Skip to content

Demo site. Fictional data; nothing is sent to anyone. Open the guided demo

AI training data and your images

Short answer

Photos posted publicly can be collected into datasets and used to train AI systems without the people in them being asked. You can ask dataset maintainers to take down entries, tell platforms not to use your content for training, and send objection or deletion requests to AI companies where the law allows. None of this changes a model that has already been trained. No service can remove a person from a trained model.

Published
Last reviewed

General information, not legal advice. This page has not yet been reviewed by a lawyer; check the linked primary sources before relying on it.

Key takeaways

  • Public datasets such as LAION's are lists of links to images on the web, with the text found beside them.
  • Platform opt-outs work going forward. They do not affect training that has already taken place.
  • No one can take a person out of an already-trained model on request.

What is the problem?

AI systems that generate or recognise images learn from very large collections of pictures gathered from the public web. LAION, a nonprofit whose datasets have been used to train AI tools, describes them as indexes to the internet: lists of URLs to the original images together with the alt text found with them.

In June 2024 Human Rights Watch reported finding 170 photos of Brazilian children in the LAION-5B dataset, some with names and locations attached. LAION confirmed the photos were there and pledged to remove them.

Removing a dataset entry does not change a model trained before the removal. A 2024 paper by machine learning, law and policy researchers concludes that machine unlearning is not a general-purpose solution for limiting what a generative model does.

How does it happen?

Automated crawlers collect pages that anyone can reach. Dataset builders publish the image links, and model developers download the images to train on. Platforms may also train on what their own members post. LinkedIn, for example, says it may use member content to train generative AI models where the law and the member's settings allow.

Copies spread. LAION says it removes verified entries from the data repositories it controls, but cannot act on past releases that circulate elsewhere.

What laws may apply?

  • EU. Article 21 of the GDPR gives a right to object to processing that relies on legitimate interests. In Opinion 28/2024, adopted on 18 December 2024, the European Data Protection Board said that whether an AI model is anonymous must be assessed case by case, and that unlawful processing during development could affect whether a model may lawfully be deployed.
  • California. The CCPA lets residents ask a business to delete personal information it collected from them, subject to exceptions. How this applies to training data depends on the company and the facts.
  • The limit. These rights concern the data a company holds and what it does next, not a model that is already trained.

What you can do yourself

These steps are free and do not need UltoPulto.

  1. Check the AI and data settings on each platform you use. On LinkedIn the setting is called Data for Generative AI Improvement.
  2. If a LAION dataset entry links to your image, use the takedown form described in LAION's FAQ.
  3. Write to the AI company: an objection under Article 21 if you live in the EU, or a CCPA deletion request if you live in California.
  4. Reduce public copies. Delete old public posts, set profiles to private, and ask sites that host your photo to remove it.
  5. Keep each request, its date and the reply.

What UltoPulto can do

  • The Exposure Scan checks AI dataset indexes as one of its sources.Built
  • AI dataset index matching against an index built from public dataset URL lists. The index is being built and reviewed.In rollout
  • Access, deletion and objection requests to AI model providers, by email or as guided portal steps with the letter prepared.Built
  • Takedown requests to dataset hosts.Built
  • Real delivery of requests. A request is sent only to a contact our team has verified; until then it stays a draft.In rollout
  • An evidence trail on every case, with the request, replies, deadline and status history.Built
  • A follow-up after the legal deadline, then a regulator complaint draft for you to review and sign.Built

What UltoPulto cannot do

  • Remove you from an AI model that has already been trained. No service can.
  • Confirm whether a specific model was trained on your images.
  • Reach copies of a dataset that other people downloaded before an entry was taken down.
  • Make an AI company agree. A request can be refused, and we record it as refused.

Sources

  1. 1FAQLAIONNon-profitOpened 2026-10-04
  2. 2Brazil: Children's Personal Photos Misused to Power AI ToolsHuman Rights WatchNon-profitOpened 2026-10-04
  3. 3Machine Unlearning Doesn't Do What You Think: Lessons for Generative AI Policy and ResearchA. Feder Cooper and co-authors, arXiv:2412.06966AcademicOpened 2026-10-04
  4. 4EDPB opinion on AI models: GDPR principles support responsible AIEuropean Data Protection BoardGovernmentOpened 2026-10-04
  5. 5Art. 21 GDPR: Right to objectGDPR text, gdpr-info.euLawOpened 2026-10-04
  6. 6California Consumer Privacy Act (CCPA)California Office of the Attorney GeneralGovernmentOpened 2026-10-04
  7. 7LinkedIn and generative AI (GAI) FAQsLinkedIn HelpCompany documentationOpened 2026-10-04

Questions

Can my photos be removed from an AI model that has already been trained?

No. There is no dependable way to take one person out of a trained model on request, and no service can do it. What can change is the data a company or dataset still holds and what is used in future; see our guide.

How do I know whether my images were used to train a model?

Usually you cannot confirm it for a specific model. What can be checked is whether a link to your image appears in a public dataset such as LAION's, which are published as lists of URLs.

Does opting out on a platform undo past training?

No. LinkedIn, for example, states that opting out stops future use of your data for generative AI training but does not affect training that has already taken place.

Does the GDPR apply to AI models?

It can. The European Data Protection Board's Opinion 28/2024 says whether a model is anonymous must be assessed case by case.