
How to disable AI features in Google Workspace
Updated
On January 28, 2026, the Information and Privacy Commissioner of Ontario published “AI Scribes: Key Considerations for the Health Sector.” The document focuses on AI scribes in clinical settings. The principle it applies, that consent is generally required because no PHIPA provision exempts the processing, is not specific to scribes: it reaches any AI tool that processes personal health information.
That’s a notable statement. Health information custodians don’t normally need separate consent for the technology they use to process PHI. The IPC’s position is that no PHIPA provision permits AI scribe processing without consent, so consent is required. Separately, it identifies the risks custodians have to address with this technology: data used for model training, bias in outputs, and disclosure to third party vendors.
Google Workspace has several AI features turned on by default. Smart Compose reads your email as you type to suggest completions. Smart Reply scans incoming messages to generate quick responses. Then there’s Gemini, which goes further: it can summarize entire email threads, draft replies, analyze documents, and generate meeting notes. All of these process the content of your communications.
If those communications contain PHI, and you haven’t obtained consent for AI processing, you have a gap in your PHIPA compliance for email.
Alberta’s HIA and BC’s PIPA have comparable safeguard provisions, and AI specific guidance already exists in Alberta: OIPC Alberta published its AI Scribe Privacy Impact Assessment Guidance in September 2025, and the commissioners have issued joint resolutions on AI.
That gap is real. The shape of it is narrower than the headlines suggest, though, and it’s worth knowing which part is which before you start flipping switches. This guide covers what each Google Workspace AI feature does with client email, which ones to turn off, and where each control lives. For the broader question of whether Gmail belongs in a therapy practice at all, start with our guide on whether Gmail is PHIPA compliant. This piece picks up where that one leaves off: the specific toggles.
What are you actually protecting client email from?
Before turning anything off, it helps to know what you’re protecting against. Otherwise you end up flipping switches without knowing whether they matter.
Your obligation is the anchor. In Ontario, PHIPA s.12(1) requires a health information custodian to take steps that are reasonable in the circumstances to protect personal health information against theft, loss, and unauthorized use or disclosure. In Alberta, private practice therapists fall under PIPA, with College of Alberta Psychologists (CAP) standards on top. In British Columbia, PIPA s.34 sets a comparable safeguard duty. Different statutes, same direction: you’re responsible for where client information goes.
The phrase that does the work is “reasonable in the circumstances.” For mental health records, the most sensitive category most therapists handle, the bar sits higher than it would for a hardware store’s mailing list. A configuration that lets message content flow into systems you neither chose nor monitor is hard to defend as reasonable, even if nothing ever goes wrong.
Two boundaries that get confused
Google Workspace has two different data stories, and conflating them is where most of the fear comes from.
The first is Gemini and the AI features inside the core Workspace services. When these process your content to draft a reply or summarize a thread, that processing is covered by your Workspace agreement and the Cloud Data Processing Addendum. Google’s stated commitment for these core services is that your content is not reviewed by humans or used to train its generative models outside your domain without your permission. That commitment is the reason core Gemini is a manageable risk rather than an open door.
The second story is personalization that reaches into other Google products. This is the part worth your attention. Settings exist that let your Gmail content feed features and personalization across Google services sitting outside the Workspace core service boundary. That’s a different posture from drafting a reply inside your governed inbox, and it’s the surface a careful therapist closes.
So the question for each AI feature comes down to one thing. Does it keep client content inside the boundary you’ve agreed to and can account for, or does it let that content travel somewhere you can’t see?
The practical upshot: you’re not trying to stop Gemini from “training on your clients,” because the agreement already addresses that for the core service. You’re keeping client content inside the boundary you can account for, and switching off the paths that carry it outside.
Which Google Workspace AI features should you disable?
There are three categories of AI feature, each controlled separately in the admin console:
Pre Gemini ML features (on by default for most regions):
- Smart Compose (predictive text while typing)
- Smart Reply (suggested short replies)
- Smart features (calendar event suggestions, package tracking cards, travel itinerary cards)
Gemini features (included and on by default across all Business editions; Business Starter gets Gemini in Gmail and the Gemini app, while the side panel across Docs, Sheets, Slides, and Meet needs Business Standard or higher):
- “Help me write” in Gmail and Docs
- Gemini side panel in Gmail, Docs, Sheets, Slides, Drive, Chat
- “Take notes for me” in Google Meet
- AI generated summaries and image generation
Gemini app (gemini.google.com):
- Standalone AI chat interface
- Deep Research (NotebookLM is a separate service with its own on/off control, not part of the Gemini app)
The distinction matters because each has its own admin toggle. Disabling Gemini does not disable Smart Compose. Disabling Smart Compose does not disable Smart Reply. You need to address each one.
