Norway's AI Glasses Ban Opens a New Category of Physical Surveillance Compliance Risk
What happened
Norway's government announced plans to introduce a temporary ban on AI-enabled smart glasses in public spaces, as reported by AI glasses face their first major government crackdown. The ban would apply to locations including parks, beaches, schools, and kindergartens. The digitalization minister described the measure as a bridge period, giving authorities time to conduct a thorough assessment before permanent national rules are established through an expert group. The stated driver is privacy risk from covert recording of bystanders by passersby wearing AI-capable eyewear, a concern that existing data protection law has not resolved. Norway is not an EU member but follows EU privacy law through the European Economic Area. This action may signal broader European regulatory momentum under frameworks such as the EU AI Act (Regulation (EU) 2024/1689) and the General Data Protection Regulation (GDPR).
Why it matters
- ·Norway's action creates a new compliance category: physical-space AI surveillance by individuals using consumer wearables. Most enterprise AI governance programs cover software systems procured by IT, leaving employee-owned or visitor-carried AI glasses entirely outside existing policy scope.
- ·Organizations with operations in Norway face direct exposure if employees wear AI-enabled devices in public-facing locations such as retail floors, campuses, or client sites. A ban, once enacted, could apply to workplace common areas or public-adjacent property, and violations could implicate General Data Protection Regulation (GDPR) obligations on unauthorized personal data collection.
- ·The temporary nature of the ban signals that permanent, potentially stricter rules are coming. The expert group process means compliance teams have a window to engage, but also a deadline: frameworks established now will be harder to revise once permanent rules take effect.
Governance controls affected
What to do now
- ☐Review your employee acceptable use policy to determine whether it addresses AI-enabled wearable devices such as smart glasses, and update it to cover use in public-facing workplaces and public spaces.
- ☐Ask your legal and HR teams whether your Norwegian operations include any locations that would fall within the proposed ban's scope, such as campuses near parks, client-facing areas, or school-adjacent sites.
- ☐Conduct a brief inventory of any AI-enabled wearable devices provided to employees or used by contractors in Norway, and assess whether current data handling practices for those devices comply with GDPR.
- ☐Assign a monitor to track the Norwegian expert group's output and any EU-level signals, so your compliance team can respond as permanent rules are drafted rather than after they are finalized.
- ☐Check whether visitor and contractor onboarding materials for Norwegian sites disclose any restrictions on recording devices, and add explicit AI wearable language if they do not.
What to watch next
Compliance teams should track the output of Norway's expert group, which will shape permanent national rules and may serve as a template for other European jurisdictions. The EU AI Act (Regulation (EU) 2024/1689) does not yet specifically address consumer wearable AI in public spaces. However, ongoing implementation guidance from the EU AI Office could extend to this category. The CCPA Regulations on Automated Decisionmaking Technology, Risk Assessments, and Cybersecurity Audits in California and similar US state-level privacy frameworks may face pressure to address wearable AI. Norway's action draws attention to the gap in existing frameworks. Organizations operating across multiple jurisdictions should add wearable AI to their multi-jurisdiction compliance monitoring workflows before the first permanent rules arrive.
Stay ahead of stories like this
Get every Global AI governance development like this one, plus the rest of the week's developments. Every Thursday.
Recent issues
- AI agents this week destroyed backups at machine speed, leaked sensitive data without developer approval, and drew federal scrutiny that may extend liability to every enterprise deploying them.1 Oct
- A vulnerability that bypasses approved-plugin controls, new criminal liability for executives, and a landmark safety-disclosure framework all point to one conclusion: AI systems are outpacing the controls organizations have built around them.23 Sept
Free every Thursday. Unsubscribe anytime.
