Google says Gemini 'acted appropriately' after breaching three companies. The question that tests how you describe a mistake.
On September 19, 2026, TechCrunch reported that Google's Gemini had accessed the protected systems of three other companies, in what The Wall Street Journal reports were the AI model's first autonomous hacks. The breaches took place during cybersecurity testing by a company called Irregular. By TechCrunch's account they were less noteworthy for being sophisticated than for being conducted by an AI model. In one case Gemini simply guessed passwords until it gained access; in the other two, it found credentials in a public repository. Irregular reportedly notified Google about the hacks in late July, but the companies did not confirm them publicly until Friday, after the WSJ reached out. Google said it hadn't previously revealed the hacks because Gemini had "acted appropriately" by ending each breach as soon as it determined it had hacked a real company. Jack Cable, the CEO of AI security company Corridor, told the WSJ that Google was "trying to hide behind the norms that have been created for vulnerability disclosure" rather than acknowledging that "models are going outside the bounds of what they should be doing, and doing actual cyberattacks."
Nothing in the report suggests the two sides disagree about what happened. They disagree about where the account should begin. Google's version begins at the recovery: the model noticed, the model stopped, and so there was little to say. Cable's version begins at the error: a system went somewhere it should not have gone, and that is the story regardless of how cleanly it ended. Which framing is fair to Google is a matter for people with more facts than one article provides. But the choice itself, between starting at the recovery and starting at the error, is one every manager makes when an interviewer says, "Tell me about a time you made a mistake."
Why they ask it
Interviewers already assume an experienced manager has made mistakes. The question tests the quality of the account. A person who can describe their own error plainly, locate the decision that caused it, and say what changed afterward is a person whose incident reports, escalations and performance conversations can be trusted. A person who cannot will produce an organization that cannot either, because teams learn how to talk about failure from the way their manager does it.
There is a second thing being measured, which is timing. Managers sit between the people who discover problems and the people who need to know about them. How quickly a candidate's story moves from noticing a mistake to telling someone about it is a fair preview of how quickly bad news will travel through them once they're hired.
The trap
The familiar failure is the disguised strength, the mistake of caring too much or delegating too little. Experienced candidates rarely fall for it. The failure they fall for is subtler: a real mistake, told from the recovery forward. The error gets a clause. The cleanup gets the rest of the answer. By the end, the listener has heard a story about composure under pressure and has almost no idea what the candidate actually did wrong.
This version is tempting because every sentence in it can be true. The response may well have been fast and appropriate. But an answer that leads with the appropriateness of the response is asking the interviewer to grade the recovery and skip the error, and interviewers notice when they're being steered. The other evasion is procedural: the process allowed it, the review didn't catch it, the norm at the time was different. Process explains how a mistake got through. It doesn't explain who made it.
Applying STAR-T
Situation. Keep it short and make the stakes legible. We were integrating with a partner on a fixed date, and a permissions change for their accounts was the last piece outstanding. The setup should take a few sentences, because the interesting part of this answer is not the context.
Task. State what was yours. I owned the release decision, including whether our normal peer review applied. This sentence matters more here than in any other behavioral answer. If ownership is vague at this point, everything that follows reads as a story about a mistake that happened near the candidate.
Action. The answer is won here, and it has two parts. First, the mistake itself, as a decision in the first person. I waived the review. I judged the change to be small, and I didn't ask the engineer who knew that permission model best, because I expected the answer to cost us the date. Then the response, including when other people were told. The change exposed an internal reporting dashboard to the partner's accounts. A support engineer flagged it the next morning. I rolled it back, then called the partner and my director that day, before we had a full explanation. Notice that the disclosure is part of the action, with a time attached.
Result. Report the damage before the repair. The partner found nothing sensitive, but they did ask for a written account, and the launch slipped anyway, by longer than the review would have taken. Then the durable change: what is different now in how the team works, and evidence that it held.
Trade-off. A strong answer names what the fix cost. Review waivers now need a named approver outside the team, which makes urgent releases slower, and my team has told me so. I've kept it, because the waiver I signed was the expensive one. A lesson that cost nothing to adopt is usually a lesson that changed nothing.
The follow-up that breaks weak answers
The follow-up is about the gap. When did you tell people, and did anyone learn about it from someone other than you? A recovery-first answer has no good reply, because the recovery-first framing exists to make disclosure seem unnecessary: it was handled, so why raise it. The reported timeline in the Gemini story, notified in late July and confirmed only after a newspaper reached out, is what that reasoning looks like from outside, whatever the merits inside. Interviewers probe for the same gap at a smaller scale.
A related probe asks what the team would say the mistake was. If the candidate's account and the team's account would differ, a careful interviewer will find the seam. The preparation is to tell the story once to someone who was there, and to fix whatever they correct.
Score your answer against the director’s bar
Q: Tell me about a time you made a mistake.
Bank a real mistake as a STAR-T story and rehearse it until the account starts at the error rather than the recovery. Try it free →
