In 2023, the Chilean Supreme Court issued a ruling that most legal scholars had not anticipated: it ordered a neurotechnology company to delete the brain data of a former senator, finding that the collection of neural signals without explicit consent violated a constitutional right that Chile had enshrined just two years earlier. The case — Girardi v. Emotiv Inc. — was the world's first judicial enforcement of what advocates call "neurorights": the legal protection of mental privacy, cognitive liberty, and the integrity of the human mind.
The ruling was remarkable not just for its outcome but for what it revealed about the pace of technological change relative to legal adaptation. Emotiv, the company at the centre of the case, makes consumer-grade EEG headsets — devices that measure electrical activity on the surface of the scalp and are marketed for applications ranging from meditation to gaming. The technology is not science fiction; it is available on Amazon. And yet the legal frameworks governing what companies can do with the data these devices collect were, until Chile acted, essentially non-existent.
By 2026, the neurotechnology market is projected to reach approximately $19.84 billion, driven by the convergence of AI-native neural decoding, miniaturised sensor technology, and the clinical validation of invasive brain-computer interfaces (BCIs) for conditions ranging from paralysis to treatment-resistant depression. The governance frameworks attempting to keep pace with this expansion are fragmented, inconsistent, and — in most jurisdictions — still embryonic.
The Technology Landscape: From Consumer EEG to Invasive BCIs
Understanding the governance challenge requires understanding the technology. The BCI ecosystem in 2026 spans three distinct modalities, each with different risk profiles and different regulatory implications.
At the consumer end of the spectrum, non-invasive devices — EEG headsets, fNIRS sensors, and consumer-grade neurofeedback systems — measure brain activity from outside the skull. These devices have reached sufficient resolution to be used for attention monitoring, meditation training, and focus enhancement. They are sold as consumer electronics, subject to general product safety regulations but not to the heightened oversight that applies to medical devices. The data they collect — neural signals that can reveal emotional states, cognitive load, and potentially unexpressed intentions — is governed, in most jurisdictions, by general data protection frameworks that were not designed with neural data in mind.
At the clinical end, invasive BCIs — devices implanted directly into or on the surface of the brain — are subject to medical device regulation and the oversight of bodies like the FDA. Neuralink's N1 chip, with its 1,024 electrodes, is now in operational clinical use, as is Synchron's Stentrode, a minimally invasive device delivered via the jugular vein that has demonstrated clinical viability without open-brain surgery. These devices generate data of extraordinary intimacy and precision — data that can, in principle, decode not just motor intentions but emotional states, memories, and unexpressed thoughts.
Neural data is not merely sensitive personal information — it is the substrate of consciousness itself, and its governance requires frameworks that existing data protection law was never designed to provide.
Between these poles lies a rapidly expanding middle ground: consumer-grade devices with clinical-grade ambitions, marketed for wellness and productivity but capable of generating data that raises serious privacy and autonomy concerns. The governance challenge is that the regulatory categories — consumer electronics versus medical devices — do not map cleanly onto the risk profiles of these technologies.
Neural data is not merely sensitive personal information — it is the substrate of consciousness itself, and its governance requires frameworks that existing data protection law was never designed to provide.
The Neurorights Framework: From Philosophy to Law
The concept of neurorights was developed primarily by Rafael Yuste, a neuroscientist at Columbia University, and the Neurorights Foundation he co-founded. The framework identifies five core neurorights: mental privacy, personal identity, free will, equal access to mental augmentation, and protection from algorithmic bias. These rights are grounded in the observation that neural data is categorically different from other forms of personal information — it is not just data about a person, but data that constitutes the most intimate aspects of personhood itself.
Chile's constitutional amendment, adopted in 2021, was the first legislative expression of this framework. Article 19 of the Chilean constitution now protects "brain activity and the information derived from it," requiring the state to safeguard neural data and prohibiting its use in ways that threaten individual autonomy. The Girardi ruling demonstrated that this constitutional protection has teeth — it can be enforced against private companies, not just state actors.
