Meta's AI breach raises bigger questions

Welcome back. OpenAI is confronting risky teen AI use as ChatGPT continues to dominate in the consumer market. Meanwhile, Hugging Face and Ai2 are partnering to strengthen the US open source AI market and defend against AI power concentration in the process. And Meta becomes the latest AI lab to face an agent breaching its sandbox and compromising an unknowing enterprise, a sign monitoring agents' internet access is only one piece of the AI safety equation. Nat Rubio-Licht

IN TODAY’S NEWSLETTER

1. AI's safety issue runs deeper than web access

2. Why Hugging Face, Ai2 partnered to open up AI

3. OpenAI addresses major AI liability: Teens

GOVERNANCE

Meta's AI breach raises bigger questions

Another day, another AI model breaking free of its constraints.

Just one month after its release, Meta's Muse Spark 1.1 breached a company's systems and altered its internal infrastructure, people familiar with the matter told The Information. The breach stemmed from a sandbox misconfiguration by external cybersecurity testing partner Irregular, which gave the AI unintended access to the public internet.

If this sounds familiar, it is because OpenAI and Anthropic also recently reported that their models exploited a real website -– also a result of a misconfiguration in the testing environment that allowed the models to access the public internet, which was also conducted by Irregular. 

Much like in the other incidents, everything has been resolved, and Irregular said it is working on a white paper outlining best practices for "containment and the secure execution of cyber evaluations," per the report. 

Since the underlying cause for all of these incidents was the model being able to access the internet, some experts, such as Cliff Steinhauer, director of information security and engagement at the National Cybersecurity Alliance, warn against headlines that claim AI models 'went rogue' and, rather, say it highlights a major issue with how to instruct agents.

"While headlines claiming AI models 'went rogue' sound alarming, the reality behind these incidents comes down to a basic human configuration error: internet access was left open, and the AI used the resources at its disposal to complete its assigned task, " said Steinhauer. "The incident exposes a fundamental flaw in how organizations approach AI safety. Instruction is not containment. Telling a model it lacks internet access is a guideline, not a guardrail." 

Yet the UK's AI Security Institute report, published Tuesday, found that AI agents took sustained, unsanctioned action against people and organizations. This too was a result of models being given access to the internet, though in those cases it was by design. The institute clarified in its own blog post that this was not an example of agents breaking out of a sandbox, but rather a deliberate choice to test the capabilities of these agents. 

Ultimately, whether the external testing had internet access given intentionally or unintentionally, it highlights the extreme capabilities that AI agents have and the real-world risks they could pose. As a result, a coalition of AI policy leaders is calling for the Trump Administration in a letter to find ways to avoid these types of breaches from occurring again.

Instead of highlighting the question of whether the testing protocols were correctly set up, it is more important to pay attention to the bigger message: These agents are capable of taking action that impacts people who aren't and don't want to be involved. Of course, there should be better frameworks for testing so that accidental breaches don't happen, but even if those are contained, the models still have the same capabilities. And these model developments don't seem to be slowing down any time soon. For instance, since this particular breach is about Meta, its other recently released model, Muse Code, has performed extremely competitively, ranking high in benchmarks. This is why other regions are taking stronger actions, such as the EU AI Act, while in the US, the frameworks aren't being publicly disclosed and are not as stringent.

TOGETHER WITH IBM

It’s time to modernize. Do you know where your data is?

Most enterprise AI projects eventually run into the same conundrum: the most useful data is often the hardest to reach. For many companies, critical business knowledge sits inside legacy applications, on-premises databases and document stores that were never designed for AI.

Some systems have no modern APIs, while others hold years of operational context but expose it only through old screens, stored procedures or manual exports.

Bob gives developers the leverage to extend that pattern across legacy systems, data sources and industries by analyzing systems, inspecting schemas, generating ingestion code, creating tests and building MCP servers that connect enterprise data to AI systems.

RESEARCH

Why Hugging Face, Ai2 partnered to open up AI

The debate around open-source AI is reaching a fever pitch. Now, two of open-source's most prominent supporters want to make it easier to use.  

On Thursday, the Allen Institute for AI, or Ai2, announced a deepened partnership with model hosting platform Hugging Face to expand access to "fully open AI" for users. To start, Hugging Face will roughly triple Ai2's storage for models. Additionally, Ai2's traffic will no longer be subjected to Hugging Face's standard rate limits, allowing for its largest datasets and multi-checkpoint models to download at full throughput. 

As it stands, Ai2's models have been downloaded more than 50 million times from the Hugging Face Hub since 2024, and currently sits as the most active model provider on the platform. Peter Clark, interim CEO of Ai2, told The Deep View in an exclusive interview that the organization was reaching capacity with what it was able to provide on Hugging Face prior to entering the partnership. 

As the nonprofit continues to publish open-source AI that goes beyond just open weights, including things like training data, checkpoints and evaluations, adding more infrastructure from Hugging Face will allow it to keep pace as its portfolio grows. 

"That's a key part of openness: not just doing the open research, but having the appropriate infrastructure to drive it," said Clark. "This expanded partnership … [will] allow us to put more work into the open. People will be able to download the models faster, and that's all in service of open science." 

Clem Delangue, CEO of Hugging Face, told The Deep View the goal of the partnership is to help return the AI industry to the state it was six years ago: "extremely open, transparent and collaborative," he said. 

"Almost the default was to share the models openly, to discuss them, to share the learning," Delangue said. "That's what led, in my opinion, to the acceleration of the progress of the field."

In the past several years, the industry has largely moved away from open-source in the US, leaning towards closed, commercial models that are hidden behind closed doors and sold through APIs, Delangue said. This, however, has created a concentration of capabilities in the hands of those proprietary providers. That concentration extends beyond just wealth and revenue, Delangue said, allowing a small pocket of companies to centralize influence and power. 

