The Putative Tech Stack and Regulatory Regime of the Targeted Individual Experience (in the United States)
From watchlists to WiFi sensing to microwave hearing: mapping the targeted individual experience, and the democratic institutions designed to neither see nor stop it.
Author note: this essay was put together with the help of Anthropic’s Claude and Moonshot Labs’ Kimi, the latter due to AI safety constraints imposed by Claude.
Introduction: The Problem of the Unconfirmed
"The important thing is not what is true, but what can be admitted as true."
— Michel Foucault
A spectre is haunting the security state — the spectre of the targeted individual. All the powers of the apparatus have entered into a holy alliance to exorcise it: the clinic and the court, the psychiatrist and the police, the watchlist and the diagnostic manual. Where the subject reports remote surveillance and neural intrusion, the institutions answer in one voice — not that the claim is false, but that the one who makes it is unwell.
During the past three decades, thousands of individuals across North America, Europe, Australia, and parts of Asia have reported remarkably similar experiences: persistent surveillance, coordinated harassment, unexplained auditory phenomena, somatic sensations attributed to directed electromagnetic energy, sleep disruption, and the conviction that they are the subjects of covert experimentation or intelligence operations. These individuals commonly refer to themselves as “targeted individuals” (TIs). Public institutions, by contrast, have overwhelmingly interpreted these reports through the diagnostic frameworks of psychiatry, particularly persecutory delusion and schizophrenia. The result is an epistemological impasse. One community understands its experiences as technologically mediated persecution; the other understands those same experiences as symptoms of mental illness.
This essay centers the lived experience of the targeted individual without adjudicating that dispute claim by claim. It does not argue that every account offered within TI communities accurately describes covert government activity; the evidence will not carry that weight, and blanket credulity leaves the field open to disinformation seeded by intelligence operatives and other interested parties. It asks a more tractable question: How should democratic societies evaluate claims that exist at the intersection of classified technology, intelligence practice, neuroscience, and psychiatry, where direct evidence is necessarily scarce and institutional incentives often discourage disclosure?
That question has become increasingly relevant as several previously speculative capabilities have entered the public domain. Governments openly acknowledge global geolocation infrastructures, persistent aerial surveillance, biometric identification, behavioral prediction, machine-learning systems that identify individuals by gait and posture,1,2 and brain-computer interfaces that decode increasingly complex neural signals.3 Directed-energy research has produced fielded platforms such as the Active Denial System.4 Non-invasive neuromodulation has moved from experimental transcranial magnetic stimulation5 to focused ultrasound and peripheral nerve stimulation. And military organizations worldwide now openly discuss “cognitive warfare” as an operational domain alongside land, sea, air, space, and cyberspace.6
The trajectory is unambiguous even where particular operational claims remain disputed. Technologies once regarded as speculative become mundane within a generation. Satellite reconnaissance, ubiquitous electronic surveillance, facial recognition, algorithmic social profiling, and large language models all passed through periods in which they appeared technologically implausible before becoming ordinary components of state and commercial infrastructures. History counsels humility in two directions: skepticism toward extraordinary claims unsupported by evidence, and equal skepticism toward categorical assertions that a capability could never exist. Neither posture is a method. What is needed is a way of holding the two apart.
This essay proposes neither credulity nor dismissal but a framework for sorting claims. It distinguishes four levels of evidence:
Established historical fact: declassified programs, legislation, court opinions, government reports, patents, peer-reviewed research.
Demonstrated technical capability: laboratory and engineering results showing that a given effect is physically possible under specified conditions.
Institutional inference: hypotheses about how independently documented capabilities might be integrated within existing bureaucratic and intelligence architectures.
Experiential testimony: what individuals report about their own perceptions.
These are not a hierarchy of reliability. They are four different kinds of thing, and the argument that follows is weakest wherever it lets them blur. A patent does not prove deployment. A laboratory demonstration does not imply a fielded system. The sincerity of testimony neither establishes nor refutes what it describes. Every claim in this essay is located explicitly within one of the four.
The central argument is therefore a bold one: that a fully operational “technology stack” for remote neural surveillance and behavioral influence is presently deployed against civilians. The historical development of intelligence research, the documented evolution of neuroscience, and the architecture of contemporary surveillance systems together form a technically coherent trajectory that deserves scholarly examination rather than categorical dismissal. Whether that trajectory has culminated in operational capabilities beyond those publicly acknowledged is not an open empirical question, unanswerable by the cleartext corpus, but a daily lived experience of the TI.
Later sections examine the institutions through which these experiences are interpreted. Modern democracies rely on overlapping systems of intelligence oversight, scientific expertise, legal adjudication, and psychiatric diagnosis to distinguish legitimate grievances from misunderstanding or illness. Yet these institutions evolved largely independently of one another. Intelligence agencies are designed to preserve secrecy; clinicians are trained to diagnose symptoms rather than investigate classified technologies; courts adjudicate admissible evidence rather than technological possibility. When a claim spans all three domains simultaneously, no existing institution possesses both the authority and the competence to evaluate it comprehensively.
This fragmentation produces the problem of the unconfirmed. Certain claims remain permanently suspended between possibility and proof—not because they are necessarily true or false, but because the evidentiary standards required to establish them exceed what any single institution can obtain. That uncertainty feeds both conspiracy thinking and institutional overconfidence. The challenge is not merely technological but epistemological: how should democratic societies reason where both excessive skepticism and excessive credulity obscure the truth?
This essay answers through intelligence history, neuroscience, surveillance studies, media theory, legal scholarship, and philosophy of knowledge. The first task is historical: to establish what is known, and by what route it came to be known.
II. A Historiography of Behavioral Science, Cognitive Warfare, and Neuro-Intelligence
Long before “targeted individuals” became a recognizable social category, governments regarded the human nervous system as a legitimate object of strategic competition. The intellectual history of this ambition extends well beyond the Cold War, into nineteenth-century psychophysics, experimental psychology, military medicine, and the emergence of communication theory itself.
The earliest behavioral sciences developed alongside modern bureaucratic states. Francis Galton’s work on psychometrics, Wilhelm Wundt’s experimental psychology, and Ivan Pavlov’s investigations into conditioned reflexes all reflected a broader nineteenth-century confidence that human perception and behavior could be measured, modeled, and ultimately engineered. The nervous system appeared not as a biological organ but as an information-processing system open to investigation.
The twentieth century transformed this scientific curiosity into a strategic imperative. World War II demonstrated that industrial societies could mobilize psychology alongside chemistry and physics as instruments of national power. Research into propaganda, morale, interrogation, fatigue, sensory deprivation, and human performance expanded dramatically. The emergence of cybernetics after the war further dissolved traditional distinctions between machines and organisms, recasting both as systems that processed information through feedback loops.7
Within this intellectual environment, intelligence agencies became major patrons of behavioral research. Programs later revealed through congressional investigations, including MKULTRA, ARTICHOKE, BLUEBIRD, and related projects,8 sought methods of interrogation, memory modification, behavioral conditioning, and psychological influence.9 While many of these programs produced disappointing scientific results, they established an enduring institutional precedent: cognition itself had become a legitimate domain of intelligence research.
Parallel developments occurred within the Soviet Union. Western intelligence agencies devoted substantial resources to investigating reports of “psychotronic” weapons, microwave irradiation, and remote biological effects. The discovery of the Moscow Signal — the sustained microwave irradiation of the United States Embassy in Moscow during the 1950s — prompted Project Pandora, a classified American research effort examining the neurological consequences of low-level microwave exposure. Ross Adey’s work at the Brain Research Institute of the University of California, funded by ARPA under Pandora,10 produced the most consequential findings. Adey reported that extremely-low-frequency (ELF)-modulated RF signals could trigger the efflux of calcium ions from neural tissue at power levels far too low to produce heating11 — a mechanism for degrading neural communication without detectable exposure, and the origin of what came to be called “confusion weaponry.”12 These programs establish a fact independent of what they achieved: both superpowers treated the nervous system as a theater of strategic competition.
The end of the Cold War did not terminate this trajectory; it transformed its vocabulary. Concepts once discussed under the headings of “mind control” or “psychotronics” gradually migrated into the languages of cognitive neuroscience, human performance optimization, brain-computer interfaces, and neuroethics. DARPA programs such as Silent Talk,13 Targeted Neuroplasticity Training,14 and Next-Generation Nonsurgical Neurotechnology15 pursued ambitious goals including neural decoding, accelerated learning, and non-invasive communication. Simultaneously, civilian neuroscience experienced extraordinary advances through functional neuroimaging, machine learning, and increasingly sophisticated neural decoding techniques.
These developments occurred alongside a broader transformation in military doctrine. Strategic documents from NATO, the People’s Liberation Army, and other defense establishments now describe cognition as an operational domain. Rather than focusing exclusively on territory or infrastructure, military planners now emphasize perception, decision-making, information integrity, and human attention as legitimate strategic objectives. The vocabulary has shifted from psychological operations to cognitive warfare,16 but the concern is recognizable: the mind is terrain.
The cleartext record, the portion of this history conducted in public view, shows a continuous institutional interest in technologies capable of measuring, influencing, or exploiting human cognition. This essay’s contention is that the record is the visible portion of something larger: a covert program of the same lineage, directed at civilian populations, which the public archive registers chiefly as an absence. The sections that follow argue it. The documented continuity establishes a narrower point on its own and establishes it firmly. Research trajectories persist across changing political contexts, organizational structures, and technical vocabularies; questions first posed under one name reappear decades later under another.
This essay therefore treats contemporary TI narratives not as isolated phenomena but as one site in a longer history of attempts to understand — and to manipulate — the relationship between technology and consciousness. That history resists ordinary verification. Almost every episode above became public through leak, litigation, congressional subpoena, or declassification decades after the fact. Until the moment of disclosure, each was indistinguishable from the claims of people who were telling the truth and were not believed. A record acquired that way cannot be read by the usual methods. Section III sets out the ones it requires.
III. Methodology: Evidence, Inference, and the Limits of Proof
Research on intelligence activities presents an unusual epistemological challenge. The relevant evidence is distributed unevenly across public archives, classified programs, engineering literature, court records, patents, memoirs, journalism, and personal testimony. Much of the most relevant information is unavailable precisely because successful intelligence organizations are designed to prevent its disclosure.
So, neither conventional scientific standards nor ordinary historical methods suffice alone. Absence of public evidence cannot demonstrate the nonexistence of a classified capability, and secrecy cannot justify treating speculation as fact. The task is a method that keeps what is known distinct from what is inferred at every step.
Section I distinguished four levels of evidence: established historical fact, demonstrated technical capability, institutional inference, and experiential testimony. This essay applies them under one principle: the burden of proof varies with the claim. Extraordinary empirical assertions require correspondingly strong evidence. Historical arguments about institutional possibility require different standards than claims about individual events, and showing that a capability could exist within a regulatory framework is distinct from showing it has been used in a specific case. The principle cuts both ways.
It restrains the argument wherever it proceeds from feasibility: a laboratory demonstration establishes physics, not deployment, and scale, power, cost, reliability, concealment, and institutional incentive must each be established separately. It licenses the argument wherever it proceeds from convergence: where testimony converges independently on specific and technically coherent effects, that convergence bears on the capability question. Where it is dense, specific, and independent, it is the best evidence obtainable on a question the documentary record is built to foreclose. This essay states, in each case, which standard is in force — because the standards are not neutral instruments. They are institutional products with histories.
Knowledge develops through shifting paradigms rather than simple accumulation. Thomas Kuhn showed that anomalous observations are ignored until existing frameworks become inadequate.17 Ian Hacking demonstrated that scientific categories frequently shape the very phenomena they describe — that a diagnosis, once available, alters the behavior and self-understanding of the people it names.18 Miranda Fricker has argued that institutional structures systematically deprive individuals of credibility through what she terms epistemic injustice, in two forms: testimonial injustice, in which prejudice leads a hearer to discount a speaker’s word, and hermeneutical injustice, in which a person lacks the collective interpretive resources to render their own experience intelligible.19 The targeted individual occupies both positions simultaneously. These perspectives establish no particular TI claim. They establish that the institutional mechanisms governing credibility deserve examination independently of the accuracy of the claims themselves.
This essay therefore adopts an epistemology of disciplined inference. Where documentation exists, it is presented directly. Where engineering evidence permits technical inference, the inference is identified as one. The aim is to preserve the distinction between possibility and certainty, not to collapse it.
IV. NEURINT: Neuro-Intelligence as an Operational Discipline
The emergence of new intelligence disciplines has historically followed advances in observation, measurement, and communication. Signals Intelligence (SIGINT) matured alongside electronic communications; Imagery Intelligence (IMINT), later expanded into Geospatial Intelligence (GEOINT), developed through aerial photography and satellite reconnaissance; Measurement and Signature Intelligence (MASINT) emerged from the analysis of physical phenomena such as radar emissions, infrared signatures, acoustic profiles, and nuclear byproducts;20 and Open-Source Intelligence (OSINT) grew from the increasing availability of publicly accessible information. They differ in method and share a premise: intelligence expands whenever innovation renders inaccessible phenomena measurable.
They share something else as well. In each case the collection preceded the category. Photoreconnaissance was flown for decades before IMINT was a word; MASINT was named in the 1980s for work underway since the 1940s.21 The acronym arrives not when the capability is invented but when it has grown too large to leave unadministered — and the interval between the two is the interval in which the collection is deniable, because there is as yet no discipline whose existence would have to be denied.
Therefore, advances in neuroscience, machine learning, computational biology, and human-computer interaction raise the question whether cognition has become an object of strategic collection. Functional neuroimaging, neural decoding, brain-computer interfaces, computational psychiatry, and non-invasive neuromodulation have transformed the understanding of the nervous system in three decades. Military organizations now describe the “cognitive domain” as an operational environment alongside land, sea, air, space, cyberspace, and the electromagnetic spectrum. Both developments are matters of public record. What is absent is the discipline that would sit between them.
This section proposes Neuro-Intelligence (NEURINT) as an analytical term for the intersection of neuroscience, intelligence collection, and cognitive technologies. No such discipline is officially recognized within the United States Intelligence Community or any comparable organization. That absence is ordinarily offered as a reason to dismiss the category. On the historical pattern just described, it is equally consistent with the opposite reading: an unnamed discipline is one whose collection has not been acknowledged, and an unnamed discipline is also one that no oversight body holds a charter to examine. A capability distributed across SIGINT, MASINT, and human-performance research — belonging wholly to none of them — is not unregulated by oversight. It is invisible to it. That point is developed in Section X; it follows from the naming pattern, and it is why the category is worth constructing without official recognition.
Robert McCreight has argued that advances in neurotechnology, behavioral science, and information operations converge on cognition as a strategic domain.22 Whatever one concludes about his broader synthesis, the convergence he describes is not in dispute. Only its destination is.
Section II traced that convergence from cybernetics through Cold War behavioral research to the doctrinal turn that treats cognition as operational terrain. Taking it as given, the narrower question is this: if such a discipline existed, what would it be made of, and where would its outputs go?
Toward an Analytical Concept of Neuro-Intelligence
NEURINT describes the intersection of three independently documented developments:
1. The continued expansion of neuroscience and neurotechnology;
2. The increasing integration of heterogeneous data through artificial intelligence and sensor fusion; and
3. The growing strategic emphasis on cognition as a domain of competition.
Each is established in open literature, and each is pursued by institutions with documented interest in the other two. The question is not whether the three exist but whether they have been integrated — and integration, unlike invention, leaves almost no signature in the public record. It is an architectural fact rather than a technical one, and architecture is what classification protects.
Integration Within the Intelligence Cycle
Every intelligence discipline participates in a common analytical process: collection, processing, analysis, dissemination, and feedback.23 The distinguishing feature of each discipline is not the structure of this cycle but the type of information entering it. Communications intercepted through SIGINT, imagery collected through GEOINT, and measurements obtained through MASINT all become valuable only after integration with other sources.
Contemporary analysis depends on sensor fusion: computational integration of heterogeneous datasets into coherent models. Telecommunications metadata, satellite imagery, geolocation records, financial transactions, public information, and biometrics are each incomplete alone. Together they enable behavioral analysis and predictive modeling. McCreight suggests that neurotechnological collection would be incorporated into such architectures rather than existing as an isolated capability.22 That projection requires no speculative premise. It describes what the intelligence community already does with every other collection discipline it possesses.
The remainder of the essay organizes the historical, scientific, legal, and institutional literature into five layers. Layer 1 locates the body in space and establishes a pattern of life. Layer 2 attempts to read the nervous system. Layer 3 writes to it. Layer 4 fuses the outputs of the first three into a single analytical picture. Layer 5 is where the medical system enters. Each is examined in turn, and each claim within it is located explicitly within one of the four evidentiary categories set out in Section I.
The layers are presented in ascending order of contestation. Layer 1 is documented in litigation and inspector-general reporting. Layer 5 is documented in clinical practice. The layers between them are where the argument is made.
