Brain-Computer Interfaces (BCI)

From neural signal to intent, with consent at the center.

ColdAI builds the software side of brain-computer interfaces: acquisition pipelines, signal processing, decoding models and the interfaces they control. We work with research teams and device makers, treat consent and neural data protection as design inputs from the first recording, and leave implants and clinical claims to the regulated device makers and clinical partners who own them.

From architecture to integration to operation
From signal to decoded intentCH1CH2CH3CH4Clean signalElectrodesSamplingArtifactsSyncNon-invasive EEG · research protocol

The opportunity

Start with a decision
worth improving.

A research team records EEG while participants imagine simple movements. It needs a pipeline that cleans the signal, decodes intent in near real time and stores recordings under strict consent terms.

From possibility to a working system

Follow the flow.

Three connected decisions. One considered architecture.

From signal to decoded intentCH1CH2CH3CH4Clean signalElectrodesSamplingArtifactsSyncNon-invasive EEG · research protocol

Conceptual flow, not a live system or measured result.

01

Acquire a clean signal

Specify the sensing modality, sampling, synchronization and artifact handling for the protocol. Non-invasive and implanted systems have very different noise, risk and regulatory profiles.

From signal to decoded intentCH1CH2CH3CH4Clean signalElectrodesSamplingArtifactsSyncNon-invasive EEG · research protocol
ElectrodesSamplingArtifactsSync
02

Decode the intent

Train and validate decoding models per user and across sessions. Report accuracy, latency and calibration effort honestly, because signal drift and individual variation shape what is achievable.

From signal to decoded intentCH1CH2CH3CH4Decoded intentFeaturesDecoderCalibrationLatencyPer-user calibration · near real time
FeaturesDecoderCalibrationLatency
03

Govern the data and the device

Apply explicit consent, minimization and access controls to neural recordings. For medical uses, align software documentation with the device's regulatory pathway and the clinical partner's study design.

From signal to decoded intentCH1CH2CH3CH4Governed recordConsentMinimizeAuditRegulatoryConsent-first neural data handling
ConsentMinimizeAuditRegulatory

The work, made concrete

What we can build
with your team.

We agree scope, dependencies and acceptance criteria before delivery. Your project can start with an assessment, a pilot or an integration into an existing system.

01

Signal acquisition and processing pipeline

Clarify the system boundary, the responsible owners and the decisions the architecture needs to support.

02

Validated decoding models and benchmarks

Turn the agreed design into reviewable work, evaluated against representative inputs and explicit success criteria.

03

Neural data governance and regulatory mapping

Make the next step operable: document responsibilities, known limitations and the path from pilot to ongoing use.

In depth

Go deeper: the signal pipeline and the law around it

One guide follows a non-invasive signal from electrode to command; the other explains which laws already treat that signal as sensitive data.

  1. 01ArchitectureEEG BCI pipeline: from raw signal to real-time decodingA reference architecture for a non-invasive EEG BCI: acquisition and sync, filtering and artifact removal, CSP, Riemannian or CNN decoders and latency budgets.
  2. 02Regulation explainerNeural data privacy laws and consent for BCI productsWhich laws now treat neural data as sensitive, from Colorado and California to the GDPR and Chile, and how to design consent, retention and access to match.

How the recording approach changes the software problem

The sensing method is usually fixed by the research question or the device partner. What it changes for the software team is worth knowing before scoping any work.

ConsiderationScalp EEGOther non-invasive methodsImplanted electrodes
Typical buildersResearch labs, assistive technology startups, consumer neurotechResearch groups and clinical research unitsDevice makers running regulated clinical programs
Signal the software receivesFast but noisy and spatially blurredfNIRS tracks slower blood-oxygen changes; MEG needs a shielded roomRicher signals from surgically placed arrays
Regulatory routeSet by the product claim: wellness, research or medicalMostly research, sometimes medicalMedical device route with clinical studies2
Where software effort goesArtifact handling, calibration, usabilitySignal modeling and slower control loopsDecoder stability, safety interlocks, documentation
ColdAI's rolePipeline, decoders, interface and governanceAnalysis pipelines and decodersSoftware and data systems beside the device maker; no hardware

The last row restates the boundary on this page: ColdAI builds software and data systems, not implantable hardware, and makes no clinical claims1.