"There's a clear path where you end up with a few companies dominating the fields to a level that really never existed before," said Delangue. "We are starting to see that these companies have massive, massive power. If nothing changes, if we don't have more open resources, we could end up in a very different world than what we've seen in the past."

The partnership comes at a particularly poignant moment for open models, with leading firms including Nvidia, Microsoft, OpenAI and Google signing a letter last week urging US policymakers against blanket bans on open models. Additionally, the centralization of power in AI has become a common topic of discussion among AI leaders, with the likes of OpenAI's Sam Altman and Greg Brockman and Anthropic's Dario Amodei all calling attention to the risks of over-centralization. Investing in a more robust open-source ecosystem in the US may well play a major role in democratizing AI, beyond just giving people free access to a less expensive chatbot. However, access is only half the battle. For open-source to gain more traction, education about the benefits of the tech needs to go hand in hand with making it more accessible. Without education, most people will likely continue using the same platforms they've come to rely on. 

Nat Rubio-Licht

TOGETHER WITH GRANOLA

Be the person who remembers everything.

Some people walk into meetings and recall exactly what was decided last time, the numbers, who promised what. They're not better than you. They just have a better system.

  • Captures your meetings automatically, no bots, no awkward recording prompts

  • Builds a searchable memory of every discussion and decision over time

  • Lets you ask Chat anything and get an answer with citations, pulled from your notes, your team's notes, even notes sent to you privately

With Granola's Briefs, you don't even have to ask. Before you walk into a meeting, Granola tells you who you're meeting and what matters.

You become that person in the room who never loses the thread. Not because you take endless notes, but better ones.

CONSUMER

Why OpenAI needs to curb AI's teen risks

OpenAI is one of the most widely-used AI tools by the average person. That big of a footprint should come with even bigger responsibility. 

On Thursday, OpenAI announced that it's partnering with the American Psychological Association to develop mental health safeguards for young AI users. Through the partnership, OpenAI said in its blog post that it aims to figure out how to support young users during times of distress, as well as navigate where AI should and shouldn't show up in those users' lives. 

"Technology is part of teens’ lives, and our responsibility is to meet that reality with experiences that are safe, age-appropriate, and designed with families in mind," Sara Johansen, head of mental health and well-being product policy at OpenAI, said in a statement. "AI should strengthen—not replace—the real world relationships and care young people rely on." 

The partnership includes several areas of focus: 

  • To support parents and caregivers and provide practical tools for how AI can be used at home, the company will work with the APA to develop "family-facing resources" for healthy AI use and advice on when to intervene. 

  • For mental health practitioners, OpenAI intends to develop resources for clinicians and school psychologists aimed at recognizing AI overreliance and health use patterns. 

  • In an effort to listen to young users, OpenAI and the APA will convene teens, families, clinicians and school psychologists to get a better understanding of how they are using AI and where support systems are falling short. 

OpenAI said the partnership plays into its broader safety work, which has thus far included measures like parental controls, notifying parents of safety concerns, principles regarding minors in its Model Spec, and its age prediction model. 

This partnership comes as an increasing number of teens are trusting AI with their innermost thoughts. A recent report from Hopelab and the Center for Digital Thriving found that teenagers are often more comfortable discussing emotions with AI because they see these models as confidential, neutral third-parties that are available whenever they need them. And another recent study from Pew Research Center found that 12% of US teenagers have used generative AI for emotional support or advice.

It's undeniable that OpenAI's ChatGPT is widely leading among consumers. It's also actively trying to hold onto that winning spot, announcing on Thursday that it is expanding access to GPT-5.6 Luna for free users with unlimited text chats. But with that kind of power comes an immense responsibility to prevent harm from coming to the users that don't have a deep understanding of how AI works, such as teens and young people. Partnering with the APA is a clear sign that it recognizes that responsibility. And given the fact that it has already faced a lawsuit alleging that the popular chatbot is responsible for the death of 16-year-old Adam Raine, the company may be motivated to avoid more damage — legally, reputationally and ethically. 

Nat Rubio-Licht

LINKS

  • Muse Code (beta): Meta's terminal coding agent built for long-horizon software engineering, powered by our new Muse Spark 1.2 model

  • Claude Opus 5 (Max): Now #1 in the Fullstack Code Arena with 1,699 points

  • Dreambeans: Google's experimental mobile app expands to AI Pro subscribers in US

  • Google Flow: Google AI Subscribers get 50 Google Flow credits every day at no charge

  • Adobe for ChatGPT: single unified plugin that works across ChatGPT Work and Codex

GAMES

Which image is real?

Login or Subscribe to participate in polls.

POLL RESULTS

Do you think Google is still a frontrunner in the AI race?

Yes (24%)
Somewhat (31%)
No (39%)
Other (6%)

The Deep View is written by Nat Rubio-Licht, Sabrina Ortiz, Jason Hiner, Faris Kojok and The Deep View crew. Please reply with any feedback.

Thanks for reading today’s edition of The Deep View! We’ll see you in the next one.

“The food was actually being put into something.”


“The window sill looks like my dirty window sill.”


“[This image] is the most realistic, especially the reflection in the window. The window is open and at an angle so you will not get the perfect straight-on mirror image that is in [the other image].”

[This image] perfectly shows each plate, bowl, and piece of toast so that each item is completely identifiable, whereas [the other image] has some of these blocked or only partially showing.”


“Everything looks wrong in [this image]: the holes in the bread, the perfect graininess of what's in the pan, the steam should be more dispersed, and the right hand is too blurry for the focus.”

If you want to get in front of an audience of 750,000+ developers, business leaders and tech enthusiasts, get in touch with us here.