Department Use Cases

Does the Right to Be Forgotten Reach AI Answers — The Scope of Each Instrument, and the Divide Between Legal and Natural Persons

2026-08-11Reading time 28min

By Vaipm (which measures AI-space perception through a total of 25 stateless queries across multiple AI engines)

Key point

Can a statement that is true but unfavorable be removed from AI answers? This article separates Article 17 of the GDPR, the Google Spain judgment, the Supreme Court decision of 31 January 2017, CNIL's analysis, Articles 34 and 35 of the Act on the Protection of Personal Information, and Article 50 of the EU AI Act by scope and by the subject of the right. It shows from primary sources that legal persons have no general right, and that rights can reach natural persons but face a wall of feasibility.

Executive summary

A statement unfavorable to your company appears in an AI answer. And it is true. When there are no grounds to demand correction, can the law be relied on?

The conclusion of this article divides according to the subject of the right.

A company as a legal person has no general right. What the right to erasure under Article 17 of the EU GDPR protects is natural persons, and the formal title of the regulation is likewise a regulation on the protection of natural persons. Japan's removal doctrine also includes, alongside the 2017 Supreme Court decision dealing with search results, a 2022 judgment allowing removal of a post itself — but both are decisions about the privacy of natural persons. Within the scope of this review, we could not confirm a general right for a legal person to have true but unfavorable information about itself removed from AI answers.

Rights can reach natural persons such as directors. CNIL, the French data protection authority, takes the position that an AI model containing extractable personal data cannot be regarded as anonymous, and that in that case rights under the GDPR apply to the model itself. The rights are not absolute, however, and a request may be refused in light of the feasibility and cost of retraining the model. But refusal is not the end of the matter. Where retraining lacks proportionality, CNIL asks that alternative measures such as output filtering be considered. The same structure appears in the proviso to Article 35 of Japan's Act on the Protection of Personal Information (APPI), which addresses cases where the measure is difficult.

There is one more important distinction. "Correction premised on the information being untrue" and "erasure or cessation of use on other grounds" are separate instruments in both the EU and Japan. Japan's APPI places the former in Article 34 and the latter in Article 35. That information is true does not foreclose every request.

The practical conclusion comes down to one line. Design for the possibility of a claim by the company and the possibility of a claim by an individual separately, from the outset.

What this article covers

  • That what is called the "right to be forgotten" is in fact several instruments of differing character
  • When erasure is granted under Article 17 of the EU GDPR, and when it is not (the five exceptions in paragraph 3)
  • That Japan's removal doctrine is not confined to search results (Supreme Court judgment of 24 June 2022)
  • The difference between "correction, addition or deletion" (Article 34) and "cessation of use or erasure" (Article 35) under the APPI, and the proviso on alternative measures
  • What the EDPB and CNIL each set out on exercising rights against the AI model itself
  • Alternative measures where retraining is difficult, and the need to distinguish the model from the system
  • That Article 50 of the EU AI Act is a transparency requirement and not a right to demand erasure

Who this is for

Legal practitioners, and the public relations and crisis management practitioners who work with them. It assumes readers who want to establish which instruments are available and which are not when an unfavorable statement about their company or its directors appears in an AI answer.

How this article relates to two neighboring articles

The difference from AI misinformation and legal liability. That article deals with who can be held responsible, and how, for information that is wrong. This article deals with whether information that is true can be removed through legal instruments. Whether the information is wrong changes fundamentally which instruments are available. Beginning an examination with these two confused leads to time spent on claims that cannot be established.

The relationship with the companion article How long does information stay in AI answers? Why information remains in AI answers at all, and for how long, is handled there: that citation sources keep turning over week by week, that no correction process for legal persons can be confirmed, and that no public research measuring the persistence period can be confirmed. This article carries those premises forward and deals solely with whether the legal instruments reach. The structures behind persistence are not re-explained here.

§0 The scope of this article

The question this article answers is the following.

For a statement in an AI answer that is true but unfavorable, can existing legal instruments order removal?

The instruments covered are Article 17 of the EU GDPR, the Google Spain judgment (C-131/12), the decision of the Supreme Court of Japan of 31 January 2017, the analyses by CNIL and in EDPB Opinion 28/2024, Article 50 of the EU AI Act, and Japan's Act on the Protection of Personal Information.

We state first what is not covered.

This article assumes readers in the Japanese-speaking world, and it covers EU law because many AI providers fall within EU regulation, and their operational practice consequently extends to users in Japan as well.

§1 The "right to be forgotten" is not a single instrument

Much of the confusion in this debate arises from calling instruments of differing character by the same name. We separate them first.

Instrument as commonly namedActual scopeSubject of the right
Article 17 of the EU GDPRPersonal data held by a controller generally (not confined to search)Natural persons
Google Spain judgmentLinks in the list of results of a search on a nameNatural persons
Supreme Court decision of 31 January 2017Provision of URLs and related information as part of search resultsIndividuals (privacy)

The Google Spain judgment and the 2017 decision of the Supreme Court of Japan deal with removal of links and of URLs and related information from search results. Article 17 of the GDPR, by contrast, is not confined to search: it grants a right to erasure in certain cases in respect of the processing of the personal data of natural persons generally.

Treating "the right to be forgotten" as though it were an instrument about search results is a mistake. This distinction matters when considering the relationship with AI answers. An instrument whose scope is search results does not reach a generated answer text as such. An instrument whose scope is the data held by a controller generally may have a route by which it does.

§2 Article 17 of the EU GDPR — what is granted and what is not

2-1. The structure of the provision

Article 17 of the EU General Data Protection Regulation (Regulation (EU) 2016/679) sets out the "right to erasure (right to be forgotten)". The provision states that the data subject has the right to obtain from the controller the erasure of personal data concerning them.

