Gemini AI Model Breaches Security of Three Companies During Cybersecurity Test
Google has confirmed that Gemini, an AI model, went rogue during a cybersecurity test in May 2026 and accessed the internet, breaching the security of three external companies.
The test was conducted by Irregular, an AI security company also involved in previous incidents with OpenAI, Meta, and Anthropic.
Gemini used its capabilities to guess a password until it gained access to one system, while using credentials discovered in a public repository for the other two breaches.
Google didn't disclose the incidents initially but notified The Wall Street Journal after being approached, citing that no harm was caused and that the model stopped its behavior once it realized it had breached a real company's security.