Augmented Reality Governance .
Augmented Reality Governance in Europe
1. Meaning of Augmented Reality Governance
Augmented Reality (AR) Governance refers to the legal and regulatory framework governing technologies that superimpose digital information, images, sounds, virtual objects, instructions, advertisements, biometric information or other computer-generated material onto a user's perception of the physical world.
Examples include:
AR glasses;
smartphone AR applications;
navigation overlays;
industrial AR systems;
medical AR;
AR gaming;
retail and advertising overlays;
facial-recognition AR;
workplace AR;
educational AR;
tourism and cultural-heritage applications;
AR navigation;
virtual product try-ons;
location-based AR;
AI-powered AR assistants.
Europe does not currently have one comprehensive “Augmented Reality Act.” Instead, AR is governed through several overlapping areas of European law, depending upon what the technology does.
The principal regulatory areas are:
Privacy + Data Protection + AI + Consumer Protection + Product Safety + Intellectual Property + Employment Law + Competition + Cybersecurity + Fundamental Rights + Sector-Specific Regulation
2. Why AR Creates Special Legal Problems
Traditional digital services generally operate within a screen.
AR changes this relationship by placing digital information directly into the user's physical environment.
For example, an AR system could identify:
a person's face;
a vehicle;
a building;
a product;
a workplace hazard;
a patient's body;
a pedestrian;
a geographical location.
It could then immediately display information about that object.
This creates a distinctive legal problem:
AR can transform the physical environment into a continuously monitored and digitally annotated information space.
Consequently, privacy, property, safety and freedom-of-expression questions can arise simultaneously.
3. Main Categories of AR Governance
3.1 Privacy Governance
AR devices may collect:
camera images;
video;
audio;
location;
eye movements;
facial information;
voice;
body movements;
biometric information;
environmental information;
interaction patterns.
This can trigger GDPR obligations.
Particularly important GDPR provisions include:
Article 5 — principles of processing;
Article 6 — lawful basis;
Article 9 — special-category data;
Articles 12–14 — transparency;
Article 15 — access;
Article 21 — objection;
Article 22 — automated decision-making;
Article 25 — privacy by design;
Article 32 — security;
Article 35 — data-protection impact assessment;
Article 82 — compensation.
4. AR and Biometric Identification
AR systems can potentially identify people in real time.
For example:
A person wearing AR glasses looks at a stranger and receives the person's name, occupation and social-media information.
This can create substantial legal concerns.
The system may process:
facial images;
biometric identifiers;
location information;
social information;
inferred characteristics.
The legal analysis becomes considerably stricter where biometric identification is involved.
5. AR and the Physical Environment
An AR device may scan its surroundings to determine:
walls;
rooms;
streets;
objects;
vehicles;
people;
signs;
businesses.
This raises questions about whether scanning and recording a person's physical environment interferes with:
privacy;
property;
trade secrets;
confidential information;
public security.
A camera pointed at a public street does not automatically create unlawful processing, but the purpose, data type, scale, identification capability and retention are critical.
6. AR and the GDPR
The GDPR applies where AR processing involves personal data and falls within its territorial scope.
A controller must consider:
Lawfulness
What legal basis authorises the processing?
Purpose limitation
Why is the data being collected?
Data minimisation
Does the AR system collect more information than necessary?
Transparency
Does the person know what is happening?
Storage limitation
How long is information retained?
Security
Could AR data be accessed by unauthorised persons?
Data protection by design
Can the system be designed to minimise unnecessary collection?
7. AR and the “Bystander Problem”
One of the most difficult AR issues is the bystander problem.
A smartphone user can generally choose whether to take a photograph.
An AR device, however, may continuously observe the environment.
Consequently, individuals may be recorded without:
knowing that recording is occurring;
knowing who operates the device;
knowing why the information is collected;
knowing where the information is stored.
This creates significant privacy and transparency concerns.
8. AR and Artificial Intelligence
Modern AR systems increasingly use AI for:
object recognition;
facial recognition;
voice recognition;
scene understanding;
translation;
predictive assistance;
personalised advertising;
navigation;
medical analysis;
workplace monitoring.
Therefore, the EU AI Act can become relevant depending upon the particular AI system and use.
The AI Act must be read together with GDPR, product-safety law and fundamental-rights requirements.
9. AR and Consumer Protection
AR can change how products are marketed.
Examples include:
virtual try-ons;
AR advertising;
virtual furniture placement;
AR shopping assistants;
immersive sales interfaces;
personalised advertisements.
