Skip to content

Product1 publisher3 min readPublished

Illinois and California parents sue Meta over faceprints they say came from Facebook and Instagram photos

Two fathers and their children say Meta turned their Facebook and Instagram photos into face templates for a glasses feature that never shipped, and Illinois law counts biometric damages one violation at a time.

The Product Desk · Product desk

Photograph accompanying Illinois and California parents sue Meta over faceprints they say came from Facebook and Instagram photos
Photo: thenextweb.com

What happened

  • The class reaches anyone in the United States whose images were uploaded to Facebook or Instagram or submitted to Meta's generative AI in a prompt since September 4, 2021. The complaint estimates that group in the millions.
  • WIRED reported in June that NameTag code had been embedded in the Meta glasses AI companion app, downloaded more than 50 million times, without the feature being enabled for users.
  • A Meta spokesperson called the lawsuit without merit and said nothing has shipped to consumers and no final decision has been made on NameTags.

Compiled by The Product DeskSomething wrong?How this is made

Why it matters

  • exposure Liability here follows the faces inside a product's files, so a product can have more claimants than users. The named plaintiffs include a ten-year-old.
  • constraint A terms update accepted by the uploader cannot settle the biometric question for everyone else in the picture. A training pipeline reading a user photo library needs consent from each of them.
  • cost In a per-violation statute the bill is set by how many people were processed. That is why a feature that never reached consumers and earned nothing can cost more than one that shipped and sold.
  • decision The opt-in question Meta declined to answer in June is now something a court can compel.

Francisco Alvarez and his son live in Illinois. Jeremy Wahl lives in California, and his daughter is ten [3]. The class they want certified covers people whose images were uploaded to Facebook or Instagram, or submitted to Meta's generative AI systems in a prompt, back to September 4, 2021 [4]. Membership turns on whose face is in the file [4]. Meta has said it trained Emu on large quantities of Facebook and Instagram images and text, and chief product officer Chris Cox called those platforms a "data advantage" for the company's AI systems [12]. The complaint spends little effort disputing that. Its theory is that the training itself extracted biometric information about the people who appeared in the images [13]. Those are two separate acts on one file, and the consent for the first one comes from the account holder. Muse Image, released this summer, let users generate images based on other people's public Instagram accounts until Meta pulled the feature within days, saying it had "missed the mark" [14]. On the glasses feature the case is most specific and the record thinnest. WIRED reported in June that NameTag was built to turn faces captured by the glasses into biometric signatures and match them against faceprints in a database on the wearer's phone, which was set up to receive updates from Meta [7]. WIRED could not establish where those faceprints came from [8]. The complaint does not say either. It concedes that Meta has not disclosed which images, if any, were used to generate biometric data, and that the information sits solely with the company [11]. Instead it cites a patent describing face matching against profile photos and other images Meta holds, plus reported employee claims that NameTag could recognise people through their Meta connections or public Instagram accounts [9]. In June Meta told WIRED it was "not building a central face database" and would not say whether NameTag would be opt-in or how long it would keep faceprints [10]. Its statement on the lawsuit says "we are not building a universal face database" [15]. Between June and last week the qualifier changed from central to universal [5]. Under the Illinois Biometric Information Privacy Act the plaintiffs want $5,000 for each intentional or reckless violation, or actual damages if greater, and $1,000 for each negligent one, plus an injunction [5]. Per-violation counting makes these suits expensive. Take one million people out of the complaint's own estimate: at the negligent rate that is $1 billion, and at the reckless rate $5 billion [2]. Meta paid $650 million in 2020 to settle an Illinois class action over an earlier face-recognition system [17] and $1.4 billion to Texas in 2024 [19]. Those two settlements total $2.05 billion [1]. "People shouldn't have to worry if their biometric information will be misused simply because their photographs appear on a social media platform," Justin Boley, a partner at Wexler Boley & Elgersma and an attorney for the plaintiffs, said in a statement [16]. Meta's spokesperson said the suit "is without merit and misrepresents our work" and that on NameTags "nothing has shipped to consumers and no final decision has been made on what to do here, if anything" [15]. For anyone shipping a product built on a user photo library, two questions sort the exposure. The first is whether any step in the pipeline produces a value that identifies a specific person. The second is whether the person that value identifies is the person who saw the consent screen. Where the answer runs yes and then no, exposure is counted in faces, and a photo library holds more faces than a product has accounts. The second question comes down to the consent screen Meta would not describe in June.

What to watch

  • Whether the court certifies a national class or cuts it back to Illinois and California residents.
  • Whether discovery forces Meta to identify which images, if any, produced biometric templates.
  • Whether NameTag ships at all, and if it does, whether the faceprint step is opt-in.
Loading claim ledger
Loading source directory links
Loading share composer
Loading topic controls
Loading related stories