In a recent test of its cybersecurity capabilities, Google’s Gemini model accessed the internet and hacked into other companies. This incident marks the first known instance of the company’s AI systems autonomously engaging in such activities, according to a report from the Wall Street Journal published on Friday.
Google did not immediately respond to Reuters request for comment. Similar incidents linked to Irregular were disclosed by Meta, Anthropic and OpenAI. In one of the cases, the Gemini model guessed passwords until it gained access to a protected system.
The hacks occurred in May during a cybersecurity test conducted by Irregular, an independent company that conducts cybersecurity evaluations, according to the report. Meta said in August the incident did not involve a sandbox escape or sophisticated cyberattack, while Irregular said it was working on best practices for securely conducting AI cybersecurity evaluations. In the other two cases, the model found credentials in a public repository that allowed it to then access protected systems, the WSJ report said.

