Google enables Gemini to access internal business data across its commercial Workspace service by default, according to a report published by ZDNET. The artificial intelligence chatbot can retrieve information from Gmail, Docs, Calendar, Drive, Chat, and Meet unless administrators actively disable the feature. While Google doesn't use this data for training its AI models or share it beyond a company's domain, the automatic access creates potential compliance and privacy concerns for organizations.

Google treats each Workspace application as an "intelligence source" that Gemini can query when formulating responses. The system works through real-time Retrieval-Augmented Generation, where Google indexes all Workspace sources and searches them during AI interactions. The tech giant doesn't build a separate AI-specific database from documents and email messages, nor does it expose prompts or generated responses to other users or organizations outside the company's domain. Google also refrains from using the internal data to train its models, according to the report.

The report identifies several scenarios where administrators might want to restrict this capability. Client contracts or regulatory restrictions may explicitly prohibit AI scanning and data retrieval from company information, creating compliance issues. Some regulations prevent data sharing even internally within an organization. The AI could accidentally produce answers that include confidential records from HR complaints or private deals and deliver those to employees in other departments, undermining necessary departmental isolation. Even innocent queries from employees without malicious intent could surface sensitive company information living in a Google Doc or Chat log.

Workspace administrators can shut down intelligence sources by logging into admin.google.com and navigating to the Generative AI section, then selecting Gemini in Workspace. From there, clicking the Workspace Intelligence Sources block brings up settings to disable the feature for the entire organization. The report notes that turning off sources for individual users requires moving those users to separate organizational units or adding them to new groups, since the individual user interface is marked as view-only. The decision to allow or block Gemini's access converts from a five-alarm regulatory fire to more of a corporate policy question, given Google's internal-only data handling approach. Organizations face a trade-off between AI convenience and control as default access becomes the industry norm, raising questions about whether opt-in rather than opt-out should govern workplace intelligence tools.