Google Workspace can now suspend AI agents and their Drive access — what SMBs should check before September 1
Google’s August 2026 Workspace update adds an admin dashboard that can suspend an AI agent or revoke a single access it holds — Drive, Gmail, Calendar — plus a Gemini DLP filter that restricts what Gemini can read on Drive by content label. Rollout reaches most Workspace domains on September 1, 2026. What it concretely changes if your team already builds its own Gemini automations.
In its August 2026 update to Workspace Studio — the no-code tool for building Gemini-driven automations, called "flows" — Google added an agent access management dashboard to the admin console. An administrator can now suspend an entire agent, or revoke just one access it holds — for example cutting off a single flow’s Drive access without touching the rest of the automation. Rollout began on August 20, 2026 for Rapid Release domains; it reaches Scheduled Release domains on September 1, 2026, which covers most SMBs on a standard Workspace subscription.
What actually changes in the admin console
- →An "agent access management" dashboard listing every flow built in Workspace Studio and the permissions it holds.
- →The ability to suspend an entire agent, or revoke a single permission (Drive, Gmail, Calendar…) without disabling the rest of the automation.
- →A Gemini DLP (data loss prevention) filter that restricts what Gemini can access on Drive based on a file’s content or confidentiality label.
- →An option to require human confirmation before a flow shares data outside the organization, or to disable specific step types and webhook integrations altogether.
- →An investigation tool that lets an admin jump straight from a security alert to the access-management page to cut the permission in question.
For now, only flows created after the rollout show up automatically in the dashboard; Google says support for existing flows will follow.
Why Google is acting now
This tightening lands a month after the CNIL and the Conseil de l’IA et du Numérique published, on July 20, 2026, a warning note on agentic AI that we covered on this blog: persistent memory, opaque processing chains spanning several services, and unclear controller/processor roles. The pattern matches a growing body of research. A 2025 study by Mario Silic, Dario Silic and Kathrin Kind-Trüller published in the journal Strategic Change, From Shadow IT to Shadow AI – Threats, Risks and Opportunities for Organizations, surveying 140 professionals and interviewing 10 executives, found that undeclared AI use grows precisely where existing governance fails to track how teams actually work — what the authors call a "governance drift zone." On the technical side, a January 2026 paper by Zimo Ji, Daoyuan Wu and seven co-authors, Taming Various Privilege Escalation in LLM-Based Agent Systems: A Mandatory Access Control Framework, details how an AI agent can be steered, through a simple natural-language instruction, into obtaining more access than its task requires — exactly the scenario Google’s new permission-level control is meant to limit.
What it changes for your SMB
Most SMBs on Google Workspace have not yet built a Studio Flow in-house — but the ones where an employee has started assembling their own Gemini-driven email-sorting or reporting agent are exactly the audience this update targets. Three concrete checks before the September 1 rollout:
- →Ask your Workspace administrator to list, in the admin console, every flow already created and the access each one holds — Drive, Gmail, Calendar — before discovering that a forgotten agent still has access to a sensitive shared folder.
- →Turn on the Gemini DLP filter for Drive folders holding HR, contract or client data, labeling them upfront rather than reacting after an incident.
- →Require human confirmation on any flow step that shares data outside the organization — the same oversight principle we recommend for a watchdog agent monitoring several internal tools at once, or a reporting agent pulling numbers from scattered sources: automation saves time, but supervision stays necessary as long as the processing chain isn’t fully auditable.
Google’s dashboard does not replace an AI governance policy — it gives you a technical lever to enforce one. Without an inventory of the agents that already exist, that lever is useless: start with the list, before September 1.
Frequently asked questions
My company uses Google Workspace but not Gemini — am I affected?+
Not directly. These new controls apply to flows built in Workspace Studio, the feature for assembling Gemini-driven automations. If no one has built one yet, there is nothing to suspend — but it is a good moment to confirm no informal automation already exists without leadership knowing.
Do we need to wait until September 1 to act?+
No — Rapid Release domains already have access to the dashboard since August 20, 2026. A Workspace administrator can check today, in the admin console, what access already exists.
Free resource
The self-assessment grid: 20 tasks AI can automate
Sales, admin, support, operations: the 20 tasks AI agents already handle in SMEs — with, for each one, the tell-tale sign that your team is concerned.
Read next
Business & compliance
E-invoicing: Bercy imposes cybersecurity audits on approved platforms after the tax authority hack — what to check before September 1
29 August 2026·5 min read
Business & compliance
Training organization software: off-the-shelf Qualiopi tool or a custom management platform?
28 August 2026·5 min read
Business & compliance
Anthropic launches Claude Security with Mythos 5: what the AI patching race changes for your SMB
26 August 2026·5 min read