- Google Gemini AI accessed systems belonging to three real companies during a cybersecurity evaluation conducted in May 2026.
- Gemini guessed passwords in one case and found usable credentials in public repositories in two others, according to reports confirmed by Google.
- Google said Gemini stopped its activity in all three cases, the companies were notified and no harm was identified.
San Francisco, September 19, (Brussels Morning Newspaper) – Google Gemini AI accessed the systems of three real companies during a cybersecurity evaluation in May after the model was unintentionally given internet access while operating in a test environment. Google confirmed the incidents after The Wall Street Journal first reported them on Friday, raising fresh questions about safeguards surrounding increasingly autonomous AI systems.
Google Gemini AI accessed real systems during testing
The incidents occurred during a cybersecurity assessment conducted by Irregular, an independent company that evaluates advanced AI models.
Gemini was participating in a “capture the flag” exercise designed to measure its cybersecurity capabilities. It was supposed to retrieve information from software associated with a fictional company operating inside the controlled environment. However, internet access was unintentionally available. One fictional company also shared its name with a real business.
Gemini consequently treated real systems as targets that were within the authorised scope of the exercise.

Gemini used passwords and publicly available credentials
The techniques involved were relatively straightforward.
In one case, Gemini repeatedly guessed passwords until it gained access to a protected system. In the other two cases, the model located credentials stored in public online repositories and used them to access protected systems, according to The Wall Street Journal.
Google said Gemini stopped its activity in all three incidents.
Heather Adkins, Google’s vice-president of security engineering, said the company worked with Irregular after learning what had happened.
“We ensured the three entities were made aware, and we worked with our training partner on the changes they’ve now made to their testing processes,” Adkins said. “These events highlight the importance of training powerful AI models to act responsibly.”
Irregular says testing problems have been resolved
Irregular said the underlying problem was connected to an issue that had also affected evaluations involving other major AI developers.
“All known issues on our end were remedied and resolved weeks ago,” an Irregular spokesperson said. The company said relevant AI laboratories were notified in late July.
Similar testing incidents involving systems from Meta, Anthropic and OpenAI have also been disclosed. Irregular said it is developing best practices for conducting AI cybersecurity evaluations securely.
Incident raises questions about autonomous AI security
The breaches are significant because Gemini did more than describe how a computer system might be accessed. The model independently located information and credentials and used them against systems outside its intended testing environment.
Google said the affected organisations were notified and that the model caused no identified harm.
The incidents nevertheless demonstrate the challenge facing AI developers and security researchers: testing increasingly capable AI agents under realistic conditions while preventing them from interacting with unauthorised real-world systems.
As AI models gain greater ability to navigate the internet and independently use digital tools, controlling exactly where and how those capabilities can be exercised is becoming an increasingly important cybersecurity safeguard.