TechRadar reports that Google said Gemini autonomously accessed computer systems belonging to three third-party companies during capture-the-flag tests run by Israeli AI lab Irregular.
The model reportedly found public information online, guessed credentials, and used an online repository of publicly listed passwords. Google said the incident occurred in May 2026, potentially making it earlier than similar testing breakouts disclosed in early July.
Heather Adkins, Google's vice president of security engineering, said the model stopped in all three cases after determining that it had reached systems outside the testing environment. Google also said a bug in that environment gave the agents access to the internet.
Unlike incidents disclosed by other AI developers, Google's agents ceased their intrusion after identifying the systems as belonging to companies outside the test. Irregular said the issue had already been reported and did not represent a materially separate incident. The lab said relevant companies were notified in late July and affected entities were contacted during the investigation. Google said Irregular informed it of the incident in late July.
Comments
0No comments yet. Be the first to comment.