
Meta’s decision to pause an internal AI training programme after employee activity data was exposed has reignited a debate over how organisations collect and secure data used to build AI systems.
The programme recorded employees’ keystrokes, mouse movements and other workplace activity to help train AI models before being suspended following an internal data leak.
On the surface, the incident looks like another data exposure story. But for security leaders, it highlights a broader challenge.
As organisations race to develop AI assistants and autonomous agents, many are collecting larger volumes of employee interaction data to improve model performance.
That data can include prompts, documents, application usage and other behavioural information that may reveal sensitive business processes or intellectual property.
The more information organisations gather, the more valuable it becomes to attackers and the greater the consequences if access controls fail.
Traditionally, insider risk programmes have focused on employees deliberately or accidentally exposing sensitive information.
AI training introduces another dimension. Data collected for legitimate purposes can quickly become a security liability if it is stored incorrectly, shared too widely or reused beyond its original purpose.
The Meta incident also raises questions about governance. Security teams may not always have visibility over what information is being collected to train AI systems, how long it is retained or who can access it. Those questions are becoming increasingly important as AI projects move from experimentation into day-to-day business operations.
For CISOs, the lesson is unlikely to be that organisations should stop training AI. Rather, AI training datasets need to be treated like any other high-value asset. Access should be tightly controlled, retention policies clearly defined and sensitive information minimised wherever possible.
The next insider threat may not come from a malicious employee stealing data. It could stem from well-intentioned AI initiatives that create large repositories of employee activity without the governance needed to protect them.
Winston House, 3rd Floor,
Units 306-309, 2-4 Dollis park,
London, N3 1HF
020 8349 4363
© 2026, Lyonsdown Limited. teiss® is a registered trademark of Lyonsdown Ltd. VAT registration number: 830519543