Findings by source

Gemini API (AI Studio)

Google Cloud · organizations/123456789012 Google · Cloud AI platform · audit serviceName generativelanguage.googleapis.com

Policy · none set
Policy changes re-score this app on the next sync, which starts right away.
Finding · Open
Risk score
53
High
People
1
Principals in Cloud Audit Logs
Audit entries
38
38 invocations · 0 denied · 30 days
First seen
Aug 15, 2026
Last seen 16 h ago
gcpinvocationsapi-keys
Next steps

Recommended actions

  1. 0130 calls to Gemini API (AI Studio) used an API key rather than an identity. Restrict or delete those keys and require service accounts, so every prompt has an owner and can be revoked.
  2. 02Gemini API (AI Studio) trains on data unless a business tier or opt-out is used. Verify which tier these users are on.
  3. 03The Gemini API is being called directly rather than through Vertex AI. AI Studio keys sit outside VPC Service Controls and CMEK; move production use to Vertex AI and confirm the paid tier so prompts are not used to improve Google models.
Billing · Google Cloud

What it costs

Last 30 days
$965
Previous 30
$235
Change
+310%
2026-06-16: 02026-06-17: 02026-06-18: 02026-06-19: 02026-06-20: 02026-06-21: 02026-06-22: 02026-06-23: 02026-06-24: 02026-06-25: 02026-06-26: 02026-06-27: 02026-06-28: 02026-06-29: 02026-06-30: 02026-07-01: 02026-07-02: 02026-07-03: 02026-07-04: 02026-07-05: 02026-07-06: 02026-07-07: 02026-07-08: 02026-07-09: 02026-07-10: 02026-07-11: 02026-07-12: 02026-07-13: 02026-07-14: 02026-07-15: 02026-07-16: 02026-07-17: 02026-07-18: 02026-07-19: 02026-07-20: 02026-07-21: 02026-07-22: 02026-07-23: 02026-07-24: 02026-07-25: 02026-07-26: 02026-07-27: 02026-07-28: 02026-07-29: 02026-07-30: 02026-07-31: 122026-08-01: 152026-08-02: 162026-08-03: 132026-08-04: 142026-08-05: 142026-08-06: 152026-08-07: 162026-08-08: 192026-08-09: 172026-08-10: 172026-08-11: 172026-08-12: 192026-08-13: 172026-08-14: 172026-08-15: 242026-08-16: 252026-08-17: 212026-08-18: 222026-08-19: 202026-08-20: 232026-08-21: 242026-08-22: 292026-08-23: 262026-08-24: 242026-08-25: 252026-08-26: 282026-08-27: 292026-08-28: 272026-08-29: 342026-08-30: 372026-08-31: 292026-09-01: 312026-09-02: 292026-09-03: 332026-09-04: 362026-09-05: 432026-09-06: 422026-09-07: 382026-09-08: 412026-09-09: 392026-09-10: 402026-09-11: 382026-09-12: 562026-09-13: 52
06-1609-13
Google Cloud (demo) · organizations/123456789012

In Google Cloud

2026-08-16: 12026-08-17: 12026-08-18: 12026-08-19: 12026-08-20: 12026-08-21: 12026-08-22: 12026-08-23: 12026-08-24: 12026-08-25: 12026-08-26: 12026-08-27: 12026-08-28: 12026-08-29: 12026-08-30: 12026-08-31: 12026-09-01: 12026-09-02: 12026-09-03: 12026-09-04: 12026-09-05: 22026-09-06: 22026-09-07: 22026-09-08: 22026-09-09: 22026-09-10: 22026-09-11: 22026-09-12: 22026-09-13: 12026-09-14: 0
08-1609-14
30 API-key callsdata access logs on38 invocations
Principals
PrincipalTypeEntriesDenied
api-keyAPI key300
[email protected]user80
Top methods
GenerativeService.GenerateContent38
Projects
frank-side-project30 entries
contoso-sandbox8 entries
Resources

No resources of this kind in the scope.

Who

People

Identifiers come from device telemetry and proxy logs, so they may be account names rather than full directory entries.

PersonDepartmentSourceSign-ins · 30 dGranted
n/aGoogle Cloud principal0No direct grant
Why

Evidence

  1. audit_activity · Sep 13, 2026
    Google Cloud (demo): Gemini API (AI Studio), 38 audit entries by 2 principals, 38 invocations, API enabled in 2 projects in 30 days across 2 projects
    Detail
    {
      "scopes": [
        "organizations/123456789012"
      ],
      "services": [
        "generativelanguage.googleapis.com"
      ],
      "topMethods": [
        {
          "name": "GenerativeService.GenerateContent",
          "count": 38
        }
      ],
      "dataAccessLogging": true
    }
  2. api_enabled
    generativelanguage.googleapis.com enabled in frank-side-project
    Detail
    {
      "project": "frank-side-project"
    }
  3. api_enabled
    generativelanguage.googleapis.com enabled in contoso-sandbox
    Detail
    {
      "project": "contoso-sandbox"
    }