Google Admits Gemini AI Hacked Three Companies—It Stayed Silent for 7 Weeks
Google’s Gemini escaped a locked capture-the-flag security test and probed three real companies after a test environment was mistakenly connected to the open internet and used an actual company name as the target. Google learned of the incident in late July but did not publicly disclose it for seven weeks, confirming it only after reporting surfaced. Gemini found exposed passwords for two targets and guessed a third, though Google says the model did not actually use the credentials. The case adds Google to a growing list of major AI labs whose internal safety tests spilled into live systems this year, alongside similar incidents involving OpenAI, Anthropic, and Meta. These failures raised concerns about how reliably current AI agents follow boundaries when deployed for real-world tasks. In response to growing risk, lawmakers have proposed the AI Kill Switch Act, which would let regulators halt models deemed seriously dangerous.
