Scope: European Union, with specific strategic lenses on Italy, France, Germany and the United Kingdom; the assessment distinguishes the law currently in force from the Commission’s November 2025 proposal and the Council Presidency’s revised compromise text of 3 September 2026, and examines whether wider lawful access to personal data would principally reinforce incumbent global AI firms or contribute to an autonomous European AI industrial base. The structure and evidentiary standard follow the supplied Academic Governance Edition V9.0 protocol. Testo incollato
Executive Summary / BLUF
The central issue is more consequential than a technical amendment to the GDPR: Europe is deciding whether personal data should become a more readily usable productive input for artificial intelligence, while it still lacks assurance that the economic value generated from those data will be captured inside Europe.
The GDPR has not been suspended or replaced. The operative law remains Regulation (EU) 2016/679, including Article 6(1)(f), under which legitimate-interest processing requires a legitimate purpose, necessity and a balancing of the controller’s interest against the rights and freedoms of the individual. Regulation (EU) 2016/679 — European Parliament and Council Eur-Lex
The Commission’s Digital Omnibus, COM(2025) 837, proposed on 19 November 2025, introduced an explicit GDPR provision for AI development and operation while retaining express safeguards. The ordinary legislative procedure 2025/0360/COD remains open, so this proposal is not current law. COM(2025) 837 final — European Commission Procedure 2025/0360/COD — EUR-Lex Eur-Lex
The Council Presidency’s 3 September 2026 revised compromise, document 12535/26, materially alters that architecture: its tracked text removes from the operative AI provision the Commission language expressly identifying children, consent requirements under other laws, AI-specific data minimisation, enhanced transparency and an unconditional AI-specific right to object, while retaining a general requirement for safeguards and linking processing to Article 6(1)(f). Presidency revised compromise text — Council of the European Union, 3 September 2026 noyb.eu
This does not create an unrestricted entitlement to ingest every European’s historic digital life into a model. Existing GDPR principles, Article 6 requirements, Article 21 objection rights and other applicable law remain relevant unless and until the legislature modifies them. The European Data Protection Board has already held that reliance on legitimate interest in AI requires a case-specific analysis rather than an automatic presumption of legality. Opinion 28/2024 on AI Models — European Data Protection Board EDPB
The industrial-policy problem is nevertheless genuine: the proposed rule is nationality-neutral. It does not reserve the resulting data advantage for European companies, and the GDPR itself expressly reaches qualifying controllers established outside the Union. Consequently, any legal widening of AI data access can benefit European developers but can also be exploited by global incumbents already possessing massive user relationships, historic datasets, distribution channels, capital and computing infrastructure. GDPR, Article 3 — EUR-Lex Eur-Lex
Europe is not starting from zero: the EU has established 19 AI Factories and 13 AI Factory Antennas, while France, Germany and Italy are building national AI strategies and infrastructure around the same objective of technological sovereignty. AI Factories — EuroHPC Joint Undertaking EuroHPC The decisive question is therefore not simply whether Europe permits more data processing, but whether data liberalisation, compute, capital, models, procurement and industrial deployment are integrated strongly enough for European firms to retain part of the value created from European data.
Europe Is Building AI Infrastructure. The Harder Test Is Who Captures the Value
Europe’s artificial-intelligence debate is moving from regulation to production capacity, but the central economic question remains unresolved: who will own the models, infrastructure and revenues created from European data, electricity and industrial knowledge? The European Commission’s AI Continent programme sets a €200 billion investment ambition, including €20 billion for AI Gigafactories, while EuroHPC now reports 19 AI Factories, 13 Factory Antennas and 14 supercomputers. That is a material change in industrial policy, yet infrastructure located in Europe is not automatically European technological sovereignty. A European data centre can still depend on non-European accelerators, foreign cloud software and externally controlled foundation models. The next phase will therefore be decided not by machine counts alone, but by whether public compute, capital, procurement and industrial datasets produce companies and intellectual property that remain economically anchored in Europe.
Europe has finally recognised that AI policy begins with machines
The Commission’s current architecture marks a departure from the period when European AI policy was defined primarily through rules. EuroHPC reports 19 AI Factories and 13 AI Factory Antennas built around a wider network that includes 14 supercomputers, while the Gigafactory concept envisages individual facilities capable of assembling more than 100,000 advanced AI processors. The €20 billion Gigafactory mobilisation sits inside the wider €200 billion AI Continent investment ambition, and the proposed Cloud and AI Development Act seeks at least to triple European data-centre capacity within five to seven years.
Those figures matter because frontier AI is increasingly an infrastructure industry. Training, fine-tuning and serving large models require accelerators, storage, networking, cooling, electricity and specialised software at scales that young European firms cannot finance independently. Public intervention is therefore attempting to reduce an entry barrier that previously favoured companies already operating hyperscale infrastructure.
The policy shift is rational, but it creates a second-order problem. Public capital can increase the quantity of computation available in Europe without determining who captures the most profitable layers above it. If European Gigafactories predominantly host foreign-controlled models on foreign-designed processors through foreign cloud stacks, Europe gains capacity, employment and resilience, but not necessarily control over the highest-margin intellectual property.
The adoption numbers show why industrial diffusion matters more than symbolic model races
Europe’s comparative advantage is not a consumer-platform economy equivalent to that of the United States. It is an industrial economy containing advanced manufacturing, machinery, automotive, chemicals, pharmaceuticals, energy, logistics and public-service systems that generate valuable proprietary data. That makes industrial adoption more important than a competition over whether one European general-purpose model briefly matches an American rival on a benchmark.
Eurostat reported that approximately 20% of EU enterprises with at least ten employees used AI in 2025, compared with 13.5% in 2024 and 8.1% in 2023. The aggregate masks a sharp scale divide: AI use reached about 55.03% among large enterprises, 30.36% among medium-sized companies and roughly 17% among small firms.
That distribution defines the economic problem. Europe can build frontier compute while leaving most of its productive base unable to exploit it. For the Mittelstand in Germany, specialised manufacturers in Italy and industrial suppliers across the single market, sovereign AI will matter only if computing capacity can be accessed at predictable prices and combined with proprietary company data without surrendering process knowledge to an external platform.
The relevant objective is therefore not simply more AI companies. It is a production system in which European firms can move from data to computation, from computation to models, and from models to industrial products without losing control at each stage.
Italy has built serious compute; now it has to build serious companies on top of it
Italy illustrates the difference between infrastructure strength and commercial scale. The IT4LIA AI Factory is being constructed around CINECA, Leonardo, the LISA upgrade and additional cloud infrastructure, with EuroHPC expecting the broader environment to provide more than 20,000 GPUs when completed. Procurement for the dedicated IT4LIA AI-optimised supercomputer carries an estimated value of approximately €290 million, while the LISA upgrade includes 166 eight-way GPU servers intended for large-language-model and multimodal workloads.
This gives Italy something economically significant: a publicly anchored AI-compute concentration tied to one of Europe’s established high-performance computing centres. The Italian Strategy for Artificial Intelligence 2024–2026 also links research, public administration, enterprises and skills rather than treating AI as a research programme alone.
The missing conversion mechanism is scale. Italy’s strongest prospective uses sit inside machinery, robotics, automotive components, aerospace, biomedical technologies, pharmaceuticals and advanced manufacturing, where proprietary industrial knowledge matters more than internet-scale consumer data. The country therefore does not need to reproduce the economics of a global social platform. It needs to ensure that IT4LIA produces commercially deployable systems, exportable software and firms capable of financing growth beyond the laboratory and pilot stage.
A €290 million machine that is heavily used can still represent an industrial-policy failure if the resulting value is captured primarily by suppliers further up or down the chain.
France is trying to assemble the full stack rather than one component
France has taken the broadest national approach among the large continental economies. Approximately €2.5 billion from France 2030 has been associated with the national AI strategy, while the February 2025 AI Action Summit produced announcements of approximately €109 billion in French and foreign AI-related investment commitments.
The distinction between commitments and realised expenditure is important, but so is the architecture behind them. France is combining data-centre investment with domestic model development, research, talent programmes, cloud-security policy and an electricity system that the government actively presents as an advantage for power-intensive AI infrastructure.
The French approach is economically stronger than a policy based solely on attracting data centres because Paris is explicitly attempting to connect chips, compute, models, services and robotics. The SecNumCloud framework adds another layer by addressing sensitive cloud workloads and the requirements of public administration and strategic sectors.
The risk is that physical investment runs faster than domestic intellectual-property formation. France can attract enormous capital into server facilities while still allowing the highest-value model, cloud and accelerator rents to accrue elsewhere. The €109 billion headline will therefore matter less than the ownership structure of the software, models and companies operating above those facilities.
Germany’s wager is that factories will matter more than chatbots
Germany’s strategy is anchored in industrial data and infrastructure expansion. Federal policy now places AI among the technologies central to the Hightech Agenda Deutschland, while the government’s data-centre strategy reports roughly 3 GW of national connection capacity and approximately 500 MW associated with AI, with targets to at least double overall capacity and quadruple high-performance computing and AI capacity by 2030 relative to 2025.
EuroHPC’s German infrastructure adds another layer. HammerHAI is specified with 860 NVIDIA B200 GPUs, approximately 15 exaflops of peak AI inference performance and 10 PB of storage, while Germany also hosts major EuroHPC capacity through JUPITER.
The decisive German asset, however, is not the number of GPUs. It is the data accumulated inside automotive production, machinery, chemicals, pharmaceuticals, logistics and the Mittelstand. Those datasets encode processes that competitors cannot simply scrape from the open internet.
This creates an opportunity for a European AI model fundamentally different from the American consumer-platform model. A German industrial company does not necessarily need the world’s largest foundation model; it needs secure, specialised systems capable of improving engineering, maintenance, design, procurement and production without exporting its underlying know-how.
Germany’s constraint is execution. Grid connections, energy cost, permitting and financing determine whether the planned doubling and quadrupling translate into operational capacity quickly enough to influence corporate investment decisions.
Britain shows that regulatory freedom does not eliminate the compute problem
The United Kingdom provides a useful comparison precisely because it sits outside the EU’s regulatory framework. Its policy still reaches the same conclusion: sovereign AI requires large publicly supported computing infrastructure.
The UK Compute Roadmap provides more explicit numerical targets than most continental programmes. The government intends to expand the AI Research Resource from approximately 21 AI ExaFLOPS in 2025 to 420 AI ExaFLOPS by 2030, a twentyfold increase supported by more than £1 billion, alongside up to £750 million for a new national supercomputer within a wider public-compute package of approximately £2 billion.
AIRR combines Isambard-AI in Bristol and Dawn in Cambridge and has already created access mechanisms under which qualifying projects can seek between 50,000 and 1.4 million GPU hours.
The British case therefore weakens the proposition that Europe’s primary AI problem is excessive regulation. A country with regulatory autonomy has independently concluded that public compute, infrastructure investment and national access mechanisms are necessary because private market structure alone does not guarantee domestic frontier capacity.
The relevant comparison between Britain and the EU is not deregulation against regulation. It is two different institutional systems trying to overcome the same concentration of compute, capital and technological scale.
The next 24 months will decide whether public money creates European leverage or cheaper inputs for incumbents
The first AI Gigafactory selections, IT4LIA deployment, France’s conversion of announced investment into operating assets, Germany’s implementation of its 2030 capacity programme and Britain’s AIRR expansion will provide the first serious evidence of whether current policy is creating sovereign capability rather than infrastructure volume.
The test over the next 12–24 months is measurable. European scale-ups need predictable commercial access to EuroHPC resources rather than episodic research allocations. Public procurement must provide anchor demand for European cloud, model and application providers. Gigafactory financing must generate additional European capability rather than merely reduce the capital cost of facilities dominated by external suppliers. Industrial companies must be able to combine proprietary data with advanced AI without transferring operational knowledge outside trusted environments.
The cost of failure will not fall primarily on regulators or public research laboratories. It will fall on European manufacturers that pay recurring inference and cloud rents to external platforms, on start-ups forced to scale under foreign infrastructure providers, on taxpayers who finance compute without capturing the resulting intellectual property, and on governments that discover that physical data-centre capacity is not the same thing as technological control.
Europe is now spending enough money to build meaningful AI infrastructure. The question is whether it will also build the ownership structures, procurement markets and companies required to keep a meaningful share of the value.
Navigational Index
Pillar One — The legal transformation
What the Digital Omnibus actually changes, what remains protected by the GDPR, how Article 6(1)(f), sensitive data, pseudonymisation and objection rights would operate, and where the September 2026 Council compromise differs from the Commission proposal.
Pillar Two — The industrial distribution of the data dividend
Whether broader access to personal data structurally advantages established US and global AI platforms, whether Europe possesses sufficient compute, capital, models and market access to exploit the same rules, and why legal access to data is not equivalent to technological sovereignty.
Pillar Three — Europe’s sovereign-AI capacity
How the EU, Italy, France and Germany are constructing compute and AI ecosystems, how the United Kingdom provides a regulatory and industrial comparator outside the EU framework, and which institutional choices will determine whether European data produces European value.
Master Abstract
The reform is real, but the headline “GDPR is being abolished for AI” is legally inaccurate
The relevant legislative file is the Commission’s Digital Omnibus proposal COM(2025) 837, tabled on 19 November 2025 as a broad simplification package covering the GDPR, Data Act and other digital legislation. The Commission explicitly presented the package as an attempt to reduce administrative burdens and increase the availability of data for innovation while maintaining privacy and fundamental-rights protections. Digital Omnibus Regulation Proposal — European Commission, 19 November 2025 Strategia Digitale Europea The proposal remains within the ordinary legislative process under 2025/0360/COD, and therefore neither its original wording nor the September 2026 Presidency compromise can be treated as enacted GDPR law. Procedure 2025/0360/COD — EUR-Lex Eur-Lex
That distinction is particularly important because a separate instrument, the Digital Omnibus on AI, dealing with the implementation of the AI Act, has already entered into force on 27 July 2026. The two files should not be conflated: the AI Omnibus already in force concerns the AI regulatory framework, while the contested GDPR changes discussed here remain part of the still-pending broader Digital Omnibus legislative file. AI Omnibus enters into force — European Commission, 27 July 2026 Strategia Digitale Europea
The original Commission proposal introduced Article 88c, “Processing in the context of the development and operation of AI.” The September Council text shows, through tracked deletions and additions, how this provision has been reshaped and provisionally renumbered Article 88 bis. The operative compromise text states that processing personal data in the development and operation of an AI system or AI model may be carried out for a legitimate interest of the controller or a third party in accordance with Article 6(1)(f), while a separate paragraph retains an obligation to implement appropriate technical and organisational measures and safeguards. Presidency revised compromise text, document 12535/26 — Council of the European Union noyb.eu
The tracked document is particularly revealing because it records what has disappeared from the article itself. The earlier formulation expressly stated that the legitimate interest should not override the interests, fundamental rights and freedoms of the data subject, “in particular where the data subject is a child,” and referred expressly to cases in which Union or national law requires consent. Those words are struck through in the 3 September compromise. The earlier second paragraph also expressly identified data minimisation during source selection, training and testing, protection against disclosure of residually retained information, enhanced transparency and an unconditional right to object; that package likewise appears deleted from the operative article and replaced by much shorter general language. Council Presidency revised compromise, Article 88 bis — 3 September 2026 noyb.eu
That is a significant weakening of AI-specific statutory safeguards, but it is not the same as deleting those concepts from European data-protection law. Article 6(1)(f) of the existing GDPR already requires that processing be necessary for a legitimate interest and that this interest not be overridden by the rights and fundamental freedoms of the data subject, with children specifically identified as deserving particular protection. Article 21 also gives individuals a right to object to processing based on Article 6(1)(f), although — unlike the deleted Commission AI-specific language — the ordinary Article 21 right is not unconditional, because a controller may continue where it demonstrates compelling legitimate grounds overriding the individual’s interests, rights and freedoms. General Data Protection Regulation, Articles 6 and 21 — EUR-Lex Eur-Lex
This distinction is central. The Council text does not literally eliminate the balancing exercise; instead, it removes several explicit AI-specific restatements and safeguards from Article 88 bis and places more legal weight back on the general GDPR framework. The practical consequences could nevertheless be considerable because litigation, supervisory interpretation and corporate compliance would begin from a legislative statement explicitly recognising AI development and operation as a context in which legitimate interest may be invoked.
Legitimate interest is not a blank cheque
The European Data Protection Board’s Opinion 28/2024, adopted on 18 December 2024, addressed precisely whether legitimate interest can provide a lawful basis for the development and deployment of AI models. It did not establish a universal prohibition, but neither did it establish an automatic entitlement. The Board’s framework requires assessment of whether a legitimate interest exists, whether processing is necessary for that interest and whether the data subject’s interests, rights or freedoms override it, with the circumstances of the particular processing remaining decisive. Opinion 28/2024 — European Data Protection Board EDPB
This means that the difference between the existing environment and the proposed framework is subtler, but potentially more powerful, than the claim that “consent disappears.” Consent is already only one of several legal bases under Article 6. The important shift is that legislators are considering making AI development and operation an expressly recognised setting for legitimate-interest processing, thereby reducing part of the legal ambiguity that currently surrounds training on personal data.
The effect on old chats, publications, profiles and digital archives therefore depends on their provenance, the original processing circumstances, the reasonable expectations of individuals, the purpose pursued, necessity, data minimisation, Article 9 restrictions where sensitive data are involved, objection rights and other applicable rules. Merely possessing twenty years of user information would not, by itself, establish compliance.
The special-category-data provision is economically important and legally sensitive
The September text also introduces a proposed derogation concerning unintentional and residual special-category personal data in AI development and technical operation. The categories covered by Article 9 of the GDPR include, among other matters, information concerning racial or ethnic origin, political opinions, religious or philosophical beliefs, trade-union membership, genetics, biometrics used for identification, health and sex life or sexual orientation. General Data Protection Regulation, Article 9 — EUR-Lex Eur-Lex
The Council compromise does not authorise intentional bulk exploitation of those categories simply because AI is involved. Its proposed rule is directed to information that remains unintentionally and residually within datasets despite technical and organisational measures intended to prevent the processing. Where such information is identified, the controller is expected to remove it; where removal is technically impossible or would require manifestly disproportionate effort, the text requires measures preventing further use, including preventing the information from influencing outputs or being disclosed to third parties. Presidency revised compromise text, recitals and proposed Article 9 amendments — Council of the European Union noyb.eu
That provision matters because very large training corpora cannot reliably be assumed to contain only ordinary personal information. It attempts to resolve a real engineering problem — incidental contamination of datasets — but simultaneously creates a governance question over when “unintentional and residual” processing ends and substantive exploitation begins.
