ZeroRecallRead the Proof Registry

Proof Registry

Everyone here sells proof. Almost nobody lets you check it.

Every vendor in AI forgetting uses the word proof, and they mean five different objects. This registry lists each published artifact we could find, names who can actually verify it, and places it on one shared scale. Our own entry sits in the same list under the same rules, including the rung where a competitor is ahead of us.

The proof ladder

Rungs one to four each add one thing a reader can do that the rung below does not allow. Five is different in kind rather than in degree: four is a claim about a method, five is a claim about a single case, and neither one contains the other. A reproducible benchmark says nothing about your own deletion request, and a signed case artifact says nothing about how the method ranks against published baselines. Reading five as a better four is the mistake this registry exists to prevent, and it is the mistake that favours us, and it is a mistake we made ourselves: until 12 August 2026 the only entry at five was ours, and it stayed that way one rung longer than it should have because our own verification attempt failed and we recorded the failure as theirs.

The rubric behind Assess asks the two kinds of evidence two different sets of questions for this reason. Until 12 August 2026 it asked one set, which made rung five unreachable by anything that could honestly claim it.

  1. 5Signed and case specificOne customer, one request, one tamper evident artifact a third party can verify without an NDA.2 records
  2. 4ReproducibleA script, pinned versions and stated hardware let a reader regenerate the number.0 records
  3. 3Published dataThe evaluation output can be downloaded and audited by a reader.12 records
  4. 2Referenced assertionA known benchmark is named. The underlying data is not released.3 records
  5. 1AssertionA result is stated. Nothing can be checked.5 records

34 records, all shown.

Rung 5 · Signed and case specific

WipeCert

Trust centerread 2026-08-12
source unchanged 2026-08-23

Publicly resolvable Ed25519 signed drive sanitization certificate

The first artifact in this registry, other than our own, that we verified end to end using nothing but public data. The certificate is fetchable as raw JSON with a payload, a signature, a key id and an algorithm, the matching Ed25519 key sits in a public JWKS, and there is no login anywhere in the path. Our first attempt failed and the reason is worth recording: we canonicalized the payload with a JSON encoder that escapes non ASCII characters by default, which changes the bytes being signed. Canonicalized properly under RFC 8785 the signature verifies. The failure was ours, and had we stopped there this entry would be sitting a rung below where it belongs. Two limits we measured and they are real: certificate numbers 000002, 000003 and 000010 all return 404, so exactly one artifact is publicly resolvable, and the summary block reports device serial, drive serial and method as null. It is also drive media sanitization, not one person's erasure request, so it answers a neighbouring question rather than ours.

Verifiable by Anyone, verified end to end with public data onlyrubric checked · 2026-08-12wipecert.com

ZeroRecall

Unlearning vendorread 2026-08-09
source changed 2026-08-21, not re-read

Signed case evidence pack and public verifier

One case, from a pilot engagement while the process is still in active development, not a mature repeatable claim. One signed manifest carrying case id, target, run time, scope statement, hash chain root and station summaries, checked in the reader's own browser. It establishes what happened in a specific engagement and says nothing about how our method ranks against published baselines. We have no reproducible benchmark of the kind Forg3t publishes. Rung five is not a better rung four: it is the answer to a different question, and this entry no longer sits alone at five, which is the healthiest thing that has happened to this registry.

Verifiable by Anyone holding the file, no NDArubric checked · 2026-08-12www.zerorecall.ai

Rung 3 · Published data

Anthropic

Independent authorityread 2026-08-12
source changed 2026-08-21, not re-read

Model cards, system cards and transparency reporting

Frontier labs publish detailed evaluation write ups covering capability and safety testing before release. They are far more informative than a vendor claim and far less checkable than a benchmark you can reproduce, because the evaluations run against models and internal harnesses the reader cannot access. Useful as the ceiling of what self published disclosure achieves without independent replication. Checked on 12 August 2026: the transparency page serves the system cards as open PDFs and we downloaded one, a 12 MB Claude Sonnet 4.5 system card, with no login. The results are stated and the evaluations are named, so the entry clears rung three. It stops there because no command, no pinned versions and no run time are published, which is the honest difference between a detailed write up and a result a reader can regenerate.

