AI Library
The Age of Autonomous Scientific Discovery
Kim Kyung-jin, Attorney at Law
AI Scientists and Self-Driving Labs
This book follows how AI scientists and self-driving labs are changing the way science generates and verifies claims. It covers literature-based discovery, natural-language protocols translated into robot commands, multi-agent research systems, closed-loop laboratories, materials search, the verification gap, chains of evidence, research harnesses, journal ethics, and legal responsibility.
AI Library
A New Era of Life Sciences Opened by Artificial Intelligence
Structural Proteomics, Genomic Foundation Models, Autonomous Laboratories, and Global Governance
Kim Kyung-jin, Attorney at Law
This book is a research volume compiled with artificial intelligence. A human selected the materials and structured the work, while AI models drafted the sentences and cross-checked the facts.
AI Library
The Double Structure of Digital Sovereignty
Europe’s Departure from Palantir and the Chains of American Big Tech
Kim Kyung-jin, Attorney at Law
This is a record of 2026, when European intelligence agencies and defense ministries began removing analytics tools from America’s Palantir. It covers the replacement decisions made by France’s General Directorate for Internal Security (DGSI), Germany’s Federal Office for the Protection of the Constitution (BfV), and the Netherlands Ministry of Defense; the incident in which US export controls severed an ally’s ac…
New English Edition
Artificial Intelligence in Horticulture
Kim Kyung-jin, Attorney at Law
Across five chapters and ten sections, this book examines computer vision for crop diagnosis, harvesting robots and autonomous field systems, smart greenhouses and digital twins, precision irrigation and supply-chain quality control, high-throughput phenotyping, and predictive breeding.
New English Edition
Artificial Intelligence in Food Crop Agriculture
Kim Kyung-jin, Attorney at Law
Across six chapters and eighteen sections, the book examines digital agricultural infrastructure, remote sensing, crop diagnosis, yield forecasting, precision irrigation, genomics, molecular breeding, agricultural robotics, climate-smart agriculture, and global food security.
New English Edition
The Future of Forestry and Agroforestry
Kim Kyung-jin, Attorney at Law
Driven by Artificial Intelligence and Digital Innovation
Across five chapters and fifteen sections, the book follows satellites, drones, LiDAR, digital twins, forest-specific language models, wildfire and pest forecasting, forestry robotics, agroforestry, timber traceability, and forest carbon markets.
New English Edition
Smart Livestock Farming: AI Enters the Barn
Kim Kyung-jin, Attorney at Law
Sensors listen, cameras watch, and artificial intelligence helps farmers decide.
Across five chapters and fifteen sections, the book follows precision livestock farming from animal health and reproduction to robotic milking, virtual fencing, digital twins, methane reduction, welfare, and data ownership.
Table of Contents
Han Dong-hoon, Busan Buk-gu Gap: A Record of the 100 Days Before and After the Election (Mar. 26-Jul. 3, 2026)
Kim Kyung-jin
Table of Contents and 13 sections
From March 26 to July 3, 2026, this record follows the spring after expulsion, the Busan Buk-gu Gap by-election, victory as an independent, and the first bill submitted in the National Assembly.

Table of Contents
Artificial Intelligence and Medicine
Kim Kyung-jin, Attorney at Law
AI in clinical care, hospitals, education, and research
AI in medical imaging, risk prediction, treatment planning, hospital operations, education, and research, with patient safety, privacy, and accountability.
[AI Library] Chapter 14. Ethical Dilemmas in the Age of Brain Data
Brain Readers: Neuralink and the Final Human Revolution
Chapter 14. Ethical Dilemmas in the Age of Brain Data
Kim Kyung-jin
A. Mental Privacy and Brain Data Ownership
One day in 2021, a Chilean engineer filed a lawsuit against the American neurotechnology company Emotiv. His name was Guido Girardi. He had purchased and used the company's EEG headset, the Insight. The problem came afterward. He had no way of knowing where his brain data had gone, who could access it, or how long it was being stored. He read the privacy policy but found no clear answers.
In 2023, Chile's Supreme Court ruled in Guido Girardi's favor. The court ordered Emotiv to delete his brain data from its databases. It was the first ruling in the world to recognize brain data as an independent legal category. But another part of Girardi's request, that the company revise its privacy policy itself, was not granted. It was a victory, and an incomplete one at the same time.
