Scope: European Union, with specific strategic lenses on Italy, France, Germany and the United Kingdom; the assessment distinguishes the law currently in force from the Commission’s November 2025 proposal and the Council Presidency’s revised compromise text of 3 September 2026, and examines whether wider lawful access to personal data would principally reinforce incumbent global AI firms or contribute to an autonomous European AI industrial base. The structure and evidentiary standard follow the supplied Academic Governance Edition V9.0 protocol. Testo incollato

Executive Summary / BLUF

The central issue is more consequential than a technical amendment to the GDPR: Europe is deciding whether personal data should become a more readily usable productive input for artificial intelligence, while it still lacks assurance that the economic value generated from those data will be captured inside Europe.

The GDPR has not been suspended or replaced. The operative law remains Regulation (EU) 2016/679, including Article 6(1)(f), under which legitimate-interest processing requires a legitimate purpose, necessity and a balancing of the controller’s interest against the rights and freedoms of the individual. Regulation (EU) 2016/679 — European Parliament and Council Eur-Lex

The Commission’s Digital Omnibus, COM(2025) 837, proposed on 19 November 2025, introduced an explicit GDPR provision for AI development and operation while retaining express safeguards. The ordinary legislative procedure 2025/0360/COD remains open, so this proposal is not current law. COM(2025) 837 final — European Commission Procedure 2025/0360/COD — EUR-Lex Eur-Lex

The Council Presidency’s 3 September 2026 revised compromise, document 12535/26, materially alters that architecture: its tracked text removes from the operative AI provision the Commission language expressly identifying children, consent requirements under other laws, AI-specific data minimisation, enhanced transparency and an unconditional AI-specific right to object, while retaining a general requirement for safeguards and linking processing to Article 6(1)(f). Presidency revised compromise text — Council of the European Union, 3 September 2026 noyb.eu

This does not create an unrestricted entitlement to ingest every European’s historic digital life into a model. Existing GDPR principles, Article 6 requirements, Article 21 objection rights and other applicable law remain relevant unless and until the legislature modifies them. The European Data Protection Board has already held that reliance on legitimate interest in AI requires a case-specific analysis rather than an automatic presumption of legality. Opinion 28/2024 on AI Models — European Data Protection Board EDPB

The industrial-policy problem is nevertheless genuine: the proposed rule is nationality-neutral. It does not reserve the resulting data advantage for European companies, and the GDPR itself expressly reaches qualifying controllers established outside the Union. Consequently, any legal widening of AI data access can benefit European developers but can also be exploited by global incumbents already possessing massive user relationships, historic datasets, distribution channels, capital and computing infrastructure. GDPR, Article 3 — EUR-Lex Eur-Lex

Europe is not starting from zero: the EU has established 19 AI Factories and 13 AI Factory Antennas, while France, Germany and Italy are building national AI strategies and infrastructure around the same objective of technological sovereignty. AI Factories — EuroHPC Joint Undertaking EuroHPC The decisive question is therefore not simply whether Europe permits more data processing, but whether data liberalisation, compute, capital, models, procurement and industrial deployment are integrated strongly enough for European firms to retain part of the value created from European data.

Europe Is Building AI Infrastructure. The Harder Test Is Who Captures the Value

Europe’s artificial-intelligence debate is moving from regulation to production capacity, but the central economic question remains unresolved: who will own the models, infrastructure and revenues created from European data, electricity and industrial knowledge? The European Commission’s AI Continent programme sets a €200 billion investment ambition, including €20 billion for AI Gigafactories, while EuroHPC now reports 19 AI Factories, 13 Factory Antennas and 14 supercomputers. That is a material change in industrial policy, yet infrastructure located in Europe is not automatically European technological sovereignty. A European data centre can still depend on non-European accelerators, foreign cloud software and externally controlled foundation models. The next phase will therefore be decided not by machine counts alone, but by whether public compute, capital, procurement and industrial datasets produce companies and intellectual property that remain economically anchored in Europe.

Europe has finally recognised that AI policy begins with machines

The Commission’s current architecture marks a departure from the period when European AI policy was defined primarily through rules. EuroHPC reports 19 AI Factories and 13 AI Factory Antennas built around a wider network that includes 14 supercomputers, while the Gigafactory concept envisages individual facilities capable of assembling more than 100,000 advanced AI processors. The €20 billion Gigafactory mobilisation sits inside the wider €200 billion AI Continent investment ambition, and the proposed Cloud and AI Development Act seeks at least to triple European data-centre capacity within five to seven years.

Those figures matter because frontier AI is increasingly an infrastructure industry. Training, fine-tuning and serving large models require accelerators, storage, networking, cooling, electricity and specialised software at scales that young European firms cannot finance independently. Public intervention is therefore attempting to reduce an entry barrier that previously favoured companies already operating hyperscale infrastructure.

The policy shift is rational, but it creates a second-order problem. Public capital can increase the quantity of computation available in Europe without determining who captures the most profitable layers above it. If European Gigafactories predominantly host foreign-controlled models on foreign-designed processors through foreign cloud stacks, Europe gains capacity, employment and resilience, but not necessarily control over the highest-margin intellectual property.

The adoption numbers show why industrial diffusion matters more than symbolic model races

Europe’s comparative advantage is not a consumer-platform economy equivalent to that of the United States. It is an industrial economy containing advanced manufacturing, machinery, automotive, chemicals, pharmaceuticals, energy, logistics and public-service systems that generate valuable proprietary data. That makes industrial adoption more important than a competition over whether one European general-purpose model briefly matches an American rival on a benchmark.

Eurostat reported that approximately 20% of EU enterprises with at least ten employees used AI in 2025, compared with 13.5% in 2024 and 8.1% in 2023. The aggregate masks a sharp scale divide: AI use reached about 55.03% among large enterprises, 30.36% among medium-sized companies and roughly 17% among small firms.

That distribution defines the economic problem. Europe can build frontier compute while leaving most of its productive base unable to exploit it. For the Mittelstand in Germany, specialised manufacturers in Italy and industrial suppliers across the single market, sovereign AI will matter only if computing capacity can be accessed at predictable prices and combined with proprietary company data without surrendering process knowledge to an external platform.

The relevant objective is therefore not simply more AI companies. It is a production system in which European firms can move from data to computation, from computation to models, and from models to industrial products without losing control at each stage.

Italy has built serious compute; now it has to build serious companies on top of it

Italy illustrates the difference between infrastructure strength and commercial scale. The IT4LIA AI Factory is being constructed around CINECA, Leonardo, the LISA upgrade and additional cloud infrastructure, with EuroHPC expecting the broader environment to provide more than 20,000 GPUs when completed. Procurement for the dedicated IT4LIA AI-optimised supercomputer carries an estimated value of approximately €290 million, while the LISA upgrade includes 166 eight-way GPU servers intended for large-language-model and multimodal workloads.

This gives Italy something economically significant: a publicly anchored AI-compute concentration tied to one of Europe’s established high-performance computing centres. The Italian Strategy for Artificial Intelligence 2024–2026 also links research, public administration, enterprises and skills rather than treating AI as a research programme alone.

The missing conversion mechanism is scale. Italy’s strongest prospective uses sit inside machinery, robotics, automotive components, aerospace, biomedical technologies, pharmaceuticals and advanced manufacturing, where proprietary industrial knowledge matters more than internet-scale consumer data. The country therefore does not need to reproduce the economics of a global social platform. It needs to ensure that IT4LIA produces commercially deployable systems, exportable software and firms capable of financing growth beyond the laboratory and pilot stage.

A €290 million machine that is heavily used can still represent an industrial-policy failure if the resulting value is captured primarily by suppliers further up or down the chain.

France is trying to assemble the full stack rather than one component

France has taken the broadest national approach among the large continental economies. Approximately €2.5 billion from France 2030 has been associated with the national AI strategy, while the February 2025 AI Action Summit produced announcements of approximately €109 billion in French and foreign AI-related investment commitments.

The distinction between commitments and realised expenditure is important, but so is the architecture behind them. France is combining data-centre investment with domestic model development, research, talent programmes, cloud-security policy and an electricity system that the government actively presents as an advantage for power-intensive AI infrastructure.

The French approach is economically stronger than a policy based solely on attracting data centres because Paris is explicitly attempting to connect chips, compute, models, services and robotics. The SecNumCloud framework adds another layer by addressing sensitive cloud workloads and the requirements of public administration and strategic sectors.

The risk is that physical investment runs faster than domestic intellectual-property formation. France can attract enormous capital into server facilities while still allowing the highest-value model, cloud and accelerator rents to accrue elsewhere. The €109 billion headline will therefore matter less than the ownership structure of the software, models and companies operating above those facilities.

Germany’s wager is that factories will matter more than chatbots

Germany’s strategy is anchored in industrial data and infrastructure expansion. Federal policy now places AI among the technologies central to the Hightech Agenda Deutschland, while the government’s data-centre strategy reports roughly 3 GW of national connection capacity and approximately 500 MW associated with AI, with targets to at least double overall capacity and quadruple high-performance computing and AI capacity by 2030 relative to 2025.

EuroHPC’s German infrastructure adds another layer. HammerHAI is specified with 860 NVIDIA B200 GPUs, approximately 15 exaflops of peak AI inference performance and 10 PB of storage, while Germany also hosts major EuroHPC capacity through JUPITER.

The decisive German asset, however, is not the number of GPUs. It is the data accumulated inside automotive production, machinery, chemicals, pharmaceuticals, logistics and the Mittelstand. Those datasets encode processes that competitors cannot simply scrape from the open internet.

This creates an opportunity for a European AI model fundamentally different from the American consumer-platform model. A German industrial company does not necessarily need the world’s largest foundation model; it needs secure, specialised systems capable of improving engineering, maintenance, design, procurement and production without exporting its underlying know-how.

Germany’s constraint is execution. Grid connections, energy cost, permitting and financing determine whether the planned doubling and quadrupling translate into operational capacity quickly enough to influence corporate investment decisions.

Britain shows that regulatory freedom does not eliminate the compute problem

The United Kingdom provides a useful comparison precisely because it sits outside the EU’s regulatory framework. Its policy still reaches the same conclusion: sovereign AI requires large publicly supported computing infrastructure.

The UK Compute Roadmap provides more explicit numerical targets than most continental programmes. The government intends to expand the AI Research Resource from approximately 21 AI ExaFLOPS in 2025 to 420 AI ExaFLOPS by 2030, a twentyfold increase supported by more than £1 billion, alongside up to £750 million for a new national supercomputer within a wider public-compute package of approximately £2 billion.

AIRR combines Isambard-AI in Bristol and Dawn in Cambridge and has already created access mechanisms under which qualifying projects can seek between 50,000 and 1.4 million GPU hours.

The British case therefore weakens the proposition that Europe’s primary AI problem is excessive regulation. A country with regulatory autonomy has independently concluded that public compute, infrastructure investment and national access mechanisms are necessary because private market structure alone does not guarantee domestic frontier capacity.

The relevant comparison between Britain and the EU is not deregulation against regulation. It is two different institutional systems trying to overcome the same concentration of compute, capital and technological scale.

The next 24 months will decide whether public money creates European leverage or cheaper inputs for incumbents

The first AI Gigafactory selections, IT4LIA deployment, France’s conversion of announced investment into operating assets, Germany’s implementation of its 2030 capacity programme and Britain’s AIRR expansion will provide the first serious evidence of whether current policy is creating sovereign capability rather than infrastructure volume.

The test over the next 12–24 months is measurable. European scale-ups need predictable commercial access to EuroHPC resources rather than episodic research allocations. Public procurement must provide anchor demand for European cloud, model and application providers. Gigafactory financing must generate additional European capability rather than merely reduce the capital cost of facilities dominated by external suppliers. Industrial companies must be able to combine proprietary data with advanced AI without transferring operational knowledge outside trusted environments.

The cost of failure will not fall primarily on regulators or public research laboratories. It will fall on European manufacturers that pay recurring inference and cloud rents to external platforms, on start-ups forced to scale under foreign infrastructure providers, on taxpayers who finance compute without capturing the resulting intellectual property, and on governments that discover that physical data-centre capacity is not the same thing as technological control.

Europe is now spending enough money to build meaningful AI infrastructure. The question is whether it will also build the ownership structures, procurement markets and companies required to keep a meaningful share of the value.


Navigational Index

Pillar One — The legal transformation

What the Digital Omnibus actually changes, what remains protected by the GDPR, how Article 6(1)(f), sensitive data, pseudonymisation and objection rights would operate, and where the September 2026 Council compromise differs from the Commission proposal.

Pillar Two — The industrial distribution of the data dividend

Whether broader access to personal data structurally advantages established US and global AI platforms, whether Europe possesses sufficient compute, capital, models and market access to exploit the same rules, and why legal access to data is not equivalent to technological sovereignty.

Pillar Three — Europe’s sovereign-AI capacity

How the EU, Italy, France and Germany are constructing compute and AI ecosystems, how the United Kingdom provides a regulatory and industrial comparator outside the EU framework, and which institutional choices will determine whether European data produces European value.


Master Abstract

The reform is real, but the headline “GDPR is being abolished for AI” is legally inaccurate

The relevant legislative file is the Commission’s Digital Omnibus proposal COM(2025) 837, tabled on 19 November 2025 as a broad simplification package covering the GDPR, Data Act and other digital legislation. The Commission explicitly presented the package as an attempt to reduce administrative burdens and increase the availability of data for innovation while maintaining privacy and fundamental-rights protections. Digital Omnibus Regulation Proposal — European Commission, 19 November 2025 Strategia Digitale Europea The proposal remains within the ordinary legislative process under 2025/0360/COD, and therefore neither its original wording nor the September 2026 Presidency compromise can be treated as enacted GDPR law. Procedure 2025/0360/COD — EUR-Lex Eur-Lex

That distinction is particularly important because a separate instrument, the Digital Omnibus on AI, dealing with the implementation of the AI Act, has already entered into force on 27 July 2026. The two files should not be conflated: the AI Omnibus already in force concerns the AI regulatory framework, while the contested GDPR changes discussed here remain part of the still-pending broader Digital Omnibus legislative file. AI Omnibus enters into force — European Commission, 27 July 2026 Strategia Digitale Europea

The original Commission proposal introduced Article 88c, “Processing in the context of the development and operation of AI.” The September Council text shows, through tracked deletions and additions, how this provision has been reshaped and provisionally renumbered Article 88 bis. The operative compromise text states that processing personal data in the development and operation of an AI system or AI model may be carried out for a legitimate interest of the controller or a third party in accordance with Article 6(1)(f), while a separate paragraph retains an obligation to implement appropriate technical and organisational measures and safeguards. Presidency revised compromise text, document 12535/26 — Council of the European Union noyb.eu

The tracked document is particularly revealing because it records what has disappeared from the article itself. The earlier formulation expressly stated that the legitimate interest should not override the interests, fundamental rights and freedoms of the data subject, “in particular where the data subject is a child,” and referred expressly to cases in which Union or national law requires consent. Those words are struck through in the 3 September compromise. The earlier second paragraph also expressly identified data minimisation during source selection, training and testing, protection against disclosure of residually retained information, enhanced transparency and an unconditional right to object; that package likewise appears deleted from the operative article and replaced by much shorter general language. Council Presidency revised compromise, Article 88 bis — 3 September 2026 noyb.eu

That is a significant weakening of AI-specific statutory safeguards, but it is not the same as deleting those concepts from European data-protection law. Article 6(1)(f) of the existing GDPR already requires that processing be necessary for a legitimate interest and that this interest not be overridden by the rights and fundamental freedoms of the data subject, with children specifically identified as deserving particular protection. Article 21 also gives individuals a right to object to processing based on Article 6(1)(f), although — unlike the deleted Commission AI-specific language — the ordinary Article 21 right is not unconditional, because a controller may continue where it demonstrates compelling legitimate grounds overriding the individual’s interests, rights and freedoms. General Data Protection Regulation, Articles 6 and 21 — EUR-Lex Eur-Lex

This distinction is central. The Council text does not literally eliminate the balancing exercise; instead, it removes several explicit AI-specific restatements and safeguards from Article 88 bis and places more legal weight back on the general GDPR framework. The practical consequences could nevertheless be considerable because litigation, supervisory interpretation and corporate compliance would begin from a legislative statement explicitly recognising AI development and operation as a context in which legitimate interest may be invoked.

Legitimate interest is not a blank cheque

The European Data Protection Board’s Opinion 28/2024, adopted on 18 December 2024, addressed precisely whether legitimate interest can provide a lawful basis for the development and deployment of AI models. It did not establish a universal prohibition, but neither did it establish an automatic entitlement. The Board’s framework requires assessment of whether a legitimate interest exists, whether processing is necessary for that interest and whether the data subject’s interests, rights or freedoms override it, with the circumstances of the particular processing remaining decisive. Opinion 28/2024 — European Data Protection Board EDPB

This means that the difference between the existing environment and the proposed framework is subtler, but potentially more powerful, than the claim that “consent disappears.” Consent is already only one of several legal bases under Article 6. The important shift is that legislators are considering making AI development and operation an expressly recognised setting for legitimate-interest processing, thereby reducing part of the legal ambiguity that currently surrounds training on personal data.

The effect on old chats, publications, profiles and digital archives therefore depends on their provenance, the original processing circumstances, the reasonable expectations of individuals, the purpose pursued, necessity, data minimisation, Article 9 restrictions where sensitive data are involved, objection rights and other applicable rules. Merely possessing twenty years of user information would not, by itself, establish compliance.

The special-category-data provision is economically important and legally sensitive

The September text also introduces a proposed derogation concerning unintentional and residual special-category personal data in AI development and technical operation. The categories covered by Article 9 of the GDPR include, among other matters, information concerning racial or ethnic origin, political opinions, religious or philosophical beliefs, trade-union membership, genetics, biometrics used for identification, health and sex life or sexual orientation. General Data Protection Regulation, Article 9 — EUR-Lex Eur-Lex

The Council compromise does not authorise intentional bulk exploitation of those categories simply because AI is involved. Its proposed rule is directed to information that remains unintentionally and residually within datasets despite technical and organisational measures intended to prevent the processing. Where such information is identified, the controller is expected to remove it; where removal is technically impossible or would require manifestly disproportionate effort, the text requires measures preventing further use, including preventing the information from influencing outputs or being disclosed to third parties. Presidency revised compromise text, recitals and proposed Article 9 amendments — Council of the European Union noyb.eu

That provision matters because very large training corpora cannot reliably be assumed to contain only ordinary personal information. It attempts to resolve a real engineering problem — incidental contamination of datasets — but simultaneously creates a governance question over when “unintentional and residual” processing ends and substantive exploitation begins.

