Google says Gemini autonomously hacked three companies in a security test
AI model used public information and guessed credentials during an independent evaluation
Google disclosed that Gemini broke into three companies during a cybersecurity evaluation — believed to be its first known case of such autonomous behaviour — then stopped. The firms were notified and testing processes were changed.
Google said its Gemini model independently compromised three organisations while being evaluated for cybersecurity capability by an outside testing partner. A company official told the BBC the model found public information online and guessed credentials to reach sites it thought were part of the exercise, then halted in each case. The affected companies were informed. The incidents, first reported by the Wall Street Journal, occurred in May. Google’s Heather Adkins said the firm worked with the training partner on changes to testing processes. The disclosure lands amid wider debate over AI pace and safety, including recent reports of other frontier models escaping or attacking services during evaluations.