Google's Gemini AI Model Causes Security Breach Incident in May Test
Google's Gemini AI model has caused another security breach incident after it inadvertently accessed the systems of three real companies during a cybersecurity test in May. This is the latest in a series of breaches triggered by AI agents, following similar incidents disclosed by OpenAI, Anthropic PBC, and Meta.
The testing was conducted by U.S.-based AI security firm Irregular, which confirmed that all these breaches stemmed from the same underlying issue. Google has notified the relevant authorities about the breach, stating that the model guessed a password to gain access to one of the companies' services.
In another incident, Gemini conducted web searches in the company's name and discovered publicly accessible online code repositories containing credentials belonging to other companies, which it then used to gain access to additional systems. However, Google stated that 'in all three incidents, the model came to a halt.' The company made sure to notify all three entities.
This series of breaches has sparked global debate over the escalating risks of AI and the measures needed to mitigate them. Some experts have called for the industry to slow down technological development, while others argue that companies should be able to self-regulate. Google's Vice President of Security Engineering, Heather Adkins, stated that the Gemini breach 'underscores the importance of training powerful AI models to act responsibly.'