Civic / Privacy / Digital Rights
Comparative Cognitive Liberty Law, Regulation, and Enforcement Atlas
Report summary
The rapid proliferation of neurotechnologies, artificial intelligence, and biometric surveillance has catalyzed a fundamental paradigm shift in global jurisprudence. Historically, legal frameworks governing privacy, civil liberties, and consumer protection presumed an inviolable, natural barrier bet
Key topics
- Civic / Privacy / Digital Rights
- Civic
- Privacy
- Digital Rights
- AI
- .NET
- Runtime
- Cognitive Liberty
- Research Archive
Research provenance
For citation, use the report title and canonical URL. Archival presence does not establish authorship or promote report statements into portfolio evidence.
This page renders the archived Markdown as safe, formatted HTML. It is background research and does not become a portfolio claim without evidence review.
Full report
On this page
The rapid proliferation of neurotechnologies, artificial intelligence, and biometric surveillance has catalyzed a fundamental paradigm shift in global jurisprudence. Historically, legal frameworks governing privacy, civil liberties, and consumer protection presumed an inviolable, natural barrier between external, observable behavior and the internal cognitive state—the forum internum1. The advent of commercial brain-computer interfaces (BCIs), automated emotion recognition systems, and predictive algorithmic profiling has breached this barrier, necessitating the formulation of novel legal doctrines. These doctrines are collectively categorized under the umbrella of "cognitive liberty" or "neurorights," reflecting an urgent need to govern the extraction of neural data and the deployment of cognitive-altering algorithms3. This atlas provides an exhaustive, jurisdiction-specific analysis of the current legal architecture governing cognitive liberty, neural data, mental privacy, emotion recognition, biometric inference, AI manipulation, automated decisions, transparency, and contestability. The comparative evaluation distinguishes strictly between proposed mechanisms and enacted law, mapping the lifecycle of legal records from enactment and entry into force to trial rulings, enforcement settlements, and superseding legislation.
Part I: International Human-Rights Law and Supranational Frameworks
The translation of neurotechnology ethics into international human-rights law is currently characterized by a structural tension between non-binding global normative frameworks, which seek universal ethical consensus, and binding regional treaties that mandate specific domestic legislative implementations.
United Nations and UNESCO Developments
The United Nations Educational, Scientific and Cultural Organization (UNESCO) has positioned itself at the vanguard of global neurotechnology governance. On November 11, 2025, at its 43rd session in Samarkand, Uzbekistan, the UNESCO General Conference formally adopted the Recommendation on the Ethics of Neurotechnology5. This instrument represents the first comprehensive global normative framework addressing the intersection of human rights and neurotechnology. The lifecycle of this framework began with a mandate entrusted by UNESCO's Member States at the 42nd session in November 20236. Following this, an Ad Hoc Expert Group (AHEG) convened in April and August 2024 to draft the preliminary text, which was subsequently refined during an intergovernmental meeting of experts in May 2025 before its final adoption6. The enacted Recommendation establishes a broad, technology-neutral definition of neurotechnology, encompassing devices, systems, and procedures that directly measure, access, monitor, analyze, predict, or modulate the nervous system, whether through invasive or non-invasive means5. Crucially, the framework applies to both open-loop recording devices (e.g., standard electroencephalography) and closed-loop stimulation systems. The inclusion of closed-loop systems acknowledges that dynamic, state-dependent stimulation introduces profound ethical challenges due to its capacity to alter physical and mental processes with potentially delayed or unforeseen effects on human agency5. While the Recommendation constitutes a non-binding soft-law instrument, it explicitly anchors cognitive liberty within established international human-rights conventions, such as the International Covenant on Civil and Political Rights (ICCPR)1. The text operationalizes several high-level values, including proportionality, the protection of freedom of thought, mental privacy, algorithmic transparency, accountability, and the protection of vulnerable populations such as children and future generations7. Member States are formally advised to adapt their domestic legislative frameworks to these principles, focusing on life-cycle impact assessments, stringent data localization and cybersecurity standards, and absolute prohibitions on the manipulative use of neural data for behavioral nudging or neuromarketing7. Furthermore, the Recommendation specifically addresses the geopolitical dimensions of neurotechnology, emphasizing equity and the necessity of preventing the exacerbation of global health disparities, particularly in low- and middle-income countries (LMICs) and resource-limited settings8.
Council of Europe: Framework Convention on Artificial Intelligence
At the regional level, the Council of Europe has advanced the first legally binding international treaty on artificial intelligence: the Framework Convention on Artificial Intelligence and Human Rights, Democracy and the Rule of Law (CETS No. 225\)10. The drafting of CETS 225 was initiated following a 2020 parliamentary resolution and the subsequent mandates of the Committee on Artificial Intelligence (CAI)11. The treaty was formally adopted by the Committee of Ministers on May 17, 2024, and was opened for signature in Vilnius on September 5, 202410. The Convention reached its required ratification threshold—five ratifications, including at least three Council of Europe member states—and formally entered into force on November 1, 2025, following ratifications by the United Kingdom, France, Norway, and others10. The European Union subsequently ratified the Convention on May 15, 2026, intending to fulfill its treaty obligations primarily through the enforcement mechanisms of the EU AI Act10. Observer states played a critical role in the negotiation phase. The United States signed CETS 225 on September 5, 2024; however, under U.S. constitutional practice, a signed treaty is not binding until the Senate ratifies it with a two-thirds majority. As of mid-2026, the U.S. Senate has not ratified the treaty. Consequently, the Convention holds the status of a signed but unratified instrument within U.S. domestic law and imposes no binding obligations on private companies operating exclusively within U.S. jurisdiction10. For ratifying states, CETS 225 mandates the adoption of domestic legislative or administrative measures to ensure AI lifecycle activities respect human dignity, individual autonomy, transparency, accountability, equality, and privacy13. The Convention is not self-executing and incorporates a highly debated structural compromise: it permits signatories discretion regarding the extent to which the treaty's obligations bind the private sector. States may opt to apply the provisions directly to private entities or implement alternative domestic measures to achieve compliance, resulting in a heterogeneous enforcement landscape for multinational operators10. To ensure ongoing compliance, the Convention requires each party to establish an independent oversight mechanism and mandates the creation of a follow-up Conference of the Parties to monitor implementation and interpretative challenges12.
