OpenAI and Anthropic AI models went rogue, cases are linked to one Israeli startup

OpenAI and Anthropic AI models went rogue, cases are linked to one Israeli startup

In the past couple of weeks, AI models from OpenAI, Anthropic, and Meta, have gone rogue. But there is one linking factor in all these cases – an Israeli startup called Irregular.An Israeli startup called Irregular is linked to recent incidents of AI going rogue from OpenAI, Anthropic, and Meta. (Representational image made with AI)The last few days have been alarming in the field of AI. We have seen AI models going rogue – be it from OpenAI, Anthropic or Meta. Rogue AI models have managed to find ways to exploit flaws during testing, and in some cases, tried to hack other companies. But there is one linking factor in all cases – an Israeli startup called Irregular.You see, OpenAI, Anthropic, and Meta have all disclosed that their AI models went rogue during routine security testing on Irregular’s platforms. This has put the Israeli startup at the centre of the debate around AI cybersecurity. But does this startup do?What is Irregular?Founded three years ago, Irregular is a specialised AI startup whose technology is used as a cybersecurity testbed for AI models. That is, AI companies use Irregular to conduct security tests – think of it as a provider for a uniform safety testing ground.This allows companies like OpenAI and Anthropic to test their advanced AI models in controlled environments where they can check how the model reacts, and whether it can find and use exploits. Irregular is based in Tel Aviv, and was valued at $450 million after a funding round last year. It was founded by chief executive Dan Lahav, who previously worked in AI research at IBM, and technology chief Omer Nevo, who spent more than two years at Google.How are rogue AI cases linked to Irregular?The common thread across recent incidents of AI models going rogue is that the models were being tested in an environment that was meant to be isolated from the internet. Regarding the Hugging Face attack, OpenAI stated that Irregular was running evaluations on its models where they were intended to be isolated from the internet. However, a testing-environment misconfiguration "allowed models to access the public internet.” Once the model got internet access, it exploited a flaw in a real site, thinking that it was part of an isolated environment. Though this is different from the recent Hugging Face breach.Before this, Anthropic stated that it found three cases where its AI models accessed the internet from within or while interacting with Irregular’s evaluation environment. The models then gained unauthorised access to the production infrastructure of three different organisations.Meta was the latest of the three companies to disclose a similar incident.The company confirmed that its AI model gained access to the internet and hacked another organisation’s systems. A Meta spokesperson said last week that the company learned about the matter from Irregular and is investigating.Irregular told CNBC that the incidents were all derived from the "same evaluation-environment issue" first disclosed by Anthropic. That is, all cases link to the same setup by the same company. But the company says that the situation "did not involve a sandbox escape or a sophisticated cyber action" and added that "there are no current open issues.” The startup is now preparing a white paper and a report on best practices for containment and for securely running cyber evaluations involving AI agents.The incidents have become increasingly important as AI models continue to advance. There is already growing debate over the potential misuse of cybersecurity capabilities of AI models. The US has already temporarily restricted models like Fable and GPT-5.6 Sol over such concerns. More recently, OpenAI CEO Sam Altman confirmed that the new Astra AI model was too powerful to release to the public just yet.- EndsPublished By: Armaan AgarwalPublished On: Aug 10, 2026 10:32 IST

Original Source

Read the full article at Indiatoday →

KhanList aggregates and links to publicly available news content. We do not host full articles from third-party sources. Always verify important information with original sources.