Meta rolled out an AI feature on Instagram in early July that let users tag public accounts and generate images using their likenesses. The tool was enabled by default, which meant millions of people had to actively opt out if they did not want their faces used in AI-generated pictures. Within three days, the outcry was so loud that Meta turned the feature off.
The speed of the reversal was striking. Multiple Instagram creators posted viral videos explaining how to opt out and expressing frustration. Sam Sooin Yang, an Instagram creator, posted a video criticizing the feature that drew over 3 million views. In it, she said, “They should have given you the option to opt in rather than opt out. But I am really getting tired of these companies pushing this AI stuff on us when we don’t want to use it.”
Meta acknowledged the misstep. The company said in a statement that “this feature missed the mark” and rolled back Instagram tagging for its AI chatbot. The feature was turned off three days after being turned on.
A Fast Public Pushback
Thorin Klosowski, senior security and privacy activist at the Electronic Frontier Foundation, said the reaction was unusually swift. “Honestly, it was great to see how quickly that happened.” Klosowski noted that the public response was “clear and immediate” and “great to see.”
The rollback may be a record for how quickly a generative AI feature was pulled. Silicon Valley companies have leaned into enabling AI features and related settings by default, and public sentiment has soured on generative AI. The Instagram episode shows what can happen when a company pushes too far.
Ben Winters, director of AI and privacy at the Consumer Federation of America, said the problem is not isolated to Instagram. “This type of behavior is not unique for Meta,” he said. Winters argued that Meta has become comfortable with defaults that favor the company. “They are stewards of the opt-out status quo that we find ourselves in, without adequate privacy regulation in the States.”
The Opt-Out Ritual
The author of this article described a familiar ritual of digging through settings to disable unwanted features. In Google Docs, an “Ask Gemini” bar appeared at the bottom of documents, and the author turned it off. On Dropbox and LinkedIn, similar opt-out steps were needed. Meta has another setting, too: Facebook’s “Enhanced Browsing” tracks in-app visited websites on mobile.
Meta spokesperson Daniel Roberts defended the company’s approach in an emailed statement. “We've built a wide array of settings and controls to help people make the privacy choices that are right for them and shape their experiences across our platforms,” Roberts said. He added, “We also conduct and fund extensive research to develop controls and data practices that are easy for people to use and understand, including through cross-industry organizations like TTC Labs.”
Winters was not convinced. He said the burden should not fall on users to protect themselves. “It is the perfect recipe for something that needs federal government intervention,” he said. He added, “That's what legislatures and governments are there for: to protect people where they are unable to protect themselves and constrain companies from doing things that are particularly abusive and deceptive at scale.”
Stay ahead of the AI curve
The most important updates, news, and content — delivered weekly.
No spam. Unsubscribe anytime.
Why Defaults Matter
Woodrow Hartzog, a professor at Boston University’s law school, explained why the default setting is so important. “People tend to stick with whatever the default option is,” he said. “So, if the default option is that you're enrolled, you're probably going to stay enrolled.”
Hartzog pointed to the European Union’s General Data Protection Regulation, or GDPR, as a model. He cited Article 25 of the GDPR, which requires that the more privacy-protective option be pre-selected by default. “The idea is that you have to build your systems to collect only what you need and nothing more,” he said. “And, if one of the options is more privacy protective than the other one, then by default, the more privacy protective option needs to be pre-selected.”
Some privacy experts have taken issue with how GDPR works in practice. But the principle of privacy by default remains powerful. In the United States, there are scattered state privacy laws, such as those in California and Maryland. There is no comprehensive federal law.
The Push for Federal Rules
Past attempts at federal privacy regulation have failed. Winters, however, is optimistic that public sentiment is shifting. He said the public is closer to federal regulation than a decade ago, driven by repeated incidents like the Instagram AI feature.
Hartzog warned about the broader consequences of auto-enrolling users into AI tools. “People say technology is just a tool that you can do good things or bad things with. That often is said to hide the ways in which technology makes certain realities more or less likely,” he said. “So when you design tools in particular ways, there are foreseeable uses of those tools.”
Automatically opting users into a deepfake tool makes a world with more deepfakes more possible, Hartzog argued. The Instagram feature allowed users to generate images using the likenesses of public accounts, which could easily be misused. The rollback came quickly, but the underlying pattern remains.
Meta’s statement that the feature “missed the mark” was a rare admission. Yet the company’s default settings continue to favor AI features across its platforms. The three-day lifespan of the Instagram tool may serve as a warning to other companies considering similar opt-out defaults.
For now, users are left to navigate a patchwork of settings on every platform. The burden of privacy protection still falls on the individual. Winters said federal intervention is needed to change that. Until then, the opt-out ritual continues.

