Machine-generated text reconstructed from brain activity is now accurate enough to approximate what a person heard, imagined or attempted to say, a capability that, offered as criminal evidence, would let prosecutors put words in a defendant’s mouth while bypassing nearly every safeguard the Federal Rules of Evidence builds around human testimony. Federal rulemakers are looking elsewhere. In early May, a Judicial Conference advisory committee deferred action on proposals addressing AI-generated evidence and deepfakes after a Justice Department representative and a Second Circuit judge questioned whether new doctrine was needed.
Fabricated video and synthetic audio resemble ordinary forgeries closely enough that existing evidentiary structures may absorb them. Neuroimaging presents the harder problem.
The relevant neurotechnology here is semantic decoding. That is, machine-generated text derived from measured neural activity rather than spoken words, a capacity recent studies have shown with remarkable force.
In 2023, researchers at the University of Texas at Austin reported that a functional magnetic resonance imaging (fMRI) decoder could generate sentences capturing the general meaning of stories people heard, speech they imagined, and silent videos they watched. That same year, another study showed that magnetoencephalography (MEG) and electroencephalography (EEG) recordings could be matched to the speech recordings participants were hearing, selected from a set of candidates rather than generated from scratch. A separate study, using implanted electrodes in a participant with amyotrophic lateral sclerosis (ALS), found that attempted speech could be decoded into text at 62 words per minute, with roughly 76% word accuracy against a 125,000-word vocabulary and far higher accuracy on a restricted 50-word set. Then, in 2025, the same UT Austin researchers pushed this further by showing that a decoder trained on one participant could be adapted to others with substantially less individualized data than earlier work required.
Though limits remain, these pipelines are proficient enough that judges should anticipate how a sentence will land with jurors who are told it was computed from the defendant’s brain. This concern is heightened by the growing use of neuroscientific material in criminal proceedings, making this a substantial issue for the Federal Rules of Evidence, especially where a mistaken reconstruction could contribute to a wrongful conviction.
The Strain on Existing Doctrine
Proposed Rule 707 is a starting point, though an incomplete one. It recognizes that machine-generated material may need a reliability screen comparable to expert testimony under Rule 702, and decoder results would almost certainly arrive through a testifying neuroscientist. The underlying instinct still holds. If a system produces material that would require expert scrutiny if spoken by a human witness, judges should resist allowing it to bypass review merely because a human never directly uttered it.
Yet reliability is only the threshold question. The more difficult issue lies elsewhere. Even a decoder accurate enough to clear a Rule 702 screen leaves open how courts should treat the generated language itself.
Consider Rule 704(b), under which an expert is barred from providing an opinion about whether the defendant had the mental state required for the charged crime. A prosecutor need not ask an expert to opine on mens rea if the accompanying evidence already speaks to it, a clear route around the rule.
Diaz v. United States presents another opening that tests the limits of Rule 704(b). There, the Supreme Court held that an expert could testify that in most circumstances a courier knows drugs are in the vehicle, because that statement offered no opinion about the particular defendant on trial. Under that reasoning, a prosecution could contend that an expert is simply making a general scientific claim. Namely, across validated subjects and conditions, the decoder usually produces language that approximates mental content accurately, leaving the jury to draw the final inference. Yet that move shifts Diaz’s class-wide account into a conduit for a singular accusation, for while the expert says “most,” the proof remains tailored to one person.
Rule 801 is implicated as well, though courts have so far treated automated output as a peripheral hearsay question. In United States v. Lizarraga-Tirado, the Ninth Circuit ruled that a Google Earth satellite image failed to constitute hearsay because, similar to a photograph, it makes “no assertion.” It also held that the automatically generated GPS tack was an assertion, but not hearsay, because a machine is not a declarant. Reliability concerns, the court said, belong to authentication under Rule 901. In United States v. Washington, the Fourth Circuit held in 2007 that PCP and alcohol-level data generated by forensic diagnostic machines were statements of machines rather than lab technicians, and so fell outside hearsay.
