Skip to main content
GDPR ReformPolicy Leak· 3 min read· in Technology

Leaked EU Council Draft Proposes Default AI Training on European Personal Data

A leaked proposal from EU member states would amend the GDPR to allow artificial intelligence companies to train models on user data without explicit consent.

By Naina Verma

Privacy Advocates 50%AI Industry & Pragmatists 50%
Privacy Advocates
Argue that the proposal is a corporate giveaway that dismantles the GDPR and legalizes the non-consensual mass scraping of European citizens' personal data.
AI Industry & Pragmatists
Maintain that strict consent requirements make training frontier models technically impossible, threatening to leave Europe technologically isolated and economically uncompetitive.

Perspectives this story doesn't cover

  • European Parliament Members
  • Data Protection Authorities (DPAs)

Why it matters

If adopted, the amendment would fundamentally alter Europe's privacy landscape, shifting the burden of protecting personal data from the companies scraping it to the individuals trying to opt out. It would provide a massive, frictionless data pipeline for AI developers at the direct expense of the GDPR's foundational consent principles.

Privacy advocates argue that a newly leaked European Council document represents the quiet dismantling of the continent’s foundational data protection laws, handing tech companies a blank check to scrape personal information for artificial intelligence training. European member states, conversely, position the exact same text as a necessary modernization of the General Data Protection Regulation (GDPR), arguing that without a default pathway to utilize public data, the bloc's domestic AI industry will be permanently outpaced by American and Chinese competitors.[1][5]

The friction centers on a leaked draft proposal circulating among EU member states, which introduces a new provision—often referred to as Article 88bis—that would explicitly make the use of personal data for AI training lawful by default. Under the current GDPR framework, companies must establish a specific legal basis, such as explicit user consent or a strictly defined "legitimate interest," before processing personal data, a hurdle that has stalled several high-profile model launches in Europe.[3][4][5][6]

According to the leaked text, the unconditional right for European citizens to opt out of having their data ingested by machine learning models would be dropped entirely. Instead, the burden would shift to the user to navigate complex, often opaque technical mechanisms to shield their information from web scrapers, provided the AI companies even offer a functional opt-out mechanism.[1][3][4]

The privacy rights organization NOYB (None of Your Business), which published the leak on September 21, 2026, has aggressively condemned the proposal. The group described the draft as a "digital expropriation" of European citizens, engineered specifically to serve the commercial interests of generative AI developers. Max Schrems and his organization argue that the amendment effectively legalizes the mass scraping practices that data protection authorities across the bloc have spent the last two years investigating and penalizing.[3][5]

Generative AI models require trillions of tokens of data to map statistical relationships, creating friction with strict European privacy laws.
The privacy rights organization NOYB (None of Your Business), which published the leak on September 21, 2026, has aggressively condemned the proposal.

From a technical perspective, the proposal addresses a genuine bottleneck in frontier model development. Generative AI systems require trillions of tokens of text and billions of images to map the statistical relationships that allow them to function. Filtering out European personal data from these massive, globally scraped datasets is computationally expensive and technically imprecise, leading many developers to simply delay launching their models in the EU rather than risk massive fines.[2][6]

The draft suggests that member states are growing increasingly anxious about this technological isolation. By loosening the GDPR's strict consent requirements, the Council appears to be prioritizing the growth of a domestic AI ecosystem over the strict interpretation of privacy rights that has defined European tech policy for the last decade. The marketing language surrounding "AI innovation" often frames this as a necessary compromise for economic survival.[2][6]

Under the proposed changes, the burden would shift to individual users to actively opt out of having their data scraped for AI training.

However, critics point out that this framing ignores the reality of what the models actually do with the data. Because large language models compress and memorize aspects of their training data, personal information ingested during training can sometimes be regurgitated in response to user prompts. This creates permanent privacy vulnerabilities that cannot be easily patched or deleted once the model weights are finalized.[1][5]

The leaked draft is currently being negotiated behind closed doors by the member states in the Council of the European Union. If the member states agree on a common position, the text will still need to survive negotiations with the European Parliament, which has historically taken a much harder line on data protection and user consent. The outcome will dictate whether Europe remains a strict privacy regulator or pivots to accommodate the data demands of the generative AI boom.[4][6]

What to know

  • A leaked EU Council draft introduces a clause allowing AI models to train on personal data by default.
  • The proposal removes the unconditional right for users to opt out of data scraping.
  • Privacy advocacy group NOYB characterizes the move as "digital expropriation" of European citizens.
  • Proponents argue the loosening is necessary to keep European AI developers competitive globally.

Where opinion splits

Privacy Advocates

View the proposal as a fatal blow to the core principles of the GDPR.

Organizations like NOYB argue that the GDPR was explicitly designed to prevent the exact scenario the Council is now proposing: the mass, non-consensual harvesting of personal data for corporate profit. They point out that AI companies have already scraped the internet without asking, and this retroactive legislative effort is merely an attempt to legalize bad behavior rather than enforce existing laws. By removing the unconditional opt-out, advocates warn that citizens will be left defenseless against automated data extraction.

EU Member States & AI Industry

Argue that the current regulatory framework is incompatible with modern machine learning.

Proponents of the loosening argue that the GDPR was written before the advent of large language models and that its strict consent mechanisms cannot be applied to datasets containing trillions of words. They warn that if developers are forced to guarantee the absence of European personal data in their training sets, they will simply stop offering their most advanced models in the EU. For member states focused on economic growth, this technological isolation poses a greater long-term threat than the abstract privacy risks of model training.

Sources

Source coverage

6 outlets

2 viewpoints surfaced

Privacy Advocates 50%AI Industry & Pragmatists 50%
  1. [1]CybernewsPrivacy Advocates

    EU proposal could let AI companies train on Europeans' data by default, noyb warns

    Read on Cybernews →
  2. [2]Polaris7AI Industry & Pragmatists

    Regulation Market: EU Council Proposes GDPR Loosening for AI Training

    Read on Polaris7 →
  3. [3]ResultsensePrivacy Advocates

    noyb: leaked EU draft makes AI data use lawful by default

    Read on Resultsense →
  4. [4]PPC LandAI Industry & Pragmatists

    EU Council draft drops unconditional opt-out from GDPR AI clause

    Read on PPC Land →
  5. [5]NOYBPrivacy Advocates

    AI: EU Member States plan “digital expropriation” of Europeans in the interest of AI companies

    Read on NOYB →
  6. [6]DemócrataAI Industry & Pragmatists

    The EU is studying allowing large AIs to use personal data without consent.

    Read on Demócrata →

Comments

Stay informed

Every angle. Every day.

Get Technology stories with full source coverage and perspective breakdowns delivered to your inbox.