Leaked GDPR draft would ease AI training on personal data
On 21 September 2026 the privacy group noyb published restricted Council of the EU documents showing how member states are reshaping the GDPR as part of the Digital Omnibus. The headline proposal would let organisations use personal data to develop and run AI systems on the basis of legitimate interest, with many of the safeguards the European Commission originally attached stripped out of the operative text. It is a negotiating draft, not law, but it tells you a great deal about where European data protection may be heading.
What the leaked text says
The documents centre on a compromise text from the Irish Presidency of the Council, dated 3 September 2026. According to reporting by PPC Land and noyb’s own analysis, the key points are:
- AI and legitimate interest (Article 88bis). Processing personal data to develop and operate AI could rely on the legitimate interest of the controller or a third party, without prior consent. The AI-specific conditions and example safeguards in the Commission’s November 2025 proposal, including an unconditional right to object, would be removed from the operative text. The standard balancing test would remain the main safeguard.
- A more far-reaching German proposal. A German submission from August 2026 would go further, creating a presumption that AI training is a legitimate interest.
- Cookies move back to ePrivacy. Device-access consent rules would return to the ePrivacy Directive, with a new exemption for measuring contextual advertising.
- Breach notification. PPC Land reports the text would require notification only for high-risk breaches, with the deadline extended to 96 hours.
- Automated decisions. The Council would restore the right not to be subject to solely automated decisions, reversing a Commission proposal to permit them in contractual settings.
noyb argues the approach amounts to treating processing as lawful simply because AI is involved, and has raised the prospect of a challenge before the Court of Justice if the final law lacks proportionate safeguards.
- Status
- A Council negotiating text. The Council still has to agree its mandate, then negotiate with the European Parliament.
- Current law
- Nothing has changed yet. Existing GDPR rules and regulator guidance still apply to AI training and use.
- Parliament
- Reported to be divided, so the final text could look quite different.
Why it matters, even if it never passes in this form
For organisations building or buying AI, the leak is a signal rather than a green light. Three things stand out.
Legitimate interest is still a test, not a switch. Even in the Council draft, the balancing test survives. That means you would still need to document your interest, show the processing is necessary and weigh it against the rights and reasonable expectations of the people whose data you use. Regulators have repeatedly found that controllers underestimate how demanding that exercise is.
Legal uncertainty is rising, not falling. A contested reform that may be litigated for years is not a stable foundation for a multi-year AI programme. Designing to today’s standard, with clear records, gives you a defensible position whichever way the text lands.
UK and EU positions may diverge further. UK organisations serving EU customers remain subject to the EU GDPR for that processing. Tracking two moving regimes at once is now a governance task in its own right.
“Build your AI governance for the law you can prove compliance with today, not the law someone hopes to pass next year.”
— Praeferre analysisWhat to do now
- Inventory AI use cases that touch personal data. Cover training, fine-tuning, retrieval, and everyday staff use of generative AI tools.
- Write a legitimate interest assessment for each. Record the purpose, necessity, the data subjects affected and the safeguards you rely on. If you cannot complete one convincingly, that is a warning sign.
- Keep objection and opt-out routes. Even if the law loosens, honouring objections reduces complaint and reputational risk.
- Check vendor terms. Understand whether your AI suppliers train on your inputs and what contractual controls you have.
- Stop sensitive data leaving by accident. Tools such as AI Data Leak Protection redact or block personal and confidential data before it reaches public AI models.
- Assign an owner to monitor the Omnibus. Track the Council mandate, trilogues and the final text, and plan a policy review when it is adopted.
Our AI advisory team helps organisations build responsible AI frameworks that work under current law and adapt as it changes, and our GRC automation platform keeps assessments and evidence in one place. See our GDPR framework page for more.
Build a responsible AI framework that stands up under today’s rules and adapts to tomorrow’s.
Explore AI advisoryCommon questions
No. The leaked documents are a Council negotiating text. The current GDPR still applies, and any change would need agreement between the Council and the European Parliament.
Legitimate interest can already be a lawful basis for some AI processing, but only where a documented balancing test supports it. The leaked draft would make that route more explicit; it would not remove the need for the assessment.
It is the provision in the Digital Omnibus GDPR amendments dealing with personal data processing in the context of AI. The Council compromise would allow such processing on the basis of legitimate interest, with fewer AI-specific safeguards than the Commission proposed.
Sources
- AI: EU Member States plan ‘digital expropriation’ of Europeans in the interest of AI companies — noyb, 21 September 2026
- EU Council draft drops unconditional opt-out from GDPR AI clause — PPC Land, 21 September 2026
- noyb: leaked EU draft makes AI data use lawful by default — Resultsense, 21 September 2026
