Austrian privacy group noyb today published restricted Council of the European Union documents in which the Irish Presidency proposes that personal data may be processed to develop and operate artificial intelligence on the GDPR's legitimate interest basis, with the conditions and example safeguards the European Commission attached to the clause in November 2025 struck from the operative text. The 158-page compromise, dated 3 September 2026 and classified LIMITE, also takes the cookie consent rules back out of the GDPR, returns them to the ePrivacy Directive and adds a consent exemption for measuring contextual advertising.
In Short
EU governments are negotiating a leaked draft law that would let companies use people's personal data to build and run AI by claiming a "legitimate interest," a legal basis that does not require asking for permission first. A privacy group says this hands AI companies a free pass, and the same draft also rewrites the cookie rules that decide which banners appear on websites. If the text survives talks with the European Parliament, a legal balancing test would be the main check on AI use of your data, and some ad measurement tied only to the page you are viewing would no longer need a click on a banner.
The clause, line by line
The document carries the reference 12535/26 under interinstitutional file 2025/0360 (COD). The Council's General Secretariat circulated it to delegations ahead of a meeting of the Antici Group (Simplification) on 11 September 2026. According to its cover note, additions to the Commission proposal appear in bold, deletions in strikethrough, and changes against the previous Presidency text, ST 10677/26, in bold underline.
The Commission numbered its AI provision Article 88c. In the Presidency version it becomes Article 88 bis, and its first paragraph reads: "The processing of personal data in the context of the development and operation of an AI system or of an AI model may be carried out for a legitimate interest of the controller or a third party in accordance with Article 6(1)(f) of this Regulation." A second paragraph states that this does not affect the controller's obligation "to choose an appropriate lawful ground of processing set out in Article 6 of this Regulation." A third, which applies whatever the lawful ground, subjects such processing to "appropriate technical and organisational measures and safeguards to protect the rights and freedoms of the data subject in accordance with this Regulation."
What has been cut matters as much as what remains. A German submission among the leaked papers reproduces the Commission's wording in its left-hand column. That version qualified the permission with "where appropriate," carved out cases where "other Union or national laws explicitly require consent," and specified that the controller's interest gives way where the data subject's rights override it, "in particular where the data subject is a child." It then offered four example safeguards: data minimisation during the selection of sources and the training and testing of a model, protection against disclosure of data residually retained in the model, enhanced transparency, and "an unconditional right to object to the processing of their personal data." Every one of those phrases is struck through in the Presidency's operative article.
Why does the last item carry weight? Under the existing GDPR, objection to direct marketing is already absolute under Article 21(2) and (3). For other processing based on legitimate interest, Article 21(1) allows a controller to carry on if it demonstrates compelling legitimate grounds. The Commission's AI safeguard would have closed that route for AI development. The Presidency text does not carry it.
Two recitals that explained the clause, 30 and 31, are deleted in full. Recital 31 had asked controllers weighing their interests to consider "respecting technical indications embedded in a service limiting the use of data for AI development by third parties," a reference that bears directly on the opt-out signals publishers use to restrict AI crawlers. A new recital, 33a, added by the Council, keeps part of the Commission's language in non-binding form. It says processing may take place under Article 6(1)(f) "where appropriate, except where such interests are overridden" by the data subject's rights, "in particular where the data subject is a child, or where other Union or national laws explicitly require consent."
The result is a structural shift rather than a wholesale deletion. The balancing test has not disappeared: Article 6(1)(f), which the new article cross-references, already requires the controller's interest to yield where the data subject's interests or fundamental rights override it, particularly where the data subject is a child. What would no longer appear on the face of the provision are the AI-specific conditions and the objection right without qualification. Recitals guide interpretation. They do not bind in the way articles do.
Germany wants a presumption
A separate working document, WK 11020/2026 ADD 4, dated 17 August 2026, carries Germany's written comments on the previous Presidency text, filed against a 28 July 2026 deadline. Berlin's drafting goes further than the Presidency on nearly every point.
The German text adds a decisive sentence creating a legal presumption: processing "for the training and technical operation of an AI system as defined in Article 3, point (1), of Regulation (EU) 2024/1689 or an AI model shall be presumed as a legitimate interest within the meaning of this provision." It strikes "national" from the consent carve-out, so that only Union law could still require consent. A second paragraph deals with purpose limitation head-on, treating data "collected or recorded for other purposes" as "presumed to be compatible with the initial purposes," subject to safeguards.
Limits do exist in the German version. The provision would not apply to public authorities performing their tasks, nor where processing "is specifically directed at certain identified or identifiable natural persons," nor where a system is designed for "the identification, monitoring, or evaluation of natural persons." Systems built to synthetically generate the voice, image or other characteristics of an identifiable person are excluded as well. Its safeguards paragraph, however, keeps only protection against disclosure of residually retained data, striking data minimisation, enhanced transparency and the objection right from the Commission's list.
