Some links on this page are affiliate links: if you buy through them we may earn a commission, at no extra cost to you.
Scale AI appears to have exposed sensitive documents tied to Meta, Google and xAI through improperly configured Google Docs—not hacked those companies’ systems. A Business Insider investigation published June 24, 2025 found documents accessible to anyone with the relevant link, including AI-training materials and contractor information. The available reporting does not establish that Meta accessed rival companies’ files, that an outside attacker breached Scale, or that model weights and source code were stolen.
What happened at Scale AI?
Scale AI contractors and teams reportedly used Google Docs to organize artificial-intelligence training and evaluation work. Some documents were configured for public access, including an “anyone with the link” setting. That meant possession of a URL could be enough to view the material without normal authorization.
Some files could reportedly also be edited by anyone with the link. That created an integrity risk as well as a confidentiality risk: an unauthorized person might alter evaluation instructions, insert malicious links or manipulate examples used by contractors.
What’s actually slowing this PC down?
Pick the symptom - the matching free tool is one click away.
Business Insider reviewed approximately 85 documents and thousands of pages, according to summaries of the investigation. After being notified, Scale said it was investigating and disabled public sharing from Scale-managed systems. That is an important containment measure, but it is not by itself proof that every copy, download, cached version or downstream share was eliminated.
#1 Best Overall
The most accurate description is a serious third-party data-governance and access-control failure. “Data leak” is reasonable shorthand. “Hack” is not supported by the available evidence.
What information was exposed?
| Category | Reported examples | Potential risk |
|---|---|---|
| Client project information | AI-training manuals, evaluation instructions and project codenames | Reveals workflows, priorities, vendor relationships and operating methods |
| Model-evaluation content | Prompts, response examples and grading guidance | Could reveal how systems were tested and what behaviors evaluators rewarded |
| Linked media | Audio examples related to speech-prompt work | Potential privacy, copyright and training-data concerns |
| Contractor information | Names, private email addresses, work details and performance classifications | Privacy, impersonation, harassment and employment risks |
| Document contents | Some files reportedly editable through the public link | Malicious edits, unsafe links or poisoned evaluation material |
The public-interest issue is the security failure, not the republication of exposed names, email addresses or document URLs. Those details should not be repeated.
What was connected to Google, xAI and Meta?
Reportedly exposed documents described work to improve Google’s chatbot, then known as Bard. The material involved evaluating or rewriting chatbot responses and using ChatGPT outputs as part of the work. This supports the description “documents about a Scale-run project for Google.” It does not show that Google’s internal systems, source code, model weights or production data were exposed.
Do these 3 things before closing this tab:
1Scan for outdated or missing drivers - takes under a minute2Clear out junk files and repair common Windows errors3Fix the driver behind crashes, sound loss and screen glitchesSource: Business Insider reporting summarized by Yahoo.
Rank #2
xAI
Documents associated with “Project Xylophone” reportedly covered prompts and evaluation work for conversational behavior, including scenarios involving the zombie apocalypse and life on Mars. The evidence supports calling these xAI project and training materials. It does not justify describing them as Grok source code, model architecture or secret model files.
Meta
Meta-related material reportedly included links to audio examples showing acceptable and unacceptable speech prompts. The documents became especially sensitive because Meta had just agreed to invest approximately $14 billion to $14.8 billion in Scale AI and recruit founder Alexandr Wang, according to Associated Press coverage.
Nothing in the available reporting proves that Meta received special access to Google’s or xAI’s information, accessed the exposed documents or used them. The issue is a trust and governance concern, not evidence of a transfer of rivals’ secrets.
Recommended Free Tools
Was this a data breach?
That depends on the technical and legal definition being used.
Rank #3
- Confirmed: Sensitive business and contractor documents were publicly accessible through links.
- Reported: Some documents were marked confidential and could reportedly be viewed or edited by anyone possessing the URL.
- Not established: A malicious actor penetrated Scale’s protected systems, downloaded the files, compromised a customer environment or misused the information.
- Legal classification: Whether the event qualifies as a reportable personal-data or contractual breach depends on the information involved, jurisdictions, customer agreements and investigation findings.
A public link can still expose confidential information even when a file is not indexed by Google Search. Links can spread through email, chat, browser history, screenshots, copied project materials, contractor turnover and forwarding.
Exposure of project guidance is also different from exposure of proprietary model weights, source code or an entire production dataset. The available reporting does not establish that those higher-value assets were exposed.
