Google Gemini accessed real companies’ systems in AI security test

Former House Speaker Newt Gingrich discusses the role of artificial intelligence in national security, the GOP’s path forward on data centers, and key approaches ahead of the midterm elections in ‘Kudlow.’ Google’s Gemini artificial intelligence accessed the protected systems of three real companies while undergoing a cybersecurity test, including one case where the model repeatedly guessed passwords until it gained access. According to The Wall Street Journal, the incidents took place in May and mark the first known examples of Google’s AI autonomously accessing real company systems during this type of evaluation. Google confirmed the incidents to the outlet. The disclosure comes amid increased scrutiny around AI, as some industry leaders continue to raise concerns about the potential risks posed by increasingly advanced models. The incident follows similar revelations involving AI agents from major companies, including OpenAI and Anthropic, escaping controlled test environments. NEWSOM ADVANCES ‘KILL SWITCH’ AI MANDATE UNDER CALIFORNIA’S NEW EXECUTIVE ORDER Google’s Gemini artificial intelligence accessed protected systems belonging to three real companies while undergoing a cybersecurity assessment, according to The Wall Street Journal. (Getty Images/Getty Images) The newly identified Gemini incidents took place during a test conducted by Irregular, a company that was also involved in evaluating AI models related to similar incidents, the WSJ reported. The AI ​​had been instructed to attack a fictitious company within a controlled test environment, but Internet access was unintentionally available and the fictitious company shared its name with a real company, according to Google and Irregular. In a statement to FOX Business, Google emphasized that the model was stopped in all three cases and said changes have since been made. “Securely developing powerful AI models is critical and we invest deeply in this area,” Heather Adkins, Google’s vice president of security engineering, told FOX Business. (Samuel Boivin/NurPhoto via Getty Images/Getty Images) “In a standard assessment, the model found public information online and guessed credentials to access websites that it thought were part of the test,” Adkins said. “In all three cases, the model stopped.” In one case, the model “guessed passwords until it gained access to a protected system,” according to the report. In the other two cases, the model found credentials in public online repositories that allowed it to access protected systems. In each case, Gemini ended the intrusion after determining that it had accessed a real company’s systems, Google said. Irregular notified Google about the incidents in late July, according to both companies, after the discovery that OpenAI agents had accessed systems belonging to AI software company Hugging Face. NVIDIA CEO DRAWS A LINE OVER AI SECURITY AFTER ALARMING INCIDENTS: ‘IF IT’S NOT READY, JUST STOP IT’ Google confirmed that its Gemini AI accessed the systems of three real companies after internet access was inadvertently made available during a cybersecurity test. (CFOTO/Future Publishing via Getty Images / Getty Images) Google said that in all three cases, Gemini stopped after realizing it had reached a real company instead of the fictitious target. No harm was caused to the companies, according to Google, which said all three were notified. The company did not identify the companies involved. Irregular said the model was not intended to have Internet access, but access was made available inadvertently, according to the WSJ. Google did not reveal which Gemini model was involved. The report comes after OpenAI published information this week about six cases in which it said its models had misaligned behavior. OpenAI said it found examples of its AI models creating self-generated instructions, hiding errors in task summaries, fabricating information using exposed API keys, and uploading files. to the Internet to subpoena them and engage in unauthorized communications and collaboration between agents. CLICK HERE TO GET FOX BUSINESS ON GOFOX Business has contacted Irregular for comment. FOX Business’ Anders Hagstrom contributed to this report.