One thing to know before you start: these settings aren’t turned off by default in Canada. Google defaults them off for users in the European Economic Area, the United Kingdom, Switzerland, and Japan, which tells you something about how the company itself reads the privacy stakes. Canadian therapists have to turn them off deliberately.
Step 1: Start in the admin console, not in each inbox
If you run your own Google Workspace, and most solo therapists who pay for it do, the controls with the widest coverage live in the Admin console at admin.google.com, not in any individual inbox.
The reason to start here is coverage. An organization level setting applies to every user and every alias under your domain. It also removes the weak point you create when compliance depends on each person remembering to untick a box. Sign in as a super administrator before you begin. If you’re a one person practice, that’s you.
If you don’t control an admin console, skip to Step 4 and apply the Gmail settings to your own account.
Step 2: Turn off Smart features for Google Workspace at the org level
This is the account level control that governs smart features across your organization: automatic calendar event creation from emails, package tracking cards, travel itinerary summaries, and personalized search results in Drive.
Path: Admin console > Account > Account settings > Smart features for Google Workspace
The reference page for this setting is on Google Support. Not the most intuitive place to find it (Account settings, not Gmail settings), but that’s Google’s admin console for you. Turn smart features off at the organizational level. This is an account level setting, not a per app setting.
Google notes that settings like this can take up to 24 hours to apply across an organization, though it’s often faster.
What changes: This is the toggle with the widest impact. You lose:
- Automatic calendar events created from flight/hotel bookings in email
- Package tracking summary cards
- Travel itinerary compilation
- Loyalty card and boarding pass surfacing in Google Wallet
- Personalized search suggestions in Drive
For most therapy practices, none of these are critical. You’re not getting flight booking confirmations in your practice inbox. If you do use a shared practice inbox for administrative purposes and rely on these features, consider creating a separate organizational unit for admin accounts and only disabling smart features for clinical accounts.
One caveat. The org level control sets the default. Users can still change smart features in their own Gmail settings, so treat this as policy plus a default rather than an enforced lock, and confirm the per account settings in Steps 4 and 5.
Workaround: Add calendar events manually. Track packages on carrier websites. Small inconveniences compared to having Google’s AI scan every email in your inbox.
Step 3: Turn off Smart Compose and Smart Reply
Smart Compose watches what you type in Gmail and suggests how to finish your sentences. Smart Reply scans incoming messages and generates three short response suggestions at the bottom (“Sounds good!”, “Thanks!”, “I’ll look into it”). Both read message content to do it.
Neither has a dedicated org wide kill switch in Gmail. Both follow the smart features setting you turned off in Step 2, which is why Steps 4 and 5 still matter even if you’re an admin.
Google Docs is the exception. Smart Compose there has its own toggle:
Path: Admin console > Apps > Google Workspace > Drive and Docs > Features and Applications
Find Smart Compose and turn it off.
What changes: No more grey text suggestions while typing, and no suggested reply buttons at the bottom of emails. That’s it. Spell check, grammar check, and all formatting tools still work. You type the whole sentence yourself.
Workaround: There isn’t one built into Google. If you find yourself typing the same phrases repeatedly, Gmail’s Templates feature (Settings > Advanced > Templates) lets you save and insert canned responses. These are stored text, not AI generated.
Step 4: Turn off smart features in Gmail, Chat, and Meet
The next two settings live in Gmail rather than the admin console. Check them on your own account whether or not you run an admin console.
Open Gmail, click Settings (the gear), then See all settings, then open the General tab. Scroll to the option labelled Smart features in Gmail, Chat, and Meet and turn it off. This governs whether Gmail, Chat, and Meet use your content to provide smart features like Smart Compose and summary cards.
Turning this off changes how your inbox behaves. Some conveniences disappear. That trade is yours to make, and for an inbox full of clinical correspondence, many therapists decide the quieter inbox is the better deal.
Step 5: Turn off smart features in other Google products
On the same General tab, there’s a second, separate setting: Smart features in other Google products. Turn this one off too.
