Security1 distinct publisher3 min readUpdated
The Autoriteit Persoonsgegevens says livestreams are personal data, faces included. Twitch's product chief says the setting is on by default because nobody would opt in.
The Watch · Security desk
Compiled by The WatchSomething wrong?How this is made
The Dutch data protection authority, the Autoriteit Persoonsgegevens, has publicly advised Twitch users to opt out of sharing their data with Amazon's AI [1]. It matters because the platform's own chief product officer has already explained the design: "If it's opt-in, nobody would opt in. That's the honest answer. So, it's going to be on by default," Mike Minton said in an interview [5].
That is an unusually clean test case. Twitch is owned by Amazon [2], is one of the largest livestreaming platforms in the world with millions broadcasting and watching every month [3], and allows Amazon to use platform content to train generative AI models with the setting enabled by default [4]. The AP's objection is about what is in that content: "Live streams on Twitch show the gamer's face, voice and name, and often include images of a private space, such as a bedroom. This constitutes personal data. In the case of facial images, this even involves sensitive personal data. Once these data are stored in Amazon's AI systems, they cannot simply be removed. As a result, users lose control over their data. Users' chats and text messages also serve as training material for Amazon" [6].
The sequence is worth pinning down. According to Ars Technica, the AI training itself is not new; what is new is the ability to opt out, and that setting arrived more than two years after a company executive confirmed Amazon was using Twitch content for AI training [8]. In April 2024, Minton said Amazon was using Twitch content to prototype AI models, though not yet at "production scale" [9]. So the control landed no earlier than April 2026, on data that had been flowing since at least the earlier admission [1].
The opt-out is also narrower than it looks. The setting sits in the Streamer Dashboard under Settings > Security and Privacy, near the bottom of the page, which is the basis for reporting that it was hard to find [7]. Its own description says turning it off does not opt a user out of Twitch and Amazon using channel content for other purposes described in the Twitch Privacy Notice, including AI-supported features for streamer growth and monetisation, viewer discovery and community safety such as AutoMod [11]. And if you post in someone else's chat, whether that text can be used for training depends on that streamer's setting, not yours [12]. In practice, no individual user can fully remove their own words from the training pool by changing their own switch [2].
Two things to watch. First, whether the AP escalates: on the record supplied, its intervention is consumer advice to switch a toggle off, not an announced investigation or penalty [3]. A regulator that describes facial images as sensitive personal data and the ingestion as irreversible has laid out the elements of a case; whether it files one is a different decision. Second, whether the chat carve-out survives contact with a regulator, because it makes the individual's consent depend on a third party's dashboard setting [12]. Malwarebytes, which reported the AP advisory, endorsed its recommendation to turn the setting off [13].
Follow any of these and your For You feed starts watching them — no settings page required.
Ranked by verification strength, evidence, and original report placement.
The Dutch Autoriteit Persoonsgegevens (AP) has advised Twitch users to opt out of sharing data with Amazon AI.
Twitch launched as a live-video platform and is currently owned by Amazon; its core product is live broadcasting with a built-in chat culture.
Twitch is one of the world's largest livestreaming platforms, with millions of people broadcasting and watching content every month.
Twitch allows Amazon to use content from its platform to train generative AI models, with the setting enabled by default.
Twitch Chief Product Officer Mike Minton said in an interview: "If it's opt-in, nobody would opt in. That's the honest answer. So, it's going to be on by default."
The AP argues: "Live streams on Twitch show the gamer's face, voice and name, and often include images of a private space, such as a bedroom. This constitutes personal data. In the case of facial images, this even involves sensitive personal data. Once these data are stored in Amazon's AI systems, they cannot simply be removed. As a result, users lose control over their data. Users' chats and text messages also serve as training material for Amazon."
Evidence-backed comparisons of source perspectives and observed adoption signals. Read the methodology
Which Builder, Operator, and Investor concerns the observed source mix emphasized—not a truth score.
Evidence, demonstrated adoption, hype gap, incentives, and confidence are assessed independently, each on its own current evidence. How these are measured.
Concrete product detail, single-publisher sourcing
The strongest evidence is directly checkable in-product material: the verbatim setting description and the exact dashboard navigation path, plus a named-executive quote and a quoted regulator rationale. Against that, the entire cluster is one security-vendor blog post, the AP position arrives without a primary document link, the timeline element is relayed second-hand from Ars Technica, and neither Twitch nor Amazon is given a response beyond the quoted line.
Shipped platform-wide, opt-out uptake unmeasured
The mechanism is not a proposal: the toggle exists in production on a platform the source describes as one of the largest livestreaming services with millions of monthly broadcasters and viewers, it defaults to on, and executives have confirmed the underlying training use since April 2024. What is entirely unmeasured is behaviour: no data on how many streamers have opted out, how much content has been ingested, or whether training has moved past prototype to production scale.
Mildly overstated framing on solid facts
The underlying facts are documented and unflattering on their own terms, but the presentation runs ahead of the record: escalating framing ('Wait, it gets worse'), an assertion that Twitch makes opting out deliberately difficult rested only on the setting's page position, and a regulator advisory presented with enforcement-like weight when no probe or penalty is described. The closing VPN promotion also does not address the described risk, which is platform-side data use rather than network surveillance.
Vendor-adjacent publisher, self-interested subject
Both ends of this story carry incentives. The sole publisher sells privacy software and closes the piece with a paid VPN pitch, giving it a commercial interest in heightened privacy alarm; the disclosure is not made in the text. On the subject side, Twitch's product chief states plainly that the design is default-on because opt-in would fail, an admission that data acquisition for Amazon's models is the driving interest, while the regulator's incentive is to assert jurisdiction over a large foreign platform.
Checkable specifics, no corroboration
Confidence is held down by single-publisher sourcing, a second-hand timeline, no primary regulator document and no company response, and lifted by the fact that the most consequential specifics (default-on state, setting path, scope-limiting copy, chat-owner asymmetry) are precise and independently checkable inside the product.
invest
Behind-the-meter gas is the data center buildout's real cost: 318 Mt a year1 distinct publisher
build
The FCC closed the border on imported robots, so RoboStore is becoming a factory1 distinct publisher
leadership
Sponsorship Is Not Retention: What An Amazon H-1B Win Still Does Not Buy1 distinct publisher
security
OpenAI's 13-17 tier turns teen AI safety into an age-assurance problem1 distinct publisher
Distinct publishers with included, body-backed reporting in this cluster.
1 article · August 20, 2026