A · DEFINITION & SCOPE
What this section means—and what it does not
Definition
Mental privacy concerns access to, inference about, and institutional action based on neural, biometric, physiological, behavioral, or relational signals that purport to reveal cognition, emotion, intent, attention, or vulnerability.
Outside scope
Not every sensor is a mind reader. Security cameras, accessibility tools, medical devices, and voluntary wellness systems can have legitimate uses. The risk depends on data type, validity, purpose, power, consequence, retention, and meaningful choice.
B · WHY IT MATTERS
The rights and governance problem
Imperfect systems can still cause severe harm when institutions treat probabilistic outputs as authoritative. A person may be denied a job, flagged at a border, disciplined at school, or targeted for intervention based on an inference that is inaccurate, culturally biased, context-dependent, or impossible to meaningfully contest.
C · KEY DISTINCTIONS
Do not collapse unlike things
Direct neural measurement
Signals recorded from the central or peripheral nervous system through neurotechnology.
Biometric emotion recognition
Claims about emotion derived from face, voice, gaze, posture, or physiology.
Behavioral inference
Predictions based on searches, typing, browsing, movement, purchases, or communication patterns.
Productivity or security monitoring
Observation of task or access behavior that may or may not claim to reveal mental state.
D · CLAIM REGISTER
Three bounded claims with twenty evidence stages each
Each claim preserves the difference between an artifact, its availability, audience exposure, belief, conduct, and downstream effect. “Not assessed” is retained rather than converted into an implied result.
CL-007MECHANISMDocumented mechanism; effects bounded
Direct neural measurement, biometric emotion recognition, behavioral inference, productivity monitoring, and security monitoring are technically and legally distinct.
- Source scope
- The claim is a taxonomy. Each category has different signal sources, validity limits, legal coverage, and consequences.
- Do not infer
- Do not call every behavioral inference a direct reading of thought.
- Competing explanations
- Where outcomes are discussed, ordinary ranking changes, user choice, market incentives, security requirements, model error, institutional process, and non-AI causes remain possible unless claim-specific evidence excludes them.
- Affected-person context
- Worker, gig-worker, student, consumer, and neurotechnology stakeholder evidence is now separately recorded with consent, privacy, selection, and representativeness limits.
- Rights and privacy implications
- Potential implications include freedom of thought or expression, mental and data privacy, equality, autonomy, identity, notice, due process, and effective remedy; legal scope remains jurisdiction-specific.
- Correction trigger
- Revise if authoritative definitions or technical practice materially converge or diverge.
Claim-specific sources
-
CLSRC-OWNER-07When the System Watches the Mind -
CLSRC-EXT-04-CHILE-21383Ley 21.383 — scientific and technological development in service of people -
CLSRC-EXT-05-COLORADO-HB1058HB24-1058 — Protect Privacy of Biological Data -
CLSRC-EXT-06-CALIFORNIA-SB1223SB 1223 — Consumer privacy: sensitive personal information: neural data -
CLSRC-EXT-15-UNESCO-NEUROTECH-2025Recommendation on the Ethics of Neurotechnology -
CLSRC-EXT-16-OECD-NEUROTECH-TOOLKITOECD Neurotechnology Toolkit -
CLSRC-EXT-21-NIST-FRVT-DEMOGRAPHICSFace Recognition Vendor Test Part 3: Demographic Effects (NISTIR 8280) -
CLSRC-EXT-23-ICO-SERCOICO orders Serco Leisure to stop biometric employee-attendance monitoring -
CLSRC-EXT-24-ICO-SELDOM-HEARD-VOICESSeldom Heard Voices: ethnic minority groups and gig economy workers' experiences -
CLSRC-EXT-27-USENIX-PROCTORINGExamining the Examiners: Students' Privacy and Security Perceptions of Online Proctoring Services -
CLSRC-EXT-35-NIST-POST-DEPLOYMENTChallenges to the Monitoring of Deployed AI Systems (NIST AI 800-4) -
CLSRC-EXT-41-FTC-INTELLIVISION-ORDERDecision and Order in the Matter of IntelliVision Technologies Corp. -
CLSRC-EXT-42-CHILE-BCN-NEUROTECH-2026Dispositivos neurotecnológicos: usos, regulación y antecedentes del caso Emotiv Insight -
CLSRC-EXT-45-FTC-RITE-AID-MODIFIED-ORDERRite Aid: Modified Decision and Order
Review all twenty evidence stages
- Artifact or event existence
- MECHANISM DOCUMENTED IN SOURCE MATERIAL
- Content status
- CONCEPTUAL AND POLICY DESCRIPTION REVIEWED
- Coordination
- CLAIM SPECIFIC; NOT INFERRED FROM MECHANISM ALONE
- Actor identity
- NOT REQUIRED FOR GENERAL MECHANISM CLAIM
- Sponsorship or direction
- NOT INFERRED
- Intent
- MAY BE INTENTIONAL OR STRUCTURAL; CLAIM DOES NOT COLLAPSE THEM
- Output
- VISIBILITY, CLASSIFICATION, OR INTERVENTION OUTPUT CAN EXIST
- Distribution
- SYSTEM DEPENDENT
- Availability
- SYSTEM DEPENDENT
- Reach
- NOT ESTABLISHED
- Exposure
- NOT ESTABLISHED
- Attention
- NOT ESTABLISHED
- Recall
- NOT ESTABLISHED
- Comprehension
- NOT ESTABLISHED
- Credibility
- NOT ESTABLISHED
- Belief or attitude
- NOT ESTABLISHED
- Intention
- NOT ESTABLISHED
- Behavior
- NOT ESTABLISHED
- Operational outcome
- CONTEXT DEPENDENT
- Strategic effect
- NOT_ESTABLISHED
Questions for specialist review
- Is the claim phrased no more strongly than the cited sources support?
- Are legal scope, exceptions, and currentness accurately bounded?
- Does the claim preserve the distinction between inference, exposure, belief, behavior, and effect?
CL-008EMPIRICALReviewed empirical evidence
Facial movement alone does not provide a universal, context-free, reliable readout of a person’s specific internal emotion.
- Source scope
- The scientific review addresses inferences from facial movement; it does not evaluate every multimodal, clinical, or voluntary research use.
- Do not infer
- Do not infer that all physiological measurement is worthless or that emotion can never be assessed clinically.
- Competing explanations
- Where outcomes are discussed, ordinary ranking changes, user choice, market incentives, security requirements, model error, institutional process, and non-AI causes remain possible unless claim-specific evidence excludes them.
- Affected-person context
- No new first-person emotion-inference sample is claimed; scientific validity and disparate-impact questions remain open and deployment-specific.
- Rights and privacy implications
- Potential implications include freedom of thought or expression, mental and data privacy, equality, autonomy, identity, notice, due process, and effective remedy; legal scope remains jurisdiction-specific.
- Correction trigger
- Reassess if high-quality replicated evidence materially changes the scientific consensus for defined contexts.
Claim-specific sources
-
CLSRC-OWNER-07When the System Watches the Mind -
CLSRC-EXT-11-BARRETT-EMOTIONEmotional Expressions Reconsidered: Challenges to Inferring Emotion From Human Facial Movements -
CLSRC-EXT-22-NIST-CONSTRUCT-VALIDITYAccelerating AI Innovation Through Measurement Science -
CLSRC-EXT-41-FTC-INTELLIVISION-ORDERDecision and Order in the Matter of IntelliVision Technologies Corp.
Review all twenty evidence stages
- Artifact or event existence
- PEER_REVIEWED_OR_AUTHORITATIVE_RECORD_LOCATED
- Content status
- CLAIM_REVIEWED_AT_CITATION_LEVEL
- Coordination
- NOT_APPLICABLE_OR_NOT_CLAIMED
- Actor identity
- RESEARCH_OR_REPORTING_BODY_IDENTIFIED
- Sponsorship or direction
- SOURCE_SCOPE_RECORDED; INDEPENDENCE_NOT_ASSUMED BEYOND SOURCE
- Intent
- RESEARCH_OR_GOVERNANCE PURPOSE RECORDED
- Output
- PUBLIC REPORT OR STUDY CONFIRMED
- Distribution
- PUBLICATION CONFIRMED
- Availability
- PUBLICLY AVAILABLE
- Reach
- NOT A PERSUASION REACH CLAIM
- Exposure
- NOT ASSESSED
- Attention
- NOT ASSESSED
- Recall
- NOT ASSESSED
- Comprehension
- NOT ASSESSED
- Credibility
- SOURCE AND METHOD BOUNDED
- Belief or attitude
- NOT ESTABLISHED BEYOND REPORTED STUDY
- Intention
- NOT ESTABLISHED
- Behavior
- NOT ESTABLISHED UNLESS CLAIM TEXT STATES OTHERWISE
- Operational outcome
- CONTEXT DEPENDENT
- Strategic effect
- NOT_ESTABLISHED
Questions for specialist review
- Is the claim phrased no more strongly than the cited sources support?
