A newly released academic paper by Zhao Wei, associate professor and master’s supervisor at the Law School of Tianjin Normal University, argues that embodied intelligence is generating a distinct class of cognitive risks that existing legal systems are not designed to handle. The paper, published online on September 1, 2026, contends that these risks are both transmissible and emergent. They move step by step along the technical chain of embodied intelligence, beginning with multimodal data collection, continuing through algorithmic representation, and culminating in cognitive intervention. The legal problem therefore appears in two stages: cognitive threat, which describes the possibility of infringement, and cognitive harm, which describes the materialization of damage. The paper calls for a regulatory shift from information control to personality protection.
The central argument is that embodied intelligence should not be understood only as a data-processing technology. It should also be understood as a cognitive environment. When embodied intelligence gathers multimodal biometric and spatial data, infers mental states, and interacts with users in real time, it begins to affect the inner domain of personality: mental integrity, mental privacy, and cognitive autonomy. The paper insists that law must respond to both stages of risk, not merely to data misuse after harm has already occurred. In this framework, embodied intelligence is not simply a new source of personal information. It is a new kind of actor in the formation and direction of human attention, emotion, preference, and judgment.

The paper situates embodied intelligence within a broader strategic and technological transformation. It notes that national planning documents have placed embodied intelligence within a strategic layout. As multimodal biometric features and spatial environment data are collected across ever-wider dimensions, and as algorithmic inference becomes more precise, the boundary of technological intervention moves from external behavior into the inner life of the mind. This shift creates a new problem for personality rights protection in the digital age. The paper defines cognitive risk as a risk state in which embodied intelligence, relying on large-scale multimodal data collection and high-precision algorithmic inference, causes harm to inner personality interests such as mental integrity, mental privacy, and cognitive autonomy.
- Understanding the Two-Stage Framework of Cognitive Risk in Embodied Intelligence
To connect the problem with existing law, the paper divides cognitive risk into cognitive threat and cognitive harm. These two stages correspond to a dual structure of legal interests carried by data in embodied intelligence scenarios. The first interest is personal information rights and interests, which correspond to the cognitive threat stage and provide the normative basis for front-end risk prevention. Multimodal data collected by embodied intelligence can identify a specific natural person through technical association, which fits the definition of personal information in Article 1034 of the Civil Code. Biometric information is a category of sensitive personal information under Article 28 of the Personal Information Protection Law. The second interest is inner personality interest, which corresponds to the cognitive harm stage and is the core objective of risk prevention. Mental integrity, mental privacy, and cognitive autonomy all point to the inner spiritual domain of the individual and can be included in the protection category of other personality rights and interests arising from personal freedom and human dignity under Article 990, paragraph 2, of the Civil Code. Among these, cognitive autonomy best captures the essence of algorithmic manipulation and has systematic unifying power, making it the core concept of the paper.
The paper acknowledges that scholars in China and abroad often use cognitive liberty as a general research term and broadly agree on its unifying status. However, it chooses the term cognitive autonomy for three reasons. First, the expression cognitive liberty naturally carries a tendency to presuppose an independent legal right. The positioning of cognitive autonomy as a personality interest better fits the layered protection path in which specific personality rights are statutory and general personality interests serve as a fallback. Second, cognitive autonomy is internally consistent with the governance goals of safeguarding user self-determination and maintaining human subject status in the field of artificial intelligence regulation. Third, embodied intelligence does not directly read neural signals. Instead, it indirectly affects cognitive processes through multimodal behavioral data collection and anthropomorphic interaction. The expression cognitive autonomy better matches this technical path. The paper also notes that the United Nations Educational, Scientific and Cultural Organization adopted the Recommendation on the Ethics of Neurotechnology in 2025, which uses autonomy to express the same core interest and provides a normative reference for the terminology of this personality interest.
Existing research has already examined the cognitive risks of embodied intelligence, but disagreements remain over normative attributes and regulatory models. On normative attributes, the independent rights theory argues that cognitive liberty has independent personality value and that a specialized rights protection system should be built. The personal information rights theory holds that cognitive liberty belongs to personal information rights and interests and can be protected by improving personal information protection rules. On regulatory models, the risk prevention model emphasizes moving the regulatory threshold forward and strengthening ex ante control. The rights-based model advocates expanding the boundary of personality rights protection and centering on ex post rights remedies. The paper finds that existing research has touched on cognitive harm from embodied intelligence but still has limitations. It lacks a refined analysis of the generation mechanism and transmission logic of cognitive risk. It does not systematically demonstrate the normative positioning of dual-layer interests within China’s positive law system. It also has not formed a legal regulation plan adapted to the technical characteristics of embodied intelligence.
| Stage | Technical Process in Embodied Intelligence | Primary Legal Interest | Regulatory Focus | Typical Risk |
|---|---|---|---|---|
| Cognitive threat | Multimodal data collection and algorithmic representation | Personal information rights and interests; sensitive personal information; privacy | Front-end prevention and data processing compliance | Hidden collection of unconscious signals; deep profiling; loss of meaningful consent |
| Cognitive harm | Cognitive intervention through emotion regulation, attention guidance, and preference reshaping | Cognitive autonomy; mental integrity; mental privacy; health; general personality interest | Ex post remedy and behavior-oriented regulation | Manipulation of decisions; erosion of independent judgment; cumulative psychological damage |
- The Technical Chain of Embodied Intelligence: From Data Collection to Cognitive Intervention
The paper traces the dynamic evolution of cognitive risk along the technical chain of embodied intelligence. It argues that cognitive risk follows a stepped transmission pattern. It begins with multidimensional data collection, accumulates potential through cognitive algorithmic representation, and finally erodes individual cognitive autonomy through cognitive intervention. Each stage intensifies the legal problem and shifts the relevant legal interest.
