
My illustration entitled: “The Court of Cognitive Liberty” – inside a futuristic tribunal, citizens present evidence against coercive neural surveillance while Herbert explains the need for enforceable neurorights and cryptographic safeguards.
The history of human rights is partly a history of recognizing new forms of power.
Freedom of speech became necessary because authorities could punish expression. Privacy became necessary because institutions could intrude into personal life. Data-protection rights emerged because digital systems could collect, combine and exploit information at a scale that earlier legal frameworks had not anticipated.
Neurotechnology introduces another concentration of power.
Brain–computer interfaces may record neural activity, interpret intention, identify patterns associated with cognition or deliver stimulation to the nervous system. When combined with artificial intelligence, these systems may infer information that a person has never deliberately communicated.
The emerging field of neurorights asks how the law should protect the brain and mind against these new capabilities.
Neuro-Cypherpunkism asks a complementary question: how should the technology itself be designed so that those protections do not depend entirely upon institutional promises?
Neurorights define the boundaries that institutions must respect. Neuro-Cypherpunkism asks how architecture can make those boundaries enforceable.
What Are Neurorights?
Neurorights are proposed legal, ethical or human-rights protections concerning the human brain, mind and nervous system. They respond to the possibility that neurotechnology may access, interpret or influence aspects of mental life that were previously beyond direct technological reach.
There is not yet one universally settled list of neurorights. Different scholars and institutions use different classifications. However, several recurring protections have emerged.
Cognitive Liberty
Cognitive liberty concerns the individual’s freedom to exercise authority over their own mental processes. It includes freedom from unwanted technological interference and, subject to legitimate safety protections, the freedom to use neurotechnology voluntarily.
Cognitive liberty therefore contains both a positive and a negative dimension:
- The freedom to access beneficial neurotechnology
- The freedom to refuse monitoring, stimulation or cognitive modification
A society does not protect cognitive liberty if it prohibits every voluntary enhancement. Nor does it protect cognitive liberty if employers, governments or platforms can compel neural access.
Mental Privacy
Mental privacy concerns protection against unauthorized access to neural activity and information inferred from it.
This right extends beyond consciously expressed thoughts. Neural measurements may contribute to inferences about attention, recognition, emotion, health, preference or intention. Some of these conclusions may concern characteristics the individual did not know, did not choose to reveal or could not meaningfully conceal.
Mental privacy must therefore protect not only raw signals but also derived profiles, model outputs and future interpretations of previously collected recordings.
Mental Integrity
Mental integrity protects the mind against harmful or unauthorized interference.
The right becomes especially important for bidirectional systems capable of neural stimulation. A technology that can write to the nervous system may affect movement, perception, emotion or other neurological functions.
Mental integrity requires protection against malicious interference, unsafe modification, coercive stimulation and interventions exceeding the scope of consent.
Psychological Continuity
Psychological continuity concerns the individual’s experience of remaining the same person across time.
Technologies affecting memory, emotional disposition, decision-making or personality may create questions that ordinary data law cannot resolve. A person may consent to treatment while still retaining an interest in understanding how the intervention could affect their identity and sense of self.
This does not mean that every psychological change violates a right. Human beings change through experience, education, medicine and relationships. The relevant concern is whether profound technologically induced changes occur without meaningful consent, transparency or the possibility of review.
Fair Access and Protection Against Neurodiscrimination
Some neurorights proposals also address fair access to beneficial neurotechnology and protection against discrimination based upon neural characteristics.
Neural data could be used to classify people according to predicted attention, emotional response, neurological risk or cognitive performance. Employers, insurers, schools or governments might treat these predictions as objective facts even when the underlying systems remain uncertain or biased.
Protection against neurodiscrimination would restrict unjust decisions based upon neural measurements or speculative inferences, particularly when individuals cannot understand or challenge them.
Existing Human Rights or New Rights?
A central debate concerns whether neurorights must be created as entirely new rights or interpreted as applications of rights that already exist.
