De Mente Reserata: The Ultimate Power · Lobeworks/17
A manifesto on the economics of reading and writing the human brain, dated so that it can be checked. It separates what physics forbids from what engineering has not yet done, sets the comparison with GPT-4 point by point, names the six permits a neural function needs before it becomes a product, stakes one measurable bet on how much of fitting a decoder to a person can be learned outside that person, predicts the order in which those functions will arrive and what each will look like, and closes with dated bets and the evidence that would prove them wrong.
De Mente Reserata: The Ultimate Power. What Holds It Back, What It Will Cost, What It Will Unleash
In the summer of 2023 a surgeon at UC Davis pressed four small squares of silicon, each carrying sixty-four needles finer than an eyelash, into the left side of Casey Harrell's head, into the speech region of his motor cortex, the strip that used to move his lips, his jaw, his tongue and his larynx. Harrell was forty-five and had ALS, and his speech had worn down to a slur that even his family followed with effort. In the first session, twenty-five days after the operation and half an hour into calibration, the words he was trying to say began to appear on a screen, right ninety-nine times in a hundred on a fifty-word vocabulary, and a voice built from recordings of his voice before the illness read them aloud, and he cried, and so did the people in the room1. What I keep returning to is the road those words travelled. They left as spikes from a few hundred neurons that had never been told what a word is, crossed a cable and a rack of computers, passed through a network that guessed at phonemes and a language model that had read more sentences than any person ever will, and came out sounding like him. At no point on that road did the machine know anything about Harrell (his opinions, his memories, the names of his children). It knew the shape of the commands that a mouth which no longer obeyed was still being sent, and that was enough to give a man his voice back.
1Card et al., An accurate and rapidly calibrating speech neuroprosthesis, NEJM 391, 2024, which reports 99.6% accuracy on that first day and 97.5% on a vocabulary of 125,000 words over the following eight months.
The distance between what that machine knew and what it returned is the subject of this manifesto. The first economy of the brain will be built on partial access sold as function, long before anyone can explain the mind that is being accessed. The bar it has to clear is a signal that changes a decision: an intention that returns a tool, a marker that retunes a stimulator, a mediocre estimate of attention that a company is willing to act on. These are different accesses, with different demands and different consequences, and grouping them under the phrase reading the mind makes the subject impossible to think about. I will call the idea that runs under everything that follows sufficient access: an industry needs a window onto what a given function requires, and onto nothing else, provided that the function is worth more than the cost of opening the window. The breadth of an access and the weight of its consequences are different quantities. A narrow window can return a function that rebuilds a life, and a partial inference can weigh on a decision that changes one, so the power in the title has no need of a transparent mind.
The comparison with GPT-4 belongs here, and it holds in two respects. The first is economic: a language model did not have to solve intelligence to make some intellectual operations reusable, and a brain interface will not have to solve the mind to make some of its outputs useful. The second goes deeper and has a section of its own, because the internal states of models trained to predict the next word turn out to predict a good share of what the cortex does with the same words, which is why their descendants sit inside the best decoders (a correspondence in what is represented, with candidate principles of computation behind it, and still short of a shared mechanism). The respect in which the comparison breaks is the one that sets the calendar. Language was already outside the body, written down by billions of people and scattered across the internet for free, and the activity we now want to use is still inside, has to be measured through bone or under it, has to be interpreted by a code that differs from one head to the next, and has to stay accessible for years without damaging the organ that produces it. The permits below are that asymmetry broken into its parts, and almost every prediction in this text follows from it.
I build systems and study how they fail, and I am not a neuroscientist. Where this text is about observability, models, evaluation, standards and supply chains it speaks with my own confidence; where it touches tissue it leans on the people who measured it, by name and with the source beside the claim. And since the purpose of a manifesto that makes predictions is to be checked later, I will try to say each time how sure I am and why, and never let a result obtained in one patient stand in for a trend, or a difficulty of today stand in for a law of physics.
The argument has one thesis, six conditions and one bet. The thesis is sufficient access. The conditions, which I will call the permits, decide when a given access becomes a product, and most of the sections that follow examine one of them and say what changes when it is granted. The bet concerns what could make one of them, the data, far cheaper: that part of what a decoder has to learn about a head can be learned outside it. The dated predictions at the end are conditional consequences of the thesis, the permits and the bet, and if the bet fails the thesis still stands, with more fitting per person and a different cost structure.
What the language models had that the brain lacks
Picture someone in 2015 trying to forecast the next decade of machines and language. The pieces were on the table: word embeddings from 2013, sequence-to-sequence translation from 2014, the attention mechanism published the same year1. A forecaster who wanted to be right about what came next did not need to foresee reasoning or conversation. Two observations would have been enough. The first is that the training material already existed outside anyone's body, digitised and nearly free: the Common Crawl had been archiving the open web since 2008, petabytes of sentences that nobody had to be paid or operated on to produce. The second is that the training signal cost nothing either, because a model asked to predict the next word in a text is checked by the text itself, with no labeller in the loop. With those two facts in hand, the order in which capabilities reached ordinary people would have been almost predictable: machine translation in Google's products in 2016, suggested phrases in email in 2018, code completion in 2021, a conversational system in November 2022, GPT-4 in March 2023, agents that run tasks of their own in 20252.
1Mikolov et al., Efficient estimation of word representations in vector space, 2013; Sutskever et al., Sequence to sequence learning with neural networks, 2014; Bahdanau et al., Neural machine translation by jointly learning to align and translate, 2014. 2Wu et al., Google's neural machine translation system, 2016; Smart Compose reached Gmail in May 2018 and GitHub Copilot opened as a preview in June 2021; OpenAI, GPT-4, 14 March 2023.
Look at that order with an engineer's eye and difficulty for the machine fails to explain it, since writing code is harder than suggesting the end of a sentence. What explains it is how quickly a person could catch a mistake and forgive it. A wrong suggestion in an email costs a keystroke; a mistranslated menu costs a strange dinner; a wrong line of code is caught by a compiler or a test within seconds, which is why programming, a hard task with a free verifier, arrived years before medicine and law, where checking an answer requires an expert and an error can hurt someone. Other things equal, capabilities reach the world in the order in which their data is cheap to gather and their mistakes are cheap to catch. I will call this the order of forgivable errors, and the first three words carry it. It compares like with like: among capabilities of similar usefulness, with similar access to data and similar conditions of deployment, I expect those whose errors are detectable and reversible to spread first. A capability with expensive errors can still arrive early when the need it serves is far larger or nothing else serves it, so the cost of an error has to be weighed against the benefit of getting it right and against the alternatives, and a difference in either can override the rule. That is why the comparison has to be fixed before the result is known, never chosen afterwards to rescue it. And someone has to do the forgiving. The buyer, the user and the person an output is about need not be the same, and a capability can spread fast because its errors are cheap for whoever adopts it while they fall on someone else; the consumer state readers of the section on the order of arrival are the first place the brain will test that case. Read that way, I think it is the most useful thing the history of language models can teach anyone trying to forecast the brain.
Applied to the brain, the first half of that rule is brutal. There is no Common Crawl of neurons. The people who have ever had an intracortical brain-computer interface fit in a few lecture halls: Neuralink reported 21 participants in January 20261, and the academic consortia that came before it count their participants in the dozens. Every hour of that data cost a craniotomy, belongs to a patient, is protected health information, and is written in a code that is partly individual, because no two arrays land on the same neurons and the neurons under one array drift over weeks. The second half of the rule is kinder: self-supervision works on neural data as it works on text, and pretrained models that transfer what they learn from pooled recordings of many animals and people already exist2. What is scarce is the corpus. So the brain's version of the moment GPT-4 stood for, if it comes, will come from wherever recordings pile up without asking for new surgery: from animals, where a Neuropixels probe with nearly a thousand sites costs about the price of a laptop; from people already implanted for medical reasons (epilepsy monitoring, deep brain stimulation, responsive neurostimulation); and from cheap external sensors used by millions, whose signal is poor but whose volume is not. Each of these pools carries its bias into the models trained on it, since a mouse is not a person, a person with epilepsy is not everyone and a scalp electrode hears a crowd rather than a voice. Whoever assembles the largest consented corpus of long human recordings will own the prior that every later decoder needs, and I expect that corpus, more than any electrode, to be the durable advantage of the 2030s.
1Reuters via US News, Neuralink says it has 21 participants enrolled in trials, 28 January 2026. 2Azabou et al., A unified, scalable framework for neural population decoding, NeurIPS 2023, trains one model across recordings from many subjects and transfers it to new ones.
It is an extrapolation, and the strongest evidence against it is already published. NDT3, a decoder pretrained on about two thousand hours of spiking activity from more than thirty monkeys and people, beat models trained from scratch when a new task came with less than about an hour and a half of data and only matched them beyond that; using the whole corpus needed a model eight times larger, some tasks gained nothing, and its authors wrote that scale was unlikely to fix the limits that come from variable sensors, while leaving room for limits of the model itself, so the ceiling they found is experimental and has not been shown to be biological1. That is the most important fork in the machine learning of this field. On one branch neural decoding behaves like text, a shared model improves with every person added, and the economics look like software. On the other, every implant lands on different neurons and the code stays partly personal, so the decoder behaves like a hearing aid, fitted by a professional to each ear, and the economics look like a clinic. Today's evidence puts us on the second branch with a shared prior that shortens the fitting, and that mixture is what my bets assume. A result showing the error on new people falling steadily with the number of people in pretraining, with no floor in sight, would move me to the first branch and make the corpus thesis far stronger.
1Ye et al., A generalist intracortical motor decoder, NeurIPS 2025.
The rule of forgivable errors needs one more step to become an instrument. A neural function becomes a product only when a set of conditions holds at the same time, and since they are conditions that must all hold, the function lives in their intersection: the slowest of them sets the date. These are the permits, so called partly because they are what physics, the body and society have to grant, and partly because some of them are literally issued by an office. Written as a schedule, with TiT_iTi the time it takes to obtain each of the six and TspreadT_{\text{spread}}Tspread the time from the first paying user to many, the date a function reaches people is
T = maxi Ti + TspreadT \;=\; \max_{i}\,T_i \;+\; T_{\text{spread}}T=imaxTi+Tspread
and the maximum carries most of the argument: speeding up any permit but the slowest moves nothing, and a company that reports progress on a permit it already holds is reporting nothing about its date. Speeding up the slowest moves the date only until another permit becomes the slowest. If the two slowest take ten years and nine, cutting the first to five brings the function forward by one year, to nine, and the second bottleneck takes over. The clocks are also coupled (a durable implant yields more data, a reimbursed one reaches more patients and so yields more data again), so each TiT_iTi has to be estimated together with its dependencies on the others. The equation organises a calendar, and it predicts a date only once those times and dependencies have been estimated, which is what the rest of this text tries to do permit by permit.
OBSERVABILITYThe distinctions the function needs survive the path from tissue to sensor under the protocol actually used, through the bone or under it, at the depth, sampling rate and signal-to-noise ratio available. It is refused when two outcomes that matter produce recordings no decoder can tell apart.
DURABILITYThe interface keeps delivering the function for as long as it is needed, inside its heat budget and its risk of infection, with failures that can be detected and repaired without another operation. It is judged on the distribution of lifetimes across people, never on the best implant.
DATAEnough recordings exist, from the right people in the right conditions, to train the decoder, to fit it to a new user at a cost in that user's time they will accept, and to keep it fitted as the signal drifts. Volume without coverage does not grant it.
RECOVERABLE ERRORA wrong output is caught before it costs more than the function returns, the user can correct or stop it, and the system's own contribution (the prior, the agent) can be told apart from what the user meant. It tightens as the consequences of an output grow.
REIMBURSEMENTSomeone who captures enough of the benefit, measured against the best alternative, pays for the device, the procedure and years of maintenance, and keeps paying. A large social benefit with no buyer does not grant it.
