bbieron@platformeconomyinsights.com

EU Commission Expected to Propose GDPR Changes to Ease AI Training

Nov 1, 2025

Report from Computerworld

In Brief – The European Commission is planning to propose revisions of the General Data Protection Regulation (GDPR) intended to ease the ability to train AI systems with data collected in Europe as part of its “Digital Omnibus” simplification proposal. Privacy advocates reacted to a leaked draft with alarm, arguing that it would greatly weaken the EU’s landmark privacy protections. The Digital Omnibus is expected to move cookie regulation from the ePrivacy Directive into the GDPR, creating a new a new Article 88a that would eliminate the current requirement for explicit consent before setting non-essential cookies and allow websites to process data for “low-risk purposes” or under any legal basis recognized by the GDPR. Critics argue that the Commission is using “cookie fatigue” created by user consent pop-ups to justify diluting core privacy standards that prioritize corporate interests over individual rights. A particularly contentious element clarifies that companies would be able to train AI models on personal data under the GDPR’s “legitimate interest” basis if safeguards like transparency and the right to object are observed, which could allow large-scale data mining for AI development. The draft reportedly also narrows the definition of sensitive data, limiting enhanced protection to information that directly reveals protected traits. The Digital Omnibus proposal is expected to be publicly released on November 19.

Context – One growing European “digital sovereignty” concern is that the continent’s AI industry is not keeping pace with the US and China. The Commission is engaged. In October it announced two initiatives to promote AI development and use, which followed the Commission’s April “AI Continent Action Plan”. Many of Europe’s AI tech firms and investors argue that the bloc’s regulatory and tax environment is too cumbersome and is slowing development. Not only is the EU’s AI Act the most aggressive AI regulatory regime, but regulatory overlaps involving other digital regimes, including the GDPR and DMA, continue to crop up, reinforcing regulatory concerns given voice in last year’s Draghi Report.

View By Monthly
Latest Blog
European Commission Issues AI Content Notification Rules

Report from MediaPost In Brief – The AI transparency rules required by Article 50 of the EU’s AI Act have taken effect, requiring companies to clearly disclose when users are interacting with artificial intelligence or viewing AI-generated or manipulated images, audio...

More Follow-On Lawsuits for Google Likely After Latest DMA Fine

Report from Reuters In Brief – European lawyers and litigation financiers say that the European Commission’s recent decision to fine Google $1 billion for violating the Digital Markets Act (DMA) may add to the wave of private antitrust lawsuits that the search giant...

More Really Smart Tech People Call for International AI Governance

Report from the Washington Post In Brief – OpenAI and Anthropic have endorsed a petition urging the US government to help create an international regime to slow down and regulate the pace of “automated AI development.” It is signed by over 1,200 “employees of frontier...

Judge Dismisses Google’s DMCA Search Scraping Lawsuit

Report from MediaPost In Brief – Federal District Court Judge Yvonne Gonzalez Rogers has dismissed Google's complaint against the Texas-based company SerpApi for allegedly violating the Digital Millennium Copyright Act (DMCA) anti-circumvention provisions by evading...

Platform Economy Insights produces a short email four times a week that reviews two top stories with concise analysis. It is the best way to keep on top of the news you should know. Sign up for this free email here.

* indicates required