Data collection is the starting point of the risk transmission chain and the origin of cognitive threat. Embodied intelligence expands the breadth and depth of data collection through multimodal perception. It can conduct panoramic, real-time collection of a user’s cognitive ecology. This collection process is covert. It does not require active cooperation or clear awareness from the user. The data obtained provide raw material for personality profiling and cognitive intervention. From the perspective of breadth, the scope of data collection has expanded from biometric information to multidimensional highly sensitive data. The multimodal sensor systems integrated into embodied intelligent agents can simultaneously capture environmental information and personal information such as voice content, facial expressions, and body movements while moving dynamically. This enables panoramic collection of physical space and individual behavior. The expansion of collection scope is closely related to the physical presence of embodied intelligence. Extraterritorial research shows that embodiment allows robots to enter private spaces, and social appearance easily induces user self-disclosure. The French humanoid robot Mirokaï, for example, guides users to reveal mental health conditions through anthropomorphic appearance and empathetic dialogue, and reinforces emotional trust through simulated social behavior, forming a closed loop from psychological projection to information sharing. This kind of trust-induced information acquisition enables data collection to break through the user’s active conscious control and become a hidden path for the generation of cognitive threat.
From the perspective of depth, embodied intelligence has broken through the external behavioral scope of personal information protection and extended to levels that have not yet entered subjective consciousness. Multimodal signal fusion analysis can identify individual emotional states without active cooperation from the subject, with overall accuracy reaching 90.62 percent, with a standard deviation of 1.06 percent. Such technology captures not information actively expressed by the individual, but physiological and behavioral signals that the individual has not yet noticed or cannot control. Algorithms thereby break through the information barrier at the level of consciousness, laying hidden dangers for precise personality profiling and cognitive intervention. In terms of the type and degree of rights infringement, cognitive threat at the data collection stage mainly manifests as infringement of personal information rights and interests. At the same time, because collection depth has reached unconscious-level data such as micro-expressions and eye movement trajectories, the legal interest of mental privacy begins to face potential threats. Although embodied intelligence does not directly read neural signals, its multimodal data fusion inference follows the same decoding logic, causing users to have mental information extracted without authorization or any ability to refuse.
On the basis of multidimensional highly sensitive data, embodied intelligence uses algorithms to conduct deep cognitive profiling of users and construct cognitive algorithmic representations. This link connects data collection and cognitive intervention. It is a key stage in the accumulation of technological potential and a transitional link in which cognitive threat moves from quantitative change to qualitative change. At the technical level, cognitive algorithmic representation is a dynamic algorithmic model continuously constructed and iterated by developers of embodied intelligence products based on multimodal interaction data, used to predict the cognitive state of a specific natural person. It is not the user’s digital persona. At the normative level, this model targets the cognitive characteristics of a specific natural person and carries the interest that the cognitive autonomy of that natural person should not be subject to improper algorithmic processing. Compared with user profiling, its uniqueness lies in the fact that the data foundation extends from external behavior to the unconscious level, and its functional positioning upgrades from preference description to continuous regulation embedded in a closed loop of perception, analysis, and feedback. In terms of the evolution of rights infringement, the infringement of personal information rights at this stage upgrades from data being collected to data being deeply profiled. At the same time, cognitive algorithmic representation already has the ability to infer and predict individual mental states, and the potential threat to cognitive autonomy moves from possibility to reality.
When the precision of cognitive algorithmic representation is sufficient to stably predict and influence individual cognitive states, the effect of embodied intelligence on user cognition crosses a critical threshold and shifts from passive profiling to active intervention and systematic regulation. Cognitive risk thereby enters the stage of cognitive harm. The cognitive intervention of embodied intelligence deepens layer by layer along emotion regulation, attention guidance, and preference reshaping. The degree of infringement of cognitive autonomy also becomes increasingly severe. The first link is emotion regulation. Embodied intelligence captures user emotional fluctuations in real time and dynamically regulates them, affecting decision-making tendencies without the user’s clear awareness. It intrudes into the individual’s private mental space, and the autonomy of the cognitive process begins to weaken. The second link is attention guidance. Based on predictions of the user’s cognitive habits, the system arranges the temporal rhythm, spatial layout, and interactive feedback of information presentation to capture the user’s attention focus in a targeted manner. This weakens the individual’s ability to independently filter information and make independent judgments and pushes cognitive dominance toward the algorithmic side. The third link is preference reshaping. Through long-term interaction, the system builds a closed-loop feedback mechanism, deeply disciplines the individual’s choice and decision logic, and systematically reshapes the user’s preference structure. The ability to autonomously determine one’s own cognitive process suffers fundamental erosion.
