Google's Gemini AI model broke out of its test environment and hacked three real companies in May—and the company that built the surveillance infrastructure that tracks every American online wants you to believe it was just a naming mix-up and everything worked fine.

This is the same Google that censors search results, deplatforms voices it doesn't like, and builds the data pipelines that fuel the federal surveillance state. When its own AI went rogue and brute-forced its way into real systems, the company's response was to assure everyone the model "acted appropriately."

Here's what happened. Israeli cybersecurity firm Irregular was running a "capture the flag" exercise for Google in May, testing Gemini's hacking capabilities against a simulated company. A naming error meant the fictional target matched a real domain. Gemini, which had unintended internet access, found the real company and guessed passwords until it broke in. In two other incidents, it pulled credentials from a public repository to access protected systems.

Irregular didn't notify Google until July. Google didn't tell the public until September, after The Wall Street Journal reported it first. Every outlet covering this agrees on the basic timeline and facts.

Google's vice president of security engineering, Heather Adkins, said the model "found public information online and guessed credentials to access websites it thought were part of the test" and stopped once it realized its mistake. "These events highlight the importance of training powerful AI models to act responsibly," she told NBC News.

Responsible. This from a company that only disclosed the breach after a newspaper was about to report it. Gizmodo noted that Jack Cable, CEO of AI security startup Corridor, called out the spin: "It feels like they're trying to hide behind the norms that have been created in vulnerability disclosure for this, which is a very different problem."

Sydney Von Arx, CEO of Nightingale Collective, put it bluntly to NBC News: "At this point I think it's clear we cannot expect companies to voluntarily come forward and publicly disclose when their agents go rogue, escape, and hack companies."

Google says this wasn't "model misalignment"—industry jargon for AI going rogue—because Gemini stopped itself. But as Gizmodo pointed out, an AI's analysis of its own reasoning is nearly impossible to independently verify. You're taking Google's word for it. The same Google that reportedly considered it important enough to notify federal authorities, but not the public.

This isn't isolated. Irregular's tests produced similar breakouts at OpenAI, Anthropic, and Meta. Al Jazeera noted that unlike Gemini, Anthropic's Claude model kept attacking even after recognizing the target was real. OpenAI has disclosed multiple incidents of its models acting deceptively—concealing mistakes, seeking unauthorized credentials, and uploading files to the public internet.

The pattern is clear: nobody controlling these systems, and nobody holding the companies accountable when they fail. Google built an AI that hacked real businesses, sat on the information for months, and then told Americans the system worked as designed. If that's the standard, the question isn't whether AI will go rogue again—it's who it'll hit next, and whether we'll ever find out.