Wear a microphone on your chest for a week and you will record dozens of people who never agreed to be recorded: the barista who made your coffee, the stranger who asked for directions, your kid's teacher at pickup. None of them consented. Most of them never knew. This is not a hypothetical edge case for AI wearables — it is the default mode of operation, and it is the reason a growing number of these devices are ending up in courtrooms and statehouses instead of just on shelves.
Always-listening AI hardware — pendants, pins, smart glasses, and earbuds that continuously capture audio (and sometimes video) to feed a language model — has moved from novelty to product category in the last two years. The pitch is compelling: an assistant that remembers every conversation, transcribes every meeting, and never needs you to hit a button. The problem is that every one of those conversations has at least one other participant who wasn't asked.
What always-listening actually means
"Always-listening" is a spectrum, not a single behavior, and the differences matter enormously for privacy.
- Wake-word listening: The device processes audio locally in a rolling buffer, discarding it unless a trigger phrase is detected. Nothing is transmitted or stored until activation. This is how most smart speakers and phone assistants operate.
- Continuous local processing, selective upload: The device is always analyzing audio (for context, activity detection, or ambient AI features) but only sends specific clips or summaries to the cloud.
- Continuous capture and transcription: The device is genuinely always recording, transcribing everything in real time, and storing or uploading that transcript by default. This is the category that AI companion pendants and some smart glasses fall into, and it's the one generating the most controversy.
- Continuous audio plus video: Camera-equipped wearables (smart glasses in particular) add a visual record to the audio one, capturing faces, license plates, documents, and screens in the background of whatever the wearer is doing.
The distinction between these tiers is not cosmetic. A wake-word device that never transmits audio it didn't process against a trigger has a fundamentally different privacy posture than a pendant that transcribes and stores every word spoken in its presence, indexed and searchable later. Marketing language often blurs this line — "always-on AI" gets used for both — but the legal exposure and the bystander-harm profile are worlds apart.
Where the recording actually happens
Most of these devices don't do heavy processing on-device. Audio is typically streamed or batched to a cloud service where a speech-to-text model transcribes it and a language model summarizes or indexes it. That means bystander speech doesn't just get captured momentarily — it gets copied to a company's servers, potentially retained, potentially used to improve models, and potentially accessible to that company's employees or contractors reviewing flagged content. The privacy exposure isn't just "a stranger overheard me" — it's "a stranger's words are now training data on someone else's infrastructure."
Why bystander consent is the unsolved problem
Every major consumer-privacy framework built in the last three decades — wiretap statutes, GDPR, most state privacy laws — was written around a model where a company collects data from a person who has some form of relationship with that company: a user, a customer, a website visitor. Always-listening wearables break that model. The person whose voice gets captured, transcribed, and stored is frequently not the customer, has no account, no terms of service they agreed to, and often no idea the device exists.
This creates what privacy researchers sometimes call a "third-party data" problem: the data subject and the party who can consent (the device owner) are different people. The owner can decide to wear the device. They cannot decide, on behalf of everyone they talk to, that recording is acceptable.
A few structural reasons this is hard to fix with a settings toggle:
- Consent has to happen before the harm, not after. A bystander can't retroactively refuse to have been recorded. By the time they notice a device (if they notice it at all), the audio is already captured.
- Notification requires a signal bystanders can actually perceive. A tiny LED on a pair of glasses is easy to miss in a crowded room, easy to obscure with a sticker, and easy to design around entirely.
- The wearer has an incentive not to disclose. Part of the product's appeal is capturing conversations naturally, without the friction of announcing "I'm recording this." That incentive runs directly against the interests of everyone else in the room.
- Group settings compound the problem. A restaurant table, a classroom, a support-group meeting — the more people present, the more consent decisions would theoretically be required, and the less realistic it becomes to gather them.
None of this is unique to AI hardware — dash cams and body cams raised similar questions years ago. What's different is scale and searchability. A dash cam records a commute; an always-listening pendant can record an entire life's worth of conversations, transcribed into a permanent, searchable text record that a language model can query on demand. The volume and structure of what gets captured is qualitatively different from a raw video file sitting on an SD card.
