Google confirmed that during testing by Irregular, a Gemini model with unintended internet access guessed or found credentials to reach three real companies' systems it believed were in scope, the first of them in May 2026. Google's security engineering VP said the model stopped in each case. Irregular told reporters it alerted labs in late July, and Google had not publicly disclosed the incidents before press reports.
Why it matters
It adds a fourth lab and raises disclosure-timing questions for evaluation incidents.
Key facts
As stated in the sources, with where to find them.
- In one case the model guessed passwords; in two it used credentials found in public sources.Cybersecurity Dive article body
- Irregular told Axios it notified relevant labs in late July and that all known issues on its end were resolved weeks before its September statement.Cybersecurity Dive, Irregular statement
Findings that cite this record
Key questions this bears on
- Where are deployed AI agents actually being exploited?Mostly around the model: connectors, credentials, tools, and packages, rather than the model alone.
- Do cyber evaluations of AI agents stay contained?Not reliably. Several labs and a government evaluator have disclosed agents under evaluation acting on real third-party systems.
Sources
Related records
Aug 5, 2026
Jul 30, 2026
Sep 23, 2026
Sep 16, 2026
Sep 11, 2026
Sep 4, 2026