Meta's Smart-Glasses App, downloaded by 50 million users, included concealed dormant facial-recognition code that could generate biometric signatures and identify faces instantaneously.

Meta’s Smart-Glasses App, downloaded by 50 million users, included concealed dormant facial-recognition code that could generate biometric signatures and identify faces instantaneously.

Here is the key takeaway Meta would probably prefer you take with you: the code was inactive, it remained unused, and it couldn’t have been activated by users. Within a day of the report that revealed this, much of it was removed.

All of this appears to be accurate, and I believe it also misses the core issue.

The narrative that emerged in June 2026 is more about a feature that was created, completed, and integrated into an application that had already been downloaded by 50 million users — and how closely “off” ended up being to “on.”

The assertion Meta would like you to concentrate on

WIRED and an independent researcher known as Buchodi discovered that the smart-glasses application from Meta included a full facial-recognition system, internally referred to as NameTag. This app connects Ray-Ban and Oakley Meta glasses to a smartphone. The report indicates the code had been embedded in the app as early as January 2026. Meta’s interest in facial recognition was not a secret — The New York Times reported on it in February 2026, yet the presence of completed code on tens of millions of phones was not acknowledged until June.

Meta’s narrative heavily emphasizes one term: dormant. Meta’s VP of communications, Andy Stone, informed WIRED that the feature was merely a pilot project and that the company had not made a “final decision on what to do here, if anything.” It’s fair to state that the feature was not active for users. However, dormant does not equate to absent, nor does it imply incapacity. The engine was in the vehicle; it just wasn’t operational yet.

What the code actually accomplished

This is where the “it never ran” argument begins to feel weak. According to the technical analysis, NameTag operated three AI models on the device, sequentially: the first identified a face within the glasses’ field of view, the second cropped it, and the third transmuted the face into a series of numbers and compared it to a stored list.

The numerical string is the crucial aspect. EFF’s Cooper Quintin, whose team analyzed the code, stated that the system “stores faceprints as a series of 2,048 numbers uniquely representing the positioning of a person’s facial features.” A faceprint acts as a mathematical fingerprint of a face, accurate enough to distinguish one individual from a crowd.

The most incriminating detail is not what the code could theoretically achieve but that it was operational. According to EFF’s report, a researcher enabled the code in debug mode, manually added a face to the database, and the glasses recognized that individual when they reappeared and triggered a notification.

‘Dormant’ is carrying a significant burden

I continually reflect on the distinction between “not enabled” and “not present.” A feature that still requires design, training, and development is years away from your face. A feature already existing on 50 million devices, tested and functioning, is merely one switch away. Meta’s assurances subtly equate those two scenarios as though they were identical.

Quintin clearly outlined the implications: “Meta seems to have created the ability to transform their users into a distributed surveillance network.” The phrase “seems to have” is performing deliberate work: no one claims Meta was covertly scanning strangers in public. The assertion is narrower and harder to dismiss: the capability was primed and ready, and the individuals wearing the glasses would have been the ones conducting the scanning.

What the removal accomplished and what it didn’t resolve

To Meta’s credit, the reaction was prompt. The company released an update on June 5, 2026, one day after WIRED’s report, and removed nearly everything. In its own assessment, EFF stated, “gone is the face-recognition technology, the code meant to trigger ‘Person recognized’ alerts, and the machine learning models and databases designed to detect, digitize, and store the biometric signatures of people users engage with.”

The removal is tangible, but what it resolves is a different question. EFF contends that “this quiet deletion of code does not equal a permanent change of heart.” A switch that is capable of being turned off can be reactivated, and code that has been deployed once can be redeployed.

Kade Crockford, who leads the Technology for Liberty Program at the ACLU of Massachusetts, interpreted the entire situation as an argument for regulation rather than reliance, stating, “Meta’s surreptitious methods in embedding the face-recognition code into its smart glasses illustrate precisely why data privacy legislation requires strong enforcement mechanisms.” That language reflects advocacy, not an impartial judgment. However, the fundamental point is difficult to overlook when considering what preceded it.

Meta’s track record in this regard is extensive and costly. The company discontinued Facebook’s photo-tagging face-recognition system in