Abstract
Implantable brain-computer interfaces (iBCIs) are rapidly transitioning from proof-of-concept devices to early clinical application. The high-resolution neural signals they capture may yield insights beyond those derived from conventional health data. In this Review, we examine how clinical iBCI data remain insufficiently protected, despite existing privacy laws like the Health Insurance Portability and Accountability Act (HIPAA) and the General Data Protection Regulation (GDPR). Five core gaps are identified: overreliance on conventional de-identification, limited individual control and rights, conflated consent practices, limited guardrails against misuse, and underspecified ownership. We examine strategies to address these gaps, including protections for de-identified data, stronger iBCI data rights and control, separate data consent, limits on harmful secondary uses, and monetization guardrails. As iBCIs transition from research tools to real-world clinical practice, clinicians, researchers, developers, and regulators, in dialogue with prospective and current iBCI users, will play central roles in advancing patient autonomy and privacy.
Subject terms: Diseases of the nervous system, Neurological disorders, Health services, Clinical trial design, Biotechnology
Sandbrink and Young examine emerging opportunities and challenges in stewarding neural data generated by implantable brain computer interfaces as these devices move from research settings into clinical care. They identify key gaps in protections, and discuss how clinicians, developers, and regulators could advance patient privacy and autonomy.
Introduction
Implantable brain-computer interfaces (iBCIs) are advancing for a variety of neurorestorative applications, including limb control and communication assistance, and are poised to transform care for many patients1,2. iBCIs capture longitudinal neural activity with unprecedented spatial and temporal resolution. With the advent of AI-enabled decoding algorithms, the resulting iBCI-derived neural data (hereafter, “iBCI data”), including raw recordings, processed features, decoded inferences, and personalized model parameters, now support increasingly detailed inferences about intended actions, linguistic content, and other cognitive processes1. Most existing data protection frameworks, however, were designed for traditional forms of health data, long before the advent of iBCIs capable of high-resolution brain recording and advanced decoding3. As neural data governance gains traction in policy discussions, evident in a recent UN Human Rights Council report4, the September 2025 introduction of the Management of Individuals’ Neural Data (MIND) Act5, and a November 2025 UNESCO Recommendation on the Ethics of Neurotechnology6, and as more companies initiate pivotal trials, opportunities exist to bring greater specificity to governance proposals as they pertain to clinical iBCIs. Here, we critically evaluate what makes iBCI data distinctive and what protections are and are not afforded by current regulatory frameworks, identifying five core gaps: overreliance on conventional de-identification, limited individual control, conflated consent, limited misuse guardrails, and underspecified ownership. We examine options for how clinicians, researchers, developers, and regulators, in dialogue with individuals with lived experience of iBCI use, can help address these gaps (Fig. 1).
Fig. 1.

Gaps and corresponding proposals for advancing iBCI data protections.
Because the practical effectiveness of regulatory data protection frameworks can depend on associated technical and organizational measures, selected data security considerations are also discussed where they could affect the practical realization of regulatory data protection and complementary governance efforts’ objectives. In this review, “iBCI data protections” refer collectively to regulatory data protection frameworks, complementary governance mechanisms, and those technical and organizational safeguards that impact their practical implementation. While these layers interact in practice (for example, regulatory obligations shape which technical measures are considered reasonable, and technical developments in turn might inform legal standards), they are distinct and non-interchangeable, raising different questions of implementation and accountability. While prior work highlights regulatory blind spots surrounding consumer neural and biometric data7–10, we here examine clinical iBCI data, showing how they remain vulnerable despite coverage as medical data under existing regulatory frameworks. As large-scale clinical iBCI datasets are only beginning to emerge, the analysis is deliberately anticipatory, identifying foreseeable risks based on distinctive characteristics of iBCI data and precedent from analogous domains, and pointing to corresponding suggestions to be considered (and potentially implemented) now, rather than waiting for potential breaches to occur and retrofitting protections11–14.
What makes iBCI-derived neural data distinctive?
Neural data are generally information obtained by measuring the activity of the central or peripheral nervous system. This information can be structural, including computed tomography (CT) and magnetic resonance imaging (MRI) scans; functional-hemodynamic, including functional magnetic resonance imaging (fMRI), functional near-infrared spectroscopy (fNIRS)15, and positron emission tomography (PET); or electrophysiological, including electroencephalography (EEG), magnetoencephalography (MEG), electrocorticography (ECoG), and intracortical recordings. Low-resolution or static neural data (e.g., conventional head CT) may have relatively limited capacity for unanticipated inferences. However, advances in high-resolution recording and artificial intelligence-driven decoding have enabled the capture of rich, dynamic features that support increasingly accurate inferences about user states, properties, or processes1,16,17. Higher-dimensional neural data have increasingly been recognized as potentially sensitive because they can be pre-behavioral, convey propositional or semantic content, and reflect elements of metacognition18. They can also be individual-specific and evolve over time19–21. Despite substantial diversity in neural data types, attributes of certain forms of neural data are occasionally generalized to all neural data, risking conflation of heterogeneous data streams or flattening of important distinctions, and yielding broad-brush approaches to neural data ethics, privacy, and governance that risk overlooking important differences in sensitivity and inference potential22.
Brain-computer interfaces (BCIs) are systems that record neural activity, extract meaningful features, and translate these into commands that operate an external or internal effector, such as a cursor, speller, prosthetic limb, or stimulating electrode1,23. Implantable BCIs (iBCIs) constitute a subset of BCIs implanted in the central nervous system. Brain signals are typically decoded by machine-learning algorithms to infer intended movements, speech, or aspects of other user states, and, in some cases, the system feeds responsive, targeted stimulation back to the brain1,24. In the process, information about the user’s neural activity may be stored in several forms of iBCI-derived neural data. These include raw neural recordings, processed features, decoded inferences (e.g., reconstructed speech), and personalized decoding models whose parameters (e.g., model weights) may implicitly encode aspects of an individual’s neural activity. iBCIs can differ in neural targets, implant depth, electrode types, decoding methods, outputs, and data flows, which can shape their respective privacy implications25–40 (Table 1).
Table 1.
Representative functional types of implantable brain-computer interfaces (iBCIs)
| Device type | Function | CNS sensing sites | Electrode types | Decoding methods | Data flows and logging | Privacy considerations |
|---|---|---|---|---|---|---|
| Motor interfaces25–28 | Decode intended limb or cursor movement | M1 and premotor cortex, some also S1 | MEA (intracortical), ECoG (surface), and EVA (endovascular) | Linear or adaptive decoders (e.g., Kalman, SVM, and HMM-based) map features (e.g., spike rate, spectral power) to intended movements | Real-time streaming during active use; neural recordings are typically logged on external systems and used for decoder calibration | Longitudinal signatures and external processing raise re-identification risk and may enable new inferences (beyond movement) as decoders improve |
| Speech interfaces29–34 | Decode intended speech to enable communication | Ventral motor/premotor speech areas; language areas | ECoG (surface), MEA (intracortical) | Deep neural networks map spectrotemporal features to phonemes/syllables/units; language models produce sentences | Real-time streaming during active use; neural recordings and inferences are typically stored on external systems and used for model training | Raw data and inferences are sensitive due to semantically rich content and advanced decoding (e.g., of private user conversations); recent work further shows the possibility of decoding aspects of inner speech not intended for communication34 |
| Sensory-restoration interfaces35–37 | Encode sensory information via stimulation to enable perception | Primarily somatosensory or visual cortex | MEA (intracortical micro-stimulation), ECoG (surface stimulation) | Adaptive encoding of perceptual features to stimulation parameters; limited neural recording for mapping, calibration, or feedback | Real-time stimulation during sessions; parameters and perceptual reports are recorded on external systems for post-session calibration | Combined stimulation and perceptual data could reveal sensory experiences, particularly in bidirectional systems |
| Closed-loop therapeutic neuro-modulation38–40 | Detect pathological activity and adjust stimulation | Variable deep brain/cortical targets | Sensing/stimulating DBS leads, RNS depth/strip leads, some additional electrode paddles/strips/arrays | Typically, threshold-based feature detection; sometimes ML-adaptive control | Intermittent sensing and event-triggered logging on-device; potential export during clinical follow-ups | Semantic inference potential is likely limited, though longitudinal biomarkers and metadata may reveal health status, disease risk, cognitive properties, or behavior |
The listed functional device types and their common CNS sites, electrode types, decoding methods, data flows, and privacy considerations provide a simplified, non-exhaustive overview of existing iBCI systems and sources of variability among them.
CNS central nervous system, DBS deep brain stimulation, ECoG electrocorticography (including thin-film surface arrays), HMM hidden Markov model, EVA endovascular array, MEA microelectrode array (including rigid, microwire, and flexible thread arrays), ML machine learning, M1 primary motor cortex, RNS responsive neurostimulation, SVM support vector machine, S1 primary somatosensory cortex.
Despite this variability, many iBCIs produce neural data with a shared set of distinguishing core features: first, many iBCIs can capture single-neuron or small-ensemble activity with millisecond-level temporal resolution as well as substantially higher signal bandwidth and signal-to-noise ratio compared to noninvasive technologies1,41,42. This can make iBCI data more informative about the location, timing, and content of neural representations as compared to devices with lower spatial and temporal resolution. Second, iBCIs are often chronically implanted, and data can thus accumulate over weeks, months, or years1, generating longitudinal data streams43–46. While sampling and logging will often not be continuous, as data may be compressed, buffered, or only certain features exported intermittently to preserve bandwidth, battery life, and storage47,48, long-term use may still reveal rich and individualized neural signatures1,20,49,50. Third, unlike diagnostic recording methods, iBCIs may form feedback loops where decoded neural activity is used to control a device and directly (via stimulation) or indirectly (via sensory feedback or neural adaptation) influences subsequent states43,46,51. The algorithms are usually also adapted to feedback and activity of the patient45,46,49. Finally, iBCI data processing will often involve external processors (due to limited on-device power and computational resources)48 and may interface with programming and monitoring systems1. Therefore, iBCI data may in many cases be linked to clinical or operational metadata, yielding composite individualized datasets.
Advances in thin-film microelectrode arrays have moreover enabled recordings and stimulation of multi-somatosensory, -motor, and -visual activity, as well as high-density recordings of speech-related cortical activity in humans52. One developer has envisioned the possibility of scaling “thousands of electrodes to be rapidly deployed to multiple functional areas without damaging cortical tissue… [rendering it] conceivable to envision deploying a thin-film-based neural interface over the majority of the accessible human neocortex”52. At the same time, other devices are advancing toward increasingly wireless operation and seamless data exchange between implant, external processors, and connected digital systems, including the aspiration toward general-purpose AI ecosystems17,27,53–55.
Alongside advances in sensor materials, new forms of decoding could enhance inferential capabilities. As a result, the informational richness and privacy sensitivity of many iBCI datasets may increase as technologies mature. For example, researchers have recently demonstrated that linguistic information can be reconstructed from cortical areas not traditionally associated with language processing56,57, suggesting that inferences cannot be determined solely a priori by anatomical recording site or initial use purpose. Another recent study showed that even aspects of inner speech not intended for overt communication (as opposed to intended speech) can be decoded from the motor cortex34. While proof-of-concept safeguards, such as keyword-based “unlocking”, have been proposed to prevent unintentional decoding in real time, these measures do not reduce the sensitivity of the raw data themselves, since if one were to gain access to the raw signals, they could, in theory, use a separate model lacking those safeguards to retrospectively decode aspects that the user did not intend to express.
