Meta quietly added facial-recognition to smart glasses, public pressure killed it in days. Here's what that cycle means for EU operators.
elcome to issue seven. This week the story resolved faster than anyone expected: Meta shipped facial-recognition code to millions of smart glasses, the internet noticed, and within days the code was gone. That whiplash turnaround is actually the most instructive thing that happened in AI compliance this week, because it reveals how thin the line is between 'quiet software update' and 'full-blown biometric incident'. Stick around for a fake news site that has been inventing EFF staff members, and a US surveillance law that finally, genuinely, expired.
Let’s go.
yours, Flux

Flux Weekly is a 6-minute briefing for people who have to actually make AI work in Europe. Sole traders to enterprise, one issue every Friday morning.

- New We updated our biometric AI vendor checklist this week to flag silent app updates as a specific audit trigger, prompted by the Meta smart glasses code incident.
- Updated Our procurement clause library now includes a 'no biometric feature additions without written notice' template following this week's events.
- ICYMI If you missed issue six's deep dive on why biometric rules apply to software updates and not just hardware launches, it is worth a re-read in light of this week's reversal.
Public pressure strips Meta's facial-recognition code from smart glasses in under a week, proving accountability works when someone is watching

What actually happened. A WIRED report exposed that Meta had embedded facial-recognition technology code inside Meta AI, the companion app for its Ray-Ban smart glasses, capable of converting face images into unique biometric identifiers to identify strangers in real time. The code was live on millions of devices before a single user had consented to anything resembling biometric processing.
Then the reversal. Within days of public outcry and EFF pressure, Meta quietly stripped the code. No formal enforcement action, no fine, no regulator order: pure reputational gravity did the work. For EU operators, this is a case study in why the AI Act's biometric rules exist. The regulation would require conformity assessment and transparency before such a system ever ships, not after journalists notice it.
Does your AI inform a decision that affects a person's job, credit, education, or essential service?

- ✓The Meta smart glasses reversal is a live proof-of-concept for why the AI Act's biometric categorisation rules exist before market placement, not after.
- ✓Surveillance pricing practices exposed in California mirror the AI Act's prohibitions on AI-driven price manipulation that exploits personal data signals.
- ✓Age-verification debates raging across US states track almost exactly the child-safety obligations EU operators already face under the AI Act and DSA combined.
- ~US: Section 702 of FISA expired on 12 June 2026, ending warrantless collection of foreign communications that routinely swept in US persons' data, a genuine civil-liberties milestone.


- 1EU AI Act Explorer (FUTURE EU)reference
An interactive map of the AI Act's articles, recitals, and annexes, searchable by obligation type and deadline.
Why we like it. The biometric categories are buried across multiple annexes; this surfaces them in plain English in one search.
- 2EFF's Surveillance Self-Defenceguide
EFF's longstanding guide to protecting personal data from surveillance technologies, updated regularly.
Why we like it. Understanding the threat model your vendors are responding to helps you write better procurement requirements.
- 3ENISA AI Cybersecurity Guidelinesofficial

The fastest compliance lesson of the year took less than a week to play out
By John Ferguson
I keep telling operators that the AI Act is not primarily about fines. It is about the moment your vendor does something you did not know about, and you have to explain it to a customer, a regulator, or a journalist. Meta gave us a live demonstration of that moment this week.
What strikes me is not that Meta added the code. It is that they assumed nobody would notice. That assumption is the whole problem. The AI Act's transparency and conformity requirements exist precisely to make that assumption untenable before the product ships, not after Twitter finds it.
The reversal happened fast because reputational pressure moved faster than any enforcement timeline. But do not bank on that speed protecting you. If the same thing happened to a mid-sized EU operator, the sequence would look very different: a data protection authority inquiry, a possible AI Act investigation, and months of uncertainty.
My take: spend two hours this week reviewing every vendor app with camera or microphone access in your stack. Ask for written confirmation of what data they process. If they cannot answer clearly, that is your answer. The compliance work is not glamorous, but it is a lot less painful than the alternative.
John Ferguson · Founder, Agentic Fluxus

Short answer.Start with the vendor's release notes and data processing addendum. If those are vague, request a written confirmation that the update introduces no new categories of personal data processing. For any app with camera access, check the permissions changelog. If the vendor cannot answer clearly within a reasonable time, that silence is itself a red flag worth escalating to your DPO.
After the Meta glasses story, what is your biggest vendor risk worry?

A site called News-USA Today has been publishing quotes from EFF staff members including Sarah Chen, Javier Morales, and Emma Rodriguez. None of them exist. The site describes itself as focused on 'clear, accurate, and useful journalism'.
Meta shipped facial-recognition code to millions of smart glasses, waited for the internet to notice, then stripped it out, all within one week. No regulator required.

