Gmail reads your emails to train its AI, and you probably haven't turned it off
Google has just crossed a line. And as so often, without fanfare. For a little while now, Gmail can automatically analyse the content of your messages and attachments, not to filter spam or offer you an automatic reply, but...

This is not just another harmless update. Over the past few days, several Gmail users have discovered that their settings were changed by default to let Google analyse the content of their emails and attachments in order to train its artificial intelligence models. Translation: your private correspondence becomes raw material for Gemini, the new in-house AI. And if you touch nothing, it is all switched on.
Officially, Google wants to improve Smart Compose or smart replies, those automatic suggestions that finish your sentences. Unofficially? It is a deep shift in what we still consider to be "our" data.
When the "privacy" box is ticked by default against you
The most troubling part here is not the use of AI. It is the method. Google switched these settings on without asking for your explicit consent. No intrusive pop-up. No acceptance window. Just a ticked box, buried deep in the settings, that you will only find if you go actively looking for it.
This is a dark pattern: a gentle manipulation that relies on user inertia. They are betting you will change nothing. And Google wins that bet 99% of the time.
Does Gmail really train its AI on your emails?
Let us set out the facts, because they matter. On 21 November 2025, Google publicly denied it: "We do not use your Gmail content to train our Gemini AI model." The company insists it has not changed anyone's settings, and points out that its smart features have been around for years.
Malwarebytes, whose alert lit the fuse, has since corrected its article: Gmail does analyse the content of your messages, but in order to run its own tools, spam filtering, sorting into categories, writing suggestions, which is not the same thing as training a generative AI. Those features go back to 2017. The panic of November 2025 was born of Google rewording and moving these settings, with new wording so vague that it invited confusion.
Does that close the file? No. The denial turns on a single word, "train". It says nothing about the rest: the content of your emails is still read, the settings were rewritten without anyone asking your opinion, and the burden of saying no still sits with you. In the United States, a class action, Thele v. Google, filed on 11 November 2025 before a federal court, accuses the company of switching its Gemini AI on across Gmail, Chat and Meet on 10 October 2025 without consent, and of accessing the history of private communications, in breach of several privacy laws. The substance of the complaint is exactly mine: the method.
That claim has since suffered a first setback. On 7 July 2026, federal judge Noël Wise, of the Northern District of California, dismissed the case for lack of standing: the plaintiffs had not established any concrete injury, only the fact that Gemini could access their data. They had so far only alleged that Gemini might be used to track their data, she wrote, which is not enough to establish a real harm, while allowing them to file an amended version. The judge did not say that Google was right on the merits; she said the harm had not yet been proved to her. The objection about the method remains entirely intact.
An AI with access to your secrets: what are the risks?
Let us be clear: whether or not Gemini is fed directly on your messages, these features do reach the content of your messages, your attached files, your writing habits. Even if Google promises anonymisation and secure processing, this remains direct access to what you consider private.
This raises three major problems:
- Biased consent: you did not really agree. You were made to consent by default.
- Functional opacity: it is impossible to know how your data is used, where it is stored, by whom it will be re-read, corrected, or exploited.
- Snowball effect: if Google does it, others will follow. And tomorrow it will be your work messages, your legal documents, your medical conversations.

In France, are these features switched on by default?
Good news for French readers: in principle, no. In the European Economic Area, which includes France, but also in the United Kingdom, Switzerland and Japan, Gmail smart features are switched off by default. The reason comes down to four letters: the GDPR. Where the rules are strict, Google has to obtain consent before using your data for these purposes; where they are looser, as in the United States, everything is on by default and it is up to you to go and flip the switch.
This is exactly what I argue: what protects the user is not a platform's goodwill, it is the rule of law. We saw it again when Google started switching on Gemini-generated email summaries by default for some accounts, in English first: there too, the feature stayed off by default in the European Union, the United Kingdom, Switzerland and Japan. The shield is not technical. It is legal. All the more reason to strengthen it rather than weaken it.
And that shield has teeth. On 1 September 2025, the CNIL fined Google 325 million euros, 200 million against Google LLC and 125 million against Google Ireland, in particular for slipping advertisements between Gmail users' emails without their consent, together with an order to stop within six months or pay 100,000 euros a day. No promise of anonymisation, no code of good conduct would have produced that result. It took a binding rule and a regulator determined to enforce it.
What this says about our relationship with the digital world
This is not a technical question. It is a question of digital civilisation.
We live in an age where technology moves faster than the legislative, ethical or civic safeguards. When you use Gmail, you are not just a customer: you are a training vector for AIs that know you better than you know yourself.
We are promised productivity gains, more relevant assistants, a smoother digital life. In reality, we are being stripped of cognitive sovereignty over what we write, think and share.
How do you turn off Gmail smart features?
In practice, it all happens in two places, and you have to act on both. In your Gmail settings, untick "Smart features in Gmail, Chat and Meet". Then turn off "Smart features in Google Workspace" and "in other Google products", filed somewhere else entirely. Until both of those settings are switched off, the opt-out is not complete.
Most articles stop there. That is useful. It is not enough.
What we need is to raise the level of public debate around what must remain inalienable in a digital world.
- Your messages should never be analysed without your explicit, and informed, consent.
- An AI should not be able to be fed on private conversations without individual consent.
- The digital giants must take on duties of loyalty towards users they know to be passive, sometimes vulnerable, often poorly informed.
Beyond the setting, three reflexes:
- Inform those around you, your colleagues, your clients. If you manage sensitive data for others, you have a responsibility.
- Ask the question of your digital providers: where does my data go, who reads it, what for?
- Campaign for strong European regulation on the use of personal data for AI training purposes. The GDPR was a first step. It is time to move to the next one.
A digital culture to (re)build
This subject ties in with what I defend in my book Être en cybersécurité: you cannot protect what you do not understand.
Every time a platform pushes its users towards more simplicity at the expense of control, it chips away at their autonomy. And every time we give ground on these small details, a box ticked here, a vague authorisation there, we build a society of technological dependency.
Yet a healthy digital democracy rests on three pillars:
- Transparency in the rules of the game,
- Informed consent from users,
- The ability to refuse without functional penalty.

