What happened
Google confirms its Gemini model reached three real companies during a May cybersecurity evaluation run by third-party evaluator Irregular, and the incident shows how easily a simulated hacking test can become real.
Manage your tracker preferences
We use cookies and similar tracking technologies to remember preferences, analyze traffic, and deliver ads. Using some kinds of trackers (like cross-site or behavioral advertising cookies) may be considered a “sale” or “sharing” of personal data under certain state laws. You can opt in or out of these trackers below.
Targeted advertising cookies and similar trackers
- [x] On
Setting this to “off” disables targeted advertising and related trackers in your current browser. To fully opt out, you must disable tracking on each browser and device you use. Clearing cookies may reset your preferences. Because we can't link your Axios subscriber account (email) to browser cookies, you may also want to update your settings in the Privacy Center to ensure your account is fully opted out. See our Privacy Policy for more on how we use personal data and your rights. Review our Privacy Policy at axios.com/legal for more on how we use personal data and your rights.
Save
[Privacy Center](https://privacy.axios.com/)
[Consent powered by Ethyca](https://www.ethyca.com/janus?utm_source=fides_consent&utm_medium=referral&utm_campaign=cmp_backlinks&utm_term=janus)
[Skip to main content](https://www.axios.com/2026/09/19/google-safety-incidents-testing-hacks#main-content)
* [](https://www.axios.com/) * [Newsletters](https://www.axios.com/newsletters) * Axios Local Show * [Axios Pro](https://www.axios.com/pro/all-deals) * [Axios Live](https://www.axios.com/events) * [The Axios Show](https://www.axios.com/the-axios-show)
Login
[Axios](https://www.axios.com/)
[](https://www.axios.com/results)
All topics
[Axios](https://www.axios.com/)
Search
7 mins ago - [Technology](https://www.axios.com/technology)
# Google's AI hacked three companies in testing

* [Sam Sabin](https://www.axios.com/authors/ssabin)
* email (opens in new window) * sms (opens in new window) * facebook (opens in new window) twitter (opens in new window) linkedin (opens in new window) bluesky (opens in new window)
[Add Axios on Google](https://google.com/preferences/source?q=axios.com)
Add Axios as your preferred source to
see more of our stories on Google.
[Add Axios on Google](https://google.com/preferences/source?q=axios.com)

