Google Drive rolls out AI ransomware detection to all users, detecting 14x more infections

3 Sources

Share

Google Drive has expanded its AI-powered ransomware detection to all Workspace users after successful beta testing. The security upgrade automatically pauses file syncing when threats are detected and now identifies 14 times more infections than the initial beta version. Available by default for business, enterprise, education, and frontline licenses, the feature helps organizations prevent widespread data corruption.

Google Drive Expands AI-Powered Ransomware Detection to All Users

Google Drive has officially rolled out its AI-powered ransomware detection feature to all Workspace users after completing beta testing that began in September 2025

1

. The security upgrade is now enabled by default for organizations with business, enterprise, education, and frontline licenses, marking a significant expansion in cloud storage security for millions of users

2

.

Source: BleepingComputer

Source: BleepingComputer

The feature leverages AI security trained on millions of real-world ransomware samples to identify maliciously modified files. When the system detects unusual activity suggesting a ransomware attack, it automatically pauses file syncing to prevent widespread data corruption across an organization's Drive

1

. This immediate response helps protect files stored in Drive, even when the compromised computer's local files are being encrypted

2

.

Detection Capabilities Improve 14x Since Beta Launch

Google reports substantial improvements since the initial beta deployment. The latest AI model now detects 14 times more infections compared to the beta version, delivering more comprehensive malware protection for Google Workspace users

2

3

. This enhancement reflects continuous refinement of the detection engine, which adapts to novel ransomware by analyzing file changes and incorporating new threat intelligence from VirusTotal

1

.

When ransomware-encrypted files are detected during desktop sync, affected users receive email alerts and notifications directly in Drive. IT administrators also receive alerts through the Admin console and can review detailed audit logs from the security center

2

. This multi-layered notification system ensures rapid response and data loss prevention across organizations.

Source: Android Police

Source: Android Police

File Restoration Capabilities Minimize Disruption

Beyond detection, Google Drive now offers robust recovery capability through its file restoration tool. After an attack is blocked, users receive detailed instructions to restore corrupted files by navigating to Settings > Restore file versions

1

. This rapid recovery helps minimize user interruption and data loss, even when working with traditional software such as Microsoft Windows and Office

1

.

The file restoration feature is available to all Google Workspace customers, Workspace individual subscribers, and users with personal Google accounts

2

. This broad availability ensures that organizations can quickly undo ransomware changes and retrieve clean versions of their data without extensive downtime.

Desktop-Only Limitation and Admin Controls

The feature comes with notable limitations. Ransomware detection only works with the desktop app on Windows and macOS, requiring version 114 or later for full detection alerts

1

2

. While file syncing will still pause on older versions, organizations should update to the latest version for complete protection.

Only IT administrators can control the feature through the Admin console under Apps > Google Workspace > Settings for Drive and Docs > Malware and Ransomware

1

. This centralized control allows organizations to manage security policies consistently, though individual users cannot toggle the feature themselves. Administrators can also adjust detection levels to align with specific workflow requirements

3

.

Competing with Microsoft and Dropbox in Cloud Security

Google's move positions Drive competitively against other cloud storage platforms. Microsoft offers similar OneDrive ransomware detection and recovery for Microsoft 365 subscribers, while Dropbox provides comparable features to customers on Business Plus, Advanced, or Enterprise plans

2

. As ransomware attacks continue to evolve and target cloud-connected systems, these protective measures become increasingly critical for organizations managing sensitive data across multiple devices and platforms.

Today's Top Stories

TheOutpost.ai

Your Daily Dose of Curated AI News

Don’t drown in AI news. We cut through the noise - filtering, ranking and summarizing the most important AI news, breakthroughs and research daily. Spend less time searching for the latest in AI and get straight to action.

© 2026 Triveous Technologies Private Limited
Instagram logo
LinkedIn logo