Meta paused its internal Model Capability Initiative (MCI) program on June 22, which tracked employee mouse movements, clicks, and keystrokes to train AI models [1, 2, 3, 4, 5, 6, 7]. The program, launched in April 2026, was initially mandatory for many US-based employees as part of Meta’s AI development efforts [1, 2, 3, 4, 5, 7].
An internal security incident exposed sensitive MCI data to all Meta employees. The leaked data included full prompts and transcriptions, private conversations, people and performance data, and DSS sensitivity ratings [1, 2, 3, 8, 5, 6, 7]. Around 45,000 internal data tables were reportedly exposed in the breach [8]. The data was stored unencrypted, and the MCI collected more data than originally disclosed, raising privacy and security concerns [1, 3, 7].
More than 1,600 Meta employees signed an internal petition opposing MCI, citing privacy, consent, and trust issues [2, 8, 4]. Employees expressed frustration in internal forums; one said, “I have accessed both personal tax and medical information through my work computer, as have many thousands of employees. We were told this data would be protected” [1]. Another employee added, “I am incensed. I don't see any evidence of malicious access, but the fact that this data wasn't locked down as originally promised is super frustrating” [5].
Meta spokesperson Tracy Clayton said, "We have carefully designed this program with privacy safeguards and while we have no indication at this time that any data was improperly accessed by Meta employees, we’re pausing it while we investigate" [1]. The pause is being rolled out gradually; the program was still recording data on the afternoon of June 22 [1, 3, 7].
An employee filed a high-priority security incident report triggering the investigation and pause of MCI [1, 3, 5, 7]. Meta CTO Andrew Bosworth acknowledged that “The tracking program’s implementation had fallen short of the standards outlined in its privacy review and that findings from the incident would be shared” [8].
Meta executives, including Mark Zuckerberg, defended MCI as key for AI training, saying the skills of Meta engineers would significantly improve model capabilities [2]. The company is investing heavily in AI this year, planning up to $145 billion in capital expenditures, with MCI as part of that strategy [2].
The incident follows reports in May that MCI collected more data than described and stored it unencrypted, raising early concerns [1, 3]. Internal forums saw mounting frustration and criticism of the program and breach [8, 4, 5]. Meta continues to investigate and has not announced when MCI might restart or end.