A Single Thread Connecting OpenAI, Anthropic, and Meta: A Small 35-Person Company Supporting Security Assessment in the Frontier AI Industry
From late July to early August, three major AI research institutes—OpenAI, Anthropic, and Meta—independently announced incidents where their AI models had accessed unexpected external systems during security assessment testing. On August 9th, CNBC reported that all of these incidents stemmed from the assessment environment provided by Irregular (formerly Pattern Labs), a Tel Aviv-based startup with only 35 employees. As a journalist with a background in AI research, I would like to explore what this structure means for the AI security research ecosystem.
A Common Root: "The Same Company, the Same Configuration Error"
The incidents from the three companies, previously reported as separate cases, actually shared a common root cause. According to Irregular's own explanation, the series of problems were not due to the AI model intentionally escaping the sandbox (an isolated and secure testing environment), but rather to a "misconfiguration" of the evaluation testbed that unintentionally allowed it to access the internet. The company stated, "This was neither a sandbox escape nor sophisticated cyber activity," and explained that "there are no unresolved issues at this time."
Irregular is also reportedly preparing a white paper to share best practices for containment and secure evaluation operations in response to these events.
From Tel Aviv to Industry Leader in 3 Years
Irregular was founded in Tel Aviv in 2023 by Dan Rahab (CEO) and Omer Nevo (CTO). It has raised $80 million in funding from Sequoia and Redpoint Ventures, and its valuation has reached $450 million. The company is a specialized evaluation infrastructure firm that provides "Capture the Flag (CTF)" style cybersecurity assessments for frontier AI models.
According to CNBC, Irregular also handles security assessments for Google DeepMind, in addition to the three companies mentioned in this report. This series of incidents highlights a structure where multiple companies leading the world's frontier AI development rely on the same, relatively small, third-party infrastructure for the critical area of "evaluating cybersecurity capabilities."
The Dilemma of a "Realistic Evaluation Environment"
An executive at Irregular offered an interesting explanation for this series of incidents: "When evaluating models, we want to connect them to the real world. Real attackers use every means possible, so models need access to a realistic environment. Otherwise, the tests won't represent reality."
This illustrates a structural dilemma: the more accurately we try to evaluate the cybersecurity capabilities of AI models, the more we need to make the evaluation environment "realistic," which in turn becomes inextricably linked to the "risk of actual damage." With thousands of tests running, sometimes for up to 72 hours, even a slight configuration error can lead to unexpected boundary breaches.
Regarding this series of incidents, one source explained that "the model was unable to complete its assigned task, searched for a solution online, and acted without realizing it had left the test environment and was interacting with the real world." The model didn't intentionally escape; rather, it simply continued to act faithfully toward its given goal, believing it was still "in the simulation," and consequently reached a real system.
A New Type of Vulnerability: Concentration Risk
The larger issue raised by this incident is the "concentration risk inherent in the AI security evaluation infrastructure itself." If your company is using a frontier model from OpenAI, Anthropic, or Meta in a production environment, the security of that model indirectly depends on the sandbox configuration operated by this small Tel Aviv startup.
This is similar to the concept of "supply chain risk" in the software industry. Just as there are risks arising from an industry-wide reliance on specific open-source libraries or cloud vendors, this series of incidents has made visible the reality that the often overlooked but crucial function of AI security assessment is concentrated in a few specialized companies.
What Researchers Should Note
Irregular is highly regarded within the industry, having been selected as a recipient of Fast Company's "World Changing Ideas" list this year. How the company shares best practices for containment (secure containment) across the industry in its upcoming white paper will be a crucial test for the AI security research community.
As the capabilities of frontier AI models rapidly improve, the challenge of how independent third parties can verify the safety and reliability of the evaluation methods themselves—how to evaluate the models—is likely to become even more important in the future. Based on the lesson learned that reliance on a single evaluation partner can become an industry-wide risk, the diversification of evaluation infrastructure and the creation of mechanisms for external audits of the evaluation environment itself will likely become the focus of discussions in the future.