The temptation to capture human activity at the source
Several recent media revelations, notably reported by Times of India and NDTV, have brought to light a troubling practice within major technology firms: attempting to record employee keystrokes and screen feeds to train artificial intelligence models designed to automate their own jobs. Known internally at Meta as "Project OT", this initiative triggered sharp internal pushback, forcing management to halt the systematic recording of desktop interactions.
This episode marks a turning point in enterprise technology. It is no longer just traditional managerial monitoring, often called "bossware", aimed at measuring active screen time. The objective is now to extract the core essence of intellectual work to feed autonomous software agents. Every drafted email, file manipulation, and operational decision risks being converted into training tokens for deep learning architectures, often without the knowledge of the workers involved.
From ordinary telemetry to cognitive expropriation
To grasp the scope of these practices, one must understand the technical mechanisms of modern telemetry. In dominant proprietary operating systems, background processes continuously collect usage metadata: application latency, tool frequency, form keystrokes, and browsing histories. When coupled with contextual activity loggers or biometric sensors, the line between routine system maintenance and the harvesting of trade know-how completely dissolves.
Legally, this approach clashes directly with modern privacy frameworks. In Quebec, Law 25 strictly governs the collection of personal information in the workplace. The Commission d'accès à l'information consistently maintains that monitoring must be justified by serious, legitimate, and proportionate reasons. Diverting workplace activity logs to train generative models without explicit consent or privacy impact assessments constitutes a clear breach of purpose limitation and transparency principles. In Europe, the European Data Protection Board (EDPB) maintains a similar stance, prohibiting the recycling of operational employee data for unsanctioned algorithmic training.
Beyond regulatory compliance, the issue directly impacts organizational integrity. An enterprise that allows employee workstations to stream continuous activity logs to third-party servers faces an invisible leak of its trade secrets, internal methodologies, and strategic intelligence.
Securing the workstation and compartmentalizing applications
Facing this threat of invisible data harvesting, technical policy cannot rely on voluntary commitments alone. It requires an architectural shift across both hardware and software, structured around two complementary layers: neutralizing telemetry on the physical machine and strictly compartmentalizing the application environment.
At the hardware level, adopting a lean native operating system such as Boréal-OS provides a foundational answer. Derived from a sovereign, verifiable Linux distribution, it installs directly onto local storage. Unlike closed commercial environments, it contains no telemetry backdoors and no background behavioural tracking modules. Keystrokes, display outputs, and active memory remain strictly confined to the local hardware. In addition, this approach extends the operational lifespan of existing computer fleets without forcing institutions into mandatory upgrade cycles driven by global software vendors.
At the software level, the ProductivIA platform applies this same principle of non-interference through sealed browser silos. Within the Nuage application, all stored records remain fully inspectable, editable, and exportable by the user or organization. No harvesting mechanism scans files or background interactions to feed outside models. When the central Assistant coordinates tasks or drafts documents, it operates through predefined application service interfaces. Requests can be routed either to public models or to Quebec provider Matania, ensuring that sensitive organizational data is never utilized for model training.
Rethinking the digital trust agreement
Recent developments confirm that workplace tools must not serve as passive surveillance conduits for technology monopolies. Extracting professional actions to build artificial agents raises fundamental questions about intellectual property in daily work and employee rights.
Building a sovereign stack, uniting a telemetry-free native operating system with a compartmentalized application platform, proves that a viable technical alternative exists. Organizations now have the means to move past opaque ecosystems and select verifiable architectures where corporate data remains, at all times, under their exclusive control.