Brain-Computer Interfaces (BCI)
From neural signal to intent, with consent at the center.
ColdAI builds the software side of brain-computer interfaces: acquisition pipelines, signal processing, decoding models and the interfaces they control. We work with research teams and device makers, treat consent and neural data protection as design inputs from the first recording, and leave implants and clinical claims to the regulated device makers and clinical partners who own them.
The opportunity
Start with a decision
worth improving.
A research team records EEG while participants imagine simple movements. It needs a pipeline that cleans the signal, decodes intent in near real time and stores recordings under strict consent terms.
From possibility to a working system
Follow the flow.
Three connected decisions. One considered architecture.
Conceptual flow, not a live system or measured result.
Acquire a clean signal
Specify the sensing modality, sampling, synchronization and artifact handling for the protocol. Non-invasive and implanted systems have very different noise, risk and regulatory profiles.
Decode the intent
Train and validate decoding models per user and across sessions. Report accuracy, latency and calibration effort honestly, because signal drift and individual variation shape what is achievable.
Govern the data and the device
Apply explicit consent, minimization and access controls to neural recordings. For medical uses, align software documentation with the device's regulatory pathway and the clinical partner's study design.
The work, made concrete
What we can build
with your team.
We agree scope, dependencies and acceptance criteria before delivery. Your project can start with an assessment, a pilot or an integration into an existing system.
Signal acquisition and processing pipeline
Clarify the system boundary, the responsible owners and the decisions the architecture needs to support.
Validated decoding models and benchmarks
Turn the agreed design into reviewable work, evaluated against representative inputs and explicit success criteria.
Neural data governance and regulatory mapping
Make the next step operable: document responsibilities, known limitations and the path from pilot to ongoing use.
In depth
Go deeper: the signal pipeline and the law around it
One guide follows a non-invasive signal from electrode to command; the other explains which laws already treat that signal as sensitive data.
- 01ArchitectureEEG BCI pipeline: from raw signal to real-time decodingA reference architecture for a non-invasive EEG BCI: acquisition and sync, filtering and artifact removal, CSP, Riemannian or CNN decoders and latency budgets.
- 02Regulation explainerNeural data privacy laws and consent for BCI productsWhich laws now treat neural data as sensitive, from Colorado and California to the GDPR and Chile, and how to design consent, retention and access to match.
How the recording approach changes the software problem
The sensing method is usually fixed by the research question or the device partner. What it changes for the software team is worth knowing before scoping any work.
| Consideration | Scalp EEG | Other non-invasive methods | Implanted electrodes |
|---|---|---|---|
| Typical builders | Research labs, assistive technology startups, consumer neurotech | Research groups and clinical research units | Device makers running regulated clinical programs |
| Signal the software receives | Fast but noisy and spatially blurred | fNIRS tracks slower blood-oxygen changes; MEG needs a shielded room | Richer signals from surgically placed arrays |
| Regulatory route | Set by the product claim: wellness, research or medical | Mostly research, sometimes medical | Medical device route with clinical studies2 |
| Where software effort goes | Artifact handling, calibration, usability | Signal modeling and slower control loops | Decoder stability, safety interlocks, documentation |
| ColdAI's role | Pipeline, decoders, interface and governance | Analysis pipelines and decoders | Software and data systems beside the device maker; no hardware |
The last row restates the boundary on this page: ColdAI builds software and data systems, not implantable hardware, and makes no clinical claims1.
Which rulebook a BCI product falls under, set by what it claims
- If
Recordings are collected only for a study, with no product on sale.
ThenWork under the study's ethics approval and informed consent, and design data handling so recordings can later be reused only where consent allows.
Research consent written narrowly today decides whether the data can train a product tomorrow.
- If
The product promises relaxation, focus or other lifestyle benefits.
ThenCheck whether it fits the FDA's general wellness policy for low-risk products and keep marketing claims inside it3.
A single sentence about treating a condition can move the product onto a medical device pathway.
- If
The software diagnoses, monitors or treats a condition, or controls an assistive device for patients.
ThenPlan for a medical device pathway, such as FDA review or conformity assessment under the EU Medical Device Regulation (EU) 2017/745, led by a qualified clinical partner4.
Software documentation, risk files and validation have to be built to that standard from the start, not retrofitted.
- If
An employer or school wants attention, stress or emotion scores.
ThenStop and review the privacy and AI rules first; the neural data privacy laws guide covers the workplace and education restrictions.
Power imbalances make consent weak in these settings, and the EU restricts emotion inference there.
Consented neural data at the center of a BCI system
Every component either produces, transforms or depends on neural recordings, which is why governance cannot be a separate workstream.
- Consented neural data
Recordings and derived features, each tagged with the purposes the participant agreed to.
- Acquisition software
Drivers, synchronization and storage for signals, markers and session metadata.
- Decoding models
Per-user and cross-session models that turn signal into intent, with confidence values.
- Controlled interface
The cursor, speller, game or assistive device the decoder drives, with safe defaults.