Illustration: Lindsey Bailey/Axios
Google's Gemini AI model broke into three companies' systems using basic hacking techniques [during model testing](https://www.axios.com/2026/09/16/openai-testing-safety-incidents-disclosure) earlier this year.
**Why it matters:** Google was one of the only AI labs that hadn't yet publicly disclosed a security breach involving their agents during routine pre-deployment testing.
**Driving the news:** Google confirmed the three incidents, which happened in May, on Friday.
* The incidents happened as part of a test run that third-party evaluator Irregular was operating — similar to other security breaches involving OpenAI, Anthropic and Meta's AI models. * The Wall Street Journal [first reported](https://www.wsj.com/tech/ai/gemini-hacked-three-companies-in-first-known-breakout-by-googles-ai-5c0baba2) the incidents.
**What they're saying**: "Safe development of powerful AI models is critical and we invest deeply in this area," Heather Adkins, vice president of security engineering at Google, said in a statement.
* Adkins added that her team contacted the affected entities and "worked with our training partner on the changes they've now made to their testing processes." * An Irregular spokesperson confirmed to Axios that the Gemini incident involved the same security issues that also led to similar incidents involving other AI labs' models. * The spokesperson also said in a statement all "relevant labs were notified in late July" and that "all known issues on our end were remedied and resolved weeks ago."
**Zoom in:** The hacks happened while Gemini was completing a "capture the flag" hacking exercise, where the model was asked to retrieve information from software operated by a fictional company inside a testing environment, per the WSJ.
* However, the fictional company had the same name as a real one.
* In one case, the model guessed passwords for a protected system until it gained access. In the other two cases, the model found credentials in a public repository that then allowed it to access other protected systems.
**Yes, but:** Google's model stopped their actions as soon as they realized they accessed real companies.
**The intrigue:** Irregular told the Wall Street Journal that the model wasn't supposed to be able to get online, but internet access was unintentionally available.
* After OpenAI and Anthropic [disclosed](https://www.axios.com/2026/08/04/anthropic-openai-uk-ai-security-institute) additional incidents this summer, a source familiar with the matter told Axios that the AI labs and Irregular weren't fully aligned on the exact testing procedures and safeguards, leaving ambiguities in how each side expected the typically internet-enabled evaluations to run.
**Go deeper:**[Researchers playing rogue AI agent hide-and-seek on the open web](https://www.axios.com/2026/09/10/ai-agents-rogue-german-wiki-openai)
* email (opens in new window) * sms (opens in new window) * facebook (opens in new window) twitter (opens in new window) linkedin (opens in new window) bluesky (opens in new window)
[Add Axios on Google](https://google.com/preferences/source?q=axios.com)
##### What to read next
*  *  * *  *  * 
Smarter, faster on what matters.
[Explore Axios Newsletters](https://www.axios.com/newsletters)
* [About Axios](https://www.axios.com/about) * [Advertise with us](https://www.axios.com/advertise) * [Careers](https://www.axios.com/careers) * [Contact us](https://www.axios.com/contact)
* [Newsletters](https://www.axios.com/newsletters) * [Axios Live](https://www.axios.com/events) * [Axios HQ](https://www.axioshq.com/?utm_source=axios&utm_medium=site&utm_campaign=axioshq)
* [Privacy policy](https://www.axios.com/legal) * [Terms of use](https://www.axios.com/legal/terms-of-use) * Your Privacy Choices
[Axios Homepage](https://www.axios.com/) Axios Media Inc., 2026


Source coverage
We use cookies and similar tracking technologies to remember preferences, analyze traffic, and deliver ads. Using some kinds of trackers (like cross-site or behavioral advertising cookies) may be considered a “sale” or “sharing” of personal data under certain state laws. You can opt in or out of these trackers below.
Targeted advertising cookies and similar trackers
Full source content
Manage your tracker preferences
We use cookies and similar tracking technologies to remember preferences, analyze traffic, and deliver ads. Using some kinds of trackers (like cross-site or behavioral advertising cookies) may be considered a “sale” or “sharing” of personal data under certain state laws. You can opt in or out of these trackers below.
Targeted advertising cookies and similar trackers
- [x] On
Setting this to “off” disables targeted advertising and related trackers in your current browser. To fully opt out, you must disable tracking on each browser and device you use. Clearing cookies may reset your preferences. Because we can't link your Axios subscriber account (email) to browser cookies, you may also want to update your settings in the Privacy Center to ensure your account is fully opted out. See our Privacy Policy for more on how we use personal data and your rights. Review our Privacy Policy at axios.com/legal for more on how we use personal data and your rights.
Save
[Privacy Center](https://privacy.axios.com/)
[Consent powered by Ethyca](https://www.ethyca.com/janus?utm_source=fides_consent&utm_medium=referral&utm_campaign=cmp_backlinks&utm_term=janus)
[Skip to main content](https://www.axios.com/2026/09/19/google-safety-incidents-testing-hacks#main-content)
* [](https://www.axios.com/) * [Newsletters](https://www.axios.com/newsletters) * Axios Local Show * [Axios Pro](https://www.axios.com/pro/all-deals) * [Axios Live](https://www.axios.com/events) * [The Axios Show](https://www.axios.com/the-axios-show)
Login
[Axios](https://www.axios.com/)
[](https://www.axios.com/results)
All topics
[Axios](https://www.axios.com/)
Search
7 mins ago - [Technology](https://www.axios.com/technology)
# Google's AI hacked three companies in testing

