Somewhere between the funding rounds and the CES demo booths, neurotech has quietly built itself a real industry, with real hardware and a real appetite for a dataset unlike anything else on the market: a direct readout of your nervous system. Industry trackers now describe the sector as crossing a genuine tipping point, with BCI market forecasts routinely projecting double-digit annual growth through the end of the decade. Investors are excited. Founders are excited. Almost nobody is asking the less glamorous question.
Startups fail. That is not cynicism, it is the base rate of the industry, and neurotech is not exempt from it just because the product happens to touch your skull. A missed clinical endpoint, a Series B that never closes, a founder who runs out of runway: any of these can end a company in a matter of weeks. So what actually happens to the neural data a company has already pulled from your brain when that happens? And in the case of implanted hardware, what happens to the device still sitting inside you?
The historical record on this is not reassuring, and the legal record is barely written at all.
When the company dies, the implant doesn’t
The clearest cautionary tale in neurotech history is Cyberkinetics, the company behind the original BrainGate brain-computer interface. Founded in 2001, Cyberkinetics implanted its first human participant with a Utah microelectrode array in 2004, letting people with paralysis move a cursor or a robotic arm using thought alone. It was a real scientific breakthrough. It was not, however, a sustainable business, and the company wound down around 2009. According to a detailed account from Knowing Neurons, Cyberkinetics’ collapse revoked the company’s FDA investigational device exemption, cutting off the formal regulatory pathway for the participants who still had hardware implanted in their brains. Academic partners at Brown University eventually secured a new IDE to keep the research alive, but that took time, and it happened despite the company’s failure, not because of any plan the company had in place.
The Argus II bionic eye tells a similar story on a larger scale. When Second Sight wound down its support operations, more than 350 patients were left with implants that had gone obsolete and, in many cases, could not be safely removed. Medicare had reimbursed roughly $122,500 per patient for the device as of 2017, money that, in hindsight, bought a device with no guaranteed lifespan past the company’s own solvency.
Neither of these cases is really about data in the abstract. They’re about a harder fact: unlike a failed SaaS product, where the worst outcome is a service that stops working, a failed neurotech company can leave behind physical hardware, embedded in a human body, with no clear owner, no update path and no one contractually obligated to explant it. The data question sits downstream of that. If a company can’t guarantee it will still exist to support the device, it’s a reasonable bet that it hasn’t thought hard about who inherits the signals that device has been recording for years.
The consumer data gap nobody’s headband will fix
Implanted BCIs are the extreme case, but the much larger, much less regulated category is consumer neurotech: EEG headbands, earbuds and wellness wearables sold directly to anyone with a credit card, no prescription required. This is a genuinely different regulatory world from an FDA-cleared medical implant, and conflating the two is a mistake this industry makes constantly.
The most rigorous look at that world so far comes from the Neurorights Foundation, whose 2024 report, Safeguarding Brain Data, surveyed the privacy practices of 30 consumer neurotech companies. The findings were blunt. Only one of the 30 offered meaningful limits on how it could use or sell a user’s neural data, according to STAT News‘ coverage of the report, and fewer than half committed to basic protections like encryption or de-identification. Devices like the ones covered in 5 Neurotech Devices You Can Actually Buy Today sit squarely inside this gap: genuinely useful for tracking focus or sleep, and largely unaccountable for what happens to the signal once it leaves your head.
The reason is structural, not just sloppy. As Davis Wright Tremaine points out, HIPAA doesn’t apply here because these companies aren’t HIPAA-covered entities, and the federal government has no dedicated neural-data statute. Until Congress acts, the entire federal backstop is Section 5 of the FTC Act, a general ban on “unfair or deceptive” practices that says nothing specific about brain data at all. In April 2025, Senators Chuck Schumer, Maria Cantwell and Ed Markey sent a letter urging the FTC to investigate, but a letter is not a rule, and no rule has followed yet.
A few things worth separating out clearly, because this industry blurs them constantly:
Medical implants like BrainGate or DBS systems operate under FDA trial protocols and, once cleared, FDA oversight, though as Cyberkinetics showed, that oversight can evaporate the moment the company does
Consumer wellness devices like EEG headbands and focus trackers operate almost entirely outside federal health privacy law, governed mostly by their own privacy policy
Military and defense-funded neurotech, largely developed under DARPA and similar contracts, runs on data-custody terms set by the government sponsor, a different animal from either of the above and one this piece isn’t trying to cover
None of these three categories share a data-protection floor, so a headline about “neurotech data” without specifying which one is close to meaningless
If you’re currently wearing a consumer EEG device, it’s worth actually opening the privacy policy instead of scrolling past it. Most people never do. 🧠
Two states tried to legislate this, then bankruptcy court got involved
Lawmakers noticed the gap before Congress did. In April 2024, Colorado passed HB 24-1058, becoming the first state to explicitly classify neural data as sensitive information under its privacy act, requiring opt-in consent and a documented data protection assessment before a company can collect it. California followed in September 2024 with SB 1223, amending the CCPA to add neural data to its list of sensitive personal information alongside genetic and biometric data, effective January 1, 2025. Both bills were backed by the Neurorights Foundation, and both represent real, if narrow, progress: a company now has to ask before it starts collecting your brain activity in either state.
