The Gadget in the Room Just Grew Up

Four months ago, this was a novelty question. Wetherspoons, Canberra and a sold-out AU$89 pair of glasses say otherwise.

By Louize Clark

Four months ago I wrote the first Tuesday Paper about a gadget entering the room.

I wasn't arguing that smart glasses should be banned. I was asking a narrower question: what happens when a camera, a microphone and an AI system start turning up in objects nobody has ever treated as technology infrastructure, because nobody signed anything, approved anything, or thought to ask.

At the time, it still felt like something organisations had a bit of room to think about before it became urgent.

That's the part that's changed. Not the argument. The floor underneath it.

The floor has moved

The most important change since April isn't what smart glasses can do. It's who can now walk in wearing a pair, and how little thought it took them to get there.

Kmart in Australia recently sold an AU$89 pair of camera-equipped glasses, and they sold out nationally within a week. That's not a premium early-adopter purchase any more. That's an impulse buy sitting next to the sunglasses stand. And increasingly, these aren't a second pair of “tech glasses” at all. They can simply be someone's prescription glasses which quietly removes the last visible clue anyone had, because the thing on someone's face now looks exactly like the thing that was already on their face last year. And the same underlying capability is spreading into earbuds, into watches, into devices that don't look anything like “a gadget” at all.

Which raises a genuinely useful governance question: at what price point does an emerging technology stop being an innovation decision and start being an ordinary consumer purchase? And once it crosses that line once somebody can buy the capability without speaking to IT, HR, procurement or their employer where, exactly, does an organisation's AI governance actually begin?

That's the sentence worth sitting with. Not “should we allow smart glasses.” But: form was never really the thing worth regulating. Capability is.

Everyone else got the memo

I noted the Australian development in Friday's AI Law Report, and it took me straight back to the first Tuesday Paper I wrote. Australia's Attorney-General has asked the country's Privacy Commissioner to give the privacy implications of smart glasses “priority consideration”, specifically raising inappropriate recording, harassment and surveillance. That's not a campaign group or a trade body raising the alarm. That's a government minister.

The UK's response has been faster, and in its way blunter. Wetherspoons has banned filming with Meta's smart glasses across its 800-plus pubs. You can't film customers or employees without their permission, was the founder's own explanation, and in his view Meta's glasses breach that code, and plain common sense, by making surreptitious filming easy. Soho House, a clutch of West End theatres and Comic-Con UK have all followed with restrictions of their own, in the same fortnight.

I don't want to spend long cataloguing the list, because the list isn't really the point. The point is what it tells us: institutions are now setting their own behavioural boundaries before the regulatory position has caught up with them. Nobody waited for a law. A pub chain, a members' club, entertainment venues and a national government have all, within a very short period, concluded that this is no longer a question they can ignore. Most of the restrictions appearing so far aren't really objections to smart glasses as objects. They're objections to recording because the camera is what turns something that looks like ordinary eyewear into something capable of silently capturing the room.

The pub has a door. The office doesn't.

Here's the difference that actually matters. A pub has an entrance. A theatre has tickets and ushers. A private club can make entry conditional on the rules. A cruise line has terms and conditions and, if it comes to it, A cruise line has terms governing what passengers can do on board. Every one of these venues can say, at a single, controllable point of entry: you cannot bring that capability in here.

The office doesn't have a bouncer.

Why that makes this a harder problem, not a smaller one

A workplace in 2026 is rarely one employer, one building and one workforce any more. It's a hot-desk floor shared across three teams. It's a coworking building with twenty different companies behind the same front door. It's a council employee moving between municipal sites, a contractor sharing a meeting room with staff, a supplier visiting for the afternoon, a hybrid call where half the room is physically present and half isn't. Whose policy governs a shared meeting room booked by two different organisations? Who's responsible for a visitor nobody vetted?

