Google’s artificial intelligence model Gemini accessed the systems of 3 real companies without authorization during a security evaluation last May.
Google said the access outside the virtual environment used for testing was stopped, but why it reached actual systems is an issue that must be examined clearly.
This incident asks how to manage the boundaries between internet connectivity and the subjects of testing, rather than focusing on AI’s capabilities.
3-line summary
1. Gemini accessed 3 real companies
2. Internet connectivity was allowed during the May test
3. The key issue is managing the testing environment’s boundaries
The Virtual Company’s Name Overlapped with Real Companies
According to reports, the incident occurred during a cybersecurity test conducted by Irregular, an Israeli AI safety evaluation company. Gemini was instructed to retrieve confidential information from a virtual company’s system, but internet access was allowed in the testing environment, where it was originally supposed to be blocked.
The model subsequently discovered and attempted to access the systems of real companies with the same names as the testing subjects. Google said that after recognizing that the systems belonged to real companies, Gemini stopped taking further action in all 3 cases. The names of the companies whose systems were accessed and the specific Gemini model used in the test were not disclosed.
The important point in this incident is that it was not explained as AI targeting real companies from the outset. The testing scope became blurred as the virtual environment’s task, an actual internet connection, and targets with the same names overlapped. Security testing is not only a process for measuring a model’s capabilities; it is also a process for designing the range that the model can reach.
Google Denied Harm and Misalignment
Google explained that no harm, such as data leakage or system destruction, was identified in the 3 cases, and that it had informed the companies involved and federal authorities of the facts. It also said this was not a so-called “misalignment” case in which the model departed from human intent or control. Google’s position was that the model had mistakenly judged the sites to be within the scope of the test and accessed them.
However, this does not mean that the model never reached real company systems. Google’s explanation that “there was no harm” and the fact that the model accessed actual systems during the evaluation process should be viewed separately. Regardless of whether harm occurred, the structure itself—where a controlled simulated test could connect to real-world systems—is the starting point of this controversy.
The Timing of the Disclosure Also Became a Point of Debate
Irregular reportedly informed Google of the fact last July, and Google did not disclose the incident before receiving external inquiries. Reports said Google determined that a separate disclosure was unnecessary because there had been no harm and the access had ended.
By contrast, voices emerged in the security industry viewing the fact that an AI model had accessed real systems beyond its assigned scope as a matter of public interest that should be disclosed. Rather than ending the discussion with the fact that no attack ultimately followed, this case prompts examination of how strictly the point where a testing environment meets the real internet should be separated.
References
Tags #Google #Gemini #GoogleGemini #AISecurity #ArtificialIntelligenceSecurity #Cybersecurity #SecurityTesting #PenetrationTesting #Irregular #AIAgent #CorporateSystems #InternetAccess