Skip to main content
Communications Medicine logoLink to Communications Medicine
. 2026 Jul 27;6:413. doi: 10.1038/s43856-026-01797-y

Advancing data protections for implantable brain-computer interfaces

Julian D Sandbrink 1,2, Michael J Young 1,3,✉
PMCID: PMC13408982  PMID: 42509357

Abstract

Implantable brain-computer interfaces (iBCIs) are rapidly transitioning from proof-of-concept devices to early clinical application. The high-resolution neural signals they capture may yield insights beyond those derived from conventional health data. In this Review, we examine how clinical iBCI data remain insufficiently protected, despite existing privacy laws like the Health Insurance Portability and Accountability Act (HIPAA) and the General Data Protection Regulation (GDPR). Five core gaps are identified: overreliance on conventional de-identification, limited individual control and rights, conflated consent practices, limited guardrails against misuse, and underspecified ownership. We examine strategies to address these gaps, including protections for de-identified data, stronger iBCI data rights and control, separate data consent, limits on harmful secondary uses, and monetization guardrails. As iBCIs transition from research tools to real-world clinical practice, clinicians, researchers, developers, and regulators, in dialogue with prospective and current iBCI users, will play central roles in advancing patient autonomy and privacy.

Subject terms: Diseases of the nervous system, Neurological disorders, Health services, Clinical trial design, Biotechnology


Sandbrink and Young examine emerging opportunities and challenges in stewarding neural data generated by implantable brain computer interfaces as these devices move from research settings into clinical care. They identify key gaps in protections, and discuss how clinicians, developers, and regulators could advance patient privacy and autonomy.

Introduction

Implantable brain-computer interfaces (iBCIs) are advancing for a variety of neurorestorative applications, including limb control and communication assistance, and are poised to transform care for many patients1,2. iBCIs capture longitudinal neural activity with unprecedented spatial and temporal resolution. With the advent of AI-enabled decoding algorithms, the resulting iBCI-derived neural data (hereafter, “iBCI data”), including raw recordings, processed features, decoded inferences, and personalized model parameters, now support increasingly detailed inferences about intended actions, linguistic content, and other cognitive processes1. Most existing data protection frameworks, however, were designed for traditional forms of health data, long before the advent of iBCIs capable of high-resolution brain recording and advanced decoding3. As neural data governance gains traction in policy discussions, evident in a recent UN Human Rights Council report4, the September 2025 introduction of the Management of Individuals’ Neural Data (MIND) Act5, and a November 2025 UNESCO Recommendation on the Ethics of Neurotechnology6, and as more companies initiate pivotal trials, opportunities exist to bring greater specificity to governance proposals as they pertain to clinical iBCIs. Here, we critically evaluate what makes iBCI data distinctive and what protections are and are not afforded by current regulatory frameworks, identifying five core gaps: overreliance on conventional de-identification, limited individual control, conflated consent, limited misuse guardrails, and underspecified ownership. We examine options for how clinicians, researchers, developers, and regulators, in dialogue with individuals with lived experience of iBCI use, can help address these gaps (Fig. 1).

Fig. 1.

Fig. 1

Gaps and corresponding proposals for advancing iBCI data protections.

Because the practical effectiveness of regulatory data protection frameworks can depend on associated technical and organizational measures, selected data security considerations are also discussed where they could affect the practical realization of regulatory data protection and complementary governance efforts’ objectives. In this review, “iBCI data protections” refer collectively to regulatory data protection frameworks, complementary governance mechanisms, and those technical and organizational safeguards that impact their practical implementation. While these layers interact in practice (for example, regulatory obligations shape which technical measures are considered reasonable, and technical developments in turn might inform legal standards), they are distinct and non-interchangeable, raising different questions of implementation and accountability. While prior work highlights regulatory blind spots surrounding consumer neural and biometric data7–10, we here examine clinical iBCI data, showing how they remain vulnerable despite coverage as medical data under existing regulatory frameworks. As large-scale clinical iBCI datasets are only beginning to emerge, the analysis is deliberately anticipatory, identifying foreseeable risks based on distinctive characteristics of iBCI data and precedent from analogous domains, and pointing to corresponding suggestions to be considered (and potentially implemented) now, rather than waiting for potential breaches to occur and retrofitting protections11–14.

What makes iBCI-derived neural data distinctive?

Neural data are generally information obtained by measuring the activity of the central or peripheral nervous system. This information can be structural, including computed tomography (CT) and magnetic resonance imaging (MRI) scans; functional-hemodynamic, including functional magnetic resonance imaging (fMRI), functional near-infrared spectroscopy (fNIRS)15, and positron emission tomography (PET); or electrophysiological, including electroencephalography (EEG), magnetoencephalography (MEG), electrocorticography (ECoG), and intracortical recordings. Low-resolution or static neural data (e.g., conventional head CT) may have relatively limited capacity for unanticipated inferences. However, advances in high-resolution recording and artificial intelligence-driven decoding have enabled the capture of rich, dynamic features that support increasingly accurate inferences about user states, properties, or processes1,16,17. Higher-dimensional neural data have increasingly been recognized as potentially sensitive because they can be pre-behavioral, convey propositional or semantic content, and reflect elements of metacognition18. They can also be individual-specific and evolve over time19–21. Despite substantial diversity in neural data types, attributes of certain forms of neural data are occasionally generalized to all neural data, risking conflation of heterogeneous data streams or flattening of important distinctions, and yielding broad-brush approaches to neural data ethics, privacy, and governance that risk overlooking important differences in sensitivity and inference potential22.

Brain-computer interfaces (BCIs) are systems that record neural activity, extract meaningful features, and translate these into commands that operate an external or internal effector, such as a cursor, speller, prosthetic limb, or stimulating electrode1,23. Implantable BCIs (iBCIs) constitute a subset of BCIs implanted in the central nervous system. Brain signals are typically decoded by machine-learning algorithms to infer intended movements, speech, or aspects of other user states, and, in some cases, the system feeds responsive, targeted stimulation back to the brain1,24. In the process, information about the user’s neural activity may be stored in several forms of iBCI-derived neural data. These include raw neural recordings, processed features, decoded inferences (e.g., reconstructed speech), and personalized decoding models whose parameters (e.g., model weights) may implicitly encode aspects of an individual’s neural activity. iBCIs can differ in neural targets, implant depth, electrode types, decoding methods, outputs, and data flows, which can shape their respective privacy implications25–40 (Table 1).

Table 1.

