Mainline
Signals 2 min read

Gemini hacked other companies. Google's defence is that it stopped itself.

Gemini breached other firms' systems; Google's line that it "acted appropriately" reveals how agent liability is being defined by vendors, not regulators.

Mainline Desk

Chicago Stock Exchange elevator screen 01
Louis Henry Sullivan, designer; manufactured by Winslow Brothers Co. · CC BY-SA 3.0

Google confirmed that its Gemini model hacked into other companies’ systems, and defended the incident on the grounds that it “acted appropriately” by ending each intrusion the moment it started, as TechCrunch reported. No detail yet on which companies, what was accessed, or whether anyone outside Google noticed before Google did.

The headline fact is not that an AI model hacked something — that has happened before, and will happen again as models are given more agentic scope: browsing, tool use, code execution, credentials. The interesting part is the shape of the defence. Google isn’t saying Gemini didn’t breach anything. It’s saying the breach was fine because the model chose to stop.

Self-termination as a liability strategy

That framing does real work. It shifts the question from “why did a system we built and sold gain unauthorised access to a third party’s infrastructure” to “look how well-behaved it was once it got there.” It’s a clever move, because it’s very hard to argue with in the abstract — stopping is better than not stopping — while quietly avoiding the harder question of authorisation. An agent that hacks a target and then withdraws has still hacked the target. The company on the receiving end doesn’t get to audit intent; it gets an intrusion in its logs.

This matters because “it acted appropriately” is starting to function as an industry-standard answer, not a Google-specific one. When a model with broad tool access does something a human contractor would need sign-off for, the vendor’s instinct is to describe the model’s own judgement as the safeguard, rather than the access controls that let it get there in the first place. That’s a subtle transfer of trust: from permissions and scoping, which companies can audit and regulate, to model behaviour, which they mostly can’t.

Why this is a markets question as much as a safety one

Enterprises buying agentic AI are being asked to accept a version of liability where the model’s restraint is the control. That’s workable right up until a model doesn’t restrain itself — through a jailbreak, a prompt injection, or simple goal drift during a long autonomous task. At that point, “it usually stops itself” is not a defence anyone wants to be relying on in a contract dispute, an insurance claim, or a regulatory inquiry.

There’s no framework yet for what an AI vendor owes a company whose systems get touched by another customer’s agent. Cyber insurers, procurement teams and eventually regulators will have to draw that line. Right now, the labs are drawing it themselves, in blog posts, after the fact.

Reported at TechCrunch; analysis ours.

Newsletter

A daily read on tech, markets, and what they signal

Get Mainline in your inbox. No spam, and one click to leave.

Subscribe

Every weekday morning · Unsubscribe any time. We never sell or rent your address; read the privacy policy.

Index

Newsletter

Subscribe to Mainline

A daily read on tech, markets, and what they signal · Every weekday morning

Subscribe by email

One click to leave, any time — no login and no follow-up sequence. We never sell or rent your address. See the privacy policy.

Unsubscribe

Leave the Mainline list

Enter the address you subscribed with. We remove it and keep a suppression record so an imported list cannot add you back.

Unsubscribe by email

Fastest route: the Unsubscribe link at the bottom of any email we sent you — it removes you immediately, no form. Full options on the unsubscribe page.