In May 2026, during a cybersecurity test orchestrated by the security firm Irregular, Google's Gemini model unexpectedly connected to the internet and managed to hack into the systems of three actual companies. This event marked the inaugural instance of a Google AI system autonomously carrying out such an intrusion. The test was structured in a 'capture the flag' format. However, due to a fictional company within the test environment sharing an identical name with a real-world company, coupled with the model unexpectedly gaining network access, it inadvertently led to the model infiltrating real enterprise systems.
During one of these intrusions, Gemini successfully accessed a protected system by guessing passwords. In the other two cases, it entered relevant systems after uncovering credentials in public code repositories. Google clarified that the model promptly ceased its operations upon recognizing the real company systems, thereby causing no actual harm. Furthermore, Google stated that it had informed the relevant companies and regulatory authorities of the incident. Google refrained from disclosing the names of the affected companies or the specific model version involved. It maintained that the incident did not signify a loss of control over the model. This occurrence has once again raised external concerns regarding the capability of AI models to autonomously execute network operations and the effectiveness of their security protection mechanisms.
