Augmented Reality Governance .

Augmented Reality Governance in Europe

1. Meaning of Augmented Reality Governance

Augmented Reality (AR) Governance refers to the legal and regulatory framework governing technologies that superimpose digital information, images, sounds, virtual objects, instructions, advertisements, biometric information or other computer-generated material onto a user's perception of the physical world.

Examples include:

AR glasses;

smartphone AR applications;

navigation overlays;

industrial AR systems;

medical AR;

AR gaming;

retail and advertising overlays;

facial-recognition AR;

workplace AR;

educational AR;

tourism and cultural-heritage applications;

AR navigation;

virtual product try-ons;

location-based AR;

AI-powered AR assistants.

Europe does not currently have one comprehensive “Augmented Reality Act.” Instead, AR is governed through several overlapping areas of European law, depending upon what the technology does.

The principal regulatory areas are:

Privacy + Data Protection + AI + Consumer Protection + Product Safety + Intellectual Property + Employment Law + Competition + Cybersecurity + Fundamental Rights + Sector-Specific Regulation

2. Why AR Creates Special Legal Problems

Traditional digital services generally operate within a screen.

AR changes this relationship by placing digital information directly into the user's physical environment.

For example, an AR system could identify:

a person's face;

a vehicle;

a building;

a product;

a workplace hazard;

a patient's body;

a pedestrian;

a geographical location.

It could then immediately display information about that object.

This creates a distinctive legal problem:

AR can transform the physical environment into a continuously monitored and digitally annotated information space.

Consequently, privacy, property, safety and freedom-of-expression questions can arise simultaneously.

3. Main Categories of AR Governance

3.1 Privacy Governance

AR devices may collect:

camera images;

video;

audio;

location;

eye movements;

facial information;

voice;

body movements;

biometric information;

environmental information;

interaction patterns.

This can trigger GDPR obligations.

Particularly important GDPR provisions include:

Article 5 — principles of processing;

Article 6 — lawful basis;

Article 9 — special-category data;

Articles 12–14 — transparency;

Article 15 — access;

Article 21 — objection;

Article 22 — automated decision-making;

Article 25 — privacy by design;

Article 32 — security;

Article 35 — data-protection impact assessment;

Article 82 — compensation.

4. AR and Biometric Identification

AR systems can potentially identify people in real time.

For example:

A person wearing AR glasses looks at a stranger and receives the person's name, occupation and social-media information.

This can create substantial legal concerns.

The system may process:

facial images;

biometric identifiers;

location information;

social information;

inferred characteristics.

The legal analysis becomes considerably stricter where biometric identification is involved.

5. AR and the Physical Environment

An AR device may scan its surroundings to determine:

walls;

rooms;

streets;

objects;

vehicles;

people;

signs;

businesses.

This raises questions about whether scanning and recording a person's physical environment interferes with:

privacy;

property;

trade secrets;

confidential information;

public security.

A camera pointed at a public street does not automatically create unlawful processing, but the purpose, data type, scale, identification capability and retention are critical.

6. AR and the GDPR

The GDPR applies where AR processing involves personal data and falls within its territorial scope.

A controller must consider:

Lawfulness

What legal basis authorises the processing?

Purpose limitation

Why is the data being collected?

Data minimisation

Does the AR system collect more information than necessary?

Transparency

Does the person know what is happening?

Storage limitation

How long is information retained?

Security

Could AR data be accessed by unauthorised persons?

Data protection by design

Can the system be designed to minimise unnecessary collection?

7. AR and the “Bystander Problem”

One of the most difficult AR issues is the bystander problem.

A smartphone user can generally choose whether to take a photograph.

An AR device, however, may continuously observe the environment.

Consequently, individuals may be recorded without:

knowing that recording is occurring;

knowing who operates the device;

knowing why the information is collected;

knowing where the information is stored.

This creates significant privacy and transparency concerns.

8. AR and Artificial Intelligence

Modern AR systems increasingly use AI for:

object recognition;

facial recognition;

voice recognition;

scene understanding;

translation;

predictive assistance;

personalised advertising;

navigation;

medical analysis;

workplace monitoring.

Therefore, the EU AI Act can become relevant depending upon the particular AI system and use.

The AI Act must be read together with GDPR, product-safety law and fundamental-rights requirements.

9. AR and Consumer Protection

AR can change how products are marketed.

Examples include:

virtual try-ons;

AR advertising;

virtual furniture placement;

AR shopping assistants;

immersive sales interfaces;

personalised advertisements.