Importantly, the degree to which these features manifest varies substantially across iBCI architectures (for example, speech interfaces designed to decode linguistic content may generate particularly inference-sensitive data, whereas many closed-loop neuromodulation systems may record more limited signals). For analytical clarity, the present analysis treats iBCI data as a common governance subject because they share structural characteristics that can, to varying degrees, generate longitudinal and inference-sensitive neural data warranting oversight consideration, while recognizing that the magnitude and nature of the discussed risks depend on sensor, decoder, and effector properties, inference potential, and use context.
The regulatory landscape of iBCI data protections
iBCI data are protected in different ways worldwide. While the present focus is on the U.S. and the EU, given their widely referenced regulatory models1, iBCI development is also rapidly advancing in other regions, including Australia, Canada, and China, where the first iBCI cleared for post-market clinical use was recently announced58,59. The governance considerations identified here are therefore offered as starting points for collective consideration and local adaptation. Over time, greater international alignment on baseline protections may reduce fragmentation, support multi-site programs, and help ensure that incentives to responsibly innovate and enable clinical access for patients who stand to benefit are not contingent on geography.
In the U.S., regulatory protections that may apply to iBCI data include the Health Insurance Portability and Accountability Act (HIPAA) Privacy and Security Rules, the Common Rule, Food and Drug Administration (FDA) regulations, state-specific laws, and regular consumer protections afforded by the FTC60. These regulations apply to iBCI data under different circumstances. HIPAA protects personal health information (PHI), including clinical iBCI data when flowing through covered entities or their business associates61. HIPAA provides patient rights to access and request amendment of their data, and limits on unauthorized use and disclosure beyond treatment, payment, and healthcare operations purposes61. In addition, appropriate administrative, physical, and technical safeguards are required to ensure confidentiality, integrity, and security of PHI62. The Common Rule sets standards for ethical oversight and consent in federally funded research63, while FDA regulation governs safety and performance of medical devices, including iBCIs, typically classified as Class III devices64. The FDA requires manufacturers to demonstrate premarket cybersecurity controls and to perform post-market vulnerability monitoring, patching, and disclosure65. Finally, the FTC covers iBCI and other data in consumer settings, primarily by restricting deceptive business practices, but offers comparatively thinner proactive data protections66.
In the EU, iBCI data are governed by a layered regulatory framework including the General Data Protection Regulation (GDPR), the Medical Device Regulation (MDR), and the Data Act. In addition, relevant provisions of the EU AI Act and the European Health Data Space (EHDS) will come into effect in the coming years. GDPR is the central personal data protection law and applies to all personal data, including iBCI data. It imposes strict requirements for informed consent, purpose limitation, and the affordance of individual data rights, including rights to access, rectification, erasure, and portability, as well as the right to object to unwanted data processing67. Under MDR, which governs safety, performance, and pre-market approval of medical devices, iBCIs are classified as Class III devices, requiring extensive clinical investigation and post-market monitoring68. Additionally, MDR imposes cybersecurity and data integrity requirements, thereby complementing GDPR68. Most recently, the Data Act, applicable since September 2025, added interoperability and data-access rights for users of connected products, including potentially iBCIs, while preserving trade-secret and safety exemptions and giving explicit precedence to the GDPR for personal data69. The EU AI Act is now in phased application and is set for full applicability in August 2027, though potential timeline adjustments have been proposed70. Under the AI Act, AI systems that function as safety components of medical devices requiring notified-body conformity assessment under the MDR, including iBCIs whose AI components influence clinical outcomes, will be classified as high-risk systems, imposing documentation, dataset quality, and additional security obligations71. To ensure traceability of AI-driven decisions, the AI Act will also require event logging, including, among other information, of model input data, which will likely include aspects of patients’ iBCI-recorded neural signals71. Finally, the European Health Data Space (EHDS), expected to take effect in 2029, will enable cross-border electronic health record access for primary (clinical) use and controlled secondary use of pseudonymized datasets under strict safeguards, including requirements for access solely within controlled environments and prohibitions on re-identification, commercial reuse, or other harmful uses72.
While these existing regulatory frameworks provide essential baseline protections, their practical applicability and enforcement in emerging clinical neurotechnology ecosystems as portended by iBCIs will depend on complementary technical and organizational safeguards. Many regulatory protections hinge on threshold criteria (e.g., whether data are classified as personal or de-identified/anonymized, whether an AI system qualifies as “high-risk”, or whether an entity falls within the scope of HIPAA or GDPR). In addition, iBCI data may traverse multiple institutional actors, such as clinical sites, device manufacturers, cloud infrastructure providers, and AI model developers, including across jurisdictions, which can fragment oversight and enforcement. The ability of enforcement authorities (such as data protection agencies) to investigate and effect protective or corrective action may further be limited by a lack of the technical expertise necessary to evaluate iBCI-specific re-identification and inference risks or to detect covert data misuse. Therefore, the realization of protections in the context of iBCI data, including formal rights, such as access, portability, or erasure, may be more complex in practice than their legal articulation suggests.
The following sections examine central areas of concern and identify key gaps in current iBCI data protections, accounting not only for policy provisions but also operational gaps that could arise in implementation. While some developers have shared ambitions to extend iBCI applications beyond therapeutic contexts and toward enhancement of human capabilities73, the following analysis of gaps focuses on clinical and biomedical research use cases; many of the identified considerations, however, are likely to remain relevant across contexts.
Key gaps in iBCI data protections
Brain biometrics and the de-identification dilemma
First, most existing regulatory protections are loosened if data have been “de-identified” or “anonymized”, rendering iBCI data that have been de-identified in accordance with regulatory standards more open to downstream usage, sharing, and commodification. In the U.S., HIPAA requires the removal of 18 demographic identifiers (“safe harbor”) for data to be considered de-identified and thus no longer subject to its privacy protections, provided the handling entity does not have actual knowledge that the remaining data could be used to identify the individual61. An alternative under HIPAA is the Expert Determination method, where an expert, defined as an individual with “appropriate knowledge of and experience with generally accepted statistical and scientific principles and methods for rendering information not individually identifiable”, certifies that the risk of re-identification is “very small”61. In the EU, GDPR similarly does not apply to data that are anonymized, provided that the re-identification is not possible by any means “reasonably likely to be used”62, though the 2025 Digital Omnibus proposals, if adopted, could narrow this definition by clarifying that data are not considered personal data for an organization unless that organization itself has realistic means to re-identify the individual, even if others do74,75.
However, evidence suggests that many existing de-identification methods are vulnerable to re-identification using novel machine learning techniques and therefore only offer limited privacy protection, particularly for high-dimensional datasets76–78. In genomic research, de-identified sequence databases have been successfully linked back to individuals through surname inference and relatedness mapping79,80. Similar vulnerabilities appear in biomedical imaging, where deep-learning models have been shown to be able to match independent chest-X-ray images of the same patient with over 95% accuracy81, and functional-connectivity patterns have enabled subject re-identification across separately released fMRI datasets82.
While comparable re-identification or linkage attacks have, to our knowledge, not yet been reported for iBCI data, EEG signatures have long been recognized as a potentially potent biometric identifier due to their marked inter-individual variability and intra-individual stability20,21,83,84. Given their substantially better signal fidelity, bandwidth, and resolution as compared to surface EEG41,85, iBCI recordings could, a fortiori, plausibly be similarly or even more uniquely identifying. While empirical evidence for this hypothesis remains limited, the absence of published attacks specific to iBCI datasets might reflect the relative novelty, limited scale, and limited public availability of such data, rather than evidence of robustness against re-identification. In fact, neural activity patterns underlying intended movements or phonemes have been found to vary significantly across individuals, which is why many iBCI systems rely on personalized decoders1,49. Finally, the likely use of iBCI data to train subsequent generations of decoders could also create the potential for membership inference attacks, where one can retrace whether an individual’s data were part of a model’s training dataset86,87, underscoring that privacy risks may persist even for nominally de-identified iBCI data. Notably, the magnitude of these risks will vary across iBCI architectures, depending on signal resolution, logging practices, data flows, and the richness of decoded outputs.
While several technical and organizational privacy-preserving security techniques have been proposed to mitigate risks of re-identification, the extent to which such safeguards adequately protect iBCI users requires further empirical study. Differential privacy describes an approach where statistical noise is added to preserve aggregate patterns while obscuring individual contributions77,88. Differential privacy can directly reduce the success of inference attacks, but often at the cost of degraded model performance and applicability primarily to large or aggregated datasets rather than individual-level data88–90. Federated learning, in which models are trained locally and only parameter updates are shared, reduces the need to exchange raw data, thereby limiting opportunities for re-identification attempts91,92, yet remains vulnerable to membership inference and reconstruction attacks from the full model93,94. Approaches such as federated data access or secure enclaves, which allow computation within protected environments95,96, may reduce exposure by containing data use to trusted infrastructures, but do not themselves anonymize the underlying data. These limitations bear on two distinct questions: whether technical methods can meet legal thresholds for de-identification, and whether those thresholds themselves are adequate for iBCI data. While a combination of the discussed technical and organizational measures might meet these legal thresholds (this warrants further investigation), the thresholds themselves may not adequately account for the inference and re-identification risks associated with high-resolution iBCI data, raising questions about the continued reliance on “release-and-forget” models in this context.
Personal control and rights over iBCI data
Even non-de-identified iBCI data may sometimes fall outside the protections that might be assumed to attach to them by virtue of accruing through a medical device. In the U.S., for instance, developers may be able to structure data flows so that neural data are not created, received, maintained, or transmitted on behalf of a HIPAA-covered entity, placing them outside HIPAA’s scope97–102. Even when regulatory protections do apply, they often do not give patients comprehensive control or rights over their data. Under HIPAA, patients are not guaranteed the right to delete (“to be forgotten”), to withdraw from downstream uses, or to receive their data in a portable format when switching providers. In the EU, GDPR offers a broader array of individual rights, but their practical application to iBCI data remains uncertain, especially where iBCI data have been integrated into AI models. Unlike raw recordings, preprocessed features, or inference readouts, which can in principle be rectified or deleted provided all storage locations are known, iBCI data embedded in AI models can become difficult to single out. While individually personalized decoders that are only used by the patient in question may be comparatively straightforwardly adjusted, the integration of data into global models that are not only trained across multiple participants but also distributed and used widely, by multiple iBCI users, could make rectification or erasure infeasible in practice. Thus, iBCI systems that rely on centralized, multi-user model training and external data storage may pose particular barriers to rectification and erasure. These issues grow sharper as groups begin to study “cross-brain transfer” of iBCI recordings across users to boost decoder performance and ease training burden103.
Emerging techniques could help address these challenges. Machine unlearning refers to methods that allow a trained model to selectively remove the influence of specific data points without retraining from scratch, often by modifying model parameters to approximate a state as if the data had never been seen104,105. In recent proof-of-concept work, such methods were able to reduce membership-inference risk in seizure-prediction models106 and to remove unwanted data influence from MRI-reconstruction models107, in both cases while largely preserving model performance. However, they remain only partially effective and difficult to apply comprehensively if not all of a given model’s copies’ locations are known or accessible, and their applicability to large, high-dimensional datasets, such as longitudinal iBCI recordings, is yet to be explored. Complementary traceable data-lineage frameworks, such as “AI model passports” that document data sources, transformations, and model versions108, could, when combined with machine unlearning, support technical reversibility for personalized decoders or global models, while blockchain approaches could strengthen auditability and consent management by recording access logs and permissions immutably on-chain109,110, though these approaches likewise remain largely untested for iBCI data.
