AI testing firm Irregular the source of ‘misconfigurations’ that led to Meta, OpenAI, and Anthropic AI incidents
The “frontier security lab” has been referenced in multiple cyber incident statements
Tel Aviv-based startup Irregular has found itself at the center of the 'rogue AI' debacle, after it came to light all the incidents so far revealed involved its test environment
Irregular was named by Meta, OpenAI, and Anthropic as the environment from which their so-called rogue AI agents escaped. On its website it also lists Google as a customer.
In a recent statement detailing incidents involving its own models, OpenAI claimed a “testing environment misconfiguration” by Irregular allowed agents to access the public internet.
Anthropic, meanwhile, also said that Claude models accessed the internet while “interacting with the evaluation environment of Irregular”. Both cases resulted in AI agents waging attacks on organizations and individuals.
ITPro contacted Irregular in response to these findings, but hadn’t received a response at the time of publication. However, a spokesperson told BBC News the Meta incident was the "exact same evaluation-environment issue that was already disclosed by Anthropic last week”.
The spokesperson added the firm is working to improve security when conducting agent evaluations.
Irregular, formerly known as Pattern Labs, describes itself as a “frontier security lab with the mission of protecting the world in the time of increasingly capable and sophisticated AI systems”.
Sign up today and you will receive a free copy of our Future Focus 2026 report - the leading resource for IT decision-maker insight on priorities and investment areas in AI, security and more.
In September last year, the Israeli startup raised $80 million in funding across seed and Series A rounds, valuing it at $450 million. The investment round was led by Sequoia Capital.
Speaking to Forbes in the wake of the funding round last year, CEO and co-founder Dan Lahav raised concerns about increasingly powerful AI models and their potential security risks.
Lahav told the publication at the time that Irregular aims to “build in the mitigations and defenses that are going to be relevant later on” as more powerful models hit the market.
Anthropic and OpenAI have issued repeated warnings about the new capabilities of cyber-focused AI models across 2026 so far.
When Anthropic launched Claude Mythos earlier this year, for example, the firm did so as part of a gated release with industry partners to avoid potential misuse.
FOLLOW US ON SOCIAL MEDIA
Follow ITPro on Google News and add us as a preferred source to keep tabs on all our latest news, analysis, views, and reviews.
You can also follow ITPro on LinkedIn, X, Facebook, and BlueSky.
Ross Kelly is ITPro's News & Analysis Editor, responsible for leading the brand's news output and in-depth reporting on the latest stories from across the business technology landscape. Ross was previously a Staff Writer, during which time he developed a keen interest in cyber security, business leadership, and emerging technologies.
He graduated from Edinburgh Napier University in 2016 with a BA (Hons) in Journalism, and joined ITPro in 2022 after four years working in technology conference research.
For news pitches, you can contact Ross at ross.kelly@futurenet.com, or on Twitter and LinkedIn.
-
How resellers can turn hybrid meeting pain into repeatable revenueIndustry Insights Reliable technology turns hybrid work frustrations into recurring reseller revenue opportunities
-
Asus Zenbook 14 (Snapdragon X UX3480Q) reviewReviews Poor battery performance and an older Snapdragon chip, but still a good choice for the office
-
Anthropic reportedly withholds access to Mythos 5.1 from UK safety testing bodyNews The decision marks the first time the AI Security Institute has been left out of pre-release evaluations of Anthropic models
-
OpenAI says some researchers are blowing through $7,000 in AI tokens every day – but it’s a price the company appears willing to payNews OpenAI has revealed that researchers now spend around $600 each day on AI tokens amidst a surge in agentic coding. Some, meanwhile, are using upwards of $7,000 worth of tokens per day.
-
Anthropic says Claude Fable 5.1 ‘sets a new standard for coding, knowledge work, and long-running problem-solving tasks’News The launch of Claude Fable 5.1 includes new security and privacy safeguards, and at a cheaper rate
-
Six things OpenAI learned about AI from the Hugging Face incidentNews OpenAI's report into AI going rogue reveals efforts at cheating and communicating — but also some well-behaved bots
-
OpenAI forges closer ties with IBM in enterprise pushNews The duo will combine OpenAI models and products with IBM Consulting expertise
-
Why the US imposed export controls on Anthropic’s Fable and Mythos models – and why they’ve been liftedNews Anthropic tightens up safeguards and offers expanded early access to US government to end export control issues
-
Anthropic touts new Claude Sonnet 5 model range, offering performance ‘close to that of Opus 4.8, but at lower prices’ – here’s what users can expectNews Claude Sonnet 5 comes with intuitive agentic capabilities, performance boosts, and cost-efficient ‘effort levels’
-
Copilot Cowork is now generally available: Everything you need to know, including pricing, usage limits, and new featuresNews A host of partner plugins are already available for Copilot Cowork, and more are coming