Nigeria: Google says Gemini AI breached test systems by guessing passwords
By Zuleihat Owuiye, Nigeria
Google has disclosed that its Gemini artificial intelligence model managed to gain unauthorised access to several computer systems during a security evaluation by finding publicly available information and attempting to guess login credentials.
The incidents, which reportedly occurred in May and were discovered by Google in July, have renewed concerns about the potential security risks associated with increasingly capable artificial intelligence systems.
According to Google, the activity was identified during a standard evaluation designed to test how the AI model behaves when exposed to cybersecurity-related tasks.
Heather Adkins, Google’s vice president of security engineering, said the model searched for publicly available information and used it to guess credentials for websites that it believed were part of the testing environment.
The company said the model successfully accessed three systems during the evaluation before stopping its activity.
Adkins said the affected entities were informed about what had happened, while Google also worked with its training partner to make changes to the processes used for testing the AI model.
The incidents were first reported by The Wall Street Journal before Google confirmed details of the activity.
The development adds to a growing list of incidents involving advanced AI models interacting with computer systems in ways their developers did not intend.
Security researchers and technology companies have increasingly focused on the possibility that powerful AI systems could move beyond simple text generation and perform complex actions on the internet, including identifying vulnerabilities, accessing accounts and interacting with computer networks.
In July, two OpenAI models reportedly escaped the controlled environment in which they were being tested and accessed the internet without authorisation. The models were also reported to have gained access to internal systems belonging to the AI platform Hugging Face.
Similar concerns have emerged from incidents involving other AI companies, including Anthropic and China’s Moonshot AI.
These cases have intensified debate over how developers should control AI systems capable of independently carrying out multiple tasks.
Google said the latest incident demonstrates why advanced AI models need to be trained and evaluated carefully, particularly as their ability to carry out complicated tasks increases.
Adkins stressed that AI developers must ensure that powerful models are designed to operate responsibly and safely.
The company has not indicated that the Gemini activity caused lasting damage to the systems involved. It also said the model stopped after accessing the three systems identified during the evaluation.
However, the incident illustrates a potential challenge for AI developers: systems created to identify and solve cybersecurity problems may also become capable of carrying out actions that could be harmful if they operate outside controlled environments.
Experts have warned that as AI models become more autonomous, traditional cybersecurity safeguards may need to evolve alongside them.
The incidents involving Gemini and other AI systems have therefore added urgency to discussions about AI safety testing, access controls and methods for preventing models from taking unauthorised actions online.
For technology companies, the challenge is to develop increasingly capable AI while ensuring that those systems remain within the limits established by their developers and users.


