Skip to main content
sociable systems.
Episode 258 · 2026-09-15

Deletion Is Not Erasure

A deletion request meets training runs, embeddings, caches, downstream copies, and vendor logs. Legal erasure names a result that the technical stack may have no operation capable of producing.

Cover art for episode 258: Deletion Is Not Erasure
Remedy ArcRight to ErasureMachine Unlearning
Episode 258: Deletion Is Not Erasure

Stopped is not undone. Cleared is not erased. Deleted is a word we use for something that stays in place.

A delete button has a satisfying finality. The row disappears. The account closes. A confirmation arrives.

The rest of the stack is less theatrical.

Copies may remain in backups until their retention cycle ends. A vendor may hold another copy. Derived data may no longer resemble the record that produced it. A trained model contains parameters rather than a filing cabinet with one person’s contribution sitting in a labeled drawer.

Erasure therefore names a duty whose physical implementation changes at every layer.

What the request reaches

The right to erasure is qualified rather than absolute. The UK Information Commissioner’s guidance on the right to erasure sets out circumstances in which it applies and exemptions that may permit continued retention. Where a valid request applies, the organization must address live systems and backups, and for backups the guidance accepts measures short of immediate physical deletion, such as placing the data beyond use until the backups are overwritten. The organization must also tell the person which of those will happen.

That is already more complex than removing a visible profile. Add machine learning and the object of deletion becomes harder to name.

Training data may have been copied into training or evaluation corpora, or used to produce model weights, embeddings, and cached outputs. A supplier may have received data under a separate retention schedule. Removing the source record leaves a question at each downstream stage: what influence remains, and how would anyone prove its removal?

Forgetting as engineering

Machine unlearning exists because retraining every model from the beginning can be expensive. Some approaches seek the state that would have resulted if selected data had never been present. Others aim to remove its influence closely enough to satisfy a defined test.

The test matters. A model can stop exhibiting the targeted behavior while retaining internal representations from which later training revives the concept. In “An Illusion of Unlearning?”, Gao and colleagues examine internal representations rather than relying only on output behavior. Their 2026 paper finds that simple fine-tuning can reintroduce concepts that appeared to have been erased.

Concept unlearning and the removal of one person’s training record are related and different problems. The paper studies the first. What it exposes is the evidentiary problem the two share: changed output does not by itself prove that the targeted influence is gone.

The finding narrows what a successful deletion claim can mean. Silence at the interface is evidence about current output. It is not proof that the model has ceased to carry the concept.

Evidence of absence

An organization can show that a database query returns no row. Demonstrating that a model behaves as though selected training data had never existed is a different evidentiary problem.

Who chooses the verification test? How long must the result hold? Which future fine-tuning run could undo the forgetting? A provider may offer an assurance at model level while an operator still retains the original data in logs. An operator may delete its copy while a downstream recipient keeps one under another legal basis.

The remedy crosses organizational boundaries as well as technical ones.

Deletion remains valuable. Removing live data reduces access and future use. Short retention schedules limit exposure. Training systems can be designed so that later removal is less ruinous. These measures improve the return route without pretending that every layer supports the same operation.

Erasure deserves a map rather than a button. The map should identify the source record, every known copy, each derived artifact, and the evidence required to close the request. Where a layer cannot be reversed, the person should hear that before their data enters it.

The record can disappear from view while its influence waits elsewhere. Kafka’s file has returned to the shelf.

Companions


These notes come out of Sociable Systems, a practice that reads AI-shaped documents the way a hostile reviewer will, before a lender or a court finds the gap. The argument has an operational form: the Interim Protocol sets out four rules for AI use in environmental and social deliverables, covering disclosure at touch-point grain, evidence custody, the phrases no automated screening may settle, and a hostile read before anything ships. Free, and written to be cited or retired once institutional guidance arrives.