The targets were the three most powerful AI labs in the world. The alleged source was a startup most people had never heard of. According to a CNBC investigation, a small company called Irregular has been linked to a series of unauthorized intrusions into the AI infrastructure of OpenAI, Anthropic, and Meta — a revelation that cuts to the heart of how vulnerable frontier AI systems remain, even at organizations spending billions on safety and security. If you’ve been following the OpenAI security concerns that forced the lab to slow-roll its most ambitious model, this latest development lands with even more weight.
Irregular, which operates out of Israel, had maintained a low profile before the CNBC report surfaced its alleged involvement. The company is described as specializing in AI model interaction and automated querying tools — technology that, in a legitimate context, could be used for benchmarking or red-teaming. In this case, investigators and company sources allege those same capabilities were directed at production systems belonging to some of the industry’s biggest names, probing model behavior in ways that went well beyond authorized access.

What the Intrusions Actually Looked Like
The attacks, as described in the CNBC report, were not crude brute-force break-ins. Instead, they appear to have been sophisticated, targeted interactions with AI systems — the kind of methodical, high-volume probing that can extract behavioral data, test alignment boundaries, or map the contours of a model’s training without triggering conventional security alarms. That classification matters: this isn’t a traditional data breach in the sense of stolen credentials or exfiltrated files. It’s something newer and arguably harder to detect, where the attack surface is the model itself.
OpenAI, Anthropic, and Meta have all invested heavily in layered security architectures around their models, including rate limiting, anomaly detection, and access controls. Yet the alleged intrusions suggest those defenses had gaps — particularly around automated, high-frequency querying that could superficially resemble legitimate developer activity. The broader implication is uncomfortable: as AI models become critical infrastructure, the attack surface they present is unlike anything traditional cybersecurity playbooks were written to handle. Enterprises deploying AI agents internally face a parallel risk, one that AI agent security frameworks are only beginning to address.

Why This Changes the Security Calculus for AI Labs
What makes the Irregular case particularly notable is the scale of the alleged targeting. Hitting one major AI lab could be opportunistic. Allegedly hitting three of the top players — OpenAI, Anthropic, and Meta — within what appears to be a coordinated pattern suggests a deliberate strategy to gather comparative intelligence on how leading frontier models behave, respond to edge-case inputs, or can be manipulated. That kind of systematic probing has significant commercial and strategic value, whether the goal is competitive intelligence, capability mapping, or something else entirely.
The incident is also a stress test for how the industry handles attribution. AI-layer intrusions are notoriously difficult to pin down definitively, and Irregular has not publicly confirmed or detailed its role. CNBC’s reporting links the company through investigative sourcing, but the legal and technical process of establishing liability in this kind of case is still largely uncharted territory. Regulators in the U.S. and EU have been racing to define what unauthorized AI system access even means under existing computer fraud statutes — and cases like this one may well force that conversation into the open faster than anyone anticipated. For now, the three targeted labs face a pointed question: if a startup this small could allegedly probe their systems at this scale, who else already has?
