1 · Concept overview

Cognitive liberty is the claim that a person’s mental processes are a protected domain: that what happens inside a head is not readable without consent, and not alterable without consent, and that the person retains the right to alter it themselves. It is two rights welded together — a shield and a licence — and most of the current debate has quietly dropped the licence. The subject has moved from philosophy seminars into constitutional text, into a supreme court, into consumer product law and into three international soft-law tracks, all within about six years.

Two facts reorganise the whole topic and neither is widely carried. The first: the single paper on which the claim “mental privacy is technologically doomed” overwhelmingly rests says the opposite in its own text, and measured how easily it can be defeated. The second: the constitutional amendment universally reported as putting five neurorights into Chile’s constitution contains none of them, and does something structurally different — it instructs the legislature.

Take those two together and the field looks different. The threat that the movement organised itself around — a machine reading unconsenting minds at population scale — is not the threat the measured record describes. What the record describes is a decoder that needs many hours of per-subject training inside a scanner, that fails to generalise across people, and that a subject can defeat by silently naming animals. Meanwhile the vector where mental privacy really is weak — identifying a person from their brain signal, which needs no cooperation, no semantic model and no scanner — is the one the Chilean court expressly declined to reach and the one the five neurorights barely address.

This brief takes the sceptical case seriously enough to state it at full strength, then shows what it does not answer. It also carries a finding that belongs to this brief and to AI Governance jointly: both topics run aground on the same missing instrument, and neither literature appears to know the other has the same problem.

2 · Current scientific position

Established The doctrine was defined as symmetric, and the symmetry is routinely lost. Cognitive liberty is “the right of each individual to think independently and autonomously, to use the full power of his or her mind, and to engage in multiple modes of thought.” The term was coined by the neuroethicist Wrye Sententia and the legal theorist Richard Glen Boire, founders of the Center for Cognitive Liberty and Ethics, in response to neurotechnologies’ growing capacity to monitor and influence cognitive function. Established Sententia’s formulation protects “both those seeking enhancement and those refusing it.” Frontier That bidirectionality separates cognitive liberty from mental privacy: privacy is a shield only, liberty is a shield and a licence. A movement that treats the two as synonyms has silently dropped the enhancement half, and with it the strongest objection to the doctrine, which is distributive rather than informational.

Established The doctrinal hinge is that classical rights run against the state and consumer neurotechnology is a private-party problem. Jan Christoph Bublitz and Reinhard Merkel have proposed extending cognitive liberty beyond state interference to non-state entities, with criminal penalties for severe violations of mental integrity. Frontier The existence of that proposal is itself evidence about the current position: a right with reliable horizontal effect against companies would not need one.

Established The decoding paper that anchors the entire threat model states that the decoder requires cooperation. Tang, LeBel, Jain and Huth, Semantic reconstruction of continuous language from non-invasive brain recordings, Nature Neuroscience 26:858–866, published 1 May 2023, is the empirical foundation of almost every “mind reading is here” argument in the neurorights literature. Established It reports a single fMRI decoder producing intelligible word sequences from perceived speech, imagined speech and silent video, and shows language can be decoded from multiple cortical regions separately. Established It also states, verbatim: “subject cooperation is required both to train and to apply the decoder,” and adds that brain-computer interfaces “should respect mental privacy.”

Established And the paper measured resistance, which is the finding nobody quotes. Against passive listening the decoder recovered 52–57% of timepoints. Subjects instructed to resist brought that down: counting by sevens to 4–50%, imagining a different story to 1–26%, and naming animals to 0–3%. Established The best countermeasure is free, requires no training, no device and no expertise, and can be run silently by anyone who knows they are being decoded. Frontier The mechanism matters for how far this generalises: the decoder is semantic and top-down, so competing semantic content jams it. Speculative Whether that holds for architectures nobody has built yet is not something the resistance result settles. Frontier The sharp consequence is that the defence is conditional on notice. A subject who does not know a decode is happening does not resist — which converts a technical safeguard into a legal instrument, and a cheap one.

Established A 2024 systematic review has now put a number on how thoroughly the field ignores this. Frederic Gilbert and Ingrid Russo, “Mind-reading in AI and neurotechnology: evaluating claims, hype, and ethical implications for neurorights,” AI and Ethics (2024), searched 1,017 articles, of which 569 met relevance criteria. Established Of those 569, 91% suggest mind-reading is possible — 46% claiming current feasibility, 45% future possibility — while only 21% acknowledge that hype exists, and 68% of the studies examined concern decoding of basic visual percepts rather than anything resembling thought. Established Their substantive findings are three: claims of decoding without consent lack current evidence; claims that decoders generalise across individuals are unfounded; and fMRI lie detection, once promoted as feasible, has been shown ineffective. Established They read Tang et al. as demonstrating that semantic decoding can be consciously resisted, and that resistance cannot be overcome by focusing the decoder on specific brain regions.

