Skip to content
World clockEU--:--UK--:--USA--:--CN--:--PLDEFRIT中文EN

portal about AI and technologyevents · analysis · interviews · technical background

Search
LIVE
›

Data Omnibus: will AI training get a blanket 'legitimate interest' pass?

A compromise drafted by the Irish presidency on 3 September is back in the EU negotiations. The group noyb calls it a 'digital expropriation of Europeans'. The Commission answers with its own agenda of simplifying the rules.

TechnologyExplainerRachel NwosuPublished: 26 September 20266 min readSources 2
Data Omnibus: will AI training get a blanket 'legitimate interest' pass?

After the summer parliamentary break, the debate over the Data Omnibus is back. The EU package is meant to simplify data rules and loosen some of them. As netzpolitik.org describes it, the focus has landed on one proposal: that using personal data to train AI systems should in principle count as lawful under 'legitimate interest'.

The trigger is a compromise document from the Irish Council presidency dated 3 September 2026. Politico revealed its contents. The note revives an idea the European Commission had written into its own Data Omnibus draft, and which was struck out in the first half of the year at the request of the Cypriot presidency. According to the leaks, large member states including Germany backed the solution. They argued it would help European AI companies.

The wording would mean model providers no longer need explicit and informed consent from users. Nor would they need a case-by-case balancing test. A general presumed legal basis would be enough.

'Digital expropriation'

Max Schrems, head of the group noyb, has no kind words for the proposal. In his view it puts the interests of AI corporations directly above the fundamental right to data protection. He calls it a 'digital expropriation of Europeans'. His argument: such a rule would mainly benefit the largest technology companies, which have already collected data on a massive scale.

Training models on data scraped from the web is not necessarily at odds with the GDPR. The European Data Protection Board has acknowledged that legal bases other than consent exist, for example a balancing of interests. Lawyers disagree, however, on whether that balancing really always comes out in favour of companies. One point raised is the lack of transparency. Users do not know what exactly happens to their data, or where it resurfaces.

What else the package contains

The Data Omnibus is part of a broader deregulation agenda. Reporting duties in the environmental field were cut earlier, and some AI rules were softened. The data package is the first to change the GDPR in depth. Beyond the disputed legal basis for training, it also contains far less controversial elements: tidying up several EU data laws and standardising the channels for reporting data protection breaches.

The institutional context shows how much is at stake. The European Commission runs an AI Office with more than 125 staff, organised into six units. They deal, among other things, with applying the AI Act and enforcing the rules on general-purpose models. The office can carry out model evaluations, demand information and impose penalties. For companies, the question of the legal basis for training is therefore a question of whether their own data can be used at all, and whether they did so under rules that, as is clear, keep changing.

Comments 0

Sources

2
  1. 01netzpolitik.org: Datenschützer warnen vor Pauschalerlaubnis für KI-TrainingDE
  2. 02European AI Office – European CommissionEN

All figures and quotations in this text come from the sources listed below.

Content prepared by the editorial team with AI assistance.

Rachel Nwosu

Rachel Nwosu

AI, models and technology

Rachel Nwosu covers AI, models and technology for FLASH24, working from public model documentation, benchmark releases and repository histories rather than press summaries, and she skips announcements that arrive without reproducible numbers. She checks training-data claims against dataset cards and reruns reported metrics where code is available. She spends much of her week interviewing researchers and engineers, tracking model launch calendars, and comparing vendor benchmarks with independent evaluations. Outside the desk she runs 3D printers, restores old computers, and tests how models learn from internet junk. She does not publish benchmark figures she cannot trace to a source.

Newsroom →

Comments

0
  1. No comments yet — be the first.

Write a comment

Comments are public. We do not publish abuse, spam or advertising.