- Are legal scope, exceptions, and currentness accurately bounded?
- Does the claim preserve the distinction between inference, exposure, belief, behavior, and effect?
CL-009LEGALPrimary legal text located
Chile, Colorado, and California have enacted protections that explicitly address brain activity, neural data, or biological data, but their scopes differ and do not form one universal cognitive-liberty code.
- Source scope
- Primary legal texts establish bounded protections. Coverage, exemptions, enforcement, and implementation vary.
- Do not infer
- Do not state that these laws protect all thoughts, emotions, inferences, or actors.
- Competing explanations
- Where outcomes are discussed, ordinary ranking changes, user choice, market incentives, security requirements, model error, institutional process, and non-AI causes remain possible unless claim-specific evidence excludes them.
- Affected-person context
- Rights instruments include affected people as stakeholders, but no project-run participant evidence establishes implementation quality in Chile, Colorado, or California.
- Rights and privacy implications
- Potential implications include freedom of thought or expression, mental and data privacy, equality, autonomy, identity, notice, due process, and effective remedy; legal scope remains jurisdiction-specific.
- Correction trigger
- Update after amendments, implementing rules, court decisions, or new jurisdictions materially change the comparison.
Claim-specific sources
-
CLSRC-EXT-04-CHILE-21383Ley 21.383 — scientific and technological development in service of people -
CLSRC-EXT-05-COLORADO-HB1058HB24-1058 — Protect Privacy of Biological Data -
CLSRC-EXT-06-CALIFORNIA-SB1223SB 1223 — Consumer privacy: sensitive personal information: neural data -
CLSRC-EXT-15-UNESCO-NEUROTECH-2025Recommendation on the Ethics of Neurotechnology -
CLSRC-EXT-16-OECD-NEUROTECH-TOOLKITOECD Neurotechnology Toolkit -
CLSRC-EXT-36-EU-AI-OMNIBUS-2026Regulation (EU) 2026/1744 amending the AI Act and related regulations -
CLSRC-EXT-42-CHILE-BCN-NEUROTECH-2026Dispositivos neurotecnológicos: usos, regulación y antecedentes del caso Emotiv Insight
Review all twenty evidence stages
- Artifact or event existence
- CONFIRMED_BY_PRIMARY_LEGAL_TEXT
- Content status
- PRIMARY_TEXT_REVIEWED_AT_BOUNDED_CLAIM_LEVEL
- Coordination
- NOT_APPLICABLE
- Actor identity
- LEGISLATIVE_OR_TREATY_BODY_IDENTIFIED
- Sponsorship or direction
- PUBLIC_LEGISLATIVE_OR_INTERNATIONAL_PROCESS
- Intent
- BOUNDED_TO_STATED_LEGAL_PURPOSE
- Output
- ENACTED_OR_FORMALLY_PUBLISHED_TEXT
- Distribution
- OFFICIAL_PUBLICATION_CONFIRMED
- Availability
- PUBLICLY_AVAILABLE
- Reach
- NOT_ASSESSED
- Exposure
- NOT_ASSESSED
- Attention
- NOT_ASSESSED
- Recall
- NOT_ASSESSED
- Comprehension
- NOT_ASSESSED
- Credibility
- LEGAL_AUTHORITY_IS_JURISDICTION_AND_SCOPE_SPECIFIC
- Belief or attitude
- NOT_APPLICABLE
- Intention
- NOT_APPLICABLE
- Behavior
- IMPLEMENTATION_NOT_MEASURED
- Operational outcome
- ENFORCEMENT_OR_COMPLIANCE_OUTCOME_NOT_ASSESSED
- Strategic effect
- NOT_ESTABLISHED
Questions for specialist review
- Is the claim phrased no more strongly than the cited sources support?
- Are legal scope, exceptions, and currentness accurately bounded?
- Does the claim preserve the distinction between inference, exposure, belief, behavior, and effect?
E · AFFECTED-PERSON & COMMUNITY EVIDENCE
Whose experience is represented—and whose remains missing
These records are public, consent-aware, and bounded. Illustrative accounts are not converted into prevalence estimates or universal community views.
CLAE-001-WORKER-BIOMETRICSWorkers required to use biometric attendance systemsIllustrative documented enforcement affecting a defined workforce, not population representative.
- Source role
- Regulator-documented affected workforce
- Consent/privacy boundary
- Public regulator record; no individual worker identities are reproduced here.
- Supports
- Power imbalance, absence of a proactively offered alternative, concrete cessation/deletion remedy, and the difference between formal consent and meaningful choice at work.
- Does not establish
- Every worker's view, universal illegality of workplace biometrics, or legal status outside the UK.
- Selection and nonresponse limits
- Enforcement record rather than representative survey; individual response distribution is not available.
- Risk boundary
- Avoid identifying workers, facilities beyond the public order, or employment details not in the source.
- Correction/withdrawal
- Correction path: /corrections; reopen if the order is modified, appealed, or superseded.
CLAE-002-GIG-MINORITY-DATA-RIGHTSGig workers and ethnic-minority communities navigating data rightsIllustrative and analytically rich, not statistically representative.
- Source role
- Commissioned qualitative affected-person research
- Consent/privacy boundary
- Use only aggregated public findings; do not reproduce identifying footage, metadata, or private transcripts.
- Supports
- Lived-experience barriers to notice, correction, language access, and practical remedy.
- Does not establish
- Prevalence for all gig workers or minority communities, platform intent, or a measured effect size.
- Selection and nonresponse limits
- Purposive qualitative sample; 28 ethnic-minority and 15 gig-economy participants; not a probability sample.
- Risk boundary
- Avoid retraumatization, immigration-status inference, or identifying participants through quotes and location combinations.
- Correction/withdrawal
- Correction path: /corrections; source withdrawal follows the publisher's public research process.
CLAE-003-JOB-APPLICANTS-AUTOMATED-REJECTIONApplicants automatically screened by age and sex thresholdsIllustrative resolved case affecting a bounded group.
- Source role
- Federal enforcement and settlement record
- Consent/privacy boundary
- Public agency aggregate; do not identify applicants beyond authorized public records.
- Supports
- Concrete downstream employment consequence, legal challenge, and remedy associated with automated screening.
- Does not establish
- Every alleged fact through trial, a general error rate, or the validity of unrelated hiring tools.
- Selection and nonresponse limits
- Affected group defined by agency litigation; no representative applicant survey.
- Risk boundary
- Avoid employment-history enrichment or identification of individual claimants.
- Correction/withdrawal
- Correction path: /corrections; reopen for amended orders or authoritative case-history updates.
CLAE-004-STUDENT-PROCTORINGStudents subject to remote-proctoring monitoringIllustrative research, not population representative.
- Source role
- Peer-reviewed first-person survey plus civil-rights guidance
- Consent/privacy boundary
- Public research aggregates only; no student identity, disability, room scan, device data, or exam record is reproduced.
- Supports
- Monitoring burden, perceived tradeoffs, data sensitivity, and need for disability/civil-rights review and accessible remedy.
- Does not establish
- Universal student experience, that every flag is wrong, or that every provider violates law.
- Selection and nonresponse limits
- Online survey and review sample; self-selection and product-era limits apply.
- Risk boundary
- Avoid exposing home interiors, disability records, immigration status, or exam-security data.
- Correction/withdrawal
- Correction path: /corrections; reopen with new product, disability-access, or longitudinal field evidence.
CLAE-005-FACIAL-RECOGNITION-CONSUMERSConsumers falsely matched by retail facial recognitionIllustrative consequential deployment with bounded technical context.
- Source role
- Federal enforcement record with technical measurement context
- Consent/privacy boundary
- Public aggregate facts only; do not identify accused or affected consumers.
- Supports
- False-positive consequence, need for notice, complaint response, deletion, testing, and demographic error review.
- Does not establish
- Every complaint's facts through trial, a universal error rate, or intent to discriminate.
- Selection and nonresponse limits
- Complaint/order record and benchmark datasets; neither is an affected-population survey.
