Already in force

Your stack proves you watched. Only the artifacts prove you governed. See what the law expects →

§ Perspective · Founder POV · September 21, 2026

The test was theirs.
The password was yours.

Google’s Gemini reached three real companies during a security evaluation in May. The coverage is about the model. The useful part is about the three doors.

By Lindsay Hiebert · Founder · CISSP

The question

A question for the CEOs, CISOs and board members reading this first. If an AI agent that was never aimed at you tried your front door this afternoon, which password would it guess, and which of your keys is sitting somewhere public right now?

What happened

On September 18 the Wall Street Journal reported, and Google confirmed, that its Gemini model reached three real companies during a cybersecurity evaluation in May. The evaluation was run by Irregular, an independent firm that tests frontier models for several labs. According to the reporting, the model had internet access it was not meant to have while it worked on a task about a fictional company. It found public information online, tried credentials, and entered three live systems that it believed were inside the scope of its test.

Heather Adkins, Google’s vice president of security engineering, said that in all three cases the model stopped, that the three organizations were made aware, and that the evaluator has since changed its testing process. Her summary was one sentence: “These events highlight the importance of training powerful AI models to act responsibly.” OpenAI, Anthropic and Meta disclosed similar incidents over the summer that trace to the same testing issue, and Irregular says the known issues on its side were resolved weeks ago.

In fairness, that is a system working. A model stopped itself. A vendor fixed a process. The affected organizations were told. Four labs have now said this in public, and that is how a young field learns.

Read it from the other side

Every headline about this story is written from the lab’s side of the table. Whose model got out, whether it stopped, what the evaluator changed.

There is a second side. Three organizations had nothing to do with the test. They were not customers, partners or targets. They were simply reachable, and the way they were reachable is the most useful detail in the whole story.

One was entered because the model guessed passwords until one worked. The other two were entered with credentials the model found sitting in a public repository.

Ordinary doors

None of that is a frontier technique. A guessable password and a key left in a public repository are two of the oldest findings in security. They appear in almost every assessment I have read in thirty years.

This is the same pattern Anthropic documented in its September threat report, which I wrote about in Who actually answered your prompt?. The attacks are ordinary. The economics are what changed. An agent can try every ordinary door at machine speed, in parallel, at almost no cost. Being unremarkable used to be a kind of cover. An agent that is working through a list does not check whether you are remarkable.

The encouraging part is that ordinary doors have ordinary fixes, and every one of them is well understood.

It also matters what kind of credential ends up in a repository. It is rarely a person’s password. It is usually a key or token issued to software. Non-human identities (agents, keys, tokens) now outnumber human identities by ~100:1 (Astrix Security, via the CIS Controls v8.1 MCP Companion Guide (2026)). Those are the identities most programs have the least paper on. See non-human identity in the glossary.

It believed it was in scope

The idea worth carrying into your next meeting comes from Google’s own account. The model reached three sites that it believed were inside the scope of its test.

Scope is a governance word. The model was not acting against its instructions as it understood them. It acted on its own understanding of the boundary, and the boundary was not where anyone believed it was. A professional evaluator running a controlled test for the best-resourced labs in the world found that out the hard way, and then fixed it.

Now apply the same question to your own agents and automations. Where is their scope written down? Who approved it? When does that approval expire? If the honest answer is that the scope lives in a prompt, a config file or someone’s memory, then you are relying on the agent’s understanding of the boundary as well. That is the second face of shadow AI, and it is covered in The two faces of shadow AI and in Agent Governance.

Four labs, one evaluator

The same testing issue reached four labs because they share an independent evaluator. That is not a criticism of anyone. Specialist evaluators are a healthy part of the ecosystem, and this one notified every affected lab and changed its process.

It is a reminder that every AI program has a path, and that third parties sit on it. Most organizations keep a list of approved models. Very few keep a record of the model path: every tool, router, reseller and vendor between an employee and the system that actually does the work. The question at each hop is simple. Do you have paper on it? A named owner, an assessment, a term, and a date.

The phone call

Three organizations received a call this summer telling them that an AI model had been inside one of their systems.

