Meta's AI training effort is capturing employee emails and browsing history, not just mouse clicks

Skye Jacobs

Posts: 2,030   +59
Staff
What we know so far: Meta's latest AI push appears to be built on something broader than it initially suggested: a detailed, ongoing log of how its employees use their work computers. How this plays out – whether as a win for Meta's AI ambitions or a regulatory headache – will depend on whether regulators accept Meta's distinction between behavioral data and personal information.

Internal documents reviewed by Reuters show that the company's Model Capability Initiative (MCI) is collecting interaction data across more than 200 apps and websites. The goal is to train AI systems to perform routine digital tasks autonomously. But exactly what the tool is collecting – and how far that collection extends – is drawing scrutiny both inside Meta and from privacy advocates.

At a basic level, MCI tracks how employees move through software: mouse movements, clicks, and navigation patterns. This kind of telemetry is useful for building AI agents that can replicate common workflows. Over time, these patterns could help train systems that don't just respond to prompts but also carry out multi-step tasks within standard workplace software.

What Meta did not initially emphasize is how much additional data may be pulled into that process.

According to internal materials, the system also captures the contents of emails and messages sent to US-based employees, even when those messages originate from colleagues overseas. In practice, that creates a potential backdoor flow of international data into the training pipeline. Meta acknowledged this in an internal FAQ, stating: "If a US-based colleague has the tool enabled while GChatting or emailing with someone outside the US, that activity would be captured."

The company maintains that the tool is installed only on US devices and is designed to analyze interaction behavior rather than the substance of communications. "In the interest of transparency, we notified non-US employees that it was deployed on the computers of US colleagues they may email or chat with in the normal course of business," said Meta spokesperson Dave Arnold. He added that Meta had weighed privacy risks during development and rollout and remained committed to complying with applicable laws and regulations.

Still, internally, some employees say the system behaves less like a narrow research tool and more like a broad data-capture layer embedded within existing monitoring software. Analyses shared within the company suggest MCI logs a wide range of activity, including code changes, browsing history, device sleep cycles, and clipboard actions.

If accurate, that would give Meta a near end-to-end view of how knowledge workers actually operate across tools – far more detailed than simple usage metrics.

One employee described the distinction this way: "Not 'an AI that clicks a dropdown for you' but 'an AI that knows which dropdown to click, what to select, which document to paste it into, and what to do next.'" The post containing that analysis was later removed, according to other employees.

Arnold disputed those claims, calling them "fundamentally inaccurate," but did not address the specific technical points raised.

There are also practical concerns about how the system operates. Employees have reported sharp increases in data usage after MCI was installed, with some saying it consumed an entire month's home internet allowance in just a few days. That kind of spike suggests the tool may be logging and uploading data continuously rather than sampling at wider intervals.

Outside the company, attention is turning to how this kind of data collection fits within existing privacy frameworks – particularly in Europe. Even if Meta's systems are technically limited to US infrastructure, the incidental capture of communications involving European employees could trigger obligations under the EU's General Data Protection Regulation.

Kleanthi Sardeli, a legal expert at privacy group NOYB, said the issue comes down to how that data is being repurposed. "This data was originally collected for the purpose of work communication and fulfilling an employment contract. Taking an employee's chat and ingesting it into an AI model is incompatible with that initial purpose," she told Reuters.

Meta has told Ireland's Data Protection Commission that collecting EU employee data is not the tool's primary objective, though it has not publicly detailed how incidental collection is handled.

The broader context is a company increasingly organized around automation. MCI is one piece of a larger effort to build AI agents that can take over routine digital work, from navigating internal tools to executing repetitive tasks. That shift has already sparked internal resistance, with some employees describing the initiative as an aggressive attempt to convert human workflows into machine-readable systems.

For privacy advocates, the implications extend well beyond Meta. Johnny Ryan of the Irish Council for Civil Liberties said the project reflects a wider shift in how work itself is being modeled. "This situation, this case, is not limited to Meta employees. It relates to every employee in every sector where they could be replaced. Everybody cares about this if they understand what it is," he said.

Permalink to story:

 
And soon enough that technology will be used even at the lowest level of job entries...with the excuse of "safety and regulation standards"

If you get to work for someone, forget about your privacy at that job.
 
And soon enough that technology will be used even at the lowest level of job entries...with the excuse of "safety and regulation standards"

If you get to work for someone, forget about your privacy at that job.
Boomer, where you been? Any large employer has been able to track your browser history and emails since the 90s.

Everyone who reads this and is shocked is outing themselves as not having held a job since Clinton was in office....
 
This has nothing to do with personal information and privacy, obviously. If Meta wants to spy on employees, there are way easier and less problematic ways.

I'm curious what will come out of this. So far Meta is aiming consistently wrong. They wasted billions on the metaverse project and then scrapped it right before the necessary hw & sw to make it work appeared. Then they blew another pile of money for the 'superintelligence' group, and will probably disband them soon for the lack of results (very likely, when they're on the verge of some breakthrough :).
And now we have this. It may work actually - just like LLMs can predict the next word, a model may be able to predict correctly the next mouse move, click etc. But I'm not sure training models on how people do things by interacting with GUIs and devices is the right approach. Someone will probably manage to bypass all that and beat them.
 
How this plays out – whether as a win for Meta's AI ambitions or a regulatory headache – will depend on whether regulators accept Meta's distinction between behavioral data and personal information.
There is no difference. Personal information is behavior, that's just a fact. If regulators forbid collecting behavior data, then they've effectively outlawed analytics as a "data aggregation practice". They have to allow the collection of employee emails and browsing history, otherwise they risk setting the precedent that behavioral data is intrinsically "personal" in nature. That would regulate the entire targeted advertising industry into oblivion and targeted ads are the reason why Google Adsense and Meta Ads are so prolific in their usage. Regulators only have to choices: act like nothing happened or "notice" the problem. But, really, what we're asking is a more complicated, philosophical problem: do you deserve to keep yourself, to yourself? Or does the ever-increasing scale of AI make the individual person insignificant, in the wake of the formation of AGI? American data collection laws are fundamentally incompatible with the GDPR, so something will have to give.

Who matters more, regulators: people or AI? It can't be both.
 
I just wonder, does Meta's AI applies to the Data protection laws & regulations ?
like,

• Universal Declaration of Human Rights (1948) [United Nations]
• PIPEDA (2000) [Canada]
• e-Privacy Directive (2002) [Europe]
• GDPR (2016)- Replaced Data Protection Directive 95/46 /EC (1995) [Europe]
• CPRA - amends the CCPA (2020) [California, USA]
• CDPA- Consumer Data Protection Act (effect2023) [Virginia, USA]
• CPA- Colorado Privacy Act (effect2023) [Colorado, USA]
• Iowa Data Privacy Act - IDPA (effect2025) [Iowa, USA]
 
Back