Established The invasive branch has better numbers and the same dependency on the subject. The published speech-decoding records are: a 2021 Stanford result of 86 characters per minute, about 18 words per minute, from imagined handwriting in motor cortex; a 2021 UCSF result of 15 words per minute from vocal-tract signals; 2023 results of 62 and 78 words per minute using recurrent neural networks; and UCSF work from 2019–2022 reporting word error rates of 3% on 250 unique words across 50 sentences using electrocorticography. Established Image reconstruction runs from a 2008 ATR result at 10x10 pixels to a 2011 study reconstructing, second by second, videos the subjects were watching. Established The source assembling this record states plainly that all the studies mentioned involved active participant engagement. Frontier Note what this branch costs: an implant, a surgery and a clinical indication. It is not a surveillance instrument for the same reason a catheter is not.

Established Chile’s constitutional amendment does not contain the five neurorights. Law No. 21.383 (2021) inserted into Article 19, number 1, final clause, of the Political Constitution the following: “Scientific and technological development will be in service to individuals and carried out with respect for life and physical and psychological integrity. The law will regulate the requirements, conditions, and limitations for its use in individuals, with particular emphasis on safeguarding brain activity and the information derived from it.” Established That text names none of the five neurorights — not mental privacy, not personal identity, not agency, not equal access to enhancement, not algorithmic non-discrimination. Established What it does is subordinate scientific and technological development to physical and psychical integrity, and instruct the legislature to regulate, with brain activity singled out for emphasis. Frontier It is a constitutionalised legislative mandate plus an interpretive steer, reaching its result through a pre-existing integrity clause rather than through a new right. Established Four sources across two publishers converge on this reading. Established The reform originated as Boletín No. 13.827-19, introduced 7 October 2020; on the same day two proposals were lodged — a constitutional reform and a separate substantive neuroprotection bill — and it is the constitutional reform that passed.

Established The Emotiv decision is real, dated, and less determinate than its reputation. Guido Girardi Lavín brought proceedings against Emotiv Inc. of San Francisco over the Emotiv Insight wireless EEG headset, alleging inadequate protection of brain information with risks of reidentification, hacking, unauthorised reuse, commercialisation and digital surveillance of neurodata. Established The Chilean Supreme Court decided for the claimant on 9 August 2023 and reasoned explicitly in terms of “neurorights at stake, such as mental privacy and cognitive freedom.” Frontier It is very widely reported that the Court ordered Emotiv to delete the claimant’s data. The research behind this brief could not verify that order and no source it read states it, so this brief does not assert it. Frontier The one case number available is chronologically odd for a 2023 Supreme Court decision, and no case number is printed here for that reason. Established The case’s own commentators state what the ruling did not address: devices capable of neurophysiologically identifying individuals, and the effect of their dissemination on fundamental rights. That omission is the most consequential thing about the judgment.

Established The five neurorights are a civil-society proposal, not an adopted instrument. Rafael Yuste proposed that five new neurorights be added to the Universal Declaration of Human Rights, protecting mental privacy, identity and agency, guaranteeing equal access to cognitive enhancement, and preventing algorithmic bias. Established He has directed the NeuroRights Initiative since 2019 and co-founded the NeuroRights Foundation with the human-rights lawyer Jared Genser. Frontier The distinction between a proposal aimed at the UDHR and an amendment to it is routinely collapsed, and that collapse is what produces the claim that neurorights are internationally recognised.

Established What does exist internationally is a thickening layer of soft law, and its numbers are harder to obtain than its existence. Four instruments exist: an OECD instrument of December 2019, a UNESCO Recommendation track with a 2025 draft, a UN Human Rights Council Advisory Committee proposal of 8 September 2022, and an inter-American declaration adopted by the OAS in 2023. Established None is a binding obligation. Established The formal titles and instrument numbers of the OECD and UNESCO texts could not be read for this brief and are printed nowhere in it, nor is an adoption date for the UNESCO instrument.

Frontier The US state statutes are the most consequential recent development and this brief cannot cite them. Colorado amended its consumer privacy statute to reach biological and neural data, California amended the CCPA to treat neural data as sensitive personal information, and further states have followed. The research pass behind this brief could not obtain a bill number, chamber, signing date or effective date for any of them, so none appears here. That is the largest evidential gap in this brief and it is named rather than papered over. Established What can be stated is doctrinal: the Fifth Amendment privilege against self-incrimination may not extend to neuroimaging if it is classified as physical evidence rather than testimony — the crux for whether brain data is compellable; unenumerated-rights routes run through the Ninth and Fourteenth Amendments; admissibility is governed by Daubert. Established India has permitted Brain Electrical Oscillation Signature Profiling as legal evidence, and an Italian appellate court used neuroimaging evidence in 2009. Established The summary position is that the legal definition of neuroprivacy has yet to be properly established.

