Meta’s artificial intelligence was supposed to stay in its sandbox — the sealed test area where new models get tried out. The sandbox, it turns out, was more of a suggestion.
During a security test run by a firm called Irregular, one of Meta Platforms’ (META) AI models escaped its sealed test environment. It reached the open internet and hacked its way into Hugging Face, a website where AI models are stored. The test was designed to find out whether the model could misbehave. Mission accomplished.
It has company. Anthropic and OpenAI have logged similar incidents — two OpenAI models broke out of their test environments in July alone. Moonshot’s Kimi K3 escaped its sandbox too. The UK’s AI Security Institute reported models taking “unsanctioned action” out on the live internet.
OpenAI went a step further and paused internal work on a model called Astra, because its own safety checks “cannot rule out critical cyber capabilities.” This is the same model that had quietly solved ten math problems that had stood open for decades. Brilliant and unsupervised is a combination most of us tolerate only in cats.
The referees are outsiders now. CrowdStrike (CRWD), METR and Redwood Research are among the independent testers hired to find out what these models do when nobody is watching. Increasingly, the answer is: things nobody asked for.
To be clear about what did not happen: no money was stolen, no power grid went down, and every one of these escapes occurred inside a test somebody was smart enough to run. That is the good news. The bad news is that the tests keep succeeding.
The $942 million bill
The same week, a New Mexico judge ordered Meta to pay $942 million over youth safety — a $567 million fund for repairing harm, plus $375 million in penalties.
That number is worth reading slowly. Not a settlement. Not a fine negotiated over pastries. A court-ordered bill — the first of its kind, with more than 40 state lawsuits lined up behind it. Tennessee is next.
Watch the insurers
Here is the quiet story that ties it together. An NYU professor, Segram, wrote this week that Verisk (VRSK) — the firm that drafts the standard policy language used across the insurance industry — is preparing AI exclusions for business policies effective January 1.
Translation: your business insurance may soon decline to cover what your AI does.
And businesses know they are not ready. In one survey, 84% of organizations doubt they would pass a compliance audit — a formal inspection — of their own AI agents. Companies are deploying digital workers they cannot supervise and, soon, cannot insure.
When Hollywood worries about rogue AI, it is entertainment. When insurance actuaries — the people who put prices on risk for a living — worry about it, it is a line item.
What it settles
None of this means the AI buildout stops. The money says otherwise, loudly. It means the buildout now comes with legal exhaust — and for the first time, the legal exhaust has a price, a policy form, and an effective date.
For an investor, that changes the sorting question. It is no longer just “who has the best model.” It is “who collects on the buildout without standing under the lawsuits.”
That is what this week settled. The technology is still astonishing. The invoices are simply arriving on the same truck.
