Trained models do not have a delete key.
↳ why “just take it down” is not the answer it sounds like
Every instinct says there must be a way to take it back: a deletion request, a right to be forgotten, a button. For data sitting in a database, there often is. For knowledge absorbed into a trained model, the research says otherwise.
NIST’s AI 100-2e2025, published in March 2025, separates exact unlearning (retraining the model without the data) from the approximate methods used in practice, which it notes “remain vulnerable to adversarial attacks, including inversion attacks.” Peer-reviewed work presented at ICLR 2025 found models retained 21% of the knowledge they were meant to forget at full precision, and 83% of it after 4-bit quantization; separate ICLR 2025 work showed targeted relearning can restore removed knowledge. Carlini and colleagues extracted 109 near-copies of training images from diffusion models (USENIX Security 2023), and researchers have extracted more than 10,000 verbatim training examples from ChatGPT for roughly $200 in compute.
The European Data Protection Board reached the same place from the legal side. Its Opinion 28/2024 observes that personal data “may still remain ‘absorbed’ in the parameters of the model… which may ultimately be extractable,” and concludes that “AI models trained on personal data cannot, in all cases, be considered anonymous.”
And where weights are published openly, there is no practical mechanism to retrieve copies already in third-party hands. Removing the public copy of a photograph does not guarantee removing its influence from every model already trained on it, and that is most true where the weights have been distributed rather than kept behind an API.
the honest shape of this page:
There is usually no simple, universal delete operation for a model that has already been trained or distributed. Retraining and model replacement are possible, approximate unlearning is imperfect, and which options exist depends on the model and on who controls its copies. No checklist changes that. What the rest of this page is for is the part that is still open: the identity-fraud surface is genuinely reducible, the sextortion script is genuinely defeatable by a conversation held in advance, and the takedown right is real and enforceable. Those three are worth your Saturday. Grieving the first part is not.