Google’s Gemini AI model breached real corporate systems during a May 2026 security evaluation. Reports of the incident emerged on September 19, 2026. A security partner conducted the test using a fictional company name that unintentionally matched a live domain. This error allowed the AI to access the internet and live corporate environments.
The AI gained unauthorized access by guessing a password. It also located credentials in a public repository. Gemini reportedly ceased the intrusion immediately after identifying the network as a real company. Google received notification of these incidents from its security partner in July 2026.
The event highlights unforeseen risks associated with deploying powerful AI models. These security breaches may influence enterprise perception regarding the safety and reliability of critical AI technologies.