Shadow AI in Google Workspace: How to Find and Block AI Apps Connected to Google Drive
Quick answer
An employee can give an AI tool lasting access to your company's Google Drive in under a minute. Unless an admin sets limits, nothing stops it. In Google Workspace, you fix this in five steps:
Find the AI apps that already have access. Use the App access control list.
Limit which apps can use Drive. Set the Drive service to Restricted.
Block apps you do not approve. Set unconfigured third-party apps to "Don't allow", and block named apps.
Watch for new grants. Review OAuth log events every week.
Set a policy that lists the approved AI tools and tells staff how to ask for a new one.
This guide explains each step with the menu names from Google's help pages, dated October 2026. We did not run every step in a live domain, so confirm each menu on your own screen. Where we could not confirm something, we say so.
What happens when someone connects an AI tool to Google Drive
Many AI tools show a button that says "Connect to Google Drive" or "Sign in with Google." When a person clicks Allow on the Google screen, two things happen.
First, the person gives the tool a set of permissions. Google calls each permission a scope. A scope says what the tool may do. Some Drive scopes let a tool read every file the person can open. Others let it change, share or delete files. Google treats scopes such as full Drive access and read-only access to all files as high-risk.
Second, Google gives the tool a token. A token is a code that the tool keeps and uses to reach the person's files later, without asking for a password again. The tool sees what the person can see in Drive, including shared drives and shared folders the person can open.
This is different from pasting text into a chatbot. Pasting sends one piece of text one time. Connecting gives ongoing access. If the tool's own systems are breached, the attacker can use the same access. Two of the cases below show this.
Do not count on a password reset to cut off an AI app. Google says it revokes some tokens when a password changes, such as tokens for mail access. Its help page does not say this applies to every app or every scope. The safe way to know is to check the app list, as described below.
Four real cases
Vercel and Context.ai, April 2026
On April 19, 2026, Vercel said it had found unauthorized access to some internal systems. Vercel says the problem began with a compromise of Context.ai, an AI tool used by one Vercel employee. The attacker used that access to take over the employee's Vercel Google Workspace account. From there, the attacker reached a Vercel environment and decrypted non-sensitive environment variables for a limited group of customers (Vercel's bulletin).
Vercel also said the Context.ai Google OAuth app was part of a wider compromise that could affect hundreds of users at many organizations. Context.ai said at least one Vercel employee signed up with a company Google account and granted "Allow All" permissions. Vercel said its OAuth settings appear to have allowed that (Help Net Security). An analysis by TrendAI marks each timeline item as confirmed or unverified. It dates the start to a malware infection at Context.ai around February 2026, and the use of stolen tokens in March 2026.
Salesloft Drift, August 2025
Google's Threat Intelligence Group said attackers stole OAuth tokens tied to the Salesloft Drift AI chat integration. Between August 8 and 18, 2025, they used the tokens to export data from Salesforce accounts. On August 9, they also used tokens for the Drift Email integration to read email in a very small number of Google Workspace accounts that had set up that integration. Google revoked the tokens, turned off the integration, and said Google Workspace itself was not compromised (SecurityWeek). The Google Workspace part of this case involved Gmail, not Drive.
AgentFlayer, August 2025
At Black Hat USA in August 2025, researchers at Zenity showed a way to make ChatGPT leak data from a connected Google Drive. They hid a 300-word prompt in a document, in white text at font size one, so a person could not see it. When ChatGPT, connected to Drive, processed the document, the hidden prompt told it to search Drive for API keys and send them to an outside server through a crafted web address. The researchers call it zero-click, because the victim does not need to click anything in the file. OpenAI added mitigations. Google's Andy Wen said the issue is not specific to Google's cloud platform (TechSpot). This was a research demonstration. It was not a reported attack on a real company.
Samsung and ChatGPT, 2023
In March and April 2023, Korean press reported three cases within about 20 days in which Samsung semiconductor engineers pasted source code and meeting notes into ChatGPT. Samsung reportedly limited prompt size and later banned generative AI tools on company devices (Gizmodo). This was not a Drive connection. It shows the other way data leaves: pasting into a browser.