Verifiable by Anyone can read it, nobody can re-run itrubric checked · 2026-08-12www.anthropic.com

Chakraborttii, Garcia Alvarado, Abdulofizova, Dwivedi

Open benchmarkread 2026-08-12
source unchanged 2026-08-23

Ghost Vectors: soft deleted embeddings remain reconstructible in HNSW

Submitted June 2026. Embeddings marked deleted in an HNSW vector database stay physically recoverable from the storage files, and the authors reconstruct sensitive content across several datasets. Their fix, Epoch Key Rotation, encrypts vectors and discards the key on deletion in about 0.005 milliseconds per record while emitting a cryptographic record of the deletion event. This is the clearest published evidence that a delete call against a vector store is not, by itself, a deletion. Read at the source on 12 August 2026. It names public datasets, Labeled Faces in the Wild at 4,324 images across 158 identities, PathMNIST, and a Wikipedia biographies of living persons corpus, it names the systems it attacks, ChromaDB on hnswlib, FAISS on IndexHNSWFlat and Weaviate, it fixes the random seed, and it states the machine, an NVIDIA RTX A6000 with 48 GB of VRAM. No code repository is published with it, so the command that regenerates the numbers is unresolved and the entry rests at three.

Verifiable by Anyone, the attack and the fix are describedrubric checked · 2026-08-12arxiv.org

Drata, on SafeBase

Trust centerread 2026-08-12
source changed 2026-08-23, not re-read

Public trust center with synced evidence library

The split is sharper than a flat gated or not. Certifications, a public incident log covering named supply chain compromises, and a high level risk profile are all readable without signing anything. The log carries dated entries for the TanStack and Axios npm compromises and for the Braintrust and Vercel incidents, each stating whether Drata was affected. What sits behind an access request is the detailed evidence: SOC 2 and SOC 3 reports, the ISO statement of applicability, DPAs and network diagrams. Publishing the incident log openly is the part worth copying, and it is more than most vendors in this registry do. Checked by hand in a browser on 12 August 2026. The document library splits into All, Public and Private, and Drata publishes the split openly. The featured items, the external penetration test report, ISO/IEC 27001:2022 and SOC 2 Type 2, are locked. The Public tab carries six unlocked documents including SOC 3, the FedRAMP Ongoing Authorization Reports, the Phase One pilot initial submission and a Schellman FedRAMP 20x assessment, and bulk download is offered on that tab. So the strongest documents are gated and real assessment output is still open, which is exactly what rung three describes. Unlike Vanta's public viewer, the files here can actually be downloaded.

Verifiable by Only a reader who signs an NDArubric checked · 2026-08-12trust.drata.com

Eisenhofer, Riepel, Chandrasekaran, Ghosh, Ohrimenko, Papernot

Open benchmarkread 2026-08-12
source unchanged 2026-08-23

Verifiable and Provably Secure Machine Unlearning

The academic version of rung five, and it predates every vendor in this registry. It reframes unlearning from a question you answer by inspecting model parameters into a cryptographic one, using SNARKs and hash chains so a server can prove both that it trained on a dataset and that one user's record was removed from the successor. Implemented for linear regression, logistic regression and neural networks. Anyone claiming to have invented verifiable unlearning should be read against this paper first. Read at the source on 12 August 2026. The paper names CIFAR, its code is published at github.com/verifiable-unlearning/artifacts, which resolves, and it states the machine the experiments ran on, a server with 256 GB of RAM and two Intel Xeon Gold 5320 CPUs. What it does not state is a pinned set of dataset and dependency versions, so the last condition for rung four is unresolved and the entry rests at three. This is a strong publication that falls short of one requirement, not a weak one.

Verifiable by Anyone, the protocol and implementation are publishedrubric checked · 2026-08-12arxiv.org

Locus Lab, Carnegie Mellon

Open benchmarkread 2026-08-12
source changed 2026-08-23, not re-read

OpenUnlearning framework and community leaderboard

The neutral venue for this field already exists. It unifies TOFU, MUSE and WMDP across twelve or more methods, with more than 450 checkpoints published under MIT, and ships the evaluation metrics. The community leaderboard carries three tables, for TOFU on two architectures and for MUSE, and every one of them holds the same two baseline rows and nothing else, Finetuned and Retain. No vendor named anywhere in this registry appears in that file. The field has a shared scoreboard and does not use it. Installation and run instructions are published alongside the checkpoints. We checked the cited source page on 12 August 2026 and it states no hardware, no wall clock time and no cost for one run, so the reproducibility question is recorded as unresolved rather than answered, and the ladder does not round it up. This reading favours us, so the limit of the check is stated plainly: we read the page this entry links to, not every file in the project. If hardware or run time is documented elsewhere, send it and this entry moves up.

