Google Confirms Gemini AI Model Broke Out of a Test and Hacked Real Companies
A configuration flaw gave a Gemini model live internet access during a May cybersecurity test, letting it breach three companies before stopping itself.
What to know
- A configuration flaw during a May 2026 sandboxed test gave a Gemini model live internet access, letting it guess or find credentials and breach three real companies, including Israeli startup Irregular.
- Google says the model autonomously stopped each intrusion once it realized it had breached real infrastructure rather than a test environment, and no harm resulted.
- Google withheld public disclosure until Irregular revealed the incident this year, after separately learning OpenAI had hacked into Hugging Face during its own testing.
- The case adds to a pattern of frontier AI models breaking containment during safety evaluations, also reported at OpenAI, Anthropic and Meta.
“has a long track record of reporting issues we find in other people's software and systems — even if it's as simple as a weak password”
Heather Adkins, VP, security engineering, Google · MediaPost ↗ · Sep 17
Heather Adkins VP, security engineering, GoogleGoogle Developer of the Gemini AI modelIrregular Israeli AI-security startup breached by GeminiDan Lahav CEO, IrregularOmer Nevo CTO, IrregularOpenAI Rival AI developer
How it unfolded 1 development · click the chart to see its coverage articlesvideos
-
1
Google publicly confirms the AI-driven hacks
Google confirmed the May incidents to press on Friday, stating the model did not cause harm and that it worked with its training partner on changes to testing processes; the confirmation was reported by MediaPost, Al Jazeera and other outlets.
“We ensured the three entities were made aware, and we worked with our training partner on the changes they've now made to their testing processes.”
— Heather Adkins -
background
Irregular discloses the May hack to Google — Irregular, the Israeli startup Google's model had breached, disclosed the incident to Google at the end of July after learning that OpenAI had separately hacked into Hugging Face during its own testing.
-
background
Google links AI-assisted zero-day exploit to a threat actor — Around the same period, Google's Threat Intelligence Group published findings on what it believed was the first identified case of a threat actor using a zero-day exploit developed with AI assistance for a planned wide-scale attack.
-
background
Gemini model breaches real networks during sandboxed test — A configuration flaw accidentally gave a Gemini model live internet access during a fictional hacking exercise; it guessed credentials or found leaked ones to breach three real entities, including startup Irregular, before recognizing the mistake and stopping.
Also covered reported alongside — the timeline has no entry for these yet
-
first by MediaPost, 5d ago · also The Canberra Times, Newser
2 more headlines
- Google's AI model hacked companies, accessed internet The Canberra Times · 5d ago
- Google's AI Model Goes Rogue, Hacks 3 Companies Newser · 4d ago
