Parents and their children from Illinois and California filed a proposed class action in federal court in Chicago last week, alleging that Meta illegally used their Facebook and Instagram photos to build NameTag, an unreleased face-recognition system for its smart glasses, and to train generative AI models including Emu and Muse Image. The suit claims the company violated state privacy laws by extracting biometric information without notice or consent. The case matters because it tests whether images users post for social purposes can be turned into the raw material of a face-recognition product.
What the lawsuit alleges
The plaintiffs are Francisco Alvarez and his son, both Illinois residents, and Jeremy Wahl, a California resident, and his 10-year-old daughter. The proposed class covers people in Illinois, California and across the United States whose images were uploaded to Facebook or Instagram or submitted to Meta's generative AI systems through prompts, dating back to September 4, 2021. The complaint estimates the national class could number in the millions. Under the Illinois Biometric Information Privacy Act, the plaintiffs seek $5,000 for each intentional or reckless violation, or actual damages if greater, and $1,000 for each negligent violation, or actual damages if greater, plus injunctive relief; the California claims seek additional damages and other relief. The complaint acknowledges that Meta has not disclosed which images, if any, were used to generate biometric data, saying that information remains solely in the company's possession.
The claim about NameTag rests on reporting that Meta employees said the feature could recognize people through their Meta connections or public Instagram accounts, and on a company patent describing face matching against profile photos and other images held by Meta. WIRED reported in June that code for NameTag had been embedded in the Meta glasses AI companion app, downloaded more than 50 million times. The feature was not enabled for users, but the analysis found the system was designed to turn faces captured by the glasses into biometric signatures and compare them with faceprints stored in a database on the user's phone, configured to receive updates from Meta. At the time, WIRED could not determine where the underlying faceprint data came from. Meta said in June it was not building a central face database, but would not answer whether NameTag would be opt-in or how it would retain faceprints.
The suit also targets Meta's image-generation systems. Meta has said it trained Emu on large quantities of Facebook and Instagram images and text, with chief product officer Chris Cox calling those platforms a data advantage for its AI systems. The complaint alleges the training process illegally harvested biometric information about people who appeared in the images. Muse Image, released this summer, had earlier drawn criticism after allowing users to generate images based on other people's public Instagram accounts, a feature removed within days after the company said it had missed the mark. The day after WIRED's June 4 report, Meta removed the NameTag code from its app, arguing the feature never existed because it was not available to consumers, even though WIRED's analysis and testing by outside researchers found a technically functional face-recognition system inside an app downloaded by tens of millions of people. Meta CTO Andrew Bosworth called the reporting incredibly misleading and absolutely dishonest, and weeks later described NameTag on a podcast as able to recognize people a glasses wearer had previously met and asked the device to remember, calling it a great feature.
What this means for business
For companies that use Meta's advertising or AI tools, the practical consequence is a new layer of legal risk attached to the image and video assets they already hold. The complaint's proposed class reaches back to September 4, 2021, which means content uploaded years ago can fall inside the period at issue. A small business that posts customer photos to Instagram has no way to verify whether those images were used for model training; a large advertiser with a media library of millions of assets faces the same uncertainty at greater scale. The $5,000 and $1,000 per-violation figures in the Illinois claim show how quickly statutory damages can accumulate when a class is measured in millions of people, and they set a benchmark for how other vendors' data practices may be priced by courts.
What the lawsuit does not establish is that Meta actually used any specific person's photos for biometric data. The complaint itself says the company has not disclosed which images, if any, were used, and Meta says nothing has shipped to consumers and no final decision has been made on NameTag. That gap matters for anyone evaluating vendors: the questions to ask are whether a supplier can document the provenance of training data, whether consent for biometric processing was collected separately from the terms of service, and whether an opt-in mechanism exists for features that identify people. Meta's own history sets the reference point. In 2020 the company agreed to pay $650 million to settle an Illinois class action over an earlier face-recognition system; in November 2021 it said it would shut that system down and delete more than a billion faceprints; in 2024 it agreed to pay Texas $1.4 billion over separate allegations of unlawful biometric collection.
The marker to watch is whether the court certifies the proposed class covering users in Illinois, California and the rest of the United States back to September 4, 2021. Certification would turn an individual complaint into a proceeding whose damages exposure is calculated across millions of accounts, and it would give other platforms a concrete measure of the cost of using social images for model training without separate consent. Until then, the practical signal for business is the direction of Meta's own product decisions: the NameTag code was removed from the app the day after the June 4 report, and the Muse Image feature that generated images from public Instagram accounts was withdrawn within days, which indicates that public and legal pressure is already shaping what ships.
