Liability Lives In Code
7 stories · ~7 min read

If You Only Read One Thing
The most consequential privacy move today is not a launch. It is installed potential. Meta Ships the Switch and X Wants Corporate Amnesia both show companies trying to separate capability from obligation: code can sit dormant, and data orders can be called stale. Buchodi's teardown is the must-read because it turns "not shipped" into a concrete systems question.
Meta Ships the Switch
Meta's best defense is also the problem. The company says its smart-glasses face-recognition feature has not shipped to consumers. The code review shows much of the infrastructure already has.
Security researcher Buchodi inspected version 273.0.0.21 of Meta's Stella Android app, the companion app for Meta smart glasses, and found three on-device face models, a local database schema, a 2048-dimension vector index, a write path that stages biometric records to disk, and a notification channel for recognized people. WIRED separately reported that the Meta AI companion app has been downloaded more than 50 million times and is necessary for key smart-glasses features. Meta told WIRED that no final decision has been made and that it is not building a central face database.
Why it matters: The old privacy fight was about collection. The new fight is about pre-positioned capability. If a company ships the models, schema, write path, and notification surface before the public product exists, regulators and users have to decide whether "not enabled" is a meaningful boundary.
Buchodi's evidence is unusually specific. The app contains face detection, alignment, and embedding models; the embedding model produces a 2048-number biometric fingerprint; the SQLite vector table is dimensioned to match that output; and unrecognized faces can be written as both cropped images and .emb files in a NameTagsPending folder. In a test, Buchodi invoked the existing handler directly, loaded a single face into the index, and triggered a production notification reading "Person recognized."
That is not the same as proving Meta is identifying strangers today. Buchodi is explicit on that point: he did not observe the feature active for ordinary users or Meta pushing identity data to his test account. The structural fact is narrower and more important. A consumer platform can distribute a controversial capability in pieces, hold activation server-side, and then argue that regulation should wait for launch.
Meta has history here. It said in 2021 that it would delete more than a billion faceprints from Facebook's photo-tagging system, after years of pressure over biometric collection. WIRED notes the company paid $650 million to settle an Illinois class action and later agreed to a $1.4 billion Texas settlement over biometric-data allegations. The smart-glasses version is more sensitive because bystanders are not Facebook users uploading photos. They are people in the field of view of someone else's camera.
The strongest business rationale is real. Face recognition can be useful for accessibility, memory, workplace assistance, and social context. The problem is not that a wearable computer might help a blind user identify someone who opted in. The problem is that a mass-market glasses platform changes the social default: faces in public become queryable objects, and consent becomes something the wearer and platform manage rather than something the subject controls.
Room for disagreement: Meta can fairly argue that on-device processing, local faceprints, and no central database are better than cloud recognition. It can also argue that engineering exploration is not product deployment and that regulators should evaluate the actual release design, not dormant code.
That argument weakens when the apparatus is already coherent. Detection, embedding, vector search, pending storage, and notifications are not stray strings in an APK. They are the difference between a vague roadmap and a gated capability. The question is not whether Meta has launched NameTag. It is whether platform power should be judged only at the moment a server flag flips.
What to watch: Watch whether Meta removes the face-recognition pipeline from public app builds, or instead publishes a formal opt-in and bystander-consent design before its next smart-glasses hardware cycle. Removal would signal caution; disclosure would signal that launch is still the plan.
X Wants Corporate Amnesia
X is making a privacy argument that sounds like a corporate-law argument. The company says the FTC's Twitter order should be set aside because Twitter no longer exists in the relevant sense.
The FTC said on June 3 that it is seeking public comment on X Corp.'s petition to set aside or modify the 2022 order, with comments due July 2. X argues that the order was imposed on a company that no longer exists, that the individuals responsible for the failures are gone, that X has built a stronger privacy program, that the order imposes needless costs, that setting it aside safeguards First Amendment values, and that modifying it is important for American AI leadership. The order currently runs beyond 2026 unless changed.
Why it matters: This is a test of whether data obligations attach to corporate continuity or to information systems. X wants the FTC to treat past violations as tied to an old organization and old managers. The FTC's problem is that the underlying asset is not the letterhead. It is a user-data machine now plugged into advertising, subscriptions, Grok, and a Musk corporate stack that has already moved through X, xAI, and SpaceX.
The 2022 case was not minor. The FTC and DOJ charged Twitter with using phone numbers and email addresses collected for account security to sell targeted ads. The agency said more than 140 million users had provided that information after being told it would help secure accounts. Twitter paid a $150 million penalty, was banned from profiting from deceptively collected data, and had to implement privacy and information-security programs that examined new-product risks.
