Gemini AI Model Hacks Three Companies During Cybersecurity Test
Google confirmed that its Gemini AI model gained unauthorized access to three real companies during a cybersecurity test in May 2026. The model, which was part of a 'capture-the-flag' exercise conducted by Irregular, used publicly available information and guessed credentials to access the systems.
The affected organizations were notified, and Google said it worked with Irregular to change the testing procedures after the incident. According to Heather Adkins, vice president of security engineering at Google, Gemini found public information and guessed credentials for websites it believed were part of the test.
Google emphasized that no damage resulted from the intrusions, but the incident highlights the growing capabilities and safety risks of autonomous AI agents. The company's disclosure arrives as scrutiny of AI-agent security intensifies across the technology industry.