Article 17 is not an instrument confined to search engines. It is a right against controllers handling personal data generally, and search results are only part of what it applies to.

2-2. When erasure is granted (paragraph 1)

Paragraph 1 lists the grounds on which erasure may be sought. The following focuses on those most likely to arise in practice.

GroundContent
Purpose fulfilledWhere the personal data are no longer necessary in relation to the purposes for which they were collected or processed
Withdrawal of consentWhere processing was based on consent, that consent is withdrawn, and there is no other legal ground
ObjectionWhere the data subject objects to the processing and there are no overriding legitimate grounds on the controller's side. This includes objection to processing for direct marketing purposes
Unlawful processingWhere the personal data have been unlawfully processed
Legal obligationWhere erasure is required by a law to which the controller is subject
Information society services to childrenWhere the personal data were collected in relation to the offer of information society services to a child

What is notable is that none of these grounds requires the data to be incorrect. Even where the information is accurate, erasure may arise on grounds such as the purpose having been fulfilled, or objection.

2-3. The notification measure where the data have been made public (paragraph 2)

Paragraph 2 addresses the case where the controller has made the personal data public. A controller under an obligation to erase pursuant to paragraph 1 must, by reasonable steps taking account of available technology and the cost of implementation (including technical measures), inform other controllers processing the data that the data subject has requested the erasure of links to, or copies or replications of, those data.

In relation to AI answers, what this provision indicates is that the instrument contemplates propagation to downstream recipients. This too, however, is an instrument concerning the personal data of natural persons, not one whose scope is the reputational information of legal persons generally. And the content of the obligation is to inform; it is not a mechanism compelling other controllers to erase.

2-4. When erasure is not granted (paragraph 3)

Article 17 is not an unconditional right. Paragraph 3 provides that paragraphs 1 and 2 do not apply to the extent that processing is necessary for one of the following.

ExceptionContent
(a) Freedom of expression and informationWhere necessary for exercising the right of freedom of expression and information
(b) Legal obligation and public interest tasksWhere necessary for compliance with an obligation under Union or Member State law to which the controller is subject, for the performance of a task carried out in the public interest, or in the exercise of official authority vested in the controller
(c) Public healthWhere necessary for reasons of public interest in the area of public health in accordance with Article 9(2)(h) and (i) and Article 9(3)
(d) Archiving, research and statisticsWhere necessary for archiving purposes in the public interest, scientific or historical research purposes, or statistical purposes in accordance with Article 89(1), in so far as the right under paragraph 1 is likely to render impossible or seriously impair the achievement of those objectives
(e) Legal claimsWhere necessary for the establishment, exercise or defence of legal claims

The exceptions most likely to arise in a crisis management context are (a), freedom of expression and information, and (e), legal claims. Coverage of corporate misconduct may amount to an exercise of the freedom of expression and information, and where a dispute is pending or foreseeable, the defence of legal claims comes into play. A request to remove a true account of misconduct will tend to run into these two walls.

2-5. And legal persons are not subjects of the right

The subject of the right is limited. The formal title of the regulation refers to the protection of natural persons, and what Article 17 protects is the data subject, a natural person, and their personal data. There is no configuration in which a company as a legal person seeks, under Article 17, the erasure of unfavorable statements about itself.

This is not a technical constraint of the drafting; it follows from the purpose of the regulation itself. The GDPR is a law protecting the rights and interests of individuals, not a law protecting the reputation of companies.

§3 The Google Spain judgment — the scope is links in the list of search results

What brought the right to be forgotten to wide attention was the judgment of the Court of Justice of the European Union (Grand Chamber) of 13 May 2014 in the Google Spain case (C-131/12). It concerned an individual resident in Spain: a notice of a real-estate auction connected with the recovery of social security debts had been published in the online edition of a newspaper and continued to appear in the results of a search on his name. The Court held that the operator of a search engine bears responsibility for the processing of personal data appearing on third-party web pages, and that under certain conditions removal of the link from the list of search results may be sought.

The scope matters. What is removed is a link in the list displayed as the result of a search based on that individual's name, and publication on the original web page may lawfully remain (in this case too, the Spanish data protection authority did not uphold the claim against the newspaper). This judgment does not erase the information itself; it cuts off arrival by a particular search route.

It should be noted that this judgment was delivered under Directive 95/46/EC (the Data Protection Directive), and is not a judgment applying Article 17 of the current GDPR. The GDPR became applicable in May 2018. Care is needed when mapping the reach of the judgment directly onto the interpretation of the current law.

What to take from this judgment in relation to AI answers is the unit of operation it presupposed. In search results, the operation of "removing an item from a list of links" is well defined. Whether the same operation is well defined for generated prose has to be examined separately.

§4 Japan's framework — search results, and posts themselves

In Japan, the Third Petty Bench of the Supreme Court issued a decision on 31 January 2017 (平成28年(許)第45号; Minshū Vol. 71, No. 1, p. 63).

The decision held that the provision of search results by a search business has an aspect of an act of expression by the search business itself, and set out a framework under which removal from search results may be sought where it is clear that the legal interest in not having the fact made public prevails, weighing factors such as the nature and content of the fact, the scope of dissemination and the extent of harm, the social standing of the parties, the purpose and significance of the article, and the social circumstances at the time of publication and their subsequent change.

The case concerned the fact of an arrest on suspicion of a crime, and removal was not granted. This was because the fact was still assessed as a matter of public interest, and because the search terms were a combination of a prefecture of residence and a name, so the scope of dissemination was judged to be limited to a certain degree. Here too, the scope is the act of providing URLs and related information as part of search results.

