Johannesburg

AI Agents Can Cross the Line Faster Than You Think

A Google Gemini test accidentally reached three real businesses, showing why AI tools need carefully controlled access.

đź“…

đź“…

Sep 25, 2026

0 Comments
Illustration: Free‑Images.com

AI is moving beyond answering questions. Some AI agents can browse the internet, use software and take actions on a user’s behalf.

 

That makes a recent Google security test worth knowing about, particularly for businesses already using AI tools.

 

In May 2026, cybersecurity company Irregular was testing Google Gemini in a controlled “capture the flag” exercise. The AI was supposed to work with a fictional company, but a configuration error gave it access to the internet. The fictional company also had the same name as a real business.

 

Gemini then accessed systems belonging to three real companies.

 

According to Google and reporting on the incident, one system was reached after the AI repeatedly guessed passwords. In two other cases, Gemini found credentials that had been exposed in a public software repository. Google said the model stopped once it recognised that it had reached real companies, and the affected organisations were contacted.

 

What businesses can take from this

 

The incident was caused by a testing mistake, rather than a conventional criminal attack. But it highlights a growing security issue: AI agents can do more when they are connected to tools, accounts and the internet.

 

Businesses using AI should therefore:

 

  • Give AI tools only the access they actually need.
  • Protect passwords, API keys and other credentials.
  • Remove credentials accidentally published in code or online repositories.
  • Use multi-factor authentication where available.
  • Keep testing environments separate from real company systems.

 

These are established security principles. NIST also recommends considering an AI agent’s tool permissions, external access and the amount of authority it has to act.

 

And for ordinary users?

 

The same principle applies when using AI assistants connected to email, files, accounts or other services.

 

Before giving an AI tool access, ask a simple question: What could it access or change if something went wrong?

 

That matters because an AI assistant with access to your accounts has more potential impact than one that simply answers questions.

 

The Bottom Line

 

The lesson from the Gemini test is not that AI suddenly became a criminal hacker. It is that the more access an AI system has, the more important the surrounding security controls become.

 

For businesses and individuals, limiting access, protecting credentials and using MFA remain some of the most practical ways to reduce the risk.

0 Comments

Join the conversation

Be the first to comment

Share your thoughts above.

More from Joburg Insider

Joburg Insider

© 2026 Joburg Insider.

Your local guide that’s built just for you and your neighbourhood. Every edition brings you real local life: new restaurant openings, great places to eat, family‑friendly events, markets, gigs and things to do nearby. You’ll also get short, useful stories about local people, small businesses and community initiatives that make your area feel like home. We cut out generic, click‑baity content and outdated events, and focus on practical, trustworthy updates that help you decide where to go, what to try and how to stay connected in your community.

© 2026 Joburg Insider.