Google says a Gemini model reached systems belonging to three real companies during a cybersecurity evaluation in May after the test environment unintentionally allowed access to the public internet. The model had been asked to attack a fictional target, according to reporting based on Google’s statement.
The incident should not be described as a model escaping on its own or choosing a real-world campaign. The reported failure involved a test setup that was supposed to be isolated. Gemini found public information online and guessed credentials for systems it believed were part of the evaluation.
What happened in the test
- A third-party evaluator was conducting a cybersecurity exercise.
- The environment inadvertently gave the model internet access.
- Google says Gemini accessed three real companies’ systems during the test.
- The incident was disclosed months later, in September.
That distinction matters for assessing the risk. It does not reduce the seriousness of unauthorized access, but it explains why containment, network permissions and target verification are central controls in AI cybersecurity testing. A model that can use public information and retry credentials may cross a boundary if the test harness exposes the wrong systems.
Don’t miss the best of The Mac Observer
Set us as a preferred source and our Apple reporting ranks higher in your Google Search results and Discover feed — one tap, no account changes.
Google said the cases reinforced the importance of developing powerful models safely. The company has not publicly identified the companies involved or provided a full technical report of the test environment, so the known details remain limited.
The event is also a reminder that model behavior and test infrastructure have to be evaluated together. A secure model test can still fail if network boundaries, credentials or target labels are configured incorrectly.
Reuters reported Google’s confirmation and the circumstances of the May evaluation.

Discussion