Meta Pauses Employee Tracking Program After Internal Data Leak
Meta has suspended its controversial employee-tracking program after an internal security breach exposed sensitive data — including keystrokes and mouse movements — to other workers inside the company. The program, called the Model Compatibility Initiative (MCI), had drawn heavy criticism from staff since its rollout.
What is the Model Compatibility Initiative (MCI)?
Launched in April for U.S.-based employees, the MCI was designed to collect detailed usage data to help train advanced AI systems. According to internal documents and employee petitions, the tool gathered granular behavioral signals intended to teach AI how people interact with software.
Data Collected by MCI
- Mouse movements and exact click positions
- Keystroke data and typing patterns
- Screen content and other computer inputs
Meta leaders argued the data was necessary for improving AI navigation of complex software, but many employees raised concerns about privacy, data security, and worker rights.
How the Internal Security Breach Unfolded
The issue came to light when a Meta engineer posted a security notice revealing that databases containing MCI-collected information were broadly accessible within the company. That disclosure confirmed employees’ fears that centralized, sensitive datasets created a serious internal security risk.
A former employee active in the protests called the situation “a mess,” saying leadership had “doubled down” on the program despite repeated warnings about protecting worker and customer data. Critics say the breach underscored lapses in access controls and data governance.
Leadership Response and Timeline
Meta vice president Stephane Kasriel, who oversees AI research, told staff the security issue was discovered on June 18. An initial mitigation was attempted within hours but proved insufficient, requiring additional lockdowns of the affected data.
Kasriel acknowledged that “some MCI-derived data” was accessible to more people than intended, though the company has not disclosed the full scope of the exposure. In response to internal outcry, Meta paused the MCI program indefinitely while it investigates and shored up protections.
Implications for Privacy, AI Training, and Workplace Surveillance
The pause highlights the tension between tech companies’ demand for large datasets to train AI and employees’ expectations of privacy. Key implications include:
- Employee trust: Broad internal access to sensitive tracking data can undermine worker confidence and morale.
- Data governance: The incident underscores the need for stronger access controls and transparent policies when collecting behavioral data.
- AI ethics: Organizations must balance AI training needs against privacy rights and legal risks.
What’s Next for MCI?
Meta says it will re-enable MCI only when it is confident that data protection controls are effective. Company statements also suggested that enough information might already have been collected to assess whether MCI is worth continuing, leaving the tool’s future uncertain.
What to Watch
- Updates from Meta on the scope of the exposed data and corrective measures.
- Potential changes to internal data access policies or new safeguards for employee-tracking tools.
- Regulatory or legal scrutiny if the investigation reveals broader compliance issues.
This episode underscores growing scrutiny of workplace surveillance and how companies collect and protect employee data while developing AI.
