I hope the situation in China drives home to everyone that the risk/reward tradeoff for facial recognition is too great, that the algorithms running it are impossible to secure against abuse, and that it should not be permitted in mass-market consumer electronics devices
In this case you would want to regulate both the device capabilities and data collection (since face AI can be done server-side with a vanilla camera)