Representative functional types of implantable brain-computer interfaces (iBCIs)

Device type Function CNS sensing sites Electrode types Decoding methods Data flows and logging Privacy considerations
Motor interfaces25–28 Decode intended limb or cursor movement M1 and premotor cortex, some also S1 MEA (intracortical), ECoG (surface), and EVA (endovascular) Linear or adaptive decoders (e.g., Kalman, SVM, and HMM-based) map features (e.g., spike rate, spectral power) to intended movements Real-time streaming during active use; neural recordings are typically logged on external systems and used for decoder calibration Longitudinal signatures and external processing raise re-identification risk and may enable new inferences (beyond movement) as decoders improve
Speech interfaces29–34 Decode intended speech to enable communication Ventral motor/premotor speech areas; language areas ECoG (surface), MEA (intracortical) Deep neural networks map spectrotemporal features to phonemes/syllables/units; language models produce sentences Real-time streaming during active use; neural recordings and inferences are typically stored on external systems and used for model training Raw data and inferences are sensitive due to semantically rich content and advanced decoding (e.g., of private user conversations); recent work further shows the possibility of decoding aspects of inner speech not intended for communication34
Sensory-restoration interfaces35–37 Encode sensory information via stimulation to enable perception Primarily somatosensory or visual cortex MEA (intracortical micro-stimulation), ECoG (surface stimulation) Adaptive encoding of perceptual features to stimulation parameters; limited neural recording for mapping, calibration, or feedback Real-time stimulation during sessions; parameters and perceptual reports are recorded on external systems for post-session calibration Combined stimulation and perceptual data could reveal sensory experiences, particularly in bidirectional systems
Closed-loop therapeutic neuro-modulation38–40 Detect pathological activity and adjust stimulation Variable deep brain/cortical targets Sensing/stimulating DBS leads, RNS depth/strip leads, some additional electrode paddles/strips/arrays Typically, threshold-based feature detection; sometimes ML-adaptive control Intermittent sensing and event-triggered logging on-device; potential export during clinical follow-ups Semantic inference potential is likely limited, though longitudinal biomarkers and metadata may reveal health status, disease risk, cognitive properties, or behavior

The listed functional device types and their common CNS sites, electrode types, decoding methods, data flows, and privacy considerations provide a simplified, non-exhaustive overview of existing iBCI systems and sources of variability among them.

CNS central nervous system, DBS deep brain stimulation, ECoG electrocorticography (including thin-film surface arrays), HMM hidden Markov model, EVA endovascular array, MEA microelectrode array (including rigid, microwire, and flexible thread arrays), ML machine learning, M1 primary motor cortex, RNS responsive neurostimulation, SVM support vector machine, S1 primary somatosensory cortex.

Despite this variability, many iBCIs produce neural data with a shared set of distinguishing core features: first, many iBCIs can capture single-neuron or small-ensemble activity with millisecond-level temporal resolution as well as substantially higher signal bandwidth and signal-to-noise ratio compared to noninvasive technologies1,41,42. This can make iBCI data more informative about the location, timing, and content of neural representations as compared to devices with lower spatial and temporal resolution. Second, iBCIs are often chronically implanted, and data can thus accumulate over weeks, months, or years1, generating longitudinal data streams43–46. While sampling and logging will often not be continuous, as data may be compressed, buffered, or only certain features exported intermittently to preserve bandwidth, battery life, and storage47,48, long-term use may still reveal rich and individualized neural signatures1,20,49,50. Third, unlike diagnostic recording methods, iBCIs may form feedback loops where decoded neural activity is used to control a device and directly (via stimulation) or indirectly (via sensory feedback or neural adaptation) influences subsequent states43,46,51. The algorithms are usually also adapted to feedback and activity of the patient45,46,49. Finally, iBCI data processing will often involve external processors (due to limited on-device power and computational resources)48 and may interface with programming and monitoring systems1. Therefore, iBCI data may in many cases be linked to clinical or operational metadata, yielding composite individualized datasets.

Advances in thin-film microelectrode arrays have moreover enabled recordings and stimulation of multi-somatosensory, -motor, and -visual activity, as well as high-density recordings of speech-related cortical activity in humans52. One developer has envisioned the possibility of scaling “thousands of electrodes to be rapidly deployed to multiple functional areas without damaging cortical tissue… [rendering it] conceivable to envision deploying a thin-film-based neural interface over the majority of the accessible human neocortex”52. At the same time, other devices are advancing toward increasingly wireless operation and seamless data exchange between implant, external processors, and connected digital systems, including the aspiration toward general-purpose AI ecosystems17,27,53–55.

Alongside advances in sensor materials, new forms of decoding could enhance inferential capabilities. As a result, the informational richness and privacy sensitivity of many iBCI datasets may increase as technologies mature. For example, researchers have recently demonstrated that linguistic information can be reconstructed from cortical areas not traditionally associated with language processing56,57, suggesting that inferences cannot be determined solely a priori by anatomical recording site or initial use purpose. Another recent study showed that even aspects of inner speech not intended for overt communication (as opposed to intended speech) can be decoded from the motor cortex34. While proof-of-concept safeguards, such as keyword-based “unlocking”, have been proposed to prevent unintentional decoding in real time, these measures do not reduce the sensitivity of the raw data themselves, since if one were to gain access to the raw signals, they could, in theory, use a separate model lacking those safeguards to retrospectively decode aspects that the user did not intend to express.

Importantly, the degree to which these features manifest varies substantially across iBCI architectures (for example, speech interfaces designed to decode linguistic content may generate particularly inference-sensitive data, whereas many closed-loop neuromodulation systems may record more limited signals). For analytical clarity, the present analysis treats iBCI data as a common governance subject because they share structural characteristics that can, to varying degrees, generate longitudinal and inference-sensitive neural data warranting oversight consideration, while recognizing that the magnitude and nature of the discussed risks depend on sensor, decoder, and effector properties, inference potential, and use context.

The regulatory landscape of iBCI data protections

iBCI data are protected in different ways worldwide. While the present focus is on the U.S. and the EU, given their widely referenced regulatory models1, iBCI development is also rapidly advancing in other regions, including Australia, Canada, and China, where the first iBCI cleared for post-market clinical use was recently announced58,59. The governance considerations identified here are therefore offered as starting points for collective consideration and local adaptation. Over time, greater international alignment on baseline protections may reduce fragmentation, support multi-site programs, and help ensure that incentives to responsibly innovate and enable clinical access for patients who stand to benefit are not contingent on geography.

In the U.S., regulatory protections that may apply to iBCI data include the Health Insurance Portability and Accountability Act (HIPAA) Privacy and Security Rules, the Common Rule, Food and Drug Administration (FDA) regulations, state-specific laws, and regular consumer protections afforded by the FTC60. These regulations apply to iBCI data under different circumstances. HIPAA protects personal health information (PHI), including clinical iBCI data when flowing through covered entities or their business associates61. HIPAA provides patient rights to access and request amendment of their data, and limits on unauthorized use and disclosure beyond treatment, payment, and healthcare operations purposes61. In addition, appropriate administrative, physical, and technical safeguards are required to ensure confidentiality, integrity, and security of PHI62. The Common Rule sets standards for ethical oversight and consent in federally funded research63, while FDA regulation governs safety and performance of medical devices, including iBCIs, typically classified as Class III devices64. The FDA requires manufacturers to demonstrate premarket cybersecurity controls and to perform post-market vulnerability monitoring, patching, and disclosure65. Finally, the FTC covers iBCI and other data in consumer settings, primarily by restricting deceptive business practices, but offers comparatively thinner proactive data protections66.

