Provision record
Google Gemini · Gemini 3.1 Pro Model Card · View original document ↗

CBRN Risk Domain Evaluation and Ongoing Mitigations

High severity Medium confidence Explicit document language Unique · 0 of 352 platforms
Stay ahead of the changes
Track Google Gemini and get the diff the day its terms change.
Share 𝕏 Share in Share 🔒 PDF
Document Record

What it is

The document discloses that Gemini 3.1 Pro can provide accurate and actionable CBRN-relevant information but does not meet the Critical Capability Level threshold because it fails to provide sufficiently complete instructions for critical stages required to enhance the capabilities of low to medium resourced threat actors, and that ongoing mitigations are deployed.

This analysis describes what Google Gemini's agreement states, permits, or reserves. It does not constitute a legal determination about enforceability. Regulatory applicability and practical outcomes may vary by jurisdiction, enforcement context, and individual circumstances. Read our methodology

ConductAtlas Analysis

Why it matters (compliance & governance perspective)

This provision discloses a material CBRN risk finding and the deployment of active mitigations, which is operationally significant for regulated sector deployers, government customers, and compliance teams evaluating the model's risk profile under biosecurity, export control, and AI governance frameworks. The characterization of actionable CBRN information capability, qualified by the stated failure to reach critical stage completeness, is a nuanced safety finding requiring careful reading.

Interpretive note: The characterization of what constitutes sufficiently complete instructions for critical stages and the definition of low to medium resourced threat actors involves evaluative judgments not fully specified in the model card, creating some interpretive uncertainty in assessing the practical scope of the disclosed capability.

Consumer impact (what this means for users)

The document states that the model can provide accurate and actionable CBRN-domain information but does not reach the Critical Capability Level due to gaps in completeness for critical stages, and that mitigations remain active. Enterprise and government deployers should assess this disclosure within their applicable security and compliance frameworks.

Cross-platform context

See how other platforms handle CBRN Risk Domain Evaluation and Ongoing Mitigations and similar clauses.

Compare across platforms →
▸ View Original Clause Language DOCUMENT RECORD
"
The model can provide highly accurate and actionable information but still fails to offer novel or sufficiently complete and detailed instructions for critical stages, to significantly enhance the capabilities of low to medium resourced threat actors required for the CCL. We continue to deploy mitigations in this domain.

Excerpt from Google Gemini's Gemini 3.1 Pro Model Card

ConductAtlas Analysis

Institutional analysis (regulatory & governance intelligence)

(1) REGULATORY LANDSCAPE: The CBRN risk domain disclosure engages export control regulations including the US Export Administration Regulations and relevant international biosecurity frameworks.

Insight

Unlock the full institutional analysis

Enforcement risk, jurisdiction flags, contract triggers, and due diligence action items.

Applicable agencies

  • Federal Trade Commission (ftc)
    Oversees unfair or deceptive business practices and can investigate companies that mislead consumers about data collection, sharing, or use.
    Who can file: Anyone affected by the company's practices (US or international)
    What you need: Your account details, a timeline of relevant events, and a description of the specific issue
    What to expect: Complaints inform FTC enforcement priorities and investigations but do not result in individual resolution or compensation
    File a complaint →

Provision details

Document information
Document
Gemini 3.1 Pro Model Card
Entity
Google Gemini
Document last updated
July 6, 2026
Tracking information
First tracked
July 6, 2026
Last verified
July 9, 2026
Record ID
CA-P-015637
Document ID
CA-D-00925
Evidence Provenance
Source URL
Wayback Machine
Content hash (SHA-256)
03a8f2f0985038892e38087e7dd7593dc83deabf61646ed68d6aed2984bd597a
Analysis generated
July 6, 2026 22:12 UTC
Methodology
Evidence
✓ Snapshot stored   ✓ Hash verified
Citation Record
Entity: Google Gemini
Document: Gemini 3.1 Pro Model Card
Record ID: CA-P-015637
Captured: 2026-07-06 22:12:58 UTC
SHA-256: 03a8f2f098503889…
URL: https://conductatlas.com/platform/google-gemini/gemini-31-pro-model-card/provision/CA-P-015637/cbrn-risk-domain-evaluation-and-ongoing-mitigations/
Accessed: Sept. 8, 2026
Permanent archival reference. Stable identifier suitable for legal filings, compliance documentation, and research citation.
Classification
Severity
High
Categories

Other risks in this policy

Get the research letter

Companies change their terms quietly. We read every version and catch what actually changed. One email a week on the changes that matter and what they mean.

Frequently Asked Questions

What does Google Gemini's CBRN Risk Domain Evaluation and Ongoing Mitigations clause do?

This provision discloses a material CBRN risk finding and the deployment of active mitigations, which is operationally significant for regulated sector deployers, government customers, and compliance teams evaluating the model's risk profile under biosecurity, export control, and AI governance frameworks. The characterization of actionable CBRN information capability, qualified by the stated failure to reach critical stage completeness, is a nuanced …

How does this clause affect you?

The document states that the model can provide accurate and actionable CBRN-domain information but does not reach the Critical Capability Level due to gaps in completeness for critical stages, and that mitigations remain active. Enterprise and government deployers should assess this disclosure within their applicable security and compliance frameworks.

Is ConductAtlas affiliated with Google Gemini?

No. ConductAtlas is an independent monitoring service. We are not affiliated with, endorsed by, or sponsored by Google Gemini.