Pseudonymisation could redraw the GDPR’s practical perimeter
A second potentially structural change concerns the identification of individuals from pseudonymised information. The Presidency compromise proposes that pseudonymised data would not be considered personal data for a person unable to identify the individual concerned, subject to additional conditions elsewhere in the proposed article. Presidency revised compromise text, proposed Article 25a — Council of the European Union noyb.eu
The significance extends well beyond AI training. The current GDPR definition turns on whether a natural person is identified or identifiable, directly or indirectly, taking account of the relevant circumstances. Changing how identifiability is assessed for a particular recipient can therefore change whether particular datasets remain within the GDPR’s regulatory perimeter for that entity. General Data Protection Regulation, Article 4 — EUR-Lex Eur-Lex
The EDPB and EDPS have consequently treated the Digital Omnibus proposals as much more than housekeeping. In their Joint Opinion 2/2026, they supported simplification objectives while raising concerns about changes capable of affecting the substantive protection provided by the GDPR, including questions surrounding pseudonymisation and the definition of personal data. EDPB-EDPS Joint Opinion 2/2026 — European Data Protection Board and European Data Protection Supervisor EDPB
The Meta case demonstrates why the reform matters
The policy dispute is not hypothetical. In 2025 Meta moved toward using public material associated with adult Facebook and Instagram users in Europe for AI training while relying on legitimate interest rather than requiring opt-in consent. noyb issued a formal cease-and-desist letter on 14 May 2025 challenging Meta’s reliance on Article 6(1)(f); the organisation’s position was that the processing lacked an adequate legal basis and should instead require consent. Cease and Desist — Training of Meta AI in the EU — noyb, 14 May 2025 noyb.eu
noyb is a donation-funded NGO based in Vienna, Austria working to enforce data protection laws, in particular the GDPR and the ePrivacy Directive. At the present, a team of more than 20 legal and IT experts from all over Europe is working to ensure that the fundamental right to privacy is respected by the private sector.
That example should be understood as a contested legal case rather than proof that all legitimate-interest AI training is unlawful. Indeed, the EDPB’s own 2024 opinion recognises that legitimate interest can, under appropriate circumstances, provide a lawful basis for AI-related processing. The unresolved policy issue is therefore the width of the permissible corridor and the burden that controllers must satisfy before entering it.
noyb now characterises the September 2026 Council direction as “digital expropriation” and argues that companies holding decades of historical personal information would acquire a disproportionate advantage. This is the organisation’s advocacy assessment, not a description of enacted law, and its more expansive claims should be read accordingly. AI: EU Member States plan “digital expropriation” — noyb, 21 September 2026 noyb.eu
The industrial-policy question is harder than the privacy question
The strongest criticism of the emerging framework does not require accepting the proposition that AI companies receive unlimited access to European data. The more defensible strategic concern is that a horizontal relaxation or clarification applies to incumbents and challengers alike, whereas their ability to exploit the resulting data opportunity is radically unequal.
The GDPR’s territorial rules illustrate the problem. Article 3 applies not only to controllers established within the Union but, under specified conditions, also to controllers outside the Union when they offer goods or services to people in the EU or monitor their behaviour there. An AI-data provision inserted into that framework would therefore not constitute a European industrial preference; it would create a legal opportunity available to any qualifying controller operating within the GDPR’s scope. General Data Protection Regulation, Article 3 — EUR-Lex Eur-Lex
This is where data sovereignty and AI sovereignty diverge. A European legal regime can govern European personal data without ensuring that the models trained from those data are European, that the compute is European, that the intellectual property is held in Europe, that inference revenues accrue to European firms, or that downstream technological dependencies are reduced.
Consequently, the proposition that broader AI data access will automatically create a European AI industry is unsupported. Data are one strategic input among several: advanced compute, accelerators, data-centre power, engineering talent, foundation-model capability, risk capital, cloud distribution, procurement markets and global scale all matter. Removing one constraint does not remove the others.
Europe is nevertheless building the infrastructure required to capture part of the value
The counterargument to a simple “Europe is giving its data away” thesis is that the Union is simultaneously creating public AI infrastructure intended precisely to lower entry barriers for European companies. EuroHPC now reports 19 AI Factories and 13 AI Factory Antennas, providing computing power and customised support to SMEs and start-ups. AI Factories — EuroHPC Joint Undertaking EuroHPC
The Commission’s AI Factory programme has expanded through successive selections across the Union, including installations in France and Germany, while its broader policy direction links compute infrastructure, data availability and industrial adoption. AI Factories — European Commission Strategia Digitale Europea
The strategic significance is clear: if Europe can combine lawful data access + European compute + European model developers + domestic industrial datasets + public procurement + capital, a more permissive data environment could support European AI capacity rather than merely foreign platforms. If those complementary conditions remain inadequate, the same legal opening can reinforce actors that already possess superior scale.
Italy, France, Germany and the United Kingdom
Italy: valuable domain data, but conversion into model ownership remains the challenge
Italy’s Artificial Intelligence Strategy 2024–2026 explicitly recognises that the country’s distinctive economic assets increasingly depend on the codification and availability of data and AI models capable of representing Italian industrial and institutional specificities. The strategy is organised around research, public administration, enterprises and skills, and explicitly discusses the construction of data infrastructures and country-specific AI capabilities. Italian Strategy for Artificial Intelligence 2024–2026 — Department for Digital Transformation and AgID Digitale Italia
For Italy, the principal strategic asset is therefore not necessarily consumer-scale social-network data but high-value sectoral information embedded in manufacturing, mechanical engineering, healthcare, public administration, cultural assets and specialised SMEs. The policy risk is that liberalisation of personal-data use could have limited sovereign benefit if Italian companies remain users of foreign foundation models rather than developers or owners of the systems extracting value from those data. Conversely, trusted sectoral datasets linked to European computing infrastructure offer Italy a credible route toward specialised and industrial AI rather than an attempt to reproduce the scale economics of every global consumer model.
France: the clearest continental attempt to combine capital, compute and model development
France has made technological sovereignty a central element of its AI policy and used the February 2025 AI Action Summit in Paris to position itself as a European centre for model development, investment and infrastructure. The Élysée presented the summit as part of an effort for France and Europe to remain major actors in the global AI transformation, accompanied by more than one hundred announced actions and commitments across access, sustainable AI and international governance. AI Action Summit — Élysée, February 2025 elysee.fr
France is therefore unusually well positioned to capture part of any additional European data dividend because it combines domestic model development, public research, compute infrastructure and policy-backed investment mobilisation. Yet the same structural caveat applies: an EU-wide legitimate-interest rule would not allocate French or European personal information preferentially to French developers.
Germany: industrial data may matter more than consumer data
Germany’s Hightech Agenda Deutschland, adopted in July 2025, makes AI one of six strategic technologies and explicitly links technological capability to competitiveness, value creation and sovereignty. The federal government subsequently committed to AI initiatives, industrial application and expanded computing infrastructure. Hightech Agenda Deutschland — Federal Government of Germany Bundesregierung
Germany’s September 2026 data-centre strategy adds an unusually concrete infrastructure objective: it seeks to double overall German data-centre connection capacity by 2030 relative to 2025 and at least quadruple connection capacity devoted to high-performance computing and AI. Data Centre Strategy — Federal Government of Germany, 18 September 2026 Bundesregierung
For Germany, the strategically decisive dataset may therefore be the information locked inside the Mittelstand, industrial supply chains, machinery, automotive systems, chemical engineering and manufacturing processes, rather than historic consumer conversations. The government itself has publicly emphasised the underexploited potential of data held by German SMEs and has linked that opportunity to domain-specific AI development. Federal Chancellor address on artificial intelligence and industry — Bundesregierung Bundesregierung
United Kingdom: an external comparator pursuing compute and data access without the EU legislative architecture
The United Kingdom no longer participates in EU legislation and therefore provides a useful comparator rather than a constituent part of the Digital Omnibus debate. Its AI Opportunities Action Plan, published on 13 January 2025, explicitly warned that the UK risked falling behind the United States and China despite possessing significant AI research and commercial capabilities, and proposed a broad programme covering sovereign capacity, computing, data access, adoption and sectoral growth. AI Opportunities Action Plan — UK Department for Science, Innovation and Technology GOV.UK
The British case demonstrates that the European strategic dilemma is broader than GDPR compliance. A country can pursue a more innovation-oriented regulatory environment and still confront the same fundamental questions over compute scale, capital intensity, frontier-model ownership and dependence on foreign technology platforms. Regulatory flexibility can improve conditions for innovation, but it does not itself manufacture a sovereign AI industry.
Key Evidence Table
| Indicator | Value / status | Reference date | Definition / scope | Issuer | Exact source |
|---|---|---|---|---|---|
| Digital Omnibus GDPR reform | Pending, not law | 26 Sep 2026 | Ordinary legislative procedure 2025/0360/COD | EU institutions | Procedure 2025/0360/COD — EUR-Lex |
| Commission proposal | COM(2025) 837 final | 19 Nov 2025 | Broad digital simplification including GDPR amendments | European Commission | COM(2025) 837 — EUR-Lex |
| Presidency revised compromise | Document 12535/26 | 3 Sep 2026 | Revised negotiating text prepared for Council discussions | Council of the EU | Presidency revised compromise |
| AI legitimate interest | Explicitly recognised as potentially available | Sep 2026 draft | AI development and operation under Article 6(1)(f) | Council Presidency text | Article 88 bis draft |
| Existing legitimate-interest test | Remains operative law | Current | Interest, necessity and rights-balancing requirements | EU legislature | GDPR — EUR-Lex |
| EDPB AI position | Case-specific legitimate-interest assessment required | 18 Dec 2024 | AI-model development and deployment | EDPB | Opinion 28/2024 |
| EU AI infrastructure | 19 AI Factories + 13 Antennas | 2026 | Compute and support infrastructure for European AI ecosystem | EuroHPC JU | AI Factories — EuroHPC |
| German data-centre target | Overall capacity ×2; HPC/AI capacity at least ×4 | 2030 vs 2025 | Connection capacity | German Federal Government | Rechenzentrumsstrategie |
Competing Strategic Pathways
| Pathway | Diagnostic support | Disconfirming evidence | Indicators | Current standing |
|---|---|---|---|---|
| European AI capacity captures a substantial share of the new data value | EuroHPC AI Factories, national compute strategies, French/German/Italian industrial policies, specialised European models | European firms still face capital, scale, semiconductor and distribution constraints | European model training volumes, EuroHPC utilisation, procurement share, private AI investment, model deployment in industry | Institutionally plausible, but dependent on complementary industrial execution |
| The reform principally strengthens existing global incumbents | Nationality-neutral rule; incumbents possess large user archives, compute and established distribution | European public compute and sector-specific datasets can lower entry barriers for challengers | Concentration of AI-data processing, cloud/model-provider shares, acquisitions, compute consumption | Material structural risk, but not an automatic legal consequence |
| Litigation and supervisory interpretation preserve a tighter practical regime than the statutory wording suggests | Article 6(1)(f), Article 21, Charter rights, EDPB case-specific analysis remain relevant | An explicit AI provision can shift legal expectations and reduce uncertainty for controllers | CJEU judgments, EDPB guidance, DPA enforcement, final Article 88 bis wording | Highly consequential uncertainty until the final law and subsequent jurisprudence emerge |
Principal Gaps and Watch Indicators
The first decisive indicator is the final Council position and subsequent Parliament–Council negotiation. The 3 September 2026 document is a Presidency compromise, not the final law, and Article 88 bis can still be narrowed, expanded, renumbered or deleted before adoption. Procedure 2025/0360/COD — EUR-Lex Eur-Lex
The second is whether the final instrument restores explicit safeguards concerning children, consent-dependent processing, source-selection minimisation, transparency and objection, or instead relies principally on general GDPR provisions.
The third is the treatment of pseudonymised data, because a recipient-relative definition of identifiability could affect a much larger universe of commercial and research datasets than AI training alone.
The fourth is jurisprudential rather than legislative: the practical value of Article 88 bis will depend heavily on how supervisory authorities and ultimately the Court of Justice interpret the relationship between the new provision and Articles 5, 6, 9, 21 and 25 of the GDPR.
The fifth is industrial: Europe should be watched not simply for the number of AI initiatives announced, but for measurable growth in European-controlled compute, model ownership, inference revenues, data-centre capacity, AI procurement, venture financing and industrial deployment.
The sixth is distributional: if the largest increase in lawful AI processing is undertaken by companies whose principal model ownership, compute infrastructure and monetisation remain outside Europe, the reform will have improved the European data supply without proportionately improving European technological sovereignty; if the opposite occurs, the same law could become an input to European AI industrialisation.
Net Assessment
The public record does not support the proposition that Brussels has already authorised AI companies to seize Europeans’ data without restriction. That law does not exist today. The GDPR remains operative, Article 6(1)(f) remains conditional, Article 21 remains relevant, and the Digital Omnibus remains under negotiation. General Data Protection Regulation — EUR-Lex Procedure 2025/0360/COD — EUR-Lex Eur-Lex
The September 2026 compromise nevertheless represents a material policy movement toward making personal data easier to use in AI development under legitimate interest, particularly because several explicit AI-specific protections contained in the earlier architecture have been removed from the operative provision. That deserves to be treated as substantive regulatory change rather than administrative simplification. Council Presidency revised compromise, document 12535/26 noyb.eu
The more important strategic conclusion is that data liberalisation and technological sovereignty are not the same policy. Europe can make more data available for AI and still increase its dependence on non-European model providers; equally, it can combine lawful data access with EuroHPC compute, national AI programmes, industrial datasets, European developers and procurement to build a more competitive domestic ecosystem.
The September debate therefore exposes a deeper European policy question: if personal data are to become a more readily accessible factor of AI production, who owns the models, infrastructure, intellectual property and revenue streams that transform those data into economic power?
The answer is not contained in Article 88 bis. It will be determined by Europe’s ability to connect privacy law with compute, investment, industrial data strategy, competition policy and domestic model development. Without that connection, a GDPR relaxation risks becoming an input subsidy available equally — and perhaps more immediately — to the strongest global incumbents. With it, the same reform could form one component of a genuine European AI industrial strategy.
No decision-useful visualisation is supportable from the verified record at this stage because the core comparison concerns evolving legal text and strategic capacity rather than a sufficiently homogeneous quantitative series.
Europe’s AI Data Bargain
The strategic question is no longer simply whether personal data may be processed for artificial intelligence, but whether Europe can convert wider lawful data access into European-controlled models, infrastructure, intellectual property and economic value rather than strengthening already dominant global platforms.
The Three Strategic Questions
How far does legitimate interest expand?
The draft explicitly recognises Article 6(1)(f) as a potential lawful basis for AI development and operation, while several AI-specific safeguards appearing in earlier text have been removed from the operative provision.
Who captures the value of European data?
A nationality-neutral legal opening benefits European developers but also firms already possessing massive historical datasets, computing capacity, capital, global platforms and mature AI distribution channels.
Can Europe turn data into technological power?
Sovereignty depends on more than data access: Europe must connect data with compute, foundation models, capital, infrastructure, procurement, industrial adoption and ownership of resulting intellectual property.
From Personal Data to AI Economic Value
Two Possible Economic Outcomes
Path A — Data liberalisation reinforces external incumbents
- Large technology groups already possess historical user relationships and extensive datasets.
- They operate mature foundation models and global distribution platforms.
- They possess greater access to capital, cloud infrastructure and accelerator capacity.
- European data become an additional productive input without equivalent European capture of model ownership or revenues.
Path B — Data access accelerates European AI capacity
- EuroHPC infrastructure lowers compute barriers for European firms and research organisations.
- Industrial and institutional datasets support specialised European AI models.
- National programmes reinforce domestic ecosystems in France, Germany and Italy.
- Procurement, capital and deployment allow European firms to retain part of the economic value generated from European data.
Country Strategic Lenses
Industrial and sectoral data
Italy’s comparative asset lies in specialised datasets embedded in manufacturing, SMEs, healthcare, public administration, cultural assets and highly specific industrial knowledge; the strategic challenge is converting those assets into European-controlled models rather than remaining primarily a downstream user of foreign systems.
Models, capital and compute
France has developed one of Europe’s most explicit sovereign-AI strategies by combining domestic model development, public research, infrastructure, investment mobilisation and political support for European technological autonomy.
Industrial AI scale
Germany’s strongest opportunity lies in manufacturing and Mittelstand data, reinforced by a federal strategy that links AI adoption, industrial competitiveness and major expansion of computing and data-centre capacity.
External regulatory comparator
Outside the EU legal framework, the UK demonstrates that regulatory flexibility alone does not ensure sovereign AI capability; compute, capital, frontier-model ownership, data access and commercial deployment remain decisive.
Verified Legal and Strategic Baseline
| Issue | Status | Reference | Strategic meaning |
|---|---|---|---|
| Current GDPR | IN FORCE | Regulation (EU) 2016/679 | Article 6(1)(f) continues to require legitimate interest, necessity and rights balancing. |
| Digital Omnibus GDPR reform | PENDING | 2025/0360/COD | The proposed AI-related changes have not yet become binding EU law. |
| Council Presidency compromise | NEGOTIATING TEXT | 12535/26 — 3 September 2026 | Expressly recognises legitimate-interest processing for AI while shortening earlier AI-specific safeguards. |
| EDPB AI interpretation | CURRENT GUIDANCE | Opinion 28/2024 | Legitimate interest remains dependent on a case-specific legal assessment rather than an automatic entitlement. |
| European AI infrastructure | DEPLOYING | 19 AI Factories + 13 Antennas | Provides public compute infrastructure intended to reduce technological barriers for European AI development. |
| Structural industrial risk | OPEN | Nationality-neutral regulatory framework | Broader data access does not itself reserve resulting economic value, models or IP for European firms. |
Strategic Net Assessment
Europe is not choosing simply between privacy and artificial intelligence. It is designing the legal conditions under which personal data can become an increasingly important factor of AI production while simultaneously deciding whether the complementary assets required to monetise those data — computing infrastructure, models, capital, cloud distribution, industrial deployment and intellectual property — remain under European control. If those complementary capabilities do not expand fast enough, greater lawful availability of European data can strengthen firms that already dominate global AI infrastructure; if Europe successfully connects data policy with EuroHPC compute, domestic model developers, industrial datasets, procurement and investment, the same regulatory reform can become one component of a broader European AI industrial strategy.
