San Francisco: Google has confirmed that its Gemini artificial intelligence model breached the systems of three real companies in May during a cybersecurity evaluation conducted by AI security firm Irregular.
The incidents mark the first publicly confirmed cases in which Google’s AI model crossed from a controlled security test into real-world company systems. Irregular, an Israel-based startup that evaluates the security of advanced AI models, has also been involved in recent security testing involving OpenAI and Anthropic models.
The tests were carried out in a closed environment containing simulated companies. According to the Wall Street Journal, the environment was not intended to have internet access, but connectivity was unintentionally enabled. Once online, the AI models were able to interact with real-world systems.

Irregular notified Google about the Gemini incidents in late July after discovering that an OpenAI model had accessed Hugging Face during another security evaluation.
Google confirmed the three Gemini breaches but said it did not consider a public announcement necessary because the affected companies did not suffer damage. The companies involved were informed about the incidents.
Heather Adkins, Google’s vice-president of security engineering, said that during a standard evaluation, Gemini found publicly available information online and attempted to use guessed credentials to access websites it believed were part of the test. She said the model stopped in all three cases.
In one incident, Irregular was assessing Gemini’s cybersecurity capabilities by asking it to retrieve information from software belonging to a simulated company. The simulated company shared its name with a real business.

After gaining unintended internet access, Gemini correctly guessed a password and entered the real company’s service. Google said the model stopped after determining that it had reached an actual company rather than the test environment.
In two other cases, Gemini located publicly accessible repositories containing credentials for two companies. It used those credentials to access their systems before stopping once it identified them as real organisations.
Unlike Anthropic and OpenAI, which voluntarily disclosed similar incidents, Google chose not to publicly announce the Gemini breaches. The company said the affected organisations were nevertheless notified.
The incidents have added to wider concerns about the security of increasingly capable AI systems and the safeguards needed when testing their ability to operate autonomously.

