Policy & Compliance

Approved AI Platforms

PMG's current approved platforms list, with risk ratings across five dimensions and plain-language guidance for staff on how each tool may be used.

Last Assessment: 16 July 2026

Approved Platforms

Claude

AnthropicJurisdiction: United States
Approved OVERALL: LIMITED

Approved for non-sensitive tasks on claude.ai; use the Vertex AI route for sensitive work. No change to our existing guidance. Use claude.ai for general, non-confidential tasks, and use Claude via Google Cloud Vertex AI for anything involving sensitive or proprietary information, since that route runs inside our existing Cloud data agreement. Opus 4.7's new MCP v2.1 and desktop-control capabilities raise the same agentic caution noted above for Claude Computer Use & MCP. If you are using Claude Design or Claude in any agentic configuration, treat it under that entry's guidance rather than this one, even if you are accessing it through the same subscription.

Risk Dimensions Assessment
Data Privacy
LIMITED
Provider Stability
MINIMAL
Decision Autonomy
LIMITED
Jurisdiction Risk
LIMITED
Use Risk
LIMITED

Gemini

Google DeepMindJurisdiction: United States
Approved OVERALL: MINIMAL

Approved for use via Google Workspace. No change. Gemini accessed through your work Google Workspace account remains approved and carries the same protections as the rest of Workspace. As Gemini becomes more deeply integrated and agentic across Android and Workspace, be mindful of any new autonomous or multi-step features it gains; those should be evaluated under the Decision Autonomy lens before being used for tasks with real-world consequences. The consumer/personal-account version remains separately rated and is not approved.

Risk Dimensions Assessment
Data Privacy
MINIMAL
Provider Stability
MINIMAL
Decision Autonomy
LIMITED
Jurisdiction Risk
LIMITED
Use Risk
MINIMAL

Mistral

Mistral AIJurisdiction: France (EU)
Approved OVERALL: MINIMAL

Approved for use when accessed through Google Cloud Vertex AI. No change. Mistral Large 3 and Small 4 are available in the Vertex AI Model Garden and run inside our Google Cloud environment, retaining the European jurisdictional posture and our existing Cloud data protections. Do not use the Mistral API directly, as that requires a separate vendor agreement outside our current setup.

Risk Dimensions Assessment
Data Privacy
MINIMAL
Provider Stability
LIMITED
Decision Autonomy
LIMITED
Jurisdiction Risk
MINIMAL
Use Risk
MINIMAL

Adobe Firefly

AdobeJurisdiction: United States
Approved OVERALL: MINIMAL

Adobe Firefly remains the preferred tool for commercial and client-facing image and now video work, given its licensed training data and explicit copyright indemnification. The new 4K cinematic Video Model and AI Assistant extend this same protection to video output. Requires an Adobe Creative Cloud licence.

Risk Dimensions Assessment
Data Privacy
MINIMAL
Provider Stability
MINIMAL
Decision Autonomy
MINIMAL
Jurisdiction Risk
MINIMAL
Use Risk
MINIMAL

Veo 3.1

Google DeepMindJurisdiction: United States
Approved OVERALL: MINIMAL

Approved for use via Google Cloud. No change. Veo 3.1 remains available through Vertex AI with the same data protections as the rest of our Cloud infrastructure, and prompts and generated videos are not used for model training. Contact Systems if you need this enabled for your role.

Risk Dimensions Assessment
Data Privacy
MINIMAL
Provider Stability
MINIMAL
Decision Autonomy
MINIMAL
Jurisdiction Risk
LIMITED
Use Risk
MINIMAL

Llama 4

Meta AI ResearchJurisdiction: United States
Approved OVERALL: MINIMAL

Approved for use when accessed through Google Cloud Vertex AI. Llama 4 Scout's expanded context window is a capability improvement that does not change the underlying jurisdiction or privacy picture. Available in the Vertex AI Model Garden, running inside our Google Cloud environment. Access via Vertex AI only; do not use Meta's consumer chat interface.

