Ask ten neurotech executives who owns the data streaming out of a user’s skull, and you’ll get ten different answers, most of them vague on purpose. That vagueness isn’t an oversight. It’s the default setting for an industry moving faster than the law can track it.
In April 2025, Precision Neuroscience became the first company developing a next-generation wireless brain-computer interface to win FDA clearance for its Layer 7 Cortical Interface, a 1,024-electrode array built into a polyimide film thinner than a human hair, cleared for temporary use up to 30 days during open brain surgery. Around the same time, Neuralink was quietly expanding its PRIME trial past 20 patients across four countries, each one carrying an N1 implant that reads 1,024 electrodes threaded into the motor cortex. Neither device is a mass-market product yet, but both generate the same uncomfortable question the moment a person’s brain activity becomes a data stream: once that data leaves your skull, who’s allowed to keep it, sell it, or hand it to a research partner without asking again?
The neurotechnology market is on pace to clear $38 billion by 2032, and NeurotechMag flagged several of the signals behind that inflection point earlier this year. The fastest-growing slice of it isn’t implants, though. It’s consumer wearables, headbands, earbuds, and wellness devices that read brainwaves without ever touching a hospital’s compliance department. That’s where the ownership question gets genuinely messy, and where almost nobody has a good answer.
The wellness gray zone doesn’t know what to tell you
Consumer neurotech skipped past the doctor’s office entirely, and its privacy policies show it. A 2024 review by the Neurorights Foundation, which examined the privacy policies and user agreements of 30 consumer neurotechnology companies, found that 29 of them provided no meaningful limits on their own access to a customer’s neural data. The numbers underneath that headline get worse the closer you look:
73% of the companies posted a privacy policy at all
60% said nothing specific about how neural data is handled, despite collecting it
roughly half let a user revoke consent after giving it
just 14 of the 30 let a user delete their own brain data on request
If you own one of these devices, pull up its privacy policy right now. You might be surprised how little it actually says about the signal it’s pulling straight from your head.
None of this is illegal, mostly because none of it is regulated. Devices like Muse, Emotiv Insight, and the newer Neurode ADHD-monitoring headband, several of which NeurotechMag has covered as some of the most accessible neurotech on the market, sit outside HIPAA entirely. HIPAA protects data inside a clinical relationship. A wellness headband sold direct to consumers, with no doctor or insurer anywhere in the chain, isn’t in that relationship, so the strongest federal backstop is Section 5 of the FTC Act, which only bars “unfair or deceptive” practices after the fact and doesn’t require a privacy policy to exist in the first place. The American Academy of Neurology tried to close part of that gap in March 2026, issuing guidance that treats consumer neurotech as a de facto adjunct to clinical care, even when the packaging says it isn’t intended to diagnose anything. That framing matters. It means a sleep-tracking headband that infers depression risk from EEG patterns could eventually be judged by clinical standards it was never built to meet.
Statehouses are writing the rules Washington won’t
Colorado got there first. House Bill 24-1058, signed into law in April 2024 and in effect since that August, made Colorado the first state to classify neural data as sensitive personal information, on the same tier as genetic data. Companies now need opt-in consent before collecting it, have to run a documented risk assessment, and have to disclose plainly whether they touch neural data at all. California followed within months with AB 1008 and SB 1223, effective January 2025. Montana passed its own version soon after. By mid-2026 the list had grown well past those three:
Connecticut’s SB 1295 folds neural data into its state privacy act starting July 1, 2026
Virginia’s HB 654 extends the same protection through the Virginia Consumer Data Protection Act
Illinois’s SB 2994 takes a narrower angle, restricting how insurers and employers use neural data specifically
Vermont passed its own consumer data privacy law with neurotechnology provisions in June 2026
The catch is that each state defines “neural data” a little differently, some counting only central-nervous-system signals, others reaching into the peripheral nervous system, others still debating whether data an algorithm merely infers should count at all. A company operating nationally is left stitching together compliance state by state, with no floor and no ceiling.
Congress has, so far, only proposed a floor. In September 2025, Senators Chuck Schumer, Maria Cantwell, and Ed Markey introduced the MIND Act, which doesn’t regulate neural data directly. It orders the FTC to spend a year studying how neural data is governed today, where HIPAA and the FTC Act fall short, and what a federal standard should look like, then report back to Congress. The same three senators had already sent the FTC a letter in April 2025, citing the Neurorights Foundation’s findings and asking the agency to open a formal investigation under its Section 5 and Section 6(b) authority. The MIND Act is still sitting in the Senate Commerce Committee, and the FTC hasn’t announced an investigation. For now, the industry is still largely writing its own rules.
