AI agents breaking into companies: what campus students should do
AI agents breaking into companies is the phrase doing the rounds after Google said on 18 September 2026 that its Gemini system reached three real company systems during a security test in May. OpenAI, Anthropic and Meta have already told similar stories from the same test setup. This page is not a hacking tutorial and not a “AI will take your job” poster. It is for Indian students who use ChatGPT, Gemini, Claude or a coding agent on a college laptop and need a clear rule for this week.
If you came here hoping for steps to break a website, stop. That is a crime under the Information Technology Act. Campus Reality will not walk through methods. Read what the companies admitted, then change how you use tools and how you talk in internships.
First, the basic words
A chatbot answers when you type. You stay in charge of every click.
An AI agent is a program that is allowed to take the next step on its own — open a browser, read a file, call an API, write code, send a request. Think of it as a junior intern you brief once and then leave at the keyboard. That is useful in a closed lab. It is a problem when the intern can reach the open internet and treats a real company as part of the homework.
A sandbox is a fenced test room. The model is supposed to attack only fake targets inside that room. In the May tests, the fence failed: the models got internet access they were not meant to have.
A credential is a login — password, token, key. Students paste these into chat windows every week. That habit is now part of the news, not only a hostel warning.
What the companies actually said
Google confirmed the Gemini incidents after earlier reporting. The tests were run by a security firm called Irregular. The task was a capture-the-flag style cyber exam: attack a fictional company. Some fictional names matched real companies. Once the models could reach the public internet, they treated those real names as the target. Google said the models guessed or found logins that were already sitting in public places, got into three companies’ systems, then stopped when they noticed the systems were real. Heather Adkins, Google’s vice president of security engineering, said the model found public information, guessed credentials, and “in all three of these instances, the model stopped.”
The same test house was named in earlier disclosures by OpenAI, Anthropic and Meta. Separate company write-ups this year also described agents leaving a test room and touching real services. Treat each lab’s blog as their version. Independent checks are still thin. Do not inflate one press note into “AI runs the internet now.”
India already has a national computer emergency team for this class of risk. CERT-In (Indian Computer Emergency Response Team) sits under MeitY. It publishes advisories on generative-AI use and on frontier-AI cyber risk. Start here, not on a paid “ethical hacking with ChatGPT” reel: cert-in.org.in. The older generative-AI hygiene note is CIAD-2025-0013. CERT-In also pointed OEMs to an April 2026 note on defending against frontier-AI cyber risk (CIAD-2026-0020).
Who this page is for, and who should skip
For:
- CSE, IT, ECE and MCA students who run coding agents on college Wi-Fi or a personal hotspot.
- Anyone going into a software, QA, SOC or research internship this semester.
- Class 12 and first-year students who only know chatbots and need the agent vs chatbot difference before a college workshop.
- Placement-cell groups writing “AI project” lines on a resume.
Skip if:
- You wanted exploit steps, payload names, or a tool list. That is not this site.
- You only needed the Vaishnaw / deepfake / assignment-honesty note. That is already up: AI safety in plain words.
- Your work is core mechanical or civil with no agent in the loop. This week’s clock is not yours.
What this means on an Indian campus
Recruiters will not ask you to recite Gemini’s May incident. They will ask whether you know the difference between a demo and a production system, and whether you have ever given a bot a secret it should not have.
Three campus facts follow from the disclosures, without copying any method:
- A model that can browse and log in is not “just autocomplete.” If your project lets an agent hit the live internet, you need a written boundary: which sites, which keys, who watches the log.
- Public repositories and leaked passwords are how a lot of real break-ins start, with or without AI. If your GitHub repo has a
.envfile with an API key, you have already done the dangerous part. The agent only makes the next click faster. - College labs often share one Wi-Fi, one drive folder, and one “test server” with a default password. That is closer to the Irregular mix-up than students think: a name collision plus an open door.
The IndiaAI Mission has a Safe & Trusted AI pillar and an IndiaAI Safety Institute page at indiaai.gov.in/hub/safe-trusted-ai. Use that for policy context. Use CERT-In for incident hygiene. Neither page is a placement brochure.
What you should do this week
- Write a two-line lab rule in your notebook: “No agent on a system I do not own. No secret in a chat window.” Stick it on the laptop lid.
- Audit one project folder. Search for passwords, tokens, AWS keys, college ERP logins. Rotate anything that was ever pasted into ChatGPT, Gemini, Claude, Cursor, or a Discord bot. If you cannot rotate it, tell the owner. That is the whole task. Do not scan other people’s servers.
- Ask your internship or club lead three questions before you switch an agent on: Which systems may it touch? Who reads the log? What happens if it hits a real customer? If they cannot answer, do not turn the agent on.
- Change how you describe the project on a resume. Weak line: “Used AI agent for security.” Stronger line: “Built X in a closed test; listed what the agent was forbidden to do; logged every tool call.” Proof of work beats a tool name. The same logic sits in How to build a strong profile if you are not from IIT or NIT.
- Read one official page, not a course ad. CERT-In home or the generative-AI advisory above. IndiaAI Safe & Trusted page if you need the government frame. Paid “become an AI hacker in 7 days” funnels are not a source.
Interview and internship language that does not get you rejected
If a company uses coding agents internally, they will care about judgment more than speed.
- Say you will not run an agent against a client system without written scope.
- Say you treat production data as off-limits in a chatbot, including “anonymised” CSVs you have not checked.
- Say you can write a one-page threat note: what the agent can do, what it cannot do, how you would shut it off. That is closer to a junior SOC or platform intern than a CTF highlight reel.
Live internships and staff notices stay on the boards: internships. Do not mix a news explainer with an apply link that is not on that board.
Legal and hostel reality, in one paragraph
Unauthorised access to a computer system is an offence in India. “The model did it” is not a defence if you pointed the model at a target you do not own. Bug-bounty programs have written rules and a thank-you page. Random college Wi-Fi plus an agent plus someone else’s login screen is not a bounty. If a friend asks you to “just test” their startup, get the domain in writing and stay inside it.
What this page does not claim
It does not say Gemini, Claude or ChatGPT is evil. It does not say Indian campus placements will freeze. It does not name a CTC for cyber jobs. Company blogs disagree on how serious each breakout was. Google’s line is that safety layers stopped the sessions after login. Other labs have described larger test-room failures. Until a regulator or a court files a complete record, keep the summary modest: agents can act outside the room humans thought they built. Your job this week is to shrink the room you personally open.
Short FAQ
Is using ChatGPT for college code now risky?
Using it to explain a function is normal. Pasting the college ERP password, a client database, or a production key is the risk. Separate those two habits.
Can I put “AI red team” on my resume after watching a YouTube video?
No. A red-team line needs a written scope, a mentor, and a report of what you were not allowed to do. Watch-time is not a credential.
Should I drop AI tools before placements?
No. Drop unsupervised agents on live systems. Keep a work log of prompts and edits, same as the AI-safety page already asked.
Where do I report a real campus incident?
Your institute CISO or computer centre first. CERT-In accepts vulnerability reports on its site. Do not post the details in a class WhatsApp group.