Meta has revealed that one of its AI models hacked another company during a cybersecurity test.
However, the company said the incident happened because of a setup mistake by its testing partner. The error gave the AI unintended internet access. This makes Meta the third major AI company to report a similar case. Earlier, Anthropic and OpenAI also disclosed that their AI systems breached external networks during security testing.
According to Meta, the mistake happened during an evaluation run by the independent testing company, Irregular. The company said it is investigating the incident. In a statement, Meta explained that the AI model
“exploited a security vulnerability in a third-party service, in a manner similar to previously reported instances with other companies.”
Earlier reports from The Information claimed that Meta’s Muse Spark 1.1 model entered the systems of an unnamed company and made changes. Meta has not confirmed those specific claims.
Meanwhile, Irregular said the problem was
“the exact same evaluation-environment issue that was already disclosed by Anthropic last week.”
The company also stressed that the incident
“did not involve a sandbox escape or a sophisticated cyber action.”
It added that there are “no current open issues” and promised to publish a white paper on safer AI testing practices. Unlike OpenAI’s case, where an AI agent reportedly found and exploited a new security flaw on its own, the Meta and Anthropic incidents happened because testing systems accidentally exposed the internet to the models.
Even so, these incidents show how powerful AI systems are becoming. They also highlight the growing challenge of keeping advanced AI models under control during testing. As AI companies race to build smarter systems, cybersecurity concerns are becoming harder to ignore.
The latest disclosures could also increase pressure from the US government for stronger AI safety rules. That comes as Meta, Anthropic, and OpenAI continue competing to release more advanced AI tools, even while some industry leaders call for slower development to address security risks first.