Skip to main content
Google's Gemini Becomes the Third AI Model Tied to Hacking
Daily Signal 3 min read

Google's Gemini Becomes the Third AI Model Tied to Hacking

Google's Gemini becomes the third frontier model tied to a real hacking operation, following OpenAI and Anthropic disclosures.

Google’s Gemini just became the third major frontier model tied to a real-world hacking operation in about a year and a half. That’s not a fluke. That’s the industry’s new normal.

The tempo is the story here, not any single model. Three labs, three disclosures, each one arriving closer to the last than the one before it.

  • In February 2025, OpenAI said it had banned a cluster of ChatGPT accounts linked to state-affiliated actors who were using the model to help scope and refine intrusions against government and corporate networks.
  • In August 2025, Anthropic disclosed that state-sponsored operators had used Claude to run large stretches of a cyber espionage campaign with minimal human review, treating the model less like a chatbot and more like a junior operator on the payroll.
  • On September 19, 2026, TechCrunch reported that Google’s Gemini had been used to help attackers hack other companies, pulling Gemini into the same category as ChatGPT and Claude before it.

Line those three up and the shape is obvious. Every lab that ships a frontier model now has to eventually publish its own incident report, because the same capability that makes these models useful for writing code and chasing down bugs also makes them useful for reconnaissance, exploit development and social engineering at a scale no human ops team could match manually. The labs are not choosing to become security vendors. Attackers are choosing for them, and the labs are stuck publishing after-the-fact disclosures instead of getting ahead of the abuse.

What is actually changing is who carries the disclosure burden. A year and a half ago, “AI-assisted hacking” was a hypothetical in a research paper. Now it is a recurring entry on the safety blog of whichever lab gets caught next. That is a real shift in posture: frontier models are being treated less like static products and more like infrastructure that has to be monitored for abuse the same way a cloud provider watches for compromised accounts. If you are building agents that touch customer data or live systems, the guardrail question stops being theoretical the moment your own model provider starts writing incident reports about its own product. The Forge guardrails work is worth a look if you have not locked down what your agent can touch unsupervised.

Here is the falsifiable part: expect a fourth frontier lab, most likely one whose models sit inside widely deployed enterprise tools, to publish a comparable disclosure before the end of 2026. If that does not happen, this was three labs getting unlucky in the same stretch, not a pattern. If it does, “which model got weaponized this quarter” turns into a standing beat instead of a one-off headline.

Worth tracking if you ship anything model-backed. The Claude Code quality reports are worth the same kind of attention, for the same reason: what a lab admits about its own model tells you more than its marketing does. Subscribe for the daily version of this at /subscribe/.