As market for facial recognition software heats up, concerns about how and when facial data is collected remain largely unaddressed due to lack of regulations
While you weren't looking, tech companies helped themselves to your photos to power a facial recognition boom. Here's how.
Context & Ripple Effects
This 2019 Fortune piece is the opening frame of the facial recognition arc: tech companies quietly harvested user photos to train models while no US rule governed how or when face data could be collected. A month later, the FT catalogued the university and government face datasets available on request, showing the training pipeline ran on material few subjects knew was in play.
The gap the article flags then widened fast: by mid-2020 Microsoft and Amazon were themselves lobbying for federal regulation as local bans spread, and Clearview AI's leaked pitch deck revealed a database that had grown past 10 billion photos with a stated path to 100 billion. The collection question raised here became the industry's defining controversy.
First-order effects
- Consumers whose photos powered the boom had no consent mechanism at the time of collection — the article documents that the default was silent use of user-uploaded images for model training.
- Vendors building on scraped face data faced no federal constraint, so database scale became the competitive metric rather than accuracy or compliance.
Second-order effects
- Once Clearview's investor materials exposed the scale of scraping, vendors like Microsoft and Amazon pivoted to calling for federal rules — partly to shape them, partly to differentiate from scrappers.
- Universities and government agencies holding requestable face datasets came under pressure as the supply side of the training pipeline, since their collections fed commercial systems without subject knowledge.
Third-order effects
- With federal regulation still absent years later, the burden shifted to states — by 2025, 23 states had passed or expanded laws restricting mass biometric scraping, fragmenting compliance into a patchwork.
- Even if government use is eventually curbed, the same technology embedded in consumer devices keeps the collection problem alive, meaning regulation of one buyer segment cannot close the gap this article identified.
The trend: Biometric data collection is outrunning federal law, leaving states to legislate scraping piecemeal while the underlying datasets keep growing.