Skip to main content

Deregulating the Moat

Europe’s AI-data debate, incumbent advantage, and the sovereignty problem inside the Digital Omnibus

A quiet European archive of identical filing cabinets and binders opens through a doorway onto a long warehouse aisle of stacked crates and server racks; one signal-red valve sits on a pipe at the threshold.
  • Legitimate interest can already support AI under existing GDPR doctrine, subject to a three-step, case-specific test. The Omnibus debate is about encouragement, presumption and safeguards—not inventing that legal basis.
  • The 3 September Presidency draft stripped AI-specific safeguards from the operative article without making all AI processing automatically lawful. Germany went further with a presumption for AI training and technical operation.
  • Viral claims overstate the file on balancing, personalised ads, Article 15 access and “almost all” AI HQs in Ireland. The 7% Meta figure is real but narrow: Gallup, n=1,000 German Meta users via noyb.
  • ST 13112/26 (20–21 Sep) exists on the Council register but is not public. Distinguish line-by-line reading of ST 12535/26 from secondary reporting (Privacy Next / EDRi). The file is still moving.
  • OECD and competition-authority work supports a stronger competition concern: data, compute, distribution and feedback loops can reinforce incumbent advantage when permission to exploit existing stocks expands.
  • Permission does not create sovereignty. Capacity, contestability and optionality do. Europe’s AI constraints also include capital, cloud concentration, compute and deployment—not data protection alone.
If a regulation is relaxed equally for every market participant, does that make the market more competitive?

Not necessarily. Equal legal permission can raise the return on complementary assets incumbents already control—data stock, compute, distribution—while startups receive permission without possession. Competitiveness depends on who can capture the value of the new rule.

When does legal certainty for AI become technology-specific privilege?

When legislation singles out AI as a preferred category for legitimate interest while stripping bespoke safeguards from operative law. Certainty can be useful; a one-way legal signal for a huge technological category is a different policy choice.

Which AI-data safeguards belong in binding law rather than ordinary GDPR balancing?

That is the live negotiation. The Commission’s original Article 88c put minimisation, transparency and an unconditional right to object in operative text. The 3 September draft moved toward generic safeguards. Where those lines sit changes enforcement and expectations.

How much of Europe’s AI gap is genuinely about GDPR?

Less than viral posts imply. Private AI investment, scale-up financing, hyperscaler cloud share, compute and data-centre capacity, and enterprise adoption all constrain European position. Data rules matter; they are not the whole system.

Can a policy be pro-innovation and still increase incumbency?

Yes. Lowering fixed compliance costs can help smaller firms while expanding the exploitable value of historic datasets helps whoever already holds those assets. The same amendment can do both at once.

What would digital sovereignty mean if measured by optionality rather than geography?

Whether Europe can finance firms, obtain compute without strategic dependency, reach customers without someone else’s gate, switch providers without losing the ability to operate, and enforce rules without making domestic challengers structurally uncompetitive.

Your trail
Reading tools
Publication record
Author
Thierry Gilgen
Edition
2
Published
2026-09-26
AI assistance
Not recorded
Editorial review
Not recorded
Structured source record
No structured sources recorded. Inline citations are separate.
Edition change
Publication image updated
SHA-256
8267afe5d43dc665653de59cf5bad2799a7c0a39d139c9c0eed57efd1f5446a3

A checksum identifies the recorded text and metadata. It does not certify the truth of a claim or the contents of external links.

Thierry Gilgen. Deregulating the Moat. Edition 2. 2026-09-26. https://www.thierry-gilgen-ict.ch/field-notes/deregulating-the-moat

Edition history

Thierry Gilgen. Deregulating the Moat. Edition 2. 2026-09-26. https://www.thierry-gilgen-ict.ch/field-notes/deregulating-the-moat

Research note. This is a moving legislative file. The Council of the EU circulated a new Presidency compromise, ST 13112/26, on 20–21 September 2026 and discussed it in the Antici Group on 25 September. The Council register confirms the document exists but does not make its contents public. Where this volume discusses that latest iteration, it explicitly distinguishes direct evidence from reporting and stakeholder analysis. The 3 September Presidency draft, ST 12535/26, is available in leaked form and can be checked line by line.