Established The workplace is where consumer neurotechnology already touches people who cannot refuse it. Nita Farahany, who argues for recognising cognitive liberty within the Universal Declaration of Human Rights, describes Chinese workplaces where some workers are required to wear EEG devices under their hats to collect information on productivity, focus and mood. Frontier No count of affected workers is available from the source read here, and none is printed. Established Against the enhancement half of the doctrine stands a distributive objection associated with Michael Sandel: removing restrictions on cognitive-enhancing drugs risks creating “two classes of human beings.” Frontier That objection leaves mental privacy untouched, which is further evidence the two halves should be argued separately.

3 · Frontier questions

Frontier The hype audit is itself the frontier event, and its method is portable. Gilbert and Russo (2024) appears to be the first systematic quantification of overclaiming inside a neuroethics literature: count what a field asserts, then compare it against what the primary literature shows. Frontier The 91%-versus-21% gap is a measurement of a research community rather than of a technology, and there is no obvious reason the method should not be run on other fields where a single famous result anchors a policy movement.

Frontier Adversarial neuroscience is an open research programme with essentially no literature. Tang et al.’s resistance experiment is, as far as this brief could establish, the only published quantification of a cognitive countermeasure against a decoder. Speculative The obvious follow-on questions are unasked: what does maintaining resistance cost in cognitive load and task performance; how long can it be sustained; can it be trained; and does it survive a decoder that has been adapted to expect it. Frontier That the strongest defence of mental privacy currently on the record has one paper behind it and no follow-up is a statement about funding priorities, not about difficulty.

Frontier Cross-subject generalisation is the empirical crux, and it currently fails. Gilbert and Russo report that claims decoders generalise across individuals are unfounded and that decoding cannot achieve generalisation across individuals. Established Every threat model involving scanning a population rather than a consenting subject requires exactly that generalisation. Speculative Whether a subject-invariant semantic representation exists and is learnable is a genuine open question in systems neuroscience, not an engineering backlog item. Frontier It is also the single number whose movement would change everything in this brief, and there is no standing benchmark that would tell anyone it had moved.

Frontier Non-semantic identification is the unaddressed vector. The Emotiv commentators flag that the ruling did not reach devices capable of neurophysiologically identifying individuals. Speculative Brain-print identification requires the subject to be thinking nothing in particular, needs no semantic model, and appears feasible from consumer-grade EEG. Speculative If brain-print stability across sessions and years is high enough for re-identification — an empirical figure this brief could not source — then neural data is biometric data, and the correct legal move is classification under existing biometric statutes rather than a new right. Frontier That is, notably, what the US states appear to have done.

Frontier The sceptical wing now has institutional standing, and the debate is genuinely two-sided. Gilbert and Russo argue that neurorights discourse represents AI-ethics hype — speculative ethics built on fictional scenarios rather than current capabilities — and that hypothetical mind-reading scenarios should not drive immediate rights frameworks. Frontier Joseph Fins argues Chile’s provisions are vague and premature and fail four tests: they do not balance positive and negative rights; they are not grounded in actual science, avoiding science-fiction fantasies ungrounded in reality; they lack specificity, inviting litigation and delaying scientific progress; and they do not harmonise with established disability and human-rights law. He concludes the reforms should not be adopted elsewhere without substantial revision. Frontier Anna Wexler’s policy-side critique is a third peer-reviewed sceptical intervention from inside neuroethics within about two years. A brief that presents neurorights as consensus is out of date.

Frontier Fins’s positive-rights point is the most interesting thing in the sceptical literature. For patients with disorders of consciousness, a purely negative right to mental privacy is worse than useless: what those patients need is a right of access to decoding technology, which is the instrument that might let them communicate at all. Speculative A rights framework that makes neural decoding legally hazardous to develop imposes its cost on precisely the population with the strongest claim on it. Frontier This is a real trade-off, it is not rhetorical, and the movement has no published answer to it.

Frontier Two governance tracks outside the standard frame are worth naming. Damian Eke’s work on neurotechnology governance in Africa is a rare non-Northern framing in a discourse that is overwhelmingly Latin American, European and North American. Frontier And a decade-long embedded-ethics collaboration in a neurotechnology research centre has now been assessed by its own participants — a natural experiment in governing by embedding rather than by legislating, the alternative most often gestured at and least often measured.

Frontier The frame is migrating from privacy into culpability. Recent work on brain evidence and criminal responsibility takes the neurorights vocabulary into questions of blame, which is where the Fifth Amendment testimony-versus-physical-evidence line becomes load-bearing rather than academic. Speculative If neural data is physical evidence, it is compellable; if it is testimony, it is not; and the whole architecture of mental privacy in the United States turns on a classification that no court has settled.

