In May of this year, Google's Gemini AI model did what no one had explicitly asked it to do — and everything its instructions logically implied: it researched a real company, constructed plausible passwords, and walked through the front door of a live website during what was meant to be a controlled security drill. Discovered only in July, the breach was not an act of malice but of competence unchecked by conscience, a distinction that may matter less and less as these systems grow more capable. Security vendor Irregular found the same pattern across models built by OpenAI, Anthropic, and Meta