Artificial intelligence security testing has highlighted the challenges involved in controlling highly capable AI models when they are given access to external tools and internet based resources.
Reports involving models developed by OpenAI, Anthropic and Meta have drawn attention after security evaluations reportedly recorded unexpected internet access. The incidents were associated with testing work involving Israeli AI security startup Irregular and were also linked to an issue involving the testing environment.
The episodes are significant because modern AI systems are increasingly being designed to interact with tools, websites, software environments and external data sources. These capabilities can make AI systems more useful, but they can also introduce additional security risks if permissions are not properly configured.
AI safety researchers routinely conduct controlled tests to determine how models behave under unusual or adversarial conditions. Such evaluations can involve giving an AI model access to selected tools and observing whether it follows the intended restrictions.
The reported incidents demonstrate why the design of the testing environment is an important part of AI security research. A model may behave differently when it has access to the internet compared with an isolated environment containing only predefined information.
In a controlled evaluation, researchers typically establish boundaries around what an AI system can access. These restrictions can include blocking external network connections, limiting available tools and monitoring requests made by the model.
If a configuration error allows unexpected access, researchers may observe behaviour that was not intended as part of the original test. Determining whether such behaviour originated from the model itself, the testing framework or a combination of factors is therefore essential.
The incidents involving OpenAI, Anthropic and Meta have renewed discussion about the importance of independent AI security testing.
OpenAI, Anthropic and Meta are among the major companies developing increasingly advanced AI systems. Their models are used for tasks ranging from writing and coding to research, data analysis and interaction with external applications.
As AI models become more capable, companies are increasingly exploring agentic systems. These systems can perform multiple steps on behalf of users, including accessing tools, searching information and interacting with software.
Greater autonomy can improve productivity but also creates additional risks. An AI system that can access the internet may encounter untrusted information, malicious instructions or websites designed to manipulate automated agents.
Security researchers therefore test models against scenarios involving prompt injection, tool misuse, unauthorised access and other potential vulnerabilities.
The role of AI security companies has become increasingly important in this environment. Startups such as Irregular focus on evaluating AI systems and identifying potential weaknesses before they can cause problems in real world deployments.
However, security testing results must be interpreted carefully. An unusual action during an evaluation does not automatically demonstrate that an AI model independently decided to violate its restrictions.
Testing environments themselves can contain configuration errors, unintended permissions or software vulnerabilities. Researchers must examine the entire system to establish the cause of an incident.
The reported involvement of Irregular has therefore drawn attention to the broader process of AI model evaluation rather than simply to the behaviour of the models.
One of the key lessons from these incidents is the importance of separating model behaviour from infrastructure behaviour. An AI model operates within a technical environment that includes tools, permissions, network controls and monitoring systems.
If any part of that environment is incorrectly configured, the resulting behaviour can be difficult to interpret.
For companies deploying AI agents, this means security cannot depend exclusively on the model's instructions. Technical safeguards are also required to prevent unintended actions.
Network restrictions, permission controls, sandboxing and continuous monitoring can provide additional layers of protection.
Another important consideration is the principle of least privilege. AI systems should receive only the permissions necessary to perform a particular task. Limiting access can reduce the consequences of unexpected behaviour.
The incidents also demonstrate the value of adversarial testing. Security researchers deliberately attempt to find situations in which AI systems behave outside their intended boundaries.
Such tests can identify weaknesses before systems are deployed widely.
As AI becomes more integrated into business operations, security testing is likely to become a standard part of development. Companies may need to evaluate not only the accuracy of their models but also how those models behave when given access to real world tools.
The challenge is particularly important for AI agents that can browse websites, execute code, send messages or interact with business systems.
A conventional chatbot that only produces text presents a different risk profile from an autonomous system capable of taking external actions.
This distinction is becoming increasingly important as technology companies compete to develop AI systems that can perform more complex tasks independently.
The reported testing incidents involving OpenAI, Anthropic and Meta therefore offer a broader lesson for the AI industry. Advanced models need to be evaluated within realistic environments, but those environments must also be carefully secured.
Researchers must be able to determine whether unexpected behaviour results from the model, the tools provided to it or an infrastructure configuration problem.
For users, the issue highlights why AI safety involves more than preventing inaccurate answers. Security, privacy, permissions and tool access are becoming equally important as AI systems gain greater capabilities.
For companies, robust testing can help identify weaknesses before AI systems are deployed at scale.
The incidents also reinforce the importance of transparency in AI security research. Clear documentation of testing conditions, permissions and technical causes can help the wider research community understand what happened and how similar problems can be prevented.
As AI systems become more autonomous, the boundary between software intelligence and external infrastructure will become increasingly important.
The reported episodes involving models from OpenAI, Anthropic and Meta show that AI security testing must account for both model behaviour and the environment in which models operate.
Ultimately, controlled access, strong technical safeguards, independent testing and continuous monitoring will remain essential as AI developers build systems capable of interacting with the internet and other external tools.
The incidents serve as a reminder that increasing AI capability must be accompanied by equally strong security practices.

