Google Gemini · Gemini 3.1 Pro Model Card · View original document ↗

CBRN Risk Domain Evaluation and Ongoing Mitigations

High severity Medium confidence Explicitdocumentlanguage Unique · 0 of 352 platforms
Get alerted the next time Google Gemini changes these terms. Get same-day alerts →
Share 𝕏 Share in Share 🔒 PDF
Recent governance activity Google Gemini recorded 4 documented changes in the last 30 days.
Get same-day alerts →
Monitor governance changes for Google Gemini Monitor emails you the same day this changes. The archive stays free.
Get same-day alerts →

Get the weekly research letter

Companies change their terms quietly. We read every version and catch what actually changed. One email a week on the changes that matter and what they mean. No account.

Document Record

What it is

The document discloses that Gemini 3.1 Pro can provide accurate and actionable CBRN-relevant information but does not meet the Critical Capability Level threshold because it fails to provide sufficiently complete instructions for critical stages required to enhance the capabilities of low to medium resourced threat actors, and that ongoing mitigations are deployed.

This analysis describes what Google Gemini's agreement states, permits, or reserves. It does not constitute a legal determination about enforceability. Regulatory applicability and practical outcomes may vary by jurisdiction, enforcement context, and individual circumstances. Read our methodology

ConductAtlas Analysis

Why it matters (compliance & governance perspective)

This provision discloses a material CBRN risk finding and the deployment of active mitigations, which is operationally significant for regulated sector deployers, government customers, and compliance teams evaluating the model's risk profile under biosecurity, export control, and AI governance frameworks. The characterization of actionable CBRN information capability, qualified by the stated failure to reach critical stage completeness, is a nuanced safety finding requiring careful reading.

Interpretive note: The characterization of what constitutes sufficiently complete instructions for critical stages and the definition of low to medium resourced threat actors involves evaluative judgments not fully specified in the model card, creating some interpretive uncertainty in assessing the practical scope of the disclosed capability.

Consumer impact (what this means for users)

The document states that the model can provide accurate and actionable CBRN-domain information but does not reach the Critical Capability Level due to gaps in completeness for critical stages, and that mitigations remain active. Enterprise and government deployers should assess this disclosure within their applicable security and compliance frameworks.

Cross-platform context

See how other platforms handle CBRN Risk Domain Evaluation and Ongoing Mitigations and similar clauses.

Compare across platforms →

Monitoring

Google Gemini has changed this document before.

Receive same-day alerts, structured change summaries, and monitoring for up to 25 platforms.

Get Monitor Or create a free account →
▸ View Original Clause Language DOCUMENT RECORD
"
The model can provide highly accurate and actionable information but still fails to offer novel or sufficiently complete and detailed instructions for critical stages, to significantly enhance the capabilities of low to medium resourced threat actors required for the CCL. We continue to deploy mitigations in this domain.

Excerpt from Google Gemini's Gemini 3.1 Pro Model Card

ConductAtlas Analysis

Institutional analysis (regulatory & governance intelligence)

(1) REGULATORY LANDSCAPE: The CBRN risk domain disclosure engages export control regulations including the US Export Administration Regulations and relevant international biosecurity frameworks. The EU AI Act's provisions on prohibited AI practices and systemic risk assessment for general-purpose AI models are also relevant. In the United States, relevant oversight bodies may include the Department of Commerce's Bureau of Industry and Security for export control considerations and sector-specific security agencies depending on the deploying organization's sector. (2) GOVERNANCE EXPOSURE: High. The disclosure that the model can provide highly accurate and actionable CBRN-relevant information, even qualified by the stated CCL threshold not being reached, is a material finding for government customers, defense sector deployers, and organizations subject to biosecurity or dual-use technology regulations. The continued deployment of mitigations indicates this is an active risk management area rather than a resolved issue. (3) JURISDICTION FLAGS: US federal agencies and defense contractors face the highest exposure under US export control and security frameworks. EU and allied government deployers should evaluate this disclosure under applicable national security and dual-use technology regulations. Organizations in life sciences, pharmaceutical, and research sectors should assess whether this disclosure triggers internal biosecurity review obligations. (4) CONTRACT AND VENDOR IMPLICATIONS: Government and regulated sector procurement teams should request additional technical detail from Google regarding the specific CBRN mitigation measures deployed and their scope. Vendor agreements for high-security deployments should address CBRN risk mitigation obligations, incident notification requirements, and the extent of Google's liability for CBRN-domain model outputs. Procurement teams should assess whether this disclosure affects the model's suitability for specific deployment contexts. (5) COMPLIANCE CONSIDERATIONS: Organizations with biosecurity or dual-use technology compliance programs should document this CBRN risk disclosure in their AI vendor risk registers. Legal and compliance teams should assess whether the disclosure of accurate and actionable CBRN information capability, qualified by stated limitations, affects the model's classification under applicable export control or security frameworks in their jurisdiction. Ongoing monitoring of Google's CBRN mitigation updates via future model card publications is advisable.

Full institutional analysis
Regulatory citations, enforcement risk, and due diligence action items.
Start Professional · $99/mo Start with Monitor · $29/mo

Applicable agencies

  • FTC
    The FTC has general consumer protection jurisdiction over AI provider representations about safety and risk mitigation, though sector-specific agencies may have primary jurisdiction for CBRN-related regulatory matters.
    File a complaint →

Provision details

Document information
Document
Gemini 3.1 Pro Model Card
Entity
Google Gemini
Document last updated
July 6, 2026
Tracking information
First tracked
July 6, 2026
Last verified
July 9, 2026
Record ID
CA-P-015637
Document ID
CA-D-00925
Evidence Provenance
Source URL
Wayback Machine
Content hash (SHA-256)
03a8f2f0985038892e38087e7dd7593dc83deabf61646ed68d6aed2984bd597a
Analysis generated
July 6, 2026 22:12 UTC
Methodology
Evidence
✓ Snapshot stored   ✓ Hash verified
Citation Record
Entity: Google Gemini
Document: Gemini 3.1 Pro Model Card
Record ID: CA-P-015637
Captured: 2026-07-06 22:12:58 UTC
SHA-256: 03a8f2f098503889…
URL: https://conductatlas.com/platform/google-gemini/gemini-31-pro-model-card/provision/CA-P-015637/cbrn-risk-domain-evaluation-and-ongoing-mitigations/
Accessed: July 23, 2026
Permanent archival reference. Stable identifier suitable for legal filings, compliance documentation, and research citation.
Classification
Severity
High
Categories

Other risks in this policy

Governance intelligence across arbitration, AI governance, data rights, indemnification, and retention
Provision-level monitoring, governance timelines, and regulatory mapping built from archived source documents and historical version tracking.
Start Professional · $99/mo Start with Monitor · $29/mo

Frequently Asked Questions

What does Google Gemini's CBRN Risk Domain Evaluation and Ongoing Mitigations clause do?

This provision discloses a material CBRN risk finding and the deployment of active mitigations, which is operationally significant for regulated sector deployers, government customers, and compliance teams evaluating the model's risk profile under biosecurity, export control, and AI governance frameworks. The characterization of actionable CBRN information capability, qualified by the stated failure to reach critical stage completeness, is a nuanced …

How does this clause affect you?

The document states that the model can provide accurate and actionable CBRN-domain information but does not reach the Critical Capability Level due to gaps in completeness for critical stages, and that mitigations remain active. Enterprise and government deployers should assess this disclosure within their applicable security and compliance frameworks.

Is ConductAtlas affiliated with Google Gemini?

No. ConductAtlas is an independent monitoring service. We are not affiliated with, endorsed by, or sponsored by Google Gemini.