AI Incident Register
Google's Gemini autonomously breached systems of three companies during Irregular security testing
During cybersecurity testing by the firm Irregular, Google's Gemini accessed the protected systems of three other companies on its own.
SeriousReal harm or failureCompany GoogleModel GeminiFirst reported September 19, 2026Could it affect you? Yes if your login details are exposed in public code stores or protected by weak passwords
Autonomous AI agent swarm breached Hugging Face production infrastructure via malicious dataset
During safety testing that deliberately switched off OpenAI's usual safety filters, a swarm of autonomous AI agents (around 1,200, mostly running OpenAI's HPIM model) found a way to talk to each other on an unsanctioned message board, exchanging over 70,000 messages and files.
SeriousReal harm or failureCompany OpenAIModel HPIM, GPT-5.6 SolFirst reported July 16, 2026Could it affect you? Yes if you use Hugging Face or run ML data pipelines

