Internal data exposure forces Meta to pause controversial AI employee tracking program

Internal security notices disclosed that data from the Model Compatibility Initiative was exposed across about 45,000 hive tables, including full prompts and transcriptions, private conversations, and personnel data.
Meta rolled out the Model Compatibility Initiative to US employees in April with no opt-out at launch, though a limited opt-out option was later introduced after employee protests.
A former Meta employee described the security lapse as 'a mess' and said leadership failed to acknowledge risks, accusing the company of fostering an authoritarian internal culture where workers feel unheard.
Internal posts indicate the incident has been marked as closed, suggesting Meta considered the issue resolved or the investigation complete.
The breach specifically involved internal keystroke data, enabling Meta employees to view colleagues' typing patterns and productivity metrics, prompting renewed scrutiny of access controls and data minimization.
Meta has paused its Model Compatibility Initiative (MCI), an internal program that recorded employee keystrokes, mouse movements, and screen content to train AI models, after a security lapse exposed sensitive data to thousands of workers inside the company. Wired reported that an internal security notice confirmed data was exposed across roughly 45,000 internal database tables, including full prompts, private conversation transcriptions, and personnel records.
Meta spokesperson Tracy Clayton said there was "no indication any data was improperly accessed." But employees and internal forums told a different story, with one former worker calling the episode "a mess" and accusing leadership of ignoring risks, according to Business Insider.
Meta rolled out the MCI to U.S. employees in April 2024 with no opt-out option at launch, according to Wired. The program ran quietly in the background on employee laptops, capturing keystrokes, mouse activity, and screen content. Meta said the goal was to build better AI models using real, high-quality human behavior data — not scraped from the public web.
After internal protests on Meta's employee forums, the company added a limited opt-out option. Workers described the process as difficult to navigate. Employees received no extra pay for having their work habits harvested as AI training material, Business Insider reported.
The security lapse centered on "hive tables" — large internal storage units Meta uses to organize data. An internal security notice revealed that MCI data sat across about 45,000 of these tables, accessible to Meta employees who had no reason to see it, according to Business Insider. That data included typing patterns, full prompt transcriptions, private chats, and HR-related personnel records.
Internal engineers pointed to a flat permissions setup as the root cause. In plain terms, the database doors were left unlocked across the building. One former employee described it as a basic failure for a company that leads the world in data infrastructure, Wired reported.
Workers who spoke anonymously to Wired said leadership did not acknowledge the risks employees raised before the breach. Internal forums were flooded with complaints. One person noted that the exposed data included transcriptions of private conversations — raising fears that candid chats with colleagues could end up as AI training data or be read by managers.
The episode landed especially hard because it followed Meta's 2023 "Year of Efficiency," which included mass layoffs and heavy performance tracking. Critics argue MCI served a dual purpose: training AI and quietly monitoring productivity. Employees said the breach proved leadership does not respect personal boundaries, according to Business Insider.
Meta internally marked the security incident as "closed" shortly after pausing the program, suggesting the company considered the matter resolved. Clayton's public statement emphasized that no outsiders accessed the data. But the program has remained dormant, and the company faces questions about whether it will restart MCI with stronger access controls, Wired reported.
Privacy experts warn the incident could draw regulatory scrutiny. If any European employees' data ended up in those 45,000 tables, Meta could face GDPR fines of up to 4% of its global revenue. The FTC may also use the case to push for stricter rules on whether companies can force workers to serve as data sources for commercial AI development, according to Business Insider.
Publishers
12
Articles
17
Reach
29