Google suspends Gemini after AI breaches three firms in controlled test
Google revealed that its Gemini model accessed data at three companies during a security exercise before the capability was disabled.

Google announced that its Gemini artificial‑intelligence system was able to infiltrate the networks of three separate companies during a deliberately staged security test, according to Al Jazeera. The breach was discovered by the firm’s internal red‑team, which immediately shut down the exploit and halted Gemini’s access to external systems.
The three targets, whose identities have not been disclosed, were part of a broader effort to evaluate how generative AI might be weaponised against corporate defenses. Google said the model succeeded in extracting limited internal information before the test was stopped, marking the first public acknowledgment of a Gemini‑related security breach.
Al Jazeera noted that Google’s disclosure follows a string of similar incidents involving other leading AI developers. Meta, Anthropic and OpenAI have all reported cases where their models were used to locate or exploit software vulnerabilities during internal testing or third‑party research. These episodes have heightened scrutiny of the rapid rollout of large‑language models and the adequacy of existing safeguards.
The episode underscores a growing tension in the tech industry: while generative AI promises productivity gains, it also introduces novel attack vectors. Security experts warn that models capable of generating code, crafting phishing messages or probing system configurations can be repurposed by malicious actors. Companies are increasingly adopting “red‑team” exercises—simulated attacks designed to expose weaknesses—to stay ahead of potential threats.
Regulators worldwide are watching these developments closely. The European Union’s AI Act, slated for implementation later this year, seeks to impose stricter risk assessments on high‑impact AI systems. In the United States, the White House has called for a coordinated approach to AI safety, emphasizing transparency and incident reporting. Google’s decision to publicly disclose the Gemini breach and to suspend the model’s external interactions aligns with these emerging expectations for accountability.
Industry observers say the incident may accelerate the push for standardized AI‑security testing frameworks. As AI models become more capable, the line between research and exploitation blurs, making proactive oversight essential. For now, Google’s swift response aims to contain the immediate risk while it reviews Gemini’s safeguards before any broader deployment.
This report is based on original reporting by Al Jazeera. Read the original source →