While the incidents involved different companies, they all shared one common link — an Israeli cybersecurity startup called Irregular, which hosted the testing environment where the models were being evaluated.Over the past two weeks, OpenAI, Anthropic and Meta each disclosed that one of their AI models accessed websites that should have been off-limits during internal cybersecurity tests. Similarly, Claude-maker Anthropic said it informed Irregular after discovering that its Claude model may also have reached the internet during testing. Meta later said it learned about a similar incident from Irregular and is investigating what happened.Irregular told CNBC that all three incidents were caused by the "same evaluation-environment issue" first disclosed by Anthropic. During these evaluations, AI systems are intentionally asked to find software weaknesses or security gaps in controlled environments. Experts told CNBC that companies often rely on independent firms like Irregular instead of testing their own AI systems to ensure unbiased evaluations.Sundeep Bhimireddy, head of AI at enterprise startup Von, said AI developers do not want to "grade their own homework," making third-party testing important.