September 2026

Your Vendor rewrote your policy under a toggle that was already switched On

A tool licensed for one job gains new capabilities through ordinary updates, under permissions often granted long ago. What this means, is that effectively, any update now can potentially be a silent update to your operating policy. Without anybody on your side having made a decision.

Let’s start with a simple example, but a widespread one. On 22 April 2026 Google began rolling out Workspace Intelligence, which it describes as “an underlying AI system that provides Gemini with a real-time understanding of your work across Google Workspace”. From then on, Gemini’s features were to draw on each user’s Gmail, Chat, Calendar and Drive. Google’s note to administrators stated the default plainly: “Workspace Intelligence is ON by default; admins can disable access to certain data sources”. It applied across Google’s business and enterprise editions.

Google announced it publicly, on its Workspace Updates blog with a line addressed to admins, and the settings to control it were in the Admin console from launch. What deserves attention is what an administrator had to do for nothing to change: find the new setting and turn it off, source by source. An organisation that had switched Gemini on for help drafting email had taken a decision about drafting; from that week the same decision also covered Gemini drawing on each user’s calendar, chat and Drive, unless an administrator went back and turned those sources off. Even then, Google’s note adds, a user can still (!) ask Gemini about specific files in a Drive that has been switched off (!), and Gemini will consult them.

Let that sink in. Drive access off doesn’t mean off. Just like that.

Now imagine this scenario somewhere with more at stake. You licensed a recruitment platform that hosts applications and schedules interviews. Then the vendor adds a layer that screens, ranks and writes to candidates. You have, in effect, signed a new recruitment policy. You initially signed for scheduling. But you are now running screening.

Your privacy notice is exposed in the same way. It describes processing that a vendor’s release may already have changed.

I wrote in May 2026 that the vendor decides where on the spectrum of autonomy a deployment sits, and the organisation decides nothing. That was about the day of installation. The larger exposure is every day after it. The vendor keeps deciding, and your one decision, the original purchase, is read as consent to all of it.

And Google’s note goes even one step further. The controls you are given govern less than their labels say. Switch Drive off as a source and, Google says, Gemini will not actively search it. So the setting turns off what Gemini reaches for on its own. A user who asks about a specific file in that Drive still gets that file read, because that path was never the setting’s to close.

The rules still stand. But one prompt, and a user has handed Gemini a file the administrator had switched off. Nothing was overruled. That door was never the setting’s to close.

Just like that, again

The same mechanism reached Windows desktops through the update channel. With an update in December 2025, Windows devices with Microsoft’s commercial desktop apps began installing its Copilot app automatically, in the background, as a single entry point to search, chat and agents. An administrator who did not want it had to clear a checkbox in a separate admin centre.

No ceremony. Nobody on your side decided anything. Policy changed, just like that.

I’m raising this for the mechanism, not the product, but one thought process here is key. The automatic installation was not enabled for customers in the European Economic Area, nor for US government tenants. The same vendor, shipping the same software, set one default for most of the world and another for those two groups. Microsoft has not said why. Well, it does not need to for the point to hold.

A default of that kind is a decision, taken by the vendor on its own reading of its situation. Until someone on your side decides otherwise, it is also your operating policy.

The law assumes a ceremony

Recruitment is where the law already names the stakes. The EU AI Act classes as high-risk AI systems intended to analyse and filter job applications or to evaluate candidates. Before putting such a system into service at the workplace, an employer must inform workers’ representatives and the affected workers, and it must assign human oversight to people with the competence, training and authority to exercise it. Under the deferral the EU adopted in July 2026, those obligations apply to these systems from 2 December 2027.

Read that again. The law is written around a ceremony: the moment an employer decides to put a system into service. Someone decides, the workers are told, oversight is assigned. But a release note skips the ceremony. A platform that scheduled interviews in the spring can be screening applicants by the autumn under the same licence, without anyone on your side having decided to put anything into service.

Whether an update like that counts as putting a system into service is a question for your lawyers. They can only answer it about an update someone has noticed.

Noticing is a responsibility that sits with you.

Decide it before the vendor does

The fix is obviously organisational, and it is straightforward enough to start before the next release lands.

  • First, decide who holds the decision rights over what each tool may do. A named person on your side decides whether a new capability is switched on for your organisation, rather than leaving it to the vendor’s default or to whichever administrator happens to read the notice.
  • Second, write down a simple data contract for each tool: what it may read, what it may write, and about whom. A capability that reaches past the contract then shows up as a change, instead of disappearing into the next update.
  • Third, set a review that fires on change rather than on the calendar: every time a tool gains a capability, and every time it reaches a new group of people, whether candidates, customers or another country’s workforce. Keep it to two to four people, with legal in the room from the first meeting, even when nothing on the table is legal yet. By the time something is, the capability is usually live. Size the review by what the tool touches (product, services, clients, operations) and by sector. A medical-device maker and a social-media company should not be running the same review. And the review reads what a control actually covers, not what its label says. The Drive setting above is why.

My co-host on Signals & Subtractions, Sam Rogers, built the inventory that sits underneath all three: a default ledger. It has one row per default in force, recording what it does, whether it still carries the value it shipped with, and the name of the person who chose it or chose to keep it. A team name does not count. Neither does the vendor. The name column is the one that tells you whether any decision has actually been taken.

The vendor will keep shipping. Improving the product is its job, and the terms will keep changing to match. Each of those changes is a decision about how your organisation works, taken in a building you do not sit in. The only part still yours is whether anyone on your side reads it as one before it goes live.

If you want to see where your own organisation stands on this, the diagnostic is the quickest way to find out.