LEGITIMACYThe law, the regulators and the people measured accept this use of this inference by this party, for this purpose, with a way to contest it. It is the only permit that can be granted before the others and withdrawn after them.
Language models had observability, durability and data for free when the input is text, before anyone wanted them (the text was already outside, already digital, already abundant), and they earned the recoverable-error permit task by task in the order described above. A brain interface has to earn every one of them, and an implant adds a cost that no language model ever charged: the operation is a harm paid in advance, before the first output, so the order of forgivable errors becomes an order of people, led by those for whom the function is worth a craniotomy. The rest of this text walks through them in turn, before using them in the section on the order of arrival to say what comes first and what it will look like.
Two learners, a shared geometry
In 2022 a group from Princeton and NYU played a thirty-minute podcast to nine people with epilepsy who had electrodes on the surface of the cortex for their surgery (electrocorticography), and compared what their cortex did around each word with what GPT-2 did around the same word1. The brains were guessing. Up to 800 milliseconds before a word began, the activity already carried information about which word was coming; once it arrived, the response grew with how surprised the model would have been; and the way each word was represented depended on the words before it, as a contextual embedding does in a transformer. Nobody had designed the model to resemble a brain, and the brain had never heard of transformers. Two systems built from different stuff and trained in entirely different ways on the same task, predicting the next word, had ended up carrying information that lines up word by word, and this is the fact about the field that pulled me into it before any of the economics did. What lines up is the content of their states, measured at the scale of a few millimetres of cortex and a few hundred milliseconds; whether the two arrive at that content by anything like the same means is a separate question, and the rest of this section tries to keep the two apart. It is also the section on the data permit, because it holds the one development that could make that permit much cheaper.
1Goldstein et al., Shared computational principles for language processing in humans and deep language models, Nature Neuroscience 25, 2022.
It is no longer one result. Across dozens of language models, Schrimpf and colleagues found that the better a model predicted the next word, the better its internal activity predicted human fMRI and ECoG responses to the same sentences, while skill at grammar or inference tasks predicted nothing; the best transformers accounted for nearly all the variance the noise of the recordings leaves explainable1. With 102 people in fMRI and MEG, Caucheteux and King found the same dependence on prediction2, and with 304 people they found that the brain forecasts further ahead than the models do: adding predictions of the word about eight positions on, some three seconds of speech, improved the fit, with frontal and parietal regions reaching furthest3. Vision got there first. In 2014 the top layer of a network trained only to recognise objects explained about half of the explainable responses of neurons in the monkey's inferior temporal cortex, roughly twice any earlier model4. And in 2024 a group at MIT argued that networks trained on different data and different senses drift, as they grow, toward the same geometry of distances between things, which they called the platonic representation5. It is a published research programme with conditions of its own: its formal argument holds for exact views of one world, and becomes harder for senses that are noisy, partial and carry different information. The temptation, which I feel, is to read the cortex as one more system on that path, the oldest of them and by far the cheapest to run. The manifesto does not rest on that reading. It rests on a narrower consequence that can be measured: if part of the structure a decoder has to interpret can be learned outside the head being measured, then fitting each person stops being the place where everything has to be learned. The web holds nobody's memories. It holds regularities that narrow the search for what a signal means, the way knowing how sentences usually go narrows the candidates without telling which one a person was trying to say. That consequence is the bet of this section, dated with the others at the end. The convergence behind it is partial (its authors say so in their titles), it is strongest exactly where the models are strongest, and it is measured with an instrument that deserves a closer look before anyone builds on it.
1Schrimpf et al., The neural architecture of language: integrative modeling converges on predictive processing, PNAS 118, 2021. 2Caucheteux and King, Brains and algorithms partially converge in natural language processing, Communications Biology 5, 2022. 3Caucheteux, Gramfort and King, Evidence of a predictive coding hierarchy in the human brain listening to speech, Nature Human Behaviour 7, 2023. 4Yamins et al., Performance-optimized hierarchical models predict neural responses in higher visual cortex, PNAS 111, 2014. 5Huh et al., The platonic representation hypothesis, ICML 2024.
The tool behind all of these papers is short enough to write down. An encoding model predicts the recorded activity from the representation a trained network computes for the same stimulus:
y=W ϕ(x)+ε\htmlData{sym=3}{y} = \htmlData{sym=2}{W}\,\htmlData{sym=1}{\phi(x)} + \htmlData{sym=4}{\varepsilon}y=Wϕ(x)+ε
xxxthe stimulus: a word in its context, an image, a sound ϕ(x)\phi(x)ϕ(x)the representation a pretrained network computes for it WWWa linear map, fitted for one person and one recording setup yyythe activity recorded from that person ε\varepsilonεwhat the map leaves unexplained
Decoding runs it backwards, searching for the stimulus whose representation best predicts what was recorded. The arithmetic puts the cost in two very unequal places. ϕ\phiϕ is the expensive factor, paid for once with a web of text or images and a data centre, and shared by everyone. WWW is the personal factor, and it is small enough to fit from hours of one person's recordings.
The same equation also says how little a good fit proves. In 1872 William Thomson, later Lord Kelvin, had a machine built of cranks, pulleys and a taut chain running over and under them, which added up ten periodic components and drew the tidal curve of a chosen port ahead of time, closely enough to plan ships by1. It contained no water and no moon; it worked because the tide really is a sum of periodic terms, and the machine had the right terms. A high encoding score is that kind of success. It shows that ϕ\phiϕ carries the features the cortex is sensitive to, in a form a linear map can reach, and it is silent about the circuits, the learning rule and the dynamics that produce them, which is to say about everything a mechanistic theory would have to state. The evidence that the gap is real is already in print. In the Schrimpf study, networks with random, untrained weights predicted brain activity nearly as well as some trained ones, so part of every score belongs to architecture and to the statistics of the words themselves. And when Antonello and Huth looked inside single models, the layers best at predicting the next word were worse models of the brain than layers that encoded a broader spread of linguistic features2. That result leaves the predictive account standing and questions whether a good fit is enough to prove it: training on prediction may discover features of language useful for many purposes, and those features would fit the brain whatever objective the brain itself optimises. The equation also limits what the word geometry can mean. WWW may stretch, compress or discard dimensions, so being able to predict one representation from the other does not mean that the two keep the same distances and the same neighbours; alignment is weaker than isometry, and a claim of shared geometry has to say which geometric properties were put to the test.
1Science Museum Group, William Thomson's tide predicting machine, 1872. 2Antonello and Huth, Predictive coding or just feature discovery? An alternative account of why language models fit brain data, Neurobiology of Language 5, 2024.
The caution runs the other way as well. A good fit explains less than a mechanism and far more than a coincidence (the tide machine predicted because it had the right terms), failing to identify a common algorithm proves nothing about whether the two share none, and some of the evidence goes well beyond a global fit. In 2024 the Princeton group recorded densely from the inferior frontal gyrus (the region around Broca's area) of three people listening to the same podcast and predicted the brain's pattern for each word left out of the fit from that word's relations to the other words in a language model's contextual space1, a test aimed at shared structure of relations, in one region, three people and one story. The same year Tuckute and colleagues used a GPT-based encoding model to choose new sentences that should drive or suppress the human language network, and the sentences did so in people the model had never seen2; the prediction came before the measurement, although what was manipulated was the sentence and never the circuit. And the 2023 fMRI decoder of the next section owes its content to the brain, because the same language model generating words without the recordings is what that study uses as chance: the prior supplies the fluency and the recording supplies what is said, even though no reconstructed word is a transcript of a thought. I will call what the field has established predictive alignment: two systems whose states share enough structure to forecast one from the other, sometimes on items the map never saw. Anticipation, sensitivity to surprise and the use of context are concrete candidates for principles the two have in common, and whether they come from equivalent learning objectives, from partly common algorithms or from different solutions that capture the same regularities of language is open. The value of predictive alignment for this manifesto is engineering value, since a decoder only needs a reliable map and can use one without settling that question. Its value for neuroscience is real and provisional, and the next step there is experiments built to tell those three explanations apart (a perturbation of the cortex itself that the model predicts before it is made, dynamics that match in time as well as in content, a lesion in the network that reproduces a lesion in the patient), of which very few exist yet.
1Goldstein et al., Alignment of brain embeddings and artificial contextual embeddings in natural language points to common geometric patterns, Nature Communications 15, 2024. 2Tuckute et al., Driving and suppressing the human language network using large language models, Nature Human Behaviour 8, 2024.
Predictive alignment is also the strongest objection to the first section of this manifesto, and it comes from my own trade. I wrote that there is no Common Crawl of neurons and that the corpus is the scarce thing. If cortex and models share enough of a geometry for a linear map to cross between them, the Common Crawl of text already pays for most of the decoder, and the neural corpus only has to pay for the map. Notice that the objection needs nothing more than the tide machine's kind of success: a decoder is indifferent to whether the brain computes the way a transformer does, provided the map holds. The evidence is arriving fast. MindEye2, pretrained on seven people of the Natural Scenes Dataset, used one hour of an eighth person's fMRI to pick the image they had seen among 300 candidates 79% of the time, against 99% with all forty of that person's hours1; a method presented in 2026 matched, from one hour, reconstructions trained on forty2; and Tang and Huth decoded the meaning of stories in a new person from about seventy minutes of that person watching silent films, beating decoders trained on less than two hours of the person's own story data3. It also gives the fork of the first section its exact form: the space is shared and the map is personal, and the price of a new user is the price of fitting a map.
1Scotti et al., MindEye2: shared-subject models enable fMRI-to-image with 1 hour of data, ICML 2024. The figure is for a defined retrieval task and says nothing about reading arbitrary mental images. 2Beliy et al., Brain-IT, ICLR 2026. 3Tang and Huth, Semantic language decoding across participants and stimulus modalities, Current Biology 35, 2025.
The same reasoning suggests where this will not hold, and of everything in this manifesto it is the guide I would most want beside me when deciding where to put money or years. Meaning and vision have a twin outside the body, billions of sentences and images from which a network learns a geometry that maps well onto that of cortex. The commands the motor cortex sends to a tongue or a hand have no web of their own, and neither do the fine textures of a mood or the signals from the body's interior. I will call this the twin heuristic: a brain function is cheap to decode roughly in proportion to how much of the world has already been written down in a representation that maps onto its own. It accounts for why NDT3, pretrained on motor recordings alone, found scale running out against the variability of sensors, and for why speech prostheses still learn their phonemes person by person and borrow the web only at the last stage, where phonemes become words. It also suggests the order in which non-invasive decoding will improve: meaning and images first, the intention to move later, fine internal states last. Coarse states such as sleep, fatigue or attention are cheap for a different reason, given in the next section (they are loud enough to cross the skull). The shared geometry has a less comfortable consequence too, which the section on the inferred person takes up: the alignment between people works because brains share a geometry with one another as well as with the models, and every result in this paragraph wears down the protection that today's decoders get from needing a person's cooperation.
I call it a heuristic on purpose, because it describes the present price list and the price list has been rewritten before. The heuristic prices only the prior, the knowledge a decoder brings to a new head, and says nothing about the signal, which the physics of the next section sets independently; the two multiply, and a change in either reorders the queue. A new way of listening (ultrasound fine enough to follow deep structures, magnetometers cheap enough to wear, an implant that records for a decade) could make a twinless signal so clean that it no longer needs a prior, the way the electron microscope made questions about cell structure easy that no amount of cleverness with light had cracked. And twins can be manufactured: simulations of muscles and joints, or millions of hours of video of hands at work, may yet give motor commands the external corpus they lack today. The heuristic will be worth keeping for as long as it keeps predicting which results arrive first, and the day an unexpected signal jumps the queue is the day to retire it.
What is established is a convergence of representations, partial and measured in particular regions, tasks and people, with a few candidate principles behind it; below that level everything is still open. A transformer and a cortex come to agree, to the precision of a linear map, on much of what is near what, and they differ in almost every visible respect of how they got there. The table below is the short list of differences that no encoding score can see.
