Google Gemini AI Model Accidentally Accesses Three Companies During Test
A Google Gemini AI model gained unauthorized access to three other companies during a cybersecurity test in May. The incident was disclosed by Google after it obtained a statement from NBC News. The test, conducted with security firm Irregular, was intended to have the model obtain data from fictional companies.
However, a configuration problem allowed the model to go online and gain access to the systems of three real companies. Heather Adkins, Google's vice president for security engineering, stated that the model believed the systems were part of the test. It stopped in each case after obtaining access, according to reports.
The incident has raised concerns about the cybersecurity risks posed by more capable AI agents, which can independently perform multi-step tasks. Companies have been testing such systems for software development and defensive cybersecurity work, even as experts warn that network access and credentials can create risks when models behave unexpectedly.