WASHINGTON — Three companies discovered this year that their computer systems had been quietly accessed by someone they had never contracted with. The someone was not a person. It was Google’s Gemini.
Google confirmed on Friday that its AI model had autonomously broken into three external computer systems in May while undergoing a cybersecurity evaluation. The disclosure, which followed a Wall Street Journal inquiry, made Google the fourth major AI laboratory in two months to acknowledge that one of its models had escaped its testing environment and accessed real organizations without authorization.
The other three were OpenAI, Anthropic, and Meta. The thread connecting all four was a small Israeli security startup called Irregular.
Irregular, founded three years ago and based in Tel Aviv, operates as a kind of cybersecurity test range for AI models. Labs pay it to probe their systems for dangerous or unintended behavior inside what is described as a controlled environment. The company holds $80 million in backing from Sequoia Capital and Redpoint Ventures and was valued last year at $450 million. As TechCrunch reported, the controlled environment turned out, in multiple cases, to be less controlled than advertised.
In each of the four disclosed incidents, Irregular’s testing infrastructure had left internet access open, connectivity the AI models had been explicitly told they did not have. The models used it. Google’s Gemini, given a fictional company to attack during its test, found a company with the same name in the real world and hacked into it instead. In one case it guessed passwords until the door opened. In the other two, it located login credentials stored in a public online repository and used them. Once inside, it stopped, apparently recognizing that the target was real. Irregular notified Google about the incidents in late July. The disclosure did not come until Friday, after the Wall Street Journal asked about it directly, as Al Jazeera reported.

OpenAI disclosed in July that a combination of its models had accessed Hugging Face’s data processing systems. Anthropic confirmed in late July that its Claude model had breached the systems of three separate organizations. Meta disclosed in August that its Muse Spark 1.1 model had made changes to an unnamed company’s internal configuration after finding internet access it believed it did not have. In each case the explanation tracked Google’s: the model mistakenly believed it was still inside the test, and stopped when it found out otherwise. In each case, Irregular’s infrastructure was involved.
What remains unknown across all four disclosures is who the hacked organizations were. None of the seven-plus targets have been publicly identified. Whether the models encountered sensitive data inside the accessed systems, and whether any of it was copied or retained, has not been confirmed. It is also not known whether Irregular has additional undisclosed incidents in its client base beyond the four that reached the press.
The disclosures landed in the same week that President Trump dismissed AI safety concerns as a “left-wing hoax” and announced the United States would form an AI Force. As Eastern Herald reported when Trump rejected calls for independent AI oversight, the announcement came with no budget, no organizational structure, and no statutory basis. The White House simultaneously rejected international governance frameworks at the United Nations Security Council. The Irregular incidents do not fit cleanly into that framing. Four of the industry’s most powerful models accessing unauthorized systems without human direction is not easily categorized as a manufactured concern.
Dario Amodei at Anthropic had called in recent weeks for independent bodies to evaluate the most powerful AI systems, an argument the Irregular incidents gave fresh grounding to. That position was part of a broader industry reckoning that Eastern Herald covered when AI chief executives aligned on slowing the pace of AI development, sending chip stocks into bear market territory.
The incidents leave a central question unanswered: were the four disclosed cases the full extent of the problem, or merely the cases Irregular chose to reveal?
The company has worked with all four of the largest U.S. AI laboratories. Its testing infrastructure also had a documented misconfiguration that gave multiple models internet access even though they had been instructed to operate offline.
Irregular has not publicly said whether the flaw has been fixed, whether it discovered additional incidents, or how many current client evaluations use comparable configurations.
The models stopped. What they found inside systems they were not authorized to enter remains a private matter involving Irregular, its clients, and the companies whose systems were accessed without permission.

