Join our Newsletter — 33% off our NHI Course
Home› Glossary› Cyber Security› Augmented Reality
Cyber Security

Augmented Reality

← Back to Glossary
By NHI Mgmt Group Updated September 29, 2026 Domain: Cyber Security

Augmented reality overlays digital information onto the physical world through a mobile device or headset. In enterprise apps, it can support troubleshooting, remote assistance, and guided work, but it also introduces camera access, live data sharing, and new privacy and integrity risks.

What Augmented Reality Means for Security and Governance

Augmented reality is not just a visual interface. It is a live computing layer that can capture the physical environment, stream sensor and camera data, and combine that context with remote systems, so security teams have to treat it as both an application surface and a data-handling environment.

The security implication is that AR often sits at the intersection of device trust, data protection, and human workflow. When the overlay is used for maintenance, remote assistance, or guided work, the same session may expose location, workspace imagery, equipment details, and operational instructions.

Data Exposure and Privacy Implications

AR can reveal far more than the user intends because the device is continuously interpreting the surrounding environment. That means the privacy question is not limited to what appears on screen, it also includes what the device sees, records, transmits, or stores.

This matters in enterprise settings where AR is used around production lines, offices, labs, or sensitive customer environments. Camera feeds, audio, annotations, and session metadata may all become part of the trust boundary, especially when the experience depends on cloud services or remote collaboration. Guidance from the EU General Data Protection Regulation (GDPR) is often relevant when AR captures identifiable people or other personal data, because the data protection, minimisation, and security principles map directly to those capture and sharing flows.

Integrity, Trust, and Operational Failure Modes

AR has integrity risks because the user is expected to act on the overlay as if it were authoritative. If instructions, labels, object recognition, or remote annotations are wrong, stale, or manipulated, the result can be unsafe action rather than a simple display error.

This is why AR systems need reliable input validation, authenticated content delivery, and careful separation between what the device observes and what the platform asserts. A compromised overlay can mislead technicians, alter work instructions, or create a false sense of verification in environments where the user is relying on the display for real-world decisions. Controls aligned with NIST SP 800-53 Rev 5 Security and Privacy Controls are relevant here because AR environments benefit from access control, system integrity, auditability, and configuration management discipline.

Deployment Patterns and Control Boundaries

Enterprise AR deployments usually depend on more than the headset or mobile app. They also rely on mobile device management, network access, identity and session controls, content delivery services, and integration with asset, workflow, or remote support platforms.

That dependency chain creates a wider attack surface than many teams expect. If the device, companion app, or back-end service is weakly configured, the exposure can extend to shared workspaces, internal documentation, and operational systems. For that reason, AR should be designed with explicit trust boundaries, least-privilege access to live data, and defensive assumptions about what the device can observe. Zero-trust guidance such as NIST SP 800-207 Zero Trust Architecture is a useful reference point when defining those boundaries.

Risk and Threat Considerations

AR systems create a concentrated exposure point because they combine perception, display, and network access in one workflow. The most important risks are unauthorized viewing of sensitive surroundings, leakage through recorded sessions, and user reliance on manipulated or stale overlay content.

Failure mechanism: An attacker, misconfiguration, or weak trust model can cause the device to capture more than intended, transmit it to unauthorised destinations, or display deceptive instructions that the user treats as operationally correct.

Impact: The result can be privacy loss, disclosure of physical-site information, unsafe work execution, and broader compromise if AR access is connected to internal systems or remote support channels.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

NIST SP 800-53 Rev 5 and NIST Zero Trust (SP 800-207) set the technical controls, while GDPR defines the regulatory obligations.

FrameworkControl / ReferenceRelevance
GDPRArt.25 — Data protection by design and by defaultAR captures and shares personal data from the physical environment.
Art.32 — Security of processingAR sessions can transmit sensitive visual and environmental data.
Recommendation — Minimise capture, retention, and sharing of AR-derived personal data by design. Protect AR processing with appropriate confidentiality, integrity, and access controls.
NIST SP 800-53 Rev 5SI-3 — Malicious Code ProtectionAR apps and companion services need protection against tampered content and payloads.
AC-6 — Least PrivilegeAR systems should limit access to cameras, overlays, and live enterprise data.
AU-2 — Event LoggingAR workflows need traceability for session access, content delivery, and remote support.
Recommendation — Scan and block malicious AR application content and delivered assets. Restrict AR app and service access to only the data and functions required. Log AR session access and content changes for later review.
NIST Zero Trust (SP 800-207)000 — Zero Trust ArchitectureAR depends on device trust, remote services, and constrained access paths.
Recommendation — Apply zero-trust verification before granting AR sessions access to sensitive resources.

Practitioner Guidance

What to watch for: Treat AR as a mixed privacy and integrity workload, not as a simple endpoint accessory. The most important design question is whether the system can safely separate ambient observation, live guidance, and stored artefacts without overexposing any of them.

Practitioner takeaway: If AR is allowed in production or sensitive environments, its security model should be reviewed like a frontline workflow system, because the device is both a sensor and a decision aid.

Deepen Your Knowledge

Sign up to our weekly newsletter — get 33% off our NHI Foundation Level Course

    NHIMG Editorial Note
    Reviewed and updated by the NHIMG editorial team on September 29, 2026.
    NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org