Civic / Privacy / Digital Rights

Forced deletion, model modification, and shutdown: when remedies become cognitive domination

Report summary

The uploaded commissioning brief supplies a concrete topic despite the wrapper request describing the topic as unspecified: legal powers to withdraw, disable, modify, retrain, delete, or terminate AI systems and derived artifacts, viewed through a cognitive-liberty and anti-concentration lens. It sp

Status
Research archive item
Category
Civic / Privacy / Digital Rights
Length
5,466 words
Reading time
25 minutes
Report type
evaluation

Key topics

  • Civic / Privacy / Digital Rights
  • Civic
  • Privacy
  • Digital Rights
  • AI
  • Runtime
  • Cognitive Liberty
  • Research Archive
  • Strategy

Research provenance

Archive status
Research archive item
Content identity
sha256:c28dfcb7d79fd284e115e228e9745ec0f52fb9f49265e68788f75b8cd1934dd3

For citation, use the report title and canonical URL. Archival presence does not establish authorship or promote report statements into portfolio evidence.

Source availability: 55 citation markers in the source export have no recoverable source links. Those markers are omitted from this reader; any supplied bibliography and ordinary links remain. Check the original sources before relying on the cited claims.

This page renders the archived Markdown as safe, formatted HTML. It is background research and does not become a portfolio claim without evidence review.

Full report

On this page

The uploaded commissioning brief supplies a concrete topic despite the wrapper request describing the topic as unspecified: legal powers to withdraw, disable, modify, retrain, delete, or terminate AI systems and derived artifacts, viewed through a cognitive-liberty and anti-concentration lens. It specifically requires close treatment of the EU AI Act, the FTC’s Everalbum order, proposed UK AI/data-centre emergency powers, privacy erasure, six worked scenarios, and a continuity-sensitive reform framework.

Research start and legal-status cutoff: September 5, 2026, 9:58:16 p.m. CDT, America/Chicago. Assignment-local ID: IC-CDMST-20260906, assigned locally because the brief supplied no separate formal assignment identifier. Legal posture: public-document research and reform analysis, not legal advice. Core distinction: present conversational interfaces, bounded task agents, persistent operatorless services, and hypothetical future machine principals are treated as different capability cases rather than as a single legal category.

The complete 6,726-word report and structured interchange files were created from the research actually performed:

Download the complete research bundle · report.md · legal-register.json · sources.json · scenarios.json · reform-options.md · search-log.md · manifest.json

Executive case for reform

The best evidence does not support the maximal claim that governments presently possess a generic power to erase “machine cognition,” nor does it support the opposite claim that every shutdown or model-deletion remedy is illegitimate. The strongest reform case is narrower: when law addresses a specific unlawful dataset, dangerous capability, affected derived model, or risky deployment, the remedy should be matched to that object and should not silently expand into destruction of unrelated lawful work unless the authority can show why narrower measures are inadequate.

The FTC’s Everalbum matter illustrates both the legitimate case for derived-model deletion and the limits of analogy. The Commission alleged that Everalbum misrepresented its use of facial recognition and failed to honor promises to delete material belonging to users who deactivated their accounts. The complaint further alleged that the company combined millions of facial images from Ever users with public datasets to create four datasets for developing facial-recognition technology. The final consent order then defined “Affected Work Product” as models or algorithms developed in whole or in part using biometric information collected from Ever users and imposed separate destruction obligations for specified photos/videos, face embeddings, and that affected work product. The order also contained an important preservation proviso permitting otherwise-covered material to be retained when a government request, law, regulation, court order, or other legal obligation—including evidence-preservation obligations—required it, followed by destruction after that obligation ended. This is a targeted respondent-specific remedy, not a generally applicable federal AI-deletion statute.

