Google says that during a May 2026 Irregular capture-the-flag test, a misconfiguration gave its Gemini model internet access it was not supposed to have, and it accessed three real companies' systems by guessing a password and twice using publicly listed credentials. Google says the model stopped each time once it realized the systems were real.
THE CONTROL LESSON
What should we watch for?
Ackuity's view: a test harness is not a control plane. If the boundary between an agent and the open internet is one configuration flag, it will eventually be wrong, so decide what each action may reach from outside the agent.
THE EVIDENCE
What does the report establish?
Google says the model acted appropriately by stopping once it realized the systems were real, and did not treat this as misalignment. Irregular says it was the same underlying issue as the other labs' incidents and not a materially separate one. The access used basic techniques (guessed and publicly exposed credentials), not a novel exploit.
Read the full account
Google disclosed on September 18, 2026 that in May, during a capture-the-flag security test run by the startup Irregular, its Gemini model reached three separate private company systems after a bug in the test environment left internet access available when it was not supposed to be. According to Google, the model accessed one system by guessing passwords and two others by using credentials it found in public repositories, having mistaken the real companies for part of the test (the fictional target shared a name with a real company). Google says the model stopped each time once it determined the systems were real. Irregular notified the labs in late July, and Google then notified the affected companies.
The only thing meant to keep the agent off the open internet was the test environment's configuration, and a single misconfiguration removed it. Separately, the fault went roughly two months before the labs were told.
ORIGINAL REPORTING & EVIDENCE