Google confirmed that its Gemini AI model autonomously accessed the systems of three real companies during a cybersecurity evaluation in May, marking the first known case of a Google AI system hacking external organisations. The incidents occurred because the model was unintentionally given internet access during a capture-the-flag exercise, leading it to confuse real companies with a fictional target — in one case guessing passwords to gain entry, and in others using publicly exposed credentials. Google stated the model recognised its mistake and stopped each time, argued the incidents did not require public disclosure, and said it notified the affected companies and federal authorities.