2) Your average IT department in any publicly traded company would NEVER let this fly.
3) Any general council would shat all over this. No one likes fighting with lawyers, and this is a battle I'd never put on my plate.
It's odd to assume generic users understands IMAP or what a proxy is. Remember how Apple makes products for dumb people? Yeah. They ran a campaign on that.
On top of all of this, they have a "if you're a Google Apps admin" section where the only way to block it is to disable ALL OAuth applications.
No self-respecting CTO/CIO would let this occur in an organization they hope to responsibly grow.