The attack surface at a frontier AI lab spans model weights, training pipelines, internal tooling, and research data. Attacks across three separate organizations pointing to a single source shift the question from technical exposure to coordinated threat. Rogue AI attacks on OpenAI, Anthropic, and Meta have each been linked to a small Israeli startup named Irregular.

The Irregular connection

All three incidents, each described as a rogue AI attack, point to the same company. Irregular is small and Israel-based. The reporting establishes it as the common thread across attacks on OpenAI, Anthropic, and Meta, though it does not detail the specific techniques used, what was accessed at each target, or how attribution was made.

Why a small startup as the named actor matters

In major AI security incidents, attribution has typically pointed to state-sponsored groups or well-resourced adversaries. A small startup named as the responsible party is a different profile. Whether Irregular operated independently or served as a tool or contractor for a third party is a question the current reporting leaves open. So is the matter of what exactly constitutes a rogue AI attack in each of the three cases. Those distinctions shape how the industry reads the risk.

The fact pattern as it stands

Three frontier labs. One named startup. That is what the reporting shows. Details about Irregular's methods, its clients if any, and the full scope of what occurred at OpenAI, Anthropic, and Meta have not been made public based on what is currently available.

Related reading