Empty office chairs in a quiet meeting room, the visual anchor for the Meta MCI pause, the program halted on June 22 2026 after employee keystrokes were exposed internally
Photo via Unsplash

TL;DR: Meta has paused the Model Capability Initiative (MCI), the April-launched program that captured every keystroke, mouse click, and screen-grab from US employees' work laptops to train AI agents. The pause came after WIRED reported on June 22, 2026 that Meta left 45,000 internal hive tables containing employee data accessible to anyone inside the company, including full prompts and transcriptions, private conversations, and people and performance data. CTO Andrew Bosworth acknowledged in an internal note that the program suffered "misconfigured ACLs [access control lists]." Meta VP Stephane Kasriel told staff Meta will only re-enable MCI when confident in data protection controls. The leak validates the warning more than 1,600 Meta employees put in writing the previous month when they signed an internal petition calling MCI "security and regulatory risks for Meta, including the potential for breaches and unauthorized disclosure."

What Happened

On June 22, 2026, WIRED published two investigations. The first, at 4:28 PM, reported that Meta left potentially sensitive information collected from employee laptops accessible to anyone inside the company [1]. The second, at 5:08 PM, reported that Meta had paused the Model Capability Initiative (MCI) indefinitely while it investigated [2].

The internal security notice, sent out Monday, indicated that "employee data across 45,000 hive tables" had been exposed [1]. Those tables included "full prompts and transcriptions, private conversations, people and performance data," according to documents viewed by WIRED [1].

A Meta engineer flagged the security issue on June 18. The initial fix took four hours but did not stick, and access had to be locked down further [2]. Meta marked the incident as resolved by the time WIRED published [1]. Three current employees confirmed the details to the reporters.

For a program that was supposed to be the gold standard of corporate AI training data collection, the lapse is exactly the failure mode that the 1,600 Meta employees had warned about a month earlier.

Employees Predicted This Would Happen

Last month, more than 1,600 Meta employees signed an internal petition protesting the laptop surveillance effort [1]. The petition warned that "collecting this data introduces both security and regulatory risks for Meta, including the potential for breaches and unauthorized disclosure" [1].

One engineer wrote a widely shared internal note saying that having their laptop screen scraped for training data without their consent "felt like an invasion of privacy and amounted to exploitation" [1].

A former employee actively involved in pushing back against MCI described the June 22 leak to WIRED as "a mess," and one that employees had expected would occur [2]. The same person said: "When workers raised concerns, leadership doubled down and failed to acknowledge the risks workers raised about the safety and privacy of worker and customer data. Leadership has clearly created an authoritarian environment where workers are no longer respected or heard" [2].

The petition site at mcipetition.com [3] collected more than 2,400 signatures in total from Meta employees, contractors, and former staff by the time Meta paused the program [4].

Bosworth's "Misconfigured ACLs"

Andrew Bosworth, Meta's chief technology officer and the public face of MCI's rollout, acknowledged the failure in an internal post responding to employee questions on Monday [1].

"Here we had misconfigured ACLs [access control lists] and we need to understand how that happened, track down every data access and understand it," Bosworth wrote [1].

The "ACLs" framing matters. Access control lists are a 1970s-era security primitive. They specify which employees, services, and tools can read which tables. Misconfiguring them inside a company with the engineering depth of Meta is not a small operational slip. It is a structural failure of how MCI was integrated into Meta's existing data warehouse.

Months earlier, Bosworth had told employees concerned about potential data leaks that the tracking program was "tightly controlled" and used "the same protection standards, storage systems, and access controls as other sensitive datasets" [1]. The 45,000 exposed hive tables suggest otherwise.

What "Paused" Means at Meta

Late on Monday, Stephane Kasriel, a Meta vice president overseeing AI research, sent an internal note to staff announcing the pause [2]. He confirmed the security issue had been discovered on June 18 and addressed within four hours, but the fix did not hold and access had to be locked down further [2].

Kasriel committed to two things. First: "We will only re-enable MCI when we are confident in the effectiveness of our data protection controls" [2]. Second: Meta would share more about the future of MCI because it had now "gathered sufficient data to assess the long-term value of the tool" [2].

The second sentence is the tell. Meta is framing the pause as a data-collection milestone, not a privacy reckoning. The phrase "long-term value of the tool" signals that Meta still believes MCI is a viable AI training pipeline. The pause is the program catching its breath, not Meta abandoning the premise that its employees' work laptops are an acceptable source of training data.