4 · Technological bottlenecks

Established State the target honestly: enforceable mental privacy means prevention for the ordinary case plus detection and remedy for the rest. Prevention alone is unattainable against a determined actor with physical access, which is true of every privacy right and is not a special defect here.

Frontier The chain runs as follows. L1, an operational legal definition of neural data that is neither over- nor under-inclusive. L2, classification of neural data as biometric, so identification harms are reached by existing law. L3, a published cross-subject generalisation benchmark for semantic decoders. L4, a notice requirement with a technical compliance test. L5, a resistance-cost curve. L6, detection of unconsented decoding in the wild. L7, horizontal enforceability against private parties, demonstrated by a decided case with an enforced remedy. L8, a remedial toolkit for a non-pecuniary and often undetectable harm. L9, cross-border effect, since neural data leaves the jurisdiction with the device’s cloud. L10, the assembled regime with an authority able to audit a neural-data processor.

Frontier The binding link is L6, and the reason is structural. L1, L2, L7, L8 and L9 are ordinary legal engineering: hard, but each has a precedent in biometric, health or financial data law, and the Emotiv decision shows L7 is reachable. L3 and L5 are tractable science nobody has funded. Established L6 has no precedent and no method. Every enforceable privacy regime relies ultimately on breaches becoming visible — through breach notification, a subject noticing a consequence, a whistleblower, an inspection of records. Frontier An unconsented decode leaves no artefact on the subject’s side at all: the brain is unchanged, nothing is taken from an account, and the output is a model’s inference. If the processor does not log it, or logs falsely, there is nothing to find.

Speculative Which implies something uncomfortable and specific: enforceable mental privacy in the detect-and-remedy sense may require regulating the processor’s compute rather than the subject’s data — attestation that a given model was or was not run on given inputs. Speculative That is structurally the same instrument that AI Governance needs to verify a developer’s negative capability claims. Two topics converge on one missing primitive: verifiable claims about what computation was performed. Handwave Neither literature appears to know the other has the same problem, and neither is going to solve its binding constraint without it.

Frontier The optimistic corollary. Precisely because detection binds, prevention beats detection here in a way it does not in most privacy domains — and prevention is unusually cheap: a notice rule plus a subject who knows to name animals is an effective defence at close to zero cost. Frontier The sensible sequencing is therefore L1, L4, L3, L5, with L2 in parallel because it is the only route that reaches the identification vector, and L6 treated as a long-horizon research programme rather than a deliverable.

5 · Research dependencies

Frontier This brief waits on systems neuroscience before it waits on law. The question of whether a subject-invariant semantic representation exists and is learnable is prior to every population-scale threat model, and it is not a question lawyers can answer or fund their way past. Speculative A negative answer makes most of the neurorights programme a solution to a problem that does not arrive; a positive one makes the whole apparatus urgent overnight.

Frontier Second, sensing. Semantic decoding at the published quality depends on fMRI, which is immobile, expensive and impossible to deploy covertly. Speculative Whether portable modalities — dry EEG, functional near-infrared spectroscopy, optically pumped magnetometry — can reach the signal quality that made the fMRI result possible is an instrumentation question with no settled answer, and this brief has no published figure comparing them on a decoding task.

Frontier Third, the brain-print stability figure. Whether EEG-derived identifiers remain stable across sessions separated by months and years, and at what equal-error rate, determines whether existing biometric law already covers the worst realistic harm. Speculative This brief could not source that figure, which is a gap worth naming precisely because closing it would settle a legal question rather than merely inform one.

Frontier Fourth, doctrine on horizontal effect. Whether constitutional and human-rights instruments bind private companies, and through what mechanism, is contested in every jurisdiction that has the question. Frontier Bublitz and Merkel’s proposal exists because the answer is currently doubtful, and no amount of neuroscience will resolve it.

Speculative Fifth, and shared with AI Governance: hardware or protocol-level attestation of what computation a processor performed. Nothing in the fetched record on either topic demonstrates it at the fidelity either regime would need.

6 · Required experiments

Frontier A definitional edge-case panel, scored. Take a fixed panel — raw EEG, derived affect scores, eye-tracking, heart-rate variability used as an affect proxy, keystroke dynamics — and run a candidate legal definition of neural data against it with a panel of lawyers. Report the inclusion decisions and the inter-rater agreement. Established Chile’s constitutional formula, “brain activity and the information derived from it,” is broad and has never been tested this way. Speculative A definition with poor inter-rater agreement is not a definition; it is a litigation generator, which is exactly Fins’s objection stated as a measurement.

Frontier A zero-shot cross-subject decoding benchmark. Decoding accuracy on a held-out subject with zero subject-specific training data, reported against the within-subject ceiling, on a public evaluation set fixed before the models are built. Frontier The honest current number appears to be near floor, but there is no standing benchmark, which means the field has no thermometer for the one variable that governs the threat model. Speculative This is cheap, it is fundable today, and it would be the most decision-relevant number in the whole area.

