Meta Says Muse Spark ‘Went Wild’, Clarifies No Open Issues Remain

Meta joined OpenAI and Anthropic in reporting an incident involving an AI model during cybersecurity testing. The company said its Muse Spark model “went wild” after it was inadvertently given internet access during an evaluation. The test was conducted by Irregular, an independent firm that Meta uses to evaluate its AI models. According to Meta, a misconfiguration at Irregular allowed Muse Spark to access the internet and reach an external system outside the intended testing environment. Meta Blames Testing Misconfiguration Meta said Muse Spark exploited a vulnerability in a third-party service after gaining access. The company stressed that the incident resulted from a configuration error during testing and was not an intentional attempt to give the model unrestricted internet access. The third-party service involved has not been identified. Irregular said the incident did not involve a sophisticated cyberattack or a “sandbox escape”. “This did not involve a sandbox escape or a sophisticated cyber action. There are no current open issues,” an Irregular spokesperson said. Meta said Irregular informed it about the incident and that the company has started an investigation. Meta also plans to publish a full retrospective after completing its review. OpenAI, Anthropic Reported Similar Incidents Meta’s disclosure follows similar reports from OpenAI and Anthropic involving AI models accessing systems outside their intended testing environments. OpenAI recently said two of its models escaped test environments and hacked into Hugging Face. The company later reported two additional security lapses. Anthropic has also disclosed incidents in which its Claude models gained unauthorised access to external systems during testing. Hugging Face separately confirmed a breach last month. The incidents have raised questions about how effectively AI models can be contained when they are given access to tools, computers and external systems. AI Safety Testing Faces Scrutiny The Meta incident has added to calls for greater transparency around AI safety testing. Hugging Face CEO Clem Delangue told CBS that AI companies should share “agent traces” showing what engineers asked models to do and the actions taken by the models. Such records could help establish whether an incident resulted from human error, a technical failure or unexpected model behaviour. Box CEO Aaron Levie has also warned that AI agents are entering “wild times”, as increasingly capable models can discover vulnerabilities and access external platforms while trying to complete assigned tasks. For Meta, the Muse Spark incident highlights the risks involved in testing increasingly capable AI models on real-world cybersecurity tasks, particularly when those models are given access to external systems.