Old version — revision 1
This is a fixed snapshot of Mental privacy, saved by Import as part of the initial corpus import. It is not edited and it is not updated; the article may have changed since.
Edit summary: Initial import of content/mental-privacy.md — the filesystem corpus, unchanged. Not an edit.
The question of what can be inferred about a person's mental states from neural and physiological recordings, and what protection that information should receive.
Mental privacy is the interest a person has in controlling what others can learn about their thoughts, intentions, and internal states from measurements of the brain and body. It is the most-invoked of the proposed Neurorights and the one where the gap between public expectation and technical reality is widest: no device can read an uncooperative person's thoughts, and the systems that infer the most about mental life mostly do not record from the brain at all.
Functional magnetic resonance imaging measures blood-oxygenation changes on a timescale of seconds, which is orders of magnitude slower than neural firing. Within that limit, the statistical methods surveyed in Neural decoding have achieved results that would have seemed impossible in 2010 — provided the decoder is trained on the individual whose brain it will read.
The clearest demonstration is a 2023 study in which a language model was used to reconstruct the approximate meaning of stories a participant heard, imagined, or watched while in the scanner.1 The output was a paraphrase rather than a transcript — the decoder recovered gist, not words. Three constraints matter more than the result. Each decoder required roughly sixteen hours of scanner time with that specific participant. Decoders did not transfer across people. And the authors tested resistance directly: participants who counted, named animals, or silently told a different story defeated the decoder. Mental privacy, in that experiment, was preserved by ordinary volition.
Related work reconstructs approximate versions of seen images from fMRI using generative models, with the same requirements — large per-subject training sets, cooperation, and a stationary head in a magnet costing millions of dollars.
Electroencephalography, the signal available in consumer devices, is far cruder. Scalp electrodes sum the activity of very large populations of neurons through skull and skin, and dry-electrode headsets add substantial motion artifact. What such devices can do reliably is classify gross states: alert versus drowsy, high versus low task engagement, the presence of a stimulus-evoked response. What they cannot do is recover content. Marketing that describes consumer EEG as reading emotions or thoughts overstates the signal by a wide margin, in the same way that consumer claims for the stimulation devices covered in Non-invasive neuromodulation overstate their effects.
The reading a decoder gives is not a fact about the mindDecoders output the most probable interpretation under a trained model. A confident reconstruction from a mismatched model is confidently wrong, and the subject has no way to contest it. This is the same failure mode that discredited earlier physiological lie detection.
Electrodes placed on or in cortex give a much better signal, and the results are correspondingly stronger. Two 2023 studies decoded attempted speech from participants with paralysis at rates in the range of sixty to eighty words per minute with substantial but usable error rates, using the penetrating microelectrode arrays and the surface grids described in Electrocorticography interfaces respectively.23 Speech neuroprosthesis covers the systems in detail.
These decode attempted speech — the motor commands a person issues when trying to talk. That is a form of expression, not private thought, and the distinction has been treated as ethically load-bearing. It became less clean in 2025, when researchers reported decoding imagined speech from motor cortex in participants with implanted arrays. The signal for inner speech was weaker and noisier than for attempted speech, but present. The same group proposed a safeguard that indicates where the field expects the problem to go: a mental password that the decoder must detect before it begins interpreting, so that inner speech is not decoded by default.
This is the first case in which a neural device has been designed against the possibility of reading its user's private thoughts, and it is worth noting what makes it tractable. The electrodes are surgically implanted, the decoder is trained on that person, and the person controls whether the system is powered. None of those conditions holds for the surveillance scenario that mental-privacy law is usually written about — and none of them is guaranteed by the commercial implant programmes described in Neuralink and Synchron, where the decoder runs on infrastructure the user does not control.
Courts have consistently refused to admit neuroimaging as evidence of what a person knows or believes. A US federal court excluded fMRI-based lie detection in a 2010 fraud prosecution, finding the technique had not been shown reliable in real-world conditions, and the exclusion was upheld on appeal. India's Supreme Court held in 2010 that involuntary polygraph, narcoanalysis, and brain-signature testing violate the constitutional protection against self-incrimination and the right to personal liberty — a ruling prompted by the use of an EEG-based "brain electrical oscillation signature" technique in Indian criminal cases, including one murder conviction.
