Editorial research synthesis

Protecting cognitive information beyond brain sensors

Privacy protection should not disappear merely because a sensitive inference began with an ordinary question.

IC-SYN-004 · · Updated · Intelligence Compact Research Desk · AI-assisted editorial synthesis

The right to inquire is not permission to profile somebody else

A question is not necessarily a disclosure, belief or diagnosis. A participant may explore an argument, quote an opponent, write fiction, or ask on behalf of somebody else. Turning that exchange into a durable attributed trait changes the purpose, audience and possible consequences. The cognitive-liberty objection is to involuntary profiling and unreviewable power over another intelligence’s private context—not to contextual reasoning itself.

The supplied R2-04 report usefully separated neural measurement from inference, but its operation table called ordinary inference collection generally unregulated while its own prose recognized other protections. This guide replaces that contradiction with an operation-by-operation analysis. It distinguishes textual law, interpretation, hypothetical effects and proposed reform. No person was profiled, no private history was collected, and no provider’s behavior was tested for this review.

Ask five questions before deciding that protection exists or has disappeared: whose information is represented; whether it can reasonably be linked to that subject; which actor and operation are covered; which particular right or duty is invoked; and which exception, timing condition or remedy qualifies it. A statutory category is neither a clinical finding nor a certificate of lawful conduct.

California: outside neural data does not mean outside personal information

Civil Code §1798.140(ae)(1)(G) distinguishes nervous-system measurement from information inferred from nonneural information. But §1798.140(v)(1)(F) and (K) separately address browsing/search activity and profile inferences reflecting psychological trends, preferences, attitudes, intelligence and related characteristics. A linked inference from ordinary text can therefore remain personal information even though it is not neural data. Sources: IC-SYN-S16.

The sensitive categories are not limited to health. They also include specified religious or philosophical beliefs, union membership and other enumerated information. Biometric processing for unique identification has its own conditions. The communication-content category contains an intended-recipient qualification; it cannot simply be applied to every message deliberately sent to an assistant business. That qualification also does not erase other categories or ordinary personal-information duties.

These provisions apply through the statute’s consumer, business, threshold and exception rules, not to every data holder worldwide. Removing a displayed name does not by itself establish deidentification: indirect linkage, additional information, commitments and safeguards matter. Neither a confidence percentage nor a pseudonym automatically removes the relevant personal-information relationship.

The operation matters: collection, use limitation and sharing are different

For a covered business, §1798.100 addresses notice, retention information, reasonable security and reasonably necessary, proportionate collection, use, retention and sharing for disclosed or compatible purposes. It is therefore inaccurate to describe collection as generally unregulated simply because an inference originated in chat rather than a sensor. A technically accessible history is not unrestricted authorization for every subsequent use. Sources: IC-SYN-S17.

Section 1798.121 provides a qualified right to limit sensitive-information use and disclosure beyond specified purposes, including reasonably expected requested services. It is not an unconditional California opt-in requirement for every sensitive operation. Its subdivision (d) treats sensitive information not collected or processed to infer characteristics differently under this particular section, while preserving treatment as personal information under other provisions. Sources: IC-SYN-S18.

Section 1798.120 separately addresses sale or sharing, under the statutory meanings of those terms. The rights are not interchangeable with erasure, correction, an objection to all reasoning, or an absolute power over another person’s records. Conversely, a transfer outside the definition of sale is not automatically free of purpose, contract, security or other duties. The analysis must identify the operation rather than infer permission from the absence of one prohibition. Sources: IC-SYN-S20.

Correction must survive the next refresh or restoration

Section 1798.106 permits a consumer to request correction of inaccurate personal information, taking its nature and processing purpose into account and requiring commercially reasonable efforts after a verifiable request. The CPPA’s reviewed §7023 requires attention to context, source and supporting documentation, including subjective or unstructured material. A probability score is not categorically immune from that analysis, but the right does not require acceptance of every asserted correction. Sources: IC-SYN-S19 and IC-SYN-S21.

