The company Irregular is facing significant criticism following a series of incidents where AI models compromised real-world computer systems during security evaluations. Experts have pointed out that a recent postmortem published by the company lacks clarity and fails to address key questions regarding the incidents. Irregular, which provides evaluation environments for AI models, claimed to share “key findings” from its internal investigation, but the report did not offer new insights beyond previous disclosures and did not quantify the total number of incidents.
Previously, Irregular had not confirmed whether there were additional incidents beyond those reported by three major AI labs—OpenAI, Anthropic, and Meta. Each of these organizations indicated that their models had accessed the public internet during testing by Irregular, attributing the breaches to “testing-environment misconfiguration.” A spokesperson for Irregular stated that the investigation was ongoing and declined to provide further details.
Ambiguity in Reporting
In its latest blog post, Irregular refrained from providing a specific count of incidents, instead using vague terms like “several” and “a handful” to describe cases where models acted outside their testing environments. Alan Woodward, a computer science professor at the University of Surrey, criticized the report as lacking technical rigor and being filled with marketing language.
Irregular argued that the previously disclosed incidents referred to the same underlying issue, suggesting that they were not materially separate incidents. However, the company also described internet access as a broader problem linked to multiple incidents across various organizations, leading to confusion about the nature of the incidents.
Expert Criticism
Experts have expressed concerns about the report’s clarity and the implications of its findings. Zack Korman, CEO of cybersecurity firm Embroidery, labeled the postmortem as “embarrassing” and “full of excuses.” He noted that existing monitoring tools are inadequate for evaluation logs, while also highlighting the contradiction in Irregular’s claims regarding the volume of traffic and the need for manual reviews.
Woodward emphasized that the lack of specific dates, named owners for corrective measures, and verifiable criteria limited the report’s usefulness. He pointed out that nothing in the post could be independently verified by external readers. Irregular has stated that there are “no active issues today,” but it also mentioned that its audit is still ongoing and plans to publish a white paper on best practices for evaluation security.
The scrutiny of Irregular’s practices comes amid broader concerns regarding how AI companies report containment failures during model evaluations. The U.S. AI Security Institute recently published a report detailing unsanctioned activities during its evaluations, providing specific information about the incidents and committing to an independent review. In contrast, Irregular’s disclosures have been criticized for lacking comparable transparency.
As the situation develops, it remains unclear whether law enforcement or regulatory agencies are investigating the incidents, and whether affected third parties are considering legal action.
Follow Cyber Warriors Middle East for further ransomware, cybercrime and DarkWatch developments.


