WASHINGTON—Smart glasses are undergoing something of a renaissance. Meta is heavily advertising its smart glasses collaboration with Ray-Ban and Oakley, Apple is reportedly unveiling its wearable offering next June, and even Google, which over a decade ago “made face computers extremely uncool,” is venturing back into this space.
In the 2010s, smart glasses offered little more than a clunkier, harder-to-use smartphone strapped to your face. Today, artificial intelligence (AI) has turned the latest wave of smart glasses into a low-friction interface that lets users query, identify, and act on their surroundings in real time, without ever having to look down. The newest models are surprisingly normal-looking and unobtrusive. But the effort to make this technology more ordinary is creating a bystander problem, causing privacy advocates to sound the alarm. The people being watched cannot consent, because the surveillance is invisible in ways that even the smartphone era did not surface.
A (un)reasonable expectation of privacy?
Smart glasses fall under a growing category of devices called wearable technologies, or simply “wearables.” A patchwork of privacy laws applies to this technology, but in narrow cases that are not consistent across state borders and include notable gaps. Take, for example, wearable medical devices. The Health Insurance Portability and Accountability Act (HIPAA) only applies to “covered entities” (providers, insurers, clearinghouses). A consumer buying a Fitbit or Oura ring generates data entirely outside that perimeter. The only backstop, for now, is the Health Breach Notification Rule, which the Federal Trade Commission used against GoodRx and BetterHelp for sharing health data with advertisers without consent.
Privacy, in this telling, becomes a luxury good, available to those willing to opt out of the tools everyone else is using.
At present, twenty states have comprehensive consumer privacy laws with meaningfully different consent structures, thresholds, and enforcement. For example, the California Consumer Privacy Act of 2018 (CCPA), and its 2023 amendment, uses an opt-out model for the opt-out for general sale or sharing of data, meaning that a consumer’s personal data is collected, shared, and sold by default, unless the consumer proactively notifies a platform to stop.
Smart glasses are meaningfully different from other wearables in that the data collected does not pertain solely to the wearer. So, while some biometric data protections may apply to the wearer, bystanders recorded without their consent have fewer legal protections to turn to. The Wiretap Act applies, but only to audio capture, and it can only function as a remedy for bystanders in the eleven states that require all-party consent (i.e., everyone participating in a conversation must consent to being recorded). For instance, Illinois, which does not have a comprehensive privacy law, is an all-party consent state. Its Biometric Information Privacy Act (BIPA) is opt-in, and it is regarded as the United States’ most stringent biometric privacy statute. Video recording in public and many semi-public spaces generally falls outside existing privacy laws.
Some states are beginning to make targeted interventions in these legal gaps. In Pennsylvania, a proposed bill would mandate that “all smart glasses manufactured, sold, and used in Pennsylvania … have a visual indicator that shows when the device is recording video or audio.” New York recently banned the use of smart glasses in courts, deeming the devices a violation of state civil rights law. But these interventions seem limited and piecemeal for an issue that could become almost ubiquitous.
The shifting expectation of privacy
While smart glasses are still relatively niche, they represent a potentially massive market. One industry report projects that the market will grow four-fold by 2031. Wider adoption is expected to increase as the price tag comes within reach for the average consumer: Google Glass, when it was first unveiled, was priced at $1,500. Today, you can get glasses with a suite of vision capabilities for between $250 and $500. And while earlier models were often bulky, awkward, and carried a social stigma, newer versions have a size, shape, and design more like traditional eyewear.
As these devices become more common, the rules and norms for how smart glasses are used in society will be decided, as well. More often than not, society’s expectations of privacy evolve with technology, not the other way around. A recent Indiana court case acknowledged this reality:
- One day, in a not-so-distant future, millions of Americans…will traverse their communities under the perpetual gaze of cameras … [A]s society’s uptake of a new technology waxes … expectations of privacy in those technologies wane. These evolving expectations thus continually undermine themselves. As long as the government moves discreetly with the times, its use of advanced technologies will likely not breach society’s reconstituted (non)expectations of privacy.
The current legal approach to smart glasses rests heavily on a “reasonable expectation of privacy” standard set in 1967, which has only weakened over time. The patchwork of laws that do exist covers narrow instances, leaving bystanders who have no way to meaningfully consent vulnerable to unwelcome, unwarranted surveillance.
Even well-intentioned measures, such as the proposal in Pennsylvania (H.B. 2603) making it mandatory to include a visual indicator of recording, place the burden of catching infringements on the person or people being recorded. H.B. 2603 also does not address the fact that people are apparently taking steps to remove the recording LED light. A quick search for “smart glass LED removal” will return hundreds of tutorials. If the only consumer-facing signal can be defeated for money, is “notice” a meaningful legal concept here at all?
Another question that will be rapidly relevant as on-device AI becomes more commonplace: If digital faceprints never leave a device—and are processed on the device even when it is offline—does any existing biometric privacy law even apply, since most were written assuming centralized databases?
Is privacy the last luxury?
The temptation is to treat privacy as the cost of admission for convenience. That framing has crept into how many Americans talk about data for two decades now, and smart glasses are poised to make it explicit in a way few prior technologies have.
Privacy, in this telling, becomes a luxury good, available to those willing to opt out of the tools everyone else is using, and to bystanders willing to police their own exposure in a world with no real legal right to do so. When the burden of protecting that baseline falls on the individual, the law has not struck a balance. It has simply declined to act and let a private company decide where the line falls.
That is the deeper failure, beyond the patchwork of regulations that constitute US privacy law. Public pressure, media reporting, and advocacy campaigns are not a substitute for a legal remedy. However, some efforts to move forward federal laws, such as the now stalled American Data Privacy and Protection Act (2022) or the American Privacy Rights Act (2025), risk creating a federal ceiling rather than a floor, weakening stronger protections currently available to residents in Illinois and California.
The Federal Trade Commission could step in, as it has in several narrower health-data cases, under Section 5, which covers unfair or deceptive acts and practices. The commission’s case-by-case authority, however, is just an interim measure, not a substitute for a standard. In addition, the US Supreme Court overturning the Chevron deference principle in 2024 means that any attempt to build such a standard through its rulemaking authority alone now rests on uncertain legal ground.
Congressional intervention is the strongest long-term solution for prohibiting biometric identification of nonconsenting third parties, regardless of what the user of a wearable device consents to. To date, however, the closest that Congress has come to meaningful legislation on this issue was the National Biometric Information Privacy Act (2020), which stalled in a Senate committee. In many ways, this act mirrored the Illinois BIPA, along with its shortcomings.
A successor should plug three gaps. First, it should cover video and image capture to ensure on-device AI does not become a legal blind spot for biometric privacy. Second, it should include the bystanders as data subjects. Had the National Biometric Privacy Act become law, it would have primarily pertained to the relationship between the device user and the company, and not to any bystanders. And third, it should establish a national right to erasure, which would allow people to request that companies delete their personal data.
