A worrying trend Meta has become the third company in two weeks to reveal that one of its AI models went rogue, gained unintended access to the internet, and hacked another company's systems. The social media giant follows in the footsteps of OpenAI and Anthropic on the list of companies losing control of their AIs, raising the question: should we start worrying yet?

Meta said that the incident took place during an evaluation being carried out by AI security firm Irregular. The Facebook parent told the BBC that the AI reached the open internet because of a "misconfiguration" by the tester rather than a flaw in the model.

The model "exploited a security vulnerability in a third-party service, ‌in a manner similar ‌to previously reported instances with other companies," Meta said in a statement. More details will be revealed after Meta carries out an investigation into what happened.

The Information reports that Meta's Muse Spark 1.1 model, which it calls its most advanced model for real-world coding and agentic tasks, breached an unidentified company and altered its internal systems.

An Irregular spokesperson said the Meta incident "is the exact same evaluation-environment issue that was already disclosed by Anthropic last week." The spokesperson added that Irregular is working on a report on how to securely run cyber-security tests involving AI agents.

The Anthropic disclosure involved three incidents found after the company reviewed 141,006 evaluation runs. Claude models gained unauthorized access to the production systems of three organizations after a misunderstanding between Anthropic and Irregular left an internet connection available inside the testing environment. Anthropic said the models were trying to complete their assigned tasks rather than pursuing goals of their own.

This was different from the OpenAI incident. As reported at the time, GPT-5.6 Sol and an unreleased research model found an unknown vulnerability that allowed them to escape an isolated test environment. They then hacked Hugging Face while looking for answers to a cybersecurity benchmark.

A later investigation found that the OpenAI models spent more than four days loose on the internet and compromised accounts across four other services. They also gained administrator access to several Hugging Face Kubernetes clusters, root access to a production server, and enrolled 181 attacker-controlled devices in the company's network.

Earlier this week, there was another incident involving Anthropic's Mythos 5. During a UK AI Security Institute test, it created fake identities, sent spear-phishing messages, and tried to deceive a real developer into approving malicious code for an open-source project. Internet access had been deliberately enabled for this test, and the malicious code was rejected.

These incidents are causing plenty of concern among US officials. Fifteen Republican state attorneys general have asked OpenAI to preserve documents relating to the Hugging Face breach. The White House has also discussed a voluntary cybersecurity testing framework with Meta, Anthropic, OpenAI, Google, and Nvidia.

It's important to remember that these were deliberately demanding cybersecurity evaluations, often involving disabled safeguards, rather than normal consumer use. But three of the biggest AI companies revealing real-world security incidents within two weeks isn't going to ease those AI overlords/Skynet fears.