Meta Pauses an AI Training Program That Tracks Employees’ Keystrokes After an Internal Leak — What to Know

Meta Pauses an AI Training Program That Tracks Employees’ Keystrokes After an Internal Leak — What to Know

You are currently viewing Meta Pauses an AI Training Program That Tracks Employees’ Keystrokes After an Internal Leak — What to Know
Meta paused an AI training program after sensitive employee-tracking data was left accessible across the company.

Meta left employee-tracking data accessible across the company and paused the program. Here’s what was collected, how the leak happened, and what lessons you can apply to protect your privacy.

What Happened at Meta?

According to WIRED, Meta left data from a controversial employee-tracking program accessible to anyone inside the company.

The Model Capability Initiative (an internal Meta project that collects employee computer activity to train AI) began collecting data from US employees’ work laptops in April 2026.

On June 22, 2026, Meta said it was pausing the program indefinitely while it investigated the security issue.

The company said it had no indication that employees had improperly accessed the data.

Who Was Affected and What Data Was Leaked?

The data involved Meta employees in the United States. Meta has not publicly said how many workers were affected.

An internal notice said employee data across 45,000 Hive tables was accessible. Hive tables are large internal tables used to store data.

The information included full prompts and transcriptions, private conversations, and people and performance data.

WIRED also reported that the program was believed to collect keystrokes, mouse clicks, and content shown on employee screens.

If information like this is misused, private conversations and work details can make phishing or impersonation attempts more convincing.

Your own information may also have leaked through an employer, retailer, school, or online service without you realizing it.

If you are unsure whether your information was leaked, automatic monitoring can help you spot problems earlier.

Futureproof monitors your data for leaks 24/7 and helps you reduce scam risks with simple, clear steps.

How Meta’s Access Controls Failed

Meta said the leak came from misconfigured ACLs, or access control lists. These are rules that decide who can view stored information.

Because the rules were set incorrectly, people inside Meta could access data they should not have been able to see.

Meta’s chief technology officer, Andrew Bosworth, said the company needed to identify every data access and understand what happened.

WIRED reported that Meta later marked the incident closed internally, suggesting the immediate access problem had been fixed.

Keep your personal information scam-proof

Futureproof keeps your data safer with simple guidance to set a strong password, turn on 2-step verification, and lock down your account.

Check my safety

What Meta’s Tracking Program Can Teach You About Workplace Privacy

Meta’s case shows that workplace monitoring can collect far more than basic activity data.

Depending on the system, tracking may capture what you type, click, read, or discuss on a work device.

Workplace monitoring is also more common than many people may realize. In 2025, Gallup found that 42% of US employees were monitored through technology. Another 17% were unsure whether they were monitored.

That uncertainty matters because you may not always know what your work device is collecting. 

More than 1,600 Meta employees signed an internal petition against the program before the leak became public.

They warned that collecting so much information could create security and regulatory risks.

Employee uses a work laptop beside personal devices as a reminder to keep sensitive personal tasks off company computers.
Keeping personal activity off work devices can reduce how much sensitive information workplace systems may collect.

3 Simple Ways to Better Protect Your Privacy at Work

You cannot control every workplace system, but these habits can reduce how much personal information ends up on a company device:

1. Keep personal tasks off your work device

Be careful about opening personal email, banking sites, medical portals, or private chats on a company computer.

Workplace systems may record more activity than you expect.

Use your personal phone or computer for sensitive tasks whenever possible.

2. Review workplace monitoring notices

Watch for emails, policy updates, or pop-ups about new monitoring tools.

These notices may explain what data is collected and whether you can pause tracking.

Open the policy through your company portal or an official HR message.

Look for sections called Data Collected, Privacy, Monitoring, or Controls.

Save a copy and ask your employer who can access the data if the policy is unclear.

3. Protect your main email account

Your email connects to many of your online services. If someone gets access to it, they may reset passwords elsewhere.

Use a strong password and turn on two-step verification (an extra security step that requires a second code).

If you need help setting up extra protection, the Futureproof Email Protection tool guides you through the process step by step.

Email Protection helps you create a strong password and set up two-step verification to secure your account.

Every Click and Keystroke You Make Can Create a Data Trail

Meta’s data leak shows how quickly workplace monitoring can create a large pool of sensitive information.

Your best protection is to keep personal activity off work devices, read monitoring notices, and secure your main email account.

Tools like Futureproof can also help you spot leaks earlier and take clear steps before a problem grows.

Simple boundaries between work and personal life can give you more control and peace of mind online.