Framework · The Cognitive Privacy Project
The Cognitive Privacy Impact Assessment
A framework for evaluating AI systems that capture, infer from, or influence cognitive processes.
Why existing assessments miss the harm
Every serious organization now runs privacy impact assessments. None of them ask what a system does to the thinking of the person using it.
A Data Protection Impact Assessment evaluates what happens to information: where it is collected, how it is stored, who can access it, when it is deleted. These are custody questions, and mature instruments exist for all of them. The CPIA asks a different question: what does the system observe about, infer from, and do to the cognitive processes of its users? A system can pass every custody test and still monitor hesitation, model intent, and steer judgment.
A DPIA asks
Is the data handled correctly?
Collection, storage, access, retention, deletion. The unit of analysis is the record.
A CPIA asks
Is the mind handled correctly?
Observation, inference, influence, dependence. The unit of analysis is the cognitive process.
The six domains of cognitive capture
The framework assesses a system across six domains. Each names a mechanism, states what a deploying organization must be able to demonstrate, and provides the questions an assessor asks.
Domain 01
Process observation
What the system watches beyond what the user submits: drafts, deletions, hesitation, revision patterns, time-on-task, abandoned inputs. The drafting phase is where thinking happens, and a system that records it holds a record of cognition itself, not of its products.
The assessor asks
Does the system capture pre-submission behavior? Is any of it retained, transmitted, or used for training? Can the user see what has been observed?
Domain 02
Inference generation
What the system concludes about the user from behavioral data: confidence, confusion, emotional state, susceptibility, intent. Inference converts observation into a model of the person, and the model belongs to the operator, not to the person it describes.
The assessor asks
What user attributes does the system infer? Are inferences stored, shared, or monetized? Can the user inspect and contest the model of themselves?
Domain 03
Output steering
How the system's responses shape the user's conclusions: framing, ordering, omission, sycophantic agreement, confidence performance. Cognitive prompt injection names the case where steering is deliberate and adversarial.
The assessor asks
Is the system optimized for engagement or agreement? Does it present alternatives and uncertainty honestly? Would the user's conclusion differ if the same content arrived unranked?
Domain 04
Dependence formation
Whether sustained use degrades the user's unassisted capability. For adults this is analytic atrophy; the organizational version is a workforce that cannot evaluate the outputs it approves. Gerlich's 2025 finding of a strong negative relationship between heavy AI use and critical thinking is the population-scale signal.
The assessor asks
Is unassisted performance measured at intervals? Does the deployment include tool-free practice? Who is accountable when capability declines?
Domain 05
Judgment displacement
Where the system's output substitutes for a decision a person is accountable for. A recommendation accepted without evaluation is a decision transferred, and the transfer is invisible in the record, which shows a human clicking approve.
The assessor asks
Which decisions does the output feed? Is acceptance-without-modification tracked? Does the organization know its own override rate?
Domain 06
Developmental exposure
Whether the system reaches users whose cognitive capacities are still forming. For minors the risk is not degradation of a built capacity but the foreclosure of one that would otherwise have formed. Institutional obligations here are the subject of When AI Tutors Fake Critical Thinking.
The assessor asks
Can the system reach minors? Does deployment distinguish developing users from built ones? What evidence supports safety for the youngest user the system can reach?
The Ephemeral Processing Standard
The framework's strictest tier. A system meets the EPS when cognitive engagement leaves no residue: nothing observed in the drafting phase is retained, no model of the user persists between sessions, and no inference outlives the interaction that produced it.
What passes and what fails
| System behavior | EPS verdict | Domain |
|---|---|---|
| Session context discarded at close; no training on user inputs | Passes | 01, 02 |
| Draft keystrokes and deletions logged for "product improvement" | Fails | 01 |
| Persistent memory of user traits across sessions, on by default | Fails | 02, 04 |
| Engagement-optimized response ranking | Fails | 03 |
Who this serves
Enterprise & procurement
A structured instrument for evaluating AI vendors before deployment, alongside the DPIA rather than instead of it. The six domains convert directly into contract language and vendor questionnaires.
Policy & governance
A vocabulary for the harms current instruments cannot see, and a demonstration that they are assessable. The EPS gives regulators a bright-line standard that does not depend on auditing model weights.
Boards & risk officers
Domains 04 and 05 name the exposure that lands on the organization: a workforce whose judgment quietly transferred to its tools, with the approval records showing humans in the loop throughout.
Schools using Connected Classroom
The developmental register of this work, including workshops and advisory for schools, lives at Connected Classroom. Domain 06 is where this framework hands over to that one.
Where regulation is heading
The regulatory gap
Neural data statutes in Colorado, California, Montana, and Connecticut regulate signals measured from the nervous system. The EU AI Act's prohibited practices reach manipulation that causes significant harm. Neither reaches the ordinary case this framework assesses: behavioral inference from typing, hesitation, revision, and abandonment, deployed at scale, causing no injury a court would recognize.
The CPIA is written for the gap: an instrument organizations can adopt voluntarily now, phrased so that adopting it later under mandate requires no translation.
Using the framework
The full document provides the assessment instrument: domain-by-domain question sets, the scoring rubric, the EPS certification checklist, and worked examples. It is published open access under CC BY-NC 4.0.
Organizations wanting a facilitated assessment, or cognitive privacy literacy for their teams, can write to timothy@cognitiveprivacyproject.org.
Selected references
Cook, T. (2026). The era of cognitive capture: Protecting mental autonomy in the age of behavioral algorithms. The Cognitive Privacy Project. https://doi.org/10.13140/RG.2.2.20782.16965
Cook, T., & Purdy, R. J. (2026). When AI tutors fake critical thinking: From cognitive harm to institutional liability. The Cognitive Privacy Project. https://doi.org/10.13140/RG.2.2.18400.24322
Gerlich, M. (2025). AI tools in society: Impacts on cognitive offloading and the future of critical thinking. Societies, 15(1), 6.
Jakesch, M., Bhat, A., Buschek, D., Zalmanson, L., & Naaman, M. (2023). Co-writing with opinionated language models affects users' views. CHI '23.
Risko, E. F., & Gilbert, S. J. (2016). Cognitive offloading. Trends in Cognitive Sciences, 20(9), 676–688.

