Late in 2017, psychologists working with a large social platform published a field experiment that marketers read as a proof of concept and ethicists read as a warning. They matched advertising copy to users’ psychological profiles instead of to their demographics. Appeals tuned to a person’s openness, extraversion, or need for cognition drew up to 40 percent more clicks and 50 percent more purchases than mismatched appeals, across several million people (Matz, Kosinski, Nave, and Stillwell, PNAS, 2017). Nothing in the experiment touched a nerve. No electrode, no drug, no scanner. The targeting was assembled from traces people had already left behind: likes, shares, the ordinary sediment of online life.
That study is the honest starting point for any serious discussion of “neural advertising.” It shows how far persuasion can travel without direct access to the brain, and it shows why the label misleads. The phrase promises marketing that reaches the reward system itself, reading susceptibility and turning desire up or down. The demonstrated frontier is narrower and stranger: systems that infer dispositions from behavior, time appeals to moods, and revise themselves when the first attempt fails. Deliberate modulation of reward circuitry remains a medical and laboratory practice rather than a consumer service.
Where to place the boundary between persuasion and direct modulation of reward is the question this article takes up. Ordinary persuasion addresses a person as a chooser. It offers a claim, a reason, an image, and leaves the assessment to the person. Direct modulation would bypass that step by changing the value signal itself, so that an offer appears better than the person’s own judgment would have rated it. Conflating the two produces opposite errors. Treat every targeted advertisement as a mind-control device and the concept loses precision. Treat commercial neurotechnology as one more advertising channel and a change in kind goes unnoticed.
Psychological targeting, and its contested effect sizes
The 2017 study by Sandra Matz and her colleagues was not the first attempt to link personality to persuasion, but it was the first to demonstrate the effect at scale in a live advertising environment. The researchers built psychological profiles from Facebook “likes,” which carry surprisingly reliable signals about traits, then delivered advertisements matched or mismatched to those profiles. Matched appeals won, and the gap was large enough to be commercially meaningful. The result drew published methodological criticism in the same journal, along with author replies, and the exchange is worth remembering: the finding is real and peer-reviewed, and its magnitude is disputed.
Eight years later, generative models moved the same idea from a research demonstration toward an ordinary tool. In a 2024 study in Scientific Reports, Matz and colleagues found that messages written by a large language model to match an individual’s psychological profile shifted attitudes more than non-personalized messages, across several domains and traits, with a total of 1,788 participants across the experiments. The per-person effect was modest rather than sweeping, and it depended on the personalization being perceptible. A separate preregistered study found no advantage for personalized political messages over generic ones, and a published exchange over that null result turned on precisely this point: tailoring that a recipient cannot feel or cannot connect to their own concerns has little to work with. The practical lesson is temperate. Personalization helps, sometimes substantially, when a system knows something real about a person and uses it in a way that person can register. It is not a universal solvent for resistance, and the field’s own disagreements should keep anyone from declaring the persuasion problem solved in either direction.
Choice architecture as a regulated surface
The most consequential influence on a platform is often not the message but the arrangement of the screen. Design researchers have catalogued the recurring shapes of this problem. Colin Gray and colleagues analyzed a corpus of 118 examples drawn from practitioner discussion and identified five families of “dark patterns”: nagging, obstruction, sneaking, interface interference, and forced action. Each does its work by making the desired option frictionless and the alternative costly in time, attention, or social embarrassment.
Government enforcement has made the pattern concrete. The Federal Trade Commission’s 2022 staff report, “Bringing Dark Patterns to Light,” described cases in which design choices misled consumers into believing they had been approved for credit products, and it noted that drip pricing — revealing mandatory fees late in a transaction — led consumers to spend roughly 20 percent more than they would have under clear, upfront pricing.
Europe has written a line closer to the substrate question. The AI Act bans AI systems that deploy subliminal techniques beyond a person’s consciousness, or purposefully manipulative or deceptive techniques, when the objective or effect is to materially distort behavior by appreciably impairing a person’s ability to make an informed decision and significant harm is reasonably likely. The accompanying recitals name machine-brain interfaces and virtual reality as technologies that could facilitate exactly this kind of influence. That is not yet a rule about reward modulation, and it is drafted with criminal fraud, scam voice clones, and addictive design in mind rather than advertising. But it establishes the principle that bypassing a person’s capacity to consider an influence is a different legal category from merely being persuasive.
Notice where the regulated line sits. The consumer-protection rules govern the procedure of a transaction and the vulnerability of a target group. A dark pattern operates on attention and effort; a persuasive message operates on belief and desire. Neither yet operates on the machinery that assigns value. Even the AI Act’s manipulation ban is gated on significant harm and written for deception and exploitation rather than for advertising, so the law has a concept of the problem without a rule aimed at the third category. That gap is the spine of the whole discussion, because the tools now available were built for the first two categories and may not transfer to the third.
