Professional social networking giant LinkedIn, a wholly owned subsidiary of Microsoft Corp., has found itself under intense regulatory scrutiny across Europe after quietly altering its privacy settings to feed members' profile information, posts, articles, and video uploads into generative artificial intelligence training pipelines.

The controversy erupted after cybersecurity researchers and privacy advocates discovered that LinkedIn had introduced a new account toggle—labeled 'Data for Generative AI Improvement'—which was pre-selected to 'On' by default for hundreds of millions of users globally before the company formally revised its public terms of service.

Quiet Policy Updates and Default Data Harvesting

Under the policy, user-generated content, professional resumes, and interaction history can be utilized to train proprietary AI models operated by LinkedIn and its corporate parent Microsoft, which powers AI writing assistants, automated job matching algorithms, and enterprise recommendation engines.

The quiet rollout immediately drew the ire of European regulators. The UK Information Commissioner's Office (ICO) intervened swiftly, expressing deep dissatisfaction with the lack of upfront notification and transparent consent. Following urgent engagements, the ICO confirmed that LinkedIn had agreed to suspend training AI models on data belonging to UK members while regulatory reviews proceed.

“Organizations must be completely transparent with the public about how their personal information is used. We welcome LinkedIn's decision to pause the use of UK user data to train generative AI while our inquiries continue.”

European Regulatory Backlash and Consent Frameworks

Simultaneously, the Irish Data Protection Commission (DPC)—LinkedIn's primary supervisory authority within the European Union under the General Data Protection Regulation (GDPR)—launched formal inquiries to evaluate whether the platform had established a valid legal basis for data processing, such as legitimate interest versus explicit, freely given user consent.

LinkedIn stated that it currently exempts users located in the EU, European Economic Area, and Switzerland from the default toggle due to strict regional privacy statutes. Nonetheless, consumer protection groups argue that automatically opting in international users without explicit affirmative consent violates international transparency norms and sets a troubling precedent for social networks monetizing proprietary user data.

Sources