
Opt-out
Opt-out refers to a rule where something is permitted by default and one must actively object if one does not want it. Online, this mainly concerns the question of whether one's own data, texts, or images may be used to train AI systems.
An opt-out is a rule based on the principle of “allowed until someone objects.” A company may therefore do something with your data as long as you don’t say otherwise. If you don’t want it, you have to take action yourself: remove a checkbox, change a setting, or write an email. The counterpart is called opt-in. There, everything is forbidden until you expressly consent. The difference sounds small, but it determines what happens to the data of most people.
Why the default setting decides almost everything
People rarely change default settings. This is well documented: anyone filling out a form usually leaves the preset settings as they are. With opt-out, this means that almost all users take part without ever having consciously consented. With opt-in, it’s the other way around—there, many are left out.
For companies, this makes an enormous difference. An advertising network with opt-out reaches practically all customers. The same network with opt-in might reach only a tenth of that. That’s why there is fierce debate over which of the two procedures applies. It’s not about wording, but about billions of dollars and very large amounts of data.
Critics consider opt-out a sham choice. The option to object exists formally, but hardly anyone actually finds it. Proponents, on the other hand, argue that opt-in would make many useful services impossible, because too little data would come together.
How an objection technically works
The simplest case is a toggle in the user account. With ChatGPT, for example, you can set it so that your own chats are not used to improve the model. Such settings take effect immediately, but only apply going forward. What has already flowed into the training can practically no longer be removed.
For entire websites, there is a second approach. In a file called robots.txt, an operator specifies which automated programs are allowed to read their pages. Such programs, called crawlers, collect texts and images for search engines and for AI training. Major providers have given their crawlers their own names so that they can be specifically blocked. However, this procedure relies on voluntary compliance, since the file technically stops no one.
A common misconception is that an opt-out works retroactively. It doesn’t. A model that has already been trained on a text does not forget it because of a later objection. Retraining would be technically possible, but it costs millions. That’s why timing matters a great deal with opt-out.
Opt-out in copyright law and in AI products
In the EU, opt-out is the basic rule for AI training with third-party content. Copyright law permits so-called text and data mining, meaning the automatic analysis of large amounts of text. However, rights holders may object to this if they do so in a machine-readable way. This rule underlies many disputes between publishers and AI companies.
The principle also appears in well-known products. Social networks like Instagram or LinkedIn have announced that they will use their users' posts for AI training, with an opt-out option buried in the fine print. Image platforms offer artists forms to remove their works from future datasets. Anyone who reads news about AI regularly comes across such announcements.
It’s important to distinguish this from consent under data protection law. For particularly sensitive data, such as health data, an opt-out is not sufficient in Europe. There, explicit consent is required. Opt-out is therefore not a blank check, but a rule for certain, less sensitive cases.