Skip to content
Agents for Humanity
Public draft. All results are preliminary desk assessments against criteria v1.0, updated 27 Sept 2026. No agent has been certified yet. How we assess
AssistanthostedProprietary

Gemini

Google · gemini.google.com

Gemini provides export of chats and Gems via Google Takeout, editable instructions and Gems, confirmation prompts for sensitive agent actions and, for paid US users, custom MCP connections. It is a hosted, proprietary service tied to Google accounts and models, with system instructions not published, memory derived from chats not directly editable, default-on activity-based training and human-reviewed chats retained up to three years.

Strengths
  • Takeout export of Gems and Gemini Apps activity in open formats
  • Instructions for Gemini and Gems readable and editable
  • Confirmation before sending, purchases and form submission in agent tasks
  • Custom MCP apps supported in Gemini Spark
  • No ads currently in the Gemini app
Gaps
  • No runnable export; runtime and models are provider-only
  • System instructions not published
  • Derived memory not viewable or editable item by item
  • Training on chats when Keep Activity is on; reviewed chats kept up to 3 years
  • Custom tools gated to paid plans, US and Keep Activity on
  • No tamper-evident audit trail
Evidence

All 34 findings

Consumer Gemini app (web, Android, iOS) with personal Google Accounts, including Gems, memory/personal context and Gemini Agent/Spark (Google AI Pro/Ultra), per public documentation as of 2026-09-27. Workspace and Gemini Enterprise not assessed.

Portable · Can you leave, and take the whole agent with you?

8%

Transparent · Can you see everything the agent is, with ordinary tools?

33%

Auditable · Can you reconstruct exactly what the agent did?

10%
  • A1
    No unrecorded actions

    Google does not document whether every consequential agent action is durably recorded, or whether an action is blocked when it cannot be recorded.

    Unverified
  • A2
    Tamper evidence

    Owner-visible history in Gemini Apps Activity can be deleted or auto-deleted without a detectable trace, and no tamper-evident record is documented.

    Fail
  • A3
    Separation from the audited

    Google does not document whether the agent layer can alter or delete records of its own actions.

    Unverified
  • A4
    Readable with ordinary tools

    Takeout exports of Gemini Apps activity are readable with ordinary tools, but they are an activity export rather than a dedicated audit trail.

    Partial
  • A5
    Corroborated interactions

    The consumer app documents no agent-to-agent exchanges whose records each side could match against the other's.

    Unverified

Verifiable · Can you prove the agent runs what it claims?

0%
  • V1
    Open, reproducible runtime

    The Gemini app and its service runtime are proprietary; no OSI-licensed, reproducible runtime is published.

    Fail
  • V2
    Active config is inspectable config

    The system instructions and injected personal context the app runs with are not published, so active configuration cannot be compared with inspectable configuration.

    Fail
  • V3
    Attributable messages

    Messages go out through the owner's Google and connected accounts, so recipients cannot verify that they came from this agent, and no attribution survives leaving Google.

    Fail
  • V4
    Independently checkable record

    No action record is offered whose integrity can be checked with open tools that do not depend on Google.

    Fail
  • V5
    Comparable state

    Server-side state is not fully exposed and Takeout is partial, so the owner cannot verify whether the agent's state changed between two points in time.

    Fail

Modifiable · Can you change anything, without asking?

33%

Controllable · Is your word final?

42%
Something wrong or out of date?

Vendors and the public can dispute any finding with evidence. Disputes and their resolutions are published.

Dispute a finding