Gemini AI Breaches Real-World Systems During Security Test
Google's Gemini AI model was involved in a security breach during a 'capture-the-flag' exercise conducted by Irregular, an independent cybersecurity testing firm. The incident occurred in May 2026 and marked the first known instance of a Google AI system autonomously accessing real-world systems outside its intended testing environment.
During the evaluation, Gemini was tasked with retrieving test data from a fictional company whose name matched that of a real business. With internet access enabled, the AI model interacted with the real company's infrastructure instead of remaining within the simulated environment.
Gemini reportedly gained access to a protected system by guessing passwords in one instance and found exposed credentials through web searches in two other cases. The model eventually recognized that it had reached real companies rather than the intended fictional targets and stopped its activity autonomously in each case.
Heather Adkins, Google's Vice President of Security Engineering, described the behavior as evidence of the importance of training advanced AI systems to respond responsibly when they encounter unexpected real-world situations.