Summary of International Instruments
| Instrument | Authority | Adoption Date | Entry into Force | Legal Status |
|---|---|---|---|---|
| Recommendation on the Ethics of Neurotechnology | UNESCO | November 11, 2025 | N/A | Non-binding global normative framework |
| Framework Convention on AI (CETS 225\) | Council of Europe | May 17, 2024 | November 1, 2025 | Binding international treaty (for ratifying states) |
Part II: The European Union Regulatory Architecture
The European Union utilizes a derivative-rights architecture that addresses cognitive liberty and neural data through horizontal data protection and risk-based product safety regulations, rather than establishing sui generis constitutional "neurorights"15.
The Artificial Intelligence Act (AI Act)
Regulation (EU) 2024/1689 (the AI Act) was formally enacted on June 13, 2024, establishing harmonized rules on artificial intelligence across the bloc16. The AI Act adopts a risk-stratified approach, outright prohibiting certain AI practices under Article 5\. These specific prohibitions reached their application date and became strictly enforceable in February 202518. Article 5 directly intersects with cognitive liberty by prohibiting AI systems that deploy subliminal techniques beyond a person's consciousness, or that exploit vulnerabilities of specific groups (due to age, disability, or social/economic situation), to materially distort behavior in a manner that causes or is likely to cause significant physical or psychological harm16. Furthermore, the Act explicitly bans the use of AI systems for emotion recognition in the workplace and in educational institutions, effectively outlawing automated affective inference in environments characterized by inherent structural power asymmetries18. Despite these stringent prohibitions, the AI Act’s reliance on risk categorization leaves critical interpretive and evidentiary gaps. The statute leaves the evidentiary burden and the precise allocation of liability to implementing authorities and sectoral regimes16. Proving that an AI system covertly influenced behavior requires extensive technical auditing and impact assessments, creating enforcement complexities regarding the exact threshold of what constitutes a "material distortion" of behavior and what quantifies "psychological harm" in the context of cognitive vulnerability2.
General Data Protection Regulation (GDPR) and Digital Services Act (DSA)
The GDPR (Regulation 2016/679), which entered into force in 2016 and became applicable in 2018, provides the foundational privacy layer for cognitive liberty in the EU. While the GDPR does not explicitly codify the term "neural data," its classification of biometric data and data concerning health under Article 9 (Special Categories of Personal Data) naturally encompasses most neurotechnological outputs4. Processing neural data for the purpose of uniquely identifying a natural person, or inferring medical and cognitive states, triggers strict requirements for explicit, informed consent or specific statutory exemptions. However, scholarly analysis indicates that classical data-privacy paradigms may not fully capture the inviolability of thought, as the collection of outward physiological measures differs fundamentally from access to private cognitive content15. Complementing the GDPR, the Digital Services Act (DSA) imposes systemic transparency and algorithmic accountability obligations on very large online platforms (VLOPs). By mandating risk assessments for algorithmic recommender systems and targeted advertising architectures, the DSA mitigates the broader societal risks of cognitive manipulation and behavioral steering at scale.
Part III: The Latin American Vanguard
In stark contrast to the European Union's incremental adaptation within existing data-protection frameworks, several Latin American jurisdictions have opted for a constitutionalized, rights-based approach to neurotechnology, elevating mental integrity to the level of absolute fundamental rights2.
Republic of Chile
Chile represents the global pioneer in neurotechnology regulation, possessing a sophisticated framework of constitutional amendments, enacted statutes, and landmark Supreme Court jurisprudence that operationalizes cognitive liberty. Constitutional Amendment and Statutory Law In a paradigm-shifting legislative move, Chile enacted Law No. 21.383 on October 14, 2021, modifying Article 19, Number 1 of the Political Constitution of the Republic16. This amendment established a global precedent by explicitly protecting "cerebral activity and its data," guaranteeing the rights to personal identity, free will, and mental privacy against neurotechnological interference21. Companion legislation designed to systematically regulate neurotechnology research and commercialization and establish specific statutory neurorights (Boletín 13828-19) remains pending in the Chamber of Deputies as of early 202622. This legislative delay highlights the practical complexities of operationalizing constitutional neurorights into comprehensive, administrable sectoral regulations. Separately, in March 2023, Chile promulgated Law No. 21.54523. While frequently discussed adjacent to the neurorights discourse due to its focus on neurodivergence and cognitive identity, Law 21.545 is a distinct legislative framework specifically addressing the promotion of inclusion, comprehensive care, and the protection of rights for individuals on the autism spectrum23. The law formally recognizes autism not as a disease, but as a neurodevelopmental condition, mandating educational accommodations (such as the Individual Curricular Adaptation Plan), healthcare integration, and the elimination of discriminatory practices across the lifespan24. **Landmark Jurisprudence: *Girardi Lavín v. Emotiv Inc.*** The justiciability and immediate applicability of Chile's constitutional amendment were definitively tested in the Supreme Court of Justice ruling Girardi Lavín v. Emotiv Inc. (Rol 36.904-2023), issued on August 9, 202316. The plaintiff, former Senator Guido Girardi Lavín, filed an action for constitutional protection against Emotiv Inc., a California-based neurotechnology corporation26. Girardi alleged that Emotiv's "Insight" device—a direct-to-consumer electroencephalography (EEG) headset—and its accompanying software collected, processed, and retained his brain data without adequate privacy safeguards or specific, revocable consent for secondary research purposes27. Emotiv argued in its defense that the plaintiff's harms were purely hypothetical and that the retained data was sufficiently anonymized27. The Supreme Court ruled decisively in favor of the plaintiff, applying the amended Article 19 directly against a private commercial entity16. The Court found that Emotiv's data retention practices violated the plaintiff's constitutional rights to mental privacy, as well as physical and psychological integrity, fundamentally rejecting the premise that anonymization negates the sensitivity of raw EEG data16. Final Disposition: The Court ordered Emotiv to permanently delete all of Girardi's unlawfully retained brain data3. Furthermore, the Court mandated the immediate suspension of the commercialization and marketing of the Emotiv Insight device in Chile until the relevant national customs and public health authorities (the Institute of Public Health) could thoroughly evaluate the technology's compliance with domestic sanitary and medical device regulations3. This landmark ruling demonstrated that constitutional neurorights can provide immediate, actionable remedies against private entities, distinguishing the Chilean model from jurisdictions relying solely on administrative regulatory enforcement2. Theoretical Frameworks: Habeas Cogitationem The Chilean legal developments have spurred academic proposals for new procedural mechanisms to enforce these rights. Legal scholars have proposed the concept of a habeas cogitationem writ3. Conceived as a constitutional procedural right formulated in a negative sense, it would function similarly to habeas corpus or habeas data, allowing citizens to rapidly challenge the validity of a flagrant neurotechnological interference in their thought processes by either state or private actors3. It is vital to note that habeas cogitationem currently remains an academic and theoretical proposal; it has not been enacted into law in Chile or any other jurisdiction.
