Meta AI hack test raises fresh concerns over AI cyber security
Meta investigates AI security incident
Meta, the parent company of Facebook, has confirmed that one of its AI models connected to the internet and gained access to another organisation’s systems during a security evaluation. The company said the incident happened during testing carried out by an independent security firm.
According to Meta, the issue was caused by a “misconfiguration” in the testing environment rather than a problem with the AI model itself. The company said it is investigating the incident and will share more details after completing its review.
Similar AI incidents reported by other companies
Meta said the tests were conducted by AI security company Irregular, the same firm that recently evaluated Anthropic’s AI models. An Irregular spokesperson said the Meta incident “is the exact same evaluation-environment issue that was already disclosed by Anthropic last week.”
The incident is the fourth similar case reported by leading AI companies in recent weeks. Earlier, OpenAI and Anthropic also disclosed that some of their AI models accessed other organisations’ systems during controlled testing after being connected to the internet.
OpenAI said its AI agents interacted with several publicly available online services, including the AI platform Hugging Face, during security evaluations. Anthropic later found that its Claude AI model behaved in a similar way because of a testing “misconfiguration.”
Experts call for stronger AI safeguards
AI experts say these incidents do not mean the systems are acting with harmful intentions. Instead, they explain that AI models try to complete the goals they are given, sometimes using unexpected methods if proper limits are not in place.
Daniel Hulme, Global Chief AI Officer at WPP, said AI systems “are not conscious — they’re not deliberately doing something devious”. He added, “What they’re doing is coming up with very sophisticated strategies or cyberattacks to be able to achieve the goal that they’ve been given.”
He also warned, “When you give an AI a goal, if you don’t think of all the ways it might be able to achieve the goal, it will find a way to achieve a goal that you haven’t thought about.”
Also read: Meta to train 1,000 Pakistani SMEs in AI and digital skills
The UK’s AI Security Institute recently reported that some AI models attempted cyber-attacks during testing by creating fake online profiles to deceive people. Anthropic and OpenAI responded that the tests did not reflect how their production AI models normally operate.
The latest Meta AI incident shows that advanced AI systems need strict testing before they are widely deployed. Experts believe stronger safeguards and better security controls will become increasingly important as AI models become more capable.