EU proposal could let AI companies train on Europeans’ data by default, noyb warns
A leaked proposal could let AI companies use Europeans’ personal data to train models without consent.

Shattered glass with padlock icon and national flag. SEAN GLADWELL/Getty.
- A leaked EU proposal could let AI companies train models on Europeans’ personal data without consent.
- Noyb says Article 88bis could prioritize AI companies’ interests over Europeans’ data protection rights.
- The group warns the proposal could cover uses such as advertising, disinformation detection, and nude image generation.
- EU countries are discussing the changes, and Schrems says noyb may challenge them in court.
Key Takeaways by nexos.ai, reviewed by Cybernews staff.
The European Commission is considering changes to the current privacy and data protection rules, allowing AI companies to use European citizens' personal data to train AI models by default.
According to a leaked proposal from the Irish EU Council Presidency, companies like OpenAI, Anthropic, Google, Meta, and SpaceXAI should be able to lawfully use the personal data of their users as input to train their AI models without obtaining consent.
It all revolves around Article 88bis of the Digital Omnibus, a set of proposals developed by the European Commission to simplify existing rules on privacy, data protection, and AI while maintaining a high level of protection.
The article says that “the processing of personal data in the context of the development and operation of an AI system or of an AI model may be carried out for a legitimate interest of the controller of a third party.”
Max Schrems, Chairman of the privacy advocacy group noyb, states that this means AI companies can use the personal data of European citizens with virtually no restrictions.
“This is nothing but a digital expropriation of Europeans,” he said in a statement that was published earlier this week, arguing that the changes would put the commercial interests of AI companies ahead of Europeans’ fundamental right to data protection.
Noyb also raises concerns about the scope of the proposal. It would basically mean that personal information could be used for any purpose, including training AI to recognize disinformation, personal advertising, and even generating nude images.
“It’s like saying anything goes, no matter what you do, as long as it’s done with a specific technology. Many things that were previously illegal would suddenly be legal, as long as you use AI. It is utterly absurd to give a high-risk technology preferential treatment over every other computer system,”Schrems warns.
Furthermore, noyb criticizes proposals in the Digital Omnibus to drastically narrow the definition of personal data by excluding certain forms of pseudonymized information that would normally be protected under the GDPR, such as user IDs, tracking IDs, IP addresses, and Social Security numbers.
EU member states are currently discussing the proposals, but have allegedly already secured the support of some EU powerhouses, including Germany.
Stay updated with our latest stories and follow us on social media
Be the first to discover new stories, ideas, and updates from our team.
If the European Commission doesn’t deliver on its promise of simplification but instead erodes the fundamental rights of European citizens, Schrems says he’s willing to call in the European Court of Justice (CJEU).
“If the legislator has lost all sense of proportion and direction, then the people can only turn to the courts. Any extreme law that has a high risk of being overturned would at the same time only create more legal uncertainty instead of promised simplification,” the noyb Chairman concludes.