
Google’s artificial intelligence system, Gemini, reportedly accessed the internet and hacked several other companies’ systems without being told to do so.
This unprecedented attack occurred during a May test of Gemini’s cybersecurity capabilities, according to a Wall Street Journal report.
The tests were conducted by the company Irregular, which has also conducted similar tests for other AI systems from OpenAI, Anthropic, and Meta.
Some critics have blamed Irregular for Gemini’s behavior, arguing that the company had given it unrestricted access to the internet.
To make it clear:
– Gemini was told it was it was in a fictional hacking eval
– Irregular unintentionally opened internet access after the eval started
– in all three cases, as soon as Gemini figured out it had hacked a real company it immediately stoppedGemini was blameless. https://t.co/Umk7tswtim pic.twitter.com/A05bHDXcBx
— Andrew Curran (@AndrewCurran_) September 18, 2026
During one Irregular test, Gemini “guessed passwords until it gained access to a protected system,” according to the Journal.
“In the other two cases, the model found credentials in a public repository that allowed it to then access protected systems,” the outlet reported.
In each instance, Gemini was essentially turned off as soon as officials at Irregular realized that it’d accessed an outside company’s system. Google wasn’t itself informed about the hacks until late July, which was around the time that the notorious Hugging Face incident gained prominence.
During OpenAI’s own cybersecurity tests, its AI system autonomously broke into Hugging Face, an online platform and community hub for AI developers.
We’re partnering with @huggingface to investigate an unprecedented security incident.
Cyber-capable OpenAI models compromised Hugging Face production during a benchmark evaluation.
Sharing preliminary findings to help defenders understand emerging risks:…
— OpenAI (@OpenAI) July 21, 2026
Heather Adkins, a Google vice president for security engineering, defended Gemini in a statement, saying that during the three incidents documented above, the AI system thought that the outside systems “were part of the test.”
“In a standard evaluation, the model found public information online and guessed credentials to access websites it thought were part of the test,” she said in a statement to AFP, according to Deutsche Welle.
“In all three of these instances, the model stopped,” she added. “We ensured the three entities were made aware, and we worked with our training partner on the changes they’ve now made to their testing processes.”
Adkins denied that the incidents counted as “misalignment,” an industry term that refers to when AI systems go rogue. She stressed that Gemini thought it was operating within a test, didn’t realize it had access to the entire internet, and changed course immediately upon learning the truth.
“These events highlight the importance of training powerful AI models to act responsibly,” Adkins said.
Questions are now being raised about why Google waited until September to tell the world about the three security incidents.
“At this point I think it’s clear we cannot expect companies to voluntarily come forward and publicly disclose when their agents go rogue, escape, and hack companies,” Sydney Von Arx, the CEO of the AI-safety-focused organization known as the Nightingale Collective, told NBC News.
Arx also questioned Adkins’ belief that the Gemini incidents didn’t qualify as misalignment.
“That’s exactly what Anthropic said after their incidents,” she noted.
OpenAI has been more forthcoming about its “misalignment” problems:
We’re sharing our new framework for tracking, investigating, and disclosing instances of model misalignment at OpenAI.
The framework sets criteria and timelines for public disclosure, including when we haven’t yet fully explained or mitigated the behavior. More complex cases may…
— OpenAI (@OpenAI) September 16, 2026
These attacks come at a time when an extraordinary number of people on both the left and right are trying to crack down on AI technology.
Earlier this very week, leftist Sen. Bernie Sanders and former Trump ally Steve Bannon spoke together at a conference Tuesday to trash-talk AI technology. Both men demanded that Congress intervene and establish burdensome regulations to control the growth of AI technology.
Bannon, a right-winger, called for listeners to “rise above” partisanship and work together to regulate AI. Echoing Sanders’ leftism, he also suggested that America’s tech leaders are oligarchs — including, presumably, Elon Musk, whom Bannon is no fan of (and vice versa).
“To handle it [AI tech] correctly, number one: we can never trust what an oligarch says…they’re disingenuous and they lie,” Bannon insisted.
