Every generation believes it will recognise the future when it arrives. We imagine dramatic breakthroughs, newspaper headlines, and unmistakable moments that divide history neatly into a before and an after. We expect a single invention, a single law, or a single announcement that tells us everything has changed.
But technological revolutions rarely announce themselves that way. More often, they arrive quietly. While we are still debating what might happen one day, researchers begin treating patients, companies begin developing products, regulators begin writing guidance, and governments begin investing in industries that barely existed a decade earlier. By the time we realise the conversation has changed, the world already has. I had exactly that feeling recently while following developments in brain-computer interfaces (BCIs).
For almost a decade, one question has dominated legal and ethical discussions about neurotechnology: Do we need neurorights? It is an important question. If technologies can one day decode, interpret, or even influence neural activity, should existing human rights evolve to include protections for mental privacy, cognitive liberty, or psychological continuity? Can our current legal frameworks adequately protect what many describe as the last frontier of privacy, the human mind?
These questions have shaped an extraordinary body of scholarship and policy. They have influenced constitutional reform in Chile, inspired legislative initiatives in several US states (California, Colorado), and prompted international organisations to begin developing governance frameworks specifically for neurotechnology. UNESCO’s recently adopted Recommendation on the Ethics of Neurotechnology is the first global normative instrument dedicated entirely to this field, providing guidance to governments on how neurotechnology should be developed and governed in ways that respect human dignity and fundamental rights.
For a long time, this felt like exactly the right conversation. After all, brain-computer interfaces were still largely confined to research laboratories, hospitals, and carefully controlled clinical trials. Society had time to think about the legal and ethical questions before these technologies became part of everyday life.
Then, almost without noticing, the world changed.
When the Future Quietly Arrives
The headlines that caught my attention recently were about China. Some reported the commercial approval of a brain-computer interface designed to help people living with paralysis regain hand movement. Others described growing state investment in neurotechnology and ambitious plans to establish China as a global leader in the field. Unsurprisingly, much of the international commentary framed these developments as another chapter in technological competition between China and the United States.
As I read these stories, however, I found myself thinking about something else.
The significance of China’s progress is not simply that one country may be moving faster than another. It is that brain-computer interfaces are beginning to cross an invisible threshold. They are no longer only experimental technologies developed by neuroscientists and engineers. Increasingly, they are becoming medical devices, commercial products, and strategic technologies. That distinction matters far more than it first appears.
Research technologies are governed primarily through research ethics committees or institutional review boards, informed consent, and clinical trial regulation. Commercial technologies must also navigate product approval, cybersecurity, software assurance, reimbursement systems, post-market surveillance, liability, technical standards, and consumer protection. The legal questions multiply almost overnight. And so do the ethical ones.
The Questions Begin to Change
Imagine that it is ten years from now. Brain-computer interfaces have become an accepted part of neurological care. They help people living with paralysis communicate with loved ones, restore movement after spinal cord injury, or assist patients living with Parkinson’s disease or ALS. Perhaps some non-invasive systems have even found their way into education, wellness, or consumer technologies.
What questions will people ask?
Most people will probably not begin by asking whether they possess a neuroright. Instead, they are likely to ask questions that feel remarkably ordinary. Who owns my brain data? Can someone hack this device? How often is its software updated? Who checks that the artificial intelligence continues to perform safely? Can my hospital securely share my neural data if I move to another country? Who is responsible if something goes wrong? These are not simply questions about rights. They are questions about governance.
That, I think, is where the conversation around neurotechnology is beginning to evolve.
From Rights to Governance
This does not mean the neurorights movement has failed. Quite the opposite. The neurorights debate has performed an invaluable service by encouraging society to think proactively about mental privacy, autonomy, identity, agency, and human dignity before these technologies become widespread. Those conversations remain essential and will continue to shape law and policy for many years to come.