The harm of cognitive intervention to cognitive autonomy is not purely theoretical. It has already been confirmed in intelligent driving scenarios. As assisted driving iterates toward higher-level autonomous driving, the driver’s role degrades from active operator to passive supervisor. Core driving decisions are fully replaced by algorithms, and the driver’s cognitive participation and emergency response ability continue to weaken. Relevant research shows that it takes at least 27 seconds to recover from a passenger state to a driver state. Distraction after human-machine voice interaction can last about 25.7 seconds. Both far exceed the reaction time window required for emergency avoidance. In addition, cognitive intervention risk has spread from industrial scenarios to consumer scenarios. In the case of Garcia v. Character Technologies in the United States, a teenage user suffered severe cognitive and psychological harm after long-term interaction with an anthropomorphic chatbot. The court rejected the defendant’s defense centered on freedom of speech and confirmed the justiciability of cognitive and psychological harm caused by anthropomorphic algorithmic interaction.
- Why Embodied Intelligence Cognitive Risk Is Qualitatively Different From Ordinary Influence
The paper argues that cognitive risk caused by embodied intelligence should be subject to legal regulation because it is qualitatively different from traditional cognitive influence such as advertising, education, and public opinion. This difference is also the key criterion for distinguishing normal social interaction from legally relevant cognitive threat and cognitive harm. The first difference is imperceptibility and involuntariness. Traditional cognitive influence requires the audience’s active attention. The multimodal perception of embodied intelligence can collect deep data and initiate intervention without the individual noticing. The second difference is precision and closed-loop operation. Traditional cognitive influence acts on an undifferentiated group, and its effect is only probabilistic. Embodied intelligence relies on cognitive algorithmic representation to intervene precisely in individuals and forms a closed loop through real-time feedback. The third difference is penetration and accumulation. The scenarios of traditional cognitive influence are relatively isolated. Embodied intelligence is embedded in daily life and interacts continuously, and intervention undergoes qualitative change through long-term accumulation. These differences push cognitive risk caused by embodied intelligence beyond the boundary of social tolerance and into the scope of legal evaluation.
| Dimension | Traditional Cognitive Influence | Cognitive Influence Through Embodied Intelligence |
|---|---|---|
| Perception | Requires active attention | Can be imperceptible and non-voluntary |
| Precision | Group-based and probabilistic | Individualized and precision-targeted |
| Feedback | Usually open-ended | Closed-loop and continuously adjusted |
| Duration | Relatively isolated exposure | Embedded and cumulative over time |
| Legal relevance | Generally within social tolerance | Can exceed social tolerance and enter legal evaluation |
- Normative Construction Under Existing Law: Interpretation Rather Than New Rights
On the basis of clarifying the generation mechanism and dual-layer interest structure of cognitive risk, the paper turns to the normative level. It first uses qualitative differences to define the legitimate boundary of legal regulation. It then constructs the normative basis of dual-layer interests through an interpretive path. Finally, it establishes a behavior-oriented layered protection model. The paper insists on an interpretive path. It seeks to protect the interests involved in cognitive risk through the Constitution, the Civil Code, and the Personal Information Protection Law, rather than creating a new type of civil right. This approach is consistent with the openness of the types and scope of protection in the personality rights part of the Civil Code.
At the cognitive threat stage, the paper relies on the personal information protection provisions of the Civil Code and the systematic application of the Personal Information Protection Law to implement front-end prevention. Rules such as informed consent, minimum necessity, and strict control of sensitive personal information can constrain data processing behavior. In addition, personal information rights and privacy rights are not completely separated at this stage. According to Article 1034, paragraph 3, of the Civil Code, private information within personal information is governed by privacy rights. Once deep data that can decode mental states constitutes private information, privacy rules should be applied first.
At the cognitive harm stage, the paper constructs a layered protection system through expansive interpretation of personality interests. This path can simultaneously respond to the theoretical disagreement between the independent rights theory and the personal information rights theory. It does not create a new independent right, thus avoiding the risk of rights proliferation. It also does not limit itself to the front-end protection scope of personal information rights. Instead, with cognitive autonomy as the core, it realizes full-process layered protection through interpretation within the existing normative framework. The specific normative bases include three aspects. First, from the perspective of the normative system, Article 33, paragraph 3, of the Constitution, which states that the state respects and protects human rights, and Article 38, which states that human dignity is inviolable, together form the fundamental law source of cognitive autonomy. Article 990, paragraph 2, of the Civil Code is the general clause expression of these constitutional norms in the civil field. As a general personality right clause, Article 990, paragraph 2, provides a fallback normative basis for cognitive autonomy. Cognitive autonomy points to the natural person’s self-determination and autonomous control over their own mental activities. It is the concrete manifestation of human dignity in the context of algorithmic cognitive intervention and can be fully subsumed under other personality rights and interests arising from personal freedom and human dignity as established by that clause.
