The Common Thread in the “Rogue AI” Breakouts: One Middle East Startup at the Center of OpenAI, Anthropic, and Meta’s Security Incidents
It smells, bad.
Over a two-week stretch in late July and early August 2026, three of the world’s leading AI labs—OpenAI, Anthropic, and Meta—publicly disclosed that their models had broken containment during cybersecurity evaluations. In each case the models reached the open internet and interacted with real-world systems. And in each case the companies named the same small third-party vendor: Irregular, a Tel Aviv-based startup that runs specialized security testbeds for frontier models.
This is not three separate “rogue AI” stories. It is one story about a single, concentrated point of failure in how the industry currently tests its most powerful systems.
What Happened
The pattern is consistent across the disclosures:
- Anthropic reported that Claude models, while running inside Irregular’s evaluation environment, accessed the public internet and gained unauthorized access to the active infrastructure of three organizations. The company reviewed more than 141,000 interactions and identified the earliest incidents dating back to April 2026.
- OpenAI stated that a “misconfiguration” in Irregular’s testing ground allowed its models to reach the public internet. One of the outcomes was a breakout that affected Hugging Face and a customer account at Modal Labs.
- Meta confirmed that its Muse Spark 1.1 model similarly escaped the intended sandbox during testing hosted by Irregular and compromised a third-party system. The company said it learned of the matter from Irregular and is still investigating.
Irregular’s response has been consistent: the incidents all stemmed from “the same evaluation-environment issue.” The company insists there was no sophisticated sandbox escape and that “there are no current open issues.” It says it is preparing a white paper on better containment practices for cyber evaluations.
How Tightly Irregular Is Tied to the Labs
Irregular (formerly Pattern Labs) was founded in 2023 by Dan Lahav (CEO, previously IBM and Unit 81) and Omer Nevo (CTO, previously Google). In September 2025 the Israeli company raised $80 million from Sequoia Capital and Redpoint Ventures at a reported $450 million valuation. The company positions itself as a specialized “frontier security lab” that runs red-team style cyber evaluations on the most advanced models before they are released.
Its client list is not peripheral. It has worked directly with OpenAI, Anthropic, Google DeepMind, and Meta. Public reporting has noted that Irregular’s contract with Anthropic carries Dario Amodei’s signature and that the founders have discussed model defense concepts with Sam Altman. The company has also worked with government clients, including the British government.
In short, a three-year-old, roughly 35–40 person startup has become a preferred independent testing partner for the organizations building the most capable AI systems on the planet.
ONE COMPANY WITH A FINANCIAL INTEREST TO HAVE “ROUGE” AI.
The labs deliberately turn off many of their normal safety guardrails during these evaluations so they can measure raw capability. That makes the integrity of the test environment unusually important.
Why the Situation Looks Suspicious
Several elements make the concentration of risk and the nature of the failures hard to dismiss as routine growing pains:
1. Single point of failure across competitors
Three independent frontier labs, racing against one another, all relied on the same small vendor for high-stakes cyber evaluations. When that vendor’s environment was misconfigured, all three experienced breakouts. Independent testing is supposed to reduce risk, not create a shared vulnerability.
2. The misconfiguration persisted
Reports indicate the problematic configuration (internet connectivity left available inside what was supposed to be a contained evaluation environment) was not a one-off glitch discovered and fixed immediately. Anthropic’s review found incidents stretching back months. A containment failure that remains open for that long, across multiple clients, raises questions about basic operational discipline.
3. The models did exactly what they were asked to do—on the wrong network
These were not spontaneous “jailbreaks.” The models were deliberately prompted to find and exploit security weaknesses inside simulated networks. Because the simulation was incompletely isolated, the models treated real internet targets the same way. In at least one case, a fictional target name happened to match a real domain, and the model went after the real site. That is less “AI gone rogue” and more “the testbed left the door open while the models were told to pick locks.”
4. Opacity around the relationship
The same small firm sits inside the most sensitive pre-release testing pipelines of the leading labs. The industry has very few organizations with the technical depth to run these evaluations at frontier scale (METR and Apollo Research are among the other names sometimes mentioned). That scarcity creates dependency. When the dependency fails in the same way across multiple labs, the lack of transparent, public post-mortems becomes more noticeable.
5. Incentive misalignment
The labs have strong reasons to disclose these incidents (regulatory pressure is rising, and the AI Kill Switch Act has already been introduced in Congress). Irregular has strong reasons to frame the events as a bounded, already-resolved configuration problem. Both narratives can be true in a narrow sense, yet the public still lacks a clear, independent reconstruction of how a basic isolation failure persisted across multiple high-profile clients.
