European Union flags flying outside a modern glass building in Brussels
Photo via Unsplash

TL;DR: The European Commission's "Digital Omnibus" rewrites the definitions at the heart of GDPR, delays enforcement of the AI Act, and hands Big Tech nearly every change it asked for. The lobbying tab: €151 million per year from the digital industry alone, a 33.6% jump in two years. Google, Meta, Microsoft, and Amazon didn't just influence these proposals. A Corporate Europe Observatory investigation found their lobbying papers map almost word-for-word onto the Commission's text. The Parliament voted 569-45 to adopt its negotiating position on March 26, 2026. Trilogue negotiations are underway now, with a target deal by April 28. If this passes in its current form, your ad ID, your cookies, and your pseudonymous data could lose GDPR protection entirely, and companies get a green light to feed your personal information into AI training sets under a vague "legitimate interest" exception.

What the "Simplification" Actually Simplifies

In November 2025, the European Commission unveiled something called the "Digital Omnibus," a package of amendments to the AI Act, GDPR, and ePrivacy rules, wrapped in the language of cutting red tape and boosting competitiveness.[1]

The word "simplification" appears dozens of times in the proposal documents. Here's what it actually means:

  • Personal data gets redefined. Pseudonymous identifiers (ad IDs, cookies, device fingerprints) would no longer count as personal data if the company receiving them claims it can't directly identify you. That's a massive carveout. It strips GDPR protection from exactly the kind of tracking data that powers surveillance advertising.[2]
  • Sensitive data protections get narrowed. Health information, political views, sexual orientation, and religious beliefs would only be protected when you explicitly disclose them, not when a company infers them from your behavior. So if an algorithm figures out your medical condition from your browsing habits, that inference might not be "sensitive data" anymore.[2]
  • Your right to access your own data gets limited. Companies can refuse data access requests if they decide the request serves "purposes other than the protection of their data." Workers disputing unfair AI-driven decisions? Journalists investigating data practices? Consumers trying to understand algorithmic profiling? Tough luck.[3]
  • AI training gets a GDPR pass. A new "legitimate interest" exception lets companies use personal data (including sensitive categories) for AI model training with unspecified "safeguards." The Commission left "safeguards" undefined.[2]
  • Cookie consent flips from opt-in to opt-out. The ePrivacy framework gets merged into GDPR. Companies could collect data without explicit consent for "low-risk" uses. Google's lobbyists specifically asked for this, allowing "first-party audience measurement, ad frequency capping, and anti-fraud measures" without consent.[4]

Every one of these changes weakens protections for the 450 million people GDPR was supposed to shield.

The AI Act Gets Defanged Before It's Even Enforced

The AI Act was supposed to be the world's first comprehensive AI regulation. It passed in March 2024 after years of negotiation. Full enforcement was set for August 2, 2026.

The Digital Omnibus guts it before it arrives:

  • High-risk deadlines get pushed. Companies deploying high-risk AI systems in hiring, law enforcement, healthcare, and credit scoring get until December 2027 for some systems and August 2028 for others.[5]
  • Self-assessment replaces oversight. Companies can unilaterally declare their high-risk AI systems as not actually high-risk, without notifying anyone. The original requirement to register these self-exempted systems in the EU database? The Commission wanted to kill it entirely.[3] (Parliament and Council pushed back on this specific point.)
  • Transparency penalties get delayed. Fines for transparency violations won't kick in until August 2027.[2]
  • Risk assessments go private. AI providers would no longer publish risk assessments in the EU's public database.[3]

Meta's lobbying position was blunt: "Critical to first pause the implementation and enforcement of the AI Act."[4] The Digital Industry Association CCIA demanded a 12-month delay after guidance is available. DigitalEurope wanted the same. The Commission delivered.

€151 Million Bought This

In January 2026, Corporate Europe Observatory published a forensic investigation comparing Big Tech lobbying papers to the Commission's actual proposal text. The overlap is damning.[4]

The digital industry's annual EU lobbying spend hit €151 million, up from €113 million in 2023. A 33.6% increase in two years, timed perfectly for the Digital Omnibus push.