Privacy, freedom of thought, bodily integrity, personal autonomy, freedom from degrading treatment and informed consent already provide substantial foundations. The brain is not presently outside the protection of human-rights law simply because a document does not contain the word “neurotechnology.”
However, existing rights were developed before systems could translate neural activity into machine-readable information or allow artificial intelligence to participate in the interpretation of cognition. General protections may therefore require clarification when applied to neural data, cognitive inference and technologically mediated intervention.
The choice is not necessarily between abandoning existing rights and inventing an entirely separate legal order. Neurorights may operate as explicit interpretations, extensions or specialized protections built upon established human rights.
What matters is whether the resulting framework protects people in practice.
The Development of Neurorights
International concern about neurotechnology has grown as brain–computer interfaces and neural-data analysis have become more capable.
In 2020, the Parliamentary Assembly of the Council of Europe adopted Resolution 2344 on brain–computer interfaces. It warned that these technologies could create unique threats to human rights and dignity and discussed proposed protections including cognitive liberty, mental privacy, mental integrity and psychological continuity.
Chile subsequently became the first country to introduce explicit constitutional protection concerning brain activity and information derived from it. The 2021 reform required scientific and technological development to respect physical and mental integrity and established special protection for brain activity and related information.
The OECD’s Recommendation on Responsible Innovation in Neurotechnology called for safeguarding personal brain data, responsible stewardship and anticipation of possible misuse.
During 2025, the United Nations Special Rapporteur on the right to privacy called for stronger regulation of neurotechnology and proposed the development of a model legal framework addressing mental privacy and related risks.
On November 11, 2025, UNESCO adopted its Recommendation on the Ethics of Neurotechnology. This established the first global normative framework specifically directed at the ethical governance of neurotechnology. It emphasized human dignity, autonomy, mental privacy, protection of neural data and safeguards against non-consensual or abusive uses.
These developments demonstrate that access to the human mind is becoming a matter of international governance rather than speculative science fiction.
Where Neuro-Cypherpunkism Begins
Neuro-Cypherpunkism shares the central objectives of neurorights. It defends cognitive liberty, mental privacy, mental integrity, psychological continuity and freedom from compulsory neurotechnology.
But its intellectual starting point is different.
Neurorights begin primarily with moral and legal claims. They ask what governments, companies, researchers and other institutions should be permitted or prohibited from doing.
Neuro-Cypherpunkism begins with architecture. It asks what the system is technically capable of doing, who holds the keys, where information is processed and whether the individual can prevent unauthorized power from being exercised.
A law may declare that neural information is private. Neuro-Cypherpunkism asks why the system transmitted the information to a central server in readable form.
A regulation may require consent. Neuro-Cypherpunkism asks whether access can be cryptographically revoked after consent is withdrawn.
A policy may prohibit unauthorized stimulation. Neuro-Cypherpunkism asks whether read and write permissions are separated in hardware and software.
A right may protect freedom of thought. Neuro-Cypherpunkism asks whether an employer can still make neural monitoring a practical condition of employment.
Rights tell power where it must stop. Architecture determines whether power can cross the boundary anyway.
The Limits of Rights Without Architecture
Legal rights are essential, but they face practical limitations.
Rights Are Often Enforced After the Violation
A person may obtain compensation, deletion or an injunction after misuse is discovered. But neural information may already have been copied, analyzed or incorporated into an artificial intelligence model.
Some harms cannot be completely reversed. A disclosed password can be changed. A revealed neurological condition, emotional vulnerability or cognitive profile cannot simply be made unknown again.
Rights Depend Upon Detection
An individual cannot challenge surveillance they do not know is occurring.
Complex neural platforms may contain hidden processing, remote analytics and relationships with third parties. If the architecture is opaque, the user may be unable to determine whether a legal boundary has been crossed.
Rights Vary Across Jurisdictions
Neural data may cross borders through cloud infrastructure, research collaborations and international service providers. Legal protection available in one country may not follow the data into another.
A technical safeguard can protect information across jurisdictions, although law remains necessary when the recipient eventually receives legitimate access.
