X updated its privacy policy to let the company use data X collects to train its AI models; Musk says X may use “just public data, not DMs or anything private”
X's recently updated privacy policy informed its users it would now collect biometric data as well as users' job …
Context & Ripple Effects
X had just expanded the categories it says it collects to include biometric, job and education information in an earlier privacy-policy update. The AI-training provision therefore makes data governance central to how the platform can build its own models, while Musk's public-data-only statement draws a narrower boundary than the policy language alone may imply.
The move also fits X's effort to treat platform content as a controlled AI input: it was soon paired with a ban on unauthorized scraping and crawling, and later extended to third-party model-training collaborators through an opt-out framework.
First-order effects
- X gains a stated policy basis to use data it collects for its AI models, while users must assess whether the stated public-data limit matches the policy's practical scope.
- The distinction between public content and DMs or other private material becomes the immediate trust and accountability boundary for X and Musk.
Second-order effects
- A platform that reserves collected content for its own models can reduce the availability of that material to outside AI developers, especially when paired with restrictions on scraping.
- Privacy-policy language becomes a competitive lever: other platforms must weigh broader training rights against user trust, while AI builders may need licensed access rather than open-web collection.
Third-order effects
- If this pattern holds, social platforms may increasingly separate public visibility from permission to reuse data for model development, making consent design and access controls part of AI competition.
- X's later shift toward allowing third-party collaborators to train on user data suggests platform data can evolve from an internal model input into a governed, potentially commercial AI asset; the durability of that model depends on clear user controls and enforcement.
The trend: Consumer platforms are turning control of user-generated data into a strategic AI asset, defining who may train on it and under what permission boundary.