Artificial intelligence, neurotechnology, and data-driven digital systems increasingly enable the collection and inference of neural and neurophysiological data, introducing novel risks to mental privacy, cognitive autonomy, and psychological integrity. Existing data protection frameworks, including the GDPR, were not designed to regulate systems capable of inferring or influencing mental states and therefore struggle to address these emerging challenges. This paper examines neuro-rights as an extension of existing privacy and security by design approaches rather than as a replacement for current regulatory frameworks. Using a structured qualitative methodology that combines a scoping literature review, comparative legal analysis, and a layered AI system model distinguishing sensing, processing, inference, and action stages, the study identifies four structural gaps in current data protection regimes: unregulated cognitive inference, temporal degradation of consent, lack of protection during reduced awareness, and insufficient safeguards against cognitive interference. Based on these findings, the paper proposes a Neuro-Rights-by-Design framework that operationalizes mental privacy and cognitive autonomy through concrete system-level design and governance controls aligned with established privacy and security principles. The results demonstrate that integrating neuro-rights into AI system design is essential for addressing risks arising from inference-driven processing in intelligent and data-intensive digital environments.
Snježana Grgić (Wed,) studied this question.
Synapse has enriched 5 closely related papers on similar clinical questions. Consider them for comparative context: