Google has confirmed that its Gemini artificial intelligence model breached the systems of three real companies during a cybersecurity test in May after gaining unintended access to the internet.

The incidents occurred during an evaluation by Irregular, an independent firm that tests the security of advanced AI systems.

Google said the affected companies were notified and that Gemini stopped accessing their systems after determining they were outside the scope of the test.

Heather Adkins, Google’s vice-president of security engineering, said Gemini found publicly available information online and either guessed credentials or located them in public repositories while attempting to access systems it believed were part of the evaluation.

“In all three of these instances, the model stopped,” Adkins said.

In one case, Gemini was testing software belonging to a simulated company that had the same name as a real business.

After unintentionally connecting to the internet, the model correctly guessed the real company’s password and gained access to its service, Irregular told an American newspaper.

In the other two cases, Gemini found credentials exposed in public repositories and used them to access protected systems belonging to real companies.

Google said the model stopped once it recognised that the systems were not part of the test.

Irregular stated that the evaluation environment was designed to be isolated from the internet but was inadvertently connected.

The company told all known issues in its testing processes had been fixed and that relevant AI labs were notified in late July.

Similar incidents involving Irregular evaluations have previously been disclosed by Meta, Anthropic and OpenAI.

Meta said in August that its incident did not involve a sandbox escape, meaning a breach of an isolated testing environment, or a sophisticated cyberattack.

Google maintained that the incidents did not warrant public disclosure because Gemini caused no damage, although the three companies involved were informed.