The EU unveils proposed updates to GDPR, including simplifying cookie permission pop-ups, and plans to water down the AI Act, after US and tech company pressure
The EU folds under Big Tech's pressure. … After years of staring down the world's biggest tech companies and setting the bar …
The policy shift matters because it places GDPR implementation and AI Act obligations in the same competitiveness debate, after earlier EU digital-rulemaking drew reported last-minute lobbying over surveillance-advertising constraints.
First-order effects
Businesses operating in Europe gain the prospect of simpler cookie-consent handling and less demanding AI compliance requirements, though the changes remain proposals rather than immediate rule changes.
EU privacy and AI regulators must prepare to translate a softer policy direction into revised guidance, enforcement priorities, or legislation.
Second-order effects
Large technology companies and US-linked firms pressing for lower compliance burdens gain leverage in the next legislative and implementation stages; smaller firms could also face lower administrative costs if simplification is adopted.
Consent-management providers and compliance advisers may need to revise products and services built around current cookie and AI-rule requirements, while privacy advocates are likely to scrutinize whether simplification reduces meaningful user control.
Third-order effects
If adopted, the changes would test whether the EU can retain rules-based market access while making its digital rulebook more responsive to competition and AI deployment pressures.
The combined treatment of privacy and AI obligations could establish a recurring pattern: rules once framed as global standards are revisited when their compliance costs become a competitiveness issue.
The trend: European digital regulation is shifting from setting expansive baseline obligations toward recalibrating enforcement and compliance burdens around AI competitiveness and market access.
The proposal to modify AI ACT is a material weakening. It removes direct AI-literacy obligations on operators (now only “encourages"), delays the entry into force of core high-risk duties, relaxes transitional rules for legacy systems, and broadens the ability to process
With the European Data Union Strategy, we aim to stimulate data sharing across companies and ensure that rules lead to real results. With new European Business Wallets valid throughout the Union, we want to make it simpler and less costly for companies to operate in the #EU.
We want to make Europe's digital rules simpler, clearer and faster. In a nutshell: 🇪🇺 Easier compliance and lower costs 🇪🇺 More room for innovation 🇪🇺 Trust and protection remaining at the core This is the Digital Package! [video]
Since 2016, the GDPR has become the cornerstone of EU digital legislation —shaping how we protect personal data & enabling trusted cross-border data flows across the Union. However, practical implementation challenges remain for both private & public organisations. [image]
We need simpler, streamlined rules on data, with targeted amendments. We will have two laws, not five: the Data Act and the GDPR. Addressing the need for a clearer and simpler regulation and reducing regulatory burden is an instrumental step. https://ec.europa.eu/...
✅ Making the implementation of the 𝗔𝗜 Act easier and clearer, while safeguarding fundamental rights. Helping companies with compliance. Simplifying measures such as AI literacy to reduce costs and burdens.
✅ Changes in 𝗱𝗮𝘁𝗮 𝗿𝘂𝗹𝗲𝘀 will save costs and time for businesses, making them more competitive. Tackling cookie banner fatigue by updating our rules. Introducing the new Data Union Strategy to unlock the full value of data and support AI development in the EU.
🔛 Making the digital rules in Europe simpler and clearer! Today the @EU_Commission presents the Digital Package. Unlocking new opportunities for businesses while removing overlaps and holding up the European standards 🧵↓