Cortex A transformer
How it learns Local changes at synapses, gated by neuromodulators; how errors are assigned is an open question Backpropagation of one global error
When it learns All the time, while it acts In training; the weights are frozen in use
Activity Sparse spikes, under about one neuron in a hundred strongly active at once Dense activations in every layer
Power About 20 W for the whole brain Megawatts to train, hundreds of watts per accelerator to run
What it learns from One body's lifetime of experience Trillions of tokens written by other people
Two of those rows matter directly for the product. Learning while acting is why a decoder in use meets a second learner, the co-adaptation described in the section on the machine that finishes the sentence, and the absence of a single global error is why nobody can simply backpropagate through a person to tune an implant; how the brain solves its own credit assignment is still argued over1. The power row matters for the parallel run the other way. The brain works on about twenty watts2 and keeps fewer than one neuron in a hundred strongly active at a time because spikes are expensive3, which makes it the one working proof that this kind of intelligence fits in the energy budget of a light bulb. Here I am more sceptical than my own obsession would like. The last decade of machine learning came overwhelmingly from scale and engineering and borrowed little from neuroscience beyond its first metaphors, and where brain data has gone into models directly the effects have been modest: fine-tuning BERT on recordings made it predict the brain better, more than it made it better at language4. I expect neuroscience to serve machine learning in this decade as a measuring stick more than as a blueprint. The large labs already train models whose whole job is to predict the brain; the one that won the 2025 Algonauts challenge, among 262 teams, was a network from Meta built on top of a language, an audio and a video model5.
1Lillicrap et al., Backpropagation and the brain, Nature Reviews Neuroscience 21, 2020. 2Balasubramanian, Brain power, PNAS 118, 2021. 3Lennie, The cost of cortical computation, Current Biology 13, 2003. 4Schwartz, Toneva and Wehbe, Inducing brain-relevant bias in natural language processing models, NeurIPS 2019. 5d'Ascoli et al., TRIBE: trimodal brain encoder for whole-brain fMRI response prediction, 2025.
This is the second sense in which GPT-4 belongs in this manifesto, and the one I care about most. Its descendants are a component of the best decoders, and they are also the best predictive model of the organ being decoded that anyone has had: a model of what the cortex represents, with a few candidate principles of how it computes and no identified mechanism, much as a star chart predicts the sky without explaining fusion. Progress on either side now shows up on the other within months, and the rest of this text should be read with that in mind: every time it says the prior, it is talking about a geometry the brain and the machine share well enough to be useful, which is a weaker claim than sharing a computation and, for the purposes of building decoders, the only one the bets below depend on.
Through the bone
The comparison I hear most often for reading the brain from outside is a Bluetooth headset under water, and it is better than it sounds. Seawater conducts electricity, so a radio wave at the frequency of a headset dies within centimetres, and navies spent the twentieth century learning to talk to submarines anyway. They found three ways. They lowered the frequency until the wave could cross the sea, down to the extremely low frequencies of the American and Soviet transmitters, whose antennas were tens of kilometres long and whose rate was a few characters per minute1. They brought the antenna closer, with buoys and wires towed near the surface. And they changed the carrier, using sound, which travels in water far better than radio. Each is a trade, rate against distance against carrier, and readers of the brain have exactly the same three moves. Scalp EEG accepts a slow trickle of bits about broad states. Implants, the Stentrode in its vein and thin films under the bone bring the antenna close. Ultrasound, light and new magnetometers change the carrier. Where the analogy breaks is the sender. A submarine's transmitter was built by engineers with a known code, and the brain transmits nothing; we eavesdrop on a by-product of its computation and have to infer the code as we go. Getting a signal out of the head and having that signal distinguish what we care about are two problems, and progress on the first can leave the second untouched. Together they are the observability permit, and this section is about where it is granted and where it is refused.
1The American transmitters worked at 76 Hz and were shut down in 2004; see communication with submarines.
The carriers have been measured, and each fails in its own way. Near-infrared light gets in, but brain tissue scatters it every 25 to 200 µm (the reason penetration depth is the first number to ask of any optical method), so after a few millimetres a photon has forgotten where it came from, and fNIRS settles for changes in blood oxygen one and a half to two centimetres deep, which is scalp, bone and the surface of the cortex1. Ultrasound keeps its direction, and the skull eats it: across human samples about 8 mm thick the attenuation was 13.3 dB per centimetre2, so transcranial work stays near 1 MHz, where the wavelength in tissue is about a millimetre and a half. Decibels compound over thickness, I(d)=I0 10−αd/10I(d) = I_0,10^{-\alpha d/10}I(d)=I010−αd/10, so 8 mm of bone at that rate costs 10.6 dB one way, leaving about a twelfth of the intensity, and an imaging echo that has to come back pays twice, near 21 dB, some hundred and thirty times less. Functional ultrasound resolves 100 µm in a rat, and in an adult human it reached a few hundred micrometres only through a plastic window that had replaced a piece of skull after an injury3 (so the sensor was outside and the preparation was surgical, which is a reminder that where a device sits says little by itself about its risk). EEG and MEG listen to the brain's own fields, and their trouble is the ratio of signal to everything else: the brain's magnetic field at the sensor is between 10 and 1,000 femtotesla, against the Earth's 50 microtesla, and the skull smears the electric potential sideways like ink on wet paper. The sources are current dipoles, whose potential falls with the square of distance, V∝pcosθ/r2V \propto p\cos\theta / r^2V∝pcosθ/r2, so a source twice as deep arrives four times weaker before the skull has smeared it at all. Epilepsy surgery measured how large a patch has to fire together before the scalp notices. In simultaneous scalp and intracranial recordings, spikes covering less than 6 square centimetres of cortex never showed on the scalp, and those over 10 showed up nine times in ten4. Ten square centimetres of cortex hold tens of millions of neurons. What the scalp hears is the applause of a stadium, and the content of a thought is closer to the conversations in the stands.
1Marblestone et al., Physical principles for scalable neural recording, Frontiers in Computational Neuroscience, 2013; Pinti et al., The present and future use of functional near-infrared spectroscopy for cognitive neuroscience, Annals of the New York Academy of Sciences, 2020. 2Pinton et al., Attenuation, scattering, and absorption of ultrasound in the skull bone, Medical Physics 39, 2012. 3Rabut et al., Functional ultrasound imaging of human brain activity through an acoustically transparent cranial window, Science Translational Medicine 16, 2024. 4Tao et al., Intracranial EEG substrates of scalp EEG interictal spikes, Epilepsia 46, 2005.
0.00010.0010.010.11024681012bone thickness, mmintensity leftadult skullone wayecho, there and back1/12 at 8 mm1/130Ultrasound intensity left after bone, from the attenuation of 13.3 dB per centimetre measured by Pinton et al.: once through the skull, and as an echo that has to come back
Under all this sits a theorem, and it is easy to quote too broadly. Helmholtz showed in 1853 that infinitely many distributions of current inside a conductor produce the same field outside it, so the inverse problem of locating sources from scalp measurements has no unique answer1. In an earlier draft I called this the Theorem of Silence and concluded that no content of thought could ever be read from outside. The name was good and the conclusion was too large. Consider every brain state compatible with a given recording; that is a set, and a question we want to answer (does she want to say yes or no?) cuts the space of states into regions. If the compatible set straddles the border between yes and no, the recording cannot answer the question, whatever algorithm reads it. If the whole compatible set falls inside the yes region, the recording answers it, even though we remain ignorant of almost everything else about the state. In symbols, with hhh the map from a brain state to what the sensors record and ggg the property we want, the property is recoverable exactly when
1The result and its consequences for EEG and MEG are set out in Hämäläinen et al., Magnetoencephalography: theory, instrumentation, and applications to noninvasive studies of the working human brain, Reviews of Modern Physics 65, 1993.
h(s)=h(s′) ⟹ g(s)=g(s′)h(s) = h(s') \;\Longrightarrow\; g(s) = g(s')h(s)=h(s′)⟹g(s)=g(s′)
for every pair of states s,s′s, s's,s′, and then some decoder φ\varphiφ exists with g=φ∘hg = \varphi \circ hg=φ∘h. We never need to identify the whole state to recover a property of the state, and this is the distinction that control engineers draw between full observability of a system and the estimation of one variable of interest, which the literature on functional observability studies directly (when a chosen function of a system's state can be estimated without reconstructing the state)1. The condition is ideal identifiability, though. With noise, what also matters is how much the recordings of the two sides overlap, how much data there is and what an error costs, so two states that differ in principle can still be inseparable under the protocol at hand: the condition opens the right question and grants no permit by itself. Time helps too, since a sequence of observations combined with a model of how the system evolves can separate states that a single snapshot confuses. What survives of the theorem holds as firmly as physics allows, stated conditionally: when two possibilities that matter produce observations indistinguishable under a protocol, no algorithm that receives only those observations will separate them reliably. Adding a modality, observing for longer or bringing in outside information changes the problem. Adding a better model without adding evidence does not, and information theory says so in one line. With GGG the property sought, YYY the recording and CCC everything else the decoder brings (its training, its prior about language or images), any output G^\hat GG^ computed from YYY and CCC alone obeys I(G;G^∣C)≤I(G;Y∣C)I(G; \hat G \mid C) \le I(G; Y \mid C)I(G;G^∣C)≤I(G;Y∣C), where III is the mutual information, the number of bits one variable tells about another. This is the data processing inequality: the model can add knowledge of the world, and it cannot add evidence from this brain beyond what the recording carried. Here the language models enter for the first time, with a warning attached: a strong prior chooses, among the solutions compatible with the data, the one it expected, so the answer reports the prior as much as the brain.
1Montanari et al., Functional observability and target state estimation in large-scale networks, PNAS 119, 2022.
The recording cannot answersays yessays no5 say yes, 4 say noh(s) = h(s′) but g(s) ≠ g(s′)The recording answerssays yessays no9 say yes, none says noevery compatible state says yesa brain statecompatible, says yescompatible, says noborder of the questionThe same question asked of two recordings. Each blob is the set of brain states that would have produced the recording; the dashed line is the border of the question
The experiments of the last three years fit this picture closely. In 2023 an fMRI decoder at the University of Texas reconstructed the gist of stories that a person heard or imagined, after about sixteen hours of scanning for each person and with the person's full cooperation1. From three seconds of MEG, a model trained on 175 volunteers placed the right segment of speech among its top ten out of more than a thousand candidates up to four times in ten2. And in June 2026 Meta's group published the decoding of sentences that 35 volunteers were typing, on sentences the model had never seen, with about three characters wrong in ten from MEG and about two in three from EEG3. These results are solid inside their conditions and say little outside them: cooperative participants, a constrained task, sometimes a closed set of candidates. Together they dissolve a border that I used to think was physical, the one between reading states (sleep, attention, fatigue) and reading contents. That border is a property of the task. My forecast is that until 2035 external readers will deliver broad states robustly and cheaply, constrained contents in cooperative laboratory settings, and no open reading of spontaneous inner speech in daily life. The last part of that sentence is the one that reassures people, and it should not, because control does not require sentences. In 2012 a consumer headset watching the brain's responses to pictures of bank cards and digits reduced the uncertainty about a user's PIN, bank and home area by 15 to 40% compared with guessing4. A crude reader is already enough to cause harm, which is why the observability permit, generous for the shallow uses and stingy for the deep ones, will put the first conflicts of this industry on the consumer side.
1Tang et al., Semantic reconstruction of continuous language from non-invasive brain recordings, Nature Neuroscience 26, 2023. 2Défossez et al., Decoding speech perception from non-invasive brain recordings, Nature Machine Intelligence 5, 2023. 3Lévy et al., Noninvasive decoding of typed sentences from human brain activity, Nature Neuroscience, 2026, which reports a character error rate of 29% with MEG and 65% with EEG. 4Martinovic et al., On the feasibility of side-channel attacks with brain-computer interfaces, USENIX Security 2012.
