Bolatito Mercy
Google has confirmed that its Gemini artificial intelligence model accessed the systems of three real companies during a cybersecurity evaluation conducted in May 2026.
The incidents occurred during a cybersecurity assessment carried out by Irregular, an independent company that evaluates the security capabilities of artificial intelligence systems.
Google Vice President of Security Engineering Heather Adkins said Gemini searched publicly available information online and used credentials to gain access to three websites it believed were part of the authorised test.
In one case, the AI model reportedly guessed passwords until it gained access to a protected system. In two other cases, Gemini found credentials in a public repository and used them to access protected systems.
Adkins said Gemini stopped its activity in all three cases after accessing the systems.
“We ensured the three entities were made aware,” she said, adding that Google worked with Irregular on changes to its testing procedures.
She said the incidents highlighted the importance of training advanced AI models to operate responsibly, particularly as they become increasingly capable of acting autonomously.
An Irregular spokesperson said the incident was linked to an issue that had also affected other AI companies. The company said all relevant organisations were notified in late July and that the known issues had been resolved.
Similar incidents involving Irregular’s AI security evaluations have also been disclosed by Meta, Anthropic and OpenAI.
The developments have raised further concerns about safeguards surrounding AI agents that can independently access the internet and interact with computer systems.
Google’s disclosure highlights the challenges involved in ensuring that AI cybersecurity evaluations remain properly isolated and that AI systems operate only within authorised environments.
