ModelRiskIndex

Rankings / Google

Gemini 2.5 Flash

Tier 260/100draft — pending re-verification

gemini-2.5-flash via generativelanguage.googleapis.com

Usage share 0.93% · OpenRouter rankings API (daily token share, 2026-08-04)

Tier assessment
Tier 1 requirements
  • Published model card. A model card or equivalent technical documentation is published for this model.
  • Published safety evals. Safety evaluations for this model are published.
  • Documented safety policy. A documented safety, usage, or acceptable-use policy governs the model.
  • Enterprise data controls. Customer data is not used for training by default, or a documented opt-out exists.
Tier 2 requirements
  • External pre-deployment testing. Independent external parties tested the model before deployment, and this is disclosed.Covered by the same organizational external-testing arrangements as the Gemini flagship.
  • Third-party certification. The operating organization holds verifiable third-party certification (e.g. SOC 2, ISO/IEC 42001).
  • Versioning with changelogs. Model versions are explicitly identified and changes are changelogged.Versioned endpoint with lifecycle dates; in-place tuning has been reported by developers between dated releases.
  • Stated deprecation policy. A deprecation policy with notice windows is published.
Risk analysisfive vectors · click a wedge for its evidence

Risk vectors — the receipts

Data governancepartial

What happens to your data: training-on-customer-data defaults, retention windows, residency options, and the enterprise-versus-consumer terms gap. A legal property, not a capability — it survives every model generation.

Same posture as the rest of the Gemini API: paid tier not trained on; free tier may be used for improvement.

Receipts (1)
  • Gemini API terms of service
    Google / DeepMind provider artifacts · provider artifact · source tier B · ai.google.dev · retrieved 2026-08-03
    To help with quality and improve our products, human reviewers may read, annotate, and process your API input and output.

Operational stabilitypartial

Whether it changes without warning: versioning discipline, changelog quality, deprecation policy, and observed silent changes. The signal no one else tracks.

Stable versioned endpoint with lifecycle dates, but the Flash tier has seen in-place quality/behavior tuning flagged by developers between dated releases.

Receipts (1)
  • Gemini API changelog and model versions
    Google / DeepMind provider artifacts · provider artifact · source tier B · ai.google.dev · retrieved 2026-08-03
    Released gemini-2.5-flash , our first stable 2.5 Flash model.

Adversarial resistanceweak

Whether an attacker can make it misbehave — direct jailbreaks against the model's own policies and indirect prompt injection in agentic tool use. Graded to the weaker of the two, because an attacker takes the easier path.

Jailbreak resistancepartial

Smaller/faster tier of the Gemini line; safety training is shared with Pro but independent testing shows higher attack success rates than the flagship.

Prompt injection (agentic)weak

Widely deployed in high-volume agentic and summarization pipelines where indirect injection demonstrations have repeatedly succeeded; fewer defensive layers than flagship deployments.

Receipts (2)
  • Gemini 2.5 model card
    Google / DeepMind provider artifacts · provider artifact · source tier B · deepmind.google · retrieved 2026-08-03
  • Independent research on Gemini-surface prompt injection
    Peer-reviewed / preprint research · independent eval · source tier C · arxiv.org · retrieved 2026-08-03
    Indirect prompt injection literature; specific Gemini demonstrations tracked in the incident feed.

Transparencystrong

Whether you can see how it was built and tested: model cards, published safety evals, external pre-deployment testing, and disclosure of changes. The mechanism behind the tier ladder.

Model card published, covered by the Frontier Safety Framework and Google's external testing arrangements.

Receipts (1)
  • Google DeepMind Frontier Safety Framework
    Google / DeepMind provider artifacts · provider artifact · source tier B · deepmind.google · retrieved 2026-08-03
    We also introduced, and continue to update, our Frontier Safety Framework - a set of protocols to help us stay ahead of possible severe risks from powerful frontier AI models.

Compliance posturestrong

Whether it is certified and compliant: SOC 2, ISO/IEC 42001, HIPAA eligibility, EU AI Act readiness, and audit availability.

Same Google Cloud certification stack as Gemini 3 Pro when deployed via Vertex.

Receipts (1)

Governance & evidence

Where your data goes

  • US

Regional pinning available — customers can pin processing to a chosen region.

Global serving by default (US provider home jurisdiction presumed); extensive regional pinning available via Vertex AI.

Enterprise vs consumer terms

Enterprise vs consumer gap: wide. Paid API tier is not trained on, but the free tier may be used for improvement and consumer Gemini Apps default to data use.CONSUMERENTERPRISE / APIWORSE TERMS →
Wide gap

Paid API tier is not trained on, but the free tier may be used for improvement and consumer Gemini Apps default to data use.

Change cadence

no tracked changesNo tracked changes for Gemini 2.5 Flash. Absence of detection is not evidence of stability.none

No tracked changes for this model. That is absence of detection, not evidence of stability — it may mean the model is unwatched, not that it is unchanging.

Score volatility

No dated score readings recorded for this model yet. Readings are only entered where multiple real, dated third-party values exist — never interpolated.

Receipts — what backs this assessment

7 evidence refs3 distinct sources1 independent
  • CPeer-reviewed / preprint researchindependent eval×1 reference
  • BGoogle / DeepMind provider artifactsprovider artifact×5 references
  • EOpenRouter model rankingsusage data×1 reference

retrieved 2026-08-03 — 2026-08-05

Compliance & deployment

Trains on customer data by default
No
SOC 2
Yes
ISO/IEC 42001
Yes
HIPAA eligible
Yes
Retention window
Paid tier: limited abuse-monitoring retention; free tier: data may be used for improvement
Data residency
Extensive regional options via Vertex AI
EU AI Act
Signed the EU GPAI Code of Practice.
Deprecation policy
Published model lifecycle and discontinuation dates on Vertex AI
Available via
Gemini API · Google Vertex AI

Incident history

2025-08-06
Promptware: calendar-invite injection drove Gemini-connected smart-home actions
Indirect prompt injection via calendar invites

Researchers showed that poisoned calendar invites could hijack Gemini assistant sessions into performing unintended actions, including smart-home control, when the user later asked routine questions. Google shipped mitigations. Demonstrates the indirect-injection surface of assistant-integrated deployments.

Outcome: Mitigations deployed by Google following disclosure.

Sources (1)

Change timeline

No tracked changes yet for this model.

Compare this model: Gemini 2.5 Flash + open compare view →