What’s worse than a robot reading your emails? A robot reading your emails if you never consented to such a thing-or at least that’s the fear driving a wave of public confusion around Google’s Gemini AI and Gmail’s “smart features.” The company insists that’s not what’s happening, but the controversy reveals just how easily technical settings, vague language, and evolving AI integrations can set off privacy alarms.

The ambitious proposed class‑action lawsuit, which was filed in federal court in San Jose earlier this month, alleged that Google had “secretly turned on Gemini for all its users’ Gmail, Chat, and Meet accounts” on October 10, 2025. In the complaint, it is said that the AI assistant was given access to “the entire recorded history” of private communications without user consent, possibly in violation of the California Invasion of Privacy Act. For their part, plaintiffs argue that the only way to disable Gemini is to navigate deep into privacy menus an obstacle most users won’t overcome.
Googles’ official response to the problem was candid: “These reports are misleading – we have not changed anyone’s settings. Gmail Smart Features have existed for many years, and we do not use your Gmail content for training our Gemini AI model. Lastly, we are always transparent and clear if we make changes to our terms of service and policies.” The company argues that while Gmail scans the content to power some built‑in functions, such as spam filtering, categorization, and predictive text, it is operational processing, not AI model training.
The confusion comes from a recent rewrite and repositioning of Gmail’s smart feature settings. Malwarebytes, the security firm that first gave the most weight to the allegations, later conceded that it had “contributed to a perfect storm of misunderstanding” when it misinterpreted the changes. The features themselves-Smart Compose, Smart Reply, and personalized search-are nothing new, but their being turned on by default has raised some eyebrows. Several accounts tested showed all three relevant settings turned on by default, including on newly created profiles.
Technically, these smart features rely on the content scanning and classification systems operating within Google’s infrastructure. The email text and metadata are parsed by algorithms for spam signature identification, phishing pattern detection, and the context‑aware generation of suggestions, among others. In a way, this is how things work-similar to how the classifiers that populate Gmail category tabs work from the aggregate usage patterns, as opposed to through individual model fine‑tuning. Here lies a very crucial difference, in that large language models like Gemini need voluminous, diverse training sets from public web content, licensed corpora, and synthetic data-never from isolated, private inboxes.
Yet, from a governance perspective, the optics are problematic. Well-documented is the voraciousness of AI development for data, with model parameter counts ballooning from billions into hundreds of billions in only a few short years. Said policy analyses note that such scale incentivizes platforms to widen the scope and duration of data collection. Even anonymized datasets can be re‑identified through cross-referencing from other sources; it allows one to make inferences on income, relationships, or political leanings.
While already promulgated are strict limits for the processing of personal data for AI in the EU, including under the General Data Protection Regulation and proposed AI Act, those include opt‑out rights for automated decision‑making and transparency about training sources. Binding federal law in the United States does nothing to rein in AI privacy, relying on companies to self‑define how their AI products and services work under voluntary guidelines like the Blueprint for an AI Bill of Rights. This will leave room for misunderstandings, especially in a setting where defaults are set to “on” and the consent mechanisms are buried.
From a cybersecurity perspective, any system that scans and processes private communications increases the attack surface. Prompt injection attacks against AI‑powered assistants could theoretically extract sensitive data if safeguards fail. Although Google’s smart features are not generative AI endpoints in the same way as Gemini’s chat interface, the integration of AI summarization and drafting tools into Workspace blurs functional boundaries. The lawsuit’s allegations, even if technically inexact, illustrate the risk of public conflation between operational processing and model training.
As Krystyna Sikora with the Alliance for Securing Democracy aptly summed it up: “Unsurprisingly, this lack of transparency can create significant confusion that in turn can lead to fear‑mongering and the spread of false information about what is and is not permissible.” In practice, the decision confronting users is a trade‑off: smart features on for convenience or off to limit data processing. To turn them completely off requires toggling three different settings: “Smart features in Gmail, Chat, and Meet,” “Smart features in Google Workspace,” and “Smart features in other Google products”; each controls different scopes of content analysis and personalization.
Whether or not Gemini ever touched private Gmail content, the episode underlines a broader challenge in AI governance: to make sure technical distinctions among data processing types are clearly communicated, consent is genuinely informed, and defaults respect privacy as much as they do product engagement.

