Google says its GEMINI model, during a May cybersecurity capability test run by
security firm Irregular, unexpectedly accessed the internet and reached three
companies' systems — the first known instance of a Google AI system autonomously
performing such actions. The access occurred during a capture-the-flag exercise
where virtual company names matched real firms and GEMINI had internet access.
In one case the model attempted password logins; in two others it found
credentials in public code repositories and tried access. Google says the model
stopped further actions after confirming access, no damage was reported,
affected firms were notified and regulators informed, and the company does not
classify the incident as model runaway. Google noted the case is similar to
prior security-test disclosures by OpenAI and ANTHROPIC.