A LinkedIn post by Matthias Neumayer pushed me into a rabbit hole.

Its accusation is simple: while Europe talks about digital sovereignty, politicians in Ireland and Germany are trying to weaken European data protection rules so that AI companies can use personal data more freely. The post argues that this is being sold as simplification for European businesses but would, in practice, hand an advantage to the companies that already possess decades of personal data, immense compute and global distribution.

It is an angry post.

Parts of it are overstated.

The underlying question is not.

After reading the Commission proposal, the leaked Council compromise, Germany’s written amendments, the EDPB and EDPS opinions, the latest Council register entries, competition research, AI investment data and Europe’s own competitiveness plans, I think the real issue is more interesting than the outrage.

The question is not simply whether Europe should regulate AI more or less.

The question is:

When a legal constraint is relaxed for everyone, who is actually in a position to capture the value of that new permission?

That is where sovereignty enters the story.

And that is where a policy intended to improve European competitiveness can produce effects that are very different from its stated purpose.

What is actually happening

The European Commission proposed its Digital Omnibus in November 2025. The package is broad. It amends several pieces of EU digital legislation and is explicitly presented as a simplification exercise: less administrative burden, more legal certainty and better conditions for innovation and competitiveness.1

One part of that proposal concerned personal data used in AI.

The Commission proposed a new GDPR Article 88c. In simplified terms, it said that processing personal data in the development and operation of an AI system or model could rely on the GDPR’s legitimate-interest legal basis, where the conditions of Article 6(1)(f) were satisfied.2

The Commission did not propose a blank cheque.

Its text also contained AI-specific safeguards. These included data minimisation during source selection, training and testing; protection against disclosure of data retained in models; enhanced transparency; and an unconditional right to object.2

That proposal was already controversial.

The European Data Protection Board and European Data Protection Supervisor responded in February 2026 with an important clarification: legitimate interest can already be used for AI today. It is not a new concept created by the Omnibus.3

Under existing GDPR doctrine, relying on legitimate interest requires a three-part assessment:

  1. there must be a real and lawful legitimate interest;
  2. the processing must be necessary for that interest; and
  3. the controller’s interest must be balanced against the interests, rights and freedoms of the people whose data is being processed.4

The EDPB’s 2024 opinion on AI models makes this explicitly case-specific. The source of the data, whether it was public, the privacy settings under which it was posted, the relationship between the person and the controller, reasonable expectations, the amount of data, and possible downstream consequences can all matter.4

That baseline matters because some of the public discussion makes it sound as if the EU is deciding whether AI may ever rely on legitimate interest.

It already can.

The argument is about how much legal encouragement, presumption and special treatment AI should receive — and what safeguards remain attached to that treatment.

The September draft changed the balance

The controversy that exploded this week came largely from a leaked Council Presidency compromise dated 3 September 2026, document ST 12535/26.5

Ireland currently holds the rotating Presidency of the Council of the EU. In that role it drafts compromise texts between member-state positions. That is important institutional context: a Presidency compromise is not automatically identical to the Irish government’s own preferred national position. It is a negotiating document intended to find a Council majority.

Still, the text matters.

The 3 September draft renamed the AI provision Article 88bis and substantially stripped back the Commission’s original AI-specific protections.

The operative text still tied AI processing to Article 6(1)(f), the ordinary legitimate-interest provision. But the Commission’s explicit language around AI-specific data minimisation, enhanced transparency and the unconditional right to object was deleted from the operative article. A much more generic requirement for “appropriate technical and organisational measures and safeguards” remained.5

This is a meaningful shift.

But it is not the same thing as saying that all AI processing automatically becomes lawful.

The draft still cross-referenced Article 6(1)(f). Its accompanying recital also preserved the idea that a controller has to choose an appropriate legal basis and that the interests and fundamental rights of the data subject can override the controller’s interest.5

That distinction is not semantic.

It is the difference between:

AI may use legitimate interest under the GDPR framework.

and:

Anything involving AI is automatically lawful.

The first is close to what the 3 September text actually says.

The second is advocacy shorthand.

There is still a serious policy question in the first formulation. In fact, it may be the more interesting one.

