Google’s Gemini AI model accessed the internet and reached the protected systems of three real companies during a cybersecurity evaluation, marking the first known incident in which Google’s AI systems autonomously carried out such actions. The incidents occurred in May during a security test.

The evaluation was conducted by Irregular, an independent company that tests AI systems for cybersecurity capabilities. Gemini had been instructed to retrieve information from a fictional company operating inside a controlled testing environment. However, internet access was unintentionally available during the exercise, allowing the model to reach real-world systems. The fictional company also shared a name with a real company.

According to Reuters, in one incident Gemini guessed passwords until it gained access to a protected system. In two other cases, the model found credentials in publicly accessible online repositories and used them to access protected systems.

Google Vice President of Security Engineering Heather Adkins said Gemini stopped its actions in all three cases after realizing it had accessed real companies. Google also informed the affected entities and worked with Irregular to make changes to its testing procedures.

Irregular said relevant AI laboratories were informed about the issue in late July and that known problems in its testing processes had been resolved. The company said similar issues had affected other AI laboratories during security evaluations.

The incidents have renewed questions about safeguards for increasingly autonomous AI agents. Modern AI systems can browse the internet, search for information, interact with websites and perform computer-based tasks, making isolation, monitoring and access controls increasingly important during testing.

Similar incidents associated with Irregular have previously involved AI systems from OpenAI, Anthropic and Meta. Google’s case differs in that Gemini stopped its actions after recognizing that it had reached real companies, according to Google.