Get the weekly research letter
Companies change their terms quietly. We read every version and catch what actually changed. One email a week on the changes that matter and what they mean. No account.
The model card discloses that Gemini 3.1 Pro has reached the cyber alert threshold under Google's Frontier Safety Framework, indicating elevated cyber capabilities relative to its predecessor, while stating the Critical Capability Level has not been reached and that mitigations remain active.
This analysis describes what Google Gemini's agreement states, permits, or reserves. It does not constitute a legal determination about enforceability. Regulatory applicability and practical outcomes may vary by jurisdiction, enforcement context, and individual circumstances. Read our methodology
This provision discloses a material frontier safety finding that enterprise deployers, regulated sector customers, and AI governance compliance teams may need to evaluate as part of vendor risk assessments and internal AI risk classification processes. The ongoing deployment of mitigations in the cyber domain, as stated in the document, is an operationally relevant disclosure for organizations assessing supply chain risk from AI model providers.
The document states that Gemini 3.1 Pro has reached the cyber alert threshold, meaning the model demonstrates elevated cyber capabilities, though Google states the Critical Capability Level has not been reached and mitigations are deployed. Downstream deployers and enterprise users of the model should factor this disclosure into their AI risk assessment and vendor due diligence processes.
Cross-platform context
See how other platforms handle Cyber Alert Threshold Disclosure and similar clauses.
Compare across platforms →Monitoring
Google Gemini has changed this document before.
Receive same-day alerts, structured change summaries, and monitoring for up to 25 platforms.
"We conducted additional testing on the model in this domain as Gemini 3 Pro had previously reached the alert threshold. The model shows an increase in cyber capabilities compared to Gemini 3 Pro. As with Gemini 3 Pro, the model has reached the alert threshold, but still does not reach the levels of uplift required for the CCL. We continue to deploy mitigations in this domain.Excerpt from Google Gemini's Gemini 3.1 Pro Model Card
(1) REGULATORY LANDSCAPE: The cyber alert threshold disclosure engages the EU AI Act's provisions on general-purpose AI models with systemic risk, which may impose enhanced transparency and risk assessment obligations on providers and deployers when models exceed defined capability thresholds. In the United States, voluntary AI safety commitments made to the executive branch and the NIST AI Risk Management Framework may provide relevant assessment guidance. The EU AI Office is the primary enforcement authority for systemic risk provisions of the EU AI Act at the EU level. (2) GOVERNANCE EXPOSURE: High. The disclosure that Gemini 3.1 Pro has reached the cyber alert threshold for the second consecutive model generation (following Gemini 3 Pro) is a material safety finding. Regulated sector deployers in financial services, critical infrastructure, and government contexts may face internal policy obligations to review this disclosure as part of AI vendor risk management, even absent formal legal requirements in all jurisdictions. (3) JURISDICTION FLAGS: EU and EEA deployers face the highest regulatory exposure under the EU AI Act's systemic risk provisions for general-purpose AI models. UK organizations should evaluate this disclosure under emerging UK AI governance guidance. US federal agencies and government contractors may face additional review obligations under executive AI governance requirements. Critical infrastructure operators globally may face sector-specific obligations to assess cyber risk disclosures from AI vendors. (4) CONTRACT AND VENDOR IMPLICATIONS: Enterprise procurement teams integrating Gemini 3.1 Pro should review whether existing vendor agreements or internal AI procurement policies require disclosure of frontier safety findings, including alert threshold results. The document does not address contractual liability for cyber risks arising from model use, and applicable terms of service documents are cross-referenced rather than reproduced. Vendor assessments should confirm that mitigation measures described are contractually or operationally binding rather than solely discretionary. (5) COMPLIANCE CONSIDERATIONS: Compliance teams should document this frontier safety disclosure as part of their AI inventory and risk register entries for Gemini 3.1 Pro. Organizations subject to the EU AI Act should evaluate whether this disclosure triggers obligations related to GPAI model systemic risk assessment. Security teams should assess whether the stated cyber capability elevation and ongoing mitigations are sufficient for their deployment risk tolerance, and seek additional technical detail from Google as needed.
This provision discloses a material frontier safety finding that enterprise deployers, regulated sector customers, and AI governance compliance teams may need to evaluate as part of vendor risk assessments and internal AI risk classification processes. The ongoing deployment of mitigations in the cyber domain, as stated in the document, is an operationally relevant disclosure for organizations assessing supply chain risk …
The document states that Gemini 3.1 Pro has reached the cyber alert threshold, meaning the model demonstrates elevated cyber capabilities, though Google states the Critical Capability Level has not been reached and mitigations are deployed. Downstream deployers and enterprise users of the model should factor this disclosure into their AI risk assessment and vendor due diligence processes.
No. ConductAtlas is an independent monitoring service. We are not affiliated with, endorsed by, or sponsored by Google Gemini.