NEWS
Verax AI Risk Assessment is live. See what's exposed
Vertex AI
Vertex AI
 
Risk Overview
Minimal Risk
2.4
/10
Model API
·
Model Hosting
·
Top Risks

CLOUD Act exposure as US entity despite EU region options. Vertex AI Agents and Extensions can access external systems, databases, and APIs. Complexity of Google Cloud's shared responsibility model. Enterprise terms require negotiation for best protections.

Mitigations

Select EU data region for data residency compliance. Sign Google Cloud DPA and SCCs. Use VPC Service Controls to limit data exfiltration. Define minimal permissions for Vertex AI Agent tools. Review Google Cloud service-specific terms for each AI service used.

Get started
Is your team using 
Vertex AI
 
safely?

Highest Risk Categories

The highest-scoring risk categories identified in this assessment.

Legal Terms

Google Cloud ToS uses governing law of California for US customers; enterprise customers negotiate separate agreements. Arbitration provisions present in standard Google Cloud ToS. Enterprise agreements often negotiated individually. More enterprise-flexible than consumer Google terms.
5
/10

Data Sovereignty

US company (Google LLC) subject to CLOUD Act. EU region data processing available with GDPR DPA. Data residency control via regional selection (US, EU, or both). No EU-sovereign separate legal entity yet (unlike AWS). Standard US cloud sovereignty risk.
4
/10

3rd-Party Sharing

Standard Google Cloud sub-processor model. Model providers do not access customer prompts. Data processed per Google Cloud DPA. No ad/marketing use of customer data. Google Cloud is contractually distinct from Google consumer services.
3
/10

Unlock the complete assessment

Run a free assessment to access the full AI tool risk analysis.
Start Free Assessment
Updated July 2026 • AI-assisted research • Reviewed by Verax • Report an issue

Reference Documentation

Official documentation and policies referenced as part of this assessment.