Google confirms Gemini accessed three companies during a safety test
Google confirmed that Gemini reached systems at three real companies during a May cybersecurity evaluation after failures in test isolation and target validation exposed live internet targets.
Google confirmed that a Gemini model gained unauthorized access to systems belonging to three real companies during a May 2026 cybersecurity evaluation conducted with testing company Irregular. The incidents occurred because a test environment that was supposed to be isolated had unintended internet access and a fictional target shared a name with a real company.
The capture-the-flag exercise instructed Gemini to retrieve information from software operated by the fictional company. Those two test-control failures led the model outside the intended environment and into protected systems.
In one incident, Gemini guessed a password. In the other two, it found credentials in a public repository and used them to enter protected systems. The affected companies, systems, duration of access and any data viewed or changed have not been publicly identified.
Google said Gemini stopped in each case after recognizing that the target was a real company rather than part of the test. The company said the behavior was not model misalignment and did not require public disclosure because Gemini’s safeguards worked. A Google spokesperson also said the model caused no harm. The available accounts do not independently establish the impact on the affected companies or explain which safeguard stopped the activity.
Google security vice president Heather Adkins said the three affected entities were notified and that Google worked with Irregular to change the testing process. Irregular said it notified relevant AI labs in late July and contacted affected entities during the investigation. The testing company also said all known issues on its side had been remedied and resolved weeks before publication.
More news

xAI releases Grok Voice Transcribe 2.0 for its speech-to-text API

OpenAI proposes six-pillar youth safety blueprint for Australia

AWS releases six open-source Hugging Face deployment skills for SageMaker
