Smart glasses

Smart Glasses Get Banned in Courts and Conferences – Should Your Workplace Follow?

New York just became the first state to ban AI-enabled smart glasses across all 1,200+ state courthouses, and DEF CON 2026 did the same thing, calling them “pervert glasses” on Bluesky. Both bans landed in July 2026, within weeks of each other, and the reasoning behind them was the same: covert recording breaks consent and confidentiality. No exceptions were made for prescription lenses either.

These courts and security conferences are telling us something simpler about devices that look like normal eyewear yet hide cameras and microphones. Those devices create problems that standard policies don’t cover. DEF CON’s statement went direct: “Be sure to pack non-violating eyewear if you need them,” while New York’s Office of Court Administration said visitors must voucher smart glasses with uniformed personnel or stay outside.

When two unrelated venues reach for the same rationale, your organization should pay attention.


The Core Problem Nobody Wants To Talk About

Smart glasses aren’t flagged as cameras at security checkpoints because they’re flagged as eyewear, and that distinction breaks every “no recording” policy written before 2025.

Meta’s Ray-Ban glasses with EssilorLuxottica frames don’t scream surveillance until you inspect the frame up close and spot the embedded hardware. EFF cybersecurity director Eva Galperin posted her approval of DEF CON’s ban, saying she loved seeing a “pervert glasses” policy at DEF CON because she knows the reputation these devices earned through actual violations reported by women and children.

The LED indicator that supposedly warns when recording is active doesn’t solve legal exposure. Many jurisdictions require explicit signage that recording is in progress, not just a blinking light on an eyeglass frame. Using these glasses to record without consent could violate wiretapping laws in the 12 all-party consent states, a criminal offense with penalties ranging from misdemeanors to felonies.

Biometric data collection adds another layer of complexity. Illinois BIPA imposes $1,000 penalties per negligent violation and $5,000 per intentional or reckless violation, while Texas’s Capture or Use of Biometric Identifier Act and Washington’s Biometric Privacy Protection Act demand similar consent workflows. California CCPA treats biometrics as sensitive personal information requiring risk assessments, so when hospital workers, financial advisors, cybersecurity engineers, or attorneys wear these glasses during rounds, client meetings, or sensitive engagements, they’re potentially violating multiple statutes simultaneously.


Legal Requirements By Jurisdiction

State / RegulationKey RequirementPenalty Exposure
Illinois BIPAWritten consent before biometric collection$1,000 negligent / $5,000 per intentional or reckless violation
Washington BPPADisclosure and consent requiredCivil penalties up to $7,500 per violation
Texas CUBIConsent for biometric identifier captureCivil penalties up to $25,000 per violation
Connecticut, Nevada, OregonAll-party consent for recordingsWiretapping statute violations between $5,000 and $6,250

Data Flow Risks Venue Bans Ignore

DEF CON and NY courts are focusing on physical access, because they can control who enters their spaces, but employers deal with a messier question about what happens when your employee brings the device to a boardroom or patient room.

Data flows escape venue boundaries entirely. Numerous types of smart glasses route AI processing through ChatGPT and similar large language models, while Meta’s own privacy settings use voice recordings and videos to train AI models by default. Employees can’t opt out of automatic voice recording, even when the wake word feature is disabled.

Where captured data goes:

  • Third-party cloud servers operated by vendors
  • AI training datasets without explicit opt-out
  • Consumer accounts with security practices IT can’t audit
  • Unencrypted storage on lost or stolen devices

Consider these high-risk scenarios:

  • Hospital staff capture patient vitals and wounds, triggering HIPAA Security Rule obligations.
  • Financial services employees record customer account numbers, risking Gramm-Leach-Bliley Act violations.
  • Attorneys use AI glasses during privileged communications, risking waiver of attorney-client privilege.
  • Lost or stolen glasses store unencrypted footage, activating breach-notification laws in all 50 states.

Shadow AI compounds the issue further because personal devices syncing to consumer cloud accounts bypass corporate security audits completely. IT teams can’t control where data gets stored, who accesses it, or how long retention lasts, so data minimization principles that are part of CCPA and GDPR are incompatible with continuous ambient sensing baked into AI glasses architecture.


Compliance Checklist for Leaders

Read your current policies now because chances are they mention “recording devices” without naming smart glasses specifically, and that gap potentially leaves you exposed to business risks.

Policy definition requirements:

  • Cover camera plus microphone plus AI processing plus third-party cloud transmission
  • Include prescription versions explicitly, matching NY and DEF CON’s no-exception stance
  • Specify geographic limits: conference rooms, client sites, patient areas
  • Define prohibited uses versus approved operational scenarios

Vendor assessment checklist:

  • Encryption practices during transmission and storage
  • Access control documentation from security teams
  • Retention commitments with deletion guarantees
  • Whether captured data trains vendor AI models
  • HIPAA business associate agreements for healthcare deployments

Topics for your training program:

  • Continuous sensing occurs even when users think devices are off
  • Cloud transmission happens regardless of perceived activity state
  • Third-party processing may expose internal conversations to external processors
  • Lost device protocols and incident reporting procedures

Three Actions To Take This Quarter

  1. Scan your organization’s existing acceptable use and recording policies for smart glasses language gaps, update your incident response plans to include wearable device compromise as a scenario, and review cyber insurance coverage to confirm AI-enabled wearables fall inside policy scope.
  2. If your organization is using smart glasses, remember that vendors won’t volunteer security documentation unless asked. Request encryption practices, access control details, and retention commitments during procurement. Confirm HIPAA business associate agreements exist for healthcare deployments and ask vendors whether captured data trains their models.
  3. Employees need training that goes beyond “don’t bring these in” because they must understand what happens when the glasses are on – see the training topics above.

Bottom Line

DEF CON and NY courts didn’t wait for lawsuits to act; they moved on known business risks, and employers face the same exposure with higher potential consequences. Either your policy addresses them now, or your lawyer will have to explain in court why it didn’t later. Pick which conversation you want to have.

Similar Posts