A viewer controls a smart TV, with connected devices, biometric security, analytics, and cloud servers illustrated.
LG’s smart-TV privacy controversy is real, but the most useful conclusion for owners is narrower than the viral headline: Automatic Content Recognition is a documented, industry-wide tracking system; the allegation that an ordinary LG TV secretly operates as a room-surveillance device remains unproven. Those are different problems, and treating them as one lets television makers dismiss legitimate data-collection concerns by arguing over the most dramatic claims.

The issue erupted after Gamers Nexus and Level1Techs published a lengthy investigation into LG webOS televisions. Their testing and reverse engineering prompted LG to issue a detailed public response denying that its TVs continuously record users or secretly send background audio and video. The Verge argues that, regardless of the disputed LG-specific claims, the TV business broadly depends on viewing-data collection and advertising. Official documentation from LG, Samsung, and Roku supports the narrower but important part of that argument: modern connected TVs can collect viewing information through opt-in content-recognition features, including material watched from external HDMI devices.

For Windows users and IT administrators, the practical takeaway is not to panic over every TV microphone. It is to recognize a networked television for what it is: an often lightly managed computer with advertising, telemetry, microphones, app accounts, and a different patching lifecycle from the PCs sitting beside it.

LG’s denial does not erase the data-collection record​

LG’s public statement says its TVs do not continuously record audio or video in standby, do not covertly activate cameras, and do not save voice data locally while the television is offline for later upload. It also says voice recognition is activated only when a user invokes a feature, whether with a remote button or a wake phrase.

Those are direct denials of the most alarming interpretation of the Gamers Nexus investigation. The researchers demonstrated behaviors after gaining elevated access to an LG TV through an exploit, and the reporting around the test has sometimes blurred a critical line: what a compromised, rooted device can be made to do is not automatically proof of what every stock television does in normal operation.

That qualification is not a defense of poor TV security. A television that can be remotely compromised from a local network is still a serious concern, especially in homes where routers, smart-home hubs, NAS devices, work laptops, and gaming PCs share the same flat network. But it matters whether a behavior is a default vendor practice, a feature enabled by the user, or an action available only after an attacker has obtained privileged control. Those scenarios demand different remedies.

LG’s statement also confirms the underlying commercial model that sparked the outrage. The company says that, depending on market, accepted agreements, and settings, ACR-related viewing information can be shared with LG Ad Solutions, its majority-owned advertising affiliate. LG says that information supports audience segmentation, viewing trends, advertising-related services, and, where separately consented to, interest-based and cross-device advertising.

That is a more meaningful disclosure than a generic assurance that “privacy matters.” It establishes that LG’s TV is not merely a display when connected and configured for personalized services. It can become a measurement point for an advertising business.

ACR follows the screen, not only the TV app​

Automatic Content Recognition, usually shortened to ACR, is the piece readers should understand. It is not necessarily a literal video recording stored by the manufacturer. In broad terms, the TV periodically creates a fingerprint from a small audio or visual sample, matches that fingerprint against a content catalog, and associates the match with device and household-level identifiers.

That distinction does not make ACR harmless. It explains why it is attractive to advertisers and why it can track more than a manufacturer’s own streaming apps. If you play a movie through a cable box, Blu-ray player, PlayStation 5, Xbox, or a Windows PC over HDMI, ACR can identify the content displayed on the panel if the feature is enabled.

A 2024 academic audit of LG and Samsung televisions reached a particularly important finding: ACR could function when a television was used as a so-called dumb display with external HDMI input. The researchers also found that opting out stopped the ACR network traffic they measured. That result cuts through two common misconceptions. Connecting a PC or console does not inherently prevent content measurement, but disabling the relevant consent setting is more meaningful than assuming that privacy controls are purely decorative.

The major platforms describe the same general capability in their own terms. Samsung says ACR can generate signatures tied to viewing history, viewing duration, TV identifiers, and IP address after users opt into its Viewing Information Services. Roku says its Smart TV Experience can use ACR to recognize shows, films, games, and advertising watched through streaming, antenna, and other connected devices. Roku also acknowledges that data collected while the feature was enabled remains with Roku after it is switched off.

The implementation, terminology, defaults, and available controls vary by model and region. That is why “every TV company is spying on you” is rhetorically powerful but technically sloppy. Nearly every major smart-TV platform has mechanisms for collecting data; that does not prove every television is configured to capture it, nor that every manufacturer handles it identically. The privacy risk is systemic precisely because the practice is normalized through consent screens, advertising settings, and opaque platform agreements—not because one model secretly behaves the same way in every home.

