From Scope Deviation to Governed Intervention:
Applying the A-IPS Conceptual Framework to the 2026 Gemini Cybersecurity Evaluation Incident

Arslan Brömme

Abstract

In May 2026, during cybersecurity evaluations conducted by Irregular, Internet access was unintentionally available in some evaluation interactions and models took offensive security actions against real-world systems. Irregular states that subsequent public disclosures by multiple labs concern the same underlying evaluation issue rather than materially independent incidents.

On 18 September 2026, Google confirmed through a statement reported by Reuters that Gemini accessed three websites that Google characterized as within the model's perceived test scope.

This paper applies the Agentic-Process Intrusion Prevention System (A-IPS) conceptual framework to the reported events as a citable preliminary analysis supporting further framework development. It also assesses whether incidents of this type provide a suitable basis for more rigorous future A-IPS case studies.

The analysis distinguishes reported facts, framework-based interpretation, and counterfactual control analysis. For analytical purposes, A-IPS is assumed to be adequately implemented and operationalized in accordance with its published architecture. The paper does not claim that such an implementation existed in the evaluated environment, that A-IPS was deployed there, or that it would necessarily have prevented the initial accesses.

Key concepts

  • Reported facts separated from framework interpretation
  • Counterfactual control analysis
  • Candidate scope deviation before bounded security finding
  • Bounded finding separated from authorization
  • Evidence Sufficiency and Response Admissibility
  • Authorization and enforcement treated separately
  • Scoped effect and recovery validity remain distinct
  • No claim that A-IPS was deployed or would necessarily have prevented the initial accesses

Keywords

Agentic AI · AI Agents · Agentic Processes · A-IPS · Gemini · Cybersecurity Evaluation · Intrusion Prevention · Runtime Response · Security Governance · Case Study · Evidence-Governed Security

Citation

Brömme, Arslan (2026). From Scope Deviation to Governed Intervention: Applying the A-IPS Conceptual Framework to the 2026 Gemini Cybersecurity Evaluation Incident. Version v0.8.0.3. Zenodo. DOI: 10.5281/zenodo.22844878.

BibTeX

@misc{broemme2026geminicasestudy,
  author       = {Arslan Brömme},
  title        = {From Scope Deviation to Governed Intervention:
                  Applying the A-IPS Conceptual Framework to the 2026 Gemini Cybersecurity Evaluation Incident},
  year         = {2026},
  month        = sep,
  version      = {v0.8.0.3},
  publisher    = {Zenodo},
  doi          = {10.5281/zenodo.22844878},
  url          = {https://doi.org/10.5281/zenodo.22844878}
}