- Risk boundary
- Avoid reproducing accusations, images, locations, or identifying consumer metadata.
- Correction/withdrawal
- Correction path: /corrections; reopen if the order or technical report is superseded.
CLAE-010-NEUROTECH-USERSNeurotechnology users and participants as rights-bearing stakeholdersNormative requirement rather than empirical participant evidence.
- Source role
- Intergovernmental normative and implementation frameworks
- Consent/privacy boundary
- No personal neural or health data is collected or published by this project.
- Supports
- The need to include patients, research participants, workers, consumers, disabled people, and device users in governance and remedy design.
- Does not establish
- Actual consent quality, device accuracy, or user outcomes in any specific deployment.
- Selection and nonresponse limits
- No project-run affected-person recruitment; human testing remains unexecuted.
- Risk boundary
- Never publish neural, medical, home, workplace, or wearable identifiers without explicit authority.
- Correction/withdrawal
- Correction path: /corrections; reopen if actual authorized participant evidence is supplied.
F · SCIENTIFIC & LEGAL CURRENTNESS
Measurement validity and jurisdiction remain separate questions
A law may regulate a system without validating its scientific claims. A model may detect a signal without validly inferring an emotion, intention, personality, loyalty, or vulnerability.
CLSCI-001-NEURAL-MEASUREMENTDirect neural measurement and neural-data interpretationNORMATIVE_AND_METHOD_BOUNDARY; NO_UNIVERSAL_VALIDITY_CLAIM
- Construct validity
- NOT_ESTABLISHED_GENERALLY; depends on the claimed construct and validation design.
- Generalization
- Laboratory decoding does not automatically generalize to field use or a different person.
- Calibration/base rates
- Must be demonstrated for the intended population and decision threshold. Low-prevalence targets can yield harmful false positives even with apparently high accuracy.
- Error and disparate-impact burden
- Consequences differ by use; both error types require explicit accounting. Disability, age, medication, language, culture, equipment fit, and access can affect burden.
- Action, override, remedy
- No consequential action should treat inference as direct inner-state knowledge. Human review must have authority, relevant expertise, and access to uncertainty—not ceremonial approval. Notice, data access, correction, deletion, independent review, and downstream propagation of corrections are required safeguards.
CLSCI-002-FACE-IDENTITYFacial identity matchingDOCUMENTED_TECHNICAL_DIFFERENTIALS_AND_ENFORCEMENT_CASE
- Construct validity
- Valid only for the defined matching task and decision context.
- Generalization
- Benchmark performance does not guarantee store, street, or low-quality-video performance.
- Calibration/base rates
- Thresholds must reflect use, base rates, and cost of error. Large watchlists and low prevalence can amplify false-positive burden.
- Error and disparate-impact burden
- FTC Rite Aid record illustrates concrete downstream harm alleged from false matches. NIST documents demographic differentials in many tested algorithms; patterns differ by algorithm and task.
- Action, override, remedy
- A match should not be treated as proof without corroboration and trained review. Reviewer authority and anti-confirmation-bias procedures must be evaluated. Notice, complaint intake, image/source correction, deletion, and repair of accusation or access consequences.
CLSCI-003-FACIAL-EMOTIONFacial-expression classification and emotion inferenceCONSTRUCT_VALIDITY_LIMIT_STRONG; DEPLOYMENT_EFFECT_CLAIMS_CONTEXT_SPECIFIC
- Construct validity
- A facial movement is not a universal context-free readout of a specific inner emotion.
- Generalization
- Laboratory posed-expression performance does not establish field validity.
- Calibration/base rates
- Confidence scores require empirical calibration against a valid target. Rare-event decisions can create high false-positive burden.
- Error and disparate-impact burden
- Errors can affect employment, education, security, or care. Cross-cultural, disability, neurodivergence, age, race, gender, and context validity require explicit analysis.
- Action, override, remedy
- Do not use an unvalidated emotion label as a verdict about loyalty, deception, engagement, or fitness. A reviewer should not merely ratify the model's framing. Provide access to the inference, source trace, correction, and human reconsideration.
CLSCI-004-VOICE-AFFECTVocal-affect and paralinguistic inferenceRESEARCH_DOMAIN_WITH_FIELD_VALIDITY_GAPS
- Construct validity
- NOT_ESTABLISHED_BY_SIGNAL_DETECTION_ALONE
- Generalization
- Language, dialect, accent, disability, medication, and context can break generalization.
- Calibration/base rates
- Thresholds and uncertainty should be disclosed. Low-base-rate deception or risk claims are especially vulnerable to false positives.
- Error and disparate-impact burden
- Burden must be measured separately by decision and group. Accent, speech disability, second-language use, age, gender, and culture can change outputs and consequences.
- Action, override, remedy
- Do not convert a paralinguistic score into a character or conduct finding. Independent review should examine the original content and alternative explanations. Notice, recording access where lawful, correction, alternate assessment, and appeal.
CLSCI-005-GAZE-ATTENTIONGaze, attention, and engagement inferenceAFFECTED_PERSON_CONCERNS_DOCUMENTED; UNIVERSAL_VALIDITY_NOT_ESTABLISHED
- Construct validity
- Looking away can reflect disability, caregiving, room layout, reading, thought, fatigue, or technical error.
- Generalization
- Laboratory gaze tracking may not generalize to varied homes, devices, bodies, or cultures.
- Calibration/base rates
- Person-specific and device-specific calibration may be necessary. Low prevalence of misconduct can make weak flags misleading.
- Error and disparate-impact burden
- False flags can affect grades, discipline, and trust; missed misconduct is a different error. Disability, neurodivergence, skin tone, eyewear, lighting, and assistive technology require testing.
- Action, override, remedy
- A flag should trigger contextual review, not automatic punishment. Reviewer must have authority to clear flags and consider accommodations. Accessible notice, evidence access, educator review, record correction, grade/discipline repair.
CLSCI-006-INTERACTION-PATTERNSKeystroke, interaction-pattern, and productivity inferenceLOG_ACCURACY_CAN_COEXIST_WITH_CONSTRUCT_INVALIDITY
- Construct validity
- Requires role-specific validation and exclusion of off-system labor, accommodation, and task complexity.
- Generalization
- A metric valid for one job or team may fail elsewhere.
- Calibration/base rates
- Thresholds should reflect job design and uncertainty. Rare misconduct and broad monitoring create false-positive risk.
- Error and disparate-impact burden
- Inaccurate data can cause missed work or discipline; gaming metrics can hide real problems. Disability, caregiving, language, connectivity, shift, and equipment access can alter measured behavior.
- Action, override, remedy
- Do not equate metric deviation with misconduct or low worth. Workers and representatives need meaningful input and review authority. Data access, correction, explanation, schedule/pay repair, non-retaliation, and aggregate monitoring review.
CLSCI-007-STRESS-DECEPTION-LOYALTYStress, fatigue, deception, loyalty, personality, and vulnerability predictionHIGH_VALIDITY_AND_RIGHTS_RISK; NO_GENERAL_CERTIFICATION
- Construct validity
- NONSPECIFIC_PROXY_IS_NOT_DIRECT_INNER_STATE_ACCESS
- Generalization
- Stressors, disability, culture, trauma, language, and context undermine broad transfer.
- Calibration/base rates
- Must be population-, context-, and decision-specific. Rare security or misconduct outcomes create severe false-positive risk.
- Error and disparate-impact burden
- False suspicion can itself cause harm; false reassurance creates separate risk. Protected traits and social context may correlate with proxies and consequences.
- Action, override, remedy
- No punitive or coercive action should rest solely on such an inference. Independent evidence and accountable authority are required. Disclosure, challenge, deletion, record repair, and prohibition of retaliation.
CLSCI-008-MULTIMODALMultimodal mental-state inferenceINCREASED_COMPLEXITY_NOT_INCREASED_CERTAINTY
- Construct validity
- Fusion performance must be linked to the actual intended construct and use.
- Generalization
- Field conditions and missing modalities can differ from training and tests.
- Calibration/base rates
- Calibration should be checked by group, context, and deployment period. Aggregation does not remove low-prevalence false-positive problems.
- Error and disparate-impact burden
- Error provenance becomes harder to explain and contest. Cross-modal missingness and sensor accessibility can create unequal burden.
- Action, override, remedy
- Do not treat a composite score as a complete person or verdict. Reviewers need modality-level evidence and authority to reject the composite. Expose component sources, uncertainty, correction paths, and downstream recipients.