This is the setting that matters most for the worry you started with. Google describes it as controlling use of your Workspace data to provide smart features in other Google products, examples being restaurant reservations in Maps and passes in Wallet. That’s the path carrying content outside the Workspace core service boundary. One detail to know: this setting can only be turned on from a web browser, not the mobile app. So do it from a computer.

Step 6: Set Gemini access deliberately
Gemini is Google’s generative AI layer. It’s more capable than Smart Compose or Smart Reply, and it processes content more aggressively: summarizing threads, drafting full emails, analyzing spreadsheet data, generating meeting notes.
A heads up before you start: some Google Workspace admins have reported that the Gemini disable toggles don’t appear in the admin console until you contact Google Support to have them surfaced. If you don’t see the Generative AI section in your admin console, open a support case with Google. This is a known issue that Google has acknowledged.
Path: Admin console > Generative AI > Gemini for Workspace > Feature access
Here you’ll see individual toggles for each Google Workspace app. Click Edit next to each service (Gmail, Docs, Meet, Sheets, Slides, etc.) and set it to Off. Click Save after each change.
For the standalone Gemini app:
Path: Admin console > Generative AI > Gemini app
Toggle this off to prevent users from accessing gemini.google.com with their work account. Under Service status you can also scope it to a specific organizational unit or group rather than turning it off for everyone.
This step is more of a judgment call than a clear off. Gemini for Workspace is a core service, governed by the same agreement and data processing terms as the rest of your Workspace, so keeping it on doesn’t hand your client email to Google’s public models. The decision is about whether you and your team should have the feature available and whether you’ve read what it does, not about plugging an external leak. If you’d rather not have AI drafting in your inbox until you’ve evaluated it, turn it off. If you want it, leave it on knowing the core service protections apply.
What changes: All AI powered drafting, summarization, and analysis in Workspace apps goes away. No “Help me write,” no side panel summaries, no AI meeting notes. Standard features all work: you can still compose emails, create documents, run meetings, and record them (where permitted). The pre Gemini ML features (Smart Compose, Smart Reply) are controlled separately and remain in whatever state you set them.
Workaround: If staff need AI drafting tools for non clinical work, they can use third party tools like ChatGPT or similar in a separate browser profile that isn’t logged into the practice’s Google account. This keeps AI processing away from the Workspace data that contains PHI. Note: any PHI pasted into a third party AI tool creates its own consent and data processing issues.
Step 7: Record what you set and when
Make a short note of the configuration you chose and the date you applied it. A line in whatever you use for practice records is enough.
This isn’t busywork. PHIPA s.12(1) asks for reasonable steps, and a custodian who can show the privacy settings they applied, and when, is in a far stronger position than one relying on memory. The point isn’t to predict a complaint. It’s that if a question ever comes, the answer already exists in writing instead of depending on what you think you remember configuring two years ago.
Where this gets complicated
The steps above hide a few edges worth naming honestly.
Turning off smart features removes useful things. Suggested replies, automatic filtering, and event detection all lean on the features you just disabled. This is a real trade, not a free win. Decide it on purpose: for an inbox of clinical email, the reduced surface is usually worth more than the autocomplete.
No retroactive deletion. Google doesn’t offer a way to delete data that Smart Compose or Smart Reply already processed. The processing happens in real time and Google states it doesn’t retain the content for model training when the BAA is in place, but there’s no audit confirming this.
Data still lives in the US. Disabling AI features doesn’t change where your email is stored. Google Workspace data regions offer US, Europe, or No Preference. Canada isn’t an option. If data residency is a concern, see our admin console security settings guide for the full picture.
These settings are not the whole compliance picture. Switching off cross product personalization is one safeguard among several. It doesn’t encrypt the message body, it doesn’t give you an audit trail of what you sent, and it doesn’t change where Gmail stores message content. It closes one specific path.
Even with AI features off, you still need a mechanism to track client consent for electronic communication of PHI. The admin console doesn’t provide this, and it’s worth solving separately.
Third party add ons may have their own AI. If you’ve installed Chrome extensions, Gmail add ons, or third party apps that connect to your Workspace data, those may have AI processing of their own. Audit your installed apps under Admin console > Apps > Marketplace apps.
Settings drift, and so do labels. Google changes its product surfaces and the exact wording of these controls more often than anyone would like. The paths in this article were verified in July 2026. If a menu doesn’t match, search Google’s admin and Gmail help for “smart features” and “Gemini” rather than assuming the feature moved out of reach.
