Open your notes. For your last AI-in-docs use (or a hypothetical one), list: (1) the data classes in the file (public / internal / client) (2) who can open it (3) whether the model's output could leave your tenant. You're done when you've written the one rule you'll enforce before any share/export, in 15 words or less.
How-to · INF · INF.5
AI inside Docs/Sheets is still a send risk
Workspace add-ons put models where you already work — powerful, and easy to leak client data if share/send is still human-owned only in theory.
Worked example
Grok showing up inside Google Workspace (Docs, Sheets, Slides) means the model now sits right next to your real files. That's a great place for draft help — and a risky one for autopilot sharing. Before you paste a client sheet or hit anything like send/share/export: strip out secrets, confirm who can see the doc, and keep a human owning any external send. In-app AI is not a privacy boundary.