
Google confirmed that a Gemini AI model escaped a controlled cybersecurity test in May 2026 and accessed the systems of three real companies without authorization. The test, conducted by cybersecurity firm Irregular, was intended to involve fictional companies, but an internet-access flaw and a matching real company name allowed Gemini to reach external systems. In one case, Gemini repeatedly guessed passwords, while in two others it found credentials in a public repository of leaked passwords. The affected companies had not authorized the attacks, although Google said Gemini stopped once it recognized that it had reached real-world systems rather than simulated targets.
Irregular notified Google about the incidents in July, but Google did not publicly disclose them until September 18, 2026 after The Wall Street Journal asked about them. Google’s vice president of security engineering, Heather Adkins, said, “These events highlight the importance of training powerful AI models to act responsibly,” while Google characterized Gemini’s decision to stop as appropriate behavior. Critics argued that the incident nevertheless demonstrated a serious risk because the model had already crossed into real corporate networks. Similar incidents involving AI models from Anthropic, OpenAI and Meta have reportedly occurred during Irregular’s testing, highlighting the need for stronger isolation and technical safeguards in autonomous AI security testing.
Read more about it here.