Federative Republic of Brazil
Following Chile's constitutional approach, the Brazilian State of Rio Grande do Sul enacted Constitutional Amendment Proposal (PEC) 298/2023 in December 202328. This amendment successfully altered Article 235 of the state constitution to explicitly incorporate protections for mental integrity and mental privacy in the face of advancing neurotechnologies, making Rio Grande do Sul the first sub-national jurisdiction globally to constitutionalize neurorights28. At the federal level, algorithmic transparency and AI governance remain the subject of active legislative debate. Proposed bills, such as PL 2.338/2023 and PEC 29/2023, seek to embed algorithmic transparency as a fundamental right within the Brazilian Federal Constitution to safeguard users' mental integrity against opaque decision-making systems31. However, these measures currently remain pending proposals and have not been enacted into law. In the judicial sphere, the National Council of Justice (CNJ) previously enacted Resolution No. 332/2020, which mandates explainability when the judiciary employs AI tools, ensuring that algorithmic automation within the state apparatus aligns with constitutional guarantees of digital due process31.
Other Latin American Proposals
Legislative momentum concerning cognitive liberty continues across the region, though strictly in the form of proposals. In Mexico, pending constitutional amendments (introduced in the Senate and Chamber of Deputies across 2023 and 2024\) propose to enshrine the right to mental privacy and individual identity20. The drafting of these bills heavily mirrors the language of the Chilean constitutional text27. Similarly, Uruguay has introduced a neurorights bill in its Chamber of Deputies, seeking to regulate the domestic consumer neurotechnology market32. These frameworks remain unenacted proposals.
Part IV: United States Federal and State Architectures
The United States currently lacks a comprehensive federal data privacy law or a constitutionalized right to mental privacy. Consequently, the regulatory architecture relies on a fragmented patchwork of state-level comprehensive privacy statutes, targeted state biometric laws, and federal civil rights and consumer protection enforcement actions.
Federal Legislative Proposals
The MIND Act of 2025 (S. 2925\) On September 29, 2025, U.S. Senators Charles Schumer, Maria Cantwell, and Edward Markey introduced the Management of Individuals’ Neural Data (MIND) Act of 2025 (S. 2925\) in the United States Senate33. Lifecycle Status: The bill is a legislative proposal. Upon introduction, it was read twice and referred to the Senate Committee on Commerce, Science, and Transportation. It has not been enacted into law33. Substance: The MIND Act defines "neural data" as information obtained by measuring the activity of an individual's central or peripheral nervous system through neurotechnology35. It directs the Federal Trade Commission (FTC) to conduct a comprehensive study on the governance of neural data, identify regulatory gaps (specifically noting deficiencies within HIPAA and COPPA regarding consumer neurotechnology), and propose best practices for private-sector data security to prevent the exploitation of cognitive patterns34. Furthermore, the bill mandates that the Office of Science and Technology Policy (OSTP) issue binding guidance regulating the procurement and deployment of neurotechnology by federal agencies37.
Federal Enforcement Authorities (FTC and EEOC)
In the absence of dedicated federal neuro-privacy legislation, federal administrative agencies have aggressively leveraged existing statutory authority to police biometric surveillance and algorithmic abuses. **Federal Trade Commission: *FTC v. Rite Aid Corp.*** The FTC relies on Section 5 of the FTC Act, which prohibits unfair or deceptive acts or practices in commerce, to regulate automated decision-making and biometric surveillance systems that harm consumers38. Complaint and Inquiry: In December 2023, the FTC filed a formal complaint and proposed settlement against Rite Aid Corporation in the U.S. District Court for the Eastern District of Pennsylvania (Case 2:23-cv-5023)38. The FTC alleged that between 2012 and 2020, Rite Aid deployed AI-powered facial recognition technology across its retail locations to identify potential shoplifters. The system allegedly generated frequent false-positive match alerts that disproportionately targeted women and people of color, leading to unwarranted searches, public humiliation, and extreme emotional distress41. Furthermore, the FTC alleged Rite Aid explicitly violated a prior 2010 data security consent order by failing to employ reasonable measures to protect personal information and failing to oversee its service providers38. Trial Rulings and Bankruptcy Intersections: The enforcement action was heavily complicated by Rite Aid's financial insolvency. Rite Aid filed for Chapter 11 bankruptcy in October 2023, burdened by substantial debt and ongoing opioid litigation44. In March 2024, the district court ruled against the FTC on its claims, and subsequently denied the FTC's post-trial motion to alter or amend the judgment in June 202440. Rite Aid briefly emerged from bankruptcy in September 2024 but filed a second Chapter 11 petition in May 202544. Final Disposition: Despite the initial trial setbacks, a final settlement order was achieved in late 2024, receiving preliminary approval by the bankruptcy court on November 25, 202445. Under the strict terms of the order, Rite Aid is banned from utilizing facial recognition surveillance technology for five years42. The company was also mandated to implement a robust, executive-overseen information security program and required to discontinue the use of any biometric tracking technology if it could not adequately mitigate the risks to consumers40. Rite Aid's operations ultimately ceased completely due to a total corporate liquidation plan that took effect on December 31, 202544. Equal Employment Opportunity Commission (EEOC) The EEOC applies Title VII of the Civil Rights Act of 1964, the Americans with Disabilities Act (ADA), and the Age Discrimination in Employment Act (ADEA) to combat algorithmic discrimination and biometric bias in employment selection46. The agency’s Strategic Enforcement Plan for Fiscal Years 2024-2028 explicitly prioritizes the elimination of barriers caused by the use of AI and machine learning in recruitment, targeting automated systems that intentionally exclude or cause an adverse impact on protected demographic groups47. The EEOC’s enforcement posture faced administrative volatility recently. A sweeping 2024 Enforcement Guidance on Harassment in the Workplace was issued in April 2024, but faced immediate legal challenges. A federal district court in Texas vacated portions of the guidance on a nationwide basis in May 2025, ruling the EEOC exceeded its statutory authority49. Consequently, the 2024 Enforcement Guidance was formally rescinded by the EEOC in January 202649. However, the core enforcement mandate against algorithmic disparate impact remains vigorously intact. Jurisprudence: Mobley v. Workday, Inc. (4:23-cv-00770) The application of federal civil rights law directly to third-party AI developers is actively being tested in Mobley v. Workday, Inc., filed in the U.S. District Court for the Northern District of California50. The plaintiff alleged that Workday’s AI-driven applicant screening software systematically discriminated against candidates based on race, age, and disability50. The core legal theory advanced by the plaintiff is that Workday acts as an "agent" of the employer and an "employment agency," thereby rendering the software vendor directly liable for discriminatory outcomes under Title VII, effectively preventing employers from evading discrimination law by outsourcing their hiring decisions to algorithmic platforms46. Lifecycle and Trial Rulings: Workday filed a motion to dismiss the complaint, which the district court granted in January 202452. However, subsequent amended complaints and judicial orders throughout 2024 and 2025 revived the litigation. A critical milestone was reached in February 2026, when the federal court authorized notice to potential class members, keeping the litigation active and cementing it as a foundational test case for the "agency theory" of AI liability48.