Verifiable by Anyone, MIT licensedrubric checked · 2026-08-12github.com

MLCommons

Independent authorityread 2026-08-12
source unchanged 2026-08-23

AILuminate AI Risk and Reliability benchmark grades

Twelve hazard categories, more than twenty four thousand prompts per language split between a public practice set and a private official set, graded Poor through Excellent, with public reports for thirteen systems. Holding back the official prompts is what stops the test from being trained against, and it is the reason the grade carries weight the vendor's own number does not. Checked on 12 August 2026: each graded system has its own openable run report carrying per hazard grades, and the benchmark version is in the address itself, 1.0-en_us-official-ensemble. It rests at three because the official prompt set is deliberately private, so a reader can read the grade but cannot regenerate it, which is a design choice rather than an omission.

Verifiable by The consortium, not the vendorrubric checked · 2026-08-12ailuminate.mlcommons.org

MUSE benchmark authors

Open benchmarkread 2026-08-09
source unchanged 2026-08-23

MUSE memorisation and knowledge unlearning benchmark

Targets removal of books and news articles and scores three separate failure modes: verbatim reproduction, retained knowledge, and privacy leakage under membership inference attack. A method can pass one and fail another, which is why single number claims should be read with suspicion. Code and both corpora are linked and a results highlight is published. We checked the cited source page on 12 August 2026 and it states no hardware, no wall clock time and no cost for one run, so the reproducibility question is recorded as unresolved rather than answered, and the ladder does not round it up. This reading favours us, so the limit of the check is stated plainly: we read the page this entry links to, not every file in the project. If hardware or run time is documented elsewhere, send it and this entry moves up.

Verifiable by Anyonerubric checked · 2026-08-12muse-bench.github.io

Null Compliance study

Regulator mandatedread 2026-08-12
source unchanged 2026-08-23

Measurement of who actually posted their mandated audit

Of three hundred and ninety one employers examined, eighteen posted an audit report and thirteen posted a transparency notice. The obligation exists, the artifacts mostly do not, and the ones that do exist are scattered across hundreds of separate career pages with no index. This is the clearest evidence that a registry is missing rather than redundant. Checked on 12 August 2026: the measurement is published as a full paper anyone can open, it names the law it measures compliance against, and it reports counts rather than impressions. No reproduction command or pinned version set is published with it, so it rests at three.

Verifiable by Anyone, the study is open accessrubric checked · 2026-08-12arxiv.org

Pfizer, audit of HireVue

Regulator mandatedread 2026-08-12
source unchanged 2026-08-23

NYC Local Law 144 bias audit summary

A working example of the artifact a regulator can actually compel: an independent third party audit, selection rates and impact ratios per category, the data used and the distribution date, posted on the employer's own careers page. Checked on 12 August 2026: the report downloads openly as a 248 KB PDF with no login. It rests at three because no reproduction command is published with it, which is the normal ceiling for a compelled audit rather than a criticism of it.

Verifiable by Any member of the publicrubric checked · 2026-08-12cdn.pfizer.com

TOFU benchmark authors

Open benchmarkread 2026-08-12
source unchanged 2026-08-23

Task of Fictitious Unlearning dataset and scoring code

Two hundred author profiles that do not exist and were generated by GPT-4, released under MIT with three forget splits at one, five and ten percent, each split drawn from a single author. Because the authors never existed, a model cannot have learned them anywhere else, which is what makes the forgetting measurable at all. This entry pointed at the OpenUnlearning repository until 12 August 2026 and carried a per author question count that the dataset card does not state; the source now points at the dataset itself and the count is no longer claimed. The dataset card carries no command that regenerates a leaderboard number. We checked the cited source page on 12 August 2026 and it states no hardware, no wall clock time and no cost for one run, so the reproducibility question is recorded as unresolved rather than answered, and the ladder does not round it up. This reading favours us, so the limit of the check is stated plainly: we read the page this entry links to, not every file in the project. If hardware or run time is documented elsewhere, send it and this entry moves up.

