메뉴
BL
Wired AI • 14일 전

메타, AI 학습·안면인식 데이터에 사진 불법 사용으로 집단소송

IMP
8/10
핵심 요약

일리노이·캘리포니아 주민들이 메타를 상대로 집단소송을 제기, 페이스북·인스타그램 사진을 동의 없이 생체정보로 추출해 미공개 안면인식 시스템 '네임택(NameTag)'과 생성형 AI(Emu, Muse Image) 학습에 사용했다고 주장했습니다. 원고측은 일리노이 생체정보보호법(BIPA)에 따라 위반당 최대 5,000달러의 배상을 청구하며, 집단소송 대상이 수백만 명에 달할 수 있습니다.

번역된 본문

일리노이와 캘리포니아에 거주하는 부모와 자녀들이 지난주 시카고 연방법원에 메타를 상대로 소송을 제기했다. 이들은 메타가 페이스북과 인스타그램 사진을 불법적으로 사용해 스마트 glasses용 미출시 안면인식 시스템인 '네임택(NameTag)'을 구축하고, Emu와 Muse Image 등 생성형 AI 모델을 학습시켰다고 주장한다. 제기된 집단소송은 메타가 통지나 동의 없이 사람들의 사진에서 생체정보를 추출함으로써 일리노이 및 캘리포니아 개인정보보호법을 위반했다고 지적한다.

와이어드(WIRED)는 6월, 네임택 코드가 5,000만 회 이상 다운로드된 메타 안경 AI 동반 앱에 비밀리에 삽입되어 있다고 보도했다. 이 기능은 앱 사용자에게 활성화되지 않았지만, 분석에 따르면 이 시스템은 안경으로 촬영된 얼굴을 생체 서명(biometric signature)으로 변환하고, 사용자 휴대폰의 데이터베이스에 저장된 이른바 '페이스프린트(faceprint)'와 비교하도록 설계되었다. 이 데이터베이스는 메타로부터 업데이트를 받도록 구성되어 있었다. 당시 와이어드는 이 페이스프린트 데이터의 출처를 확인할 수 없었다.

소장은 이 페이스프린트가 페이스북과 인스타그램 이미지에서 파생되었을 가능성이 있다고 주장한다. 메타 직원들이 네임택이 메타 연결 또는 공개 인스타그램 계정을 통해 사람을 인식할 수 있다고 주장했다는 보도, 그리고 프로필 사진 및 메타가 보유한 기타 이미지와의 얼굴 매칭을 설명하는 회사 특허가 그 근거로 제시되었다. 메타는 6월 와이어드에 "중앙 얼굴 데이터베이스를 구축하고 있지 않다"고 밝혔지만, 네임택이 옵트인 방식이 될지, 시스템이 페이스프린트를 어떻게 보관할지에 대한 질문에는 답하지 않았다. 소장은 메타가 생체데이터 생성에 어떤 이미지가 사용되었는지(사용되었다면) 공개하지 않았으며, 그 정보는 오직 회사만 보유하고 있다고 인정한다.

이 소송은 메타의 이미지 생성 시스템도 겨냥한다. 메타는 Emu를 대량의 페이스북·인스타그램 이미지와 텍스트로 학습시켰다고 밝혔으며, 제품 총책임자 크리스 콕스(Chris Cox)는 이 플랫폼들을 AI 시스템의 "데이터 우위"라고 불렀다. 소장은 이 학습 과정에서 이미지에 등장한 사람들의 생체정보가 불법적으로 수집되었다고 주장한다. 올여름 출시된 Muse Image는 다른 사람의 공개 인스타그램 계정을 기반으로 이미지를 생성할 수 있게 해 비판을 받았으며, 회사는 "기대에 미치지 못했다"고 인정하며 며칠 만에 해당 기능을 제거했다.

메타 대변인은 성명에서 "이 소송은 근거가 없으며 우리의 업무를 왜곡하고 있다. 우리는 AI 제품을 구축하고 개선하기 위해 사람들의 정보를 어떻게 사용하는지 투명하게 공개해 왔다. 네임택의 경우 소비자에게 출시된 것이 없으며, 무엇을 할지에 대한 최종 결정이 내려지지 않았다"고 말했다. "무언가를 출시하기로 결정한다면 신중한 접근과 완전한 투명성으로 진행할 것이다. 분명히 말할 수 있는 한 가지는, 우리는 보편적인 얼굴 데이터베이스를 구축하지 않는다는 것이다."

원고 측 변호사이자 Wexler Boley & Elgersma 파트너인 저스틴 볼리(Justin Boley)는 성명에서 "사람들은 자신의 사진이 소셜미디어 플랫폼에 게시되었다는 이유만으로 생체정보가 오용될까 걱정하지 않아도 될 권리가 있다"고 말했다.

