All articles
AI Policy & RegulationManufacturingLogisticsRetailReal Estate

Neural Data and the Inference Problem

Benjamin Houghton 14 August 2026 9 min read

Core Insight

Four US states now class neural data as sensitive personal information, UNESCO has adopted a global ethics framework for neurotechnology, and the EU has banned workplace emotion inference outright. Almost none of this is really about brain implants. Neural data is simply the extreme case of inferred data: information a system works out about a person from signals they never chose to hand over. The rules being written for brain data are the leading edge of rules that already cover sentiment analysis, voice stress detection, keystroke rhythm and wearable telemetry. Most businesses running those tools have not yet realised they are in scope.

The Mental Password

In August 2025, a Stanford team published a result in Cell that sounds like it belongs in a much stranger decade than this one. Inner speech, the silent monologue running through your head, could be decoded from motor cortex activity in real time, with accuracy up to 74%.

That is a genuine result. It is also the least interesting part of the study.

The interesting part is what the researchers did next, and nobody asked them to do it. They anticipated the obvious problem with a device that can decode unspoken thought, so they built a lock into it. The user thinks a chosen keyword to switch decoding on. Their four participants picked “chitty chitty bang bang.” Thought before and after the phrase the participant wanted decoded, the system complied 98.75% of the time. A password for your own head, detected almost as reliably as the speech it was gating.

Consider what that means. No regulator demanded it. No statute existed. No customer asked. The device sat in a lab with four consenting participants under a research protocol, and the engineers designed a consent gate into it anyway, because it was plainly the right thing to do.

Now hold that against your own operations. Most enterprise AI systems drawing far less exotic conclusions about far more people have nothing of the kind.

What Can This Technology Actually Do?

Before we go further, we should be precise about where the science actually is, because the coverage of this field runs a long way ahead of the evidence. Nobody can currently read free-form thought. What does exist is narrower, and still worth your attention.

Tang and colleagues (2023, Nature Neuroscience) demonstrated semantic reconstruction of continuous language from fMRI scans. That means decoding the gist of what someone was hearing or imagining, not word-for-word text. It needed hours of training per subject and the subject's active cooperation. It does not work on an unwilling or untrained person.

Meta's Brain2Qwerty study (February 2025) pushed things further, decoding typed sentences from 35 healthy volunteers using sensors outside the skull rather than implants inside it. In case you are new here, the two sensor types matter: MEG measures the magnetic fields your neurons produce and needs a shielded room, while EEG reads electrical activity through the scalp and fits into a headset you could actually wear to work. Brain2Qwerty reached a 32% character error rate with MEG on average, and 19% for its best participant. With the wearable EEG version, error jumped to 67%. The accuracy is not the point. The point is that the gap between surgical and non-surgical decoding is closing without anyone needing surgery.

At the invasive end, Neuralink reported 21 trial participants as of late January 2026, across two studies: PRIME, for cursor and device control, and VOICE, for speech restoration.

Put those together and the honest picture looks like this. The capability is narrow, consented, clinical and slow. Every example above involved a willing research participant inside a laboratory. What is not slow is the regulatory response, which has stopped waiting for the technology to mature before drawing lines around it.

So What Has Any of This Got To Do With Your Business?

Here is the bridge, and it is the reason we are writing about neuroscience at all.

The category that matters is not “mind reading,” a phrase the accuracy figures above simply do not support. The category is inference from involuntary signal: a system reaching a conclusion about somebody's internal state from data that person never consciously chose to disclose.

Neural decoding is the hardest, most extreme version of that. But your business almost certainly runs a milder version already, and has done for years. Contact centre software scoring a caller's emotional state from voice pitch. Recruitment tools running facial expression analysis across interview footage. Productivity suites inferring focus or disengagement from keystroke rhythm and mouse movement. Wearables on a factory floor flagging fatigue from heart rate variability. A retail chatbot scoring customer sentiment to decide which complaints get escalated.