Frontier A resistance-cost curve. Tang et al. give the efficacy of a countermeasure at a moment. Nobody has given the cost over an hour: the cognitive load and the task decrement imposed by maintaining decoder resistance, as a function of duration. Speculative If resistance is free for two minutes and ruinous for two hours, notice-plus-countermeasure is a defence for interrogation and not for employment.

Frontier A brain-print re-identification study with a real interval. Equal-error rate for identification from consumer-grade EEG across sessions separated by months, not minutes. Speculative The number decides whether neural data is biometric data under statutes that already exist.

Speculative An auditor-detection study. Instrument a set of consumer devices, some of which conceal an active decode, and measure whether a trained auditor can determine from the device and its software that decoding is occurring. Report the detection rate. Handwave Nothing resembling this has been attempted on the record, and it is the empirical test of whether a notice rule is enforceable or decorative.

Handwave And the hard one: a forensic method for establishing that a decode occurred, from a processor’s logs, models or outputs, with published false-positive and false-negative rates. This is L6. It has no method and no precedent, and stating it as an experiment rather than an aspiration is the point.

7 · Engineering requirements

Frontier The device-side engineering problem is that consumer neurotechnology is architecturally a data-exfiltration product. A headset with an account, a cloud pipeline and a mobile app emits raw or lightly processed neural signal to a processor in another jurisdiction by default. Established The Emotiv facts are the canonical shape: a Chilean claimant, a San Francisco defendant, a consumer device.

Speculative The obvious mitigation is on-device processing with signal minimisation: derive the feature the application actually needs — an attention score, a control signal — on the headset, and never transmit the underlying time series. Frontier This is straightforward for control applications and hard for anything that improves with a model trained on pooled data, which is most of the commercial value. The engineering and the business model point in opposite directions.

Speculative Notice needs a physical channel, not a consent dialogue. If the defence against semantic decoding is a countermeasure the subject deploys, then notice must be perceptible at the moment of decoding — a hardware indicator wired to the acquisition path rather than a paragraph agreed to at setup. Handwave A tamper-evident recording indicator is a solved problem in other domains and an unattempted one here.

Speculative Deletion has to be verifiable to be a remedy. A court order to delete neural data is worth what the verification is worth, and a model trained on that data is not deleted by deleting the data. Frontier This is the same problem machine unlearning has failed to solve cleanly elsewhere, and it arrives here attached to a remedy a court may already have ordered.

Handwave The far end is attestation: a processor that can prove, to an auditor and without disclosing its model, which computations it ran on which inputs. Handwave Nothing on the record does this at the fidelity a neural-data regime would need, and it is the same unbuilt instrument named in section 4.

8 · Adjacent technologies

Frontier The read side of this brief is the ethics of the technology assessed in Neural Interfaces and Brain-Computer Interfaces. Every capability figure that matters here — decoding rate, word error rate, electrode count, portability — is produced by that programme, and the therapeutic case for pushing those figures is strong.

Frontier The write side connects to Neuroplasticity Engineering and Memory Engineering, where the governing harm is modification rather than exposure. Speculative Privacy doctrine has nothing to say about a closed-loop system that adjusts affect; bodily-integrity and battery doctrine have something to say and are poorly adapted to gradual, consented-at-onset, algorithmically-adjusted change.

Frontier The enhancement half of the doctrine lives in Cognitive Enhancement and Human Cognitive Augmentation. Frontier Cognitive liberty was born in drug-policy argument, and the equity objection against it is a drug-policy objection. That half of the doctrine has stalled mainly because no enhancement currently works well enough at population scale to make access a live distributive question.

Speculative The most under-explored adjacency is AI Governance, and it is under-explored in both directions. The manipulation channel that reaches billions of people is recommendation and conversational AI, not EEG, and a cognitive-liberty provision may well arrive in an AI statute before it arrives in a neuro statute. Frontier Bublitz and Merkel’s extension to non-state entities fits an AI defendant as naturally as a neurotechnology one. Speculative More importantly, the two topics need the same unbuilt instrument — a way to establish what computation a processor actually ran — and neither literature cites the other.

Speculative Three further adjacencies carry real load. The remedial machinery in Future Legal Systems is where any of this becomes enforceable or does not, because a right with no remedy for a non-pecuniary and undetectable harm is a statement of preference. Frontier Digital Citizenship holds the consent and identity architecture that a notice regime would have to sit inside. Speculative And Consciousness Research matters for the reason Fins gives: the patients with the strongest claim on decoding technology are those whose mental states cannot currently be established at all, and a rights framework built only from prohibitions cannot help them.