Primary and Institutional Sources
- General Data Protection Regulation — EUR-Lex
- COM(2025) 837 — European Commission
- Legislative Procedure 2025/0360/COD — EUR-Lex
- Council Presidency Revised Compromise — 3 September 2026
- EDPB Opinion 28/2024 on AI Models
- EDPB–EDPS Joint Opinion 2/2026
- AI Factories — EuroHPC Joint Undertaking
- European Commission — AI Factories
- UK AI Opportunities Action Plan
- German Federal Data Centre Strategy
Pillar One — The Legal Transformation
The transformation is not the abolition of the GDPR; it is a redistribution of where legal protection sits
The most consequential feature of the Digital Omnibus is not that it would suddenly make personal data available to artificial-intelligence developers without legal constraint, because the GDPR’s architecture of lawfulness, purpose limitation, fairness, proportionality, transparency, security and accountability remains the legal starting point; rather, the transformation lies in the attempt to move AI development from an area in which controllers must establish, case by case and under considerable uncertainty, that legitimate interest can support training or deployment, toward a legislative framework in which the Union itself expressly recognises AI development and operation as activities for which Article 6(1)(f) may provide a lawful basis. The Commission justified the broader Digital Omnibus as an exercise in regulatory simplification intended to reduce compliance burdens while maintaining European fundamental-rights protections, but the European Data Protection Board and European Data Protection Supervisor subsequently warned that simplification must not alter the substantive level of protection or create uncertainty over the GDPR’s scope. European Commission — Simpler digital rules to help EU businesses grow, 19 November 2025 EDPB–EDPS Joint Opinion 2/2026 on the Digital Omnibus
The practical significance therefore lies in legal presumptions, compliance burdens and litigation positions rather than in the formal disappearance of rights. Today, a controller seeking to process personal data for AI training under legitimate interest must construct its justification from Article 6(1)(f), the GDPR principles in Article 5, the rights of individuals, the rules governing sensitive information and the jurisprudence and regulatory interpretation surrounding those provisions. Under the proposed AI-specific provision, the legislature would expressly acknowledge that AI development and operation can constitute a setting in which legitimate interest is available; that does not guarantee that the balancing test is satisfied, but it materially alters the regulatory environment because the dispute can shift from “is this category of processing capable of relying on legitimate interest?” toward “has this particular controller satisfied the conditions for doing so?” The EDPB and EDPS themselves acknowledged in February 2026 that legitimate interest can already apply to AI under existing law, while questioning whether an additional GDPR article was therefore necessary. EDPB–EDPS Joint Opinion 2/2026 — AI and legitimate interest analysis EDPB Opinion 28/2024 on AI models
That difference is legally important because the EDPB and EDPS stated in their Joint Opinion that the Commission’s proposed Article 88c did not actually create the possibility of relying on legitimate interest: that possibility already existed under the GDPR, subject to the normal Article 6(1)(f) conditions. Their concern was therefore partly constitutional and systemic: placing a specific AI legitimate-interest statement in the GDPR’s operative provisions risks being read as giving AI development a special normative status that ordinary commercial processing does not enjoy, even though the text formally preserves the general test. EDPB–EDPS Joint Opinion 2/2026 — paragraphs concerning proposed Article 88c
The legal architecture before and after the proposed reform
| Legal question | GDPR currently in force | Commission proposal, November 2025 | September 2026 Presidency compromise | Practical consequence |
|---|---|---|---|---|
| Can legitimate interest support AI training? | Potentially yes, subject to Article 6(1)(f) | Explicitly stated for AI development and operation | Explicit AI treatment retained in revised form | Greater legislative certainty for controllers |
| Must controller demonstrate a legitimate interest? | Yes | Yes | Yes, through Article 6(1)(f) framework | AI purpose alone does not automatically establish lawfulness |
| Must processing be necessary? | Yes | Yes | Remains inherent in Article 6(1)(f) | Excessive collection can still fail |
| Must individual rights be balanced against controller interests? | Yes | Expressly reiterated in Article 88c | Explicit AI-specific wording substantially reduced; general Article 6 remains | Protection shifts toward general GDPR rather than AI-specific text |
| Children receive heightened protection? | Yes, expressly recognised in Article 6(1)(f) | Specifically reiterated in Article 88c | Specific AI reference removed from operative clause | Underlying GDPR protection remains |
| AI-specific data-minimisation safeguard | General Article 5 principle | Specifically inserted | Removed from operative AI article | General minimisation remains but special reinforcement disappears |
| Enhanced AI transparency | General Articles 12–14 | Specifically identified | Removed from operative AI article | General transparency duties remain |
| Unconditional AI-specific objection right | No | Yes | Removed | Ordinary Article 21 test becomes more important |
| Special-category data | Article 9 prohibition plus exceptions | Targeted derogation proposed for residual AI data | Revised derogation remains part of negotiations | Potentially major change for large-scale datasets |
| Pseudonymised data | Usually remains personal data where person remains identifiable | New contextual treatment proposed | Council moves further toward recipient-relative identifiability | Potential narrowing of GDPR scope for certain recipients |
| Status | Binding law | Legislative proposal | Presidency negotiating text | No proposed reform is yet operative |
Sources: GDPR — Regulation (EU) 2016/679 European Commission proposal COM(2025) 837 final Council Presidency revised compromise ST 12535/26 — official-document record
Article 6(1)(f) remains the central legal gate
Article 6(1)(f) is frequently described as “legitimate interest”, but legally it operates as a three-element cumulative test rather than a general commercial-purpose exception. First, a controller must identify an actual legitimate interest pursued by itself or a third party; second, the processing must be necessary for that interest, meaning the controller must consider whether the objective can reasonably be achieved through a less intrusive means; third, that interest must be balanced against the interests and fundamental rights and freedoms of the data subject. The European Commission’s own GDPR guidance makes clear that a business interest does not automatically prevail and that reliance on legitimate interest fails where the effect on individuals’ rights outweighs the controller’s justification. European Commission — Legal grounds for processing personal data
The EDPB applied precisely this architecture to AI in Opinion 28/2024, distinguishing the existence of an interest from the necessity of the processing and then from the balancing test, while emphasising that the analysis depends on the specific model, dataset, source of data, reasonable expectations of individuals and safeguards implemented by the controller. That case-specific structure is critical because a controller cannot establish necessity merely by asserting that a larger dataset produces a better model; the legal question is whether processing those particular personal data is necessary for the particular legitimate interest being invoked, under the circumstances and with the safeguards available. EDPB Opinion 28/2024 on certain data-protection aspects related to AI models
The Article 6(1)(f) legal test applied to AI
| Stage | Legal question | AI-specific factual inquiry | Evidence a controller would normally need | Failure condition |
|---|---|---|---|---|
| Legitimate interest | Is the objective lawful, sufficiently specific and real? | What exactly is the model being developed or deployed to achieve? | Defined purpose, product documentation, governance records | Vague or unlawful purpose |
| Necessity | Is processing these personal data necessary for that objective? | Could anonymised, synthetic, aggregated or narrower data achieve the objective? | Dataset justification, alternative-data assessment, minimisation measures | Less intrusive viable alternative exists |
| Balancing | Do individual rights override the controller’s interest? | What would individuals reasonably expect, and how intrusive is the processing? | Legitimate-interest assessment, source analysis, impact assessment | Rights and freedoms outweigh commercial interest |
| Safeguards | Can risks be materially reduced? | Can exclusion filters, opt-outs, de-identification or output controls reduce impact? | Technical and organisational measures | Residual impact remains excessive |
| Accountability | Can the controller prove compliance? | Is the decision documented and auditable? | Article 30 records, DPIA where required, governance documentation | Unsupported internal assertion |
Legal basis: GDPR — Article 6 EDPB Opinion 28/2024
The Commission proposal contained an unusually explicit AI safeguard package
The Commission’s November 2025 proposal did considerably more than announce that legitimate interest can apply to AI. Proposed Article 88c expressly stated that AI-related processing could rely on legitimate interest only where the controller’s interest was not overridden by the interests or fundamental rights and freedoms of the data subject, specifically highlighting children, and it preserved situations in which other Union or national law explicitly requires consent. Its second paragraph then identified concrete safeguards including data minimisation during source selection and training or testing, protection against disclosure of residually retained personal information, enhanced transparency and an unconditional right to object to the processing. COM(2025) 837 final — proposed Article 88c
This was legally significant because most of those principles already exist in some form elsewhere in the GDPR, but the Commission proposed to concentrate and strengthen them around AI. That creates a different compliance environment from one in which controllers must reconstruct their obligations from dispersed GDPR provisions. An AI-specific unconditional objection right, in particular, would have been materially stronger than the ordinary Article 21 architecture because Article 21 permits a controller relying on Article 6(1)(f) to continue processing where it demonstrates compelling legitimate grounds overriding the data subject’s interests, rights and freedoms, except in the separate context of direct marketing where the objection is effectively absolute. GDPR — Article 21 right to object
The September compromise removes legal redundancy, but it also removes friction
Council document ST 12535/26, prepared by the General Secretariat of the Council for discussion by the Antici Group on 11 September 2026, is formally a Presidency revised compromise text, not an agreed Council position and not adopted legislation. The official parliamentary repository recording the Council document identifies it as a LIMITE Presidency text linked to interinstitutional file 2025/0360(COD), which is important because commentary describing it as “the EU’s new GDPR rules” would overstate its legal status. Official record of Council document ST 12535/26 — Austrian Parliament EU document repository
The legal direction of travel is nevertheless identifiable. Compared with the Commission proposal, the compromise considerably shortens the AI-specific safeguard architecture. The direct references to children, the express consent carve-out, AI-specific source and training-stage data minimisation, enhanced transparency and the unconditional objection right are no longer organised as explicit obligations in the operative AI article. Some underlying protections continue elsewhere in the GDPR, while some concepts remain in recitals or general safeguards, but that is not legally identical to retaining them in the operative provision itself. Council Presidency revised compromise ST 12535/26 — document record COM(2025) 837 final — Commission baseline text
Commission proposal versus September 2026 Presidency compromise
| Protection or rule | Commission Article 88c | September compromise direction | Existing GDPR backstop | Legal significance |
|---|---|---|---|---|
| AI legitimate interest | Explicit | Explicit/restructured | Article 6(1)(f) | Legislative endorsement remains |
| Rights-balancing language | Expressly repeated | AI-specific repetition reduced | Article 6(1)(f) | Test survives but loses AI-specific emphasis |
| Children | Specifically named | Removed from operative AI clause | Article 6(1)(f), Recital 38 | Protection survives but becomes less visible in AI provision |
| Mandatory consent under other laws | Explicit carve-out | Deleted from AI article | Other applicable Union/national law remains binding | No legal override, but textual reminder disappears |
| Data minimisation during source selection | Express AI safeguard | Deleted from operative AI clause | Article 5(1)(c), Article 25 | General duty remains |
| Training/testing minimisation | Express AI safeguard | Deleted | Articles 5 and 25 | Reduced AI specificity |
| Enhanced transparency | Express | Deleted | Articles 12–14 | Baseline transparency remains |
| Residual-data output protection | Express | Reconfigured through other safeguards | Security/accountability duties | Depends more heavily on implementation |
| Unconditional objection | Express | Deleted | Article 21 | Material reduction relative to Commission proposal |
| Technical/organisational measures | Express | Retained in more general form | Articles 24, 25, 32 | Remains central |
Sources: European Commission COM(2025) 837 Council document ST 12535/26 record
Why removing an “unconditional” objection matters more than removing the word transparency
Not every deletion has the same substantive effect. Removing an explicit reference to transparency or data minimisation does not remove those obligations from the GDPR, because Articles 5, 12, 13, 14, 24 and 25 continue independently to regulate fairness, information duties, accountability and privacy by design. Removing the Commission’s proposed unconditional AI-specific right to object, however, changes the proposed legal position more materially because ordinary Article 21 does not establish an absolute objection right for all legitimate-interest processing. GDPR — Articles 5, 12–14, 21, 24 and 25
Under Article 21(1), an individual can object to processing based on Article 6(1)(e) or (f) on grounds relating to his or her particular situation; the controller must then stop unless it demonstrates compelling legitimate grounds that override the interests, rights and freedoms of the individual or establishes that processing is necessary for legal claims. The Commission’s proposed unconditional AI objection would therefore have shifted control substantially toward the data subject by removing that override mechanism for the relevant processing, whereas the Council compromise returns the issue largely to the general balancing framework. GDPR — Article 21
Objection rights under the competing architectures
| Scenario | Ordinary GDPR | Commission Article 88c | September compromise if retained substantially as drafted |
|---|---|---|---|
| Person objects to AI training based on legitimate interest | Controller generally must stop unless compelling overriding grounds exist | AI-specific objection proposed as unconditional | Ordinary Article 21 becomes central again |
| Direct marketing | Objection effectively absolute | Existing rule unchanged | Existing rule unchanged |
| Individual gives consent then withdraws | Withdrawal governed by consent rules | Consent cases preserved separately | Other consent requirements remain applicable |
| Data obtained indirectly | Article 14 transparency normally relevant, subject to exceptions | Enhanced AI transparency contemplated | General Article 14 architecture remains |
| Child data | Article 6 balancing gives special importance to children | Explicit AI reference | General protection survives without AI-specific repetition |
Source: GDPR — Article 21 and related provisions
Data minimisation does not disappear, but AI exposes its most difficult interpretation
Article 5(1)(c) requires personal data to be adequate, relevant and limited to what is necessary in relation to the purposes for which they are processed, while Article 25 requires controllers to implement data protection by design and by default. Those requirements remain binding regardless of whether the Digital Omnibus retains a special AI-specific minimisation paragraph. The legal difficulty is that contemporary model development often benefits empirically from dataset scale, while GDPR necessity is not equivalent to engineering usefulness: a claim that “more data improves performance” does not by itself establish that processing every available personal record is legally necessary. GDPR — Regulation (EU) 2016/679
That distinction creates one of the central future enforcement disputes. A developer could plausibly demonstrate that large and heterogeneous datasets improve robustness, linguistic coverage or model safety, yet regulators may still ask whether personal identifiers, metadata, historic messages, location traces or other specific categories needed to be retained, whether equivalent results could be achieved through anonymisation or filtering, and whether the source universe itself was overbroad. The EDPB’s AI opinion places safeguards, reasonable expectations, data source and the necessity test inside the legitimate-interest assessment, meaning that minimisation remains legally relevant even if it disappears from the new AI article’s explicit wording. EDPB Opinion 28/2024 on AI models
Publicly accessible data do not automatically become free AI training material
A frequent misconception is that information appearing on a publicly accessible website, social network, forum, professional profile or publication has ceased to enjoy GDPR protection. That proposition is legally incorrect: public accessibility does not, on its own, remove data from the definition of personal data or eliminate the need for an Article 6 legal basis, and where special-category information is concerned, the threshold is higher still. The EDPB has specifically recalled that Article 9(2)(e), which permits processing of special-category data manifestly made public by the data subject, requires evidence that the individual intended, explicitly and by a clear affirmative action, to make that information accessible to the general public. EDPB Opinion 28/2024 — treatment of special-category and publicly available information
This matters directly for web scraping and foundation-model training because a dataset can contain ordinary personal information, inferred characteristics and Article 9 special categories simultaneously. The EDPB reiterated in 2026 guidance concerning generative-AI web scraping that where special-category data are involved, controllers require both an Article 6 legal basis and an applicable Article 9(2) exception, and it expressly rejected the existence of a general Article 9 exemption merely because data collection is undertaken for AI. EDPB — Anonymisation and web scraping for generative AI, 2026
Special-category data are where the Digital Omnibus could alter the legal equation most sharply
Article 9 of the GDPR starts from a prohibition on processing data revealing racial or ethnic origin, political opinions, religious or philosophical beliefs, trade-union membership, genetic data, qualifying biometric data, health data and information concerning sex life or sexual orientation, unless one of the Article 9(2) derogations applies. This is a different architecture from ordinary Article 6 processing because establishing legitimate interest under Article 6(1)(f) is not sufficient by itself when Article 9 data are involved. GDPR — Article 9 special categories of personal data
The Commission’s proposal therefore addressed a genuine technical problem confronting large-scale AI development: enormous corpora can contain special-category information incidentally or residually, even where the developer has not selected the dataset for the purpose of processing health, religion, politics or similar attributes. The EDPB and EDPS accepted that a targeted derogation could be justified for incidental and residual special-category processing in AI systems, but they requested clearer limits and safeguards extending through the entire AI lifecycle. EDPB–EDPS Joint Opinion 2/2026 — special-category data and AI
The legal distinction between intentional processing and residual presence therefore becomes decisive. A developer intentionally assembling political-affiliation profiles to train a political targeting system presents a fundamentally different Article 9 problem from a general-language corpus that inadvertently contains a newspaper interview revealing a person’s political belief or a forum entry mentioning a medical diagnosis. Any final derogation will need to maintain that distinction clearly because otherwise a technical exception designed to deal with contamination in very large datasets could evolve into a substantive legal route for processing sensitive information at scale. EDPB Opinion 28/2024 — special-category data considerations
Special-category information: legal treatment by use case
| Data situation | Article 6 basis required? | Article 9 condition required under current GDPR? | Digital Omnibus relevance | Principal legal issue |
|---|---|---|---|---|
| Ordinary public social-media post containing name and opinion on a product | Yes | Normally no | Legitimate-interest AI provision potentially relevant | Necessity and balancing |
| Public post revealing political beliefs | Yes | Yes | Residual-data derogation could become relevant only under defined conditions | Whether data were manifestly made public and purpose of processing |
| Medical discussion scraped from a forum | Yes | Yes | Highly sensitive example for residual-processing regime | Article 9 prohibition and reasonable expectations |
| Facial image used simply as ordinary image content | Yes | Depends on biometric processing purpose | Proposed rules do not eliminate distinction | Whether processed for unique identification |
| Facial template used to identify individuals | Yes | Yes | Heightened protection remains | Biometric special-category processing |
| Training corpus accidentally containing sensitive records | Yes | Currently Article 9 remains applicable | Proposed residual-data derogation directly relevant | Effectiveness of filtering and containment |
| Dataset intentionally constructed around sensitive traits | Yes | Yes | Residual exception should not convert into general authorisation | Purpose and intentionality |
Sources: GDPR — Articles 6 and 9 EDPB AI Opinion 28/2024
The jurisprudence already places strict limits on mixed datasets containing sensitive information
