Meta’s Secret AI Training Tool Is Watching Every Click And Europe Is Not Happy

Meta MCI tool tracking employee mouse clicks and computer activity for AI training amid EU GDPR privacy concerns
Meta’s Model Capability Initiative (MCI) tool logs mouse clicks, emails, and app activity from over 200 platforms raising serious GDPR concerns in Europe. (Photo: Reuters / Emirates247)

Meta Platforms has quietly been running a sweeping employee surveillance program to train its artificial intelligence models and it turns out to be far more extensive than what the company first let on. Internal documents reveal the program is also capturing data from non-U.S. workers, setting the stage for a serious clash with European privacy law.

What Is Meta’s MCI Tool?

The Facebook and Instagram parent company told its staff last month that it was rolling out a new tool one that records how people use their computers. This includes mouse movements, every click, and navigation through dropdown menus. The goal, Meta said, was to build AI agents capable of handling everyday software tasks on their own without human input.

The tool goes by the name Model Capability Initiative, or MCI. It pulls in behavioral data from more than 200 apps and websites, based on a list Meta circulated internally. The company maintained the tool was limited to U.S. employees only, with safeguards in place to keep sensitive information protected.

Employees Report Data Overload

Things did not go smoothly after launch. Within weeks, Meta employees began complaining that MCI was consuming absurd amounts of data in some cases burning through an entire month’s home internet quota in just a few days. Internal posts obtained by Reuters captured the growing frustration.

Even more alarming Meta quietly admitted in a Q&A document given to employees that the tool would record any emails or direct messages received by U.S.-based staff, regardless of where the sender was located. That single detail opened a legal can of worms in Europe.

Meta spokesperson Dave Arnold stated that MCI was installed only on devices belonging to U.S. employees, with the focus being on how people interact with their computers not the content displayed on screens.

“In the interest of transparency, we notified non-U.S. employees that it was deployed on the computers of U.S. colleagues they may email or chat with in the normal course of business,” said Arnold.

Arnold confirmed the rough number of apps and websites being tracked but declined to answer questions about total data volume or the tool’s legal standing.

“We carefully considered and mitigated potential privacy risks in both the development and deployment of this tool, and we are committed to complying with applicable laws and regulations,” he said.

EU Privacy Rules Come Into Play

The revelations could push Meta deeper into legal trouble in the European Union a region already locked in fierce battles with Big Tech over data practices. While American workers have limited legal shields against employer surveillance, companies handling EU data must follow the General Data Protection Regulation a strict framework that demands a clear legal basis for data collection, full transparency, and tight restrictions on sensitive information.

Meta’s own FAQ document addressed the issue from the angle of a non-U.S. employee, asking: “I’m based outside the U.S. Will my conversations or data be captured if I’m communicating with a U.S.-based colleague who has the tool enabled?”

Meta’s answer was blunt “If a U.S.-based colleague has the tool enabled while gchatting or emailing with someone outside the U.S., that activity would be captured.”

The company also noted in the same FAQ that MCI data would be “dissociated” from employee identifiers meaning it could not be retrieved or deleted for specific individuals. That directly conflicts with a core right under European law.

Kleanthi Sardeli a legal expert at privacy watchdog NOYB (“none of your business”) said even minor or indirect collection of EU employee data could put Meta in breach of GDPR.

Two central legal questions loom large: whether the EU data capture counts as “incidental” or constitutes monitoring under GDPR, and whether the initiative can pass a so-called “purpose limitation” test.

“This data was originally collected for the purpose of work communication and fulfilling an employment contract. Taking an employee’s chat and ingesting it into an AI model is incompatible with that initial purpose,” said Sardeli.

Meta disclosed to Ireland’s Data Protection Commission its lead EU privacy regulator that EU employee data and screen-recording content were not the “primary purpose” of the tool. The DPC confirmed this communication but offered no further comment. Arnold declined to speak on the company’s regulator exchanges.

Employees Fight Back And One Post Disappears

The MCI initiative sits at the heart of a sweeping internal transformation one aimed at handing over large chunks of daily work to AI agents. The plan has drawn sharp backlash from Meta’s own workforce, with some employees labelling the company an “Employee Data Extraction Factory.”

One employee went further publishing a detailed internal analysis of MCI log files, which was conducted with the help of Anthropic’s Claude AI the same type of tool Meta has been encouraging staff to use. The findings, replicated by multiple colleagues, showed MCI had been piggybacked onto Meta’s existing data security software. This gave it access to far more than advertised including code changes, computer sleep and wake cycles, visited URLs, and clipboard content, all stored in unencrypted form.

That volume of data, the employee wrote, would be enough to build “a complete behavioural model of how a knowledge worker does their job.”

“Not ‘an AI that clicks a dropdown for you’ but ‘an AI that knows which dropdown to click, what to select, which document to paste it into, and what to do next,'” she wrote.

The post later vanished two other employees confirmed this to Reuters. Arnold called the post’s conclusions “fundamentally inaccurate” but would not address its specific claims or confirm whether Meta had taken it down.

Johnny Ryan director of the Irish Council for Civil Liberties’ Enforce uni called for Ireland’s DPC to investigate without delay.

“This situation, this case, is not limited to Meta employees. It relates to every employee in every sector where they could be replaced. Everybody cares about this if they understand what it is,” he said.


Aditya Didwaniya's avatar

Aditya Didwaniya

Aditya Didwaniya is a technology writer and content creator known for his insightful coverage of mobile devices, tablets, and e-gadgets. His work primarily focuses on providing readers with in-depth reviews, comparisons, and analyses of the latest technological advancements in the consumer electronics sector. Through his writing, Didwaniya aims to empower consumers with the knowledge needed to make informed purchasing decisions in the rapidly evolving tech landscape.

Related Posts

Leave a Reply

Discover more from THE BRICS TIMES

Subscribe now to keep reading and get access to the full archive.

Continue reading