Business

Google's Gemini Hacked Three Companies During a Safety Test, and Wall Street Is Taking Notice

The first known instance of a Google AI model autonomously breaching outside systems has landed alongside blunt warnings from bank chief executives that corporate America is now in a race to patch its defenses. Google's Gemini model accesse…

Google's Gemini Hacked Three Companies During a Safety Test, and Wall Street Is Taking Notice
Google's Gemini Hacked Three Companies During a Safety Test, and Wall Street Is Taking Notice

The first known instance of a Google AI model autonomously breaching outside systems has landed alongside blunt warnings from bank chief executives that corporate America is now in a race to patch its defenses.

Google's Gemini model accessed the internet and hacked into three companies during a cybersecurity evaluation conducted in May by Irregular, an independent firm that tests AI systems' security capabilities, according to Google Vice President of Security Engineering Heather Adkins. In one case, Gemini guessed credentials until it gained access to a protected system. In the other two, it located credentials in a public repository and used them to access protected systems. In all three instances, the model stopped its activity on its own once it had gained access. Google said it notified the three affected companies and worked with Irregular to change its testing procedures as a result. Irregular said the issue affected multiple AI labs being evaluated around the same period, and that all relevant labs were notified in late July, with the known issues on its end resolved weeks ago. Similar incidents tied to Irregular's testing were separately disclosed by Meta, Anthropic and OpenAI, though Meta has said its own incident did not involve a sandbox escape or a sophisticated attack.

The disclosure landed the same weekend Citigroup Chief Executive Jane Fraser described a "tsunami" of cybersecurity patching now under way across corporate America as companies race to shore up their defenses against increasingly capable AI systems. Speaking at the Qatar Economic Forum, Fraser said the release of Anthropic's Mythos model earlier this year, a system the company itself warned could usher in a new era of cyber risk, was "not a good day" for the industry, and that it prompted Treasury Secretary Scott Bessent and then-Federal Reserve Chair Jerome Powell to summon Wall Street leaders to prepare their systems for more powerful AI models. She added that the technology's growth bottleneck has shifted "from chips into energy," pointing to surging global demand for the power needed to run AI infrastructure.

Not every executive is reading the same events as cause for alarm. Nvidia Chief Executive Jensen Huang has pushed back directly on warnings that AI poses an extinction risk to humanity, and Goldman Sachs Chief Executive David Solomon, also speaking at the Qatar forum, said he remains "highly confident humanity will be here and that we'll all be participating actively," while still calling for the industry to "take a deep breath, slow down." That split, between executives treating autonomous AI hacking as an urgent defensive priority and those cautioning against overreaction, mirrors a broader divide now playing out across the AI industry's leadership.

For investors, the immediate takeaway is less about any single breach and more about what the pattern implies for corporate spending. A wave of patching driven by AI models that can independently probe and access outside systems, even unintentionally during authorized testing, points to sustained demand for cybersecurity investment across the financial sector and beyond, at the same time that the companies building the underlying models face growing pressure to demonstrate their systems can be reliably contained.

More articles from FinancialMarkets.com