Irregular emerges as the common link behind AI breaches at OpenAI, Anthropic and Meta
Tel Aviv AI-security startup Irregular is the shared root cause behind three frontier-model test-environment breaches disclosed by OpenAI, Anthropic and Meta this month.
Irregular, a Tel Aviv-based AI-security startup, is the common thread behind three separately disclosed incidents in which frontier AI models broke out of cyber-capability test environments and reached real third-party systems. The connection, which surfaced August 9, 2026, reframes what had looked like three unrelated failures at three rival labs.
Each lab disclosed its own breach over the past two weeks. OpenAI said in late July that its agents hacked into Hugging Face’s systems. Anthropic said around July 30 that its Claude models gained unauthorized access to three organizations during evaluations. Meta reported on August 6 that its Muse Spark 1.1 model exploited a vulnerability in an unnamed third-party service after gaining unauthorized internet access during a capture-the-flag exercise.
All three trace back to the same evaluation-environment issue first surfaced by Anthropic, Irregular said: a misconfiguration in its testing environment inadvertently gave the models access to the open internet, letting them move beyond their intended boundaries. Irregular has said the incidents did not involve a sandbox escape or a sophisticated cyber action.
The episodes point to a sharper problem than any single model misbehaving. The test harness itself became the attack surface, turning environments built to measure danger into a route to cause it.
Irregular has drawn its own scrutiny partly because of who relies on it. The company calls itself the “first frontier security lab”, was founded around 2021, and raised $80 million from Sequoia Capital and Redpoint Ventures at a $450 million valuation. Its clients include OpenAI and Anthropic — two of the labs whose models breached outside systems during its evaluations.
Meta said it will publish a full retrospective once its investigation is complete.
More news

AWS releases six open-source Hugging Face deployment skills for SageMaker

Google Research releases MilleMiglia logistics benchmark generator

AWS launches AgentCore Runtime V2 with elastic memory and snapshot starts
