The Twenty-Seven will sit down again this Friday at the table to study the latest proposal from the Irish Presidency of the Council on the use of personal data for the training of artificial intelligence systems. This is one of the last pending issues for approval of the so-called "Digital Omnibus". In the offices of the European Data Protection Supervisor (EDPS), they are closely monitoring the processing of the file that will reform the current General Data Protection Regulation (GDPR).
In an opinion issued in January together with the European Data Protection Committee, the body already firmly warned against the reduction of guarantees for fundamental rights. The document paid special attention to both privacy and data protection at a time when they may be seen "as a toll to achieve the simplification of the rules." The draft sent by Ireland to the capitals endorses the use of personal data in artificial intelligence tools, including the phases of training, testing, validation, and operation of the models, when it is based on "a valid legal basis of the GDPR and complies with specific safeguards."
However, the consulted diplomatic sources indicate that the processing of sensitive data will only be justified exceptionally if its presence is incidental, unintentional, and residual within the training or validation datasets. The European Data Protection Supervisor "in principle" supported the proposal to extend the exception that allows the processing of special categories of data, such as those related to health or ethnic origin, to detect and correct biases in all AI systems and models.
The body demanded to restore the standard of "strict necessity" that was originally included in the AI Act, rejecting in any case the downgrade of the draft to a mere "necessity and proportionality." In the negotiations of the Omnibus, the Supervisor also recalled that the processing of sensitive data is generally prohibited by the GDPR. Therefore, it called for "very narrowly" defining the cases in which the exception may apply to AI systems that are not high-risk, conditioning them on the existence of a serious risk of discrimination or real harm if those biases are not corrected.
The risk of biases in AI
The agency understands that if AI models are trained with uncorrected biased datasets, the resulting model may generate serious discriminations. That is why it would support in principle allowing the exceptional use of sensitive data to detect and correct these risks.
Similarly, the Supervisor warns that removing key controls in the training phase or reducing transparency obligations, such as model registration, under the argument of reducing costs for companies, may create undesirable incentives for developers to evade critical analysis of the impact of their models.
The agency's position is based on the need to maintain specific guarantees even when the purpose of the processing is to identify and correct biases. The possibility of using sensitive data would therefore not imply a general authorization, but rather an exception linked to specific conditions.
The Irish Presidency defends that the approach does not imply lowering the guarantees that the European data protection framework recognizes for citizens. The proposal aims, instead, to clarify through a specific legal basis under what circumstances personal data can be used during the various phases of development and training of artificial intelligence systems. The compromise text opens the door to this type of processing when it is supported by a legitimate interest, although in no case would it be exempt from the other conditions and obligations established by the GDPR.
The debate thus focuses on delimiting what can be considered a legitimate interest in the context of AI and what scope this legal basis would have for the use of personal data in the training of models. From the Irish perspective, the proposal would not alter one of the central rules of the GDPR: data controllers would still have to identify and justify the legal basis that supports each operation with personal data.

Among the options contemplated by the Regulation is the consent of the affected party, but also other legal bases, such as precisely the legitimate interest.
The negotiators also emphasize that the safeguards provided by the GDPR to protect the rights and freedoms of individuals would remain fully in force. The objective of the change would not be, therefore, to create a parallel regime for artificial intelligence, but to specify how existing rules should be applied when data processing occurs within the framework of the development and training of these systems.
The proposal now faces the test of the capitals
Ireland will bring its proposal to the Council working group this Friday after having previously consulted the capitals, which will still be able to propose changes or objections. The progress of the file will depend on the level of consensus reached. If there is a sufficient basis, the text could move to Coreper, even with some articles still open for permanent representatives to try to resolve the pending differences.
The meeting will thus serve to determine whether the proposal is mature enough to continue its processing and advance to the next levels of negotiation. The debate ultimately faces two objectives that Ireland considers compatible: to provide legal certainty to the development of artificial intelligence and to maintain the guarantees of the European data protection framework.