Leaked EU Proposals Could Grant AI Companies Unrestricted Access to Personal Data
Brussels, Monday 21 September 2026
A leaked EU Council proposal would allow AI firms to train models on personal data without consent, sparking fierce backlash over the ‘digital expropriation’ of European citizens’ privacy.
A Regulatory Fast-Track in Brussels
On 20 September 2026, details emerged of a leaked draft of the EU’s ‘Digital Omnibus’ proposal, circulated by the Irish Presidency of the Council of the EU [1][2]. Originally announced on 1 June 2026 as an initiative to simplify digital regulations such as the General Data Protection Regulation (GDPR) and the European AI Act [6], the leaked document has sparked intense debate [GPT]. Privacy advocacy group Noyb revealed that the European Commission bypassed fundamental rights assessments and consultations with the EU’s data protection expert group, using a ‘fast-track procedure’ to push the legislative changes forward [1][2].
A Regulatory Fast-Track in Brussels
The proposal has gained informal support from Germany and several other member states seeking to promote commercial AI interests [1][2]. However, digital rights experts have raised alarms over the speed and secrecy of the negotiations [GPT]. Anabel Arias, a digital rights expert at CECU, warned that under the guise of simplification and competitiveness, these changes threaten to severely weaken fundamental rights and consumer protections [6]. With an informal vote scheduled for Friday, 25 September 2026, member states are expected to submit their opinions by the end of the week [3][6].
The Loophole of ‘Legitimate Interest’
At the heart of the controversy is Article 88bis (previously numbered as Article 88c), which proposes that processing personal data for the development and operation of AI systems automatically qualifies as a ‘legitimate interest’ under GDPR Article 6(1)(f) [1][3]. This legal reclassification would allow AI developers to bypass the explicit consent of European citizens, enabling them to process historical user data, chat histories, and social media archives collected over the last 20 to 30 years [1][4][6]. Max Schrems, the prominent Austrian jurist and founder of Noyb, warned that this would make everything Europeans have ever entered into digital systems ‘fair game’ for AI corporations [1][3][6].
The Loophole of ‘Legitimate Interest’
The draft proposal also includes measures that critics argue would dismantle core GDPR protections [GPT]. Proposed Article 25a introduces a narrow definition of personal data that excludes pseudonymised tracking identifiers, such as IP addresses and device IDs, effectively allowing tech companies to decide what constitutes personal data [2][6]. Furthermore, the amendments would allow companies to reject data subject rights requests if they deem them to be ‘abusive’ [1][2]. Schrems argued that these changes are drawn directly from the playbook of major law firms representing Big Tech, transforming safeguards into loopholes and making EU law increasingly complex and unenforceable [1].
Geopolitical and Industrial Implications
The geopolitical ramifications of the proposed framework are significant, as the rules could facilitate the transfer of EU-collected data to service providers in the United States and China [1][2]. Critics argue that this would severely disadvantage smaller European startups that lack the massive capital and data reserves of foreign tech giants [1][6]. Schrems described the policy as ‘industrial madness’, noting that it acts as a total sell-off of European data to large international corporations [6]. This shift comes at a time when US-based email providers, such as Google and Microsoft, are already facing legal scrutiny over transatlantic data transfers under the EU-US Data Privacy Framework [5].
Geopolitical and Industrial Implications
Under the US CLOUD Act, US-based providers must comply with federal data handover requests regardless of where the servers are located, a limitation that Microsoft France confirmed under oath in June 2025 [5]. While standard Google Workspace or Microsoft 365 plans cost between €6 and €8 per user per month [5], European alternatives such as Dutch-hosted services start at just €1.99 per mailbox per month [5], representing a cost reduction of 66.833% at the entry level. By easing data transfer restrictions under the GDPR for AI training, Brussels may adopt far more permissive regulations than previously anticipated, potentially accelerating the flow of European data abroad [2].
Legal Challenges and the Path Ahead
The legislative proposal must still navigate a complex approval process, including review by the European Parliament, trilogue negotiations, and potential future litigation [2]. The Irish Presidency aims to reach a consensus and approve the Digital Omnibus before 31 December 2026 [6]. Meanwhile, the EU has already initiated delays on specific provisions of the AI Act, with heavier documentation and oversight duties for high-risk sectors postponed until 2 December 2027 [5]. However, the European Parliament remains deeply divided over the issue, with the European People’s Party (EPP) favouring digital law loopholes while centre-left and far-right factions oppose giving ‘free passes’ to Big Tech [1].
Legal Challenges and the Path Ahead
If the Digital Omnibus is approved in its current form, the ultimate battleground will likely be the Court of Justice of the EU (CJEU), which has a strong historical precedent of striking down EU legislation that violates fundamental rights [1][2]. The CJEU previously invalidated transatlantic data transfer agreements in the landmark Schrems I and Schrems II rulings [5]. As European policymakers prepare for the upcoming informal vote on 25 September 2026, the tech industry and privacy advocates alike are closely watching whether Brussels will prioritise commercial competitiveness or maintain its position as a global standard-bearer for data privacy [3][6].