Loading the catalogue…
Loading the catalogue…
Google develops its AI models through Google DeepMind, a subsidiary of the US-incorporated Alphabet group, meaning all Google-hosted inference (Gemini API, Vertex AI, Workspace Gemini) is fully exposed to the CLOUD Act and FISA Section 702 regardless of EU data-residency options. On compliance, Google is comparatively proactive — an early signatory to all three chapters of the EU GPAI Code of Practice, ISO/IEC 42001 AI-management certified, and a publisher of detailed Gemma model cards — but it carries a sustained and escalating history of EU privacy fines (CNIL) and unresolved US antitrust litigation, and offers no EU-sovereign first-party inference path on Stav. The Gemma family's move to Apache 2.0 licensing is the strongest option for EU customers wanting to self-host and avoid CLOUD Act exposure entirely.
Google LLC is US-incorporated; all Google-hosted AI inference (Gemini API, Vertex AI, Workspace Gemini) is subject to CLOUD Act and FISA Section 702 compelled-access risk regardless of EU data-residency configuration. This is a structural exposure that cannot be remediated by SCCs or a DPA alone.
Escalating French CNIL enforcement pattern against Google: €50M (2019), €150M (2021), and a record €325M fine in September 2025 for Gmail ad display without consent and invalid cookie consent, with a €100,000/day non-compliance penalty attached.
The EU's Court of Justice permanently upheld a €4.1 billion antitrust fine against Google's Android practices in 2026, on top of a separately confirmed €2.42B Google Shopping fine and a €2.95B ad-tech fine (2025), plus a $1.5B Swedish damages award to PriceRunner — an entrenched pattern of EU competition-law liability.
A US District Court found in April 2025 that Google willfully monopolized the publisher ad server and ad exchange markets, triggering multiple private treble-damages lawsuits (PubMatic, Magnite) still working through litigation.
Consumer-tier Gemini (gemini.google.com) has no Data Processing Addendum, may retain and human-review prompts, and is described by third-party GDPR analysis as unsuitable for processing EU personal data on an employer's behalf — a materially different posture than the enterprise Vertex AI or Workspace tiers.
No publicly documented opt-out or erasure mechanism has been identified for personal data potentially included in Gemma/Gemini pre-training corpora, a potential gap against GDPR Article 17 for EU regulated-sector deployers.
Stav’s assessment
Editorial assessment, not legal advice. Stav's risk ratings, scores, and verdicts are our own analysis of publicly available information and may be incomplete or out of date. Verify independently before making compliance or procurement decisions.
Google's reasoning-tuned Flash-tier model for fast coding, agentic, and multi-step reasoning tasks with a million-token multimodal context window.
Google's fast, cost-focused Gemini 3.5 model with a million-token context window, mandatory configurable reasoning, and multimodal text, image, audio, and video input.
Google was the first major US cloud/AI provider to publicly commit to signing the EU GPAI Code of Practice in July 2025, ahead of peers such as Microsoft; Meta declined to sign.
Gemma 4 (released April 2026) moved to the fully permissive Apache 2.0 licence, removing the prior custom Gemma Terms of Use's usage restrictions and unilateral termination rights, and enabling EU enterprises to self-host without CLOUD Act exposure on the inference leg.
Runs one of the industry's longest-running bug bounty programmes (VRP, live since 2010), paying out over $17 million in 2025 alone across a dedicated AI Vulnerability Reward Program plus core product programmes.
Google Ireland Ltd serves as the established EEA GDPR controller under the Irish DPC's lead-authority mechanism, and enterprise-tier Gemini products (Workspace, Vertex AI) come with a standard DPA, SCCs, and EU data-residency options.
Alphabet continues to post strong operating growth and active AI investment even while absorbing a $3.5 billion EU antitrust fine as a one-off charge, indicating financial resilience and no disruption to ongoing model development.
Published safeguards & certifications
Google's reasoning-tuned Flash model: multimodal input, a million-token-plus context window, and configurable chain-of-thought for agentic, long-horizon tasks.