An honest scorecard
Separate what is demonstrated from what is imagined. Demonstrated: side-channel extraction from consumer EEG, adversarial and backdoor attacks on decoders, brainprint identification, and DP or federated training on offline neural datasets. Still speculative: real-time write-channel spoofing of a therapeutic implant, and mind-reading of free-form thought at scale.
The leakage you cannot remove
There is a hard limit no defense escapes. A BCI exists to release your intent T — a cursor move, a word. If a private attribute A is statistically entangled with that intent, then any released decode leaks at least the information the intent itself carries about A. Defenses can push leakage down toward that floor, but not below it.
Post-processing cannot increase leakage (the data-processing inequality), but whatever the released intent T reveals about A is an irreducible floor.
Dual-use and the read/write asymmetry
The same decoder that restores speech can, pointed differently, surveil it. This dual-use character means security is not only technical but governance: who may run the decoder, on whom, for what. And the read/write asymmetry returns — protecting confidentiality is largely a data problem, but protecting the integrity of a write-capable device is a safety problem with bodily stakes.
The law catches up
For the first time, law is engaging directly. Chile amended its constitution and passed a neurorights law; in a landmark 2023 ruling its Supreme Court sided with a plaintiff against a consumer-EEG company and ordered his neural data deleted — the first court decision of its kind.
Statutes are following. In 2024 both Colorado and California amended their privacy laws to treat neural data as sensitive, protected data (consumer neural-data law), and UNESCO adopted a global Recommendation on the Ethics of Neurotechnology in 2025. These sit atop older ideas — neurorights, cognitive liberty, and ownership of neural data — now moving from philosophy into enforceable rules.
Open research problems
Where should a researcher push? There is still no standard threat model or benchmark for neurosecurity, so results are hard to compare. The DP-utility gap at the neural noise floor is wide open. We lack good ways to verify decoder integrity and to obtain meaningful consent for adaptive decoders that keep changing after deployment. And implants meant to last a decade will outlive today's cryptography, raising the question of secure, updatable, post-quantum neural devices.