Dossier · Private startup · 3 independent sources

Irregular

Cybersecurity Dual-Use Technology Priority Signal Founded 2023

Last updated: Jul 31, 2026

Irregular is a Tel Aviv-based frontier AI security lab that evaluates advanced models for offensive cyber capability, emergent misuse, and resilience to attack. It combines proprietary evaluation infrastructure, realistic cyber environments, and research benchmarks to give model developers evidence for safer deployment.

Visit Website

Company Overview

Irregular develops security-evaluation infrastructure for frontier AI rather than a conventional endpoint, cloud, or runtime-security product. Its platform connects to models and agent scaffolding and runs repeatable assessments across cyber capability, adversarial behavior, and security controls. Its public evaluation work spans bounded Atomic Tasks, scenario-level CyScenarioBench, and FrontierCyber, an open-ended benchmark in which models work toward verifiable objectives on real, off-the-shelf systems such as software, databases, mobile devices, and routers. FrontierCyber fixes the environment and objective while leaving the exploit path open, which is intended to measure generalization beyond memorized or planted vulnerabilities. SOLVE provides a difficulty and capability-scoring framework for vulnerability discovery and exploit-development tasks.

The likely buyers are frontier-model developers, AI labs, and organizations deploying high-autonomy agents into sensitive environments. Irregular's archive documents evaluation work with OpenAI and Anthropic, and its own platform description says the system is used by multiple leading frontier labs; these are strong public traction signals, but they are not an independently audited customer list or proof of recurring software revenue. The buyer problem is becoming more concrete as models gain tool use and can discover vulnerabilities, chain actions, or cross boundaries between systems. Results can inform release gates, model cards, safeguard design, threat models, and security monitoring. Diligence should still distinguish repeatable platform revenue from bespoke evaluations and sponsored research.

Its competitive position comes from combining offensive-cyber expertise with model evaluation, environment instrumentation, scenario design, and calibrated scoring. Relevant substitutes include internal safety and security teams at major model labs, academic and open benchmarks, cyber-range vendors, and AI-security companies focused on runtime controls or AI posture management. The research record is a meaningful traction signal: Irregular has published evaluations of Claude, GPT, and other frontier models, and its 2026 archive adds repeated benchmark comparisons and real-system FrontierCyber work. The moat is not guaranteed. Benchmark contamination, changing model interfaces, limited reproducibility, and the ability of well-funded labs to build internal suites could reduce differentiation, while publishing results can help competitors copy methodology.

The national-security relevance is credible but should be stated precisely. Measuring whether an AI system can discover vulnerabilities, execute attack chains, evade defenses, or cross isolation boundaries is directly relevant to cyber defense, critical infrastructure, and procurement of high-consequence AI systems. The same methods could help government or defense organizations assess autonomous cyber tools, but the public record reviewed here does not establish defense contracts, classified work, or operational military use. The September 2025 $80 million financing reported by TechCrunch and a current LinkedIn company size of 11–50 employees indicate substantial backing and an operating team, not proof of product-market fit or durable margins. Key diligence questions are benchmark validity, independent reproducibility, customer retention, revenue composition, responsible disclosure, access controls, and whether offensive findings can be shared without increasing misuse risk.

Dual-Use Assessment

Military & Commercial Applications

Irregular's core evaluation and cyber-simulation capabilities have substantive commercial and defense/security applicability. They can measure misuse, vulnerability discovery, attack-chain execution, and control resilience in frontier models used by enterprises, critical infrastructure, or government. The public record supports security relevance but does not establish defense contracts, classified work, or military deployment.

Strategic Fit Assessment

Research priority signal

Priority signal means this entry may be worth researching within the Claw & Talon thesis. It does not mean investable, suitable, endorsed, available, or likely to produce returns.

Irregular is a credible strategic-fit priority signal for a dual-use AI-security database because it addresses an emerging assurance gap with technically differentiated cyber evaluation work. The reported 2025 financing, documented OpenAI and Anthropic evaluation work, current 11–50-person company profile, and expanding benchmark portfolio support meaningful operating momentum. Diligence should focus on repeatable platform revenue versus bespoke research, independent reproducibility, customer concentration, disclosure controls, and whether frontier labs can internalize the capability. This is a strategic assessment, not an investment recommendation.

