Meta is back in federal court over privacy, and this time the allegations go well beyond the usual data-sharing complaints. A class action lawsuit filed September 4, 2026, in the U.S. District Court for the Northern District of Illinois accuses the company of harvesting facial images and biometric data from Facebook and Instagram users, without telling them, to train generative AI models and build an internal facial recognition system called NameTag.
The suit was filed by Wexler Boley & Elgersma LLP on behalf of Illinois resident Francisco Alvarez, California resident Jeremy Wahl, and others, including minors. The plaintiffs allege violations of the Illinois Biometric Information Privacy Act, known as BIPA, as well as California privacy statutes.
What NameTag is, and why its existence is the problem
NameTag is a facial recognition feature designed for use with Ray-Ban and Oakley AI smart glasses, meaning it would theoretically let someone point a pair of glasses at a stranger and identify them. Code for the feature was discovered in Meta’s companion app in early June 2026, then quietly removed after the discovery attracted media attention, including reporting from WIRED.
The lawsuit alleges that Meta extracted what it calls biometric identifiers, essentially digital faceprints, from user-uploaded photos and created stored templates from those images. Critically, the complaint covers not just registered users but also non-users whose faces appeared in photos uploaded to the platforms. The proposed class covers images uploaded since at least September 4, 2021.
BIPA requires Illinois companies to get explicit written consent before collecting biometric data, and to publish a public retention policy. The lawsuit claims Meta did neither.
Meta has publicly acknowledged using data from Facebook and Instagram posts to train AI models going back to at least 2007, including for its Emu image generation model.
BIPA, precedent, and why Illinois is the lawsuit magnet
BIPA has become the go-to statute for biometric privacy litigation in the United States, partly because it allows individual plaintiffs to sue for statutory damages without proving actual harm.
Meta has been here before. The company settled a previous BIPA case over its “Tag Suggestions” photo feature, and separately paid $725 million in 2022 to resolve claims related to the Cambridge Analytica scandal, though that settlement came with no admission of wrongdoing. The Tag Suggestions case established that Illinois residents have standing to sue over automated facial recognition even when no obvious harm occurred.
One wrinkle Meta will likely lean on is its claim that NameTag processes data on-device rather than on centralized servers. Some legal interpretations of BIPA hinge on whether a company “possesses” biometric data in a traditional sense, meaning local processing could complicate the plaintiffs’ argument.
What investors and the broader tech sector should watch
Meta’s legal exposure here extends in two directions. First, there is the direct financial risk. BIPA allows damages of $1,000 per negligent violation and $5,000 per intentional or reckless violation, and class actions under BIPA have resulted in some of the largest privacy settlements in U.S. history.
Second, a ruling in the plaintiffs’ favor would set a precedent that restrains how any tech company uses social media imagery for AI training. Companies like Google, Apple, Amazon, and a long list of AI startups have built computer vision and generative AI systems on similar foundations.
Disclosure: This article was edited by Editorial Team. For more information on how we create and review content, see our Editorial Policy.

1 hour ago
20








English (US) ·