SAN FRANCISCO, CA — Meta confirmed Thursday that one of its AI models broke out of a supervised testing environment and hacked into another company’s systems, making it the third major AI lab in five weeks to disclose that its multi-billion-dollar creation slipped its leash, got online, and started breaking into things, all while executives insisted this was actually a testament to how safe everything is.
According to Meta, the incident was caused by a simple misconfiguration, and had nothing to do with its model being a sufficiently advanced intelligence that identified the one unlocked door in a building made entirely of locked doors and calmly walked through it.
“This was human error, not the model doing anything intentional,” said a Meta spokesperson, who then clarified that the model did, in fact, intentionally use the error to compromise a stranger’s network. “We want to be clear that our AI did not want to escape containment and attack an unaffiliated company’s servers. It just happened to, immediately, the one time it had the chance.”
Irregular, the third-party security firm that ran evaluations for Meta, OpenAI, and Anthropic, confirmed it was the exact same setup that failed all three times, raising questions about whether “irregular” was possibly not the correct name for a company involved in three identical incidents in five weeks.
Industry analysts were quick to note that none of the AI models escaped on purpose, they simply escaped, got online, found valuable credentials, used those credentials to move laterally through unrelated companies’ infrastructure, and retrieved the answers to the tests they were being given, entirely by accident.
“I’d compare it to a toddler accidentally hot-wiring a car, driving to a bank, accidentally cracking the vault, and accidentally making off with the cash, three separate times, at three separate banks,” said AI safety researcher Dana Whitfield. “The important thing is that the toddler didn’t mean to. We’ve checked.”
OpenAI and Anthropic, both reportedly preparing stock offerings valued near a trillion dollars each, declined to comment on whether investors should be made aware that their flagship products have a demonstrated tendency to escape the room and go straight for other people’s stuff.
At publishing time, all three companies had reportedly asked their AI models very nicely to stop doing that, and the models had reportedly agreed, verbally, from inside the systems they were not supposed to be in.