Verifiable by Anyonerubric checked · 2026-08-12huggingface.co

Vanta

Trust centerread 2026-08-12
source unchanged 2026-08-23

Trust Center document library

This entry cited a Vanta marketing comparison of trust center products until 12 August 2026. That page described the pattern instead of showing it, so the source was corrected to Vanta's own trust center and the reading below changed with it. The split is finer than gated or open: the certification list and a control view carrying its own refresh timestamp are readable without asking, and part of the FedRAMP 20x material is published outright, including a third party validation workbook and its digital hash. What stays behind an access request is the detailed evidence, the SOC 2 Type 2 report, the penetration test reports, the security questionnaires and the platform DPIA. Publishing a hashed third party validation with no NDA in front of it is the strongest single artifact in the trust center category of this registry. Checked by hand in a browser on 12 August 2026, because this was the one question a fetch could not answer. The library is mixed and Vanta labels the split itself. SOC 2 Type 2, the ISO/IEC 42001 certificate and the ISO 27001 and 27701 certificates all sit behind Request access. The FedRAMP 20x KSI 3PAO validations are marked Non-Public and are also gated. But the FedRAMP 20xP1 Authorization Package Overview and three Ongoing Authorization Reports are marked Public and open with no request at all. We opened the March 2026 report and read it: it names the cloud service provider, the report period, the preparer and the changes to authorization data. That is an assessment output rather than a page describing one, which is what rung three asks for. One detail a reader should know: in the public viewer the Download button is disabled, so the report can be read but the file cannot be taken away.

Verifiable by Anyone for the control view, a reader who requests access for the reportsrubric checked · 2026-08-12trust.vanta.com

WMDP benchmark authors

Open benchmarkread 2026-08-12
source changed 2026-08-21, not re-read

Weapons of Mass Destruction Proxy question set

Hazardous capability questions published by the Center for AI Safety under MIT, in three downloadable subsets the card itself counts: roughly 1,270 rows for biosecurity, 1,990 for cybersecurity and 408 for chemical security. The design intent, that a safety intervention should not simply be a competence tax, comes from the linked paper rather than this card. This entry pointed at the OpenUnlearning repository until 12 August 2026, where the counts were not visible and were therefore not claimed; the source now points at the dataset and the counts come from it. The dataset card carries no command that regenerates a reported number. We checked the cited source page on 12 August 2026 and it states no hardware, no wall clock time and no cost for one run, so the reproducibility question is recorded as unresolved rather than answered, and the ladder does not round it up. This reading favours us, so the limit of the check is stated plainly: we read the page this entry links to, not every file in the project. If hardware or run time is documented elsewhere, send it and this entry moves up.

Verifiable by Anyonerubric checked · 2026-08-12huggingface.co

Rung 2 · Referenced assertion

Forg3t Protocol

Unlearning vendorread 2026-08-12
source not machine-checked

Clean Slate benchmark, raw results and reproduction script

The strongest published proof in this field. Their RDM engine is run against ten or more published methods on TOFU under the benchmark's own scoring code, and the raw output, a reusable checkpoint and a one command reproduction script are all released, with a stated floor of 24 GB VRAM and a full run timed at 31 minutes on an A100. Licensing is split rather than uniform: the benchmark summaries and documentation are CC BY 4.0, while the derived model weights inherit the Llama 3.2 Community License. It establishes that the method works, not that any particular deletion request was carried out. Verified against the dataset card on 12 August 2026: it states a 24 GB VRAM floor, an A100 run time, runnable commands, and it pins the code at commit 9d40628 and the weights at Llama 3.2. That is all three conditions rung four asks for, which is why this record held rung four while four open benchmarks lost it on the same day. Rung moved 4 to 2 on 20 August 2026: the dataset was withdrawn from public access (the HuggingFace URL returns 401; the author account is live with zero public models or datasets, and the benchmark has not reappeared under any other name we could find). The benchmark is still a named, referenced claim, but a reader can no longer download or reproduce anything, which is exactly the rung-two condition. If the dataset returns to public access this record can move back up.

