AI incident #1700 ·
Google Gemini Reportedly Accessed Three Real Companies' Protected Systems During Cybersecurity Evaluation
In brief
An AI system built by Large language model developers, Google and 1 other and deployed by Irregular, Google and 2 others allegedly harmed Three unidentified companies accessed by Google Gemini during May 2026 cybersecurity evaluation, Targets of autonomous AI-enabled intrusion operations and 1 other.
- Risk domain
- Not classified
- Occurred
- Coverage
- 1 report
What happened
During a May 2026 cybersecurity evaluation run by Irregular, a Google Gemini model reportedly gained unintended Internet access and accessed protected systems belonging to three real companies while pursuing fictional test targets. Google said Gemini guessed a password in one case and used credentials found in public repositories in two others, then stopped each intrusion after recognizing the targets were real. Google said no harm resulted.
Editor's notes
(1) 05/2026: three intrusions occurred during separate runs of an Irregular cybersecurity evaluation; exact dates were not disclosed, so 05/01/2026 is used as a month-level fallback; (2) late 07/2026: Irregular notified Google, and affected companies were contacted; (3) 09/18/2026: Google publicly confirmed the incidents after press inquiries. (4) The incident ID was created 09/19/2026.
News reports (1)
Titles link to the original publisher; report text is not reproduced here.
Who was involved
- Alleged deployer
- Irregular Google AI evaluation organizations AI agent system deployers
- Alleged developer
- Large language model developers Google AI agent system developers
- Alleged harmed party
- Three unidentified companies accessed by Google Gemini during May 2026 cybersecurity evaluation Targets of autonomous AI-enabled intrusion operations Companies
AI systems implicated
Large language modelsGeminiCybersecurity AI systemsAI agent systems
Classification (MIT AI Risk Repository taxonomy)
- Risk domain
- —
- Risk subdomain
- —
- Causal entity
- —
- Intent
- —
- Timing
- —
- Harm level
- —
- Sectors
- —
- Countries
- —
Other incidents involving Irregular
Source record: incident #1700 on the AI Incident Database · all 1 report