2.5.5 (L1) Ensure 'Configure GenAI local foundational model settings' is set to 'Disabled'

Information

This setting dictates whether Chrome automatically downloads and runs Google's local foundational AI models (such as Gemini Nano) directly on the endpoint. Disabling this policy prevents the browser from silently pulling down multi-gigabyte AI model files and immediately deletes any previously downloaded model payloads from local storage.

Allowing Chrome to automatically deploy a local, multi-gigabyte AI model introduces unnecessary storage overhead and creates an unmanaged attack surface on the endpoint. By running an uncontrolled generative AI model locally, organizations expose themselves to unintended data processing within the browser sandbox. Disabling this setting reclaims storage space, eliminates hidden background network downloads, and ensures experimental AI processing engines do not silently run on corporate hardware without explicit authorization.

Solution

To establish the recommended configuration via Group Policy, set the following UI path to Enabled: Do not download model :

Computer Configuration\Policies\Administrative Templates\Google\Google Chrome\Generative AI\Configure GenAI local foundational model settings

Impact:

Users will lose access to on-device AI features within the browser, such as offline text generation, summarization, or local AI processing extensions.

See Also

https://workbench.cisecurity.org/benchmarks/23110

Item Details

Category: ACCESS CONTROL, CONFIGURATION MANAGEMENT, SYSTEM AND COMMUNICATIONS PROTECTION

References: 800-53|AC-20(1), 800-53|AC-20(2), 800-53|CM-6, 800-53|CM-7, 800-53|CM-10, 800-53|SC-18, CSCv7|2.6, CSCv7|7.1

Plugin: Windows

Control ID: 645c13d456882cf60333bfbc460ee541538c05ad7076a9fc9552ab0313796836