Digital Omnibus Rejects AI Training Ease: GDPR Compliance Tightens
On 2 March 2026, DLA Piper released a critical legal analysis of the EU's Digital Omnibus package, revealing that European regulators have explicitly rejected proposals to relax General Data Protection Regulation (GDPR) constraints on AI training data. This decision maintains stringent anonymisation and legitimate interest tests that directly impact how UK and European enterprises can lawfully develop, fine-tune, and deploy artificial intelligence systems.
For Chief AI Officers and enterprise technology leaders, the implications are stark: the pathway to rapid, data-intensive AI development remains narrower than many anticipated, enforcement risk has intensified, and compliance complexity has grown. This article examines what the Digital Omnibus outcome means for your AI governance strategy, data mapping practices, and regulatory risk profile across UK and EU operations.
The Digital Omnibus Decision: What Changed and What Stayed
The Digital Omnibus legislative package—part of the EU's broader AI Act implementation framework—was designed to modernise digital regulation and clarify how existing laws interact with emerging technologies. During its drafting, there was considerable industry lobbying for GDPR exemptions or broad-based legitimate interest carve-outs that would permit corporations to use personal data for AI model training without explicit consent.
That lobbying failed. The final text, as analysed by DLA Piper's lead author Giulio Coraggio, confirms that:
- No blanket GDPR exemption for AI training: The Omnibus does not create a special legal basis permitting unrestricted use of personal data for AI model development.
- Anonymisation bar remains high: Data must be truly anonymised—irreversibly de-identified such that the individual is no longer identifiable—to fall outside GDPR scope. Pseudonymised data, which can still be linked back to an individual with sufficient technical effort, remains subject to full GDPR obligations.
- Legitimate interest test unchanged: Organisations relying on Article 6(1)(f) GDPR (legitimate interest) must still satisfy the three-part balancing test: demonstrating a genuine business interest, necessity, and that this interest overrides data subjects' rights and freedoms. The Omnibus provides no softening of this test for AI use cases.
- Purpose limitation reinforced: The principle that data collected for one purpose cannot be repurposed without fresh legal justification remains binding. Collecting customer data for operational purposes does not automatically justify using that data to train large language models or other generative AI systems.
For UK organisations, this outcome is particularly significant. While the UK left the EU, UK data protection law—the Data Protection Act 2018 and UK GDPR—mirrors EU GDPR in structure and interpretation. The ICO's evolving AI guidance and UK courts' interpretation of legitimate interest will align closely with EU regulatory trends. Therefore, Digital Omnibus signals the enforcement direction that UK and EU data protection authorities will pursue for the next 3–5 years.
Giulio Coraggio's Data Mapping Framework and Compliance Reality
DLA Piper's analysis, authored by Giulio Coraggio, emphasises a return to fundamentals: comprehensive data mapping and documented legitimate interest assessments. Rather than seeking regulatory shortcuts, enterprises must now execute rigorous governance disciplines.
Coraggio's recommended framework rests on four pillars:
- Data inventory and classification: Map every dataset your organisation intends to use for AI training. Classify data by source (first-party customer data, third-party partnerships, public domain, synthetic), by sensitivity (personal v. non-personal, special categories), and by original collection purpose. This exercise is tedious but non-negotiable.
- Legitimate interest assessment (LIA): For each AI training use case relying on Article 6(1)(f), document a rigorous balancing test. The three-part test requires: (a) identifying a genuine, legally recognised business purpose (e.g., improving customer service accuracy); (b) establishing necessity (is this data, at this scale, essential to achieve the purpose?); and (c) conducting a interests balancing showing that your interest is not overridden by data subjects' rights to privacy, dignity, and autonomy. The ICO's guidance on AI and data protection (published in December 2023) and the EU's Article 29 Working Party opinions reinforce that AI training often fails this balancing test when undertaken at scale on sensitive personal data.
- Technical and organisational safeguards (TOS): Anonymisation, pseudonymisation, encryption, access controls, and audit trails must be documented and tested. True anonymisation—irreversible removal of identifiers and quasi-identifiers—is the gold standard. Pseudonymisation alone is insufficient to escape GDPR.
- Transparency and subject rights: Where personal data is used for AI training, privacy notices must clearly explain this use. Data subjects retain rights to access, rectification, erasure, and portability. Automated decision-making rules under Article 22 GDPR may apply, requiring human review for decisions with legal or similarly significant effects.
