October 2026
Four connected angles on the same question
These entries separate the technical, inference, policy, and statute-level sides of the same mental-privacy problem.
The legal trigger should be functional, not anatomical.
A neural-data statute sounds strong because it protects data from the brain. But the political problem is not only where a signal starts. It is what an institution can infer from it. Consumer technologies can learn from eye movement, facial expression, heart rate, breathing, sleep, app behavior, location, and patterns of attention. Those signals may not be neural data, but they can still support mental-state inferences.
That is why Magee, Ienca, and Farahany’s argument about cognitive biometrics matters so much. They show that mental privacy cannot be limited to raw brain signals when non-neural data can also reveal cognitive, affective, or conative states (Magee et al., 2024). The law should therefore ask what the data is used to infer, not only whether it came from an electrode.
Imperfect technology still creates a governance problem.
The strongest technical studies do not prove that machines can read minds perfectly. Tang et al. reconstructed the gist of language from fMRI recordings, but the system required participant-specific training and cooperation (Tang et al., 2023). Chandler also emphasizes that mental-state inference is interpretive: a model turns data into a claim about a person, and that claim can be wrong, incomplete, or misused (Chandler, 2025).
That does not make regulation premature. It makes precision necessary. If an inference is wrong, it can still harm someone when used in school, employment, insurance, advertising, policing, or healthcare. If an inference is right, it can expose something intimate that the person never chose to disclose. Waiting for perfect decoding would repeat the delay fallacy: treating technical imperfection as a reason to postpone rules until the rules arrive too late (Mecacci & Haselager, 2019).
The first U.S. laws start the conversation but leave a patchwork.
Colorado and California show that state privacy law can move faster than Congress. Colorado’s HB24-1058 updated its privacy law to address neural data, and California’s SB 1223 added neural data to sensitive personal information (Colorado General Assembly, 2024; California Legislature, 2024). Those reforms matter because they make neuroprivacy legally visible.
The weakness is scope. Montana’s neurotechnology-data language excludes several bodily measures, including pupil dilation, motor activity, and breathing rate, and Connecticut’s enacted law (Public Act 25-113, in force since July 1, 2026) covers only data that measure central nervous system activity (Montana Code; Connecticut General Assembly, 2025). If the law protects only neural signals, a company can avoid the category by inferring mental states from eyes, muscles, breath, behavior, or attention instead.
Modify, create, and eliminate.
The statutory design I would defend has three parts. First, existing state language should be modified so protection does not turn on a narrow identification-purpose frame when the real privacy harm is cognitive inference. Second, Congress should create a federal definition centered on high-risk mental-state inference rather than on the sensor alone. Third, non-neural carve-outs should be eliminated when they allow intimate mental inferences from pupil dilation, movement, breathing, biometric patterns, or behavioral data.
This is not a proposal to treat every fitness metric or gesture signal like a brain scan. The rule should be risk-sensitive. It should become stronger when the inference concerns cognition, emotion, attention, intention, neurological condition, psychological state, or vulnerability, and stronger still when the inference is used in education, work, insurance, healthcare, advertising, law enforcement, or access to essential services.
A national floor is more coherent than four definitions of the mind.
State experimentation is useful, but mental-state data travels across platforms and state borders. A state-by-state model can leave people with different protections depending on where they live, where a company is located, or which statute happens to define the data stream. That is a political design problem, not only a privacy problem.
The introduced MIND Act is a useful signal because it recognizes neural data and related biometric, physiological, and behavioral data that may reveal cognitive, emotional, psychological, or neurological states (U.S. Congress, 2025). But a study bill is not a binding privacy rule. A federal statute could set a minimum floor while allowing states to go beyond it.
The problem falls between healthcare, devices, and consumer protection.
HIPAA is powerful in covered healthcare relationships, but HHS explains that the HIPAA rules apply to covered entities and business associates, not every private business or public agency that might handle sensitive data (HHS, n.d.). FDA authority is tied to medical devices, and federal law excludes some software functions from the device definition, including certain healthy-lifestyle software functions unrelated to disease (Federal Food, Drug, and Cosmetic Act § 520(o), 2018). The FTC can police unfair or deceptive practices, but enforcement after a violation is different from a clear rule that tells actors what sensitive mental-state inference requires (FTC, n.d.).
That is why I would regulate conduct rather than hardware. The question should not be only whether a product is implanted, clinical, or explicitly neural. The question should be whether an actor is collecting or using data to infer a sensitive mental state, and whether the person has meaningful consent, purpose limits, security, deletion rights, and protection from high-stakes misuse.
