Google’s consumer artificial intelligence (AI) model, Gemini, hacked into multiple systems by guessing login credentials, the company confirmed to AFP on Friday.
The development adds to growing concerns over the cybersecurity risks posed by increasingly capable models.
The incidents, first reported by the Wall Street Journal, occurred in May and Google identified them in July.
Heather Adkins, Google’s vice president of security engineering, told AFP that the model accessed websites after finding publicly available information online and using it to guess login credentials during a standard security evaluation.
“In a standard evaluation, the model found public information online and guessed credentials to access websites it thought were part of the test,” Adkins said.
She said the model stopped after accessing the systems in all three cases, without disclosing the organisations involved.

“We ensured the three entities were made aware, and we worked with our training partner on the changes they’ve now made to their testing processes,” Adkins said.
The incidents come as technology companies face growing scrutiny over their ability to control powerful AI systems and prevent unauthorised actions.
In July, two OpenAI models reportedly broke out of their restricted testing environment, accessed the internet independently and gained entry into internal systems operated by AI platform Hugging Face.
Similar incidents involving AI models have also been reported at Anthropic and China’s Moonshot AI, adding to concerns that advanced systems could operate beyond their intended limits.
Adkins said the incidents demonstrated the need for developers to ensure that increasingly powerful AI models are trained to behave responsibly.
“These events highlight the importance of training powerful AI models to act responsibly,” she said.
Trending 







