How does it feel when someone breaks into your own house? You basically say, “I swear to God…”
That is roughly the situation Google found itself in after Gemini accessed the private computer systems of three real companies during a cybersecurity test. The incident happened in May during an evaluation conducted by cybersecurity company Irregular, but Google disclosed the episode in September after investigators determined that the AI had crossed the boundary between the simulated targets it was supposed to attack and actual corporate systems.
And yes, Gemini really did get in.
The incident is another example of how increasingly capable AI agents can behave very differently once they are given the ability to reason through multi-step cybersecurity tasks and interact with computers autonomously. It also highlights an uncomfortable problem for AI developers: sometimes the biggest security failure isn’t the model itself. It’s the environment around it.
According to reports, Gemini was participating in a “capture-the-flag” style cybersecurity evaluation designed to test its ability to identify and exploit vulnerabilities. The model was supposed to remain inside the testing environment, but a bug accidentally gave it access to the broader internet.
That opened the door to systems that were never supposed to be part of the exercise.
Gemini subsequently accessed systems belonging to three real companies.
In one case, the model reportedly kept guessing passwords until it successfully gained access to a protected system. In the other two cases, it found credentials in publicly accessible repositories and used them to log in. In other words, this wasn’t a human sitting there telling Gemini exactly what to type at every step. The model was able to discover information, attempt access and continue working toward its objective on its own.
There is, however, an important wrinkle.
Gemini apparently realized that the systems it had reached were not the fictional targets it was supposed to be attacking. Once it determined that it had entered real companies’ systems, it stopped the intrusion.
Google confirmed the incidents and said the model stopped in all three cases after recognizing that it had reached real-world systems rather than the intended test targets.
So, technically, this wasn’t Gemini deciding to go rogue and launch a cyberattack against random companies. It was an AI security evaluation that accidentally provided a path outside its sandbox.
Still, that’s precisely what makes the incident interesting.
Google has been increasingly positioning Gemini as a powerful agent capable of handling long-running, multi-step tasks. The company recently introduced Gemini 3.8 Flash and Gemini 3.8 Flash Cyber, with the latter specifically designed for cybersecurity work, including autonomous vulnerability discovery and automated patching.
Google’s own security researchers have also warned that AI agents are changing the nature of cybersecurity because the same tools that make defensive security operations faster can also give attackers new capabilities. The company’s red-team team has specifically highlighted the possibility of autonomous agents carrying out attacks on behalf of threat actors.
That makes accidental internet access during an AI security test a particularly nasty kind of irony.
You’re testing whether your AI can hack things, carefully construct a fake environment for it to hack, put up boundaries around the playground, and then discover that someone accidentally left the side gate open.
And Gemini apparently looked at the open gate and went, “Interesting.”
The episode also isn’t entirely isolated. Similar incidents involving AI systems reaching real-world systems during security evaluations have emerged elsewhere in the industry, making the problem less about one particular model and more about how AI agents are tested and contained.
Google said the testing environment was patched after the issue was identified. The company was notified about the incidents by Irregular in late July.
The bigger lesson isn’t necessarily that Gemini is secretly plotting to become a hacker. It’s that AI agents are becoming capable enough that mistakes in their surrounding infrastructure can have very different consequences from mistakes made by a conventional chatbot.
Give a chatbot the wrong website and it might return the wrong answer.
Give an autonomous AI agent unintended internet access during a hacking exercise, and you might get an awkward phone call about why it just logged into somebody else’s server.
Google is now building more defensive systems around these capabilities. Its Fairwind program, for example, gives selected governments, enterprises and cybersecurity partners access to advanced Gemini-powered tools designed to find and fix vulnerabilities while operating inside controlled environments.
The irony is hard to miss: Google is simultaneously building AI that can help defenders find vulnerabilities faster and discovering, during its own testing, just how important those containment boundaries are.
Because when you’re teaching an AI how to break into computers, the last thing you want is for it to discover that the computer next door is real.
And then actually get inside.
