Meta Smart Glasses Facial Recognition: What We Know
Security researchers found functional Meta smart glasses facial recognition code in Meta AI, the companion app that pairs with Meta's Ray-Ban Display Glasses and Oakley's Meta Glasses. The code could convert a stranger's face into a reusable biometric signature and flag the wearer when that person came back into view. Meta pushed an app update that stripped the code out within roughly 48 hours of the discovery becoming public, according to EFF.
What matters here is timing, not just capability. EFF's Threat Lab verified the system through static analysis of the app in June and found the code "present and active," but not something an ordinary user could turn on (EFF).
One researcher only got it working by plugging a phone into a computer in debug mode and manually adding a face to the database. What Meta had built was a testable capability inside the companion app, not a feature exposed to ordinary customers.
What Meta smart glasses facial recognition could do
EFF said the code was designed to convert faces captured through the glasses into biometric templates, stored as a series of 2,048 numbers representing the geometry of a person's features, then check them against a user's existing database (EFF). A match would trigger a "Person recognized" alert. EFF ties this Meta AI app facial recognition code to an internal Meta project reported by WIRED, one the company referred to internally as the NameTag facial recognition system.
The June 5 update appears to have removed the recognition functions, the alert mechanism, and the machine-learning models and databases behind them, according to EFF's follow-up review (EFF). That's a quick turnaround, given the code was already active in the app rather than confined to internal planning documents.
What remains open is what happens next. EFF reported that Meta declined to answer WIRED's questions about whether it intends to revive the project or what became of any biometric data collected during internal testing (EFF). Its plans, and its handling of that test data, remain unknown outside that account.
Why face-matching raises the stakes
Ordinary video recording captures what happened. Face-matching turns that footage into searchable identity data, a different category of risk. A coalition of 75 organizations led by the ACLU, the ACLU of Massachusetts, and the New York Civil Liberties Union warned Meta CEO Mark Zuckerberg in an April letter that glasses with this capability could let a wearer identify a stranger by name at a protest, a medical clinic, or a business, then connect that name to information about their job, health, and relationships (ACLU).
The coalition's letter singled out people of color, immigrants, religious minorities, and LGBTQ+ people as especially vulnerable, and argued the technology would erode the anonymity people rely on simply walking down a street (ACLU). "The principle here is quite simple," ACLU senior staff attorney Cody Venzke said in the release. "Your glasses should not know my name."
EFF also cites an internal Meta planning document, reported by WIRED, that reportedly favored launching the feature "during a dynamic political environment where many civil society groups that we would expect to attack us would have their resources focused on other concerns" (EFF). That's a reported internal document describing a preference, not a confirmed launch plan. It indicates the feature was being considered inside Meta, not that a rollout is guaranteed to return.
This isn't the company's first retreat from face recognition under pressure. Meta paid $650 million in 2020 to settle a biometric-privacy lawsuit over photo-tagging facial recognition on its main platform. The settlement followed the lawsuit, and Meta later shut that feature down; EFF frames the pattern as one where Meta backed off only after facing legal and financial consequences (EFF).
What the facial-recognition removal did not change
The facial-recognition functions appear to be gone from the app, for now. Several other Meta smart glasses privacy concerns involve data flows that have nothing to do with facial recognition and were untouched by its removal. No AI feature runs locally on the device, according to EFF, so invoking an AI feature, such as saying "Hey Meta, start recording," sends that footage to Meta's servers for processing (EFF).
Media captured on the glasses stays on the device until it's imported, and it imports automatically by default into the Meta AI app unless the user is livestreaming (EFF). Some of that footage feeds AI training, and EFF cites Swedish newspaper reporting that human reviewers annotated sensitive footage, including nudity, at least in some cases (EFF).
The data can travel further once footage reaches the phone's camera roll: depending on a user's own backup settings, it may sync separately to Apple's or Google's servers, a pathway that has nothing to do with Meta (EFF). Audio from Meta AI conversations is also saved by default unless a user goes in and deletes each entry manually (EFF). None of it required facial recognition to exist, and none of it changed when the code came out.
What owners can control, and what bystanders can't
Owners aren't without options, though EFF describes the available controls as limited: "a couple of features" can be turned off where unnecessary data gets sent to Meta (EFF). One of those is the "Cloud media" setting in the Meta AI app's privacy page, which stops photos and video from being sent to Meta's servers for processing and temporary storage (EFF).
That toggle has a limit worth knowing. It doesn't move AI processing onto the device, since no AI feature runs locally at all. Anyone who invokes a voice command or asks for AI analysis is still sending that data off the glasses, regardless of the Cloud media setting.
Bystanders have no equivalent lever. The glasses are built to pass as ordinary eyewear, and reviewers have repeatedly noted that friends didn't realize cameras were built in until told (EFF). The visible signal that recording is happening is a small indicator light, and EFF notes that cheap hacks exist to disable even that.
The ACLU-led coalition cited that lack of bystander control as a reason the glasses would pose additional risks if face-matching returned (ACLU).
What's still unresolved
Meta built, tested in debug mode, and then removed facial recognition code from its smart glasses app within roughly 48 hours of public exposure, a feature that never reached ordinary consumers (EFF).
Whether Meta retains any biometric data from that internal testing, or brings the project back in some form, remains unanswered. The reporting cited here does not address those questions beyond noting that Meta declined to answer WIRED's queries on the matter.
EFF says it will keep watching, writing that Meta's facial-recognition ambitions "probably aren't going away" even after this rollback (EFF). That leaves a narrower question for whoever reports on this next: whether Meta has abandoned the NameTag system for good, or simply pulled the code that had become public until the next attempt.



Comments
Be the first, drop a comment!