Meta sued over Facebook, Instagram photos used for NameTag, AI training

Meta sued over Facebook, Instagram photos used for NameTag, AI training

A group of parents and children in Illinois and California filed a proposed class-action lawsuit last week in federal court in Chicago, accusing Meta of illegally using their Facebook and Instagram photos to build NameTag, an unreleased face-recognition system for its smart glasses, and to train generative AI models including Emu and Muse Image. The complaint alleges Meta violated Illinois and California privacy laws by extracting biometric information from people's photos without notice or consent.

The NameTag allegations build on WIRED's own reporting from June, when the outlet found that code for NameTag had been secretly embedded in Meta's glasses AI companion app, an app downloaded more than 50 million times. The feature had never been switched on for users, but WIRED's analysis found the system was designed to turn faces captured by the glasses into biometric signatures and compare them against faceprints stored in a database on the user's phone, a database configured to receive updates from Meta. At the time, WIRED could not determine where the underlying faceprint data had come from.

The new complaint tries to answer that question, alleging the faceprints are possibly derived from Facebook and Instagram images. It cites reporting that Meta employees claimed NameTag could recognize people through their Meta connections or public Instagram accounts, plus a Meta patent describing face matching against profile photos and other images the company holds. When WIRED asked about this in June, Meta said only that it was "not building a central face database" and declined to say whether NameTag would be opt-in or how it would retain faceprints. The complaint itself acknowledges that Meta has not disclosed which images, if any, were used to generate the biometric data.

The suit's second target is Meta's image-generation systems. Meta has said it trained its Emu model on large quantities of Facebook and Instagram images and text, with chief product officer Chris Cox calling those platforms a "data advantage" for the company's AI. The complaint alleges that training process illegally harvested biometric information about the people who appeared in those images. It also points to Muse Image, a model Meta released this summer that drew criticism for letting users generate images based on other people's public Instagram accounts, a feature Meta pulled within days, saying it had "missed the mark."

Responding to the lawsuit, a Meta spokesperson said: "This lawsuit is without merit and misrepresents our work. We've been transparent about how we use people's information to build and improve our AI products. As for NameTags, nothing has shipped to consumers and no final decision has been made on what to do here, if anything." The spokesperson added that if Meta does roll the feature out, it will do so "with full transparency," and repeated that the company is "not building a universal face database," wording similar to, though not identical to, its June statement about not building "a central face database."

The named plaintiffs are Francisco Alvarez and his son, both Illinois residents, and Jeremy Wahl, a California resident, and his 10-year-old daughter; the article does not name either child. The proposed class is far larger: anyone in Illinois, California, or elsewhere in the US whose photos were uploaded to Facebook or Instagram, or who submitted images to Meta's generative AI tools through prompts, dating back to September 4, 2021. The complaint estimates the national class could number in the millions. "People shouldn't have to worry if their biometric information will be misused simply because their photographs appear on a social media platform," said Justin Boley, a partner at Wexler Boley & Elgersma and an attorney for the plaintiffs.

Under Illinois' Biometric Information Privacy Act, the plaintiffs are seeking $5,000 for each intentional or reckless violation, or actual damages if greater, and $1,000 for each negligent violation, or actual damages if greater, plus an order requiring Meta to change its practices. The California plaintiffs are seeking additional damages and relief under that state's law.

This is not Meta's first brush with biometric-privacy liability. In 2020, the company agreed to pay $650 million to settle an Illinois class action over an earlier, separate face-recognition system, and in November 2021 it announced it would shut that system down and delete more than a billion stored faceprints. In 2024, Meta agreed to pay Texas $1.4 billion to resolve separate allegations that it had unlawfully collected users' biometric data.

The day after WIRED's June 4 report on NameTag, Meta removed the code from its app and argued the feature "never existed" because it had not been made available to consumers, even though WIRED's analysis and testing by outside researchers had found a technically functional face-recognition system running inside an app downloaded by tens of millions of people. Meta CTO Andrew Bosworth called WIRED's reporting "incredibly misleading" and "absolutely dishonest" at the time. Weeks later, though, Bosworth described NameTag on a podcast as a system that could recognize people a glasses wearer had previously met and asked the device to remember, saying he thought it "would be a great feature." Meta has continued to describe NameTag as something it is exploring rather than a product available to consumers.

The complaint frames the case as part of a longer pattern of privacy violations at Meta, reaching back to a 2004 chat in which, it says, a young Mark Zuckerberg used a dismissive, vulgar phrase to describe people who had trusted him with their data. WIRED notes that this remark is reported rather than independently verified in this article.