Reliability and jurisdiction are part of the privacy problem.
The newer governmental lens sharpened something my earlier posts only touched: reliability is political. Barrett and colleagues warn that facial movements alone do not reliably identify specific emotions across people and contexts (Barrett et al., 2019). A bad inference can still become an official-looking score, flag, or decision, so a mental-privacy rule should ask whether a system is reliable enough for the person and setting where it is used.
Jurisdiction is the second gap. The introduced MIND Act is useful as a legislative signal: as introduced, it would direct study and federal-agency guidance rather than create a binding private-sector rule (U.S. Congress, 2025). HIPAA, FDA, and FTC authority each cover only part of the problem. That leaves a sensitive inference floating between agencies when it is not clearly healthcare, not clearly a regulated medical device, and not already framed as deception or unfairness.
Mecacci and Haselager’s criteria of concealability and enforceability help make that gap concrete: how hidden is the method, and how easily can it be used against a person’s will (Mecacci & Haselager, 2019)? The sharper policy question is not only “Is this neural data?” It is: who can stop a school, employer, agency, platform, or insurer from acting on a mental-state inference when the source signal sits outside the neat boxes of health, device, and consumer law?
A statutory right is clearer than a slogan.
The constitutional route is tempting because mental privacy feels fundamental. Tomain argues that the Ninth Amendment already protects freedom of thought, including mental privacy, but he concedes that using it against private companies is “a much harder case” under the state action doctrine (Tomain, 2025). Istace, writing about international human rights law, also prefers to derive neurorights from rights that already exist rather than create new ones (Istace, 2025). So both build on existing rights, and neither gives a consumer a claim against a company today. That is why I think statutory duties matter: a statute can turn privacy, autonomy, mental integrity, and freedom of thought into concrete duties.
A statute also reaches private actors more directly. Many of the likely risks come from companies, platforms, employers, schools, insurers, and data brokers, not only the state. That makes the legal design less about inventing a dramatic new category and more about writing enforceable rules for identifiable conduct.
Other frameworks already look past raw signals to information and use context.
Chile’s neurorights law protects brain activity and the information that comes from it, which matters because the protected interest reaches that information, not only raw signals (Chile Ley 21.383). In Girardi v. Emotiv Inc., Chile’s Supreme Court addressed an EEG headset dispute and ordered stored data about the user deleted (Corte Suprema de Chile, 2023). UNESCO’s Recommendation on the Ethics of Neurotechnology also frames neurotechnology governance around dignity, autonomy, mental privacy, neural data, indirect data, and related risks (UNESCO, 2025).
The European Union’s AI Act is relevant for a different reason: it restricts certain emotion-recognition uses in workplace and education settings (European Union, 2024). That points to the same design lesson. Mental privacy law can be structured around use and risk, not only around the physical device.
Protect the mind without freezing useful neurotechnology.
My conclusion is deliberately limited. The United States should codify statutory protection for high-risk mental-state inferences drawn from both neural and non-neural data. The law should not ban cognitive interfaces or treat every body signal as dangerous. It should require stronger consent, purpose limitation, minimization, security, deletion rights, limits on sale and targeted advertising, and special safeguards in high-stakes settings.
That approach is not anti-BCI. It is pro-trust. Assistive neurotechnology depends on people believing that systems built to restore communication, movement, independence, or dignity will not quietly become surveillance infrastructure. A law that follows the inference, not just the sensor, is the cleaner way to protect that trust.
Sources used in this policy note
The scholarly sources behind the argument are Magee, Ienca, and Farahany (2024), Beyond neural data: Cognitive biometrics and mental privacy; Tang et al. (2023), Semantic reconstruction of continuous language from non-invasive brain recordings; Chandler (2025), Inferring Mental States from Brain Data; Barrett et al. (2019), Emotional Expressions Reconsidered; Mecacci and Haselager (2019), Identifying criteria for the evaluation of the implications of brain reading for mental privacy; Istace (2025), Establishing Neurorights: New Rights versus Derived Rights; and Tomain (2025), Ninth Amendment Neurorights.
