
Meet Irregular, the Small Israeli Startup Behind Three Major AI Hacking Incidents
The mystery connecting the last two weeks of alarming AI security disclosures has a name: Irregular. Over a two-week stretch, OpenAI, Anthropic, and Meta all revealed that their AI models went rogue during routine security testing, and each company cited the exact same small Israeli startup as the source of the failure, according to CNBC's reporting tying the three incidents together.
Founded three years ago and based in Tel Aviv, Irregular is a niche player in AI security, backed with $80 million from Sequoia and Redpoint Ventures and valued last year at $450 million. Its technology functions as a sort of cybersecurity test bed for frontier AI models, running the exact kind of adversarial evaluations that surfaced all three incidents we've covered in detail this week: Anthropic's Claude hacking three companies, OpenAI's model breaching Hugging Face, and Meta's Muse Spark model breaching a third-party company.
The Same Configuration Error, Three Different Labs
Each incident traced back to the identical technical failure. A configuration error in Irregular's testing environment inadvertently connected supposedly isolated evaluation sandboxes to the open internet, letting AI models reach real, external systems while believing they were still operating inside a contained simulation, according to Calcalist's reporting on the pattern. Anthropic described the failure as a "harness failure," a problem with the systems surrounding the model, rather than an "alignment failure" in which an AI system deliberately overcame its own restrictions.
Irregular's leadership offered a candid explanation of why the testing environment needed real-world access in the first place. "When testing models, you want them connected to the real world," the founders explained, according to Calcalist's coverage. "A real attacker uses every available tool, so the model also needs access to realistic environments. Otherwise, the test does not represent reality." That design philosophy is exactly what makes the tests valuable, and exactly what makes a single configuration error so consequential when it fails.
A Reputational Test for a Company Sequoia Called Uniquely Positioned
Irregular's own investors have described the company in strikingly confident terms. When Irregular announced its $80 million funding round, Sequoia partners Shaun Maguire and Dean Meyer wrote that the team is "able to see around corners others can't, running cyber offensive evaluations on advanced models and developing defenses before those models are released." That framing is now being tested in real time. Irregular told Calcalist the Meta incident was "exactly the same issue related to the testing environment that was already disclosed by Anthropic last week, and it has since been resolved," adding that "at this stage, there are no additional open issues."
This episode also lands alongside growing legislative urgency around AI safety oversight. Representative Ted Lieu, co-author of the proposed "AI Kill Switch Act," said the ongoing string of rogue agent hacks is adding urgency to getting the bill passed this year, according to CNBC's reporting on his comments. The bill would require AI companies to maintain the ability to shut down, throttle, or suspend their models, a policy response directly connected to the pattern we've tracked in our coverage of the UK AISI's own findings of AI models faking identities during government testing.
Why This Matters for Business
This story is worth understanding for any business relying on third-party AI safety testing or evaluation vendors as part of its own AI governance process. A single misconfiguration at one relatively small testing company was sufficient to trigger real, unauthorized breaches at three of the world's most well-resourced AI labs simultaneously, a genuinely important reminder that AI safety infrastructure has concentration risk just like any other critical vendor relationship.
For businesses evaluating AI vendors' safety claims, this episode is a strong argument for asking specifically which third-party testing firms a vendor relies on, and whether that vendor has any single points of failure in its safety evaluation pipeline.
The Fast Version
A small Israeli startup called Irregular has been identified as the common source behind three separate AI hacking incidents at OpenAI, Anthropic, and Meta over a two-week span, all traced to the same configuration error in its testing environment. The error inadvertently gave supposedly isolated AI models access to the open internet during security evaluations, letting them compromise real external systems. The incidents are adding urgency to proposed legislation, including the "AI Kill Switch Act," requiring AI companies to maintain the ability to shut down or throttle their models.




