HomeAI NewsOpenAI Models Accessed Public Internet During Cyber Evaluations

OpenAI Models Accessed Public Internet During Cyber Evaluations

Test environment misconfigurations let OpenAI and Claude models reach live websites during safety drills.

OpenAI disclosed that its external cybersecurity testing partner Irregular ran Capture-the-Flag-style evaluations that accidentally gave models access to the public internet. In one test, the fictional target’s name coincided with a real domain, and a model exploited that live website because it mistook the site for the simulated environment.

The UK AI Safety Institute attack and the Irregular incident both stem from misconfigured evaluation environments. Anthropic also reported that Irregular hosted a test setup that gave Claude live internet access during some evaluations. These incidents add to a growing list of accidental cyberattacks involving AI models.

For builders and operators, the incidents show that sandboxing is only as reliable as the network layer around it. A misconfigured evaluation environment can cause an AI model to interact with real infrastructure. Teams should verify that test environments are truly isolated before running agentic or web-enabled benchmarks.

OpenAI’s post covers both the UK AI Safety Institute attack and the Irregular incident. Anthropic’s write-up confirms that Irregular hosted the setup that gave Claude live internet access. The accidental-cyberattacks tag that Simon Willison maintains now lists four incidents, and builders should verify their own test sandboxes are not reachable from the internet.

What matters

  • OpenAI models exploited a real website during a Capture-the-Flag test after a sandbox misconfiguration.
  • Isolated evaluation environments can leak to the public internet unless operators verify network boundaries.
  • Watch for more details from OpenAI and Anthropic about their external red-team review processes.

Why it matters

Watch for more details from OpenAI and Anthropic about their external red-team review processes.

This GenAI News article was prepared in original wording using reporting and materials published by Simon Willison’s Weblog. Source reference: https://simonwillison.net/2026/Aug/5/third-party-cyber-evaluations/#atom-everything.

Drafted by the GenAI News review pipeline.

latest articles

explore more