Meta confirms internal breach of employee surveillance data used for AI training
The social media giant acknowledges its privacy review standards were not met, though it maintains there is no evidence of external access to the sensitive information collected from US laptops.
Meta has confirmed a significant internal security breach that exposed sensitive data collected from US employees’ laptops, including keystrokes, mouse clicks, and screen content. The information was gathered as part of the Model Capability Initiative, a programme designed to train artificial intelligence models, and was accessible across 45,000 internal database tables. The incident has reignited tensions within the company, where over 1,600 staff members previously petitioned against the surveillance program citing privacy and security risks.
According to an internal security notice seen by WIRED, the exposed tables contained employee activity such as full prompts, transcriptions, private conversations, people data, and performance metrics. Meta spokesperson Tracy Clayton stated that the company has no indication at this time that any data was improperly accessed by Meta employees, adding that the programme was carefully designed with privacy safeguards. Sources familiar with the matter told WIRED the incident has been marked as closed, suggesting the security flaw has been resolved.
Andrew Bosworth, Meta’s chief technology officer, acknowledged in an internal post on Monday that the tracking program’s implementation had fallen short of the standards outlined in its privacy review. He confirmed that findings from the incident would be shared with staff. The breach has drawn sharp criticism on internal forums, with employees questioning how privacy reviews failed to prevent the exposure and whether all affected staff would be invited to a meeting regarding the incident.
The surveillance initiative, which began in April, has been a source of significant internal dissent. One engineer described having their laptop screen scraped for training data without consent as an invasion of privacy and exploitation. Meta executives have defended the project, with CEO Mark Zuckerberg arguing in a leaked audio recording that AI models learn best by watching high-performing employees. However, following widespread protest, Meta has begun offering more exemptions to the monitoring, allowing staff to briefly turn off surveillance for sensitive tasks such as scheduling personal appointments.
This security failure compounds a broader morale crisis at Meta, driven by mass layoffs, a turbulent reorganisation, and an aggressive push to develop AI capabilities. In March, the company created a new Applied AI team, moving approximately 6,500 employees into new roles, some of which staff have described as menial. Bosworth recently apologised for the company’s “atrocious” communication regarding the reorganisation, promising clearer dialogue and the return of some office perks as the company attempts to stabilise its workforce.