Potential problems include:

misleading representations;

hidden advertising;

manipulation;

undisclosed commercial content;

misleading product visualisation;

dark patterns.

Consumer protection therefore becomes an important component of AR governance.

10. AR and Dark Patterns

An AR interface could potentially manipulate users through:

persistent pop-ups;

virtual objects blocking alternative choices;

exaggerated visual effects;

artificial urgency;

location-triggered advertising;

repeated prompts;

hidden commercial content.

The DSA's rules concerning manipulative interface design can become relevant where an AR service falls within its scope.

The broader principle is:

Immersive technology does not remove ordinary consumer-protection obligations.

11. AR Advertising

AR allows advertisements to be placed directly onto physical environments.

For example:

A person looks at a building and sees a digital advertisement attached to it through AR glasses.

Potential issues include:

whether the advertisement is clearly identifiable;

whether location data are used;

whether the advertisement is personalised;

whether sensitive characteristics are used;

whether children receive targeted advertisements;

whether the advertiser has rights to the underlying image;

whether the overlay interferes with another business's property or trademark.

12. AR and Intellectual Property

AR can create complex IP disputes.

An AR application may display:

copyrighted artwork;

trademarks;

architectural works;

sculptures;

photographs;

maps;

logos;

commercial signs.

Questions include:

Is the underlying work protected?

Is the AR reproduction or communication to the public authorised?

Is the trademark being used commercially?

Does the AR overlay create a derivative work?

Does the AR developer have rights to the underlying database or map?

13. AR and Public Spaces

AR applications may digitally modify the appearance of:

streets;

monuments;

public buildings;

museums;

parks;

historical sites.

A legal dispute can therefore arise between:

AR developer;

property owner;

municipality;

cultural institution;

trademark owner;

copyright owner;

user.

The fact that an overlay is digital does not automatically eliminate underlying property or IP rights.

14. AR and Freedom of Expression

AR can also be an expressive medium.

Users might place:

political messages;

artistic objects;

criticism;

historical commentary;

satire;

virtual demonstrations.

European law therefore protects AR expression through:

Article 10 ECHR;

Article 11 Charter.

Restrictions must generally satisfy legality, legitimate aim and proportionality requirements.

15. AR and Property Rights

A particularly interesting question is whether a virtual object placed over physical property interferes with property rights.

There is currently no general European rule saying:

“Digital content placed over property constitutes trespass.”

The legal result depends upon the conduct involved.

For example:

purely virtual placement may raise little property-law concern;

physical installation of AR equipment is different;

commercial exploitation of a building's image can raise IP issues;

persistent digital advertising attached to a specific property can raise contractual or unfair-competition questions.

Therefore, digital overlay should not automatically be equated with physical trespass.

16. AR and Workplace Governance

AR can be used in:

manufacturing;

logistics;

construction;

healthcare;

warehousing;

maintenance;

military contexts;

training.

Employers may use AR to monitor:

employee movements;

productivity;

eye direction;

task performance;

mistakes;

location.

This can create employment-privacy issues.

Relevant principles include:

GDPR;

employment law;

equality law;

occupational safety;

collective labour rights;

Article 8 ECHR.

17. AR and Health Data

Medical AR can involve:

patient records;

anatomical images;

medical scans;

surgical guidance;

biometric measurements.

Health data receive heightened protection under GDPR Article 9.

Where AR becomes a medical device or medical software, the Medical Devices Regulation can become relevant.

This creates potentially overlapping obligations involving:

safety;

clinical performance;

data protection;

cybersecurity;

professional negligence;

product liability.

18. AR Product Safety

AR hardware can cause physical harm.

Examples include:

collision;

impaired vision;

distraction;

incorrect navigation;

overheating;

battery failure;

defective sensors;

inaccurate warnings.

European product-liability law can therefore become relevant.

The modern European product-liability framework increasingly recognises the importance of:

software;

digital components;

connected products;

cybersecurity;

software updates.

19. AR and Autonomous Decision-Making

AR may not merely display information.

It may recommend:

where to walk;

what product to purchase;

which route to take;

which person to avoid;

which workplace task to perform;

what medical action to consider.

Where automated processing produces legally significant consequences, GDPR Article 22 and related transparency provisions may become relevant.

20. AR and Children

AR games and educational systems may collect extensive information about children.

Potential issues include:

location tracking;

behavioural profiling;

advertising;

biometric data;

social interactions;

attention monitoring;

psychological manipulation.

Children's rights receive heightened protection under:

GDPR;

DSA;

Charter Article 24;

ECHR principles.