Key facts

  • A proposed class-action lawsuit filed last week in federal court in Chicago accuses Meta of using Facebook and Instagram photos, without consent, to build NameTag, an unreleased face-recognition feature for its smart glasses, and to train AI models Emu and Muse Image.
  • WIRED's June investigation found NameTag code secretly embedded in Meta's glasses AI companion app, downloaded more than 50 million times, comparing faces against a faceprint database on the user's phone that Meta could update, though WIRED could not confirm where the faceprint data came from.
  • The proposed class covers anyone in Illinois, California, or elsewhere in the US whose photos were uploaded to Facebook or Instagram, or who prompted Meta's generative AI tools, since September 4, 2021, a group the complaint estimates could reach into the millions.
  • Under Illinois' Biometric Information Privacy Act, plaintiffs are seeking $5,000 per intentional or reckless violation and $1,000 per negligent violation, on top of separate California damages claims.
  • Meta has settled biometric-privacy cases before, paying $650 million in Illinois in 2020 and $1.4 billion to Texas in 2024, and calls this new suit "without merit," saying NameTag has never shipped to consumers and no decision has been made on its release.

Why it matters

The lawsuit ties two separate Meta AI controversies into a single legal claim: an unreleased face-recognition feature for its smart glasses, and the photo data behind its Emu and Muse Image generative models. It tests whether a feature that never shipped to end users, and existed only as dormant code inside an app WIRED investigated, can still create liability under state biometric-privacy law. Meta has already paid to settle two earlier biometric cases: $650 million in Illinois in 2020, after which it shut down an older face-recognition system and deleted more than a billion stored faceprints, and $1.4 billion to Texas in 2024. This case links that history directly to how Meta trains its image-generating AI.

Who it affects

The named plaintiffs are Francisco Alvarez and his son, both Illinois residents, and Jeremy Wahl, a California resident, and his 10-year-old daughter; the article does not name either child. The proposed class reaches much further: anyone in Illinois, California, or elsewhere in the US whose photos were uploaded to Facebook or Instagram, or who submitted images to Meta's generative AI tools through prompts, at any point since September 4, 2021, a population the complaint says could number in the millions. It also touches Meta's smart-glasses users specifically: the AI companion app that WIRED found carrying dormant NameTag code has been downloaded more than 50 million times, even though the feature has never been turned on for anyone using it.

How to use it

There is no setting to change here: Meta says NameTag has never been enabled for any user and that no decision has been made on whether it ships at all. For readers, what matters is eligibility rather than action. The proposed class already covers any Facebook or Instagram user in Illinois or California, or elsewhere in the US, whose photos were uploaded to either platform, or who prompted one of Meta's generative AI tools, since September 4, 2021, and membership would not require signing up. The plaintiffs' ask under Illinois' BIPA is $5,000 per intentional or reckless violation and $1,000 per negligent violation, or actual damages if higher, plus an order that would require Meta to change how it handles this data; the California claims seek further damages under that state's own law.

How solid is it

Some of the underlying technical claim is independently sourced: WIRED's own June investigation, plus testing by outside researchers, found NameTag's code embedded in the Meta glasses app and functioning technically, matching faces against a synced, on-phone faceprint database. But where those faceprints actually came from is the complaint's inference, not a confirmed fact. It rests on reporting that unnamed Meta employees described NameTag as able to recognize people through their Meta connections or public Instagram accounts, and on a Meta patent covering face matching against profile photos, not on any admission from Meta about the data's source. Meta disputes the lawsuit's characterization of its work as a misrepresentation and has not said which images, if any, feed the system. This is a filed complaint, with claims still to be tested in court, not a finding of wrongdoing.

Risks and caveats

A court still has to certify a class before this can proceed as one, and the "in the millions" figure is the complaint's own estimate rather than anything a court has confirmed. Meta's central defense is that NameTag "never existed" as a product because it was not available to consumers, a position that sits alongside WIRED's own analysis and outside testing showing the system worked technically once its code shipped inside a widely downloaded app. Meta's public language has also shifted over time: in June it said only that it was not building "a central face database," and in response to this suit it says it is not building "a universal face database," similar wording that leaves open whether some narrower version of the system could still move forward. Meta CTO Andrew Bosworth has sent mixed signals of his own, calling the original WIRED story "incredibly misleading" and "absolutely dishonest" while later telling a podcast he thought NameTag "would be a great feature." Finally, this is a private lawsuit over statutory damages, not a regulatory action, so however it resolves, it will not by itself set rules for what other companies can do with user photos as AI training data.

“People shouldn't have to worry if their biometric information will be misused simply because their photographs appear on a social media platform.”

— Justin Boley, a partner at Wexler Boley & Elgersma and attorney for the plaintiffs