Expanding AI smart glasses market set to test UK privacy law, MLex

Time 6 Minute Read
News

AI-enabled smart glasses have faced a slew of negative headlines in the UK over fears of covert filming of people — notably women — without their consent, so it was perhaps inevitable that hard questions about their privacy law implications would come into sharper focus.

While existing rules, including the UK General Data Protection Regulation, or UK GDPR, and the Data (Use and Access) Act, can apply to the devices, to their providers and to the people who wear them, smart glasses raise questions about transparency and accountability that the UK’s Information Commissioner’s Office, or ICO, may need to clarify.

Much of the existing framework was “designed around more visible forms of recording, such as CCTV,” Jonathan Wright, a partner at law firm Hunton Andrews Kurth, told MLex. “AI glasses can be more difficult to detect. If you don't know you're being recorded, you don't know who [the data controller] is. So you can't exercise those rights."

This issue was raised in a recent blog post by Paul Arnold, ICO chief executive. He said smart glasses had prompted a debate about maintaining “meaningful transparency, accountability, and data minimization in a world where technology is becoming more capable and less visible.”

The ICO told MLex it is not currently considering technology-specific guidance for smart glasses, which include augmented-reality, or AR, glasses — which work as portable displays of other tech — particularly while it develops a new AI and automated decision-making code.

But the question may return to the regulator’s desk as the market expands beyond Meta Platforms’ Ray-Ban devices, with Snap expecting to ship its SPECS augmented-reality glasses to the UK this autumn.
Overseas, other watchdogs, and in some cases prosecutors, are also grappling with smart glasses’ privacy implications. Australia's regulator has called for new safeguards, while Ireland’s Data Protection Commission, the lead EU privacy regulator for Meta, told MLex it is helping prepare a statement on the devices, expected as early as October (see here).

— Personal or public use? —

The starting point for determining how UK privacy rules apply to smart glasses is to establish the wearer's reason for use. Under the UK GDPR's 'household exemption', individuals are exempt from privacy rules when they are processing data for personal activities, such as recording family or friends.

That protection ceases when the use is commercial, such as an influencer monetizing content they capture using smart glasses. Arnold said "a public post anyone can see" is unlikely to count as personal use.

Wright said that if influencers use data they collect and that constitutes personal data, they become a data
controller. They may then need to provide privacy information, identify a lawful basis for processing, and respond to data requests, he said, adding that many “probably haven't got a clue” that their activity creates such duties.

Whether the UK GDPR gives a bystander a route to challenge processing depends on whether they are identifiable, what the material reveals, whether the recording is intrusive, and how it is used. But a practical difficulty remains: people may not know they have been recorded, or who has recorded them.

“Under the UK GDPR, a person has rights to information, access, objection, erasure, but in practice, these rights depend on being able to identify and contact the relevant controller,” Wright said.

— Who is responsible? —

Responsibility is divided between the wearer and the provider. A wearer is responsible for the decision to record, upload or publish material, but a provider may have separate obligations where it receives, retains or analyzes footage independently.

“The wearer cannot simply blame the manufacturer for pressing record, and the manufacturer cannot blame the wearer for processing it chooses to carry out on its own servers,” Frederick Powell, a lawyer at Doughty Street, told MLex.

The ICO’s consumer guidance on the Internet of Things says organizations must consider data protection from the design stage, minimize data collection and provide privacy information that people are likely to notice and use.

“Providers should be able to explain clearly what happens to captured material, including where it goes and how bystanders can raise concerns,” Wright said.

— Bystanders and transparency —

The most difficult case concerns bystanders whose data may be captured without their knowledge. The ICO’s guidance says lights or sound can signal when a connected product is operating and processing personal information. Both Meta’s Ray-Ban glasses and Snap’s SPECS use a flashing light to indicate that recording is taking place.

Some lawyers and privacy experts however have questioned whether a flashing light is sufficient under UK transparency requirements because it assumes people will both notice it and recognize what it means.

“Our glasses are built to be noticed, with a capture LED that blinks when you take a photo or video that you can save or share, and it can't be turned off,” a Meta spokesperson said. The company added that it disables the camera if the LED is covered or has been tampered with.

Snap said SPECS do not continuously record or save audio, video or photos and do not use facial recognition to identify people around the wearer.

"They also look like a pair of AR glasses — we are not trying to hide the cameras," a spokesperson said. "The prominent external LED ... makes clear to people nearby that recording is taking place."

Those measures demonstrate an effort to make recording noticeable. They do not however resolve whether a person who sees a flashing light knows what it signifies, or how to exercise resulting rights.

Hamburg's privacy regulator has concluded that Meta’s glasses would generally not be permitted to record people outside a wearer’s family and friends under the EU GDPR (see here). The German watchdog also said the LED did not give people sufficient notice for informed consent to be obtained.

Meta itself appears keen to take the focus away from the camera element, last week unveiling a new edition of its glasses with audio functions only.

In 2022, the ICO warned that discreet AR smart glasses could enable covert surveillance. The same concern prompted programmer Paweł Szydłowski to develop the Zuckoff app, which uses Bluetooth signatures to notify people when smart glasses are nearby.

"I was shocked by the type of 'content' people recorded using the glasses, so I decided to do something about it," Szydlowski told MLex. "We can't approve products of this type without proper checks. We do it for food safety; it’s time to start doing it for AI and tech."


Originally published on September 28, 2026 with MLex. Reprinted with permission. Further duplication without permission is prohibited. All rights reserved.

Media Contact

Lisa Franz
Director of Public Relations

Jeremy Heallen
Public Relations Senior Manager
mediarelations@Hunton.com

Jump to Page