Risk Dimensions Assessment
Data Privacy
MINIMAL
Provider Stability
MINIMAL
Decision Autonomy
MINIMAL
Jurisdiction Risk
LIMITED
Use Risk
MINIMAL

Gemma 4

Google DeepMindJurisdiction: United States
Approved OVERALL: MINIMAL

Gemma 4 continues Google's approach of a lightweight, self-hostable model with no external data transfer required. Available via Vertex AI or as a self-hosted deployment within our Google Cloud environment.

Risk Dimensions Assessment
Data Privacy
MINIMAL
Provider Stability
MINIMAL
Decision Autonomy
MINIMAL
Jurisdiction Risk
MINIMAL
Use Risk
MINIMAL

Not Approved

Perplexity Computer

Perplexity AIJurisdiction: United States
Not Approved OVERALL: HIGH

An independent audit commissioned by Perplexity itself found that its agentic browser tooling could be manipulated by malicious page content into extracting information from a user's own logged-in accounts, including a demonstrated case of email contents being sent to an outside address, and separate researchers showed it could be tricked into completing a phishing attempt in minutes. Perplexity is also currently under a federal court injunction after a ruling that its browser agent accessed Amazon accounts without Amazon's authorization, even when acting with the user's own permission. Combine that with a tool whose purpose is to fill forms, manage email, and complete transactions autonomously, and the realistic exposure if anything goes wrong is high. Do not connect Perplexity's agent products to any work email, calendar, or logged-in account. If your team has a genuine need for a web automation agent, raise it with the Systems Team rather than adopting this independently.

Risk Dimensions Assessment
Data Privacy
HIGH
Provider Stability
LIMITED
Decision Autonomy
HIGH
Jurisdiction Risk
LIMITED
Use Risk
HIGH

Amazon Nova Act

AWSJurisdiction: United States
Not Approved OVERALL: LIMITED

Not approved as it does not fit into our current tooling due to it duplicating capability we may already get through Google's own automation and agent tooling on Vertex AI, not because of a specific flaw. Nova Act is a browser automation agent, and the same caution that applies to any tool that takes autonomous, multi-step action on live systems applies here: a human should review what it is authorized to touch before any deployment. Would require a separate AWS account and vendor agreement, duplicating our existing Google Cloud setup. If a specific automation use case is not achievable through our existing tools, raise it with the Systems Team for evaluation rather than setting up AWS access independently.

Risk Dimensions Assessment
Data Privacy
LIMITED
Provider Stability
MINIMAL
Decision Autonomy
HIGH
Jurisdiction Risk
LIMITED
Use Risk
HIGH

Kimi Agent Swarm

Moonshot AIJurisdiction: China (PRC)
Not Approved OVERALL: UNACCEPTABLE

Kimi is operated by a Chinese company and is subject to the same national security laws as DeepSeek, which require Chinese firms to cooperate with state intelligence requests for data with no independent judicial check. Agent Swarm compounds this by spawning multiple autonomous instances to handle research or coding tasks, meaning a single workflow can expose a much larger volume of organisational data, code, or documents to that jurisdictional risk than a single chat session would. Do not use Kimi or any Moonshot AI product for any purpose on any device. If you have previously used Kimi for work tasks, notify the DPO immediately.

Risk Dimensions Assessment
Data Privacy
UNACCEPTABLE
Provider Stability
LIMITED
Decision Autonomy
HIGH
Jurisdiction Risk
UNACCEPTABLE
Use Risk
UNACCEPTABLE

ChatGPT

OpenAIJurisdiction: United States
Not Approved OVERALL: LIMITED

Not approved as it does not fit into our current tooling due to it duplicating capability we receive through Google AI infrastructure. Same guidance as before: ChatGPT Enterprise would offer broadly similar capability to tools we already have through Gemini and Claude. There is no approved enterprise ChatGPT agreement. The personal/Plus tier remains separately rated below and is not approved for work use. If a specific GPT-5.5 capability is not available through our existing approved tools, raise it with the Systems Team for evaluation.

