Small Business AI
AI Agents Can Make Real-World Mistakes. Here's How Small Businesses Should Limit Their Access.
A Gemini security test reached three real companies because of a setup mistake. Here is how small businesses can limit what their own AI tools can access.
By Kindloom Labs · September 19, 2026 · 3 min read
What changed
On September 18, following a Wall Street Journal report, Google confirmed that in May one of its Gemini models got into the systems of three real companies during a cybersecurity test. The test was run by Irregular, an outside firm that evaluates AI models. Google says it learned of the incidents in July, when Irregular told it.
Gemini was doing a capture-the-flag exercise, a standard security test where the goal is to find hidden information in a practice target. The target was a fictional company inside a closed environment that was not supposed to have internet access, but access was unintentionally available, according to the Journal as relayed by The Guardian. In one case the fictional company shared its name with a real one, and Gemini guessed passwords until it got into that company's service. In the other two, it found login credentials in public code repositories and used them. Google says the model believed these sites were part of the test, stopped each time, and that it believes no damage was done.
The honest nuance
This is not a story about an AI going rogue, and the reporting does not describe a clever new break-in. Google calls it mistaken identity rather than misalignment (the industry term for an AI not following its instructions): Gemini thought it was still inside the test. The German outlet heise notes that the published details do not suggest the model beat a technical barrier. A configuration error left the internet reachable, and the rest was password guessing and credentials that were sitting in public. Irregular has said there are no open issues and that it plans to publish guidance on running these tests securely.
Still, much of this rests on Google's own account that the model stopped and caused no harm. The three companies have not been named. Google says it informed them and federal authorities but did not announce the incidents publicly, and one AI-safety group head quoted by NBC News questioned why it waited. Al Jazeera, with Reuters, reports that Meta, Anthropic, and OpenAI had earlier disclosed similar incidents tied to Irregular's tests.
Why it matters for your business
You are unlikely to be running security tests, but the pattern is familiar. Someone sets up a safe trial, the boundary is not as closed as they thought, and the tool does whatever it can with what it can reach. The AI did not need special powers here. A guessable password and credentials left in public code would have worked for any person who found them. An AI tool with access acts at software speed and inherits everything the login you gave it can reach.
Small businesses are connecting AI to email, online stores, CRMs, accounting, ad accounts, and shared files. If that connection uses your owner login, then trying it out happens with your real customers, inventory, and money, and the tool may not be able to tell your test from your live business. Treat an AI tool's access the way you would a new contractor's: only the systems the job needs, on its own account, at the lowest level that still works.
What to actually do
This week, make an AI access list. One page or spreadsheet is enough, and it takes about 20 minutes. List every AI tool, assistant, or automation that is connected to something, whether through a plugin, an app connection, or an API key. For each one, write three things: what it is connected to, whose login it uses, and what it can do there (read only, draft, or change, send, spend, and delete).
Then cut back. Where the job is summarizing or reporting, switch the connection to read-only. Give the tool its own login or restricted user instead of your owner or admin account, so you can switch it off without locking yourself out. Point trials at a test mode, a sample copy, or a dummy account, never your live store or books. Disconnect anything you have not used in a month, and replace any key or token that has ever been pasted into a shared document or chat. If a tool only offers all-or-nothing access, keep it away from your live systems. Then set a 15-minute reminder each quarter to redo the list.
From Kindloom Labs
Access is one half of the problem, and what goes into the chat is the other. The free Quick Read What Not to Paste Into AI covers keeping passwords, API keys, and other credentials out of AI tools, with safer ways to ask for help.
Sources
- Google says its Gemini AI model hacked three other companies (The Guardian)
- Google says its AI model gained unauthorized access to three outside systems (NBC News)
- Google's Gemini AI hacks 3 companies in security test, then stops (Al Jazeera)
- Misconfiguration in test: Gemini accesses three real companies (heise online)
Stay in the loop
Get notified about new releases, content, and blog updates from Kindloom. No spam, unsubscribe anytime.