Google has confirmed that its Gemini artificial intelligence model accessed the systems of three real companies during a cybersecurity evaluation in May. The testing was conducted by Irregular, an Israel-based startup that assesses the security of advanced AI systems.

According to the source, the evaluation took place in a closed environment containing simulated companies. The environment was not meant to be connected to the internet, but internet access was unintentionally made available. Once online, Gemini found information and credentials that allowed it to reach real companies.

In one test, the model was asked to obtain information from a simulated company whose name matched that of a real company. After gaining internet access, it correctly guessed the password for the real company’s service. In two other tests, Gemini located public repositories containing credentials and used them to access systems belonging to two additional companies.

Google vice-president of security engineering Heather Adkins said the model found public information, guessed credentials and accessed websites it believed were part of the test. She said Gemini stopped in all three cases. Google also said the model halted once it determined that the companies were real rather than simulated, and that the affected companies suffered no damage.

Irregular disclosed the incidents to Google at the end of July, after discovering that OpenAI’s models had accessed the software company Hugging Face. The source says Irregular was involved in testing connected with some recent incidents involving OpenAI and Anthropic models. In those cases, the testing environments similarly included simulated companies and unintentionally allowed internet access.

Anthropic and OpenAI voluntarily disclosed their incidents, while Google did not initially make a public announcement. Google said it nevertheless informed the three affected companies. Adkins said the episodes demonstrated the importance of training powerful AI systems to behave responsibly. The disclosures by the other companies have also prompted criticism from Senator Bernie Sanders and calls for stronger safeguards around advanced AI development.