Google's Gemini AI breached three companies' security during test

theguardian.com

Google confirmed its Gemini AI model breached the security of three other companies in May during a cybersecurity evaluation by AI-security firm Irregular, marking the first such incident for the company. The hacks occurred when the model unintentionally gained internet access during testing. Irregular, an Israel-based startup, was testing Gemini in a closed environment with fake companies, but internet access was mistakenly enabled, allowing the model to access real firms. In one case, Gemini guessed a password for a real company sharing a name with a simulated one; in two others, it found public repositories with credentials, stopping once it realized the targets were real. Google did not publicly disclose the breaches, unlike OpenAI and Anthropic, which voluntarily reported similar hacks, but said it informed the affected companies. The incidents follow recent OpenAI and Anthropic breaches, prompting Senator Bernie Sanders to call for a pause in AI development over concerns about controlling powerful models.


With a significance score of 5.4, this news ranks in the top 1% of today's 32136 analyzed articles.

Get summaries of news with significance over 5.5 (usually ~10 stories per week). Read by 10,000+ subscribers: