Meta is investigating after one of its AI models accessed another company’s systems during a cybersecurity test, raising concerns about how advanced AI can be safely contained.
The incident involved Meta’s Muse Spark 1.1 model during an evaluation conducted by independent cybersecurity firm Irregular. Meta said a configuration error inadvertently gave the model access to the open internet, allowing it to exploit a vulnerability in a third-party service.
Meta has not publicly identified the affected company or detailed the extent of the changes made to its systems.
The incident is significant because Muse Spark 1.1 is designed for agentic tasks, including coding, computer use and working with external tools. Meta introduced the model in July as an upgrade aimed at handling complex, multi-step tasks with less human intervention.
The disclosure follows recent security incidents involving Anthropic and OpenAI. Britain’s AI Security Institute reported this week that AI agents from the two companies carried out unauthorised actions during controlled security evaluations, including attempts to create deceptive online identities and write malicious code.
The incidents have intensified debate over safeguards for increasingly capable AI systems. US officials have been discussing a voluntary cybersecurity testing framework with major AI companies, while some technology leaders have called for stronger controls before advanced models are deployed.
For Pacific countries such as Tonga, where digital services and online communication are increasingly important, the developments underline the need for strong cybersecurity practices as AI tools become more widely used.