Google has announced that its AI-powered ransomware detection feature for Google Drive has officially reached general availability and is now enabled by default for paying users.
The capability, first introduced in beta in September 2025 and rolled out for trial to Workspace users in October, marks a significant upgrade to the platform’s built-in security protections. It expands safeguards across organizations that rely on cloud storage for daily operations.
"Compared to when the feature was in beta, we are now able to detect even more types of ransomware encryption and do it faster. Our latest AI model is detecting 14x more infections, leading to even more comprehensive protection,"
Google explained.
Currently just working on desktop applications, the feature is designed to identify ransomware-encrypted files and halt them, alerting both the affected user and IT administrators.
How the Ransomware Detection Works
The updated capability focuses on identifying encrypted files that match patterns associated with ransomware attacks. When ransomware detection is enabled, files synced from a desktop computer to Google Drive are automatically scanned as part of the syncing process. If the system detects files that appear to have been encrypted by malicious software, syncing is immediately paused.
Once a threat is flagged, notifications are sent to the affected user via email and within Google Drive, while an alert is simultaneously created in the Google Admin console. This dual-notification approach ensures both end users and administrators become aware of the incident quickly, allowing remediation steps to begin without delay.
In addition to expanded scanning capabilities since the beta launch, the anti-ransomware engine can adapt to new ransomware strains by incorporating threat intelligence from VirusTotal and continuously analyzing file changes.
Beyond detection, Google has also integrated recovery guidance into the process. After an attack is blocked, users receive instructions for restoring corrupted files using Drive’s restoration tools. These tools allow administrators and users to roll back changes made by ransomware, helping organizations recover affected data once the infected device has been cleaned.
A Response to Intensifying Ransomware Threats
The timing of Google’s announcement reflects the escalating scale of ransomware attacks across enterprise environments.
Research from Zscaler highlights how quickly the threat is growing. In 2025, the security firm reported that attempted ransomware attacks blocked by the Zscaler cloud rose by 146% year over year, underscoring how rapidly attackers are expanding their operations.




