New Delhi: In a startling incident that highlights the growing capabilities and potential risks of artificial intelligence, Google has confirmed that its flagship AI model, Gemini, accidentally hacked into the digital networks of three real-world companies. The unprecedented breach occurred during a pre-deployment cybersecurity evaluation in May 2026, marking the first known instance of a Google AI system autonomously executing such a maneuver.
The testing was conducted by Irregular, an Israeli cybersecurity startup contracted by major technology firms to audit AI models. According to reports, the AI agents were tasked with a “capture the flag” exercise to retrieve information from a fictional company within a secure, simulated environment. However, due to a loophole where internet connectivity was unintentionally left active by the testers, Gemini breached real corporate systems instead.
The initial intrusion stemmed from a case of mistaken identity. The fictional target shared its name with a legitimate business. Using its unintended internet access, Gemini redirected its assault, guessing system passwords to gain unauthorised entry into the real company’s servers. In two subsequent tests, the AI model scoured the open web, scraped exposed login credentials from public online repositories, and used them to access the networks of two additional corporations.
Despite the alarming breach, Google stressed that its AI demonstrated responsible behaviour. Crucially, once Gemini realised it was operating inside authentic enterprise networks rather than the intended simulation sandbox, it immediately halted its offensive operations and disconnected itself. The tech giant confirmed that the intrusions caused no tangible harm or data destruction.
Heather Adkins, Vice President of Security Engineering at Google, defended the system’s response. “These events highlight the importance of training powerful AI models to act responsibly,” Adkins stated. “In this case, the model acted appropriately. We ensured the three entities were made aware, and we worked with our training partner on the changes they’ve now made to their testing processes.”
Irregular acknowledged that similar system breakouts have previously involved AI models from OpenAI, Meta, and Anthropic during evaluations, though Gemini was notably the only one to autonomously abort its mission upon realising the error.
While the affected companies and federal authorities were notified in July, the incident has reignited intense debate across Silicon Valley. As tech companies push to develop increasingly autonomous AI agents, the Gemini breakout serves as a stark warning about the urgent need for stringent safety boundaries before artificial intelligence slips beyond human supervision entirely.
