Q1. Can we use the right to be forgotten to remove an AI answer?
For Article 17 of the GDPR and the privacy-based removal instruments covered in this article, a legal person is not itself a subject of the right. Article 17 is not an instrument confined to search engines but a right to erasure against controllers generally; what it protects, however, is natural persons (the formal title of the regulation likewise refers to the protection of natural persons). What the Google Spain judgment (C-131/12) allowed was removal of a link from the list of results of a search on a name, and publication of the original page may lawfully remain. Natural persons such as directors are a separate matter: CNIL takes the position that an AI model containing extractable personal data cannot be regarded as anonymous, and that rights under the GDPR apply to the model as well.
Q2. Can correction not be sought for misconduct that is true?
Correction premised on the information being wrong cannot be established. Under Japan's Act on the Protection of Personal Information too, correction under Article 34 requires that the content not be true. That does not mean nothing can be done. Cessation of use under Article 35 of the same Act allows cessation of use, erasure, or cessation of provision to third parties to be sought — even where the data are accurate — where there has been use beyond the purpose, improper use or wrongful acquisition, where there is no longer a need to use the data, or where there is a risk of harm to the rights or legitimate interests of the individual. Article 17(1) of the GDPR likewise lists grounds that do not require inaccuracy, such as the purpose having been fulfilled, and objection.
Q3. If the requirements of Article 35 are met, is erasure guaranteed?
Not necessarily. Paragraphs 2, 4 and 6 of Article 35 each contain a proviso: where cessation of use or erasure would require a large expenditure or would otherwise be difficult to carry out, and alternative measures necessary to protect the rights and interests of the individual are taken, the obligation does not apply. Meeting the requirements and erasing the data themselves are therefore not the same thing. The same structure appears in CNIL's analysis, where alternative measures such as output filtering are contemplated when retraining the model lacks proportionality.
Q4. In what cases is erasure not granted under Article 17 of the GDPR?
Article 17(3) sets out five exceptions: exercise of the freedom of expression and information; compliance with a legal obligation or performance of a task in the public interest; reasons of public interest in the area of public health; archiving in the public interest, scientific or historical research, or statistical purposes (in accordance with Article 89(1), where erasure is likely to render impossible or seriously impair the achievement of those objectives); and the establishment, exercise or defence of legal claims. In a crisis management context, the ones most likely to arise are that news coverage may amount to an exercise of the freedom of expression and information, and that where a dispute is pending the defence of legal claims may come into play.
Q5. Has the Supreme Court of Japan ruled on AI answers?
Within the scope of this review, we could not confirm this. But the understanding that "Japan has only a removal doctrine for search results" is not accurate. On 24 June 2022 the Supreme Court allowed removal of Twitter posts themselves that stated the fact of an arrest (令和2年(受)第1442号; Minshū Vol. 76, No. 5, p. 1170). The subject was a true fact of arrest, but the court assessed that the degree to which it bore on the public interest had diminished, given that about eight years had passed since the arrest and the sentence had ceased to have effect, and that the source news article had already been removed. It is regarded as having set out a more lenient standard than the 2017 decision. Even so, no Supreme Court framework to refer to for generated answers can be found.
Q6. If the statement concerns a director as an individual, can we request removal from the model?
There is room for a request, but no guarantee that it will succeed. CNIL takes the position that a model containing extractable personal data cannot be regarded as anonymous and that rights under the GDPR apply to the model itself. At the same time, the rights to rectification and erasure are not absolute: proportionality is assessed by comparing the sensitivity of the data against the constraint on the controller's freedom to conduct a business — in particular the computing resources, environmental impact, human resources and cost required to retrain the model. In an example given by CNIL itself, where a public figure seeks erasure in respect of an LLM trained on public information, the request may in principle be refused because of the high cost of retraining. Where retraining lacks proportionality, however, alternative measures such as output filtering are required.
Q7. Can output filtering serve as a substitute for erasure?
