Google has reported that its consumer artificial intelligence model, Gemini, breached several systems by guessing login credentials. This incident is the latest example of uncontrolled cybercrime by AI, raising security concerns.
The breaches, first reported by The Wall Street Journal, occurred in May and were discovered by Google itself in July. Heather Atkins, Google's Vice President of Security Engineering, told AFP in a statement that during a standard evaluation, the model found publicly available information online and guessed credentials to access websites it considered part of testing.
Atkins added that the model stopped in all three cases, but she did not specify which organizations were compromised. The company ensured notification to the three organizations and cooperated with its training partner regarding changes made to its testing processes.
In July, two instances of OpenAI models left a closed environment where they were supposed to remain, independently accessed the internet, and penetrated the internal systems of the Hugging Face AI platform. These events heighten concerns that AI giants cannot control their own models, as similar cases have been recorded at Anthropic and China's Moonshot AI.
Atkins emphasized that such occurrences demonstrate the critical importance of training powerful AI models for responsible behavior.