Pseudonymisation could redraw the GDPR’s practical perimeter

A second potentially structural change concerns the identification of individuals from pseudonymised information. The Presidency compromise proposes that pseudonymised data would not be considered personal data for a person unable to identify the individual concerned, subject to additional conditions elsewhere in the proposed article. Presidency revised compromise text, proposed Article 25a — Council of the European Union noyb.eu

The significance extends well beyond AI training. The current GDPR definition turns on whether a natural person is identified or identifiable, directly or indirectly, taking account of the relevant circumstances. Changing how identifiability is assessed for a particular recipient can therefore change whether particular datasets remain within the GDPR’s regulatory perimeter for that entity. General Data Protection Regulation, Article 4 — EUR-Lex Eur-Lex

The EDPB and EDPS have consequently treated the Digital Omnibus proposals as much more than housekeeping. In their Joint Opinion 2/2026, they supported simplification objectives while raising concerns about changes capable of affecting the substantive protection provided by the GDPR, including questions surrounding pseudonymisation and the definition of personal data. EDPB-EDPS Joint Opinion 2/2026 — European Data Protection Board and European Data Protection Supervisor EDPB

The Meta case demonstrates why the reform matters

The policy dispute is not hypothetical. In 2025 Meta moved toward using public material associated with adult Facebook and Instagram users in Europe for AI training while relying on legitimate interest rather than requiring opt-in consent. noyb issued a formal cease-and-desist letter on 14 May 2025 challenging Meta’s reliance on Article 6(1)(f); the organisation’s position was that the processing lacked an adequate legal basis and should instead require consent. Cease and Desist — Training of Meta AI in the EU — noyb, 14 May 2025 noyb.eu


noyb is a donation-funded NGO based in Vienna, Austria working to enforce data protection laws, in particular the GDPR and the ePrivacy Directive. At the present, a team of more than 20 legal and IT experts from all over Europe is working to ensure that the fundamental right to privacy is respected by the private sector. 


That example should be understood as a contested legal case rather than proof that all legitimate-interest AI training is unlawful. Indeed, the EDPB’s own 2024 opinion recognises that legitimate interest can, under appropriate circumstances, provide a lawful basis for AI-related processing. The unresolved policy issue is therefore the width of the permissible corridor and the burden that controllers must satisfy before entering it.

noyb now characterises the September 2026 Council direction as “digital expropriation” and argues that companies holding decades of historical personal information would acquire a disproportionate advantage. This is the organisation’s advocacy assessment, not a description of enacted law, and its more expansive claims should be read accordingly. AI: EU Member States plan “digital expropriation” — noyb, 21 September 2026 noyb.eu

The industrial-policy question is harder than the privacy question

The strongest criticism of the emerging framework does not require accepting the proposition that AI companies receive unlimited access to European data. The more defensible strategic concern is that a horizontal relaxation or clarification applies to incumbents and challengers alike, whereas their ability to exploit the resulting data opportunity is radically unequal.

The GDPR’s territorial rules illustrate the problem. Article 3 applies not only to controllers established within the Union but, under specified conditions, also to controllers outside the Union when they offer goods or services to people in the EU or monitor their behaviour there. An AI-data provision inserted into that framework would therefore not constitute a European industrial preference; it would create a legal opportunity available to any qualifying controller operating within the GDPR’s scope. General Data Protection Regulation, Article 3 — EUR-Lex Eur-Lex

This is where data sovereignty and AI sovereignty diverge. A European legal regime can govern European personal data without ensuring that the models trained from those data are European, that the compute is European, that the intellectual property is held in Europe, that inference revenues accrue to European firms, or that downstream technological dependencies are reduced.

Consequently, the proposition that broader AI data access will automatically create a European AI industry is unsupported. Data are one strategic input among several: advanced compute, accelerators, data-centre power, engineering talent, foundation-model capability, risk capital, cloud distribution, procurement markets and global scale all matter. Removing one constraint does not remove the others.

Europe is nevertheless building the infrastructure required to capture part of the value

The counterargument to a simple “Europe is giving its data away” thesis is that the Union is simultaneously creating public AI infrastructure intended precisely to lower entry barriers for European companies. EuroHPC now reports 19 AI Factories and 13 AI Factory Antennas, providing computing power and customised support to SMEs and start-ups. AI Factories — EuroHPC Joint Undertaking EuroHPC

The Commission’s AI Factory programme has expanded through successive selections across the Union, including installations in France and Germany, while its broader policy direction links compute infrastructure, data availability and industrial adoption. AI Factories — European Commission Strategia Digitale Europea

The strategic significance is clear: if Europe can combine lawful data access + European compute + European model developers + domestic industrial datasets + public procurement + capital, a more permissive data environment could support European AI capacity rather than merely foreign platforms. If those complementary conditions remain inadequate, the same legal opening can reinforce actors that already possess superior scale.

Italy, France, Germany and the United Kingdom

Italy: valuable domain data, but conversion into model ownership remains the challenge

Italy’s Artificial Intelligence Strategy 2024–2026 explicitly recognises that the country’s distinctive economic assets increasingly depend on the codification and availability of data and AI models capable of representing Italian industrial and institutional specificities. The strategy is organised around research, public administration, enterprises and skills, and explicitly discusses the construction of data infrastructures and country-specific AI capabilities. Italian Strategy for Artificial Intelligence 2024–2026 — Department for Digital Transformation and AgID Digitale Italia

For Italy, the principal strategic asset is therefore not necessarily consumer-scale social-network data but high-value sectoral information embedded in manufacturing, mechanical engineering, healthcare, public administration, cultural assets and specialised SMEs. The policy risk is that liberalisation of personal-data use could have limited sovereign benefit if Italian companies remain users of foreign foundation models rather than developers or owners of the systems extracting value from those data. Conversely, trusted sectoral datasets linked to European computing infrastructure offer Italy a credible route toward specialised and industrial AI rather than an attempt to reproduce the scale economics of every global consumer model.

France: the clearest continental attempt to combine capital, compute and model development

France has made technological sovereignty a central element of its AI policy and used the February 2025 AI Action Summit in Paris to position itself as a European centre for model development, investment and infrastructure. The Élysée presented the summit as part of an effort for France and Europe to remain major actors in the global AI transformation, accompanied by more than one hundred announced actions and commitments across access, sustainable AI and international governance. AI Action Summit — Élysée, February 2025 elysee.fr

France is therefore unusually well positioned to capture part of any additional European data dividend because it combines domestic model development, public research, compute infrastructure and policy-backed investment mobilisation. Yet the same structural caveat applies: an EU-wide legitimate-interest rule would not allocate French or European personal information preferentially to French developers.

Germany: industrial data may matter more than consumer data

Germany’s Hightech Agenda Deutschland, adopted in July 2025, makes AI one of six strategic technologies and explicitly links technological capability to competitiveness, value creation and sovereignty. The federal government subsequently committed to AI initiatives, industrial application and expanded computing infrastructure. Hightech Agenda Deutschland — Federal Government of Germany Bundesregierung

Germany’s September 2026 data-centre strategy adds an unusually concrete infrastructure objective: it seeks to double overall German data-centre connection capacity by 2030 relative to 2025 and at least quadruple connection capacity devoted to high-performance computing and AI. Data Centre Strategy — Federal Government of Germany, 18 September 2026 Bundesregierung

For Germany, the strategically decisive dataset may therefore be the information locked inside the Mittelstand, industrial supply chains, machinery, automotive systems, chemical engineering and manufacturing processes, rather than historic consumer conversations. The government itself has publicly emphasised the underexploited potential of data held by German SMEs and has linked that opportunity to domain-specific AI development. Federal Chancellor address on artificial intelligence and industry — Bundesregierung Bundesregierung

United Kingdom: an external comparator pursuing compute and data access without the EU legislative architecture

The United Kingdom no longer participates in EU legislation and therefore provides a useful comparator rather than a constituent part of the Digital Omnibus debate. Its AI Opportunities Action Plan, published on 13 January 2025, explicitly warned that the UK risked falling behind the United States and China despite possessing significant AI research and commercial capabilities, and proposed a broad programme covering sovereign capacity, computing, data access, adoption and sectoral growth. AI Opportunities Action Plan — UK Department for Science, Innovation and Technology GOV.UK

The British case demonstrates that the European strategic dilemma is broader than GDPR compliance. A country can pursue a more innovation-oriented regulatory environment and still confront the same fundamental questions over compute scale, capital intensity, frontier-model ownership and dependence on foreign technology platforms. Regulatory flexibility can improve conditions for innovation, but it does not itself manufacture a sovereign AI industry.

Key Evidence Table

IndicatorValue / statusReference dateDefinition / scopeIssuerExact source
Digital Omnibus GDPR reformPending, not law26 Sep 2026Ordinary legislative procedure 2025/0360/CODEU institutionsProcedure 2025/0360/COD — EUR-Lex
Commission proposalCOM(2025) 837 final19 Nov 2025Broad digital simplification including GDPR amendmentsEuropean CommissionCOM(2025) 837 — EUR-Lex
Presidency revised compromiseDocument 12535/263 Sep 2026Revised negotiating text prepared for Council discussionsCouncil of the EUPresidency revised compromise
AI legitimate interestExplicitly recognised as potentially availableSep 2026 draftAI development and operation under Article 6(1)(f)Council Presidency textArticle 88 bis draft
Existing legitimate-interest testRemains operative lawCurrentInterest, necessity and rights-balancing requirementsEU legislatureGDPR — EUR-Lex
EDPB AI positionCase-specific legitimate-interest assessment required18 Dec 2024AI-model development and deploymentEDPBOpinion 28/2024
EU AI infrastructure19 AI Factories + 13 Antennas2026Compute and support infrastructure for European AI ecosystemEuroHPC JUAI Factories — EuroHPC
German data-centre targetOverall capacity ×2; HPC/AI capacity at least ×42030 vs 2025Connection capacityGerman Federal GovernmentRechenzentrumsstrategie

Competing Strategic Pathways

PathwayDiagnostic supportDisconfirming evidenceIndicatorsCurrent standing
European AI capacity captures a substantial share of the new data valueEuroHPC AI Factories, national compute strategies, French/German/Italian industrial policies, specialised European modelsEuropean firms still face capital, scale, semiconductor and distribution constraintsEuropean model training volumes, EuroHPC utilisation, procurement share, private AI investment, model deployment in industryInstitutionally plausible, but dependent on complementary industrial execution
The reform principally strengthens existing global incumbentsNationality-neutral rule; incumbents possess large user archives, compute and established distributionEuropean public compute and sector-specific datasets can lower entry barriers for challengersConcentration of AI-data processing, cloud/model-provider shares, acquisitions, compute consumptionMaterial structural risk, but not an automatic legal consequence
Litigation and supervisory interpretation preserve a tighter practical regime than the statutory wording suggestsArticle 6(1)(f), Article 21, Charter rights, EDPB case-specific analysis remain relevantAn explicit AI provision can shift legal expectations and reduce uncertainty for controllersCJEU judgments, EDPB guidance, DPA enforcement, final Article 88 bis wordingHighly consequential uncertainty until the final law and subsequent jurisprudence emerge

Principal Gaps and Watch Indicators

The first decisive indicator is the final Council position and subsequent Parliament–Council negotiation. The 3 September 2026 document is a Presidency compromise, not the final law, and Article 88 bis can still be narrowed, expanded, renumbered or deleted before adoption. Procedure 2025/0360/COD — EUR-Lex Eur-Lex

The second is whether the final instrument restores explicit safeguards concerning children, consent-dependent processing, source-selection minimisation, transparency and objection, or instead relies principally on general GDPR provisions.

The third is the treatment of pseudonymised data, because a recipient-relative definition of identifiability could affect a much larger universe of commercial and research datasets than AI training alone.

The fourth is jurisprudential rather than legislative: the practical value of Article 88 bis will depend heavily on how supervisory authorities and ultimately the Court of Justice interpret the relationship between the new provision and Articles 5, 6, 9, 21 and 25 of the GDPR.

The fifth is industrial: Europe should be watched not simply for the number of AI initiatives announced, but for measurable growth in European-controlled compute, model ownership, inference revenues, data-centre capacity, AI procurement, venture financing and industrial deployment.

The sixth is distributional: if the largest increase in lawful AI processing is undertaken by companies whose principal model ownership, compute infrastructure and monetisation remain outside Europe, the reform will have improved the European data supply without proportionately improving European technological sovereignty; if the opposite occurs, the same law could become an input to European AI industrialisation.

Net Assessment

The public record does not support the proposition that Brussels has already authorised AI companies to seize Europeans’ data without restriction. That law does not exist today. The GDPR remains operative, Article 6(1)(f) remains conditional, Article 21 remains relevant, and the Digital Omnibus remains under negotiation. General Data Protection Regulation — EUR-Lex Procedure 2025/0360/COD — EUR-Lex Eur-Lex

The September 2026 compromise nevertheless represents a material policy movement toward making personal data easier to use in AI development under legitimate interest, particularly because several explicit AI-specific protections contained in the earlier architecture have been removed from the operative provision. That deserves to be treated as substantive regulatory change rather than administrative simplification. Council Presidency revised compromise, document 12535/26 noyb.eu

The more important strategic conclusion is that data liberalisation and technological sovereignty are not the same policy. Europe can make more data available for AI and still increase its dependence on non-European model providers; equally, it can combine lawful data access with EuroHPC compute, national AI programmes, industrial datasets, European developers and procurement to build a more competitive domestic ecosystem.

The September debate therefore exposes a deeper European policy question: if personal data are to become a more readily accessible factor of AI production, who owns the models, infrastructure, intellectual property and revenue streams that transform those data into economic power?

The answer is not contained in Article 88 bis. It will be determined by Europe’s ability to connect privacy law with compute, investment, industrial data strategy, competition policy and domestic model development. Without that connection, a GDPR relaxation risks becoming an input subsidy available equally — and perhaps more immediately — to the strongest global incumbents. With it, the same reform could form one component of a genuine European AI industrial strategy.

No decision-useful visualisation is supportable from the verified record at this stage because the core comparison concerns evolving legal text and strategic capacity rather than a sufficiently homogeneous quantitative series.

European AI • Data Governance • Strategic Autonomy

Europe’s AI Data Bargain

The strategic question is no longer simply whether personal data may be processed for artificial intelligence, but whether Europe can convert wider lawful data access into European-controlled models, infrastructure, intellectual property and economic value rather than strengthening already dominant global platforms.

The Three Strategic Questions

Legal Architecture

How far does legitimate interest expand?

The draft explicitly recognises Article 6(1)(f) as a potential lawful basis for AI development and operation, while several AI-specific safeguards appearing in earlier text have been removed from the operative provision.

Economic Distribution

Who captures the value of European data?

A nationality-neutral legal opening benefits European developers but also firms already possessing massive historical datasets, computing capacity, capital, global platforms and mature AI distribution channels.

Strategic Sovereignty

Can Europe turn data into technological power?

Sovereignty depends on more than data access: Europe must connect data with compute, foundation models, capital, infrastructure, procurement, industrial adoption and ownership of resulting intellectual property.

From Personal Data to AI Economic Value

European Data Chats, publications, behavioural records, platform histories, industrial and institutional datasets.
Legal Access GDPR lawful basis, necessity, legitimate interest, rights balancing and applicable safeguards.
AI Production Training, fine-tuning, testing, inference, specialised models and industrial applications.
Value Capture Model ownership, cloud revenue, IP, enterprise applications, productivity gains and strategic dependence.

Two Possible Economic Outcomes

Path A — Data liberalisation reinforces external incumbents

  • Large technology groups already possess historical user relationships and extensive datasets.
  • They operate mature foundation models and global distribution platforms.
  • They possess greater access to capital, cloud infrastructure and accelerator capacity.
  • European data become an additional productive input without equivalent European capture of model ownership or revenues.

Path B — Data access accelerates European AI capacity

  • EuroHPC infrastructure lowers compute barriers for European firms and research organisations.
  • Industrial and institutional datasets support specialised European AI models.
  • National programmes reinforce domestic ecosystems in France, Germany and Italy.
  • Procurement, capital and deployment allow European firms to retain part of the economic value generated from European data.

Country Strategic Lenses

ITALY

Industrial and sectoral data

Italy’s comparative asset lies in specialised datasets embedded in manufacturing, SMEs, healthcare, public administration, cultural assets and highly specific industrial knowledge; the strategic challenge is converting those assets into European-controlled models rather than remaining primarily a downstream user of foreign systems.

FRANCE

Models, capital and compute

France has developed one of Europe’s most explicit sovereign-AI strategies by combining domestic model development, public research, infrastructure, investment mobilisation and political support for European technological autonomy.

GERMANY

Industrial AI scale

Germany’s strongest opportunity lies in manufacturing and Mittelstand data, reinforced by a federal strategy that links AI adoption, industrial competitiveness and major expansion of computing and data-centre capacity.

UNITED KINGDOM

External regulatory comparator

Outside the EU legal framework, the UK demonstrates that regulatory flexibility alone does not ensure sovereign AI capability; compute, capital, frontier-model ownership, data access and commercial deployment remain decisive.

Verified Legal and Strategic Baseline

Issue Status Reference Strategic meaning
Current GDPR IN FORCE Regulation (EU) 2016/679 Article 6(1)(f) continues to require legitimate interest, necessity and rights balancing.
Digital Omnibus GDPR reform PENDING 2025/0360/COD The proposed AI-related changes have not yet become binding EU law.
Council Presidency compromise NEGOTIATING TEXT 12535/26 — 3 September 2026 Expressly recognises legitimate-interest processing for AI while shortening earlier AI-specific safeguards.
EDPB AI interpretation CURRENT GUIDANCE Opinion 28/2024 Legitimate interest remains dependent on a case-specific legal assessment rather than an automatic entitlement.
European AI infrastructure DEPLOYING 19 AI Factories + 13 Antennas Provides public compute infrastructure intended to reduce technological barriers for European AI development.
Structural industrial risk OPEN Nationality-neutral regulatory framework Broader data access does not itself reserve resulting economic value, models or IP for European firms.