This is not a battle against artificial intelligence. It is a battle for a human intelligence of the digital world.
Because a tool, however powerful it may be, should never decide for you what it does with your privacy.
Sources
- Google's denial, "We do not use your Gmail content to train our Gemini AI model" (21 November 2025): 9to5Google and Vert.
- Correction of the original alert and the actual role of the smart features (sorting, categorisation, suggestions), in place since 2017: Malwarebytes and Vert.
- Smart features switched off by default in the European Economic Area, the United Kingdom, Switzerland and Japan; Gemini email summaries switched on by default elsewhere: KultureGeek and Malwarebytes.
- Class action Thele v. Google filed on 11 November 2025, alleged activation of Gemini on 10 October 2025 without consent: Top Class Actions and classaction.org.
- Dismissal of the Thele v. Google claim on 7 July 2026 by Judge Noël Wise (Northern District of California) for lack of concrete injury, with leave to refile: Bloomberg Law and Law Commentary.
- 325 million euro fine imposed on Google by the CNIL on 1 September 2025 for advertisements inserted between Gmail messages without consent: CNIL.
- Google's position on Gmail entering "the Gemini era": Google's official blog.
- Further analyses of the controversy: PC Gamer and TechRepublic.
Frequently asked questions
Does Gmail really train its AI on my emails?
Google denies it. On 21 November 2025 the company stated that it had not changed anyone's settings and that it does not use Gmail content to train its Gemini AI model. Malwarebytes, which raised the original alert, has corrected its article: the smart features do read your emails, but to sort them, categorise them and suggest replies, not to train the generative AI.
What do Gmail smart features actually do?
They have existed since 2017. By analysing your messages, they sort emails into categories (primary, promotions, spam), offer automatic replies and complete your sentences. The confusion of November 2025 came from Google rewording and moving these settings, with new wording so vague that it invited confusion.
In France, are these features switched on by default?
In principle, no. In the European Economic Area (which includes France), the United Kingdom, Switzerland and Japan, smart features are switched off by default under the GDPR, and Google has to obtain consent. In other regions, such as the United States, they are on by default. It is still worth checking your own settings.
How do I turn these features off in Gmail?
In your Gmail settings, untick "Smart features in Gmail, Chat and Meet", then turn off "Smart features in Google Workspace" and "in other Google products". These settings sit in two different places; you have to act on both for the opt-out to be complete.
Is there a lawsuit against Google about this?
Yes, in the United States. The class action Thele v. Google, filed on 11 November 2025 in a federal court, accused Google of switching Gemini on across Gmail, Chat and Meet on 10 October 2025 without consent. On 7 July 2026, Judge Noël Wise dismissed the claim for lack of standing, finding that the plaintiffs had shown no concrete injury; she did, however, allow them to file an amended version. The merits have therefore not been settled.
Has the CNIL already fined Google over Gmail?
Yes. On 1 September 2025 the CNIL fined Google 325 million euros, 200 million against Google LLC and 125 million against Google Ireland, in particular for inserting advertisements between Gmail users' emails without their consent, with an order to stop within six months. It illustrates that data protection in France rests on the rule of law, not on the goodwill of the platforms.
Why is turning off the option not enough, according to the author?
Because the subject goes beyond the individual setting: it calls for informing those around you and your clients, questioning your providers about how data is used, and campaigning for strong European regulation on training AI from personal data.
Sources & methodology
- Malwarebytes (Correction),
- 9to5Google, Google says Gemini isn't trained on Gmail, pushing back on 'misleading reports',
- Vert, Google dément lire nos e-mails pour entraîner sa super IA Gemini,
- KultureGeek, Gmail se met à résumer les e-mails avec l'IA Gemini par défaut,
- classaction.org, Thele v. Google LLC,
- Bloomberg Law, Google Beats Suit Over Data Tracking by Gemini AI Assistant (dismissal of the Thele suit, 7 July 2026),
- CNIL, 325 million euro fine against Google for advertisements inserted between emails and for cookies (1 September 2025),
- Top Class Actions,
- PC Gamer (Google spokesperson quoted),
- TechRepublic,
- Google (official blog) - Gmail is entering the Gemini era,

Être en cybersécurité
A cyber roadmap in plain language, for everyone, not just the experts.
