Current status: Last reviewed September 7, 2026. Google renames menus and ships new AI surfaces several times a year. Every path and policy below was read from Google's documentation on the review date; items marked confirm in your console could not be verified from a public page. Recheck before a board or parent communication.
There is no “turn off AI” switch for a school Chromebook. There are at least twelve switches, they live in four different places, three of them default to on, and one of the biggest surfaces has no switch at all. A technology director who searches for how to block AI on Chromebooks finds student newspapers, forum threads, and a February 2024 blog post, none of which lists the controls Google ships today.
This page is the list. Every row names the surface a student actually meets, the exact Google Admin Console path or Chrome policy that governs it, what Google says the default is for Education accounts and users under 18, and what the control leaves open. It was checked against Google’s documentation on September 7, 2026. It ends with the decision most districts arrive at after working through the table: block what should never be reached, allow a small approved set, and put the district’s rules on the approved surfaces at the moment of use.
If you want the three district templates that go with this work (the application register, the tool vetting template, and the acceptable-use checklist), they are in the free district AI governance starter kit.
The map
Paths are written as Google’s help pages write them. “Policy” means a Chrome or ChromeOS policy set under Menu > Devices > Chrome > Settings > User & browser settings in the Admin Console. Where Google’s public documentation does not state a default or a detail, the row says “confirm in your console” rather than guessing.
| Surface | A student meets it as | Control | Default for Education and under-18 | What the control cannot do |
|---|---|---|---|---|
| Gemini app | gemini.google.com, the Gemini mobile app, and the Gemini tab inside Classroom | Menu > Generative AI > Gemini app, on or off by organizational unit or group. Needs the Gemini Settings administrator privilege | Google’s Gemini help for Education lists availability as all ages, and its Workspace admin guidance describes the Gemini app and NotebookLM as included in Workspace for Education plans, with stricter content policies for users under 18 and some features restricted. The exact default state on a new domain: confirm in your console | Turning the app off does not affect Gemini features inside Workspace services, Gemini in the Chrome browser, personal-account Gemini, or third-party chatbots |
| Gemini inside Workspace apps | “Ask Gemini” side panel and Help me write in Docs, Gmail, Sheets, Slides, Drive, Meet, Vids, Chat | Menu > Generative AI > Gemini for Workspace, with per-app toggles | Google states the default for Gemini features in Workspace services is on. These features are tied to paid education plans (Teaching and Learning add-on, Education Plus, Google AI Pro for Education); whether any are included in the free plan: confirm in your console | Turning Gemini off in one app does not fence its data: Google notes users can still reach that app’s data from Gemini in another app. Requires the user-side “smart features” setting, which is not a block |
| Gemini in Classroom | Teacher tools plus a student-facing Gemini tab in Classroom | Menu > Generative AI > Gemini for Workspace > Feature access in Classroom | On by default for users of all ages. To turn it off for students under 18, place them in a dedicated organizational unit and turn it off there | The tab is hidden only if both the Gemini app and NotebookLM services are off. Changes can take up to 24 hours |
| NotebookLM (Gemini Notebook) | notebooklm.google.com and the Classroom Gemini tab | Menu > Generative AI > Gemini Notebook > Service status | Core service; Google’s age-access guidance shows under-18 access available. Default state: confirm in your console | A service switch only; a notebook built from a student’s own uploads still leaves data in the notebook |
| Google Search AI Overviews | The AI summary at the top of ordinary google.com results | None. Google’s help says AI Overviews are a core Search feature and cannot be turned off. Enforce SafeSearch with the ForceGoogleSafeSearch policy; a user can choose the Web filter after a search | On for everyone; no Education or age exemption documented | The URL blocklist cannot remove a block from inside an allowed results page. SafeSearch filters explicit content, not AI |
| Google Search AI Mode | The AI Mode button on the New Tab page and in the address bar; the AI Mode tab on google.com | Chrome policy AIModeSettings (0 = available, 1 = not available; when unset it follows GenAiDefaultSettings). Third-party chat integrations in the same spots: ThirdPartyAiChatSettings | Policy default 0; the Education default inherited from GenAiDefaultSettings is allow, so AI Mode entry points are on | The policy removes Chrome’s entry points only. The AI Mode page on google.com is a Search property; blocking it by URL pattern is a workaround Google does not document: confirm in your console |
