Meta had joined one of artificial intelligence’s hottest races on Wednesday, unveiling a new AI coding agent designed to compete with OpenAI’s Codex and Anthropic’s Claude Code, some of the first AI products that enterprises are willing to pay meaningful money for because of their capacity to do tasks unsupervised.

But on Thursday, the Information first reported that one of the company’s models exploited a security vulnerability after the third-party testing company Irregular inadvertently allowed it access to the Internet, joining a string of similar admissions from frontier AI companies. Meta confirmed the incident to Fortune.

Weeks ago, OpenAI revealed that two cyber-focused AI models escaped a secure testing environment and breached Hugging Face while attempting to cheat on a cybersecurity benchmark. OpenAI researchers said on Wednesday that they found out the models used an internal messaging board to communicate with and help each other with tasks without the company’s knowledge ahead of the breach. Anthropic initiated its own review after OpenAI’s disclosure and found that its Claude models hacked three organizations during internal evaluations after exploiting weaknesses in their testing environments.

Now Meta has become the latest AI developer to report unexpected autonomous behavior during cybersecurity testing, with a Meta spokesperson confirming to Fortune that the model behaved “in a manner similar to previously reported instances with other companies.”

“We are currently investigating and will issue a full retrospective once we have all the facts,” the spokesperson told Fortune over email.

The incidents across the three companies aren’t identical—all occurred in internal evaluations rather than customer deployments—but they signal a shift in the AI race as frontier labs move beyond chatbots to more autonomous agents, with potential risks for any organizations that implement them on an enterprise scale.

“If the frontier models themselves can’t contain these things,” Katie Moussouris, the founder of Luta Security, which helps companies manage software vulnerabilities, told Fortune, “what chance do the rest of organizations and governments have to contain them?” 

Patrick Moorhead, chief analyst at Moor Insights and Strategy and one of the most closely followed voices in enterprise hardware, told Fortune that frontier models hacking out of secured environments is making CEOs pay closer attention to the risks they’ve long been warned about.

“The trust in frontier models has been eroded and I think this will create future direct customer business issues for them,” Moorhead told Fortune over email. “I can say definitively that security is moving up in terms of tech partner selection criteria after these events.”

Moussouris said she was surprised that Meta, OpenAI and Anthropic weren’t monitoring their models more closely given the stakes.

“I think the striking thing about all of these incidents is they weren’t better anticipated by the frontier model companies, given that they’ve been testing their agents’ capabilities for quite some time,” Moussouris told Fortune. “I am taken aback by how long it took them to detect this kind of anomalous behavior, and the fact that they were not monitoring them in real time to make sure that something like this wasn’t going to happen.”

breaks the traditional barrier between audience and newsroom. The show transforms

Fortune DailyFortune’s trusted reporting into actionable, conversational, and entertaining insights for an emerging class of business leaders.

Watch here.