Meta's Ray-Ban smart glasses sold over 7 million units in 2025, tripling the prior year's numbers. The company is now targeting production of up to 30 million pairs a year. These are not niche gadgets. They look like ordinary Ray-Bans, they are worn in offices, airports, shops, and streets, and they carry live cameras.
The app that connects those glasses to a phone had something hidden inside it. Journalists found dormant code for a face-recognition system called NameTag. It was not active for users, but security researchers described it as being "one switch away" from going live. Meta removed the code on June 5, a day after the findings were published.
That same app also contained remnants of software from Rank One Computing, a Denver company that makes face-recognition tools for the US Marshals Service, the Navy's investigative branch, and Special Operations Command. Rank One developed technology capable of identifying a face from a kilometer away under a government research contract. About 80 percent of its revenue comes from government clients. Its chief executive previously ran the FBI division responsible for the bureau's biometric databases. Its board includes former senior CIA and FBI officials.
The license Meta acquired from Rank One supports up to 10 million facial profiles and includes a check that confirms whether a camera is seeing a real person rather than a photo. None of it was ever active for users. Meta declined to explain why it licensed the software, when the arrangement began, or whether it is still ongoing.
This is not a new story for Meta. In 2020, it paid $650 million to settle claims it scanned faces in photos without user consent in Illinois. In 2024, it paid $1.4 billion to Texas for the same kind of conduct, the largest privacy settlement ever secured by a single US state. Meta has denied wrongdoing in both cases. The $1.4 billion figure is being paid out over five years.
The pattern worth understanding is this: a feature is built, it sits waiting, it gets discovered, it gets removed, and eventually a settlement follows. What is different this time is the form factor. Previous violations involved photos uploaded to a social platform. This involves a camera mounted on a pair of glasses that is worn in public, around people who never agreed to be scanned and are unlikely to notice the small indicator light on the frame.
In 2024, two Harvard students proved the point without any help from Meta. They connected the glasses' camera feed to third-party face-search tools and identified strangers on a subway, pulling up names, addresses, and phone numbers in real time. They built nothing unusual. They just connected tools that already existed.
There are no federal rules in the United States governing how companies can use face recognition. Some states require police to obtain a warrant. A few, like Illinois, restrict private companies from using it without consent. Most do not. Consumer-facing companies are moving faster than regulation.
For anyone who manages people, facilities, or customer interactions, the relevance is straightforward. Wearable cameras are becoming normal. The technology to identify faces at scale is available and being actively developed for consumer products. Whether your staff, your customers, or people walking through your premises could be identified without their knowledge is no longer a science-fiction question. It is a product-development question being worked on right now, by a company with 50 million phones already running its companion app.