Google Gemini: What the governance framework covers — and what it leaves to you
Applying the AI Minimum Viable Governance (AI-MVG) framework and the Seba 12 Ps of Responsible AI
Third installment. Previously: Anthropic and OpenAI. Each stands alone — but the pattern across all three is where the real governance story begins.
This miniseries examines frameworks shaping AI governance globally — from AI labs to regulatory bodies to standards organizations — and surfaces what leaders need to know about the gaps, whether intentional or not. Not to critique AI Labs or organizations. But to ask three questions every institution should be asking before deployment, not after a policy update lands in your inbox.
Question one: What was the framework designed to govern?
Google’s responsible AI framework is one of the most comprehensive published by any AI lab. It spans seven governance pillars — research, policies, testing, mitigation, launch review, monitoring, and governance forums — including an AGI Futures Council that brings board-level attention to frontier AI risk.
Gemini 3 underwent more safety evaluations than any previous Google model, with over 350 red-team exercises across text, audio, images, video, and agentic AI. Google has published an annual Responsible AI Progress Report, introduced an AI control center for Workspace administrators, and structured its governance to evolve alongside its most capable models.
It governs the model. Thoroughly. Seriously. At scale. That deserves acknowledgment before the harder question is asked.
| Dimension | What Google’s framework addresses |
|---|---|
| Safety evaluation | 350+ red-team exercises; external assessments by Apollo Research, Vaultis, and Dreadnode |
| Governance structure | Seven-layer framework spanning research through governance forums and the AGI Futures Council |
| Transparency | Annual Responsible AI Progress Report; public disclosure of safety methods and results |
| Agentic AI controls | AI control center for Workspace; agent inventory and access controls introduced 2026 |
| Enterprise data protection | Cloud Data Processing Addendum; no model training on customer data without permission |
Question two: The governance gap — what falls outside the frame?
Institutional deployment.
A transparency note. The policy language examined here came from a personal Google account — not an enterprise contract, not a hospital procurement agreement, not a university licensing deal. This analysis is extrapolating, and names that clearly. Enterprise institutions operate under a separate legal framework — the Google Cloud Master Agreement and Cloud Data Processing Addendum — with stronger protections. Enterprise institutions should review Google Workspace terms directly. That said, even enterprise contracts contain provisions worth examining closely.
Here is what the current consumer Terms of Service say:
“If you don’t agree to the new terms, you should remove your content and stop using the services. You can also end your relationship with us at any time, without penalty, by closing your Google Account.”
That is a contract clause — not a threat. Google is updating its Terms of Service on July 30, 2026. That update may be routine. The next one may not be. And even in enterprise contracts, pre-GA offerings — including certain Gemini features — may be changed, suspended, or discontinued at any time without prior notice to the customer.
For institutions that have made AI infrastructure, departure is not a decision. It is a disruption. Who evaluates whether to stay? Who owns the risk if you do? The vendor cannot answer those questions. Only the institution can. This is precisely the kind of question the book Ungoverned was written to surface.
| Dimension | Google’s framework | What AI-MVG requires |
|---|---|---|
| What it governs | The AI platform and model | Institutional deployment and consequences |
| Terms changes | With notice (consumer); without notice on pre-GA features | A governance process ready before the change arrives |
| Primary question | “Is the model safe?” | “Can we responsibly continue using it?” |
| Vendor dependency | Not addressed | Must be mapped before deployment |
| Change management | Not addressed | Must be defined before deployment |
| Executive accountability | Internal to Google | Must be assigned institutionally |
Question three: What governance must institutions build before deployment?
This is where AI Minimum Viable Governance (AI-MVG) begins. Not after a terms update forces the question — before deployment, when institutions still have the leverage to negotiate, plan, and govern with intention.
- Vendor dependency mapping — know what breaks if this vendor changes or disappears
- Decision ownership — name who is accountable for each AI-assisted institutional decision
- Policy monitoring — establish a process to track vendor policy changes in real time
- Change management triggers — define what level of vendor change requires institutional review
- Contingency planning — document what happens if access is suspended or terms become unacceptable
- Executive accountability — assign a named leader responsible for AI governance outcomes, not just adoption
This week’s lens
The Seba 12 Ps of Responsible AI: Policy
The Seba 12 Ps of Responsible AI provide a practical framework for evaluating institutional AI governance readiness. This edition focuses on Policy — the fourth P. Most institutions think AI policy means an acceptable-use document. It doesn’t. Policy also means having a governance process ready before your vendor rewrites the rules — knowing who has authority to evaluate whether continued use is appropriate, and who owns the institutional risk if it isn’t.
| P | Dimension | Vendor coverage | Institutional gap |
|---|---|---|---|
| 1 | Purpose | Defined by Google at model level | Institutional purpose alignment not evaluated |
| 2 | People | Google internal teams and governance forums | Institution must assign human accountability |
| 3 | Processes | Seven-layer internal governance process | Institutional deployment process not governed |
| 4 | Policy | Acceptable use, prohibited use, ToS | No institutional change-response process |
| 5 | Privacy | CDPA for enterprise; consumer ToS for individuals | Institutional data flows may exceed vendor scope |
| 6 | Performance | Safety benchmarks and red-team results published | Institutional performance standards not set |
| 7 | Procurement | Enterprise agreements available | Dependency and exit terms rarely negotiated |
| 8 | Partnerships | Third-party integrations governed by Google | Institutional third-party risk not mapped |
| 9 | Predictability | Pre-GA features may change without notice | No institutional continuity plan |
| 10 | Protection | Enterprise data protection via CDPA | Consumer accounts have weaker protections |
| 11 | Proof | Annual Responsible AI Progress Report | Institutional audit trail rarely established |
| 12 | Precedent | Not addressed by vendor | Who owns decisions when AI gets it wrong? |
Vendor governance governs the platform. Institutional governance governs the consequences. One governs the model. The other governs the decision. That is the foundation of AI Minimum Viable Governance.
Bring this analysis to your organization
Dr. Seba delivers keynote presentations and executive workshops on AI Minimum Viable Governance — built for boards, trustees, CIOs, and senior leadership teams who need practical governance frameworks, not theoretical ones.
Book a keynoteInquire about workshopsSubscribe to Ungoverned
Dr. Freddie Seba helps boards, trustees, and executive leadership teams build practical AI governance before AI failures make governance unavoidable. Scholar-operator · Silicon Valley founder · Global executive · EdD, USF · MBA, Yale · MA, Stanford
Sources:
Google Terms of Service (consumer)
https://policies.google.com/terms
Updating July 30, 2026
Google Workspace Enterprise Terms of Service
https://workspace.google.com/terms/premier_terms
Google Cloud Platform Terms of Service
https://cloud.google.com/terms
Google 2026 Responsible AI Progress Report
https://www.libertify.com/interactive-library/google-responsible-ai-2026-progress-report-guide/
Note: this is a third-party interactive guide to the report. For the primary source, search “Google 2026 Responsible AI Progress Report” — Google has not posted a single stable direct URL for the PDF itself. I’d recommend linking to Google’s main Responsible AI page at https://ai.google/responsibility/ and noting “February 2026” so readers can locate the current report.
Google Workspace Service Specific Terms
https://workspace.google.com/terms/service-terms/
This analysis is part of Ungoverned: Applied Frameworks Under the Lens, a recurring miniseries applying the AI-MVG framework and the Seba 12 Ps of Responsible AI to organizations shaping AI governance globally. Drafted with AI-assisted tools. Final editorial judgment and responsibility remain with the author.

Leave a Reply