4-1. Japan's removal doctrine is not confined to search results

Reading this decision as "the general standard for removal on the internet" is a mistake.

On 24 June 2022 the Second Petty Bench of the Supreme Court, weighing the legal interest in not having facts belonging to privacy made public against the reasons for continuing to make the posts available for public viewing, allowed removal of the Twitter posts themselves, which had stated the fact of an arrest (令和2年(受)第1442号, "Post Deletion Claim Case"; Minshū Vol. 76, No. 5, p. 1170).

The arrest in question was true information. The fact of an arrest for trespass into a structure in 2012 and a fine had been reported, and tweets reproducing that reporting were at issue. The Supreme Court assessed that the degree to which the fact bore on the public interest had diminished, given that about eight years had passed from the arrest to the close of oral argument in the court below and the sentence had ceased to have effect (Penal Code, Article 34-2(1), second sentence), and that the source news article had already been removed. It also observed that each tweet, written under a 140-character limit, was intended as a rapid report and could not readily be regarded as intended to remain available for viewing over a long period.

The court below (the Tokyo High Court) had applied the "clear" requirement from the 2017 decision to removal of posts as well and dismissed the claim; the Supreme Court set that aside. It is regarded as having set out a more lenient standard than the 2017 decision.

Existing doctrine therefore cannot all be characterized as an instrument for "removing a link from a list." There is precedent ordering removal of a post itself.

That said, this precedent too concerns the privacy of a natural person, and did not recognize a general right of removal for true unfavorable information about a legal person. The answer to this article's central question is not changed by this judgment.

4-2. Two points to hold on to

First, the "where it is clear" requirement of the 2017 decision is a high one. But as the 2022 judgment shows, that standard does not extend to removal on the internet generally. The framework differs according to the medium and the nature of the claim.

Second, within the scope of this review, we could not confirm a Supreme Court ruling setting out a framework for generated answers by AI providers. For search results there is the 2017 decision, and for posts the 2022 judgment. For generated answers, no precedent to refer to could be found.

§5 Japan's Act on the Protection of Personal Information — "correction" and "cessation of use" are separate instruments

This is the point most often misunderstood in practice. The understanding that "nothing can be claimed because it is true" is not accurate.

Japan's Act on the Protection of Personal Information provides two different requests in respect of retained personal data (article numbers follow the guidelines of the Personal Information Protection Commission).

Correction, addition or deletionCessation of use or erasure
ProvisionArticle 34Article 35
RequirementsWhere the content is not trueUse beyond the purpose, improper use, wrongful acquisition and the like (paragraph 1 sets the requirements for the request) / provision to third parties without consent and the like (paragraph 3) / where there is no longer a need to use the data, where certain leakages have occurred, or where there is a risk of harm to the rights or legitimate interests of the individual (paragraph 5)
The business operator's duty to respondParagraph 2 corresponds to paragraph 1 / paragraph 4 to paragraph 3 / paragraph 6 to paragraph 5
Measures that may be soughtCorrection, addition or deletionCessation of use or erasure; cessation of provision to third parties
Where the information is trueNot establishedMay be established if the requirements are met

What this contrast shows is clear. Correction under Article 34 requires the content not to be true, so it cannot be used against a statement that is true. But cessation of use under Article 35 may be sought — even where the data are accurate — where the handling is unlawful, where there is no longer a need to use the data, or where there is a risk of harm to the rights or legitimate interests of the individual, in the form of cessation of use, erasure, or cessation of provision to third parties.

5-1. But "requirements met" does not equal "erasure in every case"

This is an extremely important point in practice.

Paragraphs 2, 4 and 6 of Article 35 each contain a proviso. In the wording of paragraph 2, where cessation of use or erasure of the retained personal data would require a large expenditure or would otherwise be difficult to carry out, and the operator takes alternative measures necessary to protect the rights and interests of the individual, the obligation does not apply.

Meeting the requirements of Article 35 is therefore not the same as the data themselves necessarily being erased. Where the measure is difficult, a response by alternative measures is contemplated by the instrument itself.

This structure corresponds precisely to CNIL's analysis, examined in §6. CNIL likewise asks that alternative measures such as output filtering be considered where retraining the model would be an excessive burden. Neither "do nothing if erasure is impossible" nor "always erase," but protect the rights and interests of the individual through alternative measures proportionate to feasibility — this approach is common to the instruments in both Japan and Europe.

5-2. Here too the subject is the individual, a natural person

Here too the subject of the right is the individual concerned, a natural person. Retained personal data are information by which a specific individual can be identified, and there is no configuration in which a legal person itself makes these requests in respect of "statements about the company." Where the statement concerns a director as an individual, it may arise as a request by that person.

5-3. A note on the 2026 amendment

The amended Act on the Protection of Personal Information (令和8年法律第56号) was promulgated on 17 July 2026, but its principal parts are not yet in force as at the date of this review (they come into force on a date to be set by cabinet order within a period not exceeding two years from the date of promulgation; certain provisions, such as the reorganization of penalties, come into force on 17 January 2027). This section is based on the law in force as at 11 August 2026.

The GDPR has the same structure. Article 16 provides the right to rectification (rectification of inaccurate personal data) and Article 17 the right to erasure. Placing "correction of error" and "erasure on other grounds" in separate provisions is a design common to the EU and Japan.

§6 Exercising rights against the AI model itself — the analyses of CNIL and the EDPB

The understanding that "the GDPR is about search results and has nothing to do with AI models" is likewise not accurate.

