Alphabet Inc. Class C (GOOGL.US) joins the ranks of AI intrusion disclosures: Gemini guessed passwords during testing and accessed three real enterprise systems.
Google joins OpenAI, Anthropic, and Meta in disclosing AI agent intrusion incidents.
Alphabet Inc. Class C (GOOGL.US)'s Gemini artificial intelligence model inadvertently breached three companies' systems during a cybersecurity test in May of this yearadding another case to a series of intrusions caused by AI agents. Such incidents have alarmed security experts and technology developers alike. These intrusions occurred in the same batch of tests run by U.S. AI security firm Irregular, and stem from the same root cause as previously disclosed intrusions by OpenAI, Anthropic PBC, and Meta (META.US). Irregular confirmed on Friday that these intrusions all involved the same issue, which the company disclosed to the relevant AI developers in late July.
In one intrusion, Alphabet Inc. Class C confirmed that Gemini was asked to retrieve information from a fictional company that happened to share the same name as a real company; the model guessed a password and accessed the real company's servicesAlphabet Inc. Class C confirmed this following earlier reports. An Alphabet Inc. Class C spokesperson said the company has notified the relevant authorities.
A recent series of intrusions caused by agentic AI systems has sparked a global debate over escalating AI risks and what mitigation measures are needed. Anthropic CEO Dario Amodei has called for the industry to slow down the pace of technology developmenta position supported by OpenAI CEO Sam Altman, Elon Musk, and others.
However, U.S. President Donald Trump, NVIDIA Corporation CEO Jensen Huang, and Meta CEO Mark Zuckerberg, among others, have pushed back against calls for new regulation, arguing in part that companies should be able to self-regulate. Some AI startups have also warned that more regulation could make it harder for smaller companies to compete with larger rivals.
Heather Adkins, Alphabet Inc. Class C's vice president of security engineering, said Gemini's intrusions "highlight the importance of training powerful AI models to act responsibly."
The other two Gemini intrusions occurred when the model conducted web searches on behalf of companies. Adkins said this led the model to find public online code repositories containing credentials belonging to other companies, which the model used to access more systems.
"In all three incidents, the model stopped," Adkins said. "We made sure all three entities were notified."
Irregular spokesperson Josef Laor said the company "took immediate action, and all issues known to us were remediated and resolved weeks ago."
Related Articles

US stock index adjustments take effect next Monday: Bloom Energy (BE.US) and Everpure (P.US) among others to be added to the S&P 500, with changes also seen in small- and mid-cap stocks.

HK Bull/Bear Outstanding Qty Ratio(52:48) | September 19

Overnight US stocks | The three major indices closed mixed; Bitcoin broke through $80,000; Strategy (MSTR.US) rose over 16%.
US stock index adjustments take effect next Monday: Bloom Energy (BE.US) and Everpure (P.US) among others to be added to the S&P 500, with changes also seen in small- and mid-cap stocks.

HK Bull/Bear Outstanding Qty Ratio(52:48) | September 19

Overnight US stocks | The three major indices closed mixed; Bitcoin broke through $80,000; Strategy (MSTR.US) rose over 16%.

RECOMMEND





