The Privacy Advisor · Jedidiah Bracy, IAPP Editorial Director

On privacy and machine unlearinng: A discussion with Jevan Hutson

March 10, 2026·40 min·3 clips
The act of machine unlearning can itself expose whether someone's data was in the original training set — a perverse privacy backfire.
The problem starts before anyone asks for deletion. Large language models rely on massive data flows, and the host sets that reality against privacy-law duties around purpose limitation, minimization, access, and erasure. Machine unlearning comes in as a possible fix for information that was used in training and later becomes subject to deletion obligations. The guest describes it as a set of techniques, not magic. Once data has helped shape a broad AI model, real purpose limitation gets shaky because the model's value comes from mixing inputs and generalizing from them in ways that are hard to trace. Black-box behavior makes the problem worse. Removing a dataset does not guarantee that every pattern or influence tied to that source disappears. The governance answer is partly about planning ahead. The guest separates reactive cleanup from development pipelines built with unlearning in mind from the start. Erasure rights stay at the center. The paper's right-to-be-forgotten framing is where unlearning has the clearest role and where privacy compliance gets most practical. Counsel are already running into it. The guest says these questions come up for both outside counsel and inside counsel when users want information deleted after it has trained AI systems. The episode does not sell easy confidence. Unlearning can belong in the practitioner and regulator toolkit, but it cannot make up for weak early choices about purpose limits and minimization. Regulators matter here. The closing point is that privacy law can survive the AI era only if regulators understand the technical methods well enough to set expectations people can actually follow. A consent order is expected. The guest predicts machine unlearning will appear in a regulatory consent order within four years, as a serious privacy-enforcement move rather than a technical curiosity.

As heard by us

A clear privacy-law discussion of what machine unlearning can help erase, and what AI teams still have to design for upfront.

Machine unlearning gets treated here as a practical privacy problem, not a magic fix. Jevan Hutson explains why AI models strain familiar rules around purpose limitation, data minimization, erasure rights, and access requests: once training data has been mixed into a broad…

Read the full review in PlayNext →

Why you'd press play

If you want the privacy-law response to AI training data, start here.

Read the full recommendation in PlayNext →
Listen to the show on