In my opinion, training models on user data without their real consent (real consent = e.g. the user must sign a contract or so, so he's definitely aware), should be considered a serious criminal offense.
I believe that only concerns European users. Moreover, I believe a simple press of an OK button is fine with GDPR. This data (type and volume) however, is way more serious and can't be agreed on by just pressing a button.