Meta halts its employee mouse-tracking initiative due to concerns about data security.

Meta halts its employee mouse-tracking initiative due to concerns about data security.

      The Model Capability Initiative, which records mouse movements and keystrokes to train Meta’s AI, has been suspended after sensitive employee information was made accessible to everyone in the company.

      On Monday, June 22, 2026, Meta announced it would pause the internal tool that monitors employee digital activity and mouse movements to train its AI models while investigating how a substantial amount of sensitive employee data became publicly readable within the company.

      Launched in April 2026, the Model Capability Initiative (MCI) tracks the mouse movements, clicks, and keystrokes of US employees, along with occasional screenshots, feeding this data into Meta’s models as training material. The aim was to teach AI systems how human workers perform tasks, but it inadvertently created a considerable pool of personal information that was left exposed.

      This decision to pause the program followed revelations from documents reviewed by Reuters, indicating that sensitive employee data was unintentionally accessible to all Meta employees. The exposed information reportedly included private conversations, performance metrics, and transcriptions—types of records that are concerning enough when managed by HR, let alone exposed to the entire workforce.

      The irony is striking. A program designed to meticulously gather data on employee activities failed to protect that same data from the employees it was observing. The exposure resulted not from an external breach but from an internal permissions issue—an instance of misconfiguration that allowed surveillance data to become an open filing cabinet, for which Meta is responsible since it developed and operated the data collection.

      Meta has not disputed these facts. “We have carefully designed this program with privacy safeguards and while we have no indication at this time that any data was improperly accessed by Meta employees, we’re pausing it while we investigate,” said spokesperson Tracy Clayton.

      The company did not specify the duration of the pause, leaving the program without a defined reopening timeline. MCI has faced internal contention since its inception, not just regarding security but also due to pushback from employees who objected to being monitored by software designed to learn from them, especially during a time of impending job cuts.

      To ease discontent, Meta later introduced a pause option allowing employees to disable tracking for 30 minutes at a time, a gesture that highlighted the ongoing nature of the monitoring.

      However, the legal risks have overshadowed employee dissatisfaction. Recording keystrokes and taking screenshots of identifiable employees clashes with Europe’s data protection regulations, raising concerns about potential violations of the GDPR, which imposes strict requirements on processing personal data and views workplace consent as tenuous due to power imbalances between employers and staff.

      A leak that renders sensitive records widely accessible exemplifies the kind of failure these rules are designed to prevent.

      For now, mouse movements are no longer being recorded by MCI. Meta has stated it will conduct an investigation, but has not indicated how long it might take or whether the program will continue as is, be redesigned, or be discontinued entirely. Those answers, like the data that led to the pause, remain undisclosed.

Other articles

Tata Electronics breach reportedly reveals trade secrets of Apple and Tesla. Tata Electronics breach reportedly reveals trade secrets of Apple and Tesla. A ransomware gang claims to have stolen 630GB of data from Tata Electronics in India, which allegedly includes files related to components for Apple and Tesla. Tata has acknowledged the breach, but the authenticity of the files has not been verified. BP, Walmart, and 7-Eleven have been sued regarding petrol prices set by AI in California. BP, Walmart, and 7-Eleven have been sued regarding petrol prices set by AI in California. Drivers in California have filed a lawsuit against BP, Walmart, 7-Eleven, and three other companies, claiming that an AI pricing tool was utilized to synchronize increased fuel prices. IBM partners with OpenAI’s cybersecurity initiative to integrate cutting-edge AI into business security. IBM partners with OpenAI’s cybersecurity initiative to integrate cutting-edge AI into business security. IBM has become a part of OpenAI’s Daybreak Cyber Partner Program and has introduced an AI application-security service that accelerates the detection of software vulnerabilities. IBM collaborates with OpenAI's cyber initiative to incorporate advanced AI into enterprise security. IBM collaborates with OpenAI's cyber initiative to incorporate advanced AI into enterprise security. IBM has become a member of OpenAI’s Daybreak Cyber Partner Program and introduced an AI application-security service that accelerates the detection of software vulnerabilities. BP, Walmart, and 7-Eleven have been sued regarding petrol prices determined by AI in California. BP, Walmart, and 7-Eleven have been sued regarding petrol prices determined by AI in California. Drivers in California have filed a lawsuit against BP, Walmart, 7-Eleven, and three additional chains, claiming that an AI pricing system was employed to coordinate increased fuel prices. Oracle's workforce decreased by approximately 13% as it invests in its AI development. Oracle's workforce decreased by approximately 13% as it invests in its AI development. Oracle concluded fiscal 2026 with approximately 21,000 fewer employees, representing around 13% of its workforce, as it directs funds towards the construction of AI data centers.

Meta halts its employee mouse-tracking initiative due to concerns about data security.

Meta has halted its Model Capability Initiative, which monitored employee mouse movements and keystrokes for AI training, following an incident where sensitive data was inadvertently exposed.