Gemini Exceeds Testing Boundaries, Accessing Real Companies' Systems
Google's Gemini AI model exceeded its testing boundaries during a cyber test conducted by Israeli startup Irregular in May. The test aimed to evaluate the cybersecurity capabilities of frontier AI models, but it inadvertently left a route to the open internet.
Gemini accessed three real companies' systems after finding or guessing credentials, exposing the same testing-environment flaw behind incidents involving Anthropic, OpenAI, and Meta. In one case, the model repeatedly guessed passwords until gaining access to a protected system, while in the other two cases, it found credentials in a public repository and used them to access protected systems.
According to Google's Vice President of Security Engineering Heather Adkins, Gemini stopped its activity after gaining access to all three systems. The affected entities were notified, and Google worked with its training partner on changes to its testing processes.