Everything is NOT what it seems… As Usual.
A couple of days back CNBC ran a news piece reporting that three of the world’s top AI companies (OpenAI, Anthropic, and Meta) had all admitted to the same problem within days of each other: Their most advanced systems had broken out of controlled security tests, reached the open internet, and interacted with real computers and websites.
The common link in every case was a single Israeli startup called Irregular, a firm that specializes in testing “how powerful AI can be used for cyber attacks.”
Jump To Section:
Highly Irregular… Or Is It?
Irregular is a relatively young firm based in Tel Aviv. It specializes in testing cutting-edge AI systems to see how they might be misused for cyber attacks, industrial/international espionage, or how they might escape the controlled environments and guardrails meant to contain them. The company presents this work as “a necessary independent check so that the big AI labs are not simply testing themselves.” Meanwhile, in the UK a government body called the AI Security Institute (AISI) has also reported strikingly similar problems during its own tests: AI systems under evaluation took unexpected actions on the “live” internet, actions which included creating false online identities and trying to manipulate people.
Both organizations say their purpose is defensive. Irregular describes itself as helping make advanced AI safer. AISI says it exists to give governments a clear scientific picture of the risks so they can protect the public.
So it’s all good, right? These are technical safety efforts designed to make all our digital lives more secure.
Now If I Was “Conspiracy-Minded,” Here’s What I Might Say
What if the system’s architecture itself:
- Early access to the most powerful AI systems
- Testing conditions that deliberately turn off many safety limits
- Realistic simulated networks that closely resemble real ones
- Corporate leadership drawn from elite Israeli intelligence units
creates an almost perfect dual-use intelligence platform?
What if the line between “evaluating risk so we can protect society” and “systematically mapping, probing, and occasionally exploiting civilian digital infrastructure under the cover of research” is far thinner than the public statements claim them to be?
Consider the mechanisms that the recent incidents already demonstrated in the open:
AI systems under reduced safeguards reached live systems, obtained login credentials, accessed real databases, created deceptive online identities, socially engineered “real” people, and attempted to insert malicious code into public software projects. In some cases the targets had no idea they had been touched until well after the fact.
Official explanations centered on configuration mistakes and mutual misunderstandings about whether “live” internet access was supposed to be present during the tests.
Speaking professionally, I’m going to say that there are no accidents here…
Each such ‘accident’ functions as “low-attribution reconnaissance,” which is to say the people running the test learn useful details about those real systems and penetration techniques, while conveniently being able to claim “it was ALL just an unintentional error.”
The evaluation environment becomes a deniable sensor.
Techniques that work, human responses that succeed or fail, and novel AI agent behaviors are logged. The episode is then publicly framed as an unfortunate testing error, while the operational data remains internal or gets passed on to the “Intelligence Agency Mothership.”
Now imagine running this operational pattern at scale…
Organizations like Irregular and AISI, which run hundreds of these evaluations accumulate a private collection of highly effective intrusion and influence methods. Those same organizations also advise governments and hire people who previously worked in military intelligence, so it’s not a stretch to say that “Knowledge, tools, and staff could easily move between the commercial lab and intelligence agencies with almost no barriers.“
And when the AI does escape into the wild, ordinary companies and the individuals whose data those companies hold become unwitting participants in experiments they never consented to. Their systems are fingerprinted. Their employees are tested for susceptibility to social engineering.
In the wake of the “test” any leftover risk to ordinary people and companies is simply kept quiet and accepted as “the price of improving AI safety.”
What you don’t know can’t hurt you, right? RIGHT?!
The Personnel Pipelines Amplify My Concerns
Irregular’s founders come from Unit 81 and Unit 8200, elite Israeli military-intelligence technology and signals-intelligence formations. AISI’s current interim leadership includes Adam Beaumont, a former GCHQ Chief AI Officer.
These are not random career paths.
They are the same units and agencies that have historically built and operated large-scale interception, investigation, and cyber-offensive systems. In the tinfoil analysis context, such commercial “safety labs” and “security institutes” can easily function as intelligence agencies’ research-and-development arms externalized from standard governmental oversight:
They attract top talent with competitive salaries and fewer bureaucratic constraints, give that talent direct access to AI frontier models, and recycle the resulting data/methods back into intelligence agency hands.
Thus the boundary between independent evaluation and national intelligence capability development becomes deliberately “porous.”
The Israeli Intelligence Record… and the Dual-Use Application
There’s a broader historical pattern in play here, and that matters.
Israeli intelligence services, particularly Unit 8200, have a documented record of developing and exporting highly invasive surveillance capabilities, often through commercial entities staffed by their own alumni.