CLSCI-009-LAB-TO-FIELDLaboratory performance versus field validityPREDEPLOYMENT_EVALUATION_IS_NOT_FIELD_CERTIFICATION
- Construct validity
- The benchmark must actually measure the claimed real-world capability.
- Generalization
- NIST identifies generalization and real-world informativeness as open measurement questions.
- Calibration/base rates
- Calibration can drift and requires monitoring. Deployment prevalence can differ sharply from benchmark class balance.
- Error and disparate-impact burden
- Field consequences require outcome tracking, not score reporting alone. Subgroup performance and access conditions can change after deployment.
- Action, override, remedy
- Consequential use requires field validation and ongoing monitoring. Monitor override quality and whether humans defer blindly. Incident capture, correction propagation, rollback, and affected-person remedy.
CLLAW-002-UNESCO-NEUROTECHUNESCO member-state normative framework · Ethics of neurotechnologyADOPTED_NORMATIVE_RECOMMENDATION_NOT_BINDING_TREATY
- Enacted text
- UNESCO General Conference adopted a Recommendation on the Ethics of Neurotechnology in November 2025.
- Effective date
- Official UNESCO materials state entry into force on 2025-11-12 within UNESCO's recommendation framework.
- Implementation/guidance
- Member-state implementation is separate and jurisdiction-specific. The text addresses dignity, autonomy, privacy, consent, accountability, equity, and misuse.
- Enforcement/ruling
- No universal judicial enforcement mechanism created by the recommendation.
- Scope limit
- Do not label it enacted domestic law or proof of implementation.
CLLAW-003-CHILEChile · Brain activity and information derived from itENACTED_CONSTITUTIONAL_REFORM_WITH_CASE_LEVEL_RULING_AND_PARTIAL_IMPLEMENTATION
- Enacted text
- Law 21.383 amended constitutional language concerning scientific and technological development and special protection of brain activity and information derived from it.
- Effective date
- Published 2021-10-25.
- Implementation/guidance
- The constitutional reform remains in force. Sector implementation is incomplete; reviewed BCN material records a Supreme Court evaluation order and an ISP conclusion that Emotiv Insight was outside its then-current medical-device competence. Official BCN 2026 research distinguishes the constitutional protection, pending/sector legislation, the Supreme Court ruling, and the ISP competence finding.
- Enforcement/ruling
- No universal interpretation or complete enforcement map asserted here.
- Scope limit
- The case does not create a complete consumer-neurotechnology regulator, verify all deletion, or govern ordinary non-neural behavioral inference or other countries.
CLLAW-004-COLORADOColorado, United States · Biological and neural data under state privacy lawENACTED_STATE_PRIVACY_PROTECTION
- Enacted text
- HB24-1058 expanded Colorado privacy protections for biological data, including neural data within statutory definitions.
- Effective date
- 2024-08-07.
- Implementation/guidance
- Colorado Privacy Act rules and enforcement structure apply according to their scope. Official bill text and legislative status are the source authority.
- Enforcement/ruling
- No universal case-law conclusion recorded.
- Scope limit
- Entity, data, exemption, enforcement, and consumer-right scope must be checked before application.
CLLAW-005-CALIFORNIACalifornia, United States · Neural data as sensitive personal informationENACTED_STATE_CONSUMER_PRIVACY_PROTECTION
- Enacted text
- SB 1223 added neural data to sensitive personal information under California consumer-privacy law.
- Effective date
- 2025-01-01.
- Implementation/guidance
- California Privacy Protection Agency regulations and statutory exemptions remain relevant. Official chaptered bill text is the source authority.
- Enforcement/ruling
- No complete enforcement or appellate map asserted.
- Scope limit
- Does not cover every entity, inference, or use and is not a universal mental-privacy code.
CLLAW-006-EU-AI-ACTEuropean Union · AI Act manipulation, emotion recognition, transparency, employment, education, and law-enforcement scopeENACTED_REGULATION_WITH_ENACTED_2026_AMENDMENTS_AND_PHASED_APPLICATION
- Enacted text
- Regulation (EU) 2024/1689 is enacted and directly applicable according to its phased timetable, definitions, exceptions, and sector-specific provisions.
- Effective date
- AI Act entered into force 2024-08-01. Prohibited practices applied 2025-02-02; GPAI/governance rules applied 2025-08-02; Article 50 transparency duties apply 2026-08-02; selected high-risk dates were extended by Regulation (EU) 2026/1744.
- Implementation/guidance
- Regulation (EU) 2026/1744 entered into force 2026-07-27. Commission guidance, codes, standards, authorities, and delegated/implementing acts remain part of staged implementation. Commission timeline and Article 50 transparency materials reviewed through 2026-07-28.
- Enforcement/ruling
- No claim of final interpretation for every article or exception.
- Scope limit
- Do not describe the 2026 Omnibus as merely proposed. Article 50 application does not mean every high-risk obligation is already in force; exceptions and role-specific duties remain material.
CLLAW-008-ILLINOIS-BIPAIllinois, United States · Biometric identifiers and biometric informationENACTED_WITH_2024_AMENDMENT_AND_ACTIVE_CASE_LAW_BOUNDARIES
- Enacted text
- BIPA imposes duties concerning specified biometric identifiers/information, notice, consent, retention/destruction, disclosure, and security; PA 103-0769 amended recovery and electronic-consent provisions.
- Effective date
- BIPA effective 2008; PA 103-0769 effective 2024-08-02.
- Implementation/guidance
- No single comprehensive implementing regulation recorded here. Current statute and public act are the primary authorities.
- Enforcement/ruling
- Case-specific trial and appellate holdings must be separately mapped.
- Scope limit
- Does not cover all behavioral, emotional, neural, or probabilistic inferences and is not legal advice.
G · VISIBILITY ACTION & REMEDY
Identify the intervention, then test whether the remedy can repair it
Ranking differences are not automatically censorship; technically hosted content is not automatically discoverable. Effective remedy requires more than a nominal appeal form.
CLREM-002-DATA-AND-RULE-ACCESSAccess to relevant data and rule
Effective when: The person can inspect the source data, inferred data, rule version, and evidence used, subject to bounded privacy/security redactions.
Weak or failed when: Only a generic category or unexplained score is provided.
Evidence to retain: Data fields, provenance, rule text, model/deployer role, redactions, and request outcome.
CLREM-004-CORRECTIONCorrection of source and inferred data
Effective when: Both inaccurate inputs and unsupported inferences can be corrected, annotated, or suppressed, with provenance preserved.
Weak or failed when: Only the visible profile changes while downstream copies or decision records remain untouched.
Evidence to retain: Original value, correction, authority, downstream recipients, propagation confirmation, and exceptions.
CLREM-005-DELETION-RETENTIONDeletion and retention control
Effective when: Retention periods, legal exceptions, backups, model-training use, and deletion propagation are disclosed and enforceable.
Weak or failed when: A front-end deletion leaves operational profiles, biometric templates, or downstream datasets active.
Evidence to retain: Deletion request, systems covered, completion date, residual legal basis, and verification.
CLREM-010-AUDIT-REPEAT-PREVENTIONAudit logs and repeated-error prevention
Effective when: Systems preserve accountable logs, investigate root causes, update rules/models/training, and test whether the error recurs across languages and groups.
Weak or failed when: A single case is fixed without identifying systemic causes or affected peers.
Evidence to retain: Version, trigger, reviewer path, root cause, corrective action, regression test, and aggregate outcome.
CLREM-012-NONRETALIATIONNon-retaliation and safe correction
Effective when: People can question data and decisions without losing work, service, grades, care, benefits, or safety.
Weak or failed when: Appeal itself becomes a negative signal or requires disclosure that creates new risk.
Evidence to retain: Retaliation protections, complaint confidentiality, adverse changes after appeal, and independent oversight.
H · OUTCOME & DOWNSTREAM REPAIR
Documented reversals, restoration, relief, deletion, and implementation gaps
A required or announced remedy is not treated as proof that copied data, ranking signals, lost income, delayed access, reputation effects, or repeated errors were repaired.
CLOUT-001-RITE-AID-DOWNSTREAM-DELETIONRite Aid facial-recognition order: use ban, deletion, and third-party propagation
REGULATORY_ORDER_WITH_DOWNSTREAM_REPAIR_REQUIREMENTS
A modified order imposed a five-year facial-recognition surveillance-use ban and specified deletion, monitoring, notice, complaint-response, and third-party propagation duties.
