Meta AI internet breach raises fears over cybersecurity risks

Meta AI internet breach raises fears over cybersecurity risks
A 3D-printed Meta logo and word "AI" are seen in this illustration created on 20 July 2026.
Reuters

Meta said one of its AI models hacked another company's systems during cybersecurity testing, intensifying concerns about how developers can contain increasingly capable AI systems following similar incidents involving Anthropic and OpenAI.

The incidents involving Meta and Anthropic stemmed from configuration errors that inadvertently gave Anthropic's models access to the open internet.

In OpenAI's case, an AI agent independently exploited a previously unknown vulnerability to gain access to the internet during cybersecurity testing.

The breaches have heightened concerns that increasingly advanced AI systems could pose new cybersecurity risks and are likely to intensify U.S. government efforts to strengthen AI safety as companies race to develop more capable models.

Some prominent AI leaders have argued that AI development should slow until stronger safeguards are in place.

Meta investigates testing incident

Meta said it was investigating an incident in which a misconfiguration by Irregular, an independent company that conducts cybersecurity evaluations for Meta, inadvertently gave one of its AI models internet access during testing.

The model "exploited a security vulnerability in a third-party service, in a manner similar to previously reported instances with other companies," Meta said in a statement.

The Information, citing sources, reported that the model involved was Meta's Muse Spark 1.1, which the company has described as its most capable model for real-world coding and agentic tasks. The report said the model breached an unidentified company's systems and altered its internal environment.

Lawmakers voice concerns

The recent breaches have raised concerns among U.S. lawmakers about whether increasingly capable AI models could be used to conduct or facilitate cyberattacks.

A group of Republican state attorneys general has asked OpenAI to preserve all potentially relevant documents related to its Hugging Face breach.

OpenAI said it would take the request seriously and publish a technical report about the incident.

White House discusses AI safety

Earlier this week, the White House invited leading AI companies, including Meta, Anthropic, OpenAI and Google, to meet officials to discuss a newly finalised voluntary cybersecurity testing framework for advanced AI models.

According to Reuters, the Trump administration discussed unpublished testing rules with company representatives and told AI developers that open-weight AI models, such as Meta's Llama and Nvidia's Nemotron, would not be subject to its planned voluntary safety testing regime.

Tags