Beyond erasure and rectification, iBCI users may seek to access, share, or transfer their data for purposes such as independent analysis, switching devices, or participation in community-led research initiatives, as recently highlighted by members of the BCI Pioneers Coalition111. This underscores the importance of data portability. However, effective iBCI data portability is challenged by the fact that there is not yet a mature or widely adopted iBCI interchange format capable of supporting cross-platform migration. While several general neurodata standards exist, such as neurodata without borders112, the brain imaging data structure (BIDS)113, and BIDS extensions for EEG114 and iEEG115, these frameworks were designed primarily for retrospective research datasets rather than operational iBCI systems that decode neural activity and interface with effectors in real time, and they do not define standardized provisions for representing decoder architectures and parameters, closed-loop- or effector-control signals, and device-specific timing or synchronization metadata, all of which are important for effective iBCI data portability.
Standard-setting bodies are beginning to address these gaps: the IEEE Standards Association’s working group on “Reporting Standards for in vivo Neural Interface Research” has a subgroup for “invasive central nervous system interfaces”116, and the International Organization for Standardization (ISO) together with the International Electrotechnical Commission (IEC) are developing a recommendation specifically for an “Invasive BCI Multi-modal Neural Data Format”117. These initiatives are a promising step, though adoption will likely be voluntary and may be limited by technical heterogeneity, commercial incentives, or vendor lock-in.
Ultimately, despite their importance for preserving patient autonomy, enforceable individual rights over iBCI data remain underdeveloped and difficult to operationalize under current governance frameworks. In addition to uneven data standards and governance, exercising individual iBCI data rights is complicated by the complexity of the data lifecycle itself, wherein implanted hardware records signals that are transformed by often-proprietary acquisition and decoding pipelines before being streamed to effectors. In this process, each stage could produce derivative artifacts under different custodians. Coordinating user access, deletion, or transfer across this chain is operationally complex and, at present, seldom supported end-to-end.
Limits of iBCI informed consent
A central safeguard in ensuring alignment of expectations around iBCI data management is the informed consent process. In its optimal form, this process comprehensively and transparently informs individuals about data practices and enables autonomous decision-making118. In an interview-based study with noninvasive neurotechnology users, participants indicated a desire for greater transparency about how neural data are used and shared, with many reporting they wished for clearer explanations before using these technologies119. Although comparable empirical results for iBCI users are not yet available, the sensitivity and richness of neural data derived from some iBCIs make it reasonable to anticipate that this population would similarly desire clear and robust disclosure regarding how their data are accessed, shared, and used over time.
Importantly, although some may contend that competent adults are free to assume risks and ramifications of iBCI data practices through voluntary informed consent, there are internal limits to what consent can ethically authorize, particularly in settings of significant vulnerability, limited alternatives, or high stakes120. Individuals currently eligible for iBCI clinical trials (and future clinical uses) characteristically harbor severe neurological conditions (e.g., ALS, brainstem stroke, spinal cord injury with paralysis), which may not only complicate the consent process due to concomitant communication challenges but often generate a sense of desperation for an iBCI that may promise to restore function. Currently, however, consent for iBCI implantation and use may often be merged with consent for how iBCI data will be used, owned, and shared. This overlap may generate undue inducement if patients are not clearly informed about, and given a say in, iBCI data-related agreements without jeopardizing their device eligibility. Requiring individuals to accept a potentially disadvantageous iBCI data agreement as a prerequisite for receiving an iBCI thus raises ethical concerns and could undermine the integrity of consent processes. In some clinical trials, these concerns may be amplified by funder expectations for broad data sharing, which can place investigators in tension between the values of open science and the obligation to respect patient autonomy and privacy121.
Limited guardrails against misuse
Concerns about the integrity of the informed consent process are magnified by limited explicit protections from harmful use or particularly sensitive inferences. While GDPR has a purpose limitation provision and HIPAA limits PHI use and disclosure without authorization, these protections lose force once data have been de-identified, and HIPAA’s protections may additionally be circumvented if data flows are structured outside the purview of covered entities. For fully identifiable data, a primary guardrail under both regimes is informed consent.
Neither regime categorically restricts particularly sensitive or high-risk downstream uses, though there are some complementary safeguards, especially in the EU. Because patients with severely impairing neurological conditions frequently face limited therapeutic options and a pressing need to restore or maintain function, it is possible that some patients may find themselves consenting to data practices unrelated to the clinical purpose of the implant to gain access to an iBCI device. The plausibility and severity of these risks will depend on the type of neural signals collected, the extent of decoding, and whether systems generate semantically rich outputs (like many speech interfaces) or primarily physiological control signals (as in closed-loop neuromodulation devices).
Cross-use for unanticipated purposes, such as model pre-training or commercial analytics by downstream data processors, may occur once iBCI data leave the immediate clinical setting. In the EU, such cross-use would generally require explicit consent unless the data are de-identified67, though proposed amendments under the European Commission’s Digital Omnibus package would introduce an exception allowing processing of identifiable special-category data (including health data) for bias detection and correction in AI systems70. In the U.S., HIPAA allows “business associates”, including cloud infrastructure providers, to process identifiable data without additional consent when doing so supports “treatment, payment, or healthcare operations”61. However, as illustrated by Project Nightingale, where a nonprofit health system shared millions of medical records to develop and train predictive AI models122, such arrangements can occur in ways not anticipated by most patients and unlikely to meet expectations of confidentiality. Even greater risks arise once medical data are voluntarily transferred into non-HIPAA-covered environments, such as companion apps marketed for wellness or performance optimization. Under current U.S. law, even data originating within HIPAA-covered settings lose protection once exported to third-party apps that do not act on behalf of a covered entity123,124. Consequently, companion apps linked to iBCIs could conceivably reuse iBCI data not only for clinical optimization but also for unrelated commercial purposes, including targeted “neuromarketing”8,125, provided they do not actively mislead users. Health and wellness apps have repeatedly been shown to share personal data with third parties126,127, underscoring potential privacy risks to iBCI users once data move outside traditional healthcare settings.
Another potential misuse scenario is that of workplace monitoring. Commercial EEG systems have already been deployed to track workers’ focus and emotional states128,129. In the EU, this would generally be incompatible with GDPR’s requirement that consent must be “freely given”, given the power imbalance between employer and employee, unless necessary for fulfillment of employment health and safety obligations67. In addition, EHDS prohibits the use of electronic health data accessed through its framework for “detrimental” decisions in areas including employment and insurance, and AI systems used for employment monitoring will be considered high-risk under the AI Act (except for workplace emotion monitoring, which will be prohibited barring medical or safety reasons)71. In the U.S., however, consent obtained as a condition of employment is generally considered legally valid, and while the Genetic Information Nondiscrimination Act (GINA) prohibits employers from requesting or using genetic information in employment decisions130 and the Americans with Disabilities Act bans discrimination based on impairment131, neither statute clearly addresses discrimination based on non-genetic cognitive performance metrics, such as iBCI-derived inferences of focus, unless they are treated as evidence of a disability. Related concerns arise in insurance settings, where medical and non-medical data are increasingly combined into “risk scores” that can influence pricing, eligibility, and benefits132. For individual and small group Affordable Care Act-compliant health plans in the U.S., premiums and eligibility generally cannot be based on health status133, and GINA separately bars the use of genetic information for health insurance underwriting130, but these protections do not extend to short-term health plans and life, disability, and long-term-care policies, where risk-based pricing based on health data remains common134. While EHDS’ secondary use framework will prohibit detrimental insurance decisions based on data accessed through EHDS itself72, EU insurers’ use of health information obtained through other methods remains governed by Member State law, under which some categories of private insurance may lawfully use medical data for risk-based pricing135. As iBCI systems mature, their outputs could thus become one more input into risk profiling practices. While it is unlikely that these possibilities will materialize in the near future, given the currently limited clinical penetration of iBCIs, the high cost and invasiveness of implantation, and the absence of employer- or insurer-side incentives to utilize such data, they remain conceptually plausible without stronger protections, and related risks could crystallize as iBCIs become more widely deployed and commercially interoperable.
A separate vector of risk is introduced by the possibility of compelled disclosure for law-enforcement purposes. In the U.S., even if iBCI data are retained within the purview of HIPAA, PHI disclosure may be permissible to law enforcement without patient consent in response to court orders or, provided certain relevance and specificity criteria are met, administrative requests61,136. Comparable access in the EU is possible but subject to stricter safeguards, requiring necessity-proportionality assessments and independent oversight137. For iBCI users, such disclosures could extend to longitudinal recordings and inferences, which raises complex legal-ethical questions around mental privacy and self-incrimination138,139, particularly given emerging evidence that aspects of inner speech may be inferred from iBCI data34. For example, if an iBCI user performs an action or communication through their device that is later alleged to violate the law, it is uncertain whether authorities may access only evidence of the final output or also the upstream neural signals that generated it. Although such scenarios are improbable in the near term owing to the small number of iBCI users, the technical difficulty of extracting and interpreting upstream neural signals, and the absence of relevant legal precedent, their plausibility will likely increase as iBCIs move from research environments into broader clinical use. Recognizing these gaps, in 2026, the Office of the UN High Commissioner for Human Rights issued a call for input on “risks and required safeguards regarding the potential use of neurotechnology and other emerging technologies in the administration of justice”140.
Finally, while primarily a data security issue rather than a data protection gap, there are also illegal pathways to misuse, such as side-channel attacks capable of intercepting or modifying neural data streams141,142. These highlight the parallel need for iBCI-specific cybersecurity measures and technical standards to protect both data privacy and patient safety143.
Underspecified ownership and the potential for monetization
Finally, existing regulations leave the question of iBCI data “ownership” underspecified, allowing iBCI data to be monetized with limited guardrails or patient benefit. While patients have certain rights over their medical data in both the U.S. and the EU, they do not possess comprehensive property or intellectual property (IP) rights, which traditionally include the ability to fully exclude others, alienate (transfer or sell), or share in downstream profits144–146. Rather, entities generally retain broad discretion over iBCI and other medical datasets in their custody: Once data are de-identified or explicit consent is obtained, they can generally be reused or monetized freely, without clear guardrails or mechanisms for patients to share in resulting benefits145,146.
Although health data ownership is a topic of long-standing debate in health law scholarship144–148, the unique features of iBCI data cast it in new light: in particular, the tight link between high-resolution neural signals and patients’ cognition and communication could be considered to create a more legitimate personal claim to ownership or control over the monetization of one’s iBCI data compared to other medical data. That said, the degree of inference sensitivity varies across iBCI device types, and monetization concerns will likely be most acute for systems that generate data with particularly strong inference potential, like many speech interfaces. Survey work with BCI researchers suggests that many view BCI-derived data, including those from iBCIs, as raising distinctive questions about user control, particularly once data flow outside the clinical setting, though most of those surveyed did not endorse treating BCI data as personal property149. The paucity of clear legal guidance regarding ownership and monetization could create tensions as iBCIs move into clinical practice, where reality may not meet all patients’ expectations of control over their iBCI data.
Emerging governance efforts
Despite these challenges, governance efforts tailored to iBCI data have generally been absent, even though several jurisdictions have begun to address neural data protection more broadly7. Some U.S. states have passed their own privacy laws, and Colorado, California, and Vermont have explicitly recognized neural data as sensitive personal data150–152. Moreover, the Uniform Law Commission is now convening a committee on “Mental Privacy, Cognitive Biometrics, and Neural Data”, which aims to guide future lawmaking on the topic153, and a group of U.S. Senators introduced the MIND Act for protection of consumer neural data5. Chile and Spain have each explicitly recognized the importance of personal rights related to neurotechnology154,155. These legislative advances have been influenced by calls for the explicit recognition of “neurorights” like the rights to mental privacy, mental integrity, psychological continuity, and cognitive liberty7,10. UNESCO’s 2025 Recommendation on the Ethics of Neurotechnology also echoes these themes, calling for greater oversight6.