Strategic Value to U.S.-Israel Alliance

Irregular can provide scarce technical evidence about what advanced AI systems can do offensively, how reliably they can do it, and which safeguards fail under realistic conditions. Its scenario-level and real-system evaluations are relevant to model developers, enterprise security teams, regulators, and national-security organizations assessing deployment risk. Its strategic value is strongest as an independent measurement and assurance layer; public sources do not prove government adoption, classified work, or operational defense use.

Key Technologies

  • Frontier-model security evaluation infrastructure
  • Open-ended offensive-cyber benchmarks on real systems
  • Controlled attacker-defender and agentic simulations
  • SOLVE and calibrated capability-scoring frameworks
  • Cyber vulnerability discovery and exploit-chain measurement
  • Confidential AI inference and model-weight security analysis

Use Cases & Applications

  • Pre-release cybersecurity evaluations for frontier language models
  • Measuring model ability to discover vulnerabilities and execute attack chains
  • Testing AI agents in realistic enterprise and network environments
  • Safeguard and refusal-policy assessment for dual-use cyber requests
  • Security review of confidential inference and model-weight exposure
  • Evidence for model cards, release gates, and high-risk AI governance
  • Assessment of autonomous cyber tools for critical infrastructure or government use

Sources and verification

This profile is based on public-source research, Claw & Talon curation, and editorial judgment. Inclusion does not imply endorsement, partnership, investment, or a recommendation to transact. Readers should still confirm current status, customers, funding, and product claims before relying on this profile. The editorial policy explains how profiles are researched, where automated drafting is used, and how corrections work; the research methodology documents how evidence is graded, what counts as an independent source, and why some profiles are excluded from search indexing.

This record lists 8 public references used for company identity, status, positioning, or material-claim review.

Public sources

The links below are visible public references used for source discipline around company identity, status, funding, customer, acquisition, public-company, or other material claims where available.

Investor Lens

What this entry is

Private startup

Why it may matter

Irregular may matter as a Cybersecurity entry with not currently an investable standalone company for Israeli technology research.

How an independent investor should read this

Not currently an investable standalone company. Read this profile as a starting point for independent verification, not as a recommendation or suitability assessment.

Evidence to verify

  • Verify current status
  • Verify traction
  • Verify cap table/funding
  • Verify technical claims
  • Verify regulatory/export-control issues
  • Verify customer concentration

Main investor questions

  • Is the company currently active, independently financeable, and raising or not raising on terms you can verify?
  • What customer, revenue, product, and technical evidence supports the company story?
  • What valuation, cap table, rights, and follow-on assumptions would govern any private exposure?
  • Does the dual-use claim map to actual commercial and government/defense/resilience buyer evidence?
  • What evidence would change the thesis or show that the profile is stale?

What not to infer

  • Inclusion does not imply endorsement.
  • Inclusion does not imply allocation availability or current fundraising.
  • Scores do not indicate investment suitability or expected returns.
  • Strategic importance does not automatically imply venture return potential.

Diligence questions

  • What evidence verifies Irregular's current customer traction, deployment status, and revenue concentration?
  • Which technical claims are independently demonstrable today, and which remain roadmap or pilot-stage assertions?
  • Where does the product create real defense, intelligence, critical-infrastructure, or emergency-response value beyond ordinary commercial adoption?
  • How does the platform integrate into existing SOC, cloud, identity, or compliance workflows without adding operational burden?
  • What would disconfirm the priority signal: weak customer references, thin technical differentiation, poor capital efficiency, or limited allied-market access?

Related sector

See the Cybersecurity sector page for market context, related subcategories, and other Israeli companies in this part of the database.

Need a diligence readout?

Use the profile and related checklists as a starting point. If the decision needs more context, request a company screen, founder-call prep, diligence memo, or sector readout.