What Meta launched on 7 July

Muse Image is the first image generation model designed entirely in-house by Meta Superintelligence Labs, Meta’s own AI laboratory, led by Alexandr Wang and built through mass recruitment since 2025. Free for ordinary use (heavier use being reserved for Meta’s paid tiers), the tool is integrated into the Meta AI app, into more than 30 new effects for Instagram Stories, and into direct conversations with Meta AI on WhatsApp. Facebook, Messenger and advertising via Meta Advantage+ were due to follow “in the coming weeks”. The rollout started in the United States for the Stories effects, and in a limited number of countries for WhatsApp.

Technically, the tool can handle complex text instructions, merge several photos into a single image, make targeted edits without regenerating everything, and even produce QR codes or legible text inside an image. A video model, Muse Video, was already announced as the next step.

The mechanism that lit the fuse

None of that would have been enough to trigger the controversy. The problem came from one specific feature, grafted onto Muse Image: any user could mention a public Instagram account’s handle in a Meta AI prompt and obtain an image generated from that account’s photos, including a depiction of the person’s face in a scene entirely made up.

That feature was on by default for all public adult accounts — no need to accept it, tick it or even discover it. Only private accounts and accounts belonging to users under 18 were automatically excluded. In the notification, Meta’s policy was unambiguous: the person whose face is used “will not be notified of content created using Meta’s AI features” — not “not immediately”, not “unless they ask”: never.

To turn the feature off, you had to open Instagram, go to Profile > Menu > Sharing and reuse, then manually switch off the “Posts”, “Reels” and “Reels audio” toggles. A three-click setting, but buried in a submenu most users never open. And even once turned off, that setting only applied going forward: images already generated while the feature was active stayed in circulation, with no recourse.

Three minutes to make a deepfake: the demonstration that said it all

The most telling proof did not come from an expert report, but from a journalistic test. Minutes after access opened, CNET journalist Katelyn Chedraoui typed the Instagram handle of her colleague Abrar Al-Heeti into Meta AI and obtained, with no authorisation requested by the platform, an image depicting her dressed as a pirate. Chedraoui then asked her colleague’s permission before publishing the image in her article — but nothing in the tool’s own operation obliged her to ask anything before generating it.

That is exactly the scenario described by the video circulating on social media: a stranger, on the other side of the country or the world, taking public photos and manufacturing a scene that never happened.

The outcry in 72 hours

The reaction was swift and came from every profession concerned with people’s likenesses. SAG-AFTRA, the union representing around 160,000 American actors and media professionals, urged its members to opt out immediately, calling the choice of automatic opt-in “a complete misreading of public sentiment about dangers that were entirely obvious”. The talent agency CAA went further, publicly demanding that protection be the default setting, and the use of a person’s likeness the exception, subject to their explicit agreement.

On the consumer advocacy side, JB Branch, of Public Citizen, summed the situation up in a sentence: “Meta has once again chosen the creepiest possible path.” He added: “People should not wake up to find their face has become a raw material for AI,” before calling on the US Congress to legislate for explicit prior consent. Haley McNamara, executive director of the National Center on Sexual Exploitation, was blunter still: “How could this have been signed off? [Meta] is creating obvious and foreseeable opportunities for exploitation, sexual abuse, harassment and impersonation.” The fears were explicitly about the production of non-consensual sexual imagery, including of celebrities.

The 10 July withdrawal, and what it does not change

Under that accumulated pressure, Meta announced on Friday 10 July 2026 that the mention/remix feature was “no longer available” on Instagram, acknowledging that it had “missed the mark”. CAA welcomed “Meta’s swift decision to withdraw the Muse Image feature”, and SAG-AFTRA called the reversal “a responsible decision”.

But an analysis published by Forbes the following day adds an important nuance, verified by Le Recul: only the consumer-facing, viral feature was withdrawn. The integration of Muse Image into Meta Advantage+, the automated advertising platform for advertisers, was never suspended and is continuing its rollout “in the coming weeks”. In other words, the technical capacity to turn public photos into AI-generated content remains fully operational on the advertising side — without the same union pressure or the same media coverage that protected the celebrities represented by CAA and SAG-AFTRA. The small advertisers, agencies and creators who use these kinds of tools have no equivalent organisation to carry their objections.

