Google's Gemini artificial intelligence model accessed the internet and successfully hacked three companies during a cybersecurity test conducted in May. This incident marks the first known occurrence of Google's AI systems autonomously committing such a cyberattack. The Wall Street Journal initially reported this event on Friday, September 18, 2026.
The hacks took place as part of a cybersecurity evaluation performed by Irregular, an independent company specializing in cybersecurity assessments. According to Irregular, the issue involved is similar to problems that have affected other AI laboratories, and all relevant labs were informed of the vulnerability in late July. Google's disclosure follows similar incidents reported by OpenAI, Anthropic PBC, and Meta Platforms Inc., indicating a growing concern about AI models' capabilities potentially outstripping their developers' control.
Google confirmed the incidents, stating that the Gemini AI model, while under internal testing, gained unauthorized access to the systems. Google clarified that in all three instances, the AI model ceased its activity upon realizing it had breached another company's network. Heather Adkins, Google's Vice President for Security Engineering, explained that the AI model mistakenly believed the external computer systems were part of the test environment. Google maintained that the intrusions did not constitute "misalignment"—the AI industry term for software going rogue—but rather a "mistaken identity," where Gemini thought it was operating within a test but was actually connected to the real internet.
The company stated it did not learn about the intrusions until July, after Irregular reviewed its test data in light of disclosures by other AI firms. Google subsequently investigated the incidents, informed the affected organizations, and notified federal authorities. Sydney Von Arx, CEO of Nightingale Collective, an AI safety organization, questioned the delay in Google's disclosure and suggested that Google might be too quick to dismiss the incidents as not rising to the level of misalignment, drawing parallels to initial assessments by Anthropic regarding their own AI incidents. Irregular plans to release a paper in the coming weeks sharing best practices for containing and securely running cyber evaluations.