NeuroAI NEUROAINEUROAI.SITE
ESC

Who owns your neural signals? The quiet race to write brain-data rights into law

As brain-computer interfaces (脑机接口) leave the lab, China and the world are racing to decide whether neural data is just another health record or a new class of human right.

2026-10-07 · 831 words · NeuroAI
Who owns your neural signals? The quiet race to write brain-data rights into law

In a Beijing hospital, a patient with epilepsy agrees to wear a brain-computer interface (脑机接口) headset during surgery so doctors can map language function. The device records not just electrical noise but patterns that, decoded by machine learning, can reveal what the person intends to say, what they feel, even traits they never chose to disclose. Who is allowed to keep that signal? Who may sell it, and who can delete it?

These questions sounded like philosophy a decade ago. In 2025 and 2026 they became regulation.

China puts neural data on the table

China moved early on the ethics front. In 2023, relevant authorities issued the country's first Ethical Principles and Governance Recommendations for Brain-Computer Interface (脑机接口) (《脑机接口伦理原则和治理建议书》), laying out five principles: non-maleficence, respect for autonomy, privacy protection, transparency and fairness. It named the core risks plainly — neural-intervention safety, non-autonomous decision-making, and leakage of "brain privacy."

The more operational step came on 23 July 2025, when the Ministry of Science and Technology (科技部) published the Ethical Guidelines for Neurotechnology Medical Research Involving Humans (《涉及人的神经技术医学研究伦理指引》), drafted by the medical-ethics subcommittee of the National Science and Technology Ethics Committee. The guidelines apply to neuro-data collection, analysis and neuromodulation in human research. They state plainly that researchers must treat any technology touching "mental privacy" with caution, build safeguards against leakage, misuse and access without consent, and guarantee participants the right to access, correct and delete their own mental data.

Under China's Personal Information Protection Law (个人信息保护法), neural information is already treated as sensitive personal information, which means processing it requires the individual's separate consent — and, critically, a separate consent again if that data is later shared. Legal scholars note that neural data is unusually hard to anonymise: because brain signals are highly individuating, re-identification risk stays high even after de-identification. When Beijing and Shanghai unveiled brain-computer interface (脑机接口) action plans in January 2025 that floated "open sharing" of neural data, legal commentators pushed back, arguing neural data should not be opened the way ordinary health data is.

The global picture is fragmenting

China is not alone. In 2020 Chile became the first country to pass a neuro-protection law, forbidding systems that intrude on neuronal activity in ways that could damage a person's psychological continuity or weaken free will. UNESCO, in November 2025, adopted its first ethical recommendation on neurotechnology across its 194 member states — non-binding, but a global marker.

The United States is stuck at the federal level. The MIND Act, introduced in the Senate in September 2025, does not actually protect neural data; it only directs the Federal Trade Commission to study the issue, and it has stalled in committee. In the vacuum, states moved: Colorado, California, Montana and Connecticut have classified neural data as sensitive information, and Montana went further by extending its genetic-privacy law to cover neurotechnology outright.

Why this matters to ordinary readers

Most people will meet neural data long before they meet an implant. Consumer EEG headsets (脑电图头戴设备) for sleep, focus and gaming already stream brain signals to apps. A workplace wellness programme, an insurer, or a landlord could one day ask for "just a quick brain scan." The legal gap is the danger: today, in most jurisdictions, there is no settled rule saying a company may not monetise the signal your brain produces while you wear its device.

The emerging consensus among lawmakers is to treat neural data as a new category — closer to biometric and genetic data than to a step count. The scholarly frame gaining ground is a set of "neuro-rights": cognitive liberty, mental privacy, mental integrity and psychological continuity.

What to watch next

The practical move for any reader is to treat this as a developing story rather than a settled one. Revisit it in a few months: the claims that survive contact with real deployments are the ones worth keeping; the rest will quietly fade. Following the direction of travel beats betting on any single announcement.

Honest limitations

This article describes proposed and enacted rules, not a settled global standard. China's 2025 guideline is advisory for researchers, not a binding data-protection statute, and enforcement mechanisms for neural data specifically are still developing. The UNESCO recommendation is non-binding. U.S. state laws vary in scope and are fragmented. Figures about re-identification risk and anonymisation difficulty come from legal scholarship rather than measured breach data. No single worldwide treaty yet defines "neural data" uniformly, so cross-border cases remain ambiguous.

What readers can do now

  • Before using any consumer brain-sensing device, read its privacy policy for where neural data is stored and whether it is uploaded to the cloud.
  • Prefer devices that process signals locally on the device rather than streaming raw brain data to servers.
  • In China, know that neural information is legally "sensitive personal information" — you can demand separate consent and deletion under the Personal Information Protection Law (个人信息保护法).
  • Support clear labelling: ask employers, clinics and apps whether neural data is shared with third parties, and for what purpose.

Related coverage

More in “Brain–Computer Interface” → · Back to home · Markdown version