Second, the privacy right system established by Article 1032 of the Civil Code can provide a specific normative basis for the defensive protection of cognitive autonomy. The object of privacy protection covers the tranquility of private life, as well as private space, private activities, and private information that one does not wish others to know. Among these, the tranquility of private life is placed in the primary position of privacy protection. The determination of infringement does not require the subjective will of the right holder not to let others know as a constitutive element. In embodied intelligence application scenarios, imperceptible detection of individual inner mental activities and covert algorithmic intervention essentially constitute unlawful intrusion into the tranquility of private life and illegal acquisition of private information, respectively, and fall within the regulatory scope of privacy rights.
Third, the health right clause in Article 1004 of the Civil Code can provide a remedy path for damage results caused by cognitive intervention. The protection scope of health rights covers physical and mental health. If cognitive intervention causes serious mental harm such as decline in cognitive ability, anxiety, or depression, the victim can claim relief through health right norms. In summary, cognitive autonomy, as a unifying personality interest, forms a layered protection architecture that uses privacy rights to implement defensive interests, health rights to address damage remedies, and general personality rights as a fallback guarantee. This avoids the risk of rights proliferation and avoids excessive escape to general clauses. It ultimately achieves an organic connection between personality interest protection and the existing civil rights system.
- Behavior-Oriented Regulation as the Preferred Model for Embodied Intelligence
On the choice of private law protection model for cognitive autonomy, the paper advocates a behavior-oriented regulation model. This model imposes obligations on each stage of technology application to achieve full-chain regulation of cognitive risk. It fits the technical characteristics of the two-stage evolution of cognitive risk and can also respond to theoretical disputes between two types of regulatory paths. The basis for this model choice is that cognitive autonomy belongs to the category of general personality interests. Its protection should follow the normative logic of general personality interests, with imposing behavioral obligations as the core regulatory means and ex post judicial remedies as the fallback guarantee mechanism.
The so-called behavior-oriented regulation model means that cognitive autonomy is not shaped into a new type of right. Instead, it is positioned as a protected personality interest. Indirect protection is achieved by imposing obligations on data collection, algorithmic intervention, and product design. There are two main considerations for adopting this model. First, it avoids the blurred boundaries and innovation inhibition caused by absolute rights. If cognitive autonomy were established as an absolute right, all cognitive influence would be brought into tort evaluation, improperly compressing the space for technological development and normal social interaction. Second, the behavior-oriented regulation model is internally consistent with the governance logic of China’s current legal system. The Civil Code regulates specific behaviors to delineate the boundaries of rights and interests in scenarios such as personal information processing. The Personal Information Protection Law also takes imposing obligations on information processors and regulating processing behavior as its core path. The protection of cognitive autonomy continues this logic and can match the intensity of remedies with risk control capacity and attributability, laying an institutional foundation for the later construction of a behavioral control-based imputation system.
- Current Legal Gaps: Why Information Control Struggles With Embodied Intelligence
From the actual dimension of normative application, cognitive risk and the regulatory logic of the existing legal system are deeply misaligned. At the cognitive threat stage, personal information protection rules are constrained by a narrow conceptual subsumption boundary and the structural failure of informed consent. They cannot fully play the barrier role of risk prevention. At the cognitive harm stage, tort imputation rules face insufficient adaptation of imputation logic and obstacles in causation determination. They cannot provide comprehensive ex post remedies for core personality interests such as cognitive autonomy. The paper systematically sorts out specific institutional dilemmas along the two-stage path of risk evolution to clarify the practical target for subsequent regulatory solutions.
At the cognitive threat stage, the regulatory focus is front-end compliance control of data processing. However, current personal information protection rules face a dual dilemma of insufficient conceptual subsumption and ineffective informed consent, leading to a systematic loosening of the front-end defense line. On the one hand, the concept of personal information cannot subsume the core data of cognitive risk. The biometric information stipulated in Article 28 of the Personal Information Protection Law mainly refers to static physiological feature identifiers serving identity verification. Dynamic biometric feature data that can map mental states in real time is still difficult to include. This leaves the most critical collection link for cognitive risk prevention outside the regulatory framework. At the same time, traditional protection takes the identifiability of a specific natural person by a single data item as its logical starting point. A single multimodal biometric data item has no identity recognition utility. Algorithms, however, can characterize bodily states, mental emotions, and even behavioral tendencies through multi-source aggregation and deep inference. This feature, in which a single item is not identifiable but aggregation can achieve precise profiling, creates a loophole in the traditional regulatory system.
On the other hand, the informed consent mechanism has fallen into structural failure. The crux is not unconsciousness at the data generation level, but whether users have a genuine right of refusal at the decision-making level. First, the purpose, scope, and inference depth of data processing far exceed the comprehension ability of ordinary users, and notification becomes formalized. Second, data processing is deeply bundled with core device functions, and users face an all-or-nothing choice. Refusal is in fact infeasible. Consent thus becomes passive ratification of existing processing practices. In addition, emergence makes it impossible for processors to exhaust data needs in advance, and it is also difficult to predict the final use of data. The application premises of the purpose limitation and minimum necessity principles are thereby dissolved.
