DISA IL6 provisional authorization on disconnected infrastructure
Google states that Distributed Cloud air-gapped services carry Impact Level 6 provisional authorizations issued by DISA, and lists Gemini on Google Distributed Cloud among the services in that IL6 scope. IL6 sits above the levels DoD associates with CUI.
Is Gemini on Google Distributed Cloud (air-gapped) safe for CUI?
by Google
As of July 27, 2026. FedRAMP authorizations, DoD Impact Level approvals and vendor data-handling terms change. Every finding below links to the primary source it came from — open it and confirm the current status before you make a boundary decision.
What this verdict rests on
The source the finding above is drawn from, quoted so you can check the reading rather than take our word for it.
Primary source
“Google Distributed Cloud air-gapped services meet demanding US government compliance requirements that are verified through formal third-party authorizations, including the Impact Level 6 (IL6) provisional authorizations (PA) issued by the Defense Information Systems Agency (DISA).”
Google Cloud documentation — DoD compliance scope for Distributed Cloud air-gapped · read 2026-07-27
FedRAMP
Outside FedRAMP by design (not a hosted cloud service)
DoD Impact Level
IL6 provisional authorization (DISA)
Deployment pattern
In-boundary / self-hosted inference
Overview
Google Distributed Cloud air-gapped runs Google's stack — including Gemini models — on infrastructure disconnected from the public internet, typically in the customer's own facility. It is the vendor-supplied end of the in-boundary pattern: someone else's software, your physical boundary.
Where does the data physically go?
The first question in any CUI boundary decision is not whether a product is secure — it is which system boundary the data lands in, and whose authorization covers that boundary.
Data location
Inference runs on air-gapped infrastructure rather than in a hosted cloud region. The whole point of the pattern is that there is no network path off the deployment, which is why it is authorized at a level above the CUI ones.
Primary source
“Google Distributed Cloud air-gapped services meet demanding US government compliance requirements that are verified through formal third-party authorizations, including the Impact Level 6 (IL6) provisional authorizations (PA) issued by the Defense Information Systems Agency (DISA).”
Google Cloud documentation — DoD compliance scope for Distributed Cloud air-gapped · read 2026-07-27
Model training and retention
Not established. We did not establish an explicit training or retention statement for the air-gapped configuration from a primary source. It is reasonable to expect no external training path from a disconnected deployment, but reasonable expectation is not a citation — verify the terms with Google for your deployment.
What authorization exists?
A platform-level authorization does not automatically extend to every service running on it. What matters is whether this specific AI service is named in the authorization scope.
FedRAMP authorization
FedRAMP is a programme for hosted cloud services, and an air-gapped on-premises deployment sits outside it by construction. The authorization Google publishes for this product is the DoD one: IL6 provisional authorizations issued by DISA, with Gemini on Google Distributed Cloud named in the in-scope service list.
Primary source
“Google Distributed Cloud air-gapped services meet demanding US government compliance requirements that are verified through formal third-party authorizations, including the Impact Level 6 (IL6) provisional authorizations (PA) issued by the Defense Information Systems Agency (DISA).”
Google Cloud documentation — DoD compliance scope for Distributed Cloud air-gapped · read 2026-07-27
DoD Impact Level
Google states that Distributed Cloud air-gapped services are verified through formal third-party authorizations including IL6 provisional authorizations issued by DISA, and its in-scope list names Gemini on Google Distributed Cloud, including Gemini Pro and Gemini Flash.
Primary source
“Google Distributed Cloud air-gapped services meet demanding US government compliance requirements that are verified through formal third-party authorizations, including the Impact Level 6 (IL6) provisional authorizations (PA) issued by the Defense Information Systems Agency (DISA).”
Google Cloud documentation — DoD compliance scope for Distributed Cloud air-gapped · read 2026-07-27
Vendor's own position on CUI
Not established. Google does not state a CUI or DFARS 252.204-7012 position for the air-gapped product in the documentation we read — the IL6 authorization is the claim it makes. Confirm the contractual position with Google before treating the authorization as an answer to a DFARS flowdown.
