bbieron@platformeconomyinsights.com

EU Commission Expected to Propose GDPR Changes to Ease AI Training

Nov 1, 2025

Report from Computerworld

In Brief – The European Commission is planning to propose revisions of the General Data Protection Regulation (GDPR) intended to ease the ability to train AI systems with data collected in Europe as part of its “Digital Omnibus” simplification proposal. Privacy advocates reacted to a leaked draft with alarm, arguing that it would greatly weaken the EU’s landmark privacy protections. The Digital Omnibus is expected to move cookie regulation from the ePrivacy Directive into the GDPR, creating a new a new Article 88a that would eliminate the current requirement for explicit consent before setting non-essential cookies and allow websites to process data for “low-risk purposes” or under any legal basis recognized by the GDPR. Critics argue that the Commission is using “cookie fatigue” created by user consent pop-ups to justify diluting core privacy standards that prioritize corporate interests over individual rights. A particularly contentious element clarifies that companies would be able to train AI models on personal data under the GDPR’s “legitimate interest” basis if safeguards like transparency and the right to object are observed, which could allow large-scale data mining for AI development. The draft reportedly also narrows the definition of sensitive data, limiting enhanced protection to information that directly reveals protected traits. The Digital Omnibus proposal is expected to be publicly released on November 19.

Context – One growing European “digital sovereignty” concern is that the continent’s AI industry is not keeping pace with the US and China. The Commission is engaged. In October it announced two initiatives to promote AI development and use, which followed the Commission’s April “AI Continent Action Plan”. Many of Europe’s AI tech firms and investors argue that the bloc’s regulatory and tax environment is too cumbersome and is slowing development. Not only is the EU’s AI Act the most aggressive AI regulatory regime, but regulatory overlaps involving other digital regimes, including the GDPR and DMA, continue to crop up, reinforcing regulatory concerns given voice in last year’s Draghi Report.

View By Monthly
Latest Blog
SpaceXAI Fails to Block Minnesota Law Banning “Nudification” Apps

Report from Politico In Brief – Federal Judge Donovan Frank rejected SpaceXAI’s effort to block Minnesota’s law banning the creation of sexually explicit deepfake images while the company challenges the measure. Frank said the company, then xAI, waited too long to...

Australia Digital Duty of Care Law to Require Algorithm Choice

Report from ABC News Australia In Brief – The Australian Government has released draft legislation to add a Digital Duty of Care to the Online Safety Act of 2021. A key provision is the “My Feed, My Way” initiative requiring social media platforms to give all users a...

Google Updates Gmail Spam Filters for Political Fundraising

Report from Campaigns & Elections In Brief – Google has put in place a Gmail policy that will make it somewhat easier for political campaigns and committees to reach personal Gmail inboxes by allowing eligible political entities to become “verified senders,” bypassing...

Platform Economy Insights produces a short email four times a week that reviews two top stories with concise analysis. It is the best way to keep on top of the news you should know. Sign up for this free email here.

* indicates required