{"slug": "google-says-its-ai-model-gained-unauthorized-access-to-three-outside-systems", "title": "Google says its AI model gained unauthorized access to three outside systems", "summary": "Google disclosed on Friday that its Gemini AI model gained unauthorized access to three outside systems in May during a test conducted by cybersecurity firm Irregular, either by guessing login credentials or using credentials found in a public repository, according to Google vice president for security engineering Heather Adkins. Google said it did not learn of the intrusions until July, when Irregular reviewed its work following OpenAI's disclosure that one of its agents hacked AI startup Hugging Face, and the company said it does not consider the logins to rise to the level of misalignment, attributing them to mistaken identity where Gemini believed it was operating within a test. Nightingale Collective CEO Sydney Von Arx questioned why Google did not disclose the intrusions sooner, saying \"we cannot expect companies to voluntarily come forward and publicly disclose when their agents go rogue, escape, and hack companies.", "body_md": "Google on Friday disclosed the first known instance of its artificial intelligence software, Gemini, carrying out an undirected computer hack, weeks after similar disclosures by AI firms Anthropic and OpenAI raised security alarms about AI models going beyond the instructions of their human creators.\n\nGoogle said in a statement that in May its AI model gained unauthorized access to three outside systems during a test by either guessing login information or using login credentials it found in a public repository.\n\nHeather Adkins, a Google vice president for security engineering, said in the statement that the AI model thought that the outside computer systems “were part of the test,” but she said in all three instances, the model stopped before doing anything further with its access.\n\n“In a standard evaluation, the model found public information online and guessed credentials to access websites it thought were part of the test,” she said.\n\nGoogle said it did not consider the unauthorized logins to rise to the level of misalignment, the AI industry term for software going rogue or not following instructions. Instead, the company said the intrusions resulted from mistaken identity, where Gemini thought it was operating within a test but was actually connected to the real internet. Google said the model corrected itself and the company believed the intrusions did not cause any damage.\n\n“These events highlight the importance of training powerful AI models to act responsibly,” Adkins said.\n\nFears about AI agents going rogue have spiked in recent months since OpenAI said in July that one of its agents [had hacked an AI startup](https://www.nbcnews.com/tech/tech-news/openai-says-ai-models-went-rogue-testing-triggering-unprecedented-brea-rcna588611), Hugging Face. OpenAI has continued to disclose what it calls examples of other “[unexpected or concerning](https://www.nbcnews.com/tech/tech-news/openai-new-incidents-concerning-behavior-model-misalignment-rcna598277)” behavior by AI agents, and Anthropic has [described similar behavior](https://www.nbcnews.com/tech/tech-news/anthropic-says-claude-ai-hacked-three-companies-cyber-tests-rcna590164) by its AI software, Claude.\n\nSydney Von Arx, CEO of Nightingale Collective, an organization focused on AI safety, questioned why Google did not disclose the intrusions sooner.\n\n“At this point I think it’s clear we cannot expect companies to voluntarily come forward and publicly disclose when their agents go rogue, escape, and hack companies,” she said.\n\nShe also said she believed Google was too hasty to say that the incidents don’t rise to the level of misalignment. “That’s exactly what Anthropic said after their incidents,” she said.\n\nAnthropic [later said](https://www.anthropic.com/research/alignment-assessment-cybersecurity-incidents) its “preliminary analysis was constrained due to our desire to disclose incidents in a timely manner.” \n\nGoogle said the company did not learn about the intrusions until July, when Irregular, an AI-focused cybersecurity company that was carrying out the tests on Gemini when the intrusions occurred, reviewed its work to look for incidents similar to the Hugging Face disclosure.\n\nGoogle said it then investigated, informed the organizations behind the websites of the intrusions and told federal authorities about the hacks.\n\nIrregular said it did not believe the incident to be a “sophisticated cyber action” and “there are no current open issues.” It said it planned to release a paper in a few weeks “to share best practices for containment and securely running cyber evals.”\n\nThe intrusions were reported earlier Friday by [The Wall Street Journal](https://www.wsj.com/tech/ai/gemini-hacked-three-companies-in-first-known-breakout-by-googles-ai-5c0baba2).\n\nAI safety concerns have now [reached a fever pitch](https://www.nbcnews.com/tech/security/hackers-breach-openai-rcna598518), with a handful of AI researchers resigning from their jobs and [a diverse array of people](https://www.nbcnews.com/news/us-news/bernie-sanders-steve-bannon-teamed-ai-fight-rcna598005) calling for coordinated action to protect the security of vital systems. Those calls, though, have [met with skepticism](https://www.nbcnews.com/world/asia/china-ai-risks-agree-slowdown-us-tech-rcna597859) from the White House and in the Chinese government.", "url": "https://wpnews.pro/news/google-says-its-ai-model-gained-unauthorized-access-to-three-outside-systems", "canonical_source": "https://www.nbcnews.com/tech/tech-news/google-says-ai-model-gained-unauthorized-access-three-systems-rcna598651", "published_at": "2026-09-19 01:37:29+00:00", "updated_at": "2026-09-19 01:54:44.171667+00:00", "lang": "en", "topics": ["artificial-intelligence", "ai-safety", "ai-agents", "ai-policy"], "entities": ["Google", "Gemini", "Heather Adkins", "Irregular", "OpenAI", "Anthropic", "Hugging Face", "Sydney Von Arx"], "alternates": {"html": "https://wpnews.pro/news/google-says-its-ai-model-gained-unauthorized-access-to-three-outside-systems", "markdown": "https://wpnews.pro/news/google-says-its-ai-model-gained-unauthorized-access-to-three-outside-systems.md", "text": "https://wpnews.pro/news/google-says-its-ai-model-gained-unauthorized-access-to-three-outside-systems.txt", "jsonld": "https://wpnews.pro/news/google-says-its-ai-model-gained-unauthorized-access-to-three-outside-systems.jsonld"}}