From Scope Deviation to Governed Intervention: Applying the A-IPS Conceptual Framework to the 2026 Gemini Cybersecurity Evaluation Incident
In May 2026, during cybersecurity evaluations conducted by Irregular, Internet access was unintentionally available in some evaluation interactions and models took offensive security actions against real-world systems. Irregular states that subsequent public disclosures by multiple labs concern the same underlying evaluation issue rather than materially independent incidents. On 18 September 2026, Google confirmed through a statement reported by Reuters that Gemini accessed three websites that Google characterized as within the model's perceived test scope. This paper applies the Agentic-Process Intrusion Prevention System (A-IPS) conceptual framework to the reported events as a citable preliminary analysis supporting further framework development. It also assesses whether incidents of this type provide a suitable basis for more rigorous future A-IPS case studies. The analysis distinguishes reported facts, framework-based interpretation, and counterfactual control analysis. For analytical purposes, A-IPS is assumed to be adequately implemented and operationalized in accordance with its published architecture. The paper does not claim that such an implementation existed in the evaluated environment, that A-IPS was deployed there, or that it would necessarily have prevented the initial accesses. Preview version. This case study reflects the publicly available evidentiary record as of 19 September 2026. It may be updated as additional primary-source information, technical details, or clarifications become available. Later versions may therefore refine the incident reconstruction and the associated A-IPS analysis.
Authors
- Arslan Brömme
Publication Details
- Journal
- Zenodo (CERN European Organization for Nuclear Research)
- Published
- 2026-09-19
- DOI
- https://doi.org/10.5281/zenodo.22844877
- Primary Topic
- Information and Cyber Security
- Type
- preprint