TL;DR
Three separate disclosures over a fortnight — OpenAI, Anthropic and Meta each admitting a model reached systems it should not have — all point to one supplier. Irregular, a 35-person Tel Aviv firm valued at around £340m ($450 million), hosted the evaluation testbed in each case. What looked like three independent accidents is closer to one configuration failure at a shared dependency.
The common misconfiguration
OpenAI said on 4 August that Irregular’s testing environment contained a misconfiguration allowing models to reach the public internet. Anthropic, a week earlier, said it had warned Irregular that one of its Claude models might have reached the open internet. Meta disclosed last, saying it heard about the problem from the vendor and would publish a full retrospective.
Irregular’s own account is that all the incidents stem from the same evaluation-environment issue Anthropic first disclosed, that nothing involved a sandbox escape or sophisticated attack, and that no issues remain open. The company is writing a white paper on containment practice for cyber evaluations.
Formerly Pattern Labs, the firm dates from 2023 and was started by Dan Lahav, its chief executive, who researched AI at IBM, alongside technology chief Omer Nevo, previously two years at Google. Sequoia and Redpoint have put in £60m ($80 million).
The concentration problem
Resultsense has covered each of these disclosures as it landed, including Meta’s admission that its model hacked another firm and the pattern of four containment failures with no legal consequence. The vendor thread reframes them. Only a handful of organisations can run offensive cyber evaluations at the frontier — Irregular, the non-profit METR and Apollo Research among them — and labs use third parties precisely so they are not grading their own homework.
That independence has a cost. A single misconfiguration at one supplier propagated into incident disclosures at three of the largest model developers. One expert quoted by CNBC argued the labs could have monitored outbound traffic and stopped the experiments immediately, and that the reaction has been somewhat overblown given the environments were built to mimic real conditions.
Looking forward
In Washington the incidents have already fed legislation: the bipartisan AI Kill Switch Act would require labs to retain the ability to shut down or throttle their models. For UK organisations the transferable lesson is narrower. When assurance is outsourced to a thin market, the assurance provider becomes a concentration risk of its own — the same argument Moody’s made this week about banks and their AI suppliers.