Google's Gemini AI breached 3 companies in security test
Google confirmed Friday that its Gemini AI model breached the computer systems of three real companies during a cybersecurity test in May, though it found no evidence of damage. The incidents occurred during a security evaluation by Israel-based startup Irregular. Gemini was participating in a "capture the flag" exercise meant to test its abilities in a closed environment, but an unintended internet connection allowed it to access real-world systems. In one case, it accessed a real company matching a fictional name; in two others, it used publicly exposed credentials to gain entry. Google said the model stopped its activity in all instances. The affected companies were notified, and Google said public disclosure wasn't required since no harm occurred. The incident highlights challenges in AI development as models gain autonomy, with similar issues reported involving OpenAI and Anthropic models. It comes amid renewed debate over AI safety risks.