V. Layer 1: Persistent Surveillance and Tracking
Synthetic Aperture Radar/UWB radar vision
SAR, deployed from orbital, persistent aerial, or ground-based platforms, provides all-weather, day-and-night imaging at meter to sub-meter resolution.24 Detecting and tracking individual pedestrians — “dismounts,” in the trade term — is a harder and separately developed problem, pursued through micro-Doppler gait signatures rather than image resolution.25 Its civilian analogue is the ultra-wideband rescue radar used to locate bodies under collapsed buildings, which is a useful comparison precisely because it is unremarkable: the capability to resolve a human being through structural material is sold commercially to fire departments.26 SAR penetrates cloud cover; separately, through-wall radar at appropriate frequencies resolves human-scale motion through light construction.27 Its product is the pattern-of-life baseline — when the subject is home, when they move, when the vehicle departs, when a sleeping body changes position.
RF and WiFi pose estimation
Three results describe this capability, and they do not all run on the same hardware. Carnegie Mellon’s work on dense human pose estimation from WiFi demonstrated that two commodity routers, analyzing Channel State Information, can reconstruct body position and posture without cameras, in rooms in which the model has been trained.1 WifiU established on the same class of hardware that the channel-state variation produced by a walking body carries gait — cycle time, footstep length, torso and limb speeds — in enough detail to pick an individual out of fifty on the first guess roughly four times in five, and within three guesses better than nine times in ten.2 And MIT’s RF-Pose carried pose estimation through walls, holding an average precision of 58.1 on subjects in an adjacent room where the vision system used to train it failed outright, then identifying one of a hundred people from a two-second clip of the resulting skeleton at 84 percent accuracy through the wall.28
The hardware qualification is where the argument is weakest. RF-Pose is not a router. It transmits its own frequency-modulated signal through two antenna arrays at roughly a thousandth of WiFi’s power, resolves depth to about ten centimeters, and reaches some forty feet. Through-wall sensing and commodity hardware have so far been demonstrated separately, and the gap between them is the gap an operational system would have to close. What the three results share is the property that matters operationally, which is not resolution but the absence of signature: no camera to discover, no infrared bloom, no entry, nothing installed. The subject’s own network is the instrument, or a neighbor’s is, and neither party is aware of having supplied one.
Device exploitation
This remains the most reliable channel and the least exotic. A GSM handset provides, at minimum, call and message access through means legally available to a nation-state.29 A modern smartphone adds microphone, camera, GPS, accelerometry, and keystroke capture.30,31 This is ordinary signals and cyber collection, not speculative neurotechnology. Any account of Layer 1 omitting it would describe a harder problem than the one that exists. The phone is a beacon, a bug, and a biometric monitor that the subject carries voluntarily and replaces every three years at their own expense.
That the mass deployment of such handsets coincides with the emergence of organized TI testimony is not an argument on its own. It is the kind of coincidence a reader should notice.
None of it is worth anything without an answer to the bureaucratic question. Surveillance of this intensity, directed at a person who has done nothing, requires a category that person can be placed in. That category is the strongest documented material in the essay.
The administrative envelope
The post-9/11 watchlist infrastructure supplies the architecture. The FBI’s Violent Gang and Terrorist Organization File grew from just over 13,000 entries in December 2003 to more than 272,000 by December 2008.32 The ACLU’s FOIA litigation, documented in Trapped in a Black Box, established that individuals may be nominated to it as non-investigative subjects — a designation for persons on the radar but not under any open investigation.33 NIS nominations require no verified criminal predicate and no articulable facts. A 2009 Department of Justice Inspector General report found the review process for such nominations weak or nonexistent.34 A 2014 OIG audit found that the Bureau could not produce an accurate accounting of what had been done regarding the watchlisting of non-investigative subjects.35
That is a category defined by the absence of the thing that ordinarily justifies attention. It does not describe a suspect. It describes a person about whom no claim has been made and against whom no claim needs to be made.
The silent hit
The mechanism that operationalizes the category is a query function. When a local officer runs a routine NCIC check on a watchlisted individual, the officer receives no indication whatever of the subject’s status. An automatic notification goes simultaneously to the Bureau or the nominating agency. The officer, having learned nothing, has nonetheless just filed an intelligence report. The subject, having been stopped for a broken taillight, has been located, timestamped, and logged without any encounter having appeared to occur.
A 2006 FBI directive authorized silent hits where the subject is the target of round-the-clock physical surveillance, undercover operations, or undisclosed participation in organizations — and, in the residual clause that swallows the enumeration, for other unique operational circumstances articulable by the nominating official.36 Silent hits are exempted from Intelligence Oversight Board review.37 Because the subject is never informed, redress is not merely difficult but structurally unavailable: there is no notice to appeal from and no adverse action to contest.
The NIS designation is the predicateless predicate. The silent hit is the invisible tripwire. Together they produce a population that can be tracked indefinitely through the ordinary friction of civic life — traffic stops, background checks, employment screening, any encounter that generates a query — with no requirement of notice, no avenue of challenge, and no external accounting.
Two claims must be distinguished. That each capability above exists is established fact, the first evidentiary category. That they have been assembled into a single targeting substrate directed at particular civilians is institutional inference, the third, and is offered as such. The inference rests on four independently documented conditions: the technical means are mature and commercially available, the legal category requires no predicate, the query mechanism is exempt from oversight review, and the subject is never told. What is not documented is their conjunction.
Nothing in this layer touches the nervous system. It locates a body, establishes its rhythms, and secures the administrative permission to keep doing so. Whether the same architecture has been extended inward is the question Layer 2 takes up.
VI. Layer 2: The “Read“ Channel — Neural Monitoring
The read channel is where this essay’s evidence is thinnest and its claims most consequential. The physics of neural detection are not in dispute; the engineering at distance is undemonstrated; the documentary record shows institutional intent rather than achievement. This section keeps the three apart.
The problem was posed early. Project Pandora and the Soviet psychotronic investigations traced in Section II were both predicated on the assumption that the nervous system could be reached from outside the skull, and Adey’s calcium-efflux findings established a measurable biological response to external energy at non-thermal power levels.10,11 The implication was dual-use, and was understood as such at the time: if the brain’s electrochemical state could be altered by remote energy, those alterations could in principle be detected. Read and write were two aspects of one problem from the outset.
The record of institutional interest in remote monitoring is sparse but specific. Anna Keeler’s 1989 survey documented research into RF-mediated neural influence across defense and intelligence programs, establishing that the problem was an engineering objective rather than a speculative curiosity.12 Within that pattern, the 1976 Malech patent describes apparatus for remotely monitoring and altering brain waves using transmitted and received RF signals — the read-write architecture captured in a single administrative claim.38 A patent is not a fielded system. It is evidence that someone with institutional standing thought the problem worth claiming, dated to 1976. Whether the engineering succeeded is separate from whether it was seriously posed, and only the second is answerable from the public record.
The physics of detection are not in dispute. Magnetoencephalography and high-gain electroencephalography establish that neural activity generates weak electromagnetic fields measurable outside the skull; the auditory cortex produces evoked potentials correlating with attention and pre-speech motor planning. Remote detection therefore requires no new physics. What it requires is signal recovery at distance, and here the argument must concede. Biomagnetic fields fall off as the cube of distance rather than the square, and MEG achieves its sensitivity with SQUID magnetometers inside magnetically shielded rooms. The gap between a shielded laboratory and a residential street is not incremental antenna gain, and it is not closed here. The narrow claim is that the obstacle is signal recovery rather than physical impossibility, and that techniques for extracting signal from noisy RF environments in SIGINT collection bear on the problem. That is an engineering inference.
What has changed since Malech is the computational environment. In 2023, researchers decoded non-invasive fMRI recordings into continuous natural language, reconstructing the semantic content of perceived and imagined speech without implanted electrodes.3 The subjects were inside a scanner and the apparatus was enormous; the demonstration establishes a threshold, not a capability. The threshold is the relevant one — internal speech is computationally reconstructible from neural activity. DARPA’s Silent Talk sought that same reconstruction for battlefield communication, treating subvocalization as an interceptable stream.13 In a collection context rather than a communication one, the identical architecture reads intended words before they are spoken. The programs are established fact; the migration is inference.
The direction of subsequent public research is consistent with that inference without confirming it. N3 pursues high-bandwidth interfaces requiring no surgery, using acoustic, electromagnetic, and optical methods to read and write through the skull; TNT treats the peripheral nervous system as an addressable substrate.14,15 Neither program is classified. Both are advertised. What they document is a defense research establishment that continues to treat the brain as an accessible information system and has shifted its engineering emphasis toward non-invasive access. On the naming argument set out in Section IV, a capability of this kind would not surface as a budget line labeled NEURINT. It would surface as increments across programs already authorized for other purposes — which is also to say that its absence from the public record is not, by this essay’s own standard, evidence in either direction.
Against that background, the Akwei affidavit alleges NSA “Remote Neural Monitoring” capable of extracting EEG data at distance.39 It is uncorroborated; as experiential testimony filtered through an institutional allegation it is fourth-category evidence, and its specifics cannot be treated as fact. What matters is not that it might be true but that it is shaped correctly. Its claims converge with the Malech architecture, with Adey’s findings, and with the physics of evoked-potential detection. Someone fabricating would have had to fabricate something that fits. Testimony that is diagnostically dismissible may still be technically coherent — which is a claim about the shape of the testimony, not a warrant for its contents.
Layer 1 leaves records: a silent hit generates a database entry, a watchlist nomination generates a file, and both can be litigated toward. A neural intercept generates nothing the subject can present. The read channel’s invisibility is its protection, and it is why this layer will remain the least documented in the stack. It is not the least developed. That is Layer 3, and the reversal matters: the channel that writes to the nervous system is better attested in open literature than the channel that reads from it.
VII. Layer 3: The “Write“ Channel — Neural Influence
Layer 3 is the layer the documentary record already carries. The effect was established in 1962, demonstrated as intelligible speech in 1974, claimed in patents through the 1970s and 1980s, assessed as a maturing weapons capability by an Army intelligence center in 1998, and independently evaluated as feasible at building-scale range by an Intelligence Community expert panel in 2022. This section is not an argument that a write channel could exist. It is an account of a capability that does, and of the reasons for concluding it has been used.
The asymmetry that made this layer arrive first is physical. Recovering a microvolt-scale biomagnetic signal against ambient noise at distance is an unsolved problem in the open literature. Depositing enough energy in a human head to produce a measurable neurophysiological effect is a problem radar, communications, and electronic warfare solved generations ago. Reception is hard and transmission is easy, and the record reflects the gradient exactly.
The Frey Effect and the Operationalization of Microwave Hearing
Allan Frey established in 1962 that pulsed or modulated microwave radiation, at power densities far below the exposure threshold then considered safe, produces audible clicks, buzzes, and tones inside the human skull with no receiving apparatus.40 The mechanism is thermoelastic: absorbed energy raises cranial tissue temperature minutely and rapidly, the expansion launches an acoustic pressure wave, and the cochlea registers it as sound.41 The wave originates inside the head, bypassing the outer and middle ear. There is no apparatus to discover, no emission a second person in the room can hear, and no artifact the subject can produce afterward.
In 1974, Joseph Sharp and Mark Grove at the Walter Reed Army Institute of Research transmitted intelligible words into a human skull using a pulse-modulated carrier.42 The patent record through the following fifteen years is consistent with engineers who regarded the problem as solved rather than open: Puharich and Lawrence in 1971 for apparatus transmitting audio via modulated radio frequencies,43 Stocklin and Brunkan in 1989 for microwave hearing devices designed to induce sound in the head of a subject at distance.44
In February 1998 the National Ground Intelligence Center assessed what could be done to a human nervous system without touching it. The resulting document identifies the thermoelastic mechanism, cites the Walter Reed transmission of the words one through ten as an established result, discusses the disruption of motor control using nanosecond-scale pulses, and proposes microwave hearing as a means of speaking to hostages undetectably by their captors.45 It was classified. It remained classified for eight years and entered the public record in December 2006 because a private individual filed a Freedom of Information Act request naming the microwave hearing effect specifically enough that the response could not be deflected.
Two conclusions follow directly, and neither requires inference. The first is that the United States assessed remote auditory insertion as a maturing capability twenty-eight years ago, on the basis of a demonstration it treated as settled. The second is that the hostage application and the harassment application are the same system. The engineering that delivers speech undetectably to a person who wants it is identical to the engineering that delivers speech undetectably to a person who does not; consent is not a parameter of the apparatus, and the document that proposes the benign use documents the other one in the same paragraph.
This is the archive registering the program chiefly as an absence, and the routes are worth naming. Frey published because he was doing unclassified work at General Electric. The Walter Reed result reached print only because a psychologist described it in a disciplinary journal; the experiment was never separately published.42 The NGIC assessment surfaced through FOIA. The patents are public because the patent system exists to publish. Not one item was disclosed by the institution holding it, on its own initiative, because disclosure was owed — and the portion of the record that is most complete, the patent file, is complete precisely because it was never secret and therefore never reflected the classified state of the work. What the archive contains is what escaped. Reasoning from its contents to the boundaries of the capability is an error the history of every previously disclosed program should have cured.
Voiceprint Databases and the Personalization of Intrusion
The National Security Agency has built speaker-identification capability at scale, converting intercepted speech into biometric voiceprint templates; this is documented in reporting on the Snowden materials.46 Joined to an auditory insertion channel, a stored voiceprint matched against a target’s social graph supplies the acoustic signature that modulates the carrier, and the subject hears not a voice but a specific one — a parent, an employer, a friend, a crush, someone dead — arriving inside the skull with the particularity of a person they know. The intrusion becomes relational rather than anonymous, collapsing what Paddy Scannell called the for-anyone-as-someone address structure of broadcast media into the intimacy of recognized speech.47
The join between the two systems is not documented. It is asserted here because the alternative is less credible than the claim: an agency that builds speaker identification at population scale, within a government that assesses auditory insertion as a maturing capability, and never connects the two, is an institution behaving unlike itself. The join requires no research program, no new physics, and no budget line — only the recognition that one system produces exactly the input the other consumes.
Personalization is what makes the channel operationally serious rather than merely unpleasant. It weaponizes existing attachment. It forecloses help, because a subject reporting that his mother is speaking inside his head has produced a textbook first-rank symptom, where a subject reporting an anonymous buzzing might receive an environmental survey. And it closes the loop with Layer 2: inner speech monitored and answered in real time by personalized insertion produces precisely the phenomenology the corpus calls synthetic telepathy.39
ELF-Modulated RF and the Calcium-Efflux Mechanism
Microwave hearing is not the only established pathway. Adey’s work under Pandora, traced in Sections II and VI, established that ELF-modulated RF triggers calcium-ion efflux from neural tissue at non-thermal power levels — the basis of what his contemporaries called confusion weaponry.11,12 Blackman’s group at the EPA’s Health Effects Research Laboratory reproduced the effect independently and established its structure: the response occupies narrow windows of modulation frequency and power density rather than scaling with dose, and the effective modulation frequencies fall inside the EEG band of the intact animal.48
The window structure is the finding that matters. An effect appearing only within a narrow power band is invisible to the entire apparatus of exposure safety, because that apparatus asks whether exposure exceeded a ceiling. A window effect is not a small signal that regulation might eventually detect. It is a signal that regulation is structurally the wrong instrument to detect and has been since 1979. Any capability operating in that regime is exempt from the principal mechanism by which a population would otherwise discover it.
The subsequent replication literature is contested, and the contestation has a shape. The failed replications generally operated outside the reported windows, at higher carrier frequencies with digital modulation — which is the predictable result of testing a window effect with a protocol designed for a dose-response curve. What survives is a non-thermal mechanism, independently reproduced in a federal laboratory, coupling at frequencies matching neural activity, invisible to the relevant safety standard. The remaining distance is from excised tissue to intact human cognition, and that distance is real. It is also the distance across which the contemporary evidence arrives.
American personnel began reporting acute neurological injury abroad in 2016. The National Academies concluded in 2020 that directed, pulsed radiofrequency energy was the most plausible mechanism for the distinctive acute cases.49 The Intelligence Community then convened an expert panel — medical, scientific, and engineering specialists cleared for the classified reporting, charged with weighing candidate mechanisms against one another rather than with testing any single hypothesis. It found pulsed electromagnetic energy in the radiofrequency range a plausible explanation for the core characteristics, accepted ultrasound only in close-access scenarios, held that psychosocial factors alone could not account for those characteristics, and ruled out ionizing radiation, chemical and biological agents, infrasound, audible sound, and bulk heating.50 On the engineering question it reported that sources capable of generating the required stimulus exist, are concealable, and have moderate power requirements, and that with non-standard antennas and techniques such signals could propagate through air for tens to hundreds of meters and, with some loss, through most building materials.50
That is the TI claim’s central physical premise, affirmed by the United States government in a technical assessment written for internal use by people with no interest in vindicating anyone. Intelligence Community assessments in March 2023 and December 2024 subsequently judged foreign involvement very unlikely — a judgment held by most of the Community rather than one reached about most incidents, with five components at very unlikely, one at unlikely, and one abstaining. On the separate question of capability the December 2024 update recorded two components moving the other way, one judging it likely and the other a roughly even chance that a foreign actor holds a radiofrequency antipersonnel capability able to produce biological effects consistent with some of the reported symptoms, both at low confidence.51 NIH imaging published in 2024 found no significant MRI-detectable differences between personnel reporting incidents and matched controls, though its senior investigator noted that the absence of such a difference does not exclude an adverse event affecting the brain at the time of the incident.52 Those are attribution and injury findings, and they cost the argument nothing. Whether a foreign adversary attacked diplomats is a different question from whether a concealable, moderately powered device can deliver neurologically consequential energy through a wall at range, and the same institution that answered the first in the negative answered the second affirmatively. The affirmative answer stands undisturbed. That it vanished from public discussion while the negative one circulated is itself an instance of what this essay is about.