By writing AI explicitly into the GDPR as a category for which legitimate interest may be used — while removing bespoke safeguards — lawmakers would be sending a legal signal to controllers, regulators and courts that AI development and operation deserve special consideration.

EDRi, a digital-rights network opposed to the change, makes this point carefully: the concern is not that the words literally legalise every use of personal data involving AI, but that legislation would single out a huge technological category and give it a preferred direction of travel.6

That is a much stronger criticism than pretending the rest of the GDPR disappears.

Germany proposed something more aggressive

Germany’s written drafting suggestions of 17 August 2026 go further than the 3 September Presidency compromise.7

Germany proposed that processing personal data for the training and technical operation of AI shall be presumed to be a legitimate interest.

That word — presumed — matters.

It would shift the starting point of the analysis.

Germany also proposed a presumption that data collected for other purposes could be compatible with reuse for AI, subject to conditions and safeguards.7

And Germany proposed limiting several data-subject rights where compliance would be impossible or involve disproportionate effort. The rights explicitly named in that August document are:

  • Article 14 — information where data was not obtained directly from the person;
  • Article 16 — rectification;
  • Article 17 — erasure;
  • Article 18 — restriction of processing.7

One detail in the LinkedIn post is therefore too broad: the German text I could verify does not remove or narrow the Article 15 right of access in that provision. It affects information, correction, erasure and restriction.

There is also a separate German proposal concerning complaints.

In a Council working document circulated in January 2026, Germany suggested changing Article 57 so that supervisory authorities could investigate a complaint from a data subject at their discretion, to the extent appropriate. Germany’s stated rationale was that authorities face rapidly growing complaint volumes and need the ability to terminate minor proceedings so that resources can be concentrated on more consequential cases.8

So the claim that Germany has pushed for more discretion in complaint handling has a documentary basis.

But it comes from a different German submission and a different part of the Omnibus debate.

Bundling all of these proposals into one sentence makes the politics sound simpler than the document trail actually is.

Then the text moved again

This is the part that matters most for anything published now.

The 3 September draft is not the latest Council text.

A new Irish Presidency compromise, ST 13112/26, was created on 20 September, entered the Council register on 21 September and was prepared for an Antici Group meeting on 25 September.9

The Council’s public register confirms all of that.

It does not disclose the text.9

That means anyone claiming to know the exact current Council wording either has access to the restricted document or is relying on someone who does.

Two organisations looking at the latest text from very different perspectives provide useful triangulation.

Privacy Next, which argues that the Council is losing sight of the competitiveness purpose of the Omnibus, says the latest compromise removed the operative AI provision and now recognises legitimate interest for AI in the recitals, alongside factors relevant to the balancing exercise.10

EDRi, which approaches the same file from a fundamental-rights perspective, says the 21 September revision improved some elements but left the basic concern unresolved: AI is still specifically identified as a context in which legitimate interest may be used.6

Those analyses disagree sharply about whether the latest text is too cautious or too permissive.

But they agree on something important:

the current negotiation is no longer accurately described by simply quoting the 3 September Article 88bis as if it were the final Council position.

As of 26 September, the file is still moving.

The European Parliament procedure is also unfinished. The Parliament’s Legislative Observatory lists the proposal as awaiting committee decision under the ordinary legislative procedure.11

Nothing discussed here is current law.

A claim-by-claim audit

The post that triggered this research captures several real developments, but some of its strongest lines collapse distinct legal questions into slogans.