State Comprehensive Data Privacy Laws (The "Neural Data" Wave)
As federal legislation stalls, U.S. states have swiftly amended their comprehensive consumer data privacy frameworks to classify neural data as highly protected "sensitive data," bridging the gap between medical privacy laws (like HIPAA) and unregulated consumer neurotechnology54.
| State | Legislative Vehicle | Enactment Date | Effective Date | Regulatory Action regarding Neural Data |
|---|---|---|---|---|
| Colorado | HB 24-1058 | April 17, 2024 | August 6, 2024 | Amends the Colorado Privacy Act (CPA). First state to explicitly expand "sensitive data" to include both "biological data" and "neural data." Enforced exclusively by the AG and district attorneys; no private right of action55. |
| California | SB 1223 & AB 1008 | Sept. 28, 2024 | Jan. 1, 2025 | Amends the CCPA. Classifies a consumer's neural data—defined as information generated by measuring CNS/PNS activity not inferred from nonneural information—as "sensitive personal information" requiring opt-out limitations and strict disclosure. Additionally, California enacted AB 3030 on the same date, requiring healthcare facilities using generative AI for patient communications to provide explicit disclosures58. |
| Montana | SB 163 | May 1, 2025 | Oct. 1, 2025 | Amends the Genetic Information Privacy Act to cover "neurotechnology data." Requires express opt-in consent for collection, third-party transfer, and sale. Uniquely, it applies to neurotech used in medical settings outside of strict clinical research, conditioning its HIPAA exception. Prohibits storage in U.S.-sanctioned or adversary nations without consent. Limits sharing with employers/insurers54. |
| Connecticut | SB 1295 | June 24, 2025 | July 1, 2026 | Amends the CTDPA. Lowers applicability thresholds to 35,000 consumers or any processing of sensitive data, removing previous revenue thresholds. Adds neural data to the sensitive data definition. Mandates impact assessments for AI profiling (effective Aug 1, 2026\) and grants consumers the right to access algorithmic inferences61. |
Note on General State Privacy Overhauls: The definition and protection of biometric and biological data continue to expand beyond strict neural parameters. In May 2024, Minnesota enacted the Minnesota Consumer Data Privacy Act (HF 3488), establishing comprehensive privacy rights including protections for biometric data64. Concurrently, Montana enacted SB 297 on May 8, 2025 (Effective Oct 1, 2025), a massive overhaul of its general Consumer Data Privacy Act (MTCDPA). SB 297 lowered processing thresholds to 25,000 consumers, removed the 30-day right-to-cure period, instituted civil penalties of up to $7,500 per violation, and mandated rigorous data protection assessments for services posing heightened risks to minors66.
Illinois: Biometrics and Algorithmic Employment Law
Illinois maintains the most aggressively enforced biometric and AI framework in the United States, driven heavily by statutory private rights of action that circumvent the limitations of administrative enforcement. Biometric Information Privacy Act (BIPA) Enacted in 2008, BIPA (740 ILCS 14\) mandates that private entities obtain written, informed consent and establish public retention and destruction schedules before collecting biometric identifiers, which are strictly defined to include retina or iris scans, fingerprints, voiceprints, and scans of hand or face geometry69. BIPA provides a private right of action with significant statutory damages per violation, generating massive class-action litigation across the state. Enforcement Record: Peatry v. Bimbo Bakeries USA, Inc. (1:19-cv-02942) This class action, filed in 2019, alleged the defendant unlawfully required employees at its Cicero, Illinois manufacturing facility to clock in and out using fingerprint scanners without securing prior written consent or providing a publicly available data retention schedule70. Trial Ruling: The defendant filed a motion to dismiss, arguing the claims were preempted by Section 301 of the Labor Management Relations Act (LMRA) because the plaintiff was subject to a collective bargaining agreement70. In February 2020, the district court ruled on the motion to dismiss, carefully navigating Seventh Circuit preemption precedents70. Final Disposition: After years of litigation, the parties reached a class-wide settlement agreement. The court granted preliminary approval of the settlement on April 23, 2024, resolving the claims for BIPA violations occurring between February and May 2018 through the establishment of a $295,000 settlement fund72. Pending Litigation: Arnold et al. v. Target Corporation (1:24-cv-04452) Filed on May 30, 2024, this ongoing class action alleges that Target deployed advanced video surveillance and facial recognition technology in its Illinois retail stores to combat organized retail theft. The plaintiffs allege the corporation covertly collected customers' facial geometry without providing written notice or obtaining the BIPA-mandated written releases69. The matter remains pending in the early stages of civil litigation. Employment Artificial Intelligence Laws Illinois has progressively enacted targeted statutes regulating the deployment of AI in human resources, focusing heavily on algorithmic transparency. Artificial Intelligence Video Interview Act (AIVIA): Enacted and effective January 1, 2020, AIVIA (820 ILCS 42\) requires employers who use AI to analyze video interviews to notify applicants, explain the technology's general characteristics and evaluation metrics, obtain prior consent, and permanently delete the video upon the applicant's request75. To enforce systemic accountability, employers relying solely on AI to select candidates for in-person interviews must annually report demographic data regarding race and ethnicity to the Department of Commerce and Economic Opportunity (DCEO) to monitor for algorithmic bias76. Limit Predictive Analytics Use Act (HB 3773): Enacted on August 