In the EU, iBCI data are governed by a layered regulatory framework including the General Data Protection Regulation (GDPR), the Medical Device Regulation (MDR), and the Data Act. In addition, relevant provisions of the EU AI Act and the European Health Data Space (EHDS) will come into effect in the coming years. GDPR is the central personal data protection law and applies to all personal data, including iBCI data. It imposes strict requirements for informed consent, purpose limitation, and the affordance of individual data rights, including rights to access, rectification, erasure, and portability, as well as the right to object to unwanted data processing67. Under MDR, which governs safety, performance, and pre-market approval of medical devices, iBCIs are classified as Class III devices, requiring extensive clinical investigation and post-market monitoring68. Additionally, MDR imposes cybersecurity and data integrity requirements, thereby complementing GDPR68. Most recently, the Data Act, applicable since September 2025, added interoperability and data-access rights for users of connected products, including potentially iBCIs, while preserving trade-secret and safety exemptions and giving explicit precedence to the GDPR for personal data69. The EU AI Act is now in phased application and is set for full applicability in August 2027, though potential timeline adjustments have been proposed70. Under the AI Act, AI systems that function as safety components of medical devices requiring notified-body conformity assessment under the MDR, including iBCIs whose AI components influence clinical outcomes, will be classified as high-risk systems, imposing documentation, dataset quality, and additional security obligations71. To ensure traceability of AI-driven decisions, the AI Act will also require event logging, including, among other information, of model input data, which will likely include aspects of patients’ iBCI-recorded neural signals71. Finally, the European Health Data Space (EHDS), expected to take effect in 2029, will enable cross-border electronic health record access for primary (clinical) use and controlled secondary use of pseudonymized datasets under strict safeguards, including requirements for access solely within controlled environments and prohibitions on re-identification, commercial reuse, or other harmful uses72.

While these existing regulatory frameworks provide essential baseline protections, their practical applicability and enforcement in emerging clinical neurotechnology ecosystems as portended by iBCIs will depend on complementary technical and organizational safeguards. Many regulatory protections hinge on threshold criteria (e.g., whether data are classified as personal or de-identified/anonymized, whether an AI system qualifies as “high-risk”, or whether an entity falls within the scope of HIPAA or GDPR). In addition, iBCI data may traverse multiple institutional actors, such as clinical sites, device manufacturers, cloud infrastructure providers, and AI model developers, including across jurisdictions, which can fragment oversight and enforcement. The ability of enforcement authorities (such as data protection agencies) to investigate and effect protective or corrective action may further be limited by a lack of the technical expertise necessary to evaluate iBCI-specific re-identification and inference risks or to detect covert data misuse. Therefore, the realization of protections in the context of iBCI data, including formal rights, such as access, portability, or erasure, may be more complex in practice than their legal articulation suggests.

The following sections examine central areas of concern and identify key gaps in current iBCI data protections, accounting not only for policy provisions but also operational gaps that could arise in implementation. While some developers have shared ambitions to extend iBCI applications beyond therapeutic contexts and toward enhancement of human capabilities73, the following analysis of gaps focuses on clinical and biomedical research use cases; many of the identified considerations, however, are likely to remain relevant across contexts.

Key gaps in iBCI data protections

Brain biometrics and the de-identification dilemma

First, most existing regulatory protections are loosened if data have been “de-identified” or “anonymized”, rendering iBCI data that have been de-identified in accordance with regulatory standards more open to downstream usage, sharing, and commodification. In the U.S., HIPAA requires the removal of 18 demographic identifiers (“safe harbor”) for data to be considered de-identified and thus no longer subject to its privacy protections, provided the handling entity does not have actual knowledge that the remaining data could be used to identify the individual61. An alternative under HIPAA is the Expert Determination method, where an expert, defined as an individual with “appropriate knowledge of and experience with generally accepted statistical and scientific principles and methods for rendering information not individually identifiable”, certifies that the risk of re-identification is “very small”61. In the EU, GDPR similarly does not apply to data that are anonymized, provided that the re-identification is not possible by any means “reasonably likely to be used”62, though the 2025 Digital Omnibus proposals, if adopted, could narrow this definition by clarifying that data are not considered personal data for an organization unless that organization itself has realistic means to re-identify the individual, even if others do74,75.

However, evidence suggests that many existing de-identification methods are vulnerable to re-identification using novel machine learning techniques and therefore only offer limited privacy protection, particularly for high-dimensional datasets76–78. In genomic research, de-identified sequence databases have been successfully linked back to individuals through surname inference and relatedness mapping79,80. Similar vulnerabilities appear in biomedical imaging, where deep-learning models have been shown to be able to match independent chest-X-ray images of the same patient with over 95% accuracy81, and functional-connectivity patterns have enabled subject re-identification across separately released fMRI datasets82.

While comparable re-identification or linkage attacks have, to our knowledge, not yet been reported for iBCI data, EEG signatures have long been recognized as a potentially potent biometric identifier due to their marked inter-individual variability and intra-individual stability20,21,83,84. Given their substantially better signal fidelity, bandwidth, and resolution as compared to surface EEG41,85, iBCI recordings could, a fortiori, plausibly be similarly or even more uniquely identifying. While empirical evidence for this hypothesis remains limited, the absence of published attacks specific to iBCI datasets might reflect the relative novelty, limited scale, and limited public availability of such data, rather than evidence of robustness against re-identification. In fact, neural activity patterns underlying intended movements or phonemes have been found to vary significantly across individuals, which is why many iBCI systems rely on personalized decoders1,49. Finally, the likely use of iBCI data to train subsequent generations of decoders could also create the potential for membership inference attacks, where one can retrace whether an individual’s data were part of a model’s training dataset86,87, underscoring that privacy risks may persist even for nominally de-identified iBCI data. Notably, the magnitude of these risks will vary across iBCI architectures, depending on signal resolution, logging practices, data flows, and the richness of decoded outputs.

While several technical and organizational privacy-preserving security techniques have been proposed to mitigate risks of re-identification, the extent to which such safeguards adequately protect iBCI users requires further empirical study. Differential privacy describes an approach where statistical noise is added to preserve aggregate patterns while obscuring individual contributions77,88. Differential privacy can directly reduce the success of inference attacks, but often at the cost of degraded model performance and applicability primarily to large or aggregated datasets rather than individual-level data88–90. Federated learning, in which models are trained locally and only parameter updates are shared, reduces the need to exchange raw data, thereby limiting opportunities for re-identification attempts91,92, yet remains vulnerable to membership inference and reconstruction attacks from the full model93,94. Approaches such as federated data access or secure enclaves, which allow computation within protected environments95,96, may reduce exposure by containing data use to trusted infrastructures, but do not themselves anonymize the underlying data. These limitations bear on two distinct questions: whether technical methods can meet legal thresholds for de-identification, and whether those thresholds themselves are adequate for iBCI data. While a combination of the discussed technical and organizational measures might meet these legal thresholds (this warrants further investigation), the thresholds themselves may not adequately account for the inference and re-identification risks associated with high-resolution iBCI data, raising questions about the continued reliance on “release-and-forget” models in this context.