Two more paragraphs go further still. The information duty in Article 14 and the rights in Articles 16 to 18, covering rectification, erasure and restriction, would not apply where compliance "proves impossible or would involve a disproportionate effort." In those cases a controller would publish, before training, that personal data will be used and explain how objections or rectification requests can be filed; after training, it would apply "all technically available measures" against disclosure or identification. The Commission would draw up practical guidelines under Article 96 of the AI Act. Processing of special category data would be permitted by cross-reference to the Article 9 derogations.
None of this comes from nowhere. Germany submitted a 19-page document on 23 October 2025 asking for GDPR changes beyond the Commission's own agenda, including on the legal basis for AI training.
noyb's reading, and where the texts differ
noyb, the organisation chaired by Max Schrems, presents the Presidency draft as a transfer of value from citizens to technology companies. "This is nothing but a digital expropriation of Europeans," Schrems said, according to noyb. He argued that "many things that were previously illegal would suddenly be legal, as long as you use AI," and described the approach, "from an industrial policy perspective," as madness.
According to noyb, companies "are automatically assumed to have an overriding 'legitimate interest' if they train or use any AI product." That description matches the German drafting, which uses the word "presumed," more closely than it matches the Presidency article, which routes the permission through Article 6(1)(f) and so, on its face, preserves the balancing test. noyb links both documents in the same piece, labelling the Presidency paper "extreme" and the German paper a proposal for "massive liberalization." The Presidency text does remove the explicit child reference, the national consent carve-out and the objection right from the article itself, and it is those removals that noyb's criticism attaches to.
noyb also offers an advertising example. According to noyb, personalised advertising without consent is currently unlawful in the EU but would become lawful if the personalisation relied on AI. The same Presidency document, however, keeps a consent requirement for storing or reading information on devices in the ePrivacy Directive, and Article 88 bis does not mention that rule. Much cookie-based targeting depends on exactly that kind of device access. How the two instruments would interact is a question the draft leaves open.
On procedure, noyb says the Commission chose a fast-track route "without any fundamental rights assessment and without directly involving the European expert group on data protection." It notes that Ireland hosts the EU headquarters of most US and Chinese AI companies, and it frames the change against a longer history: European data protection legislation dates to 1981.
Cookie rules go back to ePrivacy
In the Commission's proposal, Article 88a would have moved the device-access consent rule into the GDPR. Article 88b would have obliged websites to honour automated, machine-readable consent signals sent by browsers. In the 3 September text both articles are struck in full, and the amending instruction now adds a single article after Article 88 rather than several. The browser-signal recital, 46, has gone too. When the Council removed Article 88b in its 18 June 2026 text, the transfer of consent rules into the GDPR under Article 88a was still in place. It no longer is.
Article 5 of the draft instead rewrites Article 5(3) of the ePrivacy Directive. Member States must ensure that storing or accessing information on a device "is only allowed when that person has given his or her consent, in accordance with Regulation (EU) 2016/679." Storage or access without consent, and subsequent processing "for the same purpose," is lawful only where "solely related to and strictly necessary for" one of six purposes. The first two are carrying out the transmission of a communication and providing a service, including its functionality, that the user explicitly requested. The third covers anonymous aggregated audience figures, provided the data are not shared with third parties or combined with third-party data. The fourth covers audience measurement under Article 24 of the European Media Freedom Act, on condition that personal data are pseudonymised immediately after collection. The fifth is technical security.
The sixth ground, covering contextual advertising measurement, is marked as new against the July text. It applies to "measuring the display and performance of advertising that is based solely on the immediate content displayed during an individual visit to a single web page or on the basis of a single search query." The exemption holds only where the measurement "does not involve profiling, data retention or any link with the past or future activity of the subscriber or user," and where it is carried out by the provider of the online service, jointly with others, or by a third party on its behalf. Recital 44f gives the examples it has in mind: "capping cookies, advertising audience measurement cookies, or cookies to combat click fraud."
Here the recital and the article pull in different directions. Frequency capping works by counting how often a device has already seen an ad, which is a link to past activity. The recital names capping cookies as covered; the operative text excludes any such link. How national regulators would square the two is not settled by the draft.
The exemption answers, in part, requests from both sides of the argument. Alliance Digitale had asked for contextual advertising, frequency capping and fraud prevention to be exempted, while data protection authorities suggested adding contextual advertising exceptions in February and warned against splitting device rules across two legal instruments.