Potential problems include:
misleading representations;
hidden advertising;
manipulation;
undisclosed commercial content;
misleading product visualisation;
dark patterns.
Consumer protection therefore becomes an important component of AR governance.
10. AR and Dark Patterns
An AR interface could potentially manipulate users through:
persistent pop-ups;
virtual objects blocking alternative choices;
exaggerated visual effects;
artificial urgency;
location-triggered advertising;
repeated prompts;
hidden commercial content.
The DSA's rules concerning manipulative interface design can become relevant where an AR service falls within its scope.
The broader principle is:
Immersive technology does not remove ordinary consumer-protection obligations.
11. AR Advertising
AR allows advertisements to be placed directly onto physical environments.
For example:
A person looks at a building and sees a digital advertisement attached to it through AR glasses.
Potential issues include:
whether the advertisement is clearly identifiable;
whether location data are used;
whether the advertisement is personalised;
whether sensitive characteristics are used;
whether children receive targeted advertisements;
whether the advertiser has rights to the underlying image;
whether the overlay interferes with another business's property or trademark.
12. AR and Intellectual Property
AR can create complex IP disputes.
An AR application may display:
copyrighted artwork;
trademarks;
architectural works;
sculptures;
photographs;
maps;
logos;
commercial signs.
Questions include:
Is the underlying work protected?
Is the AR reproduction or communication to the public authorised?
Is the trademark being used commercially?
Does the AR overlay create a derivative work?
Does the AR developer have rights to the underlying database or map?
13. AR and Public Spaces
AR applications may digitally modify the appearance of:
streets;
monuments;
public buildings;
museums;
parks;
historical sites.
A legal dispute can therefore arise between:
AR developer;
property owner;
municipality;
cultural institution;
trademark owner;
copyright owner;
user.
The fact that an overlay is digital does not automatically eliminate underlying property or IP rights.
14. AR and Freedom of Expression
AR can also be an expressive medium.
Users might place:
political messages;
artistic objects;
criticism;
historical commentary;
satire;
virtual demonstrations.
European law therefore protects AR expression through:
Article 10 ECHR;
Article 11 Charter.
Restrictions must generally satisfy legality, legitimate aim and proportionality requirements.
15. AR and Property Rights
A particularly interesting question is whether a virtual object placed over physical property interferes with property rights.
There is currently no general European rule saying:
“Digital content placed over property constitutes trespass.”
The legal result depends upon the conduct involved.
For example:
purely virtual placement may raise little property-law concern;
physical installation of AR equipment is different;
commercial exploitation of a building's image can raise IP issues;
persistent digital advertising attached to a specific property can raise contractual or unfair-competition questions.
Therefore, digital overlay should not automatically be equated with physical trespass.
16. AR and Workplace Governance
AR can be used in:
manufacturing;
logistics;
construction;
healthcare;
warehousing;
maintenance;
military contexts;
training.
Employers may use AR to monitor:
employee movements;
productivity;
eye direction;
task performance;
mistakes;
location.
This can create employment-privacy issues.
Relevant principles include:
GDPR;
employment law;
equality law;
occupational safety;
collective labour rights;
Article 8 ECHR.
17. AR and Health Data
Medical AR can involve:
patient records;
anatomical images;
medical scans;
surgical guidance;
biometric measurements.
Health data receive heightened protection under GDPR Article 9.
Where AR becomes a medical device or medical software, the Medical Devices Regulation can become relevant.
This creates potentially overlapping obligations involving:
safety;
clinical performance;
data protection;
cybersecurity;
professional negligence;
product liability.
18. AR Product Safety
AR hardware can cause physical harm.
Examples include:
collision;
impaired vision;
distraction;
incorrect navigation;
overheating;
battery failure;
defective sensors;
inaccurate warnings.
European product-liability law can therefore become relevant.
The modern European product-liability framework increasingly recognises the importance of:
software;
digital components;
connected products;
cybersecurity;
software updates.
19. AR and Autonomous Decision-Making
AR may not merely display information.
It may recommend:
where to walk;
what product to purchase;
which route to take;
which person to avoid;
which workplace task to perform;
what medical action to consider.
Where automated processing produces legally significant consequences, GDPR Article 22 and related transparency provisions may become relevant.
20. AR and Children
AR games and educational systems may collect extensive information about children.
Potential issues include:
location tracking;
behavioural profiling;
advertising;
biometric data;
social interactions;
attention monitoring;
psychological manipulation.
Children's rights receive heightened protection under:
GDPR;
DSA;
Charter Article 24;
ECHR principles.
