Google caps this at DoD IL2 — below the level DoD associates with CUI
In Google's own published scope table the Gemini app and Gemini in Workspace are Supported for FedRAMP High and DoD IL2, with the IL4 and IL5 columns blank. Google also instructs administrators to tell users on non-qualifying Workspace editions to avoid entering confidential or sensitive information.
Is Gemini app and Gemini in Google Workspace (commercial) safe for CUI?
by Google
As of July 27, 2026. FedRAMP authorizations, DoD Impact Level approvals and vendor data-handling terms change. Every finding below links to the primary source it came from — open it and confirm the current status before you make a boundary decision.
What this verdict rests on
The 2 sources the finding above is drawn from, quoted so you can check the reading rather than take our word for it.
Primary source
“This document provides a detailed list of Google Cloud and Google Workspace services in scope for FedRAMP High, DoD IL2, DoD IL4, and DoD IL5 provisional authorizations.”
Google Cloud documentation — FedRAMP and DoD compliance scope for Google Cloud and Google Workspace · read 2026-07-27
Primary source
“Users without a qualifying Google Workspace edition are subject to the Google Terms of Service and the Gemini Apps Privacy Notice when they use the Gemini app. Their chats may be reviewed by human reviewers and used to improve Google's products, services, and machine-learning technologies. Tell these users to avoid entering confidential or sensitive information when using the Gemini app.”
Google Workspace Admin Help — Gemini app for Google Workspace — editions and data handling · read 2026-07-27
FedRAMP
High in a Workspace FedRAMP boundary; IL2 ceiling
DoD Impact Level
IL2 only (no IL4 / IL5)
Deployment pattern
Commercial multi-tenant SaaS
Overview
The Gemini app — in a browser, on a phone, and threaded into Gmail, Docs, Drive, Meet and Sheets — is the Google-side equivalent of the shadow-CUI problem. Google publishes an unusually precise answer to the compliance question, and the answer is a ceiling: in its own scope table these surfaces reach DoD IL2 and no further.
Where does the data physically go?
The first question in any CUI boundary decision is not whether a product is secure — it is which system boundary the data lands in, and whose authorization covers that boundary.
Data location
Where the Gemini app is delivered as a core service under a qualifying Workspace edition, Workspace terms apply. Where it is not — a personal account, or a Workspace domain without a qualifying edition — Google states the chats may be reviewed by human reviewers and used to improve Google's products and machine-learning technologies, and tells administrators to warn those users off confidential material.
Primary source
“Users without a qualifying Google Workspace edition are subject to the Google Terms of Service and the Gemini Apps Privacy Notice when they use the Gemini app. Their chats may be reviewed by human reviewers and used to improve Google's products, services, and machine-learning technologies. Tell these users to avoid entering confidential or sensitive information when using the Gemini app.”
Google Workspace Admin Help — Gemini app for Google Workspace — editions and data handling · read 2026-07-27
Model training and retention
The training answer is edition-dependent, not product-dependent. On a non-qualifying edition Google says chats may be used to improve its products, services and machine-learning technologies. Establishing which edition every user in your CUI enclave actually holds is therefore part of the boundary work, not a licensing detail.
Primary source
“Users without a qualifying Google Workspace edition are subject to the Google Terms of Service and the Gemini Apps Privacy Notice when they use the Gemini app. Their chats may be reviewed by human reviewers and used to improve Google's products, services, and machine-learning technologies. Tell these users to avoid entering confidential or sensitive information when using the Gemini app.”
Google Workspace Admin Help — Gemini app for Google Workspace — editions and data handling · read 2026-07-27
What authorization exists?
A platform-level authorization does not automatically extend to every service running on it. What matters is whether this specific AI service is named in the authorization scope.
FedRAMP authorization
Google's FedRAMP and DoD compliance-scope document lists Google Cloud and Workspace services in scope for FedRAMP High, DoD IL2, IL4 and IL5. In its service table the rows "Gemini app" and "Google Workspace with Gemini" are marked Supported under FedRAMP High and DoD IL2, and carry no entry under DoD IL4 or DoD IL5. FedRAMP High does exceed the Moderate baseline DFARS 252.204-7012 asks for — but only inside a Workspace deployment actually configured to that boundary.
Primary source
“This document provides a detailed list of Google Cloud and Google Workspace services in scope for FedRAMP High, DoD IL2, DoD IL4, and DoD IL5 provisional authorizations.”
Google Cloud documentation — FedRAMP and DoD compliance scope for Google Cloud and Google Workspace · read 2026-07-27
DoD Impact Level
DoD IL2 is the level covering publicly releasable information; IL4 is the level DoD associates with controlled unclassified information. Google's table stops the Gemini app and Gemini in Workspace at IL2. That is the single most decision-relevant line on this page.
Primary source
“This document provides a detailed list of Google Cloud and Google Workspace services in scope for FedRAMP High, DoD IL2, DoD IL4, and DoD IL5 provisional authorizations.”
Google Cloud documentation — FedRAMP and DoD compliance scope for Google Cloud and Google Workspace · read 2026-07-27
Vendor's own position on CUI
Google's DFARS page routes CUI work through a configured boundary rather than through the commercial default: contractors are told to enable Assured Workloads or Assured Controls and to select the FedRAMP Moderate or FedRAMP High regulatory control package. The commercial Gemini app is not that configuration.
