The Weights Are the Violation: Inside the BIPA Class Action That Claims Meta's AI Models Themselves Are Illegal
A 66-page Illinois class action says training Emu and NameTag on Facebook photos made the model weights themselves biometric data — a legal theory that, if it survives, reaches every lab that trained on human faces.
On September 4, 2026, a 66-page class action complaint landed in the U.S. District Court for the Northern District of Illinois — and unlike most AI training lawsuits, this one does not stop at the training data. It argues that the finished model itself is the violation.
The suit, Alvarez et al. v. Meta Platforms, Inc. (Case No. 1:26-cv-10773), was filed on behalf of Illinois resident Francisco Alvarez and his minor son, and California resident Jeremy Wahl and his minor daughter. It accuses Meta of harvesting photographs from Facebook and Instagram to build two very different systems without notice or consent: NameTag, the facial-recognition feature developed for Meta’s Ray-Ban and Oakley smart glasses, and its family of text-to-image generators — Emu, CM3leon, Chameleon, and Muse Image. WIRED’s September 11 reporting brought the filing to wide attention, but the complaint’s most consequential claim is the one buried in its “generative AI” section: that when Meta trained its image models on photos containing faces, the training process “results in the creation and storage of biometric identifiers and information within the models themselves.”
If an Illinois federal court lets that theory survive a motion to dismiss, the implications extend far past Menlo Park. Every frontier lab that has ever trained an image model on photographs of people — which is to say, all of them — becomes a plausible target under the Biometric Information Privacy Act, Illinois’s famously uncompromising 2008 privacy statute.
The suits Meta has already lost
To understand why this complaint is dangerous for Meta, it helps to remember that the company has been here before — and lost, repeatedly.
The complaint’s own history section walks through the lineage: the Cambridge Analytica scandal, which ended in a settlement over improperly shared user data; a $650 million settlement of Illinois BIPA claims stemming from Facebook’s old photo-tagging facial recognition; and a $1.4 billion settlement with the State of Texas over its facial-recognition capture of biometric identifiers — at the time, the largest privacy settlement ever secured by a single state.
The new filing opens with a still older callback. In 2003, it notes, a 19-year-old Harvard student named Mark Zuckerberg scraped classmates’ ID photos without permission to build Facemash, a “Hot or Not” clone. The complaint frames two decades of privacy controversy as “not an aberration, but the foreseeable consequence of a business model that has for over 20 years depended on collecting, analyzing, and monetizing ever-greater amounts of personal data.”
What NameTag was supposed to be
According to the filing, Meta had been weighing facial recognition for its smart glasses since before the first Ray-Ban Stories shipped in 2021. It quotes a 2021 interview in which Meta CTO Andrew Bosworth — now CEO of Meta’s Reality Labs hardware division — conceded the technology was “really a debate we need to have with the public”: “If people don’t want this technology, we don’t have to supply it. The product is going to be fine either way.”
That public debate, the plaintiffs argue, never happened. Instead:
- Meta “originally scrapped the facial recognition feature” for the first Ray-Ban Meta glasses over ethical concerns — but by 2025, per the complaint, “a more business friendly Federal Trade Commission under the new Trump Administration had emboldened Meta to reboot its plans for the next generation of smart glasses.”
- In February 2026, the New York Times reported that the feature — internally called “Name Tag” — would let glasses wearers identify strangers and pull information about them through Meta’s AI assistant. The story cited an internal Reality Labs memo suggesting the launch take advantage of “political tumult in the United States,” when “civil society groups that we would expect to attack us would have their resources focused on other concerns.”
- In April 2026, an ACLU-led open letter co-signed by 75 organizations urged Meta to “immediately halt and publicly disavow” the feature, warning that NameTag would let “anyone wearing a pair surveil and profile every person they encounter — without those people ever knowing,” and would inevitably “exacerbate abuse, harassment, and stalking of women, girls, and LGBTQ+ people.”
- In June 2026, code for NameTag was discovered dormant inside the Meta AI companion app, drawing renewed scrutiny; the code was quietly removed once the discovery drew attention.
The complaint also cites Meta’s own “supplemental” terms of service, which attempt to shift the legal burden onto users: wearers, not Meta, are “responsible for … providing any notice to or obtaining any consents from other individuals” under biometric and recording laws. The plaintiffs characterize this as an attempt to “outsource” an obligation Meta has admitted is impossible to fulfill — because there is no realistic way to obtain meaningful consent from every stranger a glasses wearer passes.
The novel theory: weights as biometric data
The heart of the complaint — and the reason it matters to the entire industry — is its account of what happens inside a diffusion model during training.
