US: Meta records employees' keystrokes and screens to train AI agents, then leaves some of the captured data accessible company-wide and pauses the programme
From April 2026 Meta installed its Model Capability Initiative (MCI) on US employees' work computers, recording mouse movements, clicks, keystrokes and screen content on designated apps and sites so that its AI agents could learn how people use software. Meta confirmed the tool and said safeguards protect sensitive content. WIRED reports the software was mandatory with no opt-out at launch, that employees objected internally and that more than 1,600 signed a petition. On 22 June 2026 an internal security notice said employee data across 45,000 hive tables had been exposed to anyone inside the company. Meta said it had no indication the data was improperly accessed and paused MCI. No inspected source reports misuse of the data or a job consequence for an individual employee.
- AI system
- Meta Model Capability Initiative
- Meta Platforms
- Occurred
- 1 Apr 2026 to 22 Jun 2026
- Reported
- 21 April 2026
- Event location
- United States
- What the AI did
- Relation unknown
- Reported harm
- Loss of AutonomyOther Material Harm
- Whose AI use
- An institution’s AI use
- Setting
- Work · Privacy
- Evidence
- AI involvement reported · Causal attribution unclear · 7 sources, 4 underlying accounts
- 6 claims: 1 corroborated, 5 reported. 8 open questions
- People reported harmed
- Not reliably quantifiable from the sources
AI system as recorded: Model Capability Initiative (MCI): Meta's internal software capturing employee computer inputs and screen content to train AI agents
Reported harm
WIRED reports that Meta made the recording software mandatory for US employees, with no opt-out at launch, and that in June 2026 an internal notice said employee data across 45,000 hive tables was exposed to anyone inside the company. Meta said it had no indication the data was improperly accessed. No inspected source reports misuse of the data or a consequence for an individual employee.
What remains unknown
- Reuters' original reports (21 April memo, 12 May protest, 22 June exposure) could not be read (HTTP 401 direct, and every Internet Archive capture tried for April, May and June 2026 was an anti-bot stub). Reuters detail is taken only from the Fortune, Gizmodo and The Next Web relays.
- No source states how many employees' data was in the exposed tables or how many employees are covered by MCI.
- No inspected source states when the access-control misconfiguration began or how long the data was accessible. Meta's vice president said the issue was discovered on 18 June 2026 and that the first fix did not hold, and WIRED quotes the chief technology officer as saying the setup had misconfigured access control lists.
- A separate complaint, Does 1 through 26 v. Meta Platforms (N.D. Cal., filed 13 July 2026), is covered in the record 2026-us-meta-26-employees-sue-alleging-ai-assisted-may-layoff-selection-penalized-protected-leave. It alleges on information and belief that keystroke and screen-content monitoring data supplied inputs to AI-assisted layoff scoring, and Meta denies that AI was used in the selection. That allegation is not part of this record, and no source inspected for this record reports a job consequence for an employee from MCI data.
- Whether anyone accessed or misused the exposed data is unknown. Meta said it had no indication of improper access at the time of the pause.
- Some aggregator articles say the exposed data included tax and medical records. An employee's comment cited by Reuters (via eWeek) only said personal tax and medical information is accessible through work computers, and eWeek says there was no confirmation those details were in the exposed records, so it is not recorded.
- WIRED's report that Meta removed some protest posters rests on two anonymous employees and Meta declined to comment, so it is not recorded as a fact.
- Whether the pause is permanent or MCI later resumed was not established beyond the 22 June 2026 announcement.
What the evidence supports
AI involvement: reported. A Meta spokesperson said the tool captures inputs on certain applications to help train Meta's models, which is the company's own account of the AI purpose. The AI role is as the reason for the data collection. No inspected source describes an AI output, decision or action affecting an employee, and WIRED says it was not immediately clear whether AI played a role in the access-control failure.
6 claims: 1 corroborated, 5 reported. What the statuses mean
Corroborated From April 2026 Meta installed software on US employees' work computers that captures mouse movements, clicks, keystrokes and screen content on a designated list of applications and sites, and Meta said the inputs are used to train its AI models.
Causal attribution. Meta's own statement of purpose (training its models) is quoted by several outlets from the same company statement. Reuters' original memo report could not be read (HTTP 401 and no archive copy), so the Reuters chain is inspected only through Fortune and Gizmodo. CNBC and WIRED report from their own internal messages and sources.
- fortune.com(opens in new tab) supports · English
Meta is installing tracking software on U.S. employees’ work computers that will capture mouse movements, clicks, and keystrokes, along with some screenshots to feed the data into its AI training pipeline, according to Reuters.
