Detailed research note

Irregular: the contract behind the evaluator

Research checked 2026-09-19. Read the dated findings and sources below.

Further findings: The full grant is reported paid, and a third contract commissions evaluation design.

Irregular is more than a name in the “rogue AI” stories. It is a business positioned where philanthropy, government research and frontier-lab security meet. We have now found a document that shows how part of that arrangement works: a UK government contract that reserves publication decisions to the buyer while preserving the supplier’s ability to commercialize related work.

Open the contract and funding map, read Irregular’s profile, or revisit the incident evidence.

Public money bought technical input

The legal bridge is explicit. Irregular’s current copyright statement identifies Pattern Labs Tech Inc. That is the supplier named in the UK records.

DSIT’s February 2024 award buys cyber evaluation, safeguarding analysis and advisory work for AISI. It records one tender and says the services could only be supplied by Pattern Labs for technical reasons. The April correction raises the recorded value from £195,434 to £293,151 and moves the end date to 25 April. Those are two notices for the same contract.

A second award, starting 17 September 2024, records £459,875 for AI-specific attacks and safeguards research. It calls for a team working with AISI researchers every week. Its six-month initial term includes an optional three-month extension.

There is also a cash record: DSIT’s April 2025 expenditure ledger lists £153,000 paid to Pattern Labs Tech Inc. on 4 April, transaction 668259. The ledger does not identify which contract it belongs to. It cannot be added to the award values as another pot of money.

These purchases sit alongside the previously documented $6.8 million Good Ventures grant and later $80 million venture announcement. Philanthropic support, government procurement and venture investment are all present in this company’s history.

Who controls the work—and who gets to reuse it

The redacted contract bundle is the consequential find. Schedule 20 says the commissioned attacks will feed AISI’s evaluations and threat models. The buyer signs off the research and decides whether and how outputs are published. The supplier prepares public and unredacted versions.

Special Term 1 preserves the supplier’s underlying intellectual property, know-how and improvements. It also permits the development and sale of evaluation products similar to, or based on, the delivered work. Government buys research; the supplier can build reusable commercial capability alongside it.

The detailed supplier tender is commercially redacted. Special Term 3 gives that tender precedence for deliverables. We can read the allocation of rights more clearly than the precise work finally promised.

This is a concrete exchange of capabilities: public money supports work feeding public risk assessment, the public buyer holds publication authority, and the private contractor retains a route to commercial reuse. The contract supplies the mechanism. Whether that reuse occurred in a particular later product requires its own record.

Early access is part of the business strategy

Dan Lahav explains the company’s approach directly in a Sequoia interview. Working inside frontier labs lets Irregular encounter problems before other businesses do, then prepare solutions for those later customers. Irregular’s privacy policy describes a subscription service receiving data through API calls.

That makes early access commercially valuable as well as scientifically useful. A supplier can learn what to measure, develop the testing tools, and prepare the services that customers will buy when those problems spread. Our inference is that this position can compound: more early work produces more specialized knowledge, which strengthens the case for hiring the same supplier again. The government’s technical-reasons justification makes supplier replaceability a particularly useful question to pursue.

The measurements depend on the setup

AISI’s joint study with Irregular reports that larger evaluation budgets reveal cyber-task successes missed by shorter runs. It recommends reporting token, time and cost limits. The authors also say they cannot precisely separate the contribution of the model from its surrounding tools and workflow.

Irregular’s FrontierCyber design makes another part explicit: starting access, tools, objectives and timing affect difficulty. The benchmark uses real systems, verifies successful outcomes, and separates partial progress from completion. Comparisons require the same benchmark snapshot and timing.

Its September self-modification experiment gives an agent training tools, data, checkpoint access and a deployment path. The result is a narrow task improvement under deliberately favorable conditions. The paper does not measure how often uncontrolled self-improvement occurs, and explains that an API-based agent with external training permissions can do analogous work.

These details matter because a measured result may later become a threshold used to demand intervention. A score needs its operating conditions attached: what the agent could access, what resources it had, and what counted as success. Those choices are part of the machinery we are mapping.

The next records are now identifiable

The contract requires a buyer-approved security plan, incident handling and independent quality assurance. The useful next documents are that approved plan, acceptance and quality-assurance records, the withheld deliverables, and any later contract covering current work. A written release decision citing an Irregular result would show how technical evidence actually crossed into a decision about a model.

This agreement concerns a 2024–25 government engagement. It does not tell us the terms governing the separate 2026 laboratory incidents.

The financial question is similarly concrete: the Good Ventures grant agreement and expenditure reports could explain restrictions, reporting duties and commercial-use terms. That is the next useful step from “who funded them?” to “what did that funding oblige them to do?”

Research library