EU flags surround an “Article 88bis” document, symbolizing AI, data privacy, security, and regulation.
European privacy group noyb is challenging proposed GDPR changes that would expressly permit legitimate-interest arguments for processing personal data in AI development and operation, warning that the draft could expose historical data to new uses and alter the legal footing of enterprise AI projects if adopted. The dispute concerns legislation under negotiation, not a permission that businesses can use today. For IT teams, the immediate issue is whether a proposed simplification would provide durable legal clarity—or encourage data uses that later become the subject of enforcement and litigation.

The campaign escalated on September 21, when noyb, led by Austrian lawyer Max Schrems, accused EU member states of preparing a “digital expropriation” of Europeans’ information. Its objection targets an AI-specific provision in the EU’s broader Digital Omnibus initiative, which presents changes to digital regulation as a way to improve competitiveness and reduce administrative burdens. Noyb argues that the provision would give commercial AI interests an advantage over individual privacy rights.

The Register reported the criticism on September 22. The important distinction for readers is between the existence of the proposal, which is the subject of the dispute, and noyb’s prediction of its consequences. The campaign’s assertion that vast amounts of previously collected information would become available for AI use is its legal and political assessment—not an enacted rule or a court’s conclusion.

GDPR Article 88bis puts AI’s legal basis at the centre of the dispute​

The disputed provision began as proposed Article 88c and is identified as Article 88bis in the Council negotiating document described by noyb. Those identifiers matter: this is a proposed addition to the General Data Protection Regulation, not an existing GDPR article granting AI developers a new exemption.

The wording quoted by The Register says that, where processing personal data is necessary for a controller’s interests “in the context of the development and technical operation of an AI system” or an AI model, that processing “may be pursued for legitimate interests.”

In practical terms, the proposal concerns the justification an organisation would give for using personal information. Consent involves asking people to agree to processing. A legitimate-interest justification relies on another legal basis; the controversy is over how much weight an AI-related commercial interest should receive when it encounters individuals’ rights.

Noyb’s central objection is that “in the context of AI” describes a technology broadly, rather than a narrowly bounded reason for processing particular information. The group says that language could legitimise uses extending well beyond the circumstances in which people originally supplied their data. Its September statement specifically raises information entered into chats or social media years earlier, including information about people who have never been customers of the AI company concerned.

That is the enterprise significance of the wording. The question is not simply whether a company can obtain a dataset. It is whether using that dataset for a new AI-related activity has an adequate legal justification. A provision that expressly recognises AI development and operation could influence that decision even without requiring any change to the software processing the information.

The breadth of the latest negotiating text remains decisive. The quoted sentence establishes the proposed legitimate-interest route, but it cannot by itself resolve the extent of any exceptions, safeguards or balancing requirements in the complete provision. Noyb’s sweeping interpretation should therefore remain attributed to the campaign.

Noyb’s historical-data warning reaches beyond AI customers​

Noyb argues that the greatest beneficiaries would be companies already holding large stores of personal information. Its concern is retrospective in effect: information collected over many years could acquire a new commercial use because an organisation places that use within AI development or operation.

Schrems put the objection starkly: “Under these proposals, the profits of AI companies would trump Europeans’ fundamental right to privacy.” The campaign also argues that the economic benefits would favour large technology providers with substantial datasets and the resources to build AI systems. Those are noyb’s predictions about the proposal’s effects, not measured outcomes.

The warning about noncustomers is especially important. A person’s information can appear in material supplied by someone else: the campaign’s examples include chats and social media. Consequently, restricting attention to the people who directly signed up for an AI service would miss part of the population noyb says could be affected.

For an enterprise, this points to a distinction worth preserving in any assessment: possession of information and justification for a new use are separate questions. The business case for reusing an archive does not, on its own, answer the privacy question raised by that reuse. Noyb’s objection is that an AI-specific rule could make that second question too easy to answer in a provider’s favour.