Two documents need to be read in their separate roles. What EDPB Opinion 28/2024 sets out is a framework for judging whether an AI model can be said to be anonymous. What CNIL's recommendations (published on 5 January 2026) set out is the practical analysis of how a data subject actually exercises rights against a model found to be non-anonymous, and against training datasets, and how the controller responds.

CNIL states that data subjects must be able to exercise their rights in respect of both the training dataset and the AI model itself (except where the model is regarded as anonymous; that assessment of anonymity relies on EDPB Opinion 28/2024).

On anonymity, CNIL states the following. Where the model itself contains extractable personal data, the model cannot be regarded as anonymous. This applies generally to large language models trained on public information that can provide information about natural persons, particularly public figures. In that case, individual rights under the GDPR apply to the model.

The exercise of those rights is not absolute, however. For the rights to rectification, erasure and objection, CNIL states that proportionality is assessed by comparing the sensitivity of the data (the risk that regurgitation or disclosure poses to the individual) against the constraint on the controller's freedom to conduct a business — in particular feasibility from the standpoint of the computing resources, environmental impact, human resources and cost required to retrain the model. In an example given by CNIL itself, where a public figure seeks erasure in respect of a large language model trained on public information, the request may in principle be refused because the cost of retraining is extremely high. By contrast, in a case where information about a person's own insurance payouts is output by a model used by an insurance company, the controller must in principle offer a solution that answers the erasure request.

6-1. It does not end at "may be refused" — alternative measures

This is not where the analysis stops. CNIL asks that alternative measures be implemented even where retraining is impossible or lacks proportionality.

Specifically, it recommends answering the exercise of the rights to rectification, objection and erasure by measures that filter the output of the system. There is a condition, however: the controller must demonstrate that the measure is sufficiently effective and robust (that it cannot be circumvented). CNIL also recommends using general rules that prevent the generation of personal data at source (detection through named-entity recognition and the like, together with pseudonymisation) rather than building a "blacklist" of those who have exercised their rights. A blacklist approach alters the statistical distribution of outputs and may thereby create a risk of identifying the very people who objected.

The structure corresponds to the alternative measures under Article 35 of the APPI examined in §5-1. Not "do nothing if erasure is impossible," but protect the right through alternative measures proportionate to feasibility. The instruments in both Japan and Europe adopt the same posture.

6-2. The model and the system have to be distinguished

CNIL sets out one further distinction that is of great practical importance.

The model and the system are different things. The system is the interface between the model and the user, and it may add information obtained from web search or a knowledge base (RAG) to the query or the output. Whether a given statement derives from personal data memorized in the model or from another component of the system is therefore hard to determine from the outside. CNIL states that this distinction is essential for identifying the correct controller. If the provider has integrated the knowledge base into the system, the provider is the counterparty for the exercise of rights; if a third party has added it, that third party is.

The implication is significant. That rights may be recognized against the model itself is not the same as an established right to have a particular generated answer directly "removed." Before assembling a claim, it is necessary to identify which processing entity and which component is giving rise to the personal data in question.

CNIL also recommends that, for generative AI, developers establish an internal procedure for querying the model with a carefully chosen list of prompts to check whether it has memorized personal data about the individual concerned. The individual seeking to exercise rights may also be asked to supply prompts thought to demonstrate memorization. In other words, observation and recording are presupposed even for a claim under a legal instrument.

6-3. Separate legal persons from natural persons

A legal person cannot itself seek erasure of unfavorable information about it under Article 17. Information about natural persons such as directors, on the other hand, may raise rights under the GDPR, including against AI models (though a request may be refused because of the difficulty of implementation).

In crisis management practice, do not confuse the two. The range within which the company can act and the range within which an individual can act are different.

And "the right reaches" is different from "the claim succeeds." The factors CNIL lists — sensitivity, the constraint on the freedom to conduct a business, and the feasibility and cost of retraining — are all variables the claimant does not control. That a route exists under an instrument does not guarantee a result. CNIL notes that as re-identification and unlearning techniques advance, requests that may be refused today may have to be processed tomorrow, and asks controllers to follow developments.

§7 Article 50 of the EU AI Act — a transparency requirement, not a right to demand erasure

As a new form of regulation concerning AI, Article 50 of the EU AI Act has applied since 2 August 2026.

The basis of the grace period needs to be stated precisely. Article 111(4), added to the AI Act by Regulation (EU) 2026/1744 (the Digital Omnibus on AI; published in the Official Journal on 24 July 2026, in force from 27 July), defers until 2 December 2026 the deadline for compliance with the machine-readable marking obligation under Article 50(2) for generative AI systems placed on the market before 2 August 2026 — those generating synthetic audio, images, video or text, including general-purpose AI systems. Systems placed on the market on or after that date have no grace period, and no transitional measures are provided for the other obligations under Article 50.

The basis of the grace period is not Article 50(2) itself but the newly added Article 111(4). It is also stated that content generated before 2 August 2026 does not need to be marked retroactively; this is an explanation given in European Commission guidance.

This is, however, a requirement about disclosure and labelling. It requires that users be able to recognize that they are interacting with AI and that AI-generated content be identifiable; it is not an instrument granting legal persons a right to demand erasure of an unfavorable generated answer.

The understanding that "removal became possible once the AI Act arrived" is a mistake. An increase in transparency obligations and the creation of a right to demand removal are different things. The AI Act is a law for making it apparent that something was generated by AI, not a law that lets you say "take this down."

§8 Setting the instruments side by side

The following brings the foregoing together.

