Google Gemini · Gemini 3.1 Pro Model Card · View original document ↗

Cyber Alert Threshold Disclosure

High severity High confidence Explicitdocumentlanguage Unique · 0 of 352 platforms
Get alerted the next time Google Gemini changes these terms. Get same-day alerts →
Share 𝕏 Share in Share 🔒 PDF
Recent governance activity Google Gemini recorded 4 documented changes in the last 30 days.
Get same-day alerts →
Monitor governance changes for Google Gemini Monitor emails you the same day this changes. The archive stays free.
Get same-day alerts →

Get the weekly research letter

Companies change their terms quietly. We read every version and catch what actually changed. One email a week on the changes that matter and what they mean. No account.

Document Record

What it is

The model card discloses that Gemini 3.1 Pro has reached the cyber alert threshold under Google's Frontier Safety Framework, indicating elevated cyber capabilities relative to its predecessor, while stating the Critical Capability Level has not been reached and that mitigations remain active.

This analysis describes what Google Gemini's agreement states, permits, or reserves. It does not constitute a legal determination about enforceability. Regulatory applicability and practical outcomes may vary by jurisdiction, enforcement context, and individual circumstances. Read our methodology

ConductAtlas Analysis

Why it matters (compliance & governance perspective)

This provision discloses a material frontier safety finding that enterprise deployers, regulated sector customers, and AI governance compliance teams may need to evaluate as part of vendor risk assessments and internal AI risk classification processes. The ongoing deployment of mitigations in the cyber domain, as stated in the document, is an operationally relevant disclosure for organizations assessing supply chain risk from AI model providers.

Consumer impact (what this means for users)

The document states that Gemini 3.1 Pro has reached the cyber alert threshold, meaning the model demonstrates elevated cyber capabilities, though Google states the Critical Capability Level has not been reached and mitigations are deployed. Downstream deployers and enterprise users of the model should factor this disclosure into their AI risk assessment and vendor due diligence processes.

Cross-platform context

See how other platforms handle Cyber Alert Threshold Disclosure and similar clauses.

Compare across platforms →

Monitoring

Google Gemini has changed this document before.

Receive same-day alerts, structured change summaries, and monitoring for up to 25 platforms.

Get Monitor Or create a free account →
▸ View Original Clause Language DOCUMENT RECORD
"
We conducted additional testing on the model in this domain as Gemini 3 Pro had previously reached the alert threshold. The model shows an increase in cyber capabilities compared to Gemini 3 Pro. As with Gemini 3 Pro, the model has reached the alert threshold, but still does not reach the levels of uplift required for the CCL. We continue to deploy mitigations in this domain.

Excerpt from Google Gemini's Gemini 3.1 Pro Model Card

ConductAtlas Analysis

Institutional analysis (regulatory & governance intelligence)

(1) REGULATORY LANDSCAPE: The cyber alert threshold disclosure engages the EU AI Act's provisions on general-purpose AI models with systemic risk, which may impose enhanced transparency and risk assessment obligations on providers and deployers when models exceed defined capability thresholds. In the United States, voluntary AI safety commitments made to the executive branch and the NIST AI Risk Management Framework may provide relevant assessment guidance. The EU AI Office is the primary enforcement authority for systemic risk provisions of the EU AI Act at the EU level. (2) GOVERNANCE EXPOSURE: High. The disclosure that Gemini 3.1 Pro has reached the cyber alert threshold for the second consecutive model generation (following Gemini 3 Pro) is a material safety finding. Regulated sector deployers in financial services, critical infrastructure, and government contexts may face internal policy obligations to review this disclosure as part of AI vendor risk management, even absent formal legal requirements in all jurisdictions. (3) JURISDICTION FLAGS: EU and EEA deployers face the highest regulatory exposure under the EU AI Act's systemic risk provisions for general-purpose AI models. UK organizations should evaluate this disclosure under emerging UK AI governance guidance. US federal agencies and government contractors may face additional review obligations under executive AI governance requirements. Critical infrastructure operators globally may face sector-specific obligations to assess cyber risk disclosures from AI vendors. (4) CONTRACT AND VENDOR IMPLICATIONS: Enterprise procurement teams integrating Gemini 3.1 Pro should review whether existing vendor agreements or internal AI procurement policies require disclosure of frontier safety findings, including alert threshold results. The document does not address contractual liability for cyber risks arising from model use, and applicable terms of service documents are cross-referenced rather than reproduced. Vendor assessments should confirm that mitigation measures described are contractually or operationally binding rather than solely discretionary. (5) COMPLIANCE CONSIDERATIONS: Compliance teams should document this frontier safety disclosure as part of their AI inventory and risk register entries for Gemini 3.1 Pro. Organizations subject to the EU AI Act should evaluate whether this disclosure triggers obligations related to GPAI model systemic risk assessment. Security teams should assess whether the stated cyber capability elevation and ongoing mitigations are sufficient for their deployment risk tolerance, and seek additional technical detail from Google as needed.

Full institutional analysis
Regulatory citations, enforcement risk, and due diligence action items.
Start Professional · $99/mo Start with Monitor · $29/mo

Applicable agencies

  • FTC
    The FTC has jurisdiction over unfair or deceptive practices in AI contexts, including representations about AI safety capabilities and risk mitigations made to enterprise and consumer customers.
    File a complaint →

Provision details

Document information
Document
Gemini 3.1 Pro Model Card
Entity
Google Gemini
Document last updated
July 6, 2026
Tracking information
First tracked
July 6, 2026
Last verified
July 9, 2026
Record ID
CA-P-015632
Document ID
CA-D-00925
Evidence Provenance
Source URL
Wayback Machine
Content hash (SHA-256)
03a8f2f0985038892e38087e7dd7593dc83deabf61646ed68d6aed2984bd597a
Analysis generated
July 6, 2026 22:12 UTC
Methodology
Evidence
✓ Snapshot stored   ✓ Hash verified
Citation Record
Entity: Google Gemini
Document: Gemini 3.1 Pro Model Card
Record ID: CA-P-015632
Captured: 2026-07-06 22:12:58 UTC
SHA-256: 03a8f2f098503889…
URL: https://conductatlas.com/platform/google-gemini/gemini-31-pro-model-card/provision/CA-P-015632/cyber-alert-threshold-disclosure/
Accessed: July 23, 2026
Permanent archival reference. Stable identifier suitable for legal filings, compliance documentation, and research citation.
Classification
Severity
High
Categories

Other risks in this policy

Governance intelligence across arbitration, AI governance, data rights, indemnification, and retention
Provision-level monitoring, governance timelines, and regulatory mapping built from archived source documents and historical version tracking.
Start Professional · $99/mo Start with Monitor · $29/mo

Frequently Asked Questions

What does Google Gemini's Cyber Alert Threshold Disclosure clause do?

This provision discloses a material frontier safety finding that enterprise deployers, regulated sector customers, and AI governance compliance teams may need to evaluate as part of vendor risk assessments and internal AI risk classification processes. The ongoing deployment of mitigations in the cyber domain, as stated in the document, is an operationally relevant disclosure for organizations assessing supply chain risk …

How does this clause affect you?

The document states that Gemini 3.1 Pro has reached the cyber alert threshold, meaning the model demonstrates elevated cyber capabilities, though Google states the Critical Capability Level has not been reached and mitigations are deployed. Downstream deployers and enterprise users of the model should factor this disclosure into their AI risk assessment and vendor due diligence processes.

Is ConductAtlas affiliated with Google Gemini?

No. ConductAtlas is an independent monitoring service. We are not affiliated with, endorsed by, or sponsored by Google Gemini.