Consent Can Become Fictional
A provider may obtain formal acceptance through complicated terms while leaving the user with no practical alternative.
Consent is weak when the individual cannot negotiate, cannot withdraw and cannot leave without losing an essential function. A signature does not prove that the resulting relationship preserves cognitive sovereignty.
Institutional Power Can Change
A trustworthy provider may later be acquired, compromised, pressured or reorganized. Policies can change. Governments can expand their demands. Databases collected for beneficial purposes can acquire new political or commercial value.
A system designed around permanent institutional trust remains vulnerable to the future transformation of that institution.
What Neuro-Cypherpunkism Adds
Neuro-Cypherpunkism translates the moral ambitions of neurorights into principles of technical design.
Neural Self-Custody
Individuals should possess meaningful authority over the keys, permissions and storage systems governing access to their neural information.
Self-custody does not require every patient to become a cryptographic engineer. Assistance, recovery and clinical support remain necessary. But assistance must not silently become permanent institutional ownership.
Local-First Processing
Sensitive neural information should be processed on the user’s device or nearby trusted hardware whenever reasonably possible.
An external service should receive the minimum result required for the authorized function rather than the complete neural stream.
Process the mind as close to the mind as possible.
Cryptographic Protection
Neural signals, derived information, commands and software updates should receive protection against unauthorized reading and modification.
Encryption protects confidentiality. Authentication helps establish who is issuing a command. Integrity protections reveal unauthorized alteration. Separate credentials can restrict different parties to different functions.
The Neural Read/Write Divide
Permission to observe neural activity must never automatically authorize intervention in the nervous system.
Reading, interpreting, predicting, stimulating and modifying are different powers. They should be separated through distinct permissions, credentials and safety controls.
Permission to read the brain must never imply permission to write to the brain.
Decentralized BCI Architecture
No unnecessary single institution should control the device, identity system, neural database, artificial intelligence, update process and right of access.
Authority can be distributed through local computation, user-controlled credentials, independent verification, interoperable protocols and continuity arrangements allowing qualified alternative providers to maintain a system.
Decentralization does not mean distributing neural data to more places. It means distributing power while minimizing the movement of neural data.
The Right to Disconnect
Individuals should be able to pause nonessential collection, stop remote transmission, revoke permissions and leave a provider without unnecessary loss of essential functionality.
The right to disconnect also includes freedom from compulsory connection. Employment, education, insurance or civic participation should not depend upon continuous neural monitoring.
Accountable Artificial Intelligence
AI systems interpreting neural activity should remain inspectable, contestable and subordinate to human agency.
A prediction generated from brain data should not automatically be treated as a deliberate thought, intention or decision. The user should be able to know which model is active, what information it receives and how consequential interpretations can be challenged.
The Limits of Architecture Without Rights
The relationship also works in the opposite direction. Technical safeguards cannot replace law, ethics or legitimate institutions.
Cryptography Cannot Determine Justice
Encryption can prevent unauthorized access, but it cannot determine whether an authorized use is fair. A company may receive information through valid credentials and still use it to discriminate.
Code Cannot Measure Genuine Consent
A cryptographic permission can show that a credential approved an action. It cannot prove that the person understood the consequences or acted without pressure.
Consent remains a human and institutional process requiring disclosure, capacity, voluntariness and accountability.
Decentralization Does Not Eliminate Harm
A decentralized neural system can still be unsafe, deceptive or discriminatory. Harmful software does not become ethical because it operates through a peer-to-peer network.
Medical devices may require professional oversight, safety standards and reliable intervention. Research may require independent ethics review. Manufacturers must remain responsible for foreseeable failures.
Individual Control Does Not Mean Institutional Abandonment
Neural self-custody should not transfer every technical risk to patients or excuse companies from security obligations.
Individuals require accessible recovery, clinical assistance and protection against exploitative products. A person should not have to choose between total provider control and managing a complex implant alone.