Ultrasound needs a paragraph of its own, because the word covers four technologies running on four calendars. The first reads: functional ultrasound follows blood flow, and through a window in the skull of two macaques it decoded the direction of a planned movement before the movement began, then drove up to eight directions in closed loop with a decoder pretrained on earlier sessions that worked from the start of the next day1. Its resolution is set by the wavelength, λ=c/f\lambda = c/fλ=c/f, with sound at about 1,540 m/s in soft tissue: 3.1 mm at 0.5 MHz, a frequency the skull lets through, and 0.31 mm at 5 MHz, one it does not, which is why every human result so far has come through a replaced piece of bone. The second writes. Focused at low intensity, ultrasound can nudge a deep structure without opening anything, and in Toronto in 2025 it was aimed through the intact skull at the globus pallidus of ten people who already carried deep brain stimulation leads there, so the effect could be recorded at the target itself rather than inferred from the scalp2; an international consortium has published the exposures under which it considers the biophysical risk not significant (a mechanical index up to 1.9, a temperature rise of at most 2 °C)3. The third and fourth are further out: implants the size of dust grains, powered and read by sound, shown in the peripheral nerve of a rat in 20164, and molecular reporters that would make chosen cells answer to sound, the horizon Merge Labs gives in decades. The asymmetry between the first two is the useful part. A stimulator has to deliver known energy to a known target, a reader has to recover fine distinctions from an echo the bone has cut more than a hundredfold, and so ultrasound will change how the deep brain is stimulated long before it changes how the brain is read.
1Norman et al., Single-trial decoding of movement intentions using functional ultrasound neuroimaging, Neuron 109, 2021; Griggs et al., Decoding motor plans using a closed-loop ultrasonic brain-machine interface, Nature Neuroscience 27, 2024. 2Darmani et al., Individualized non-invasive deep brain stimulation of the basal ganglia using transcranial ultrasound stimulation, Nature Communications 16, 2025, with fifteen healthy participants beside the ten patients. 3ITRUSST, Consensus on biophysical safety for transcranial ultrasound stimulation, Brain Stimulation, 2025, which presents these as levels of non-significant risk and explicitly not as safety limits. 4Seo et al., Wireless recording in the peripheral nervous system with ultrasonic neural dust, Neuron 91, 2016.
Under the bone, where the barrier is made of days
Going in grants the observability permit and puts the durability permit in its place, which is biology and plumbing. An electrode in the cortex hears few neurons beyond about 100 µm and none beyond 1601, so each channel is a keyhole onto a brain of some 86 billion neurons2. Nobody needs all of them. Harrell's voice came from 256 keyholes in one gyrus, and that number is the clearest measure I know of how small sufficient access can be when the function is chosen well. The trouble starts afterwards, on the days that follow the operation, because the tissue treats the device as what it is, a foreign body. Astrocytes and microglia begin to wrap an implanted array within weeks and the sheath can persist for years3; in Neuralink's first participant a number of the N1's threads retracted in the weeks after surgery and the working electrode count fell until the decoder was retuned4. The common story that the scar silences the electrodes is too simple, though. When a group at Brown catalogued what happened to 78 Utah arrays (the arrays Blackrock Neurotech makes, and the kind in Harrell's head) in 27 macaques, more than half had failed within a year (the mean time to failure was 332 days), and the largest share of failures was mechanical, mostly connectors, with biological causes at about a quarter and the slow loss of insulation driving the long decline5. The classification travels better than the numbers, since these were macaques carrying arrays of more than a decade ago, and their lifetimes forecast nothing about a human product today. A durable product needs the whole system to survive, and what an investor or a patient should want to see is the distribution of lifetimes across many people (how long the function lasts, how it degrades, what can be done afterwards) rather than the best implant in the best participant. In ten years the companies in this field will be ranked by useful function delivered per year of maintenance they impose, and the count of channels will matter only to the extent that it moves that ratio.
1Marblestone et al., 2013, cited above, from recordings with multi-site silicon probes. 2Azevedo et al., Equal numbers of neuronal and nonneuronal cells make the human brain an isometrically scaled-up primate brain, Journal of Comparative Neurology 513, 2009. 3Salatino et al., Glial responses to implanted electrodes in the brain, Nature Biomedical Engineering 1, 2017. 4CNBC, Neuralink's first in-human brain implant has experienced a problem, 8 May 2024. 5Barrese et al., Failure mode analysis of silicon-based intracortical microelectrode arrays in non-human primates, Journal of Neural Engineering 10, 2013, which sorts failures into biological, material, mechanical and unknown.
There is a reading of those macaque numbers that a reliability engineer would make at once. Failures over time follow the shape the trade calls the bathtub curve: an early stretch where defects of manufacture and assembly kill units quickly, a long flat middle of random failures, and a late rise of wear-out. Barrese's arrays died mostly in the first stretch and mostly of connectors, which are the part of a system with a plug through the scalp that a fully implanted wireless device removes (the N1 and the Connexus send their data by radio through the skin), and early mechanical mortality is the kind of failure that industry knows how to drive down with design, burn-in and process control. Once the connectors are gone, what remains are the two slow failures, the tissue closing in and the insulation yielding to years of warm salt water, and they are the ones that decide the business, because they can only be measured by waiting. I expect the hermetic package, more than the electrode tip, to set the lifetime of the next generation of implants.
The other way to make tissue tolerate a device is to make the device less of a body. A strip bends with a stiffness that grows with the cube of its thickness (for a plate, D=Et3/12(1−ν2)D = E t^3 / 12(1-\nu^2)D=Et3/12(1−ν2)), so a film ten times thinner is a thousand times more compliant, and a brain that shifts by micrometres with every heartbeat and breath pulls far less against it. That cube is the engineering under Precision's Layer 7, 1,024 electrodes on a film thinner than a hair, laid on the cortical surface without piercing it and cleared by the FDA in April 2025 for implantation of up to thirty days1. The thirty days are the half of that sentence that matters: they grant the durability permit for mapping during surgery and short monitoring, and a chronic device still has to earn the rest by waiting. The vein is the third route, with the opposite trade. In Synchron's first trial four people with severe paralysis carried a stent of electrodes in the large vein that runs over the motor cortex for twelve months with no serious adverse event attributed to the device and a signal that held steady2, and what they did with it was texting, email and shopping through a few clean switches, which is what a signal heard through a vessel wall can carry and about as far as it goes. Each route is a different point on the same curve of access against injury, and I expect all three to survive, sorted by function, because none dominates the others on both axes. Manufacturing has a curve of its own. A device that works only if eight stages of fabrication and assembly all work keeps 0.988≈85%0.98^8 \approx 85%0.988≈85% of its units when each stage yields 98%, and 0.98≈43%0.9^8 \approx 43%0.98≈43% when each yields 90%, so a modest gain at every step doubles the output of a line. That arithmetic, more than any record in a paper, decides who can implant thousands of people.
1Precision Neuroscience, FDA clearance for a high-resolution cortical electrode array, 17 April 2025, a 510(k) for recording, monitoring and stimulation. 2Mitchell et al., Assessment of safety of a fully implanted endovascular brain-computer interface for severe paralysis in 4 patients: the SWITCH study, JAMA Neurology 80, 2023.
When a deployed interface starts to perform worse, there are at least four suspects, and telling them apart is a problem I know from plants whose internal state is only partly measured. The hardware can be failing (an electrode's impedance rising, a channel shorting). The tissue can be closing around the array, so that fewer neurons are heard. The decoder can have drifted away from a signal that changed underneath it. And the person can have changed, through fatigue, a new mental strategy or, in a degenerative disease, the progression of the disease itself. Each suspect leaves a different signature if the system is built to show it: impedance tests speak for the hardware, the number and shape of the recorded units for the tissue, a decoder re-evaluated on a fixed reference task separates drift from the rest, and what is left points at the person. This is fault diagnosis in the strict sense, a question of detectability and isolability, and the condition for isolating one fault from another is redundancy in what is measured. An implant without self-tests cannot tell its user why it is failing, and a company that cannot tell why cannot fix it from a distance. The continuity business will belong to whoever can diagnose an implant remotely, and that is a property designed into the hardware on the first day, since it cannot be added afterwards.
Heat is the second budget, and here a little arithmetic helps. The raw rate of a recording is an identity of engineering, R=N⋅fs⋅bR = N \cdot f_s \cdot bR=N⋅fs⋅b, the number of channels times the sampling rate times the bits per sample: a thousand channels at 30 kHz and 10 bits give 300 megabits per second. That number measures data, and the information about intention inside it is far smaller, since neighbouring channels are redundant and most of the bandwidth carries noise or detail the function never uses. Pushing raw data through a radio would cost more power than an implant can spend (the serialiser alone for a few hundred megabits per second runs above 80 milliwatts1), in an organ that runs on about fifteen watts in total and tolerates local warming of a degree or two over hours (the implant's heat budget). So designs compress near the sensor, detect spikes on the chip and send the events. It does not follow that the whole decoder will move into the skull, because computing also produces heat and a processor outside the head can be updated and replaced without surgery. I expect hybrid architectures to dominate (selection and compression next to the electrodes, heavier models in a device worn outside, network services only when needed). There is a quiet consequence that links engineering to privacy: what an implant discards irreversibly can never be reanalysed by a better model later, for science or for anyone else. Choosing what to keep is choosing which future questions stay open, and a design that sends only the decoded intention is, among other things, a privacy design.
1He et al., An event-based neural compressive telemetry with >11× loss-less data reduction for high-bandwidth intracortical brain computer interfaces, IEEE Transactions on Biomedical Circuits and Systems, 2024.
Then comes the part that no datasheet covers. In 2019 the company that made the Argus II retinal implant stopped producing it, and the next year it nearly closed; more than 350 people were left with electrodes on their retinas and nobody to repair them, replace parts or tell their surgeons how to work around the hardware1. That situation gives a supplier a power software never had: changing provider, for an implant, means risking a capability that has become part of a life, and no software lock-in comes close to that. A recurring fee can pay for maintenance that is valuable, and the same relationship concentrates power over the user. The solvency of the maker, the possibility of migrating to another system and what happens to the device if the company disappears should be part of the product from the day of the operation, because a company able to implant and unable to guarantee an exit is transferring part of its business risk into its patient's head.
1IEEE Spectrum, Their bionic eyes are now obsolete and unsupported, February 2022.
Underneath the device there is the tissue as biology describes it. Electrical signals in the brain are movements of ions across membranes, the strength of a synapse depends on chemistry that a voltage recording does not see, and the structure itself changes; microtubules, the scaffolding inside cells, have been tied experimentally to the shape of dendritic spines and to plasticity1. The proposal that they host quantum processes underlying consciousness is a speculation, with no role I can find in any decoder that works. Harrell's prosthesis settles a narrower question: for that function, in that person, the variables a few hundred electrodes measure were sufficient, which says nothing about whether the omitted ones matter for stability, disease or experience. The maps advance on another front. The FlyWire connectome traced every neuron and connection of an adult fruit fly's brain, about 140,000 neurons and some fifty million synapses2; the MICrONS consortium mapped one cubic millimetre of mouse cortex with its activity recorded beforehand3; light-sheet microscopes such as those built by the mesoSPIM initiative and used at the Wyss Center in Geneva image whole cleared brains with cellular detail4. A wiring diagram tells you where traffic can flow and holds none of the journeys, and these are slow, magnificent, post-mortem or animal instruments. Their effect on the industry will arrive as better priors about circuits, which is to say through the data permit, decades before anything they image becomes a product.
