Privacy activist Bankston reported that Google's Gemini AI appears to be accessing private PDF documents in Google Drive without explicit user consent. Bankston claims that once Gemini is triggered on one document, it automatically processes subsequent files of the same type, even when settings indicate the feature is disabled. Google disputes these claims, stating that Gemini requires proactive activation and operates within privacy-preserving settings, suggesting the behavior might be related to legacy Workspace Labs settings or the use of the Drive side panel.
Kevin Bankston, a privacy activist, claims that Google's Gemini AI scans private Google Drive PDFs without explicit user consent. Bankston reports that after using Gemini on one document, the AI continues to access similar files automatically. Google disputes these claims, stating that Gemini requires proactive user activation and operates within privacy-preserving settings.
Risk classification
- Primary risk domain: 2 Privacy & Security
- Primary risk subdomain: 2.1 Compromise of privacy by obtaining, leaking or correctly inferring sensitive information
The incident involves an AI system accessing and processing private, non-public documents in Google Drive without explicit user consent.
Additional risk subdomains
- 7.3 Lack of capability or robustness: The system failed to reliably respect user settings and toggles, representing a lack of robustness in its control interface.
Causal factors
- Entity: AI
- Intent: Unintentional
- Timing: Post-deployment
The incident was caused by an unexpected behavior or glitch in the Gemini AI system automatically processing files despite user settings being disabled.
EU AI Act risk tier
- Risk tier: 3 Limited Risk
Risk Level 3: Limited Risk. The system involved is Google Gemini, which operates as a chatbot and general-purpose AI assistant within Google Workspace, falling under the Limited Risk category.
AI system and alleged parties
- AI system: Gemini (Google)
- AI purpose: Writing Assistant; Question Answering
- Behaviour type: Assistant
- Alleged developer: Google
- Alleged deployer: Google, Gemini
- Alleged harmed parties: Kevin Bankston, Google users, Google Drive users
Harm severity
Highest direct severity in any category: Substantial. Severity is scored from Negligible to Catastrophic in each harm category, for harm the reports describe as caused directly or indirectly by the AI system.
- Physical: direct Negligible, indirect Negligible
- Infrastructure: direct Negligible, indirect Negligible
- Property: direct Negligible, indirect Negligible
- Financial: direct Negligible, indirect Negligible
- Environmental: direct Negligible, indirect Negligible
- Malicious content: direct Negligible, indirect Negligible
- Differential treatment: direct Negligible, indirect Negligible
- Civil rights: direct Negligible, indirect Negligible
- Democracy: direct Negligible, indirect Negligible
- Privacy: direct Minor, indirect Negligible
- Psychological: direct Negligible, indirect Negligible
- Epistemic: direct Negligible, indirect Negligible
- Child sexual exploitation and abuse: direct Negligible, indirect Negligible
Privacy
Reported: Yes, the report explicitly describes a potential privacy violation where Google Gemini accessed private documents without user consent.
Directly caused: The AI system allegedly accessed and summarized private PDF documents in Google Drive for user Bankston, despite the user having disabled Gemini summaries in Gmail, Drive, and Docs.
Indirectly caused: N/A
Inferred additional harm: It is possible that other users who disabled the Gemini integration had their private documents accessed and processed without their explicit consent due to the same software behavior.
People affected
- Occurrences reported: 1
- People reportedly harmed: 1
- People reportedly exposed: 1
Potential causes
Management
- Inadequate Settings Design: Google placed critical privacy toggles in non-intuitive locations.
Technology
- Workspace Labs Override: Workspace Labs enrollment in 2023 may override current Gemini settings.
- Automatic File Type Trigger: Using Gemini on one file type triggers auto-summarization on future files.
- Persistent Side Panel State: Keeping the side panel open causes Gemini to automatically read new files.
Data Inputs
- Automatic Document Access: Gemini automatically ingests open document content without explicit consent.
Human Factors
- Prior Workspace Labs Opt-In: User opted into legacy Labs program, leading to unexpected settings override.
- Lack of UI State Awareness: User did not realize keeping the side panel open would trigger auto-scans.
Process and Methods
- Inaccurate Settings Guidance: Gemini bot provided incorrect locations for privacy settings toggles.
- Ineffective Toggle Enforcement: System failed to respect the disabled state of Gemini summaries in Drive.
Information quality
- Classification confidence: Medium
- Reason for confidence: The report provides a detailed account from a privacy activist, but Google disputes the assertions, suggesting alternative explanations like side-panel usage or legacy settings. This creates some ambiguity about the exact technical cause of the behavior.
- Ambiguities identified: Whether Gemini actually accessed the documents without permission, or if it was triggered by user interaction with the side panel or legacy Workspace Labs settings.
- Alternative interpretations: The behavior could be an intended feature of the side panel that the user misunderstood, rather than a privacy bug or glitch.
- Missing information: Technical logs or independent verification confirming whether Gemini processed the files without any user interaction and despite disabled settings.
A privacy activist reported that Google Gemini automatically accessed and summarized private Google Drive PDFs despite disabled settings. While highlighting potential data privacy and user consent issues within cloud platforms, the incident represents a minor software configuration or behavioral issue with negligible direct national security implications.
- Overall national security impact: Minor
- Response level: Moderate
- Scope: Multiple nations
- Primary target: No clear primary
- Other affected: Unknown
- Alleged perpetrator: Unknown
Threat characteristics
- Imminence: Long-term. This is a software behavior issue that does not present an imminent national security crisis.
- Autonomy: Human-supervised. The AI automatically processed and summarized documents without explicit per-file confirmation, though within a user-controlled environment.
- Novelty: Established threat. Unintended data access and software configuration issues in cloud services are well-established technical risks.
Impact by dimension
- Physical security: Negligible. No physical systems, kinetic threats, or critical infrastructure were affected or targeted in this incident.
- Information security: Negligible. No classified intelligence was compromised, and there is no indication of state-sponsored information warfare or espionage.
- Sovereignty: Negligible. The incident involves a commercial cloud service and does not impact state authority, border control, or government decision-making.
- Economic security: Negligible. No strategic technology theft, financial market manipulation, or critical supply chain disruptions occurred.
- Societal stability: Minor. Represents a minor privacy concern regarding automated data processing in cloud storage, but lacks scale or intent to threaten societal stability.