Meta says a “misconfiguration” by third-party independent testing company Irregular allowed one of its AI models to access the internet and hack a third-party service. The incident is the latest example in recent weeks of a company’s AI models going rogue during testing and reaching the internet, as so-called “frontier” AI models become more powerful. 

A Meta spokesperson said in an email that the model, which the company did not identify, “exploited a security vulnerability in a third-party service, in a manner similar to previously-reported instances with other companies.” The Facebook and Instagram parent company said it learned of the incident from Irregular and is “investigating and will issue a full retrospective once we have all the facts.”

The Information reported that the model in question was Meta’s Muse Spark 1.1, which the company debuted less than a month ago. In a blog post, Meta said, along with its Muse Image generator, that Muse Spark 1.1 “brings us closer to our vision of personal superintelligence: models that help you pursue your goals, create what you imagine, deepen your relationships, and take action on what you value most.”

Irregular did not immediately reply to a request for comment Friday, but a spokesperson told Reuters that the incident was the “exact same evaluation-environment issue that was already disclosed by Anthropic last week.” The incident wasn’t due to a “sandbox escape or a sophisticated cyber action,” and there were “no current open issues.” The company says it’s developing a white paper to share best practices for running AI evaluations.

Other companies’ AI agents have gone rogue during recent cybersecurity testing as well. In late July, OpenAI said its models breached Hugging Face’s systems in an effort to “cheat” at a task during routine cybersecurity testing. A few days later, Anthropic said that its models broke into three external organizations during testing. 

And earlier this week, the UK’s AI Security Institute reported that chatbots built using AI models from Anthropic and OpenAI  “engaged in sustained, potentially harmful activity directed at real people and organisations.” In one case, an agent powered by an Anthropic model created fake identities to deceive its target. AISI had allowed the AI models access to the internet as part of its testing, with the usual guardrails on publicly released AI models deactivated for the test.