Families Sue Meta Over Claims It Used Facebook Photos to Build Secret Face Recognition
A federal lawsuit filed in Chicago accuses Meta of harvesting faceprints from millions of user photos without consent to power NameTag and two AI image systems.

Key points
- Families in Illinois and California filed a federal lawsuit against Meta in Chicago alleging illegal use of Facebook and Instagram photos for face recognition and AI training.
- The suit targets NameTag, an unreleased face-recognition feature for Meta's smart glasses, plus AI image generators called Emu and Muse Image.
- Under Illinois' Biometric Information Privacy Act, a state law giving residents specific rights over biological identifiers such as fingerprints and facial measurements, Meta faces up to $5,000 per intentional violation.
- Meta paid $650 million in 2020 and $1.4 billion in 2024 to settle separate biometric data claims in Illinois and Texas.
- The proposed class action could cover millions of people whose photos appeared on Facebook or Instagram from September 4, 2021 onwards.
Two fathers and their children walked into federal court in Chicago last week and accused Meta of doing something most users never agreed to: scanning their family photos, extracting facial measurements, and feeding that data into AI systems.
The proposed class action, first reported by Wired, targets three Meta projects: NameTag, a face-recognition system designed to work with Meta's Ray-Ban smart glasses; and Emu and Muse Image, two AI tools that generate pictures from text descriptions.
What did Meta allegedly do with people's photos?
The lawsuit says Meta pulled biometric identifiers from photos on both platforms without telling users or asking permission. NameTag is the sharpest point of the complaint. Wired's analysis in June found that code for the feature had been quietly built into Meta's glasses companion app, downloaded more than 50 million times. The system was designed to turn faces captured by the glasses' camera into a mathematical faceprint, then compare it against a database on the user's phone, configured to receive updates from Meta's servers.
Meta removed the code the day after Wired's report. The company said the feature never existed because it was never switched on for users, even though independent researchers confirmed a working version was shipped inside the app. It's worth reading that sentence twice: a functional face-recognition system rode along in an app held by tens of millions of people, and Meta's position is that it doesn't count because nobody flipped the switch.
Meta's CTO Andrew Bosworth called Wired's original reporting "incredibly misleading" and "absolutely dishonest," then described NameTag on a podcast as something that could recognise people a glasses wearer had previously met and asked the device to remember. "I think it would be a great feature," he said. We've been tracking the privacy questions around these glasses since July; our 21 August story found that spotting a recording pair in the wild is harder than most people expect.
On the AI training side, Meta's chief product officer Chris Cox publicly called the platforms a "data advantage" for training Emu. Muse Image drew separate criticism this summer after briefly letting users generate pictures based on other people's public Instagram accounts, a feature Meta pulled within days.
Meta denies the claims. "This lawsuit is without merit and misrepresents our work," a company spokesperson said. "We are not building a universal face database."
What does this mean for ordinary people?
If you posted photos of yourself or your children on either platform after September 4, 2021, the lawsuit's proposed class likely includes you. No action is needed at this stage; courts decide whether a case can proceed as a group claim before individuals need to act. Illinois residents could receive $1,000 to $5,000 per violation if it succeeds.
This isn't Meta's first collision with biometric privacy law. The company paid $650 million in 2020 to settle an earlier Illinois face-recognition case and agreed to delete more than a billion stored faceprints. In 2024 it paid Texas $1.4 billion over similar allegations.
Paying and moving on without admitting wrongdoing, twice, and still arriving at a third complaint is the real story here. Each new product cycle seems to re-ask the same consent questions Meta has already lost money over. Watch whether this case forces a genuine opt-in mechanism, or produces another nine-figure cheque and no structural change.