21. Important European Case Law

1. Google Spain SL, Google Inc. v AEPD and Mario Costeja González

C-131/12, CJEU, 13 May 2014

The CJEU examined the responsibilities of search engines in relation to personal information.

Importance for AR

An AR search system may similarly identify and retrieve information about people or places.

The case supports the broader principle that digital intermediaries processing personal information can have independent data-protection responsibilities.

Relevance: strong analogical authority.

22. Google LLC v CNIL

C-507/17, CJEU, 24 September 2019

The CJEU considered the territorial scope of search-engine delisting obligations.

AR significance

AR applications may operate across multiple European countries.

The case demonstrates the importance of distinguishing:

EU-wide obligations;

national implementation;

territorial scope.

This becomes especially important for globally deployed AR services.

Relevance: analogical but important for cross-border digital governance.

23. Glukhin v Russia

Application No. 11519/20, ECtHR, 4 July 2023

The case concerned the use of facial-recognition technology to identify an individual.

The ECtHR found serious implications for privacy under Article 8 ECHR.

Importance for AR

This is particularly relevant to AR because AR glasses could potentially perform:

facial recognition;

real-time identification;

tracking;

biometric matching.

Glukhin demonstrates that technological identification can constitute a serious interference with privacy.

Relevance: highly significant analogical authority for biometric AR.

24. S. and Marper v United Kingdom

Applications Nos. 30562/04 and 30566/04, ECtHR Grand Chamber, 4 December 2008

The case concerned retention of fingerprints and DNA profiles.

The Court emphasised the privacy implications of systematic retention of biometric information.

AR significance

AR systems can potentially create persistent biometric databases through:

facial recognition;

gait recognition;

iris recognition;

voice identification.

S. and Marper therefore supports strong scrutiny of biometric retention and use.

Relevance: analogical but foundational.

25. Bărbulescu v Romania

Application No. 61496/08, ECtHR Grand Chamber, 5 September 2017

The case concerned workplace monitoring.

The ECtHR established important principles concerning the balance between:

employee privacy;

employer interests;

workplace monitoring.

AR significance

Employers using AR glasses to monitor workers may collect information about:

movements;

communications;

productivity;

physical behaviour.

Bărbulescu provides an important framework for assessing workplace AR surveillance.

Relevance: highly relevant by analogy.

26. López Ribalda and Others v Spain

Applications Nos. 1874/13 and 8567/13, ECtHR Grand Chamber, 17 October 2019

The case concerned covert workplace video surveillance.

The ECtHR examined the proportionality of workplace monitoring under Article 8.

AR significance

AR devices can potentially function as continuous workplace surveillance tools.

The case demonstrates that employer monitoring must be assessed in light of:

necessity;

proportionality;

employee expectations;

safeguards;

purpose.

Relevance: strong analogical authority.

27. Planet49

C-673/17, CJEU, 1 October 2019

The CJEU addressed consent relating to cookies.

AR significance

AR applications can use:

tracking technologies;

behavioural analytics;

advertising identifiers;

location tracking.

Planet49 reinforces the requirement that consent mechanisms satisfy European data-protection standards.

Relevance: direct GDPR/ePrivacy principle; analogical to AR.

28. Meta Platforms Ireland v Bundeskartellamt

C-252/21, CJEU, 4 July 2023

The CJEU examined the relationship between competition law and personal-data processing by a dominant platform.

AR significance

A dominant AR ecosystem might combine data from:

AR glasses;

smartphones;

social networks;

advertising systems;

location services.

The case demonstrates that data practices can have both privacy and competition dimensions.

29. Österreichische Post

C-300/21, CJEU, 4 May 2023

The CJEU considered compensation under GDPR Article 82.

AR significance

If an AR system unlawfully processes personal or biometric information, a claimant may potentially seek compensation.

However, the legal analysis still requires attention to:

infringement;

damage;

causation;

compensability.

A GDPR violation does not mean that every claimant automatically receives damages.

30. SCHUFA

Joined Cases C-26/22 and C-64/22, CJEU, 7 December 2023

The CJEU addressed automated scoring and automated decision-making.

AR significance

AI-powered AR could generate:

identity scores;

risk assessments;

behavioural profiles;

consumer classifications.

SCHUFA is therefore relevant to the governance of AR systems that make consequential decisions based upon automated profiling.