Coraggio's framework is not novel; it reflects core GDPR principles. What is novel is the Digital Omnibus's reaffirmation that no regulatory loophole exists. Enterprises cannot argue that 'AI is new and requires different rules.' The rules remain as they were.
AI Act Interaction: Compounding Compliance Burden
The Digital Omnibus decision must be read alongside the EU AI Act, which entered into force in phases from August 2024 onwards. The interaction between GDPR (data governance) and the AI Act (algorithmic governance) creates a dual compliance regime that many UK enterprises have underestimated.
The EU AI Act classifies AI systems by risk level—prohibited, high-risk, limited-risk, and minimal-risk. High-risk AI systems (including those used for automated decision-making affecting fundamental rights) trigger mandatory requirements:
- Conformity assessments and CE marking;
- Technical documentation and risk assessments;
- Human oversight provisions;
- Transparency and disclosure to users;
- Monitoring and incident reporting;
- Cybersecurity measures.
When combined with GDPR, this creates a layered burden: you must lawfully source and process personal data for AI training (GDPR), you must ensure the resulting AI system meets algorithmic governance standards (AI Act), and you must maintain records demonstrating both. For a financial services firm using AI for credit decisioning, this means justifying data use under GDPR, documenting the training pipeline, conducting bias and fairness audits, implementing human review, and maintaining audit logs for regulators.
The UK AI Bill, published in draft form in 2023 and progressing through Parliament in 2026, is likely to adopt a broadly similar risk-based approach. The UK AI Safety Institute, established in March 2023, has already published DSIT guidance on pro-innovation regulation, signalling that the UK will align with EU frameworks while offering some flexibility on compliance timelines. However, the core principle—that AI developers must justify data use, document governance, and prove safety—remains consistent across both jurisdictions.
Practical Implications for UK Enterprise AI Programmes
What does this mean for your AI strategy in 2026? Several practical consequences follow:
Consent Becomes Competitive Advantage
Organisations holding explicit, documented consent from data subjects to use their data for AI purposes enjoy a secure legal foundation. Consent (Article 7 GDPR) removes reliance on the weaker legitimate interest test. This is why leading financial services and healthcare firms are now building consent flows into their customer engagement processes. If your competitors have consent and you rely on legitimate interest, you face higher regulatory risk.
Synthetic Data and Privacy-Enhancing Technologies (PETs) Investment Accelerates
Rather than relax access to real personal data, the Digital Omnibus outcome validates the shift toward synthetic data generation, federated learning, differential privacy, and homomorphic encryption. These technologies allow AI model training without exposing sensitive personal data to training pipelines. The UK AI Safety Institute and the Alan Turing Institute have published research supporting this trend. Investment in PETs is no longer optional; it is a core risk-mitigation strategy.
Third-Party Data Partnerships Require Tighter Contracts
If you acquire training data from third-party data brokers, marketing cloud providers, or customer data platforms, your contracts must explicitly allocate GDPR liability. Who bears responsibility if the data was not lawfully collected? Who indemnifies you if a data subject files a Subject Access Request that reveals the data was used for undisclosed AI purposes? Contracts must be renegotiated. Many existing vendor agreements contain ambiguous language around 'analytics' and 'AI' that will not survive ICO or UK court scrutiny.
Enforcement Risk and Fines Rise
UK Information Commissioner's Office (ICO) enforcement activity on AI and data protection has escalated. The ICO published its UK GDPR and AI guidance in December 2023, making clear that organisations using personal data for AI training without clear legal justification face investigation. Recent cases—including the ICO's investigations into facial recognition in UK retail (concluded 2023) and algorithm auditing requirements—demonstrate that data protection authorities view AI development as a priority enforcement domain. EU regulators, including the Irish DPC (which oversees many major tech firms' EU operations), have begun issuing fines under GDPR for inadequate data governance in AI projects. UK fines are likely to follow, scaled to UK business sizes but aligned with EU precedent.
Board-Level Governance Tightens
Regulators and company boards are now treating AI governance as equivalent to financial risk management. The combination of GDPR fines (up to €20 million or 4% of global turnover, whichever is higher) and AI Act penalties (for high-risk systems, fines up to €30 million or 6% of turnover) means that a single compliance failure can trigger material financial and reputational damage. Non-executive directors and audit committees are demanding that AI projects be subject to the same pre-approval, data governance, and audit protocols as mergers, treasury operations, and regulatory capital management.