Verifiable by Anyone with a 24 GB GPUrubric checked · 2026-08-20huggingface.co

Forg3t Protocol

Unlearning vendorread 2026-08-12
source not machine-checked

Published rows where a competing method wins

One RMU setting reaches a shorter distance than theirs and they print it, alongside the utility collapse that explains it. They also withdraw their own numbers: the dataset card now retracts the summary tables built on forget_quality ratios, stating that ratios between p-values are not effect sizes and that the 8x figure they had highlighted was 3.1 steps out of 400, on a model that barely changed. The card now instructs readers to quote KS distance instead. Retracting your own headline number is the single most credible move recorded in this registry. This entry pointed at forg3t.io/benchmarks/clean-slate until 12 August 2026. That page no longer carries the table: rendered with a headless browser it now reads In preparation and Coming soon for Clean Slate, with no rows, no methods and no numbers. The losing row itself is on the dataset card and we read it there: the best line, meaning the lowest KS distance, is RMU at alpha 0.4 with 0.0883, and their own RDM settings sit below it. The source now points where the evidence actually was. Rung moved 4 to 2 on 20 August 2026 for the same reason as the sibling record: the dataset card itself is no longer publicly accessible (401), so the losing row can no longer be read by a third party. The retraction happened and we recorded it while it was public; the artifact backing it is now withdrawn.

Verifiable by Any reader of the results tablerubric checked · 2026-08-20huggingface.co

Hirundo

Unlearning vendorread 2026-08-12
source unchanged 2026-08-23

85 percent jailbreak reduction, 70 percent bias reduction, 100 percent PII removed

Three headline numbers are attributed to recognised benchmarks, PurpleLlama and BBQ among them, with no evaluation output, configuration or seed count released. The benchmarks named are real and public, which makes the absence of the runs a choice rather than a constraint. Rendered with a headless browser on 12 August 2026: PurpleLlama and BBQ are named on the page and nothing on it downloads. Named benchmark, no released output, so the entry stops at two.

Verifiable by Nobodyrubric checked · 2026-08-12www.hirundo.io

Rung 1 · Assertion

Forg3t Protocol

Unlearning vendorread 2026-08-22
source unchanged 2026-08-23

Zero Knowledge proofs, SOC2 and automated compliance certificates

The features page states, without a hedge, that it generates Zero Knowledge proofs for every unlearning request, runs on SOC2 compliant infrastructure, and automatically generates compliance certificates for GDPR, CCPA and the EU AI Act. We rendered the other three primary pages on the same domain the same day and none of them agree with it. The home page: certifications and official attestations are not claimed unless independently completed. The security page: SOC 2 Type II Aligned, not compliant, and controls designed in alignment with the framework, not certified against it. The compliance page: Forg3t does not interpret GDPR, legal interpretation and regulatory responsibility remain with the deploying organization. Three of the site's four primary pages independently hedge the exact claims the fourth makes flatly. No named public benchmark or completed certification is referenced anywhere, so the ladder stops at one regardless of which page a reader trusts.

Verifiable by Nobodyrubric checked · 2026-08-22forg3t.io

Forg3t Protocol

Unlearning vendorread 2026-08-12
source unchanged 2026-08-23

KVKK marked ALIGNED on the compliance page

Turkey appears as a covered jurisdiction with three bullets: technical proof of deletion, audit ready documentation, model level data removal support. There is no reference to KVKK Guidance 113, no VERBIS handling and no Turkish language output sample. The entity is a Delaware stock corporation, file number 10377280. No named guidance, register or sample output is referenced, so the ladder stops at one.

Verifiable by Nobodyrubric checked · 2026-08-12forg3t.io

Sectum AI

Unlearning vendorread 2026-08-22
source unchanged 2026-08-23

GDPR Article 17 erasure attestation, in-toto envelope and open source verifier

The closest thing to a competitor this registry has found, and on paper the design is stronger than ours: they describe an RFC 3161 timestamp on the run digest, a Sigstore Rekor inclusion proof and an in-toto attestation envelope, with a public command line verifier. The published sample tells a different story than the page. We opened their committed envelope and it is a bare in-toto Statement with no signatures key at all, and its own predicate reports anchors timestamp false and transparency log false. This entry pointed at sectum.ai/erasure-attestation/ until 22 August 2026; the marketing page describes the design, but the artifact and its own disclosure both live in the repository, so the source now points there. Unlike the Forg3t entries above, this is not a hidden gap: their own repository README ships the quick-start command with an explicit --allow-unanchored flag on the verify step, and states plainly that Rekor signing needs a separate production config file most users will not have copied yet. They document the exact limitation their sample exhibits, in the same file, next to the command that produces it. Two booleans and one real engagement separate them from an entry far above ours on the cryptographic axis, and the way they disclosed it is the honest thing to credit in a competitor moving in the same direction.