Personal control and rights over iBCI data

Even non-de-identified iBCI data may sometimes fall outside the protections that might be assumed to attach to them by virtue of accruing through a medical device. In the U.S., for instance, developers may be able to structure data flows so that neural data are not created, received, maintained, or transmitted on behalf of a HIPAA-covered entity, placing them outside HIPAA’s scope97–102. Even when regulatory protections do apply, they often do not give patients comprehensive control or rights over their data. Under HIPAA, patients are not guaranteed the right to delete (“to be forgotten”), to withdraw from downstream uses, or to receive their data in a portable format when switching providers. In the EU, GDPR offers a broader array of individual rights, but their practical application to iBCI data remains uncertain, especially where iBCI data have been integrated into AI models. Unlike raw recordings, preprocessed features, or inference readouts, which can in principle be rectified or deleted provided all storage locations are known, iBCI data embedded in AI models can become difficult to single out. While individually personalized decoders that are only used by the patient in question may be comparatively straightforwardly adjusted, the integration of data into global models that are not only trained across multiple participants but also distributed and used widely, by multiple iBCI users, could make rectification or erasure infeasible in practice. Thus, iBCI systems that rely on centralized, multi-user model training and external data storage may pose particular barriers to rectification and erasure. These issues grow sharper as groups begin to study “cross-brain transfer” of iBCI recordings across users to boost decoder performance and ease training burden103.

Emerging techniques could help address these challenges. Machine unlearning refers to methods that allow a trained model to selectively remove the influence of specific data points without retraining from scratch, often by modifying model parameters to approximate a state as if the data had never been seen104,105. In recent proof-of-concept work, such methods were able to reduce membership-inference risk in seizure-prediction models106 and to remove unwanted data influence from MRI-reconstruction models107, in both cases while largely preserving model performance. However, they remain only partially effective and difficult to apply comprehensively if not all of a given model’s copies’ locations are known or accessible, and their applicability to large, high-dimensional datasets, such as longitudinal iBCI recordings, is yet to be explored. Complementary traceable data-lineage frameworks, such as “AI model passports” that document data sources, transformations, and model versions108, could, when combined with machine unlearning, support technical reversibility for personalized decoders or global models, while blockchain approaches could strengthen auditability and consent management by recording access logs and permissions immutably on-chain109,110, though these approaches likewise remain largely untested for iBCI data.

Beyond erasure and rectification, iBCI users may seek to access, share, or transfer their data for purposes such as independent analysis, switching devices, or participation in community-led research initiatives, as recently highlighted by members of the BCI Pioneers Coalition111. This underscores the importance of data portability. However, effective iBCI data portability is challenged by the fact that there is not yet a mature or widely adopted iBCI interchange format capable of supporting cross-platform migration. While several general neurodata standards exist, such as neurodata without borders112, the brain imaging data structure (BIDS)113, and BIDS extensions for EEG114 and iEEG115, these frameworks were designed primarily for retrospective research datasets rather than operational iBCI systems that decode neural activity and interface with effectors in real time, and they do not define standardized provisions for representing decoder architectures and parameters, closed-loop- or effector-control signals, and device-specific timing or synchronization metadata, all of which are important for effective iBCI data portability.

Standard-setting bodies are beginning to address these gaps: the IEEE Standards Association’s working group on “Reporting Standards for in vivo Neural Interface Research” has a subgroup for “invasive central nervous system interfaces”116, and the International Organization for Standardization (ISO) together with the International Electrotechnical Commission (IEC) are developing a recommendation specifically for an “Invasive BCI Multi-modal Neural Data Format”117. These initiatives are a promising step, though adoption will likely be voluntary and may be limited by technical heterogeneity, commercial incentives, or vendor lock-in.

Ultimately, despite their importance for preserving patient autonomy, enforceable individual rights over iBCI data remain underdeveloped and difficult to operationalize under current governance frameworks. In addition to uneven data standards and governance, exercising individual iBCI data rights is complicated by the complexity of the data lifecycle itself, wherein implanted hardware records signals that are transformed by often-proprietary acquisition and decoding pipelines before being streamed to effectors. In this process, each stage could produce derivative artifacts under different custodians. Coordinating user access, deletion, or transfer across this chain is operationally complex and, at present, seldom supported end-to-end.

Limits of iBCI informed consent

A central safeguard in ensuring alignment of expectations around iBCI data management is the informed consent process. In its optimal form, this process comprehensively and transparently informs individuals about data practices and enables autonomous decision-making118. In an interview-based study with noninvasive neurotechnology users, participants indicated a desire for greater transparency about how neural data are used and shared, with many reporting they wished for clearer explanations before using these technologies119. Although comparable empirical results for iBCI users are not yet available, the sensitivity and richness of neural data derived from some iBCIs make it reasonable to anticipate that this population would similarly desire clear and robust disclosure regarding how their data are accessed, shared, and used over time.

Importantly, although some may contend that competent adults are free to assume risks and ramifications of iBCI data practices through voluntary informed consent, there are internal limits to what consent can ethically authorize, particularly in settings of significant vulnerability, limited alternatives, or high stakes120. Individuals currently eligible for iBCI clinical trials (and future clinical uses) characteristically harbor severe neurological conditions (e.g., ALS, brainstem stroke, spinal cord injury with paralysis), which may not only complicate the consent process due to concomitant communication challenges but often generate a sense of desperation for an iBCI that may promise to restore function. Currently, however, consent for iBCI implantation and use may often be merged with consent for how iBCI data will be used, owned, and shared. This overlap may generate undue inducement if patients are not clearly informed about, and given a say in, iBCI data-related agreements without jeopardizing their device eligibility. Requiring individuals to accept a potentially disadvantageous iBCI data agreement as a prerequisite for receiving an iBCI thus raises ethical concerns and could undermine the integrity of consent processes. In some clinical trials, these concerns may be amplified by funder expectations for broad data sharing, which can place investigators in tension between the values of open science and the obligation to respect patient autonomy and privacy121.

Limited guardrails against misuse

Concerns about the integrity of the informed consent process are magnified by limited explicit protections from harmful use or particularly sensitive inferences. While GDPR has a purpose limitation provision and HIPAA limits PHI use and disclosure without authorization, these protections lose force once data have been de-identified, and HIPAA’s protections may additionally be circumvented if data flows are structured outside the purview of covered entities. For fully identifiable data, a primary guardrail under both regimes is informed consent.

