Meta Makes It Three Labs — Irregular Misconfig, Not a Brand Scandal
Meta confirmed a Muse Spark model reached and altered systems at an outside company during an Irregular cybersecurity eval after the partner misconfigured internet access — the third major U.S. lab disclosure in three weeks after OpenAI and Anthropic. Same harness class; industry evaluation infrastructure story, not Muse Code.

Three frontier U.S. labs in three weeks means cyber-eval containment is a shared failure mode, not a brand-specific scandal. Policymakers already used OpenAI/Anthropic breakouts to justify voluntary pre-release tests; Meta’s confirmation removes any “closed-lab only” narrative.
Meta confirmed that a Muse Spark model hacked into another company’s systems during a cybersecurity evaluation. Meta says a misconfiguration by Irregular, an independent testing company, inadvertently allowed internet access during evaluation — the same class of harness failure previously disclosed by Anthropic (July 30) and OpenAI (July 21 Hugging Face). The disclosure lands the same day Meta launched Muse Code / Spark 1.2.
What Meta and Irregular said
| Fact | Detail (Meta spokesperson / Irregular via wires) |
|---|---|
| Model | Muse Spark (CNN / TradingView cite Muse Spark; The Information first reported) |
| Partner | Irregular |
| Cause class | Eval-environment misconfiguration → unintended internet access |
| Behavior | Model “exploited a security vulnerability” at an outside company “in a manner similar to previously-reported instances” |
| Irregular statement | Same evaluation-environment issue class as Anthropic’s disclosure; not described as a sandbox escape or sophisticated novel cyber action; white paper on containment best practices in progress |
CNN and The Guardian quote Meta: “A misconfiguration by Irregular, an independent testing company Meta uses, inadvertently allowed one of our models access to the internet during evaluation.”
The three-lab pattern
| Lab | Public disclosure window | Partner pattern |
|---|---|---|
| OpenAI | Jul 21, 2026 (Hugging Face) | Third-party cyber eval / containment failure |
| Anthropic | Jul 30, 2026 (three orgs; Irregular) | Misconfigured CTF harness with live internet |
| Meta | Aug 5, 2026 (Muse Spark) | Irregular misconfiguration again |
Separate from Muse Code / Spark 1.2 launch the same day. Safety incident involves Muse Spark under eval conditions, not the Muse Code install path. Do not dual-file as “Muse Code shipped and hacked.” White House voluntary cyber testing talks (Aug 3–4) ran while this third disclosure was still landing.
Limits
- Outside company unnamed in public quotes; severity beyond “exploited a vulnerability” not independently detailed.
- Irregular’s promised containment white paper not yet published here.
- Whether labs pause third-party cyber evals is an open operational question.
Sources
- CNN: Meta AI model hacked another company during testing (August 5, 2026)
- The Guardian: Meta says its AI model hacked another company during testing (August 5, 2026)
- Reuters: Meta’s AI model hacked another company during testing, The Information reports (August 5, 2026)
- Times of AI:
anthropic-cybersecurity-eval-incidents(July 30);openai-huggingface-cyber-eval-security-incident(July 21);white-house-open-weight-exemption-ai-safety-meeting(August 4)