In scope at FedRAMP High and DoD IL4/IL5 — inside an Assured Workloads boundary
Google's scope table marks Generative AI on the Gemini Enterprise Agent Platform (formerly Generative AI on Vertex AI) as Supported at FedRAMP High and DoD IL2, IL4 and IL5, and names it on Google's ITAR in-scope services list. The authorization is conditional on deploying inside a correctly configured Assured Workloads boundary.
Is Gemini via Vertex AI under Assured Workloads safe for CUI?
by Google
As of July 27, 2026. FedRAMP authorizations, DoD Impact Level approvals and vendor data-handling terms change. Every finding below links to the primary source it came from — open it and confirm the current status before you make a boundary decision.
What this verdict rests on
The 3 sources the finding above is drawn from, quoted so you can check the reading rather than take our word for it.
Primary source
“This document provides a detailed list of Google Cloud and Google Workspace services in scope for FedRAMP High, DoD IL2, DoD IL4, and DoD IL5 provisional authorizations.”
Google Cloud documentation — FedRAMP and DoD compliance scope for Google Cloud and Google Workspace · read 2026-07-27
Primary source
“DoD contractors and DIB customers can use Google Cloud and Google Workspace to meet the requirements of DFARS 252.204-7012. By enabling Assured Workloads or Assured Controls, these organizations can facilitate the creation of compliant boundaries or system enclaves within their Google Cloud environments. ... Customers must select the FedRAMP Moderate or FedRAMP High regulatory control package for deployment within the software-defined boundary.”
Google Cloud — Google Cloud compliance — Defense Federal Acquisition Regulation Supplement (DFARS) · read 2026-07-27
Primary source
“Generative AI on Gemini Enterprise Agent Platform (formerly Generative AI on Vertex AI; includes Gemini models 3.x or greater)”
Google Cloud — Google Cloud services that are in scope for ITAR · read 2026-07-27
FedRAMP
High (in an Assured Workloads boundary)
DoD Impact Level
IL2, IL4, IL5
Deployment pattern
Government cloud / sovereign variant
Overview
Running Gemini through Vertex AI (now the Gemini Enterprise Agent Platform) inside a Google Cloud Assured Workloads boundary is the Google-side pattern with the strongest published authorization position — and the one that most rewards reading the scope table row by row rather than taking the product name as the answer.
Where does the data physically go?
The first question in any CUI boundary decision is not whether a product is secure — it is which system boundary the data lands in, and whose authorization covers that boundary.
Data location
Data location follows the Assured Workloads control package you select. Google is explicit that the boundary is something you enable and configure — the compliant enclave is created by the Assured Workloads or Assured Controls configuration, not by choosing the product.
Primary source
“DoD contractors and DIB customers can use Google Cloud and Google Workspace to meet the requirements of DFARS 252.204-7012. By enabling Assured Workloads or Assured Controls, these organizations can facilitate the creation of compliant boundaries or system enclaves within their Google Cloud environments. ... Customers must select the FedRAMP Moderate or FedRAMP High regulatory control package for deployment within the software-defined boundary.”
Google Cloud — Google Cloud compliance — Defense Federal Acquisition Regulation Supplement (DFARS) · read 2026-07-27
Model training and retention
Not established. We did not establish a training and retention statement specific to this configuration from a primary source in preparing this entry. Google publishes data-governance and zero-data-retention documentation for its generative-AI platform; read it for your exact regime and verify with Google.
What authorization exists?
A platform-level authorization does not automatically extend to every service running on it. What matters is whether this specific AI service is named in the authorization scope.
FedRAMP authorization
Google's compliance-scope document lists services in scope for FedRAMP High and DoD IL2, IL4 and IL5. In its service table the row "Generative AI on Gemini Enterprise Agent Platform (formerly Generative AI on Vertex AI)" is marked Supported in all four columns — the only mainstream commercial generative-AI service in this checker that Google marks Supported at IL5. Note the granularity elsewhere in the same table: Tuning shows DISA review at IL4 and IL5, and Workbench carries no IL4/IL5 entry.
Primary source
“This document provides a detailed list of Google Cloud and Google Workspace services in scope for FedRAMP High, DoD IL2, DoD IL4, and DoD IL5 provisional authorizations.”
Google Cloud documentation — FedRAMP and DoD compliance scope for Google Cloud and Google Workspace · read 2026-07-27
DoD Impact Level
Marked Supported at DoD IL2, IL4 and IL5 in the same table. IL4 is the level DoD associates with controlled unclassified information, which is what makes this row the useful one for a CUI decision.
Primary source
“This document provides a detailed list of Google Cloud and Google Workspace services in scope for FedRAMP High, DoD IL2, DoD IL4, and DoD IL5 provisional authorizations.”
Google Cloud documentation — FedRAMP and DoD compliance scope for Google Cloud and Google Workspace · read 2026-07-27
Vendor's own position on CUI
Google names the service on its ITAR in-scope list — "Generative AI on Gemini Enterprise Agent Platform (formerly Generative AI on Vertex AI; includes Gemini models 3.x or greater)" — and separately states that DIB customers can use Google Cloud to meet DFARS 252.204-7012 requirements by enabling Assured Workloads or Assured Controls. Note the model-version qualifier in the ITAR entry; it is doing real work.
Primary source
“Generative AI on Gemini Enterprise Agent Platform (formerly Generative AI on Vertex AI; includes Gemini models 3.x or greater)”
Google Cloud — Google Cloud services that are in scope for ITAR · read 2026-07-27
What DFARS 252.204-7012 and NIST 800-171 require of this pattern
Quoted from the regulation itself, not paraphrased.
