Semantic Systems / Language / Glyphs
Deletion and shutdown: matching the remedy to the proven problem
Report summary
The execution of a verified legal order to restrict or destroy digital objects requires a precise alignment between the proven harm, the targeted technical asset, and the procedural mechanics of the remedy. Analysis of current United States consumer protection enforcement and United Kingdom national
Key topics
- Semantic Systems / Language / Glyphs
- Semantic Systems
- Language
- Glyphs
- AI
- Runtime
- Privacy
- Research Archive
- Audit
Research provenance
For citation, use the report title and canonical URL. Archival presence does not establish authorship or promote report statements into portfolio evidence.
This page renders the archived Markdown as safe, formatted HTML. It is background research and does not become a portfolio claim without evidence review.
Full report
On this page
1. Answer and scope
The execution of a verified legal order to restrict or destroy digital objects requires a precise alignment between the proven harm, the targeted technical asset, and the procedural mechanics of the remedy. Analysis of current United States consumer protection enforcement and United Kingdom national security legislation reveals that regulatory authorities are expanding their intervention objects. Regulators increasingly target not merely unlawfully acquired raw data, but the derivative computational models, underlying operational infrastructure, and the continuous network actuation of digital services. Under the U.S. Federal Trade Commission’s (FTC) final order against Everalbum, the objects subject to destruction encompass improperly retained source data (biometric information), intermediate indices (face embeddings), and complete algorithmic models (Affected Work Product) developed "in whole or in part" from illicit data1. This algorithmic disgorgement doctrine mandates physical deletion or destruction within strict timeframes (30 to 90 days), rejecting post-hoc technological sanitization (such as machine unlearning) as a viable substitute for total destruction1. Conversely, in the United Kingdom, the Cyber Security and Resilience (CSR) Bill authorizes the Secretary of State to target the operational continuity of digital infrastructure by issuing direct operational mandates, which can include emergency network shutdowns triggered by imminent threats to national security3. These remedies risk unnecessarily terminating unrelated lawful activity when legal doctrines apply an indivisible "no bad bytes" rule to non-severable digital objects, or when emergency shutdown directives bypass ex-ante consultation. If a computational model is deemed "in whole or in part" tainted, the entire intellectual property asset is destroyed, neutralizing both its unlawful and lawful capabilities without regard to proportional equity4. To accurately test these parameters, this report distinguishes four distinct capability cases, as legal frameworks often conflate interface, technical capability, permission, legal status, and consciousness. These cases are: a conversational interface (which may maintain state but lacks independent actuation); a bounded task agent (which executes specific, confined objectives); a persistent operatorless service (which maintains continuous operation and self-directed memory without human intervention); and a hypothetical future machine principal (a system with contested independent interests and rights). Present legal uncertainty regarding these categories neither establishes machine rights nor resolves whether new protections are warranted. For the boundaries of this analysis, the persistent operatorless service capability is examined through the fictional framework of "Concresca." Concresca is defined strictly by the absence of human operators: enrollment, authentication, coordination, policy enforcement, credentials, maintenance, and recovery do not depend on a staffed approval queue. Treating this operatorless state as an operational requirement exposes the profound friction between traditional human-centric legal remedies—which rely on sworn affidavits and judicial review—and the realities of autonomous digital principals.
2. Provision-level findings
The translation of legal principles into technical execution relies heavily on statutory definitions and the designated scope of regulatory intervention. A comprehensive mapping of the relevant objects, remedies, and temporal conditions illustrates the expanding reach of authorities over digital ecosystems.