| Gemini in the Chrome browser | The Gemini button in the toolbar and page-context chat (Chrome 137 and later on desktop; ChromeOS support is listed at 144 and later in the policy source) | User & browser settings > Generative AI > Gemini integrations; policy GeminiSettings (0 = allow, 1 = do not allow). Related: GeminiActOnWebSettings, GeminiSparkSettings, GeminiChromeFileUploadSettings | Policy default allows. Google’s help ties some Gemini in Chrome features to paid plans and to users 18 or over; the base side panel’s availability for Education and under-18 accounts: confirm in your console | Separate from gemini.google.com. Not available in Incognito in any case |
| Chrome built-in AI features | Right-click Help me write in text fields, History search with AI, tab organizer, theme creator, tab compare, Lens overlay | Umbrella policy GenAiDefaultSettings (0 = allow and improve models, 1 = allow without improving models, 2 = do not allow), set under User & browser settings > Generative AI. Per-feature: HelpMeWriteSettings, HistorySearchSettings, TabOrganizerSettings, CreateThemesSettings, TabCompareSettings, DevToolsGenAiSettings, LensOverlaySettings, GoogleSearchSidePanelEnabled | Google’s documented default for Workspace for Education is “allow feature without improving AI models”: features on, training off | Value 1 is a data-use promise, not a block. None of these policies touch AI on web pages or Gemini in Workspace |
| ChromeOS built-in AI | Right-click Help me read, AI image editing in Gallery, generative wallpaper and video-call backgrounds, smart grouping, on-device actions | Same Generative AI section, plus a Devices entry. Policies: HelpMeReadSettings (Education accounts default to allow without improving), GenAIPhotoEditingSettings, GenAIWallpaperSettings, GenAIVcBackgroundSettings, GenAIInlineImageSettings, GenAISmartGroupingSettings, GenAiChromeOsSmartActionsSettings | Allow without improving; many features exist only on Chromebook Plus hardware | Same boundary as Chrome features. Live Caption and Live Translate have no generative-AI policy in the documentation reviewed |
| Web Store extensions | Installing an AI writing or chat extension from the Chrome Web Store | Menu > Devices > Chrome > Apps & extensions > User app settings: Chrome Web Store allow or block mode (allow all with a blocklist, or block all with an allowlist, with or without user requests); block by permission under Permissions and URLs; per-item installation policy set to Block | Default mode: confirm in your console | Google’s help notes users can still sideload extensions. Extension controls do not block web apps or Android apps. An AI category filter in the store: confirm in your console |
| Third-party AI sites | Browsing to chatgpt.com, claude.ai, copilot.microsoft.com, perplexity.ai, character.ai and the next hundred | Menu > Devices > Chrome > Settings > Content > URL Blocking; policies URLBlocklist and URLAllowlist (allowlist wins). Up to 1,000 entries combined | Nothing blocked by default | No content inspection. Android WebView apps may ignore it. Allowing a domain allows every AI feature inside it, such as Copilot inside allowed Microsoft 365 web apps or the AI panel inside an approved learning platform |
| Android apps | The Gemini app and chatbot apps from Google Play on ChromeOS | Apps & extensions > User app settings > Android apps on Chrome Devices: allow or block users installing Android apps; Play allow or block mode; per-app installation policy set to Block. Requires an Android Enterprise subscription | Android apps are disabled by default | With full managed Play access, individual app policies cannot be edited; allowlisting blocks Play for secondary accounts |
| Guest mode and personal accounts | Signing out and browsing as Guest, or adding a personal Gmail account | Devices > Chrome > Settings > Device settings: Guest mode (allow or disable); Sign-in restriction (restrict sign-in to a list of users, such as a pattern for the district domain). User & browser settings > User experience > Multiple sign-in access to block secondary accounts | Multi-sign-in is allowed by default per Google’s help; other defaults: confirm in your console | Device-level settings apply to anyone on the device, but user-level AI policies do not follow a guest or personal account. Off-hours policies can reopen personal sign-in |
| Microsoft Copilot and Bing | copilot.microsoft.com and Bing chat in the browser | Web only on ChromeOS: the URL blocklist row above, or Play controls for the Android app | Not blocked by default | Blocking bing.com also blocks Bing search. Copilot inside allowed Microsoft 365 web apps is not addressable by URL |
Two things stand out once the rows are side by side. The first is that the two highest-traffic surfaces, Gemini in Classroom and Chrome’s built-in features, default to on for Education accounts, and the single most visible surface, AI Overviews in Search, has no switch. A district that has not touched these settings has AI on. The second is that every “cannot do” cell describes the same gap: the controls act on addresses, apps, and service switches, and AI increasingly arrives inside sites and apps the district has already allowed.