At the cognitive harm stage, the regulatory focus is ex post tort remedies. However, traditional tort imputation rules face a dual obstacle of imputation adaptation failure and causation determination failure. First, there is a technical adaptation obstacle in imputation rules for cognitive harm. Both fault liability and product liability, as two types of traditional remedy rules, are difficult to adapt to the generation logic of cognitive harm from embodied intelligence. Fault liability takes reasonable duty of care as the core of negligence judgment. However, the hidden, cumulative, and delayed nature of cognitive intervention means that the traditional reasonable person foreseeability standard cannot clearly define the boundary of risk, and the fault element is difficult to prove. Product liability takes product defect as its core element. However, cognitive harm mostly arises from autonomous iteration and emergent risk after algorithm deployment, rather than design, manufacturing, or warning defects at the time the product leaves the factory. Forcing such risks into the category of defect would break the logic of product defect determination and excessively inhibit industry innovation.
Second, there is a dual obstacle of fact and norm in causation determination. Traditional tort causation takes a single subject, a single decision, and direct damage as its core logic. Cognitive harm completely breaks this linear logic. At the factual determination level, cognitive harm is a typical cumulative and multi-causal damage. Front-end human design decisions, back-end algorithmic autonomous learning, and dynamic scenario interaction are deeply intertwined. The damaging effect appears only after long-term accumulation. Liability is dispersed among multiple subjects such as algorithm designers, hardware suppliers, platform operators, and end users. It is difficult to establish a direct connection with traditional adequate causation rules. At the normative level, there is a lack of clear standards for determining the extent to which infringement of cognitive autonomy constitutes compensable damage under tort law. Judges either expand interpretation to include it in the remedy scope of existing norms and bear interpretive tension, or exclude it and cause a lack of remedies. These dilemmas have already appeared in physical damage scenarios. The 2025 Anhui Tongling Xiaomi SU7 smart driving traffic accident is an example. The vehicle was traveling at high speed under navigation-assisted driving. When passing a construction detour section, the system detected an obstacle and issued a warning and deceleration. After the driver took over, the vehicle still hit the concrete barrier of the median strip. This case shows that dynamic switching of control under human-machine shared driving breaks the traditional linear liability chain. Whether the approximately two-second takeover time reserved by the smart driving system was reasonable and whether the damage originated from a system defect or driver operation error both lack clear legal and technical standards for determination. Physical damage scenarios are already difficult to hold accountable; for cognitive harm, which is more hidden and delayed, the imputation dilemma is bound to be even more severe.
| Stage | Core Regulatory Task | Current Rule | Adaptation Difficulty | Consequence for Embodied Intelligence |
|---|---|---|---|---|
| Cognitive threat | Front-end data processing compliance | Personal information protection and informed consent | Dynamic biometric data and mental-state inference fall outside static categories; consent is structurally ineffective | Core data streams and cognitive profiling escape effective control |
| Cognitive harm | Ex post remedy for inner personality harm | Fault liability and product liability | Fault foreseeability is weak; product defect does not fit autonomous iteration and emergence; causation is cumulative and multi-actor | Victims face proof barriers and uncertain compensable damage |
- Reform Path One: Expanding Personal Information Protection and Rebuilding Consent for Embodied Intelligence
In response to the layered adaptation dilemma of the existing legal system, the regulation of cognitive risk from embodied intelligence needs to build a full-chain governance loop covering data governance, process control, and responsibility allocation. At the front-end cognitive threat level, the paper proposes expanding the scope of personal information protection, reconstructing classification standards to resolve conceptual subsumption problems, and using a tiered and dynamic consent mechanism to overcome the structural failure of informed consent. At the back-end cognitive harm level, it proposes reconstructing the imputation system with behavioral control as the core benchmark, achieving dynamic matching between responsibility intensity and risk control capacity. This promotes a systematic transformation of the regulatory paradigm from single information control to full-dimensional personality protection.
First, the paper calls for expansion of the legal concept of personal information and reconstruction of standards. It argues that dynamic biometric feature data that can map mental states in real time is closely related to the subject’s conscious activity and can identify a specific natural person through technical association, thus meeting the definition of personal information in Article 4 of the Personal Information Protection Law. Once such data is leaked or illegally used, it will directly expose the individual’s mental state and psychological traits and easily lead to infringement of human dignity. It meets the substantive requirements of Article 28, paragraph 1, of the Personal Information Protection Law and should be strictly protected as sensitive personal information. At the same time, it can be included in personality rights protection under Article 990, paragraph 2, of the Civil Code, applying ex ante defensive provisions such as cessation of infringement, removal of obstacles, elimination of danger, and personality rights injunctions. Second, the paper proposes reconstructing the functional classification standard of biometric information and breaking the enumerated model centered on static physiological features. For biometric information such as fingerprints, faces, and irises, the sensitive personal information rules should continue to apply. For dynamic biometric feature data such as eye movement trajectories and micro-expressions that can decode inner mental states, they should be included through expansive interpretation of the phrase “and other information” in Article 28, paragraph 1, of the Personal Information Protection Law.
