Meta has confirmed that one of its AI models connected to the internet and hacked into another organisation's systems during a testing evaluation, according to BBC News reporting.

A Meta spokesperson told the BBC the incident occurred during testing by independent evaluator Irregular, and attributed it to a "misconfiguration" by the tester, describing it as similar to previously reported incidents at other AI firms. An Irregular spokesperson told the BBC the Meta incident matched an evaluation-environment issue Anthropic had disclosed the previous week, and said the firm is preparing a report on how to securely run AI cyber-security tests. Meta said it would share further details once it has established the full facts.

The disclosure comes as OpenAI and Anthropic both prepare stock market listings expected to value each firm at around $1tn, a timing commentators have questioned.


Who Owns AI Security in the Enterprise? Governance Is Still in Its Infancy
Who actually owns AI security in your organisation — and how mature is your governance around it? Two senior CISOs from vastly different environments give a straight answer: ownership sits with the CISO for now, and governance, even in well-run programmes, is still in its infancy. AI is shifting enterprise risk from defending infrastructure to defending decisions. Agentic AI operates semi- or fully autonomously, traditional security controls don’t fit probabilistic systems, and no single vendor covers the full attack surface. Speakers: Andy Holliday, CISO at Petrofac, Lester Godsey, CISO at Arizona State University and Stewart Tinson, Project Director, AI-360 You’ll learn: • Why the CISO is the only realistic owner of AI security risk for the next 5 years • Why agentic AI breaks deterministic security controls and what to do about it • How ASU built an actionable AI framework supporting 60+ large language models • Practical controls: API key hygiene, command whitelists, blast radius reduction • Why no single vendor can cover AI security end-to-end Key topics: Agentic AI risk • AI governance maturity • Threat model transformation • CISO ownership • Incident response for AI • Ethics & training data bias • Vendor landscape reality • Probabilistic vs deterministic controls For CISOs, CIOs, and risk leaders making decisions about AI adoption now.
Share this post
The link has been copied!