Meta NameTag Face RecognitionCode Existed in Meta AI App

A forensic analysis of the Meta AI app uncovered dormant NameTag face recognition code on millions of devices.

By Central
Meta's NameTag face recognition code was found hidden in the Meta AI app, though Meta claims it is not functional.
Highlights
  • NameTag is a face-recognition pipeline designed to identify people a user has met while wearing Meta's smart glasses.
  • Security researcher confirmed the code could recognize faces, including a photograph of philosopher Michel Foucault.
  • Meta removed the code from the app within 24 hours after WIRED's report, suggesting it was more than abandoned work.

Meta Face Recognition Code Found Hidden in Meta AI Smart Glasses App

Meta’s public relations machinery has spent weeks trying to argue that a software feature does not exist if users cannot activate it, but a detailed examination of the company’s Meta AI application tells a very different story. The feature in question is NameTag, an in-development face-recognition system built specifically for Meta’s Ray-Ban smart glasses. A forensic analysis of the Meta AI companion app—downloaded tens of millions of times—revealed robust, technically functional code for NameTag sitting dormant on users’ devices as early as January 2025.

What Is NameTag and How Does It Work

NameTag is a face-recognition pipeline designed to identify people a user has met previously while wearing Meta’s smart glasses. Based on code discovered in the Meta AI app, the system is designed to capture a photograph of a person’s face through the glasses’ camera, match it against a locally stored database of faces the user has manually tagged, and display the individual’s name. The system does not connect to any central database of identities and is intended to function only when the glasses are actively being worn. The core components of this detection-and-matching pipeline were present and assembled in the app by May 2025.

Meta’s Conflicting Statements on the Feature’s Existence

Meta’s Vice President of Communications, Andy Stone, publicly stated that NameTag does not exist, arguing that WIRED could not expect detailed answers about a feature that was not available. Yet only weeks later, Meta’s Chief Technology Officer, Andrew Bosworth, spent several minutes describing the feature in detail on a podcast, explaining that it would identify “somebody you met in person with your glasses on who introduced themselves.” When confronted with this apparent contradiction, Meta pointed to Bosworth’s conditional language—specifically his use of the word “would”—to claim the feature remains purely hypothetical. The company continues to stress that the capability is not currently available to consumers.

Independent Code Analysis Confirms Functionality

At WIRED’s request, a security researcher known as Buchodi reviewed the NameTag code embedded in the Meta AI application. The analysis demonstrated that the code was capable of successfully performing face recognition: it recognized a photograph of the philosopher Michel Foucault, famously known for his writings on surveillance and power. The code was removed from the application within 24 hours of WIRED’s initial report, an action that itself suggests the feature was more than abandoned internal work. Meta had been developing NameTag since early 2025, licensing third-party face-recognition software and integrating it into the app that runs on millions of phones worldwide.

What This Means for User Privacy and Security

The presence of inactive but fully constructed face-recognition code on millions of consumer devices raises significant questions about the lifecycle of software features and user consent. A face-recognition system embedded in a camera-equipped wearable device, even when dormant, represents a latent privacy risk. While Meta insists that NameTag is designed only to identify people a user has already met and tagged, the broader implication is that the foundational technology for real-time facial identification at scale is already deployed in the field. Security-conscious users should be aware that the underlying hardware and software capability exists, and that the decision to activate it rests entirely with the manufacturer.

How to Protect Your Privacy When Using Smart Glasses

For users in the US, UK, Australia, and Canada who own or are considering Meta’s smart glasses, practical steps can reduce privacy exposure. First, review the app permissions granted to Meta AI and revoke access to the camera and photo library if the functionality is not actively needed. Second, ensure the app and device firmware are kept up to date, as security patches may address unauthorized local access to sensor data. Third, consider using a reputable no-log VPN service when the glasses are connected to public Wi-Fi, as this encrypts the data stream between the device and Meta’s servers. Finally, users should regularly audit what data Meta has stored about them through the company’s privacy dashboard.

What Affected Users Should Do Now

Meta has demonstrated that it can deploy, remove, and potentially reactivate face-recognition code on devices it does not fully own. The most immediate action for anyone using the Meta AI app is to check for the latest version and install it, as Meta has confirmed it removed the NameTag code in a subsequent update. Beyond that, users should treat any camera-equipped wearable as a device that can be repurposed for surveillance without their knowledge. The strongest practical defense is to use a paid VPN with a verified no-logs policy when transmitting data from the glasses, and to treat the device’s camera as an untrusted sensor until the company provides binding, verifiable commitments about how it handles biometric data.

Share This Article