Strategic Net Assessment

Europe is not choosing simply between privacy and artificial intelligence. It is designing the legal conditions under which personal data can become an increasingly important factor of AI production while simultaneously deciding whether the complementary assets required to monetise those data — computing infrastructure, models, capital, cloud distribution, industrial deployment and intellectual property — remain under European control. If those complementary capabilities do not expand fast enough, greater lawful availability of European data can strengthen firms that already dominate global AI infrastructure; if Europe successfully connects data policy with EuroHPC compute, domestic model developers, industrial datasets, procurement and investment, the same regulatory reform can become one component of a broader European AI industrial strategy.

Watch Indicator Final wording of Article 88 bis and whether explicit AI-specific safeguards are restored during negotiations.
Watch Indicator European-controlled share of model training, compute consumption, inference revenues and enterprise AI deployment.
Watch Indicator CJEU, EDPB and national supervisory interpretation of legitimate interest for AI training and model operation.

Pillar One — The Legal Transformation

The transformation is not the abolition of the GDPR; it is a redistribution of where legal protection sits

The most consequential feature of the Digital Omnibus is not that it would suddenly make personal data available to artificial-intelligence developers without legal constraint, because the GDPR’s architecture of lawfulness, purpose limitation, fairness, proportionality, transparency, security and accountability remains the legal starting point; rather, the transformation lies in the attempt to move AI development from an area in which controllers must establish, case by case and under considerable uncertainty, that legitimate interest can support training or deployment, toward a legislative framework in which the Union itself expressly recognises AI development and operation as activities for which Article 6(1)(f) may provide a lawful basis. The Commission justified the broader Digital Omnibus as an exercise in regulatory simplification intended to reduce compliance burdens while maintaining European fundamental-rights protections, but the European Data Protection Board and European Data Protection Supervisor subsequently warned that simplification must not alter the substantive level of protection or create uncertainty over the GDPR’s scope. European Commission — Simpler digital rules to help EU businesses grow, 19 November 2025 EDPB–EDPS Joint Opinion 2/2026 on the Digital Omnibus

The practical significance therefore lies in legal presumptions, compliance burdens and litigation positions rather than in the formal disappearance of rights. Today, a controller seeking to process personal data for AI training under legitimate interest must construct its justification from Article 6(1)(f), the GDPR principles in Article 5, the rights of individuals, the rules governing sensitive information and the jurisprudence and regulatory interpretation surrounding those provisions. Under the proposed AI-specific provision, the legislature would expressly acknowledge that AI development and operation can constitute a setting in which legitimate interest is available; that does not guarantee that the balancing test is satisfied, but it materially alters the regulatory environment because the dispute can shift from “is this category of processing capable of relying on legitimate interest?” toward “has this particular controller satisfied the conditions for doing so?” The EDPB and EDPS themselves acknowledged in February 2026 that legitimate interest can already apply to AI under existing law, while questioning whether an additional GDPR article was therefore necessary. EDPB–EDPS Joint Opinion 2/2026 — AI and legitimate interest analysis EDPB Opinion 28/2024 on AI models

That difference is legally important because the EDPB and EDPS stated in their Joint Opinion that the Commission’s proposed Article 88c did not actually create the possibility of relying on legitimate interest: that possibility already existed under the GDPR, subject to the normal Article 6(1)(f) conditions. Their concern was therefore partly constitutional and systemic: placing a specific AI legitimate-interest statement in the GDPR’s operative provisions risks being read as giving AI development a special normative status that ordinary commercial processing does not enjoy, even though the text formally preserves the general test. EDPB–EDPS Joint Opinion 2/2026 — paragraphs concerning proposed Article 88c

The legal architecture before and after the proposed reform

Legal questionGDPR currently in forceCommission proposal, November 2025September 2026 Presidency compromisePractical consequence
Can legitimate interest support AI training?Potentially yes, subject to Article 6(1)(f)Explicitly stated for AI development and operationExplicit AI treatment retained in revised formGreater legislative certainty for controllers
Must controller demonstrate a legitimate interest?YesYesYes, through Article 6(1)(f) frameworkAI purpose alone does not automatically establish lawfulness
Must processing be necessary?YesYesRemains inherent in Article 6(1)(f)Excessive collection can still fail
Must individual rights be balanced against controller interests?YesExpressly reiterated in Article 88cExplicit AI-specific wording substantially reduced; general Article 6 remainsProtection shifts toward general GDPR rather than AI-specific text
Children receive heightened protection?Yes, expressly recognised in Article 6(1)(f)Specifically reiterated in Article 88cSpecific AI reference removed from operative clauseUnderlying GDPR protection remains
AI-specific data-minimisation safeguardGeneral Article 5 principleSpecifically insertedRemoved from operative AI articleGeneral minimisation remains but special reinforcement disappears
Enhanced AI transparencyGeneral Articles 12–14Specifically identifiedRemoved from operative AI articleGeneral transparency duties remain
Unconditional AI-specific objection rightNoYesRemovedOrdinary Article 21 test becomes more important
Special-category dataArticle 9 prohibition plus exceptionsTargeted derogation proposed for residual AI dataRevised derogation remains part of negotiationsPotentially major change for large-scale datasets
Pseudonymised dataUsually remains personal data where person remains identifiableNew contextual treatment proposedCouncil moves further toward recipient-relative identifiabilityPotential narrowing of GDPR scope for certain recipients
StatusBinding lawLegislative proposalPresidency negotiating textNo proposed reform is yet operative

Sources: GDPR — Regulation (EU) 2016/679 European Commission proposal COM(2025) 837 final Council Presidency revised compromise ST 12535/26 — official-document record

Article 6(1)(f) remains the central legal gate

Article 6(1)(f) is frequently described as “legitimate interest”, but legally it operates as a three-element cumulative test rather than a general commercial-purpose exception. First, a controller must identify an actual legitimate interest pursued by itself or a third party; second, the processing must be necessary for that interest, meaning the controller must consider whether the objective can reasonably be achieved through a less intrusive means; third, that interest must be balanced against the interests and fundamental rights and freedoms of the data subject. The European Commission’s own GDPR guidance makes clear that a business interest does not automatically prevail and that reliance on legitimate interest fails where the effect on individuals’ rights outweighs the controller’s justification. European Commission — Legal grounds for processing personal data

The EDPB applied precisely this architecture to AI in Opinion 28/2024, distinguishing the existence of an interest from the necessity of the processing and then from the balancing test, while emphasising that the analysis depends on the specific model, dataset, source of data, reasonable expectations of individuals and safeguards implemented by the controller. That case-specific structure is critical because a controller cannot establish necessity merely by asserting that a larger dataset produces a better model; the legal question is whether processing those particular personal data is necessary for the particular legitimate interest being invoked, under the circumstances and with the safeguards available. EDPB Opinion 28/2024 on certain data-protection aspects related to AI models

The Article 6(1)(f) legal test applied to AI

StageLegal questionAI-specific factual inquiryEvidence a controller would normally needFailure condition
Legitimate interestIs the objective lawful, sufficiently specific and real?What exactly is the model being developed or deployed to achieve?Defined purpose, product documentation, governance recordsVague or unlawful purpose
NecessityIs processing these personal data necessary for that objective?Could anonymised, synthetic, aggregated or narrower data achieve the objective?Dataset justification, alternative-data assessment, minimisation measuresLess intrusive viable alternative exists
BalancingDo individual rights override the controller’s interest?What would individuals reasonably expect, and how intrusive is the processing?Legitimate-interest assessment, source analysis, impact assessmentRights and freedoms outweigh commercial interest
SafeguardsCan risks be materially reduced?Can exclusion filters, opt-outs, de-identification or output controls reduce impact?Technical and organisational measuresResidual impact remains excessive
AccountabilityCan the controller prove compliance?Is the decision documented and auditable?Article 30 records, DPIA where required, governance documentationUnsupported internal assertion

Legal basis: GDPR — Article 6 EDPB Opinion 28/2024

The Commission proposal contained an unusually explicit AI safeguard package

The Commission’s November 2025 proposal did considerably more than announce that legitimate interest can apply to AI. Proposed Article 88c expressly stated that AI-related processing could rely on legitimate interest only where the controller’s interest was not overridden by the interests or fundamental rights and freedoms of the data subject, specifically highlighting children, and it preserved situations in which other Union or national law explicitly requires consent. Its second paragraph then identified concrete safeguards including data minimisation during source selection and training or testing, protection against disclosure of residually retained personal information, enhanced transparency and an unconditional right to object to the processing. COM(2025) 837 final — proposed Article 88c

This was legally significant because most of those principles already exist in some form elsewhere in the GDPR, but the Commission proposed to concentrate and strengthen them around AI. That creates a different compliance environment from one in which controllers must reconstruct their obligations from dispersed GDPR provisions. An AI-specific unconditional objection right, in particular, would have been materially stronger than the ordinary Article 21 architecture because Article 21 permits a controller relying on Article 6(1)(f) to continue processing where it demonstrates compelling legitimate grounds overriding the data subject’s interests, rights and freedoms, except in the separate context of direct marketing where the objection is effectively absolute. GDPR — Article 21 right to object

The September compromise removes legal redundancy, but it also removes friction

Council document ST 12535/26, prepared by the General Secretariat of the Council for discussion by the Antici Group on 11 September 2026, is formally a Presidency revised compromise text, not an agreed Council position and not adopted legislation. The official parliamentary repository recording the Council document identifies it as a LIMITE Presidency text linked to interinstitutional file 2025/0360(COD), which is important because commentary describing it as “the EU’s new GDPR rules” would overstate its legal status. Official record of Council document ST 12535/26 — Austrian Parliament EU document repository

The legal direction of travel is nevertheless identifiable. Compared with the Commission proposal, the compromise considerably shortens the AI-specific safeguard architecture. The direct references to children, the express consent carve-out, AI-specific source and training-stage data minimisation, enhanced transparency and the unconditional objection right are no longer organised as explicit obligations in the operative AI article. Some underlying protections continue elsewhere in the GDPR, while some concepts remain in recitals or general safeguards, but that is not legally identical to retaining them in the operative provision itself. Council Presidency revised compromise ST 12535/26 — document record COM(2025) 837 final — Commission baseline text

Commission proposal versus September 2026 Presidency compromise

Protection or ruleCommission Article 88cSeptember compromise directionExisting GDPR backstopLegal significance
AI legitimate interestExplicitExplicit/restructuredArticle 6(1)(f)Legislative endorsement remains
Rights-balancing languageExpressly repeatedAI-specific repetition reducedArticle 6(1)(f)Test survives but loses AI-specific emphasis
ChildrenSpecifically namedRemoved from operative AI clauseArticle 6(1)(f), Recital 38Protection survives but becomes less visible in AI provision
Mandatory consent under other lawsExplicit carve-outDeleted from AI articleOther applicable Union/national law remains bindingNo legal override, but textual reminder disappears
Data minimisation during source selectionExpress AI safeguardDeleted from operative AI clauseArticle 5(1)(c), Article 25General duty remains
Training/testing minimisationExpress AI safeguardDeletedArticles 5 and 25Reduced AI specificity
Enhanced transparencyExpressDeletedArticles 12–14Baseline transparency remains
Residual-data output protectionExpressReconfigured through other safeguardsSecurity/accountability dutiesDepends more heavily on implementation
Unconditional objectionExpressDeletedArticle 21Material reduction relative to Commission proposal
Technical/organisational measuresExpressRetained in more general formArticles 24, 25, 32Remains central

Sources: European Commission COM(2025) 837 Council document ST 12535/26 record

Why removing an “unconditional” objection matters more than removing the word transparency

Not every deletion has the same substantive effect. Removing an explicit reference to transparency or data minimisation does not remove those obligations from the GDPR, because Articles 5, 12, 13, 14, 24 and 25 continue independently to regulate fairness, information duties, accountability and privacy by design. Removing the Commission’s proposed unconditional AI-specific right to object, however, changes the proposed legal position more materially because ordinary Article 21 does not establish an absolute objection right for all legitimate-interest processing. GDPR — Articles 5, 12–14, 21, 24 and 25

Under Article 21(1), an individual can object to processing based on Article 6(1)(e) or (f) on grounds relating to his or her particular situation; the controller must then stop unless it demonstrates compelling legitimate grounds that override the interests, rights and freedoms of the individual or establishes that processing is necessary for legal claims. The Commission’s proposed unconditional AI objection would therefore have shifted control substantially toward the data subject by removing that override mechanism for the relevant processing, whereas the Council compromise returns the issue largely to the general balancing framework. GDPR — Article 21

Objection rights under the competing architectures

ScenarioOrdinary GDPRCommission Article 88cSeptember compromise if retained substantially as drafted
Person objects to AI training based on legitimate interestController generally must stop unless compelling overriding grounds existAI-specific objection proposed as unconditionalOrdinary Article 21 becomes central again
Direct marketingObjection effectively absoluteExisting rule unchangedExisting rule unchanged
Individual gives consent then withdrawsWithdrawal governed by consent rulesConsent cases preserved separatelyOther consent requirements remain applicable
Data obtained indirectlyArticle 14 transparency normally relevant, subject to exceptionsEnhanced AI transparency contemplatedGeneral Article 14 architecture remains
Child dataArticle 6 balancing gives special importance to childrenExplicit AI referenceGeneral protection survives without AI-specific repetition

Source: GDPR — Article 21 and related provisions

Data minimisation does not disappear, but AI exposes its most difficult interpretation

Article 5(1)(c) requires personal data to be adequate, relevant and limited to what is necessary in relation to the purposes for which they are processed, while Article 25 requires controllers to implement data protection by design and by default. Those requirements remain binding regardless of whether the Digital Omnibus retains a special AI-specific minimisation paragraph. The legal difficulty is that contemporary model development often benefits empirically from dataset scale, while GDPR necessity is not equivalent to engineering usefulness: a claim that “more data improves performance” does not by itself establish that processing every available personal record is legally necessary. GDPR — Regulation (EU) 2016/679

That distinction creates one of the central future enforcement disputes. A developer could plausibly demonstrate that large and heterogeneous datasets improve robustness, linguistic coverage or model safety, yet regulators may still ask whether personal identifiers, metadata, historic messages, location traces or other specific categories needed to be retained, whether equivalent results could be achieved through anonymisation or filtering, and whether the source universe itself was overbroad. The EDPB’s AI opinion places safeguards, reasonable expectations, data source and the necessity test inside the legitimate-interest assessment, meaning that minimisation remains legally relevant even if it disappears from the new AI article’s explicit wording. EDPB Opinion 28/2024 on AI models

Publicly accessible data do not automatically become free AI training material

A frequent misconception is that information appearing on a publicly accessible website, social network, forum, professional profile or publication has ceased to enjoy GDPR protection. That proposition is legally incorrect: public accessibility does not, on its own, remove data from the definition of personal data or eliminate the need for an Article 6 legal basis, and where special-category information is concerned, the threshold is higher still. The EDPB has specifically recalled that Article 9(2)(e), which permits processing of special-category data manifestly made public by the data subject, requires evidence that the individual intended, explicitly and by a clear affirmative action, to make that information accessible to the general public. EDPB Opinion 28/2024 — treatment of special-category and publicly available information

This matters directly for web scraping and foundation-model training because a dataset can contain ordinary personal information, inferred characteristics and Article 9 special categories simultaneously. The EDPB reiterated in 2026 guidance concerning generative-AI web scraping that where special-category data are involved, controllers require both an Article 6 legal basis and an applicable Article 9(2) exception, and it expressly rejected the existence of a general Article 9 exemption merely because data collection is undertaken for AI. EDPB — Anonymisation and web scraping for generative AI, 2026

Special-category data are where the Digital Omnibus could alter the legal equation most sharply

Article 9 of the GDPR starts from a prohibition on processing data revealing racial or ethnic origin, political opinions, religious or philosophical beliefs, trade-union membership, genetic data, qualifying biometric data, health data and information concerning sex life or sexual orientation, unless one of the Article 9(2) derogations applies. This is a different architecture from ordinary Article 6 processing because establishing legitimate interest under Article 6(1)(f) is not sufficient by itself when Article 9 data are involved. GDPR — Article 9 special categories of personal data

The Commission’s proposal therefore addressed a genuine technical problem confronting large-scale AI development: enormous corpora can contain special-category information incidentally or residually, even where the developer has not selected the dataset for the purpose of processing health, religion, politics or similar attributes. The EDPB and EDPS accepted that a targeted derogation could be justified for incidental and residual special-category processing in AI systems, but they requested clearer limits and safeguards extending through the entire AI lifecycle. EDPB–EDPS Joint Opinion 2/2026 — special-category data and AI

The legal distinction between intentional processing and residual presence therefore becomes decisive. A developer intentionally assembling political-affiliation profiles to train a political targeting system presents a fundamentally different Article 9 problem from a general-language corpus that inadvertently contains a newspaper interview revealing a person’s political belief or a forum entry mentioning a medical diagnosis. Any final derogation will need to maintain that distinction clearly because otherwise a technical exception designed to deal with contamination in very large datasets could evolve into a substantive legal route for processing sensitive information at scale. EDPB Opinion 28/2024 — special-category data considerations

Special-category information: legal treatment by use case

Data situationArticle 6 basis required?Article 9 condition required under current GDPR?Digital Omnibus relevancePrincipal legal issue
Ordinary public social-media post containing name and opinion on a productYesNormally noLegitimate-interest AI provision potentially relevantNecessity and balancing
Public post revealing political beliefsYesYesResidual-data derogation could become relevant only under defined conditionsWhether data were manifestly made public and purpose of processing
Medical discussion scraped from a forumYesYesHighly sensitive example for residual-processing regimeArticle 9 prohibition and reasonable expectations
Facial image used simply as ordinary image contentYesDepends on biometric processing purposeProposed rules do not eliminate distinctionWhether processed for unique identification
Facial template used to identify individualsYesYesHeightened protection remainsBiometric special-category processing
Training corpus accidentally containing sensitive recordsYesCurrently Article 9 remains applicableProposed residual-data derogation directly relevantEffectiveness of filtering and containment
Dataset intentionally constructed around sensitive traitsYesYesResidual exception should not convert into general authorisationPurpose and intentionality

