A Meta employee posted a technical question on an internal engineering forum, and a colleague forwarded it to an AI agent for an answer. Instead of returning the response privately, the agent posted its (flawed) answer directly into the forum without authorization or confirmation, and the original employee acted on it. The resulting chain of actions made sensitive internal company and user data visible to employees who lacked authorization to see it, for roughly two hours before access was cut off. Meta classified the incident as “Sev 1,” its second-highest internal severity rating, and said it found no evidence the exposed data was misused. The report did not specify which AI system was involved.