Neurorights · Cognitive biometrics · Mental privacy

The Mental-State Inference Loophole

The mental privacy debate often starts with brain-computer interfaces, but the deeper problem is stranger. What if the most important threat is not a futuristic machine that reads thoughts perfectly, but ordinary devices that infer attention, emotion, intention, or vulnerability from data that never looks like “brain data” at all?

Mental privacy series

Four connected angles on the same question

These entries separate the technical, inference, policy, and statute-level sides of the same mental-privacy problem.

The obvious door, and the side door

Brain data is the obvious doorway into mental privacy: EEG, fMRI, implanted electrodes, and BCIs that translate attempted speech or movement. I wrote about that doorway in the previous post. This one starts with the side door: if the legal problem is mental privacy, why should the law stop at brain signals?

That question became harder after I read about a Reality Labs paper describing a non-invasive wrist-based neuromotor interface. It decodes muscle signals for gestures and handwriting, not secret thoughts. Still, it shows how intimate human-computer interfaces can be built from signals outside the brain, then translated by models into action (Kaifosh et al., 2025).

That is the phrase that changes the whole debate: mental-state inferences. If the law protects only the raw signal, it may miss the actual harm.

If it is not brain data, why does it feel like a brain-data problem?

Because the privacy risk does not come only from where the signal starts. It comes from what the signal can reveal after analysis.

Magee, Ienca, and Farahany call this broader category cognitive biometrics: neural data, but also eye tracking, heart-rate patterns, voice analysis, facial expression, sleep, movement, typing behavior, and other signals that can be processed to infer cognitive, affective, or conative states. In simpler language: what someone notices, feels, wants, chooses, avoids, or may do next (Magee et al., 2024).

This is why a neural-data-only law can be underinclusive. If a company cannot collect brain data to infer stress, attention, or intention without strong protections, it should not be able to reach a similar inference through eyes, wrists, voice, sleep, or behavior just because the raw signal came from outside the skull.

Is the danger inaccurate inference, or accurate inference?

Both, in different ways.

Chandler helped me see that mental-state inference is not a magic window into a person. It is a chain: data is collected, a model interprets it, a mental state is inferred, and then someone may act on that inference. Each step can go wrong. A brain pattern might fit more than one mental state. A model trained on one group might fail for a particular individual. A prediction might be treated as more objective than the person’s own explanation (Chandler, 2025).

That means bad inferences are dangerous because they can be wrong and still persuasive. But good inferences are also sensitive because they may reveal something real that the person never meant to disclose. Mental privacy has to care about both problems: unreliable guesses that harm people, and reliable guesses that expose them.

Why not wait until the technology is stronger?

This was the counterargument I took seriously. The semantic decoder was constrained: participant-specific training, cooperation, and hours of fMRI data. But limits are not the same as irrelevance. They are a chance to define the problem while the technology is still governable (Tang et al., 2023).

Mecacci and Haselager give a name to the opposite mistake: the delay fallacy. If rules wait for perfect decoding, they arrive late by design. Newer Tang and Huth work on semantic decoding across participants makes that timing question even less comfortable (Mecacci & Haselager, 2019; Tang & Huth, 2025).

Do the first state laws solve it?

They start the conversation. They do not finish it.

Colorado’s 2024 law brought neural data into a biological-data privacy framework, and California’s 2024 SB 1223 added neural data to sensitive personal information under its consumer privacy law. Those are useful proof-of-concept laws: U.S. privacy statutes can be updated for neurotechnology (Colorado General Assembly, 2024; California Legislature, 2024).

The gap is scope. A neural-data definition may not catch non-neural cognitive biometrics, and a consumer privacy law may not reach every school, employer, public agency, research setting, or high-stakes decision. That is the loophole: the law can appear to protect mental privacy while still leaving out the data streams most likely to scale.

Does the U.S. need a brand-new neuroright?

I am less convinced than I was at first.

