A Suggested Question Nobody Wanted Answered

Kalie Robins, a Utah-based content creator, posted a video of herself and one of her daughters singing in the car to Instagram and Facebook. When she checked the post, Meta AI had surfaced a suggested prompt: "Who's the child passenger?" Curious, she tapped it, and told Futurism what happened next: "It just kept going and going, and that pit in my stomach just kept getting bigger and deeper."

Meta AI did not stop at the daughter visible in the video. It identified her second daughter too, along with both girls' ages, their likely school grade, their favorite beach and hiking trail, where the family lives, and, according to Futurism's review of the exchange, both girls' birth weights and Robins' own professional background in mental health advocacy. Robins said she had never published her daughters' names herself. Meta AI pulled them from a grandmother's Facebook post announcing one daughter's birth, years earlier.

The Profile Existed Before Anyone Asked a Question

The detail that matters is not the conversation Robins had with Meta AI. It is what Meta AI had already assembled before she typed a single word: a cross-referenced profile of two named minors, built by combining her own posts with unrelated posts from relatives who had no reason to expect their birthday photos and birth announcements would be fed into someone else's AI feature years later.

Meta spokesperson Dina El-Kassaby told The Verge the company "missed the mark" and that "the feature never should have prompted the individual with questions like that," adding that Meta has corrected the issue and that the feature only ever surfaces information a user could already see themselves. That statement addresses the prompt. It does not address the profile, which Meta AI had to build, correctly identifying two children across years of third-party posts, before it could suggest anything at all.

Two New Child-Safety Laws, Neither Built for This

2026 has produced real momentum on AI and child safety: the EU AI Act's Article 50 now requires disclosing that a user is talking to an AI system, and California's SB 1119, signed this month, mandates crisis protocols and parental controls inside AI companion chatbots. Both are genuine advances. Neither would have caught this incident, because both are written for the moment a child or parent is actively talking to an AI. Nothing here was a conversation with a child. It was a feature quietly profiling a child for someone else's convenience, with no chat interface in sight.

RuleWhat It CoversCovers This Incident?
EU AI Act, Article 50Disclosing that a user is talking to an AI chatbotNo - no chatbot conversation took place
California SB 1119 (2026)Crisis protocols and parental controls inside AI companion chatbotsNo - the same reason, no chat occurred
GDPR, Article 22 and Recital 38Automated profiling, with explicit extra protection for childrenOn paper, yes - never yet enforced against a 'suggested question' feature

That third row is the uncomfortable one. GDPR's Recital 38 already states that children merit specific protection with regard to profiling, and Article 22 narrowly restricts automated decisions that significantly affect a person to three exceptions: contractual necessity, legal authorization, or explicit consent. None of those exceptions plausibly covers a grandmother's decade-old birthday post being cross-referenced to profile her granddaughter for an AI feature. The law that could reach this incident already exists in Europe. It has simply never been tested against a feature marketed as a convenience rather than a decision.

A Patched Prompt Is Not a Patched Pipeline

Every European parent whose family posts across generations on Meta's platforms, exactly the pattern that exposed Robins' daughters, sits inside the same profiling pipeline Meta says it has now "corrected." What Meta actually fixed is the surface: the suggested question that made the profiling visible. Nothing in its statement describes retiring the underlying cross-account aggregation that built the profile in the first place, which means the same data-minimization question GDPR was written to force, whether that profile should have been assembled at all, was never actually answered, only hidden from view again.

Servola Journal

We do this for everyone trying to keep up with what technology is doing to our lives. The people who build it, and the people it happens to. The Servola Journal exists so that what we learn belongs to all of them.

Nobody pays us for this. No ads, no paywall, free to everyone. We just believe that understanding what's happening to all of us shouldn't depend on who can afford to pay for it.

If it gave you something today, tell us to keep going. Follow us, leave a like, or write a positive comment. We read every one, and they are what keeps us going.