Smart glasses, sighting the risks
We last examined the risks of AI-enabled smart glasses, after Swedish newspapers Svenska Dagbladet and Göteborgs-Posten claimed that outsourced workers at a Kenyan subcontractor were able to view private and intimate user footage captured by Meta's Ray-Ban AI smart glasses.
In the months since, the landscape has shifted considerably. AI-enabled technology has rapidly found its footing in consumer markets and a wave of smart glasses has entered the mainstream, with more tech companies poised to enter the market before the end of the year.
Regulatory concern has accelerated at pace with this market growth. Regulatory authorities across the UK and Europe are issuing increasingly pointed commentary on the privacy and security risks posed by smart glasses, and we are seeing enforcement action, litigation and outright prohibitions, with venues, including cinemas and pub chain Wetherspoons in the UK, banning visitors from wearing smart glasses on their premises.
As unease grows over the power of AI and opaque data flows, the message on smart glasses is clear: the privacy and security challenges posed are no longer theoretical, and the time for proactive risk management is now.
Technology: The changing risk profile
The latest generation of smart glasses - most prominently Meta's Ray-Ban smart glasses, which are produced in collaboration with EssilorLuxottica and reportedly command around 76% of the global smart glasses market - blend camera, microphone, and AI-powered features into wearable tech.
These smart glasses are capable of capturing high-resolution images and video, recording audio, and leveraging AI to bring a number of additional capabilities, including facial recognition.
In an important shift, the latest versions of these devices are now virtually indistinguishable from conventional eyewear. With a warning light that can be easily bypassed or overlooked, bystanders, including colleagues and members of the public, have no reliable way to know that they are being observed, recorded, or subjected to AI-driven analysis.
Transparency: The core risks
From a data protection perspective, a fundamental issue is the potential for covert data collection at scale.
Particularly where recordings lead to the publication of images on social media, this dissemination of personal data to an indefinite group of people removes any question of reliance on the household exemption, placing such activity squarely under the scrutiny of data privacy regulators.
The UK and EU GDPR are built on principles of transparency, fairness, and lawfulness. Smart glasses, by their nature, make compliance with these principles exceptionally difficult. A device that can record continuously, process biometric data, and transmit information to third-party servers - all without the knowledge of those being recorded – is in conflict with the regulatory framework. European regulators have begun to say so publicly.
The Hamburg Commissioner for Data Protection and Freedom of Information issued its Final Report on the Technical and Data Protection Review of the Ray-Ban Meta AI Glasses (Report) this month. The Report noted that structures for applying facial recognition as a feature are already in place, albeit not yet active, within the software and emphasised that the use of the glasses poses significant challenges regarding transparency requirements. Notably, the Report concluded that where AI training is enabled, the wearer and Meta become joint controllers, and that neither consent nor legitimate interest realistically provides a lawful basis for processing bystander data in those circumstances.
A German consumer advocacy group, HateAid, has filed a criminal complaint against Meta and other companies involved in selling the devices in Germany, citing a breach of German digital privacy laws and in France, prosecutors have opened at least one criminal probe into suspected sexual harassment related to the social media trend of using smart glasses to covertly film women on the street without their consent. The French data protection authority (the CNIL) has also confirmed it is receiving increasing numbers of complaints from businesses about smart glasses being used in the workplace.
Norway's Data Protection Authority (Datatilsynet) has written a formal letter to the government urging it to assess whether smart glasses require specific regulation, proposing measures that include restricting where the devices may be used, and imposing requirements on intrusive functions such as biometric identification.
Paul Arnold MBE, Interim Chief Executive of the UK’s Information Commissioner’s Office (ICO), who is himself severely visually impaired, offered a more measured perspective in a blog post from September 2026. He argued against treating technologies such as smart glasses as inherently good or bad but emphasised that the challenges raised by smart glasses extend beyond the reach of data protection law alone, also raising broader questions about public expectations and safety by design. Arnold specifically observed that most transparency mechanisms in physical spaces rely on visual cues such as CCTV signage or even the visible act of raising a smartphone. Wearable technologies expose a broader problem: how can people understand or object to data processing if they cannot identify when information is being captured?
In addition to the UK and European activity noted above, Australia, under the Albanese government, is considering a “world-leading” ban on camera-equipped smart glasses in government offices and service centres due to privacy and security concerns. In the United States, a proposed privacy class action has been filed against Meta over the training data used for its AI and facial recognition systems - a case which has potential implications for the broader smart glasses ecosystem, particularly when it comes to the handling of biometric data.
The recent case UAB Business Enterprise v Oneta Limited [2026] EWHC 543 (Ch) offers a further cautionary illustration. A claimant’s evidence in that case was rejected when he was found to be receiving coaching through smart glasses he was wearing in court during cross-examination, which were connected to his phone. His Majesty’s Courts and Tribunals Service has since banned Meta smart glasses from court buildings across England and Wales because of their ability to record images and video while being worn.
These developments highlight that the misuse of smart glasses can have consequences that extend beyond data protection compliance, reaching into the integrity of legal proceedings and professional conduct, as well as presenting a risk to the public.
Managing the risks
The technology is already here, and it is improving fast. The regulatory framework is playing catch up. We expect guidance from the ICO, the European Data Protection Board, and national supervisory authorities to develop rapidly as adoption grows and enforcement experience accumulates.
In the meantime, organisations that take a structured, proactive approach to the growing prevalence of smart glasses now will be far better positioned when that framework matures, and we see some convergence of opinion amongst regulators.
The CNIL has confirmed it is being increasingly contacted by businesses wanting to know whether they can ban smart glasses at work entirely. Whilst this may be the appropriate approach in some circumstances, more limited restrictions may be preferable to a blanket prohibition on AI-enabled glasses and other wearable devices where they support staff members or business interests.
That said, where employees bring personal devices into the workplace under BYOD policies, the potential for audio and visual monitoring of colleagues, clients, and visitors creates significant compliance challenges under both data protection and employment law, so the approach an organisation takes should very much be assessed on a case-by-case basis. To avoid the risks of regulatory enforcement and reputational harm, employers must carefully assess the lawful basis for any processing that results from smart glasses use and establish clear, enforceable policies governing whether, how and the extent to which the devices may be used, taking into consideration:
workplace safety;
protecting confidential or proprietary information;
safeguarding customer, employee, or client privacy; and
ensuring compliance with applicable law.
For organisations seeking instead to implement governance controls around the use of smart glasses, we would recommend the following steps:
address smart glasses in staff training and awareness programmes to ensure that employees understand the compliance exposure for the employer of wearing smart glasses;
review and update existing BYOD, acceptable-use, workplace monitoring and incident-response policies to address smart glasses explicitly. They can no longer be ignored as a ‘future tech’ problem;
conduct, or refresh, data protection impact assessments wherever smart glasses are in use, under consideration, or likely to be brought onto premises by employees or visitors;
ensure that appropriate notices are in place so that individuals are informed about any recording or data collection taking place;
consider the contractual and technical measures needed to manage third-party data sharing and international transfers arising from device use; and
continue to closely monitor the evolving regulatory landscape.