However, most of these initiatives treat neural data as a unitary category, overlooking important differences in spatiotemporal resolution, data flows, and inference potential across technologies. While recent scholarship has urged lawmakers to shift from pure neural data governance toward the notion of inference-sensitive “cognitive biometric data” (including neural and non-neural data with substantive capacity for mental state inference)8, previous cognitive biometric and neural data-related governance efforts have primarily focused on consumer technology, sometimes explicitly exempting medical data regulated through existing health data frameworks150,151. As a result, such efforts have tended to give less sustained attention to the most sensitive types of neural data, such as clinical iBCI data. This leaves open important questions about how far current approaches can address the persistent challenges identified in clinical iBCI contexts.
Closing gaps in iBCI data protections
A variety of approaches could be taken to close the identified gaps. Some may argue that iBCI data are a fundamentally value-laden expression or part of the self that ought to be protected by an extended right to bodily integrity156. However, this is challenged by the recognition that there is a clear distinction between bodily tissue and data derived from an individual that are not part of their organism. Acknowledging this issue, others have proposed to instead protect neural data (as an umbrella category that implicitly includes iBCI data) by a right to psychological integrity, arguing that they are analogous to neurocognitive properties of the brain157. That said, it is difficult to ignore the fact that neural data (unlike neural activity) can be replicated and distributed, and that manipulating a person’s neural or iBCI data does not necessarily affect their mind. While protections are clearly necessary, iBCI data are still data: non-physical, replicable, and shareable.
Another approach could be to apply a property or IP model to iBCI data. At first glance, this may appear appropriate given the close connection between iBCI data and patients’ mental states and may seem to address several of the identified gaps: it could provide a legal basis for constraining post-de-identification “release-and-forget” data flows, strengthen individual control, including over monetization, and potentially mitigate some forms of misuse. However, it is unclear whether property or IP rights would materially improve on existing data governance frameworks, as many of the identified challenges involve downstream control, secondary use, and enforcement rather than legal ownership, which, unlike data rights tied to the individual, may be transferred away146. A property-based approach may also introduce undue pressure on patients to license or sell iBCI data146,147 and may slow data sharing and scientific progress by fragmenting access permissions158.
Recognizing these concerns, most jurisdictions have not adopted comprehensive personal property rights for medical data, and most academic scholarship is critical of such proposals144–146. While some U.S. states have designated limited categories of patient data as “property” (e.g., medical records in New Hampshire159; genetic information in several other states160), these provisions have in practice added little beyond existing HIPAA-style access and confidentiality148. Other frameworks tend instead to confer rights to data curators or processors rather than the individuals whom the raw data were recorded from. For example, the EU’s sui generis database right gives database “makers” exclusive rights to prevent extraction and re-use of substantial parts of the database161, and China’s emerging data property rights system aims to grant rights to use, license, and profit from value-added “data products”, while individual personal data (including medical, neural, and iBCI data) are expected to remain governed under privacy and data security law162,163.
Beyond practical challenges, there is a conceptual difficulty in applying property or IP frameworks to iBCI data: while people can own intellectual creations or physical objects, iBCI-recorded neural signals are not necessarily identical to raw ideas, typical creations, or biological material. Between the organic neural activity occurring in the brain and the data ultimately captured, there is a long chain of transformations: signals must be detected, amplified, filtered, subjected to feature extraction, and represented through algorithms before any meaningful output is produced. At each stage, iBCI data become increasingly entangled with device-specific engineering and external processes. Because these processed signals are not in a one-to-one relation of identity with the underlying neural events or cognitive states, and because they reflect layers of developer innovation and machine interpretation, the boundary between what “belongs” to the user and what is the product of iBCI design becomes blurry. Therefore, the application of property or IP frameworks to iBCI data would be practically and conceptually challenging and unlikely to resolve the gaps identified.
In light of the foregoing challenges, we propose a tailored and multi-layered approach that seeks to address the identified gaps in a risk-proportionate manner. These suggestions are intended to be considered across the various clinical and research contexts in which iBCI data are generated and aggregated, including industry-sponsored trials, clinical deployments, and publicly-funded academic studies, though their implementation should be calibrated to context and available resources, recognizing that smaller research settings may face different resource constraints than large commercial actors. This applies particularly to the suggested emerging technical safeguards, such as differential privacy, machine unlearning, blockchain-based consent management, and traceable data lineage, as well as to the more exploratory governance proposals, such as inference-sensitive use restrictions and benefit-sharing models, whose feasibility and suitability across specific iBCI deployment contexts remain to be established. Implementing the presented framework will require efforts not only from policymakers, but also, of equal importance, from clinicians, researchers, and developers working with iBCIs, as well as the input of iBCI users and their care partners.
Addressing the de-identification dilemma
To address the de-identification dilemma, opportunities exist to sensitize de-identification standards to the realities of modern re-identification methods. De-identification should be treated as one necessary but not sufficient layer of privacy protection, rather than a decisive threshold after which all downstream protections cease to apply. Primary responsibility here lies with iBCI developers and researchers for the implementation of robust de-identification methods, and with regulators and funders for setting minimum standards and oversight expectations.
To ensure that de-identification is as effective as possible, clinicians, researchers, and developers engaged in iBCI work could apply differential privacy or related privacy-preserving measures where possible. Developers and researchers could also consider red-teaming approaches (where adversarial attacks are simulated to identify and patch weaknesses164) to test and demonstrate the robustness of de-identification methods within their specific devices and data modalities, rather than relying on a monolithic model like HIPAA’s safe harbor or the judgment of de-identification experts without iBCI-specific expertise. Recognizing that even state-of-the-art de-identification may not provide definitive protection, iBCI data sharing for secondary use could, whenever possible and including when data have been de-identified, be paired with auditable access environments, such as secure enclaves or federated access frameworks, particularly in the case of iBCI systems that generate especially high-dimensional, longitudinal, or semantically rich datasets, like many speech interfaces. In tandem, ongoing implementation science research and real-world testing of effective de-identification and cryptography methods for iBCI data specifically are needed.
On the regulatory side, community efforts could be supported through positive incentive structures, for example, by making demonstrated privacy due diligence for de-identified iBCI data a prerequisite for public funding, similar to existing NIH data sharing requirements165. Ongoing policy deliberations create an opportunity to examine how emerging reforms might affect privacy standards for iBCI data and other kinds of data that may be particularly vulnerable to re-identification, and to explore targeted carve-outs or safeguards where warranted. Finally, policymakers in the U.S., EU, and beyond could explore extending selected protections to nominally de-identified iBCI data, including by recommending or requiring, as a condition of regulatory approval, the complementary use of auditable access environments when sharing for secondary use, thus keeping data traceable, and, where appropriate, maintaining certain data subject rights like the right to erasure, discussed in more detail below.
Strengthening personal control and data rights
To augment individual control over iBCI data, technical mechanisms and standards development to enhance patient agency, alongside appropriate data rights like those to erasure and portability, could be fostered. Effective implementation will require simultaneous action by developers, standard-setting bodies, and regulators.
Specifically, in parallel with the privacy-preserving approaches discussed above, iBCI developers and researchers may consider implementing traceability mechanisms, such as auditable data access logs and model-lineage tracking tools (e.g., via AI model passports108). In addition, future work could explore the effectiveness, safety, and practicality of “smart-contract” blockchain approaches109 (e.g., limited to on-chain storage of metadata or access-control tokens) to enable patient real-time decision-making over secondary access and use, supporting dynamic, longitudinal consent. On the model development side, decoder training pipelines may be designed in ways that preserve the feasibility of selective deletion of individual subject influences, for example, via SISA-like (sharded, isolated, sliced, and aggregated) training105. These measures would primarily operate on iBCI data, model training procedures, and access metadata stored outside of the implant itself, and so their feasibility would likely not be substantially affected by its real-time, power, and safety constraints. That said, engineering costs and potential clinical risks in the context of iBCIs warrant further investigation, and the necessity and feasibility of such measures will likely vary depending on whether the specific iBCI datasets in question are only used for personalization or also for training global models to be deployed across users. Continued iBCI data standards-development efforts, such as those by ISO and IEC, can ensure interoperability and more uniform applicability of data security approaches across iBCI systems. Importantly, inclusion of iBCI-specific information, such as decoder parameters, effector-control signals, and synchronization metadata, can support effective data portability.
To support these efforts, opportunities exist to create incentives for the adoption of technical standards, such as via making adherence to recognized iBCI data storage standards an expected part of approval submissions, similar to established FDA expectations around imaging format interoperability166. Similar mechanisms may be considered for data or model traceability methods, though further work is needed to stress-test such methods and identify the optimal approaches for clinical iBCI data prior to regulatory action. Finally, jurisdictions that do not currently grant portability or erasure rights for medical-device-generated data, such as the U.S. under HIPAA, could consider targeted regulatory extensions for iBCI data through agency rulemaking (e.g., by the U.S. Department of Health and Human Services) or statutory amendments, recognizing their privacy and autonomy implications.
Unifying iBCI informed consent
To address limitations in current iBCI consent practices, informed consent for iBCI data use and sharing could be established as a distinct, longitudinal, and standardized process. Here, particular responsibility lies with clinicians, researchers, and developers, while regulatory endorsements or requirements could play a supporting role.
In the short term, where most iBCIs are solely available as part of research studies, clinicians, researchers, and developers are best positioned to ensure that individuals are comprehensively counseled about device-specific data-related risks, benefits, and uncertainties, including the plausible need to process and analyze data for research purposes. Opportunities exist to design this process as explicitly longitudinal, with patients empowered to opt out of non-essential provisions throughout. As iBCIs transition into clinical practice, where therapeutic benefit, rather than the collection of research data, may be the primary goal, data-related consent should be disentangled from consent for device implantation and clinical use, to ensure that access to a clinically necessary and potentially life-changing device does not depend on agreeing to potentially wide-ranging data reuse terms. In research contexts, funders could consider calibrating data-sharing expectations for high-resolution iBCI datasets, so that open-science requirements remain proportionate to, and do not inadvertently undermine, the exercise of data-related autonomy and informed consent in the context of iBCI recordings. To facilitate implementation, future work is needed and underway to develop a standardized template for iBCI consent, adaptable to device architecture and inference potential, and incorporating explicit data-related considerations167.
Once a standardized consent template exists, professional bodies and regulators such as the FDA could endorse it via guidance or, where feasible and appropriate, conditional incentives linked to regulatory approval. In investigational contexts, iBCI-specific informed consent criteria could be integrated into institutional review board (IRB) review processes where appropriate.
Establishing guardrails against misuse
To minimize risks from misuse, secondary use of iBCI data could be limited to clearly defined and authorized use cases. Responsibility for preventing misuse lies with iBCI developers, data holders, and controllers, supported by (and subject to) regulatory guidance and enforcement.
Complementing privacy- and control-enhancing measures as well as comprehensive informed consent, providers could consider explicitly counseling patients about sharing iBCI data with third parties, such as companion applications, whose terms and conditions may contain permissive secondary-use clauses, circumventing HIPAA or even GDPR safeguards. Clinical sites and manufacturers may explore applying an iBCI-adapted form of the Mental Data Protection Impact Assessment, an inference-sensitive, anticipatory risk assessment model for the processing of data that can be used to infer cognitive, affective, or conative mental states168. In adjusted form, this could be used to structure device architecture-sensitive pre-release review of secondary iBCI data uses that are not prohibited or directly covered by patient consent (e.g., use of de-identified data or use of identifiable data for medical AI model training), complementing existing purpose-limited business associate agreements (under HIPAA) and data processing agreements (under GDPR) between healthcare providers and external processors, which contractually restrict downstream processing purposes but do not systematically evaluate inference-level risks, and may not fully prevent problematic secondary use even of identifiable medical data, as illustrated by Project Nightingale122. Finally, future work is needed to convene multiple stakeholders, including clinicians, researchers, developers, ethicists, regulators, patients, and individuals with lived experience of iBCI use, to articulate iBCI-specific guidance that distinguishes clinically or scientifically justified use cases from ethically problematic ones, informed by criteria such as clinical necessity, proportionality, and availability of alternatives.