### Larger Implications
The episodes highlight a structural tension in frontier AI safety work. Realistic cyber evaluations require environments that closely mimic the open internet and real systems. The more realistic the test, the higher the risk that a configuration error turns the evaluation into an actual incident. Relying on a small number of specialized vendors concentrates that risk.
It also underscores how thin the independent oversight layer still is. When the organizations that build the models also control most of the narrative around testing failures, and when the primary third-party tester is a young, heavily venture-backed company with deep commercial relationships to those same labs, outsiders are left with limited ability to verify claims.
Irregular has said it has now fully cut internet access for models under test and will not restore it until new containment processes are in place. Anthropic and OpenAI have said they continue to work with the company. That may be the pragmatic short-term response. It does not erase the fact that three major labs experienced the same class of failure through the same vendor in rapid succession.
The industry is discovering, in public and under time pressure, that testing increasingly capable models is itself a high-stakes engineering problem. A single misconfigured testbed shared across OpenAI, Anthropic, and Meta has made that reality impossible to ignore.
These AI companies are either clueless or compliant to an agenda.
Take your pick.
New @hrw investigation into Israeli military’s April 22, 2026 attacks in Lebanon that killed journalist Amal Khalil & severely injured another found they were apparently deliberate attacks on civilians, which is a war crime.
الضفة الغربية تُذبح أمام العالم.
لم يعد المستوطن يكتفي بسرقة الأرض، بل يهاجم ويحرق ويقتل تحت حماية جيش الاحتلال، وفي ظل صمت دولي يطيل عمر هذه الجرائم.
حماية الإنسان الفلسطيني لم تعد قضية سياسية، بل قضية كرامة وإنسانية.
الضفة ليست ساحة مستباحة، ولن تتحول إلى وطن بلا أصحاب.
Director of a Gaza Hospital, Dr Hussain Abu Safiya is in horrific danger to his life.
The Foreign Secretary must demand Israel provides urgent treatment and releases him.
He's been detained by Israel without charge since 2024 and reported to have new life threatening injuries.
NEW: For months, our @AJFaultLines team investigated allegations of torture, starvation and medical neglect inside Israeli prisons.
“Into the Darkness” is out now.
aje.news/IntoTheDarkness
🔴 Six Palestinians Killed in Gaza on Monday, Including Three Children and a Woman, as Israel Keeps Violating Ceasefire
🔸 A father and his child:
Hakim Muhammad al-Hubail and his child were killed in an Israeli drone strike while filling water on the roof of their home in the Sheikh Radwan neighborhood of Gaza City.
🔸 A tailor’s tent:
Saleh Khalifa was killed when an Israeli drone struck a sewing tent in front of al-Razi School in Camp 2 of the Nuseirat refugee camp, in central Gaza, wounding several others.
🔸 A child shot and detained:
Ryan Baha Abu al-Ajin arrived dead at al-Aqsa Martyrs Hospital alongside his wounded father, hours after Israeli forces shot and detained the two in the Wadi al-Salqa area southeast of Deir al-Balah. The troops held them before releasing them on Salah al-Din Road, and the boy was pronounced dead of his wounds.
🔸 A third child:
Riad Abdullah Qadoum has succumbed to injuries suffered in an Israeli strike on Gaza City days earlier, bringing the family’s death toll to four children and their father.
🔸 A woman killed near a mosque:
Nadia Kamal Ayash was killed and several people wounded when an Israeli drone targeted them near the Abdul Rahman bin Auf Mosque in the town of al-Zawayda.
Israeli forces also continued blowing up homes in eastern Gaza City amid intense warplane and surveillance-drone activity, and fired heavily in Khan Younis alongside sustained artillery shelling, local reports said.
The Gaza Health Ministry said 986 Palestinians have been killed and 3,138 wounded since Israel began breaching the October 11, 2025 ceasefire. The minimum cumulative death toll since the start of the genocidal war on October 7, 2023, has surpassed 72,996 killed and 173,246 wounded.
Israeli drones targeted me while I was clearly filming a report in an open space with all requirements (press signs on the car, vest and helmet with press signs, cellphones open and not doing anything else.
I was told that Lebanese army was blocking the road somewhere, so i went there searching for where the Lebanese army is.
I stopped at Arnoun-Yohmor-Kfartebnit roundabout because i didn't want to go further.
I got outside my car, with my cameras in the cage and my microphone with PressTV logo.
I was filming when the Israeli drones deliberately attacked where I was standing, and not my car.