And above all: the images already generated during the 72 hours it was active do not disappear with the feature’s withdrawal. Meta has announced no measure to identify them or have them taken down.

And if you are in France?

With around 28.2 million users at the start of 2026 according to We Are Social/Meltwater, Instagram is the third most used social network in France. Muse Image’s initial rollout targeted Stories in the United States and WhatsApp in a limited number of countries, with no official confirmation of availability in France or the European Union for the generation tool itself. But that geographical limitation only protects you halfway: a public Instagram account held by someone in France could, during those 72 hours, be mentioned and exploited by any user who did have access to the tool elsewhere in the world. The victim’s nationality or location was never a criterion of protection.

On the substance, France’s CNIL is watching Meta’s AI practices closely. Since late May 2025, the company has already been training its models on the public posts (text, photos, comments) of adult European users of Facebook and Instagram, with a right to object available through a dedicated form. But that right to object only covers the content you publish yourself — not photos of you published by third parties. That is exactly the gap Muse Image’s mention mechanism exploited: whatever your own privacy settings, as long as someone else has a public photo of you, it could serve as raw material.

The European regulator with jurisdiction over Meta remains the Irish Data Protection Commission, the company’s GDPR lead authority through the one-stop-shop mechanism — not the CNIL directly, even though it is following the file. On top of that comes a more technical compliance question: Muse Image’s “Content Seal” watermark is machine-readable but invisible to the naked eye, which could sit in tension with the obligation to label AI content depicting real people clearly and visibly, provided for by the European AI Act from 2 August 2026 — three weeks after Muse Image’s launch.

Meta and biometric data: the bill already exists

This is not the first time Meta has had to answer for the use of its users’ faces without sufficient consent. In 2023, the company paid 68.5 million dollars to settle a class action brought in Illinois, the only American state with a binding law on biometric data (the Biometric Information Privacy Act, or BIPA). At issue: Instagram’s facial recognition feature, active from 2015 to 2021, which suggested identifications of people in photos without sufficient consent according to the claimants. Around 4 million Illinois residents were covered, for an average payment of around 32.56 dollars each.

Muse Image does not fall under the same legal framework — automatic facial recognition and AI image generation are not governed by the same texts — but the underlying pattern repeats: a feature that exploits users’ likenesses faster than consent can keep up, corrected only after the fact, under outside pressure rather than through anticipation.

What this concretely changes for you

If you have a public Instagram account and you are over 18, your public photos could technically have been used by Muse Image between 7 and 10 July 2026, without your being informed and with no way of checking after the fact. Checking your account’s “Sharing and reuse” settings now remains a useful precaution: nothing indicates that Meta will not relaunch a similar version, and the company’s history — on AI training in Europe as on facial recognition in the United States — shows a recurring pattern of aggressive launch, retreat under pressure, then an adjusted return.

This case adds to a series of incidents where generative AI tools were used to produce images of real people without their agreement, a concern Le Recul has already documented in detail regarding sexualised deepfakes generated through Grok and the safety of minors faced with these tools in our ChatGPT versus Grok comparison. The company’s name changes; the pattern stays identical: the feature is deployed first, the guardrails discussed afterwards.

What to take away

Meta launched Muse Image on 7 July 2026, its first AI image generator developed in-house by Meta Superintelligence Labs, integrated free into Meta AI, Instagram and WhatsApp.

A side feature let anyone mention a public Instagram account and generate an AI image with that person’s face, on by default, with no consent and no notification, for all public adult accounts.

Under pressure from SAG-AFTRA, the CAA and associations such as Public Citizen, Meta withdrew that feature on 10 July 2026, that is 72 hours after its launch, acknowledging that it had “missed the mark”.

The integration of Muse Image into Advantage+, Meta’s advertising platform, is nonetheless continuing its rollout, and the images already generated during those three days remain in circulation.

In France, no official confirmation of the tool’s availability exists, but French public accounts could be exploited by users located elsewhere, regardless of the victim’s location.

The figure to remember

72 hours.

That is how long it took Meta to launch a generative AI feature switched on by default over the photos of public accounts, take an outcry from actors’ unions, talent agencies and digital rights groups, then withdraw it while admitting its mistake — without, however, cutting off access to the same technology on the advertising side, or guaranteeing the deletion of the images already produced.