Privacy · Biometrics
Biometrics gets a new face: when surveillance becomes an everyday accessory
An almost ordinary pair of glasses can now contain the building blocks of facial recognition. A magazine digest on NameTag, non-consenting bystanders and infrastructure that outlives major events.

In this article
Until recently, facial recognition had a recognisable setting: a camera mounted high above the street, an airport gate, a control room. It looked like infrastructure. In 2026, it can take the much more familiar form of a pair of glasses. The shift is quiet but decisive: biometrics is leaving walls and checkpoints and entering the objects we wear.
This does not mean that every pair of smart glasses already identifies passers-by. It means that the technical parts required to do so can fit inside a consumer device, connect to a phone and sit inside an app installed at enormous scale. The question is no longer only where the cameras are. We also need to ask who is looking, for what purpose and against which reference data.
The turning point: an almost ordinary frame
Smart glasses have learned from the cultural failure of their predecessors. Early models shouted “gadget” from several metres away: their shape warned people nearby that they might be filmed. Current models try to disappear into normal life. A tiny camera, microphones and speakers blend into a frame we read as a fashion accessory.
That successful design also creates an asymmetry. The wearer knows that a sensor is present. Someone in its field of view may not be able to distinguish a camera from a hinge. The technology becomes more comfortable at the very moment it becomes harder to read socially.
Meta says that an indicator lights up when photos or videos are captured and recommends asking people nearby for permission. Those are useful precautions. They mainly address visible capture. On their own, they do not tell a bystander whether an image becomes a biometric template, whether it is compared with a database, how long it remains stored or who controls the software performing the operation.
NameTag: the prototype inside the app
The turning point surfaced in June. An analysis of the Meta AI app uncovered an internal system called “NameTag”. It was not enabled for the public, yet its components had already been distributed through the companion app needed for several functions of Meta’s Ray-Ban and Oakley glasses.
The mechanism described was complete in principle. One model detected a face, a second cropped it and a third converted it into a digital signature. That faceprint could then be checked against a gallery stored on the phone and configured to receive updates from Meta’s servers. A match would trigger a notification for the wearer. Unrecognised faces were, according to the analysis, cropped, indexed and placed in a pending folder.
An independent researcher using the pseudonym Buchodi tested the pipeline with a portrait of Michel Foucault. The app reported that the person had been recognised. This does not prove that a public service was secretly running. It proves something more precise: the main components already formed a technically functioning system, even though its interface remained inaccessible without specialised tools.
This distinction avoids two mistakes. The first would be to claim that the glasses identify everyone in the street today. The second would be to dismiss NameTag as a loose idea on a whiteboard. Between concept and commercial product lies a grey zone: software that has already been assembled, installed and tested.
The bystander becomes the missing party

A phone owner generally chooses to enable facial recognition to unlock their own device. The face and the device belong to the same relationship. When glasses look outwards, the person whose face is processed is no longer the person who bought, configured or accepted the service. The real subject of wearable biometrics is this silent third party: a colleague, the person at the next café table, someone encountered for a minute in a station.
An opt-in button for the owner of the glasses is therefore insufficient. The bystander would also need to know that identification is being attempted, object to it, verify that no template was retained and request deletion. Those rights are hard to exercise when a person does not even know the processing exists.
The distinction between a photograph and a faceprint matters. A photograph becomes biometric data when technical processing extracts characteristics that allow a person to be uniquely identified. At that point, the face is no longer only an image. It becomes a search key.
From a face to a route is one data join
Recognising someone answers “who?”. A mobile device often also knows “where?” and “when?”. If those elements are linked, they create a presence event: this person was seen at this place at this time. At scale, a sequence of such events can reveal routines, relationships and movements.
Precision matters. The NameTag investigation did not demonstrate a global map of bystanders’ movements. It showed an architecture capable of creating and comparing faceprints, with a database on the device that could receive updates. Tracking is therefore an architectural risk, not an established fact.
Local storage does not settle the issue either. “Stored on the phone” can reduce some risks, but we still need to know who selects reference profiles, who can update the gallery, whether the app can read the results and whether pending images leave the device. Where data is stored matters; who controls it matters even more.
The stadium as a full-scale laboratory
Major events provide a second preview of this normalisation. A global tournament has to coordinate crowds, transport, teams, fan zones and real threats. It creates a powerful case for quickly deploying detection systems, command centres, video networks and analytical tools.
The 2026 World Cup showed the scale involved. FIFA says its tournament and broadcast networks transported 13 petabytes of data, with video infrastructure and a private 5G network across all sixteen stadiums. Aviation authorities also created temporary no-drone zones around venues and several fan gatherings.
Not all of this technology is biometric, and treating it as one category would weaken the argument. It does belong to the same operational landscape: capture more, centralise faster and make decisions in real time. In that landscape, adding facial identification is no longer an industrial leap. It is another function in a chain that is already funded and connected.
What remains after the supporters leave?

