Product1 publisher3 min readPublished
Gemini reads your Workspace by default, and the off switch is in the admin console
ZDNet reports that Gemini's access to Gmail, Docs, Calendar and Chat is enabled by default in Google Workspace. The consent decision has already been made on admins' behalf.
The Product Desk · Product desk
Drafted by a language model from the sources cited here and checked against its claim ledger before publication. How we use AISend a correction
What happened
- In Google Workspace, Gemini has access to Gmail, Docs, Calendar, Chat and more by default; Google defaults to allowing Gemini access to all Workspace services.
- Gemini is available in Chat, Drive, Docs, Calendar, Meet and Gmail, so users can interact with it from whatever work surface they are using.
- Workspace considers each of these data sources to be a Workspace Intelligence Source.
- Google does not use exposed Workspace company data for training or outside the company's domain, does not share prompts or generated responses with other users or organizations, and does not create an AI-specific database from documents and email messages.
- Google indexes all Workspace sources; when Gemini receives a prompt it uses real-time retrieval-augmented generation, searching Workspace data, retrieving relevant information it has permission to touch, and formulating an answer.
Compiled by The Product DeskSomething wrong?How this is made
Why it matters
Google Workspace gives Gemini access to Gmail, Docs, Calendar, Chat and other services by default, according to ZDNet [1]. Any admin who assumed that pointing an AI assistant at the company's mail and documents would require an affirmative decision has already had that decision made for them, and reversing it is an administrative chore rather than a purchasing one [1][11].
The mechanism is less exotic than the marketing around it. Gemini shows up in Chat, Drive, Docs, Calendar, Meet and Gmail [2] - six surfaces [13] - and Workspace treats each of those data stores as a Workspace Intelligence Source [3]. ZDNet describes the retrieval path as ordinary search plumbing: Google already indexes Workspace content, and when a prompt arrives Gemini performs real-time retrieval-augmented generation, searching that index, pulling back material it has permission to touch, and composing an answer [5].
Google's stated limits matter here. Per the same account, Workspace data is not used to train Gemini, is not used outside the customer's domain, prompts and responses are not shared with other users or organisations, and no separate AI database is built from the documents and mail [4]. ZDNet's own framing is that this moves the issue from a five-alarm regulatory fire to a corporate policy question [6].
Policy questions are still expensive. The compliance case for switching this off is client contracts or regulations that explicitly prohibit AI scanning and retrieval of company information, or rules that restrict data sharing even internally [7]. The operational case is blast radius: a model that answers from indexed corporate content can surface confidential records such as HR complaints or private deals to employees in other departments [8], and curious or malicious staff can use queries to route around departmental safeguards [9]. Even without bad intent, an innocent question can return sensitive material that happens to live in a Doc or a Chat log [10].
Note what the retrieval design implies. Because Gemini pulls only what it has permission to reach [5], the exposure surface is whatever your existing sharing permissions already allow, so over-shared drives and legacy documents become the failure mode rather than the model itself [14]. Turning Gemini off does not fix those permissions; it only stops a fast, natural-language way of finding them.
The remedy sits with admins, who can turn off intelligence sources [11]. ZDNet's walkthrough begins by signing in to an account with Google Workspace admin access [12]; the source material we have does not carry the remaining click path, so treat the specific console labels as something to confirm in your own tenant rather than take on faith from a how-to.
Two things are worth tracking. First, whether Google keeps this default as regulated customers push back, since a default-on setting is the vendor's choice and can be changed by the vendor. Second, whether your contracts and regulators already answer the question for you: if a client agreement bars AI scanning of their data [7], the toggles are not a preference, they are a control you have to be able to evidence.