Same structure as the neural case: signal in, conclusion out, nothing disclosed by the person it concerns. Lower resolution, yes. But already deployed, at scale, and in several jurisdictions already regulated.

The version in the laboratory gets the headlines. The version in your technology stack is the one with a compliance date attached to it.

What Does the Law Already Say?

Regulators have not treated these as separate problems, and the rules vary enormously in how much force they carry.

The EU: binding now, hardest teeth

Article 5(1)(f) of the EU AI Act prohibits AI systems used to infer the emotions of a person in workplace and education settings, with narrow exceptions for medical or safety purposes. The standard example of a permitted use is fatigue monitoring in a cockpit.

infer emotions of a natural person in the areas of workplace and education institutions

EU AI Act, Article 5(1)(f), listing a prohibited practice

That prohibition has applied since 2 February 2025, and the penalty regime carries fines up to €35 million or 7% of global turnover, whichever is higher. Two details matter commercially. It binds deployers as well as vendors, so buying the tool rather than building it is no defence. And it applies extraterritorially: if the people affected sit in the EU, you are in scope wherever your business is headquartered. France's regulator, CNIL, has already named recruitment technology as a 2026 enforcement priority.

The US: a growing patchwork, no federal floor

Four states now have neural-data-specific law, and each is drawn differently. Colorado's HB 24-1058 (effective August 2024) is narrowest, requiring opt-in consent and limited to identification purposes. California's AB 1008 and SB 1223 (effective January 2025) run an opt-out model but cover more ground, including employee data. Montana regulates neural data through its genetic information privacy act. Connecticut became the fourth from 1 July 2026. Nothing federal ties these together, and nothing federal looks imminent.

International and the UK

UNESCO adopted its Recommendation on the Ethics of Neurotechnology at its General Conference in Samarkand, entering into force on 12 November 2025 with the backing of all 194 member states. It is not binding, but it sets the normative frame that other regulators are already citing, and it warns specifically against workplace applications that monitor productivity or profile employees. Chile went further back in 2021, amending its constitution to protect mental integrity directly.

The UK has no neural-data category at all. GDPR's biometric and health provisions apply only by analogy, and the ICO's Tech Futures: Neurotechnology report urged a precautionary approach rather than waiting for someone to test the gap.

Why Doesn't Consent Fix This?

The instinct is to treat all of this as a paperwork problem. Get a signature, tick the box, move on. A March 2026 analysis from Stanford Law School sets out why that does not hold for this class of data.

The argument is structural. A person cannot meaningfully evaluate what a model will infer from a raw signal before the inference exists. So agreeing to let a system collect your voice, your keystrokes or your expression is not the same as agreeing to whatever conclusion it eventually draws from them. The paper calls for protections grounded in cognitive liberty rather than the usual framing of data as property.

Is that a theoretical worry? The evidence says otherwise. The Neurorights Foundation's 2024 audit of 30 consumer neurotechnology companies found 29 of them had effectively unrestricted internal access to users' brain data, and almost all reserved the right to pass it onward. Most likely nobody in that chain breached their own privacy policy. The policy simply never specified what would be inferred, because at the moment of signature nobody could have said.

This is the argument underneath everything else here. A permissions checkbox obtains consent for a signal. It cannot obtain consent for a conclusion.

Our View

The panic is aimed at the wrong thing. The public conversation about neurotechnology is almost entirely about implants, a technology with 21 consented patients under FDA oversight. The real exposure sits elsewhere: a contact centre scoring caller emotion, a recruitment tool reading facial expressions, a productivity suite inferring focus from typing rhythm. Those run now, at scale, on people who never opted into anything, and in the EU several of them are already illegal. That asymmetry of attention is the actual story.

Inference is becoming regulated as collection, and that direction is settled. The detail is a mess. Four US states, four definitions, no federal law, no UK statute. The direction is not a mess at all, and it only tightens. Build to the stricter standard now. Retrofitting governance onto a live system costs multiples of designing it in.