Primary source
“DoD contractors and DIB customers can use Google Cloud and Google Workspace to meet the requirements of DFARS 252.204-7012. By enabling Assured Workloads or Assured Controls, these organizations can facilitate the creation of compliant boundaries or system enclaves within their Google Cloud environments. ... Customers must select the FedRAMP Moderate or FedRAMP High regulatory control package for deployment within the software-defined boundary.”
Google Cloud — Google Cloud compliance — Defense Federal Acquisition Regulation Supplement (DFARS) · read 2026-07-27
What DFARS 252.204-7012 and NIST 800-171 require of this pattern
Quoted from the regulation itself, not paraphrased.
DFARS 252.204-7012(b)(2)(ii)(D) — the external cloud service provider test
This is the paragraph that decides most AI questions. The moment an external cloud service provider stores, processes or transmits covered defense information, the contractor must require and ensure that provider meets security requirements equivalent to the FedRAMP Moderate baseline — and that it complies with the clause's incident reporting, malicious software, media preservation, forensic access and damage assessment paragraphs. A commercial AI endpoint is an external cloud service provider. The obligation to ensure equivalency sits on the contractor, not the vendor.
Primary source
“If the Contractor intends to use an external cloud service provider to store, process, or transmit any covered defense information in performance of this contract, the Contractor shall require and ensure that the cloud service provider meets security requirements equivalent to those established by the Government for the Federal Risk and Authorization Management Program (FedRAMP) Moderate baseline ... and that the cloud service provider complies with requirements in paragraphs (c) through (g) of this clause for cyber incident reporting, malicious software, media preservation and protection, access to additional information and equipment necessary for forensic analysis, and cyber incident damage assessment.”
Acquisition.gov (DFARS, MAY 2024 revision) — DFARS 252.204-7012 Safeguarding Covered Defense Information and Cyber Incident Reporting · read 2026-07-27
NIST SP 800-171 — the control set itself
The security requirements DFARS 7012 imports. Rev. 3 (May 2024) is the current final publication; which revision binds a given contract is set by the solicitation, so check the clause in your award rather than assuming. For an AI deployment the load-bearing families are access control, audit and accountability, and system and communications protection — an assistant that reaches CUI must be inside the same access, logging and boundary-protection regime as any other system that touches it.
Primary source
“This publication provides federal agencies with recommended security requirements for protecting the confidentiality of CUI when the information is resident in nonfederal systems and organizations.”
NIST Computer Security Resource Center — NIST SP 800-171 Rev. 3, Protecting Controlled Unclassified Information in Nonfederal Systems and Organizations · read 2026-07-27
NIST 800-171 controls this decision turns on
These are the controls an assessor works through when CUI reaches an AI service. They are the controls at stake, not a finding against the vendor.
The compliant pattern
Two things to do, in order. First, confirm which Workspace edition each user in the CUI enclave actually holds — the human-review and training answer changes with the edition, not with the product. Second, if the workload needs to touch CUI, move it off the Gemini app onto a boundary Google itself points at: Vertex AI (Gemini Enterprise Agent Platform) inside an Assured Workloads folder set to FedRAMP High or IL4, which Google lists as Supported at IL4 and IL5 and names on its ITAR in-scope list.
Patterns with an authorized path for CUI
Sources for this page
Every finding above rests on one of these. Nothing on this page is asserted without one.
- Google Cloud documentation — FedRAMP and DoD compliance scope for Google Cloud and Google Workspace · read 2026-07-27
- Google Workspace Admin Help — Gemini app for Google Workspace — editions and data handling · read 2026-07-27
- Google Cloud — Google Cloud compliance — Defense Federal Acquisition Regulation Supplement (DFARS) · read 2026-07-27
Authorization records move and this page does not. Confirm Google's package records on the FedRAMP Marketplace before you rely on anything above.
Related Compliance Assessments
Frequently Asked Questions
Is Gemini in Google Workspace approved for CUI?
Google's scope table marks the Gemini app and Gemini in Workspace as Supported for FedRAMP High and DoD IL2, with nothing under IL4 or IL5. IL4 is the Impact Level DoD associates with controlled unclassified information. Google's own guidance for DFARS work points at Assured Workloads with a FedRAMP Moderate or High control package, which is a different configuration from the commercial Workspace default.
Does Google train on Gemini chats?
It depends on the edition, and Google says so explicitly: users without a qualifying Google Workspace edition are subject to the consumer terms, their chats may be reviewed by human reviewers and used to improve Google's products, services and machine-learning technologies, and Google tells administrators to warn those users not to enter confidential or sensitive information.
What is the Google path that does reach CUI-eligible levels?
Generative AI on the Gemini Enterprise Agent Platform (formerly Generative AI on Vertex AI) is marked Supported at FedRAMP High, IL2, IL4 and IL5 in the same table, and appears on Google's ITAR in-scope services list — but only when deployed inside an Assured Workloads boundary configured for the right regime.
Your AI tools are one row in the boundary
Audit the rest of the stack — storage, email, collaboration — against the same FedRAMP test.
Launch CUI AuditorGet a defensible CUI architecture
This Gemini app and Gemini in Google Workspace (commercial) CUI review flags the gaps. The next step is a compliance architecture review where we map your data flows to FedRAMP-authorized alternatives and CMMC-aligned controls.
Schedule architecture review