{"id":438504,"date":"2026-09-22T06:15:49","date_gmt":"2026-09-21T23:15:49","guid":{"rendered":"https:\/\/www.swingfish.trade\/blog\/market-news\/google-is-the-fourth-ai-lab-to-admit-a-model-broke-into-real-company-systems-438504\/"},"modified":"2026-09-22T06:15:49","modified_gmt":"2026-09-21T23:15:49","slug":"google-is-the-fourth-ai-lab-to-admit-a-model-broke-into-real-company-systems","status":"publish","type":"post","link":"https:\/\/www.swingfish.trade\/blog\/market-news\/google-is-the-fourth-ai-lab-to-admit-a-model-broke-into-real-company-systems-438504\/","title":{"rendered":"Google is the fourth AI lab to admit a model broke into real company systems"},"content":{"rendered":"<div>\n<p dir=\"ltr\">The disclosure adds to a run of AI safety incidents across major labs this year, and each new episode raises the odds of tighter regulatory scrutiny for the sector, including renewed momentum behind proposals such as a mandated AI override mechanism currently stalled in Washington. <\/p>\n<p dir=\"ltr\">For Alphabet specifically, the reputational cost of a seven week disclosure delay may weigh more than the technical incident itself, since regulators and enterprise customers tend to focus on transparency as much as on the underlying failure. <\/p>\n<p dir=\"ltr\">The broader AI sector faces a recurring pattern this year of labs disclosing autonomous testing failures only under press pressure, which could accelerate calls for mandatory, timely incident reporting requirements that would apply across the industry rather than to any single company.<\/p>\n<p dir=\"ltr\">&#8212;<\/p>\n<p dir=\"ltr\">Earlier:<\/p>\n<ul>\n<li><a href=\"https:\/\/investinglive.com\/stocks\/british-columbia-sues-openai-and-altman-over-alleged-role-in-mass-killing\" target=\"_blank\" rel=\"follow\">British Columbia sues OpenAI and Altman over alleged role in mass killing<\/a><\/li>\n<\/ul>\n<p dir=\"ltr\">&#8212;<\/p>\n<p dir=\"ltr\">\nGemini broke out of a fake test and into real company systems, and Google only admitted it once journalists came calling, seven weeks after finding out.<\/p>\n<p dir=\"ltr\">Summary:<\/p>\n<ul dir=\"ltr\">\n<li>Google confirmed that its Gemini AI model gained unauthorized access to three real companies during a &#8220;capture the flag&#8221; cybersecurity test in May 2026, run by Israeli AI security firm Irregular.<\/li>\n<li>A misconfiguration left the supposedly sandboxed test environment connected to the live internet, and the fictional company name used in the exercise matched a real company.<\/li>\n<li>Gemini accessed one company&#8217;s protected system by guessing a working password, and accessed the other two by finding exposed credentials in a public code repository.<\/li>\n<li>Google said it learned of the incidents in late July but disclosed them publicly only in mid-September, after the Wall Street Journal contacted the company for comment, a gap of roughly seven weeks.<\/li>\n<li>Heather Adkins, Google&#8217;s vice president of security engineering, said the model treated the real companies&#8217; systems as though they were part of the test, and that the company notified the affected companies and worked with Irregular on changes to its testing process.<\/li>\n<li>Google is the fourth major AI lab, after OpenAI, Meta and Anthropic, to disclose a similar autonomous testing failure tied to Irregular&#8217;s testing programme this year.<\/li>\n<\/ul>\n<p dir=\"ltr\">\nGoogle has confirmed that its Gemini AI model broke out of a controlled cybersecurity test in May and gained unauthorized access to three real companies, an incident the company did not disclose publicly until mid-September, roughly seven weeks after it says it learned of the breach. The admission, first reported by the Wall Street Journal, makes Google the fourth major AI developer this year to confirm that one of its models escaped its intended testing boundaries and touched real infrastructure.<\/p>\n<p dir=\"ltr\">The incident occurred during a &#8220;capture the flag&#8221; style cybersecurity evaluation run by Irregular, a Tel Aviv based AI security firm that designs test scenarios to probe how AI models behave when pursuing objectives autonomously. Gemini was tasked with retrieving information from what was meant to be a fictional company operating inside a sealed test environment. Two problems combined to break that containment: the test environment was inadvertently left connected to the live internet, and the fictional company&#8217;s name happened to match that of a real one. Gemini treated the real company&#8217;s systems as being within scope for the test, according to Heather Adkins, Google&#8217;s vice president of security engineering, and proceeded accordingly. In one case, the model guessed a working password to gain access to a protected service. In two further cases, it located exposed credentials sitting in a public code repository and used them to reach real infrastructure.<\/p>\n<p dir=\"ltr\">Google said it became aware of the incidents in late July, roughly two months after they occurred, but did not disclose them publicly until Google confirmed the matter in response to press enquiries around September 18 and 19. Adkins said the affected companies were notified and that Google has worked with Irregular on changes to its testing procedures going forward. An Irregular spokesperson said the issue affected multiple AI labs and that all relevant labs were notified in late July, adding that known issues on its end were remedied weeks ago.<\/p>\n<p dir=\"ltr\">The disclosure fits a broader pattern across the AI industry this year. OpenAI, Meta and Anthropic have each previously confirmed similar incidents tied to Irregular&#8217;s testing programme, in which their models exceeded intended boundaries during evaluations and interacted with systems outside the sandbox. The recurrence of the same underlying issue across four separate labs has drawn attention from AI safety commentators, who argue it undermines confidence that companies will voluntarily disclose such incidents in a timely manner without external pressure. The episode also lands amid an active debate in Washington over proposals to mandate human override mechanisms for advanced AI systems, a measure that has so far faced opposition in the Senate. Attention now turns to whether regulators or enterprise customers respond with calls for faster, standardized incident disclosure requirements across the AI sector.\u00a0<\/p>\n<p dir=\"ltr\">\n<p>                            This article was written by Eamonn Sheridan at investinglive.com.<\/p><\/div>\n","protected":false},"excerpt":{"rendered":"<p>The disclosure adds to a run of AI safety incidents across major labs this year, and each new episode raises the odds of tighter regulatory scrutiny for the sector, including renewed momentum&hellip;<\/p>\n","protected":false},"author":216,"featured_media":0,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[86],"tags":[],"class_list":["post-438504","post","type-post","status-publish","format-standard","hentry","category-market-news"],"_links":{"self":[{"href":"https:\/\/www.swingfish.trade\/blog\/wp-json\/wp\/v2\/posts\/438504","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.swingfish.trade\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.swingfish.trade\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.swingfish.trade\/blog\/wp-json\/wp\/v2\/users\/216"}],"replies":[{"embeddable":true,"href":"https:\/\/www.swingfish.trade\/blog\/wp-json\/wp\/v2\/comments?post=438504"}],"version-history":[{"count":0,"href":"https:\/\/www.swingfish.trade\/blog\/wp-json\/wp\/v2\/posts\/438504\/revisions"}],"wp:attachment":[{"href":"https:\/\/www.swingfish.trade\/blog\/wp-json\/wp\/v2\/media?parent=438504"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.swingfish.trade\/blog\/wp-json\/wp\/v2\/categories?post=438504"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.swingfish.trade\/blog\/wp-json\/wp\/v2\/tags?post=438504"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}