Model Armor release notes

This page contains release notes for features and updates to Model Armor. You can periodically check this page for announcements about new or updated features, bug fixes, known issues, and deprecated functionality.

You can see the latest product updates for all of Google Cloud on the Google Cloud page, browse and filter all release notes in the Google Cloud console, or programmatically access release notes in BigQuery.

To get the latest product updates delivered to you, add the URL of this page to your feed reader, or add the feed URL directly.

September 18, 2026

Feature

Filter version v4 is available and set as the default for the Latest alias. Filter version v3 is promoted to the Stable alias in all supported regions except the following:

  • In asia-northeast3, v1 remains the Stable version.
  • In australia-southeast2, v3 becomes the Stable version on September 25, 2026.

If your templates use the Stable alias, they automatically upgrade to v3 when v3 becomes Stable in that region.

Filter versions v1 (except in asia-northeast3, and starting September 25, 2026 in australia-southeast2) and v2 transition to Legacy status and retire on December 17, 2026. If your templates are explicitly configured with v1 or v2 in regions where those versions are in Legacy status, you must migrate them to v3 or the Stable alias before December 17, 2026.

For more information, see Version release timeline and Model Armor filter version history.

September 04, 2026

Feature

Clarification: August 5, 2026 release note for Melbourne and Seoul

In Melbourne (australia-southeast2) and Seoul (asia-northeast3), only the Sensitive Data Protection filter is supported when data residency is enforced. To use other Model Armor features in these regions, disable data residency enforcement in the template.

For information about available Model Armor features for each region, see Supported features by region.

September 02, 2026

Feature

Filter version v3 will be promoted to the Stable alias on or before September 25, 2026. On the same date, filter versions v1 and v2 transition to Legacy status and retire on November 29, 2026.

If your templates use the Stable alias, they will automatically upgrade to v3 when it is promoted. If your templates use explicit version numbers (v1 or v2), migrate them to v3 or the Stable alias before November 29, 2026.

For more information, see Set the filter version for a template.

August 27, 2026

Feature

You can disable data residency enforcement for in-use and in-transit data in Model Armor templates. Disabling data residency enforcement allows cross-jurisdictional routing to enable Model Armor features that are otherwise unavailable in limited-support regions. Data at rest remains compliant with data residency requirements.

For more information, see Set data residency compliance and Data residency and endpoints.

August 25, 2026

Feature

Model Armor supports screening prompts and responses up to 65,536 tokens (262,144 characters) for prompt injection and jailbreak detection, responsible AI, and child sexual abuse material (CSAM) filters. Model Armor scans only the first 256 URLs found in prompts and responses.

For more information, see Token system limits.

August 05, 2026

Feature

Model Armor supports data residency compliance for in-use and in-transit data in the following regions:

  • Melbourne (australia-southeast2)
  • Seoul (asia-northeast3)

To maintain data residency compliance, these regions have limited feature support. For more information about data residency enforcement in Model Armor, see Data residency and endpoints.

For information about available Model Armor features for each region when using templates, see Supported features by region.

A clarification for this release note is provided in the September 4, 2026 release note.

August 03, 2026

Feature

Filter version v3 will be promoted to the Stable alias on August 31, 2026. On the same date, filter versions v1 and v2 transition to Legacy status and retire on November 29, 2026.

If your templates use the Stable alias, they automatically upgrade to v3 on August 31, 2026. If your templates use explicit version numbers (v1 or v2), migrate them to v3 or Stable before November 29, 2026. For more information, see Set the filter version for a template.

July 20, 2026

Feature

The responsible AI safety filter for the hate speech, harassment, sexually explicit, and dangerous content categories has been upgraded to improve detection accuracy and reduce the rate of false positives.

July 10, 2026

Feature

Streaming sanitization for text is generally available (GA). For more information, see Sanitize streaming text prompts.

July 08, 2026

Feature

Model Armor supports data residency in-use and in-transit compliance in Japan (asia-northeast1) and the United Kingdom (europe-west2). These regions have limited feature support. For more information, see Data residency.

July 01, 2026

Feature

You can select the modality (text, images, or both) when creating a Model Armor template in the Google Cloud console. Image modality is supported in the us and eu multi-regions. This feature is in Preview. For more information, see Image screening.

June 25, 2026

Feature

Model Armor supports screening images within prompts and responses. This feature extends Model Armor's protection capabilities to multimodal inputs, helping you detect and mitigate risks associated with image content in your AI applications. This feature is in Preview. For more information, see Image screening.

