AI Policy

AI and the Right to Be Forgotten: Can You Ever Truly Disappear?

AI right to be forgotten illustration of person fading from digital data trail
AI and the Right to Be Forgotten

By Stuart Kerr, Technology Correspondent, LiveAIWire

The AI right to be forgotten sounds simple in principle and turns out to be almost impossible to enforce in practice. A man in Germany successfully petitioned Google in 2014 to delist search results linking his name to a decades-old bankruptcy. The European Court of Justice ruling that enabled that delisting established the right to be forgotten as a legal principle in EU data protection law.

It did not make him disappear. The information remained on the original websites; it remained in the memories of people who had read it; and it remained, somewhere, in the training data of AI models that had ingested those web pages before the delisting was processed. The right to be forgotten was real. The forgetting was not.

AI has made the right to be forgotten simultaneously more important and harder to enforce. The scale at which personal information is ingested, processed, and reproduced by AI systems vastly exceeds anything that earlier data protection frameworks anticipated. Understanding what the right means in an AI context, and what genuine enforcement would require, is one of the most practically significant questions in current data protection law.

What the AI Right to Be Forgotten Actually Covers

The AI right to be forgotten stems from GDPR Article 17, under which individuals have the right to request erasure of their personal data from data controllers who hold it, subject to conditions and exceptions. In practice, the right most commonly applies to search engine delisting, the removal of personal information from websites, and the deletion of records from databases.

The AI complication arises at the training data stage. When a personal data point is included in the training dataset for an AI model, it influences the model’s parameters in a distributed way that is not easily reversible. Deleting the original training record does not remove the model’s learned associations, vocabulary, or the implicit knowledge it acquired from processing the deleted data. Research from the UK Information Commissioner’s Office has acknowledged this challenge directly, calling for the development of machine unlearning techniques that can remove specific data influences from trained models without requiring complete retraining.

Machine Unlearning: The Technical State of Play

Machine unlearning, the technical mechanism that would make the AI right to be forgotten enforceable by modifying a trained model to remove the influence of specific training data points, is an active area of research that has produced promising results in controlled settings. Full retraining is computationally prohibitive at the scale of frontier AI models, where a single training run costs tens of millions of dollars. Approximate unlearning methods have been developed that can reduce the model’s association with specific data without full retraining, but verifying whether those methods have actually removed the influence, rather than merely obscuring it, remains technically difficult.

What this means for anyone who has submitted a right to erasure request to an AI company: the legal obligation to process your request may be met through documentation and process rather than through verified technical removal of your data’s influence from AI systems.

Generative AI and Personal Data Reproduction

Large language models and image generation systems can reproduce personal information in ways that create fresh privacy violations beyond the training data question. A language model that has processed news articles, court records, or social media content during training may generate text that accurately describes private information about identifiable individuals, not because it has retrieved a stored record, but because the training process has encoded associations that the model can reconstruct from appropriate prompts.

Several European data protection authorities have issued guidance and enforcement decisions addressing this. The Italian Data Protection Authority’s 2023 temporary ban on ChatGPT, later lifted after OpenAI provided additional information about its data practices, established that AI systems are subject to GDPR even when their data handling does not fit neatly into categories the regulation was designed for.

The Right Across Borders

The AI right to be forgotten is a European legal concept that applies to data controllers operating in or directing services at EU residents. Its application to AI systems trained globally and accessed globally is complicated by jurisdictional questions that have not been fully resolved. Outside the EU, the right to be forgotten has no direct equivalent in most jurisdictions, though privacy law frameworks in California, Brazil, and several other jurisdictions provide related but narrower rights.

The broader challenge of applying legal frameworks designed for an earlier technological environment to AI systems applies acutely here, a tension LiveAIWire has also traced in our coverage of AI valuation tools entering divorce court. The question of data rights and posthumous digital identity is a close cousin: LiveAIWire’s coverage of AI digital resurrection found that in both cases, the law provides a right whose technical enforcement is significantly more complex than the right itself acknowledges.

What Genuine Enforcement Would Require

Genuine enforcement of the AI right to be forgotten would require, at minimum, technical standards for machine unlearning that can be independently verified, disclosure requirements for the personal data included in AI training datasets, audit mechanisms that allow data protection authorities to assess whether erasure requests have been technically fulfilled, and liability frameworks that assign responsibility when AI systems reproduce information that subjects have successfully requested to be erased. None of these components of a functioning AI right to be forgotten are currently in place at sufficient maturity or scale.

The broader accountability gap in AI systems that make consequential decisions using personal data is directly relevant here too, as LiveAIWire has traced in our coverage of the silent bias that reinforces inequality in AI systems. Transparency and erasure rights are two dimensions of the same underlying challenge of giving individuals meaningful control over how their data is used in systems they cannot observe. The European Data Protection Board guidelines on the right to erasure address the technical complexity of erasure in automated decision-making systems directly.

About the Author

Stuart Kerr is Technology Correspondent at LiveAIWire, covering artificial intelligence, cybersecurity, and the social impact of emerging technology. He publishes daily at LiveAIWire.com.