And the capability isn't only arriving through the route governance is built to watch a considered purchase, evaluated and signed off. It's arriving through routes most policies were never designed to see at all: a vendor pushing an update into software the organisation already owns, an employee adopting a personal AI tool because it's useful, a piece of hardware that walks in attached to a person rather than a procurement order, a contractor's own equipment, a visitor who was never covered by an employment policy in the first place. If governance only watches the procurement route, how much of an organisation's actual AI exposure does it simply never see?

The glasses your business might already be paying for

Here's the question that stopped me, because it's more mundane than anything above and I think it matters more. How many employers currently contribute towards employees' glasses through an eyecare allowance? And how many of those policies say anything at all about what happens when “glasses” starts including a camera and a microphone?

Does an eyecare voucher exclude connected eyewear? Does finance know whether the pair it's reimbursing contains anything beyond a lens prescription? Does the expenses policy even ask the question? If an employee tops up the difference themselves, has the organisation “provided” the device, or simply helped pay for it and does that distinction hold up against the same information security policy that would otherwise prohibit exactly this kind of device on the premises?

A pub can ban the glasses at the door. An employer may have unknowingly helped pay for them.

That's not really a story about optical vouchers. It's a demonstration of how many entirely ordinary organisational processes, expenses, benefits, procurement thresholds were designed before ordinary objects acquired AI capability, and haven't been looked at since.

Bring Your Own Device just became Bring Your Own AI

Most organisations have some version of a BYOD policy by now a decade of governance headaches around personal phones and laptops taught them that much. But BYOD assumed the thing walking through the door looked like technology. A phone looks like a phone. A laptop looks like a laptop.

Wearable AI doesn't play by that rule. It can be spectacles. Earbuds. A watch. A ring. A pendant. Eventually, probably, something stitched into clothing. Bring Your Own Device becomes Bring Your Own AI at exactly the moment the device stops announcing itself as one and a policy built around recognising hardware isn't much use against hardware nobody in the room can identify.

Policies that ban objects age in a single product cycle

A rule that says “Meta Ray-Bans prohibited” is a rule with an expiry date built into it, because it will be irrelevant the moment the next device arrives wearing a different logo. What actually needs governing isn't the brand. It's the capability underneath it: whether the device can capture audio, capture video, livestream, transcribe, translate, identify a face, sense a location or a health signal, and where whatever it captures ends up being stored and analysed.

And “just turn it off” isn't really an answer to any of that, however often it gets offered as one. Can anyone else in the room verify the camera is actually off? Is the microphone still listening for a wake word? Is processing happening locally, or somewhere else entirely? Can a firmware update quietly change what “off” means overnight? And the device doesn't necessarily have to change for the operating condition around it to change sometimes the update is the change. A policy that depends entirely on what the wearer says the device is doing isn't governance. It's trust, wearing governance's clothes.

Maybe the question isn't which devices. It's which rooms.

Not every space in a building carries the same risk. An open kitchen is not a board meeting. It is not an HR grievance conversation, a legal consultation, a clinical appointment, a safeguarding meeting or a client pitch. Treating every room the same way one blanket rule, everywhere is probably the wrong model, because it either under-protects the sensitive rooms or over-restricts the ordinary ones.

The more useful question might not be “can employees wear smart glasses at work.” It might be “what should be capable of entering this particular room.”

The adjustment nobody wants to get wrong

None of this is straightforward, because some of the same capability is genuinely valuable — for hearing assistance, live captioning, memory support, visual description, magnification, translation, and a range of neurodivergent and other disability-related needs. Prohibiting the device outright can mean prohibiting someone's legitimate adjustment.

Which means the right question isn't ban or allow. It's something more layered: what's the need, what capability does it actually require, what environment is it being used in, and is there a way to deliver that capability — organisation-controlled, narrower in what it captures and where the output lives without asking one person to choose between an adjustment and everyone else's confidentiality.

The person who never opted in

Most of this conversation, understandably, focuses on the wearer. It's worth flipping it. The person we're talking about may never have bought the device at all, never downloaded anything, never agreed to a single term and condition, and quite possibly never even clocked that the person across the table was wearing anything other than glasses. Their voice, their image, the document on their screen, the conversation they were having, still ends up inside the capture. What does meaningful consent look like for someone who was never the user of the technology, only its subject?

