One device, several destinations
In March, Rokid shipped an update integrating four large language models into a single platform on its glasses. Auganix reported how the update lets a wearer toggle between providers, including Gemini, ChatGPT, DeepSeek and Qwen, on a device-to-cloud architecture.
As engineering, that is a sensible answer to a real problem. Different models are better at different languages, latency varies by region, and locking a user to one vendor ages badly. We have no complaint with the product decision. The consequence for everyone else in the frame is that the processor handling an image of their face is chosen by a stranger, from a list, moments before the capture happens.
This is a different problem from changing capability
A device that gains a feature through firmware changes what it can do, which is its own difficulty. This one is narrower and harder to argue away. The capability stays constant while the destination moves, and destination is the part that carries legal weight.
Data protection regimes attach obligations to where processing occurs and who performs it. A bystander in Ottawa whose image is sent for inference has a different set of rights depending on which entry the wearer picked, and no way to learn which one that was. Selecting a provider is presented as a preference, in the same interface tone as picking a voice or a language, and it decides the jurisdiction of somebody else's face.
Disclosure belongs at capture, not in settings
We would put the provider in the capture moment itself. If a device announces anything to the people around it, the announcement should name where the material is going, and any device that cannot say so plainly should not be sending images off itself at all.
The wider point is that on-device processing has been treated as a premium feature, something a buyer might pay extra for. For the person in front of the lens it is the only version of the arrangement with a stable answer, and they never get a vote on whether it was purchased.