Google began enabling Gemini across Workspace tenants for many subscribers without requiring a separate opt-in decision from IT. For some organisations, the AI layer was live before any security review was even scheduled.
The question security teams bring to us is the same one they raised when Microsoft Copilot landed. Is it safe? The same two-part answer applies, and the second part is the one that requires work. At the platform level, Gemini is built with enterprise controls in mind. Your data stays inside your Workspace tenant, Google does not use customer data from Workspace to train Gemini models when the appropriate enterprise terms are in place, and the assistant operates within the permissions the signed-in user holds. The exposure risk sits somewhere less comfortable. Gemini inherits every sharing permission, domain-wide link, and access grant already in your Drive, Gmail, and Meet. Years of accumulated sharing sprawl becomes instant, conversational retrieval.
Gemini is as safe as your Workspace configuration. For most organisations, that is where the real work begins.
How Gemini actually reaches your data
Gemini does not operate with special elevated access. It acts as the signed-in user, surfacing whatever that person can already open, and it does so across the full breadth of the Workspace suite.
For a typical employee that footprint is wider than most IT teams expect. Their Gmail inbox and sent history. Google Drive files they own and everything shared with them. Docs, Sheets, and Slides they have been granted edit or view access to. Meet recordings and transcripts they were part of. Calendar invites and their attached files. Gemini can read, summarise, and respond based on all of this in a single prompt.
Gemini does not grant permissions the user does not already hold. The change is speed and surface area. A document buried in a shared Drive folder from three years ago was always reachable in principle. Gemini makes it a search result.
Where the real exposure sits
The model is rarely the problem. The Workspace configuration is. A few patterns come up consistently.
Drive sharing that predates any policy. Google Drive makes sharing easy, and over the years most tenants build up a long tail of files and folders where permissions were set loosely and never reviewed. Documents shared with the entire domain are common; so are files shared via link with no expiry date. Gemini can read and summarise all of it. Sensitive content that was technically visible to everyone in the organisation but practically obscure now surfaces in a prompt response.
Gmail reach. Gemini in Gmail can summarise threads, draft replies drawing on past conversations, and answer questions about a user's inbox. For most professional roles that inbox contains client names, commercial terms, personal information, and correspondence that was never meant to be aggregated or quoted back in bulk. A user asking Gemini to summarise their recent exchange with a client gets exactly that. So does a user who phrases their question a little more broadly than they intended.
Meet transcripts and notes. Gemini can generate notes from Google Meet sessions and summarise recorded meetings. Confidential discussions, the kind where people speak more candidly than they would in a document, become text that can be retrieved and quoted later. The functionality is useful when the meeting content is appropriate for it. The problem is that most organisations have not decided which meetings qualify and which do not.
Admin defaults that favour adoption over control. Google's default Workspace settings lean toward making Gemini easy to use. Admin controls exist to restrict which data sources Gemini draws on, to require explicit user consent, and to limit features to specific organisational units. Most tenants have not worked through those settings deliberately. Running with whatever Google ships is a reasonable starting point for a pilot. It is not a sustainable position for a firm that handles client data.
Audit logging gaps. Many Workspace tenants have basic audit logging in place but have not configured it to capture Gemini-specific activity. If a member of staff asked Gemini to summarise a sensitive document and then shared that summary externally, could you reconstruct what happened? In most tenants today, the answer is no. This connects to the broader challenge of building an AI audit trail for compliance that actually covers the tools staff are using.
Why this matters for regulated firms
For an FCA or PRA-regulated firm, the exposure runs beyond security into governance territory. Supervisors expect firms to demonstrate where and how AI touches data and decisions affecting clients. If Gemini can reach client correspondence, advice records, or transaction-related documents across a user's footprint, and you cannot show what it surfaced or who saw it, that is an evidential gap a regulator or professional indemnity insurer will find.
SRA-regulated law firms face a sharper version of the same question. Privileged client communications sitting in Gmail, Drive, and Docs are exactly the data Gemini is designed to work across. The obligation to protect privilege does not disappear because the tool is useful. It requires that you know what the tool can reach before you let it operate.
Healthcare providers and any organisation holding special-category personal data under UK GDPR face equivalent obligations. Gemini's access to clinical correspondence or HR files is not inherently wrong. Leaving that access unexamined and uncontrolled is.
All of this connects to the architecture of an AI governance framework for the enterprise. The principle at the centre of that work is consistent across every tool. You cannot govern what you have not mapped. For Gemini, that mapping starts with understanding what is already shared across your Workspace environment, which for most tenants is a much larger surface than anyone expects.
What to examine before Gemini goes wide
A deliberate review before switching Gemini on for the whole organisation follows a clear order of questions.
Start with Drive sharing. What proportion of files in your environment are shared with the entire domain or available via link? What does that look like for your most sensitive folders and projects? Sharing audits take time in a large tenant, but you need a picture of the back catalogue before you can judge the exposure.
Then look at Gmail. Which roles in your organisation handle the most sensitive correspondence? What would Gemini be able to summarise for a typical person in one of those roles? Is that something you have a policy position on, or has the question not yet come up?
Review your Workspace admin settings for Gemini specifically. Google has added controls at the admin level that let you restrict data sources, require data protection acknowledgements, and limit Gemini features to particular organisational units. Most tenants have not touched these. Walking through them with AI risk in mind usually surfaces settings worth changing.
Confirm your audit logging covers Gemini interactions. If it does not, close that gap before you have an incident that requires you to explain it.
Then document what you found. The output of this review is not just a to-do list for the security team. It is the evidential baseline you can hand to your board, a regulator, or an insurer to show the risk is understood and is being managed. A verbal assurance that Gemini is probably fine does not serve any of those audiences. We explore the sequencing of this work in more detail in our piece on what an AI data leakage assessment finds.
The shadow Gemini problem
Most discussions of Gemini for Workspace focus on the licensed, admin-controlled AI layer inside your tenant. The harder problem is Gemini outside it.
Google Gemini is also available as a consumer product, free to use in a browser, with no enterprise data protection terms attached. If staff have been pasting work content into the consumer version, that data is going to a different environment entirely: different terms, different retention, and no admin oversight. Many organisations discover this pattern during an assessment. The habit formed before the enterprise version arrived and has not changed since.
This is the heart of the shadow AI problem. Approved tools sit alongside unapproved ones, and the boundary between them is not always clear to the person doing the work. Our piece on what shadow AI is and why it matters covers the full picture, including the most common routes by which consumer AI products end up carrying data from regulated environments.
How to get a clear view of your exposure
The most practical starting point is to measure what Gemini can actually reach in your Workspace today, for a representative user, before deciding what controls to put in place. Our Google Workspace Gemini Risk Assessment does exactly that. It maps what a typical user can surface through Gemini, the Drive sharing and admin setting gaps behind it, and a prioritised plan to close the exposure.
If your AI risk runs wider than Gemini alone, across Copilot, ChatGPT, and other tools your staff reach for, the AI Data Leakage Risk Assessment covers the full picture in one exercise. The Microsoft 365 Copilot risk assessment applies the same approach to the Microsoft side of the environment, and our overview of what shadow AI is explains the unapproved tools that usually show up alongside the licensed ones.
Gemini can be safe in your Workspace. Whether it is safe right now depends entirely on what it can reach. In most tenants, that has never been checked.
