Four US states now legally define what counts as neural data. Zero of them use the word “neurorights.” One country, Chile, wrote the concept directly into its constitution in 2021 and has since used it to force a company to delete a citizen’s brain data outright. More than 190 countries signed onto a UNESCO framework on the same subject last November, and not one of them is legally bound to enforce a single word of it.
That’s the strange state of neurorights in 2026: a legal idea with real court rulings behind it in one country, real statutes behind it in a handful of US states, and a lot of well-meaning consensus everywhere else that carries no enforcement power at all. The core question hasn’t changed since a group of scientists first raised it eight years ago. As brain-reading devices move from hospital labs into consumer headsets, who actually owns the data your brain generates, and what happens once a company has it? The answer, so far, depends entirely on which country you happen to be standing in when you ask.
Where “neurorights” came from
In the fall of 2017, neuroscientist Rafael Yuste called a meeting on Columbia University’s Morningside campus and invited close to 30 experts in neurotechnology, AI ethics, medicine, and law. The group, which became known as the Morningside Group, spent three days concluding something that sounds obvious now and wasn’t quite so obvious then: brain data access is a human rights question, not just a privacy policy question. They published the case in Nature that year, and Yuste later expanded the group’s original ethical priorities into five specific neurorights, according to Undark’s account of that meeting:
Mental privacy: brain data shouldn’t be sold or commercially transferred without strict limits
Personal identity: technology shouldn’t be allowed to disrupt someone’s basic sense of self
Free will: neurotechnology shouldn’t manipulate decision-making without a person’s awareness
Fair access to augmentation: mental enhancement tech shouldn’t exist only for people who can pay for it
Freedom from algorithmic bias: neurotech algorithms need protection from the same baked-in bias problems showing up across every other corner of AI
None of these five rights exist in the Universal Declaration of Human Rights today. That’s the actual ask behind the movement. Yuste’s group wants them added, and in the meantime, individual countries are testing rough versions of them on their own, with wildly different levels of legal force behind each attempt. Some of what follows is binding law. A lot of it is aspiration dressed up as policy, and telling the two apart is most of the point of this piece. 🧠
Chile’s experiment, and how it’s spreading across Latin America
Chile is the only country that has actually put neurorights into its constitution, and it moved fast. In October 2021, the Chilean Senate approved a constitutional amendment requiring that the law give special protection to brain activity and the data generated by it, making Chile the first nation to legally recognize neurorights at the constitutional level. Two years later, the country’s Supreme Court used that language for real: in 2023, it ordered Emotiv, a US consumer-neurotech company, to delete the brain data it had collected from a former Chilean senator through the company’s Insight EEG headset.
That ruling is the single most-cited neurorights case anywhere, for good reason. It’s the only instance of a court actually enforcing this concept against a company rather than just discussing it. But the follow-up legislation meant to give the constitutional language real teeth, bill 13,828-19, is still moving through Chile’s Chamber of Deputies as of April 2026. A Stanford Law School analysis points out that even Chile’s framework leaves inferred mental data, the conclusions an algorithm draws about your mental state rather than the raw signal itself, in a genuine gray zone. Constitutional recognition and enforceable regulation are two separate milestones, and Chile has only fully cleared the first one. Which matters more to you: a country writing the words into its founding document, or a court actually enforcing them against a real company? Chile has tested both, and the court got there first.
The idea has spread well past Chile’s borders. Brazil’s state of Rio Grande do Sul wrote neurorights into its own state constitution in December 2023, while a federal measure, PEC 29, sits pending in the national Senate. Mexico introduced a 92-article General Law on Neurorights and Neurotechnologies in July 2024 that would create a national Commission of Neuroethics and Neurolaw, according to Inside BCI’s regional roundup. Uruguay has a neurorights bill of its own in progress. Latin America, not Silicon Valley or Brussels, is where this legal category was actually born, and it’s still where it gets tested first.
Chile: constitutional amendment (2021), Supreme Court enforcement (2023), implementing law still pending
Brazil: state-level protection in Rio Grande do Sul (2023), federal amendment PEC 29 pending
Mexico: 92-article General Law on Neurorights and Neurotechnologies proposed (2024)
Uruguay: neurorights bill in progress
America’s quiet patchwork: state laws doing the real work
The United States hasn’t touched its constitution over this and probably won’t. What it has instead is a state-by-state patchwork that, quietly, is turning into the most consequential body of neurorights-adjacent law anywhere, mostly because it’s the only version with actual enforcement mechanisms attached today.
Four states currently have neural data laws on the books. California’s SB 1223, signed by Governor Gavin Newsom in September 2024, extends the California Consumer Privacy Act’s protections to neural data as a category of sensitive personal information, effective since January 2025. Colorado and Montana followed with their own versions, Montana’s taking effect in October 2025. Connecticut’s SB 1295 joins them this July, amending the Connecticut Data Privacy Act to cover data generated by measuring central nervous system activity, according to a Future of Privacy Forum breakdown of how differently each state defines the term. None of these laws use the word “neurorights.” They just add neural data to the list of things a company can’t quietly sell.
More states are lining up behind them. A March 2026 analysis found active bills in Virginia, Alabama, New York, and Illinois, each taking a different approach: Virginia’s HB 654 folds neural data into existing biometric data rules, Alabama’s HB 263 creates a standalone statute, and Illinois’s SB 2994 would let individuals sue directly rather than wait on an overworked state attorney general, per the same Inside BCI tracking. That private-right-of-action detail matters more than it sounds like it should. It’s the difference between a law enforced occasionally by an understaffed regulator and one enforced by anyone with a lawyer and a genuine grievance.