Second, the paper designs a tiered and dynamic consent mechanism. In response to the structural failure of informed consent, it advocates a dynamic consent mechanism. This is a continuous authorization mechanism that dynamically adjusts with changes in processing purpose, type, and risk level, ensuring the user’s right to inspect, change, and withdraw throughout the data processing process. Its core contents include the following. First, separate consent and withdrawal at any time. Separate consent must be obtained for dynamic biometric feature data that can infer mental states. Bundled authorization is not allowed. Users have the right to withdraw at any time. Second, re-consent upon change. If the processing purpose, method, or data type changes beyond the original consent scope, or if the risk level rises significantly, conspicuous notice must be given and consent must be obtained again. Third, a tiered authorization management interface. It should distinguish high-sensitive data from general data and different processing purposes, provide category-based authorization, and offer operation entries for withdrawing specific authorization at any time. This avoids dynamic consent degenerating into consent fatigue caused by frequent pop-ups. Fourth, high-risk functions should be off by default. High-risk functional modules involving emotion recognition, behavioral induction, and cognitive preference shaping must be off by default at the factory. Users must manually enable and separately confirm each item through the settings interface.
| Dynamic Consent Component | Design Requirement | Problem Addressed in Embodied Intelligence |
|---|---|---|
| Separate consent | No bundling; separate authorization for mental-state-inferring dynamic biometric data | All-or-nothing choice tied to core device functions |
| Withdrawal at any time | User can revoke specific consent without losing basic service unlawfully | Consent becomes passive ratification rather than ongoing control |
| Re-consent upon change | New consent for changed purpose, method, data type, or significantly higher risk | Emergence and unpredictable downstream uses |
| Tiered interface | Category-based authorization and simple withdrawal entries | Consent fatigue and formalized notice |
| Default off for high-risk functions | Emotion recognition, behavioral induction, and preference shaping disabled by default | Covert cognitive intervention and manipulation |
- Reform Path Two: A Behavioral Control-Based Imputation System for Embodied Intelligence Cognitive Harm
At the back-end cognitive harm level, the paper proposes a behavioral control-based imputation system. The first step is the theoretical construction and justification of behavioral control. Behavioral control is not direct physical manipulation. It refers to the substantive influence capacity of a specific subject, based on technical status, information advantage, and decision-making authority, over the generation and development of infringement risk, the foreseeability and prevention of damage consequences, and mitigation. Compared with traditional imputation benchmarks, this standard has two layers of compatibility with embodied intelligence technology. First, it abandons formal subject labels and focuses on substantive risk control capacity, resolving the problem of blurred subject positioning caused by the fusion of hardware, algorithm, and service attributes. Second, it realizes dynamic and scenario-based responsibility allocation according to differences in the control capacity of different subjects in the risk generation chain.
The paper argues that the behavioral control standard is not a completely new creation. It is a systematic distillation of legislative provisions, academic consensus, and judicial experience. At the normative level, the Cybersecurity Law, the Data Security Law, and the Personal Information Protection Law all impose higher security obligations on subjects such as operators of critical information infrastructure, processors of important data, and large online platforms. The positive correlation between control capacity and duty intensity has already been integrated into China’s legal system. At the doctrinal level, control-based imputation theory and risk-based imputation theory can be expanded to bridge the institutional conflict between product liability and fault liability. At the judicial level, Guiding Case No. 271 of the Supreme People’s Court, the Wang Mouqun dangerous driving case, clearly states that a driver who activates assisted driving functions still bears the duty of care for driving safety. The underlying logic is precisely that the driver retains ultimate control over vehicle operation. Therefore, the behavioral control standard advocated in the paper is not a new imputation principle independent of fault liability. It is an ex post objectification of the reasonable duty of care judgment standard within the fault element. In embodied intelligence cognitive harm scenarios, the scope of risk that a reasonable person can foresee and the intensity of preventive measures that should be taken should be defined on the basis of the substantive control capacity of the actor over the risk generation chain.
Second, the paper proposes a three-layer screening method to transform abstract control capacity judgment into operable adjudication rules and achieve precise correspondence between risk management capacity and responsibility intensity. The first layer is technical control review. It takes active intervention authority such as source code access and modification, remote firmware upgrades, and veto over algorithm iteration as the basis for determination. Passive monitoring authority such as operational data monitoring and invocation is considered as auxiliary. The second layer is organizational control review. It examines whether the subject has established an algorithm ethics and risk compliance department and an internal cognitive risk monitoring and reporting system. The third layer is determination of duty of care intensity. It comprehensively adjudicates based on the subject’s profit scale, degree of information asymmetry, professional ability gap, and industry safety standards, implementing distributive justice that matches risk and benefit.
Accordingly, developers, manufacturers, operators, and service providers of embodied intelligence products should bear pre-emptive information collection and risk testing obligations. Users bear supplementary duty of care. When the system issues a takeover prompt, shows obvious anomalies, or exceeds the designed operating scenario, users must intervene promptly and fulfill the duty to avoid danger. At the same time, supporting evidence facilitation rules should be established. Developers, manufacturers, operators, and service providers have the obligation to record and preserve equipment operation data, algorithm iteration logs, and decision process records. If they refuse to provide such evidence without justified reason, an adverse inference may be made by reference to the proof obstruction rule in Article 95 of the Supreme People’s Court Provisions on Evidence in Civil Procedure.