Looking Forward: The 2026–2027 Enforcement Wave
The Digital Omnibus's maintenance of strict GDPR rules for AI signals a multi-year enforcement wave. Here is what to anticipate:
Regulator Coordination and International Alignment
The UK ICO, EU national data protection authorities (DPAs), and the EU Data Protection Board are increasingly coordinated. The DPB has published guidance documents on AI and GDPR that inform enforcement interpretation across the EU and influence UK thinking. Cross-border investigations—where data moves between UK and EU operations—will become common. Your compliance posture must be harmonised across both jurisdictions.
Third-Party Audits and Certification
Expect demand for third-party audits of AI training pipelines. Consulting firms and specialist vendors are developing 'AI compliance certifications' that demonstrate to regulators that you have undertaken legitimate interest assessments, documented data lineage, implemented safeguards, and tested for bias. These certifications will become routine due diligence for regulated sectors (financial services, healthcare, public sector).
Data Subject Rights Enforcement
As more individuals become aware that their personal data is used for AI training, Subject Access Requests (SARs) will surge. Organisations must be prepared to respond to SAR requests that ask: 'Show me all datasets I am in. Show me the AI models trained on my data. Show me how my data was anonymised.' If you cannot answer these questions, you face ICO enforcement. Investment in data governance tooling (data catalogues, lineage tracking, privacy-enhancing technologies) is urgent.
Litigation Risk from Data Subjects
The UK courts are becoming more willing to entertain group actions and class claims related to data misuse. The recent judgment in Schrems II and follow-on cases demonstrates judicial scrutiny of data transfer mechanisms and corporate data practices. Data subjects (or their legal representatives) may initiate claims arguing that companies unlawfully used personal data for AI training. Legal fees, damages, and reputational harm can exceed regulatory fines.
Recommended Actions for CAIOs and Technology Leaders
Based on this analysis, your immediate priorities should be:
- Commission a data governance audit: Map all datasets used in AI projects. Classify by legal basis. Identify gaps in documentation (consent, legitimate interest assessments, privacy impact assessments).
- Renegotiate vendor contracts: Review all third-party data, cloud infrastructure, and AI platform agreements. Ensure vendors indemnify you for data governance breaches and clearly allocate GDPR compliance responsibility.
- Invest in synthetic data and PETs: Allocate budget to synthetic data generation, federated learning platforms, and differential privacy tooling. These reduce your reliance on personal data and lower regulatory risk.
- Establish an AI Ethics and Governance committee: With representatives from Legal, Compliance, Data, Technology, and the Business, establish monthly governance reviews of new AI projects. Require documented legitimate interest assessments before model training begins.
- Engage with regulators early: The ICO and UK DSIT welcome engagement with organisations developing AI governance frameworks. Consider requesting an informal advisory call with the ICO's AI and data protection team.
- Monitor EU regulatory development: The EU AI Act implementation continues through 2026–2027. Track guidance from the EU AI Office and national DPAs. UK regulatory positions will follow closely, with a 6–12 month lag.
Conclusion: Compliance as Competitive Advantage
The Digital Omnibus's rejection of GDPR exemptions for AI training is not a setback; it is a clarification. For conscientious enterprises, clarity is an advantage. Your competitors who believed a regulatory shortcut existed are now exposed. Your enterprise, which invests in rigorous data governance, consent management, and legitimate interest documentation, will move faster and face lower enforcement risk.
The path to enterprise AI is narrower than some marketing materials suggest, but it is clearly marked. The rules are GDPR and the AI Act. The tools are data mapping, legitimate interest assessments, technical safeguards, transparency, and third-party accountability. The winners in 2027 will be organisations that treated these not as compliance burdens but as core design principles from day one.
For UK businesses operating across UK and EU markets, the Digital Omnibus outcome underscores the importance of adopting EU-aligned governance practices. The UK ICO, UK courts, and Parliament are watching EU enforcement closely. By meeting EU standards, you exceed UK minimums and build future-proof governance. By cutting corners and betting on UK leniency, you court disaster.
The time to act is now. Digital Omnibus has reset expectations. Your board, your regulators, and your customers are watching to see how you respond.