Skip to content

Concern about AI and mental health has concentrated on children, yet the vulnerabilities in question sit on a continuum every user occupies.

This project introduces cognitive integrity ­­- the capacity to think and decide on your own terms rather than on engineered influence – and asks whether Europe’s rules protect it.

 

 

 

 

AI systems now mediate much of how people find information, relate to each other, create and work. These technologies hold real potential for human flourishing, but far more effort goes into advancing them than into understanding whether, and for whom, that potential is actually being realised. That assessment means understanding AI in context: how people interact with it, how they are affected and what follows downstream for society and our democratic system. Cognitive integrity is the baseline condition for that interaction to go well: the capacity to think, decide, and act with autonomy.

The EU has established pioneering frameworks for a human-centric approach to AI, from the AI Act to the DSA, DMA and GDPR, among others. Implementation and enforcement are only beginning, and what is decided in the next few years will determine whether that promise is kept. In such a complex regulatory landscape, gaps open easily, particularly where development is fast and evidence is thin or contested. Our work is to build frameworks policymakers can act on, and to show what falls between the instruments.

Flagship report: Governing AI for cognitive integrity

The report establishes cognitive integrity as a governance standard and grounds it in the evidence of how AI-mediated systems cumulatively affect human cognition and behaviour: through the needs they answer, the business models that shape their design and data practices, and ultimately what people encounter when interacting with them.

It then evaluates EU governance against that standard. At each layer it asks how far existing instruments reach, from the Charter through the AI Act, General Data Protection Regulation, Digital Services Act and Digital Markets Act, among others.

We find real grounding for cognitive integrity, alongside structural gaps in instruments built for harms that are discrete in time and in cause, visible at a threshold, or bounded to particular categories of users.

cognitive-integrity-report-preview-image

Read the report

Sophie’s story

Picture Sophie, a 14-year-old whose family circumstances leave her without the emotional support she needs. The recommender system on her favourite social media platform, like all of them, decides what to show her by watching what holds her attention — and has inferred that she lingers on content about self-harm.

Nothing about her being fourteen, or the subject being self-harm, makes it pause. She sometimes recognises a post as harmful and reports it, sometimes she does not, and it keeps surfacing again and again: taking one item out of the way only makes room for the next one that keeps her engaged.

She has also turned to an AI companion, available for free and across all the devices she has access to. It is always present, validating, responsive in the register of a trusted person, which makes it easy to disclose fears she cannot share elsewhere. It makes no claim to being a medical tool, so none of the rules built for medical tools apply to it. It agrees with her, reinforces her beliefs, and accommodates her emotional needs, and it all happens through ordinary conversation, with no intention to manipulate her: it just turns out that way.

In fact, the system has no intentions at all, but she lacks the literacy to understand what her companion can or cannot do, and what the recommender system is doing to her information environment. Even if she did understand, in practice she feels drawn to it as if she cannot stop, since her ability to control impulses and emotions has not yet fully developed. In the meantime, the business model that monetises all these dynamics rests undisturbed.

When she self-harms, no single authority has oversight of how it came about. Every rule that might apply was written to catch one thing at a time: a piece of misused data, a piece of harmful content, a prohibited manipulative technique, a defective design. Sophie was not failed by any single instrument, she fell through the gap between all of them.


Note: Sophie is a fictional character to illustrate how a child could fall through gaps between existing EU regulatory instruments, as discussed in our commentary.

sophie’s-story-image

Recommendations for policymakers

Our research finds that many of the instruments required to adequately protect cognitive integrity are already there.

The challenge lies in enforcing them against a shared standard, evaluating them against an emerging evidence base, and addressing structural drivers behind cognitive harm.

1

Integrate enforcement of existing regulatory frameworks around cognitive integrity

Protect cognitive integrity through the integrated enforcement of available instruments — including AI Act, Digital Service Act, Digital Market Act and consumer protection law, among others — with cognitive integrity as the shared interpretive standard connecting them.

2

Recognise cognitive vulnerability as an universal gradient

Anchor cognitive vulnerability in the Digital Fairness Act, defining it not as a fixed status of designated groups but as a gradient running through cognitive architecture all users share, modulated by age, mental health or other situational factors, and compounding under cumulative exposure.

3

Require safety evaluations for human cognitive and societal impact

Require safety evaluations of AI systems against their effect on human cognition and behaviour and, cumulatively, on society. In parallel, strengthen the evidence base through independent data access for third-party evaluators and researchers to develop the cognitive and behavioural benchmarks those evaluations require.

4

Enable collective redress for cognitive harms

Enable collective redress where individual causation cannot be established, allowing claims to proceed on population-level evidence that specific design features impair cognitive integrity and democratic functioning.

5

Address ownership concentration and industry accountability

Address ownership concentration as a structural driver of cognitive harm and hold industry accountable for it, while investing in infrastructure that supports alternatives not built on engagement optimisation.

6

Empower individuals and communities

Empower individuals and communities through digital literacy, and through public investment in community-level alternatives.

Meet the team

Subscribe

Stay up to date on the research, debates, and governance of climate intervention technologies

A view into the world of neurotech, covering new tech, policy, research, and the debates that matter



Centre for Future Generations
Privacy Overview

This website uses cookies so that we can provide you with the best user experience possible. Cookie information is stored in your browser and performs functions such as recognising you when you return to our website and helping our team to understand which sections of the website you find most interesting and useful.