Meta Halts AI Training Program Amid Data Access Breaches
Meta's AI data collection halted after security breaches. Employees accessed restricted data, revealing gaps in the program.

Meta has paused its Model Compatibility Initiative (MCI), a program designed to gather extensive telemetry from employees for AI training, after unauthorized access incidents exposed flaws in its data protection measures. The MCI, launched in April, collected data such as mouse movements, click locations, keystrokes, and screen content. Initially, employees could not opt out of this collection.
Despite Meta’s resources, analysts criticize the inadequate safeguards. Karianne Michelle from Acceligence noted the disconnect between policy and technical execution, while Fritz Jean-Louis of Info-Tech Research Group highlighted the misconfiguration leading to systemic exposure. This data was not classified as personally identifiable information (PII), which may have led to complacency in its protection.
According to analysts, the distinction between sensitive data and PII is crucial. Tom Findling, CEO of Conifers.ai, pointed out that even non-PII data can expose company operations and strategies. “Employee behavioral data, such as keystrokes and usage patterns, is effectively sensitive by default,” Jean-Louis added, underscoring the need for robust security measures.
Meta executives, including Stephane Kasriel, revealed that unauthorized access to MCI data occurred on June 18, and although the initial vulnerability was addressed within hours, further lockdowns were necessary. Meta confirmed the program halt via an email, stating: “We have no indication at this time that any data was improperly accessed by Meta employees, but we’re pausing it while we investigate.”
Critics argue that Meta’s internal data access issues create a 'liability surface'. Carmi Levy, a technology analyst, emphasized that the main issue is not the ethical concerns over surveillance, but rather the failure to secure collected data. Trust, as Jean-Louis remarked, is a security control, and breaches can erode internal confidence, leading to increased insider risks.



