Beyond the Platform: Immutable Portability and the Governance of Persistent Personal AI Profiles

Kenna Young, Maurice McBride

Abstract


Persistent AI memory is transforming artificial intelligence from a session-bound tool into an increasingly individualized relationship. Existing portability regimes allow users to retrieve certain records, but they do not yet govern the broader, evolving body of context, preferences, inferences, relationships, instructions, and provenance that enables continuity across time. This article defines that governance object as the Persistent Personal AI Profile (PPAIP) and proposes Immutable Portability as a governing principle. Immutable Portability combines two propositions: an enduring, non-revocable right and practical capability to retrieve, retain, and transfer a PPAIP in functionally usable form, and a restriction on post-termination beneficial exploitation by a former provider absent a separate legitimate basis. The article situates this proposal against existing European and U.S. portability and AI-governance frameworks, current platform export practices, and emerging work on portable AI memory and personal AI sovereignty. It further argues that effective governance will require interoperable standards, supervision, revision authority, and accountability, while also confronting lifecycle questions involving dormancy, incapacity, death, succession, destruction, and possible economic transfer. These issues warrant anticipatory attention from cybersecurity leaders, policymakers, standards bodies, legal scholars, and technology providers before proprietary dependence becomes structurally entrenched.

Keywords


Artificial Intelligence; Persistent Personal AI Profile; Immutable Portability; Data Portability; Interoperability

Full Text:

PDF

References


Anderson, A., Ahmad, A., & Chang, S. (2024). Case-based learning for cybersecurity leaders: A systematic review and research agenda. Information & Management, 61, 104015. https://doi.org/10.1016/j.im.2024.104015

De Hert, P., Papakonstantinou, V., Malgieri, G., Beslay, L., & Sanchez, I. (2018). The right to data portability in the GDPR: Towards user-centric interoperability of digital services. Computer Law & Security Review, 34, 193–203. https://doi.org/10.1016/j.clsr.2017.10.003

European Parliament & Council of the European Union. (2016). Regulation (EU) 2016/679 (General Data Protection Regulation), Article 20.

European Parliament & Council of the European Union. (2023). Regulation (EU) 2023/2854 on harmonised rules on fair access to and use of data (Data Act).

European Parliament & Council of the European Union. (2024). Regulation (EU) 2024/1689 laying down harmonised rules on artificial intelligence (Artificial Intelligence Act).

Fallatah, K. U., Barhamgi, M., & Perera, C. (2023). Personal Data Stores (PDS): A review. Sensors, 23, 1477. https://doi.org/10.3390/s23031477

Federal Trade Commission. (2020). Data to go: The FTC's workshop on data portability—Summary. Federal Trade Commission.

Gines, D. (2026, February 17). Portable AI Memory (PAM) specification v1.0. https://portable-ai-memory.org/spec/v1.0/

Google. (n.d.). Download your Gemini Apps data. Gemini Apps Help. https://support.google.com/gemini/answer/16920332?hl=en

Guston, D. H. (2014). Understanding 'anticipatory governance'. Social Studies of Science, 44, 218–242. https://doi.org/10.1177/0306312713508669

Hothi, S. (2026). Personal AI sovereignty: From platform data extraction to user-controlled artificial intelligence. SSRN. https://doi.org/10.2139/ssrn.7335879

Microsoft. (n.d.). Manage your Copilot activity history in the privacy dashboard. Microsoft Support. https://support.microsoft.com/en-US/Privacy/manage-your-copilot-activity-history-in-the-privacy-dashboard

OECD. (2024). Framework for anticipatory governance of emerging technologies (OECD Science, Technology and Industry Policy Papers, No. 165). OECD Publishing. https://doi.org/10.1787/0248ead5-en

OpenAI. (n.d.). Exporting your ChatGPT history and data. OpenAI Help Center. https://help.openai.com/en/articles/7260999-how-do-i-export-my-chatgpt-history-and-data

OpenAI. (n.d.). How to delete your account. OpenAI Help Center. https://help.openai.com/en/articles/6378407-how-do-i-delete-my-account

Pentland, S., South, T., Greenwood, D., Pei, J., He, Z., & Moskowitz, B. (2026, March 16). The future of personal AI: Portable and persistent personal memory through a unified human context protocol. Stanford Digital Economy Lab. https://digitaleconomy.stanford.edu/publication/the-future-of-personal-ai-portable-and-persistent-personal-memory-through-a-unified-human-context-protocol/

Perplexity. (2026, July 28). Account deletion. Perplexity Help Center. https://www.perplexity.ai/help-center/en/articles/10354879-account-deletion

Ramezan, C. A. (2025). Understanding the chief information security officer: Qualifications and responsibilities for cybersecurity leadership. Computers & Security, 152, 104363. https://doi.org/10.1016/j.cose.2025.104363

Sahin, Z., & Vance, A. (2025). What do we need to know about the Chief Information Security Officer? A literature review and research agenda. Computers & Security, 148, 104063. https://doi.org/10.1016/j.cose.2024.104063

Uniform Law Commission. (2015). Revised Uniform Fiduciary Access to Digital Assets Act.

U.S. Government Accountability Office. (2019, January). Internet privacy: Additional federal authority could enhance consumer protection and provide flexibility (GAO-19-52). https://www.gao.gov/products/gao-19-52




DOI: https://doi.org/10.53889/citj.v4i2.955

Article Metrics

Abstract view : 0 times
PDF - 0 times

Refbacks

  • There are currently no refbacks.


Copyright (c) 2026 Cybersecurity and Innovative Technology Journal

Creative Commons License
This work is licensed under a Creative Commons Attribution 4.0 International License.