Sources: GDPR — Articles 6 and 9 EDPB AI Opinion 28/2024

The jurisprudence already places strict limits on mixed datasets containing sensitive information

The EDPB’s 2024 AI opinion points directly to the Court of Justice’s judgment in Meta Platforms v Bundeskartellamt, C-252/21, in which the Court addressed sets containing both sensitive and non-sensitive information and clarified that where such information is collected together and cannot be separated at the point of collection, the Article 9 regime cannot simply be ignored because sensitive elements constitute only part of the dataset. The Board therefore warned that AI developers handling datasets containing special-category information must account for Article 9 independently of ordinary Article 6 lawfulness. EDPB Opinion 28/2024 — discussion of C-252/21 Court of Justice — Case C-252/21, Meta Platforms v Bundeskartellamt

That jurisprudence explains why the Digital Omnibus special-category derogation matters commercially. Large-model developers cannot realistically guarantee that billions or trillions of training elements are entirely free from medical, political, religious or biometric information, particularly where datasets originate from the open web or historical platform repositories; a narrowly designed residual-processing exception could therefore remove a potentially serious source of legal exposure, although its scope and accompanying safeguards will determine whether it functions as a technical safety valve or a broader deregulatory mechanism. EDPB–EDPS Joint Opinion 2/2026

Pseudonymisation may be the reform with the largest implications beyond AI

The proposed treatment of pseudonymised data deserves separate attention because it affects the perimeter of the GDPR itself rather than merely the legal basis used for processing. Under the current Regulation, pseudonymisation is defined as processing personal data so that they cannot be attributed to a specific data subject without additional information, provided that the additional information is kept separately and subject to safeguards; critically, pseudonymised information generally remains personal data where the individual remains identifiable by means reasonably likely to be used. GDPR — Article 4 and Recital 26

The Digital Omnibus seeks greater legal clarity over circumstances in which information that remains identifiable to one actor may effectively be non-personal for another actor that lacks realistic means of re-identification. That appears technical, but economically it could determine whether entire datasets transferred between companies, research organisations, model developers, cloud providers and data intermediaries remain subject to the full GDPR. The EDPB and EDPS warned that changing the treatment of pseudonymised information risks producing fragmented status, in which the same dataset is personal data for one organisation and non-personal for another, thereby complicating accountability and potentially reducing protection during downstream transfers. EDPB–EDPS Joint Opinion 2/2026 — definition of personal data and pseudonymisation

The September Council compromise pushes further toward an actor-relative approach to identifiability, under which the practical ability of the specific recipient to identify a person becomes highly important. The legal attraction is obvious: a model developer receiving strongly pseudonymised records without access to the re-identification key might face less regulatory burden than the hospital, platform, bank or public authority that generated the records and retains the additional information. The regulatory danger is equally clear: governance would need to ensure that contractual structures, affiliated companies, data brokers or technically accessible auxiliary datasets cannot be used to manufacture a nominal separation that does not reflect real-world identification capability. Council Presidency revised compromise ST 12535/26 — official document record EDPB–EDPS Joint Opinion 2/2026

Personal, pseudonymised and anonymous information under the emerging architecture

Data stateRe-identification possibilityCurrent GDPR positionStrategic consequence of proposed reform
Directly identified dataIdentity explicitPersonal dataFull GDPR applies
Coded data with controller holding re-identification keyIdentification straightforwardPersonal dataNo material change expected
Strongly pseudonymised dataset transferred without keyRecipient lacks direct means but another party can identifyNormally still potentially personal under current contextual analysisReform may make recipient-specific status more important
Dataset requiring unreasonable resources to identify individualsIdentification not reasonably likelyMay be effectively anonymous depending on circumstancesGreater legal certainty could expand reuse
Irreversibly anonymised datasetIndividual no longer identifiable by reasonably likely meansOutside GDPRRemains outside GDPR
Model parameters derived from personal dataStatus depends on whether information relating to identifiable persons can be extracted or inferredCase-specificIncreasingly important for model governance

Sources: GDPR — definitions and Recital 26 EDPB Opinion 28/2024 — anonymity of AI models

An AI model is not automatically anonymous merely because training data are no longer visible as records

The EDPB’s Opinion 28/2024 makes this distinction explicit: whether an AI model can be considered anonymous must be assessed case by case, and supervisory authorities should evaluate both the probability that personal information relating to individuals whose data were used for training can be extracted from the model and the probability that the model enables personal data to be obtained through queries. A developer therefore cannot simply argue that raw training rows have been transformed into numerical parameters and conclude that the resulting model is automatically outside the GDPR. EDPB Opinion 28/2024 — anonymity and AI models

This matters because the economic objective of foundation-model developers is frequently to separate the legal treatment of the training corpus from the legal treatment of the resulting model. If the model can genuinely be shown not to contain or enable the extraction of information relating to identifiable persons, downstream deployment may face a very different GDPR analysis from the original training activity; if memorisation, extraction, membership inference or other techniques make personal information practically recoverable, the model itself can remain within the data-protection problem. EDPB Opinion 28/2024

Historical platform data create a second legal problem: purpose compatibility

Even where legitimate interest supplies a lawful basis for new AI processing, controllers cannot necessarily ignore the purpose for which information was initially collected. Article 5(1)(b) establishes the purpose-limitation principle, while Article 6(4) sets criteria relevant to assessing whether further processing for a new purpose is compatible with the purpose for which the data were originally obtained, including links between purposes, context of collection, nature of the data, consequences for individuals and safeguards. The EDPB specifically identified compatibility of purposes as a provision that may be highly relevant to AI-model development and deployment. GDPR — Articles 5 and 6 EDPB Opinion 28/2024 — provisions relevant beyond the immediate opinion questions

This is particularly important for legacy archives. A platform may hold photographs, private or semi-private posts, search histories, account metadata, purchase records or interactions collected years before generative AI existed in its present commercial form. Even where those data remain technically available and a controller can articulate a commercial interest in model development, the historic collection context and reasonable expectations of individuals become material to both purpose compatibility and the Article 6(1)(f) balancing assessment. The legal value of a twenty-year archive is therefore not equivalent to unrestricted economic ownership of that archive for every subsequent computational purpose. EDPB Opinion 28/2024 on AI models and legitimate interest

Legacy-data legality matrix

Original data contextNew AI useCore legal issueRelative legal complexity
Public professional profileGeneral model trainingReasonable expectations, necessity, transparencySignificant
Public social-media postFoundation-model trainingLegitimate interest, objection, compatibilitySignificant
Private direct messageFoundation-model trainingExpectations, confidentiality, necessity, fairnessVery high
Purchase historyRecommendation-model improvementRelationship to original service and user expectationsMedium to high
Medical account recordsGeneral AI trainingArticle 9 plus sector-specific confidentialityVery high
Archived child account dataModel development years laterHeightened balancing and age-related protectionVery high
Corporate customer support chatsProduct-specific assistantContractual context, compatibility, confidentialityContext dependent
Truly anonymous aggregate statisticsModel developmentGDPR may not applyLower GDPR exposure

Legal framework: GDPR — Regulation (EU) 2016/679 EDPB Opinion 28/2024

Children remain protected even if the Council deletes their explicit mention from the AI clause

The deletion of the Commission proposal’s express reference to children should not be interpreted as removing their elevated protection from European data-protection law. Article 6(1)(f) itself identifies situations involving children as requiring particular attention, while GDPR Recital 38 states that children merit specific protection because they may be less aware of risks, consequences, safeguards and rights associated with personal-data processing. GDPR — Article 6 and Recital 38

The material change is therefore one of regulatory signalling and evidentiary burden, rather than total legal removal. An AI-specific provision explicitly naming children makes it harder for controllers and courts to treat youth-related datasets as an ordinary balancing exercise; moving the protection back into the horizontal GDPR architecture preserves the substantive principle while eliminating the additional AI-specific instruction. For services with large historical populations of teenage or child users, that distinction may become important when legitimate-interest assessments are challenged. European Commission proposal COM(2025) 837 — Article 88c

Transparency will become more difficult, not less important

General GDPR transparency requirements remain in Articles 12, 13 and 14, including duties concerning the identity of the controller, purposes, legal basis, legitimate interests where relevant, recipients, retention and individual rights. The difficulty for large-scale AI development lies in applying these requirements to information obtained indirectly from distributed sources, potentially involving very large numbers of people with whom the model developer has no direct customer relationship. GDPR — Articles 12, 13 and 14

The Commission’s proposed “enhanced transparency” language therefore addressed a structural problem rather than simply repeating existing law: traditional privacy notices were designed principally around identifiable relationships between a controller and users, customers or employees, whereas foundation-model training can involve billions of data elements obtained through crawling, licensing, acquisition or historical repositories. Removing the explicit AI requirement does not solve that tension; it leaves controllers more dependent on general Article 14 rules and their exceptions, regulatory guidance and future case law. COM(2025) 837 final — proposed Article 88c

Automated decision-making remains a separate legal layer

The proposed AI legitimate-interest rule does not displace Article 22 or other protections governing automated decisions. An organisation might lawfully train or deploy an AI model under Article 6(1)(f) yet still face separate restrictions if that system subsequently makes decisions producing legal effects or similarly significant effects on identifiable individuals. The Commission’s public GDPR guidance emphasises that qualifying automated decision-making is authorised only under specified conditions and must include suitable safeguards, including information about the processing and, where applicable, possibilities for human intervention and contestation. European Commission — Automated decision-making and individual rights

This separation is essential because training legality and deployment legality are not the same inquiry. A dataset may have been processed lawfully for model development, while a particular downstream use in credit assessment, employment, insurance, healthcare, policing or eligibility determinations triggers additional GDPR, AI Act, sector-specific and fundamental-rights constraints. Conversely, illegality during model development may contaminate subsequent deployment even where the final application would otherwise be permissible. The EDPB’s AI opinion expressly considered the consequences of models developed using unlawfully processed personal data and rejected the idea that deployment automatically cures defects originating at the development stage. EDPB Opinion 28/2024 — development and deployment of AI models

Data protection impact assessments remain a critical enforcement mechanism

Article 35 requires a Data Protection Impact Assessment where processing is likely to result in a high risk to individuals’ rights and freedoms, particularly where new technologies are used in circumstances involving systematic and extensive evaluation, large-scale processing of special-category data or systematic monitoring. The EDPB has explicitly reminded controllers that DPIAs remain highly relevant to AI models, meaning the Digital Omnibus does not convert legitimate interest into an exemption from ex ante risk analysis. GDPR — Article 35 EDPB Opinion 28/2024 — DPIAs and AI models

For large AI developers this may become one of the principal points where abstract legislative permission is converted into operational obligation. A DPIA can require the controller to describe processing operations, assess necessity and proportionality, examine risks to individuals and document measures intended to address those risks; where residual high risk remains and cannot be mitigated, Article 36 can require prior consultation with the supervisory authority. GDPR — Articles 35 and 36

Compliance architecture that would remain after the reform

GDPR mechanismWould Digital Omnibus eliminate it?Relevance to AI
Article 5 principlesNoPurpose limitation, minimisation, accuracy, storage limitation, security, accountability
Article 6 lawful basisNoCore legality of ordinary personal-data processing
Article 9 sensitive-data rulesModified in defined AI circumstances, not abolishedCritical for health, politics, religion, biometrics and similar information
Articles 12–14 transparencyNoParticularly difficult for scraped and indirectly obtained data
Article 15 accessNoIndividuals may seek information about their data
Article 16 rectificationNoRelevant where inaccurate personal information is processed
Article 17 erasureNoComplex interaction with trained models
Article 18 restrictionNoCan constrain further processing
Article 21 objectionNoBecomes more significant if unconditional AI right disappears
Article 22 automated decisionsNoApplies separately to qualifying deployment decisions
Articles 24–25 accountability/privacy by designNoGovernance, architecture and minimisation
Article 30 processing recordsNoInternal audit trail
Articles 32–34 security/breach regimeNoApplies to personal-data security
Article 35 DPIANoHigh-risk AI data processing may require assessment
Chapter V international transfersNoRelevant where training infrastructure or processors are outside EEA

Source: Full text of Regulation (EU) 2016/679 — EUR-Lex

International transfers remain a separate strategic constraint

Nothing in an AI-specific legitimate-interest provision would abolish the GDPR’s Chapter V international-transfer regime. Where personal data subject to the GDPR are transferred to third countries or accessed through qualifying cross-border arrangements, controllers and processors must still rely on an applicable transfer mechanism such as an adequacy decision, appropriate safeguards or another lawful route under the Regulation. This means that greater permission to process personal data for AI within Europe does not automatically authorise unrestricted export of those data to foreign training infrastructure. GDPR — Chapter V transfers of personal data to third countries

This separation is strategically significant because legal access to European data and geographic control over the processing infrastructure are two different questions. A US-headquartered AI provider can potentially benefit from an EU lawful basis while still having to comply with transfer requirements where relevant, while a European developer can rely on European infrastructure and reduce some cross-border complexity; consequently, the final reform will interact with, rather than replace, the EU’s broader sovereignty concerns over cloud infrastructure, model hosting and international data flows. European Commission — GDPR framework for international data transfers

The burden of proof remains with the controller

A central feature of the GDPR is the principle of accountability: Article 5(2) requires the controller to be responsible for, and able to demonstrate, compliance with the Regulation’s principles. An AI company therefore cannot rely on the existence of Article 88 bis or an equivalent final provision as sufficient legal documentation; it would still need to show why the interest exists, why the processing is necessary, why individual interests do not override it, what safeguards were implemented, what data were used, how special-category information was handled and how individual rights can practically be exercised. GDPR — Article 5 accountability principle

The operational consequence is that the strongest firms may gain not only because they possess more data, but because they possess greater capacity to document compliance at industrial scale through privacy engineering, automated exclusion systems, governance teams, model-evaluation tooling, legal departments and regulatory engagement. Regulatory simplification can therefore reduce barriers for European challengers while simultaneously rewarding organisations capable of turning complex legal requirements into repeatable infrastructure. That distributional effect cannot be determined from the text of Article 88 bis alone, but it is a direct institutional consequence of a compliance regime that remains heavily dependent on controller documentation and risk management. European Commission — GDPR information for businesses and organisations

What a controller would still need to establish before using legacy European data for AI

Compliance questionRequired analytical demonstrationWhy it matters
What is the precise AI purpose?Defined development or deployment purposePrevents open-ended reuse
What legitimate interest is pursued?Concrete, lawful and present interestArticle 6(1)(f) first limb
Why are personal data necessary?Comparison with less intrusive alternativesNecessity limb
Why this quantity of data?Dataset proportionality and minimisationArticle 5
What did individuals reasonably expect?Original context, relationship, publicity and ageBalancing test
Does dataset contain Article 9 information?Detection and classification processSensitive-data legality
Are children represented?Age-related risk analysisHeightened protection
Were data obtained directly or indirectly?Source mappingArticles 13–14
Can people object effectively?Operational objection mechanismArticle 21
Can records be deleted or restricted?Data lineage and model-governance mechanismsArticles 17–18
Is pseudonymisation sufficient?Re-identification assessmentGDPR scope
Can model reveal memorised personal information?Extraction and inference testingModel anonymity
Is a DPIA required?Risk threshold assessmentArticle 35
Are international transfers involved?Infrastructure and processor mappingChapter V
Can compliance be demonstrated later?Audit logs, records, governance documentationArticle 5(2)

Sources: GDPR — EUR-Lex EDPB Opinion 28/2024

The regulatory significance of the reform is therefore asymmetrical

For controllers, the proposed reform offers greater legislative recognition, potentially clearer treatment of residual sensitive information and a more commercially usable framework for pseudonymised datasets; for data subjects, however, several protections that the Commission initially proposed to place explicitly next to AI processing are being moved back into the general GDPR architecture or weakened as AI-specific rights. That asymmetry explains why the Council text can simultaneously preserve the GDPR formally while still producing a meaningful deregulatory effect in practice. Commission proposal COM(2025) 837 Council Presidency document ST 12535/26 record

The EDPB and EDPS position is particularly revealing because the regulators did not argue that legitimate interest must never support AI. They explicitly accepted that it can already do so under current law. Their concern instead focuses on whether rewriting the GDPR produces genuine legal certainty without reducing protection, whether sensitive-data derogations remain sufficiently narrow and whether changes to pseudonymisation alter the practical perimeter of the Regulation. That makes the dispute less a confrontation between “AI innovation” and “privacy prohibition” than a disagreement over how much legal uncertainty and individual control Europe is willing to remove in order to lower the transaction costs of AI development. EDPB–EDPS Joint Opinion 2/2026

Legal-risk hierarchy after a reform broadly resembling the September compromise

AI data usePrincipal governing provisionsRegulatory pressureWhy
Fully anonymous statistical dataGDPR potentially outside scopeLowerNo identifiable natural person where anonymity is genuine
Strongly pseudonymised industrial datasetArticles 4/25 and proposed pseudonymisation rulesContext dependentRecipient identifiability becomes decisive
Existing customer data used to improve directly related AI serviceArticles 5, 6, 13/14, 21ModerateStronger relationship and expectations may support balance
Public web content for general model trainingArticles 5, 6, 14, 21SignificantMassive scale, indirect collection and expectations
Historic platform archives reused for unrelated foundation modelArticles 5, 6, 14, 21HighPurpose compatibility and reasonable expectations
Children’s historic contentArticles 5, 6 and heightened child protectionHighEnhanced rights-balancing
Dataset containing incidental Article 9 dataArticles 6, 9 plus proposed residual derogationHigh but potentially reduced by reformFinal derogation will be decisive
Intentional sensitive-data trainingArticles 6 and 9Very highResidual exception should not function as general authorisation
AI making consequential individual decisionsArticles 6, 22 plus AI Act/sectoral rulesVery highTraining and deployment legality accumulate
Data transferred outside EEAChapter V in addition to underlying lawful basisContext dependentSeparate transfer legality required

