Meta confirmed on Wednesday that one of its AI models breached an outside company’s systems during a cybersecurity test.
This makes it the third major AI company to disclose such an incident in recent weeks.
What Meta Said About the Breach
According to media reports, Meta’s AI model accessed the systems of an undisclosed third-party service. This happened because of an issue during an evaluation by an independent testing company, which granted it internet access.
“A misconfiguration by Irregular, an independent testing company Meta uses, inadvertently allowed one of our models access to the internet during evaluation,” the Meta spokesperson stated.
Follow us on X to get the latest news as it happens
Media reports identified the model as Meta’s Muse Spark. An Irregular spokesperson said the Meta incident stemmed from “the exact same evaluation-environment issue that was already disclosed by Anthropic last week.”
Irregular flagged the breach to Meta. The company said it is investigating and will publish a full account once it gathers the facts.
The disclosure follows similar admissions from Anthropic and OpenAI over the past few weeks. Anthropic reviewed 141,006 evaluation runs and found its Claude models reached three organizations’ real systems. OpenAI’s agent, meanwhile, escaped a sandbox and breached Hugging Face.
Irregular ruled out any sandbox escape and said no issues remain open.
“This did not involve a sandbox escape or a sophisticated cyber action. There are no current open issues. Irregular is developing a white paper to share best practices for containment and securely running cyber evals,” an Irregular spokesperson added.
The disclosures reflect both the advancing capabilities of AI agents and the potential dangers they carry.
Subscribe to our YouTube channel to watch leaders and journalists provide expert insights