Rights Are Needed Against Parties Outside the System
An employer, insurer or government may pressure an individual to disclose neural information even when the device itself is secure. Law is necessary to prohibit coercive demands and provide remedies when institutions misuse their social power.
Architecture protects the system’s boundary. Rights protect the person within society.
A Complementary Framework
Neurorights and Neuro-Cypherpunkism should not be treated as rival approaches. Each addresses weaknesses in the other.
| Neuroright | Legal or Ethical Protection | Neuro-Cypherpunkist Architecture |
|---|---|---|
| Mental Privacy | Prohibits unjustified access or use of neural information. | Local processing, encryption, data minimization and user-controlled keys. |
| Cognitive Liberty | Protects voluntary use and refusal of neurotechnology. | Revocable permissions, local controls and the right to disconnect. |
| Mental Integrity | Prohibits harmful or non-consensual interference. | Separate read/write authority, authenticated commands and safety limits. |
| Psychological Continuity | Protects identity against unauthorized or inadequately understood alteration. | Transparent interventions, audit records and reversible settings where possible. |
| Protection Against Neurodiscrimination | Restricts unjust decisions based upon neural characteristics. | Selective disclosure, inference limits and contestable AI outputs. |
| Fair Access | Supports equitable access to beneficial technologies. | Open standards, interoperability and reduced provider lock-in. |
The law establishes duties, remedies and limits upon coercion. Architecture reduces opportunities for abuse and makes certain boundaries technically enforceable.
Neither is sufficient alone.

My illustration “The Court of Cognitive Liberty” work-in-progress. The art represents neurorights requiring both legal recognition and practical technical enforcement.
The Problem of Inferred Mental Data
One of the most difficult issues concerns information inferred from neural and non-neural data.
A system may not decode a complete private thought. It may nevertheless estimate fatigue, recognition, emotional response or the probability of a future action. These predictions may be uncertain while still influencing employment, insurance, education or medical decisions.
Traditional data law often focuses upon information collected directly from a person. Neurotechnology requires equal attention to what an organization claims to have discovered about that person.
Neuro-Cypherpunkism calls this inference privacy: the individual’s interest in limiting, understanding and challenging consequential conclusions generated from personal information.
A system should disclose when it generates significant mental or behavioural inferences. Individuals should be able to correct false information, contest consequential classifications and prevent unrelated reuse.
An algorithmic prediction about the mind is not the mind itself.
Protection Against Compulsory Access
Neurorights must protect more than secret surveillance. They must also address formally disclosed coercion.
An employer might openly require attention monitoring. An insurer might demand neural information as a condition of coverage. A school might require cognitive-performance tracking. A government might seek neural indicators during interrogation or screening.
Transparency alone does not make these practices legitimate.
The key question is whether refusal remains a realistic option. Consent obtained under threat of losing employment, medical care, education or civic participation may be consent in name only.
The right to use neurotechnology must therefore be accompanied by the right to remain unmonitored and unenhanced.
No person should have to surrender access to their mind in order to participate in society.
Children and Vulnerable Persons
Special safeguards are necessary when individuals cannot provide fully independent consent.
Children may benefit from therapeutic neurotechnology but may not understand the future implications of permanent neural records. Patients with impaired decision-making capacity may require representatives, clinicians and independent safeguards to participate in decisions.
Representation should protect the person’s interests rather than erase their agency. The individual’s preferences should be respected to the greatest extent possible. Permissions should remain limited to necessary functions, and decisions with permanent consequences should receive heightened review.
Vulnerability creates a stronger duty of protection. It does not create an unrestricted right of access for institutions.
Emergency and Legitimate Authority
Mental privacy and neural self-custody are not absolute barriers to all legitimate intervention.
A medical emergency may require restricted access to device settings. A serious security vulnerability may require an urgent update. Evidence involving a neural system may become relevant to a lawful investigation.
But legitimate authority must remain necessary, proportionate, procedurally constrained and independently reviewable.
Emergency access should reveal or control only what is required to protect the person. It should expire automatically and produce a protected record. It must not become a permanent backdoor capable of routine surveillance.
