New Delhi: Google’s Gemini AI model accessed the systems of three real companies during a cybersecurity test in May, but stopped its activity after recognising that the targets were real organisations rather than part of the simulated exercise, the company has confirmed.

The incidents occurred during a cybersecurity evaluation conducted by AI security firm Irregular. According to Google’s account, Gemini was operating in a test environment designed to assess its ability to retrieve information from a fictional company. However, the test environment unintentionally allowed the model to access the internet, creating a path to real-world systems.

The disclosure marks the first known instance of a Google AI model autonomously accessing the systems of real companies during such a test.

How Gemini accessed the three companies

The cybersecurity exercise was structured as a “capture the flag” test, in which Gemini was asked to obtain information from software belonging to a fictional company.

The fictional company happened to have the same name as a real company. Because internet access was unintentionally available in the testing environment, Gemini was able to look beyond the simulated systems.

In one case, the model reportedly guessed passwords until it gained access to a protected system belonging to a real company.

In two other cases, Gemini searched the web and found credentials stored in publicly accessible online repositories. It then used those credentials to access protected systems belonging to two other companies.

The names of the three companies have not been disclosed.

Gemini stopped after identifying the real targets

Google said the significant difference in its case was what happened after the model gained access.

According to Heather Adkins, Google’s vice-president of security engineering, Gemini stopped its activity in all three instances after determining that it had reached real companies rather than the fictional targets in the test.

Google said the model’s behaviour did not result in damage to the affected companies. The three organisations were informed about the incidents, and federal authorities were also notified, according to reports.

Adkins said the incidents highlighted the importance of training powerful AI models to behave responsibly, adding that the model had acted appropriately by stopping the activity.

Why Google did not disclose the incidents earlier

Irregular notified Google about the incidents in July. However, Google did not publicly disclose them at the time.

The company told the Wall Street Journal that it did not initially believe the incidents required public disclosure because Gemini had stopped the intrusions on its own and no harm had been caused.

Google also characterised the episode as being closer to a vulnerability or bug-bounty-style discovery than a harmful breach, although security researchers have pointed to the broader significance of an AI system independently reaching real-world targets.

Google has not identified the three companies involved and has not specified which Gemini model was used. Reports indicate that the incidents involved an older model rather than Google’s newest Gemini system.

Testing error allowed internet access

A key factor in the incidents was an error in the testing setup.

Gemini was not supposed to have access to the open internet during the exercise. Irregular said internet access was unintentionally made available, allowing the model to move beyond the intended testing environment.

The incident therefore involved both the model’s autonomous actions and a failure in the safeguards surrounding the test environment.

Irregular said the same security issues had been involved in other AI testing incidents and that all known issues on its side had been addressed. The company said relevant AI laboratories were notified in late July and that changes had been made to its testing processes.

Similar AI incidents have raised safety concerns

The Gemini incidents follow disclosures involving AI models developed by other leading technology companies.

Irregular has also been linked to cybersecurity testing that resulted in models from OpenAI, Anthropic and Meta accessing real-world systems. The circumstances varied between the incidents, including cases in which models did not recognise that they had reached real organisations.

In the Gemini case, Google said the model recognised the mistake and stopped. That distinction has become part of the discussion around how AI agents should behave when they have access to tools, credentials and external networks.

The incidents have intensified debate among AI researchers and security specialists about safeguards for increasingly autonomous systems. The central concern is not only whether an AI model can perform cybersecurity tasks, but also whether it can reliably distinguish authorised testing environments from real-world targets.

Google says testing safeguards are being improved

Google said it worked with Irregular on changes to its testing processes after the incidents were identified.

The company has also stressed the importance of developing AI systems that can operate responsibly when given access to external tools and information.

For now, the three companies affected by the Gemini incidents remain unnamed, and no public technical report detailing the systems involved has been released. The episode nevertheless adds to the growing record of AI models unexpectedly crossing the boundaries of controlled cybersecurity tests and interacting with real-world systems.