JOVANA
Explore Library Glossary Getting Started Three Levels Fields How it works Mission
Join the mission
All guides

The Governance Stack: Why Reading the Brain Needs New Rules

Neural data is not like other data. Meet the layered architecture — individual rights, device regulation, national law, international norms — being built to govern brain reading and writing, and the two rival philosophies underneath it.

What makes neural data different

Governance always begins with a claim about what is at stake. For neurotechnology the claim is that neural signals are unlike any data we have regulated before: they are generated involuntarily, correlate with mental states we never chose to disclose, and — with a decoder — can yield inferences about intention, affect, health, or identity. It helps to separate two things. The raw neural data (a voltage trace, a spike train) is one object; the decoded inference drawn from it is another. Much of the legal debate is really about the inference, which is why proposals increasingly treat neural data as special-category (sensitive) data deserving heightened protection.

The neurorights proposal

Two influential taxonomies frame the field. Ienca & Andorno (2017) proposed four candidate rights: cognitive liberty (the right to think freely and to choose whether to use neurotech), mental privacy, mental integrity (protection from unauthorized alteration of neural activity), and psychological continuity (protection of one's sense of identity over time). Separately, the Morningside Group and Yuste's NeuroRights initiative advanced five: mental privacy, personal identity, agency (free will), fair access to mental augmentation, and protection from algorithmic bias.

These lists overlap but are not identical, and that matters: a right names an interest the law should defend, but it does not by itself say who bears the duty, what counts as infringement, or what remedy follows. The neurorights framework is best read as an agenda that still has to be translated — through statute, regulation, and courts — into enforceable obligations. Volume III's job is to show how far that translation has actually gone.

The governance stack

The governance stack as nested layers: individual neurorights at the core, then device regulation, then national law, then international governance. Each layer can only enforce what the layers around it enable.

Reading the layers from the inside out clarifies who does what. Individual rights state the interests to protect. Device regulation (medical-device law, safety and efficacy review) governs what may be built and sold. National law — data-protection statutes, consumer law, constitutions — sets binding domestic duties. International governancecross-border norms, OECD and UNESCO instruments — coordinates across states and shapes soft-law expectations. Crucially, a right at the core is only as strong as the enforcement in an outer layer that gives it teeth.

Two philosophies: new rights vs. existing law

Underneath every concrete proposal sits a foundational disagreement. One camp argues neurotech is sui generis — special enough to warrant new, explicitly named rights, because existing categories miss the intimacy and involuntariness of brain data. The other warns of rights inflation: adding rights that are vague or redundant can dilute the whole human-rights system, and much of the concern (privacy, bodily integrity, non-discrimination) may already be covered by data-protection law and existing fundamental rights, better enforced than reinvented.