Google starts testing client-side encryption for Gmail with some Workspace users, and plans to add it to its Android and iOS apps
Google has launched a beta of its client-side encryption for Gmail, letting businesses apply to test out the feature meant to make “sensitive data” and attachments unreadable even to Google.
Context & Ripple Effects
This beta extends a program Google started in mid-2021, when it added client-side encryption to data stored in Workspace and Chat — until now, Gmail itself stayed outside that boundary. The December launch opens a beta window for Workspace administrators to enroll through January 20, with the stated goal of making sensitive messages and attachments unreadable even to Google.
The roadmap matters as much as the beta: Google says client-side encryption will reach Gmail's Android and iOS apps later, and subsequent coverage shows the arc completing — a [[a:884125|2025 encryption model that drops the need for senders and recipients to run custom software or swap certificates]], followed by an enterprise rollout of end-to-end encrypted Gmail on mobile devices.
First-order effects
- Workspace administrators can now apply to enroll their organizations in the Gmail beta through January 20, gaining mail and attachments that Google itself cannot decrypt.
- Businesses handling regulated or sensitive correspondence get a native option instead of bolt-on encryption tools, since the feature lives inside Gmail rather than requiring external software.
Second-order effects
- Google's 2025 follow-up model removes the certificate-exchange burden that typically limits enterprise encryption deployments, lowering the adoption cost that keeps most business mail unencrypted.
- Once Gmail encryption works natively on Android and iOS, competitors selling secure-email gateways and add-on encryption for Workspace environments face pressure from a feature Google bundles at no extra step.
Third-order effects
- If the pattern holds — Workspace files and Chat in 2021, Gmail web in 2022, a frictionless model in 2025, mobile in 2026 — Google is structurally repositioning Workspace as a zero-knowledge platform where the provider holds no readable copy of enterprise communications.
- That shift moves the trust question for enterprise email from 'do you trust your vendor' to 'does your vendor even have access', a standard regulators and procurement teams may increasingly treat as table stakes.
The trend: Google is progressively dismantling its own ability to read enterprise email, turning client-side encryption from a niche Workspace add-on into default architecture across Gmail on every platform.