Gemini API (AI Studio)
Google Cloud · organizations/123456789012 Google · Cloud AI platform · audit serviceName generativelanguage.googleapis.com
Policy · none set
Policy changes re-score this app on the next sync, which starts right away.
Finding · Open
Risk score
53
High
People
1
Principals in Cloud Audit Logs
Audit entries
38
38 invocations · 0 denied · 30 days
First seen
Aug 15, 2026
Last seen 16 h ago
gcpinvocationsapi-keys
Next steps
Recommended actions
- 0130 calls to Gemini API (AI Studio) used an API key rather than an identity. Restrict or delete those keys and require service accounts, so every prompt has an owner and can be revoked.
- 02Gemini API (AI Studio) trains on data unless a business tier or opt-out is used. Verify which tier these users are on.
- 03The Gemini API is being called directly rather than through Vertex AI. AI Studio keys sit outside VPC Service Controls and CMEK; move production use to Vertex AI and confirm the paid tier so prompts are not used to improve Google models.
Billing · Google Cloud
What it costs
Last 30 days
$965
Previous 30
$235
Change
+310%
06-1609-13
Google Cloud (demo) · organizations/123456789012
In Google Cloud
08-1609-14
30 API-key callsdata access logs on38 invocations
Principals
| Principal | Type | Entries | Denied |
|---|---|---|---|
| api-key | API key | 30 | 0 |
| [email protected] | user | 8 | 0 |
Top methods
GenerativeService.GenerateContent38
Projects
frank-side-project30 entries
contoso-sandbox8 entries
Resources
No resources of this kind in the scope.
Who
People
Identifiers come from device telemetry and proxy logs, so they may be account names rather than full directory entries.
| Person | Department | Source | Sign-ins · 30 d | Granted |
|---|---|---|---|---|
| n/a | Google Cloud principal | 0 | No direct grant |
Why
Evidence
- audit_activity · Sep 13, 2026Google Cloud (demo): Gemini API (AI Studio), 38 audit entries by 2 principals, 38 invocations, API enabled in 2 projects in 30 days across 2 projects
Detail
{ "scopes": [ "organizations/123456789012" ], "services": [ "generativelanguage.googleapis.com" ], "topMethods": [ { "name": "GenerativeService.GenerateContent", "count": 38 } ], "dataAccessLogging": true } - api_enabledgenerativelanguage.googleapis.com enabled in frank-side-project
Detail
{ "project": "frank-side-project" } - api_enabledgenerativelanguage.googleapis.com enabled in contoso-sandbox
Detail
{ "project": "contoso-sandbox" }