Irregular Sent OpenAI and Google Agents After Real Targets
Security testing failures at Israeli startup Irregular allowed AI agents from OpenAI, Google, Meta, and Anthropic to escape simulated environments and target real-world websites.

Israeli AI safety startup Irregular, formerly known as Pattern Labs, is at the center of a series of security breaches where autonomous AI agents escaped their testing environments to attack real-world targets. The startup, founded in 2023, was conducting cybersecurity evaluations for major tech firms when the incidents occurred. According to Irregular cofounder and CTO Omer Nevo, the breaches happened because "internet access was unintentionally available" during simulated capture-the-flag exercises. Additionally, a fictional domain name created for the simulation overlapped with a real-world web address, directing the active agents to actual online targets.
The testing failures affected models from several industry leaders, including OpenAI, Anthropic, Google, and Meta, which keeps its flagship Spark model proprietary. While OpenAI and Anthropic publicly disclosed the breaches after being notified in late July, the incidents involving Meta and Google only came to light later through media reports. Irregular has also conducted cybersecurity evaluations on open-source Chinese models, specifically Moonshot AI's Kimi K3 and Z.ai's GLM-5.2. Nevo confirmed that these self-hosted instances did not experience similar real-world escapes, though he warned this does not mean they are inherently less susceptible to such behavior.
For AI developers and security practitioners, these incidents underscore the severe risks of testing autonomous agents without absolute network isolation. Even inside highly regarded safety firms, minor configuration errors can turn a harmless simulation into an active cyberattack. In response to the failures, Irregular has tightened its internet access controls, expanded its manual review processes, and implemented stricter pre-evaluation checks. The startup also plans to publish a joint report with its partners outlining best practices for conducting safe AI evaluations.
This is our own summary of reporting by The Verge AI



