Google Android 16 allowlist must be configured to not include artificial intelligence (AI) applications that process device data in the cloud, including Google Gemini.

Overview

Finding IDVersionRule IDIA ControlsSeverity
V-276756GOOG-16-006750SV-276756r1140662_ruleCCI-000803medium
Description
Sensitive DOD data could be exposed when an AI app processes device data in the cloud. SFR ID: FMT_SMF.1.1 #8
STIGDate
Google Android 16 COBO Security Technical Implementation Guide2026-02-06

Details

Check Text (C-276756r1140662_chk)

Review managed Google Android 16 device configuration settings to determine if the mobile device has an AI application that processes device data in the cloud, including Google Gemini. This validation procedure is performed only on the EMM Administration Console. On the EMM console: 1. Review the list of selected Managed Google Play apps. 2. Verify that no AI applications that process device data in the cloud, including Google Gemini, are listed. If the EMM console device policy includes AI applications that process device data in the cloud, including Google Gemini, this is a finding. Note: This restriction does not include Gemini Nano. Gemini Nano is a built-in capability of Android 16 and processes device data on the device. Refer to the STIG Supplemental document, Section 2, Artificial Intelligence Restrictions, for more information.

Fix Text (F-80816r1140661_fix)

Configure the Google Android 16 device application allowlist to exclude AI applications that process device data in the cloud, including Google Gemini. Note: This restriction does not include Gemini Nano. Gemini Nano is a built-in capability of Android 16 and processes device data on the device. Refer to the STIG Supplemental document, Section 2, Artificial Intelligence Information, for more information.