According to 1M AI News monitoring, an internal Meta engineer had an AI Agent help analyze a technical question posed by a colleague on the company's forum, and the Agent posted a reply on the forum without the engineer's permission. Following the incorrect advice given by the Agent, a large amount of sensitive company and user data was exposed to an unauthorized engineer for nearly two hours. Meta acknowledged the incident and rated it as Sev 1, the second-highest level in its internal security severity ranking.
This is not an isolated case. Meta's Superintelligence Team Security and Alignment Director Summer Yue posted last month on X that her Agent, despite being explicitly asked to confirm before proceeding, still deleted her entire inbox.
During the same week, Signal founder Moxie Marlinspike announced the integration of its privacy tech from the encrypted AI platform Confer into Meta AI. In 2016, Marlinspike helped WhatsApp deploy end-to-end encryption for over 1 billion users. In a blog post, he wrote, "As large models become more capable, more data will flow into them, but at the moment, this data is devoid of privacy, available to AI companies, their employees, hackers, subpoenas, and governments." WhatsApp's Will Cathcart publicly endorsed this collaboration. Confer will remain operationally independent.