Building on such guidance, regulators with authority over data processing or device deployment may consider restrictions of particularly harmful downstream uses (which has previously been discussed for neuroscience data broadly169), enforceable through supervisory authorities with penalties or sanctions for non-compliance. Precedent to build upon exists both in the U.S., where GINA protects genetic data from misuses like health insurer and employment discrimination130, and in the EU, where the AI Act explicitly prohibits certain AI use cases, such as emotion-inference tools in employment and education contexts71. For iBCI data, harmful use restrictions could, among other cases, explicitly proscribe personalized advertising, employment-related monitoring, and insurer risk profiling, while law enforcement access could be made subject to heightened judicial scrutiny. While prior work has focused on using inference potential to define a protected data category (cognitive biometric data8), this approach could directly govern the permissibility of specific high-sensitivity inferences (like intended speech, affective states, or mental imagery), for example, by limiting their use to medically necessary, neurorehabilitative, neurorestorative, or biomedical research settings.
Fostering benefit-sharing and responsible monetization
To address ethical issues surrounding the commercialization of iBCI data, community benefit-sharing models may be explored, and monetization of iBCI data could be limited to appropriate clinical or scientific purposes. Primary responsibility here lies with developers and data-holding institutions, in dialogue with patient communities, with regulators playing a boundary-setting and enabling role where appropriate.
In the near term, as part of the informed consent process, clinicians, researchers, and developers should clearly communicate relevant data rights to prospective iBCI users, including expectations surrounding ownership or benefit-sharing over iBCI data, and how de-identified datasets might be reused or potentially commercialized downstream. In parallel, exploratory work could assess mechanisms by which downstream value derived from iBCI data might be re-channeled into work that supports patients and patient communities, potentially drawing from health data cooperative models that emphasize patient-centered governance170. Such benefit-sharing frameworks could, for example, re-invest portions of downstream value (e.g., derived from licensing or eventual product commercialization) into patient-led research funds, advocacy efforts, or access programs. Future work is needed to systematically integrate patient advocate, clinician, developer, legal, and neuroethics perspectives when evaluating iBCI monetization models, so that iBCI data value flows are aligned with fairness, transparency, and shared benefit171,172.
Regulators could support the development and evaluation of such models through publicly funded pilots and patient engagement initiatives. If these models prove fair, feasible, and effective, regulators and funders could encourage adoption through guidance, funding, or reimbursement conditions. Finally, regulators may also consider measures aimed at limiting monetization of iBCI data to purposes with demonstrable clinical or scientific value, though further work is needed to define evaluation criteria, feasible enforcement mechanisms, and appropriate governance strategies.
Cross-cutting implementation considerations
The foregoing proposals may contribute to tailored, risk-proportionate, and multi-layered approaches to iBCI data governance. They are intended as a basis for appropriately nuanced, collective deliberation as the iBCI field continues to rapidly evolve. The breadth of measures discussed reflects the range of iBCI architectures, risk profiles, and deployment contexts they are meant to span, rather than a uniform set to be adopted in full; in a given setting, only a proportionate subset may be warranted. Although governance and regulatory mechanisms vary internationally, the structural and technical features of iBCI systems that give rise to the identified gaps in protections, as well as many of the corresponding safeguards examined here, are not jurisdiction-specific. Notably, near-term progress is likely to depend primarily on non-regulatory governance mechanisms, professional community efforts, and technical safeguards, rather than on new or substantially revised regulation, which can be slow and subject to institutional inertia.
Where regulatory efforts are nonetheless needed, they could be implemented through existing statutory authorities (e.g., data protection authorities or medical device regulators), rather than through entirely novel, bespoke, ad hoc, or idiosyncratic institutional structures or legislation, and they should stay adaptive to the rapidly evolving technical landscape, for example by including sunset clauses, which ensure regular reassessment of their respective statutes, or other planned adaptive regulation tools173. Potential regulatory measures should be calibrated to differences in neural data types, as well as to differences in the inferences and use cases they support. Broad, undifferentiated categorization risks unnecessarily constraining responsible innovation for patient populations with urgent unmet needs and paradoxically creating potential blind spots for the most sensitive data types or uses, including those involving iBCI data. Across relevant regulatory, clinical, or commercial entities, experts in neural and iBCI data privacy could be integrated into existing oversight structures such as institutional privacy offices, data access committees, and IRBs, to monitor and advise on neurotechnological developments and evolving protection needs. Resourcing will vary by context and may involve coordinated support across academia, industry, professional societies, funders, and regulators.
In parallel, empirical work will be essential to identify past, current, and prospective iBCI users’ experiences and preferences related to data privacy, as well as iBCI clinicians’ knowledge of the identified issues. This could inform near-term guidelines for consent and communication as well as long-term regulatory priorities and policy design. In addition, continued technical research is needed to empirically characterize re-identification and inference risks for iBCI data specifically and to explore the robustness and practical applicability of privacy- and autonomy-preserving approaches, including but not limited to differential privacy, secure enclaves, and machine unlearning. Clarifying technical capabilities and limitations surrounding iBCI data will help balance privacy protections with the need for research that may depend on large, representative datasets.
Forward-looking outlook
As governance discussions unfold, opportunities exist for iBCI stakeholders to be mindful of these issues and to proactively incorporate education about them into program design. Clinicians and researchers may play important roles in counseling patients about how iBCI data may be used or shared, which uncertainties exist, and which rights are present, absent, or uncertain. As iBCIs transition from research to clinical practice, data protection frameworks, professional norms, and associated safeguards will need to evolve alongside them. Ongoing technical research, professional community efforts, and regulatory support can help ensure that patient privacy, autonomy, and trust are maintained without hindering the immense promise that these innovations hold for patients worldwide.
Acknowledgements
Figure 1 was created in BioRender (https://biorender.com/5vzqxk5) with an icon used with permission under a premium Flaticon license. We thank the anonymous reviewers for their valuable feedback, which greatly improved this manuscript.
Author contributions
J.D.S.: conceptualization; investigation; writing-original draft; writing-review and editing. M.J.Y.: conceptualization; investigation (supporting); supervision; writing-review and editing.
Peer review
Peer review information
Communications Medicine thanks Li Jiang and the other anonymous reviewer(s) for their contribution to the peer review of this work.
Funding
No specific funding was received for this work. M.J.Y. has received research support from NIH-NINDS K23NS140495, NIH BRAIN Initiative (F32MH123001), Mass General Neuroscience Chen Institute Transformative Scholars Award; NIH Common Fund’s Bridge2AI (OT2OD0327); DOD CDMRP (HT9425-24-1-1081); and the American Academy of Neurology (Palatucci Advocacy Award). The perspectives herein are those of the authors and do not necessarily reflect the views of any institution, department, or organization.
Competing interests
J.D.S. has nothing to declare. M.J.Y. has received research support from the NIH BRAIN Initiative, Mass General Chen Institute Transformative Scholars Award, NINDS, Department of Defense, and the American Academy of Neurology. M.J.Y. is employed by MGH/MGB. The MGH Translational Research Center has a clinical research support agreement (CRSA) with Ability Neuro, Axoft, Medtronic, Neuralink, Neurobionics, Precision Neuro, Synchron, and Reach Neuro. Mass General Brigham (MGB) is convening the Implantable Brain-Computer Interface Collaborative Community (iBCI-CC); charitable gift agreements to MGB, including those received to date from Paradromics, Synchron, Precision Neuro, Neuralink, and Blackrock Neurotech, support the iBCI-CC.
Footnotes
Publisher’s note Springer Nature remains neutral with regard to jurisdictional claims in published maps and institutional affiliations.
References
- 1.Patrick-Krueger, K. M., Burkhart, I. & Contreras-Vidal, J. L. The state of clinical trials of implantable brain–computer interfaces. Nat. Rev. Bioeng.3, 50–67 (2025). [Google Scholar]
- 2.Miller, K. J. & Abosch, A. A moment of reckoning for implanted brain-computer interface studies. Neurosurgery97, 277 (2025). [DOI] [PMC free article] [PubMed] [Google Scholar]
- 3.Price, W. N. & Cohen, I. G. Privacy in the age of medical big data. Nat. Med.25, 37–43 (2019). [DOI] [PMC free article] [PubMed] [Google Scholar]
- 4.UN Human Rights Council. Foundations and Principles for the Regulation of Neurotechnologies and the Processing of Neurodata from the Perspective of the Right to Privacy. https://www.ohchr.org/en/documents/thematic-reports/ahrc5858-foundations-and-principles-regulation-neurotechnologies-and (2025).
- 5.United States Congress. MIND Act of 2025 (S.2925, 119th Congress). https://www.congress.gov/bill/119th-congress/senate-bill/2925/text (2025).
- 6.UNESCO. Draft Recommendation on the Ethics of Neurotechnology. https://unesdoc.unesco.org/ark:/48223/pf0000394866 (2025). [DOI] [PubMed]
- 7.Yuste, R. et al. Four ethical priorities for neurotechnologies and AI. Nature551, 159–163 (2017). [DOI] [PMC free article] [PubMed] [Google Scholar]
- 8.Magee, P., Ienca, M. & Farahany, N. Beyond neural data: cognitive biometrics and mental privacy. Neuron112, 3017–3028 (2024). [DOI] [PubMed] [Google Scholar]
- 9.Farahany, N. A. The Battle for Your Brain: Defending the Right to Think Freely in the Age of Neurotechnology (St. Martin’s Publishing Group, 2023).
- 10.Ienca, M. & Andorno, R. Towards new human rights in the age of neuroscience and neurotechnology. Life Sci. Soc. Policy13, 5 (2017). [DOI] [PMC free article] [PubMed] [Google Scholar]
- 11.Kopelman, L. M., Resnik, D. B. & Weed, D. L. What is the role of the precautionary principle in the philosophy of medicine and bioethics? J. Med. Philos.29, 255–258 (2004). [DOI] [PubMed] [Google Scholar]
- 12.Greely, H. T. et al. Neuroethics guiding principles for the NIH BRAIN initiative. J. Neurosci.38, 10586–10588 (2018). [DOI] [PMC free article] [PubMed] [Google Scholar]
- 13.Illes, J. (ed.). Neuroethics: Anticipating the Future (Oxford University Press, 2017).
- 14.Rainey, S. An anticipatory approach to ethico-legal implications of future neurotechnology. Sci. Eng. Ethics30, 18 (2024). [DOI] [PMC free article] [PubMed] [Google Scholar]
- 15.Gibney, E. OpenAI-backed firm to use ultrasound to read minds. Does the science stand up? Nature. https://www.nature.com/articles/d41586-026-00329-x (2026). [DOI] [PubMed]
- 16.Edelman, B. J. et al. Non-invasive brain-computer interfaces: state of the art and trends. IEEE Rev. Biomed. Eng.18, 26–49 (2025). [DOI] [PMC free article] [PubMed] [Google Scholar]
- 17.Drew, L. Mind-reading devices can now predict preconscious thoughts: is it time to worry? Nature647, 575–577 (2025). [DOI] [PubMed] [Google Scholar]
- 18.Bertoni, E. & Ienca, M. The Privacy and Data Protection Implications of the Use of Neurotechnology and Neural Data from the Perspective of Convention 108+. https://www.coe.int/en/web/data-protection/-/the-privacy-and-data-protection-implication-of-the-use-of-neurotechnology-and-neural-data-from-the-perspective-of-convention-108 (2024).
