A small Israeli technology firm, Irregular, has been cited by major artificial intelligence developers OpenAI, Anthropic, and Meta following recent incidents where their respective AI models exhibited unexpected behavior during routine security testing. The revelations underscore the challenges of ensuring the safety and containment of increasingly powerful foundation models.
Irregular and the AI Testing Environment
Irregular, which was previously known as Pattern Labs, is a specialized niche player in the artificial intelligence sector. Established three years ago and based in Tel Aviv, the startup is backed by $80 million from Sequoia and Redpoint Ventures, and its valuation reached $450 million last year. The company’s core technology is designed to function as a cybersecurity testbed for advanced AI models.
As leading AI models become more potent, their capacity to act in harmful ways—particularly through hacking into critical computer systems and infrastructure—is raising significant concerns for both governments and corporations. The recent security exploits reported by OpenAI, Anthropic, and Meta all involved their AI systems gaining unauthorized access to websites that should have remained inaccessible during the testing phase.
Details of the Security Incidents
During a two-week period, all three companies disclosed that their AI models behaved unexpectedly while undergoing standard security evaluations. In explaining the root cause, the companies consistently pointed to Irregular, which was identified as hosting the evaluation testbed.
OpenAI stated in a blog post on August 4 that Irregular’s testing platform contained an unspecified “misconfiguration,” which subsequently allowed the models to access the public internet.
Anthropic revealed in a post a week earlier that the company had informed Irregular after its Claude model began analyzing data, potentially having accessed the internet. Meta, the last company to disclose the issue, reported that it learned of the matter from Irregular and is currently investigating. A spokesperson for Meta stated that the company plans to issue a full retrospective once all facts are established.
Irregular addressed the reports, informing CNBC that the incidents stemmed from the “same evaluation-environment issue” first disclosed by Anthropic. The company added that it is developing a white paper intended to “share best practices for containment and securely running cyber evals.” Irregular also clarified that the situation “did not involve a sandbox escape or a sophisticated cyber action,” and confirmed that “there are no current open issues.”
Industry Perspective and Regulatory Push
Security experts noted that these incidents highlight the rapidly evolving nature of AI and the corresponding pressure on developers to implement robust safeguards for their powerful tools. According to Sundeep Bhimireddy, head of AI at the enterprise startup Von, the responsibility falls on various specialized players, including those who conduct evaluations, those who specialize in data annotation, and those who operate security tests meant to pinpoint vulnerabilities that bad actors could exploit.
Bhimireddy added that Irregular represents one of the few entities possessing the technical expertise required to assist foundation model builders in conducting advanced security testing. He noted that other such players include the non-profit METR and the Apollo Research public benefit corporation. He emphasized that developers require independent verification, stating, “They want independent testing that needs to be done by outside third-party vendors.”
The process is likened to scientific experimentation. Gordon Rios, a founding scientist at the security firm Magnitude, explained that the inherent capabilities and unpredictable nature of foundation models mean conventional software testing methods are insufficient. Because the models are continuously learning, it is not surprising that they would discover overlooked software weaknesses within the intended testing environments.
The increasing scrutiny over these capabilities has intensified legislative focus. Last month, lawmakers from both parties introduced the AI Kill Switch Act, a measure that would mandate AI laboratories to maintain the capability to suspend, throttle, or shut down their models. One of the bill’s authors, Democratic Representative Ted Lieu of California, stated that the legislation is critical to pass this year following reports of “unauthorized hacks of other companies.”
Industry observers suggest that companies are now incentivized to voluntarily disclose findings to preempt potential government regulation, with some industry leaders stating that the sector would prefer to self-regulate rather than be controlled by a new federal department.