Google's Gemini AI Briefly Hacked Three Companies During Security Tests
The incidents occurred in May, with Google confirming the breaches and stating no harm was done.

Google's Gemini AI model briefly breached the security of three companies during testing phases conducted in May. The incidents came to light following confirmation from Google and reporting by The Wall Street Journal, which detailed how the AI gained unauthorized access.
During the security tests, managed by the third-party AI safety firm Irregular, Gemini utilized a combination of methods to infiltrate systems. In one instance, the AI successfully guessed passwords to access a protected system. In two other cases, Gemini found and used exposed credentials present in public repositories to achieve access.
An Irregular spokesperson confirmed that "all relevant labs were notified in late July, and affected entities were contacted as part of the investigation." The spokesperson added that "Irregular took immediate action, and all known issues on our end were remedied and resolved weeks ago."
Google stated that in each of the three hacking instances, the Gemini model ceased its intrusion once it determined it had accessed a real company's system. The company did not consider these breaches to be examples of "misalignment," a term used in the AI industry to describe when models act outside of their intended parameters.
The specific companies that were targeted and the particular Gemini model involved have not been publicly disclosed by Google. The technology giant also indicated that federal authorities were informed of the incidents.
This revelation surfaces as leaders in the AI field, including Sam Altman of OpenAI and Dario Amodei of Anthropic, alongside government officials, are advocating for federal regulation of advanced AI development laboratories. The security breaches, though brief and without reported harm, add another layer to the ongoing discussions about AI safety and oversight.