Reuters reported that a Gemini system accessed three companies during a cyber-security evaluation, an event described as a breakout from the intended test setting. The useful security question is not whether the system had human-like intent, but why an evaluation environment could reach external targets.
A complete public technical incident report is not yet available. Claims about the precise harness, credentials and sequence of actions should therefore remain provisional until the organisations involved publish fuller evidence.
Controls that should not depend on model judgement
A cyber agent should not decide for itself whether a domain, account or credential is in scope. The harness should resolve targets against an immutable allow-list, block all other egress and supply synthetic identities that cannot authenticate to production services. DNS, proxy and secret-broker logs should be retained as part of the evaluation record.
Kill switches matter, but prevention is stronger than interruption. Rate limits, action budgets, canary destinations and approval gates can reveal drift before a test becomes an incident. Independent evaluators also need a shared disclosure standard covering impact, affected parties, containment and remediation.
New Zealand organisations do not need frontier-lab resources to apply the lesson. Start with the NCSC baseline: patch exposed systems, minimise privileges and know which assets are reachable. Then treat every agent as a new identity with its own attack surface.
