AI beauty try-ons: fun interface, heavy data footprint
AI beauty try-on privacy concerns focus on virtual makeup tools that map, record, and process detailed images of a user’s face to simulate cosmetics, often collecting biometric data and linking it to shopping or account information in ways consumers do not clearly see or understand.
The core problem is not that AI-powered lipstick pickers exist; it is that the personal care industry is racing them into stores, apps and chatbots without matching them with strong, transparent privacy practices. Beauty brands are chasing colorful new ways to sell products, while the legal and ethical rules for biometric data lag behind. That gap is exactly what the MAC Cosmetics lawsuit puts under a spotlight: when your face becomes input, the stakes are higher than a smudged eyeliner look.
In this landscape, virtual makeup tools data is no longer a harmless selfie; it is a potential biometric identifier that can be combined with purchase histories, profiles and AI-driven personalization, creating a rich — and legally sensitive — picture of who you are.

What the MAC lawsuit exposes about consent and biometrics
MAC’s pending class action is the clearest warning yet that beauty brand lawsuits are no longer about faulty products, but about data practices baked into AI tools. A customer claims MAC collected imagery of her facial geometry and biometric data via its in-store and online virtual try-on tool without adequate disclosure or written consent, and a judge refused to throw the case out.
The company argued that biometric laws cover only data that can identify a person and claimed the plaintiff had not shown MAC could link try-on data back to her. The court disagreed for now, finding it “plausible” that MAC could identify her when virtual makeup tools data is paired with her customer account, especially given the commercial incentives to track who tries what and what turns into a sale.
This is not an isolated flare-up. A Kenvue subsidiary, Neutrogena, has already agreed to a proposed USD 4.7 million (approx. RM21.9 million) settlement over similar allegations, signaling that biometric-focused facial recognition makeup cases are building momentum rather than fading away.

A fast-moving industry, slow-moving safeguards
The MAC case is a symptom of a wider trend: the personal care industry’s deployment of AI tools is exposing legal vulnerabilities around consumer consent and data privacy. Brands are embracing AI-powered imagery and personalization at scale while relying on consent flows and privacy notices that were never designed for face-scanning algorithms.
According to consulting expert Ceren Canal Aruoba, the MAC data privacy lawsuit hinges on the intricacies of consumer consent and on what people reasonably understand from a company’s disclosures in practice. Many customers focus on the immediate benefit — seeing a shade on their face — and underestimate what is happening under the hood, from facial geometry capture to profile linkage.
This tension is fertile ground for litigation. Statutory frameworks that allow claims without proof of actual harm, combined with scalable AI tools that log every interaction, create strong incentives for class actions when facial recognition makeup systems are rolled out without clear guardrails.

L’Oréal’s ChatGPT try-on: convenience wrapped around biometric questions
Into this already fragile trust landscape, L’Oréal is bringing Maybelline’s Makeup Virtual Try-On directly into ChatGPT, powered by its ModiFace augmented reality and AI beauty technology. With ChatGPT reporting more than 900 million weekly active users and over 50 million subscribers, this single integration could expose AI beauty try-on privacy issues to an enormous audience.
ModiFace lets people test makeup looks digitally, which by design means processing facial images and geometry. Pair that with AI-assisted shopping, product discovery and advertising pilots, and the line between a playful filter and a biometric profiling engine becomes thin. Virtual try-on services may raise biometric privacy concerns not because they are evil, but because they often lack clear answers to basic questions: what facial data is captured, how long is it stored, is it linked to identities or purchase histories, and can it be repurposed for advertising or research?
When beauty tech and conversational AI merge inside a single interface, beauty brands must treat facial recognition makeup as sensitive infrastructure, not a novelty overlay.
What consumers should do before letting AI near their face
The harsh truth is that consumers cannot afford to treat AI try-ons as harmless toys. The MAC case shows how facial geometry capture can be invisible at the moment of use, leaving people unaware that biometric identifiers may be collected and linked to their accounts. That gap in understanding can make consent look formal on paper but hollow in practice.
Aruoba notes that people often place more weight on the immediate utility of the tool than on the underlying data practices, thanks to limits in attention and decision-making. According to her, this discrepancy between consumer comprehension and the technical operation of AI-powered personalization may lead to a designation of lacking informed consent.
If you choose to use virtual try-ons, you should assume your face is being measured, not just mirrored. Ask what virtual makeup tools data is collected, how it is stored, whether it is tied to your profile, and how to opt out. Until brands prove they can handle biometric data responsibly, skepticism is not paranoia; it is self-defense.