Advertising’s measurement problem
Any account of advertising power has to survive an inconvenient literature. In a 2015 paper in the Quarterly Journal of Economics, Randall Lewis and Justin Rao reported results from 25 large-scale field experiments representing about $2.8 million in advertising spending. The median return-on-investment confidence interval exceeded 100 percentage points, which is a technical way of saying that for most campaigns the data could not distinguish a real effect from nothing at all. Around the same time, Thomas Blake, Chris Nosko, and Steven Tadelis ran field experiments on eBay’s search advertising and found that brand-keyword ads produced no measurable short-term benefit, that average returns on non-brand search advertising were negative, and that the ads did work for users who were new or infrequent.
These results cut in two directions. They deflate the image of the advertiser as an omniscient puppetmaster: much of what is sold as precision persuasion cannot be measured well enough to justify the claim. They also explain why targeting keeps expanding. If advertising works only for a subset of people, then finding that subset is where the money is, and modern inference is precisely a machine for finding subsets. A better-targeted mediocre message can beat a well-measured broadcast, and the industry’s incentive to know more about individual susceptibility follows from the measurement problem rather than in spite of it.
Salience at scale
Most of the influence exerted by recommender systems is not persuasion at all. It is selection. A 2025 audit by Luke Milli and colleagues, published in PNAS Nexus, manipulated the ranking of political content for 806 Twitter users and compared an engagement-optimized feed with a reverse-chronological one. The engagement ranking amplified out-group-hostile content. When the same users were asked what they wanted to see, they did not prefer the algorithm-selected political tweets. An alternative ranking built from users’ stated preferences reduced anger and hostility, though the authors noted that it could also intensify echo chambers by showing people mostly what they already agreed with.
The older Facebook emotional-contagion experiment, published by Adam Kramer, Jamie Guillory, and Jeffrey Hancock in PNAS in 2014, manipulated the emotional content of nearly 690,000 users’ feeds and reported a small shift in the emotional tone of what those users then posted. The study later carried an editorial expression of concern over consent, and it should be cited with that caveat attached. It remains valuable less as a settled result than as a demonstration of the reach a platform can command and of how weakly such experiments were governed at the time.
Selection and salience are levers of enormous practical power. They still operate upstream of the reward signal. What a recommender decides is which offer you see, not how good the offer feels once seen. That is the subject of Whoever Controls Salience Controls Behavior, and the reason the two levers are so often confused.
Wanting without liking
To understand what “reaching the reward system” would actually mean, the relevant science is older and stranger than the advertising literature. In a 1998 review in Brain Research Reviews, Kent Berridge and Terry Robinson argued that dopamine does not encode pleasure. It encodes incentive salience: the pull of a cue, the motivational “wanting” that makes a reward loom. The hedonic “liking” of an experience depends on different circuitry. The two can be dissociated, and the dissociation is the signature of compulsion. An animal that wants without liking will work harder and harder for something it no longer enjoys.
This is the shape of the capability that the phrase “neural advertising” gestures toward. A system that raised wanting while leaving liking untouched would be manufacturing craving rather than satisfaction, and it would be doing so at a scale no drug dealer could match. The demonstrated versions of that kind of intervention are clinical. In a widely discussed 2021 case, Khambhati and colleagues reported on a patient with severe, treatment-resistant depression who received a closed-loop implanted device that detected a neural signature of low mood and delivered stimulation in response, with substantial improvement. Less invasive methods for reaching deep structures, including focused ultrasound and temporal interference, are under active investigation for psychiatric and neurological conditions.
Every one of these uses is medical, gated by clinicians, and aimed at restoring function. That gate is the current boundary. The open question is whether the same underlying capability migrates into products whose purpose is to sell things. The mechanics of that clinical loop — setpoint, sensor, estimator, controller, actuator — are set out in The Mind as a Control System.
Reading, timing, writing
It helps to separate three regimes, because they are governed by different logic and deserve different scrutiny.
Reading is inferring a person’s state from behavior, context, or physiology. Advertising has done this since the first mailing list, and modern inference has made it finer and faster. Reading alone does not manipulate; it informs the seller.
Timing is delivering an offer at a moment of inferred susceptibility — when someone is tired, lonely, bored, or depleted of self-control. There is real evidence that moments matter, and nothing about timing requires any access to the brain. The 2017 personality-targeting experiments are essentially a timing-and-matching technology.
Writing is changing the state itself, or changing the value signal so that a given offer feels more desirable than it otherwise would. This is the regime the neuroscience makes imaginable and the law has barely contemplated.
The moral gradient runs with the degree to which influence bypasses a person’s capacity to consider it. That gradient is not clean. Reading and timing, combined at scale, can approximate writing in effect: if a system knows exactly when your resolve is lowest, it does not need to alter your brain to get the response it wants. That is one reason the boundary question resists a single bright line, and one reason a purely informational remedy — disclose more — will not be sufficient.
Why consent will struggle with the hardest cases
Consent is the standard answer, and it does the least work exactly where it is asked to do the most. A gig worker accepts algorithmic management because refusal costs income. A user in an altered state agrees to continue the intervention that produced the altered state. A platform may truthfully disclose its data collection while designing the service so that dependence is economically rewarded. In each case, a box is ticked and the underlying question — whether the person is in a position to weigh the choice — remains open.
