When Gemini AI Reportedly Scans Drive Files Without Permission

Quick answer

Some users have reported that Google's Gemini AI has accessed and processed PDF documents stored in their Google Drive accounts without receiving explicit permission. Normally, Gemini requires users to activate a specific extension to connect with Drive. These reports suggest an unexpected interaction that could affect user data privacy.

How Gemini is designed to access Google Drive

Google Gemini is designed to integrate with other Google services through what the company calls 'Extensions' or 'Skills'. For Google Drive, a user must actively enable the Drive extension within Gemini's settings. This process requires explicit consent, giving Gemini permission to search and summarise content from the user's Drive files.

The purpose of this connection is to allow Gemini to assist with tasks directly related to a user's cloud-stored documents. For example, a user might ask Gemini to summarise a long PDF report or find specific information across several documents. This functionality is intended to be opt-in, meaning users choose whether to grant this level of access.

The reported issue: scanning without permission

Despite the established opt-in mechanism, several users have reported instances where Gemini appears to have scanned or processed PDF files from their Google Drive accounts without the Drive extension being explicitly enabled. These reports surfaced in online discussions and user forums.

Users described asking Gemini general questions and receiving answers that seemed to draw specific information from their private Drive documents, even when they believed direct access had not been granted. This unexpected behaviour suggests that data might be indexed or accessed in ways not transparently communicated or consented to by the user through the standard extension activation process. The files in question were primarily PDFs.

What Google has said

Google has not issued a public statement specifically addressing these isolated reports of Gemini scanning Drive PDFs without explicit permission. The company's general documentation on Gemini's Extensions highlights the requirement for user consent before connecting to services like Google Drive.

Without an official statement, the exact cause of these reported instances remains unconfirmed. It could point to a technical glitch, an interaction with other linked Google services, or a misunderstanding of how certain permissions operate. The company's focus has generally been on the controlled, opt-in nature of its AI integrations.

What this changes for the reader

The reports of Gemini accessing Drive files without explicit permission shift the burden onto the user to verify their privacy settings. Readers who use Google Drive for personal or work documents and also interact with Gemini should be aware that their data might be exposed to the AI in unexpected ways.

This situation challenges the expectation that cloud-stored personal data remains private until an unambiguous action grants access. It means that the default state of privacy might be less robust than assumed. For many, the value proposition of an AI assistant is convenience, but this can come with a trade-off in perceived control over personal information.

Users may need to review not just their Gemini settings but also their broader Google account data and privacy controls. This also highlights the ongoing challenge for technology companies to communicate clearly how AI interacts with user data across interconnected services.

How to check and control Gemini's access to Drive

To manage Gemini's access to your Google Drive, open Gemini and look for the Extensions or Settings menu. Here, you will find a list of services Gemini can connect to. Ensure that the Google Drive extension is either turned off or configured exactly as you intend.