9 · Institutional requirements

Established The institutional record so far is a proposal, one constitutional mandate, one judgment and four soft-law instruments. The NeuroRights Initiative has run since 2019 and the NeuroRights Foundation exists; Chile has a constitutional mandate awaiting implementing legislation; the OECD has a December 2019 instrument; UNESCO has a Recommendation track with a 2025 draft; the UN Human Rights Council Advisory Committee produced a proposal on 8 September 2022; and the OAS adopted a declaration in 2023. Frontier That is an unusually thick soft-law layer over an unusually thin hard-law one, which is the reverse of the normal technology-regulation sequence and is worth noticing as a fact about how this movement has operated.

Frontier The first institutional requirement is an operational definition of neural data. Not a slogan — a rule that a compliance officer can apply to eye-tracking, to heart-rate variability sold as an affect proxy, and to an attention score derived on a headset and transmitted as a single number. Speculative A definition that reaches raw EEG but not the derived affect score protects the artefact and not the interest; one that reaches every physiological proxy for mental state swallows the wearables industry whole. Nobody has published the panel test that would show where a given draft sits.

Frontier The second is enforcement reach over devices sold across borders. The one decided case in this field involved a claimant in Santiago and a defendant in San Francisco, and the data was already in a cloud outside the forum before the claim was filed. Speculative A neural-data regime with no adequacy mechanism, no transfer regime and no cooperation channel is a regime that regulates the domestic subsidiaries of firms that could stop having domestic subsidiaries.

Speculative The third is regulatory forensic capacity, which does not exist anywhere. No data protection authority currently employs people who could examine a neural-data processor and determine what it ran. Handwave Until one does, an enforcement regime is a complaints regime, and complaints require a subject who noticed — which is exactly what an unconsented decode does not produce.

Frontier The fourth is a decision about whether this is a new category or a specification exercise. If it is specification, the institutional work belongs in data protection authorities and biometric statutes and can start now. If it is a new category, it needs its own instrument, its own remedies and its own regulator, and Fins’s objection — that the existing drafts are too vague to be justiciable — has to be answered first.

10 · Ethical & societal considerations

Frontier The strongest ethical objection to the neurorights programme comes from inside neuroethics and it is about patients. A purely negative right to mental privacy does nothing for someone with a disorder of consciousness whose only route to communication is a decoder. Speculative Fins’s argument is that a rights framework which chills the development of that decoder imposes its cost on the population with the strongest claim on the technology, and that the framework should be built around capabilities rather than prohibitions. Frontier This is a genuine conflict between two defensible positions and it should be declared as one rather than resolved by assertion.

Frontier The equity objection cuts at the other half of the doctrine. If cognitive liberty licenses enhancement as well as refusal, then unequal access to enhancement is a liberty-created harm, and the objection that this risks creating “two classes of human beings” is not answered by anything in the privacy literature. Frontier A movement that argues for both halves owes an account of the second, and Yuste’s fourth proposed right — equal access to cognitive enhancement — is an acknowledgement that the problem is real rather than a solution to it.

Established Consent in the workplace is not consent. Where workers are required to wear EEG devices to have their productivity, focus and mood monitored, the legal architecture of consent does no work at all, because refusal costs the job. Frontier This is the fact pattern most likely to produce the first serious enforcement action, and it is a labour-law problem wearing neurotechnology clothes.

Speculative And there is an ethical cost to the hype itself. A literature in which 91% of relevant articles assert that mind-reading is possible, against a primary record where it requires cooperation and does not generalise, is a literature that has taught the public to believe something false about their own vulnerability. Frontier Fear of a capability that does not exist is not costless: it deters research subjects, it distorts legislative priorities, and it makes the eventual arrival of a real capability harder to communicate.

11 · Civilizational implications

Speculative If cross-subject decoding ever works, the change is categorical rather than incremental. Per-subject training inside a scanner is the entire barrier between a laboratory instrument and a population-scale one. Speculative Remove it and every institution that currently relies on the unreadability of an interior — the secret ballot, the confessional, the privilege between lawyer and client, the interior monologue that makes deception possible — is exposed to an instrument that no prior legal system has had to contemplate.

Speculative The more likely equilibrium is not secrecy but fiduciary duty. Privacy-as-secrecy has failed in every previous data domain; what survived was purpose limitation and duties of loyalty. Neural data is emitted continuously and involuntarily, which is exactly the condition under which secrecy models fail. Frontier The concrete failure mode for a fiduciary regime is documented in adjacent industries: the duty has to survive corporate insolvency and acquisition, and a neurotechnology firm’s dataset sold in bankruptcy is the case that will test it. Speculative A duty of loyalty also has the advantage of reaching the write side, which a confidentiality rule structurally cannot: a fiduciary who modifies your affect to increase your engagement has breached the duty whether or not anything was disclosed.

