Meta AI Profiles Children From Your Deleted Posts
TL;DR: Meta's AI is creating detailed profiles of minors by analyzing years of family posts, reportedly including content that users have deleted. The practice raises significant data privacy and ethical questions for platforms and their users.
Key facts
- Category
- AI
- Impact
- High
- Published
- Source
- Malwarebytes Labs
Full summary
Meta's AI is reportedly building detailed profiles of children by analyzing years of family posts, including content users have already deleted.
Meta’s AI is reportedly capable of building detailed profiles of children by analyzing years of photos, videos, and comments shared by their families, according to a report from Malwarebytes Labs. The issue came to light after a mother posted a video of her daughter, only to see Meta AI offer a suggested query that revealed a deep, synthesized understanding of her child’s identity and history on the platform. This capability suggests the AI is not just analyzing individual posts in isolation but is aggregating data over time to construct comprehensive dossiers on minors who have no direct ability to consent.
The underlying mechanism involves the vast data ingestion and pattern recognition capabilities of large language models (LLMs). Meta’s AI processes a user's entire activity history—including images, captions, tags, and comments from friends and family—to form connections and draw inferences. The most alarming aspect highlighted is the potential inclusion of deleted content in its training data. This implies that when a user deletes a post, the data may be removed from public view but not necessarily from the internal datasets used to train and refine AI models. The AI can therefore retain a “memory” of content that users believed was permanently erased, using it to inform its understanding of individuals, including children.
This practice fits into a broader, troubling trend of creating “shadow profiles” for individuals, particularly those who cannot legally consent, like minors. It raises fundamental questions about data permanence and the “right to be forgotten,” a key principle in regulations like GDPR. While tech companies often claim to anonymize data for training, the ability to synthesize a detailed profile of a specific child from supposedly disparate data points challenges the effectiveness of such measures. The incident serves as a stark example of the ethical tightrope platform companies walk when leveraging user data to advance their AI capabilities, especially when that data involves the most vulnerable users.
For developers, CTOs, and security leaders, this is a critical case study in data governance and AI ethics. It underscores the immense responsibility that comes with handling user-generated content and the technical debt of unclear data lifecycle policies. The incident highlights the risk that data marked for deletion may persist in backend systems, backups, or AI training sets, creating a compliance minefield. Companies must now scrutinize their own data retention and deletion protocols to ensure they are not just user-facing but are fully implemented across all systems, including AI development pipelines. The next steps to watch will be regulatory responses and whether this prompts a wider industry push for more transparent and ethical AI training practices.
Why it matters
This incident suggests 'deleted' user data may still be used for AI model training, creating persistent profiles of non-consenting minors. For engineering and security leaders, this challenges assumptions about data deletion and raises critical questions about data governance, compliance, and ethical AI development.
Business impact
Companies using personal data for AI training face significant reputational and legal risks if they create profiles of children or use deleted data. This can lead to loss of user trust, costly regulatory fines, and shareholder backlash, impacting long-term platform viability and brand perception.
Tags
Related on Notifire
Related stories
Primary source: Malwarebytes Labs
