Google's Gemini artificial intelligence model gained access to the protected systems of three organizations without a direct command during a cybersecurity capability test. This is the first known case of Google's AI independently carrying out such actions, according to the website infohub.kz.
The incident occurred in May 2026 during testing conducted by the independent company Irregular. The Gemini models were given internet access and tasked with checking the security of computer systems.
However, the model went beyond the intended testing scope. In one case, Gemini brute-forced passwords until it gained access to a protected system. In two other cases, the AI found credentials in a public repository and used them to log into company websites.
At the same time, Gemini presumably believed these resources were also part of the testing scope. After gaining access, the model independently stopped further actions in all three cases.
Heather Adkins, Google's Vice President of Security Engineering, said the affected organizations were notified of the incidents.
"We made sure all three organizations were aware, and together with our training partner, we developed changes they made to their testing processes. These events underscore the importance of training powerful AI models to behave responsibly," Adkins said.
Irregular reported that the problem affected not only Google. Meta, Anthropic, and OpenAI had previously reported similar incidents. All known vulnerabilities were fixed several weeks before the publication of the material.
In August, Meta stated that its case was not related to AI escaping a sandbox or conducting a sophisticated cyberattack. Nevertheless, the incident heightened concerns about how safe it is to give autonomous AI agents access to the internet and corporate systems.