Risk Dimensions Assessment
Data Privacy
LIMITED
Provider Stability
MINIMAL
Decision Autonomy
LIMITED
Jurisdiction Risk
LIMITED
Use Risk
LIMITED

Grok

xAIJurisdiction: United States
Not Approved OVERALL: HIGH

Grok collects and trains on user data, including X account activity, and has no enterprise data agreement available to us. New multi-agent sub-systems do not change this assessment, since the underlying data handling is the limiting factor. Gemini covers any real-time search and research need within our existing protections. Do not use Grok for work tasks.

Risk Dimensions Assessment
Data Privacy
HIGH
Provider Stability
LIMITED
Decision Autonomy
LIMITED
Jurisdiction Risk
LIMITED
Use Risk
HIGH

Meta AI

MetaJurisdiction: United States
Not Approved OVERALL: HIGH

Meta AI, including the new Muse Spark integration, remains embedded across WhatsApp, Instagram, and Facebook, and any work information shared with it, even casually, is subject to Meta's advertising data practices and may be used for model training. Do not share work-related information, client names, or project details with Meta AI in any context, including on personal devices.

Risk Dimensions Assessment
Data Privacy
HIGH
Provider Stability
MINIMAL
Decision Autonomy
LIMITED
Jurisdiction Risk
LIMITED
Use Risk
HIGH

Character.AI

Character TechnologiesJurisdiction: United States
Not Approved OVERALL: HIGH

Character.AI remains a roleplay and entertainment platform with no professional use case and a documented history of legal scrutiny over harmful content. New features such as Charms currency and mid-chat image generation do not change the underlying assessment. Should not be accessed on company devices or networks.

Risk Dimensions Assessment
Data Privacy
HIGH
Provider Stability
LIMITED
Decision Autonomy
LIMITED
Jurisdiction Risk
LIMITED
Use Risk
HIGH

Microsoft Copilot

MicrosoftJurisdiction: United States
Not Approved OVERALL: LIMITED

Not approved as it does not fit into our current tooling due to it duplicating capability we already receive through Google AI Infrastructure, which provides equivalent functionality through Gemini. The new PowerPoint/Excel/Word Agents and unified Teams experience are capable additions, but they do not change the underlying calculus: there is no approved access to M365 Copilot, and staff should not sign up for personal M365 accounts for work purposes. Raise role-specific needs with your manager.

Risk Dimensions Assessment
Data Privacy
LIMITED
Provider Stability
MINIMAL
Decision Autonomy
LIMITED
Jurisdiction Risk
LIMITED
Use Risk
LIMITED

Cursor

AnysphereJurisdiction: United States
Not Approved OVERALL: LIMITED

Approved on Business/Enterprise tier only, with Privacy Mode enforced. This is an upgrade from our prior assessment. Cursor's Business and Enterprise tiers now enable Privacy Mode by default, enforceable organization-wide so individual users cannot disable it, with zero data retention agreements covering all of its model providers, SOC 2 Type II certification, and the option for customer-managed encryption keys. This addresses our previous core objection, which was that Cursor uploaded entire codebases by default with no enterprise agreement. What has not changed is that AI coding tools as a category remain high-risk for accidental leakage of credentials and source code, and Cursor's own Background Agents and Hooks push further into unattended, multi-step autonomy, which a 2025 vulnerability (CurXecute) showed can be exploited through indirect prompt injection. Approved for use only on Business or Enterprise tier with Privacy Mode locked on and auto-run disabled for shell commands on sensitive repositories. Gemini Code Assist remains the preferred default for most developers since it is already included in our Cloud subscription; Cursor is approvable where its specific capabilities are genuinely needed.