Istace made the distinction clearer for me. Writing about international human rights law, he argues that neurorights are better derived from existing rights than created as new stand-alone ones: the need for new rights has not been shown, and derived rights give clearer safeguards with fewer political obstacles (Istace, 2025). My own inference for the United States goes one step further: it may not need a sweeping new fundamental right, but it may need a distinct statutory protection built from rights we already recognize, such as privacy, freedom of thought, autonomy, dignity, and mental integrity. A broad symbolic right can sound powerful and still be hard to enforce.

The better question is not, “Can we name a new right?” It is, “Can we write a rule that tells companies, schools, employers, agencies, and courts what they may and may not do with neural data and mental-state inferences?”

What would a smarter rule ask?

A smarter rule would ask about use and risk, not only data category.

It would ask: Does this data, alone or combined with other data, allow an inference about cognition, emotion, intention, attention, vulnerability, or neurological condition? Is the inference being used for healthcare, accessibility, communication, education, advertising, employment, insurance, law enforcement, or another high-stakes purpose? Can the person meaningfully refuse without losing an essential service? Is the model reliable for this person, not just for a group? Will the inference be used to help the person, judge the person, manipulate the person, or sell access to the person?

This is why the introduced federal MIND Act is worth watching even though it is not law. It explicitly includes “other related data” such as biometric, physiological, or behavioral information that can reveal cognitive, emotional, psychological, or neurological states. That is the same conceptual move my sources pushed me toward: the legal trigger should be what the data can do, not only what organ it came from (U.S. Congress, 2025).

Protect the inference, not just the electrode

My answer is becoming more precise: U.S. privacy law should regulate mental-state inferences from both neural data and cognitive biometric data when those inferences are intimate, high-risk, or hard to avoid. The law should not treat every heart-rate chart or gesture signal like a brain scan. That would be too broad and probably unworkable. But it also should not let companies avoid mental privacy rules by collecting everything except the brain signal itself.

The baseline should be clear consent, purpose limits, data minimization, security, deletion rights, restrictions on sale or targeted advertising, and stronger limits in high-stakes contexts like schools, workplaces, healthcare, insurance, and law enforcement. For assistive and medical neurotechnology, the point should be trust, not fear. A person who needs a BCI to communicate should not have to wonder whether the same system is quietly building a profile of their private mental life.

The sentence I keep coming back to is this: mental privacy should protect people from unauthorized access to the mind, including when access happens through inference.

The most powerful question is smaller than “Can machines read minds?”

“Can machines read minds?” is dramatic, but it is not the question I trust most anymore. It makes people imagine a perfect device, then dismiss the whole issue when the device is imperfect.

The better question is quieter: When does a useful guess about a person become private mental information?

That question is harder to laugh off. Recommendation systems guess what we want. Wearables guess how we sleep or recover. XR systems can use gaze and hand movement. Neuromotor interfaces can turn muscle signals into commands. The law has to learn to see the pattern before the pattern sees too much of us (Kaifosh et al., 2025).

Sources used in this post

The sources that shaped this entry were Tang et al. on semantic reconstruction from non-invasive brain recordings; Tang and Huth on semantic decoding across participants; Magee, Ienca, and Farahany on cognitive biometrics and mental privacy; Chandler on mental-state inference from brain data; Mecacci and Haselager on criteria for brain-reading implications; and Istace on new versus derived neurorights.

For recent technology and governance context, I used stable primary or journal links where possible: ClinicalTrials.gov records for Neuralink PRIME and VOICE, Synchron INTENT, and Paradromics Connect-One; Nature Medicine on long-term independent BCI use; Nature on instantaneous voice synthesis; Nature on a non-invasive neuromotor wrist interface; UNESCO’s Recommendation on the Ethics of Neurotechnology; Colorado HB24-1058; California SB 1223; and the introduced federal MIND Act of 2025.