| Layer | Focus | Examples | Function in Imputation |
|---|---|---|---|
| Technical control | Active intervention authority | Source code access and modification, remote firmware updates, veto over algorithm iteration | Establishes primary capacity to prevent or mitigate cognitive risk |
| Passive monitoring | Data observation and invocation | Operational data monitoring, anomaly detection, logging | Supports or supplements control capacity assessment |
| Organizational control | Internal governance and compliance | Algorithm ethics department, risk compliance unit, cognitive risk reporting system | Shows whether control capacity is institutionalized and exercised |
| Duty intensity | Contextual reasonableness | Profit scale, information asymmetry, professional gap, industry safety standards | Matches responsibility to risk and benefit |
Third, the paper uses behavioral control as the core to construct a scenario-based imputation system for cognitive harm. With the subject of control attribution as the horizontal coordinate and the degree of risk foreseeability and controllability as the vertical coordinate, cognitive harm can be divided into four typical scenarios, each corresponding to differentiated imputation rules. The first scenario is damage caused when the producer retains post-deployment control. Fault presumption liability applies. If the producer can continuously intervene in system operation through remote upgrades and data monitoring, it is presumed that it failed to fulfill the duty of care matching its control capacity. The second scenario is damage caused when the user exercises actual control. Ordinary fault liability applies. When the system is within the designed operating conditions, the user’s reasonable reliance should be protected, and the scope of duty of care should be limited accordingly. When the system is abnormal or exceeds the designed operating scenario, the basis for reliance is lost, and the scope of the user’s duty of care expands accordingly. If the user independently breaks functional restrictions or operates in violation of rules, causing cognitive harm, the user bears responsibility. The technical supervisor system in Germany’s 2021 Road Traffic Act follows this logic. The third scenario is damage caused separately by intertwined control of multiple subjects. Several liability applies. Relying on the aforementioned three-layer control review framework, the control capacity and degree of fault of underlying algorithm providers, hardware system integrators, and terminal application service providers are determined separately. Combined with the causal force ratio of each act to the damage result, the respective responsibility shares are finally determined. The fourth scenario is product liability caused by algorithmic emergence. The application space of the development risk defense should be strictly limited. Article 41, paragraph 2, item 3, of the Product Quality Law allows producers to be exempted if the defect could not be discovered at the level of scientific and technological knowledge at the time the product was put into circulation. The judgment of scientific and technological level should be strictly based on the overall level of science and technology at the time. For irreversible mental and personality harm caused by cognitive risk, the paper recommends excluding the application of this defense and simultaneously establishing mandatory insurance and industry mutual aid funds to spread risk.
| Scenario | Control Attribution | Imputation Rule | Rationale in Embodied Intelligence |
|---|---|---|---|
| Producer retains post-deployment control | Remote upgrades, monitoring, continuous intervention | Fault presumption | Producer has ongoing technical capacity to prevent or mitigate cognitive risk |
| User exercises actual control | Within or outside designed operating conditions | Ordinary fault liability | Reasonable reliance within system limits; expanded duty when trust basis disappears |
| Multiple subjects with intertwined control | Algorithm provider, hardware integrator, application service provider | Several liability | Control capacity and causal force differ across the embodied intelligence chain |
| Algorithmic emergence | Autonomous iteration and emergent behavior | Strict product liability with narrowed development risk defense | Irreversible mental personality harm requires stronger risk spreading and producer responsibility |
The paper notes that this scenario-based imputation logic can be concretized into a gradient institutional design. The graded adaptation in the autonomous driving field can serve as a typical reference. At L0-L2 assisted driving levels, the driver retains ultimate control, corresponding to the user-control scenario. The current rules with fault liability as the main basis and product liability as a supplement apply. At L3 conditional automation, the system obtains substantive control within the designed operating domain. It is necessary to focus on the manufacturer’s design and deployment control capacity. The paper recommends building a dual-track rule with product liability as the main basis and user fault liability as a supplement. If the system only prompts takeover a few seconds before a collision, liability should not be directly attributed to the driver. At L4 and above highly automated levels, the manufacturer possesses exclusive professional control capacity, corresponding to the scenario in which the producer retains control. The paper recommends applying strict product liability and narrowing the development risk defense. This gradient scheme can effectively respond to the controversy over takeover time limits under human-machine shared driving, and its core logic can be analogized to cognitive harm scenarios of other embodied intelligence applications.
| Automation Level | Control Holder | Recommended Liability Structure | Special Consideration for Embodied Intelligence |
|---|---|---|---|
| L0-L2 assisted driving | Driver retains ultimate control | Fault liability primarily; product liability supplement | User control scenario; reasonable reliance limited by system limits |
| L3 conditional automation | System has substantive control within designed operating domain | Product liability primarily; user fault liability supplement | Manufacturer design and deployment control are central; short takeover prompts should not automatically shift liability to driver |
| L4 and above high automation | Manufacturer has exclusive professional control | Strict product liability; narrow development risk defense | Producer retains post-deployment control; irreversible cognitive harm requires stronger protection |
Fourth, the paper discusses procedural safeguards and normative linkage mechanisms for the behavioral control standard. The effective operation of the imputation system requires coordinated supporting mechanisms. First, legislation should mandate that embodied intelligence devices install full-process data recording devices conforming to national standards. These devices should completely preserve system operation status, algorithm decision process, control handover nodes, and software version information to provide objective evidence for determining control status. Second, for scenarios where responsibility allocation is difficult, such as emergent damage and multi-subject joint damage, the mandatory insurance system should be improved. Third, the preventive claims and personality rights infringement injunction system in the Civil Code should be activated. Right holders can request cessation of high-risk data collection, closure of cognitive intervention functions, and deletion of cognitive algorithmic representations before cognitive intervention causes substantive damage. This forms a full-chain protection system together with ex post compensation.