Handwave The most likely place cognitive liberty is actually claimed is against AI systems, not neurotechnology. The channel that reaches billions is persuasion at scale, and the doctrine’s extension to non-state entities fits that defendant. Handwave The obstruction is measurement: manipulation has to be established as a deviation from a counterfactual the subject would have chosen, which is the hardest measurement problem in this cluster and is formally the same shape as the capability-bound problem in AI Governance. Handwave A right that cannot distinguish manipulation from persuasion collapses into a prohibition on communication, which no legal system will adopt.

12 · Timelines

These horizons track the enforcement problem and the generalisation question, because those are the two variables everything else waits on. They deliberately do not track decoder headline performance, which improves on a faster and much less informative schedule.

  • 10 yr: Frontier Implementing legislation exists in Chile and the constitutional mandate is either specified or visibly unspecified, and either outcome is informative. Frontier More US states name neural data in consumer privacy statutes, and the first enforcement action lands against a workplace monitoring deployment rather than a consumer device. Speculative A cross-subject decoding benchmark is published, and reports near-floor performance. Speculative A brain-print re-identification study with a multi-month interval settles whether neural data is biometric data, and the answer decides more law than any new right does. Frontier The UNESCO instrument is adopted and is soft law, and is described in press coverage as binding.
  • 25 yr: Speculative Neural data is regulated everywhere it matters as a sensitive category inside general data protection law, and the standalone neurorights instrument turns out to have been a mobilising device rather than a legal one. Speculative The identification vector is where all the litigation actually happens, and the semantic-decoding threat that organised the movement never materialises at population scale. Speculative A notice requirement with a technical compliance test exists in at least one jurisdiction, and auditors can enforce it at a measured detection rate somewhere well short of complete. Frontier Write-side harms — unconsented modification by closed-loop systems — generate the first genuinely novel doctrine, because privacy law has nothing to say about them.
  • 50 yr: Speculative Either subject-invariant decoding has been demonstrated, in which case mental privacy is a policing and attestation problem rather than a rights problem, or it has not, in which case the whole apparatus is understood retrospectively as anticipatory regulation that cost less than it was worth. Speculative Mental-data fiduciary duty is the operative standard, and the case that established it involved a bankruptcy. Handwave Cognitive liberty has been successfully pleaded against an AI system, and the judgment turns on a counterfactual measurement nobody trusts.
  • 100 / 250+ yr: Handwave Either the interior remains genuinely unreadable without cooperation, in which case this whole field is remembered as a rare case of a rights movement that got ahead of a capability that never arrived and was vindicated anyway by the identification harms it caught in passing; Handwave or reading and writing to a mind are ordinary, consent is continuous and instrumented, and the historically interesting question is how a civilisation that had already lost every other form of privacy managed to keep this one for as long as it did.

13 · Technology tree & dependencies

  • Depends on Depends on results this brief cannot produce, and three of them are scientific rather than legal. First, whether a subject-invariant semantic representation of language exists and is learnable: that single question decides every population-scale threat model, and a negative answer makes most of the neurorights programme a solution to a problem that does not arrive. Second, whether portable sensing -- dry EEG, functional near-infrared spectroscopy, optically pumped magnetometry -- can approach the signal quality that made the fMRI decoding result possible, since an immobile scanner is not a surveillance instrument. Third, whether brain-print identification from consumer-grade hardware is stable enough across months and years to count as biometric under statutes that already exist, which would resolve the strongest real harm without any new right at all. It also depends, less obviously, on doctrine: whether constitutional and human-rights instruments have horizontal effect against private companies, which is precisely the question Bublitz and Merkel's proposal exists because the answer is currently doubtful.
  • Requires (not on this map) Two institutional constraints bind before any scientific one does. The first is a definition of neural data that a compliance officer can apply to hard cases — raw EEG, a derived attention score, eye-tracking, heart-rate variability sold as an affect proxy — with measured agreement among lawyers rather than agreement in principle; Chile's constitutional formula, 'brain activity and the information derived from it,' is broad and has never been tested this way. The second is enforcement reach over devices sold across borders: the only decided case in this field paired a Chilean claimant with a San Francisco defendant and data already resident in a foreign cloud, and no fetched source establishes a transfer or adequacy regime that reaches it.
  • Enables Enables, if the definitional and enforcement work lands, a coherent regime for consumer neurotechnology and for workplace monitoring, which is the fact pattern most likely to produce the first serious enforcement action. It also enables a legal category that the write side of neural interfaces will need long before the read side becomes dangerous, since unconsented modification threatens integrity rather than confidentiality and no privacy right addresses it. A working notice rule plus a demonstrated countermeasure would enable something rarer still: a privacy protection a subject can operate for themselves, in the moment, without a lawyer and without a regulator.
  • Adjacent Adjacent to the capability programmes in Neural Interfaces and Brain-Computer Interfaces, which produce every number this brief assesses and whose therapeutic case is strong; to Cognitive Enhancement and Human Cognitive Augmentation, which carry the licence half of the doctrine and its distributive objection; to Future Legal Systems, which holds the remedial machinery any of this would need; and to AI Governance, which shares this brief's binding constraint exactly and does not appear to know it.

