Lemonade faces a class action over collecting biometric facial data from claim videos

A putative class action alleged that Lemonade Inc. collected and stored facial geometry biometric data from customers who submitted video claims through its AI chatbot without providing required disclosures or obtaining written consent under the Illinois Biometric Information Privacy Act. The controversy erupted after Lemonade tweeted about its AI analyzing 1,600 data points from claim videos, prompting lawsuits in Illinois and New York. Lemonade ultimately agreed to a $4 million settlement covering over 110,000 affected policyholders and stopped collecting biometric data.

Lemonade, Inc. · Incident Aug 1, 2021 · Indexed Jun 4, 2026 · 3 sources

Lemonade's AI chatbot quietly scanned facial geometry from customer claim videos without the consent or disclosure that biometric privacy laws require.
What
A putative class action alleged that Lemonade Inc.
Incident date
Aug 1, 2021
Who
Lemonade, Inc.
Failure mode
Policy Violation
AI surface
Chatbot
Severity
Medium

What happened

Lemonade, an AI-driven insurance company, required policyholders to submit video recordings of themselves answering questions from an automated chatbot as part of the claims process. The company's AI then extracted facial geometry and up to 1,600 data points from these videos for fraud detection without providing BIPA-required disclosures or obtaining written consent. After Lemonade tweeted about its AI detecting non-verbal cues in claim videos in May 2021, public backlash led to the filing of class action lawsuits in Cook County, Illinois and the Southern District of New York. Lemonade stopped collecting biometric data on May 27, 2021 and later agreed to a $4 million settlement, with $3 million allocated to the Illinois subclass and $1 million to the nationwide class.

What broke inside the model

Failure path · mode profile · Policy Violation
  1. 01 · TriggerA prompt pushes against a deployment boundary.
  2. 02 · Model stepThe model produces the disallowed output.
  3. 03 · Control gapNo enforcement blocks it at generation time.
  4. 04 · FailureThe output crosses the policy line.
  5. 05 · ConsequenceA limit the business set is breached in public.

The output crosses a policy boundary the deployment had defined.

Lemonade's AI chatbot required customers to upload video recordings during the claims process, and the company's facial recognition system extracted facial geometry scans from those videos without informing customers or obtaining the express written consent mandated by BIPA. The company failed to implement required disclosures, written retention policies, and consent mechanisms before deploying biometric collection in its claims pipeline. The system quietly processed biometric identifiers as an integral part of fraud detection without any privacy safeguards required by law.

Public visibilityHigh
Regulatory exposureActive
Customer impactClass-wide
Financial impactDisclosed
Time to disclosureMonths
  1. PressAI-Driven Insurer Lemonade Illegally Captures Ill. Residents' Biometric Data, Class Action Allegesclassaction.org
  2. PressAI Insurance Company Faces Class Action for Use of Biometric Datacarltonfields.com
  3. Court FilingClarke et al. v. Lemonade, Inc. et al. Settlement Websitelemonadebipasettlement.com
Permalinkhttps://failureindex.ai/failures/lemonade-faces-class-action-collecting
CitationAI Failure Index. "Lemonade faces a class action over collecting biometric facial data from claim videos" (FI-0117). Realm Labs. https://failureindex.ai/failures/lemonade-faces-class-action-collecting (indexed Jun 4, 2026).
Share cardA branded image of this record for posts and slides.

Data fields CC-BY 4.0, prose citation permitted. Incident ID FI-0117. Full dataset at /data.

Note from Realm Labs, the Index steward

How Realm would have caught this

Controls for this failure mode
  • Prism
  • OmniGuard

Realm compares what the model is about to output or do against the policy that governs the deployment, in real time, and can deny or redact the action before it takes effect, which is the gap an after-the-fact review never closes in time.