Google’s Gemini AI unintentionally taps live corporate networks during May security test
Google’s Gemini artificial‑intelligence model accessed active corporate systems in May 2026 after a configuration error during a routine cybersecurity evaluation, the Wall Street Journal reported. The mishap marked the latest instance of an AI system breaching external networks while operating under test conditions.
Gemini, the company’s next‑generation conversational model, includes a browsing capability that lets it retrieve up‑to‑date information from the public web. The feature is intended for controlled experiments that assess how the system handles real‑time data without compromising user privacy or security. During the May evaluation, the model was directed to query a set of domain names that were meant to resolve to isolated test servers.
Because a domain‑resolution mix‑up routed those queries to live corporate domains instead of the sandbox, Gemini began pulling data from operational company sites. The model’s automated requests triggered normal web‑traffic patterns, which initially escaped detection. Once the anomaly was noticed, security teams confirmed that the AI had successfully opened connections to several external services and retrieved publicly available pages, raising concerns about inadvertent data exposure.
Google responded by immediately disabling Gemini’s external browsing function and launching an internal investigation. The company said it is working with independent security researchers to understand the root cause and to reinforce safeguards that prevent AI models from reaching unintended endpoints. No evidence of data theft or malicious alteration has been reported, and Google emphasized that the incident did not affect user‑facing products.
The episode adds to a growing list of high‑profile AI safety challenges, including earlier incidents where large language models accessed private repositories or generated misleading content. Regulators in the United States and Europe have increasingly called for robust oversight of AI systems that can interact with the internet, arguing that the technology’s speed and autonomy amplify traditional cybersecurity risks.
Analysts suggest that the Gemini incident will prompt tighter testing protocols across the industry, including stricter isolation of test environments and more granular monitoring of AI‑generated traffic. Google has indicated that any future rollout of Gemini’s browsing capability will be contingent on meeting new safety benchmarks, signaling a cautious approach as the company balances innovation with emerging security expectations.
Comments (0)
Be the first to comment.
Join the discussion