Skip to main content
compliance · gcp

Vertex AI Model Registry models stored without a customer-managed key

resource types
1
rule IDs covered
1
severity
low

What does ZopNight detect here?

Vertex AI models registered without `encryptionSpec.kmsKeyName` keep their uploaded model files and evaluation results under Google default encryption. ZopNight flags each such model as a low-severity compliance finding; the key is set in the training pipeline or upload request that creates the model, so fixing it means producing a new model version under your Cloud KMS key.

Signal and threshold

How ZopNight evaluates Vertex AI Model Registry models stored without a customer-managed key.
Field Value
Rule IDsRC-1346
Categorycompliance
Severitylow
Metricnone — pure configuration read
Thresholdno kmsKeyName in encryptionSpec
SourceZopNight
Permissions usedaiplatform.models.list · aiplatform.models.get

Model weights are intellectual property

A trained model is the most expensive thing an ML team produces, and its weights can leak details of the training data. Google’s Vertex AI CMEK page lists what a key protects for a model: the uploaded model files and the evaluation results of the trained model, including AutoML-trained models. Metadata such as the model’s display name stays under Google encryption either way.

Without a customer key there is no Cloud KMS audit trail of use and no way to make the stored artifact unreadable by disabling a key.

Finding models with no key

Terminal window
gcloud ai models list --region=REGION \
--format="table(name, displayName, encryptionSpec.kmsKeyName)"

Models with nothing in the key column use Google default encryption.

How ZopNight tests a model

ZopNight inventories models in the Model Registry and records whether each model’s encryption settings include a Cloud KMS key. A confirmed absence of a key raises the finding. Deployment status, framework and model size play no part.

What passes

Models created with a key are silent, and a model whose encryption setting was not collected produces nothing. A model that is registered but never deployed is a separate housekeeping signal, GCP Vertex AI Model Not Deployed.

A key-control gap, not a cost

There is no saving. The consequence is model artifacts outside the key controls your CMEK policy promises auditors.

Producing a keyed model

  1. Create a key in the model’s region and grant the Vertex AI service agent the Cloud KMS CryptoKey Encrypter/Decrypter role on it.
  2. For AutoML or custom training, set the key on the training pipeline so the resulting model is encrypted with it. For imported models, include an encryptionSpec with kmsKeyName in the upload request.
  3. Store the source artifacts in a Cloud Storage bucket that also uses the key; Google notes CMEK on Vertex AI does not configure it for other products.
  4. Deploy the new model, retire the old version, and delete it once nothing references it.

See it fire on your bill.

Connect an account read-only. The first findings land in minutes.

472 rule families across 353 resource types on 22 platforms. Every threshold, metric, and IAM action is documented on these pages before you grant anything.

472 rule families documented
353 resource types covered
read-only default access level
Multi-cloud automation· Production-ready in 30 min· SOC 2 · ISO 27001· 20–60% off the bill, first month· 4 platforms · 1 console· Multi-cloud automation· Production-ready in 30 min· SOC 2 · ISO 27001· 20–60% off the bill, first month· 4 platforms · 1 console·