31. Consolidated Case-Law Table

CaseCourtPrincipleAR relevance
Google Spain, C-131/12CJEUSearch-engine data responsibilityAR identification/search
Google v CNIL, C-507/17CJEUTerritorial scope of digital rightsCross-border AR
Glukhin v RussiaECtHRFacial recognition/privacyBiometric AR
S. & Marper v UKECtHRBiometric-data retentionFacial/biometric AR
Bărbulescu v RomaniaECtHRWorkplace monitoringAR workplace surveillance
López Ribalda v SpainECtHRProportionality of surveillanceAR monitoring
Planet49, C-673/17CJEUConsent and trackingAR tracking
Meta Platforms, C-252/21CJEUData + competitionAR ecosystems
Österreichische Post, C-300/21CJEUGDPR compensationAR privacy harm
SCHUFA, C-26/22 & C-64/22CJEUAutomated decision-makingAI-powered AR

32. AR and Data Protection Impact Assessments

A DPIA under GDPR Article 35 may be particularly important where AR involves:

systematic monitoring;

biometric identification;

large-scale location tracking;

vulnerable persons;

health data;

workplace surveillance;

automated profiling.

An AR provider should therefore assess the system before deployment, rather than waiting until privacy litigation occurs.

33. AR Governance and Data Minimisation

A privacy-protective AR system might use:

on-device processing;

short retention periods;

local anonymisation;

automatic blurring;

privacy zones;

prohibition of biometric identification;

encryption;

visible recording indicators.

These are examples of privacy by design, rather than merely post-hoc compliance.

34. AR and Cybersecurity

AR devices can create cybersecurity vulnerabilities because they may combine:

cameras;

microphones;

sensors;

cloud services;

biometric data;

location;

personal accounts.

A compromised AR device could reveal highly sensitive information about:

where a person is;

whom they are looking at;

what they are seeing;

what they are saying;

what environment they occupy.

Security therefore becomes a central component of AR governance.

35. AR and Trade Secrets

Industrial AR may display:

factory layouts;

engineering diagrams;

production processes;

customer information;

confidential instructions.

If AR glasses record or transmit this information to an external cloud provider, trade-secret risks can arise.

The issue may involve:

confidentiality;

cybersecurity;

employee duties;

contractual obligations;

trade-secret legislation.

36. AR and Intellectual Property Infringement

Potential infringement scenarios include:

Copyright

An AR application reproduces protected artwork.

Trademark

An AR advertisement uses another company's logo.

Design rights

An AR system reproduces protected product designs.

Database rights

An AR navigation service copies a protected database.

Architectural works

An AR application digitally reproduces protected structures.

The legal analysis depends upon the particular IP right and the technical manner in which the AR system reproduces or communicates the material.

37. AR and Freedom of Expression

An AR system can also become a medium of political or artistic expression.

For example:

virtual protest signs;

historical reconstructions;

political overlays;

satirical digital objects;

artistic installations.

Any regulatory restriction must therefore consider:

Article 10 ECHR + Article 11 Charter + legitimate regulatory objective + proportionality.

A blanket prohibition on AR overlays would raise significantly different issues from a narrowly tailored prohibition on unlawful biometric surveillance.

38. AR and Competition Law

Competition issues can arise where a dominant AR ecosystem controls:

hardware;

operating systems;

app stores;

AR advertising;

mapping;

user data;

identity systems.

Potential concerns include:

self-preferencing;

exclusion of competing AR applications;

discriminatory access;

tying;

data advantages;

interoperability restrictions.

The DMA may become especially significant where an AR provider falls within the relevant gatekeeper framework.

39. AR and Product Liability

An AR headset could potentially be defective because of:

faulty hardware;

dangerous software;

incorrect navigation;

cybersecurity vulnerability;

defective updates;

inaccurate warnings.

Potential defendants could include:

manufacturer;

software provider;

distributor;

importer;

other responsible economic operators under applicable legislation.

A claimant would still need to establish the relevant legal elements under the applicable product-liability regime.

40. AR and Medical Applications

Medical AR creates particularly sensitive governance questions.

Examples:

surgical navigation;

augmented medical imaging;

rehabilitation;

visual assistance;

diagnosis support.

Potential liability can arise from:

defective software;

inaccurate information;

data breaches;

inadequate warnings;

professional negligence;

improper patient consent.

The Medical Devices Regulation may apply where the AR product falls within the definition of a medical device.

41. AR and Public Authorities

Police and other public authorities could theoretically use AR for:

facial recognition;

navigation;

surveillance;

crowd management;

evidence gathering.

This can engage:

GDPR;

law-enforcement data rules;

ECHR Article 8;

Article 10;

procedural safeguards.

