Meta Sued Over Training Data for Its AI and Face-Recognition Systems
Meta faces a class action lawsuit alleging it violated Illinois and California privacy laws by extracting biometric data from users' photos without notice or consent The complaint centers on the "NameTag" feature, code for which was secretly embedded in the Meta glasses AI companion app downloaded over 50 million times, designed to convert faces into biometric signatures compared against a faceprint database Meta's generative AI systems (Emu and Muse Image) are also targeted for allegedly harves
Analysis
TL;DR
- Meta faces a class action lawsuit alleging it violated Illinois and California privacy laws by extracting biometric data from users' photos without notice or consent
- The complaint centers on the "NameTag" feature, code for which was secretly embedded in the Meta glasses AI companion app downloaded over 50 million times, designed to convert faces into biometric signatures compared against a faceprint database
- Meta's generative AI systems (Emu and Muse Image) are also targeted for allegedly harvesting biometric information from Facebook and Instagram images used in training
- This follows Meta's history of biometric data violations, including a $650 million settlement in 2020 and a $1.4 billion payment to Texas in 2024
- The proposed national class could number in the millions, with plaintiffs seeking $5,000 per intentional violation under Illinois' Biometric Information Privacy Act
Why It Matters
This lawsuit represents a significant escalation in regulatory and legal scrutiny of how AI companies collect and use biometric data, particularly in the context of generative AI training pipelines. For AI practitioners, it underscores the growing legal risk of using social media images for model training without explicit consent, especially when biometric identifiers are involved. The case could set important precedents for how biometric privacy laws apply to emerging AI technologies and shape industry practices around data sourcing.
Technical Details
- NameTag System: Code was embedded in the Meta glasses AI companion app (50M+ downloads) designed to capture faces via glasses cameras, convert them into biometric signatures ("faceprints"), and compare them against a local database on the user's phone that could receive updates from Meta
- Faceprint Database: The system was configured to store faceprints and receive updates from Meta, though Meta claims no central face database exists; the origin of the faceprint data is alleged to come from Facebook and Instagram images
- Emu and Muse Image: Meta's image-generation models trained on large quantities of Facebook and Instagram images and text; Muse Image previously allowed users to generate images based on public Instagram accounts before the feature was removed
- Legal Framework: Illinois Biometric Information Privacy Act (BIPA) allows $5,000 per intentional/reckless violation and $1,000 per negligent violation; California privacy laws also apply
- Timeline: Class period begins September 4, 2021; Meta removed NameTag code on June 5, 2026, one day after WIRED's report
Industry Insight
- AI companies should urgently audit their training data pipelines for biometric information and ensure compliance with BIPA and similar state privacy laws, particularly when sourcing from social media platforms
- The "we didn't ship it" defense may not hold in court—embedding functional biometric recognition code in a widely downloaded app, even if disabled, appears to have triggered legal liability
- Meta's pattern of biometric violations (2020 settlement, 2024 Texas resolution, now this lawsuit) signals that regulators and plaintiffs' attorneys are treating biometric privacy as a persistent compliance failure, not an isolated incident—proactive transparency and opt-in consent mechanisms will be essential going forward
Disclaimer: The above content is generated by AI and is for reference only.