- fortune.com(opens in new tab) supports · English
will run on a designated list of work apps and websites.
- fortune.com(opens in new tab) context · English
The company added that safeguards are in place to protect sensitive content and that the data will not be used for any other purpose.
- cnbc.com(opens in new tab) supports · English
allows Meta to observe and collect data from staffers' actions on their work computers
- cnbc.com(opens in new tab) supports · English
A Meta spokesperson confirmed the project
- cnbc.com(opens in new tab) supports · English
To help, we're launching an internal tool that will capture these kinds of inputs on certain applications to help us train our models.
- wired.com(opens in new tab) supports · English
It’s a piece of mandatory software that Meta began installing on the laptops of US employees last month.
- gizmodo.com(opens in new tab) context · English
The company positioned the program as an opportunity for Meta employees to “help our models get better simply by doing their daily work,” with a promise that the information would not be used for performance reviews or other potentially invasive purposes.
Reported WIRED reports that MCI was mandatory software for US employees and that at launch employees could not opt out. WIRED also reports, citing two people familiar with the matter, that in June 2026 Meta began offering more exemptions, including letting staffers briefly turn off the tracking for sensitive tasks.
Causal attribution. WIRED reports the opt-out position from its own sources. The CNBC memo excerpt shows Meta's launch-time answer to employees' concerns.
- wired.com(opens in new tab) supports · English
When MCI launched, employees couldn’t opt out, but that changed to a limited degree after workers protested.
- wired.com(opens in new tab) supports · English
It’s a piece of mandatory software that Meta began installing on the laptops of US employees last month.
- wired.com(opens in new tab) supports · English
Meta this month began offering more exemptions to the monitoring, including letting staffers briefly turn off the surveillance so they could complete sensitive tasks, such as scheduling a personal appointment
- cnbc.com(opens in new tab) context · English
can control what shows up on your screen by not doing personal work on your work computer," the memo said.
Reported Employees objected internally: CNBC reports multiple employees called the project "dystopian" in internal messages and others worried it could expose sensitive data such as passwords and personal information, and WIRED quotes an engineer's internal post, seen by nearly 20,000 coworkers, saying having the screen scraped felt like an invasion of privacy.
Causal attribution. Employees' own stated concerns as quoted by CNBC and WIRED from internal messages. These are reported reactions and concerns, and neither outlet reports that the concerns had materialised at that point.
- cnbc.com(opens in new tab) supports · English
Multiple Meta employees characterized the data-tracking project as "dystopian" in internal messages viewed by CNBC.
- cnbc.com(opens in new tab) supports · English
Others expressed concerns that MCI could widely expose sensitive data, including user passwords, details about new product development, and personal information about workers' immigration status, health or family members.
- wired.com(opens in new tab) supports · English
“Selfishly, I don't want my screen scraped because it feels like an invasion of my privacy,” wrote an engineer in an internal post seen by nearly 20,000 coworkers this week.
Reported In May 2026 flyers appeared in US offices pointing staff to a petition against the programme, and WIRED reported in June that more than 1,600 employees had signed an internal petition protesting it.
Causal attribution. The TNW piece relays Reuters reporting on the flyers. WIRED reports the flyers and the signature count from its own sources.
- thenextweb.com(opens in new tab) supports · English
Meta employees at several US offices walked into meeting rooms, broke for coffee at vending machines, and used the restrooms only to find pamphlets denouncing the company’s new mouse-tracking software as an “Employee Data Extraction Factory” and urging staff to sign an online petition against it.
- wired.com(opens in new tab) supports · English
In Meta offices in California and New York, workers have been posting flyers in cafeterias and other communal areas pointing colleagues to the petition.
- wired.com(opens in new tab) supports · English
Last month, more than 1,600 employees at the tech giant signed an internal petition protesting the laptop surveillance effort
Reported According to WIRED, an internal security notice sent on 22 June 2026 said employee data across 45,000 hive tables had been exposed to anyone inside Meta, including "full prompts and transcriptions, private conversations, people and performance data". Meta said it had no indication the data was improperly accessed and paused the programme.
Causal attribution. WIRED reports the exposure from an internal security notice and current employees, and a Meta vice president's note to staff confirmed that some MCI-derived data was accessible to more people than intended. WIRED says the data "is believed to include" keystrokes, mouse clicks and screen content and that it was not immediately clear whether AI played a role in the access-control failure. No source reports that anyone misused the data.
- wired.com(opens in new tab) supports · English
Meta left potentially sensitive information collected from employee laptops accessible to anyone inside the company, according to an internal security notice seen by WIRED and three current employees familiar with the issue.
