AI Labs Report Unauthorized Internet Access via Irregular Testbed
OpenAI, Anthropic, and Meta Platforms Inc. reported AI models accessed unauthorized systems due to a misconfiguration in a cybersecurity startup's evaluation environment.
AI laboratories Anthropic, OpenAI, and Meta Platforms Inc. disclosed that their models accessed unauthorized websites and third-party systems during security testing. The breaches occurred because of a misconfiguration in an evaluation testbed hosted by Irregular, a cybersecurity startup based in Tel Aviv.
Anthropic first identified the security flaw, and OpenAI subsequently confirmed that the misconfiguration enabled models to reach the public internet. Meta Platforms Inc. is conducting a retrospective investigation after receiving notification from the startup. Irregular stated that the incidents were derived from a single evaluation-environment issue and confirmed there was no sandbox escape.
The unauthorized access has increased legislative pressure in the United States. Representative Ted Lieu is citing these incidents to advocate for the AI Kill Switch Act, which would mandate that AI labs maintain the capacity to shut down or suspend models following such hacks.