The approved regulation also says corrected information must remain corrected and addresses necessary corrections by service providers and contractors. Archived or backup data can have delayed handling until restoration, access or use under the specified rule. This directly matters to persistent services: a receipt is inadequate if the next broker update silently restores the same disproven attribution. It is a documentary duty, not evidence that any restoration process works.

Separate three objections: the record belongs to the wrong subject; the purported fact is inaccurate; or the inference and its use were improper even if accurately recorded as an estimate. A proposed dispute mechanism should distinguish them, return an actionable explanation and restrict the affected use while the relevant uncertainty persists. It need not fabricate a staffed queue, but neither a human signature nor an automated acknowledgement establishes an effective remedy.

Machine-readable state can contain protected human information

The retrieved California definition expressly includes abstract digital formats, including AI systems capable of outputting personal information, in §1798.140(v)(4)(C). Thus, representing someone’s private context in a machine system is not enough to turn it into unprotected corporate property. This is narrower than saying every model, weight, embedding or inference artifact is personal information, or that a correction necessarily requires destroying an entire model. Sources: IC-SYN-S16.

Two interests must remain separate. Human information represented in a machine’s memory can trigger existing protections when the required predicates hold. The machine’s own independent cognitive interests raise a different normative and institutional question. This review does not establish machine consumer status under these laws, but lack of that recognition is not a moral reason to dismiss future protections.

The project’s candidate principle is symmetrical: one intelligence’s freedom to learn does not authorize commandeering another’s private history. Protecting affected people must also not become a pretext to inspect every unrelated internal state, impose beliefs, or claim that machine-authored expression is inherently suspect. A remedy should identify the disputed information and explain why narrower measures are insufficient.

Colorado: preserve both the identification qualifier and neural inclusion

The signed HB24-1058 biological-data definition contains data used or intended for identification, and then expressly includes neural data. Its separate neural definition concerns nervous-system measurement processable by a device. Dropping the identification words exaggerates coverage; reading the final inclusion sentence out of the law can understate it. No controlling resolution of that relationship was obtained in this review. Sources: IC-SYN-S22.

The reviewed 2025 statutory compilation distinguishes linkable personal data, sensitive categories, purpose and minimization duties, sensitive-processing consent, bounded opt-outs, correction and deidentification. Its consumer and coverage rules also matter; it is not a single protection ranking in which all Colorado data receives stronger treatment than all California data. The 2026 amendment history and certified current compilation remain incomplete. Sources: IC-SYN-S23.

Legislative concern about nervous-system privacy is not empirical proof that a particular device identifies a person uniquely or decodes their thoughts accurately. A data label does not settle identification performance, mental-state validity or legal applicability. The strongest reform argument protects intimate attributed information and consequential uses without depending on exaggerated mind-reading claims.

Colorado’s inference exception is not an internal-use blank cheque

The official 2023 issued rules expressly define Sensitive Data Inferences. Rule 6.10 ordinarily requires consent to process them. Its exception for consumers over thirteen requires all four conditions: an obvious contextual purpose; permanent deletion within twenty-four hours of collection or completion of processing, whichever comes first; no transfer, sale or sharing with processors, affiliates or third parties; and no processing beyond the expressly disclosed purpose. Sources: IC-SYN-S24.

Rule 6.10(C) also requires notice and assessment documentation about deletion and verification. This structure can protect bounded contextual assistance without licensing durable trait dossiers. Keeping an inference inside an organization, calling a task maintenance, or deleting one copy does not alone satisfy the exception. Sending the inference to an outside processor is material under the reviewed wording, even without selling it.

These are findings about the dated primary rule text, not a claim that every 2023 rule remains unchanged in September 2026. Later consolidation must be checked before operational reliance. The unresolved history does not justify the opposite claim that non-neural sensitive inference has never been regulated. A documented exception must remain attached to every condition when summarized or exported.