The EDPB’s 2024 AI opinion points directly to the Court of Justice’s judgment in Meta Platforms v Bundeskartellamt, C-252/21, in which the Court addressed sets containing both sensitive and non-sensitive information and clarified that where such information is collected together and cannot be separated at the point of collection, the Article 9 regime cannot simply be ignored because sensitive elements constitute only part of the dataset. The Board therefore warned that AI developers handling datasets containing special-category information must account for Article 9 independently of ordinary Article 6 lawfulness. EDPB Opinion 28/2024 — discussion of C-252/21 Court of Justice — Case C-252/21, Meta Platforms v Bundeskartellamt
That jurisprudence explains why the Digital Omnibus special-category derogation matters commercially. Large-model developers cannot realistically guarantee that billions or trillions of training elements are entirely free from medical, political, religious or biometric information, particularly where datasets originate from the open web or historical platform repositories; a narrowly designed residual-processing exception could therefore remove a potentially serious source of legal exposure, although its scope and accompanying safeguards will determine whether it functions as a technical safety valve or a broader deregulatory mechanism. EDPB–EDPS Joint Opinion 2/2026
Pseudonymisation may be the reform with the largest implications beyond AI
The proposed treatment of pseudonymised data deserves separate attention because it affects the perimeter of the GDPR itself rather than merely the legal basis used for processing. Under the current Regulation, pseudonymisation is defined as processing personal data so that they cannot be attributed to a specific data subject without additional information, provided that the additional information is kept separately and subject to safeguards; critically, pseudonymised information generally remains personal data where the individual remains identifiable by means reasonably likely to be used. GDPR — Article 4 and Recital 26
The Digital Omnibus seeks greater legal clarity over circumstances in which information that remains identifiable to one actor may effectively be non-personal for another actor that lacks realistic means of re-identification. That appears technical, but economically it could determine whether entire datasets transferred between companies, research organisations, model developers, cloud providers and data intermediaries remain subject to the full GDPR. The EDPB and EDPS warned that changing the treatment of pseudonymised information risks producing fragmented status, in which the same dataset is personal data for one organisation and non-personal for another, thereby complicating accountability and potentially reducing protection during downstream transfers. EDPB–EDPS Joint Opinion 2/2026 — definition of personal data and pseudonymisation
The September Council compromise pushes further toward an actor-relative approach to identifiability, under which the practical ability of the specific recipient to identify a person becomes highly important. The legal attraction is obvious: a model developer receiving strongly pseudonymised records without access to the re-identification key might face less regulatory burden than the hospital, platform, bank or public authority that generated the records and retains the additional information. The regulatory danger is equally clear: governance would need to ensure that contractual structures, affiliated companies, data brokers or technically accessible auxiliary datasets cannot be used to manufacture a nominal separation that does not reflect real-world identification capability. Council Presidency revised compromise ST 12535/26 — official document record EDPB–EDPS Joint Opinion 2/2026
Personal, pseudonymised and anonymous information under the emerging architecture
| Data state | Re-identification possibility | Current GDPR position | Strategic consequence of proposed reform |
|---|---|---|---|
| Directly identified data | Identity explicit | Personal data | Full GDPR applies |
| Coded data with controller holding re-identification key | Identification straightforward | Personal data | No material change expected |
| Strongly pseudonymised dataset transferred without key | Recipient lacks direct means but another party can identify | Normally still potentially personal under current contextual analysis | Reform may make recipient-specific status more important |
| Dataset requiring unreasonable resources to identify individuals | Identification not reasonably likely | May be effectively anonymous depending on circumstances | Greater legal certainty could expand reuse |
| Irreversibly anonymised dataset | Individual no longer identifiable by reasonably likely means | Outside GDPR | Remains outside GDPR |
| Model parameters derived from personal data | Status depends on whether information relating to identifiable persons can be extracted or inferred | Case-specific | Increasingly important for model governance |
Sources: GDPR — definitions and Recital 26 EDPB Opinion 28/2024 — anonymity of AI models
An AI model is not automatically anonymous merely because training data are no longer visible as records
The EDPB’s Opinion 28/2024 makes this distinction explicit: whether an AI model can be considered anonymous must be assessed case by case, and supervisory authorities should evaluate both the probability that personal information relating to individuals whose data were used for training can be extracted from the model and the probability that the model enables personal data to be obtained through queries. A developer therefore cannot simply argue that raw training rows have been transformed into numerical parameters and conclude that the resulting model is automatically outside the GDPR. EDPB Opinion 28/2024 — anonymity and AI models
This matters because the economic objective of foundation-model developers is frequently to separate the legal treatment of the training corpus from the legal treatment of the resulting model. If the model can genuinely be shown not to contain or enable the extraction of information relating to identifiable persons, downstream deployment may face a very different GDPR analysis from the original training activity; if memorisation, extraction, membership inference or other techniques make personal information practically recoverable, the model itself can remain within the data-protection problem. EDPB Opinion 28/2024
Historical platform data create a second legal problem: purpose compatibility
Even where legitimate interest supplies a lawful basis for new AI processing, controllers cannot necessarily ignore the purpose for which information was initially collected. Article 5(1)(b) establishes the purpose-limitation principle, while Article 6(4) sets criteria relevant to assessing whether further processing for a new purpose is compatible with the purpose for which the data were originally obtained, including links between purposes, context of collection, nature of the data, consequences for individuals and safeguards. The EDPB specifically identified compatibility of purposes as a provision that may be highly relevant to AI-model development and deployment. GDPR — Articles 5 and 6 EDPB Opinion 28/2024 — provisions relevant beyond the immediate opinion questions
This is particularly important for legacy archives. A platform may hold photographs, private or semi-private posts, search histories, account metadata, purchase records or interactions collected years before generative AI existed in its present commercial form. Even where those data remain technically available and a controller can articulate a commercial interest in model development, the historic collection context and reasonable expectations of individuals become material to both purpose compatibility and the Article 6(1)(f) balancing assessment. The legal value of a twenty-year archive is therefore not equivalent to unrestricted economic ownership of that archive for every subsequent computational purpose. EDPB Opinion 28/2024 on AI models and legitimate interest
Legacy-data legality matrix
| Original data context | New AI use | Core legal issue | Relative legal complexity |
|---|---|---|---|
| Public professional profile | General model training | Reasonable expectations, necessity, transparency | Significant |
| Public social-media post | Foundation-model training | Legitimate interest, objection, compatibility | Significant |
| Private direct message | Foundation-model training | Expectations, confidentiality, necessity, fairness | Very high |
| Purchase history | Recommendation-model improvement | Relationship to original service and user expectations | Medium to high |
| Medical account records | General AI training | Article 9 plus sector-specific confidentiality | Very high |
| Archived child account data | Model development years later | Heightened balancing and age-related protection | Very high |
| Corporate customer support chats | Product-specific assistant | Contractual context, compatibility, confidentiality | Context dependent |
| Truly anonymous aggregate statistics | Model development | GDPR may not apply | Lower GDPR exposure |
Legal framework: GDPR — Regulation (EU) 2016/679 EDPB Opinion 28/2024
Children remain protected even if the Council deletes their explicit mention from the AI clause
The deletion of the Commission proposal’s express reference to children should not be interpreted as removing their elevated protection from European data-protection law. Article 6(1)(f) itself identifies situations involving children as requiring particular attention, while GDPR Recital 38 states that children merit specific protection because they may be less aware of risks, consequences, safeguards and rights associated with personal-data processing. GDPR — Article 6 and Recital 38
The material change is therefore one of regulatory signalling and evidentiary burden, rather than total legal removal. An AI-specific provision explicitly naming children makes it harder for controllers and courts to treat youth-related datasets as an ordinary balancing exercise; moving the protection back into the horizontal GDPR architecture preserves the substantive principle while eliminating the additional AI-specific instruction. For services with large historical populations of teenage or child users, that distinction may become important when legitimate-interest assessments are challenged. European Commission proposal COM(2025) 837 — Article 88c
Transparency will become more difficult, not less important
General GDPR transparency requirements remain in Articles 12, 13 and 14, including duties concerning the identity of the controller, purposes, legal basis, legitimate interests where relevant, recipients, retention and individual rights. The difficulty for large-scale AI development lies in applying these requirements to information obtained indirectly from distributed sources, potentially involving very large numbers of people with whom the model developer has no direct customer relationship. GDPR — Articles 12, 13 and 14
The Commission’s proposed “enhanced transparency” language therefore addressed a structural problem rather than simply repeating existing law: traditional privacy notices were designed principally around identifiable relationships between a controller and users, customers or employees, whereas foundation-model training can involve billions of data elements obtained through crawling, licensing, acquisition or historical repositories. Removing the explicit AI requirement does not solve that tension; it leaves controllers more dependent on general Article 14 rules and their exceptions, regulatory guidance and future case law. COM(2025) 837 final — proposed Article 88c
Automated decision-making remains a separate legal layer
The proposed AI legitimate-interest rule does not displace Article 22 or other protections governing automated decisions. An organisation might lawfully train or deploy an AI model under Article 6(1)(f) yet still face separate restrictions if that system subsequently makes decisions producing legal effects or similarly significant effects on identifiable individuals. The Commission’s public GDPR guidance emphasises that qualifying automated decision-making is authorised only under specified conditions and must include suitable safeguards, including information about the processing and, where applicable, possibilities for human intervention and contestation. European Commission — Automated decision-making and individual rights
This separation is essential because training legality and deployment legality are not the same inquiry. A dataset may have been processed lawfully for model development, while a particular downstream use in credit assessment, employment, insurance, healthcare, policing or eligibility determinations triggers additional GDPR, AI Act, sector-specific and fundamental-rights constraints. Conversely, illegality during model development may contaminate subsequent deployment even where the final application would otherwise be permissible. The EDPB’s AI opinion expressly considered the consequences of models developed using unlawfully processed personal data and rejected the idea that deployment automatically cures defects originating at the development stage. EDPB Opinion 28/2024 — development and deployment of AI models
Data protection impact assessments remain a critical enforcement mechanism
Article 35 requires a Data Protection Impact Assessment where processing is likely to result in a high risk to individuals’ rights and freedoms, particularly where new technologies are used in circumstances involving systematic and extensive evaluation, large-scale processing of special-category data or systematic monitoring. The EDPB has explicitly reminded controllers that DPIAs remain highly relevant to AI models, meaning the Digital Omnibus does not convert legitimate interest into an exemption from ex ante risk analysis. GDPR — Article 35 EDPB Opinion 28/2024 — DPIAs and AI models
For large AI developers this may become one of the principal points where abstract legislative permission is converted into operational obligation. A DPIA can require the controller to describe processing operations, assess necessity and proportionality, examine risks to individuals and document measures intended to address those risks; where residual high risk remains and cannot be mitigated, Article 36 can require prior consultation with the supervisory authority. GDPR — Articles 35 and 36
Compliance architecture that would remain after the reform
| GDPR mechanism | Would Digital Omnibus eliminate it? | Relevance to AI |
|---|---|---|
| Article 5 principles | No | Purpose limitation, minimisation, accuracy, storage limitation, security, accountability |
| Article 6 lawful basis | No | Core legality of ordinary personal-data processing |
| Article 9 sensitive-data rules | Modified in defined AI circumstances, not abolished | Critical for health, politics, religion, biometrics and similar information |
| Articles 12–14 transparency | No | Particularly difficult for scraped and indirectly obtained data |
| Article 15 access | No | Individuals may seek information about their data |
| Article 16 rectification | No | Relevant where inaccurate personal information is processed |
| Article 17 erasure | No | Complex interaction with trained models |
| Article 18 restriction | No | Can constrain further processing |
| Article 21 objection | No | Becomes more significant if unconditional AI right disappears |
| Article 22 automated decisions | No | Applies separately to qualifying deployment decisions |
| Articles 24–25 accountability/privacy by design | No | Governance, architecture and minimisation |
| Article 30 processing records | No | Internal audit trail |
| Articles 32–34 security/breach regime | No | Applies to personal-data security |
| Article 35 DPIA | No | High-risk AI data processing may require assessment |
| Chapter V international transfers | No | Relevant where training infrastructure or processors are outside EEA |
Source: Full text of Regulation (EU) 2016/679 — EUR-Lex
International transfers remain a separate strategic constraint
Nothing in an AI-specific legitimate-interest provision would abolish the GDPR’s Chapter V international-transfer regime. Where personal data subject to the GDPR are transferred to third countries or accessed through qualifying cross-border arrangements, controllers and processors must still rely on an applicable transfer mechanism such as an adequacy decision, appropriate safeguards or another lawful route under the Regulation. This means that greater permission to process personal data for AI within Europe does not automatically authorise unrestricted export of those data to foreign training infrastructure. GDPR — Chapter V transfers of personal data to third countries
This separation is strategically significant because legal access to European data and geographic control over the processing infrastructure are two different questions. A US-headquartered AI provider can potentially benefit from an EU lawful basis while still having to comply with transfer requirements where relevant, while a European developer can rely on European infrastructure and reduce some cross-border complexity; consequently, the final reform will interact with, rather than replace, the EU’s broader sovereignty concerns over cloud infrastructure, model hosting and international data flows. European Commission — GDPR framework for international data transfers
The burden of proof remains with the controller
A central feature of the GDPR is the principle of accountability: Article 5(2) requires the controller to be responsible for, and able to demonstrate, compliance with the Regulation’s principles. An AI company therefore cannot rely on the existence of Article 88 bis or an equivalent final provision as sufficient legal documentation; it would still need to show why the interest exists, why the processing is necessary, why individual interests do not override it, what safeguards were implemented, what data were used, how special-category information was handled and how individual rights can practically be exercised. GDPR — Article 5 accountability principle
The operational consequence is that the strongest firms may gain not only because they possess more data, but because they possess greater capacity to document compliance at industrial scale through privacy engineering, automated exclusion systems, governance teams, model-evaluation tooling, legal departments and regulatory engagement. Regulatory simplification can therefore reduce barriers for European challengers while simultaneously rewarding organisations capable of turning complex legal requirements into repeatable infrastructure. That distributional effect cannot be determined from the text of Article 88 bis alone, but it is a direct institutional consequence of a compliance regime that remains heavily dependent on controller documentation and risk management. European Commission — GDPR information for businesses and organisations
What a controller would still need to establish before using legacy European data for AI
| Compliance question | Required analytical demonstration | Why it matters |
|---|---|---|
| What is the precise AI purpose? | Defined development or deployment purpose | Prevents open-ended reuse |
| What legitimate interest is pursued? | Concrete, lawful and present interest | Article 6(1)(f) first limb |
| Why are personal data necessary? | Comparison with less intrusive alternatives | Necessity limb |
| Why this quantity of data? | Dataset proportionality and minimisation | Article 5 |
| What did individuals reasonably expect? | Original context, relationship, publicity and age | Balancing test |
| Does dataset contain Article 9 information? | Detection and classification process | Sensitive-data legality |
| Are children represented? | Age-related risk analysis | Heightened protection |
| Were data obtained directly or indirectly? | Source mapping | Articles 13–14 |
| Can people object effectively? | Operational objection mechanism | Article 21 |
| Can records be deleted or restricted? | Data lineage and model-governance mechanisms | Articles 17–18 |
| Is pseudonymisation sufficient? | Re-identification assessment | GDPR scope |
| Can model reveal memorised personal information? | Extraction and inference testing | Model anonymity |
| Is a DPIA required? | Risk threshold assessment | Article 35 |
| Are international transfers involved? | Infrastructure and processor mapping | Chapter V |
| Can compliance be demonstrated later? | Audit logs, records, governance documentation | Article 5(2) |
Sources: GDPR — EUR-Lex EDPB Opinion 28/2024
The regulatory significance of the reform is therefore asymmetrical
For controllers, the proposed reform offers greater legislative recognition, potentially clearer treatment of residual sensitive information and a more commercially usable framework for pseudonymised datasets; for data subjects, however, several protections that the Commission initially proposed to place explicitly next to AI processing are being moved back into the general GDPR architecture or weakened as AI-specific rights. That asymmetry explains why the Council text can simultaneously preserve the GDPR formally while still producing a meaningful deregulatory effect in practice. Commission proposal COM(2025) 837 Council Presidency document ST 12535/26 record
The EDPB and EDPS position is particularly revealing because the regulators did not argue that legitimate interest must never support AI. They explicitly accepted that it can already do so under current law. Their concern instead focuses on whether rewriting the GDPR produces genuine legal certainty without reducing protection, whether sensitive-data derogations remain sufficiently narrow and whether changes to pseudonymisation alter the practical perimeter of the Regulation. That makes the dispute less a confrontation between “AI innovation” and “privacy prohibition” than a disagreement over how much legal uncertainty and individual control Europe is willing to remove in order to lower the transaction costs of AI development. EDPB–EDPS Joint Opinion 2/2026
Legal-risk hierarchy after a reform broadly resembling the September compromise
| AI data use | Principal governing provisions | Regulatory pressure | Why |
|---|---|---|---|
| Fully anonymous statistical data | GDPR potentially outside scope | Lower | No identifiable natural person where anonymity is genuine |
| Strongly pseudonymised industrial dataset | Articles 4/25 and proposed pseudonymisation rules | Context dependent | Recipient identifiability becomes decisive |
| Existing customer data used to improve directly related AI service | Articles 5, 6, 13/14, 21 | Moderate | Stronger relationship and expectations may support balance |
| Public web content for general model training | Articles 5, 6, 14, 21 | Significant | Massive scale, indirect collection and expectations |
| Historic platform archives reused for unrelated foundation model | Articles 5, 6, 14, 21 | High | Purpose compatibility and reasonable expectations |
| Children’s historic content | Articles 5, 6 and heightened child protection | High | Enhanced rights-balancing |
| Dataset containing incidental Article 9 data | Articles 6, 9 plus proposed residual derogation | High but potentially reduced by reform | Final derogation will be decisive |
| Intentional sensitive-data training | Articles 6 and 9 | Very high | Residual exception should not function as general authorisation |
| AI making consequential individual decisions | Articles 6, 22 plus AI Act/sectoral rules | Very high | Training and deployment legality accumulate |
| Data transferred outside EEA | Chapter V in addition to underlying lawful basis | Context dependent | Separate transfer legality required |
