The Always-On Glasses I Would Wear

/images/always-on/redon-eye-balloon.jpg
Odilon Redon, The Eye, Like a Strange Balloon, Mounts Toward Infinity, 1882. Art Institute of Chicago.

In 2011, Black Mirror aired an episode called "The Entire History of You". Everyone has a small implant, the grain, that records everything they see. Nothing is ever lost. At the airport, a security guard asks the protagonist to replay his last few days, and he fast-forwards through them for a stranger.

It aired as dystopia. Fifteen years later, the hardware is on shelves. Camera glasses are sold as fashion, and the industry is openly building toward a device that sees what you see, all day: always on.

I am not sure the grain is the dystopia. I spent years at Meta Reality Labs Research, where Project Aria was developed: research glasses built for exactly this kind of data. Aria is research, run under protocols and review by people who care about getting this right, and it is exactly the kind of work this problem needs. What will ship is another matter. Meta, Google and Snap, which between them define this market, make their money from attention and profiles, and the version of this device that is good for you is worth less to that business than the version that is not.

The smartphone precedent

The smartphone is a genuinely good computing device: a computer, a camera, a library and a map, in a pocket. It is still all of those things. It is also the reason for the rows of bowed heads in any train carriage, over the short-form feed that TikTok perfected. When the Wall Street Journal set dozens of bots loose on TikTok, the feed needed a single signal to find each one's weak spot: how long it lingered. Phones did this from a pocket. The phone must be taken out, held, looked down at, and put back.

Glasses are sold on the same promise the phone was, a genuinely useful computer on your body, and they will run on the same business model. The difference is that there is no pocket. The display sits at zero distance and is worn all day, so the feed no longer has to compete with the world for your attention. It overlays it.

What the device collects

The phone's feed had one signal to work with. Glasses supply many more. "Camera glasses" undersells them: the payload is not clips. It is image, audio, motion, location and, eventually, gaze, fused and aggregated over months. Where you looked, and for how long, is a readout of attention itself: interest, hesitation, attraction. Your eyes rest on a stranger a second longer than you meant to, and eye tracking files it, with a timestamp, next to every other lingering look you have ever given. On a phone, the feed learns what holds you from what you pause on while scrolling. A gaze tracker sees what you linger on in the world: faces, bodies, price tags, the exit, your own reflection in a shop window.

The risk is not only that a human watches your footage. It is what models infer from the aggregate: your routines, your relationships, and the people you looked at, profiled by devices they never bought.

Where the data lives, and who is in it

The honest case for always-on is real. An assistant has to see your context, and a memory has to record. For a blind user, glasses that describe the world are not a convenience, they are sight, and nothing in this piece argues against them: they perceive and keep nothing, and the argument here is about keeping. Wanting to keep more of your life is not the problem either. Diaries and photographs have always done that.

So I do not object to the recording. I object to where it lives and who is in it. A record of my life on a server is not my memory. It is a timeline that a company holds, aggregates with a billion others, and mines for whatever holds attention best. On the device, the same record is a diary. It can be lost or stolen, but it cannot be pooled, and nobody can read it without asking me.

The second problem survives even with the data on the device, because my memory of my life has other people in it. A recording of them, unlike my memory of them, can be copied, searched and leaked. A phone raised to record is a gesture: people see it and can object, wave, or leave. Glasses delete the gesture. In the summer of 2026 the Greek health minister toured Lemnos wearing Ray-Ban Metas, and the backlash came afterwards and online, once the photographs circulated. Had he held up a phone, everyone he met would have seen they were being recorded and acted accordingly. The glasses removed that moment.

Recording lands on everyone at the table, like cigarette smoke, so the veto belongs to the person who did not opt in. The industry's current answer is anonymisation, and Aria's own EgoBlur is a good one, but anonymising people on the device does not remove them. Blurring faces still leaves how you move and what you said, and a summary that deletes the footage, "lunch with Maria, she is worried about her father", drops her face and keeps her secret. The veto is over capture that is continuous, invisible and kept, where there is never a moment to say no.

The law does not see it that way yet, though it has been here before. The Kodak appeared in 1888, and two years later Warren and Brandeis wrote "The Right to Privacy", the paper the modern right to privacy descends from, in direct response to instantaneous photography. A camera you could carry was enough to produce a new right. The line it drew was at publishing, not at photographing, and that is still the line: in most places, taking a photo of you in public is legal. In 2024 two Harvard students connected Ray-Ban Metas to a face search engine and read out the names, addresses and relatives of strangers as they walked past. That is not a photo, and a line drawn for photographs does not cover it.

The glasses I would wear

There is a version of this device I would wear. It computes on hardware I own: the frame, the phone in my pocket, or a machine in my house. The stream, raw and inferred, never reaches anyone else's server. Whether it is off is a physical fact I can check, not a promise. It keeps everything about my life, because my life is mine to keep. Other people are in it because they explicitly said yes, and can say no from then on.

It does not exist, and the reasons are not only commercial. The field that would build it sits between hardware security, on-device perception and human-computer interaction, and most of its problems are open. Four of them:

  • All-day perception on hardware the wearer owns. Continuous vision and audio models inside the power budget of something light enough to wear, with nothing offloaded to anyone else's server.
  • Verifiably off. A switch that cuts the wire or an indicator light that software cannot fake lets the wearer know the camera is off. It tells the bystander nothing, because a modified device looks the same from the outside. Nothing exists that lets a stranger check.
  • Consent from non-users. The person who has to be able to say no is a stranger at the next table with no device, no account and no relationship to the wearer.
  • Withdrawal of consent. Someone who said yes can later say no. The law covers only the extreme case: sharing an intimate recording without consent is a crime across the United States and most of Europe, keeping one is not. For everything else there is no rule. A recording of a shared moment has several people in it, and deleting it for one deletes it for all. Wear the device through a three-year relationship and then separate. Most of what either of you has of those years is now a recording the other person is in. Who can delete what is unresolved.

There are more. The device has to confirm that the person who said yes is the person in frame, without recognising everyone else. Backups have to be readable only by the wearer, since a phone that syncs to the cloud has already handed the data to someone else. Search across years of footage has to run on hardware the wearer owns, with the index staying there. Children cannot consent, on either side of the frame. And nobody has said what happens to the archive at a border, or when the wearer dies.

These are interesting problems to work on. The people who have worked on them so far come from usable security and human-computer interaction, under the name bystander privacy. An early study put a researcher in AR glasses in a café in 2014 and interviewed the people at the next tables, and a 2026 study found that bystanders consistently ask for more transparency than wearers are willing to give. The hardware side belongs to trusted computing, and the power side to on-device machine learning.

The power problem is on every roadmap, because every product needs it solved. Almost everything else on this list protects people who are not the customer, which makes it a lower priority for an attention business. That leaves those problems to universities, and to any maker that would rather sell glasses than attention. It is not a bad place for a problem to be.