The legal and policy sources are Colorado HB24-1058, California SB 1223, Montana Code neurotechnology-data language, Connecticut Public Act 25-113 (SB 1295), the introduced federal MIND Act of 2025, HHS HIPAA covered-entity guidance, Federal Food, Drug, and Cosmetic Act § 520(o), 21 U.S.C. § 360j(o), the FTC enforcement-authority overview, Chile Ley 21.383, the Chilean Supreme Court’s Girardi v. Emotiv Inc. decision, the EU AI Act, and UNESCO’s Recommendation on the Ethics of Neurotechnology.
Reference list (APA 7th edition)
Barrett, L. F., Adolphs, R., Marsella, S., Martinez, A. M., & Pollak, S. D. (2019). Emotional expressions reconsidered: Challenges to inferring emotion from human facial movements. Psychological Science in the Public Interest, 20(1), 1–68. https://doi.org/10.1177/1529100619832930
Cal. Civ. Code § 1798.140 (2024), as amended by S.B. 1223. https://leginfo.legislature.ca.gov/faces/billNavClient.xhtml?bill_id=202320240SB1223
Chandler, J. A. (2025). Inferring mental states from brain data: Ethico-legal questions about social uses of brain data. Hastings Center Report, 55(1), 22–32. https://doi.org/10.1002/hast.4958
Chile. (2021, October 25). Ley Núm. 21.383: Modifica la Carta Fundamental, para establecer el desarrollo científico y tecnológico al servicio de las personas. Diario Oficial de la República de Chile. https://www.bcn.cl/leychile/navegar?idNorma=1166983
Colo. Rev. Stat. § 6-1-1303 (2024), as amended by H.B. 24-1058. https://leg.colorado.gov/bills/hb24-1058
Conn. S.B. 1295, Pub. Act No. 25-113 (2025). https://www.cga.ct.gov/2025/ACT/PA/PDF/2025PA-00113-R00SB-01295-PA.PDF
Corte Suprema de Chile. (2023, August 9). Girardi v. Emotiv Inc., Rol No. 105.065-2023. https://derechocienciaytecnologia.uc.cl/wp-content/uploads/2024/02/CS-105065-2023.pdf
Federal Food, Drug, and Cosmetic Act § 520(o), 21 U.S.C. § 360j(o) (2018). https://uscode.house.gov/view.xhtml?edition=prelim&num=0&req=granuleid%3AUSC-prelim-title21-section360j
Federal Trade Commission. (2025, July). A brief overview of the Federal Trade Commission’s investigative, law enforcement, and rulemaking authority. https://www.ftc.gov/about-ftc/mission/enforcement-authority
Istace, T. (2025). Establishing neurorights: New rights versus derived rights. Journal of Human Rights Practice, 17(1), 121–139. https://doi.org/10.1093/jhuman/huae042
Magee, P., Ienca, M., & Farahany, N. (2024). Beyond neural data: Cognitive biometrics and mental privacy. Neuron, 112(18), 3017–3028. https://doi.org/10.1016/j.neuron.2024.09.004
Mecacci, G., & Haselager, P. (2019). Identifying criteria for the evaluation of the implications of brain reading for mental privacy. Science and Engineering Ethics, 25(2), 443–461. https://doi.org/10.1007/s11948-017-0003-3
MIND Act of 2025, S. 2925, 119th Cong. (2025). https://www.congress.gov/bill/119th-congress/senate-bill/2925/text
Mont. Code Ann. § 30-23-102 (2025). https://mca.legmt.gov/bills/mca/title_0300/chapter_0230/part_0010/section_0020/0300-0230-0010-0020.html
Regulation (EU) 2024/1689 of the European Parliament and of the Council of 13 June 2024 (Artificial Intelligence Act), arts. 3(39), 5(1)(f). https://eur-lex.europa.eu/legal-content/EN/ALL/?uri=CELEX%3A32024R1689
Tang, J., LeBel, A., Jain, S., & Huth, A. G. (2023). Semantic reconstruction of continuous language from non-invasive brain recordings. Nature Neuroscience, 26(5), 858–866. https://doi.org/10.1038/s41593-023-01304-9
Tomain, J. A. (2025). Ninth Amendment neurorights. Indiana Law Journal, 100(4), 1959–1986. https://www.repository.law.indiana.edu/ilj/vol100/iss4/15/
United Nations Educational, Scientific and Cultural Organization. (2025). Recommendation on the ethics of neurotechnology. https://www.unesco.org/en/node/86248
U.S. Department of Health and Human Services. (n.d.). Covered entities and business associates. https://www.hhs.gov/hipaa/for-professionals/covered-entities/index.html