Prefer to listen? Click play for AI narration

The GDPR is about to change for the first time since 2018, and AI is the reason. The European Commission's Digital Omnibus, proposed on 19 November 2025, would recognise AI development as a legitimate interest and narrow what counts as personal data. Negotiations resumed in September 2026 under the Irish Council presidency, and final adoption is unlikely before late 2026.

None of this is law yet. But it shows where European data protection is heading, and any business that builds or buys AI should plan for it now. Our earlier articles cover the record-keeping and cookie proposals and the wider simplification debate. This one is about AI.

What the Commission proposed for AI

The package touches several GDPR rules that matter for AI:

ProposalWhat it would do
AI training as a legitimate interest (new Article 88c)Let organisations rely on legitimate interest to develop and operate AI models, with “enhanced safeguards” and an unconditional right for individuals to opt out
“Residual” sensitive data (new Article 9(2)(k))Tolerate special-category data that ends up in training sets by accident, if the controller tries to prevent its collection, removes it promptly and stops it appearing in outputs
Narrower personal dataData held by an organisation with no reasonable means to identify the person would fall outside the GDPR for that organisation
Breach notification96 hours instead of 72, only high-risk breaches reported, one EU portal for GDPR, NIS2, DORA and eIDAS notices
Cookies and browser signals (new Article 88a)Cookie rules move into the GDPR, and websites must honour machine-readable consent signals sent by browsers

Where the negotiations stand

The AI provisions are the most contested part of the package. A leaked compromise text from the Irish presidency, published by the privacy group noyb in September, renumbers the AI article as Article 88 bis and goes further than the Commission: it would presume that processing personal data to train and operate an AI system is a legitimate interest. Privacy groups warn that this turns a case-by-case balancing test into a blanket endorsement.

Parliament amendments range from deleting the AI articles to adding stronger safeguards, and the EDPB and EDPS have raised concerns about weaker protection. This also reverses the picture from June, when the AI language appeared to have stalled in the Council. The final text could still look very different from today's drafts.

19 Nov 2025
Digital Omnibus proposed by the Commission
Art. 88c
Legitimate interest for AI, renumbered 88 bis in the Council text
72 h
Breach deadline that still applies today
30 Oct 2026
EDPB web-scraping consultation closes

What will not change is the direction: regulators accept that AI is trained on personal data, and the argument is now about which safeguards make it lawful.

Why this matters even if you never train a model

Most small and mid-sized companies do not build foundation models. But many fine-tune models, paste customer data into AI tools, or buy software from vendors who do. The Omnibus affects them in three ways.

The narrower definition of personal data deserves a separate warning. It is tempting to read it as permission to stop worrying about pseudonymised data. It is not: a test based on the holder's own means is fragile, because the moment data is shared, combined or breached, the answer can change. Treat it as a possible future simplification, not a plan.

💬
GDPRGard Product
Putting customer chats through AI? Get the GDPR basics right first

GDPRChat is an AI customer chat widget built with Article 7 consent gates and automatic data deletion — compliance built into the architecture, not bolted on after a regulator starts asking questions.

See GDPRChat →

What to do now

  1. Map where personal data enters your AI tools, including prompts, file uploads, fine-tuning sets and chat logs.
  2. Write or update a legitimate interest assessment for each AI use case: the purpose, why AI is necessary, and why individuals' rights do not override it.
  3. Build a simple opt-out route for customers and staff whose data might be used for AI, and test that it works.
  4. Keep your breach plan on the 72-hour clock. The 96-hour deadline is a proposal; do not design around it.
  5. Add AI questions to vendor due diligence: training use, retention, sub-processors and handling of sensitive data. See why AI features need a DPIA.
  6. Record your decisions. Whatever text is finally adopted, regulators will ask what you knew and when you acted.

The bottom line

The Digital Omnibus is a signal, not a free pass. Companies that document their AI processing well today will be ready whichever version of the text is finally adopted, and will be in a far better position than those waiting for the law to settle before they start.

Book a free consultation with GDPRGard → and we will help you map where AI touches personal data in your business.

Sources

Share this article

Also read:

⚠️ This article is for informational purposes only and does not constitute legal advice. For complex compliance situations, consult a qualified data protection professional. GDPR and EU AI Act requirements are subject to ongoing regulatory guidance — verify current obligations with your legal adviser.