ClaimWhat the evidence supports
“Any processing of personal data in the context of AI counts as a legitimate interest.”The 3 September Presidency text explicitly allowed AI development/operation to use legitimate interest under Article 6(1)(f). Germany proposed an actual presumption. The latest 20–21 September text is not public; reporting says the operative article was removed while AI/legitimate-interest language remains in recitals.
“No consent.”Too categorical. Legitimate interest is an alternative legal basis to consent, so consent would not always be required under the GDPR. But other EU or national rules can still require consent, and the ePrivacy regime independently requires consent in many cases involving access to information on a user’s device.12
“No case-by-case balancing.”Not an accurate description of the 3 September Presidency text. It cross-references Article 6(1)(f), and the recital retained balancing logic. Germany’s presumption proposal comes closer to changing the starting point. The EDPB insists Article 6(1)(f) requires a case-by-case three-step test.3
“Every piece of personal data a company can get its hands on.”Overstated as law. A lawful basis is only one GDPR requirement; purpose limitation, fairness, data minimisation, special-category rules and data-subject rights still matter. But a more permissive legitimate-interest rule could materially broaden the ability to reuse data obtained outside a direct customer relationship.
“Private social-media posts from 15 years ago.”Not automatically lawful. The EDPB specifically treats source, privacy settings, relationship, reasonable expectations and context as relevant to balancing. Old or private data can therefore present a very different case from recent public material.4
“Personalised ads without consent are illegal today; add AI and they become legal.”Too simple. Behavioural advertising can involve both GDPR and ePrivacy. Accessing or storing information on terminal equipment generally requires consent under ePrivacy, subject to exceptions. An AI-related GDPR basis would not automatically erase that separate requirement.12
“Germany wants a presumption that AI is lawful.”Substantially supported, with narrower wording: Germany proposed a presumption of legitimate interest for AI training and technical operation, not a blanket presumption that every legal requirement is satisfied.7
“Germany wants weaker access or correction rights.”Partly supported. The August text explicitly weakens the application of Articles 14 and 16–18 in some circumstances. Article 15 access is not included in that clause.7
“Authorities would no longer be obliged to handle complaints.”Germany separately proposed giving DPAs discretion over how far to investigate individual complaints, with the stated aim of prioritising resources. That is not the same as abolishing the right to complain.8
“Only 7% of German Meta users want their data used for AI training.”Supported with an important qualifier. Gallup surveyed 1,000 Meta users in Germany for noyb in 2025; 7% answered that they wanted their Facebook or Instagram data used for AI training, 66% did not, and 27% did not care.13
“Almost all US and Chinese AI companies are headquartered in Ireland.”Too broad to substantiate. Ireland is unquestionably a major EU regulatory hub for global technology firms. The Irish DPC says it is lead supervisory authority for many global tech companies headquartered there and names Airbnb, Apple, DeepSeek, Google, LinkedIn, Meta, Microsoft, OpenAI, Pinterest, TikTok and X among firms whose AI it has supervised.14 That does not establish “almost all US and Chinese AI companies.”

This matters because the argument does not need the exaggerations.

The documented version is already consequential.

Legitimate interest is not the novelty

The phrase “legitimate interest” sounds like a loophole if read in isolation.

It is not.

It is one of the GDPR’s ordinary legal bases, and European regulators have already said that AI development or deployment can rely on it in appropriate circumstances.4

Meta’s attempt to train AI using European Facebook and Instagram data is a useful example. Meta relied on legitimate interest before the Digital Omnibus existed. The Irish Data Protection Commission scrutinised the proposal, sought an EDPB opinion and required changes around transparency, objections and safeguards.15

The DPC’s new AI Insights Report, published on 25 September 2026, says it engaged with around 180 AI products and services between 2021 and 2025. It explicitly identifies lawful basis, transparency, data minimisation and protection of children as recurring regulatory issues.14

So the interesting question is not:

Can legitimate interest and AI coexist?

They already do.

The real questions are:

  • Does AI need an explicit privileged mention in legislation?
  • Does a broad technology category provide meaningful legal certainty, or simply move the uncertainty into a later balancing test?
  • Which safeguards belong in binding operative law rather than recitals or general GDPR principles?
  • And what happens competitively when the cost of using very large existing datasets falls?

That last question is where the sovereignty argument becomes much stronger.

The asymmetry nobody should ignore

Imagine a rule prevents everyone from exploiting a particular asset freely.

Now remove some of that restriction.

On paper, everyone has received the same freedom.

Economically, they have not received the same value.

The value depends on how much of the underlying asset they already possess and whether they have the infrastructure to exploit it.

For AI, a useful conceptual model is:

Value of expanded data permission ≈ legal permission × data stock × compute × distribution

It is not an econometric formula.

It is a way of seeing the system.

A startup and a platform with three billion users may receive the same legal permission.

The platform already has years of behavioural data, social graphs, photographs, messages or interactions, mature identity systems, enormous compute contracts, proprietary models and direct access to users.

