Google Drive AI ransomware detection now protects all Workspace users with 14x better detection

Reviewed byNidhi Govil

4 Sources

Share

Google Drive has rolled out AI-powered ransomware detection to all Workspace users after months of beta testing. The feature, enabled by default, pauses file syncing when threats are detected and now identifies 14 times more infections than earlier versions. Users can restore clean file versions while IT admins receive alerts through the Admin console.

Google Drive Expands AI-Powered Ransomware Detection Feature to All Workspace Users

Google has officially rolled out its AI-powered ransomware detection feature to all Google Workspace users, marking a significant security upgrade for organizations relying on cloud storage

1

. After testing the tool with a limited group during its beta version last year, the feature is now enabled by default across business, enterprise, education, and frontline licenses

2

. The system leverages a specialized AI model trained on millions of real-world ransomware samples, designed to identify maliciously modified files and prevent widespread data corruption within organizations

1

.

Source: BleepingComputer

Source: BleepingComputer

The detection engine continuously analyzes file changes and incorporates new threat intelligence from VirusTotal, allowing it to adapt to novel ransomware threats as they emerge

1

. This proactive approach addresses the dangerous combination of ransomware threats and cloud storage, where malware can quickly encrypt files stored on internet servers, leaving users without easy recovery options

3

.

Source: TechSpot

Source: TechSpot

Detecting 14x More Infections with Enhanced AI Model

Since its debut in beta, Google's ransomware detection capability has improved dramatically. The latest AI model now detects 14 times more infections compared to previous versions, while also working faster to provide significantly stronger protection

2

. Thousands of users tested the tool during its beta phase, demonstrating its ability to scale reliably and achieve its intended purpose across diverse organizational environments

3

.

When the system identifies unusual activity suggesting a ransomware attack, it automatically pauses file syncing to prevent the spread of encrypted files across devices

1

. This immediate response helps minimize user interruption and data loss, even when traditional software such as Microsoft Windows and Office is involved

1

. While the feature won't prevent files on a compromised computer from being encrypted, documents stored in Google Drive remain protected and can be quickly restored once the malware infection is resolved

2

.

File Restoration Capabilities and Alert System

Beyond detecting potential ransomware activity, Google Drive now offers comprehensive file restoration capabilities that allow users to replace encrypted files with clean copies stored in the cloud

3

. Users can restore unaffected file versions by navigating to Settings > Restore file versions, with the ability to apply restoration to multiple files at once

1

. This recovery capability can save organizations both time and money by eliminating the need to pay ransoms

3

.

Source: Android Police

Source: Android Police

When ransomware-encrypted files are detected during syncing from a desktop computer to Google Drive, the system pauses desktop sync immediately

2

. Affected users receive alerts through multiple channels, including email notifications and desktop notifications, with detailed instructions for restoring corrupted files

1

. IT administrators also receive alerts through the Admin console's security center and can review the audit log to track incidents

1

.

Desktop App Requirements and Admin Controls

The ransomware detection feature works exclusively with the desktop app on Windows and macOS, requiring version 114 or later for detection alerts

1

. However, file syncing will still pause on older versions when threats are detected

2

. While the feature is enabled by default for all Google Workspace users, only IT administrators can control it through the Admin console under Apps > Google Workspace > Settings for Drive and Docs > Malware and Ransomware

1

.

Administrators have the flexibility to disable the feature for their entire organization if needed, and can also adjust detection levels to align with specific workflow requirements

4

. The file restoration feature is available not only to Google Workspace customers but also to Workspace individual subscribers and users with personal Google accounts

2

. Despite growing threats from emerging technologies, ransomware infections remain one of the most severe risks to user and business data, making this security upgrade particularly relevant for organizations heavily invested in Google's ecosystem

3

.

Today's Top Stories

TheOutpost.ai

Your Daily Dose of Curated AI News

Don’t drown in AI news. We cut through the noise - filtering, ranking and summarizing the most important AI news, breakthroughs and research daily. Spend less time searching for the latest in AI and get straight to action.

© 2026 Triveous Technologies Private Limited
Instagram logo
LinkedIn logo