What DFARS 252.204-7012 and NIST 800-171 require of this pattern
Quoted from the regulation itself, not paraphrased.
DFARS 252.204-7012(b)(2)(i) — NIST SP 800-171 on your own systems
Any unclassified system owned or operated by or for the contractor that processes, stores or transmits covered defense information is a "covered contractor information system" and carries the full NIST SP 800-171 requirement set. An AI assistant does not sit outside this because it is new: if CUI reaches it, the system it runs on is in scope, and the revision that applies is the one in effect when the solicitation issued.
Primary source
“Except as provided in paragraph (b)(2)(ii) of this clause, the covered contractor information system shall be subject to the security requirements in National Institute of Standards and Technology (NIST) Special Publication (SP) 800-171 ... in effect at the time the solicitation is issued or as authorized by the Contracting Officer.”
Acquisition.gov (DFARS, MAY 2024 revision) — DFARS 252.204-7012 Safeguarding Covered Defense Information and Cyber Incident Reporting · read 2026-07-27
NIST SP 800-171 — the control set itself
The security requirements DFARS 7012 imports. Rev. 3 (May 2024) is the current final publication; which revision binds a given contract is set by the solicitation, so check the clause in your award rather than assuming. For an AI deployment the load-bearing families are access control, audit and accountability, and system and communications protection — an assistant that reaches CUI must be inside the same access, logging and boundary-protection regime as any other system that touches it.
Primary source
“This publication provides federal agencies with recommended security requirements for protecting the confidentiality of CUI when the information is resident in nonfederal systems and organizations.”
NIST Computer Security Resource Center — NIST SP 800-171 Rev. 3, Protecting Controlled Unclassified Information in Nonfederal Systems and Organizations · read 2026-07-27
NIST 800-171 controls this decision turns on
These are the controls an assessor works through when CUI reaches an AI service. They are the controls at stake, not a finding against the vendor.
The compliant pattern
This is the heaviest of the in-boundary options and the one with the strongest published DoD authorization. Treat the deployment as a system inside your boundary: it goes in the SSP and the boundary diagram, and the operational controls — access, audit, configuration management, media handling for the update path — are yours even though Google supplies the stack. Because an IL6 authorization is a higher bar than the CUI levels, do not assume it settles a DFARS flowdown on its own: get the contractual position from Google in writing alongside the authorization record.
Patterns with an authorized path for CUI
Sources for this page
Every finding above rests on one of these. Nothing on this page is asserted without one.
- Google Cloud documentation — DoD compliance scope for Distributed Cloud air-gapped · read 2026-07-27
Related Compliance Assessments
Frequently Asked Questions
Is Gemini on Google Distributed Cloud approved for CUI?
Google publishes an IL6 provisional authorization from DISA for Distributed Cloud air-gapped services, with Gemini named in the in-scope list. IL6 sits above the Impact Levels DoD associates with controlled unclassified information. Google does not state a DFARS 252.204-7012 position for the product in the documentation we read, so confirm that contractually.
Why does this have no FedRAMP authorization?
FedRAMP authorizes hosted cloud service offerings. An air-gapped, customer-sited deployment is not one, so it is authorized through the DoD provisional authorization process instead. The absence of a FedRAMP record here is a category fact, not a gap.
How does this differ from self-hosting an open-weight model?
Both keep inference inside your physical boundary. This one comes with a vendor-supplied stack and a published DoD authorization; self-hosting gives you full control of the stack and no vendor authorization to inherit. The control burden is similar; the procurement and the evidence trail are not.
Your AI tools are one row in the boundary
Audit the rest of the stack — storage, email, collaboration — against the same FedRAMP test.
Launch CUI AuditorGet a defensible CUI architecture
This Gemini on Google Distributed Cloud (air-gapped) CUI review flags the gaps. The next step is a compliance architecture review where we map your data flows to FedRAMP-authorized alternatives and CMMC-aligned controls.
Schedule architecture review