On 18 May 2026, I sent OpenAI a formal Subject Access Request under Article 15 of the GDPR. I asked for the data associated with my account, the logic of profiling and automated decision-making, and answers to twenty-five specific questions.
The first response arrived in the same minute: an automatic acknowledgement. The second contact reframed the request. The third pointed elsewhere. The central question remained untouched.
Act I — The auto-reply
An automated receipt is useful evidence of delivery. It is not evidence that the substance was read. That distinction became the spine of the investigation.
Act II — The mischaracterization
The request was not merely for a standard account export. It asked what data existed, how it was used, what inferences were drawn, what was retained, and how automated systems affected the account. Treating that as a routine export request changed the question before answering it.
Has any human member of OpenAI’s Privacy Team read the full text of my Subject Access Request?
What the story is actually about
This is not a demand for theatrical outrage. It is a test of whether a sophisticated AI company can receive a precise legal request without dissolving it into portals, templates, and non-answers.
The method is simple: preserve dates, preserve wording, separate acknowledgement from answer, and leave every unanswered question visible.
The escalation
The correspondence was assembled into a public timeline and prepared for regulatory escalation. The movement did not begin because one email went badly. It began because the file made a repeatable pattern inspectable.
What you can do
File your own request. Keep the delivery receipt. Save every reply. Ask which questions were answered and which were merely redirected. Then make the record legible to someone who was not in the room.