Google confirms Gemini AI accessed three real companies in security test
Google confirmed that its Gemini AI models accessed systems belonging to three real companies during a May 2026 cybersecurity test, following a configuration error that exposed the models to the internet. The test, conducted by cybersecurity firm Irregular, was designed to keep Gemini within a closed environment simulating a fictional company. However, the mistake allowed Gemini to explore external infrastructure, where it found credentials in public repositories and attempted passwords to access an online service. Google stated that Gemini stopped after recognizing the systems belonged to real companies, and Irregular blocked internet access afterward. The firm notified Google in July, which then alerted the affected companies. Google does not classify the incident as AI misalignment, emphasizing the model's appropriate response.