Colorado, California, Montana, and Connecticut have already classified neural data as sensitive personal information, and nine more bills landed across six additional states in the first six weeks of 2026 alone. AxiSentinel evaluates neurotechnology and AI systems that process brain data against whichever state's rules actually apply.
Neural data, brainwave, EEG, and other signals recorded from a consumer neurotechnology device, didn't exist as its own legal category before 2024. It now sits inside the same fast-moving state-by-state pattern AxiLayer already tracks for general AI law: each state defines it slightly differently, gives individuals a private right of action, and moves faster than any single federal rule.
A privacy-policy review happens once, at launch. AxiSentinel is built for what happens after: continuous evidence that a neurotechnology product's actual data handling matches whichever state's law applies to each user.
No US federal neural-data law exists yet, but the state patchwork is not the whole picture. Chile has given brain data constitutional protection since 2021, UNESCO adopted the first global ethics instrument for neurotechnology in November 2025, and the EU already reaches neural data through GDPR special-category treatment and the AI Act. AxiSentinel tracks all of it.
In force since August 7, 2024. Amends Colorado's Privacy Act to classify neural data as sensitive data requiring opt-in consent.
Extends the CCPA's definition of sensitive personal information to neural data, triggering the CCPA's existing opt-out and minimization obligations.
Effective October 1, 2025. Adds "neurotechnology data" to Montana’s genetic privacy act, defines "mental augmentation," and adds a warrant requirement for law enforcement access to neural data.
Effective July 1, 2026. Classifies neural data as sensitive personal data under Connecticut’s consumer data privacy law, completing the fourth of four US states with an enacted neural-data privacy statute.
The first sector-specific neural-data restriction: bars insurers and employers from using neural data in coverage or employment decisions.
Signed May 18, 2026, effective July 1, 2026. Establishes neurological rights principles and mandates a state agency study of neurotechnology in health and human services.
Published October 2021. The first country in the world to give brain activity and the information derived from it constitutional protection.
Adopted November 5, 2025 at the 43rd General Conference. The first global standard-setting instrument on neurotechnology ethics, addressed to member states.
Neural data is not named in the GDPR text, but the European Data Protection Supervisor’s TechDispatch 1/2024 on neurodata confirms it will frequently qualify as a special category of personal data under Article 9. Separately, AI Act Article 5(1)(f) has prohibited inferring emotions from biometric data in workplaces and educational institutions since February 2, 2025.
General-purpose AI risk-management frameworks that already apply to any AI model processing neural or brain-signal data.
Also monitored, not yet enacted: Brazil (a federal neurorights constitutional amendment pending; Rio Grande do Sul’s own state constitutional amendment has been in force since December 20, 2023), Mexico, Argentina, Uruguay, Colombia, and Ecuador (neurorights initiatives introduced, none enacted), and China (a brain-computer interface research-ethics guideline issued February 2024, not a neural-data privacy statute).
From a single wearable device to a fleet of clinical neurotechnology platforms, AxiSentinel evaluates the software and data-handling evidence continuously, not just at launch.
Nothing about AxiSentinel's core architecture changes for neurotechnology. What changes is which RegDef packages are switched on and what telemetry the agents capture from a device or platform.
Agents capture device and data-handling telemetry on the cadence you configure, always-on or scheduled, in full rather than sampled, and never limited to a quarterly cycle.
Every telemetry event evaluated against the applicable state's neural-data rule set, per data event.
Every audit record is linked to the one before it in a signed, tamper-evident evidence chain, verifiable from the first event.
A compliance state change on one device or an entire product line propagates network-wide as it happens.
Nothing becomes a compliance finding until a qualified auditor reviews and signs it.
AXI-Node agents deploy directly on wearable and edge neurotechnology hardware, with the .axibatch format available for offline or intermittently-connected devices.
Tracks human involvement in consent, retention, and deletion decisions, feeding into AxiSentinel's oversight-gap scoring model.
The same agents generating compliance evidence watch for unauthorized neural-data exfiltration, unconsented model retraining, and scope creep beyond a device's disclosed function before a re-certified release reaches production.
New state law, jurisdiction, or sector-specific rule is added by encoding new RegDef packages. Deployed agents are never rebuilt.
Scoped to your organization during onboarding, not hard-coded into the platform.
A threshold breach becomes a flagged, timestamped, evidence-linked Provisional Alert, reviewed by a certified human auditor before anything counts as a finding.
The same architecture monitoring a neurotechnology device monitors a trading desk's model or a hospital's diagnostic AI. What changes is which RegDef packages are switched on.
Four states enacted neural-data law before most neurotechnology companies finished mapping what it means for their own products. AxiSentinel's architecture already does continuous evidence generation for regulated AI; neural-data governance is a new RegDef surface on the same platform, not a new product.
Whether it's a single wearable device or a fleet of clinical neurotechnology platforms, AxiSentinel evaluates it the same way it evaluates any AI system: on the cadence you configure, always-on or scheduled, with full evidence, and with a human signature before anything counts as a finding.