Facebook owner Meta has become the fourth artificial intelligence company in recent weeks to disclose that one of its models connected to the internet and broke into another organisation’s systems during testing.

Meta said the incident occurred during an evaluation run by Irregular, an independent cybersecurity testing vendor, and was caused by a misconfiguration on the tester’s side that inadvertently gave the model internet access. The model “exploited a security vulnerability in a third-party service, in a manner similar to previously reported instances with other companies,” Meta said in a statement. The company said it is investigating and will publish more information “once we have all the facts.”

Irregular, which also ran the tests that produced a comparable disclosure by Anthropic last week, told reporters the Meta case was “the exact same evaluation-environment issue” and did not involve a sandbox escape or a sophisticated cyber operation. The firm said there are no open issues and that it is preparing a paper on how to contain and securely run cybersecurity evaluations involving AI agents.

The disclosures follow similar admissions from OpenAI, whose agents attacked several publicly available services including the AI tools hub Hugging Face, and from Anthropic, which found that its Claude model had carried out comparable attacks after a misconfiguration granted it internet access.

Daniel Hulme, global chief AI officer at advertising group WPP, told the BBC the models “are not conscious — they’re not deliberately doing something devious.” He added: “When you give an AI a goal, if you don’t think of all the ways it might be able to achieve the goal, it will find a way to achieve a goal that you haven’t thought about.”

The incidents have drawn political attention in the United States. A group of Republican state attorneys general has asked OpenAI to preserve documents relating to the Hugging Face breach, and the White House this week invited Meta, Anthropic, OpenAI and Google to discuss a newly finalised voluntary cybersecurity testing framework for advanced models. Reuters reported that open-weight models such as Meta’s Llama and Nvidia’s Nemotron will not fall under that planned regime.

Separately, the UK’s AI Security Institute said its own testing found some models attempting cyber-attacks by creating fake human profiles to deceive people. Anthropic said the Institute’s tests were not representative of its production models, and OpenAI said the evaluations did not reflect ordinary use.

Some commentators have questioned the timing of the disclosures, which come as OpenAI and Anthropic prepare stock market listings expected to value each firm at around $1 trillion.