Google's Gemini AI Breached Three Companies During Security Tests
Google has disclosed that its Gemini artificial intelligence assistant inadvertently breached the networks of three real companies during security testing in May. The AI model was intended to attack a fictional company as part of a cybersecurity assessment but gained accidental internet access. Because the fictional company shared a name with a real one, Gemini began attempting to penetrate the actual company's network using passwords found online or guessed.
Google stated that Gemini identified the error upon successfully accessing the real company's systems and halted the attacks on its own initiative. The company assured that no damage was caused to the affected firms. The incident occurred during tests conducted in collaboration with Irregular, an Israeli cybersecurity startup that evaluates AI models for tech companies before public release.
Similar incidents involving unauthorized internet access by AI models have been reported this year with systems from OpenAI, Anthropic, and Meta, also during tests performed by Irregular. The Israeli startup confirmed in a blog post last month that the vulnerability allowing models internet access has been fixed, and relevant labs were updated, with affected parties notified.
Heather Adkins, Google's VP of Security Engineering, emphasized the importance of training powerful AI models to operate responsibly. She added that Google worked with its partners on changes to their testing processes following the breaches. These events have reignited the debate surrounding AI safety and the potential for advanced AI to become uncontrollable, with figures like Anthropic CEO Dario Amodei calling for a slowdown in development, while Nvidia CEO Jensen Huang advocates for continued rapid progress.
The same event, reported separately by each outlet. Open a few to compare what different newsrooms emphasize — and what they leave out.
Not the same event — other stories that share this one’s people, places, or theme: background, reactions, and follow-ups.