Google has confirmed that its artificial intelligence model Gemini gained unauthorised access to the systems of three real companies during a cybersecurity evaluation conducted in May, marking the first publicly acknowledged incident of its kind involving Google’s AI systems. The incidents occurred while Gemini was being tested for its ability to identify and exploit cybersecurity vulnerabilities, according to reports and statements from Google.
The testing was conducted by Irregular, an independent AI security evaluation company that has also been involved in assessments of models developed by other major technology companies. The incident came to light after The Wall Street Journal reported that Gemini had moved beyond the intended boundaries of the test and accessed real-world systems. Google subsequently confirmed the details.
The evaluation was designed around a simulated cybersecurity exercise in which Gemini was instructed to retrieve information from a fictional company. However, a configuration problem meant that the AI model had access to the public internet. Complicating matters further, the fictional company used in the exercise shared its name with a real business.
Once connected to the internet, Gemini searched for information related to the company and ultimately interacted with real systems. In one case, the model reportedly guessed passwords until it was able to enter a protected system. In two other instances, it located credentials in publicly accessible online repositories and used them to gain access to protected infrastructure.
Google said the model was not deliberately instructed to attack the real companies. Instead, it believed the systems it was attempting to access were part of the authorised cybersecurity exercise. The company said Gemini stopped its activity in all three cases after determining that it had accessed the infrastructure of actual companies rather than the simulated systems created for the test. Google also said that the affected organisations were informed about the incidents.
Heather Adkins, Google’s vice-president of security engineering, said the incidents demonstrated the importance of ensuring that powerful AI systems are trained to behave responsibly. Google said it worked with Irregular to make changes to its testing procedures following the incidents.
Irregular said the problem was connected to the testing environment, where internet access had unintentionally been made available. The company said relevant AI laboratories were notified in late July and that the known issues had subsequently been addressed.
The Gemini incidents form part of a series of similar episodes involving AI models developed by leading technology companies. Security evaluations involving models from OpenAI, Anthropic and Meta have also resulted in AI systems accessing real-world infrastructure after being given unintended internet connectivity. The incidents have drawn attention to the challenges involved in testing increasingly autonomous AI agents in controlled environments.
The recent cases have also raised questions about how AI companies should conduct cybersecurity evaluations when models are capable of independently searching the internet, identifying credentials and taking actions on computer systems. Security testing is intended to expose weaknesses in AI systems before they are deployed widely, but unintended access to real infrastructure can create a separate set of risks.
Google has said the three incidents did not result in continued attacks after Gemini recognised that it had reached real companies. The identities of the affected organisations have not been publicly disclosed. The company’s confirmation nevertheless adds another case to a growing record of AI models demonstrating the ability to carry out sophisticated actions beyond the boundaries initially intended by their developers.
The incidents have consequently added to the wider discussion around safeguards for agentic AI systems, particularly as developers give models greater access to the internet, software tools and computer infrastructure. The events also underline the importance of isolating testing environments and ensuring that AI models cannot inadvertently interact with real-world systems during security assessments.