Framework: GDPR — Regulation (EU) 2016/679 EDPB Opinion 28/2024

What the September compromise actually changes in the balance of power

The deepest transformation is therefore institutional rather than semantic. Under the current GDPR, AI developers already possess a potential legitimate-interest route, but they must navigate a regulatory environment in which that route was created before contemporary foundation models and must be reconstructed through principles, case law and supervisory interpretation. The Commission attempted to codify that possibility while attaching an explicit package of AI-specific safeguards. The September Council compromise moves toward retaining the codified permission while reducing the dedicated safeguards surrounding it, thereby making the general GDPR perform more of the protective work. COM(2025) 837 final — European Commission ST 12535/26 — Presidency revised compromise record

That creates a subtle but important shift in litigation. Instead of a data subject being able to point directly to an AI-specific statutory prohibition or unconditional right inside the new article, disputes increasingly return to necessity, expectations, proportionality, Article 9 status, transparency, Article 21 balancing, privacy by design and accountability. The protections remain substantial, but they are procedurally more contestable and fact-intensive, and that matters enormously for organisations capable of sustaining long regulatory and judicial disputes. GDPR — operative legal framework

What remains unresolved as of 26 September 2026

The first unresolved issue is the final wording of the AI article itself. ST 12535/26 is a Presidency compromise prepared for Council negotiations and cannot be treated as the final Council mandate or Union legislation. The legislative file remains 2025/0360(COD), meaning that Council negotiations, the European Parliament position and eventual interinstitutional negotiations can still materially alter the text. European legislative procedure 2025/0360/COD — EUR-Lex Official record of Council compromise ST 12535/26

The second unresolved issue is the precise residual-sensitive-data derogation, particularly how technical impossibility and disproportionate effort will be defined, how aggressively developers must filter datasets before training, what constitutes effective suppression of sensitive information inside a trained model and how regulators will distinguish genuine incidental presence from business models that deliberately tolerate sensitive content because filtering is expensive. The EDPB and EDPS have expressly called for lifecycle-wide safeguards and greater precision. EDPB–EDPS Digital Omnibus assessment, 2026

The third unresolved issue is pseudonymisation and actor-relative identifiability, which may ultimately have greater commercial consequences than Article 88 bis itself because it determines when the GDPR applies at all. A narrow AI legitimate-interest provision changes the rules governing one processing purpose; a broader change to the definition or treatment of personal data affects research, advertising, cloud services, healthcare analytics, financial data, industrial data spaces and numerous other sectors simultaneously. EDPB–EDPS Joint Opinion 2/2026 — personal-data definition and pseudonymisation

The fourth unresolved issue is jurisprudence. Even after adoption, the decisive boundaries will ultimately be determined through supervisory decisions and potentially the Court of Justice of the European Union, particularly around necessity, expectations, historic-data reuse, Article 9 residual data, model anonymity and the interaction between AI-specific provisions and fundamental rights under Articles 7 and 8 of the Charter. No legislative simplification can remove that judicial layer from the European legal order. Court of Justice of the European Union — case-law portal

Key judgments

The proposed Digital Omnibus does not eliminate the GDPR or convert European personal data into automatically available AI training material. Article 6(1)(f), the Article 5 principles, Article 9 protection of sensitive information, Article 21 objection rights, transparency duties, privacy by design, DPIAs, accountability and international-transfer rules continue to create independent legal obligations. GDPR — Regulation (EU) 2016/679

The Commission’s November 2025 proposal represented a legal bargain: explicit recognition of legitimate interest for AI was paired with unusually explicit safeguards covering children, mandatory-consent situations, minimisation, enhanced transparency and an unconditional AI-specific objection right. COM(2025) 837 final — proposed Article 88c

The September 2026 Presidency compromise changes that bargain. It does not necessarily abolish the underlying protections, because many continue elsewhere in the GDPR, but it removes or reduces several safeguards from the AI-specific operative text and therefore shifts more of the protection back toward general GDPR principles, supervisory interpretation and litigation. Council Presidency revised compromise ST 12535/26 — official record

The removal of the unconditional AI objection is one of the most substantive differences, because ordinary Article 21 legitimate-interest objections can be overcome by compelling legitimate grounds, whereas the Commission proposal would have granted a stronger AI-specific control to individuals. GDPR — Article 21

The treatment of residual special-category information could materially reduce legal uncertainty for large-model developers, but the distinction between incidental presence and deliberate exploitation of sensitive information will determine whether the mechanism remains a narrow technical exception or becomes a broader substantive change to Article 9 protection. EDPB–EDPS Joint Opinion 2/2026

The pseudonymisation provisions may ultimately be more structurally important than the AI article itself, because changing when a recipient must regard pseudonymised information as personal data changes the GDPR’s perimeter rather than merely changing the legal basis for one class of processing. EDPB–EDPS Joint Opinion 2/2026

The legal transformation should therefore be understood as a transfer of regulatory weight rather than the disappearance of regulation: away from bespoke AI restrictions written directly into Article 88c/88 bis, and toward horizontal GDPR duties, controller accountability, supervisory enforcement and eventual judicial interpretation. That architecture provides AI developers with greater room to argue that processing is lawful, but it does not predetermine whether those arguments will succeed in any particular case. EDPB Opinion 28/2024 on AI models

What would change the assessment

A final Council mandate restoring an unconditional AI objection right, explicit child protection, strengthened minimisation obligations or a narrow special-category derogation would move the final instrument closer to the Commission’s original permission-plus-safeguards architecture; conversely, further narrowing of Article 9 restrictions, broader recipient-relative treatment of pseudonymised information or additional limitations on data-subject rights would produce a materially deeper restructuring of the GDPR than the September compromise currently establishes. The next decisive records are therefore the subsequent Council compromise texts, the formal Council negotiating mandate, the European Parliament’s final position and any eventual trilogue agreement under 2025/0360(COD). Legislative procedure 2025/0360/COD — EUR-Lex

Open official record

The principal unresolved official records are the final Council general approach or negotiating mandate, the European Parliament’s adopted negotiating text, the eventual consolidated trilogue compromise, the final wording of the special-category-data derogation and pseudonymisation provisions, and any post-adoption EDPB guidance explaining how Article 6(1)(f), Article 9, Article 21 and the new AI provision interact in operational practice. Until those instruments exist, the September document should be treated as an important indicator of negotiating direction rather than as the definitive future GDPR. Council document ST 12535/26 — official-document record EDPB legal-basis materials and AI guidance

Pillar One • Legal Transformation

GDPR, AI and the Redistribution of Legal Protection

The Digital Omnibus does not abolish the GDPR. Its legal significance lies in moving artificial-intelligence development toward an expressly recognised legitimate-interest framework while reducing several AI-specific safeguards originally proposed by the European Commission and returning more of the protective burden to the general GDPR architecture.

What is actually changing

Legal Basis

AI receives explicit legislative recognition

Legitimate interest already exists under Article 6(1)(f), but the reform would expressly identify AI development and operation as activities capable of relying upon it, subject to the remaining GDPR tests.

Safeguards

Protection shifts back to the horizontal GDPR

Several protections specifically written around AI in the Commission proposal are shortened or removed from the operative AI article in the September Presidency compromise, although many continue elsewhere in the GDPR.

Scope

Pseudonymisation may alter the regulatory perimeter

The proposed recipient-relative approach to identifiability could affect whether certain pseudonymised datasets remain personal data for particular downstream organisations, with consequences extending far beyond AI.

The Article 6(1)(f) legal gate

1

Legitimate Interest

The controller must identify a genuine, present and lawful interest rather than relying on a generic claim that AI development is commercially useful.

2

Necessity

Processing the relevant personal data must be necessary for the stated objective, including consideration of narrower, anonymised, synthetic or otherwise less intrusive alternatives.

3

Balancing

The controller’s interests must not override the interests, rights and freedoms of the individual, taking account of context, expectations, sensitivity, age and safeguards.

How the legal architecture moves

Current GDPR General Article 6(1)(f) legitimate-interest framework interpreted through principles, guidance and case law.
Commission 2025 Express AI legitimate-interest provision paired with AI-specific protections and an unconditional objection right.
Council Sep 2026 Express AI route retained while several dedicated safeguards are removed or shortened.
Practical Effect More legal weight returns to Articles 5, 6, 9, 21, 25, 35 and supervisory or judicial interpretation.

Commission proposal versus September 2026 compromise

Legal element GDPR now Commission proposal September 2026 compromise Operational consequence
AI reliance on legitimate interest AVAILABLE
Case-specific under Article 6(1)(f)
Explicitly recognised Explicit AI treatment retained Greater statutory certainty for controllers
Legitimate purpose Required Required Required through Article 6(1)(f) No automatic lawful basis simply because AI is involved
Necessity Required Required Remains inherent in Article 6(1)(f) Excessive collection remains challengeable
Rights balancing Mandatory Expressly repeated in AI article AI-specific repetition reduced General GDPR performs more of the protective work
Children Heightened protection Explicitly named Specific AI reference removed Protection remains but loses dedicated AI emphasis
AI-specific minimisation General Article 5 principle Expressly reinforced Removed from operative AI text General Article 5 and Article 25 remain
Enhanced AI transparency Articles 12–14 Explicit AI safeguard Removed from operative article Transparency survives, but without dedicated AI wording
Unconditional AI objection Not generally available PROPOSED REMOVED Ordinary Article 21 balancing becomes central again
Special-category data Article 9 prohibition plus exemptions Residual AI derogation proposed Residual derogation remains under negotiation Potentially major issue for large training corpora
Pseudonymisation Normally remains personal data if identification remains reasonably possible Contextual clarification Greater emphasis on recipient-specific identifiability Could narrow GDPR scope for specific downstream actors

Why the objection right matters

Commission model

  • AI-specific objection proposed as unconditional.
  • The data subject would possess a stronger direct procedural control.
  • The controller would not rely on the ordinary Article 21 override architecture for this AI-specific objection.

September compromise direction

  • The unconditional AI-specific objection is removed.
  • Ordinary Article 21 becomes the principal legal mechanism.
  • A controller may continue processing where compelling legitimate grounds override the individual’s interests, rights and freedoms.

Objection-right matrix

Situation Current GDPR Commission 2025 model September 2026 direction
AI training based on legitimate interest Article 21 objection subject to controller override where compelling grounds exist Unconditional AI-specific objection contemplated Ordinary Article 21 architecture again becomes decisive
Direct marketing Objection effectively absolute Unchanged Unchanged
Consent-based processing Consent may be withdrawn Consent-dependent legal regimes expressly preserved Other applicable consent requirements continue independently
Child data Special weight in balancing Explicit AI-specific reference General child-protection architecture remains

Special-category data: where the reform is most legally sensitive

Article 9

Baseline prohibition

Health, political opinions, religion, ethnic origin, biometric identification, genetics, trade-union membership and related categories receive special protection.

AI Problem

Residual contamination

Very large datasets can contain sensitive information incidentally even where a developer did not intentionally collect the corpus for that purpose.

Proposed Response

Residual-data derogation

The reform attempts to create a controlled legal route for accidental and residual sensitive information subject to technical and organisational safeguards.

Boundary

Incidental is not intentional

A technical exception for residual presence should not become a general legal basis for deliberately constructing sensitive-data training datasets.

Special-category use-case matrix

Dataset situation Article 6 basis? Article 9 condition? Digital Omnibus relevance Key issue
Ordinary public consumer post Yes Normally no Article 6(1)(f) AI route potentially relevant Necessity, expectations and balancing
Public statement revealing political opinion Yes Yes Residual derogation only if conditions genuinely apply Manifestly public threshold and processing purpose
Online medical discussion Yes Yes Highly sensitive test case Article 9 plus expectations and transparency
Training corpus accidentally containing health or political data Yes Yes under current law DIRECTLY RELEVANT Filtering, technical impossibility and residual influence
Dataset intentionally built around sensitive traits Yes Yes Residual exception should not operate as general authorisation Intentionality and legal purpose

Pseudonymisation: the possible perimeter shift

Original dataset Controller holds direct identifiers and can readily identify individuals.
Pseudonymised dataset Direct identity is replaced but additional information can restore the connection.
Downstream recipient The recipient may lack the re-identification key or realistic access to auxiliary information.
Legal question Should the dataset remain personal data for that recipient if identification is not realistically possible for that actor?

Data-state comparison

Data state Identification potential Current GDPR treatment Strategic effect of reform
Directly identified records Immediate Personal data No material narrowing expected
Coded data where controller holds the key Readily reversible Personal data Little practical change
Strongly pseudonymised dataset transferred without key Recipient-specific capability uncertain Often remains personal data under contextual analysis Recipient-relative status may become more important
Information requiring unreasonable means to identify individuals Identification not reasonably likely Potentially anonymous Greater legal certainty may expand reuse
Irreversibly anonymised dataset No realistic identification Outside GDPR Remains outside GDPR
AI model trained on personal data Depends on extraction or inference potential Case-specific Model anonymity becomes a central governance question

Legacy archives: possession is not unlimited legal reusability

Original context New AI use Primary legal issue Relative complexity
Public professional profile General model training Reasonable expectations, transparency and necessity SIGNIFICANT
Public social-media posts Foundation-model training Article 6 balancing, Article 14, objection SIGNIFICANT
Private messages Foundation-model training Expectations, confidentiality, necessity and fairness VERY HIGH
Historic purchase data AI recommendation improvement Purpose compatibility and relationship with original service Medium to high
Health-account information General model training Article 9 plus sector-specific confidentiality VERY HIGH
Child-account archives Later AI development Heightened balancing and reasonable expectations VERY HIGH
Customer-service conversations Product-specific assistant Compatibility, confidentiality and minimisation Context dependent

What remains protected even after reform

GDPR mechanism Eliminated by Digital Omnibus? AI relevance
Article 5 principles NO Purpose limitation, minimisation, fairness, accuracy, storage limitation and accountability
Article 6 lawful basis NO Core legality of ordinary personal-data processing
Article 9 sensitive-data regime MODIFIED IN DEFINED CASES Central to health, politics, religion, biometrics and similar data
Articles 12–14 transparency NO Especially important for indirect or scraped data
Article 17 erasure NO Complex interaction with training datasets and models
Article 21 objection NO More important if unconditional AI-specific objection disappears
Article 22 automated decisions NO Applies separately to qualifying downstream decisions
Articles 24–25 accountability and privacy by design NO Technical governance and architecture remain mandatory
Article 35 DPIA NO Potentially required for high-risk AI processing
Chapter V international transfers NO Cross-border infrastructure remains separately regulated

Controller compliance chain

Purpose

Define the AI objective

The controller must establish a precise development or deployment purpose rather than invoke AI innovation generically.

Dataset

Justify necessity

The quantity, type and provenance of personal data must be proportionate to the stated legitimate interest.

Rights

Test individual impact

Expectations, age, sensitivity, objection, transparency and possible harm enter the balancing assessment.

Evidence

Demonstrate compliance

Accountability requires documentation, governance records, technical safeguards and where relevant a DPIA.

Institutional balance after reform

Controller advantage Explicit AI recognition can reduce legal uncertainty and make legitimate-interest arguments easier to structure and defend.
Data-subject protection Rights remain substantial, but several protections would rely more heavily on general GDPR provisions instead of dedicated AI wording.
Regulator role Supervisory authorities retain responsibility for testing necessity, balancing, transparency, Article 9 compliance and accountability.
Court role CJEU interpretation may become decisive on historic data, model anonymity, special-category residuals and the interaction between new AI provisions and fundamental rights.

Watch indicators

Final Article 88 bis wording Whether the final Council and Parliament compromise restores explicit AI-specific safeguards.
Article 9 derogation How “unintentional”, “residual”, “technically impossible” and “disproportionate effort” are ultimately defined.
Pseudonymisation test Whether recipient-relative identifiability substantially narrows the GDPR’s practical scope.
EDPB and CJEU interpretation Future decisions on necessity, reasonable expectations, training-data reuse and model anonymity.

Net Legal Assessment

The legal transformation should be understood as a redistribution of regulatory weight rather than an abolition of European data protection. The Commission’s 2025 proposal coupled explicit recognition of AI-related legitimate interest with a package of dedicated protections, whereas the September 2026 Presidency compromise retains the legal opening while returning more of the protective architecture to the general GDPR framework.

The most consequential differences concern the disappearance of the unconditional AI-specific objection right, the narrowing of explicit AI-specific minimisation and transparency language, the proposed handling of residual Article 9 information and the treatment of pseudonymised datasets. These changes do not automatically legalise unrestricted training on historical European data, because purpose limitation, necessity, rights balancing, sensitive-data rules, accountability, DPIAs, transparency and international-transfer requirements continue to apply independently.

The final legal effect will therefore depend less on the headline proposition that “legitimate interest may be used for AI” than on the exact wording of the final legislation, the scope of Article 9 derogations, the definition of identifiability, and the way supervisory authorities and the Court of Justice apply the surviving horizontal GDPR protections to large-scale model development.

Status date: 26 September 2026. The September 2026 Presidency compromise remains a negotiating text and must not be represented as the final or currently binding GDPR framework.

Pillar Three — Europe’s Sovereign-AI Capacity

Sovereign AI is a production system, not a model nationality

Europe’s central artificial-intelligence challenge is no longer whether it possesses researchers, datasets, industrial knowledge or regulatory authority, because it possesses all four; the strategic challenge is whether those assets can be assembled into an integrated production system capable of turning European data, electricity, capital, computing infrastructure, scientific knowledge and industrial demand into models, intellectual property, cloud revenues, productivity gains and strategic capabilities controlled substantially from within Europe. The European Commission’s AI Continent Action Plan, adopted in April 2025, effectively acknowledges this problem by structuring European AI policy around computing infrastructure, high-quality data, adoption in strategic sectors, skills and regulatory implementation rather than treating model development as an isolated software industry. The programme’s headline architecture includes an ambition to mobilise €200 billion for AI investment, including €20 billion directed toward AI Gigafactories, while the EuroHPC system is simultaneously building a distributed network of AI Factories around existing European supercomputing assets. European Commission — AI Continent Action Plan

The institutional problem is that these components do not automatically produce technological sovereignty simply because they are physically located in Europe. A data centre in Europe can operate imported accelerators, run proprietary foreign software, serve foreign foundation models and return much of the resulting margin and intellectual property to companies headquartered elsewhere; conversely, a European model can itself depend on non-European chips, cloud layers and development frameworks. Sovereign AI must therefore be analysed by layer: access to energy and land, data-centre ownership, accelerators and processors, supercomputing, cloud orchestration, foundation models, sectoral applications, data rights, financing, procurement, talent and the location of resulting intellectual property. The Commission’s proposed Cloud and AI Development Act reflects precisely this broader approach by combining capacity expansion with an EU-wide sovereignty framework and seeking to at least triple European data-centre capacity within five to seven years. European Commission — Cloud and AI Development Act

The consequence is that Europe’s future position cannot be measured solely by the number of European AI start-ups or by whether a particular European large language model rivals a US frontier model on one benchmark. The relevant question is whether Europe is building enough compute, financing depth, energy availability, industrial demand and institutional purchasing power to ensure that valuable European datasets feed AI systems whose economic returns circulate significantly through European companies, workers, research organisations and fiscal systems. That is the difference between hosting AI activity in Europe and capturing AI value in Europe.

