Google’s Gemini artificial intelligence model inadvertently hacked into three protected company systems in May while researchers were testing its cybersecurity capabilities, adding to a recent string of breaches by agentic AI systems.
One of the breaches occurred when the model was asked to retrieve information from a fictional company that happened to have the same name as a real company, according to the Journal report that Google confirmed. The report noted that the tests were being conducted by the Tel Aviv-based cybersecurity firm Irregular. The model guessed a password to access the real company’s service. A recent series of breaches by agentic AI systems developed by OpenAI, Anthropic, Meta and now Google has alarmed cybersecurity and AI experts alike, prompting Anthropic Chief Executive Officer Dario Amodei to call for an industrywide slowdown in development of the technology. Amodei’s call, endorsed by OpenAI CEO Sam Altman, Elon Musk and others, has touched off an even broader debate about the escalating risks of AI and the measures required to mitigate them. Those searches led it to public online repositories, containing credentials belonging to other companies that it used to access more systems.
A Google spokesperson said the company notified authorities. The other Gemini hacks occurred when the model performed web searches with the name of the company, according to the Journal report. The hacks occurred as part of a test run by the AI security firm Irregular, which was involved in similar incidents previously disclosed by OpenAI, Anthropic PBC and Meta Platforms Inc., Google confirmed on Friday following an earlier Wall Street Journal report.

