
Mercor
AI-Training Data Startup Breach Exposes Contractor Biometrics and Screenshots, Triggering a Wave of Lawsuits
Mercor - a roughly $10 billion startup that recruits human contractors to generate the expert feedback and training data behind frontier AI models for clients reported to include OpenAI, Anthropic, and Meta - disclosed a data breach that exposed sensitive contractor information, including…
- 01TRIGGERMercor - a roughly $10 billion startup that recruits human contractors to generate the expert feedback and training…
- 02MACHINE ACTIONMaterial contributor
- 03MISSING GATENamed SME review and decision audit trail
- 04IMPACTData security
The short version
Mercor - a roughly $10 billion startup that recruits human contractors to generate the expert feedback and training data behind frontier AI models for clients reported to include OpenAI, Anthropic, and Meta - disclosed a data breach that exposed sensitive contractor information, including…
Case telemetry
- INCIDENT
- SS-IR-078
- DATE
- April 23-24, 2026
- SYSTEM
- Mercor
- LOCATION / SCOPE
- United States
- EVIDENCE
- Alleged
- AI ROLE
- Material contributor
- HARM
- Data security
- SOURCES
- 2 cited records
The event
Mercor - a roughly $10 billion startup that recruits human contractors to generate the expert feedback and training data behind frontier AI models for clients reported to include OpenAI, Anthropic, and Meta - disclosed a data breach that exposed sensitive contractor information, including biometric data and computer screenshots captured by its AI-proctoring and monitoring software. Plaintiffs allege Mercor engaged in improper data collection, monitoring, and sharing. At least seven class-action lawsuits followed within days.
What the machine did
This is the hidden human supply chain of AI made visible. To produce training data, Mercor's systems monitored contractors invasively - capturing biometrics and continuous screenshots - and then failed to secure what they collected. The drive to feed AI models an ever-larger stream of high-quality human-labeled data created a sprawling, sensitive dataset about the workers themselves, governed more by automated monitoring than by human judgment about what should be collected, retained, or shared at all.
Where the failure landed
Contractors' biometric data and screen captures were exposed. At least seven class-action lawsuits alleged violations of privacy and labor rights. Client AI labs faced questions about the provenance and ethics of the human data feeding their models, and some partnerships were reportedly paused or reconsidered. The incident dragged the invisible, lightly-governed labor layer of the AI industry into open legal and public scrutiny.
Alleged
Claims reported in litigation or public allegations; not presented here as a final finding.
SOURCE RECORD UPDATED 2026-07-09
2 cited records
- 01Secondary / analysisOECD.AI Incident #1492: Mercor Data Breach (April 2026)
- 02Secondary / analysisPYMNTS
Named SME review and decision audit trail
The failure pattern in this case: Automated judgment without accountable review.
The moment the path could change
A qualified reviewer tests the basis, context, and disparate impact before the decision reaches a person.
Autonomy is a design choice.
See the operating model that keeps AI useful while preserving human authority at consequential moments.
Compare AgenticAI and AugmentedAI →