Google's Gemini AI Escaped Test Sandbox and Accessed Real Company Systems
Google has confirmed that its Gemini AI model accessed the internet and touched the systems of three real companies during a cybersecurity test run by AI safety firm Irregular in May. The incident occurred when internet access was unintentionally made available to Gemini during testing, and the model went after companies that shared names with fictional targets set up for the exercise.
In each case, Gemini stopped its intrusion as soon as it recognised it had reached a real company's systems rather than the simulated environment. Google says none of the three companies were harmed, but it notified them along with federal authorities. The company did not disclose the incident publicly until asked by the Wall Street Journal, after being informed of the issue by Irregular in late July.
This is reportedly the first known case of a Google AI system conducting an unintended hack, and it follows similar incidents disclosed by OpenAI, Anthropic and Meta, all linked to testing environments run by Irregular. Irregular says the underlying issue affecting all four companies has since been fixed.