Samsung’s entry into AI-powered glasses forces CISOs to again consider corporate risk

· Source: Computerworld · Field: Technology & Digital — Artificial Intelligence & Machine Learning, Cybersecurity & Data Privacy, Cloud Computing & IT Infrastructure · Depth: Intermediate, medium

Summary

Samsung's entry into the AI-powered glasses market, joining Apple, Google, and Meta, compels CISOs and IT leaders to re-evaluate corporate risks associated with these devices. Key concerns include data leakage, privacy violations, and compliance issues, exacerbated by the difficulty of enforcing policies given user-controlled settings and devices' history of ignoring guardrails. While smart glasses may have recording indicators, these are easily circumvented. Experts like Carmi Levy and Jitesh Ubrani highlight the near impossibility of outright bans, noting that the underlying data capture risk isn't new, but smart glasses significantly reduce the friction for covert recording. Additional risks involve corporate intellectual property exposure and data sovereignty. Analysts Meghan Hollis and Jitesh Ubrani advocate for education and tiered policies, recommending strict no-wearables rules for sensitive areas like boardrooms and R&D labs, while allowing for disclosure in general office settings, rather than blanket prohibitions.

Key takeaway

For CISOs and IT leaders managing corporate risk from emerging AI wearables, recognize that blanket bans are largely unenforceable and may create legal issues. Instead, you should implement tiered acceptable use policies, strictly prohibiting devices in sensitive areas like boardrooms and R&D labs, while requiring disclosure in general office settings. Prioritize educating your end-users on the potential harm of unauthorized recording to the company and clients, reinforcing consequences for non-compliance.

Key insights

AI smart glasses escalate covert data capture risk, demanding tiered policies and user education over unenforceable bans.

Principles

Method

Implement tiered policies: strict no-wearables in sensitive areas (boardrooms, R&D), disclosure in general offices. Educate end-users on company harm from unauthorized recording, reinforcing consequences.

In practice

Topics

Best for: CTO, VP of Engineering/Data, Executive, AI Security Engineer, Security Engineer, IT Professional

Related on AIssential

Open in AIssential →

Editorial summary, takeaway, and curation by AIssential. Original article published by Computerworld.