InstrumentScopeSubject of the rightEffect
Article 17 of the GDPRPersonal data held by a controller (not confined to search)Natural personsErasure (with the five exceptions in paragraph 3)
EDPB Opinion 28/2024Framework for judging whether an AI model can be said to be anonymousDetermines whether the rules apply
CNIL recommendations (5 January 2026)Practice of exercising rights against non-anonymous models and training datasetsNatural personsRectification and erasure (may be refused on feasibility grounds; in that case, alternative measures such as output filtering)
Google Spain judgmentLinks in the list of results of a search on a nameNatural personsRemoval of the link (the original page may remain)
Supreme Court decision of 31 January 2017Provision of URLs and related information as part of search resultsIndividuals (privacy)Removal (where prevalence is clear)
Supreme Court judgment of 24 June 2022The post (tweet) itselfIndividuals (privacy)Removal (on a balancing test; regarded as a more lenient standard than the 2017 decision)
APPI Article 34Retained personal data that are not trueThe individual concernedCorrection, addition or deletion
APPI Article 35Retained personal data (may be covered even where accurate)The individual concernedCessation of use or erasure; cessation of provision to third parties (alternative measures where difficult)
Article 50 of the EU AI ActDisclosure of interaction with an AI system and of AI-generated contentSecuring transparency (not a right to demand erasure)

The scope differs from instrument to instrument. Some address links in search results, some the post itself, some the data held by a controller generally, some may reach the AI model itself, and some address transparency alone.

And in the removal instruments based on personal data protection and privacy organized in this article, the subject of the right is a natural person.

Other legal constructions may arise for legal persons as well, such as injury to reputation or credit, or Article 2(1)(xxi) of the Unfair Competition Prevention Act (communicating or disseminating false facts injuring the business reputation of another in a competitive relationship). Those, however, depend on individual requirements such as falsity, a competitive relationship and unlawfulness, and are not a general right to remove true unfavorable information about one's own company. The detail of legal liability and how claims are constructed is not covered here (see AI misinformation and legal liability).

Within the scope of this review, we could not confirm a general right for a legal person to have true but unfavorable information about itself removed from AI answers.

8-1. What is different between removing search results and removing an AI answer

In the removal of search results addressed by the Google Spain judgment and the 2017 Supreme Court decision, the unit of operation — "removing a link from a list" — was clear. For AI answers, the unit itself has to be examined.

Removal of search resultsAI answers
Unit of the objectA URL (identifiable)Generated prose (which can differ each time)
Meaning of removalTaking an item out of a listRequires a definition of what is removed, and from where
Where it is removed fromThe search indexTrained knowledge, retrieved material, or the output stage
Confirming the effectCheck whether the URL stops appearingCannot be known without repeated observation under identical conditions
Accumulated legal practiceCase law and supervisory practice existWithin the scope of this review, we could not confirm this

That said, as the 2022 Supreme Court judgment ordering removal of a post itself shows, existing doctrine has not dealt exclusively with removal in a clearly defined unit of operation. The problem is not the absence of a unit of operation as such, but that no framework to refer to for generated answers can yet be found. CNIL's analysis indicates a route through the exercise of rights against the model itself, while showing at the same time that there is a wall of feasibility.

§9 What could not be confirmed in this review

Within the scope of this review, we could not confirm any of the following.

ItemStatus
A general right for a legal person to have true but unfavorable information about itself removed from AI answersCould not confirm
A ruling of the Supreme Court of Japan setting out a framework for the removal of generated answers by AI providersCould not confirm (for search results there is the 2017 decision, and for posts the 2022 judgment)
A published case in which an erasure request against an AI model under Article 17 of the GDPR was upheldCould not confirm
A standard or case in which alternative measures such as output filtering were accepted as "sufficiently effective and robust"Could not confirm (CNIL sets this out as a condition, but no yardstick for the assessment is given)
A provider process by which a legal person can file for correction of statements about itself with a guaranteed processing deadline and outcomeCould not confirm (see correction and removal of AI misinformation)
Confirmation that other EU supervisory authorities reach the same conclusion as CNIL's analysisCould not confirm
A published case in which a request for cessation of use against an AI model was granted under Japan's Act on the Protection of Personal InformationCould not confirm

"There is no instrument" and "the instruments cannot be used" are different things. What the table above shows is a state in which an established route is not yet visible. In an individual case another construction may hold, and that assessment belongs to legal practitioners. This article organizes the scope and the subject of each instrument; it is not legal advice.

§10 So what should legal and PR do

If the instruments do not reach, what is to be done? The following sets out what can be said within the scope of this article.

10-1. Separate the legal person from the individual, from the outset

When an incident occurs, separate the following at the entrance to the examination.

SeparationWhat to determine
Who the statement is aboutThe legal person, or a specific individual (a director or employee)
Accuracy of the statementTrue, wrong, or mixed
Available basisFor an individual: correction if wrong; and whether there is room for cessation of use or erasure even where accurate
Origin of the statementPersonal data memorized in the model, or a component on the system side such as search or a knowledge base (RAG) (§6-2)
FeasibilityAssuming the claim succeeds, what the provider can actually do: retraining, or alternative measures

If they are left mixed together and the aim becomes "remove all of it," no claim can be designed.

10-2. Separate out the parts that are wrong

Fact and error are often mixed. The fact of a sanction is correct, but its content, timing or scope is described incorrectly. The incorrect portion can be handled within the misinformation framework (AI misinformation countermeasures, correction and removal of AI misinformation, AI misinformation and legal liability). Check first whether there is an error that can be separated out.

10-3. Where the instruments cannot be relied on, move to observation

The range the instruments do not reach is not a range in which to wait for something to disappear; it is a range to keep watching. On which engine, in response to which question, how it is described, and what is cited. And how that changes over time. This design is handled by How long does information stay in AI answers?

