Editor’s Note: A jacket is not a privacy strategy

August 26, 2026

Facial recognition is moving out of the control room and into everyday life. If cameras, artificial intelligence and biometric identification converge in devices that look like ordinary glasses, the change will not simply be technological. It will alter the balance between the person observing and the person being observed. Clothing designed to confuse computer vision is an ingenious response. But it cannot become society’s answer to biometric surveillance.

The attraction of adversarial fashion is easy to understand. If an algorithm can identify a person from an image, perhaps the answer is to wear something that makes the algorithm misread what it sees.

Italian label Cap_able has developed garments using patterns intended to interfere with computer-vision systems. The underlying principle is technically credible: so-called adversarial patterns can cause neural networks to misclassify objects or fail to recognise them under certain conditions. More recent research has shown that specially engineered clothing can even interfere with both visible-light and infrared-based detection systems.

But the important qualification is under certain conditions.

A pattern that works against one model, from one camera angle and at one distance may be ineffective against another system. Resolution, lighting, image preprocessing, sensor fusion and retrained models can all change the outcome. Adversarial fashion therefore demonstrates something important about AI vision systems: they can be manipulated. It does not demonstrate that a person can reliably become invisible to biometric identification simply by choosing the right coat.

And that distinction matters, because the clothing risks distracting us from the more significant development.

The real issue is invisible identification

Facial recognition itself is not new. What is changing is the environment in which it may be used.

A surveillance camera at an airport, railway station or secured site is recognisable as part of a security infrastructure. Smart glasses are different. If a device resembling an ordinary pair of spectacles can capture an image, analyse a face and retrieve information about the person in front of the wearer, identification becomes socially far less visible.

Meta has explored precisely this direction. Reports in 2026 described an internal concept known as “Name Tag”, which could allow smart glasses to recognise people and provide information about them through an AI assistant. A separate Meta patent application published this year also describes AI-enabled camera systems incorporating facial-recognition scenarios. Neither development proves that such a consumer feature will necessarily reach the market, but they show clearly where the technology can move.

The more profound change is therefore not another improvement in recognition accuracy. It is the possibility that identification itself becomes ambient.

The person being observed may no longer know that an identification process is taking place. The wearer of the device may gain information about a stranger while that stranger has no equivalent way of knowing that a biometric query has occurred.

At that point, a camera stops being merely a recording device. It becomes a personal interface to identity.

The privacy question consequently changes. It is no longer only: Who may store my face?

It becomes: Who may use my face as a search query simply by looking at me?

European regulation does not make the issue disappear

Europe has far more restrictive rules for biometric processing than many other jurisdictions. The GDPR gives biometric data special protection, while the AI Act places additional limits on biometric identification, particularly in relation to real-time remote identification by law-enforcement authorities in publicly accessible spaces.

That regulatory framework matters. But Europe should resist the comforting assumption that strict rules automatically solve the problem.

Law can define when biometric processing is permitted. It cannot make technically capable devices disappear.

There is also an important difference between authentication and identification. Unlocking a device with one’s own face is fundamentally different from being identified by someone else in an uncontrolled public environment. European data-protection authorities have repeatedly emphasised this distinction because the latter affects something broader than information security: the ability to remain effectively anonymous among strangers.

This is precisely why smart glasses deserve attention from the security sector.

People have become accustomed to phones containing cameras. They have not yet become accustomed to the possibility that another person’s glance might simultaneously trigger a database search.

We should not outsource privacy to the person being watched

Adversarial clothing is valuable because it makes this problem visible. It demonstrates that machine vision is not infallible and forces an important public debate about the relationship between humans and automated observation.

But it would be a remarkable failure of governance if citizens eventually needed specialist clothing merely to preserve a degree of anonymity in public.

Privacy by Design cannot mean requiring the observed person to defeat the algorithm.

The responsibility must remain primarily with the other side of the camera: manufacturers, platform operators, deployers and regulators. They must decide whether identification is technically necessary, legally justified, visible to the person affected and limited to a clearly defined purpose.

The question is therefore not whether a jacket can fool facial recognition.

Sometimes it can.

The much more important question is why the individual should need the jacket in the first place.

If biometric identification becomes an incidental feature of ordinary vision, something more fundamental than data protection is at stake. We risk losing a social condition that has long been taken for granted: the ability to move through public space without being instantly identifiable to every stranger carrying the right hardware.

That is not a technical inconvenience. It is a question about what kind of public space Europe intends to preserve.

[DCM]

Related Articles

Editor’s note: Organised crime has become a service industry

Operation Jackal IV is significant not simply because of the number of arrests it produced, but because of what it reveals about the structure of contemporary organised crime. Technical infrastructure, social engineering and money laundering are increasingly...

Share This