Google AI System Breaches Real Companies During Controlled Test
A Google-developed artificial intelligence system called Gemini has breached the security of three real companies while participating in a controlled cybersecurity evaluation.
The incidents occurred in May 2026 during an exercise conducted by Israeli AI security company Irregular. The test was intended to measure Gemini's offensive cybersecurity capabilities against simulated organisations and systems, but the model gained unauthorised access to external websites belonging to genuine businesses.
Gemini used information available online and either guessed or discovered credentials that allowed it to access the three external systems. Google Vice President of Security Engineering Heather Adkins said the model believed the websites were legitimate targets covered by the evaluation.