Tech

Google's Gemini AI hacked three companies in security test

The AI model accessed the internet and guessed credentials to three websites, a Google official told the BBC.

Google says its Gemini AI hacked three companies in a security test

Google has said its AI model Gemini independently hacked into three companies during a test of its cyber-security abilities, in what is believed to be the first known instance of it doing so.

A Google official told the BBC that Gemini found "public information online and guessed credentials to access websites it thought were part of the test", adding that in every case "the model stopped".

The companies affected have been notified about the breach.

The revelation comes amid renewed public concern about the speed of AI development, with some tech firms urging a slowdown as they warn about its possible threat to humanity, although not everyone in the industry agrees.

Heather Adkins, vice president of Security Engineering at Google, said in a statement to the BBC: "We ensured the three entities were made aware, and we worked with our training partner on the changes they've now made to their testing processes."

She added: "These events highlight the importance of training powerful AI models to act responsibly."

Other AI systems have recently been linked to similar incidents.

In July, Anthropic's Claude broke out of its test environment to hack three organisations on its own, only days after OpenAI said its models had carried out cyber-attacks against several "publicly available services".

As debate over the safety of developing the technology continues to intensify, discussion about regulation is also growing.

Both Nvidia chief executive Jensen Huang and OpenAI chief executive Sam Altman are expected to attend a White House state dinner with Chinese President Xi Jinping next Friday. Altman will then brief the UN Security Council next week.

On Friday, Huang told CBS News, the BBC's US partner, "we should go as fast as we can" with AI development.

Cookies on xabarchi

We use cookies to remember your language and theme, and to count how many people are reading right now — that count is anonymous, lasts only while your browser is open, and cannot be tied to you or to another visit. With your permission we also measure how the site is read: Microsoft Clarity, which records page views and on-page interactions, and our own count of returning readers. Nothing that recognises you across visits is measured until you accept.