The ring of stars is only as strong as the lock that holds it — and the lock is open.
That is the practical upshot of a proposed "AI carve-out" in the GDPR, tucked into the EU's Digital Omnibus package. It is being sold as simplification. I think it is the wrong fix for the wrong problem. The GDPR's weakness was never that it asks too much of companies. It is that it is enforced too little, by regulators with too many reasons to look away.
What's on the table
The Commission tabled the Digital Omnibus on 19 November 2025, calling it a set of "technical amendments" to bring "immediate relief to businesses". On 21 September 2026, the privacy group noyb published two leaked Council documents showing where member states have taken it since: the Irish Presidency's compromise text of 3 September (Council doc. 12535/26) and Germany's written comments of 17 August.
Three changes stand out:
An AI legitimate-interest clause (Art. 88bis). Processing personal data "in the context of" developing or running an AI system "may be carried out for a legitimate interest of the controller". In plain terms: no consent needed if it's for AI.
A narrower definition of personal data. Data would not count as personal for a company that lacks the means to identify the person. Pseudonymous identifiers like user IDs, tracking IDs and IP addresses could regularly fall outside the GDPR.
"Abusive" data requests. Companies get more room to refuse access requests they judge to be made with "abusive intention".
Germany wants to go further still. Its comments strike out data minimisation and the "unconditional right to object" from the AI safeguards. The comments also exempt companies from the rights to information, access, rectification and erasure (Arts. 14, 16–18) where compliance would take "disproportionate effort".
It is not a unanimous rush in one direction: the compromise text has had to keep an "appropriate level of protection" wording to hold the room, and Germany's deletions did not go unopposed. To be fair to the text: the balancing test and a child-protection clause are still in there, and none of this is law yet. The GDPR applies unchanged today. Wave one of the same package, though, is already on the books: the European Parliament approved the AI Omnibus on 16 June 2026. This GDPR carve-out is wave two — and the one that rewrites a fundamental right. The Council has no agreed position, and Parliament's committees are still working through roughly 1,800 amendments with no vote scheduled. But the direction of travel is clear.
Why this is backwards
The case for the change deserves a fair hearing. The Commission presents the Omnibus as its answer to the Draghi report on European competitiveness, with burden-reduction targets of around 25% for companies and 35% for SMEs. Europe does need to build its own AI, and it can't do that if every developer drowns in legal uncertainty. But look at what this particular change actually does.
It isn't needed. The EU's own data-protection watchdogs have already said so. In their Joint Opinion 2/2026, the EDPB and EDPS point out that legitimate interest can already be used for AI under current law. A special clause is "not necessary", and its vague "may" and "where appropriate" wording would "decrease rather than increase legal certainty". On the personal-data definition, they "strongly urge" lawmakers not to adopt it at all.
It singles out the riskiest technology for the lightest rules. The AI Act treats AI as a technology that needs extra care, yet this clause would give it lighter data rules than any other computer system. The consumer group BEUC warned the Irish Presidency that the clause creates "a legal presumption that any personal data processing is legitimate by default, as long as it is used for AI." And it noted the contradiction: "The EU cannot simultaneously call for restrictions on AI development, while permitting such unfettered access to the personal data of European citizens."
It lets companies grade their own homework — and still doesn't deliver the promised relief. Whether data is "personal", whether a request is "abusive", whether compliance is a "disproportionate effort": each of these is judged first by the company doing the processing. BEUC calls this "effectively allowing companies to decide whether or not they choose to comply with the GDPR". Even Ecommerce Europe, which speaks for the online retailers this package was supposedly written for, complains that the new articles "introduce new compliance layers rather than removing existing ones". Simplification that adds complexity for ordinary businesses, while handing the largest AI firms a free pass, is not simplification.
It rewards the rule-breakers. More than 130 civil-society groups and unions warned in November 2025 that this approach would "punish the companies that want legal certainty and to play by the EU's rules". Much of what the carve-out would legalise is exactly what regulators and courts have spent years pushing back on. Rewriting the law to match the violations tells every company that patience pays better than compliance.
The real problem is enforcement
If the GDPR needs reform, it is in how it's enforced, not in what it protects.
Under the GDPR's "one-stop-shop" system, a company operating across the EU is supervised mainly by the regulator in the country where it has its main establishment. For most big US and Chinese tech and AI companies, that country is Ireland. It is where they base their EU headquarters, and it's where much of their European profit is booked and taxed.
The sums are enormous. According to the Irish Fiscal Advisory Council, just three companies paid 46% of Ireland's corporation tax in 2024, about €13 billion. Two of them are tech firms, and those two alone account for around 40% of all receipts.
