Skip to main content
TrustEdge AI
Model developer

Google DeepMind

Frontier model developer. This row describes the Gemini Developer API on its paid tier — the first-party route. Gemini bought through Vertex AI on Google Cloud is a different contractual product with a materially different compliance posture, and is not yet tracked here.

4 of 7 criteria carry a sourced value · 3 recorded as a gap ·  Verified August 8, 2026

What this means for a regulated buyer

Our analysis, not Google DeepMind’s. Every statement here traces to a sourced claim further down the page.

The safety grade and the compliance posture come from two different places, and the developer API is not where Google documents its compliance.

Where it is strong

  • The paid tier carries a clear, unambiguous exclusion from product improvement, quoted in full on this page.
  • Third of nine in the FLI Summer 2026 Index, and one of only three companies to clear an F in the Existential Safety domain.
  • Google Cloud, where the equivalent models are sold as Vertex AI, carries an extensive published compliance programme.

What to check or negotiate

  • Retention on the paid tier is "a limited period of time" and is never quantified anywhere in the terms. Every other developer tracked here publishes a number or an explicit zero-retention path.
  • The unpaid tier is materially different: content is used to improve Google products and "Human reviewers may read, annotate, and process your API input and output." An API key not attached to billing carries those terms.
  • The Google Cloud BAA covered-products list includes neither the Gemini Developer API nor Google AI Studio. As read on 2026-08-07 it did not list Vertex AI either — only "Vertex AI Workbench instances".
  • No certification scope or sub-processor disclosure specific to the developer API was located; both exist for Google Cloud.

Verdict

For regulated workloads, route through Google Cloud and confirm your exact product against the BAA covered-products list. The developer API is the wrong contracting surface for PHI.

The full record

Every criterion, with Google DeepMind’s own wording where it is hedged or carries exclusions, the primary source, and the date we last read it.

FLI safety grade

Safety-research posture, per the Future of Life Institute

C · 2.01 (Summer 2026)

Third overall of the nine companies graded, and the only company other than Anthropic and OpenAI to clear an F in the Existential Safety domain, with a D.

Primary source · verified 2026-08-07

BAA available

Will they sign a business associate agreement for PHI

Not publicly documented

Google documents BAA scope as an explicit list of Covered Products and instructs customers to "Disable or otherwise ensure that you do not use Google Cloud Products that are not explicitly covered by the BAA (see Covered Products) when working with PHI." The Gemini Developer API and Google AI Studio do not appear on that list, which covers Google Cloud products such as Gemini Enterprise, Gemini Code Assist and Gemini in BigQuery. The list read on 2026-08-07 also contained no entry for Vertex AI itself, only "Vertex AI Workbench instances". A buyer with PHI should treat the developer API as out of scope and confirm the exact Google Cloud product against that list.

Primary source · verified 2026-08-07

Certifications

Independently audited attestations

Not publicly documented

No certification scope covering the Gemini Developer API specifically was found in the API additional terms, the API documentation, or Google Cloud’s compliance pages, which are scoped to Google Cloud products. Google holds an extensive certification portfolio, but it attaches to Google Cloud and Workspace rather than to this developer surface. This is a finding about where the certifications are scoped, not a claim that Google lacks them.

Primary source · verified 2026-08-07

Trains on your data

Whether your inputs and outputs feed model training

Not by default — Paid tier only. Prompts and responses on paid services are excluded from product improvement; the unpaid tier is used for improvement and is subject to human review.

The split is the whole story here. Paid: "Google doesn’t use your prompts (including associated system instructions, cached content, and files such as images, videos, or documents) or responses to improve our products." Unpaid: "Google uses the content you submit to the Services and any generated responses to provide, improve, and develop Google products and services", and "Human reviewers may read, annotate, and process your API input and output." An API key that has not been attached to billing carries the unpaid terms.

Primary source · verified 2026-08-07

Retention

How long your data is kept, and where

Paid tier: prompts and responses logged for "a limited period of time" for policy enforcement. No duration is published.

Google: "Google logs prompts and responses for a limited period of time, solely for detecting and preventing violations of the Prohibited Use Policy… and any required legal or regulatory disclosures." The period is not quantified anywhere in the terms. Every other developer tracked here publishes a number or an explicit zero-retention path; this one does not, which is the material difference for a buyer who must document retention.

Primary source · verified 2026-08-07

Subprocessors

Who else processes your data

Not publicly documented

Google publishes a detailed sub-processor list for Google Cloud, with advance notice governed by the Cloud Data Processing Addendum and notification sent to Essential Contacts without any need to subscribe. That page is scoped to Google Cloud. No equivalent disclosure scoped to the Gemini Developer API was located.

Primary source · verified 2026-08-07

EU AI Act

Obligations, and which transfer to you as deployer

Google is a signatory to the EU General-Purpose AI Code of Practice, the voluntary route to demonstrating compliance with the AI Act.

The Commission lists the signatory as "Google". Read from the Commission’s published list rather than from a vendor announcement.

Primary source · verified 2026-08-07

This is a model developer, so the FLI grade above describes its safety-research posture. It says nothing about whether a deployment is compliant — that comes from the contractual terms, either this vendor’s own or those of a platform you run the model through.

Safety grades come from the FLI AI Safety Index, Summer 2026 — what it measures, and what it explicitly does not.

Deploying Google DeepMind in a regulated environment

We help regulated organisations build AI vendor diligence that holds up in an audit.