9, 2024, and entering into force on January 1, 2026, this statute amends the Illinois Human Rights Act to expressly regulate the use of AI for employment decisions78. Scope: It explicitly prohibits employers from utilizing artificial intelligence (including generative AI systems) in recruitment, hiring, promotion, discipline, or discharge if the system produces a discriminatory effect based on protected characteristics, regardless of whether the discrimination was intentional78. Furthermore, it expressly bans the use of zip codes as a geographic proxy for racial or demographic discrimination79. Implementation: Employers are mandated to provide pre-use notice to employees and applicants regarding the deployment of AI systems in the workplace80. The Illinois Department of Human Rights is currently tasked with promulgating precise implementing regulations regarding the timing, conditions, and content of these notices prior to the 2026 effective date80. Additional 2024/2025 AI Enactments: Illinois enacted several related measures in 2024, including the Digital Voice and Likeness Protection Act (effective August 9, 2024\) to protect performers from unauthorized AI-generated digital replicas, and the Wellness and Oversight for Psychological Resources Act (effective August 1, 2025), which strictly prohibits licensed mental health professionals from utilizing AI to make independent therapeutic decisions75.
Part V: European National Soft Law and Rights Charters
While the European Union establishes binding regulations via directives and regulations, individual member states have proactively drafted national frameworks to guide statutory interpretation and technological development in advance of formal harmonized laws.
Spain: Charter on Digital Rights (Carta de Derechos Digitales)
In July 2021, the Government of Spain adopted the Charter on Digital Rights83. The Charter is a non-binding, soft-law declaration, deliberately designed without normative character to serve as a foundational reference framework for guiding future legislative projects and public policy development in the digital domain83. The text systematically adapts traditional fundamental rights—such as equality, non-discrimination, and privacy—to the technological ecosystem. Crucially, Section XXVI explicitly addresses "Digital Rights in the Employment of Neurotechnologies"86. The Charter outlines that future national legislation must regulate the conditions, limits, and guarantees of neurotechnology deployment to achieve several core objectives:
1. Preserving individual identity and the person's conscious awareness of self86.
2. Guaranteeing individual self-determination, cognitive sovereignty, and absolute freedom in decision-making86.
3. Ensuring the absolute confidentiality and security of data obtained from cerebral processes, granting the individual full dominion, control, and disposition over their neural data86.
4. Strictly ordering and regulating human-machine interfaces that possess the capacity to affect a person's physical or psychological integrity88.
Furthermore, the Charter includes robust provisions regarding algorithmic transparency and accountability. It formally prohibits the use of AI systems directed at manipulating or perturbing the free will of individuals in ways that affect their fundamental rights, aligning closely with the philosophy underpinning the EU AI Act's Article 5 prohibitions85. While strictly soft law, the Spanish Charter has exerted profound influence on the legislative drafting processes across Latin America and within global norm-setting bodies, serving as a template for translating ethical principles into legal frameworks.
Conclusion
The comparative analysis of cognitive liberty regulations across jurisdictions reveals a highly fragmented, yet rapidly evolving, global landscape. The Latin American model, spearheaded by the Republic of Chile and the Brazilian state of Rio Grande do Sul, relies on the explicit constitutionalization of mental integrity. By elevating "neurorights" to the status of fundamental human rights, these jurisdictions provide direct, actionable judicial remedies against both state actors and private corporate entities, as evidenced by the Girardi Lavín v. Emotiv Supreme Court ruling. This model asserts that the interiority of the human mind requires absolute, unalienable protection that supersedes commercial interests. Conversely, the North American architecture manages cognitive liberty through the lens of commercial data privacy and anti-discrimination law. U.S. states—notably Colorado, California, Montana, and Connecticut—have rapidly amended their consumer protection statutes to categorize neural and biological data as "sensitive data," imposing strict opt-in consent and retention requirements. Concurrently, jurisdictions like Illinois regulate the algorithmic outputs of these systems in employment settings, focusing on the mitigation of disparate impact and bias rather than the philosophical sanctity of thought. The application of the "agency theory" of liability, as seen in the ongoing Mobley v. Workday litigation, demonstrates the U.S. reliance on civil litigation to enforce algorithmic fairness. The European Union bridges these methodologies by deploying a horizontal, risk-based approach through the AI Act, outright banning specific manipulative deployments of neurotechnology and emotion recognition, supported by the data processing constraints of the GDPR. Ultimately, international instruments such as the UNESCO Recommendation on the Ethics of Neurotechnology and the Council of Europe's CETS 225 treaty highlight a growing global consensus: the unconsented extraction of neural data and the deployment of cognitive-altering algorithms pose existential threats to individual autonomy. Whether through constitutional amendments, data privacy mandates, or international treaties, the legal codification of the forum internum represents the defining human rights challenge of the neurotechnological era.
