AI: EU Member States plan “digital expropriation” of Europeans in the interest of AI companies
EU member states may prioritize AI company profits over data protection rights.
Summary
A leaked document from the Irish Presidency suggests EU member states are considering proposals that would allow AI companies to use personal data collected over decades with virtually no restrictions, prioritizing corporate profits over fundamental data protection rights. This move, supported by several member states including Germany, could effectively enable 'digital expropriation' of European citizens' data and potentially lead to a significant outflow of data and know-how to US and Chinese corporations.
Full text
Artificial Intelligence / 21 September 2026 In a leaked document, the Irish Presidency proposes to EU Member States that the interest of OpenAI, Anthropic, Google, Meta and SpaceX to make profits should take precedence over the fundamental right to data protection. Use of personal data “in the context of AI” should automatically be lawful. There seems to be wide informal agreement by many Member States. In particular, Big Tech would be able to use all personal data collected over the past decades with virtually no restrictions, as long as this happens “in the context” of AI. Schrems: “Under these proposals, the profits of AI companies would trump European’s fundamental right to privacy. This is nothing but a digital expropriation of Europeans.” All this is happening despite the key figures of AI corporations actively warn about the enormous risks associated with their own products. Politico Article with initially leaked documents (paywalled)Leaked extreme proposal by the Irish Presidency (PDF)Proposal from Germany for the massive liberalization of AI companies (PDF)Overview page of the European Commission on the “Digital Omnibus”Last limits fall: Profits of AI companies trump data protection? As part of the Digital Omnibus Proposal, the European Commission claimed to adopt only minor simplifications for EU companies, whilst explicitly claiming to maintain a “high level of protection” for Europeans. As the changes were intended to be minimal, a “fast-track procedure” was chosen - without any fundamental rights assessment and without directly involving the European expert group on data protection.Article 88c proposed by the European Commission (now Article 88bis in the Council document) intends to liberate the use of personal data for AI. The proposal is currently with the Council, where the Irish Presidency currently holds the reins. Ireland serves as the EU headquarter for the majority of the US and China’s AI corporations. With support of Germany and other EU powerhouses, it is currently proposed, that, when using personal data “in the context of AI”, companies are generally permitted to do basically anything. The commercial interests of AI companies should generally trump the fundamental rights of users. This general allowance would also apply to individuals who have never been customers of an AI company, or to data entered decades ago, for example in chats or on social media. All personal data that an AI company can somehow get its hands on would fall under the provision. There is no need to ask users for consent – companies are automatically assumed to have an overriding “legitimate interest” if they train or use any AI product.Schrems: “A likely majority of EU member states are now saying that the interests of Elon Musk, Marc Zuckerberg, Google or Open AI, in making enormous profits, should take precedence over European’s fundamental right to data protection. This is nothing short of the ‘digital expropriation’ of Europeans. Everything we have ever entered into digital systems, or that AI corporations have otherwise obtained, becomes fair game for AI corporations to use.”The sale of European data to the US and China. Politicians seem to believe, that the European economy will benefit from the abolishment of as many laws as possible. Nonetheless, the exact opposite can be expected: most EU companies neither have the access to the same volume of data, nor the capital to compete with US corporations. In many cases, this could also mean that the data collected by EU companies (but processed on platforms or services in the US) would flow to providers in the US or China.Schrems: “This legislative change primarily benefits the big players, those who have collected massive amounts of European’s data. This is a complete sell-off of European data to global corporations. It would also result in a large amount of know-how flowing from EU companies to the US or China. From an industrial policy perspective, such an approach is madness.” A blank check for an entire technology? Usually, the GDPR permits processing for specific purposes (e.g. retention for tax records or fraud prevention). However, the currently proposed Article 88c (or Article 88bis) legitimises an entire technology. Regardless of the purpose for which it is used, any AI system would be lawfully sucking up any personal data by default. For example, the proposed Article would also permit the training and use of AI for manipulation, disinformation, the generation of nude images, or killer drones and indeed any other questionable purpose. Many processing operations that were so far illegal would suddenly become legal – just because they are done “in the context” of an AI system. For example, data processing for personal advertising purposes (without consent) is currently illegal in the EU. Now however, if advertising is to be personalised using AI technology, it would suddenly become legal.Schrems: “It’s like saying anything goes — no matter what you do — as long as it’s done with a specific technology. Many things that were previously illegal would suddenly be legal, as long as you use AI. It is utterly absurd to give a high-risk technology preferential treatment over every other computer system.” The 45-year promise of data protection is collapsing. On a European level, data protection legislation has existed since 1981. For decades, Europeans have been promised that such (supposedly) “strict” data protection, would ensure that platforms such as Twitter/X, Facebook or Instagram, and corporations such as Google or Microsoft which collect vast amounts of data, would “never” use it for other purposes that for what they were shared. The proposed Article 88c (or now 88bis) breaks this promise: all collected data is suddenly up for grabs, for any use, by any AI system.Schrems: “Since the 1980s, we have promised people that whilst large corporations may hold onto the data, they are only permitted to use it to a limited extent. Article 88bis now suddenly throws open the floodgates, and allows unlimited use of all data for AI.” Further massive limitations on protections and rights. The EU member states have further proposed drastically narrowing the definition of “personal data”, meaning that, amongst other things, it is unclear whether, for example, online tracking would still be covered by the GDPR. This is meant to be done via so-called "pseudonyms" that should regularly not be covered by the GDPR anymore. The problem is, that most IT systems primarily work with pseudonyms (such as user IDs, tracking IDs, IP addresses or social security numbers). Furthermore, internal company knowledge and capabilities should be an element to be taken into account to determine if the GDPR even applies. Equally, data subject rights should not be applicable if they are “abused” by a data subject. In practice, these "subjective" factors are prone to abuse. The decision of whether data is still “personal” or a right is “abusive” would be primarily made by the companies that are regulated by the law. Both of these measures can make it almost impossible to enforce the GDPR in practice. In each individual case, companies could have lengthy debates about their (unknown) internal capabilities and intentions and speculate about the potentially "abusive" intentions of users. Such debates typically drag on for years and drown procedures in enormous delays and enormous costs - so anything but "simplification".Schrems: “These changes are right from the playbook of any big law firm defending big tech. We spend years in courts and before authorities to get these claims rejected. The EU legislator will likely turbocharge them and hence make EU law even more complex and unenforceable.” Position of the European Commission and the European Parliament. The European Commission made a 180-degree turn a while ago, and currently clearly prioritises the interests of industry lobbies over fundamental rights. The position of the European Parli