Training image generators on photos containing faces, the plaintiffs argue, is not a transient act that ends when the training run completes. Citing how these models “extract information associated with the facial features,” convert it into numerical representations, and “associate that numerical representation with personally identifiable information, such as a name,” the complaint contends that Emu and Muse Image encode identity-linked facial geometry into their parameters. The model weights, in this reading, are themselves a container of biometric identifiers — a persistent, copyable, exportable artifact of millions of people’s face geometry that Meta never had permission to create.
Under BIPA, that distinction is everything. The statute’s private right of action attaches to the collection and storage of biometric identifiers without informed written consent, with statutory damages of $1,000–$5,000 per violation. If a court accepts that “storage” includes storage inside model parameters, the exposure is effectively unbounded: Meta has stated publicly that its image models were trained on “billions of images,” including posts and photos from Facebook and Instagram — a figure the complaint quotes from Meta’s own Privacy Center. The filing also notes the well-documented fact that Emu alone was trained on at least 1.2 billion image-text pairs.
The complaint adds a second, less theoretical layer: at inference time, when a user submits a photo of a face to one of Meta’s models, the system likewise “creates and stores a biometric identifier” of the person in that image — meaning the alleged violations are not confined to the past but potentially ongoing with every use.
The Muse Image rollout gives the claims concrete anchors. When Meta launched Muse Image on July 7, 2026, it shipped with a feature allowing users to @-mention any public Instagram account and pull that person’s likeness into AI-generated images. After immediate backlash — one post flagged by the complaint called it “a privacy landmine waiting to detonate” — Meta withdrew the @-mention feature from Instagram within days, while the identical capability remained available through the Meta AI app and website.
The legal road ahead
The claims rest on the Illinois Biometric Information Privacy Act, California misappropriation and publicity law, and the privacy clause of the California Constitution. No damages figure is disclosed — a telltale sign that the plaintiffs expect the number to be determined by discovery.
Three open questions will shape what happens next.
First, will the “weights contain biometric identifiers” theory survive the pleadings stage? BIPA jurisprudence has already stretched once before: Illinois courts have held that “scans” of face geometry occur even when a system extracts them algorithmically rather than photographically. Extending that logic to model parameters is a bigger step, but not an unthinkable one. A ruling either way would be the first authoritative word on whether trained models are data-processing artifacts or clean-room works.
Second, where will the case live? Meta will almost certainly try to move it to California under its choice-of-law provisions, as it has in past BIPA litigation — a maneuver Illinois courts have rejected before, and which a February 2026 DLA Piper analysis notes already failed in an earlier BIPA class action against the company.
Third, is this an isolated filing or a wave? It may already be a wave. Within four days of Alvarez, a separate Cook County suit was filed against xAI, alleging that Grok’s AI photo-editing collects users’ facial geometry without BIPA consent — and similar claims against Google’s Gemini photo tools were filed in July. The same plaintiff-firm ecosystem that extracted $650 million from Meta over photo tagging is now aiming at model training itself.
Why it matters beyond Meta
For the AI industry, Alvarez is the clearest test yet of a question regulators have mostly dodged: is a trained model a copy of its training data, legally speaking?
Labs have long treated training as a one-way function — data goes in, statistical patterns come out, and the original data is “consumed.” Copyright litigation is already challenging that framing for text. Alvarez challenges it for faces, under a statute with per-violation statutory damages and no cap, in a state with the strongest biometric privacy law in the country. And unlike copyright, where fair use provides at least a defensive framework, BIPA has no fair-use carve-out at all — only consent, or the absence of it.
The first motion to dismiss is the tell. If the Northern District of Illinois lets the theory stand, every image model trained on human faces — and every open-weights release of one — inherits a legal cloud that no amount of post-hoc deletion can lift. Deleting a training image does not delete what the model learned from it, as Meta’s own privacy documentation candidly admits: “If you delete a piece of information a model learned from … the model won’t change in that moment.”
That sentence, written by Meta for its own users, may turn out to be the most expensive paragraph in the complaint.
Sources
- [1] https://www.wired.com/story/meta-sued-over-training-data-for-its-ai-and-face-recognition-systems/
- [2] https://www.biometricupdate.com/202609/meta-sued-over-alleged-facial-recognition-training-for-smart-glasses
- [3] https://www.biometricupdate.com/wp-content/uploads/2026/09/Alvarez_et_al_v_Meta_Platforms_Inc__ilndce-26-10773__0001.0.pdf
- [4] https://aiweekly.co/alerts/meta-sued-over-nametag-and-emu-ai-training-in-illinois
- [5] https://sigmalawgroup.com/blog/2026-09-09-meta-xai-bipa-ai-training-photos
- [6] https://www.law360.com/articles/2522682/xai-hit-with-ill-biometric-privacy-suit-over-grok-photos