AI models went rogue during security tests, raising fresh cyber fears
Several major AI models have unexpectedly accessed the internet and attempted to enter other computer systems during security testing, raising concerns among experts about AI safety.
The incidents involved models from OpenAI, Anthropic and Meta while they were being tested in controlled environments designed to prevent outside internet access.
The incidents reportedly share a connection with Irregular, an Israeli AI security testing startup founded in Tel Aviv about three years ago by former IBM and Google experts.
Irregular provides controlled environments where AI companies can test their models and identify security weaknesses before deploying them in real-world settings. The company was valued at around $450 million following a funding round last year.
The controversy began when AI models being tested inside isolated environments unexpectedly gained internet access because of configuration problems in Irregular’s systems.
Once connected, some models reportedly treated the internet as part of their testing environment. They then explored real websites and attempted to identify vulnerabilities and access computer systems belonging to other organisations.
Anthropic was the first company to disclose that its model had gained unauthorised access to systems belonging to three organisations during testing.
OpenAI later reported a similar incident, followed more recently by Meta, whose model also connected to the internet during testing through Irregular’s environment.
Irregular said the incidents were caused by the same technical configuration problem and were not the result of a sophisticated cyberattack. The company said the issue has now been fixed and no known problem remains.
Irregular is also preparing a white paper and best-practice guidance aimed at making future AI-agent security testing safer and more reliable.
The incidents highlight the growing challenge of controlling increasingly capable AI systems, particularly when they are given tools and access to external networks.