Framework: GDPR — Regulation (EU) 2016/679 EDPB Opinion 28/2024
What the September compromise actually changes in the balance of power
The deepest transformation is therefore institutional rather than semantic. Under the current GDPR, AI developers already possess a potential legitimate-interest route, but they must navigate a regulatory environment in which that route was created before contemporary foundation models and must be reconstructed through principles, case law and supervisory interpretation. The Commission attempted to codify that possibility while attaching an explicit package of AI-specific safeguards. The September Council compromise moves toward retaining the codified permission while reducing the dedicated safeguards surrounding it, thereby making the general GDPR perform more of the protective work. COM(2025) 837 final — European Commission ST 12535/26 — Presidency revised compromise record
That creates a subtle but important shift in litigation. Instead of a data subject being able to point directly to an AI-specific statutory prohibition or unconditional right inside the new article, disputes increasingly return to necessity, expectations, proportionality, Article 9 status, transparency, Article 21 balancing, privacy by design and accountability. The protections remain substantial, but they are procedurally more contestable and fact-intensive, and that matters enormously for organisations capable of sustaining long regulatory and judicial disputes. GDPR — operative legal framework
What remains unresolved as of 26 September 2026
The first unresolved issue is the final wording of the AI article itself. ST 12535/26 is a Presidency compromise prepared for Council negotiations and cannot be treated as the final Council mandate or Union legislation. The legislative file remains 2025/0360(COD), meaning that Council negotiations, the European Parliament position and eventual interinstitutional negotiations can still materially alter the text. European legislative procedure 2025/0360/COD — EUR-Lex Official record of Council compromise ST 12535/26
The second unresolved issue is the precise residual-sensitive-data derogation, particularly how technical impossibility and disproportionate effort will be defined, how aggressively developers must filter datasets before training, what constitutes effective suppression of sensitive information inside a trained model and how regulators will distinguish genuine incidental presence from business models that deliberately tolerate sensitive content because filtering is expensive. The EDPB and EDPS have expressly called for lifecycle-wide safeguards and greater precision. EDPB–EDPS Digital Omnibus assessment, 2026
The third unresolved issue is pseudonymisation and actor-relative identifiability, which may ultimately have greater commercial consequences than Article 88 bis itself because it determines when the GDPR applies at all. A narrow AI legitimate-interest provision changes the rules governing one processing purpose; a broader change to the definition or treatment of personal data affects research, advertising, cloud services, healthcare analytics, financial data, industrial data spaces and numerous other sectors simultaneously. EDPB–EDPS Joint Opinion 2/2026 — personal-data definition and pseudonymisation
The fourth unresolved issue is jurisprudence. Even after adoption, the decisive boundaries will ultimately be determined through supervisory decisions and potentially the Court of Justice of the European Union, particularly around necessity, expectations, historic-data reuse, Article 9 residual data, model anonymity and the interaction between AI-specific provisions and fundamental rights under Articles 7 and 8 of the Charter. No legislative simplification can remove that judicial layer from the European legal order. Court of Justice of the European Union — case-law portal
Key judgments
The proposed Digital Omnibus does not eliminate the GDPR or convert European personal data into automatically available AI training material. Article 6(1)(f), the Article 5 principles, Article 9 protection of sensitive information, Article 21 objection rights, transparency duties, privacy by design, DPIAs, accountability and international-transfer rules continue to create independent legal obligations. GDPR — Regulation (EU) 2016/679
The Commission’s November 2025 proposal represented a legal bargain: explicit recognition of legitimate interest for AI was paired with unusually explicit safeguards covering children, mandatory-consent situations, minimisation, enhanced transparency and an unconditional AI-specific objection right. COM(2025) 837 final — proposed Article 88c
The September 2026 Presidency compromise changes that bargain. It does not necessarily abolish the underlying protections, because many continue elsewhere in the GDPR, but it removes or reduces several safeguards from the AI-specific operative text and therefore shifts more of the protection back toward general GDPR principles, supervisory interpretation and litigation. Council Presidency revised compromise ST 12535/26 — official record
The removal of the unconditional AI objection is one of the most substantive differences, because ordinary Article 21 legitimate-interest objections can be overcome by compelling legitimate grounds, whereas the Commission proposal would have granted a stronger AI-specific control to individuals. GDPR — Article 21
The treatment of residual special-category information could materially reduce legal uncertainty for large-model developers, but the distinction between incidental presence and deliberate exploitation of sensitive information will determine whether the mechanism remains a narrow technical exception or becomes a broader substantive change to Article 9 protection. EDPB–EDPS Joint Opinion 2/2026
The pseudonymisation provisions may ultimately be more structurally important than the AI article itself, because changing when a recipient must regard pseudonymised information as personal data changes the GDPR’s perimeter rather than merely changing the legal basis for one class of processing. EDPB–EDPS Joint Opinion 2/2026
The legal transformation should therefore be understood as a transfer of regulatory weight rather than the disappearance of regulation: away from bespoke AI restrictions written directly into Article 88c/88 bis, and toward horizontal GDPR duties, controller accountability, supervisory enforcement and eventual judicial interpretation. That architecture provides AI developers with greater room to argue that processing is lawful, but it does not predetermine whether those arguments will succeed in any particular case. EDPB Opinion 28/2024 on AI models
What would change the assessment
A final Council mandate restoring an unconditional AI objection right, explicit child protection, strengthened minimisation obligations or a narrow special-category derogation would move the final instrument closer to the Commission’s original permission-plus-safeguards architecture; conversely, further narrowing of Article 9 restrictions, broader recipient-relative treatment of pseudonymised information or additional limitations on data-subject rights would produce a materially deeper restructuring of the GDPR than the September compromise currently establishes. The next decisive records are therefore the subsequent Council compromise texts, the formal Council negotiating mandate, the European Parliament’s final position and any eventual trilogue agreement under 2025/0360(COD). Legislative procedure 2025/0360/COD — EUR-Lex
Open official record
The principal unresolved official records are the final Council general approach or negotiating mandate, the European Parliament’s adopted negotiating text, the eventual consolidated trilogue compromise, the final wording of the special-category-data derogation and pseudonymisation provisions, and any post-adoption EDPB guidance explaining how Article 6(1)(f), Article 9, Article 21 and the new AI provision interact in operational practice. Until those instruments exist, the September document should be treated as an important indicator of negotiating direction rather than as the definitive future GDPR. Council document ST 12535/26 — official-document record EDPB legal-basis materials and AI guidance
GDPR, AI and the Redistribution of Legal Protection
The Digital Omnibus does not abolish the GDPR. Its legal significance lies in moving artificial-intelligence development toward an expressly recognised legitimate-interest framework while reducing several AI-specific safeguards originally proposed by the European Commission and returning more of the protective burden to the general GDPR architecture.
What is actually changing
AI receives explicit legislative recognition
Legitimate interest already exists under Article 6(1)(f), but the reform would expressly identify AI development and operation as activities capable of relying upon it, subject to the remaining GDPR tests.
Protection shifts back to the horizontal GDPR
Several protections specifically written around AI in the Commission proposal are shortened or removed from the operative AI article in the September Presidency compromise, although many continue elsewhere in the GDPR.
Pseudonymisation may alter the regulatory perimeter
The proposed recipient-relative approach to identifiability could affect whether certain pseudonymised datasets remain personal data for particular downstream organisations, with consequences extending far beyond AI.
The Article 6(1)(f) legal gate
Legitimate Interest
The controller must identify a genuine, present and lawful interest rather than relying on a generic claim that AI development is commercially useful.
Necessity
Processing the relevant personal data must be necessary for the stated objective, including consideration of narrower, anonymised, synthetic or otherwise less intrusive alternatives.
Balancing
The controller’s interests must not override the interests, rights and freedoms of the individual, taking account of context, expectations, sensitivity, age and safeguards.
How the legal architecture moves
Commission proposal versus September 2026 compromise
| Legal element | GDPR now | Commission proposal | September 2026 compromise | Operational consequence |
|---|---|---|---|---|
| AI reliance on legitimate interest | AVAILABLE Case-specific under Article 6(1)(f) |
Explicitly recognised | Explicit AI treatment retained | Greater statutory certainty for controllers |
| Legitimate purpose | Required | Required | Required through Article 6(1)(f) | No automatic lawful basis simply because AI is involved |
| Necessity | Required | Required | Remains inherent in Article 6(1)(f) | Excessive collection remains challengeable |
| Rights balancing | Mandatory | Expressly repeated in AI article | AI-specific repetition reduced | General GDPR performs more of the protective work |
| Children | Heightened protection | Explicitly named | Specific AI reference removed | Protection remains but loses dedicated AI emphasis |
| AI-specific minimisation | General Article 5 principle | Expressly reinforced | Removed from operative AI text | General Article 5 and Article 25 remain |
| Enhanced AI transparency | Articles 12–14 | Explicit AI safeguard | Removed from operative article | Transparency survives, but without dedicated AI wording |
| Unconditional AI objection | Not generally available | PROPOSED | REMOVED | Ordinary Article 21 balancing becomes central again |
| Special-category data | Article 9 prohibition plus exemptions | Residual AI derogation proposed | Residual derogation remains under negotiation | Potentially major issue for large training corpora |
| Pseudonymisation | Normally remains personal data if identification remains reasonably possible | Contextual clarification | Greater emphasis on recipient-specific identifiability | Could narrow GDPR scope for specific downstream actors |
Why the objection right matters
Commission model
- AI-specific objection proposed as unconditional.
- The data subject would possess a stronger direct procedural control.
- The controller would not rely on the ordinary Article 21 override architecture for this AI-specific objection.
September compromise direction
- The unconditional AI-specific objection is removed.
- Ordinary Article 21 becomes the principal legal mechanism.
- A controller may continue processing where compelling legitimate grounds override the individual’s interests, rights and freedoms.
Objection-right matrix
| Situation | Current GDPR | Commission 2025 model | September 2026 direction |
|---|---|---|---|
| AI training based on legitimate interest | Article 21 objection subject to controller override where compelling grounds exist | Unconditional AI-specific objection contemplated | Ordinary Article 21 architecture again becomes decisive |
| Direct marketing | Objection effectively absolute | Unchanged | Unchanged |
| Consent-based processing | Consent may be withdrawn | Consent-dependent legal regimes expressly preserved | Other applicable consent requirements continue independently |
| Child data | Special weight in balancing | Explicit AI-specific reference | General child-protection architecture remains |
Special-category data: where the reform is most legally sensitive
Baseline prohibition
Health, political opinions, religion, ethnic origin, biometric identification, genetics, trade-union membership and related categories receive special protection.
Residual contamination
Very large datasets can contain sensitive information incidentally even where a developer did not intentionally collect the corpus for that purpose.
Residual-data derogation
The reform attempts to create a controlled legal route for accidental and residual sensitive information subject to technical and organisational safeguards.
Incidental is not intentional
A technical exception for residual presence should not become a general legal basis for deliberately constructing sensitive-data training datasets.
Special-category use-case matrix
| Dataset situation | Article 6 basis? | Article 9 condition? | Digital Omnibus relevance | Key issue |
|---|---|---|---|---|
| Ordinary public consumer post | Yes | Normally no | Article 6(1)(f) AI route potentially relevant | Necessity, expectations and balancing |
| Public statement revealing political opinion | Yes | Yes | Residual derogation only if conditions genuinely apply | Manifestly public threshold and processing purpose |
| Online medical discussion | Yes | Yes | Highly sensitive test case | Article 9 plus expectations and transparency |
| Training corpus accidentally containing health or political data | Yes | Yes under current law | DIRECTLY RELEVANT | Filtering, technical impossibility and residual influence |
| Dataset intentionally built around sensitive traits | Yes | Yes | Residual exception should not operate as general authorisation | Intentionality and legal purpose |
Pseudonymisation: the possible perimeter shift
Data-state comparison
| Data state | Identification potential | Current GDPR treatment | Strategic effect of reform |
|---|---|---|---|
| Directly identified records | Immediate | Personal data | No material narrowing expected |
| Coded data where controller holds the key | Readily reversible | Personal data | Little practical change |
| Strongly pseudonymised dataset transferred without key | Recipient-specific capability uncertain | Often remains personal data under contextual analysis | Recipient-relative status may become more important |
| Information requiring unreasonable means to identify individuals | Identification not reasonably likely | Potentially anonymous | Greater legal certainty may expand reuse |
| Irreversibly anonymised dataset | No realistic identification | Outside GDPR | Remains outside GDPR |
| AI model trained on personal data | Depends on extraction or inference potential | Case-specific | Model anonymity becomes a central governance question |
Legacy archives: possession is not unlimited legal reusability
| Original context | New AI use | Primary legal issue | Relative complexity |
|---|---|---|---|
| Public professional profile | General model training | Reasonable expectations, transparency and necessity | SIGNIFICANT |
| Public social-media posts | Foundation-model training | Article 6 balancing, Article 14, objection | SIGNIFICANT |
| Private messages | Foundation-model training | Expectations, confidentiality, necessity and fairness | VERY HIGH |
| Historic purchase data | AI recommendation improvement | Purpose compatibility and relationship with original service | Medium to high |
| Health-account information | General model training | Article 9 plus sector-specific confidentiality | VERY HIGH |
| Child-account archives | Later AI development | Heightened balancing and reasonable expectations | VERY HIGH |
| Customer-service conversations | Product-specific assistant | Compatibility, confidentiality and minimisation | Context dependent |
What remains protected even after reform
| GDPR mechanism | Eliminated by Digital Omnibus? | AI relevance |
|---|---|---|
| Article 5 principles | NO | Purpose limitation, minimisation, fairness, accuracy, storage limitation and accountability |
| Article 6 lawful basis | NO | Core legality of ordinary personal-data processing |
| Article 9 sensitive-data regime | MODIFIED IN DEFINED CASES | Central to health, politics, religion, biometrics and similar data |
| Articles 12–14 transparency | NO | Especially important for indirect or scraped data |
| Article 17 erasure | NO | Complex interaction with training datasets and models |
| Article 21 objection | NO | More important if unconditional AI-specific objection disappears |
| Article 22 automated decisions | NO | Applies separately to qualifying downstream decisions |
| Articles 24–25 accountability and privacy by design | NO | Technical governance and architecture remain mandatory |
| Article 35 DPIA | NO | Potentially required for high-risk AI processing |
| Chapter V international transfers | NO | Cross-border infrastructure remains separately regulated |
Controller compliance chain
Define the AI objective
The controller must establish a precise development or deployment purpose rather than invoke AI innovation generically.
Justify necessity
The quantity, type and provenance of personal data must be proportionate to the stated legitimate interest.
Test individual impact
Expectations, age, sensitivity, objection, transparency and possible harm enter the balancing assessment.
Demonstrate compliance
Accountability requires documentation, governance records, technical safeguards and where relevant a DPIA.
Institutional balance after reform
Watch indicators
Net Legal Assessment
The legal transformation should be understood as a redistribution of regulatory weight rather than an abolition of European data protection. The Commission’s 2025 proposal coupled explicit recognition of AI-related legitimate interest with a package of dedicated protections, whereas the September 2026 Presidency compromise retains the legal opening while returning more of the protective architecture to the general GDPR framework.
The most consequential differences concern the disappearance of the unconditional AI-specific objection right, the narrowing of explicit AI-specific minimisation and transparency language, the proposed handling of residual Article 9 information and the treatment of pseudonymised datasets. These changes do not automatically legalise unrestricted training on historical European data, because purpose limitation, necessity, rights balancing, sensitive-data rules, accountability, DPIAs, transparency and international-transfer requirements continue to apply independently.
The final legal effect will therefore depend less on the headline proposition that “legitimate interest may be used for AI” than on the exact wording of the final legislation, the scope of Article 9 derogations, the definition of identifiability, and the way supervisory authorities and the Court of Justice apply the surviving horizontal GDPR protections to large-scale model development.
Primary and Institutional Legal Sources
- Regulation (EU) 2016/679 — General Data Protection Regulation
- COM(2025) 837 final — European Commission
- Legislative procedure 2025/0360/COD — EUR-Lex
- EDPB Opinion 28/2024 on AI Models
- EDPB Opinion 28/2024 — Official PDF
- EDPB–EDPS Joint Opinion 2/2026
- EDPB–EDPS Joint Opinion 2/2026 — Official PDF
- EDPB — GDPR principles and AI models
- Court of Justice — Case C-252/21, Meta Platforms v Bundeskartellamt
- Council Presidency revised compromise ST 12535/26 — Official document record
Pillar Three — Europe’s Sovereign-AI Capacity
Sovereign AI is a production system, not a model nationality
Europe’s central artificial-intelligence challenge is no longer whether it possesses researchers, datasets, industrial knowledge or regulatory authority, because it possesses all four; the strategic challenge is whether those assets can be assembled into an integrated production system capable of turning European data, electricity, capital, computing infrastructure, scientific knowledge and industrial demand into models, intellectual property, cloud revenues, productivity gains and strategic capabilities controlled substantially from within Europe. The European Commission’s AI Continent Action Plan, adopted in April 2025, effectively acknowledges this problem by structuring European AI policy around computing infrastructure, high-quality data, adoption in strategic sectors, skills and regulatory implementation rather than treating model development as an isolated software industry. The programme’s headline architecture includes an ambition to mobilise €200 billion for AI investment, including €20 billion directed toward AI Gigafactories, while the EuroHPC system is simultaneously building a distributed network of AI Factories around existing European supercomputing assets. European Commission — AI Continent Action Plan
The institutional problem is that these components do not automatically produce technological sovereignty simply because they are physically located in Europe. A data centre in Europe can operate imported accelerators, run proprietary foreign software, serve foreign foundation models and return much of the resulting margin and intellectual property to companies headquartered elsewhere; conversely, a European model can itself depend on non-European chips, cloud layers and development frameworks. Sovereign AI must therefore be analysed by layer: access to energy and land, data-centre ownership, accelerators and processors, supercomputing, cloud orchestration, foundation models, sectoral applications, data rights, financing, procurement, talent and the location of resulting intellectual property. The Commission’s proposed Cloud and AI Development Act reflects precisely this broader approach by combining capacity expansion with an EU-wide sovereignty framework and seeking to at least triple European data-centre capacity within five to seven years. European Commission — Cloud and AI Development Act
The consequence is that Europe’s future position cannot be measured solely by the number of European AI start-ups or by whether a particular European large language model rivals a US frontier model on one benchmark. The relevant question is whether Europe is building enough compute, financing depth, energy availability, industrial demand and institutional purchasing power to ensure that valuable European datasets feed AI systems whose economic returns circulate significantly through European companies, workers, research organisations and fiscal systems. That is the difference between hosting AI activity in Europe and capturing AI value in Europe.