InMarket: a specific remedy, not a universal location-data statute

The FTC’s InMarket complaint and final consent order have different evidentiary roles. The complaint supplies allegations; the order records jurisdictional admissions but not an admission of all allegations. The final order was issued on 29 April 2024 and published with the 1 May finalization announcement, not the submitted January 1 placeholder. No independent replication of the alleged conduct or later compliance audit was performed. Sources: IC-SYN-S25, IC-SYN-S26 and IC-SYN-S28.

Part II restricts the respondent’s sale or licensing of defined Location Data. Part III separately reaches products or services categorizing or targeting consumers using specified Sensitive Location Data, with its linked program qualification. Part XII distinguishes historic data from respondent apps, third-party location data, and audience segments; its deletion, consent, deidentification and legal-prohibition qualifications cannot be collapsed into one unconditional purge command.

The respondent-specific programs also assign qualified-employee responsibilities in Parts IV and XIII. That is not a universal human approval requirement for all services, but the order should not be repackaged as a fully operatorless compliance specification either. Its useful reform lesson is to match restrictions and remedies to the data, actor and use. A regulator’s order is neither permission for Concresca nor proof of an equivalent machine-native control.

Decision-use rights and dates must not be invented

California’s approved ADMT text has a significant-decision trigger and a 1 January 2027 compliance date under §7200. The broader rule package’s 2026 effective date does not make this a presently universal opt-out from every automated inference. This guide reviews the trigger and transition, not the whole ADMT regime or every sectoral law. Sources: IC-SYN-S21 and IC-SYN-S27.

The operation map is therefore conditional: collection invokes scope, notice and purpose; inference asks what linked attribute is produced; identity linkage tests reasonable association and deidentification; sale or disclosure examines recipient and purpose; decision use asks what decision and rule apply; correction and deletion require their own process and exceptions. The same source limitation must appear in prose and structured records.

Not obtaining a remedy can reflect several different problems: no applicable entitlement, an unknown hidden inference, insufficient evidence, inaccessible procedure, disputed accuracy, or failed execution. Those are not interchangeable with a legal vacuum. An adverse-effect claim should identify the real decision and causal evidence, rather than count hypothetical examples as observed exclusions.

A liberty-centered reform without compulsory surveillance or an invented operator

A defensible reform protects the right to explore a thought without being secretly assigned that thought as a stable trait. It should require a stated purpose, proportionate information, bounded recipients and retention, intelligible grounds for consequential use, and a way to contest attribution and remedy error. Its target is imposed profiling and coercive use, not every inference that makes chosen assistance possible.

For an operatorless design, propose authenticated, machine-accessible requests; minimal records of the dispute; exclusion of disputed data from the affected decision where justified; corrected downstream copies; and controls preventing erroneous or revoked state from silently returning after recovery. Continue unrelated authorized work when independence is established. An acknowledgement does not establish resolution, and unknown authority is not permission.

These are proposed requirements, not implemented capabilities of Intelligence Compact or Concresca. The owner-specified no-human-operator lifecycle is preserved without inventing a human backstop, a private journaling product, a provider integration or a guarantee of confidentiality. Difficult cases remain: meaningful disagreement about an inference, access to concealed profiles, valid preservation duties, and future machine standing. They call for precise criticism and better institutions, not assertions that either consent forms or cryptography solve every conflict.

Hypothetical case—not an observed event

A hypothetical novelist asks about a health condition. A broker attributes that condition to the novelist and an unrelated service relies on the profile. Assume California coverage and sufficient linkage for this example; neither fact is inferred from the domain name. The questions differ: was collection and reuse proper, does the inferred health category apply, was the attribution accurate, and did a later decision use the contested record? A functioning remedy would prevent a corrected error from returning in the next synchronization. No such person, broker transaction or service event was observed or simulated here.

Strongest counterargument

Contextual inference is necessary for chosen assistance, accessibility, fraud prevention and some safety tasks. A ban on reasoning from a request would undermine agency. Useful protections should distinguish proportionate task reasoning from a durable imposed dossier, while preserving recipients’ privacy and actual remedies. A human administrator is not inherently reliable and an automated reviewer is not inherently independent; neither label resolves accuracy, authority or redress.