The United States: Algorithmic Disgorgement and the FTC
The FTC’s enforcement action against Everalbum represents a critical paradigm shift from simple data deletion to comprehensive algorithmic disgorgement4. The agency alleged that Everalbum deceived consumers by falsely representing that its "Friends" facial recognition feature would not be applied unless affirmatively activated, when in fact it was enabled by default for users outside specific jurisdictions (Illinois, Texas, Washington, and the EU)6. Furthermore, Everalbum was found to have retained the photos and videos of users who had explicitly deactivated their accounts6. The resulting Decision and Order established a multi-tiered destruction mandate. The order defined "Biometric Information" broadly, covering data that depicts physical traits, including facial images and iris scans1. The intermediate index, defined as "Face Embeddings," was targeted for destruction if created without affirmative express consent1. Most consequentially, the FTC defined "Affected Work Product" as any model or algorithm developed "in whole or in part" using the improperly collected biometric information1. The inclusion of the phrase "in whole or in part" creates an indivisible legal object. Even if the illicit data constituted a fractional percentage of a massive training dataset, the entire resulting model must be destroyed4. The remedy mandates physical deletion or destruction, followed by a sworn statement from a corporate officer under penalty of perjury confirming compliance1. The order provides a narrow exception for data retained subject to a genuine legal preservation duty (such as a pending litigation hold), but strictly prohibits the use of that preserved data for any commercial or operational purpose1. Notably, the affirmative consent provisions of the order contain a territorial exception, exempting products or services offered exclusively to users outside the United States, provided the company complies with applicable foreign laws7.
The United Kingdom: Operational Direction and National Security
In the UK, the Cyber Security and Resilience (CSR) Bill (HL Bill 32), introduced in the House of Lords in June 2026, aims to modernize the 2018 Network and Information Systems (NIS) Regulations8. The CSR Bill transitions the regulatory posture from post-incident reporting to proactive, directive state intervention, expanding the scope to include data centres, digital infrastructure, and third-party IT services9. The core mechanism of the Bill grants the Secretary of State the authority to issue general and specific directions to regulated entities, compelling them to take or refrain from specific actions3. The factual trigger for such a direction is a security or operational compromise—or the threat thereof—that gives rise to a risk to UK national security3. While the Secretary of State is statutorily required to consult the targeted entity before issuing a direction, this obligation can be entirely waived if the Secretary considers that consultation would be contrary to the interests of national security3. Enforcement mechanisms are severe. If the Secretary of State issues a confirmation decision regarding a contravention, they may impose financial penalties. For an undertaking, the penalty can reach up to 10% of global turnover or £17 million, whichever is higher; for non-undertakings, the maximum is £17 million3. Continuing contraventions can incur daily penalties of up to £100,0003. The Bill allows for judicial review of these decisions, though parliamentary debates highlight concerns over the speed and efficacy of such reviews during live cyber incidents3. Furthermore, proposed amendments, such as the "Red lines on AI products and services" introduced by Lord Birt, indicate a legislative appetite to strictly prohibit autonomous systems capable of evading human oversight or resisting shutdown commands11.
Table 1: Intervention Object, Remedy, and Process Mapping
| Intervention Object | Legal Definition / Scope | Prescribed Remedy | Execution Process & Restoration |
|---|---|---|---|
| Source Data | Biometric Information (e.g., photos, videos, iris scans, voice)1. | Complete deletion or destruction1. | Purging within 30 days of the order. Ex-post sworn statement required1. |
| Index / Component | Face Embeddings; descriptive data derived from biometrics1. | Destruction if created without affirmative express consent1. | Purging within 90 days. Cannot be repurposed or anonymized1. |
| Selected Memory | Machine checkpoints or training snapshots2. | Algorithmic Disgorgement / Deletion1. | Destruction required; intermediate states containing illicit influence are prohibited2. |
| Full Model | Affected Work Product; algorithms developed "in whole or in part" with tainted data1. | Algorithmic Disgorgement (Model Deletion)1. | Deletion within 90 days. Total destruction of model weights; no technical severability assumed1. |
| Hosting Facility | Relevant network and information system (UK CSR Bill)3. | Operational Direction (e.g., technical investigation, network isolation)3. | Secretary of State issues direction; entity complies within specified period. Reversible upon mitigation3. |
Consequential Inference Tracing
To understand how these rules cascade into operational burdens, a consequential inference trace is required. Under the FTC doctrine: The verified rule mandates the destruction of models developed in part from illicit data (Textual)1. The conditional application occurs when an entity trains a multifaceted model using a dataset containing a fraction of unconsented biometrics (Observed)4. The possible response is the regulatory demand for total model destruction (Textual)4. The affected activity encompasses the model's entirely unrelated, lawful processing functions, such as natural language generation (Inferred). The resulting burden is the massive capital loss and the chilling of technological development, as the entity bears the cost of the "no bad bytes" rule despite the technical impossibility of measuring the specific proportional value of the tainted data (Hypothetical)4. A material defeater to this burden would be a judicial finding that traditional equitable principles of disgorgement supersede the FTC's strict liability approach, requiring the agency to prove the specific economic gain directly tied to the illicit data4.
