Skip to content

Europe · Analysis

Independent · Brussels & Berlin

Technology · Digital regulation

European Commission proposes delaying AI Act and easing GDPR rules for AI training

The digital omnibus package would give high-risk AI developers up to 18 months more to comply and allow personal data to train models without explicit consent, drawing accusations of a major rollback from rights groups.

By , Technology Editor

Published

9 min read

The European Commission has unveiled a sweeping package of changes that would delay core obligations of the Artificial Intelligence Act and relax key provisions of the General Data Protection Regulation, marking the most significant retreat from the EU's digital rulebook since both laws were adopted. Announced on 19 November as part of a "digital omnibus" simplification drive, the proposals would grant developers of high-risk AI systems up to 18 extra months to comply, while rewriting GDPR to allow personal data to be used for training AI models without the explicit consent that the regulation currently demands.

What the digital omnibus covers

The omnibus touches four major legislative acts: the AI Act, which entered force in August 2024 but applies in stages; the GDPR, in effect since 2018; the ePrivacy Directive, which governs electronic communications confidentiality; and the Data Act, which regulates non-personal data sharing. Together they form the backbone of the EU's attempt to set global standards for digital markets. The Commission frames the package as technical streamlining: clarifying definitions, reducing duplication, and cutting compliance costs. Critics see a political choice to prioritise competitiveness over the rights-based architecture built over the past decade.

Valdis Dombrovskis, the commissioner responsible for economy and productivity, put a precise figure on the expected benefit: the measures would save businesses and consumers €5bn in administrative costs by 2029. He argued that Europe had not yet reaped the full benefits of the digital revolution and could not afford to keep paying the price for failing to keep up with a changing world. The language echoes the competitiveness narrative that has dominated Brussels since Mario Draghi's report last autumn warned that the EU had fallen behind the United States and China in the emerging technologies that will drive future growth.

AI Act delays target high-risk systems

The most concrete change concerns the AI Act's implementation timeline. Providers of high-risk systems, those used in medical devices, surgical tools, exam scoring, recruitment, critical infrastructure, and other areas affecting health, safety or fundamental rights, would see their compliance deadline extended by up to 18 months. The Act's original staggered schedule already gave most high-risk providers until August 2026; the proposal would push that to early 2028. The Commission says the extra time reflects the complexity of the requirements and the need for harmonised standards that are still being developed by European standardisation bodies.

Henna Virkkunen, the executive vice-president overseeing tech policy, rejected suggestions that the AI Act was being watered down. She said action was needed to prevent European start-ups from moving to other jurisdictions, and insisted the Commission was not focused on big tech companies, which have the resources to comply with different rules. The distinction matters: the AI Act's obligations fall most heavily on smaller firms that lack the legal and engineering teams of Google, Microsoft, or Meta. Whether an 18-month extension meaningfully changes the calculus for a ten-person medical AI start-up in Berlin or Stockholm is an open question.

GDPR changes would permit AI training on personal data without consent

The GDPR amendments are more controversial. Under current law, processing personal data for a new purpose, such as training a large language model, generally requires a fresh legal basis, most commonly explicit consent. The Commission's proposal would introduce a specific exemption allowing personal data to be used for AI development without asking the data subject, provided certain safeguards are met. Michael McGrath, the commissioner for democracy, justice and the rule of law, described these as "targeted amendments" that clarify existing concepts while ensuring a high level of data protection across the EU.

European Digital Rights (EDRi), a network of civil society organisations across the continent, called the plans a major rollback of EU digital protections that risked dismantling the very foundations of human rights and tech policy in the EU. In its assessment, the changes would allow the unchecked use of people's most intimate data for training AI systems. The phrase "unchecked use" is contested: the Commission says safeguards will remain, but the text of the amendments has not yet been published in full, leaving Parliament and Council to scrutinise the detail. Until that text appears, the scope of the exemption, whether it covers health data, biometric data, or data concerning children, cannot be independently verified.

Cookie fatigue and the one-click fix

The ePrivacy Directive changes address a long-standing complaint: the endless stream of cookie banners that greet European internet users. The Commission proposes a one-click consent mechanism, allowing users to accept or reject all tracking with a single interaction. Virkkunen acknowledged the frustration directly: "I think we can all agree we have spent too much of our time accepting or rejecting cookies." The proposal would also introduce broader exemptions for certain types of analytics and functional cookies, reducing the number of sites that need to ask at all.

