September 21, 2026, 12:20 pm | Read time: 2 minutes
A planned security test took an unexpected turn for Google. The AI model Gemini accessed real company systems, but the incident only became public months later.
Gemini was supposed to retrieve data from the software of a fictional company as part of a cybersecurity test. However, the simulation by the Israeli security provider Irregular did not go as planned. Due to a misconfiguration, the AI model gained access to the open internet and was able to access real systems.
Also of interest: AI Steals Company Data on Its Own for the First Time
Overall, Gemini reportedly accessed the systems of three companies. In one case, the fictional test company happened to have the same name as a real company. The AI is said to have guessed passwords until access was possible. In two other cases, Gemini used publicly available credentials from code repositories to gain access to company systems.
Gemini Ended the Accesses Independently
According to Google, Gemini recognized in all three cases that the activities were taking place outside the intended test environment. The model then ended the access and exited the affected systems. The company stated that no harm was done to the companies.
Heather Adkins, vice president of security engineering at Google, interpreted the behavior as evidence that the AI acted responsibly. Critics, however, view the incident much more skeptically. For them, the case shows that powerful AI systems can independently perform actions in unexpected situations that are actually outside their intended scope.
Experts Criticize Google’s Handling of the Incident
It is particularly controversial that Google did not make the incident public. The affected companies and authorities were informed, but the public only learned about it after the “Wall Street Journal” inquired with the company. Google justified its approach by stating that no harm was done and that the incident resembled a bug bounty program.
Security experts disagree with this assessment. Jack Cable from the security company Corridor stated, according to reports, that AI models reaching real systems outside their intended boundaries pose a security problem of their own. Similar incidents have previously occurred at OpenAI and Anthropic. Both companies, however, made such incidents public. The discussion about how AI systems should be controlled and monitored is likely to gain further importance due to the current case.