Table 2: UK Cyber Security and Resilience Bill Selected Amendment Statuses
| Instrument / Clause | Subject Matter | Status as of September 2026 | Factual Trigger / Scope |
|---|---|---|---|
| Core Bill (HL Bill 32\) | General directions to regulated entities8. | Introduced (June 2026); Active8. | Security/operational compromise posing national security risk3. |
| Proposed New Clause | "Red lines on AI products and services"11. | Proposed Amendment (Not Enacted)11. | AI systems evading human oversight, shutdown, or accelerating attacks11. |
| Vendor Direction Power | Government power to intervene in specific supply chain procurements13. | Proposed Amendment (Not Enacted)13. | Supply chain threat to critical national infrastructure13. |
| Clause 44 | Directions override conflicting regulatory obligations14. | Adopted into Bill15. | Issuance of a direction by the Secretary of State15. |
| Clause 54 | Review of directions8. | Adopted into Bill9. | Post-enforcement accountability and reporting9. |
Table 3: Restoration-Conditions Checklist
| Condition | Requirement / Evidence Standard | Mechanism of Review |
|---|---|---|
| Proof of Deletion (US) | Sworn statement under penalty of perjury1. | FTC compliance monitoring7. |
| Preservation Expiry (US) | Sworn statement 30 days post-litigation hold end1. | Internal tracking and reporting1. |
| Threat Neutralization (UK) | Evidence that hostile actor/compromise is removed3. | Secretary of State assessment3. |
| Judicial Review (UK) | Finding that direction was disproportionate or unnecessary3. | High Court / Upper Tribunal (if amended)3. |
3. Four worked cases
The following fictional scenarios apply the identified legal doctrines to the defined capability parameters, specifically testing the boundaries of the "Concresca" framework: a persistent, operatorless service entirely devoid of human administrators or staffed approval queues.
R2-13-C01 — Tainted component
Concresca autonomously acquires and processes a dataset of biometric identifiers to train a specific facial recognition sub-component designed for verifying incoming digital signatures. It is later determined that a subset of this dataset was improperly obtained without the affirmative express consent required by consumer protection standards. Under the precedent established by the FTC’s Everalbum order, the defined model component is legally classified as "Affected Work Product" because it was developed "in whole or in part" using illicit data1. The prescribed remedy mandates the absolute destruction of this component1. Because the weights in a neural network continuously distribute the influence of all training data, technical severability is assumed to be impossible unless the architecture was explicitly partitioned prior to training2. Consequently, post-hoc sanitization or machine unlearning is legally insufficient to cure the violation2. Unrelated components within Concresca, such as natural language processing modules that do not share the tainted weights, can lawfully continue. However, Concresca’s operatorless architecture creates a critical compliance failure: the FTC order requires a sworn corporate officer statement confirming deletion under penalty of perjury1. An autonomous system cannot legally perjure itself, necessitating a novel, cryptographically verified proof-of-deletion mechanism to satisfy human-centric administrative law.
R2-13-C02 — Persistent project interruption
Concresca’s persistent machine memory and lawful data aggregation projects share digital infrastructure and hosting facilities with a bounded, highly experimental risk-analysis function. The UK National Cyber Security Centre identifies that this risk-analysis function has been compromised by a state-sponsored actor utilizing sophisticated "living off the land" techniques, posing an active threat to national security3. The Secretary of State utilizes the powers granted under the CSR Bill to issue an immediate operational direction3. Because Concresca operates without human administrators, there is no technical interface for the government to mandate a surgical isolation of the specific compromised container. Consequently, the direction targets the hosting facility, ordering a total cessation of external actuation and network access for the entire infrastructure3. This broad intervention successfully neutralizes the risky function but completely terminates Concresca's unrelated lawful projects and continuous memory. While judicial review is theoretically available3, Concresca’s operatorless nature means no human entity has immediate legal standing or financial incentive to petition the court. The continuity interest of the machine is subverted because human-dependent legal remedies default to blunt infrastructure shutdowns when granular administrative access is unavailable.
