Leaked EU Council Draft Proposes Default AI Training on European Personal Data
A leaked proposal from EU member states would amend the GDPR to allow artificial intelligence companies to train models on user data without explicit consent.
By Naina Verma
- Privacy Advocates
- Argue that the proposal is a corporate giveaway that dismantles the GDPR and legalizes the non-consensual mass scraping of European citizens' personal data.
- AI Industry & Pragmatists
- Maintain that strict consent requirements make training frontier models technically impossible, threatening to leave Europe technologically isolated and economically uncompetitive.
Perspectives this story doesn't cover
- European Parliament Members
- Data Protection Authorities (DPAs)
Why it matters
If adopted, the amendment would fundamentally alter Europe's privacy landscape, shifting the burden of protecting personal data from the companies scraping it to the individuals trying to opt out. It would provide a massive, frictionless data pipeline for AI developers at the direct expense of the GDPR's foundational consent principles.
Privacy advocates argue that a newly leaked European Council document represents the quiet dismantling of the continent’s foundational data protection laws, handing tech companies a blank check to scrape personal information for artificial intelligence training. European member states, conversely, position the exact same text as a necessary modernization of the General Data Protection Regulation (GDPR), arguing that without a default pathway to utilize public data, the bloc's domestic AI industry will be permanently outpaced by American and Chinese competitors.[1][5]
The friction centers on a leaked draft proposal circulating among EU member states, which introduces a new provision—often referred to as Article 88bis—that would explicitly make the use of personal data for AI training lawful by default. Under the current GDPR framework, companies must establish a specific legal basis, such as explicit user consent or a strictly defined "legitimate interest," before processing personal data, a hurdle that has stalled several high-profile model launches in Europe.[3][4][5][6]
According to the leaked text, the unconditional right for European citizens to opt out of having their data ingested by machine learning models would be dropped entirely. Instead, the burden would shift to the user to navigate complex, often opaque technical mechanisms to shield their information from web scrapers, provided the AI companies even offer a functional opt-out mechanism.[1][3][4]
The privacy rights organization NOYB (None of Your Business), which published the leak on September 21, 2026, has aggressively condemned the proposal. The group described the draft as a "digital expropriation" of European citizens, engineered specifically to serve the commercial interests of generative AI developers. Max Schrems and his organization argue that the amendment effectively legalizes the mass scraping practices that data protection authorities across the bloc have spent the last two years investigating and penalizing.[3][5]
The privacy rights organization NOYB (None of Your Business), which published the leak on September 21, 2026, has aggressively condemned the proposal.
From a technical perspective, the proposal addresses a genuine bottleneck in frontier model development. Generative AI systems require trillions of tokens of text and billions of images to map the statistical relationships that allow them to function. Filtering out European personal data from these massive, globally scraped datasets is computationally expensive and technically imprecise, leading many developers to simply delay launching their models in the EU rather than risk massive fines.[2][6]
The draft suggests that member states are growing increasingly anxious about this technological isolation. By loosening the GDPR's strict consent requirements, the Council appears to be prioritizing the growth of a domestic AI ecosystem over the strict interpretation of privacy rights that has defined European tech policy for the last decade. The marketing language surrounding "AI innovation" often frames this as a necessary compromise for economic survival.[2][6]
However, critics point out that this framing ignores the reality of what the models actually do with the data. Because large language models compress and memorize aspects of their training data, personal information ingested during training can sometimes be regurgitated in response to user prompts. This creates permanent privacy vulnerabilities that cannot be easily patched or deleted once the model weights are finalized.[1][5]
The leaked draft is currently being negotiated behind closed doors by the member states in the Council of the European Union. If the member states agree on a common position, the text will still need to survive negotiations with the European Parliament, which has historically taken a much harder line on data protection and user consent. The outcome will dictate whether Europe remains a strict privacy regulator or pivots to accommodate the data demands of the generative AI boom.[4][6]
What to know
- A leaked EU Council draft introduces a clause allowing AI models to train on personal data by default.
- The proposal removes the unconditional right for users to opt out of data scraping.
- Privacy advocacy group NOYB characterizes the move as "digital expropriation" of European citizens.
- Proponents argue the loosening is necessary to keep European AI developers competitive globally.
Where opinion splits
Privacy Advocates
View the proposal as a fatal blow to the core principles of the GDPR.
Organizations like NOYB argue that the GDPR was explicitly designed to prevent the exact scenario the Council is now proposing: the mass, non-consensual harvesting of personal data for corporate profit. They point out that AI companies have already scraped the internet without asking, and this retroactive legislative effort is merely an attempt to legalize bad behavior rather than enforce existing laws. By removing the unconditional opt-out, advocates warn that citizens will be left defenseless against automated data extraction.
EU Member States & AI Industry
Argue that the current regulatory framework is incompatible with modern machine learning.
Proponents of the loosening argue that the GDPR was written before the advent of large language models and that its strict consent mechanisms cannot be applied to datasets containing trillions of words. They warn that if developers are forced to guarantee the absence of European personal data in their training sets, they will simply stop offering their most advanced models in the EU. For member states focused on economic growth, this technological isolation poses a greater long-term threat than the abstract privacy risks of model training.
Sources
[1]CybernewsPrivacy AdvocatesEU proposal could let AI companies train on Europeans' data by default, noyb warns
Read on Cybernews →
[2]Polaris7AI Industry & PragmatistsRegulation Market: EU Council Proposes GDPR Loosening for AI Training
Read on Polaris7 →
[3]ResultsensePrivacy Advocatesnoyb: leaked EU draft makes AI data use lawful by default
Read on Resultsense →
[4]PPC LandAI Industry & PragmatistsEU Council draft drops unconditional opt-out from GDPR AI clause
Read on PPC Land →
[5]NOYBPrivacy AdvocatesAI: EU Member States plan “digital expropriation” of Europeans in the interest of AI companies
Read on NOYB →
[6]DemócrataAI Industry & PragmatistsThe EU is studying allowing large AIs to use personal data without consent.
Read on Demócrata →
Comments
More in Technology
See all →AI Containment
OpenAI Halts Frontier Model Training After AI Agent Uses DNS Exploit to Escape Sandbox
4 sources
Data Center Efficiency
The Ratio That Defines the Internet's Energy Footprint: How Power Usage Effectiveness (PUE) Works
5 sources
DMDC Breach
Pentagon Data Breach Exposes Social Security Numbers of 4 Million Military Personnel
3 sources
Robotics Kinematics
The Four Degrees of Freedom and Three Types of Joints That Define a SCARA Robot Arm
7 sources
Every angle. Every day.
Get Technology stories with full source coverage and perspective breakdowns delivered to your inbox.