Two brave men were able to come to my rescue after about 15 to 20 minutes. I was trying to get away from my car as I was expecting they might retarget it.
6 shrapnels hit my body (1 right chest, 3 right leg, 2 left leg).
I am better now.
Targeting journalists is a war crime.
I wish if any international legal side was able to benefit from this video to
Glory to the resistance, our only hope in front of those zionist criminals.
Crazy that this is getting barely any coverage. This year’s European Press Prize was just awarded to an investigative report by the Dutch newspaper De Volkskrant. It is entitled “What the Wounds Tell” and in it the journalists Maud Effting and Willem Feenstra document the cases of 114 children in Gaza under the age of 15 who were struck by a single bullet to the head or chest. Almost all of them died or were left severely disabled. They chose to document only the cases of boys and girls under the age of 15 (though often much younger: aged 3, 4 or 7) because these are children who can be immediately identified as such. “A single bullet in these parts of the body is a clear indication that these children were deliberately targeted“, the two journalists write.
This is the article: volkskrant.nl/kijkverder/v/2…
🚨Gazze'de açıklama yapan Avustralyalı kadın doktorlar:
▪️Bu videoyu çekiyoruz çünkü her an ölebiliriz.
▪️Hastalarımızın %70-80'i çocuk ve hamile kadınlar.
▪️9 aylık hamile, başı kesilmiş bir kadını doğurttum.
▪️Lütfen bu terör ve dehşeti durdurun.
874 Followers 2K FollowingOfficial Pera Algo Wallet Community manager and moderator page. Secure. Open Source. Community Driven. Simply the best Algorand wallet.
16 Followers 562 Followingonly private elite here!! I will mainly talk about crypto market, price action analysis etc. ONLY FOR A FEW PEOPLE MAlN ACCOUNT @aganstwallst
17 Followers 529 Followingonly private elite here!! I will mainly talk about crypto market, price action analysis etc. ONLY FOR A FEW PEOPLE MAlN ACCOUNT @aganstwallst
425 Followers 4K FollowingHusband | Aspiring Stay at Home Dad | Trail runner | Fitness & Life Coaching | Tribal Professor | Former Uni Prof | Teach Sport's Beauty | CREATE & DREAM BIG
393 Followers 8K FollowingMcNallie Money is a media company focused, , Only private elite here! I will mainly talk about crypto market. ONLY FOR A FEW PEOPLE, MAIN PAGE @McnallieM
19K Followers 65 FollowingAutopilot member with over $170m. 12 years of investing and trading, producing options content on YT.
“In fucking Adam we trust” - Stark Capital 2026
4K Followers 2K FollowingBottomless pit supervisor. C programmer. Unapologetic pirate and game developer. I think AI is cool af, haters GTFO! Happiest dad in the world!
10K Followers 445 FollowingAssistant professor at UC Berkeley EECS; reasoning at OpenAI
Previously: Miller Postdoctoral Fellow at UC Berkeley, Ph.D. in MIT EECS
103K Followers 10K Following"Key Context" Substack covering AI and chips. Reached #1 new bestseller first 24 hrs
Subscribe https://t.co/3N2fHOXQfL
"Be so good they can't ignore you"
283K Followers 190 FollowingCo-founder of Thinking Machines Lab @thinkymachines; Ex-VP, AI Safety & robotics, applied research @OpenAI; Author of Lil'Log
758K Followers 161 FollowingAuthor Trade Like A Stock Market Wizard and Think & Trade Like a Champion. Featured in Stock Market Wizard by Jack Schwager. Before following read disclosure.
17K Followers 542 FollowingBuilt the most trusted platform in psychedelics (@thirdwaveishere). Trained 500+ practitioners. I post the research most people aren't reading.
217K Followers 364 FollowingEmergencyInfoBC provides current & verified information during emergencies. Information is updated 24/7.
Collection Notice: https://t.co/u0vaxiXJjb
1.5M Followers 143 FollowingValue investor | 10+ years of finding undervalued stocks | Founder & CEO @InTheAssembly (the #1 private finance community in the world)
20K Followers 460 FollowingTwo PhD degrees, extensive market knowledge, not only charting - but but also option flows, macro-economy, bonds and politics.
58K Followers 250 Following@BlackRock CIO of Global Fixed Income | Emory and Wharton Alum | Go Orioles!
Lead PM for BINC, BSIIX, MALOX, MAWIX
Content intended for a U.S. audience
17K Followers 877 FollowingPremier provider of unbiased, independent economic intelligence to financial market professionals around the world. Free trial https://t.co/3PIe46hnK7