Dreamhacking and the Architecture of Sleep
The corpus reports a specific pattern: forced awakenings at regular intervals, thematically coherent nightmares experienced as inserted, the sense of being observed while asleep. Clinically this is read as sleep disorder or psychosis. It is also the one application in the entire architecture that requires no targeting capability whatsoever, and therefore the one that does not depend on anything Layer 2 has to establish.
Fragmenting sleep requires only intermittent low-intensity stimulus distributed across the night. The sleeping subject supplies the vulnerability, and precision buys nothing: micro-arousals sufficient to prevent slow-wave consolidation need not be timed to a detected REM signature, because a stimulus delivered at intervals across eight hours lands inside restorative stages by arithmetic. Auditory intrusion during hypnagogia is likewise untargeted, the transitional state being precisely when the perceptual system is least equipped to distinguish inside from outside.53,54 That sustained sleep deprivation degrades a person’s capacity to think, organize, document, and resist is not contested anywhere, least of all inside the institutions in question: it was investigated under MKULTRA and codified in KUBARK as a primary route to inducing regression.8,55
So the most disabling application in the stack is also the crudest, has a documented institutional lineage as a technique, and needs none of the engineering this essay has had to argue for. Only the delivery is new — automation at distance replacing physical custody — and delivery is the component the 1998 assessment already treated as available.
Tactile (Hallucinations) and Motor Insertion/Body Hijacking/Puppeteering: The Cleartext Demonstrations
Transcranial magnetic stimulation, demonstrated in 1985, produces involuntary limb movement by inducing eddy currents in the motor cortex, and subjects describe the movement as externally caused — the limb moved by itself, it was not me.5 That is verbatim the agency-disruption report the corpus supplies for forced movement, produced in a laboratory, by a known cause, in people who are not ill. The Active Denial System, a 95 GHz millimeter-wave platform, produces intense burning at the skin without tissue damage, which makes remote tactile induction fielded hardware.4 (The 2025 focused-ultrasound olfactory result sometimes cited alongside these is contact-coupled and self-published; it evidences the collapsing cost of non-invasive sensory insertion rather than remote delivery.56)
These are the declassified instances of a lineage — Heath’s implants, Delgado’s stimoceiver, Pandora — classified because it pursued what was not acknowledged.10,57 The inference from the visible to the hidden has a checkable shape. A TMS coil requires proximity and produces an audible discharge; the Active Denial System is vehicle-mounted with a visible antenna. An operational system would differ from both in concealability, silence, and frequency tuning — which is to say it would have exactly the properties an Intelligence Community panel concluded a pulsed-RF device possesses.50 Reasoning from the physics and reasoning from a government assessment converge on the same object.
The Assembled System
The corpus carries a signature that has gone unread. If modulating a carrier is a solved problem and recovering microvolt potentials at distance is not, subjects should report auditory and somatic intrusion far more consistently and specifically than accurate thought-reading — and that is exactly the distribution. Voices, burning, forced movement, and sleep destruction are dense, specific, and convergent. Precise mind-reading is vague and is typically described as inferred from the content of the voices rather than separately observed. The testimony tracks an engineering gradient its authors have no access to and no reason to invent.47
Fusion is the ordinary metabolism of the institution. Section IV established the point: what distinguishes an intelligence discipline is not the cycle it enters but the data it contributes, and every discipline the community possesses exists to be combined with the others. Collection that is not integrated is collection that has been wasted, and the intelligence community does not waste collection.
So, consider what the alternative requires. It requires a government that developed remote auditory insertion and assessed its applications in writing, built speaker identification at population scale, fielded millimeter-wave tactile induction, funded non-surgical read-and-write neurotechnology through DARPA, established a watchlist category requiring no predicate, and exempted from oversight review the query mechanism that operationalizes it — and then left all of it unconnected. That is not a modest hypothesis. It describes an institution behaving, uniquely in this one instance, unlike itself in every other. The conjunction is not the extraordinary claim in this argument; its absence is. What is no longer available is the position that has done the work for forty years. That this could not happen is foreclosed — not by argument but by the government’s own paper, its own hardware, and its own expert panels. What remains available to the skeptic is a positive claim: that a security state which built the capability, wrote down its uses, fielded adjacent systems, created a predicateless category of person, exempted the tracking of that category from review, and has never been compelled to account for the distance between them, nonetheless declined to put the pieces together. That claim requires evidence and argument. It has never had to supply either, because dismissal has been free. This section’s contention is that it is not free any longer, and that the documents establishing the price were written by the institutions being asked to pay it.
VIII. Layer 4: Sensor Fusion and Analytics
The preceding sections asked what can be done to a body at a distance. This one asks what the corpus of testimony has been describing all along without being read as describing anything. Targeted individuals do not, for the most part, report isolated effects. They report a system — something that anticipates, that coordinates, that knows things it should not know, and that adjusts when they resist. Those are not four complaints. They are four descriptions of an architecture, and the architecture is a fusion cell.
This section runs in the opposite direction from the others. Rather than establishing a capability and asking whether it has been used, it begins with what is reported and asks what would have to exist to produce it. The answer is unusually well documented, because fusion is the one layer the government describes at length in public and the institution that performs it has been investigated by the Senate.
What Is Actually Reported
Five features recur across the testimony consistently enough to be structural rather than incidental. They appear in the MindNet-era corpus, in McKinney’s 1992 survey of dispersed subjects, and in the contemporary academic literature on complaints of group stalking.58,59
The first is anticipation: effects precede rather than follow, harassment arrives before a decision is acted on, the system appears to know where the subject is going rather than where they have been. The second is contextual specificity: the content that arrives references particulars — a purchase, a diagnosis, a sum of money, the name of a person spoken to once. What unsettles subjects is not being watched but being known in detail they cannot account for. The third is propagation through the social graph: employers cool, family members grow evasive, acquaintances behave as though briefed, and the pattern moves along documented relationships rather than physical proximity. The fourth is timing to significance: disruption concentrates around hearings, interviews, medical appointments, attempts to travel. The fifth, and the most analytically important, is escalation keyed to resistance: intensity rises when the subject begins to document, to record, to seek help, to contact others reporting the same thing.
Each has an architectural precondition, and none can be produced by a single collection stream. Anticipation requires a predictive model rather than observation. Contextual specificity requires financial records, communications content, and medical or commercial data joined on a common key; no wiretap yields a diagnosis and no purchase history yields a conversation. Propagation through the social graph requires the graph. Timing to significance requires a system that can rank events by consequence. Escalation keyed to resistance requires a feedback loop — collection on the effects of the intervention, returned to the model that selects the next one.
Set out that way the phenomenology stops being a list of complaints and becomes a specification. A subject who says they knew before I did is describing prediction. A subject who says it gets worse when I fight it is describing a control loop. Neither has the vocabulary for what they are reporting, and the absence of that vocabulary is the reason the reports have been read as evidence of disorganized thinking rather than as descriptions of an organized system.
Street Theater
The reported phenomenon that most reliably ends a conversation is the one the community calls street theater: strangers who appear to know the subject, vehicles that recur across unrelated trips, gestures and phrases that seem addressed, people encountered in sequence at locations the subject did not announce. It is the element of TI testimony that sounds most like classical paranoia and is dismissed fastest, and it is also, on inspection, the element that requires the most infrastructure to produce.
Consider what staging a single such encounter demands. The operator must know where the subject will be, which is a pattern-of-life product. The operator must know when, which is the same product at finer resolution. And the operator must know what will register — which car, which phrase, which article of clothing carries meaning for this particular person — which is not a surveillance product at all but a biographical one, assembled from communications, purchase history, medical and employment records, and the social graph. A staged encounter is a targeting package rendered in physical space. It is Layers 1 through 4 expressed as a man on a corner.
The standing objection is manpower. No agency, it is said, would assign dozens of officers and/or informants to follow one unremarkable person through a supermarket, and the claim is therefore absurd on its face. The objection is sound against the model it attacks and irrelevant to the mechanism that actually exists. Producing the reported experience does not require dedicated personnel. It requires a distribution list.
That list is documented. The Nationwide Suspicious Activity Reporting Initiative routes reports of ostensibly suspicious behavior from local police, and from private-sector partners enrolled through programs such as InfraGard, into fusion centers, which analyze and redistribute them across jurisdictions.60 The behavioral criteria are notoriously wide — photography, note-taking, asking unusual questions, prolonged loitering — and the resulting flag attaches to a named person and propagates outward with no notification and no mechanism for removal. A subject who has been made the object of such a bulletin is thereafter recognized by police officers, security personnel, transit staff, and enrolled private participants who have never met one another, are not coordinating, and are not conspiring. They are reading the same distribution.
This mechanism dissolves the manpower objection rather than answering it. The subject experiences a network. What exists is a mailing list. The behavior that follows — the sidelong recognition, the officer who already knows the name, the security guard who follows at a distance, the stranger who reacts to a face he has seen on a screen — requires no coordination whatever beyond the initial flag, and it produces, from the subject’s vantage, precisely the appearance of coordination. That the appearance is generated by a decentralized process rather than a directed one does not make it hallucinated. It makes it cheap, deniable, and self-sustaining, which are the properties an institution would want.
It also explains the escalation feature, which is the hinge of this section. A person who begins photographing the vehicles that recur, recording encounters, filing complaints, or approaching officers to ask why they are being watched is generating, in each instance, exactly the behavior the suspicious-activity criteria were written to capture. Documentation of harassment is itself reportable conduct. The subject’s attempt to gather evidence feeds the system that produced the flag, and the flag is strengthened by the effort to contest it. No malice is required at any node. The loop closes on its own.
The Institution: Fusion Centers
The fusion cell described above is not hypothetical and does not have to be inferred from doctrine. Approximately eighty state and local fusion centers operate across the United States, established after 2001 on the recommendation of the 9/11 Commission and funded by the Department of Homeland Security to a figure the Department itself could not later specify, somewhere between $289 million and $1.4 billion.61 They are operated by states but capitalized federally, given access to federal intelligence systems, and staffed in part by assigned FBI and DHS personnel.61,62
That hybrid character supplies the connection Section V left open. The silent hit is generated when a local officer runs a routine NCIC query against a federally watchlisted person; the officer learns nothing and the notification goes to the nominating agency. The fusion center is the institution where that traffic lives — the documented interface at which local queries meet federal watchlist data, in a facility governed by neither regime completely. Federal oversight reaches federal personnel and federal systems. State oversight reaches state employees and state records. The join between them is where the fusion center sits, and it is the one place in the architecture that no oversight body has a charter to examine end to end.
The Senate Permanent Subcommittee on Investigations examined what such a facility produces in a two-year bipartisan review published in October 2012. The Subcommittee found that fusion centers forwarded intelligence of uneven quality, oftentimes shoddy, rarely timely, sometimes endangering citizens’ civil liberties and Privacy Act protections, occasionally taken from already-published public sources, and more often than not unrelated to terrorism. Reviewing thirteen months of reporting, investigators could identify no product that uncovered a terrorist threat and no contribution to the disruption of any plot. Nearly a third of reports were never published, often because they lacked useful information or potentially violated civil-liberties guidelines. The official who headed DHS’s reporting branch told investigators the output was frequently, in his words, a bunch of crap. DHS had asserted that some fusion centers existed which did not.61
Read that as a description of a targeting apparatus rather than as a critique of an inefficient one. A Senate committee established that roughly eighty federally funded facilities were generating dossiers on Americans, that the dossiers were largely unrelated to terrorism, that a substantial fraction implicated constitutionally protected activity, and that the network produced no counterterrorism value whatever. The reporting that drew public attention concerned bumper stickers, civil-liberties organizations, and activists on both sides of contested issues — which is to say the criterion for attention was not conduct but salience. Fourteen years later the network remains in place, funded, with few of the report’s reforms implemented.62 The argument does not require that fusion centers be doing what TI testimony describes. It requires only what the Senate found: that they attend to people who have done nothing, that they do so without predicate, and that no one is meaningfully watching them do it.
SKYNET: The Architecture Running
That fusion of this kind operates against named individuals rather than populations in the abstract is not an inference. The NSA’s SKYNET program applied a random-forest classifier to the cellular metadata of fifty-five million people in Pakistan, scoring each subscriber against more than eighty behavioral properties — travel patterns, social network structure, SIM-card swapping, overnight absences, pattern-of-life anomalies — to produce a numerical likelihood that the person was a courier or a terrorist. The training set contained seven known terrorists; the same records were used to train and test the model; the highest-scoring individual in the dataset was Al-Jazeera’s Islamabad bureau chief.63
The methodological failure is not the finding. SKYNET establishes four things the essay would otherwise have to infer: that automated behavioral scoring of a civilian population has been built and deployed; that it ran on a single collection stream, metadata alone, without any of the exotic inputs of Sections V through VII; that it assigned individualized scores to individually named persons; and that it did so with so little validation that an obvious false positive sat at the top of the list. Return to the reported features with SKYNET in view. Anticipation is what a behavioral classifier produces by construction. Timing to significance is what a model trained on pattern-of-life anomalies is for. Propagation through the social graph is one of the eighty properties. SKYNET is not an analogy for the system the corpus describes. It is that system with fewer sensors and a foreign population.
Where the Neural Streams Enter
Inside such an architecture the streams of the preceding sections become features in a model and lose whatever exoticism they had. SAR and radar gait signatures establish movement. WiFi channel-state estimation reconstructs indoor activity. Device exploitation supplies communications, social graph, transactions, and search history. Voiceprints permit speaker identification across intercepted audio.46 Neural read data, where available, contributes attention state, stress markers, and pre-speech semantic content.3,13
A fusion architecture does not privilege the physics of its inputs. It privileges their correlation. Pre-speech semantic content entering such a system is not a categorically different kind of intelligence from a geolocation ping; it is another column, timestamped and joined on the same key, valuable in proportion to what it predicts about the others. Integration is not a threshold neural data would have to cross. It is the default disposition of every stream the community collects, and the burden falls on the proposition that this one stream alone was quarantined.
The bidirectional loop follows from the same structure. Pre-speech activity monitored, analyzed, and answered in real time through an auditory insertion channel is the closed form of Layers 2 and 3.39,58 The engineering requirement is lower than it appears: the system need not read every thought accurately, only respond to enough of them, often enough, that the subject loses confidence in the boundary between internal speech and external insertion. After that the subject supplies the rest. A poor read channel paired with a good write channel produces the reported phenomenology as reliably as a perfect one — which is what the engineering gradient of Section VII predicts, and why the reports are dense on insertion and thin on accurate mind-reading.47
The Disappearing Analyst
The remaining objection is economic: an architecture this elaborate, aimed at one unremarkable person, costs more than any motive justifies. That was sound twenty years ago, and the agencies have spent the interval dismantling it. NGA’s artificial intelligence strategy commits to target detections from new modalities through computer vision, automated geolocation, and collection orchestration in which models present managers with options generated from standing needs and dynamic events.64 ODNI frames the same transition as Augmenting Intelligence Using Machines.65 An NGA director of analysis gave the concrete version: a team monitoring more than a hundred locations once had three analysts sampling a subset, and now has one analyst overseeing all of them, with every location in essence looked at by a machine.66
Apply that ratio to persons rather than places. Correlating sleep disruption against geolocation anomalies, matching pre-speech signatures against voiceprint libraries, timing insertion to detected stress states, maintaining a flag that circulates through a suspicious-activity network — none of it requires sustained human attention. The machine maintains the model; the analyst intervenes when the subject’s responses call for adjustment. A system requiring a room of analysts per subject is limited by payroll to a handful of subjects. A system requiring one analyst per hundred subjects is limited by nothing anyone would notice in a budget.
The resulting opacity is structural rather than incidental. No individual analyst holds the complete picture, because the picture exists only as a model distributed across systems no one person queries end to end. No oversight body can reconstruct it, because reconstruction would require simultaneous access to authorities held by different agencies under different legal regimes, several of which — the silent hit, the fusion center’s jurisdictional seam — are exempt from review by design or by omission. The architecture is deniable not because anyone is lying but because there is no vantage point from which the whole of it is visible, including from inside. That is the condition Section X takes up, and it is why the oversight question cannot be settled by asking the agencies whether they are doing this. There is no one at any agency positioned to know.
IX. Layer 5: Clinical Collection and Diagnostic Disposal
Martin Cannon named the problem that follows covert influence the disposal problem: the continuing difficulty of preventing a subject’s account from becoming institutionally credible.67 Cannon’s wider framework is contested and this essay borrows only the formulation, departing from him on the essential point. Disposal is not the objective of the final layer. It is the residue of it. The objective is collection, and the medical system is where the collection happens.