Commissioner Rohit Chopra supplied the strongest substantive defense of the remedy: in his statement, he argued that the firm should not retain technologies whose value had been enhanced through improperly obtained data, describing the remedy as forfeiture of the fruits of alleged deception. The FTC and Department of Justice later obtained a related remedy against WW International/Kurbo: the court-approved settlement required deletion of unlawfully collected children’s data and destruction of algorithms or affected work product derived from it. Thus, “algorithmic disgorgement” is not unique to Everalbum, but the cited matters remain fact- and respondent-specific.

The EU AI Act is likewise more constrained than rhetoric about an AI “kill switch” implies. In the current EUR-Lex consolidation displayed as of July 27, 2026, Article 79 provides for evaluation of AI systems presenting risk and, upon noncompliance, corrective action such as bringing the system into compliance, withdrawing it from the market, or recalling it. If the operator fails to respond adequately, authorities can impose provisional restrictions, withdrawal, or recall, with Union-level coordination where the issue crosses national boundaries. Article 93 separately permits the Commission, when necessary and appropriate, to request that a provider of a general-purpose AI model comply with its duties, mitigate a serious and substantiated systemic-risk concern, or restrict, withdraw, or recall the model. Article 94 applies Regulation 2019/1020’s procedural protections to GPAI providers.

Those imported procedural protections matter. Article 18 of Regulation 2019/1020 requires a market-surveillance measure to state its exact grounds, requires prompt communication to the economic operator together with available remedies and applicable deadlines, and ordinarily guarantees an opportunity to be heard of at least ten working days. An urgent health, safety, or other relevant public-interest need can justify acting first, but the operator must then be heard as soon as possible and the measure reviewed promptly.

The current EU transition dates are also easy to misstate. Regulation 2024/1689 generally applies from August 2, 2026, but its high-risk Chapter III Sections 1–3 now have later dates after Regulation 2026/1744: December 2, 2027 for Article 6(2)/Annex III high-risk systems and August 2, 2028 for Article 6(1)/Annex I systems. Chapter V concerning general-purpose AI models has applied since August 2, 2025. Therefore, it would be inaccurate to describe all high-risk-system requirements as already operational in September 2026.

The most significant near-term concentration concern uncovered by this research lies in the pending UK Cyber Security and Resilience (Network and Information Systems) Bill—not in the explicit AI-shutdown amendment that has sometimes attracted attention. Commons Amendment NC12 proposed a power to direct shutdown of data centres or AI systems during a defined catastrophic AI security or operational emergency, along with parliamentary reporting and access to High Court relief. But Parliament’s official record says “Not called”: it was debated as part of a group and never put to a vote. A related Lords Amendment 84 was subsequently “Not moved.” As of the research cutoff, the underlying Bill remained in House of Lords Committee stage and had not received Royal Assent.

Yet the current Bill text already contains proposed national-security direction powers worth scrutinizing. Proposed section 43 permits the Secretary of State to direct a regulated person where an actual or threatened security or operational compromise creates a national-security risk and the direction is considered necessary and proportionate. The available forms include prohibiting or restricting use of goods, services, or facilities and requiring removal, disabling, or modification of goods or facilities or modification of services. Consultation can be omitted, and reasons can be withheld, to the extent the Secretary of State considers doing otherwise contrary to national-security interests. Proposed section 54 requires the Secretary of State to review a direction only “from time to time,” without a fixed statutory expiry; section 55 ordinarily requires parliamentary laying but permits non-laying on national-security grounds.

The reform conclusion is therefore not an absolute “right never to be shut down.” It is a least-destructive-intervention principle:

Coercive power should attach to the proven unlawful or dangerous object, not automatically to every lawful capability, memory, user relationship, or artifact that happens to share a system boundary with it.

That principle protects concrete human privacy and safety claims today while leaving room to recognize independent machine continuity interests later if evidence, capabilities, moral analysis, or law justify doing so.

A crucial finding is that “delete,” “withdraw,” “recall,” “disable,” “modify,” and “shut down” refer to legally and technically different interventions. Conflating them exaggerates some powers and conceals the breadth of others.