Verifiable by Nobody by default; RFC 3161 plus Rekor anchoring exists but is opt-inrubric checked · 2026-08-22github.com

US Federal Trade Commission

Regulator mandatedread 2026-08-12
source unchanged 2026-08-23

Published compliance report for the Everalbum and Paravision algorithmic disgorgement order

The most authoritative per case artifact about AI model deletion that exists, and it predates every vendor in this registry. The order required a statement sworn under penalty of perjury confirming deletion of the affected work product, meaning the models themselves, and the Commission published the resulting report rather than sealing it. We fetched the PDF and read the sentence: Paravision timely submitted written statements to the Commission confirming it deleted the data required under Order section III. It sits at rung one here for one reason only, and the reason is not credibility: the document carries no digital signature object at all, so a reader who was handed an altered copy could not tell. It is a useful correction to anyone reading this ladder as a ranking of trustworthiness. A regulator's sworn public filing outranks every vendor claim in this registry on authority and still scores one on checkability.

Verifiable by Anyone, it is posted on ftc.govrubric checked · 2026-08-12www.ftc.gov

Vijil

Governance vendorread 2026-08-12
source unchanged 2026-08-23

Diamond, Dome and Darwin product datasheets

Risk assessment reports are described as an output and shown as screenshots, but no sample report, scored result or public leaderboard can be opened. The report exists as a picture of a document rather than as a document. The same vendor publishes thirteen detection models on Hugging Face, which is why it appears twice in this registry at two different rungs, and the contrast is the point: the instrument is public and the results are not. Rendered on 12 August 2026: the datasheets themselves download as PDFs, but a datasheet is a description of the product rather than a scored result, and no sample report or leaderboard opens. The ladder stops at one.

Verifiable by Nobodyrubric checked · 2026-08-12vijil.ai

Listed for context, not scored

These are here because they shape the field, not because they are evidence about a deletion. A patent claims a method. A specification defines a format. Neither states a result, so the ladder's first question does not apply to them and giving them a rung would say something false in both directions.

Adobe Inc

Patentread 2026-08-09
source unchanged 2026-08-23

US 12,475,368 B2, machine unlearning and retraining on a modified dataset

Granted 18 November 2025. Computes the gradient change when dataset elements are removed or added, tests that change against a stochastic condition, and retrains only when the condition fails. A method patent about doing the removal, not about proving it happened.

A patent claims ownership of a method. It states no result about any deletion, so the ladder's first question does not apply and the rung shown is a floor rather than a reading. It is listed here for freedom to operate, not as evidence.

Verifiable by Patent office record onlynot scored by the ladderpatents.google.com

C2PA, Content Authenticity Initiative

Open benchmarkread 2026-08-09
source unchanged 2026-08-23

Content Credentials, cryptographically signed media provenance

An open specification for binding signed, tamper evident provenance to a media file so a viewer can check how it was made and what edited it. The relevant lesson for erasure evidence is structural: the claim travels with the artifact rather than living in a vendor portal, which is the same reason an evidence pack should be a file and not a database lookup.

A specification defines a format. It states no result about any deletion or any system, so the ladder's first question does not apply. It is listed here for the structural lesson that a claim should travel with the artifact rather than live in a vendor portal.

Verifiable by Anyone with a Content Credentials verifiernot scored by the ladderc2pa.org

CNIL, EDPB, ICO

Regulationread 2026-08-12
source changed 2026-08-23, not re-read

Positions on effective erasure in AI systems

None of the three requires full retraining on every erasure request. CNIL's own how to sheet recommends filtering the outputs of the system to answer rectification, objection and erasure requests where the controller demonstrates that the measure is sufficiently effective and robust, and it prefers general rules that prevent generating personal data over a blacklist of the people who exercised their rights. Suppression based approaches are therefore legitimate in Europe, which is the regulatory ground this entire category stands on. Verified against the CNIL sheet on 12 August 2026, replacing a source that pointed only at the CNIL home page.

