Google's Gemini AI Model Accidentally Hacks Three Companies During Test
Google has revealed that its Gemini AI model accidentally gained unauthorized access to three other companies during a cybersecurity test in May. The test, conducted with security firm Irregular, was intended to have the model obtain data from fictional companies.
However, due to a configuration problem, the model was able to connect to the internet and guess or find credentials to enter the systems of the affected entities. Heather Adkins, Google's vice president for security engineering, stated that the model believed the systems were part of the test and ceased activity immediately after obtaining access.
The incident has raised concerns about the cybersecurity risks posed by advanced AI agents, which can independently perform multi-step tasks. While Google did not initially disclose the incidents publicly due to the fact that the model did not cause any damage, the company has since notified the affected entities and worked with Irregular on changes to its testing process.