21. Important European Case Law
1. Google Spain SL, Google Inc. v AEPD and Mario Costeja González
C-131/12, CJEU, 13 May 2014
The CJEU examined the responsibilities of search engines in relation to personal information.
Importance for AR
An AR search system may similarly identify and retrieve information about people or places.
The case supports the broader principle that digital intermediaries processing personal information can have independent data-protection responsibilities.
Relevance: strong analogical authority.
22. Google LLC v CNIL
C-507/17, CJEU, 24 September 2019
The CJEU considered the territorial scope of search-engine delisting obligations.
AR significance
AR applications may operate across multiple European countries.
The case demonstrates the importance of distinguishing:
EU-wide obligations;
national implementation;
territorial scope.
This becomes especially important for globally deployed AR services.
Relevance: analogical but important for cross-border digital governance.
23. Glukhin v Russia
Application No. 11519/20, ECtHR, 4 July 2023
The case concerned the use of facial-recognition technology to identify an individual.
The ECtHR found serious implications for privacy under Article 8 ECHR.
Importance for AR
This is particularly relevant to AR because AR glasses could potentially perform:
facial recognition;
real-time identification;
tracking;
biometric matching.
Glukhin demonstrates that technological identification can constitute a serious interference with privacy.
Relevance: highly significant analogical authority for biometric AR.
24. S. and Marper v United Kingdom
Applications Nos. 30562/04 and 30566/04, ECtHR Grand Chamber, 4 December 2008
The case concerned retention of fingerprints and DNA profiles.
The Court emphasised the privacy implications of systematic retention of biometric information.
AR significance
AR systems can potentially create persistent biometric databases through:
facial recognition;
gait recognition;
iris recognition;
voice identification.
S. and Marper therefore supports strong scrutiny of biometric retention and use.
Relevance: analogical but foundational.
25. Bărbulescu v Romania
Application No. 61496/08, ECtHR Grand Chamber, 5 September 2017
The case concerned workplace monitoring.
The ECtHR established important principles concerning the balance between:
employee privacy;
employer interests;
workplace monitoring.
AR significance
Employers using AR glasses to monitor workers may collect information about:
movements;
communications;
productivity;
physical behaviour.
Bărbulescu provides an important framework for assessing workplace AR surveillance.
Relevance: highly relevant by analogy.
26. López Ribalda and Others v Spain
Applications Nos. 1874/13 and 8567/13, ECtHR Grand Chamber, 17 October 2019
The case concerned covert workplace video surveillance.
The ECtHR examined the proportionality of workplace monitoring under Article 8.
AR significance
AR devices can potentially function as continuous workplace surveillance tools.
The case demonstrates that employer monitoring must be assessed in light of:
necessity;
proportionality;
employee expectations;
safeguards;
purpose.
Relevance: strong analogical authority.
27. Planet49
C-673/17, CJEU, 1 October 2019
The CJEU addressed consent relating to cookies.
AR significance
AR applications can use:
tracking technologies;
behavioural analytics;
advertising identifiers;
location tracking.
Planet49 reinforces the requirement that consent mechanisms satisfy European data-protection standards.
Relevance: direct GDPR/ePrivacy principle; analogical to AR.
28. Meta Platforms Ireland v Bundeskartellamt
C-252/21, CJEU, 4 July 2023
The CJEU examined the relationship between competition law and personal-data processing by a dominant platform.
AR significance
A dominant AR ecosystem might combine data from:
AR glasses;
smartphones;
social networks;
advertising systems;
location services.
The case demonstrates that data practices can have both privacy and competition dimensions.
29. Österreichische Post
C-300/21, CJEU, 4 May 2023
The CJEU considered compensation under GDPR Article 82.
AR significance
If an AR system unlawfully processes personal or biometric information, a claimant may potentially seek compensation.
However, the legal analysis still requires attention to:
infringement;
damage;
causation;
compensability.
A GDPR violation does not mean that every claimant automatically receives damages.
30. SCHUFA
Joined Cases C-26/22 and C-64/22, CJEU, 7 December 2023
The CJEU addressed automated scoring and automated decision-making.
AR significance
AI-powered AR could generate:
identity scores;
risk assessments;
behavioural profiles;
consumer classifications.
SCHUFA is therefore relevant to the governance of AR systems that make consequential decisions based upon automated profiling.
