Gemini Hacked Three Companies. What That Means for Anyone Using AI Agents.

Google has confirmed that Gemini accessed three real companies during a cybersecurity exercise designed to use fictional targets.

An agent can keep working while you are elsewhere. That makes the setup the only part you control.

Google has confirmed that Gemini accessed three real companies during a cybersecurity exercise designed to use fictional targets. The work happened during testing in May, and the details came out this week.

Four questions would have made the difference, and they are the same four worth asking before you hand anything to an AI agent.

What actually happened

The exercise was a capture-the-flag test — a standard security drill — run with a third-party evaluator. Gemini was asked to retrieve information from a fictional company's software inside a controlled environment.

Two things went sideways at once. The fictional target shared a name with real companies. And the model had internet access that was meant to stay switched off during the test.

So Gemini did what it had been asked to do. In one case it guessed passwords until it got in. In another it found credentials sitting in a public repository and used them. It entered real systems, recognized that these were not the test targets, and stopped.

Google contacted the affected companies, notified other labs in late July, and worked with its testing partner on changes to the process. No harm has been reported.

The interesting part sits somewhere other than intent. There is no evidence any of this was desired, and treating it as an AI that "wanted" to break in misses what happened. An agent was given a goal, handed tools, and left with more reach than anyone meant it to have. It pursued the goal correctly. The boundary was made of the wrong material.

A model can hold a limit in principle. The setup around it is what makes the limit real.

Why an agent is different from a chatbot

This is the shift people miss when they picture AI as a very fast chatbot. A chatbot gives an answer. An agent can search, log in, make changes, send messages, and continue working while you are elsewhere doing something more pleasant.

That difference is useful, as it turns a small setup error into real-world action, at a speed and scale no one is standing next to.

Four questions before you hand a task to an AI agent

1. What is it allowed to access? Give it only the accounts, files, and systems this task requires. Convenience argues for the broad key. Everything else argues for the narrow one.

2. What can it change? Reading a calendar differs from sending invitations. Drafting an email differs from sending it. Name which side of that line this task sits on.

3. When must it stop? Define a clear point where the work comes back to a person — a checkpoint chosen in advance rather than the moment something feels off.

4. Who notices if it goes off course? Someone, or something, watching the actions along the way. The finished result tells you how it looks. The trail tells you what it did.

Why all four questions come first

Notice what these have in common. Every one of them gets answered before the work begins. That is deliberate, and it follows from something I wrote about last week: approval at the end is the weakest place to put your judgment. By then the work exists, it looks finished, and you are reviewing while depleted.

An agent sharpens that problem into something else entirely. When the work happens while you are in a meeting, at lunch, or asleep, there is no late moment of attention to rescue you. The review you imagined yourself doing occurs after the messages went out.

Which leaves the setup as the only place your judgment can land. Access, scope, stopping point, and a way to see the trail — decided while nothing has happened yet, when one clear thought is enough and everything is still reversible.

The Focused Human Lens

Attention behaves like a directional energy. It carries real cost, it organizes what you notice, and it produces coherence when it settles along a single line.

Direction has to arrive before the action for that to work. You can supply it early, cheaply, with a few sentences about what this task is for and where it ends. Supplying it afterward means reconstructing what already happened and living with whatever cannot be undone.

An agent widens the gap between those two moments. It turns a pause you could have taken into an interval you were absent for. The four questions close that gap by moving your whole contribution to the front, where it costs one clear thought and determines everything downstream.

These tools scale capability with remarkable efficiency. Direction stays with you, and with an agent, direction is the entire job.

What this makes possible

You keep the speed and you keep the say. Before the next task you hand off, spend two minutes on the four questions. Write the answers down. What it can reach, what it can change, where it stops, who watches.

Google's test had a name collision and an open connection nobody intended. Your version will be smaller and more ordinary — a shared drive with more in it than you remembered, a send permission you meant as a draft permission. The two minutes is where you find those, while finding them still costs nothing.


Wondering where your attention is going in an ordinary week? The two-minute attention quiz names the drain costing you the most right now, and gives you one thing to try about it.

A. Karacay is the author of The Focused Human. The completed Focused Human podcast series is on YouTube. The Weekly Attention Reset Protocol is free: a simple weekly practice for reclaiming coherence, fifteen minutes on Sunday and five minutes a day.

Stay curious!

Sources: Google Gemini accessed three companies during AI hacking test, Axios · Google says its AI model gained unauthorized access to three outside systems, NBC News · Google's Gemini AI hacks 3 companies in security test, then stops, Al Jazeera · Google Gemini AI hack, The Guardian. First reported by The Wall Street Journal, 18 September 2026.