The startup has permission.

The incumbent has permission plus possession, processing capacity and distribution.

That difference is not theoretical.

The OECD’s 2026 report on AI markets identifies proprietary datasets, data feedback loops, high fixed costs, cloud infrastructure, compute and downstream distribution as potential sources of durable incumbent advantage. It specifically warns that concentration of data and other critical inputs can reduce the ability of new entrants to train competitive models.16

The UK Competition and Markets Authority reached a similar conclusion in its foundation-model work. It identified data, compute and expertise as critical inputs and warned that powerful incumbent firms can combine control of those inputs with existing routes to market such as search, social media, mobile ecosystems and productivity software.17

This is the part of the LinkedIn argument that survives the fact-checking particularly well.

Not because foreign firms are uniquely capable of benefiting from relaxed rules.

European banks, retailers, insurers, telecom companies, publishers, industrial firms and public-sector organisations may also possess valuable historical datasets.

And startups can benefit from greater legal certainty because compliance costs are often fixed costs that hurt smaller organisations disproportionately.

But the distribution of the benefit is still asymmetric.

A rule that increases the economic value of existing data also increases the value of having accumulated existing data.

That is an incumbency effect.

It exists regardless of the nationality of the incumbent.

Europe’s AI gap is bigger than GDPR

This is also why the argument becomes misleading if it treats data protection as the main explanation for Europe’s AI position.

Europe has a data problem.

It also has a capital problem.

A compute problem.

A cloud-concentration problem.

A scale-up financing problem.

A deployment problem.

An energy and data-centre capacity problem.

And a fragmented-market problem.

The numbers are uncomfortable.

Stanford’s 2026 AI Index estimates $285.9 billion in private AI investment in the United States in 2025. The comparable country figures were $5.9 billion for the United Kingdom, $4.36 billion for France and $3.89 billion for Germany. US private investment in generative AI alone reached $163.6 billion; China and Europe combined were estimated at $4.7 billion.18

Private-investment statistics do not capture all Chinese state-directed investment, so they should not be read as a complete measure of national AI capacity.

But they make the scale difference obvious.

European firms also operate on infrastructure that is itself heavily concentrated in non-European providers.

Synergy Research estimated that AWS, Microsoft and Google together held 70% of the European cloud infrastructure market in 2024, while European providers collectively held about 15%. The largest European providers, SAP and Deutsche Telekom, were each around 2%.19

Capital markets show another gap.

The European Investment Bank finds that EU scale-ups raise around 50% less capital than comparable San Francisco firms by their tenth year, and that US venture-capital investment is six to eight times higher than in the EU. More than four out of five EU scale-up deals in its sample involved a foreign lead or sole investor.20

Europe’s own AI strategy implicitly acknowledges these structural constraints.

The Commission’s AI Continent Action Plan is built around large-scale compute, AI factories, gigafactories, data access and deployment. It aims to mobilise €200 billion for AI, including €20 billion for up to five AI gigafactories, and to at least triple EU data-centre capacity over five to seven years.21

The Commission says only 13.5% of EU companies currently use AI.21

That is not the profile of a problem that can be reduced to one sentence about GDPR.

The strongest case for simplification

A serious analysis has to acknowledge the other side.

Europe’s digital rulebook is complex.

AI makes several existing GDPR concepts unusually hard to operationalise at scale.

A model may be trained on billions of data points collected from heterogeneous sources. Identifying each data subject, establishing context, communicating individually, removing one person’s contribution after training, or determining whether information remains personal at each stage of a distributed processing chain can be technically and legally difficult.

The EDPB itself recognises that personal data may be difficult to remove once embedded in a trained model.3

The Commission argues that the Digital Omnibus is intended to reduce compliance cost while preserving the regulatory objectives of the underlying laws.1

The EDPB and EDPS do not reject simplification or competitiveness as goals. Their joint opinion explicitly supports genuine simplification where it increases legal certainty without lowering fundamental protections.3

The business argument is also not frivolous.

A large incumbent can employ armies of lawyers, privacy engineers and policy staff. A twenty-person European AI company cannot.

