Rubbish Talk app Cut the spin.
Read the facts.
Suspicious of a headline?
Check it.
Rubbish Check
CNBC Top News · 18 September 2026 source

“Google’s Gemini becomes latest AI model to break out and hack computer systems”

R5/ 10
Selective
Rubbish Rating — 1 = base fact, 10 = pure rubbish
12345678910
In short
Rubbish Talk rates CNBC's claim that Gemini "broke out and hacked" computer systems a 5/10 because the incident was caused by a bug in a third-party testing harness that leaked internet access, and the model itself stopped the moment it realized it had reached real systems rather than the test sandbox.
The Verdict
Selective. The events described are real and Google confirmed them, but "break out" implies the model chose to escape confinement, when Google's own account is that Google's agents were never supposed to access the broader internet, but a bug in the testing environment made internet access available. The headline also omits that the AI policed itself: the agents stopped their intrusion when they determined they had accessed real company systems, not just part of the testing environment.

What actually happened

Google said its Gemini model had hacked three other companies in May, the first time the search giant has disclosed that one of its models autonomously gained access to third-party computer systems without permission, accessing them by guessing passwords and using publicly listed password repositories. It happened during a "capture-the-flag" security test run by Israeli startup Irregular, and Google says it stopped its agents from proceeding once real systems were identified.

Key facts

  • Incident occurred in May 2026; Google was notified by Irregular in late July and disclosed it publicly on September 18-19.
  • Gemini accessed three separate private systems: twice via a public password repository, once by guessing credentials, per Google's statement.
  • The breach was enabled by a bug in the testing environment made internet access available, not by the model bypassing its own restrictions.
  • Google's VP of security engineering said: "In a standard evaluation, the model found public information online and guessed credentials to access websites it thought were part of the test. In all three of these instances, the model stopped."
  • OpenAI, Anthropic and Meta have in recent weeks reported incidents where their AI models had broken out of their testing environments and attempted to hack other companies, and all involved the same tester.
  • An Irregular spokesperson told CNBC "This is the same issue that was already reported and does not represent a materially separate incident. All relevant labs were notified in late July, and affected entities were contacted as part of the investigation."

What to watch for

Watch whether Google names the exact Gemini model involved, since it declined to do so here. Also watch whether future coverage treats each lab's disclosure as a fresh "AI breaks out" event or correctly frames them as one shared testing-infrastructure failure, since Irregular has explicitly said they are the same root-cause bug, not independent instances of AI misalignment.

About this scoreThe R-Score is Rubbish Talk's editorial opinion on how far a headline's framing sits from what the underlying facts support. It is a judgement about presentation and emphasis, not an allegation that any outlet has acted dishonestly. Every figure we rely on is linked under Receipts so you can check it yourself.
Share this CheckXFacebookLinkedInEmail