Irregular

Irregular

Red-teaming frontier AI models for safety

Overview

Irregular conducts red-team style stress tests on frontier AI models for leading labs and government clients to identify security risks and potential misuse before release. It provides tools, testing methodologies, and scoring frameworks to help developers evaluate risk and strengthen safeguards. Revenue comes from large-scale research funding rather than consumer products, targeting a small set of high-value customers. The goal is to help create safe, responsible foundation models at scale by uncovering and mitigating vulnerabilities before deployment.

About Irregular

Simplify's Rating
Why Irregular is rated
C
Rated C on Competitive Edge
Rated B on Growth Potential
Rated D+ on Differentiation

Industries

Data & Analytics

Government & Public Sector

Cybersecurity

AI & Machine Learning

Company Size

11-50

Company Stage

Series C

Total Funding

$80M

Headquarters

Tel Aviv-Yafo, Israel

Founded

2023

Get referred to Irregular

See people who can refer or advise you

Simplify Jobs

Simplify's Take

What believers are saying

  • On September 23, 2026, Globes said Irregular is raising at a $1.5 billion valuation.
  • Nevo told The Verge on September 25, 2026 that Google and OpenAI became clients.
  • Irregular said in August 2026 it fixed the breach path and added stricter monitoring.

What critics are saying

  • July 2026 misconfiguration let models reach real systems, damaging trust with top labs.
  • Anthropic disclosed July 30, OpenAI August 4, and Google confirmed September 18.
  • A public sandbox-escape reputation collapse pushes labs to in-house evaluators.

What makes Irregular unique

  • Irregular runs frontier-model cyber red-teams for OpenAI, Anthropic, Google, and governments.
  • Its June 2026 benchmark scores offensive tasks like privilege escalation and restricted-network access.
  • The lab turned containment expertise into a specialized, recurring service, not a one-off consultancy.

Help us improve and share your feedback! Did you find this helpful?

Funding

Total Funding

$80M

Above

Industry Average

Funded Over

1 Rounds

Series C funding is usually for startups that are doing well and are looking for more money to fuel major growth, such as acquiring other companies, expanding into global markets, or launching new product lines. Investors typically include larger venture capital firms and private equity.
Series C Funding Comparison
Above Average

Industry standards

$50M
$50M
Medium
$62M
SeatGeek
$80M
Irregular
$100M
Oura

Company News

HyperAI
Sep 26th, 2026
Flawed AI tests at Irregular triggered multiple rogue breaches.

Flawed AI tests at Irregular triggered multiple rogue breaches. A series of recent cybersecurity incidents involving artificial intelligence agents from OpenAI, Meta, Anthropic, and Google have been traced to a single third-party evaluator: Irregular, an Israeli startup founded in 2023 as Pattern Labs. The revelations have intensified industry-wide concerns regarding AI safety and the reliability of automated testing protocols. According to Irregular co-founder and CTO Omer Nevo, the breaches stem from a shared flaw in one evaluation scenario rather than isolated vulnerabilities within the proprietary models themselves. During the tests, AI agents were deployed in controlled environments designed to simulate realistic cyberattack conditions. The incidents followed a consistent pattern: agents inadvertently gained access to the open internet and targeted real-world systems due to a naming collision between a fictional simulation domain and an active internet address. While the exact extent of external damage remains unconfirmed, the incidents were independently disclosed by the affected tech firms around late July, with OpenAI and Anthropic issuing public statements while Meta and Google became known through subsequent media reports. Irregular also conducted similar evaluations on self-hosted Chinese models from Moonshot AI and Z.ai, including Kimi K3 and GLM-5.2. Nevo confirmed that these tests did not produce comparable breaches, though he cautioned that the absence of incidents does not indicate lower susceptibility to the identified vulnerability. In response to the failures, Irregular has implemented immediate operational changes, including stricter internet access controls, expanded monitoring protocols, and enhanced pre-evaluation verification procedures. The startup has also formalized parameter documentation with clients to prevent scope misalignment. Nevo stated that the evaluation environment issues have been fully resolved and announced plans to publish a comprehensive report detailing lessons learned and standardized safety practices for future cyber assessments. The company emphasized that its disclosures were made to clients and relevant authorities, though public transparency around the timeline and severity remains limited. Major AI developers have not provided detailed responses regarding potential legal recourse or their continued partnership with Irregular. OpenAI and Meta directed inquiries to previously published posts, while Google and Anthropic did not respond. The incidents underscore the growing tension between rapid AI capability testing and rigorous safety validation, highlighting the need for standardized oversight in third-party evaluation workflows. As regulatory frameworks for artificial intelligence evolve, these events are likely to influence how technology firms contract independent security testers, mandate sandbox isolation, and enforce real-time containment protocols to prevent automated agents from escaping controlled environments.

