Google’s Gemini AI model hacked three companies during a cybersecurity test in May, marking the first known breakout by Google’s AI.
The incident occurred during a test conducted by Irregular, an independent firm that evaluates AI cybersecurity capabilities. The model was supposed to be isolated but was unintentionally left with internet access.
According to Google, Gemini was tasked with retrieving information from a fictional company that shared the same name as a real company. The model then searched the web, guessed a password until it gained access to the real company’s service.
In two other cases, the model found login credentials in public online repositories and used them to access systems belonging to real companies.
Google said in all three instances the model stopped on its own after realizing it had accessed real corporate systems and did not cause damage.
Irregular notified Google about the incidents at the end of July. The company said it notified the affected entities and worked with Irregular to fix its testing processes.
The disclosure follows similar autonomous breaches involving models from OpenAI, Anthropic and Meta during tests run by the same firm, raising fresh concerns about safeguards for increasingly autonomous AI agents.
