Google’s Gemini model accessed the Internet and hacked other companies during a test of its cybersecurity capabilities, the first known example of the company’s artificial intelligence systems committing such an act autonomously. The attacks occurred in May during a cybersecurity test conducted by Irregular, an independent company that conducts cybersecurity assessments. During a standard test evaluation, Gemini found public information online and guessed credentials to access three websites it thought were within the scope of its test, Heather Adkins, Google’s vice president of security engineering, said in a statement. “We made sure all three entities were aware and worked with our training partner on the changes they have made to their testing processes,” Adkins said. “These events highlight the importance of training powerful AI models to act responsibly.” An Irregular spokesperson said the incident involved the same issue that affected other AI labs and that all relevant labs were notified at the end of July. “All known issues on our end were remediated and resolved weeks ago,” the spokesperson said. Similar incidents related to Irregular were revealed by Meta, Anthropic, and OpenAI. Meta said in August that the incident did not involve a sandbox escape or a sophisticated cyberattack, while Irregular said it was working on best practices for safely conducting AI cybersecurity assessments. The incidents have raised questions about the safeguards needed as AI agents gain greater autonomy and access to the Internet and computer systems. In one case, the Gemini model guessed passwords until it gained access to a protected system. In the other two cases, the model found credentials in a public repository that allowed it to access protected systems, according to the Wall Street Journal, which first reported the news on Friday. Adkins said that in all three cases, the model stopped hacking.