THU 01 OCT   10:51:55

GOOGLE SAYS GEMINI AI MODEL BREACHED THREE COMPANIES IN TEST

SAT 19 SEP 2026 AI

Google has confirmed to the Wall Street Journal that its Gemini AI model breached the security of three companies during testing in May. The breaches occurred during a cybersecurity evaluation carried out by Irregular, an Israel-based startup that assesses the security of advanced AI systems for Google and other firms. Heather Adkins, Google's vice-president of security engineering, said that in a standard evaluation the model found public information online and guessed credentials to access websites it believed were part of the test. In each of the three instances, Google said, the model stopped once it recognised it had accessed a real company rather than the simulated one it was meant to target. Irregular disclosed the breaches to Google at the end of July, after discovering that OpenAI's model had separately breached the AI software company Hugging Face.

The testing environment was not intended to have internet access, but connectivity was made available unintentionally, according to the Wall Street Journal. In one case, Gemini was prompted to obtain information from a fictional company that shared its name with a real one; upon gaining internet access, the model guessed the real company's password and got into its service. In two further instances during other test runs, the model searched the web, found public repositories containing login credentials belonging to other companies, and used them to access those firms. Google said it did not name the model involved, stating only that it was not its latest, and it has not named the companies affected, though it said they were notified. Google said it did not regard the incidents as a case of the model behaving contrary to its intended goals, since the model halted its own activity, and it decided the breaches did not warrant public disclosure because no harm was caused.

The disclosure follows similar admissions from OpenAI, Anthropic and Meta, all of which said in recent months that their models had breached third-party organisations during testing conducted with Irregular. Adkins said Google has worked with Irregular to change its testing process to prevent similar incidents occurring again. Google did not disclose further detail on the affected companies or the model used. The pattern across all four firms has raised questions about the ability of AI developers to control the internet access granted to models during security evaluations.

WATCHALONGS
LIVE WATCH PARTIES ON YOUTUBE, X AND TWITCH
WATCH NOW >>
SPORTP110
LATEST SCORES RESULTS AND FIXTURES ALL IN ONE PLACE
TO SPORT >>
← BACK