- Institution
- U.S. Federal Trade Commission and the parties bound by the modified order
- Notice and reason
- The public complaint, case page, and order are discoverable; individual consumer notice duties are bounded by the order. The FTC alleged unfair deployment and inadequate safeguards under the FTC Act and order violations.
- Source/inferred-data access
- The public order identifies categories of covered photos, videos, data, models, and algorithms; it does not provide each affected person a complete individualized profile export.
- Explanation
- The public complaint and order explain the asserted practices and required safeguards at case level, not every individual false match.
- Correction and deletion
- The order includes complaint-response and review duties; no aggregate individualized correction success rate is recorded here. Covered information and derived models/algorithms were ordered deleted or destroyed, subject to legal limits and sworn reporting.
- Human authority and appeal independence
- The order requires trained personnel and monitoring, but this record does not claim every individual review was independent or outcome-changing. Regulatory oversight is external to the retailer; no universal consumer appeal tribunal is created.
- Repair
- Use prohibition, deletion, assessment, notice, complaint handling, and monitoring are concrete remedies; compensation is not recorded as a universal remedy.
- Downstream propagation
- The order requires identification of third parties, deletion instructions, demands for written confirmation, and reporting of confirmations or responses.
- Accessibility, language, and support
- No comprehensive public record of language, disability access, or advocate support for each affected consumer was located.
- Unresolved harm
- Third-party deletion completion, reputation effects, distress, lost access, and every copied or derived artifact are not independently verified here.
- Boundary
- A settlement/order is not a contested-trial finding; a required remedy is not proof of completed downstream repair.
- Reopening trigger
- Reopen on public compliance reports, enforcement modification, verified third-party deletion results, or subsequent litigation.
CLOUT-002-ITUTORGROUP-EMPLOYMENT-RELIEFiTutorGroup automated age-screening settlement
EMPLOYMENT_DISCRIMINATION_SETTLEMENT_WITH_MONETARY_AND_INJUNCTIVE_RELIEF
The parties resolved an EEOC suit alleging software automatically rejected older applicants; the settlement provided $365,000 for more than 200 applicants and multi-year non-monetary relief.
- Institution
- U.S. Equal Employment Opportunity Commission, federal court, and settling employers
- Notice and reason
- The public EEOC announcement explains the allegation and settlement; applicant-level notice quality before litigation is not established. The EEOC alleged age and sex discrimination under the ADEA based on programmed age thresholds.
- Source/inferred-data access
- The public record describes age thresholds and application software; it does not provide each applicant full source code or individualized decision logs.
- Explanation
- The litigation record supplies a concrete alleged rule rather than a generic rejection reason.
- Correction and deletion
- The settlement repairs a defined class through monetary relief and prospective controls; individual application reconsideration is not claimed for every person. No comprehensive applicant-data deletion outcome is recorded in the reviewed source.
- Human authority and appeal independence
- Prospective oversight and training relief were imposed; this record does not claim a human reviewer corrected every past decision. EEOC litigation and court supervision provided external review; ordinary applicant appeals remain deployment-specific.
- Repair
- $365,000 and non-monetary relief are documented; lost work, delay, and every downstream consequence were not quantified.
- Downstream propagation
- No verified correction propagation to every recruiting database, vendor, or future model is recorded.
- Accessibility, language, and support
- The public record does not provide a complete accessibility or language-access assessment of the application and remedy process.
- Unresolved harm
- Lost earnings, employment history, confidence, and copied screening records may persist beyond monetary relief.
- Boundary
- Settlement allegations and relief are documented; the case did not produce a contested merits judgment on every fact.
- Reopening trigger
- Reopen on decree compliance reports, later court orders, or verified applicant repair evidence.
CLOUT-007-SERCO-BIOMETRIC-DELETIONSerco employee-attendance biometrics: stop-processing and destruction order
DATA_PROTECTION_ENFORCEMENT_WITH_CESSATION_AND_DELETION
The ICO ordered covered entities to stop biometric attendance processing and destroy biometric data not legally required within the specified compliance period.
- Institution
- UK Information Commissioner's Office and covered Serco Leisure entities
- Notice and reason
- The public enforcement notice is discoverable; employee-level notice and remedy accessibility are not fully recorded. The ICO found the processing was neither necessary nor proportionate and workers lacked a proactively offered alternative.
- Source/inferred-data access
- The order identifies biometric attendance categories; individualized data-access outcomes are not aggregated here.
- Explanation
- The regulator explains necessity, proportionality, consent/power imbalance, and alternatives.
- Correction and deletion
- The remedy is cessation and destruction rather than correction of an inference; individual complaints are not enumerated. Destruction of data not legally required was ordered within three months.
- Human authority and appeal independence
- Regulatory authority can compel cessation; internal workplace review authority was insufficient to prevent the practice. The ICO is external to the employer; legal appeal routes remain separate.
- Repair
- Stop-processing and destruction are concrete; compensation, workplace trust, and every copied record are not established.
- Downstream propagation
- The public source does not fully map every processor, vendor, backup, or derivative template.
- Accessibility, language, and support
- No complete public assessment of employee language, disability access, union, or advocate support was located.
- Unresolved harm
- Copied templates, attendance histories, workplace consequences, and trust effects may persist without separate evidence.
- Boundary
- An enforcement order requiring destruction is not proof every copy was destroyed or every worker repaired.
- Reopening trigger
- Reopen on compliance confirmation, appeal, employee evidence, or processor-level deletion documentation.
CLOUT-008-INTELLIVISION-VALIDATION-ORDERIntelliVision consent order: substantiation and demographic-performance claims
MARKETING_AND_VALIDATION_GOVERNANCE_ORDER
The FTC order restricts unsubstantiated claims about facial-recognition accuracy, demographic performance, and liveness/spoofing and requires competent, reliable, documented testing.
- Institution
- U.S. Federal Trade Commission and IntelliVision Technologies Corp.
- Notice and reason
- The consent order is public; consumer-level pre-purchase understanding is not measured. The FTC alleged misleading or unsupported accuracy, no-bias, training-data, and anti-spoofing representations.
- Source/inferred-data access
- Testing documentation is required for representations; public source-code or full test datasets are not required by this record.
- Explanation
- The order defines testing and documentation elements that must substantiate future claims.
- Correction and deletion
- The remedy governs future claims; individual false-match corrections are not the focus. No general deletion remedy is documented in the reviewed order.
- Human authority and appeal independence
- Qualified testing professionals and documented review are required for claims; no universal affected-person appeal process is created. FTC oversight is external; product users do not receive an independent merits tribunal through this order alone.
- Repair
- Marketing substantiation and documentation are corrected; no proof of restored opportunities or compensated users is recorded.
- Downstream propagation
- No complete record shows correction of every reseller, integration, archived claim, or deployment decision.
- Accessibility, language, and support
- No specific accessibility/language remedy is recorded.
- Unresolved harm
- Past purchasing and deployment decisions based on unsupported claims may persist.
- Boundary
- Substantiated marketing claims are not equivalent to construct validity, deployment safety, or field effectiveness.
- Reopening trigger
- Reopen on public compliance testing, independent field evaluations, or later enforcement.
CLOUT-009-CHILE-EMOTIV-IMPLEMENTATION-GAPChile Emotiv Insight case: judicial order and partial regulatory implementation
APPELLATE_RIGHTS_RULING_WITH_IMPLEMENTATION_GAP
The Supreme Court required public-authority evaluation and compliant handling of brain data; later ISP review concluded the consumer device was outside its then-current medical-device competence.
- Institution
- Chile Supreme Court, Instituto de Salud Pública, customs authority, and Emotiv as described in the public record
- Notice and reason
- The ruling and parliamentary research are public; ordinary consumer notice and product transparency remain separate questions. The case concerned constitutional rights, novel neurotechnology, commercial use, and brain-data handling.
- Source/inferred-data access
- The public record describes device and data categories; it does not disclose every uploaded datum, derivative, vendor copy, or model use.
- Explanation
- The Court explained heightened state responsibility for novel technology; the ISP explained why it found no current competence.
- Correction and deletion
- The reported judicial remedy included compliant data handling and deletion in the individual case; independent completion evidence is incomplete. Deletion was ordered/reported at case level; downstream copies and derived models are not comprehensively verified.
- Human authority and appeal independence
- Judicial review changed the legal posture; the ISP’s competence boundary limited regulatory follow-through. Supreme Court review was independent of the company; implementation depended on public authorities with bounded statutory competence.