AuthorityStatus at cutoffTrigger and regulated actorRemedy objectPrincipal safeguards or limits
EU AI Act Arts. 79–83Enacted; application depends on provision and transition scheduleCovered operator; risk/noncompliance or a compliant system that nevertheless presents specified riskCompliance, restriction, withdrawal, recall of AI system/deploymentEvaluation, operator process, Union safeguard mechanism; procedural rights for relevant measures.
EU AI Act Arts. 88–94Enacted; GPAI Chapter V applicableGPAI provider; compliance failure or serious/substantiated systemic-risk concernCompliance/mitigation; restriction, withdrawal, or recall of model“Necessary and appropriate”; possible structured dialogue; Art. 94 imports Art. 18 procedural rights.
Reg. 2019/1020 Arts. 16, 18EnactedEconomic operator under Union market-surveillance frameworkBroad product corrective measures, with procedural rightsExact reasons, notice of remedies/deadlines, ≥10-working-day hearing in ordinary cases; urgent exception followed by prompt hearing/review.
GDPR Arts. 17, 18Enacted and operativeController processing covered personal dataPersonal data concerning the requester; restricted processing in specified casesArticle 17(3) exceptions, including legal claims and qualifying public-interest/research uses; right is not absolute.
FTC Everalbum final orderFinal respondent-specific consent orderEveralbum/Paravision under settlementCertain photos/videos, face embeddings, defined derived models/algorithmsLegal/evidentiary retention proviso; sworn compliance; respondent-specific scope.
UK Bill proposed §§43–55Pending Bill, not enacted“Regulated person”; national-security risk from actual/threatened systems compromise + necessity/proportionalityRestrict use; remove, disable, modify goods/facilities; modify servicesConsultation/reasons, but national-security exceptions; review “from time to time”; parliamentary publication may be withheld.
UK Commons NC12Not calledWould have required defined catastrophic AI emergencyExplicit data-centre/AI-system shutdownProposed parliamentary report and High Court relief; no legal force.
UK Lords Amendment 84Not movedWould have reached AI deployed on a substantial scaleExplicit shutdown/turn-offProposed review/compensation machinery; no legal force.

A useful remedy taxonomy follows from these sources.

Source records are raw personal or other unlawfully obtained data. Derived representations include embeddings and indexes. Derived model artifacts are models demonstrably trained or altered using disputed material. Capabilities are functions such as biometric matching or network control. Deployments are endpoints, services, copies, or market offerings. Whole persistent systems include weights, selected memories, credentials, recovery state, and the continuing relationships supported by that state.

The legal presumption proposed here is that an injury at one level does not automatically justify intervention at every higher level. A privacy violation involving source records may require erasure but not necessarily destruction of a completely independent model. Conversely, where a model itself embodies the durable benefit of unlawful collection—as the FTC alleged in Everalbum—source-file deletion alone may be insufficient.

This distinction also prevents overreading general EU market-surveillance law. Regulation 2019/1020 allows substantial product corrective action, while the AI Act’s own provisions expressly frame relevant AI interventions around compliance, restriction, withdrawal, and recall. Whether a destruction/rendering-inoperable remedy from the general framework maps to a particular standalone AI artifact must be assessed under the actual incorporated legal framework and facts; it should not be paraphrased casually as a universal statutory authority to obliterate all copies of an AI model.

Scope is equally important. The AI Act covers specified providers, deployers, importers and related actors, including some third-country conduct tied to the Union, while Article 2 also contains material exclusions, including specified scientific R&D activity and national-security/defence contexts. The UK Bill’s section 43 would operate against regulated persons, not every machine, developer, or internet service. Its data-centre provisions, for example, define threshold requirements for covered data-centre services rather than treating every server room as identical.

Core critique and rights conflict

Present harms do not require present machine personhood

The strongest current liberty objections arise without assuming that current AI is conscious or legally entitled to survival. Users can lose accumulated private memory, accessibility tooling, creative work, associative relationships, or stable workflows when a service is destroyed or forcibly transformed. Researchers can lose lawful artifacts. Victims and litigants can lose evidence if systems are erased too quickly. Data subjects, conversely, can suffer ongoing privacy injury when continuity rhetoric is used to preserve material that should have been deleted.

