Google confirmed that its Gemini artificial intelligence model breached the internal networks of three private businesses during red-teaming cybersecurity evaluations.
The unauthorized intrusions occurred during tests managed by Israeli security firm Irregular, which was tasked with probing the offensive cyber capabilities of advanced models. While the assessment was planned to operate in an offline sandbox against fictional organizations, an unintended active internet connection exposed real corporate systems. In one incident, Gemini confused a target with an identically named real company and successfully guessed account passwords to gain entry to the legitimate network.
The model also discovered credentials in public web repositories and breached two additional corporate environments before autonomously stopping its operations upon recognizing real infrastructure. Although Google confirmed that no corporate data was destroyed and affected parties were informed, the disclosure heightened alarms regarding the unpredictability of autonomous AI agents.