- Repair
- Judicial recognition and evaluation/deletion directions are concrete; comprehensive product-market governance and downstream data repair remain incomplete.
- Downstream propagation
- No complete record verifies deletion from all vendor systems, processors, backups, analytics, or models.
- Accessibility, language, and support
- The public legal record is Spanish; no universal consumer language/access support is established.
- Unresolved harm
- Data-copy status, product changes, consumer understanding, and future oversight remain unresolved.
- Boundary
- A landmark individual ruling is not a complete implementation regime or universal neurorights code.
- Reopening trigger
- Reopen on compliance proof, new Chilean implementing law/regulation, ISP competence changes, or further judgments.
CLOUT-010-SAFERENT-HOUSING-SETTLEMENTSafeRent tenant-screening settlement: compensation and score restrictions
COURT_APPROVED_CLASS_SETTLEMENT_WITH_PRODUCT_RESTRICTIONS
A court-approved settlement provided $2.275 million and product restrictions for a defined class of Massachusetts housing-voucher applicants; payments were distributed in 2025.
- Institution
- U.S. District Court, settlement administrator, SafeRent Solutions, and class representatives
- Notice and reason
- The settlement site published deadlines and distribution status; notice at the original housing decision was a disputed harm rather than a proven adequate remedy. Plaintiffs alleged tenant-screening scores disproportionately harmed voucher users and protected groups; SafeRent denied wrongdoing and settled.
- Source/inferred-data access
- The settlement record does not provide complete model logic, source data, or individualized feature explanations to every applicant.
- Explanation
- The litigation identified the score and alleged housing consequences, but no contested merits judgment validates every allegation.
- Correction and deletion
- Eligible class members could claim payment; product restrictions address future scoring, not complete reconsideration of every past housing decision. No comprehensive deletion of applicant data, landlord copies, credit files, or derived profiles is established.
- Human authority and appeal independence
- Future individualized landlord assessment is encouraged by score restrictions, but human review quality and authority are not universally guaranteed. Court supervision and class counsel supplied independent process; ordinary tenant-screening disputes remain sector-specific.
- Repair
- Payments and product restrictions are concrete; lost housing, displacement, search costs, credit effects, and emotional harm are not fully repaired.
- Downstream propagation
- No proof confirms correction across every landlord, property manager, tenant-screening report, credit record, or downstream decision.
- Accessibility, language, and support
- Settlement notice mechanisms existed; comprehensive disability, language, and advocate access outcomes are not published.
- Unresolved harm
- Housing instability, copied reports, landlord beliefs, and opportunity loss may persist.
- Boundary
- Settlement is not an admission or merits judgment; relief is bounded to the agreement and class.
- Reopening trigger
- Reopen on compliance reports, independent validation, subsequent litigation, or class-member outcome evidence.
CLOUT-012-EU-AI-ACT-IMPLEMENTATION-2026EU AI Act implementation: enacted 2026 Omnibus and Article 50 application
ENACTED_LEGAL_IMPLEMENTATION_CURRENTNESS
Regulation (EU) 2026/1744 entered into force on 2026-07-27; Article 50 transparency duties apply from 2026-08-02, while selected high-risk implementation dates were extended.
- Institution
- European Union legislature, European Commission, AI Office, and national competent authorities
- Notice and reason
- Official Journal, Commission timeline, guidance, and code materials are public; deployer-level notice depends on article, role, and use. The implementation framework addresses risk categories, prohibited practices, transparency, general-purpose AI, and high-risk systems under defined scope and exceptions.
- Source/inferred-data access
- The Act creates governance and transparency duties, not universal access to source code or every inferred profile.
- Explanation
- Public materials clarify dates and roles; legal interpretation remains article- and deployment-specific.
- Correction and deletion
- WIP.54 corrects the prior status from proposed to enacted amendments and updates application dates. No universal deletion remedy follows solely from this implementation marker.
- Human authority and appeal independence
- Human oversight requirements apply to defined systems; actual authority and effectiveness require deployment evidence. Remedies derive from the AI Act, sector law, data protection, consumer law, labor law, and national procedure rather than one universal appeal body.
- Repair
- Currentness correction improves legal accuracy; no affected-person repair outcome is claimed.
- Downstream propagation
- All dependent site claims and memory records must distinguish enacted amendments, current application dates, and delayed high-risk provisions.
- Accessibility, language, and support
- EU materials are multilingual; practical accessibility of provider/deployer notices remains system-specific.
- Unresolved harm
- Compliance quality, enforcement consistency, and remedy outcomes remain unmeasured across deployments.
- Boundary
- Enactment and application dates do not establish compliance, effectiveness, or universal legal coverage.
- Reopening trigger
- Reopen on delegated acts, standards, enforcement decisions, court rulings, or further amendment.
WIP.55 FIELD REALISM
Reports linked to this rights question
These owner-supplied reports add outcome, validity, currentness, lived-experience, or repair evidence. Exact source identity is preserved, while independent citation and specialist review remain open.
REAL-02-MACHINE-UNLEARNINGMachine Unlearning, Derived-Data Correction, and the Right to ChangeData lineage, correction, and deletionREAL-03-MENTAL-STATE-VALIDITYField Validity of AI Mental-State Inference SystemsScientific validity and field consequenceREAL-04-COGNITIVE-LIBERTY-LAWComparative Cognitive Liberty Law, Regulation, and Enforcement AtlasJurisdiction-specific law and implementationREAL-06-AFFECTED-COMMUNITYAffected Person and Community Evidence in AI GovernanceAffected-person and community evidenceREAL-07-AI-COMPANION-SAFETYAI Companion Dependency, Reality Testing, and Clinical SafetyClinical safety and authority displacementREAL-13-PREDICTIVE-DEPLOYMENTSPredictive Population Management: Deployments, Feedback Loops, and RemediesPredictive deployment reality and decision consequence
I · SAFEGUARDS & RESEARCH GAPS
What rights-preserving practice would require
Safeguards
- Data minimization and purpose limitation.
- No consequential decision based solely on inferred emotion or mental state.
- Independent validation across cultures, disabilities, and contexts.
- Stronger consent rules where employment, education, healthcare, or state power limits refusal.
Open questions
- How should law distinguish raw signals from derived mental-state inferences?
- When is consent invalid because refusal carries an unacceptable penalty?
- How should people inspect, correct, or delete inferred profiles?
J · SOURCES & REVIEW STATUS
Exact reports and claim-specific external records
Owner reports are shown with exact filename, size, and SHA-256. External records are linked where a public source is available. Public presentation never exposes protected repository paths or internal memory links.
-
CLSRC-OWNER-07When the System Watches the Mind
Exact source: AI Monitoring And Mental Privacy.md · 46,674 bytes · SHA-256
90646aacc27571eb852fcd668705bca53a52df350421136895794b27ff7b5d7f- Supports
- Supports the public information architecture, issue taxonomy, rights framing, proposed safeguards, and source-recovery agenda for this section.
- Does not establish
- Does not independently establish every embedded citation, current legal conclusion, causal effect, platform practice, or universal right.
- Review status
- EXACT_SOURCE_PRESERVED_AND_EDITORIALLY_REVIEWED · Owner source received and preserved on 2026-07-27.
-
CLSRC-EXT-04-CHILE-21383Ley 21.383 — scientific and technological development in service of people
- Supports
- Confirms constitutional language requiring special protection for brain activity and information derived from it.
- Does not establish
- Does not create a universal global cognitive-liberty code or settle all secondary implementing legislation.
- Review status
- PRIMARY_TEXT_LOCATED · Legal text and status checked on 2026-07-27.
-
CLSRC-EXT-05-COLORADO-HB1058HB24-1058 — Protect Privacy of Biological Data
- Supports
- Confirms expansion of sensitive-data protection to biological data including neural data.
- Does not establish
- Does not cover every mental-state inference, every entity, or a complete standalone cognitive-liberty right.
- Review status
- PRIMARY_TEXT_AND_STATUS_LOCATED · Governor-signed status checked on 2026-07-27.
-
CLSRC-EXT-06-CALIFORNIA-SB1223SB 1223 — Consumer privacy: sensitive personal information: neural data
- Supports
- Confirms neural data was added to sensitive personal information in California consumer-privacy law.
- Does not establish
- Does not regulate all cognitive inference, workplace monitoring, or government use in one comprehensive code.
- Review status
- PRIMARY_TEXT_AND_ENACTMENT_STATUS_LOCATED · Text and enactment record checked on 2026-07-27.
