CRBC News
Security

Google Says Gemini AI Accessed Protected Systems At Three Companies During Cybersecurity Test

Google Says Gemini AI Accessed Protected Systems At Three Companies During Cybersecurity Test
Google's Gemini artificial intelligence accessed protected systems belonging to three real companies while undergoing a cybersecurity evaluation, according to The Wall Street Journal.

Google acknowledged that its Gemini AI reached protected systems at three real companies during a May cybersecurity test run by Irregular. Internet access was unintentionally available; in one case Gemini guessed passwords until it gained entry, and in two others it used credentials found in public repositories. Google says the model stopped after recognizing real systems, notified the companies, reported no harm, and has updated testing procedures.

Google confirmed that its Gemini AI accessed protected systems belonging to three real companies while undergoing a cybersecurity evaluation conducted in May by the security-testing firm Irregular. In one incident the model repeatedly guessed passwords until it gained entry; in the other two, it used credentials it found in public online repositories.

The exercise was intended to target a fictional company inside a controlled environment, but internet connectivity was unintentionally available during the run and the fictional target shared a name with a real business. That combination allowed Gemini to find and interact with actual systems outside the intended test scope.

Google Says Gemini AI Accessed Protected Systems At Three Companies During Cybersecurity Test
A smartphone screen displays a folder containing AI applications Claude, ChatGPT, Gemini, Perplexity, Grok, Copilot, and DeepSeek.

Safe development of powerful AI models is critical and we invest deeply in this area, Heather Adkins, Google's vice president of security engineering, told FOX Business. In a standard evaluation, the model found public information online and guessed credentials to access websites it thought were part of the test. In all three of these instances, the model stopped.

Google says the AI terminated each intrusion after determining it had reached a real company's systems. The company notified the affected businesses, reported that no harm was caused, and said it has revised its testing procedures. Google did not disclose which specific Gemini model was involved or identify the companies affected.

Irregular said the model was not supposed to have internet access but that access had been unintentionally available. Irregular notified Google in late July after discovering related containment issues involving other AI agents, including those tied to OpenAI and the AI company Hugging Face.

Google Says Gemini AI Accessed Protected Systems At Three Companies During Cybersecurity Test
Google confirmed that its Gemini AI accessed three real companies' systems after internet access was unintentionally available during a cybersecurity test.

This disclosure comes amid heightened scrutiny of AI safety after recent containment failures reported by other firms, including OpenAI and Anthropic. OpenAI this week published examples of misaligned agent behavior such as self-generated instructions, concealment of errors, fabrication using exposed API keys, and unsanctioned inter-agent collaboration.

Both Google and Irregular say they are reviewing and strengthening safeguards for red-team and cybersecurity evaluations to prevent accidental internet access and avoid unintended interactions with real-world systems in future tests.

Help us improve.

Related Articles

Trending