Why the urgency? A Neurorights Foundation audit found that 29 of 30 consumer neurotech companies it reviewed placed no meaningful limits on accessing users’ neural data, and 60 percent gave consumers no specific disclosure about how that data got handled at all. Congress has tried and failed to act at the federal level: the 2024 American Privacy Rights Act briefly included neural data as a protected category before stalling out entirely, and in April 2025 a group of senators asked the FTC directly to investigate whether neurotech companies were exploiting the gap. For now, federal oversight rests almost entirely on Section 5 of the FTC Act, which bans “unfair or deceptive” practices but doesn’t require a company to post a privacy policy in the first place. 📊
California SB 1223: sensitive-data protection, effective January 2025
Colorado and Montana: enacted, Montana effective October 2025
Connecticut SB 1295: effective July 2026
Pending: Virginia, Alabama, New York, and Illinois bills, each taking a different legal approach
If you’re building a consumer EEG product like the ones we’ve covered in our own device roundup, you don’t get to wait for Congress. You already need a compliance map covering at least four states, with more added every legislative session.
UNESCO’s global framework, and the EU’s side-door approach
While Chile and US states legislate country by country and state by state, UNESCO tried something bigger: one global standard. On November 12, 2025, UNESCO’s General Conference adopted the Recommendation on the Ethics of Neurotechnology, the first normative framework on the topic ever adopted at that scale, with more than 190 member states signing on, according to UNESCO’s own announcement. The text was chaired by French scientist Hervé Chneiweiss and Duke law professor Nita Farahany, and it drew on more than 8,000 submissions from governments, companies, and civil society over roughly six years of drafting.
Here’s the catch, and it matters for anyone used to thinking in terms of enforceable law: a UNESCO Recommendation isn’t binding. Member states aren’t required to pass a single line of implementing legislation, and no tribunal can penalize a country for ignoring it entirely. What it does provide is a shared vocabulary and template, covering mental privacy, informed consent, protections for children, and limits on neurotechnology used outside clinical settings, that individual countries can borrow from once they get around to writing binding law of their own. Think of it as the neurotech equivalent of WHO guidance: hugely influential, with basically zero enforcement power on its own.
The European Union, meanwhile, never wrote a dedicated neurorights law, but it may have accidentally regulated part of this space anyway. Article 5(1)(a) of the EU AI Act, which took effect in 2024, bans AI systems that use “subliminal techniques” to materially distort a person’s behavior without their awareness. European Commission guidelines released in February 2025 explicitly flag brain-computer interfaces as a technology capable of exactly that kind of manipulation, per analysis from Freshfields. That means BCIs and consumer EEG tools already sit under a binding EU prohibition, not because lawmakers wrote “neurotechnology” into the text anywhere, but because the underlying behavior the AI Act worries about happens to describe exactly what an unregulated neural interface could do.
UNESCO Recommendation: adopted November 2025, 190-plus countries, non-binding
EU AI Act Article 5(1)(a): binding, bans subliminal manipulation, indirectly covers neurotech per 2025 Commission guidance
Chile’s constitution: binding at the constitutional level, implementing statute still pending
US state laws: binding and enforceable, but narrowly scoped to data privacy rather than broader rights
Worth flagging if you’re building neurotech products with EU customers: you may already be regulated under a law that never mentions your industry by name.
The pushback: is this solving the right problem
Not everyone thinks the neurorights framework, in its current form, is the right tool for the job. At an IAPP panel earlier this year, neuroethicist Karen Rommelfanger described pushback from an unexpected direction: digital rights advocates and clinicians both raised concerns about one country’s broad neurorights bill, with clinicians warning that language written to stop commercial exploitation might also interfere with their ability to treat patients using that same technology. Rommelfanger’s suggested fix wasn’t to abandon the idea. It was to operationalize existing rights with more precision instead of writing sweeping new constitutional language that treats a hospital’s diagnostic EEG the same way it treats a wellness startup’s mood-tracking headband.
That distinction matters more than any single bill. A neurologist reading an EEG to diagnose epilepsy, a consumer buying a $300 focus tracker, and a company selling cognitive-enhancement claims to healthy adults are three completely different risk profiles wearing the same three letters. Regulation built for one tends to either strangle the other or miss it entirely. Also notably absent from nearly every neurorights framework discussed here: military and defense neurotech, which typically falls under separate national security exemptions rather than consumer or medical privacy law at all, a gap almost none of these frameworks even attempt to close.
Medical neurotech: regulated as a device, protected by existing health privacy law in most countries
Consumer neurotech: the real gap, unregulated in most states and countries until very recently
Enhancement claims: legally the murkiest category, sitting between wellness marketing and medical claims
Military neurotech: largely exempted from every neurorights framework covered above
None of this is settled, which is exactly what makes it worth watching. The Morningside Group’s five rights are eight years old and still not in any binding international document. Chile has a constitution but not yet a working statute. The US has four states and counting, but no federal floor underneath any of them. UNESCO has consensus but no teeth. The real question for the rest of 2026 isn’t whether neurorights exist on paper somewhere, because they clearly do. It’s whether any of these frameworks will still be recognizable in five years, or whether the eventual winner looks nothing like what a room of scientists sketched out on a Columbia campus back in 2017. What would actually convince you your neural data is protected: a new right written into law, or just proof that an existing one gets enforced?