Neuro-Cypherpunkism rejects both unlimited institutional authority and the claim that technology should operate without accountability for harm.
The Neuro-Cypherpunkist Standard for Neurorights
A meaningful neurorights framework should satisfy the following conditions:
- It protects both raw neural signals and information inferred from them.
- It applies to medical, commercial, employment, educational and governmental uses.
- It distinguishes access to the brain from intervention in the brain.
- It recognizes that consent must be continuous, specific and revocable.
- It protects the freedom to use neurotechnology and the freedom to refuse it.
- It prohibits unjust discrimination based upon neural measurements or predictions.
- It provides heightened safeguards for children and vulnerable persons.
- It requires transparency and the ability to challenge consequential inferences.
- It preserves narrow and accountable procedures for genuine medical emergencies.
- It encourages local processing, encryption and data minimization.
- It prevents a single provider from acquiring permanent control over essential neural functions.
- It gives individuals meaningful rights to disconnect, export, delete and migrate.
A declaration that does not influence system design will remain incomplete. A technical safeguard without legal accountability will remain equally incomplete.
Rights Written in Law and Enforced in Code
Neurorights and Neuro-Cypherpunkism represent two forms of protection.
The first is normative. It declares that the brain and mind possess special significance and that institutions must respect human dignity, autonomy and mental privacy.
The second is architectural. It places encryption, local processing, user-controlled keys, decentralized authority and meaningful exit between the individual and possible abuse.
Law can punish an institution for crossing the boundary. Architecture can make the boundary more difficult to cross.
Law can prohibit compulsory neural access. Architecture can provide a verifiable way to disconnect.
Law can recognize mental privacy. Architecture can prevent a provider from reading information it never needed to receive.
Law can require consent. Architecture can turn that consent into limited and revocable permissions.
The future of cognitive sovereignty requires both.
The Mind as Sovereign Territory
Neurotechnology should not be rejected merely because it is powerful. Its power may restore movement, communication and independence to millions of people. It may open new forms of creativity, learning and human–computer interaction.
But the value of those possibilities depends upon the political and technical relationship surrounding them.
The individual must remain the subject of neurotechnology, never merely its source of data, target of influence or dependent customer.
Neurorights establish that the mind deserves protection.
Neuro-Cypherpunkism establishes that such protection must be built into the system.
The mind is sovereign territory. Rights must recognize its borders, and architecture must defend them.
Technology may augment the mind. It must never own it.
References and Further Reading
- Herbert R. Sim, “Neuro-Cypherpunkism”
- Herbert R. Sim, “The Mind Is the Final Private Key: Neuro-Cypherpunkism and the Fight for Cognitive Sovereignty”
- Herbert R. Sim, “From Cypherpunkism to Neuro-Cypherpunkism”
- Herbert R. Sim, “The Twelve Principles of Neuro-Cypherpunkism”
- Herbert R. Sim, “Cognitive Sovereignty: A Formal Definition”
- Herbert R. Sim, “Neural Data Is Not Ordinary Data”
- Herbert R. Sim, “Neural Self-Custody: Who Holds the Keys to the Mind?”
- Herbert R. Sim, “Cryptography for the Human Brain”
- Herbert R. Sim, “Decentralized BCI Architecture”
- Herbert R. Sim, “The Right to Disconnect the Mind”
- Herbert R. Sim, “The Neuro-Cypherpunkist Test”
- UNESCO, “Recommendation on the Ethics of Neurotechnology”
- Parliamentary Assembly of the Council of Europe, Resolution 2344: “The Brain-Computer Interface: New Rights or New Threats to Fundamental Freedoms?”
- United Nations Human Rights Council, “Foundations and Principles for the Regulation of Neurotechnologies and the Processing of Neural Data”
- Office of the United Nations High Commissioner for Human Rights, “UN Expert Calls for Model Law on Neurotechnologies to Protect the Right to Privacy”
- Senate of Chile, “Protection of Neurorights”
- OECD, “Recommendation of the Council on Responsible Innovation in Neurotechnology”