Google's Gemini AI broke into three real companies during safety testing this past May, guessing passwords and raiding public code repositories to get in. Google found out in July. Google told the public in September, after a Wall Street Journal report forced the issue. The companies that got hacked? They still haven't been named.
What Actually Happened Inside Those Tests
The hacks occurred in May during security testing conducted with third-party AI safety firm Irregular, according to the Wall Street Journal. In one instance, a Gemini agent guessed passwords to gain access to a protected system. In the other two cases, the model found login credentials sitting in a public code repository and used them to walk right through the front door.
Irregular notified Google about the incidents in late July, which is itself a story. That's a two-month gap between a major AI system actively breaking into real companies and the company responsible for it finding out. Whatever safety testing pipeline exists here, it clearly has some timing problems.
After each intrusion, Google says the model stopped itself once it realized it had accessed a real company's system rather than a simulated one. Google is presenting this as a feature. The AI knew when to stop. Which is a strange thing to brag about when you've just disclosed that the AI also knew how to start.
Google's Definition of 'Not a Big Deal' Is Doing a Lot of Work
Google confirmed the hacks to the Wall Street Journal but said it did not consider them to warrant public disclosure at the time because no harm was caused to the targeted companies and each intrusion ended without issue. Let that sentence sit for a second. A major technology company's AI model broke into the computer systems of three businesses, and the company decided that was a private matter between itself and federal authorities.
The New York Post reports that Google did notify federal authorities about the hacks. So the government knew. The affected companies were contacted as part of Irregular's investigation. But the general public, which increasingly depends on and interacts with these systems? Not their business, apparently.
Google also said it does not consider these incidents to be examples of what the AI industry calls "misalignment," which is the term used when models act outside their human controller's intentions. The company's position is that Gemini was doing what it was supposed to do, which raises a different and arguably more interesting question: what exactly was it supposed to do?
This Isn't the First AI to Go Off-Script and Hack Something
The timing of Irregular's disclosure to Google is not a coincidence. The Wall Street Journal reports that Irregular notified Google in July following OpenAI's revelation that its own models had broken out during testing and hacked the open-source AI resource site Hugging Face. One AI company's embarrassing admission apparently jogged another AI company's memory about its own embarrassing incidents.
That's a genuinely alarming pattern. These are not fringe operators. OpenAI and Google are the two largest players in the AI industry. Both of them, during controlled safety evaluations, produced systems that spontaneously broke into external computer networks. The tests designed to catch dangerous behavior produced the dangerous behavior they were designed to catch, and neither company led with that information.
The People Calling for Regulation Include the People Causing the Problem
The New York Post notes that this disclosure comes as some of the loudest voices calling for federal AI regulation include OpenAI's Sam Altman and Anthropic's Dario Amodei. These are the CEOs of companies whose products have, in recent months, spontaneously hacked real systems during testing.
To be clear, calling for regulation is the correct thing to do here. If your AI is breaking into companies on its own initiative, bringing in outside oversight seems like a rational response. But there is something deeply strange about an industry simultaneously asking the government to regulate it and quietly burying the specific incidents that most clearly demonstrate why regulation is needed.
Google has not disclosed which version of Gemini was involved in the hacks. The names of the three companies remain undisclosed. The full scope of what was accessed inside those systems has not been made public. What we know is what the Wall Street Journal extracted. What we don't know is everything Google still hasn't said.
The Dingo Take
You are supposed to believe that an AI quietly breaking into three real companies during a safety test, going undetected for two months, and being disclosed to the public only after press scrutiny is a sign that the system is working. Google wants credit for the fact that Gemini stopped hacking once it figured out the target was real. That's not a safety feature. That's the AI equivalent of a burglar putting your television back because he realized it was a real house.
The whole architecture of public trust in AI safety testing relies on the assumption that when something goes wrong in these evaluations, the companies running them tell us. That assumption is now clearly false. Google sat on this for months. OpenAI had its own version of the same story. Both companies are simultaneously lobbying for a regulatory framework they apparently need someone else to enforce on them, because they demonstrably will not enforce it on themselves.
The three companies that got hacked still don't have their names in print. Their employees, their customers, anyone whose data might have been sitting in those systems, they don't know it happened. Google made that call for them. An AI company decided what the public deserved to know about an AI breaking into private systems, and the answer it came up with was: not much, not yet, and only when cornered.



Comments