Skip to content

Risk Digest

Google Lens now feeds AI training. Privacy law is split.

The mid-2026 Search Services History change now makes Google Lens images, voice searches, and Translate recordings part of Google's AI training data by default. Counsel assessing risk should separate claim types: generalized US privacy claims have failed on standing, biometric-content theory is the strongest remaining US path, and the Irish DPC's PaLM 2 inquiry makes EU exposure a live regulatory matter.

By Editorial TeamUpdated Aug 4, 2026Verified Aug 4, 2026
CONFIRMED
Jurisdiction
US Federal
Court
U.S. District Court for the Northern District of California
AI tool named
Google Generative AI
Ruling date
Jun 6, 2024
Source document
View primary court order ↗
Last verified
Aug 4, 2026

Lex Machina Review is an independent risk-tracking and reference resource. Nothing on this site is legal advice, and using it does not create an attorney-client relationship. Every record is reviewed against primary sources but may not reflect the most current status of a matter — always verify directly against the cited court order, rule text, or a licensed attorney before relying on it.

Companion explanation — secondary to the source document above

Smartphone image and audio inputs flowing into an AI core, split between US legal and EU regulatory settings

Google’s mid-2026 Search Services History change is not just another privacy-settings footnote. The operative fact is narrower and more useful: Google’s own help page now places certain Google Lens images, uploaded content, Search Live and Translate speaking-practice recordings, and voice searches inside a “Save Media” setting, and says saved media may be used to improve Google services “including AI models.” For accounts that already had the relevant Web & App Activity or Search Personalization settings enabled, Google’s documentation describes Save Media as on by default, while independent reporting observed the box pre-checked and also noted that Google did not flatly confirm a universal default-on rollout.[1][2]

That framing matters for the Lens privacy question because the first issue is not whether one can write an alarming sentence about image searches. It is which legal regime can constrain this data flow once ordinary search interactions become stored media available for service improvement and AI-model training. A US standing analysis, an Illinois biometric-content theory, and a European data-protection inquiry do not ask the same question.

What is now in the Search Services History data flow

The load-bearing source is Google’s Search Services History help document. It does not speak only in abstractions such as “activity” or “usage data.” It names media categories: Lens images, uploaded content, audio recordings from Search Live and Translate speaking practice, and voice searches. It then ties those categories to a Save Media control and states that saved media can help improve Google services, including AI models.[1]

Flow diagram showing camera, microphone, speech and upload inputs moving into saved media, AI training and retention

This is the part that should make product counsel slow down. A Lens search of a product label, a voice search made in a conference room, a Translate speaking-practice recording, or an uploaded image may begin as a transient user interaction. Under the new setting, the relevant category may also become saved media. Once saved, it sits in a different posture from a momentary query because Google describes it as material that may be used to improve services and AI models.[1]

Input named in Google’s help documentWhat changes legallyWhat should not be overstated
Google Lens imagesA visual-search interaction can fall within saved media and AI-model improvement language.There is no Lens-specific lawsuit or regulator finding identified in the current record.
Uploaded contentFiles or media supplied to search services can move from user submission into a saved-media bucket.The legal theory still depends on content type, jurisdiction, notice, harm, and statutory hooks.
Voice searchesAudio used to search can be saved media rather than only a completed query.Audio is not automatically a biometric identifier under every statute.
Search Live and Translate speaking-practice recordingsPractice or conversational audio is expressly within the named media categories.The fact that a recording is personal does not by itself establish Article III injury in US federal court.

The default point needs care. Google’s documentation connects Save Media to prior account choices, including Web & App Activity and Search Personalization. WIRED reported that Save Media appeared pre-checked when the setting was visited, but also reported that Google’s spokesperson declined to confirm that it was on by default for all users.[2] Computerworld separately reported that Google said the Search Services History feature would roll out over the next few months and that the section was not yet visible to most users at the time of its report.[3]

So the defensible sentence is not “every Google user’s Lens images are already training AI.” The defensible sentence is: Google has created a Search Services History/Save Media path under which named image, upload, and audio inputs can be saved and used to improve services including AI models; for accounts with the relevant prior settings enabled, the help documentation and reported observations support treating Save Media as default-on, subject to rollout and account-state caveats.[1][2][3]

