Imagine scrolling through old photos of family gatherings, birthday parties, or a child’s first steps, and then learning that those images may have been quietly harvested to teach a machine how to recognize faces. That is the unsettling possibility at the heart of a new federal lawsuit filed in Chicago. A group of parents and their children from Illinois and California are suing Meta, the company behind Facebook, Instagram, and smart glasses technology. They claim that Meta illegally used photos people posted on its platforms to build a face-recognition feature called NameTag, which was designed for its smart glasses, and to train powerful generative AI models. The lawsuit accuses Meta of violating privacy laws in both states by pulling biometric information from people’s photographs without notice or consent. For the families suing, it’s not just about technology; it’s about control over our most personal data — our own faces. As one of the attorneys put it, people shouldn’t have to worry that their biometric information will be misused simply because their photographs appear on a social media platform.
At the center of the complaint is NameTag, an unreleased face-recognition system that was quietly embedded in the Meta glasses AI companion app. WIRED reported in June that code for NameTag had been hidden inside this app, which had been downloaded more than 50 million times. Although the feature was never turned on for users, an analysis found that the system was designed to take faces captured by the glasses and turn them into biometric signatures — essentially digital faceprints. Those faceprints could then be compared with a database stored on the user’s phone, and that database was set up to receive updates from Meta. At the time, it wasn’t clear where all the faceprint data originally came from. The new lawsuit argues that those faceprints may well have been derived from Facebook and Instagram photos. The complaint points to reporting that Meta employees claimed NameTag could recognize people through their Meta connections or public Instagram accounts. It also cites a company patent describing face matching against profile photos and other images held by Meta. Meta has denied building a “central face database,” but it hasn’t fully answered whether NameTag would be opt-in or how long faceprints would be stored. The complaint acknowledges that Meta has not disclosed exactly which images, if any, were used for biometric data, and says that information remains entirely in the company’s hands.
But NameTag is only one part of the lawsuit. The case also targets Meta’s broader use of photos to train generative artificial intelligence. Meta has openly admitted that it trained its image-generation model Emu on large quantities of Facebook and Instagram images and text. In fact, Meta’s chief product officer called those platforms a “data advantage” for the company’s AI systems. The lawsuit alleges that this training process illegally harvested biometric information about people who appeared in the images. That means every face in every photo posted to a family page, a school group, or a public account could have become part of an AI system’s education. The complaint also mentions Muse Image, a newer AI feature released this summer. Muse Image drew criticism right away because it allowed users to generate pictures based on other people’s public Instagram accounts. Meta removed that feature within days, saying it had “missed the mark.” But the lawsuit argues that the damage was already done. For the plaintiffs, these tools represent a pattern: Meta collecting facial biometrics from ordinary users without asking, and then using them to power products that are often hidden from public view until they’ve already caused concern.
Meta, for its part, rejects the allegations outright. A spokesperson said in a statement that the lawsuit is without merit and misrepresents the company’s work. Meta says it has been transparent about how it uses people’s information to build and improve its AI products. As for NameTag, the spokesperson emphasized that nothing has shipped to consumers and that no final decision has been made about what to do with the feature, if anything. Meta promised that if it does decide to roll something out, it will take a thoughtful approach and do so with full transparency. The company also repeated its position that it is not building a universal face database. Still, the plaintiffs argue that secrecy around the feature tells a different story. The fact that NameTag was embedded in an app downloaded tens of millions of times, even if not activated, suggests that Meta was preparing for a face-recognition launch without telling users. The company’s statement doesn’t answer the central question of whether photos posted by families and friends were used to create faceprints or train AI models. And the complaint notes that only Meta truly knows what happened to the data it collected, because it has never offered a clear accounting of its use of photos and biometric information.
The proposed class action could affect an enormous number of people. It includes individuals in Illinois, California, and across the United States whose images were uploaded to Facebook or Instagram, or were submitted to Meta’s generative AI systems through prompts, dating back to September 4, 2021. The complaint estimates that the national class could number in the millions. That’s a lot of families, a lot of faces, and a lot of personal data potentially caught up in one case. The legal claims are especially strong in Illinois, where the Biometric Information Privacy Act gives residents one of the strictest protections for facial scans and other biometric data in the country. Under that law, the plaintiffs are seeking $5,000 for each intentional or reckless violation, or actual damages if greater, and $1,000 for each negligent violation, or actual damages if greater. They are also asking the court for injunctive relief, which could force Meta to change its practices or hand over more information about what it has done with people’s photos. The California claims add the possibility of further damages and other relief. For a company like Meta, even the potential scale of this lawsuit is significant, both financially and in terms of public trust.
At its core, this lawsuit is about something deeply personal: our faces are not just images; they are identifiers that connect to who we are. In an age where AI can generate realistic pictures, imitate voices, and recognize people in seconds, the question of who owns our biometric information has never been more urgent. The families suing Meta are not accusing the company of just storing vacation photos. They’re saying that Meta turned ordinary social media posts into training data for facial recognition and AI systems, without consent, in ways that could have consequences for years to come. Meta counters that it is being transparent and that NameTag was never released. But the lawsuit argues that the potential for misuse is enough, and that people deserve to know what is happening with their faces before, not after, technology is built. As the case moves forward, it may shape how tech companies handle biometric data from social media platforms. For now, the message from the plaintiffs is simple: posting a photo online doesn’t mean you’ve given up your right to privacy. And no algorithm, no matter how powerful, should get to decide what your face is worth.