In Ireland, that dependence is widely felt and openly discussed. It even shapes the debate over Irish unity: when The Irish News weighed whether the Republic could shoulder the cost of Northern Ireland, it noted that a third of the state's €107 billion in tax came from US tech and pharma giants. The sentiment is that these revenues pay for the country's future plans. As one Irish Times headline put it: "We can't wean ourselves off US multinationals' taxes even if we wanted."
That is a built-in conflict of interest. The government responsible for enforcing the rules against these companies also has a strong financial interest in keeping them happy and keeping them there. Tough enforcement risks the investment and tax base it depends on. Soft enforcement costs it nothing directly, because the harm falls on citizens all over Europe, not on its budget.
The track record fits. Ireland spent eight years fighting the European Commission so it would not have to collect €13 billion in back taxes from Apple, until the EU Court of Justice ruled against it in September 2024. Its data regulator, the DPC, has repeatedly been overruled for going too easy. In Meta's EU–US data transfer case, which began with a complaint in 2013, the DPC's preference was not to fine Meta at all; after objections from four other national regulators, the EDPB forced through a record €1.2 billion fine in May 2023. By the Irish Council for Civil Liberties' 2023 count, 75% of the DPC's decisions referred to its European peers had been overruled. Then, in October 2025, Ireland made Niamh Sweeney, a former Meta and WhatsApp public-policy head, one of its three data protection commissioners. The ICCL complained to the European Commission, warning it would be read "as a signal of impunity".
To be fair, the DPC does issue big fines: over €4 billion since 2018, including €530 million against TikTok in 2025, according to its latest annual report. But the landmark case against Meta shows how often the pressure to act has had to come from outside Ireland.
The Omnibus story makes this painfully concrete. Ireland currently holds the Council presidency and is the penholder on this very file. According to Privacy Next, it was the Irish presidency that reopened the AI question in July, asking member states whether the rules gave enough "legal certainty" and inviting "further measures to facilitate compliance" for AI companies. Germany's list of deletions was the answer.
So the same country that hosts the companies, and supervises them, is also steering the rewrite of the rules they're supervised under. Critics who call the draft a wish list for big tech are easier to understand in that light.
Weakening the text makes this worse. Every vague new term, whether "where appropriate", "disproportionate effort" or "abusive intention", is a judgement call. The regulator making that call first is the one with the conflict. As the consultancy GDPR Local notes, both a "blank cheque" reading and a harmless reading are "available from the same document". It isn't hard to guess which one a reluctant enforcer will lean towards.
What reform should look like instead
The businesses asking for simplification have a point: small companies do struggle with paperwork, and the single breach-notification system in the Omnibus is a sensible change that even the watchdogs welcome. But real reform would start where the law actually fails:
Break the link between host country and enforcer for the largest companies. Cross-border cases against the biggest platforms and AI firms could be handled by an EU-level body, or by the EDPB directly, instead of a single national regulator with a stake in the outcome.
Set deadlines. Complaints shouldn't sit for years. Binding timelines for cross-border cases would make the rules mean something.
Fund regulators properly. An understaffed regulator facing the legal teams of trillion-dollar companies is enforcement in name only.
Keep the rules themselves intact. No AI exception, no self-assessed definition of personal data. If AI firms need guidance, the EDPB has already given it.
Cut real red tape for small firms. Relief should go to the bakery and the local web shop, not to the companies with the biggest data appetite.
It isn't over yet
The good news is that nothing is decided. The GDPR applies in full today. The Council still has no common position. The European Parliament hasn't voted in committee, let alone in plenary, and trilogue negotiations haven't started. The file is handled jointly by Parliament's industry committee (ITRE) and its civil-liberties committee (LIBE), so the rights side has a seat at the table. And if an extreme version passes anyway, the privacy group that published the leak has signalled it will take it to the Court of Justice, which has struck down EU laws with comparable rights infringements before.
That means there is still time to push back, and to push for the reform that is actually needed. Write to your MEPs, especially those on ITRE and LIBE. Ask your government how it plans to vote in the Council. Support the groups watching this file closely.
Europe built the GDPR to say that people, not companies, own the right to their data. The answer to companies ignoring that promise isn't to rewrite the promise. It's to finally enforce it, with a regulator that has no reason to hold back.
Sources
Council compromise text 12535/26, leaked (3 Sept 2026)
Germany's comments, WK 11020/2026 ADD 4, leaked (17 Aug 2026)
European Commission: Digital Omnibus Regulation Proposal (19 Nov 2025)
EDPB–EDPS Joint Opinion 2/2026 (10 Feb 2026)
GDPR Local: What the leaked Council documents say (24 Sept 2026)
BEUC letter to the Irish Presidency (23 Sept 2026)
EDRi and 133 organisations: open letter (13 Nov 2025)
Praxikon: European Parliament file status (15 Sept 2026)
Ecommerce Europe: where the file is right now (7 Sept 2026)
Maples Group: key findings of the DPC's 2025 annual report (30 June 2026)