Glukhin is particularly important when assessing biometric surveillance.

42. AR and Children

A governance framework for children's AR should examine:

age verification;

location collection;

advertising;

biometric processing;

social interaction;

content recommendation;

behavioural profiling;

psychological manipulation;

safety;

parental controls.

The best-interest principle concerning children can become particularly important where immersive technology is involved.

43. Potential Civil Claims

AR-related civil litigation could involve:

Privacy claim

Unauthorised recording or biometric identification.

GDPR claim

Unlawful processing or inadequate security.

Defamation/reputation claim

AR system displays false information about a person.

IP claim

Unauthorised reproduction or commercial use of protected material.

Consumer claim

Misleading AR advertising or product representation.

Product-liability claim

Defective headset or AR software causes injury.

Employment claim

Unlawful AR surveillance.

Contract claim

AR service fails to provide promised functionality.

Competition claim

Dominant AR ecosystem excludes competitors.

44. Defences

Potential defences include:

valid consent;

legitimate interests;

statutory authority;

public-interest justification;

necessity;

proportionality;

freedom of expression;

absence of personal data;

anonymisation;

lack of causation;

absence of compensable damage;

technical limitations;

compliance with applicable regulatory requirements.

However, compliance with one regime does not automatically establish compliance with all others.

45. Practical AR Governance Test

A European AR system can be analysed using the following sequence:

Technology → Data → Purpose → Actor → Legal Basis → Risk → Rights → Safety → Harm → Remedy

More specifically:

What does the AR system actually do?

What information does it collect?

Does it identify individuals?

Does it process biometric or health information?

Who controls the processing?

What is the legal basis?

Is consent required?

Is AI involved?

Is the system high-risk?

Is the device safe?

Are consumers adequately informed?

Are children involved?

Are employees monitored?

Are third-party IP rights affected?

Is expression affected?

Has legally recognised harm occurred?

What remedy is available?

46. Direct vs Analogical Case Law

There is currently no mature European case-law category specifically called “Augmented Reality Governance.”

Accordingly, the cases should be classified carefully.

Strongest analogies

Glukhin v Russia — biometric identification.

S. and Marper v UK — biometric data.

Bărbulescu v Romania — workplace monitoring.

López Ribalda v Spain — surveillance.

Google Spain — digital identification/search.

Planet49 — tracking and consent.

Broader digital-governance authorities

Meta Platforms

Österreichische Post

SCHUFA

Google v CNIL

These cases do not decide AR disputes specifically, but their legal principles can apply to AR systems depending on their functionality.

47. Key Principles of European AR Governance

The emerging European approach can be summarised as follows:

AR is not a legally unregulated technological space.

The GDPR can apply to AR-generated personal data.

Biometric AR requires particularly careful legal analysis.

Real-time identification can engage Article 8 ECHR.

Workplace AR surveillance must satisfy privacy and proportionality requirements.

AR advertising remains subject to consumer-protection rules.

AI-powered AR may fall within the AI Act depending on its use and risk category.

AR hardware and software can raise product-safety and liability issues.

AR overlays can implicate copyright, trademarks and other IP rights.

AR expression is protected by European freedom-of-expression principles.

Children require heightened protection.

AR platforms can raise competition and gatekeeper issues.

Digital processing does not automatically override physical-world property and privacy interests.

Compliance with one European regulatory regime does not create immunity under another.

The responsible company cannot generally escape liability merely because an AI system generated the AR output.

48. Conclusion

Augmented Reality Governance in Europe is an emerging cross-disciplinary field rather than a single statutory regime.

Its legal structure is best understood as an intersection of:

GDPR + AI Act + Digital Services Act + Consumer Law + Product Liability + Medical Device Law + Intellectual Property + Employment Law + Competition Law + Cybersecurity + Charter Rights + ECHR

The most important European cases are Google Spain, Google v CNIL, Glukhin, S. and Marper, Bărbulescu, López Ribalda, Planet49, Meta Platforms, Österreichische Post and SCHUFA.

Together, these authorities establish an important principle: AR does not receive a special exemption from ordinary European legal protections merely because information is delivered through an immersive interface. Where AR involves biometric identification, continuous surveillance, behavioural profiling, automated decision-making, targeted advertising, unsafe products or misuse of personal information, existing European legal doctrines can impose substantial obligations.

At the same time, not every AR overlay is unlawful. European law requires a fact-specific assessment of purpose, legal basis, necessity, proportionality, technological function, user expectations, potential harm and the rights of affected third parties.

LEAVE A COMMENT