Media & Culture

Meta's MCI employee tracking tool paused after internal data leak

Meta's secretive employee surveillance tool exposed sensitive data to all staff.

Deep Dive

Meta has paused its controversial Model Compatibility Initiative (MCI) program after an internal security lapse exposed potentially sensitive employee data to the broader workforce. The MCI tool, launched in April to all US employees, collects detailed computer inputs like mouse movements, click locations, keystrokes, and screen content. Meta stated the tool was essential for training AI to interact with computer software as humans do, and that employees were the best sources for that training. Workers were initially unable to opt out, though some flexibility was later granted after protests. Internal petitions raised concerns about privacy, security, and personal liberty.

On Monday, a Meta engineer issued a security notice revealing that MCI databases were exposed to all employees. The security issue was initially discovered on June 18 and resolved within four hours, but that fix did not hold, requiring further access restrictions. In an internal memo, Meta vice president Stephane Kasriel announced the pause, stating the company would only re-enable MCI when confident in data protection controls. He noted that Meta had now gathered sufficient data to evaluate the tool's long-term value. Employees expressed frustration in internal forums, with a former activist worker calling the lapse a "mess" and accusing leadership of ignoring earlier warnings. The pause has left some staff confused, as MCI continued running on some laptops even after the announcement.

Key Points
  • Meta's Model Compatibility Initiative (MCI) launched in April 2024 to all US employees, collecting mouse movements, clicks, keystrokes, and screen content for AI training.
  • On June 18, an internal security issue exposed MCI databases to all Meta employees; a fix was applied in 4 hours but failed to permanently lock down access.
  • Meta paused MCI after internal backlash, stating it will re-enable only when data protection controls are fully confirmed—and noted it has enough data to assess the tool's value.

Why It Matters

This breach underscores risks of pervasive workplace surveillance and could reshape trust in AI training data sourced from employee activity.

📬 Get the top 10 AI stories daily