Consent mechanics survive the move. Users must be able to refuse with a single click. While consent is valid, a provider cannot ask again for the same purpose, and after a refusal it must wait at least six months. Recital 45 applies this to "any provider that accesses or stores information in the terminal equipment of a subscriber or user, including so-called third-party cookie." Taken together, these would become statutory design requirements for every consent management platformserving EU users. A new Article 15a(5) would require Member States to hand enforcement of Article 5(3) to their GDPR supervisory authority.
The draft is not consistent on timing. Article 17(3) gives Member States 24 months after adoption to transpose the rules. The final provisions, by contrast, state that Article 5(2) of the omnibus applies six months after publication.
Personal data after the SRB judgment
The Commission's proposed additions to the personal data definition in Article 4(1) are struck. The Council moves the question into a new Article 25a, whose second paragraph states: "Pseudonymised data shall not be considered personal data for a person if that person is unable to identify the natural person to whom the data relates, unless paragraph 5 applies." A third paragraph adds that "a natural person is not identifiable where the likelihood of identification is insignificant in practice."
Two safeguards follow. Data a processor handles on a controller's behalf remain personal data for that processor. And where data are passed to a third party that possesses or can obtain means reasonably likely to identify the person, both the transmission and the third party's processing count as processing of personal data. That structure tracks the Court of Justice's 4 September 2025 judgment in EDPS v Single Resolution Board more closely than the Commission's wording did, wording the data protection authorities had said contradicted the case law.
The Commission's plan to set identifiability criteria through implementing acts is struck. Instead, the European Data Protection Board must issue an opinion on pseudonymisation and anonymisation, with its Chair required to request it within six months of entry into force. The Board already has anonymisation guidelines out for comment until 30 October.
noyb warns that most IT systems run on pseudonyms, among them user IDs, tracking IDs and IP addresses. "These changes are right from the playbook of any big law firm defending big tech," Schrems said, according to noyb. In advertising, where hashed identifiers move between platforms, clean rooms and measurement vendors, the onward-transmission rule would carry most of the weight.
Access requests, breaches and automated decisions
Article 12(5) would let a controller charge a fee or refuse a request where "an abusive intention on the part of the data subject submitting those requests can be demonstrated." The burden stays with the controller, which must show "reasonable grounds to believe" that a request is unfounded, excessive or abusive. Article 57(4) would hand supervisory authorities the same tool for complaints.
Breach notification changes more visibly. Only breaches likely to result in a high risk would require notification, within 96 hours rather than the current 72, and notifications would pass through a national entry point. The Board would publish lists of what does and does not meet the high-risk threshold within nine months.
On automated decisions, the Commission had redrafted Article 22 as a permission. The Council restores the wording as a right not to be subject to solely automated decisions, and deletes the Commission's phrase allowing such decisions for contracts "regardless of whether the decision could be taken otherwise than by solely automated means."
A new Article 9(2)(k) covers "unintentional and residual" sensitive data in AI development. Controllers must erase such data once identified; where erasure is technically impossible or requires disproportionate effort, they must protect it instead. The Council struck the word "manifestly" before "disproportionate," lowering the bar for keeping the data rather than removing it.
Platform rules survive in part
The Commission proposed repealing the platform-to-business Regulation 2019/1150, keeping a handful of provisions until 31 December 2032. The Council strikes that plan and amends the regulation instead. Articles 2(11), 2(12), 6, 8 to 10, 12 to 14, 16, 17 and 18(2) to (4) would be deleted from entry into force. Article 9, the duty to explain what data sellers and platforms can access, is on that list. Articles 3, 5 and 7, on terms and conditions, ranking transparency and differentiated treatment, are not.
Why the marketing community is watching
For advertisers, the lawful basis for AI training is not an abstract matter. Meta said it would begin processing EU users' data for AI training under legitimate interest from 27 May 2025, and noyb sent the company a cease and desist letter on 14 May. A later survey found only 7% of users wanted their data used that way. A digest published by the European Data Protection Board, covering 62 one-stop-shop decisions, found that controllers routinely underestimate what the balancing test demands. A paper in International Data Privacy Law warned that legitimate interest risks sliding into a formality in AI training.
Those findings frame the stakes of the drafting choice. If the balancing test is the principal remaining check, its quality in practice decides how much protection the new article leaves. The Commission, for its part, describes the package as aiming to ensure that compliance "comes at a lower cost, delivers on the same objectives, and brings in itself a competitive advantage to responsible businesses." Whether the September text matches that description is now a question for the co-legislators.
What comes next
The Council still has to settle its mandate before negotiating with Parliament. A coalition of 19 organisations wrote on 10 September to the Irish presidency and co-rapporteurs Kaljurand and Salla asking for the browser signal to be restored. According to noyb, Parliament is split: most of the European People's Party tends to favour loosening EU digital laws, centre-left groups have pushed back, and far-right groups increasingly oppose a "free pass" for Big Tech.
noyb points to the Court of Justice as a last resort, recalling that the court has struck down EU law over data retention and over transfers of EU data to the United States. "If the legislator has lost all sense of proportion and direction, then the people can only turn to the courts," Schrems said, according to noyb. Would a law of this breadth survive that scrutiny? The Presidency text does not engage with the question.
