Return to Threats

Meta to Use Off-Site Business Data for Feed and AI Personalization

thehackernews.com 2026-06-09 data leakage High

What Happened

Meta on Tuesday announced that it will use information shared by other businesses to personalize users' feed and responses from its artificial intelligence (AI) chatbot, expanding its scope beyond targeted ads. "Businesses often share information about people's activity on their sites with us to make ads more relevant," Meta said in a statement. "We already use this data - like games you play

Why It Matters

Reportedly, Meta plans to use off-site business data (such as activity on third‑party websites and online purchases) not just for advertising, but also to personalize users' feeds and responses from its AI chatbot.[1][2] This expands the scope of cross-site tracking and data sharing from ad targeting into broader AI-driven content and interaction personalization. From a CyberSE.AI perspective, this raises material data leakage and privacy governance risks: organizations whose sites or apps share data with Meta may be indirectly contributing to a richer behavioral profile that informs AI interactions, with limited transparency or user control. Enterprises need clear AI data governance policies, vendor DPIAs, and CISO-level oversight to define what off-site data may flow into external AI systems and to ensure compliance with privacy regulations and internal data handling standards.

Healthcare Fintech SaaS SMB AI startups

CyberSE Analysis

This signal maps to data leakage. Organizations using AI agents, LLM APIs, SaaS integrations, or sensitive data workflows should review whether this class of issue could create unauthorized tool execution, data leakage, weak approval gates, or unmanaged supply-chain exposure.

Recommended Actions

  • Restrict AI agent tool permissions and production write paths.
  • Review sensitive data access across prompts, logs, embeddings, memory, and SaaS integrations.
  • Add human approval workflows for high-impact or state-changing actions.
  • Run prompt injection and indirect prompt injection tests against affected workflows.
  • Document the owner, control gap, and remediation deadline for this risk class.

Source

https://thehackernews.com/2026/06/meta-to-use-off-site-business-data-for.html

Talk to AI CISO