The Genesis of Weight-Level Remedies
Traditional privacy enforcement commanded companies to delete raw source files (photographs, audio recordings, personal records) while leaving the computational models trained on that data operational. This created a profound structural moral hazard: a company could harvest data illicitly, complete training, pay a regulatory fine, and retain a permanent commercial asset derived from the violation.
In 2021, the United States Federal Trade Commission broke with this precedent in its settlement with photo-storage app Everalbum, ordering the company to delete not only the retained user photos, but all facial recognition models and algorithms developed using those photos. The FTC reinforced this doctrine in subsequent enforcement actions:
- WW International & Kurbo (2022): Ordered the destruction of weight matrices and algorithms trained on children's health data collected in violation of COPPA.
- Amazon Alexa (2023): Mandated the deletion of machine learning algorithms trained on retained geolocation and voice data.
- FTC v. Rite Aid (2023): Prohibited the deployment of biometric surveillance models built on defective, biased facial recognition systems.
Algorithmic disgorgement rests on a foundational premise: because the data's economic value and potential harm both persist inside the trained model, a remedy that leaves the model standing leaves the violation standing.
The Antidote to Erasure Theater
Algorithmic disgorgement serves as the primary legal and structural countermeasure to Erasure Theater and Architectural Repeal. When technical architectures render surgical Machine Unlearning unverifiable, cosmetic output filters and prompt guardrails cannot satisfy statutory destruction mandates.
Disgorgement bypasses the verification wall by targeting the entire model artifact. Where an operator cannot prove that personal data has been excised from its weights, equity requires the forfeiture of the asset.
Economic Realignment: Pricing Deletion into Training
The strategic power of algorithmic disgorgement lies in its impact on frontier training economics. Monetary fines—even those reaching hundreds of millions of dollars—function in practice as a cost of doing business for trillion-dollar tech platforms. In contrast, the destruction of a frontier model destroys months of training compute, engineering milestones, and commercial pipelines.
A credible prospect of disgorgement forces operators to price consent and provenance screening into initial architectural decisions, shifting the safeguard from cosmetic downstream filtering to strict upstream curation.
Field Notes & Ephemera
Field Note: "The company treated statutory fines as amortized overhead. It was only when the court ordered the destruction of the 70-billion-parameter checkpoint that the executive committee halted automated crawling. Disgorgement targets the asset itself, not the balance sheet."