SQL accuracy now sits directly on the critical path with no index to fall back on. But the direction is clear — the connector is becoming an MCP server, and "the index" is becoming a catalog.

