Right to Erasure in Generative Artificial Intelligence Models: Functional Neutralization Standard
Main Article Content
Abstract
The training of generative artificial intelligence models has reshaped the challenges facing data protection by creating systems in which the removal of personal information is technically difficult once it has been incorporated into the model. Against this background, this article examines the legal scope of the right to erasure under Article 17 of the General Data Protection Regulation (GDPR) when personal data have been used to train a generative artificial intelligence model. The study adopts a qualitative documentary approach grounded in doctrinal legal study and an interpretive research paradigm. The analysis demonstrates that the technical infeasibility of physically removing embedded personal data does not constitute an independent exception to the right to erasure. To address this issue, the article develops a verifiable functional neutralization standard based on a three-part test comprising non-reproducibility, non-inferability, and proportionality of the required technical effort. It concludes that the obligation to erase personal data remains mandatory, while functional neutralization is compatible with the right to erasure only where it produces verifiable outcomes, effectively reduces the risk of identification, and is supported by appropriate documentation, auditing, and oversight.
Article Details
References
Achille, A., Kearns, M., Klingenberg, C., & Soatto, S. (2024). AI Model Disgorgement: Methods and Choices. Proceedings of the National Academy of Sciences, 121(18), e2307304121. https://doi.org/10.1073/pnas.2307304121
Arentowska, E. (2026). Prawo do bycia zapomnianym w erze AI: Czy pelne usunięcie danych z modelu sztucznej inteligencji jest możliwe? Krytyka Prawa, 18(1), 98-114. https://doi.org/10.7206/kp.2080-1084.837
Beduschi, A. (2026). Data Protection in the Era of Agentic Artificial Intelligence. Computer Law & Security Review, 61, 106342. https://doi.org/10.1016/j.clsr.2026.106342
Carlini, N., Tramèr, F., Wallace, E., Jagielski, M., Herbert-Voss, A., Lee, K., Roberts, A., Brown, T., Song, D., Erlingsson, Ú., Oprea, A., & Raffel, C. (2021). Extracting Training Data from Large Language Models. In Proceedings of the 30th USENIX Security Symposium (pp. 2633-2650). USENIX Association. https://www.usenix.org/conference/usenixsecurity21/presentation/carlini-extracting
Cevallos, I. D., Benalcázar, M. E., Valdivieso Caraguay, Á. L., Zea, J. A., & Barona-López, L. I. (2025). A Systematic Literature Review of Machine Unlearning Techniques in Neural Networks. Computers, 14, 150. https://doi.org/10.3390/computers14040150
Chahine, K., Zakka El Nashef, G., Abdel Karim, A. K., Al Atem, M., Noura, H. N., & Arnaout, M. (2026). A Survey of Machine Unlearning for Electric Power Systems: From Privacy Compliance to Resilient Grid Operations. Array, 31, 100987. https://doi.org/10.1016/j.array.2026.100987
Cippitani, R. (2025). Retos jurídicos del tratamiento de los datos (personales y no personales) a través de sistemas de inteligencia artificial en el derecho de la Unión Europea. Revista Justicia y Derecho, 8(t), 1-21. http://dx.doi.org/10.32457/rjyd.v8it.3232
European Data Protection Board. (2024, 17 de diciembre). Dictamen 28/2024 sobre determinados aspectos de la protección de datos relacionados con el tratamiento de datos personales en el contexto de los modelos de IA. https://www.edpb.europa.eu/documents/opinion-of-the-board-art-64/opinion-282024-on-certain-data-protection-aspects-related-to_es
Fan, C., Liu, J., Zhang, Y., Wong, E., Weis, D., & Liu, S. (2024). SalUn: Empowering Machine Unlearning Via Gradient-Based Weight Saliency in Both Image Classification and Generation. International Conference on Learning Representations (ICLR 2024). https://proceedings.iclr.cc/paper_files/paper/2024/hash/ec4d2e436794d1bf55ca83f5ebb31887-Abstract-Conference.html
Feretzakis, G., Papaspyridis, K., Gkoulalas-Divanis, A., & Verykios, V. S. (2024). Privacy-Preserving Techniques in Generative AI and Large Language Models: A Narrative Review. Information, 15(11), 697. https://doi.org/10.3390/info15110697
Gao, X., Ma, X., Wang, J., Sun, Y., Li, B., & Ji, S. (2024). VeriFi: Towards Verifiable Federated Unlearning. IEEE Transactions on Dependable and Secure Computing, 21(6), 5720-5736. https://doi.org/10.1109/TDSC.2024.3382321
Graves, L., Nagisetty, V., & Ganesh, V. (2021). Amnesiac Machine Learning. Proceedings of the Thirty-Fifth AAAI Conference on Artificial Intelligence, 35(13), 11516-11524. https://doi.org/10.1609/aaai.v35i13.17371
Izzo, Z., Smart, M. A., Chaudhuri, K., & Zou, J. (2021). Approximate Data Deletion from Machine Learning Models. In A. Banerjee & K. Fukumizu (Eds.). Proceedings of the 24th International Conference on Artificial Intelligence and Statistics (AISTATS) 2021 (Vol. 130, pp. 2008-2016). PMLR. https://proceedings.mlr.press/v130/izzo21a/izzo21a.pdf