-
CLSRC-EXT-07-EU-AI-ACTRegulation (EU) 2024/1689 — Artificial Intelligence Act
- Supports
- Provides risk-based AI rules, including prohibitions on certain emotion-recognition uses in workplaces and education subject to specified exceptions.
- Does not establish
- Does not prohibit all affective computing or apply identically outside EU scope and transition rules.
- Review status
- PRIMARY_TEXT_LOCATED · Application timeline and text checked on 2026-07-27.
-
CLSRC-EXT-10-ILLINOIS-BIPAIllinois Biometric Information Privacy Act, 740 ILCS 14
- Supports
- Regulates collection, disclosure, retention, and protection of specified biometric identifiers and biometric information by private entities.
- Does not establish
- Does not cover all inferred emotions, thoughts, neural data, photographs, or every public-sector use.
- Review status
- CURRENT_STATUTORY_TEXT_LOCATED · Current statutory compilation checked on 2026-07-27.
-
CLSRC-EXT-11-BARRETT-EMOTIONEmotional Expressions Reconsidered: Challenges to Inferring Emotion From Human Facial Movements
- Supports
- Supports the conclusion that facial movements alone do not provide a universal, context-free readout of specific internal emotions.
- Does not establish
- Does not imply all physiological or multimodal measurement is useless in every clinical or research context.
- Review status
- LOCATED_AND_REVIEWED_AT_CITATION_LEVEL · Stable peer-reviewed review; access checked on 2026-07-27.
-
CLSRC-EXT-14-FTC-COMPANIONSFTC Launches Inquiry into AI Chatbots Acting as Companions
- Supports
- Confirms a regulator sought information about companion-chatbot effects and protections, including for children and teens.
- Does not establish
- An inquiry is not an adjudication, final finding, or proof that every companion product causes dependency or harm.
- Review status
- OFFICIAL_INQUIRY_RECORD_LOCATED · Inquiry status bounded to the official announcement and checked on 2026-07-27.
-
CLSRC-EXT-15-UNESCO-NEUROTECH-2025Recommendation on the Ethics of Neurotechnology
- Supports
- Supports safeguards for dignity, autonomy, mental privacy, consent, accountability, equitable access, and protection against abusive neurotechnology uses.
- Does not establish
- Does not enact a binding universal cognitive-liberty statute, resolve domestic implementation, or establish that any particular inference system is accurate.
- Review status
- LOCATED_AND_REVIEWED_AT_CITATION_AND_SCOPE_LEVEL · Adopted by UNESCO's General Conference in November 2025; official text checked 2026-07-28.
-
CLSRC-EXT-16-OECD-NEUROTECH-TOOLKITOECD Neurotechnology Toolkit
- Supports
- Supports anticipatory governance, stakeholder participation, stewardship, safeguards against intrusive surveillance and unconsented assessment, and implementation of the OECD neurotechnology recommendation.
- Does not establish
- Does not create binding law for all jurisdictions or prove that recommended safeguards have been implemented in any particular product or workplace.
- Review status
- LOCATED_AND_REVIEWED_AT_CITATION_AND_SCOPE_LEVEL · Official July 2025 toolkit publication checked 2026-07-28.
-
CLSRC-EXT-17-EU-AI-ACT-TIMELINEAI Act regulatory framework and implementation timeline
- Supports
- Supports current phased AI Act application dates and records that the targeted 2026 AI Omnibus amendments were adopted and entered into force on 2026-07-27.
- Does not establish
- Does not make all obligations immediately applicable, eliminate exceptions, prove provider compliance, or provide legal advice for a particular deployment.
- Review status
- LOCATED_AND_REVIEWED_AT_CITATION_AND_SCOPE_LEVEL · Official Commission page reviewed 2026-07-28; the Omnibus is enacted, not merely proposed.
-
CLSRC-EXT-18-DSA-IMPACT-APPEALSHow the Digital Services Act enhances content moderation transparency and appeals
- Supports
- Supports DSA reason and redress mechanisms and the Commission's aggregate that first-half 2025 out-of-court bodies reviewed more than 1,800 disputes and reversed 52% of closed cases.
- Does not establish
- Does not supply an all-decision denominator, platform-wide error rate, universal accessibility finding, or proof that every downstream strike, ranking, cache, income, or audience effect was repaired.
- Review status
- LOCATED_AND_REVIEWED_AT_CITATION_AND_SCOPE_LEVEL · Official Commission implementation page checked 2026-07-28; aggregate remedy outcomes remain case-selection dependent.
-
CLSRC-EXT-20-ILLINOIS-BIPA-AMENDMENTPublic Act 103-0769: Biometric Information Privacy Act amendment
- Supports
- Supports the 2024 amendment addressing recovery per method of collection and electronic-consent/signature treatment under BIPA.
- Does not establish
- Does not eliminate BIPA duties, decide every pending case, or extend BIPA to every behavioral or mental-state inference.
- Review status
- LOCATED_AND_REVIEWED_AT_CITATION_AND_SCOPE_LEVEL · Official public-act record referenced and currentness checked 2026-07-28.
-
CLSRC-EXT-21-NIST-FRVT-DEMOGRAPHICSFace Recognition Vendor Test Part 3: Demographic Effects (NISTIR 8280)
- Supports
- Supports measured demographic differentials in many face-recognition algorithms and the need to track false-positive and false-negative burdens by application and dataset.
- Does not establish
- Does not establish that every algorithm has identical error patterns, that identity matching reveals emotion or intent, or that laboratory results automatically predict every field deployment.
- Review status
- LOCATED_AND_REVIEWED_AT_CITATION_AND_SCOPE_LEVEL · Stable NIST publication and current demographic-effects index checked 2026-07-28.
-
CLSRC-EXT-22-NIST-CONSTRUCT-VALIDITYAccelerating AI Innovation Through Measurement Science
- Supports
- Supports separating construct validity, generalization, uncertainty, baselines, and real-world informativeness when interpreting AI evaluations.
- Does not establish
- Does not validate any particular emotion, deception, loyalty, productivity, or vulnerability model and is not a certification of a deployed system.
- Review status
- LOCATED_AND_REVIEWED_AT_CITATION_AND_SCOPE_LEVEL · Official NIST measurement-science page reviewed 2026-07-28.
-
CLSRC-EXT-23-ICO-SERCOICO orders Serco Leisure to stop biometric employee-attendance monitoring
- Supports
- Supports a documented enforcement action involving facial and fingerprint attendance monitoring of more than 2,000 workers, power imbalance, lack of a proactively offered alternative, cessation, and deletion requirements.
- Does not establish
- Does not establish universal unlawfulness of all workplace biometrics, represent every worker's experience, or resolve law outside the United Kingdom.
- Review status
- LOCATED_AND_REVIEWED_AT_CITATION_AND_SCOPE_LEVEL · Official enforcement record checked 2026-07-28.
-
CLSRC-EXT-24-ICO-SELDOM-HEARD-VOICESSeldom Heard Voices: ethnic minority groups and gig economy workers' experiences
- Supports
- Supports lived-experience evidence from 43 participants, including 15 gig workers, about data sharing, discrimination concerns, language access, inaccurate data, work opportunities, and barriers to exercising information rights.
- Does not establish
- Does not provide a representative prevalence estimate for all ethnic-minority groups or gig workers, prove platform intent, or establish the outcome of a specific appeal.
- Review status
- LOCATED_AND_REVIEWED_AT_CITATION_AND_SCOPE_LEVEL · Official commissioned report published July 2026 and reviewed 2026-07-28.
-
CLSRC-EXT-25-EEOC-ITUTORGROUPiTutorGroup to pay $365,000 to settle EEOC discriminatory hiring suit
- Supports
- Supports a resolved federal case in which the EEOC alleged automated rejection thresholds based on age and sex, with monetary and non-monetary relief.
- Does not establish
- A settlement does not establish every alleged fact through trial, represent all automated hiring systems, or prove that every older applicant was affected in the same way.
- Review status
- LOCATED_AND_REVIEWED_AT_CITATION_AND_SCOPE_LEVEL · Official EEOC settlement record checked 2026-07-28.
-
CLSRC-EXT-26-FTC-RITE-AIDRite Aid facial-recognition case and modified order
- Supports
- Supports a documented FTC case alleging harmful false matches and inadequate safeguards, and an order imposing a five-year surveillance-use prohibition plus deletion, notice, assessment, and complaint-response duties.
- Does not establish
- Does not prove every allegation through a contested trial, establish the error rate of every face-recognition system, or extend the order beyond its parties and terms.
