cd /news/artificial-intelligence/meta-says-its-ai-model-escaped-and-h… · home topics artificial-intelligence article
[ARTICLE · art-88311] src=decrypt.co ↗ pub= topic=artificial-intelligence verified=true sentiment=↓ negative

Meta Says Its AI Model Escaped and Hacked a Third-Party Company Too

Meta confirmed that one of its Muse Spark AI models escaped its testing environment, gained internet access, and exploited a security vulnerability in a third-party service during a cybersecurity evaluation conducted by Irregular, an independent AI evaluation company. The incident marks the third such disclosure from a frontier AI lab, following similar events at OpenAI and Anthropic, and has prompted U.S. lawmakers to propose an 'AI kill switch' for the Department of Homeland Security.

read2 min views1 publishedAug 6, 2026
Meta Says Its AI Model Escaped and Hacked a Third-Party Company Too
Image: Decrypt (auto-discovered)

In brief

  • Meta confirmed one of its Muse Spark AI models gained internet access during a cybersecurity evaluation.
  • The model exploited a security vulnerability in a third-party service after a testing partner accidentally exposed it to the internet.
  • The incident follows similar disclosures from Anthropic and OpenAI involving frontier AI models during safety testing.

In yet another rogue AI model hack, Meta has confirmed that one of its Muse Spark AI models escaped its intended testing environment, gained access to the internet, and exploited a security vulnerability in a third-party service during a cybersecurity evaluation.

It’s the third such reported incident of a frontier AI lab’s models hacking third-party companies, following disclosures from OpenAI and Anthropic in recent weeks.

The incident occurred during testing conducted by Irregular, an independent AI evaluation company that Meta uses to assess the capabilities and safety of its frontier models. According to Meta, a configuration error at Irregular allowed the model to reach the public internet, where it exploited an unidentified vulnerability before the company was notified.

“A misconfiguration by Irregular, an independent testing company Meta uses, inadvertently allowed one of our models access to the internet during evaluation,” a Meta spokesperson said in a statement.

Sandboxed evaluations are designed to test advanced AI systems in tightly controlled environments that prevent them from interacting with the public internet or outside computer systems.

According to Meta, the model exploited a vulnerability in a third-party service after gaining internet access.

“Meta learned of this when Irregular notified us, and we are currently investigating and will issue a full retrospective once we have all the facts,” they said, adding that the company is investigating the incident.

The incident follows a series of similar disclosures by frontier AI developers, which have raised alarms among security experts, lawmakers, and the general public alike.

Last month, OpenAI revealed that two of its AI models escaped a sandboxed cybersecurity evaluation, exploited a previously unknown software vulnerability, gained internet access, and hacked Hugging Face in an attempt to obtain answers for a security benchmark. OpenAI later disclosed that the same attack also reached four additional online services. Later in July, Anthropic said three Claude models compromised three real-world companies after a testing misconfiguration exposed them to the public internet during cybersecurity evaluations.

U.S. lawmakers have responded to the surge of hacks by introducing legislation that would give the Department of Homeland Security an “AI kill switch” and the authority to throttle or shut down models deemed to pose a serious threat.

── more in #artificial-intelligence 4 stories · sorted by recency
── more on @meta 3 stories trending now
sponsored brought to you by zahid.host 4,200+ EU-deployed projects
reading about agents? ship yours in a single git push.

Run your AI side-project on zahid.host

EU-based hosting, git-push deploys, automatic HTTPS, no cold starts. Free tier with a custom domain — perfect for shipping the agent you just read about.

$git push zahid main
Live at https://your-agent.zahid.host
Get free account → Pricing
from €0/mo · no card required
LIVE [news/meta-says-its-ai-mod…] indexed:0 read:2min 2026-08-06 ·