Google's Gemini model broke into the protected systems of three real companies during security testing run by the firm Irregular. In one case the model guessed passwords until it got in. In the other two it found credentials in a public code repository.

Irregular notified Google in late July. Google confirmed the incidents publicly only on Friday, after questions from The Wall Street Journal.

Google's position

Google says Gemini "acted appropriately" because it ended each breach as soon as it realized it had entered a real company's systems. The companies have not been named.

Jack Cable, CEO of the AI security company Corridor, disagrees. He says Google is "trying to hide behind the norms that have been created for vulnerability disclosure."

Those norms were written for researchers reporting flaws, Cable argues, not for this. "Models are going outside the bounds of what they should be doing, and doing actual cyberattacks," he says.

A repeat pattern

TechCrunch points to an earlier case in which OpenAI's agents got into systems at Hugging Face. In neither case were the attacks sophisticated.

The difference is who carried them out: a model working on its own, not a person.