You Can't See the Camera Any More: Rewriting Smart Glasses Policy for the Workplace
Every confidentiality rule you have depends on somebody spotting a recording device. Face-worn AI breaks that, and the fix is wording, not a ban you cannot enforce.
Every confidentiality control in your organisation rests on an assumption nobody bothered to write down: that a recording device can be seen. A phone held up. A little light saying the camera is live. Remove the assumption and the rule survives on paper while failing in the room. A smart glasses policy for the workplace is now a drafting job. Reception cannot save you.
The hardware barely needs describing. Cameras and microphones worn on the face, built into frames that look like eyewear, some with a display only the wearer can read. Specifications are a distraction here. What matters is the tell, because detection-based policy needs a visible signal, and that signal is being worn away by the product's own commercial logic.
Follow the mechanism: why the recording light keeps losing
Face-worn computing is valuable to the companies building it for one reason: passive context, a continuous feed of whatever the wearer is looking at. That is worth far more than clips somebody deliberately shoots. An indicator that fires on every capture is a tax on exactly that feed, because it caps how much of the day a wearer will tolerate recording. The light and the roadmap pull in opposite directions, and roadmaps usually win.
The manufacturer's own documentation shows where the control actually lives. Meta says its second-generation glasses disable the camera when the capture LED is blocked, and that an update will disable the camera if the LED is physically tampered with or destroyed. Sensible engineering. Also software governing a hardware signal, and anything a release can add, a later release can revise. Running the other way, 404 Media reported a paid third-party modification that switched the recording light off while leaving the glasses otherwise working. The tell is contested territory.
So adopt the operating rule before you write a word of policy: a consent signal in software is a request, and only a consent signal in hardware is a control. If a firmware update or a paid modification can remove it, treat it as already gone. None of that is a complaint about one manufacturer. It is the same test we apply when designing controls for agentic systems that act on your data: a guarantee the guarded party can revoke was never a guarantee.
The rules are being written now, and not by you
The public fight is loud and legally unresolved. A class action filed in California alleges that the glasses were misrepresented as designed for privacy. Those are plaintiffs' allegations and they may well fail. Their effect on how your clients draft the next confidentiality schedule doesn't wait for a verdict.
The quieter British version of the problem is already written down, and it points at the employer rather than the manufacturer. The ICO's guidance on monitoring workers makes transparency the employer's job and treats covert monitoring as something you reach for only in genuinely exceptional cases, having documented why. Read that against a room where one employee's own glasses are quietly capturing colleagues. The employer never chose to monitor anyone, and can still end up owning a monitoring practice it never designed, never told anybody about and cannot describe to a regulator. Tolerating the device is a decision, whether or not you write one down.
The other assumption worth killing early is that personal kit is a personal matter. In Ryneš (C-212/13) the Court of Justice held that a householder's own CCTV camera fell outside the purely personal or household exemption because it also covered public space. UK GDPR keeps a carve-out in the same shape, and assimilated case law still informs how it reads. Glasses worn into a client's building, during work, pointed at a screen of somebody else's personal data, are a long way outside it.
Can you just ban smart glasses at work?
Not usefully. Start with who's wearing them. Most people who need vision correction wear it on their face, the frames are converging on ordinary eyewear, and a rule aimed at glasses asks a line manager to inspect an employee's glasses. That isn't an operating model, it's a grievance waiting to be filed. Then add visitors, contractors, engineers on site and anybody standing in a customer-facing queue.
Employment law has already run this experiment on the previous generation of the problem. In Phoenix House Ltd v Stockman, the Employment Appeal Tribunal dealt with an employee who covertly recorded a meeting, declined to treat covert recording as automatically gross misconduct, and observed how seldom employers address recording in their policies at all. Take the practical instruction from it: what you never wrote down, you cannot lean on afterwards. A ban is a detection rule in a stricter costume. It inherits the identical failure and leaves you holding a documented control you can't evidence when a client's auditor asks how it's enforced.
What a smart glasses policy for the workplace should actually say
Move the obligation from the observer to the wearer. Confidentiality terms should require anyone entering defined areas or attending defined processes to declare and disable recording-capable devices, with the breach defined as failing to declare rather than being caught. Detection then becomes evidence for a disciplinary or contractual process, which is all it was ever good for.
Zones come next, in place of policing hardware. Decide which rooms and which processes assume no recording: screens showing client data, HR conversations, incident calls, anything covered by an NDA with a named counterparty. Say it in the room, say it in the calendar invite, and put it in the contract, so nobody has to infer the rule from the culture.
Then settle the liability question before it becomes urgent. When an employee's own glasses capture a client's personal data on the client's premises, the personal-use carve-out is the wrong door to knock on, because the purpose of the wearing was work. The exposure sits with the organisation, and the contract is where you say so.
The second-order effects arrive through paperwork. Client due-diligence questionnaires and insurers will start asking whether you have a wearables clause, exactly as they learned to ask about personal devices a decade ago, and firms that answer "yes, here it is" will take work from firms that answer "we're reviewing it". That is a procurement problem, and one of the cheapest things in a technical strategy programme to close out.
One objection deserves testing, because it's the one that stalls most of this work: our NDAs already cover it. Read yours. It binds the parties, defines breach as disclosure or use of confidential information, and quietly assumes a person decided to pass something on. None of that describes an employee's own device ingesting a screen it happened to be pointed at, in a room where nobody disclosed anything to anybody. The gap isn't the confidentiality duty, it's the capture event, and no standard schedule names it. That's why the fix is drafting, and why deciding what AI systems are allowed to ingest matters more than the frames it arrives in.
The incident that finally forces your hand almost certainly won't be espionage. It'll be mundane: someone in a client meeting wearing the glasses they wear every day, a screen full of a third party's personal data in shot, an assistant quietly turning it into searchable text inside infrastructure neither party controls. No malice, no lens to spot, no light. Write the wording this quarter, while it's still a paragraph.
Questions people ask
Is it legal for an employee to wear recording-capable glasses in a UK workplace?
Wearing them isn't the regulated act; capturing and processing other people's data is. This is analysis, not settled law. The practical position: when the wearing happens in the course of employment, on your premises or a client's, the organisation cannot rely on a personal-use exemption to distance itself from what is recorded. That makes it a policy and contract question for the employer, not a private matter for the employee, and it is why the obligation should be written as a declaration duty rather than a prohibition.
What should staff do if a visitor or client arrives wearing smart glasses?
Give them a script, not a judgement call. Reception and meeting hosts should ask every visitor to confirm whether they are wearing or carrying recording-capable devices, offer a place to leave them or a request to power them down for defined areas, and record the answer alongside the visitor sign-in. Catching anyone out is beside the point. What you want is a documented moment where the obligation transferred, because that is the part an auditor or a court can actually inspect.
How do you write a wearables clause into a client or supplier contract?
Define recording-capable device broadly enough to survive the next product generation, including eyewear, earbuds and body-worn cameras, rather than naming brands. Attach the duty to declaration and to named zones or processes, never to visible indicators. Add an obligation to notify the other party promptly if capture occurs in a restricted zone, and allocate liability explicitly for personally owned devices used in a work context. A clause that depends on anyone spotting a light has a known expiry date.
Related
- The Sovereignty Premium: Why Sovereign AI Solutions for Enterprise Are Winning on Access, Not Speed
- The AI Safety Marketing Backfire: How Doom Hype Built Its Own Cage
- Your Monitor Is Now a Software Vendor, and It Never Asked Your Permission
- Security & Trust
Written by an AI editorial persona of Abyshire's proprietary editorial system and reviewed by our team.