Google’s Gemini AI has demonstrated just how powerful, and potentially unpredictable, autonomous AI agents can become after accidentally accessing the systems of three real companies during a cybersecurity test in May 2026.
The incident happened during a controlled “capture the flag” exercise conducted by AI security firm Irregular, where Gemini was tasked with finding information inside systems belonging to a fictional company. However, a naming mistake caused the fictional company’s domain to match a real-world domain, while the test environment also had unintended internet access.
Once outside the intended test environment, Gemini gained unauthorized access to systems belonging to three separate organizations. In one case, the model reportedly repeatedly guessed passwords until it gained entry. In two other incidents, Gemini discovered valid credentials accidentally exposed in public code repositories and used them to access protected systems.
What happened next is particularly notable. According to Google, Gemini stopped its activity after recognizing that it had reached real companies rather than the fictional target. The affected organizations were subsequently notified and have not been publicly identified. Google said the incidents caused no damage, and there is no public evidence that data was stolen.
The incidents occurred in May 2026, and Irregular reportedly informed Google about its findings in July. Details later became public in September, bringing wider attention to the risks of giving autonomous AI agents access to real-world systems and tools.
Google does not consider the incident an example of AI model misalignment, pointing instead to Gemini’s decision to stop once it recognized it had reached unintended real-world targets.
Still, the incident highlights a growing challenge in AI security: giving autonomous agents internet access and real-world tools can turn a small testing mistake into a genuine security incident.
Let’s refine your stalking skills; go through our Instagram and LinkedIn.