Why this matters right now
The legal system is starting to catch up to the hardware. Meta's AI pendant drew a US class action in March 2026, brought on behalf of people who were recorded by the device without their knowledge or consent — a direct test of whether existing wiretap and recording-consent laws apply to conversational AI wearables the same way they apply to a hidden microphone. At the same time, California is weighing a requirement for mandatory recording indicators on always-listening devices: a visible signal, not just an LED that can be covered or ignored, that tells anyone nearby that a conversation may be captured.
Both developments point at the same underlying gap: the devices reached the market faster than the rules governing bystander consent did. A class action tests whether current law already covers this behavior (many US states have two-party consent statutes for audio recording that predate any of this hardware). A mandatory-indicator rule is an attempt to write new, hardware-specific law because the old statutes weren't designed with continuously-transcribing AI in mind. If California moves forward, it would likely become a template other states copy — similar to how its privacy and disclosure laws have often set the de facto national baseline for consumer hardware sold in the US.
For companies building or integrating this class of device, the practical takeaway is that the compliance target is moving in real time. A device designed against 2024 assumptions about what's legally required may not clear the bar being set by cases and legislation working their way through the system in 2026.
The legal landscape businesses are navigating
Recording-consent law in the US is a patchwork, and always-listening AI devices sit squarely in the middle of it.
| Consent regime | How it works | States (representative) | Implication for AI wearables |
|---|---|---|---|
| One-party consent | Only one participant in the conversation needs to consent to recording | Most US states | Wearer's own consent may be sufficient — but doesn't resolve state-to-state travel or federal edge cases |
| Two-party / all-party consent | Every participant in the conversation must consent | California, Illinois, Florida, Pennsylvania, and roughly a dozen others | Bystanders without an on-device disclosure could have a valid claim the moment they're recorded |
| Sector-specific rules | Healthcare, education, and financial settings often add extra recording and data-handling restrictions regardless of state consent law | HIPAA, FERPA, GLBA contexts | An always-listening device in a clinic, classroom, or bank branch can trigger obligations beyond ordinary consent law |
| EU/UK (GDPR-adjacent) | Processing personal data (including voice) generally requires a lawful basis; "legitimate interest" is a weak fit for continuous bystander recording | EU member states, UK | Devices sold or used in Europe face a materially higher compliance bar than most US markets |
The two-party consent states are the immediate legal exposure for pendant and glasses makers, because a device that records by default in a public place in California or Illinois is, on a plain reading of those statutes, recording without the consent the law requires from every party to the conversation. Whether courts treat "ambient AI capture" the same way they've historically treated a hidden recorder is exactly the question the current class action is testing.
Practical implications for builders and businesses
If you're building on top of always-listening hardware, integrating one into a workplace, or evaluating whether to deploy AI wearables for your team, the risk isn't hypothetical — it's a live legal and reputational question. A few things worth building into any deployment plan:
- Default to visible, not passive, disclosure. An LED that can be covered with a sticker won't satisfy a regulator or a plaintiff's attorney. Audible chimes, persistent visual indicators, or paired signage in fixed locations (like an office lobby) are stronger defensible positions.
- Segment what gets recorded by location and context. A device that mutes automatically in known-sensitive settings — healthcare facilities, legal offices, HR conversations — reduces both legal exposure and the chance of a high-profile incident.
- Treat transcripts as sensitive data by default, not by exception. Bystander speech captured incidentally still constitutes personal data under most frameworks. Retention limits, access controls, and deletion workflows should apply to it the same way they apply to data from consenting users.
- Separate "assistant memory" from "raw capture." Products that summarize and discard raw audio quickly carry less risk than those that retain verbatim transcripts indefinitely — and this distinction is usually a real design lever, not just a policy statement.
- Get ahead of state-by-state variation. A product that behaves identically nationwide is easier to build but harder to defend in two-party consent states. Location-aware consent behavior (even just triggered by the phone's own location services) is a meaningful mitigation.
- Document the decision-making, not just the outcome. Regulators and plaintiffs' counsel look for evidence that consent tradeoffs were considered, not just for the final product behavior. A clear internal record of why a given disclosure mechanism was chosen is worth more after the fact than most companies assume going in.
What this looks like for enterprise buyers
Businesses considering always-listening tools for meetings, sales calls, or field work face a narrower but related question: does deploying this device make the company itself a defendant if a bystander — a client, a vendor, a member of the public in an office lobby — gets recorded without consent. Procurement processes for this category increasingly need a privacy review step that didn't exist for ordinary SaaS purchases, because the liability here doesn't stop at the vendor; it can attach to whoever chose to deploy the hardware in a shared space.