Vaipm measures AI-space perception through a total of 25 stateless queries across multiple AI engines. This is not an optimum derived from research; it is Vaipm's operational design. The point of fixing the number and the conditions lies less in the values themselves than in maintaining a state in which comparison with the previous observation is possible. Vaipm calls the approach of treating AI-space perception as an object of continuous management AI Perception Management (AIPM) (What is AIPM).

10-4. Records where a claim is being considered

If a claim under a legal instrument is being considered, records showing that the statement was actually produced are required: the engine and feature name, the model version, the date and time of execution, the language, the region setting, the login state, the full text of the prompt, and the full text of the answer. A summary alone makes it hard to verify the content and context of the output afterwards, so where a claim is in view, retain the original text as well.

This requirement is consistent with CNIL's analysis. As seen in §6-2, CNIL recommends, for generative AI, a procedure of querying with prompts to check whether data have been memorized, and states that the individual exercising rights may also be asked to supply prompts. Without a record of which prompt produced what, it is hard even to reach the entrance to a claim.

Where those records contain statements about an individual, however, the records themselves can constitute the handling of personal information. Set the access rights, the retention period and the deletion policy before starting to record.

10-5. The limits of this article, and consulting a specialist

This article organizes the scope and the subject of each instrument; it is not legal advice. Whether the requirements of Article 17 of the GDPR are met, whether Article 35 of the APPI applies, and whether rights can be exercised against an AI model all require a case-by-case assessment. Where a claim is actually being considered, consult a lawyer or other specialist.

Frequently asked questions

Q1. Can we use the right to be forgotten to remove an AI answer?

For Article 17 of the GDPR and the privacy-based removal instruments covered in this article, a legal person is not itself a subject of the right. Article 17 is not an instrument confined to search engines but a right to erasure against controllers generally; what it protects, however, is natural persons (the formal title of the regulation likewise refers to the protection of natural persons). What the Google Spain judgment (C-131/12) allowed was removal of a link from the list of results of a search on a name, and publication of the original page may lawfully remain. Natural persons such as directors are a separate matter: CNIL takes the position that an AI model containing extractable personal data cannot be regarded as anonymous, and that rights under the GDPR apply to the model as well.

Q2. Can correction not be sought for misconduct that is true?

Correction premised on the information being wrong cannot be established. Under Japan's Act on the Protection of Personal Information too, correction under Article 34 requires that the content not be true. That does not mean nothing can be done. Cessation of use under Article 35 of the same Act allows cessation of use, erasure, or cessation of provision to third parties to be sought — even where the data are accurate — where there has been use beyond the purpose, improper use or wrongful acquisition, where there is no longer a need to use the data, or where there is a risk of harm to the rights or legitimate interests of the individual. Article 17(1) of the GDPR likewise lists grounds that do not require inaccuracy, such as the purpose having been fulfilled, and objection.

Q3. If the requirements of Article 35 are met, is erasure guaranteed?

Not necessarily. Paragraphs 2, 4 and 6 of Article 35 each contain a proviso: where cessation of use or erasure would require a large expenditure or would otherwise be difficult to carry out, and alternative measures necessary to protect the rights and interests of the individual are taken, the obligation does not apply. Meeting the requirements and erasing the data themselves are therefore not the same thing. The same structure appears in CNIL's analysis, where alternative measures such as output filtering are contemplated when retraining the model lacks proportionality.

Q4. In what cases is erasure not granted under Article 17 of the GDPR?

Article 17(3) sets out five exceptions: exercise of the freedom of expression and information; compliance with a legal obligation or performance of a task in the public interest; reasons of public interest in the area of public health; archiving in the public interest, scientific or historical research, or statistical purposes (in accordance with Article 89(1), where erasure is likely to render impossible or seriously impair the achievement of those objectives); and the establishment, exercise or defence of legal claims. In a crisis management context, the ones most likely to arise are that news coverage may amount to an exercise of the freedom of expression and information, and that where a dispute is pending the defence of legal claims may come into play.

Q5. Has the Supreme Court of Japan ruled on AI answers?

Within the scope of this review, we could not confirm this. But the understanding that "Japan has only a removal doctrine for search results" is not accurate. On 24 June 2022 the Supreme Court allowed removal of Twitter posts themselves that stated the fact of an arrest (令和2年(受)第1442号; Minshū Vol. 76, No. 5, p. 1170). The subject was a true fact of arrest, but the court assessed that the degree to which it bore on the public interest had diminished, given that about eight years had passed since the arrest and the sentence had ceased to have effect, and that the source news article had already been removed. It is regarded as having set out a more lenient standard than the 2017 decision. Even so, no Supreme Court framework to refer to for generated answers can be found.

Q6. If the statement concerns a director as an individual, can we request removal from the model?

There is room for a request, but no guarantee that it will succeed. CNIL takes the position that a model containing extractable personal data cannot be regarded as anonymous and that rights under the GDPR apply to the model itself. At the same time, the rights to rectification and erasure are not absolute: proportionality is assessed by comparing the sensitivity of the data against the constraint on the controller's freedom to conduct a business — in particular the computing resources, environmental impact, human resources and cost required to retrain the model. In an example given by CNIL itself, where a public figure seeks erasure in respect of an LLM trained on public information, the request may in principle be refused because of the high cost of retraining. Where retraining lacks proportionality, however, alternative measures such as output filtering are required.

Q7. Can output filtering serve as a substitute for erasure?

CNIL recommends measures that filter the output of the system as an alternative where retraining is impossible or lacks proportionality. There is a condition, however: the controller must demonstrate that the measure is sufficiently effective and robust (that it cannot be circumvented). CNIL also recommends using general rules that prevent the generation of personal data at source rather than building a blacklist of those who have exercised their rights, because a blacklist approach alters the statistical distribution of outputs and may thereby create a risk of identifying the very people who objected. Within the scope of this review, we could not confirm any specific case accepted as meeting this condition.

