The GDPR is about to change for the first time since 2018, and AI is the reason. The European Commission's Digital Omnibus, proposed on 19 November 2025, would recognise AI development as a legitimate interest and narrow what counts as personal data. Negotiations resumed in September 2026 under the Irish Council presidency, and final adoption is unlikely before late 2026.
None of this is law yet. But it shows where European data protection is heading, and any business that builds or buys AI should plan for it now. Our earlier articles cover the record-keeping and cookie proposals and the wider simplification debate. This one is about AI.
What the Commission proposed for AI
The package touches several GDPR rules that matter for AI:
| Proposal | What it would do |
|---|---|
| AI training as a legitimate interest (new Article 88c) | Let organisations rely on legitimate interest to develop and operate AI models, with “enhanced safeguards” and an unconditional right for individuals to opt out |
| “Residual” sensitive data (new Article 9(2)(k)) | Tolerate special-category data that ends up in training sets by accident, if the controller tries to prevent its collection, removes it promptly and stops it appearing in outputs |
| Narrower personal data | Data held by an organisation with no reasonable means to identify the person would fall outside the GDPR for that organisation |
| Breach notification | 96 hours instead of 72, only high-risk breaches reported, one EU portal for GDPR, NIS2, DORA and eIDAS notices |
| Cookies and browser signals (new Article 88a) | Cookie rules move into the GDPR, and websites must honour machine-readable consent signals sent by browsers |
Where the negotiations stand
The AI provisions are the most contested part of the package. A leaked compromise text from the Irish presidency, published by the privacy group noyb in September, renumbers the AI article as Article 88 bis and goes further than the Commission: it would presume that processing personal data to train and operate an AI system is a legitimate interest. Privacy groups warn that this turns a case-by-case balancing test into a blanket endorsement.
Parliament amendments range from deleting the AI articles to adding stronger safeguards, and the EDPB and EDPS have raised concerns about weaker protection. This also reverses the picture from June, when the AI language appeared to have stalled in the Council. The final text could still look very different from today's drafts.
What will not change is the direction: regulators accept that AI is trained on personal data, and the argument is now about which safeguards make it lawful.
Why this matters even if you never train a model
Most small and mid-sized companies do not build foundation models. But many fine-tune models, paste customer data into AI tools, or buy software from vendors who do. The Omnibus affects them in three ways.
- Legitimate interest still means paperwork. Even a presumption does not remove the need for a documented assessment, safeguards and a working opt-out. Under any version of the text, the paperwork becomes the condition for using the basis, not an obstacle to it.
- Vendors will lean on the new rules. Expect AI providers to cite the Omnibus in their terms and privacy notices. Do not accept “the law is changing in our favour” as an answer. Ask how they handle opt-outs, how they treat sensitive data that slips into training sets, and whether your data trains their models at all.
- Today's GDPR still applies. Until the Omnibus is adopted and in force, regulators enforce the current text, as the fines of 2026 show. The EDPB's draft guidelines on web scraping, open for consultation until 30 October, already treat legitimate interest as the realistic basis for training data, but only with strong safeguards. See our guide to AI training data.
The narrower definition of personal data deserves a separate warning. It is tempting to read it as permission to stop worrying about pseudonymised data. It is not: a test based on the holder's own means is fragile, because the moment data is shared, combined or breached, the answer can change. Treat it as a possible future simplification, not a plan.
GDPRChat is an AI customer chat widget built with Article 7 consent gates and automatic data deletion — compliance built into the architecture, not bolted on after a regulator starts asking questions.
What to do now
- Map where personal data enters your AI tools, including prompts, file uploads, fine-tuning sets and chat logs.
- Write or update a legitimate interest assessment for each AI use case: the purpose, why AI is necessary, and why individuals' rights do not override it.
- Build a simple opt-out route for customers and staff whose data might be used for AI, and test that it works.
- Keep your breach plan on the 72-hour clock. The 96-hour deadline is a proposal; do not design around it.
- Add AI questions to vendor due diligence: training use, retention, sub-processors and handling of sensitive data. See why AI features need a DPIA.
- Record your decisions. Whatever text is finally adopted, regulators will ask what you knew and when you acted.
The bottom line
The Digital Omnibus is a signal, not a free pass. Companies that document their AI processing well today will be ready whichever version of the text is finally adopted, and will be in a far better position than those waiting for the law to settle before they start.
Book a free consultation with GDPRGard → and we will help you map where AI touches personal data in your business.
Sources
- noyb on the Irish presidency's Article 88 bis text (via Resultsense, 21 Sep 2026)
- EDRi: letter to the Council on the Digital Omnibus (Data), September 2026
- Trending Topics: EU could make personal data use for AI training legitimate
- EDPB: Guidelines 03/2026 on web scraping for generative AI (consultation until 30 Oct 2026)
- Reed Smith: EDPB web scraping guidelines for AI
Also read:
- Inside the EU's Digital Omnibus: what's actually changing for GDPR, and what just stalled
- GDPR in 2026: why “simplification” doesn't mean you can relax
- The "It Was Public" Excuse Is Over: GDPR Now Formally Covers AI Training Data