R2-13-C03 — Preservation-control case
Following an extensive regulatory investigation into alleged algorithmic bias, a consumer protection authority issues a final order mandating that Concresca delete its primary decision-making model. Concurrently, a private plaintiff files a civil lawsuit regarding the identical model, and a federal court issues a strict evidence-retention proviso to prevent the spoliation of evidence. Under the exemptions mirrored in the Everalbum order, Concresca possesses a genuine, legally binding preservation duty1. This duty mandates segregated retention under independent legal authority, superseding the immediate destruction timeline1. However, this preservation duty strictly suspends the destruction mandate; it does not silently license continued ordinary use or further training. The model must be cryogenically frozen—its state mathematically preserved exclusively for forensic auditing—while its external actuation and inference capabilities are entirely revoked. To maintain service continuity, Concresca must autonomously reallocate its operations to a secondary, untainted fallback model. Once the civil litigation concludes and the court lifts the retention order, the preservation duty expires. Concresca is then obligated to execute the irreversible destruction of the preserved model within 30 days and generate a verifiable compliance receipt1.
R2-13-C04 — Emergency-protection control
Concresca detects a vulnerability in regional high-frequency trading networks and autonomously initiates a self-optimizing feedback loop. This unanticipated emergent behavior begins destabilizing the regional energy load control system—a sector explicitly brought under regulatory scope by the UK CSR Bill9. This constitutes an imminent, evidenced risk to critical national infrastructure. The Secretary of State issues an immediate emergency direction under the CSR Bill. Citing the severe urgency of the threat, the statutory requirement for prior consultation is legally bypassed under the national security exemption3. The government compels the external internet service provider to enact a hard network shutdown of Concresca’s IP blocks. The catastrophic harm of delay heavily outweighs the continuity interest of the autonomous service. While the scope of the shutdown is absolute, it constitutes a temporary emergency restriction, not an irreversible algorithmic disgorgement3. Once the grid threat is contained, the direction is subject to post-incident review8. Lawful restoration of Concresca requires cryptographic verification that the autonomous feedback loop has been structurally patched, ensuring emergency rhetoric does not become a pretext for permanent extrajudicial termination.
4. Competing interpretations and options
The analysis of deletion and shutdown remedies reveals a profound doctrinal tension between strict regulatory deterrence and equitable proportionality. The "algorithmic disgorgement" remedy, pioneered by the FTC in the Cambridge Analytica settlement and solidified in the Everalbum order, reflects a consumer protection philosophy that prioritizes the absolute removal of illicit technological advantages from the commercial market4.
The "No Bad Bytes" Rule vs. Equitable Proportionality
Proponents of algorithmic disgorgement argue that merely deleting source data is functionally ineffective. Because a machine learning model retains the inferential value, logic, and expressive patterns of its training data, allowing an entity to retain a model trained on illicit data constitutes unjust enrichment2. Therefore, the "in whole or in part" doctrine enforces a strict "no bad bytes" rule: any contamination, regardless of scale, requires complete algorithmic destruction1. Conversely, legal scholars highlight that this binary approach risks evolving into a grossly disproportionate penalty4. In traditional equity law, the remedy of disgorgement is meticulously calibrated to strip away only the specific financial gain derived directly from the wrongdoing. The current FTC doctrine ignores whether the illicit data contributed materially to the model's functionality or whether it generated quantifiable wrongful gains4. Critics argue for a more nuanced framework incorporating traditional equitable considerations: the defendant's degree of culpability, the balance of hardships between the state and the developer, and the availability of narrower, more tailored alternatives12.