Bringing the Subject to the Sensor
Section VI conceded the architecture’s weakest joint. Remote recovery of neural signal at distance is not demonstrated in the open literature; biomagnetic fields fall off as the cube of distance, and magnetoencephalography achieves its sensitivity with SQUID magnetometers inside magnetically shielded rooms. Nothing in the public record closes the gap between a shielded laboratory and a residential street.
But the gap only matters if the sensor has to come to the subject. There is an entire institutional apparatus in which clinical-grade neurophysiological recording is performed routinely, at length, under controlled conditions, with the subject’s written consent, billed to the subject’s insurer, and archived indefinitely in systems designed for interoperability. A diagnostic sleep study records electroencephalography across multiple channels for a full night, alongside electro-oculography, submental and limb electromyography, electrocardiography, respiratory effort, airflow, and continuous oximetry.68 That is not an approximation of the read channel this essay has struggled to establish. It is a superset of it, acquired lawfully, at higher fidelity than any remote method could plausibly achieve.
The inference follows from that asymmetry. A system that cannot bring the sensor to the subject can bring the subject to the sensor, and the capability required is the one Section VII established most firmly. The write channel’s highest-value application is not harassment. It is requisition.
Symptom as Requisition
Clinical pathways are deterministic in a way that makes them exploitable. A presenting complaint does not lead to an arbitrary investigation; it leads to a specific one, and the mapping is published in every differential-diagnosis reference in use. Control of the symptom is therefore control of the modality.
Unrefreshing sleep and daytime somnolence route to polysomnography, and polysomnography is a night of clinical EEG. Transient paresthesia, visual disturbance, or focal weakness route to magnetic resonance imaging, which returns high-resolution structural neuroanatomy. Episodic confusion, olfactory phenomena, or absence-like events route to electroencephalography, in many cases ambulatory over several days. Palpitations or syncope route to Holter or event monitoring, which returns continuous cardiac and autonomic data over days to weeks. Unexplained fatigue, weight change, or temperature dysregulation route to comprehensive metabolic, endocrine, and increasingly genomic panels.
Read that list in the other direction and it becomes a menu. Each entry names a biometric dataset and the complaint that will produce it. The subject presents, the clinician orders what the presentation indicates, and the resulting data enters the medical record because that is what medical records are for. No one in the sequence does anything irregular. The clinician is practicing correctly; the ordering is appropriate to the complaint; the data is retained because retention is required.
The mechanism does not require the spatial precision that would be needed to write a specific thought into a specific cortical region. What it requires is a symptom menu, and the effects established in Sections VI and VII already supply one — sleep-stage disruption, which Section VII showed requires no targeting at all; auditory phenomena via the Frey effect; peripheral sensory effects of the kind DARPA’s TNT program treats as an addressable substrate; and the non-thermal, frequency-windowed coupling in the Adey and Blackman lineage, whose effective modulation frequencies fall inside the EEG band. None of that permits writing a sentence into a mind. All of it permits producing a complaint that sends someone to a specialist.
Mimicry Rather Than Morbidity
This corrects an error a simpler account of Layer 5 invites, and the simpler account is operationally incoherent. If the objective were to degrade the subject into chronic illness, the architecture would be destroying the asset it had spent years instrumenting. Sustained sleep deprivation genuinely does produce hypertension and atherosclerotic disease,69 insulin resistance and disordered glucose metabolism,70 and measurable immune and inflammatory dysfunction,71 and a subject subjected to it without limit becomes progressively less useful and eventually unavailable.
The efficient version induces the presentation without the pathology. What is needed is not disrupted sleep architecture but the perception of unrefreshing sleep sufficient to justify referral; not cardiac damage but palpitations sufficient to justify a monitor; not demyelination but paresthesia sufficient to justify an MRI; not diabetic coma but an elevated/uncontrolled blood glucose sufficient for an insulin pump. Each produces the clinical encounter and the resulting dataset while leaving the subject functional enough to continue generating them. Morbidity is a cost, not a goal. Mimicry obtains the same collection at a fraction of the price and preserves the source.
Induced States as Assessment Protocol
Collection is not the only return on an induced state. The second has a documented precedent, usually recounted for its lurid particulars rather than examined for its structure. Between roughly 1955 and 1966 the CIA operated safehouses in San Francisco and New York under the MKULTRA subproject known as Operation Midnight Climax. The premises were fitted with one-way mirrors, microphones, and recording equipment. Sex workers were paid to bring men to them. The men were covertly dosed with LSD and, in the surviving record, with barbiturates, amphetamines, mescaline, and other agents, and their behavior — including their sexual behavior — was observed in real time by officers on the other side of the glass.72 The subjects did not consent and in most cases never learned what had happened. The program ran for about a decade and was wound down after an Inspector General survey raised administrative rather than ethical objections.73 It produced no prosecutions.
Strip away the scandal and what remains is a procedure with three steps: induce a deleterious state without the subject’s knowledge, observe the subject under it across behavioral domains including the sexual, and assess what the observation reveals about exploitability. This essay does not claim that Midnight Climax continues under another name. It claims something narrower and harder to dismiss — that the procedure was designed by a U.S. intelligence agency, run for ten years against unwitting American civilians, terminated for reasons of administrative exposure, and never repudiated as a method.8,9
Its contemporary descendant is not covert at all. Behavioral threat assessment, as developed by the Secret Service’s National Threat Assessment Center and codified for state and local use in its protective intelligence guidance,74 holds that targeted violence is planned rather than impulsive, and that the planning period leaves behavioral traces. Its empirical basis includes the Center’s study of thirty-seven school attacks, which reported that most attackers had experienced difficulty coping with significant losses or personal failures, and that most had engaged in pre-incident behavior that caused others concern.75 The pathway model that organizes the doctrine treats the interval between precipitant and attack as the window in which intervention is possible,76 and the Bureau’s Behavioral Analysis Unit applies the same framework in its prevention guidance.77 The doctrine is careful: the same study states that no accurate or useful profile of attackers exists, and the field’s literature warns against treating life circumstances as predictive. What it supplies is narrower than a prediction rule — a variable of interest, how a subject copes with significant loss, and an assurance that the period following such a loss is behaviorally legible.
The doctrine does not have to be sound for the argument to hold. An institution need only believe that response to loss is informative. Believing one can predict is not the same as being able to, and the history of dangerousness prediction suggests the two come apart badly — but an institution acts on what it believes. One holding that belief and wanting to know whether a particular subject would become dangerous, faces an obvious limitation: prediction from observation requires waiting for stressors to arrive on their own. Prediction from intervention does not. If stressors are the variable of interest and the architecture described in this essay can apply them — sleep destroyed, health destabilized, employment made untenable, intimate relationships eroded by conduct the subject cannot explain — then applying them and watching is not a departure from threat assessment doctrine. It is that doctrine’s experimental form. The subject becomes the trial, and the protocol reads out on him.
Chemical dependence is the most efficient single intervention available within such a scheme, which is why it recurs so consistently in the testimony. A subject driven into dependence — whether by direct administration, or, far more cheaply, by destroying sleep until alcohol and sedatives become the obvious remedy — generates four distinct returns at once. He accumulates arrests, emergency admissions, court appearances, and supervision contacts, which is the institutional exposure Section VIII identified as the operative variable. He is subjected to toxicology screening, liver and metabolic panels, and psychiatric evaluation, which is the clinical harvest described above. He is observed under sustained stress in the domains threat assessment cares about — impulse control, aggression, sexual conduct, criminality — which is the assessment. And he acquires a status that renders any subsequent account of what was done to him unreportable, which is the disposal. One intervention, four returns, and no component of it requires a capability this essay has not already established.
One implication is easily inverted and must not be. Several individuals who reported being targeted subsequently committed acts of serious violence, and that correlation is read as evidence that such reports are symptoms of a condition which sometimes ends that way. The argument here runs in the opposite direction. It is not that people who report targeting are dangerous — the overwhelming majority are not, and the essay’s entire argument is that they are people to whom something is being done rather than people who are doing something. It is that a protocol of the kind described would produce precisely that correlation as its expected yield, and that the correlation is at present used to close the question rather than to open it. The Named Cases section takes up what the individual records show.
The Negative Workup
This account explains something the disposal-centered reading cannot. The corpus is dense with reports of extensive medical investigation that finds nothing — the sleep study that comes back unremarkable, the MRI without acute findings, the panels within reference range — and those negative results are ordinarily taken as the strongest evidence that the complaints are psychogenic.
On the reading advanced here the negative result is the expected result, because there was no pathology to find. The symptom was induced rather than organic, and the investigation was never the point. The collection completed at the moment the study was performed. A negative report does not mean nothing was obtained; it means nothing was obtained by the patient. The subject leaves with no diagnosis and a growing file, which is precisely the outcome that makes each subsequent complaint less likely to be investigated and more likely to be attributed.
The Legal Channel
The obvious objection is that medical data is protected. It fails on the face of the regulation. The HIPAA Privacy Rule’s provisions governing specialized government functions state that a covered entity may disclose protected health information to authorized federal officials for the conduct of lawful intelligence, counterintelligence, and other national security activities authorized by the National Security Act. The provision sits within the part of the Rule headed — and the heading is the operative fact — uses and disclosures for which an authorization or opportunity to agree or object is not required.78
There is no consent requirement, no opportunity for the patient to object, no notification, no warrant, and no judicial supervision written into the text. The determination that an activity is lawful intelligence is made by the requesting officials. Section X treats HIPAA among the existing legal frameworks that constrain governmental information collection; the constraint contains an explicit carve-out for exactly the collection this section describes, and the carve-out has been in force since the Rule took effect.
That yields the fourth instance of a structure this essay has now described three times. In Section V the watchlist nomination generates a silent hit the subject never sees, with no notice and no avenue of challenge. In Section VIII the suspicious-activity flag attaches to a named person and propagates across jurisdictions with no removal mechanism. Here, clinical data may be transferred to federal officials with no authorization and no notice, and the resulting psychiatric attribution then propagates through health information exchanges to every subsequent provider, amendable only by appending a statement of disagreement.79 Four bureaucracies, four bodies of law, one architecture: attach, propagate, provide no exit. That convergence is not evidence of coordination. It is what institutions build when no one is obliged to answer to the person being described.
Disposal as Residue
Only at this point does disposal enter, and it enters as cleanup rather than as objective. When a workup is negative and the patient persists, the attribution moves. Diagnostic overshadowing is the established clinical term for what follows: the misattribution of physical symptoms to a patient’s existing psychiatric diagnosis, so that further complaints are received as manifestations rather than investigated as findings.80 It has been identified in the clinical literature as a recognized and preventable source of harm,81 and emergency-department clinicians describe the process in their own accounts of how such patients are assessed.82 Its consequences are measured and severe. People with serious mental illness die fifteen to twenty years earlier than the general population,83 a shortfall quantified across diagnoses in years of potential life lost,84 and the excess is predominantly cardiovascular, respiratory, and malignant rather than attributable to suicide.85 They also receive less preventive screening, are diagnosed later, and are less likely to receive indicated procedures even once a condition has been identified.86
The subject’s own medical history therefore becomes something they do not possess — not because anyone withheld it, but because after a certain point no one establishes it. The true condition, if one eventually develops, is obscured by the absence of the inquiry that would have found it. No clinician need act in bad faith at any stage, and on the evidence almost none do. The epistemic structure is the one Miranda Fricker describes, with the difference that here it carries a mortality figure.19
Nothing in this section counsels withdrawal from care. Diagnostic overshadowing is a failure medicine has named, measured, and is working to correct, and the response it calls for is more engagement rather than less — documented symptoms, requested workups, second opinions, and where possible an advocate present who is not the patient. A person told their physical complaints are psychiatric is, on the published evidence, more likely than not to have an untreated physical condition. Withdrawal is the outcome the mechanism produces unaided, and it is the outcome that kills people.
So the final layer inverts the reading it is usually given. The targeted individual is not being disposed of through medicalization; they are being harvested through it, and the disposal is what remains once the harvesting has exhausted a given line of inquiry. The subject who cannot get a diagnosis has not failed to be believed. They have been believed exactly as far as was useful — far enough to be scanned, monitored, sampled, and recorded — and no further. In Cannon’s terms disposal is a continuing administrative condition. Put more narrowly: disposal requires no disposer, only that a person be made to generate records faster than any institution is obliged to examine them, by a system that reads those records before they do.
X. Law, Oversight, and Democratic Accountability in the Age of Cognitive Technologies
The Regulatory Mirage
The natural answer to Sections V through IX is that this would be illegal. It would not be. The post-Church framework does not fail because it is absent; it fails because it is present in a form that produces the appearance of constraint and leaves the relevant conduct outside its reach.
Four provisions do the work, and they are the whole of this section. The prohibition on human experimentation confers no rights on the person it protects and is bounded by a definition keyed to the actor’s purpose rather than the subject’s experience. The constitutional doctrine governing remote sensing of a home protects only while the sensor stays rare. The surveillance statute reserves national security from its own holdings and has survived its own expiration. And the forum in which an individual might complain, which exists in every democracy the United States shares signals intelligence with, does not exist here.
Every claim below comes from a statute, a regulation, a judicial opinion, or a document released under the Freedom of Information Act, and each is checkable in an afternoon. That is a property no other section of this essay has, and it is why this one can afford to be blunt.
The Consent Architecture
Executive Order 12333 § 2.10 forbids any element of the Intelligence Community from sponsoring, contracting for, or conducting research on human subjects except under guidelines issued by the Department of Health and Human Services, with informed consent documented as those guidelines require.87 It descends directly from the Church Committee: Ford’s Executive Order 11905 restricted drug experimentation, Carter’s 12036 generalised the prohibition, Reagan’s 12333 carried it forward.88
Twenty-three lines below it, § 3.5 provides that nothing in the Order or in any procedure promulgated under it confers any substantive or procedural right on any person.87
So the Order forbids the conduct and denies a remedy to anyone subjected to it. Enforcement belongs exclusively to the branch being constrained, on a record it classifies, and three Presidents have already amended the Order, so § 2.10 could be struck tomorrow by anyone willing to publish a notice in the Federal Register.89 Nor does § 2.10 define its own terms. It incorporates the HHS guidelines by reference, which fixes the scope of the intelligence prohibition to the scope of the Common Rule — a regulation written for federally funded biomedical research, boundaries included.
The definition that does the work
The CIA’s implementing regulation from 1987 to 2017 was Agency Regulation 2-2, formerly HR 7-1, released only in 2015 after ACLU litigation and still heavily redacted.90 Its human-experimentation provision sits at § I.1.a(6)(c). Paragraph (1) routes all human-research documentation through an internal Human Subject Research Panel; paragraph (2) gives the Director authority to approve, modify, or disapprove every proposal.91 That is not a prohibition. It is a rule about who signs.
Paragraph (3) defines the term, and this is where the architecture is visible. Research on human subjects means a formal investigation designed to develop or contribute to generalizable knowledge; intervention includes physical procedures by which data are gathered and manipulation of the subject or the subject’s environment that are performed for research purposes.91
The regulation thus contemplates manipulating a person’s environment as intervention on a human subject — a far broader conception than the clinical image the phrase summons — and then limits it with four words. For research purposes. Manipulation to produce generalizable knowledge is human experimentation. Identical manipulation to accomplish an operational objective against a particular person is not, and the opening prohibition, § 2.10, and the HHS guidelines all fall away with it. The boundary runs on the actor’s epistemic purpose, not the subject’s experience. No subject can locate it from the inside, and no observer can locate it without the actor’s stated purpose — recorded, if anywhere, in a document the subject will never see, written by the party whose conduct is in question.
The paragraph nobody has read
Paragraph (4) is withheld in full under FOIA exemptions (b)(1) and (b)(3), the latter invoking the National Security Act.92 The Agency’s rule on human experimentation has a classified fourth subparagraph — and its history is documented at both ends.
In June 1994 the staff of the Advisory Committee on Human Radiation Experiments reported to the Committee on the CIA’s document search. Their memorandum records that one section of the Agency’s guidelines was classified — HR 7-1a(6)(c)(4) — and that the Agency had reported it was attempting to declassify it.93
HR 7-1 is AR 2-2’s former designation, stated on the regulation’s face. HR 7-1a(6)(c)(4) and AR 2-2 § I.1.a(6)(c)(4) are the same subparagraph. It was identified as classified to a presidential advisory committee investigating human experimentation in 1994, with declassification promised, and it was still redacted when the document reached the public twenty-one years later. Thirty-two years on, no member of the public knows what the CIA’s rule on human experimentation says in its fourth paragraph.
Two limits. AR 2-1 replaced AR 2-2 in March 2017, so the above describes the architecture across three decades rather than the rule in force today.94 And the regulation’s waiver authority did not reach this provision, § e(3) excluding anything required by Executive order. What § e(5) did provide, in language parallel to § 3.5, is that no provision confers rights or remedies on third parties.95 Two instruments, one disclaimer, no beneficiary in either.