Which rulebook a BCI product falls under, set by what it claims

  • If

    Recordings are collected only for a study, with no product on sale.

    Then

    Work under the study's ethics approval and informed consent, and design data handling so recordings can later be reused only where consent allows.

    Research consent written narrowly today decides whether the data can train a product tomorrow.

  • If

    The product promises relaxation, focus or other lifestyle benefits.

    Then

    Check whether it fits the FDA's general wellness policy for low-risk products and keep marketing claims inside it3.

    A single sentence about treating a condition can move the product onto a medical device pathway.

  • If

    The software diagnoses, monitors or treats a condition, or controls an assistive device for patients.

    Then

    Plan for a medical device pathway, such as FDA review or conformity assessment under the EU Medical Device Regulation (EU) 2017/745, led by a qualified clinical partner4.

    Software documentation, risk files and validation have to be built to that standard from the start, not retrofitted.

  • If

    An employer or school wants attention, stress or emotion scores.

    Then

    Stop and review the privacy and AI rules first; the neural data privacy laws guide covers the workplace and education restrictions.

    Power imbalances make consent weak in these settings, and the EU restricts emotion inference there.

Consented neural data at the center of a BCI system

Every component either produces, transforms or depends on neural recordings, which is why governance cannot be a separate workstream.

recordstrainsdrivesheld-out setssupports01Consented neural data02Acquisition software03Decoding models04Controlled interface05Evaluation evidence06Regulatory file
  1. Consented neural data

    Recordings and derived features, each tagged with the purposes the participant agreed to.

  2. Acquisition software

    Drivers, synchronization and storage for signals, markers and session metadata.

  3. Decoding models

    Per-user and cross-session models that turn signal into intent, with confidence values.

  4. Controlled interface

    The cursor, speller, game or assistive device the decoder drives, with safe defaults.

  5. Evaluation evidence

    Held-out and closed-loop results, calibration effort and failure cases.

  6. Regulatory file

    Software documentation aligned to the device pathway where one applies.

Conceptual view of how BCI software components relate to neural data. It is not a deployed system or a measured result.

How a BCI software engagement is usually sequenced

  1. Read the protocol and the claims

    Start from the research protocol or product brief and the exact claims it makes. Those two documents decide the paradigm, the regulatory route and the consent model.

    Output
    Scope note with regulatory route
    Owner
    Sponsor and ColdAI lead
  2. Audit hardware and data access

    Confirm the recording hardware exposes raw signal and timestamps, list existing datasets and their consent terms, and identify ethics, clinical or regulatory partners.

    Output
    Hardware and data inventory
    Owner
    Research or device team
  3. Build the pipeline baseline

    Stand up acquisition, pre-processing and a simple baseline decoder before anything sophisticated, so later improvements are measured against something real.

    Output
    Working pipeline and baseline results
    Owner
    Engineering
  4. Validate decoders honestly

    Evaluate on held-out sessions and in closed loop, and report accuracy, latency and calibration effort per user, including users the system did not work for.

    Output
    Benchmark report
    Owner
    Engineering with the research lead
  5. Package governance and documentation

    Deliver the consent model, retention rules, access controls and, for medical uses, software documentation mapped to the device pathway.

    Output
    Governance and regulatory mapping pack
    Owner
    Privacy and regulatory leads

What ColdAI builds in neurotechnology, and what it leaves to others

Our part is software and data systems: signal acquisition and processing pipelines, validated decoding models and benchmarks, and neural data governance with regulatory mapping1. We do not design or manufacture implants or electrodes, we do not run clinical studies, and we make no clinical claims. Where a product is a medical device, the clinical partner and the manufacturer lead the regulatory pathway, and our software documentation follows their quality system, typically including a software lifecycle aligned with IEC 623045.

