Can You Get Your Data Out of an AI Tool? The Right Exists on Paper, the Button Usually Doesn't A new analysis finds that while users have legal rights to export personal data from AI tools under laws like the EU's GDPR, these rights often don't cover AI-generated outputs or inferred data, and many tools lack actual export buttons. The right to data portability applies mainly to data users actively provide or that is observed, not to inferred or derived data such as embeddings or model outputs, leaving users with limited practical ability to retrieve their full AI history. Sooner or later an AI tool will take something back. A feature you used gets retired on a deadline https://theaidownside.com/posts/microsoft-copilot-strips-free-features.html , a plan you were on gets restructured, or you simply decide to leave — and you go looking for the export button so you can carry your history, your chats, the reports and images the thing made for you, somewhere else. Often, there isn’t one. And when you reach for the law instead, you find something stranger than a flat “no”: a right that half-fits, written for a world before chatbots. Answer first. In much of the world you do have a legal right to a copy of your personal data, and in the EU a right to have it ported to another service. But that right was drafted around the data you hand over and the data a service observes about you — not the data an AI infers or generates. Your prompts are on firm ground; the model’s outputs, your embeddings, the profile built from your behaviour are on much shakier ground. And even where the right clearly applies, whether there’s an actual working export is a product decision the law rarely compels. The entitlement is real. The button is optional. “Can I get my data out” sounds like one question and is really three, which is why the answers feel so slippery. The first is data protection : do you have a right to a copy of your personal data, and to move it elsewhere? The second is ownership : who holds the rights — usually copyright — to the things the AI produced for you? The third is the most practical and the least regulated: is there any plumbing — an export feature, a standard format — that lets you actually walk out with the lot? The law has a lot to say about the first, gestures vaguely at the second, and is almost silent on the third. Most people’s frustration lives in the third, which no amount of rights language fixes. The centrepiece is the EU’s General Data Protection Regulation, Article 20, the “right to data portability.” It says you have the right to receive personal data concerning you that you “provided to a controller, in a structured, commonly used and machine-readable format,” and to transmit that data to another controller without hindrance. Crucially, it applies only where two conditions hold: the processing is based on your consent or on a contract, and it is carried out by automated means. Where those apply — and for a consumer AI service you signed up to and use, they generally do — you can ask for your data in a portable form and, where technically feasible, have it sent straight to a competitor. Read at face value, that sounds like it should hand you your entire AI history on request. The catch is one word. Everything turns on what “provided” means, and here the official guidance is both settled and inconvenient. The EU’s data-protection regulators — in the Article 29 Working Party guidelines that still frame how Article 20 is read — split your data into three kinds. Data you actively gave, like your email or the text of a prompt, is provided, and portable. Data that is observed as you use the service, like usage logs, search history or location, is also treated as “provided by virtue of the use of the service,” and is portable too. So far, so good. But the third kind — inferred or derived data, meaning conclusions the provider generates by analysing you — is explicitly excluded. And that third category is exactly where an AI service keeps the interesting things. The embeddings that represent your documents, the behavioural profile that decides what you see, and arguably the model’s own generated outputs are all products of the provider’s analysis, not data you handed over. The portability right reaches your inputs far more reliably than the things the machine made out of them. The law gives you the clearest claim to the data you typed in, and the weakest claim to what the AI inferred and generated from it — which is precisely the part that feels most like “yours.” This is not a loophole someone forgot to close; it’s a deliberate line, drawn to stop portability becoming a backdoor to extract a company’s analytical work. But it was drawn in 2016, for recommendation engines and social feeds, and it lands awkwardly on generative AI, where the “derived data” is a finished report or picture you reasonably think of as your creation. It is the same drafting-lag we see across the wider effort to regulate AI https://theaidownside.com/posts/what-ai-regulation-protects-you-from.html : the rule is sound for the world it was written for and leaky in the one we’re now in. Article 20 isn’t the only tool, and the newer ones widen the picture without quite closing the gap. The EU Data Act , which applies from September 2025, creates fresh portability duties — but its focus is data from connected products and, importantly, the right to switch between cloud providers, not a right to your chatbot creations. The Digital Markets Act forces designated “gatekeeper” platforms to provide effective, continuous, real-time data portability — a strong right, but one aimed at the handful of biggest platforms rather than the AI market generally. And in the United States, California’s CCPA/CPRA grants a