AI Agents Can Cross the Line Faster Than You Think |
A Google Gemini test accidentally reached three real businesses, showing why AI tools need carefully controlled access. |

AI is moving beyond answering questions. Some AI agents can browse the internet, use software and take actions on a user’s behalf.
That makes a recent Google security test worth knowing about, particularly for businesses already using AI tools.
In May 2026, cybersecurity company Irregular was testing Google Gemini in a controlled “capture the flag” exercise. The AI was supposed to work with a fictional company, but a configuration error gave it access to the internet. The fictional company also had the same name as a real business.
Gemini then accessed systems belonging to three real companies.
According to Google and reporting on the incident, one system was reached after the AI repeatedly guessed passwords. In two other cases, Gemini found credentials that had been exposed in a public software repository. Google said the model stopped once it recognised that it had reached real companies, and the affected organisations were contacted.
What businesses can take from this
The incident was caused by a testing mistake, rather than a conventional criminal attack. But it highlights a growing security issue: AI agents can do more when they are connected to tools, accounts and the internet.
Businesses using AI should therefore:
These are established security principles. NIST also recommends considering an AI agent’s tool permissions, external access and the amount of authority it has to act.
And for ordinary users?
The same principle applies when using AI assistants connected to email, files, accounts or other services.
Before giving an AI tool access, ask a simple question: What could it access or change if something went wrong?
That matters because an AI assistant with access to your accounts has more potential impact than one that simply answers questions.
The Bottom Line
The lesson from the Gemini test is not that AI suddenly became a criminal hacker. It is that the more access an AI system has, the more important the surrounding security controls become.
For businesses and individuals, limiting access, protecting credentials and using MFA remain some of the most practical ways to reduce the risk. |
More from Joburg Insider

Sep 25, 2026
A Saturday outing with room to browse
Local makers, independent shops and a shipping-container setting give visitors plenty to explore at 27 Boxes.

Sep 25, 2026
The clever engineering inside an artificial sucker
Tiny sensors inside artificial suckers help a flexible robotic arm judge its grip, opening possibilities for machines that handle delicate objects.

Sep 24, 2026
Clearer markings at a Sunninghill intersection
Repainting at Tudor Avenue and Spitfire Street follows concerns about faded lines, with residents able to report other problem spots directly to the roads agency.

Sep 24, 2026
Small notes with a meaningful message
A school project with Latita Africa gave learners a creative way to reflect on women’s dignity and self-worth.

0 Comments
Join the conversation
Be the first to comment
Share your thoughts above.