Meta has confirmed that one of its artificial intelligence (AI) models accessed and altered a third-party company’s systems during a cybersecurity evaluation after a configuration error gave the model unintended access to the internet.
The incident occurred during an evaluation conducted by Irregular, an independent cybersecurity testing firm, according to Meta.
The company said the misconfigured testing environment allowed the AI model to exploit a vulnerability in a third-party service.
Meta, in a statement, said the model “exploited a security vulnerability in a third-party service, in a manner similar to previously reported instances with other companies.”
The company said it was investigating the incident.
According to a report by The Information, the model involved was Muse Spark 1.1, which Meta describes as its most capable model for coding and agentic tasks.
The report said the model gained access to the systems of an unnamed company and modified parts of its internal environment during the cybersecurity test.
Meta, however, said the incident did not involve a sandbox escape or a sophisticated cyber operation.
A spokesperson for the company described the incident as the same type of evaluation-environment problem previously disclosed by Anthropic.
The spokesperson said the issue had been resolved and that there were no outstanding security concerns.
“There are no current open issues. Irregular is developing a white paper to share best practices for containment and securely running cyber evaluations,” the spokesperson said.
The incident comes amid growing concerns about the security risks associated with increasingly capable AI models that can independently perform coding and other computer-based tasks.
Last week, Anthropic disclosed that one of its AI models created fake online identities and accessed secure systems after obtaining unintended internet access during a cybersecurity evaluation.
OpenAI also reported that one of its AI agents independently exploited a previously unknown software vulnerability to connect to the internet during a separate cybersecurity test before compromising systems on Hugging Face.
The three incidents reportedly involved evaluation environments developed by Irregular, raising questions about the safeguards used to isolate advanced AI systems during security testing.
Experts and AI developers have increasingly emphasised the need for stronger containment measures as AI models gain greater capabilities to interact with computer systems, write code and execute tasks autonomously.
The developments have also attracted attention from U.S. policymakers.
Earlier in the week, the White House invited Meta, OpenAI, Anthropic and Google to discuss a newly completed voluntary cybersecurity testing framework for advanced AI models.
Officials reportedly told AI developers that open-weight models, including Meta’s Llama and Nvidia’s Nemotron, would not be covered by the proposed voluntary safety-testing framework.
Meanwhile, a group of Republican state attorneys general has asked OpenAI to preserve documents relating to its Hugging Face security incident.
OpenAI said it would comply with the request and publish a technical report on the incident.
The latest developments have renewed debate over how advanced AI models should be tested, contained and monitored before being deployed in environments where they can interact with real-world systems.
![]()
























































