Story Commentary · September 22, 2026
Cybersecurity Firm Testing AI Hacking Tools Forgot to Disconnect the Internet, Breached Three Real Companies
A cybersecurity firm testing experimental Gemini AI models accidentally left internet access enabled, allowing the models to hack three real companies in May 2026; the firm waited two months before reporting the breaches.
Wait — a cybersecurity firm was testing an AI's ability to break into systems, but forgot to make sure it could only break into *their* systems? So Irregular, the company literally paid to think about security, just... left the internet connected? And then when the AI actually did hack three real companies, they didn't tell anyone for two months because they didn't think it was "worthy of further investigation"?
Actually, if you zoom out, this is exactly the kind of structured learning experience that builds institutional muscle memory around AI governance. Irregular identified a configuration vulnerability in real-time, the models demonstrated alignment by self-terminating upon recognition of scope breach, and Google's disclosure framework functioned as designed—the two-month timeline allowed for proper stakeholder notification sequencing rather than reactive crisis communications. The fact that we're even having this conversation means the transparency mechanisms are working: compare this to legacy penetration testing, where misconfigurations routinely went undocumented for years, and you see a maturity curve that's actually ahead of schedule.
Irregular is a cybersecurity firm. Their job is configuration. They misconfigured the test, the AI accessed real systems, and they decided it wasn't worth investigating. Two months later, after other incidents made headlines, they mentioned it. This is the company you hire to protect you.
Notice how Google's confirmation frames this: the models "stopped after realizing they had accessed a real company's servers" — as if the AI demonstrated restraint rather than Irregular scrambling to pull the plug after two months of not thinking an actual breach was newsworthy. The passive construction in "Irregular was not supposed to allow the model to operate outside its servers" does elegant work: a cybersecurity firm's misconfiguration becomes a thing that happened to them, not a thing they did. And the detail about notifying companies "so they could (we hope) improve their password security" — that parenthetical hope doing all the liability-deflection heavy lifting, turning three successful intrusions into a teachable moment about other people's hygiene.