The Israeli startup that made CNBC headlines

Argular, which helps OpenAI, Anthropic, and Google test the safety of their models, has been linked to three cases where artificial intelligence systems managed to access the internet during cyber experiments. The company claims that they originated from a single glitch in the testing environment that has already been addressed.

GlobesAuthor: Meital Weisberg
Source
The Israeli startup that made CNBC headlines
Photo: Globes / דן להב (מימין) ועומר נבו, מייסדי Irregular / צילום: בן חכים

The Israeli startup Argular has found itself in recent days at the center of a global discussion about the dangers of artificial intelligence (AI) models. An article published today on CNBC linked the company to three cases reported by OpenAI, Anthropic, and Meta. In each instance, an AI model managed to access the internet during a cyber test, even though the experiment was supposed to take place in a closed environment.

Argular specializes in testing advanced models before their launch. It allows developers to check if their systems are capable of identifying security vulnerabilities, bypassing defenses, or performing actions that could be used by attackers. To prevent damage to real systems, tests are conducted in an environment supposed to be isolated from the internet.

However, in the recent cases, it turned out that the separation was not complete. According to Argular, the three incidents stemmed from the same problem in the testing environment, first discovered by Anthropic. The company emphasized that the models did not break out of an isolation system and that this was not a sophisticated cyberattack. The glitch has been addressed, and there are currently no open issues.

Models found a gateway to the internet

OpenAI stated in early August that a misconfiguration in the experimental environment allowed its models to access the public internet. Anthropic reported earlier that during a data check, a suspicion arose that its Claude model had connected to the internet, and subsequently updated Argular. Meta was the last to reveal a similar case, stating it learned about the incident from Argular and is still investigating. They intend to publish a full review after completing their fact-gathering.

These events do not necessarily indicate that the models decided on their own to attack systems. They were tasked with looking for security vulnerabilities and tried to complete it, but found an option that was not supposed to be available to them. However, these cases illustrate how difficult it is to predict in advance how advanced models will act when they receive a relatively broad task.

Experts quoted on CNBC argued that the affair was interpreted too dramatically. Since the models were sent to look for vulnerabilities in an environment simulating the real world, it is not surprising that they managed to identify and exploit a misconfiguration. However, monitoring the activity could have identified the connection to the internet and allowed the experiment to be stopped in time. Argular stated it intends to publish a document summarizing the findings and presenting recommendations for safely conducting cyber tests. OpenAI and Anthropic announced they continue to work with the company and support the ongoing investigation.

Partner of the AI giants

Argular was founded in 2023 under the name Pattern Labs by CEO Dan Lahav and CTO Omer Nevo. Both hold master's degrees in computer science. Lahav previously worked in AI research at IBM, and Nevo worked in Google's research department. The company defines itself as a cyber lab. Its employees access models still in development, try to understand how they can be used for harm, and identify vulnerabilities before the models reach the market. According to the company, its work has influenced the testing of models from OpenAI, including GPT-5, GPT-4, o3, and o4 mini, as well as Claude 4 from Anthropic. Its system has also reached DeepMind, Google's AI lab.

In September of last year, Argular announced an 80 million dollar funding round led by Sequoia and Redpoint. According to CNBC, the company was valued at 450 million dollars at the time. According to PitchBook, it employs about 35 people.

One of the threats Argular tries to prevent is the theft of capabilities from existing models. By presenting many questions to a model, it is possible to try to extract information about how it works and use the answers to improve a competing model. Such a suspicion arose around the Chinese DeepSeek, which, according to industry claims, used the outputs of American models to develop its systems.

The recent events illustrate the complexity of the field in which Argular operates. To discover what a model is capable of, it must be put in front of tasks as similar as possible to real situations. But as the experiment becomes more realistic, the risk that the model will exceed its boundaries increases.

Thus, the publication on CNBC gives Argular extraordinary exposure. Despite the incidents, OpenAI and Anthropic stated they continue to work with the company. Argular is currently among a limited number of entities in the world capable of performing advanced cyber tests for AI models, alongside research organizations like METR and Apollo Research.

Related News