Does AI need consent to identify people by name in photos?

Updated 2026-07-151,600 searches/moRanked #216 of 519· AI explained
Short answer

It depends entirely on where you are — there's no single US rule. Illinois requires written consent before capturing a faceprint and lets individuals sue directly; Texas requires consent but only the attorney general can enforce. Most US states have no such law. Clearview AI paid $51.75 million in 2025 over scraped faceprints. This is general information, not legal advice.

Why — the first-principles explanation

The key distinction, and the one that decides your answer, is between a photo and a faceprint. A photo is just an image. A faceprint — the biometric identifier — is a mathematical template extracted from the geometry of a face, precise enough to match that person anywhere. Most laws don't regulate photographs at all. They regulate the extraction step, the moment software converts a face into a template. That's why "can I post this picture?" and "can I run face recognition on it?" have completely different answers.

The reason biometrics get special treatment is a physical fact: you cannot change your face. A leaked password gets reset in thirty seconds. A leaked faceprint is permanent, and it works at a distance, without your knowledge, on a face you can't take off. That asymmetry — permanent, remote, and passive — is the whole justification for consent rules that don't apply to other data.

The US has no federal biometric privacy law, so the map is patchy and jurisdiction is everything. Illinois BIPA is the strong one: it requires notice and written consent before capturing an Illinois resident's biometric identifier, including a faceprint. Its power isn't the rule — it's the private right of action. Individuals can sue directly, which is why the litigation is real: Clearview AI, which built its database by scraping billions of internet images without consent, reached a $51.75 million class settlement approved in March 2025, the largest biometric privacy resolution to date. An earlier 2022 ACLU consent order permanently barred Clearview from selling its faceprint database to most private entities nationwide. Texas has a similar statute (CUBI) but only the attorney general can enforce it — no private suits — which changes the practical risk enormously. Most states have nothing.

There's a second route that catches people out: even with no biometric statute, general consumer-protection law applies. The FTC banned Rite Aid from using facial recognition for surveillance for five years in December 2023 — not under a biometric law, but because deploying a system that falsely flagged shoppers as shoplifters was unfair to consumers. People were wrongly detained and publicly accused, and the system was used disproportionately in neighborhoods with large Black, Latino, and Asian communities. The order forces Rite Aid to notify consumers when their biometric data is enrolled and to delete it. Accuracy and deployment are regulated too, not just consent.

Elsewhere, biometrics are typically special-category data requiring an explicit legal basis under GDPR-style regimes, generally stricter than most of the US.

One asymmetry worth knowing: identifying yourself is not the issue. Tagging your own face, unlocking your own phone — you consented. The legal question arises when you extract a faceprint from someone else who didn't. And the person whose consent matters is the one in the photo, not the person who took it.

An example that makes it click

Think about the difference between a photograph of a house and a copy of its key.

Anyone can photograph a house from the street. That's fine everywhere. But if you take a picture of the lock and machine a working key from it, you've done something categorically different — even though you started with a photo and never touched the door. You now hold something that opens that house forever, from anywhere, without the owner knowing.

A faceprint is the key. The photo is legal almost everywhere; extracting the key from it is what the law reaches for. And the crucial part: the owner can change their lock. Your face doesn't have that option. That's why Illinois demands written permission before anyone cuts a key from your face — and why they let you sue the person who did.

How to do it

  1. Identify the jurisdiction first — it decides everything. Illinois BIPA requires written consent and allows private lawsuits; Texas CUBI requires consent but only the attorney general enforces it; most US states have no biometric statute.
  2. Separate the photo from the faceprint. Storing or posting an image is usually unregulated; extracting a biometric template from it is the act these laws target.
  3. Check whose face it is. Identifying yourself is not the issue — the legal question arises when you extract a faceprint from someone who didn't consent.
  4. If you're building anything that runs face recognition on other people, get written consent, publish a retention and destruction schedule, and don't scrape — Clearview's model produced a $51.75M settlement and a nationwide sales ban.
  5. Under GDPR-style regimes, treat biometrics as special-category data requiring an explicit legal basis; consent standards are generally stricter than most US states.
  6. Consult a licensed attorney before deploying face recognition. This page is general information, the law varies by state and country, and BIPA in particular carries per-violation statutory damages.

