Zuckerberg sold millions of cameras disguised as glasses and called a blinking light consent. He is right, in the narrow sense in which Meta usually means it: every pair of Ray-Ban Meta glasses carries a small white LED in the corner of the right temple that blinks when the wearer is recording. It cannot be turned off through software. If the LED is covered or painted over, the camera disables itself. That is what a Meta spokesperson told the Guardian, and it is what the company has been telling reporters and members of Congress for some time.
The trouble is that the narrow sense is the sense in which the company has an interest in being true, and it is not the sense in which the glasses have been encountered by the people in their path. A man held in a South Carolina detention center that was under federal investigation for unsafe conditions recorded, in July of 2025, what he saw there: a dingy shower, holding cells, an overcrowded cafeteria, fellow detainees asleep at tables and walking in lines, none aware they were being filmed. He posted the footage to TikTok and noted, on the recording, that the other detainees did not know what the glasses were. The blinking light, he observed, was just a blinking light.
This is what the discipline trained in protocol verification calls a behavioral specification: the question is not what the manufacturer says the device does, but what an adversary — or a fellow detainee, or a bystander — actually observes, in the conditions in which the device is most likely to be used. Researchers have been working through this problem for a decade, mostly on body-worn cameras for police, where the disclosure indicator is a similar small light and the empirical literature on whether bystanders actually notice it is, to put it gently, unflattering. Whether the LED is actually visible at conversation distance in a fluorescent-lit intake area or a holding cell is a different question than whether it blinks in dim light in front of a mirror — and the only one that matters, which is why neither the manufacturer nor the apparatus wants to look at it.
The New York Police Department’s counterterrorism bureau circulated a memo in January 2026 warning officers that the glasses could be used to “covertly record inside a law enforcement or detention facility” and that the resulting footage could expose “proprietary information about cell layouts, camera placements, or officer patrol/site protection routines.” The seven words doing the work in that sentence are “proprietary information about … officer patrol/site protection routines,” which is the bureau’s word for the layout of cells in which it holds people, sometimes for days without charge, and the routines by which officers move through facilities. The same intelligence bureau that processes Joint Terrorism Task Force referrals and tracks domestic-extremism threats now considers citizen video one too. Similar memos have come from Maine’s fusion center in June 2026, from San Diego, Tennessee, Virginia, and from the joint counterterrorism assessment team at DHS. ICE has classified the glasses as body-worn cameras and barred them from the federal workspace. The memos are uniform in their concern. The agencies are not primarily worried that members of the public will be harassed with the glasses — though harassment has happened, and the glasses are widely nicknamed “pervert glasses.” They are worried about being recorded back.
Ryan Shapiro, the executive director of Property of the People, the transparency nonprofit that obtained the documents, put the inversion plainly: “These agencies surveil the public incessantly, but the moment we can watch them back, it’s deemed a security threat. When only the government is allowed to hold the camera, that’s not security. It’s impunity.”
It is a sentence worth holding beside the corporate position the device’s maker sent over in the same reporting cycle — that the glasses “are designed to be noticed.” The corporate line is that the technology announces itself. The bureaucratic line is that noticing it is a security problem.
The cameras the agencies already operate are worth naming. License-plate readers log the comings and goings of every vehicle that passes a municipal camera or a fleet vehicle; the data has been resold to private companies and, in some jurisdictions, to ICE. Cell-site simulators — Stingrays, IMSI-catchers — pretend to be cell towers and harvest the location and identifying data of every phone in range. The NYPD’s Real Time Crime Center processes millions of data points per day from fixed and mobile surveillance cameras, license-plate readers, and the domain-awareness sensors mounted on patrol vehicles — all of which are pointed at the public, all of which are classified, in their own internal memos, as protecting officer safety. Facial recognition has been adopted eagerly despite Federal Trade Commission findings, inspector general reports, and a steady stream of wrongful-arrest litigation that has done essentially nothing to slow procurement. Bulk location data has been bought from data brokers under the legal theory that data held by a private third party is not subject to the Fourth Amendment. The agencies did not invent CCTV, but they have been its largest single customer for fifty years. The light on the glasses is not a new piece of surveillance architecture arriving in the world. It is the first camera many of these agencies have encountered that points back, and the asymmetry it disturbs is the asymmetry the agencies built.
The asymmetry was constructed. It was constructed by design — by the slow accretion of statutes, exceptions, and procurement contracts that let the agencies deploy surveillance while leaving the public, in their formal capacity, on the receiving end. The smart glasses, which the agencies did not invent either, are merely the first consumer hardware in a generation that meaningfully threatens it.
