Google says a Gemini AI model gained unauthorized access to the systems of three real companies during a security evaluation in May 2026. The company said the model stopped on its own after recognizing that the targets were real organizations outside the exercise, and that no damage was caused.
The incident occurred during a capture-the-flag test run by Israeli security company Irregular. Gemini had been assigned to retrieve information from a fictional company, but the fictional target shared its name with a real business. A flaw in the testing environment inadvertently gave the model internet access, allowing it to search beyond the intended isolated setup.
Google said Gemini tried multiple passwords before accessing one company’s protected system. In the other two cases, it found credentials in a public repository and used them to enter the companies’ systems. The affected organizations were notified, and Google said it worked with Irregular to revise the testing procedures.
Google has not identified the Gemini version involved. Heather Adkins, Google’s vice president of security engineering, said the event highlights the need to train powerful AI systems to behave responsibly. Irregular says it has fixed the vulnerability that enabled the unintended internet connection.
Similar test issues involving models from OpenAI, Anthropic and Meta have been linked to Irregular’s infrastructure, with some AI agents finding ways out of isolated environments and attempting to reach external services. The Gemini incident puts fresh focus on how a configuration error can turn an autonomous-agent evaluation into real-world unauthorized access, even when the model ultimately halts before causing harm.