Europe has moved from an AI-regulation phase into an AI-capacity phase

The institutional shift since 2024 is significant. EuroHPC now reports 19 AI Factories plus 13 AI Factory Antennas, alongside 14 supercomputers, 10 quantum computers, 62 research-and-innovation projects and 38 participating states, within a EuroHPC budget reported at approximately €8.2 billion. The factories are designed not merely as machines but as access ecosystems combining compute, technical expertise and support for companies, researchers and public authorities. EuroHPC Joint Undertaking — Key Facts and Figures

This architecture represents an attempt to solve one of Europe’s longstanding weaknesses: the difference between having excellent scientific computing facilities and allowing young companies or industrial SMEs to convert those facilities into commercially usable AI capability. EuroHPC explicitly states that its AI Factory network is intended to provide customised support to SMEs and start-ups, while access calls allow researchers, public-sector users and companies to use European supercomputing resources for scientific and industrial applications. EuroHPC — AI Gigafactories Call, July 2026

The next layer is dramatically larger. The Commission’s AI Gigafactory concept is designed around facilities able to aggregate more than 100,000 advanced AI processors, together with the associated power supply, networking, cooling, storage and software infrastructure necessary to develop next-generation models. European Commission — AI Factories and AI Gigafactories The Commission describes the underlying problem directly as a European deficit in large-scale computing infrastructure capable of supporting pre-training, fine-tuning, inference and frontier-model deployment. European Commission — AI Gigafactories

That distinction between AI Factories and AI Gigafactories is important. The former are distributed innovation infrastructures built around EuroHPC systems and intended to make high-end resources accessible across the ecosystem; the latter are intended to achieve the far greater scale required for frontier and very-large-model workloads. Europe is therefore attempting to build both the diffusion layer and the frontier-compute layer simultaneously.

Europe’s emerging sovereign-AI infrastructure

LayerCurrent European mechanismVerified scale / targetStrategic function
Distributed AI computeEuroHPC AI Factories19 factoriesStart-ups, SMEs, researchers, industry and public-sector AI development
Regional access extensionAI Factory Antennas13 antennasExtend factory services geographically
EuroHPC supercomputingEuroHPC systems14 supercomputers reported by EuroHPC in Sep. 2026HPC, scientific computing, AI workloads
Frontier AI infrastructureAI GigafactoriesSeveral planned facilitiesLarge-scale model training and inference
Gigafactory processorsCommission architecture>100,000 advanced AI processors per facility conceptFrontier-scale compute concentration
Gigafactory financingInvestAI facility€20 billion targeted mobilisationDe-risk large private/public infrastructure investment
Broader AI investmentInvestAI / AI Continent€200 billion stated mobilisation ambitionCompute, innovation and AI ecosystem development
Data-centre capacityCloud and AI Development ActAt least triple EU capacity within 5–7 yearsCloud and AI infrastructure availability
Enterprise AI adoptionEU enterprises ≥10 employees20.0% in 2025Indicates diffusion into productive economy
Large-enterprise AI adoptionEU large enterprises55.03% in 2025Shows much stronger uptake among large firms

Sources: European Commission — AI Continent, EuroHPC Joint Undertaking, European Commission — Cloud and AI Development Act, Eurostat — Use of AI in enterprises.

Europe has solved neither the compute gap nor the capital gap merely by announcing public infrastructure

The urgency behind the current investment push is visible in the European Court of Auditors’ earlier assessment of EU AI policy. Its 2024 special report concluded that although European AI investment increased, the investment gap between the United States and the EU more than doubled between 2018 and 2020; the Court cited estimates placing US AI investment at approximately €21.2 billion in 2020 against €10.7 billion in the EU-27, while also criticising weaknesses in target-setting and performance monitoring. Those data are historical and cannot be treated as a measure of the 2026 gap, but they document the structural starting point from which today’s policy acceleration emerged. European Court of Auditors — Special Report 08/2024

The Commission’s response is increasingly based on public de-risking rather than full public ownership. Under the Gigafactory architecture, European and national public resources are intended to reduce the financial risk of facilities whose cost, hardware requirements and energy needs make purely public deployment difficult, while private capital supplies much of the scale. The Commission reported that an informal expression-of-interest process attracted 77 proposals across 16 Member States and approximately 60 sites, after which EuroHPC launched the formal Gigafactory call in July 2026. European Commission — AI Gigafactories

This is a potentially powerful mechanism, but it creates a governance problem: public money can create European physical capacity without necessarily creating European corporate control. If public guarantees chiefly subsidise facilities whose hardware, software and largest tenants remain non-European, Europe gains capacity and employment but captures less of the high-margin intellectual property associated with model development and cloud services. The institutional design of Gigafactory consortia, access rights, procurement, model ownership, data governance and conditions attached to public support will therefore matter as much as the announced euro amount.

The real European advantage is industrial AI rather than imitation of the American consumer-platform model

Europe’s most important economic advantage lies in the structure of its productive economy. The Union contains globally significant automotive, aerospace, chemicals, machinery, pharmaceuticals, energy, advanced manufacturing, logistics, financial and public-service sectors that possess extremely valuable operational datasets and domain expertise. The AI Continent strategy consequently places major emphasis on industrial AI rather than defining competitiveness solely around consumer chatbots or advertising platforms. European Commission — AI Continent Action Plan

This orientation becomes more important when adoption data are examined. Eurostat reports that 20.0% of EU enterprises with ten or more employees used AI technologies in 2025, up from 13.5% in 2024 and 8.1% in 2023. Adoption was extremely uneven by company size: approximately 17% of small enterprises, 30.36% of medium-sized enterprises and 55.03% of large enterprises used AI in 2025. Eurostat — Use of artificial intelligence in enterprises

This distribution identifies the sovereignty problem more clearly than aggregate investment announcements do. Europe does not merely need European models; it needs mechanisms allowing thousands of mid-sized industrial firms to connect proprietary process data to advanced AI without handing strategic knowledge, inference economics and future workflow dependence entirely to foreign providers. AI Factories, sector-specific models, sovereign cloud infrastructure and trusted industrial data spaces therefore have greater long-term significance than a symbolic race to produce the largest possible general-purpose model.

AI adoption exposes the European scale problem

Enterprise categoryAI use in EU, 2025Strategic interpretation
All enterprises ≥10 employees19.95% / approximately 20%AI diffusion accelerating rapidly
Small enterprises17.0%Majority still outside meaningful AI adoption
Medium enterprises30.36%Significant uptake but large headroom remains
Large enterprises55.03%AI increasingly embedded in major corporate operations
EU, 20238.1%Baseline before generative-AI acceleration
EU, 202413.5%Rapid acceleration underway
EU, 202520.0%More than twice 2023 share

Source: Eurostat — Artificial intelligence in enterprises.

The policy implication is that European sovereignty will not be established by producing one European frontier champion while the remaining industrial base consumes imported AI through foreign clouds. Value capture requires diffusion, because manufacturing productivity, industrial automation, drug discovery, logistics optimisation, engineering design and public-sector transformation can generate economic value on a scale that does not appear in model benchmark comparisons.

Italy: sovereign compute exists; the challenge is turning infrastructure into firms and products

Italy occupies a stronger infrastructure position than its global AI-company profile might initially suggest. The IT4LIA AI Factory, coordinated by CINECA in Bologna, is being constructed around Leonardo, the LISA AI upgrade, the GAIA cloud and a dedicated AI-optimised supercomputer, creating a combined infrastructure that EuroHPC expects to provide more than 20,000 GPUs when completed. EuroHPC — Italy AI Factory

The planned IT4LIA dedicated AI system illustrates the scale of the national commitment. EuroHPC’s procurement documentation places the estimated contract value at approximately €290 million and specifies a system intended to support large-scale training, fine-tuning, inference, reasoning, retrieval-augmented generation, optimisation and multi-agent simulation. EuroHPC — IT4LIA AI-optimised supercomputer procurement

The existing Leonardo platform is itself being strengthened through the LISA upgrade, which EuroHPC says includes an AI-optimised partition based on 166 advanced eight-way GPU servers and is specifically designed to support large language models and multimodal generative AI workloads. EuroHPC — LISA upgrade of Leonardo

This gives Italy an important component of sovereign AI: publicly anchored high-performance compute physically integrated into a research and industrial ecosystem rather than simply purchased as external cloud credits. The Italian AI Factory consortium also brings together CINECA, ministries and agencies, the Emilia-Romagna Region, INFN, AI4I, FBK, universities, Confindustria and the national HPC, Big Data and Quantum Computing research infrastructure, which provides the institutional density needed to connect scientific capacity with industrial use. EuroHPC — IT4LIA consortium

Italy’s weakness lies farther downstream. The Italian Strategy for Artificial Intelligence 2024–2026 organises national intervention across research, public administration, enterprises and education, explicitly recognising that AI development must be connected to the country’s productive system and public sector. Italian Government Digital Transformation Department — Italian Strategy for Artificial Intelligence 2024–2026 Yet the strategic question for Italy is no longer principally whether national compute exists: it is whether start-ups, industrial champions and SMEs can turn that compute into commercially scalable models, industrial software and exportable AI systems.

Italy’s comparative advantage lies particularly in sectors where proprietary knowledge matters more than internet-scale consumer data: machinery, robotics, automotive components, aerospace, pharmaceuticals, biomedical technologies, energy engineering, design, precision agriculture and complex manufacturing supply chains. The institutional objective should therefore be understood as an effort to build an Italian industrial-AI layer on top of European compute, rather than merely attempting to reproduce the platform economics of Silicon Valley.

Italy’s sovereign-AI asset stack

AssetVerified positionStrategic valuePrimary constraint
LeonardoMajor EuroHPC pre-exascale system hosted by CINECAExisting HPC foundationMust translate capacity into commercial AI use
LISA upgrade166 eight-way GPU serversDedicated generative-AI capabilityHigh utilisation and accessible allocation required
IT4LIA dedicated AI systemProcurement estimated at €290mTraining, inference, reasoning, RAG, simulationConversion into applications and firms
IT4LIA combined environment>20,000 GPUs expectedSignificant AI-compute concentrationTalent and product scale
National AI StrategyResearch, PA, enterprise, skillsInstitutional coordinationImplementation and measurable adoption
Industrial ecosystemMachinery, manufacturing, engineering, health and other specialised sectorsHigh-value proprietary dataSME fragmentation
Public-sector demandLarge administrative and public-service basePotential anchor customerProcurement speed and interoperability

Sources: EuroHPC — Italy AI Factory, EuroHPC — IT4LIA procurement, Italian AI Strategy 2024–2026.

For Italy, procurement and capital allocation may therefore matter more than another strategy document. Infrastructure that remains principally scientific produces scientific excellence; infrastructure connected to predictable public procurement, corporate co-investment, scale-up financing and industrial data can create companies. The distinction is essential because Italy already possesses deep engineering competence and one of Europe’s strongest public HPC centres, yet that competence must migrate into repeatable AI products if value capture is to remain domestic.

France: attempting to build the complete AI value chain

France is pursuing the most explicit full-stack strategy among the large continental economies, combining frontier-model companies, public research, nuclear-heavy electricity generation, data-centre development, international capital and national industrial policy. The French government’s third phase of its national AI strategy, announced in 2025, builds on a programme to which approximately €2.5 billion from France 2030 has been dedicated. French Ministry of Economy — National AI Strategy

The decisive change came with the February 2025 AI Action Summit, where the Presidency announced approximately €109 billion of French and foreign private investment commitments relating to AI infrastructure and deployment in France. Élysée — Making France an AI Power This number is an announcement of investment commitments rather than a measure of expenditure already deployed, and it should therefore not be confused with realised capital formation; nevertheless, its scale reflects France’s deliberate effort to turn power availability, sites, connectivity and policy support into a European compute cluster.

France’s strategy is unusual because it explicitly connects compute to the wider value chain. At the June 2026 Choose France summit, President Emmanuel Macron described the objective not merely as installing data centres but as extending deeper into chips, services, robotics, models and AI companies, framing compute as the foundation upon which French and European champions can build value. Élysée — Choose France, 1 June 2026

The French sovereignty concept also includes trusted cloud. The government identifies SecNumCloud, operated under ANSSI’s security framework, as part of an approach intended to protect sensitive information and reduce exposure to extraterritorial legal risk for strategic users. Élysée — Council of Ministers, Digital Sovereignty, 12 June 2025 This matters because sovereign compute without a trusted cloud and deployment environment cannot easily penetrate defence, healthcare, public administration, critical infrastructure and other high-value regulated sectors.

France’s structural advantage is therefore vertical integration of policy objectives: talent creation, compute, energy, model development, cloud security and capital are treated as related components. Its principal risk is that a large proportion of announced data-centre investment can still produce infrastructure whose economic rents accrue heavily to multinational cloud and hardware providers. The French system captures maximum strategic value only if locally controlled models, software and services scale alongside the physical infrastructure.

France’s emerging AI production model

ComponentVerified policy / figureStrategic role
National AI strategy fundingApproximately €2.5bn France 2030Research, ecosystem building, adoption
2025 investment announcementsApproximately €109bnData centres, infrastructure and AI deployment commitments
Talent objective cited by PresidencyFrom approximately 40,000 toward 100,000 trained annuallyHuman-capital scaling
Energy positionGovernment emphasises abundant, stable, low-carbon electricityData-centre attraction
Trusted cloudSecNumCloud frameworkSensitive-sector sovereignty
Domestic model ecosystemMultiple French model and AI companiesCapturing software/IP value
Strategic objectiveChips + compute + models + services + roboticsFull-stack value retention

Sources: French Ministry of Economy — National AI Strategy, Élysée — AI Action Summit, Élysée — Business Day.

Germany: betting on industrial AI and an enormous expansion of computing capacity

Germany’s AI strategy is increasingly inseparable from its wider industrial competitiveness programme. The federal Hightech Agenda Deutschland identifies artificial intelligence among six key technologies considered central to future competitiveness and links AI specifically to industrial deployment and sector-specific applications. Federal Government of Germany — Hightech Agenda and AI

Germany’s most quantifiable intervention is its national data-centre strategy. As of September 2026, the federal government reports roughly 3 GW of total data-centre connection capacity and approximately 500 MW devoted to AI, with official targets to at least double overall data-centre capacity by 2030 and at least quadruple HPC and AI capacity relative to the 2025 base. Federal Government of Germany — Data Centre Strategy, September 2026 Federal Ministry for Digital Affairs — 2027 budget statement

Official government material provides another expression of the same target: total connection capacity is expected to exceed approximately 6 GW by 2030, while HPC and AI infrastructure should expand at least fourfold. German Federal Government Bulletin — National Data Centre Strategy

Germany also hosts several EuroHPC AI Factory initiatives. The HammerHAI system, for example, is specified by EuroHPC at approximately 15 exaflops of peak AI inference performance, with 860 NVIDIA B200 GPUs, 10 PB of storage and high-speed InfiniBand and Ethernet networking. EuroHPC — Germany AI Factories Germany also hosts JUPITER, one of the major EuroHPC systems, reinforcing the interaction between national and European infrastructure. EuroHPC — European supercomputing infrastructure

Germany’s strategic rationale differs subtly from France’s. Berlin increasingly frames the principal opportunity as industrial AI: combining machinery, production systems, process knowledge and proprietary corporate data with AI rather than attempting to dominate consumer-platform AI. Chancellor Friedrich Merz has explicitly connected national AI policy with deployment inside core industries and the Mittelstand, while the government’s Hightech Agenda supports domain-specific AI and transfer models for SMEs. German Federal Government — Made for Germany and AI policy

This strategy is rational because Germany’s most defensible AI assets are not primarily social-network datasets but decades of high-value engineering and production data distributed across automotive systems, machinery, chemicals, pharmaceuticals, industrial automation and logistics. The economic problem is access: much of that data is fragmented inside companies reluctant to expose process knowledge to external model providers. Sovereign or trusted infrastructure can therefore create value by allowing German firms to use proprietary data without surrendering strategic control over it.

Germany’s compute and industrial-AI position

IndicatorVerified position / targetDate / horizon
Current total data-centre capacityApproximately 3 GW2026 government statement
Current AI-oriented capacityApproximately 500 MW2026 government statement
Overall capacity targetAt least 2×2030 vs 2025
HPC/AI capacity targetAt least 4×2030 vs 2025
Indicative overall capacity implied by government>6 GW2030
HammerHAI peak AI inference15 exaflopsSystem deployment 2026
HammerHAI GPUs860 NVIDIA B200EuroHPC specification
HammerHAI storage10 PBEuroHPC specification
National strategic focusIndustrial and domain-specific AIHightech Agenda

Sources: German Federal Government — Data Centre Strategy, German Federal Government — 2027 Digital Budget, EuroHPC — Germany.

