Meta has put its Model Capability Initiative on ice for US employees after an internal leak reportedly exposed sensitive staff data across the company. Sources say Meta treated it as a SEV 2 security incident.
The Model Capability Initiative appears to have started in April 2026 for Meta’s US workforce. It tracked day-to-day activity across more than 200 apps and websites. Reports say that included keystrokes, mouse movement and recurring screenshots, all meant to help train Meta’s internal models and assistants. At first, employees reportedly had to take part. A later option to pause tracking for 30 minutes didn’t do much to ease the privacy backlash.
According to those reports, the leak left about 45,000 “hive tables” broadly accessible. The data inside reportedly covered workplace chats, performance information, meeting transcripts, and possibly even tax or medical records.
This came after more than 1,600 Meta employees had already raised red flags, according to reports, about the level of surveillance involved and the risk of building a huge repository of sensitive data without protections strong enough to match it. If you follow how AI companies collect and handle employee data, this one deserves attention.
Privacy lawyers and tech specialists say the access controls look weak. The system may also have swept up communications involving Meta employees in Europe, which could bring GDPR scrutiny with it. Regulators may now look more closely at mandatory employee data collection across the tech industry.
At this point, Meta has paused the Model Capability Initiative for US employees while it tries to explain what went wrong and repair trust inside the company.