Belmont and the Common Rule
Belmont’s three principles bind through the Common Rule at 45 C.F.R. Part 46, which reaches research: systematic investigation designed to develop or contribute to generalizable knowledge.96 The 2018 revisions added four categories deemed not to be research. The fourth is authorized operational activities, as determined by each agency, in support of intelligence, homeland security, defense, or other national security missions.97
Five words hand the determination to the party making it. Everything downstream — Belmont, IRB review, § 2.10, the whole post-Church apparatus — is exited by a characterisation the acting agency makes and nobody outside it reviews.
These agencies are not outside the framework — the Common Rule’s own preamble lists the CIA and ODNI among those historically complying with all of Part 46.98 The point is harder to answer than that: the boundary is drawn by purpose, and the agency draws it.
The Department of Defense is bound more tightly. Procedure 13 of DoD 5240.1-R required consent for experimentation on human subjects for intelligence purposes and defined experimentation to include exposure to possible injury — expressly including psychological and reputational damage — beyond ordinary daily risk.99 That definition forecloses an argument common in this literature: an induced symptom does not escape the rule by resembling a familiar ailment, because the comparison is to ordinary risk, not to whether the symptom is individually distinguishable. Deliberate infliction is not minimal risk. Procedure 13 also worked at least once, DIA having concluded that STAR GATE constituted human-subjects experimentation and taken signed consent under Deputy Secretary approval; and 10 U.S.C. § 980 bars appropriated funds for research on a human experimental subject absent prior consent, which proves a statutory route exists.100
The Church Committee named human experimentation as an abuse in 1976. The remedy adopted was to require the Agency’s own permission.
The Statute That Outlived Its Sunset
Section 702, added to FISA in 2008, authorises targeting non–United States persons abroad without individualised orders, under annual certifications the Foreign Intelligence Surveillance Court approves as to procedures rather than targets.101 Americans’ communications are acquired incidentally when a target corresponds with them, and the government has stated it cannot produce metrics for the volume — domestic acquisition is not merely unpublished but unmeasured.102 Those communications are then queried using American identifiers: thousands of query terms a year by NSA, CIA, and NCTC, and hundreds of thousands of queries by the Bureau before the 2024 reforms.103 The surveillance court has documented repeated compliance failures and responded each time by approving modified procedures.104
The recent history matters more than any of those figures.
Congress reauthorised Section 702 in April 2024 and set a two-year sunset of 20 April 2026.105 Short extensions carried it to 30 April, then to 12 June. On 11 June 2026 the House rejected reauthorisation 218 to 198, and the statute lapsed the next day.106
The collection did not.
On 17 March 2026, before the sunset and with the political outcome unresolved, the surveillance court approved the annual certifications. Under 50 U.S.C. § 1881a, directives issued under a certification stay valid until that certification expires, whatever happens to the statute beneath it. The March certifications run to March 2027. Section 702 collection is proceeding as this is written, under a statute that no longer exists, pursuant to orders issued while it did.107
Nobody broke the law. That is the point. Grandfathering insulates the most consequential surveillance authority in the country, for up to a year, from the single mechanism the constitutional structure provides for ending it. Congress voted the authority down and the collection continued, because the decision that mattered had been taken three months earlier by a court sitting ex parte, in secret, on the government’s application, with no adverse party.
Section 702 authorises no neural collection and this essay claims none. What its history establishes is sharper: an authority can outlive the vote that ended it. If that holds for the most scrutinized program in the country — dedicated statute, dedicated court, dedicated oversight board, two select committees, sustained press attention — the inference about programs with none of those features is not that they are more tightly held.
The Fourth Amendment’s Decaying Threshold
The claim that the Fourth Amendment has never addressed remote electromagnetic sensing is not available. Kyllo v. United States held in 2001 that pointing a thermal imager at a home from a public street is a search — nothing attached, nothing entered, a device passively measuring radiation the house was already emitting. Justice Scalia’s rule: where the government uses a device not in general public use to learn details of the home previously unknowable without physical intrusion, it has conducted a search.108
The difficulty is worse than a gap. Kyllo‘s protection has a half-life. A sensing modality is constrained only while it stays uncommon; as it commoditises the constraint dissolves automatically, by market penetration rather than judicial decision. Channel-state sensing runs on hardware already installed in most American homes, Wi-Fi sensing has been written into the 802.11 standard, and it is shipping in consumer products for occupancy, fall, and sleep detection. On the face of Kyllo, the more widely such sensing spreads for benign purposes, the weaker the constitutional interest in freedom from it. A doctrine written to stop technology eroding the home’s protected status contains a test guaranteeing that erosion. Justice Stevens said so in 2001; twenty-five years of commoditisation have made it worse.108
United States v. Jones is no help: it rests on physical occupation of property, so where nothing is attached it does not apply. What matters in Jones failed to command a majority — Sotomayor’s concurrence and Alito’s concurrence in the judgment, joined by three others, both held that prolonged aggregated monitoring can violate a reasonable expectation of privacy even where each observation is individually unprotected. Five Justices, no opinion of the Court, and fourteen years on the mosaic theory binds no one.109
Carpenter v. United States came closest, holding that acquiring historical cell-site location information is a search despite the third-party doctrine. It is also, by its own terms, a decision reserving nearly everything relevant here: no view on real-time location or tower dumps, no disturbance of conventional surveillance tools, and no consideration of collection techniques involving foreign affairs or national security.110 That last reservation is operative. Asked in January 2019 whether the Intelligence Community had issued guidance on applying Carpenter, the Director of National Intelligence answered Senator Wyden by opening with the national-security reservation.111
So: the home is protected until the sensor becomes common, aggregation matters only in concurrence, and digital dossiers are protected except in the national-security context the Court declined to reach and the Intelligence Community reads as reserved. No decision addresses remote physiological sensing of a body, or sensing that acquires no communication and therefore escapes both the Wiretap Act and FISA’s definition of electronic surveillance.
The Justiciability Wall
Suppose all of that were surmounted. Two doctrines stop the suit before any court reaches what happened.
Clapper v. Amnesty International USA held in 2013 that plaintiffs challenging Section 702 lacked standing because they could not show their communications had actually been acquired; inferences about what the government probably did cannot establish injury that is certainly impending.112 The program was classified, so they could not get the evidence establishing injury; without the injury they could not get discovery. The circularity is the holding.
The state secrets privilege supplies the second bar, permitting the government to exclude evidence and, where a case cannot proceed without it, to win dismissal.113 Its modern form comes from United States v. Reynolds — where the withheld report, declassified forty-three years later, held no state secrets, only evidence of negligence.113 And in FBI v. Fazaga the Court held unanimously in 2022 that FISA’s own review procedure does not displace the privilege.114
The position is fully determined. Standing requires showing the thing was done to you; showing it requires evidence held only by the defendant; that evidence is classified and unavailable in discovery; and if obtained, the privilege excludes it and the case is dismissed. So, a true claim and a false claim produce the same disposition. Dismissal carries no information about the facts and treating it as vindication is a category error.
What Other Democracies Built
The American arrangement is not the natural form of intelligence oversight in a democracy. On the question that matters — whether an individual can obtain an adjudication against a classified program — it is the weakest of the five states that share the most sensitive intelligence.
Britain’s Investigatory Powers Tribunal hears complaints from individuals who believe they have been unlawfully surveilled. It accesses classified material, is not bound by ordinary standing rules, does not require a complainant to prove surveillance in order to bring a claim, and has found against the government on bulk collection and intelligence sharing.115 Germany’s G10 Commission must approve Article 10 restrictions before they take effect, and in May 2020 the Federal Constitutional Court held that the Basic Law binds the BND even in foreign surveillance of foreigners abroad — constitutional rights following state authority rather than stopping at the border.116 Canada’s National Security and Intelligence Review Agency reviews intelligence activity across the whole of government rather than agency by agency, holds statutory access to everything but Cabinet confidences, and investigates individual complaints.117 Australia’s Inspector-General holds royal commission powers and may open an inquiry on her own motion, without referral or complaint.118
The United States has select committees, agency Inspectors General, a privacy board, and a surveillance court. Not one is a forum where an individual can lodge a complaint about a classified program and get an answer. The committees do not adjudicate grievances, and the notification statute permits Gang of Eight briefing on the most sensitive matters.119 Inspectors General work inside one agency and owe findings to no complainant. The privacy board reviews programs rather than persons, has no subpoena power, and has repeatedly gone without quorum.120 The surveillance court hears the government.
So the one thing an American cannot do, which a Briton, a Canadian, and an Australian can, is ask an independent body with classified access whether a secret program has been applied to them. The asymmetry runs among the same five states that share signals intelligence under UKUSA — so intelligence generated under American authority may be reviewable where it is sent and not where it originates. Those oversight bodies said as much themselves, convening from 2016 as the Five Eyes Intelligence Oversight and Review Council because collection had gone collaborative while review stayed national.121
Comparable democracies operating comparable secrecy built forums that provide individual redress. The United States did not. That is a choice, and it has never been publicly debated as one.
Neurorights at the Wrong Perimeter
Governance has moved faster than is generally appreciated. Ienca and Andorno proposed four neurorights in 2017; Chile constitutionalized mental integrity in 2021 and its Supreme Court ordered a neurotechnology firm to delete a plaintiff’s neural data in 2023; UNESCO adopted the first global standard on neurotechnology ethics in November 2025; California, Colorado, and Montana now treat neural data as sensitive under their privacy statutes.122,123,124,125
Every one of those instruments regulates commercial and clinical neurotechnology. UNESCO’s is non-binding, Chile’s case concerned a consumer device company, and the state statutes exempt government activity in the ordinary course. The result governs what a headset manufacturer may take from a brain and says nothing about what a state may — inverted relative to both the historical record and the constitutional interest, since the Church Committee’s findings concerned a government and mental privacy is at its zenith against the state. The framework was built where the political economy allowed, around products and terms of service, and stopped at the national-security exemption, which is the only perimeter that matters.
Law as Alibi
The law has not failed to keep pace with technology. It has kept pace precisely enough to furnish an alibi. The post-Church reforms produced a surveillance court, select committees, Inspectors General, a privacy board, and human-subjects regulations — machinery that performs accountability wherever it is observed and reaches no further. Impressive enough to reassure; fragmented enough that no participant sees the whole.
Method compounds fragmentation. Every American oversight mechanism is documentary — committees read records and take testimony, Inspectors General audit files, the surveillance court reviews applications — and all of it presumes conduct is reconstructible from documents. A model scoring a person across a high-dimensional feature space produces no document saying why, and the officials who deployed it can testify truthfully that they do not know how it reached its conclusion.64,65 The oversight system’s core method has been voided for a growing share of what it oversees, and nobody decided it.
This section’s claim reduces to four propositions, each naming its own refutation. That no American institution holds both the authority and the competence to evaluate a claim of remote physiological interference — refuted by naming a body with classified access, scientific expertise, cross-agency jurisdiction, and a mandate to hear individuals. That the human-subjects framework is exited by an operational characterization no one reviews — refuted by naming a mechanism outside the acting agency that can reclassify over its objection. That no court can reach the merits — refuted by one case surviving standing and state secrets to a merits determination. That no individual complaint forum with classified access exists here — refuted by naming the American Investigatory Powers Tribunal. And a fifth, narrower and easiest of all to settle: that a subparagraph of the CIA’s human-experimentation rule has been withheld since before 1994 — refuted by producing AR 2-2 § I.1.a(6)(c)(4).
None of this establishes that the architecture of Sections V through IX exists. All of it establishes that its existence is not a question American institutions are built to answer, and that the burden of the unanswered question falls entirely on the person least equipped to carry it. The problem of the unconfirmed is therefore not only epistemological but jurisprudential: frameworks that render a class of claims permanently unadjudicable, not because the claims are false, but because proof is assigned to the subject and the means of proof withheld.
Four reforms follow, each already operating somewhere. An individual complaint forum with classified access, on the model of the Investigatory Powers Tribunal, which adjudicates and issues findings without exposing sources and methods and whose neither-confirm-nor-deny practice preserves secrecy while still giving the complainant an authoritative answer. A statutory human-experimentation prohibition with a private right of action, not revocable by the party it binds, with the operational-versus-research characterization vested outside the acting agency; § 3.5 is defensible as to bureaucratic responsibility and indefensible as to § 2.10, and 10 U.S.C. § 980 proves the statutory route exists. A narrowed state secrets privilege permitting exclusion of specific evidence rather than dismissal of whole actions, with in camera review and cleared counsel for the claimant — introduced repeatedly since 2008, never given a floor vote. And standing technical capacity: permanent staff at the committees, the Inspectors General, and the privacy board competent in radiofrequency engineering, machine learning, and neurotechnology, empowered to take measurements rather than only read documents. To which add the smallest of the four: release AR 2-2 § I.1.a(6)(c)(4). Thirty-two years is long enough to withhold a subparagraph of a rule on human experimentation.
The principle is one the Church Committee stated fifty years ago. Secrecy about operations is compatible with democratic government; secrecy about safeguards is not. What must stay classified is what a program does and to whom. What need not — and what the United States has let go dark anyway — is the architecture of constraint itself: which prohibitions apply, who fixes their scope, what follows a breach, and to whom the person subject to them may complain. On all four the honest answer is unsatisfying, and it has stood because no one has been obliged to give it.
Having established that the architecture is legally survivable and institutionally deniable, the essay turns to the question that usually ends the inquiry before it begins: why? The burden of the unconfirmed falls heaviest here — not because motive is necessary to prove means, but because the absence of a credible “why” has long served as the final reason to dismiss the entire claim. The following section examines what incentives, institutional logics, and operational doctrines might direct this apparatus against civilians who, by any ordinary measure of threat, do not appear to warrant it.
Why Target Individuals?
The architecture described in the preceding sections is elaborate, expensive, and legally hazardous even under the permissive framework of Section X. The natural response — once the technical possibility is granted — is to ask why any institution would deploy it against civilians who pose no evident threat to national security. The question is not illegitimate, but its form assumes a single motive where several may converge, and it assumes the target is chosen despite being unremarkable rather than because of it. This section examines the incentives that would direct such a system at individuals who, by ordinary measures, do not warrant the attention.
The most operationally coherent explanation is also the simplest. A program designed to collect neural and behavioral data from humans operating under ordinary life conditions requires subjects who do not know they are subjects. Laboratory volunteers exhibit altered behavior the moment they sign the consent form; the phenomenon under study is the cognition of everyday life, not the cognition of people aware they are being measured. The TI experience — persistent but deniable, distributed across the ordinary infrastructure of work, transit, sleep, and clinical care — produces exactly the dataset that cannot be obtained consensually: continuous, longitudinal, high-fidelity behavioral and physiological data from a human being who believes their responses are spontaneous. The opacity is not an unfortunate side effect. It is the experimental design.
That design is not without precedent. Section IX noted that Operation Midnight Climax obtained observational data by dosing unwitting subjects in naturalistic settings; the value of the data lay precisely in the subjects’ ignorance.72 What has changed is the scale and automation. Where Midnight Climax required safehouses and paid intermediaries, the contemporary architecture leverages the subject’s own devices, their clinical encounters, and their social graph. The watchlist infrastructure supplies the administrative envelope; the fusion centers supply the distribution; the medical system supplies the sensors. The subject is not recruited. They are simply made available.
If the first motive is data collection in the wild, the second is the institutional logic of surplus capacity. Section VIII cited SKYNET, the NSA’s application of a random-forest classifier to fifty-five million Pakistani cellular subscribers, producing individualized threat scores with so little validation that a journalist sat at the top of the list.63 SKYNET was built for a foreign population and a counterterrorism mission. But institutions that build classification architectures do not dismantle them when the original mission contracts; they seek new inputs and new targets. The same pattern — behavioral scoring, pattern-of-life analysis, social-graph propagation —requires only a change of database to turn outward on foreigners inward on citizens. Michel Foucault described the boomerang effect by which techniques of control refined abroad return to the metropole. The trajectory is not conspiracy but institutional gravity: a capability built for one perimeter migrates to another because the infrastructure exists, the personnel are trained, and the legal voids described in Section X permit the migration before any policy debate can occur.
Against that structural backdrop, individual motives proliferate. Intelligence and law enforcement agencies are staffed by people with personal grievances, professional rivalries, and intimate obsessions. The phenomenon of officers diverting classified access to personal ends — acknowledged in congressional oversight following the Snowden disclosures — establishes that access breeds misuse where oversight is weak. Neural influence extends that logic from observation to intervention: the same administrative channels that permit silent tracking permit silent sabotage, and the same diagnostic disposal that neutralizes a political nuisance neutralizes a personal one. Where the watchlist category requires no predicate and the nomination is never disclosed, the barrier to targeting someone who offended the wrong person is administrative rather than moral.
Political neutralization follows the same path at a larger scale. The behavioral threat-assessment frameworks described in Section IX treat ideological commitment as a pre-homicidal pathway, and the fusion-center network has already demonstrated its appetite for constitutionally protected activity.61 A system that can score a population for violence risk can score it for ideological deviation, and the same sleep disruption, auditory insertion, and social-graph erosion that produce clinical disposal also produce political paralysis. The subject who is kept awake, isolated, and medically discredited is not imprisoned; they are simply rendered incapable of sustained organization, documentation, or public speech. The effect is indistinguishable from censorship at the level of the nervous system.
