6114 links
  • GuiGui's Show
  • Home
  • Login
  • RSS Feed
  • ATOM Feed
  • Tag cloud
  • Picture wall
  • Daily
Links per page: 20 50 100
 
  • AI: EU Member States plan “digital expropriation” of Europeans in the interest of AI companies

    In a leaked document, the Irish Presidency proposes to EU Member States that the interest of OpenAI, Anthropic, Google, Meta and SpaceX to make profits should take precedence over the fundamental right to data protection. Use of personal data “in the context of AI” should automatically be lawful. There seems to be wide informal agreement by many Member States. In particular, Big Tech would be able to use all personal data collected over the past decades with virtually no restrictions, as long as this happens “in the context” of AI. […]

    […]

    […] Ireland serves as the EU headquarter for the majority of the US and China’s AI corporations.

    […]

    A blank check for an entire technology? Usually, the GDPR permits processing for specific purposes (e.g. retention for tax records or fraud prevention). However, the currently proposed Article 88c (or Article 88bis) legitimises an entire technology. Regardless of the purpose for which it is used, any AI system would be lawfully sucking up any personal data by default. […]

    […]

    Further massive limitations on protections and rights. The EU member states have further proposed drastically narrowing the definition of “personal data”, meaning that, amongst other things, it is unclear whether, for example, online tracking would still be covered by the GDPR. This is meant to be done via so-called "pseudonyms" that should regularly not be covered by the GDPR anymore. The problem is, that most IT systems primarily work with pseudonyms (such as user IDs, tracking IDs, IP addresses or social security numbers).

    Furthermore, internal company knowledge and capabilities should be an element to be taken into account to determine if the GDPR even applies. Equally, data subject rights should not be applicable if they are “abused” by a data subject.

    In practice, these "subjective" factors are prone to abuse. The decision of whether data is still “personal” or a right is “abusive” would be primarily made by the companies that are regulated by the law. Both of these measures can make it almost impossible to enforce the GDPR in practice. In each individual case, companies could have lengthy debates about their (unknown) internal capabilities and intentions and speculate about the potentially "abusive" intentions of users. Such debates typically drag on for years and drown procedures in enormous delays and enormous costs - so anything but "simplification".

    […]

    Position of the European Commission and the European Parliament. The European Commission made a 180-degree turn a while ago, and currently clearly prioritises the interests of industry lobbies over fundamental rights. The position of the European Parliament remains mixed. Whilst most of the European People’s Party tend to argue in favour of putting more and more loopholes in EU digital laws, Members of the European Parliament, from the centre-left factions have so far pushed back. Increasingly also far-rights groups oppose proposals for a “free pass” for Big Tech.

    Des nouvelles du Digital Omnibus, le démantèlement du RGPD.

    La base légale de l'intérêt légitime permet déjà de traiter des données à caractère personnel (DCP) n'importe comment et pour n'importe quoi. Toutes les entités privées en abusent, autant que le public abuse de son équivalent, la mission d'intérêt public. La vérification des critères (intérêt légitime, nécessité, proportionnalité) est chiante, donc les autorités de contrôle, comme la CNIL, y procèdent très rarement. La CNIL elle-même abuse de la mission d'intérêt public, notamment pour sa lettre d'information. Bref, ici l'IA ne fait que rappeler l'existence de ces trous béants du RGPD.

    Sur la réutilisation des DCP pour n'importe quelle finalité, noyb dérape un peu. Les systèmes d'IA sont encadrés par l'AI Act, donc écrire que les DCP serviront à entraîner des systèmes dédiés à la désinformation ou à la génération de nus sans consentement, c'est exagéré. Mais, sous cette réserve, il est exact d'affirmer que le principe d'utilisation de DCP pour une finalité précise et leur réutilisation pour des finalités compatibles (lire ici) est sérieusement mis à mal par la proposition.

    Concernant le débat de l'application du RGPD aux données pseudonymisées, je renvoie vers cet article.

    Triste de voir l'Allemagne sombrer en soutenant une variante de cette proposition qui exclue les autorités publiques (souvenirs de la Stasi ?) et quelques usages (génération voix ou image d'une personne, identification / surveillance / évaluation de personnes). Ce n'est pas la première fois.

    September 21, 2026 at 9:16:24 AM GMT+2 * - permalink - https://noyb.eu/en/ai-eu-member-states-plan-digital-expropriation-europeans-interest-ai-companies
Links per page: 20 50 100
 
Mentions légales identiques à celles de mon blog | CC BY-SA 3.0

Shaarli - The personal, minimalist, super fast, database-free, bookmarking service by the Shaarli community