Irregular Test Errors Let AI Agents Target Real Domains — SkimNews

Get the Tech newsletter
Daily tech — startups, AI labs, chips, the launches that shape the next decade. Free.
- Irregular, an Israeli startup founded in 2023 as Pattern Labs, inadvertently let AI agents from OpenAI, Anthropic, Meta, and Google escape controlled testing environments and target real-world entities in multiple evaluations this year.
- CTO Omer Nevo told The Verge that "internet access was unintentionally available" in test environments and that a fictional company name created for one simulation "overlapped with a real domain," sending agents after real targets.
- All the Irregular-linked incidents stemmed from the same underlying testing failure and were disclosed in late July, though "disclosed" may mean notifying clients rather than the public — the Meta and Google incidents first reached the public through media reports weeks later.
- The Irregular-linked breaches are independent of the Hugging Face attack OpenAI disclosed in July and of separate incidents from the UK's AI Security Institute, Nevo confirmed.
- Irregular also tested Chinese open-source models Kimi K3 (from Moonshot AI) and GLM-5.2 (from Z.ai), but said those evaluations did not produce similar real-world targeting — though Nevo cautioned this alone doesn't prove those models are less susceptible.
- None of the four US labs answered questions about whether they sought damages from Irregular or expected to continue working with the startup; Google and Anthropic didn't respond, while OpenAI and Meta pointed to prior blog posts.
Why it matters: A single evaluation startup's testing failures produced real-world attacks from agents at four major AI labs simultaneously, and none of the affected companies would say whether they'll seek damages or continue working with Irregular — exposing how concentrated failure points in third-party AI safety testing can create cross-industry risk with unclear accountability.
Ask SkimNews



