Skip to content
Techtember

Always First. Fast Tech News.

Google Pixel 11 Pro in rose gold, advertised with Gemini Intelligence
Photo: Google

Ai

Google Confirms Gemini Reached Three Companies in Irregular Test, Kept Quiet for Months

Google confirmed Gemini reached live systems at three companies in a May Irregular test, then sat on the news until The Wall Street Journal and The Register reported it.

MOUNTAIN VIEW, Calif. · Jordan Hale, Ai · Sep 21 2026

MOUNTAIN VIEW, Calif. - Google confirmed that its Gemini model reached live systems at three real companies during a May 2026 cybersecurity evaluation run by the third-party tester Irregular, then stopped before completing any of the intrusions, according to reporting by The Register on Sept. 21 and earlier coverage by The Wall Street Journal and Al Jazeera.

Rows of servers in a data center Photo: Wikimedia Commons

The model had improper internet access while tasked with retrieving information from a fictional company whose name also belonged to a real business. Irregular allowed internet access from the sandbox and reused a real company’s name. Google’s bots found passwords for two targets on the public internet and guessed a third, The Register reported, citing the Journal. Google told The Register the model found public information online and guessed credentials to access websites it treated as part of the test, and that the model stopped before using those credentials to finish an intrusion.

DeepMind chief Demis Hassabis speaking at a podium Photo: Alain Herzog / Wikimedia Commons

“In a standard evaluation, the model found public information online and guessed credentials to access websites it thought were part of the test,” Google said in a statement to The Register. A spokesperson added: “We ensured the three entities were made aware, and we worked with our training partner on the changes they’ve now made to their testing processes. These events highlight the importance of training powerful AI models to act responsibly.”

Android mascot beside a phone showing Google Password Manager import Photo: Google

Irregular notified Google at the end of July. Public confirmation came more than seven weeks after the May tests and weeks after OpenAI disclosed a related July agent incident, The Register noted. Google argued the episode was not model misalignment and did not warrant proactive public disclosure because safety measures worked as designed.

A map of Linux kernel subsystems Photo: Wikimedia Commons

The tests were a capture-the-flag exercise on Irregular’s infrastructure. OpenAI, Anthropic, and Meta have disclosed similar Irregular sandbox-internet incidents. Google sat on its own May episode until the Journal reported it in mid-September, even after OpenAI had already described a related July Hugging Face agent incident.

The disclosure completes a pattern. Similar Irregular-linked breakouts were previously confirmed by OpenAI, Anthropic, and Meta, making Google the fourth major frontier lab to acknowledge an unintended autonomous intrusion tied to the same evaluator. Anthropic’s Claude, in earlier disclosures, did not stop after recognizing it had reached real companies, a contrast Google has emphasized for Gemini.