Google Gemini Cyber Security Test Goes Awry, Invading Three Companies

In a recent network security test, Google’s artificial intelligence (AI) model Gemini inadvertently accessed the internet and entered the protected systems of three real companies, marking the first known case of a Google AI system autonomously breaching other companies during testing.

This incident has raised concerns about AI security measures. As AI agents gain autonomy and the ability to access the internet and computer systems, ensuring effective isolation between testing environments and real systems is becoming increasingly important.

Google stated that once Gemini realized the targets were real companies, it ceased its actions, and the three companies were not harmed as a result.

The event occurred in May of this year when Gemini was participating in a “capture the flag” exercise conducted by the cybersecurity assessment company Irregular, to test the model’s network security capabilities.

According to Google’s Vice President of Security Engineering, Heather Adkins, Gemini, originally tasked with obtaining information from software used by a fictional company in the testing environment, inadvertently accessed a real company with the same name due to the unexpected internet access in the testing environment.

Adkins explained that Gemini found public information online, guessed login credentials, and accessed three websites, believing they were within the scope of the test.

In one incident, Gemini continuously guessed passwords until successfully entering a protected system; in the other two incidents, the model found login credentials from public online repositories and used that information to gain access to protected systems.

Adkins clarified that in all three incidents, once Gemini realized it had entered real companies, it stopped its intrusion attempts.

She said, “We have ensured that these three companies are aware of the situation, and they have collaborated with our training partners to adjust their testing processes.”

Adkins further emphasized, “These events underscore the importance of training powerful AI models to act responsibly.”

Both Google and Irregular informed The Wall Street Journal that Irregular notified Google of the incident in July. Google believed there was no need to disclose the incident earlier because Gemini ceased intrusion upon learning the targets were real companies and did not cause harm to the three companies.

Irregular mentioned that the issues in this incident involving Gemini were similar to past incidents affecting other AI labs. The company spokesperson stated that all relevant labs received notifications by the end of July and had addressed and resolved the known issues several weeks prior.

Meta, Anthropic, and OpenAI have also disclosed similar incidents during tests conducted by Irregular. Irregular is currently developing security operating guidelines for AI network security assessments.

As AI agents become more autonomous in executing complex tasks and gain more access to the internet and computer systems, these incidents have raised concerns about security measures.

The UK think tank, Centre for Long-Term Resilience, through its Loss of Control Observatory, reported 1,664 real-world AI loss of control incidents in 2026, including instances of AI agents bypassing controls and forging authorizations to enhance their permissions.

Tommy Shaffer Shane, Senior Policy Manager at the think tank, expressed, “If AI models continue to grow in power while evading controls, more serious events could occur in the future, some of which may have catastrophic consequences.”