I think the comments here are arguing past each other. If a machine learning model can correctly classify $attribute by photos in 70% of the cases, that is an academic result.
Should it used for the ever popular pre-crime detection scams or for misclassifying feminine looking men as homosexuals? No, that is nasty and is forbidden in the EU. At least for companies, the security state of course does whatever it wants without any repercussions.
Should it be used in principle? No, classifying humans by a machine algorithm is dehumanizing.
Should research be done at all? If the subjects are volunteers and it is confined to a university, it should be allowed. But researchers should not be surprised it they are confronted with obvious parallels to phrenology. This literally is phrenology.