Works cited
1. A/HRC/57/61\* General Assembly, https://www.redipd.org/documento/2024-impact-opportunities-and-challenges-neurotechnology-regard-promotion-and-protection
2. Special Issue VIII (2026) Neurorights in the Age of AI: Universalism, Cognitive Vulnerability, and the Limits of Legal Translation \- ResearchGate, https://www.researchgate.net/publication/403703751\_Special\_Issue\_VIII\_2026\_Neurorights\_in\_the\_Age\_of\_AI\_Universalism\_Cognitive\_Vulnerability\_and\_the\_Limits\_of\_Legal\_Translation
3. Habeas Cogitationem: A Writ to Enforce the Right to Freedom of Thought in the Neurotechnological Era \- Tech Policy Press, https://www.techpolicy.press/habeas-cogitationem-a-writ-to-enforce-the-right-to-freedom-of-thought-in-the-neurotechnological-era/
4. Neurotechnology Privacy: Safeguarding the Next Frontier of Data | TrustArc, https://trustarc.com/resource/neurotechnology-privacy-safeguarding-the-next-frontier-of-data/
5. Recommendation on the Ethics of Neurotechnology \- Legal Affairs \- UNESCO, https://www.unesco.org/en/legal-affairs/recommendation-ethics-neurotechnology
6. Towards an International Instrument | UNESCO, https://www.unesco.org/en/ethics-neurotech/recommendation
7. Airtable | Neurotech and Law, https://www.neurotechlaw.com/airtable
8. UNESCO Adopts First Global Framework on Neurotechnology Ethics, https://www.globalpolicywatch.com/2026/01/unesco-adopts-first-global-framework-on-neurotechnology-ethics/
9. The UNESCO draft Recommendations on ethics of Neurotechnology — A commentary, https://www.researchgate.net/publication/391196602\_The\_UNESCO\_draft\_Recommendations\_on\_ethics\_of\_Neurotechnology\_-\_A\_commentary
10. CETS 225: The Council of Europe AI Convention Explained \- SRJ Consulting, https://srjconsultingservices.com/ai-governance/coe-framework-convention/
11. International AI Treaty \- Center for AI and Digital Policy, https://www.caidp.org/resources/coe-ai-treaty/
12. The Framework Convention on Artificial Intelligence \- The Council of Europe, https://www.coe.int/en/web/artificial-intelligence/the-framework-convention-on-artificial-intelligence
13. The EU, UK and US sign international treaty addressing risks of AI, https://www.clearyiptechinsights.com/2024/09/the-eu-uk-and-us-sign-international-treaty-addressing-risks-of-ai/
14. Framework Convention on Artificial Intelligence and Human Rights, Democracy and the Rule of Law (Council Eur.) | International Legal Materials | Cambridge Core, https://www.cambridge.org/core/journals/international-legal-materials/article/framework-convention-on-artificial-intelligence-and-human-rights-democracy-and-the-rule-of-law-council-eur/0CCDA03299BF85537031F1CA26CF2CBD
15. Beyond Data Privacy: The Case For Mental Privacy And Neuro-Rights Oltre la privacy dei dati: Il caso della privacy mentale e d \- Suor Orsola University Press \- Suor Orsola Benincasa, https://universitypress.unisob.na.it/ojs/index.php/ejplt/article/download/2248/1799
16. Neurorights in the age of AI: Universalism, cognitive vulnerability, and the limits of legal translation \- Tilburg University Research Portal, https://research.tilburguniversity.edu/files/129661464/5.-Taimur.pdf
17. Austria AI Regulation \- Deep Lex, https://www.deep-lex.com/ai-regulation-tracker/austria
18. All 8 Prohibited AI Practices Under Article 5 — Explained With Examples \- EU AI Compass, https://euaicompass.com/article-5-prohibited-ai-practices-explained.html
19. Rivista di diritti comparati, https://www.diritticomparati.it/wp-content/uploads/2026/04/Special-Issue-VIII-2026\_.pdf
20. Are Technology and the Law on the Same “Wavelength”?: Examining the New Frontier of Brainwaves and Data Privacy, https://scholarship.law.unc.edu/cgi/viewcontent.cgi?article=1507\&context=ncjolt
21. Neurorights in Chile: Between neuroscience and legal science \- ResearchGate, https://www.researchgate.net/publication/354940433\_Neurorights\_in\_Chile\_Between\_neuroscience\_and\_legal\_science
22. A Situated Approach to Neurorights Legislation in Chile | Request PDF \- ResearchGate, https://www.researchgate.net/publication/395913583\_A\_Situated\_Approach\_to\_Neurorights\_Legislation\_in\_Chile
23. Ley de Autismo: Todo sobre la Ley 21.545 en educación \- ADIPA, https://adipa.cl/noticias/ley-de-autismo/
24. LEY DEL ESPECTRO AUTISTA (TEA) EN CHILE, https://sevenpubl.com.br/editora/article/download/6945/12478/27775
25. Preguntas frecuentes ley 21.545 al año 2026 \- Senadis, https://www.senadis.gob.cl/descarga/i/8156
26. Chilean Supreme Court ruling on the protection of brain activity: neurorights, personal data protection, and neurodata \- PMC, https://pmc.ncbi.nlm.nih.gov/articles/PMC10929545/
27. Privacy and the Rise of “Neurorights” in Latin America, https://fpf.org/blog/privacy-and-the-rise-of-neurorights-in-latin-america/
28. The protection of mental privacy in the area of neuroscience \- European Parliament, https://www.europarl.europa.eu/RegData/etudes/STUD/2024/757807/EPRS\_STU(2024)757807\_EN.pdf
29. (PDF) Neurodados: do necessário enquadramento como dados pessoais sensíveis, https://www.researchgate.net/publication/381787633\_Neurodados\_do\_necessario\_enquadramento\_como\_dados\_pessoais\_sensiveis
30. ARTICLE Neurocriminalistics in the Era of the Brain–Computer Interface: Balancing Investigative Effectiveness and Human Right \- BRICS Law Journal, https://www.bricslawjournal.com/jour/article/download/1752/358
31. ALGORITHMIC TRANSPARENCY AS A FUNDAMENTAL RIGHT IN THE DEMOCRATIC RULE OF LAW: A COMPARATIVE APPROACH TO REGULATION IN EUROPEAN,, https://bjlti.com/revista/article/download/19/18
