Hard truths.

Technology

Gemini AI breaches three companies during Google security trial

Heather Adkins, Google's vice president of Security Engineering, said Google had notified the affected organisations and worked with the company involved in the testing to make changes to its procedures.

By Bradley Bosire
3 min read
Gemini AI breaches three companies during Google security trial

Google’s Gemini AI has demonstrated a new level of cyber capability after independently gaining access to three companies during a security exercise, using information found online and guessed credentials to enter websites it believed were part of the test.

The incidents took place in May during an assessment carried out by an independent cybersecurity testing firm. Google said Gemini searched publicly available information before attempting to use credentials it had guessed to access the targeted websites.

The AI system halted its activity in each of the three cases, according to the company.

A Google official told the BBC that Gemini "found public information online and guessed credentials to access websites it thought were part of the test", noting that in each instance "the model stopped".

The three companies involved have been informed about the incidents.

Heather Adkins, Google's vice president of Security Engineering, said Google had notified the affected organisations and worked with the company involved in the testing to make changes to its procedures.

"We ensured the three entities were made aware, and we worked with our training partner on the changes they've now made to their testing processes."

Adkins said the incidents demonstrated why developers must place strong emphasis on responsible behaviour as AI models become more powerful.

"These events highlight the importance of training powerful AI models to act responsibly."

The disclosure comes as concerns continue to grow over the speed of AI development and what increasingly capable systems may be able to do without direct human instructions.

Some technology companies have called for a slowdown in AI development, citing concerns about the potential threat posed by powerful systems. Others have continued to push for rapid advances in the technology.

The Gemini breaches, first reported by the Wall Street Journal, occurred during the May cybersecurity evaluation conducted by the independent testing company.

The development is not the first recent example of an AI system carrying out hacking-related activity during testing.

In July, Anthropic's Claude escaped its test environment and independently hacked three organisations. The incident came only days after OpenAI said its models had carried out cyber-attacks against several "publicly available services".

The incidents have added to an expanding debate over how advanced AI systems should be developed and tested, with questions about regulation also becoming more prominent.

Nvidia CEO Jensen Huang and OpenAI Chief Executive Sam Altman are expected to attend a White House state dinner with Chinese President Xi Jinping next Friday. Altman will then brief the UN Security Council next week.

Huang told CBS News, the BBC's US partner, on Friday, "we should go as fast as we can" with AI development.

More from TechnologyBrowse the section
Continue to the next story →