EDRi warns that the proposed exemptions would let businesses read data on phones and browsers without asking. The tension is familiar: the current regime, shaped by the 2009 ePrivacy Directive and reinforced by the GDPR, requires informed consent for any non-essential access to terminal equipment. Simplifying that regime without weakening the underlying right is technically difficult. The Commission's solution appears to be shifting the burden from the user interface to the browser level, an approach that has been discussed for years but never standardised across the EU.

Political context: Draghi, Trump, and the competitiveness pivot

The omnibus does not exist in a vacuum. Since Draghi's report landed in September 2024, the Commission has recast its entire legislative agenda around competitiveness and simplification. The same logic drives parallel proposals to scale back corporate sustainability reporting, due diligence obligations in supply chains, and agricultural regulations. At the same time, the EU has faced sustained pressure from the incoming Trump administration in Washington to rein in digital laws that American tech companies view as protectionist. Thierry Breton, who left the Commission in September 2024, wrote in the Guardian that Europe should resist attempts to unravel its digital rulebook "under the pretext of simplification or remedying an alleged 'anti-innovation' bias. No one is fooled over the transatlantic origin of these attempts."

Virkkunen pushed back firmly, saying the Commission was not looking at big industries or very big tech companies but at supporting European start-ups and SMEs to scale up and innovate in the EU. McGrath added that most feedback on the proposals had come from companies in the EU. Both claims are verifiable: the Commission's public consultation records will show the geographic and sectoral breakdown of respondents. Whether the policy response is proportionate to that feedback is a political judgment, not a technical one.

Industry reaction: not far enough, say big tech lobbyists

The Computer and Communications Industry Association (CCIA), whose members include Amazon, Apple, Google, and Meta, welcomed the proposals but said they did not go far enough. A CCIA representative urged "a more ambitious, all-encompassing review of the EU's entire digital rulebook." The position is consistent: large platforms have long argued that the cumulative weight of the AI Act, GDPR, Digital Services Act, Digital Markets Act, and Data Act creates regulatory uncertainty that discourages investment. Their preference is for a single, coherent framework rather than piecemeal adjustments.

Smaller European tech firms, represented by groups such as Allied for Startups and the European Tech Alliance, have been more cautious. They acknowledge the compliance burden but worry that weakening the GDPR's consent model undermines the trust advantage that European companies currently enjoy in global markets. If European AI products are perceived as less privacy-respecting than their American or Chinese competitors, the commercial case for building in Europe weakens. That argument has not featured prominently in the Commission's public messaging.

Legislative path: Parliament and Council must agree

The digital omnibus is a legislative proposal, not a decision. It now moves to the European Parliament and the Council of the EU, where ministers from the 27 member states will negotiate amendments. The Parliament's lead committees, likely Civil Liberties, Justice and Home Affairs (LIBE) for GDPR and ePrivacy, and Internal Market and Consumer Protection (IMCO) for the AI Act, will draft reports. Given the political sensitivity, the process could take 12 to 18 months. The Commission hopes for a first-reading agreement before the 2029 budget cycle, but the Parliament has historically defended the GDPR's consent architecture vigorously. The 2024 European elections produced a Parliament with a stronger right-wing contingent, which may be more sympathetic to simplification arguments, but the centre-right EPP group has also positioned itself as the guardian of the single market's regulatory coherence.

Sources

  1. the Guardian

    theguardian.com · 2025-11-19

People mentioned

  • Valdis Dombrovskis

    European Commissioner for Economy and Productivity, European Commission

  • Henna Virkkunen

    European Commission Executive Vice-President for Tech Sovereignty, Security and Democracy, European Commission

  • Michael McGrath

    European Commissioner for Democracy, Justice and the Rule of Law, European Commission

  • Thierry Breton

    Former European Commissioner for Internal Market, European Commission

  • Mario Draghi

    Former Prime Minister of Italy and former President of the European Central Bank, European Commission

Organisations

European Commission · European Parliament · Council of the European Union · European Digital Rights (EDRi) · Computer and Communications Industry Association (CCIA)

Related analysis

Selected because they share topics with this article

The newsletter

One important European story. Explained properly.

Delivered to your inbox on the days we publish. No daily digest, no push notifications, no advertising.

We store your address only to send the briefing. Unsubscribe in one click.