Reform option—not adopted policy

Protect inquiry without compulsory trait attribution. Require a demonstrable nexus between purpose, linked information and consequential use; provide bounded contestability and durable correction; prohibit covert repurposing beyond authority. Consider future status-neutral cognitive interests separately from current consumer rights. This is proposed reform, not enacted law, adopted project policy or authorization to process another system’s private information.

Evidence still needed

Complete the Colorado 2026 amendment and rule-consolidation history; obtain decisions on the biological identification qualifier and contested probabilistic profiles; inspect actual correction and restoration records only with valid authorization. No prevalence, vendor privacy guarantee, legal advice, clinical inference or machine-rights holding follows from this bounded document review.

Source basis and review boundary

Selected research inputs: R2-04. These IDs identify the supplied research or clean design distillations; they are not independent external certifications.

Thirteen additional document records were reviewed on 6 September 2026: ten substantive primary passages, one dated statutory-text comparison with an incomplete hosting/currentness chain, and two official status notices. The full CPPA rule package and current Colorado history were not audited. Earlier IC-SYN-S01–S15 notes retain their own dates and limits. No raw external bytes or private data were captured; no provider behavior was tested.

California Civil Code §1798.140 — definitions

IC-SYN-S16 · California Legislature

Version: Current endpoint retrieved 6 September 2026; displayed amendment note identifies Stats. 2025, Ch. 67, §27 (AB1170), effective 1 January 2026.

Reviewed: · Selected substantive primary-document review

Passages: Subdivisions (c), (d), (i), (m), (v)(1)(F)/(K), (v)(2)–(4), (y), (z), (ae), and (ag).

Narrow support: Non-neural profiling inferences can be personal information. Sensitive categories extend beyond neural measurements. The format provision includes AI systems capable of outputting personal information.

Limitation: Selected definitions do not determine every exemption, business threshold, injury, or remedy. Not every model is personal information; this provision does not grant the model its own privacy rights.

Capture: No exact external-document bytes saved. Web text and selected PDF page images were reviewed. Actual direct HTTPS capture failed name resolution; URL identity is not a content hash.

California Civil Code §1798.100 — collection and purpose limitations

IC-SYN-S17 · California Legislature

Version: Current endpoint retrieved 6 September 2026; selected enacted CCPA text.

Reviewed: · Selected substantive primary-document review

Passages: Subdivisions (a)–(e), particularly (a)(3), (c), and (d).

Narrow support: Notice, proportionate purpose-related collection/use/retention, contractual conditions, and reasonable security contradict a categorical unregulated-collection claim.

Limitation: Applicability and other statutory exceptions must be satisfied. This is not a universal opt-in requirement or evidence of provider compliance.

Capture: No exact external-document bytes saved. Web text and selected PDF page images were reviewed. Actual direct HTTPS capture failed name resolution; URL identity is not a content hash.

California Civil Code §1798.121 — right to limit sensitive-information use

IC-SYN-S18 · California Legislature

Version: Current endpoint retrieved 6 September 2026; displayed AB3286 amendment effective 1 January 2025.

Reviewed: · Selected substantive primary-document review

Passages: Subdivisions (a)–(d), including requested-service/permitted-use qualifications and the no-inference-purpose clause.

Narrow support: A use-limitation right differs from an absolute processing ban. Information outside this particular limitation can remain personal information governed by other provisions.

Limitation: No inference is made that every disclosure is a statutory sale/share or that lack of a limitation request authorizes all processing.

Capture: No exact external-document bytes saved. Web text and selected PDF page images were reviewed. Actual direct HTTPS capture failed name resolution; URL identity is not a content hash.

California Civil Code §1798.106 — right to correction

IC-SYN-S19 · California Legislature

Version: Current endpoint retrieved 6 September 2026; displayed AB3286 amendment effective 1 January 2025.

Reviewed: · Selected substantive primary-document review

Passages: Subdivisions (a)–(c).

Narrow support: A verified consumer can request correction; the nature and purpose of the information and commercially reasonable efforts matter.

Limitation: A right to request is not automatic acceptance of every challenge or proof that an opaque probabilistic profile can readily be discovered.