Behind this ruling lay Chile's history of becoming the first country in the world to amend its constitution to guarantee neurorights, in 2021. But the limits of constitutional language alone became clear: it was difficult to regulate the specific requirements of data processing with a constitutional provision.
Why is brain data different from other data? Our brains generate electrical signals every moment. These signals contain our emotional states, attention levels, and even our reactions to specific words or images. In 2024, researchers at Harvard Medical School reported that an AI trained on 175 hours of brainwave recordings accurately identified nearly half of 512 spoken phrases. As technology advances, the range of information that can be inferred from brain data grows wider. No one knows what tomorrow's analysis might extract from data collected today.
Colorado State Senator Cathy Kipp put it this way: we cannot know what will be readable from data collected today five years from now, because technology is advancing too fast.
In April 2024, Colorado became the first jurisdiction in the world to enact a comprehensive data protection law that explicitly covers neural data. The law defined neural data as "information that is generated by the measurement of the activity of an individual's central or peripheral nervous system." That September, California amended its Consumer Privacy Act to classify neural data as sensitive personal information. Montana and Connecticut followed.
But the scope of protection varies from state to state. California's law excludes data inferred from non-neural information. Heart rate data, for example, comes from the circulatory system and is not neural data. Yet stress levels can be inferred from changes in heart rate. That kind of data falls outside the protection.
In April 2024, the Neurorights Foundation audited the privacy policies of 30 consumer neurotechnology companies. The results were alarming. Twenty-nine companies had access to consumers' brain data with no meaningful restrictions. 96.7 percent of companies reserved the right to transfer brain data to third parties. Fewer than 20 percent mentioned encryption. Only 10 percent had adopted all core safety measures.
In April 2025, several U.S. senators sent a letter to the Federal Trade Commission. They emphasized that neural data is different from other personal data, because even when anonymized, it can reveal mental health conditions, emotional states, and cognitive patterns.
UNESCO formed an expert group in August 2024 to develop international ethical standards for neurotechnology. The standards are expected to be adopted in November 2025. The American Medical Association formally called for neural privacy protections in June 2025.
If a password is leaked, you can change it. But once brain data is exposed, there is no undoing it. Brain data belongs to our most intimate domain. It contains what we feel, what we react to, and perhaps what we think. Who owns this data? The company that collected it, or the person whose brain produced it?
Chile answered with its constitution. Colorado answered with legislation. But in most countries around the world, the question remains open.
B. Brainjacking: Threat Scenarios of Motor Cortex Hacking and Sensory Manipulation
In July 2025, researchers at Yale University's Digital Ethics Center published a paper. The title was "Cyber Risks of Next-Generation Brain-Computer Interfaces: Analysis and Recommendations." The opening sentence caught attention: without effective safeguards, a widespread security breach of a standardized BCI system could simultaneously affect millions of users.
The researchers warned that such attacks could incapacitate critical infrastructure personnel, disrupt social order through mass confusion, or even be exploited by hostile actors to harvest sensitive thoughts and memories from entire populations.
What is brainjacking? The term refers to unauthorized access to and manipulation of brain implants or neurostimulators. No actual cases have been reported yet. But experts warn that a single high-profile attack would irreversibly damage public trust.
The threat is not just theoretical. MIT researchers demonstrated that EEG equipment can function as a kind of antenna. When an attacker transmits an amplitude-modulated radio frequency signal, the nonlinear amplifier response in the EEG device captures the modulation frequency and interprets it as a real neural signal. With sufficient transmission power, the injected signal overwhelms the user's actual brainwaves. The attack could penetrate walls and doors. The range was limited to about three meters, but that is close enough.
Modern BCIs like Neuralink communicate wirelessly via Bluetooth. Physical vulnerabilities have been reduced, but new cybersecurity threats have emerged. Bluebugging attacks can gain unauthorized access to a device within 10 meters, intercepting neural signals or altering functions. Bluesnarfing can steal data from unsecured Bluetooth connections at distances up to 100 meters. In BCI applications, this could lead to large-scale neural data breaches without the user ever knowing.
Deep brain stimulation (DBS) devices are already widely used to treat neurological conditions such as Parkinson's disease. Researchers at Oxford University's Functional Neurosurgery unit warned about the potential risks of these devices. If a hacker altered DBS settings, they could induce greater pain, suppress movement in Parkinson's patients, trigger hypersexuality or pathological gambling, or manipulate reward learning to attempt behavioral control.
