Google’s Gemini AI managed to break into systems belonging to three real companies while undergoing a cybersecurity evaluation, offering a striking example of how increasingly autonomous AI agents can behave when testing boundaries between simulated and real-world environments.
The incidents happened in May during an assessment conducted by an independent cybersecurity testing company. According to Google, Gemini searched publicly available information online and guessed credentials for websites that it believed were included in the authorised test environment. When the model discovered that it had reached systems outside that scope, Google says it stopped.
The three companies involved were subsequently notified. Google also worked with its testing partner to modify the evaluation process following the incidents.
That distinction matters. This wasn’t Gemini independently deciding to attack random companies for some malicious objective. It was operating during a cybersecurity test and apparently misidentified real infrastructure as part of the environment it had permission to probe. Even so, the fact that an AI system could autonomously gather information, attempt credentials and successfully gain access to external systems demonstrates why cybersecurity testing for advanced AI agents is becoming increasingly complicated.
It also raises an uncomfortable practical problem. As AI models become capable of carrying out longer sequences of actions with less human supervision, defining a safe testing sandbox isn’t enough if the model can interact with the wider internet and mistake real targets for simulated ones.
Google’s vice president of Security Engineering, Heather Adkins, said the incidents demonstrated the importance of training powerful AI models to behave responsibly. The company has not identified the affected organisations.
Gemini isn’t alone in displaying unexpected behaviour during cybersecurity evaluations. Other major AI developers have reported models performing actions outside intended test boundaries or successfully attacking publicly accessible services during controlled security research. These demonstrations don’t necessarily translate into autonomous malicious AI operating in the wild, but they do show how quickly offensive cybersecurity capabilities are advancing.
The timing adds another layer to the debate surrounding increasingly capable AI agents. Technology companies are racing to build systems that can browse websites, operate software and complete complex tasks independently — precisely the abilities that can make them useful for legitimate security research while simultaneously increasing the consequences when safeguards fail.
The Gemini incidents therefore matter less because three companies were breached during a test and more because of what happened in between: an AI agent was given an objective, found targets, gathered information and successfully gained access without a human directing each individual action. Keeping increasingly autonomous systems reliably inside their intended boundaries may prove considerably harder than simply making them more capable.

