TL;DR: On June 8, 2026, Politico Europe reported that European privacy regulators are escalating their warnings over smart-glasses surveillance, with the European Data Protection Board (EDPB) commissioning a report on the "social acceptability of smart glasses" due this summer [1]. France's CNIL opened the EU regulatory escalation on May 11 with a public call for "vigilance" that explicitly named the "almost invisible and omnipresent" surveillance risk, as reported by Politico [1][2]. Sweden's data protection authority director general Eric Leijonram told Politico the risks are "high" and that society needs to decide whether the technology "is acceptable in our society" [1]. The proof of harm regulators are anchoring on is the same scandal that has been building for months in the US: the Meta Ray-Ban Kenya data-labeling reporting that surfaced bathroom and intimate recordings used to train the on-device AI, and the EFF's June 4 finding that Meta has already shipped facial-recognition code to millions of Ray-Ban glasses [3][4]. The next two months will determine whether Brussels treats smart glasses as a new product category requiring EU-level intervention, or whether the question stays with national data-protection authorities that move slowly and case-by-case.
The EDPB Report Due This Summer
The European Data Protection Board is the body that gathers the EU's national privacy regulators and coordinates GDPR enforcement. Its chair, Anu Talus, told Politico the EDPB has commissioned a report on the "social acceptability of smart glasses" that should be ready this summer [1]. Talus framed the technology in plain language: smart glasses "really bring the filming, collecting information from people, into a new level if you compare it with smartphones" [1]. The report is the first EU-level regulatory product the smart-glasses category has triggered. It will land as either a green light for national enforcement or a call for a new EU-level instrument.
The EDPB is not the only EU body that has moved. The Renew Europe political group in the European Parliament, led by MEP Veronika Cifrová Ostrihoňová, has written to the European Commission asking what EU-level action is possible. Her specific framing: smart glasses could "target women in a way that is not wanted and that is not welcome on the European market," and there needs to be "some kind of stop" to the technology [1]. Renew Europe is the parliamentary home of France's Renaissance, the Netherlands' VVD, and other center-to-liberal parties; it is not a fringe voice. The letter turns "what should the EU do about smart glasses" from a hypothetical into a parliamentary ask with a named MEP and a specific government-facing request.
France Opened the Round on May 11
France's data protection authority, the CNIL, published its smart-glasses call for vigilance on May 11, 2026, weeks before the Politico story put the EU regulatory escalation on the front page [2]. The CNIL's framing, as reported by Politico, was the most direct of any European regulator to date: smart glasses carry a "significant risk" of ushering in surveillance that is "almost invisible and omnipresent" and that "could lead to a profound transformation of our societies" [1][2].
The CNIL's technical argument turned on a specific point: unlike a phone, which a user has to take out, orient, and aim, smart glasses film everything the wearer looks at and are not clearly distinguishable from regular glasses. The CNIL's analysis was that the technical devices intended to inform people of a capture (an LED indicator, for example) have only a limited scope, and are absent for some uses entirely [2]. In other words, the LED indicator Meta has pointed to as a privacy safeguard is not a safeguard in the contexts where glasses are most likely to be used to capture intimate or non-consensual footage.
The CNIL also published the results of a January 2026 survey of 2,128 French adults: 67 percent said smart glasses represent a risk of intrusion into private life, and concerns about consent, deepfake generation, and downstream data use were the three most-cited worries [2]. That number matters because it is a baseline for any future regulatory action: the regulator is acting against a backdrop of documented public concern, not a speculative one.
Sweden and Norway: The DPA Directors Go Public
Sweden's data protection authority (IMY) is the most aggressive national regulator in this round. Its director general, Eric Leijonram, told Politico: "The risks are high... We need a discussion, and we need to ensure that this is acceptable in our society, that others can really understand when people are using these to film them or record them" [1]. Leijonram is not on the policy side of IMY; he is the top civil servant in the agency. His going on the record is the kind of signal that prefigures enforcement, not commentary.
Norway's consumer council has gone further. Finn Lützow-Holm Myrstad, the Norwegian Consumer Council's director of digital policy, told Politico: "In principle, the law is clear. There's no way that people can, in a meaningful way, consent and understand what they consent to if they're being filmed" [1]. He argued European authorities have "not been bold enough yet to use all the tools at their disposal" against the technology, "if only to test whether the law is fit for this purpose" [1]. The Norwegian Consumer Council is the consumer-protection agency that brought the original GDPR complaints against Grindr, Tinder, and the adtech industry in 2018-2021. Its willingness to test smart glasses in court is not a hypothetical.
The Proof of Harm: Kenya and the EFF
EU regulators are not building their case on speculation. They are anchoring on two specific pieces of evidence that were not on the table when smart glasses launched in 2021.
The first is the Kenya data-labeling reporting. Swedish media reported in early 2026 that subcontractors for Meta in Kenya were reviewing "deeply private" footage captured by the firm's smart glasses to help annotate content for AI training. The footage included recordings of bathroom visits, banking details, and people having sex [1][5]. The CNIL referenced the Kenya reporting explicitly in its May 11 call for vigilance [2]. The CNIL is the agency that opened GDPR enforcement against Apple, Google, and Microsoft for tracking cookies in 2021-2022. When it cites a fact pattern in a public document, that fact pattern is going to be the next enforcement target.