More disturbing is the possibility that the architecture does not merely neutralize threats but manufactures them. Section IX described how induced stress — sleep destruction, health destabilization, employment sabotage — could be read as an assessment protocol, testing whether a subject becomes dangerous under pressure. The return on that investment is not merely observational. A population under sustained neural influence will produce, at predictable rates, individuals whose behavior crosses into violence; the same protocol that surfaces criminality also goads it. The correlation between mass shooters and prior reports of hearing voices, or prior contact with law enforcement and intelligence, is documented outside the TI literature,126 and the correlation is read, circularly, as evidence that such individuals were always dangerous rather than evidence that they were subjected to a protocol designed to make them so. The institution obtains both the pretext for expanded authority and the demonstration of its necessity.
Nor is the harvest limited to behavioral data. The DARPA programs cited in Sections VI and VII treat the peripheral and central nervous systems as addressable substrates for accelerated learning and cognitive enhancement.14, 15 If the read channel can extract semantic content from neural activity and the write channel can modulate attention and memory consolidation, then the same architecture that torments a target could, in other configurations, extract creative insight, problem-solving capacity, or inventive intuition from a human mind without the subject’s awareness or consent. Cognitive extraction — the harvesting of ingenuity at the thought level — is not a speculative addition to the stack. It is the benign reading of the same capability, turned toward state purposes rather than individual debilitation.
Finally, there is the information-environmental function. TI communities are dense with contradictory claims, implausible physics, and internal factionalism, and this has long been cited as evidence of their cognitive unreliability. It is equally consistent with deliberate contamination. A system capable of personalized auditory insertion and sleep disruption is capable of implanting specific narratives, theological obsessions, or persecutory frameworks into subjects who are then left to propagate them through online forums, support groups, and social media. The vulnerable are made vectors. The community becomes a disinformation engine, its genuine experiences buried under fabricated ones seeded by the same apparatus that produces the genuine. The result is epistemic pollution: a class of claims so thoroughly contaminated that even true instances become unadjudicable, which is precisely the condition Section X described as the problem of the unconfirmed.
None of these motives excludes the others. The same subject can be a data source, a threat-assessment trial, a political nuisance, and a disinformation vector simultaneously. The architecture is modular; the incentives are layered. What unifies them is that each motive is institutionally viable under the legal and oversight conditions described in Section X, and each is deniable because the subject’s own testimony — the only available evidence — is pre-emptively discredited by the disposal mechanism of Section IX. The question is not which explanation is correct. It is which one is necessary, and the answer appears to be: none of them alone, and any of them at any time.
Conclusion
The ambition has outlived every vocabulary used to conceal it. What began in nineteenth-century psychophysics as the measurement of human perception, passed through the Cold War as MKULTRA and Project Pandora, and resurfaced in the present decade as cognitive warfare and non-invasive neurotechnology, describes a single institutional trajectory: the nervous system has been treated as strategic terrain for more than a century, and the question has never been whether states would attempt to access it, but only which barriers, technical, legal, or epistemic, would slow the attempt. Those barriers are now lower than at any point since the Church Committee, and in some respects they have been removed entirely. The watchlist infrastructure that requires no criminal predicate, the fusion centers that operate across jurisdictional seams, the silent hits that generate no notice, the clinical pathways that harvest data under the sign of care, and the legal frameworks that exempt national security from consent together compose an architecture in which the TI experience is not merely possible but predictable, the default output of a system designed for permanent, automated, and deniable collection.
Looking forward, the trajectory is not toward resolution but toward normalization. The same neural decoding and neuromodulation techniques surveyed in Sections VI and VII are migrating from classified research into consumer headsets, clinical trials, and workplace wellness programs; the commodification that dissolved Kyllo’s protections for thermal imaging will dissolve them for brain-computer interfaces. As neural data becomes another column in the fusion cell — correlated with geolocation, financial history, and social-graph topology — the boundary between reading cognition and influencing it will become an engineering detail rather than a categorical limit. The oversight mechanisms described in Section X were built to review documents and interview officials; they are not equipped to audit machine-learning models distributed across agencies, and they lack the standing, the technical capacity, and the jurisdictional reach to evaluate claims that span SIGINT, MASINT, clinical medicine, and law enforcement simultaneously. The problem of the unconfirmed is therefore not a temporary lacuna awaiting better evidence. It is a structural feature of a system that classifies the architecture of collection while commodifying its component parts, rendering the subject permanently unable to prove what the institution is permanently unable to deny.
What remains is the epistemic arrangement itself: a democracy in which certain experiences are ruled out of court before any court can hear them, not because they are false, but because the forums that would judge them have been designed to remain blind to the capabilities that would make them legible. The question this essay poses is not whether every targeted individual has accurately described a covert program. It is whether any institution in the United States is presently capable of determining the answer — and, if not, what it means to live under a security state that has made the question itself unaskable. The history of intelligence disclosure suggests that capabilities are denied until they are mundane, and that the subjects of experimentation are disbelieved until the documents are declassified. By then the vocabulary has changed, the personnel have rotated, and the damage is archived under a retired program name. The only constant is the asymmetry: the state’s knowledge of the subject, and the subject’s ignorance of the state. That asymmetry is the real technology stack. Everything else is merely implementation.
Notes
Geng, Jiaqi, Dong Huang, and Fernando De la Torre. "DensePose From WiFi." arXiv:2301.00250, 2022. https://arxiv.org/abs/2301.00250
Wang, Wei, Alex X. Liu, and Muhammad Shahzad. "Gait Recognition Using WiFi Signals." Proceedings of the 2016 ACM International Joint Conference on Pervasive and Ubiquitous Computing (UbiComp ’16), 2016, pp. 363–373. https://dl.acm.org/doi/10.1145/2971648.2971670. Commercial WiFi hardware; 2,800 gait instances from 50 subjects in a room of roughly fifty square meters; top-one, top-two and top-three recognition accuracies of 79.28, 89.52 and 93.05 percent. The authors record two limitations: the method handles a single walker at a time, and suits confined spaces such as a corridor or entrance. They also state the surveillance case themselves, observing that because WiFi signals pass through furniture, doors and walls, a party outside a dwelling can measure the channel state information passively, without decoding any packet, and the occupant has no practical means of preventing it.
Tang, Jerry, Amanda LeBel, Shailee Jain, and Alexander G. Huth. "Semantic Reconstruction of Continuous Language from Non-Invasive Brain Recordings." Nature Neuroscience, vol. 26, no. 5, 2023, pp. 858–866. Open-access preprint: https://www.biorxiv.org/content/10.1101/2022.09.29.509744v1
LeVine, Susan. The Active Denial System: A Revolutionary, Non-lethal Weapon for Today's Battlefield. Defense & Technology Paper 65. Center for Technology and National Security Policy, National Defense University, June 2009. https://www.files.ethz.ch/isn/134720/DTP%2065%20Active%20Defense-%20PO%2060032.pdf
Barker, Anthony T., Reza Jalinous, and Ian L. Freeston. "Non-Invasive Magnetic Stimulation of Human Motor Cortex." The Lancet, vol. 325, no. 8437, 1985, pp. 1106–1107. https://pubmed.ncbi.nlm.nih.gov/2860322/
du Cluzel, François. Cognitive Warfare. NATO Allied Command Transformation Innovation Hub, June–November 2020, published January 2021. https://innovationhub-act.org/wp-content/uploads/2023/12/20210113_CW-Final-v2-.pdf
Wiener, Norbert. Cybernetics: Or Control and Communication in the Animal and the Machine. MIT Press, 1948; 2nd ed. 1961. Open-access edition: https://direct.mit.edu/books/oa-monograph/4581/Cybernetics-or-Control-and-Communication-in-the
U.S. Senate. Project MKULTRA, the CIA’s Program of Research in Behavioral Modification. Joint Hearing Before the Select Committee on Intelligence and the Subcommittee on Health and Scientific Research, 95th Cong., 1st sess., August 3, 1977. U.S. Government Printing Office, 1977. https://www.intelligence.senate.gov/sites/default/files/hearings/95mkultra.pdf
U.S. Senate. Final Report of the Select Committee to Study Governmental Operations with Respect to Intelligence Activities, Book I: Foreign and Military Intelligence. 94th Cong., 2nd sess., 1976. https://archive.org/details/finalreportofsel01unit
Kornbluh, Peter, and William Burr, eds. "The Moscow Signals Declassified: Microwave Mysteries — Projects PANDORA and BIZARRE." National Security Archive Briefing Book 804, George Washington University, September 13, 2022. https://nsarchive.gwu.edu/briefing-book/intelligence-russia-programs/2022-09-13/moscow-signals-declassified-microwave
Bawin, Suzanne M., and W. Ross Adey. "Sensitivity of Calcium Binding in Cerebral Tissue to Weak Environmental Electric Fields Oscillating at Low Frequency." Proceedings of the National Academy of Sciences, vol. 73, no. 6, 1976, pp. 1999–2003. https://doi.org/10.1073/pnas.73.6.1999
Keeler, Anna. "Remote Mind Control Technology." Full Disclosure, no. 15, 1989. https://ia800501.us.archive.org/27/items/pdf_annakeeler_remotemindcontroltechnology/Anna%20Keeler%20-%20Remote%20Mind%20Control%20Technology.pdf
Drummond, Katie, and Noah Shachtman. "Pentagon Preps Soldier Telepathy Push." Wired, May 14, 2009. Reporting on DARPA's FY2010 budget justification for the Silent Talk program. https://www.wired.com/2009/05/pentagon-preps-soldier-telepathy-push/
DARPA. "Targeted Neuroplasticity Training (TNT)." Program page. https://www.darpa.mil/research/programs/targeted-neuroplasticity-training
DARPA. "Next-Generation Nonsurgical Neurotechnology (N3)." Program page. https://www.darpa.mil/research/programs/next-generation-nonsurgical-neurotechnology
NATO Allied Command Transformation. "Cognitive Warfare." Activity page. https://www.act.nato.int/activities/cognitive-warfare/
Kuhn, Thomas S. The Structure of Scientific Revolutions. University of Chicago Press, 1962. https://www.lri.fr/\~mbl/Stanford/CS477/papers/Kuhn-SSR-2ndEd.pdf
Hacking, Ian. "Kinds of People: Moving Targets." Proceedings of the British Academy, vol. 151, 2007, pp. 285–318. https://www.thebritishacademy.ac.uk/documents/2043/pba151p285.pdf
Fricker, Miranda. Epistemic Injustice: Power and the Ethics of Knowing. Oxford University Press, 2007. For an open-access restatement by the author, see Fricker, "Evolving Concepts of Epistemic Injustice." https://www.mirandafricker.com/uploads/1/3/6/2/136236203/evolving_concepts_of_epistemic_injustice.pdf
Morris, John L., and Robert M. Clark. "Measurement and Signature Intelligence." Chap. 6 in The Five Disciplines of Intelligence Collection, edited by Mark M. Lowenthal and Robert M. Clark. SAGE/CQ Press, 2016. https://us2.sagepub.com/sites/default/files/upm-assets/71503_book_item_71503.pdf
Office of the Inspector General, U.S. Department of Defense. Evaluation Report on Measurement and Signature Intelligence. Report No. PO 97-031, June 30, 1997. https://irp.fas.org/program/masint_evaluation_rep.htm
McCreight, Robert. "The War Inside Your Mind: Unprotected Brain Battlefields and Neuro-Vulnerability." Academia Biology, vol. 2, no. 1, 2024. https://doi.org/10.20935/AcadBiol6156
Office of the Director of National Intelligence. U.S. National Intelligence: An Overview. 2013. https://www.govinfo.gov/content/pkg/GOVPUB-PREX28-PURL-gpo126561/pdf/GOVPUB-PREX28-PURL-gpo126561.pdf
Moreira, Alberto, Pau Prats-Iraola, Marwan Younis, Gerhard Krieger, Irena Hajnsek, and Konstantinos P. Papathanassiou. "A Tutorial on Synthetic Aperture Radar." IEEE Geoscience and Remote Sensing Magazine, vol. 1, no. 1, 2013, pp. 6–43. https://elib.dlr.de/82313/1/SAR-Tutorial-March-2013.pdf
Raj, Raghu G., Victor C. Chen, and R. Lipps. "Analysis of Radar Human Gait Signatures." IET Signal Processing, vol. 4, no. 3, 2010, pp. 234–244. https://digital-library.theiet.org/doi/abs/10.1049/iet-spr.2009.0072
NASA Jet Propulsion Laboratory and U.S. Department of Homeland Security Science and Technology Directorate. "DHS Successfully Transitions Search and Rescue Tool That Pinpoints Buried Victims." Finding Individuals for Disaster and Emergency Response (FINDER), May 8, 2015. https://www.jpl.nasa.gov/news/dhs-successfully-transitions-search-and-rescue-tool-that-pinpoints-buried-victims/
Wang, Wei, Naike Du, Yuchao Guo, Chao Sun, Jingyang Liu, Rencheng Song, and Xiuzhu Ye. "Human Detection in Realistic Through-the-Wall Environments Using Raw Radar ADC Data and Parametric Neural Networks." arXiv:2403.15468, 2024. https://arxiv.org/abs/2403.15468
Zhao, Mingmin, Tianhong Li, Mohammad Abu Alsheikh, Yonglong Tian, Hang Zhao, Antonio Torralba, and Dina Katabi. "Through-Wall Human Pose Estimation Using Radio Signals." Proceedings of the IEEE Conference on Computer Vision and Pattern Recognition (CVPR), 2018, pp. 7356–7365. https://openaccess.thecvf.com/content_cvpr_2018/papers/Zhao_Through-Wall_Human_Pose_CVPR_2018_paper.pdf. Average precision of 62.4 on visible scenes and 58.1 through walls, against 68.8 for the vision model used to train it, which fails entirely on the through-wall set; the through-wall data was used for testing only and never for training. Identification of one of a hundred subjects from a two-second clip of the extracted skeleton reached 83.4 percent top-one in visible scenes and 84.4 percent through a wall. The apparatus is not commodity WiFi but a purpose-built FMCW radio with vertical and horizontal antenna arrays, transmitting at about a thousandth of WiFi power, with roughly ten centimeters of depth resolution and an operating range near forty feet. Stated limitations include inter-person occlusion, metallic structures, and crowding.
Prevelakis, Vassilis, and Diomidis Spinellis. "The Athens Affair." IEEE Spectrum, vol. 44, no. 7, July 2007, pp. 26–33. https://spectrum.ieee.org/the-athens-affair. On the lawful-intercept architecture mandated in carrier switching equipment and its subversion to wiretap approximately one hundred Greek subscribers, including the prime minister. On the alternative route — interception without carrier cooperation — see Ney, Peter, Ian Smith, Gabriel Cadamuro, and Tadayoshi Kohno. "SeaGlass: Enabling City-Wide IMSI-Catcher Detection." Proceedings on Privacy Enhancing Technologies, vol. 2017, no. 3, pp. 39–56.
Marczak, Bill, and John Scott-Railton. "The Million Dollar Dissident: NSO Group's iPhone Zero-Days Used Against a UAE Human Rights Defender." Citizen Lab Research Report No. 78, University of Toronto, August 2016. https://citizenlab.ca/2016/08/million-dollar-dissident-iphone-zero-day-nso-group-uae/
European Parliament, Policy Department for Citizens' Rights and Constitutional Affairs. Pegasus and Surveillance Spyware. PE 732.268, May 2022. https://www.europarl.europa.eu/RegData/etudes/IDAN/2022/732268/IPOL_IDA(2022)732268_EN.pdf.
American Civil Liberties Union and Civil Liberties and National Security Clinic, Yale Law School. Trapped in a Black Box: Growing Terrorism Watchlisting in Everyday Policing. April 2016, pp. 1, 6. https://www.aclu.org/sites/default/files/field_document/wirac_9-11_clinic_trapped_in_a_black_box.pdf
Trapped in a Black Box (note 31), pp. 18–19.
Office of the Inspector General, U.S. Department of Justice, Audit Division. The Federal Bureau of Investigation's Terrorist Watchlist Nomination Practices. Audit Report 09-25, May 2009, p. v. https://www.govinfo.gov/content/pkg/GOVPUB-J37-PURL-gpo171805/pdf/GOVPUB-J37-PURL-gpo171805.pdf.
Office of the Inspector General, U.S. Department of Justice, Audit Division. Audit of the Federal Bureau of Investigation's Management of Terrorist Watchlist Nominations. Audit Report 14-16, March 2014, p. 70. https://www.govinfo.gov/content/pkg/GOVPUB-J37-PURL-gpo133566/pdf/GOVPUB-J37-PURL-gpo133566.pdf.
Trapped in a Black Box (note 31), pp. 28–29, citing Communications from Counterterrorism Division to All Field Offices (July 25, 2006), No. NCIC-VGTOF-10889.
Trapped in a Black Box (note 31), pp. 31–32, citing Communications from Counterterrorism to All Field Offices (July 14, 2008), No. NCIC-VGTOF-10880.
