# GCP Vertex AI vertex-model Without CMEK

> Flags Vertex AI models whose files and evaluation results are not encrypted with a customer-managed key.

Source: https://zop.dev/integrations/gcp/recommendations/gcp-vertex-ai-vertex-model-without-cmek

---

## Model weights are intellectual property

A trained model is the most expensive thing an ML team produces, and its weights can leak details
of the training data. Google's [Vertex AI CMEK page](https://cloud.google.com/vertex-ai/docs/general/cmek)
lists what a key protects for a model: the uploaded model files and the evaluation results of the
trained model, including AutoML-trained models. Metadata such as the model's display name stays
under Google encryption either way.

Without a customer key there is no Cloud KMS audit trail of use and no way to make the stored
artifact unreadable by disabling a key.

## Finding models with no key

```bash
gcloud ai models list --region=REGION \
  --format="table(name, displayName, encryptionSpec.kmsKeyName)"
```

Models with nothing in the key column use Google default encryption.

## How ZopNight tests a model

ZopNight inventories models in the Model Registry and records whether each model's encryption
settings include a Cloud KMS key. A confirmed absence of a key raises the finding. Deployment
status, framework and model size play no part.

## What passes

Models created with a key are silent, and a model whose encryption setting was not collected
produces nothing. A model that is registered but never deployed is a separate housekeeping signal,
<a href="https://zop.dev/integrations/gcp/recommendations/gcp-vertex-ai-model-not-deployed">GCP Vertex AI Model Not Deployed</a>.

## A key-control gap, not a cost

There is no saving. The consequence is model artifacts outside the key controls your CMEK policy
promises auditors.

## Producing a keyed model

1. Create a key in the model's region and grant the Vertex AI service agent the Cloud KMS
   CryptoKey Encrypter/Decrypter role on it.
2. For AutoML or custom training, set the key on the training pipeline so the resulting model is
   encrypted with it. For imported models, include an `encryptionSpec` with `kmsKeyName` in the
   upload request.
3. Store the source artifacts in a Cloud Storage bucket that also uses the key; Google notes CMEK
   on Vertex AI does not configure it for other products.
4. Deploy the new model, retire the old version, and delete it once nothing references it.