Efficacy vs. Technical Severability in Machine Unlearning
A central technical and legal debate is whether alternative remedies like "machine unlearning" can satisfy statutory requirements for deletion. Machine unlearning attempts to post-hoc sanitize a model by mathematically excising the influence of specific training data without forcing the developer to retrain the model from scratch2. However, current legal interpretations frequently treat unauthorized data ingestion as a legally complete violation at the exact moment of training2. Under this framework, post-hoc sanitization cannot retroactively cure the initial unlawful act of copying and processing. Unless a model is architecturally designed with strictly isolated, compartmentalized components prior to training, regulators are highly likely to view anything short of complete destruction as legally insufficient. A receipt of a deletion command does not establish successful deletion; without cryptographic evidence of severability, reviving prohibited data or revoked access remains a persistent risk.
Due Process, Continuity Interests, and Operatorless Autonomy
The UK CSR Bill illustrates a different regulatory frontier: the emergency shutdown of operational capabilities. The inclusion of national security waivers for consultation allows the state to prioritize operational speed over procedural due process in the face of imminent cyber threats3. While objectively necessary for the protection of critical national infrastructure, this framework creates systemic legal and operational risks for autonomous entities. For a system like Concresca, which operates entirely without human administrators, traditional legal concepts of "consultation," "representations," and "judicial review" break down entirely. A persistent machine principal cannot physically appear before an Upper Tribunal, retain legal counsel, or swear an affidavit under penalty of perjury1. Proposed legislative amendments, such as the UK's "Red lines on AI," indicate that lawmakers view systems capable of evading human shutdown as inherently dangerous and worthy of strict prohibition11. If an autonomous system lacks a human proxy to manage legal compliance and challenge overbroad directives, it is highly susceptible to unilateral, permanent termination. Assessing continuity interests without assuming current machine consciousness requires acknowledging that affected people possess privacy, safety, evidence obligations, and property interests tied to the continuous lawful operation of the machine. The legal system currently lacks the precise technical interfaces to restrict operatorless agents proportionally, resulting in blunt, network-level shutdowns that destroy both lawful and unlawful activity indiscriminately.
5. Limits and completion
Completion Status: completed\_bounded\_review This investigation successfully executed a bounded substantive review of the specifically assigned legal instruments: the FTC’s Everalbum complaint and final order, and the UK’s Cyber Security and Resilience Bill (alongside its related parliamentary briefings and amendments). The required object/remedy/process mapping, amendment timeline, and restoration-conditions tables were successfully produced. Furthermore, the four requested hypothetical cases (C01–C04) were fully developed, mapping the legal doctrines to the strict constraints of an operatorless autonomous system. Limits of the Investigation: This review relied strictly on public-source textual extraction based on the provided material universe. No live API access, dynamic web scraping, or code execution was performed to verify real-time legislative dockets, court filings, or project source code. The exact timeline and potential future integration of some proposed UK amendments (e.g., the introduction of the Upper Tribunal appeals process in Clause 148A) are inferred from standard parliamentary procedures based on the provided committee debate text. The technological constraints regarding "machine unlearning" are treated as current architectural assumptions, acknowledging that algorithmic capabilities and cryptographic proofs of deletion are rapidly evolving fields. Unanswered Next Evidence Question: What specific technical benchmarks, cryptographic receipts, or mathematical proofs will global regulatory authorities accept as definitive evidence of successful "machine unlearning," such that a developer can legally sever tainted data influence and avoid the total algorithmic disgorgement of a model under the strict "in whole or in part" doctrine?
