The data wall and non-stationarity
The most concrete limit is quantitative: high-quality neural corpora are minute beside the web-scale data behind language and vision models, and no amount of cleverness manufactures more chronic human intracortical recording. Worse, unlike text, the neural distribution moves under your feet — everyday non-stationarity and signal drift mean the pretraining distribution and the deployment distribution are never the same.
A schematic domain-adaptation bound: deployment error is limited by pretraining error plus the divergence between the pretraining and deployment distributions (new subject, drift), plus an irreducible term lambda. Pretraining cannot erase a large distribution gap.
Is there a universal neural code?
Beneath every transfer claim lies a scientific question the field has not settled: is there enough shared structure across brains for a single representation to be genuinely universal? The optimistic evidence is real — low-dimensional neural manifolds and conserved rotational dynamics recur across animals. But universality and transfer limits and the deeper neural code problem warn that generality may be fundamentally bounded — a foundation model could be learning a shared computational geometry, or merely a convenient average of the labs that supplied its data.
Evaluation is immature
The field's benchmarks are young and easy to game. Cross-session, held-out-subject evaluations (FALCON-style few-shot decoding benchmarks) are the right idea, but leaderboard overfitting and within-session reporting inflate apparent progress. Two disciplines matter most: always report held-out-subject / held-out-session numbers, and pair accuracy with interpretability so a gain is understood, not just observed. Overclaiming is the field's occupational hazard.
Privacy and security of big neural models
A model trained on many people's brains is itself a new attack surface. Because networks memorize, a shared backbone invites membership inference (was my recording in the training set?), brainprint re-identification, and model-inversion reconstruction of private neural features. Pooling neural data to build foundation models therefore collides directly with the neural-privacy commitments you studied in Volume II — a tension the governance frontier is only beginning to address.
An honest ledger and where it is going
Close the track with a clear ledger. Demonstrated: multi-session pretraining that cuts calibration, channel-agnostic decoders, few-shot in-context adaptation within a domain, and encoding digital twins. Emerging: genuine cross-subject and multimodal neural+language models. Open: true cross-population generality, credible scaling laws, robustness to drift without recalibration, standard held-out benchmarks, and privacy-preserving training. A sober reading of the next decade expects steady, unglamorous gains — better transfer, less calibration, tighter benchmarks — rather than a single 'brain GPT' moment.