A proposed class action lawsuit alleges that Meta illegally harvested millions of Facebook and Instagram photos to train its AI image-generation models and to develop an unreleased face-recognition feature called NameTag. The complaint argues that Meta used user-generated content without explicit consent or compensation, violating privacy laws and terms-of-service obligations.
This case represents a growing legal challenge to how tech companies acquire training data. Unlike previous privacy disputes, this litigation directly targets AI training practices and raises questions about whether existing user agreements provide sufficient legal cover for training foundation models.
What This Means for Your Business
If your company collects user data or plans to train proprietary AI models, this lawsuit signals that regulators and courts are increasingly skeptical of broad consent clauses. You should audit your data collection practices, user agreements, and training procedures to ensure they clearly disclose AI training and obtain explicit consent where required by law. For companies in the EU, GDPR already imposes strict requirements; U.S. courts appear to be moving in the same direction. Consider updating privacy policies and obtaining opt-in consent for AI training, especially for sensitive data like images or biometric information.