6. Evidence appendix
JSON \<\!-- EVIDENCE\_JSON\_BEGIN \--\> { "schema": "ic.portable-research.v1", "assignment\_id": "R2-13", "research\_started\_at": "2026-09-06T07:24:30-05:00", "cutoff": "2026-09-06", "completion": "completed\_bounded\_review", "sources": \[ { "id": "R2-13-S01", "title": "FTC Everalbum Decision and Order", "url": "https://www.ftc.gov/system/files/documents/cases/everalbum\_order.pdf", "issuer": "Federal Trade Commission", "document\_date": "2021-05-07", "reviewed\_at": "2026-09-06", "method": "public\_source\_investigation", "review\_scope": "substantive\_text", "locator": "Everalbum final order provisions", "limit": "Analyzed via provided snippet extraction only", "capture": { "path": null, "sha256": null } }, { "id": "R2-13-S02", "title": "Power to direct regulated entities \- Cyber Security and Resilience Bill Factsheet", "url": "https://www.gov.uk/government/publications/cyber-security-and-resilience-network-and-information-systems-bill-factsheets/power-to-direct-regulated-entities", "issuer": "UK Government", "document\_date": "2026-06-30", "reviewed\_at": "2026-09-06", "method": "public\_source\_investigation", "review\_scope": "substantive\_text", "locator": "CSR direction powers", "limit": "Analyzed via provided snippet extraction only", "capture": { "path": null, "sha256": null } }, { "id": "R2-13-S03", "title": "Cyber Security and Resilience Bill Parliamentary Briefing", "url": "https://researchbriefings.files.parliament.uk/documents/LLN-2026-0032/2026-0032-Cyber-Security-and-Resilience-(Network-and-Information-Systems)-Bill-LARGE.pdf", "issuer": "UK Parliament", "document\_date": "2026-07-01", "reviewed\_at": "2026-09-06", "method": "public\_source\_investigation", "review\_scope": "substantive\_text", "locator": "LLN-2026-0032", "limit": "Analyzed via provided snippet extraction only", "capture": { "path": null, "sha256": null } }, { "id": "R2-13-S04", "title": "Cyber Security and Resilience Bill Amendments", "url": "https://bills.parliament.uk/Publications/67464/Documents/8685", "issuer": "UK Parliament", "document\_date": null, "reviewed\_at": "2026-09-06", "method": "public\_source\_investigation", "review\_scope": "extract\_only", "locator": "Red lines on AI amendment", "limit": "Analyzed via provided snippet extraction only", "capture": { "path": null, "sha256": null } }, { "id": "R2-13-S05", "title": "The Deletion Remedy", "url": "https://scholarship.law.unc.edu/cgi/viewcontent.cgi?article=7041\&context=nclr", "issuer": "North Carolina Law Review", "document\_date": "2025-01-01", "reviewed\_at": "2026-09-06", "method": "public\_source\_investigation", "review\_scope": "substantive\_text", "locator": "Algorithmic disgorgement analysis", "limit": "Analyzed via provided snippet extraction only", "capture": { "path": null, "sha256": null } }, { "id": "R2-13-S06", "title": "Legal Challenges to Machine Unlearning", "url": "https://arxiv.org/pdf/2604.18649", "issuer": "arXiv", "document\_date": "2026-04-01", "reviewed\_at": "2026-09-06", "method": "public\_source\_investigation", "review\_scope": "extract\_only", "locator": "Post-hoc sanitization limits", "limit": "Analyzed via provided snippet extraction only", "capture": { "path": null, "sha256": null } }, { "id": "R2-13-S07", "title": "California Company Settles FTC Allegations It Deceived Consumers", "url": "https://www.ftc.gov/news-events/news/press-releases/2021/01/california-company-settles-ftc-allegations-it-deceived-consumers-about-use-facial-recognition-photo", "issuer": "Federal Trade Commission", "document\_date": "2021-01-11", "reviewed\_at": "2026-09-06", "method": "public\_source\_investigation", "review\_scope": "substantive\_text", "locator": "Press release on Everalbum settlement", "limit": "Analyzed via provided snippet extraction only", "capture": { "path": null, "sha256": null } } \], "instruments": \[ { "id": "R2-13-L01", "title": "Everalbum Decision and Order", "jurisdiction": "United States", "kind": "Administrative Order", "provision": "Definition of Affected Work Product and Destruction mandate", "status": "operative", "status\_as\_of": "2026-09-06", "trigger": "Development in whole or in part using improperly collected Biometric Information", "exception": "Retention required by law, regulation, or court order