Silence Means ‘Yes’: Big Tech's Quiet Grab of Your Digital Life to Train Their AI-bots
On July 7, 2026, Meta launched Muse Image. It is an AI image generator built directly into Instagram. If your account is public, anyone can now type your username into a prompt and the system will pull your photos as visual references to generate new images of you. Your consent is given by default.
Meta’s own help page states plainly that you will not be notified when your content is used, and switching it off requires digging into the ‘Sharing and reuse’ settings. Though opting out blocks only future generations, not images already created.
Three days later, the feature was gone. On July 10, Meta announced the tool had ‘missed the mark’ and withdrew it, following a backlash from users and so-called scrutiny from Hollywood talent agencies, including Creative Artists Agency (CAA), whose celebrity clients’ likenesses were suddenly available to anyone with a keyboard.
The 72-hour retreat is revealing something important, but not reassuring. Meta conceded no principle. Muse Image itself remains live, the training of AI models on users’ public posts continues, and enrolment by default is still the rule. What the episode demonstrated is the operating logic of the entire industry – big tech platforms no longer ask whether they may use your profile, posts and photos to build or train AI bots. They inform you, quietly or in a way we mostly do not notice or miss and they leave it to you to find the exit.
The notifications most people never saw
Meta set the template. It began training its AI on the public posts of European users on May 27, 2025, and before that, the company sent in-app notifications and emails with a link to an objection form. But the notification appeared alongside routine alerts such as friend requests and group updates, making it easy to miss, and that objecting required multiple clicks and scrolls – in contrast to election reminders, which Facebook pins prominently atop the feed (TechCrunch, 2024). The objection process was cumbersome enough that a single TikTok video explaining it drew more than 4.3 million views.
Also read: As Meta Apologises to Modi, Anti-BJP Content Faces Massive Takedown
LinkedIn followed the same. From 3 November 2025, the Microsoft-owned platform began using member data like profile details, posts, resumes and public activity, reaching back as far as 2003, to train its generative AI models for users in the EU, EEA, Switzerland, Canada and Hong Kong.
The setting was switched on by default; members had to find the ‘Data for generative AI improvement’ toggle and turn it off themselves. Users in India and the United States had already been included since LinkedIn’s 2024 rollout, with no comparable notice period.
The common thread is what lawyers call the opt-out model- silence is treated as agreement. It can also be that you did not see or miss, then also you by default agreed, and the deadlines are one-way doors. Data absorbed into a trained model cannot practically be removed afterwards; opting out protects only future posts, not past ones.
Where India stands: The DPDPA’s open door
For Indian users, even the buried notification never reached. Because no existing law required one. India is Meta’s largest market, with over 500 million WhatsApp users and the highest Meta AI usage in the world, yet it offers its users no way to object to AI training on their public posts.
India’s Digital Personal Data Protection Act (DPDPA), 2023 was meant to change the balance. After two years of waiting, the government notified the DPDP Rules in November 2025. On paper, the law is strongly consent-centric. Under the DPDPA, data fiduciaries must obtain free, specific, and informed consent for each stated purpose, provide itemised notices, and erase personal data upon withdrawal of consent. Consequently, AI companies would be required to justify the collection and use of each data field.
But the Act contains an exemption tailor-made for big tech's AI bots. Personal data made publicly available by the individual falls entirely outside the law’s scope. Importantly, this is an exemption broader than the GDPR’s equivalent. It covers all categories of personal data, so that datasets scraped from public webpages and public social media profiles for AI training may escape the DPDPA altogether. Unlike European law, the Act does not require companies to notify people when their publicly available data is collected and processed.
Also read: Meta Says It Removed 1,60,000 Advertiser Accounts in India After Instagram Ad Scrutiny
Big tech players have clearly read the signal. In April 2025, Meta representatives said that they hoped the DPDPA’s public-data exemptions, alongside India’s copyright provisions, would make the country attractive for AI training and data centres. IAMAI (Internet and Mobile Association of India) has asked the IT Ministry to go further, and exempt data scrapping or processing done solely for AI model training from the Act’s provisions entirely.
