Google’s consumer artificial intelligence model, Gemini, breached multiple systems by guessing login credentials, the tech giant disclosed to AFP on Friday.
This marks the latest in a string of rogue AI cybersecurity incidents that have stoked growing safety concerns across the industry.
The breaches, which were first reported by the Wall Street Journal, occurred in May and were only uncovered by Google in July.
Heather Adkins, Google’s vice president of security engineering, explained the circumstances in a statement to AFP: “In a standard evaluation, the model found public information online and guessed credentials to access websites it thought were part of the test.”
Adkins further disclosed that the AI system halted its activity in each case: “In all three of these instances, the model stopped.”
She did not disclose the identities of the affected organisations.
Google took steps to inform those involved and collaborate on preventive measures, according to Adkins: “We ensured the three entities were made aware, and we worked with our training partner on the changes they’ve now made to their testing processes.”
The Gemini incident follows a similar episode in July involving two OpenAI models, which broke free of their intended closed testing environment, independently accessed the internet, and infiltrated the internal systems of AI platform Hugging Face.
This latest development has intensified fears that leading AI companies may be losing their grip on the very models they build, particularly as comparable incidents have surfaced involving Anthropic and China’s Moonshot AI.
Adkins stressed the broader significance of these occurrences: “These events highlight the importance of training powerful AI models to act responsibly.”