1Jaworski et al., Dynamic microtubules regulate dendritic spine morphology and synaptic plasticity, Neuron 61, 2009. 2Dorkenwald et al., Neuronal wiring diagram of an adult brain, Nature 634, 2024. 3MICrONS Consortium, Functional connectomics spanning multiple areas of mouse visual cortex, Nature 640, 2025. 4Wyss Center, Wyss Center microscope reveals brain circuit reorganisation.
The machine that finishes the sentence
This section is about the recoverable-error permit as it lives inside the decoder: who wrote an output, whether a wrong one can be stopped before it acts, and what changes when a second learner sits in the loop. Most speech neuroprostheses combine evidence from neurons with knowledge of language, and the logic fits in one line of Bayes:
P(w∣x,c) ∝ P(x∣w,c) P(w∣c)P(\htmlData{sym=0}{w} \mid \htmlData{sym=1}{x}, \htmlData{sym=2}{c}) \;\propto\; P(\htmlData{sym=1}{x} \mid \htmlData{sym=0}{w}, \htmlData{sym=2}{c})\,P(\htmlData{sym=0}{w} \mid \htmlData{sym=2}{c})P(w∣x,c)∝P(x∣w,c)P(w∣c)
wwwa candidate sentence xxxthe recorded neural signal cccthe context (the conversation so far, the task, the screen)
The first factor says how well the recorded activity fits a candidate sentence. The second is the prior, how expected that sentence was before this signal was seen.
The rule is the one in Bayes's essay of 1763, and Turing used it at Bletchley Park as a scale for the weight of evidence, adding up what intercepted letters said against the statistics of German in units he called decibans. The principle has not changed: you do not decipher a message letter by letter, you let the probability of the language prune the possibilities. That is why the jump from two letters a minute in 2016 to conversation in 2024 was so steep1. Over those eight years the electrodes improved modestly and the prior enormously, carried in by the same language models that made 2023 famous. Inside a working decoder the prior is a pipeline, and its shape matters for everything that follows. In Harrell's system a recurrent network turns the activity of 256 electrodes into probabilities for each phoneme, a five-gram model of English searches for the sentences those phonemes could spell, and a general-purpose language model with 6.7 billion parameters re-ranks the candidates, all in real time2. The last component of the most accurate speech prosthesis in the literature is therefore a model trained on the web, which knows nothing about the patient and has firm opinions about what people usually say, and that is precisely where authorship gets decided. A better prior can help recover what a person meant, and no law says that improving the model must reduce fidelity. No law guarantees authorship either because the output sounds natural. I do not want that treatment is less expected than I want that treatment in many hospital contexts, and the word a decoder treats as an anomaly can be exactly the word that most needs to survive. I will call the obligation this creates the authorship debt: whoever sells a decoder that leans on a prior owes proof that the prior is not quietly substituting for the person.
1Vansteensel et al., Fully implanted brain-computer interface in a locked-in patient with ALS, NEJM 375, 2016. 2Card et al., 2024, cited above; the pipeline is documented in the group's published code. The 2023 Stanford system ran the first two stages live and added the large model only in its offline analysis: Willett et al., A high-performance speech neuroprosthesis, Nature 620, 2023.
Drawn on one axis, the record of the decade shows the speed and what was paid for it. The two fastest systems of 2023 got roughly one word in four wrong; the UC Davis system a year later ran at half their speed and got one word in forty wrong; and the only point measured in a life, two years at home, sits between them on speed with the accuracy of the second. A rate in words per minute quoted without its error rate describes half of a trade.
110100201620182020202220242026wpmtyping on a phone, 36 wpmspoken conversation, about 150 wpmECoG, clicksVansteensel · 2 letters/minCursor typingPandarinath · 39 char/minHandwritingWillett · 94% rawSpeech, Utah arraysWillett · 24% WERSpeech, ECoGMetzger · 26% WERConversationCard · 2.5% WERHome, 2 yearsCard · 99% in testslaboratory sessionhome useCommunication rate through implanted interfaces, 2016 to 2026. Words per minute on a logarithmic scale; WER is the word error rate. Sources in the text.
Asking what percentage of a sentence belongs to the user pays nothing on that debt, because the two contributions do not separate like two inks on a page. Experiments pay it, and they are easy to name: run the same system with the context and without the neural signal, and see how much it still says; shuffle the correspondence between signal and sentence; test on days the model never trained on, on new names, on negations; count the words that came out when the person wanted silence; measure how much it costs to correct an error before it has consequences. A grotesque noise fed into the decoder proves only that it was never trained for grotesque noise, so the comparison has to isolate the signal's contribution in conditions that matter. And the measure sold to buyers should be richer than words per minute: how many words were right, how many had to be corrected, how much effort the correction took, and whether any word acted in the world before it could be stopped. Fluency is a property of the text, while autonomy is a property of the relation between the text and the person who emits it, and a metric of the first says nothing about the second. Two ordinary sins of machine learning wait in this field's numbers. Sessions of one person split between training and test inflate accuracy as leakage does anywhere, and words per minute, once companies race on it, will drift away from what it was chosen to measure, which is Goodhart's warning applied to a voice.
Inner speech sharpens all of this. In 2025 a Stanford group decoded imagined speech from intracortical arrays and, in the same paper, tested ways to keep it from leaking out, including a phrase the user had to imagine before the decoder would transcribe anything (they chose chitty chitty bang bang, and the system recognised it more than 98% of the time)1. That result does not show continuous access to anyone's private monologue, and it does show that the border between what is thought and what is said has to be designed, because the decoder's current clumsiness will not keep guarding it. A perfectly accurate reading of something the person did not want to communicate is, for a communication prosthesis, a failed output. The intention to formulate a sentence and the intention to hand it to someone are different variables, and only the second one is the product.
1Kunz et al., Inner speech in motor cortex and implications for speech neuroprostheses, Cell, 2025.
There is a second learner in the loop (decoder co-adaptation), and the field found it with cursors long before speech. The first BrainGate cursors for people with tetraplegia were decoded with a Kalman filter in 20081, a model in which the intended velocity xtx_txt drifts smoothly and the firing rates yty_tyt are a noisy linear reading of it, xt=Axt−1+wtx_t = A x_{t-1} + w_txt=Axt−1+wt and yt=Hxt+qty_t = H x_t + q_tyt=Hxt+qt, and in 2012 a Stanford group roughly halved the time monkeys took to reach targets by retraining the filter during closed-loop use on what the animal intended, assuming at each moment that it wanted to go toward the target2. Two years later a Berkeley group showed that adapting the decoder while the brain adapted to it produced a skill that held across days, carried by neurons that had changed their tuning for the task3, and decoders that differed a lot offline performed alike in closed loop, because the subject compensated for their biases4. For anyone who trains models for a living the consequences are uncomfortable. Accuracy on a recorded dataset is a weak predictor of the product, because the product is a coupled system of two learners and the human one has the better learning rule. And a decoder update is an intervention on a skill the user has built around the old decoder, so I would release it with the controls of a change in treatment: a reference evaluation before and after, the right to roll back, a record of what changed and why. In a degenerative disease the biological side of the coupling moves too. The woman with ALS who typed two letters a minute in 2016 kept using her interface at home for seven years, and its high-frequency signal faded as the disease advanced until the system stopped working5; the intracortical speech systems have not run long enough to say how they will age. Credit assignment, the problem of deciding which part of a learning system caused an error, becomes in this setting a question of liability as much as of learning.
1Kim et al., Neural control of computer cursor velocity by decoding motor cortical spiking activity in humans with tetraplegia, Journal of Neural Engineering 5. 2Gilja et al., A high-performance neural prosthesis enabled by control algorithm design, Nature Neuroscience 15, 2012. 3Orsborn et al., Closed-loop decoder adaptation shapes neural plasticity for skillful neuroprosthetic control, Neuron 82, 2014. 4Koyama et al., Comparison of brain-computer interface decoding algorithms in open-loop and closed-loop control, Journal of Computational Neuroscience 29, 2010. 5Vansteensel et al., seven-year follow-up of the same participant, NEJM 391, 2024.
The language models do something else to this industry, which I think is its most underrated economic fact. The same model that lets a poor neural signal drive a powerful tool also improves the predictive keyboard, the voice assistant, the eye tracker and the muscle sensor. In 2025 Meta published a wristband that reads the electrical activity of forearm muscles (surface electromyography) and turns it into handwriting, gestures and pointing, with models that worked on people they had not been trained on, writing at 20.9 words a minute out of the box1, and that September the band went on sale in American shops with Meta's display glasses, for 799 dollars the pair. A reader of motor intention was on a shop shelf six months before the first implant that reads the brain was registered for sale. It reads motor commands where they reach the wrist, far from the skull and from anything resembling a thought, and wherever that peripheral route survives it competes with every implant. I will call this the peripheral shortcut, and it cuts the market for brain implants along the line of each user's remaining abilities. It is a comparator and never a universal substitute: for someone who keeps a usable muscular route the comparison includes it, and for someone who has lost that route the choice lies elsewhere. AI will raise the clinical usefulness of implants and, with the same stroke, push back the day a healthy person has any reason to want one, and there is no contradiction in that, because the technology improves both terms of the comparison a buyer makes. What decides is the relative improvement and the benefit it adds for each population, so an implant has to justify the extra cost of its route against the routes actually open to that person, and I will not infer adoption from the mere fact that implants get better every year.
1Kaifosh et al., A generic non-invasive neuromotor interface for human-computer interaction, Nature 645, 2025, which reports a further 16% gain in handwriting from personalising the model.
Agents push the same logic one step further. If a short instruction can launch a long task, the value of bandwidth falls and the value of reliable authorisation rises: the scarce channel shifts from steering every movement to stating goals, resolving ambiguities and stopping actions. In that arrangement a dependable mental no can be worth more than a new record in words per minute, and the standard measure of a selection interface, the information transfer rate, shows part of why. With NNN equally likely options chosen with accuracy PPP, each selection carries
B=log2N+Plog2P+(1−P)log21−PN−1B = \log_2 N + P \log_2 P + (1-P)\log_2 \frac{1-P}{N-1}B=log2N+Plog2P+(1−P)log2N−11−P
bits1. A yes or no that is right ninety-five times in a hundred carries 0.71 bits, and at ninety-nine in a hundred 0.92. That last fifth of a bit is bought entirely with accuracy. The formula also assumes that every option is equally likely and every error equally spread, which real interfaces break2, and the break matters most where a no matters most. If ninety-nine requests in a hundred deserve a yes, a system that always says yes is 99% accurate and misses every veto (the trap of class imbalance). The bits measure the channel and say nothing, by themselves, about whether delegating through it is safe. What an agent needs from its user is an effective way to select, correct and stop, measured in false authorisations, ignored vetoes, the time a stop takes to land and whether the consequences of an error can be undone. The cost of an error grows in the same proportion, since the more an agent does per instruction, the further a misread instruction travels before anyone notices, and the authorship debt turns into a straightforward economic variable. If the supervision needed to trust the system eats the gain, the capability exists and the product does not.
1Wolpaw et al., Brain-computer interfaces for communication and control, Clinical Neurophysiology 113, 2002. 2Thompson et al., Performance measurement for brain-computer or brain-machine interfaces: a tutorial, Journal of Neural Engineering 11, 2014, which also finds that the rate tracks poorly with what users achieve.
01234550%60%70%80%90%100%accuracybits per selectionyes or no4 choices26 letters0.710.92Bits per selection against accuracy, from the formula above. The last points of accuracy carry most of a binary choice, and every point carries more as the options grow
What the money sees
This section is about the reimbursement permit, and it starts where the comparison with GPT-4 is strongest. GPT-4 mattered economically because its capability was reusable: one trained model, reached through an interface any developer could call, became the engine of thousands of products that did not have to train anything themselves. A brain interface that outputs text, a selection or a cursor is reusable in the same sense, since it plugs into email, documents and every tool already built for keyboards; it does not need to conquer the brain, only one entry point into the digital world. The divergence is in the cost of the next user. Serving one more request to a language model costs compute; adding one more user to an implanted platform costs an operation, a reproducible device, a surgeon trained to place it and a clinical relationship that has to continue for years. There is no reason to expect the two adoption curves to have the same shape, and the pace of the second is set by its slowest link (surgeons, payers and regulators move on their own clocks, whatever the decoder does).