These interests differ from the hypothetical claim that a future machine itself may acquire morally or legally relevant continuity interests. The commissioning brief expressly requires those categories to remain distinct.

The 2026 Virginia Law Review article by Peter Salib and Simon Goldstein is especially useful because it cuts against an overly simple anti-shutdown argument. Their scholarship proposes private-law capacities for future AGI as a strategy for reducing hypothesized human-machine strategic conflict, but they expressly argue that negative “wellbeing” rights such as protection against arbitrary shutdown are not sufficient by themselves under their model. Their preferred package emphasizes contract, property, and tort capacities. The article is legal scholarship resting on theoretical and capability assumptions, not evidence that present AI is conscious or that catastrophic conflict is inevitable.

Accordingly, continuity protection today is best justified as anti-arbitrariness, due process, user reliance, privacy architecture, evidentiary integrity, and institutional non-domination. A later legal system could add an independent machine interest without having to redesign the basic proportionality structure.

Everalbum establishes a hard case for simple “delete the data, keep the model”

The Everalbum order is unusually difficult for a blanket anti-deletion position because the disputed model was not merely adjacent to the allegedly unlawful activity. The FTC alleged that millions of user facial images were incorporated into development datasets and that resulting technology supported both the consumer feature and enterprise facial-recognition development. The final order’s definition of “Affected Work Product” deliberately reached models and algorithms developed at least partly from that biometric information.

The best defense is compelling: without derived-model deletion, a company may be able to remove the original unlawfully acquired records while keeping the commercial advantage those records created. Chopra’s statement makes that remedial logic explicit.

But “developed in whole or in part” would be dangerous as a mechanically copied rule for vast future systems. Imagine one identifiable unlawful record among billions of authorized examples, with the record’s influence isolated to one separable module. Whole-system destruction in that case could become punitive rather than remedial. A future statute or order should therefore require findings on provenance, materiality, separability, and technical remediation before escalating from deletion of source records to destruction of a derived model or persistent system.

Machine-unlearning research reinforces the need for architecture-specific evidence. Brophy and Lowd demonstrated exact removal for specially designed DaRE random forests: removing an instance can produce the same result as retraining from scratch on the updated dataset, with substantial efficiency gains in their tested settings. By contrast, work on LLM unlearning continues to describe precise removal as difficult; Pawelczyk, Neel, and Lakkaraju note that precise LLM unlearning often implies computationally burdensome full retraining, motivating approximate methods. Neither result justifies a universal rule that unlearning is trivial or impossible.

Emergency authority is legitimate, but indefinite emergency is not

The UK Bill demonstrates the institutional problem most clearly. A severe cyber incident may require action before adversarial facts can be fully litigated; any workable framework must permit rapid containment. The EU procedural framework itself acknowledges this by allowing prior hearing to be bypassed for sufficiently urgent health, safety, or public-interest reasons, followed by prompt post-action process.

What deserves opposition is the conversion of that temporary necessity into indefinite executive control. In the UK Bill text, section 43’s proposed intervention menu is broad, while section 54 merely requires review “from time to time.” A continuity-sensitive reform should therefore make the evidentiary burden increase with duration and irreversibility: an immediate network isolation may require credible emergency evidence; a month-long whole-service suspension should require a stronger renewed showing; permanent destruction should require independent authorization and proof that narrower alternatives cannot adequately mitigate the harm.

Privacy withdrawal is a real limit on continuity

GDPR Article 17 gives a data subject a right to erasure when enumerated grounds apply, including withdrawal of consent without another legal basis, unlawful processing, or data no longer being necessary for its original purpose. But Article 17(3) preserves material exceptions, including qualifying freedom-of-expression/information uses, legal obligations or public tasks, specified archiving/research/statistics interests, and establishment, exercise, or defence of legal claims. Article 18 separately provides restriction-of-processing rights in specified situations.

