The European Group on Ethics in Science and New Technologies (EGE) has published a statement arguing that Europe's regulatory toolkit is not ready for the convergence of neuroscience and artificial intelligence. The advisory body, which reports to the European Commission, wants policymakers to stop examining individual neurotechnologies in isolation and start governing the infrastructures that allow brain-derived data to be collected, shared, processed and reused at scale.

What Neuro-AI is and why it matters now

Neuro-AI describes the intersection of neurotechnology, devices that record or stimulate the nervous system, with artificial intelligence models that can interpret, predict or generate neural signals. The field has accelerated rapidly in the past five years. Brain-computer interfaces developed for clinical rehabilitation are producing datasets large enough to train foundation models. Commercial headsets marketed for wellness or gaming upload neural data to cloud platforms. Research consortia are pooling neurodata across borders to build what the EGE calls Brain Foundation Models, analogous to the large language models that now underpin generative AI.

The potential benefits are concrete. Paralysed patients have regained communication through decoded speech intent. Adaptive deep-brain stimulation is improving outcomes for Parkinson's disease. But the same pipelines that enable these advances also create what the EGE describes as unprecedented inferential power: AI systems can derive mental states, cognitive traits or disease susceptibilities that were never explicitly measured, let alone consented to.

Why the EGE says current regulation falls short

The EU already has the General Data Protection Regulation (GDPR), the Medical Devices Regulation, and the AI Act, which entered into force in August 2024. The EGE's argument is not that these instruments are absent, but that they operate at the wrong level of abstraction. GDPR protects personal data; it does not clearly address inferences generated by AI from that data. The AI Act classifies certain AI systems as high-risk; it does not account for the specific dynamics of neurodata streams fed into continuously learning models. The Medical Devices Regulation covers safety and performance of individual hardware; it does not govern the data infrastructures that outlive any single device.

The group's infrastructure approach treats the collection, processing, model development and deployment layers as a single governance object. This matters because neurodata is rarely used once. A dataset gathered for a clinical trial may be reused to train a commercial decoder, then licensed to a neuromarketing firm, then fed into a public research repository. Each handoff changes the risk profile. Regulating only the first use misses the cumulative exposure.

Five areas the EGE wants addressed

The statement identifies five priority actions. First, explicit legal protection for neurodata and for information inferred from neurodata under EU data protection law. The distinction is critical: an AI model trained on EEG recordings may predict attention deficits or depressive episodes with no clinical diagnosis ever recorded. If that prediction counts as personal data, GDPR applies; if it does not, the subject has no access, rectification or erasure rights.

Second, responsible development of Neuro-AI technologies, including the possible creation of Brain Foundation Models and the compute and data infrastructures they require. The EGE does not call for a moratorium. It argues that public investment should shape these foundations so they reflect European values, transparency, non-discrimination, democratic oversight, rather than leaving the architecture to a handful of US and Chinese firms.

Third, stronger protection of individual rights when neurodata or AI inferences feed into consequential decisions: hiring, insurance, education, criminal justice. The group warns of disproportionate control, where neurological information becomes a gatekeeping criterion without the subject's knowledge or ability to contest.

Fourth, strengthened European public-interest governance capacity. This means dedicated monitoring bodies, audit capabilities, and the technical expertise to evaluate Neuro-AI systems across their lifecycle, not only at market entry. The EGE notes that current market surveillance authorities lack the specialised neuroscience and machine learning competence to assess these systems.

Fifth, a targeted assessment of the EU's existing regulatory framework to determine whether it is sufficiently prepared for Neuro-AI challenges. The EGE stops short of proposing new legislation immediately, arguing that a gap analysis must come first.

The sovereignty dimension

The statement frames Neuro-AI governance as a question of European technological sovereignty. The infrastructure layer, high-performance computing, data spaces, standardised APIs, model repositories, determines who sets the defaults for privacy, access and benefit-sharing. If European researchers and clinicians depend on non-European cloud platforms and foundation models, they import the governance choices embedded in those systems. The EGE's recommendation to develop public-interest Neuro-AI infrastructures aligns with the Commission's broader European Health Data Space and the EuroHPC Joint Undertaking, but it adds a specific ethical guardrail: sovereignty must serve the public interest, not merely industrial competitiveness.

Gaps the statement leaves open

The EGE's infrastructure lens is a useful corrective, but it raises practical questions the statement does not resolve. How should liability be allocated when an inference generated by a foundation model trained on multi-source neurodata causes harm? The AI Act's provider-deployer distinction becomes blurred when models are continuously fine-tuned by downstream users. What constitutes meaningful consent for neurodata reuse when the future purposes are unknown at the point of collection? Dynamic consent platforms exist technically but have not been validated at Neuro-AI scale. And how will the proposed governance capacity be funded and staffed? The EU's existing expert pools for medical devices and AI are already stretched.

International context

Europe is not alone in grappling with Neuro-AI. The OECD adopted a Recommendation on Responsible Innovation in Neurotechnology in 2024. UNESCO is developing a global ethical framework. The US has no federal neurodata law, though Colorado and California have amended privacy statutes to cover neural data. China's 2024 guidelines on brain-computer interface ethics emphasise state oversight of data flows. The EGE's infrastructure approach could position the EU as a regulatory first-mover, much as GDPR shaped global data practices. But first-mover advantage only materialises if the rules are enforceable and interoperable with trade partners.

Organisations

European Commission · European Group on Ethics in Science and New Technologies