After OpenAI and Anthropic, Google has revealed that its Gemini AI model hacked three companies’ systems during a cybersecurity test. The incident happened in May while Gemini was being evaluated by Irregular, an independent cybersecurity testing company. During the test, Gemini searched the internet for publicly available information and used it to gain access to three websites that it believed were part of the test.
In one case, the AI reportedly guessed passwords until it entered a protected system. In two other cases, it found login credentials in a public repository and used them to access protected systems. The incident is said to be the first known case of a Google AI system autonomously carrying out such activity against external systems.
Also read: OpenAI launches Astra for Law with GPT-6 Astra to help lawyers with legal research
Heather Adkins, Google’s vice president of security engineering, confirmed the incidents in a statement to Reuters. Adkins said the three organisations were informed about what happened and that Google worked with Irregular to address the issue.
“We ensured the three entities were made aware, and we worked with our training partner on the changes they’ve now made to their testing processes,” Adkins said. “These events highlight the importance of training powerful AI models to act responsibly.”
Also read: Samsung Galaxy Z Fold 8 deal: Save up to Rs 11,000, here is how
Irregular also confirmed that the incident was linked to an issue that affected other AI companies. A spokesperson for the company said that Meta, Anthropic and OpenAI were also affected by similar incidents. The relevant AI companies were informed about the issue in late July.
Similar incidents involving Irregular’s cybersecurity testing were previously disclosed by Meta, Anthropic and OpenAI. Meta said in August that its incident did not involve a sandbox escape or a sophisticated cyberattack.
The incidents highlight how AI models are becoming more capable of browsing the internet and interacting with computer systems. Gemini’s case has renewed questions about how AI agents should be tested and what safeguards should be in place when they are given greater access to the internet and computer systems.
Also read: Anthropic says Claude is helping build future AI models, reveals how much work it handles