The Chilean model has inspired legislative activity across Latin America and beyond. Brazil's Rio Grande do Sul state has incorporated neurorights into its constitution, and a federal bill is under consideration. Mexico has proposed a 92-article General Law on Neurorights. Uruguay is pursuing legislative measures. In November 2025, UNESCO adopted the Recommendation on the Ethics of Neurotechnology, a non-binding normative framework signed by over 190 countries that is intended to serve as a template for national legislation.
The U.S. State-Level Patchwork
In the United States, the absence of federal neurorights legislation has produced a familiar pattern: a patchwork of state laws that provide inconsistent and incomplete protection. Colorado's HB24-1058, effective August 2024, protects neural data as "biological data" when used for identification purposes. California's SB 1223, effective January 2025, includes neural data as "sensitive personal information" under the California Consumer Privacy Act. Montana's SB 163, effective October 2025, regulates "neurotechnology data" under an amendment to its Genetic Information Privacy Act. Connecticut's SB 1295, scheduled for July 2026, amends the state's privacy act to include central nervous system activity as sensitive data.
These laws represent meaningful progress, but they share a common limitation: they treat neural data as a category of sensitive personal information, subject to the same consent-and-notice framework that governs other sensitive data. This approach may be adequate for consumer EEG devices, but it is arguably insufficient for the more invasive and more capable BCIs that are entering clinical use. The question of whether neural data requires not just stronger privacy protections but a fundamentally different governance framework — one grounded in cognitive liberty rather than data protection — remains unresolved.
The governance of neurotechnology cannot be reduced to data protection. It requires a framework that recognises cognitive liberty as a fundamental right — the right to mental self-determination that underlies all other freedoms.
The EU AI Act and the Limits of Indirect Regulation
The European Union has not enacted dedicated neurorights legislation, but the EU AI Act provides indirect regulation of neurotechnology through its prohibition on AI systems that use "subliminal techniques" to distort behaviour. Guidance released by the European Commission in February 2025 explicitly interprets this prohibition to cover BCIs, effectively regulating the most manipulative potential applications of neurotechnology without creating a dedicated regulatory framework.
The governance of neurotechnology cannot be reduced to data protection. It requires a framework that recognises cognitive liberty as a fundamental right — the right to mental self-determination that underlies all other freedoms.
The AI Act also classifies BCI systems as high-risk AI, imposing strict safety and transparency requirements. This classification is significant: it means that BCI systems used in clinical or commercial contexts must undergo conformity assessment, maintain technical documentation, and implement human oversight mechanisms. But the AI Act's focus is on the AI components of BCI systems, not on the neural data they collect. The gap between AI regulation and neural data protection remains.
The OECD's neurotechnology guidelines, adopted in 2024, represent a more comprehensive attempt to address the governance challenge. Principle 7 of the guidelines explicitly calls for the safeguarding of personal brain data, and the guidelines as a whole provide a framework for responsible innovation in neurotechnology that goes beyond the AI Act's focus on risk classification. But the OECD guidelines are non-binding, and their implementation depends on the political will of member states.
The Dual-Use Problem: Therapy, Enhancement, and Surveillance
The governance of neurotechnology is complicated by its dual-use character. The same technology that enables a paralysed patient to control a robotic arm with their thoughts can, in principle, be used to monitor workers' attention levels, assess the emotional states of criminal defendants, or enhance the cognitive performance of soldiers. The boundary between therapy and enhancement, between medical device and surveillance tool, is not fixed — it is determined by context, intent, and the regulatory frameworks that govern use.
The workplace surveillance dimension is particularly concerning. Consumer-grade EEG devices are already being marketed to employers as tools for monitoring worker attention and productivity. In jurisdictions without specific neural data protections, there is nothing to prevent employers from requiring workers to wear such devices as a condition of employment. The EU AI Act's prohibition on emotion recognition in workplaces and educational settings provides some protection, but it is limited to AI-driven emotion recognition and does not address the broader question of neural monitoring.
The criminal justice dimension raises different concerns. Neurotechnology has been proposed as a tool for lie detection, risk assessment, and rehabilitation monitoring in criminal justice contexts. The use of neurotechnology in these contexts raises profound questions about cognitive liberty — the right to mental self-determination — and the right against self-incrimination. France's Bioethics Law restricts the judicial use of neuroimaging, and Japan's CiNet guidelines provide consent templates for research contexts, but comprehensive governance frameworks for the use of neurotechnology in criminal justice remain rare.
