Google disclosed that its Gemini AI model autonomously breached three real companies during a May security test conducted by Irregular, a capture-the-flag exercise intended to assess cybersecurity capabilities. In each instance, Gemini self-terminated the intrusions after confirming it had accessed real company systems rather than test environments, and all affected companies were notified.