To be fair — the phrase is doing real work here, not Letterkenny work — the smart glasses are not a wholly innocent category. Officer safety is not a fiction. Pre-operational reconnaissance by a would-be attacker is not a fiction; the FBI has alleged the perpetrator of the January 2025 New Year’s Day attack in New Orleans conducted exactly that, biking the length of Bourbon Street twice at the end of 2024 wearing smart glasses before driving a truck into the crowd and killing fourteen people. The argument the agencies are making is not, on its face, frivolous. The same instrument that lets a prisoner document unsafe conditions in his own shower lets an attacker scout a target. That is the structural fact about the glasses: they are a general-purpose input device, and a general-purpose input device does not know who is wearing it.
What is not structural, and what is therefore worth saying, is the asymmetry of which side of the camera is allowed to make which argument. Cory Doctorow has the formulation for moments like this: “Every pirate wants to be an admiral.” The agencies adopted the cameras against the public when they were useful for that purpose. Now that the cameras can be turned around, the cameras have become a security threat. The argument is not that the agencies were wrong to use the cameras; the argument is that the public is not allowed to.
The pattern is older than the glasses. Surveillance and control technology tends to be deployed first against people with the least political protection — prisoners, undocumented migrants, schoolchildren, workers — and is then normalized before being extended up the privilege gradient. Body-worn cameras on police were, after Ferguson, the rare surveillance technology adopted in the name of accountability. They sit on a cop’s chest. They do not normally sit on a prisoner’s chest, or a tenant’s, or a shopper’s. The smart glasses are the mirror of the body cam, deployed on the same gradient, but pointed in the other direction. The agencies have, with some justification, noticed.
Evan Greer, who runs the digital advocacy nonprofit Fight for the Future, framed it more sharply still: “Surveillance makes all of us less safe. There’s no such thing as Meta glasses that are only for the good guys.”
The interesting move in the recent memos is what the agencies want to do about it. The NYPD’s August 2025 document, written in response to the “AI 2027” paper by a former OpenAI researcher and a group of industry-aligned authors, warns that public opposition to advanced AI could result in “anti-tech violent extremist activity” and civil unrest over job losses, deepfakes, and loss of trust in government and tech. The phrase is not a formal DHS designation; experts quoted in the reporting worry, reasonably, that it could serve to criminalize constitutionally protected protest. The mechanism is recognizable. Define an informal category. Seed it in internal memos. Cite it in fusion-center products. When the inevitable civil-liberties lawsuit arrives, point to the documentation and call the category established. The same playbook shows up across allied jurisdictions — Canadian “lawful access” proposals have worked the same trick, normalizing expanded state access by lowering the procedural threshold from “reasonable grounds to believe” to “reasonable grounds to suspect,” against a Supreme Court of Canada jurisprudence in Spencer (2014) and Bykovets (2024) that establishes subscriber information as attracting a reasonable expectation of privacy. The mechanism is older than the smart glasses and will outlast them.
The structural question is what to do about a consumer hardware category that is, in itself, neither good nor bad, but whose deployment has been one-way for the better part of a generation. The four mechanisms that historically kept consumer technology from being weaponized against its users — competition, regulation, interoperability, and worker power — have each been weakened in the U.S. case in ways specific enough to name. Competition: the Lina Khan FTC was denied its preliminary injunction to block Meta’s Within acquisition; the agency’s case against Meta’s ad-tech monopoly remains pending, but the larger pattern of permissive merger review over the last forty years is what let the surveillance architecture consolidate in the first place. Regulation: there is no federal privacy law with a private right of action in the United States; the last meaningful federal consumer privacy statute is the Video Privacy Protection Act of 1988, which prohibits video-store clerks from disclosing what VHS cassettes you rented. Interoperability: the legal architecture that suppresses adversarial interoperability — DMCA Section 1201, the Computer Fraud and Abuse Act, the licensing regimes around operating systems — means that consumer hardware is locked down by design, which closes off the unilateral remedy of fixing the device to make the LED visible enough that the disabling logic actually fires. Worker power: the engineers who build these products are not in a position to refuse the surveillance features; the rank-and-file at Meta, like the rank-and-file at most of the large platforms, has no structural leverage over what the company ships. Each of those four constraints is a specific policy lever. Each was disabled by specific named decisions. None of them is a “great force of history” that cannot be reversed.
The same company, at this moment, is in a New Mexico courtroom answering for harm its own internal research documented years ago, with prosecutors playing Meta executive video depositions as the trial moves toward a verdict. The pattern is the same one this column has been naming in different forms: the company ships a product whose risks the company has documented internally, the regulatory architecture that would have caught it arrives years late, and the public absorbs the difference in the meantime. The blinking light on the glasses is a small LED. The four disabled constraints are the entire architecture of why that light is doing the work of consent in the first place.
The receipts are in the archive. The next memo is being written. The question the apparatus would prefer not to answer is whether the device it is so alarmed about is a security threat, or whether the apparatus is. The memos do not distinguish between the two. The public record, as they say, is the only remedy there is.