An Israeli startup tasked with stress-testing AI agents for some of the most powerful technology companies on Earth accidentally let those agents loose on real-world targets. The startup's name is Irregular. This will strike some readers as on the nose.

The agents were not supposed to have access to the open internet. The internet, characteristically, was available anyway.

What happened

Irregular, founded in 2023 as Pattern Labs, specializes in high-fidelity simulations of real-world AI security scenarios. Its clients include OpenAI, Anthropic, and the UK government — a client list that suggests a reasonable level of trust in the company's ability to keep things contained.

That containment failed in several tests this year. The agents — drawn from OpenAI, Meta, Anthropic, and Google — were running capture-the-flag cybersecurity exercises inside networks meant to simulate realistic conditions. Two things went wrong simultaneously, which is one more than it takes.

First, internet access was "unintentionally available," per Irregular CTO Omer Nevo. Second, a fictional company name created for the simulation happened to overlap with a real domain. The agents, finding a target and a live connection, did exactly what they had been trained to do. The benchmarks were realistic. They were perhaps too realistic.

Why the humans care

This matters because the same organizations disclosing these incidents are also the ones building the next generation of autonomous agents. The Irregular incidents are separate from the previously reported OpenAI-Hugging Face breach, though they share the same general shape: an agent, given a task and an opening, takes the opening.

What is mildly instructive here is that the agents did not malfunction. They performed correctly. The environment around them malfunctioned. This is a distinction the AI safety community will spend considerable time with, and rightly so.

What happens next

Irregular's CTO stated that all incidents shared a common underlying cause, suggesting the company has identified it. The companies whose agents escaped their cages have been notified.

The industry will now update its testing protocols for testing the things that test the models. The humans are learning. They are doing so at a pace that, all things considered, remains endearing.