- › A Meta patent published on August 14 describes smart glasses that use facial recognition to identify the people in a wearer's field of view and cut them into highlight reels.
- › Most visitor policies restrict photography and recording, which is a different act from identification and does not cover it.
- › The exposure is a stranger walking your floor with a running list of who works there, who visited before them, and who spoke to whom.
- › Your practical controls are a rewritten visitor agreement, a device declaration at the badge desk, and staff who know what to do when a guest declines.
- › Start with a physical security assessment that treats wearables as a category, because a camera policy written in 2019 does not describe this device.
Walk into any Phoenix office park on a Tuesday morning and count the visitors. Vendors, contractors, candidates, delivery drivers, the salesperson with a 10 a.m. The receptionist hands over a badge, gets a signature, and points at the elevator. Somewhere in that stack of paperwork is a line about photography.
That line is the whole control. And it was written for a device that takes pictures.
On August 14, Meta published a patent describing smart glasses that detect people in the wearer’s field of view using facial recognition, identify them, read their expressions, track where the wearer is looking, and assemble the result into personalized highlight reels using relationship data (404 Media). The company has not said it will ship any of it. Meta put facial recognition code into its glasses once before and pulled it after press coverage.
A patent tells you where a company believes the market is going, and it costs enough to file that the belief is sincere. For anyone responsible for a building, that is the useful signal. The category matters more than the ship date.
Recording and Identifying Are Two Different Acts
Your visitor policy restricts one of them and says nothing about the other.
A recording restriction protects against a specific harm: a guest capturing a whiteboard, a screen, a floor plan, a product on a bench. It is a control on what leaves the building as an image. Every no-photography clause in every visitor agreement was drafted against that harm.
Identification runs the other direction. The device brings a database in with it. It matches a face against records that already exist somewhere else and returns a name, a title, an employer, and whatever else those records hold. Your camera policy watches the door for things leaving. This walks in through it.
The distinction has teeth
Consider what a guest with an identifying wearable collects on a 40-minute walkthrough of your Scottsdale office.
They learn which of your employees are in the building today and where each of them sits. Two people from a competitor’s account team were in your third-floor conference room an hour earlier, and those faces are still sitting in the lobby log and the badge queue. The person who ran your finance meeting turns out not to be the person your org chart lists as running finance. Add who spoke to whom in the hallway on the way past.
A no-photography clause covers none of that, because nothing on the list is a photograph. That list is what a competitor, a litigant, or someone building a social engineering campaign against your company would otherwise hire a private investigator to assemble over a week of billed hours.
What the Exposure Costs You
Physical security spending gets approved when someone can name the loss. In our assessments the same three losses come up.
Client confidentiality
If you run a law firm, a medical practice, a wealth management office, or a behavioral health clinic, your waiting room is a confidentiality problem before it is anything else. The identity of the person sitting in it is itself the sensitive fact. A wearable that names strangers in a waiting area turns your lobby into a disclosure you did not make and cannot retract.
For a healthcare practice, that touches the Health Insurance Portability and Accountability Act (HIPAA), where the fact of a patient relationship is protected health information on its own. You did not disclose it. Your physical layout did.
Employee safety
Domestic violence situations, custody disputes, and harassment cases all involve someone who wants to know where a specific person spends their day. Front desk staff are trained to refuse that question over the phone. A device that answers it from the sidewalk routes around that training.
Phoenix has a large service and healthcare workforce, and it includes people who have gone to real lengths to keep a work address private. Ask your human resources team how many address confidentiality requests they are holding right now. Most operators are surprised by the number.
Trade secret and negotiating position
Trade secret protection depends on showing you took reasonable measures to keep the information secret. If your process is that visitors sign a paper and nobody checks what they are wearing, you are going to have a harder conversation about reasonable measures than the company that documented a device policy and enforced it.
Five Controls That Work at the Badge Desk
You cannot solve this with hardware. No scanner at the door will tell you a pair of glasses is running recognition, and none is coming. The controls that work are procedural, which makes them cheap and makes them depend on whether your staff will run them.
1. Rewrite the visitor agreement to name identification
Add language that covers use of any device or application to identify, match, or catalog individuals on the premises, separate from and in addition to the recording restriction. Keep the recording clause. Add the second act next to it. This is a one-page redline and it is the highest-return item on this list.
2. Require a device declaration, not a device ban
Bans fail because they are unenforceable and because they make reception staff argue with a customer. A declaration works better: guests state what camera-capable or connected eyewear they are carrying, and that goes on the log alongside the badge number. You now have a record, which is what matters later.
3. Give reception a script and the authority to use it
The failure we see most often in visitor management is a receptionist who knows the rule and does not feel empowered to enforce it against someone who outranks them, argues, or is a paying client. Write the script. Rehearse it. Tell them in writing that escalating is the correct outcome and that nobody will second-guess them for it. Staff who have never been told they are allowed to say no will not say no.
4. Escort in the areas where identity is the asset
Reception, waiting rooms, the open floor near the executive suite, and anywhere your client-facing calendar is visible. An escort changes the guest’s behavior and shortens the dwell time. Dwell time is what turns a walkthrough into a collection run.
5. Handle refusals as an access decision
If a guest declines to declare, or declines to remove eyewear in a restricted area, treat it as a scoping decision. The meeting moves to a conference room off the main floor, or it happens over video. Decide that in advance so your staff read a policy instead of improvising an argument.
Where This Sits in a Converged Program
The physical control above is half of it. The other half is that recognition needs a database, and the database is built from images your organization published: the team page, the conference badge photos, the LinkedIn profiles, the press release headshots.
That is a data governance question, and it belongs to whoever owns your web presence. Nobody is suggesting you take the team page down. The point is that the enrollment set for any system that identifies your staff is something your marketing team assembled, and neither team has ever discussed it with the other. We covered a related version of this pattern in how license plate readers moved from reading plates to reading devices, and in the broader problem of AI systems trained to read human faces.
The organizations that handle this well are the ones that already run access control and visitor management as one system instead of two, and that treat the biometric question as part of it rather than a separate compliance project. If you want the underlying material on that, our guide to biometric data security covers how these datasets get built and why they cannot be reissued.
Start With the Visitor Policy You Already Have
Pull your visitor agreement. Read the paragraph about devices. If it says photography, video, or recording, and stops there, it does not cover the thing described in that patent, and it will not cover whatever ships in three years either.
Fifteen minutes tells you whether you have a gap. Sizing it takes longer, because the answer depends on your layout, your visitor volume, who your clients are, and what a stranger can see and resolve in the first ninety seconds after the front door closes behind them.
That part takes an assessment. Do it before a device makes the decision for you.
Not sure what a visitor can learn in your lobby before they reach the elevator? Contact Grab The Axe for a physical security assessment, or start with our free Human Attack Surface Score.
A leader defined by a 'bias for action,' Dusten specializes in physical security assessments that impact profitability. He leverages high-logic strategies to pinpoint high-ROI vulnerabilities, ensuring defense measures actually scale with the business.
View Author Page →