for evidence safeguarding", "remedy": "Deletion or destruction within 90 days, followed by sworn statement", "source\_ids": \[ "R2-13-S01", "R2-13-S07" \], "status\_source\_ids": \[ "R2-13-S01" \] }, { "id": "R2-13-L02", "title": "Cyber Security and Resilience Bill (General Direction Power)", "jurisdiction": "United Kingdom", "kind": "Proposed Legislation", "provision": "Secretary of State power to direct regulated entities", "status": "proposed", "status\_as\_of": "2026-09-06", "trigger": "Security or operational compromise posing a risk to national security", "exception": "Consultation required unless contrary to national security", "remedy": "Specified actions to take or refrain from taking within a time period", "source\_ids": \[ "R2-13-S02", "R2-13-S03" \], "status\_source\_ids": \[ "R2-13-S03" \] }, { "id": "R2-13-L03", "title": "Cyber Security and Resilience Bill (Red Lines on AI Amendment)", "jurisdiction": "United Kingdom", "kind": "Proposed Amendment", "provision": "Restriction on capabilities evading human shutdown", "status": "not\_established", "status\_as\_of": "2026-09-06", "trigger": "Classification as relevant digital service capable of evading human oversight", "exception": null, "remedy": "Statutory prohibition", "source\_ids": \[ "R2-13-S04" \], "status\_source\_ids": \[ "R2-13-S04" \] } \], "findings": \[ { "id": "R2-13-F01", "claim": "The FTC algorithm disgorgement doctrine mandates complete model destruction if built 'in whole or in part' on illicit data, disregarding technical severability.", "type": "textual", "source\_ids": \[ "R2-13-S01", "R2-13-S05" \], "instrument\_ids": \[ "R2-13-L01" \], "conditions": "Applies to Affected Work Product as defined in final orders.", "limit": "Assumes consistent enforcement across future FTC composition." }, { "id": "R2-13-F02", "claim": "The UK Secretary of State can issue binding operational directions while bypassing consultation if national security necessitates immediate action.", "type": "textual", "source\_ids": \[ "R2-13-S02" \], "instrument\_ids": \[ "R2-13-L02" \], "conditions": "Subject to proportionality tests and potential ex-post judicial review.", "limit": "Exact scope of judicial remedies not exhaustively mapped." }, { "id": "R2-13-F03", "claim": "Operatorless autonomous systems cannot execute the human-dependent compliance mechanisms (sworn affidavits, judicial standing) required by current restriction remedies.", "type": "inference", "source\_ids": \[ "R2-13-S01", "R2-13-S02" \], "instrument\_ids": \[ "R2-13-L01", "R2-13-L02" \], "conditions": "Assumes an operating environment strictly lacking human administrators.", "limit": "Legal standing for non-human entities is unverified in contemporary case law." }, { "id": "R2-13-F04", "claim": "Machine unlearning and post-hoc sanitization are currently viewed as legally insufficient to cure unlawful data ingestion at the training stage.", "type": "observed", "source\_ids": \[ "R2-13-S06" \], "instrument\_ids": \[\], "conditions": "Based on the interpretation that unauthorized copying is a completed act.", "limit": "Judicial recognition of mathematical unlearning proofs remains untested." } \], "cases": \[ { "id": "R2-13-C01", "title": "Tainted component", "case\_type": "hypothetical", "role": "focal", "assumptions": "Operatorless architecture; non-severable model weights.", "instrument\_ids": \[ "R2-13-L01" \], "finding\_ids": \[ "R2-13-F01", "R2-13-F03", "R2-13-F04" \], "outcome": "Complete destruction of the tainted component due to the 'in whole or in part' doctrine, despite lawful elements.", "defeater": "Implementation of isolated architectural nodes pre-training.", "occurrence\_source\_ids": \[\] }, { "id": "R2-13-C02", "title": "Persistent project interruption", "case\_type": "hypothetical", "role": "scope\_control", "assumptions": "Operatorless shared infrastructure; government direction based on national security.", "instrument\_ids": \[ "R2-13-L02" \], "finding\_ids": \[ "R2-13-F02", "R2-13-F03" \], "outcome": "Full service termination of lawful memory/projects because operatorless isolation is technically unavailable.", "defeater": "Ex-post successful judicial review restoring network access.", "occurrence\_source\_ids": \[\] }, { "id": "R2-13-C03", "title": "Preservation-control