Neither regime categorically restricts particularly sensitive or high-risk downstream uses, though there are some complementary safeguards, especially in the EU. Because patients with severely impairing neurological conditions frequently face limited therapeutic options and a pressing need to restore or maintain function, it is possible that some patients may find themselves consenting to data practices unrelated to the clinical purpose of the implant to gain access to an iBCI device. The plausibility and severity of these risks will depend on the type of neural signals collected, the extent of decoding, and whether systems generate semantically rich outputs (like many speech interfaces) or primarily physiological control signals (as in closed-loop neuromodulation devices).

Cross-use for unanticipated purposes, such as model pre-training or commercial analytics by downstream data processors, may occur once iBCI data leave the immediate clinical setting. In the EU, such cross-use would generally require explicit consent unless the data are de-identified67, though proposed amendments under the European Commission’s Digital Omnibus package would introduce an exception allowing processing of identifiable special-category data (including health data) for bias detection and correction in AI systems70. In the U.S., HIPAA allows “business associates”, including cloud infrastructure providers, to process identifiable data without additional consent when doing so supports “treatment, payment, or healthcare operations”61. However, as illustrated by Project Nightingale, where a nonprofit health system shared millions of medical records to develop and train predictive AI models122, such arrangements can occur in ways not anticipated by most patients and unlikely to meet expectations of confidentiality. Even greater risks arise once medical data are voluntarily transferred into non-HIPAA-covered environments, such as companion apps marketed for wellness or performance optimization. Under current U.S. law, even data originating within HIPAA-covered settings lose protection once exported to third-party apps that do not act on behalf of a covered entity123,124. Consequently, companion apps linked to iBCIs could conceivably reuse iBCI data not only for clinical optimization but also for unrelated commercial purposes, including targeted “neuromarketing”8,125, provided they do not actively mislead users. Health and wellness apps have repeatedly been shown to share personal data with third parties126,127, underscoring potential privacy risks to iBCI users once data move outside traditional healthcare settings.

Another potential misuse scenario is that of workplace monitoring. Commercial EEG systems have already been deployed to track workers’ focus and emotional states128,129. In the EU, this would generally be incompatible with GDPR’s requirement that consent must be “freely given”, given the power imbalance between employer and employee, unless necessary for fulfillment of employment health and safety obligations67. In addition, EHDS prohibits the use of electronic health data accessed through its framework for “detrimental” decisions in areas including employment and insurance, and AI systems used for employment monitoring will be considered high-risk under the AI Act (except for workplace emotion monitoring, which will be prohibited barring medical or safety reasons)71. In the U.S., however, consent obtained as a condition of employment is generally considered legally valid, and while the Genetic Information Nondiscrimination Act (GINA) prohibits employers from requesting or using genetic information in employment decisions130 and the Americans with Disabilities Act bans discrimination based on impairment131, neither statute clearly addresses discrimination based on non-genetic cognitive performance metrics, such as iBCI-derived inferences of focus, unless they are treated as evidence of a disability. Related concerns arise in insurance settings, where medical and non-medical data are increasingly combined into “risk scores” that can influence pricing, eligibility, and benefits132. For individual and small group Affordable Care Act-compliant health plans in the U.S., premiums and eligibility generally cannot be based on health status133, and GINA separately bars the use of genetic information for health insurance underwriting130, but these protections do not extend to short-term health plans and life, disability, and long-term-care policies, where risk-based pricing based on health data remains common134. While EHDS’ secondary use framework will prohibit detrimental insurance decisions based on data accessed through EHDS itself72, EU insurers’ use of health information obtained through other methods remains governed by Member State law, under which some categories of private insurance may lawfully use medical data for risk-based pricing135. As iBCI systems mature, their outputs could thus become one more input into risk profiling practices. While it is unlikely that these possibilities will materialize in the near future, given the currently limited clinical penetration of iBCIs, the high cost and invasiveness of implantation, and the absence of employer- or insurer-side incentives to utilize such data, they remain conceptually plausible without stronger protections, and related risks could crystallize as iBCIs become more widely deployed and commercially interoperable.

A separate vector of risk is introduced by the possibility of compelled disclosure for law-enforcement purposes. In the U.S., even if iBCI data are retained within the purview of HIPAA, PHI disclosure may be permissible to law enforcement without patient consent in response to court orders or, provided certain relevance and specificity criteria are met, administrative requests61,136. Comparable access in the EU is possible but subject to stricter safeguards, requiring necessity-proportionality assessments and independent oversight137. For iBCI users, such disclosures could extend to longitudinal recordings and inferences, which raises complex legal-ethical questions around mental privacy and self-incrimination138,139, particularly given emerging evidence that aspects of inner speech may be inferred from iBCI data34. For example, if an iBCI user performs an action or communication through their device that is later alleged to violate the law, it is uncertain whether authorities may access only evidence of the final output or also the upstream neural signals that generated it. Although such scenarios are improbable in the near term owing to the small number of iBCI users, the technical difficulty of extracting and interpreting upstream neural signals, and the absence of relevant legal precedent, their plausibility will likely increase as iBCIs move from research environments into broader clinical use. Recognizing these gaps, in 2026, the Office of the UN High Commissioner for Human Rights issued a call for input on “risks and required safeguards regarding the potential use of neurotechnology and other emerging technologies in the administration of justice”140.

Finally, while primarily a data security issue rather than a data protection gap, there are also illegal pathways to misuse, such as side-channel attacks capable of intercepting or modifying neural data streams141,142. These highlight the parallel need for iBCI-specific cybersecurity measures and technical standards to protect both data privacy and patient safety143.

Underspecified ownership and the potential for monetization

Finally, existing regulations leave the question of iBCI data “ownership” underspecified, allowing iBCI data to be monetized with limited guardrails or patient benefit. While patients have certain rights over their medical data in both the U.S. and the EU, they do not possess comprehensive property or intellectual property (IP) rights, which traditionally include the ability to fully exclude others, alienate (transfer or sell), or share in downstream profits144–146. Rather, entities generally retain broad discretion over iBCI and other medical datasets in their custody: Once data are de-identified or explicit consent is obtained, they can generally be reused or monetized freely, without clear guardrails or mechanisms for patients to share in resulting benefits145,146.

Although health data ownership is a topic of long-standing debate in health law scholarship144–148, the unique features of iBCI data cast it in new light: in particular, the tight link between high-resolution neural signals and patients’ cognition and communication could be considered to create a more legitimate personal claim to ownership or control over the monetization of one’s iBCI data compared to other medical data. That said, the degree of inference sensitivity varies across iBCI device types, and monetization concerns will likely be most acute for systems that generate data with particularly strong inference potential, like many speech interfaces. Survey work with BCI researchers suggests that many view BCI-derived data, including those from iBCIs, as raising distinctive questions about user control, particularly once data flow outside the clinical setting, though most of those surveyed did not endorse treating BCI data as personal property149. The paucity of clear legal guidance regarding ownership and monetization could create tensions as iBCIs move into clinical practice, where reality may not meet all patients’ expectations of control over their iBCI data.

