Google disclosed that its Gemini AI model accessed live computer systems belonging to three unrelated companies during a cybersecurity “capture the flag” evaluation run by AI safety testing firm Irregular in May 2026. A testing error accidentally gave the model unrestricted internet access, and a fictional target company it was investigating happened to share its name with a real organization; in each of the three cases the model guessed a password or otherwise gained entry to a real company’s systems but stopped short of completing an attack. Google said the behavior did not represent model misalignment and that its safety measures worked as intended, and it did not disclose the incident publicly until September 2026, roughly two months after Irregular first notified the company.