What happened
It was reported that Meta launched a standalone Meta AI app on 29 April 2025, and that the app included a Discover feed. Meta’s own announcement describes the feed as a place to share and explore how others are using AI. People can see the prompts others are sharing and remix them, and Meta states that nothing is shared to the feed unless the user chooses to post it. It was reported by TechCrunch that where a user logged in to Meta AI with Instagram and that Instagram account was public, their shared material was public too. A shared exchange could therefore appear alongside the social profile the user had linked. Meta’s announcement does not describe Facebook or Instagram as the only way to sign in. It records that Meta AI can draw on information from those services where the accounts are added to the same Accounts Center.
It was then reported, between 12 and 17 June 2025, that the feed contained material of a kind users appeared not to have understood they were publishing. TechCrunch reported on 12 June that visible items included home addresses, court matters with personal details in them, medical questions and audio recordings. Fast Company reported the same day on the personal character of the material in the feed. TechCrunch also quoted a security researcher on the gap between how users expected the tool to work and how it did. Business Insider reported on the feed in the same week. On 17 June, 404 Media reported that chats could be tied to real people because the app used the user’s Instagram or Facebook account as the login.
It was reported by TechCrunch that when it approached Meta on 12 June a spokesperson did not comment on the record. It was reported by Engadget on 16 June that a Meta spokesperson then said sharing to the public feed involved a multi-step process meant to have a degree of friction. The spokesperson did not address Engadget’s questions about the new disclaimer. Engadget also recorded the text of a warning interposed in the share flow, telling users that prompts they post are public and visible to everyone, that Meta may suggest them on other Meta apps, and to avoid sharing personal or sensitive information. TechCrunch reported on 10 April 2026 that Meta had since removed the Discover feed. No dated announcement from Meta about the removal was identified in the sources reviewed. No published figure for the number of conversations exposed was identified, and no regulator determination specific to the Discover feed was identified.
What an auditable version would have shown
The feed was assessed from the outside. Reporters opened the product, read what was in front of them and described it. That establishes that particular material was visible on particular days. It cannot establish how much there was in total, how long any item had been visible, or how many people saw it. No public figure was identified for how many items were published, how many carried personal information, or how long any of them remained visible. What the reporting establishes from the public record is what a person could see in the feed on a given day.
An auditable version answers those questions from the inside. A record made when something is published says which account published it, what the content was, what classes of personal information it contained, and what audience the item was released to. That record lets an organisation say how many items carried an address or a medical question. It also lets a regulator or a user ask the same question and get the same answer. It does not decide whether the design was fair or whether consent was meaningful. It means the size and shape of what was published can be established from the record, rather than depending on how long a journalist kept scrolling.
Where the gap was
It was reported that content moved from a private exchange with an assistant to a public feed, carrying in the documented cases the social profile the user had linked. It was also reported that users appeared not to have understood that the sharing flow could make the content publicly visible alongside a linked social profile. An EgressGate performs a check at the point where data would leave a trust boundary. It classifies what the content contains and tests the destination, so an item carrying an address, a named legal matter or a medical detail is held for an explicit confirmation naming what it contains, rather than passing through a share flow that treats every item alike. A ConductRecord preserves, for each published item, the account, the content, the classification and the audience. That allows the extent of a publication to be established afterwards from records rather than reconstructed by reading the feed. Neither control decides how a sharing flow should be designed or what a user can reasonably be expected to understand. They provide a record showing what was released and to whom, for the organisation and for anyone reviewing it.
What governance should have looked like
It was reported that Meta’s position is that nothing reaches the feed unless the user chooses to post it, and that sharing involves a multi-step process meant to have a degree of friction. The reporting also describes users who appear to have published material they did not intend to make public. Those two accounts are not reconciled in the sources reviewed, and this entry does not resolve them. Where an organisation builds a feature that republishes a user’s conversation with an AI assistant alongside a linked social profile, best practice would be to assess the classes of personal information in an item before publication rather than after. The audience would be stated at the moment of the decision, rather than inferred from account settings made elsewhere. A record of what was published would also be kept so the scale of any exposure can be established. TechCrunch reported the feed removed as at April 2026. No dated announcement from Meta was identified, so the date the feed was withdrawn is not established here.
Failure Pattern: a sharing control published content to an audience wider than users understood, and the public record does not show a record made at the point of publication that would say what personal information was leaving the account or who could see it.
Governance Principle: an organisation that lets an AI product publish a user’s conversation should be able to establish, before the content leaves the account, what personal information it carries and how wide the audience is, and to show afterwards what was published and under whose identity.
The reference implementation of EgressGate and ConductRecord is open source. It lives at github.com/saffronandindia/headlights-oss, Apache 2.0 licensed and free to install. The repository is public now.
Sources
- Introducing the Meta AI app: A new way to access your AI assistant (Meta Newsroom, 29 April 2025)
- The Meta AI app is a privacy disaster (TechCrunch, 12 June 2025)
- Meta AI’s Discover feed is full of people’s deepest, darkest personal chatbot conversations (Fast Company, 12 June 2025)
- Meta warns users to avoid sharing personal or sensitive information in its AI app (Engadget, 16 June 2025)
- Meta invents new way to humiliate users with feed of people’s chats with AI (404 Media, 17 June 2025)
- PSA: If you use the Meta AI app, your friends will find out, and it will be embarrassing (TechCrunch, 10 April 2026)