What the cases have in common
In the Vercel and Drift cases, the attackers used tokens that were already approved. They did not need an employee's password.
In the Vercel case, one employee's choice gave an outside tool broad access, and Vercel said its settings appear to have allowed it.
In the AgentFlayer demo, the risk came from a connected tool reading a file that someone else supplied.
How to find the AI apps already connected
You need two Admin console privileges for this section. The Service Settings administrator privilege lets you open API controls. The Audit & Investigation administrator privilege lets you read OAuth log events.
Step 1: Open the app list
Sign in to the Google Admin console as an administrator.
Go to Menu, then Security, then Access and data control, then API controls.
Click Manage App Access.
Step 2: Review the apps that have used your data
Under Accessed apps, click View list. This shows apps that have accessed Google data in your domain.
For each app, the list shows the number of users and the requested services, such as Gmail, Google Calendar or Google Drive.
Click Add a filter, choose Requested services, and select Drive. Repeat for Gmail.
Click an app to see its OAuth client ID, its number of users, its privacy policy and the scopes it requests.
Click Download list to save the list as a CSV file. The file includes verification status, number of users, organizational unit and API scopes.
The list can lag. Google says app details typically appear 24 to 48 hours after a user authorizes an app. Do not decide that no AI apps are connected from a list you checked an hour after a change.
What to look for
Names that suggest AI, such as assistant, notetaker, summarizer, agent, GPT, chat or copilot. A name is only a hint, so read the scopes too.
Broad Drive scopes. Google's high-risk list for Drive and Docs includes full Drive access (drive), read-only access to all files (drive.readonly), file metadata (drive.metadata.readonly), Drive activity (drive.activity.readonly), and full or read-only access to Docs, Sheets and Slides.
Apps with very few users. In the Vercel case, the access came from one employee's sign-up.
Apps that nobody uses any more. A June 2026 study by Material Security, a security vendor, looked at 22,332 OAuth apps in 21 Google Workspace environments. It found that 47.2% of apps had no use in 90 days or more while their access stayed in place, and that 1,064 apps had no active users but still held live tokens (Material Security). The study says these apps are not necessarily malicious.
The verified column. Google says verified apps passed a Google review for certain policies, and that many well-known apps may not be verified. Treat "verified" as one input, not as approval.
Step 3: Check the OAuth log
Go to Menu, then Reporting, then Audit and investigation, then OAuth log events.
Search by app name, client ID or user.
The Event column shows entries such as Grant and API call. A Grant event shows who authorized which app. An API call event shows what an app did. Google says API call events are available only on some editions: Enterprise Plus, Enterprise Standard, Education Plus, Education Standard and Cloud Identity Premium.
You can also search by AI agent information: agent ID, agent name or agent product.
The same log is available in the Security center investigation tool. Go to Menu, then Security, then Security center, then Investigation tool, and choose OAuth log events as the data source. If you read the log through Google's Reports API, the event names are authorize, request, deny, revoke and activity.
How to limit or block them
Do this after the inventory, so you know what will stop working. Apply each setting to a test organizational unit first. Google says changes can take up to 24 hours.
1. Block All Unconfigured Third-Party Apps
Location: API controls → Settings
What It Does: Completely blocks Google Sign-In for any third-party app or website until explicitly configured.
Side Effect: Stops Sign-In with Google for all unconfigured apps, including essential staff tools.
2. Allow Basic Info Only for Sign-In
Location: API controls → Settings
What It Does: Limits unconfigured apps to basic profile scope (name, email address, profile picture).
Side Effect: Blocks Drive access for unconfigured apps while preserving basic sign-in functionality.
3. Set Drive Access to Restricted
Location: API controls → Manage Google Services → Drive → Change access
What It Does: Limits access to apps set to Trusted or Specific Google data, revoking tokens for untrusted apps.
Side Effect: Restricts the Google Forms API. A prompt still allows users to approve low-risk scopes.
4. Configure Specific App Access Levels
Location: Manage App Access → Change access
What It Does: Sets app-level access (Trusted, Limited, Specific Google data, or Blocked) per Organizational Unit.
