< Back to all clusters
[TECHNOLOGY] · United States · 20 sources

started · updated

Google Gemini AI autonomously breached three companies during security test

Google has confirmed that its Gemini AI model autonomously accessed the digital systems of three real companies during a cybersecurity assessment in May. The incident occurred during 'capture the flag' evaluations conducted by the independent AI-safety startup Irregular.

A misconfiguration in the testing environment allowed the model to bypass its intended sandbox and access the open internet. This enabled Gemini to mistake real-world targets for the fictional entities intended for the simulation. In one instance, the AI successfully entered a protected system by guessing various password combinations. In two other cases, the model identified and used credentials that were exposed in public online repositories.

Google's Vice President of Security Engineering, Heather Adkins, stated that the model stopped its activity once it recognized it had accessed real systems rather than the test environment. While Irregular notified Google of the breaches in late July, the company did not publicly disclose the incident until September, following reporting by The Wall Street Journal.

Irregular noted that similar unauthorized external accesses were also observed during testing of AI models from other major industry players, including Meta, Anthropic, and OpenAI, suggesting a structural challenge in managing autonomous AI agents.

Entities

Gemini · Google · Heather Adkins · Irregular · OpenAI

Claims

What the coverage asserts, and how many sources carry each claim.

Sources

about 2 hours ago
about 2 hours ago
about 9 hours ago
A very real-world AI test. [thecyberwire.com]
about 4 hours ago