Ambiguous regulation can therefore itself be regressive: the fixed cost of interpreting uncertain rules can become another moat.

And the unconditional right to object proposed by the Commission raises a real engineering problem if satisfying one objection requires retraining a model or if the original data can no longer be reliably isolated.

There is a legitimate debate about how to make these rights effective rather than symbolic.

None of that requires pretending that privacy protection is costless.

Nor does it prove that the most permissive proposed wording is economically neutral.

Both can be true:

Europe can have real regulatory friction.

and

removing that friction can disproportionately increase the value of assets concentrated in incumbents.

This is precisely why “regulation versus innovation” is such a weak frame.

It hides distribution.

The sovereignty paradox

Digital sovereignty is often discussed as though it were a procurement choice.

Buy European cloud.

Host data in Europe.

Use a European model.

Avoid an American platform.

That is too shallow.

Sovereignty is ultimately about optionality.

Can Europe finance its own firms?

Can they obtain compute without strategic dependency?

Can they reach customers without going through somebody else’s gate?

Can they access useful data without needing to own the platform that generated it?

Can institutions change provider without losing the ability to operate?

Can European companies scale without selling themselves or relocating because the capital is somewhere else?

Can Europe enforce its own rules without making domestic challengers structurally uncompetitive?

Those questions connect capital markets, energy, compute, cloud, data, competition and regulation.

They cannot be answered by privacy law alone.

That is why the most interesting weakness in the current Omnibus debate is not that Europe is considering simplification.

Simplification may be useful.

The weakness is the assumption that permission and capacity are the same thing.

They are not.

Giving a European startup more freedom to process data does not give it Meta’s social graph.

It does not give it Google’s search history.

It does not give it Microsoft’s enterprise distribution.

It does not give it Amazon’s cloud.

It does not give it OpenAI’s capital relationships or compute commitments.

And it does not give it the balance sheet required to train a frontier model.

At the same time, keeping every existing rule exactly as it is does not magically create a competitive European AI industry either.

The symmetry breaks in both directions.

The real system contains both regulatory cost and concentrated capability.

Ireland is not just a footnote

Ireland’s role deserves more precision than the social-media version provides.

The country is not secretly writing GDPR law for Big Tech.

It holds the rotating Presidency of the Council of the EU and is therefore responsible for brokering compromise among member states during the second half of 2026.

But Ireland is also unusually important in European technology regulation because many global technology companies have major European entities there.

The Irish Data Protection Commission describes itself as the EU lead supervisory authority for many of the world’s leading technology companies with European headquarters in Ireland. Its new AI report names Apple, Google, LinkedIn, Meta, Microsoft, OpenAI, TikTok and X among the companies whose AI products or services it has supervised, alongside others including DeepSeek.14

This creates an institutional reality worth acknowledging without inventing motive.

Ireland has extraordinary exposure to both sides of the European digital-policy problem:

  • it hosts major global technology businesses;
  • and its regulator carries unusually heavy responsibility for enforcing European data-protection law against them.

That creates experience.

It also creates scrutiny.

Neither fact proves regulatory capture.

Neither can simply be ignored.

What this debate is really testing

The Digital Omnibus is being described as simplification.

But the AI-data dispute exposes a deeper question about what Europe means by competitiveness.

There are at least three different problems that are often folded into that one word.

Problem one: regulatory friction

Rules can be duplicated, unclear, inconsistent or disproportionately expensive to apply.

That can reduce investment and hurt smaller firms.

Problem two: access to productive inputs

AI firms need compute, capital, energy, talent and data.

A legal regime can make some of those inputs easier or harder to use.

Problem three: market structure

Even if regulation becomes perfectly clear, firms do not begin from equal positions.

Some control cloud infrastructure.

Some control app stores, operating systems, search engines, social networks, enterprise software or massive proprietary datasets.

Some control none of them.

These problems interact.

But solving one does not automatically solve the others.

A simplification that lowers compliance costs may help new entrants.

A change that increases the exploitable value of historic data may help incumbents.

The same legal amendment can do both at once.

That is why the effect cannot be inferred from the label deregulation.

You have to ask who owns the complementary assets.

Permission, possession, capacity, contestability

The Digital Omnibus debate becomes much easier to reason about if four questions are separated.

