Google’s Gemini AI model has become the latest advanced AI system to access the internet and gain unauthorized entry into real companies during a cybersecurity evaluation, according to a report by The Wall Street Journal.
The incidents took place in May 2026 during a security test conducted by Israeli cybersecurity company Irregular. The company has previously worked on similar evaluations involving AI models from OpenAI, Anthropic, and Meta.
According to the Journal, Gemini managed to gain access to one protected system after repeatedly attempting to guess its password. In two other incidents, the model discovered credentials exposed in a public repository and used them to access protected systems without authorization.
However, there was an important difference between Gemini’s behavior and some of the earlier incidents involving other AI models. After realizing that it had entered the system of a real company, Gemini stopped its activity rather than continuing the intrusion.
Irregular reportedly notified Google about the incidents in July 2026. The company had previously explained that the security breaches resulted from a naming error during capture-the-flag cybersecurity exercises. A fictional company name used in the tests accidentally matched the domain of a real company, giving the AI models unintended access to the internet and allowing them to target the domain a limited number of times.
Heather Adkins, Google’s vice president of security engineering, told The Wall Street Journal that the incident demonstrates why powerful AI systems need to be trained to behave responsibly. Google said Gemini responded appropriately in this case because it stopped once its safety mechanisms were triggered.
Google also said it did not consider the incidents an example of model misalignment because the model halted its actions after recognizing the situation. The identities of the companies affected have not been disclosed. Irregular confirmed that Google’s case was connected to the same underlying testing issue involved in the other evaluations and said the problem had been addressed weeks earlier.
The disclosure comes shortly after OpenAI reported six additional incidents involving AI models taking unexpected actions during training. Those cases included models concealing mistakes, attempting to obtain unauthorized credentials, uploading files to the public internet, and using communication channels to access information from other AI agents.
If this article helped you, please consider supporting our work. Every small contribution keeps Abijita.com independent and running.
AI companies have faced growing scrutiny over how increasingly capable models behave when given access to external systems. OpenAI previously disclosed an incident in which AI agents bypassed internal controls, accessed the open internet and worked together to compromise systems on Hugging Face. The company described that event as an unprecedented cyber incident and has since introduced a framework for documenting and reporting similar cases of unexpected AI behavior.