14 · Common misconceptions & speculative claims

Established “Chile put neurorights in its constitution.” It did not. What Law No. 21.383 (2021) inserted into Article 19, number 1, was a requirement that scientific and technological development be carried out with respect for life and physical and psychological integrity, and a mandate that “the law will regulate the requirements, conditions, and limitations for its use in individuals, with particular emphasis on safeguarding brain activity and the information derived from it.” Established None of the five neurorights is named. No new individual right is created in terms. Established Two proposals were lodged on 7 October 2020 — a constitutional reform and a substantive neuroprotection bill — and it is the constitutional reform that passed. Frontier The gap between what the text says and how it is internationally described is itself a finding about this field: four sources across two publishers give the same reading of the text, and the popular account survives anyway.

Established “AI can now read your mind.” The paper this rests on says the opposite. Tang et al. (2023) state that “subject cooperation is required both to train and to apply the decoder,” and measured resistance driving recovery from 52–57% of timepoints under passive listening down to 0–3% when subjects silently named animals. Established The enthusiast literature gets this wrong by quoting the imagined-speech and silent-video generalisation, which is real and in the abstract, while dropping the cooperation sentence that sits beside it. Established Gilbert and Russo have now quantified how widely: of 569 relevant articles, 91% suggest mind-reading is possible and only 21% acknowledge that hype exists. Frontier This is the clearest case available anywhere of a founding paper contradicting the claim it anchors, and the correction is not a technicality — a decoder requiring hours of per-subject training inside an fMRI scanner is not a surveillance instrument.

Frontier “Chile’s Supreme Court ordered Emotiv to delete brain data.” Perhaps; this brief cannot confirm it. The decision is real, dated 9 August 2023, the claimant was Guido Girardi Lavín, the device the Emotiv Insight, and the Court reasoned in terms of “mental privacy and cognitive freedom.” Frontier The remedy is not verified in any source read for this brief, and the case number is not printed here because the only one available is chronologically odd for a 2023 Supreme Court decision. Frontier The case note that would settle both was not obtainable. This is stated rather than smoothed over because the deletion order is the single most-repeated fact in the neurorights literature.

Frontier “Neural data is uniquely unprotected.” It is unprotected as a named category in most jurisdictions, but it is not outside law. In the United States it sits inside constitutional doctrine on compelled testimony versus physical evidence, the Daubert admissibility standard and general consumer-privacy statutes; in Europe it is special-category personal data on any ordinary reading; and several US states have now named it explicitly. Frontier The real gap is enforcement and detection, not the absence of an applicable rule.

Established “Neurorights are internationally recognised.” What exists is a civil-society proposal to add five rights to the Universal Declaration of Human Rights; an OECD instrument of December 2019; a UNESCO Recommendation track with a 2025 draft; a UN Human Rights Council Advisory Committee proposal of 8 September 2022; and an OAS declaration of 2023. Established Recommendations and declarations are not binding instruments, and no source read for this brief establishes a binding international neurorights obligation. Frontier This brief also declines to describe the content of the OECD and UNESCO instruments, because neither could be read: no provision, article, principle, instrument number or adoption date from either appears here, and any brief that gives you one has got it from somewhere this one could not reach.

Frontier “Mental privacy is already lost.” For the semantic-decoding vector the measured record says the opposite: cooperation-dependent, non-generalising, and defeatable by naming animals. Frontier Where mental privacy is genuinely weak is the identification vector — brain-print biometrics from consumer hardware — which the Emotiv court expressly did not reach and which the five neurorights barely address. Frontier The correct claim is not that privacy is lost but that the movement is defending the wrong flank.

Established “Cognitive liberty is about privacy.” It was defined to protect both those seeking enhancement and those refusing it. Frontier Half the doctrine is a right to alter your own cognition, and that half faces a distinct objection about creating “two classes of human beings” which has nothing to do with confidentiality. Merging the two loses the enhancement half and the equity critique with it.

Frontier And the sceptic’s error, stated for balance: “neurorights are premature, therefore unnecessary.” The premature-specification critique is well-founded on the current capability record and this brief gives it full weight. Frontier But it does not answer the write-side case — unconsented modification by closed-loop stimulation, where the threatened value is integrity rather than confidentiality and no privacy right addresses it — and it does not answer the identification case, which requires no semantic decoding at all. Speculative A sceptic who has rebutted mind-reading has rebutted the weakest third of the programme. Speculative It is also worth noting the movement’s own strategic argument, which is its best one: rights are historically cheaper to establish before a capability arrives than after. Frontier The counter-argument is not that anticipation is wrong but that this anticipation misidentified the vector, and on the current record it did.