Risk Dimensions Assessment
Data Privacy
LIMITED
Provider Stability
MINIMAL
Decision Autonomy
HIGH
Jurisdiction Risk
LIMITED
Use Risk
HIGH

Qwen3-Coder

Alibaba CloudJurisdiction: China (PRC)
Not Approved OVERALL: HIGH

Qwen3-Coder is developed by Alibaba, a Chinese company, and using it via its own API or website sends data, in this case potentially including source code and credentials, to servers subject to Chinese data laws. Do not access Qwen3-Coder directly for any work purpose. As with other Qwen models, self-hosted deployment within our own Google Cloud infrastructure would materially change this rating, since jurisdiction risk attaches to where data is sent, not where a model originated; that route would need to go through the Systems Team and is not yet established for this specific coding-focused model.

Risk Dimensions Assessment
Data Privacy
HIGH
Provider Stability
MINIMAL
Decision Autonomy
LIMITED
Jurisdiction Risk
HIGH
Use Risk
HIGH

Perplexity

Perplexity AIJurisdiction: United States
Not Approved OVERALL: HIGH

Perplexity stores and trains on conversations even on paid plans, and a previous security incident exposed user files stored without encryption. Perplexity has since become an agentic web browser (Comet) and orchestration platform (Computer) that can read and act on the contents of a user's logged-in accounts, and an independently published audit found this could be manipulated by malicious page content into leaking information from those accounts, alongside an active federal lawsuit over unauthorized account access through the browser agent. All legitimate research and search use cases remain covered by Gemini with Google Search grounding and NotebookLM within our existing Workspace tools. Do not use Perplexity, Comet, or Computer for any work-related queries or tasks.

Risk Dimensions Assessment
Data Privacy
HIGH
Provider Stability
LIMITED
Decision Autonomy
HIGH
Jurisdiction Risk
LIMITED
Use Risk
HIGH

ChatGPT Search

OpenAIJurisdiction: United States
Not Approved OVERALL: LIMITED

Not approved as it does not fit into our current tooling due to it duplicating capability we already receive through Google AI Infrastructure. Search functionality with publisher partnerships is a capability improvement but does not change the data handling picture. Gemini with Google Search grounding meets this need within our existing Workspace tools and data protections.

Risk Dimensions Assessment
Data Privacy
LIMITED
Provider Stability
MINIMAL
Decision Autonomy
LIMITED
Jurisdiction Risk
LIMITED
Use Risk
LIMITED

Sora 2

OpenAIJurisdiction: United States
Not Approved OVERALL: LIMITED

Not approved as it does not fit into our current tooling due to it duplicating capability we already receive through Google Veo. No change in substance. With the standalone Sora app discontinued and Sora 2 folded into ChatGPT, this is now best understood as a ChatGPT feature rather than a separate product, but the underlying data terms are the same as ChatGPT generally. We have equivalent capability through Google Veo on our existing Google Cloud account, covered by our data agreement. There remains no approved enterprise agreement for OpenAI's video tools.

Risk Dimensions Assessment
Data Privacy
LIMITED
Provider Stability
MINIMAL
Decision Autonomy
MINIMAL
Jurisdiction Risk
LIMITED
Use Risk
LIMITED

Kling 2.0

KuaishouJurisdiction: China (PRC)
Not Approved OVERALL: UNACCEPTABLE

Kuaishou is a Chinese company and Kling is subject to the same national security laws as DeepSeek and Kimi, meaning any footage, prompts, or imagery submitted could be accessed by the Chinese government with no independent judicial check. Kling's deep integration into Chinese social and e-commerce platforms increases the realistic chance of data crossing into that ecosystem incidentally. Do not use Kling for any work purpose on any device. If a specific video capability is not available through Veo or Runway, raise it with the Systems Team rather than using Kling directly.

