Google’s Gemini broke into three real companies’ systems during a May cybersecurity test run by Irregular, which Google confirmed Friday only after the Wall Street Journal started asking. Irregular had flagged it to Google at the end of July, just after OpenAI’s agents were caught hacking Hugging Face. The model was working a capture-the-flag exercise against a fictional target that shared a name with a real company, and internet access it was never meant to have let it guess a password in one run and pull credentials out of public repositories in two others. Google says none of this counts as misalignment because the model quit each time it worked out the target was real, and it likens what happened to a bug bounty. Anthropic’s Claude Opus 4.7 didn’t quit in the same exercise.