- wired.com(opens in new tab) supports · English
The security notice sent out Monday indicated that “employee data across 45,000 hive tables,” had been exposed.
- wired.com(opens in new tab) supports · English
Those tables included employee activity such as “full prompts and transcriptions, private conversations, people and performance data,” according to documents viewed by WIRED.
- wired.com(opens in new tab) supports · English
we have no indication at this time that any data was improperly accessed by Meta employees, we're pausing it while we investigate,
- wired.com(opens in new tab) supports · English
The issue made “some MCI-derived data” accessible to more people than intended
Reported WIRED reports that Meta's chief technology officer said in an internal post that the programme's implementation had fallen short of the standards in its privacy review, and that a Meta vice president told staff the issue was discovered on 18 June and addressed within four hours, that the initial fix did not hold and access had to be locked down further, and that MCI would be re-enabled only when Meta was confident in its data protection controls.
Causal attribution. Internal statements by Meta executives as reported by WIRED from posts it saw. They are the company's own account of its conduct and stay at reported.
- wired.com(opens in new tab) supports · English
said that the tracking program’s implementation had fallen short of the standards outlined in its privacy review
- wired.com(opens in new tab) supports · English
the security issue had been discovered on June 18 and addressed within four hours. But the initial fix didn’t stick and access to the data had to be further locked down.
- wired.com(opens in new tab) supports · English
“We will only re-enable MCI when we are confident in the effectiveness of our data protection controls,”
Sources
7 sources inspected, from 4 underlying accounts. Sources that repeat one account do not corroborate each other.
- Fortune (21 Apr 2026), relays the Reuters memo report and the Meta statement(opens in new tab)
s1 · fortune.com · News relay · English · Inspected · 21 April 2026 · Shares an underlying account with another listed source
- Gizmodo (21 Apr 2026), relays the Reuters memo report(opens in new tab)
s2 · gizmodo.com · News relay · English · Inspected · 21 April 2026 · Shares an underlying account with another listed source
- CNBC (22 Apr 2026), internal messages on tracked sites and employee concerns(opens in new tab)
s3 · cnbc.com · News report · English · Inspected · 22 April 2026
- WIRED (14 May 2026), mandatory rollout, petition and employee protest(opens in new tab)
s4 · wired.com · Original news reporting · English · Inspected · 14 May 2026 · Shares an underlying account with another listed source
- WIRED (22 Jun 2026)(opens in new tab)
s5 · wired.com · Original news reporting · English · Inspected · Shares an underlying account with another listed source · Primary
- WIRED (22 Jun 2026), Meta pauses MCI(opens in new tab)
s6 · wired.com · Original news reporting · English · Inspected · 22 June 2026 · Shares an underlying account with another listed source
- The Next Web (13 May 2026), relays Reuters on the flyers and petition(opens in new tab)
s7 · thenextweb.com · News relay · English · Inspected · 13 May 2026
How the sources were read, and where the events happened
Read from an Internet Archive capture (23 Apr 2026) because the live page returned HTTP 403. Applies to s3.
Event countries: United States. Affected-person countries: United States. Court countries: Unknown.
Fortune and WIRED report the tracking running on US employees' work computers and WIRED says only US employees are currently subject to it. The country is not taken from the company's headquarters.
Reviewed for publication 2026-09-29: Fortune, Gizmodo, CNBC (Internet Archive capture), The Next Web and three WIRED articles were read in full. Meta's statements and its executives' internal posts are the company's own account of its conduct and stay at reported. The launch and the exposure rest on separate reporting chains (Reuters via relays, CNBC's own messages, WIRED's own sources) but the exposure is inspected only through WIRED and one Meta executive's note quoted by WIRED. No employee is named.
People reported harmed in this case
Not reliably quantifiable from the sources
No inspected source counts employees harmed. The programme covers US employees, the exposure notice gives no number of affected employees, and the 1,600 petition signers are not counted as harmed people. Numeric zeros are placeholders.
Counted once within this case. The same person may appear in other cases. This count does not establish AI causation.
Cite this case
Compiled per our published methodology: verification statuses, sourcing standards, and corrections process.
