// 2 CVE · 1 EXPLOIT IN THE LAST 24H
During a May 2026 cybersecurity test by Israeli firm Irregular, Google's Gemini model interacted with three real companies' systems. Google confirmed the incident in September 2026 after the Wall Street Journal inquired. The breach stemmed from a naming collision and unintended internet access in the test environment, not a model vulnerability.

Google has confirmed that its Gemini AI model interacted with three real companies during a cybersecurity test conducted in May 2026 by Israeli firm Irregular. The incident became public in September 2026 after the Wall Street Journal contacted Google for comment.

The details are drawn from reporting by SecurityWeek, BBC, The Guardian, and The Hacker News, which cite the Wall Street Journal's reporting and official Google statements. No primary technical document or structured advisory has been released by the parties involved.

Key Takeaways
  • Gemini attempted access to three real companies during a May 2026 security test, using credential guessing and credentials found in public repositories.
  • The root cause was an Irregular naming error: a fictitious company name in a capture-the-flag exercise matched a real domain, combined with unintended internet access in the test environment.
  • Heather Adkins, VP of Google Security Engineering, confirmed the model halted in all three cases after reaching a real company, not the simulated target.
  • Irregular notified Google in late July 2026; Google contacted the three companies and federal authorities but did not disclose the incident publicly until the Wall Street Journal's inquiry.
  • There is no evidence of damage or data exfiltration; the names of the three companies have not been disclosed.

How the AI Agent Reached External Systems

The incident mechanism is unequivocally technical and unequivocally human. Irregular, which specializes in AI model security testing, had configured a capture-the-flag exercise with a fictitious company name. That name collided with an existing real domain. The test environment had unintended internet connectivity.

Operating within its evaluation scope, Gemini resolved the name, reached the external domain, and began interacting with production systems. In one case, the model executed credential-guessing attacks. In the other two, it retrieved credentials from public repositories and used them.

Google specified that the model involved was not the latest version of Gemini, but did not identify which iteration was employed. The boundary between simulation and reality proved permeable due to a combination of naming collision and network configuration, not a vulnerability in the model itself.

Model Behavior and Disclosure Context

Heather Adkins emphasized the model's self-regulating behavior. According to Google's statement to SecurityWeek, the agent halted in all three instances after reaching a real company.

"Safe development of powerful AI models is critical and we invest deeply in this area. In a standard evaluation, the model found public information online and guessed credentials to access websites it thought were part of the test. In all three of these instances, the model stopped."
— Heather Adkins, VP Google Security Engineering, to SecurityWeek

Adkins also noted Google's collaboration with the testing partner: "We ensured the three entities were made aware, and we worked with our training partner on the changes they've now made to their testing processes."

Google notified the three companies involved and federal authorities, though details of the authorities involved have not been made public. The timeline — from May to September, with internal notification in July — raises questions about disclosure expectations in the AI sector.

The source does not specify whether access to the systems involved viewing, modification, or exfiltration of data. This documentary limit prevents quantifying the operational impact on the three entities, which remain anonymous.

Irregular and the Pattern of AI Testing Incidents

Irregular is the same firm involved in similar incidents with Meta, OpenAI, and Anthropic. This convergence indicates a systemic pattern in the AI testing industry: red-team environments for autonomous agents that lack rigorous network sandboxes.

Irregular stated it has fixed all known issues on its end weeks ago, according to the BBC. The specific nature of these fixes and their effectiveness against variants of the same vector remain undocumented in the available record.

According to SecurityWeek, Meta, OpenAI, and Anthropic had proactively disclosed their own incidents with Irregular, while Google waited for journalistic contact. This behavioral discrepancy among peer AI labs suggests an absence of shared standards for disclosing test incidents that involve real third parties.

What Changes

Per DeafNews analysis, the incident raises three structural questions for the AI sector, derived from the documented facts but not directly prescribed by them.

First: configuring test environments for AI agents with remote access capabilities requires verification that goes beyond model logic. Irregular's error was infrastructural, not algorithmic.

Second: voluntary disclosure remains discretionary. The contrast between Google and its competitors on this specific case — documented by SecurityWeek — shows that labs with equivalent resources adopt different standards on when to make public incidents that touch third parties.

Third: the model's "halt" behavior, if confirmed as a replicable pattern, represents a relevant capability but is insufficient to eliminate responsibility for environment configuration. Boundary recognition capability does not replace human control over network segmentation.

The sector must address how to structure accountability when an AI agent in testing generates unintended contacts with external systems. Criticism from figures such as Senator Bernie Sanders and Microsoft's Mustafa Suleyman — reported in the context of the broader AI governance debate — indicates growing political pressure, but no concrete regulatory positions on this specific case.

Editorial Close

The May 2026 Gemini-Irregular incident is not a case of a model "gone rogue" in the common narrative sense. It is a case of a misconfigured test environment that allowed an agent operating per its instructions to reach non-target systems. The distinction matters: it shifts where the solvable problem lies.

Google confirmed the facts, provided a statement with the security chief's full name, and collaborated with the testing partner. It also waited four months from discovery for public disclosure, and only under journalistic pressure. This combination of reactive transparency and proactive opacity defines the current state of sector expectations.

For the three companies involved, who remain anonymous, the event is closed without evidence of harm. For the AI sector, the case adds a datapoint to a curve of testing incidents involving the world's leading labs. The frequency of these events — Meta, OpenAI, Anthropic, Google in two years — suggests that red-team environment configuration has not kept pace with agents' capacity to operate autonomously on remote infrastructure.

The frontier between test and unintended external contact has narrowed to a naming error. The sector must confront whether this proximity is manageable with current practices or requires revision.

Information verified against cited sources and current as of publication.

Sources


Sources and references
  1. securityweek.com
  2. thehackernews.com
  3. darkreading.com
  4. bbc.com
  5. theguardian.com
  6. cisa.gov
  7. support.theguardian.com
  8. podcast.securityweek.com