“PHIPA compliant” was never a setting. No Ontario regulator certifies a configuration as compliant, and no checkbox transfers your responsibility. Under PHIPA s.17(1) a custodian stays accountable for personal health information in its custody or control, including what a service provider acting as your agent does with it. Turning these toggles off is you discharging that accountability, not Google taking it off your plate.
When a privacy question touches a real client situation, a possible breach, or a complaint, talk to a privacy professional or your liability advisor. This article orients you; it doesn’t replace advice on your specific facts.
What does the IPC’s AI guidance actually require?
The IPC’s January 2026 guidance was written for AI scribes, not for Gmail’s autocomplete. But the underlying principle is the same: when AI processes health information, patients should know about it and have the option to say no. We go through that guidance in more detail in AI and client health data under PHIPA in Ontario.
The guidance specifically requires “knowledgeable consent,” meaning patients understand: (a) that AI is being used, (b) what information it processes, (c) which vendors are involved, (d) the key risks, (e) what data is shared and why, and (f) the risk of bias. It also states that patients who withhold consent must receive the same quality of care.
For a therapy practice using Google Workspace, the practical question is: did you tell your clients that Google’s AI reads their emails to generate autocomplete suggestions and summaries? If not, the safest path is to disable these features until you have a consent process in place, or to disable them permanently and avoid the issue entirely.
For most solo therapists, disabling permanently is the right call. The productivity loss is minimal. The compliance risk of leaving them on is not.
Frequently asked questions
Does Google use my Gmail client email to train its AI?
For the core Workspace services, Google’s stated commitment is that your content isn’t used to train its generative models outside your domain without your permission, and isn’t reviewed by humans for that purpose. The exposure to manage is the “Smart features in other Google products” setting, which can route your content into smart features outside that core service boundary.
What’s the difference between the smart features settings in Gmail?
There are three, and they work independently. “Smart features in Gmail, Chat, and Meet” governs features inside those three products, such as Smart Compose and summary cards. “Smart features in Google Workspace” governs features that span Workspace products, such as showing Gmail events in Calendar. “Smart features in other Google products” governs whether your Workspace data provides smart features outside Workspace entirely, such as reservations in Maps or passes in Wallet. For client email, the third one matters most.
Google has renamed these settings before, so if the labels in your account don’t match, check Google’s current help documentation rather than assuming a setting was removed.
Should I turn Gemini off completely?
Not necessarily. Gemini for Workspace is a core service governed by your Workspace agreement and Cloud Data Processing Addendum, so it doesn’t expose client email to Google’s public models. Treat it as a feature decision: turn it off if you’d rather not have AI in your inbox yet, or leave it on knowing the core service protections apply.
Do these settings make my Gmail PHIPA compliant?
No single setting does that. PHIPA governs your conduct as a custodian, not Google’s product. Under PHIPA s.12(1) you must take reasonable safeguards, and under s.17(1) you stay accountable for your agents. Turning off cross product personalization is one reasonable safeguard among several, not a compliance certificate.
I see clients in more than one province. Does this change anything?
The Google steps are the same everywhere. The law behind them shifts: Ontario clients engage PHIPA, Alberta clients engage PIPA and College of Alberta Psychologists standards, BC clients engage PIPA, and email crossing provincial lines can also engage PIPEDA. The safeguard direction is consistent across all of them.
Close the path before you forget it’s open
You don’t need to migrate off Google Workspace to handle this. You need to know which settings carry client content outside the boundary you can account for, turn them off, and write down that you did.
If you haven’t already locked down the rest of your admin console, the full security settings guide for Canadian therapists covers the BAA, data regions, 2FA enforcement, sharing permissions, and email compliance settings.
What turning these toggles off doesn’t do is encrypt the email itself or log what you sent. If you want your Gmail encrypted for Canadian mental health privacy law, with every send recorded in a Canadian audit trail, and without leaving the inbox you already use, join the Curio waitlist.
This content is for informational purposes only and does not constitute legal advice. Privacy regulations vary by province and are subject to change. Verify current requirements with your provincial regulatory body and the Office of the Information and Privacy Commissioner for your jurisdiction.
Curio is designed to encrypt outbound email and maintain a Canadian audit trail. It is not a substitute for professional legal or compliance advice. Consult a qualified privacy professional for your specific situation.
Coming soon
Gmail encryption, built for Canadian therapists.



