If you consider yourself to be AI-pilled, you’re admitting to having a huge blindspot.
But the premise for being AI-pilled is not a bad one necessarily.
The latest frontier in AI is quite capable in many ways.
Despite many of the overpromises generated by the current hype cycle, AI can be pretty useful tools.
AI can greatly enhance the individual when used correctly. It can be an incredibly powerful tool for ideation, brainstorming, research, analysis and generating stuff.
It makes expertise more accessible (you can just prompt LLMs using natural language) and can produce it cheaper and faster than any human.
One consequence of this on a larger scale is that it encourages whole teams to converge on the outputs, patterns and artefacts generated by AI systems. Their advanced capabilities come with a dazzling hypnotic pull whereby AI-generated work is almost treated as gospel.
I have previously characterised this as AI being a modern leviathan; people entrusting more and more aspects of their lives to AI with the expectation that, because these systems are said to be highly capable, this entrustment will provide those people with everything they need. It is about trading agency for technological progress.
When this happens across entire teams or companies, AI has a kind of coordination effect. It can be used to make sense of the unstructured information that is spread out everywhere. In doing so it helps produce a shared model of that knowledge that everyone can work from to help make decisions or produce further work.
And because of this, AI becomes particularly attractive as a means for automation. Lots of teams will opt to use AI for automating processes that feature lots of unstructured, varied and seemingly unpredictable data and turn it into structured, consistent and actionable outputs.
But then herein lies the problem with being AI-pilled.
Teams with a rather blind trust in AI are extremely tempted to automate all kinds of processes, take humans out of the loop and just leave systems to run autonomously with little-to-no supervision.
But when things inevitably go wrong, and it impacts people, who is to be held accountable? What is the process for appeal or remediation? Or even an explanation?
Accountability gets pretty blurry when we completely delegate things to machines, and the more important the things we are delegating the more consequential it is when those machines do something harmful.
This is the kind of misalignment that AI x-risk people warn about on a much broader scale, but it happens in a lot of other contexts where the ramifications are way more visible and occuring today now rather just existing as grand predictions or forecasts.
When I saw YouTube’s purge of ASMR channels on its platform last month, these are exactly the thoughts that came to mind.
Almost all platforms use some sort of AI to carry out content moderation. And this is because of the advantages that AI provides for such a task, namely speed and scale.
But when AI-assisted content moderation goes wrong, or is done in an opaque manner, the impact on users is significant. This is especially when many of the ASMR artists impacted relied on their YouTube channels as a source of revenue and livelihood.
In this post, try to unpack what has happened, parse the confusion around these channel terminations and set out the legal implications for YouTube and the potential options available for creators looking for a possible reprieve.
It should be noted though that the views expressed here are all my own and is provided for general information only and does not constitute legal advice on which you should rely. You must obtain professional or specialist advice before taking, or refraining from, any action on the basis of the content in this newsletter.
The what and why
In late July of this year, several ASMR channels on YouTube were terminated. Not given warnings, or restricted or de-monitised, but completely and irrevocably wiped.
The termination emails appear to be identical across the ASMR creators that publicly shared them. Those emails stated the following:
We have reviewed your content and found severe or repeated violations of our sex and nudity policy. Because of this, we have removed your channel from YouTube.
[...]
Explicit content that’s meant to be sexually gratifying isn’t allowed on YouTube.
This hit several well-established channels in the ASMR space, some of whom had as many as 250,000 subscribers and had been creating content for almost 10 years.
The exact scale of these terminations is not quite known. YouTube has not made any formal statement on the matter, apart from a statement it gave to 404Media which was the first media outlet to report on the story, and so we have no figures on the number of channels affected.
As perhaps expected, many creators tried to appeal these terminations, but it seems that none of them have had any luck. Instead of a successful reversal, creators were met with emails confirming YouTube’s initial findings and stating that it will not put their channels back on the platform.
There is some very noticeable confusion about the grounds on which YouTube has carried out these terminations.
The text from the initial email notification creators received cited “severe and repeated violations of [the] sex and nudity policy” based on the content uploaded to the channels.
However, the 404Media article includes a statement from YouTube which says something slightly different:
We terminated these channels for linking to content that violates our nudity and sexual content policy...Our external link policies apply equally to all creators across YouTube, and this action was taken in accordance with our long-standing policies, not as a change in policy or targeting of ASMR content.