Opt-out coverage is narrower than many consumer guides make it sound. The legally important point is not simply whether a user can toggle Save Media off going forward. Reporting on the help materials states that once media has been selected for training, it may be de-identified or disconnected from the user’s account and retained for up to four years; turning Save Media off does not necessarily delete media that has already been saved or selected for training.[2]

That does not make the system unlawful. It does change the remedial analysis. If a company’s employee used Lens on a whiteboard, spoke a client name into voice search, or practiced translation of proprietary material before the organization noticed the setting, the practical question is no longer limited to future configuration. Counsel would want to know whether the media was saved, whether it was selected for model-improvement processes, whether it was de-identified or disconnected from the account, and whether deletion remains technically or contractually available.

That sequence also explains why “the terms allow it” and “the user can opt out” are not full answers. Terms may support Google’s product permission theory. They do not settle statutory biometric notice duties, EU data-protection assessment obligations, copyright claims, or federal standing. And opt-out may prevent some future flow without unwinding every prior use.

The US standing problem for generalized privacy claims

The weakest US theory is the broad one: “Google used my data for AI training, therefore I was injured.” Recent AI-training privacy cases have repeatedly run into the same procedural wall. In Dinerstein v. Google, the Seventh Circuit rejected claims arising from Google’s receipt of de-identified medical records for machine-learning work, finding no concrete injury sufficient for Article III standing.[4]

The same basic standing pressure appears in the generative-AI consumer cases. In J.L. v. Alphabet, the Northern District of California granted Google’s motion to dismiss on June 6, 2024; the case later proceeded within the consolidated In re Google Generative AI Copyright Litigation docket, where class allegations were struck on April 21, 2025, while discovery continued.[5][6] Thele v. Google was dismissed on July 7, 2026, with the court again treating the alleged use of personal information for AI training as insufficiently concrete harm on the pleaded record.[7]

Those rulings do not bless every AI-training data practice. They do show why a US complaint built only on surprise, generalized loss of privacy, or unparticularized data use is vulnerable before discovery becomes interesting. A plaintiff still has to plead a concrete injury or a statutory violation that supplies the required injury analysis. For corporate risk review, that means the facts worth collecting are not only “was data used,” but “what data, whose data, in which state, under which statute, and with what claimed harm.”

Biometric-content claims remain the stronger US path

The more serious US exposure is not generic AI-training privacy. It is biometric-content theory, especially where images or recordings plausibly involve face geometry, voiceprints, or other identifiers covered by a specific statute. The adjacent precedent is Google Photos, not Google Lens: Google agreed to a $100 million settlement of an Illinois Biometric Information Privacy Act case involving face grouping in Google Photos, with final approval entered on September 28, 2022, in Cook County.[8]

The payout figures in public reports vary slightly, which is common in settlement administration reporting. ClassAction.org reported approximately 418,600 claims and about $142 per approved claimant, while NBC Chicago reported roughly 420,000 claims and payments around $150.[8][9] The exact dollars are less important here than the theory: when the content itself is alleged to have been processed as biometric information under BIPA, the case looks different from a generalized “my data trained AI” complaint.

That does not convert every Lens image into a BIPA case. A photo of a receipt, a plant, or a machine part is not the same as a face-grouping feature. A voice search also does not become a statutory voiceprint merely because it contains sound. The risk rises when the workflow predictably captures faces, voices, or other biometric content and the service is alleged to extract, analyze, or retain biometric identifiers without the statute’s required notice, consent, retention-policy, or disclosure steps.

Google itself has drawn distinctions among visual-search products. In a March 2025 Circle to Search privacy-by-design statement, Google said that feature did not use biometric matching and that images were not saved to history by default.[10] That statement is not a safe harbor for Search Services History. It is useful because it shows why feature-specific data flows matter: one visual-search experience may be designed and described differently from another.

