Google Workspace gets two new DLP controls for Gemini and agentic flows
From 20 August 2026, Workspace admins gain Gemini DLP and Agent DLP: runtime controls to protect sensitive data in AI and automated workflows.
Google is giving Workspace admins two new tools to control how sensitive data flows through AI and automated workflows. From 20 August 2026 on Rapid Release domains (1 September 2026 for Scheduled Release), two new runtime data loss prevention policy types become available: Gemini DLP and Agent DLP.
These are not broad policy toggles. They are runtime controls that evaluate data conditions at the moment something is happening, whether that is Gemini reaching into Drive or an automated flow processing information on a user’s behalf.
What Gemini DLP does
Gemini DLP restricts Gemini’s ability to access Drive data based on content conditions and labels. In practical terms, this means you can configure a policy that stops Gemini from reading files that contain, for example, personally identifiable information or documents labelled as confidential, even if the user requesting that access would normally be allowed to see those files themselves.
Google has noted that support for additional services beyond Drive is coming, though no specific timeline has been given.
For organisations that have been cautious about enabling Gemini broadly because of concerns about what it might surface or summarise from sensitive documents, this is a meaningful addition. It gives admins a way to draw a clear line between what a human can access and what Gemini can access, enforced at runtime rather than relying solely on file permissions.
What Agent DLP does
Agent DLP applies to Workspace Studio flows, which are the no-code automated workflows users can build to handle tasks like drafting emails, processing information from Drive, or taking action in other Workspace services.
The control works at the level of the data involved in the flow, specifically what data the flow is pulling in, what it is processing, and what it is outputting. Based on those conditions, admins can either block the flow from executing entirely or require the user to review and approve it before it proceeds.
That second option, requiring end-user review, is particularly useful. It means sensitive workflows do not have to be blocked outright. Instead, there is a checkpoint: the flow pauses, the user is asked to confirm, and only then does it continue. This keeps automation useful while ensuring a human remains in the loop when the stakes are higher.
Who gets these controls
Both Gemini DLP and Agent DLP are restricted to higher-tier Workspace plans. Specifically, they are available on Frontline Standard and Frontline Plus, Enterprise Standard and Enterprise Plus, Education Fundamentals, Education Standard, and Education Plus, and Enterprise Essentials Plus.
The broader Workspace Studio security features announced alongside these controls (including agent identities, audit logging, and the Agent Access Management dashboard) are available more widely, including on Business Starter, Standard, and Plus plans.
If your organisation is on a mid-tier plan and you were hoping these DLP controls would be included, they are not. This is one to raise with your account team if data protection in agentic workflows is a priority.
The broader picture
These two controls do not exist in isolation. Google has been building out a broader governance layer for agentic tools throughout 2026. The AI Control Center, announced in May 2026, gives admins a central place to monitor and manage how AI features interact with Workspace data. The Agent Access Management dashboard, part of this same August 2026 release, lets admins suspend flows or revoke specific OAuth scopes for individual flows, and links directly from audit events to the management page to speed up incident response.
There is also improved audit logging: actions taken by Studio flows, such as edits to Drive files or emails sent via Gmail, now include flow context in the audit record, a unique flow identifier and the owner’s details. This makes it considerably easier to understand after the fact what an automated workflow actually did.
One important caveat on the audit and identity features: they apply to newly created flows only. Existing flows will gain support in a future update, so if you have flows already running in your environment, do not assume they are immediately covered by the new governance controls.
What this means for you
If you are an IT admin evaluating whether to enable Workspace Studio or Gemini features more broadly, these controls remove some of the risk that has made that decision complicated. You can now set policy on what Gemini is allowed to read, not just who is allowed to use Gemini. And you can require human approval for automated flows that touch sensitive data, rather than having to choose between enabling automation fully or blocking it entirely.
If you are a user who builds or uses Studio flows, you may find that some flows pause for your review in a way they did not before. That is intentional. The confirmation step is there because the admin has determined that the data involved warrants it.
For organisations in regulated sectors, combining Agent DLP with the new audit trail means you have both a preventive control and a forensic record, which is a more complete compliance position than either would provide on its own.
Rollout begins on 20 August 2026 for Rapid Release domains, with up to three days for the feature to appear. Scheduled Release domains will see a gradual rollout beginning 1 September 2026, with up to 15 days for full visibility. Admins can find setup guidance in the Workspace Studio admin guide and the specific DLP configuration documentation linked from the announcement.