← Back to blog Cybersecurity

Gemini lands on Windows with Alt+Space: how to control which AI assistants get installed on the PCs of your Mexico operation

4 min read

On September 10 Google released Gemini, its AI assistant, for Windows 10 and 11, as reported by ADSLZone. It installs like any program, opens from any application with Alt+Space and can look at what is on screen to answer about it.

Add Copilot, the Microsoft assistant already built into Windows, and the staff in your Mexico office now have two AIs one keystroke away. Over contracts, email, the ERP and the customer list. Nobody in IT approved it, and head office probably has not heard about it yet.

What Alt+Space changes

AI over whatever is on screen No more copying into a chat window: the assistant reads the window that is open.

Until now, using AI on a document meant opening a browser, logging into a chat and pasting the text. That small effort stopped most people.

Now the accountant in Monterrey can have payroll open, press Alt+Space and ask ‘summarize this’. Whatever is on screen goes to Google under the account that person signed in with. If it is a personal Gmail, payroll ends up in a history the company cannot see or delete.

This is shadow AI: AI used at work without IT knowing. In our experience it is far more common than malware, and almost nobody does it with bad intent. They just want to finish faster.

The real risk, without drama

The account is the problem Under a personal Gmail the history is out of your reach; under a company account you can see it and delete it.

Gemini and Copilot are not dangerous by themselves. The problem is the account they run under and what they get shown.

What can happenExample in a Mexico office
Customer data in personal accountsSales asks to summarize an email with a client price list
Contracts leaving the companySomeone asks ‘explain this clause’ with the PDF open
Screens of internal systemsA question about an ERP error includes tax IDs and invoices
History nobody can deleteThe person resigns and it all stays in their Gmail

There is a cross-border angle too. Your data commitments to customers in the US or Europe do not stop at the border, but the policies you push from head office often do. PCs joined to no domain, local admins, personal Gmail: we see it every week.

Deciding which AI is allowed

Our view: banning all AI does not work. People use it from their phones and you lose visibility. What works is picking one and giving it a company account.

Banning AI outright versus allowing it with rules
Banning AI outright versus allowing it with rules
An outright ban just moves the problem to personal phones Fotos: Santeri Viinamäki · CC BY-SA 4.0 · Wikimedia Commons / Pexels

The rule we apply with clients is simple:

  • If your email runs on Google Workspace, your assistant is Gemini with a corporate account.
  • If your email runs on Microsoft 365, your assistant is Copilot with a corporate account.
  • Everything else, including Gemini with a personal Gmail, gets blocked or limited.

Then the human part: say clearly what can be pasted (your own email, a manual) and what cannot (customer data, contracts, payroll, passwords). In Spanish, for the local team, not buried in an English policy PDF. Business plans of Workspace and 365 have different terms than the free versions about what happens to what you type; check the ones for your plan.

How to block or allow by policy

Rules, not reminders A policy applies itself on every PC; a message in the group chat is forgotten in a week.

Two tools do the heavy lifting. Intune is the Microsoft service for managing devices from the cloud. GPOs are group policies: rules a domain server pushes to every PC on the network. Either one works, as long as the Mexico PCs are actually enrolled.

MeasureHowWhat it achieves
Users without admin rightsStandard Windows accountsNobody installs Gemini or anything else unapproved
Allowed-program listIntune or GPO with AppLockerOnly what IT approved can run
Sign-in with corporate accounts onlyWorkspace or 365 policiesEven if the AI opens, personal Gmail cannot log in
Copilot on or off by departmentGPO or IntuneSales yes, accounting no, for example

Removing admin rights is the cheapest measure and the one that solves the most. Many Mexico offices still run with everyone as administrator because it was faster during setup. There, anyone installs anything.

If you also have apps connected to email or AI agents acting on their own, those are separate fronts: see how to audit OAuth apps in Workspace and 365. Most of the enrollment and policy work can be done through remote IT support from Mexico, with a visit only for PCs that were never joined to anything.

ProcessBi team reviewing device policies for a company in Mexico
Tell us which AI your Mexico team uses today and we will set the rules together Foto: Pexels

What about your Mexico operation?

Try this today: ask your Mexico office who has installed Gemini or uses Copilot, and with which account. The answer usually surprises head office.

At ProcessBi we do this hardening once and keep it current under a support plan: each month we check what got installed, who asked for exceptions and whether a new AI changed the rules. There will be another one. It starts with a free assessment of your PCs and accounts.

Book your free assessment — we reply the same business day.

Your path

Running IT in Mexico from abroad

17 of 32
  1. Smart hands ✓ Read You are here 2 min
  2. Remote support ✓ Read You are here 3 min
  3. Nearshoring checklist ✓ Read You are here 2 min
  4. Retail rollouts ✓ Read You are here 2 min
  5. Fake IT support ✓ Read You are here 3 min
  6. Backups that restore ✓ Read You are here 3 min
  7. Secure M365 ✓ Read You are here 3 min
  8. Windows 10 deadline ✓ Read You are here 4 min
  9. Audit app access ✓ Read You are here 3 min
  10. CEO fraud ✓ Read You are here 4 min
  11. Office 2016 cutoff ✓ Read You are here 3 min
  12. Patch today ✓ Read You are here 4 min
  13. Patch VMware ✓ Read You are here 4 min
  14. Office 2021 EOL ✓ Read You are here 3 min
  15. Starlink for sites ✓ Read You are here 3 min
  16. Cardless access ✓ Read You are here 4 min
  17. Control AI on PCs ✓ Read You are here 4 min
  18. ScreenConnect flaw ✓ Read You are here 4 min
  19. Server 2022 EOL ✓ Read You are here 3 min
  20. Exposed cameras ✓ Read You are here 3 min
  21. Domain trust fix ✓ Read You are here 4 min
  22. Patch Cisco ISE ✓ Read You are here 3 min
  23. Protect the plant ✓ Read You are here 3 min
  24. Move to 25H2 ✓ Read You are here 4 min
  25. Outages and UPS ✓ Read You are here 3 min
  26. IT maintenance ✓ Read You are here 4 min
  27. Third-party scripts ✓ Read You are here 3 min
  28. License audit ✓ Read You are here 4 min
  29. Bajío fiber corridor ✓ Read You are here 3 min
  30. Check Point flaw ✓ Read You are here 4 min
  31. Cashless payments ✓ Read You are here 3 min
  32. AI that hacks alone ✓ Read You are here 3 min
  33. Field services
Next Critical ScreenConnect flaw under active exploitation: what to do if your Mexico operation or its IT provider uses this remote access tool