Gmail Finally Gets Native End-to-End Encryption on Android and iOS — No Third-Party Apps Required
Google has rolled out client-side encryption for Gmail on mobile devices for Workspace Enterprise Plus subscribers, letting users compose and read encrypted messages without leaving the app. Personal Gmail accounts are not yet supported.
Google’s Gmail client-side encryption — E2EE that keeps decryption keys entirely off Google’s servers — is now available natively on Android and iOS for Google Workspace Enterprise Plus subscribers. Until now, mobile users who needed end-to-end encrypted email had to route messages through a separate portal or rely on third-party tools like S/MIME clients. That workaround is gone.
The feature is built on client-side encryption (CSE), meaning Google cannot read message content or attachments. Keys are managed by the organization’s chosen key management service — not Google. For regulated industries like healthcare, finance, and defense contracting, that distinction matters enormously for compliance with frameworks like HIPAA, FedRAMP, and ITAR.
Encrypted messages sent to recipients outside the organization — including non-Gmail addresses — are delivered as a secure link. Recipients open the content in a browser-based secure viewer without needing to install anything. That’s a meaningful usability improvement over the previous approach, which required recipients to jump through multiple hoops to access encrypted content.
The tradeoff is direct: E2EE breaks Google’s AI features. Smart Compose, smart replies, and spam filtering all depend on Google’s ability to process message content. With CSE enabled, those features are disabled for encrypted threads. Organizations have to decide whether the compliance and security value outweighs the loss of AI-assisted productivity features — for most enterprise security teams, that’s an easy call.
Eligibility is narrow. The feature requires a Google Workspace Enterprise Plus license with either the Assured Controls or Assured Controls Plus add-on. Standard Workspace tiers and personal Gmail accounts are excluded. Google has not committed to a timeline for broader availability.
The announcement follows years of pressure on major email providers to ship encryption that doesn’t require trusting the platform. ProtonMail and Tutanota have offered E2EE as a core feature for years; Gmail’s 3.5 billion user base makes even a narrow rollout significant. The enterprise-first approach is deliberate — it lets Google test the infrastructure and key management integrations before a broader deployment.
For Workspace administrators, setup involves configuring an external key service (Google supports Thales, Flowcrypt, Virtru, and others), enabling CSE in the Admin console, and granting it to the relevant organizational units. The mobile rollout doesn’t change the admin configuration — it extends a feature that was already available on web to the clients where most enterprise users actually work.