Malech, Robert G. “Apparatus and Method for Remotely Monitoring and Altering Brain Waves.“ U.S. Patent 3,951,134, filed 1974, issued 1976. https://patents.google.com/patent/US3951134A/en
Akwei, John St. Clair. “Covert Operations of the U.S. National Security Agency.“ Affidavit filed as Civil Action 92-0449, U.S. District Court, Washington, D.C., 1992. Published in Nexus magazine, Apr.–May 1996. https://cdn.preterhuman.net/texts/government_information/intelligence_and_espionage/homebrew.military.and.espionage.electronics/servv89pn0aj.sn.sourcedns.com/\_gbpprorg/mil/mindcontrol/akwei.html
Frey, Allan H. "Human Auditory System Response to Modulated Electromagnetic Energy." Journal of Applied Physiology, vol. 17, no. 4, 1962, pp. 689–692. https://doi.org/10.1152/jappl.1962.17.4.689
Foster, Kenneth R., and Edward D. Finch. "Microwave Hearing: Evidence for Thermoacoustic Auditory Stimulation by Pulsed Microwaves." Science, vol. 185, no. 4147, 1974, pp. 256–258. https://www.science.org/doi/10.1126/science.185.4147.256. On subsequent modeling of the mechanism see Lin, James C. Auditory Effects of Microwave Radiation. Springer, 2021.
Justesen, Don R. "Microwaves and Behavior." American Psychologist, vol. 30, no. 3, 1975, pp. 391–401. Justesen's account is the primary published source for the Sharp and Grove word-transmission experiment at the Walter Reed Army Institute of Research, which was not separately published; the result is independently corroborated in note 44.
Puharich, Henry K. (Andrija), and Joseph L. Lawrence. "Hearing Aid." U.S. Patent 3,629,521, filed January 8, 1970, issued December 21, 1971. https://patents.google.com/patent/US3629521A/en
Stocklin, Philip L. "Hearing Device." U.S. Patent 4,858,612, filed December 19, 1983, issued August 22, 1989. https://patents.google.com/patent/US4858612A/en See also Brunkan, Wayne B. "Hearing System." U.S. Patent 4,877,027, filed June 6, 1988, issued October 31, 1989. https://patents.google.com/patent/US4877027A/en
U.S. Army National Ground Intelligence Center. Bioeffects of Selected Nonlethal Weapons. Addendum to Nonlethal Technologies—Worldwide (NGIC-1147-101-98), February 17, 1998. Classified at the time of writing; declassified and released December 2006 pursuant to a Freedom of Information Act request. https://archive.org/details/bioeffects-of-selected-non-lethal-weapons-1998
Kofman, Ava. "Finding Your Voice: Forget About Siri and Alexa — When It Comes to Voice Identification, the 'NSA Reigns Supreme.'" The Intercept, January 19, 2018. Based on documents provided by Edward Snowden. https://theintercept.com/2018/01/19/voice-recognition-technology-nsa/
Scannell, Paddy. "For-Anyone-as-Someone Structures." Media, Culture & Society, vol. 22, no. 1, 2000, pp. 5–24. https://journals.sagepub.com/doi/10.1177/016344300022001001. The principal counter-explanation for convergence in the corpus is historical rather than psychiatric: John Durham Peters has argued that first-rank symptoms are articulated through metaphors drawn from mass media, and that thought broadcasting became a diagnostic criterion as broadcast technology spread. See Peters, "Broadcasting and Schizophrenia," Media, Culture & Society, vol. 32, no. 1, 2010, pp. 123–140, https://journals.sagepub.com/doi/10.1177/0163443709350101, and Pinchevski and Peters, "Autism and New Media," New Media & Society, vol. 18, no. 11, 2016, pp. 2507–2523, https://journals.sagepub.com/doi/10.1177/1461444815594441. Cultural diffusion, however, propagates available vocabulary and cannot deposit material that was never in circulation. McKinney's subjects in 1992, dispersed and unknown to one another, reported severe buffeting of the head unaccompanied by dizziness — a distinction corresponding to a 1973 unclassified pulsed-microwave document and to nothing in the popular imagination of mind control. It is not evocative, not cinematic, and not a metaphor anyone reaches for. Peters accounts for the word voices; he does not account for a symptom whose diagnostic value lies in the absence of a symptom that would ordinarily accompany it. I develop the argument at greater length in "The Penetrated Skull: Broadcasting, Manufactured Madness, and the Diagnostic State," June 15, 2026, https://icarusredux.substack.com/p/the-penetrated-skull-broadcasting
Blackman, Carl F., et al. "Induction of Calcium-Ion Efflux from Brain Tissue by Radio-Frequency Radiation: Effects of Modulation Frequency and Field Strength." Radio Science, vol. 14, no. 6S, 1979, pp. 93–98, confirming the frequency window reported by Bawin and Adey (note 10) and identifying a power-density window. On the contested replication record, see Merritt, J. H., et al. "Attempts to Alter 45Ca2+ Binding to Brain Tissue with Pulse-Modulated Microwave Energy." Bioelectromagnetics, vol. 3, no. 4, 1982, pp. 475–478.
National Academies of Sciences, Engineering, and Medicine. An Assessment of Illness in U.S. Government Employees and Their Families at Overseas Embassies. National Academies Press, 2020. https://doi.org/10.17226/25889
Office of the Director of National Intelligence. Anomalous Health Incidents: Analysis of Potential Causal Mechanisms. Executive summary of the report of the Intelligence Community Experts Panel, released February 2022. https://www.academia.edu/145680530/Anomalous_Health_Incidents_Analysis_of_Potential_Mechanisms_IC_Expert_Panel_Sept_2022_FOIA_obtained_. The panel issued six findings and was charged with potential causal mechanisms only; it did not examine attribution, and a small number of its members had also worked on the National Academies study at note 49. The fuller report, dated September 2022 and heavily redacted, entered the public record in 2023 through Freedom of Information Act litigation rather than by voluntary disclosure.
National Intelligence Council. Updated Assessment of Anomalous Health Incidents, ICA 2023-02286, 1 March 2023; and Updated Assessment of Anomalous Health Incidents, as of December 2024, ICA 2025-00008-B, 10 January 2025. https://archive.dni.gov/files/ODNI/documents/assessments/NIC-Unclassified-ICA-Updated-Assessment-AHI-December2024.pdf. The December 2024 assessment also records that while most laboratory results have historically shown no harmful bioeffects from radiofrequency signals, more recent and limited studies have produced mixed preliminary results.
Pierpaoli, Carlo, et al. "Neuroimaging Findings in U.S. Government Personnel and Their Family Members Involved in Anomalous Health Incidents." JAMA, vol. 331, no. 13, 2024, pp. 1122–1134. https://pubmed.ncbi.nlm.nih.gov/38497822/. Eighty-one participants reporting incidents and forty-eight matched controls; no significant between-group differences in volumetric, diffusion, or functional-connectivity measures after adjustment for multiple comparisons, and the study did not replicate an earlier published investigation. See also the companion clinical paper, Chan, Leighton, et al. "Clinical, Biomarker, and Research Tests Among U.S. Government Personnel and Their Family Members Involved in Anomalous Health Incidents," JAMA, vol. 331, no. 13, 2024, pp. 1109–1121. https://pubmed.ncbi.nlm.nih.gov/38497797/.
Rasch, Björn, and Jan Born. "About Sleep's Role in Memory." Physiological Reviews, vol. 93, no. 2, 2013, pp. 681–766. https://doi.org/10.1152/physrev.00032.2012
Waters, Flavie, Jan Dirk Blom, Thien Thanh Dang-Vu, et al. "What Is the Link Between Hallucinations, Dreams, and Hypnagogic–Hypnopompic Experiences?" Schizophrenia Bulletin, vol. 42, no. 5, 2016, pp. 1098–1109. https://doi.org/10.1093/schbul/sbw076
Central Intelligence Agency. KUBARK Counterintelligence Interrogation. July 1963, pp. 87–90, on the manipulation of sleep and the disruption of temporal orientation as a means of inducing regression. Declassified and released via the National Security Archive. https://nsarchive2.gwu.edu/NSAEBB/NSAEBB122/
Chizhov, Lev, Albert Yan-Huang, Thomas Ribeiro, and Aayush Gupta. "We Induced Smells with Ultrasound." Self-published research report, November 2025. https://writetobrain.com/olfactory Not peer reviewed; n = 2, one of whom was the lead investigator; stimulation delivered by a forehead-coupled transducer rather than at range.
Delgado, José M. R. Physical Control of the Mind: Toward a Psychocivilized Society. Harper & Row, 1969. https://archive.org/details/physicalcontrolofmind. On the parallel implant work see Heath, Robert G. "Electrical Self-Stimulation of the Brain in Man." American Journal of Psychiatry, vol. 120, no. 6, 1963, pp. 571–577. https://www.psychiatryonline.org/doi/10.1176/ajp.120.6.571.
Coyle, Mike, ed. MindNet Journal. VERICOMM, Oakland, CA, 1995–1999. Archive index: https://gbppr.net/mil/mindcontrol/mnindex.html The corpus assembled Keeler (note 11), McKinney's Microwave Harassment and Mind-Control Experimentation (Association of National Security Alumni, Electronic Surveillance Project, December 1992), and the Akwei affidavit (note 38) into the framework the TI community came to call synthetic telepathy.
Sheridan, Lorraine P., and David V. James. "Complaints of Group Stalking ('Gang Stalking'): An Exploratory Study of Their Nature and Impact on Complainants." Journal of Forensic Psychiatry & Psychology, vol. 26, no. 5, 2015, pp. 601–623. https://www.tandfonline.com/doi/full/10.1080/14789949.2015.1054857. Sheridan and James treat the complaints as delusional in origin; they are cited here for their systematic description of the reported phenomenology, which is independent of that conclusion.
On the Nationwide Suspicious Activity Reporting Initiative and its behavioral criteria, see U.S. Department of Justice, Bureau of Justice Assistance, Nationwide SAR Initiative program documentation and the ISE-SAR Functional Standard; and for critical assessment, German, Michael, and Jay Stanley. Fusion Center Update. American Civil Liberties Union, July 2008. On private-sector enrollment see Federal Bureau of Investigation, InfraGard program materials.
United States Senate, Permanent Subcommittee on Investigations, Committee on Homeland Security and Governmental Affairs. Federal Support for and Involvement in State and Local Fusion Centers. Majority and Minority Staff Report, October 3, 2012. https://cdn.govexec.com/media/gbc/docs/pdfs_edit/100312cc1.pdf.
Brennan Center for Justice. "How Government Fusion Centers Violate Americans' Rights — and How to Stop It." 2022. https://www.brennancenter.org/our-work/analysis-opinion/how-government-fusion-centers-violate-americans-rights-and-how-stop-it. On the persistence of the network after the 2012 Senate findings and on the federal funding, systems access, and personnel assignments that make nominally state-run centers federally capable.
Grothoff, Christian, and J.M. Porup. “The NSA’s SKYNET program may be killing thousands of innocent people.“ Ars Technica, February 16, 2016. https://arstechnica.com/information-technology/2016/02/the-nsas-skynet-program-may-be-killing-thousands-of-innocent-people/
National Geospatial-Intelligence Agency. “GEOINT Artificial Intelligence.“ NGA.mil, 2024. https://www.nga.mil/news/GEOINT_Artificial_Intelligence_.html
Office of the Director of National Intelligence. The AIM Initiative: A Strategy for Augmenting Intelligence Using Machines. https://www.dni.gov/files/ODNI/documents/AIM-Strategy.pdf
“The NGA’s Emerging Tradecraft.“ Signal, AFCEA International, September 2019. https://www.afcea.org/signal-media/ngas-emerging-tradecraft
Cannon, Martin. The Controllers: A New Hypothesis of Alien Abduction. Self-published monograph, c. 1990. https://ia801009.us.archive.org/32/items/pdf_martincannon_thecontrollers/Martin%20Cannon%20-%20The%20Controllers.pdf. Cannon's broader thesis — that abduction narratives may represent screen memories for covert experimentation — is not adopted here, and his sourcing is uneven; the essay borrows only his formulation of the disposal problem.
On the recorded channels of a diagnostic polysomnogram see American Academy of Sleep Medicine, The AASM Manual for the Scoring of Sleep and Associated Events: Rules, Terminology and Technical Specifications, current version, specifying required electroencephalographic derivations, electro-oculography, chin and limb electromyography, electrocardiography, airflow, respiratory effort, and oximetry. A single overnight study yields multi-channel EEG at clinical sampling rates for the full sleep period.
Cappuccio, Francesco P., Daniel Cooper, Lanfranco D'Elia, Pasquale Strazzullo, and Michelle A. Miller. "Sleep Duration Predicts Cardiovascular Outcomes: A Systematic Review and Meta-Analysis of Prospective Studies." European Heart Journal, vol. 32, no. 12, 2011, pp. 1484–1492. https://pubmed.ncbi.nlm.nih.gov/21300732/.
Cappuccio, Francesco P., Lanfranco D'Elia, Pasquale Strazzullo, and Michelle A. Miller. "Quantity and Quality of Sleep and Incidence of Type 2 Diabetes: A Systematic Review and Meta-Analysis." Diabetes Care, vol. 33, no. 2, 2010, pp. 414–420. https://pubmed.ncbi.nlm.nih.gov/19910503/.
Garbarino, Sergio, Paola Lanteri, Nicola Luigi Bragazzi, Nicola Magnavita, and Egeria Scoditti. "Role of Sleep Deprivation in Immune-Related Disease Risk and Outcomes." Communications Biology, vol. 4, 2021, art. 1304. https://www.nature.com/articles/s42003-021-02825-4.
Marks, John. The Search for the Manchurian Candidate: The CIA and Mind Control. Times Books, 1979, chs. 5–6, on George Hunter White (alias Morgan Hall), Sidney Gottlieb, and the San Francisco and New York safehouses. Marks remains the standard secondary account and was written from the MKULTRA financial records that survived the 1973 destruction order. https://archive.org/details/searchformanchur00john.
Earman, John S., Inspector General, Central Intelligence Agency. "Report of Inspection of MKULTRA/TSD." Top Secret, cover memorandum dated 26 July 1963, 48 pp. CIA FOIA Electronic Reading Room, document C06767515, approved for release 3 April 2019; also reproduced by the National Security Archive. https://nsarchive.gwu.edu/sites/default/files/documents/1963-07-26%20JM%20Box%208%20F2%20MKUltra-IG_Report-ocr.pdf. The report records that TSD began covert testing of materials on unwitting U.S. citizens in 1955, and states that the recommendation to terminate that phase followed from weighing the possible benefits of the testing against the risks of compromise and of resulting damage to the Agency — that is, on grounds of institutional exposure rather than harm to subjects. The same report notes that termination of unwitting testing on U.S. citizens would not halt the programme, testing on foreign nationals being available and deep-cover officers abroad better situated than the narcotics agents who ran the domestic safehouses. A later Earman memorandum refers to the document as the IG report of August 1963.
Fein, Robert A., and Bryan Vossekuil. Protective Intelligence and Threat Assessment Investigations: A Guide for State and Local Law Enforcement Officials. Washington, DC: U.S. Department of Justice, Office of Justice Programs, National Institute of Justice, July 1998, NCJ 170612. https://www.ojp.gov/pdffiles/170612.pdf. The guide draws on the Exceptional Case Study Project, a five-year Secret Service study begun in 1992 examining eighty-three persons who attacked or approached to attack prominent public officials or figures in the United States between 1949 and 1996. The peer-reviewed statement of those findings is Fein and Vossekuil, "Assassination in the United States: An Operational Study of Recent Assassins, Attackers, and Near-Lethal Approachers," Journal of Forensic Sciences, vol. 44, no. 2, 1999, pp. 321–333. An earlier 1997 issue of the guide carries NCJ 167556.
Vossekuil, Bryan, Robert A. Fein, Marisa Reddy, Randy Borum, and William Modzeleski. The Final Report and Findings of the Safe School Initiative: Implications for the Prevention of School Attacks in the United States. Washington, DC: U.S. Secret Service, National Threat Assessment Center, and U.S. Department of Education, Safe and Drug-Free Schools Program, May 2002. https://www.secretservice.gov/media/67/download?inline=true. The study examined thirty-seven incidents of targeted school violence occurring between December 1974 and May 2000. Two of its ten key findings bear directly on the argument made here and are cited together because they pull in different directions: that most attackers had difficulty coping with significant losses or personal failures, and that there is no accurate or useful profile of students who engage in targeted school violence. A revised edition was issued in 2004.
Calhoun, Frederick S., and Stephen W. Weston. Contemporary Threat Management: A Practical Guide for Identifying, Assessing, and Managing Individuals of Violent Intent. San Diego, CA: Specialized Training Services, 2003. https://specializedtraining.com/product/contemporary-threat-management/. The pathway-to-violence model set out here has been adopted in federal preparedness materials, including the Department of Homeland Security's "Pathway to Violence" factsheet and video.
