What the NameTag Discovery Means
The Meta AI privacy scandal centers on a hidden feature called NameTag, a face-recognition system embedded in the Meta AI companion app that quietly shipped to tens of millions of phones, raising urgent questions about biometric data, user consent, and how mobile app security issues are disclosed. WIRED’s reverse-engineering work showed that Meta had bundled dormant face-recognition libraries into its app, internally labeled NameTag, which could create local “faceprints” from people’s faces. These components were present in app builds that supported Ray-Ban and Oakley smart glasses, turning ordinary phones into potential hubs for device-side identification. Although Meta described the work as exploratory, users were never informed that this capability sat inside an app installed more than 50 million times. The result is a Meta AI privacy scandal that surfaced only after outside researchers went looking for it, rather than through proactive disclosure.

How NameTag Reached 50 Million Phones
According to WIRED’s analysis, NameTag code began shipping in the Meta AI app as early as January 2026, long before any public launch of a face-recognition feature. The app, which pairs with Meta’s Ray-Ban and Oakley smart glasses, has been downloaded more than 50 million times, meaning its dormant modules reached a massive user base. Researchers identified three AI models and UI traces capable of detecting faces, cropping them, and encoding them into faceprints stored on users’ devices. One quotable finding from the reporting is that “three AI models already delivered to phones” established a ready-made pipeline for biometric identification. Even though Meta had not activated NameTag for public use, the technical scaffolding for real-time recognition and notifications was present on everyday devices, turning what might have been internal testing into an immediate public privacy concern.
Why Hidden Face Recognition Is a Privacy Red Flag
Hidden face-recognition code changes the risk picture even when it is labeled as dormant. For everyday users, the problem is not only what NameTag could do, but that it arrived without clear notice or opt-in. The Meta AI app already requested camera and microphone permissions to support smart glasses, so the presence of NameTag blurred the line between legitimate functionality and a potential NameTag app vulnerability. Privacy groups warned that such a system could enable stalkers or abusive partners to track people in public, while security researchers called the rollout “nearly ready to go” because the key components were already in place. This gap between app permissions, user awareness, and the actual data collection infrastructure shows how quickly assistive technology can slide into everyday surveillance when transparency is missing or delayed.
Meta’s June Code Removal and What It Doesn’t Solve
After WIRED exposed the embedded NameTag modules, Meta released a June 2026 update that removed almost all of the face-recognition libraries from the Meta AI app. This face recognition code removal reduced immediate risk, but it did not answer key questions. Meta called the feature exploratory and declined to explain how long any captured images or faceprints might have been stored locally, whether any were uploaded, or whether NameTag could return in a different form. For regulators and users, the quiet code purge highlights a pattern: ship dormant modules to production, then retract them only after scrutiny. That approach undermines confidence in mobile app security and makes it harder to trust that the version in your pocket matches the public description. Removal is a step, not closure, for a Meta AI privacy scandal still under investigation.
How Users and Lawmakers Should Respond
The NameTag episode shows that relying on app store descriptions and permission prompts is not enough to protect biometric privacy. Users should review which apps control their camera, microphone, and Bluetooth connections, especially when those apps integrate with smart glasses, and be ready to uninstall software that carries unclear features. Lawmakers and regulators, meanwhile, are likely to focus on stricter consent rules, audit rights, and penalties when companies deploy biometric pipelines without clear disclosure. Privacy advocates argue that “shipping the building blocks before public debate risks normalizing surveillance,” a warning that goes beyond any single Meta AI privacy scandal. A more transparent future would include public testing programs, independent security reviews of dormant code, and detailed transparency reports whenever experimental biometric features are pushed to large user bases.






