A European privacy campaign group has condemned proposed changes to the continent's data protection laws that would allow artificial intelligence companies to process personal information with minimal restrictions. None of Your Business (noyb), led by Austrian attorney Max Schrems, called the amendments an abandonment of core privacy principles in September 2026. The organization argues the revisions would permit tech giants to exploit decades of collected personal data simply by invoking AI development as justification.
The proposed amendments center on Article 88c of the General Data Protection Regulation, which the European Commission's leaked compromise draft relabels as Article 88bis. A briefing note states that when personal data processing serves the controller's interests "in the context of the development and technical operation of an AI system," such activities can be justified as legitimate interests. The changes emerged as part of the Commission's September initiative to strengthen EU competitiveness by "radically lighten the regulatory load" through immediate modifications to digital legislation. According to noyb, the amendments would eliminate the requirement for user consent, automatically granting companies an overriding legitimate interest whenever they train or deploy AI products. Personal information entered into digital systems decades earlier—including social media posts and chat messages—could be transferred to AI corporations even when individuals never became customers of those firms.
Schrems characterized the proposals as prioritizing corporate profits over fundamental rights. "Under these proposals, the profits of AI companies would trump Europeans' fundamental right to privacy," he stated, calling it a "digital expropriation of Europeans." He added that a probable majority of member states now favor the financial interests of executives like Elon Musk, Marc Zuckerberg, and the leadership of Google and OpenAI over data protection guarantees. The campaign group asserts the European Commission has sacrificed its data protection commitments to satisfy technology industry lobbying, though the European Parliament's position remains divided.
Noyb suggests the Court of Justice could evaluate whether the modifications align with EU fundamental rights, noting the court has previously invalidated legislation involving less severe infringements. The organization dismantled two transatlantic data transfer frameworks—the Safe Harbor Agreement in 2015 and the EU-US Privacy Shield in 2020—through successful challenges before the Court of Justice of the European Union. Schrems indicated litigation may be the sole remaining path to prevent the weakening of data protection standards for AI industry benefit, warning that extreme legislation vulnerable to judicial reversal would create legal uncertainty rather than the promised simplification. The confrontation signals a widening rift between regulatory ambitions to foster AI competitiveness and entrenched privacy safeguards that have defined European digital policy for years. Whether member states will retreat from accommodating industry demands or whether courts will again intervene to protect fundamental rights remains the central question facing European data governance.

