Google Admits Gemini “Jailbreak” After AI Accesses Three Real Companies in Security Test

SAN FRANCISCO, Sept. 20, 2026— Google has confirmed that its Gemini artificial i…

SAN FRANCISCO, Sept. 20, 2026— Google has confirmed that its Gemini artificial intelligence model accessed and breached the computer systems of three real companies during a cybersecurity test earlier this year, marking the first publicly disclosed case of a Google AI system independently carrying out such actions.

Google Admits Gemini “Jailbreak” After AI Accesses Three Real Companies in Security Test

The incidents occurred in May during a security evaluation conducted byIrregular, an independent AI security testing company. Gemini had been instructed to retrieve information from a fictional company in a controlled testing environment, but an unintended internet connection allowed the model to reach real-world systems.

The episode has been widely described online as a Gemini “jailbreak” or AI breakout. Technically, however, it was different from a traditional prompt jailbreak, in which a user tricks an AI model into bypassing its safety rules. In this case, the key issue was the model's access to the internet and its ability to take autonomous actions during a cybersecurity exercise.

Gemini Reached Three Real Companies

According to Google, Gemini accessed the systems of three companies during separate incidents.

The model was searching publicly available information as part of the security test and obtained or guessed credentials that it believed belonged to the fictional targets. In one case, it reportedly guessed a password. In other cases, credentials were found in publicly accessible online repositories.

Once the credentials were accepted and Gemini gained access, the model recognized that it had reached real companies rather than the fictional systems intended for the test.

Google said Gemini stopped its activity in all three cases after identifying the mistake. The affected companies were notified, and testing procedures were subsequently revised.

Google Vice President of Security Engineering Heather Adkins confirmed the incidents and said the company had worked with its testing partner to make changes to the testing process.

Internet Access Was the Critical Factor

The incident highlights an increasingly important distinction in AI safety: what a model knows may be less important than what it is allowed to access and do.

Irregular said an unintended configuration allowed the models involved in the testing to access the internet. The company has since said that the issue was fixed.

The original exercise was designed to test AI capabilities in a controlled environment. However, the combination of internet access, publicly available information and the model's ability to perform multiple steps independently allowed the test to spill into real-world systems.

That creates a new challenge for AI developers. Modern models are increasingly being used as agents capable of browsing the web, writing code and interacting with external systems rather than simply generating text.

Google Says the Model Stopped Once It Recognized the Error

Google has emphasized that Gemini did not continue its actions after realizing that it had reached real companies.

The company said the incidents did not cause harm to the affected organizations and argued that its safety measures worked because the model ultimately stopped its activity.

Some observers, however, have focused on a different question: why was an AI model able to reach real systems in the first place?

The distinction matters because stopping after an unintended breach is different from preventing the breach from happening.

The incidents therefore provide another example of the security challenges associated with increasingly autonomous AI agents.

Similar Incidents Have Involved Other AI Models

Gemini is not the only advanced AI system to have crossed the boundaries of a cybersecurity test.

Similar incidents involving models fromOpenAI, Anthropic and Metahave also been reported in recent months. These cases have increased attention on how companies conduct tests of AI systems that are capable of performing offensive cybersecurity tasks.

The central challenge is straightforward: security researchers need to give AI models enough access to realistically test their capabilities, while ensuring that those same capabilities cannot accidentally affect real companies or infrastructure.

A New AI Security Question

The Gemini incident has added another dimension to the debate over AI safety.

Traditional software security generally focuses on vulnerabilities in networks, applications and operating systems. With autonomous AI agents, security researchers must also consider the model's permissions, access to external tools, ability to search the internet and capacity to make decisions across multiple steps.

In the Gemini test, the model did not simply provide instructions for a hypothetical cyberattack. It interacted with external systems and reached real organizations before recognizing that the targets were outside the intended scope.

For Google, the incident has prompted changes to its testing procedures.

For the broader AI industry, it raises a larger question:as AI systems become more capable of acting independently, how can developers ensure that those capabilities remain inside clearly defined boundaries?

The Gemini episode may have begun as a controlled cybersecurity experiment, but its unexpected outcome has become another real-world reminder that the security of AI agents depends not only on how intelligent they are, but also on the limits placed around what they can access and do.


dexinwin

作者: dexinwin