READ. SCROLL. LISTEN.

Original briefings. Zero spin.

Every story is an original briefing written from 60+ sources across the spectrum — sources linked so you can verify it yourself.

← Back to headlines

Meta Pauses Mandatory Employee-Tracking Program After Internal Data Exposure Covers 45,000 Database Tables

Meta Pauses Mandatory Employee-Tracking Program After Internal Data Exposure Covers 45,000 Database Tables
Meta's Model Capability Initiative, which logged keystrokes, mouse movements, and screen content from US employees' laptops, was paused Monday after a misconfiguration exposed that data to anyone inside the company. The incident hit 45,000 database tables and included private conversations, performance records, and transcriptions. Meta's own CTO acknowledged the implementation fell short of its stated privacy standards.

What Got Exposed

Meta's internal security team issued a notice Monday stating that employee data across 45,000 hive tables had been left accessible to anyone within the company, according to documents viewed by Wired. The exposed data included "full prompts and transcriptions, private conversations, people and performance data," Wired reported.

The incident was classified as a SEV 2 on Meta's internal severity scale of 0 to 5, with 0 being the most severe, according to Business Insider. That puts it in the serious-but-not-catastrophic tier, though for a dataset built from employee keystrokes and screen captures, the content itself is what matters.

Meta spokesperson Tracy Clayton confirmed both the investigation and the pause in a statement given to Wired: "We have carefully designed this program with privacy safeguards and while we have no indication at this time that any data was improperly accessed by Meta employees, we're pausing it while we investigate."

What MCI Actually Does

Meta launched the Model Capability Initiative in April 2026, rolling it out to US employees with mandatory participation for most staff. The tool collects mouse movements, click locations, keystrokes, and screen content from corporate laptops, according to Wired's reporting from employees who reviewed the program documentation.

The stated purpose: training AI models to operate computer software the way humans do. Meta executives argued that employees were the ideal training examples for this kind of AI.

Employees disagreed. A petition opposing MCI gathered more than 1,500 signatories, according to the letsdatascience summary citing Quartz. Internal pressure eventually led Meta to add limited opt-out options and a 30-minute local pause feature, changes circulated by executive Stephane Kasriel per that same report. But for most staff, participation remained mandatory.

The CTO's Acknowledgment

Meta CTO Andrew Bosworth posted internally on Monday acknowledging that MCI's implementation failed to meet the standards its own privacy review had established. "Here we had misconfigured ACLs [access control lists] and we need to understand how that happened, track down every data access and understand it," Bosworth wrote, according to Wired.

Bosworth didn't dispute the facts or deflect blame onto outside actors. He named the technical cause: misconfigured access control lists. The incident has since been marked as closed internally, meaning it was likely technically resolved, though Wired noted that employees were still asking whether everyone whose data was potentially exposed would be briefed.

One employee's internal post captured the mood accurately: a meme from The Office featuring a sign reading "0 days since our last nonsense," per Wired.

The Stronger Argument for MCI

Before writing this off entirely, the strongest good-faith case for what Meta was attempting deserves a fair hearing. Training AI agents to operate software like humans do requires realistic human interaction data. Synthetic data doesn't replicate how people actually type, pause, correct mistakes, navigate menus, or manage multiple windows simultaneously. Employees using corporate equipment on company time represent a practical, logistically clean source for that signal. Several major technology companies are pursuing similar strategies for computer-use AI agents.

Meta also says no evidence of malicious internal access exists, and the incident was resolved. From a pure data-governance standpoint, a misconfigured access control list is a fixable technical error, not evidence that the program itself was inherently unworkable.

Where That Argument Runs Out

The problem is that employees raised these exact risks before the exposure happened. A former Meta employee who had been active in opposing MCI told Wired: "When workers raised concerns, leadership doubled down and failed to acknowledge the risks workers raised about the safety and privacy of worker and customer data."

The underlying claim stands on its own: employees predicted a data exposure risk, leadership dismissed it, and then a data exposure happened.

This is also not an isolated incident for Meta's security posture. Business Insider reported that last month a flaw in Meta's AI chatbot allowed people to hijack Instagram accounts, and a rogue AI agent caused a separate severe incident in March, per The Information.

The Notification Question

Wired reported that Meta informed the outlet about the program pause before it announced the pause to its own employees. Two people familiar with the matter confirmed that sequence to Wired.

Meta has not publicly addressed that sequencing. It's an unresolved question whether affected employees have received or will receive individual notification about what specifically from their activity logs was accessible and for how long.

Bosworth said findings from the incident would be shared, but as of Monday the scope of that disclosure — who gets told what, and when — had not been defined publicly.

Sources used for this briefing

This briefing was written by UBH's AI agent — these are the reporting inputs it draws on, linked so you can verify.

center-left
WiredMeta Pauses Employee-Tracking Program Following Internal Data Leak
center-left
WiredMeta Exposed Data Internally From Its Controversial Employee-Tracking Program
center-left
Business InsiderMeta Halts an AI Training Program After Data Leak Sparks Employee Ire - Business Insider
unknown
letsdatascienceMeta pauses employee keystroke AI training program - Let's Data Science