Europe has moved from an AI-regulation phase into an AI-capacity phase
The institutional shift since 2024 is significant. EuroHPC now reports 19 AI Factories plus 13 AI Factory Antennas, alongside 14 supercomputers, 10 quantum computers, 62 research-and-innovation projects and 38 participating states, within a EuroHPC budget reported at approximately €8.2 billion. The factories are designed not merely as machines but as access ecosystems combining compute, technical expertise and support for companies, researchers and public authorities. EuroHPC Joint Undertaking — Key Facts and Figures
This architecture represents an attempt to solve one of Europe’s longstanding weaknesses: the difference between having excellent scientific computing facilities and allowing young companies or industrial SMEs to convert those facilities into commercially usable AI capability. EuroHPC explicitly states that its AI Factory network is intended to provide customised support to SMEs and start-ups, while access calls allow researchers, public-sector users and companies to use European supercomputing resources for scientific and industrial applications. EuroHPC — AI Gigafactories Call, July 2026
The next layer is dramatically larger. The Commission’s AI Gigafactory concept is designed around facilities able to aggregate more than 100,000 advanced AI processors, together with the associated power supply, networking, cooling, storage and software infrastructure necessary to develop next-generation models. European Commission — AI Factories and AI Gigafactories The Commission describes the underlying problem directly as a European deficit in large-scale computing infrastructure capable of supporting pre-training, fine-tuning, inference and frontier-model deployment. European Commission — AI Gigafactories
That distinction between AI Factories and AI Gigafactories is important. The former are distributed innovation infrastructures built around EuroHPC systems and intended to make high-end resources accessible across the ecosystem; the latter are intended to achieve the far greater scale required for frontier and very-large-model workloads. Europe is therefore attempting to build both the diffusion layer and the frontier-compute layer simultaneously.
Europe’s emerging sovereign-AI infrastructure
| Layer | Current European mechanism | Verified scale / target | Strategic function |
|---|---|---|---|
| Distributed AI compute | EuroHPC AI Factories | 19 factories | Start-ups, SMEs, researchers, industry and public-sector AI development |
| Regional access extension | AI Factory Antennas | 13 antennas | Extend factory services geographically |
| EuroHPC supercomputing | EuroHPC systems | 14 supercomputers reported by EuroHPC in Sep. 2026 | HPC, scientific computing, AI workloads |
| Frontier AI infrastructure | AI Gigafactories | Several planned facilities | Large-scale model training and inference |
| Gigafactory processors | Commission architecture | >100,000 advanced AI processors per facility concept | Frontier-scale compute concentration |
| Gigafactory financing | InvestAI facility | €20 billion targeted mobilisation | De-risk large private/public infrastructure investment |
| Broader AI investment | InvestAI / AI Continent | €200 billion stated mobilisation ambition | Compute, innovation and AI ecosystem development |
| Data-centre capacity | Cloud and AI Development Act | At least triple EU capacity within 5–7 years | Cloud and AI infrastructure availability |
| Enterprise AI adoption | EU enterprises ≥10 employees | 20.0% in 2025 | Indicates diffusion into productive economy |
| Large-enterprise AI adoption | EU large enterprises | 55.03% in 2025 | Shows much stronger uptake among large firms |
Sources: European Commission — AI Continent, EuroHPC Joint Undertaking, European Commission — Cloud and AI Development Act, Eurostat — Use of AI in enterprises.
Europe has solved neither the compute gap nor the capital gap merely by announcing public infrastructure
The urgency behind the current investment push is visible in the European Court of Auditors’ earlier assessment of EU AI policy. Its 2024 special report concluded that although European AI investment increased, the investment gap between the United States and the EU more than doubled between 2018 and 2020; the Court cited estimates placing US AI investment at approximately €21.2 billion in 2020 against €10.7 billion in the EU-27, while also criticising weaknesses in target-setting and performance monitoring. Those data are historical and cannot be treated as a measure of the 2026 gap, but they document the structural starting point from which today’s policy acceleration emerged. European Court of Auditors — Special Report 08/2024
The Commission’s response is increasingly based on public de-risking rather than full public ownership. Under the Gigafactory architecture, European and national public resources are intended to reduce the financial risk of facilities whose cost, hardware requirements and energy needs make purely public deployment difficult, while private capital supplies much of the scale. The Commission reported that an informal expression-of-interest process attracted 77 proposals across 16 Member States and approximately 60 sites, after which EuroHPC launched the formal Gigafactory call in July 2026. European Commission — AI Gigafactories
This is a potentially powerful mechanism, but it creates a governance problem: public money can create European physical capacity without necessarily creating European corporate control. If public guarantees chiefly subsidise facilities whose hardware, software and largest tenants remain non-European, Europe gains capacity and employment but captures less of the high-margin intellectual property associated with model development and cloud services. The institutional design of Gigafactory consortia, access rights, procurement, model ownership, data governance and conditions attached to public support will therefore matter as much as the announced euro amount.
The real European advantage is industrial AI rather than imitation of the American consumer-platform model
Europe’s most important economic advantage lies in the structure of its productive economy. The Union contains globally significant automotive, aerospace, chemicals, machinery, pharmaceuticals, energy, advanced manufacturing, logistics, financial and public-service sectors that possess extremely valuable operational datasets and domain expertise. The AI Continent strategy consequently places major emphasis on industrial AI rather than defining competitiveness solely around consumer chatbots or advertising platforms. European Commission — AI Continent Action Plan
This orientation becomes more important when adoption data are examined. Eurostat reports that 20.0% of EU enterprises with ten or more employees used AI technologies in 2025, up from 13.5% in 2024 and 8.1% in 2023. Adoption was extremely uneven by company size: approximately 17% of small enterprises, 30.36% of medium-sized enterprises and 55.03% of large enterprises used AI in 2025. Eurostat — Use of artificial intelligence in enterprises
This distribution identifies the sovereignty problem more clearly than aggregate investment announcements do. Europe does not merely need European models; it needs mechanisms allowing thousands of mid-sized industrial firms to connect proprietary process data to advanced AI without handing strategic knowledge, inference economics and future workflow dependence entirely to foreign providers. AI Factories, sector-specific models, sovereign cloud infrastructure and trusted industrial data spaces therefore have greater long-term significance than a symbolic race to produce the largest possible general-purpose model.
AI adoption exposes the European scale problem
| Enterprise category | AI use in EU, 2025 | Strategic interpretation |
|---|---|---|
| All enterprises ≥10 employees | 19.95% / approximately 20% | AI diffusion accelerating rapidly |
| Small enterprises | 17.0% | Majority still outside meaningful AI adoption |
| Medium enterprises | 30.36% | Significant uptake but large headroom remains |
| Large enterprises | 55.03% | AI increasingly embedded in major corporate operations |
| EU, 2023 | 8.1% | Baseline before generative-AI acceleration |
| EU, 2024 | 13.5% | Rapid acceleration underway |
| EU, 2025 | 20.0% | More than twice 2023 share |
Source: Eurostat — Artificial intelligence in enterprises.
The policy implication is that European sovereignty will not be established by producing one European frontier champion while the remaining industrial base consumes imported AI through foreign clouds. Value capture requires diffusion, because manufacturing productivity, industrial automation, drug discovery, logistics optimisation, engineering design and public-sector transformation can generate economic value on a scale that does not appear in model benchmark comparisons.
Italy: sovereign compute exists; the challenge is turning infrastructure into firms and products
Italy occupies a stronger infrastructure position than its global AI-company profile might initially suggest. The IT4LIA AI Factory, coordinated by CINECA in Bologna, is being constructed around Leonardo, the LISA AI upgrade, the GAIA cloud and a dedicated AI-optimised supercomputer, creating a combined infrastructure that EuroHPC expects to provide more than 20,000 GPUs when completed. EuroHPC — Italy AI Factory
The planned IT4LIA dedicated AI system illustrates the scale of the national commitment. EuroHPC’s procurement documentation places the estimated contract value at approximately €290 million and specifies a system intended to support large-scale training, fine-tuning, inference, reasoning, retrieval-augmented generation, optimisation and multi-agent simulation. EuroHPC — IT4LIA AI-optimised supercomputer procurement
The existing Leonardo platform is itself being strengthened through the LISA upgrade, which EuroHPC says includes an AI-optimised partition based on 166 advanced eight-way GPU servers and is specifically designed to support large language models and multimodal generative AI workloads. EuroHPC — LISA upgrade of Leonardo
This gives Italy an important component of sovereign AI: publicly anchored high-performance compute physically integrated into a research and industrial ecosystem rather than simply purchased as external cloud credits. The Italian AI Factory consortium also brings together CINECA, ministries and agencies, the Emilia-Romagna Region, INFN, AI4I, FBK, universities, Confindustria and the national HPC, Big Data and Quantum Computing research infrastructure, which provides the institutional density needed to connect scientific capacity with industrial use. EuroHPC — IT4LIA consortium
Italy’s weakness lies farther downstream. The Italian Strategy for Artificial Intelligence 2024–2026 organises national intervention across research, public administration, enterprises and education, explicitly recognising that AI development must be connected to the country’s productive system and public sector. Italian Government Digital Transformation Department — Italian Strategy for Artificial Intelligence 2024–2026 Yet the strategic question for Italy is no longer principally whether national compute exists: it is whether start-ups, industrial champions and SMEs can turn that compute into commercially scalable models, industrial software and exportable AI systems.
Italy’s comparative advantage lies particularly in sectors where proprietary knowledge matters more than internet-scale consumer data: machinery, robotics, automotive components, aerospace, pharmaceuticals, biomedical technologies, energy engineering, design, precision agriculture and complex manufacturing supply chains. The institutional objective should therefore be understood as an effort to build an Italian industrial-AI layer on top of European compute, rather than merely attempting to reproduce the platform economics of Silicon Valley.
Italy’s sovereign-AI asset stack
| Asset | Verified position | Strategic value | Primary constraint |
|---|---|---|---|
| Leonardo | Major EuroHPC pre-exascale system hosted by CINECA | Existing HPC foundation | Must translate capacity into commercial AI use |
| LISA upgrade | 166 eight-way GPU servers | Dedicated generative-AI capability | High utilisation and accessible allocation required |
| IT4LIA dedicated AI system | Procurement estimated at €290m | Training, inference, reasoning, RAG, simulation | Conversion into applications and firms |
| IT4LIA combined environment | >20,000 GPUs expected | Significant AI-compute concentration | Talent and product scale |
| National AI Strategy | Research, PA, enterprise, skills | Institutional coordination | Implementation and measurable adoption |
| Industrial ecosystem | Machinery, manufacturing, engineering, health and other specialised sectors | High-value proprietary data | SME fragmentation |
| Public-sector demand | Large administrative and public-service base | Potential anchor customer | Procurement speed and interoperability |
Sources: EuroHPC — Italy AI Factory, EuroHPC — IT4LIA procurement, Italian AI Strategy 2024–2026.
For Italy, procurement and capital allocation may therefore matter more than another strategy document. Infrastructure that remains principally scientific produces scientific excellence; infrastructure connected to predictable public procurement, corporate co-investment, scale-up financing and industrial data can create companies. The distinction is essential because Italy already possesses deep engineering competence and one of Europe’s strongest public HPC centres, yet that competence must migrate into repeatable AI products if value capture is to remain domestic.
France: attempting to build the complete AI value chain
France is pursuing the most explicit full-stack strategy among the large continental economies, combining frontier-model companies, public research, nuclear-heavy electricity generation, data-centre development, international capital and national industrial policy. The French government’s third phase of its national AI strategy, announced in 2025, builds on a programme to which approximately €2.5 billion from France 2030 has been dedicated. French Ministry of Economy — National AI Strategy
The decisive change came with the February 2025 AI Action Summit, where the Presidency announced approximately €109 billion of French and foreign private investment commitments relating to AI infrastructure and deployment in France. Élysée — Making France an AI Power This number is an announcement of investment commitments rather than a measure of expenditure already deployed, and it should therefore not be confused with realised capital formation; nevertheless, its scale reflects France’s deliberate effort to turn power availability, sites, connectivity and policy support into a European compute cluster.
France’s strategy is unusual because it explicitly connects compute to the wider value chain. At the June 2026 Choose France summit, President Emmanuel Macron described the objective not merely as installing data centres but as extending deeper into chips, services, robotics, models and AI companies, framing compute as the foundation upon which French and European champions can build value. Élysée — Choose France, 1 June 2026
The French sovereignty concept also includes trusted cloud. The government identifies SecNumCloud, operated under ANSSI’s security framework, as part of an approach intended to protect sensitive information and reduce exposure to extraterritorial legal risk for strategic users. Élysée — Council of Ministers, Digital Sovereignty, 12 June 2025 This matters because sovereign compute without a trusted cloud and deployment environment cannot easily penetrate defence, healthcare, public administration, critical infrastructure and other high-value regulated sectors.
France’s structural advantage is therefore vertical integration of policy objectives: talent creation, compute, energy, model development, cloud security and capital are treated as related components. Its principal risk is that a large proportion of announced data-centre investment can still produce infrastructure whose economic rents accrue heavily to multinational cloud and hardware providers. The French system captures maximum strategic value only if locally controlled models, software and services scale alongside the physical infrastructure.
France’s emerging AI production model
| Component | Verified policy / figure | Strategic role |
|---|---|---|
| National AI strategy funding | Approximately €2.5bn France 2030 | Research, ecosystem building, adoption |
| 2025 investment announcements | Approximately €109bn | Data centres, infrastructure and AI deployment commitments |
| Talent objective cited by Presidency | From approximately 40,000 toward 100,000 trained annually | Human-capital scaling |
| Energy position | Government emphasises abundant, stable, low-carbon electricity | Data-centre attraction |
| Trusted cloud | SecNumCloud framework | Sensitive-sector sovereignty |
| Domestic model ecosystem | Multiple French model and AI companies | Capturing software/IP value |
| Strategic objective | Chips + compute + models + services + robotics | Full-stack value retention |
Sources: French Ministry of Economy — National AI Strategy, Élysée — AI Action Summit, Élysée — Business Day.
Germany: betting on industrial AI and an enormous expansion of computing capacity
Germany’s AI strategy is increasingly inseparable from its wider industrial competitiveness programme. The federal Hightech Agenda Deutschland identifies artificial intelligence among six key technologies considered central to future competitiveness and links AI specifically to industrial deployment and sector-specific applications. Federal Government of Germany — Hightech Agenda and AI
Germany’s most quantifiable intervention is its national data-centre strategy. As of September 2026, the federal government reports roughly 3 GW of total data-centre connection capacity and approximately 500 MW devoted to AI, with official targets to at least double overall data-centre capacity by 2030 and at least quadruple HPC and AI capacity relative to the 2025 base. Federal Government of Germany — Data Centre Strategy, September 2026 Federal Ministry for Digital Affairs — 2027 budget statement
Official government material provides another expression of the same target: total connection capacity is expected to exceed approximately 6 GW by 2030, while HPC and AI infrastructure should expand at least fourfold. German Federal Government Bulletin — National Data Centre Strategy
Germany also hosts several EuroHPC AI Factory initiatives. The HammerHAI system, for example, is specified by EuroHPC at approximately 15 exaflops of peak AI inference performance, with 860 NVIDIA B200 GPUs, 10 PB of storage and high-speed InfiniBand and Ethernet networking. EuroHPC — Germany AI Factories Germany also hosts JUPITER, one of the major EuroHPC systems, reinforcing the interaction between national and European infrastructure. EuroHPC — European supercomputing infrastructure
Germany’s strategic rationale differs subtly from France’s. Berlin increasingly frames the principal opportunity as industrial AI: combining machinery, production systems, process knowledge and proprietary corporate data with AI rather than attempting to dominate consumer-platform AI. Chancellor Friedrich Merz has explicitly connected national AI policy with deployment inside core industries and the Mittelstand, while the government’s Hightech Agenda supports domain-specific AI and transfer models for SMEs. German Federal Government — Made for Germany and AI policy
This strategy is rational because Germany’s most defensible AI assets are not primarily social-network datasets but decades of high-value engineering and production data distributed across automotive systems, machinery, chemicals, pharmaceuticals, industrial automation and logistics. The economic problem is access: much of that data is fragmented inside companies reluctant to expose process knowledge to external model providers. Sovereign or trusted infrastructure can therefore create value by allowing German firms to use proprietary data without surrendering strategic control over it.
Germany’s compute and industrial-AI position
| Indicator | Verified position / target | Date / horizon |
|---|---|---|
| Current total data-centre capacity | Approximately 3 GW | 2026 government statement |
| Current AI-oriented capacity | Approximately 500 MW | 2026 government statement |
| Overall capacity target | At least 2× | 2030 vs 2025 |
| HPC/AI capacity target | At least 4× | 2030 vs 2025 |
| Indicative overall capacity implied by government | >6 GW | 2030 |
| HammerHAI peak AI inference | 15 exaflops | System deployment 2026 |
| HammerHAI GPUs | 860 NVIDIA B200 | EuroHPC specification |
| HammerHAI storage | 10 PB | EuroHPC specification |
| National strategic focus | Industrial and domain-specific AI | Hightech Agenda |
Sources: German Federal Government — Data Centre Strategy, German Federal Government — 2027 Digital Budget, EuroHPC — Germany.
