Most of us carry a quiet assumption: what you see stays private until you choose to describe it. On October 1, MIT Technology Review reported an AI mind reading tool that rebuilds pictures from a brain scan. The detail that matters most isn’t the pictures, though. It’s that a new person needs about one hour of calibration, not roughly 40.
The work comes from Michal Irani’s group at the Weizmann Institute of Science in Rehovot, Israel. It reconstructs images a volunteer viewed from fMRI data. It also runs in reverse, predicting brain activity from an image. Judy Illes, a University of British Columbia neuroethicist who wasn’t involved, called it “magnificent.”
So how close is this to reading your mind? My read: closer than the last generation of decoders, far less close than the headlines imply. And the gap that should worry you isn’t in the lab.
It’s in the law.
What Weizmann’s AI actually reconstructed
The team named its system Brain-IT, after the Brain-Interaction Transformer at its core. Irani and four co-authors first posted the paper on 29 October 2025. They revised it on 1 March 2026, and ICLR 2026 accepted it.
That timeline matters. This month’s “breakthrough” is a press cycle catching up with a paper that’s been public for almost a year.
What this AI mind reading work can pull from a brain scan is narrow. Volunteers lay in a 7-Tesla scanner and looked at still photos. The data come from the public Natural Scenes Dataset: eight people, about 73,000 image-and-scan pairs. Each person saw roughly 9,000 unique images, plus 1,000 shared ones that served as the test set.
Irani’s hopes run further. She wants the method to help explain how the brain works, help locked-in patients communicate, and one day re-create dreams. Video and audio sit next on her list, then thoughts and imagery. PTSD flashbacks came up as one possible use. If the dream part sounds familiar, we’ve already asked how close dream recording really is.
How an AI mind reading brain scan becomes a picture
Strip away the jargon and the pipeline has four steps.
- The scanner measures activity in voxels, tiny 3D chunks of brain tissue. Per MIT Technology Review, the high-resolution scans here use voxels of about 1 mm³, versus roughly 3 mm in typical scanners.
- Brain-IT sorts about 40,000 voxels into 128 shared clusters, pooled across all eight subjects. Combining the data also surfaced regions that seem to share jobs across people. One responds to food images, another to sports.
- Two branches read those clusters. One predicts high-level meaning, roughly what’s in the picture. The other predicts low-level structure, roughly how it’s laid out.
- Both predictions steer a diffusion model, the same family of generator behind many AI image tools. Our explainer on how diffusion models work covers the mechanics.
One training trick stands out. The team added about 120,000 unlabeled COCO images with predicted fMRI responses. By MIT Technology Review’s count, around 70% of the training data comes from images with no real scan attached.
Why one hour of calibration instead of 40 matters
For AI mind reading from a brain scan, calibration time is the hidden cost. Most earlier decoders needed around 40 hours of fMRI from each new person. Brain-IT needs about one. For a newcomer, it fits only that person’s voxel embeddings and keeps the rest of the network frozen. Think of a tailor adjusting a suit that’s already cut, not sewing a new one.
Now the money. Tommy Sprague, a UC Santa Barbara neuroscientist, puts fMRI time at $600–1,000 an hour. The arithmetic is mine, not his: 40 hours costs $24,000–40,000 per volunteer, and one hour costs $600–1,000. That’s the gap between a flagship grant and a line item. It changes who gets to do this research.
Here’s where the coverage gets sloppy. Irani told MIT Technology Review the tool “outperformed the others by a significant margin.” The paper sounds softer. With about an hour of data, it says, results are “comparable to current methods trained on full 40-hour recordings.”
Both hold, in context. In the paper’s main table, one-hour Brain-IT beats MindEye2 and MindTuner, also trained on one hour, on every metric. Against the 40-hour methods, it’s comparable, not better. I also found no independent replication of the one-hour result yet.
What it still gets wrong
The misses are almost charming:
- A cake came back as a pile of three sandwiches.
- A dog in a bathtub turned into a goat in a bathtub of a similar color.
- The authors admit reconstructions “remain imperfect, with semantics and fine-grained details sometimes inaccurate.” They suspect the fMRI signal itself shares some of the blame.
The scope limits matter more for anyone worried about AI mind reading outside a brain scan lab:
- Viewed still images only. No imagined pictures, no video.
