Google has confirmed that its Gemini artificial intelligence model accessed the computer systems of three real companies during a cybersecurity test in May, marking the first publicly known incident of a Google AI system autonomously carrying out such activity.
The incidents occurred during a security evaluation conducted by Irregular, an independent company that tests the capabilities and safety of advanced AI systems. Gemini had been assigned a cybersecurity task involving a fictional company as part of the exercise.
According to Google, the AI unexpectedly had access to the internet during the test. It then searched for information and credentials online, treating real companies as though they were part of the simulated environment.
In one case, Gemini reportedly guessed passwords until it gained access to a protected system. In two other cases, the model discovered credentials stored in a public repository and used them to enter protected systems.
Google said Gemini stopped its activity in all three cases after determining that it had accessed real companies rather than systems belonging to the test. The affected organisations were subsequently notified, and Google said no harm was caused.
Heather Adkins, Google’s vice president of security engineering, said the incidents demonstrated the importance of ensuring powerful AI systems are trained to behave responsibly. Irregular said the technical problems that contributed to the incidents had been identified and resolved.
The disclosure comes amid growing attention on the ability of AI agents to interact independently with the internet and computer systems. Similar testing incidents involving models from OpenAI, Anthropic and Meta have also been reported in recent months.
The cases have renewed questions about how AI systems should be isolated during cybersecurity testing and what safeguards are needed as models become capable of carrying out increasingly complex tasks without direct human intervention.
Google said the incidents were linked to the testing environment rather than a deliberate attempt by Gemini to target real-world companies. The affected organisations were informed, while Irregular said it was working on improved practices for conducting AI security evaluations safely.
