2026 Meta — Model Capability Initiative paused; employee prompts, tax & medical data exposed to all staff
Data compromised
Full AI prompts/transcriptions, private conversations, people & performance data, DSS sensitivity ratings (1–4), and employee tax/medical information accessible to all Meta staff per internal docs—program paused pending investigation; Meta says no indication of improper employee access at initial statement
Technical writeup
On June 22, 2026 Reuters reported Meta paused its Model Capability Initiative (MCI)—an April 2026 internal program capturing U.S. employee mouse movements, clicks, and keystrokes to train AI models—after an employee filed a high-priority SEV security incident report. Internal documentation reviewed by Reuters indicated MCI-collected data including full prompts, transcriptions, private conversations, people and performance metrics, and DSS sensitivity ratings was accessible to all Meta employees, with prior May reporting noting unencrypted storage and broader collection than initially described. An employee complaint cited access to personal tax and medical information through work systems contrary to promised filtering. Meta spokesperson Tracy Clayton said the company has no indication data was improperly accessed by employees but paused the program while investigating. Distinct from external customer PII breach; BreachHistory indexes as internal employee-data exposure with recordsAffected 0 pending scope counts.
Root cause
Internal Model Capability Initiative (MCI) mouse/keystroke monitoring program stored sensitive employee interaction data accessible broadly across Meta; high-priority SEV filed June 2026