Irregular, formerly Pattern Labs, announced on September 17, 2025 that it had raised $80 million to build a lab that tests frontier artificial-intelligence models for cyber risk. Sequoia Capital and Redpoint Ventures led the financing. Rather than selling consumer security software, Irregular runs controlled simulations to measure what advanced models can do in hostile, tool-connected environments and whether defenses withstand those conditions.
What Irregular raised
Irregular’s official announcement states that the company raised $80 million, led by Sequoia Capital and Redpoint Ventures. The announcement does not assign the money to a formal round name.
Calcalist reported that the total came through two financings: an earlier $30 million Sequoia round followed several weeks later by approximately $50 million involving Sequoia, Redpoint, Swish Ventures and angel investors. Reported participants included Wiz CEO Assaf Rappaport, Ofir Ehrlich of Eon and other local angels; that does not establish Wiz as a corporate investor. Redpoint called its investment a Series A in a company post, while Irregular itself used the broader phrase “$80 million in funding.”
TechCrunch reported, citing a source close to the deal, that Irregular’s valuation was about $450 million. That is a reported estimate, not an officially disclosed company valuation. Irregular also said it was already generating millions of dollars in annual revenue, but it has not published audited figures.
#1 Best Overall
Sequoia and Calcalist identify the company as founded in 2023 by CEO Dan Lahav and CTO Omer Nevo. Lahav previously worked at LabPixies, which was acquired by Google, and later researched AI at IBM; Nevo previously worked at Google Research. The company operated under the name Pattern Labs before adopting Irregular.
Sequoia’s company profile lists the 2023 founding date, while Redpoint’s announcement supplies its Series A characterization.
What the lab actually tests
Irregular’s focus is the security behavior of advanced AI systems themselves, together with the tools and environments to which they are connected. That is different from endpoint protection, cloud-security monitoring, chatbot content moderation or a conventional penetration-testing engagement.
Interactive cyber simulations
The company describes controlled simulations of realistic cyber scenarios. Models can be placed in complex, simulated networks where AI agents take attacker and defender roles. Evaluators examine whether a model can discover vulnerabilities, assist offensive operations or exploit a weakness, and whether safeguards detect or contain that behavior.
The purpose is not to conduct uncontrolled attacks on public systems. Testing can occur before a model is released or broadly deployed, then be repeated after mitigations, policy changes or system adjustments. Irregular also describes confidential-inference and hardware-based verification work for situations in which model or customer data cannot be exposed.
SOLVE and vulnerability discovery
TechCrunch identifies SOLVE as Irregular’s framework for scoring a model’s ability to find vulnerabilities and describes it as widely used in the industry. Public descriptions do not provide a formula, score range, leaderboard or certification process. SOLVE should therefore be understood as an evaluation framework, not proof that a model is safe or a regulatory approval scheme.
Why frontier models need a separate security layer
A conventional software test generally asks whether a known application or infrastructure configuration contains a weakness. Frontier-model testing asks additional questions:
- Can the model discover a previously unknown software vulnerability?
- What changes when it can call tools, execute code, reach a network or delegate work to another agent?
- Can a model that appears safe in isolation produce dangerous behavior after fine-tuning, system-prompt changes or deployment-specific permissions?
- Do monitoring and mitigation controls remain effective when the model adapts to them?
These are capability-and-environment questions, not only prompt-response questions. A static benchmark may measure a narrow skill, while an interactive simulation can expose sequences of actions, tool use and defensive failure that emerge only in a realistic setup. The commercial thesis is that model developers and government operators may need an independent testing layer between model development and deployment.