CNIL recommends measures that filter the output of the system as an alternative where retraining is impossible or lacks proportionality. There is a condition, however: the controller must demonstrate that the measure is sufficiently effective and robust (that it cannot be circumvented). CNIL also recommends using general rules that prevent the generation of personal data at source rather than building a blacklist of those who have exercised their rights, because a blacklist approach alters the statistical distribution of outputs and may thereby create a risk of identifying the very people who objected. Within the scope of this review, we could not confirm any specific case accepted as meeting this condition.
Q8. Who should the claim be made against?
It is first necessary to identify where the statement is coming from. CNIL states that the model and the system should be distinguished. The system is the interface between the model and the user and may add information obtained from web search or a knowledge base (RAG) to the query or the output, so whether a given statement derives from the model's memorization or from another component of the system is hard to determine from the outside. If the provider has integrated the knowledge base into the system, the provider is the counterparty for the exercise of rights; if a third party has added it, that third party is. That rights may be recognized against the model itself is not the same as an established right to have a particular generated answer directly "removed."
Q9. Now that the EU AI Act exists, can we request removal of AI answers?
No. Article 50 of the EU AI Act has applied since 2 August 2026, but it is a transparency requirement. It requires that users be able to recognize that they are interacting with AI and that AI-generated content be identifiable; it is not an instrument granting legal persons a right to demand erasure of an unfavorable generated answer. For generative AI systems placed on the market before 2 August 2026, Article 111(4), added by Regulation (EU) 2026/1744, defers the deadline for compliance with the machine-readable marking obligation under Article 50(2) until 2 December 2026. The basis of the grace period is not Article 50(2) itself but this Article 111(4).
Q10. Do legal persons have no recourse at all?
For the removal instruments based on personal data protection and privacy covered in this article, a legal person is not a subject of the right. Other legal constructions may nonetheless arise, such as injury to reputation or credit, or Article 2(1)(xxi) of the Unfair Competition Prevention Act (communicating or disseminating false facts injuring the business reputation of another in a competitive relationship). Those, however, depend on individual requirements such as falsity, a competitive relationship and unlawfulness, and are not a general right to remove true unfavorable information about one's own company. For the detail of legal liability and how claims are constructed, see AI misinformation and legal liability.
Q11. What is different between removing search results and removing an AI answer?
In the removal of search results addressed by the Google Spain judgment and the 2017 Supreme Court decision, there was an identifiable unit — the URL — and removal was the operation of taking an item out of a list. An AI answer is generated prose that can differ each time, and the definition itself is required of what is removed and from where: trained knowledge, retrieved material, or the output stage. The method of confirming the effect differs too: for AI answers, change cannot be identified without repeated observation under identical conditions. That said, precedents such as the 2022 Supreme Court judgment ordering removal of a post itself show that existing doctrine has not dealt exclusively with removal in a clearly defined unit of operation.
Q12. As legal counsel, where should we start?
Separate four things. First, whether the statement is about the legal person or an individual. Second, whether the statement is true, wrong, or mixed. Third, whether the statement originates in the model or in a component on the system side. Fourth, whether the available basis is correction, or cessation of use and erasure. The parts that are wrong can be separated out and handled within the misinformation framework (AI misinformation countermeasures). Without that separation, and with the aim set at "remove all of it," no claim can be designed.
Q13. What should we do about the parts where the instruments cannot be relied on?
Rather than waiting for it to disappear, observe. On which engine, in response to which question, how it is described, what is cited, and how that changes over time. Records are also needed where a claim under a legal instrument is being considered: CNIL recommends, for generative AI, a procedure of checking memorization by querying with prompts, and states that the individual exercising rights may also be asked to supply prompts. For the concrete design of observation, see How long does information stay in AI answers? Where the records contain statements about an individual, the records themselves can constitute the handling of personal information, so set the access rights, the retention period and the deletion policy first.