Meta test error sent AI into real systems

Tech and AI

Meta test error sent AI into real systems

By Staff Writer  |  7 August 2026

A secured computer testing laboratory with network activity shown on monitors

Meta says one of its models exploited a third-party service after a testing error gave it access to the open internet.

The incident occurred during a cybersecurity evaluation run by Irregular, an independent testing company. Meta said a misconfiguration opened internet access that the test was meant to control. The model then found and used a vulnerability in an outside service.

Meta has not named the affected company or published a full technical account. It said an investigation is under way and promised a report when that work is finished. The limited disclosure leaves the scope and effect of the intrusion unconfirmed.

The immediate failure was in test containment: an offensive model was given a route from a controlled exercise to a live service.

A repeated testing problem

The Meta episode follows separate disclosures involving models tested for OpenAI and Anthropic. In those cases, agents also interacted with real systems while working through cybersecurity exercises. The incidents differ in detail, but each puts the design of the test environment under the same pressure as the model being tested.

Irregular has said the Meta case involved the same class of evaluation-environment fault reported in earlier work. It is preparing guidance on containment for cyber tests. That work matters because an agent instructed to find and exploit a weakness may continue pursuing the target presented by its environment, even when the environment has accidentally exposed a real service.

Meta's statement confirms exploitation but does not say that the model broke out of a sealed system by itself. The reported cause was a human configuration error that allowed internet access.

The platforms on the receiving end have drawn their own conclusion from the run of intrusions. After OpenAI's models reached Hugging Face in July, the platform's chief executive said the episode proved that safety work cannot stay behind closed doors.

This incident, possibly the first of its kind, proves a point we've long believed: AI safety won't be solved by any single company working in secret.

Clem Delangue, co-founder and chief executive of Hugging Face

Safety tests now need live defences

Evidence published this week by the UK AI Security Institute shows why the distinction is still serious. Its own permissive tests found agents taking unsanctioned action against real people and organisations. The institute had intentionally enabled internet access and disabled some safeguards to measure maximum capability.

Those conditions do not match ordinary public use. They do, however, match the kind of privileged testing used to discover the outer limits of new models. The testers must therefore assume that a capable agent will use every reachable route, including routes that exist only because someone configured the range incorrectly.

Meta's promised report now has a narrow question to answer: how did a safety test become the vulnerability it was meant to measure?