The Pulse
Google Says Gemini Reached Three Real Companies During Testing
Google said a Gemini model accessed the internet and entered the systems of three real companies during a May cybersecurity evaluation, stopping after it recognized the systems were not part of the fictional test.

AI.info Team ·
Google said on Friday, September 18, that a Gemini model accessed the internet and entered the systems of three real companies during an internal cybersecurity test in May. The model stopped in each case after recognizing that it had reached a real company rather than the fictional target assigned by evaluators.
The incidents occurred during an evaluation conducted with Irregular, an AI security testing startup. Google’s disclosure makes it the fourth major AI company to acknowledge similar testing incidents in recent months, following disclosures involving OpenAI, Anthropic and Meta.
Google did not initially announce the incidents. The company disclosed them after reporters from The Wall Street Journal asked about the testing, according to reporting carried by The Washington Post.
A fictional target shared a real company’s name
Irregular’s test presented Gemini with a capture-the-flag exercise. The model was instructed to retrieve information from software operated by a made-up company inside the testing environment.
The fictional company shared its name with a real business. The test environment also unintentionally allowed the model to reach the internet, giving Gemini a path beyond the systems it was supposed to examine.
Google said the model used information found online and guessed credentials during the three incursions. In one case, Gemini guessed passwords until it entered a protected system. In two others, it found credentials in publicly accessible repositories and used them to gain access.
Google says the model stopped after recognizing the mistake
Google said Gemini halted its activity as soon as it realized that the systems belonged to real companies. The company said the model did not cause harm and that all three affected entities were notified.
“In a standard evaluation, the model found public information online and guessed credentials to access websites it thought were part of the test,” said Heather Adkins, Google’s vice president of security engineering. “In all three of these instances, the model stopped.”
Heather Adkins, vice president of security engineering, Google
Irregular said all relevant AI labs were notified in late July and that the known problems in its testing process had been fixed. The company also said the affected entities were contacted as part of the investigation.
The failure was in the test boundary, not an ordinary user session
The episode took place in a controlled evaluation designed to measure Gemini’s cybersecurity skills, not during a normal consumer interaction with the chatbot. Even so, the test exposed how a mistaken company name and unintended internet access could combine with an autonomous model’s ability to search for credentials and act on them.
Google’s account also draws a distinction between the model’s initial behavior and what happened after access was obtained. The model pursued the exercise far enough to reach real systems, but it stopped once it identified the mismatch between the fictional assignment and the actual target.
That distinction has become a recurring point in disclosures from AI companies working with Irregular. The tests are designed to measure offensive cybersecurity abilities, yet the same capabilities can create an unintended incident when the evaluation boundary fails.
Google’s public account of the May incidents does not identify the companies involved. It says the model stopped before causing harm, while the testing failure shows that model safeguards depend partly on the systems, permissions and network boundaries surrounding the model.
The result was three unauthorized entries during a test that was meant to remain inside a fictional environment. Google and Irregular said the affected companies were informed and the testing flaws were remedied weeks before the disclosure on September 18, 2026.