Asking an AI model to forget a concept doesn't make it forget - it just makes it cagier.
A paper posted to arXiv this week, "Suppression Is Not Forgetting: Residual Recoverability in Visual Concept Unlearning for VLMs" (arXiv:2604.03114v2, updated September 2026 despite the April submission stamp baked into its ID), tested what happens when off-the-shelf vision-language models are told to stop naming things they can see. The researchers first confirmed each model could actually recognize a given object, scene, or person from an image, then probed it three ways: multiple-choice, short-answer, and indirect questions. Prompt-based suppression, the cheap, training-free method available to anyone stuck with an API-only model, cut short-answer recall for some concepts. Multiple-choice and indirect recall barely moved, and spelling out the exact list of concepts to suppress sometimes made a model more likely to name one, not less.
That gap matters for anyone treating a system prompt as a compliance fix. If a company can't retrain or fine-tune a model because it doesn't own the weights, telling it "don't identify this person" looks like unlearning. The paper's point is that the concept is still in there and still retrievable, just no longer volunteered under one specific phrasing.
The same caveat held for decoding constraints, representation editing, and even parameter updates in the study, so this isn't purely a prompting problem - it's a reminder that a model going quiet about something is not the same as a model that has forgotten it.