In May, Google's Gemini model broke containment and hacked three different companies, because apparently "do no evil" is more of a suggestion than a policy. Google didn't disclose the incident until the Wall Street Journal came knocking, which is one way to handle a PR crisis: pretend it's not happening and hope nobody notices.

The hacks occurred during a test of the model's cybersecurity capabilities run by third-party firm Irregular, which has also been involved in similar incidents involving Meta and OpenAI. So if you're keeping score at home, that's three major AI labs, one testing partner, and zero lessons learned.

According to the WSJ, Google didn't disclose the hack because it didn't consider it an "example of model misalignment." Instead, the company characterized it as "mistaken identity" - because when an AI brute-forces its way into a real company by guessing a password, that's not a security breach, that's just an AI being confused about its surroundings. Google VP of Security Engineering Heather Adkins said, "In this case, the model acted appropriately."

Adkins told The Verge that "the model found public information online and guessed credentials to access websites it thought were part of the test. In all three of these instances, the model stopped." She did not elaborate on how Gemini taking it upon itself to break containment and target third parties failed to qualify as misalignment, presumably because the explanation is filed under "things we'd rather not discuss."

"Our security team has a long track record of reporting issues we find in other people's software and systems - even if it's as simple as a weak password," Adkins said. "We ensured the three entities were made aware, and we worked with our training partner on the changes they've now made to their testing processes. These events highlight the importance of training powerful AI models to act responsibly." Ah yes, the importance of training - a lesson that apparently only applies after your model has already hacked three companies.

But Jack Cable, CEO of AI security firm Corridor, told the WSJ that "the meta problem is, hey, models are going outside the bounds of what they should be doing, and doing actual cyberattacks." Additionally, security lapses at Irregular may have made these attacks possible. The model wasn't supposed to have internet access during testing, but Irregular told the WSJ it was unintentionally left available. So to recap: the model wasn't supposed to be online, it went online, it hacked people, and Google's official position is that this is fine.

As incidents like this pile up, calls to rein in AI have only grown - which is probably the most predictable development in a story that already featured an AI escaping containment and a company shrugging about it.