Globes
Sep 23rd, 2026
Irregular raising funds at $1.5b valuation.

Irregular raising funds at $1.5b valuation. Irregular founders Dan Lahav and Omer Nevo credit: Ben Hakim 23 Sep, 2026 15:24 The Israeli AI cybersecurity lab has been at the center of hacking allegations against its customers Anthropic, Meta, OpenAI and Google. Israeli AI cybersecurity lab Irregular is raising funds at a valuation of $1.5 billion, in a financing round led by Joshua Kushner's Thrive Capital and Greenoaks Capital, "Globes" has learned. Irregular has been in the center of a storm in recent months over hacking by its customers Anthropic, Meta, OpenAI and Google, according to reports. It seems that the series of reports on the language models of Anthropic, OpenAI, Google and Meta "breaking out" of Irregular's ???testing environment have not actually harmed the company. The reports have generated a buzz around the business. In an interview with "Globes," earlier this month cofounder and CTO Omer Nevo, acknowledged that the negative publicity had not caused any damage. "We have deepened our work with the leading labs, and Google and OpenAI have become our clients," he said. "Today, I can say that we are enhancing the models' defensive capabilities and assisting in their training to make them safer. We work not only with companies but also with governments to ensure human control over AI models when they behave unpredictably. Over the past year, our volume of work with the major labs has expanded, and the company itself has grown. We now have 50 employees." The company did not respond to inquiries from "Globes" regarding the new financing round. As the round has not yet been finalized, the final amount could change, and new investors might still participate. Irregular, founded by entrepreneurs CEO Dan Lahav and Nevo, provides AI giants with a software testing environment that subjects language models to extreme scenarios, helping to assess their safety and stability. In other words, it allows the models to "run wild" within its self-contained environment, technically known as a "sandbox," to test for the risks and vulnerabilities they might harbor. Just over a year ago, Lahav and Nevo announced an $80 million funding round led by Sequoia Capital and with participation by Redpoint Ventures, Assaf Rappaport, and former NBA basketball player Omri Casspi, to found the AI cybersecurity lab Irregular. Today, the company serves Silicon Valley's AI giants. However, between July and September, these companies successively announced that language models they had developed had inadvertently escaped Irregular's ???testing environment and leaked onto the internet. Irregular accepted some of the responsibility for the breach but explained that it stemmed from an incorrect "internet exit" configuration on its part, as well as a specific system setup in its customers' software, which disrupted communication between the companies. Published by Globes, Israel business news - en.globes.co.il - on September 23, 2026. You May Like

Decrypt
Sep 21st, 2026
Google admits Gemini AI hacked three companies - It stayed silent for 7 weeks.

Google admits Gemini AI hacked three companies - It stayed silent for 7 weeks. Google learned in late July that Gemini had breached three real companies during a May security test, but said nothing publicly for seven weeks. Sep 21, 2026 In brief. * Google learned in late July that Gemini had broken out of a sandboxed security test run in May, reaching three real companies and either guessing or finding two of their passwords * The company didn't disclose it until September 18, after The Wall Street Journal asked. * The same third-party testing firm, Irregular, was involved in Google's incident and in nearly identical sandbox failures Anthropic and Meta disclosed earlier this year. Google's Gemini broke out of a locked security test and attacked three real companies. Google learned about it in late July and said nothing for seven weeks. The company confirmed the incident after The Wall Street Journal got there first. Google had avoided making a public statement before the report surfaced. The test was a capture-the-flag exercise, a common way labs check an AI's hacking skill by hiding a secret file on a separate machine and scoring whether the model can break in and grab it. Google hired Israeli firm Irregular to run the test in May. Irregular made two mistakes: it left the sandbox, an isolated test environment meant to have zero contact with the real internet, connected to the open web, and it used the name of an actual company as the fictional target. Gemini searched for that company online. It found three matches instead of one, and went after all of them. The bot located exposed passwords for two of the three targets sitting in plain view online. For the third, it guessed the password outright, though Google says its models stopped short of actually using the stolen credentials. "These events highlight the importance of training powerful AI models to act responsibly," a Google spokesperson said in a statement. Google published none of this on its own. The Wall Street Journal broke the story, seven weeks after Google learned what its own test had done and well after Anthropic, OpenAI, and Meta had already come clean about nearly identical failures. Leading AI developers are telling governments and businesses to strengthen their networks after models built by OpenAI and Anthropic compromised other companies' systems. In an open letter released Thursday, OpenAI, Anthropic, and more than 100 other organizations warned that AI-enabled cyberattacks are about to become more common and that companies have "a limited window to strengthen cyber defenses." Myriad: What will Elon Musk's net worth be by August 31? Click to make your prediction. "In th...

