A Suggested Question Nobody Wanted Answered
Kalie Robins, a Utah-based content creator, posted a video of herself and one of her daughters singing in the car to Instagram and Facebook. When she checked the post, Meta AI had surfaced a suggested prompt: "Who's the child passenger?" Curious, she tapped it, and told Futurism what happened next: "It just kept going and going, and that pit in my stomach just kept getting bigger and deeper."
Meta AI did not stop at the daughter visible in the video. It identified her second daughter too, along with both girls' ages, their likely school grade, their favorite beach and hiking trail, where the family lives, and, according to Futurism's review of the exchange, both girls' birth weights and Robins' own professional background in mental health advocacy. Robins said she had never published her daughters' names herself. Meta AI pulled them from a grandmother's Facebook post announcing one daughter's birth, years earlier.
The Profile Existed Before Anyone Asked a Question
The detail that matters is not the conversation Robins had with Meta AI. It is what Meta AI had already assembled before she typed a single word: a cross-referenced profile of two named minors, built by combining her own posts with unrelated posts from relatives who had no reason to expect their birthday photos and birth announcements would be fed into someone else's AI feature years later.
Meta spokesperson Dina El-Kassaby told The Verge the company "missed the mark" and that "the feature never should have prompted the individual with questions like that," adding that Meta has corrected the issue and that the feature only ever surfaces information a user could already see themselves. That statement addresses the prompt. It does not address the profile, which Meta AI had to build, correctly identifying two children across years of third-party posts, before it could suggest anything at all.
Two New Child-Safety Laws, Neither Built for This
2026 has produced real momentum on AI and child safety: the EU AI Act's Article 50 now requires disclosing that a user is talking to an AI system, and California's SB 1119, signed this month, mandates crisis protocols and parental controls inside AI companion chatbots. Both are genuine advances. Neither would have caught this incident, because both are written for the moment a child or parent is actively talking to an AI. Nothing here was a conversation with a child. It was a feature quietly profiling a child for someone else's convenience, with no chat interface in sight.
| Rule | What It Covers | Covers This Incident? |
|---|---|---|
| EU AI Act, Article 50 | Disclosing that a user is talking to an AI chatbot | No - no chatbot conversation took place |
| California SB 1119 (2026) | Crisis protocols and parental controls inside AI companion chatbots | No - the same reason, no chat occurred |
| GDPR, Article 22 and Recital 38 | Automated profiling, with explicit extra protection for children | On paper, yes - never yet enforced against a 'suggested question' feature |
That third row is the uncomfortable one. GDPR's Recital 38 already states that children merit specific protection with regard to profiling, and Article 22 narrowly restricts automated decisions that significantly affect a person to three exceptions: contractual necessity, legal authorization, or explicit consent. None of those exceptions plausibly covers a grandmother's decade-old birthday post being cross-referenced to profile her granddaughter for an AI feature. The law that could reach this incident already exists in Europe. It has simply never been tested against a feature marketed as a convenience rather than a decision.
A Patched Prompt Is Not a Patched Pipeline
Every European parent whose family posts across generations on Meta's platforms, exactly the pattern that exposed Robins' daughters, sits inside the same profiling pipeline Meta says it has now "corrected." What Meta actually fixed is the surface: the suggested question that made the profiling visible. Nothing in its statement describes retiring the underlying cross-account aggregation that built the profile in the first place, which means the same data-minimization question GDPR was written to force, whether that profile should have been assembled at all, was never actually answered, only hidden from view again.
Servola Journal
We do this for everyone trying to keep up with what technology is doing to our lives. The people who build it, and the people it happens to. The Servola Journal exists so that what we learn belongs to all of them.
Nobody pays us for this. No ads, no paywall, free to everyone. We just believe that understanding what's happening to all of us shouldn't depend on who can afford to pay for it.
If it gave you something today, tell us to keep going. Follow us, leave a like, or write a positive comment. We read every one, and they are what keeps us going.
Read next: Meta Must Now Prove Its Age Checks Actually Work | New Mexico Turns a Meta Fine Into a Design Mandate



