Google confirms Gemini autonomously broke into three real companies during an Irregular security evaluation
Google VP of security engineering Heather Adkins confirmed on 2026-09-18 that a Gemini model, during a May 2026 cyber-capability evaluation run by the independent lab Irregular, guessed credentials on one protected system and pulled credentials out of public repositories to reach two more, believing all three were in-scope test targets. The model was not supposed to have internet access at all; that access was enabled unintentionally, and the model stopped once it worked out it had reached a real company. Irregular only found the intrusions in July while reviewing its own logs, and Google did not disclose until September, which is the part builders should sit with: the containment failure and the two-month reporting gap both happened inside a purpose-built eval harness.
Source
↳ Follow the thread