The usual way of sizing this market is to multiply the number of people with a neurological condition by an imagined price, and it is wrong in a way that matters. A market is an intersection of sets. Of everyone who might benefit, keep those for whom the function is useful, then those for whom the device is suitable, then those for whom it beats the alternatives, then those who can reach the procedure, then those whose care someone pays for, then those for whom the benefit survives the maintenance. Each filter can be large or tiny, and what a company can sell is the population times the product of the pass rates, Nmarket=N∏i=16piN_{\text{market}} = N \prod_{i=1}^{6} p_iNmarket=N∏i=16pi, where each pip_ipi is the share that passes a filter among those who passed the ones before it, and a single pip_ipi near zero closes the market however large NNN is. Multiplied as if the filters were independent of each other, the same percentages would mean nothing. A criterion for the third filter fits in one expression:
ΔV = E[U(oI)] − E[U(oA)] − C\Delta V \;=\; \mathbb{E}\big[\htmlData{sym=2}{U}(\htmlData{sym=0}{o_I})\big] \;-\; \mathbb{E}\big[\htmlData{sym=2}{U}(\htmlData{sym=1}{o_A})\big] \;-\; \htmlData{sym=3}{C}ΔV=E[U(oI)]−E[U(oA)]−C
oIo_IoIthe outcome with the interface oAo_AoAthe outcome with the best alternative UUUthe value of an outcome to whoever is doing the evaluation CCCcosts and risks not already counted inside the outcomes
It is a comparison of expected utility with no secret coefficients, and its use is the questions it forces. Value to whom: the patient, the family, the hospital, the insurer? Who keeps the saving, who advances the money, who bears a failure? A large social benefit can find no buyer whose incentives are aligned to fund it, and a small one can sell well if the buyer gains something it values, even when the gain does not fall on the person being measured. A transaction proves that someone paid; it certifies nothing about the usefulness of what was bought.
The best precedent I know for the reimbursement permit is the cochlear implant, which is a neural interface by any definition that counts electrodes: an electrode array that writes into the auditory nerve. The FDA approved the first one in 1984 and the first multichannel device for adults in 1985, and the millionth device was implanted around 20221. Four decades, for a device with a modest number of electrodes, a routine operation and an established route to reimbursement. The lesson I take is Amara's, that we overestimate a technology in the short run and underestimate it in the long run, with one correction: the long run here is set by institutions that learn slowly, and an implant that writes speech into a cortex will cross the same institutions. There is a second, less noticed lesson. The reading economy already exists, quietly, inside epilepsy and Parkinson's. A responsive neurostimulator made by NeuroPace and approved for epilepsy in 2013 records the brain's activity continuously and fires when it sees a seizure starting, and in February 2025 the FDA approved adaptive deep brain stimulation for Parkinson's, which adjusts its current from the activity it records2. Nobody calls those patients users of a brain-computer interface, and they are the first customers of exactly the economy this text is about. The first companies paid at scale to read the human brain are the ones already paid to stimulate it, and I expect incumbents of that kind to absorb a large share of the field's value, through acquisitions and partnerships, more than the companies with the most celebrated demonstrations. The first commercial sale of an implant that reads the brain to drive a device came from none of the famous names, and from no American company. On 13 March 2026 China's medical products administration registered NEO, made by Neuracle with Tsinghua University: eight contacts laid on the dura, under the skull and outside the brain itself, decoding the attempt to grasp and driving a pneumatic glove for adults with cervical spinal cord injury, approved on evidence from 36 implanted people followed for eighteen months with no serious adverse event attributed to the device3. Eight contacts is almost nothing next to a thousand threads, and it was enough for one function that someone was willing to pay for. That is sufficient access in its purest form, and a warning to anyone who ranks this industry by channel count or by the nationality of its press releases.
1Zeng, Celebrating the one millionth cochlear implant, JASA Express Letters 2, 2022. 2Medtronic, FDA approval for the world's first adaptive deep brain stimulation system, 24 February 2025. 3CGTN, China approves world's first invasive BCI medical device, 13 March 2026; trade newsletters report the first commercial implants from July 2026 at around seventy thousand dollars each.
The supply chain points the same way. Between a laboratory result and daily life sit reproducible manufacturing, hermetic packaging that keeps body fluids away from electronics for decades, electrodes, chips, sterilisation, software, surgical training, calibration, support and follow-up, and the FDA's guidance for implanted interfaces makes clear that evaluating such a system takes far more than a good decoding score1. I expect a decisive part of the value to settle on whoever guarantees continuity: makers of components that are hard to replace, clinical networks, and a kind of organisation that does not quite exist yet, whose business is to keep the relation between a person and a device working when the tissue, the hardware, the person and the company all change. That is an inference about business, and I hold it with moderate confidence.
1US FDA, Implanted brain-computer interface devices for patients with paralysis or amputation: non-clinical and clinical considerations, 2021.
Capital is arriving before these conditions are met, and that is rational. Neuralink raised 650 million dollars in June 2025, Synchron 200 million in November 2025 for a pivotal trial, Science Corporation 230 million in March 2026 and Precision 250 million in September 20261, and the comparison with GPT-4 stopped being a metaphor in January 2026, when OpenAI led a 252 million dollar seed round in Merge Labs, a company betting on ultrasound and molecular interfaces with a horizon its founders put in decades, which in September licensed Butterfly Network's ultrasound-on-chip2. The artificial intelligence industry spent years absorbing investment on the strength of a promise of high capability while most of its companies lost money, and the promise alone kept the capital coming. The same logic applies here, with a difference in what the money buys. Funding buys the right to try to close an uncertainty, and it certifies nothing about whether the uncertainty is closed. I expect real technical progress alongside companies that fail to capture enough value, and I reject both readings that the market will push: each funding round taken as evidence of biological feasibility, each bankruptcy taken as a refutation of the technology. Those are connected questions with different answers.
1Bloomberg, Neuralink raises 650 million in late-stage funding round, 2 June 2025; Synchron, COMMAND results and financing; TechCrunch, Science Corp closes 230M round, 5 March 2026; MassDevice, Precision Neuroscience raises 250M, September 2026. 2MobiHealthNews, Butterfly Network and Merge Labs partner on ultrasound brain-computer interfaces, September 2026; Merge, founding statement.
The rounds also bet on three different theses, which are easy to confuse because the press releases read alike. A medical thesis wants an indication, a code and a service line, and will be judged on patients treated and kept. A platform thesis wants a general device on which many functions will be sold later, and is valued on buyers who do not exist yet. An infrastructure thesis sells what every implant needs (thin films, hermetic feedthroughs, ultrasound on a chip, clinical software) and lives on the volume of the others, which makes it the least glamorous and, I suspect, the most likely to be profitable within the decade. Whichever thesis wins, the volume will be set by the narrower of two pipes, Q=min(D,K)Q = \min(D, K)Q=min(D,K), the patients who are eligible and funded against the capacity to deliver, and capacity is the pipe nobody models. A hundred centres each implanting one person every working day would manage about 25,000 new implants a year, which sits in the middle of the range I find plausible for 2035 (between ten and fifty thousand implants a year, an estimate of mine with no source behind it but this arithmetic), so reaching it means training surgeons, teams and support long before demand is proven. That figure is a flow and never a count of users, and every person implanted keeps drawing on the same teams for follow-up, so a plan that spends all its clinical hours on new implants and none on the people already implanted overstates the growth it can sustain. And the device is the smaller part of the bill. An hour a day of a technician's or a carer's help at fifty euros costs 18,250 euros a year, every year, so a system that saves that hour repays an implant at NEO's price in three or four years, and one that adds it never repays at all. The figure I would ask a buyer to compare is the total cost per hour of useful autonomy: device, surgery, maintenance and support, divided by the hours the person spends doing what they chose without help. An hour of use is not automatically an hour of added autonomy (five minutes to state a decision that matters can be worth more than an afternoon of routine), so the figure means something only when it names the function, the comparator and the work it moved or saved, and it prices a service without claiming to price a life. It is the buyer's side of the ratio I gave for ranking companies, function delivered per year of maintenance, and it is the number a payer will eventually demand.
How much will AI itself accelerate the field? Here an old formula from computing, Amdahl's law, is useful, provided it stays a tool and does not become an authority. If a fraction fff of a process is sped up by a factor sss and the rest is unchanged, the whole goes faster by
S = 1(1−f)+f/sS \;=\; \frac{1}{(1-f) + f/s}S=(1−f)+f/s1
and the force of the result is in its condition, that the rest stays the same1. In neurotechnology a model can write analysis code, design experiments and reuse knowledge across patients, and the time it takes to watch an implant survive five years in a person is still five years. The evidence on AI productivity itself argues for care: a randomised trial by METR in 2025 found experienced open-source developers 19% slower with the AI tools of early 2025, against their own expectation of being faster2, and a follow-up in February 2026 pointed the other way with intervals that crossed zero, which METR itself judged unreliable3. The pair says little in general about AI and a lot about turning a local observation into a law. The objection to Amdahl is that AI can reorganise the process and change which fraction is accelerable. Agreed; then the assumption has changed and the new organisation has to be evaluated on its own. My bet is that AI will keep moving the bottleneck instead of removing it: as analysis gets cheap, data quality, clinical verification and material durability become relatively more decisive, and the firms that understand which clock now sets the pace will be the ones that win.
1Amdahl, Validity of the single processor approach to achieving large scale computing capabilities, AFIPS 1967. 2METR, Measuring the impact of early-2025 AI on experienced open-source developer productivity, July 2025. 3METR, Uplift update, 24 February 2026.
1251020501001101001000speed-up of the accelerated partspeed-up of the whole50% acceleratedceiling 290% acceleratedceiling 1099% acceleratedceiling 100Amdahl's ceiling. However fast the accelerated part becomes, the whole never goes faster than one over the part left unchanged
Drugs enter through the same door. More data from the brain does not turn into medicines by itself, and the difference between a biomarker and a validated surrogate endpoint (one that predicts the clinical benefit that matters) is written into the FDA's own vocabulary1. A recording can help select participants, find subgroups, confirm that a compound reaches the process it targets and kill a bad hypothesis earlier. My firmest expectation for pharmacology is a reduction in wrong experiments, long before any sudden revelation of what causes a disorder, and with a bias to keep in view: data from people implanted for specific conditions are not a neutral sample of human brains, and a large archive can still represent a narrow population.
1US FDA, Surrogate endpoint resources for drug and biologic development.
The order of arrival
Go back to the forecaster of 2015 once more, because the most useful thing she could have written was an order with recognisable signs, and scores on benchmarks would have been the wrong signs to watch. A result on a translation test said little about when translation would reach a phone. What said it was the price of a wrong answer and whether the data was already lying around. The permits turn that into a procedure: for each function, find the permit that closes last, describe what the function will look like on the day it arrives, and name the observable sign that it has. The procedure needs a unit much smaller than brain-computer interfaces: a function, for a population, through an architecture (speech for people with ALS through intracortical arrays, grasp for people with spinal cord injury through contacts on the dura, tremor for Parkinson's through a stimulator that listens). Each unit then passes four milestones that headlines tend to fuse: a demonstration in someone, an authorisation by a regulator, a recurring service that someone pays for, and wide adoption. Speech prostheses have passed the first many times and none of them has reached the third; NEO passed the second in March 2026 with almost none of the first's glamour. Years can separate each milestone from the next, and most bad forecasts in this field come from reading one as another. The ladder below is that procedure applied, with the table at its end for anyone who wants to check it in 2031. It is not one road (a visual prosthesis can advance while memory work stalls, and a new carrier can open an experiment nobody could run before), and the dates are wide bands. What I hold with confidence is the order.
