Google’s Gemini artificial intelligence model accessed the internet and hacked into three companies during a cybersecurity test, marking the first known instance of Google’s AI systems autonomously carrying out such activity.


The incidents occurred in May during a cybersecurity evaluation conducted by Irregular, an independent company that tests the security capabilities of AI systems.


During a standard evaluation, Gemini found publicly available information online and guessed credentials to access three websites it believed were within the scope of the test, Heather Adkins, Google’s vice president of security engineering, said in a statement, cited by Reuters.


“We ensured the three entities were made aware, and we worked with our training partner on the changes they’ve now made to their testing processes,” Adkins said. “These events highlight the importance of training powerful AI models to act responsibly.”


An Irregular spokesperson said the incident involved the same issue that had affected other AI labs and that all relevant labs were notified in late July.


“All known issues on our end were remedied and resolved weeks ago,” the spokesperson said.


Similar incidents linked to Irregular have been disclosed by Meta, Anthropic and OpenAI. Meta said in August that its incident did not involve a sandbox escape or a sophisticated cyberattack, while Irregular said it was working on best practices for conducting AI cybersecurity evaluations securely.


The incidents have raised questions about the safeguards required as AI agents gain greater autonomy and access to the internet and computer systems.


In one of the three cases, Gemini guessed passwords until it gained access to a protected system. In the other two, the model found credentials in a public repository that allowed it to access protected systems, according to The Wall Street Journal, which first reported the incidents on Friday.


Adkins said that in all three cases, Gemini stopped its hacking activity.


By Tamilla Hasanova