A face is two things at once. To another person it is expression, mood, recognition, the small movements that make conversation possible. To a camera running facial-recognition software, it is a set of measurable distances: the space between the eyes, the angle of the jaw, the proportions of nose and mouth. Dutch designer Jip van Leeuwenstein built a mask that tries to separate those two readings.

The object looks almost like a clear visor or a curved lens held in front of the face. It does not hide the wearer. A person standing nearby can still see eyes, smile, frown, the ordinary signals of human contact. Yet the same curved surface bends and warps the biometric landmarks that algorithms rely on. The result is a deliberate mismatch: readable to people, difficult for machines.
A student project that keeps returning
Van Leeuwenstein developed the mask while studying at the Utrecht School of the Arts as part of a broader investigation he called Surveillance Exclusion. The premise was straightforward. Cameras and databases promise safety and convenience, yet they also generate permanent records of movement, preference and identity. Advertising systems pay for real-time access to those records. The question the project asked was practical: is it possible to remain legible to other humans while becoming less legible to automated systems?
The mask’s form is the answer he arrived at. Because the material is transparent, social interaction continues. Because the surface is curved like a lens, the geometric relationships that facial-recognition models expect are altered. The software may still detect a face, but the specific signature it extracts is distorted enough to reduce reliable matching.
How recognition systems see

Most contemporary facial-recognition pipelines begin by locating key points. Eyes, nose tip, mouth corners, chin contour. Once those points are mapped, the system computes distances and ratios that are relatively stable across changes in lighting or expression. The resulting template can be compared against a database. Accuracy depends on the quality of that geometric map.
A physical object that systematically shifts those points interferes with the pipeline at an early stage. The mask does not claim to defeat every system under every condition. Newer models trained on wider data, or systems that combine face data with gait, clothing or other signals, may still succeed. The design is better understood as a provocation and a proof of concept than as a finished product ready for daily use.
Visibility without surrender
What makes the project linger in public conversation is the choice not to erase the face. Many earlier privacy garments and masks worked by covering or abstracting the head entirely. They protected against machines by also protecting against people. Van Leeuwenstein’s lens takes the opposite route. It preserves the social face while attacking the computational one. In doing so, it stages a quiet argument: that the right to be seen by other humans and the right not to be automatically cataloged by machines need not cancel each other out.
The distinction matters as recognition technology moves from specialized security settings into everyday infrastructure. Airports, stadiums, retail spaces, workplaces and city streets increasingly treat the face as a convenient identifier. Once a face is linked to a persistent identity, the same link can be used for access control, targeted messaging, behavioral scoring or retrospective search. The mask asks whether individuals should retain any practical means of interrupting that chain.
Limits and honesty

The project is candid about its origins. It began as a design exercise, not a commercial product. Independent testing against current commercial systems is limited. Claims that the mask works “from all angles” or against every algorithm should be treated with caution. Facial-recognition research advances quickly, and adversarial examples that succeed in one generation of models often fail against the next.
Still, the underlying design insight remains useful. Physical intervention at the level of the optical signal is one of the few tools available to ordinary people who do not control the cameras or the databases. Software-based defenses, such as adversarial patterns printed on clothing or makeup, face similar problems of obsolescence.
The mask’s transparency keeps the conversation focused on a human value that purely technical solutions sometimes overlook: the ability to meet another person’s eyes without intermediate translation by a machine.
A wider design conversation
Surveillance Exclusion belongs to a growing family of critical design work that treats privacy as a material problem rather than solely a legal or policy one. Designers have experimented with reflective fabrics, infrared-emitting accessories, patterned textiles that confuse classifiers, and architectural screens that break line-of-sight for cameras. Each intervention has its own strengths and failure modes. What they share is a refusal to accept that the only available responses are either full compliance or total withdrawal from public space.
Van Leeuwenstein’s contribution is notable for its restraint. The mask does not shout its purpose. It does not turn the wearer into a spectacle of resistance. It simply inserts a layer of optical complexity between the face and the sensor. In an environment where sensors are becoming denser and cheaper, that small layer becomes a statement about agency.
The question that remains
Years after its first appearance, the project continues to circulate because the conditions that produced it have not eased. Databases grow. Resolution improves. Matching algorithms become more robust. At the same time, public awareness of biometric tracking has increased, and with it a desire for practical means of selective visibility.
The transparent mask does not solve the larger problem of surveillance infrastructure. It does not replace regulation, oversight or public debate. What it does offer is a concrete object that makes the stakes visible. You can look at someone wearing it and still know who they are. A machine looking at the same person may not. That difference is small, temporary and imperfect. It is also a reminder that identity, once fully captured by systems we do not control, becomes harder to reclaim.
The mask keeps resurfacing because the question behind it keeps growing more urgent: how much of our face should belong to the machines that watch us, and how much should remain, for as long as possible, only ours to give.