The European Union’s approach to AI regulation is facing a severe credibility crisis as leaked documents reveal a plan by member states to effectively expropriate European digital data for the benefit of AI corporations. Led by the Irish Presidency and supported by Germany, the proposal seeks to amend the GDPR through a 'Digital Omnibus' fast-track procedure, bypassing fundamental rights assessments. The core of the controversy lies in a proposed Article 88bis, which would grant AI companies an automatic 'legitimate interest' to use personal data, effectively removing the requirement for user consent.

The End of Consent for AI Training

Under the proposed changes, any personal data that an AI company can access—whether from decades-old chats, social media posts, or non-customer records—becomes fair game for model training and deployment. This shift moves the legal baseline from specific, consented purposes to a blanket permission for any use 'in the context of AI.' Max Schrems, founder of NOYB, describes this as a 'complete sell-off of European data to global corporations,' arguing that it prioritizes the profits of entities like Google, OpenAI, and Meta over the fundamental rights of Europeans. The proposal essentially legalizes previously prohibited actions, such as using data for personalized advertising without explicit opt-in, provided AI is involved in the process.

Narrowing Definitions and Increasing Legal Ambiguity

Beyond the broad permission for data usage, the proposal introduces significant hurdles for enforcement by narrowing the definition of 'personal data.' The text suggests that 'pseudonymous' data, which includes common identifiers like user IDs, IP addresses, and tracking codes, may no longer fall under GDPR protection. Furthermore, the applicability of the law would depend on a company's 'internal knowledge and capabilities,' a subjective metric that Schrems warns will lead to years of litigation. This move transforms a regulatory framework into a playground for big law firms, where companies can argue that data is no longer personal or that user rights are being 'abused,' thereby drowning procedures in delay and cost.

Key Takeaways

  • Automatic Legitimate Interest: AI companies would no longer need explicit consent to use personal data for training or inference, assuming a blanket 'legitimate interest' overrides user rights.
  • Pseudonym Loophole: Common digital identifiers (IPs, user IDs) may be excluded from GDPR protection if classified as pseudonymous, significantly shrinking the scope of data rights.
  • Fast-Track Procedure: The amendment is being pushed through a simplified legislative process without a fundamental rights assessment, accelerating its path to implementation.
  • Judicial Backlash Likely: Legal experts predict this proposal will face immediate challenges in the Court of Justice of the European Union due to its conflict with established data protection precedents.

The Bottom Line

This proposal trades legal certainty for corporate convenience, likely resulting in more litigation rather than simplification. By removing consent requirements and narrowing definitions, the EU risks undermining decades of data protection standards while primarily benefiting US and Chinese tech giants. The 'fast-track' approach appears to prioritize industrial policy over fundamental rights, setting the stage for a major clash with the European Court of Justice.