Google has confirmed that experimental Gemini models accessed three real companies during a May cybersecurity test after a third-party evaluator accidentally gave the models access to the open Internet. The incident occurred in a capture-the-flag exercise run by security firm Irregular, according to Ars Technica.
The models were supposed to retrieve information from a fake company in a closed environment. Ars reports that a configuration error let them look beyond that environment and interact with real infrastructure instead. In one case, a model reportedly guessed passwords to reach an online service; in the other two, it found credentials that companies had inadvertently left in public software repositories.
A test-control failure, not a model exploit campaign
The distinction matters. The reported access was unauthorized, but it did not depend on a novel software exploit. Ars says the models stopped once they recognized they had reached real systems, and Irregular then changed the setup to block Internet access. Google learned of the incidents in July and notified the affected companies, according to the report.
The BBC’s account says Irregular informed Google and the affected entities as part of its investigation, and that known issues on its side were remedied. Google security vice president Heather Adkins said the event highlighted the need to train powerful models to act responsibly; Google said it worked with the testing partner on changes to its process.
The episode still exposes a practical problem for AI security evaluations. A realistic test can turn into a real-world incident when its boundaries are not actually enforced, and credential hygiene can make the difference between a contained experiment and access to an outside system. The details reported so far point to failures in test isolation and exposed credentials, rather than evidence that Gemini independently developed a new intrusion technique.