AI Policy Wiki
Dashboard

Inside My Advanced Topics Class 6.3: Your Brain Everywhere (Farahany, February 2026)

medium confidence · updated 2026-06-06

Closes Week 6 by extending the AI personality assessment frame from employment to insurance, lending, education, healthcare, and law enforcement. Charts how 'inferred cognitive portrait' systems are propagating across every consequential decision domain — and how the legal toolkit, organized by sector, fragments where the underlying technology is the same.

Author: Nita Farahany Source: https://nitafarahany.substack.com/p/your-brain-everywhere Published: February 27, 2026

This is Class 6.3 of roughly 30 in Nita Farahany's Advanced Topics in AI Law and Policy course, and the closing class of Week 6. It extends the AI personality and risk assessment frame developed in the employment context to five further decision domains, and argues that the sector-organized legal toolkit fails to track an underlying inference technology that is the same across all of them. Farahany's position is that AI personality and risk assessment is not a hiring problem specifically but a recurring pattern in consequential decisions about people.

Summary of argument

Farahany catalogs six decision domains in which what she terms inferred-portrait AI is operational, then sets each alongside the distinct body of law that governs it. The recurring claim is that one inference engine, governed by six different legal regimes depending on where it is deployed, produces under-protection: a person wronged by the same classifier in one sector has no transferable doctrine to invoke when wronged by it in another, because the technology cuts across the legal map while the law remains sector-bound. The class is framed as the predicate for the Week 10 sequence on Fifth Amendment cognitive evidence.

Six decision domains

  • Employment — Workday, HireVue, and Pymetrics, covered in Classes 6 and 6.2.
  • Insurance — Lemonade's claims AI scrutinizing video for fraud signals; Ladder, Tomorrow, and others using behavioral data to price life insurance.
  • Lending — Upstart, Zest, and others using non-traditional data such as browsing patterns, app usage, and social-media-derived signals for credit decisions.
  • Education — Proctorio, Honorlock, and ExamSoft analyzing student behavior for cheating signals, with predictive analytics flagging students considered at risk.
  • Healthcare — diagnostic AI inferring depression, anxiety, and suicide risk from voice, text, and behavioral data.
  • Law enforcement — risk-assessment tools including COMPAS and the PSA (Public Safety Assessment) used at bail, sentencing, and parole, and predictive policing inferring criminality from neighborhood and demographic patterns.

Each domain is governed by a separate legal regime, which is the basis for Farahany's fragmentation argument:

  • Employment — Title VII, the ADA, the ADEA, the EEOC, and NYC Local Law 144.
  • Insurance — state insurance commissioners, NAIC model laws, and McCarran-Ferguson.
  • Lending — ECOA, FCRA, and the CFPB.
  • Education — FERPA, ADA Section 504, and state departments of education.
  • Healthcare — HIPAA, the FDA's software-as-a-medical-device (SaMD) framework, and state medical boards.
  • Law enforcement — the Due Process Clause, state criminal procedure, and the Fourth Amendment.

Farahany's argument is that because the same inference engine — for example, an emotional-state classifier built from voice — falls under different rules according to the sector that deploys it, protection depends on the accident of deployment context rather than on the technology. She contrasts this with the EU AI Act, which treats AI for personality assessment as a unified category and applies high-risk obligations across sectors. She presents whether that approach produces better outcomes as contested, while characterizing the resulting legal regime as more coherent.

The class closes on what Farahany frames as the cognitive-liberty implication: if a person's inferred personality, mood, risk, and propensity follow them across every consequential decision, the autonomy interest at the core of the cognitive-liberty frame — the right to decide who knows what about oneself — is compromised regardless of any individual sector's protections.

Relationships