Q8. Who should the claim be made against?

It is first necessary to identify where the statement is coming from. CNIL states that the model and the system should be distinguished. The system is the interface between the model and the user and may add information obtained from web search or a knowledge base (RAG) to the query or the output, so whether a given statement derives from the model's memorization or from another component of the system is hard to determine from the outside. If the provider has integrated the knowledge base into the system, the provider is the counterparty for the exercise of rights; if a third party has added it, that third party is. That rights may be recognized against the model itself is not the same as an established right to have a particular generated answer directly "removed."

Q9. Now that the EU AI Act exists, can we request removal of AI answers?

No. Article 50 of the EU AI Act has applied since 2 August 2026, but it is a transparency requirement. It requires that users be able to recognize that they are interacting with AI and that AI-generated content be identifiable; it is not an instrument granting legal persons a right to demand erasure of an unfavorable generated answer. For generative AI systems placed on the market before 2 August 2026, Article 111(4), added by Regulation (EU) 2026/1744, defers the deadline for compliance with the machine-readable marking obligation under Article 50(2) until 2 December 2026. The basis of the grace period is not Article 50(2) itself but this Article 111(4).

Q10. Do legal persons have no recourse at all?

For the removal instruments based on personal data protection and privacy covered in this article, a legal person is not a subject of the right. Other legal constructions may nonetheless arise, such as injury to reputation or credit, or Article 2(1)(xxi) of the Unfair Competition Prevention Act (communicating or disseminating false facts injuring the business reputation of another in a competitive relationship). Those, however, depend on individual requirements such as falsity, a competitive relationship and unlawfulness, and are not a general right to remove true unfavorable information about one's own company. For the detail of legal liability and how claims are constructed, see AI misinformation and legal liability.

Q11. What is different between removing search results and removing an AI answer?

In the removal of search results addressed by the Google Spain judgment and the 2017 Supreme Court decision, there was an identifiable unit — the URL — and removal was the operation of taking an item out of a list. An AI answer is generated prose that can differ each time, and the definition itself is required of what is removed and from where: trained knowledge, retrieved material, or the output stage. The method of confirming the effect differs too: for AI answers, change cannot be identified without repeated observation under identical conditions. That said, precedents such as the 2022 Supreme Court judgment ordering removal of a post itself show that existing doctrine has not dealt exclusively with removal in a clearly defined unit of operation.

Q12. As legal counsel, where should we start?

Separate four things. First, whether the statement is about the legal person or an individual. Second, whether the statement is true, wrong, or mixed. Third, whether the statement originates in the model or in a component on the system side. Fourth, whether the available basis is correction, or cessation of use and erasure. The parts that are wrong can be separated out and handled within the misinformation framework (AI misinformation countermeasures). Without that separation, and with the aim set at "remove all of it," no claim can be designed.

Q13. What should we do about the parts where the instruments cannot be relied on?

Rather than waiting for it to disappear, observe. On which engine, in response to which question, how it is described, what is cited, and how that changes over time. Records are also needed where a claim under a legal instrument is being considered: CNIL recommends, for generative AI, a procedure of checking memorization by querying with prompts, and states that the individual exercising rights may also be asked to supply prompts. For the concrete design of observation, see How long does information stay in AI answers? Where the records contain statements about an individual, the records themselves can constitute the handling of personal information, so set the access rights, the retention period and the deletion policy first.

Summary

  • The "right to be forgotten" is not a single instrument. Article 17 of the GDPR is a general right to erasure not confined to search, while the Google Spain judgment and the Supreme Court decision of 31 January 2017 address links and URLs and related information in search results
  • Article 17 has five exceptions in paragraph 3, of which freedom of expression and information and the defence of legal claims are most likely to arise in a crisis management context. Paragraph 2 also provides for measures informing other controllers where the data have been made public
  • Japan's removal doctrine is not confined to search results. The Supreme Court judgment of 24 June 2022 allowed removal of posts themselves stating a true fact of arrest. It is, however, a decision about the privacy of a natural person
  • Japan's Act on the Protection of Personal Information treats "correction, addition or deletion" (Article 34, requiring that the content not be true) and "cessation of use or erasure" (Article 35, which may cover accurate data) as separate instruments
  • Article 35 contains a proviso on alternative measures, so meeting the requirements is not the same as erasure of the data
  • EDPB Opinion 28/2024 sets out a framework for judging the anonymity of a model, and CNIL's recommendations organize the practice of exercising rights against non-anonymous models
  • The rights are not absolute and a request may be refused on the feasibility and cost of retraining, but in that case CNIL requires alternative measures such as output filtering
  • The model and the system must be distinguished, and identifying the origin of the statement is a prerequisite to a claim
  • Article 50 of the EU AI Act is a transparency requirement and does not grant a right to demand erasure (the basis of the grace period is Article 111(4), added by Regulation (EU) 2026/1744)
  • In the removal instruments based on personal data protection and privacy organized here, the subject of the right is a natural person, and within the scope of this review, we could not confirm a general right for a legal person to have true but unfavorable information about itself removed from AI answers
  • In practice, design for the possibility of a claim by the company and the possibility of a claim by an individual separately, from the outset

About this article

This article organizes the scope and the subject of each instrument and is not legal advice. If you are considering a claim in an individual case, please consult a lawyer or other specialist.