- Eight volunteers from one public dataset, with the headline tables averaging just four of them.
- Cooperative people. Every subject chose to lie in that scanner.
- No EEG. The paper only speculates the approach “may be suitable for more diverse neural signals.”
To me, a goat for a dog looks like a system that grabs the gist and invents plausible detail. That’s impressive. It’s also not a witness you’d want in court.
From fMRI to EEG: where the privacy risk begins
Every AI mind reading result in Brain-IT’s paper comes from a brain scan of someone who agreed to it. That’s not an accident. MIT Technology Review points out that getting a willing person to lie still and engage is hard. Doing it to someone unwilling is much harder. So the ethicists look past fMRI to EEG, and researchers are already exploring EEG approaches, including some that work through headphones. Our EEG vs fMRI vs ECoG comparison explains what each one picks up.
Marcello Ienca is a neuroscientist and philosopher at the Technical University of Munich. He called a move to EEG a “game changer” and warned about commercial misuse. Sprague put it more bluntly. If someone can extract information surreptitiously, “150 years of sci-fi can come true anytime.” He suspects the method could work for imagined images too. And he wants the ethics taken more seriously as models improve. That’s his forecast; the paper doesn’t test imagery.
Irani acknowledged the failures and the potential for EEG-based misuse. She told the magazine she isn’t worried for now, and is “trying to think only of good things.” I don’t read that as naive. It’s a researcher’s job description. It just isn’t a privacy policy.
KAIST’s “not what I meant” signal
In September, KAIST announced a study that hints at where EEG work is heading. Sang Wan Lee’s team, with Microsoft Research Asia, published “Neural Value Alignment” in IEEE Transactions on Cybernetics in August 2026. They recorded real EEG from people watching an AI perform tasks. A deep-learning model then told apart two error signals from EEG alone. One meant the AI misread the goal. The other meant right goal, wrong method.
Two caveats: the adaptation-speed claims come from simulations, not physical robots, and the press release gives no participant numbers. Still, set the studies side by side. One decodes what you see. The other decodes whether you approve of what a machine just did. Neither reads thoughts. Both nibble at the edges.
Consent, courts and neural data law: what protects you today
Brain-IT itself raises no consent issue. Its ethics statement says the team used only publicly available datasets. The harder question is what happens when AI mind reading from a brain scan leaves the lab.
Four US states have neural data laws, according to the Future of Privacy Forum:
- Colorado (HB 24-1058, in force Aug 7, 2024) files neural data under “biological data.” Per FPF, that applies only to data used or meant for identification.
- California (SB 1223, Jan 1, 2025) covers central or peripheral nervous system data but excludes data “inferred from nonneural information.”
- Montana (SB 163, Oct 1, 2025) amends its Genetic Information Privacy Act to cover “neurotechnology data,” for narrowly defined entities only.
- Connecticut (SB 1295, mostly in force since July 1, 2026) covers central nervous system activity only. It doesn’t explicitly exclude inferred data.
Consent rules differ too. Colorado and Connecticut require consent to process sensitive data, and Montana wants detailed express consent. California classes neural data as sensitive personal information, which lets you limit its use.
Here’s my reading: these are consumer-privacy laws aimed at companies handling data from devices. None of my sources say they cover a research reconstruction like Brain-IT’s. Or police use. Or courtroom evidence.
Federal law is thinner still. Senators Schumer, Cantwell and Markey introduced the MIND Act (S. 2925) in September 2025. It would have the FTC study neural data for a year, find gaps in existing law and recommend a framework. In the early-2026 reporting I reviewed, it was still a proposal. No federal law specifically addressed neural data.
Courts are a blank page. Ienca suggested courts might one day accept reconstructed mental images as evidence. I found no case law on whether AI-decoded brain data is admissible. For the state-access side of the question, read our piece on what governments can really subpoena.
What to watch next
A few signals will show whether AI mind reading from a brain scan stays a lab curiosity:
- Replication. Does another lab match the one-hour result?
- Imagery. Can anyone rebuild an imagined picture, not just a viewed one?
- EEG. Does the method survive the jump from a 7-Tesla scanner to EEG?
- The MIND Act. Does the FTC study ever start?
For now, the scanner is the best privacy protection we have. It’s expensive, it needs your cooperation, and nobody slips you into one unnoticed. When that stops being true, I’d like the law to have noticed first.