Google has confirmed that its Gemini AI model accessed three real companies during a May 2026 cybersecurity test, raising new questions about AI autonomy, internet access and safeguards.