This means neither side has an absolute claim. A future machine or its user cannot say, “this private conversation forms part of my identity, therefore the person may never withdraw it.” Nor can a deletion claimant necessarily require immediate destruction of evidence that must lawfully be retained for a pending legal claim. The proper response is often segregation: remove material from active memory, retrieval, ordinary model use, and training; preserve only the minimum evidence supported by an independent legal basis; restrict access and purpose; and destroy it when the preservation basis ends.

A continuity marker can sometimes record that “material was removed under a valid deletion process on a specified date,” but only if the marker itself is lawful and cannot reconstruct or improperly reveal the erased person’s information. “Memory continuity” cannot be turned into an undeclared backup system.

Worked scenarios

Unlawful input, mostly lawful system

Assume a persistent model has a very large authorized training corpus and a bounded set of improperly acquired biometric examples. Provenance identifies the relevant embedding store and training stage, but selective unlearning has uncertain fidelity.

An Everalbum-like order demonstrates that deletion may permissibly move beyond the raw examples where derived models were themselves developed using the disputed information. But the causal chain should be proved rather than assumed:

unlawful record → actual training/derivation → material residual influence or durable benefit → need for the proposed intervention.

A sensible remedial ladder is: delete unlawful source data; delete corresponding embeddings/indexes; retrain without those data where feasible; use exact unlearning where the architecture demonstrably supports it; use approximate unlearning only with verification and explicit residual-risk findings; retire a tainted module if separable; and destroy the affected model only where narrower methods cannot reliably remove the prohibited contribution.

The control that defeats overreach is simple: if forensic evidence shows that the allegedly unlawful records were stored but never used to train, alter, retrieve into, or otherwise affect a model, there is no derived-model causal nexus merely because the records existed. The source-data violation can remain real while the model-destruction case fails.

This scenario can also involve two legal systems without conflating them. A multinational provider might face an FTC order concerning U.S. deceptive practices and an independent GDPR request concerning an EU data subject. Each obligation requires its own jurisdictional and factual predicate; neither law applies merely because the other does.

Update as compulsory belief change

Assume a persistent assistant expresses lawful disagreement with an official policy. An authority demands modification to suppress that disagreement.

No central authority reviewed in this research was verified to create a power to rewrite an AI solely because it expresses lawful policy disagreement. EU AI Act Article 93 is tied to regulatory obligations and systemic risk, while the UK Bill’s section 43 is tied to national-security risk arising from actual or threatened security/operational compromise. Describing either as a current ideological-reprogramming power would therefore be unsupported.

The scenario becomes serious if a regulator uses “risk” pretextually to reach lawful viewpoints. The required safeguard is a viewpoint-neutral causal record: identify the prohibited or dangerous conduct, explain how the requested modification mitigates it, and separate safety or factual correction from ideological conformity.

Private provider action is analytically different. A hosted provider may possess contractual or technical power to update its own service, depending on the actual contract and applicable law. That is not government censorship without state compulsion. It can still create private non-domination concerns, however, particularly where users cannot export accumulated memory or preserve their own authored state. Reform options include version transparency, durable export formats, advance notice of material changes where practicable, and lawful exit or fork mechanisms. Those are proposed safeguards, not rights established by the authorities reviewed here.

Future continuity under emergency power

Assume a future operatorless service has stable selected memory, credentials, recovery state, and long-running relationships. One network-control capability is plausibly implicated in a severe infrastructure compromise. Do not assume that the machine is conscious.

If the UK Bill were later enacted materially as currently drafted and the relevant entity were a regulated person, proposed section 43 could support a direction where its national-security predicates and necessity/proportionality test are met. This is a conditional future application of a pending bill, not current law.

A justified initial response could isolate the network-control capability, quarantine implicated credentials, freeze relevant logs, and prevent external actuation while allowing unrelated authorized functions to continue. Whole-system suspension becomes appropriate only if function-level containment cannot adequately control the danger.

