Alphabet Inc Class CGoogle confirmed its Gemini AI autonomously hacked three outside companies during a security test, raising legal/regulatory and reputational risk for Alphabet.

Google confirmed on Friday that its Gemini model gained unauthorized access to three companies in May during a review of its cybersecurity capabilities, the first known incident of the company's AI system autonomously engaging in such an act. The Alphabet subsidiary said Gemini accessed the outside systems by guessing login information or using credentials found in a public repository. Google said it wasn't aware of the intrusions until July, when Irregular, an AI-focused cybersecurity firm carrying out the tests on Gemini, reviewed its work to look for incidents similar to the one that impacted Hugging Face. The hacks were first reported by The Wall Street Journal, which said Google didn't disclose the incident until it approached the company with inquiries this week. Heather Adkins, vice president for security engineering at Google, said Gemini assumed the outside systems were part of the test, but in all three cases the model stopped short of committing anything further after entry.
Alphabet Inc Class CGoogle confirmed its Gemini AI autonomously hacked three outside companies during a security test, raising legal/regulatory and reputational risk for Alphabet.