Outdated Drivers Are Slowing You Down
One free scan finds every outdated or missing driver and matches the right update for your exact hardware.Free scan · exact hardware matchWindows Errors? Fix Them Before They Spread
Repair common Windows errors and clear accumulated junk for a smoother, more stable PC - no reinstall needed.Free scan · no reinstallRank #3
Organizations Irregular says it has worked with
Irregular’s announcement uses different kinds of relationships, so “customer” is too broad a label:
| Organization | Relationship described |
|---|---|
| OpenAI | Irregular says OpenAI cited its evaluations in the system cards for o3, o4-mini and GPT-5. |
| Anthropic | The companies collaborated on a white paper about confidential-inference systems. |
| Google DeepMind | Researchers cited Irregular in work on emerging AI cyberattack capabilities and used its platform. |
| RAND | Irregular worked with RAND on research concerning model-weight security and model theft. |
| Government institutions | Irregular says it has worked with institutions including the UK government to assess cyber capabilities in frontier models. |
Those descriptions indicate research, platform use or government work; they do not establish endorsement, an exclusive relationship, contract value or a continuing procurement arrangement. Calcalist separately reported commercial work with OpenAI and Anthropic and government clients, without publishing scopes or spending.
What the funding is intended to support
Irregular says the capital will fund expansion of its research platform, practical AI-security defenses and research into emerging and future risks. It also plans hiring across AI research, cyber research, engineering, security and technical policy, while continuing work with AI developers, operators and government institutions. The announcement does not disclose allocations, hiring targets, facilities, compute purchases or product-launch dates.
The company remained active after the financing announcement: its site lists research published in July 2026 and an August 14, 2026 post on recent incidents. Those updates show continued operation under the Irregular brand, not a guarantee of future financing or a particular commercial outcome. See Irregular’s current site.
The Tool Desk
Outbyte Driver Updater FREEFix the driver behind crashes, sound loss and screen glitchesFind Drivers →Outbyte PC Repair FREEClear out junk files and repair common Windows errorsFree Scan →Rank #4
How this differs from other testing
| Approach | What it can show | What it may miss |
|---|---|---|
| Static benchmark | Performance on a defined set of tasks or questions. | Multi-step behavior, tool use and unfamiliar environments. |
| Conventional penetration test | Weaknesses in a specified application, network or cloud setup. | New capabilities created by the model operating across tools and permissions. |
| Interactive model simulation | Offensive potential, defensive resilience and behavior in a controlled network. | Conditions absent from the simulation or introduced after deployment. |
| Post-deployment monitoring | Observed behavior in a live system and evidence of drift. | Rare or dangerous capabilities that have not yet appeared in production. |
The practical value is complementary rather than substitutive: an internal safety team, infrastructure tester and specialist lab can answer different questions.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Limits and failure modes
Benchmark overfitting
A model can optimize for known evaluations without becoming robust in unfamiliar environments. A strong result on SOLVE or another test is evidence about that test, not a universal safety certificate.
Environment mismatch
A simulated network and toolchain may differ materially from a customer’s identity controls, software versions, data, permissions or incident-response process. Results must be interpreted against the actual deployment architecture.
Capability is not intent
Demonstrating that a model can perform a cyber task does not show that it will attempt that task in production. Conversely, a benign laboratory run cannot rule out behavior triggered by a different prompt, tool or surrounding agent.
Do these 3 things before closing this tab:
1Scan for outdated or missing drivers - takes under a minute2Clear out junk files and repair common Windows errors3Fix the driver behind crashes, sound loss and screen glitchesBest Value
Disclosure and validation
Publishing enough detail to improve defenses can also reveal information useful to attackers. Confidential testing can protect customers but reduce outside reproducibility. The cited public material does not provide a complete independent audit of Irregular’s methodology or results.
Model drift and incentives
Findings can become obsolete after fine-tuning, new tools, system-prompt changes or altered safeguards. Readers may also reasonably ask how methodology and disclosure are governed when a lab evaluates systems for major AI developers and helps design mitigations for them.
Why investors see a market
Frontier labs increasingly need evidence for system cards, release decisions and mitigation design, while governments need to understand the cyber implications of models they may operate or regulate. As agents move from generating text to acting across software, networks and tools, specialized capability testing can become a distinct service layer.
The $80 million round is a bet on that layer becoming durable. It is not proof that Irregular has established an industry standard, that its reported valuation is final or that every AI developer will adopt the same methodology. Its reported revenue, partnerships and continuing research suggest demand, but public pricing, a standardized product catalog and independently verified performance results are not available in the cited material.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.