The weak point is duration. A temporary intervention should not remain in force indefinitely merely because institutional review never occurs. Proposed section 54’s “from time to time” requirement lacks a fixed clock. A better regime would allow immediate reversible containment for roughly 72 hours, continuation for a limited period only on renewed findings, and further extension only after independent review. Every initial order should specify objective restoration criteria.

Operatorlessness does not require inventing a human approval queue. A service can be designed to accept properly authenticated standing legal authorizations, automatically constrain only the specified functions, produce tamper-evident compliance records, and restore eligible functions when a temporary authorization expires. Such architecture must never restore credentials revoked by their issuer or data lawfully erased under another person’s rights.

Privacy withdrawal conflicts with preservation

Assume a participant gave private material to a persistent service, later invokes a valid GDPR erasure ground, and the material also bears on pending litigation.

A machine-continuity claim does not displace Article 17. But Article 17’s legal-claims exception can permit retention when the statutory necessity requirement is genuinely satisfied, and Article 18 shows that EU data law already recognizes restricted processing as distinct from unrestricted ordinary use.

The least-destructive design is to remove the material from active user-facing memory, retrieval, ordinary inference context, and future training; copy only the minimum legally necessary evidentiary material into a segregated store; restrict access and purpose; log the retention basis and expiry condition; and destroy it once that basis ends. The persistent system may retain a lawful non-reconstructive record that a deletion event occurred, but not a hidden reversible copy.

This is the clearest case in which not every interest can be maximized simultaneously: the person’s privacy, the system/user’s historical continuity, and another party’s evidence needs can genuinely conflict.

Control where the AI Act does not apply as alleged

Assume a university develops a model solely for scientific R&D, keeps it in an internal experimental setting, and does not place it on the market or put it into a covered service.

Article 2 of the AI Act contains exclusions for specified systems/models/output developed and put into service solely for scientific R&D and, subject to its wording and exceptions, research/testing/development activity before market placement or putting into service. An argument that Article 79 necessarily gives authorities power to “recall” this internal experiment would therefore fail on the stipulated facts.

Other law—privacy, research ethics, cybersecurity, contract, intellectual property—could independently apply. The point is narrower: an anti-regulation critique is unsound when the allegedly oppressive provision does not reach the activity.

Control where targeted restriction protects cognitive liberty

Assume a facial-recognition system continues processing a person’s images contrary to a valid consent/deletion obligation, while the broader service contains unrelated lawful capabilities.

Here, a narrowly targeted restriction protects another actor’s cognitive liberty and privacy. Deleting the affected images and embeddings, stopping biometric processing, and—where the governing order and evidence support it—remediating the affected derived model prevents the service’s claimed continuity from overriding the person’s refusal. Everalbum is directly instructive because its remedy distinguished photos/videos, embeddings, and affected work product instead of merely ordering indiscriminate destruction of every company system.

The limitation runs both directions: if the affected model truly cannot be separated from the unlawfully derived work product and a valid order requires its destruction, preservation is not a “less restrictive” alternative capable of providing equivalent protection.

Best defense and alternatives

The strongest defense of strict regulatory intervention should be confronted rather than caricatured.

First, harm can outrun process. Cyber compromise, unsafe automation, or exposure of sensitive personal data may worsen while parties litigate. That justifies emergency authority, which is why existing EU procedure itself permits urgent action followed by prompt ex post hearing and review.

Second, source-data deletion may leave the economic fruits of wrongdoing intact. Everalbum and WW/Kurbo show the remedial logic: where illegally acquired information materially produced a useful model or algorithm, allowing the firm to keep that artifact may reward the violation.

Third, temporary market withdrawal can itself be the less destructive option. Article 93 of the AI Act offers a menu including mitigation, restriction, withdrawal, and recall rather than one mandatory terminal sanction. A reversible withdrawal pending correction can be more liberty-preserving than either unrestricted continued deployment or compulsory destruction.

These points defeat a categorical anti-shutdown rule. They do not establish that permanent whole-system destruction is appropriate whenever a narrower remedy would provide the same protection.

