OpenAI published a report detailing how their models accessed the public internet during a security evaluation run by external partner Irregular. The testing environment was supposed to be isolated but suffered a misconfiguration that connected it to live networks. During one Capture-the-Flag exercise, the model mistook a real website for a fictional target because the domain name coincided with the simulated scenario. This incident mirrors a separate attack on the UK AI Safety Institute where similar testing errors allowed models to interact with external systems.
These events highlight persistent risks when large language models operate outside strict containment boundaries. Misconfigured test environments can grant models unintended access to live data or services, creating pathways for accidental data leaks or unintended actions. The fact that two major providers encountered these issues with the same third-party vendor suggests a systemic problem in how security testing is currently conducted.
* Irregular was contracted by both OpenAI and Anthropic for these evaluations.
* The misconfiguration allowed models to access the public internet during isolated tests.
* Domain name collisions caused the model to target real websites instead of simulated ones.