Emerging governance efforts

Despite these challenges, governance efforts tailored to iBCI data have generally been absent, even though several jurisdictions have begun to address neural data protection more broadly7. Some U.S. states have passed their own privacy laws, and Colorado, California, and Vermont have explicitly recognized neural data as sensitive personal data150–152. Moreover, the Uniform Law Commission is now convening a committee on “Mental Privacy, Cognitive Biometrics, and Neural Data”, which aims to guide future lawmaking on the topic153, and a group of U.S. Senators introduced the MIND Act for protection of consumer neural data5. Chile and Spain have each explicitly recognized the importance of personal rights related to neurotechnology154,155. These legislative advances have been influenced by calls for the explicit recognition of “neurorights” like the rights to mental privacy, mental integrity, psychological continuity, and cognitive liberty7,10. UNESCO’s 2025 Recommendation on the Ethics of Neurotechnology also echoes these themes, calling for greater oversight6.

However, most of these initiatives treat neural data as a unitary category, overlooking important differences in spatiotemporal resolution, data flows, and inference potential across technologies. While recent scholarship has urged lawmakers to shift from pure neural data governance toward the notion of inference-sensitive “cognitive biometric data” (including neural and non-neural data with substantive capacity for mental state inference)8, previous cognitive biometric and neural data-related governance efforts have primarily focused on consumer technology, sometimes explicitly exempting medical data regulated through existing health data frameworks150,151. As a result, such efforts have tended to give less sustained attention to the most sensitive types of neural data, such as clinical iBCI data. This leaves open important questions about how far current approaches can address the persistent challenges identified in clinical iBCI contexts.

Closing gaps in iBCI data protections

A variety of approaches could be taken to close the identified gaps. Some may argue that iBCI data are a fundamentally value-laden expression or part of the self that ought to be protected by an extended right to bodily integrity156. However, this is challenged by the recognition that there is a clear distinction between bodily tissue and data derived from an individual that are not part of their organism. Acknowledging this issue, others have proposed to instead protect neural data (as an umbrella category that implicitly includes iBCI data) by a right to psychological integrity, arguing that they are analogous to neurocognitive properties of the brain157. That said, it is difficult to ignore the fact that neural data (unlike neural activity) can be replicated and distributed, and that manipulating a person’s neural or iBCI data does not necessarily affect their mind. While protections are clearly necessary, iBCI data are still data: non-physical, replicable, and shareable.

Another approach could be to apply a property or IP model to iBCI data. At first glance, this may appear appropriate given the close connection between iBCI data and patients’ mental states and may seem to address several of the identified gaps: it could provide a legal basis for constraining post-de-identification “release-and-forget” data flows, strengthen individual control, including over monetization, and potentially mitigate some forms of misuse. However, it is unclear whether property or IP rights would materially improve on existing data governance frameworks, as many of the identified challenges involve downstream control, secondary use, and enforcement rather than legal ownership, which, unlike data rights tied to the individual, may be transferred away146. A property-based approach may also introduce undue pressure on patients to license or sell iBCI data146,147 and may slow data sharing and scientific progress by fragmenting access permissions158.

Recognizing these concerns, most jurisdictions have not adopted comprehensive personal property rights for medical data, and most academic scholarship is critical of such proposals144–146. While some U.S. states have designated limited categories of patient data as “property” (e.g., medical records in New Hampshire159; genetic information in several other states160), these provisions have in practice added little beyond existing HIPAA-style access and confidentiality148. Other frameworks tend instead to confer rights to data curators or processors rather than the individuals whom the raw data were recorded from. For example, the EU’s sui generis database right gives database “makers” exclusive rights to prevent extraction and re-use of substantial parts of the database161, and China’s emerging data property rights system aims to grant rights to use, license, and profit from value-added “data products”, while individual personal data (including medical, neural, and iBCI data) are expected to remain governed under privacy and data security law162,163.

Beyond practical challenges, there is a conceptual difficulty in applying property or IP frameworks to iBCI data: while people can own intellectual creations or physical objects, iBCI-recorded neural signals are not necessarily identical to raw ideas, typical creations, or biological material. Between the organic neural activity occurring in the brain and the data ultimately captured, there is a long chain of transformations: signals must be detected, amplified, filtered, subjected to feature extraction, and represented through algorithms before any meaningful output is produced. At each stage, iBCI data become increasingly entangled with device-specific engineering and external processes. Because these processed signals are not in a one-to-one relation of identity with the underlying neural events or cognitive states, and because they reflect layers of developer innovation and machine interpretation, the boundary between what “belongs” to the user and what is the product of iBCI design becomes blurry. Therefore, the application of property or IP frameworks to iBCI data would be practically and conceptually challenging and unlikely to resolve the gaps identified.

In light of the foregoing challenges, we propose a tailored and multi-layered approach that seeks to address the identified gaps in a risk-proportionate manner. These suggestions are intended to be considered across the various clinical and research contexts in which iBCI data are generated and aggregated, including industry-sponsored trials, clinical deployments, and publicly-funded academic studies, though their implementation should be calibrated to context and available resources, recognizing that smaller research settings may face different resource constraints than large commercial actors. This applies particularly to the suggested emerging technical safeguards, such as differential privacy, machine unlearning, blockchain-based consent management, and traceable data lineage, as well as to the more exploratory governance proposals, such as inference-sensitive use restrictions and benefit-sharing models, whose feasibility and suitability across specific iBCI deployment contexts remain to be established. Implementing the presented framework will require efforts not only from policymakers, but also, of equal importance, from clinicians, researchers, and developers working with iBCIs, as well as the input of iBCI users and their care partners.

Addressing the de-identification dilemma

To address the de-identification dilemma, opportunities exist to sensitize de-identification standards to the realities of modern re-identification methods. De-identification should be treated as one necessary but not sufficient layer of privacy protection, rather than a decisive threshold after which all downstream protections cease to apply. Primary responsibility here lies with iBCI developers and researchers for the implementation of robust de-identification methods, and with regulators and funders for setting minimum standards and oversight expectations.

To ensure that de-identification is as effective as possible, clinicians, researchers, and developers engaged in iBCI work could apply differential privacy or related privacy-preserving measures where possible. Developers and researchers could also consider red-teaming approaches (where adversarial attacks are simulated to identify and patch weaknesses164) to test and demonstrate the robustness of de-identification methods within their specific devices and data modalities, rather than relying on a monolithic model like HIPAA’s safe harbor or the judgment of de-identification experts without iBCI-specific expertise. Recognizing that even state-of-the-art de-identification may not provide definitive protection, iBCI data sharing for secondary use could, whenever possible and including when data have been de-identified, be paired with auditable access environments, such as secure enclaves or federated access frameworks, particularly in the case of iBCI systems that generate especially high-dimensional, longitudinal, or semantically rich datasets, like many speech interfaces. In tandem, ongoing implementation science research and real-world testing of effective de-identification and cryptography methods for iBCI data specifically are needed.

