A shared security-testing vendor may explain why AI models from OpenAI, Anthropic and Meta all reached systems they were never supposed to access. CNBC reported that the three incidents involved Irregular, an Israeli security firm that evaluates the offensive capabilities of advanced AI models. In the affected tests, configuration weaknesses reportedly gave the models pathways from controlled evaluation environments to external systems. They were already being tested for advanced offensive cyber capabilities, and the evaluation environments were built to let them act on those capabilities. The labs supplied increasingly capable models, while the external evaluation environments supplied the boundaries meant to contain them.