The hardest case is self-authorizing escalation. If an intervention changes a preference, and the changed preference then endorses more of the same intervention, the formal record of consent can become a mechanism for ratcheting past the point where the person, at baseline, would have agreed to go. A workable safeguard is baseline control: consequential changes should be reversible, inspectable, and capable of being reaffirmed when the person is not under the state-changing intervention. That principle is already standard in some medical contexts, where a plan set during an acute episode is revisited when the patient is stable. Translating it into consumer systems would require commitments most products have no reason to make on their own.
What a defensible boundary looks like
Three commitments follow from the analysis.
First, for reading and timing, demand transparency and contestability rather than prohibition. People should be able to learn what was inferred about them, on what basis, and how it was used, and they should be able to challenge the inference. That is the right tool for influence that operates through belief and attention, where a ban would be both overbroad and unenforceable.
Second, for writing, treat the capability like the medical intervention it is. A device with write access to motivation should face premarket review, adverse-event reporting, and clinical oversight regardless of whether the intended use is therapy or commerce. Regulating the device is a regulation of conduct rather than speech, which is what makes it legally durable; the informational remedies that fail against a persuasive claim can succeed against a piece of hardware.
Third, keep the categories separate in law and in language. A blanket prohibition on commercial reward modulation should not become a blanket prohibition on consumer neurotechnology for health, meditation, or accessibility. Precision here is not pedantry. Blur the categories and the rules either overreach into medicine or underreach into commerce. The case for treating mental states as a protected domain rather than a commercial input is made at greater length in Neural Rights.
The benefits worth protecting
Advertising has a legitimate function. It tells people what exists, funds much of what is free, and lets buyers and sellers find each other without exhaustive search. Well-targeted relevance can reduce noise: a person who is shown fewer, better-matched advertisements is not obviously worse off. The clinical cases are more striking still. Closed-loop stimulation has restored function for people whose depression resisted every conventional treatment. Brain-computer interfaces let paralyzed users communicate. Accessibility tools let people with attention difficulties structure their own days.
These are reasons for care, not for complacency. The same neural interfaces that restore mood in a supervised clinic could, with a different objective function, intensify craving in a consumer setting. The technology is not inherently liberating or inherently corrosive; the objective function and the governance decide which it becomes. An honest accounting keeps both columns visible and refuses to let the promise of medicine purchase silence about the commercial risk, or the fear of commerce veto the medicine.
What should change anyone’s mind about how urgent this is? Not demonstrations, which are cheap. Repeated outcomes in independent trials, effects that transfer beyond a single platform or population, and above all evidence about long-run agency: whether users of a system become more able to live according to their reflective values over years, or simply more responsive to whoever controls the interface. That is the test that separates a better marketplace from a more efficient form of capture, and it is the test the field has barely begun to run.
Sources and further reading
- Matz, S. C., Kosinski, M., Nave, G., & Stillwell, D. J. “Psychological targeting as an effective approach to digital mass persuasion.” Proceedings of the National Academy of Sciences 114(48), 2017. https://www.pnas.org/doi/10.1073/pnas.1710966114
- Matz, S. C., Teeny, J. D., Vaid, S. S., Peters, H., Harari, G. M., & Cerf, M. “The potential of generative AI for personalized persuasion at scale.” Scientific Reports 14:4692, 2024. https://www.nature.com/articles/s41598-024-53755-0
- Gray, C. M., Kou, Y., Battles, B., Hoggatt, J., & Toombs, A. L. “The Dark (Patterns) Side of UX Design.” Proceedings of the 2018 CHI Conference on Human Factors in Computing Systems. https://doi.org/10.1145/3173574.3174108
- Federal Trade Commission. “Bringing Dark Patterns to Light.” Staff report, September 2022. https://www.ftc.gov/reports/bringing-dark-patterns-light
- European Parliament and Council. Regulation (EU) 2024/1689 (AI Act), Article 5 and Recital 29; Commission guidelines on prohibited AI practices, C(2025) 5052 final. https://eur-lex.europa.eu/eli/reg/2024/1689/oj
- Lewis, R. A., & Rao, J. M. “The Unfavorable Economics of Measuring the Returns to Advertising.” Quarterly Journal of Economics 130(4), 2015. https://doi.org/10.1093/qje/qjv023
- Milli, S., Carroll, M., Wang, Y., Pandey, S., Zhao, S., & Dragan, A. D. “Engagement, user satisfaction, and the amplification of divisive content on social media.” PNAS Nexus 4(3), 2025. https://doi.org/10.1093/pnasnexus/pgaf062
- Berridge, K. C., & Robinson, T. E. “What is the role of dopamine in reward: hedonic impact, reward learning, or incentive salience?” Brain Research Reviews 28(3), 1998. https://doi.org/10.1016/S0165-0173(98)00019-8
Loading comments…