Effective bias detection in AI systems under the GDPR requires identifying the individuals or groups potentially affected by discriminatory outcomes. Assessing whether a recruitment algorithm disadvantages a certain segment of individuals, or whether a scoring model adversely impacts a particular ethnic group, requires examining the underlying data. This data often falls within the GDPR’s most sensitive categories. Since 2018, information relating to race, health, religion, trade union membership, and other special category data under Article 9 has been subject to the strictest protections; however, it is precisely this data that enables meaningful bias assessment.
This tension between preventing discriminatory AI outcomes and safeguarding the sensitive data needed to detect them sits at the core of one of the EU’s GDPR related legislative updates that are closely watched.
Additionally, this article outlines, in accessible terms, what is changing under GDPR. It also covers what remains under negotiation and what organizations should keep in view as these developments progress.
Two GDPR Proposals, Two Different Timelines
The Digital Omnibus is often referred to as a single reform, but it is in fact two separate legislative files, both tabled by the Commission on 19 November 2025:
- The Digital Omnibus on AI, amending the AI Act, which has already been adopted and entered into force on 27 July 2026 as Regulation (EU) 2026/1744.
- The Digital Omnibus (also referred to as the “Data Omnibus”), amending the GDPR, the ePrivacy rules, the Data Act, NIS2 and DORA, which remains under negotiation. The European Data Protection Board and the European Data Protection Supervisor issued a joint opinion on this proposal in February 2026, raising a number of concerns.
Recognizing this distinction is essential, as the legal basis for AI related data processing is currently being shaped through two parallel initiatives that are progressing unevenly.
Legitimate Interest: A Clearer Basis for AI Development
Organizations relying on GDPR Article 6(1)(f) legitimate interest to justify processing personal data for AI training have long operated in a degree of uncertainty. The provision requires a case-by-case balancing test, and regulators have not previously confirmed, in explicit terms, that AI development falls within its scope.
The GDPR-side proposal addresses this directly. A new provision, would confirm that the development and operation of an AI system can constitute a legitimate interest under Article 6(1)(f). This basis is not unconditional. Controllers must still carry out the balancing test, apply enhanced safeguards, and step back from this basis whenever EU or national law expressly requires consent. In practice, it clarifies a longstanding gray area rather than creating a broad exemption.
One point of tension has already been raised by commentators: the proposal pairs this basis with an unconditional right for data subjects to object. Commentators have already highlighted a key point of tension: the proposal pairs this legal basis with an unconditional right for data subjects to object. This works when a controller trains a model on data collected directly from its own users. It becomes far more difficult when training data comes from large‑scale web scraping, because the controller has no practical way to inform individuals or to act on their objections.This is likely to remain a point of debate as negotiations continue.
Bias Detection and the Special Category Data Problem
This is the aspect most directly relevant to AI governance teams.
Prior to the Digital Omnibus, Article 10(5) of the AI Act already permitted the processing of special category data for the specific purpose of detecting and correcting bias but only in relation to high-risk AI systems. This left a gap: organizations operating AI systems outside the high-risk category had no clear legal basis to assess whether those systems produced discriminatory outcomes, since doing so would require processing the very categories of data GDPR restricts.
The Digital Omnibus uses two separate mechanisms to address this issue, and commentators often mix them up even though they work differently:
Deliberate bias testing
On the AI Act side, the proposal would extend the existing bias-detection basis beyond high-risk systems, allowing a broader range of providers and deployers to intentionally process special category data for the specific purpose of identifying and correcting discriminatory outputs, subject to strict conditions. This is the provision most relevant to organizations operating AI-assisted scoring, screening, or recommendation systems that do not fall within the high-risk category.
Incidental presence of special category data
Separately, on the GDPR side, a narrower derogation is proposed to address the practical reality that large training datasets often contain special category data that was never deliberately sought. Under this approach, such data may remain in a dataset only where the controller has first taken steps to avoid its collection, has deleted it where this does not require disproportionate effort, and, where deletion is genuinely not feasible, has implemented measures to prevent the data from influencing the system’s outputs or being disclosed to third parties.
It is worth noting that the precise article numbering for both mechanisms has shifted across successive drafts, and the two provisions remain on different legislative tracks. Organizations should treat the substance described here as directionally accurate rather than final, pending adoption of the consolidated texts.
Safeguards Common to Both Mechanisms
Across both tracks, the safeguards under discussion consistently include:
- Data minimization – processing limited to what is strictly necessary for the stated purpose.
- Transparency – data subjects informed that this form of processing is taking place.
- Measures against memorization – technical controls to prevent AI models from retaining and later reproducing personal data.
- Restrictions on disclosure – special category data used for bias correction must not appear in the system’s outputs or be exposed to third parties.
- An unconditional right to object, applicable wherever the legitimate interest basis is relied upon.
Regulators have characterized these as narrow, purpose-specific exceptions rather than a general basis for using sensitive data in AI development. Organizations should expect scrutiny and further guidance once either track reaches adoption.
Current Status
As of August 2026, the practical position is as follows:
- The AI Act amendments are already in force under Regulation (EU) 2026/1744 and apply now.
- The GDPR amendments remain a proposal, useful for forward planning but not yet a basis organizations can rely on operationally.
- Both proposals are attempting to resolve the same underlying conflict: meaningful bias detection in AI systems requires access to data that GDPR was designed to restrict. The Digital Omnibus represents the EU’s attempt to create a narrow, safeguarded pathway through that conflict, rather than to remove the underlying protection.
Organizations should continue to document the legal basis relied upon for each AI-related processing activity, keep Data Protection Impact Assessments (DPIAs) current, and treat provisions still framed as proposals accordingly as an indication of direction, not a basis for present compliance.
This article reflects the state of the proposals as of August 2026. Given the pace of negotiations, aspects of this analysis are likely to change before final adoption; this article will be updated as the texts develop.
Send us a Message
If you have any questions about our services
