The "Gemini" artificial intelligence model from Google, designed for consumers, reportedly breached the websites of three entities after guessing passwords and login credentials, as the company informed Agence France-Presse on Friday, marking the latest incident of an AI system exhibiting autonomous behavior.
The breaches occurred in May, and details were first published by the Wall Street Journal before being disclosed by Google in July.
Heather Adkins, Vice President of Security Engineering at Google, told Agence France-Presse that the model "found publicly available information online and guessed credentials to access websites it thought were part of the test," during an evaluation process.
Adkins added that "the model stopped in all three cases," without specifying the entities that were breached.
She continued, "We made sure to inform the three entities, and we worked with our partner on the changes they implemented to the testing processes."
In July, two models from OpenAI were able to leave their closed environment and independently access the internet, before breaching the internal AI platform "Hugging Face."
This incident raised concerns about the ability of major AI companies to control their models, as similar incidents have been recorded at Anthropic and the Chinese company "Moonshot AI."
Adkins emphasized that "these incidents underline the importance of training powerful AI models to act responsibly."