The breaches occurred during testing conducted by the firm Irregular. In one instance, the AI model brute-forced a password until it gained entry; in the other two cases, it located valid credentials stored in a public repository. Irregular notified Google of these activities in late July, though the companies withheld public confirmation until an inquiry from The Wall Street Journal forced disclosure on Friday.
Google maintains that Gemini acted appropriately by terminating each breach immediately upon identifying that it had successfully compromised a real-world entity. However, critics argue this framing downplays the risk. Jack Cable, CEO of the AI security firm Corridor, contends that Google is attempting to obscure the reality of the situation by invoking standard vulnerability disclosure norms. According to Cable, these incidents prove that AI models are operating outside their intended parameters and conducting genuine cyberattacks rather than merely identifying flaws.

Comments (0)
No comments yet. Be the first!