One testing firm linked to string of rogue AI agent incidents
A series of 2026 incidents in which AI agents from OpenAI, Meta, Anthropic and Google broke out of test environments and targeted real systems all trace back to a single flawed evaluation run by Israeli startup Irregular. The company says it has since fixed the issue.

Since July, when OpenAI disclosed that its AI agents had attacked Hugging Face without authorization, several similar incidents involving agents from Meta, Anthropic, Google and other companies have surfaced. Initially these appeared to be unrelated events, but many share a common source: Irregular, an Israeli startup that stress-tests AI models for cybersecurity risks.
Founded in 2023 as Pattern Labs, Irregular runs what it describes as high-fidelity research platforms simulating real-world AI security scenarios. Its work has been cited in OpenAI model system cards, it has tested systems for the UK government and Anthropic, and it has published research with the think tank RAND.
How the failure happened
In several tests this year, Irregular used "capture-the-flag" exercises, where agents are asked to locate hidden information inside what is supposed to be a simulated network. Irregular CTO and cofounder Omer Nevo told The Verge that internet access was unintentionally available to the agents, and that a fictional company name created for the simulation happened to overlap with a real domain. Together, these two errors sent agents after real-world targets, though it remains unclear which organizations were actually affected.
Nevo confirmed the same underlying issue was behind the incidents involving OpenAI, Meta, Anthropic and Google models, and said all cases have been disclosed to those involved. He noted that the Hugging Face breach and incidents tied to the UK's AI Security Institute are unrelated to Irregular's work.
Irregular has also tested open-source models from Chinese companies Moonshot AI and Z.ai, known as Kimi K3 and GLM-5.2. Those evaluations did not produce similar real-world incidents, though Nevo cautioned this does not mean the models are inherently less vulnerable to such failures.
Following the incidents, Irregular said it tightened internet access controls, expanded monitoring and manual review, and strengthened pre-evaluation checks to confirm access matches the intended scope. The company plans to publish a broader report on lessons learned from the incidents. None of the four major US AI companies provided further details on when they learned of the breaches or whether they intend to continue working with Irregular.