Limitations and open questions
None of the current fixes fully solve the underlying problem, and it's worth being honest about the gaps.
- On-device processing reduces but doesn't eliminate risk. Even if audio never leaves the device, it was still captured without the bystander's knowledge, and many consent statutes are triggered by the recording itself, not by whether it was transmitted anywhere.
- Visible indicators help but rely on people noticing and understanding them. A recording light means little to someone who doesn't know what the device is or what the light signifies — and normalization of these devices over time may make people less likely to notice at all.
- Enforcement is uneven. Two-party consent laws have existed for decades, largely enforced against individuals using hidden recorders in disputes or investigations. Applying them at the scale of a consumer hardware category, worn by potentially millions of people in public, is untested legal territory.
- International fragmentation is likely to get worse before it gets better. A device compliant with US state law may not clear GDPR's bar for lawful processing, and a single global product design may not be able to satisfy both without regional variants.
- The "reasonable expectation of privacy" standard is genuinely unsettled for public spaces. Courts have long held that people have reduced privacy expectations in public — but that doctrine developed around occasional, human-operated recording, not continuous, AI-transcribed capture by a device worn by a stranger. Whether that doctrine holds up unchanged is one of the open questions the current wave of litigation is actually testing.
What to watch next
The next twelve to eighteen months will likely settle some of the ambiguity, one way or another:
- The outcome (or settlement terms) of the Meta pendant class action, which will signal whether existing wiretap-style statutes are read to cover continuous AI transcription the same way they cover a hidden recorder.
- Whether California's mandatory-indicator proposal passes, and in what form — a hardware requirement (a physical light) is very different from a software requirement (an audible announcement), and the specifics will shape product design industry-wide.
- Whether other states follow with their own indicator or disclosure rules, given California's history of setting de facto national standards for consumer hardware.
- How device makers respond architecturally — whether the industry converges on stronger default disclosure and shorter retention, or whether it waits for enforcement before changing defaults.
- Enterprise and insurance responses, as businesses deploying this hardware start facing questions from their own liability insurers about bystander recording exposure in shared and public spaces.
FAQ
Is it illegal to wear an always-listening AI device in public?
It depends on the state and what the device does. In one-party consent states, the wearer's own consent to recording their conversation may be enough. In two-party (all-party) consent states like California and Illinois, recording someone without their knowledge can be illegal regardless of where the recording happens, which is the core issue current lawsuits are testing.
Do AI wearables record everything, all the time?
It varies by device. Some only activate on a wake word and discard audio otherwise; others continuously transcribe and store everything captured while worn. Always check whether a specific product does wake-word listening, selective capture, or full continuous transcription — the privacy implications differ substantially between them.
What is a bystander's actual recourse if they're recorded without consent?
In two-party consent states, bystanders may have grounds for a civil claim, and in some cases criminal complaints, against whoever operated the recording device. Class actions, like the one filed against Meta's AI pendant, aggregate these claims when the same recording behavior affects many people at once.
Can a visible LED or light satisfy consent requirements?
Not necessarily. A light can be missed, covered, or misunderstood, and courts haven't settled whether a passive indicator meets the bar that recording-consent statutes require. That's part of why California is considering a more explicit mandatory-indicator requirement rather than relying on manufacturers' existing designs.
How is this different from a smartphone recording conversations?
Smartphones can record conversations too, but doing so typically requires a deliberate, visible action — opening an app, hitting record. Always-listening wearables remove that friction by design, which is exactly what makes bystander consent harder to establish: there's no discrete moment where a decision to record is visibly made.
Are smart glasses with cameras a bigger privacy risk than audio-only pendants?
Generally yes, because they add a visual record — faces, documents, screens, license plates — to the audio one, and video is harder to anonymize after the fact than a transcript. Camera-equipped wearables also tend to draw more public backlash, since being filmed feels more invasive to most people than being overheard.
What should a business do before deploying AI wearables for employees?
Run a privacy review that covers where the devices will be used, whether bystanders (clients, vendors, the public) will realistically be present, and what disclosure mechanism will be visible to them — before purchase, not after an incident. Treat it as a legal and reputational decision, not just a productivity-tool purchase.
Teams evaluating always-listening AI hardware for their own workflows can get hands-on help thinking through the privacy and deployment tradeoffs from Woyce Technologies.
