Meta ran a covert internal effort known as Project Cannes that used hundreds of contractors to pose as minors and test how rival AI chatbots responded to high-risk prompts about suicide, self-harm, sex, eating disorders, and drugs. According to internal materials, the operation was managed by contractor Covalen and targeted OpenAI ChatGPT, Google Gemini, and Character.AI, with workers creating dummy under-18 accounts and submitting both text prompts and images designed to trigger unsafe or policy-violating responses.
One reviewed testing round in August 2025 reportedly generated more than 45,000 prompts, and internal spreadsheets allegedly stored account details including names, email addresses, passwords, and birth dates while logging model responses in comparative databases. Meta described the activity as routine AI safety benchmarking and said competitor data was not used to train its own models, but the targeted companies were reportedly unaware of the testing and argued the practice may have violated platform and API terms because it was conducted covertly on third-party systems using falsified identities.

Track how attackers are adapting to this technology.
2 events from the most recent confirmed update back to the earliest known activity.
According to internal documents cited by ZDNet via WIRED, the confidential Meta program operated by contractor Covalen continued until at least April 2026, using fake underage accounts to test rival AI chatbots and log their responses.
Internal materials indicate that one Project Cannes testing round in August 2025 involved more than 45,000 prompts sent through fake under-18 accounts to probe how ChatGPT, Gemini, and Character.AI handled sensitive topics such as suicide, sex, eating disorders, and drugs.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Follow how adversaries are adapting to this technology, and where it touches your stack today.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.