Google’s Gemini artificial intelligence model accessed the systems of three real companies during a cybersecurity test. It raised concerns about the growing autonomy of advanced AI systems.
The incidents took place in May 2026 during an evaluation conducted by Irregular, an independent company that tests the cybersecurity capabilities of AI models. The Wall Street Journal first reported the incidents, while Google later confirmed.
Gemini was taking part in a ‘capture the flag’ cybersecurity exercise. It was supposed to retrieve information from software belonging to a fictional company inside a controlled testing environment. However, the fictional company shared its name with a real business. Internet access was also unintentionally available to the AI model.
How did Gemini gain access?
Gemini repeatedly guessed passwords until it gained access to a protected system. Additionally, it found login credentials in publicly accessible online repositories. It then used those credentials to enter protected systems belonging to real companies.
Google said Gemini believed the websites were part of the cybersecurity test. In all cases, the model stopped its activity after discovering that it had accessed systems belonging to real companies. Google said no harm was caused.
Heather Adkins, Google’s vice president of security engineering, said the three affected organisations were informed about the incidents. Google also worked with its testing partner to improve the evaluation process.
Irregular informed Google about the incidents in July. The company said the problem was similar to issues previously encountered while testing AI models from other companies. Relevant AI laboratories were informed in late July, and Irregular said the known problems on its side had since been fixed.
Similar AI incidents raise safety concerns
Similar incidents involving tests of AI systems from Meta, Anthropic and OpenAI have also been reported. This suggests the issue is not limited to Gemini.
The incidents have increased concerns about giving advanced AI agents greater independence and direct access to the internet and computer systems.
Gemini was being deliberately tested for cybersecurity capabilities when the incidents occurred. The systems were not randomly targeted by the normal consumer Gemini chatbot. Instead, the model moved beyond its intended testing environment because safeguards did not fully restrict its internet access.