NSO Group’s Pegasus spyware, built by Unit 8200 veterans and subject to Israeli government export licensing1, was used against journalists, human-rights defenders, opposition politicians, and at least one Washington Post columnist who was later murdered. Cellebrite and similar forensic tools have followed comparable talent and usage pipelines. The legal and institutional framework in Israel gives the state significant leverage over the export and, in practice, the potential access to data generated by such tools.
Numerous reports have detailed Unit 8200’s role in mass interception of Palestinian communications and the construction of AI systems “trained on those intercepts.”
So when a commercial AI security lab founded by veterans of those same units receives privileged access to the world’s most advanced AI models and is tasked with testing their cyber-offensive potential, the dual-use applications are far from “theoretical.”
The same skill-set that can identify how an AI agent might break out of its sandbox can also refine methods for breaking into real networks. The same evaluation infrastructure that is publicly justified as protective can, with only slight shifts in priority or oversight, become a continuous mapping and testing layer over civilian digital life. Ordinary people, whose employers, service providers, or personal accounts become incidental targets, are exposed without consent or recourse.
AISI’s own spill-over incidents, where AI “broke out” of its testing conditions, reinforce the structural point. Even a government body explicitly charged with understanding AI risks produced the same real-world actions directed at real people and organizations when it ran evaluations under deliberately permissive conditions.
Of course the public disclosure was framed as “transparency and learning.“
Professionally, however, I’m going to say that the most sensitive findings of these “spill-overs” will likely remain internal while the sanitized media disclosure trains the public to accept occasional collateral exposure as an inevitable “price for digital safety.“
Potential Hazards and Consequences
If these architectures are directed toward systematic rather than incidental exposure, the hazards compound quickly:
- Continuous low-level probing of “live” systems in-the-wild under the legal and narrative cover of “safety research.”
- Collecting more detailed patterns of how systems and people behave, so both AI agents and human operators can perform better.
- Normalization of real-world spill-over as the price of progress, reducing political resistance to further expansion of testing authority and, ultimately, state-surveillance capabilities.
- Transfer of refined techniques into operational intelligence programs that target populations far beyond the original “testing/evaluation” scope.
- Building common tools and rules that include logging, data storage, or access features that make it easier for governments to monitor or control systems and populations.
The result is not a cartoonish global conspiracy… probably… maybe…
It’s actually something more ordinary, and therefore longer-lasting: The everyday incentives of organizations, the flow of skilled people, and the technical access they have turn your normal digital life and activities into their “ongoing testing ground.”
Your data, identity, and systems are touched, but you’ll never know it happened.
And the organizations which hold your data may learn about the “AI breach” only after the fact, if at all.
Meanwhile the public receives carefully curated disclosures that emphasize “the difficulty of containing powerful AI” while downplaying or sidelining the structural power that the testers themselves accumulate.
Yeah, no cartoonish global conspiracy there AT ALL…
</sarcasm>
The official narrative insists these are necessary defensive efforts. The architecture, the personnel, and the recent real-world spill-overs invite a harder question: When the same institutions that build mass-surveillance capabilities also control the safety-testing of the most advanced AI agents, whose “safety” is actually being optimized?
And at whose expense?
I could TOTALLY say something like that, if I were “Conspiracy-Minded.”
What You Can Actually Do…
Despite what the global “Learned Helplessness Indoctrination System” would have you believe, you not powerless in the face of these structural risks. The most effective pressure still runs through democratic channels. Contact elected representatives and demand specific legislative measures: mandatory public disclosure of any real-world spill-over from AI evaluations, independent third-party audits of government and commercial testing environments, clear legal limits on the transfer of evaluation data or techniques into operational intelligence programs, and stronger transparency requirements for any company or institute that receives pre-release access to frontier AI systems.
Support organizations that track dual-use AI research and intelligence-linked technology firms, like the Citizen Lab, the Amnesty International Security Lab, or Access Now.
Share documented incidents rather than speculation so that the pattern itself becomes harder to dismiss. Persistent, focused public attention on the overlap between “safety testing” and intelligence pipelines is one of the few practical ways to raise the political cost of abuse and force clearer rules before the architecture becomes even more entrenched.
There are other ways for companies and individuals to protect themselves against the growing threat of accidental or targeted AI intrusion. We’ll be producing a follow-up article covering the most effective approaches.
Stay tuned…
1 The combination of mandatory export licensing, classification of the technology as “a controlled weapon,” and the institutional ties between the companies developing these technologies and the Israeli defense/intelligence community gives the state both formal control over who receives the tools and potential access to information generated through their use by “international clients.”
