Meta has spent the past two months collecting keystrokes, mouse movements, screenshots, and chat messages from the laptops of its US-based employees. The program is called the Model Capability Initiative. The goal, as Meta has explained it, is to teach AI systems to use common office software the way a real person does: clicking through menus, switching between apps, drafting emails. Rather than hire outside contractors to simulate this, Meta decided to use its own workforce.
The program covers over 200 applications and websites, including Gmail, Slack, LinkedIn, and Meta's own internal tools. Employees were told there is no way to opt out on a company device. When Meta's CTO confirmed that in writing on an internal forum, the response from staff was a flood of angry and shocked emoji reactions.
More than 1,600 employees signed a petition demanding the program end. Physical protest flyers appeared in Meta's US offices. A formal union drive started at Meta's UK offices, described by its organizers as the first of its kind triggered directly by AI-driven workplace surveillance at a major US tech company. Meta offered a partial concession in early June: employees can pause data collection for up to 30 minutes for sensitive tasks. The petition signatories want it stopped entirely.
Then came the security failure. All of that collected data, including what an internal notice described as "full prompts and transcriptions, private conversations, people and performance data," was left accessible to any employee inside the company. The exposure covered 45,000 internal data tables. The incident was classified at Meta's second-highest severity level.
Meta says the issue is resolved and there is no indication the data was improperly accessed. That is a narrow claim. It means no one has evidence of a breach. It does not mean the data was not seen.
The wider legal picture makes this harder to contain. The program is almost certainly legal under US federal law, which puts few restrictions on what employers can monitor on company-owned devices. Europe is a different story. Meta acknowledged in its own internal documents that the tool captures emails and messages between US employees and colleagues anywhere in the world. A Meta employee in California chatting with a colleague in Dublin means that Dublin employee's messages get ingested into the training pipeline. European privacy law, the GDPR, generally prohibits exactly this kind of data processing without a clear legal basis. The Irish Data Protection Commission, which supervises Meta in the EU, was told the program only applied to US machines.
For anyone running a business, the Meta situation is a live preview of decisions that are coming for every organization. AI agents that can operate computers autonomously are the next frontier for every major technology company. To train those agents, the companies building them need large amounts of data showing how real people use real software. Meta chose to collect that data from its own workforce, without asking permission.
The employees pushing back are not wrong about what is happening. The better a person is at their job, the more useful their daily computer behavior is as training data for a system that could, eventually, do that job without them. That is not a conspiracy theory. It is the stated purpose of the program.
Meta is spending between $125 billion and $145 billion on AI infrastructure in 2026 alone, nearly double what it spent in 2025. First-quarter revenue this year was $56.3 billion, up 33 percent year over year. The company can afford to collect this data without exploiting its own staff to do it. The fact that it chose not to is a decision worth understanding, because the pressure to make the same choice will reach other industries well before the regulators do.