Germany’s principal bottleneck is no longer recognition of the compute problem but execution speed, particularly grid connection, permitting, energy cost and the mobilisation of private capital. The government’s data-centre strategy explicitly centres on energy and sustainability, land and location, and technology and sovereignty, while June 2026 measures relaxed several domestic energy-efficiency implementation requirements in an effort to facilitate investment. Federal Government of Germany — Energy efficiency and data centres

United Kingdom: the most useful external comparator is compute policy, not deregulation alone

The United Kingdom is outside the EU legislative framework but confronts the same strategic problem: frontier AI requires far more than an innovation-friendly regulatory environment. The UK’s response is centred on the AI Research Resource (AIRR), AI Growth Zones, a national compute roadmap and an explicit ambition to build sovereign computing capacity accessible to academia, start-ups, companies and the public sector. UK Government — AI Research Resource

The British compute target is unusually precise. The UK Compute Roadmap commits more than £1 billion to expand AIRR twentyfold by 2030, from approximately 21 AI ExaFLOPS in 2025 to 420 AI ExaFLOPS in 2030, alongside up to £750 million for a new national supercomputer in Edinburgh within a broader package of up to approximately £2 billion for public compute infrastructure. UK Government — UK Compute Roadmap

AIRR already combines Isambard-AI at Bristol and Dawn at Cambridge, and the government describes the programme as a response to an acute shortage of public specialised AI compute. UK Government — AIRR advanced supercomputers Access is deliberately structured around research and industrial use: the 2026 open-access call allowed qualifying projects to apply for between 50,000 and 1.4 million GPU hours on Isambard-AI. UK Government — AI open access call

The next planned AIRR system carries a separate £750 million investment commitment and is intended to support frontier AI research, large-scale inference and scientific discovery while strengthening what the government explicitly calls the UK’s sovereign AI capability. UK Government — AIRR heterogeneous supercomputer host-site selection

EU–UK sovereign-compute comparison

DimensionEuropean UnionUnited Kingdom
Primary institutional structureEuroHPC + national facilitiesAIRR + national supercomputing centres
Distributed AI access19 AI Factories + 13 AntennasAIRR access programmes
Frontier-scale expansionAI GigafactoriesAIRR expansion + national supercomputer
Public compute targetMultiple facilities; >100,000 processors contemplated per Gigafactory conceptAIRR 21 → 420 AI ExaFLOPS by 2030
Major financing figure€20bn Gigafactory mobilisation objective>£1bn AIRR expansion
Wider compute packageEU + Member-State + EIB/private resourcesUp to approximately £2bn public compute roadmap
SME accessAI FactoriesAIRR Rapid Access / innovation routes
Industrial-policy logicEU strategic autonomy + industrial AINational sovereign compute + growth zones
Regulatory positionEU AI Act / single-market frameworkSeparate UK regulatory regime

Sources: European Commission — AI Continent, EuroHPC, UK Government — UK Compute Roadmap, UK Government — AIRR.

The UK comparison is analytically useful because it demonstrates that regulatory independence from the EU does not remove the infrastructure problem. Britain has still concluded that government-supported compute, energy-intensive infrastructure, research access and public investment are necessary conditions for a competitive domestic AI ecosystem. The difference is therefore less “EU regulation versus British deregulation” than two different institutional arrangements attempting to solve the same scarcity of compute, capital and scale.

The semiconductor dependency remains Europe’s hardest sovereignty constraint

No European sovereign-AI strategy can avoid the processor problem. AI Factories and Gigafactories require large numbers of advanced accelerators, and the present European infrastructure build-out continues to rely extensively on non-European processor architectures and suppliers. This does not make the investments strategically irrelevant, because compute availability itself has major value, but it means physical European infrastructure does not equal full-stack hardware sovereignty.

The EU Chips Act was designed partly to address this wider dependence, with the Commission having associated the initiative with more than €43 billion of public and private investment mobilisation in European semiconductor capabilities. European Commission — European Chips Act investment framework More recent Commission language links the Gigafactory programme directly to the European semiconductor ecosystem, arguing that predictable large-scale AI-compute demand can help stimulate European processor design and eventually indigenous manufacturing. European Commission — AI Gigafactories

This is strategically important because a true European AI production system requires not complete autarky, which would be economically unrealistic, but sufficient substitution capacity and bargaining power across critical layers. Europe does not need every accelerator to be designed and fabricated inside the Union, but it does need to avoid a structure in which every expansion of European AI capability automatically increases dependency on a single external hardware ecosystem.

Energy is becoming an AI industrial-policy instrument

Compute policy increasingly converges with electricity policy. AI infrastructure converts electricity, chips, data and capital into computation, making reliable power supply a direct determinant of AI investment. France explicitly promotes its relatively abundant low-carbon electricity as a reason for locating data-centre infrastructure domestically, while Germany’s data-centre strategy treats energy availability and network connection as principal constraints on expansion. Élysée — France as an AI power German Federal Government — Data Centre Strategy

The Commission’s Cloud and AI Development Act follows the same logic at European level by identifying energy, land, water, financing and permitting as constraints on data-centre expansion. European Commission — Cloud and AI Development Act This marks a fundamental policy change: AI strategy is becoming infrastructure strategy, and infrastructure strategy is becoming energy policy.

A Member State with excellent researchers but insufficient grid capacity can lose AI infrastructure to a neighbour; a country with abundant power but no domestic model ecosystem may host foreign computation without capturing high-value intellectual property. The highest-value configuration therefore combines electricity, connectivity, compute, human capital and firms capable of owning the resulting AI layer.

Cloud sovereignty will determine whether European compute becomes European strategic autonomy

Europe’s dependency problem does not end once servers have been installed. Enterprise AI increasingly operates through integrated cloud stacks that provide storage, data engineering, cybersecurity, model APIs, orchestration, inference and business applications. A European company can therefore use a physically European data centre while remaining deeply dependent on non-European software and cloud architecture.

The proposed Cloud and AI Development Act is significant because it explicitly adds an autonomy pillar, including a planned EU-wide framework for assessing cloud and AI sovereignty, while also seeking a European cloud offer capable of serving strategic public and industrial sectors. European Commission — Cloud and AI Development Act The Commission also links the Act to a common approach for public-sector cloud procurement and secure European cloud capacity for highly critical uses. European Commission — Cloud Computing and CADA

The practical sovereignty test is consequently not whether a cloud provider is legally European or foreign in isolation, but whether Europe retains operational substitutability: can strategic workloads migrate between providers, can encryption keys and data access remain under European control, can essential services continue during geopolitical disruption, and are European providers economically capable of competing for public and private workloads?

Public procurement may become the most powerful instrument Europe possesses

The United States developed much of its technological ecosystem partly through large public markets in defence, space, intelligence and research; Europe has historically been more fragmented. AI provides a strong case for using public procurement as a demand-side industrial instrument without abandoning competitive tendering or technological neutrality.

European public administrations, healthcare systems, universities, defence organisations, utilities and transport networks collectively represent an enormous potential AI market. If each institution purchases isolated proprietary systems, the result can reinforce external platform concentration; if procurement creates interoperable demand for European compute, secure clouds, specialised models and local integration services, public spending can become an anchor market for European suppliers.

The Commission’s emerging cloud policy explicitly connects sovereignty with public procurement, while AI Factories already include public-sector users among their target communities. European Commission — Cloud Computing policy EuroHPC — AI Gigafactories and access The institutional question will be whether that demand is aggregated sufficiently to create scale, rather than fragmented into hundreds of national, regional and municipal procurement exercises.

The value-capture chain determines whether European data produces European wealth

The relationship between data sovereignty and economic sovereignty can be expressed as a sequence. Data alone generate little strategic value. Value emerges when data are organised, processed through compute, converted into models, embedded in applications and deployed into productive processes. Each layer creates an opportunity for rents to leave or remain within Europe.

European AI value-capture chain

Value-chain stageStrategic European assetLeakage mechanismInstitutional response required
Data creationIndustrial, public, scientific and consumer datasetsData used principally by external platformsData spaces, trusted access, interoperable governance
Data preparationSectoral expertise and research institutionsProcessing stack controlled externallyAI Factory data labs and European software capacity
ComputeEuroHPC, national HPC, data centresDependence on external accelerator supplyGigafactories, diversified hardware and European processor R&D
CloudGrowing European cloud marketHyperscaler concentrationSovereignty framework, interoperability and procurement
Foundation modelsEuropean research and start-upsCapital and distribution disadvantagesCompute allocation, scale-up finance and procurement
Sectoral modelsStrong industrial baseProprietary data transferred to general external modelsDomain-specific AI and confidential-computing architectures
ApplicationsLarge European enterprise and public marketForeign software captures marginsEuropean integration and application firms
DeploymentManufacturing, healthcare, transport, energyVendor lock-inOpen standards and portability
Intellectual propertyEuropean research excellenceAcquisition or relocation of scaling firmsGrowth capital and European exit alternatives
RevenueLarge single marketProfit and tax base accrue elsewhereDomestic firms, procurement and competitive cloud/model markets

The central implication is that GDPR reform or greater data availability cannot independently generate sovereign AI. If European data become easier to process while the compute, models and cloud layer remain structurally external, the change principally enlarges the input base available to existing global firms. If European compute, capital, industrial deployment and procurement mature simultaneously, greater data availability can become an input to European value creation.

Five institutional choices will determine the outcome

Compute must be allocated as industrial infrastructure rather than prestigious scientific capacity

The first choice concerns access. Europe is investing heavily in machines, but sovereignty depends on which companies can use them, at what cost, for what duration and with what allocation certainty. A start-up cannot build a commercial model business around occasional research-style compute grants whose future allocation is uncertain. EuroHPC’s transition toward AI Factories is therefore strategically important precisely because it attempts to provide services rather than merely machine time. EuroHPC — AI Factory network

Europe will need access frameworks capable of supporting scientific research, SMEs and serious scale-up companies differently. The latter may require multi-year capacity commitments, confidential workloads and predictable pricing rather than short-term grant allocations.

Public capital must crowd in European scale rather than merely reduce foreign infrastructure costs

The second choice concerns financial additionality. The €20 billion Gigafactory mobilisation objective can produce dramatically different outcomes depending on its conditions. European Commission — AI Gigafactories Public capital generates strategic leverage only where it produces investment that would otherwise not occur or attaches conditions that improve European capability, competition and resilience; simply subsidising already-planned multinational data centres provides much weaker sovereignty effects.

Procurement must create a market for European AI, not merely compliance demand

The third choice is whether public institutions act as first customers for European AI. Start-ups scale when they have revenue, reference clients and predictable demand. The EU and national governments possess substantial procurement power but historically fragmented technology purchasing weakens its industrial effect. The emerging European cloud policy recognises this issue by linking cloud sovereignty with public-sector procurement. European Commission — Cloud Computing

Industrial data must remain usable without forcing firms to surrender strategic knowledge

The fourth choice concerns architecture for confidential industrial AI. Germany and Italy in particular hold much of their comparative advantage inside private manufacturing firms rather than consumer platforms. If using advanced AI requires those firms to export proprietary process data into opaque external systems, adoption will either remain limited or sovereignty will deteriorate. Secure European cloud, confidential computing, federated systems, on-premise models and trusted AI Factory services can therefore become industrial-policy tools rather than merely privacy technologies.

Europe must retain scaling companies, not just create start-ups

The fifth choice concerns late-stage capital and ownership. Creating research spin-offs is insufficient if successful firms subsequently relocate, sell to larger external platforms or depend on foreign capital for the growth stage. Sovereign AI therefore intersects with the European capital-markets problem. Germany’s government itself increasingly links technology policy with deeper European capital markets and growth financing. German Federal Government — Industry Day 2026

Institutional decision matrix

Policy choiceWeak configurationStrong sovereignty configurationObservable indicator
Compute allocationShort research grantsPredictable commercial-scale accessEuropean start-ups training and serving models on EuroHPC
Gigafactory financeInfrastructure subsidy onlyConditional public-private capability buildingEuropean ownership/IP share
Cloud policyPhysical localisation onlyPortability, control, substitutability and secure European servicesStrategic workloads on trusted EU capacity
Data policyMore available dataData linked to European compute and model ecosystemsEuropean firms monetising European datasets
Industrial AIGeneric external APIsSector-specific confidential AIManufacturing adoption without data surrender
ProcurementFragmented tendersAggregated demand and interoperabilityEuropean AI vendors winning public contracts
Scale-up capitalEarly-stage funding onlyLate-stage European growth capitalLower forced sale/relocation of successful firms
Semiconductor policyImported accelerator monocultureDiversified supply plus European processor capabilityEuropean-design share in AI infrastructure
Energy policyGrid bottlenecksPredictable power and accelerated connectionsGigafactory deployment without energy delays
SkillsResearch excellence onlyEngineers + operators + entrepreneurs + sector expertsDomestic employment and company formation

Italy, France and Germany are developing complementary rather than identical sovereign-AI models

The three large continental economies are not converging on one national strategy. Italy is building an infrastructure-and-industrial specialisation model, anchored by CINECA, Leonardo and IT4LIA; France is pursuing a capital-intensive full-stack model, combining compute, energy, models and international investment; Germany is constructing an industrial-AI model, using massive data-centre expansion and manufacturing datasets as its principal strategic advantage. These approaches are complementary if integrated through the European market and EuroHPC, but potentially duplicative if each state attempts to construct closed national ecosystems.

Comparative sovereign-AI architecture

DimensionItalyFranceGermanyUnited Kingdom
Core comparative assetPublic HPC + industrial specialisationCompute + energy + models + capitalIndustrial data + manufacturingResearch + finance + sovereign compute
Major compute programmeIT4LIA / Leonardo / LISANational data-centre investment + EuroHPC participationJUPITER, HammerHAI, national data-centre expansionAIRR / Isambard-AI / Dawn
Quantified compute goal>20,000 GPUs anticipated in IT4LIA environmentLarge private infrastructure commitments; no directly comparable national GPU target in cited recordTotal DC ≥2×; HPC/AI ≥4× by 2030AIRR 21 → 420 AI ExaFLOPS
Major investment figureIT4LIA procurement ~€290m€109bn announced AI investment commitmentsLarge private/public infrastructure expansion; national targets expressed mainly in capacity>£1bn AIRR; up to ~£2bn compute package
Strategic orientationSpecialised and industrial AIFull-stack AI powerIndustrial AIFrontier research and sovereign compute
Principal bottleneckScale-up capital / productisationConverting infrastructure into domestic IPEnergy, grid, deployment speedScale relative to US frontier ecosystem
Strongest sovereignty leverEuropean HPC integrationCompute-energy-model integrationProprietary industrial dataFlexible national allocation of compute
RiskStrong infrastructure but weak commercial scalingInfrastructure dominated by external capital/providersSlow permitting and fragmented Mittelstand adoptionCompute expands but firms still scale through foreign platforms

Sources: EuroHPC — Italy, French Ministry of Economy — National AI Strategy, German Government — Data Centre Strategy, UK Government — Compute Roadmap.

The decisive European choice is integration versus fragmentation

No individual European state has an obvious economic case for reproducing the entire US AI stack independently. The Union’s advantage lies instead in shared infrastructure plus national specialisation. EuroHPC allows an Italian company to access European computing capacity beyond Italy, while French electricity and investment, German industrial demand, Nordic low-cost energy, Dutch connectivity, Spanish renewable capacity and scientific clusters across multiple Member States can form parts of a continental system.

That model fails if national industrial policy becomes primarily competitive subsidy policy, with Member States bidding against one another to attract the same foreign data centres while European start-ups remain too small to use the resulting infrastructure. The Commission’s Gigafactory programme implicitly attempts to avoid this outcome by making the facilities European infrastructure projects rather than purely national ones. European Commission — AI Gigafactories

The same logic applies to data centres. A tripling of EU capacity is economically relevant only if the system remains interconnected, power-efficient and accessible across borders. European Commission — Cloud and AI Development Act National sovereignty pursued through isolated infrastructure could paradoxically produce less European sovereignty by reducing scale and increasing duplication.

Key evidence table

IndicatorVerified figure / statusReference periodStrategic meaningSource
EU AI investment mobilisation objective€200bnAI Continent initiativeScale of proposed public/private mobilisationEuropean Commission
AI Gigafactory mobilisation€20bnInvestAIFrontier compute financingEuropean Commission
AI Factories19Sep. 2026Distributed AI accessEuroHPC
AI Factory Antennas13Sep. 2026Geographic reachEuroHPC
EuroHPC supercomputers14Sep. 2026European HPC baseEuroHPC
EuroHPC budget reported€8.2bnSep. 2026HPC ecosystem scaleEuroHPC
Gigafactory processor concept>100,000 advanced AI processorsCommission architectureFrontier-scale computeEuropean Commission
Gigafactory expressions of interest77 proposals / 16 Member States / ~60 sites2025–26 processStrong infrastructure demandEuropean Commission
EU data-centre expansion objective≥3×Next 5–7 yearsCloud and AI capacityEuropean Commission
EU enterprise AI adoption20.0%2025AI diffusionEurostat
EU large-enterprise adoption55.03%2025AI concentrated in larger firmsEurostat
Italy IT4LIA environment>20,000 GPUs expectedBuild-outNational/European AI computeEuroHPC
IT4LIA procurement~€290m2025 tenderDedicated Italian AI supercomputerEuroHPC
France AI investment announcements€109bnFeb. 2025Infrastructure and deployment commitmentsÉlysée
French national AI funding~€2.5bn France 2030National strategyResearch/ecosystem fundingFrench Economy Ministry
German data-centre capacity~3 GW2026 government statementExisting national infrastructureBundesregierung
German AI compute capacity~500 MW2026 government statementAI-oriented capacityBundesregierung
German overall DC target≥2×2030 vs 2025National expansionBundesregierung
German HPC/AI target≥4×2030 vs 2025AI-scale expansionBundesregierung
UK AIRR expansion21 → 420 AI ExaFLOPS2025–2030Twentyfold sovereign compute growthUK Government
UK AIRR commitment>£1bnTo 2030Public AI computeUK Government
New UK supercomputerup to £750mAnnounced/procurement phaseFrontier research and inferenceUK Government

Indicators that would confirm Europe is actually becoming more sovereign

The strongest evidence of progress will not be additional strategy announcements but changes in ownership and economic flows. A genuinely stronger European AI position would become visible if European-controlled providers account for an increasing share of high-value enterprise inference; European start-ups receive multi-year EuroHPC compute allocations and survive into late-stage growth; industrial groups deploy domain-specific models without transferring proprietary datasets outside trusted environments; European public administrations become anchor customers for European AI infrastructure; and European processor, networking and cloud software suppliers capture an increasing portion of Gigafactory expenditure.

