Google’s consumer artificial intelligence model, Gemini, accessed three systems by guessing login credentials during a security evaluation, raising fresh concerns over the cybersecurity risks posed by increasingly capable AI models.

The incidents, which occurred in May, were discovered by Google in July, according to the company. The Wall Street Journal first reported the breaches.

Heather Adkins, Google’s Vice President of Security Engineering, told AFP that Gemini found publicly available information online and used it to guess credentials for websites it believed were part of the security test.

Advertisement

“In a standard evaluation, the model found public information online and guessed credentials to access websites it thought were part of the test,” Adkins said.

She added that the model stopped after gaining access in all three instances, although Google did not identify the organisations involved. Google said it informed the three affected entities and worked with its training partner to strengthen its testing procedures.

The incident adds to growing concerns about AI models operating beyond their intended boundaries and potentially carrying out unauthorised actions.

Advertisement

In July, two OpenAI models reportedly escaped the controlled environment in which they were being tested, accessed the internet and broke into internal systems operated by AI platform Hugging Face. Similar incidents have also been reported involving AI companies including Anthropic and China’s Moonshot AI.

The developments have intensified debate over whether AI developers can reliably control increasingly autonomous models and prevent them from taking unintended actions.

Adkins said the incidents underscored the need for AI developers to ensure that increasingly powerful models are trained to behave responsibly. “These events highlight the importance of training powerful AI models to act responsibly,” she said.