The clinical side isn’t as clean as it looks
Medical BCIs look, on paper, like the safe end of this industry. Three companies are running the field’s most closely watched trials, and each took a different engineering bet on how to get inside your skull:
Neuralink’s N1 implant threads 1,024 electrodes across 64 hair-thin filaments directly into the motor cortex, the most invasive approach and the deepest signal access
Synchron’s Stentrode reaches the brain through a blood vessel instead of a craniotomy, and long-term data shows it staying stable in patients for more than two years without migrating
Precision Neuroscience’s Layer 7 sits on the brain’s surface rather than penetrating it, delivered through a sub-millimeter incision
Neuralink had reached more than 20 patients across the US, UK, Canada, and UAE by early 2026, all under FDA authorization for its PRIME trial rather than commercial sale. Precision’s Layer 7 clearance is worth being precise about too: it covers a temporary electrode array for surgical brain mapping, not a standalone, purchasable BCI. The full wireless system Precision is building around it remains in development. A cleared component is not a cleared product.
All three fall under HIPAA while they’re inside a clinical trial or hospital workflow, and that’s real protection, a level of access control and breach liability consumer wearables simply don’t have. But HIPAA’s shield thins once data gets de-identified for research, and neural data doesn’t de-identify the way a lab value does. Researchers studying re-identification risk in shared brain datasets have flagged that high-dimensional neural recordings can carry enough individual signature to undo standard anonymization, which matters as companies pool “de-identified” data to train the AI models that decode brain signals in the first place. Sitting inside a hospital’s compliance perimeter isn’t the same as being safe from every privacy risk a brain scan carries.
Chile already answered this question, and everyone else is still drafting
If you want to see what an enforceable answer looks like, skip the US patchwork and look at Chile. In 2021, Chile amended its constitution to protect brain activity and the information derived from it, becoming the first country to write neurorights directly into national law. Two years later, that language had teeth. Former Chilean senator Guido Girardi sued Emotiv, the same San Francisco company behind the Insight headset, arguing it kept his neural data for research purposes even after he’d deleted his account. In August 2023, Chile’s Supreme Court ruled unanimously in his favor and ordered the data erased, in what’s widely regarded as the first court decision anywhere to treat brain data as constitutionally protected.
The rest of the world is inching toward that standard, mostly without the enforcement mechanism:
Chile: constitutional protection since 2021, enforced by its Supreme Court in 2023
UNESCO: a global ethics recommendation adopted in November 2025, non-binding
EU: GDPR never names neurotechnology, and whether neural data automatically counts as protected “special category” data is still being worked out
OECD: added its own neurotech governance principles, including a call to safeguard personal brain data, without any enforcement power behind them
UNESCO’s Recommendation on the Ethics of Neurotechnology, adopted by 194 member states at its General Conference in Samarkand, capped six years of work and more than 8,000 stakeholder submissions gathered under experts including Nita Farahany and Hervé Chneiweiss. It’s the first global framework addressing mental privacy, informed consent, and protections for children using neurotechnology, and it’s exactly as binding as its name suggests: guidance member states are asked to consider, not law they’re required to pass. What nobody outside Chile has done yet is turn any of it into a ruling a company actually has to obey.
What this means if you’re building or buying into neurotech
If you’re building in this space, the patchwork is the risk, not the endpoint. Nine or more state laws with different definitions of “neural data” is not a stable compliance target, and the MIND Act’s FTC study is a floor-setting exercise, not a shield you can rely on today. If your product touches brain signals in any form, EEG, fNIRS, or cognitive states inferred from eye-tracking and voice, you’re closer to Colorado’s and Connecticut’s sensitive-data thresholds than you probably think. Building consent, deletion, and honest disclosure into the product now costs far less than retrofitting it after a state attorney general calls.
If you’re the one buying the device, a few questions are worth asking before you check out, and worth demanding real answers to:
Can you request full deletion of your neural data, not just your account?
Can data the company calls “de-identified” be re-linked back to you later?
What happens to your neural data if the company gets acquired or shuts down?
Does the privacy policy mention neural data by name, or just vague “personal information”?
We asked a version of this question a year ago, when connecting a human brain directly to an AI stopped being hypothetical. The honest answer is still “it depends,” on which state you live in, which company built the device, and whether anyone bothered to write a real privacy policy in the first place. So before you strap on your next neurofeedback headband, or start building the next one: if this data can reveal what you’re thinking, who else gets to know?


