A group of parents and children from Illinois and California filed a lawsuit in federal court in Chicago last week claiming that Meta illegally mined their Facebook and Instagram photos to develop NameTag, an unreleased facial recognition tool for its smart glasses, and to train generative AI models including Emu and Muse Image. The proposed class action claims Meta broke Illinois and California privacy laws by pulling biometric data from people's images without warning or permission. WIRED had reported in June that NameTag code was secretly built into the Meta glasses AI companion app, which had been downloaded over 50 million times, and that the system was designed to convert faces captured by the glasses into biometric signatures and match them against so-called faceprints kept in a database on the user's device.

The lawsuit claims those faceprints may come from Facebook and Instagram pictures, pointing to reports that Meta staff said NameTag could identify people through their Meta contacts or public Instagram profiles, plus a company patent outlining face matching against profile images and other photos Meta holds. Meta told WIRED in June it wasn't "building a central face database," but declined to answer whether NameTag would be opt-in or how the system would keep faceprints. The complaint notes that Meta hasn't revealed which images, if any, were used to create biometric data, saying that information sits only with the company. The suit also targets Meta's image-generation tools, claiming the training process illegally collected biometric information about people who showed up in the images. Meta has said it trained Emu on large volumes of Facebook and Instagram photos and text, with chief product officer Chris Cox calling those platforms a "data advantage" for its AI systems.

The plaintiffs are Francisco Alvarez and his son, both Illinois residents, and Jeremy Wahl, a California resident, and his 10-year-old daughter. But the proposed class covers people in Illinois, California, and nationwide whose images were uploaded to Facebook or Instagram or were sent to Meta's generative AI systems through prompts, going back to September 4, 2021. The complaint estimates the national class could reach into the millions. Under Illinois' Biometric Information Privacy Act, the plaintiffs want $5,000 for each intentional or reckless violation, or actual damages if higher, and $1,000 for each negligent violation, or actual damages if higher, plus injunctive relief. The California claims seek extra damages and other relief. A Meta spokesperson said in a statement that the lawsuit is "without merit and misrepresents our work," adding that the company has "been transparent about how we use people's information to build and improve our AI products."

This isn't Meta's first run-in with biometric data penalties. In 2020, the company agreed to pay $650 million to settle an Illinois class action over an earlier face-recognition system, and in November 2021 announced it would shut down that system and delete over a billion faceprints. In 2024, Meta agreed to pay Texas $1.4 billion to resolve separate claims it had unlawfully gathered biometric data from users. The day after WIRED's June 4 report about NameTag, Meta pulled the code from its app, arguing the feature never existed because it wasn't available to consumers, even though WIRED's analysis and testing by outside researchers found a technically functional face-recognition system shipped inside an app downloaded by tens of millions of people. The complaint frames the case as part of a much longer string of privacy violations from Meta, reaching back to Facebook's earliest days and citing a 2004 chat in which CEO Mark Zuckerberg reportedly called people who had trusted him with their data "dumb fucks." The suit underscores how platforms once viewed primarily as social networks now double as training grounds for AI systems, raising questions about whether users who uploaded personal photos years ago understood they might later fuel facial recognition or image generation tools. For companies racing to build AI advantages, the line between legitimate data use and privacy violation remains a moving target that courts will now help define.