Given this precedent, along with Rule 801’s description of a “statement” as a person’s assertion, and a “declarant” as the person who made it, brain-decoding software would presumably fall outside both categories. It would likely instead be classified as another “machine statement,” which risks routing around the hearsay rules even though the generated text is, functionally, the kind of material Rule 801 exists to police.
However, if reconstructed language were to be treated as an assertion, a further problem arises: who is the declarant? Under the Sixth Amendment, a criminal defendant has, among other enumerated protections, the right to “be confronted with the witnesses against him.” This is often referred to as the Confrontation Clause, through which the accused may cross-examine the prosecution’s witnesses. Yet if the classification of the declarant remains unclear, this may produce instances where there is no witness to confront.
The Supreme Court considered the clause in Smith v. Arizona in 2024. There, a forensic analyst presented the written findings of a colleague who had performed the drug testing, then offered an opinion built on those findings. The Court held that when an expert conveys an absent analyst’s statements, and those statements support the opinion only if true (i.e., the results of the test), that opinion enters for its truth and may implicate confrontation rights.
In Smith, producing the original analyst for cross-examination would address the problem, though the Court remanded without deciding whether her notes were testimonial. In ordinary forensic practice the fix is straightforward. A chemist explains how the test works and the basis for the interpretation, subject to cross-examination. With semantic decoding, perhaps questioning the neuroscientist will likewise be sufficient, though if the generated prose is expected to accurately represent mental content, it is performing truth-dependent work while again functioning as out-of-court testimony.
Current doctrine is therefore left in a strange position. For if the output is not an assertion, it still affords the prosecution assertion-like privileges. If it is an assertion, it lacks a declarant and strains confrontation. If it has a declarant, the only possible candidate is the subject from whom it was derived, a subject who never spoke those words and may reject the attribution.
A Rule Against Mental Quotation
As a preemptive measure, courts ought to adopt an anti-conduit presumption with presentation, corroboration, and access requirements.
First, any assertion-adjacent material bearing on a defendant’s mental state should be treated as inadmissible when presented in natural language on Rule 704(b) grounds, while also being clearly distinguished from class-wide mental-state testimony established in Diaz. Rule 703 already lets an expert rely on otherwise inadmissible facts or data while barring disclosure to the jury unless the probative value in helping jurors evaluate the opinion substantially outweighs the prejudicial effect. Thus, the admissible form is an opinion. The expert testifies to what the fMRI measured and what semantic features the model detected, without presenting or quoting the reconstructed text.
Second, courts should require independent corroboration before allowing decoder-derived material to serve an incriminatory purpose. If the text suggests knowledge of, say, a weapon location, independent proof must link the accused to the object, site, or relevant event within a broader prosecutorial narrative. Corroboration would keep the output from substituting for ordinary proof and discipline the factfinder’s interpretation by ensuring the technology supplements the case rather than creating it.
Lastly, courts ought to mandate meaningful defense access before decoder-derived material is admitted. Federal Rule of Criminal Procedure 16 already requires disclosure of scientific testing and expert materials in criminal cases, and in McWilliams v. Dunn, the Supreme Court applied Ake v. Oklahoma to hold that due process can require a defendant be given expert assistance to evaluate, prepare and present a defense in a case that turned on evidence of organic brain dysfunction. Decoder outputs fit comfortably within that precedent, and disclosure would give the defense meaningful technical access to the reconstruction process. That access is what allows the defense to push back when the government’s interpretation outruns what the method can support.
These safeguards are modest and preserve semantic decoding as a scientific enterprise, while leaving room for its careful participation in foreseeable criminal trials. In medical contexts, semantic decoding can give words to the voiceless, but when the state uses it to place words in the mouth of the accused, a single mistaken phrase can become the evidence that convicts an innocent person.
Ivan Ramirez is a student at the University of North Carolina School of Law.