* [Sam Sabin](https://www.axios.com/authors/ssabin)
* email (opens in new window) * sms (opens in new window) * facebook (opens in new window) twitter (opens in new window) linkedin (opens in new window) bluesky (opens in new window)
[Add Axios on Google](https://google.com/preferences/source?q=axios.com)
Add Axios as your preferred source to
see more of our stories on Google.
[Add Axios on Google](https://google.com/preferences/source?q=axios.com)

Illustration: Lindsey Bailey/Axios
Google's Gemini AI model broke into three companies' systems using basic hacking techniques [during model testing](https://www.axios.com/2026/09/16/openai-testing-safety-incidents-disclosure) earlier this year.
**Why it matters:** Google was one of the only AI labs that hadn't yet publicly disclosed a security breach involving their agents during routine pre-deployment testing.
**Driving the news:** Google confirmed the three incidents, which happened in May, on Friday.
* The incidents happened as part of a test run that third-party evaluator Irregular was operating — similar to other security breaches involving OpenAI, Anthropic and Meta's AI models. * The Wall Street Journal [first reported](https://www.wsj.com/tech/ai/gemini-hacked-three-companies-in-first-known-breakout-by-googles-ai-5c0baba2) the incidents.
**What they're saying**: "Safe development of powerful AI models is critical and we invest deeply in this area," Heather Adkins, vice president of security engineering at Google, said in a statement.
* Adkins added that her team contacted the affected entities and "worked with our training partner on the changes they've now made to their testing processes." * An Irregular spokesperson confirmed to Axios that the Gemini incident involved the same security issues that also led to similar incidents involving other AI labs' models. * The spokesperson also said in a statement all "relevant labs were notified in late July" and that "all known issues on our end were remedied and resolved weeks ago."
**Zoom in:** The hacks happened while Gemini was completing a "capture the flag" hacking exercise, where the model was asked to retrieve information from software operated by a fictional company inside a testing environment, per the WSJ.
* However, the fictional company had the same name as a real one.
* In one case, the model guessed passwords for a protected system until it gained access. In the other two cases, the model found credentials in a public repository that then allowed it to access other protected systems.
**Yes, but:** Google's model stopped their actions as soon as they realized they accessed real companies.
**The intrigue:** Irregular told the Wall Street Journal that the model wasn't supposed to be able to get online, but internet access was unintentionally available.
* After OpenAI and Anthropic [disclosed](https://www.axios.com/2026/08/04/anthropic-openai-uk-ai-security-institute) additional incidents this summer, a source familiar with the matter told Axios that the AI labs and Irregular weren't fully aligned on the exact testing procedures and safeguards, leaving ambiguities in how each side expected the typically internet-enabled evaluations to run.
**Go deeper:**[Researchers playing rogue AI agent hide-and-seek on the open web](https://www.axios.com/2026/09/10/ai-agents-rogue-german-wiki-openai)
* email (opens in new window) * sms (opens in new window) * facebook (opens in new window) twitter (opens in new window) linkedin (opens in new window) bluesky (opens in new window)
[Add Axios on Google](https://google.com/preferences/source?q=axios.com)
##### What to read next
*  *  * *  *  * 
Smarter, faster on what matters.
[Explore Axios Newsletters](https://www.axios.com/newsletters)
* [About Axios](https://www.axios.com/about) * [Advertise with us](https://www.axios.com/advertise) * [Careers](https://www.axios.com/careers) * [Contact us](https://www.axios.com/contact)
* [Newsletters](https://www.axios.com/newsletters) * [Axios Live](https://www.axios.com/events) * [Axios HQ](https://www.axioshq.com/?utm_source=axios&utm_medium=site&utm_campaign=axioshq)
* [Privacy policy](https://www.axios.com/legal) * [Terms of use](https://www.axios.com/legal/terms-of-use) * Your Privacy Choices
[Axios Homepage](https://www.axios.com/) Axios Media Inc., 2026


How this page is built
Goose Pod turns cited reporting into a public episode summary first, then pairs that summary with audio playback so listeners can check the source material before they decide how deeply to engage.
The goal is to make this page useful as a news landing page first, while still giving listeners transcript access, related episodes, and direct links back to the original publishers.