Some projects are better served elsewhere. A team that needs new electrode hardware needs a device engineering firm. A university lab with strong signal-processing expertise may need only extra engineering capacity for a fixed period. A program that is mainly about running a clinical trial needs a clinical research organization. We will say so when that is the case.

BCI work at ColdAI draws on the wider frontier technologies practice, which judges emerging options against a conventional baseline, and on our custom AI model development work for decoder training and evaluation.

How BCI programs lose credibility with funders and regulators

Marketing claims run ahead of evidence

Early signalProduct pages describe mind reading or treatment while the evidence covers a lab task.

MitigationReview every public claim against the evaluation report and the intended regulatory route before publication.

Consent scope creep

Early signalRecordings gathered for one study start appearing in training sets for another product.

MitigationTag purposes at acquisition and enforce them in the data platform, not in a policy document.

Locked to one headset vendor's SDK

Early signalChanging hardware would mean rewriting acquisition and retraining everything.

MitigationPut a hardware abstraction layer between devices and the pipeline, and store data in an open format.

Regulatory documentation started late

Early signalA medical use is planned but design decisions and test evidence were never recorded.

MitigationKeep design records and test evidence from the first prototype if a medical route is plausible.

Frequently asked questions

What does ColdAI deliver in a brain-computer interface project?

Typically three things: a signal acquisition and processing pipeline, validated decoding models with benchmarks, and a neural data governance and regulatory mapping pack. Projects start from a defined research or product protocol, access to recording hardware and datasets, and the ethics, clinical or regulatory partners the work needs.

Does ColdAI work on implanted BCI systems?

Only on the software and data side, alongside the device maker and its clinical partners. We do not design implantable hardware, run clinical studies or make clinical claims. For implanted systems, the manufacturer leads the regulatory pathway and our software documentation follows its quality system.

Is every brain-computer interface a medical device?

No. Whether a BCI is regulated as a medical device depends mainly on its intended use and claims. Research tools and some lifestyle products sit outside device regulation, although privacy law still applies to the recordings. Software that diagnoses, monitors or treats a condition, or controls an assistive device for patients, is likely to be a medical device.

How should BCI decoder accuracy be reported?

Per user and per session, on data the model never saw during training, alongside latency, calibration time and the share of users who could not achieve control. Closed-loop results with real feedback matter more than offline accuracy. The EEG pipeline guide in this section lists the evaluation mistakes that most often inflate results.

Can a brain-computer interface be combined with VR or AR?

Yes. A headset can present stimuli under tight control and show feedback in context, which is why researchers pair the two. It adds timing and electrical-noise challenges, since displays and headsets sit close to the electrodes. Our extended reality practice covers the XR side of such projects.

Sources

  1. Brain-Computer Interfaces (BCI) — ColdAI
  2. Implanted Brain-Computer Interface (BCI) Devices for Patients with Paralysis or Amputation: Non-clinical Testing and Clinical Considerations — US Food and Drug Administration
  3. General Wellness: Policy for Low Risk Devices — US Food and Drug Administration
  4. Regulation (EU) 2017/745 on medical devices — EUR-Lex
  5. IEC 62304:2006 Medical device software: software life cycle processes — IEC

Connect the architecture

The next connection.

Explore the complementary capabilities that can turn an individual technology into a complete workflow.

Your next move

Bring us the
real problem.

A workflow that takes too long. A system that cannot connect. An idea that needs a technical path. Start there, and we can define what to investigate, build and measure.

  • A defined research or product protocol
  • Access to recording hardware and datasets
  • Ethics, clinical or regulatory partners
See how we approach delivery
Where are you starting?

Opens your email app with an editable brief. Nothing is sent until you send it.

shayan@coldai.org