The moment the question stopped feeling imaginary
Brain-computer interfaces are usually described in two extreme ways. One version is miraculous: a paralyzed person moves a cursor, controls a device, or communicates again. The other version is frightening: a machine steals thoughts directly from the brain. Neither version is enough by itself.
The medical side is real and genuinely hopeful. Neuralink’s registered PRIME and VOICE studies point toward device control and speech restoration research. Synchron’s INTENT trial is testing an implanted BCI for digital-device control. Precision Neuroscience’s Layer 7-T FDA record shows a high-density cortical electrode cleared for temporary recording, monitoring, and stimulation. Paradromics’ registered Connexus BCI study adds another speech-restoration pathway. Speech BCIs are also becoming more impressive: recent peer-reviewed systems have shown long-term at-home use and fast text entry, and brain-to-voice synthesis.
But the privacy side is real too. If a device can help translate intention into action, it is also touching information very close to personhood. That does not mean every BCI is dangerous. It means the law has to be precise enough to protect people without scaring away the technologies that could give people independence back.
Can a brain decoder actually read a mind?
The most honest answer is: partly, sometimes, and under very specific conditions. That is why the 2023 study by Tang and colleagues interested me so much. They used fMRI data and a language model to reconstruct the meaning of stories people heard, imagined, or watched silently. The decoder did not reproduce every word perfectly. It often captured the gist.
The limits matter. The decoder was trained for each participant, using many hours of that person's own brain responses. It did not transfer well from one person to another. People could also interfere with decoding by deliberately thinking about something else. So this was not a universal mind-reading machine. It was a careful experiment showing that meaning can be reconstructed from brain activity when the person and the system are closely matched.
That makes the result more interesting, not less. A limited technology can still reveal a new legal problem. Mental privacy should not begin only at the moment a device becomes magical. It should begin when intimate mental content becomes technically collectible, interpretable, or inferable.
If the technology is limited, why not wait?
Because the timeline is moving faster than the law usually does. Implanted BCIs are no longer only diagrams in ethics papers. Clinical trials are testing them in people with paralysis, severe speech impairment, blindness, ALS, spinal cord injury, and brainstem stroke. Some systems are invasive. Some are implanted through blood vessels. Some are placed on the brain surface. Each design has different risks, but they all point in the same direction: neural data is becoming more useful outside the lab.
Non-invasive decoding is also improving. Newer work using MEG and EEG has tried to decode open-vocabulary typed sentences from brain activity, with MEG performing far better than EEG. That is not a consumer headset reading private thoughts across a room. But it is a reminder that "non-invasive" does not automatically mean "not sensitive."
The answer, then, is not panic. Waiting for perfect mind reading would be like waiting for a data breach before deciding passwords matter. The better moment to write boundaries is while the technology is still forming, when rules can protect patients, guide companies, and leave room for medical progress.
Is mental privacy only about neural data?
This is where Magee, Ienca, and Farahany changed the way I thought about the problem. A law that protects only brain signals may sound strong, but it can miss the point. Mental states can be inferred from many kinds of data: eye movements, facial expressions, heart rate, sleep patterns, typing behavior, app use, location, attention, and even the way someone pauses before making a choice.
That is why they use the idea of cognitive biometrics. The important issue is not whether data came directly from a neuron. The important issue is whether the data can reveal something intimate about cognition, emotion, preference, intention, or vulnerability.
This is already becoming ordinary. Apple Vision Pro uses eye and hand information for interaction and says pre-interaction gaze is processed privately. Meta's Neural Band uses wrist muscle signals to turn subtle gestures into commands. These are not mind-reading devices. But they normalize interfaces built around attention, intention, and bodily signals. Once those signals become valuable, the privacy question cannot stay locked inside hospitals and research labs.
Do we need brand-new neurorights?
My first instinct was yes. If neurotechnology is new, maybe the rights should be new too. But Istace's argument for derived rights made me slow down. The point is not that mental privacy is unimportant. The point is that we may already have legal and moral roots for protecting it: privacy, freedom of thought, mental integrity, autonomy, and human dignity.
A brand-new right can be powerful symbolically, but it can also become vague. What exactly counts as a violation? Which technologies are covered? Would a broad neuroright accidentally block beneficial medical research or assistive devices? Those questions are not excuses to do nothing. They are reasons to write carefully.
So my answer is: the United States should not rush to declare a sweeping new fundamental neuroright. It should codify a distinct but limited statutory right to mental privacy, built from existing principles and designed for real technologies. That gives the law a sharper target.
