What a year of data over 150 organizations reveals about enterprise AI adoption and the security gap it created
We analyzed anonymized data from 159 organizations for trends in data governance and security across the cloud workspace as AI adoption continues to accelerate. Read the full results here.
Something shifted in enterprise Google Workspace environments starting in late 2025. Organizations began restricting file access at a pace that had no precedent in our data. Permissions revoked. Shared links disabled. Access controls tightened across hundreds of millions of files every month. By spring 2026, restricting activity had grown more than tenfold compared to where it stood twelve months earlier.
Something triggered it. The data tells you exactly what.
The Adoption That Already Happened
When an employee connects an AI tool to their Google account, they are not submitting a request. They are granting access. One OAuth authorization and the tool can read Drive, Gmail, calendars, and everything else that employee can reach. No ticket. No IT review. No entry in any approval system.
We analyzed 159 organizations to understand what that looks like at scale. What we found was not a controlled rollout. It was a distributed adoption event, running simultaneously across every organization, largely invisible to the security teams responsible for managing it.
Across those 159 organizations, 978 distinct applications had connected to Google Workspace through OAuth. Not deployed by IT. Authorized by individual employees who found a useful tool and used it.

The highest-volume application in our dataset had been authorized by more than 152,000 unique users. It did not go through IT. It spread the same way every consumer application spreads: one employee at a time.
Most of those 978 applications have no name. Not because the data is incomplete, but because the majority are private OAuth projects built within specific organizations that were never registered as public products. They appear in logs only as a numeric project ID. No product name. No vendor. No description of what they do or what they access. This is what "AI didn't wait for your governance policy" looks like in the data. Even when organizations want to understand their app footprint, the information simply is not there. The app with over 152,000 users across this dataset is a number. Today, six months from now, a year from now, it will still be a number. There is no way to know what it is, who maintains it, or whether the access it holds was ever intentional.
What Those Tools Walked Into
Before you can evaluate what AI access means for your organization, you need to understand the environment those tools landed in. We mapped it across email and Drive for every organization in the dataset.
The email findings were unambiguous. Of the 158 organizations with email monitoring enabled, every single one had sensitive data at significant scale.
This is not a sign of poor security hygiene. It is a sign of how enterprise systems are built: onboarding workflows email credentials to new users, vendors send login details to account managers, finance teams share payment information over email. These are normal operations. The accumulation is invisible until someone measures it.
How AI Access Works Through OAuth
1. An employee authorizes an AI tool with a single click.
2. The tool receives a persistent token linked to that employee's Google account.
3. It can now read every file the employee can open and every email in their inbox.
4. This access persists until it is explicitly revoked, regardless of subsequent policy changes.
5. There is no separate permission layer between the employee's access and the tool's access.
Drive told the same story. Among the organizations with Drive monitoring in place, 63 percent had files flagged for sensitive content by Google's own DLP classifiers. Source code was the largest single category, hundreds of millions of files containing API keys, database credentials, and deployment configurations. Payroll records, financial models, and files containing Social Security Numbers were present across the dataset at significant scale.

The Course-Correction and the Gap It Leaves
This is where the two trends collide.
Starting in late 2025, something made organizations start aggressively cleaning up file access. Security and IT teams began asking harder questions about what AI tools could reach and tightening the controls they had. The behavioral shift in the data is clear and consistent across the dataset.
The effort is real. But there is a critical distinction between what those controls address and what AI access actually requires.
Restricting Drive sharing permissions determines who can view a file going forward. It does not revoke OAuth access that was already granted. An AI tool authorized before those controls were put in place retains the access it received at that moment, across email and Drive, regardless of what has been cleaned up since.
Sharing controls and AI access controls are two different problems. Most organizations are actively working on one. Almost none are systematically working on both.
What the Full Investigation Covers
The data in this investigation represents the actual state of AI adoption in enterprise Google Workspace environments, not projections or policy assessments. It covers the complete sensitive data landscape across 159 organizations, the OAuth application footprint including the specific patterns that make certain applications impossible to identify from log data alone, and the access behavior trends that reveal how organizations are changing in response to the AI adoption pressure they are already under.
Three Questions to Ask About Your AI Footprint
1. What sensitive data exists in the environments AI agents will access?
2. Which AI apps are connected, and what are they actually reading?
3. Is there a way to detect and respond when access patterns change?
The organizations that will scale AI most confidently are the ones that looked at their environment before they scaled. The data exists. The analysis is done.