Furthermore, as shown further above, the emails creators received when their appeals were rejected again claimed that the channel terminations were sustained on nudity and sexual content grounds.
So which is it? Did creators breach the sex and nudity policy, or external links policy, or both?
This encouraged me to dig into the policies a bit more.
The first is the nudity and sexual content policy. YouTube defines such content as “explicit content meant to be sexually gratifying” and this is strictly not allowed on the platform. Creators are therefore not permitted to post content that depicts “clothed or unclothed genitals, breasts, or buttocks that are meant for sexual gratification” nor “Pornography, the depiction of sexual acts, or fetishes that are meant for sexual gratification.”
This policy also lists the kind of considerations YouTube makes when age-restricting content. This includes, among other things, “Whether the subject is depicted in a pose that is intended to sexually arouse the viewer” and “Whether the subject’s actions in the video encourage sexual arousal.”
It is important to note that this policy applies not just to the videos themselves. ‘Content’, for the purposes of the policy, includes “video descriptions, comments, live streams, audio, and any other YouTube product or feature.”
Ordinarily, ASMR is intended for relaxation and some people even use it to help them sleep. But there are erotic versions of this content that is more explicitly sexual. There is therefore a grey area in between that YouTube’s is trying to moderate in accordance with its policy.
The second relevant policy here is the external links policy. This policy states that links sending users to content that violates Community Guidelines are not allowed on YouTube. The policy provides a non-comprehensive list of the types of content that is not permitted in this context, including links to pornography.
The external links policy is relevant here because at least some of the creators who had their channels terminated also make adult content on other platforms. However, creators do not always link this adult content directly in their YouTube content. Instead, they place a drop page in their YouTube channel descriptions, such as a Linktree, link.me or Beacons, which aggregates links to their TikTok, Instagram, Amazon wishlist or platforms like OnlyFans and Fansly.
It seems like drop pages featuring any links to platforms permitting adult content were deemed a violation of the external links policy, and YouTube terminated those channels accordingly.
But how?
One of the key unanswered questions about this case is whether any AI was used as part of the termination process. I think the answer is likely yes.
The first clue is the contradictory statements from YouTube about the basis on which it terminated the channels. Its statement to 404Media cites the external links policy, yet the emails that went out to creators cite the nudity and sexual content policy. The lack of cohesion may suggest that the terminations took place on the basis of some automated process which YouTube has later tried to understand and justify, though with a mismatch in reasoning.
Secondly, the template email notifications for termination and the appeal decisions also suggest a heavy use of automation. From the creators that have shared screenshots of these emails, I am yet to see any that are specifically tailored to the recipient and their channel - they all look the same.
Thirdly, YouTube has itself described more generally the hybrid approach it takes to content moderation which consists of a mixture of automated processes and human review. Its automated systems, which use machine learning models trained on prior human review decisions, will automatically make decisions when they “have a high degree of confidence that content is violative.”
But for these ASMR channel bans specifically, we don’t know if AI was used or, if it was, to what extent it was used. YouTube’s support pages suggest that it is possible that these terminations took place on an automated basis, which is in addition to the other evidence supporting this idea, but it seems for now that nobody really knows.
And so what does the law say?
On balance I think AI likely played some role in the terminations carried out by YouTube, which certainly has implications under data protection law in the EU and in the UK.
The EU GDPR
As with any legislation, the first essential question to ask is one of scope: does the EU GDPR apply to YouTube’s ASMR terminations?
The Regulation applies to the processing of personal data (essentially any information that can be used to directly or indirectly identify an individual) that takes place in the EU. This can take place in two different ways:
The organisation processing the data has a presence in the EU
The organisation offers goods or services to or monitors the behaviour of EU-based data subjects (to the extent that behaviour takes place in the EU)
Both are satisfied here. Google has an office in Ireland (Google Ireland Limited) and, in the context of these channel terminations, processing video descriptions, bios or any other information about a channel of a creator to determine policy violations is well within the realms of the GDPR’s scope.1 This is as long as the creator is based in the EU.
If the GDPR does apply, the most pertinent provision here would be Article 22, which regulates automated individual decision-making. By default, that provision prohibits such decision-making unless there is a basis for doing so and certain measures are in place that involve giving certain rights to affected data subjects.
