Gemini (Google)
Google's Gemini model family reaches organisations through several distinct routes — the consumer/enterprise Gemini app, Gemini embedded in Google Workspace (Docs, Sheets, Gmail), and Vertex AI, Google Cloud's enterprise platform for building on Gemini directly — each with a different data-processing and governance posture, the same pattern as Microsoft's Copilot family.
Last reviewed: 2026-08-24
What it is
Gemini is Google's model family, made available through several products rather than one: the Gemini app (consumer and business use); Gemini embedded in Google Workspace apps, grounding responses in an organisation's own Workspace content; and Vertex AI, Google Cloud's platform for building custom applications and agents directly on Gemini and other models, with enterprise-grade data controls. Which route an organisation uses determines its actual governance posture more than the underlying model does.
Where it's adopted
The Gemini app for general-purpose assistant use; Gemini in Workspace for organisations already on Google Workspace, surfaced directly inside Docs, Sheets, and Gmail; Vertex AI by engineering and data teams building bespoke AI applications and agents with enterprise data-governance and access controls. The enterprise-relevant governance questions differ sharply between the consumer-facing app and Vertex AI's platform controls.
Governance, compliance, security, and engineering considerations.
As with Copilot, "Gemini" names a model family reached through different products with different governance profiles — sign-off should specify the Gemini app, Workspace integration, or Vertex AI, not "Gemini" generically.
Vertex AI carries Google Cloud's enterprise data-processing and residency terms, materially different from the consumer Gemini app's terms. Gemini in Workspace inherits an organisation's existing Workspace data-processing agreement. Confirm which terms actually apply to the deployment in question.
Gemini in Workspace shares Microsoft 365 Copilot's oversharing risk profile: it surfaces what a user's existing Workspace permissions already allow. Vertex AI-built applications carry the same excessive-agency and prompt-injection risk categories as any agentic system, determined by what the application built on it is permitted to do.
For Vertex AI applications, the same lifecycle control points apply as any AI system built in-house: evaluation, monitoring, and incident response are the deploying organisation's responsibility, not the platform's. For Gemini in Workspace, the operative discipline is Workspace permissions hygiene, not application engineering.
Where this connects to the Risk & Control Library.
Informational cross-references, not formal platform tags — none of these entries are specific to Gemini (Google) alone; they're the generic risks and controls most relevant to this category of tool.
- Sensitive information disclosure — The relevant risk for Gemini in Workspace, for the same reason as Microsoft 365 Copilot — it surfaces what existing permissions already allow.
- Excessive agency — Applies to agentic applications built on Vertex AI, scoped by what that specific application is permitted to do.
- Inadequate AI vendor due diligence — Due diligence needs to be scoped per product (app, Workspace integration, or Vertex AI), given how differently each handles data.
- Inference usage quotas and rate limiting — A directly applicable engineering control for any Vertex AI-built application, where cost and usage are the deploying team's own responsibility.
Deployment-governance patterns.
What good practice looks like when adopting this tool.
- Name the specific Gemini product in any governance decision — the Gemini app, Gemini in Workspace, or Vertex AI — never "Gemini" alone.
- Audit Workspace permissions hygiene before enabling Gemini in Workspace broadly, for the same reason as Microsoft 365 Copilot.
- For Vertex AI-built applications, apply the full engineering lifecycle (evaluation, monitoring, incident response) as the deploying organisation's own responsibility, not something the platform provides by default.
- Confirm which data-processing and residency terms apply to the specific product in use, rather than assuming one Google-wide answer.