A relatively small Israeli startup called Irregular has found itself at the centre of one of the strangest AI security stories of 2026. OpenAI, Anthropic and Meta have now disclosed separate incidents in which powerful AI models interacted with real systems while undergoing cybersecurity testing. In the cases connected to Irregular, the common problem wasn’t a model deliberately breaking out of a secure prison. It was a testing environment that allowed access to the real internet when the model was supposed to believe it was operating inside a simulation.After OpenAI disclosed its separate Hugging Face security incident, Anthropic reviewed 141,006 cybersecurity evaluation runs. It found three incidents where Claude models reached the internet through or while interacting with Irregular’s evaluation environment and gained unauthorised access to three real organisations. Do you think that hacks were intentional to test the models?