June 24, 2026

Feature

You can enable Model Armor on an Agent Gateway resource to apply your organization's content security guardrails to prompts and responses that pass through the gateway. This feature is generally available (GA).

For more information, see Integrate Model Armor with Agent Gateway.

June 22, 2026

Feature

Model Armor supports data residency in-use compliance in Singapore (asia-southeast1). This region has limited feature support. Filter version v3 under the Latest alias is available in asia-southeast1 and it includes an updated prompt injection and jailbreak detection filter to improve accuracy and reduce false positives. For more information, see Data residency.

June 16, 2026

Feature

Filter version v3 under the Latest alias is available in asia-south1 and northamerica-northeast2. This version includes an updated prompt injection and jailbreak detection filter to improve accuracy and reduce false positives.

June 08, 2026

Feature

Model Armor supports data residency in-use compliance in Mumbai (asia-south1) and Toronto (northamerica-northeast2). This compliance lets you meet regional data locality requirements when using Model Armor in these regions. For more information, see Data residency.

May 25, 2026

Feature

Model Armor supports multiple filter versions, allowing you to choose the version that best suits your needs for stability and access to the latest features. You can configure versions within your templates using version numbers or aliases such as Latest, Stable, and Legacy. For more information, see Set the filter version for a template.

A new filter version, v3, is available under the Latest alias. v3 features an updated prompt injection and jailbreak detection filter. This new model has been trained to:

  • Significantly reduce false positives.
  • Provide improved detection and mitigation against various attack vectors.

May 12, 2026

Feature

Model Armor supports streaming sanitization for text. You can process user prompts and model responses more efficiently for large inputs and low-latency scenarios by sending text to the Model Armor API as a stream of chunks. This feature is in Preview. For more information, see Sanitize streaming text prompts.

April 22, 2026

Feature

Model Armor is available in Gemini Enterprise Agent Platform and integrates with Agent Gateway to provide enhanced security and governance for your AI agent interactions. This integration lets you enforce Model Armor's AI safety and security policies directly on gateway traffic.

To screen AI agents for content security risks and block violations, configure Model Armor on the gateways that govern your agents. You can then do the following:

This feature is in Preview. For more information, see Integrate with Agent Gateway.

April 10, 2026

Change

The level of detail provided in the virusDetails field of the Antivirus filter scan results has been updated. To enhance security and align with data handling policies, responses no longer include specific names of security vendors or threat signatures. Instead, generalized placeholders are used when a threat is detected. This change does not affect the efficacy of the Antivirus filter's detection capabilities.

April 06, 2026

Change

Model Armor is FedRAMP High compliant.

Feature

Model Armor can sanitize data passed in as rich documents that have specific metadata labels. To use this feature, create a custom metadata label infoType in Sensitive Data Protection. Use the custom infoType in an advanced Sensitive Data Protection configuration in your Model Armor template.

March 31, 2026

Change

Prompt injection and jailbreak detection was improved to reduce the rate of false positives and false negatives.

March 27, 2026

Change

Model Armor is available in the following regions:

  • asia-northeast1 (Japan)
  • asia-northeast3 (South Korea)
  • europe-southwest1 (Madrid)
  • europe-west9 (Paris)
  • northamerica-northeast2 (Canada)

For more information, see Locations.

March 26, 2026

Change

The malicious URL detection and responsible AI safety filters are fixed to improve detection accuracy and reduce the rate of false positives.

March 06, 2026

Change

Model Armor is available in the australia-southeast2 (Melbourne) region. For more information, see Model Armor Locations.

March 05, 2026

Change

For non-English requests, the translation process was enhanced to improve service availability and processing efficiency.

February 27, 2026

Change

The behavior of multi-language detection for text prompts and model responses has changed.

Previously, if you specified the source language in your sanitization request, Model Armor compared the specified language with the automatically detected language. If the specified and detected languages differed, Model Armor skipped the request.

With this change, if you specify the source language, Model Armor uses that language to evaluate the request. It no longer attempts to automatically detect the language.

February 10, 2026

Change

The error messages returned by the Sensitive Data Protection detector have been modified to exclude internal details. If a transient or internal quota error occurs, you will receive the message: Error occurred while processing sensitive data detection. Please try again.

January 30, 2026

Change

The prompt injection and jailbreak detection filter for the Mumbai (asia-south1) and Singapore (asia-southeast1) regions is upgraded to improve detection accuracy and reduce the rate of false positives.

December 15, 2025

Feature

You can