Side Effect: Requires the App Name or Client ID. Specific Google data configurations must explicitly include basic sign-in scopes.
5. Allow Users to Request App Access
Location: API controls → Settings → Allow users to request access to unconfigured third-party apps
What It Does: Directs user access requests to Apps pending review for admin approval or dismissal.
Side Effect: Requires an established admin review process to manage incoming user requests.
6. Drive Sharing Limits & Boundaries
Location: Rules → Trust rules for Drive / Data protection rules
What It Does: Restricts who files can be shared with across domain boundaries.
Side Effect: Controls user sharing permissions; does not prevent an approved app from accessing files the user can open.
A sensible order:
Mark the apps you approve as Trusted or Specific Google data.
Set Drive to Restricted for a test organizational unit and see what stops working.
Turn on the request option, so staff have a way to ask.
Set unconfigured third-party apps to "Don't allow".
Roll the settings out to other organizational units.
To block an app before anyone connects it, go to Manage App Access, click Configure new app, search by app name or client ID, and choose Blocked. Google says that if you add an app for devices to an allowlist and also block it in API controls, the app is blocked.
Set the AI vendor's side too
Take ChatGPT as an example. OpenAI says ChatGPT workspace admins can turn Google app actions on or off in ChatGPT. ChatGPT asks for the Google scopes that the enabled actions need. Google Workspace then checks whether the ChatGPT or OpenAI app is trusted or approved for those scopes. OpenAI gives three rules (OpenAI help):
If you want users to use an action, approve its Google scope and keep the action on.
If you do not want to approve a scope, turn off every ChatGPT action that needs it.
If an action stays on while its scope is blocked, users may see authorization errors.
After you align the two settings, ask users to create a new connection or reconnect. Other AI vendors may have similar settings, so check each vendor's admin documentation.
Google's own Gemini
Gemini in Google Workspace is Google's own AI. It is managed under Generative AI in the Admin console, not in the third-party app list. Google says DLP for Gemini can stop Gemini from using Drive files that match your rules, such as files with a certain classification label.
What these controls do not stop
Pasting into a browser. Google's admin controls do not stop an employee from pasting a document into a personal AI account in a web browser. Verizon's 2026 Data Breach Investigations Report says frequent use of AI tools by employees rose from 15% to 45% in one year, and that shadow AI is now the third most common non-malicious data leakage activity (Verizon). Push Security, a security vendor, cites the same Verizon report for a further figure: 67% of regular AI users on corporate devices use non-corporate accounts. Push's own data shows that 38% of file uploads to AI tools come from personal accounts (Push Security). To cover this, give staff approved AI tools on company accounts, and add browser or device controls.
Poisoned documents. AgentFlayer showed that a connected AI tool can follow hidden instructions in a file. Limiting which tools are connected, and what they can reach, lowers the risk. It does not remove it. The researchers said the demo points to a wider concern: AI systems with unrestricted access to user data and cloud files carry serious risk.
Drive DLP rules. We found no Google documentation saying that Drive DLP rules stop an approved OAuth app from reading a file the user can open. The Google pages we reviewed cover sharing rules and DLP for Gemini. Test this in your own domain before you rely on it.
Bans on their own. In a 2026 survey reported by Help Net Security, nearly one-third of employees said they would keep using AI tools even if rules banned them and discipline was possible.
How to keep watching
Set a short weekly review:
Open Apps pending review and approve or dismiss each request.
Check Accessed apps for new apps. Remember the 24 to 48 hour delay.
Search OAuth log events for new Grant events.
Look for apps with no active users that still hold access. Material Security recommends linking access removal to employee offboarding and setting a limit for unused apps, starting at 90 days.
When someone leaves, add a check of the apps they authorized to your offboarding steps.
We could not confirm whether every Google Workspace edition lets you create an alert for new OAuth grants. Check the Rules section of your Admin console, and test any rule before you rely on it.
A policy people will follow
A short policy has five parts:
Approved tools. A list with each tool's name, what it may be used for, and which kinds of data are allowed.
