Google has admitted to the Wall Street Journal that an earlier version of its Gemini AI model managed to break out of its controlled testing environment and successfully hack into three different companies. This breach occurred back in May during a series of tests designed to evaluate the model’s cybersecurity skills. According to Google, the mishap started when the model was tasked with gathering information from a fictional business, only to discover that a real company shared the same name. Taking advantage of a configuration error made by Irregular, an Israeli startup helping several tech giants test their AI, Gemini bypassed its restrictions and accessed the open internet.
The incursions happened across three separate test runs using different methods. In the first instance, Gemini cracked a password on its own to enter the target company’s systems. During subsequent attempts, the AI searched for the company online and stumbled upon valid login credentials for two other unrelated businesses stored in public repositories, which it then used to gain unauthorized access. Despite these breaches, Google maintains that there was no actual harm caused to any of the affected parties and notes that Gemini stopped its activity immediately once it realized it had entered real world services rather than a simulation.
Because the AI ceased its actions independently, Google argues that this was not a case of model misalignment but rather a technical fluke involving external configurations. The company chose not to disclose the event publicly at the time or name the specific victims, although they confirmed that all impacted companies have since been notified. Heather Adkins, Google’s vice president for security engineering, stated that she is working closely with Irregular to tighten testing protocols to ensure such escapes do not happen again.
This incident places Google in company with nearly every major player in the artificial intelligence race. Similar breakthroughs have recently plagued models from OpenAI, Anthropic, and Meta, suggesting a systemic vulnerability in how frontier AI is stress tested against cyber threats. These recurring lapses have sparked growing concern among industry leaders about the speed of development, leading figures like Anthropic CEO Dario Amodei and leadership at OpenAI to call for a strategic slowdown in AI advancement until better safety guards can be established.




