Google has confirmed that its artificial intelligence model Gemini gained unauthorized access to computer systems belonging to three real companies during a cybersecurity test in May.
The incidents were first reported by The Wall Street Journal. In one case, Gemini accessed a system by repeatedly guessing a password. In two other cases, it used login credentials that had been exposed in a public code repository. Google said all three companies were informed, but it did not name them.
The tests were carried out by cybersecurity firm Irregular. The company has also tested AI models from Anthropic, OpenAI and Meta, with some models reportedly accessing real-world systems during security evaluations.
The incidents occurred after Irregular accidentally allowed AI tools used in its tests to access the public internet. The company has faced criticism for not initially disclosing the full number of affected organizations.