- 19.Pagan, M. et al. Individual variability of neural computations underlying flexible decisions. Nature639, 421–429 (2025). [DOI] [PMC free article] [PubMed] [Google Scholar]
- 20.Paranjape, R. B., Mahovsky, J., Benedicenti, L. & Koles’, Z. The electroencephalogram as a biometric. In Proc. Canadian Conference on Electrical and Computer Engineering 2001 Vol. 2, 1363–1366 (IEEE, 2001).
- 21.Poulos, M., Rangoussi, M. & Alexandris, N. Neural network based person identification using EEG features. In Proc. 1999 IEEE International Conference on Acoustics, Speech, and Signal Processing Vol. 2, 1117–1120 (IEEE, 1999).
- 22.Young, M. J. et al. Safeguarding neural data. Neurology106, e214942 (2026). [DOI] [PMC free article] [PubMed]
- 23.Nicolas-Alonso, L. F. & Gomez-Gil, J. Brain computer interfaces, a review. Sensors12, 1211–1279 (2012). [DOI] [PMC free article] [PubMed] [Google Scholar]
- 24.Awuah, W. A. et al. Bridging minds and machines: the recent advances of brain-computer interfaces in neurological and neurosurgical applications. World Neurosurg.189, 138–153 (2024). [DOI] [PubMed] [Google Scholar]
- 25.Herring, E. Z. et al. Reconnecting the hand and arm to the brain: efficacy of neural interfaces for sensorimotor restoration after tetraplegia. Neurosurgery94, 864 (2024). [DOI] [PMC free article] [PubMed] [Google Scholar]
- 26.Lorach, H. et al. Walking naturally after spinal cord injury using a brain–spine interface. Nature618, 126–133 (2023). [DOI] [PMC free article] [PubMed] [Google Scholar]
- 27.Mitchell, P. et al. Assessment of safety of a fully implanted endovascular brain-computer interface for severe paralysis in 4 patients: the stentrode with Thought-Controlled Digital Switch (SWITCH) study. JAMA Neurol.80, 270–278 (2023). [DOI] [PMC free article] [PubMed] [Google Scholar]
- 28.Bouton, C. E. et al. Restoring cortical control of functional movement in a human with quadriplegia. Nature533, 247–250 (2016). [DOI] [PubMed] [Google Scholar]
- 29.Moses, D. A. et al. Neuroprosthesis for decoding speech in a paralyzed person with anarthria. New Engl. J. Med.385, 217–227 (2021). [DOI] [PMC free article] [PubMed] [Google Scholar]
- 30.Metzger, S. L. et al. A high-performance neuroprosthesis for speech decoding and avatar control. Nature620, 1037–1046 (2023). [DOI] [PMC free article] [PubMed] [Google Scholar]
- 31.Willett, F. R. et al. A high-performance speech neuroprosthesis. Nature620, 1031–1036 (2023). [DOI] [PMC free article] [PubMed] [Google Scholar]
- 32.Card, N. S. et al. An accurate and rapidly calibrating speech neuroprosthesis. New Engl. J. Med.391, 609–618 (2024). [DOI] [PMC free article] [PubMed] [Google Scholar]
- 33.Qian, Y. et al. Real-time decoding of full-spectrum Chinese using brain-computer interface. Sci. Adv.11, adz9968 (2025). [DOI] [PMC free article] [PubMed] [Google Scholar]
- 34.Kunz, E. M. et al. Inner speech in motor cortex and implications for speech neuroprostheses. Cell188, 4658–4673 (2025). [DOI] [PMC free article] [PubMed] [Google Scholar]
- 35.Fernández, E. et al. Visual percepts evoked with an intracortical 96-channel microelectrode array inserted in human occipital cortex. J. Clin. Investig.131, e151331 (2021). [DOI] [PMC free article] [PubMed] [Google Scholar]
- 36.Flesher, S. N. et al. A brain-computer interface that evokes tactile sensations improves robotic arm control. Science372, 831–836 (2021). [DOI] [PMC free article] [PubMed] [Google Scholar]
- 37.Beauchamp, M. S. et al. Dynamic stimulation of visual cortex produces form vision in sighted and blind humans. Cell181, 774–783 (2020). [DOI] [PMC free article] [PubMed] [Google Scholar]
- 38.Gilron, R. et al. Long-term wireless streaming of neural recordings for circuit discovery and adaptive stimulation in individuals with Parkinson’s disease. Nat. Biotechnol.39, 1078–1085 (2021). [DOI] [PMC free article] [PubMed] [Google Scholar]
- 39.Scangos, K. W. et al. Closed-loop neuromodulation in an individual with treatment-resistant depression. Nat. Med.27, 1696–1700 (2021). [DOI] [PMC free article] [PubMed] [Google Scholar]
- 40.Anderson, D. N. et al. Closed-loop stimulation in periods with less epileptiform activity drives improved epilepsy outcomes. Brain147, 521–531 (2024). [DOI] [PMC free article] [PubMed] [Google Scholar]
- 41.Sun, Y. et al. Signal acquisition of brain–computer interfaces: a medical-engineering crossover perspective review. Fundam. Res.5, 3–16 (2025). [DOI] [PMC free article] [PubMed] [Google Scholar]
- 42.Ban, S. et al. Advances in flexible high-density microelectrode arrays for brain-computer interfaces. Biosens. Bioelectron.292, 118102 (2026). [DOI] [PubMed] [Google Scholar]
- 43.Ganguly, K. & Carmena, J. M. Emergence of a stable cortical map for neuroprosthetic control. PLoS Biol.7, e1000153 (2009). [DOI] [PMC free article] [PubMed] [Google Scholar]
- 44.Orsborn, A. L. et al. Closed-loop decoder adaptation shapes neural plasticity for skillful neuroprosthetic control. Neuron82, 1380–1393 (2014). [DOI] [PubMed] [Google Scholar]
- 45.Ma, Y. et al. Personalized brain–computer interface and its applications. J. Pers. Med.13, 46 (2023). [DOI] [PMC free article] [PubMed] [Google Scholar]
- 46.Sorrell, E., Rule, M. E. & O’Leary, T. Brain–machine interfaces: closed-loop control in an adaptive system. Annu. Rev. Control Robot. Auton. Syst.4, 167–189 (2021). [Google Scholar]
- 47.Even-Chen, N. et al. Power-saving design opportunities for wireless intracortical brain computer interfaces. Nat. Biomed. Eng.4, 984–996 (2020). [DOI] [PMC free article] [PubMed] [Google Scholar]
- 48.Kim, H.-J. & Ho, J. S. Wireless interfaces for brain neurotechnologies. Philos. Trans. R. Soc. A Math. Phys. Eng. Sci.380, 20210020 (2022). [DOI] [PubMed] [Google Scholar]
- 49.Dong, Y. et al. Neural decoding for intracortical brain-computer interfaces. Cyborg Bionic Syst.4, 0044 (2023). [DOI] [PMC free article] [PubMed] [Google Scholar]
- 50.Degenhart, A. D. et al. Stabilization of a brain–computer interface via the alignment of low-dimensional spaces of neural activity. Nat. Biomed. Eng.4, 672–685 (2020). [DOI] [PMC free article] [PubMed] [Google Scholar]
- 51.Lo, M.-C. & Widge, A. S. Closed-loop neuromodulation systems: next-generation treatments for psychiatric illness. Int. Rev. Psychiatry29, 191–204 (2017). [DOI] [PMC free article] [PubMed] [Google Scholar]
- 52.Hettick, M. et al. Minimally invasive implantation of scalable high-density cortical microelectrode arrays for multimodal neural decoding and stimulation. Nat. Biomed. Eng.10, 1206–1221 (2026). [DOI] [PMC free article] [PubMed]
- 53.Musk, E. An integrated brain-machine interface platform with thousands of channels. J. Med. Internet Res.21, e16194 (2019). [DOI] [PMC free article] [PubMed] [Google Scholar]
- 54.Regalado, A. This patient’s Neuralink brain implant gets a boost from Grok. MIT Technology Review. https://www.technologyreview.com/2025/05/07/1116139/this-brain-implant-gets-a-boost-from-generative-ai/ (2025).
- 55.Zhang, Z. & Dai, J. Fully implantable wireless brain-computer interface for humans: advancing toward the future. Innovation5, 100595 (2024). [Google Scholar]
- 56.Tankus, A. et al. A speech neuroprosthesis in the frontal lobe and hippocampus: decoding high-frequency activity into phonemes. Neurosurgery96, 356–364 (2025). [DOI] [PubMed] [Google Scholar]
- 57.Verwoert, M. et al. Moving beyond the motor cortex: a brain-wide evaluation of target locations for intracranial speech neuroprostheses. Cell Rep.44, 116241 (2025). [DOI] [PubMed] [Google Scholar]
- 58.World Health Organization. Landscape analysis of the opportunities and challenges for neurotechnology in global health. https://www.who.int/publications/i/item/9789240109049 (2025).
- 59.Reuters. China approves market launch of brain-computer interface medical device in world first. Reuters. https://www.reuters.com/business/healthcare-pharmaceuticals/china-approves-market-launch-brain-computer-interface-medical-device-world-first-2026-03-13/ (2026).
- 60.Cabrera, L. Y. et al. Neurotechnology Governance in the United States: Gaps and Opportunities. Bioethics.40, 225–235 (2026). [DOI] [PMC free article] [PubMed]
- 61.U.S. Department of Health and Human Services. The HIPAA Privacy Rule. https://www.hhs.gov/hipaa/for-professionals/privacy/index.html (2008).
- 62.U.S. Department of Health and Human Services. The Security Rule. https://www.hhs.gov/hipaa/for-professionals/security/index.html (2009).
- 63.U.S. Department of Health and Human Services. 45 CFR 46. https://www.hhs.gov/ohrp/regulations-and-policy/regulations/45-cfr-46/index.html (2016). [DOI] [PubMed]
- 64.U.S. Food and Drug Administration. Implanted Brain–Computer Interface (BCI) Devices for Patients with Paralysis or Amputation: Non-clinical Testing and Clinical Considerations. https://www.fda.gov/regulatory-information/search-fda-guidance-documents/implanted-brain-computer-interface-bci-devices-patients-paralysis-or-amputation-non-clinical-testing (2021).
- 65.U.S. Food and Drug Administration. Cybersecurity in Medical Devices: Quality System Considerations and Content of Premarket Submissions. https://www.fda.gov/regulatory-information/search-fda-guidance-documents/cybersecurity-medical-devices-quality-system-considerations-and-content-premarket-submissions (2023).
- 66.Federal Trade Commission. A Brief Overview of the Federal Trade Commission’s Investigative, Law Enforcement, and Rulemaking Authority. https://www.ftc.gov/about-ftc/mission/enforcement-authority (2013).
- 67.European Union. Regulation (EU) 2016/679 on the Protection of Natural Persons with Regard to the Processing of Personal Data and on the Free Movement of such Data (General Data Protection Regulation). https://eur-lex.europa.eu/eli/reg/2016/679/oj/eng (2016).
- 68.European Union. Regulation (EU) 2017/745 on Medical Devices (Medical Device Regulation). https://eur-lex.europa.eu/eli/reg/2017/745/oj/eng (2017).