Key facts

Infographic: Does AI need consent to identify people by name in photos — short answer and key facts
Visual summary — Does AI need consent to identify people by name in photos?
▶ The 60-second explainer (script)

Does AI need consent to identify people by name in photos? It depends entirely on where you are — and the distinction that decides it is between a photo and a faceprint. A photo is just an image. A faceprint is a mathematical template extracted from the geometry of someone's face, precise enough to match them anywhere. Most laws don't regulate photographs at all. They regulate the extraction step — the moment software turns a face into a template. So can I post this picture and can I run face recognition on it have completely different answers. Why do biometrics get special treatment? One physical fact: you cannot change your face. A leaked password resets in thirty seconds. A leaked faceprint is permanent, works at a distance, without your knowledge, on a face you can't take off. Permanent, remote, passive — that's the whole justification. Now the map, and it's patchy, because the US has no federal biometric privacy law. Illinois BIPA is the strong one: notice plus written consent before capturing an Illinois resident's faceprint. But its real power isn't the rule — it's that individuals can sue directly. Which is why Clearview AI, which scraped billions of internet images to build faceprints, paid a fifty-one point seven five million dollar class settlement approved in March 2025, the largest biometric privacy resolution ever. An earlier consent order permanently barred them from selling that database to most private companies nationwide. Texas has a similar law but only the attorney general can enforce it — no private suits — which changes the practical risk enormously. Most states have nothing at all. And one asymmetry: identifying yourself isn't the issue. Tagging your own face, unlocking your phone — you consented. The question arises when you extract a faceprint from someone else who didn't. This is general information, not legal advice — talk to an attorney before deploying anything.

What authoritative sources say

Federal Trade Commission — Rite Aid Banned from Using AI Facial Recognition After FTC Says Retailer Deployed Technology without Reasonable Safeguardsgov — The FTC barred Rite Aid from using facial recognition for surveillance for five years (announced December 19, 2023), finding it falsely flagged consumers as shoplifters; the order requires notifying consumers when their biometric information is enrolled in a database and deleting biometric information. source ↗
Federal Trade Commission — Coming face to face with Rite Aid's allegedly unfair use of facial recognition technologygov — FTC analysis of why Rite Aid's deployment of facial recognition was unfair to consumers, including erroneous match rates and disproportionate deployment. source ↗
ACLU — Settlement Ensures Clearview AI Complies With Illinois Biometric Privacy Laworg — Illinois BIPA requires companies collecting an Illinois resident's biometric identifier such as a faceprint to first notify the individual and obtain written consent; the May 2022 consent order permanently banned Clearview from making its faceprint database available to most private entities nationwide and barred Illinois state and local government access for five years. source ↗
The Record — Long-running Clearview AI class action biometric privacy case settlesmedia — A federal judge approved a $51.75 million Clearview AI biometric privacy class action settlement on March 20, 2025 — the largest biometric privacy resolution to date. source ↗

People also ask

Is it illegal to run face recognition on a photo I took?

Depends on the state and on whose face it is. In Illinois, extracting a faceprint from an identifiable person requires notice and written consent, and they can sue you directly. In most US states there's no biometric statute. Taking the photo and extracting a faceprint are legally different acts.

Why is Illinois the state everyone mentions?

Because of the private right of action. Other states have consent rules too — Texas requires consent under CUBI — but only Illinois lets individuals sue directly rather than waiting on an attorney general. That's what makes BIPA the one with real litigation behind it.

Does consent come from the photographer or the person pictured?

The person whose face it is. Owning or having taken the photo doesn't give you rights to their biometric template — the laws protect the individual whose face is being converted into an identifier, not the image's owner.

What did Clearview AI actually do wrong?

It scraped billions of images from the internet and extracted faceprints without notice or consent, then sold access. That produced a 2022 consent order permanently barring sales to most private entities nationwide and a $51.75 million class settlement approved in March 2025.

Does this apply to tagging myself in my own photos?

No. Identifying yourself isn't the issue — you consented. The legal question arises when a faceprint is extracted from someone else who didn't agree to it. Unlocking your own phone with your face is the same principle.

Related questions