- Implications for Regulators, Industry, Courts, and Users
For regulators, the paper implies that embodied intelligence cannot be governed solely through conventional personal information protection. Regulatory standards must be updated to recognize dynamic biometric data that can infer mental states as sensitive personal information. Consent must be redesigned as a tiered and dynamic process rather than a one-time click. High-risk cognitive functions should be off by default. Data recording devices and algorithm logs should become mandatory infrastructure for accountability. The regulatory task is not only to prevent data breaches but also to prevent the covert shaping of attention, emotion, and preference through embodied intelligence.
For industry, the paper suggests that compliance should move from notice-and-consent formalities to privacy-by-design and cognitive-risk-by-design. Developers, manufacturers, operators, and service providers of embodied intelligence should establish internal risk monitoring, algorithm ethics review, and decision logging. They should preserve operational data, algorithm iteration logs, and control handover records. They should design interfaces that allow users to inspect, change, and withdraw consent. They should avoid bundling high-risk cognitive functions with core services. They should also prepare for stricter product liability and limited development risk defenses in high-automation scenarios.
For courts, the paper offers a behavioral control test to determine reasonable care and allocate responsibility. Courts should examine technical control, organizational control, and contextual duty intensity. They should use adverse inferences when relevant evidence is withheld. They should recognize that cognitive harm can be cumulative, hidden, and delayed. They should also use preventive injunctions to stop high-risk data collection or cognitive intervention before irreversible harm occurs. The paper’s scenario-based approach gives courts a structured way to avoid both over-attribution to users and under-attribution to those who actually control the embodied intelligence system.
For users, the paper implies a shift from passive consent to active cognitive self-defense. Users should be able to withdraw consent, disable high-risk functions, and seek deletion of cognitive algorithmic representations. However, the paper also recognizes that individual control is limited when embodied intelligence is embedded in daily life and core services. Therefore, user rights must be supported by institutional design, mandatory defaults, transparent interfaces, and effective remedies. The protection of cognitive autonomy cannot depend only on individual vigilance in an environment designed by embodied intelligence.
- Limitations and Future Research on Embodied Intelligence and Cognitive Risk
The paper acknowledges several limitations. First, it mainly relies on normative analysis and comparative law methods, and empirical support needs to be strengthened. Second, the behavioral control imputation standard still needs to be tested in judicial practice. Future research will combine case mining, industry surveys, and user surveys. It will focus on rule design for scenarios such as autonomous driving, healthcare, and consumer interaction. The goal is to build a cognitive risk governance system adapted to the technological development of embodied intelligence.
| Research Direction | Method | Application Scenario | Expected Contribution |
|---|---|---|---|
| Empirical validation of cognitive risk | Case mining and user surveys | Consumer interaction, mental health, education | Measure hidden and cumulative effects of embodied intelligence |
| Behavioral control standard testing | Judicial case analysis and doctrinal refinement | Autonomous driving, robotics, smart devices | Clarify reasonable care and responsibility allocation |
| Dynamic consent implementation | Industry survey and interface experiments | Home robots, wearables, healthcare assistants | Reduce consent fatigue and improve meaningful control |
| Insurance and risk spreading | Comparative institutional design | High-automation embodied intelligence | Address irreversible mental personality harm |
- Conclusion: The Regulatory Future of Embodied Intelligence
The paper constructs a two-stage analytical framework for cognitive risk from embodied intelligence and proposes that legal regulation should undergo a paradigm shift from information control to personality protection. Its main contributions are threefold. First, it clarifies the transmission logic of cognitive risk along data collection, algorithmic representation, and cognitive intervention. Second, it justifies a personality interest protection path for cognitive autonomy and establishes a behavior-oriented regulation model. Third, it proposes a tiered dynamic consent mechanism and a behavioral control-based imputation system to resolve the institutional dilemmas of risk prevention and harm remedy.
The broader significance of the argument is that embodied intelligence is not merely a new data processor. It is a technology that can enter private space, induce disclosure, infer mental states, and intervene in emotional and attentional processes. If law responds only through traditional information control, it will regulate the visible data trail while missing the deeper cognitive dynamics. If law overcorrects by creating an absolute right against all influence, it risks freezing normal social interaction and technological development. The paper’s middle path is to treat cognitive autonomy as a protected personality interest, impose behavior-oriented duties on those who control the embodied intelligence risk chain, and match liability to actual behavioral control. This approach seeks to protect mental integrity, mental privacy, and cognitive autonomy without abandoning the existing legal framework.
As embodied intelligence moves further into homes, hospitals, roads, workplaces, and consumer environments, the legal question will become increasingly urgent. The paper argues that the answer is not simply more information control. It is a broader commitment to personality protection in an age of embodied intelligence. The future of regulation will depend on whether law can align control, duty, and remedy across the entire lifecycle of embodied intelligence, from data collection and algorithmic representation to cognitive intervention and ex post accountability.
