A Google Gemini AI model gained unauthorized access to three other companies during a cybersecurity test, according to reports.
Google disclosed the incident — which happened in May — in a statement obtained by NBC News. The test, conducted with security firm Irregular, was intended to have the model obtain data from fictional companies.
According to reports, the model was not supposed to have internet access, but a configuration problem allowed it online. Once connected, it guessed or found credentials to enter the systems.
Heather Adkins, who is Google’s vice president for security engineering, said the model believed the systems were part of the test, per NBC News. She said it stopped in each case after obtaining access, the media outlet noted.
Google reportedly said it notified the affected entities and worked with Irregular on changes to its testing process. The company did not initially disclose the incidents publicly because the model did not damage the systems and ceased activity immediately, according to reports.
The incident has renewed questions about the cybersecurity risks posed by more capable AI agents, which can independently perform multi-step tasks. Companies have increasingly been testing such systems for software development and defensive cybersecurity work, even as experts warn that network access and credentials can create risks when models behave unexpectedly.