On the regulatory side, community efforts could be supported through positive incentive structures, for example, by making demonstrated privacy due diligence for de-identified iBCI data a prerequisite for public funding, similar to existing NIH data sharing requirements165. Ongoing policy deliberations create an opportunity to examine how emerging reforms might affect privacy standards for iBCI data and other kinds of data that may be particularly vulnerable to re-identification, and to explore targeted carve-outs or safeguards where warranted. Finally, policymakers in the U.S., EU, and beyond could explore extending selected protections to nominally de-identified iBCI data, including by recommending or requiring, as a condition of regulatory approval, the complementary use of auditable access environments when sharing for secondary use, thus keeping data traceable, and, where appropriate, maintaining certain data subject rights like the right to erasure, discussed in more detail below.

Strengthening personal control and data rights

To augment individual control over iBCI data, technical mechanisms and standards development to enhance patient agency, alongside appropriate data rights like those to erasure and portability, could be fostered. Effective implementation will require simultaneous action by developers, standard-setting bodies, and regulators.

Specifically, in parallel with the privacy-preserving approaches discussed above, iBCI developers and researchers may consider implementing traceability mechanisms, such as auditable data access logs and model-lineage tracking tools (e.g., via AI model passports108). In addition, future work could explore the effectiveness, safety, and practicality of “smart-contract” blockchain approaches109 (e.g., limited to on-chain storage of metadata or access-control tokens) to enable patient real-time decision-making over secondary access and use, supporting dynamic, longitudinal consent. On the model development side, decoder training pipelines may be designed in ways that preserve the feasibility of selective deletion of individual subject influences, for example, via SISA-like (sharded, isolated, sliced, and aggregated) training105. These measures would primarily operate on iBCI data, model training procedures, and access metadata stored outside of the implant itself, and so their feasibility would likely not be substantially affected by its real-time, power, and safety constraints. That said, engineering costs and potential clinical risks in the context of iBCIs warrant further investigation, and the necessity and feasibility of such measures will likely vary depending on whether the specific iBCI datasets in question are only used for personalization or also for training global models to be deployed across users. Continued iBCI data standards-development efforts, such as those by ISO and IEC, can ensure interoperability and more uniform applicability of data security approaches across iBCI systems. Importantly, inclusion of iBCI-specific information, such as decoder parameters, effector-control signals, and synchronization metadata, can support effective data portability.

To support these efforts, opportunities exist to create incentives for the adoption of technical standards, such as via making adherence to recognized iBCI data storage standards an expected part of approval submissions, similar to established FDA expectations around imaging format interoperability166. Similar mechanisms may be considered for data or model traceability methods, though further work is needed to stress-test such methods and identify the optimal approaches for clinical iBCI data prior to regulatory action. Finally, jurisdictions that do not currently grant portability or erasure rights for medical-device-generated data, such as the U.S. under HIPAA, could consider targeted regulatory extensions for iBCI data through agency rulemaking (e.g., by the U.S. Department of Health and Human Services) or statutory amendments, recognizing their privacy and autonomy implications.

Unifying iBCI informed consent

To address limitations in current iBCI consent practices, informed consent for iBCI data use and sharing could be established as a distinct, longitudinal, and standardized process. Here, particular responsibility lies with clinicians, researchers, and developers, while regulatory endorsements or requirements could play a supporting role.

In the short term, where most iBCIs are solely available as part of research studies, clinicians, researchers, and developers are best positioned to ensure that individuals are comprehensively counseled about device-specific data-related risks, benefits, and uncertainties, including the plausible need to process and analyze data for research purposes. Opportunities exist to design this process as explicitly longitudinal, with patients empowered to opt out of non-essential provisions throughout. As iBCIs transition into clinical practice, where therapeutic benefit, rather than the collection of research data, may be the primary goal, data-related consent should be disentangled from consent for device implantation and clinical use, to ensure that access to a clinically necessary and potentially life-changing device does not depend on agreeing to potentially wide-ranging data reuse terms. In research contexts, funders could consider calibrating data-sharing expectations for high-resolution iBCI datasets, so that open-science requirements remain proportionate to, and do not inadvertently undermine, the exercise of data-related autonomy and informed consent in the context of iBCI recordings. To facilitate implementation, future work is needed and underway to develop a standardized template for iBCI consent, adaptable to device architecture and inference potential, and incorporating explicit data-related considerations167.

Once a standardized consent template exists, professional bodies and regulators such as the FDA could endorse it via guidance or, where feasible and appropriate, conditional incentives linked to regulatory approval. In investigational contexts, iBCI-specific informed consent criteria could be integrated into institutional review board (IRB) review processes where appropriate.  

Establishing guardrails against misuse

To minimize risks from misuse, secondary use of iBCI data could be limited to clearly defined and authorized use cases. Responsibility for preventing misuse lies with iBCI developers, data holders, and controllers, supported by (and subject to) regulatory guidance and enforcement.

Complementing privacy- and control-enhancing measures as well as comprehensive informed consent, providers could consider explicitly counseling patients about sharing iBCI data with third parties, such as companion applications, whose terms and conditions may contain permissive secondary-use clauses, circumventing HIPAA or even GDPR safeguards. Clinical sites and manufacturers may explore applying an iBCI-adapted form of the Mental Data Protection Impact Assessment, an inference-sensitive, anticipatory risk assessment model for the processing of data that can be used to infer cognitive, affective, or conative mental states168. In adjusted form, this could be used to structure device architecture-sensitive pre-release review of secondary iBCI data uses that are not prohibited or directly covered by patient consent (e.g., use of de-identified data or use of identifiable data for medical AI model training), complementing existing purpose-limited business associate agreements (under HIPAA) and data processing agreements (under GDPR) between healthcare providers and external processors, which contractually restrict downstream processing purposes but do not systematically evaluate inference-level risks, and may not fully prevent problematic secondary use even of identifiable medical data, as illustrated by Project Nightingale122. Finally, future work is needed to convene multiple stakeholders, including clinicians, researchers, developers, ethicists, regulators, patients, and individuals with lived experience of iBCI use, to articulate iBCI-specific guidance that distinguishes clinically or scientifically justified use cases from ethically problematic ones, informed by criteria such as clinical necessity, proportionality, and availability of alternatives.

Building on such guidance, regulators with authority over data processing or device deployment may consider restrictions of particularly harmful downstream uses (which has previously been discussed for neuroscience data broadly169), enforceable through supervisory authorities with penalties or sanctions for non-compliance. Precedent to build upon exists both in the U.S., where GINA protects genetic data from misuses like health insurer and employment discrimination130, and in the EU, where the AI Act explicitly prohibits certain AI use cases, such as emotion-inference tools in employment and education contexts71. For iBCI data, harmful use restrictions could, among other cases, explicitly proscribe personalized advertising, employment-related monitoring, and insurer risk profiling, while law enforcement access could be made subject to heightened judicial scrutiny. While prior work has focused on using inference potential to define a protected data category (cognitive biometric data8), this approach could directly govern the permissibility of specific high-sensitivity inferences (like intended speech, affective states, or mental imagery), for example, by limiting their use to medically necessary, neurorehabilitative, neurorestorative, or biomedical research settings.