Timeline
- 1981: Data protection legislation is established at European level, according to noyb.
- 14 May 2025: noyb sends Meta a cease and desist letter over AI training
- August 2025: A survey finds only 7% of users want Meta to use their data for AI
- 4 September 2025: The Court of Justice rules in EDPS v Single Resolution Board
- 23 October 2025: Germany submits a 19-page GDPR reform document
- 19 November 2025: The European Commission publishes the Digital Omnibus proposal.
- December 2025: The Netherlands raises formal concerns about the package
- 10 February 2026: The EDPB and EDPS adopt a joint opinion rejecting key GDPR amendments
- March 2026: An EDPB digest of 62 legitimate interest decisions is published
- 21 May 2026: Alliance Digitale publishes 17 recommendations on the Digital Omnibus
- 18 June 2026: The Council removes Article 88b from its compromise text
- 28 July 2026: The deadline for Member State comments on Presidency text ST 10677/26 passes.
- 17 August 2026: Germany's drafting suggestions circulate as WK 11020/2026 ADD 4.
- 3 September 2026: The Presidency revised compromise text 12535/26 is issued, deleting Articles 88a and 88b and renumbering the AI clause as Article 88 bis.
- 10 September 2026: 19 organisations ask EU institutions to restore Article 88b
- 11 September 2026: The Antici Group (Simplification) meets on the revised text.
- 21 September 2026: noyb publishes the leaked Presidency and German documents.
- 30 October 2026: The EDPB consultation on anonymisation guidelines closes
Related PPC Land coverage
- European Commission proposes major GDPR changes for AI and data processing - The draft amendments to personal data, legitimate interest and breach thresholds circulated in November 2025.
- Brussels proposes sweeping GDPR changes to benefit AI developers - Early reporting on the legitimate interest basis for AI and the absence of an impact assessment.
- Europe proposes machine-readable consent signals for GDPR compliance - How Article 88b and its media exemption were designed.
- Netherlands raises serious concerns about EU Digital Omnibus privacy changes - A Member State assessment warning that the GDPR amendments could weaken protection.
- Europe's privacy watchdogs reject Commission's plan to narrow GDPR protections - The February 2026 joint opinion from the EDPB and EDPS.
- French ad industry draws a line in the sand on EU cookie overhaul - Alliance Digitale's support for the AI clause and its requested consent exemptions.
- EU Council drops cookie signal after Google lobbying - EUR 40-50 bn at stake - The June removal of Article 88b and the lobbying record behind it.
- 19 groups ask EU to re-insert the cookie banner fix Google lobbied out - The September open letter addressed to the Irish presidency and Parliament's co-rapporteurs.
- Germany pushes for sweeping data protection simplification beyond EU proposal - Berlin's October 2025 demands, including on AI training.
- Court clarifies personal data definition in pseudonymized transfers - The SRB judgment that Article 25a now tracks.
- EDPB replaces 2014 anonymity test with 3-part framework for ad data - Guidelines 02/2026 and their consultation deadline.
- EDPB's damning digest: how 'legitimate interest' fails in practice - An analysis of how controllers apply the balancing test across 62 decisions.
- GDPR's AI training legal battle: regulators converge but still clash - A comparative study of the legal bases regulators accept for AI training.
Summary
Who: The Irish Presidency of the Council of the European Union, which drafted the compromise; Germany, which proposed a legal presumption of legitimate interest for AI; the European Commission, author of the original Digital Omnibus; and noyb, the privacy group chaired by Max Schrems, which published the documents.
What: A restricted Presidency compromise text that allows personal data to be processed for AI development and operation on the legitimate interest basis without the Commission's AI-specific conditions and safeguards, returns cookie consent rules to Article 5(3) of the ePrivacy Directive with a new exemption for contextual advertising measurement, recasts pseudonymised data rules in a new Article 25a, and amends rather than repeals the platform-to-business regulation.
When: The compromise text is dated 3 September 2026 and was prepared for a Council working group meeting on 11 September 2026; Germany's comments are dated 17 August 2026; noyb published both today.
Where: The European Union, across all 27 Member States, through negotiations in the Council that precede trilogue talks with the European Parliament.
Why: The Digital Omnibus is meant to cut compliance costs, but the drafting choices on AI, device access and personal data decide how advertisers, publishers and AI developers may use personal data in Europe, and noyb argues the current direction subordinates fundamental rights to commercial interests.
Discussion