Consent is not a control. A checkbox obtains permission to collect a signal. It cannot obtain informed permission for a conclusion the person could not anticipate and the vendor may never have specified. The control that works is an audit trail on the inference itself: what was derived, from what input, by which model, and who had standing to challenge it. That is a systems problem, not a legal one.

A line we hold commercially. We do not build systems that infer employees' emotional states. Not primarily because the EU bans it, but because the underlying science is contested and the power in that relationship sits entirely on one side. It is work we decline.

Where we might be wrong. Treating every inference as sensitive by default could stall genuinely useful analytics and hand an advantage to competitors working to a looser standard. And the EU prohibition attaches specifically to biometric inference, which means text-based sentiment analysis arguably sits outside it. That distinction has not been tested by enforcement and may not survive first contact with it. As of today, though, it is real, and we would rather say so than round it away.

What Does This Mean in Your Industry?

Manufacturing

Fatigue and safety monitoring is the one place where an exception may genuinely apply, since the AI Act carves out safety purposes. Do not assume the carve-out covers you by default. A wearable that flags a worker as too tired to operate machinery is arguably safety. The same wearable feeding a productivity dashboard is not, and running both off one data stream collapses the distinction you would need to defend. Separate the pipelines before someone asks you to.

Logistics

Driver-facing telemetry is the exposure here: cameras scoring alertness, headsets detecting stress in a dispatcher's voice, apps inferring fatigue from driving patterns. Much of this arrived through insurance or fleet-safety vendors rather than an AI procurement process, so it often sits outside whatever AI governance you have built. Start by finding out what your fleet systems already infer, because almost nobody has that inventory.

Retail

Customer sentiment scoring is so embedded in contact centre platforms that most teams have never treated it as a decision they made. Two questions worth answering this quarter. Is the scoring done on voice, which puts it squarely in biometric territory, or on transcribed text, which currently sits in a greyer area? And does a low sentiment score change how a customer is treated, priced or prioritised? If it does, you are making consequential decisions on an inference nobody consented to.

Real Estate

The exposure is tenant screening and lending, where AI has a documented history of discrimination, and where inference creeps in quietly. A model that infers financial stress or reliability from behavioural signals rather than stated financial data is drawing exactly the kind of conclusion this regulation is moving to cover. Give people a straight answer when they ask why a decision went the way it did, and make sure you can actually produce one.

What Should You Actually Do?

The four controls we build into every agentic system, approval workflows, role boundaries, audit logs and escalation rules, apply just as cleanly to inference. Here is what that looks like in practice.

  1. Inventory the gap between what you collect and what you infer. Most teams have documented the first thoroughly and never audited the second at all.
  2. Classify inferred attributes as sensitive by default, rather than waiting for a statute to name them. The law is consistently behind the deployment.
  3. Stop emotion inference in HR, recruitment and contact centres if any of your people or customers sit in the EU. Check what your vendor's system actually does, not what the contract says it does.
  4. Log the inference, not just the input. An audit trail recording the signal but not the conclusion drawn from it proves nothing when someone asks you to justify a decision.
  5. Fix your vendor terms on derived data. Who owns the inference once it is made, can it be shared onward, and can it be deleted on request.

Everything we build at U4RIA runs on one principle: AI you can see, govern and trust. Every action an agent takes passes a policy check before it executes and lands in an audit trail afterwards. Applied to inference, that means the conclusion your system reached about a person is a logged, reviewable, challengeable event rather than something buried in a vendor's model. You can see how we build that layer on our Operational Intelligence Platform.

Back to the Password

A research team building the most invasive version of this technology designed a consent gate into it before anyone made them, for four people who had already agreed to be there.

Businesses running the mild version, at scale, on people who never picked a password and never got asked, mostly have not.

That gap is not a neuroscience story. It is an operations one, and it is the only part of this you actually control.

At U4RIA, we believe AI is a tool to help humans, not replace them. Like what we're about? See what your business is truly capable of. Experience U4RIA.

