Subscribe To Newsletters

Don’t Forget The Right To Be Forgotten

For AI investors, data governance is becoming a critical test of risk and value.

and
Neha Parekh

What every board member of a fund investing in AI needs to understand about data, liability, and the limits of compliance.

Luxembourg’s fund industry sits at the intersection of two trends: the accelerating use of artificial intelligence across portfolio companies, and one of the most demanding data protection enforcement environments.

Boards that treat these as separate topics, are mispricing risk.

In 2026, “privacy debt” can wipe out the value of an AI investment overnight.

Data Is the Fuel. It Can Become Liability.

Every AI model is built on data.

The quality and volume of that data determines the model’s value and the investment thesis behind it.

But what if the data was not properly sourced?

Under the EU’s GDPR and many other privacy regulations around the world, personal data cannot be repurposed without the explicit consent given at the time of collection.

If a target company has trained its AI models on customer data without that consent, or without a documented chain of provenance, it has created a contingent liability that can dominate the liquidation waterfall.

(Neha Parekh. Photo © All rights reserved)
(Neha Parekh. Photo © All rights reserved)

High-risk system violations from August 2026 carry significant penalties. While prohibited AI practices can trigger fines of up to €35 million or 7% of global annual turnover, non-compliance with the requirements for high-risk systems, the category most portfolio companies will fall under, carries a maximum of €15 million or 3%

For a mid-market portfolio company, an enforcement action at either level is a potentially terminal event that destroys value before returns ever reach the waterfall.

As a board member, the question is whether the portfolio company can show where its training data came from, who authorised its use, and what consent was in place.

Why the Right to Be Forgotten Becomes Impossible to Guarantee

In a traditional database, satisfying a deletion request is straightforward: locate the record, delete it, document the action.

But once personal data is used to train a model, it becomes woven into the mathematical structure of the system itself.

There is currently no reliable way to remove one person’s data from a trained model without rebuilding the entire system from scratch.

Regulators have drawn the logical conclusion.

The US Federal Trade Commission has already ordered model deletion in live enforcement cases.

In its settlement with Rite Aid, the FTC required the destruction of all data, models, and derived algorithms from a facial recognition system built on improperly collected data.

The business consequence is severe: AI models can take years to build at a cost of millions, and when contaminated data runs across multiple models, all of them may need to be destroyed simultaneously.

For a portfolio company whose core asset is its AI, that order can completely wipe out the value of the asset.

Where These Liabilities Hide

Standard acquisition due diligence checks the privacy policy, reviews data agreements, and confirms regulatory registrations.

What it rarely does is trace where the AI training data came from.

The 2026 Thales Data Threat Report found that only 34% of organisations have complete knowledge of where their own data is stored.

(Pascal Hernalsteen. Photo © All rights reserved)

A company that cannot answer that question about itself cannot credibly guarantee how it sourced the data used to train its models.

The exposure tends to sit in three places:

  • marketing data used for model training without explicit consent,
  • customer interaction records repurposed for AI without proper authorisation, and
  • third-party datasets acquired under licences that did not cover AI training.

None of these show up in a standard legal review.

A buyer who does not look will not find them until the next buyer does.

The Exit Risk Board Members Must Anticipate

Privacy debt surfaces at exit.

When an undisclosed liability emerges during buyer due diligence, it cuts the valuation.

That liability is settled at the company level first, reducing the proceeds that flow into the waterfall – cutting into preferred returns and carried interest before either is paid.

A material privacy settlement can eliminate most of the fund manager’s performance fee.

Informed buyers in 2026 ask for AI impact assessments, documented proof of data ownership for each model, and demonstrated capacity to process deletion requests at scale.

A company that cannot produce these risks losing the deal entirely.

Three Questions Every Board Should Be Asking

The board’s role is not to become a data protection authority.

It is to ask the right questions at the right moments.

Before acquisition: can this company show where its training data came from and confirm that proper consent was in place?

During the holding period: can the company demonstrate documented data flows and a growing evidence file that a future buyer will require?

Before the exit: can it produce impact assessments and provenance records on demand, and has it tested its processes against the EU AI Act’s August 2026 requirements?

Where a dedicated chief privacy officer is not yet justified by the company’s size, a fractional or shared resource deployed across the portfolio offers a practical and proportionate alternative.

A New Dimension of Fiduciary Duty

In the AI economy, data governance has become part of the board’s fiduciary duty.

Luxembourg’s CNPD has been designated as the country’s lead enforcement body under the EU AI Act, with full oversight of high-risk AI systems beginning August 2, 2026.

Luxembourg-based funds are directly within scope.

The discipline that boards already apply to financial due diligence, operational risk, and regulatory compliance now needs to extend to one further question: does this company know what data trained its models, and can it prove it?

Data is an asset. In the AI economy, it becomes a liability the moment governance fails.

The right to be forgotten becomes a test of whether the investment thesis survives the questions a buyer’s lawyers will ask.

This article was published in the 10th edition of Forbes Luxembourg.


 

 

Read more articles:

Will Companies Ever Be Run By An AI CEO?

Luxembourg Households Favour Financial Security

MiCA’s Moment: Why Coinbase Is Betting On Luxembourg To Lead Europe’s Crypto Future

A la une