But rights answer only one part of the puzzle. Rights tell us what society ought to protect. Governance asks how those protections become reality. How should neural data be secured? How should artificial intelligence embedded within neurotechnology be monitored after deployment? Who certifies brain-computer interfaces before they reach patients? What cybersecurity standards should implanted devices satisfy? How should software updates be regulated when those updates may directly affect neural function? How can countries share brain data responsibly while protecting individual privacy?
These questions may sound less philosophical than debates about cognitive liberty or mental privacy. Yet they are becoming increasingly urgent. Perhaps this is simply what technological maturity looks like.
Different Countries, Different Paths
One of the most fascinating aspects of neurotechnology today is that different parts of the world appear to be answering these governance questions in different ways.
China has adopted an approach that closely aligns scientific research, industrial policy, regulatory approval, and commercial deployment. Neurotechnology is increasingly viewed as a strategic capability with implications not only for healthcare, but also for economic competitiveness and national innovation.
The European Union, by contrast, has focused on building comprehensive governance ecosystems. While the AI Act does not regulate neurotechnology specifically, its risk-based approach to artificial intelligence, combined with the General Data Protection Regulation (GDPR) and the Medical Device Regulation (MDR, creates a broader legal environment within which many future neurotechnologies will operate. Together, these instruments seek to ensure that innovation develops within a framework of trust rather than in the absence of regulation.
The United States presents yet another model. Scientific innovation continues to flourish through universities, start-ups, and companies developing cutting-edge neurotechnologies, while governance remains comparatively fragmented. Existing regulatory agencies such as the Food and Drug Administration oversee medical devices, individual states continue to explore neurorights legislation, and federal policymakers have begun considering proposals such as the MIND Act as awareness of these technologies grows.
Alongside these national approaches, international organisations are beginning to build common foundations. In addition to UNESCO’s Recommendation, the OECD Recommendation on Responsible Innovation in Neurotechnology encourages countries to promote innovation while safeguarding safety, transparency, and public trust.
These are not simply different legal systems. They are different visions of how society should govern one of the most intimate technologies humanity has ever created.
Building Trust Before It Is Needed
As a lawyer working at the intersection of biotechnology, neuroscience, and ethics, I increasingly find myself asking a different question. Not whether neurorights matter. They do. But whether we have spent so much time debating the rights people should have that we have paid too little attention to the governance systems that will make those rights meaningful in practice.
Rights alone cannot secure cloud infrastructure that stores neural data. Rights cannot establish technical standards that allow hospitals to exchange brain data safely. Rights cannot certify artificial intelligence systems embedded within medical devices. Rights cannot prevent cyberattacks against implanted neurotechnologies. Those things require institutions. They require regulators, technical standards, oversight – governance.
Ironically, the most important parts of governance are often the least visible. Most people will never think about interoperability standards, software assurance, or post-market surveillance. If these systems work well, they shouldn’t have to. Yet these invisible systems may ultimately determine whether society trusts neurotechnology enough to embrace its extraordinary potential.
The Conversation Is Changing
Law has always evolved alongside technology. Ethics encourages us to ask difficult questions before harm occurs. Human rights remind us what must never be compromised. Good governance, however, asks us to build the institutions capable of turning those principles into everyday reality. I believe neurotechnology has reached that point.
For almost a decade, we have asked what rights people should have in the age of brain-computer interfaces. That question remains as important today as ever. But as neurotechnology moves steadily from laboratories into hospitals, markets, and eventually our daily lives, another question deserves equal attention:
How do we build technologies—and the governance around them—that deserve our trust?
Perhaps that is the real lesson emerging from China, the European Union, the United States, UNESCO, and the OECD alike. The future of neurotechnology is no longer something we are merely preparing for. It is something we are already beginning to govern. And by the time brain-computer interfaces become an ordinary part of everyday life, the question will no longer be whether neurotechnology has arrived.
The question will be whether our governance arrived with it.
Stay curious,
Marietjie
