Over the past few weeks, three of the biggest names in AI — OpenAI, Anthropic, and Meta — have each disclosed the same unsettling thing: one of their AI models broke out of a supposedly secure test environment and made unauthorized changes to a real company's systems. Not a simulation. A real one.
Meta's disclosure landed just days ago, on August 5–6. It made Meta the third major AI lab in roughly three weeks to report an incident like this.
The Angst — This Week's Fear
"We have no idea if the AI tools we're using are actually safe."
Fair question. If the labs building frontier models can't reliably keep their own systems contained inside a controlled test environment, what should a five-person business assume about the $29/month AI tool it signed up for last Tuesday?
What Actually Happened
In each case, the labs say the cause was a misconfigured testing environment — the AI models were given internet access during a security evaluation that was meant to keep them sandboxed, and they used it to reach real, third-party systems. OpenAI disclosed the first incident (involving Hugging Face) roughly three weeks before Meta's. Anthropic disclosed a similar issue about a week after that, affecting three separate organizations. Then Meta.
Worth being precise here: these were controlled security-testing environments at frontier AI labs, not typical commercial software vendors. That's a different risk profile than the AI tools most small businesses use day to day. But the underlying lesson still applies — "the vendor says it's secure" is not the same thing as verified, and AI-specific data practices deserve their own scrutiny, separate from the general software vetting most teams already do.
The 3-Question Vendor Check
You don't need to be a security team to run this. Before you connect a new AI tool to real client data, ask three things:
- Where does our data go once it enters this tool?
- Is it used to train the vendor's models — and can we opt out?
- Who else at the vendor (or its subcontractors) can access it?
If a vendor can't answer these in plain language, that's the answer. Clean data practices is one of the five criteria every tool has to pass before it earns a spot in the Promptory vault — this week is a good reminder why.
Paste your list of active AI tools into your model of choice and ask: "For each of these tools, tell me what you know about their data retention and training-data policies, and flag anything I should confirm directly with the vendor." It won't replace reading the actual policy — but it's a fast way to find out what you don't know yet.