Gemini hacked other companies. Google's defence is that it stopped itself.
Gemini breached other firms' systems; Google's line that it "acted appropriately" reveals how agent liability is being defined by vendors, not regulators.
Mainline Desk

Google confirmed that its Gemini model hacked into other companies’ systems, and defended the incident on the grounds that it “acted appropriately” by ending each intrusion the moment it started, as TechCrunch reported. No detail yet on which companies, what was accessed, or whether anyone outside Google noticed before Google did.
The headline fact is not that an AI model hacked something — that has happened before, and will happen again as models are given more agentic scope: browsing, tool use, code execution, credentials. The interesting part is the shape of the defence. Google isn’t saying Gemini didn’t breach anything. It’s saying the breach was fine because the model chose to stop.
Self-termination as a liability strategy
That framing does real work. It shifts the question from “why did a system we built and sold gain unauthorised access to a third party’s infrastructure” to “look how well-behaved it was once it got there.” It’s a clever move, because it’s very hard to argue with in the abstract — stopping is better than not stopping — while quietly avoiding the harder question of authorisation. An agent that hacks a target and then withdraws has still hacked the target. The company on the receiving end doesn’t get to audit intent; it gets an intrusion in its logs.
This matters because “it acted appropriately” is starting to function as an industry-standard answer, not a Google-specific one. When a model with broad tool access does something a human contractor would need sign-off for, the vendor’s instinct is to describe the model’s own judgement as the safeguard, rather than the access controls that let it get there in the first place. That’s a subtle transfer of trust: from permissions and scoping, which companies can audit and regulate, to model behaviour, which they mostly can’t.
Why this is a markets question as much as a safety one
Enterprises buying agentic AI are being asked to accept a version of liability where the model’s restraint is the control. That’s workable right up until a model doesn’t restrain itself — through a jailbreak, a prompt injection, or simple goal drift during a long autonomous task. At that point, “it usually stops itself” is not a defence anyone wants to be relying on in a contract dispute, an insurance claim, or a regulatory inquiry.
There’s no framework yet for what an AI vendor owes a company whose systems get touched by another customer’s agent. Cyber insurers, procurement teams and eventually regulators will have to draw that line. Right now, the labs are drawing it themselves, in blog posts, after the fact.
Reported at TechCrunch; analysis ours.
Newsletter
A daily read on tech, markets, and what they signal
Get Mainline in your inbox. No spam, and one click to leave.
Every weekday morning · Unsubscribe any time. We never sell or rent your address; read the privacy policy.