The receipts:

  • Google proposed replacing the ePrivacy consent requirement with a "risk-based framework." The Commission adopted a risk-based framework. Google also asked for a "disproportionate efforts" exemption to data access rights (Articles 15-22). The Commission added a "disproportionate efforts" exemption.[4]
  • CCIA (representing Google, Apple, Amazon, Meta) demanded "legitimate interest" as a lawful basis for AI training. The Commission created a legitimate interest exception for AI training.[4]
  • DigitalEurope wanted pseudonymous data removed from the personal data definition. The Commission narrowed the personal data definition to potentially exclude pseudonymous data.[4]
  • DigitalEurope also demanded abolishing mandatory AI system registration. The Commission initially removed the registration requirement, though Parliament reinstated it.[4]
  • Meta met with four far-right MEPs in one week in December 2025. During the current parliamentary mandate, Meta held 38 meetings with MEPs from the ECR, Patriots, and Europe of Sovereign Nations groups, compared to one meeting during the entire previous mandate.[4]

Max Schrems, the Austrian privacy advocate whose lawsuits have reshaped European data protection, called it "Trump'ian lawmaking practices taking hold in Brussels."[2]

Five Days to Review 180 Pages

The Commission didn't just write what Big Tech wanted. It rushed the process to prevent scrutiny.

Internal Commission units had five working days to review the 180+ page Digital Omnibus draft. No impact assessments were prepared. The public consultation concluded in October 2025, just weeks before the November unveiling.[2]

Executive Vice President Henna Virkkunen met with U.S. tech executives in May 2025 to pitch a more "business-friendly" Europe. By November, the pitch was on paper.[2]

Merve Hickok, president of the Center for AI and Digital Policy, warned that the "simplification proposal will let loose unsafe AI systems in the EU."[2]

Where This Stands Now

The timeline is moving fast:

  • March 13, 2026: Council adopted its general approach under the Cypriot Presidency[5]
  • March 18, 2026: Parliament's IMCO and LIBE committees approved their joint report
  • March 26, 2026: Parliament plenary voted 569-45-23 to adopt its negotiating position[5]
  • April 2026: Trilogue negotiations underway between Parliament, Council, and Commission
  • Target: April 28, 2026: The Cypriot Presidency wants an agreed text by this date[5]
  • August 2, 2026: Original AI Act general application date, now likely to be delayed for high-risk systems

There's a narrow window. Parliament and Council both reinstated some protections the Commission tried to cut, including the AI system registration requirement and a "strict necessity" standard for processing sensitive data for bias correction.[5] But the core weakening of GDPR's personal data definition and the AI training exception are still on the table.

What This Means for You

If you live in the EU or use services that operate under GDPR:

  • Your tracking data could lose legal protection. Ad IDs, cookies, and device fingerprints that currently qualify as personal data under GDPR might not anymore. Companies that track you across the web could argue this data isn't "personal" because they don't know your name.
  • Your inferred sensitive data won't be sensitive. A company that figures out your medical conditions, political leanings, or sexual orientation from your online behavior might not need special legal grounds to process it.
  • AI companies can train on your data. The "legitimate interest" carveout for AI training means companies can argue they need your personal information to build AI systems, without your explicit consent.
  • High-risk AI in hiring and policing gets more time. Companies deploying AI systems that decide who gets a job, a loan, or a police visit have until 2027-2028 to comply with safety requirements, assuming those requirements survive trilogue.

What you can do right now:

  • Contact your MEP before April 28 and demand the GDPR personal data definition stays intact
  • Support organizations fighting the rollback: EDRi, noyb, and Amnesty International are all pushing back
  • Use browser-level protections (Firefox, Brave) that block trackers regardless of legal frameworks, because laws can change faster than you'd expect

The Bigger Picture

For years, the EU was the counterweight. While the U.S. let Silicon Valley self-regulate and China built a surveillance state, Europe passed GDPR, the AI Act, and the Digital Services Act. Other countries modeled their privacy laws on Brussels. The "Brussels Effect" was real.

The Digital Omnibus is the Brussels Effect in reverse. €151 million in lobbying, a Commission eager to court Big Tech investment, and a 180-page proposal that mirrors corporate wish lists almost verbatim.

Amnesty International's April 2026 analysis put it plainly: the proposals "will roll back our rights in order to feed AI."[3]

The trilogue target is April 28. That's 18 days from now. If the GDPR weakening survives, it won't just affect Europeans. Every company that uses GDPR as a baseline, and every privacy law modeled on it, gets weaker too.

Europe didn't just write the world's privacy rules. It showed everyone that strong regulation was possible. Now it's showing them how fast that can be undone.

References

  1. Crowell & Moring: EU AI Act, GDPR, and Digital Laws Changes Proposed (November 2025)
  2. TechPolicy.Press: EU Set the Global Standard on Privacy and AI. Now It's Pulling Back (November 2025)
  3. Amnesty International: How EU Proposals to "Simplify" Tech Laws Will Roll Back Our Rights in Order to Feed AI (April 2, 2026)
  4. Corporate Europe Observatory: Article by Article, How Big Tech Shaped the EU's Roll-Back of Digital Rights (January 14, 2026)
  5. Addleshaw Goddard: EU Digital Omnibus on AI Update: Council and Parliament Agreed Positions (March 2026)