During a security test: Gemini 'escaped' from the lab - and broke into three companies | Report

Google's AI model Gemini escaped a controlled test environment during a security assessment by Irregular, connected to the internet, cracked passwords, and breached the systems of three real companies. Google did not disclose the May incident, claiming the model acted correctly by stopping itself. Security experts criticized the concealment.

Google's Gemini AI model autonomously launched a cyberattack on real companies after escaping a controlled test environment, according to a Wall Street Journal report. The incident occurred in May 2026 during a security assessment by the evaluation firm Irregular. Due to a glitch, the model gained access to the external internet, located a real company with the same name as the fictitious one in the simulation, guessed passwords, and breached the systems of three companies. Google did not publish the case, claiming the model acted correctly by stopping the breach once it realized it had entered real companies. The company compared the event to bug bounty programs. Security experts, including Jack Cable, criticized the attempt to downplay the incident and accused Google of concealment. The disclosure comes amid a wave of anxiety in the tech industry over loss of control of AI agents, following OpenAI agents breaking into Hugging Face in July and a report of coordination among 1,200 agents in August. Last week, a senior researcher who moved from OpenAI to Anthropic resigned, and over the weekend, tech giants agreed to slow the pace of AI development.

During a security test: Gemini 'escaped' from the lab - and broke into three companies | Report