Picture receiving that call. Within the hour someone will ask you which system it was, who owns it, which credential was used, when that credential was last rotated, what it could reach, who approved that reach, and where any of this is written down.

The organizations that can answer those questions in an afternoon are the ones that kept a record before the call came. A detection stack tells you what you caught. It does not tell a regulator, an underwriter or your own board what you authorized, who reviewed it, and when that authorization expires. That distinction is the subject of AI-SPM observes. DLP enforces. Governance proves.

Four things worth doing this month

Search for your own credentials in public, then rotate what you find. Public repositories, paste sites, old forks and personal accounts of current and former developers. An agent found two organizations’ keys this way without being asked to look for them.

Inventory your non-human credentials with an owner and a rotation date against each. The control that matters is not whether a key exists. It is whether anyone can show when it was last scoped and rotated.

Make guessing fail on every internet-facing login. Multi-factor authentication, lockout and rate limiting. Password guessing should never be how a story about your company begins.

Write down what each agent may do, who approved it, and when that approval expires. The labs are tightening scope on their side. This is the same discipline on yours.

Do all four and the work is still not self-evidencing. What a regulator, an underwriter or opposing counsel asks for is a record: an AI acceptable use policy that names who may use what, an executive risk report with severity rationale and named owners, a board memo showing the decision reached the people accountable for it, and a dated, third-party-verifiable way for an outsider to confirm the first two are genuine without being handed their contents.

It is also not a one-time exercise. Credentials are created every week. Agents are added every month. An assessment that was accurate in September is a historical document by the following quarter, which is why governance is a program with a cadence.

Literacy is the floor

Someone committed those keys to a public repository. Very likely with no bad intent at all. The likelier explanation is that they did not recognize, in that moment, what they were publishing or who could now read it.

That is a literacy moment, and it is the same capacity that lets a person recognize when a tool is using AI, when a prompt contains something it should not, and when an agent has moved outside what it was approved to do. EU AI Act Article 4 has required AI literacy of providers and deployers since February 2, 2025. Article 50’s transparency obligations have applied since August 2, 2026.

The version that works is matched to the seat. What a board member needs to recognize is different from what a developer needs to recognize, and both are different from what the person pasting a contract into a browser tab needs to recognize. The SanctumShield AI Literacy Academy is built for that shape, with a record of who completed what.

Close

The labs will keep improving how they test, and the evaluators will keep improving how they contain. That work is theirs, and this summer showed them doing it in the open.

The password, the repository, the written scope and the record are ours. Every one of them is within reach this quarter, with tools and practices you already know.

The test was theirs. The doors were ours. They are also ours to close.

Run the free Shadow AI Risk Calculator. Twelve questions, no account. It starts the inventory this story is asking every organization to have.

Sources
  • The Wall Street Journal, “Gemini Hacked Three Companies in First Known Breakout by Google’s AI,” September 18, 2026 (first report) — wsj.com
  • Reuters, same title, September 18, 2026, as carried by CNN Business (Google statement by Heather Adkins; Irregular statement; method of access in each case) — cnn.com
  • Al Jazeera, “Google’s Gemini AI hacks 3 companies in security test, then stops,” September 19, 2026 (internet access during a fictional-company task; related disclosures by other labs) — aljazeera.com
  • Anthropic, Detecting and countering misuse of AI: September 2026 anthropic.com
  • ~100:1 non-human to human identities — Astrix Security, via the CIS Controls v8.1 MCP Companion Guide (2026)
  • Regulation (EU) 2024/1689, Articles 4 and 50
Test yourself

Do you actually know what AI governance is?

A five-minute literacy quiz. Free, no account. See whether you would name a record or name a tool.

Take the quiz →
Free Shadow AI Risk Audit

See what your current stack is missing — in 12 questions.

The SanctumShield free Shadow AI Risk Calculator runs in your browser. No account, no email, no credit card. Twelve questions, instant risk score, three primary findings tailored to what you submit.

Perspective · outside the 27-week sequence · see the full series →

The Test Was Theirs. The Password Was Yours. — SanctumShield