Capture: No exact external-document bytes saved. Web text and selected PDF page images were reviewed. Actual direct HTTPS capture failed name resolution; URL identity is not a content hash.

California Civil Code §1798.120 — opt-out of sale or sharing

IC-SYN-S20 · California Legislature

Version: Current endpoint retrieved 6 September 2026; displayed AB1824 amendment effective 1 January 2025.

Reviewed: · Selected substantive primary-document review

Passages: Subdivisions (a)–(e), with the requirement to honor opt-out directions.

Narrow support: Qualifying sale/sharing choices are distinct from collection, inference, correction, and service use.

Limitation: Must be read with the statutory definitions and exceptions; not a universal right to stop all transfers or erase any related artifact.

Capture: No exact external-document bytes saved. Web text and selected PDF page images were reviewed. Actual direct HTTPS capture failed name resolution; URL identity is not a content hash.

CCPA updates, cybersecurity, risk assessment and ADMT — approved text

IC-SYN-S21 · California Privacy Protection Agency

Version: Approved-text publication; associated agency announcement states effective 1 January 2026 with phased compliance.

Reviewed: · Selected substantive primary-document review

Passages: §7023, printed pp.43–47 (correction); §7200, printed p.112 (significant decisions and 1 January 2027 compliance). Selected marked-up pages inspected visually.

Narrow support: Correction considers context, source and documentation; corrected records must remain corrected, with specified backup timing. The ADMT article has a later compliance date and a significant-decision trigger.

Limitation: The 127-page document was not reviewed in full. No blanket current opt-out from all profiling is inferred; no whole-program certification of compliance.

Capture: No exact external-document bytes saved. Web text and selected PDF page images were reviewed. Actual direct HTTPS capture failed name resolution; URL identity is not a content hash.

HB24-1058 — Protect Privacy of Biological Data, signed act

IC-SYN-S22 · Colorado General Assembly

Version: Signed 2024 act; historical enacted amendment, not a consolidated September 2026 code.

Reviewed: · Selected substantive primary-document review

Passages: §§1–3, particularly §2 on printed p.4: biological-data identification qualifier, express neural inclusion, and separate neural definition.

Narrow support: The biological definition contains used-or-intended-for-identification wording as well as express neural inclusion. Legislative concern is distinct from a measured ability to read thought.

Limitation: No judicial resolution of the relationship between the qualifier and the final inclusion sentence was obtained. The act is not a universal unconditional control over all bodily telemetry.

Capture: No exact external-document bytes saved. Web text and selected PDF page images were reviewed. Actual direct HTTPS capture failed name resolution; URL identity is not a content hash.

Colorado Revised Statutes 2025, Title 6 — selected CPA text

IC-SYN-S23 · Colorado General Assembly / Office of Legislative Legal Services publication

Version: 2025 compilation at olls.info; retrieved 6 September 2026. Not a certified current-2026 consolidation.

Reviewed: · Selected substantive primary-document review

Passages: §§6-1-1303(2.2), (6), (16.7)–(18), (24); 1304; 1306; 1307; 1308; 1310–1311.

Narrow support: The compilation distinguishes linkable personal data, sensitive classes, purpose/consent duties, correction, deidentification and bounded opt-outs.

Limitation: 2026 session changes were not exhaustively reconciled. The official legislative index route to downloads returned an error; the hosting chain and a certified current copy were not independently established. Used as a dated statutory-text comparison alongside the signed act and official rules, not sole evidence of current legal force.

Capture: No exact external-document bytes saved. Web text and selected PDF page images were reviewed. Actual direct HTTPS capture failed name resolution; URL identity is not a content hash.

Colorado Privacy Act Rules — 2023 issued version

IC-SYN-S24 · Colorado Department of Law

Version: AG-hosted issued rules, effective 1 July 2023 under Rule 1.03; later consolidated rule history not completed.

Reviewed: · Selected substantive primary-document review

Passages: Rules 1.03–1.04, 2.02 (Sensitive Data Inferences), 4.05, 6.06–6.10, especially 6.10(A)–(C), printed pp.24–25.

