The supposed "security team" is busy fighting Google engineers connecting to internal systems to do their work. E.g. somebody figured how to control the coding AI agent from their phone -- red alert, ban all access from phones to AI for everybody (even with corporate accounts).
You say that like it's a bad thing. If I am trusting Google with all sorts of personal information, I expect robust access controls to data and systems