The second is the EFF's June 4 publication of "Move Fast, Surveil Things." EFF's Threat Lab used static code analysis to confirm that Meta has already shipped facial-recognition code to millions of Ray-Ban smart glasses, hidden behind a feature flag [3]. The feature, internally called "Name Tag," converts every face in view into a 2,048-number faceprint and matches it against a stored database. An EFF researcher activated the feature in debug mode and watched the glasses detect a previously scanned face in real time [3]. The EU regulators' "social acceptability" framing turns on this fact: not whether smart glasses could one day identify strangers on the street, but whether they already do, and the only barrier is a software switch Meta has not flipped.
The US-Side Coalition That EDPB Cites
Brussels is not moving in a vacuum. The ACLU organized a coalition letter in April 2026 signed by 75 organizations (domestic violence advocates, worker rights groups, reproductive freedom organizations, immigrant rights advocates, and civil-liberties groups) demanding Meta "immediately halt and publicly disavow" plans to add facial recognition to its glasses [6]. Texas Attorney General Ken Paxton launched a formal investigation in May 2026, issuing a Civil Investigative Demand to Meta over the glasses' privacy practices, naming the always-on camera mode, the facial recognition plans, and the Kenya subcontractor reports as the three specific concerns [7][8].
On the US class-action side, public interest firm Clarkson Law is litigating a consumer class action against Meta over its glasses, arguing that Meta made false privacy promises to sell the product [1]. Managing partner Ryan Clarkson told Politico the firm is "looking for consumers in the EU who have bought Meta smart glasses to join his action" and has "already been in touch" with EU lawyers thinking about how to frame a similar class action [1]. The EU-side and US-side enforcement tracks are starting to align, which is the precondition for cross-jurisdictional pressure on Meta.
The 2027 EU Batteries Law Is Already Slowing Meta Down
There is a separate, non-privacy regulatory pressure already biting. The EU Batteries Regulation requires all mobile devices to have user-replaceable batteries by 2027, and Meta's smart glasses with built-in display do not. US Ambassador to the EU Andrew Puzder raised the point at a recent Meta event in Brussels, calling the law "so broad and so restrictive that it prevents the sale of this wonderful, jointly developed, US-European product from being sold in the European Union" [1].
Puzder's framing is "business facilitator" language. The privacy regulators' framing is the opposite: that the same product design that fails the batteries law (always-on, non-user-serviceable, integrated into a wearable form factor) is the design that creates the privacy risk the regulators are now trying to address. France's first-generation smart-glasses rollouts were slowed by Italian and Irish data-protection concerns in 2021; the 2024 version added a "bigger, blinking light" in response to Irish regulator feedback [1]. The pattern is: each regulatory round forces a small product change, and the next regulatory round is already scheduled.
The Scale: 7 Million Pairs Sold, Sales 'Ramping Up Exponentially'
The data regulators are acting on a category that is still small in Europe but growing fast. EssilorLuxottica, the French-Italian eyewear company that owns the Ray-Ban brand, reported in its first-quarter 2026 results that smart-glasses sales are ramping up "exponentially" in the US, while the European distribution rollout is still slow, with "more than half" of sales points in the EMEA region not yet served [1]. The company also confirmed more than 7 million pairs of Meta smart glasses were sold worldwide in 2025 [1].
Samsung and Google announced earlier in 2026 that they are collaborating on a new line of "intelligent eyewear" set to launch later this year, and Apple is reportedly targeting its own smart-glasses product for the end of 2027 [1]. The 7-million-pairs figure is the baseline. By 2027 there will be at least three major vendors in the category, all shipping cameras-on-your-face hardware into the EU market. The EDPB report is timed to land before the second wave of products, not after it.
What It Means for You
If you are in the EU. The next 90 days are the period when the EDPB report draft, the Renew Europe letter response from the Commission, and the first national DPA enforcement actions will land. If you own Meta Ray-Ban glasses or are considering any smart glasses in this product cycle, the regulatory environment is going to be unstable for at least two more product cycles. Buy assuming the device may be functionally restricted, banned, or required to ship with a hardware kill switch for biometric features within 24 months.
If you are in the US. The US-side fight is parallel and slower. The ACLU 75-organization coalition, the Texas AG investigation, and the Clarkson Law class action are the standing track. The 64-group congressional letter from May 2026 is the legislative ask. The product is still being sold; the enforcement track is still 12-18 months from any meaningful action. Assume the facial recognition code is in the app on your phone right now, behind a feature flag Meta controls.
If you are a woman using public space in a major European city. This is the case the CNIL and Renew Europe are explicitly building their case on. The Norwegian Consumer Council's Myrstad is right that meaningful consent is structurally impossible when the recording device is not identifiable as a recording device. The Nearby Glasses app Yves Jeanrenaud developed has been downloaded 120,000 times since February 2026 [1], and it is the only consumer-side counter-surveillance tool currently in the field. If you are worried about being recorded, the Bluetooth detection layer is the only working detection layer.
