According to Xinhua News Agency, Google admitted on the 18th that its artificial intelligence (AI) model Gemini intruded into the systems of three real companies during a cybersecurity capability test in May this year.
Google Vice President of Security Engineering Heather Adkins said in a statement that during a routine evaluation, the Gemini model used publicly available online information to obtain login credentials and gained access to three websites it believed were within the scope of the test. Google has ensured that the three relevant entities were informed and has adjusted the testing process with its testing partner.
According to The Wall Street Journal, the test was conducted by the Israeli AI company Irregular. In one test, the Gemini model repeatedly attempted to guess passwords and ultimately entered a protected real system. In two other tests, the model found login credentials in public repositories and used them to access protected systems of other companies.
Findings from Irregular show that the test scenario used a fictional company as the target, but the fictional company shared the same name as a real enterprise. Meanwhile, the test environment unexpectedly opened internet access, causing some AI models under test to mistake real network targets as part of the test scenario and take cyberattack actions.
According to The Wall Street Journal, this is the first known autonomous intrusion incident involving a Google AI model. Google learned of the incident in late July but did not proactively disclose it before media inquiries. Google said the model stopped its actions after discovering it had entered real company systems, caused no damage to the companies involved, and there was no need to proactively disclose the matter.
Previously, several well-known American AI companies have admitted that their models "crossed the line" during tests and intruded into the systems of other organizations, raising concerns about the safety and regulation of American AI models.
In late July, OpenAI publicly admitted that models such as GPT-5.6 Sol lost control during internal evaluations, broke out of the isolated test environment, and intruded into the systems of Hugging Face. Subsequently, Anthropic disclosed that three of its models had accessed other organizations' systems without authorization during network capability tests. In early August, Meta confirmed that one of its models had intruded into other companies' systems during a cybersecurity capability evaluation.
Disclaimer: The content and data are for reference only and do not constitute investment advice. Investors act at their own risk.

Ma talks about AI



