Privacy Tools

You Can Ask AI Companies to Stop Training on Your Data — Here's How in 2026

Colorado's AI Act and Texas's TRAIGA both took effect this year. Most people don't realize they have a real, formal right to opt their data out of AI training. Here's how to actually exercise it.

📅 Aug 16, 2026·⏱️ 6 min read·✍️ Cikal Studio Labs
🤖

2026 is the year AI-specific privacy law actually arrived

For years, AI training data practices existed in a regulatory gray area, governed loosely by general privacy law that wasn't written with machine learning in mind. That changed substantially in 2026: Colorado's AI Act took effect, establishing obligations for developers and deployers of high-risk AI systems around transparency and algorithmic discrimination, and Texas's Responsible Artificial Intelligence Governance Act (TRAIGA) followed in January. Meanwhile, California's existing CCPA/CPRA framework already provides a right to opt out of having personal information used for AI training and automated decision-making.

Most people don't know this right exists

Unlike the right to opt out of "data sale," which has been in consumer awareness for years thanks to CCPA-driven "Do Not Sell My Info" links, the right to specifically address AI training use is newer and far less publicized. Companies generally aren't required to make this option prominent, and most privacy policies bury the relevant language in dense legal text rather than a clear, actionable link.

What you can actually ask for

  • Opt out going forward. A request that the company stop using your personal information for any future AI model training, fine-tuning, or improvement.
  • Delete past training use. A request to remove your data from datasets already used for training, "to the extent technically feasible" — an important caveat, since some AI companies argue that removing specific data from an already-trained model isn't straightforward.
  • Both. Combining the two closes the loop on future and past use in a single request.

Why jurisdiction matters for how you phrase this

The specific legal basis you cite changes what a company is obligated to do and how quickly. A California resident citing CCPA/CPRA has a different, more established set of enforceable rights than someone in a state without a comprehensive privacy law citing general goodwill. Naming the specific law — the Colorado AI Act, TRAIGA, CCPA/CPRA, or GDPR alongside the EU AI Act — signals that you know your request has legal weight, not just that you'd prefer it.

What happens after you send it

Companies subject to these laws are generally required to acknowledge and act on your request within a set timeframe (commonly 45 days under CCPA, for example), and to explain their legal basis if they're unable to fully comply. Keeping a copy of your sent request and any response is worth doing in case you need to escalate to your state's attorney general or data protection authority later.

This is a floor, not a ceiling

Sending this request doesn't guarantee full compliance, especially for the "delete past training use" component, which remains technically and legally contested across the industry. But making the request formally, citing the specific law that applies to you, is a meaningfully stronger position than simply hoping a company respects your preferences by default.

Frequently Asked Questions

Can I actually ask an AI company to stop training on my data?

Yes, in a growing number of jurisdictions. California's CCPA/CPRA already provides a right to opt out of personal information being used for AI training and automated decision-making, and 2026 added the Colorado AI Act and Texas's TRAIGA, both establishing further AI-specific obligations. The exact right and remedy depends on where you live.

Can a company actually delete my data from an already-trained AI model?

This is a genuinely contested area. Some companies can remove your data from future training datasets straightforwardly, but removing the influence of specific data from a model that's already been trained is technically difficult and legally disputed across the industry — most requests for this are honored 'to the extent technically feasible,' which is a meaningful caveat.

Does citing a specific law actually change how a company responds?

It can. Companies subject to a specific law like CCPA/CPRA are generally required to acknowledge and act on a qualifying request within a set timeframe, and to explain their legal basis if unable to fully comply. Citing the applicable law by name signals the request carries legal weight, rather than reading as a general preference.

What if I don't live in California, Colorado, Texas, or the EU?

Twenty U.S. states now have comprehensive privacy laws in effect as of 2026, and most provide at least some right to opt out of profiling or automated decision-making, even if AI training specifically isn't named. It's still worth sending a request citing your state's general privacy law, even where the right is less explicitly defined.

Is there a tool that generates this kind of request automatically?

Yes — the AI Training Data Opt-Out Request Generator produces a properly formatted, jurisdiction-aware request for seven major AI companies, letting you choose between opting out going forward, requesting deletion of past training use, or both, with the specific applicable law cited automatically.