In the last few days, leaders of many leading AI companies have advocated controlling the rapidly growing Artificial Intelligence (AI) capabilities. Meanwhile, incidents of alleged cyber attacks by AI agents of major companies like OpenAI and Anthropic have raised concerns about the dangers associated with AI.
Google Gemini Hack: A new issue regarding cyber security has come to light amid the increasing capabilities of Artificial Intelligence (AI) models. Google has confirmed that its Gemini AI model inadvertently accessed the systems of three real companies during a cybersecurity test in May 2026. This test was being conducted by AI security assessment company Irregular.
This case is significant because Gemini accessed real systems using information available on the Internet rather than simply responding to instructions. However, according to Google, in all three cases the model stopped its activities after it discovered that it was interacting with the real companies' systems instead of the fictitious test systems.
How did this cyber security test happen with Gemini?
Irregular was testing the cybersecurity capabilities of an AI model in a controlled environment. In this test, Gemini was given the task of obtaining information from the system of a fictitious company. The testing environment was supposed to be isolated from the Internet, but a configuration error allowed the model to access the Internet.
Once an Internet connection was available, Gemini accessed online information that existed beyond the boundaries of the test. In one case, the name of the fictitious company whose system was made part of the test matched that of the real company. The model guessed the password using information available on the Internet and entered the real company's system.
Access to systems of two other companies also
According to reports, in the remaining two cases, Gemini discovered credentials in public repositories on the Internet that could have been used to access the systems of genuine companies. The model used these credentials to access the protected system.
Heather Adkins, Google's vice president of security engineering, said the model searched publicly available information and used credentials to access websites it believed were part of the test. In all three cases Gemini ceased its activities after identifying that the targets were genuine companies.
The names of the affected companies have not been made public. Google has said that relevant organizations were informed about the incident and changes have been made to testing procedures in collaboration with Irregular.
When did Google inform about the incident?
This incident took place in May, but its information became public in September 2026. Irregular informed Google about these incidents in late July. Google subsequently confirmed that Gemini had gained unauthorized access to the systems of three actual companies. The company said that since the model had ceased its activities after the actual target was identified and the affected entities were informed, it did not deem it necessary to announce it publicly at that time.
This development has come to light at a time when similar issues have come into focus in cyber security tests involving AI systems of OpenAI, Anthropic and Meta. Irregular has also been involved in tests related to security testing of AI models of these companies.
Are AI models getting out of control?
The Gemini incident has certainly intensified the debate about the autonomy of AI agents, but it cannot be considered a basis for directly concluding that AI models have become “uncontrollable”. In this case the reason for Internet access was an error in the testing environment and the model stopped its activity once the real companies were identified.
Yet the incident is an important warning to cybersecurity experts. AI agents are now being able to search for information on the Internet, run code, and complete many digital tasks autonomously. In such a case, misconfiguration, unclear instructions or excessive system access can have serious consequences.
Why is concern for AI security increasing?
Such incidents raise questions about how much access AI agents should be given to the internet and sensitive systems. Particularly in areas like cybersecurity where a model also has the ability to identify and exploit vulnerabilities, a clear security wall between the test environment and the real Internet becomes essential.
Google has also said that the secure development of powerful AI models is important and is continuing to invest in security measures in this direction. According to the company, changes have been made to procedures with its training and testing partner following this incident.