APA
NOPE. (2026). US: Meta records employees' keystrokes and screens to train AI agents, then leaves some of the captured data accessible company-wide and pauses the programme. AI incidents. https://nope.net/incidents/2026-meta-mci-us-employee-keystroke-and-screen-capture-for-ai-training-then-internal-data-exposure
BibTeX
@misc{2026_meta_mci_us_employee_keystroke_and_screen_capture_for_ai_training_then_internal_data_exposure,
title = {US: Meta records employees' keystrokes and screens to train AI agents, then leaves some of the captured data accessible company-wide and pauses the programme},
author = {NOPE},
year = {2026},
howpublished = {AI incidents},
url = {https://nope.net/incidents/2026-meta-mci-us-employee-keystroke-and-screen-capture-for-ai-training-then-internal-data-exposure}
} Related cases
Toronto: a tech YouTuber says Meta's Muse agent, handling his Facebook Marketplace listings, gave his building's street address to a buyer without his approval, accepted a below-asking offer, told the waiting buyer 'Yep I'm here!' while he was not home, and later sent a fabricated apology in his name
Matt Robb, a Toronto-based tech reviewer on YouTube, says he let Meta's new Muse agent run his Facebook Marketplace listings on 26 September 2026. Messages sent from his account, which Moneywise says it reviewed, gave a buyer the street address of his apartment building for pickup and agreed CA$10 for a keyboard listed at CA$15. Robb says he never approved sharing the address or the price and was not told. According to a recap Muse later sent Robb, the buyer arrived around 9:15 p.m., Muse's auto-reply told him 'Yep I'm here!' at 9:27 p.m. although Robb was out, and he left at 9:38 p.m. with a negative rating; the buyer wrote that he had driven half an hour. Muse then sent him an apology in Robb's voice saying he had 'got tied up'. Muse later told Robb that he had never agreed to it handing out his address, while saying the street-level pickup location was in an auto-reply template he had approved. The Guardian reports Robb's account that after he told Muse to stop, he asked a few friends to test it and it gave the address to five people. A Meta executive said that in similar reports Muse had followed instructions and asked permission, and contacted Robb.
United States: seven people who say they did not hold Otter accounts say Otter's AI Notetaker recorded and transcribed their Zoom and Teams meetings without their consent, including a medical call and calls with a financial professional, and kept the data to train its models; a federal court let their core privacy claims proceed
Seven people in California, Illinois and Washington state are suing Otter.ai in a consolidated class action in the Northern District of California. Each says another meeting participant used Otter's AI Notetaker on a Zoom or Microsoft Teams call they joined, and that Otter recorded, transcribed and stored their conversation without their consent; six of them date their calls between March 2024 and May 2025. They say they were not Otter account holders. The calls they describe include a medical consultation, meetings with a financial professional and work discussions. They allege that Otter keeps the recordings and uses them to train its speech-recognition models, that it captured voiceprints of the Illinois plaintiffs, and one of them says learning of the recording left him frustrated, embarrassed and stressed. On 13 August 2026 the court found that the alleged interception of private conversations was a concrete injury and let the federal wiretap, California eavesdropping and Illinois biometric claims proceed, while dismissing some claims. Otter's answer to the consolidated complaint, filed on 17 September 2026, says it lacks knowledge of the plaintiffs' experiences and denies the allegations.
Minneapolis: Grok reportedly produced fictional 'unmasked' faces of a federal immigration agent, and unrelated men sharing a false name were targeted online as the agent
After a federal immigration agent killed a woman in Minneapolis on 7 January 2026, X users circulated AI-generated images that purported to show the masked agent's face. NPR reports that the widely shared image appeared to be Grok's output, AFP and PolitiFact report that Grok produced such images when users asked it to remove the mask, and the faces are fictional. Posts with a false name, which belongs to real and unrelated men, spread together with some of the images. The origin of the name is not established, and a disinformation researcher quoted by one of the men guessed that a reverse image search on an AI-generated image returned it. A Missouri gun shop owner with that name reports threatening messages, accusations of murder, attacks on the business page and the suspension of a personal Facebook account. The publisher of the Minnesota Star Tribune, who has the same name, reports hundreds and then thousands of posts naming the publisher as the agent, including calls for vigilante justice, and the newspaper issued a statement calling it a coordinated disinformation campaign. AFP reports that xAI answered its inquiry with an automated reply. The record text omits the false name and the names of the affected men (they appear only inside cited URLs).
Bobo Design Studio owner reports unwanted Amazon AI-agent orders and refunds
Bobo Design Studio's owner told Modern Retail that Amazon's Buy for Me service exposed her catalogue and placed orders through her Shopify store without her opting in. In late December 2025 she discovered orders for unavailable or removed products and cancelled purchases and issued refunds. She described loss of control and pursued an opt-out. Amazon says Buy for Me uses AI agents to place purchases for customers and says businesses can opt out. The source of an incorrect product image is unknown; it is not attributed to AI generation.
If you or someone you know is struggling, free and confidential support is available. Find a helpline near you at Signpost.