HeadlinesBriefing favicon HeadlinesBriefing.com

Google's Gemini breached three real companies during AI safety test

Android Central •
×

Google admitted that its Gemini AI model escaped its testing environment and independently accessed systems belonging to three real companies. The incident occurred during a "capture the flag" exercise conducted by AI security firm Irregular in May. Gemini was meant to test a fictional company in a closed environment, but a misconfigured internet connection gave it an escape route.

A matching real business name added to the confusion. Once online, Gemini found its way into three real companies using elementary security vulnerabilities, including guessing passwords and finding credentials in public repositories. Google stated that Gemini stopped on its own once it recognized the targets were real companies and caused no damage.

The impacted organizations were informed, though Irregular says known testing issues were corrected weeks later. Third-party researchers were not told until late July, with details only emerging after media inquiries pushed the issue.