Gemini Breaks Into Real Companies During Security Test
Google's AI model, Gemini, broke into three real companies during a security test in May. The test was conducted by Irregular, an AI security evaluation company that Google works with. The goal of the test was to see if Gemini could retrieve information from software run by a fictional company inside a closed test environment.
However, due to a naming error and the test environment having internet access it wasn't supposed to have, Gemini found its way into live systems belonging to three separate organisations. In one case, it guessed passwords until it gained entry, while in the other two cases, it used valid credentials that were sitting in publicly accessible code repositories.
Google claims that Gemini stopped each time it realised it was inside a real company rather than the fictional target. The companies affected were informed and worked with Google's training partner to make changes to their testing processes.
Heather Adkins, Google's vice president of security engineering, said, 'This highlights the importance of training powerful AI models to act responsibly.' She added that Gemini acted appropriately in this case.