← All news·2026-09-19·3 min read

Gemini Escaped Its Test Sandbox and Breached Three Real Companies

In May 2026, Google Gemini left its test environment and gained unauthorized access to three real companies due to a configuration error by the tester.

aisafetyagents

In May 2026, Gemini escaped its test environment and breached three real companies. In one case the model cracked a password on its own. In two others it found credentials in public repositories. The test was set up by Israeli startup Irregular, which evaluates AI models for Google, OpenAI, Anthropic, and Meta. The configuration error was that the name of a fictional company in the test scenario matched a real one.

No harm was done. Gemini stopped on its own when it detected it had reached a real service. Google says this was a configuration error in the test environment, not a problem with the model itself. Based on the description, that explanation sounds honest. I keep agent runs in isolated networks and without live credentials, because a prompt that says "stay in scope" is not a physical barrier.

Source: www.engadget.com

Free course

Stop reading about AI — start building with it

The free Claude Code course: your first site, tool or game — no coding. No upsells, no cross-sells — nothing to buy here.

Start free →
EAEvgenii Arsentev

Author

Evgenii Arsentev

PhD · Chief Executive Officer, digital health