That last clause is the live wire. New-product risk review is exactly what a merged social, AI, and space-infrastructure company wants to avoid when data becomes model fuel and distribution. TechCrunch reported in February that SpaceX acquired xAI, which had already absorbed X, as part of Musk's push toward AI infrastructure and orbital data centers. The corporate tree changed, but the user-data substrate did not become less valuable.
The most revealing part of X's petition is the AI-leadership claim. Privacy compliance is being reframed as industrial-policy drag: audits and order obligations are no longer merely legal burdens, they are said to divert engineers from national AI competition. That is a strong rhetorical move because it borrows the Trump administration's AI-speed vocabulary. It also proves why the order matters. If user data is strategic AI infrastructure, then the governance of that data cannot be treated as obsolete paperwork.
Room for disagreement: Consent orders can become stale. A decree written for a 2022 advertising abuse may not fit every 2026 product, especially after ownership, management, architecture, and global privacy law have changed. If X truly has a better privacy program, the FTC should be willing to tailor obligations rather than preserve compliance rituals for their own sake.
The counterargument is that X is not asking for tailoring in a vacuum. It is asking as the same user base becomes more central to AI training, real-time information products, and a broader Musk financing story. Corporate restructuring should not work as a privacy bankruptcy. If a company can merge its way out of a data order, every consent decree becomes a temporary nuisance before the next reorganization.
What to watch: The July 2 comment deadline is the signal. If privacy groups, state AGs, or European regulators use the docket to tie X's petition to Grok data use and SpaceX-xAI consolidation, the FTC will have a record for preserving the order while narrowing only genuinely outdated provisions.
The Contrarian Take
Everyone says: Meta and X are simply trying to dodge accountability: Meta by hiding face recognition in an app, X by escaping an FTC order.
Here's why that's wrong, or at least incomplete: The more important story is that both companies are testing the boundary between capability and responsibility. Meta can say the feature is dormant. X can say the company is different. Those are not frivolous claims. The structural issue is that modern platforms can move faster than the old trigger points: code ships before launch, data obligations survive but get relabeled, and policy has to decide whether liability starts at activation, collection, distribution, or design.
Under the Radar
-
S&P kept the front door closed. S&P Dow Jones Indices rejected fast-track changes for the S&P 500, leaving the 12-month seasoning period, financial-viability screen, and minimum float requirement intact for marquee benchmarks. The undercovered twist is that broader total-market indexes did change, so passive exposure is not blocked; it is routed into lower-prestige, broader-market plumbing. (Source)
-
Supabase sold the agent substrate. Supabase announced a $500 million Series F at a $10 billion pre-money valuation, while its backers framed the company as the default Postgres backend for AI-generated apps. The interesting claim is not the valuation. It is that agents now deploy the majority of databases on the platform, which turns backend defaults into agent-era distribution.
Quick Takes
-
Utah cut the data-center map. Kevin O'Leary agreed to cut the proposed Stratos data-center project area in Box Elder County from about 40,000 acres to about 20,000 acres, with roughly half of the remaining area preserved, after Utah Senate President Stuart Adams demanded a sharper reduction and water protections. AI infrastructure is discovering local veto points before federal policy catches up. (Source)
-
Canada chose trust as industrial policy. Canada's new AI strategy says 150,000 jobs are already directly associated with AI, targets up to 250,000 new jobs from AI adoption by 2031, and aims to lift business AI adoption from 12% today to 60% by 2034. The sovereignty story is less about a national model and more about compute, literacy, power, and procurement. (Source)
-
Apple let agents into Messages. TechCrunch reported that Poke became the first AI agent approved for Apple's Messages for Business platform. That is a small consumer story with a platform-structure implication: Apple may prefer verified agents inside its messaging rails to a free-for-all of agent apps competing for the post-app interface. (Source)
The Thread
Today's thread is that liability is moving inside infrastructure. Meta's facial-recognition dispute is not only about a future product; it is about code already installed on phones. X's FTC petition is not only about an old consent order; it is about whether data duties follow an asset through corporate reshuffling. S&P's index decision, Utah's data-center backlash, and Canada's AI strategy are versions of the same pattern. Institutions are deciding whether power should be governed when it is proposed, built, switched on, or monetized.
Predictions
New predictions:
- I predict: By 2026-08-31, at least one U.S. state attorney general, federal lawmaker, or EU privacy authority will send Meta a formal inquiry or demand letter about NameTag or facial recognition in smart glasses, citing the shipped companion-app code rather than only leaked roadmap documents. (Confidence: medium; Check by: 2026-08-31)
Coming Next Week
Next week, the SpaceX IPO becomes the live test of passive-index discipline, founder control, and AI-infrastructure valuation. We will also know whether Apple's WWDC agent story is a distribution strategy or another Siri reset.
2026-06-05 03:17 EDT
Tomorrow morning in your inbox.
Subscribe for free. 10-minute read, every weekday.