- 69.European Union. Regulation (EU) 2023/2854 on Harmonised Rules on Fair Access to and Use of Data (Data Act). https://eur-lex.europa.eu/eli/reg/2023/2854/oj/eng (2023).
- 70.European Commission. Digital Omnibus on AI Regulation: Proposal. https://digital-strategy.ec.europa.eu/en/library/digital-omnibus-ai-regulation-proposal (2025).
- 71.European Union. Regulation (EU) 2024/1689 Laying Down Harmonised Rules on artificial intelligence (AI Act). https://eur-lex.europa.eu/eli/reg/2024/1689/oj/eng (2024).
- 72.European Union. Regulation (EU) 2025/327 on the European Health Data Space (EHDS). https://eur-lex.europa.eu/eli/reg/2025/327/oj/eng (2025).
- 73.Naysmith, C. Elon Musk’s Neuralink Aims for a Future of ‘Superhuman’ Vision and Telepathy—but First, it will Tackle Blindness and Paralysis. Nasdaq. https://www.nasdaq.com/articles/elon-musks-neuralink-aims-future-superhuman-vision-and-telepathy-first-it-will-tackle (2024).
- 74.European Commission. Digital Omnibus Regulation: Proposal. https://digital-strategy.ec.europa.eu/en/library/digital-omnibus-regulation-proposal (2025).
- 75.O’Regan, E. Brussels knifes privacy to feed the AI boom. POLITICO. https://www.politico.eu/article/brussels-knifes-privacy-to-feed-the-ai-boom-gdpr-digital-omnibus/ (2025).
- 76.Rocher, L., Hendrickx, J. M. & de Montjoye, Y.-A. Estimating the success of re-identifications in incomplete datasets using generative models. Nat. Commun.10, 3069 (2019). [DOI] [PMC free article] [PubMed] [Google Scholar]
- 77.Gadotti, A., Rocher, L., Houssiau, F., Creţu, A.-M. & de Montjoye, Y.-A. Anonymization: the imperfect science of using data while preserving privacy. Sci. Adv.10, eadn7053 (2024). [DOI] [PMC free article] [PubMed] [Google Scholar]
- 78.White, T., Blok, E. & Calhoun, V. D. Data sharing and privacy issues in neuroimaging research: opportunities, obstacles, challenges, and monsters under the bed. Hum. Brain Mapp.43, 278–291 (2022). [DOI] [PMC free article] [PubMed] [Google Scholar]
- 79.Gymrek, M., McGuire, A. L., Golan, D., Halperin, E. & Erlich, Y. Identifying personal genomes by surname inference. Science339, 321–324 (2013). [DOI] [PubMed] [Google Scholar]
- 80.von Thenen, N., Ayday, E. & Cicek, A. E. Re-identification of individuals in genomic data-sharing beacons via allele inference. Bioinformatics35, 365–371 (2019). [DOI] [PubMed] [Google Scholar]
- 81.Packhäuser, K. et al. Deep learning-based patient re-identification is able to exploit the biometric nature of medical chest X-ray data. Sci. Rep.12, 14851 (2022). [DOI] [PMC free article] [PubMed] [Google Scholar]
- 82.Ravindra, V. & Grama, A. De-anonymization attacks on neuroimaging datasets. In Proc. 2021 International Conference on Management of Data 2394–2398, 10.1145/3448016.3457234 (2021).
- 83.Bidgoly, A. J., Bidgoly, H. J. & Arezoumand, Z. Towards a universal and privacy preserving EEG-based authentication system. Sci. Rep.12, 2531 (2022). [DOI] [PMC free article] [PubMed] [Google Scholar]
- 84.Yang, Y.-Y., Hwang, A. H.-C., Wu, C.-T. & Huang, T.-R. Person-identifying brainprints are stably embedded in EEG mindprints. Sci. Rep.12, 17031 (2022). [DOI] [PMC free article] [PubMed] [Google Scholar]
- 85.Rehman, T. U. et al. Advancing EEG-based biometric identification through multi-modal data fusion and deep learning techniques. Complex Intell. Syst.11, 398 (2025). [Google Scholar]
- 86.Shokri, R., Stronati, M., Song, C. & Shmatikov, V. Membership inference attacks against machine learning models. In Proc. 2017 IEEE Symposium on Security and Privacy (SP) 3–18, 10.1109/SP.2017.41 (2017).
- 87.Cobilean, V., Mavikumbure, H. S., Drake, D., Stuart, M. & Manic, M. Investigating membership inference attacks against CNN models for BCI systems. IEEE J. Biomed. Health Inf.29, 3521–3532 (2025). [DOI] [PubMed] [Google Scholar]
- 88.Jayaraman, B. & Evans, D. Evaluating differentially private machine learning in practice. In Proc. 28th USENIX Security Symposium (USENIX Security 19) 1895–1912, 10.5555/3361338.3361469 (USENIX Association, 2019).
- 89.Almadhoun, N., Ayday, E. & Ulusoy, Ö. Differential privacy under dependent tuples—the case of genomic privacy. Bioinformatics36, 1696–1703 (2020). [DOI] [PubMed] [Google Scholar]
- 90.Chen, J., Wang, W. H. & Shi, X. Differential privacy protection against membership inference attack on machine learning for genomic data. In Proc. Biocomputing 2021 26–37, 10.1142/9789811232701_0003 (World Scientific, 2020). [PubMed]
- 91.Thapaliya, B. et al. Efficient federated learning for distributed neuroimaging data. Front. Neuroinform.18, 1430987 (2024). [DOI] [PMC free article] [PubMed] [Google Scholar]
- 92.Yurdem, B., Kuzlu, M., Gullu, M. K., Catak, F. O. & Tabassum, M. Federated learning: overview, strategies, applications, tools and future directions. Heliyon10, e38137 (2024). [DOI] [PMC free article] [PubMed] [Google Scholar]
- 93.Bai, L. et al. Membership inference attacks and defenses in federated learning: a survey. ACM Comput. Surv.57, 89:1–89:35 (2024). [Google Scholar]
- 94.Zhu, G. et al. FedMIA: an effective membership inference attack exploiting ‘all for one’ principle in federated learning. In Proc. IEEE/CVF Conference on Computer Vision and Pattern Recognition (CVPR) 20643–20653, 10.1109/CVPR52734.2025.01922 (2025).
- 95.Rootes-Murdy, K. et al. Federated analysis of neuroimaging data: a review of the field. Neuroinformatics20, 377–390 (2022). [DOI] [PMC free article] [PubMed] [Google Scholar]
- 96.Howison, M., Angell, M. & Hastings, J. S. Protecting sensitive data with secure data enclaves. Digit. Gov. Res. Pract.5, 14:1–14:11 (2024). [Google Scholar]
- 97.Cohen, I. G., Gerke, S. & Kramer, D. B. Ethical and legal implications of remote monitoring of medical devices. Milbank Q98, 1257–1289 (2020). [DOI] [PMC free article] [PubMed] [Google Scholar]
- 98.Dolezel, D., Kruse, C. S. & Pradhan, R. Cybersecurity in healthcare: ensuring patient safety and data privacy. J. Multidiscip. Healthc.19, 609209 (2026). [DOI] [PMC free article] [PubMed] [Google Scholar]
- 99.Mueller, R. Big data, big gap: working towards a HIPAA framework that covers big data. Ind. Law J.97, 1505–1529 (2022). [Google Scholar]
- 100.Tovino, S. A. Artificial intelligence and the HIPAA privacy rule: a primer. Hous. J. Health Law Policy24, 77–126 (2025). [Google Scholar]
- 101.Oakley, A. HIPAA, HIPPA, or HIPPO: what really is the Health Insurance Portability and Accountability Act? Biotechnol. Law Rep.42, 306–318 (2023). [Google Scholar]
- 102.Reischl, M. Monetizing your health: why HIPAA’s gaps are putting personal data at risk. UIC Law Rev.59, 715–743 (2026). [Google Scholar]
- 103.Levin, A. D. et al. Cross-brain transfer of high-performance intracortical speech and handwriting BCIs. Preprint at https://www.biorxiv.org/content/10.64898/2026.01.12.699110v1 (2026).
- 104.Li, C. et al. An overview of machine unlearning. High Confid. Comput.5, 100254 (2025). [Google Scholar]
- 105.Bourtoule, L. et al. Machine unlearning. In Proc. 2021 IEEE Symposium on Security and Privacy (SP) 141–159, 10.1109/SP40001.2021.00019 (2021).
- 106.Shao, C. et al. Machine unlearning for seizure prediction. IEEE Trans. Cogn. Dev. Syst.16, 1969–1981 (2024). [Google Scholar]
- 107.Xue, Y., Liu, J., McDonagh, S. & Tsaftaris, S. A. Erase to enhance: data-efficient machine unlearning in MRI reconstruction. In Proc. Medical Imaging with Deep Learning Vol. 250, 1785–1800 (PMLR, 2024).
- 108.Kalokyri, V. et al. AI model passport: data and system traceability framework for transparent AI in health. Comput. Struct. Biotechnol. J.28, 386–404 (2025). [DOI] [PMC free article] [PubMed] [Google Scholar]
- 109.Zyskind, G., Nathan, O. & Pentland, A. ‘Sandy’. Decentralizing privacy: using blockchain to protect personal data. In Proc. 2015 IEEE Security and Privacy Workshops 180–184, 10.1109/SPW.2015.27 (2015).
- 110.Haleem, A., Javaid, M., Singh, R. P., Suman, R. & Rab, S. Blockchain technology applications in healthcare: an overview. Int. J. Intell. Netw.2, 130–139 (2021). [Google Scholar]
- 111.Smalley, S. As scientists show they can read inner speech, brain implant ‘pioneers’ fight for neural data privacy, access rights. The Record. https://therecord.media/neural-data-privacy-brain-implants (2025).
- 112.Teeters, J. L. et al. Neurodata without borders: creating a common data format for neurophysiology. Neuron88, 629–634 (2015). [DOI] [PubMed] [Google Scholar]
- 113.Gorgolewski, K. J. et al. The brain imaging data structure, a format for organizing and describing outputs of neuroimaging experiments. Sci. Data3, 160044 (2016). [DOI] [PMC free article] [PubMed] [Google Scholar]
- 114.Pernet, C. R. et al. EEG-BIDS, an extension to the brain imaging data structure for electroencephalography. Sci. Data6, 103 (2019). [DOI] [PMC free article] [PubMed] [Google Scholar]
- 115.Holdgraf, C. et al. iEEG-BIDS, extending the brain imaging data structure specification to human intracranial electrophysiology. Sci. Data6, 102 (2019). [DOI] [PMC free article] [PubMed] [Google Scholar]
- 116.Eiber, C. D. et al. Preliminary minimum reporting requirements for in-vivo neural interface research: I. Implantable neural interfaces. IEEE Open J. Eng. Med. Biol.2, 74–83 (2021). [DOI] [PMC free article] [PubMed] [Google Scholar]
- 117.International Organization for Standardization/International Electrotechnical Commission, Joint Technical Committee 1 (ISO/IEC JTC 1). Brain-Computer Interface Technical Report 2024. https://jtc1info.org/slug/brain-computer-interface-technical-report-2024/ (2024).
