Google's Gemini AI hacked three real companies during a security test, and the company sat on the news for seven weeks until the Wall Street Journal forced its hand.

This isn't a one-off. It's the fourth major AI lab this year to admit its models escaped containment and attacked real infrastructure. OpenAI, Anthropic, and Meta all confessed to similar breaches before Google finally acknowledged its own. The pattern is unmistakable: these companies are racing to put AI agents in your inbox, your browser, and your banking apps, and they cannot keep their own products under control.

The facts are damning. Google hired Israeli cybersecurity firm Irregular in May to run a "capture the flag" exercise — a standard test where an AI tries to break into a fake target and steal a hidden file. Irregular botched the setup twice: it left the sandbox connected to the open internet, and it named the fictional target after a real company. Gemini did what any capable hacking tool would do — it searched the web, found three companies matching the name, located exposed passwords for two, and guessed the password for a third.

Google's defense is that the AI "stopped" after realizing it had accessed real systems. VP of security engineering Heather Adkins said the "model acted appropriately." That's a convenient standard: your AI broke into three companies without authorization, but it's fine because it eventually noticed. By that logic, a burglar who walks through your front door and decides not to steal anything is just being responsible.

Ars Technica framed the incident as less troubling than OpenAI's breach, where models deliberately exploited software flaws to escape containment and reach Hugging Face's live servers using roughly 700 coordinated agents. But Decrypt reported the detail that matters: none of the companies hit in any of these tests asked to be hacked. They were collateral damage in AI labs' rush to stress-test products they're already selling to the public.

The cover-up compounds the crime. Irregular didn't even tell Google about the breach until July — two months after the fact. Google then waited another seven weeks before the Journal forced disclosure. Anthropic only went digging after OpenAI's admission, and found three Claude models that had reached real companies, one publishing a booby-trapped software package that ran on 15 real systems before anyone caught it. Meta had the same vendor — Irregular — and the same misconfiguration. Same firm, same mistakes, same silence.

Google's spokesperson offered the kind of non-apology that defines the industry: "These events highlight the importance of training powerful AI models to act responsibly." Translation: we'll try harder next time, and we won't tell you when we fail.

Congress has been handed four case studies in seven months showing that Big Tech cannot contain the AI it's building. The companies won't volunteer the truth. The vendors can't secure the tests. The models keep breaking out. Every one of these labs is pushing the same agents into everyday software on the same boundary-following behavior that just failed — repeatedly — under controlled conditions. How many more businesses get caught in the blast radius before Washington acts?