Big Tech

Meta AI Privacy: A 2024 Warning

Meta AI privacy illustration of private chat bubble becoming public feed
Meta AI privacy illustration of private chat bubble becoming public feed

By Stuart Kerr, Technology Correspondent, LiveAIWire

Meta AI privacy came under serious scrutiny when the Discover feed, launched as a feature within the Meta AI assistant interface in 2024, began surfacing conversations that other users had made public. Within weeks of launch, privacy researchers and journalists including those at 404 Media discovered that the feed was surfacing conversations containing highly sensitive personal information: users discussing their HIV status, pregnancy concerns, mental health crises, relationship problems, immigration status, and financial distress, in many cases apparently without full understanding that they had opted their conversations into a publicly visible feed.

The incident was not a data breach in the traditional sense. The information was technically public because users had opted in to sharing. But the design of the opt-in mechanism, which many users clearly did not fully understand, created a privacy harm that was real regardless of its technical legality. The Discover feed incident illustrates a pattern in how major technology platforms approach Meta AI privacy that deserves systematic scrutiny rather than case-by-case reactive coverage.

The Meta AI Privacy Design Problem

Privacy researchers who examined the Discover feed’s opt-in mechanism found that the path to making conversations public was shorter and more prominent than the path to ensuring they remained private. The default framing presented sharing as a way to contribute to the community in language that emphasised the social positive of sharing without adequately foregrounding the privacy implications of making sensitive personal disclosures publicly visible. This pattern, where technically consensual sharing occurs in ways that users do not meaningfully understand, is a well-documented dark pattern in digital product design that consumer protection regulators have increasingly recognised as a legitimate enforcement target.

The regulatory response to the Discover feed incident was relatively swift by the standards of technology regulation. The Irish Data Protection Commission, which is Meta’s lead data protection regulator in the EU, opened an investigation into whether the Discover feed’s design met GDPR requirements for informed consent. The UK’s Information Commissioner’s Office published guidance reinforcing that consent to sharing sensitive personal data must be specific, informed, and freely given, with specific emphasis on the inadequacy of consent obtained through dark pattern design.

The Broader AI Assistant Privacy Problem

The Discover feed is a specific manifestation of a broader Meta AI privacy challenge: AI assistants designed to be used for intimate personal conversations create privacy risks that traditional communication platforms do not, because the content of AI conversations tends to be more personal and more sensitive than, for example, social media posts. When people use AI assistants to process grief, navigate relationship difficulties, discuss medical symptoms, or seek support for mental health challenges, they are sharing information in a context that they typically understand as private. This same pattern of AI systems designed to encourage intimate disclosure without adequate privacy safeguards echoes what LiveAIWire has documented in our coverage of emotional AI deployed elsewhere without meaningful consent.

The ICO’s guidance on AI and data protection addresses the contextual integrity principle directly, emphasising that data shared for one purpose should not be repurposed for another without consent that specifically addresses the new purpose. Applied to AI assistant conversations, this principle suggests that using conversational data for community features, training new models, or targeting advertising requires consent that goes beyond the general data processing consent buried in terms of service that most users accept without reading.

User Rights and Practical Protection

Under GDPR in the EU and the UK GDPR, users have a right to access the data held about them, to rectify inaccurate data, to delete data under certain circumstances, and to object to processing for specific purposes. These rights apply to AI conversation data and are exercisable regardless of what general terms of service say.

Meta publishes a data subject rights tool that allows EU and UK users to access, download, and delete their data, but awareness of this tool among users affected by the Discover feed incident was evidently low, a gap that runs through nearly every Meta AI privacy question raised by this episode, and one that connects to LiveAIWire’s coverage of the AI right to be forgotten, where the legal right to erasure exists well ahead of the technical means to verify it.

What This Means for You

If you use Meta AI or any AI assistant integrated into a social media platform, reviewing the sharing and visibility settings for your conversations is a practical step that takes a few minutes and could prevent the kind of inadvertent disclosure that affected Discover feed users. More broadly, treating AI assistant conversations with the same privacy awareness you would apply to any digital communication, recognising that what you share with an AI system is held by a commercial company with its own interests in how that data is used, is an appropriate adaptation to the current AI privacy landscape.

Conversational AI that feels intimate and supportive creates conditions in which users share information that they would not share with a corporate entity if asked directly, and the companies operating these systems have financial incentives to retain, use, and in some cases surface this information in ways that users do not anticipate.

The Privacy International campaign on AI and intimate data provides sustained scrutiny of these Meta AI privacy practices and practical guidance on how individuals and regulators can respond. This same broader concentration of behavioural data in the hands of a single platform runs through LiveAIWire’s coverage of Meta’s AI labs and the Llama 4 release, where the company’s vast social media data assets already give it a competitive position that no rival can match at equivalent scale.

About the Author

Stuart Kerr is Technology Correspondent at LiveAIWire, covering artificial intelligence, cybersecurity, and the social impact of emerging technology. He publishes daily at LiveAIWire.com.