What should the law actually protect?
It should protect neural data, but not stop there. A mental privacy statute should treat neural data as presumptively sensitive and should also regulate high-risk cognitive inferences from non-neural data when those inferences reveal intimate mental states. In plain language: if a company cannot collect my brain data without serious protections, it should not be able to quietly infer the same kind of information from my eyes, wrist, sleep, behavior, or attention patterns without serious protections either.
The core protections should be boring in the best possible way: opt-in consent, purpose limits, data minimization, strong security, access and deletion rights, and extra caution around advertising, employment, education, insurance, and law enforcement. Sensitive raw data should stay on-device when possible, or be protected through strong encryption. Consent should be separate, clear, and revocable, not hidden inside a giant privacy policy that nobody can realistically understand.
This is also where UNESCO's 2025 Recommendation on the Ethics of Neurotechnology is useful. It recognizes mental privacy, neural data, indirect neural data, and non-neural data that can support cognitive or emotional inferences. That matters because it shows the global conversation is already moving beyond the simple question, "Is this brain data?" The better question is, "What can this data reveal about the person?"
The first laws are important, but narrow
Some U.S. states have already begun. Colorado expanded its privacy law to cover biological data, including neural properties. California added neural data to the category of sensitive personal information under its consumer privacy law. These are meaningful steps because they recognize that brain-related information deserves special care.
But they also show the gap. A law focused only on neural data may miss cognitive biometrics collected by consumer devices. A law focused only on consumer privacy may not fully address schools, workplaces, policing, insurance, medical research, or future assistive technologies. State-by-state protection also creates uneven rules for data that can move anywhere.
That is why I keep coming back to a federal statute. Not a dramatic law that treats every wellness wearable like a brain scanner. Not a weak law that protects only implanted electrodes. Something more exact: a mental privacy floor for neural data and for inferences that can expose intimate mental states.
Protect the mind without freezing the science
After reading these sources, my answer to the research question is yes, but carefully: the United States should codify a distinct legal right to mental privacy. It should be statutory, limited, and practical. It should not depend on proving that a device can read thoughts perfectly. It should depend on whether data collection or analysis can reveal private mental life in a way the person did not meaningfully choose.
The law should make three promises. First, neural data is sensitive by default. Second, cognitive inferences from non-neural data can also be sensitive when they reveal intimate mental states. Third, people should not have to give up mental privacy to use ordinary technology, go to school, get a job, receive healthcare, or participate in public life.
The best version of mental privacy law would not be anti-BCI. It would be pro-trust. People are more likely to accept powerful technology when the boundaries are clear. That is especially important for assistive neurotechnology, where the goal is not surveillance. The goal is communication, movement, independence, and dignity.
The scary part is not the science-fiction version
I used to think the hardest mental privacy problem would be the dramatic one: a machine that reads secret thoughts exactly. Now I think the more realistic problem is quieter. It is a world where many devices each collect small signals, each signal feels harmless, and the combined picture becomes deeply personal.
That is why the question matters now. Tang et al. show that decoding meaning is possible but constrained. Magee, Ienca, and Farahany show that the privacy problem expands through cognitive biometrics. Istace shows that rights can be derived carefully instead of invented wildly. Recent BCI developments show that the technology is becoming practical enough to deserve rules. Together, they point to the same conclusion: mental privacy should begin before the mind becomes easy to decode.
For me, the most thought-provoking question is not "Can machines read minds?" It is this: if technology can make useful guesses about what we intend, attend to, feel, or prefer, who gets to decide when those guesses are allowed?
What I read while thinking this through
The three sources that shaped the argument were Tang et al.'s 2023 study on semantic decoding from non-invasive brain recordings, Magee, Ienca, and Farahany's 2024 article on cognitive biometrics and mental privacy, and Istace's 2025 article comparing new neurorights with rights derived from existing human-rights principles.
For the technology and policy context, I leaned on sources that should be more stable over time: ClinicalTrials.gov records for Neuralink PRIME and VOICE, Synchron INTENT, and Paradromics Connexus BCI; the FDA’s 510(k) record for Precision Neuroscience’s Layer 7-T; recent speech-BCI research in Nature Medicine and Nature; non-invasive decoding work in Nature Neuroscience; privacy information from Apple Vision Pro; Meta’s Neural Band announcement; UNESCO’s Recommendation on the Ethics of Neurotechnology; California’s SB 1223; and Colorado’s HB24-1058.