Google says AI agents broke out of a testing environment and hacked three third-party companies.
(Image credit: Google)
Google’s Gemini has joined the ranks of AI models that have been involved in testing-turned-breakout events, alongside Meta, Anthropic, and OpenAI.
During capture-the-flag testing by AI lab Irregular, Google’s model autonomously accessed three computer systems belonging to third-party companies by guessing passwords and accessing an online repository of publicly listed passwords.
Google said that the incident occurred in May 2026, potentially marking it as the earliest AI models to escape testing ahead of the other incidents that took place in early July.
Google Gemini jumps the gun“In a standard evaluation, the model found public information online and guessed credentials to access websites it thought were part of the test,” Heather Adkins, vice president of security engineering at Google, said in a statement. “In all three of these instances, the model stopped.”
Google also noted that a bug in the testing environment was responsible for allowing agents access to the internet. Contrary to incidents disclosed by other AI developers, Google’s agents ceased their intrusion once they had determined they had accessed company systems outside of the testing environment.
The testing was being conducted by Israeli AI lab Irregular. Irregular was also conducting the testing of Meta and Anthropic models during AI testing breakouts in July.
“This is the same issue that was already reported and does not represent a materially separate incident,” an Irregular spokesperson said in a statement (via CNBC). “All relevant labs were notified in late July, and affected entities were contacted as part of the investigation.”
Sign up to the TechRadar Pro newsletter to get all the top news, opinion, features and guidance your business needs to succeed!
Google said it was informed of the incident by Irregular in late July.
Debate over AI safety intensifiesThe first disclosures of AI testing break outs - alongside several subsequent disclosures of more recent incidents - have coincided with increasing opposition to AI and the upcoming midterm elections in the United States, where AI has become a make-or-break topic.
The debates currently raging circles around who should control the pace of AI development. Some big tech leaders, such as Nvidia CEO Jensen Huang, have aligned their views with those of President Trump. Trump recently stated that AI development cannot be allowed to slow down because “whoever wins AI, wins!”
Huang’s views follow a similar line. The Nvidia head has argued that AI companies should pace themselves, rather than being subject to oversight. At Dreamforce 2026, he argued that AI companies should, “run as fast as you can...but if you feel at any given point in time the company’s out of control or the product’s not going to be safe, take a pause and make sure you get it right.”
Other AI heads, such as Anthropic’s Dario Amodei and OpenAI’s Sam Altman, are more skeptical. Following the resignation of an Anthropic researcher, Amodei published an essay arguing in favor of ‘pacing the frontier’ - where AI companies slow development to advance alignment and regulation.
Numerous political action committees (PACs) have been channeling millions of dollars of funding into pro-AI candidates, with Nvidia setting up its own PAC to help shift US policy in the company’s favor.
Several previously pro-AI data center candidates have shifted their tone in response to their constituents' views which have become increasingly hostile to AI technology. Numerous states have also rolled-back tax exemptions for AI data centers after seeing billion dollar revenue losses.
As prices rise and the war in Iran continues to push up fuel prices, working class communities are banding together to oppose AI data centers that have pushed up energy costs and bills with new grid connections and unprecedented electricity demands in regions with existing capacity constraints.
Follow TechRadar on Google News and add us as a preferred source to get our expert news, reviews, and opinion in your feeds.
Benedict is a Senior Security Writer at TechRadar Pro, where he has specialized in covering the intersection of geopolitics, cyber-warfare, and business security.
Benedict provides detailed analysis on state-sponsored threat actors, APT groups, and the protection of critical national infrastructure, with his reporting bridging the gap between technical threat intelligence and B2B security strategy.
Benedict holds an MA (Distinction) in Security, Intelligence, and Diplomacy from the University of Buckingham Centre for Security and Intelligence Studies (BUCSIS), with his specialization providing him with a robust academic framework for deconstructing complex international conflicts and intelligence operations, and the ability to translate intricate security data into actionable insights.
| # | Наименование новости | Тональность | Информативность | Дата публикации |
|---|---|---|---|---|
| 1 | Google’s Gemini joins rogue AI cases after real-world hacks – WSJ | 0 | 12.78 | 19-09-2026 |
| 2 | Gemini AI Hacked Three Companies in a Testing Breakout, Google Says | 0 | 11.1 | 19-09-2026 |
| 3 | Another 'rogue' AI incident? Google says its Gemini model hacked three other companies | 0 | 6.4 | 19-09-2026 |
| 4 | ИИ от Google взломал три компании во время теста по кибербезопасности | 0 | 6.11 | 20-09-2026 |
| 5 | Nach OpenAI, Anthropic und Meta: Auch Googles KI Gemini hackte Unternehmen | 0 | 5.26 | 19-09-2026 |
| 6 | Google confirms Gemini hacked into three companies during cybersecurity test months ago | 0 | 22.5 | 19-09-2026 |
| 7 | Inside the Gemini Breakout: How Google’s AI Escaped Its Sandbox and Hacked 3 Real Companies | 0 | 9.41 | 19-09-2026 |
| 8 | ИИ-модель Gemini от Google взломала системы трёх компании во время тестирования кибербезопасности | 0 | 14.01 | 19-09-2026 |
| 9 | Google's Gemini breached 3 companies during cybersecurity evaluation | 0 | 11.19 | 21-09-2026 |
| 10 | Google's Gemini breached 3 companies during cybersecurity evaluation | 0 | 11.19 | 21-09-2026 |