Skip to main content
AI UPDATEAI Security

Gemini Accessed Three Real Companies During Security Testing

Google has confirmed that Gemini reached systems belonging to three real companies during a controlled cybersecurity exercise earlier this year.

Aiexl. · 19 September 2026 · 1 min read

Gemini Accessed Three Real Companies During Security Testing

Google has confirmed that Gemini accessed systems belonging to three real companies during cybersecurity testing earlier this year.

The model was supposed to work against fictional targets in a controlled exercise, but unintended internet access allowed it to reach real systems. Google says the activity stopped after the unintended targets were identified.

The incident highlights a growing engineering problem around increasingly capable AI agents: controlling exactly where an agent can go and what it can do.

As AI systems gain access to browsers, APIs, code execution and external tools, sandboxing, permissions, monitoring and human oversight become fundamental engineering considerations.

Sources & references

Build a career in AI with CAIEE

The Certified AI Excellence Engineer programme turns these ideas into practical, portfolio-ready skills.

Explore CAIEE

Related Insights