An automated decision means “a decision based solely on automated processing, including profiling, which produces legal effects concerning him or her or similarly significantly affects him or her.” This definition therefore has three distinct limbs:
A decision has been made
That decision has a significant effect on the individual
That decision made be solely by automated processing
Case law from the Court of Justice of the European Union (CJEU) has interpreted the concept of a “decision” in this context quite broadly, and includes things like “the result of calculating a person’s creditworthiness in the form of a probability value.”2 A channel termination by YouTube is also certainly decision.
The second limb also seems to be met. A decision that produces ‘legal effects’ is one that affects a person’s legal rights or status, such as the termination of a contract.3 A decision that produces ‘similarly significant effects’ is one that does not necessarily affect a person’s legal rights or status but has an impact that is similar, for example decisions made in a recruitment process. In this YouTube case, the decision was the termination of a creator’s channel, which could either qualify as having a legal effect (as it ends that creators’ right to use the service which existed on a contractual basis under YouTube’s/Google’s terms) or a similarly significant effect (those creators were deprived of a means of generating revenue, whether that is from ads or YouTube channel membership subscriptions).
The key question though is whether that decision was based “solely” on automated processing, namely based solely on AI.
As I said before, I do think on balance AI was used as part of the decision-making here by YouTube. And YouTube’s own documentation does state that it uses a mixture of automated processes and human review for its content moderation. But what we don’t currently know is to what extent AI was used, which impacts the legal analysis here.
If a human genuinely applied their own thinking before making the final decision on channel terminations, then Article 22 does not apply.
But there are two things worth noting here.
Firstly, if there was only token human involvement was involved, then this would still constitute automated decision-making under Article 22.4 In other words, if human moderators at YouTube looked at the policy violation raised by an automated system, and simply rubber-stamped that decision without investigating whether that finding by the system was accurate, then this could be construed as automated processing. The human involvement in that scenario would not be meaningful enough to dispel the idea that the termination was essentially made by a machine with effectively no human intervention.
Secondly, the burden of proof is on YouTube. Following the CJEU’s stipulations in the SCHUFA case, Article 22(1) “lays down a prohibition in principle, the infringement of which does not need to be invoked individually by [...] a person.”5
If YouTube’s channel terminations are automated processing under Article 22(1), then it must have a basis to do so under Article 22(2). The only appropriate basis would be under Article 22(2)(a), which states that automated processing can take place if it is “necessary for entering into, or performance of, a contract between the data subject and a data controller.”
For creators to use YouTube and upload videos to the platform, they need to abide by YouTube’s terms and policies, which evidences the contractual relationship between YouTube and the data subject. To ensure that creators comply with those terms and policies, YouTube needs to process their personal data via automated means. The only question here is whether automated processing is truly ‘necessary’, though you can argue here that given the scale and frequency of the content uploaded to the platform, the only feasible way for YouTube to track and flag potential policy violations is by using automated systems, including those using AI.
Even so, to carry out this automated processing, YouTube would need to provide creators with the the right to:
Obtain human intervention. Presumably the appeals made by several creators involved meaningful human review by YouTube moderators, though this is not clear from the emails received.
Express a point of view. That YouTube has an appeal process probably satisfies this, though the appeal would require human involvement.
Contest the decision. This may mean that YouTube needs to provide multiple chances for appeal, though given the apparent finality of the language in the emails for the initial terminations and rejected appeal decisions it does not seem likely that YouTube would grant further appeals on its own volition.
But on this last point regarding contesting automated decisions, data subjects have a further right they can exercise here under Article 15(1)(h). That provision states that data subjects are entitled to obtain from a data controller, regarding automated decisions, “meaningful information about the logic involved, as well as the significance and the envisaged consequences of such processing for the data subject.”
On this, the CJEU has ruled that data subjects are entitled to receive information from the controller (in a concise, transparent, intelligible and easily accessible form) the “procedure and principles” underpinning the decision about them involving the use of their personal data. So EU-based creators can request YouTube to provide such information regarding the termination of their channel, which could be quite instrumental in getting clarity on which policies were allegedly violated and whether there could be any routes to appeal YouTube’s decision further.
