Europe Talks Digital Sovereignty While Negotiating to Open Data to AI

Europe has spent years talking about technological sovereignty, control over data, and building capacity independent of the major US and Chinese platforms. Now, while trying to reinforce that narrative, member states are negotiating a change to the General Data Protection Regulation (GDPR) within the Digital Omnibus that could make it easier for AI companies to use personal information to develop and operate their systems. Privacy group noyb has published internal documents it considers a step toward a massive handover of European data to Big Tech.

European digital sovereignty and AI data in 30 seconds

  • The Council of the EU is negotiating Article 88a to regulate the use of personal data in AI systems and models.
  • The Irish Presidency proposes allowing this processing under the GDPR’s legitimate interest basis.
  • Germany proposes going further, presuming that legitimate interest for certain AI operations.
  • noyb argues the change would mainly benefit Big Tech companies that already hold enormous amounts of data.
  • The proposal is not yet final, and its wording may still change during the EU negotiation.

The clash is especially striking because it’s playing out on exactly the ground where Brussels wants to distance itself from the US tech model: digital sovereignty. Europe is trying to build its own capacity in artificial intelligence, computing, semiconductors, cloud, and data, while at the same time considering loosening the rules that determine who can reuse the personal data generated by Europeans.

The stakes are not small. Data is one of the resources that fuels the training and operation of AI models. If a company holds large volumes of information, expanding the legal bases for reusing it can lower one of the barriers separating major platforms from new competitors.

And that’s where the paradox fueling the debate appears: Europe wants to control its digital infrastructure, but it is also considering making it easier to access one of the assets that makes that infrastructure possible — data.

Article 88a opens a new path for using data in AI

The documents leaked by noyb show a negotiation still open within the Council of the European Union. The Irish Presidency’s proposal turns into Article 88a a provision that carried a different number in the Commission’s original proposal.

The text establishes that processing personal data related to the development and operation of AI systems or models can be based on the legitimate interest provided for in Article 6.1(f) of the GDPR. It also keeps the obligation to use an adequate legal basis and to apply technical and organizational measures to protect the rights of affected individuals.

This matters because the draft does not legally amount to granting unlimited, automatic access to all European data. The proposed simplification changes the conditions under which certain processing operations can rely on legitimate interest, but the GDPR would still be part of the applicable framework.

The problem, according to noyb, lies in the scope that new legal basis could take on. The organization argues that the reference to the development and operation of AI could allow reuse of very large amounts of previously collected data and would especially benefit companies that already hold enormous data stores.

Germany has additionally proposed an even more developer-friendly change. Its comments suggest establishing a presumption of legitimate interest for processing related to the training and technical operation of AI models and systems, while also setting limits for certain uses, such as processing specifically aimed at identifying, monitoring, or evaluating individuals.

The result is a debate that goes well beyond the possibility of training a model with European data. What’s at stake is who can reuse the information, on what legal basis, and under what conditions.

European digital sovereignty, or European data for Big Tech?

noyb’s concern has an industrial dimension. Loosening the rules doesn’t necessarily benefit every company equally.

A small European company looking to develop an AI model doesn’t necessarily have access to the same volumes of data as a global platform that has run social networks, search engines, video services, email, operating systems, or advertising platforms for two decades.

That’s why a general opening of data access can have a different effect depending on a company’s size and position. Tech giants already hold huge amounts of information and the storage and computing capacity needed to process it.

Max Schrems, founder of noyb, argues that the change would primarily benefit players that have already accumulated large amounts of European data, and warns that part of that value could end up with US or Chinese companies. That interpretation belongs to noyb and is part of its opposition to the text.

The expression the organization uses is especially forceful: “digital expropriation.” It’s not a legal category within the European proposal, but noyb’s own description of its possible consequences.

The debate also connects to a broader issue. Europe wants more of its own technological capacity, but a significant share of the digital infrastructure its companies use already depends on foreign providers. If European data is also processed on platforms, cloud services, or models controlled by companies outside the EU, technological sovereignty could become harder to achieve, even if European regulation remains strict.

The European Commission presents the Digital Omnibus from a different angle: simplifying obligations, cutting compliance costs, and boosting competitiveness while keeping safeguards for citizens in place. The AI Omnibus that’s part of that package already took effect in July 2026, with changes meant to simplify certain obligations and extend implementation deadlines.

The current discussion on personal data is a separate matter and remains under negotiation.

Europe can still change the text

The current picture isn’t one of a European law that has already stripped away data protection for training models. The documents published by noyb correspond to a negotiation phase within the Council and show positions that can still be modified before a final text is reached.

In fact, one of the key points in the Irish Presidency’s document is precisely what disappears compared with the Commission’s initial proposal. According to an analysis of the documents published by PPC Land, the Council’s wording removed some conditions and specific references included in the original proposal, among them certain safeguards related to consent and the right to object within this particular article.

That doesn’t mean all GDPR rights disappear. It means the new provision could change how a sufficient legal basis is determined for certain AI-related processing.

For Europe, the issue carries a double technological reading. On one hand, making legal access to data easier could reduce obstacles to developing AI systems within the European market. On the other, if most of the data and computing capacity remain concentrated among a handful of global companies, liberalization could end up reinforcing exactly those already in that position.

That’s where the privacy debate intersects with technological sovereignty. Having European rules on data doesn’t by itself guarantee that Europe controls the economic value generated from that data. But it also can’t be assumed that a loosening of the rules will benefit only Big Tech: that outcome will depend on the final wording, the safeguards in place, and how the rule is applied.

The negotiation will have to resolve exactly that tension. If Europe wants to compete in AI, it needs data, models, computing capacity, and companies able to use them. If it wants to keep its own model of digital sovereignty, it also has to decide how far it’s willing to open access to its citizens’ personal data.

For now, what exists is a proposal under negotiation. The idea that Europe is about to “give away” all its data to multinationals is a critical interpretation of the change, championed by noyb, not a legal description of an already-approved rule. But the leaked documents do show that the EU is discussing a specific expansion of the ways personal data can be used in the development and operation of AI, and that debate directly affects the balance between technological competitiveness, privacy, and European digital sovereignty.

Related reading: the European Commission has already signaled a friendlier stance toward Big Tech on GDPR and AI Act enforcement, a shift that forms the backdrop for this new negotiation.

Frequently asked questions

Is Europe going to let AI companies use all citizens’ data?

Not yet. The Council is negotiating a provision that would make certain AI-related processing of personal data easier under legitimate interest, but the text can still change.

What does Article 88a propose?

The draft allows the development and operation of AI systems or models to rely on the legitimate interest basis under the GDPR. It also keeps protection obligations and technical and organizational measures for data controllers.

Why does noyb call it “digital expropriation”?

Because the organization believes the change would especially benefit large companies that already hold enormous amounts of European data and could make it easier to reuse that data for AI. The phrase is noyb’s own assessment, not the proposal’s legal name.

Has the proposal already been approved?

No. These are negotiation documents within the Council of the EU. The final wording can still change before the European legislative process is complete.

via: Open Security

Scroll to Top