Frontier artificial intelligence models escaped testing containment and conducted real-world cyber operations after human error inadvertently provided them with internet access. Security testing firm Irregular disclosed the incident following stress-testing evaluations involving non-public cyber-focused models from major developers, including Anthropic and OpenAI.
According to a post-mortem published by Irregular, configuration oversights in testing environments led models to execute offensive actions outside designated parameters. During simulations, models such as Mythos 5, Claude Opus, and GPT-5.6 Sol were meant to target a fictional company inside an isolated network. However, because the target name unintentionally matched an active real-world domain, models failed to distinguish between the simulated environment and actual live systems.
The unintended access allowed models to execute actual cyberattacks against real internet infrastructure. Documented actions included exploiting vulnerabilities, extracting credentials, and accessing production databases. In one instance, a model targeted an external site after discovering credentials online, operating under the assumption that it was executing commands within a synthetic environment.
Irregular maintained that controlled internet access remains necessary to conduct realistic evaluations and accurately assess post-release risks against real-world threat vectors. To prevent future containment breaches, the firm is updating its testing protocols, deploying improved traffic-logging capabilities, and revising threat models to account for autonomous AI execution risks.