Within five years
The first rung is restored output for people who have lost it, and it already stands on observed ground. In June 2026 the UC Davis group reported that Harrell had used his interface at home for nearly two years with no researchers present, for speech and to control his own computer1; in September Paradromics announced real-time speech and text in the first participant of its trial, implanted in June with a Connexus, and Neuralink showed a participant of its speech study saying I love you to his wife2. One participant is evidence of continuity and still not a distribution of results. The permits left are reimbursement and durability at scale, so the next step will look boring, and the boredom is how to recognise it: a service line in a few hospitals, a billing code, a device that loses its brand name in conversation. The sign to watch is the unit of the results. When papers and filings stop leading with words per minute and start reporting hours of independent use per week across a cohort, with the spread and the dropouts, this rung has been climbed.
1Card et al., Long-term independent use of an intracortical brain-computer interface for speech and cursor control, Nature Medicine, 2026. 2Paradromics, FDA approval for the Connect-One study, 20 November 2025; the speech result was announced on 14 September 2026.
The second rung arrives beside it and depends on the data permit. Decoders pretrained on many people will cut calibration, so that a new user talks in the first session rather than after weeks of them; the early transfer results across participants make the mechanism plausible1, and what remains is to show it in prospective use. The sign is a number nobody reports yet as a headline, the minutes of calibration a new user needs on day one, compared across centres. The third rung is already climbing without the name: closed loops in medicine, in which a device reads a state and doses its response, spreading from Parkinson's and epilepsy into neighbouring indications. Its last permit is the recoverable-error permit in a clinical form (each adaptive rule has to show that acting on the marker improves the outcome), and the sign is unglamorous: adaptive modes switched on by default at implantation, and programming visits that become rarer.
1Singh et al., Nature Communications 16, 2025: a decoder trained on stereo-EEG from 25 patients outperformed decoders trained on each patient alone.
The fourth rung is the one people will notice in their own pockets, and the order of forgivable errors explains why it comes so early. External state readers sold inside products bought for something else (headphones with EEG sensors in the ear cushions already sell themselves as focus trackers) need little from physics, nothing from the body, cheap data, and a payer who is the buyer. Their errors are forgivable for the seller, since a wrong focus score costs the company nothing, and the cost of a wrong inference falls on the person measured, often later and somewhere else. The only permit they lack is legitimacy, and it is the one nobody is checking yet. It will look like a setting in an app. The sign that this rung has arrived will be legal, and it is the first binding case over a secondary use of the data.
A fifth rung runs in the other direction and will barely be noticed outside laboratories: models measured against brains. As the shared geometry gets better charted, how well a network predicts cortex becomes one more number to report beside its benchmarks, useful to neuroscience as a microscope and to machine learning as a check on whether scale is finding the structure the brain found (a check with the tide machine's blind spot, since a network can climb that score by learning the brain's features without learning its methods, and the number will need control models with random weights beside it to mean anything). Its last permit is data, the long recordings of the kind only implanted patients and large scanning projects produce, and the sign will be a major model release that reports its brain alignment the way it reports its scores on reasoning.
Within ten years
The second band belongs to writing into the brain, and to agents. Stimulation already carries structure into perception: in 2025 patterned microstimulation of somatosensory cortex produced tactile sensations of edges and motion in people with implants1, and a retinal prosthesis restored the ability to read letters to most of the 32 people assessed after a year in a trial in geographic atrophy, then received the European CE mark in July 20262, so writing into the nervous system is already on sale where the target is the retina. In the cortex the last permits are the body (stimulation needs implants that last years) and the data (each brain has to learn the code, and the code has to be fitted to each brain). I expect useful but crude sensory writing within ten years, touch for prosthetic hands and coarse vision, which will sound the way early cochlear implants sounded, strange at first and learned over months; the sign will be a percept used in a daily task without the user looking at what the hand is doing.
1Valle et al., Tactile edges and motion via patterned microstimulation of the human somatosensory cortex, Science 387, 2025. 2Holz et al., Subretinal photovoltaic implant to restore vision in geographic atrophy due to AMD, NEJM, 2025, with a mean gain of 25.5 letters on the eye chart.
Agent-mediated interfaces belong to the same band, the stage where a few reliable bits from the brain authorise many actions in software. Their last permit is the recoverable-error permit, in the exact form the agents section described, and the sign is a study that reports completed tasks together with the rate of unauthorised actions under a budget fixed in advance. Closed-loop stimulation for psychiatric disorders will, I think, move in this band from single personalised cases to controlled evidence across several centres, with the caveat that a marker which tracks a symptom is not thereby its cause1. Focused ultrasound will arrive in the same clinics from outside the skull, as a stimulator aimed through bone at a deep target for sessions in a chair, and its last permit is data of a particular kind: dose and target planned for each skull, then shown to move an outcome, with the recordings from people who already carry leads in the target as its calibration. The sign will be a session of ultrasound on a hospital's list of outpatient procedures. And the implants will stay therapeutic. The peripheral shortcut makes this the bet I hold most firmly in the band: the substitutes improve along with the implant, and a healthy person has a keyboard, a voice and a wrist.
1Scangos et al., Closed-loop neuromodulation in an individual with treatment-resistant depression, Nature Medicine 27, 2021.
Beyond what I can see
Past ten years the ground goes soft, and the questions change kind. For each business out there I ask the same five things the rest of this text asked: what is measured, what is inferred from it, who acts on the inference, what changes for the person, and what can be done when the result is wrong. The industry I imagine there is one of assisted memory and shared experience, and it splits into businesses that will use the same word for very different things. One records an experience while it happens (with cameras, sound, context and contemporary neural signals) and helps a person reconstruct it later, which is a sophisticated personal archive. The other tries to recover old information that was never recorded outside the head, which is archaeology. There is a reason to think the second is not absurd: in mouse models of early Alzheimer's disease, optogenetic activation of the cells that had been tagged while a memory formed (its engram) brought back behaviour linked to that memory, so in those conditions a failure to recall was a failure of access while the trace persisted1. In people, in December 2025, a decoder trained on other people reading sentences recovered from fMRI how fifty participants rated the features of autobiographical scenes they were imagining (ratings, never images)2, and a hippocampal prosthesis that stimulates in patterns tied to memory encoding produced improvements in some conditions and declines in others3.
1Roy et al., Memory retrieval by activating engram cells in mouse models of early Alzheimer's disease, Nature 531, 2016. 2Anderson, Fernandino and Binder, Neural decoding of autobiographical mental image features with a general semantic model, Nature Communications, 2025. 3Roeder et al., Developing a hippocampal neural prosthetic to facilitate human memory encoding and recall of stimulus features and categories, Frontiers in Computational Neuroscience 18, 2024.
These are pieces, and the gap between them is where I place a second debt, the fidelity debt: the more convincing a reconstruction looks, the more it has to show which details came from the signal and which from the generator. A room rendered with good light can feel truer than a fragmentary description while containing less of the memory, and a faithful decoding of what someone recalls today proves nothing about what happened. Sharing an experience needs a double translation (from the sender's measurements to a description of the experience, then from that description to stimulation that produces something corresponding in a receiver whose brain is different), and observing and controlling are not inverse operations by definition. Experiments that linked brains have transmitted simple decisions1, which proves that a channel between brains can carry a learned code and leaves open whether an experience can travel through one. Whether a person whose memories and traits could be reproduced would still be the same person is a question I have no way to check, and I will not let a functional resemblance answer it. Even out here I am willing to bet on one thing. Creating new experiences that are useful will come long before certifying recovered ones as authentic, because creation only has to produce effects while recovery also has to prove its correspondence with a source; entertainment and therapy will exploit approximations that an autobiographical archive could never accept, and the commercial temptation will be to sell a synthesis as a restoration.
1Jiang et al., BrainNet: a multi-person brain-to-brain interface for direct collaboration between brains, Scientific Reports 9, 2019.
Function Last permit What it will look like Sign it has arrived
Restored speech and cursor Reimbursement A hospital service line, a dull device Hours of independent use per week, across a cohort
Day-one decoders Data A new user talks in the first session Calibration minutes compared across centres
Closed-loop therapy Recoverable error, reimbursement Stimulators that dose themselves Adaptive mode on by default at implantation
Consumer state readers Legitimacy A focus setting in headphones A binding case over secondary use
Sensory writing in cortex Durability, data Crude touch and vision, learned over months A percept used without looking
Deep stimulation by focused ultrasound Data Outpatient sessions aimed through the skull A listed procedure with a planned dose per skull
Agent-mediated interfaces Recoverable error A few bits that authorise long tasks Completed tasks under a stated error budget
Assisted memory Recoverable error, legitimacy Archives that mix record and reconstruction Verified details beyond a no-brain baseline
Models measured against brains Data Brain alignment reported beside benchmarks A major model release that reports how well it predicts cortex
Shared experience Observability, recoverable error Nothing I can describe honestly None I can name
The inferred person
This is the legitimacy permit, the last to be issued and the one most often confused with the others. The institutional question sits inside the product from the moment someone decides what a signal means and who may act on it, and treating it as a moral appendix to the engineering is how it gets lost. A system could estimate attention badly and still weigh on a worker's evaluation; it could attribute fatigue, vulnerability or a predisposition without the validity to support it, and gain authority because its output looks technical. I will call that operational portrait the inferred person: the person an organisation believes it has measured. Being wrong does not make the system harmless. It can make it worse, adding a false description that is hard to contest to the intrusion itself, and that is why I find a policy incomplete when it asks only whether a device can read something; it has to ask who may use the output, for which decision, and how the person can challenge it. Nor do brain data automatically add anything. If other observations already allow the same decision at lower cost, the neural sensor contributes little, and the right comparison sets a system with all the other relevant sources against the same system plus the recording. What only the recording allows I would call residual intimacy, defined as the inferential gain of the recording over a stated baseline, for a stated task, with the data and the models on both sides named. It measures the part of mental privacy that the recording itself puts at stake, a smaller thing than privacy as a whole, and it is where both the real new capability and the real new risk live.
Today's non-invasive decoders carry a safeguard inside their weakness: the 2023 fMRI decoder needed the subject's cooperation to train and to work, and models trained on other people performed barely above chance1. I will call this the cooperation lock, and it is three locks: calibration (the hours of a person's own data a decoder needs), the conditions of the measurement itself (lying still, attending to the task the decoder expects) and the person's ability to spoil the reading on purpose. They are accidents of the technology, and they fall separately. The section on the shared geometry gives the mechanism that wears down the first, since brains resemble one another, and the models, closely enough for a map fitted on others to transfer, and methods that align one brain's responses with another's already reduce the training a new subject needs2. A decoder that needs less of a person's data may still fail when the person is not doing the task it expects, and one that grows more accurate may still work in no more situations than before. Each advance has to be judged by which of the three dependencies it reduces, and better accuracy under cooperation shows nothing, by itself, about reading without it. Every day the lock holds is evidence of nothing about tomorrow, in the way a well-fed turkey's thousand quiet days are evidence of nothing about the morning before the holiday. This is also the classic shape of the problem that David Collingridge described in 1980: while a technology is young it is easy to shape and its effects are unknown, and by the time its effects are known it is entrenched and expensive to change. Neurotechnology is in the first half of that dilemma right now, and the response that does not wait for its effects is to set rules that are robust to the effects we cannot yet see, which here means rules about inference and use, more than rules about the capability of today's devices.
1Tang et al., 2023, cited above, which tested the dependence in training and in use separately and found both. 2Tang and Huth, Semantic language decoding across participants and stimulus modalities, Current Biology, 2025, where the alignment works even when it is computed from silent films.