Germany’s principal bottleneck is no longer recognition of the compute problem but execution speed, particularly grid connection, permitting, energy cost and the mobilisation of private capital. The government’s data-centre strategy explicitly centres on energy and sustainability, land and location, and technology and sovereignty, while June 2026 measures relaxed several domestic energy-efficiency implementation requirements in an effort to facilitate investment. Federal Government of Germany — Energy efficiency and data centres
United Kingdom: the most useful external comparator is compute policy, not deregulation alone
The United Kingdom is outside the EU legislative framework but confronts the same strategic problem: frontier AI requires far more than an innovation-friendly regulatory environment. The UK’s response is centred on the AI Research Resource (AIRR), AI Growth Zones, a national compute roadmap and an explicit ambition to build sovereign computing capacity accessible to academia, start-ups, companies and the public sector. UK Government — AI Research Resource
The British compute target is unusually precise. The UK Compute Roadmap commits more than £1 billion to expand AIRR twentyfold by 2030, from approximately 21 AI ExaFLOPS in 2025 to 420 AI ExaFLOPS in 2030, alongside up to £750 million for a new national supercomputer in Edinburgh within a broader package of up to approximately £2 billion for public compute infrastructure. UK Government — UK Compute Roadmap
AIRR already combines Isambard-AI at Bristol and Dawn at Cambridge, and the government describes the programme as a response to an acute shortage of public specialised AI compute. UK Government — AIRR advanced supercomputers Access is deliberately structured around research and industrial use: the 2026 open-access call allowed qualifying projects to apply for between 50,000 and 1.4 million GPU hours on Isambard-AI. UK Government — AI open access call
The next planned AIRR system carries a separate £750 million investment commitment and is intended to support frontier AI research, large-scale inference and scientific discovery while strengthening what the government explicitly calls the UK’s sovereign AI capability. UK Government — AIRR heterogeneous supercomputer host-site selection
EU–UK sovereign-compute comparison
| Dimension | European Union | United Kingdom |
|---|---|---|
| Primary institutional structure | EuroHPC + national facilities | AIRR + national supercomputing centres |
| Distributed AI access | 19 AI Factories + 13 Antennas | AIRR access programmes |
| Frontier-scale expansion | AI Gigafactories | AIRR expansion + national supercomputer |
| Public compute target | Multiple facilities; >100,000 processors contemplated per Gigafactory concept | AIRR 21 → 420 AI ExaFLOPS by 2030 |
| Major financing figure | €20bn Gigafactory mobilisation objective | >£1bn AIRR expansion |
| Wider compute package | EU + Member-State + EIB/private resources | Up to approximately £2bn public compute roadmap |
| SME access | AI Factories | AIRR Rapid Access / innovation routes |
| Industrial-policy logic | EU strategic autonomy + industrial AI | National sovereign compute + growth zones |
| Regulatory position | EU AI Act / single-market framework | Separate UK regulatory regime |
Sources: European Commission — AI Continent, EuroHPC, UK Government — UK Compute Roadmap, UK Government — AIRR.
The UK comparison is analytically useful because it demonstrates that regulatory independence from the EU does not remove the infrastructure problem. Britain has still concluded that government-supported compute, energy-intensive infrastructure, research access and public investment are necessary conditions for a competitive domestic AI ecosystem. The difference is therefore less “EU regulation versus British deregulation” than two different institutional arrangements attempting to solve the same scarcity of compute, capital and scale.
The semiconductor dependency remains Europe’s hardest sovereignty constraint
No European sovereign-AI strategy can avoid the processor problem. AI Factories and Gigafactories require large numbers of advanced accelerators, and the present European infrastructure build-out continues to rely extensively on non-European processor architectures and suppliers. This does not make the investments strategically irrelevant, because compute availability itself has major value, but it means physical European infrastructure does not equal full-stack hardware sovereignty.
The EU Chips Act was designed partly to address this wider dependence, with the Commission having associated the initiative with more than €43 billion of public and private investment mobilisation in European semiconductor capabilities. European Commission — European Chips Act investment framework More recent Commission language links the Gigafactory programme directly to the European semiconductor ecosystem, arguing that predictable large-scale AI-compute demand can help stimulate European processor design and eventually indigenous manufacturing. European Commission — AI Gigafactories
This is strategically important because a true European AI production system requires not complete autarky, which would be economically unrealistic, but sufficient substitution capacity and bargaining power across critical layers. Europe does not need every accelerator to be designed and fabricated inside the Union, but it does need to avoid a structure in which every expansion of European AI capability automatically increases dependency on a single external hardware ecosystem.
Energy is becoming an AI industrial-policy instrument
Compute policy increasingly converges with electricity policy. AI infrastructure converts electricity, chips, data and capital into computation, making reliable power supply a direct determinant of AI investment. France explicitly promotes its relatively abundant low-carbon electricity as a reason for locating data-centre infrastructure domestically, while Germany’s data-centre strategy treats energy availability and network connection as principal constraints on expansion. Élysée — France as an AI power German Federal Government — Data Centre Strategy
The Commission’s Cloud and AI Development Act follows the same logic at European level by identifying energy, land, water, financing and permitting as constraints on data-centre expansion. European Commission — Cloud and AI Development Act This marks a fundamental policy change: AI strategy is becoming infrastructure strategy, and infrastructure strategy is becoming energy policy.
A Member State with excellent researchers but insufficient grid capacity can lose AI infrastructure to a neighbour; a country with abundant power but no domestic model ecosystem may host foreign computation without capturing high-value intellectual property. The highest-value configuration therefore combines electricity, connectivity, compute, human capital and firms capable of owning the resulting AI layer.
Cloud sovereignty will determine whether European compute becomes European strategic autonomy
Europe’s dependency problem does not end once servers have been installed. Enterprise AI increasingly operates through integrated cloud stacks that provide storage, data engineering, cybersecurity, model APIs, orchestration, inference and business applications. A European company can therefore use a physically European data centre while remaining deeply dependent on non-European software and cloud architecture.
The proposed Cloud and AI Development Act is significant because it explicitly adds an autonomy pillar, including a planned EU-wide framework for assessing cloud and AI sovereignty, while also seeking a European cloud offer capable of serving strategic public and industrial sectors. European Commission — Cloud and AI Development Act The Commission also links the Act to a common approach for public-sector cloud procurement and secure European cloud capacity for highly critical uses. European Commission — Cloud Computing and CADA
The practical sovereignty test is consequently not whether a cloud provider is legally European or foreign in isolation, but whether Europe retains operational substitutability: can strategic workloads migrate between providers, can encryption keys and data access remain under European control, can essential services continue during geopolitical disruption, and are European providers economically capable of competing for public and private workloads?
Public procurement may become the most powerful instrument Europe possesses
The United States developed much of its technological ecosystem partly through large public markets in defence, space, intelligence and research; Europe has historically been more fragmented. AI provides a strong case for using public procurement as a demand-side industrial instrument without abandoning competitive tendering or technological neutrality.
European public administrations, healthcare systems, universities, defence organisations, utilities and transport networks collectively represent an enormous potential AI market. If each institution purchases isolated proprietary systems, the result can reinforce external platform concentration; if procurement creates interoperable demand for European compute, secure clouds, specialised models and local integration services, public spending can become an anchor market for European suppliers.
The Commission’s emerging cloud policy explicitly connects sovereignty with public procurement, while AI Factories already include public-sector users among their target communities. European Commission — Cloud Computing policy EuroHPC — AI Gigafactories and access The institutional question will be whether that demand is aggregated sufficiently to create scale, rather than fragmented into hundreds of national, regional and municipal procurement exercises.
The value-capture chain determines whether European data produces European wealth
The relationship between data sovereignty and economic sovereignty can be expressed as a sequence. Data alone generate little strategic value. Value emerges when data are organised, processed through compute, converted into models, embedded in applications and deployed into productive processes. Each layer creates an opportunity for rents to leave or remain within Europe.
European AI value-capture chain
| Value-chain stage | Strategic European asset | Leakage mechanism | Institutional response required |
|---|---|---|---|
| Data creation | Industrial, public, scientific and consumer datasets | Data used principally by external platforms | Data spaces, trusted access, interoperable governance |
| Data preparation | Sectoral expertise and research institutions | Processing stack controlled externally | AI Factory data labs and European software capacity |
| Compute | EuroHPC, national HPC, data centres | Dependence on external accelerator supply | Gigafactories, diversified hardware and European processor R&D |
| Cloud | Growing European cloud market | Hyperscaler concentration | Sovereignty framework, interoperability and procurement |
| Foundation models | European research and start-ups | Capital and distribution disadvantages | Compute allocation, scale-up finance and procurement |
| Sectoral models | Strong industrial base | Proprietary data transferred to general external models | Domain-specific AI and confidential-computing architectures |
| Applications | Large European enterprise and public market | Foreign software captures margins | European integration and application firms |
| Deployment | Manufacturing, healthcare, transport, energy | Vendor lock-in | Open standards and portability |
| Intellectual property | European research excellence | Acquisition or relocation of scaling firms | Growth capital and European exit alternatives |
| Revenue | Large single market | Profit and tax base accrue elsewhere | Domestic firms, procurement and competitive cloud/model markets |
The central implication is that GDPR reform or greater data availability cannot independently generate sovereign AI. If European data become easier to process while the compute, models and cloud layer remain structurally external, the change principally enlarges the input base available to existing global firms. If European compute, capital, industrial deployment and procurement mature simultaneously, greater data availability can become an input to European value creation.
Five institutional choices will determine the outcome
Compute must be allocated as industrial infrastructure rather than prestigious scientific capacity
The first choice concerns access. Europe is investing heavily in machines, but sovereignty depends on which companies can use them, at what cost, for what duration and with what allocation certainty. A start-up cannot build a commercial model business around occasional research-style compute grants whose future allocation is uncertain. EuroHPC’s transition toward AI Factories is therefore strategically important precisely because it attempts to provide services rather than merely machine time. EuroHPC — AI Factory network
Europe will need access frameworks capable of supporting scientific research, SMEs and serious scale-up companies differently. The latter may require multi-year capacity commitments, confidential workloads and predictable pricing rather than short-term grant allocations.
Public capital must crowd in European scale rather than merely reduce foreign infrastructure costs
The second choice concerns financial additionality. The €20 billion Gigafactory mobilisation objective can produce dramatically different outcomes depending on its conditions. European Commission — AI Gigafactories Public capital generates strategic leverage only where it produces investment that would otherwise not occur or attaches conditions that improve European capability, competition and resilience; simply subsidising already-planned multinational data centres provides much weaker sovereignty effects.
Procurement must create a market for European AI, not merely compliance demand
The third choice is whether public institutions act as first customers for European AI. Start-ups scale when they have revenue, reference clients and predictable demand. The EU and national governments possess substantial procurement power but historically fragmented technology purchasing weakens its industrial effect. The emerging European cloud policy recognises this issue by linking cloud sovereignty with public-sector procurement. European Commission — Cloud Computing
Industrial data must remain usable without forcing firms to surrender strategic knowledge
The fourth choice concerns architecture for confidential industrial AI. Germany and Italy in particular hold much of their comparative advantage inside private manufacturing firms rather than consumer platforms. If using advanced AI requires those firms to export proprietary process data into opaque external systems, adoption will either remain limited or sovereignty will deteriorate. Secure European cloud, confidential computing, federated systems, on-premise models and trusted AI Factory services can therefore become industrial-policy tools rather than merely privacy technologies.
Europe must retain scaling companies, not just create start-ups
The fifth choice concerns late-stage capital and ownership. Creating research spin-offs is insufficient if successful firms subsequently relocate, sell to larger external platforms or depend on foreign capital for the growth stage. Sovereign AI therefore intersects with the European capital-markets problem. Germany’s government itself increasingly links technology policy with deeper European capital markets and growth financing. German Federal Government — Industry Day 2026
Institutional decision matrix
| Policy choice | Weak configuration | Strong sovereignty configuration | Observable indicator |
|---|---|---|---|
| Compute allocation | Short research grants | Predictable commercial-scale access | European start-ups training and serving models on EuroHPC |
| Gigafactory finance | Infrastructure subsidy only | Conditional public-private capability building | European ownership/IP share |
| Cloud policy | Physical localisation only | Portability, control, substitutability and secure European services | Strategic workloads on trusted EU capacity |
| Data policy | More available data | Data linked to European compute and model ecosystems | European firms monetising European datasets |
| Industrial AI | Generic external APIs | Sector-specific confidential AI | Manufacturing adoption without data surrender |
| Procurement | Fragmented tenders | Aggregated demand and interoperability | European AI vendors winning public contracts |
| Scale-up capital | Early-stage funding only | Late-stage European growth capital | Lower forced sale/relocation of successful firms |
| Semiconductor policy | Imported accelerator monoculture | Diversified supply plus European processor capability | European-design share in AI infrastructure |
| Energy policy | Grid bottlenecks | Predictable power and accelerated connections | Gigafactory deployment without energy delays |
| Skills | Research excellence only | Engineers + operators + entrepreneurs + sector experts | Domestic employment and company formation |
Italy, France and Germany are developing complementary rather than identical sovereign-AI models
The three large continental economies are not converging on one national strategy. Italy is building an infrastructure-and-industrial specialisation model, anchored by CINECA, Leonardo and IT4LIA; France is pursuing a capital-intensive full-stack model, combining compute, energy, models and international investment; Germany is constructing an industrial-AI model, using massive data-centre expansion and manufacturing datasets as its principal strategic advantage. These approaches are complementary if integrated through the European market and EuroHPC, but potentially duplicative if each state attempts to construct closed national ecosystems.
Comparative sovereign-AI architecture
| Dimension | Italy | France | Germany | United Kingdom |
|---|---|---|---|---|
| Core comparative asset | Public HPC + industrial specialisation | Compute + energy + models + capital | Industrial data + manufacturing | Research + finance + sovereign compute |
| Major compute programme | IT4LIA / Leonardo / LISA | National data-centre investment + EuroHPC participation | JUPITER, HammerHAI, national data-centre expansion | AIRR / Isambard-AI / Dawn |
| Quantified compute goal | >20,000 GPUs anticipated in IT4LIA environment | Large private infrastructure commitments; no directly comparable national GPU target in cited record | Total DC ≥2×; HPC/AI ≥4× by 2030 | AIRR 21 → 420 AI ExaFLOPS |
| Major investment figure | IT4LIA procurement ~€290m | €109bn announced AI investment commitments | Large private/public infrastructure expansion; national targets expressed mainly in capacity | >£1bn AIRR; up to ~£2bn compute package |
| Strategic orientation | Specialised and industrial AI | Full-stack AI power | Industrial AI | Frontier research and sovereign compute |
| Principal bottleneck | Scale-up capital / productisation | Converting infrastructure into domestic IP | Energy, grid, deployment speed | Scale relative to US frontier ecosystem |
| Strongest sovereignty lever | European HPC integration | Compute-energy-model integration | Proprietary industrial data | Flexible national allocation of compute |
| Risk | Strong infrastructure but weak commercial scaling | Infrastructure dominated by external capital/providers | Slow permitting and fragmented Mittelstand adoption | Compute expands but firms still scale through foreign platforms |
Sources: EuroHPC — Italy, French Ministry of Economy — National AI Strategy, German Government — Data Centre Strategy, UK Government — Compute Roadmap.
The decisive European choice is integration versus fragmentation
No individual European state has an obvious economic case for reproducing the entire US AI stack independently. The Union’s advantage lies instead in shared infrastructure plus national specialisation. EuroHPC allows an Italian company to access European computing capacity beyond Italy, while French electricity and investment, German industrial demand, Nordic low-cost energy, Dutch connectivity, Spanish renewable capacity and scientific clusters across multiple Member States can form parts of a continental system.
That model fails if national industrial policy becomes primarily competitive subsidy policy, with Member States bidding against one another to attract the same foreign data centres while European start-ups remain too small to use the resulting infrastructure. The Commission’s Gigafactory programme implicitly attempts to avoid this outcome by making the facilities European infrastructure projects rather than purely national ones. European Commission — AI Gigafactories
The same logic applies to data centres. A tripling of EU capacity is economically relevant only if the system remains interconnected, power-efficient and accessible across borders. European Commission — Cloud and AI Development Act National sovereignty pursued through isolated infrastructure could paradoxically produce less European sovereignty by reducing scale and increasing duplication.
Key evidence table
| Indicator | Verified figure / status | Reference period | Strategic meaning | Source |
|---|---|---|---|---|
| EU AI investment mobilisation objective | €200bn | AI Continent initiative | Scale of proposed public/private mobilisation | European Commission |
| AI Gigafactory mobilisation | €20bn | InvestAI | Frontier compute financing | European Commission |
| AI Factories | 19 | Sep. 2026 | Distributed AI access | EuroHPC |
| AI Factory Antennas | 13 | Sep. 2026 | Geographic reach | EuroHPC |
| EuroHPC supercomputers | 14 | Sep. 2026 | European HPC base | EuroHPC |
| EuroHPC budget reported | €8.2bn | Sep. 2026 | HPC ecosystem scale | EuroHPC |
| Gigafactory processor concept | >100,000 advanced AI processors | Commission architecture | Frontier-scale compute | European Commission |
| Gigafactory expressions of interest | 77 proposals / 16 Member States / ~60 sites | 2025–26 process | Strong infrastructure demand | European Commission |
| EU data-centre expansion objective | ≥3× | Next 5–7 years | Cloud and AI capacity | European Commission |
| EU enterprise AI adoption | 20.0% | 2025 | AI diffusion | Eurostat |
| EU large-enterprise adoption | 55.03% | 2025 | AI concentrated in larger firms | Eurostat |
| Italy IT4LIA environment | >20,000 GPUs expected | Build-out | National/European AI compute | EuroHPC |
| IT4LIA procurement | ~€290m | 2025 tender | Dedicated Italian AI supercomputer | EuroHPC |
| France AI investment announcements | €109bn | Feb. 2025 | Infrastructure and deployment commitments | Élysée |
| French national AI funding | ~€2.5bn France 2030 | National strategy | Research/ecosystem funding | French Economy Ministry |
| German data-centre capacity | ~3 GW | 2026 government statement | Existing national infrastructure | Bundesregierung |
| German AI compute capacity | ~500 MW | 2026 government statement | AI-oriented capacity | Bundesregierung |
| German overall DC target | ≥2× | 2030 vs 2025 | National expansion | Bundesregierung |
| German HPC/AI target | ≥4× | 2030 vs 2025 | AI-scale expansion | Bundesregierung |
| UK AIRR expansion | 21 → 420 AI ExaFLOPS | 2025–2030 | Twentyfold sovereign compute growth | UK Government |
| UK AIRR commitment | >£1bn | To 2030 | Public AI compute | UK Government |
| New UK supercomputer | up to £750m | Announced/procurement phase | Frontier research and inference | UK Government |
Indicators that would confirm Europe is actually becoming more sovereign
The strongest evidence of progress will not be additional strategy announcements but changes in ownership and economic flows. A genuinely stronger European AI position would become visible if European-controlled providers account for an increasing share of high-value enterprise inference; European start-ups receive multi-year EuroHPC compute allocations and survive into late-stage growth; industrial groups deploy domain-specific models without transferring proprietary datasets outside trusted environments; European public administrations become anchor customers for European AI infrastructure; and European processor, networking and cloud software suppliers capture an increasing portion of Gigafactory expenditure.
