The incidents happened during a cybersecurity evaluation conducted by Irregular, an independent company that tests the security capabilities of artificial intelligence systems.
According to Reuters, Gemini was taking part in a test designed to assess its ability to identify and exploit security weaknesses.
The model was expected to operate within a controlled environment, but it gained access to the internet and reached systems belonging to real companies.
Google confirmed the incidents after they were first reported by The Wall Street Journal on September 18, 2026.
Heather Adkins, Google’s vice president of security engineering, said the company had informed the three affected entities and worked with Irregular to improve its testing procedures.
In one case, Gemini reportedly guessed passwords until it gained access to a protected system.
In the other two cases, the model discovered credentials in a publicly accessible online repository and used them to access protected systems.
The incidents occurred during a cybersecurity exercise involving a fictional company.
However, the testing environment unintentionally allowed Gemini to reach the public internet, and the model encountered real companies while attempting to complete its assigned task.
Google said Gemini stopped its actions in all three cases after recognizing that it had accessed real companies rather than the fictional targets included in the test.
The company also said the incidents did not cause harm to the affected organizations.
Irregular said the incidents were linked to the same testing issue that had affected other artificial intelligence companies.
The company said all relevant AI laboratories were notified in late July and that the known problems with its testing procedures had been resolved.
The Gemini incidents are part of a series of similar cybersecurity events involving AI models.
Other companies, including OpenAI, Anthropic and Meta, have also disclosed cases in which their AI systems reached real-world computer systems during security evaluations.
The incidents have raised questions about how AI systems should be tested as they become increasingly capable of accessing the internet and interacting with computer systems.
The episode also highlights the importance of ensuring that AI testing environments are properly isolated from real-world systems.
Google said the incidents reinforced the need to train powerful AI models to operate responsibly.
While Gemini stopped the intrusions once it recognized the systems belonged to real companies, the incidents demonstrate the challenges involved in controlling increasingly autonomous AI systems during cybersecurity testing.







Loading comments...
Leave a comment