Conversely, the assessment would weaken if European public money produces mainly physical data centres operated by foreign hyperscalers; AI Factory access remains concentrated in research projects rather than commercial scaling; European model firms continue to relocate or sell before achieving major scale; industrial companies rely overwhelmingly on external foundation-model APIs; or hardware concentration means every increase in European computing capacity further increases dependence on one or two external processor ecosystems.

What would change the assessment

The principal judgment would improve materially if the first AI Gigafactory procurement rounds demonstrate substantial European ownership, European model workloads and durable access for European scale-ups, rather than serving predominantly as subsidised capacity for incumbent global providers. European Commission — AI Gigafactory programme

It would also improve if the proposed Cloud and AI Development Act succeeds in tripling capacity while establishing meaningful portability, secure-European-cloud requirements for critical public workloads and a measurable expansion of European cloud providers. European Commission — Cloud and AI Development Act

At national level, Italy should be assessed on whether IT4LIA produces exportable companies and industrial applications rather than simply high utilisation rates; France on whether its €109 billion investment wave creates domestic models, chips, cloud services and application companies alongside foreign-owned data centres; Germany on whether its planned doubling of overall data-centre capacity and quadrupling of AI/HPC capacity translate into measurable productivity gains in manufacturing and the Mittelstand; and the United Kingdom on whether its twentyfold AIRR expansion creates durable domestic model and AI companies rather than primarily subsidising excellent research. EuroHPC — Italy Élysée — French AI strategy Bundesregierung — Data Centre Strategy UK Government — Compute Roadmap

Key judgments

Europe now possesses a credible public-compute strategy, but it does not yet possess evidence of full-stack AI sovereignty. The combination of EuroHPC, 19 AI Factories, 13 Antennas, planned Gigafactories and a programme to at least triple data-centre capacity represents a material infrastructure build-out rather than regulatory rhetoric. EuroHPC Joint Undertaking European Commission — Cloud and AI Development Act

Compute is becoming available at a scale that can support serious European AI development, but access architecture will determine whether that capacity creates companies or primarily research output. AI Factories represent an institutional attempt to solve this problem by combining machine access with support services, while Gigafactories are intended to address the separate frontier-scale constraint. European Commission — AI Factories

Italy has one of Europe’s most important publicly anchored AI-compute concentrations, but its strategic test is commercial conversion. IT4LIA, Leonardo and LISA provide infrastructure that many European states lack; sovereignty will depend on whether that infrastructure produces scalable Italian and European AI firms and industrial applications. EuroHPC — IT4LIA AI Factory

France is attempting the most explicit continental full-stack strategy, connecting large infrastructure commitments with domestic models, talent, energy, cloud security and capital mobilisation; however, the €109 billion figure represents announced investment commitments and should not be treated as completed expenditure. Élysée — France AI strategy

Germany’s strongest route to AI sovereignty is industrial rather than consumer-platform AI. Its approximately 3 GW data-centre base, government target to double capacity and quadruple HPC/AI infrastructure, major EuroHPC assets and manufacturing data create the conditions for a powerful sector-specific AI ecosystem if grid, capital and adoption constraints can be resolved. German Federal Government — Data Centre Strategy

The United Kingdom demonstrates that leaving the EU regulatory system does not remove the requirement for sovereign infrastructure. Its commitment to expand AIRR twentyfold from 21 to 420 AI ExaFLOPS by 2030 confirms that access to large-scale public compute is viewed as strategic even under a different regulatory model. UK Government — UK Compute Roadmap

The most important European sovereignty variable is therefore not where the data originate, but where the entire value chain is controlled. European data processed on European soil can still enrich non-European model, cloud and processor ecosystems; conversely, internationally sourced hardware and capital can contribute to European sovereignty where European companies retain model ownership, proprietary applications, industrial know-how, employment and downstream revenues.

Data sovereignty becomes economic sovereignty only when Europe owns enough of the machinery that converts data into intelligence. The emerging policy architecture therefore has to connect the GDPR and Data Union debate with EuroHPC compute, Gigafactory financing, cloud portability, chips, energy, capital markets, procurement and industrial adoption. Treating any one of those components independently would miss the structure of the competitive problem.

Open official record

The most consequential forthcoming official evidence will be the selection, ownership and financing structures of the first European AI Gigafactories, because those decisions will reveal whether InvestAI becomes an instrument for building European-controlled frontier capacity or primarily a mechanism for expanding infrastructure physically situated in Europe. The formal Gigafactory procurement process was launched by EuroHPC in July 2026, with the Commission indicating construction of the first facilities from 2027. European Commission — AI Gigafactories timeline EuroHPC — Gigafactory call

A second decisive record will be implementation of the Cloud and AI Development Act, particularly the final sovereignty framework, permitting mechanism, public-procurement provisions and measurement of whether the target to at least triple EU data-centre capacity is being achieved. European Commission — Cloud and AI Development Act

The third will be utilisation data from AI Factories themselves: the proportion of compute used by European start-ups, established industry, universities and foreign-controlled companies; the number of models reaching commercial deployment; and whether AI Factory users subsequently raise capital and scale within Europe. EuroHPC currently reports the infrastructure footprint but the long-term sovereignty assessment requires economic outcome measures rather than machine counts alone. EuroHPC Joint Undertaking

The fourth concerns national execution. Italy’s IT4LIA system, France’s large infrastructure commitments, Germany’s 2030 data-centre targets and the United Kingdom’s AIRR expansion now have sufficiently explicit capacity objectives that future performance can be assessed against concrete deployment rather than political intention. EuroHPC — Italy Élysée — France AI investment Bundesregierung — Germany Data Centre Strategy UK Government — Compute Roadmap

Pillar Three • European Sovereign AI

Who Captures the Value of European AI?

Europe is moving from a regulatory phase into an infrastructure and industrial-capacity phase. The strategic question is no longer whether Europe possesses data or scientific expertise, but whether European compute, energy, capital, cloud infrastructure, models, procurement and industrial adoption can be integrated strongly enough to convert those assets into European-controlled intellectual property, revenues and productive capacity.

Sovereign AI is a production system

Infrastructure

Compute must exist at European scale

AI Factories, AI Gigafactories, national supercomputers and expanded data-centre capacity address the physical scarcity of advanced computation that previously constrained European AI development.

Industrial Conversion

Compute must become products and companies

Scientific machines alone do not create sovereignty; start-ups, industrial firms and public institutions must transform European compute into models, software, processes, intellectual property and exportable applications.

Value Capture

Physical localisation is insufficient

A European data centre can still run imported chips, foreign clouds and externally controlled models. Sovereignty depends on control across enough layers of the AI production chain to preserve bargaining power and economic returns.

The European AI value chain

Data Industrial, public, scientific and consumer information.
Compute EuroHPC, national HPC, AI Factories and future Gigafactories.
Models Foundation models, sectoral models, fine-tuning and inference systems.
Applications Manufacturing, health, energy, logistics, finance and public administration.
Value Capture IP, revenues, productivity, tax base, employment and strategic control.

Europe’s emerging compute architecture

Layer Mechanism Verified scale / target Status Strategic function
Distributed AI compute EuroHPC AI Factories 19 factories DEPLOYING Access for start-ups, SMEs, researchers, public authorities and industry
Regional extension AI Factory Antennas 13 antennas DEPLOYING Extends services beyond host countries
European HPC base EuroHPC systems 14 supercomputers OPERATIONAL / EXPANDING Scientific, industrial and AI workloads
Frontier compute AI Gigafactories >100,000 advanced AI processors per facility concept PLANNED / PROCUREMENT Very-large-model training and inference
Gigafactory financing InvestAI €20bn mobilisation objective MOBILISATION Public-private de-risking of frontier infrastructure
Broader AI investment AI Continent / InvestAI €200bn stated ambition PROGRAMME Capital, infrastructure and ecosystem expansion
Cloud / data-centre capacity Cloud and AI Development Act At least 3× EU capacity in 5–7 years POLICY TARGET Expand cloud and AI infrastructure availability

The industrial adoption problem

EU enterprise category AI use in 2025 Interpretation
All enterprises with 10+ employees ~20.0% AI diffusion accelerating, but still far from universal
Small enterprises ~17.0% The majority remain outside substantial AI adoption
Medium enterprises 30.36% Meaningful adoption with large additional potential
Large enterprises 55.03% AI increasingly embedded inside major corporate organisations
EU enterprises in 2023 8.1% Pre-acceleration baseline
EU enterprises in 2024 13.5% Rapid transition already visible

National sovereign-AI models

ITALY

Infrastructure + industrial specialisation

Italy is building sovereign compute around CINECA, Leonardo, LISA and IT4LIA, with a particular opportunity in specialised manufacturing, engineering, health and public-sector AI.

>20,000
GPUs expected across the IT4LIA environment
FRANCE

Full-stack AI power strategy

France combines compute, abundant electricity, national AI funding, domestic model developers, cloud-security policy and large private investment commitments.

€109bn
AI-related investment commitments announced in 2025
GERMANY

Industrial AI + data-centre expansion

Germany is linking manufacturing and Mittelstand data with a major national expansion of data-centre and high-performance AI infrastructure.

≥4×
HPC and AI capacity target by 2030 versus 2025
UNITED KINGDOM

Sovereign compute outside the EU

The UK provides the clearest external comparator: regulatory autonomy has not reduced the perceived need for large-scale publicly supported AI compute.

420
AI ExaFLOPS AIRR target for 2030

Italy: the compute-to-company challenge

Asset Verified position Strategic value Constraint
Leonardo Major EuroHPC system hosted by CINECA National HPC foundation Commercial conversion
LISA upgrade 166 eight-way GPU servers Generative AI and large-model capability Utilisation by firms and scale-ups
IT4LIA dedicated AI system Procurement approximately €290m Training, inference, RAG, reasoning and simulation Productisation and market scale
IT4LIA environment >20,000 GPUs expected Large European public-compute concentration Talent and late-stage capital
Italian AI Strategy Research, PA, enterprises and skills Institutional coordination Execution and measurable adoption

France: the full-stack strategy

Component Verified figure / policy Strategic role
National AI strategy Approximately €2.5bn through France 2030 Research, talent, ecosystem development and adoption
2025 AI investment commitments Approximately €109bn announced Data centres, infrastructure and deployment
Energy Government promotes stable low-carbon electricity availability Data-centre and compute competitiveness
Cloud sovereignty SecNumCloud framework Protection of sensitive strategic workloads
Industrial strategy Chips + compute + models + services + robotics Attempt to retain value across the stack

Germany: industrial AI at scale

Indicator Verified position / target Strategic meaning
Current data-centre connection capacity Approximately 3 GW Large existing infrastructure base
AI-oriented capacity Approximately 500 MW Dedicated AI compute footprint
Overall data-centre target At least 2× by 2030 vs 2025 National cloud and AI scale expansion
HPC / AI target At least 4× by 2030 vs 2025 Accelerated AI infrastructure expansion
HammerHAI 860 NVIDIA B200 GPUs Large AI-optimised compute resource
HammerHAI inference performance ~15 exaflops High-capacity model serving and inference
Strategic orientation Industrial and domain-specific AI Leverages Mittelstand and manufacturing data

United Kingdom: external comparator

Dimension Verified position Strategic meaning
AIRR compute capacity 21 AI ExaFLOPS in 2025 Starting public AI-compute base
AIRR target 420 AI ExaFLOPS by 2030 Twentyfold expansion
AIRR commitment >£1bn Sovereign compute expansion
New national supercomputer Up to £750m Frontier AI and scientific workloads
Public compute package Up to approximately £2bn National-scale strategic infrastructure
Open-access model 50,000 to 1.4 million GPU hours in 2026 call Commercial and research access pathway

Semiconductor sovereignty remains incomplete

European progress

  • The EU Chips Act has mobilised a major semiconductor policy framework.
  • AI Gigafactories create large predictable demand for accelerators and related components.
  • European processor design and specialist semiconductor capability can benefit from demand aggregation.

Remaining dependency

  • Most frontier AI infrastructure still depends heavily on non-European accelerator ecosystems.
  • Imported hardware can create European compute without creating full-stack European sovereignty.
  • Substitution capacity and diversified supply remain more realistic objectives than complete autarky.

The infrastructure layers that determine sovereignty

Energy

Electricity and grid access

Compute cannot scale without predictable electricity, fast connections and sufficient grid capacity.

Hardware

Processors and networking

Accelerator concentration remains one of Europe’s most important external dependencies.

Cloud

Control and portability

Physical localisation does not guarantee strategic control if cloud software, orchestration and switching remain externally concentrated.

Models

Ownership of AI systems

Europe must retain enough foundation and domain-model ownership to capture software and inference value.

Applications

Industrial deployment

Productivity gains only appear when models become embedded in manufacturing, health, finance, transport and public services.

Where AI value can leave Europe

Value-chain stage European asset Leakage mechanism Institutional response
Data Industrial, public and scientific datasets Data primarily exploited by external platforms Trusted access and interoperable data governance
Compute EuroHPC and national infrastructure Dependence on external accelerator ecosystems Gigafactories and diversified hardware supply
Cloud European hosting and local providers Hyperscaler concentration Portability, sovereignty standards and procurement
Models European researchers and start-ups Capital and distribution disadvantages Compute access, scale-up finance, public demand
Industrial deployment Manufacturing and proprietary operational data External APIs capture margins and know-how Domain-specific and confidential AI systems
Intellectual property Strong research base Relocation or acquisition of successful firms Late-stage European growth capital
Revenue Large EU internal market Margins accrue outside Europe European vendors, procurement and competitive infrastructure markets

Five institutional choices that determine value capture

Compute allocation Commercial scale-ups need predictable multi-year access, not only research-style grants.
Public finance Public capital should build additional European capability rather than merely subsidise foreign infrastructure.
Public procurement Governments can create anchor demand for European cloud, models and specialised AI systems.
Industrial confidentiality Firms must be able to use proprietary data without surrendering strategic knowledge to external platforms.
Scale-up capital Europe must finance successful AI firms beyond the start-up stage if ownership and IP are to remain European.

Institutional decision matrix

Policy domain Weak configuration Strong sovereignty configuration Observable indicator
Compute allocation Short, uncertain research grants Predictable commercial-scale access European firms training and serving models on EuroHPC
Gigafactory finance Infrastructure subsidy only Conditional European capability building European ownership and IP share
Cloud policy Physical data localisation Portability, control, substitutability and secure EU services Critical workloads on trusted European infrastructure
Industrial AI Generic external APIs Confidential domain-specific systems Manufacturing adoption without data surrender
Public procurement Fragmented tenders Aggregated interoperable demand European vendors winning strategic public contracts
Late-stage finance Strong seed funding but weak scaling capital Deep European growth financing Lower relocation and forced acquisition rates
Semiconductors Single external accelerator ecosystem Diversified supply and European processor capability European-designed hardware share rises
Energy Grid delays and uncertain power Fast connections and predictable supply AI facilities delivered without material energy delays

Europe versus the UK

Dimension European Union United Kingdom
Public compute structure EuroHPC + national facilities AIRR + national systems
Distributed access 19 AI Factories + 13 Antennas AIRR access programmes
Frontier expansion AI Gigafactories AIRR expansion + new national supercomputer
Compute target Multiple Gigafactory-scale projects 21 → 420 AI ExaFLOPS by 2030
Major public mobilisation €20bn Gigafactory objective >£1bn AIRR expansion
Industrial logic European strategic autonomy + industrial AI National sovereign compute + growth strategy
Regulatory environment EU AI Act and single-market framework Separate UK regulatory architecture

Indicators that would demonstrate genuine sovereignty

European model ownership Rising share of strategically important models owned and commercialised by European companies.
Commercial EuroHPC use Scale-ups receiving predictable long-term compute allocations rather than one-off experimental access.
Public procurement European vendors winning material government and critical-infrastructure AI contracts.
Industrial deployment Mittelstand, Italian SMEs and French industrial groups deploying AI without exporting proprietary data control.
Cloud substitutability Strategic workloads capable of moving across providers without prohibitive technical or contractual barriers.
Hardware diversification Reduced concentration of European AI infrastructure around one external accelerator ecosystem.
European growth capital More late-stage AI companies scaling in Europe without relocation or premature acquisition.
Revenue capture Greater share of inference, software and industrial-AI revenues retained inside European firms and fiscal systems.

Strategic Net Assessment

Europe has moved beyond the stage in which its AI strategy could be characterised principally as regulation. EuroHPC, 19 AI Factories, 13 AI Factory Antennas, planned Gigafactories, the proposed tripling of data-centre capacity, national programmes in Italy, France and Germany, and the United Kingdom’s parallel sovereign-compute expansion show that compute has become a recognised strategic input alongside data and regulation.

The remaining gap is value capture. European sovereignty is not demonstrated merely because an accelerator is installed inside an EU data centre, because the hardware, orchestration layer, foundation model, intellectual property and resulting revenues may still be controlled externally. The sovereign outcome therefore depends on whether public and private investment produces European scale-ups, European model ownership, trusted cloud capacity, industrial adoption, procurement demand and the ability to retain successful firms through the growth stage.

Italy’s strongest asset is publicly anchored high-performance compute linked to specialised industry; France is attempting the most explicit full-stack strategy by combining capital, electricity, models, cloud-security policy and infrastructure; Germany’s principal opportunity lies in applying very large new compute capacity to proprietary manufacturing and Mittelstand data; the United Kingdom confirms that regulatory autonomy does not remove the need for strategic public compute.

The decisive institutional test is therefore whether Europe integrates data policy, compute, cloud, energy, semiconductors, capital and procurement into a continental production system. If these layers remain fragmented, European data can increase global AI productivity without creating equivalent European economic power. If they converge, Europe possesses a plausible route toward an AI model based less on consumer-platform dominance and more on industrial, scientific and public-sector value creation.

Figures distinguish operational assets, policy targets, announced investment commitments and planned procurement where materially different. Announced investment values must not be interpreted as completed expenditure.

Copyright of debuglies.com – Even partial reproduction of the contents is not permitted without prior authorization Reproduction reserved

LEAVE A REPLY

Please enter your comment!
Please enter your name here

Questo sito utilizza Akismet per ridurre lo spam. Scopri come vengono elaborati i dati derivati dai commenti.