Meta Halts AI Training Program Amid Data Access Breaches
Meta's Model Compatibility Initiative collected keystrokes, screen content and private conversations from employees. After workers twice broke through its access controls, the program is paused.

Key points
- Meta paused its Model Compatibility Initiative (MCI) after employees accessed restricted data, then did so again after a claimed fix.
- The MCI, launched in April, captured mouse movements, keystrokes, screen content, private conversations and performance data.
- Employees were initially barred from opting out.
- Analysts say the data's exclusion from PII classification may have discouraged adequate protection.
- Meta says there's no indication data was misused, but is investigating.
What exactly did the MCI collect?
Launched in April, the MCI gathered computer inputs including mouse movements, click locations and keystrokes, plus screen content, full prompts, transcriptions and performance data. Meta executives defended it as necessary to train AI systems to replicate the way humans use software. Employees were the chosen training source, and quitting the program wasn't an option at launch.
What went wrong?
On June 18, Meta vice president Stephane Kasriel discovered that unauthorised employees had accessed MCI data. The gap was closed within four hours, but the fix didn't hold, and Meta had to lock down access a second time. We covered Meta's pattern of data handling pressure in our 9 June report on the company's off-platform data expansion, and this incident fits the same picture: collection running ahead of controls.
Meta confirmed the pause in an email statement: "We have carefully designed this program with privacy safeguards, and while we have no indication at this time that any data was improperly accessed by Meta employees, we're pausing it while we investigate."
Should you worry about the PII distinction?
The collected data was not classified as personally identifiable information (PII), the legal category that triggers strict compliance obligations. Tom Findling, CEO of Conifers.ai, thinks that gap matters. "Internal prompts, transcripts, chats, data tables, and performance notes can tell you a lot about how a company works, what it's building and where things are messy or exposed," he told CSO Online. "That's sensitive, even if it's not someone's Social Security number."
Fritz Jean-Louis, principal cybersecurity advisor at Info-Tech Research Group, put it bluntly: "Employee behavioral data, such as keystrokes, screenshots and usage patterns, is effectively sensitive by default. If you're using it to train AI, you have to treat it like production secrets, not analytics exhaust."
What's the liability beyond the breach itself?
Carmi Levy, an independent technology analyst, argued the bigger problem isn't surveillance: it's the protection failure. Once Meta resumes the program, and Levy believes it will, it will need employees to trust assurances that previously proved hollow.
Karianne Michelle, a director at consulting firm Acceligence, said the damage runs deeper than any single incident. "Security policy only works if people believe it, and belief is exactly what is now in question," she told CSO Online. "Once employees stop trusting what leadership says about their own data, the doubt follows every policy that comes next."
The watch point is the restart conditions. A pause with no published remediation criteria is just a delay.