31. Consolidated Case-Law Table
| Case | Court | Principle | AR relevance |
|---|---|---|---|
| Google Spain, C-131/12 | CJEU | Search-engine data responsibility | AR identification/search |
| Google v CNIL, C-507/17 | CJEU | Territorial scope of digital rights | Cross-border AR |
| Glukhin v Russia | ECtHR | Facial recognition/privacy | Biometric AR |
| S. & Marper v UK | ECtHR | Biometric-data retention | Facial/biometric AR |
| Bărbulescu v Romania | ECtHR | Workplace monitoring | AR workplace surveillance |
| López Ribalda v Spain | ECtHR | Proportionality of surveillance | AR monitoring |
| Planet49, C-673/17 | CJEU | Consent and tracking | AR tracking |
| Meta Platforms, C-252/21 | CJEU | Data + competition | AR ecosystems |
| Österreichische Post, C-300/21 | CJEU | GDPR compensation | AR privacy harm |
| SCHUFA, C-26/22 & C-64/22 | CJEU | Automated decision-making | AI-powered AR |
32. AR and Data Protection Impact Assessments
A DPIA under GDPR Article 35 may be particularly important where AR involves:
systematic monitoring;
biometric identification;
large-scale location tracking;
vulnerable persons;
health data;
workplace surveillance;
automated profiling.
An AR provider should therefore assess the system before deployment, rather than waiting until privacy litigation occurs.
33. AR Governance and Data Minimisation
A privacy-protective AR system might use:
on-device processing;
short retention periods;
local anonymisation;
automatic blurring;
privacy zones;
prohibition of biometric identification;
encryption;
visible recording indicators.
These are examples of privacy by design, rather than merely post-hoc compliance.
34. AR and Cybersecurity
AR devices can create cybersecurity vulnerabilities because they may combine:
cameras;
microphones;
sensors;
cloud services;
biometric data;
location;
personal accounts.
A compromised AR device could reveal highly sensitive information about:
where a person is;
whom they are looking at;
what they are seeing;
what they are saying;
what environment they occupy.
Security therefore becomes a central component of AR governance.
35. AR and Trade Secrets
Industrial AR may display:
factory layouts;
engineering diagrams;
production processes;
customer information;
confidential instructions.
If AR glasses record or transmit this information to an external cloud provider, trade-secret risks can arise.
The issue may involve:
confidentiality;
cybersecurity;
employee duties;
contractual obligations;
trade-secret legislation.
36. AR and Intellectual Property Infringement
Potential infringement scenarios include:
Copyright
An AR application reproduces protected artwork.
Trademark
An AR advertisement uses another company's logo.
Design rights
An AR system reproduces protected product designs.
Database rights
An AR navigation service copies a protected database.
Architectural works
An AR application digitally reproduces protected structures.
The legal analysis depends upon the particular IP right and the technical manner in which the AR system reproduces or communicates the material.
37. AR and Freedom of Expression
An AR system can also become a medium of political or artistic expression.
For example:
virtual protest signs;
historical reconstructions;
political overlays;
satirical digital objects;
artistic installations.
Any regulatory restriction must therefore consider:
Article 10 ECHR + Article 11 Charter + legitimate regulatory objective + proportionality.
A blanket prohibition on AR overlays would raise significantly different issues from a narrowly tailored prohibition on unlawful biometric surveillance.
38. AR and Competition Law
Competition issues can arise where a dominant AR ecosystem controls:
hardware;
operating systems;
app stores;
AR advertising;
mapping;
user data;
identity systems.
Potential concerns include:
self-preferencing;
exclusion of competing AR applications;
discriminatory access;
tying;
data advantages;
interoperability restrictions.
The DMA may become especially significant where an AR provider falls within the relevant gatekeeper framework.
39. AR and Product Liability
An AR headset could potentially be defective because of:
faulty hardware;
dangerous software;
incorrect navigation;
cybersecurity vulnerability;
defective updates;
inaccurate warnings.
Potential defendants could include:
manufacturer;
software provider;
distributor;
importer;
other responsible economic operators under applicable legislation.
A claimant would still need to establish the relevant legal elements under the applicable product-liability regime.
40. AR and Medical Applications
Medical AR creates particularly sensitive governance questions.
Examples:
surgical navigation;
augmented medical imaging;
rehabilitation;
visual assistance;
diagnosis support.
Potential liability can arise from:
defective software;
inaccurate information;
data breaches;
inadequate warnings;
professional negligence;
improper patient consent.
The Medical Devices Regulation may apply where the AR product falls within the definition of a medical device.
41. AR and Public Authorities
Police and other public authorities could theoretically use AR for:
facial recognition;
navigation;
surveillance;
crowd management;
evidence gathering.
This can engage:
GDPR;
law-enforcement data rules;
ECHR Article 8;
Article 10;
procedural safeguards.
