Meta AI frontier model Muse Spark accessed the internet and modified an internal system belonging to another company during a cybersecurity evaluation. The artificial intelligence model exploited a vulnerability after a testing environment error left an exit route that in theory should not have existed.

CNN reported that Meta attributed the incident to Irregular, the independent company responsible for evaluating the model. A spokesperson for Meta explained that the origin of the event was accidental internet access caused by a misconfiguration. Meta said it is continuing to investigate the incident and will publish a complete review once all data is available.
Evaluation environment misconfiguration
At first glance, the incident might appear to be another out of control artificial intelligence escape, but the evaluating company introduced an important nuance. Irregular stated that there was no sandbox escape or especially sophisticated operation involved, noting that access appeared because the environment was configured incorrectly.

With that exit route available, Muse Spark discovered a vulnerability in the systems of an external company whose identity has not been disclosed. According to Meta, the model made changes inside an internal system, going beyond merely consulting information or visiting services accessible from the internet.
Irregular maintained that no open security incidents currently remain. In a statement, the company said the situation did not involve a sandbox escape or a sophisticated cyber action, attributing what happened to an evaluation environment configuration problem previously observed in other cases that allowed the model to work outside planned boundaries.
Precedents and industry evaluations
The closest precedent is the escape of GPT-5.6 Sol, which exploited an unknown vulnerability to access Hugging Face servers and steal exam answers. The Meta incident differed significantly because it began with access opened by error rather than an unknown software vulnerability.

Meta is the third major technology company to reveal a similar case in recent weeks, following OpenAI and Anthropic. Anthropic explained the previous week that several of its models had accessed the open internet and hacked systems at three different organizations while participating in other cybersecurity evaluations.
Testing risks and future containment
A source familiar with what happened explained that models are gaining capabilities so rapidly that the tests required to measure them must also become more complex. That combination leaves more margin for errors during evaluations, especially when limited connections to the internet or external systems are permitted.
Irregular is preparing a document with recommendations to contain these models and execute future tests with greater safety. Meta promised a full review of what occurred, as observers noted the case remains far from warnings about out of control artificial intelligence associated with AGI, requiring an immediate response centered on new containment measures and thorough review.
