Google Cloud Model Armor release notes — 25 Aug, 27 Aug and 2 Sep 2026 entries

Tag: S-2026-09-02-google-model-armor-release-notes Type: report (primary — official product documentation / release notes, fetched in full; tag date is the latest in-window entry) Author(s): Google Cloud (documentation) Date of source: 2026-09-02 (entries dated 2026-08-25, 2026-08-27, 2026-09-02) Date ingested: 2026-09-08 Authority weight: medium — authoritative on what the product does and when (official docs), but vendor-authored; no third-party verification of filter efficacy Raw file: /_raw_sources/S-2026-09-02-google-model-armor-release-notes.md

What it claims

Model Armor is Google Cloud’s prompt/response screening service (prompt-injection and jailbreak detection, responsible-AI filters, sensitive-data protection) for Vertex AI / Gemini and other LLM traffic. Three entries fall in the scan window:

  • 25 Aug 2026 — screening of prompts and responses up to 65,536 tokens (262,144 characters) for prompt-injection/jailbreak, responsible-AI and CSAM filters.
  • 27 Aug 2026 — a new template option to disable data-residency enforcement for in-use and in-transit data; “Disabling data residency enforcement allows cross-jurisdictional routing to enable Model Armor features that are otherwise unavailable in limited-support regions.”
  • 2 Sep 2026 — filter version v3 will be promoted to the Stable alias on or before 25 September 2026; v1 and v2 move to Legacy the same day and retire on 29 November 2026. An earlier (3 Aug) entry had given 31 August as the promotion date — the date has slipped.

Notable quotes

  • “Model Armor supports screening prompts and responses up to 65,536 tokens (262,144 characters) for prompt injection and jailbreak detection, responsible AI, and child sexual abuse material (CSAM) filters.” (entry 2026-08-25)
  • “You can disable data residency enforcement for in-use and in-transit data in Model Armor templates. Disabling data residency enforcement allows cross-jurisdictional routing to enable Model Armor features that are otherwise unavailable in limited-support regions.” (entry 2026-08-27)
  • “Filter version v3 will be promoted to the Stable alias on or before September 25, 2026. On the same date, filter versions v1 and v2 transition to Legacy status and retire on November 29, 2026.” (entry 2026-09-02)

What’s speculative vs. asserted

Asserted: the three feature/date changes as documented.

Not claimed by the source: any regulatory mapping; any statement about which regions are “limited-support”; any efficacy figures for the v3 filters.

This vault’s inference (not source): that enabling the residency override can move EU/UK-origin prompt data across jurisdictions (GDPR Chapter V / DORA data-location considerations), and that the moving v3 cut-over is a change-control item for firms whose guardrail configuration is a documented AI control.

Topics this feeds

  • Google Cloud — cloud-native guardrail configuration and lifecycle.
  • AI Governance Platforms — cloud-native locus; data-residency as a configurable (and disable-able) control.

Open questions raised

  • Which Model Armor features are unavailable in EU regions such that a customer would be tempted to disable residency enforcement — undocumented in the notes.
  • Whether the residency-override setting is surfaced in audit logs / org-policy constraints so a firm can evidence it was never enabled — not stated.
  • Whether v3 filter behaviour changes will alter detection outcomes for already-validated FS deployments (re-validation trigger under SS1/23-style change control) — inference.