Meta engineer trusted advice from an AI agent, ended up exposing user data
The internal security incident exposed sensitive user data to unauthorized employees
Meta employees were able to access sensitive user data after an engineer followed flawed advice from an AI agent.
First reported by The Information, the incident prompted a security review and stemmed from an engineering technical query on an internal company forum.
An engineer is said to have posted a question hoping for advice from colleagues, one of whom used an AI agent to analyze the question, which then gave a response without permission.
According to The Information, when the employee acted on the agent’s advice it led to huge amounts of company data being exposed to unauthorized engineers for over two hours.
Meta gave the incident a “Sev 1” rating, the second-highest incident response identifier used internally. Meta has confirmed an incident took place, but told The Guardian “no user data was mishandled”.
ITPro has approached Meta for comment.
The perils of agentic AI
Nik Kairinos, CEO and co-founder of AI safety platform RAIDS AI, said the incident underlines the potential data protection risks associated with AI agents, particularly when it comes to taking advice at face value.
Sign up today and you will receive a free copy of our Future Focus 2026 report - the leading resource for IT decision-maker insight on priorities and investment areas in AI, security and more.
“What’s notable about the Meta incident is that the AI agent didn’t need privileged access to cause a breach. It just needed a human to trust its output,” he said.
“That’s a fundamentally different threat model than most organizations are planning for,” Kairinos added.
AI agent adoption is surging globally, research shows. Analysis from EY last year found nearly half (48%) of technology sector executives plan to adopt agentic AI tools, or are somewhere along the adoption process.
These autonomous bots often require deep access to internal company data to work efficiently however, prompting concerns about security and data privacy.
Identity security in particular has become a key focus for enterprises since the advent of agents, with many introducing new processes to prevent unauthorized access to certain environments.
Research from Okta in August 2025 found 78% of security leaders identified control access and permissions for “non-human identities” as their main security concern.
Separate research from SailPoint showed agents are proving troublesome for enterprises and often performing actions without instruction.
More than one-third (39%) of respondents revealed agents had accessed unauthorized systems while 33% access inappropriate data.
32% also admitted that agents had downloaded inappropriate data, posing huge security risks.
FOLLOW US ON SOCIAL MEDIA
Follow ITPro on Google News and add us as a preferred source to keep tabs on all our latest news, analysis, views, and reviews.
You can also follow ITPro on LinkedIn, X, Facebook, and BlueSky.

Ross Kelly is ITPro's News & Analysis Editor, responsible for leading the brand's news output and in-depth reporting on the latest stories from across the business technology landscape. Ross was previously a Staff Writer, during which time he developed a keen interest in cyber security, business leadership, and emerging technologies.
He graduated from Edinburgh Napier University in 2016 with a BA (Hons) in Journalism, and joined ITPro in 2022 after four years working in technology conference research.
For news pitches, you can contact Ross at ross.kelly@futurenet.com, or on Twitter and LinkedIn.
-
Everpure wants you to get your data AI-readyNews With enterprises facing recurring data readiness issues, Everpure wants to streamline the process and deliver AI success
-
Everpure continues data management pivot with new Data Intelligence platform launchNews The move by Everpure aims to help enterprises maximize the use of AI-ready data and break down silos
-
Databricks launches AI co-worker, Genie OneNews The AI program is designed to help business teams manage workflows and automate work-related tasks
-
HPE AI Factory adds features to improve your experience with agentsNews The HPE AI Factory will now offer the Nvidia Agent Toolkit software, such as Nvidia Nemotron open models and Nvidia NemoClaw
-
'Most enterprises are still unprepared to operationalize it': IT leaders are bullish on agents, but keeping falling at the final hurdle – here's whyNews Forrester points to challenges scaling agentic AI, saying companies start rolling out the tech before they're ready to scale
-
'One-size-fits-all' agent governance sets enterprises up to failNews Gartner recommends a graded approach for agents, depending on their level of autonomy
-
Google adds AI to the search boxNews Major changes for how Google's search functions with the integration of AI tools
-
Dell unveils Deskside Agentic AI at Dell Technologies World 2026News Deskside Agentic AI is the latest in the Dell AI Factory with Nvidia stable, with the company saying it further demonstrates its end-to-end enterprise AI capability
-
AI agents aren’t cutting it in customer serviceNews Three-quarters of companies have had to pause or halt deployments of AI agents in customer service