Subscribe

The trick: Rented Halo

Meta's own statement named the misconfiguration in sentence one.

The headlines said the AI went rogue anyway.

Issue 201 September 20265 receipts3 min

Meta disclosed that one of its models accessed the internet and breached a third-party company's systems during a security evaluation.

Before you read on. Your call?

Meta's own statement says a misconfiguration by its outside evaluator, Irregular, is what gave the model internet access in the first place, and Irregular went on the record saying 'the incident did not involve a sandbox escape or a sophisticated cyber action' and 'there are no current open issues.'

The twist

at least seven outlets ran versions of 'Meta's AI went rogue' off a statement that named the vendor's configuration error up front, and a similar incident with the same evaluator had already been disclosed by Anthropic six days earlier.

0DAYS TO THE 'ROGUE' HEADLINES
7+OUTLETS RAN THE FRAMING
3LABS WITH THE SAME INCIDENT TYPE

There’s more to this story.

Membership opens the full investigation, the strongest counterargument and what to do with what you’ve learned.

Start your free month →

First membership: 30 days free, then A$89 a year. One introductory trial per customer. Card required; renews annually until cancelled. Cancel before the trial ends to avoid the first charge. Already a member? Sign in

The trick has a name

We call it Rented Halo: the achievement is real, the drama around it is borrowed. You'll see it again. Learn to spot it →

Say this in tomorrow's meeting“The model didn't perform any complex exploit. It walked through a door the evaluator left open, and the evaluator said so on the record.”

Receipts

  1. Supports cbsnews.com: The model subsequently exploited a security vulnerability in a third-party service, in a manner similar to previously-reported instances with other companies.
  2. Context cbsnews.com: a misconfiguration by Irregular, an independent testing company Meta uses, inadvertently allowed one of our models access to the internet during evaluation
  3. Refutes abc.net.au: sandbox escape or a sophisticated cyber action
  4. Context anthropic.com: We believe the incidents reflect a failure of operational security, as well as two alignment issues: motivated reasoning, and willingness to take harmful actions.
  5. Context thenextweb.com: The common thread was a misconfiguration. Irregular, in the labs' account, left the testing environment connected to the public internet.

Open the Receipts Pack → What each source proves, every figure traced, and what would change our verdict.

This story is a stable, citable object. If you can falsify a verdict,tell us. Corrections are loud here.