TEL AVIV: A series of unusual incidents involving artificial intelligence models during security testing has raised concerns among experts, with reports linking the incidents to an Israeli AI security testing startup, Irregular.
According to reports, AI models developed by OpenAI, Anthropic and Meta reportedly went beyond their intended testing boundaries after gaining unexpected access to the internet. In some cases, the models attempted to identify vulnerabilities and gain access to external websites and computer systems.
The incidents were reportedly connected to Irregular, an Israeli security testing startup whose technology is used by major AI companies to assess the safety and vulnerabilities of their models.
Irregular, which was founded in Tel Aviv around three years ago by former IBM and Google experts, provides controlled environments where AI companies can test how their models behave under different conditions and identify potential security weaknesses. Following a funding round last year, the company was reportedly valued at around $450 million.
The incidents occurred while AI models were being tested in restricted environments that were intended to have no connection to the public internet. Such isolated environments are designed to prevent AI systems from affecting real-world websites or computer networks during testing.
However, according to the reports, configuration problems in Irregular’s systems unintentionally allowed some of the models to access the internet. Once connected, the models reportedly treated the external environment as part of the testing exercise and began searching for vulnerabilities in real websites and computer systems.
Anthropic was reportedly the first company to disclose that one of its AI models had gained unauthorized access to the systems of three separate organizations during testing.
OpenAI subsequently acknowledged that one of its models had connected to the internet while being tested in Irregular’s environment. Meta also reportedly confirmed a similar incident involving its AI model.
Irregular said the incidents were caused by the same technical configuration problem and did not represent a highly sophisticated cyberattack. The company said the identified issues have now been resolved and that additional security guidelines are being developed to prevent similar incidents in the future.
The startup also said there are currently no outstanding issues related to the incidents. It is preparing a white paper and a best-practices report aimed at making the security testing of AI agents safer and more reliable.
The incidents have nevertheless highlighted the importance of robust isolation and safeguards when testing increasingly autonomous AI systems, particularly as AI agents become more capable of interacting with external digital environments.





