With the launch of Meta’s new AI agents push, the company has also initiated a public relations blitz in an effort to reassure users that it can be trusted with their data, despite many past instances of data misuse.
Meta’s Muse AI agents are designed to make things easier for people, by undertaking tasks on their behalf, with its Muse bots able to search the internet, make purchases, analyze banking data, recommend insurance plans, dig into health information and much more.
Basically, Meta’s Muse AI agents are able to provide insight on whatever data you give them access to. But in order for this to be truly valuable, users will have to give Meta’s AI tools access to a lot more of their sensitive data and information.
Meta wants the public to feel safe in doing so, which is why it’s also outlined a range of data-protective processes aligned with Muse usage to ensure that whatever info people choose to share with the bot remains locked away and protected from any outside access, even from Meta itself.
But winning public trust will be a key challenge in securing widespread adoption of the system. Because as many court cases have shown, Meta’s “move fast and break things” ethos prioritizes innovation over safety, which has led to repeated data breaches and harms that are generally only identified in retrospect.
As a reminder, here’s an incomplete list of the many times that Meta has been accused of misusing people’s data over the years:
- In 2007, Meta was sued by a user over the public disclosure of private information via its Beacon program, as reported by The Washington Post. Meta settled the case by ending the Beacon program and creating a $9.5 million fund for privacy and security (New York Times).
- Also in 2007, Meta was forced to shut down a program which used Facebook users’ names and likenesses in ads without their consent. Facebook settled the case and issued payments to impacted users (Bloomberg).
- In 2011, Meta was sued for tracking user activity off Facebook via cookies. After fighting it for over a decade, Meta finally agreed to pay $90 million to settle the case in 2022 (The Verge).
- In 2014, Meta was accused of scanning users’ private messages to collect data for ad targeting. Meta agreed to cease using data in DMs in order to settle the case (Courthouse News Service).
- In 2014 and 2015 regulators in France and Belgium sued Meta over the tracking of non-users and logged-out users for advertising purposes (The Guardian).
- In 2016, Meta faced legal action over the use of facial ID in its photo-tagging feature. This case, and several similar legal filings, led to Meta shutting down its facial ID program in 2021.
- In 2018, Meta was sued over a data breach which exposed the personal information of around 30 million users (The Denver Post).
- In 2019, Turkish authorities fined Meta $282,000 for violation of data protection laws which affected nearly 300,000 people (Reuters).
- Also in 2019, the FTC imposed a $5 billion penalty on Meta and required it to submit to new restrictions and requirements following the Cambridge Analytica incident.
- In 2021, Meta was sued for breaching the public trust in knowingly creating systems that caused harm in order to maximize profit. The accusations stemmed from an internal data leak by former Meta employee Frances Haugen, and led to various other lawsuits along the same lines (The Guardian).
- In 2022, Meta was sued for more than $3 billion in a lawsuit which claimed that 44 million UK Facebook users had their data exploited after signing up to the social network (The Guardian).
- Also in 2022, the Texas Attorney General’s office sued Meta over the collection of user biometric data without consent. Meta agreed to pay $1.4 billion in compensation and shut down its biometric data collection process (The Washington Post).
- Also in 2022, Meta faced a lawsuit over the collection of people’s health data (TechTarget).
- Also in 2022, Meta was fined $461 million by Irish regulators for violating children’s privacy (BBC).
- In 2023, Meta was fined a record $1.3 billion by the European Data Protection Board for transferring EU user data back to the U.S. without explicit permission or adequate protections in place (CNBC)
- In 2024, the Irish Data Protection Commission issued Meta with a $263 million fine for a data breach that exposed the personal info of 29 million Facebook users.
- In 2026, hackers were able to gain access to over 20,000 Instagram accounts after tricking Meta’s AI-powered support bot.
- Also in 2026, Meta agreed to pay $18 billion in penalties, and implement new measures, in order to settle a case brought by a coalition of U.S. attorneys general which accused the company of misrepresenting the extent of child-related mental health harms caused by its apps.
This, again, is not a complete listing of all the times Meta has been accused of misusing data and the resulting lawsuits, which have cumulatively cost the company more than $25 billion in fines, and resulted in many rules being imposed on the business to protect people’s information.
Maybe Meta has learned from these cases, and will roll those learnings into its new Private Processing approach for Meta AI, which will process user information gathered by its devices inside “confidential virtual machines.”
But the company has a long history of pushing ahead with products, then dealing with the fallout in retrospect.