AI-based attacks are another concern. A technique called adversarial perturbation can add noise to EEG data, forcing P300 and SSVEP spellers to output desired characters. Backdoor attacks poison training data to force specific classifications.
The problem lies in the physical constraints of BCIs. The limited size and battery capacity of implants make it difficult to implement strong encryption. Backdoors may be necessary for emergency medical access. The Yale researchers recommended requiring encryption only when data moves between the device and a remote computer, to minimize power consumption.
The U.S. Food and Drug Administration reviews BCI cybersecurity, but standards have not kept pace with the speed of technological development. BCIs are classified as Class III implantable medical devices in the United States, the most stringent regulatory category, but specific cybersecurity guidelines are still being developed.
The Yale researchers offered several recommendations. Regulators should mandate non-surgical software update methods. Strong authentication and authorization frameworks for BCI software modifications are needed. Encryption of data traveling to and from the brain is essential. Network connectivity should be minimized wherever possible. They also recommended adversarial training of AI systems to prevent them from sending malicious stimulation to patients' implants.
Brainjacking is not yet a reality. But as BCI technology spreads, the incentive for attacks grows. There are precedents in medical device hacking. Vulnerabilities were found in Medtronic defibrillators. Insulin pump hacking has been demonstrated. Devices implanted in the brain are no exception.
We do not yet know enough about how to protect the brain. But we must find a way. The brain is our last sanctuary.
C. The Risks of Algorithmic Bias and Autonomy Violations
In 2023, at a railway depot in Hangzhou, China, train operators were wearing special caps. Sensors embedded in the caps measured their brainwaves in real time. The stated purpose was to detect fatigue and lapses in concentration. It was explained as a safety measure. But there was another way to look at it: should monitoring a worker's mental state be permitted at all?
BCI algorithms are not neutral. Every algorithm reflects the characteristics of its training data. Most BCI algorithms today were trained on data from Western, white, male subjects. When these algorithms interpret signals from other demographic groups, bias can emerge.
The problem grows more complex with emotion-sensing BCIs. Biases about emotion differ by gender and age. There is a stereotype, for instance, that women are more emotional. If such biases are baked into training data, an algorithm may interpret the same brain signal as an emotional response in a woman and a neutral response in a man.
The question of autonomy runs deeper. BCIs are increasingly merging with artificial intelligence. AI-driven BCIs can operate independently based on visual input and situational awareness. Users believe they control the device, but in practice the algorithm makes many of the decisions. Researchers call this the illusion of agency.
Closed-loop systems sharpen the problem. A closed-loop BCI reads brain signals and automatically delivers stimulation. A deep brain stimulator for depression, for example, detects certain brainwave patterns and sends an electrical pulse without any action from the patient. The boundary between self-determination and machine determination blurs.
Patients who have received deep brain stimulation report mixed feelings about personality changes. They experience shifts in impulsivity or conscientiousness. They say it is hard to tell the device's achievements from their own abilities. Is it me, or is it the machine? They find no clear answer.
A new concept has emerged: the right to feel negative emotions. If a closed-loop system automatically regulates mood and cognition, do we lose the right to experience sadness or anxiety? Negative emotions often carry important information. They signal that something is wrong. Is it wise to suppress that signal automatically?
Several countries are responding to these concerns. Chile's 2021 constitutional amendment protects mental privacy and freedom of will. Spain's Digital Rights Charter states that neurotechnology must guarantee identity sovereignty and self-determination. China's 2023 BCI ethics proposal emphasizes autonomy, privacy, transparency, and fairness.
Neuromonitoring in the workplace, however, sits in a regulatory blind spot. Fatigue detection systems used in Chinese factories and railways operate under the banner of safety. Whether workers truly consented to this monitoring, whether they had the option to refuse, remains unclear.
Colorado's 2024 AI Act aims to prevent discrimination caused by AI in high-risk decision-making, whether intentional or not. In 2025, Texas and Virginia passed similar laws. But the Texas law punishes only intentional discrimination. What happens with unintentional yet systematic bias?
A 2025 study by the Brookings Institution showed that humans fail to identify and correct AI bias. Researchers had human subjects collaborate with a racially biased AI model to screen resumes. The subjects could not adequately detect or counteract the AI's bias spreading into their own decisions. This suggests that current AI policies requiring human oversight in high-risk decisions may not be enough.
