These are here because they shape the field, not because they are evidence about a deletion. A patent claims a method. A specification defines a format. Neither states a result, so the ladder's first question does not apply to them and giving them a rung would say something false in both directions.
Adobe Inc
Patentread 2026-08-09
source unchanged 2026-08-23US 12,475,368 B2, machine unlearning and retraining on a modified dataset
Granted 18 November 2025. Computes the gradient change when dataset elements are removed or added, tests that change against a stochastic condition, and retrains only when the condition fails. A method patent about doing the removal, not about proving it happened.
A patent claims ownership of a method. It states no result about any deletion, so the ladder's first question does not apply and the rung shown is a floor rather than a reading. It is listed here for freedom to operate, not as evidence.
Verifiable by Patent office record onlynot scored by the ladderpatents.google.com C2PA, Content Authenticity Initiative
Open benchmarkread 2026-08-09
source unchanged 2026-08-23Content Credentials, cryptographically signed media provenance
An open specification for binding signed, tamper evident provenance to a media file so a viewer can check how it was made and what edited it. The relevant lesson for erasure evidence is structural: the claim travels with the artifact rather than living in a vendor portal, which is the same reason an evidence pack should be a file and not a database lookup.
A specification defines a format. It states no result about any deletion or any system, so the ladder's first question does not apply. It is listed here for the structural lesson that a claim should travel with the artifact rather than live in a vendor portal.
Verifiable by Anyone with a Content Credentials verifiernot scored by the ladderc2pa.org CNIL, EDPB, ICO
Regulationread 2026-08-12
source changed 2026-08-23, not re-readPositions on effective erasure in AI systems
None of the three requires full retraining on every erasure request. CNIL's own how to sheet recommends filtering the outputs of the system to answer rectification, objection and erasure requests where the controller demonstrates that the measure is sufficiently effective and robust, and it prefers general rules that prevent generating personal data over a blacklist of the people who exercised their rights. Suppression based approaches are therefore legitimate in Europe, which is the regulatory ground this entire category stands on. Verified against the CNIL sheet on 12 August 2026, replacing a source that pointed only at the CNIL home page.
Regulator positions state what would satisfy the law, not that anything was deleted. The ladder's first question does not apply. This entry is listed because it is the ground that makes suppression based approaches legitimate in Europe, not because it is evidence about a deletion.
Verifiable by Anyone, the positions are publishednot scored by the ladderwww.cnil.fr Coinbase Inc
Patentread 2026-08-09
source unchanged 2026-08-23US 12,456,052 B2, verifiability of machine learning model unlearning
Granted 28 October 2025. The independent claims cover running unlearning across multiple stages, generating a cryptographic value for the model instance at each stage, and storing those values so the process can later be verified. Zero knowledge techniques appear in the specification rather than as the only claimed mechanism. This is the closest granted claim to the proof side of this market, and it is held by a company that does not sell unlearning.
A patent claims ownership of a method. It states no result about any deletion, so the ladder's first question does not apply and the rung shown is a floor rather than a reading. It is listed here for freedom to operate, not as evidence.
Verifiable by Patent office record onlynot scored by the ladderpatents.google.com European Commission, AI Office
Regulationread 2026-08-09
source unchanged 2026-08-23GPAI Code of Practice and Model Documentation Form
Final version published 10 July 2025, covering transparency, copyright, and safety and security. Its transparency core is a standard Model Documentation Form with tiered disclosure, so different facts go to the AI Office, to national authorities, and to downstream providers. The template is public; the completed forms largely are not, which is the same shape as the trust center problem.
A code of practice states commitments, not results. The ladder's first question does not apply, so this entry is listed as regulatory context rather than scored as evidence.
Verifiable by Anyone can read the template, few filled forms are publicnot scored by the ladderartificialintelligenceact.eu European Commission, AI Office
Regulationread 2026-08-12
source unchanged 2026-08-23Public template for summarising GPAI training data
Final template published 24 July 2025. Providers must give an overview of training data including sources, large datasets and top domain names, and the Commission page states the template requests this so that parties with legitimate interests can exercise their rights under EU law. This is the first regulation anywhere that makes a training data disclosure a routine published artifact rather than something extracted through litigation.
A mandated template defines what must be disclosed. It reports no result about any deletion, so the ladder's first question does not apply and this entry is listed as regulatory context.
Verifiable by Anyone, once a provider publishes its summarynot scored by the ladderdigital-strategy.ec.europa.eu Hirundo
Unlearning vendorread 2026-08-09
source unchanged 2026-08-23Google DeepMind case study placement
A named third party association carries real signal about commercial traction and is the strongest asset on their site. It reports nothing about unlearning efficacy, which is a separate question from customer quality.