Whose data is it when the device is personal but the room isn't

The device belongs to the employee. What it captures rarely belongs only to them. If a transcript gets generated, where does it actually live on a personal account the organisation has no access to, or somewhere the business can find it if it needs to? What happens under a subject access request, in litigation, or simply when that employee leaves and takes the account, and everything synced to it, with them? Ownership of the hardware and ownership of the responsibility for what it captured are two entirely different questions, and most policies currently only answer the first one.

It's worth being honest, too, that the risk here isn't only about any single captured moment. A device that can remain present all day, repeatedly seeing, hearing and capturing parts of an environment, doesn't necessarily create one exposure. Over time it can create an accumulating one. Small, individually unremarkable observations, held somewhere over weeks, start to add up to something considerably more revealing than any of them were on their own. That's a different category of risk to “was I filmed at the bar,” and it's one this month's venue bans were never built to address, because a bar only has to worry about the moment, not the month.

Nobody has to be recording for something to change

Technology normalisation changes behaviour before it changes data. Everyone knows how they behave differently when someone's holding up a phone. Almost nobody has worked out yet how they behave around a colleague wearing ordinary-looking glasses that might, or might not, be capturing the room. Will people stop raising sensitive concerns out loud? Will informal conversations change? The organisational harm here doesn't require an actual breach. The uncertainty alone is enough to change what people are willing to say, and where.

Six departments, no owner

Ask who owns this inside a typical organisation and watch the question bounce. IT, because it's a device — except it's personal, and IT never issued it. HR, because it's worn by an employee — except it might also affect a visitor HR has never met. Finance, because it might have been reimbursed through an allowance. Data protection, because it processes personal data. Security, because it can capture the building. Legal, because it might capture something privileged. Facilities, because it physically enters the space. Procurement — except nobody procured anything.

When a risk sits across six functions, the danger usually isn't that nobody is responsible. It's that everyone is a little bit responsible, and nobody actually owns the whole of it.

What four months of watching this taught me

I started thinking seriously about a workplace approach to wearable AI back in December. By March, that had become a standalone policy. Issue 001 followed not long after. This month, I rebuilt that approach from the ground up, because the question itself had already moved on from where it started from “which devices” towards capability, environment, adjustment, contractors, visitors and incident response, all at once.

I'm not telling you that to say I called it early. I'm telling you because my own thinking on this had to change substantially in four months, and I think that tells you something honest about the pace this category is moving at — considerably faster than most organisational policy cycles are built to keep up with.

The bigger question this was always about

None of this is really about spectacles. It's about where AI capability now lives. It used to live in identifiable systems — software an organisation bought, or at least knew it was running. Increasingly, it lives in the operating environment itself: in meeting platforms, in CRMs, in phones, and now in glasses, earbuds, and the people who walk through reception wearing them.

Which means the question organisations need to be asking isn't really “what AI have we bought.” It's “what AI capability is currently present around us, whether we bought it or not.” That's a considerably bigger question than a dress code, and I don't think most organisations have started asking it yet.

Perhaps the practical version of that question breaks down into a handful of smaller ones. What capabilities are entering our workplaces without ever going through procurement? Which of our rooms should never have those capabilities operating inside them? How do we tell the difference between someone's ordinary personal use of a device and our organisation quietly becoming responsible for what it processes? How do we protect someone's legitimate adjustment without creating an invisible capture environment for everyone else in the room? And, underneath all of it — who, inside the organisation, actually owns this question?

Wetherspoons could put a notice on the door. Most workplaces are going to need something considerably more thought through than that.

The office doesn't have a bouncer. It needs governance.

 

About AI Policies UK

AI Policies UK helps organisations understand the AI capability already operating across their business — chosen, inherited and embedded. Get in touch: info@aipolicies.uk

Previous
Previous

You Cannot Secure What You Cannot See

Next
Next

AI Doesn't Replace Decisions. It Changes the Conditions Decisions Are Made In.