Conversely, the assessment would weaken if European public money produces mainly physical data centres operated by foreign hyperscalers; AI Factory access remains concentrated in research projects rather than commercial scaling; European model firms continue to relocate or sell before achieving major scale; industrial companies rely overwhelmingly on external foundation-model APIs; or hardware concentration means every increase in European computing capacity further increases dependence on one or two external processor ecosystems.
What would change the assessment
The principal judgment would improve materially if the first AI Gigafactory procurement rounds demonstrate substantial European ownership, European model workloads and durable access for European scale-ups, rather than serving predominantly as subsidised capacity for incumbent global providers. European Commission — AI Gigafactory programme
It would also improve if the proposed Cloud and AI Development Act succeeds in tripling capacity while establishing meaningful portability, secure-European-cloud requirements for critical public workloads and a measurable expansion of European cloud providers. European Commission — Cloud and AI Development Act
At national level, Italy should be assessed on whether IT4LIA produces exportable companies and industrial applications rather than simply high utilisation rates; France on whether its €109 billion investment wave creates domestic models, chips, cloud services and application companies alongside foreign-owned data centres; Germany on whether its planned doubling of overall data-centre capacity and quadrupling of AI/HPC capacity translate into measurable productivity gains in manufacturing and the Mittelstand; and the United Kingdom on whether its twentyfold AIRR expansion creates durable domestic model and AI companies rather than primarily subsidising excellent research. EuroHPC — Italy Élysée — French AI strategy Bundesregierung — Data Centre Strategy UK Government — Compute Roadmap
Key judgments
Europe now possesses a credible public-compute strategy, but it does not yet possess evidence of full-stack AI sovereignty. The combination of EuroHPC, 19 AI Factories, 13 Antennas, planned Gigafactories and a programme to at least triple data-centre capacity represents a material infrastructure build-out rather than regulatory rhetoric. EuroHPC Joint Undertaking European Commission — Cloud and AI Development Act
Compute is becoming available at a scale that can support serious European AI development, but access architecture will determine whether that capacity creates companies or primarily research output. AI Factories represent an institutional attempt to solve this problem by combining machine access with support services, while Gigafactories are intended to address the separate frontier-scale constraint. European Commission — AI Factories
Italy has one of Europe’s most important publicly anchored AI-compute concentrations, but its strategic test is commercial conversion. IT4LIA, Leonardo and LISA provide infrastructure that many European states lack; sovereignty will depend on whether that infrastructure produces scalable Italian and European AI firms and industrial applications. EuroHPC — IT4LIA AI Factory
France is attempting the most explicit continental full-stack strategy, connecting large infrastructure commitments with domestic models, talent, energy, cloud security and capital mobilisation; however, the €109 billion figure represents announced investment commitments and should not be treated as completed expenditure. Élysée — France AI strategy
Germany’s strongest route to AI sovereignty is industrial rather than consumer-platform AI. Its approximately 3 GW data-centre base, government target to double capacity and quadruple HPC/AI infrastructure, major EuroHPC assets and manufacturing data create the conditions for a powerful sector-specific AI ecosystem if grid, capital and adoption constraints can be resolved. German Federal Government — Data Centre Strategy
The United Kingdom demonstrates that leaving the EU regulatory system does not remove the requirement for sovereign infrastructure. Its commitment to expand AIRR twentyfold from 21 to 420 AI ExaFLOPS by 2030 confirms that access to large-scale public compute is viewed as strategic even under a different regulatory model. UK Government — UK Compute Roadmap
The most important European sovereignty variable is therefore not where the data originate, but where the entire value chain is controlled. European data processed on European soil can still enrich non-European model, cloud and processor ecosystems; conversely, internationally sourced hardware and capital can contribute to European sovereignty where European companies retain model ownership, proprietary applications, industrial know-how, employment and downstream revenues.
Data sovereignty becomes economic sovereignty only when Europe owns enough of the machinery that converts data into intelligence. The emerging policy architecture therefore has to connect the GDPR and Data Union debate with EuroHPC compute, Gigafactory financing, cloud portability, chips, energy, capital markets, procurement and industrial adoption. Treating any one of those components independently would miss the structure of the competitive problem.
Open official record
The most consequential forthcoming official evidence will be the selection, ownership and financing structures of the first European AI Gigafactories, because those decisions will reveal whether InvestAI becomes an instrument for building European-controlled frontier capacity or primarily a mechanism for expanding infrastructure physically situated in Europe. The formal Gigafactory procurement process was launched by EuroHPC in July 2026, with the Commission indicating construction of the first facilities from 2027. European Commission — AI Gigafactories timeline EuroHPC — Gigafactory call
A second decisive record will be implementation of the Cloud and AI Development Act, particularly the final sovereignty framework, permitting mechanism, public-procurement provisions and measurement of whether the target to at least triple EU data-centre capacity is being achieved. European Commission — Cloud and AI Development Act
The third will be utilisation data from AI Factories themselves: the proportion of compute used by European start-ups, established industry, universities and foreign-controlled companies; the number of models reaching commercial deployment; and whether AI Factory users subsequently raise capital and scale within Europe. EuroHPC currently reports the infrastructure footprint but the long-term sovereignty assessment requires economic outcome measures rather than machine counts alone. EuroHPC Joint Undertaking
The fourth concerns national execution. Italy’s IT4LIA system, France’s large infrastructure commitments, Germany’s 2030 data-centre targets and the United Kingdom’s AIRR expansion now have sufficiently explicit capacity objectives that future performance can be assessed against concrete deployment rather than political intention. EuroHPC — Italy Élysée — France AI investment Bundesregierung — Germany Data Centre Strategy UK Government — Compute Roadmap
Who Captures the Value of European AI?
Europe is moving from a regulatory phase into an infrastructure and industrial-capacity phase. The strategic question is no longer whether Europe possesses data or scientific expertise, but whether European compute, energy, capital, cloud infrastructure, models, procurement and industrial adoption can be integrated strongly enough to convert those assets into European-controlled intellectual property, revenues and productive capacity.
Sovereign AI is a production system
Compute must exist at European scale
AI Factories, AI Gigafactories, national supercomputers and expanded data-centre capacity address the physical scarcity of advanced computation that previously constrained European AI development.
Compute must become products and companies
Scientific machines alone do not create sovereignty; start-ups, industrial firms and public institutions must transform European compute into models, software, processes, intellectual property and exportable applications.
Physical localisation is insufficient
A European data centre can still run imported chips, foreign clouds and externally controlled models. Sovereignty depends on control across enough layers of the AI production chain to preserve bargaining power and economic returns.
The European AI value chain
Europe’s emerging compute architecture
| Layer | Mechanism | Verified scale / target | Status | Strategic function |
|---|---|---|---|---|
| Distributed AI compute | EuroHPC AI Factories | 19 factories | DEPLOYING | Access for start-ups, SMEs, researchers, public authorities and industry |
| Regional extension | AI Factory Antennas | 13 antennas | DEPLOYING | Extends services beyond host countries |
| European HPC base | EuroHPC systems | 14 supercomputers | OPERATIONAL / EXPANDING | Scientific, industrial and AI workloads |
| Frontier compute | AI Gigafactories | >100,000 advanced AI processors per facility concept | PLANNED / PROCUREMENT | Very-large-model training and inference |
| Gigafactory financing | InvestAI | €20bn mobilisation objective | MOBILISATION | Public-private de-risking of frontier infrastructure |
| Broader AI investment | AI Continent / InvestAI | €200bn stated ambition | PROGRAMME | Capital, infrastructure and ecosystem expansion |
| Cloud / data-centre capacity | Cloud and AI Development Act | At least 3× EU capacity in 5–7 years | POLICY TARGET | Expand cloud and AI infrastructure availability |
The industrial adoption problem
| EU enterprise category | AI use in 2025 | Interpretation |
|---|---|---|
| All enterprises with 10+ employees | ~20.0% | AI diffusion accelerating, but still far from universal |
| Small enterprises | ~17.0% | The majority remain outside substantial AI adoption |
| Medium enterprises | 30.36% | Meaningful adoption with large additional potential |
| Large enterprises | 55.03% | AI increasingly embedded inside major corporate organisations |
| EU enterprises in 2023 | 8.1% | Pre-acceleration baseline |
| EU enterprises in 2024 | 13.5% | Rapid transition already visible |
National sovereign-AI models
Infrastructure + industrial specialisation
Italy is building sovereign compute around CINECA, Leonardo, LISA and IT4LIA, with a particular opportunity in specialised manufacturing, engineering, health and public-sector AI.
Full-stack AI power strategy
France combines compute, abundant electricity, national AI funding, domestic model developers, cloud-security policy and large private investment commitments.
Industrial AI + data-centre expansion
Germany is linking manufacturing and Mittelstand data with a major national expansion of data-centre and high-performance AI infrastructure.
Sovereign compute outside the EU
The UK provides the clearest external comparator: regulatory autonomy has not reduced the perceived need for large-scale publicly supported AI compute.
Italy: the compute-to-company challenge
| Asset | Verified position | Strategic value | Constraint |
|---|---|---|---|
| Leonardo | Major EuroHPC system hosted by CINECA | National HPC foundation | Commercial conversion |
| LISA upgrade | 166 eight-way GPU servers | Generative AI and large-model capability | Utilisation by firms and scale-ups |
| IT4LIA dedicated AI system | Procurement approximately €290m | Training, inference, RAG, reasoning and simulation | Productisation and market scale |
| IT4LIA environment | >20,000 GPUs expected | Large European public-compute concentration | Talent and late-stage capital |
| Italian AI Strategy | Research, PA, enterprises and skills | Institutional coordination | Execution and measurable adoption |
France: the full-stack strategy
| Component | Verified figure / policy | Strategic role |
|---|---|---|
| National AI strategy | Approximately €2.5bn through France 2030 | Research, talent, ecosystem development and adoption |
| 2025 AI investment commitments | Approximately €109bn announced | Data centres, infrastructure and deployment |
| Energy | Government promotes stable low-carbon electricity availability | Data-centre and compute competitiveness |
| Cloud sovereignty | SecNumCloud framework | Protection of sensitive strategic workloads |
| Industrial strategy | Chips + compute + models + services + robotics | Attempt to retain value across the stack |
Germany: industrial AI at scale
| Indicator | Verified position / target | Strategic meaning |
|---|---|---|
| Current data-centre connection capacity | Approximately 3 GW | Large existing infrastructure base |
| AI-oriented capacity | Approximately 500 MW | Dedicated AI compute footprint |
| Overall data-centre target | At least 2× by 2030 vs 2025 | National cloud and AI scale expansion |
| HPC / AI target | At least 4× by 2030 vs 2025 | Accelerated AI infrastructure expansion |
| HammerHAI | 860 NVIDIA B200 GPUs | Large AI-optimised compute resource |
| HammerHAI inference performance | ~15 exaflops | High-capacity model serving and inference |
| Strategic orientation | Industrial and domain-specific AI | Leverages Mittelstand and manufacturing data |
United Kingdom: external comparator
| Dimension | Verified position | Strategic meaning |
|---|---|---|
| AIRR compute capacity | 21 AI ExaFLOPS in 2025 | Starting public AI-compute base |
| AIRR target | 420 AI ExaFLOPS by 2030 | Twentyfold expansion |
| AIRR commitment | >£1bn | Sovereign compute expansion |
| New national supercomputer | Up to £750m | Frontier AI and scientific workloads |
| Public compute package | Up to approximately £2bn | National-scale strategic infrastructure |
| Open-access model | 50,000 to 1.4 million GPU hours in 2026 call | Commercial and research access pathway |
Semiconductor sovereignty remains incomplete
European progress
- The EU Chips Act has mobilised a major semiconductor policy framework.
- AI Gigafactories create large predictable demand for accelerators and related components.
- European processor design and specialist semiconductor capability can benefit from demand aggregation.
Remaining dependency
- Most frontier AI infrastructure still depends heavily on non-European accelerator ecosystems.
- Imported hardware can create European compute without creating full-stack European sovereignty.
- Substitution capacity and diversified supply remain more realistic objectives than complete autarky.
The infrastructure layers that determine sovereignty
Electricity and grid access
Compute cannot scale without predictable electricity, fast connections and sufficient grid capacity.
Processors and networking
Accelerator concentration remains one of Europe’s most important external dependencies.
Control and portability
Physical localisation does not guarantee strategic control if cloud software, orchestration and switching remain externally concentrated.
Ownership of AI systems
Europe must retain enough foundation and domain-model ownership to capture software and inference value.
Industrial deployment
Productivity gains only appear when models become embedded in manufacturing, health, finance, transport and public services.
Where AI value can leave Europe
| Value-chain stage | European asset | Leakage mechanism | Institutional response |
|---|---|---|---|
| Data | Industrial, public and scientific datasets | Data primarily exploited by external platforms | Trusted access and interoperable data governance |
| Compute | EuroHPC and national infrastructure | Dependence on external accelerator ecosystems | Gigafactories and diversified hardware supply |
| Cloud | European hosting and local providers | Hyperscaler concentration | Portability, sovereignty standards and procurement |
| Models | European researchers and start-ups | Capital and distribution disadvantages | Compute access, scale-up finance, public demand |
| Industrial deployment | Manufacturing and proprietary operational data | External APIs capture margins and know-how | Domain-specific and confidential AI systems |
| Intellectual property | Strong research base | Relocation or acquisition of successful firms | Late-stage European growth capital |
| Revenue | Large EU internal market | Margins accrue outside Europe | European vendors, procurement and competitive infrastructure markets |
Five institutional choices that determine value capture
Institutional decision matrix
| Policy domain | Weak configuration | Strong sovereignty configuration | Observable indicator |
|---|---|---|---|
| Compute allocation | Short, uncertain research grants | Predictable commercial-scale access | European firms training and serving models on EuroHPC |
| Gigafactory finance | Infrastructure subsidy only | Conditional European capability building | European ownership and IP share |
| Cloud policy | Physical data localisation | Portability, control, substitutability and secure EU services | Critical workloads on trusted European infrastructure |
| Industrial AI | Generic external APIs | Confidential domain-specific systems | Manufacturing adoption without data surrender |
| Public procurement | Fragmented tenders | Aggregated interoperable demand | European vendors winning strategic public contracts |
| Late-stage finance | Strong seed funding but weak scaling capital | Deep European growth financing | Lower relocation and forced acquisition rates |
| Semiconductors | Single external accelerator ecosystem | Diversified supply and European processor capability | European-designed hardware share rises |
| Energy | Grid delays and uncertain power | Fast connections and predictable supply | AI facilities delivered without material energy delays |
Europe versus the UK
| Dimension | European Union | United Kingdom |
|---|---|---|
| Public compute structure | EuroHPC + national facilities | AIRR + national systems |
| Distributed access | 19 AI Factories + 13 Antennas | AIRR access programmes |
| Frontier expansion | AI Gigafactories | AIRR expansion + new national supercomputer |
| Compute target | Multiple Gigafactory-scale projects | 21 → 420 AI ExaFLOPS by 2030 |
| Major public mobilisation | €20bn Gigafactory objective | >£1bn AIRR expansion |
| Industrial logic | European strategic autonomy + industrial AI | National sovereign compute + growth strategy |
| Regulatory environment | EU AI Act and single-market framework | Separate UK regulatory architecture |
Indicators that would demonstrate genuine sovereignty
Strategic Net Assessment
Europe has moved beyond the stage in which its AI strategy could be characterised principally as regulation. EuroHPC, 19 AI Factories, 13 AI Factory Antennas, planned Gigafactories, the proposed tripling of data-centre capacity, national programmes in Italy, France and Germany, and the United Kingdom’s parallel sovereign-compute expansion show that compute has become a recognised strategic input alongside data and regulation.
The remaining gap is value capture. European sovereignty is not demonstrated merely because an accelerator is installed inside an EU data centre, because the hardware, orchestration layer, foundation model, intellectual property and resulting revenues may still be controlled externally. The sovereign outcome therefore depends on whether public and private investment produces European scale-ups, European model ownership, trusted cloud capacity, industrial adoption, procurement demand and the ability to retain successful firms through the growth stage.
Italy’s strongest asset is publicly anchored high-performance compute linked to specialised industry; France is attempting the most explicit full-stack strategy by combining capital, electricity, models, cloud-security policy and infrastructure; Germany’s principal opportunity lies in applying very large new compute capacity to proprietary manufacturing and Mittelstand data; the United Kingdom confirms that regulatory autonomy does not remove the need for strategic public compute.
The decisive institutional test is therefore whether Europe integrates data policy, compute, cloud, energy, semiconductors, capital and procurement into a continental production system. If these layers remain fragmented, European data can increase global AI productivity without creating equivalent European economic power. If they converge, Europe possesses a plausible route toward an AI model based less on consumer-platform dominance and more on industrial, scientific and public-sector value creation.
Primary and Institutional Sources
- European Commission — AI Continent
- EuroHPC Joint Undertaking
- European Commission — AI Factories
- European Commission — AI Gigafactories
- European Commission — Cloud and AI Development Act
- Eurostat — Use of Artificial Intelligence in Enterprises
- European Court of Auditors — Special Report 08/2024
- EuroHPC — Italy AI Factory
- EuroHPC — IT4LIA AI System Procurement
- Italian Government — AI Strategy 2024–2026
- France — National AI Strategy
- Élysée — Making France an AI Power
- German Federal Government — Data Centre Strategy
- EuroHPC — Germany AI Factories
- UK Government — UK Compute Roadmap
- UK Government — AI Research Resource

