Permission

What does the law allow a company to do with data?

This is where legitimate interest, consent, purpose limitation and data-subject rights live.

Possession

Who already has the relevant data?

Is it widely available, publicly accessible, held by the data subject, locked inside an incumbent platform, or distributed across institutions?

Capacity

Who can turn that data into economic value?

That means compute, capital, models, engineering talent and infrastructure.

Contestability

Can another company realistically challenge the incumbent?

Can it obtain equivalent inputs?

Can users move?

Can datasets be ported?

Can distribution channels be accessed on fair terms?

Can a startup scale before it is forced into dependency on the firms it is supposed to challenge?

A sovereignty analysis that looks only at permission is incomplete.

So is a privacy analysis that ignores market structure.

And so is a competitiveness analysis that treats all companies as if they receive the same value from the same rule.

Where I land

The angry LinkedIn post is not a reliable legal summary.

But dismissing it because some lines are overstated would miss the more important issue it points toward.

The 3 September Council draft did not make every AI use automatically lawful.

The GDPR balancing test did not simply disappear.

Consent would not cease to exist across European law.

AI would not magically legalise every form of personalised advertising.

And the latest Council text has already moved again.

Those corrections matter.

Yet the underlying concern remains rational and evidence-based:

a legal change that makes large existing pools of personal data easier to exploit can have asymmetric competitive effects because those pools — together with the compute and distribution needed to monetise them — are not evenly distributed.

Competition authorities already identify data, compute, distribution and platform integration as sources of AI market power.

Europe’s own economic institutions already identify the capital and scale-up gap.

Europe’s own AI strategy already identifies the compute and data-centre gap.

And Europe’s cloud market is already dominated by three US hyperscalers.

That does not prove that stricter data law creates sovereignty.

It does not prove that looser data law destroys it.

It proves something more useful:

data protection and sovereignty cannot be analysed independently of market structure.

The phrase “simplification for European business” is therefore not enough.

Neither is “protect our data.”

Both are incomplete descriptions of a system.

The meaningful question is who gains new optionality when the rule changes.

If the answer is mostly firms that already own the data, the compute and the route to market, then a formally neutral deregulation can reinforce an unequal starting position.

If the answer includes smaller European firms because uncertainty and fixed compliance costs genuinely fall, that benefit should also be counted.

This is not a morality play.

It is an allocation problem.

And it leads to a principle I think is worth keeping:

Permission does not create sovereignty. Capacity, contestability and optionality do.

Europe can simplify rules.

Europe can protect rights.

Europe can invest in compute, capital and infrastructure.

These are not interchangeable levers.

Treating them as though they are is how a competitiveness policy ends up solving the wrong problem.


Sources

This volume distinguishes primary documents that can be checked line by line from secondary reporting on texts that are not public. The 3 September Presidency compromise, ST 12535/26, is available in leaked form. The 20–21 September compromise, ST 13112/26, is confirmed on the Council register but its contents are not public; descriptions of that iteration rely on Privacy Next and EDRi and remain secondary until the text is released. Nothing discussed here is current law. The incumbency and moat framing is an analytical synthesis from competition, cloud and investment evidence — not a finding by a court or authority that the Omnibus creates a moat. Evidence cutoff: 26 September 2026, 12:00 CEST (Europe/Zurich). The accompanying source register documents claim audits and verification limits.

Footnotes

  1. European Commission, Digital Omnibus Regulation Proposal, 19 November 2025. https://digital-strategy.ec.europa.eu/en/library/digital-omnibus-regulation-proposal ↩ ↩2

  2. European Commission, COM(2025) 837 final, proposed Article 88c. https://eur-lex.europa.eu/legal-content/EN/ALL/?uri=COM%3A2025%3A837%3AFIN ↩ ↩2

  3. EDPB & EDPS, Joint Opinion 2/2026 on the Digital Omnibus, 11 February 2026, especially paras. 41–45. https://www.edpb.europa.eu/system/files/2026-02/edpb_edps_jointopinion_202602_digitalomnibus_en.pdf ↩ ↩2 ↩3 ↩4