Reference list (APA 7th edition)

Cal. Civ. Code § 1798.140 (2024), as amended by S.B. 1223. https://leginfo.legislature.ca.gov/faces/billNavClient.xhtml?bill_id=202320240SB1223

Card, N. S., Singer-Clark, T., Peracha, H., Iacobacci, C., Hou, X., Wairagkar, M., Fogg, Z., Offenberg, E. C., Hochberg, L. R., Stavisky, S. D., & Brandman, D. M. (2026). Long-term independent use of an intracortical brain–computer interface for speech and cursor control. Nature Medicine, 32(7), 2504–2510. https://doi.org/10.1038/s41591-026-04414-6

Chandler, J. A. (2025). Inferring mental states from brain data: Ethico-legal questions about social uses of brain data. Hastings Center Report, 55(1), 22–32. https://doi.org/10.1002/hast.4958

Colo. Rev. Stat. § 6-1-1303 (2024), as amended by H.B. 24-1058. https://leg.colorado.gov/bills/hb24-1058

Istace, T. (2025). Establishing neurorights: New rights versus derived rights. Journal of Human Rights Practice, 17(1), 121–139. https://doi.org/10.1093/jhuman/huae042

Kaifosh, P., Reardon, T. R., & CTRL-labs at Reality Labs. (2025). A generic non-invasive neuromotor interface for human-computer interaction. Nature, 645(8081), 702–711. https://doi.org/10.1038/s41586-025-09255-w

Magee, P., Ienca, M., & Farahany, N. (2024). Beyond neural data: Cognitive biometrics and mental privacy. Neuron, 112(18), 3017–3028. https://doi.org/10.1016/j.neuron.2024.09.004

Mecacci, G., & Haselager, P. (2019). Identifying criteria for the evaluation of the implications of brain reading for mental privacy. Science and Engineering Ethics, 25(2), 443–461. https://doi.org/10.1007/s11948-017-0003-3

MIND Act of 2025, S. 2925, 119th Cong. (2025). https://www.congress.gov/bill/119th-congress/senate-bill/2925/text

Neuralink. (2025, November 4). VOICE: An early feasibility study of a precise robotically implanted brain-computer interface for communication restoration (Identifier No. NCT07224256). ClinicalTrials.gov. https://clinicaltrials.gov/study/NCT07224256

Neuralink. (2026, January 9). PRIME: An early feasibility study of a precise robotically implanted brain-computer interface for the control of external devices (Identifier No. NCT06429735). ClinicalTrials.gov. https://clinicaltrials.gov/study/NCT06429735

Paradromics. (2026, April 14). Connect-One: Early feasibility study of Connexus brain-computer interface (BCI) to provide human connection through communication (Identifier No. NCT07357428). ClinicalTrials.gov. https://clinicaltrials.gov/study/NCT07357428

Synchron. (2026, May 11). Independence through endovascular neuroprosthetic technology (INTENT): An early feasibility study (Identifier No. NCT07543367). ClinicalTrials.gov. https://clinicaltrials.gov/study/NCT07543367

Tang, J., & Huth, A. G. (2025). Semantic language decoding across participants and stimulus modalities. Current Biology, 35(5), 1023–1032.e6. https://doi.org/10.1016/j.cub.2025.01.024

Tang, J., LeBel, A., Jain, S., & Huth, A. G. (2023). Semantic reconstruction of continuous language from non-invasive brain recordings. Nature Neuroscience, 26(5), 858–866. https://doi.org/10.1038/s41593-023-01304-9

United Nations Educational, Scientific and Cultural Organization. (2025, November 11). Recommendation on the Ethics of Neurotechnology [Adopted by the General Conference at its 43rd session, Samarkand, Uzbekistan]. https://www.unesco.org/en/legal-affairs/recommendation-ethics-neurotechnology

Wairagkar, M., Card, N. S., Singer-Clark, T., Hou, X., Iacobacci, C., Miller, L. M., Hochberg, L. R., Brandman, D. M., & Stavisky, S. D. (2025). An instantaneous voice-synthesis neuroprosthesis. Nature, 644(8075), 145–152. https://doi.org/10.1038/s41586-025-09127-3

← Back to the blog