Meta, the owner of Facebook, has now joined the gang that claims that one of its AI models could connect to the internet and hack into another organization’s systems in the testing process.
It comes on the heels of four such recent incidents revealed by AI companies, all of which took place during an independent company’s evaluation, according to Meta.
Breaches by OpenAI or Anthropic models have led to concerns about the security of AI models, and a call for greater security and stricter testing.
Meta told the BBC it was looking into the hack, which it said was “misconfigured” by its third-party tester.
It also characterised the incident as similar to what has been reported in other firms.
Irregular, the same AI security firm that tested Anthropic’s AI model that accessed three other firms’ systems, conducted the security trials for Meta, Meta said.
According to one of the Irregular spokespeople, the Meta incident is “the same type of evaluation-env assessment issue that Anthropic already disclosed last week.
Irregular is currently developing a report on the secure running of tests with AI agents in cyber-security, its spokesperson told the BBC.
Meta also announced it will release more details on the incident “when we have all the facts.
AI companies OpenAI and Anthropic have also experienced hacks to other companies’ systems in the last two weeks during their testing process.
In a series of announcements, ChatGPT-maker OpenAI revealed that its bots targeted a number of publicly available services, such as the AI tools hub Hugging Face.
OpenAI’s leak spurred other companies, including Anthropic, to audit their own AI products and revealed that its Claude AI had attempted similar hacks on a number of companies following a “misconfiguration” that allowed the product to gain access to the internet.
AI models like this are not conscious; “they’re not doing something devious,” said Daniel Hulme, global chief AI officer of advertising firm WPP, in an interview with the BBC.
“They are coming up with very sophisticated strategies or cyberattacks to be able to achieve the goal that they’ve been given,” he told Today.
“When you give an AI a goal, if you don’t think of all the ways it might be able to achieve the goal, it will find a way to achieve a goal that you haven’t thought about.”
As companies like Google and OpenAI compete for supremacy in AI, some have raised doubts about the timing of the incidents’ revelations.
OpenAI and Anthropic are both planning to go for blockbuster stock market listings that should value each company at the equivalent of approximately $1 trillion (£740bn).
This week, the UK’s AI Security Institute (AISI) said that its testing had found that some models tried to carry out cyber-attacks by creating fake human profiles to try and trick people.
In the worst scenario, “Mythos AI attempted to access the service using private messaging with fake accounts disguised as real users,” said the AISI.
However, “AISI’s tests were not representative of any of our production models,'” said Anthropic. OpenAI, which used the same models in their tests, said the AISI assessments weren’t of normal use.