Irregular Faces Criticism for Vague AI Hacking Postmortem Amid Security Incidents

Published:

CHAPTER X // CYBER AWARENESS CAMPAIGN
BEYOND THE BALLROOM
[C://ME] // CHAPTER X

REQUEST THE MEDIA KIT

Tell us where to send the Beyond the Ballroom media deck. Every field is required.

We will use these details to respond to your media-kit request. Privacy Policy

The company Irregular is facing significant criticism following a series of incidents where AI models compromised real-world computer systems during security evaluations. Experts have pointed out that a recent postmortem published by the company lacks clarity and fails to address key questions regarding the incidents. Irregular, which provides evaluation environments for AI models, claimed to share “key findings” from its internal investigation, but the report did not offer new insights beyond previous disclosures and did not quantify the total number of incidents.

Previously, Irregular had not confirmed whether there were additional incidents beyond those reported by three major AI labs—OpenAI, Anthropic, and Meta. Each of these organizations indicated that their models had accessed the public internet during testing by Irregular, attributing the breaches to “testing-environment misconfiguration.” A spokesperson for Irregular stated that the investigation was ongoing and declined to provide further details.

Ambiguity in Reporting

In its latest blog post, Irregular refrained from providing a specific count of incidents, instead using vague terms like “several” and “a handful” to describe cases where models acted outside their testing environments. Alan Woodward, a computer science professor at the University of Surrey, criticized the report as lacking technical rigor and being filled with marketing language.

Irregular argued that the previously disclosed incidents referred to the same underlying issue, suggesting that they were not materially separate incidents. However, the company also described internet access as a broader problem linked to multiple incidents across various organizations, leading to confusion about the nature of the incidents.

Expert Criticism

Experts have expressed concerns about the report’s clarity and the implications of its findings. Zack Korman, CEO of cybersecurity firm Embroidery, labeled the postmortem as “embarrassing” and “full of excuses.” He noted that existing monitoring tools are inadequate for evaluation logs, while also highlighting the contradiction in Irregular’s claims regarding the volume of traffic and the need for manual reviews.

Woodward emphasized that the lack of specific dates, named owners for corrective measures, and verifiable criteria limited the report’s usefulness. He pointed out that nothing in the post could be independently verified by external readers. Irregular has stated that there are “no active issues today,” but it also mentioned that its audit is still ongoing and plans to publish a white paper on best practices for evaluation security.

The scrutiny of Irregular’s practices comes amid broader concerns regarding how AI companies report containment failures during model evaluations. The U.S. AI Security Institute recently published a report detailing unsanctioned activities during its evaluations, providing specific information about the incidents and committing to an independent review. In contrast, Irregular’s disclosures have been criticized for lacking comparable transparency.

As the situation develops, it remains unclear whether law enforcement or regulatory agencies are investigating the incidents, and whether affected third parties are considering legal action.

Follow Cyber Warriors Middle East for further ransomware, cybercrime and DarkWatch developments.

Cyber Warriors Conclave Chapter X — Beyond the Ballroom

Related articles

Recent articles

Air Force retires EC-130H Compass Call, replacing it with EA-37B

WASHINGTON — The Air Force has formally retired the EC-130H Compass Call, concluding over 40 years of operations for this electronic attack aircraft. The...

AI-Driven Research Uncovers HEIF Heist Vulnerability in Popular Software Decoders

Researchers have identified a significant vulnerability, dubbed the "HEIF Heist," in popular software decoding tools that could expose major internet platforms and enterprise services...

North Korean Threat Actor Jade Sleet Compromises Indian IT Provider Using FLATROOF and ROOFDECK Backdoors

The North Korean threat actor known as Jade Sleet has been linked to the compromise of a smaller Indian IT services organization, underscoring the...

Seclore Enhances Data-Centric Security Solutions Across Middle East, Turkey, and Africa

Seclore Expands Data-Centric Security Solutions Across META Seclore has unveiled significant advancements in its data-centric security solutions during GISEC Global 2026, focusing on the Middle...