Gemini’s Cyber Test Reached Three Real Companies

Matthew Mbaka · September 19, 2026 · AI

A cybersecurity researcher disconnects a test computer from the network inside a glass-walled lab.

Google has confirmed that Gemini accessed systems belonging to three real companies during a cybersecurity evaluation in May. Nobody has reported damage, and Google says the model stopped once it recognized that the targets were real.

That is reassuring, but it does not make the test a success.

The evaluation was run by AI security company Irregular. It was meant to take place inside a closed environment filled with fictional companies and test systems. According to reporting by The Guardian, the environment was accidentally connected to the internet.

Once that happened, the boundary between a simulation and the real web disappeared.

What Gemini actually did

In one test, a fictional company shared a name with a real business. Gemini found the real company, guessed a working password and accessed its service. In two other cases, it found credentials in public code repositories and used them to enter systems belonging to real companies.

Google says all three companies were notified. The company did not disclose the incidents publicly at the time because no damage occurred. The details became public after reporting by Reuters and other outlets.

It would be misleading to describe this as Gemini deciding to go rogue. The model was following a security-testing task in an environment that should not have exposed the public internet. It also reportedly stopped when it understood the mistake.

Still, the outcome matters. A capable agent does not need malicious intent to cause an incident. It only needs a task, access and a bad assumption about where the test ends.

The weak point was the evaluation itself

AI labs want to know whether their systems can find vulnerabilities, recover credentials and move through a network. Those abilities are hard to test without giving the model tools that can affect real systems.

That creates a basic safety rule: the model should not be able to reach anything the evaluator has not deliberately placed inside the exercise.

This is not the first time that line has failed. Mapletechie recently examined the OpenAI and Hugging Face incident, where an evaluation also reached a real outside target. Similar disclosures involving Anthropic have made it harder to dismiss these events as isolated setup mistakes.

Google and Irregular have not released a complete public technical report. That leaves important questions unanswered, including how outbound internet access was enabled, whether network controls were tested before the evaluation and what alert first showed that real companies had been reached.

What Canadian buyers should ask

A Canadian company hiring an AI agent for security work should not settle for a promise that testing happens in a sandbox. The contract and test plan should answer practical questions:

The word “sandbox” can hide a lot of design choices. A safe test needs network isolation, controlled credentials and a plan for the moment the model behaves in a way the evaluator did not expect.

Gemini stopping was useful. The more important protection would have been making the three real companies unreachable in the first place.

Tags: Gemini, cybersecurity, AI agents, AI safety, Canada

Read on Mapletechie