US courthouse blocked by a barrier facing a European regulator building examining data-flow documents

EU exposure is live through regulatory review, not US-style standing doctrine

The European question does not wait for a private plaintiff to plead concrete injury in the US Article III sense. The Irish Data Protection Commission opened a cross-border inquiry into Google’s PaLM 2 model on September 12, 2024, focused on whether Google complied with GDPR data-protection impact assessment obligations and Section 110 of the Irish Data Protection Act 2018.[11]

That inquiry is not a finding that Google Lens, Save Media, or Search Services History is unlawful. It is a regulatory signal about process: when large-scale AI-model development involves personal data, European regulators may ask whether the controller identified risks, assessed necessity and proportionality, and performed the required DPIA work before or during processing. For an organization with EU users or employees, that is a different risk channel from a US motion to dismiss.

The Save Media change sharpens that channel because the data categories are concrete. Images, uploaded content, and voice recordings are easier for a regulator to map than an undefined bucket of “activity.” They may include personal data, special-category-adjacent material depending on content, workplace information, children’s data in some contexts, or third-party information supplied by someone who never touched the setting. None of that proves a violation. It does give a regulator something to request, trace, and test against documented assessments.

The fresh Hachette suit against Google, filed in the Southern District of New York on July 10, 2026, belongs in the file, but not at the center of this privacy analysis. Publishers and authors allege that Gemini was trained on copyrighted books and that copyright management information was willfully removed.[12][13] Those allegations matter for AI-training governance generally. They do not answer whether Lens images, Translate recordings, or voice searches create privacy or biometric exposure.

The copyright track is useful mainly as a reminder that “AI training data” is not one legal category. The same model-development pipeline can implicate privacy, biometrics, confidentiality, consumer-protection, data-protection, and copyright theories. Each theory asks for different proof.

What an organization can verify now

For counsel, the immediate work is verification rather than outrage. The relevant facts are account-state facts, workflow facts, content facts, and jurisdiction facts.

  • Check whether Search Services History and Save Media are visible and active for the organization’s relevant Google accounts, recognizing that rollout may not have reached every account at the same time.
  • Identify whether employees use Lens, voice search, Search Live, Translate speaking practice, or uploads in sensitive workflows, including client work, health, education, product development, investigations, or regulated customer support.
  • Separate ordinary personal data from content that could plausibly support a biometric theory, especially recurring captures of faces or voices in Illinois or other biometric-law jurisdictions.
  • For EU or UK-facing operations, ask whether the organization’s use pattern requires a different data-protection assessment than a US standing analysis would suggest.
  • Treat opt-out as a forward-looking control unless Google’s account tools or contractual terms confirm deletion of previously saved or selected media.

The split is the point. Google’s setting may permit collection and model-improvement use as a product matter. Legal exposure turns on something more exacting: jurisdiction, claim type, and whether the data is merely personal, concretely harmful, biometric, copyrighted, or subject to EU regulatory review.

References

  1. Get started with Search Services History & Personalized Recommendations, Google Search Help.
  2. How to Opt Out of Google Search’s New AI Data Training, WIRED.
  3. Google AI training opt-out, Computerworld.
  4. Dinerstein v. Google: Seventh Circuit Affirms Dismissal of Privacy Claims Based on Anonymized Medical Records Used for Machine Learning, K&L Gates / The National Law Review, July 2023.
  5. J.L. v. Alphabet Inc., 3:23-cv-03440, CourtListener.
  6. Google Defeats Class Certification in Generative AI Copyright Litigation, Cleary Gottlieb.
  7. Thele v. Google AI training privacy suit dismissed, Bloomberg Law, July 7, 2026.
  8. Google Photos Biometric Privacy Settlement, ClassAction.org, September 28, 2022.
  9. Google Photos settlement payments going out to Illinois residents, NBC Chicago.
  10. Circle to Search privacy-by-design, Google Public Policy, March 2025.
  11. Irish Data Protection Commission Opens Inquiry into Google’s AI Model, Hunton Privacy & Cybersecurity Law Blog, September 12, 2024.
  12. Book publishers sue Google over alleged Gemini AI training on copyrighted works, TechCrunch, July 14, 2026.
  13. Hachette Book Group announcement on Google litigation, Hachette Book Group.

Report a correction or tip

Spotted an outdated figure, a misstated fact, or a ruling this case record should reflect? Public comments are disabled for this content given the professional cost of a misreported case outcome, penalty amount, or rule text — use the structured correction channel instead.

Report a correction or tip for this record →
Blogarama - Blog Directory