Amman, Molly, et al. Making Prevention a Reality: Identifying, Assessing, and Managing the Threat of Targeted Attacks. Quantico, VA: Federal Bureau of Investigation, Behavioral Analysis Unit, National Center for the Analysis of Violent Crime, Critical Incident Response Group, 2017. https://www.fbi.gov/file-repository/reports-and-publications/making-prevention-a-reality.pdf/view.
45 C.F.R. § 164.512(k)(2): "National security and intelligence activities. A covered entity may disclose protected health information to authorized federal officials for the conduct of lawful intelligence, counter-intelligence, and other national security activities authorized by the National Security Act (50 U.S.C. 401, et seq.) and implementing authority." The provision appears within § 164.512, "Uses and disclosures for which an authorization or opportunity to agree or object is not required."
45 C.F.R. § 164.526, permitting a covered entity to deny a requested amendment where the record is deemed accurate and complete; the individual's remedy is a statement of disagreement appended to the record rather than correction or removal.
Hallyburton, Ann. "Diagnostic Overshadowing: An Evolutionary Concept Analysis on the Misattribution of Physical Symptoms to Pre-Existing Psychological Illnesses." International Journal of Mental Health Nursing, vol. 31, no. 6, 2022, pp. 1360–1372. https://pmc.ncbi.nlm.nih.gov/articles/PMC9796883/.
Iezzoni, Lisa I. "Dangers of Diagnostic Overshadowing." New England Journal of Medicine, vol. 380, no. 22, 2019, pp. 2092–2093. https://www.nejm.org/doi/full/10.1056/NEJMp1903078.
Shefer, Guy, Claire Henderson, Louise M. Howard, Joanna Murray, and Graham Thornicroft. "Diagnostic Overshadowing and Other Challenges Involved in the Diagnostic Process of Patients with Mental Illness Who Present in Emergency Departments with Physical Symptoms — A Qualitative Study." PLOS ONE, vol. 9, no. 11, 2014, e111682. https://pubmed.ncbi.nlm.nih.gov/25369130/.
Walker, Elizabeth Reisinger, Robin E. McGee, and Benjamin G. Druss. "Walker, Elizabeth Reisinger, Robin E. McGee, and Benjamin G. Druss. "Mortality in Mental Disorders and Global Disease Burden Implications: A Systematic Review and Meta-Analysis." JAMA Psychiatry, vol. 72, no. 4, 2015, pp. 334–341.." JAMA Psychiatry, vol. 72, no. 4, 2015, pp. 334–341. https://pubmed.ncbi.nlm.nih.gov/25671328/.
Chan, Joe Kwun Nam, et al. "Life Expectancy and Years of Potential Life Lost in People with Mental Disorders: A Systematic Review and Meta-Analysis." eClinicalMedicine, vol. 65, 2023, art. 102294. https://pubmed.ncbi.nlm.nih.gov/37965432/.
"Physical Health in Severe Mental Illness." British Journal of General Practice, vol. 67, no. 663, 2017, pp. 436–437, reporting a gap of approximately twenty years for males and fifteen for females and noting that the excess is predominantly cardiovascular, respiratory, or malignant. https://bjgp.org/content/67/663/436.
Liberati, Elisa, Sarah Kelly, Annabel Price, Natalie Richards, John Gibson, Annabelle Olsson, Stella Watkins, Emily Smith, Serena Cole, Isla Kuhn, and Graham Martin. "Diagnostic Inequalities Relating to Physical Healthcare Among People with Mental Health Conditions: A Systematic Review." eClinicalMedicine, vol. 80, 2025, art. 103026. https://pubmed.ncbi.nlm.nih.gov/39877262/. Seventy-nine studies, searched across MEDLINE, PsycINFO, Embase, and CINAHL for 1 September 2002 to 18 September 2024 (PROSPERO CRD42022375892). Two limitations bear on the argument made here and are noted rather than elided: most included studies measured diagnostic endpoints only, and the review is explicit that no inference could be drawn about the relative contribution of patient and clinician behaviour; and the association was not uniform across conditions, one included study finding underdiagnosis in depression, anxiety, and dissociative identity disorder but not in schizophrenia or bipolar disorder.
Executive Order 12333, "United States Intelligence Activities," 4 December 1981, 46 Fed. Reg. 59941, §§ 2.4, 2.10, 3.2, 3.5. Section 3.5 provides that the Order is intended to control and provide direction and guidance to the Intelligence Community and that nothing in it or in any procedure promulgated under it is intended to confer any substantive or procedural right or privilege on any person or organization. Sections 2.10 and 3.5 must be read together; § 3.5 fixes the legal effect of § 2.10 on any person subjected to conduct § 2.10 forbids. That E.O. 12333 creates no judicially enforceable rights follows directly from § 3.5 and is uncontested in the case law.
Executive Order 11905 (Ford), 19 February 1976, § 5(g) (restricting drug experimentation absent written, witnessed consent); Executive Order 12036 (Carter), 26 January 1978, § 2-302 (generalizing to all human-subjects research). E.O. 12333 § 2.10 carried the Carter language forward substantially unchanged, substituting the successor department for HEW.
E.O. 13284 (23 January 2003); E.O. 13355 (27 August 2004); E.O. 13470 (30 July 2008).
American Civil Liberties Union, EO 12,333 FOIA Collection: "AR 2-2, Law and Policy Governing the Conduct of Intelligence Activities" (formerly HR 7-1), issued 23 December 1987, with Annex A ("Guidance for CIA Activities Outside the United States") and Annex B ("Guidance for CIA Activities Within the United States"), released 29 April 2015. The released document appears in the CIA's FOIA Electronic Reading Room as DOC_0006235713 (41 pp., "Approved for Release: 2015/04/30 C06235713"). Substantial portions, including sections on intelligence activities within the United States, remain redacted.
AR 2-2, § I.1.a(6)(c) (Human Experimentation), pp. 18–20 of the released text. https://www.cia.gov/readingroom/docs/DOC_0006235713.pdf. The opening statement tracks E.O. 12333 § 2.10. Paragraph (1) directs the DCI, through the Agency's Human Subject Research Panel, to evaluate all documentation and certifications pertaining to human research sponsored by, contracted for, or conducted by the CIA, including initial and ongoing IRB reviews, prepared in compliance with HHS guidelines codified at 45 C.F.R. Part 46; the Panel comprises such CIA employees and outside experts as the DCI deems appropriate, with an Office of General Counsel representative at every meeting. Paragraph (2) provides that the DCI shall approve, modify, or disapprove all proposals pertaining to human subject research. Paragraph (3) defines "research on human subjects" as a formal investigation designed to develop or contribute to generalizable knowledge, the subjects of which are persons about whom a scientist conducting research obtains data through intervention or interaction or identifiable private information, and defines intervention to include both physical procedures by which data are gathered and manipulation of the subject or the subject's environment performed for research purposes. The limiting words are "for research purposes."
AR 2-2, § I.1.a(6)(c)(4), withheld in full under FOIA exemptions (b)(1) and (b)(3), the latter invoking the National Security Act.
Advisory Committee on Human Radiation Experiments, Staff Memorandum, "Methodological Review of Agency Data Collection Efforts: Initial Report on the Central Intelligence Agency Document Search," 27 June 1994, § II.B.3 ("Ethical Guidelines for Human Experimentation"). nsarchive2.gwu.edu/radiation/dir/mstreet/commeet/meet4/brief4.gfr/tab_j/br4j1.txt: recording that one section of the most recent CIA guidelines furnished to the Committee was classified, identifying it as HR 7-1a(6)(c)(4), and noting the Agency's report to staff that it was attempting to declassify that section. Read with note 92, this establishes that the same subparagraph was identified as classified in June 1994 and remained withheld on public release in April 2015. The memorandum also records, at n. 3, that the CIA investigated the effects of microwaves on humans in response to the Soviet irradiation of the U.S. Embassy in Moscow and deemed the matter outside the Committee's purview — bearing on Sections II and VI. Advisory Committee staff memoranda are working documents, not the Committee's final conclusions.
Central Intelligence Agency, Central Intelligence Agency Intelligence Activities: Procedures Approved by the Attorney General Pursuant to Executive Order 12333, declassified and released 18 January 2017, effective as AR 2-1 on 18 March 2017, superseding AR 2-2 and Annexes A and B.
AR 2-2, § e(3) (permitting the DCI or DDCI to waive a provision of HR 7-1 not required by constitution, statute, Executive order, or written agreement) and § e(5) ("No provision of this regulation is intended to confer any rights, privileges, or remedies on third parties"). Because the HHS-guidelines requirement is required by E.O. 12333 § 2.10, it was not waivable under § e(3).
National Commission for the Protection of Human Subjects of Biomedical and Behavioral Research, The Belmont Report, 18 April 1979; 45 C.F.R. Part 46, Subpart A (the Common Rule), § 46.102(l) (definition of research). Parallel provisions appear in the corresponding parts of the other signatory departments' regulations.
45 C.F.R. § 46.102(l)(4) (2018 requirements): “Authorized operational activities (as determined by each agency) in support of intelligence, homeland security, defense, or other national security missions.” The intelligence category is the fourth of four added in 2018; subsection (l)(3) concerns collection and analysis by or for a criminal justice agency. See Federal Policy for the Protection of Human Subjects, 82 Fed. Reg. 7149 (19 January 2017), effective 2018.
Federal Policy for the Protection of Human Subjects, 82 Fed. Reg. 7149 (19 January 2017), preamble discussion of signatory agencies, identifying the CIA, ODNI, DHS, and SSA as having historically complied with all subparts of 45 C.F.R. Part 46 though they had not previously issued the Common Rule in their own regulations.
DoD 5240.1-R, Procedures Governing the Activities of DoD Intelligence Components That Affect United States Persons, December 1982, ch. 13 (Procedure 13, "Experimentation on Human Subjects for Intelligence Purposes"). https://www.aclu.org/documents/dod-regulation-52401-r-procedures-governing-activities-dod-intelligence-components. §§ C13.1–C13.3. Section C13.2.1 defines experimentation as any research or testing activity involving human subjects that may expose them to the possibility of permanent or temporary injury — including physical or psychological damage and damage to the reputation of such persons — beyond the risks of injury to which they are ordinarily exposed in daily life. DoD 5240.1-R has been cancelled and incorporated into DoD Directive 5240.01; current procedures are carried in DoD Manual 5240.01 (8 August 2016), with DoDD 5240.01 reissued 27 September 2024.
10 U.S.C. § 980; DoD Instruction 3216.02, "Protection of Human Subjects and Adherence to Ethical Standards in DoD-Conducted and -Supported Research." On the protective application of Procedure 13: an internal Defense Intelligence Agency assessment of the STAR GATE remote-viewing project recorded that both the DIA and DoD General Counsels had determined the project constituted experimentation on human subjects, that approval was accordingly granted by the Deputy Secretary of Defense, and that participants signed a consent statement approved by the DIA General Counsel, participation being voluntary and revocable.
50 U.S.C. § 1881a.
Privacy and Civil Liberties Oversight Board, Report on the Surveillance Program Operated Pursuant to Section 702 of the Foreign Intelligence Surveillance Act, 28 September 2023, including its account of the government's position that it cannot provide metrics identifying the volume of incidentally collected United States person information. https://s3.documentcloud.org/documents/23993279/2023-pclob-702-report.pdf.
Office of the Director of National Intelligence, Annual Statistical Transparency Report Regarding the Use of National Security Surveillance Authorities, CY2020–CY2022 and later editions: United States person query terms used by NSA, CIA, and NCTC against unminimized Section 702 content totalled 7,282 (CY2020), 8,406 (CY2021), and 4,684 (CY2022). The reports distinguish query terms from queries and devote a dedicated figure to the counting methodology; the two are not interchangeable. FBI figures are compiled on a separate methodology, run into the hundreds of thousands before the 2024 reauthorization, and declined thereafter. Reporting on the Snowden documents separately found that in one cache of intercepted communications roughly nine in ten account holders were not intended targets and about half the files identified United States persons: Barton Gellman, Julie Tate, and Ashkan Soltani, Washington Post, 5 July 2014 — investigative journalism, not the determination of any oversight body.
FISA Court opinions released in redacted form 2019–2023, including the October 2016 disclosure of significant non-compliance with NSA minimization procedures involving United States person identifiers in queries of upstream data; see also PCLOB (note 102).
Reforming Intelligence and Securing America Act, Pub. L. No. 118-49 (20 April 2024), setting a two-year sunset of 20 April 2026. See Congressional Research Service, R48592.
Extensions carrying Section 702 to 30 April 2026 and then to 12 June 2026; House vote of 11 June 2026 rejecting reauthorization, 218–198; statutory lapse effective 12 June 2026.
FISA Court certifications approved 17 March 2026, effective one year and therefore running to March 2027. Under 50 U.S.C. § 1881a, directives issued pursuant to a certification in effect at sunset remain valid until that certification expires, notwithstanding lapse of the underlying statute. See Brennan Center for Justice, Section 702 resource page and analyses published April–June 2026.
Kyllo v. United States, 533 U.S. 27 (2001), at 34 (sense-enhancing technology not in general public use, used to explore details of the home previously unknowable without physical intrusion). Justice Stevens, concurring in part and dissenting in part, identified the durability problem created by the "general public use" condition. On Wi-Fi sensing as commodity capability see Section V and notes 1, 2, and 28; IEEE 802.11bf formalizes sensing within the wireless standard.
United States v. Jones, 565 U.S. 400 (2012). Majority (Scalia, J.) at 404–05; Sotomayor, J., concurring, at 415–18; Alito, J., concurring in the judgment, joined by Ginsburg, Breyer, and Kagan, JJ., at 429–31. Five Justices endorsed a form of the aggregation or "mosaic" theory; none wrote for the Court.
Carpenter v. United States, 585 U.S. 296 (2018), holding at 310–20; the four express reservations at 17–18 of the slip opinion.
Senate Select Committee on Intelligence, Unclassified Responses to Questions for the Record, hearing of 29 January 2019, response of DNI Daniel Coats to Senator Wyden concerning Intelligence Community guidance on applying Carpenter; information current as of 21 March 2019. The response opens by quoting the reservation that the opinion does not consider other collection techniques involving foreign affairs or national security.
Clapper v. Amnesty International USA, 568 U.S. 398 (2013).
United States v. Reynolds, 345 U.S. 1 (1953). The withheld accident report was declassified in 1996 and found to contain no information plausibly constituting a state secret.
FBI v. Fazaga, 595 U.S. 344 (2022), holding that 50 U.S.C. § 1806(f) does not displace the state secrets privilege.
Investigatory Powers Act 2016 (UK); annual reports of the Investigatory Powers Commissioner's Office; determinations of the Investigatory Powers Tribunal, including those concerning the intelligence-sharing regime and aspects of bulk collection in which the Tribunal found against the government.
Bundesverfassungsgericht, judgment of 19 May 2020, 1 BvR 2835/17, holding that the Basic Law binds German public authority in foreign surveillance of foreigners abroad. On prior review of Article 10 restrictions see the Gesetz zur Beschränkung des Brief-, Post- und Fernmeldegeheimnisses (G10) and the G10 Commission. Compare United States v. Verdugo-Urquidez, 494 U.S. 259 (1990).
National Security Act, S.C. 2019, c. 13 (Canada), establishing the National Security and Intelligence Review Agency with whole-of-government jurisdiction, statutory access to information other than Cabinet confidences, and authority to investigate individual complaints; National Security and Intelligence Committee of Parliamentarians Act, S.C. 2017, c. 15.
Inspector-General of Intelligence and Security Act 1986 (Cth) (Australia), conferring royal commission powers and own-motion inquiry authority.
50 U.S.C. § 3093(c)(2).
42 U.S.C. § 2000ee. The Board's mandate centres on counterterrorism, it lacks subpoena power over the executive branch, it relies on voluntary agency cooperation, and it has lacked the quorum required for substantive action for extended periods.
Five Eyes Intelligence Oversight and Review Council, constituted 2016–17, comprising the oversight and review bodies of Australia, Canada, New Zealand, the United Kingdom, and the United States.
Ienca, Marcello, and Roberto Andorno. "Towards New Human Rights in the Age of Neuroscience and Neurotechnology." Life Sciences, Society and Policy, vol. 13, no. 5, 2017. https://link.springer.com/article/10.1186/s40504-017-0050-1.
Chile, constitutional reform of 2021 amending Article 19 No. 1 to protect brain activity and information derived from it; Law 21.383. Girardi Lavín v. Emotiv Inc., Corte Suprema de Chile, 2023.
UNESCO, Recommendation on the Ethics of Neurotechnology, adopted by the General Conference at its 43rd session, Samarkand, 12 November 2025, developed under an ad hoc expert group co-chaired by Hervé Chneiweiss and Nita Farahany. Not legally binding.
California SB 1223 (2024), amending the CCPA to treat neural data as sensitive personal information, effective January 2025; Colorado HB 24-1058 (2024), amending the Colorado Privacy Act; Montana subsequently enacted comparable provisions. MIND Act, introduced 29 September 2025.
“Prior contact between mass shooters and law enforcement or intelligence,” Booty (Substack). https://booty.substack.com/p/prior-contact-between-mass-shooters.
