I'm not sure they'd gain anything. If a user has Facebook or Instagram (or any social network really) on their phone, which most do, then Apple has access to a corpus of personal information and face images that's big enough to build a massively detailed picture of someone's life with an accurate biometric model. Apple users, rightly or wrongly, trust Apple not to abuse that information. Likewise Google's users, Facebook, etc.
It's too late to be talking about the dangers of letting corporations gain access to personal data and facial biometrics. The question now is how do we protect ourselves and our loved ones in a world where that data, for most people, is out there by default.
However, there's an API for this tech as well and apps could abuse it. I bet they'll introduce a permission request for this though.