Thank you for bringing this up. I see that Gemini Enterprise is enabled on ALL of our OUs - which has since been changed. One of the features I'm not comfortable with is the ability to share Gemini chats outside of the domain, which can be turned off separately. I queried the difference between Gemini in Workspace and Gemini Enterprise. Here's what I was given:
When Gemini Enterprise is enabled, the primary "risk" of data sharing typically comes from Extensions.
Extensions allow Gemini to interact with other apps. While most are Google-owned (like Drive, Gmail, or Maps), some can connect to external platforms. However, as an Admin, you have full control over these.
🛡️ How Data Sharing is Restricted
By default, Google’s enterprise-grade protections ensure that:
No Training on Your Data: Google does not use your school's data to train its public models.
Internal Stays Internal: If a teacher uses Gemini to summarize a Google Doc, that text is processed securely and is not shared with any third party unless a specific third-party extension is enabled and used.
⚙️ How to Audit & Restrict Third-Party Sharing
To ensure data isn't leaking to outside companies, you can manage these settings in the Google Admin Console:
Manage Extensions: Go to Apps > Additional Google Services > Gemini Business and Enterprise Settings. Here, you can see which "Google Apps in Gemini" (Extensions) are active.
Tip: You can turn off specific extensions (like Google Maps or YouTube) if you don't want Gemini passing location or search data to those services.Control Workspace Data Access: In the same settings area, look for "Allow Gemini to access Google Workspace data."
Check Third-Party App Permissions: Go to Security > Access and data control > API controls.
Here, you can see if any third-party AI agents or apps have been granted permission to access your domain's data. You can "Trust," "Limit," or "Block" these apps individually.