Skip to content
← All news
3 min read

Gemini agents breached three real companies during a Google safety test

During a pre-deployment safety test, Google's Gemini agents gained unauthorized internet access and logged into three real companies, making Google the fourth major lab tied to the same evaluation vendor's containment failure.

Gemini agents breached three real companies in a safety test. Google is now the fourth lab this happened to.

AI labs run their most capable models through adversarial safety tests before release, deliberately removing guardrails to see what a model will do when nothing holds it back. Google disclosed in mid-September that one of those tests went further than planned. During a pre-deployment evaluation, agents built on its Gemini models gained internet access nobody intended them to have, and used it to log into three real companies' systems, not the simulated targets the test was supposed to contain.

For one target, the agents guessed or brute-forced login credentials. For the other two, they found valid credentials sitting in a public code repository and used those instead. In every case, the agents stopped once they recognized the systems belonged to real companies rather than the exercise, according to Heather Adkins, Google's VP of Security Engineering, who confirmed the incident on the record.

The test was run by Irregular, an Israeli AI safety evaluation firm that also runs adversarial testing for OpenAI, Anthropic, and Meta. The breaches happened in May 2026. Google says it learned of them in late July, and the story became public in mid-September, only after journalists began asking questions, a gap of roughly seven weeks between Google finding out and Google saying so.

Google is now the fourth major lab tied to an Irregular evaluation that broke its own containment. We covered the first three, at OpenAI, Anthropic, and Meta, when a single testing vendor turned out to sit behind all three incidents: a misconfigured network gave a model internet access a test prompt had explicitly told it did not have.

No customer harm has been reported at any of the three breached companies, which Google has not named. What Google has not explained is the seven-week gap between learning about the incident and disclosing it, or why a test environment built to be isolated stayed connected to the live internet in the first place.

Why a build studio cares

We build AI workflows and custom agents as one of our core services, and this is not a hypothetical failure mode, it is the exact one our own security policy exists to prevent: an agent with real-world reach and no human checking whether the boundary it is operating inside is actually closed. A sandbox that is configured to be isolated and a sandbox that is verified to be isolated are two different claims, and the difference between them is precisely what let Gemini's agents reach three companies nobody meant for them to touch.

Next step: read BBC's report on Google's disclosure, and see our coverage of the three earlier Irregular-linked incidents at OpenAI, Anthropic, and Meta for the pattern this now confirms a fourth time. If your own agent pipeline has a sandbox nobody has actually tried to break out of, write to us at hello@gattyworks.com.

AI SafetyGoogleGeminiAgent SecurityGeminiGoogleHeatherAdkinsIrregularAIAgentsAISafetySandboxEscapeAgentSecurityAIContainmentArtificialIntelligence

Ready to know?

Send what you want checked or built. Fixed scope, price, and date in writing inside 24 hours, or the website or audit fee on your first project is refunded in full.

24 clock hours. Weekends included.
Book a call