Neural Least Privilege: An Authorization Framework for Foundation-Model-Enabled Neuroadaptive Healthcare
Abstract
Foundation and generative models are moving from passive clinical prediction toward interactive health systems that can recommend or adapt interventions. Neural interfaces make this shift safety-critical because the same system may infer patient state and act back on the patient. We take the position that clinical authority must not expand automatically with model capability. We formalize neural least privilege: a foundation-model-enabled neuroadaptive system should receive only the task-scoped authority needed to read signals, expose inferences, specify targets, and actuate an approved clinical function. A Neural Authorization Specification separates these permissions from trajectory-level safety requirements and a trusted runtime filter. An illustrative auditory neuroprosthesis spans restoration, consented augmentation, unauthorized targeting, and prospective adaptive influence. We also propose a virtual-patient protocol for testing whether capability transfers to new patients more reliably than authorization and safety. We report no new experiments and make no end-to-end clinical safety claim.