EU Plans to Bypass Consent for AI
Based on research by NOYB
A leaked proposal from the Irish EU Presidency suggests rewriting data protection rules to automatically legitimize the use of personal data for artificial intelligence. This move, backed by Germany and other member states, would allow giants like OpenAI, Google, and Meta to bypass consent requirements, effectively prioritizing their commercial interests over the fundamental right to privacy. For Swedish companies, this signals a potential collapse of the data sovereignty framework that has long defined European digital compliance.
The core of the controversy lies in a proposed amendment, currently Article 88bis, which argues that using data in the context of AI should grant companies an overriding legitimate interest. This means historical data, social media chats, and even information from non-customers could be harvested for training models without explicit permission. The proposal also seeks to narrow the definition of personal data by excluding pseudonyms like user IDs and IP addresses, while introducing subjective tests to determine if data subject rights are being abused. This creates a legal gray zone where enforcement becomes nearly impossible, as companies could argue their internal capabilities or the user’s intent justify any data processing.
The practical impact on Swedish CTOs and CISOs is severe. If this legislation passes, the compliance gap widens dramatically, as companies could face pressure to integrate US-based AI services that rely on this new, laxer data regime. This exposes organizations to significant reputational and legal risks, particularly if European data is transferred to jurisdictions with weaker protections. Furthermore, the erosion of data subject rights means your customers’ ability to demand deletion or correction of their data could vanish, undermining trust and violating the spirit of GDPR even if the letter of the law changes.
This regulatory shift reinforces the urgent need to process data locally within the EU. By keeping sensitive information within Swedish or European borders, you maintain a layer of legal insulation against global AI mandates that seek to commodify personal information. Local processing ensures that your data architecture remains aligned with strict privacy principles, protecting your organization from the fallout of a legislative race to the bottom that favors Big Tech profits over individual rights.