Juliussen, B. A., Rui, J. P., & Johansen, D. (2023). Algorithms that Forget: Machine Unlearning and the Right to Erasure. Computer Law & Security Review, 51, 105885. https://doi.org/10.1016/j.clsr.2023.105885
Le-Khac, U. N., & Truong, V. N. X. (2025). A Survey on Large Language Models Unlearning: Taxonomy, Evaluations, and Future Directions. Artificial Intelligence Review, 58, 399. https://doi.org/10.1007/s10462-025-11376-7
Li, N., Zhou, C., Gao, Y., Chen, H., Zhang, Z., & Kuang, B. (2025). Machine Unlearning: Taxonomy, Metrics, Applications, Challenges, and Prospects. IEEE Transactions on Neural Networks and Learning Systems, 36(8), 13709-13729. https://doi.org/10.1109/TNNLS.2025.3530988
Mo, Y. (2024). The Right to Erasure of Personal Information in Large Language Models: Challenges and Responses. Tsinghua China Law Review, 17(1), 27-53. https://www.tsinghuachinalawreview.law.tsinghua.edu.cn/issues/info/10514
Partohaghighi, M., Marcia, R., West, B. J., & Chen, Y. (2026). A Survey on Bias and Fairness in Machine Unlearning. Journal of Information and Intelligence, 4(3), 183-201. https://doi.org/10.1016/j.jiixd.2026.03.003
Popowicz-Pazdej, A. (2023). Why the Generative AI Models Do Not Like the Right to Be Forgotten: A Study of Proportionality of Identified Limitations. Przegląd Prawniczy Uniwersytetu im. Adama Mickiewicza, 15, 217-239. https://doi.org/10.14746/ppuam.2023.15.10
Raposo, V. L. (2026). The AI Gospel According to the EDPB: An Overview of Opinion 28/2024 on Data Protection Aspects in AI models. Computer Law & Security Review, 61, 106300. https://doi.org/10.1016/j.clsr.2026.106300
Sanz-Salguero, F. J. (2025). Tutela de la información personal: desafíos para la protección de los datos biométricos en Chile. Ius et Praxis, 31(2), 3-23. https://doi.org/10.4067/S0718-00122025000200003
Tellez Dominguez, A. (2025). El derecho a la privacidad en México ante la inteligencia artificial y el Big Data: desafíos regulatorios. Universita Ciencia, 13(37), 99-118. https://doi.org/10.5281/zenodo.16740314
Tribunal de Justicia de la Unión Europea. Gran Sala. Google Spain SL y Google Inc. v. Agencia Española de Protección de Datos (AEPD) y Mario Costeja González (Asunto C-131/12, ECLI:EU:C:2014:317); 13 de mayo de 2014.
Tribunal de Justicia de la Unión Europea. Sala Tercera. TK v. Asociaţia de Proprietari bloc M5A-ScaraA (Asunto C-708/18, ECLI:EU:C:2019:1064); 11 de diciembre de 2019.
Tribunal de Justicia de la Unión Europea. Sala Novena. Koninklijke Nederlandse Lawn Tennisbond v. Autoriteit Persoonsgegevens (Asunto C-621/22, ECLI:EU:C:2024:858); 04 de octubre de 2024.
Unión Europea. (2012a). Carta de los Derechos Fundamentales de la Unión Europea (2012/C 326/02). Diario Oficial de la Unión Europea, C 326/391. https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=oj:JOC_2012_326_R_0391_01
Unión Europea. (2012b). Versión consolidada del Tratado de Funcionamiento de la Unión Europea. Diario Oficial de la Unión Europea, C 326/49. https://eur-lex.europa.eu/eli/treaty/tfeu_2012/oj/eng
Unión Europea. (2016). Reglamento (UE) 2016/679 del Parlamento Europeo y del Consejo, de 27 de abril de 2016, relativo a la protección de las personas físicas en lo que respecta al tratamiento de datos personales y a la libre circulación de estos datos y por el que se deroga la Directiva 95/46/CE (Reglamento General de Protección de Datos). Diario Oficial de la Unión Europea, L 119. https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX%3A02016R0679-20160504
Unión Europea. (2024). Reglamento (UE) 2024/1689 del Parlamento Europeo y del Consejo, de 13 de junio de 2024, por el que se establecen normas armonizadas en materia de inteligencia artificial y por el que se modifican los Reglamentos (CE) n. o 300/2008, (UE) n. o 167/2013, (UE) n. o 168/2013, (UE) 2018/858, (UE) 2018/1139 y (UE) 2019/2144 y las Directivas 2014/90/UE, (UE) 2016/797 y (UE) 2020/1828 (Reglamento de Inteligencia Artificial). Diario Oficial de la Unión Europea. https://eur-lex.europa.eu/eli/reg/2024/1689/oj/eng
Viollier Bonvin, P. A. (2025). La compatibilidad del web scraping con los principios de la protección de datos personales. Ius et Scientia, 11(2), 74-103. https://doi.org/10.12795/IETSCIENTIA.2025.i02.04
Wang, W., Zhang, C., Tian, Z., & Yu, S. (2026). SMS: Self-Supervised Model Seeding for Verification of Machine Unlearning. IEEE Transactions on Dependable and Secure Computing, 23(1), 1219-1231. https://doi.org/10.1109/TDSC.2025.3615615
Warthon, M. (2024). Restricting Access to AI Decision-Making in the Public Interest: The Justificatory Role of Proportionality and Its Balancing Factors. Internet Policy Review, 13(3), 1-32. https://doi.org/10.14763/2024.3.1801
Zhang, D., Finckenberg-Broman, P., Hoang, T., Pan, S., Xing, Z., Staples, M., & Xu, X. (2025). Right to Be Forgotten in the Era of Large Language Models: Implications, Challenges, and Solutions. AI and Ethics, 5(1), 2445-2454. https://doi.org/10.1007/s43681-024-00573-9