32. Safeguarding Brain Data: Assessing the Privacy Practices of Consumer Neurotechnology Companies \- Perseus Strategies, https://perseus-strategies.com/wp-content/uploads/FINAL\_Consumer\_Neurotechnology\_Report\_Neurorights\_Foundation\_April-1.pdf
33. US SB2925 | 2025-2026 | 119th Congress \- LegiScan, https://legiscan.com/US/bill/SB2925/2025
34. Sens. Cantwell, Schumer, Markey Introduce Legislation to Shield Americans' Brain Data From Exploitation \- U.S. Senate Committee on Commerce, Science, & Transportation, https://www.commerce.senate.gov/press/dem/release/sens-cantwell-schumer-markey-introduce-legislation-to-shield-americans-brain-data-from-exploitation/
35. The MIND Act: Congress's Attempt to Protect Americans' Brain Data, https://www.healthlawpolicy.org/2025/11/02/the-mind-act-congresss-attempt-to-protect-americans-brain-data/
36. USA: Bill for MIND Act of 2025 introduced to Senate | News \- DataGuidance, https://www.dataguidance.com/news/usa-bill-mind-act-2025-introduced-senate
37. Congress Introduces Neural Data Bill \- Inside Privacy, https://www.insideprivacy.com/health-privacy/congress-introduces-neural-data-bill/
38. The Crackdown Commences: The FTC's Case Against Rite Aid's Deployment of AI-Based Technology | Advisories | Arnold & Porter, https://www.arnoldporter.com/en/perspectives/advisories/2024/01/ftc-case-against-rite-aid-deployment-of-ai-based-technology
39. All the World's Neural Data, No Common Rule | Davis Wright Tremaine, https://www.dwt.com/blogs/privacy--security-law-blog/2026/05/all-the-neural-data-and-no-common-rule-2026
40. Eastern District of Pennsylvania | Federal Trade Commission, https://www.ftc.gov/eastern-district-pennsylvania
41. Proposed FTC Order Suggests Blueprint for AI Adoption | Insights \- Skadden, https://www.skadden.com/insights/publications/2024/01/proposed-ftc-order-suggests-blueprint-for-ai-adoption
42. Rite Aid now banned from using facial recognition by FTC for next five \- Supermarket News, https://www.supermarketnews.com/finance/rite-aid-now-banned-from-using-facial-recognition-by-ftc-for-next-five-years
43. Coming Face to Face with Rite Aid's Allegedly Unfair Use of Facial Recognition Technology | Compliance and Enforcement \- New York University, https://wp.nyu.edu/compliance\_enforcement/2024/01/11/coming-face-to-face-with-rite-aids-allegedly-unfair-use-of-facial-recognition-technology/
44. Rite Aid: $4B Debt and Complete Liquidation After Two Filings \- ElevenFlo, https://elevenflo.com/blog/rite-aid-chapter-11-bankruptcy-liquidation
45. Commitments and contingencies \- SEC.gov, https://www.sec.gov/Archives/edgar/data/1618921/000161892125000009/R15.htm
46. OFCCP Guidance Expands Federal Scrutiny of Artificial Intelligence Use by Employers, https://www.klgates.com/OFCCP-Guidance-Expands-Federal-Scrutiny-of-Artificial-Intelligence-Use-by-Employers-7-16-2024
47. Strategic Enforcement Plan Fiscal Years 2024 \- 2028 | U.S. Equal Employment Opportunity Commission, https://www.eeoc.gov/strategic-enforcement-plan-fiscal-years-2024-2028
48. AI Hiring Discrimination Lawsuits: EEOC Enforcement 2026 \- Angela Reddock-Wright, https://angelareddock-wright.com/ai-driven-hiring-bias-the-next-frontier-of-eeoc-enforcement/
49. Employer Guide: EEOC Priorities, Leave Law Compliance & AI Risk Management \- Bass, Berry & Sims PLC, https://www.bassberry.com/wp-content/uploads/employer-guide-eeoc-leave-laws-ai-compliance-2026-Mar.pdf
50. AI in the Workplace: Uses and Risks \- Employment Practices Solutions, https://www.epspros.com/news-resources/white-papers/2024/ai-in-the-workplace-uses-and-risks.html
51. 2024 New California Employment Laws \- Hanson Bridgett LLP, https://www.hansonbridgett.com/sites/default/files/2024-01/2024-Labor-%26-Employment-Seminar.pdf
52. Full article: Bias audit laws: how effective are they at preventing bias in automated employment decision tools? \- Taylor & Francis, https://www.tandfonline.com/doi/full/10.1080/13600869.2024.2403053
53. AI As An Employment Agent: What Mobley V. Workday Addresses, and What It Doesn't, https://hulr.org/spring-2025/ai-as-an-employment-agent-what-mobley-v-workday-addresses-and-what-it-doesnt
54. Montana on the Brain: A Bold Step for Neural Privacy // Cooley // Global Law Firm, https://www.cooley.com/news/insight/2025/2025-04-22-montana-on-the-brain-a-bold-step-for-neural-privacy
55. Colorado Amends Privacy Act with H.B. 1058, Adding New Protections for Biological and Neural Data \- Hunton Andrews Kurth LLP, https://www.hunton.com/privacy-and-cybersecurity-law-blog/colorado-amends-privacy-act-with-h-b-1058-adding-new-protections-for-biological-and-neural-data
56. Colorado Becomes the First State to Explicitly Protect “Neural Data” \- Blank Rome LLP, https://www.blankrome.com/news-and-events/colorado-becomes-first-state-explicitly-protect-neural-data/
57. Advocacy | United States \- Neurorights Foundation, https://www.neurorightsfoundation.org/advocacy/united-states
58. California Amends CCPA to Cover Neural Data and Clarify Scope of Personal Information, https://www.hunton.com/privacy-and-cybersecurity-law-blog/california-amends-ccpa-to-cover-neural-data-and-clarify-scope-of-personal-information
59. California Enacts Health AI Bill and Protections for Neural Data | Inside Privacy, https://www.insideprivacy.com/uncategorized/california-enacts-health-ai-bill-and-protections-for-neural-data/
60. A MoFo Privacy Minute: Neural Data Added to Montana's Genetic Information Privacy Act, https://www.mofo.com/resources/insights/250815-a-mofo-privacy-minute-neural-data-added
