The model card discloses that Gemini 3.1 Pro has reached the cyber alert threshold under Google's Frontier Safety Framework, indicating elevated cyber capabilities relative to its predecessor, while stating the Critical Capability Level has not been reached and that mitigations remain active.
This analysis describes what Google Gemini's agreement states, permits, or reserves. It does not constitute a legal determination about enforceability. Regulatory applicability and practical outcomes may vary by jurisdiction, enforcement context, and individual circumstances. Read our methodology
This provision discloses a material frontier safety finding that enterprise deployers, regulated sector customers, and AI governance compliance teams may need to evaluate as part of vendor risk assessments and internal AI risk classification processes. The ongoing deployment of mitigations in the cyber domain, as stated in the document, is an operationally relevant disclosure for organizations assessing supply chain risk from AI model providers.
The document states that Gemini 3.1 Pro has reached the cyber alert threshold, meaning the model demonstrates elevated cyber capabilities, though Google states the Critical Capability Level has not been reached and mitigations are deployed. Downstream deployers and enterprise users of the model should factor this disclosure into their AI risk assessment and vendor due diligence processes.
Cross-platform context
See how other platforms handle Cyber Alert Threshold Disclosure and similar clauses.
Compare across platforms →"We conducted additional testing on the model in this domain as Gemini 3 Pro had previously reached the alert threshold. The model shows an increase in cyber capabilities compared to Gemini 3 Pro. As with Gemini 3 Pro, the model has reached the alert threshold, but still does not reach the levels of uplift required for the CCL. We continue to deploy mitigations in this domain.Excerpt from Google Gemini's Gemini 3.1 Pro Model Card
(1) REGULATORY LANDSCAPE: The cyber alert threshold disclosure engages the EU AI Act's provisions on general-purpose AI models with systemic risk, which may impose enhanced transparency and risk assessment obligations on providers and deployers when …
Enforcement risk, jurisdiction flags, contract triggers, and due diligence action items.
Get the research letter
Companies change their terms quietly. We read every version and catch what actually changed. One email a week on the changes that matter and what they mean.
This provision discloses a material frontier safety finding that enterprise deployers, regulated sector customers, and AI governance compliance teams may need to evaluate as part of vendor risk assessments and internal AI risk classification processes. The ongoing deployment of mitigations in the cyber domain, as stated in the document, is an operationally relevant disclosure for organizations assessing supply chain risk …
The document states that Gemini 3.1 Pro has reached the cyber alert threshold, meaning the model demonstrates elevated cyber capabilities, though Google states the Critical Capability Level has not been reached and mitigations are deployed. Downstream deployers and enterprise users of the model should factor this disclosure into their AI risk assessment and vendor due diligence processes.
No. ConductAtlas is an independent monitoring service. We are not affiliated with, endorsed by, or sponsored by Google Gemini.