Decoding the business of technology.
examnity.

New Australian Privacy Reforms Address Smart Glasses and AI Surveillance Risks

As SMH.com.au reports, Australia’s federal government is preparing draft changes to privacy law aimed at keeping pace with smart glasses and artificial intelligence.

Aaron Blake, Threat Intelligence & Privacy Correspondent · updated September 01, 2026

New Australian Privacy Reforms Address Smart Glasses and AI Surveillance Risks

The package includes an online identity safeguard called IDLock and a proposed right to have personal information destroyed by social media and search companies. Attorney-General Michelle Rowland is expected to release the draft on Monday, followed by industry consultation and a possible introduction to parliament by the end of 2026. The federal package is still a draft. Enterprises should treat it as a direction of travel, not a finished compliance manual.

Cameras without a clear perimeter

Smart glasses resemble ordinary glasses but can photograph or film what the wearer sees. That creates a more awkward privacy problem than a phone: recording can happen in a workplace, meeting or public space without bystanders immediately knowing.

The proposed federal legislation is not a complete rulebook for the devices. The report separately describes a Greens proposal that would ban their import for 12 months over privacy concerns. A Startland News headline is also focusing on the employment question, asking how employers that use or ban smart glasses could face legal challenges. The available evidence does not establish a legal outcome, but the operational issue is already practical.

IT and procurement teams evaluating the hardware should determine whether recording can be disabled, whether users can tell when capture is active, how captured material is accessed and what happens when a wearer enters a space where other people have not agreed to be recorded. A privacy policy laminated inside the box is not a control. Hardware behavior is.

The wider lesson is straightforward: the person wearing the device is not the only person exposed to it. Anyone who enters the device’s field of view may become part of the recorded dataset. That makes consent a systems problem, not a pop-up window and a vague button labeled “agree.”

Identity gains a visible switch

IDLock is the more concrete proposal. After an initial trial, the service is slated for addition to Australians’ myGov accounts in 2027. According to the report, it would let people block, unblock and monitor the use of identity documents. It is also intended to show whether identity information has been exposed through a data breach or hacking incident.

The system builds on the Credential Protection Register, established in 2022. The report says the register has blocked more than 830,000 fraudulent identity-verification attempts since then. That figure is not evidence that identity fraud has been solved. It is evidence that attempted fraud is already an industrial-scale process and that defensive systems have had to become correspondingly less polite about it.

For enterprise IT teams, the proposal points toward prevention rather than waiting for a breach to finish its paperwork. Identity controls are moving closer to the account layer, where users can see and restrict document use. The implementation remains ahead, however. Organizations should not build internal procedures around draft features or promise capabilities before the trial, legislative text and final rules are available.

That distinction matters. A control that exists only in a slide deck is decorative. A control that can be tested, monitored and revoked is considerably more useful.

AI, retention and the limits of “delete”

Artificial intelligence is inside the privacy package because the report says technology companies are feeding large volumes of data into systems used to train AI models, with limited regard for people’s privacy and copyright. That allegation should not be confused with a legal finding, but it explains why the proposed right to erasure matters.

Under the reported terms, people could ask social media and search companies to destroy their personal information rather than retain it. The right would not apply to media organizations publishing news articles. This is not a universal delete button. It is a narrower mechanism with boundaries, exclusions and a likely future stream of request-handling work.

Companies should not market erasure as the guaranteed destruction of every copy, everywhere. Before designing controls, they should map where personal information is stored, how retention is enforced, where backup copies sit and how incoming requests will be authenticated. Only then does “right to erasure” become an engineering specification instead of a slogan.

The consultation period and the reported target of introducing legislation by the end of 2026 leave room for the rules to change. Until the final text arrives, the sensible posture is modest: document what smart glasses collect, keep identity safeguards visible, stop describing erasure as absolute deletion and watch the legislation rather than the marketing deck.