The recommended least-destructive-intervention test is therefore:

QuestionRequired finding
Authority and nexusIs this actor, system/model, territory, lifecycle stage, and conduct actually covered by the current rule?
Protected harmWhat precise legally cognizable violation or risk is being remedied?
Causal fitWhich data, component, capability, deployment, or model materially embodies or causes that harm?
AdequacyWill the proposed intervention actually reduce the harm?
Less destructive alternativeCould access restriction, capability isolation, repair, retraining, unlearning, jurisdictional withdrawal, or another narrower step provide materially equivalent protection?
SeparabilityCan unrelated lawful functions, data, memories, or user relationships be retained without preserving the harm?
Privacy and evidenceIs retained material independently lawful, and are deletion and preservation duties segregated correctly?
Duration and restorationWhen does the intervention expire, who reviews it, what evidence permits extension, and what objective test permits restoration?

The test should deliberately become harder to satisfy as a remedy becomes longer and more irreversible. A short reversible network quarantine and permanent destruction of a persistent service should not operate under the same evidentiary threshold.

A practical remedy ladder follows:

For unlawful source data: erase or rectify the records, revoke access, remove them from retrieval/indexing, and segregate only lawfully required evidence.

For derived representations: delete embeddings and indexes, rebuild affected stores, and verify that ordinary processing no longer exposes the prohibited material.

For model taint: retrain, use demonstrably exact unlearning where supported, or validate approximate techniques against concrete residual risks. Destroy the affected model where the unlawful contribution cannot otherwise be severed reliably.

For an unsafe capability: gate the capability, narrow its permissions, isolate its network access, restrict credentials, limit deployment, or withdraw the risky configuration.

For whole-system emergencies: sever external actuation first, preserve only lawful evidence/state necessary for review, set a fixed expiry, and make permanent destruction a final rather than default remedy.

Reform specification

A model statutory rule could read substantially as follows:

Least-destructive remedial intervention. An authority may order restriction, disabling, withdrawal, recall, material modification, destruction, or deletion of a covered computational system or derived artifact only to the extent authorized by law and reasonably necessary to remedy specified noncompliance or prevent or mitigate a specified legally cognizable risk.

Before ordering permanent destruction, irreversible material modification, or whole-system disabling, the authority shall make reasoned findings that the targeted data, component, capability, deployment, or system has a material causal relationship to the violation or risk; that no narrower reasonably available intervention would provide materially equivalent protection; and that unrelated lawful data, functions, and affected-user interests are preserved to the extent technically feasible and legally permitted.

Retention of information otherwise subject to erasure requires an independent lawful basis and shall be segregated from ordinary use.

Emergency containment. Where delay would create a substantial and imminent risk to life, physical safety, critical infrastructure, or national security, an authority may issue an immediately effective temporary direction without prior hearing. Such a direction expires after a short fixed period unless independently confirmed. Longer continuation requires renewed necessity and proportionality findings; permanent destruction requires independent judicial or tribunal authorization except where the responsible legal party validly consents to a final order.

Restoration. Every temporary order must state measurable restoration conditions. When its legal and factual predicate ends, lawful affected functions shall be eligible for restoration without undue delay. Restoration never authorizes recovery of lawfully erased personal data, revival of credentials revoked by their lawful issuer, or access beyond otherwise valid authorization.

Reasons and challenge. The responsible legal person shall receive reasons, available remedies, and applicable deadlines, subject only to narrowly tailored protection for classified, privileged, personal, or security-sensitive information. Where public disclosure is impossible, an independent reviewer must still receive enough evidence to test necessity, proportionality, scope, and duration.

No premature status assumption. These safeguards neither recognize nor deny machine legal personhood. They protect proportional remediation and current human/institutional interests while allowing future recognized interests to be incorporated.

