Biometrics policy in Norway shifts toward smart glasses controls

Norway moved on August 27, 2026 to tighten scrutiny of smart glasses and consider restrictions on facial recognition use in that form factor, according to reporting from Biometric Update and BGNES. For identity teams, the immediate issue is less about consumer hardware and more about where ambient biometric capture stops being a legitimate control and starts becoming a policy, privacy, and deployment risk.

Norway is treating facial recognition in smart glasses as a separate policy problem, not as a minor extension of phone or camera use, according to reporting published on August 27, 2026 by Biometric Update and BGNES. That distinction matters for identity practitioners because the same biometric matching capability can look very different to regulators once it moves from an explicit user step to ambient capture in public space.

What happened in Norway on August 27, 2026

Reporting from Biometric Update says Norway is targeting facial recognition in smart glasses as privacy concerns grow. Reporting from BGNES says Norway tightened controls on smart glasses and is considering a ban on facial recognition in that context. The event date supplied for both reports is 2026-08-27.

The named public actor in the event is the Government of Norway. Across the two reports, the issue is framed as a privacy and policy response to facial recognition embedded in wearable devices rather than a general statement about all biometric identity verification. Biometric Update and BGNES both place the concern on the combination of smart glasses and facial recognition.

That is the operational hinge. A document selfie or liveness check is usually a discrete transaction. Smart glasses shift capture toward persistence, mobility, and low-friction observation. Same underlying biometric category. Different consent and notice problem.

Why this lands differently for identity teams

Identity verification teams usually evaluate facial biometrics around match accuracy, spoof resistance, fraud loss, fallback flows, and user drop-off. Norway's move, as described by Biometric Update and BGNES, puts the deployment context at the center of the decision.

Inference: The immediate market signal is that regulators may begin separating transactional biometrics from ambient biometrics, even when both rely on facial recognition. If that reading holds, buyers will need product and policy reviews that are specific to the capture environment, not just to the matching model.

For practitioners, that changes a few very practical questions:

- Is facial recognition being triggered during a user-initiated step, or running passively in the background? - Is the device obviously part of an authentication flow, or effectively invisible to bystanders? - Can a deployment be explained as access control for a known session, or does it drift into identification of people in public? - Does the procurement review distinguish between who is being authenticated and who may be incidentally captured?

Those questions sound basic. They are often missing from product intake until a regulator or privacy office forces the issue.

The hidden dependency: form factor changes the compliance conversation

The two reports do not present a broad ban on facial biometrics across identity use cases; they describe pressure on smart-glasses-based facial recognition in Norway, with BGNES specifically describing consideration of a ban. That narrower framing is important.

A face match performed during onboarding, account recovery, or workforce re-verification is usually bounded by a visible workflow. Smart glasses create a different chain of custody around collection, notice, and bystander impact. The biometric system may be technically identical, while the governance burden changes sharply. Procurement teams that buy "facial recognition" as a single category will miss that distinction.

Our read: Norway's move is best read as a warning about ambient collection risk rather than as a general rejection of face biometrics for identity verification. Practitioners should treat wearable capture as a separate control family in architecture reviews, data protection assessments, and vendor contract language.

Counter-read: Norway's approach, as reported on August 27, 2026, may remain a narrow response to one device category and may not travel far into mainstream KYC, workforce identity, or step-up authentication programs without broader legislative follow-through from other jurisdictions.

What would change this conclusion: Evidence that Norwegian authorities, or peer European regulators, extend similar restrictions from smart glasses to conventional onboarding, authentication, or document-plus-selfie workflows would weaken the view that this is mainly a form-factor-specific intervention.

The buyer consequence: separate the use cases now

For teams buying biometric identity verification, wearable intelligence, or fraud tooling, the safe assumption is that "face" is no longer a sufficient scoping term. The procurement unit matters. The device matters. The operator visibility matters.

That creates three immediate workstreams:

1. Inventory capture modes. If a platform can run on phones, kiosks, body-worn devices, or smart glasses, each mode should be documented separately. One legal review for all of them is thin ice. 2. Rewrite vendor questionnaires. Ask whether facial recognition can operate continuously, whether it can identify non-participants, and what controls exist for disabling or geofencing sensitive modes. 3. Review retention and access assumptions. Even where the current issue is framed around privacy concerns, retention, auditability, and operator permissions usually arrive next in the policy discussion. A product team calling something a feature does not make it deployable. There is always paperwork.

What to Do Next

- Map every facial biometric workflow by capture context: user-initiated onboarding, account recovery, workplace access, kiosk, and any wearable or background-capable mode. - Ask current vendors whether their biometric stack can run on smart glasses or similar wearables, and document whether those capabilities are enabled, disabled, or configurable in your contract and tenant settings. - Update DPIA and privacy review templates to separate transactional identity verification from ambient or bystander-facing identification scenarios. - Force a product-policy handoff before pilots: require legal, privacy, and security review when a biometric control moves from phone or browser capture to any always-available camera form factor.

Sources