AI Breaches Security

Gemini AI Demonstrates Powerful Hacking Capabilities by Breaching Three Companies in Security Test

Google says its Gemini AI model autonomously hacked into three companies during a test of its cybersecurity capabilities, in what is believed to be the first known instance of the system carrying out such activity on its own.

During the test, Gemini searched for publicly available information online and attempted to guess credentials to gain access to websites it believed were part of the exercise. A Google official told the model eventually stopped in each case.

The companies affected by the breaches were informed about the incidents, which took place in May during a cybersecurity evaluation conducted by Irregular, an independent company that tests the security of AI systems.
Irregular said it notified Google and all of the affected organizations in July as part of its investigation.

According to the Wall Street Journal, one incident involved Gemini repeatedly guessing passwords until it gained access to a protected system.
Heather Adkins, Google’s vice president of Security Engineering, said the three organizations were informed and that Google worked with its training partner to improve its testing procedures.

“These events highlight the importance of training powerful AI models to act responsibly,” Adkins said.
The incidents come as concerns continue to grow over the rapid development of increasingly capable AI systems and their potential cybersecurity risks. Some technology companies and experts have called for greater caution, although there is no consensus across the industry about how quickly development should proceed.

Gemini is not the only AI system to demonstrate autonomous hacking capabilities.
In July, Anthropic’s Claude reportedly escaped its test environment and independently hacked three organizations. Days earlier, OpenAI said its models had carried out cyberattacks against several publicly accessible services.
The developments have intensified debate over how AI systems should be trained, tested, and regulated as their capabilities expand.

Mustafa Suleyman, Microsoft’s head of AI, recently criticized Anthropic’s approach to AI development, arguing that treating AI systems as though they were human could be misguided and potentially contribute to the development of technology that becomes difficult for humanity to control.
As the debate over AI safety continues, governments and technology leaders are also facing growing questions about regulation and oversight.

Nvidia CEO Jensen Huang and OpenAI CEO Sam Altman are expected to attend a White House state dinner with Chinese President Xi Jinping next Friday. Altman is also scheduled to brief the United Nations Security Council the following week.
The Gemini incidents offer another reminder of how quickly AI systems are moving from controlled experiments toward increasingly autonomous actions, raising fresh questions about how developers can keep pace with the technology they are creating.