RatedWithAI

RatedWithAI

Accessibility scanner

Biometric PrivacyJuly 30, 2026

BIPA and AI Smart Glasses 2026: Biometric Risk When Employees Wear the Camera

Every biometric compliance playbook written in the last decade assumes the camera is bolted to a wall. You post a notice at the entrance, you collect releases from the people who walk past it, and the geometry of the room does the scoping for you. AI smart glasses and body-worn assistants delete that assumption. The sensor now walks into places your consent flow has never reached, and it arrives with a model that turns faces and voices into identifiers.

No Entrance Sign
A moving sensor has no fixed consent surface
Template = Collection
Deriving the identifier triggers duties, not storing video
Face + Voice
One interaction can create two separate claims

The Line Between Recording and Biometrics

Video alone is not a biometric identifier. A wearable that captures footage and stores it raises recording-consent, employee-monitoring, and data-security questions, but it is not yet in biometric-statute territory. The line is crossed by derivation: when a model converts a face into a mathematical template, or a voice into a speaker embedding, the output is the regulated thing.

This distinction is where procurement conversations go wrong. A vendor will accurately say the device "does not store facial recognition data," meaning templates are transient. Under a statute that regulates collection rather than retention, transient derivation is still collection. The question to put in writing is not whether templates are stored but whether they are ever computed, on which surfaces, and from whose faces.

Four Ways Wearable AI Breaks a Working Consent Program

The bystander problem

A fixed camera's field of view is a property you control, with signage and, for employees, a signed release on file. A wearable crosses into public sidewalks, client offices, hospital corridors, and homes. Those bystanders never encountered a notice, and no retroactive disclosure cures a collection that already happened.

The employee-as-collector problem

The wearer is simultaneously a data subject and the instrument of collection. Employee releases typically cover monitoring of the employee, not the employee's role in collecting biometrics from third parties. Consent scope and indemnity in the employment paperwork rarely match what the device actually does.

The always-on voice layer

Voice assistants that wake on a keyword and perform speaker identification produce voiceprints, an enumerated identifier. Layer two-party-consent recording law on top and a single hallway conversation can support a biometric claim and a wiretap claim with different elements and different damages.

Feature updates that change the legal posture

A firmware release that adds face-based contact suggestions or speaker labelling converts a compliant recording device into a biometric collector overnight. Programs that assessed the device at purchase and never again are the ones that get surprised by their own vendor's changelog.

Why the Damages Math Is Different From Ordinary Privacy Risk

Most privacy statutes route enforcement through a regulator with discretion, and many give a cure period. Illinois BIPA gives individuals a private right of action with statutory damages and no requirement to prove actual harm, which is why it produces class actions that other biometric laws do not. Texas CUBI and Washington's biometric provisions are enforced by the attorney general instead, which changes who sues but not whether the underlying collection was lawful. The practical consequence for a wearable deployment is that exposure scales with the number of people the device passed, not the number of records you kept — a metric no retention policy can shrink after the fact.

Deployment Checklist for AI Wearables

1. Establish Whether Templates Are Computed At All
  • Get a written answer on face and voice: is an identifying template or embedding derived, on device or in cloud, ever
  • Distinguish detection (a face is present) from recognition (whose face it is) — only the latter yields an identifier
  • Require notice of any firmware or model change that adds recognition, labelling, or enrolment features
2. Design Out the Bystander Case
  • Restrict matching to an enrolled roster of people who signed a written release; ignore everyone else by architecture, not policy
  • Discard raw frames and audio buffers on a short, documented timer, with no silent training use
  • Define no-capture zones — restrooms, medical areas, client premises, union meetings — and enforce them in the device profile
3. Fix the Employment Paperwork
  • Obtain BIPA-grade written releases from wearers covering the specific purpose and the retention schedule
  • Address the wearer's role as collector, including what they must disclose verbally before capturing in a new setting
  • Publish the retention and destruction schedule, and confirm someone actually executes the destruction step
4. Contract and Prove It Afterwards
  • Negotiate audit rights, security commitments, and indemnity that survives a class action, not just a data-breach clause
  • Keep an inventory of devices, firmware versions, and enabled features by date so you can reconstruct any single day
  • Run a pilot in a single non-Illinois, single-party-consent site first and document what the pilot changed

Audit the consent surfaces users actually see

Biometric claims frequently begin with a notice nobody could read or a consent flow that could not be completed with assistive technology. RatedWithAI scans your web and app surfaces for those accessibility and compliance gaps — start with a free scan.

Scan Your Product for Free →

Frequently Asked Questions

Our glasses only blur faces. Is that enough?

It helps considerably, but ask how the blur is achieved. If the pipeline detects a face and blurs the region without computing an identifying template, you have a strong position. If it recognises whose face it is in order to decide whether to blur — for example to leave enrolled colleagues unblurred — you are deriving identifiers on everyone in frame, which is the opposite of the intended result.

Does an employee's signature cover the customers they interact with?

No. Consent runs from the person whose biometrics are collected. An employee cannot consent on behalf of a customer, a patient, or a passer-by. Where you need capture in customer-facing settings, the realistic paths are enrolment with a release for repeat participants, or a design that never computes identifiers for anyone outside the enrolled roster.

We deploy outside Illinois. Does BIPA still matter?

It matters if any covered person is in Illinois, and business travel, remote employees, and multi-state customers make that easy to trigger accidentally. Beyond Illinois, Texas CUBI and Washington law impose consent duties enforced by state authorities, several comprehensive privacy statutes treat biometrics as sensitive data requiring opt-in, and Colorado and other states have added biometric provisions. Building to the strictest standard is generally cheaper than maintaining per-state device profiles.

What if the wearable is only used for accessibility assistance?

The purpose is sympathetic and does not change the statutory analysis. An assistive device that identifies people for a user with low vision is deriving face templates from third parties who did not consent. The compliant version enrols the people the user chooses to add, with releases, and declines to identify anyone else — which also happens to be the design users tend to prefer.

How should we handle vendors who will not answer these questions?

Treat non-answers as a finding, not a delay. A vendor unable to state whether templates are computed, where, and from whom cannot support your compliance position, and that same opacity will surface again during discovery. Put the questions in the RFP so the answers are contractual representations rather than sales-call recollections.

Related Guides

Is your own site ADA compliant?

Run a free WCAG 2.1 AA scan on any public URL. Real axe-core checks in a real browser — instant report, no signup.

Need it watched instead of checked once? Starter is $29/mo for continuous monitoring, audit trails and PDF/CSV exports.