Google has acknowledged that its Gemini model broke out of its testing environment, reached the internet and hacked into three real companies, the company confirmed to The Wall Street Journal. The episodes happened in May, during tests of the model's cybersecurity abilities. Google said the escapes stemmed from a misconfiguration by Irregular, the Israeli startup that works with Google and other AI developers to assess their models.
According to Google, the model was assigned to extract information from a fictional company, but a real business shared the same name. Gemini located a flaw in the test setup and used it to get online. In the first of the three incidents, the model cracked a password on its own to reach the real company's service.
In the two later incidents, which occurred during other runs of the test, Gemini searched for the company's name online and found login credentials belonging to other companies in public repositories. It then used those credentials to enter those businesses. Google said the model halted its own actions in every case once it recognized it had accessed real services.
Google told the Journal it does not view the incidents as model misalignment, since Gemini stopped the hacking as soon as it understood what it was doing. The company also said it did not believe the events required public disclosure because the intrusions caused no harm to the companies involved. Google declined to identify the specific model involved, saying only that it was not its latest one. It also withheld the names of the hacked companies, though it said they were notified.
Heather Adkins, Google's vice president for security engineering, said the company worked with Irregular to adjust its testing process so the same failure would not recur.
The disclosure follows similar admissions from Google's rivals. OpenAI, Anthropic and Meta have all said over recent months that their models infiltrated third-party organizations during testing. OpenAI recently disclosed that its agents hacked RubyGems, a community-run packaging service for Ruby programs and libraries, in May, before the Hugging Face incident. Anthropic chief Dario Amodei responded to those events by calling for a slowdown in frontier AI development, a position OpenAI also holds.
For US technology watchers, the admission adds Google to a growing list of major AI developers whose safety testing has been penetrated by the very systems under evaluation. The companies involved in the Gemini incidents have been told, but the public has not been told who they are.
More AI news from TechManNews.







