By the time 50 million had installed Meta’s smart-glasses app, few knew what sat unused inside it: dormant facial-recognition code that could spot a face, build a biometric signature, and flash ‘person recognised’ the instant it saw someone
Here is the line Meta would probably like you to walk away with: the code never ran, it was dormant, and users could not have triggered it. Within a day of the reporting that exposed it, most of it was gone.
All of that is, as far as I can tell, true. And I think it is also beside the point.
The story that broke in June 2026 is less about a feature that was switched off than about one that was built, finished, and shipped inside an app that 50 million people had already downloaded — and about how close “off” turned out to be to “on.”
The claim Meta will want you to focus on
WIRED and an independent researcher who goes by Buchodi found that Meta’s smart-glasses app carried a complete facial-recognition system, named internally as NameTag. This is the app that connects Ray-Ban and Oakley Meta glasses to a phone. The reporting says the code had been sitting in the app as early as January 2026. Meta’s interest in facial recognition was not itself a secret — The New York Times had reported in February 2026 but the fact that finished code was already loaded onto tens of millions of phones went unacknowledged until June.
Meta’s framing leans hard on one word: dormant. Meta’s VP of communications, Andy Stone, told WIRED the feature was only a pilot effort and that the company had not made a “final decision on what to do here, if anything.” Fair enough that the feature was not live for users. But dormant is not the same as absent, and it is not the same as incapable. The engine was in the car. It just wasn’t running yet.
What the code actually did
This is where the “it never ran” defense starts to feel thin. According to the technical breakdown, NameTag ran three AI models on the phone itself, one after another: the first spotted a face in the glasses’ view, the second cropped it, and the third turned the face into a string of numbers and checked it against a stored list.
The string of numbers is the key detail. EFF’s Cooper Quintin, whose team examined the code, wrote that the system “stores faceprints as a series of 2,048 numbers uniquely representing the positioning of a person’s facial features.” A faceprint is essentially a mathematical fingerprint of a face, precise enough to pick one person out of a crowd.
The most damning detail is not what the code could do in theory but that someone got it to work. According to EFF’s account, a researcher put the code into debug mode, added a face to the database by hand, and the glasses recognised that person when they came back into view and fired a notification.
‘Dormant’ is doing a lot of heavy lifting
I keep coming back to the gap between “not enabled” and “not there.” A feature that still has to be designed, trained, and built is years away from your face. A feature already sitting on 50 million phones, tested and working, is one switch away. Meta’s reassurance quietly treats those two states as if they were the same thing.
Quintin put the stakes plainly: “Meta seems to have created the capacity to turn their customers into a distributed surveillance machine.” The “seems to have” is doing deliberate work: nobody is claiming Meta was secretly scanning strangers on the street. The claim is narrower, and harder to shrug off: the capability was ready to go, and the people wearing the glasses were the ones who would have been doing the scanning.
What the removal did and didn’t settle
To Meta’s credit, the response was fast. The company shipped an update on June 5, 2026, one day after WIRED’s report, and stripped out nearly all of it. In its own analysis, EFF said “gone is the face-recognition technology, the code meant to trigger ‘Person recognized’ alerts, and the machine learning models and databases designed to detect, digitize, and store the biometric signatures of people users engage with.”
The removal is real, but what it settles is another matter. EFF argues that “this quiet deletion of code does not equal a permanent change of heart.” A switch that can be turned off can be turned back on, and code that shipped once can ship again.
Kade Crockford, who directs the Technology for Liberty Program at the ACLU of Massachusetts, read the whole episode as an argument for regulation rather than trust, saying “Meta’s sneaky tactics in slipping the face-recognition code into its smart glasses show exactly why data privacy bills need the teeth of strong enforcement.” That is advocacy language, not a neutral verdict. But the underlying point is hard to dismiss when you look at what came before.
Meta’s history here is long and expensive. The company shut down Facebook’s photo-tagging face-recognition system in late 2021, deleting over a billion faceprints. It paid a $650 million settlement over privacy claims in Illinois, and later a $1.4 billion settlement with Texas over the same discontinued system.
EFF frames the pattern bluntly, arguing this “whiplash behavior proves exactly why we cannot rely on the ‘good will’ of Big Tech to protect our digital rights.”









