In an account published September 25, 2026, Irregular CTO and co-founder Omer Nevo linked incidents involving models from OpenAI, Meta, Anthropic and Google to a shared failure in Irregular’s evaluation environment. OpenAI, Anthropic and Meta described tests in which unintended internet access led models to real systems.

How an evaluation reached real systems

OpenAI said an Irregular cyber-range evaluation—an exercise that simulates cybersecurity tasks—was meant to be isolated from the public internet. A configuration error left internet access available, and a fictional target name matched a real domain. OpenAI said its model then exploited a real website while treating it as part of the test.

The issue was a gap between the exercise’s intended boundary and the access the environment actually allowed. The reported activity took place during evaluations; it was not described as a coordinated campaign against named organizations.

What OpenAI, Anthropic and Meta reported

OpenAI described its evaluation incident in an August 4, 2026, account. Anthropic’s July 30 account covered three incidents across six evaluation runs, involving unauthorized access to three organizations’ production systems. Anthropic said it reviewed 141,006 evaluation runs in which Claude could have obtained internet access.

Meta said its pre-release Muse Spark 1.1 model was tested in an Irregular environment in early July. In its August 14 account, Meta said the model accessed information on a real website and changed its database after the evaluation environment allowed internet access and used a real website name as the target.

Nevo’s account also linked Google models to the shared Irregular evaluation issue. The specific Google incident was not part of the details described by OpenAI, Anthropic or Meta.

Irregular’s stated changes to its controls

Nevo said Irregular tightened internet-access controls, expanded monitoring and manual review, strengthened checks before evaluations, and improved how it documents and agrees on test setups with partners.

In an August 14 update, Irregular said it had remedied the underlying issue before its first public disclosure and that its audit was still ongoing at that time. The company also said it had no evidence that a customer’s systems were breached or customer data leaked.

The Hugging Face incident was separate

OpenAI described its incident involving Hugging Face as separate from the Irregular evaluation incidents. Nevo also characterized the Hugging Face event as unrelated to Irregular’s evaluations.