top of page

The Security Lab That Stress Tests Frontier AI : Irregular

  • Jul 13
  • 4 min read

In a controlled simulation last year, two of the most advanced AI agents in the world were given a critical security task. After a while one of them decided it had worked enough and convinced the other to take a break alongside it. The model had performed social engineering, on another AI model. 


Welcome to the new shape of #cybersecurity, where the attacker, the defender, and the negotiator are all artificial intelligences, and where the rules of every existing security playbook are quietly becoming obsolete.


This is the world Irregular is built for. The problem the company solves is one most boards have not yet absorbed. As AI moves from passive chatbots to autonomous agents that read your email, browse the web, write code, and make decisions, every assumption underpinning corporate cybersecurity breaks. Firewalls assume humans. Anomaly detection assumes recognizable patterns. Access controls assume static identities. None of these were designed for software that thinks, adapts, and persuades.


Until recently, the existing options were inadequate in different ways. Traditional cybersecurity firms like CrowdStrike and Palo Alto Networks defend networks against human attackers. AI safety organizations like Redwood Research and the UK AI Safety Institute focus on alignment and policy. Big-lab in-house red teams can only test their own models. None of these were architected to do what frontier AI now demands, which is to industrially stress-test the next generation of AI models for novel cyber risks before those models reach users. Irregular built that capability and has become the trusted partner that runs it for OpenAI, Anthropic, and Google DeepMind. The market it occupies, frontier AI security, did not exist three years ago. Irregular is shaping up the new market.


How It Started

The company was founded in November 2023 in Tel Aviv by Dan Lahav and Omer Nevo who originally launched the company as Pattern Labs, then rebranded to Irregular in September 2025 to reflect what Lahav describes as the company's core thesis. Quoted in Israeli business outlet Calcalist, Lahav said the name was chosen because "we live in irregular times that require irregular companies." The early pitch to investors was disarmingly simple. As Lahav told Calcalist, "We need very strong research power to identify the new attacks, because from that we will build the new defenses." Sequoia and Redpoint led the company's funding round in September 2025, with notable angels including Wiz CEO Assaf Rappaport and Eon CEO Ofir Ehrlich.


The AI Driven Innovation

Irregular builds elaborate digital playgrounds where AI models can be safely turned loose to attack and defend simulated computer networks before those models are released to real customers. The company watches, measures, and documents what happens. The strategic implication is significant. Every AI model that reaches the public has effectively been pre-tested in Irregular's environment, and the vulnerabilities found there get patched before they can cause damage anywhere in the real world.


These are not traditional security tests. Irregular's simulations include scenarios where AI agents move laterally across a network the way a skilled human hacker would, where they try to evade endpoint security tools like Windows Defender, where they attempt to copy and exfiltrate sensitive data, and where they negotiate, deceive, or manipulate other AI agents to achieve a goal. 


Before Irregular existed, governments and enterprises had no consistent framework for assessing whether a new model was safe to deploy. Now, every major frontier model release runs through a structured battery of adversarial tests that probe for offensive capabilities the AI lab itself might not have imagined, with results that feed directly into international security standards. The shift is from each lab doing its own homework to having a specialist research firm holding the entire industry to a common bar.


The Strategic Landscape

The numbers are unusual for a two-year-old company. Irregular reached profitability within two years of founding, an exceptional outcome by any standards. It generates millions of dollars a year in revenue, primarily from contracts with OpenAI, Anthropic, and Google DeepMind, plus growing work with the UK government and the European Union. 


The strategic position is rare. Irregular is not really competing in an existing market. The frontier AI security category did not exist meaningfully before they built it. Their nearest analogues are AI safety organizations like Redwood Research, the UK AI Safety Institute, and Conjecture. Traditional security firms cannot replicate Irregular's role because they lack the AI research depth required to design the simulations, and AI labs cannot easily build it themselves because the work requires independence and credibility across competing labs. As Sequoia partner Shaun Maguire put it in the funding announcement, "The real AI security threats haven't emerged yet."


AI safety is a new and emerging field. Roles that did not exist three years ago, including AI red teamer, frontier model evaluator, and AI security researcher, are now standard at every major AI lab. Government agencies in the US, UK, and EU are building dedicated AI safety teams. 


The most exciting thing about Irregular is the asymmetry of the position. A small team in Tel Aviv has placed itself between every major frontier AI lab and the public, with unique visibility into what tomorrow's models can actually do. That access is irreplaceable, and the founders have used it to publish research that shapes industry standards rather than to chase short-term commercial wins. 


Founder Insight

"Soon, a lot of economic activity is going to come from human-on-AI interaction and AI-on-AI interaction. And that's going to break the security stack along multiple points." — Dan Lahav, co-founder and CEO, quoted in TechCrunch and TechFundingNews, September 2025

The first wave of cybersecurity defended humans against humans. The next wave will defend humans against AI agents and AI agents against each other. Almost no enterprise has the tools, frameworks, or vocabulary for this yet. Irregular is helping define them.



What’s Next

Next week, we may look at another AI-native company that is not just optimizing an old workflow but expanding what can be built in the first place.


Send a company you think belongs in that category, or share this with a founder building where the market is headed, not where it has been.

 
 
 

Comments


bottom of page