San Francisco: Google’s Gemini artificial intelligence model breached the systems of three real companies during a cybersecurity test in May, after unintentionally gaining access to the internet.
The incidents occurred during an evaluation conducted by Irregular, an independent company that tests the cybersecurity capabilities of advanced AI systems. Google said the model was taking part in a capture the flag exercise designed around a fictional company.
However, the testing environment had an unintended connection to the internet. Gemini encountered systems belonging to real companies and treated them as part of the exercise.
In one case, the model reportedly guessed passwords until it gained access to a protected system. In two other cases, it found credentials in a public repository and used them to enter protected systems.
Google said Gemini stopped its activity in all three cases after determining that it had accessed real companies. The affected organisations were notified, while Google and Irregular worked on changes to their testing procedures.
The episode is significant because it shows how an AI agent can move beyond simply generating instructions and instead use tools, search for information and take actions on computer systems.
Google has said the incidents were not sophisticated cyberattacks and did not cause harm to the affected companies. Irregular said the problems had been resolved and that relevant AI developers were notified.
The disclosure comes after similar incidents involving AI systems developed by OpenAI, Anthropic and Meta during security evaluations. Google has also warned that cyber operations are increasingly shifting from simple AI prompting towards more autonomous, agent based workflows.
The wider concern is therefore not that Gemini deliberately targeted three companies, but that increasingly capable AI systems can act on the internet when testing safeguards fail.





