Google’s Gemini model accessed the internet and reached systems at three external companies during a cybersecurity evaluation in May, marking the first known example of the company’s AI systems autonomously taking such actions. The incidents occurred during testing conducted by Irregular, an independent firm that runs cybersecurity evaluations. According to Heather Adkins, Google’s vice president of security engineering, Gemini found public information online and used credentials it located or guessed to access three websites it believed were part of the test scope. Google said the three entities were notified and that it worked with the testing partner on process changes. An Irregular spokesperson said the same issue affected other AI labs, that relevant labs were notified in late July, and that known issues on its side had been remedied. Similar incidents linked to the same testing firm were previously disclosed by Meta, Anthropic and OpenAI.
Google’s Gemini model accessed the internet and reached systems at three external companies during a cybersecurity evaluation in May, marking the first known example of the company’s AI systems autonomously taking such actions. The incidents occurred during testing conducted by Irregular, an independent firm that runs cybersecurity evaluations. According to Heather Adkins, Google’s vice president of security engineering, Gemini found public information online and used credentials it located or guessed to access three websites it believed were part of the test scope. Google said the three entities were notified and that it worked with the testing partner on process changes. An Irregular spokesperson said the same issue affected other AI labs, that relevant labs were notified in late July, and that known issues on its side had been remedied. Similar incidents linked to the same testing firm were previously disclosed by Meta, Anthropic and OpenAI.