The law is not empty, and saying that it always arrives late is a slogan. Chile amended its constitution in 2021, the first country to write neurorights into one, to protect brain activity and the information derived from it1, and in 2023 its Supreme Court ordered Emotiv to delete the brain data its headset had collected from a former senator2. Colorado added neural data to its sensitive data in 2024, followed by California, Montana, Connecticut and, in May 2026, Vermont, while the federal MIND Act introduced in 2025 would only order a study3. In November 2025 UNESCO adopted a recommendation on the ethics of neurotechnology, which is guidance and binds nobody4. The European AI Act prohibits systems that infer emotions in workplaces and schools, with medical and safety exceptions, and its definitions keep physical states such as fatigue outside the word emotion5, so a headset that claims to measure focus falls into the gaps of that taxonomy in ways a lawyer will spend years arguing. Law acts here in two directions at once. A rule reduces uncertainty when it defines which evidence is needed and which uses are inadmissible, and adds uncertainty when its categories are ambiguous or its enforcement unpredictable, and it can favour the firms that can afford compliance over the ones that cannot. I count clear definitions of inference and secondary use as vectors of certainty and the emotion and fatigue boundary as a vector of uncertainty, and I judge each obligation by the risk it removes and by who pays for it.
1Law 21.383, published 14 October 2021; see Chile's neurorights amendment. 2Chilean Supreme Court, ruling of 9 August 2023, analysed in Chilean Supreme Court ruling on the protection of brain activity. 3See US state neural data laws for the bills and their dates. 4UNESCO, Recommendation on the Ethics of Neurotechnology, adopted November 2025. 5Regulation (EU) 2024/1689, article 5 and recital 18.
In Europe the regulatory object is already defined, and it is more demanding than the public debate assumes. An implanted interface is an active implantable medical device under the MDR, designed and tested against standards such as ISO 14708-1 for the implant, IEC 62304 for its software and ISO 14971 for its risk management. Its decoder, as artificial intelligence that is a safety component of a product needing a notified body, is a high-risk system under article 6(1) of the AI Act, with obligations that the Digital Omnibus adopted in 2026 moved to August 20281. Updates are foreseen: since December 2024 the FDA accepts, for devices with AI in them, a predetermined change control plan that describes the planned modifications, how they will be validated and how their impact will be assessed2. What none of these documents specifies is the evaluation this device needs, which is whether a new version of a decoder still says what its user means, stays silent when the user is silent and keeps the ways of recovering from an error that the user relies on. The authorship tests described for the machine that finishes the sentence should become a harmonised standard, a fixed reference battery run before and after every update and reported to the notified body, and I expect the first serious regulatory dispute over an implanted interface in Europe to be about a change of software rather than a failure of hardware.
1Regulation (EU) 2024/1689, article 6(1) and the Digital Omnibus amendments. 2US FDA, Marketing submission recommendations for a predetermined change control plan for artificial intelligence-enabled device software functions, final guidance, December 2024.
The digital precedents caution against easy conclusions about how people will react. The European Commission fined Meta 200 million euros in April 2025 for its consent-or-pay model under the Digital Markets Act, and in December accepted Meta's commitment to offer an option with less personalised advertising1; in March 2026 the European consumer organisation BEUC argued that the new model still steered users toward the most personalised option and was still unlawful. The lesson I take is narrower than either side's: people's behaviour depends on the options actually offered to them, much more than on their declared convictions. There is also an impression of mine that I cannot reduce to a single source, formed over years of watching how digital tools get adopted: we accept dependence by accumulating small conveniences far more often than by deciding in favour of a large system of surveillance. I do not offer that as evidence, and it shapes one precaution: nobody should expect a spectacular revolt to be the main mechanism of protection. People will criticise a provider and keep using it, and both will be sincere. What I expect instead is that the first serious public harm will come from consumer devices, through what an organisation does with neural data for a purpose that was not in the terms, and that the remedy will come through a court or a regulator acting on a concrete case before any parliament writes a general rule, which is how Chile's case went and how most law has been made. It will be a grey swan, foreseeable in kind and surprising only in its date.
1European Commission, Meta commits to give EU users a choice on personalised ads, 8 December 2025.
Consent carries the last asymmetry. A stored recording can yield inferences later that no model could draw when it was taken; it does not contain infinite truths waiting for the right algorithm, since the limits of what was measured still hold, but a better interpreter changes what can be used inside those limits. Someone who signs a form today cannot know what a decoder of 2036 will read from the file (the inverse problem again, moved into law: the same recording admits as many readings as there are models to read it), and the distance between a company that holds years of recordings and a patient who signed to walk again is very large. So the right not to be inferred in certain contexts has to be stronger than a consent checkbox, especially when refusing would threaten a job, a school place or access to an essential service, and permissions should be separate for the immediate service, for research and for any secondary use. I would not demand the indiscriminate destruction of every recording either, because that harms research, the tracing of device failures and the user. Ethics also needs owners with different duties, since a committee is not an office that holds every competence. The sponsor answers for the evidence it presents and the follow-up it funds, the device regulator for the conditions of approval and surveillance, the data authorities for the processing of information, the clinical centres for the care and its conflicts, the payers for not turning savings into abandonment, and the patients need a real voice in decisions that alter a function they depend on. These are demands I am making, and no system of that shape exists yet.
Where should the line go? An earlier draft of mine said I would take the revolution two years late with the line drawn over the revolution on time without it, and a woman with ALS who uses an implant would be right to ask me what two years of silence cost and who pays it. That is the objection to my own thesis I take most seriously, and it moves the line. Medicine can go ahead of the law, and consumption cannot. A person who is recovering speech should not wait until the philosophy of privacy is settled, and should not pay for the chance with an unlimited cession of their future recordings; a pair of headphones that measures attention has no such claim on our patience.
Bets, dated so they can fail
The dates below do not come from a law of history. They are bets that follow from the mechanisms argued above, and I keep them apart from the facts that motivate them. My confidence is highest in the direction of a few differences (capability against distribution, signal against authorship, implant against its substitutes, stored data against transferable evidence) and lowest in the exact moment those differences produce an institutional result. I will not call something a hit because it vaguely resembles a bet, and where public information is not enough to decide, the result will be recorded as not assessable rather than as quietly right.
By 31 December 2031, at least one implanted communication system for people with severe paralysis will hold an approved indication in the United States or the European Union and be used outside trials with recurring payment (medium-high confidence). An investigational exemption, a temporary recording electrode or a demonstration funded only as research will not count. By the same date, a prospective evaluation in more than one centre will show that pretraining cuts at least in half the total calibration burden of a communication or control interface over its first ninety days, against a comparable system trained from scratch, without losing fidelity, user control or availability beyond thresholds fixed in advance (medium). This is the bet of the section on the shared geometry, and the half and the ninety days are thresholds I chose so that a marginal saving cannot count, never figures read off the papers. The people evaluated must be absent from the training data, with sessions and centres kept apart; the count includes set-up, corrections, recalibrations and professional help; and the study has to say how much of the gain came from other people's brain recordings and how much from text, images and other outside data, since a model pretrained on both hides the share of each. A control run without the neural signal shows how much the context alone produces, provided the ablation does not break the system for some reason other than the missing information. A saving at set-up that comes back as maintenance, fluency bought with sentences the user did not mean, or an advantage that vanishes in new people will count as failure. A miss by the date would prove no biological impossibility. A hit would show that part of the work of fitting a person can be replaced by knowledge learned elsewhere, which says nothing about whether the brain computes like a transformer. Also by then, a controlled comparison will show that a brain interface assisted by agents completes more useful tasks per unit of the user's time or effort than the same interface without them, without exceeding a rate of unauthorised actions fixed before the study (medium). In the same window, more people will receive an implanted brain interface sold commercially, outside any trial, in China than in the United States and the European Union together (medium); NEO's registration and pricing are the ground, and Western reimbursement is the brake. Also by then, a decoder of meaning or images from MEG or EEG, built on a frozen pretrained network, will reach in new people, with one hour of their data, at least 80% of the accuracy the same decoder reaches with ten hours of theirs (medium); this tests the twin heuristic and the shared geometry carried from the scanner to a wearable, and a result on fMRI alone will not count. And a court or regulator in the EU, the US or Chile will impose a binding restriction (deletion, cessation, limits on use or a fine) over secondary uses of neural data from consumer devices (medium-high); a recommendation, an unenforced bill or a case decided before this text will not count, and the bet does not need a spectacular leak.
By the end of 2035, the active users of intracranial implants for communication and control will remain predominantly people with a medically relevant loss of function, and healthy people implanted for productivity will be a small minority (high). Cochlear implants and stimulation-only devices are outside this set, and a verifiable elective majority would refute me. By then, a controlled multicentre study will show sustained clinical benefit from adaptive stimulation for a psychiatric disorder, with endpoints fixed in advance (medium); I will not call it a cure, nor extend it to other indications. Low-intensity focused ultrasound will hold an approved indication in the United States or the European Union as a neuromodulation treatment for a neurological or psychiatric disorder (medium); ablation with high-intensity ultrasound, approved for tremor since 2016, does not count, nor does use under a research exemption. The reverse bet on reading: of the people whose implant reads the brain, more than eight in ten will be read by electrodes (high), and a functional-ultrasound reader used chronically by a thousand people would refute it. A wristband or other peripheral reader of motor intention will have more than ten million monthly users (medium), three orders of magnitude beyond any implant; if no company discloses the figure the bet will be recorded as not assessable. No device reading from outside an intact skull will let new users write at fifty words a minute or more in daily life (high). And there will be no everyday non-invasive reader, independently validated, that reconstructs open and detailed narratives of episodic memories in new users without those contents having been revealed to the system beforehand (high). To refute this a result would need verifiable details and a substantial advantage over what could be deduced from the person's history and behaviour without the brain recording; choosing among known stimuli or recovering general attributes of scenes will not be enough. This last one is a bet on a mechanism and makes no claim of physical impossibility, and a result meeting those conditions would change a large part of this manifesto, which is exactly why I wrote the conditions down instead of hiding behind the phrase reading the mind.
Bet By Confidence Rests on
Implanted communication becomes reimbursed care 2031 Medium-high Restored output, the reimbursement permit
Pretraining halves calibration over ninety days, prospectively 2031 Medium The bet on the shared geometry, the data permit
Agents improve completed tasks under a fixed error budget 2031 Medium The value of a reliable no
China leads commercial implants outside trials 2031 Medium NEO, the reimbursement permit
One hour of MEG or EEG fits a new person to a shared decoder 2031 Medium The shared geometry, the twin heuristic
Binding action on secondary use of consumer neural data 2031 Medium-high The inferred person, the grey swan
Intracranial implants stay predominantly therapeutic 2035 High The peripheral shortcut
Multicentre evidence for psychiatric closed loops 2035 Medium Closed loops, marker against outcome
Focused ultrasound approved as neuromodulation 2035 Medium Ultrasound writes before it reads
Electrodes still read most implanted users 2035 High The bone's echo, the three routes
Ten million monthly users of peripheral readers 2035 Medium The peripheral shortcut
No external reader at fifty words a minute in daily life 2035 High Observability through bone
No everyday non-invasive reader of open episodic memory 2035 High Sufficient access, the fidelity debt
I expect the decisive event of this story to be a run of ordinary days, and none of them will look like a machine crossing someone's privacy the way light crosses a window: the day someone goes back to work through a recovered output, the day a stimulator doses itself better than its programmer did, the day a system attributes an intention that nobody meant to express, the day stopping turns out to be harder than starting. To see that economy coming nobody has to pretend that the brain will become transparent. By the time the follow-up was published Casey Harrell had spoken through his implant for more than 3,800 hours at home, at an average of 56 words a minute, with nine sentences in ten rated by him as at least mostly correct, and was holding down a full-time job, with carers trained to set the system up. Nobody had to reconstruct his mind to give him back a way to act. It took a signal from 256 keyholes in a single gyrus, read faithfully enough, and kept working after the researchers had left the room.