Gemini AI Scans Enterprise Data by Default, Raises Governance Concerns
Google's Gemini AI assistant now has default access to almost all business data stored in Google Workspace, unless administrators actively disable it. This means that the AI can potentially read confidential client communications in Gmail, scan financial projections in Sheets, and review strategic planning documents in Docs, among other things.
The company has been promoting how the AI assistant can surface insights from across Workspace applications, but many administrators were caught off guard by the default-on nature of these permissions. The opt-out model puts the burden on IT teams to discover and disable the feature, rather than making it an explicit decision point.
Google's approach is sparking alarm among IT teams who manage sensitive business information, raising questions about whether Google prioritized AI functionality over enterprise data governance. Competitors like Microsoft have faced similar scrutiny over AI data access in their enterprise products, suggesting that AI vendors are struggling to balance powerful capabilities with enterprise security models.
The situation also exposes how rapidly AI is reshaping enterprise software assumptions. Features that would have required extensive security reviews and explicit approval processes are now being rolled out as default configurations, with vendors betting that AI capabilities will outweigh privacy concerns.