Direct answer · GDPR
Is a trained AI model anonymous?
Not automatically. According to the EDPB (Opinion 28/2024), whether an AI model trained on personal data is anonymous must be assessed case by case. The likelihood of extracting personal data from the model, and of obtaining them through queries to the model, must be insignificant, taking into account all the means reasonably likely to be used. If the model is not anonymous, the GDPR continues to apply to the model itself.
For you to establish
- Has it been tested whether training data can be extracted from the model (for example with attacks on the model)?
Articles
- Art. 4(1) GDPR Definition of personal data.
Guidelines and decisions
- Guidelines 02/2026 on Anonymisation (EDPB, v1.0, 2026-07-07)Guidelines 02/2026 on anonymisation.
- Opinion 28/2024 on certain data protection aspects related to the processing of personal data in the context of AI models (European Data Protection Board (EDPB), Opinion 28/2024 (artikel 64 lid 2 AVG), 2024-12-17)Anonymity case by case; the likelihood of extraction and of obtaining data through queries must be insignificant.
