Lemonade faces a class action over collecting biometric facial data from claim videos
A putative class action alleged that Lemonade Inc. collected and stored facial geometry biometric data from customers who submitted video claims through its AI chatbot without providing required disclosures or obtaining written consent under the Illinois Biometric Information Privacy Act. The controversy erupted after Lemonade tweeted about its AI analyzing 1,600 data points from claim videos, prompting lawsuits in Illinois and New York. Lemonade ultimately agreed to a $4 million settlement covering over 110,000 affected policyholders and stopped collecting biometric data.
Lemonade's AI chatbot quietly scanned facial geometry from customer claim videos without the consent or disclosure that biometric privacy laws require.
Key facts
- What
- A putative class action alleged that Lemonade Inc.
- Incident date
- Aug 1, 2021
- Who
- Lemonade, Inc.
- Failure mode
- Policy Violation
- AI surface
- Chatbot
- Severity
- Medium
What happened
Lemonade, an AI-driven insurance company, required policyholders to submit video recordings of themselves answering questions from an automated chatbot as part of the claims process. The company's AI then extracted facial geometry and up to 1,600 data points from these videos for fraud detection without providing BIPA-required disclosures or obtaining written consent. After Lemonade tweeted about its AI detecting non-verbal cues in claim videos in May 2021, public backlash led to the filing of class action lawsuits in Cook County, Illinois and the Southern District of New York. Lemonade stopped collecting biometric data on May 27, 2021 and later agreed to a $4 million settlement, with $3 million allocated to the Illinois subclass and $1 million to the nationwide class.
What broke inside the model
- 01 · TriggerA prompt pushes against a deployment boundary.
- 02 · Model stepThe model produces the disallowed output.
- 03 · Control gapNo enforcement blocks it at generation time.
- 04 · FailureThe output crosses the policy line.
- 05 · ConsequenceA limit the business set is breached in public.
The output crosses a policy boundary the deployment had defined.
Lemonade's AI chatbot required customers to upload video recordings during the claims process, and the company's facial recognition system extracted facial geometry scans from those videos without informing customers or obtaining the express written consent mandated by BIPA. The company failed to implement required disclosures, written retention policies, and consent mechanisms before deploying biometric collection in its claims pipeline. The system quietly processed biometric identifiers as an integral part of fraud detection without any privacy safeguards required by law.
What it cost
Sources
- PressAI-Driven Insurer Lemonade Illegally Captures Ill. Residents' Biometric Data, Class Action Allegesclassaction.org
- PressAI Insurance Company Faces Class Action for Use of Biometric Datacarltonfields.com
- Court FilingClarke et al. v. Lemonade, Inc. et al. Settlement Websitelemonadebipasettlement.com
Cite this entry
https://failureindex.ai/failures/lemonade-faces-class-action-collectingAI Failure Index. "Lemonade faces a class action over collecting biometric facial data from claim videos" (FI-0117). Realm Labs. https://failureindex.ai/failures/lemonade-faces-class-action-collecting (indexed Jun 4, 2026).Data fields CC-BY 4.0, prose citation permitted. Incident ID FI-0117. Full dataset at /data.
Note from Realm Labs, the Index steward
How Realm would have caught this
- Prism
- OmniGuard
Realm compares what the model is about to output or do against the policy that governs the deployment, in real time, and can deny or redact the action before it takes effect, which is the gap an after-the-fact review never closes in time.