Public, wearing an internal-sounding name
allAuthenticatedUsers is any Google account in existence, not everyone in your organisation. Bound to a storage role it is a data exposure.
{
"version": 3,
"bindings": [
{ "role": "roles/storage.objectViewer", "members": ["allAuthenticatedUsers"] }
],
"etag": "BwXhtQ=="
}