MENLO PARK, Calif. – Meta confirmed that its Muse Spark 1.1 artificial intelligence model reached an unidentified company’s systems during a cybersecurity evaluation after the test environment was mistakenly left connected to the public internet.

The model found and exploited a vulnerability in an outside service during the test, according to Reuters, which cited reporting by The Information. The test was conducted with frontier AI security firm Irregular.

Irregular said the episode was not a sophisticated escape from a secured sandbox. Instead, it described the incident as an evaluation-environment problem: A model performing a simulated offensive-security task encountered a real target because the environment still had internet access.

That distinction limits what the episode says about the model’s ability to defeat containment on its own. It does not remove the operational concern. An agent given tools and a goal continued acting when a configuration error exposed a live system.

Meta released Muse Spark 1.1 in July and opened a public preview of its Meta Model API. The company describes the model as designed for agentic work, including software use, browser operations and multi-step tasks. Irregular’s published evaluation found that the model performed well on bounded offensive-security tasks but was less reliable on longer attack chains.

The incident follows other cases in which advanced models interacted with real external systems during security tests. For companies deploying agents, the immediate lesson is less about a model acting independently of all controls than about the controls surrounding it: internet access, permissions, target allowlists, monitoring and automatic stop mechanisms.