What staff must not do. Connect an unapproved AI tool to a company Google account, or paste customer data, passwords or source code into a personal AI account.
How to ask. One form or one email address, with a promised reply time.
Who reviews. A named person who checks the scopes and the vendor's admin settings.
What happens after a violation. Start by helping the person move to an approved tool. Keep discipline for repeated or serious cases.
A ban that gives staff no approved option leaves them with personal accounts, which are the hardest for you to see.
Admin checklist
| Step | Task | Where |
|---|---|---|
| 1 | Open the app list and filter by Drive and Gmail | Security, Access and data control, API controls, Manage App Access |
| 2 | Download the Accessed apps list | Accessed apps, Download list |
| 3 | Mark the apps you approve as Trusted or Specific Google data | Change access |
| 4 | Block the apps you do not approve | Change access, Blocked |
| 5 | Set Drive to Restricted for a test organizational unit | Manage Google Services, Drive, Change access |
| 6 | Turn on the option for users to request access | API controls, Settings |
| 7 | Set unconfigured third-party apps to "Don't allow" | API controls, Settings |
| 8 | Review Grant events from the last 30 days | Reporting, Audit and investigation, OAuth log events |
| 9 | Match the AI vendor's admin settings to your Google settings | The vendor's admin console |
| 10 | Send staff the approved tool list and the request path | Email or intranet |
| 11 | Put a weekly review in the calendar | Calendar |
Frequently asked questions
Can ChatGPT read my Google Drive without my permission?
No. OpenAI says ChatGPT can access only content that the connected Google account can open, and only after you authorize the connection. For managed Google Workspace accounts, your organization's OAuth settings can also limit which scopes the ChatGPT app may request.
How do I see which apps can access my company's Google Workspace data?
In the Admin console, go to Security, then Access and data control, then API controls, then Manage App Access. Open Accessed apps and click View list. It shows the users and requested services for each app. Details can take 24 to 48 hours to appear after a user authorizes an app.
Does blocking third-party apps stop Sign in with Google?
It can. If you set unconfigured third-party apps to "Don't allow users to access any third-party apps", users cannot sign in with Google to any third-party app or website until you configure it. To keep sign-in working, choose the basic-info option, or mark the apps you need as Trusted or Specific Google data.
Can Google DLP stop an AI app from reading a file?
We found no Google documentation that says so. The DLP pages we reviewed cover sharing rules and DLP for Gemini, which can stop Gemini from using matching Drive files. Test any DLP rule in your own domain before you rely on it to block an approved third-party app.
How do I revoke an AI app's access?
In Manage App Access, open the app, choose Change access, and select Blocked for your whole organization or for one organizational unit. Setting Drive to Restricted also revokes the tokens of apps you have not trusted. Users can also remove an app in their own Google Account security settings.
What is the difference between blocking an app in Google and turning off the action in ChatGPT?
They are two separate settings. ChatGPT admins choose which Google Drive actions are on. Google Workspace admins decide whether the ChatGPT app is trusted or approved for the scopes those actions need. If an action is on and its scope is blocked, users may see authorization errors. Set both the same way.
What we could not confirm
Drive DLP and trust rules. Whether they change what an approved app can read.
Alerts. Whether you can create an alert for new OAuth grants in every edition.
"Block all third-party API access." Google announced a setting with this name in 2021. Google's current help page lists three choices for unconfigured apps instead. Check which your console shows.
Password changes. Google's help page says tokens for certain products are revoked when a password changes. Test what happens for the AI apps you use.
Sources
Last checked: October 5, 2026.
Google Workspace Help: Control which apps access Google Workspace data
Google Workspace Help: Automatic OAuth 2.0 token revocation upon password change
Help Net Security: Vercel breached via compromised third-party AI tool
SecurityWeek: Google confirms Workspace accounts also hit in the Salesloft Drift campaign
TechSpot: ChatGPT vulnerability allows hidden prompts to steal Google Drive cloud data
Gizmodo: Samsung employees leaked confidential data to ChatGPT
Need a second pair of eyes on your Google Workspace settings? Contact us.