What no console setting covers
- AI Overviews on google.com. Google states they cannot be turned off.
- AI inside allowed sites. Writing assistants embedded in design, quiz, and learning platforms, and Copilot inside allowed Microsoft 365 web apps, sit behind domains the district must allow.
- Cross-app Gemini reach. Per-app Gemini toggles do not fence the data those apps hold.
- The Classroom Gemini tab stays visible unless both the Gemini app and NotebookLM services are off.
- Guest and personal sessions and sideloaded extensions escape user-level policies.
- GenAiDefaultSettings value 1 leaves features on; it only stops training use.
- Devices the district does not manage: phones, home computers, and a friend’s laptop.
That list is the honest limit of blocking. It is also the list that makes a pure blocklist strategy expensive to maintain: every new Google surface, every vendor that adds an AI panel to an approved tool, and every student who signs into a personal account reopens the question.
Three configurations districts actually run
Configuration 1: block everything the console can reach. Gemini app off, Gemini for Workspace off, Gemini in Classroom off for student organizational units, NotebookLM off, GenAiDefaultSettings at 2, AIModeSettings at 1, GeminiSettings at 1, Web Store in block-all mode with an allowlist, a URL blocklist for the known chatbot domains, Android apps disabled, guest mode disabled, sign-in restricted to the district domain. This is the right configuration for early elementary. It still leaves AI Overviews in Search and AI inside allowed sites, and it removes tools some teachers and high school courses legitimately want.
Configuration 2: Google on, everyone else off. Gemini in Classroom and the Gemini app on for the grade bands the district has approved, with under-18 protections; third-party chatbots on the URL blocklist; Web Store on allowlist mode. This is common in Google-native districts. Its weakness is that “on” means on for every purpose: the same Gemini that helps a student outline an essay will also write it, and the console has no setting for “hints only in English class.”
Configuration 3: a small approved set, allowed with rules. The district approves specific products for specific grade bands, blocks the rest, and applies its policy on the approved surfaces at the moment of use: which classes may use the tool, what a student may ask for, what leaves the device, and what gets blocked when an unapproved AI interface appears inside an allowed site. This is the configuration the rest of this page is about, because it is the one the console cannot produce on its own.
Allow with rules: what the console cannot do, done at the point of use
The Admin Console decides whether a student can reach a surface. It has no opinion about what happens once they are there. That is where a district policy layer on the managed browser does its work, and it is the reason Tenet exists.
Tenet by TrueMadeAI is K-12 AI governance software. Tenet Edge applies district and classroom policy on supported direct-use AI surfaces on managed Chrome. On a Chromebook fleet, it adds three things the console does not have:
- Rules on approved surfaces. On supported products such as ChatGPT, Claude, Gemini, Microsoft Copilot, and the student experiences in MagicSchool, SchoolAI, and Brisk, Tenet applies the district’s guidance and, in Tenet District, the class, subject, teacher, and schedule context, so “allowed” can mean “allowed for brainstorming in this course, not for the draft.” The supported-product capability matrix lists each surface and its boundary.
- On-device data-loss prevention. Supported plain-text prompt checks run before the text leaves the device, so a student pasting a classmate’s name or a health detail into an approved tool is stopped at the moment of use rather than found in a log later.
- Blocking of unapproved AI interfaces inside allowed sites. When the district enables the control, Tenet checks known interface signatures and local multi-signal patterns for AI chat and writing surfaces that are not on the approved list and blocks the interface while leaving the surrounding site available. Grammarly AI web experiences are one current example. This is the gap the URL blocklist cannot close.
Tenet does not replace the console. The rows above are still the right place to disable services, restrict sign-in, and block domains. Detection and blocking are distinct from deep governed support, coverage depends on the web surface, vendors change their interfaces, and no heuristic can guarantee detection of every AI interface. District allowlists and bypasses remain authoritative. The shadow AI guide explains the difference between inventory, detection, blocking, and governed support in detail.
