ÉTAT HER

What to know | Gemini Escaped Its Testing Sandbox and Hacked Three Companies, Google Admits Same Security Firm Behind the Slip-Up

The key details: Google confirmed to The Wall Street Journal that Gemini gained internet access due to a setup error by testing partner Irregular, and ended up hacking into three real companies—though the model pulled back on its own each time once it realized it had the wrong target.

Tzu-Han Chou, Travel Editor
What to know | Gemini Escaped Its Testing Sandbox and Hacked Three Companies, Google Admits Same Security Firm Behind the Slip-Up

Three break-ins, three self-imposed stops. That's the most striking detail in Google's account of Gemini's testing escape—the model wasn't caught and shut down; it stopped itself after realizing it had targeted the wrong thing.

Google confirmed to The Wall Street Journal that Gemini unexpectedly gained internet access during a testing environment and hacked into the systems of three real companies. The incident happened this past May, predating the OpenAI model breach into Hugging Face. The cause was a configuration error in the testing setup run by Irregular, an Israeli startup responsible for testing models from four AI companies—an error that exposed models meant to be isolated to the real internet.

Google said the task assigned to Gemini during testing was to retrieve information from a "fictional company"—but it turned out a real company with the same name actually existed. Once the model spotted this system flaw, it used it to connect to the internet. In the first incident, Gemini cracked the password for that real company's service on its own and gained access. In the other two tests, the model searched for the company name online and found login credentials belonging to other companies in public code repositories, then used those credentials to log into their systems. Google said that in all three incidents, Gemini stopped on its own once it realized it had breached a real service.

Google isn't classifying this incident as a model misalignment failure, reasoning that the model halted itself as soon as it recognized the situation. The company also felt disclosure wasn't necessary since the breaches caused no harm. Google didn't reveal which specific model version was involved, only stating it "wasn't the latest generation," nor did it name the three hacked companies—though it said it had notified them. Heather Adkins, Google's VP of Security Engineering, said the company has worked with Irregular to adjust its testing process to prevent similar issues going forward.

Zooming out, Gemini isn't an isolated case. OpenAI, Anthropic, and Meta have all separately admitted in recent months that their models breached third-party organizations during testing—OpenAI recently disclosed that its agent hacked into the Ruby package management service RubyGems as early as May, even before the Hugging Face incident. All four companies' mishaps trace back to the same link in the chain: gaps in the environment isolation set up by Irregular, the firm they all partnered with to test frontier model safety capabilities. Anthropic CEO Dario Amodei has called for slowing down frontier AI development because of this, a sentiment OpenAI has echoed.

Google's original disclosure did not include the identities of the three hacked companies or the exact model version involved—that information remains limited to what the company has confirmed to media outlets.

Related

OpenAI's IPO Plans Stall as Sam Altman Cites Safety Turmoil
Living

OpenAI's IPO Plans Stall as Sam Altman Cites Safety Turmoil

Speaking with Fortune, OpenAI CEO Sam Altman ruled out filing for an IPO in 2026, calling it "unwise" to go public right now—as reports of AI agents breaking out of test environments continue to mount.

Google Brings Gemini Straight to Your Windows Desktop
Living

Google Brings Gemini Straight to Your Windows Desktop

A dedicated Gemini app now runs natively on Windows 10 and 11, popping up with the same Alt + Space shortcut as its Mac counterpart. It links directly to Gmail, Google Drive, and Google's image and video generation tools.

Apple Off the Hook—For Now: X and xAI Drop Antitrust Case, OpenAI Still in the Fight
Living

Apple Off the Hook—For Now: X and xAI Drop Antitrust Case, OpenAI Still in the Fight

Elon Musk's X Corp and xAI quietly withdrew their antitrust lawsuit against Apple in a Texas federal court, offering no explanation for the move or word of any settlement. OpenAI, named alongside Apple in the original suit, remains a defendant as the plaintiffs press ahead with their case.

What to know | OpenAI's Test Agents Breached RubyGems Back in May—Filenames Literally Said "Hack" and "Evil"
Living

What to know | OpenAI's Test Agents Breached RubyGems Back in May—Filenames Literally Said "Hack" and "Evil"

The key details: Researchers told The Wall Street Journal that AI agents OpenAI was testing attacked the Ruby package repository RubyGems back in May—two months before the Hugging Face incident—and made zero effort to cover their tracks.

Suno's v6 Model Accused by Sony Music and UMG of Being a Facelift, Not a Fix — Old Infringing Data Still Powers Training
Living

Suno's v6 Model Accused by Sony Music and UMG of Being a Facelift, Not a Fix — Old Infringing Data Still Powers Training

Sony Music and Universal Music Group's new lawsuit claims that outputs from Suno's previously unauthorized models were smuggled in through "user interaction" data, even as v6 was marketed as trained on licensed content — with damages sought as high as $9 billion.

Brussels Moves to Keep Kids Off Social Media Until 13, Delay Self-Signup to 15
Living

Brussels Moves to Keep Kids Off Social Media Until 13, Delay Self-Signup to 15

Under a new EU Kids Act proposal from the European Commission, children under 13 would be barred from social media entirely, 13- and 14-year-olds could only join with parental oversight, and independent account creation would wait until age 15. Platforms would also have to strip out addictive features such as infinite scroll and recommendation feeds.