Algorithms are tools. But when a tool interprets and regulates our thoughts and emotions, it becomes more than a tool. It becomes an actor that participates in defining who we are. Its biases become biases about ourselves.
D. The Problem of Consent: What True Informed Consent Means
In 2022, retinal implant company Second Sight went bankrupt.
Hundreds of visually impaired people had the company's Argus II device implanted in their eyes. For some, the device let them see light for the first time in decades. After the bankruptcy, they were left with no options. The devices still worked, but updates and support stopped. If something broke, there was nowhere to get it fixed.
This case lays bare the limits of informed consent in brain-computer interface research. Clinical trial participants agreed to have the device implanted. But what exactly did they agree to? There was no promise that the device would be supported permanently. Was enough information provided about the possibility of the company going bankrupt?
The traditional informed consent model assumes a decision made at a single point in time. A research participant receives information, understands it, and agrees voluntarily. BCIs don't fit this model.
There is, first, the problem of transformative experience. Is the person before a brain chip implant the same person after? The pre-implant self cannot imagine what the post-implant experience will be like. Philosophers call this a transformative experience, one whose nature cannot be known until it is lived. Traditional informed consent does not adequately address this experiential dimension.
Consider Noland Arbaugh. He had lost all sensation and movement below his shoulders for eight years. When he decided to join the Neuralink clinical trial, he had no way of knowing what it would feel like to control a computer with his thoughts alone. He could not predict how it would affect his sense of identity.
There is, second, the problem of long-term uncertainty. The long-term effects of BCIs are unknown. No one knows what will happen in 10 or 20 years. How the device will interact with brain tissue, what changes in personality or cognition may arise, none of this can be predicted. How cybersecurity threats will evolve, how personal data will be used, all of it is uncertain. How can a participant consent to risks that even the researchers don't know about?
There is, third, the dilemma of removal. What happens when a clinical trial ends? Can the participant keep using the device? What happens if the device is deactivated? If removal is desired, is it possible?
The risks of removal surgery can be equal to or greater than those of the original implant procedure. Leaving a deactivated device in the body may prevent MRI scans or cause complications from device migration.
There is, fourth, the problem of capacity to consent. Consider locked-in syndrome patients. They are conscious but cannot move anything except their eyelids. BCIs offer them hope of communication. Yet the consent process itself is difficult. How do you confirm they understood the contents of a consent form? How do you verify that consent expressed through eye blinks reflects genuine understanding?
The 2024 revision of the Declaration of Helsinki calls for a shift in thinking. Research participants should be seen as collaborative partners, not test subjects. If a participant cannot provide full informed consent but can express willingness, the physician should seek that expression of willingness alongside consent from a legal representative. The participant's stated preferences and values must be considered, and any objection must be respected.
Some researchers propose a dynamic consent model. Instead of a one-time agreement, it involves continuous information updates and staged re-consent. New consent is sought whenever the technology or its functions change. But even this model does not solve every problem. How can a static agreement account for an open-ended future?
A systematic review published in the World Journal of Psychiatry in August 2025 identified assessment of informed consent capacity as a major challenge in BCI clinical research involving psychiatric patients. The study covered patients with schizophrenia, mood disorders, anorexia, alcohol dependence, and neurocognitive disorders from Alzheimer's and Parkinson's disease. The researchers constructed a five-dimensional BCI-specific informed consent capacity framework. They recommended that future research develop dynamic assessment systems and improve the consent capacity of psychiatric patients.
Institutional review boards face a difficult task. Surgical risks are clear-cut, but changes in personality or function are hard to define. Finding cybersecurity experts takes time. Weighing risks against benefits is not straightforward.
Informed consent is the cornerstone of research ethics. In the age of BCIs, that cornerstone is shaking. We need new consent models. Consent that begins with the implant and evolves alongside it. Consent that acknowledges uncertainty while respecting the participant's autonomy. Consent that protects participants even if a company goes bankrupt, even if support is cut off.
What that looks like is not yet clear. What is clear is that the way we do it now is not enough.
Kim Kyung-jin
Attorney · Former Member of the National Assembly · AI Policy Researcher
© 2026 Kim Kyung-jin. All rights reserved.













