Exclusive: Meta Left Sensitive Employee Laptop Data Exposed Internally, Pauses Controversial AI Training Program After Breach

By Paresh Dave and Lauren Goode News
Exclusive: Meta Left Sensitive Employee Laptop Data Exposed Internally, Pauses Controversial AI Training Program After Breach

Exclusive: Meta Left Sensitive Employee Laptop Data Exposed Internally, Pauses Controversial AI Training Program After Breach

Sensitive personal data collected from Meta employees’ work laptops was left accessible to any staff member inside the company, according to an internal security notice reviewed by WIRED and three current Meta employees with direct knowledge of the incident.

The data was gathered as part of a divisive internal initiative to train the company’s artificial intelligence models, and is confirmed to include records of keystrokes, mouse clicks, and full content displayed on the screens of Meta’s U.S.-based employees.

Meta spokesperson Tracy Clayton first confirmed to WIRED that the company was investigating the security lapse. As this report was being prepared for publication, Clayton added that Meta was halting the data collection program indefinitely. “We have carefully designed this program with privacy safeguards, and while we have no indication at this time that any data was improperly accessed by Meta employees, we’re pausing it while we investigate,” Clayton told WIRED.

Monday’s internal security alert noted that “employee data across 45,000 hive tables” had been left unsecured, according to documents viewed by WIRED. The exposed datasets included employee activity such as “full prompts and transcriptions, private conversations, people and performance data,” the documents show.

Many Meta employees quickly framed the security failure as confirmation of the risks they warned of when the company launched the laptop tracking effort in April, under the program name Model Capability Initiative, according to comments shared in internal company forums.

| Got a confidential tip for our reporters? |

|---|

| Are you a current or former Meta employee who wants to share insight into this issue or other internal company matters? We want to hear from you. Contact us securely using a non-work device on Signal: Peard33.24 and ChaoticGoode.12. |

Per internal posts seen by WIRED, employees discussing the incident on Monday raised questions about how Meta’s privacy review process failed to prevent the exposure, and whether every employee whose data was put at risk will be invited to a full briefing on what went wrong.

In a popular internal forum where staffers regularly share jokes and memes, one employee posted a still from The Office of character Jim Halpert holding a sign that reads, “0 days since our last nonsense.”

Unnamed Meta sources, who are not authorized to speak publicly on internal matters, tell WIRED the incident has now been marked as closed internally, meaning the access issue has likely been resolved.

In an internal post responding to employee questions on Monday, which was reviewed by WIRED, Meta Chief Technology Officer Andrew Bosworth acknowledged that the tracking program’s rollout fell short of the standards outlined in its original privacy review, and pledged that full investigation findings would be shared with staff. “Here we had misconfigured ACLs [access control lists] and we need to understand how that happened, track down every data access and understand it,” Bosworth wrote.

Just a couple of months ago, Bosworth told employees concerned about potential data leaks that the tracking program is “tightly controlled” and uses the same protection standards, storage systems, and access controls as other sensitive Meta datasets, according to internal posts reviewed by WIRED.

Last month, more than 1,600 Meta employees signed an internal petition protesting the laptop surveillance effort, warning that “collecting this data introduces both security and regulatory risks for Meta, including the potential for breaches and unauthorized disclosure.” Petitioners also raised concerns about what they viewed as insufficient privacy safeguards from the company. One engineer shared a widely circulated internal note arguing that having their laptop screen scraped for AI training without explicit consent felt like an invasion of privacy and amounted to worker exploitation.

Meta executives have repeatedly defended the data-gathering project, arguing it is necessary to train AI systems to use computer software the way humans do. In leaked audio of a company meeting from last month, Meta CEO Mark Zuckerberg told employees that “AI models learn from watching really smart people do things,” and the “average intelligence of the people who are at this company is significantly higher” than the average contractor hired specifically to produce this kind of training data.

After widespread internal pushback, Meta began offering broader exemptions to the monitoring program earlier this month, including allowing staffers to temporarily turn off surveillance to complete sensitive personal tasks such as scheduling a private appointment, according to two people familiar with the change. Some employees still continue to demand the tracking program be shut down entirely.

Meta faces stricter regulatory scrutiny over data security than most major tech companies. It is bound by a U.S. Federal Trade Commission consent decree that expires in 2040, requiring the company to maintain formal processes to prevent data breaches. But current and former employees have told WIRED that the decree’s requirements are inadequate and outdated for Meta’s current AI work. Meta has also begun shifting some work of reviewing programs and features for privacy and security risks to AI tools, and it was not immediately clear whether AI played any role in the access configuration error that exposed the MCI data.

This security incident is expected to deepen the ongoing morale crisis at Meta, where employees have already been frustrated by years of mass layoffs, turbulent company reorganization, and an all-consuming company-wide push to develop new AI models and features. In March, Meta launched a new Applied AI team and moved roughly 6,500 employees into new roles focused on improving AI models. Some Meta staffers have described the AI-related assignments they received as menial and “soul-crushing.”

Just last week, Bosworth sent a company-wide memo apologizing for Meta’s “atrocious” internal communication around the AI reorganization, and promised improvements including more transparent updates and the return of popular office perks.


Update 6:25 EDT, 6/22/2026: This story was updated to include new clarification from Meta’s spokesperson and additional context around the incident.