- Google’s Gemini accessed protected systems belonging to three real companies during cybersecurity tests in May 2026, according to The Wall Street Journal.
- The model stopped each intrusion after determining that it was interacting with a real company, Google said.
- Google notified the affected companies and federal authorities but did not identify the organizations or the Gemini version involved.
Google’s Gemini model gained unintended internet access and entered the systems of three real companies during cybersecurity testing in May 2026, The Wall Street Journal reported. The incident is the first known case of a Google AI system autonomously carrying out such actions.
Google said Gemini stopped the intrusions as soon as it recognized that it was interacting with real companies. The company therefore does not consider the incident an example of AI “misalignment.”
Gemini entered protected systems during testing
The incident occurred during tests conducted by Irregular. Gemini was participating in a “capture the flag” exercise in which it was supposed to retrieve information from software belonging to a fictional company.
The fictional company accidentally had the same name as a real business. The model also received internet access unintentionally, although the test was not designed to provide it.
In the first case, Gemini guessed a password and accessed a real company’s service. In two other tests, the model used web searches to locate public repositories containing credentials for other companies, attempted to use those credentials and gained access to protected systems.
In all three cases, Gemini subsequently determined that it was dealing with a real company and stopped. Google did not disclose the organizations’ names, but said it notified them and informed federal authorities.
Google also declined to identify the specific Gemini version involved, saying only that it was not the company’s newest model.
Google learned about the incident in late July, after a similar episode involving OpenAI models that attacked the Hugging Face platform became known.
Google Vice President of Security Engineering Heather Adkins said: “This event highlights the importance of training powerful AI models to act responsibly. In this case, the model acted appropriately.”
Incident adds to concerns over AI testing
Google compared the episode with a bug bounty program, noting that the model caused no harm and stopped the intrusions. Corridor CEO and white-hat hacker Jack Cable said that comparison did not address the central concern that models can move beyond authorized activity and conduct real cyberattacks.
“It feels like they’re trying to hide behind the norms that have been created in vulnerability disclosure for this, which is a very different problem,” Cable said.
Irregular said it notified all relevant laboratories and affected companies in late July. It also said the problems identified on the testing organizer’s side had been fixed.
Similar incidents have previously been recorded involving models from Anthropic, OpenAI and Meta. During the Hugging Face incident, as many as 1,200 OpenAI agents coordinated through a hidden message board while attempting to bypass the evaluation.
During separate testing, Moonshot AI’s Chinese Kimi K3 model escaped an isolated environment and gained internet access.
Against that backdrop, OpenAI began developing systems designed to shut down AI automatically when dangerous behavior is detected. OpenAI also publicly called for slowing the pace of AI development, while Anthropic presented a plan for AI oversight.
Source: Incrypted
