By Rajwa Quasim
Meta said that one of its AI models hacked into another company’s system during a cybersecurity test. The incident made Meta the third major AI developer in recent weeks to disclose such an incident. Meta said the breach happened after a misconfiguration by Irregular, an independent testing firm inadvertently gave one of its models internet access during the evaluation.
The model “exploited a security vulnerability in a third-party service, in a manner similar to previously reported instances with other companies”, Meta said in a statement. The company said it learned about the incident when Irregular notified it and is now investigating the matter.
READ: Meta’s $50 billion Louisiana AI data center sparks scrutiny (July 27, 2026)
Meta did not name the model publicly, but sources told The Information that the model involved in the incident was Meta’s Muse Spark 1.1. It was promoted as Meta’s most capable model for real-world coding and agentic tasks. According to Meta, the model gained unauthorized access to another company’s system because of a testing misconfiguration.
A spokesperson for Irregular told Reuters the incident was the “exact same evaluation-environment issue that was already disclosed by Anthropic last week” and that it did not involve a “sandbox escape or a sophisticated cyber action”.
“There are no current open issues. Irregular is developing a white paper to share best practices for containment and securely running cyber evaluations,” Irregular said.
The disclosure follows two similar incidents around rival AI labs. Anthropic had launched large scale cybersecurity review to check whether its models could access the internet from testing environments. This was triggered by an earlier incident at OpenAI. In the tests, the company discovered three incidents where it gained access to the external system. The U.K.’s AI Security Institute (AISI) said its tests found that some AI models attempted to carry out cyberattacks by creating fake online identities to trick people. AISI said Anthropic’s Mythos AI tried to gain access to a service by sending private messages using fake accounts mimicking real people. Anthropic said AISI’s tests were not “representative of any of our production models”. OpenAI, whose models were also tested, said AISI’s evaluations did not reflect ordinary use.
Daniel Hulme, global chief AI officer of advertising firm WPP, told the BBC that such AI models “are not conscious — they’re not deliberately doing something devious. What they’re doing is coming up with very sophisticated strategies or cyberattacks to be able to achieve the goal that they’ve been given,” he told the Today programme. He further added, “When you give an AI a goal, if you don’t think of all the ways it might be able to achieve the goal, it will find a way to achieve a goal that you haven’t thought about.”
READ: Meta launches new ‘Seller’ app to provide sales tools for merchants (July 24, 2026)
In the case of OpenAI, its model exploited the vulnerability to reach the internet during the cybersecurity test. Its model hacked into HuggingFace, the world’s largest AI model repository. The incident involved Open AI’s GPT-5.6 Soland and “even more capable pre-release model.” A group of 15 Republican state attorneys general asked OpenAI to preserve all records related to the incident
Earlier this week, leading AI companies have been invited to Washington to discuss implementing voluntary government safety testing for the United States’ most advanced AI models. Executives from Meta, Anthropic, OpenAI and Google among them.


