Can You Get Your Data Out of an AI Tool? The Right Exists on Paper, the Button Usually Doesn't
Data-protection law gives you a right to portability. It was written before chatbots, and the gap it leaves — inferred and generated data — is exactly where your AI history lives.
Sooner or later an AI tool will take something back. A feature you used gets retired on a deadline, a plan you were on gets restructured, or you simply decide to leave — and you go looking for the export button so you can carry your history, your chats, the reports and images the thing made for you, somewhere else. Often, there isn’t one. And when you reach for the law instead, you find something stranger than a flat “no”: a right that half-fits, written for a world before chatbots.
Answer first. In much of the world you do have a legal right to a copy of your personal data, and in the EU a right to have it ported to another service. But that right was drafted around the data you hand over and the data a service observes about you — not the data an AI infers or generates. Your prompts are on firm ground; the model’s outputs, your embeddings, the profile built from your behaviour are on much shakier ground. And even where the right clearly applies, whether there’s an actual working export is a product decision the law rarely compels. The entitlement is real. The button is optional.
Three questions hiding in one
“Can I get my data out” sounds like one question and is really three, which is why the answers feel so slippery.
The first is data protection: do you have a right to a copy of your personal data, and to move it elsewhere? The second is ownership: who holds the rights — usually copyright — to the things the AI produced for you? The third is the most practical and the least regulated: is there any plumbing — an export feature, a standard format — that lets you actually walk out with the lot? The law has a lot to say about the first, gestures vaguely at the second, and is almost silent on the third. Most people’s frustration lives in the third, which no amount of rights language fixes.
What the law actually gives you: GDPR Article 20
The centrepiece is the EU’s General Data Protection Regulation, Article 20, the “right to data portability.” It says you have the right to receive personal data concerning you that you “provided to a controller, in a structured, commonly used and machine-readable format,” and to transmit that data to another controller without hindrance. Crucially, it applies only where two conditions hold: the processing is based on your consent or on a contract, and it is carried out by automated means. Where those apply — and for a consumer AI service you signed up to and use, they generally do — you can ask for your data in a portable form and, where technically feasible, have it sent straight to a competitor.
Read at face value, that sounds like it should hand you your entire AI history on request. The catch is one word.
The word that swallows your AI history: “provided”
Everything turns on what “provided” means, and here the official guidance is both settled and inconvenient. The EU’s data-protection regulators — in the Article 29 Working Party guidelines that still frame how Article 20 is read — split your data into three kinds. Data you actively gave, like your email or the text of a prompt, is provided, and portable. Data that is observed as you use the service, like usage logs, search history or location, is also treated as “provided by virtue of the use of the service,” and is portable too. So far, so good.
But the third kind — inferred or derived data, meaning conclusions the provider generates by analysing you — is explicitly excluded. And that third category is exactly where an AI service keeps the interesting things. The embeddings that represent your documents, the behavioural profile that decides what you see, and arguably the model’s own generated outputs are all products of the provider’s analysis, not data you handed over. The portability right reaches your inputs far more reliably than the things the machine made out of them.
This is not a loophole someone forgot to close; it’s a deliberate line, drawn to stop portability becoming a backdoor to extract a company’s analytical work. But it was drawn in 2016, for recommendation engines and social feeds, and it lands awkwardly on generative AI, where the “derived data” is a finished report or picture you reasonably think of as your creation. It is the same drafting-lag we see across the wider effort to regulate AI: the rule is sound for the world it was written for and leaky in the one we’re now in.
Portability beyond GDPR — wider, but not deeper
Article 20 isn’t the only tool, and the newer ones widen the picture without quite closing the gap. The EU Data Act, which applies from September 2025, creates fresh portability duties — but its focus is data from connected products and, importantly, the right to switch between cloud providers, not a right to your chatbot creations. The Digital Markets Act forces designated “gatekeeper” platforms to provide effective, continuous, real-time data portability — a strong right, but one aimed at the handful of biggest platforms rather than the AI market generally. And in the United States, California’s CCPA/CPRA grants a right to receive your personal information in a portable and, where feasible, readily usable format — again strongest for the data you supplied.
Stack them up and the shape is consistent. Several regimes agree you should be able to get your personal data and take it elsewhere. None of them cleanly guarantees that the transcript of your conversations, the images you generated, or the podcasts a tool made for you come out in a form you can actually re-use. The right is real; its edges stop just short of the thing you most want to carry.
What actually lands in the export
Suppose you clear every hurdle: the right applies, you file the request, the company complies. What arrives is often its own disappointment, and this is the part the rights language never prepares you for. A portability or subject-access request can be satisfied, lawfully, with a data dump — a ZIP of JSON and CSV files that technically contains your data and is, in practice, unusable by a human and un-importable by a rival product. “Structured, commonly used and machine-readable” is a genuinely low bar: a machine can read it, which is not the same as another service being able to ingest it, or you being able to open it and find your Tuesday-afternoon conversation.
It helps to separate two rights that get muddled here. A subject-access request gets you a copy of your data, for your own eyes — the transparency right. Portability is meant to get it to you in a form you can move — the switching right. The first is well-worn and companies answer it routinely, if grudgingly; the second is the one with teeth for competition, and it’s precisely the one that’s weakest for generated content and least likely to come with real tooling. So the common experience — a bulk archive that proves the company holds a lot about you, but won’t drop cleanly into anything else — is the system half-working as designed, not malfunctioning. You asked to move house and were handed a photograph of your belongings.
Who owns the thing the AI made you, anyway?