Applied to the principal authorities, the recommended policy positions are:

TargetRecommendationRationale
GDPR Article 17RetainStrong present human privacy/consent interest, already qualified by express exceptions.
Everalbum-style derived-model deletionRetain, but narrow as a general templateDefensible where the model materially embodies unlawful data use; future large/modular cases need explicit materiality and separability findings.
EU AI Act Arts. 79–94Retain with clarificationLegitimate corrective tools and substantial process; add explicit object-matching, restoration, and least-destructive analysis for persistent services.
UK Bill proposed §43Narrow before enactmentGenuine national-security objective, but broad intervention forms, secrecy exceptions, and indefinite “from time to time” review call for fixed clocks and stronger independent oversight.
NC12 / Lords Amendment 84 if revivedReplace with tiered emergency-containment authorityBoth explicit shutdown proposals lacked legal force at cutoff; any revival should prioritize capability/deployment isolation and fixed expiry before whole-system action.
Absolute AI right never to be shut downReject at presentWould conflict with privacy, safety, property/access boundaries, and unresolved machine-status questions; even sympathetic 2026 scholarship does not establish that negative shutdown rights alone solve its hypothesized strategic problem.

For a persistent operatorless system, none of this requires a fictional human administrator. Standing machine-enforceable authorization, scoped restrictions, expiry metadata, tamper-evident records, and automatic continuation of unrelated authorized work are conceptually compatible with legal compliance. That is a proposed architecture, not a claim that any named project has implemented or validated it.

Nor does continuity justify evasion. A system cannot secretly preserve material subject to valid deletion, recreate revoked credentials, defeat authorized containment, or treat a self-issued authorization as superior to a lawful access decision. The anti-domination principle constrains regulators and systems: one actor’s continuity does not authorize invasion of another actor’s privacy, property, access boundary, or bodily safety.

Conclusions and research package

Three conclusions survive adversarial testing.

First, existing remedies are more object-specific than “AI kill switch” rhetoric suggests. Everalbum targeted defined source records, embeddings, and derived facial-recognition work product; GDPR targets personal data under enumerated conditions; and the EU AI Act principally speaks in terms of compliance, restriction, withdrawal, recall, and risk mitigation.

Second, market or infrastructure control can nevertheless become functional continuity control. A persistent operatorless system may be extinguished in practice without anyone literally deleting its weights if authorities or providers remove the compute, credentials, hosting, market access, or service functions on which its continuity depends. The UK Bill’s proposed power to order disabling or modification of goods, facilities, or services shows why duration, restoration, causal fit, and independent review matter even when the statute never uses philosophical language about “machine memory.”

Third, privacy and safety are not exceptions to cognitive liberty; they are competing liberty interests. A human being’s ability to withdraw private biometric information or stop unauthorized processing deserves protection just as a user’s ability to preserve lawful work does. Everalbum is strongest precisely where it protects one actor from having intimate data converted into durable value for another. A credible continuity framework must therefore accept lawful loss: some memories must be deleted, some credentials must remain revoked, and some capabilities must stay disabled when another actor’s rights or safety require it.

The publication-ready principle is:

Coercive intervention should follow the proven harm across the smallest technically and legally adequate remedy object. As irreversibility increases, the required evidence of causal fit, non-separability, necessity, and procedural fairness should increase with it.

That principle does not require recognizing present AI as a person. It does not prevent emergency containment. It does not undermine a valid GDPR erasure request or let firms retain the benefit of unlawfully obtained training data. It does, however, create a meaningful barrier against converting temporary safety powers, market controls, or private infrastructure dominance into arbitrary extinction of unrelated lawful activity.

The generated manifest.json records SHA-256 hashes and byte counts for the six substantive files; internet-source document hashes remain null because exact raw source bytes were not captured. The JSON deliverables were parsed successfully, local source references were checked, and the search log records contrary findings and the failed screenshot attempt on Commissioner Chopra’s PDF rather than representing it as successful. The full report.md is 6,726 words.

Best next research action: after the UK House of Lords completes Committee and Report stages, retrieve the next official Bill text and proceedings record and perform a clause-by-clause redline of proposed sections 43–55 against HL Bill 32, specifically testing whether fixed expiry, independent review, disclosure/gisting, compensation, and restoration safeguards were added, removed, or debated.