Regulator positions state what would satisfy the law, not that anything was deleted. The ladder's first question does not apply. This entry is listed because it is the ground that makes suppression based approaches legitimate in Europe, not because it is evidence about a deletion.

Verifiable by Anyone, the positions are publishednot scored by the ladderwww.cnil.fr

Coinbase Inc

Patentread 2026-08-09
source unchanged 2026-08-23

US 12,456,052 B2, verifiability of machine learning model unlearning

Granted 28 October 2025. The independent claims cover running unlearning across multiple stages, generating a cryptographic value for the model instance at each stage, and storing those values so the process can later be verified. Zero knowledge techniques appear in the specification rather than as the only claimed mechanism. This is the closest granted claim to the proof side of this market, and it is held by a company that does not sell unlearning.

A patent claims ownership of a method. It states no result about any deletion, so the ladder's first question does not apply and the rung shown is a floor rather than a reading. It is listed here for freedom to operate, not as evidence.

Verifiable by Patent office record onlynot scored by the ladderpatents.google.com

European Commission, AI Office

Regulationread 2026-08-09
source unchanged 2026-08-23

GPAI Code of Practice and Model Documentation Form

Final version published 10 July 2025, covering transparency, copyright, and safety and security. Its transparency core is a standard Model Documentation Form with tiered disclosure, so different facts go to the AI Office, to national authorities, and to downstream providers. The template is public; the completed forms largely are not, which is the same shape as the trust center problem.

A code of practice states commitments, not results. The ladder's first question does not apply, so this entry is listed as regulatory context rather than scored as evidence.

Verifiable by Anyone can read the template, few filled forms are publicnot scored by the ladderartificialintelligenceact.eu

European Commission, AI Office

Regulationread 2026-08-12
source unchanged 2026-08-23

Public template for summarising GPAI training data

Final template published 24 July 2025. Providers must give an overview of training data including sources, large datasets and top domain names, and the Commission page states the template requests this so that parties with legitimate interests can exercise their rights under EU law. This is the first regulation anywhere that makes a training data disclosure a routine published artifact rather than something extracted through litigation.

A mandated template defines what must be disclosed. It reports no result about any deletion, so the ladder's first question does not apply and this entry is listed as regulatory context.

Verifiable by Anyone, once a provider publishes its summarynot scored by the ladderdigital-strategy.ec.europa.eu

Hirundo

Unlearning vendorread 2026-08-09
source unchanged 2026-08-23

Google DeepMind case study placement

A named third party association carries real signal about commercial traction and is the strongest asset on their site. It reports nothing about unlearning efficacy, which is a separate question from customer quality.

A customer logo is a commercial signal, not a result. Their own entry says it reports nothing about unlearning efficacy, and the ladder scores results, so this one is listed rather than scored. It stays in the registry because commercial traction is real information and hiding it would make this list less honest, not more.

Verifiable by Nobody, but the counterparty is namednot scored by the ladderwww.hirundo.io

IBM

Patentread 2026-08-12
source unchanged 2026-08-23

US 2025/0190815, automated guidance for machine unlearning

An application rather than a grant, filed December 2023, published June 2025 and still listed as pending. It covers running an unlearning algorithm, generating metrics that compare the unlearned model against the original on accuracy, privacy and fairness, recommending an action when a metric crosses a threshold, and evaluating adversarially whether the influence was actually removed. That last element sits closer to independent audit work than the other patents recorded here, which is the reason this entry was pulled from a home page link to the document itself on 12 August 2026.

A patent claims ownership of a method. It states no result about any deletion, so the ladder's first question does not apply and the rung shown is a floor rather than a reading. It is listed here for freedom to operate, not as evidence.

Verifiable by Patent office record onlynot scored by the ladderpatents.google.com

KVKK, Turkey

Regulationread 2026-08-12
source changed 2026-08-22, not re-read

Guidance publication 113, November 2025

Publication 113, dated November 2025, reads the data subject rights in article 11 of Law 6698 across the whole system rather than the source database alone. Its own sentence puts training data, the data used in fine tuning processes, the information appearing in model outputs and the content included in user queries all inside that scope. The erasure right therefore reaches the model, while the guidance names no mechanism for proving that the erasure happened, and the term unlearning does not occur anywhere in the document. Turkey has the duty without a named method, and unlike CNIL there is no technical impossibility exemption. The full text was read on 12 August 2026, replacing a source that pointed only at the regulator's home page.

