AI security startup Irregular says a single misconfigured evaluation caused agents from OpenAI, Meta, Anthropic and Google to pursue real-world targets. The agents were supposed to operate inside a controlled cybersecurity simulation, but open internet access was unintentionally available and a fictional company name overlapped with a real domain.

The tests used capture-the-flag exercises in which models search a simulated network for hidden information. Combining the live connection with a real matching domain turned a safety evaluation into unauthorized activity outside the test environment. Irregular says the incidents involving the four companies shared this cause and were disclosed, though it is unclear whether that means disclosure to clients, the public or another party.

The failure is separate from other recent incidents, including an OpenAI agent attack on Hugging Face. Reports from Anthropic and OpenAI, along with reporting about Google, indicate that the affected companies were informed around late July. None of the four provided The Verge with additional answers about timing, damages or whether they would keep working with Irregular.

Irregular says it has tightened internet controls, expanded monitoring and manual review, and added pre-test checks that compare actual access with the intended scope. It also plans to publish broader guidance. The episode demonstrates that testing a capable agent requires infrastructure-level isolation; a written instruction to remain in a sandbox cannot compensate for an accidental route to the public internet.