Sources

  • Kunz, Abramovich Krasa, Willett et al. (2025). Inner speech in motor cortex and implications for speech neuroprostheses. Cell 188(17), 4658–4673 — the 74% inner-speech decoding accuracy and the “chitty chitty bang bang” consent-keyword mechanism (98.75% gating accuracy) — https://www.cell.com/cell/fulltext/S0092-8674(25)00681-6
  • EurekAlert / Stanford (14 Aug 2025) — coverage of the inner-speech study — https://www.eurekalert.org/news-releases/1093888
  • Lévy, Zhang, d'Ascoli, King et al. (2025). Brain-to-Text Decoding: A Non-invasive Approach via Typing (Brain2Qwerty). arXiv:2502.17480 — https://arxiv.org/abs/2502.17480
  • Tang, LeBel, Jain & Huth (2023). Semantic reconstruction of continuous language from non-invasive brain recordings. Nature Neuroscience — https://www.nature.com/articles/s41593-023-01304-9
  • Reuters, via Yahoo (28 Jan 2026) — Neuralink reaching 21 trial participants across the PRIME and VOICE studies — fact-checked for this piece — https://www.yahoo.com/news/articles/elon-musks-neuralink-says-21-183038116.html
  • EU AI Act (Regulation 2024/1689), Article 5: Prohibited AI Practices — https://artificialintelligenceact.eu/article/5/
  • European Commission, Guidelines on prohibited artificial intelligence practices, C(2025) 884 final, 4 Feb 2025 — https://digital-strategy.ec.europa.eu/en/policies/regulatory-framework-ai
  • Future of Privacy Forum — Red Lines under the EU AI Act: the prohibition of emotion recognition in the workplace and education institutions — https://fpf.org/blog/red-lines-under-eu-ai-act-unpacking-the-prohibition-of-emotion-recognition-in-the-workplace-and-education-institutions/
  • UNESCO, Recommendation on the Ethics of Neurotechnology, entered into force 12 Nov 2025 — https://www.unesco.org/en/legal-affairs/recommendation-ethics-neurotechnology
  • Stanford Law School, Law and Biosciences Blog (30 Mar 2026) — Who Owns Digital Thoughts? The Limits of Property Law and the 2025 UNESCO Recommendation on the Ethics of Neurotechnology — https://law.stanford.edu/2026/03/30/who-owns-digital-thoughts-the-limits-of-property-law-and-the-2025-unesco-recommendation-on-the-ethics-of-neurotechnology/
  • Neurorights Foundation / Perseus Strategies (2024). Safeguarding Brain Data: Assessing the Privacy Practices of Consumer Neurotechnology Companies — the 29-of-30 finding — https://perseus-strategies.com/wp-content/uploads/2024/04/FINAL_Consumer_Neurotechnology_Report_Neurorights_Foundation_April-1.pdf
  • KFF Health News — States Pass Privacy Laws To Protect Brain Data Collected by Devices — state-by-state comparison — https://kffhealthnews.org/mental-health/colorado-california-montana-states-neural-data-privacy-laws-neurorights/
  • ICO, Tech Futures: Neurotechnology (2023) — https://ico.org.uk/about-the-ico/research-and-reports/tech-futures-neurotechnology/
  • U4RIA: Agentic Governance — The Boss of Your AI — the four controls referenced here — https://www.u4riaai.com/articles/agentic-governance-the-boss-of-your-ai
  • U4RIA: The Operational Intelligence Platform — https://www.u4riaai.com/api-agents
  • U4RIA Articles — https://www.u4riaai.com/articles
Weekly briefing

Stay ahead of where AI is going

One research-grade article every week, the shifts before they hit, translated for your business. Subscribers also get each piece as a branded PDF.

No spam. One email a week. Unsubscribe any time.

We use essential cookies to run this site, and, with your consent, analytics cookies to help us understand how it's used. Learn more