A guidance publication states an obligation, not a result. It tells controllers what erasure must achieve; it does not report that any deletion happened or how anyone checked it. The ladder's first question does not apply, so this entry is listed as the regulatory ground this market stands on rather than scored as evidence.

Verifiable by Anyone, the guidance is publishednot scored by the ladderwww.kvkk.gov.tr

Lemon Inc, ByteDance

Patentread 2026-08-09
source unchanged 2026-08-23

US 12,591,750 B2, generative language model unlearning

Granted 31 March 2026, the most recent grant in this set. The claim takes paired sets of undesirable and desirable behaviours and applies iterative parameter updates that suppress the unwanted output while holding performance on benign input. That is behavioural suppression, which is the approach most vendors in this registry actually ship.

A patent claims ownership of a method. It states no result about any deletion, so the ladder's first question does not apply and the rung shown is a floor rather than a reading. It is listed here for freedom to operate, not as evidence.

Verifiable by Patent office record onlynot scored by the ladderpatents.google.com

SLSA and Sigstore

Open benchmarkread 2026-08-09
source unchanged 2026-08-23

Build provenance attestations for software artifacts

Not an AI artifact, included because it is the mature version of what this market is groping toward. Software supply chain security already settled on signed, machine readable provenance anchored in a public transparency log, so a consumer can check where a binary came from without trusting the publisher. AI erasure evidence is roughly where software provenance was before this existed.

A specification defines a format. It states no result about any deletion or any system, so the ladder's first question does not apply. It is listed here because software supply chain security already solved the problem this market is still groping toward, not as evidence about forgetting.

Verifiable by Anyone, with public transparency logsnot scored by the ladderslsa.dev

Vijil

Governance vendorread 2026-08-12
source changed 2026-08-23, not re-read

Thirteen published detection models for safety and injection

Publishing the instrument is a legitimate proof route even when customer results stay private: a reader can inspect what is actually being measured. Thirteen models are downloadable, and the download counts are themselves a signal of real use rather than shelfware, with prompt injection detection at roughly 10,700 and toxic content at 1,800 pulls in the trailing month, measured 20 August 2026 via the HuggingFace API; these are rolling 30 day counters and move week to week. No datasets are published, so the models can be run but the evaluations behind them cannot be reproduced.

Thirteen downloadable detection models are an instrument, not a result. Publishing the instrument is a real contribution and a reader can inspect exactly what is being measured, but the entry states no outcome for any deletion, and their own customer results stay private. The ladder scores results, so this one is listed rather than scored.

Verifiable by Anyone who downloads and runs a modelnot scored by the ladderhuggingface.co

Rules this registry runs on

  1. Every entry links to a live source. An entry whose source cannot be opened does not go in.
  2. Where a competitor is ahead of us it is written plainly. Forg3t publishes a reproducible benchmark and we do not, and that is recorded here rather than left out.
  3. The last checked date does not lie. An entry not re-confirmed in the current pass keeps its older date and is marked, and a scan re-fetches every source to reopen the question when one changes or dies. The whole registry was last swept on 2026-08-12. If that date is far behind today, treat the entries as stale and check the sources yourself, which is the point of listing them.
  4. Our own record sits in the same list under the same scale and links to a verifier anyone can run without signing anything.
  5. Every placement is reproducible. Each record either carries the answers that produce its rung, checked by a test that fails when the two disagree, or is marked as not scored because it is not evidence about a deletion at all. As of 12 August 2026 no record rests on an unexplained editorial judgement.

One of the two rung five entries is ours, so read it with that in mind and then go check it. The verifier runs in your browser, stores nothing, and will tell you if a pack has been tampered with, including by us.

Publish something and think it belongs here

This list is what we could find and open, which is not the same as what exists. If you publish evidence about deletion, forgetting or AI safety and it is not here, send the artifact itself and we will read it against the same four rules. If your entry is already here and a sentence in it is wrong, tell us which sentence. We have corrected our own placement of someone else's evidence once already, and we would rather do it again than leave it standing.

Send an artifact or a correction