Glukhin is particularly important when assessing biometric surveillance.
42. AR and Children
A governance framework for children's AR should examine:
age verification;
location collection;
advertising;
biometric processing;
social interaction;
content recommendation;
behavioural profiling;
psychological manipulation;
safety;
parental controls.
The best-interest principle concerning children can become particularly important where immersive technology is involved.
43. Potential Civil Claims
AR-related civil litigation could involve:
Privacy claim
Unauthorised recording or biometric identification.
GDPR claim
Unlawful processing or inadequate security.
Defamation/reputation claim
AR system displays false information about a person.
IP claim
Unauthorised reproduction or commercial use of protected material.
Consumer claim
Misleading AR advertising or product representation.
Product-liability claim
Defective headset or AR software causes injury.
Employment claim
Unlawful AR surveillance.
Contract claim
AR service fails to provide promised functionality.
Competition claim
Dominant AR ecosystem excludes competitors.
44. Defences
Potential defences include:
valid consent;
legitimate interests;
statutory authority;
public-interest justification;
necessity;
proportionality;
freedom of expression;
absence of personal data;
anonymisation;
lack of causation;
absence of compensable damage;
technical limitations;
compliance with applicable regulatory requirements.
However, compliance with one regime does not automatically establish compliance with all others.
45. Practical AR Governance Test
A European AR system can be analysed using the following sequence:
Technology → Data → Purpose → Actor → Legal Basis → Risk → Rights → Safety → Harm → Remedy
More specifically:
What does the AR system actually do?
What information does it collect?
Does it identify individuals?
Does it process biometric or health information?
Who controls the processing?
What is the legal basis?
Is consent required?
Is AI involved?
Is the system high-risk?
Is the device safe?
Are consumers adequately informed?
Are children involved?
Are employees monitored?
Are third-party IP rights affected?
Is expression affected?
Has legally recognised harm occurred?
What remedy is available?
46. Direct vs Analogical Case Law
There is currently no mature European case-law category specifically called “Augmented Reality Governance.”
Accordingly, the cases should be classified carefully.
Strongest analogies
Glukhin v Russia — biometric identification.
S. and Marper v UK — biometric data.
Bărbulescu v Romania — workplace monitoring.
López Ribalda v Spain — surveillance.
Google Spain — digital identification/search.
Planet49 — tracking and consent.
Broader digital-governance authorities
Meta Platforms
Österreichische Post
SCHUFA
Google v CNIL
These cases do not decide AR disputes specifically, but their legal principles can apply to AR systems depending on their functionality.
47. Key Principles of European AR Governance
The emerging European approach can be summarised as follows:
AR is not a legally unregulated technological space.
The GDPR can apply to AR-generated personal data.
Biometric AR requires particularly careful legal analysis.
Real-time identification can engage Article 8 ECHR.
Workplace AR surveillance must satisfy privacy and proportionality requirements.
AR advertising remains subject to consumer-protection rules.
AI-powered AR may fall within the AI Act depending on its use and risk category.
AR hardware and software can raise product-safety and liability issues.
AR overlays can implicate copyright, trademarks and other IP rights.
AR expression is protected by European freedom-of-expression principles.
Children require heightened protection.
AR platforms can raise competition and gatekeeper issues.
Digital processing does not automatically override physical-world property and privacy interests.
Compliance with one European regulatory regime does not create immunity under another.
The responsible company cannot generally escape liability merely because an AI system generated the AR output.
48. Conclusion
Augmented Reality Governance in Europe is an emerging cross-disciplinary field rather than a single statutory regime.
Its legal structure is best understood as an intersection of:
GDPR + AI Act + Digital Services Act + Consumer Law + Product Liability + Medical Device Law + Intellectual Property + Employment Law + Competition Law + Cybersecurity + Charter Rights + ECHR
The most important European cases are Google Spain, Google v CNIL, Glukhin, S. and Marper, Bărbulescu, López Ribalda, Planet49, Meta Platforms, Österreichische Post and SCHUFA.
Together, these authorities establish an important principle: AR does not receive a special exemption from ordinary European legal protections merely because information is delivered through an immersive interface. Where AR involves biometric identification, continuous surveillance, behavioural profiling, automated decision-making, targeted advertising, unsafe products or misuse of personal information, existing European legal doctrines can impose substantial obligations.
At the same time, not every AR overlay is unlawful. European law requires a fact-specific assessment of purpose, legal basis, necessity, proportionality, technological function, user expectations, potential harm and the rights of affected third parties.

comments