- Evaluation evidence
Held-out and closed-loop results, calibration effort and failure cases.
- Regulatory file
Software documentation aligned to the device pathway where one applies.
How a BCI software engagement is usually sequenced
Read the protocol and the claims
Start from the research protocol or product brief and the exact claims it makes. Those two documents decide the paradigm, the regulatory route and the consent model.
Audit hardware and data access
Confirm the recording hardware exposes raw signal and timestamps, list existing datasets and their consent terms, and identify ethics, clinical or regulatory partners.
Build the pipeline baseline
Stand up acquisition, pre-processing and a simple baseline decoder before anything sophisticated, so later improvements are measured against something real.
Validate decoders honestly
Evaluate on held-out sessions and in closed loop, and report accuracy, latency and calibration effort per user, including users the system did not work for.
Package governance and documentation
Deliver the consent model, retention rules, access controls and, for medical uses, software documentation mapped to the device pathway.
What ColdAI builds in neurotechnology, and what it leaves to others
Our part is software and data systems: signal acquisition and processing pipelines, validated decoding models and benchmarks, and neural data governance with regulatory mapping1. We do not design or manufacture implants or electrodes, we do not run clinical studies, and we make no clinical claims. Where a product is a medical device, the clinical partner and the manufacturer lead the regulatory pathway, and our software documentation follows their quality system, typically including a software lifecycle aligned with IEC 623045.
Some projects are better served elsewhere. A team that needs new electrode hardware needs a device engineering firm. A university lab with strong signal-processing expertise may need only extra engineering capacity for a fixed period. A program that is mainly about running a clinical trial needs a clinical research organization. We will say so when that is the case.
BCI work at ColdAI draws on the wider frontier technologies practice, which judges emerging options against a conventional baseline, and on our custom AI model development work for decoder training and evaluation.
How BCI programs lose credibility with funders and regulators
Marketing claims run ahead of evidence
Early signalProduct pages describe mind reading or treatment while the evidence covers a lab task.
MitigationReview every public claim against the evaluation report and the intended regulatory route before publication.
Consent scope creep
Early signalRecordings gathered for one study start appearing in training sets for another product.
MitigationTag purposes at acquisition and enforce them in the data platform, not in a policy document.
Locked to one headset vendor's SDK
Early signalChanging hardware would mean rewriting acquisition and retraining everything.
MitigationPut a hardware abstraction layer between devices and the pipeline, and store data in an open format.
Regulatory documentation started late
Early signalA medical use is planned but design decisions and test evidence were never recorded.
MitigationKeep design records and test evidence from the first prototype if a medical route is plausible.
Frequently asked questions
What does ColdAI deliver in a brain-computer interface project?
Typically three things: a signal acquisition and processing pipeline, validated decoding models with benchmarks, and a neural data governance and regulatory mapping pack. Projects start from a defined research or product protocol, access to recording hardware and datasets, and the ethics, clinical or regulatory partners the work needs.
Does ColdAI work on implanted BCI systems?
Only on the software and data side, alongside the device maker and its clinical partners. We do not design implantable hardware, run clinical studies or make clinical claims. For implanted systems, the manufacturer leads the regulatory pathway and our software documentation follows its quality system.
Is every brain-computer interface a medical device?
No. Whether a BCI is regulated as a medical device depends mainly on its intended use and claims. Research tools and some lifestyle products sit outside device regulation, although privacy law still applies to the recordings. Software that diagnoses, monitors or treats a condition, or controls an assistive device for patients, is likely to be a medical device.
How should BCI decoder accuracy be reported?
Per user and per session, on data the model never saw during training, alongside latency, calibration time and the share of users who could not achieve control. Closed-loop results with real feedback matter more than offline accuracy. The EEG pipeline guide in this section lists the evaluation mistakes that most often inflate results.
Can a brain-computer interface be combined with VR or AR?
Yes. A headset can present stimuli under tight control and show feedback in context, which is why researchers pair the two. It adds timing and electrical-noise challenges, since displays and headsets sit close to the electrodes. Our extended reality practice covers the XR side of such projects.
Sources
- Brain-Computer Interfaces (BCI) — ColdAI
- Implanted Brain-Computer Interface (BCI) Devices for Patients with Paralysis or Amputation: Non-clinical Testing and Clinical Considerations — US Food and Drug Administration
- General Wellness: Policy for Low Risk Devices — US Food and Drug Administration
- Regulation (EU) 2017/745 on medical devices — EUR-Lex
- IEC 62304:2006 Medical device software: software life cycle processes — IEC
Connect the architecture
The next connection.
Explore the complementary capabilities that can turn an individual technology into a complete workflow.
Your next move
Bring us the
real problem.
A workflow that takes too long. A system that cannot connect. An idea that needs a technical path. Start there, and we can define what to investigate, build and measure.
- A defined research or product protocol
- Access to recording hardware and datasets
- Ethics, clinical or regulatory partners