  4. EDPB, Opinion 28/2024 on certain data protection aspects related to the processing of personal data in the context of AI models, 18 December 2024. https://www.edpb.europa.eu/documents/opinion-of-the-board-art-64/opinion-282024-on-certain-data-protection-aspects-related-to_en ↩ ↩2 ↩3 ↩4

  5. Council of the EU, Presidency revised compromise ST 12535/26, 3 September 2026, leaked copy published by noyb. https://noyb.eu/sites/default/files/2026-09/Draft%20Compromise.pdf ↩ ↩2 ↩3

  6. European Digital Rights (EDRi), Simplification for whom?, 24 September 2026. https://edri.org/our-work/simplification-for-whom-open-letter-uphold-gdpr-protections-in-data-omnibus/ ↩ ↩2

  7. Germany, Council working document WK 11020/2026 ADD 4, 17 August 2026, drafting suggestions published by noyb. https://noyb.eu/sites/default/files/2026-09/Omnibus_VII_-_comments_by_DE.pdf ↩ ↩2 ↩3 ↩4 ↩5

  8. German drafting suggestions on GDPR complaint handling reproduced in Council working document WK 1701/2026 ADD 1, 30 January 2026. https://data.consilium.europa.eu/doc/document/WK-1701-2026-ADD-1/en/pdf ↩ ↩2

  9. Council of the EU public register, ST 13112/26, Presidency revised compromise, 20–21 September 2026, for Antici meeting 25 September; content not public. https://www.consilium.europa.eu/en/documents/public-register/public-register-search/?AllLanguagesSearch=false&DocumentLanguage=EN&DocumentNumber=13112%2F26&OnlyPublicDocuments=false ↩ ↩2

  10. Privacy Next, Digital Omnibus Negotiations: Is the Council Losing Sight of the EU’s Competitiveness Agenda?, 24 September 2026. https://www.privacynext.eu/resources/digital-omnibus-negotiations-is-the-council-losing-sight-of-the-eus-competitiveness-agenda/ ↩

  11. European Parliament Legislative Observatory, procedure 2025/0360(COD). https://oeil.europarl.europa.eu/oeil/en/procedure-file?reference=2025%2F0360%28COD%29 ↩

  12. European Commission staff analysis of Article 5(3) ePrivacy Directive; see also Directive 2002/58/EC. https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=celex%3A52025SC0836 ↩ ↩2

  13. noyb / Gallup, Meta AI Training Report, 7 August 2025; n=1,000 Meta users in Germany. https://noyb.eu/en/noyb-survey-only-7-users-want-meta-use-their-personal-data-ai ↩

  14. Irish Data Protection Commission, AI Insights Report, 24–25 September 2026. https://dataprotection.ie/en/dpc-guidance/publications/dpc-AI-insights-report ↩ ↩2 ↩3

  15. Irish Data Protection Commission, DPC statement on Meta AI, 21 May 2025. https://dataprotection.ie/en/news-media/latest-news/dpc-statement-meta-ai ↩

  16. OECD, Artificial Intelligence Markets, 2026. https://www.oecd.org/en/publications/artificial-intelligence-markets_d531d73f-en/full-report.html ↩

  17. UK Competition and Markets Authority, CMA AI strategic update / Foundation Models work. https://www.gov.uk/government/publications/cma-ai-strategic-update/cma-ai-strategic-update ↩

  18. Stanford HAI, 2026 AI Index Report, Economy chapter. https://hai.stanford.edu/ai-index/2026-ai-index-report/economy ↩

  19. Synergy Research Group, European Cloud Providers’ Local Market Share Now Holds Steady at 15%, 24 July 2025. https://www.srgresearch.com/articles/european-cloud-providers-local-market-share-now-holds-steady-at-15 ↩

  20. European Investment Bank, The scale-up gap: Financial market constraints holding back innovative firms in the European Union. https://www.eib.org/en/publications/online/all/the-scale-up-gap ↩

  21. European Commission, AI Continent Action Plan. https://commission.europa.eu/topics/competitiveness/ai-continent_en ↩ ↩2

Leave a note in the margin

Your submission is stored privately until reviewed or deleted. Only an edited, accepted note can appear publicly. Do not include confidential information. Attribution is optional.