The New Fingerprint

Introduction A photograph used to be evidence of appearance. Increasingly, it can be a source of data to define who they are.
That distinction is being tested by wearable technology. A proposed class-action lawsuit accused Meta of collecting photos from Facebook and Instagram, using them to develop facial-recognition features for Ray-Ban and Oakley smart glasses, and allegedly violating Illinois’s Biometric Information Privacy Act, or BIPA.¹
The lawsuit is only an allegation, but the underlying legal question is broader: When does an ordinary image become legally protected biometric information?
A Face Is More Than a Photo
Illinois law draws a distinction between a photograph and biometric information. BIPA defines a biometric identifier to include a scan of “face geometry,” while excluding photographs. Biometric information is defined as information based on that biometric identifier that is used to identify an individual.²
That distinction makes sense when biometric technology was relatively specialized. AI makes the boundary hard to maintain. A photo can be analyzed by software, mapped to facial measurements, compared with another image, and used to determine if two photos are the same person. The photo remains a photograph, but the information extracted from it can become something substantially more sensitive.
Why Consent Matters
BIPA is unusual in that it treats biometric information differently from ordinary data. The law generally requires private entities collecting biometric identifiers or information to provide notice, explain the purpose and duration of collection, and obtain written consent.³ It restricts disclosure and requires publicly available policies for destruction of biometric data.
The underlying idea is simple: a password can be changed. A face cannot. That makes biometric information unusually difficult to replace once it is compromised. If a company loses a password, a user can create another one. If a database of facial identifiers is improperly exposed, the underlying identifier remains attached to the individual.
The AI Problem
Artificial intelligence complicates the statute because privacy laws were largely written before consumer AI systems existed.
Consider a pair of smart glasses. The glasses can capture images. Software can analyze the images. An AI system can potentially identify people, recognize the surroundings, and infer information from what the camera sees.
At what point does this become biometric processing? The law may answer that question differently if the technology is just storing an image, analyzing facial characteristics, creating a mathematical representation of a face, or using that representation to identify a person.
The Law Is Chasing the Technology
The problem goes beyond smart glasses. Facial recognition systems are increasingly tied to cameras, smartphones, transportation systems, and other technologies. Voice assistants can analyze speech. Devices can recognize fingerprints and faces. AI systems can derive more sophisticated information from ordinary recordings.
Legislatures are therefore faced with a difficult choice. They can write very broad privacy statutes that capture new technologies but may regulate ordinary information too aggressively. Or they can write narrowly defined statutes providing certainty today but becoming outdated tomorrow.
Illinois chose a middle ground by writing BIPA, specifically identifying categories such as fingerprints, voiceprints, and face geometry. Technology is making those categories less distinct.
The Question of Ownership
Traditional property law asks who owns a physical object. Privacy law increasingly asks something different: who has rights about information about a person?
A company may own the camera. It may own the servers. It may own the software. But that does not necessarily mean it owns the biometric identity extracted from a person’s face. That distinction could become one of the most defining questions in digital privacy law.
People voluntarily create enormous amounts of data every day. They take photos, post videos, send messages, and use devices that constantly collect information. Yet the information derived from those actions can reveal far more than the original user intended.
Why It Matters
Biometric information is fundamentally different from other data because it is tied to the body. AI means companies can extract increasingly sensitive information from material that looks innocuous at the surface. A photo can become a facial template. A voice recording can become a voiceprint. A video can become a database of identifiable people.
Privacy law must therefore regulate what companies collect, but also what they can derive from the information. That is where the next generation of privacy disputes will likely be fought.
Conclusion
The central problem with biometric privacy is not that technology can recognize a face. It is that technology can recognize a person without them realizing what has been extracted from the image.
Illinois’s BIPA was written to give people control over some of the most permanent information about themselves. AI is testing whether those protections were written broadly enough. The law can define a photo, although it is a lot harder to define the identity that hides inside it.
Doe v. Meta Platforms, Inc., proposed class action, N.D. Ill., filed Sept. 4, 2026.
740 ILCS 14/10. Illinois defines “biometric identifier” to include a scan of face geometry while excluding photographs; “biometric information” includes information based on a biometric identifier used to identify an individual.
740 ILCS 14/15(b). The statute generally requires informed written consent before a private entity collects or otherwise obtains biometric identifiers or information.



Comments