The document discloses that Gemini 3.1 Pro can provide accurate and actionable CBRN-relevant information but does not meet the Critical Capability Level threshold because it fails to provide sufficiently complete instructions for critical stages required to enhance the capabilities of low to medium resourced threat actors, and that ongoing mitigations are deployed.
This analysis describes what Google Gemini's agreement states, permits, or reserves. It does not constitute a legal determination about enforceability. Regulatory applicability and practical outcomes may vary by jurisdiction, enforcement context, and individual circumstances. Read our methodology
This provision discloses a material CBRN risk finding and the deployment of active mitigations, which is operationally significant for regulated sector deployers, government customers, and compliance teams evaluating the model's risk profile under biosecurity, export control, and AI governance frameworks. The characterization of actionable CBRN information capability, qualified by the stated failure to reach critical stage completeness, is a nuanced safety finding requiring careful reading.
Interpretive note: The characterization of what constitutes sufficiently complete instructions for critical stages and the definition of low to medium resourced threat actors involves evaluative judgments not fully specified in the model card, creating some interpretive uncertainty in assessing the practical scope of the disclosed capability.
The document states that the model can provide accurate and actionable CBRN-domain information but does not reach the Critical Capability Level due to gaps in completeness for critical stages, and that mitigations remain active. Enterprise and government deployers should assess this disclosure within their applicable security and compliance frameworks.
Cross-platform context
See how other platforms handle CBRN Risk Domain Evaluation and Ongoing Mitigations and similar clauses.
Compare across platforms →"The model can provide highly accurate and actionable information but still fails to offer novel or sufficiently complete and detailed instructions for critical stages, to significantly enhance the capabilities of low to medium resourced threat actors required for the CCL. We continue to deploy mitigations in this domain.Excerpt from Google Gemini's Gemini 3.1 Pro Model Card
(1) REGULATORY LANDSCAPE: The CBRN risk domain disclosure engages export control regulations including the US Export Administration Regulations and relevant international biosecurity frameworks.
Enforcement risk, jurisdiction flags, contract triggers, and due diligence action items.
Get the research letter
Companies change their terms quietly. We read every version and catch what actually changed. One email a week on the changes that matter and what they mean.
This provision discloses a material CBRN risk finding and the deployment of active mitigations, which is operationally significant for regulated sector deployers, government customers, and compliance teams evaluating the model's risk profile under biosecurity, export control, and AI governance frameworks. The characterization of actionable CBRN information capability, qualified by the stated failure to reach critical stage completeness, is a nuanced …
The document states that the model can provide accurate and actionable CBRN-domain information but does not reach the Critical Capability Level due to gaps in completeness for critical stages, and that mitigations remain active. Enterprise and government deployers should assess this disclosure within their applicable security and compliance frameworks.
No. ConductAtlas is an independent monitoring service. We are not affiliated with, endorsed by, or sponsored by Google Gemini.