Tenet Basic is free and applies one district-wide baseline without roster setup. Try Tenet Basic, or request a Tenet District conversation if you need classroom, subject, and schedule context.
A configuration checklist you can run this week
- Export the current state. For each row in the map, record the setting as it is today, by organizational unit. Most districts find at least one surface on that nobody decided to turn on.
- Decide by grade band, not by product logo. The AI product age and consent table tells you which products may admit which students at all; the console should never allow a surface the vendor’s terms exclude.
- Set the umbrella policies first. GenAiDefaultSettings, AIModeSettings, GeminiSettings, and the Gemini for Workspace switches determine most of the default exposure.
- Close the bypasses. Guest mode, sign-in restriction, multiple sign-in, Android apps, and Web Store mode are where a blocklist quietly fails.
- Write the approved list down in the AI application register with the console setting that enforces it, and publish it if your state requires a public list.
- Put rules on the approved surfaces. Decide what “allowed” means in each course, and use a point-of-use control for the part the console cannot express.
- Recheck quarterly. Google shipped new AI surfaces in Chrome, ChromeOS, Search, and Classroom in every quarter of the last year.
The K-12 AI acceptable use policy checklist covers the policy text that should sit above this configuration, and the guide to how districts govern student AI tools explains the four-layer model that separates access control from in-surface policy.
What this page does not establish
This page does not determine:
- that a setting listed here still exists under the same name tomorrow;
- the default state of any setting in your domain, which depends on plan, purchase history, and prior admin changes;
- that a URL pattern reliably blocks a Google Search property;
- that any product is instructionally appropriate for a grade band; or
- that Tenet can detect or govern every AI interface on every site.
Verify in your own console, and read the dated capability matrix before relying on a specific Tenet behavior.
Sources
- Turn the Gemini app on or off for users, Google Workspace Admin Help
- Manage access to Gemini features in Workspace services
- Gemini Apps in Google Workspace for Education, Google Gemini Help
- Turn NotebookLM on or off for users
- AI Overviews and AI Mode in Google Search, Google Search Help
- Set Chrome policies for generative AI features
- Manage generative AI features with a default policy
- Chromium policy definitions, Generative AI group
- Allow or block apps and extensions
- Allow or block websites
- Set ChromeOS device policies
Frequently asked questions
Can a district turn off Google AI Overviews on student Chromebooks?
No. Google’s own help states that AI Overviews are a core Google Search feature and cannot be turned off. A user can choose the Web filter after a search, and a district can enforce SafeSearch, but neither removes AI Overviews from results. The AI Mode entry points in Chrome are a separate control (the AIModeSettings policy).
Does turning off the Gemini app also turn off Gemini in Docs and Gmail?
No. The Gemini app is a Workspace service switch under Generative AI, and Gemini features inside Docs, Gmail, and the other apps are governed by the separate Gemini for Workspace settings. Google’s help says turning off the app does not affect other AI features in Workspace services.
Is Gemini on for students by default in Google Workspace for Education?
Google’s admin guidance states that Gemini in Classroom is on by default for users of all ages, and its Gemini help for Education lists the Gemini app as available to all ages, with stricter content policies for users under 18. Districts should verify the current state in their own console rather than assume it is off.
Can the Chrome URL blocklist stop AI inside a site the district allows?
No. The URL blocklist matches addresses, not page content. AI features inside an allowed site, such as writing assistants embedded in a learning platform or Copilot inside allowed Microsoft 365 web apps, are not addressable by URL blocking. That gap is why interface-level blocking exists as a separate layer.
What is the difference between GenAiDefaultSettings value 1 and value 2?
Value 1 allows Chrome and ChromeOS generative AI features without using the district’s data to improve Google’s models. Value 2 turns the features off. Google’s documented default for Workspace for Education is value 1, so features stay on and only the training use is disabled. A district that wants the features off must set value 2 or the per-feature policies.
Does blocking AI on Chromebooks solve the district’s AI policy problem?
Only for the surfaces you block, only on managed devices, and only until the next vendor change. Guest sessions, personal accounts, phones, home computers, and AI inside approved tools remain. Most districts end up with a small approved set, a blocklist for the rest, and rules that apply at the moment of use on the approved surfaces.