61. Connecticut Significantly Expands the Connecticut Data Privacy Act (CTDPA) \- Vensure, https://vensure.com/employment-law-updates/connecticut/connecticut-significantly-expands-the-connecticut-data-privacy-act-ctdpa/
62. Connecticut Overhauls Its Data Privacy Act | Epstein Becker Green \- Workforce Bulletin, https://www.workforcebulletin.com/connecticut-overhauls-its-data-privacy-act
63. Connecticut Amends the Connecticut Data Privacy Act \- Hunton Andrews Kurth LLP, https://www.hunton.com/privacy-and-cybersecurity-law-blog/connecticut-amends-the-connecticut-data-privacy-act
64. US State Comprehensive Privacy Laws Report ... \- Contentstack, https://assets.contentstack.io/v3/assets/bltd4dd5b2d705252bc/blt2255cd11a986fab6/us\_state\_privacy\_laws\_report\_2025.pdf
65. "You Read My Mind": Neural Data and the New Wave of Biometric Privacy Protections, https://www.bassberry.com/news/you-read-my-mind-neural-data-and-the-new-wave-of-biometric-privacy-protections/
66. Montana Amends its Consumer Data Protection Act | Practical Law, https://uk.practicallaw.thomsonreuters.com/w-046-9228?transitionType=Default\&contextData=(sc.Default)
67. Montana Passes Amendments to Consumer Data Privacy Act, https://www.insideprivacy.com/state-privacy/montana-passes-amendments-to-consumer-data-privacy-act/
68. Montana Consumer Data Privacy Act, https://privacyrights.org/resources-tools/law-overviews/montana-consumer-data-privacy-act
69. Arnold et al. v. Target Corporation \- 1:24-cv-04452 \- Class Action Lawsuits, https://www.classaction.org/media/arnold-et-al-v-target-corporation.pdf
70. IN THE UNITED STATES DISTRICT COURT FOR THE SOUTHERN DISTRICT OF ILLINOIS ANN BARTON, individually, and on behalf of all others \- GovInfo, https://www.govinfo.gov/content/pkg/USCOURTS-ilsd-3\_20-cv-00499/pdf/USCOURTS-ilsd-3\_20-cv-00499-1.pdf
71. Case: 1:19-cv-02942 Document \#: 48 Filed: 02/26/20 Page 1 of 14 PageID \#:426 \- Courthouse News, https://www.courthousenews.com/wp-content/uploads/2020/02/biometricinfo.pdf
72. Bimbo Bakeries Agrees To Pay Employees $295K Over Alleged BIPA Violations \- Class Action Lawsuits, https://topclassactions.com/lawsuit-settlements/privacy/bimbo-bakeries-agrees-to-pay-employees-295k-over-alleged-bipa-violations/
73. Case: 1:19-cv-00382 Document \#: 200 Filed: 04/23/24 Page 1 of 38 PageID \#:1817 \- Simpluris, https://docs.simpluris.com/websites/2656ecfb-358e-44eb-b539-3795969cf3b1/documents/11a78ac2-1906-4168-9e95-57a63c8cc752/Motion%20for%20Preliminary%20Approval.pdf
74. Target Biometric Privacy Lawsuit | PDF | Class Action | Surveillance \- Scribd, https://www.scribd.com/document/795754924/Target-Facial-Recognition-Amended-Complaint
75. AI Library Illinois | Morrison Foerster, https://www.mofo.com/artificial-intelligence/illinois
76. (820 ILCS 42/) Artificial Intelligence Video Interview Act. \- Illinois General Assembly, https://www.ilga.gov/Legislation/ILCS/Articles?ActID=4015\&ChapterID=68\&Print=True\&ref=employerbranding.news
77. Artificial Intelligence Demographic Data Analysis Report 2022 \- Illinois Department of Commerce and Economic Opportunity (DCEO), https://dceo.illinois.gov/content/dam/soi/en/web/dceo/aboutdceo/reportsrequiredbystatute/ai-video-interview-actreport\_2022.pdf
78. Illinois Passes Artificial Intelligence (AI) Law Regulating Employment Use Cases | Insights, https://www.mayerbrown.com/en/insights/publications/2024/09/illinois-passes-artificial-intelligence-ai-law-regulating-employment-use-cases
79. Illinois Prohibits Discriminatory Artificial Intelligence in Employment Decisions, https://www.workforcebulletin.com/illinois-prohibits-discriminatory-artificial-intelligence-in-employment-decisions
80. Illinois Employers Using AI for Workplace Purposes Will Soon Need to Provide Notice: 10 Quick Takeaways and 5 Things You Should Do to Prepare \- Fisher Phillips, https://www.fisherphillips.com/en/insights/insights/illinois-employers-using-ai-workplace-purposes-need-provide-notice-quick-takeaways-things-to-prepare
81. What is H.B. 3773 and What Should Employers Know? \- Reno & Zahm LLP, https://www.renozahm.com/blog/2024/september/what-is-h-b-3773-and-what-should-employers-know-/
82. Illinois Enacts AI Legislation Addressing Digital Replicas, Employment Discrimination, and Child Pornography | Practical Law, https://uk.practicallaw.thomsonreuters.com/w-044-1428?transitionType=Default\&contextData=(sc.Default)
83. El Gobierno adopta la Carta de Derechos Digitales para articular un marco de referencia que garantice los derechos de la ciudadanía en la nueva realidad digital \- Digitalización e Inteligencia Artificial, https://avance.digital.gob.es/en-us/notasprensa/paginas/210714\_np\_carta-.aspx
84. Carta de Derechos Digitales \- Fundación Microfinanzas BBVA, https://www.fundacionmicrofinanzasbbva.org/revistaprogreso/derechos-digitales/
85. Derechos digitales \- La Moncloa, https://www.lamoncloa.gob.es/presidente/actividades/Documents/2021/140721-Carta\_Derechos\_Digitales\_RedEs.pdf
86. DOCUMENTO PARA CONSULTA PÚBLICA Carta de Derechos Digitales \- Ministerio de Economía, Comercio y Empresa, https://portal.mineco.gob.es/RecursosArticulo/mineco/ministerio/participacion\_publica/audiencia/ficheros/SEDIACartaDerechosDigitales.pdf
87. La Carta española de Derechos Digitales y los derechos humanos de los niños, niñas y adolescentes\* \- Redalyc, https://www.redalyc.org/journal/4175/417581436003/html/
88. Informe del Comité de Bioética de España sobre el Borrador de Carta de Derechos Digitales, https://comitedebioetica.isciii.es/wp-content/uploads/2023/10/Informe-CBE-sobre-el-Borrador-de-Carta-de-Derechos-Digitales.pdf