Consumer wearables, the enterprise security threat

David Sandell Avatar

Posted on

by

AI-enabled consumer wearables have moved beyond far-fetched gadgets into something people use in everyday life, from your local barista to the stranger next to you on the train. With increased adoption and enhanced features, comes a new wave of security and data privacy concerns presenting Australian CISOs and security leaders with a unique governance challenge.

Meta smart glasses sales tripled year on year across 2025, and Meta reported Reality Labs revenue of $431 million (USD) in Q2-26, putting camera-and-mic eyewear firmly in mainstream consumer territory. The wearable market is broader than eyewear, spanning always-on pins, clip-on recorders used by millions of professionals, and smart rings that track biometrics.

The unseen risk to enterprise environments from wearables is not well understood, or managed relative to the potential impact of misuse. These devices have the ability to capture sensitive data, intellectual property (IP), and confidential conversations in high-risk environments (boardrooms, server rooms, clinical settings, and research labs), with no real way for conventional network or endpoint controls to see what is happening.

Security leaders should assume these devices will enter sensitive environments, regardless of current policy. Like any unmanaged device that does not connect to the corporate network, conventional controls are ineffective and the risk needs to be mitigated through physical and administrative policy instead.

Attack surface and threat vectors

Wearing smart glasses, or any other consumer wearable at work is not evidence of nefarious intent. The risk is the device, not the person, and that risk exists regardless of what the wearer intends. They break down into two broad categories:

Murky software supply chains

You don’t need an external attacker or a malicious insider for this to go wrong; the vendor’s own murky supply chains are enough. Throughout 2026, CI-ISAC has spoken with our members about software supply chain risks. This is another clear example of that risk in motion. Anything captured on your premises by an employee or visitor’s wearable is likely to be routed offshore for human review, or used to train AI models, as a standard vendor process. There is no contract between your business and their subcontractor, no data processing agreement, and no visibility into who is on the other end.

Example: In February 2026, Swedish journalists revealed that Meta routes footage that is captured by Ray-Ban Meta glasses users to human reviewers at a Kenya-based subcontractor to improve the AI’s performance. Workers described reviewing footage that included nudity, financial details, and private conversations. Meta claimed that faces are automatically blurred before review, but workers on the ground said the blurring frequently failed.

Implication: This is a company with a market cap in the hundreds of billions and a dedicated trust and safety function. If that’s the standard of control at the top of the market, it is worth considering what is happening to the information captured by the $89 K-Mart glasses, Amazon wearables, or the AI transcribers being used here in Australia. There is no named subcontractor to investigate, no journalist digging, and in most cases, no meaningful privacy policy. Unlike European Union organisations operating under GDPR, Australian entities have no (effective) legal mechanism to enforce data deletion requests or audit security controls against offshore Chinese software platforms. When sensitive IP or operational conversations are captured by $30 to $80 offshore wearables, you can safely assume that data is permanently retained and subject to foreign state access.

Jurisdictional risks for wearables

For critical infrastructure sectors, the underlying threat is not only poor privacy hygiene, but Chinese statutory jurisdiction. Under China’s National Intelligence Law (2017) and their Data Security Law (2021), Chinese technology companies and their subsidiaries are legally obligated to support, assist, and cooperate with national intelligence efforts. Members cannot rely on vendor privacy policies or end-user licence agreements to protect enterprise data. Once audio, location data, or transcribed boardroom conversations hit Chinese controlled infrastructure, the Chinese Communist Party can compel access to that data at any time, with zero visibility, audit capability, or legal recourse for Australian organisations.

Positive security culture fills the gaps

Unless you’re working in a Zone 4+ under the Protective Security Policy Framework (PSPF), an airport, or maybe Parliament House – the chances are throwing a human scanner at your building entry isn’t viable for your organisation. There aren’t meaningful network or endpoint security controls for detecting these devices; and that leaves people. Creating a positive, and no-fault security culture is critical here. Clear signage tells visitors and contractors they are required to take off and turn off their smart glasses or AI pins in designated areas. They also remind staff that they are obligated to say something. Framing the policy as what devices are not allowed in specific areas depersonalises any conversations that are needed in order to enforce the policy. No one is at fault, it’s the rule for that area. 

Our National Intelligence Office produced a strategic briefing for our members, which contained the following recommendations to reduce the identified risks: 

  1. Update your existing device policies: Most companies already have a device policy, but in reality, smart glasses and adjacent wearables have fallen through the cracks. You are encouraged to:
    • Assess whether they are permitted on-premises, under what conditions, and by whom and where.
    • Assess and name high-value spaces where they are prohibited and back this with signage so the rule is visible. 
    • Ensure any changes cover transient staff and contractors.
  2. Educate staff and foster your reporting culture: Once policy exists, train teams on it and the specific enterprise risks it aims to prevent, including IP exposure, biometric data capture, offshore data risks, and personal criminal liability under state surveillance law. Pair this with a low-friction way for staff to flag smart glasses or AI pins in sensitive areas.
  3. Align enforcement across functions: No single team owns this risk end to end. Cybersecurity, physical security, legal, HR, and compliance all need visibility and a coordinated response. Assign clear ownership for who actions a reported breach, whether that is a conversation, a formal incident, or a compliance notification.
  4. Require consent protocols: If permissible in that area, require that any smart glasses or personal recorders display an active, unobscured recording indicator, and that the wearer seek the agreement of present individuals before recording.
  5. Monitor regulatory change: Privacy Act Tranche 2 reforms, state surveillance law, and OAIC guidance are all actively moving, assign ownership for tracking developments relevant to your sector so policy does not get left in the dust.