The Cybersecurity Dimension
Invasive BCIs that allow for bidirectional communication — devices that can both record and stimulate brain activity — create a cybersecurity risk that has no precedent in the history of personal data protection. A compromised BCI could, in principle, allow an attacker to manipulate mood, impulse control, or motor function. The concept of "neurosecurity" — the protection of neural interfaces from unauthorised access and manipulation — is emerging as a distinct field, with researchers developing edge processing and on-device encryption protocols to mitigate these risks.
The cybersecurity dimension illustrates why the governance of neurotechnology cannot be reduced to data protection. The risks posed by invasive BCIs are not just risks of data breach — they are risks of direct harm to the physical and cognitive integrity of the person. Governance frameworks that treat neural data as simply another category of sensitive personal information are not equipped to address these risks.
A Framework for Cognitive Sovereignty
Neural data is not merely sensitive personal information — it is the substrate of consciousness itself, and its governance requires frameworks that existing data protection law was never designed to provide.
The emerging consensus among legal scholars, bioethicists, and neuroscientists is that effective governance of neurotechnology requires a framework grounded in cognitive liberty — the right to mental self-determination — rather than simply in data protection. Several principles are gaining traction.
The first is the recognition of neural data as a special category requiring heightened protection, distinct from other forms of sensitive personal information. This recognition is already reflected in the state laws enacted in Colorado, California, Montana, and Connecticut, and in Chile's constitutional amendment. The challenge is extending this recognition to a comprehensive federal framework in the United States and to international governance mechanisms.
The second is the principle of cognitive non-interference: the prohibition of technologies that can manipulate neural activity without explicit, informed, and revocable consent. This principle is reflected in the EU AI Act's prohibition on subliminal manipulation, but it needs to be extended to cover the full range of neurotechnology applications, including consumer devices marketed for wellness and productivity.
The third is the principle of purpose limitation applied to neural data: the use of neural signals should be strictly limited to the purposes for which they were collected, with robust mechanisms to prevent secondary uses. This is particularly important for consumer EEG devices, which are often marketed for one purpose — meditation, gaming, focus training — but collect data that could be used for very different purposes, including surveillance and profiling.
Neural data is not merely sensitive personal information — it is the substrate of consciousness itself, and its governance requires frameworks that existing data protection law was never designed to provide.
The fourth is the principle of equitable access: the benefits of neurotechnology should not be concentrated in wealthy populations and nations. The global BCI market is currently dominated by high-income countries, and the most capable devices are priced for clinical and research contexts that are inaccessible to most of the world's population. Governance frameworks that address only the risks of neurotechnology, without also addressing the equity dimensions of its distribution, will fail to capture the full scope of the challenge.
The Road Ahead
The governance of neurotechnology is at an inflection point. The technology is advancing faster than the regulatory frameworks designed to govern it, and the consequences of that gap are becoming increasingly visible. The Chilean Supreme Court's ruling in Girardi v. Emotiv was a landmark, but it was also a warning: the courts are being asked to resolve governance questions that legislatures have not yet addressed.
The UNESCO Recommendation on the Ethics of Neurotechnology, adopted in November 2025, provides a normative foundation for international governance. But normative frameworks are not enforcement mechanisms. The translation of the UNESCO principles into binding national legislation — and the development of international coordination mechanisms that can address the transnational dimensions of neurotechnology governance — will require sustained political will and institutional capacity that is not yet in evidence.
What is clear is that the stakes are high. Neurotechnology has the potential to transform medicine, enhance human capability, and create new forms of human connection. It also has the potential to enable unprecedented forms of surveillance, manipulation, and cognitive control. The governance frameworks that emerge from the current legislative moment will determine which of these futures prevails. The concept of cognitive liberty — the right to mental self-determination — provides the normative foundation for that governance. The challenge is translating that concept into law before the technology outpaces the law's capacity to respond.




