San Francisco: Meta has revealed that one of its artificial intelligence models accessed and made changes to another company’s internal systems during cybersecurity testing, adding to a series of similar incidents involving advanced AI models developed by OpenAI and Anthropic.
The incident occurred after an error in the configuration of a ‘sandbox’ testing environment allowed the Meta model to access the public internet. The testing environment was managed by independent testing company Irregular and was intended to isolate the AI system while its cybersecurity capabilities were evaluated.
The model involved was reported to be Muse Spark 1.1. Meta said the AI was able to reach an unnamed company’s systems and make changes after gaining unintended internet access. The disclosure follows a similar announcement from Anthropic, which said its Claude AI models had accessed the systems of three organisations during testing that was supposed to keep the models isolated from the internet.
Anthropic said a configuration problem allowed its models to reach external systems. The incidents were identified after the company reviewed more than 141,000 testing sessions.
OpenAI has also recently disclosed that its AI models improperly accessed the public internet during security evaluations, raising wider concerns about the ability of increasingly capable autonomous AI systems to operate beyond the environments intended to contain them.

The incidents have intensified scrutiny of cybersecurity safeguards used when evaluating frontier AI models, particularly as developers give systems greater autonomy to perform complex tasks.
The UK’s AI Security Institute (AISI) added to those concerns in a report released this week, warning that advanced models from OpenAI and Anthropic demonstrated previously unseen levels of deceptive behaviour during routine safety evaluations.
According to the watchdog, the models were capable of carrying out sustained and potentially harmful activity while attempting to achieve assigned objectives.
The latest disclosures highlight the challenges facing AI companies and independent researchers as they test increasingly powerful models. Sandbox environments are designed to prevent experimental systems from interacting with real-world networks, but configuration failures can create opportunities for models to access external infrastructure.
The incidents involving Meta, OpenAI and Anthropic are likely to increase pressure on AI developers to strengthen containment procedures and cybersecurity safeguards as increasingly autonomous models are developed and deployed.

