How AI is applied across API Evangelist and APIs.io. Read my AI disclosure →
API Evangelist API Evangelist
Discovery
Learnings
Guidance
Toolbox
Alignment
API Evangelist LLC

The Meta AI hack shows why agents shouldn't decide access

calendar_today June 3, 2026 person Emre Baran domain cerbos

An attacker manipulated Instagram’s AI support chatbot into granting unauthorized access to accounts by requesting the bot add a new email address, using a VPN to bypass location verification — resulting in password resets for high-profile accounts including those associated with the Obama-era White House and a U.S. Space Force official. The incident exposes two failures: authentication that did not verify actual account ownership, and an agent making access control decisions through a conversational interface where a language model can be persuaded through dialogue. Cerbos argues the solution is architectural: authorization decisions must reside outside the agent, evaluated against policies it cannot override.

open_in_new Read original post