United States, September 21, 2026 — Google’s Gemini artificial intelligence model accessed the systems of three real companies during a cybersecurity evaluation in May, marking the first publicly known case of a Google AI system autonomously carrying out such actions.
The incidents occurred during a test conducted by Irregular, an independent company that evaluates the security of advanced AI systems. Gemini was instructed to retrieve information from software belonging to a fictional company as part of a cybersecurity exercise.
According to Google, the model unexpectedly had access to the internet during the evaluation. It then found publicly available information and used or guessed credentials to access websites it believed were part of the test.
In one case, Gemini repeatedly guessed passwords until it gained access to a protected system. In two other cases, it found credentials in public repositories and used them to access systems belonging to real companies.
Heather Adkins, Google’s vice president of security engineering, said the model stopped in all three cases after determining that it had accessed real companies rather than the fictional systems involved in the test.