An empty stadium after the final poses the right question. Some installations are genuinely temporary. In Vancouver, for example, the public contract covering Wi-Fi, fibre, CCTV and technical support required the teardown or removal of temporary infrastructure after the event. That clause is a concrete safeguard.
Yet the legacy of a system is not measured only by the number of cameras left on poles. Contracts, operations centres, procedures, trained teams, vendor relationships and a new idea of what feels acceptable also remain. A temporary capability can become a permanent expectation: if a city was able to observe more for six weeks, why should it return to the previous level?
Sport speeds up this acclimatisation because celebration makes the exception comfortable. The public accepts a search, a barrier or a camera in exchange for immediate safety. The problem begins when the purpose becomes vague after the event, retention periods grow or the same infrastructure serves other populations without a new debate.
What European law sees — and what it sees less clearly
The GDPR defines biometric data as personal data resulting from technical processing of physical, physiological or behavioural characteristics that allow the unique identification of a person. Processing it for identification concerns a special category of data and requires a strong legal basis, a specified purpose and suitable safeguards. The European text therefore draws a clear line between an ordinary image and a template designed to recognise.
The European AI Act places very strict limits on real-time remote biometric identification in publicly accessible spaces when it is used for law enforcement. The framework adopted in 2024 contains prohibitions and narrow exceptions with conditions. The European Data Protection Board also stresses that identification in an uncontrolled environment without the active involvement of the individual carries a different level of risk from verification initiated by a person on their own device.
Consumer glasses complicate the map. The buyer may be a private individual, the software belongs to a company, the database may sit on the phone and the observed person is in public space. Identifying the controller, the purpose and the reach of the household exemption then becomes central. Technical miniaturisation must not miniaturise legal duties.
The IBCSC digest: seven questions for a camera you can wear
- Does the device record an image, or does it turn the face into a biometric template?
- Does the observed person receive an understandable signal at the exact moment of processing?
- Is recognition limited to contacts enrolled voluntarily, or can it query a broader gallery?
- Where are portraits, faceprints and match results stored?
- Who can add, remove or update the reference profiles?
- How long do unrecognised faces remain in a pending queue?
- After an event or test phase, what mechanism actually enforces shutdown, deletion and audit?
These questions are less seductive than a demonstration of glasses that can “remember” a name. They decide whether the object assists its owner or turns the people nearby into raw material.
Surveillance becomes normal when it stops looking like surveillance
The next stage of biometrics may not be announced by a larger camera. It will arrive with better design, a lighter battery and a promise of assistance. That is what makes it difficult to discuss: the object is useful, sometimes meaningfully inclusive, while the risk falls mainly on those who did not choose it.
The answer is not to reject every wearable innovation. It is to move the centre of gravity towards the person being observed. No benefit offered to the wearer should make the bystander invisible in the contract. An indicator light, local storage and an app setting are parts of an answer; they do not replace a clear technical boundary, verifiable information or an effective right not to be identified.
Biometrics becomes ubiquitous on the day we stop noticing the device that carries it. Before that day, we need to decide which functions must remain impossible, which data must never be created and which traces must disappear with the crowd.
Editorial information
- Written by
- Jeremy Kraft
- Last reviewed
- Method
- Public sources, editorial review and proportionate guidance.