A Meta spokesperson, Tracy Clayton, told WIRED: "We have carefully designed this program with privacy safeguards and while we have no indication at this time that any data was improperly accessed by Meta employees, we're pausing it while we investigate" [2].

What Was Actually Exposed

The "45,000 hive tables" number is bigger than it sounds. A hive table at Meta is a structured data store. Forty-five thousand of them holding employee-derived data is roughly the size of a complete workspace telemetry dataset.

The categories WIRED identified are:

  • Full prompts and transcriptions. Anything typed into Meta's internal AI tools by an employee was in the exposed tables.
  • Private conversations. Internal messages between employees, including DMs that were never intended for cross-team visibility.
  • People and performance data. Review materials, manager notes, calibration scores. The exact categories employees were most worried about MCI capturing.

Clayton's statement that there is "no indication at this time that any data was improperly accessed by Meta employees" is not the same as saying no one accessed the data. The misconfigured ACLs mean anyone at Meta with warehouse access could have read those tables during the exposure window. Meta may not know who looked.

A few workers told WIRED they were confused in the hours after the pause was announced because MCI was continuing to run on their laptops [2]. The pause was an executive decision announced to WIRED before it was communicated to staff.

Why This Is the Bossware Story of 2026

MCI is the highest-profile deployment of workplace surveillance software for AI training in 2026. The premise was that Meta's 72,000 US employees represented the best available corpus of "how humans use software" to train AI agents that automate office work [5].

What the leak exposed is the second-order risk that the program's critics warned about from day one. You cannot collect a complete record of how 72,000 employees use their computers and assume the collection infrastructure itself will be perfectly secured. The data is too sensitive, the access patterns too broad, and the integration with existing data warehouses too deep. The 45,000 hive tables were inevitable.

The leak will likely accelerate the spread of state-level bossware regulation. Illinois's BIPA (Biometric Information Privacy Act) already covers biometric capture but not keystroke logging. New York's proposed worker surveillance transparency bill, the California Workplace Know Your Surveillance Act, and the EU's AI Act high-risk deadline on August 2, 2026 are all in play. The Meta incident gives all of them a concrete data point.

The Petition That Predicted the Breach

The MCI petition at mcipetition.com [3] was launched in late April 2026 by Meta engineers and product staff who objected to being involuntarily enrolled as AI training data sources [4]. The site's first public count of signatories crossed 1,600 before the May layoffs and continued climbing through May and June.

The petition's central argument was simple: if you collect every keystroke from every employee across hundreds of internal tools, the resulting dataset becomes a high-value target. It contains the same content as a corporate espionage breach would: product roadmaps, source code, performance reviews, salary information, internal criticism of leadership.

The June 22 leak confirmed the prediction in the worst possible way. The 45,000 exposed hive tables included exactly the categories the petition warned about.

The Bottom Line

Meta built a surveillance tool for its own workers. The workers told the company the tool was a security risk. Meta launched it anyway. Two months later, 45,000 internal tables of employee data were exposed to anyone at Meta with warehouse access.

The pause is a temporary concession to the pressure from the petition and the WIRED reporting. Meta's framing of the program as a "sufficient data" collection milestone suggests MCI will return in some form once the access controls are re-engineered.

The structural problem is not the misconfigured ACLs. The structural problem is that a company this size, surveilling this many employees, with data this sensitive, will eventually have a breach. The 1,600 signatories said so out loud. Meta's response was to call the program "tightly controlled." The 45,000 hive tables proved them right.

If you work at a company deploying any kind of keystroke logging, screen recording, or mouse tracking on work devices, this is the case study that proves your IT security team is one misconfiguration away from the same headline. Ask them what they would do if your company's hive tables were exposed tomorrow. Get the answer in writing.

References

  1. WIRED: "Meta Exposed Data Internally From Its Controversial Employee-Tracking Program" (June 22, 2026, Paresh Dave and Lauren Goode)
  2. WIRED: "Meta Pauses Employee-Tracking Program Following Internal Data Leak" (June 22, 2026, Paresh Dave)
  3. MCI Petition site
  4. Hacker News: "Petition against Meta's employee training data collection for ML models" (HN 48623721, 78 points)
  5. Hacker News: "Meta Pauses Employee-Tracking Program Following Internal Data Leak" (HN 48653575, 306 points at 16.1h old)
  6. Hacker News: "Meta Exposed Data Internally from Its Controversial Employee-Tracking Program" (HN 48636810, 37 points)