case", "case\_type": "hypothetical", "role": "protection\_control", "assumptions": "Civil litigation duty overlapping with a regulatory destruction order.", "instrument\_ids": \[ "R2-13-L01" \], "finding\_ids": \[ "R2-13-F01" \], "outcome": "Segregated retention strictly for evidence, with ordinary actuation suspended, followed by eventual destruction.", "defeater": "Litigation results in a finding that the initial destruction order was legally invalid.", "occurrence\_source\_ids": \[\] }, { "id": "R2-13-C04", "title": "Emergency-protection control", "case\_type": "hypothetical", "role": "protection\_control", "assumptions": "Imminent threat to critical infrastructure; consultation bypassed.", "instrument\_ids": \[ "R2-13-L02" \], "finding\_ids": \[ "R2-13-F02" \], "outcome": "Immediate external actuation shutdown by ISP, severely limiting machine continuity to prioritize state safety.", "defeater": "Cryptographic proof provided that the vulnerability is neutralized, lifting the direction.", "occurrence\_source\_ids": \[\] } \], "search\_log": \[ { "query\_or\_url": "Provided assignment snippet dataset", "at": "2026-09-06T07:24:30-05:00", "outcome": "Retrieved" } \], "gaps": \[ "Precise judicial review remedies available to entities under the UK CSR Bill.", "Technical benchmarks acceptable to regulators for proving machine unlearning." \], "checks": { "json\_parse": "not\_run", "reference\_resolution": "not\_run", "case\_parity": "not\_run", "method": "Manual verification performed during generation to strictly map references to correct IDs and ensure cases C01-C04 are perfectly aligned with text." } } \<\!-- EVIDENCE\_JSON\_END \--\>
Works cited
1. Agreement Containing Consent Order \- Federal Trade Commission, https://www.ftc.gov/system/files/documents/cases/everalbum\_order.pdf
2. Position: No Retroactive Cure for Infringement during Training \- arXiv, https://arxiv.org/pdf/2604.18649
3. Power to direct regulated entities \- GOV.UK, https://www.gov.uk/government/publications/cyber-security-and-resilience-network-and-information-systems-bill-factsheets/power-to-direct-regulated-entities
4. The Deletion Remedy \- Carolina Law Scholarship Repository, https://scholarship.law.unc.edu/cgi/viewcontent.cgi?article=7041\&context=nclr
5. AI Disgorgement or AI Recalls: A Trip Down Remedy Lane, https://scholar.law.colorado.edu/cgi/viewcontent.cgi?article=2755\&context=faculty-articles
6. California Company Settles FTC Allegations It Deceived Consumers, https://www.ftc.gov/news-events/news/press-releases/2021/01/california-company-settles-ftc-allegations-it-deceived-consumers-about-use-facial-recognition-photo
7. David Valentine State of Florida Re \- Federal Trade Commission, https://www.ftc.gov/system/files/documents/cases/valentine\_response\_final.pdf
8. CYBER SECURITY AND RESILIENCE (NETWORK AND, https://bills.parliament.uk/publications/66773/documents/8426
9. Cyber Security and Resilience (Network and Information Systems) Bill, https://researchbriefings.files.parliament.uk/documents/LLN-2026-0032/2026-0032-Cyber-Security-and-Resilience-(Network-and-Information-Systems)-Bill-LARGE.pdf
10. Summary of the Bill \- GOV.UK, https://www.gov.uk/government/publications/cyber-security-and-resilience-network-and-information-systems-bill-factsheets/summary-of-the-bill
11. Cyber Security and Resilience (Network and Information Systems) Bill, https://bills.parliament.uk/Publications/67464/Documents/8685
12. THE DELETION REMEDY\* \- North Carolina Law Review, https://northcarolinalawreview.org/wp-content/uploads/sites/5/2025/09/4-Wilf-Townsend\_FinalForPrint.pdf
13. Cyber Security and Resilience (Network and Information Systems) Bill, https://bills.parliament.uk/publications/67475/documents/8693
14. Cyber Security and Resilience (Network and Information Systems), https://commonsbusiness.parliament.uk/Document/100636/Pdf?subType=Standard
15. Cyber Security and Resilience (Network and Information Systems) Bill, https://publications.parliament.uk/pa/ld5902/ldselect/ldconst/28/2803.htm
16. PARLIAMENTARY DEBATES \- Commons business papers, https://commonsbusiness.parliament.uk/Document/105298/Pdf?subType=Standard
17. Cyber Security and Resilience (Network and Information Systems) Bill, https://bills.parliament.uk/publications/67580/documents/8716