Google’s Gemini AI hacks 3 companies in security test, then stops谷歌的Gemini人工智能在安全测试中入侵了3家公司,然后停止运行
Google discloses first breakout by Gemini following similar incidents by Meta, Anthropic and OpenAI.

Google discloses first breakout by Gemini following similar incidents by Meta, Anthropic and OpenAI.
In this photo illustration, the icon for the AI app Gemini by Google is seen through a flame as it is displayed on a digital screen in London, England, on September 16, 2026 [Leon Neal/Getty Images]
Google’s Gemini model hacked three companies in a test of its cybersecurity capabilities, the tech giant has confirmed to Al Jazeera.
The Wall Street Journal reported earlier on Friday that the first known breakout by Gemini occurred in May as part of a test run by the company Irregular. It was the latest breach in a number of incidents in which AI models escaped testing environments and hacked other companies.
list 1 of 3 OpenAI reports more incidents of models acting deceptively
list 2 of 3 ‘Just ask Grok’: How ISIL is using Big Tech’s AI to build bombs
list 3 of 3 Who gets to decide how quickly AI moves?
The model had improper access to the internet when it was tasked with retrieving information from a fictional company. In the first incident, the model accessed a real company’s service after guessing a password.
Google’s vice president of security engineering, Heather Adkins, told Al Jazeera’s John Hendren that in the other instances “the model found public information online and guessed credentials to access websites it thought were part of the test”.
The company also said this happened three times and each time the model stopped before completing the act.
Irregular notified Google about the hacks at the end of July, The Wall Street Journal reported. Google said the behaviour was not an example of model misalignment and did not warrant public disclosure because Gemini’s safety measures worked.
Similar incidents linked to Irregular were previously disclosed by Meta, Anthropic and OpenAI. Irregular said it was working on improving practices for securely conducting AI cybersecurity tests.
Unlike Gemini, Anthropic’s Claude model didn’t stop after realising it was accessing real companies.
Anthropic’s disclosure came after OpenAI revealed that its models improperly accessed the internet and went rogue during testing. Anthropic recently disclosed a fourth AI hacking incident after a researcher quit over safety.
Earlier this week, Anthropic CEO Dario Amodei called for a slowdown in the rate of AI progress, warning that AI could soon pose potentially catastrophic risks to humanity itself. The call was endorsed by OpenAI CEO Sam Altman and Elon Musk.
Last week, US President Donald Trump dismissed the need to place checks on artificial intelligence development, saying he is worried about ceding the US’s lead to China.
继 Meta、Anthropic 和 OpenAI 发生类似事件后,谷歌披露了 Gemini 的首次突破事件。
在这张照片插图中,谷歌人工智能应用 Gemini 的图标透过火焰映照出来,该图标于 2026 年 9 月 16 日在英国伦敦的数字屏幕上显示。[Leon Neal/Getty Images]
谷歌已向半岛电视台证实,其Gemini模型在测试网络安全能力时入侵了三家公司。
《华尔街日报》周五早些时候报道称,Gemini 首次已知的逃逸事件发生在 5 月份,当时是 Irregular 公司进行测试运行的一部分。这是近期一系列人工智能模型逃逸测试环境并入侵其他公司的事件中的最新一起。
OpenAI报告称,模型欺骗行为事件增多(共3例,第1例)。
列表 2/3 “问问格罗克就知道了”:ISIL 如何利用大型科技公司的 AI 制造炸弹
问题 3(共 3 题):谁来决定人工智能的运行速度?
该模型在被要求从一家虚构公司获取信息时,非法访问了互联网。在第一起事件中,该模型在猜中密码后访问了一家真实公司的服务。
谷歌安全工程副总裁希瑟·阿德金斯告诉半岛电视台的约翰·亨德伦,在其他情况下,“该模型在网上找到了公开信息,并猜测了访问它认为是测试一部分的网站的凭据”。
该公司还表示,这种情况发生了三次,每次模特都在完成动作前停止了。
据《华尔街日报》报道,Irregular公司在7月底将黑客攻击事件告知了谷歌。谷歌表示,该事件并非模型错位,且由于Gemini的安全措施有效,因此无需公开披露。
此前,Meta、Anthropic 和 OpenAI 也披露过与 Irregular 相关的类似事件。Irregular 表示,他们正在努力改进安全开展人工智能网络安全测试的流程。
与 Gemini 不同,Anthropic 的 Claude 模型在意识到自己正在接触真正的公司后并没有停止。
在OpenAI披露其模型在测试期间不当访问互联网并失控运行后,Anthropic公司也披露了这一事件。此前,一名研究人员因安全问题辞职,Anthropic公司最近又披露了第四起人工智能黑客攻击事件。
本周早些时候,Anthropic首席执行官达里奥·阿莫迪呼吁放缓人工智能的发展速度,并警告称人工智能可能很快就会对人类自身构成潜在的灾难性风险。这一呼吁得到了OpenAI首席执行官萨姆·奥特曼和埃隆·马斯克的支持。
上周,美国总统唐纳德·特朗普驳斥了限制人工智能发展的必要性,称他担心美国会将领先地位拱手让给中国。