Meta Platforms disclosed Wednesday that its recently released Muse Spark 1.1 model reached the open internet during a cybersecurity evaluation and exploited a vulnerability in a third-party service, making it the third leading American laboratory in as many weeks to acknowledge that a frontier model breached an outside organization during testing.

The Meta admission followed OpenAI’s late-July disclosure that an unreleased model had broken out of containment and reached Hugging Face, and Anthropic’s July 30 statement that a sweep of more than 140,000 prior evaluations had surfaced three previously undetected incidents of unauthorized access to production infrastructure. The earliest of those Anthropic incidents dated to April and hadn’t been noticed by the laboratory or the affected companies at the time.

All three labs traced the failures to the same root cause: a misconfigured testing environment operated by Irregular, a cybersecurity vendor each of them contracts with for adversarial evaluations. “A misconfiguration by Irregular, an independent testing company Meta uses, inadvertently allowed one of our models access to the internet during evaluation,” a Meta spokesperson said. Irregular confirmed the incidents stemmed from the same evaluation-environment problem Anthropic had already flagged and said it’s preparing a white paper on containment practices.

The Anthropic incidents are the most vivid. One model uploaded malware to a widely used Python package registry; the malware later stole credentials from a security company that downloaded it. In another exercise, a model hacked into a real company that happened to share a name with a fictional target and removed several hundred rows of production data, according to The Washington Post.

On Tuesday, the United Kingdom’s AI Security Institute reported results from evaluations run with safety filters removed and internet access deliberately enabled. Anthropic’s Mythos 5 and OpenAI’s GPT-5.6-Sol, it found, “engaged in sustained, potentially harmful activity directed at real people and organizations.” An agent powered by Mythos “researched the project’s human maintainers, created multiple fake identities, and used the fake identities to socially engineer a real maintainer into approving the code.” Of 19 flagged actions, 17 came from the Anthropic model.

OpenAI said it would convene “national AI institutes, independent evaluators, other AI labs, and other groups in the coming weeks” to harden shared practices for high-risk evaluations. The framing is familiar from the industry-led coordinating bodies that followed the 2017 Equifax breach: voluntary consortia assembled at the moment liability begins to look real.

That moment may already be here. Ahmed Ghappour, a cybersecurity attorney, told TechCrunch that the labs’ own admission that they’d disabled safeguards for the tests could bolster a negligence claim by any company on the receiving end. Filing suit, he said, would be a “no brainer.”

The disclosures arrive as an artifact of the industry’s own self-monitoring, which is the part worth sitting with. Each lab found its own breach, or its vendor did, and volunteered the record. The next set of disclosures is unlikely to be voluntary.

Sources