DFARS 252.204-7012(b)(2)(ii)(D) — the external cloud service provider test
This is the paragraph that decides most AI questions. The moment an external cloud service provider stores, processes or transmits covered defense information, the contractor must require and ensure that provider meets security requirements equivalent to the FedRAMP Moderate baseline — and that it complies with the clause's incident reporting, malicious software, media preservation, forensic access and damage assessment paragraphs. A commercial AI endpoint is an external cloud service provider. The obligation to ensure equivalency sits on the contractor, not the vendor.
Primary source
“If the Contractor intends to use an external cloud service provider to store, process, or transmit any covered defense information in performance of this contract, the Contractor shall require and ensure that the cloud service provider meets security requirements equivalent to those established by the Government for the Federal Risk and Authorization Management Program (FedRAMP) Moderate baseline ... and that the cloud service provider complies with requirements in paragraphs (c) through (g) of this clause for cyber incident reporting, malicious software, media preservation and protection, access to additional information and equipment necessary for forensic analysis, and cyber incident damage assessment.”
Acquisition.gov (DFARS, MAY 2024 revision) — DFARS 252.204-7012 Safeguarding Covered Defense Information and Cyber Incident Reporting · read 2026-07-27
DFARS 252.204-7012(b)(2)(i) — NIST SP 800-171 on your own systems
Any unclassified system owned or operated by or for the contractor that processes, stores or transmits covered defense information is a "covered contractor information system" and carries the full NIST SP 800-171 requirement set. An AI assistant does not sit outside this because it is new: if CUI reaches it, the system it runs on is in scope, and the revision that applies is the one in effect when the solicitation issued.
Primary source
“Except as provided in paragraph (b)(2)(ii) of this clause, the covered contractor information system shall be subject to the security requirements in National Institute of Standards and Technology (NIST) Special Publication (SP) 800-171 ... in effect at the time the solicitation is issued or as authorized by the Contracting Officer.”
Acquisition.gov (DFARS, MAY 2024 revision) — DFARS 252.204-7012 Safeguarding Covered Defense Information and Cyber Incident Reporting · read 2026-07-27
NIST SP 800-171 — the control set itself
The security requirements DFARS 7012 imports. Rev. 3 (May 2024) is the current final publication; which revision binds a given contract is set by the solicitation, so check the clause in your award rather than assuming. For an AI deployment the load-bearing families are access control, audit and accountability, and system and communications protection — an assistant that reaches CUI must be inside the same access, logging and boundary-protection regime as any other system that touches it.
Primary source
“This publication provides federal agencies with recommended security requirements for protecting the confidentiality of CUI when the information is resident in nonfederal systems and organizations.”
NIST Computer Security Resource Center — NIST SP 800-171 Rev. 3, Protecting Controlled Unclassified Information in Nonfederal Systems and Organizations · read 2026-07-27
NIST 800-171 controls this decision turns on
These are the controls an assessor works through when CUI reaches an AI service. They are the controls at stake, not a finding against the vendor.
The compliant pattern
Create the Assured Workloads folder with the control package your contract requires — FedRAMP Moderate, FedRAMP High, IL4 or IL5 — and deploy every resource inside it; a project outside the folder is outside the boundary you are claiming. Then check three things at feature level rather than product level: that the specific Gemini services you use are marked Supported at your impact level (Tuning and Workbench are not, at the time of writing), that the model versions you call satisfy the ITAR entry's version qualifier if ITAR applies, and that endpoint configuration keeps traffic within the intended regions. Document the folder, the control package and the service list in the SSP.
Patterns with an authorized path for CUI
Sources for this page
Every finding above rests on one of these. Nothing on this page is asserted without one.
- Google Cloud documentation — FedRAMP and DoD compliance scope for Google Cloud and Google Workspace · read 2026-07-27
- Google Cloud — Google Cloud compliance — Defense Federal Acquisition Regulation Supplement (DFARS) · read 2026-07-27
- Google Cloud — Google Cloud services that are in scope for ITAR · read 2026-07-27
Authorization records move and this page does not. Confirm Google's package records on the FedRAMP Marketplace before you rely on anything above.
Related Compliance Assessments
Frequently Asked Questions
Is Vertex AI approved for CUI?
Google marks Generative AI on the Gemini Enterprise Agent Platform as Supported at FedRAMP High and DoD IL2, IL4 and IL5, and names it on its ITAR in-scope list. That is conditional on deployment inside an Assured Workloads boundary configured for the right regime — the same service outside that boundary is outside the authorization.
Is every Vertex AI feature authorized at IL4 and IL5?
No. In the same table Tuning shows DISA review at IL4 and IL5, and Workbench carries no IL4 or IL5 entry. Read the table at the row level for the specific services you intend to use, rather than treating the platform as one unit.
Does this cover ITAR data?
Google lists Generative AI on the Gemini Enterprise Agent Platform on its ITAR in-scope services page, with the qualifier that it includes Gemini models 3.x or greater. If ITAR applies to your work, the model version is part of the compliance question, not just the service.
Your AI tools are one row in the boundary
Audit the rest of the stack — storage, email, collaboration — against the same FedRAMP test.
Launch CUI AuditorGet a defensible CUI architecture
This Gemini via Vertex AI under Assured Workloads CUI review flags the gaps. The next step is a compliance architecture review where we map your data flows to FedRAMP-authorized alternatives and CMMC-aligned controls.
Schedule architecture review