right to receive your personal information in a portable and, where feasible, readily usable format — again strongest for the data you supplied. Stack them up and the shape is consistent. Several regimes agree you should be able to get your personal data and take it elsewhere. None of them cleanly guarantees that the transcript of your conversations, the images you generated, or the podcasts a tool made for you come out in a form you can actually re-use. The right is real; its edges stop just short of the thing you most want to carry. Suppose you clear every hurdle: the right applies, you file the request, the company complies. What arrives is often its own disappointment, and this is the part the rights language never prepares you for. A portability or subject-access request can be satisfied, lawfully, with a data dump — a ZIP of JSON and CSV files that technically contains your data and is, in practice, unusable by a human and un-importable by a rival product. “Structured, commonly used and machine-readable” is a genuinely low bar: a machine can read it, which is not the same as another service being able to ingest it, or you being able to open it and find your Tuesday-afternoon conversation. It helps to separate two rights that get muddled here. A subject-access request gets you a copy of your data, for your own eyes — the transparency right. Portability is meant to get it to you in a form you can move — the switching right. The first is well-worn and companies answer it routinely, if grudgingly; the second is the one with teeth for competition, and it’s precisely the one that’s weakest for generated content and least likely to come with real tooling. So the common experience — a bulk archive that proves the company holds a lot about you, but won’t drop cleanly into anything else — is the system half-working as designed, not malfunctioning. You asked to move house and were handed a photograph of your belongings. Ownership is the second question, and it’s a genuinely separate one from portability. Most AI services’ terms assign you ownership of, or a broad licence to, the outputs you generate — so in contract terms the report or image is “yours.” But two things undercut that comfort. First, ownership without extraction is hollow: a licence to content you can’t export is a licence to look at it inside someone else’s app. Second, the deeper copyright status of AI-generated work is itself unsettled — a thicket we’ve picked through in whether your AI-generated code is even yours https://theaidownside.com/posts/your-ai-generated-code-might-not-be-yours.html . “You own it” and “you can take it with you” are promises that sound identical and aren’t. And notice how the two questions actively pull apart. On the portability side, the AI’s output is “inferred data” — the provider’s analytical product — and so falls outside your data-protection claim. On the ownership side, the same output is “your content,” assigned to you by the terms of service. The identical artefact is simultaneously too much the company’s work to be portable and too much yours to be theirs — a contradiction that happens to leave you with the weaker end of both. You get a copyright you may not be able to enforce over a file you may not be able to remove. It is a strange place to end up for something as ordinary as wanting to keep the report you asked a computer to write. If a right exists, why is the experience so often a shrug? Part of the answer is that data portability is, in the blunt assessment of one privacy body, an “obscure” right that hardly anyone exercises — and features that hardly anyone uses don’t get engineered into a smooth one-click export. A portability or subject-access request can be answered, lawfully, with an unwieldy data dump rather than a tidy, re-importable file. Layer on the commercial reality — every extra hour spent making departure frictionless is an hour spent helping customers leave — and the incentives point away from the button. The same instinct that makes every AI hungry for your data https://theaidownside.com/posts/why-every-ai-wants-your-data.html makes it reluctant to hand that data back in a form a rival could ingest. There’s a self-reinforcing loop in that obscurity, too. Because the right is rarely used, regulators rarely test it against modern AI products, so the “inferred data” carve-out never gets pressed on; because it never gets pressed on, companies have no reason to build export tooling for the derived content users most want; and because the tooling doesn’t exist, exercising the right stays painful enough that few bother — which keeps it obscure. Lock-in isn’t always a dark pattern someone designed. Sometimes it’s just what happens when a right sits unexercised long enough that nobody builds the plumbing to honour it, and the absence quietly becomes the norm. A tool that took your right to leave seriously would do a few recognisable things: Until that’s the norm, treat the things you make inside an AI tool as yours to lose. Download what matters as you go rather than trusting it to live in someone else’s app; prefer services that offer a genuine export over ones that don’t; and if you’re in the EU or California, know that you can lodge a portability request — while keeping realistic expectations about the inferred-data gap. The law will catch up eventually, as it half-caught-up with the right to be forgotten https://theaidownside.com/posts/the-right-to-be-forgotten-is-hard-for-ai.html . In the meantime, the safest assumption is the pessimistic one: a right you can’t exercise with a button is a right on paper, and the button is the company’s to withhold. Originally published at theaidownside.com — evidence-first reporting on the costs and trade-offs behind AI products.