Risk Dimensions Assessment
Data Privacy
UNACCEPTABLE
Provider Stability
LIMITED
Decision Autonomy
MINIMAL
Jurisdiction Risk
HIGH
Use Risk
HIGH

Qwen 3.7

Alibaba CloudJurisdiction: China (PRC)
Not Approved OVERALL: HIGH

Not approved via direct API. No change in principle from our existing Qwen guidance. Do not access Qwen 3.7 via the Alibaba Cloud API or website for any work purpose. Earlier Qwen models are available via Vertex AI Model Garden, where they run inside our Cloud environment under our data agreement; whether Qwen 3.7 specifically has been added to that route should be confirmed with the Systems Team before assuming it is approved.

Risk Dimensions Assessment
Data Privacy
HIGH
Provider Stability
MINIMAL
Decision Autonomy
LIMITED
Jurisdiction Risk
HIGH
Use Risk
HIGH

DeepSeek V4

DeepSeekJurisdiction: China (PRC)
Not Approved OVERALL: UNACCEPTABLE

DeepSeek remains subject to Chinese national security laws requiring data handover to the state on demand, and prior security research found hidden code transmitting user data to Chinese state-controlled infrastructure. V4's improved cost and performance do not change this. Do not use DeepSeek for any purpose on any device. If you have previously used DeepSeek for work tasks, notify IT immediately.

Risk Dimensions Assessment
Data Privacy
UNACCEPTABLE
Provider Stability
LIMITED
Decision Autonomy
LIMITED
Jurisdiction Risk
UNACCEPTABLE
Use Risk
UNACCEPTABLE

Kimi

Moonshot AIJurisdiction: China (PRC)
Not Approved OVERALL: UNACCEPTABLE

Kimi remains subject to Chinese national security laws with no independent mechanism to prevent government data access, and there is no data agreement or privacy certification covering our use. Rapid iteration (K2.5 through K2.7) does not change the jurisdictional analysis. Do not use Kimi for any purpose on any device. If you have previously used Kimi for work tasks, notify the DPO immediately.

Risk Dimensions Assessment
Data Privacy
UNACCEPTABLE
Provider Stability
LIMITED
Decision Autonomy
LIMITED
Jurisdiction Risk
UNACCEPTABLE
Use Risk
UNACCEPTABLE

MiniMax

MiniMaxJurisdiction: China (PRC)
Not Approved OVERALL: HIGH

MiniMax is a Chinese company and carries the same jurisdictional risk as other mainland Chinese AI platforms assessed here: data submitted is subject to Chinese government access laws with no independent judicial check. Do not use MiniMax for any work purpose. As with Qwen and Yi, self-hosted deployment within our own infrastructure would change this analysis, but no such route has been established; raise any specific use case with the Systems Team rather than accessing MiniMax directly.

Risk Dimensions Assessment
Data Privacy
HIGH
Provider Stability
LIMITED
Decision Autonomy
LIMITED
Jurisdiction Risk
HIGH
Use Risk
HIGH

Zhipu AI

Zhipu AIJurisdiction: China (PRC)
Not Approved OVERALL: HIGH

Zhipu AI is a Chinese company and GLM-5.1 carries the same jurisdictional risk as other mainland Chinese AI platforms in this matrix. Do not use Zhipu AI products for any work purpose. Self-hosted, Google Cloud-based deployment would change the jurisdictional picture, as with Qwen, but is not currently established; raise specific needs with the Systems Team.

Risk Dimensions Assessment
Data Privacy
HIGH
Provider Stability
LIMITED
Decision Autonomy
LIMITED
Jurisdiction Risk
HIGH
Use Risk
HIGH

Kuaishou (Kling)

KuaishouJurisdiction: China (PRC)
Not Approved OVERALL: UNACCEPTABLE

Kuaishou is a Chinese company subject to the same national security laws as DeepSeek and Kimi. Do not use any Kuaishou or Kling product for any work purpose on any device.

Risk Dimensions Assessment
Data Privacy
UNACCEPTABLE
Provider Stability
LIMITED
Decision Autonomy
MINIMAL
Jurisdiction Risk
HIGH
Use Risk
HIGH