Ownership is the second question, and it’s a genuinely separate one from portability. Most AI services’ terms assign you ownership of, or a broad licence to, the outputs you generate — so in contract terms the report or image is “yours.” But two things undercut that comfort. First, ownership without extraction is hollow: a licence to content you can’t export is a licence to look at it inside someone else’s app. Second, the deeper copyright status of AI-generated work is itself unsettled — a thicket we’ve picked through in whether your AI-generated code is even yours. “You own it” and “you can take it with you” are promises that sound identical and aren’t.
And notice how the two questions actively pull apart. On the portability side, the AI’s output is “inferred data” — the provider’s analytical product — and so falls outside your data-protection claim. On the ownership side, the same output is “your content,” assigned to you by the terms of service. The identical artefact is simultaneously too much the company’s work to be portable and too much yours to be theirs — a contradiction that happens to leave you with the weaker end of both. You get a copyright you may not be able to enforce over a file you may not be able to remove. It is a strange place to end up for something as ordinary as wanting to keep the report you asked a computer to write.
Why there’s so rarely a button
If a right exists, why is the experience so often a shrug? Part of the answer is that data portability is, in the blunt assessment of one privacy body, an “obscure” right that hardly anyone exercises — and features that hardly anyone uses don’t get engineered into a smooth one-click export. A portability or subject-access request can be answered, lawfully, with an unwieldy data dump rather than a tidy, re-importable file. Layer on the commercial reality — every extra hour spent making departure frictionless is an hour spent helping customers leave — and the incentives point away from the button. The same instinct that makes every AI hungry for your data makes it reluctant to hand that data back in a form a rival could ingest.
There’s a self-reinforcing loop in that obscurity, too. Because the right is rarely used, regulators rarely test it against modern AI products, so the “inferred data” carve-out never gets pressed on; because it never gets pressed on, companies have no reason to build export tooling for the derived content users most want; and because the tooling doesn’t exist, exercising the right stays painful enough that few bother — which keeps it obscure. Lock-in isn’t always a dark pattern someone designed. Sometimes it’s just what happens when a right sits unexercised long enough that nobody builds the plumbing to honour it, and the absence quietly becomes the norm.
What responsible portability would look like — and what to do now
A tool that took your right to leave seriously would do a few recognisable things:
- A real export, not a data dump. Your conversations, files and generated media in an open, documented format you could re-import elsewhere — not a legal-minimum ZIP of JSON no human can use.
- Honesty about the derived-data line. Say plainly what a portability request will and won’t include, rather than letting you assume it covers everything.
- Bulk, not one-by-one. If a feature is being retired, the exit should be a single download, not a manual rescue of each item against a deadline.
- Extraction that matches the ownership claim. If the terms say you own your outputs, the product should let you actually take them.
Until that’s the norm, treat the things you make inside an AI tool as yours to lose. Download what matters as you go rather than trusting it to live in someone else’s app; prefer services that offer a genuine export over ones that don’t; and if you’re in the EU or California, know that you can lodge a portability request — while keeping realistic expectations about the inferred-data gap. The law will catch up eventually, as it half-caught-up with the right to be forgotten. In the meantime, the safest assumption is the pessimistic one: a right you can’t exercise with a button is a right on paper, and the button is the company’s to withhold.
Frequently asked questions
What's the difference between data portability and data ownership?
Portability is a data-protection right: the ability to get a copy of your personal data in a usable format and, in some regimes, to have it transmitted to another service. Ownership is about who holds legal rights — usually copyright — in a piece of content. They come apart badly with AI. You might 'own' (or be licensed) a report or image a tool generated for you under its terms of service, yet have no portability right to it under data-protection law because it's derived data, and no export button to extract it in practice. Three separate questions, three separate answers.
Does GDPR let me download my ChatGPT or Copilot history?
Partly. GDPR Article 20 gives you the right to receive the personal data you provided to a service, in a structured, commonly used, machine-readable format, where the processing is based on your consent or a contract and is carried out automatically. Your prompts and account data are the strongest case. The weaker case is everything the system generated or inferred from you — model outputs, embeddings, a behavioural profile — which regulators' guidance treats as excluded from the portability right. So a legal request can compel a copy of what you put in more reliably than a copy of what the AI made out of it.
What counts as 'provided' data versus 'inferred' data?
Guidance from EU regulators splits it three ways. Data you actively and knowingly gave (your email, your prompt) is 'provided' and portable. Data 'observed' by virtue of your using the service (usage logs, search history) is also treated as provided and portable. But 'inferred' or 'derived' data — conclusions the provider generates by analysing your behaviour, such as a profile or a model output — is excluded. Most of what makes an AI history valuable and revealing lives in that excluded third category.
If I have a right to my data, why is there often no export button?
Because a right and a feature are different things. Data portability is, in the words of one privacy body, an 'obscure' right that few people exercise, so there's little pressure to build slick tooling for it — and a subject-access or portability request can legally be answered with a data dump rather than a clean, re-importable export. Add the commercial incentive to make leaving inconvenient, and the ambiguity over whether generated content is even covered, and you get the common result: a legal entitlement, and no button that satisfies it in one click.
Sources
- Article 20 GDPR — Right to data portability (full text) — GDPR / EU
- Guidelines on the right to data portability (wp242rev.01) — 'provided', observed vs inferred data — Article 29 Working Party (EU)
- Data portability in the EU: an obscure data subject right — IAPP
- Data Act — overview, scope and application from 12 September 2025 — European Commission
- California Consumer Privacy Act (CCPA) — consumer rights including data portability — California Attorney General