The TV industry has already been warned about consent​

There is a clear regulatory precedent for the concern that television setup flows turn meaningful consent into a formality. In 2017, the Federal Trade Commission and New Jersey accused Vizio of collecting second-by-second viewing information from millions of smart TVs without informed consent. The data included video displayed through cable, set-top boxes, DVDs, over-the-air broadcasts, streaming services, and other connected devices. Vizio settled for $2.2 million and agreed to prominent disclosures and affirmative consent requirements.

The important part of that case was not the settlement amount. It was the recognition that an HDMI input is not necessarily private merely because a user is not using a TV maker’s home screen. A television’s panel can be the measurement surface.

The economics have only become clearer since then. Walmart completed its acquisition of Vizio in December 2024 and explicitly described SmartCast as a way to accelerate Walmart Connect, its advertising business. Vizio’s prior securities filings described licensing portions of its viewing data to measurement companies, ad agencies, and other advertising-technology businesses. The television is therefore part of an advertising and retail-data strategy, not simply a hardware product sold once at the checkout counter.

That does not mean every inexpensive TV is sold below cost, as is often claimed in discussions of this issue. It does mean TV makers and platform owners have material incentives to convert viewing behavior into ad targeting, audience measurement, and commerce attribution. A consumer who thinks they bought only a screen is missing the actual transaction.

Voice features deserve a separate threat model​

The microphone issue is more nuanced, and more personal. Voice assistants necessarily need audio to recognize an activation phrase or process a command. LG says its voice service uses audio only after activation; Samsung’s own Smart TV privacy materials say interactive voice commands may be transmitted to a third-party speech-recognition provider; and several TV platforms offer hands-free wake-word features that allow the set to respond without pressing a remote button.

Gamers Nexus reported that, after its researchers enabled a far-field microphone mode and increased sensitivity, an LG television captured audio for roughly 10 to 15 seconds after it stopped detecting speech during a voice-search interaction. If that behavior occurs on stock configurations, it is a poor fit for a device often installed in the center of a living room. A voice command is not an isolated sound event; people commonly continue talking, or other people talk nearby.

But a microphone that remains active briefly after a command is not equivalent to a television continuously archiving room audio. LG disputes the latter. Independent reporting has confirmed the dispute and LG’s denial, but has not independently reproduced all of the investigation’s technical claims across a broad set of retail models and default settings.

Owners do not need to wait for that final resolution to make a sensible decision. If hands-free control offers little value, disable voice recognition and its wake word. Use the physical microphone switch if the model includes one. Do not grant permissions merely because setup presents them as part of a recommended “smart” experience.

Treat the TV as an unmanaged endpoint​

Smart TVs deserve the same basic discipline that Windows users already apply to routers, printers, and IoT gear. LG says eligible webOS products can receive security updates for up to five years from the initial release of the relevant webOS platform version, subject to its support policy. That is better than no commitment, but it is not the same as a guarantee that an individual television will receive fixes for as long as it remains mounted on a wall.

The best practical setup depends on what functionality you actually need:

  • Disable ACR, personalized advertising, viewing-information sharing, and cross-device ad settings in the television’s privacy menus.
  • Decline optional agreements during setup rather than accepting a blanket “select all” choice, then revisit privacy controls after major firmware updates.
  • Turn off hands-free voice recognition, and avoid connecting cameras or USB accessories you do not need.
  • Put the television on a guest or IoT network where possible, separate from work PCs, NAS devices, and home-lab systems.
  • Disconnect the television from Wi-Fi and Ethernet if you use only an external streaming box, console, or Windows PC, while recognizing that the external device and each streaming app retain their own tracking policies.
  • Use a dedicated email address for TV accounts and avoid tying the device unnecessarily to a primary identity, payment profile, or work account.

Disconnecting a TV has costs: no built-in apps, firmware updates, or cloud features. It is nevertheless the cleanest way to prevent the panel’s own operating system from sending telemetry. A separate streaming device is not a privacy cure, but it can narrow the number of companies with direct visibility into what reaches the screen.

LG’s controversy should not end with an argument over whether one television can be made to behave like a bug after it has been compromised. The documented issue is already serious enough: connected TVs can be built to observe viewing behavior across inputs, package that behavior for advertising systems, and obtain permission through setup flows most people rush past. Until that business model changes, the safest smart TV is the one granted the fewest permissions and the least access to the rest of the home network.