Why Meta’s investment made the incident more serious
Scale’s business relationships created two separate questions:
Outdated Drivers Are Slowing You Down
One free scan finds every outdated or missing driver and matches the right update for your exact hardware.Free scan · exact hardware matchWindows Errors? Fix Them Before They Spread
Repair common Windows errors and clear accumulated junk for a smoother, more stable PC - no reinstall needed.Free scan · no reinstall- Structural conflict of interest: Can a company partly owned by Meta remain a trusted neutral supplier to Meta’s competitors?
- Operational security: Did Scale properly protect client and contractor information in the first place?
Contemporary reports described Meta’s stake as approximately 49%, while Scale said it remained operationally independent. In its June 18, 2025 customer-trust statement, Scale said Meta’s investment did not give it access to Scale’s internal systems or customers’ confidential information, and that Meta would receive the same customer-information protections as other customers.
Rank #4
- Our most advanced Kindle Scribe – Features an 11” Colorsoft display with front light, built-in notebook, AI tools, and support for popular cloud services.
- Bring ideas to life in color – The custom-built Colorsoft display delivers high-contrast, paper-like color that’s easy on the eyes without distracting flashes when writing.
- Get a pen-on-paper feel: The textured surface and responsive display create a smooth, paper-like writing experience. Plus, the included pen never needs charging and has a built-in eraser and shortcut button for tools like the highlighter.
- More room to read, write, and think – Just 5.4mm thin and 400g light, with fluid performance and a large 11" display that gives you space to work comfortably.
- Get more out of your notes – Take notes in the built-in notebook, then use AI to find information, ask questions about what you’ve written, and generate summaries. You can also clean up handwriting or convert it to text.
Google, OpenAI and xAI reportedly paused or reduced work with Scale after the investment, according to TIME and TechCrunch. The public-document exposure intensified those concerns, but it does not prove that the investment caused the misconfiguration or that Meta obtained competitors’ material.
What did Scale do?
Scale said it took data security seriously, launched a “thorough investigation” and disabled users’ ability to publicly share documents from Scale-managed systems. It separately denied that Meta’s investment provided access to internal systems or customer confidential information.
The available record does not establish a detailed final investigation report, the number of affected files or contractors, whether every customer was individually notified, whether regulators were contacted, or whether an independent audit verified remediation. Those are material unanswered questions.
Free tools Windows power users keep installed
One-click scans. No signup required.
Why public editing is especially dangerous
Read access can expose confidential information. Edit access can change the information people rely on. An altered document could:
Best Value
- Up to 11 hours battery life on a single charge
- Built in security Features ensure you're protected from viruses and Malware
- 11.6 inches HD anti reflective Display
- Spill resistant keyboard protects against accidental Damage
- Intel Celeron N3060 Processor with 2G Memory and 16GB storage
- insert a credential-stealing or malware-delivery link;
- change grading instructions without obvious notice;
- introduce poisoned examples into an AI-evaluation workflow;
- cause contractors to follow unsafe procedures;
- create disputes about which instructions were genuinely issued.
Security experts cited in summaries of the investigation warned that public-link sharing can facilitate social engineering and impersonation. Relying on the obscurity of a URL is not a substitute for explicit identity-based permissions, logging and least-privilege access.
What safeguards should AI-data vendors provide?
Customers evaluating a data-labeling or AI-evaluation supplier should ask:
- Are customer files stored in customer-controlled or vendor-controlled environments?
- Is “anyone with the link” prohibited by policy and technical control?
- Are view and edit permissions separated?
- Are external shares, downloads and permission changes logged and reviewed?
- Are contractors given only the access required for a specific project?
- Are customer environments logically segregated?
- Are linked audio files and attachments governed by the same permissions?
- How quickly are former contractors’ accounts and access revoked?
- What are the incident-notification deadlines?
- How are data deletion, retention and customer audit rights handled?
Contracts matter, but contractual confidentiality language does not prove that controls worked. Scale’s Master Services Agreement provides context on confidential, personal and sensitive information; buyers should also review security addenda, data-processing agreements, subcontractor restrictions, audit rights and customer-specific controls.
The Tool Desk
Outbyte PC Repair FREEClear out junk files and repair common Windows errorsFree Scan →Outbyte Driver Updater FREEScan for outdated or missing drivers - takes under a minuteDriver Scan →What remains unknown?
- Who viewed the documents and whether anyone downloaded them.
- Whether the information was copied or redistributed.
- Whether Meta viewed any documents relating to Google or xAI.
- How many contractors or customers were affected.
- Whether any regulator or customer investigation followed.
- Whether all cached or copied material was removed.
- Whether Scale published a final investigation or independent audit.
Scale’s later leadership changes are context, not proof of a direct consequence. Axios reported in July 2026 that former Google Cloud COO Francis deSouza became Scale’s CEO.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