A customer logo is a commercial signal, not a result. Their own entry says it reports nothing about unlearning efficacy, and the ladder scores results, so this one is listed rather than scored. It stays in the registry because commercial traction is real information and hiding it would make this list less honest, not more.
Verifiable by Nobody, but the counterparty is namednot scored by the ladderwww.hirundo.io IBM
Patentread 2026-08-12
source unchanged 2026-08-23US 2025/0190815, automated guidance for machine unlearning
An application rather than a grant, filed December 2023, published June 2025 and still listed as pending. It covers running an unlearning algorithm, generating metrics that compare the unlearned model against the original on accuracy, privacy and fairness, recommending an action when a metric crosses a threshold, and evaluating adversarially whether the influence was actually removed. That last element sits closer to independent audit work than the other patents recorded here, which is the reason this entry was pulled from a home page link to the document itself on 12 August 2026.
A patent claims ownership of a method. It states no result about any deletion, so the ladder's first question does not apply and the rung shown is a floor rather than a reading. It is listed here for freedom to operate, not as evidence.
Verifiable by Patent office record onlynot scored by the ladderpatents.google.com KVKK, Turkey
Regulationread 2026-08-12
source changed 2026-08-22, not re-readGuidance publication 113, November 2025
Publication 113, dated November 2025, reads the data subject rights in article 11 of Law 6698 across the whole system rather than the source database alone. Its own sentence puts training data, the data used in fine tuning processes, the information appearing in model outputs and the content included in user queries all inside that scope. The erasure right therefore reaches the model, while the guidance names no mechanism for proving that the erasure happened, and the term unlearning does not occur anywhere in the document. Turkey has the duty without a named method, and unlike CNIL there is no technical impossibility exemption. The full text was read on 12 August 2026, replacing a source that pointed only at the regulator's home page.
A guidance publication states an obligation, not a result. It tells controllers what erasure must achieve; it does not report that any deletion happened or how anyone checked it. The ladder's first question does not apply, so this entry is listed as the regulatory ground this market stands on rather than scored as evidence.
Verifiable by Anyone, the guidance is publishednot scored by the ladderwww.kvkk.gov.tr Lemon Inc, ByteDance
Patentread 2026-08-09
source unchanged 2026-08-23US 12,591,750 B2, generative language model unlearning
Granted 31 March 2026, the most recent grant in this set. The claim takes paired sets of undesirable and desirable behaviours and applies iterative parameter updates that suppress the unwanted output while holding performance on benign input. That is behavioural suppression, which is the approach most vendors in this registry actually ship.
A patent claims ownership of a method. It states no result about any deletion, so the ladder's first question does not apply and the rung shown is a floor rather than a reading. It is listed here for freedom to operate, not as evidence.
Verifiable by Patent office record onlynot scored by the ladderpatents.google.com SLSA and Sigstore
Open benchmarkread 2026-08-09
source unchanged 2026-08-23Build provenance attestations for software artifacts
Not an AI artifact, included because it is the mature version of what this market is groping toward. Software supply chain security already settled on signed, machine readable provenance anchored in a public transparency log, so a consumer can check where a binary came from without trusting the publisher. AI erasure evidence is roughly where software provenance was before this existed.
A specification defines a format. It states no result about any deletion or any system, so the ladder's first question does not apply. It is listed here because software supply chain security already solved the problem this market is still groping toward, not as evidence about forgetting.
Verifiable by Anyone, with public transparency logsnot scored by the ladderslsa.dev Vijil
Governance vendorread 2026-08-12
source changed 2026-08-23, not re-readThirteen published detection models for safety and injection
Publishing the instrument is a legitimate proof route even when customer results stay private: a reader can inspect what is actually being measured. Thirteen models are downloadable, and the download counts are themselves a signal of real use rather than shelfware, with prompt injection detection at roughly 10,700 and toxic content at 1,800 pulls in the trailing month, measured 20 August 2026 via the HuggingFace API; these are rolling 30 day counters and move week to week. No datasets are published, so the models can be run but the evaluations behind them cannot be reproduced.
Thirteen downloadable detection models are an instrument, not a result. Publishing the instrument is a real contribution and a reader can inspect exactly what is being measured, but the entry states no outcome for any deletion, and their own customer results stay private. The ladder scores results, so this one is listed rather than scored.
Verifiable by Anyone who downloads and runs a modelnot scored by the ladderhuggingface.co