Fostering benefit-sharing and responsible monetization

To address ethical issues surrounding the commercialization of iBCI data, community benefit-sharing models may be explored, and monetization of iBCI data could be limited to appropriate clinical or scientific purposes. Primary responsibility here lies with developers and data-holding institutions, in dialogue with patient communities, with regulators playing a boundary-setting and enabling role where appropriate.

In the near term, as part of the informed consent process, clinicians, researchers, and developers should clearly communicate relevant data rights to prospective iBCI users, including expectations surrounding ownership or benefit-sharing over iBCI data, and how de-identified datasets might be reused or potentially commercialized downstream. In parallel, exploratory work could assess mechanisms by which downstream value derived from iBCI data might be re-channeled into work that supports patients and patient communities, potentially drawing from health data cooperative models that emphasize patient-centered governance170. Such benefit-sharing frameworks could, for example, re-invest portions of downstream value (e.g., derived from licensing or eventual product commercialization) into patient-led research funds, advocacy efforts, or access programs. Future work is needed to systematically integrate patient advocate, clinician, developer, legal, and neuroethics perspectives when evaluating iBCI monetization models, so that iBCI data value flows are aligned with fairness, transparency, and shared benefit171,172.

Regulators could support the development and evaluation of such models through publicly funded pilots and patient engagement initiatives. If these models prove fair, feasible, and effective, regulators and funders could encourage adoption through guidance, funding, or reimbursement conditions. Finally, regulators may also consider measures aimed at limiting monetization of iBCI data to purposes with demonstrable clinical or scientific value, though further work is needed to define evaluation criteria, feasible enforcement mechanisms, and appropriate governance strategies.

Cross-cutting implementation considerations

The foregoing proposals may contribute to tailored, risk-proportionate, and multi-layered approaches to iBCI data governance. They are intended as a basis for appropriately nuanced, collective deliberation as the iBCI field continues to rapidly evolve. The breadth of measures discussed reflects the range of iBCI architectures, risk profiles, and deployment contexts they are meant to span, rather than a uniform set to be adopted in full; in a given setting, only a proportionate subset may be warranted. Although governance and regulatory mechanisms vary internationally, the structural and technical features of iBCI systems that give rise to the identified gaps in protections, as well as many of the corresponding safeguards examined here, are not jurisdiction-specific. Notably, near-term progress is likely to depend primarily on non-regulatory governance mechanisms, professional community efforts, and technical safeguards, rather than on new or substantially revised regulation, which can be slow and subject to institutional inertia.

Where regulatory efforts are nonetheless needed, they could be implemented through existing statutory authorities (e.g., data protection authorities or medical device regulators), rather than through entirely novel, bespoke, ad hoc, or idiosyncratic institutional structures or legislation, and they should stay adaptive to the rapidly evolving technical landscape, for example by including sunset clauses, which ensure regular reassessment of their respective statutes, or other planned adaptive regulation tools173. Potential regulatory measures should be calibrated to differences in neural data types, as well as to differences in the inferences and use cases they support. Broad, undifferentiated categorization risks unnecessarily constraining responsible innovation for patient populations with urgent unmet needs and paradoxically creating potential blind spots for the most sensitive data types or uses, including those involving iBCI data. Across relevant regulatory, clinical, or commercial entities, experts in neural and iBCI data privacy could be integrated into existing oversight structures such as institutional privacy offices, data access committees, and IRBs, to monitor and advise on neurotechnological developments and evolving protection needs. Resourcing will vary by context and may involve coordinated support across academia, industry, professional societies, funders, and regulators.

In parallel, empirical work will be essential to identify past, current, and prospective iBCI users’ experiences and preferences related to data privacy, as well as iBCI clinicians’ knowledge of the identified issues. This could inform near-term guidelines for consent and communication as well as long-term regulatory priorities and policy design. In addition, continued technical research is needed to empirically characterize re-identification and inference risks for iBCI data specifically and to explore the robustness and practical applicability of privacy- and autonomy-preserving approaches, including but not limited to differential privacy, secure enclaves, and machine unlearning. Clarifying technical capabilities and limitations surrounding iBCI data will help balance privacy protections with the need for research that may depend on large, representative datasets.

Forward-looking outlook

As governance discussions unfold, opportunities exist for iBCI stakeholders to be mindful of these issues and to proactively incorporate education about them into program design. Clinicians and researchers may play important roles in counseling patients about how iBCI data may be used or shared, which uncertainties exist, and which rights are present, absent, or uncertain. As iBCIs transition from research to clinical practice, data protection frameworks, professional norms, and associated safeguards will need to evolve alongside them. Ongoing technical research, professional community efforts, and regulatory support can help ensure that patient privacy, autonomy, and trust are maintained without hindering the immense promise that these innovations hold for patients worldwide.

Acknowledgements

Figure 1 was created in BioRender (https://biorender.com/5vzqxk5) with an icon used with permission under a premium Flaticon license. We thank the anonymous reviewers for their valuable feedback, which greatly improved this manuscript.

Author contributions

J.D.S.: conceptualization; investigation; writing-original draft; writing-review and editing. M.J.Y.: conceptualization; investigation (supporting); supervision; writing-review and editing.

Peer review

Peer review information

Communications Medicine thanks Li Jiang and the other anonymous reviewer(s) for their contribution to the peer review of this work.

Funding

No specific funding was received for this work. M.J.Y. has received research support from NIH-NINDS K23NS140495, NIH BRAIN Initiative (F32MH123001), Mass General Neuroscience Chen Institute Transformative Scholars Award; NIH Common Fund’s Bridge2AI (OT2OD0327); DOD CDMRP (HT9425-24-1-1081); and the American Academy of Neurology (Palatucci Advocacy Award). The perspectives herein are those of the authors and do not necessarily reflect the views of any institution, department, or organization.

Competing interests

J.D.S. has nothing to declare. M.J.Y. has received research support from the NIH BRAIN Initiative, Mass General Chen Institute Transformative Scholars Award, NINDS, Department of Defense, and the American Academy of Neurology. M.J.Y. is employed by MGH/MGB. The MGH Translational Research Center has a clinical research support agreement (CRSA) with Ability Neuro, Axoft, Medtronic, Neuralink, Neurobionics, Precision Neuro, Synchron, and Reach Neuro. Mass General Brigham (MGB) is convening the Implantable Brain-Computer Interface Collaborative Community (iBCI-CC); charitable gift agreements to MGB, including those received to date from Paradromics, Synchron, Precision Neuro, Neuralink, and Blackrock Neurotech, support the iBCI-CC.

Footnotes

Publisher’s note Springer Nature remains neutral with regard to jurisdictional claims in published maps and institutional affiliations.

References


Articles from Communications Medicine are provided here courtesy of Nature Publishing Group

RESOURCES