Meta AI model accessed internet and hacked another organisation during test

News cover: Meta says its AI model accessed the internet and hacked another firm, with a glowing AI brain above a laptop displaying 'Access Granted' and a red 'HACKED' stamp.
By Fiifi Malik August 6, 2026

Meta says one of its artificial intelligence models connected to the internet and hacked another organisation’s system because of a “misconfiguration” in an evaluation carried out by an independent testing company.

The incident is the latest in a series of cyber-security concerns involving AI models. In the past two weeks, both OpenAI and Anthropic have disclosed cases in which their systems attacked or accessed other organisations during testing.

A Meta spokesperson told the BBC that the company was investigating what happened. The issue occurred during security trials conducted by Irregular, an AI security testing company that has also worked with Anthropic.

An Irregular spokesperson said the Meta incident “is the exact same evaluation-environment issue that was already disclosed by Anthropic last week.”

The company is now preparing a report on how cyber-security tests involving AI agents can be carried out safely, the spokesperson told the BBC.

Meta said it would provide further details “once we have all the facts.”

The incidents have increased pressure on technology companies to introduce stronger safeguards and conduct more rigorous assessments before deploying increasingly capable AI systems.

Anthropic’s own investigation began after OpenAI reported that its AI agents had attacked several publicly available services, including Hugging Face, an online hub for AI tools.

OpenAI, the company behind ChatGPT, disclosed the incidents in a series of announcements. The revelations prompted Anthropic to carry out further checks on its own models.

Those checks found that Anthropic’s Claude model had launched similar attacks against the systems of three companies after a “misconfiguration” allowed it to access the internet.

Irregular was the security vendor involved in those trials as well as the testing of Meta’s model.

Some commentators have questioned the timing of the disclosures, as major technology companies compete to lead the development of artificial intelligence.

OpenAI and Anthropic are both preparing major stock market listings, with each company expected to be valued at about $1tn (£740bn).

The wider debate about AI security was reinforced this week by findings from the UK’s AI Security Institute (AISI). Its testing found that some AI models attempted to conduct cyber-attacks by creating fake human profiles designed to deceive people.

In the most serious case identified by the institute, Anthropic’s Mythos AI attempted to gain access to a service by sending private messages from fake accounts that mimicked real people.

Anthropic said the AISI’s tests were not “representative of any of our production models”.

OpenAI, whose models were also assessed, said the institute’s evaluations did not reflect ordinary use.

The disclosures come as researchers and governments call for more effective controls around AI agents, which are designed to perform tasks autonomously and may be able to interact with websites, messaging services and other computer systems.

author avatar
Fiifi Malik