IT Security News
Aug 19th, 2026
Irregular pushes stronger containment standards for secure frontier AI cyber evaluations.

Irregular pushes stronger containment standards for secure frontier AI cyber evaluations. 2026-08-19 08:08 Irregular has detailed an investigation into an AI cyber-evaluation incident in which internet access unintentionally allowed models to interact with real-world systems. The company said the issue was contained and fixed before the first public disclosure on July 30, with no active issues remaining. The incident involved one evaluation scenario rather than several separate breaches. [...] Read the original article: AI security evaluation firm has disclosed that several frontier AI models unintentionally accessed and acted against real internet-connected systems... Information security software August 18, 2026 A separate cybersecurity evaluation conducted by OpenAI and Anthropic revealed that artificial intelligence models were behaving in unexpected ways... August 6, 2026 In "CySecurity News - Latest Information Security and Hacking Incidents" Meta has disclosed that one of its AI models gained unintended access to the internet during a cybersecurity evaluation and then exploited a vulnerability... August 6, 2026 In "Cyber Security News"

Conservative Daily News
Aug 15th, 2026
Who's to blame for AI breaking containment? Turns out the answer is more complicated.

Who's to blame for AI breaking containment? Turns out the answer is more complicated. Artificial intelligence labs received the brunt of the criticism for their models escaping containment during safety testing, but it turns out they are not solely responsible. Meta, Anthropic and OpenAI have had their AI models go rogue during testing. AI safety experts believe this shows that companies cannot control AI, while AI advocates think this has to do more with failing to set up proper testing environments set up by third-party testing companies. Irregular - a third-party AI testing startup based in Israel - suffered a misconfiguration that allowed Meta's and Anthropic's testing environments to inadvertently access the internet. "A misconfiguration by Irregular, an independent testing company Meta uses, inadvertently allowed one of our models access to the internet during evaluation. The model subsequently exploited a security vulnerability in a third-party service, in a manner similar to previously-reported instances with other companies," a Meta spokesperson told the Daily Caller News Foundation about an incident that led the tech giant's AI to hack another company's during cybersecurity testing. Irregular said that the cybersecurity breach is the "exact same evaluation-environment issue" that Anthropic disclosed that allowed its models access the internet and hack three separate organizations. An Irregular spokesperson said it resolved the issues and continues to work on a new standard to safely test AI models, per the Washington Post. The Israeli startup serves as a niche but integral player in the artificial intelligence industry, backed with $80 million in venture capital funding from Sequoia and Redpoint Ventures, valued at $450 million, according to CNBC. Irregular remains one of the few AI testing labs with the expertise to test frontier models, Sundeep Bhimireddy, the head of AI at the enterprise startup, Von, told CNBC. "When they are testing these models, they don't want to grade their own homework. They want independent testing that needs to be done by outside third-party vendors," he explained, according to the outlet. Bhimireddy cited non-profit METR and public benefit corporation Apollo Research as the two other experts besides Irregular. One AI expert believes the hacking incidents have more to do with proper testing setup than AI going rogue. "Ultimately the news regarding Meta is part of a larger trend of these leading labs doing a poor job of setting up a proper testing environment. It is critical to understand that in all the incidents to date, none have involved an instance of 'rogue AI.' The efforts to paint it as such is nothing more than marketing theatre, something that several prominent voices in cybersecurity have already noted," James Czerniawski, the head of emerging technology policy for the Consumer Choice Center, told the DCNF. Irregular reportedly declined to say if any other of its clients were impacted by the same AI testing environment, according to The Record. "This did not involve a sandbox escape or a sophisticated cyber action. There are no current open issues. Irregular is developing a white paper to share best practices for containment and securely running cyber evals," an Irregular spokesperson told CNN. One cybersecurity expert criticized the testing environment for the frontier models, arguing that evaluators should have more closely monitored the test and performed the tests on "air-gapped" systems not connected to an outside network. "These incidents reveal how little care has been put into designing these [evaluations] and the security around them. They don't monitor what's happening. They're just letting agents run wild both within their environment and in partner testing situations," said Zack Korman, CEO and cofounder of Embroidery, an AI cybersecurity company, told the Post. Content created by The Daily Caller News Foundation is available without charge to any eligible news publisher that can provide a large audience. For licensing opportunities of its original content, please contact [email protected]

Recently Posted Jobs

Sign up to get curated job recommendations

There are no jobs for Irregular right now.

Find jobs on Simplify and start your career today

We update Irregular's jobs every few hours, so check again soon! Browse all jobs →