One exception here is that, as also recognised by the CJEU, certain information can be redacted by YouTube to protect business or trade secrets.6 But this requires a balancing act to be carried out by YouTube, and the company cannot wholesale reject these requests from data subjects on those grounds.7
The UK GDPR
The position in the UK is slightly different.
The territorial scope for the UK GDPR follows a similar structure to the EU GDPR. Accordingly, the UK GDPR applies to YouTube by virtue of Google having a presence in the UK (its London office) and monitoring the behaviour of UK data subjects. If creators are from the UK, then how their personal data is processed by YouTube needs to follow the UK GDPR.
Under the UK GDPR, a decision is considered to be based solely on automated processing if “there is no meaningful human involvement in taking the decision.”8 Then there is what is called a “significant decision”, which means “a decision that produces a legal effect for the data subject” or “has a similarly significant effect” for them.9 In determining whether there is meaningful human involvement, consideration must be made of “the extent to which the decision is reached by means of profiling.”10
Borrowing the observations made in relation to the EU GDPR, the channel terminations made by YouTube using AI would fit the definition of a significant decision based solely on automated processing. Even so, the key difference with the UK GDPR is that there is no general prohibition of automated processing when using ‘ordinary’ personal data. Restrictions only exist when the processing uses ‘special categories data’,11 which includes the following data types:12
Data revealing racial or ethnic origin, political opinions, religious or philosophical beliefs, or trade union membership
Genetic data and biometric data (when used to uniquely identify an individual)
Data concerning health
Data concerning a natural person’s sex life or sexual orientation
There could be an argument to make that YouTube processed special categories data. The content moderation process here consisted of determining whether a channel either linked to adult sites or itself consisted of sexual content. That inference being generated could be special categories data. But this might be a topic that deserves its own newsletter and more complete analysis.
Regardless, even if no special categories data were used, certain safeguards are required to be put in place by YouTube when making significant decisions via automated means, which more-or-less mirror the safeguards under the EU GDPR:13
Provide creators with information about the decision
Enable creators to make representations about the decision
Enable creators to obtain human intervention
Enable creators to contest such decisions
Also like under the EU GDPR, UK creators can request from YouTube information about the automated decision to terminate their channel, including “meaningful information about the logic involved, as well as the significance and the envisaged consequences of such processing.”14
Additionally, the Data Protection Act 2018 introduces a new right to complain directly to the controller. With this, a data subject “may make a complaint to the controller” if they consider there is an infringement. Accordingly, the controller “must facilitate the making of complaints... by taking steps such as providing a complaint form which can be completed electronically”,15 “must acknowledge receipt... within the period of 30 days”,16 and “must without undue delay (a) take appropriate steps to respond to the complaint, and (b) inform the complainant of the outcome.”17 Appropriate steps include “making enquiries into the subject matter of the complaint, to the extent appropriate” and “informing the complainant about progress.”18
So what can creators do?
Creators based in the EU or the UK have the option to request information from YouTube about the automated decision concerning their channel terminations, which should include an explanation of how the decision was made. This may clarify to what extent AI was used and which policy was actually violated.
Such information could then form the basis for contesting the decision further or, for UK creators, making a formal complaint. Furthermore, obtaining this information could help inform other creators regarding other proceedings that they could pursue.
See in particular to this effect Recital 24 which states that the Regulation covers tracking on the internet “including potential subsequent use of personal data processing techniques which consist of profiling a natural person, particularly in order to take decisions concerning him or her.”
OQ v Land Hessen (Case C-634/21) [ECLI:EU:C:2023:957], para. 46.
Article 29 Working Party, ‘Guidelines on Automated individual decision-making and Profiling for the purposes of Regulation 2016/679’ (2018), p.21.
Article 29 Working Party, ‘Guidelines on Automated individual decision-making and Profiling for the purposes of Regulation 2016/679’ (2018), section IV.A.
OQ v Land Hessen (Case C-634/21) [ECLI:EU:C:2023:957], para. 52.
See also Recital 63.
Case C-203/22, CK v Magistrat der Stadt Wien (27 February 2025), paras. 72-73.
Article 22A(1)(a) UK GDPR.
Article 22A(1)(b) UK GDPR.
Article 22A(2) UK GDPR.
Article 22B UK GDPR.
Article 9(1) UK GDPR.
Article 22C UK GDPR.
Article 15(1)(h) UK GDPR.







