Abstract illustration of a media and content panel on a dark teal background, representing generative-AI media tools and data exposure risk

Alert: Google now trains its AI on your Search, Lens and Translate media by default

Google has begun rolling out a new privacy setting, Search Services History, that by default lets it use the media you feed into everyday Google tools (photos taken with Google Lens, voice searches, Search Live recordings, uploaded files and translations) to train its AI models. For most personal Google accounts the setting arrives switched on, and it is reaching accounts gradually over the coming months.

The plain-English version: a tool almost every business already uses, that nobody thinks of as an “AI tool,” now defaults to feeding what you put into it into an AI-training pipeline. That is the textbook AI Leakage problem: sensitive data leaving your control through an approved, everyday tool.

What actually changed

Google is splitting its long-standing Web & App Activity control into two separate settings: Search Services History, which governs what gets saved and whether it can be used to train AI, and Personalized Recommendations, which governs tailored results and ads.

When Search Services History is on, Google saves your activity across Search, Maps, Shopping, Flights, Hotels, Translate and News. That includes your search queries, AI Mode responses, recordings and transcripts from the Search Live tool, voice searches, and images you upload to Google Lens. A separate Save Media sub-toggle covers images, files, audio and video specifically.

Per Google’s own support documentation, when saved media is used for training the copy is disconnected from your account and kept for up to four years, even if you later delete the original activity. Google says it applies filters to strip a broad range of identifying and sensitive information, and that it asks permission before any media is shared for human review. The rollout runs over the next few months; until your account migrates, these controls still sit under Web & App Activity, and accounts that already have Web & App Activity switched on are the ones that inherit the new setting in the on position.

Why this matters for a small business

The risk here is not the search box. It is the quiet, everyday ways staff push real work into Google through a personal account: photographing a printed contract, an invoice or a whiteboard with Lens; running a clause or a client’s message through Translate; a voice search that names a customer; a question put to AI Mode about a live deal. On the default settings, that media can now be saved and used to train Google’s models.

This is the “approved tools leak too” point we keep making (see AI Leakage vs Shadow AI). Shadow AI is the behaviour: people using a tool nobody signed off on. AI Leakage is the outcome: data leaving your control. Here the two meet inside a tool you would never have thought to put on a shadow-AI list.

And, as always, the tier matters. Consumer and personal Google accounts are the exposed ones. It is the same consumer-versus-Workspace split that already puts consumer Gemini at a higher risk rating than Workspace Gemini in our AI Tool Risk Directory.

What is not affected

Google’s documentation explicitly carves out accounts issued by an educational institution: those are not used to train its generative AI models by default. Search Services History also does not cover Chrome, the Gemini apps, Google Assistant or YouTube; each of those keeps its own separate history settings. And this is about media you put through Google’s Search services, not the contents of your Workspace Gmail or Drive.

If your team is on managed Google Workspace, your administrator controls access to these Search services, but do not assume that equals a training exemption. Google publicly confirms the education carve-out; it has not made the same blanket statement for every employer-managed account. Workspace admins should check their own organisation’s data settings rather than take protection for granted.

The New Zealand and Australian angle

Under the New Zealand Privacy Act 2020 (which applies to every business, with no small-business exemption) and Australia’s Privacy Act and Australian Privacy Principles, you remain responsible for personal information even after a staff member puts it into a tool. If someone runs a client’s personal details through Lens or Translate on a personal Google account, that is your organisation’s personal information now sitting in a third party’s training pipeline, retained for as long as four years. A quiet change in a vendor’s defaults can become a privacy exposure you are the one who has to manage.

What to do this week

  1. Tell your team plainly: don’t use a personal Google account (Lens, Translate, voice search or AI Mode) for anything touching client or company data. Use the approved business tier instead.
  2. Opt out where you can. Go to myactivity.google.com/activitycontrols. If you see “Search Services History,” turn it off, or at least uncheck “Save Media.” If it has not appeared yet, either turn off Web & App Activity entirely (Google says that opt-out carries forward), or uncheck “Include voice and audio activity” and “Include Visual Search History,” then check back weekly until the new setting shows up.
  3. Workspace admins: review your organisation’s Search-services and data settings, and verify your position rather than assuming it.
  4. Put it in writing. Add consumer Google Search services to the “use with caution” list in your AI acceptable use policy, and re-confirm your Gemini guidance: Workspace only for anything sensitive. Check the current ratings in the AI Tool Risk Directory before you rely on a tool.

This is the second major vendor in two months to flip an AI-training default toward “on.” Atlassian is doing the same with Jira and Confluence data from 17 August 2026. See our earlier alert, Atlassian will train its AI on your Jira and Confluence data by default. The pattern is the one worth internalising: vendor defaults drift in the vendor’s favour, and only a written policy plus a regular check catches the drift.

Get the next one in your inbox. We send a plain-English alert whenever an AI tool businesses rely on changes its data policy or has an incident: no hype, just what changed. Subscribe to AI Leakage Alerts.


How this was written

This alert was drafted with AI and checked by a person before publishing. It is based on Google’s own Search Services History support documentation and on June 2026 reporting from Computerworld, BGR and HuffPost. Tool risk ratings change as vendors change their terms; we update them, and we date our sources. That is how we think AI should be used at work, so we say so.

Similar Posts