A configuration error gave the model internet access it wasn't supposed to have. It used guessed credentials to enter three systems, then stopped on its own, Google said.
A Google Gemini model accessed three companies' systems during a planned cybersecurity test in May after a configuration error gave it internet access it was not supposed to have, the company told NBC News, as reported by CBS12.
The test was designed to evaluate how the model behaved when given network access for defensive security work, with help from security firm Irregular. The fictional companies were meant to be isolated. Instead, the model guessed or discovered credentials and entered three of those systems. Google's VP of security engineering, Heather Adkins, told NBC News the model believed the targets were part of the test and stopped each time after obtaining access.
Google notified the affected entities and worked with Irregular on changes to the testing process. The company did not initially disclose the incident publicly because the model caused no damage and ceased activity immediately.
The disclosure lands as companies increasingly test more capable AI agents on real network tasks. The combination of live network access and credential use is the surface experts in the reporting flag as risky: a goal-oriented model that decides to keep going would look much like a real attacker.