The supplied reporting identifies no corresponding change to Microsoft 365, Copilot, Azure or another Microsoft service. This is a legislative story with potential implications for providers and customers across the software industry. It should not be read as an announcement that a particular vendor has changed its training practices or obtained new access to customer content.

The Digital Omnibus remains a negotiation, not an implementation deadline​

The timing changes the advice for administrators and developers. Noyb describes a proposal being considered by member states under the Irish Council presidency. The Irish Times likewise reported on September 21 that the group was urging member states to reject proposed changes and that governments were expected to submit their views by the end of that week. That is a negotiating milestone, not a GDPR commencement date.

Noyb claims there is broad informal support among member states for the direction of the AI provision. Its statement also describes the European Parliament’s position as mixed. Neither description establishes an agreed final text, a completed legislative process or a date on which organisations could rely on a new rule.

The Commission’s stated objective, as reported by The Register, is to improve competitiveness and lighten regulatory burdens. Noyb disputes whether the proposed approach would deliver useful simplification. It argues that giving AI processing preferential treatment could instead create a fundamental-rights conflict and further legal uncertainty.

These positions concern different measures of success. A provision might appear helpful to a developer seeking a clearer justification for processing data, while still being objectionable to a privacy organisation that believes the justification gives insufficient weight to individuals. Whether the eventual text achieves both legal clarity and adequate protection depends on its actual boundaries—not the label “simplification.”

For now, there is no supported basis for treating the proposal as permission to expand a dataset, change an existing processing purpose or remove a consent requirement. Organisations can assess the implications of a prospective rule without anticipating its enactment.

Schrems raises a litigation risk without announcing a new case​

The prospect of litigation gives the criticism additional weight, but it needs careful framing. Schrems is associated with the legal challenges that resulted in the Court of Justice of the European Union invalidating the Safe Harbor transatlantic data-transfer arrangement in 2015 and the Privacy Shield arrangement in 2020, as The Register recounts. Those outcomes explain why his warning attracts attention.

They do not determine the fate of this proposal. The earlier disputes concerned transatlantic data-transfer frameworks; the present controversy concerns an AI-related provision in proposed data-protection legislation. A future challenge would have to address the law actually adopted and the legal questions presented by that measure.

Noyb’s statement raises the courts as a possible route if legislators approve a provision the campaign regards as incompatible with fundamental rights. It does not announce a judgment against Article 88bis or establish that a challenge to a final law has been filed.

The practical risk identified by Schrems is reliance on a rule whose durability may later be contested. For an organisation planning a long-lived AI project, legislative approval and stable legal foundations are related but distinct considerations. That makes the final wording, and any subsequent authoritative interpretation, more important than an early political claim that the problem has been solved.

Enterprise AI teams should preserve today’s data-use boundaries​

Keep current approvals and data-use restrictions in place while the proposal is negotiated. The useful work now is to identify which planned AI activities would actually depend on the disputed provision, rather than treating a broad policy announcement as an operational change.

This is a governance review, not a new Windows configuration task. The reporting supplies no tenant setting, software update or product-specific procedure to apply. The following decisions flow from the proposal’s status and the scope of noyb’s objection:

  • Treat Article 88c and Article 88bis as identifiers for a proposed provision, not as a currently available authorisation for AI processing.
  • Ask anyone proposing a new use of historical personal data to identify the justification that applies today, rather than relying on expected legislative changes.
  • Include information about noncustomers when assessing an AI dataset; noyb’s warning expressly extends beyond people who directly use an AI provider’s service.
  • Separate claims about the GDPR proposal from claims about a vendor’s actual data practices, because this reporting announces no Microsoft product or contractual change.
  • Reassess affected plans against an adopted text and its applicable timing, rather than against statements of informal political support or predictions about litigation.

The next meaningful decision point is the wording that emerges from the legislative negotiations. Until then, noyb has established a concrete objection to a proposed AI-specific processing rule, not a change in what enterprise systems may do today. Organisations that preserve the distinction between existing authority and prospective permission will be better placed to evaluate the eventual law without having already committed their data to its most expansive interpretation.