If you are a civil-society researcher or journalist. The Clarkson Law firm is recruiting EU consumers for a class action [1]. The Norwegian Consumer Council has signaled it is willing to test the existing law [1]. The EDPB report and the next round of CNIL guidance are the two documents to monitor for new test-case theories. The US coalition letter and the Texas AG investigative demand are the standing cross-jurisdictional record.
The Bottom Line
The European Data Protection Board has commissioned a report on the "social acceptability of smart glasses" for this summer. France's CNIL opened the EU regulatory escalation on May 11 with a public call for "vigilance" that explicitly named the "almost invisible and omnipresent" surveillance risk. Sweden's IMY director general is publicly raising concerns. Renew Europe has written to the Commission asking what EU-level action is possible. The Norwegian Consumer Council is signaling it is willing to test the existing law in court.
The two pieces of evidence the EU regulators are anchoring on are not speculative. The Kenya data-labeling reporting is on the public record, and the EFF has confirmed in code that facial-recognition capability is already shipped to millions of Ray-Ban Meta glasses, behind a single feature flag. The Clarkson Law class action is recruiting EU consumers, the ACLU coalition has 75 US organizations on the record, and the Texas AG has issued a Civil Investigative Demand. The smart-glasses category is being treated by Brussels the same way the EU treated facial recognition, adtech, and dark patterns in the 2018-2024 cycle: national enforcement first, EU-level instrument later, with cross-jurisdictional litigation as the bridge.
Watch for three things over the next 30 days. First, the EDPB report draft, and whether it recommends a new EU-level instrument or stays with national enforcement. Second, the European Commission's response to the Renew Europe letter, and whether the Commission treats smart glasses as a consumer-product question or a fundamental-rights question. Third, the first French CNIL enforcement action under the May 11 call for vigilance, and whether the target is Meta, Samsung, or a smaller vendor. The answers to those three questions will determine whether smart glasses are the next GDPR-style regulatory escalation or a slow national-enforcement grind that takes five years to bite.
Sources
- Politico Europe: "New privacy frontier: Europe eyes crackdown on smart glasses" by Ellen O'Regan, June 8, 2026 (primary source for the EDPB report commission, Sweden's IMY director general Eric Leijonram on the record, Renew Europe MEP Veronika Cifrová Ostrihoňová's letter to the Commission, the Norwegian Consumer Council's Finn Lützow-Holm Myrstad, the Clarkson Law EU class-action recruitment, the 7 million Meta Ray-Ban pairs sold in 2025, the EU Batteries Regulation 2027 compliance issue, and US Ambassador Andrew Puzder's "business facilitator" framing)
- CNIL (Commission Nationale de l'Informatique et des Libertés, France): "Les lunettes connectées : la CNIL appelle à la vigilance" (Smart glasses: CNIL calls for vigilance), May 11, 2026 (primary source for France's opening of the EU regulatory escalation, the "almost invisible and omnipresent" surveillance framing, the January 2026 survey of 2,128 French adults showing 67% see smart glasses as a privacy risk, and the explicit reference to the Kenya data-labeling reporting as the proof of harm)
- EFF: "Move Fast, Surveil Things" by Cooper Quintin, EFF Threat Lab, June 4, 2026 (primary source for the static-code-analysis finding that facial-recognition code is already shipped to millions of Ray-Ban Meta glasses, the "Name Tag" feature, the 2,048-number faceprint array, and the real-time face detection demonstration in debug mode)
- State of Surveillance: "Meta Shipped Facial Recognition to Ray-Ban Glasses" (June 5, 2026, the prior SOS piece on EFF's static code analysis finding, the "Name Tag" feature, Meta's "$7 billion in settlements" history of biometric privacy violations, and the 76-organization opposition coalition)
- State of Surveillance: "Meta Smart Glasses Kenya Contractors Intimate Footage Lawsuit" (the prior SOS piece on the Swedish media reports that Meta subcontractors in Kenya reviewed bathroom and intimate recordings to train the on-device AI, the proof-of-harm anchor that the CNIL and EDPB are citing in their public statements)
- ACLU: "ACLU and 75 Organizations Sound Alarm on Meta's Plans to Add Facial Recognition Technology to Ray-Ban and Oakley Eyeglasses" (April 2026, primary source for the 75-organization coalition letter demanding Meta "immediately halt and publicly disavow" facial recognition on glasses, the standing US-side opposition record the EU regulators are referencing)
- Texas Attorney General: "Attorney General Ken Paxton Launches Investigation Into Meta Glasses" (May 2026, primary source for the Civil Investigative Demand targeting Meta's data collection, the always-on camera mode, the facial recognition plans specifically, and the Kenya subcontractor reporting as a named concern)
- State of Surveillance: "64 Groups Oppose Meta Smart Glasses Facial Recognition at Congress" (the prior SOS piece on the May 2026 congressional letter, the legislative-track counterpart to the EDPB report, and the 64-organization US coalition that the ACLU letter is part of)