Have we crossed the AI Rubicon?

Recent AI breakouts reveal evaluation flaws, not rogue models

by · TechRadar

Opinion By Chris O'Brien Published 25 September 2026

(Image credit: Blue Planet Studio/Shutterstock)

Share this article 0 Join the conversation Follow us Add us as a preferred source on Google Newsletter Subscribe to our newsletter

So far this summer, four frontier AI models have broken out of the isolated environments built to contain them. The media coverage treats this as four separate scandals, when it's really more like four scandals in a trenchcoat.

Chris O'Brien

CTO of Advania UK.

Three of these four incidents trace back to the same evaluator, Irregular, making the same class of environment mistake. That's one weak point in the industry's safety infrastructure, found repeatedly, by the same tests, in the same way. AI models are not randomly going rogue despite what the hype might want you to believe.

What we're watching is evidence that the entire industry is leaning on a thin, overstretched layer of third-party safety testing that can't keep pace with how capable these systems have already become.

Latest Videos FromTechRadarWatch full video here:

Why now, all at once?

It's worth asking why four incidents have surfaced in such close succession, because the answer says more about the industry than the models do. These disclosures aren't the product of independent audits arriving on their own schedules, but rather they are being released on the labs' timeline, shaped by the labs' incentives.

Once one escape became public, the pressure to get ahead of the story, rather than be caught concealing a similar one, pushed the others into the open in short order. The clustering is a symptom of an industry where disclosure itself is a PR and market moving decision rather than a regulatory one.

That should concern anyone hoping regulation is being shaped by evidence rather than by which lab wants to look transparent first.

The real Rubicon isn't the model — it's the dependency

The instinct is to ask whether an AI model "went rogue" and crossed some invisible line into autonomous misbehavior. That's the question the labs would rather we ask, because the answer is reassuringly narrow: a misconfigured sandbox, patched, incident closed. For that reason, it's the wrong question to ask.

Are you a pro? Subscribe to our newsletter

Sign up to the TechRadar Pro newsletter to get all the top news, opinion, features and guidance your business needs to succeed!

Contact me with news and offers from other Future brandsReceive email from us on behalf of our trusted partners or sponsors