180 incidents on record · 2026 Headlights Incident reports by Ellie Harris · Melbourne
10 new this week Library last updated 30 August 2026
← The incident library
HD-INC-161
Consumer AI · United States · 2025 · Data exposure & egress

Meta's standalone AI app carried a Discover feed that reporters found was publishing users' conversations, in the cases they documented alongside a linked Facebook or Instagram profile, and the company added a warning screen after the reporting

By Ellie Harris · Filed Meta AI app launched 29 April 2025; feed contents documented publicly 12 to 17 June 2025

Alleged: Meta Platforms, Inc. developed or deployed the AI system implicated in this incident. Details are drawn from public reports; parties are presumed innocent of any wrongdoing not established by an official finding.

Meta's standalone AI app carried a Discover feed that reporters found was publishing users' conversations, in the cases they documented alongside a linked Facebook or Instagram profile, and the company added a warning screen after the reporting

What happened

It was reported that Meta launched a standalone Meta AI app on 29 April 2025, and that the app included a Discover feed. Meta’s own announcement describes the feed as a place to share and explore how others are using AI. People can see the prompts others are sharing and remix them, and Meta states that nothing is shared to the feed unless the user chooses to post it. It was reported by TechCrunch that where a user logged in to Meta AI with Instagram and that Instagram account was public, their shared material was public too. A shared exchange could therefore appear alongside the social profile the user had linked. Meta’s announcement does not describe Facebook or Instagram as the only way to sign in. It records that Meta AI can draw on information from those services where the accounts are added to the same Accounts Center.

It was then reported, between 12 and 17 June 2025, that the feed contained material of a kind users appeared not to have understood they were publishing. TechCrunch reported on 12 June that visible items included home addresses, court matters with personal details in them, medical questions and audio recordings. Fast Company reported the same day on the personal character of the material in the feed. TechCrunch also quoted a security researcher on the gap between how users expected the tool to work and how it did. Business Insider reported on the feed in the same week. On 17 June, 404 Media reported that chats could be tied to real people because the app used the user’s Instagram or Facebook account as the login.

It was reported by TechCrunch that when it approached Meta on 12 June a spokesperson did not comment on the record. It was reported by Engadget on 16 June that a Meta spokesperson then said sharing to the public feed involved a multi-step process meant to have a degree of friction. The spokesperson did not address Engadget’s questions about the new disclaimer. Engadget also recorded the text of a warning interposed in the share flow, telling users that prompts they post are public and visible to everyone, that Meta may suggest them on other Meta apps, and to avoid sharing personal or sensitive information. TechCrunch reported on 10 April 2026 that Meta had since removed the Discover feed. No dated announcement from Meta about the removal was identified in the sources reviewed. No published figure for the number of conversations exposed was identified, and no regulator determination specific to the Discover feed was identified.

What an auditable version would have shown

The feed was assessed from the outside. Reporters opened the product, read what was in front of them and described it. That establishes that particular material was visible on particular days. It cannot establish how much there was in total, how long any item had been visible, or how many people saw it. No public figure was identified for how many items were published, how many carried personal information, or how long any of them remained visible. What the reporting establishes from the public record is what a person could see in the feed on a given day.

An auditable version answers those questions from the inside. A record made when something is published says which account published it, what the content was, what classes of personal information it contained, and what audience the item was released to. That record lets an organisation say how many items carried an address or a medical question. It also lets a regulator or a user ask the same question and get the same answer. It does not decide whether the design was fair or whether consent was meaningful. It means the size and shape of what was published can be established from the record, rather than depending on how long a journalist kept scrolling.

Where the gap was

It was reported that content moved from a private exchange with an assistant to a public feed, carrying in the documented cases the social profile the user had linked. It was also reported that users appeared not to have understood that the sharing flow could make the content publicly visible alongside a linked social profile. An EgressGate performs a check at the point where data would leave a trust boundary. It classifies what the content contains and tests the destination, so an item carrying an address, a named legal matter or a medical detail is held for an explicit confirmation naming what it contains, rather than passing through a share flow that treats every item alike. A ConductRecord preserves, for each published item, the account, the content, the classification and the audience. That allows the extent of a publication to be established afterwards from records rather than reconstructed by reading the feed. Neither control decides how a sharing flow should be designed or what a user can reasonably be expected to understand. They provide a record showing what was released and to whom, for the organisation and for anyone reviewing it.

What governance should have looked like

It was reported that Meta’s position is that nothing reaches the feed unless the user chooses to post it, and that sharing involves a multi-step process meant to have a degree of friction. The reporting also describes users who appear to have published material they did not intend to make public. Those two accounts are not reconciled in the sources reviewed, and this entry does not resolve them. Where an organisation builds a feature that republishes a user’s conversation with an AI assistant alongside a linked social profile, best practice would be to assess the classes of personal information in an item before publication rather than after. The audience would be stated at the moment of the decision, rather than inferred from account settings made elsewhere. A record of what was published would also be kept so the scale of any exposure can be established. TechCrunch reported the feed removed as at April 2026. No dated announcement from Meta was identified, so the date the feed was withdrawn is not established here.

Failure Pattern: a sharing control published content to an audience wider than users understood, and the public record does not show a record made at the point of publication that would say what personal information was leaving the account or who could see it.

Governance Principle: an organisation that lets an AI product publish a user’s conversation should be able to establish, before the content leaves the account, what personal information it carries and how wide the audience is, and to show afterwards what was published and under whose identity.

The reference implementation of EgressGate and ConductRecord is open source. It lives at github.com/saffronandindia/headlights-oss, Apache 2.0 licensed and free to install. The repository is public now.

Sources

The mailing list

Fresh incident reports every week. One email to match.

We add new incidents to the library regularly, and send a single short email each week with what's new. The library stays free and open; this is just how you keep up with it.

No tracking. Unsubscribe in one click.

The record

An auditable system would have produced a signed, tamper-evident record the moment this happened: what the system did, the version that did it, the basis it acted on, and the action taken, and Meta Platforms, Inc. could have produced it on demand.

This is the record the system as deployed did not produce in a signed, auditable form.

What this teaches
Capture what happened when it happens
What the system did, the version that did it, the basis it acted on, and the action taken, recorded at the moment, not reconstructed after.
Sign it, so no one has to trust the record-keeper
A tamper-evident entry. Edit it later and the signature breaks. The record does not ask for the benefit of the doubt.
Make it verifiable by anyone
A court, a regulator, a customer's lawyer can check the record themselves, without taking the company, or us, at our word.

Headlights summarises publicly reported AI incidents. All summaries are independently written, attributed to their original sources, and intended for research and educational purposes. Allegations are identified as such until established through official findings.

This report is based on the sources listed above and reflects information available at the time of review; later developments may not be captured. Where a person is described as charged with or alleged to have done something, that allegation is unproven unless a conviction or a court or regulatory finding is stated. Headlights publishes journalism and commentary, not legal advice.

Want to write back?

Direct to my inbox.

ellie@useheadlights.com →