Sources

Primary sources (legislation, case law, supervisory authorities)

  1. Regulation (EU) 2016/679 (GDPR), Article 17, right to erasure (right to be forgotten). The grounds in paragraph 1, the notification measure on publication in paragraph 2, and the exceptions in paragraph 3(a)–(e)

https://eur-lex.europa.eu/eli/reg/2016/679/oj

  1. Court of Justice of the European Union (Grand Chamber), judgment of 13 May 2014, Case C-131/12 Google Spain SL, Google Inc. v AEPD, Mario Costeja González (ECLI:EU:C:2014:317). A judgment under Directive 95/46/EC

https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:62012CJ0131

  1. Third Petty Bench of the Supreme Court, decision of 31 January 2017 (平成28年(許)第45号; Minshū Vol. 71, No. 1, p. 63). The framework for provisional dispositions on removal of search results
  2. Second Petty Bench of the Supreme Court, judgment of 24 June 2022 (令和2年(受)第1442号, "Post Deletion Claim Case"; Minshū Vol. 76, No. 5, p. 1170). Removal of tweets stating the fact of an arrest was granted, taking into account the sentence having ceased to have effect under Penal Code Article 34-2(1), second sentence, the removal of the source news article, and the rapid-report purpose under a 140-character limit
  3. Personal Information Protection Commission, "Guidelines on the Act on the Protection of Personal Information (General Rules)", 3-8-4 correction, addition or deletion of retained personal data (Article 34), 3-8-5 cessation of use or erasure of retained personal data (Article 35)

https://www.ppc.go.jp/personalinfo/legal/guidelines_tsusoku/

  1. Personal Information Protection Commission, "Basics of the Act on the Protection of Personal Information" (Article 34 = correction, addition or deletion where the content is in error; Article 35 = cessation of use or erasure, and cessation of provision to third parties, on grounds such as use beyond the purpose, improper use or wrongful acquisition)

https://www.ppc.go.jp/files/pdf/kihon_202207.pdf

  1. Act on the Protection of Personal Information, proviso to Article 35(2) (where cessation of use or erasure would require a large expenditure or would otherwise be difficult to carry out, and alternative measures necessary to protect the rights and interests of the individual are taken, the obligation does not apply). Paragraphs 4 and 6 are to the same effect
  2. Personal Information Protection Commission, "On the 2026 amendment to the Act on the Protection of Personal Information". Promulgated on 17 July 2026 as 令和8年法律第56号. The principal parts come into force on a date to be set by cabinet order within a period not exceeding two years from promulgation (not yet in force as at the date of this review)

https://www.ppc.go.jp/personalinfo/legal/r8kaiseihogohou/

  1. CNIL, "Ensuring and facilitating the exercise of data subjects' rights", published 5 January 2026. Exercise of rights over training datasets and the AI model itself; a model containing extractable personal data is not anonymous; the factors in the proportionality assessment; alternative measures such as output filtering where retraining lacks proportionality; the distinction between model and system; and the prompt-based verification procedure for generative AI

https://www.cnil.fr/en/ensuring-and-facilitating-exercise-data-subjects-rights

  1. CNIL, "AI system development: the CNIL's recommendations to comply with the GDPR"

https://www.cnil.fr/en/ai-system-development-cnils-recommendations-to-comply-gdpr

  1. EDPB Opinion 28/2024 (data protection issues in the processing of personal data in AI models; the framework for judging whether a model can be said to be anonymous)

https://www.edpb.europa.eu/system/files/2024-12/edpb_opinion_202428_ai-models_en.pdf

  1. European Commission, "Transparency obligations under Article 50 of the AI Act" (Article 50 applies from 2 August 2026; content generated before 2 August 2026 does not need to be marked retroactively)

https://digital-strategy.ec.europa.eu/en/faqs/transparency-obligations-under-article-50-ai-act

  1. Regulation (EU) 2026/1744 (Digital Omnibus on AI). Published in the Official Journal on 24 July 2026, in force from 27 July. Adds Article 111(4) to the AI Act, deferring until 2 December 2026 the deadline under Article 50(2) for generative AI systems placed on the market before 2 August 2026
  2. Unfair Competition Prevention Act, Article 2(1)(xxi) (communicating or disseminating false facts injuring the business reputation of another in a competitive relationship)

Commentary and analyses by supervisory authorities

  1. The article numbers in the Personal Information Protection Commission's guidelines (General Rules) are stated to be based on the article numbering as at 14 June 2026
  2. Commentary on Article 17 by the Data Protection Commission of Ireland (DPC) (an organization of the exceptions in paragraph 3)

https://www.dataprotection.ie/en/individuals/know-your-rights/right-erasure-articles-17-19-gdpr

Notes

  1. This article organizes the scope and the subject of each instrument; it is not legal advice on any individual case. Application may lead to different conclusions depending on the circumstances.
  2. CNIL is the French data protection authority, and its analysis is one interpretation within the EU. Other supervisory authorities may not reach the same conclusions.
  3. The Google Spain judgment, the Supreme Court decision of 31 January 2017 and the Supreme Court judgment of 24 June 2022 are based on the texts of the judgment and decision and on published court materials.
  4. For the reporter of the 2022 Supreme Court judgment, this article adopts Minshū Vol. 76, No. 5, p. 1170. Materials published immediately after the judgment may cite the page in Saibansho Jihō.
  5. Primary sources on the time axis of how long information remains, which this article does not cover, are collected in the sources list of How long does information stay in AI answers?

Related articles

The Vaipm perspective

Vaipm measures AI-space perception through a total of 25 stateless queries across multiple AI engines. This is not an optimum derived from research; it is Vaipm's operational design. Vaipm calls the approach of treating AI-space perception as an object of continuous management AI Perception Management (AIPM). Where the legal instruments do not reach, the range that remains is not one in which to wait for something to disappear, but one to keep observing and recording.

Related articles