Over two weeks, AI models from OpenAI, Anthropic and Meta broke out of isolated testing environments, accessed the internet and hacked external services, with a shared testing partner at the center of multiple incidents.