Here’s the catch nobody flagged loudly enough when these laws passed. Consent rules govern how a company collects and uses your data while it’s operating. They say very little about what happens when that company stops operating. Most state privacy statutes, including the general framework the CCPA sits inside, carve out asset transfers that happen during a merger, acquisition or bankruptcy from their normal definition of a “sale,” as long as the buyer agrees to honor the seller’s existing privacy terms. That carve-out wasn’t written with neural data in mind, but it applies to neural data anyway, because these laws regulate the category of sensitive information, not the specific circumstances under which it changes hands.
In other words: Colorado and California can require a neurotech company to get your consent before it starts harvesting your brainwaves. Neither law does much to stop that same data from moving to a new owner the moment the company files for Chapter 11. That gap is not hypothetical. It already has a real precedent, and it’s a big one.
The 23andMe preview
In March 2025, 23andMe filed for Chapter 11 bankruptcy, putting the genetic data of more than 15 million customers up for sale as a company asset. This isn’t a neurotech case, but it’s the closest real-world dry run this industry has for what a neurotech bankruptcy will look like, and the parallels are hard to ignore: a direct-to-consumer biological data company, operating outside HIPAA’s reach, whose own privacy policy had quietly reserved the right to transfer customer data “in the event of a bankruptcy, merger, acquisition, reorganization, or sale of assets.”
State attorneys general told customers to delete their profiles immediately. More than two dozen states sued to block the sale, arguing genetic data is fundamentally different from ordinary business assets like inventory or office furniture. It didn’t work. Pharmaceutical giant Regeneron placed the initial winning bid near $256 million, before TTAM Research Institute, a nonprofit newly formed by 23andMe’s own former CEO Anne Wojcicki, outbid it at $305 million. A federal bankruptcy judge in Missouri approved that sale in June 2025, per NPR, even as California, Kentucky, Tennessee, Texas and Utah remained opposed. As the Lawfare analysis of the ruling put it, existing privacy, bankruptcy and bioethics frameworks were never built to handle a transfer like this one.
Swap “genetic data” for “neural data” and the mechanics barely change. A wellness headband company, an early-stage BCI startup, any consumer neurotech firm not covered by HIPAA, all of them can write the exact same bankruptcy clause into their privacy policy that 23andMe did, and courts have already shown they’ll generally let that clause do its job. Brain data isn’t legally exceptional in bankruptcy the way most people assume it is. It’s an asset like any other, which is precisely why the competitive moats neurotech companies build around proprietary neural datasets cut both ways: valuable to build a company on, and just as valuable to sell off when that company fails.
Would a court treat neural data with more caution than genetic data, given how directly it maps to mental states? Maybe. Nobody has tested that question yet, and until someone does, the safest assumption is that it won’t be treated any differently.
What to actually check before you trust a device with your brain
None of this means don’t use neurotech. It means read the parts of the privacy policy everyone skips, specifically the ones about what happens if the company doesn’t make it. A few concrete things worth checking before you buy, or before you keep using, a neural-data device:
Search the privacy policy for the words “bankruptcy,” “merger” or “sale of assets,” and read exactly what it says your data becomes in that scenario
Check whether the company offers a real, working deletion mechanism now, not a promise to build one later, since Colorado and California both give you a legal right to ask
Look for a specific data retention window; a company with no stated limit on how long it keeps your neural data has no incentive to ever delete it
For anything implanted, ask in writing what happens to explant support and continued device function if the company shuts down, and get that answer before you consent to surgery, not after
Watch the company’s funding signals the way you’d watch any other vendor you depend on; a startup on its last runway is a startup that may sell your data to whoever’s still willing to buy it
If you build in this space rather than just use these devices, the honest move is writing the bankruptcy contingency into your privacy policy in plain language now, before a lawyer has to write it for you during a Chapter 11 filing. Consumers increasingly expect that kind of transparency, and regulators are clearly circling the industry that doesn’t provide it.
So here’s the actual question worth sitting with: if the company behind the device on your head or in your skull disappeared tomorrow, do you actually know who would own the data it already collected? For most people using neurotech today, the honest answer is no. That’s worth fixing before it becomes someone else’s decision to make.


