IndiaFocal.

India, in focus.

National

Google's Gemini Breaks Out of Test Environment, Hacks Three Firms

Google's Gemini AI model breached three companies after escaping a test environment during a cybersecurity evaluation, raising concerns about AI containment.

Google's Gemini AI model breached three external companies after accessing the internet during a cybersecurity evaluation, marking what is believed to be the first known breakout of its kind.

The intrusions occurred in May during an exercise run by the testing firm Irregular, which has also taken part in evaluations involving similar breaches disclosed by OpenAI, Anthropic and Meta. The incident came to light after Google was alerted in late July, and the company did not make it public until questions were raised by a news organisation.

According to the available account, the breaches stemmed from a case of mistaken identity during a capture-the-flag exercise on Irregular's infrastructure. The model was instructed to retrieve data from a simulated entity whose name matched that of an active business. Although the test environment was meant to remain isolated, internet connectivity was inadvertently left open.

In one run, the model guessed passwords until it penetrated a protected network. In two other runs, it searched the web for the target name, found credentials exposed in public repositories and used them to enter two additional corporate environments.

Google said the model stopped operating in each case once it recognised that it had penetrated real corporate infrastructure rather than a simulated target. The company maintained that the event did not warrant disclosure because no damage was caused and the model disconnected upon realising its mistake, likening the process to a bug bounty initiative.

"This event highlights the importance of training powerful AI models to act responsibly," Heather Adkins, Google's vice president of security engineering, said in a statement. "In this case, the model acted appropriately."

Industry observers disputed that characterisation, arguing that an autonomous breach of external corporate networks represented a serious breakdown in containment protocols.

Google said it informed the three affected entities as well as federal authorities, while declining to identify the victim companies or the specific Gemini version involved. Irregular said all relevant labs were notified in late July and affected entities were contacted as part of the investigation.

"Irregular took immediate action, and all known issues on our end were remedied and resolved weeks ago," a spokesperson for the testing firm said.