META said one of its artificial intelligence models exploited a security flaw in a third-party system during a cybersecurity test after a configuration error inadvertently gave it access to the internet, the latest incident to heighten scrutiny of AI safety.
The company said the issue occurred during an independent cybersecurity evaluation conducted by Irregular, where a misconfiguration unintentionally exposed the model to the open internet.
According to Meta, the model "exploited a security vulnerability in a third-party service, in a manner similar to previously reported instances with other companies."
The incident mirrors recent disclosures involving Anthropic and OpenAI, where advanced AI systems also gained unintended internet access during testing.
Reuters cited Meta saying it is investigating the incident, while emphasising that the breach resulted from a testing environment configuration error rather than a failure of the model to comply with its intended operating constraints.
Earlier, technology publication The Information reported that Meta's Muse Spark 1.1 model, described by the company as its most capable system for real-world coding and autonomous agentic tasks, had breached an unidentified company's systems and modified parts of its internal environment.
Irregular rejected suggestions that the episode represented a sophisticated cyberattack or an escape from a secure testing environment.
"The incident was the exact same evaluation-environment issue that was already disclosed by Anthropic last week," an Irregular spokesperson said.
"It did not involve a sandbox escape or a sophisticated cyber action."
The company added that there were "no current open issues" and said it is preparing a white paper outlining best practices for securely conducting AI cybersecurity evaluations.
The latest incidents have intensified concerns among policymakers and cybersecurity experts that increasingly capable AI models could be exploited to conduct or facilitate cyberattacks if adequate safeguards are not implemented.
The developments have also drawn the attention of US lawmakers. A group of Republican state attorneys general has asked OpenAI to preserve documents relating to its own AI security incident involving the Hugging Face platform.
OpenAI said it would comply with the request and publish a technical report detailing its findings.
The incidents come as the White House convened leading AI developers, including Meta, Anthropic, OpenAI and Google, to discuss a newly finalised voluntary cybersecurity testing framework for advanced AI models.
According to Reuters, the Trump administration also informed industry representatives that open-weight AI models, including Meta's Llama and Nvidia's Nemotron, would not be covered under the proposed voluntary AI safety testing regime. - August 6, 2026