원고는 일리노이 거주자인 프란시스코 알바레즈(Francisco Alvarez)와 그의 아들, 캘리포니아 거주자 제러미 왈(Jeremy Wahl)과 그의 10세 딸이다. 제안된 집단소송에는 2021년 9월 4일 이전부터 페이스북이나 인스타그램에 이미지를 업로드했거나 프롬프트를 통해 메타의 생성형 AI 시스템에 제출한 일리노이, 캘리포니아 및 전미 국민들이 포함된다. 소장은 전국 단위 집단이 수백만 명에 달할 것으로 추정한다. 원고들은 일리노이 생체정보 프라이버시법(BIPA)에 따라 고의적 또는 과실적 위반당 각각 5,000달러 또는 1,000달러(실제 손해액이 더 클 경우 그 금액)와 금지명령(injunctive relief)을 구하고 있다.

원문 보기
원문 보기 (영어)
Comment Loader Save Story Save this story Comment Loader Save Story Save this story A set of parents and their children in Illinois and California filed a lawsuit last week in federal court in Chicago alleging that Meta illegally used their Facebook and Instagram photos to build NameTag , an unreleased face-recognition system for its smart glasses, and to train generative AI models including Emu and Muse Image . The proposed class action alleges that Meta violated Illinois and California privacy laws by extracting biometric information from people’s photos without notice or consent. WIRED reported in June that code for NameTag had been secretly embedded in the Meta glasses AI companion app, which had been downloaded more than 50 million times. While the feature had not been enabled for users of the app, the analysis found that the system was designed to turn faces captured by the glasses into biometric signatures and compare them with so-called faceprints stored in a database on the user’s phone. That database was configured to receive updates from Meta. At the time, WIRED could not determine where the underlying faceprint data came from. The complaint alleges that those faceprints are possibly derived from Facebook and Instagram images, citing reporting that Meta employees claimed that NameTag could recognize people through their Meta connections or public Instagram accounts, along with a company patent describing face matching against profile photos and other images held by Meta. Meta told WIRED in June that it was “not building a central face database,” but it would not answer questions about whether NameTag would be opt-in or how the system would retain faceprints. The complaint acknowledges that Meta has not disclosed which images, if any, were used for generating biometric data, saying that information remains solely in the company’s possession. The suit also targets Meta’s image-generation systems. Meta has said it trained Emu on large quantities of Facebook and Instagram images and text, with chief product officer Chris Cox calling those platforms a “data advantage” for its AI systems. The complaint alleges that the training process illegally harvested biometric information about people who appeared in the images. Muse Image, released this summer, had earlier drawn criticism after allowing users to generate images based on other people’s public Instagram accounts, a feature the company removed within days after saying it had “missed the mark.” “This lawsuit is without merit and misrepresents our work. We've been transparent about how we use people's information to build and improve our AI products. As for NameTags, nothing has shipped to consumers and no final decision has been made on what to do here, if anything,” a Meta spokesperson says in a statement. “If we do decide to roll something out, we will take a thoughtful approach and do so with full transparency. One decision we can be clear about—we are not building a universal face database.” “People shouldn’t have to worry if their biometric information will be misused simply because their photographs appear on a social media platform,” Justin Boley, a partner at Wexler Boley & Elgersma and an attorney for the plaintiffs, said in a statement. The plaintiffs are Francisco Alvarez and his son, both Illinois residents, and Jeremy Wahl, a California resident, and his 10-year-old daughter. But the proposed class includes people in Illinois, California, and across the United States whose images were uploaded to Facebook or Instagram or were submitted to Meta’s generative AI systems through prompts, dating back to September 4, 2021. The complaint estimates that the national class could number in the millions. Under Illinois’ Biometric Information Privacy Act, the plaintiffs are seeking $5,000 for each intentional or reckless violation, or actual damages if greater, and $1,000 for each negligent violation, or actual damages if greater, as well as injunctive relief. The California claims seek additional damages and other relief. This is not the first time Meta has faced fines over its handling of biometric data. In 2020, the company agreed to pay $650 million to settle an Illinois class action over an earlier face-recognition system. In November 2021, the company announced that it would shut down the system and delete more than a billion faceprints. In 2024, Meta agreed to pay Texas $1.4 billion to resolve separate allegations that it had unlawfully collected biometric data from users. The day after WIRED’s June 4 report about NameTag, Meta removed the code from its app. The company argued that the feature never existed because it was not available to consumers, even though WIRED’s analysis and testing by outside researchers found a technically functional face-recognition system shipped inside an app downloaded by tens of millions of people. Meta CTO Andrew Bosworth called WIRED’s reporting “incredibly misleading” and “absolutely dishonest.” Weeks later, Bosworth described NameTag on a podcast , saying it could recognize people that a glasses wearer had previously met and had asked the device to remember. “I think [it] would be a great feature,” he said. Meta continued to describe NameTag as something it was exploring rather than a product available to consumers. The complaint frames the case as part of a much longer pattern of privacy violations from Meta. Reaching back into Facebook’s earliest days, it cites a 2004 chat in which CEO Mark Zuckerberg reportedly referred to people who had trusted him with their data as “dumb fucks.” Updated 9/11/2026 at 3:09 pm EDT: Added comment from Meta.