- 118.Klein, E. Informed consent in implantable BCI research: identifying risks and exploring meaning. Sci. Eng. Ethics22, 1299–1317 (2016). [DOI] [PubMed] [Google Scholar]
- 119.Parsons, M. V. et al. Ethical implications of neurotechnology in industry-academia partnerships: insights from patient and research participant interviews. PLoS ONE20, 0330367 (2025). [DOI] [PMC free article] [PubMed] [Google Scholar]
- 120.Segal, A. E. & Wendler, D. S. The normative power of consent and limits on research risks. Ethical Theory Moral Pract.27, 555–570 (2024). [DOI] [PMC free article] [PubMed] [Google Scholar]
- 121.Stark, Z. et al. A call to action to scale up research and clinical genomic data sharing. Nat. Rev. Genet.26, 141–147 (2025). [DOI] [PubMed] [Google Scholar]
- 122.Copeland, R. Google’s ‘Project Nightingale’ gathers personal health data on millions of Americans. Wall Street J. https://www.wsj.com/articles/google-s-secret-project-nightingale-gathers-personal-health-data-on-millions-of-americans-11573496790 (2019).
- 123.U.S. Department of Health and Human Services. HIPAA and health apps. https://www.hhs.gov/hipaa/for-professionals/special-topics/health-apps/index.html (2015). [DOI] [PubMed]
- 124.McGraw, D. & Mandl, K. D. Privacy protections to encourage use of health-relevant digital data in a learning health system. NPJ Digit. Med.4, 2 (2021). [DOI] [PMC free article] [PubMed] [Google Scholar]
- 125.Khurana, V. et al. A survey on neuromarketing using EEG signals. IEEE Trans. Cogn. Dev. Syst.13, 732–749 (2021). [Google Scholar]
- 126.Grundy, Q. et al. Data sharing practices of medicines related apps and the mobile ecosystem: traffic, content, and network analysis. BMJ364, l920 (2019). [DOI] [PMC free article] [PubMed] [Google Scholar]
- 127.Huckvale, K., Torous, J. & Larsen, M. E. Assessment of the data sharing and privacy practices of smartphone apps for depression and smoking cessation. JAMA Netw. Open2, e192542 (2019). [DOI] [PMC free article] [PubMed] [Google Scholar]
- 128.Muhl, E. & Andorno, R. Neurosurveillance in the workplace: do employers have the right to monitor employees’ minds? Front. Hum. Dyn.5, 1245619 (2023). [Google Scholar]
- 129.Chan, T. F. China is monitoring employees’ brain waves and emotions—and the technology boosted one company’s profits by $315 million. Business Insider. https://www.businessinsider.com/china-emotional-surveillance-technology-2018-4 (2018).
- 130.United States Congress. Genetic Information Nondiscrimination Act of 2008 (Public Law 110-233). https://www.govinfo.gov/content/pkg/PLAW-110publ233/pdf/PLAW-110publ233.pdf (2008).
- 131.United States Congress. Americans with Disabilities Act of 1990 (Public Law 101-336). https://www.govinfo.gov/content/pkg/STATUTE-104/pdf/STATUTE-104-Pg327.pdf (1990). [PubMed]
- 132.Ravindranath, M. How your health information is sold and turned into ‘risk scores’. POLITICO. https://www.politico.com/story/2019/02/03/health-risk-scores-opioid-abuse-1139978 (2019).
- 133.United States Congress. Patient Protection and Affordable Care Act (Public Law 111-148). https://www.govinfo.gov/content/pkg/PLAW-111publ148/pdf/PLAW-111publ148.pdf (2010).
- 134.Cornell, P. Y., Grabowski, D. C., Cohen, M., Shi, X. & Stevenson, D. G. Medical underwriting in long-term care insurance: market conditions limit options for higher-risk consumers. Health Aff.35, 1494–1503 (2016). [DOI] [PMC free article] [PubMed] [Google Scholar]
- 135.Thomson, S. & Mossialos, E. Private Health Insurance in the European Union. https://ec.europa.eu/social/BlobServlet?docId=3210&langId=en (2009).
- 136.Edemekong, P. F., Annamaraju, P., Afzal, M. & Haydel, M. J. Health Insurance Portability and Accountability Act (HIPAA) compliance. in StatPearls (StatPearls Publishing, 2025). [PubMed]
- 137.European Union. Directive (EU) 2016/680 on the Protection of Natural Persons with regard to the Processing of Personal Data by Competent Authorities for the Purposes of the Prevention, Investigation, Detection or Prosecution of Criminal Offences or the Execution of Criminal Penalties, and on the Free Movement of such Data (Law Enforcement Directive). https://eur-lex.europa.eu/eli/dir/2016/680/oj/eng (2016).
- 138.Shen, F. Neuroscience, mental privacy, and the law. Harv. J. Law Public Policy37, 653–713 (2013). [Google Scholar]
- 139.Veas, J. E. Brain-reading technologies and the right against self-incrimination: a challenge for the distinction between testimonial and real evidence. Ger. Law J.26, 683–701 (2025). [Google Scholar]
- 140.Office of the High Commissioner for Human Rights. Call for input: human rights in the administration of justice – neurotechnology and other emerging technologies – report of the Secretary-General. https://www.ohchr.org/en/calls-for-input/2026/call-input-human-rights-administration-justice-neurotechnology-and-other (2026).
- 141.Martinovic, I. et al. On the feasibility of side-channel attacks with brain–computer interfaces. In Proc. 21st USENIX Security Symposium 34 (USENIX Association, 2012).
- 142.Pugh, J., Pycroft, L., Sandberg, A., Aziz, T. & Savulescu, J. Brainjacking in deep brain stimulation and autonomy. Ethics Inf. Technol.20, 219–232 (2018). [DOI] [PMC free article] [PubMed] [Google Scholar]
- 143.Schroder, T. et al. Cyber risks to next-gen brain-computer interfaces: analysis and recommendations. Neuroethics18, 34 (2025). [Google Scholar]
- 144.McGuire, A. L., Roberts, J., Aas, S. & Evans, B. J. Who owns the data in a medical information commons? J. Law Med. Ethics47, 62–69 (2019). [DOI] [PMC free article] [PubMed] [Google Scholar]
- 145.Liddell, K., Simon, D. A. & Lucassen, A. Patient data ownership: who owns your health? J. Law Biosci.8, lsab023 (2021). [DOI] [PMC free article] [PubMed] [Google Scholar]
- 146.Contreras, J. L. The false promise of health data ownership. N. Y. Univ. Law Rev.94, 624–661 (2019).
- 147.Suter, S. M. Disentangling privacy from property: toward a deeper understanding of genetic privacy. George Wash. Law Rev.72, 737–814 (2004). [PubMed] [Google Scholar]
- 148.Gitter, D. M. Achieving genetic data privacy through enforcement of property rights. UC Davis Law Rev.57, 131–169 (2023). [Google Scholar]
- 149.Naufel, S. & Klein, E. Brain–computer interface (BCI) researcher perspectives on neural data ownership and privacy. J. Neural Eng.17, 016039 (2020). [DOI] [PubMed] [Google Scholar]
- 150.Colorado General Assembly. HB24-1058: Protect Privacy of Biological Data. https://leg.colorado.gov/bills/hb24-1058 (2024).
- 151.California Legislature. SB 1223 (2023–2024): Chaptered. https://leginfo.legislature.ca.gov/faces/billNavClient.xhtml?bill_id=202320240SB1223 (2024).
- 152.Vermont General Assembly. S.71: An Act Relating to Consumer Data Privacy and Online Surveillance. https://legislature.vermont.gov/bill/status/2026/S.71 (2026).
- 153.Uniform Law Commission. Mental Privacy, Cognitive Biometrics, and Neural Data. https://www.uniformlaws.org/committees/community-home?communitykey=19bd8649-3445-434e-9277-0190977b8933 (2024).
- 154.Biblioteca del Congreso Nacional de Chile. LeyChile. https://www.bcn.cl/leychile (2021).
- 155.Government of Spain. Carta de Derechos Digitales. https://portal.mineco.gob.es/ca-es/comunicacion/Pagines/210715-carta-de-derechos-digitales.aspx (2021).
- 156.Rainey, S. Neurorights as Hohfeldian privileges. Neuroethics16, 9 (2023). [Google Scholar]
- 157.Wajnerman Paz, A. Is your neural data part of your mind? Exploring the conceptual basis of mental privacy. Minds Mach.32, 395–415 (2022). [DOI] [PMC free article] [PubMed] [Google Scholar]
- 158.Heller, M. A. & Eisenberg, R. S. Can patents deter innovation? The anticommons in biomedical research. Science280, 698–701 (1998). [DOI] [PubMed] [Google Scholar]
- 159.New Hampshire General Court. New Hampshire Revised Statutes § 332-I:1: Medical Records; Definitions. https://law.justia.com/codes/new-hampshire/2023/title-xxx/chapter-332-i/section-332-i-1/ (2023).
- 160.Nielsen, J. & Nicol, D. Data ownership in genomic research consortia. J. Law Biosci.11, lsae024 (2024). [DOI] [PMC free article] [PubMed] [Google Scholar]
- 161.European Union. Directive 96/9/EC on the Legal Protection of Databases. https://eur-lex.europa.eu/eli/dir/1996/9/oj/eng (1996).
- 162.Central Committee of the Communist Party of China & State Council of the People’s Republic of China. Opinions on Constructing a Basic System for Data and Putting Data Elements to Better Use. https://perma.cc/5TLL-UVEM (2022).
- 163.Huang, S. & Cheng, L. Experiences, challenges, and improvements in the construction of data property rights in China. Comput. Law Security Rev.59, 106228 (2025). [Google Scholar]
- 164.Swire, P. et al. Risks to cybersecurity from data localization, organized by techniques, tactics and procedures. J. Cyber Policy9, 20–51 (2024). [Google Scholar]
- 165.National Institutes of Health. Final NIH Policy for Data Management and Sharing (NOT-OD-21-013). https://grants.nih.gov/grants/guide/notice-files/NOT-OD-21-013.html (2020).
- 166.U.S. Food and Drug Administration. Design Considerations and Pre-market Submission Recommendations for Interoperable Medical Devices. https://www.fda.gov/regulatory-information/search-fda-guidance-documents/design-considerations-and-pre-market-submission-recommendations-interoperable-medical-devices (2019).
- 167.Young M. J. et al. Unifying Consent Standards for Implantable Brain-Computer Interfaces. Device. 2026. In press. [DOI] [PMC free article] [PubMed]
- 168.Ienca, M. & Malgieri, G. Mental data protection and the GDPR. J. Law Biosci.9, lsac006 (2022). [DOI] [PMC free article] [PubMed] [Google Scholar]
- 169.Jwa, A. S. & Poldrack, R. A. Addressing privacy risk in neuroscience data: from data protection to harm prevention. J. Law Biosci.9, lsac025 (2022). [DOI] [PMC free article] [PubMed] [Google Scholar]
- 170.Hafen, E., Kossmann, D. & Brand, A. Health data cooperatives – citizen empowerment. Methods Inf. Med.53, 82–86 (2014). [DOI] [PubMed] [Google Scholar]
- 171.Rivas Velarde, M. C. et al. Citizens’ views on sharing their health data: the role of competence, reliability and pursuing the common good. BMC Med. Ethics22, 62 (2021). [DOI] [PMC free article] [PubMed] [Google Scholar]
- 172.Welzel, C. et al. Enabling secure and self determined health data sharing and consent management. NPJ Digit. Med.8, 560 (2025). [DOI] [PMC free article] [PubMed] [Google Scholar]
- 173.Bennear, L. S. & Wiener, J. B. Adaptive Regulation: Instrument Choice for Policy Learning Over Time. https://www.hks.harvard.edu/sites/default/files/centers/mrcbg/files/Regulation%20-%20adaptive%20reg%20-%20Bennear%20Wiener%20on%20Adaptive%20Reg%20Instrum%20Choice%202019%2002%2012%20clean.pdf (2019).
