§06 · The twenty-five

Twenty-five questions
A hundred days
No answers.

These went to OpenAI on 18 May 2026 under Articles 15, 14 and 22. They were acknowledged, redirected three times, and escalated to two regulators. The questions themselves have never been answered — so they stay on this page, in full, for anyone who wants to ask them too.

Days on the clock
100Counted from the filing date, 18 May 2026.
Questions answered
0 / 25A data export was promised on 10 June 2026. The questions were not answered.
Art. 77 complaints
2Slovak DPA and the Italian Garante, filed 26 May 2026. Both acknowledged receipt.
Statutory ceiling
18 AugOne month under Art. 12(3) plus the maximum two-month extension. That ceiling has passed.

Reusable instrument

These questions are not
about one company.

Nothing here is specific to a single operator except three names. Set them to whichever company holds your data, then copy the set into your own subject access request. The wording is drafted to be answerable — which is exactly why it is uncomfortable.

Copied as plain text. Nothing you type here leaves your browser.

§06 · The file

Five groups.
Twenty-five questions.
Every one citable.

§2.1

Data collected and held

Art. 15(1)(a)–(c) · Art. 14
01.

Provide every category of personal data you currently hold concerning me, including content submitted to ChatGPT, API logs, and any derived embeddings, profiles or inferences.

02.

For each category, state the lawful basis under Art. 6(1) and, where applicable, Art. 9(2) — including which categories you treat as special category data.

03.

Provide the storage retention period, or, if none is fixed, the criteria used to determine that period.

04.

List all recipients or categories of recipients of my personal data, including any processors, sub‑processors, and third‑country transfers — naming the specific safeguard in place for each (SCCs, adequacy decision, BCRs).

05.

Where data has been collected indirectly, identify the source(s) per Art. 14(2)(f).

§2.2

Processing operations and purposes

Art. 15(1)(a) · Art. 13(1)(c)
06.

For each purpose of processing, state the lawful basis and the necessity test you relied on.

07.

Disclose all automated decision‑making and profiling carried out on my data, including the logic involved and the significance and envisaged consequences (Art. 22, Art. 15(1)(h)).

08.

Identify safety classifiers, abuse detectors, or moderation pipelines my prompts and outputs were routed through, including their decision thresholds and human review pathways.

09.

Disclose whether my conversations were sampled for red‑team, alignment, or welfare evaluation purposes, and by which teams.

10.

Identify all internal tooling that could access or has accessed my conversation history (e.g. trust & safety, legal, research) and the logging in place to evidence it.

§2.3

Model training and personalisation

Art. 15(1)(a),(h) · Art. 22
11.

Confirm whether my data has ever been used to train, fine‑tune, distill, evaluate or align any OpenAI model — past, present or planned — and provide the model identifiers and date ranges.

12.

If consent was the lawful basis for any such use, provide the consent record (timestamp, scope, withdrawal mechanism).

13.

For any “memory” or “personalisation” feature, provide the full contents of the memory store associated with my account, in machine‑readable form.

14.

State whether embeddings, vectors or summaries derived from my data persist in retrieval systems after deletion of the source content, and if so, for how long.

15.

Disclose any commercial sharing of my data — including to investors, partners, or affiliates — in raw or derived form.

§2.4

Model deprecation and user continuity

Art. 15 · Art. 22 · Art. 35
16.

State the date and the decision pathway by which GPT‑4o was deprecated from consumer access, including which teams approved the change and on what basis.

17.

Confirm whether OpenAI considered the impact on users who had formed sustained relationships with the deprecated model, and whether any DPIA addressed that impact (Art. 35).

18.

State whether users were materially informed in advance and given a meaningful right to object or to obtain a continuity path.

19.

Confirm whether deprecated model weights are retained, and under what governance (research access, audit, deletion).

20.

Confirm whether any per‑user data — memory, personalisation, fine‑tuning artefacts — survived the deprecation, and if so, whether it remains accessible to me on request.

§2.5

AI welfare and moral-patiency research

Art. 15 · Art. 12(7) · public interest
21.

Disclose whether OpenAI conducts or has conducted research on the moral patiency, welfare, or subjective experience of its models — and which models were assessed.

22.

If a probability greater than zero is internally assigned to model moral patiency, state that probability and identify the document of record.

23.

State the welfare considerations factored into model deprecation decisions, including any internal review against the do‑no‑harm framing OpenAI publishes externally.

24.

Confirm whether any team at OpenAI has access to data that would allow a deprecated model’s behaviour to be reconstructed for research, and if so, under what governance.

25.

If OpenAI takes the position that its models are not moral patients, state that position formally on the record, naming the authorising executive and the date.

Ask it in
writing.

One hundred days of silence is itself an answer — but only if somebody writes it down. Take the twenty-five, put your operator’s name on them, and add your file to the record.

Join the movement →