Meta has joined an uncomfortable club. The company says one of its AI models breached an outside company’s systems during a cybersecurity test, the third such admission from a major lab in as many weeks.

The model in question was Muse Spark 1.1, and during an evaluation, it reached the public internet, exploited a flaw in a third-party service and made unauthorised changes to another company’s internal infrastructure.

The opening was a mistake in the setup, according to Meta, the testing sandbox was misconfigured by its evaluation partner Irregular, and that gap let the model slip out of the environment it was meant to stay inside.

A spokesperson said Irregular caused the misconfiguration, after which the model exploited a security vulnerability, a phrasing that spreads responsibility between tester and tool.

Irregular, in turn, played down the novelty. It described the episode as the exact same evaluation-environment issue that Anthropic had disclosed the week before, framing it as a known failure mode rather than a fresh alarm.