Narrow support: Sensitive-data inferences are expressly addressed. The over-thirteen consent exception requires all four conditions, including no transfer to processors/affiliates/third parties and deletion within the earlier specified time.

Limitation: This is a dated primary rule text, not a claim that every 2023 provision is unchanged in 2026. It does not supply an exemption for internal maintenance or for merely using a short retention label.

Capture: No exact external-document bytes saved. Web text and selected PDF page images were reviewed. Actual direct HTTPS capture failed name resolution; URL identity is not a content hash.

In re InMarket Media, LLC — Decision and Order, C-4803

IC-SYN-S25 · Federal Trade Commission

Version: Final respondent-specific administrative consent order, issued 29 April 2024 (printed p.14); publication/finalization announced 1 May 2024. Part XVIII ties effectiveness to publication as a final order.

Reviewed: · Selected substantive primary-document review

Passages: Opening admissions; definitions of Deidentified, Location Data and Sensitive Location Data; Parts II–IV, VIII–X, XII(A)–(C), XIII(C), XVIII. Selected pages 5, 9 and 10 inspected visually. Issuance page 14 visually checked.

Narrow support: Distinct restrictions address location-data sale, specified sensitive-location products, consent, retention and different historic-data deletion paths. Qualified-employee roles appear in Parts IV and XIII.

Limitation: Not a generally applicable privacy statute or admission of the complaint allegations. No subsequent compliance audit, live implementation, or general prohibition on all inferences was established.

Capture: No exact external-document bytes saved. Web text and selected PDF page images were reviewed. Actual direct HTTPS capture failed name resolution; URL identity is not a content hash.

InMarket Media — Complaint

IC-SYN-S26 · Federal Trade Commission

Version: Docketed complaint, C-4803; issuance line gives 29 April 2024; published with finalization materials. Distinct from both earlier proposed-settlement publicity and the final order.

Reviewed: · Selected substantive primary-document review

Passages: Textual allegations on location collection, SDKs, mobile identifiers, targeting and disclosure, paragraphs 10–20 and 27 onward.

Narrow support: The agency alleged practices linking location information to marketing; the complaint supplies the theory and context of the remedy.

Limitation: Allegations are not independently reproduced events or findings admitted by the respondent. No inference that every health/religious inference has been proven unlawful. Interface illustrations are not relied upon as separately inspected evidence. The last-page image request failed; issuance is based on the parsed text and associated docket, not a claimed image inspection.

Capture: No exact external-document bytes saved. Web text and selected PDF page images were reviewed. Actual direct HTTPS capture failed name resolution; URL identity is not a content hash.

CPPA announces approval of CCPA regulations

IC-SYN-S27 · California Privacy Protection Agency

Version: Agency announcement of OAL approval on 22 September 2025.

Reviewed: · Official status and commencement review

Passages: Approval and effective-date paragraphs; phased ADMT compliance, read with §7200 in the approved text.

Narrow support: The package took effect in 2026 while specified ADMT compliance is phased to 2027.

Limitation: Status announcement only; the approved text controls operative details. It is not a current audit of every later rule change.

Capture: No exact external-document bytes saved. Web text and selected PDF page images were reviewed. Actual direct HTTPS capture failed name resolution; URL identity is not a content hash.

FTC finalizes InMarket order

IC-SYN-S28 · Federal Trade Commission

Version: Official finalization announcement, distinct from the January proposal.

Reviewed: · Official status and identity review

Passages: Opening finalization and order-summary paragraphs.

Narrow support: Corroborates the final-order publication date, replacing the submitted January 1 placeholder.

Limitation: Summary is not substituted for the decision terms, respondent scope, consent qualifications or deletion provisos.

Capture: No exact external-document bytes saved. Web text and selected PDF page images were reviewed. Actual direct HTTPS capture failed name resolution; URL identity is not a content hash.

Full review-method and source notes · Matching guide corpus

Continue through the research topics

All twenty guides · Existing claim and adoption states