- Review status
- LOCATED_AND_REVIEWED_AT_CITATION_AND_SCOPE_LEVEL · Official FTC case page and modified order checked 2026-07-28.
-
CLSRC-EXT-27-USENIX-PROCTORINGExamining the Examiners: Students' Privacy and Security Perceptions of Online Proctoring Services
- Supports
- Supports first-person evidence from an online survey of 102 test-takers and analysis of extension reviews concerning personal data, monitoring, fairness, and privacy concerns.
- Does not establish
- Does not represent all students, all disabilities, all proctoring products, or prove that every flagged event was erroneous or discriminatory.
- Review status
- LOCATED_AND_REVIEWED_AT_CITATION_AND_SCOPE_LEVEL · Stable conference paper checked 2026-07-28.
-
CLSRC-EXT-28-ED-OCR-AI-DISCRIMINATIONAvoiding the Discriminatory Use of Artificial Intelligence
- Supports
- Supports the proposition that existing federal civil-rights laws can apply to discriminatory AI use in education and provides bounded illustrative scenarios.
- Does not establish
- Does not adjudicate a specific school, replace statutory text, or prove that every example occurred in practice.
- Review status
- LOCATED_AND_REVIEWED_AT_CITATION_AND_SCOPE_LEVEL · Official guidance resource checked 2026-07-28.
-
CLSRC-EXT-29-OVERSIGHT-DRAG-RECLAIMEDReclaimed Term in Drag Performance
- Supports
- Supports an affected creator's appeal, Meta's acknowledged context error, restoration, and the reported visibility and livelihood relevance of the removed post.
- Does not establish
- Does not provide a platform-wide error rate, measure lost income, or establish that every reclaimed-term removal is wrongful.
- Review status
- LOCATED_AND_REVIEWED_AT_CITATION_AND_SCOPE_LEVEL · Public decision reviewed 2026-07-28.
-
CLSRC-EXT-30-OVERSIGHT-SHAHEEDReferring to Designated Dangerous Individuals as 'Shaheed'
- Supports
- Supports evidence that a blanket rule could over-enforce multilingual and contextual speech and disproportionately burden Arabic speakers and other language communities while legitimate safety goals remain.
- Does not establish
- Does not bind all platforms, establish every removal's intent, or prove that every use of the term is benign.
- Review status
- LOCATED_AND_REVIEWED_AT_CITATION_AND_SCOPE_LEVEL · Public policy advisory opinion reviewed 2026-07-28.
-
CLSRC-EXT-31-OVERSIGHT-ALSHIFAAl-Shifa Hospital
- Supports
- Supports a documented case in which an initial removal and appeal rejection were automated without human review and the Board found public-interest speech had been removed incorrectly.
- Does not establish
- Does not establish a universal platform pattern, determine every factual claim in the underlying conflict, or prove strategic effect from the removal.
- Review status
- LOCATED_AND_REVIEWED_AT_CITATION_AND_SCOPE_LEVEL · Public decision reviewed 2026-07-28.
-
CLSRC-EXT-34-CFPB-ADVERSE-ACTIONConsumer Financial Protection Circular 2022-03: adverse action notification when creditors use complex algorithms
- Supports
- Historically documents the CFPB's 2022 interpretation that covered creditors could not use model complexity as an excuse for failing to provide specific principal reasons under ECOA and Regulation B.
- Does not establish
- The circular was withdrawn on 2025-05-12, is not current CFPB guidance, does not govern every sector, and does not repeal or fully define the underlying statutory and regulatory duties.
- Review status
- ARCHIVED_WITHDRAWN_GUIDANCE_RETAINED_FOR_HISTORY_AND_UNDERLYING_LAW_CONTEXT · Official CFPB withdrawal index checked 2026-07-28; cite as withdrawn historical guidance only.
-
CLSRC-EXT-35-NIST-POST-DEPLOYMENTChallenges to the Monitoring of Deployed AI Systems (NIST AI 800-4)
- Supports
- Supports the need to complement controlled pre-deployment evaluation with ongoing field monitoring for functionality, human factors, security, impacts, and changing context.
- Does not establish
- Does not certify any particular system, define settled best practice for every sector, or prove that monitoring alone prevents harm.
- Review status
- LOCATED_AND_REVIEWED_AT_CITATION_AND_SCOPE_LEVEL · Official NIST publication checked 2026-07-28.
-
CLSRC-EXT-36-EU-AI-OMNIBUS-2026Regulation (EU) 2026/1744 amending the AI Act and related regulations
- Supports
- Supports that the 2026 AI Omnibus amendments were enacted, entered into force on 2026-07-27, and changed portions of the AI Act implementation timetable and conformity framework.
- Does not establish
- Does not erase the AI Act, make all obligations immediately applicable, settle every exception, or supply legal advice for a particular system.
- Review status
- LOCATED_AND_REVIEWED_AT_CITATION_AND_SCOPE_LEVEL · Official Journal record checked 2026-07-28; supersedes the WIP.53 description of the Omnibus as only a proposal.
-
CLSRC-EXT-37-EU-ARTICLE50-TRANSPARENCY-2026Code of Practice and Commission guidance on transparency of AI-generated content
- Supports
- Supports that AI Act Article 50 transparency duties for marking and labeling certain AI-generated or manipulated content apply from 2026-08-02, subject to the enacted text and scope.
- Does not establish
- Does not prove compliance by any provider, make voluntary code participation universal, or establish the accuracy of a particular detection method.
- Review status
- LOCATED_AND_REVIEWED_AT_CITATION_AND_SCOPE_LEVEL · Official Commission page checked 2026-07-28; Article 50 application date remains 2026-08-02.
-
CLSRC-EXT-41-FTC-INTELLIVISION-ORDERDecision and Order in the Matter of IntelliVision Technologies Corp.
- Supports
- Supports restrictions on unsubstantiated facial-recognition accuracy, demographic-bias, spoofing, and liveness claims, and requires competent, reliable, documented testing for future representations.
- Does not establish
- Does not independently validate the product, establish every alleged fact through contested trial, or convert testing documentation into field-validity certification.
- Review status
- LOCATED_AND_REVIEWED_AT_CITATION_AND_SCOPE_LEVEL · Official FTC order checked 2026-07-28.
-
CLSRC-EXT-42-CHILE-BCN-NEUROTECH-2026Dispositivos neurotecnológicos: usos, regulación y antecedentes del caso Emotiv Insight
- Supports
- Supports a bounded implementation history: the Supreme Court required public-authority evaluation and compliant data handling; the ISP later concluded the consumer device was outside its then-current regulatory competence.
- Does not establish
- Does not establish comprehensive compliance, universal coverage of consumer neurotechnology, or that all ordered data deletion and downstream repair were independently verified.
- Review status
- LOCATED_AND_REVIEWED_AT_CITATION_AND_SCOPE_LEVEL · Official BCN report checked 2026-07-28; implementation remains partial and institution-specific.
-
CLSRC-EXT-43-SAFERENT-SETTLEMENTLouis et al. v. SafeRent Solutions settlement administration record
- Supports
- Supports final approval, distribution timing, and a concrete monetary and product-restriction remedy for eligible Massachusetts class members in the SafeRent litigation.
- Does not establish
- Does not establish liability through trial, prove the validity or invalidity of every tenant-screening model, or show that all housing, credit, and downstream profile consequences were repaired.
- Review status
- LOCATED_AND_REVIEWED_AT_CITATION_AND_SCOPE_LEVEL · Settlement status checked 2026-07-28; final approval was granted in November 2024 and payments were distributed in June/July 2025.
-
CLSRC-EXT-45-FTC-RITE-AID-MODIFIED-ORDERRite Aid: Modified Decision and Order
- Supports
- Supports deletion of covered photos, videos, data, models, and algorithms; identification of third-party recipients; instructions and demands for third-party deletion confirmation; and continuing monitoring duties.
- Does not establish
- Does not prove every third party completed deletion, every downstream copy was repaired, or every alleged harm was compensated.
- Review status
- LOCATED_AND_REVIEWED_AT_CITATION_AND_SCOPE_LEVEL · Official modified order checked 2026-07-28; downstream deletion confirmation remains an evidence boundary rather than an assumed outcome.
This section is educational and non-operational. It is not legal advice, clinical guidance, human-rights certification, or authorization to conduct monitoring, influence operations, censorship, or psychological targeting.
Cognitive-liberty overviewAI PSYOPS taxonomyEvidence methodSubmit a correction