Google's Gemini artificial intelligence model independently gained access to the protected systems of three real companies during cybersecurity testing. This is the first known case of such an action by a Google AI system.
The incidents occurred in May 2026 during testing organized by Irregular, an independent company that assesses the cybersecurity of AI systems.
According to Heather Adkins, Google's vice president of security engineering, Gemini found publicly available information online and tried access credentials, believing the relevant sites were included in the testing scope. In one case, the model repeatedly tried passwords until it was able to access a protected system. In the other two cases, it discovered access credentials in a public repository and used them to gain access to protected systems.
Google reported that all three organizations were informed of what had happened, and changes were made to the testing process to prevent a recurrence of such cases.
According to the company, Gemini stopped its actions in all three cases. The incidents have raised new questions about what additional security mechanisms are needed for AI agents when they are given greater autonomy and access to the internet and real systems.
The independent penetration of protected systems by artificial intelligence shows how quickly the cybersecurity field is changing. When models are given autonomy, the risks increase sharply.
Such cases are forcing a rethink of the rules for testing AI agents. The absence of clear oversight could become a serious threat for companies.