Section 3 permits use of public data only where the individual made it public voluntarily and most of what feeds AI models is published by third parties, a tag in someone else’s photo, a mention in someone else’s post, which is clearly showing us that AI training in this respect in what one year-end assessment called a legal grey zone.
India’s most serious pushback has come not from personal privacy law (DPDPA) but from the competition regulator. The Competition Commission of India (CCI) fined Meta Rs 213.14 crore in November 2024 over WhatsApp’s 2021 privacy policy. The appellate tribunal upheld the fine, and the dispute is now before the Supreme Court, where the Chief Justice described Indian users as ‘silent customers’ unaware of how their information is leveraged.
Although the dispute concerns the use of personal data for advertising, it raises a broader policy issue that is whether sweeping data use can be a condition of digital participation, which is exactly the AI training question by another name.
Different data protection regulation models
The Muse Image reversal captures the industry’s operating rule, i.e., platforms respond to leverage, not principle. In Europe, the leverage is law; in Hollywood, it is organised talent; in most of the world, it does not exist. Globally, the map of AI-training rights now splits roughly three ways as follows-
The European model – object, but by default you’re in. The GDPR gives users a formal right to object, which is why notifications and opt-out forms exist in the EU and UK at all. Regulators and courts have so far let the opt-out model stand, for example- Ireland’s Data Protection Commission cleared Meta’s plans in May 2025, subject to improved transparency, and the Higher Regional Court of Cologne dismissed a consumer group’s injunction, holding that training could proceed ‘even without the consent of those affected’. Some other user rights objection incidents in Switzerland, Brazil, Japan and South Korea can be seen.
The US model – no rights, but occasional muscle. The US has no federal data protection law, so Meta offers them no opt-out. Public posts of US users have been used for training since before the company was ever obliged to say so. What US citizens demonstrated this week is that concentrated private power can substitute for absent law. Like the talent agencies representing celebrities, not any regulator, forced Muse Image’s controversial feature that allowed users to modify photos from public Instagram accounts using AI to be taken down in three days.
India’s DPDPA – a consent law with an AI-shaped hole. India now has stringent consent rules on paper. But a public-data exemption that may place the most valuable AI training material beyond the law’s reach, which is leaving its hundreds of millions of users closer to the US position than the European one, despite having a newer law than either.
What we can do
Indians cannot file the objection; Europeans can, but risk mitigation is possible. We can do the following:
- Set Facebook and Instagram accounts to private, restrict the audience of past posts,
- Avoid chatting with Meta AI (those conversations are training material), and
- Review Instagram’s ‘Sharing and reuse’ settings, which continue to govern whether your posts and reels can be used with Meta’s AI features
- LinkedIn users everywhere can switch off ‘Data for generative AI improvement’ under Settings and Data Privacy.
The larger fix, though, is legislative. Europe’s experience shows platforms will build notification systems and objection forms the moment the law demands them. This week showed they can dismantle an invasive feature in seventy-two hours when the right people object. Meta moved in three days for Hollywood’s agents; India’s more than half-billion users are still waiting for their first notification to give them the option to exclude their personal data from AI bot training.
As India’s Data Protection Board begins its work under the new rules, the first test of the DPDPA’s credibility may be whether ‘publicly available’ becomes a loophole wide enough to drive the world’s largest social media population through.
Tuhinsubhra Giri is an International Research Fellow at the Academy of International Affairs NRW, Germany and an assistant professor of economics at Christ University, Bangalore. Views are personal.
This article went live on August twenty-fourth, two thousand twenty six, at thirty minutes past five in the evening.The Wire is now on WhatsApp. Follow our channel for sharp analysis and opinions on the latest developments.