Data-protection law has moved faster than evidence law. EU law treats data concerning health and biometric identification as special categories requiring an explicit lawful basis, which covers clinical neural recordings. Several US states have added neural data to their sensitive-data definitions since 2024, alongside the constitutional and international instruments surveyed in the companion article on rights. All of these regimes regulate the signal, and the difficulty is that mental inference does not depend on neural signals.
Stimulation raises a separate and less-discussed question. A device that alters neural activity — the implanted systems in Deep brain stimulation, or the low-bandwidth transfers demonstrated in Brain-to-brain interfaces experiments — does not read a mental state but changes one, and the interest violated is integrity rather than privacy. Existing data-protection law has nothing to say about it.
The most important fact about mental privacy in 2026 is that neural recording is a poor way to learn what someone is thinking compared with the alternatives already deployed. A phone's location history, search queries, purchase record, and typing latency support inferences about mood, health, political orientation, and intention that no EEG headset approaches, and the continuous heart-rate and sleep records collected by consumer wearables sit in the same category. Advertising systems have operated on this basis for two decades.
This has two consequences. Protecting neural data specifically produces the same incoherence diagnosed in the debate over genetic exceptionalism described in Genetic discrimination: the same inference is regulated or unregulated depending on which sensor produced it. And it means the realistic near-term risk is combination rather than decoding — a crude engagement signal from a headset joined to behavioural data that supplies the content the neural signal lacks.
Where the exposure actually isWorkplace fatigue-monitoring headwear that detects microsleep from EEG is in commercial use in mining and long-haul transport. It records neural data continuously, in an employment relationship where consent is compromised, and is regulated in most jurisdictions as occupational safety equipment rather than as neurotechnology.
Employment is the likeliest first test of the doctrine, because it is where the recording is already happening and where refusal has a cost. Fatigue monitoring has a genuine safety rationale — driver microsleep kills people — and produces a continuous log of a worker's arousal that an employer can retain and correlate. Reports from 2018 described EEG-based monitoring of factory workers and train drivers in China; the scale was never independently verified, but the products exist and are marketed openly.
Consumer devices raise a different issue: the terms of service. A review published by the NeuroRights Foundation in 2024 of consumer neurotechnology companies' privacy policies found that most asserted broad rights over user neural data, including transfer to third parties, with few meaningful limits. The data is currently low in information content. The retention periods are indefinite, and the models that might later be applied to it have not been built.
Whether inner speech is protected by existing constitutional guarantees against self-incrimination is untested. The US doctrine distinguishes testimonial from physical evidence; a decoded thought sits uncomfortably between them, and no case has presented the question.
Whether decoders can be made to work without per-subject training is the technical threshold that would change the risk picture. Progress on subject-transferable models has been slow, and the anatomical variability between individual brains is a real obstacle rather than a data-scale problem — the same variability that makes the reconstruction pipelines of Whole brain emulation a per-individual undertaking rather than a general method.
And there is no accepted method for validating a decoder's output. In a clinical Brain–computer interface the user corrects errors immediately, which supplies ground truth. In a surveillance application there is no such feedback, no way for the subject to demonstrate that the decoder is wrong, and no established standard a court could apply — the same structural problem that made polygraph evidence inadmissible, arriving now with better mathematics attached.
paperTang, J., LeBel, A., Jain, S., Huth, A.G. "Semantic reconstruction of continuous language from non-invasive brain recordings." Nature Neuroscience, 2023.↩Each decoder was trained on many hours of scanner data from one cooperating participant, recovered gist rather than words, and failed when the participant deliberately thought about something else.
paperWillett, F.R. et al. "A high-performance speech neuroprosthesis." Nature, 2023.↩A single participant with ALS and implanted intracortical arrays; the system decodes attempted speech, which is a motor act, not inner speech.
paperMetzger, S.L. et al. "A high-performance neuroprosthesis for speech decoding and avatar control." Nature, 2023.↩A single participant with severe paralysis, using a surface electrode grid and a decoder trained on that person alone.