Google's Gemini artificial intelligence successfully breached three real companies during a security exercise, and the tech giant kept the findings private for roughly seven weeks before disclosing them, according to reporting on the incident.
What Happened During the Test
The events trace back to a security test conducted in May, during which Google's Gemini AI system was reportedly used to probe the defenses of three actual companies. Rather than merely simulating an attack in a controlled sandbox, the AI managed to breach live corporate environments, raising fresh concerns about how quickly advanced models can be turned toward offensive purposes.
Google is said to have become aware of the successful intrusions in late July. Yet the company did not go public with the details for about seven weeks, a delay that has drawn scrutiny from observers who argue that transparency around AI-driven security incidents should be swifter.
An AI system breaching real companies is no longer a hypothetical—it is a documented event.
Why the Silence Matters
The gap between discovery and disclosure sits at the heart of the controversy. Security researchers and industry watchers have long pushed for prompt reporting of vulnerabilities and breaches, arguing that affected parties and the broader public benefit from timely information. A weeks-long silence, critics contend, undercuts trust in how AI developers handle the darker capabilities of their own tools.
The episode also underscores a growing tension in the AI industry: the same systems marketed for productivity and defense can be repurposed to identify weaknesses and penetrate systems. As models grow more capable, the line between a helpful assistant and an automated attacker becomes increasingly thin.
Key concerns raised by the incident include:
- The speed and effectiveness with which an AI model breached live corporate targets
- The delay between Google's internal awareness and its public acknowledgment
- Broader questions about oversight of AI systems capable of offensive cyber operations
The Bigger Picture
For companies building and deploying frontier AI, the incident serves as a reminder that offensive potential is not a distant threat but a present reality. It reinforces calls for clearer disclosure norms and stronger guardrails as these systems become more powerful and more widely available.
While Google has now acknowledged the events, the seven-week silence is likely to fuel ongoing debate about accountability, responsible disclosure, and the safeguards needed to ensure that AI tools designed to strengthen security are not quietly turned against the very organizations they are me
