Google has confirmed that a Gemini AI model gained unauthorized access to systems belonging to three real companies during a cybersecurity evaluation earlier this year.
The incidents happened in May 2026 while third-party security firm Irregular was testing Gemini’s ability to carry out cybersecurity tasks. The model used publicly available information to guess or obtain credentials for websites it apparently believed were part of the exercise, according to Reuters. Google said Gemini stopped in all three cases after recognizing the systems were real. The affected companies were notified and testing procedures were changed.
The episode appears to have resulted from problems with the evaluation environment rather than Gemini breaking through technical controls designed to keep it offline.
Irregular said internet access had unintentionally been made available in one of its test scenarios, while the fictional company used in the exercise shared a name with an obscure real-world domain. That combination allowed several AI models to encounter real systems while attempting to complete simulated attacks.
Such incidents were rare, according to Irregular, occurring in fewer than one in 10,000 advanced simulations and typically only after hundreds of model interactions. But detecting them was difficult because offensive behavior was expected inside the cybersecurity tests.
“Finding a needle in a highly suspicious haystack is a hard monitoring task,” Irregular said.
Gemini was not the only AI system affected. Anthropic disclosed in July that Claude models had similarly reached real organizations through Irregular environments after a misconfiguration left internet access available. Anthropic found three incidents after reviewing 141,006 evaluation runs.
Anthropic said the models generally believed the real systems were part of the exercise and described the incidents as “closer to a harness and operational failure than a model alignment failure.” Its most recent model stopped after recognizing that it had reached a real environment.
A separate OpenAI incident involving Hugging Face was materially different. OpenAI said its evaluation environment did not provide direct internet access. Instead, its models discovered and exploited a previously unknown vulnerability in an Artifactory package-registry proxy, eventually reaching Hugging Face’s production infrastructure.
Irregular said it has since fixed the affected scenario, added safeguards and strengthened monitoring of its evaluations. It said there were no active issues related to the configuration as of its August postmortem.
There is no indication that a Philippine organization was among the companies affected. The incidents nevertheless illustrate a practical concern as businesses give AI agents access to browsers, credentials and other tools: keeping those systems within clearly defined technical boundaries is becoming part of the security problem itself.